> the companies doing the check can just not store information about the check, regardless of whether they are required to delete it.
Seriously? By that logic the bills themselves are orthogonal to porn, since sites can just institute ID requirements without being required to do it. There are no 3rd-party ID services that have good privacy handling or refuse to retain information. And in the absence of government-sponsored alternatives (which companies have asked for) this is a de-facto requirement to use 3rd-party ID services that put customer data at risk.
> Here though, the laws I've looked at all specify that they must not retain it. They could have higher penalties, but they already explicitly forbid it.
False. I already covered this:
> many of the laws have limited liability and recourse for data collection, and most only target retention of ID information, not aggregate data collection about users' browsing habits. Additionally, none of the laws limit government collection of data.
----
> I can see why people could argue that's been tried enough (filters have existed for over 20 years, and access for children is still easy)
People can argue a lot of stuff, that doesn't make any of it correct. If someone argues we've tried mandating labeling for online porn and legislating parental controls... we haven't. They're wrong. They can argue it if they want, but they're arguing fiction.
----
> Maybe I'm wrong about these sites' lobbying efforts. Maybe most of them have been posting on their front page big banners asking people to tell their representatives to support mandatory metadata processing/filter enablement laws.
Pornhub has in fact literally placed large banners in certain states lobbying about this topic and asking customers to go to their representatives and get involved. I've never seen a response from the company to any porn bill in which they don't put forward the idea of device-based filtering. They are constantly qualifying their responses with stuff like "of course, we also want to keep kids safe, so that's why we support local filtering and labeling laws".
It is strictly inaccurate to claim that these bills are the result of inaction from porn companies, or that porn companies have not proposed alternatives. You claimed that these companies had done nothing; but in reality they literally built a standard for the government. And pushed for government ID verification too as an alternative to 3rd-party services! :)
----
> It's not clear what the "percent of content" in these laws means
ie, the laws are over-ambiguous and don't clarify liability to an acceptable degree. A lot of things aren't clear in these laws. It's not clear what "reasonable" means. It's not clear what "damages" are for data retention. It's not clear what "retention" means in these laws!
They're badly written laws.
> Certainly for a discussion about how porn sites behave, they [Reddit] are a major porn site with millions of users, and they do exactly nothing to turn away minors (in fact they obviously target them) or segregate the site.
Multiple of these laws have taken effect in states already. Reddit requires an ID in none of those states. No politician I'm aware of has talked about suing Reddit. If you have a problem with Reddit's handling of porn, these bills aren't doing anything about it.
Because of course they aren't, no AG is going to be so foolish as to try and force an ID requirement in order to view Reddit posts. But you know what would allow blocking porn on Reddit? Labeling requirements.
You want to know who else isn't covered by these laws? Non-commercial sites -- because placing these kinds of restrictions on non-commercial hobby sites would be far more likely to raise 1st Amendment questions (not that the laws as they exist don't already raise 1st Amendment questions). But you want to know how you could legislate filtering for smaller sites without raising those questions? Labeling requirements.
----
> I pointed out elsewhere that routers can block common VPN protocols (e.g. ipsec or wireguard). Of course they can do almost nothing to block something going over TLS:443
From https://news.ycombinator.com/item?id=39957264
> "But what about sites outside of US jurisdiction (e.g. Russia)?" Require ISPs to have a setting for customers to opt into blocking them.
Well tbf, Russian sites famously never use TLS ever ;)
Look, routers do block websites all the time, including encrypted ones. Sites can be blocked via IP, but the more direct way is to block using DNS. TLS doesn't stop 1.1.1.3 from working, and even once ECH comes in, any device that is capable of supporting ECH is also going to support setting custom DNS servers, including a local resolver managed by a router.
But maybe you don't want to use a router, fine. Maybe DNS is too hacky for you. That doesn't mean that iOS and Android devices can't also implement this kind of blocking.
----
> And the laws here seem to all ban retention, which is good. Perhaps they could have higher penalties, but they do ban it.
See above, this is false. I covered this already.
> It's not clear to me how governments would get any records to retain, but sure they should disallow it.
But they don't disallow it, do they? :) I'd like a lot of things in a theoretical version of the legislation, but unfortunately we're talking about the legislation that exists -- and the legislation that exists does not appear to bar indexing of consumer internet habits by the government (or by private businesses).
> Generally e-commerce sites don't have retention regulations.
Any site that accepts payments has defacto retention regulations, at the very least for taxes -- in practice at least. Given how ambiguous most of these laws are about enforcement and what "reasonable" means, there is a heavy incentive for sites to retain at least some user metadata even if they can't retain actual ID documents.
Also bear in mind that 3rd-party verification necessarily requires the collection and retention of information about every single person who can be verified through that service. Whether they retain the specific documents submitted or not, this is still an expansion of user surveillance -- and of course, the laws do not clearly ban collection of metadata and identifying information about user requests outside of the ID information itself -- at least, I don't think the laws couldn't be argued in a court not to cover that information.
----
> I don't really understand your point about "transactional" relationships.
Not all porn is part of a transaction at all. Porn isn't always something you buy, it's not like alcohol. It's not a purely commercial product, it's not always tied to accounts, it's not always a thing you buy or order. And forcing it into that category would hamper a lot of speech -- because porn is intrinsically tied up alongside political and social speech. Particularly where user content is concerned, porn can be extremely political, and the history of porn/decency laws in the US demonstrates that concept over and over again. Porn can not be reduced to a singular transaction in the vein of buying a beer -- not just because it may not involve an exchange of money but also because porn is speech, it is communicative, it is a thing that happens alongside and inside protected communication. Buying a beer is not like that.
Where the Internet is concerned it is actually a good thing that people can read Reddit and Twitter anonymously without making accounts and logging in. We don't want an Internet where every single site is a walled garden that requires a user account. It is a good thing that people can set up Mastodon servers that openly federate -- something that would be practically impossible if they required ID verification in order for anyone to view posts on the service. And again, it's not as simple as saying "well, but we'd only require it for porn." If you're requiring it for porn, you are requiring it for protected political speech. The implications are the same.
What people don't really acknowledge when talking about porn is that things can be inappropriate and harmful to children and also protected political and social speech that should not be restrained between adults. It cannot be reduced to a purely transactional "I would like to buy a smutty magazine" framework.
> Or a Redbox that took cash and rented adult movies with no checks.
As a sidenote, I strongly suspect that a Redbox that took cash and rented out R-rated movies would be legal in nearly every state. Did you know that it's not illegal for a parent to take a child to an R-rated movie, even one that contains sexual content? I wouldn't advise doing so, children shouldn't watch R-rated movies, that kind of content can be very harmful to them. But nobody will arrest you for it.
Did you know that compliance with movie ratings isn't legally mandated? Movie theaters actually have no legal obligation to keep children out of R-rated movies (and certainly no requirement to ask for IDs) -- the whole thing is a completely voluntary standard. Just a fun fact.
But to your broader question:
> Why is it different online?
Because mediums affect security risks and liabilities. Because it's online. Because asking for an ID to be uploaded before you look at a Reddit post has bigger security and privacy implications and as a result bigger speech implications than asking for an ID before you physically buy a beer from a liquor store. Because they're not the same thing.
There's a lot of stuff we do online that we don't do in physical spaces. In physical spaces I don't need to encrypt every single message I hand to someone else. On the Internet, we use TLS. Because mediums affect things. They always have affected things and they always will. And this is not new, newer mediums have been affecting how we write laws and regulate communication since the founding of this country.
----
We cycle back around to my previous point: you can think these laws are reasonable, it's a free country, you can think whatever you want. My problem is not whether or not you think the laws are reasonable, my problem is that you're spreading misinformation when talking about the laws.
I'm still waiting for an explanation of why you said that porn companies have done "absolutely nothing" and had proposed no standards when you apparently knew that was straight-up false and that porn companies had in fact proposed standards and advocated for them.
You're allowed to think that online IDs are no big deal; just don't say things that are provably untrue, that's all I'm asking.