Live data from Hacker News

GrapheneOS refuses to comply with new age verification laws for operating system

tomshardware.com

151–160 of 171 posts

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#151

Earlier quoted context omitted.

> Next step is to add your race, then income, then who you voted for https://en.wikipedia.org/wiki/Slippery_slope

From your link: > non-fallacious forms of the argument can also exist.[7]: 273–311

Yes they can, but claiming a theoretical future event as fact (or inevitable) I would consider particularly fallacious as it's impossible to prove.

And I think history also shows these claims rarely end up happening the way these alarmists think it will.

Usually when a slope appears, regulation steps in, technology evolves, or the culture shifts, rather than society devolving into some inescapable dystopian hellscape.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#152
post #149

Earlier quoted context omitted.

> It is tracking real identity from every source to every destination otherwise known as user-tracking. except this is not true at all yes there are people which try to systematically hijack child protection laws all the time for stuff like that but e.g. the californium law is very clearly intended to avoid exactly that (that= tracking real identity) > they would require an RTA header they are politicians focused on…

A API to get the users age category (incl. localization, e.g. `us:13`). It needs explicit permissions and providers are not allowed to force it, An API actually means that more and more details about the user will inevitably be added with time. This is a user-trackers dream come true. No thanks. One static header, done and dusted. But this needs to be more complicated then 13+,18+ I will never agree with this nor wil…

> An API actually means that more and more details about the user will inevitably be added with time.

with that logic you could also argue a computer means more APIs will be added over time

especially if it's a law mandated API which doesn't allow any additional thing this really isn't a problem

> I will never agree with this nor will most people

except overall (at least outside no HN bubble) most people would disagree with you, actually the huge majority of parents and children affected by that would disagree

Treating a 16 year old like they are 13 is just completely absurd.

Expecting parent to make decisions about every single peace of content (website, YT, video) their child, even if older, watches without providing any guidance and defaults is not practical at all and due to that is guaranteed to fail.

To be frank you comment is completely quixotic, lacking any relation to the reality most parents live in today.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#153

Earlier quoted context omitted.

> Age verification at the OS level makes no sense to me. it's the only form of "age verification" which can be done in a somewhat privacy respecting way (as in at most leak the age) the idea is to "bounce back" the "is old enough" decision to parent controls and let the parent choose (the Californian law doesn't quite do that perfectly, but goes into that direction) and if you sell what is more or less a general purp…

Ideally, they'd require OS (desktop and mobile) to have an adult mode and a restricted mode (set up by the adults when they buy the device), and then let third-party apps confirm the status (e.g., age) in the latter case. Then you have minimal privacy issues and many parents actually want something like this.

yes pretty much

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#154

Earlier quoted context omitted.

You'd need to closely read the law and have a lawyer advise you, but a neat attempt might be to just ask for the date of birth, send that "in real time" to the App Store program, and then have that program simply discard it? I don't think current iterations of the law require that this be sent off-device in any way.

The second requirement of the California law is that there be an API available to all apps that returns the age band a user is in -- one of: age age >= 13 && age age >= 16 && age age >= 18 A non-maliciously compliant implementation would need to retain a date of birth or equivalent until the user was over 18. A maliciously compliant API could just wait 18 years after account creation before yielding an answer. (remem…

> One of the oddities about the way the law is phrased is that it requires the age band information about the user be provided to "the developer" rather than to the application.

So, expose it via a Unix socket only accessible to the account named "developer"?

Only half joking.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#156
post #149

Earlier quoted context omitted.

A API to get the users age category (incl. localization, e.g. `us:13`). It needs explicit permissions and providers are not allowed to force it, An API actually means that more and more details about the user will inevitably be added with time. This is a user-trackers dream come true. No thanks. One static header, done and dusted. But this needs to be more complicated then 13+,18+ I will never agree with this nor wil…

> An API actually means that more and more details about the user will inevitably be added with time. with that logic you could also argue a computer means more APIs will be added over time especially if it's a law mandated API which doesn't allow any additional thing this really isn't a problem > I will never agree with this nor will most people except overall (at least outside no HN bubble) most people would disagr…

Random person jumping in to say, the original comment from 'Bender' is what is agreed with by almost every human I've spoken to. It is most definitely the take of every parent in my social circle, the vast majority of whom are outside of the tech space.

The issue you're describing is strictly one of parenting, and not one that can or should be handled via some government agency. Their (Bender's) suggestion is actually the best that I've seen for handling this issue, and the only one I believe those I know would all happily agree with.

On a side note, this entire comment of yours is very unhinged. I'd wager you're far far far from being aware of the 'reality most parents live in today', based off of what you've said here.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#157

Earlier quoted context omitted.

Apps requesting an age is not extraneous and there are many legal and safety reasons why an app may collect this information. If the operating system doesn't do it you run into the cookie banner situation where every individual site has to implement a dialog box asking the user instead of there being a standardized way to do it.

I'll bite: what's the safety reason for an app to ask for age verification? What kind of apps do you people use that are so dangerous? Does the computer zap you if you misuse the app or what?

For example an app may want to disable chat or private messages with other people if the user is a kid.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#158

Earlier quoted context omitted.

> An API actually means that more and more details about the user will inevitably be added with time. with that logic you could also argue a computer means more APIs will be added over time especially if it's a law mandated API which doesn't allow any additional thing this really isn't a problem > I will never agree with this nor will most people except overall (at least outside no HN bubble) most people would disagr…

Random person jumping in to say, the original comment from 'Bender' is what is agreed with by almost every human I've spoken to. It is most definitely the take of every parent in my social circle, the vast majority of whom are outside of the tech space. The issue you're describing is strictly one of parenting, and not one that can or should be handled via some government agency. Their (Bender's) suggestion is actuall…

EDIT: Thinking about it more I _guess_ we are more misunderstanding each other then we are fundamentally disagreeing (through I guess we still are disagreeing :) )

---

> I'd wager you're far far far from being aware of the 'reality most parents live in today',

I'm not (EDIT: As in I have enough parents in my live, through there may be larger cultural differences.)

and it's beyond my understanding how anyone can think treating a 13 and a 16 year one alike is a reasonable solution

similar all the things I have proposed gives parents the tooling needed

you make it sound like having an app fully controlled and replaceable by the parents is somehow removing power/choice from them. But nothing in it excludes parents from allowing or disallowing children to watch content from other age categories, potentially on a peace by peace basis

what it does is take the IRL system which isn't perfect but works reasonable good from how we e.g. handle the sale of movies and applies it to the digital world

including the option to ignore it

but we also have to recognize the reality that not all parents bother to even try to properly parent, and others are stressed, overworked and struggle. So having a triviale setup once and get some somewhat reasonable baseline solution is important (and yes it shouldn't be important, but IRL it is anyway)

similar I think it's important to realize that not just 18+ content can be harmful a barely not 18+ horror movie can still be quite traumatizing for some 13 year old. At the same time when children become 16+ you should have build a relation of trust with them where they shouldn't need to tell you or ask you for permission for everything not appropriate for 13 year olds on the internet. But while trust is grate you still would want to do more than that to keep them away from e.g. online gambling and some other sides. Which brings us back to having a baseline which works without spying on your child but still blocks some things off. I don't see how this is supposed to work without a having a 16+ age category between 13/12+ and 18+.

I guess we can probably agree on the fact that most content should only need the content age rating -> you decide (through parent controls) app direction. The OS --api--> Site/App direction is only really needed to serve a feed of "next" content and some other edge cases you could argue aren't in the best interest of children. But also there are better ways to fix those issues (through other means) IMHO. So I personally still would include it. At least for the age range 16+.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#159

I wonder how things like computers at the library will work. This whole thing is just so stupid and intrusive. I can't imagine anyone will benefit from this except advertisers, doxxers and Big Brother.

You're not really going to be watching porn at the library though, just saying

Age checks certainly won't be restricted only to porn sites. Tons of sites have 13+ ToS like Facebook & the various other social sites, Discord too iirc. The reason people are so adamantly against this proposal is that it ties the machine to a particular identity. So how does a public computer work? If age verification is implemented at the OS level, can we even have public terminals? All those interfaces in stores that are just a website in kiosk mode? Would they be illegally representing end users if it's set as an adult on a master account/login? This proposal is so stupid and poorly thought out it's alarming.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#160

Earlier quoted context omitted.

Random person jumping in to say, the original comment from 'Bender' is what is agreed with by almost every human I've spoken to. It is most definitely the take of every parent in my social circle, the vast majority of whom are outside of the tech space. The issue you're describing is strictly one of parenting, and not one that can or should be handled via some government agency. Their (Bender's) suggestion is actuall…

EDIT: Thinking about it more I _guess_ we are more misunderstanding each other then we are fundamentally disagreeing (through I guess we still are disagreeing :) ) --- > I'd wager you're far far far from being aware of the 'reality most parents live in today', I'm not (EDIT: As in I have enough parents in my live, through there may be larger cultural differences.) and it's beyond my understanding how anyone can think…

When it comes to 16+ I am not concerned about them at all. Sounds cold, no? But in reality 16 year olds have a network of people in their friend circle that can bypass any restrictions anyone sets on them. In my experience the more money spent trying to isolate them from a perceived harm will just make it more likely their circle/bubble/network of friends have already long since bypassed it sometimes out of spite or just to prove they can.

Case in point, games rated G are what many of them use for watching porn, sharing warez and pirated movies and streaming movies/porn together. This is already a thing in many rated-G games especially but not limited to games that use VR headsets, social games and such. Some of the smaller indie games are how some bypass sanctions, embargoes and more. That is just one of many examples of how teen bypass all perceived restrictions. Some small children will see porn in these games but that is a different problem for a different day.

My focus is entirely on small children and their most common use cases. The 99% problem. Keeping the nastier parts of the internet partitioned from small children is mostly accepted by most parents, is the right time to do it before they such as teens know what they are being locked out of. As the child evolves and develops the parent can decide when it is time to lift parental controls and then sit with the child whilst they explore the nastiest of nastiness together. The parent can answer questions instead of waiting until they are young tweens for their tween friends to incorrectly answer questions and start spreading STD's and/or getting impregnated to learn the hard way. Before someone says it, yes tweens are getting pregnant more often because their bodies are developing earlier now due to chemicals they are being exposed to and they are hitting puberty much earlier, some as young as 8 or 9. Some are getting penetrated as young as 6 or 7 and younger. They need to learn from their parents, not random kids their age or random websites or some GPT.

One simple static RTA header set on a load balancer or accelerator or within server applications is done and dusted. It does not get any easier. A check for that header by the user agent or application on a locked down child account to trigger parental controls is also easy. This was a thing in the early 2000's on MSIE and a few other browsers based on MSIE I think SlimBrowser and a few others. An intern could likely add this check in an afternoon not counting Quality Assurance time. No leaking data via API's, no sharing age or any other identifying attributes. If someone is arguing to gather this data I can not take their ideas in good faith because I have worked along side all the nasty people that want this data and I know they have no ethics and will sell this data with all manor of evil people and evil organizations that would be good bed buddies with Epstein and friends. I am unwavering on this belief. I have whipped this dead horse into micronized dust and will continue long after that micronized dust is broken into Quarks and Leptons.

Post reply on HN