3 ms·
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to blo
by autoexec 2mo ago
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
That just entertains the false justification for what is ultimately about surveillance and control. There are privacy preserving alternatives to accounts and ID/face scans but no one in power is interested in them because the loss of privacy is the entire point.
- giantg2 2mo agoWhat might those be? Everything I've seen is ineffective or can be compromised. I think letting parents parent is probably the best option, but will require better/easier/free tools and education to help lock down different categories of harm.
- autoexec 2mo agoThere's nothing that can't be worked around or compromised in some way. Even the face scans and ID scans being used today are being circumvented. In the end we do need parents to parent, but websites should help. The easiest way would be for websites to send an HTTP header to the client so that censorware can know to block or allow it accordingly.
- Gander5739 2mo ago> The easiest way would be for websites to send an HTTP header to the client so that censorware can know to block or allow it accordingly. That sounds very similar to the suggestion of the original commenter, that you responded to with >> That just entertains the false justification for what is ultimately about surveillance and control.
- autoexec 2mo agoI assumed that when he asked "What might those be?" he was talking about privacy preserving ways to address that same false justification. I'm not sure how you took it some other way.
- Gander5739 2mo agoBut the commenter's original suggestion, that "apps and websites ... simply include a recommended age", is privacy preserving, no?
- lcnPylGDnU4H9OF 2mo agoThey didn't say OP's proposal wasn't privacy-preserving, but that preservation of personal privacy is contrary to the actual reason that age checks are being pushed by politicians.
- Gander5739 2mo agoApologies, then, I misinterpreted > That [solution] just entertains the false justification for what is ultimately about surveillance and control.
- codedokode 2mo agoThe header must confirm that site is age-appropriate. No header should be interpreted as "adults only". This is the safest option, and it doesn't require 99% of webmasters to do anything which is in my opinion better than any other proposal.
- autoexec 2mo agoExactly. That's the problem I have with the "restricted to adults" header. Ideally the header wouldn't have a "safe for kids" value either because what one parents feels is safe will be very different from what another parent would find appropriate. I think The Internet Content Rating Association had the right idea were the header would show if a site contained specific types of content or not and it was up to parents to decide how much to censor.
- wongarsu 2mo agoWebsite generates a random nounce, the government offers to sign the json { over_18: true, nounce: [inserted_here] }. That signing is coupled to you being signed in, or scanning your passport via nfc or whatever That significantly reduces the leaked information: the service doesn't receive any information who you are, and the government doesn't know what service you use. They can collude, but that does not reveal more to them than most current age-verification methods. Children can get another adult to sign their request, but that's a working attack on nearly any age verification (including in-person purchases) Of course this doesn't replace parenting
- giantg2 2mo ago"They can collude, but that does not reveal more to them than most current age-verification methods." Or just correlate the IP.
- HDBaseT 2mo agoThe word nounce is used to describe a sex offender, at least in the UK.
- klondike_klive 2mo agoSpecifically a child molester.
- EmbarrassedHelp 2mo agoThat's how members of the UK government refer to anyone that supports privacy and encryption
- slater 2mo ago*nonce
- antonvs 2mo ago> or scanning your passport You’re not helping.
- codedokode 2mo ago1) When buying a device, store employee could program user's age range. 2) When configuring a device, parent may toggle "child mode" checkbox to switch the device into "child mode", protected with a password or fingerprint. 3) The tokens, containing a private key (same for all tokens) can be sold in liquor stores to adults only. This token could confirm the age without a passport. It is interesting that is US (unless I am wrong) you can vote and change the government without a selfie and a passport, but you need them to use Reddit or Discord. > but will require better/easier/free tools and education to help lock down different categories of harm. There should be a single big "child mode" checkbox for normal people and "configure" button for 1% of geeks. Most people do not need tools and have no interest in configuring allowed categories. > Everything I've seen is ineffective or can be compromised Selfie/passport also can be compromised by asking a friend/older brother/parents to verify your account. Especially if you have a poor adult friend with alcoholic dependency in dire need of a new portion.
- giantg2 2mo agoNumber 2 is basically here for many things, but not as easy as a single checkbox. Number 3 is something I've thought about, but it seems that's never seriously discussed in politics.
- codedokode 2mo agoThere should be a single checkbox (when setting up the phone), and "configure" button hidden deep in the settings for the minority. Most people do not like complicated UIs and unnecessary work.
- squigz 2mo agoNot only would #3 be ineffective, it would affect poor people a lot more.
- annzabelle 2mo agoI've never had to do a selfie or a passport for Reddit or Discord, including in the US and Australia.
- 2mo ago
- txrx0000 2mo agoCorrect observations. But have you wondered why those solutions are ineffective? Kids nowadays use phones and tablets for the most part. They don't even know how to use a computer that well and are not taught properly. But this isn't really on the kids. Now, suppose I'm an OS developer. I cannot simply fork Android or iOS to create a child-friendly toy operating system for smartphones with a reduced set of features. The hardware is locked down to oblivion. They want you to use their OS. And their OS has no user accounts, permissions, or firewall configs. Well, then suppose I'm an app developer, and I want to make a browser or social app with built-in client-side content filtering. But my browser doesn't pass Cloudflare or whatever attestation, and is blocked from half of the sites. It might not even be approved on their app store so people will never find it. Fine. Then I want to change what content is filtered within the approved apps. But those options either don't exist or is some kind of cloud service where you give them your age, and they decide what to filter. ========= Parents can't even control what software runs on their own hardware. How are they supposed to control what runs on their child's hardware? ========= "The market failed", so they can sell you parenting among other things as a service, with surveillance as a free gift. The tech companies make money while the government gets control over the populace. It's a terrible arrangement. That is why most digital parenting solutions you've seen are ineffective or can be easily compromised. Tech companies along with the government are playing chess against you at every level of the stack. Don't ever forget the PRISM program exposed by Edward Snowden. Apple, Google, Microsoft, Facebook - they're all complicit. Don't look at what their PR department says, look at what they do: https://en.wikipedia.org/wiki/Edward_Snowden#Revelations https://en.wikipedia.org/wiki/Edward_Snowden#Revelations One possible short-term solution is antitrust legislation for hardware vendors to ship their devices without an OS... is what I would say if we lived in a sunshine and butterflies world. Maybe the EU is not thoroughly captured yet and still has the ability to implement this, but I doubt it. Technoauthoritarians are building a panopticon to contain the sheep, and they're not even hiding it at this point: https://www.youtube.com/watch?v=sQqQtgRdjZU https://www.youtube.com/watch?v=sQqQtgRdjZU https://www.youtube.com/watch?v=d34b7taQ640 https://www.youtube.com/watch?v=d34b7taQ640 The actual long-term solution is difficult. We have to make our own computers and radio equipment before they outlaw mining and manufacturing using the same safety excuses, which will happen when humanoid robots can do those jobs. The entire stack has to be open-source, which means we will have to diffuse fab technology everywhere so that people can manufacture computers locally, from mining to wafers to final assembly, in every city, or even at home. There are very talented people working on this problem, so it will be done. Just don't fall for the narrative that surveillance is inevitable or needed.
- bigstrat2003 2mo agoIf indeed the push for age verification is being done under false pretenses as you suggest, then one should propose solutions that accomplish the stated goals while preserving privacy. Either the solutions will be accepted, or the people advancing false pretenses will be forced to come up with new false pretenses, which will weaken their arguments. Either way is a win.
- JoshTriplett 2mo ago> then one should propose solutions that accomplish the stated goals while preserving privacy Solution: sites and apps optionally provide metadata suggesting their content/age-appropriateness, parents locally configure software to look at that metadata (including what to do with things that don't have metadata), or they don't, depending on their parenting style and the maturity of their child. Done. No laws or identification or invasive measures required.
- autoexec 2mo agoIt's been done. Here are a couple of examples: https://en.wikipedia.org/wiki/Internet_Content_Rating_Association https://en.wikipedia.org/wiki/Internet_Content_Rating_Associ... https://www.rtalabel.org/page.php?content=howtofaq https://www.rtalabel.org/page.php?content=howtofaq Use of those kinds of headers needs to be voluntary for websites, which means that censorware has to block any site that doesn't return the header, not just those sites where the value of that header indicates adult content. That will encourage websites to support the header or risk being auto-blocked by any censorware in use, but that's a problem for the RTA header since it only indicates adult content.
- markovs_gun 2mo agoTo me the biggest piece of evidence that these methods don't actually work for age verification and are completely for surveillance and data collection is that you can't use them to buy wine at the self checkout at the grocery store. Like if it's effective, why can't the self checkout camera tell that I'm over 21 and can buy wine? Because it's not and everyone knows it.
- hinata08 2mo ago> There are privacy preserving alternatives to accounts and ID/face scans I don't see how forcing people to you scan their IDs and turn their camera one is better for privacy. The only explanation is THEY WATCH, literately