Live data from Hacker News

GrapheneOS refuses to comply with new age verification laws for operating system

tomshardware.com

141–150 of 171 posts

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#141
post #54

Earlier quoted context omitted.

What are you talking about, most households give personal phones to their children, especially teenagers. Laptops aren't rare either.

Once you get outside the SV and NYC bubbles, the vast majority of kids do not have their own laptops in the US. Phones, obviously are somewhat more common, but as even you note that's mainly with regard to teenagers - the average 10 year old in middle America does not have their own phone.

Most of these kids have their own tablets though:

> By 2 years old, 4 in 10 children have their own tablet (40%), and by 4 years old, more than half of children (58%) do.

Tablet ownership rises to 68% at age 8.

https://www.commonsensemedia.org/sites/default/files/researc...

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#142
post #74

Can someone catch me up how FB et al are not the ones responsible for age verification? Is it lack of something similar to PKI for identify verification?

Why would you want every site on the internet to traffic in government IDs? This is by far the least bad out of all possible ways to implement age checking. The benefit of this is that it can short-circuit support for more onerous age verification. The writing has been on the wall for some time now: the era of completely unrestricted internet is coming to an end. The question is how awful will the new normal be? This…

> This is by far the least bad out of all possible ways to implement age checking.

Not quite. The least bad (that I'm aware of) is to mandate RTA headers (or an equivalent more comprehensive self categorization system) and to also mandate that major platforms (presumably OS and browsers, based on MAU or some such) implement support for filtering on those headers.

But sending a binned age as per the California law is the next best thing to that.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#143

Age verification at the OS level makes no sense to me. Most households aren't going to have a separate device for every family member and so you will end up with a tablet or computer set up by one of the parents (and thus having their age stored) that will be used by both parents and children. Likewise, people generally won't create a separate account for every potential user.

> “Most households aren't going to have a separate device for every family member…”

They want us to all to have user accounts and login like well behaved workers. So cute. Little Donald can login for hisself, and doesn’t need mommy to do it for him.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#144

Age verification at the OS level makes no sense to me. Most households aren't going to have a separate device for every family member and so you will end up with a tablet or computer set up by one of the parents (and thus having their age stored) that will be used by both parents and children. Likewise, people generally won't create a separate account for every potential user.

> Age verification at the OS level makes no sense to me

If taken at face value, sure.

The goal of those age verification laws are not age verification.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#145
post #25

In the meantime systemd already added handling for Age to the system bus. Next step is to add your race, then income, then who you voted for...

Why? Why should Linux ever implement local laws like this as core functionality? Especially invasive/anti-privacy ones. If someone wants to introduce an age-verification-ca-module, fine, but not make it core. Yes I understand systemd is not the kernel, but its ubiquitous enough. That just says to every country around the world; Windows, Mac, and even Linux is on board too, let's make it law also! I dunno, I always ex…

> Why? Why should Linux ever implement local laws like this as core functionality?

I have no idea.

But they did actually bend over.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#146

Good on them. Devices shouldn't collect any extraneous data by default other than that needed to fulfill a feature a user consciously selects, and that includes this stupid age verification spyware regimes are pushing. An adult had to pay for the ISP connection; that's the extent of age verification needed. We shouldn't be demanding adults expose their identities to for-profit entities and surveillance states, so muc…

Apps requesting an age is not extraneous and there are many legal and safety reasons why an app may collect this information. If the operating system doesn't do it you run into the cookie banner situation where every individual site has to implement a dialog box asking the user instead of there being a standardized way to do it.

I'll bite: what's the safety reason for an app to ask for age verification?

What kind of apps do you people use that are so dangerous? Does the computer zap you if you misuse the app or what?

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#147
post #109

Earlier quoted context omitted.

Or just not have it at all? What is wrong with parental controls AND parenting? What real issue does this solve?

What is wrong with parental controls AND parenting? Nothing. This has never been about protection of children. It is tracking real identity from every source to every destination otherwise known as user-tracking. If this was about protecting children they would require an RTA header on all adult and user-generated content sites and require the most common user agents to look for that header if parental controls are e…

> It is tracking real identity from every source to every destination otherwise known as user-tracking.

except this is not true at all

yes there are people which try to systematically hijack child protection laws all the time for stuff like that

but e.g. the californium law is very clearly intended to avoid exactly that (that= tracking real identity)

> they would require an RTA header

they are politicians focused on law making, they have no idea what an "header" even is!

A politicians job is to identify issues consult people with expertise, propose a solution based on this people feedback and then listen to feedback, including from other groups. If they need to know what an HTTP header is and how that works something went really wrong.

But this is also where things often do go wrong, by a) dishonest and outright malicious consulting telling politicians bullshit, b) politicians having a over the top simplified understanding of a topic and think that it's still suited for extrapolating things from it leading them to nonsensical outcomes.

And if then large part of the industry which do care about non abusive solutions loudly refuses to provide any solution and denounce anyone trying to do so you are basically opening even more doors for anyone with malicious intentions. Which is pretty much the situation we have now.

Even worse not only do many people in the tech/hacker community not only not try to help with finding an acceptable solution they often outright reject that there is even a problem.

But there is a problem, a huge one even.

As just one dump example of many: it's currently harder for a teenager to get access to some wholesome soft porn then it is to watch potentially traumatizing and definitely not healthy content (weather it's violence, or certain forms of hard core porn(1)), or access sites/apps with gambling, prying on children, hate mongering, glorification of mobbing etc. etc.

And lets not forget most parents are non technical people, which means most of the reasonable usable and privacy protecting existing tools are not actually usable by them (and not available by default, and they can't reasonable evaluate which ones are okay either).

Also please don't say I grew up with a uncontrolled internet (~25-35y) and I am fine. Putting aside that the internet was very different back then. But also hardly anyone in that age range is truly mentally fine (for a lot of reasons, but that anyway makes it a pretty bad argument).

> RTA header

is insufficient, age isn't just 18+ or 13+. Through many media sites love to pretend that is the case

Furthermore this doesn't work for "feed" content as the server needs to know what to filter one before returning content.

But this is also the direction I have proposed in previous comments and not that far away from the direction the Californian law went to (but very much different to the UK law):

- provide a min. age category indicator for all content (most times by app, sometimes per-content in that app, sometimes per-origin per-content in that app (e.g. YT accessed through the browser). But this needs to be more complicated then 13+,18+ as categories differ by country and you should include tags and some other stuff.

- A parent control API which has a simple/naive default impl. but can be replaced with whatever parent think is right.

- A API to get the users age category (incl. localization, e.g. `us:13`). It needs explicit permissions and providers are not allowed to force it, every contents min-age-constraints still have to go through the parent control app. It's only for selecting content feed/preview. The specific content served might still be rejected by the parent controls! Using it for anything else should be made criminal illegal with personal liabilities for executives. (e.g. using it to try to sniff the exact age date of a person). A implementation which just serves `us:18` but then refused anything >13+ or similar must be treated as a legit possibility, the app must still work in general, but it might not have any further previews. Etc. Etc.

- The trust of age hints/evaluation is anchored solely in the parent controls, the setup of the parent controls is the parents responsibility. Any form of identification(2), AI face scans or similar as a requirement for setting up parent controls/not having a permanent 13+ account or similar _is strictly outlawed_.

- All sold products with preinstalled OS must have a default parent control app which is trivially to setup up in it's default setup and the default setup must only reqiore 1. localization (preset to current country if known, changeable), 2. age to auto adapt the age group where alternative the parent can set the age group, even through that means they have to change it in the future manually (needed for special care children). It also in it's default setup must not track/spy on everything the child does.

- Adult accounts still need compatibility with the APIs but will always provide 18+/yes content allowed.

- Products and e.g. downloadable OSes can decide to be "adult only", in which case their access must be guarded like any other adult only content (e.g. when you buy it) but in which case they don't need to support child accounts and can instead return hard coded 18+/yes content allowed.

(This is already the short(er) version :/, e.g. most countries have a 18-21 category, for many countries that category is only irrelevant for things anyway involving a identification (e.g. signing certain contracts, doing certain jobs), but e.g. the US relation to alcohol is an exception).)

---------

(1): And I don't mean just a bit of soft bondage, but things which will lead to serious health issues long term and/or involve violence, glorification of violence, suppression, misogyn, implications of torture, rape, child abuse or in case of drawn/generated content non-implications and even snuff.

(2): There can be some acceptable ways, e.g. a clerk checking your ID IRL, without recording anything except yes/no. Digital ID setups which only communicate adult yes/no without identification etc. But given that all relevant devices tend to be too expensive for children to buy them themself and you also should trust your child if it approaches adulthood (and might have the money) I don't think anything like that is really needed. In general this should focus on efficient solutions for age group <16. IMHO if you still need parent controls for 16+ you messed up parenting.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#148

Earlier quoted context omitted.

Or just not have it at all? What is wrong with parental controls AND parenting? What real issue does this solve?

It solves the problem of your kid borrowing a phone from another kid at school.

no it doesn't

also doesn't need to IMHO

it solves the problem of it being too trivial for a 12 year old to access content which at best is quite problematic and at worst outright traumatizing

as in, the same reason we have laws that a clerk glances at the age on you id if you look young and buy alcohol but your parent are still allowed to let you drink with them if they think its right (or what a 16+ movie with them etc. etc.)

this is also why it really shouldn't be anything much more fancy then parent controls checking min age of content locally / indication of age for feed fetching. Everything else is disproportional (unrelated from all the other issue it might have).

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#149
post #109

Earlier quoted context omitted.

What is wrong with parental controls AND parenting? Nothing. This has never been about protection of children. It is tracking real identity from every source to every destination otherwise known as user-tracking. If this was about protecting children they would require an RTA header on all adult and user-generated content sites and require the most common user agents to look for that header if parental controls are e…

> It is tracking real identity from every source to every destination otherwise known as user-tracking. except this is not true at all yes there are people which try to systematically hijack child protection laws all the time for stuff like that but e.g. the californium law is very clearly intended to avoid exactly that (that= tracking real identity) > they would require an RTA header they are politicians focused on…

A API to get the users age category (incl. localization, e.g. `us:13`). It needs explicit permissions and providers are not allowed to force it,

An API actually means that more and more details about the user will inevitably be added with time. This is a user-trackers dream come true. No thanks. One static header, done and dusted.

But this needs to be more complicated then 13+,18+

I will never agree with this nor will most people. Content is either adult or not adult. That is how existing parental laws are structured in most countries. The parent must decide if the child is ready to view content that is rated anything other than "G". The parent decides, not some app, not some API.

A child account on a tablet, phone, laptop need only prevent tampering with browser settings and by default enable parental controls which in turn simply look for an RTA header or any other indicators that the site or content is adult or user-generated in nature. Keep it simple. If people wont enable looking for a header then the only reason they would go far further and screw with an API would be if it were to the benefit of evil. (marketing, sales, manipulation of the child, manipulation of the parent).

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#150

Earlier quoted context omitted.

> Age verification at the OS level makes no sense to me. it's the only form of "age verification" which can be done in a somewhat privacy respecting way (as in at most leak the age) the idea is to "bounce back" the "is old enough" decision to parent controls and let the parent choose (the Californian law doesn't quite do that perfectly, but goes into that direction) and if you sell what is more or less a general purp…

That's why Meta paid for these os-based age identification laws[1], shifting the responsibility from itself onto the app stores. I agree it's probably preferable to do it on device instead of every website implementing an id check through shady as fuck[2] third parties like Persona. This whole thing is just such a mess though, people rightfully distrust everybody involved, all these bought and paid-for politicians. A…

> They should scrap it all, no more "child safety" laws until we kicked money out of politics.

the current state has been close to that, and is co-associated to be a related to many existing issues wrt. to children/mental health/child safety (I very intentionally use co-associated instead of correlated, and definitely not root cause)

you could say law makers of many countries have given the industry ~30 years time to self regulate and come up with something acceptable by themself

The industry didn't. Now they have to regulate, it's their job and responsibility to do so :(

(but it's also their responsibility to not listen to highly malicious/biased lobbyist trying to hijack it into surveillance laws!)

honestly to some degree the industry still has a short time frame to fix it themself, provide an acceptable solution which can mostly work internationally (by having localization in it) and pitch that to the EU and US states not having yet decided on age verification laws, so that the few which already have some bad laws are pressured to change course

Through the problem is many non-cooperate entities instead insist it's all nonsense and there is no problem and companies like G, MS, Meta etc. have little interest fixing the situation. A misguided, hard to implement age verification law creates a legal moat to hinder smaller competing companies...

we have seen the same with the EU AI act, it's general outline is very reasonable especially if base that assessment on the corner comments. But thanks to big tech lobbyist hijacking it it became a economical/regulatory moat catastrophe (in the details and the parts which have not yet taking effect, not in every aspect).

Post reply on HN