4 ms·
> By demonizing them and failing to engage with the worries over social media and pornography We have brought it on ourselves. There is a really good way to do
by judge2020 2mo ago
> By demonizing them and failing to engage with the worries over social media and pornography We have brought it on ourselves.
There is a really good way to do this that solves most concerns: https://blog.google/innovation-and-ai/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/ https://blog.google/innovation-and-ai/technology/safety-secu...
The only real downside to this is that a 0kp cannot be reliably tied to an identity of the person using the device and thus tickets could be proxied/shared around with semi technical tools (and/or an ai agent tasked with creating a proxy). This really isn't solvable without device-level attestation[0], as if a website needs to reliably say "this person is actually this person" then it needs all pieces of data itself.
This could be solved by adding in a still privacy-preserving step like "The device is doing periodic face id scans and matching them to an identity, and constantly renews/re-presents to the age assurance consumer", but that has its own drawbacks[0].
0: Namely, lock in to devices that can do this, and that includes basically guaranteeing a double digit percentage of adult humans would not have access due to their device being old, unsupported, missing the hardware, etc. And with so many humans excluded, you would not have mass adoption. Probably also excludes rooted devices if we bring in attestation of unmodified software.
- Aurornis 2mo agoIt’s weird to see that locking down devices even further is being proposed as a solution to anything. The unspoken part of this requirement is that websites would have to block users who aren’t connecting via one of these attested, verified, locked down devices. There is the obvious loophole that using a VPN to a country without these requirements would circumvent it. That’s how kids are already circumventing age restrictions in places like Australia and it’s why the UK has taken an interest in attacking VPNs.
- judge2020 2mo agoLocked down devices are kind of the only solution that both (A) preserves privacy and (B) solves the problem. However, it indeed strips a user of the freedom to use their device in the way that they want; although, safe to say that the US doesn't have all that much problem with that, given Apple's continued market dominance. The alternative is what we're getting right now: laws that require verifying ID documents, often in ways that restrict even the notion of maintaining the user's privacy. Attestation might be an "OK" to "good" solution while this is between bad and really bad.
- speedstyle 2mo agoClient-side filtering solves the problem, because children's clients are owned by their parents. We should mandate that websites and apps send metadata about the content being served (eg extending the Rating: RTA header from 20 years ago) and mandate that OSs/browsers allow filtering to be easily configured at setup. This is a more private but also much more granular/useful solution, it's only difficult today because of a lack of coordination
- judge2020 2mo agoIt's not difficult at all. It's not good enough for lawmakers. Their requirement is opt-in to adult content, not opt-out (i.e. the goal is parents don't need to interact with their child or set up parental controls themselves). Which is really bad.
- speedstyle 2mo agoIt is difficult for parents to do this today! You can either have a limited set of apps with no general internet access (fine for younger kids), or domain-list filtering which takes significant work to set up, has many false positives and negatives, ie it's both a chore to request/allow useful things, and easy to get around. Lawmakers have been convinced the solution is opt-in, so websites can self-categorize and nothing needs to be configured on device – and I agree that websites need to self-categorize, but then this would make it very easy to reliably filter on device.
- judge2020 2mo agomy iPhone has "Limit Adult Websites" as an option - and it blocks some known less-than-mainstream adult content sites. I can basically guarantee it consumes the RTA header/label in addition to maybe a list of sites Apple maintains as adult content (maybe similar data to those DNS providers with an IP that DNS blocks adult sites).
- Magnusmaster 2mo agoLocked down devices will never preserve privacy since the government can just mandate spyware that you won't be able to remove. There is no form of digital ID that isn't evil, but anything requiring attestation is super evil.
- intrasight 2mo agoThose in tech who study this already understand the need to hardware attestation. Everyone else will understand soon enough. Old hardware will have to be grandfathered. Old cars don't track us and that has created a market for old cars. Hardware age attestation will be a long timeframe project. The current work should be towards standards that can get us there. Finally, anonymity didn't exist for my grandparents. It won't exist for my grandchildren.
- deleted 2mo ago[deleted]
- judge2020 2mo ago> Hardware age attestation will be a long timeframe project. The current work should be towards standards that can get us there. Unfortunately it's so much easier for lawmakers to slap down a law that says "you must verify IDs right now if you want to continue to exist" with no requirement, and often not even support for, privacy preserving ways to make this happen. The laws are happening now. The chance of reform to align with a privacy-preserving option once the laws are implemented is slim to none.
- intrasight 2mo agoAnd obviously we must push back strongly against laws that do not accomplish any collective benefit. I think the only law that makes sense is to say that at some future date hardware will be required to have age attestation.
- csnover 2mo ago> Finally, anonymity didn't exist for my grandparents. Your grandparents could walk to the next town over and give themselves a different name and nobody would ever know who they were. They could get a job, be paid in cash, and deposit that money in a bank account with no KYC. They could drop a letter in a public mailbox without a return address, or put up posters at night, or make phone calls from public telephones. Nobody would know who did it, and there would be no surveillance footage to review after the fact, no digital footprint to trace. They could write a letter to their local newspaper to be printed with a fake name, or publish a book or story or magazine under an assumed identity. There were no ALPRs, no automated facial recognition, no built-in vehicle telematics, no drones, no smartphones to track anyone’s movement, no doorbell cameras on every block, no video tapes, no serial numbers hidden in the printouts from copy machines, no DNA analysis, no databases instantly searchable with the click of a button. Feel free to make a value judgement about whether what we have now is better or worse than the past, if you want, but don’t invent history to rationalise it. The internet did not invent anonymity. It used to be the default.
- Tangurena2 2mo agoThis sounds like an implementation of The Right to Read: https://dl.acm.org/doi/10.1145/253671.253726 https://dl.acm.org/doi/10.1145/253671.253726 https://www.gutenberg.org/files/1981/1981-h/1981-h.htm https://www.gutenberg.org/files/1981/1981-h/1981-h.htm That essay seemed unrealistic and dystopic when it was originally written. Now it seems like the typical T&C of every e-reader. If facial recognition was anything other than a PhD type project at that time, that would have prevented the main plot of the essay.