Live data from Hacker News

Do Not Turn Child Protection into Internet Access Control

news.dyne.org

311–320 of 486 posts

Re: Do Not Turn Child Protection into Internet Access Control

#311
post #295

Earlier quoted context omitted.

They were also likely done with keyboards and mice. Should we require id at point of purchase for those?

Alright, so does that mean we don't need KYC for gun purchases or bank accounts either? Of course you're probably going to say something about how guns and bank accounts are crucial components to crime, in which case the same holds for AI in the mexican telecoms hack.

Just yesterday I thought about the right middle ground for KYC when buying guns.

The issue with centrally registering guns is than when you country is taken over by hostile forces (whether an invading army or a democratically elected abuser who turns it into a dictatorship), they know who has the guns and can force those people to surrender them (politely at first, authoritarians always use a salami slicing technique).

The issue with no controls is that even anti-social and mentally ill people can get them.

I wonder if the right middle ground could be:

- Sellers have to do their due diligence - require ID, proof of psychological examination, whatever else is deemed the right balance.

- Not doing due diligence means they get punishment equal to that for any offense committed with that gun.

- They might be required to mark/stamp the gun so that it can be traced back to them or have witnesses for the transfer.

Re: Do Not Turn Child Protection into Internet Access Control

#312

Earlier quoted context omitted.

> the API requires every service to implement it and that's not happening No it doesn't. A browser/appinstaller with parental/age controls enabled would fail as unavailable if there was no age rating on the website/app. This is exactly the solution we should be aiming for, as it keeps the incentives lined up instead of turning them upside down. One big problem with the laws currently being pushed is that it leaves th…

I shouldn't have defended the API or age rating solution. It's just a trap in hindsight. That kind of solution must be rejected altogether even if it's the OS checking the app/website's age rating header, because we'd be giving the OS oligopoly (Apple, Google, Microsoft) way too much leverage, and in the long term they're going to make it so that you can only run their approved apps because unapproved apps didn't imp…

You can still get hardware that you can install your own OS on. But you have to be deliberate about picking it out before a purchase, rather than hoping to unlock a random carrier phone down the line. For example my phone is a Pixel running Graphene. It has a locked down bootloader that could only be unlocked with the online consent of Google. While this most certainly chafes me (and if I could snap my fingers and make such schemes blink out of existence I would), I do have to admit that it really isn't that debilitating.

The unlocking process zaps the userdata partition. This security model would totally suffice for locking down a child's phone. If the child zaps their phone and erases everything on it, then the parent can handle that out of band.

For the general problem, I would say that there has been a longstanding market failure here, in that parental control software isn't widespread or straightforwardly usable across different websites. Your 3 points don't really address that. (2) has been doable on standard desktops forever, and (3) just pushes mobile devices back towards the capability of desktops (which on its own is laudable!). But standard desktops have had these capabilities for decades and still haven't evolved the kind of straightforward parental controls that most parents are demanding.

Re: Do Not Turn Child Protection into Internet Access Control

#313
post #4

What's sad is how effective this is. Religious groups figured out a few years ago that anti-porn groups accomplish nothing, but if you start an anti-trafficking group you can restrict porn access.

If that reduced trafficking, would it not be a worthwhile exchange?

Re: Do Not Turn Child Protection into Internet Access Control

#314

Earlier quoted context omitted.

There will always be weird tail risks. The law should only get involved where there are widespread systemic problems. People are occasionally hospitalized due to self, family, or friends handling food improperly. That doesn't warrant a legal intervention whereas dining establishments do. > before someone inevitably says “where were the parents?” and wash their hands of the situation Nope, that's exactly what I say. T…

I live in extremely fire prone areas. Many of us are pretty damn okay at beating back the flame and controlling the flow of the worst of things away from homes, but nobody is perfect. We don't expect every family and parent in these areas to have fire fighting skills, self evacuation is recommended. Parents every where now find themselves surrounded by the delibrately laid gasoline of addictive social media and groom…

I agree with that however I'm puzzled by your comment because in the context that you're responding to I don't think I said anything that would imply otherwise. Being particularly skilled in "defensive cyber security" isn't a requirement to avoid grooming of your child in the general case - some combination of communication, supervision, and filtering is.

> It's reasonable to expect communities to want simple barriers and means of protection, the existance of reasonable control and throttling options for parents.

I agree 100%! However ID verification is not a reasonable (or even particularly effective) solution to that. I apologize if I've misconstrued your intended meaning but given the broader context that's what it seems like you're implying.

Realistically there's no way to prevent grooming other than keeping tabs on your child. The least labor intensive (but also most intrusive) way to do that is probably whitelist parental controls and watching for unauthorized devices. It is not even remotely realistic to expect a communication platform to detect that a child is speaking with an adult they don't know (as opposed to one they do) and also that it isn't a benign interaction (such as a gaming group or etc) and then somehow act on that information (how?) without manufacturing an absurd dystopia in the process.

When it comes to filtering I think it would be reasonable to impose a standard self categorization protocol on all website operators. That would make non-whitelist filtering much more reliable (a boon to parents, educators, and employers) without negatively impacting privacy or personal freedoms.

Re: Do Not Turn Child Protection into Internet Access Control

#315
post #150

Earlier quoted context omitted.

I was talking about the party. This shit is and always has been pushed from both parties. Even democrat states like California and Colorado are on board. See also, the OS age verification legislation.

TBH California one doesn't require age verification (while many other states do). It only requires the OS to provide a mechanism for the user to indicate their age group and apps should use the information (instead of asking for PII themselves). It's a fake one, but somehow drew most attention.

If that is true about the California case, it is basically a fluke. Lobbyists don't have total control of the legislation after all. It sounds almost benign when posed that way, but it is the wrong solution either way. The better solution is to tell people to install filtering software to block content that they don't want. Then you don't have to worry about compliance of individual sites, personal information, or any of it. This filtering strategy also makes sense for privacy and handling the subjective nature of what is age-appropriate or offensive.

Re: Do Not Turn Child Protection into Internet Access Control

#316
post #297

Earlier quoted context omitted.

The California bill gets it backwards. Rather than Internet services taking the user's age and deciding what content to serve, the Internet service or app should broadcast the age rating of its content to the OS (if convenience is desired), like how movie ratings work. The responsibility to decide what content is suitable for a child should rest in the hands of that child's parent, not the state or the corporation. e…

That's not my understanding. This is what the bill says: Provide a developer who has requested a signal with respect to a particular user with a digital signal via a reasonably consistent real-time application programming interface that identifies [the age group]. So the app requests a signal (like, calling an API), and the OS returns the signal (returning the age group). Regarding API vs installation lock, TBH I don…

The California law is horrible because it forces everyone to let tech companies and governments decide what's suitable for children, rather than let parents decide. It's telling parents to give every app their child's age and trust that the apps will do the right thing. It also legitimizes personal data collection (in this case, the user's age) for every app and service on the Internet that wants to know your age.

The password-based app installation lock I proposed in my original comment doesn't require any kind of age checking at all, so it naturally doesn't fit the California law. The device owner (in this case, the parent who buys the device for their child) gets to decide what apps can be installed on their child's phone on an app-by-app basis using a password set by the parent. The app store doesn't need to know, and the apps don't need to know.

Re: Do Not Turn Child Protection into Internet Access Control

#317
Gullible to believe its about kids - especially when there's a million options to limit the internet on devices already.

IMAGINE A WAR.

Now - wouldn't a government LOVE to know who's saying what? Rather than shutting down the entire $$$$$ corporate internet.

Money concerns as usual.

Re: Do Not Turn Child Protection into Internet Access Control

#318

The big issue isn’t even age verification. The end goal is verified user identification. They want every transaction on the internet to be associated with the exact identity of the user. No more anonymity. In the short term the way it will be implemented is this — age verification will not be a binary, it will also want to push your DoB, name, location etc and they say “the choice is with the user” but the default wi…

IMAGINE A WAR.

Now - wouldn't a government LOVE to know who's saying what? Rather than shutting down the entire $$$$$ international corporate internet.

Money concerns as usual.

Re: Do Not Turn Child Protection into Internet Access Control

#319

That's the trick, it's always been about control. No-one in such positions actually cares about the children.

The adult entertainment industry cared decades ago [0]. Their solution is simple: sites send the RTA meta tag if applicable, browsers in accounts configured by guardians as "children" look for it. [1]

[0] https://en.wikipedia.org/wiki/Association_of_Sites_Advocatin...

[1] https://www.rtalabel.org/

Re: Do Not Turn Child Protection into Internet Access Control

#320

Earlier quoted context omitted.

What did it affect in your life? Ultimately something with affect a kid’s life.

I mean... access to adult content at that age is really, really bad. It really messed up my brain. Gore videos, chatting with adults, etc. But I learned many good things, too. It's a double-edged sword.

Seeing people squish at a young age - and I am not being flippant here - helped reduce my teen "I'm immortal! I'm unstoppable!" phase.

I saw very quickly that what separates a live person from a very deceased flat person was a moment of sillyness/forgetfullness/stupidity. "I didn't SUSPECT that is even possible to happen to a person!" - "We're....fragile?!" - "Ah, bike helmet... I think they're REALLY GOOD idea...."

PSA's just aren't listened to by teenagers. But something that's real - that happened, with the security camera timestamp in the corner... kids learn safety.

Post reply on HN