Live data from Hacker News

Do Not Turn Child Protection into Internet Access Control

news.dyne.org

461–470 of 486 posts

Re: Do Not Turn Child Protection into Internet Access Control

#461

Earlier quoted context omitted.

I don't think it's a market failure. The reality that password-gating software installation at the OS level can be done on most desktops but not most phones is the opposite sign of a market failure. Mobile OSes have increasingly stripped down capabilities in recent years precisely because of anti-competitive practices. The reason standard desktops have not evolved even better parental control features is not because…

You're focused on "password gating" for installing apps, but the largest subject here is websites. (also a nit: very few Linux systems are set up with noexec on home directories, I know "portable apps" exist for Windows, and I assume MacOS has similar dynamics) > the absolute level of demand for parental control features has been low until recent years, and even this recent wave of demand is somewhat manufactured. I…

Ok, I'll give you my two cents, but you'll have to fill in the details on your own.

After curated local content, you could get an old desktop (and later a laptop too) and install a Linux distro of your choice on it, something reasonably modern. Put Minecraft on it, and show your child how to start a singleplayer world. Show them how to use the web browser, and add a curated list of sites in the bookmarks. Leave them to figure out the rest on their own. Withhold the sudo and BIOS passwords at the beginning, but give them the passwords when they're ready. I think for the sudo password, it's when they try to host their own Minecraft server for the first time, and BIOS password when they explicitly ask you for it (though these may never happen, depends on the kid, so set your own milestones). Configure the OS and programs as you see fit early on, but don't make changes secretly after they've had the computer for a few months. Block unwanted sites and limit access times with your WiFi router or OS firewall as you see fit. Eventually, they'll figure out how to get around or tear down the barriers you put up, and that's fine, just pretend you don't know or give them a vague hint if they do something too egregious like stealing the neighbor's WiFi. Gradually loosen your control as they get older. And if something breaks, let them watch how you fix it.

Don't give them a phone. Or even if you do, strip it down so that it can only be used for calls, but you can add apps over time. Don't buy them mobile data. Let them buy their own phone and mobile data when they're old enough to earn the money, and that's when your digital supervision ends.

Regarding a solution that "just works": when your child goes out to play, you're the guide that protects them and shows them around town. You know the roads, buildings, people and rules better than they do. There aren't any solutions that "just work" which exempt you from your job as a guide. Well, there are, but that just means someone else is watching your child for you. I think digital parenting is similar in this regard. Parents needs to understand the digital landscape well enough to guide and advise their kids. Solutions which don't strip away parental rights and responsibilities will require some effort to use.

Re: Do Not Turn Child Protection into Internet Access Control

#462

Earlier quoted context omitted.

The arguments for background checks generally have to be split into two separate classes of people. The first is the mentally ill. Intuitively it seems desirable to say that someone undergoing treatment for e.g. depression shouldn't buy a gun. The problem here is the massive perverse incentive. If you're pretty depressed but you're not inclined to forfeit your ability to buy firearms, you now have a significant incen…

> And if you have a policy that doesn't even solve most of the original problem while creating several new ones, maybe it's just a bad idea? Are you saying everyone should be allowed to have a gun? Because that's genuinely an interesting position. My proposal came from the view that if we need gun control, we should make sure it cannot be abused into a self reinforcing loop where a completely disarmed population is t…

> Are you saying everyone should be allowed to have a gun?

We can probably make an exception for people who are currently in prison.

> I would be interested if there is research into these indirect effects you talk about.

This is a political question so all of the research is performed by partisans for one side or the other. On top of that, most of this stuff is inherently hard to measure, e.g.:

> For example I'd like to know how often people actually snitch, whether there are attempts/procedures to protect info about who snitched, how often they are killed for snitching, how often having a gun helps them, etc.

The government is going to try to avoid disclosing who snitches and the criminals are going to try to find out and retaliate. But if the criminals have a way of finding out (e.g. bribe the cops) then it will be illegal and no one will want to admit it's happening, and likewise if they successfully retaliate they'll want to do it a way that doesn't catch them a murder conviction.

So now someone few people are going to notice winds up dead. If they were an informant at some point in the past, those records are closely guarded for obvious reasons, so how is someone trying to collect statistics even supposed to know that? Likewise, if their death is made to look like an accident or the killer is never caught, how do you know how often it was actually an accident or an unrelated crime?

Which then leads into this:

> E.g. because if a hit can come at any time from anywhere, having a gun might only give a feeling of safety.

Part of the premise of having a weapon is as a deterrent, which gives you another measurement problem: If a lot of the snitches are keeping weapons even though they're not allowed to and that's successfully deterring anyone from trying to kill them, neither the snitches nor their hitmen are going to admit to either one because they're both breaking the law.

The lack of anybody having good numbers also feeds into the problem itself, because then the snitches have to guess whether it will help them and a lot of them are going to regard the risk of getting killed as a bigger threat than the risk of getting caught with a gun. Or worse, the hitmen will like their chances better when the law requires their target to be unarmed. And both of those happen stochastically as a result of the inherent uncertainty regardless of your own guess for how effective the victim having a weapon is at deterring retaliation.

Re: Do Not Turn Child Protection into Internet Access Control

#463
post #227

Earlier quoted context omitted.

> filtering those devices' network requests at the network gateway, or filtering one hop up onto the provider's infrastructure These things are not possible with any reliability, we spent two decades encrypting everything.

I'm not imagining filtering based on the path. Even with https, hostname is visible before the handshake. And even when Encrypted Client Hello is widely implemented, it's also easy enough for network providers to drop any ECH packets from devices flagged as "for children" and signal to those devices that their handshake must reveal the hostname, at least to the router doing the filtering.

What's the standard signal for "please disable CH encryption because your network wants to spy on you" and why would any device respect it?

Re: Do Not Turn Child Protection into Internet Access Control

#464
post #433
post #226

Earlier quoted context omitted.

ZKPs don't buy anything, since an online service can sell them by the thousand and you're just trusting the client that it belongs to the actual user. You might as well just do "User-Age-Category: 18plus" then and save a headache.

> then if i want i can jump through some hoops and pay some money or something to get a digital id that lets me attach a zkp

Yeah, so some guy is selling his zkps by the millions for a dollar each. Since they're zkps you can't find out who it was, and the system is pointless.

Re: Do Not Turn Child Protection into Internet Access Control

#465

Earlier quoted context omitted.

> Do please be specific about those. Here is one example: It's likely that we will never know who was behind the attempted backdoor in the xz library, which was almost successful in making a huge number of Linux installations worldwide vulnerable to remote exploitation. [1] That malicious contributor is protected by online anonymity. Now, I know that it's probable that a state actor was behind "Jia Tan", meaning they…

> > and justify for the class why those involved couldn't have voluntarily done away with anonymity for that particular interaction. The project in question could have chosen to verify identities if they deemed it worthwhile to do so.

> The project in question could have chosen to verify identities if they deemed it worthwhile to do so.

But isn't this exactly what various social media companies are doing now? Choosing "to verify identities" because they have "deemed it worthwhile to do so?"

And don't tell me "the difference is scale", unless you're prepared to explain exactly what difference that makes.

Re: Do Not Turn Child Protection into Internet Access Control

#466

Earlier quoted context omitted.

That isn't a third category, those are people who have been convicted of a crime and want to commit another one. It's the same general category of not being able to solve people committing crimes by making already-illegal things even more illegal. And on top of that you get to add two new problems. The first is the deterrent to reporting, both before and after a conviction. In the original case the victim now can't e…

> those are people who have been convicted of a crime and want to commit another one FWIW, this is why i said "anti-social" and not criminals in my original post. I think with many habitual abusers, the warning signs are there for a long time (often from childhood) before they break the law and before they are convicted. > "permanently can't own a gun" This points to other issues with the current system of punishment…

> FWIW, this is why i said "anti-social" and not criminals in my original post. I think with many habitual abusers, the warning signs are there for a long time (often from childhood) before they break the law and before they are convicted.

But then what are you proposing to do? Tell people they lose a right based on vibes even though they've never been convicted of anything?

> Maybe what we need is a post-prison evaluation to determine which case we're dealing with and whether restrictions (if any) should be temporary or permanent.

Maybe we should reorient prisons into places that actually rehabilitate prisoners and then release the ones that are actually rehabilitated.

> FWIW regarding domestic violence, I think any target of it would be crazy to stay with the aggressor in the same household.

This is one of the things which is hard for the system to tell from the outside. There are legitimate predators with no record because they have the right friends. Then there are alcoholics who are violent drunks and therefore have a record, but haven't had a drink in ten years and then everything seems fine until they have a relapse. Or the exact same thing except that they stay clean and then everything actually is fine.

There are also people who live with an occasionally violent partner because the alternative was their relentlessly violent parents. I find it hard to judge people who have only bad options and then pick one of them.

> the abuser should be required to pay for housing for a reasonable period of time so the target can move away, etc.

The situation commonly happens to begin with because they're both poor and can only stay above water by sharing accommodations. If you want shelters then build shelters; we don't need things that would only work when the perpetrator has enough money to lawyer their way out of it anyway.

Re: Do Not Turn Child Protection into Internet Access Control

#467
post #463

Earlier quoted context omitted.

I'm not imagining filtering based on the path. Even with https, hostname is visible before the handshake. And even when Encrypted Client Hello is widely implemented, it's also easy enough for network providers to drop any ECH packets from devices flagged as "for children" and signal to those devices that their handshake must reveal the hostname, at least to the router doing the filtering.

What's the standard signal for "please disable CH encryption because your network wants to spy on you" and why would any device respect it?

It's not: disable CH encryption because your network wants to spy on you.

It is: disable CH encryption because the owner of this device, to whom we are leasing connectivity, has set the "isChild" flag for this device to true in her account with us so that we can filter the Internet for this device.

There's no such standard signal right now. But I'd prefer such a signal strongly over code that I cannot control running on my own device to enforce legislation. If we're going to enforce these things somewhere, code on my devices is the last place I want that enforcement to happen.

> ...and why would any device respect it?

Because if they do not the ISP drops all further packets and the connection dies.

Re: Do Not Turn Child Protection into Internet Access Control

#468

Earlier quoted context omitted.

I mean, I don't disagree with the sentiment of keeping trans ideology away from kids, in exactly the way I'd want to protect them from any kind of religious indoctrination.

Gender dysphoria can be medically studied, is not an ideology and is not a disorder. Hope this clears things up.

And lobotomies are a legit cure as is all the other quackery that profession has provided as facts.

Re: Do Not Turn Child Protection into Internet Access Control

#469
post #464
post #433

Earlier quoted context omitted.

> then if i want i can jump through some hoops and pay some money or something to get a digital id that lets me attach a zkp

Yeah, so some guy is selling his zkps by the millions for a dollar each. Since they're zkps you can't find out who it was, and the system is pointless.

no. you can pay verisign or google or the government of estonia or whatever for a digital id and they can issue you a zkp that is signed by them that attests whatever without giving up your identity.

Re: Do Not Turn Child Protection into Internet Access Control

#470
post #229

Devices with child locks turned on really shouldn't have access to everything on the Internet. A simple protocol could let cooperating websites know when child locks are on, so they don't show inappropriate content. Whitelisting or blacklisting could handle the rest. This doesn't mean every device needs to implement child locks. It also shouldn't affect anyone using unlocked devices at all.

> a simple protocol could let cooperating websites know when child locks are on, so they don't show inappropriate content. Isn't that literally the California law?

Sort of, except OP also says:

> This doesn't mean every device needs to implement child locks

Which is the exact opposite of what the California law says, going so far as to mandate that open source embedded operating systems ask users for their age.

Post reply on HN