Live data from Hacker News

Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

github.com

131–140 of 1001 posts

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#131
I don't understand it . There are so many ways to child-proof a device . Google Family Link and the Apple equivalent . Use cloudflares Family dns (blocks porn websites etc ..)

Instead of just creating a course that explains how to child-proof a device, we have to surveil everyone.

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#132

Earlier quoted context omitted.

I am from EU, and contrary to age verification laws in general. My stance is that if somebody is a minor, his/her/their parents/tutors/legal guardian are responsible for what they can/cannot do online, and that the mechanism to enforce that is parental control on devices. Having said that, open-source zero-knowledge proofs are infinitely less evil (I refuse to say "better") than commercial cloud-based age monitoring…

> Having said that, open-source zero-knowledge proofs are infinitely less evil (I refuse to say "better") than commercial cloud-based age monitoring baked into every OS To be honest, I worry that the framing of this legislation and ZKP generally presents a false dichotomy, where second-option bias[1] prevails because of the draconian first option. There's always another option: don't implement age verification laws a…

App and website developers shouldn't be burdened with extra costly liability to make sure someone's kids don't read a curse word, parents can use the plethora of parental controls on the market if they're that worried.

App and website operators should add one static header. [1] That's it, nothing more. Site operators could do this in their sleep.

User-agents must look for said header [1] and activate parental controls if they were enabled on the device by a parent. That's it, nothing more. No signalling to a website, no leaking data, no tracking, no identifying. A junior developer could do this in their sleep.

None of this will happen of course as bribery (lobbying) is involved.

[1] - https://news.ycombinator.com/item?id=46152074

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#133
post #101

Earlier quoted context omitted.

I believe CFAA talks about exceeding authorization, not just typing in things that are not true.

CFAA has been narrowed in scope through legal decisions but AFAIK it still applies to anyone using false information to bypass security measures. In my view, a federal prosecutor could easily make the argument that age gating is a security measure. You’re welcome to be a test case if you disagree!

But are you bypassing a security measure if you provide false information, when true information would also have let you pass?

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#134

I don't understand it . There are so many ways to child-proof a device . Google Family Link and the Apple equivalent . Use cloudflares Family dns (blocks porn websites etc ..) Instead of just creating a course that explains how to child-proof a device, we have to surveil everyone.

Because they’re not really trying to protect kids.

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#135
post #28
post #2

I am now waiting for Gruber (daringfireball.net) to post another rant about how terrible EU regulation is. Zero-knowledge proofs are the way to go for this type of thing, I find it mind-boggling that the US lets itself be bamboozled into complete lack of privacy.

Even with ZKP this is still highly problematic, it create difficulty for undocumented people to access the web, create ton of phishing opportunity, reinforce censorship on most site (as they will now all need to be minor compliant or need age verification), reinforce the chilling effect and make the web even less crawlable/archivable (or you need to give a valid citizen ID to your crawler/archiver). With no proof it…

>it create difficulty for undocumented people to access the web

Why is this such a sticking point in US politics? If the "undocumented" people aren't supposed to be in the country in the first place, why should rest of society cater to them? Even if you're against age verification for other reasons, dragging in the immigration angle is just going to alienate the other half of the population who don't share your view on undocumented people, and is a great way to turn a non-partisan issue into a partisan one. It's kind of like campaigning for medicare for all, and then listing "free abortions and gender affirming surgery" as one of the arguments for it.

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#136
for ~2 decades i have attended events, written to my representatives, proposed solutions to whoever i can, and encouraged my students to do the same as various attempts are made to strip regular people of their privacy. for ~2 decades now, i have been trying to fight this fight.

one scary observation is that each year, less and less people care. at least, this is true among my students. plenty of them believe the 'protect the children' line and are more than willing to do whatever the government/big tech suggests. or they just shrug ("what difference would i make?").

for context, i teach at a college level, in tech. a few of my classes are from the cybersec program, one of the programs that should understand and care about the implications of bills like these, and even the majority of them do not care about this stuff anymore. they grew up with instagram and facebook and cameras everywhere. they grew up knowing that any little fuck up they have is recorded and posted online. they know that by the time they go to college, all of their data has already been leaked a few times. they never really had an expectation of privacy in the first place, so it just isnt a big deal.

as someone who interacts with this next generation of "hackers" on a daily basis... the concept of cypherpunk is gone. i got into this field because of my beliefs. they are going into this field because they want a chance at buying a house some day, and know that big tech has big bucks.

i am tired. and i recognize that this is exactly what they (lobbyists, meta, etc.) want! but i am tired and discouraged. more and more i find myself having to actively fight the urge to give up. i am not ready to give up just yet... but, i am sorry to say that as someone closer to retirement than i am comfortable admitting, i only have so much energy left.

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#137

The idea that it might cost "someone" $2 every time a user opens and app AND it sends a bunch of private data to a 3rd party is completely dystopian, let alone everything else. And a serious question: with deepest respect to the author for their extraordinarily impressive time and effort in this investigation... Why was this not already flagged by political reporters or investigative journalists? I'm not American so…

When a megacorp funds a network of non-profits to lobby a bunch of politicians, draft legislation, and tell them to take it to committee, that can happen without much visibility, especially when it's been orchestrated at the state level, as this has. Where does any of this show up until there's a vote called on it? There's no open debate. No working "across the aisle" to address concerns. There's nothing left of the legislative process that started this country, or, indeed, any Western representative democracy. So someone has to be watching, see something on an agenda that raises the hairs on their necks, figure out what it is, and if there's a story there, and they're not going to get any help from anyone because everyone involved knows how the public is going to feel about it. And then, as the article indicates, even a place like Reddit is going to astroturf the effort to get the story out. (Which I've been trying to point out for YEARS, but which -- surprise, surprise! -- gets supressed.)

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#138

Earlier quoted context omitted.

CFAA has been narrowed in scope through legal decisions but AFAIK it still applies to anyone using false information to bypass security measures. In my view, a federal prosecutor could easily make the argument that age gating is a security measure. You’re welcome to be a test case if you disagree!

But are you bypassing a security measure if you provide false information, when true information would also have let you pass?

Again, you’re welcome to be a test case.

I do think there is a stronger case against the next under-18 Aaron Swartz, who will get hit with 200 felonies for setting his age wrong (one felony per app/service) after pissing off someone important.

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#139

I don't understand it . There are so many ways to child-proof a device . Google Family Link and the Apple equivalent . Use cloudflares Family dns (blocks porn websites etc ..) Instead of just creating a course that explains how to child-proof a device, we have to surveil everyone.

Because they’re not really trying to protect kids.

Please scan your asshole to use the toaster.

It's to save the kids.

We care about the kids. We don't bomb them.

Re: Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

#140
post #2

I am now waiting for Gruber (daringfireball.net) to post another rant about how terrible EU regulation is. Zero-knowledge proofs are the way to go for this type of thing, I find it mind-boggling that the US lets itself be bamboozled into complete lack of privacy.

I am from EU, and contrary to age verification laws in general. My stance is that if somebody is a minor, his/her/their parents/tutors/legal guardian are responsible for what they can/cannot do online, and that the mechanism to enforce that is parental control on devices. Having said that, open-source zero-knowledge proofs are infinitely less evil (I refuse to say "better") than commercial cloud-based age monitoring…

> My stance is that if somebody is a minor, his/her/their parents/tutors/legal guardian are responsible for what they can/cannot do online, and that the mechanism to enforce that is parental control on devices.

Imho there is a place for regulation in that, actually. Devices that parents are managing as child devices could include an OS API and browser HTTP header for "hey is this a child?" These devices are functionally adminned by the parent so the owner of the device is still in control, just not the user.

Just like the cookie thing - these things should all be HTTP headers.

"This site is requesting your something, do you want to send it?

Y/N [X] remember my choice."

Do that for GPS, browser fingerprint, off-domain tracking cookies (not the stupid cookie banner), adulthood information, etc.

It would be perfectly reasonable for the EU to legislate that. "OS and browsers are required to offer an API to expose age verification status of the client, and the device is required to let an administrative user set it, and provide instructions to parents on how to lock down a device such that their child user's device will be marked as a child without the ability for the child to change it".

Either way, though, I'm far more worried about children being radicalized online by political extremists than I am about them occasionally seeing a penis. And a lot of radicalizing content is not considered "adult".

Post reply on HN