Live data from Hacker News

Goodbye, and Thanks for All the Bikesheds

queue.acm.org

161–170 of 285 posts

Re: Goodbye, and Thanks for All the Bikesheds

#161

Earlier quoted context omitted.

> Parental control does not work today, it's too fragmented and too difficult. Then legally require it to be effective and easy-to-use-if-you-take-a-few-minutes-to-read-the-instructions. See also [0]. [0] https://news.ycombinator.com/item?id=48911863 >

This is literally what California did with the Digital Age Assurance Act, AB1043.

> This is literally what California did with the Digital Age Assurance Act, AB1043.

There's apparently information that you didn't read contained in the footnote of the comment you replied to.

Based on this layman's reading of the law, [0] California did literally the opposite. They require major OS vendors to require users to enter their birthdate or indicate in some other way their current age, and then require programs and websites to act on that age information. This is entirely different from requiring major OS vendors to allow a "guardian account" to set fairly-fine-grained restrictions on one or more -er- "ward accounts", and then requiring programs and websites to refuse let the "ward account" do the things that those restrictions say that it isn't permitted to do.

"Restrict by age" neither accounts for precocious under-eighteens, nor does it account for vulnerable elderly or otherwise brain/developmentally-damaged adults who need protected. And because "restrict by age" cares very much about your age, and because it's not going to work nearly as well as promised by those pushing it, it will inevitably require scans of both a photo ID and one's face and/or other biometrics.

A "you don't need to know anything about this account other than that these are the things it's not supposed to be able to do" system gives zero shits about the identity of a person, so there's no plausible path for it to gate access behind submission of any identifying documents to any third party.

[0] https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...>

Re: Goodbye, and Thanks for All the Bikesheds

#162
post #23

I don't think age restriction will impact FOSS in the long term. If there are some regulations that threaten FOSS now, they are going to be adopted in the long term. Regulations for age restriction are understandable. A lot of modern technology is harming kids (and I don't mean dirty videos, social media seems to be much more harmful). A sensible regulator would leave some responsibility to the parents, but require r…

It is already happening. E.g. soon F-Droid and any unattested open source Android app distribution will be gone, due in Sep 2026.

Same with GitHub and similar, we have CLAs for a while now for licensing. But I see project maintainers are frustrated with AI generated slop PRs and bad actor contributions. The ecosystem will be closing. You will be able to read code, but forget creating PR without some ID verification (because this is for kids or against terrorism).

Re: Goodbye, and Thanks for All the Bikesheds

#163

I guess tech has grown too large and fractured and maybe most working software engineers are too young to be familiar with phk and his points of view. He's been a strong privacy and FOSS advocate for decades and has more credibility on both of these topics than nearly anyone on this board. He also has an account and comments frequently. phkamp. I suggest reading some of his comments before making judgment. So many kn…

Sadly, after the 2024 anti-E2E-messaging piece[1] I do in fact think he’s pretty anti-privacy overall. Perhaps calling that pro-regulation is more correct, but my (non-American) experience over the last, say, twenty years does not include literally a single piece of regulation that traded privacy for more government control (however reasonable) and went well, so, same difference. Accomlished hacker holds some wrong-t…

It's extraordinary to me how highly intelligent people can't tell the difference between saying "don't this because people don't have the right to do it" and "don't do this because even if you're correct you'll go to prison for it".

That's the difference he's pointing out in your linked article. There's nothing "anti-E2E" about that piece that he wrote. He says explicitly that people can have whatever standard of encryption they're comfortable with in the post. His piece is entirely about letting all parties to communication decide their limits on privacy. It's a solution that lets people maintain their rights, lets businesses stay compliant with the law and also meets with political reality.

The staunch privacy advocates acting like privacy has to be all or none are right but not in the way they believe. If you continue to build privacy technology where the only option is total privacy then don't be surprised when nation states take all of your privacy away. There's no privacy in prison.

Also you can be totally justified in working on such tools, but western liberal governments will still imprison you for it. Hell, a guy sat in jail for four years just for ignoring a court order to unlock his phone (United States v. Rawls). He won the appeal but still sat in prison and judges can do that. That's kinda the point of the article.

phk is doing nothing more than telling people the temperature of the room outside of their bubble.

Re: Goodbye, and Thanks for All the Bikesheds

#164

Earlier quoted context omitted.

This is literally what California did with the Digital Age Assurance Act, AB1043.

> This is literally what California did with the Digital Age Assurance Act, AB1043. There's apparently information that you didn't read contained in the footnote of the comment you replied to. Based on this layman's reading of the law, [0] California did literally the opposite. They require major OS vendors to require users to enter their birthdate or indicate in some other way their current age, and then require pro…

It requires you to enter a birth date which is not required to be your birth date. In case of a conflict between the age verification birth date and any other birth date, only the age verification birth date may be used for age appropriateness checks.

Re: Goodbye, and Thanks for All the Bikesheds

#165

Earlier quoted context omitted.

A working solution can forestall a worse one. Because of the age verification law in California, which is very explicit that you only need a device-wide checkbox, nobody can use the argument that they need a passport scan to comply with the law.

We’ve had the “compromise” solutions forever before the harder stance tech took on privacy in the last few years, and governments abused them into oblivion. Every time the tech allowed it, it was legally abused and applied much wider than initially promised. This isn’t just about age verification but also encryption. Every time you step back, the opposing force advances one step and soon you’ll have the same discussi…

Non sequitur. I didn't say anything about backdoors or privacy.

Re: Goodbye, and Thanks for All the Bikesheds

#166

Earlier quoted context omitted.

> This is literally what California did with the Digital Age Assurance Act, AB1043. There's apparently information that you didn't read contained in the footnote of the comment you replied to. Based on this layman's reading of the law, [0] California did literally the opposite. They require major OS vendors to require users to enter their birthdate or indicate in some other way their current age, and then require pro…

It requires you to enter a birth date which is not required to be your birth date. In case of a conflict between the age verification birth date and any other birth date, only the age verification birth date may be used for age appropriateness checks.

Okay? That is not parental controls that are

  [L]egally require[d] ... to be effective and easy-to-use-if-you-take-a-few-minutes-to-read-the-instructions.
Additionally, I expect that -due to kids lying about their ages- within five or ten years, the regs will have "graduated" from self-attestation to ID and biometrics collection. It's likely that other states will require that sort of collection much sooner, causing every US-based company to do that regardless of the existence of less-invasive regs.

Like, seriously... if "the kids can lie about their age and there are no consequences for lying" is the bar you want to set, just do the 1990's thing where sites and programs have a "Warning! This might not be suitable for kids!" page/screen that has a checkbox that the kids can check or button that they can press that lets them lie that they're over-seventeen and grants them access.

Re: Goodbye, and Thanks for All the Bikesheds

#168
post #144

I had to stop reading halfway through to respond. > In comparison, tech sisters advocating for an absolute right to privacy seem to be a very rare, and maybe mythical, species. Ever heard of Meredith Whittaker? > We could have designed our protocols to be minimally compatible with “a nation of laws,” but the tech bros insisted that compromise was treason, and, as a result, we will lose more privacy than necessary. Th…

> Ever heard of Meredith Whittaker? The fact that you name one makes her very rare indeed.

- Cindy Cohn, Executive Director of the EFF

- Eva Galperin, Director of Cybersecurity at the EFF

- Runa Sandvik, formerly of Tor Project

- Yan Zhu, EFF Fellow and CISO at Brave

And many, many more.

It rankled me more than a bit that the author apparently looked around his bubble in Denmark and the FOSS community, saw no "tech sister" privacy advocates, and decided to paint with the widest brush possible and assume there are none anywhere.

Re: Goodbye, and Thanks for All the Bikesheds

#169

A bit of an aside, but after someone introduced me to the notion of Reversible Decisions, it quickly became apparent to me that the solution to the bikeshed problem is to throw money at it before the roosters can start preening about which color the shed should be. Decisions that are reversible should just go with the instinctive answer of whoever volunteers to work on it. I've been in many meeting rooms where, becau…

This often massively discounts the cost of reversing decisions. People often work to build things without any thought given to those who have to maintain it afterwards. Especially when it's not them.

I worked at a large, publicly-traded multinational where decades prior and they were still just a 4 man startup they decided the database server and all timestamps should be in the local timezone.

They are still using EST today even when they have global sharding of their customers/databases between US, EU, LATAM, SEA...

--- you're also assuming that the product roadmap will afford your engineers any time to build it the second, third, fourth, etc. time.

Re: Goodbye, and Thanks for All the Bikesheds

#170
post #56

> my personal guess is that the opportunities for anonymity on the Internet will shrink until mothers no longer are forced to have “the talk” when their daughters get their first mobile phone. As the parent of a daughter, I am totally on board with that. depends on the age but.. they've probably discovered all kinds of shit already or heard about it from others

The attitute expressed in the quote, "until mothers no longer are forced to have 'the talk' when their daughters get their first mobile phone," is both wrong in its assumptions and dangerous for its well-known consequence: the enabling of petty tyranny. Forced, indeed. There will never be a world populated by humans in which you do not need to have numerous talks with your children about the nature of humans, especia…

Well put.

But the problem is, those same forces you're describing are employed to fool people into believing the fictions that support these regressive movements. The real danger we should be focusing on is "won't someone think of the impressionable adults".

Post reply on HN