Live data from Hacker News

What we call "age verification" is actually mass surveillance

pluralistic.net

291–300 of 520 posts

Re: What we call "age verification" is actually mass surveillance

#291

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

> Could you be more specific as to what you're imagining? sure, i'll put my favorite two. though you'll find much more detailed and thought-out versions of these (and others) in the dozens of other giant threads on the same topic. - buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is no…

> - websites issue content tags, browsers consume them, you enter your age into the OS during setup.

Why would that be acceptable though? What if a user does not trust the operating system? Even Linux may not be safe in the future, what with age sniffing coming by Red Hat integrating it into system already. And Red Hat plans more - xorg is abandoned on purpose, for instance.

Re: What we call "age verification" is actually mass surveillance

#292
post #96

Earlier quoted context omitted.

HN uses magical platform votes.

And it should be transparent about it. When Dan uses a magic lever, it should be visible.

Would Facebook be okay if all the Nazi propaganda posts were tagged "Facebook boosted this post"?

Re: What we call "age verification" is actually mass surveillance

#293

> "Age verification" means that everyone who does anything online will have to submit to fine-grained tracking and recording of all their online activities. its been said 1000 times here, but: age verification doesn't have to be a nightmare dystopia of 24/7 fine-grained tracking and recording unless you are somehow hoping to achieve 100% success rate (something we have not done with any other law ever). there are sev…

It doesn't even need 'age verification'. Ostensibly, the goal is to prevent children from accessing content their parents don't want them to see. That means all that's needed is a standard way for parents to make sure that websites know their children are children. They don't need identity, they don't need actual age, we don't even need a complicated cryptographic solution. California had the right idea - establish a…

or don't put the burden on the website at all, but let the parent choose whitelists of child-appropriate sites based on whatever criteria they want.

Re: What we call "age verification" is actually mass surveillance

#294

Earlier quoted context omitted.

Could you be more specific as to what you're imagining? I don't personally see a way to verify someone's age which doesn't involve either credit card verification, photo id verification, or some sort of facial recognition. If you know enough about someone to verify their age—even to a relatively low degree of accuracy—you probably know enough to pinpoint who they are in general. Heck—in most cases, we can't even tell…

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

There is no real practical difference between ‘attested devices’ and scanning ID…

Re: What we call "age verification" is actually mass surveillance

#295
post #238

Earlier quoted context omitted.

If you use physical ids to verify your identity, they normally verify that your face matches the image on the id, no? That’s not possible for web id.

Doppelgängers Don’t Just Look Alike—They Also Share DNA https://www.smithsonianmag.com/smart-news/doppelgangers-dont...

Yeah, but being able to share Id with someone who happens to look eerily like you is different from just handing people your ID and they are able to use it like it was implied. That’s not how IDs are used.

Re: What we call "age verification" is actually mass surveillance

#296
post #219

Earlier quoted context omitted.

If they have access to the "dark web" they can already do anything that requires age verification there. In the same way you expect that the rule to "not sell UUIDs" wouldn't be respected there, I wouldn't expect other age-verification rules to be respected, no matter the verification method.

Well, it's rather harder to sell bottles of beer on the dark web than short text strings.

That is true, it is harder, although AFAIK people do sell all kinds of illegal things there.

Re: What we call "age verification" is actually mass surveillance

#297
post #113
post #61

Earlier quoted context omitted.

> UUID card is non-identifying. Kids aren't going to trade Pokemon cards in the playground anymore...

Well, they could trade identifying ones too or even stollen ID cards if you want to go this way. They could also trade porn-filled thumb drive or old-school glossy paper magazine. There no way to prevent kid's exposure to stuff at a 100% success rate. There no way to avoid exposure completely

Indeed but you are the one who claimed it was not a hard problem.

I don't think any one of us pushing back here on those claims do so for the heck of NOT finding a "solution", rather genuinely asking because so far it seems nobody did find such a solution without compromises that is in the end not worth it due to the flaw in said solution.

The point isn't to be critical of your process, only of the claim that it's a trivial problem.

Re: What we call "age verification" is actually mass surveillance

#298

> "Age verification" means that everyone who does anything online will have to submit to fine-grained tracking and recording of all their online activities. its been said 1000 times here, but: age verification doesn't have to be a nightmare dystopia of 24/7 fine-grained tracking and recording unless you are somehow hoping to achieve 100% success rate (something we have not done with any other law ever). there are sev…

It doesn't even need 'age verification'. Ostensibly, the goal is to prevent children from accessing content their parents don't want them to see. That means all that's needed is a standard way for parents to make sure that websites know their children are children. They don't need identity, they don't need actual age, we don't even need a complicated cryptographic solution. California had the right idea - establish a…

[dead]

Re: What we call "age verification" is actually mass surveillance

#299

Earlier quoted context omitted.

The way identity wallets work: The government issues an eID to your wallet. The ID is signed by the government and linked to the device to prevent transferring the credential. A public/private key-pair is generated by the secure enclave in your phone, the public key along with proof of possession of the private key is included in the request for the government eID. The government signs individual attributes combined…

> The website only sees the ‘over_18’ attribute, which is backed by the government signature Not true. The device's public key is also sent, which functions as a stable device identifier. We've spent years trying to get away from stable tracking IDs and fingerprinting. Returning to a system where devices are sending a stable ID to a website to prove ownership is a step backward. There are proposed mitigations like is…

There are schemes where you don't need key pairs for each user (assuming the government has some way of authenticating users). Private State Tokens use blinded tokens for this.

It doesn't prevent tokens from being stolen or sold, but the token issuer only accepts each token once and can limit the rate that tokens are issued and control how fast they expire, giving decent control over how practical using stolen or sold tokens are.

Re: What we call "age verification" is actually mass surveillance

#300

Earlier quoted context omitted.

That's because you're treating AV as a system that must be 100% correct immediately. This isn't banking or an election. As soon as you loosen off the requirements to "reasonable effort", you can start looking at account age, facial features, social attestation, and include retrospective tools to revisit someone's verification if they get in and start acting like a child. Heuristically messy but far from impossible to…

I understand it doesn't need to be 100% correct. But I think what you're describing is either (A) going to be very privacy invasive, (B) going to create problems for lots of adults, or (C) going to be precisely as effective as a checkbox saying "I agree I am over 18 years old".

It's "social media". The whole thing is profiling for advertisers. The idea that there's privacy is laughable.

There is a network effect as a child's peers stop using social media though. Make it inconvenient enough for enough for kids and they'll read a book, take up slam poetry or whatever it was kids did before our attention became currency.

Post reply on HN