Calif. Law to Protect Children's Privacy Could Lead to Invasive Age Verification
reason.com
reason.com
I get that privacy issues can be most sensitive to those under 18, but it's important to recognize that enforcing far stronger privacy restrictions alongside strong age-verification expectations (no more "are you 18+? yes/no" or "what is your birthday?" questions) can only come at the expense of anonymous browsing.
https://greasyfork.org/en/scripts/423851-simple-youtube-age-...
Works fine for me on FireFox + Greasemonkey
No, this is not true, there are numerous ways for a system to authenticate a user without the endpoint requesting the authentication knowing who the user is — or the system verifying the user knowing what endpoint system is requesting the authentication; only the user knows both who they are and the endpoint they want access to.
EDIT: This appears to cover some aspects, still reviewing it and to confirm it covers all the system attributes I described:
https://crypto.stackexchange.com/questions/96232/zkp-prove-t...
Obviously looking for example, but if you’re able to think of an additional issues that need to be accounted for, let me know.
Even then, if the government actively compelling endpoints to hand over their data is within the threat model, the government could inspect any cached temporary tokens to deanonymize the users. This could perhaps be mitigated with some way for users to irreversibly transform the temporary tokens given by the government, but I'm not sure if that's possible while retaining the ability for endpoints to verify the tokens.
Overall, though, the sharing problem seems to me to be the biggest issue by far with this scheme. What makes a user an individual human? In current implementations, their unique government ID (perhaps made illegal to falsify) is used for this. But I can't see how individual humans can be distinguished in a privacy-preserving way.
Never really gave system much thought at the time, since governments rarely want less data or to provide anonymous access — and average person does not care about anonymous access, in fact, in my experience they want everything logged. Same topic could easily be applied to numerous functions such as border crossings, but governments want to track who is crossing instead of just checking individual authorization to enter.
I first saw them used with Clouflare's Privacy Pass https://www.hcaptcha.com/privacy-pass, they've also been used with Google's trust token proposal.
For those interested, here’s the related paper covering it:
https://www.petsymposium.org/2018/files/papers/issue3/popets...
And yes, my understanding was tokens entered a pool of one-time tokens and neither the government or endpoint was able to cross reference them to a specific user.
Which to me might mean it might address if user is refused new tokens, it might not account for if the tokens are revoked or the authorizing entity ceased to exist, but the attribute was uniform, for example age.
https://privacypass.github.io/protocol/
All and all, at very least, appears to be an extensive and extendable standard, assuming those involved are reasonable and there’s no conflicting interests.
https://news.ycombinator.com/item?id=33133749
Ideally, endpoints would not even know the specific authentication provider, but that the authentication came from a authentication service that’s authorized to confirm a given identity and related attributes; for example, being over X age is a binary attribute and numerous entities should be able to authenticate that and it be honored by a jurisdiction similar to how passports are uniform.
This problem doesn't exist with today's simple prompts that just ask for your birthday and blindly trust the end user.
Surprisingly (to me at least), certain cryptographic tricks can do a pretty big chunk of that, by having the website/government and user/government interactions occur ahead of time. But as far as I can see, there's still the issue with these tricks that 18+ people could share their access with under-18 people, which the government would want to prevent.
Also, does appear Privacy Pass covers the other aspects, which is covered on this page, but still trying to work through if it covers all aspects of a system that at least for myself I would be agreeable to use for things like: age verification, citizenship, captchas, etc — basically anonymous verification of identity attributes.
I also don't really see how present physical identity could be proven in a privacy-preserving manner, if you don't trust the government or endpoints not to abuse that physical data. Alas, even if I take your word for it, I doubt that governments would implement such an indirect system for age verification in practice, especially since they might want to revoke any erroneously-issued tokens.
(And even if anonymous non-circumventable age gating were to become a reality, I still wouldn't be a fan of differential privacy regulations for minors, since many ordinary sites would become inaccessible to teenagers from following the path of least resistance. Either impose the regulations on all users, impose them gradually depending on age, or don't impose them at all.)
Wouldn't they know your IP address from which the request is coming? Or potentially use other browser tracking and fingerprinting tricks?
Maybe I misunderstood but it didn't sound like you were describing blind tokens issued in advance.
Thus, the government might learn that some user accessed that particular endpoint
In my view the government knowing the endpoint associated with an individual request is a critical shortcoming. It's just too short a crevasse for them to jump to get that missing piece (identity). Even if the protocol is sound there are other means (eg. force an endpoint to hand over logs, associate with authentications via timing or other characteristics, and use other tracking metadata provided by the endpoint itself or other third parties or even ISP's to figure out who accessed what). No thank you.
Also creates an easy, centralized chokepoint for more widespread censorship. Simply put, the government is not a choice actor I would trust with this type of capability. The technology is not mature enough to truly, in practice, provide the protections needed to do this right.
I've commonly seen this cited as a benefit of uncircumventable age gates, but I think that most proposed systems I've seen are far stricter than they need to be for this: they have a hard line exactly at 18 or 21, and allow neither read nor write access to gated-off sites. Should a 17-year-old teenager be able to access no more social media than a 7-year-old child can? And must read access always be gated, even though gating write access would be sufficient to prevent this overrunning? Teenagers have to learn how to operate in the adult world at some point, and I worry that pushing so much access to age 18 all at once could have major unintended consequences.
As long as there is potential, significant liability attached to showing under-18's certain content it's safer to just not show them anything questionable until they're 18.
I'm with you, I think a gradient would be developmentally better, but our legal system discourages that. I think the same thing exists across other parallels; people get a ton of options dumped on them at 18. It would probably be better to phase that in over time.
But that isn't how collection-maximizing surveillance companies work. Right now, the lowest friction is to ask for birthdays where they can get away with it, but never really verify. If the law gives them a reason to verify, then the incentive is to expand their plaintext-based all-knowing systems to perform verification.
Sure, we'd likely see a startup that promises to do privacy-respecting age verification, but it would go nowhere. What incentive would there be for Google et al to adopt it, as opposed to say just requesting your driving license number with a message implying that California "made" them to do this ? The companies without the cloud to demand personal info would then outsource the verification to the bigger surveillance companies.
This topic demonstrates one of the main pathologies of the US model of governance. Instead of pushing constructive actionable privacy restrictions for everyone, the government is poised to create another hook that merely emboldens corporate control.
What we need is a US GDPR with an analogous definition of consent - if implementing functionality to examine and delete my data is too hard, then just don't store surveillance records about me in the first place! But what we'll end up getting is ineffectual nonsense to be nullified with more clickwrap legalese that nobody reads.
no, its not.. but a bulk of FB/Google dollars that are, dwarfs a lot of other things.. its a sick situation, I can agree with that.. important to speak out
Only the government should need real IDs.
For example, if I am actually over 18 and intend to watch a video intended for over 18, I should be able to use a fake ID for it.
False dichotomy.
(Also known as false dilemma, bogus dilemma, either-or fallacy, black-and-white fallacy.)[FN1]
If the website protects the privacy of all persons, not just those under 18, then there is no problem complying this law.
It's like the folks who claim the web cannot or would not exist unless advertising is permitted. It is a self-serving statement of an opinion. It has no evidentiary basis.
This false prediction, nonsense reasoning is probably accepted by generations that did not experience the internet before advertising was permitted, before online advertising became pervasive, and/or before online advertising was based on data collection and targeted. The fact is the internet and web did exist without advertising. There is no technical limitation that requires a website to collect data and/or serve ads.
Common retorts to such historical facts include such gems as
"I would never want to go back to 199x", or
"All the wonderful content of the web today would disappear."
1. Computers and networks are never going to return to 1990's prices and speeds. Speeds keep increasing and prices keep decreasing.
2. Who would have guessed, but today's commercial web content is actually being generated mostly by website users themselves rather than website operators. "Tech" companies operating high traffic websites have promoted their own "business", online advertising, to lure people into uploading to their websites without expecting payment in return. Like some sort of opaque lottery. This is why the web has become a cesspool of "clickbait" and garbage "content".
The usual ethical difference, as I've understood it from prior discussions, is that a legal adult user can always consent to a company using their data, so long as the data is knowingly given to the company, the user has been honestly informed of what that data is used for, and the user can revoke the company's access to their data at any point. (Some people recognize less-strict conditions as acceptable, I'm just taking these as a baseline.)
However, many of these new regulations outright prohibit minor users' data from being used in certain ways, even if those users have freely consented to it, with the justification that minors are unable to evaluate the full consequences of their data being used. Since businesses face major liability for violating these regulations, they have two options: either implement the strictest possible age-related regulation for every user, or implement an age gate that cannot be circumvented short of the user committing fraud.
In this particular regulation, some of the wording is vague, requiring a "compelling reason" to collect minor users' data, regardless of those users' consent. Businesses abhor that kind of liability: how do they protect every user as if they might be a vulnerable minor, under every possible interpretation of the regulation? The easier path by far is to require an age gate.
Thus, I'd argue that the better path would be to require uniform privacy regulations, recognizing that random websites don't want to be in the business of age verification. Either require the same strong privacy regulations for all users, or don't implement the new regulations for minors at all.
No one, whether they are 18 or 81, wants to consent to surreptitious data collection for undisclosed uses.
But "tech" companies cannot survive without conducting surveillance. And so it is the false "tradeoff" (false dilemma) that they must sell to the public to survive.^1
Why do so many "dark patterns" exist. Because no one in their right mind wants to consent to what is actually going on with the collected data at these websites, which need not be disclosed by law so how would anyone on the outside even know. We let these websites get away with this nonsense in the case of adults but with children it is just too egregious to allow. Hence the AADC. This by no means suggests that adults want to consent. The dark patterns target people of any age.
1. If do not allow data collection and surveillance then there can be no web. That is total BS. We just saw instructions on how to download Wikipedia yesterday on the HN front page. We can build hospitals with opioid money but that does not provide a justification for selling opioids without restriction. We can also build hospitals with taxes or donations.
So what exact actions make up "collecting data"? Is it how long the data is stored? How the data is obtained from the users? Whether the users are aware that it is stored? What kind of data is stored? How the data is used by the website? Whether the data is transmitted to third parties? Some combination of all of these?
People both on this site and elsewhere have come up with different answers to all of these questions, and we need to nail it down if we want to have effective regulations.
https://www.thedailybeast.com/beyond-sketchy-facebook-demand...
https://www.theverge.com/2019/4/18/18485089/facebook-email-p...
Facebook does not sell user data. No need. They sell access to the targets of the collection to advertisers, including political campaigns, among other things. We have no way to know all the uses Facebook makes of the data they collect.
If Facebook were to go under, what would happen to the all the data collected.
What should be most concerning is that Facebook buys data. When combined with the data they have collected about people, this creates a potential hazard the Facebook user has no way to assess. There is nothing in any Privacy Policy, including Facebook's, that suggests a website operator will not obtain data about the website users from other sources.
In addition, with use of "beacons" or similar, Facebook collects data about what websites Facebook users, and www users in general, visit outside of Facebook.
Perhaps people would not consent to Facebook holding so much data about them, from various sources. Far more than what they themselves have voluntarily submitted to Facebook. We will never know because people are not full information and the choice whether to opt out.
Facebook is not a credit bureau. When credit bureaus tried to collect this much data about people from various sources, the practice became the subject of federal regulation. For example, FCRA, FACTA, FCBA and Reg B.
More generally speaking, governments should start seeing the hoarding of data by itself and others as a national security threat, open source any government systems — and offer bounties for anyone able to maintain the objectives of a system while reducing the system’s access to sensitive data.
______________
* EDIT: 100% sure that it’s technically possible to have an endpoint anonymously verify age and a verification system to do so without knowing the endpoint requesting the verification, but unable to find technical explanation of how this might be done using existing technology; might be wrong, but believe it included a combination of differential privacy and zero knowledge proofs. Does anyone have a link to detailed explanation of how to implement such a system?
Better idea: webcam verification of government ID. Client-side/in-browser AI software matches only name and birthday before passing OK to website. Zero information is actually transmited/stored. Patent please.
There are numerous ways for a system to authenticate a user without the endpoint requesting the authentication knowing who the user is — or the system verifying the user knowing what endpoint system is requesting the authentication; only the user knows both who they are and the endpoint they want access to.
But minecraft has always been an "all ages" game, not a kids game. And it was first advertised/promoted on 4chan.
As someone who prefers tape I feel discriminated against.
With IRMA it is easy to log in and make yourself known, by disclosing only relevant attributes of yourself. For instance, in order to watch a certain movie online, you prove that you are older than 16, and nothing else.
Their docs[2] are pretty good.
[1] https://irma.app/?lang=en [2] https://irma.app/docs/what-is-irma/
Did I miss something?
Another user suggested Privacy Pass system, which I have reviewed before and currently reviewing to see if it fits system profile I am describing:
And this is all to improve the privacy of children?
All things should be considered UNRATED (adult) by default.
Adults that want to should set a flag in the OS account, which should be passed along (or optionally also set as a child account) by browsing software. In child safe mode such software would then follow a set of local policy decisions and refuse to operate with content not declared child safe. Such an account feature might also forward the data to other accounts for review (parent, guardian, teacher, etc).
THEN, the enforcement, sites which incorrectly claim to be a given rating should get hit with the charges that enables.
We could go a step further by banning highly accurate fingerprinting and make things nice n generic; hopefully making ads as generic as the wonderful ads as-seen-on-tv.
...daunting for millions of parents, who'd imagine (often rightly) that their kids, aided by friends & on-line instructions & such, would all-to-easily bypass the parental controls.
...dis-empowering for politicians lusting after attention & votes, who think that moral panics and big-government-control-freak "solutions" are their best friends.
They only accept credit cards (debit cards being the norm in Europe), effectively forcing you to send a photo of your passport to Google.
Very nice. Bravo.
And Germans supposedly pride themselves for their privacy concerns.
This explanation seems to be quite terse, "If you use a credit card, any temporary authorization will be fully refunded. If you use an ID, Google will delete the image after verifying your age."
Both methods would require me to provide them (or some other entity) new personal data. In the case of credit card payment, credit card number (and thus what bank I am using, maybe also what kind of card I have) and my home address.
My government issued ID has also other information like a photo of me, my signature, social security number, all my given names and card number. I wonder if they would accept an electronic copy that would have all those covered.
https://www.nytimes.com/2021/11/09/opinion/democrats-blue-st...
This just horrifies me. Silicon valley companies have already made it incredibly hard to parent children, with things like disappearing photos, and locked down phones given even to young children.
Like I get 16 years and up needing stuff like that, but younger than that? Parents should be able to see what's going on their kids life. These days 90% of their life is in the phone, which is the one place blocked from parents.
In the past children had a limited circle of people in contact with them, and for the most part parents knew who was talking to their children. These days? It's the entire world who has access.
California had couple of iterations of CCPA and so far it is not looking that good either, but worth trying.
And if you don't see how that can be an issue, you have lived a blessed life where you or your family & friends were not prosecuted by violent authoritarian governments arms, that exist in liberal democracies today or discriminated against for minority attribute X, both of which exist even in Scandinavia today.