Age verification is incompatible with the internet
jonaharagon.com
jonaharagon.com
That's not what's being asked. There already exists software, and optional functionality on OSs/routers/browsers, that allows parents to restrict what sites can be viewed. This software covers more sites (and offer greater customization) than proposals involving sites verifying ID would, since:
* The software can trivially add sites to its blacklist regardless of whether they're outside of jurisdictions that would require ID verification
* Sites are more likely to identify themselves as pornographic than to implement ID verification, since it's a significantly smaller burden
* Small/obscure sites that could fall under the radar with non-compliance on ID verification can still be blocked by the software with statistical/ML methods
* For young children a whitelist of known-safe sites can be used
Neither approach is perfect. With ID verification, a child could use a free VPN to bypass it, or be shown a friend's older brother's ID. With filter software, a child could borrow an unfiltered device and find an unfiltered Internet connection to use it on. The question is: would ID verification be better to such an extent that it justifies the privacy invasion and increased risk of fraud, blackmail, etc.? To me, it seems substantially worse than existing solutions.
That's not the world we live in today. Stores local to me will sell a (terrible but internet capable) phone for $35 to anyone. So you are proposing moving the age verification to the device purchasing stage?
Here's a couple. You can buy these and use them with the free wifi at McDonalds or with a $30 prepaid plan.
I'm not saying I support these age verification schemes but saying parents can easily control access to the internet is dead wrong.
https://www.walmart.com/ip/Metro-by-T-Mobile-TCL-ION-X-32GB-...
https://www.walmart.com/ip/Simple-Mobile-Nokia-C110-32GB-Gre...
These deals are extremely common in the US: https://slickdeals.net/newsearch.php?q=tracfone&searcharea=d...
The point of this is to introduce friction. The goal is not 100% effectiveness and it's a strawman to suggest it is.
Once you get to a state where the kid is unsupervised, is determined to break the rules, and has money to help them do it, they're going to succeed.
For example, at least a few years back it was basically impossible to enforce DNS based filtering on iOS devices much less other more invasive setups.
Because you choose to give your children freedom to operate their device however they see fit, you are in support of legislation that restricts what they can use their device to access on the internet?
Do we arrest the parent or the child when the child posts a picture of their genitals on insta-snap?
Even whitelist-based parental controls aren't great given what's accessible on major sites that accept user-generated content.
There absolutely is a real problem here - too-early exposure to sex is one of the biggest drivers of sex offenders.
This argument is essentially that it's acceptable for websites to show porn to children if their parents don't care or are fine with it.
It's a horrible, dangerous thing regardless of if parents are involved are not, and therefore should not solely be the responsibility of the parents.
Minor children really shouldn't have an expectation of privacy while they're out on the big, bad Internet. The best advice is for families to have computers in common areas only, where children's screens can be noticed and observed by parents at all times. That's not so much about a lack of trust in your own children, but beware the rest of the Internet.
By all means, teens can be granted increasing privileges and privacy as they grow up and begin to have their own lives. IF you as a parent have fostered their trust and you've inculcated "street smarts", then at a certain point you let go and trust them as well. Amazing how that all works.
You don't know your child until you've seen their browser history (before they've had a chance to clear it). Take a peek sometime.
I let my kids think I trust them, but I trust them about as much as the GRU. They think I actually believe that they don't have Discord installed, but I already know what they changed the icon and app label to. They think I believe they're not uploading videos to YouTube, but they are. They have no qualms about lying to me-- and I have a good relationship with these two.
Most children aren't. You're definitely telling on yourself more than commenting on how children behave. Trust is a shared activity. If you treat children like you'd treat the GRU that's exactly how they'll behave.
> and I have a good relationship with these two.
If you have a good relationship, why are they lying to you? Is it because they don't trust you? Is that because you don't trust them? I wonder who started it. I'm pretty sure you'll blame them again, so I'll pre-answer for that. "they proved it already by making [some mistake]" ...yeah, kids will make mistakes, but when you forgive them, and believe in them, and prove that they can trust you, they will. By treating them like the GRU all you do is prove they can't trust you. You're supposed to be the adult, right? You have to go first, children are only able to copy what they see.
Trust must be gained.
> You don't know your child until you've seen their browser history
Are you sure ? This is like this MTV commercial when the child is watching porn when the parents enter the room, only to switch to MTV afterwards.
In other words, my objection is not to your assertion that parents should work to develop trusting and respectful relationships with their children. Nor do I disagree that such relationships would go a long ways towards addressing media consumption. My disagreement is with the idea that it is always possible to be completely successful.
There would be legal consequences if a child were to walk into a store and purchased age restricted products. It is because others are not allowed to interfere with the parenting of children. (Some, albeit not all, age restricted products allow for parental discretion rather than being an outright prohibition.) There are also other ways of looking at this, such as protecting vulnerable populations from exploitation. (Such as the sale of addictive substances like alcohol and tobacco to minors.)
I would consider framing the issue as offloading parental responsibilities onto society as disingenuous at best.
The world has become a crazy and disgusting shit.
Why not ? Ads, wherever pervert, are ok. As long as they don't watch porn... /s
I'm not in any way saying the solution is requiring uploading id or similar verification, but thinking parents can actually effectively control what their kids access is just plain wrong. Always has been.
Well, Microsoft Family Safety was very effective to not allow Firefox to run, although Edge ran fine. /s
Jokes aside, what would be the failure mode if some metadata about audience minimum age was given legal blessing? Regular browsers would simply ignore it, browsers with enabled parental controls would reject the page or site. Vendors of parental controls could focus their efforts on suppressing those sites that lie and the numerous proxy services that would inevitably pop up (but that's a problem they already have I assume). What am I missing?
There's no legal blessing for this, but there's already an industry standard (in the vein of the ESRB ratings): https://www.rtalabel.org/index.html?content=howto Most porn sites have already voluntarily applied this label.
> What am I missing?
My best explanation is that moral panic always plays well to voters.
You are missing, that many people in that space don't want to solve that specific problem
* Some companies and their lobbies want to sell their products for filtering or whatever
* Some people want to get rid of all sinful porn
* Some want to block a lot more content for more people and need infrastructure
* Some want to have further control
Etc. "protecting the children" is often a good way to denounce opponents
It really shouldn't be needed: web pages are all about tags with data and metadata. It shouldn't be hard to add metadata about content type.
I never quite understood why labeling initiatives never gained traction:
* https://en.wikipedia.org/wiki/Platform_for_Internet_Content_...
* https://www.w3.org/2007/powder/
Throw some <meta> tags in and browsers can parse: then have a password-protected "filter controls" area in settings (and perhaps a GPO for corporate environments).
Sane technology legislation requires competent representatives. This is what folks voted for. Parenting responsibility in the aggregate, very broadly speaking, is not what it used to be. This is not to say that parents today are worse, but that standards and resources are different (two adults having to work full time, quality time per week between parent and child, ubiquitous access to social, screens, and internet, etc).
In theory you could implement age based access controls, but as the article points out, these are full of tradeoffs, and none of them are good. You will either get vendor lock in, violations of constitutional rights, a wider dispersal of Personally identifiable information, or a poorly thought through government implemented solution whose only feedback is additional legislation.
Parental desires to prevent children from seeing inappropriate content is not strictly opposed to individual free speech rights, the need for dynamism and open competition in the marketplace, or a need for privacy and information security. To say these issues need to be balanced would be a false dichotomy. Perhaps the solution is for society to respect parents by giving them the resources they need, through paid parental leave and employment protections.
Specifically, it's likely that police and/or national security would use them in ways that would result in false arrests and/or chilling online behavior. It is also becoming increasingly likely that Christian Nationalists would use them to censor speech that they don't like and/or to persecute people that they disagree with.
I am not for it but it wouldn’t be hard to do in countries like that; I guess the US doesn’t have / want this? Like a state owned social security login site?
Lots of identity protocols like OAuth have the provider do the redirect so they know the site. Which makes sense cause they want to validate the site. But it works to have the app do the redirect. They end up passing the token to the sire.
I worked on a privacy preserving system that did this among other things. Third parties who received an attestation of some property could verify it.
To be fully private, a bit more is required. Crucially, each time an attestation is provided it is made unlinkable to previous times it may have been provided. So the third party only knows the attestation they have just received is valid, but not that it is the same unknown person they saw yesterday.
Not giving all our information to data driven businesses just to exist.
Besides that, why is any of that complicated stuff even needed? I know my age, and I am able to verify my age without involving any 3rd party, software, AI etc. If someone else wants to lie about their age, I am not convinced that I should need to jump through hoops and give away my own privacy as part of any of the flawed schemes supposedly intended to prevent that, as some governments are trying to push.
There is no legal binding to who signed the Eula in normal end user accept. This differs from a paper contract where the signature is person identifiable.
Your cats paw could have clicked on the Eula accept :). Who is liable then the cat?
I think that if Eulas was taken to highest court of law they may not hold through screening.
Says: - the porn site creates a challenge and send it to the browser. - the browser goes to the governmental service where one uses tax ID or the like to prove age. The service returns a challenge answer encoded with the government private key - the browser goes back to the porn site with the answer. The porn site uses the public key to decode the governmental response and validate it does correspond to the challenge.
As I see it, theres no PII that the site can get, no history leak on the government side, no excessive centralisation, nothing frighting really.
Do I miss something?
The point of the article? The idea that I shouldn't have to ask my government for permission to view information/media? The fact that this absolutely will doxx your privacy to the government?
I'm all for, "wont somebody think of the children", but IMO protecting children is a 'solved' problem. When a child runs into the street we blame the parents, we don't install gates down every sidewalk. When a kid is seen riding a bike without a helmet, again, we don't decide that you need to send your government a selfie before the tires unlock.
Sites do have a responsibility to ensure people don't misuse their content. But liquor stores only ask for ID when you try to buy a dangerous substance, they don't make you ask your government for permission.
And that works flawlessly, fake IDs definitely aren't a thing, and I'm sure the same applies to this online ID thing.
Edit: I had 2nd thoughts about this because I don't like to make slippery slope arguments but this one seems worthy of consideration at the very least. Once this exists, all sites dealing with fraud will start to use it. Which Will have a DOS effect on government servers, which means they will try to mitigate it by requiring the requesting site provide a site ID and unique ID for the request. So much for any of the features that people expect might protect some privacy.
Done properly this will not reveal your online behavior to the government any more than using your government issued ID card to enter a bar leaks your location to the issuing party.
Now, whether governments should have the right to restrict access to certain types of information and media based on age is a different question
This is incorrect, and a gross misunderstanding of how either network requests on the internet work, or crypto... likely both.
Are you really saying someone looking at an ID card is the same as my computer sending a request containing my ID to a government entity, and waiting for a response?
1. User verifies their age with a trusted party (which may or may not be a government body)
2. User requests a token from the trusted party. The token is signed so 3rd parties can verify it. The token also includes the public key of the user so 3rd parties can verify whom it is for
3. The user shares this token with the 3rd party site, who is now able to verify the user’s age. Note, the 3rd party site never has to contact the issuer of the token other than to get their public key.
With this model, the token issuer is not able to connect the user to the 3rd party site directly.
We can, of course, think about possible attacks but this is just a basic illustration of the possibilities.
Why would it ever be?
Either incompetency or Malevolence will make itself manifest.
Sometimes "think of the children" really is think of the children.
> One-third of Mexicans aged 6 to 19 are overweight or obese, according to UNICEF. They may not be disproportionately affected by COVID-19 now, but they can suffer myriad health issues, especially in adulthood. [2]
(for comparison, 20% of children in the US are obese [4])
[1] https://www.npr.org/2020/09/14/912029399/we-had-to-take-acti...
[2] https://twitter.com/CongresoOaxaca_/status/12910804963032227...
[3] https://twitter.com/Magaly_LopezOax/status/12910848195611729...
... though it probably shouldn't use the same age cutoff as beer. 18 or even 15 would be better.
The downside is that - even with mild enforcement - fast food would get even more expensive for people who buy the cheap items which are currently subsidized by drinks.
Very tired of the libertarian arguments when they obviously don't work.
On the other hand, we know that communism works on the small scale due to the success of various traditional communities and non-profits.
Depending on the specific system being discussed, there's also significant evidence that "more moderate" systems related to communism (e.g. various forms of socialism) work. Part of the problem that I've had in trying to interact with libertarian ideas is that they tend to be purist. In particular, when confronted with criticisms they tend to claim that under a complete libertarian system they wouldn't occur. However, that precludes the ability to consider whether an incomplete libertarian system might have merit.
Libertarianism <---> Authoritarianism
Capitalism <---> Communism
Usually the sweet spot is somewhere in the middle of both, which is what the United States is (though some may argue we've begun to slide towards the extremes)
The government ensures that realistic healthy options are available but doesn't force people to select them.
The government applies a minimal tax to the most obviously unhealthy options but doesn't otherwise restrict anything.
The government applies regulations before 18 years old but not afterwards.
Unironically this should be a mechanism.
While I recognize no system is perfect, we would still socialize those born into misfortunes, I see no reason not to mandate intensive regulations. It is immoral to require society to pay for shit decision making.
It was sarcasm. Pointing extreme of previous sentence.
My German national id has an eid feature that you can use, for example when buying booze online to verify your age. There's a dedicated public company set up for this, so the vendor only gets a yes/no. That's much, much better than typing your personal information into some random website from a privacy standpoint. It's better to have verification behind a dedicated API abiding by some standards than the "type everying into the webform and pray" status quo.
And as a sidenote on the cultural issue itself. I have no problem with porn or drinking etc, but when I go into a store for anything adult related someone at the door asks me for my id. Idk why people make a fuzz about having some basic due dilligence in digital marketplaces. Cinemas need to make sure people who attend adult movies are of age, bar owners need to make sure underaged kids don't order drinks. This is a completely reasonable level of responsiblity on business owners.
Thats not possible to do, so they go and attack it with fake outrage (and it are all fake, children are not actually interested in sex nor do they spontainously combust if they see naked adults).
Same with exedus cry, which is not about "saving adult performers" but about making it harder and harder to run a porn site.
I personally think that the libertarian argument is good: the government should focus on things other than this.
Which means devices could enact opt-in controls. Periodically scanning screenshots for nudity? That’s a feature… for an app. You’ve got all the right filtering apps? You’re a compliant semi-trustworthy teenager/Christian/Muslim/Exodus Cry member/citizen of the state religion. Parental controls keep the apps activated. A computer with 1995 Netscape continues to work with arbitrary Internet content. git and Docker don’t pause for AV when a comment contains the string “XXX”.
What you’re talking about are the movements behind the blockers. We can imagine an app which targets “sin” rather than nudity. Detecting corrosive text stories, especially homoeroticism. That this is merely very approximate detecting false positives is a feature, not a bug. One can’t be too careful with the intentions of outsiders. That the app itself collects more PII than the zero-knowledge proofs explained here is not interesting to its market; they already give superlative trust to those app makers. Perfectly acceptable to be carefree with the intentions of insiders.
Parents get a device that sanitizes as much as they want. Religious communities get to bless smartphones as finally advancing their fight against sin. The opt-in apps stay out of the way of well-adjusted busy people.
I’m ok with that scenario but I predict it requires a committed user base, patience with false detections, sustained funding, noticeable battery impact, and empowers some speciality app makers to be morality custodians. I’m less ok with one government getting all that right across a global communications network, even for the worst content.
But lawmakers who want control don’t like those apps. They want (1) the effects to be broadly distributed, (2) that the gatekeepers be hyperactive invite-only groups on social media, (3) that those volunteer ratings boards promote certain tastes over others. Song of Solomon must never be blocked. A reference to a torrent that contains a gay furry story? AV the entire domain, read the story into the Congressional Record, AV the Congressional Record.
Obviously hyperbole, but my point is that these are the contours of what a minority want with power. This comment section is full of people who want one government to make parenting choices for all, but as quoted in the article about the lawmaker from Utah, the censors are shockingly bad at predicting the future. We have to scrutinize their implementations when all proposed solutions depend on a powerful government intervening past the HTTP header level whenever someone finds inadequate supervision within any particular open forum.
The issue is the companies being targeted have simply chosen to not enact any AV or gating measures because it would impact their existing business. Additionally, the targeted companies have solutions available but are leveraging legal and lobbying efforts vs. changing their business.
Source: I work for a company that distributes a widely used AV product.
For adult industry, the issue is gating web traffic. But as I explained to a regulator mentioned in the article, as long as there are shady companies who won’t comply and can’t be fined, it’s a moot point.
> For adult industry, the issue is gating web traffic.
Clealry that is not the only issue as adult sites have chosen to stop operating rather than comply in jurisdictions that require AV.
You can believe that a standard committee of very smart people (technical and regulatory) was thinking about all these problems so saying “what about X” isn’t helpful when X is an obvious concern.
A sufficiently advanced attacker could probably figure something out (especially with these 3p apps which are bound to have security flaws), but it will be out of reach for most people (these apps will hopefully be discontinued once the OS wallets integration is complete - they should only be used for pilot programs and if they’re not they will be stopped once they become a known vector of identity theft).
The harder problem is attestation for >13 services since kids that age may not have digital devices and government ID but that’s a government policy problem to figure out.
Really? Doesn't HN show on a monthly basis that no, exactly nothing directly follows from that premise? Typically the committee has completely different incentives and directions from, well, half the planet's wants?
At that stage though, mine was just a question. I was curious.
> they will be stopped once they become a known vector of identity theft
Okay. I'll agree to disagree. See US Social Security Numbers, cell phone numbers, credit card system...
- At point of purchase for a consumer device that can view Internet content, the salesperson (or web store) is required to ask if the device is for an underage child, in which case either the device is placed in "child safe" mode, or printed instructions are directly provided giving instructions to do such. The child protection settings should be linked to the parent's e-mail address (so they can be lifted when the child is of age, or the device is given to someone else, etc).
- Consumer devices must support filtering for underage users (they already do, although perhaps this could be made more standardized and easier to use).
- Adult sites are required to list themselves as such so they can be filtered (they already do this quite voluntarily).
Of course, this assumes that legislators are making these rules in good faith (I strongly suspect they are not, and thus they are actually unconstitutional attempts to restrict free speech).
There's actually a meta tag that most adult sites set to do this already. It's also used by Google to identify a website as adult for SafeSearch reasons. The process seems simple enough, https://www.rtalabel.org/index.html?content=howto (meta tag) and https://www.rtalabel.org/index.html?content=howtofaq#apache (http header)
It is strange web browsers don't take advantage of it, though. This combined with some kind of AI model would work in most cases I bet.
Also underage people could go to the store and lie about their age, so if we want this plan to be effective we’d need to ID everybody buying electronics, which would be annoying.
It also isn’t clear what it means for a device to be “for somebody,” if somebody buys a desktop and a kid lives in their house, it is at least possible that the kid will get access to it.
Obviously porn blocking should just be something parents should concern themselves with, and parents alone. Software and device vendors already provide all the necessary tools.
But VPNs have already come up as the way around these new age-verification laws, and that didn't stop them. Kids can always find ways around this stuff (when I was in high school eons ago, just about everyone was underage drinking, and a lot of my friends had porno mags too).
Fortunately, most democratic countries will be constitutionally prevented from enacting full-blown police states to stop kids from doing naughty things. Hopefully.
Constitution/law just transfer responsibility to other entity. Whithout responsibility, there is no freedom. State never bringing morale or ethics to society. I would rather focus on why kids doing naughty things, where they learn it, what are consequences of their actions, etc.
In general, there would be more implementation problems the farther we look away from there: what about things like laptops, particularly laptops with Linux, or raspberries pi, or heck, an Analogue Pocket… there’s a whole range of computing devices; locking down all this stuff would be a huge pain-in-the-butt process. Rather than have some legislatively confusing mess where every device manager has to wonder if they are responsible for implementing some giant DRM scheme, we’re better off just letting the market handle it.
(*) Yes, jailbreaking gets around that, but now you’ve circumvented a content-control system, which is a bigger legal problem under DMCA than any legal Internet content.
However I disagree that the plan would really be able to accomplish what legislators claim they are trying to accomplish, so I don’t think this line of argument works as a rhetorical device.
I’m not sure that “Whether Software and device vendors already provide all the necessary tools” is really the sticking point… sorry, I’d write more, but actually I’m not sure how that is supposed to link into the argument so I’m not sure where to go with it.
It's not hard to imagine a jailbreak showing up shortly to defeat it. Even Apple can't prevent jail breaking for their devices. I think it's unreasonable to expect other consumer devices manufacturers to win a game of cats and mouses like that.
Requiring legislations on this is even worse. It will serve as a regulatory capture for big corps that can afford to invest on security.
Games and everything need to be vetted when you are 17? Since if you allow them any kid could also download a custom browser as well to get past that, and if there is a way, this info will be shared amongst kids.
Just as with the “you must be at least 18 to view this site, only click ok if you’re at least 18” popups, I’m pretty sure a smart 17 year old could figure out that notpornhub.com silently drops the special filter tag but is otherwise identical to pornhub.com
Fortunately, most democratic countries will be constitutionally prevented from enacting full-blown police states to stop kids from doing naughty things. Hopefully.
Is there a penalty if they don't?
Is there a penalty if an adult lies? Is there a penalty if an underage person pretends to be an adult?