This reminds me of being refused entry to a nightclub in the US because I’d forgotten my passport, even though I had a European ID card and I’m over 40. Offline, age checks already often become rigid “approved identity document” checks. Online, that problem seems even worse, because the check can become a persistent identity layer across the web.
What we call "age verification" is actually mass surveillance
411–420 of 520 posts
Re: What we call "age verification" is actually mass surveillance
#412> "Age verification" means that everyone who does anything online will have to submit to fine-grained tracking and recording of all their online activities. its been said 1000 times here, but: age verification doesn't have to be a nightmare dystopia of 24/7 fine-grained tracking and recording unless you are somehow hoping to achieve 100% success rate (something we have not done with any other law ever). there are sev…
Re: What we call "age verification" is actually mass surveillance
#413Am I the only one who looked at NSFW websites at 10 years old and played games with voice chat with players of all ages too, and I turned out to be well adjusted productive member of society? People need to chill.
Re: What we call "age verification" is actually mass surveillance
#414Earlier quoted context omitted.
For starters here, the difference is that only devices that parents give to kids need to have secure boot and controlled software sources. The point is that every other device remains completely unaffected. But in general there is a huge difference between the freedom-destroying properties of secure boot with closed app stores, and the next step of remote attestation. Remote attestation lets the server insist that yo…
No, thank you. As a parent, I want to give a device to my child that they can hack, just like I had. Why are we treating kids like adversarial threats? If my kid gets around parental controls, I’ll revoke their phone privileges. No need for invasive security.
Yes, as a parent you should be able to say this! You should also be able to say other things like I want my kid to have full access to wikipedia. Or I do not want my kid to have access to Faceboot, including a special Faceboot4Kidz version that their corporate attorneys have declared is completely suitable for minors.
My whole point arguing for client side controls is that it allows parents to express these types of fine-grained preferences, without merely putting the onus on tech companies to make these decisions in a top-down fashion serving their own self interest!
As for secure boot specifically, my point is that it is already here on basically every phone. One of the most security-forward phone OSs (Graphene) even requires it. I've got philosophical problems with manufacturers baking privileged backdoor keys into hardware, but it's already prevalent. If you think I'm arguing in favor of restrictions, then please go educate yourself on the security properties of remote attestation to see what I'm actually arguing in favor of heading off!
Re: What we call "age verification" is actually mass surveillance
#415Earlier quoted context omitted.
You're mixing up false positives and false negatives. Nobody is going to be incorrectly blocked under this system unless they lost their ID, and the fix there is getting a new ID. Some kids skipping the block sometimes isn't catastrophic, especially because there won't be all this peer pressure to join adult social media when 90% or more are blocked.
You know this? My guess is that companies will be held responsible for anyone accessing there content that is not supposed to. In that light they will feel the need to block any unknowns that come through rather than potentially face issues if someone who is technically banned from accessing gets in. I'm not sure how you confidently can say that every company is going to allow the people we can't verify have access?
If you're talking about other unknowns, you need to explain why they're unknowns.
Re: What we call "age verification" is actually mass surveillance
#416The slippery slope argument is hugely valid, but having kids not have access to alcohol, porn and guns is very normal. We don't even discuss it in the 'physical world' because it's absolutely normative. Even in 'Europe' kids aren't going into the liquor store stocking up obviously - there are always age and responsibility-related conventions. The 'online' nature of this piques our anti-authoritarian triggers and tend…
The analogy would be an alcohol shop employee with a photographic and infinite memory which then staples an AirTag to your skin to see where you're headed off after you've purchased your booze
Re: What we call "age verification" is actually mass surveillance
#417The slippery slope argument is hugely valid, but having kids not have access to alcohol, porn and guns is very normal. We don't even discuss it in the 'physical world' because it's absolutely normative. Even in 'Europe' kids aren't going into the liquor store stocking up obviously - there are always age and responsibility-related conventions. The 'online' nature of this piques our anti-authoritarian triggers and tend…
We discuss age requirements in the physical world not much because the physical world allows age checks without mass surveillance.
Re: What we call "age verification" is actually mass surveillance
#418Earlier quoted context omitted.
It doesn't even need 'age verification'. Ostensibly, the goal is to prevent children from accessing content their parents don't want them to see. That means all that's needed is a standard way for parents to make sure that websites know their children are children. They don't need identity, they don't need actual age, we don't even need a complicated cryptographic solution. California had the right idea - establish a…
> Ostensibly, the goal is to prevent children from accessing content their parents don't want them to see This is not even ostensibly the goal. Ostensibly, the goal is that the government controls what a child can do.
Re: What we call "age verification" is actually mass surveillance
#419Earlier quoted context omitted.
No, thank you. As a parent, I want to give a device to my child that they can hack, just like I had. Why are we treating kids like adversarial threats? If my kid gets around parental controls, I’ll revoke their phone privileges. No need for invasive security.
> No, thank you Yes, as a parent you should be able to say this! You should also be able to say other things like I want my kid to have full access to wikipedia. Or I do not want my kid to have access to Faceboot, including a special Faceboot4Kidz version that their corporate attorneys have declared is completely suitable for minors. My whole point arguing for client side controls is that it allows parents to express…
I’m well educastes on what remote attestation means, and I know it’s the status quo. But it is not required by law. And I’d very much like for it to continue being optional indefinitely, and not bundled with a different “save the children” law.
More specifically, I don’t want to have to prove to the OEM that I’m an adult to unlock my bootloader or disable SecureBoot. Or, more realistically, I don’t want OEMs deciding it’s cheaper to stop offering that choice because they don’t want to risk unlocking the bootloader on a child’s device.