Age verification providers say don’t worry about California design code
techdirt.com
techdirt.com
> Today AB 2273, the California Age-Appropriate Design Code passed the state senate by a vote of 30-0. The assembly unanimously passed an earlier version of the bill back in May ... there needs to be a concurrence step in the assembly in the next couple days. Then to Governor's desk.
Bill text: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
UK Safety Tech, https://www.gov.uk/government/publications/safer-technology-...
UK Online Safety bill, https://www.techradar.com/features/uk-online-safety-bill
> Protecting children by ensuring they are not exposed to inappropriate content online. This include stricter age-verification processes to access certain websites - like pornography sites - and, in some cases, the need to monitor private chat for child sexual abuse materials
> Securing adults from 'legal but harmful content' by removing such content from their platforms. This rule applies on major social media like Instagram (already in the spotlight for damaging mental health) and TikTok.
The really ironic thing is that there were armed guards at a children-permitted drag show, that were wearing plate carriers with LGBT flags on them. I'm all for that, man. Defend what you believe in with your constitutional rights. But what confuses me is the same people they're defending, are generally the same group of people that want to eliminate their right to own so-called "weapons of war" (which were originally engineered for the civilian market, mind you).
Sure, in the US, the 2nd Amendment does relate to a right/liberty, but other countries have managed to enjoy greater liberty (in particular, fewer murders per capita) while heavily restricting the use of firearms. That doesn't necessarily mean that the US would be better if the 2nd Amendment were repealed, I'm just saying that "boo firearms" is a perfectly valid (and liberty defending) opinion for some people in the country to hold, unlike "hooray (warrantless) government spying" or "hooray hackable voting machines".
Just consider what it is you are "all for". You want an environment where parents need to surround their children with armed guards in order to protect them from armed militias trying to intimidate them into not exercising their right of assembly. Does that really sound like a country where people are free?
Fewer murders aren't an example of greater liberty, they're an example of a desirable outcome that some people decide outweighs the loss of liberty.
To illustrate, you could also achieve fewer murders through warrantless government spying, and I think you'd agree that that proposal would be pretty hard to spin as increased liberty.
> You want an environment where parents need to surround their children with armed guards in order to protect them from armed militias trying to intimidate them into not exercising their right of assembly.
Do they want that? I just heard them say they respect the second amendment, nothing about allowing intimidation or making no tradeoffs to the point of requiring armed guards. This feels like a pretty big strawman to tear down the opinion above, rather than acknowledging that it's fine to prioritize safety over liberty but it's also fine to prioritize liberty over safety, and everyone is okay with different tradeoffs.
To say this another way: put everyone in a steel cage, watch your murder rate plummet.
But!, hey: every life was protected.
Freedom comes at a price. It always will. That means recognizing that it can put you in danger sometimes. An authoritarian regime would shut down crime much quicker than a free nation would. Does that make authoritarianism preferable? Hell no. I'd rather defend my property/person/family myself when the time comes. Because as you've probably heard countless times: "When seconds count, the police are only minutes away."
Ostensibly, the "cancel culture" that people are concerned about (nearly entirely focused on the already wealthy and powerful, who oddly are not silenced when dominating the airwaves about their supposed cancelling) is nothing compared to the real danger that threatens real average folks in our own communities.
I think you'd find that many of the people you perceive to be on the opposite side of you are concerned with the same issues that you are, and no, they do not think it's cool and normal.
>Estimate the age of child users with a reasonable level of certainty appropriate to the risks that arise from the data management practices of the business or apply the privacy and data protections afforded to children to all consumers
https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml...
If so, does this practically mean that websites would contract with third party age-estimation services which do store state-identity records? What's the track record of such vendors with data protection? Can the state provide age verification services directly, since they are already trusted with the data?
I don't see any replies disputing your reading of the bill, and I'm not sure you are saying that this is a good bill for these reasons.
The requirement is doing something horribly invasive to determine age. We all know it doesn't have to be facial recognition (though this is probably cheapest and least invasive, even though it's still gross).
It's also worth noting that while the bill prohibits entities with significant child audiences from retaining the information, it doesn't appear to extend that limitation to service providers providing age verification services.
No, it doesn't say that it would always need to be more invasive than that.
I doubt a prompt asking the age would generally be seen as "Estimate the age of child users with a reasonable level of certainty..."
Having to deal with invasive means of validating your age is a reasonably anticipatable consequence of this law. And it shouldn't be a big surprise that the data ends up misused, even if the law makes a token (very weak) effort to prohibit that.
I'm hearing that as "wave a magic wand that costs way too much per shake and hope the magic is strong enough that you don't get sued in one of three different ways."
It gets even more abiguous:
> Configure all default privacy settings provided to children by the online service, product, or feature to settings that offer a high level of privacy, unless the business can demonstrate a compelling reason that a different setting is in the best interests of children.
How are we defining "high level of privacy?" The text seems to imply just the "highest setting you have available."
And all of this hinging on if a child is "likely" to access the service in any way.
No, they did not provide a work phone.
If the latter, zbar should do the trick to decode it.
If it requires iOS or Android, that'd be a cue to inform them how you currently don't own a device with either and ask how to make it work on your Pinephone running Mobian. More people need to be comfortable with being uncomfortable for this to start changing.
Assuming employees will have personal Android/iOS devices and require registering and using them for work functions is something which needs to be mentioned in an employment contract to have any standing.
Similarly, what about people on the cusp? It's pretty hard to tell a 19-year-old from a 17-year-old, so won't there be a large population of people it simply won't work on?
[0]In an entirely spurious and random manner at the relative whim of each establishment.
It layers on to that non existent technology to perfectly identify age from video and with the bonus of a huge dataset matching faces to internet browsing.
For iPhone users who use Face ID, it could cache the result, and send it to sites (signed by a per-device certificate, issued by Apple's CA) in the background, so that most users wouldn't even know this law existed.
If Apple can perform a digital attestation of a derived attribute, e.g. "older than 18", rather that disclosing name, DoB, address to the visited website, it would likely be well received.
But at that point, we're a hair's breadth away from state-corporate fusion.
I don’t know about websites, but one of Apple’s examples is almost exactly that – “older than 21” – for purchasing alcohol (in the US, yes, yes) without giving over all of the rest of the information on your ID.
Lidar is only on the iPhone Pro rear cameras.
clutches mmWave-less FaceID-less LIDAR-less iPhone SE3
If a state or other entity passes an internet bill I think is unconstitutional or otherwise infringes upon my rights as both a web user and web developer, I'm simply going to ignore the "law" and continue on, business as usual. Sue me. The curtain is falling. I can't be assed to care. California is beyond arrogant if they think they can pull this off.
Before I get roasted, GDPR is mostly a good thing, even if its implementation has made browsing the internet worse and more annoying, at least I have legal avenues for deleting my data that didn't exist before. But this is case by case. Supporting GDPR doesn't mean I should support SESTA and ilk.
https://en.wikipedia.org/wiki/On_the_Internet,_nobody_knows_...
Dear California legislators, please try to encode the above privacy ideal into law instead of the opposite.
https://hackaday.com/2008/07/02/age-verification-cameras-eas...
I always wondered whether local logging is an option. Everything little Johnny does in his iPhone gets recorded and sent to dad’s MacBook Pro for processing every night. A local process looks for anomalous content while also producing a report of all sites visited and apps used. Taking a screenshot every 5s is going to be ~1GB per day but maybe Johnny doesn’t get to use his phone until yesterday’s log has been processed?
Perversely, to configure such a system you would have to actively prove you were doing so for a minor. You wouldn’t want to enable adults monitoring other adults.
If I worked at Apple this is something I would actively want to build, if it wasn’t there already. Anything to undercut these thin-end-of-the-wedge big brother bills and take the wind out of the “think of the children!” content authoritarians.
A parent.
Tech can help us find a middle ground between in my day we let them run free in the yard and now my child am become zombie screen addict, destroyer of childhoods.
I am no longer a minor but thinking back to the time that I was I would consider this to be a pretty big intrusion into my privacy. YMMV with your children.
It's cheaper to generate fake content than real content. Arguably it's already cheaper to generate fake content than to read real content. At which point, the information battle gets very asymmetric. It becomes very cheap for an authoritarian regime to flood an open regime's electorate with fake content, but the authoritarian regime doesn't face the same problem.
Kids are resilient. You wouldn't know that if you sit them in the corner with a digital device to babysit. But you will definitely be a better parent if you engage with your kids in their online life, and spend the time to communicate with them about whats going on out there.
Also, keep the Internet out of focus until they get close to the double-digits. Books and real family activities are best.
As an example, Linode HQ is in Philadelphia, PA and Vultr is in West Palm Beach, FL. Linode have a colo in Fremont, CA and Vultr have a colo in Los Angeles, CA. Would having a colo in California bind them and their customers to this requirement? e.g. If I only use the colocation sites not in California would that suffice, or do I need to migrate to providers that do not have a presence in California?
Sure, you could give yours to a friend but you could also scan a friend's face with the biometric suggestion or their ID with that suggestion. At least the TOTP suggestion would be quicker to verify, [can be] more privacy-friendly, and can be offloaded onto any devices (you already have one if you're going to need to verify yourself).
- https://www.insideprivacy.com/ccpa/californians-approve-ball...
- https://ballotpedia.org/California_Proposition_24,_Consumer_...
If we're being truly precise, CCPA and CRPA are just (acronyms for the) names for the laws which amended the California Civil Code, and the resulting sections of the Civil Code as amended don't officially have either name.
https://babylonbee.com/video/i-wish-we-all-could-leave-calif...
How long before some profit-maximizing vice president suggests that the requested phrases should be advertising slogans, with these ad slots sold to the highest bidder? We're this close to literally building the "Drink verification can to continue" dystopia that we were warned of:
https://www.reddit.com/r/copypasta/comments/fejdvl/drink_ver...
If y'all remember those "solve media" captchas there were a few years back, forcing people to watch an ad then type a slogan? Yeah this would def happen.
Also jim_kreggis I cant reply to you bc dead but uhh what? Weird asf ngl.
Years ago I encountered a company that sought to do this with a CAPTCHA service; having people type out an advertising phrase to prove their humanity. I thought that was pretty gross, but making people actually say it is even worse. Making people habitually say "I love coca-cola" to access their online accounts seems likely to erode people's sense of self.
Product page from the vendor: https://nlpcaptcha.in/en/nlpcaptcha.html
>Simpli5d technologies makes Captcha an integral part of their products. They provide an engaging Captcha for brands wherein the user engages with the brand by filling the brand message or engaging with the brand across its publisher reach to ensure two way real human engagement with the brand.
> Further, this is not just restricted to Captcha and Simpli5d also provides similar solutions on Video pre-roll to ensure there is two way engagement with the brand in the pre-roll as well and not just restricted to blind video views. In general in a video pre-roll campaign the brand is not sure if the video has in reality attracted the eyeballs of the consumer. All these solutions are also available on mobile.
I noticed a related effect after getting a Google Home. After a while, my first instinct if I wanted something, was to call out “Hey, Google!” into an empty room. I was literally reprogrammed, in the most disgusting sense possible, to have a brand embedded into my brain as an integral part of a frequent habit.
I don’t want the future to look like this. It’s far too close to the “verification can” meme for my liking.
I guess that'll be just in time for OpenAI or Stability Diffusion to have an app for that.
Somewhere inside a government department inspecting log-in videos "My goodness, have you seen how many websites Tom Cruise logs into each day!"