Live data from Hacker News

Online age verification is the hill to die on

x.com

441–450 of 750 posts

Re: Online age verification is the hill to die on

#441
post #8

The one and only method I will participate in is server operators setting a RTA header [1] for URL's that may contain adult or user-generated or user-contributed content and the clients having the option to detect that header and trigger parental controls if they are enabled by the device owner. That should suffice to protect most small children. Teens will always get around anything anyone implements as they are alr…

How would this work with sites like YouTube which allow sharing of content, potentially not appropriate for children, but the content is generated by the site's users? Who will be fined for "violations"? And how would such a fine be levied, especially internationally?

This already has been solved. Youtube disables viewing via embeds for any content that has been age restricted. Either you view it on Youtube which requires logging in to see age restricted content in the first place, or you get the ! icon and the warning about needing to log in.

Re: Online age verification is the hill to die on

#442

Earlier quoted context omitted.

We've spent the past three decades trying to invent ways to deduce identity and build profiles of what would otherwise be anonymous users. When the government steps in and compels people to formally identify themselves by their government names, what would you expect these companies to do? They're not gonna say "no thanks."

Why the heck would the government compel people to formally identify themselves to read or comment on a newspaper or a blog? That's absurd and unconstitutional in the US. You're starting from an assumption that is invalid to begin with.

I don't know. Why would the government compel someone to formally identify himself to put cash in a box at the bank? Why would the government compel people to take off their shoes to get on a plane? Or submit biometric data drive a car? KYC for a phone line...

It's not invalid. I have no reason to believe that this isn't going to creep.

Re: Online age verification is the hill to die on

#443

Earlier quoted context omitted.

This is exactly the way it should be done. Device with parental controls enabled disables content client-side when the header is detected. As far as I can tell, it's a global optimum, all trade-offs considered.

Well why haven't all the big tech companies done it then? They have only themselves to blame. They had years to fix the problem of inappropriate content being delivered to kids and their response was sticking their fingers in their ears and saying "blah blah blah parenting blah blah blah" And it really should be the opposite. Assume content is not kid-safe by default, and allow sites to declare if they have some othe…

The tech companies are the ones lobbing for age verification.

The entire point of this scheme is mass surveillance and shifting responsibility away from big tech companies. It has nothing at all to do with "protecting" kids. Preventing kids from accessing adult material is not even remotely a goal, it is a pretext. Just like every other "think of the children" argument.

Re: Online age verification is the hill to die on

#444
post #8

The one and only method I will participate in is server operators setting a RTA header [1] for URL's that may contain adult or user-generated or user-contributed content and the clients having the option to detect that header and trigger parental controls if they are enabled by the device owner. That should suffice to protect most small children. Teens will always get around anything anyone implements as they are alr…

An outstanding idea. Those lobbying for age verification hate it though, because they want to be the arbiters of age, and all that juicy PII that they can analyze and resell.

I'm not so sure. I think the push is from the government actually. But companies are not exactly opposed to it. Quite the contrary. Big corporations see compliance as a moat. Tobacco companies supported stricter regulations on tobacco advertisements, because they had the deep pockets required to follow the changing laws. Mr. Altman is all-in on AI regulation, because it will mire down competitors while OpnAI has already "slipped past the wire" and done all their training pre-crackdown. When given a choice between regulating their industry (platforms and operating systems) vs regulating someone else's (porn sites and the like) they'll always helpfully "volunteer" to be the first to be regulated. It's just good business.

Re: Online age verification is the hill to die on

#445

Earlier quoted context omitted.

ID system should be based on commercial bank. If you need to prove your identity or whatever about yourself just tell them to ask your bank and bank will ask you which information about yourself you are willing to share with whoever requested to confirm something about you. When ID is tied to your bank account you guard it like you guard your bank account. Because it is the same thing. This will drastically lower the…

That's just feudalism with less extra steps

From what I know about feudalism, this is a non-obvious statement. Care to develop ?

Re: Online age verification is the hill to die on

#446
post #289

Earlier quoted context omitted.

That's a good idea. There could be two headers, the existing RTA header that adult sites use today [1] and another static header that explicitly states there shall be no adult content. [1] - https://www.shodan.io/search?query=RTA-5042-1996-1400-1577-R... [THESE ARE ADULT SITES, NSFW]

What is adult content? I know parents who have no problem with their kids seeing porn. I know parents who give their kids a beer. I know parents who take their kids to violent movies. I used to know parents who will give their kids cigarettes. Most parents I know will disagree with their kids doing one of the above. I know songs that were played on the radio in 1960 that would not be allowed today, even though today…

i can make arguments as to potential merits of kids having a beer/cigarette, listening to swear words, or witnessing casual violence. i cant make an argument for letting kids see hardcore pornography in any capacity.

Re: Online age verification is the hill to die on

#447
post #429
post #8

The one and only method I will participate in is server operators setting a RTA header [1] for URL's that may contain adult or user-generated or user-contributed content and the clients having the option to detect that header and trigger parental controls if they are enabled by the device owner. That should suffice to protect most small children. Teens will always get around anything anyone implements as they are alr…

I agree with the general idea, but I would like this header to be more fine grained than just a binary "adult" or not. For example, so that you can distinguish between content that is age appropriate for teenagers and older from content that is suitable for all ages.

It should indicate which exact HTML elements are classified, so that a social media feed can selectively tag posts on the home feed.

Re: Online age verification is the hill to die on

#448
post #292

Earlier quoted context omitted.

>I disagree. The ability to render a page could simply mean that parental controls were not enabled on the device. Not being able to detect all children doesn't mean that being able to detect 80% of them is somehow less disturbing.

The point and overall goal should be to not signal anything to the server operator unless a credit card is being used. Everyone is whomever they claim to be as far as anyone is concerned, until payments are required which today means sharing identity and age (via the credit card information on file with the financial institution and is shared today) . In the case of RTA the only signalling taking place is a server he…

This is also how age attestation works. The client could be anyone at any age, all the server knows is they've opted to see over-18 content

Re: Online age verification is the hill to die on

#450
it didn't have to be like this. If we had trusted NGOs with strong funding and a track record of independence and integrity they could shim between token generation and application. Allowing governments to produce identity tokens and applications to verify them with the shim blocking each side from knowing of the other.

But we don't have that, so he's probably right.

Post reply on HN