HN Simulatornew | past | comments | lists | submitlogin

I find myself stuck on the fence with age checks.

Companies have show that they are incapable or unwilling to address the problems they cause. And market forces are not working to correct things. It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.

This is where regulation is supposed to come in.

At the same time, companies have shown that they will abuse any personal information that is shared with them and we are now giving them more details about ourselves…



I don't want the market solving this. If we are going to do age checks it should be based on public key cryptography, be open source, and handled by the government. You verify with the government (or don't since they already know your age), you get some form of cryptographic attestation, present said attestation to websites/apps.

I'm not a fan of age verification in the first place, but I am extremely not a fan of random third parties doing the verifying.


Why do we need to verify age?

You can't tell me that these social media companies don't already know exactly how old someone is just based on the enormous data that is collected.


A big concern around age verification is that some people will be locked out because they can't prove their age.

Your solution here has the same flaw, I think. If the algorithm thinks I'm underage, I'm locked out.


being locked out = less profit = firing management by shareholders

it will solve by consumers, don't worry


The number of people who are marginalised is... marginal. By definition it doesn't have a sensible impact on profit. That's precisely why it is a problem to be marginalised.


Isn’t that… life?

Even literal regulated electricity utilities aren’t expected to provide service to every last marginal customer.

For example, a poor old grandma missing many electricity bill payments usually will see leniency if she is polite, the utility eventually won’t try to collect cash anymore and instead put a lien on the home while continuing to provide service.

But if the billing department receives multiple threats from her, then they may just cut the service.


I really hope our freedom's aren't relinquished on a platform as fortified as "It is what it is".


This doesn’t make sense?

How does “freedom” relate to an electrical utility deciding whether to cut service?


"Freemdom" is accepting that mostly marginalized people get their power cut because they are marginalized. Your reaction to that is to shrug and move on instead of investigating the systems below that keep the marginalized as so.

Even if we take marginalization out of it, this is the same kind of system that let's Healthcare recklessly utilize AI Systems to automatically reject patients' care, with a Herculean effort required to find a human to talk to. Its easy yo shrug until you are hallucinated into their crosshair.

But sure, that's "freedom".


Even after re-reading this comment, it still reads like gibberish. As if my example was half read, or not at all.

By definition, a billing department of a utility has to be able to “marginalize”… in order to function.

There’s literally no other way I can see for it to work.


Not entirely sure what you are trying to say, other than you don't really care as long as you are not the one who is marginalised.

Anyway it's generally a tradeoff: is it worth doing it? By adding very strict age verification systems and marginalising people, do we make society globally better or not? Will those age verification systems work to prevent underage people from accessing the stuff we don't want them to access in the first place? Not clear. If they do, will it result in underage people being better? Not clear. And if it does, will it have been worth the damage on the people it marginalised? Not clear.


Since my old reply was flagged, this now seems like coordinated trolling.

I really doubt you are genuinely incapable of understanding what “regulated electricity utilities” or “expected to provide service” means.


A whole this voting / flagging system here is basically lottery.

I can't write more than 5 posts per day and I can have negative karma because people doing more downvoting than upvoting.

So there is no point to wonder, if it's coordinated trolling or not.


I didn't downvote you, not sure what you are talking about.


Is this AI written?

I didn’t accuse you of downvoting. It’s literally not possible for HN users to downvote the comment they reply to.

Anyone with seemingly over 10k karma would know that.


I genuinely didn't know :-). I don't generally downvote comments I reply to. I don't downvote when I disagree, I downvote when I believe the comment is very low quality, in which case I don't engage at all.


It won't.

Do you aware how many people are locked out from access of the bank because the bank think they are too risky by some algorithm and no human review?

And people got rejected for flying because they have same name as somebody on no fly list?


yep, just like cases now where people are locked out of their accounts for no reason with no recourse. totally solved!


In the aggregate sure. But do you really think profit motive means they will be precise for every individual?


Because it's all about bringing in digital ID and gated internet. Not age.


They would prefer to know, not estimate, which is why they are pushing these initiatives basically on their own accord.

Also, if you've ever played with this kind of data, there is immense overlap between how some adults and some kids use the internet. Is this user legally a child, or just emotionally a child? Similar to the problem of "There is overlap between the smartest bears and dumbest tourists" in designing bear proof garbage cans.


They do already like YouTube and ChatGPT, so they'll ask for your age only when they're unsure.


And that should be highly illegal to demand that a user submits to age verification.


Why? Sounds like it'd be the exact opposite, if they're showing age gated stuff of course they'd ask for your age.


chatgpt began to spam me pretty hard for last a few months.

chatgpt basically never sent email and it's regular now - like 2 4 emails per month

so, it doesn't look great for chatgpt


If you want to use a service that is age restricted either by law or the company providing it how else would you do it? It's the same IRL. I don't like it as well and we certainly lived through the wild wild west times in the 90s and 00s but the more something gets economical important the more scrutiny it gets. Maybe we just need something new.


Well these kind of laws are trying to legislate technology into existence; we don’t have a means to do it, yet “we demand for the technology to exist through ‘reasonable methods’, now get to work.”

If that’s the nearly infinite wiggle room we’re playing with then I’d say what about Adult and Child versions of phones? You have to flash your ID to the clerk to buy an adult one, like buying cigarettes at a gas station, and then you get to do what the internet offers. Child phones - let parents and governments come up with whatever they want to block. The phone autoupdates in the background with the blocklist, the device can’t do those things. There ya go. Each person and family gets to make their own choices and nobody has to give an ID card to PornHub or a company that literally exists to harvest your information. Win-win?


We already have a version of the child phone: it's parental supervision.

When I was a kid there was no TV in my bedroom nor a computer. Everything I watched or did online was on full display in the family room. What changed in the modern home where that's not the case? Are kids glued to their phones because their parents are too?


I completely agree. In fact the tools already exist to make a “child” phone. I was just giving up some inconsequential ground since many people are apparently stuck on the government padding the earth to protect their fuck-trophy. “OK - government mandated OPTIONAL DNS filtering on all routers. Super easy interface, auto-subscribe to government compiled list.” Scratches their itch and doesn’t affect me since I just won’t enable it, nor will I buy the “child phone”, and I don’t have to send a rectal scan to Facebook either. Yay all around.


This is scary though too. If the gov managed a key server like this, almost all companies would start requiring it. But this effectively gives the gov a very easy way to lock you out of everything.


This is really nothing new and has always be the case It's not possible to tech yourself out of a political problem.

So if there is something being done we should choose a solution that has at least some accountability to the general public (through elected representatives).

The alternative is Google, Apple etc where almost anyone has exactly zero influence and the government can still block as they like.


If all alternatives are bad you should do none of them, not squabble about which one is slightly less bad.


Not doing anything is also an alternative, theoretically it can be worse than other alternatives too...


This will be possible if done by third parties anyway, it will just be apple, google and maybe meta, a single phone call is enough to cut you off. At least if the government is doing it, the app doesn't get your id.


Either the app will get the id, you will be prevented from running arbitrary software on your device, or the whole thing will not work because it becomes trivial to sell your age verification tokens.


Like the government doesn’t already have that power?


As opposed to if google, Microsoft and apple operate the key server and a government can influence them?


I'm already locked out by many of the private companies so...


EU already does this with the eIDAS system and it works quite well.


You're seriously proposing letting governments decide which of their citizens are allowed unrestricted access to the internet?

Of all the 3rd parties who could be responsible for this, I trust the government the least.

But really the best solution here is no third party. The device owner (e.g. parents) should be responsible for setting the user's age when setting up the device. Anything that tries to take that responsibility away from parents and give it to a third party is necessarily going to be highly authoritarian; putting that third party in the role of parent for everyone, adults included.


Out of all the 3rd parties, I think the government is the one that we can more cleanly hold accountable. Not only through voting but also requiring transparency. Is it the perfect system? Hell no, but the incentives for a traditional LLC not aligned with what this kind of service should offer


>>Of all the 3rd parties who could be responsible for this, I trust the government the least.

Really? can you name any 3rd party you'd trust with this more than your own government?

Given that you know, the government already has all of this info on us. This isn't a choice between "the government doesn't know how old I am" and "the government has all the info on me". Governments usually already do. They have enough data already to issue such proof just by the virtue of us living in the country. Tax records, birth records, driving licences, council taxes, passport info, medical information - there's more than enough to give me a cryptographic certificate that says "yes, gambiting is definitely 18 years old" without me having to do anything. Compared to literally any third party that cannot do any of this, unless they buy my marketing cookies on the open market or something, or yes - I actually go out of my way to give them my passport/credit card/selfies etc.


It’s not really about the info but restricting access to people. Imagine they restrict access to social medial to people with different political opinions as the ruling party in the government


The whole idea is that the government gives you a cryptographic token that proves you are over 18, but that token can be used anywhere. They don't get to say what websites can look at it, because...how would they.


The concern isn't that an authoritarian government locks you out of some age-restricted sites, it's that it locks you out of them all.


Well, sure. But that doesn't answer my original question - which 3rd party provider do you trust more with your own data more than the government[which in most cases already has this data]


Data ownership is just one area of concern. Controlling our access to the internet is another.

If age verification was an open standard, we could hope for competition so that we could jump ship from a bad actor. If one blocks our access, we would have alternatives. In theory.

Not so with a centralized government-mandated service.


Who is in charge of certifying implementers? What happens when I provide an implementation and don't verify anything at all?


I'm not saying age verification is a good idea, just that a centralized government-mandated implementation is a bad way to do an already bad idea.


The government can just arrest you and lock you out of all sites. It's not like they cannot do it today.


You can disable Internet access for millions instantly. You can't arrest millions.


Again, this can be done already? Look at any authoritarian country killing internet access the moment anything happens.


This could be more targeted, like a no-fly list for the internet. Political dissidents, journalists, etc. could be effectively exiled from online activity.


If it has to happen, this is exactly how it should. Please feel for those of us in the UK who are currently denied access to some pretty significant services unless we send our passport to a random third party.


> some pretty significant services

What services are those other than p*rn?


This is how it's planned in the EU is it not?


Maybe? I'm not sure since the UK is no longer part of the EU; we're running quite a bit behind on this kind of thing now.



That makes the most sense.

And, that public key of yours must be used only on given platforms. You want to participate on Facebook or Reddit, then you use that public key to prove who you are. Which platforms require verification is another issue.

But it should still be legal and allowed to access conventional forums, Usenet , tor accessible discord servers without having to prove who you are.

Otherwise , the right to organize is over and we effectively live in an authoritarian regime .


I’m from The Government, and I’m here to help.

One not entirely inaccurate definition of government is a loose agglomeration of third parties.

Or, less flatteringly, a stupendously large way too loose agglomeration of way too many third parties welding way too much power way too arbitrarily.


Despite that fun trope, in reality democratic government reguarly delivers very well: Traffic safety systems work easily, dependably, economically. The Internet was developed by the government, the web at a government-funded research institution. NASA is the most cutting edge, most adventurous organization in the history of humanity. The US military created GPS for example, and has more globalized operations than any other organization has ever imagined, and from the bottom of the sea to GEO. Diseases are managed and contained, etc.

(Now if the people want to tear apart government, democracy delivers that too.)


Good points. Governments haven't been all bad.

Although more recently, at least in Australia, it would be difficult to claim the federal government, and the Victorian state government, have done anything good.

By any metric one might care to measure they've made everything worse.


The difference here is that in a functioning democracy people have some control over their government. All the institutions are specifically built to be transparent and work for the public good, at least, in some sense of the word. A corporation, especially a monopoly doesn't care what you think, you have no control over it and the only thing that really matters to them is their bottom line. Are governments perfect? Of course not. Are random corpos better? Again, of course not.


I don't want anyone to solving this.

This is problem generated by govt, and they just want to solve it with "children safety" as excuse. This is parents problem, not my problem.


Why not just let the parents set an age on the device via parental controls? Why do we need a whole cryptographic system and the government in between, for something that is really just a way to say « this device doesn’t want to have adult content »? It’s way simpler to have that at the device level, and would enable even adults who don’t want adult content to block it for themselves

Edit: I just realized that’s exactly what Android is announcing in the article, so that’s pretty neat


I want the market solving this but I don’t want to give any information to anyone who asks. I want Apple to verify me once, and then others to trust Apple that the device accessing their service is owned by someone over 18.

I’ll bet that most people are in the same boat - they trust their device manufacturer with information like their credit card number, but not anyone else.

And I think it’s a pragmatic compromise.


How does this work if you use Linux or Graphene OS?


It's not supposed to. Just one more way to limit our freedom to control our own devices.


And the market won't solve it in a way without perverse incentive unless you have government regulations. Too much money on the line at this point.


I’d personally prefer if nobody verified me ever, and people stopped asking for it altogether. It’s not a compromise, because nothing about this is pragmatic, necessary, or for any benefit of society—this is yet more creeping authoritarian control, and I’m absolutely floored how readily everyone else bends over for it. I say no. Fuck no. I will sabotage and obfuscate every aspect of this at every opportunity.

The people clutching pearls and screaming “what about the children” can deliver universal healthcare, child care, parental leave, and free education FIRST, and then I will extend a modicum of trust for their overriding “concerns”. Until then, I’m gonna treat this as the bad faith power grab that it very clearly is.


It is a scary thought but I kind of like this idea. Having a yubi key that is issued by the government that is unique to you and has your age saved on it, it's by far the most private and secure way to verify your age.


No. It should be none of that. It should be a checkbox either set by the phone store when you buy the phone or set during the first boot process.


In this case will it be a transparent traceability and the mapping to user real identity close to 100%?


>It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.

Then who should? Government, where each implementation strips away rights to privacy - which in some countries, including mine, are a constitutional right? Where it expands powers of government to track everyone's activity online - and remember we're one election away from total policy shift(just like with latest US elections)?

Free market? The profitable solution is, depending on environment - either ignore the problem(profit from ads served to children, no extra work necessary), or strip away all privacy (to filter out bots and get paid more per ad).

The sad reality is that "parent should take responsibility" is least bad option available, and takes into the account individual development of a child.

Even creation of a highly regulated child only internet creates more problems - as now that becomes a highly profitable target for bad actors(both individual abusers, and companies trying to serve ads)


Let's also not forget that many of the problems this supposedly solves are not even specific to children. The attention economy is bad for everyone.


In principle, it is possible to make a privacy-preserving age check.

Site/app asks "≥18?", device generates a UUID specifically for that [app/domain + device], the device passes that UUID to government database along with the "≥18?" question and the ID card info but not the app/domain, government database gives the answer and signs just the UUID and the answer and doesn't include any ID card info.

Government doesn't know what you're looking at, website doesn't know your ID.

(There's probably also better ways to do all this, I'm not a cryptographer and I expect that will be obvious from this comment to people who are).


In reality, the ones making such check will want extra capabilities 'just in case' as we observe now, or just go for simpler solution because it's cheaper.

How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.

It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.

Even in countries in which this requires a subpoena, agencies break the law frequently and don't get punished.

Legal systems aren't computer systems. This isn't a technical problem but a social/political one.


> How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.

True, but as this problem exists without any ID at all*, I don't see how the addition of the ID cards makes any difference?

> It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.

This is why I specified a "UUID specifically for that [app/domain + device]". Can't aggregate when each app/domain gets a different signed UUID.

> Legal systems aren't computer systems. This isn't a technical problem but a social/political one.

While true, the reverse also applies: computer systems are not legal systems.

I think many lawmakers' ignorance of this is to the detriment of everyone.

In this case, the social/political problem is: we want to stop kids accessing age-inappropriate material.

The options-space for doing this appears to be:

(0) give up

(1) require parents to limit their kids' behaviour (to which I say: "Have you met a kid? Do you remember being one?")

(2) require websites to age-rank appropriately (to which I say in a sarcastic tone of voice: "Gee, that worked soooooo well for GDPR")

(3) require operating systems to intermediate. Will this suck? Yes. Will it be buggy? Also yes. Will there be false positives and false negatives? Yes to both. Will it be a constant fight as kids keep finding loopholes? Indeed.

But you know what else? All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out. A school full of kids can beat their parents at the security game because they have more time to spend on finding exploits than the parents have to spend keeping up, the reverse is true of the difference between kids and Google LLC etc.

It doesn't need to be perfect, the kids aren't a computer program.

What does need to be held to a high standard is making sure the OSes don't leak all over the place.

* to be specific, the Investigatory Powers Act 2016 is one of two reasons I left the UK, just look at how over-broad the "Internet connection records without a warrant" list is https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016#...


> All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out

What would be the incentive for meta to deploy that against their own self interests?

> Will it be a constant fight as kids keep finding loopholes? Indeed.

Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…


> What would be the incentive for meta to deploy that against their own self interests?

The normal method is passing laws. That's kinda the point of laws.

Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.

> Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…

Hardly. This is more like gardening. It matters much less if kids get a few days of messing around where they're not ment to be, than if it's continuous.

And ultimately, if you want to run a business without spending money on legally required actions, you're in the wrong business, nobody should shed tears for you.


> Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.

In an ideal world. Personal experience has shown that isn't the case with him.


>The options-space for doing this appears to be:

(0) give up

...

(n) waste resources

yeah, i think current state is good enough, might as well slap regulation and ban any form of targetted ads.


I'd be on board with banning micro-targeted ads, and more broadly any use of psychology to induce similar states as regulated exogenous drugs equivalent to the simple language descriptions of US Schedule I, II, and III.

However, the issues are rather broader than showing ads to kids who have no money to spend on whatever is being advertised.


This can’t work because it creates a market for people that have an ID that cleared gates to lease/borrow to those that can’t.


It cannot work *perfectly*, but unlike most crypto stuff, it doesn't have to (at least, that part doesn't need to). It's a social/political problem, not a technical one.

The goal doesn't even need to be to make a completely perfect, impossible to circumvent, barrier for all minors; all this needs to do is just make it equally difficult for a minor to get adult (for whatever definition thereof) content online as it is to get tobacco or alcohol or gambling in real life, the hard part being to do so without compromising privacy, privacy being the bit which has to be done perfectly.


> (for whatever definition thereof)

See, that's why this can't be solved technically.

Pornhub has a decent amount of sexual health material on it so there's an argument to be made for allowing teens access to at least parts of it.

> privacy being the bit which has to be done perfectly.

> It cannot work perfectly

So we agree that this is going to end poorly?


> See, that's why this can't be solved technically.

Which "this"? There's multiple things here. I'm suggesting one specific "this" (anonymous age verification) in response to another "this" (the internet is not suitable for all ages).

> Pornhub has a decent amount of sexual health material on it so there's an argument to be made for allowing teens access to at least parts of it.

There's more content on the internet than any human can consume in a lifetime, so the presence of age-appropriate stuff as a subset of some website is no more relevant than how the intro to a porn film ("there's something wrong with my fridge, it's sooooo hot", though I am thinking of a beer commercial parodying this) is not itself 18 or R18 or whatever your local certification is called.

> So we agree that this is going to end poorly?

On the contrary, literally all the rest of my comment after that quote is cut explain why we *do not agree* about this.


And the verification systems rushing at us are immune to this?


> Government doesn't know what you're looking at, website doesn't know your ID.

But then the government knows your location at any point of time and how often you use websites requiring the age check. Also, if your device is configured to do it automatically, a child can also follow this verification.


Google and Verizon sell that data to the government right now. The US's official position is that buying info they aren't legally allowed to collect is perfectly fine, as if you were given a privacy right in the constitution only to enable an info broker economy, and not because of the obvious and understood harms of the government having whatever info about you they want.

If you want the US government to not know something about you, unfortunately there's a lot of changes that need to happen, including entirely new political parties and making changes to the Supreme Court, and popular support for taking the privacy rights you already have much more seriously.


> But then the government knows your location at any point of time and how often you use websites requiring the age check.

Not as described. There's no location info in that path, and the signed statement of that UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.

(Should I consider expiry? It's not like people age backwards?)

> Also, if your device is configured to do it automatically, a child can also follow this verification.

Yes, if that device has been associated with a government ID and also the government ID signing process fails to make use the things we've already got on-device like how my phone reads my fingerprint to know I'm me and can store copies of some forms of government ID (in some places but not where I live, Apple Wallet apparently only supports some US states, Japan, Greece, and UAE).


> Not as described. There's no location info in that path

Ip address and general time of day will tell you a lot about location. Not street level, but country or state level.

> UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.

So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?


> So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?

How? Phones are already locked down pretty hard. Anything like this would need to be in something secured at the OS level just to stop signatures getting leaked between apps.

If you're thinking "kid roots device, replaces OS entirely", that's not the problem of the manufacturer of the OS that just got deleted.


> How? Phones are already locked down pretty hard

But never well enough, it seems.

If you can't revoke the token then I'll just sell mine to whomever needs it.

Kids will beg/borrow/steal their parents / older siblings ... etc.

The "harden the device, bake in controls that are difficult to circumvent and managed by not-the-primary-device-user" approach is _very_ similar to DRM. All that does is punish the innocent.

I have never once had VLC tell me that the mkv file I just opened can't be played because I'm not in the right region or because my screen is too old to support encryption. I have had family learn the hard way that DRM is not in their best interest, though. Now they just ask me for the movie on a pen drive when I visit next :).


> But never well enough, it seems.

"Never well enough" for stopping teens (and pre-teens) installing access tokens?

Has any adolescent in history ever managed to so much as spoof someone else's session cookie *on their phone*? And if so, when? If this is a flaw which comes up once every five iOS versions or whatever, who cares?

> Kids will beg/borrow/steal their parents / older siblings ... etc.

They occasionally get alcohol, too, despite restrictions. The point is to *mostly* stop them.

And it's not like the payment systems have not already solved the same problem.

> All that does is punish the innocent.

Which is literally something I'm trying to solve with my suggestion up-thread: here's a way to do age attestation that doesn't need to punish anyone.


> Phones are already locked down pretty hard.

Which is not how it should be done at all. Outsourcing your security to a big brother leads to all kinds of problems like planned obsolescence and spying.


> Outsourcing your security to a big brother leads to all kinds of problems like planned obsolescence and spying.

But, won't somebody think of the children!

_sigh_.


This is thinking of the adults though.


We have cars, and kids are not allowed to drive them. Yet we do not have mechanisms in place to ensure kids aren't driving cars because the responsibility falls on the parents, and it works. By and large, parents understand the threats and navigate this requirement perfectly fine; outliers are few enough that we can deal with them on an individual basis.

The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small. Personally, my vote is that they just don't think it's that big of a problem.

To me, the ideal solution would be more granular and better parental control configurations, especially on the web. Pair that with preconfigured devices that have "unremovable" parental controls, branded as "kids/youth phones." If parents care about this, they'll buy those phones for their kids and the problem is solved. If they don't, then this isn't something parents want, and we shouldn't really pursue it further.


Parents haven't asked for help keeping their children from driving their car though.


> The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small.

Sometimes parents know their children, and what's best for them, better than faceless politicians (who we've seen are often attracted to said children for some reason).

Growing up in my household there was a time when I was allowed to read and watch whatever I found interesting. My younger brother was not. That was because my parents knew us and judged that at my level of maturity I was unlikely to be negatively impacted, whereas my brother would get nightmares or copy-cat things he saw that he definitely shouldn't.

That's how it should be. Yes, there are bad parents who will decide poorly. That's the cost of freedom.


I sympathetic to this perspective, as a parent, but also, there are just a lot of kids out there with bad parents.

My personal philosophy is that parents have a duty to raise their children but that duty is on behalf of the society into which the children will eventually enter. Consequently, a just society may sometimes impose itself on parental freedoms (in the case of neglect, for example) because, in the end, the child's ultimate guardian and responsibility is the society itself, not the parents. The internet is full of material exposure to which, for children, could reasonably be construed as neglect or abuse, and it is insufficient to leave the entirety of the responsibility to the parents, in that case.

I don't know why Americans are so obsessed with freedom as if were the only social good that a society can pursue. There are many things which make life worth living, that contribute to flourishing, and freedom is high on that list, but its not the only thing.

All that said, I don't approve of age checks of the sort being proposed everywhere now. We can do a lot better at mitigating these problems without damaging privacy so much.


I think that the individual does not raise children on behalf of society, I think that society raises children on behalf of the individual. I also think that when society fails to keep up it's end of the deal, the individual should have the right to walk away from it.

Your stance is also reasonable, and I understand it. I just happen to disagree with it at a pretty fundamental level.

> I don't know why Americans are so obsessed with freedom as if were the only social good that a society can pursue.

It's an interesting question isn't it? The balance between what is best for the individual, and what is best for society and who gets to decide exactly where the balance should be is probably one of the most fundamental problems that face humans.

Personally, I'm so far left that I've almost gone right. I think that others should be able to raise their children however they'd like unless it rises to the level of genuine violent abuse. Just making different moral, political, or lifestyle choices alone should never cost someone their right to parent.


The EU actually has a very good, privacy protecting way of doing this based on zero knowledge proofs.

Unfortunately they completely botched it by having the proof-of-concept app rely on Apple & Googles integrity APIs - which a bunch of countries copied.


ZKPs may as well just be unencrypted HTTP headers which would be way simpler and easier to implement. All a ZKP proves is that at least one person in the world is over 18.


This is not completely true.

With ZKP, if you make a business out of reselling tokens you get with your own identity, eventually they will see that you use orders of magnitude more tokens than normal people.

So with ZKP it's more difficult to cheat. Not impossible, just less accessible.


They're not ZK if they can do that


Each individual proof is zero knowledge, but downloading a _bunch_ of them is an indicator, yes. There's no real way to work around this with the current ZKP scheme. I'd argue ZKP is, in theory, the least worse option of all current age verification scheme.

My personal opinion is that age verification itself is a bad idea, but if we're going to go ahead with it, I'd much rather we use ZKP for it than the current mess of "upload your passport and picture of yourself to dodgy 3rd parties that likely now have your browsing traffic associated with your real name"...


So the government would impose a maximum limit on the number of porn sites you can visit each day?


Not necessarily, but it would be difficult to justify why you need to access 1000 porn sites every day, I guess?

The point is that if you build a service that sells age verification tokens, you are doing something illegal. And if you start doing something illegal by gathering said tokens with your own identity, maybe it's not the most clever way to do something illegal?


So the government would limit me to accessing only 999 porn sites a day?

Is it going to be like structuring law, where it's illegal to access 1000 or more but it's also illegal to avoid accessing 1000 or more by accessing a lower number?


The government won't limit you - they can't really know what you use those proofs for anyways, that's the zero knowledge part, and supposedly they'll be necessary for social media at some point, so a ZK proof won't necessarily mean porn use. The only thing the govt knows is how many proofs are being downloaded. And you can bet politicians wouldn't do anything to prevent voting-age you from accessing social media - how else are they supposed to get you to vote for them (or hate their opponents).

Now, a scenario I can see happening is, the ZKP-issuing agency may find a single client downloading several orders of magnitude more proofs than the average citizen, find that suspicious, refer them to the police, who'd get a warrant to investigate said person. Then, the police may manage to connect said person with a proof distribution service. Something along those lines.

Again, I'm personally not a huge fan of the whole age gating, but if we're going to go about it, this is the least worse option. Which is really saying something.


How many proofs will be illegal to download? Will downloading and discarding proofs in an infinite loop be a crime?


Of course they are. The whole point of ZKP is that whoever gives you the token cannot link it to your identity. So you can get a token with your own identity and sell it to someone else, and nobody will know...

... unless you get thousands of tokens every day and sell them on a website, where suddenly you start leaking information about yourself everywhere. ZKP still did its job: it's not the tokens that link to your identity, it's your behaviour.


The EU app is still shitty and unfixable, because it requires that you send personal information to a third party. The only acceptable and privacy respecting option is self declaration, which doesn't need any ZKP or any other bullshit.


I have a feeling that, in order to protect privacy, those regulations must fall on the parents too. It is their primary responsibility to take care of their children. Maintaining your kids digital hygiene should be important to the lawmakers and the child protections services.


What should they do about it?


Who? The lawmakers? I believe banning children up to a certain age from having Internet-enabled mobile devices is a good starting point, and both child protection services and law enforcement services should fully cooperate with parents in enforcing that ban. If you see a kid smoking a cigarette or taking drugs, you know parents have failed somewhere along the road and it would be preferable if the government could step in to help.


This is a reasonable perspective, but don't you think the internet has the potential to do good as well as evil? I remember seeing some interactive lever applet as a kid where you could move the fulcrum. (Slightly) educational stuff. Shouldn't that be allowed?


There are any number of alternatives, I favor a walled off whitelisted subset of the internet that requires age verification and then we can let kids on that and otherwise ban them from the general internet and also ban internet enabled devices in general. However, this costs and undoubtably wouldn't be perfect as there are people out there who want to chat up your kids, look at how much work a roblox style site needs to do against internet users who probably shouldn't be chatting up kids.

For those precocious kids who parents decide should be the exception because they are "good with computers" well I'm thinking some sort of waiver would be required that held the parents responsible then maybe let the kid hack on the internet but this is an unpopular view, the unpopular part being the "parents being responsible for their kids" bit.

But in general I think its a tough time to be legislating this stuff because "reasonable perspectives" are not what we are voting into office right now lol


Educational content was already a thing well before the internet got everywhere.

When I was in primary school, one of the things teachers had us do was debate the pros- and cons- of television. The pro side included educational content.

First Windows PC at any of my schools had Encarta.

Wikipedia can be downloaded in entirety and read offline, though it is so broad it may need a degree of filtering to become age-appropriate even for 16 year olds.


I have a feeling that, currently, the cons outweigh the pros. Maybe if the digital landscape changes in the future, then we can reconsider those limitations. So far, the mobile Internet - the apps mainly - is a hostile environment for a young human, and I'd say they are pretty dangerous to the adults too.


In many schools in the US now, kids are issued mandatory iPads from age 5 and are required to use them to complete school assignments.


Which sounds like a government mandated child harm measure to me.


Most of the US education system is.


That is extremely upsetting.


Wait until you hear about the pepper-spraying drones being put into service in schools.

https://news.ycombinator.com/item?id=49091153


This is reasonable up to the point of lawmakers suddenly deeming rainbow flags just as bad as drugs (Russia as an example). Your example may work in well intended countries but completely ignores that a country can VERY easily shift into a regime that does not have good ethics abusing these kinda laws.


Not having an internet censorship law never stopped a country from making rainbow flags illegal.


There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.

There should however be no force age verification. Social media companies already know how old you are or very close to it using the data they collect everyday. Using this data they should be required to use "best effort" to determine which algorithm you fall in. Nothing is 100% and we should stop pretending it is, sure some kids will find a way around but they would also if there is a age verification system.


> There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.

Frankly, in that case I want the kids algorithm. It is preferable for me as an adult, I do not want the intentionally harmful one either.


This. Just give me the option to have pagination. Sweet, old, pagination. Like here on Hacker News. I can then review one or maybe 2 pages, and that is all. Like a physical magazine where there's a clear end.

I have the firm belief that infinite scrolling is one of the darkest pattern that was ever invented.


Hang on... Hacker News very clearly has a complex, opaque [1] algorithm that orders stuff. Maybe it's not user-specific, and maybe that's a good dividing line, but these are the kinds of factors we're going to have to think about if we want to introduce regulation around 'algorithms'.

Infinite scrolling is a very different issue (although it's definitely a contributor to the harm, I agree).

([1] Unless I'm being unfair here; maybe the algorithm is available somewhere, I just don't see it obviously linked anywhere)


Yeah, seriously, New York just passed law that makes it illegal to show engagement-driven feeds to kids.

I can’t wait to not age verify on instagram and permanently get back a feed that’s only people I follow.


You know you can also just not use Instagram...


I used to quite like instagram when it was a good way to keep up with a well curated group of friends who would share occasional interesting photos (though even then it could end up being performative).

But you’re right, these days I’ve largely stopped using after i realized every time I opened it, I was looking at a stream of drivel designed to keep me scrolling.


It just seems dumb to me. These companies don't have any power, if people simply exercised their free will and stopped using the platforms they would die off.


You can often do that via settings. But we could do with a law that makes it a crime to override a user setting that has been explicitly set, without notifying the user.


Oh but you enabled the setting "don't use infinite scroll" and we've deprecated infinite scroll so that isn't a setting anymore. While improving service for our customers we have introduced "unrolling pages" which prefetches the next page and attaches it to the end of the previous page to provide a smooth reading experience, and of course we've given that its own setting which you haven't set, and it defaults to enabled to provide the best seamless reading experience for most people.

Next we're thinking about spatial pages, an innovation which considers the app as a viewport flying over the pages laid out in a line. In consideration we have database-views which presents the unpaged tables of content in the database directly to the end user, completely bypassing outdated 'page' skeuomorphisms from the olden days of printers and books. Further out, our researchers are working on Shepherd Tone-inspired viewing, where technically legally it is paged, but it looks and feels like it isn't!


Children here are a distraction. Any harm these companies are causing to children is also being inflicted on adults. The correct solution is to end the harmful behavior for all, not set up required identity verification.


> It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.

That's like saying "take a look at owners of fast sport cars, it's obvious this is not working and they have too many accidents." If you want to patronize other parents and think the government should be more responsible and parents less responsible, please state that honestly. Don't make up alleged "facts" to make a point.

Otherwise, I'll just say "it's obvious you're wrong, just observe the world around you and you know age verification is a non starter."


> Companies have show that they are incapable or unwilling to address the problems they cause

> This is where regulation is supposed to come in.

This is such a misdirected effort... Why the heck are we focusing on addressing those problems for a small subset of population (kids) while creating even bigger problems for the rest? Lets regulate those companies into actually addressing the problems they cause for everyone!


> companies have shown that they will abuse any personal information that is shared with them

This is the rot at the center of tech IMO. We have all these wondrous toys but we can't do something as simple as verify age without abuse. What's the point of all this tech if we can't trust any of it?


> This is where regulation is supposed to come in.

And who do you think pushes/pais for regulations ? The same companies which are "regulated".


> It’s also pretty obvious that saying “parent should take responsibility” is also not working.

So punish those people.

Stop letting them neglect the responsibility a parent innately has to their child

and to the rest of us.


Stop punishing me by asking for ID when I buy alcohol!


If you are an elderly person, this position becomes wildly reasonable.

No youths are spoofing being 75 at the corner store.


That's a false equivalence and you know it.



> This is where regulation is supposed to come in.

Yes, agreed. However regulation does not necessarily have to mean age checks.

The most obvious low hanging fruit to start off with is open and interoperable content filtering infrastructure (ie parental controls) so that there's some common standard that literally everything supports out of the box. It needs to all work together - the current situation tends to be spotty and unreliable thus parents tend not to bother trying to use it.

Start with an extensible metadata format that enables websites to self-classify pages. Account for things like loading alternative resources on the same page. Mandate that all websites and app stores include such metadata and that all browsers and operating systems have some baseline functionality for making use of such data in a sensible manner.

Only after that has completely and utterly failed should we even begin to consider highly invasive measures such as mandating government ID checks.


There's nothing to be confused about, this isn't about age verification. It's about increasing surveillance and ending anonymity.

The "think of the children" shit is just a tactic to make emotional, non-critical-thinking people into die-hard soldiers for the cause that get angry when you argue against it.

"Oh you're against protecting children? What are you, some kind of pedophile?"


Parents should take responsibility and not let their children smoke, and we still banned selling cigarets to children. Just because something should be some way, doesn't mean as a society we shouldn't do anything about it.

In any case, the story with parents and addictive devices is even harder for parents than e.g. cigarets. For example, a LOT of schools in the UK think that it's good to give childrens ipads to study, and there's nothing that parents can do to prevent this. In this specific situation saying that "parents should take responsibility" is unfair to parents, because their only option to avoid this is home schooling.


That's a false equivalence. The only thing we should be doing is tackling addictive algorithms for everyone, and providing purely optional parental controls that are disabled by default.


> The only thing we should be doing is tackling addictive algorithms for everyone

Oh so you agree with me, that it should be banned, like cigarettes. Thank you.

Why'd you call it "false equivalence" then? Why not call it "a really good equivalence"?


100%, it's not like adults are immune to misinformation, social media addiction or scams. Those platforms should be safe for all people regardless of their age, nationality, sexual orientation, gender or religion.


The parenting argument is a complete cop-out. There's no universe where you can be shoulder hovering 24/7. This could've been solved years ago with robust parental controls. But companies like Google just didn't want to because they wanted to shove ads in kids' faces.


I think we can approach this from more than one angle. Yes, it cannot be entirely on parents, but parents should bear some responsibility to not just hand a device over to their children with unrestricted access to the entire internet.


Up until relatively recently you would have to install custom VPNs and maybe add Pihole into the mix to achieve anything close to that. Easy for us here, but we're in a small minority.


Parental controls have been part of mobile devices for years, but so have bypasses. For instance, you can bypass Google's parental control settings by opening the help page in the Google settings and clicking links until you get to the Google homepage.

I doubt it matters because nobody seems to configure the parental controls that are there, anyway. Only schools seem to try, and only because they're legally held responsible for what kids do on their computers.


Parental controls are complicated and obscure, IME. Setting up a child to play Minecraft through Microsoft was like setting up a web server with firewalls and reverse proxy... only less sensible. I'd appreciate that is so they can get parents to set accounts as 'adult' so Microsoft can exploit them.

You can set up, for example a child friendly DNS (Family version of OpenDNS) then Firefox come along and bypass it (DoH).

Probably, we need an OS level setting, per account, browsers would need to expose it to websites, apps installed would have to check and provide content according to local legislation/rules. Bypasses would have to be performed by an "adult" account.

The main issue is that adults would be able to set themselves as children and avoid negative commercial activity. That's a problem because it means FANG, etc, will lobby against it and then ensure their implementations are convoluted and broken.


Parenting doesn't have to mean become a helicopter either. In fact, that's the worst kind of parenting because it doesn't prepare the kid for a future without a parent around.


Good parenting is not shoulder hovering... It's teaching and instilling values and lessons that get the child to make the right choices in regard to what they do with technology. Like how we teach kids not to talk to strangers.

Parents should be teaching kids from a early age how to use technology responsibly.


I think you've done a great job identifying the three main options and why two of them (parents, censorship-by-default) just will not work. That leaves regulation; the only way we will prevent children—or anyone—from coming to harm is to stop companies from producing this harmful content in the first place.

Either that, or just accept the harm.


Who decides what is harm? An unelected bureaucrat? Now you’re going into censorship area


No, I'd prefer elected representatives to do that, in the same way they've decided on all the other existing harms we legislate for.


And what happens when those representatives decide things like rainbow flags being a crime or so much as mentioning the existence of trans people in front of a kid is equivalent to a sex crime. The US has states pushing legislation to make abortion a crime punishable by the death penalty while also using flock cameras to track people traveling across the country to places it's complete legal to do so. But yeah let's give those people a way to tie every website that woman may view while searching for a safe option now directly linked to her I.D. or that adult searching for gender affirming care is now outed because their ID is linked to the site. So when states like Kansas legislate all trans people's drivers licenses be revoked they can just say okay who in the state has looked at transgender healthcare related websites and have a list of people to go after.




Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: