I'm fundamentally opposed to age verification because it usually leads to mandatory account creation no matter how privacy friendly the age verification process itself may be. It's already extremely annoying that, for example, on YouTube, you can no longer watch many videos without an account. Furthermore, the whole thing also reinforces monopolies. Once you've verified your age on one platform, the barrier to switching to another is even higher than before.
The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating. Once this were established, websites targeting all age groups would have a strong incentive to participate. Otherwise, they would suddenly become invisible to a large portion of their underage users.
And instead of an age you could even make the indication about what is potentially objectionable so that parents can choose when to allow their kids to see what - and adults can also choose to avoid certain things.
The part I'm most opposed to is requiring a full KYC with verifying an age as an excuse. My Gmail account has been active for >18 years, that should be enough proof.
It won’t because KYC is a legal process and you don’t want to prophets that across the entire system with bypasses for it. That’s legal trouble waiting to happen.
Yes, Google also wants to tie back to legal identities to sell ads. I’m not saying they’re doing this in good faith, but proxies like this get messy and dangerous for legal/compliance.
At glance this looks reasonable but how do you enforce that kids connection always goes through the parents control?
You are just moving the verification point to another gate, it means that no anonymous connections are possible anymore to the entire Internet because we want to allow parents to control their kids.
You want to use your friends Wi-Fi? Now that requires full identification so that we know that its not some kid trying to look at stuff their parents don't allow.
Want to connect your cat toilet to the internet? Well, we will need to either cryptographically identify the device or attach its ID to your real ID because we don't want to allow kids look at stuff their parents did not allow and this might just be a proxy device for some nerdy 14 y/o.
Want to use your old PC? Sorry that's not possible, now all devices that connect to the internet require biometric identification because we can't tell if this is an adult or just some kid using a legacy device to look at stuff their parents don't allow.
The answer is quite simple. You just don't verify it. The point isn’t to verify the age but to set the age on the device itself. If the parents set the age on the cell phone or computer, that setting is then used as the basis. The operating systems can be configured so that only the device administrator can change the age. Systemd already has a field for storing the age, which programs can read. If the child doesn’t know the root password for the laptop, they can’t change the age. If they do manage to get around that, well, so be it. The solution doesn’t have to be perfect because it would still be an improvement over the current situation without restricting adults in any way.
I have personally used the parental controls on Android, iOS and ChromeOS and to be honest they are terrible. Issues with syncing changes, the terrible UX for parental access control (iOS...), issues around audit/access logs, issues around prompting the parent for access.
I am honestly shocked that Apple known for its polished experience hasn't been forced by angry parents.
My daughter's school actually advised parents to not enable parental controls on her ChromeBook because it would interfere with the school's education websites but my daughter was caught playing web games in class so we decided to lock her down anyways.
> my daughter was caught playing web games in class
Hilarious to me. The biggest game of whack-a-mole ever. I would love to know if this lockdown was successful (and if so, how it worked).
In my city, there is a district that is so “locked down” that the images from Wikipedia don’t even load. But guess what? Kids still find ways to play games.
If you only care about individual individuals, fine be that way.
If you care about the massive impact on society, and you have a shred of a soul or empathy, which I’m sure you don’t, you’d recognize the need for systemic support and better mechanisms in this area
Parental controls on devices are not hard because they are intrinsically hard. The companies just do not care about them, because nobody has forced them to be implemented sensibly. There is absolutely zero reason an Android device could not have a shiny button saying "Kid's device" when you set it up and never need configuring again. So this is not a criticism of the approach, and only a criticism of the companies.
No, the point was that the actual decision happens client side and under the control of the sysadmin (the parent).
> You are just moving the verification point to another gate
Yeah, the gate being the decision of legal entities of age, aka. adults.
> You want to use your friends, Wi-Fi?
That would still do whatever your parent decided for you.
> Want to connect your can toilet to the internet?
Whether the toilet can connect to the network, is the decision of the network administrator, and toilets don't contain UAs, so that wouldn't even have software on them, where you could configure such behaviour.
You're making the mistake of assuming that every kid has access to identified device and that device is under parent control. You can't make this assumption because that's not true.
It might be true for some middle class helicopter parents that have iPhones and time to manage and keep it under strict control but there are non-middle class kids out there who just use whatever device they can get their hands on and their parens neither have time nor ability to control that.
In real life, it doesn't work like this for most people. In real life, kids want something and either the parents agree to buy that and then they no longer bother with that device or the kid saves its money trades something and get that device.
The idea that a kid gets an expensive device that can't buy by itself and the parents have control or what device the kid gets is a very middle-class assumption. Life isn't that perfect for most people.
Walmart has sold android smartphones of okay functionality that poor people depend on for decades.
Like, less than $100. Nowadays they have $20 ones that are locked to pay as you go monthly purchases, which is definitely worse than the old tracfone days but about the same price if you had to top up every month anyway. That's ignoring used phones.
That's not parents issue. That's why we go after people who sell or give drugs to kids. Is a serious offense, we don't wave our hands and say its parents problem and not drugging kids is a popular policy unlike drug enforcement for adults.
Yeah, but that assumes, that there are people out there, selling smartphones to children at scale. First the price for one is way to large for the financial budget of a child, and second that gets even more price-intensive, after the first one got confiscated by the parent.
There are literally people out there selling smartphones to children at scale. A smartphone these days can be bought for as cheap as a burger because 2nd hand market exist and its not limited to iPhones.
And the child can also go and buy a porn magazin, which is likely to be eventually found by the parent, just like the burner phone you suggest. The former is also going to be cheaper.
If you are depending on the police to keep your kid from doing drugs, you have failed as a parent. I promise you, your kid can locate drugs better than the cops can arrest low level dealers.
You as a parent need to teach your kid how to behave (mostly through things like teaching ethics and morals) not by running a safe prison until your kid is 18.
I agree, however the problem is that large number of parents can't do that and it becomes a societal issue. That's why we are talking about that, otherwise it would have been private family issue.
Drugs, alcohol, teen pregnancy and now social media has become societal issue as enough parents failed to control their kids actions or development.
So sure, we go after anybody who gives or sells devices without basic parental controls directly to kids. So you need to be 18 to buy a phone, which we're 90% of the way to anyway with the way credit cards work.
The fundamental point is that the Internet is not a daycare. All of these attempts to put the burden on sites boil down to changing this dynamic, recasting the Internet as if it should be appropriate to use as a daycare. Today it's big tech and porn. Tomorrow it's any writing that the the religious reich dislikes. Monday it's technical sites as they can help kids bypass restrictions. Tuesday it's international sites being blocked at the ISP-level because they don't bother with any of this crap.
We also need to remember the context here, lest we carry water for big tech's continued abuse. The main reason the surveillance industry is reaching for age verification (ie identity verification) is that harm to children is so far the only regulatory cause of action that has been found to stick. Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information. Where what we actually need is to stop their abuse for adults as well - eg data privacy, anti-trust regulation to open up their services to competing clients, and at this point probably straight up regulation of purposely-addictive "algorithmic" feeds.
> Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information.
I've said before and I'll say again that this approach (strict age gating) also is going to produce a slew of really vulnerable 18 year olds. If I were a sports gambling site, I'd be salivating at getting a fresh crop of 18 year old boys each year who have had zero opportunity to learn how to navigate the Internet and who are legally on the hook for everything they do.
OnlyFans, likewise, is going to work out great! Now the 17 year old girls turning 18 won't have access to things like the social media of former OF performers or access to any communities where sex workers discuss the downsides of their job or how to stay safe.
Have to protect the children, don't you know. That way they can be perfectly pure and innocent when they turn 18 and are ready to be exploited. Like fattening up cattle.
Yes! And this dovetails into a point I really should have made as well. The thing about "age verification" (ie identity verification) is that it puts the decision of what kids should access wholly in the hands of corporate attorneys. For example we can easily imagine a "Facebook4Kidz" website that has many of the same terrible dynamics as regular Faceboot, but that Faceboot's attorneys can justify as being legally compliant. As a parent, you would really want to block this too - while all of these proposals for identity verification and site-based-control claim to solve the problem but leave you with no way to do that!
This ties into your comment because as a kid approaches adulthood, as a parent you also want to loosen those restrictions so that they can develop these skills - gradually while under your supervision. Whereas the corporate attorneys will just say that they're strictly off limits, right up until it's then open season as you're pointing out.
And you want them to learn in a situation where the stakes are lower: at 18, someone can put themselves into a ton of debt or put nudes in the wrong place and just nuke their life in a way that they can't fix for a decade and everyone shrugs and is like 'you're a grown up!'
Think of all the kids who back in the day got scammed out of their Neopoints, or lost all of their in game currency in GTA, etc. That's a way, way better way to learn about account security and who to trust than their first experience with scammers involving real money.
Is the problem that we're exploiting kids, or is the problem that we're exploiting people? We're not going to be able to protect kids from exploitation in a society/culture that explicitly condones exploitation. If we think exploiting people is fine, actually, as long as they're over 18, then your kids will never be safe, because they will grow up.
Even setting aside the obvious examples I listed, binge drinking used to be a huge problem amongst college aged kids. Who's to say that the Internet/social media wouldn't be similar? How many kids are going to flunk out of school because they can't stop watching digital crack and now mom and dad aren't around to stop them? And unlike binge drinking, your body won't eventually revolt against you, and with the addiction consultants The Machine employs, there will always be new content. People grow out of binge drinking because eventually it grows stale and hangovers when you're 35 are far worse than ones when you're 21, but that's not true of social media use.
To tie this to other issues, we're already seeing issues with relationship and family formation amongst young people. I'm not sure flash banging them with addictive content when they're in their prime years is the call. If all it took for the Internet to be healthy was holding off until adulthood, we'd expect people who were adults when they started to have a healthy relationship with social media. They very much do not.
I wonder if it would work to make it illegal to sell ad impressions of underage people. Do whatever you want as long as you can prove its being done to adults, or prove you have no economic incentive to algorithmically engagement bait
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
I'm afraid you'd get the cookie banner problem but way worse. Everyone that's not Meta/Google/Apple would immediately add a legal CYA "18+" age rating and stop thinking any more about it.
That's how it should be. Make the Internet 18+ by default and sites targeted at younger audiences can add a more detailed rating. Let people configure their devices however they like it.
The whole problem with the regulation we have right now is that it assumes the Internet is for kids, and everything for adults must be hidden. When we really just should declare the whole Internet as 18+ and the sites for kids should be the specially marked exceptions.
So kids shouldn’t have access to sites like Wikipedia? Banning the internet is not the correct solution many kids depend on the internet to have access to education.
The argument could be made for banning social media but the whole internet I don’t think it’s the correct approach
I never thought about that and I find it might actually be the right way for a solution... I was just looking into the Google Play Store now: in Brazil apps need to have an age rating, facebook and instagram for example are 16+, but browsers like firefox, chrome, etc are rated for 'all ages', even though you can access the whole internet through them. If we actually did what you said and inverted the logic: restrict everything to 18+ and specifically mark what is allowed to under-18s it would make parental controls much more effective.
Someone would complain that without ID verification kids would be able to sneak onto the regular Internet and therefore we should eliminate privacy on the regular Internet, just like they're doing now.
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
Agreed, just make age controls available to parents, optional, and keep the user age data on the local device. External hosts can verify against it in obvious ways. But isn't that what California's law said, that commenters on HN opposed so strongly?
Many years ago I worked a technical support job for Xbox services, and the amount of calls about "unauthorized charges" was obscene. Xbox provided parental controls, but it required the parent to set up their child's account themselves, and many couldn't be bothered.
And people give their children cigarettes and liquor, that's bad as well. But that's the responsibility of being an adult. If the adult is deemed not worthy of raising children, society has already established a process of dealing with that too.
> for example, on YouTube, you can no longer watch many videos without an account.
I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?
IMHO, they should have Youtube 18+ (Adult book store) where you need an ID and YouTube <18 where you do not (Barnes and Nobles), and they can filter the content as apporpriate.
I think it is evil that YouTube enables kids access to both grooming and violent material.
The problem is that digital IDs get recorded. The physical examples you give are generally not. The clerk at the ticket counter or entrance doesn't give a shit who you are, they just need the picture to match you and the DOB to 18+ years ago. If you're old enough, they dont even card you.
> I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?
I don't like this one either. Does the cinema store the ID (or information extracted from said ID) of every single user visiting, along with what they've watched, on electronic records that can and will eventually be breached? Do they ask a third party (like Persona) for said verification providing the user's information?
On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.
> On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.
This is something that can be done online as well. Capitalism is controllable.
Companies have show that they are incapable or unwilling to address the problems they cause. And market forces are not working to correct things. It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.
This is where regulation is supposed to come in.
At the same time, companies have shown that they will abuse any personal information that is shared with them and we are now giving them more details about ourselves…
I don't want the market solving this. If we are going to do age checks it should be based on public key cryptography, be open source, and handled by the government. You verify with the government (or don't since they already know your age), you get some form of cryptographic attestation, present said attestation to websites/apps.
I'm not a fan of age verification in the first place, but I am extremely not a fan of random third parties doing the verifying.
The number of people who are marginalised is... marginal. By definition it doesn't have a sensible impact on profit. That's precisely why it is a problem to be marginalised.
Even literal regulated electricity utilities aren’t expected to provide service to every last marginal customer.
For example, a poor old grandma missing many electricity bill payments usually will see leniency if she is polite, the utility eventually won’t try to collect cash anymore and instead put a lien on the home while continuing to provide service.
But if the billing department receives multiple threats from her, then they may just cut the service.
If you want to use a service that is age restricted either by law or the company providing it how else would you do it? It's the same IRL. I don't like it as well and we certainly lived through the wild wild west times in the 90s and 00s but the more something gets economical important the more scrutiny it gets. Maybe we just need something new.
Well these kind of laws are trying to legislate technology into existence; we don’t have a means to do it, yet “we demand for the technology to exist through ‘reasonable methods’, now get to work.”
If that’s the nearly infinite wiggle room we’re playing with then I’d say what about Adult and Child versions of phones? You have to flash your ID to the clerk to buy an adult one, like buying cigarettes at a gas station, and then you get to do what the internet offers. Child phones - let parents and governments come up with whatever they want to block. The phone autoupdates in the background with the blocklist, the device can’t do those things. There ya go. Each person and family gets to make their own choices and nobody has to give an ID card to PornHub or a company that literally exists to harvest your information. Win-win?
We already have a version of the child phone: it's parental supervision.
When I was a kid there was no TV in my bedroom nor a computer. Everything I watched or did online was on full display in the family room. What changed in the modern home where that's not the case? Are kids glued to their phones because their parents are too?
This is scary though too. If the gov managed a key server like this, almost all companies would start requiring it. But this effectively gives the gov a very easy way to lock you out of everything.
This is really nothing new and has always be the case
It's not possible to tech yourself out of a political problem.
So if there is something being done we should choose a solution that has at least some accountability to the general public (through elected representatives).
The alternative is Google, Apple etc where almost anyone has exactly zero influence and the government can still block as they like.
This will be possible if done by third parties anyway, it will just be apple, google and maybe meta, a single phone call is enough to cut you off.
At least if the government is doing it, the app doesn't get your id.
Either the app will get the id, you will be prevented from running arbitrary software on your device, or the whole thing will not work because it becomes trivial to sell your age verification tokens.
If it has to happen, this is exactly how it should. Please feel for those of us in the UK who are currently denied access to some pretty significant services unless we send our passport to a random third party.
You're seriously proposing letting governments decide which of their citizens are allowed unrestricted access to the internet?
Of all the 3rd parties who could be responsible for this, I trust the government the least.
But really the best solution here is no third party. The device owner (e.g. parents) should be responsible for setting the user's age when setting up the device. Anything that tries to take that responsibility away from parents and give it to a third party is necessarily going to be highly authoritarian; putting that third party in the role of parent for everyone, adults included.
>>Of all the 3rd parties who could be responsible for this, I trust the government the least.
Really? can you name any 3rd party you'd trust with this more than your own government?
Given that you know, the government already has all of this info on us. This isn't a choice between "the government doesn't know how old I am" and "the government has all the info on me". Governments usually already do. They have enough data already to issue such proof just by the virtue of us living in the country. Tax records, birth records, driving licences, council taxes, passport info, medical information - there's more than enough to give me a cryptographic certificate that says "yes, gambiting is definitely 18 years old" without me having to do anything. Compared to literally any third party that cannot do any of this, unless they buy my marketing cookies on the open market or something, or yes - I actually go out of my way to give them my passport/credit card/selfies etc.
It’s not really about the info but restricting access to people. Imagine they restrict access to social medial to people with different political opinions as the ruling party in the government
The whole idea is that the government gives you a cryptographic token that proves you are over 18, but that token can be used anywhere. They don't get to say what websites can look at it, because...how would they.
And, that public key of yours must be used only on given platforms. You want to participate on Facebook or Reddit, then you use that public key to prove who you are. Which platforms require verification is another issue.
But it should still be legal and allowed to access conventional forums, Usenet , tor accessible discord servers without having to prove who you are.
Otherwise , the right to organize is over and we effectively live in an authoritarian regime .
Despite that fun trope, in reality democratic government reguarly delivers very well: Traffic safety systems work easily, dependably, economically. The Internet was developed by the government, the web at a government-funded research institution. NASA is the most cutting edge, most adventurous organization in the history of humanity. The US military created GPS for example, and has more globalized operations than any other organization has ever imagined, and from the bottom of the sea to GEO. Diseases are managed and contained, etc.
(Now if the people want to tear apart government, democracy delivers that too.)
The difference here is that in a functioning democracy people have some control over their government. All the institutions are specifically built to be transparent and work for the public good, at least, in some sense of the word. A corporation, especially a monopoly doesn't care what you think, you have no control over it and the only thing that really matters to them is their bottom line. Are governments perfect? Of course not. Are random corpos better? Again, of course not.
I want the market solving this but I don’t want to give any information to anyone who asks. I want Apple to verify me once, and then others to trust Apple that the device accessing their service is owned by someone over 18.
I’ll bet that most people are in the same boat - they trust their device manufacturer with information like their credit card number, but not anyone else.
>It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.
Then who should? Government, where each implementation strips away rights to privacy - which in some countries, including mine, are a constitutional right? Where it expands powers of government to track everyone's activity online - and remember we're one election away from total policy shift(just like with latest US elections)?
Free market? The profitable solution is, depending on environment - either ignore the problem(profit from ads served to children, no extra work necessary), or strip away all privacy (to filter out bots and get paid more per ad).
The sad reality is that "parent should take responsibility" is least bad option available, and takes into the account individual development of a child.
Even creation of a highly regulated child only internet creates more problems - as now that becomes a highly profitable target for bad actors(both individual abusers, and companies trying to serve ads)
In principle, it is possible to make a privacy-preserving age check.
Site/app asks "≥18?", device generates a UUID specifically for that [app/domain + device], the device passes that UUID to government database along with the "≥18?" question and the ID card info but not the app/domain, government database gives the answer and signs just the UUID and the answer and doesn't include any ID card info.
Government doesn't know what you're looking at, website doesn't know your ID.
(There's probably also better ways to do all this, I'm not a cryptographer and I expect that will be obvious from this comment to people who are).
In reality, the ones making such check will want extra capabilities 'just in case' as we observe now, or just go for simpler solution because it's cheaper.
How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.
It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.
Even in countries in which this requires a subpoena, agencies break the law frequently and don't get punished.
Legal systems aren't computer systems. This isn't a technical problem but a social/political one.
> How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.
True, but as this problem exists without any ID at all*, I don't see how the addition of the ID cards makes any difference?
> It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.
This is why I specified a "UUID specifically for that [app/domain + device]". Can't aggregate when each app/domain gets a different signed UUID.
> Legal systems aren't computer systems. This isn't a technical problem but a social/political one.
While true, the reverse also applies: computer systems are not legal systems.
I think many lawmakers' ignorance of this is to the detriment of everyone.
In this case, the social/political problem is: we want to stop kids accessing age-inappropriate material.
The options-space for doing this appears to be:
(0) give up
(1) require parents to limit their kids' behaviour (to which I say: "Have you met a kid? Do you remember being one?")
(2) require websites to age-rank appropriately (to which I say in a sarcastic tone of voice: "Gee, that worked soooooo well for GDPR")
(3) require operating systems to intermediate. Will this suck? Yes. Will it be buggy? Also yes. Will there be false positives and false negatives? Yes to both. Will it be a constant fight as kids keep finding loopholes? Indeed.
But you know what else? All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out. A school full of kids can beat their parents at the security game because they have more time to spend on finding exploits than the parents have to spend keeping up, the reverse is true of the difference between kids and Google LLC etc.
It doesn't need to be perfect, the kids aren't a computer program.
What does need to be held to a high standard is making sure the OSes don't leak all over the place.
> What would be the incentive for meta to deploy that against their own self interests?
The normal method is passing laws. That's kinda the point of laws.
Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.
> Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…
Hardly. This is more like gardening. It matters much less if kids get a few days of messing around where they're not ment to be, than if it's continuous.
And ultimately, if you want to run a business without spending money on legally required actions, you're in the wrong business, nobody should shed tears for you.
> Government doesn't know what you're looking at, website doesn't know your ID.
But then the government knows your location at any point of time and how often you use websites requiring the age check. Also, if your device is configured to do it automatically, a child can also follow this verification.
> But then the government knows your location at any point of time and how often you use websites requiring the age check.
Not as described. There's no location info in that path, and the signed statement of that UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.
(Should I consider expiry? It's not like people age backwards?)
> Also, if your device is configured to do it automatically, a child can also follow this verification.
Yes, if that device has been associated with a government ID and also the government ID signing process fails to make use the things we've already got on-device like how my phone reads my fingerprint to know I'm me and can store copies of some forms of government ID (in some places but not where I live, Apple Wallet apparently only supports some US states, Japan, Greece, and UAE).
> So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?
How? Phones are already locked down pretty hard. Anything like this would need to be in something secured at the OS level just to stop signatures getting leaked between apps.
If you're thinking "kid roots device, replaces OS entirely", that's not the problem of the manufacturer of the OS that just got deleted.
The EU actually has a very good, privacy protecting way of doing this based on zero knowledge proofs.
Unfortunately they completely botched it by having the proof-of-concept app rely on Apple & Googles integrity APIs - which a bunch of countries copied.
ZKPs may as well just be unencrypted HTTP headers which would be way simpler and easier to implement. All a ZKP proves is that at least one person in the world is over 18.
With ZKP, if you make a business out of reselling tokens you get with your own identity, eventually they will see that you use orders of magnitude more tokens than normal people.
So with ZKP it's more difficult to cheat. Not impossible, just less accessible.
Of course they are. The whole point of ZKP is that whoever gives you the token cannot link it to your identity. So you can get a token with your own identity and sell it to someone else, and nobody will know...
... unless you get thousands of tokens every day and sell them on a website, where suddenly you start leaking information about yourself everywhere. ZKP still did its job: it's not the tokens that link to your identity, it's your behaviour.
Each individual proof is zero knowledge, but downloading a _bunch_ of them is an indicator, yes. There's no real way to work around this with the current ZKP scheme. I'd argue ZKP is, in theory, the least worse option of all current age verification scheme.
My personal opinion is that age verification itself is a bad idea, but if we're going to go ahead with it, I'd much rather we use ZKP for it than the current mess of "upload your passport and picture of yourself to dodgy 3rd parties that likely now have your browsing traffic associated with your real name"...
Not necessarily, but it would be difficult to justify why you need to access 1000 porn sites every day, I guess?
The point is that if you build a service that sells age verification tokens, you are doing something illegal. And if you start doing something illegal by gathering said tokens with your own identity, maybe it's not the most clever way to do something illegal?
I have a feeling that, in order to protect privacy, those regulations must fall on the parents too. It is their primary responsibility to take care of their children. Maintaining your kids digital hygiene should be important to the lawmakers and the child protections services.
Who? The lawmakers? I believe banning children up to a certain age from having Internet-enabled mobile devices is a good starting point, and both child protection services and law enforcement services should fully cooperate with parents in enforcing that ban. If you see a kid smoking a cigarette or taking drugs, you know parents have failed somewhere along the road and it would be preferable if the government could step in to help.
This is a reasonable perspective, but don't you think the internet has the potential to do good as well as evil? I remember seeing some interactive lever applet as a kid where you could move the fulcrum. (Slightly) educational stuff. Shouldn't that be allowed?
There are any number of alternatives, I favor a walled off whitelisted subset of the internet that requires age verification and then we can let kids on that and otherwise ban them from the general internet and also ban internet enabled devices in general. However, this costs and undoubtably wouldn't be perfect as there are people out there who want to chat up your kids, look at how much work a roblox style site needs to do against internet users who probably shouldn't be chatting up kids.
For those precocious kids who parents decide should be the exception because they are "good with computers" well I'm thinking some sort of waiver would be required that held the parents responsible then maybe let the kid hack on the internet but this is an unpopular view, the unpopular part being the "parents being responsible for their kids" bit.
But in general I think its a tough time to be legislating this stuff because "reasonable perspectives" are not what we are voting into office right now lol
Educational content was already a thing well before the internet got everywhere.
When I was in primary school, one of the things teachers had us do was debate the pros- and cons- of television. The pro side included educational content.
First Windows PC at any of my schools had Encarta.
Wikipedia can be downloaded in entirety and read offline, though it is so broad it may need a degree of filtering to become age-appropriate even for 16 year olds.
I have a feeling that, currently, the cons outweigh the pros. Maybe if the digital landscape changes in the future, then we can reconsider those limitations. So far, the mobile Internet - the apps mainly - is a hostile environment for a young human, and I'd say they are pretty dangerous to the adults too.
This is reasonable up to the point of lawmakers suddenly deeming rainbow flags just as bad as drugs (Russia as an example).
Your example may work in well intended countries but completely ignores that a country can VERY easily shift into a regime that does not have good ethics abusing these kinda laws.
Children here are a distraction. Any harm these companies are causing to children is also being inflicted on adults. The correct solution is to end the harmful behavior for all, not set up required identity verification.
There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.
There should however be no force age verification. Social media companies already know how old you are or very close to it using the data they collect everyday. Using this data they should be required to use "best effort" to determine which algorithm you fall in. Nothing is 100% and we should stop pretending it is, sure some kids will find a way around but they would also if there is a age verification system.
> There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.
Frankly, in that case I want the kids algorithm. It is preferable for me as an adult, I do not want the intentionally harmful one either.
This. Just give me the option to have pagination. Sweet, old, pagination. Like here on Hacker News. I can then review one or maybe 2 pages, and that is all. Like a physical magazine where there's a clear end.
I have the firm belief that infinite scrolling is one of the darkest pattern that was ever invented.
Hang on... Hacker News very clearly has a complex, opaque [1] algorithm that orders stuff. Maybe it's not user-specific, and maybe that's a good dividing line, but these are the kinds of factors we're going to have to think about if we want to introduce regulation around 'algorithms'.
Infinite scrolling is a very different issue (although it's definitely a contributor to the harm, I agree).
([1] Unless I'm being unfair here; maybe the algorithm is available somewhere, I just don't see it obviously linked anywhere)
You can often do that via settings. But we could do with a law that makes it a crime to override a user setting that has been explicitly set, without notifying the user.
Oh but you enabled the setting "don't use infinite scroll" and we've deprecated infinite scroll so that isn't a setting anymore. While improving service for our customers we have introduced "unrolling pages" which prefetches the next page and attaches it to the end of the previous page to provide a smooth reading experience, and of course we've given that its own setting which you haven't set, and it defaults to enabled to provide the best seamless reading experience for most people.
Next we're thinking about spatial pages, an innovation which considers the app as a viewport flying over the pages laid out in a line. In consideration we have database-views which presents the unpaged tables of content in the database directly to the end user, completely bypassing outdated 'page' skeuomorphisms from the olden days of printers and books. Further out, our researchers are working on Shepherd Tone-inspired viewing, where technically legally it is paged, but it looks and feels like it isn't!
We have cars, and kids are not allowed to drive them. Yet we do not have mechanisms in place to ensure kids aren't driving cars because the responsibility falls on the parents, and it works. By and large, parents understand the threats and navigate this requirement perfectly fine; outliers are few enough that we can deal with them on an individual basis.
The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small. Personally, my vote is that they just don't think it's that big of a problem.
To me, the ideal solution would be more granular and better parental control configurations, especially on the web. Pair that with preconfigured devices that have "unremovable" parental controls, branded as "kids/youth phones." If parents care about this, they'll buy those phones for their kids and the problem is solved. If they don't, then this isn't something parents want, and we shouldn't really pursue it further.
> The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small.
Sometimes parents know their children, and what's best for them, better than faceless politicians (who we've seen are often attracted to said children for some reason).
Growing up in my household there was a time when I was allowed to read and watch whatever I found interesting. My younger brother was not. That was because my parents knew us and judged that at my level of maturity I was unlikely to be negatively impacted, whereas my brother would get nightmares or copy-cat things he saw that he definitely shouldn't.
That's how it should be. Yes, there are bad parents who will decide poorly. That's the cost of freedom.
> This is where regulation is supposed to come in.
Yes, agreed. However regulation does not necessarily have to mean age checks.
The most obvious low hanging fruit to start off with is open and interoperable content filtering infrastructure (ie parental controls) so that there's some common standard that literally everything supports out of the box. It needs to all work together - the current situation tends to be spotty and unreliable thus parents tend not to bother trying to use it.
Start with an extensible metadata format that enables websites to self-classify pages. Account for things like loading alternative resources on the same page. Mandate that all websites and app stores include such metadata and that all browsers and operating systems have some baseline functionality for making use of such data in a sensible manner.
Only after that has completely and utterly failed should we even begin to consider highly invasive measures such as mandating government ID checks.
I think you've done a great job identifying the three main options and why two of them (parents, censorship-by-default) just will not work. That leaves regulation; the only way we will prevent children—or anyone—from coming to harm is to stop companies from producing this harmful content in the first place.
100%, it's not like adults are immune to misinformation, social media addiction or scams. Those platforms should be safe for all people regardless of their age, nationality, sexual orientation, gender or religion.
> It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.
That's like saying "take a look at owners of fast sport cars, it's obvious this is not working and they have too many accidents." If you want to patronize other parents and think the government should be more responsible and parents less responsible, please state that honestly. Don't make up alleged "facts" to make a point.
Otherwise, I'll just say "it's obvious you're wrong, just observe the world around you and you know age verification is a non starter."
The parenting argument is a complete cop-out. There's no universe where you can be shoulder hovering 24/7. This could've been solved years ago with robust parental controls. But companies like Google just didn't want to because they wanted to shove ads in kids' faces.
I think we can approach this from more than one angle. Yes, it cannot be entirely on parents, but parents should bear some responsibility to not just hand a device over to their children with unrestricted access to the entire internet.
Up until relatively recently you would have to install custom VPNs and maybe add Pihole into the mix to achieve anything close to that. Easy for us here, but we're in a small minority.
Parental controls have been part of mobile devices for years, but so have bypasses. For instance, you can bypass Google's parental control settings by opening the help page in the Google settings and clicking links until you get to the Google homepage.
I doubt it matters because nobody seems to configure the parental controls that are there, anyway. Only schools seem to try, and only because they're legally held responsible for what kids do on their computers.
Parental controls are complicated and obscure, IME. Setting up a child to play Minecraft through Microsoft was like setting up a web server with firewalls and reverse proxy... only less sensible. I'd appreciate that is so they can get parents to set accounts as 'adult' so Microsoft can exploit them.
You can set up, for example a child friendly DNS (Family version of OpenDNS) then Firefox come along and bypass it (DoH).
Probably, we need an OS level setting, per account, browsers would need to expose it to websites, apps installed would have to check and provide content according to local legislation/rules. Bypasses would have to be performed by an "adult" account.
The main issue is that adults would be able to set themselves as children and avoid negative commercial activity. That's a problem because it means FANG, etc, will lobby against it and then ensure their implementations are convoluted and broken.
Parenting doesn't have to mean become a helicopter either. In fact, that's the worst kind of parenting because it doesn't prepare the kid for a future without a parent around.
Parents should take responsibility and not let their children smoke, and we still banned selling cigarets to children. Just because something should be some way, doesn't mean as a society we shouldn't do anything about it.
In any case, the story with parents and addictive devices is even harder for parents than e.g. cigarets. For example, a LOT of schools in the UK think that it's good to give childrens ipads to study, and there's nothing that parents can do to prevent this. In this specific situation saying that "parents should take responsibility" is unfair to parents, because their only option to avoid this is home schooling.
Well, the API itself seems fairly well designed from a privacy perspective. It only shares age ranges, not specific ages, and only if you allow it. The data is also fuzzed to prevent an app from determining your exact birth date, and it's all tied in to the parental control system.[1]
The problem remains though that, since the laws this feature was created to comply with put the onus on Google to verify the user's age and not on the device owner (e.g. the parents), the method they use to determine the user's age to feed into this API is terrible from both a privacy and freedom perspective: they force you to send them a copy of your government ID, and delete your account if you don't comply.[3]
The API is tied to a Google account though. You can't simply install an app on Android and have Android tell it what the user's age is, it has to first have google maps, youtube, play services, etc. installed and you need to make an account and log in globally on your device before it can tell the app an age. I don't know that I'd call that a good design for an Android API
I think it's the old that need to be protected more on the Internet since they disproportionately fall prey to online scams. So let's age-gate their access to online services too. If you are old and want to send money to someone, you get age-gating and second-factor authorization from a competent young person. If you want to watch porn online, believe it or not, age-gating and second-factor authorization.
Honestly, I wouldn't be opposed to that either. If we're protecting kids, we should also protect the old and feeble. Old people, people with developmental handicaps, you name it: they're being exposed to a world that can and will abuse you if you have any faith in humanity left and don't have the technical skills to identify things like fake domains and scam sites.
For some reason we're making sure no 12 year old can drive or run for any government positions, but a 90 year old can keep the driver's license that they've had since before the start of colour television, or make critical decisions affecting millions. We can't have it both ways.
I was just saying yesterday that we (Finland) could take the bullet and create a luxury resort for all the zillionaires in the world.
Connect them with each other and populate their air-gapped "Internet" with like-minded authoritarian AI-bots and create special news like Don and Vladimir are being fed to keep them from tantrums. A win win for everyone!
Ooh, and mental health services. Plenty of mental health services as we're so poor of a race that even our richest can't afford enough therapy to feel alright!
I doubt the purpose is even age verification. They already can know I have a visa card which is credit card that can be only applied by an adult by looking at the BIN. Why they need my id card if the purpose is actually age verification?
I think this is actually a reaction to the over-reaching laws various governments are enacting. This is the way it should work - parents check a box that says "the user is 13 years old", and then apps and websites can see what the parent set.
This is much much better than having to do face scans and credit checks etc. to prove to some sketchy third party that you are over 18.
I think if Google had bothered to do this 5 years ago we might not be in the shitty situation we are now, but it's probably too late now.
It's not like children can buy overpriced phones or tablets. You can force the stores to help setup up restrictions for their devices for parents that don't know how or want to. Then start doing massive fines and restrictions on websites or app stores that host unregulated apps.
If they can afford to buy them on their own, good for them.
You don't use age to decide what's appropriate; I don't mind if my kids see naked bodies. I do care if they see naked porn star bodies, and porn, although actual amateur porn with a range of body shapes is okay. Fighting is okay, but actual graphic bloody violence is less so (funkytown cartel video is no bueno).
I don't understand why apps need to know anything about a specific age. If we have to go down this road, which I really don't, why can't we just simply have verification whether or not an age fits within a range better yet a category. Yes, age can still be inferred, for example, under 21 or over 21.
> To request a user's age range and sharing status, you call the Play Age Signals API (beta) from your app at runtime. The default age ranges the API returns are 0-12, 13-15, 16-17, and 18+, but you can receive custom age ranges.
But I don't find it any better. I don't see any viable reason to provide identification to my phone's OS. If a parent buys a phone for their child, they can already set up parental controls before handing it over.
I wish Motorola all the best with their GrapheneOS partnership.
The rumored Motorola devices are even more expensive. It's the signature and some foldables, all in the 1000+ MSRP range. At least with pixels you can get the a series for as little as 400 on sale.
If you buy one of the Motorola Grapheneos phones, you're gonna be marked. You will stand out in the crowd. It has happened before and will happen more frequently as the world becomes more authoritarian.
On the other hand, privacy becomes a luxury. People love signaling their status and standing out from the crowd. Entire car and clothing brands exist solely because of that.
And if enough people stand out, it doesn't matter anymore.
If anything, I would imagine that Google's changes are motivated by driving traffic to their Google Play Store, where they make billions in commissions.
Once this framework is in place for the Google Play Store, perhaps they can lobby for strict age verification laws, and then tell developers who publish outside of Google Play that they are responsible for compliance themselves.
It's amazing how naive and gullible people are even after all the many thousands of examples of lies and gaslighting over many generations now. It seems to be a permanent characteristic of a certain subset of people, and seemingly a majority of people, at least in the west and at least in this era.
It always gives me the "he only beats me because he loves me" or "he wouldn't beat me if I knew how to behave better" vibes. It's not healthy, not sane, not rational.
One disagreement though; I don't even think they will lock people out of their devices outside of very narrow and specific instances or examples to "cut the grass" as the Israelis call it, to scare and remind people they are the slaves and the long arm of the tyranny can reach out and crush them if they don't self-censor and self-subjugate. Psychological and ideological control has very much proved itself far more effective than physical control in all circumstances. They want to be able to monitor and then use methods and technologies to control that have not really come to light in society even thought they were systematized through the Iraq war. You are now the "insurgents", are you old enough to remember those, those insurgents in their own country?
Laws have been written that mandate that applications and services treat various age ranges differently. You can't serve porn to kids, kids under 15/16 have very strict privacy regulations in some areas, and certain content age ratings are an industry standard only because that was the industry way of getting out of being regulated.
For kids this is a privacy risk because there are so many thresholds. Once you're above 18, all you need to care about is "are you a pensioner".
Kids have been lying about their age since the dawn of the internet and people have started catching on, so now we're getting actual restrictions rather than the assertion that nobody in their right mind would click "I am 18 or older" to access a website.
Californian law mandates that operating systems keep track of their users' age, so of course Android must follow. In all of the cases listed on Google's blog, though, the option to not share information and download an app that doesn't ask for your age range is still an option.
This isn't aimed at you specifically, but I think many technologists seem to innately misunderstand the slippery slope hypothesis which helps form the bedrock of American politics.
Too many seem to fall into the familiar problem-solving mode, ready to provide compromises or solutions while forgetting that once the infrastructure is in place, it can easily be modified later to undo the compromises which facilitated its acceptance in the first place. There is an inherent power asymmetry and it's not generally in favor of those building and using the infrastructure.
They also actively undermine the US constitution. Will be interesting to see whether the remaining judges have any power to change this or whether they were also integrated into the new dictatorship model.
They want to track everyone now. Age sniffing is just one additional step for forcing verification. This will continue - see how suspiciously many countries adopt new legislation. It is quite fascinating to me to see how easy it is to kill off democracies.
Doesn't seem like most of the people on this thread actually read what they're planning.
It seems like a very good solution to me. It gives parents a simple solution to define the age of the phones user and a mechanism to allow apps to get an age range and tailor usage appropriately.
It does all this while leaving everyone else undisturbed.
Put the age range into http headers and you solve children accessing content via the web as well.
What a pain reading this blog post. It's about them complying with recent regulations, but they never mention it once: they word it so it sounds like they are doing this out of the good of their hearts.
The words "law," "regulation," or "compliance" do not appear once, despite being the entire reason the post exists.
Also on the "privacy-preserving tool", technically apps get a bracket ("16–17") instead of a birthdate. But who holds the actual data? Google. The privacy improvement is against the developer only.
Seriously ready to fully drop google emails and services, i'm using vivaldi + personal email for a while now, the migration was slow a bit painful but complete.
Only the phone is still attached to play store and google, but i'm 100% ready to switch to the fully supported Chinese variant of ColorOS and flush Google into the toilet once and for all. But my next phone will 100% be a Sailfish again.
For me to fully drop google someone needs to create something compatible with Android Auto in my car, it doesn't sound like a big deal but that's a big enough thing for me to need it now.
I think also something needs to be done to the companies that we know are targeting teens and children with tactics for addiction. Meta was found to have engaged in such tactics and nothing really happened to them
I'd be totally fine to solve this problem by banning children from the internet altogether. Not that I'd enforce this or anything. Just so no one other than the parents can be liable when things go wrong.
There's more and more evidence that internet access isn't healthy to have for children anyway.
But we don't put barbed wire on random sidewalks and then blame parents if a kid walks over it and gets hurt. There is the attractive nuisance doctrine, among other things.
We don't leave the barbed wire on the side walk but require everyone that wants to walk on it to age verify first either. And the attractive nuisance doctrine some states have is absolutely bonkers.
>Viewing the continuance of our race as only the responsibility of parents is pathological.
That seems to be a uniquely American pathology.
Everywhere where else in the world, and in non-white American subcultures, the community taking a hand in raising children is expected. But many Americans seem to consider it socialist and an attack on Christian values.
See Hillary Clinton getting mocked for saying "it takes a village"[0] or BLM being accused of wanting to "destroy the nuclear family" by encouraging community based parenting[1].
You have a kid, you have responsibility for that kid. In Germany we have a term "Aufsichtspflicht" for this, which roughly translates to duty of supervision. Up to a certain age of the kid parents will be made responsible for damages your kid caused.
One pretty funny example of that was a kid spending 1000s of Euros on a MMORPG because the MMO offered a payment option that allowed people to pay through their phone bill. Parents could've easily prevented any of that happening, but in that generation it was pretty common that kids were tech savvy while parents couldn't be bothered to learn about computers, which imo already is problematic.
Nowadays there are many many ways to supervise your children's online access. And yes, there are also many many ways for kids to work around that too, but ultimately if you buy your kid a device with internet access, you should try to supervise that. Parents need to care more about what their children are up to, instead of silencing them with a tablet for a moment of personal silence.
A small example would be to set the device into "kiosk mode" which many companies use for their employee devices too. Prevent app installs, check what pages ur kids visit with their browsers and whatnot. Just make sure to be open about it so you don't hurt your kids by violating their privacy and trust towards you. Hell we even got parents having their kids take air tags with them so the parents know where they are.
This is actually a step in the right direction. I don't want to share my id and selfie with every stupid social media app/site. I would much rather allow parents to configure their children's devices to share their age.
Just like every new Android "feature", the first thing that comes to mind when reading this is how will it work if you aren't logged in to Google on your phone. Am I supposed to give up and pretend it's normal to have to log in to an online account to use a personal computer?
A question to the crypto nerds here - is there a way to prove that you are of age, but you can't be deanonymized even if the government, identity provider and the website itself collaborate to do it?
By the way, this also explains one reason why Google shut down third
party access/applications recently on Android. Android (if one uses
the Google software) becomes the ultimate spy tool on people. At the
same time you see several countries force age sniffing on people -
this is the beginning of the end of the free web. It will happen in
various steps; the next one is Microsoft adding this to their software.
Linux is also ready to support age verification through systemd. Luckily, there are still distros without it, like Void Linux. I switched to it recently and now my media PC boots faster than my TV takes to turn on.
I couldn’t care less about children or about what is ultimately a parenting issue (keep your fucking kids off the internet). A problem that affects a subset of the population is not something that should be solved by subjecting the entire population to inconvenience. Just make it illegal to use the internet for under 18s or under 16s or whatever and let it be assumed that all users are of the appropriate age.
If I a child is on the internet without adult supervision, that’s a parenting problem, not an issue for the state or other people to solve.
This smells like Soviet Union. The next step will be a requirement to confirm your identity - trying to justify it with a wicked manipulation tactic "we need to know your are not lying when selecting your age". No one asked for it to begin with. Android is normalising totalitarianism and mass spying on citizens, one step at a time. This is a very bad feature and a very bad development.
Its the same thing with Europe allowing scans of private chats now. Nobody would tolerate a person opening the letters from ur physical mail box and reading through each of them just to see if you do [insert illegal activity]. But once this stuff happens digitally, people seem to simply tolerate it.
If I remember correctly, in 2019 there were huge protests against upload filters were people actually protested on the streets in Europe. Now there is almost NOTHING for chat scans, NOTHING for age verifications, NOTHING for making Android less open. Its really frightening what the general public tolerates nowadays.
The authorities open letters all the time. Try sending a letter to prison without it getting scanned.
The problem with this comparison is that the authorities can open a letter if they need to for various well-intended reasons, but they cannot open an encrypted message. Either the authorities can scan all messages, or they can scan no messages, there's no inbetween.
The mandate to verify age before selling alcohol has been around forever. This is not a new idea. The biggest restriction until now has been that there was no good way to do these kinds of age verification, but that problem has been solved. You can still debate whether or not age verification is a good idea for specific subjects, but selling 10 year olds alcohol or porn has been illegal for much longer than the internet has existed.
It would make for a good alternative, but so would any app that doesn't implement scanning. If they can force Signal to implement client-side scanning or ban it entirely, they can do the same to PGP software. In theory you could do RSA by hand, but it would require a lot of hard work.
Last time I checked an Android phone was not selling me alcohol or porn. It requires specific deliberate actions to get access to anything like this with a phone. Any checks could be justified on the store or web-site level, not on the phone level. Treating every citizen as a child or even worse a potential criminal who needs to be constantly checked at numerous checkpoints the state so kindly put everywhere is exactly the stinking smells of the Soviet Union I'm talking about.
I think you're misinformed, they didn't have age checks on smartphones in Soviet Union.
But there're countries where that already exists. They usually get labelled as a threat to democracy. Isn't it ironic? It's as if our own governments are the greatest threat to our way of life.
Age checks are inevitable sadly. No one would tolerate “adult” services and goods rendered directly to children without age check.
The main argument is that there is an assumption this data is not stored in the real world, which is only sometimes true. Some places like airports and some concerts, shows, bars, etc. scan identification with digital readers whose data is presumably retained. One reason for this is because fake identification is a thing so defense against this converges to the same solution as digital verification.
Imo best to spend energy thinking of the appropriate solution that minimizes privacy violation than conceptual fighting against the idea.
We could settle on a privacy-preserving idea, like physical cards with single-use codes sold in stores after showing ID, similar to alcohol. Then a few years later they would ban cash payments for those. Then require sellers/payment operators to report all transactions to a central registry. The slope has always been slippery.
If you don't even try to use simple available measures to prevent your own child from vaping then it's unfair to say you have zero tolerance for children vaping.
Did you mean "plenty of parents wouldn't tolerate “adult” services and goods rendered directly to children" when you said "No one would tolerate “adult” services and goods rendered directly to children"?
I'm fundamentally opposed to age verification because it usually leads to mandatory account creation no matter how privacy friendly the age verification process itself may be. It's already extremely annoying that, for example, on YouTube, you can no longer watch many videos without an account. Furthermore, the whole thing also reinforces monopolies. Once you've verified your age on one platform, the barrier to switching to another is even higher than before.
The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating. Once this were established, websites targeting all age groups would have a strong incentive to participate. Otherwise, they would suddenly become invisible to a large portion of their underage users.
And instead of an age you could even make the indication about what is potentially objectionable so that parents can choose when to allow their kids to see what - and adults can also choose to avoid certain things.
Exactly, without this you’re handing the power to decide what is “appropriate” to someone else.
Force a PEGI-like system for every apps please.
It would be awesome.
The part I'm most opposed to is requiring a full KYC with verifying an age as an excuse. My Gmail account has been active for >18 years, that should be enough proof.
… but how many people really believe that will happen?
Fight together with everyone else, or when stage 2 (“full KYC”) is implemented you won’t have any leverage.
It won’t because KYC is a legal process and you don’t want to prophets that across the entire system with bypasses for it. That’s legal trouble waiting to happen.
Yes, Google also wants to tie back to legal identities to sell ads. I’m not saying they’re doing this in good faith, but proxies like this get messy and dangerous for legal/compliance.
>YouTube, you can no longer watch many videos without an account.
What YouTube video can I not watch via yt-dlp without an account?
Anything age-restricted.
FreeTube can.
At glance this looks reasonable but how do you enforce that kids connection always goes through the parents control?
You are just moving the verification point to another gate, it means that no anonymous connections are possible anymore to the entire Internet because we want to allow parents to control their kids.
You want to use your friends Wi-Fi? Now that requires full identification so that we know that its not some kid trying to look at stuff their parents don't allow.
Want to connect your cat toilet to the internet? Well, we will need to either cryptographically identify the device or attach its ID to your real ID because we don't want to allow kids look at stuff their parents did not allow and this might just be a proxy device for some nerdy 14 y/o.
Want to use your old PC? Sorry that's not possible, now all devices that connect to the internet require biometric identification because we can't tell if this is an adult or just some kid using a legacy device to look at stuff their parents don't allow.
The answer is quite simple. You just don't verify it. The point isn’t to verify the age but to set the age on the device itself. If the parents set the age on the cell phone or computer, that setting is then used as the basis. The operating systems can be configured so that only the device administrator can change the age. Systemd already has a field for storing the age, which programs can read. If the child doesn’t know the root password for the laptop, they can’t change the age. If they do manage to get around that, well, so be it. The solution doesn’t have to be perfect because it would still be an improvement over the current situation without restricting adults in any way.
Are you a parent?
I have personally used the parental controls on Android, iOS and ChromeOS and to be honest they are terrible. Issues with syncing changes, the terrible UX for parental access control (iOS...), issues around audit/access logs, issues around prompting the parent for access.
I am honestly shocked that Apple known for its polished experience hasn't been forced by angry parents.
My daughter's school actually advised parents to not enable parental controls on her ChromeBook because it would interfere with the school's education websites but my daughter was caught playing web games in class so we decided to lock her down anyways.
> my daughter was caught playing web games in class
Hilarious to me. The biggest game of whack-a-mole ever. I would love to know if this lockdown was successful (and if so, how it worked).
In my city, there is a district that is so “locked down” that the images from Wikipedia don’t even load. But guess what? Kids still find ways to play games.
This is the improved iOS parental controls. When they shipped it (and for years afterward) it simply did not work https://www.wsj.com/tech/personal-tech/apples-parental-contr...
It really is surprising given Apple's reputation for UX and safety.
Being parent is not supposed to be easy
If you only care about individual individuals, fine be that way.
If you care about the massive impact on society, and you have a shred of a soul or empathy, which I’m sure you don’t, you’d recognize the need for systemic support and better mechanisms in this area
Parental controls on devices are not hard because they are intrinsically hard. The companies just do not care about them, because nobody has forced them to be implemented sensibly. There is absolutely zero reason an Android device could not have a shiny button saying "Kid's device" when you set it up and never need configuring again. So this is not a criticism of the approach, and only a criticism of the companies.
No, the point was that the actual decision happens client side and under the control of the sysadmin (the parent).
> You are just moving the verification point to another gate
Yeah, the gate being the decision of legal entities of age, aka. adults.
> You want to use your friends, Wi-Fi?
That would still do whatever your parent decided for you.
> Want to connect your can toilet to the internet?
Whether the toilet can connect to the network, is the decision of the network administrator, and toilets don't contain UAs, so that wouldn't even have software on them, where you could configure such behaviour.
You're making the mistake of assuming that every kid has access to identified device and that device is under parent control. You can't make this assumption because that's not true.
It might be true for some middle class helicopter parents that have iPhones and time to manage and keep it under strict control but there are non-middle class kids out there who just use whatever device they can get their hands on and their parens neither have time nor ability to control that.
How many children, actually have the money to buy themself another smartphone, or get a smartphone gifted by random people? I bet that's very rare.
In real life, it doesn't work like this for most people. In real life, kids want something and either the parents agree to buy that and then they no longer bother with that device or the kid saves its money trades something and get that device.
The idea that a kid gets an expensive device that can't buy by itself and the parents have control or what device the kid gets is a very middle-class assumption. Life isn't that perfect for most people.
Walmart has sold android smartphones of okay functionality that poor people depend on for decades.
Like, less than $100. Nowadays they have $20 ones that are locked to pay as you go monthly purchases, which is definitely worse than the old tracfone days but about the same price if you had to top up every month anyway. That's ignoring used phones.
Even poor kids get christmas money sometimes.
That's a parent issue, the same as if their kid has a secret stash of cocaine or enjoys dancing in traffic.
No technical measure can fix stupid.
That's not parents issue. That's why we go after people who sell or give drugs to kids. Is a serious offense, we don't wave our hands and say its parents problem and not drugging kids is a popular policy unlike drug enforcement for adults.
Yeah, but that assumes, that there are people out there, selling smartphones to children at scale. First the price for one is way to large for the financial budget of a child, and second that gets even more price-intensive, after the first one got confiscated by the parent.
There are literally people out there selling smartphones to children at scale. A smartphone these days can be bought for as cheap as a burger because 2nd hand market exist and its not limited to iPhones.
And the child can also go and buy a porn magazin, which is likely to be eventually found by the parent, just like the burner phone you suggest. The former is also going to be cheaper.
Guess what they check before they sell the kid a porn magazine
Everything is a parents issue.
If you are depending on the police to keep your kid from doing drugs, you have failed as a parent. I promise you, your kid can locate drugs better than the cops can arrest low level dealers.
You as a parent need to teach your kid how to behave (mostly through things like teaching ethics and morals) not by running a safe prison until your kid is 18.
And yes, I am a parent of multiple kids.
I agree, however the problem is that large number of parents can't do that and it becomes a societal issue. That's why we are talking about that, otherwise it would have been private family issue.
Drugs, alcohol, teen pregnancy and now social media has become societal issue as enough parents failed to control their kids actions or development.
> not by running a safe prison until your kid is 18.
And in addition, such an approach, will not lead to a child magically becoming an adult all of a sudden when they turn 18.
So sure, we go after anybody who gives or sells devices without basic parental controls directly to kids. So you need to be 18 to buy a phone, which we're 90% of the way to anyway with the way credit cards work.
The fundamental point is that the Internet is not a daycare. All of these attempts to put the burden on sites boil down to changing this dynamic, recasting the Internet as if it should be appropriate to use as a daycare. Today it's big tech and porn. Tomorrow it's any writing that the the religious reich dislikes. Monday it's technical sites as they can help kids bypass restrictions. Tuesday it's international sites being blocked at the ISP-level because they don't bother with any of this crap.
We also need to remember the context here, lest we carry water for big tech's continued abuse. The main reason the surveillance industry is reaching for age verification (ie identity verification) is that harm to children is so far the only regulatory cause of action that has been found to stick. Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information. Where what we actually need is to stop their abuse for adults as well - eg data privacy, anti-trust regulation to open up their services to competing clients, and at this point probably straight up regulation of purposely-addictive "algorithmic" feeds.
> Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information.
I've said before and I'll say again that this approach (strict age gating) also is going to produce a slew of really vulnerable 18 year olds. If I were a sports gambling site, I'd be salivating at getting a fresh crop of 18 year old boys each year who have had zero opportunity to learn how to navigate the Internet and who are legally on the hook for everything they do.
OnlyFans, likewise, is going to work out great! Now the 17 year old girls turning 18 won't have access to things like the social media of former OF performers or access to any communities where sex workers discuss the downsides of their job or how to stay safe.
Have to protect the children, don't you know. That way they can be perfectly pure and innocent when they turn 18 and are ready to be exploited. Like fattening up cattle.
Yes! And this dovetails into a point I really should have made as well. The thing about "age verification" (ie identity verification) is that it puts the decision of what kids should access wholly in the hands of corporate attorneys. For example we can easily imagine a "Facebook4Kidz" website that has many of the same terrible dynamics as regular Faceboot, but that Faceboot's attorneys can justify as being legally compliant. As a parent, you would really want to block this too - while all of these proposals for identity verification and site-based-control claim to solve the problem but leave you with no way to do that!
This ties into your comment because as a kid approaches adulthood, as a parent you also want to loosen those restrictions so that they can develop these skills - gradually while under your supervision. Whereas the corporate attorneys will just say that they're strictly off limits, right up until it's then open season as you're pointing out.
Yes!
And you want them to learn in a situation where the stakes are lower: at 18, someone can put themselves into a ton of debt or put nudes in the wrong place and just nuke their life in a way that they can't fix for a decade and everyone shrugs and is like 'you're a grown up!'
Think of all the kids who back in the day got scammed out of their Neopoints, or lost all of their in game currency in GTA, etc. That's a way, way better way to learn about account security and who to trust than their first experience with scammers involving real money.
Is the problem that we're exploiting kids, or is the problem that we're exploiting people? We're not going to be able to protect kids from exploitation in a society/culture that explicitly condones exploitation. If we think exploiting people is fine, actually, as long as they're over 18, then your kids will never be safe, because they will grow up.
Even setting aside the obvious examples I listed, binge drinking used to be a huge problem amongst college aged kids. Who's to say that the Internet/social media wouldn't be similar? How many kids are going to flunk out of school because they can't stop watching digital crack and now mom and dad aren't around to stop them? And unlike binge drinking, your body won't eventually revolt against you, and with the addiction consultants The Machine employs, there will always be new content. People grow out of binge drinking because eventually it grows stale and hangovers when you're 35 are far worse than ones when you're 21, but that's not true of social media use.
To tie this to other issues, we're already seeing issues with relationship and family formation amongst young people. I'm not sure flash banging them with addictive content when they're in their prime years is the call. If all it took for the Internet to be healthy was holding off until adulthood, we'd expect people who were adults when they started to have a healthy relationship with social media. They very much do not.
No obviously we can just require that drug dealers make sure they distribute cocaine in packets that only open for adults.
There are definitely toilets that have UAs.
I wonder if it would work to make it illegal to sell ad impressions of underage people. Do whatever you want as long as you can prove its being done to adults, or prove you have no economic incentive to algorithmically engagement bait
Your second paragraph describes the approach in the blog post almost exactly.
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
I'm afraid you'd get the cookie banner problem but way worse. Everyone that's not Meta/Google/Apple would immediately add a legal CYA "18+" age rating and stop thinking any more about it.
That's how it should be. Make the Internet 18+ by default and sites targeted at younger audiences can add a more detailed rating. Let people configure their devices however they like it.
The whole problem with the regulation we have right now is that it assumes the Internet is for kids, and everything for adults must be hidden. When we really just should declare the whole Internet as 18+ and the sites for kids should be the specially marked exceptions.
So kids shouldn’t have access to sites like Wikipedia? Banning the internet is not the correct solution many kids depend on the internet to have access to education.
The argument could be made for banning social media but the whole internet I don’t think it’s the correct approach
I never thought about that and I find it might actually be the right way for a solution... I was just looking into the Google Play Store now: in Brazil apps need to have an age rating, facebook and instagram for example are 16+, but browsers like firefox, chrome, etc are rated for 'all ages', even though you can access the whole internet through them. If we actually did what you said and inverted the logic: restrict everything to 18+ and specifically mark what is allowed to under-18s it would make parental controls much more effective.
Someone would complain that without ID verification kids would be able to sneak onto the regular Internet and therefore we should eliminate privacy on the regular Internet, just like they're doing now.
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
Agreed, just make age controls available to parents, optional, and keep the user age data on the local device. External hosts can verify against it in obvious ways. But isn't that what California's law said, that commenters on HN opposed so strongly?
Many years ago I worked a technical support job for Xbox services, and the amount of calls about "unauthorized charges" was obscene. Xbox provided parental controls, but it required the parent to set up their child's account themselves, and many couldn't be bothered.
I imagine the same thing will happen here...
And people give their children cigarettes and liquor, that's bad as well. But that's the responsibility of being an adult. If the adult is deemed not worthy of raising children, society has already established a process of dealing with that too.
> for example, on YouTube, you can no longer watch many videos without an account.
I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?
IMHO, they should have Youtube 18+ (Adult book store) where you need an ID and YouTube <18 where you do not (Barnes and Nobles), and they can filter the content as apporpriate.
I think it is evil that YouTube enables kids access to both grooming and violent material.
The problem is that digital IDs get recorded. The physical examples you give are generally not. The clerk at the ticket counter or entrance doesn't give a shit who you are, they just need the picture to match you and the DOB to 18+ years ago. If you're old enough, they dont even card you.
> I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?
I don't like this one either. Does the cinema store the ID (or information extracted from said ID) of every single user visiting, along with what they've watched, on electronic records that can and will eventually be breached? Do they ask a third party (like Persona) for said verification providing the user's information?
On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.
> On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.
This is something that can be done online as well. Capitalism is controllable.
I find myself stuck on the fence with age checks.
Companies have show that they are incapable or unwilling to address the problems they cause. And market forces are not working to correct things. It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.
This is where regulation is supposed to come in.
At the same time, companies have shown that they will abuse any personal information that is shared with them and we are now giving them more details about ourselves…
I don't want the market solving this. If we are going to do age checks it should be based on public key cryptography, be open source, and handled by the government. You verify with the government (or don't since they already know your age), you get some form of cryptographic attestation, present said attestation to websites/apps.
I'm not a fan of age verification in the first place, but I am extremely not a fan of random third parties doing the verifying.
Why do we need to verify age?
You can't tell me that these social media companies don't already know exactly how old someone is just based on the enormous data that is collected.
A big concern around age verification is that some people will be locked out because they can't prove their age.
Your solution here has the same flaw, I think. If the algorithm thinks I'm underage, I'm locked out.
being locked out = less profit = firing management by shareholders
it will solve by consumers, don't worry
The number of people who are marginalised is... marginal. By definition it doesn't have a sensible impact on profit. That's precisely why it is a problem to be marginalised.
Isn’t that… life?
Even literal regulated electricity utilities aren’t expected to provide service to every last marginal customer.
For example, a poor old grandma missing many electricity bill payments usually will see leniency if she is polite, the utility eventually won’t try to collect cash anymore and instead put a lien on the home while continuing to provide service.
But if the billing department receives multiple threats from her, then they may just cut the service.
It won't.
Do you aware how many people are locked out from access of the bank because the bank think they are too risky by some algorithm and no human review?
And people got rejected for flying because they have same name as somebody on no fly list?
yep, just like cases now where people are locked out of their accounts for no reason with no recourse. totally solved!
In the aggregate sure. But do you really think profit motive means they will be precise for every individual?
If you want to use a service that is age restricted either by law or the company providing it how else would you do it? It's the same IRL. I don't like it as well and we certainly lived through the wild wild west times in the 90s and 00s but the more something gets economical important the more scrutiny it gets. Maybe we just need something new.
Well these kind of laws are trying to legislate technology into existence; we don’t have a means to do it, yet “we demand for the technology to exist through ‘reasonable methods’, now get to work.”
If that’s the nearly infinite wiggle room we’re playing with then I’d say what about Adult and Child versions of phones? You have to flash your ID to the clerk to buy an adult one, like buying cigarettes at a gas station, and then you get to do what the internet offers. Child phones - let parents and governments come up with whatever they want to block. The phone autoupdates in the background with the blocklist, the device can’t do those things. There ya go. Each person and family gets to make their own choices and nobody has to give an ID card to PornHub or a company that literally exists to harvest your information. Win-win?
We already have a version of the child phone: it's parental supervision.
When I was a kid there was no TV in my bedroom nor a computer. Everything I watched or did online was on full display in the family room. What changed in the modern home where that's not the case? Are kids glued to their phones because their parents are too?
They do already like YouTube and ChatGPT, so they'll ask for your age only when they're unsure.
chatgpt began to spam me pretty hard for last a few months.
chatgpt basically never sent email and it's regular now - like 2 4 emails per month
so, it doesn't look great for chatgpt
Because it's all about bringing in digital ID and gated internet. Not age.
This is scary though too. If the gov managed a key server like this, almost all companies would start requiring it. But this effectively gives the gov a very easy way to lock you out of everything.
This is really nothing new and has always be the case It's not possible to tech yourself out of a political problem.
So if there is something being done we should choose a solution that has at least some accountability to the general public (through elected representatives).
The alternative is Google, Apple etc where almost anyone has exactly zero influence and the government can still block as they like.
If all alternatives are bad you should do none of them, not squabble about which one is slightly less bad.
Not doing anything is also an alternative, theoretically it can be worse than other alternatives too...
As opposed to if google, Microsoft and apple operate the key server and a government can influence them?
This will be possible if done by third parties anyway, it will just be apple, google and maybe meta, a single phone call is enough to cut you off. At least if the government is doing it, the app doesn't get your id.
Either the app will get the id, you will be prevented from running arbitrary software on your device, or the whole thing will not work because it becomes trivial to sell your age verification tokens.
EU already does this with the eIDAS system and it works quite well.
If it has to happen, this is exactly how it should. Please feel for those of us in the UK who are currently denied access to some pretty significant services unless we send our passport to a random third party.
> some pretty significant services
What services are those other than p*rn?
This is how it's planned in the EU is it not?
Maybe? I'm not sure since the UK is no longer part of the EU; we're running quite a bit behind on this kind of thing now.
You're seriously proposing letting governments decide which of their citizens are allowed unrestricted access to the internet?
Of all the 3rd parties who could be responsible for this, I trust the government the least.
But really the best solution here is no third party. The device owner (e.g. parents) should be responsible for setting the user's age when setting up the device. Anything that tries to take that responsibility away from parents and give it to a third party is necessarily going to be highly authoritarian; putting that third party in the role of parent for everyone, adults included.
>>Of all the 3rd parties who could be responsible for this, I trust the government the least.
Really? can you name any 3rd party you'd trust with this more than your own government?
Given that you know, the government already has all of this info on us. This isn't a choice between "the government doesn't know how old I am" and "the government has all the info on me". Governments usually already do. They have enough data already to issue such proof just by the virtue of us living in the country. Tax records, birth records, driving licences, council taxes, passport info, medical information - there's more than enough to give me a cryptographic certificate that says "yes, gambiting is definitely 18 years old" without me having to do anything. Compared to literally any third party that cannot do any of this, unless they buy my marketing cookies on the open market or something, or yes - I actually go out of my way to give them my passport/credit card/selfies etc.
It’s not really about the info but restricting access to people. Imagine they restrict access to social medial to people with different political opinions as the ruling party in the government
The whole idea is that the government gives you a cryptographic token that proves you are over 18, but that token can be used anywhere. They don't get to say what websites can look at it, because...how would they.
That makes the most sense.
And, that public key of yours must be used only on given platforms. You want to participate on Facebook or Reddit, then you use that public key to prove who you are. Which platforms require verification is another issue.
But it should still be legal and allowed to access conventional forums, Usenet , tor accessible discord servers without having to prove who you are.
Otherwise , the right to organize is over and we effectively live in an authoritarian regime .
I’m from The Government, and I’m here to help.
One not entirely inaccurate definition of government is a loose agglomeration of third parties.
Or, less flatteringly, a stupendously large way too loose agglomeration of way too many third parties welding way too much power way too arbitrarily.
Despite that fun trope, in reality democratic government reguarly delivers very well: Traffic safety systems work easily, dependably, economically. The Internet was developed by the government, the web at a government-funded research institution. NASA is the most cutting edge, most adventurous organization in the history of humanity. The US military created GPS for example, and has more globalized operations than any other organization has ever imagined, and from the bottom of the sea to GEO. Diseases are managed and contained, etc.
(Now if the people want to tear apart government, democracy delivers that too.)
The difference here is that in a functioning democracy people have some control over their government. All the institutions are specifically built to be transparent and work for the public good, at least, in some sense of the word. A corporation, especially a monopoly doesn't care what you think, you have no control over it and the only thing that really matters to them is their bottom line. Are governments perfect? Of course not. Are random corpos better? Again, of course not.
No. It should be none of that. It should be a checkbox either set by the phone store when you buy the phone or set during the first boot process.
In this case will it be a transparent traceability and the mapping to user real identity close to 100%?
I want the market solving this but I don’t want to give any information to anyone who asks. I want Apple to verify me once, and then others to trust Apple that the device accessing their service is owned by someone over 18.
I’ll bet that most people are in the same boat - they trust their device manufacturer with information like their credit card number, but not anyone else.
And I think it’s a pragmatic compromise.
How does this work if you use Linux or Graphene OS?
>It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.
Then who should? Government, where each implementation strips away rights to privacy - which in some countries, including mine, are a constitutional right? Where it expands powers of government to track everyone's activity online - and remember we're one election away from total policy shift(just like with latest US elections)?
Free market? The profitable solution is, depending on environment - either ignore the problem(profit from ads served to children, no extra work necessary), or strip away all privacy (to filter out bots and get paid more per ad).
The sad reality is that "parent should take responsibility" is least bad option available, and takes into the account individual development of a child.
Even creation of a highly regulated child only internet creates more problems - as now that becomes a highly profitable target for bad actors(both individual abusers, and companies trying to serve ads)
In principle, it is possible to make a privacy-preserving age check.
Site/app asks "≥18?", device generates a UUID specifically for that [app/domain + device], the device passes that UUID to government database along with the "≥18?" question and the ID card info but not the app/domain, government database gives the answer and signs just the UUID and the answer and doesn't include any ID card info.
Government doesn't know what you're looking at, website doesn't know your ID.
(There's probably also better ways to do all this, I'm not a cryptographer and I expect that will be obvious from this comment to people who are).
In reality, the ones making such check will want extra capabilities 'just in case' as we observe now, or just go for simpler solution because it's cheaper.
How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.
It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.
Even in countries in which this requires a subpoena, agencies break the law frequently and don't get punished.
Legal systems aren't computer systems. This isn't a technical problem but a social/political one.
> How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.
True, but as this problem exists without any ID at all*, I don't see how the addition of the ID cards makes any difference?
> It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.
This is why I specified a "UUID specifically for that [app/domain + device]". Can't aggregate when each app/domain gets a different signed UUID.
> Legal systems aren't computer systems. This isn't a technical problem but a social/political one.
While true, the reverse also applies: computer systems are not legal systems.
I think many lawmakers' ignorance of this is to the detriment of everyone.
In this case, the social/political problem is: we want to stop kids accessing age-inappropriate material.
The options-space for doing this appears to be:
(0) give up
(1) require parents to limit their kids' behaviour (to which I say: "Have you met a kid? Do you remember being one?")
(2) require websites to age-rank appropriately (to which I say in a sarcastic tone of voice: "Gee, that worked soooooo well for GDPR")
(3) require operating systems to intermediate. Will this suck? Yes. Will it be buggy? Also yes. Will there be false positives and false negatives? Yes to both. Will it be a constant fight as kids keep finding loopholes? Indeed.
But you know what else? All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out. A school full of kids can beat their parents at the security game because they have more time to spend on finding exploits than the parents have to spend keeping up, the reverse is true of the difference between kids and Google LLC etc.
It doesn't need to be perfect, the kids aren't a computer program.
What does need to be held to a high standard is making sure the OSes don't leak all over the place.
* to be specific, the Investigatory Powers Act 2016 is one of two reasons I left the UK, just look at how over-broad the "Internet connection records without a warrant" list is https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016#...
> All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out
What would be the incentive for meta to deploy that against their own self interests?
> Will it be a constant fight as kids keep finding loopholes? Indeed.
Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…
> What would be the incentive for meta to deploy that against their own self interests?
The normal method is passing laws. That's kinda the point of laws.
Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.
> Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…
Hardly. This is more like gardening. It matters much less if kids get a few days of messing around where they're not ment to be, than if it's continuous.
And ultimately, if you want to run a business without spending money on legally required actions, you're in the wrong business, nobody should shed tears for you.
This can’t work because it creates a market for people that have an ID that cleared gates to lease/borrow to those that can’t.
> Government doesn't know what you're looking at, website doesn't know your ID.
But then the government knows your location at any point of time and how often you use websites requiring the age check. Also, if your device is configured to do it automatically, a child can also follow this verification.
> But then the government knows your location at any point of time and how often you use websites requiring the age check.
Not as described. There's no location info in that path, and the signed statement of that UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.
(Should I consider expiry? It's not like people age backwards?)
> Also, if your device is configured to do it automatically, a child can also follow this verification.
Yes, if that device has been associated with a government ID and also the government ID signing process fails to make use the things we've already got on-device like how my phone reads my fingerprint to know I'm me and can store copies of some forms of government ID (in some places but not where I live, Apple Wallet apparently only supports some US states, Japan, Greece, and UAE).
> Not as described. There's no location info in that path
Ip address and general time of day will tell you a lot about location. Not street level, but country or state level.
> UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.
So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?
> So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?
How? Phones are already locked down pretty hard. Anything like this would need to be in something secured at the OS level just to stop signatures getting leaked between apps.
If you're thinking "kid roots device, replaces OS entirely", that's not the problem of the manufacturer of the OS that just got deleted.
Let's also not forget that many of the problems this supposedly solves are not even specific to children. The attention economy is bad for everyone.
The EU actually has a very good, privacy protecting way of doing this based on zero knowledge proofs.
Unfortunately they completely botched it by having the proof-of-concept app rely on Apple & Googles integrity APIs - which a bunch of countries copied.
ZKPs may as well just be unencrypted HTTP headers which would be way simpler and easier to implement. All a ZKP proves is that at least one person in the world is over 18.
This is not completely true.
With ZKP, if you make a business out of reselling tokens you get with your own identity, eventually they will see that you use orders of magnitude more tokens than normal people.
So with ZKP it's more difficult to cheat. Not impossible, just less accessible.
They're not ZK if they can do that
Of course they are. The whole point of ZKP is that whoever gives you the token cannot link it to your identity. So you can get a token with your own identity and sell it to someone else, and nobody will know...
... unless you get thousands of tokens every day and sell them on a website, where suddenly you start leaking information about yourself everywhere. ZKP still did its job: it's not the tokens that link to your identity, it's your behaviour.
Each individual proof is zero knowledge, but downloading a _bunch_ of them is an indicator, yes. There's no real way to work around this with the current ZKP scheme. I'd argue ZKP is, in theory, the least worse option of all current age verification scheme.
My personal opinion is that age verification itself is a bad idea, but if we're going to go ahead with it, I'd much rather we use ZKP for it than the current mess of "upload your passport and picture of yourself to dodgy 3rd parties that likely now have your browsing traffic associated with your real name"...
So the government would impose a maximum limit on the number of porn sites you can visit each day?
Not necessarily, but it would be difficult to justify why you need to access 1000 porn sites every day, I guess?
The point is that if you build a service that sells age verification tokens, you are doing something illegal. And if you start doing something illegal by gathering said tokens with your own identity, maybe it's not the most clever way to do something illegal?
So the government would limit me to accessing only 999 porn sites a day?
I have a feeling that, in order to protect privacy, those regulations must fall on the parents too. It is their primary responsibility to take care of their children. Maintaining your kids digital hygiene should be important to the lawmakers and the child protections services.
What should they do about it?
Who? The lawmakers? I believe banning children up to a certain age from having Internet-enabled mobile devices is a good starting point, and both child protection services and law enforcement services should fully cooperate with parents in enforcing that ban. If you see a kid smoking a cigarette or taking drugs, you know parents have failed somewhere along the road and it would be preferable if the government could step in to help.
This is a reasonable perspective, but don't you think the internet has the potential to do good as well as evil? I remember seeing some interactive lever applet as a kid where you could move the fulcrum. (Slightly) educational stuff. Shouldn't that be allowed?
There are any number of alternatives, I favor a walled off whitelisted subset of the internet that requires age verification and then we can let kids on that and otherwise ban them from the general internet and also ban internet enabled devices in general. However, this costs and undoubtably wouldn't be perfect as there are people out there who want to chat up your kids, look at how much work a roblox style site needs to do against internet users who probably shouldn't be chatting up kids.
For those precocious kids who parents decide should be the exception because they are "good with computers" well I'm thinking some sort of waiver would be required that held the parents responsible then maybe let the kid hack on the internet but this is an unpopular view, the unpopular part being the "parents being responsible for their kids" bit.
But in general I think its a tough time to be legislating this stuff because "reasonable perspectives" are not what we are voting into office right now lol
Educational content was already a thing well before the internet got everywhere.
When I was in primary school, one of the things teachers had us do was debate the pros- and cons- of television. The pro side included educational content.
First Windows PC at any of my schools had Encarta.
Wikipedia can be downloaded in entirety and read offline, though it is so broad it may need a degree of filtering to become age-appropriate even for 16 year olds.
I have a feeling that, currently, the cons outweigh the pros. Maybe if the digital landscape changes in the future, then we can reconsider those limitations. So far, the mobile Internet - the apps mainly - is a hostile environment for a young human, and I'd say they are pretty dangerous to the adults too.
In many schools in the US now, kids are issued mandatory iPads from age 5 and are required to use them to complete school assignments.
Which sounds like a government mandated child harm measure to me.
Most of the US education system is.
That is extremely upsetting.
Wait until you hear about the pepper-spraying drones being put into service in schools.
https://news.ycombinator.com/item?id=49091153
This is reasonable up to the point of lawmakers suddenly deeming rainbow flags just as bad as drugs (Russia as an example). Your example may work in well intended countries but completely ignores that a country can VERY easily shift into a regime that does not have good ethics abusing these kinda laws.
Not having an internet censorship law never stopped a country from making rainbow flags illegal.
Children here are a distraction. Any harm these companies are causing to children is also being inflicted on adults. The correct solution is to end the harmful behavior for all, not set up required identity verification.
There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.
There should however be no force age verification. Social media companies already know how old you are or very close to it using the data they collect everyday. Using this data they should be required to use "best effort" to determine which algorithm you fall in. Nothing is 100% and we should stop pretending it is, sure some kids will find a way around but they would also if there is a age verification system.
> There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.
Frankly, in that case I want the kids algorithm. It is preferable for me as an adult, I do not want the intentionally harmful one either.
This. Just give me the option to have pagination. Sweet, old, pagination. Like here on Hacker News. I can then review one or maybe 2 pages, and that is all. Like a physical magazine where there's a clear end.
I have the firm belief that infinite scrolling is one of the darkest pattern that was ever invented.
Hang on... Hacker News very clearly has a complex, opaque [1] algorithm that orders stuff. Maybe it's not user-specific, and maybe that's a good dividing line, but these are the kinds of factors we're going to have to think about if we want to introduce regulation around 'algorithms'.
Infinite scrolling is a very different issue (although it's definitely a contributor to the harm, I agree).
([1] Unless I'm being unfair here; maybe the algorithm is available somewhere, I just don't see it obviously linked anywhere)
Yeah, seriously, New York just passed law that makes it illegal to show engagement-driven feeds to kids.
I can’t wait to not age verify on instagram and permanently get back a feed that’s only people I follow.
You can often do that via settings. But we could do with a law that makes it a crime to override a user setting that has been explicitly set, without notifying the user.
Oh but you enabled the setting "don't use infinite scroll" and we've deprecated infinite scroll so that isn't a setting anymore. While improving service for our customers we have introduced "unrolling pages" which prefetches the next page and attaches it to the end of the previous page to provide a smooth reading experience, and of course we've given that its own setting which you haven't set, and it defaults to enabled to provide the best seamless reading experience for most people.
Next we're thinking about spatial pages, an innovation which considers the app as a viewport flying over the pages laid out in a line. In consideration we have database-views which presents the unpaged tables of content in the database directly to the end user, completely bypassing outdated 'page' skeuomorphisms from the olden days of printers and books. Further out, our researchers are working on Shepherd Tone-inspired viewing, where technically legally it is paged, but it looks and feels like it isn't!
We have cars, and kids are not allowed to drive them. Yet we do not have mechanisms in place to ensure kids aren't driving cars because the responsibility falls on the parents, and it works. By and large, parents understand the threats and navigate this requirement perfectly fine; outliers are few enough that we can deal with them on an individual basis.
The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small. Personally, my vote is that they just don't think it's that big of a problem.
To me, the ideal solution would be more granular and better parental control configurations, especially on the web. Pair that with preconfigured devices that have "unremovable" parental controls, branded as "kids/youth phones." If parents care about this, they'll buy those phones for their kids and the problem is solved. If they don't, then this isn't something parents want, and we shouldn't really pursue it further.
> The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small.
Sometimes parents know their children, and what's best for them, better than faceless politicians (who we've seen are often attracted to said children for some reason).
Growing up in my household there was a time when I was allowed to read and watch whatever I found interesting. My younger brother was not. That was because my parents knew us and judged that at my level of maturity I was unlikely to be negatively impacted, whereas my brother would get nightmares or copy-cat things he saw that he definitely shouldn't.
That's how it should be. Yes, there are bad parents who will decide poorly. That's the cost of freedom.
> This is where regulation is supposed to come in.
Yes, agreed. However regulation does not necessarily have to mean age checks.
The most obvious low hanging fruit to start off with is open and interoperable content filtering infrastructure (ie parental controls) so that there's some common standard that literally everything supports out of the box. It needs to all work together - the current situation tends to be spotty and unreliable thus parents tend not to bother trying to use it.
Start with an extensible metadata format that enables websites to self-classify pages. Account for things like loading alternative resources on the same page. Mandate that all websites and app stores include such metadata and that all browsers and operating systems have some baseline functionality for making use of such data in a sensible manner.
Only after that has completely and utterly failed should we even begin to consider highly invasive measures such as mandating government ID checks.
I think you've done a great job identifying the three main options and why two of them (parents, censorship-by-default) just will not work. That leaves regulation; the only way we will prevent children—or anyone—from coming to harm is to stop companies from producing this harmful content in the first place.
Either that, or just accept the harm.
Who decides what is harm? An unelected bureaucrat? Now you’re going into censorship area
No, I'd prefer elected representatives to do that, in the same way they've decided on all the other existing harms we legislate for.
100%, it's not like adults are immune to misinformation, social media addiction or scams. Those platforms should be safe for all people regardless of their age, nationality, sexual orientation, gender or religion.
> It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.
That's like saying "take a look at owners of fast sport cars, it's obvious this is not working and they have too many accidents." If you want to patronize other parents and think the government should be more responsible and parents less responsible, please state that honestly. Don't make up alleged "facts" to make a point.
Otherwise, I'll just say "it's obvious you're wrong, just observe the world around you and you know age verification is a non starter."
Related recent discussion: https://news.ycombinator.com/item?id=49084938
The parenting argument is a complete cop-out. There's no universe where you can be shoulder hovering 24/7. This could've been solved years ago with robust parental controls. But companies like Google just didn't want to because they wanted to shove ads in kids' faces.
I think we can approach this from more than one angle. Yes, it cannot be entirely on parents, but parents should bear some responsibility to not just hand a device over to their children with unrestricted access to the entire internet.
Up until relatively recently you would have to install custom VPNs and maybe add Pihole into the mix to achieve anything close to that. Easy for us here, but we're in a small minority.
Parental controls have been part of mobile devices for years, but so have bypasses. For instance, you can bypass Google's parental control settings by opening the help page in the Google settings and clicking links until you get to the Google homepage.
I doubt it matters because nobody seems to configure the parental controls that are there, anyway. Only schools seem to try, and only because they're legally held responsible for what kids do on their computers.
Parental controls are complicated and obscure, IME. Setting up a child to play Minecraft through Microsoft was like setting up a web server with firewalls and reverse proxy... only less sensible. I'd appreciate that is so they can get parents to set accounts as 'adult' so Microsoft can exploit them.
You can set up, for example a child friendly DNS (Family version of OpenDNS) then Firefox come along and bypass it (DoH).
Probably, we need an OS level setting, per account, browsers would need to expose it to websites, apps installed would have to check and provide content according to local legislation/rules. Bypasses would have to be performed by an "adult" account.
The main issue is that adults would be able to set themselves as children and avoid negative commercial activity. That's a problem because it means FANG, etc, will lobby against it and then ensure their implementations are convoluted and broken.
Parenting doesn't have to mean become a helicopter either. In fact, that's the worst kind of parenting because it doesn't prepare the kid for a future without a parent around.
Parents should take responsibility and not let their children smoke, and we still banned selling cigarets to children. Just because something should be some way, doesn't mean as a society we shouldn't do anything about it.
In any case, the story with parents and addictive devices is even harder for parents than e.g. cigarets. For example, a LOT of schools in the UK think that it's good to give childrens ipads to study, and there's nothing that parents can do to prevent this. In this specific situation saying that "parents should take responsibility" is unfair to parents, because their only option to avoid this is home schooling.
Well, the API itself seems fairly well designed from a privacy perspective. It only shares age ranges, not specific ages, and only if you allow it. The data is also fuzzed to prevent an app from determining your exact birth date, and it's all tied in to the parental control system.[1]
The problem remains though that, since the laws this feature was created to comply with put the onus on Google to verify the user's age and not on the device owner (e.g. the parents), the method they use to determine the user's age to feed into this API is terrible from both a privacy and freedom perspective: they force you to send them a copy of your government ID, and delete your account if you don't comply.[3]
[1]: https://support.google.com/googleplay/answer/17232873
[2]: https://developer.android.com/google/play/age-signals/unders...
[3]: https://support.google.com/accounts/answer/1333913
The API is tied to a Google account though. You can't simply install an app on Android and have Android tell it what the user's age is, it has to first have google maps, youtube, play services, etc. installed and you need to make an account and log in globally on your device before it can tell the app an age. I don't know that I'd call that a good design for an Android API
I think it's the old that need to be protected more on the Internet since they disproportionately fall prey to online scams. So let's age-gate their access to online services too. If you are old and want to send money to someone, you get age-gating and second-factor authorization from a competent young person. If you want to watch porn online, believe it or not, age-gating and second-factor authorization.
Honestly, I wouldn't be opposed to that either. If we're protecting kids, we should also protect the old and feeble. Old people, people with developmental handicaps, you name it: they're being exposed to a world that can and will abuse you if you have any faith in humanity left and don't have the technical skills to identify things like fake domains and scam sites.
For some reason we're making sure no 12 year old can drive or run for any government positions, but a 90 year old can keep the driver's license that they've had since before the start of colour television, or make critical decisions affecting millions. We can't have it both ways.
Can't we build a gateway in the internet that detects if someone is a influential CEO or something and just bar access to the internet?
I was just saying yesterday that we (Finland) could take the bullet and create a luxury resort for all the zillionaires in the world.
Connect them with each other and populate their air-gapped "Internet" with like-minded authoritarian AI-bots and create special news like Don and Vladimir are being fed to keep them from tantrums. A win win for everyone!
Ooh, and mental health services. Plenty of mental health services as we're so poor of a race that even our richest can't afford enough therapy to feel alright!
There's a Pink Floyd song about just such a thing, Fletcher Memorial Home: https://www.youtube.com/watch?v=zDDzR2zSgsM
If you have more than 100 million in the bank you should be barred from using the internet...
Good idea, you got my vote!
... unfortunately I don't have a vote according to Tobi
https://fortune.com/2026/07/27/shopify-ceo-voting-rights-str...
What does this have to do with age verification?
We've already decided to do verification of users, now we can look into which groups of users should be limited or barred entirely.
I doubt the purpose is even age verification. They already can know I have a visa card which is credit card that can be only applied by an adult by looking at the BIN. Why they need my id card if the purpose is actually age verification?
To verify that your opinions are correct
This coordinated worldwide effort at the same time is very creepy.
It just means politicians read the news.
If only they used that time to listen to their constituents instead.
And aren't very imaginative.
I think this is actually a reaction to the over-reaching laws various governments are enacting. This is the way it should work - parents check a box that says "the user is 13 years old", and then apps and websites can see what the parent set.
This is much much better than having to do face scans and credit checks etc. to prove to some sketchy third party that you are over 18.
I think if Google had bothered to do this 5 years ago we might not be in the shitty situation we are now, but it's probably too late now.
It's not like children can buy overpriced phones or tablets. You can force the stores to help setup up restrictions for their devices for parents that don't know how or want to. Then start doing massive fines and restrictions on websites or app stores that host unregulated apps.
If they can afford to buy them on their own, good for them.
You don't use age to decide what's appropriate; I don't mind if my kids see naked bodies. I do care if they see naked porn star bodies, and porn, although actual amateur porn with a range of body shapes is okay. Fighting is okay, but actual graphic bloody violence is less so (funkytown cartel video is no bueno).
Put that in an age range Google.
This should be in front page
I'm surprised that there are so many still think that this is really about protecting kids. This is not an organic movement at all.
> in our ongoing partnership with parents and developers by announcing the expansion of the Google Play Age Signals API
Which parents and which developers? How many of them? From where?
I don't understand why apps need to know anything about a specific age. If we have to go down this road, which I really don't, why can't we just simply have verification whether or not an age fits within a range better yet a category. Yes, age can still be inferred, for example, under 21 or over 21.
The API behaves this way:
> To request a user's age range and sharing status, you call the Play Age Signals API (beta) from your app at runtime. The default age ranges the API returns are 0-12, 13-15, 16-17, and 18+, but you can receive custom age ranges.
https://developer.android.com/google/play/age-signals/use-ag...
But I don't find it any better. I don't see any viable reason to provide identification to my phone's OS. If a parent buys a phone for their child, they can already set up parental controls before handing it over.
I wish Motorola all the best with their GrapheneOS partnership.
You can also get GrapheneOS right now on Google-branded hardware, which is expensive but not enshittified.
True. Though I have mixed feelings buying new pixel from Google after all these actions.
Then buy a used or open box one. There's plenty of people who try switching to Android and buy Pixels, but go back to their iPhones in a week.
I don't. When they start making shit hardware, stop buying their hardware. As long as it's good, buy it. That's a free market price signal.
I don't think there's enough GrapheneOS users to make a 'free market price signal' here
>which is expensive
The rumored Motorola devices are even more expensive. It's the signature and some foldables, all in the 1000+ MSRP range. At least with pixels you can get the a series for as little as 400 on sale.
If you buy one of the Motorola Grapheneos phones, you're gonna be marked. You will stand out in the crowd. It has happened before and will happen more frequently as the world becomes more authoritarian.
On the other hand, privacy becomes a luxury. People love signaling their status and standing out from the crowd. Entire car and clothing brands exist solely because of that.
And if enough people stand out, it doesn't matter anymore.
Yes, people can tell a phone is running Graphene. They just can't get in.
LineageOS is still a thing too.
Because it's not about age at all. That's just ruse to get a lever to lock people out of their devices if they don't behave.
How would that make sense?
If anything, I would imagine that Google's changes are motivated by driving traffic to their Google Play Store, where they make billions in commissions.
Once this framework is in place for the Google Play Store, perhaps they can lobby for strict age verification laws, and then tell developers who publish outside of Google Play that they are responsible for compliance themselves.
people on discord get sniped semi regularly by fraudulent child exploitation reports
It makes total sense. You here assume that this is only driven by Google. Once you include state actors, suddenly it makes sense.
They gather more data now. Only verified users will be able to use the internet in unrestricted ways - that is what is new.
When there is a clear motivation to protect a $50B/year revenue stream, that seems to be the more likely explanation.
If it appeals to politicians who view "protect the children" and surveillance positively, that is a bonus.
It's amazing how naive and gullible people are even after all the many thousands of examples of lies and gaslighting over many generations now. It seems to be a permanent characteristic of a certain subset of people, and seemingly a majority of people, at least in the west and at least in this era.
It always gives me the "he only beats me because he loves me" or "he wouldn't beat me if I knew how to behave better" vibes. It's not healthy, not sane, not rational.
One disagreement though; I don't even think they will lock people out of their devices outside of very narrow and specific instances or examples to "cut the grass" as the Israelis call it, to scare and remind people they are the slaves and the long arm of the tyranny can reach out and crush them if they don't self-censor and self-subjugate. Psychological and ideological control has very much proved itself far more effective than physical control in all circumstances. They want to be able to monitor and then use methods and technologies to control that have not really come to light in society even thought they were systematized through the Iraq war. You are now the "insurgents", are you old enough to remember those, those insurgents in their own country?
Laws have been written that mandate that applications and services treat various age ranges differently. You can't serve porn to kids, kids under 15/16 have very strict privacy regulations in some areas, and certain content age ratings are an industry standard only because that was the industry way of getting out of being regulated.
For kids this is a privacy risk because there are so many thresholds. Once you're above 18, all you need to care about is "are you a pensioner".
Kids have been lying about their age since the dawn of the internet and people have started catching on, so now we're getting actual restrictions rather than the assertion that nobody in their right mind would click "I am 18 or older" to access a website.
Californian law mandates that operating systems keep track of their users' age, so of course Android must follow. In all of the cases listed on Google's blog, though, the option to not share information and download an app that doesn't ask for your age range is still an option.
This isn't aimed at you specifically, but I think many technologists seem to innately misunderstand the slippery slope hypothesis which helps form the bedrock of American politics.
Too many seem to fall into the familiar problem-solving mode, ready to provide compromises or solutions while forgetting that once the infrastructure is in place, it can easily be modified later to undo the compromises which facilitated its acceptance in the first place. There is an inherent power asymmetry and it's not generally in favor of those building and using the infrastructure.
Indeed - Flock cameras showed this.
They also actively undermine the US constitution. Will be interesting to see whether the remaining judges have any power to change this or whether they were also integrated into the new dictatorship model.
Surely it's not the camera per se, it iss the people who are installing them. One key driver is lack of efficient law enforcement.
Do you force people not to give up their own liberties? In a democracy?
Although better privacy laws would cut off the access of non-customers to the data of those customers devices.
Because it has never been merely about age only.
They want to track everyone now. Age sniffing is just one additional step for forcing verification. This will continue - see how suspiciously many countries adopt new legislation. It is quite fascinating to me to see how easy it is to kill off democracies.
Doesn't seem like most of the people on this thread actually read what they're planning.
It seems like a very good solution to me. It gives parents a simple solution to define the age of the phones user and a mechanism to allow apps to get an age range and tailor usage appropriately.
It does all this while leaving everyone else undisturbed.
Put the age range into http headers and you solve children accessing content via the web as well.
Through a Google account. It's not some device check.
Well it's google and google does everything through their accounts.
But the principle of this can work on everything.
Own an iphone, apple can do the same tied to the apple account.
On a windows machine you can do the same tied the user account login for the child.
People will no doubt pick holes in something like this, but it's the least intrusive, least effort solution to the problem that will actually work.
What a pain reading this blog post. It's about them complying with recent regulations, but they never mention it once: they word it so it sounds like they are doing this out of the good of their hearts. The words "law," "regulation," or "compliance" do not appear once, despite being the entire reason the post exists.
Also on the "privacy-preserving tool", technically apps get a bracket ("16–17") instead of a birthdate. But who holds the actual data? Google. The privacy improvement is against the developer only.
Seriously ready to fully drop google emails and services, i'm using vivaldi + personal email for a while now, the migration was slow a bit painful but complete. Only the phone is still attached to play store and google, but i'm 100% ready to switch to the fully supported Chinese variant of ColorOS and flush Google into the toilet once and for all. But my next phone will 100% be a Sailfish again.
I run on proton for decade and it's not exactly gmail high tech solution, but it's secure.
I have mozilla, brave, waterfox, mullvad and a few others.
It's amazing to see how google and others big companies are marking you as bot.
For me to fully drop google someone needs to create something compatible with Android Auto in my car, it doesn't sound like a big deal but that's a big enough thing for me to need it now.
Buy a separate tablet and a roll of duct tape. If you're careful, you can completely cover whatever obsolete nonsense is built into the car.
Why is this part of Play Services? It should be something on-device as part of AOSP, not something that further entrenches Google.
(In case it's not obvious: rethorical question, Google just wants to do platform lock-in with Android and sees this as a useful means to bludgeon it.)
I think also something needs to be done to the companies that we know are targeting teens and children with tactics for addiction. Meta was found to have engaged in such tactics and nothing really happened to them
Will these be compatible with the Digital Credentials API in Chrome (https://developer.chrome.com/blog/digital-credentials-api-or...) or will websites be essentially locked out of friction-less age verification?
I'd be totally fine to solve this problem by banning children from the internet altogether. Not that I'd enforce this or anything. Just so no one other than the parents can be liable when things go wrong.
There's more and more evidence that internet access isn't healthy to have for children anyway.
I would've never learnt to program or learnt to speak English or learn about other cultures
thanks so much for being awesome like this, pulling the ladder when it no longer concerns you. so mature and brave
Yeah. And if a kid drinks beer only the parents should be liable.
Why are we all so horny to transfer unlimited liability to parents?
Because raising children is unequivocally the parents' responsibility. It's, like, their main job.
But we don't put barbed wire on random sidewalks and then blame parents if a kid walks over it and gets hurt. There is the attractive nuisance doctrine, among other things.
We don't leave the barbed wire on the side walk but require everyone that wants to walk on it to age verify first either. And the attractive nuisance doctrine some states have is absolutely bonkers.
Yes we do leave pubs on the sidewalk and require everyone that wants to drink there to age verify first, what are you talking about
Viewing the continuance of our race as only the responsibility of parents is pathological.
Moreover, children are all of our [mid-term] futures too. If education fails, there are no doctors for anyone not ultra-wealthy.
You have to look from the other direction too - children have natural rights and deserve to be extending dignity as humans too.
>Viewing the continuance of our race as only the responsibility of parents is pathological.
That seems to be a uniquely American pathology.
Everywhere where else in the world, and in non-white American subcultures, the community taking a hand in raising children is expected. But many Americans seem to consider it socialist and an attack on Christian values.
See Hillary Clinton getting mocked for saying "it takes a village"[0] or BLM being accused of wanting to "destroy the nuclear family" by encouraging community based parenting[1].
[0]https://www.cnn.com/ALLPOLITICS/1996/news/9608/27/hillary.sp...
[1]https://medium.com/@emailnatesmith/the-blm-statement-on-fami...
You have a kid, you have responsibility for that kid. In Germany we have a term "Aufsichtspflicht" for this, which roughly translates to duty of supervision. Up to a certain age of the kid parents will be made responsible for damages your kid caused. One pretty funny example of that was a kid spending 1000s of Euros on a MMORPG because the MMO offered a payment option that allowed people to pay through their phone bill. Parents could've easily prevented any of that happening, but in that generation it was pretty common that kids were tech savvy while parents couldn't be bothered to learn about computers, which imo already is problematic.
Nowadays there are many many ways to supervise your children's online access. And yes, there are also many many ways for kids to work around that too, but ultimately if you buy your kid a device with internet access, you should try to supervise that. Parents need to care more about what their children are up to, instead of silencing them with a tablet for a moment of personal silence.
¿What are those ways?
A small example would be to set the device into "kiosk mode" which many companies use for their employee devices too. Prevent app installs, check what pages ur kids visit with their browsers and whatnot. Just make sure to be open about it so you don't hurt your kids by violating their privacy and trust towards you. Hell we even got parents having their kids take air tags with them so the parents know where they are.
Or the device could be mandated to have a "child mode" with more specific restrictions designed for children.
What's the difference between an age check and a total identification check?
If you can only check that the person is above age without checking who they are, then it's not the same, is it?
Besides the page header and footer, the post has 0 use of the word "Android", which feels telling of Google's approach these days.
This is actually a step in the right direction. I don't want to share my id and selfie with every stupid social media app/site. I would much rather allow parents to configure their children's devices to share their age.
post refers to apps. how about browsers? will this allow browsers to block content based on the user's age ?
> expand... worldwide till the end of the year
So at the end of the year they contract again?
Or should the headline read _by_ the end of the year?
Surveillance comes for us all.
Global surveillance incoming.
Heard Google is also rolling out QR codes to get past captchas? Ie linked to a device that would now be identity linked too.
All seems pretty dystopian or to quote googles slogan - being evil
I already saw it on youtube. However, ctrl + f5 fixed it.
On the other hand, youtube became so unusable that I have spotify premium now.
So, give it a few years and corpos will take it down because of missing profits.
Incoming? Have you been asleep for 30 years?
Title is: Delivering safer, age-appropriate experiences on Google Play
this just ends up with the movie rating system, gamed and easily ignored by most people
Just like every new Android "feature", the first thing that comes to mind when reading this is how will it work if you aren't logged in to Google on your phone. Am I supposed to give up and pretend it's normal to have to log in to an online account to use a personal computer?
A question to the crypto nerds here - is there a way to prove that you are of age, but you can't be deanonymized even if the government, identity provider and the website itself collaborate to do it?
"Providing a safe online experience and protecting users from harm is a top priority at Google Play." LOL NO. amount of malware says otherwise.
The usual "but think of the children" tactic.
What's hilarious is how Westerners still think they're much different from China or the former Soviet Union anymore.
They are still quite different.
Parroting that mantra is how we got here.
And there's no sign of improvement on the horizon, only the tightening of the noose.
Safety!
This is what I keep telling people
Age check is only pushed because this way you can tell humans from bots.
Prove me wrong
There will be ways to circumvent and even use verified devices as botnets.
They want your data.
YOU have become their product.
By the way, this also explains one reason why Google shut down third party access/applications recently on Android. Android (if one uses the Google software) becomes the ultimate spy tool on people. At the same time you see several countries force age sniffing on people - this is the beginning of the end of the free web. It will happen in various steps; the next one is Microsoft adding this to their software.
Linux is also ready to support age verification through systemd. Luckily, there are still distros without it, like Void Linux. I switched to it recently and now my media PC boots faster than my TV takes to turn on.
> YOU have become their product
LOL
behind the curve, and completely missing the point.
I couldn’t care less about children or about what is ultimately a parenting issue (keep your fucking kids off the internet). A problem that affects a subset of the population is not something that should be solved by subjecting the entire population to inconvenience. Just make it illegal to use the internet for under 18s or under 16s or whatever and let it be assumed that all users are of the appropriate age.
If I a child is on the internet without adult supervision, that’s a parenting problem, not an issue for the state or other people to solve.
'Google will build the walls on their garden two bricks higher by end of year'
I don’t understand how are they even checking the age ??
They aren't. The device administrators (ie. the parents) set an age range in the OS' config and then the OS tells applications the value. That's it.
In some jurisdictions/countries they have to call some government service which then tells them whether a person is above or below a certain age.
Theoretically you could make this double blind and that's the story they are telling.
We have no way to (dis)prove it though.
Alas, here goes the freedom, with thunderous applause.
This smells like Soviet Union. The next step will be a requirement to confirm your identity - trying to justify it with a wicked manipulation tactic "we need to know your are not lying when selecting your age". No one asked for it to begin with. Android is normalising totalitarianism and mass spying on citizens, one step at a time. This is a very bad feature and a very bad development.
Its the same thing with Europe allowing scans of private chats now. Nobody would tolerate a person opening the letters from ur physical mail box and reading through each of them just to see if you do [insert illegal activity]. But once this stuff happens digitally, people seem to simply tolerate it. If I remember correctly, in 2019 there were huge protests against upload filters were people actually protested on the streets in Europe. Now there is almost NOTHING for chat scans, NOTHING for age verifications, NOTHING for making Android less open. Its really frightening what the general public tolerates nowadays.
The authorities open letters all the time. Try sending a letter to prison without it getting scanned.
The problem with this comparison is that the authorities can open a letter if they need to for various well-intended reasons, but they cannot open an encrypted message. Either the authorities can scan all messages, or they can scan no messages, there's no inbetween.
The mandate to verify age before selling alcohol has been around forever. This is not a new idea. The biggest restriction until now has been that there was no good way to do these kinds of age verification, but that problem has been solved. You can still debate whether or not age verification is a good idea for specific subjects, but selling 10 year olds alcohol or porn has been illegal for much longer than the internet has existed.
And if everyone is treated the same as someone who has been tried and convicted of a crime worthy of incarceration we are well into the dystopia.
Communicating via PGP encrypted snail mail seems an attractive option.
It would make for a good alternative, but so would any app that doesn't implement scanning. If they can force Signal to implement client-side scanning or ban it entirely, they can do the same to PGP software. In theory you could do RSA by hand, but it would require a lot of hard work.
Last time I checked an Android phone was not selling me alcohol or porn. It requires specific deliberate actions to get access to anything like this with a phone. Any checks could be justified on the store or web-site level, not on the phone level. Treating every citizen as a child or even worse a potential criminal who needs to be constantly checked at numerous checkpoints the state so kindly put everywhere is exactly the stinking smells of the Soviet Union I'm talking about.
Not just android
I think you're misinformed, they didn't have age checks on smartphones in Soviet Union.
But there're countries where that already exists. They usually get labelled as a threat to democracy. Isn't it ironic? It's as if our own governments are the greatest threat to our way of life.
Age checks are inevitable sadly. No one would tolerate “adult” services and goods rendered directly to children without age check.
The main argument is that there is an assumption this data is not stored in the real world, which is only sometimes true. Some places like airports and some concerts, shows, bars, etc. scan identification with digital readers whose data is presumably retained. One reason for this is because fake identification is a thing so defense against this converges to the same solution as digital verification.
Imo best to spend energy thinking of the appropriate solution that minimizes privacy violation than conceptual fighting against the idea.
> No one would tolerate “adult” services and goods rendered directly to children without age check
I don't think it's fair to say that parents who don't care to use parental control measures already available to them have no tolerance for that.
Also, for a more substantive answer see: https://news.ycombinator.com/item?id=49108086
We could settle on a privacy-preserving idea, like physical cards with single-use codes sold in stores after showing ID, similar to alcohol. Then a few years later they would ban cash payments for those. Then require sellers/payment operators to report all transactions to a central registry. The slope has always been slippery.
Parental controls don’t solve all of the issues. The same way telling your kids not to do drugs is not a solution to vaping use.
If you don't even try to use simple available measures to prevent your own child from vaping then it's unfair to say you have zero tolerance for children vaping.
Strange comment, plenty of parents try and fail to stop their kids to do certain things.
Did you mean "plenty of parents wouldn't tolerate “adult” services and goods rendered directly to children" when you said "No one would tolerate “adult” services and goods rendered directly to children"?
Then maybe we need to teach parenting in schools instead of trying to outsource it to the government.
Google preps your surveillance device for CBDC without your consent.