Live data from Hacker News

Online age verification is the hill to die on

x.com

611–620 of 750 posts

Re: Online age verification is the hill to die on

#611
post #34

Age verification on Australian social media has loopholes. Underage influencers use an agency to manage their social media for them. So anyone with enough followers or money can continue using social media under the age of 16. If you are going to implement age controls, you should implement a ban on underage influencers as well.

That's the legal loophole that I'm sure a tiny number of people are using. In the real world, reportedly around 3/4 of kids under 16 that were using social media still are by either having changed their age during the window and using a sibling or older friend to do face scans for age recognition, or by creating new accounts and again using an older friend/sibling/relative etc. for the age verification. I heard about the ways children of some of my cousins got around it at Christmas, and their parent's didn't care!

The most embarrassing thing is that our Government thought the idiotic idea was workable in the first place... But of course now they've gone and made things worse, because now kids' profiles pretend to be older, so more inappropriate stuff (like gambling ads for those who put an over-18 birthdate) can get targeted at them - great job, eSafety Commissioner!

Re: Online age verification is the hill to die on

#613

In the age of AI I think it’s only necessary and inevitable to implement some of kind of internet ID system to stop the massive onslaught of AI generated fraud, malicious hacking, and spam. If age verification is a Trojan horse to erase online anonymity, so be it, I see that as a worthy goal. Humans are inherently social, and social networks are based on trust. Trust is primarily a function of reputation, peer pressu…

> Trust is primarily a function of reputation, peer pressure, and legal consequences. The trust is somewhat of a one-way street. We are supposed to trust the entities in power. If we break their trust, there are consequences. If said entities break our trust, we can do little about it. > I don’t see why anyone would want to remove any of this. To protect some freelance journalists in Iran? For some, perhaps. However,…

> you will continue to still use and profit off the Internet in the meantime

If I stop my internet use that won't save anybody, so there's no point in doing it. If shutting down the whole internet is necessary to save a life, I would support it. The only reason I don't is because that's not possible and even if it were possible it would not actually save more people than it would harm right now.

Re: Online age verification is the hill to die on

#614
post #301

In the age of AI I think it’s only necessary and inevitable to implement some of kind of internet ID system to stop the massive onslaught of AI generated fraud, malicious hacking, and spam. If age verification is a Trojan horse to erase online anonymity, so be it, I see that as a worthy goal. Humans are inherently social, and social networks are based on trust. Trust is primarily a function of reputation, peer pressu…

We will see how your opinion changes when someone steals your ID and voice and you end up being defrauded due to the government chosing the cheapest Indian shop to mishandle your data

Not going to be any worse than the oncoming onslaught of AI-powered scam, fraud, and hacks that are enabled by a lack of legal consequences.

Re: Online age verification is the hill to die on

#615
post #299

Earlier quoted context omitted.

That's not the best example, since the levels set for Prop 65 warnings are so low that the warnings are effectively useless; every single commercial building in CA now somehow causes cancer.

Surely we both understand the point I was making in that labels are already compelled by laws today. Fine, cigarettes must be labelled as being a risk of causing cancer. The punishment for failing to do this is both civil and federal penalties including massive fines and federal prison time.

Now that I think about it, perhaps that example did a good job of demonstrating how ill-conceived requirements can wind up having zero effect except for just making everything a little bit more inconvenient.

Re: Online age verification is the hill to die on

#617

In the age of AI I think it’s only necessary and inevitable to implement some of kind of internet ID system to stop the massive onslaught of AI generated fraud, malicious hacking, and spam. If age verification is a Trojan horse to erase online anonymity, so be it, I see that as a worthy goal. Humans are inherently social, and social networks are based on trust. Trust is primarily a function of reputation, peer pressu…

My first question to you is whether you are a pro-privacy advocate yourself, znnajdla. I don't see any biographical information listed in your profile so I'd initially assume that you value privacy on some degree. I am curious as to whether there are contexts where you want to be able to post an opinion through a pseudonym, without your ideas being easily tied to and subjected to judgments based on your legal name, y…

> I don't see any biographical information listed in your profile so I'd initially assume that you value privacy on some degree.

Extremely powerful entities like the CIA or NSA could easily personally identify me from my HackerNews profile if they wanted to, as could a dedicated attacker. The problem with "privacy" on the internet right now is that it's a lie - you only have privacy from your peers and ordinary citizens, but not from powerful entities. It would be better if we had a level playing field and everyone could be identified by everyone. Then the normal evolved human behaviours of trust-based social networks could function properly, and we could also fight AI-bot-based social media control, scam, and fraud.

It's not "privacy" it's "information asymmetry" which I'm attacking.

Re: Online age verification is the hill to die on

#619
post #607

Earlier quoted context omitted.

> That's why everyoneisover18.com forwards the request to my bank or my broker Doesn't work. The response won't be signed by real-broker.com. The permission request/response itself goes direct from the server at restricted-site.com to the server at real-broker.com over TLS, so you can't MITM it, it's not controlled by the client and you won't be able to just pass out a cached response. Your malicious client plugin co…

real-broker opens a web page allowing them to verify somehow. The browser extension sends me their URL and cookies so I can load the same page and verify myself. All automated of course.

You could, you could also go to their house and go through the process for them, but in either case I don't think it's going to scale very well (rate-limiting would seem to be called for, maybe with 2FA as well, to mitigate this sort of thing and remove the possibilities for automation).

But sure, you could subvert it on a small scale, just as you can borrow someone else's driving license to register in 'normal' systems already. You could also register an account, validate it and then sell the login details, regardless of what proof of age scheme you use.

The point is the scheme is no worse at validation than asking for ID and it protects user privacy by keeping all ID details away from individual websites, which is the more important part IMHO.

Re: Online age verification is the hill to die on

#620
post #99

Earlier quoted context omitted.

Make it a duplication resistant hardware token that you can get for free then. The stakes just aren't high enough to worry about these kinds of edge cases.

The stakes just aren't high enough for us to implement any of this crap for the Internet in the first place. Let alone an entire government-administered hardware supply chain.

Would be great, if we could all agree on that and simply everyone who is tasked implementing it in code refusing, and then letting non-engineers themselves try to do it and fail, and then have a good laugh about the figurative middle finger we gave them for their bs.
Post reply on HN