Live data from Hacker News

Online age verification is the hill to die on

x.com

291–300 of 750 posts

Re: Online age verification is the hill to die on

#291

Good: some commenters here realize it's an attack on privacy Bad: some still entertain the idea that we should do age verification using some sort of crypto primitives There is no reason for age verification at all. I am from the goatse generation. Rotten.com. steakandcheese. Horrific stuff tbh, I mostly stayed away from it, and I didn't need a helicopter government to protect me from it. The moment you accept the na…

Nah, that already didn't work because corps are very good at creating network effects in children and will set up multi-billion-dollar businesses around them. And then the kids with protective parents become the weird ones in school. I'll die on the hill of curtailing this stuff in a privacy-preserving way.

Re: Online age verification is the hill to die on

#292
post #228

Earlier quoted context omitted.

I disagree. The ability to render a page could simply mean that parental controls were not enabled on the device. Some parents have assessed the situation and trust their children to be psychologically ready for adult situations. The client could be literally any age. Today devices do not default to accounts being child accounts. Some day this may change and may require an initial administrator password or something…

>I disagree. The ability to render a page could simply mean that parental controls were not enabled on the device. Not being able to detect all children doesn't mean that being able to detect 80% of them is somehow less disturbing.

The point and overall goal should be to not signal anything to the server operator unless a credit card is being used. Everyone is whomever they claim to be as far as anyone is concerned, until payments are required which today means sharing identity and age (via the credit card information on file with the financial institution and is shared today).

In the case of RTA the only signalling taking place is a server header being transmitted to the client. The client could be anyone at any age. Nothing to explicitly leak or disclose. Server operators can guess all they desire as some do using AI based on user behavior of which they sometimes get wrong.

Re: Online age verification is the hill to die on

#293
post #41

Age verification can be achieved without destroying anonymity and privacy online using anonymous credential systems, but it has to be designed that way from the ground up, and no one pushing age verification is interested in preserving privacy.

This comes up in every thread, but the purpose of the laws is not to verify that someone can access an anonymous token. If we had a true anonymous token system then everyone would just share tokens around. The real world analog would be if you could buy beer at the store with anyone's ID because they didn't make any effort to reasonably check that the ID was yours or discourage people from sharing or copying IDs. The…

Continuous age verification isn't possible, so you'll have to store some sort of proof of age somewhere, and that proof will always be sharable.

Let's say Facebook has verified my age somehow. I could share my Facebook login credentials, or the token that their authorization server sends back in response. You can create some hurdles to doing that, like requiring a second factor, but I can just share that too.

You might as well go down the route of accepting that possibility. These systems are never going to hold up in the face of a determined enough teenager.

Re: Online age verification is the hill to die on

#294
There are lots of ways to implement identity verification while preserving privacy. It's actually a super interesting engineering problem. Estonia has an excellent model to build on. The government can maintain a "traditional" ID system based on documents and in-person verification, and provide you with a device similar to a yubi-key or Bitcoin hardware wallet that could be used to share specific, cryptographically verifiable claims with third parties, like your age, or even just a boolean "over 18", but also your name or other information if you choose, with a way to control the access and audit which parties have verified which claims with the govt.

Re: Online age verification is the hill to die on

#295
I've heard that we could use zero-knowledge ID proofs to show someone is of age without revealing any more but I don't think that's the plan and the demand for age restrictions doesn't feel like a grassroots effort of concerned parents. It feels like an NGO/bureaucrat driven law and I assume its purpose is to de-anonymize people on the internet.

Re: Online age verification is the hill to die on

#296
post #222

Earlier quoted context omitted.

That would also amount to compelled speech. I disagree. The legal requirement to apply a warning label is a well known, understood and accepted process that is applied to a myriad of hazards to children and adults . As just one example businesses in some states, most notably California are compelled to add warning labels to foods and other products that could cause cancer.

Do you believe using the Internet should require a license? Isn’t that what covers these product warning labels?

I never implied an internet license. Rather if a server operator a business has content that may be adult in nature they must label their site. Businesses require a license already but that is unrelated to this.

Re: Online age verification is the hill to die on

#297

Good: some commenters here realize it's an attack on privacy Bad: some still entertain the idea that we should do age verification using some sort of crypto primitives There is no reason for age verification at all. I am from the goatse generation. Rotten.com. steakandcheese. Horrific stuff tbh, I mostly stayed away from it, and I didn't need a helicopter government to protect me from it. The moment you accept the na…

Nah, that already didn't work because corps are very good at creating network effects in children and will set up multi-billion-dollar businesses around them. And then the kids with protective parents become the weird ones in school. I'll die on the hill of curtailing this stuff in a privacy-preserving way.

> I'll die on the hill of curtailing this stuff in a privacy-preserving way.

At some point you'll realize the contradiction in not trusting these "multi-billion-dollar businesses" to the point that you are risking enslaving humanity and "dying on this hill" and yet at the same time trusting those same businesses to implement this dystopian system in a privacy-preserving way.

When that realization hits, it will be a loud sound, possibly heard by nearby telepaths.

Re: Online age verification is the hill to die on

#298
post #201

An attestation-like system to detect humanity at time of post is absolutely for useful online spaces in the era of AI slop. The writing style of the author is very annoying.

Until people hit "attest" and then copy the text from ChatGPT.

Those people would be subjected to permanent, identity-bound bans.

Re: Online age verification is the hill to die on

#299
post #222

Earlier quoted context omitted.

That would also amount to compelled speech. I disagree. The legal requirement to apply a warning label is a well known, understood and accepted process that is applied to a myriad of hazards to children and adults . As just one example businesses in some states, most notably California are compelled to add warning labels to foods and other products that could cause cancer.

That's not the best example, since the levels set for Prop 65 warnings are so low that the warnings are effectively useless; every single commercial building in CA now somehow causes cancer.

Surely we both understand the point I was making in that labels are already compelled by laws today.

Fine, cigarettes must be labelled as being a risk of causing cancer. The punishment for failing to do this is both civil and federal penalties including massive fines and federal prison time.

Re: Online age verification is the hill to die on

#300
post #289

Earlier quoted context omitted.

Or could have a header saying this is not adult-only content, and a parentally-controlled device will block things that don't participate.

That's a good idea. There could be two headers, the existing RTA header that adult sites use today [1] and another static header that explicitly states there shall be no adult content. [1] - https://www.shodan.io/search?query=RTA-5042-1996-1400-1577-R... [THESE ARE ADULT SITES, NSFW]

What is adult content? I know parents who have no problem with their kids seeing porn. I know parents who give their kids a beer. I know parents who take their kids to violent movies. I used to know parents who will give their kids cigarettes. Most parents I know will disagree with their kids doing one of the above. I know songs that were played on the radio in 1960 that would not be allowed today, even though today we allow some swearing on the radio.
Post reply on HN