5 ms·
There are two things very very wrong with the California law, which you call "age indication". 1) The parental responsibility is given to the wrong people. You
by txrx0000 6mo ago
There are two things very very wrong with the California law, which you call "age indication".
1) The parental responsibility is given to the wrong people. You're basically being forced by law to give all apps and websites your child's age on request, and then trusting those online platforms to serve the right content (lol). It should be the other way around. The apps and websites should broadcast the age rating of their content, and the OS fetches that age rating, and decides whether the content is appropriate by comparing the age rating to the user's age. The user's age, or age bracket, or any information about the user at all, should not leave the user's computer.
2) The age API is not "completely private". It's a legally-mandated data point that can be used to track a user across apps and websites. We must reject all legally-mandated tracking data points because it sets the precedent for even more mandatory tracking to be added in the future. We should not be providing an API that makes it easier for web platforms to get their hands on user data!
For many years, certain tech companies, SIGs, and governments have fought against technologies that could enable real digital parenting, all while claiming to do the opposite and "protecting children". They craft a narrative to convince you that top-down digital surveillance and access-control is for your own good, but it's time we reject that and flip their narrative upside down: https://news.ycombinator.com/item?id=47472805 https://news.ycombinator.com/item?id=47472805
- heavyset_go 6mo ago> For many years, certain tech companies, SIGs, and governments have fought against technologies that could enable real digital parenting, all while claiming to do the opposite and "protecting children". They craft a narrative to convince you that top-down digital surveillance and access-control is for your own good, but it's time we reject that and flip their narrative upside down The EFF has a good series related to this[1]. [1] https://www.eff.org/deeplinks/2026/03/rep-finke-was-right-age-gating-isnt-about-kids-its-about-control https://www.eff.org/deeplinks/2026/03/rep-finke-was-right-ag...
- Ferret7446 6mo ago> The apps and websites should broadcast the age rating of their content, and the OS fetches that age rating, and decides whether the content is appropriate by comparing the age rating to the user's age. How would you make that happen? Many websites would not be subject to your jurisdiction.
- txrx0000 6mo agoAssume they're 18+ then. But even that's still not a great solution. I outline a better solution that doesn't require any legal enforcement at all, in the link at the bottom of my original comment.
- ekr____ 6mo agoWe're actually seeing this play out right now with the server-based age assurance systems which are already widely deployed and mandated under the UK Online Safety Act and laws in about 25 US States. In many cases, the sites just comply, presumably because they are worried that the regulators have a way to reach them even if they aren't hosted in the relevant jurisdiction. In some cases, however, the sites just ignore the regulations or tell the regulators to pound sand, as 4Chan is doing with UK OfCom: https://www.bbc.com/news/articles/c624330lg1ko https://www.bbc.com/news/articles/c624330lg1ko
- kelnos 6mo agoSo? The same problem exists for having the OS broadcast the user's age range to all apps/services/websites: the service outside your jurisdiction doesn't have to actually restrict content based on age. At least with the reverse system (services broadcast an age rating), you have some nice properties: 1. You can set it up so that if the service doesn't broadcast an age rating, access is denied. 2. You aren't leaking age information (even if it's just a range) to random websites outside your jurisdiction.
- ekr____ 6mo ago> 1) The parental responsibility is given to the wrong people. You're basically being forced by law to give all apps and websites your child's age on request, and then trusting those online platforms to serve the right content (lol). It should be the other way around. The apps and websites should broadcast the age rating of their content, and the OS fetches that age rating, and decides whether the content is appropriate by comparing the age rating to the user's age. The user's age, or age bracket, or any information about the user at all, should not leave the user's computer. FWIW, this is not quite an accurate description of AB1043, in at least three respects: 1. Apps don't get your exact age, just an age range. 2. Websites don't get your age at all. 3. AB1043 itself doesn't mandate any content restrictions; it just says that the app now has "actual knowledge" of the user's age. That's not to say that there aren't other laws which require age-specific behaviors, but this particular one is pretty thi on this. In addition, I certainly understand the position that the age range shouldn't leave the computer, but I'm not sure how well that works technically, assuming you want age-based content restrictions. First, a number of the behaviors that age assurance laws want to restrict are hard to implement client side. For example, the NY SAFE For Kids act forbids algorithmic feeds, and for obvious reasons that's a lot easier to do on the server. Second, even if you do have device-side filtering, it's hard to prevent the site/app from learning what age brackets are in place, because they can experimentally provide content with different age markings and see what's accepted and what's blocked. Cooper, Arnao, and I discuss this in some more detail on pp 39--42 of our report on Age Assurance: https://kgi.georgetown.edu/research-and-commentary/age-assurance-online/ https://kgi.georgetown.edu/research-and-commentary/age-assur... I'm not saying that this makes a material difference in how you should feel about AB 1043, just trying to clarify the technical situation.
- txrx0000 6mo agoThanks for the clarification. Regarding what to do with algorithmic feeds, instead of forcing platforms like Facebook to be less evil, we should give parents the ability to simply uninstall Facebook, and prevent it from being installed by the child. We could implement a password lock for app installation/updates at the OS-level that can be enabled in the phone's settings, that works like Linux's sudo. Every time you install/uninstall/update an app, it asks for a password. Then parents would be able to choose which apps can run on their child's device. Notice their strategy: these companies make it hard/impossible for you to uninstall preloaded apps, and they make it hard to develop competing apps and OSes, and they degrade the non-preloaded software UX on purpose, which creates the artificial need to filter the feeds in existing platforms that these companies control. They also monopolize the app store and gatekeep which apps can be listed on it, and which OS APIs non-affliated apps can use. Instead of accepting that and settling with just filtering those existing platforms' feeds, we should have the option to abandon them entirely. We need the phone hardware companies to open-source their device firmware, drivers, and let the device owner lock/unlock the bootloader with a password, so that we could never have a situation like the current one where OSes come preinstalled with bloat like TikTok or Facebook, and the bootloader is locked so you can't even install a different OS and your phone becomes a brick when they stop providing updates. If we allow software competition, then child protection would have never been a problem in the first place because people would be able to make child-friendly toy apps and toy OSes, and control what apps and OS can run on the hardware they purchased. Parents would have lots of child-friendly choices. This digital parenting problem was manufactured by the same companies trying to sell us a "solution" like this Cali bill or in other cases ID verification, which coincidentally makes it easier for them to track people online.
- packetlost 6mo ago1. I don’t see how that’s better in any real way. You can infer the exact same information as querying the range and it makes dynamic behavior based on age range (ex. access to age restricted chat rooms as an obvious example) completely impossible. 2. Is it meaningfully more identifying than User-Agent? There’s dozens of other datapoints for uniquely identifying a user. If we get a few high profile lawsuits because advertising companies knowingly showed harmful ads to children, I’d consider it a win. Age is not that interesting of a data point.
- kelnos 6mo ago> I don’t see how that’s better in any real way. It's so much better. In the one case, the OS is leaking age information (even if just an age range) to every service it talks to. In the other case, the OS isn't telling anyone anything, and is just responding to the age rating that the app/service advertises.
- packetlost 6mo agoThat response reveals exactly the same information.
- gzread 6mo agoHow would you implement a feed of mixed content? Say you're YouTube and some videos are about puppies and some videos are about guns? How would you hide only the gun videos from the homepage when the user is under 16?
- hdgvhicv 6mo agoWhy does YouTube allow videos about guns but not boobs?
- user205738 6mo agowhy not? These are quite modest and decent examples Music video by Mylène Farmer performing Libertine. (C) 1997 Polydor (France) ^[https://youtu.be/oGFr_NcKyfo?t=325 https://youtu.be/oGFr_NcKyfo?t=325] TWIN BUSCH® Germany - Making-of Kalender 2017 ^[https://www.youtube.com/watch?v=WP7HYlBsVB4 https://www.youtube.com/watch?v=WP7HYlBsVB4] TWIN BUSCH® Germany - Making-of Kalender 2018 ^[https://www.youtube.com/watch?v=sdCga9jqD_8 https://www.youtube.com/watch?v=sdCga9jqD_8] Making-of TWIN BUSCH® Kalender 2024 ^[https://www.youtube.com/watch?v=A9JNBdYUYiA https://www.youtube.com/watch?v=A9JNBdYUYiA] MAKING OF | Twin Busch Kalender 2026 ^[https://www.youtube.com/watch?v=cWPastHi8Vs https://www.youtube.com/watch?v=cWPastHi8Vs] and more: https://youtu.be/YzDHQXKBRek https://youtu.be/YzDHQXKBRek https://youtu.be/draP5nH_WXk https://youtu.be/draP5nH_WXk https://youtu.be/LkpTshwskgg https://youtu.be/LkpTshwskgg I'm not even talking about entire sections that feature blatantly pornographic or perverted content, some of which are clearly aimed at a younger audience who might accidentally stumble upon it through keywords you wouldn't expect.
- miki123211 6mo agoIf we accept the premise that age restrictions of any kind are good (which, just to be clear, I don't think we should), there are good reasons for tailoring your content based on the user's age. Imagine you're a streaming service, trying to show a list of movies that a user can watch. If you can only communicate age restrictions to the OS, but can't actually check the users age, you have a choice of showing a list of movies that some users won't actually be able to watch, or a list of movies limited to those appropriate for all ages. Neither are great options. If you can check the user's age bracket, you can actually tailor the list to what the user can realistically watch.
- exe34 6mo agoThere are only about 120 versions to target if you pick each individual age - or a handful if you bracket it. You can simply create a lookup table for eachage group and let the user's device decide which one to show.
- txrx0000 6mo agoThe user can voluntarily give the platform their age by typing it into their account profile in that streaming app. You can already do this right now. No laws required. The problem at hand is we have a new law that forces everyone to give their age to every app. It's mandatory personal info collection.
- charcircuit 6mo agoApps need to know the age of the user in order to follow the law. There will always need to be a way for apps to get the age of the user. If the OS does not give anything the apps will have to implement it themselves.