Online ID / age verification: the death of online search
decoded.legal
decoded.legal
I'm under no illusions, btw. I know they'll access it. I know I did as a teen (albeit magazines rather than the web) but I think a dialogue is sorely missing about damage, the impact on women, body image, etc etc. The more this is pushed into a black/white old enough / not old enough over-simplified scenario, the less we can have nuanced conversations about it all.
I suspect this whole move is purely an optics piece. That doesn't make it any less dangerous, in fact it maybe makes it more dangerous, but it explains the incompetence and lack of thought behind it.
Today we have criminals, government, criminals in government, and numerous corporations desperate to build surveillance profiles on us at every opportunity. These are passed to third-party aftermarkets to the highest bidder. Once obtained, no one is concerned about securing that data.
So instead of attempting to shut the dangerous things away you teach them how to recognize them, why they want to avoid them, why sometimes other kids or even adults fall for it and how they deal with it. Our parents took that approach with us in regards to smoking, drugs and alcohol and it worked out quite well. Or let's say: It worked out a thousand times better as with other kids who just got punished for even looking strange at a pack of cigarettes.
A nice side effect of this is that your kids will be more likely to talk about what stuff they encounter and how it affects them, if you don't try to push them away from the stuff they should not use (punishment), but instead try to pull them into a worldview where that stuff isnt something that interests them in the first place (beyond natural curiosity).
For example, the DMV and payroll companies are selling our private details as we speak. Resistance would result in homelessness.
We can't even get grown Adults to do that.
small data point - so the overall affect could be negligible - however,
6 years ago a youngster I was watching came home with digital literacy handouts and had teachings about internet hygene, non-trustworthy data sources, and more.
since then, more than once a year we use news stories to discuss false info, digital stalking, methods used to dox via photos, sextortion scams and more.
we've spent time talking about checking multiple sources for information, especially health or sex info - and especially for any 'viral challenges'.
So it won't be long before this next gen is adults that have been taught to look for these things, and I'm sure many have witnessed at least part of the shit show the parents have been going through yelling at their screens and each other about fake news and similar.
Not sure that the apps are making it easier to check sources, but at least the teaching of the option is a thing much more so than I think most of 'the adults' of today had a chance to learn anyhow.
If you have your childrens iPhones as part of a family setup you can also block their access that way.
However I salute you for your choice, which is the harder and better way. If more parents did as you, we would not have the issues we have today.
Porn is nice enough but watch, but because there is essentially no discussion about how to have sex (outside of school, which at best is put tab a in slot b, here is how not to become pregnant, this is what STDs are.) the only input too many teens get is porn.
1. Heavily restrict the porn/bad sites.
or
2. Let them see the bowels of the internet, and hope they will go in the opposite direction.
Reminds me about how my parents explained drugs to me. They told me a lot about different substances, why it is bad, why people get addicted them, what it does to them. E.g. my father had a friend who was a alcoholic till he died and he told us the story of how fun it all started and how everything went south for him. Similar things for other drugs, cigarettes, etc. Not for the sake of shocking us, but to rationally and emphatically explain the dangers (and fascinations) involved with the thing.
With all 4 kids this turend out to be a pretty solid strategy
Today, I know in many places people are being killed in awful ways because of their religion or lack of it, sex, what they identify as, or because they live in a unstable place.
Plus, you can tell a child the stove may be hot a million times, yet they will touch it and burn themselves. Children and younger adults often feel they know better and something wont happen to them.
Apples allows you to disable their access to install apps, browse the web (with or without restrictions) or use any other installed app. You can turn your childs iPhone into essentially an ipod with facetime (that can only contact you) if you want.
If you give them an unlucked laptop, you are right of course. So don't do that, if you want to go that route.
All Pi-hole instances use it by default. https://github.com/pi-hole/pi-hole/releases/tag/v4.4
> Note: The canary domain only applies to users who have DoH enabled as the default option. It does not apply for users who have made the choice to turn on DoH by themselves.
https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
Also the dangers of the web should be apoken about in school. Digital literacy and all that.
Google and my employer deal with massive amounts of spam emails and gets it right 99.9999999% of the time.
There’s a reason why Google captcha me on their own properties.
(It’s inexplicable why EBay captchas me AFTER I submit 2FA…)
We know who the bots are, but if you want your visitors to do some free work for my training models, so be it.
The captchas need some work though. If you want me to select all photos with carS, I’m not going to choose the photos with one car only.
I have to do it every month to pay my electricity bill and I absolutely despise it.
On the other hand, I'm looking forward to the moment when AI/ML becomes good enough that there simply won't be a way to make a captcha that would reliably tell humans and machines apart.
Possible robot.
> my electricity bill
Probable robot.
> looking forward to the moment when... there simply won't be a way to make a captcha that would reliably tell humans and machines apart
Definite robot.
Google does this too and it drives me nuts. What's makes it even more of a "fuck you" is they will do it to paying users, (business accounts)... if you refresh the page three times the captcha goes away, they are just trying their luck at using people for free ML training labour.
If you're trying to get through these while spending the least amount of time on them, you want to answer "How would most people presented with this answer the following: _______ ?" as opposed to "What do you think is the most correct answer to the following ________ ?"
So I bought the thing from another vendor.
Emails are literal treasure troves of data and are easy to pull signals out of for determining spamminess. HTTP GET requests, on the other hand, aren't - and there's no way to associate them with other spam-connected properties (like you can with click-through domains in emails) besides by blocking entire IP ranges for the ASN not moderating their customer base.
Facebook, Weibo and other smaller platforms around the world prove that's not going to happen.
(Too) Many people are still going to be trash even with their actual identity out in the open.
So just leave the Internet be, for the love of everything.
The principle driver of antisocial behaviour online seems to be impunity, immunity, and/or disinhibition. Anonymity and/or pseudonymity are related, but nowhere near identical.
As Yonatan Zunger, chief architect of Google+ (and now an ex-Googler) pointed out, compulsory identification amplifies rather than removes power relationships. This is his principle (and IMO devastating) response to David Brin's Transparent Society argument. Minorities and the disempowered obliged to identify themselves lose even more power in the bargain.
What empowers abuse is the ability to inflict harm without perception of risk, whether that perception is accurate or not. Disinhibition reduces perception whilst overall risk remains high. (The concept is captured in the word "assassin", deriving from the Arabic, hashīshīn, referencing hashhish --- assassins had reduced inhibitions through pharmaceutical influence.) Legal immunity, the cover of a crowd, operating extrajurisdictionally, cover of a state or other significant actor, or simple mass delusions can all provide the reality or appearance of impunity.
Mandating identity itself creates new avenues for abuse, including the revoking of official credentials, bureaucratic incompetence, bribery, and the potential of a "permanent archive" of all accesses (already substantially present through numerous mechanisms) which can be mined at arbitrary future dates, but as-yet unknown entities with as-yet unknown motives.
I'll note that I'm one of numerous reasonably-well-know pseudonymous HN members.
Fixed that for you. There might be young readers here who haven't verified their ages.
https://web.archive.org/web/20180903205908/https://plus.goog...
At the heart of his argument:
In practice, the forced revelation of information makes individual privilege and power more important. When everyone has to play with their cards on the table, so to speak, then people who feel like they can be themselves without consequence do so freely -- these generally being people with support groups of like-minded people, and who are neither economically nor physically vulnerable. People who are more vulnerable to consequences use concealment as a method of protection: it makes it possible to speak freely about controversial subjects, or even about any subjects, without fear of harassment.
(A classic experiment which you can easily replicate is to change your profile photo to that of a young woman for a few weeks. Change nothing else, even your name, and see what happens to your interaction pattern. I've seen quite a few people run this test and the results are, shall we say, quite visible)
GamerGate is one example after another of why transparency has asymmetric effects. The worst-case consequence for members of the mobs is fairly minimal: they won't face social ostracism by their friends (who after all, support them), they are highly unlikely to be placed in any physical danger (the police will protect them), and their jobs are not likely to be affected either -- and if they are, they can find others. Conversely, the threats against women in the field were physical and real, and (as you'll see if you ever experience the real ability of local and federal law enforcement to deal with harassment and threat cases, for manifold reasons) there is reason to believe that they do not have access to adequate police protection.
(I'd mentioned the G+ link a few times in earlier HN comments. HN's Algolia search is one of the secret strengths of HN, and is a chief reason I comment here as extensively as I do: I can often find earlier mentions of some point and reference or expand, occasionally correct, those.)
(Zunger and I apparently each believe firmly in paragraph-long parenthetical digressions.)
Original submitted to the queue: https://news.ycombinator.com/item?id=27858439
But in many cases, there's no reasonable way to accomodate identity / credential / characteristic assertion into data flows (e.g., commandline tools, proxies).
I don't think anybody is arguing that it will reduce all negative activity, just some.
Seems like it's either a data breach waiting to happen or makes it much easier for the worst to dox and target people.
I think the pro-real-names position would argue that it is net negative for society for people to have this ability, we should only be saying aloud what we are willing to put our reputations behind.
I don’t agree with this position, but afaik that’s the position.
But, yeah, there are exceptions and corner cases to everything. I believe the fundamental idea is that "real" life didn't used to be like that, nor is it today. You just don't see the stuff you see online happening at the corner store. And the difference is that it's people you might see again, or can call the police on, or just recognise as fellow humans.
The problem of anonymity sometimes being required also isn't entirely new. There have long been guarantees (or attempts at such) of anonymity for situations where the need for it was generally acknowledged. In one such case, the organisation even adopted it as their name: Alcoholics Anonymous.
The people doing the harrasment do so under their own names.
people would avoid getting mental help, support groups, religion questions, sexual health, etc if they worried it would be easy to be exposed.
As far as I know, this hasn't been confirmed by anyone other than the dev themself yet. The personal information is also not in the archive, so someone (4chan staff or archive staff) did their job. We'll have to wait and see for the truth of that case, if it ever comes to light.
However I also agree with gp(?) swatting and similar is a problem.
I've experienced these things from internet things - resulted in knocks on the door, 'certified letters' - and pics of my house posted online with people on said blog asking others to drive by and honk.. I'm talking three separate incidents by two or three different people for different reasons - all from internet.
luckily for us it was more nerve racking that people were trying these things and nothing aside from the knocks became an issue - well one of them cost me a business relationship now that I think about it.
Mmm. In some cases terribly dangerous things to their health, like being gay in a country that forbids it. Or criticising a government that forbids it. Or saying something that only becomes illegal or publicly reprehensible after the fact.
The real issue here is the dedicated toxic users: sites like 4chan and Kiwifarm for example. Those groups are typically responsible for the real damage we see on the internet, and there's likely no way for us to ever flush them out. It's a cat-and-mouse game that cannot be won, only indefinitely postponed (which is a victory in their books).
from ddos attacks to the 4chan party van - these things can escalate quickly beyond control and have real world consequences. I've seen it actually happen more than once.
One could argue that they shouldn't be and that's maybe a separate conversation, but for example, right now, if someone defames me in person, I can sue them and if they defame me on the internet under anonymity, and I don't think I can (yes they can be anonymous in person but I think it's much more difficult).
Yes, it's probably a separate conversation, but I don't think we should give these bad laws more teeth.
> Facebook, Weibo and other smaller platforms around the world prove that's not going to happen.
I don't think it's worth taking the entities' arguments seriously when linking real identities also just happens to make them a lot of money. It's clearly just a smokescreen for their true monetary intentions.
This is what shocked the hell out of me as older Gen X and Boomers got into Facebook.
I remember one instance I saw where there was quite a lot of nastiness regarding a series of fights that broke out on a cruise ship off of Australia. Someone involved in it posted a video that his father then shared on Facebook. Then some dude starts posting all these vile racist comments (apparently anti-Lebanese racism is a big problem there) under it. REAL NAME. Basically calling a whole ethnic group criminals on the page of someone whose own son was quite possibly in danger.
I got... curious. I clicked on Racist Dude's profile. Sure enough everything was set to public. He had pictures of his kids. Their names too. Then I got more curious. Less than 5 minutes on Google and I knew what extracurricular activities they were involved in and when they were likely to be there. I felt a little sick at how easy it was to -- can you even call it doxxing when it all hanging out like that?? Anyway, I kept my mouth shut, logged out, tuned out, dropped out.
I still wonder what Racist Dude's best case scenario was there. Even if his vile opinions were 100% true... congratulations on insulting a large family of criminals while exposing everything about yourself?? It boggles the mind. Don't ever try to steelman the ravings of a psychopath.
real name, public profile - showed she was a 10 year firefighter in previous town.
I mean - how dumb on top of overly crass can someone be in a public forum? Mind blown that day - and it's not the only case I'm sure there are many every day on the interweb.
Even people who smoke joints are more surreptitious than racists.
As for authenticating publishers, I think HTTPS is a terrific idea. If some don't want to sign their content, fine. I'll adjust my esteem for them accordingly.
First we protect children. Then we protect specific groups. Then they redefine who should be protected of what.
In the end a few protect all the others from knowing things they shouldn't know. And knowledge is power, as always.
We all know about the evil manipulators who favor that lie but frankly those stupid enough to believe bear moral agency as well.
The only thing that would be influenced is cross national relationships, and sitting in a separate country probably affects that way more than having equal access to the same webpages.
The moralizing coming from all angles is weird, since everyone involved would probably consider themselves a problem-solver.
I got a PC that was all mine and an ADSL internet connection at 16 years old, before of that I used the family computer, but not really used the internet a lot since back in the day it was quite expensive, and when I did I was monitored by my parents. I got a smartphone that was capable of accessing the internet everywhere at 18, before of that only a phone that did phone calls and SMS. And still grow up fine and managed to get a good career in IT.
There is no reason whatsoever for a child younger than 14 to use the internet on its own, without the surveillance of his parents. And there is even no reason for him to have a smartphone. If as a parents you are concerned about giving him a phone for emergencies, just give him a 10$ feature phone that can only do phone calls and SMS. It's as simple as that.
Nowadays kids are always in front of a computer or a phone, they no longer go out to play, instead they spend their time on Tiktok or other stupid social media. We must change that, not the internet.
It can be very hard to enforce unless you are a stay-at-home helicopter parent who homeschools.
Peer pressure (not just on the child, but also the parents) and the need to fit in will result in your child demanding their own device by like eight at the latest, and mounting pressure to do so. (Apps are part of the curriculum in some places now!) And failing that they'll just buy and hide their own device by like 14. Though as you imply, if they aren't capable of self-regulating by about 14 you've probably already lost.
Everything from game consoles to the television to the fridge may be Internet-connected. Prepaid plans with data are as little as a single day's lunch allowance in some parts of the world. All their friends have electronic devices with internet access. Along with access at school. And probably some circumvented access at home... it's quite hard to actually keep kids offline.
Every media device in the house is connected to the internet. Every media device in kids' friends houses is connected to the internet. Everything at school is connected and now they need laptops with actual webcams at home.
They're immersed in it daily, and most of the use is unmonitored.
The problem is that parents aren’t trusted to do their job by some and some want the government to step in and do as much parenting as possible. That’s not how parenting works though. The government doesn’t own your children and shouldn’t get to decide how they’re raised.
The OS level filters and parental controls exist, and have for years. Though a slight logical tweak or a slightly improved system might be more helpful.
The Internet, by default, should be free and considered 'unsafe'.
Sites and services that claim to be Safe for Children should have to actively tag themselves as such. That might involve metadata. It might involve third party organizations like commercial certificate providers signing that claim; or governments, or insurance program registrations, or groups dedicated to whatever moral police panic is in vogue, etc.
Let people Opt In to creating locked down accounts that are nanny state and useless. Don't FORCE it on everyone.
Also, the concept of what is "safe for children" differs between countries. One major way of oppressing LGBTQI+ people is to outlaw showing anything that promotes LGBTQI+ "lifestyles" to children.
Your second point is an interesting extension: 'safe for children, in all countries' would lead to a race to the most bland, safe, content: "baaaah" - 1984.
There's no right way to "protect children" when some countries define any mention of LGBTQI+ to be unsafe for children. There is no way I, as a random website creator, can figure out the appropriate worldwide label for my content. Am I foisting "the effort of protecting children to others"? I don't think so.
Now after 17 years, they are asking me to age-verify my account. So far I have refused, but I think eventually I'll be forced to cough it up.
I have a feeling that it will probably start with birthday first, and then later expand to adding real name, address, and government issued ID.
There are already scam emails with this basic concept, such as falsely claiming to have video of you watching porn.
I don't present myself as something other than what I am. So, they can't really blackmail me. Life's easier when I don't do anything I'm ashamed of.
You ask Facebook to ID me, fine, but my-pretty-face.ws will continue existing unchecked and there’s nothing you can do unless you want to start blocking 80% of the internet.
The solution is simple: Move the damn check to the device or network. Block content at schools and lock down your own children’s devices.
Along those same lines, the internet can in fact have scalable information verification (age,height,income,sex...etc) with robust privacy: https://certisfy.com
In other words, cryptographic certificates can solve this problem.
However if a user is smart enough to bypass those checks it's likely that the content they are blocking will not do them any harm (though equally i'm not sure i've seen research that suggests that exposure to adult content online is harmful specifically to those under 18)
I have however seen plenty of research that suggests that social media is harmful to just about everyone, and we're not trying to block that
I don't think so; forging a reverse DNS so your IP address looks like you're a spider connecting from google.com is not trivial. The other aspects of the connection can be easily faked, of course, but that means nothing if the site is validating on IP block or domain.
(There will likely be trivial ways to defeat the age checks, just not by way of the route of successfully pretending to be the Google spider.)
It's not even an important front in the culture war.
It's called treason. For example:
> Treason against the United States, shall consist only in levying War against them, or in adhering to their Enemies, giving them Aid and Comfort.
The US shows the limits of that approach - many important civil rights are the results of "judicial activism" in the face of legislators, and the legislators remain really upset by that.
Also the UK constitution really does not work that way. Formal censorship was only abandoned in the 1960s and "official secrets" are still illegal to publish.
The key idea for this project was it's carrot and stick, all UK providers get adult ID they can use to hook billing (a carrot), and then we block all access to any non-UK providers who don't get in line (the stick), thus protecting the schmucks who fell into line rather than leaving. They hope this is enough to pressure global companies into doing the same and once it's the status quo they assume it stays that way through inertia.
The white paper says OK, some Britons will use Tor and there's no a lot we can do about that, but most Britons won't know how or won't bother. We can block everything else by beefing up DNS blocks that big UK ISPs already implement, the remaining ISPs can be forced to do the same or we'll lock them up, it'll cause a few protests and so on but we can weather that with our overwhelming public support.
All that's before TLS 1.3 and before DoH let alone ECH, oblivious DoH, and onwards into the foreseeable future. So today the result is that the "stick" part of the plan doesn't work and it will work less every day, their citizens can trivially choose not to accept the limitation and will do so in huge numbers. Without the stick, the carrot doesn't look very juicy after all, the non-UK market doesn't want your censored ID-requiring site, there's a better one without those problems. And of course today that government looks a lot more tired and unpopular than when this was originally floated.
The price for this quixotic moral crusade continues to soar, the eventual purpose of it remains unclear, eventually maybe Boris' replacement will announce (to applause) that the government has abandoned it, after spending all this time and money to no purpose.
I'd seen it posted to Mastodon earlier.
Critiques are very much on point.
If only Orwell were alive today, I wonder what he'd think.
The first paragraphs of the article itself address this. Is that insufficient or unclear?
It seems like it's Europe and probably the European commission but a bit of web search doesn't turn up anything.
Given that, and the massive amount of money in search, I think the headline falls somewhere between clickbait and a flat-out lie.
Sites would just have to decide which search engines they want to allow to spider them, which will probably be a hardcoded list in a webserver config file somewhere, with the associated public keys.
If we're lucky, webserver package maintainers will try to keep these lists up to date, and Google may even contribute some funds for the development effort, doing just enough to stop this system from triggering an anti-trust investigation.