Live data from Hacker News

Kids can bypass some age checks with a drawn-on mustache

theregister.com

191–200 of 203 posts

Re: Kids can bypass some age checks with a drawn-on mustache

#191
post #90
post #25

The result will be age verification with a passport or ID "to protect the children". Probably this was the goal all along.

Tier 1 networks legally not allowed to route packets that aren't digitally signed by a cryptographic ID linked to you

Additionally tier 1 networks legally not allowed to route packets that don't include an attestation that they were produced by a computer running only approved software.

https://web.archive.org/web/20220814024158/https://gabrielsi...

Re: Kids can bypass some age checks with a drawn-on mustache

#192
post #189

Earlier quoted context omitted.

But you can't preserve privacy while rate-limiting token generation unless you have a way of identifying someone, which could be as simple as requiring an account. And even if it's illegal to hand them out, it's not hard to set up a tor site to do it. I would be first in line to counter the state with such an implementation of this is the path we tread.

I think you misunderstand what "privacy-preserving" means here. The whole point is that they CAN identify you (to verify your age), but in... well a privacy-preserving manner :-). That is, one side knows who you are, but not what you do; the other side knows what you do, not who you are. > And even if it's illegal to hand them out, it's not hard to set up a tor site to do it. If a kid can use Tor to get a token, they…

> The whole point is that they CAN identify you (to verify your age), but in... well a privacy-preserving manner :-).

But how can this be done so that the site and I'd verifier can't collude on a backchannel to unmask you?

> In a non-functional democracy, I guess don't complain if someone burns your car "to counter the state" some day if you think like this.

I don't advocate for destroying private property. Sharing tokens doesn't destroy property or ip/copyright.

Re: Kids can bypass some age checks with a drawn-on mustache

#193
post #189

Earlier quoted context omitted.

I think you misunderstand what "privacy-preserving" means here. The whole point is that they CAN identify you (to verify your age), but in... well a privacy-preserving manner :-). That is, one side knows who you are, but not what you do; the other side knows what you do, not who you are. > And even if it's illegal to hand them out, it's not hard to set up a tor site to do it. If a kid can use Tor to get a token, they…

> The whole point is that they CAN identify you (to verify your age), but in... well a privacy-preserving manner :-). But how can this be done so that the site and I'd verifier can't collude on a backchannel to unmask you? > In a non-functional democracy, I guess don't complain if someone burns your car "to counter the state" some day if you think like this. I don't advocate for destroying private property. Sharing t…

> But how can this be done so that the site and I'd verifier can't collude on a backchannel to unmask you?

Now we're talking :-). Look at Privacy Pass, it's interesting!

If you like RFCs, it's here: https://www.rfc-editor.org/rfc/rfc9576.html

Kagi has a nice explanation here: https://help.kagi.com/kagi/privacy/how-does-privacy-pass-wor...

Re: Kids can bypass some age checks with a drawn-on mustache

#194

Earlier quoted context omitted.

My 12yo son is already significantly taller than me! We had to use his passport to prove he’s much younger than these systems report because they were locking him out from chatting to his friends (said the age gap was too big)

How do they know how tall he was ? Oh perhaps his face looks older too ?

yeah, his face looks older too I guess. Was mostly calling out that height isn't going to necessarily help either.

Re: Kids can bypass some age checks with a drawn-on mustache

#195

Earlier quoted context omitted.

My 12yo son is already significantly taller than me! We had to use his passport to prove he’s much younger than these systems report because they were locking him out from chatting to his friends (said the age gap was too big)

Wait, am I understanding correctly: for your child to chat with their friends you had you send a copy of their passport to a stranger in the Internet because "a system" thought they were older looking that their friends? What are we doing even?

yeah :( I'm definitely not in the pro "kids need to be protected from the internet/social media/whatever" camp as I'd much rather teach my kids to make smart decisions and manage it ourselves vs the government mandated solution we now have. The way it's implemented though means services (Roblox in this case) have to verify the age of the child. Those kids can only talk to other kids that are +/- some range from their own age. So it was either let him continue playing as though he's a 16yo but not actually be able to play with any of his friends, or use the identity verification provider they have to prove he's not. The whole thing is a gross mess imo.

Re: Kids can bypass some age checks with a drawn-on mustache

#196
post #193

Earlier quoted context omitted.

> The whole point is that they CAN identify you (to verify your age), but in... well a privacy-preserving manner :-). But how can this be done so that the site and I'd verifier can't collude on a backchannel to unmask you? > In a non-functional democracy, I guess don't complain if someone burns your car "to counter the state" some day if you think like this. I don't advocate for destroying private property. Sharing t…

> But how can this be done so that the site and I'd verifier can't collude on a backchannel to unmask you? Now we're talking :-). Look at Privacy Pass, it's interesting! If you like RFCs, it's here: https://www.rfc-editor.org/rfc/rfc9576.html Kagi has a nice explanation here: https://help.kagi.com/kagi/privacy/how-does-privacy-pass-wor...

Thanks. I appreciate the link. One thing I wasn't able to fully understand from the Kagi article: how does this solve the problem of "token handoff"? For example, if User A generates a token (from an unlimited search acct) and hands it to User B, whom has no association with Kagi, how does Kagi block User B's access? Or do they just assume it's fine because the token count is capped at a low enough value as to make it unprofitable for me, as a user, to purchase an unlimited search plan and then resell my plan at a lower price (making a profit on volume) by handing out my precomputed tokens to my resold subscribers to use?

Re: Kids can bypass some age checks with a drawn-on mustache

#197
post #193

Earlier quoted context omitted.

> But how can this be done so that the site and I'd verifier can't collude on a backchannel to unmask you? Now we're talking :-). Look at Privacy Pass, it's interesting! If you like RFCs, it's here: https://www.rfc-editor.org/rfc/rfc9576.html Kagi has a nice explanation here: https://help.kagi.com/kagi/privacy/how-does-privacy-pass-wor...

Thanks. I appreciate the link. One thing I wasn't able to fully understand from the Kagi article: how does this solve the problem of "token handoff"? For example, if User A generates a token (from an unlimited search acct) and hands it to User B, whom has no association with Kagi, how does Kagi block User B's access? Or do they just assume it's fine because the token count is capped at a low enough value as to make i…

It doesn't solve it.

I don't think that there is a need for a technical solution to that, though. In the Kagi example, probably they trust that their users won't do that, and someone could already resell searches this way (e.g. write some kind of proxy). Similarly, an adult can already help a kid get access to stuff they shouldn't. But the point is to make it harder for kids to do it on their own, for their own sake.

It's not computer security, where your system is "as weak as the weakest part". We don't care if a few kids access social media: the goal would be to make it such that the norm, for kids, is to not have social media.

Re: Kids can bypass some age checks with a drawn-on mustache

#198
post #197

Earlier quoted context omitted.

Thanks. I appreciate the link. One thing I wasn't able to fully understand from the Kagi article: how does this solve the problem of "token handoff"? For example, if User A generates a token (from an unlimited search acct) and hands it to User B, whom has no association with Kagi, how does Kagi block User B's access? Or do they just assume it's fine because the token count is capped at a low enough value as to make i…

It doesn't solve it. I don't think that there is a need for a technical solution to that, though. In the Kagi example, probably they trust that their users won't do that, and someone could already resell searches this way (e.g. write some kind of proxy). Similarly, an adult can already help a kid get access to stuff they shouldn't. But the point is to make it harder for kids to do it on their own, for their own sake.…

Thank you. This helps my understanding, and I would find this solution the proper one if we determine that this road must be walked.

But I still have reservations that this would be the "foot in the door", because people like me will generate and publish tokens publicly, and then lobbyists will use this as the reason why we can't allow the use of private keys unless the website receiving them can certify they belong to the user presenting them, thus forcing a rework of the implementation.

Re: Kids can bypass some age checks with a drawn-on mustache

#199

Earlier quoted context omitted.

>All this age verification stuff is pseudoscience and more importantly it isn't tested or standardized at all. It's just theater Abdicating responsibility, standards and government enforcement are three of white collar America's favorite things. Seems like an opportunity for someone to become a billionaire by creating a standardization and licensing agency and then paying for some shills to get the ball rolling. Give…

So what would you do to combat the very real problems associated with (unlimited) access to known cognitive harms for minors?

not op, but my thoughts..

1 - hold the parents accountable for putting a dangerous weapon in the hands of munchkins without supervision.

2 - phone manufactures and or internet providers that sell and connect them, must include a bouncer bot system like a locked phone. The parents get to choose and change which set of bouncers filter the phones.

These can be simple like 18 and over content according to your jurisdiction block.. but I would hope they would spend time to choose multiple bouncers that block different things for different values and offer ways to request access to blocked things.

I have posted more details previously.

Re: Kids can bypass some age checks with a drawn-on mustache

#200
post #197

Earlier quoted context omitted.

It doesn't solve it. I don't think that there is a need for a technical solution to that, though. In the Kagi example, probably they trust that their users won't do that, and someone could already resell searches this way (e.g. write some kind of proxy). Similarly, an adult can already help a kid get access to stuff they shouldn't. But the point is to make it harder for kids to do it on their own, for their own sake.…

Thank you. This helps my understanding, and I would find this solution the proper one if we determine that this road must be walked. But I still have reservations that this would be the "foot in the door", because people like me will generate and publish tokens publicly, and then lobbyists will use this as the reason why we can't allow the use of private keys unless the website receiving them can certify they belong…

I think there is a sane debate to have around whether or not we want privacy-preserving age verification, indeed. And how much of a "foot in the door" it is (is it building more surveillance technology, or is it actually building privacy-preserving technology that will counter it?).

My concern is that "society" may want to control social media for kids, and if we say "either you don't do it or you leak the IDs", it may end up on "ok then let's leak the IDs" without even considering the better way.

I am just very frustrated because right now, even in a place like here where it's supposed to be around tech-savvy people, the discussion feels like kids repeating what they heard: "it's like ChatControl, it's fundamentally stupid and impossible".

Post reply on HN