Live data from Hacker News

The Age Verification Trap: Verifying age undermines everyone's data protection

spectrum.ieee.org

151–160 of 1001 posts

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#151

We are missing accessible cryptographic infrastructure for human identity verification. For age verification specifically, the only information that services need proof of is that the users age is above a certain threshold. i.e. that the user is 14 years or older. But in order to make this determination, we see services asking for government ID (which many 14-year-olds do not have), or for invasive face scans. These…

> We are missing accessible cryptographic infrastructure for human identity verification. like most proposed solutions, this just seems overcomplicated. we don't need "accessible cryptographic infrastructure for human identity". society has had age-restricted products forever. just piggy-back on that infrastructure. 1) government makes a database of valid "over 18" unique identifiers (UUIDs) 2) government provides to…

The government will want some way to uncover who bought the token. They'll probably require the store to record the ID and pretend like since it's a private entity doing it, that it isn't a 4A violation. Then as soon as the token is used for something illegal they'll follow the chain of custody of the token and find out who bought it.

No matter what the actual mechanism is, I guarantee they will insist on something like that.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#152

Earlier quoted context omitted.

100% correct. At this point the harms to children from social media use are very well documented. Like everything else in society, there are tradeoffs here, I'm much more concerned with the damage done to children's developing brains than I am to violations of data privacy, so I'm okay with age verification, however draconian it may be.

We need to destroy privacy and anonymity online for the noble goal of the government banning teenagers from looking at Twitter and Instagram? If it's a concern, parents can prevent or limit their children's use. If all this were being done to prevent consistent successful terrorist attacks in the US with tens of thousands of annual casualties, I'd say okay maybe there is an unavoidable trade-off that must be made her…

It isn’t just about teenagers though I think I outlined that? We need to make sure people online are real people and yes we should prevent kids from being exposed to algorithms designed to addict then.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#153

Most of this debate makes more sense if the actual goal is liability reduction, not child safety. If it were genuinely about protecting kids, you'd regulate infinite scroll and algorithmic engagement optimization, not who can log in.

I think it's because there's always a group of nosy busybodies finger-wagging about protecting the children and we have to do decorative theatrics to satiate whatever narratives they've convinced themselves of

This is a group particularly beloved by politicians, because you can pretty much use them as a smokescreen whenever you want to pass authoritarian legislation...

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#154

It's kind of weird to me how every article on this topic here has people rushing to comment within a couple minutes with some generic "yes I too support ID checks for internet use!". Has the vibe really shifted so much among tech-literate people?

I think it's quite embarrassing that the WWW exists since more than 3 decades and still there's no mechanism for privacy friendly approval for adults apart from sending over the whole ID. Of course this is a huge failure of governments but probably also of W3C which rather suggests the 100,000th JavaScript API. Especially in times of ubiquitous SSO, passkeys etc. The even bigger problem is that the average person nee…

SSO and passkeys don't solve adult verification. I don't see how this problem is embarrassing for the www - it's a hard problem in a socially permissible way (eg privacy) that can successfully span cultures and governments. If you feel otherwise, then solutions welcome!

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#155
I am so surprised by the comments on this thread. I was not expecting to see so many people on Hacker News in favor of this. As is typically the case with things like this, the reasoning stems from agreeing with the goal of age verification, with little regard to whether age verification could ever actually work. It reminds me in some sense to the situation with encryption where politicians want encryption that blocks "the bad guys" while still allowing "the good guys" to sneak in if necessary. Sure, that sounds cool, it's not possible though. I suppose DRM is a better analogue here, an increasingly convoluted system that slowly takes over your entire machine just so it can pretend that you can't view video while you're viewing it.

To be clear, tackling the issue of child access to the internet is a valuable goal. Unfortunately, "well what if there was a magic amulet that held the truth of the user's age and we could talk to it" is not a worthwhile path to explore. Just off the top of my head:

1. In an age of data leaks, identity theft, and phishing, we are training users to constantly present their ID, and critically for things as low stakes as facebook. It would be one thing if we were training people to show their ID JUST for filing taxes online or something (still not great, but at least conveys the sensitivity of the information they are releasing), but no, we are saying that the "correct future" is handing this information out for Farmville (and we can expect its requirement to expand over time of course). It doesn't matter if it happens at the OS level or the web page level -- they are identical as far as phishing is concerned. You spoof the UI that the OS would bring up to scan your face or ID or whatever, and everyone is trained to just grant the information, just like we're all used to just hitting "OK" and don't bother reading dialogs anymore.

2. This is a mess for the ~1 billion people on earth that don't have a government ID. This is a huge setback to populations we should be trying to get online. Now all of a sudden your usage of the internet is dependent on your country having an advanced enough system of government ID? Seems like a great way for tech companies to gain leverage over smaller third world companies by controlling their access to the internet to implementing support for their government documents. Also seems like a great way to lock open source out of serious operating system development if it now requires relationships with all the countries in the world. If you think this is "just" a problem of getting IDs into everyone's hands, remember that it a common practice to take foreign worker's passports and IDs away from them in order to hold them effectively hostage. The internet was previously a powerful outlet for working around this, and would now instead assist this practice.

3. Short of implementing HDCP-style hardware attestation (which more or less locks in the current players indefinitely), this will be trivially circumvented by the parties you're attempting to help, much like DRM was.

Again, the issues that these systems are attempting to address are valid, I am not saying otherwise. These issues are also hard. The temptation to just have an oracle gate-checker is tempting, I know. But we've seen time and again that this just (at best) creates a lot of work and doesn't actually solve the problem. Look no further than cookie banners -- nothing has changed from a data collection perspective, it's just created a "cookie banner expert" industry and possibly made users more indifferent to data collection as a knee-jerk reaction to the UX decay banners have created on the internet as a whole. Let's not 10 years from now laugh about how any sufficiently motivated teenager can scan their parent's phone while they're asleep, or pay some deadbeat 18 year-old to use their ID, and bypass any verification system, while simulateneously furthering the stranglehold large corporations have over the internet.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#156

Everything is a trade off in the world. I think that people who are anti-id ignore this but for me personally it’s harder and harder to accept the trade offs of an internet without id. AI has only accelerated this, I don’t want to live in a world where the average person unknowingly interacts with bots more than other individuals and where black market actors can sway public opinion with armies of bots. I think most…

You're not thinking more than one step ahead. If you let a third party define who "has ID", "is human", etc. you give that third party control over you. You already gave control of your attention away to the sites who host the UGC, now you also give away control of your sense of reality. At any point they can tell a real human what they can and can't say, and if they go against their masters, their "real human" statu…

I am though. In the world I live in I already have to give power over myself to corporations and a government, I don’t buy this as an argument for continuing to let internet companies skirt existing laws.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#157

Earlier quoted context omitted.

> We are missing accessible cryptographic infrastructure for human identity verification. like most proposed solutions, this just seems overcomplicated. we don't need "accessible cryptographic infrastructure for human identity". society has had age-restricted products forever. just piggy-back on that infrastructure. 1) government makes a database of valid "over 18" unique identifiers (UUIDs) 2) government provides to…

The government will want some way to uncover who bought the token. They'll probably require the store to record the ID and pretend like since it's a private entity doing it, that it isn't a 4A violation. Then as soon as the token is used for something illegal they'll follow the chain of custody of the token and find out who bought it. No matter what the actual mechanism is, I guarantee they will insist on something l…

if the goal is to "protect children", or just generally make parts of the internet age-gated, my proposal is 100% fine.

if the goal is "surveil everyone using the internet", yes, very obviously my proposal would not be selected, and you will have to upload your id to various 3rd-party id verifiers.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#158

Everything is a trade off in the world. I think that people who are anti-id ignore this but for me personally it’s harder and harder to accept the trade offs of an internet without id. AI has only accelerated this, I don’t want to live in a world where the average person unknowingly interacts with bots more than other individuals and where black market actors can sway public opinion with armies of bots. I think most…

No the argument is bad actors will reliably find a way to bypass these systems at an industrial scale while you'll instead snag honest people instead.

Look at the facebook real name policy.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#159

It's kind of weird to me how every article on this topic here has people rushing to comment within a couple minutes with some generic "yes I too support ID checks for internet use!". Has the vibe really shifted so much among tech-literate people?

The vibe has shifted quite a bit among the general populace, not just in tech.

The short version is that voters want government to bring tech to heel.

From what I see, people are tired of tech, social media, and enshittified apps. AI hype, talk of the singularity, and fears about job loss have pushed things well past grim.

Recent social media bans indicate how far voter tolerance for control and regulation has shifted.

This is problematic because government is also looking for reasons to do so. Partly because big tech is simply dominant, and partly because governments are trending toward authoritarianism.

The solution would have been research that helped create targeted and effective policy. Unfortunately, tech (especially social media) is naturally hostile to research that may paint its work as unhealthy or harmful.

Tech firms are burned by exposés, user apathy, and a desire to keep getting paid.

The lack of open research and access to data blocks the creation of knowledge and empirical evidence, which are the cornerstones of nuanced, narrowly tailored policy.

The only things left on the table are blunt instruments, such as age verification.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#160

It's kind of weird to me how every article on this topic here has people rushing to comment within a couple minutes with some generic "yes I too support ID checks for internet use!". Has the vibe really shifted so much among tech-literate people?

I think it's quite embarrassing that the WWW exists since more than 3 decades and still there's no mechanism for privacy friendly approval for adults apart from sending over the whole ID. Of course this is a huge failure of governments but probably also of W3C which rather suggests the 100,000th JavaScript API. Especially in times of ubiquitous SSO, passkeys etc. The even bigger problem is that the average person nee…

> and still there's no mechanism for privacy friendly approval for adults apart from sending over the whole ID. Of course this is a huge failure of governments but probably also of W3C

I consider it a huge success of the Internet architects that we were able to create a protocol and online culture resilient for over 3 decades to this legacy meatspace nonsense.

> That being said, this is a 1 bit information, adult in current legislation yes/no.

If that's all it would take to satisfy legislatures forever, and the implementation was left up to the browser (`return 1`) I'd be all for it. Unfortunately the political interests here want way more than that.

Post reply on HN