Live data from Hacker News

What we call "age verification" is actually mass surveillance

pluralistic.net

241–250 of 520 posts

Re: What we call "age verification" is actually mass surveillance

#241

Earlier quoted context omitted.

Some probably will. 99% of them don't even know what "Chromium" is. This doesn't have to be perfect.

Right now, they don't know. They're going to learn very quickly when they want to use some website and they can't. We agree it doesn't need to be 100% perfect. But it needs to be at least, like, 60% perfect, right? And unless you make it at least a bit hard to bypass, it will stop virtually no one.

Some undoubtedly will.

Installing a new browser is already a bit hard for most people. I think you are a little skewed in your thinking being online on HN.

You also aren't thinking about age. Certainly 16 and 18 year old probably can get a new browser installed. But a 14 year old? 12 year old? 10 year old? That barrier is a lot higher the younger a kid is.

Re: What we call "age verification" is actually mass surveillance

#242
post #216

Earlier quoted context omitted.

Because those things cost money to make and to maintain, whereas there's no intrinsic cost to prove one is an adult.

Yes there is. You need to pay for a drivers license or a passport and so on. So there is an intrinsic cost to prove who you are where you are from and what your birthday is already. You have to pay for all sorts of small things to participate in normal society. This isn't a serious criticism. By definition this is not a life critical thing, it's something that is procured in order to access specific services on the i…

>You need to pay for a drivers license or a passport and so on.

I have a government ID and I didn't pay for it. I can use it to travel to nearby countries in lieu of a passport. The assumption that IDs are necessarily non-free (to the issuee) is pretty funny to me.

>it's something that is procured in order to access specific services on the internet, which is not free.

The maintenance of the Internet is already paid for through ISP contracts.

Re: What we call "age verification" is actually mass surveillance

#243

I don’t think saving them from spying is the main concern. Instead it’s the direct negative effects of the usage upon the kids that’s the concern. Not that age verification isn’t problematic

Then ban underage smartphones altogether, that would probably make the single biggest improvement in child safety and mental health. Trying to police content is an utter waste of time.

Re: What we call "age verification" is actually mass surveillance

#244
The slippery slope argument is hugely valid, but having kids not have access to alcohol, porn and guns is very normal. We don't even discuss it in the 'physical world' because it's absolutely normative.

Even in 'Europe' kids aren't going into the liquor store stocking up obviously - there are always age and responsibility-related conventions.

The 'online' nature of this piques our anti-authoritarian triggers and tends to err our judgment a bit.

There are valid reasons to do this, and there is 'a right way' - maybe we should have some hope and promote that.

I'm not hugely optimistic that they'll get it right, but we should aspire for to build the world we want. There's enough momentum that it's plausible.

Re: What we call "age verification" is actually mass surveillance

#245
post #38
post #26

Earlier quoted context omitted.

Sure here's one example of decentralizing it -- it's going to be overly simple just as a toy example to show how easy it could be: Whenever you want to prove your adult you go to "am I an adult.gov" and you use your credit card or whatever to prove you are an adult. At which point you get a 1-time 5-digit code that is UNIVERSAL TO EVERY SINGLE HUMAN and good for 1 hour (everybody who uses the site gets the same code…

Headline news: children infiltrate the universal adult one time password scheme for porn, parents panic! Turns out the 18 year olds started selling access to their younger friends, who resold it to their younger friends.

are you kidding? there will always be a million porn sites not hosted in the US that everybody will have access too.

This sort of pedantry is really just supporting the opposition.

Re: What we call "age verification" is actually mass surveillance

#246

In Canada the approach is going to be that social media and AI companies will need to figure out a system where those under 16 can’t access content. The government will be able to grant exemptions if the company can satisfy regulators that they have built and maintained adequate, alternative structural safeguards to protect children on their platform. Further to that, companies are required to do this in a strict dat…

> The internet has grown into a bit of a letdown to some degree, especially social media.

You have a flair for understatement.

> If I have to upload an ID or insert a grey hair into a scanner, that website or app will be dead to me and I will move on to something else or nothing at all.

Same. I joke that when I retire I'm throwing out every computer in my house. Turns out the gov't may effectively do that for me, because I will not be handing out my ID to web sites. That is a hard line for me.

Re: What we call "age verification" is actually mass surveillance

#247

> "Age verification" means that everyone who does anything online will have to submit to fine-grained tracking and recording of all their online activities. its been said 1000 times here, but: age verification doesn't have to be a nightmare dystopia of 24/7 fine-grained tracking and recording unless you are somehow hoping to achieve 100% success rate (something we have not done with any other law ever). there are sev…

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

just do what they did in Leisure suit Larry, ask some skill testing questions that only someone older than 18 would know. Give them a short time to answer so they can't look it up.

Re: What we call "age verification" is actually mass surveillance

#248
post #149

The main problem is providing infrastructure for a government that can over use it in future if move to ultra right/left/authoritarian spectrum Just for example Russia build infrastructure for blocks website for child safety, but it started to used much further

> The main problem is providing infrastructure for a government that can over use it in future if move to ultra right/left/authoritarian spectrum

The US is an instructive example in real time. Roughly everyone worries about what happens when their opponent gains control of the government and then promptly forgets how much they worried when their side has it.

Re: What we call "age verification" is actually mass surveillance

#249

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

If you are referring to EUID (not fully sure as you said EU eID, i dont know if you are referring the estonia of eID like system)

I have to mention that EUID is not private, since there's "provider" element which informs website if you are 18 or not. The flow is:

1) You scan QR code 2) Your EUDI wallet does verification, informs provider to tell you are 18+ 3) Provider informs website you are 18+

The EUID draft doesnt mention tech like ohttp for anonymizing requests. So there's risk of provider keeping track of who you are. So while everybody claims its fully anonymous which is just false. Government could ask website/service for the token or account information then use timestamp or token then combining with "provider" logs, your identity will be exposed.

EUID has another problem which is letting all countries implement system, which is wasteful duplication effort so this probably will be outsourced and to same company to reduce duplication efforts. Then it'll be centralized and they happen be collecting telemetry data for "experience improvements" as everysite out there do.

I haven't even mentioned biggest problems like requiring attestation Apple/Google. While spec doesn't require it, but the likehood country's app requiring it will be very high.

Re: What we call "age verification" is actually mass surveillance

#250
post #239

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

you generate a random number and send it to website you want to visit. Website you want to visit generates a one-time private/public key for the purpose of this login attempt, hashes your random number, and sends the hash back to you. You connect to the government auth platform, auth yourself to your government, and ask them to sign the hash you received. You pass the signed hash as well as the original random number…

> Sure, it won't hold up against collusion between website and government, but nothing would.

Right, so it's just privacy theatre.

Post reply on HN