>It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.
Then who should? Government, where each implementation strips away rights to privacy - which in some countries, including mine, are a constitutional right? Where it expands powers of government to track everyone's activity online - and remember we're one election away from total policy shift(just like with latest US elections)?
Free market? The profitable solution is, depending on environment - either ignore the problem(profit from ads served to children, no extra work necessary), or strip away all privacy (to filter out bots and get paid more per ad).
The sad reality is that "parent should take responsibility" is least bad option available, and takes into the account individual development of a child.
Even creation of a highly regulated child only internet creates more problems - as now that becomes a highly profitable target for bad actors(both individual abusers, and companies trying to serve ads)
In principle, it is possible to make a privacy-preserving age check.
Site/app asks "≥18?", device generates a UUID specifically for that [app/domain + device], the device passes that UUID to government database along with the "≥18?" question and the ID card info but not the app/domain, government database gives the answer and signs just the UUID and the answer and doesn't include any ID card info.
Government doesn't know what you're looking at, website doesn't know your ID.
(There's probably also better ways to do all this, I'm not a cryptographer and I expect that will be obvious from this comment to people who are).
In reality, the ones making such check will want extra capabilities 'just in case' as we observe now, or just go for simpler solution because it's cheaper.
How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.
It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.
Even in countries in which this requires a subpoena, agencies break the law frequently and don't get punished.
Legal systems aren't computer systems. This isn't a technical problem but a social/political one.
> How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.
True, but as this problem exists without any ID at all*, I don't see how the addition of the ID cards makes any difference?
> It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.
This is why I specified a "UUID specifically for that [app/domain + device]". Can't aggregate when each app/domain gets a different signed UUID.
> Legal systems aren't computer systems. This isn't a technical problem but a social/political one.
While true, the reverse also applies: computer systems are not legal systems.
I think many lawmakers' ignorance of this is to the detriment of everyone.
In this case, the social/political problem is: we want to stop kids accessing age-inappropriate material.
The options-space for doing this appears to be:
(0) give up
(1) require parents to limit their kids' behaviour (to which I say: "Have you met a kid? Do you remember being one?")
(2) require websites to age-rank appropriately (to which I say in a sarcastic tone of voice: "Gee, that worked soooooo well for GDPR")
(3) require operating systems to intermediate. Will this suck? Yes. Will it be buggy? Also yes. Will there be false positives and false negatives? Yes to both. Will it be a constant fight as kids keep finding loopholes? Indeed.
But you know what else? All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out. A school full of kids can beat their parents at the security game because they have more time to spend on finding exploits than the parents have to spend keeping up, the reverse is true of the difference between kids and Google LLC etc.
It doesn't need to be perfect, the kids aren't a computer program.
What does need to be held to a high standard is making sure the OSes don't leak all over the place.
> What would be the incentive for meta to deploy that against their own self interests?
The normal method is passing laws. That's kinda the point of laws.
Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.
> Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…
Hardly. This is more like gardening. It matters much less if kids get a few days of messing around where they're not ment to be, than if it's continuous.
And ultimately, if you want to run a business without spending money on legally required actions, you're in the wrong business, nobody should shed tears for you.
> Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.
In an ideal world. Personal experience has shown that isn't the case with him.
I'd be on board with banning micro-targeted ads, and more broadly any use of psychology to induce similar states as regulated exogenous drugs equivalent to the simple language descriptions of US Schedule I, II, and III.
However, the issues are rather broader than showing ads to kids who have no money to spend on whatever is being advertised.
It cannot work *perfectly*, but unlike most crypto stuff, it doesn't have to (at least, that part doesn't need to). It's a social/political problem, not a technical one.
The goal doesn't even need to be to make a completely perfect, impossible to circumvent, barrier for all minors; all this needs to do is just make it equally difficult for a minor to get adult (for whatever definition thereof) content online as it is to get tobacco or alcohol or gambling in real life, the hard part being to do so without compromising privacy, privacy being the bit which has to be done perfectly.
> See, that's why this can't be solved technically.
Which "this"? There's multiple things here. I'm suggesting one specific "this" (anonymous age verification) in response to another "this" (the internet is not suitable for all ages).
> Pornhub has a decent amount of sexual health material on it so there's an argument to be made for allowing teens access to at least parts of it.
There's more content on the internet than any human can consume in a lifetime, so the presence of age-appropriate stuff as a subset of some website is no more relevant than how the intro to a porn film ("there's something wrong with my fridge, it's sooooo hot", though I am thinking of a beer commercial parodying this) is not itself 18 or R18 or whatever your local certification is called.
> So we agree that this is going to end poorly?
On the contrary, literally all the rest of my comment after that quote is cut explain why we *do not agree* about this.
> Government doesn't know what you're looking at, website doesn't know your ID.
But then the government knows your location at any point of time and how often you use websites requiring the age check. Also, if your device is configured to do it automatically, a child can also follow this verification.
Google and Verizon sell that data to the government right now. The US's official position is that buying info they aren't legally allowed to collect is perfectly fine, as if you were given a privacy right in the constitution only to enable an info broker economy, and not because of the obvious and understood harms of the government having whatever info about you they want.
If you want the US government to not know something about you, unfortunately there's a lot of changes that need to happen, including entirely new political parties and making changes to the Supreme Court, and popular support for taking the privacy rights you already have much more seriously.
> But then the government knows your location at any point of time and how often you use websites requiring the age check.
Not as described. There's no location info in that path, and the signed statement of that UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.
(Should I consider expiry? It's not like people age backwards?)
> Also, if your device is configured to do it automatically, a child can also follow this verification.
Yes, if that device has been associated with a government ID and also the government ID signing process fails to make use the things we've already got on-device like how my phone reads my fingerprint to know I'm me and can store copies of some forms of government ID (in some places but not where I live, Apple Wallet apparently only supports some US states, Japan, Greece, and UAE).
> So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?
How? Phones are already locked down pretty hard. Anything like this would need to be in something secured at the OS level just to stop signatures getting leaked between apps.
If you're thinking "kid roots device, replaces OS entirely", that's not the problem of the manufacturer of the OS that just got deleted.
If you can't revoke the token then I'll just sell mine to whomever needs it.
Kids will beg/borrow/steal their parents / older siblings ... etc.
The "harden the device, bake in controls that are difficult to circumvent and managed by not-the-primary-device-user" approach is _very_ similar to DRM.
All that does is punish the innocent.
I have never once had VLC tell me that the mkv file I just opened can't be played because I'm not in the right region or because my screen is too old to support encryption.
I have had family learn the hard way that DRM is not in their best interest, though. Now they just ask me for the movie on a pen drive when I visit next :).
"Never well enough" for stopping teens (and pre-teens) installing access tokens?
Has any adolescent in history ever managed to so much as spoof someone else's session cookie *on their phone*? And if so, when? If this is a flaw which comes up once every five iOS versions or whatever, who cares?
> Kids will beg/borrow/steal their parents / older siblings ... etc.
They occasionally get alcohol, too, despite restrictions. The point is to *mostly* stop them.
And it's not like the payment systems have not already solved the same problem.
> All that does is punish the innocent.
Which is literally something I'm trying to solve with my suggestion up-thread: here's a way to do age attestation that doesn't need to punish anyone.
Which is not how it should be done at all. Outsourcing your security to a big brother leads to all kinds of problems like planned obsolescence and spying.
Which would be fine, if it was just a trade union like originally designed. I really love the original idea of EU. I could even get behind more federation style, although trade union is vastly preferable for me - but I do understand people pushing for it.
Yet EU has overstepped that ages ago, and you can see that with SKG recently. The only tool we, as citizens, have to actually try to affect EC is effectively useless. EC can be wined and dined by lobbyists, including outside of official recorded proceedings(!) and can just ignore you.
Not to mention a lot of other systems in EU were made with idea that countries would operate for their own best interest, and that interest was aligned for every member state:
- Shared energy market, which was crashed by Germany ideologically decommissioning nuclear power plants in middle of energy crisis.
- Free movement of people within Schengen area - which is crashed by countries taking mass of immigrants which they think they need(i don't live there so i won't judge), but then they can move around whole of the area - including the countries with vastly stricter regulations for migration.
- Digital euro as a backdoor to enforce transition to euro across the whole area, limiting the ways in which member states can dictate their own monetary policy. Digital euro must be accepted by all vendors across EU - even in the countries not using euro at all.
And that's ignoring slippery slope towards CDBC with expiration date.
- erosion of free speech and constant doublethink language, and noticing flaws in EU is undemocratic/euroskeptical(biggest sin possible) - even if it comes from "how to improve EU" point of view. or even if one points out that EU itself isn't democratic.
- double loyalty in case of politicians where there's a conflict between national and European interest. Do you pursue national benefit, or do you go against it in such cases and hop onto EU track - where there are plenty of unelected positions?
and also double loyalty in case of EC members - they should pursue good of all EU by their own charter, but there's no punishment nor anything systemic to discourage them from abusing their power and pursuing national interests.
All of those are minor or major flaws that slowly fracture EU. And by this point I don't think the system can be reformed.
>Lets say the primary force we need to prevent is russian influence campaigns that back and push far right nationalists who will destabilize democracy. Is that a sufficient reason for controls?
No. Because if you solve underlying tensions in society the so called russian propaganda has nothing to take hold on.
Also who and under what rules will decide which propaganda is allowed? is American propaganda fine? Chinese? Japanese? UAE?
Not only this creates dissident, and suppresses voices critical of current government. but also gives extraordinary power on level of soviet union to current government.
You might trust current EU to not abuse it, but it might take a single elections, or single term for un-elected(!) officials in EC for attidute to change.
Just like in US - a lot of powers were granted but suddenly there's a person willing to abuse them.
For that to be even considered in EU we would need a lot more check and balances - especially for European Comission and Council.
Another issue is - is EU a trade union or federation? if former - this is outside of EU's responsiblities and powers. if later - look at point above.
If you really wanted to solve this problem you would go after advertisers and data collection companies, and regulate them.
>It doesn't answer the question of "what do we do about parents that don't do their job properly."
Like with normal cases - have court go over this.
But decision if any form of age lock should be implemented or not is up to parents. You cannot just shift argument to "you HAVE to restrict children from internet or else!"
What about the California version, where the government says you HAVE to offer parents the choice to restrict their children from the internet or not? That seems like a pretty reasonable middle ground, and solves the actual problems without denying privacy.
or cyclists should have their own lanes, pedestrians shouldn't walk on them - and vice versa. and if you're stuck behind someone slow just overtake them when you can.
Safe or not - it is up to individual to decide if it is worth the risk.
I hate this approach to them problem, because it is not a technical problem.
Because it focuses on technical aspects and accepts the premise of 'age verification must be solved'. It doesn’t, and discretion what content and and what age children and teenagers can consume should be up to parents.
Then who should? Government, where each implementation strips away rights to privacy - which in some countries, including mine, are a constitutional right? Where it expands powers of government to track everyone's activity online - and remember we're one election away from total policy shift(just like with latest US elections)?
Free market? The profitable solution is, depending on environment - either ignore the problem(profit from ads served to children, no extra work necessary), or strip away all privacy (to filter out bots and get paid more per ad).
The sad reality is that "parent should take responsibility" is least bad option available, and takes into the account individual development of a child.
Even creation of a highly regulated child only internet creates more problems - as now that becomes a highly profitable target for bad actors(both individual abusers, and companies trying to serve ads)
reply