Live data from Hacker News

The Age Verification Trap: Verifying age undermines everyone's data protection

spectrum.ieee.org

731–740 of 1001 posts

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#731

We'll try everything, it seems, other than holding parents accountable for what their children consume. In the United States, you can get in trouble if you recklessly leave around or provide alcohol/guns/cigarettes for a minor to start using, yet somehow, the same social responsibility seems thrown out the window for parents and the web. Yes, children are clever - I was one once. If you want to actually protect child…

As a parent blocking websights is a joy, maybe the rule should be to allow guardians more ability to control that. Trying to block some services is not trivial As a human, I'd love to see the rest of you fools quit that. If HN ever starts to algorithm me I'll be gone too.

And as a bonus you can block your boomer parent's access to cnn and msnbc (or whatever its called now) and perhaps fox. It will make Thankgiving a lot more pleasant for all.

PS Mom, I don't know why cnn doesn't work anymore. ;)

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#732

Earlier quoted context omitted.

Thanks for posting this. The inherent problem with all zero knowledge identity solutions is that they also prevent any of the safeguards that governments want for ID checking. A true zero knowledge ID check with blind signatures wouldn't work because it would only take a single leaked ID for everyone to authenticate their accounts with the same leaked ID. So the providers start putting in restrictions and logging and…

This specific problem is solved by requiring that any anonymous ZK ID once used for an account be marked on an immutable ledger preventing multiple uses of the same ID. Sharing it would be pointless as multiple attempts to use it get burned. Yet none of those sites know who you are, only that you have a unique valid ID pass. They just have to check any login attempts against that ledger - easy enough.

> They just have to check any login attempts against that ledger - easy enough.

So like CT logs, but several orders of magnitude bigger? I thought centralized TLS revocation lists failed due to scale. How will this differ?

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#733

Earlier quoted context omitted.

> give parents strong monitoring and restriction tools The problem is that it's bloody hard to actually do this. I'm in a war with my 7yo about youtube; the terms of engagement are, I can block it however I want from the network side, and if he can get around it, he can watch. Well, after many successful months of DNS block, he discovered proxies. After blocking enough of those to dissuade him, he discovered Firefox…

Sounds like a smart kid, is part of you secretly proud of him for his tenacity? Is it impractical to keep an eye on what he's doing on his computer, i.e. physically checking in on him from time to time? How about holding him responsible for his own behavior, to develop respect for the rules you impose? Is it just hopeless, and if so how come? Is it impossible for him to understand why you don't want him watching cert…

Personally I wouldn't want to expose a child to "the algorithm" ie recommendations. It turns up useful stuff but (IMO) the stream contains an unacceptable concentration of radioactive waste and becomes increasingly concentrated if you click on any of it.

I might suggest explaining this to him, providing a uBlock filter to sanitize the page, and requiring use of said filter.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#734
post #318

Earlier quoted context omitted.

This only works if I ban my child from having any friends since they all have unlimited mobile access to the internet.

Could your child not just call or text their friends? Or is the real expectation to not have to intervene at all about their preferred platform?

I'm saying they'll use their friend's devices.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#735

Earlier quoted context omitted.

I know this is weird, but I'm in some ways not really sure who is on the side of freedom here. I get your position, but like. The whole idea of the promise of the internet has been destroyed by newsfeeds and mega-corps. There is almost literally documented examples of Facebook executives twirling their mustaches wondering how they can get kids more addicted. This isn't a few bands with swear words, and in fact, I thi…

> I just like, can't help but start with fuck these companies. All other arguments are downstream of that. Better the nanny state than Nanny Zuck. How about we reject all institutional nannies? It is much easier to implement user-controlled on-device settings than any sort of over-the-Internet verification scheme. Parents purchase their children's devices and can adjust those settings before giving it to their kids.…

My friends kids have access to his home servers. They don’t get to roam on the internet. It’s shocking to think parents might structure their child’s lives.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#736

Earlier quoted context omitted.

I know this is weird, but I'm in some ways not really sure who is on the side of freedom here. I get your position, but like. The whole idea of the promise of the internet has been destroyed by newsfeeds and mega-corps. There is almost literally documented examples of Facebook executives twirling their mustaches wondering how they can get kids more addicted. This isn't a few bands with swear words, and in fact, I thi…

>There is almost literally documented examples of Facebook executives twirling their mustaches wondering how they can get kids more addicted. Then close their business. Age verification just makes their crimes even more annoying.

Yes, please close it!

Ah, oh, decision makers are shareholders themselves and are benefiting from this too.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#737
Is this article AI-generated? https://www.pangram.com/history/f421130b-eefc-4f8c-b380-da0a... . I find it worrying that authors don't disclose the amount of AI assistance used in drafting and editing upfront. It sets a worrying precedent where everything is AI unless proven otherwise.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#738
post #608
post #423

Earlier quoted context omitted.

In your system, can companies verify age offline, or do they need to send a token to the Government's authority to verify it (letting the Government identify and track users)? Switzerland is working on a system that does the former, but if Government really wants to identify users, they can still ask the company to provide the age verification tokens they collected, since the Government hosts a centralized database t…

That assumes the companies store the individual tokens, as does the government. Neither of which are part of the design, but could be done if both sides desired it. The Swiss design actually doesn't store the issued tokens centrally. It only stores a trust root centrally and then a verifier only checks the signature comes from that trust root (slightly simplified).

If companies are required to verify age, then it's in their best interest to store all tokens, just in case they are ever accused of not verifying it.

The Swiss E-ID system stores people identifiers and token status lists in their so-called "Base Registry". From https://swiyu-admin-ch.github.io/technology-stack/#credentia...

> Decentralized Identifiers (DID) developed by the W3C represent an identifier standard that provides a subject-controlled method for identifying individuals, organizations, or objects online. In the swiyu Trust Infrastructure, DIDs are utilized as a standard identifier for issuers and verifiers. They are centrally hosted on the swiyu Base Registry.

> In this protocol, the trusted authority issues certifications (“trust statements”) concerning the identity (i.e., who is the real-world identity controlling a DID) and legitimacy (i.e., who is allowed to issue or verify credentials of a specific VC schema) about an entity as SD-JWT VC and publishes these trust statements in the trust registry.

> Token Status Lists are signed, maintained and published by the credential issuers but hosted on the Base Registry.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#739
post #410

We'll try everything, it seems, other than holding parents accountable for what their children consume. In the United States, you can get in trouble if you recklessly leave around or provide alcohol/guns/cigarettes for a minor to start using, yet somehow, the same social responsibility seems thrown out the window for parents and the web. Yes, children are clever - I was one once. If you want to actually protect child…

It's very easy to lock up alcohol/cigarettes, a child should never have access. Internet usage is more like broadcast media, a child should have regular access. The positives and negatives of Internet usage are more extreme than broadcast media but less than alcohol/guns. The majority of people lack the skills to properly censor Internet without hovering over the child's shoulder full-time as you would with a gun. Be…

Ironically, the government that is pushing this only set a drinking age just a couple of years ago (as in the last 10 years). In case you believed this was actually about kids.

Re: The Age Verification Trap: Verifying age undermines everyone's data protection

#740
post #328

Earlier quoted context omitted.

> holding parents accountable for what their children consume There is a local dive bar down the street. I haven't expressly told my kids that entering and ordering an alcoholic drink is forbidden. In fact, that place has a hamburger stand out front on weekends and I wouldn't discourage my kids from trying it out if they were out exploring. I still expect that the bartender would check their ID before pulling a pint…

That same argument doesn't hold water on the internet. Its a communication medium. Its like a flow of information. You don't enter or leave physically spaces. the information flows to you where ever you are. trying to apply the same kinds of laws to the internet is a recipe for disaster because you are effecting everyone at the same time.

Yes, afaik authentication is performed by applications at L7 and as such flows via Internet protocols like anything else.

All kinds of laws are applied to services provided via Internet. For example, once upon a time people said collecting sales tax was an insurmountable problem and a disaster for ecommerce. Time passes and what do you know, people figured out ways to comply with laws.

Post reply on HN