Live data from Hacker News

So, you’ve hit an age gate. What now?

eff.org

271–280 of 306 posts

Re: So, you’ve hit an age gate. What now?

#271

Earlier quoted context omitted.

> Stores that sell other age-restricted products. So far, I've never seen an age verification scratch card sold anywhere > How would they be traced? Your ID is collected at retail and its barcode scanned along with a barcode on the card, your personal data and card ID get uploaded to a server operated by the entity that created the cards and/or the state. ID barcode scan can be replaced or used alongside facial recog…

Buying alcohol is nothing like getting an anonymous token that grants the right to a Google account. This is equivalent to saying you either need to be over 16 or have a parents permission which will not work for any number reasons that someone else can enumerate. It's a nice idea. Won't work.

Why won't it work?

Re: So, you’ve hit an age gate. What now?

#273
post #263
post #72

Earlier quoted context omitted.

While I agree with this in spirit, here in the UK both major parties along with the public at large generally support these types of laws.

I sincerely doubt that the average UK (or US, or French, or German) citizen even knows what a VPN is beyond "that thing you sign in to for porn," let alone knows enough about it to have an informed opinion on the laws surrounding them.

Neither does the average politician, so where exactly is the impetus for changing the law going to come from?

Re: So, you’ve hit an age gate. What now?

#274

Earlier quoted context omitted.

I’ve been noodling on this idea for a while but I think getting commercial acceptance would be hard. People have tried it with crypto albeit with lukewarm results. I think to have the network effects required to be successful in such an endeavor, it would have to come from a vendor like apple or google unfortunately. You kind of want an mTLS for the masses with a chain of trust that makes sense.

mTLS is no good because the target service could then uniquely identify you. I think you explicitly want a three-party scheme where the target service just accepts the idp's assertion about your age in a cryptographically secure way.

I feel like mTLS could still work in third-party signing.

Re: So, you’ve hit an age gate. What now?

#275

Earlier quoted context omitted.

My Google account is more than 18 years old and I hit an age prompt when I was trying to watch some FPGA video (out of all things). So no, account age is not necessarily a factor.

They probably need to account for parents allowing kids to use their account, so account age can be a factor but not an automatic pass.

Parents allowing kids to use their account is a problem with any current approach.

Re: So, you’ve hit an age gate. What now?

#277
post #176

Earlier quoted context omitted.

How would you suggest they verify age? I am not aware of a good way to do it from a privacy and security perspective.

You can take a look at what Switzerland is about to do: https://www.homburger.ch/de/insights/swiss-voters-approve-ne... !

> Once issued, the e-ID will be stored in a secure digital wallet application on the user’s smartphone or other compatible device.

That sounds like Apple & Google-blessed Android only, open source gadgets and non-Microsoft desktops not supported. Estonia at least used smart cards where a reader can be plugged into just about anything.

Re: So, you’ve hit an age gate. What now?

#278

Earlier quoted context omitted.

Would be very tough to implement in the US, as proposing any sort of "national ID" is pretty much a nonstarter, at least up to this point. States could do it, and maybe agree on some protocols so that things like privacy-preserving "age verification" could be done. Maybe the feds could push it like they did with speed limits: make federal funding contingent upon adopting e-ID. Would still get a lot of pushback.

The problem with e-ID is its focused on identity verification, not just age verification and that's where the problem lies. We still need the ability to be psuedoanonymous online. We should be able to verify age without divulging any identifying information to the service requesting age verification. An e-ID registry could work on a sort of public/private key system so long as the services requesting informatino from…

If an e-ID can vouch you are citizen number #3223423, it should be able to use the same crypto to vouch that your birth date predates a threshold, without revealing anything else. It's more a question of requirements gathering & UX (and political will).

Re: So, you’ve hit an age gate. What now?

#279

Earlier quoted context omitted.

The fundamental question that needs answering is: should we actually prevent minors below the age of X from accessing social media site Y? Is the harm done significant enough to warrant providing parents with a technical solution for giving them control over which sites their X-aged child signs up, and a solution that like actually works? Obviously pinky-swear "over 13?" checkboxes don't work, so this currently does…

> The fundamental question that needs answering is: should we actually prevent minors below the age of X from accessing social media site Y? I suspect if you ask Hacker News commenters if we should put up any obstacles to accessing social media sites for anyone, a lot of people will tell you yes. The details don't matter. Bashing "social media" is popular here and anything that makes it harder for other people to use…

> Would you be willing to submit to ID verification for the sites you participate

I would not. Because there are better options out there if the objective is purely age verification that's as rigorous as the status quo for buying alcohol or cigarettes.

Here's one option: https://news.ycombinator.com/item?id=46447282 that I proposed. It is by no means the best or only one.

Re: So, you’ve hit an age gate. What now?

#280

Earlier quoted context omitted.

The fundamental question that needs answering is: should we actually prevent minors below the age of X from accessing social media site Y? Is the harm done significant enough to warrant providing parents with a technical solution for giving them control over which sites their X-aged child signs up, and a solution that like actually works? Obviously pinky-swear "over 13?" checkboxes don't work, so this currently does…

> The fundamental question that needs answering is: should we actually prevent minors below the age of X from accessing social media site Y? This is only an interesting question if we can prevent it. We couldn't prevent minors from smoking, and that was in a world where you had to physically walk into a store to buy cigarettes. The internet is even more anonymous, remote-controlled, and wild-west. What makes us think…

But we can do age verification that's as strict as buying cigarettes and sacrifice next to no privacy.

https://news.ycombinator.com/item?id=46447282 That should be good enough for anyone, unless their real motive is to force everyone to upload their IDs.

Post reply on HN