Pornhub prepares to block five more states rather than check IDs
arstechnica.com
arstechnica.com
* They don't want the work to do the verification to be their problem, and to be legally responsible when (not if) it goes wrong.
* They know that age restricted devices are few and far between, so this is just an effort to kick the can down the road another decade.
* Even if all new devices support age restrictions, there will be a myriad of legacy devices that will continue to have access.
* They know people in the affected states will just use a VPN to another state anyway. If all the US eventually adopts these laws, they'll block the site entirely from the US and secretly fund and post informational videos on how to use VPNs to get around the restrictions.
* By blocking the states, they get more publicity for themselves, but also potentially anger a group of people into arguing their cause.
One thing that I think is interesting is that they are placing a lot of trust on reliable state-level geo-IP. They're only a few bad DB records or a BGP failure that routes people from these states to other servers away from a potentially costly fine. But maybe given the benefits above, this is just another cost of doing business for them.
Trust that could be contractually guaranteed, no? “We believe in our database so much that we’ll pay the fine if we’re wrong.”
> They don't want the work to do the verification to be their problem, and to be legally responsible when (not if) it goes wrong.
That's literally caring about PII. Quite a bit more than the state legislative sponsors of and "think of the children" advocates for these laws, too.
In fact, I'd hazard a guess that the only reason they have the ability to block users from certain states is because they already had that information as it made their data more valuable to advertisers. They're probably already sharing information down to the city or district level with advertisers.
Of course, I don't really think the politicians give much of a shit about porn. They just want the mechanisms in place to monitor everyone's activities online, and porn is the easiest place to start. Then it will expand to everything else.
(And I agree that seeing either is bad for children, I just don't think requiring age verification actually helps in anyway.)
Seems like the real motive here is deanonymization.
Back to pornhub. There is no way to verify age, have security and anonymity at the same time on the internet. What would be stopping a "rum runner" from sharing his ID with a friend ?
I think this is the main reason pornhub is blocking these states. They know it is really impossible to comply with the laws. They also know their customers want both security and anonymity. Once that trust is breached, customers will leave. For a good example there was that "affair" site a few years ago that had a breach and I think ended up folding.
Can you share how exactly 'caught' and in how much 'many cases'?
I'm exceptionally skeptical this works for any settlement bigger than a 1000 people.
On the client: The typical parental controls situation with a blocklist. Responsible adult sites could send an HTTP header like X-Adult-Content or something to ensure they would be blocked by clients with the controls on. This could be enforced by regulation, with devices for children required to respect that header in addition to shipping with a blocklist. This couldn't be bypassed with something like a VPN (which you probably couldn't install with parental controls on anyway), because it would be baked into the client.
In the network: Similar blocklist style situation - this already exists to a certain extent in some countries. Mobile phone providers and ISPs would be required to block adult content (via dns or similar) by default, with a toggle to switch it off available to the adult account owner. We already block illegal content this way.
On the server side: This requires adult websites to be cooperative, which they will only be if they care about the jurisdiction in question. This potentially pushes kids/others to access sketchier sites which wouldn't be blocked.
I am strongly for pushing this down the stack to the client. I don't have kids, but I'm pretty sure iOS and Android as well as MacOS and Windows all have robust parental control systems. I'm sure people use them, and we can safely encourage people to use them more. If they aren't on by default already for children, they could be.
Short of biometric verification with presence detection I don't see how it's possible to do remote age verification in a good enough way that you couldn't just use an adult's credit card or device to bypass it.
Anyone who knows anything about tech knows this is just a wedge issue, and people aren't interested in solutions to the actual problem of kids accessing inappropriate material, only soundbites.
After having more progressive abortion and trans care laws than Europe (where parties like the "Christian Democrats" in Germany rule), how exactly?
The Republicans want to performatively participate in their moral panic by asking for (stupid) age verification; meanwhile, the Democrats control tech and media, AI stonecolds prompts with "Trump" as "dangerous content", they want to ban everything off the Internet they don't like, and would oppress free speech with Canada's new hate speech laws if they could.
So the law equally prohibits distribution of guns and pornography to children.
Apple is what it is today, might not be the same Apple tomorrow.
We need only look at... (checks notes) every other profit driven company (thats all of them) to see how this will go when quarterly earnings are flat and/or falling
Suppose I want to start a business where I don’t want the liability of having to deal with all the laws about minors. Then I can use the government API to only allow people over whatever age.
That is not a reason for the government to not do something. We entrust them with nuclear weapons and aircraft carriers. Not to mention Snowden already proved the government has back doors into all the big tech companies, so it’s already not a secret who is visiting what website. And FISA courts and secret warrants under gag order and blah blah.
It’s just inconvenient for everyone.
As for it being centralised, I'm all for web-of-trust but I thought we'd pretty much given up on that?
I'm not aware of any large scale user implementations of the protocol though (people have been getting compatible ID cards for years, but I don't know any software that uses them outside of probably cigarette vending machines in Spain). Do you know any?
I don't know if that's what you're talking about but, in Belgium for example, to fill taxes online and to do various other types of pointless administratrivia you must use your EID card, which you put in an EID card reader (typically connected by USB).
Now the EU-wide biometrics, a sheer horror (the EU court of justice ruled that the biometrics data can be used for other uses and stored in databases outside the card... although at first it was supposed to be private), isn't implemented all around the EU yet.
My EID car was emitted in 2016 and is valid until 2026 and definitely doesn't have any biometrics data in it. I don't know if the system shall already be put in place in 2026 when I'll have to renew it for another ten years.
My point being: biometrics and NFC are probably not present on a lot of EU citizens' ID cards... Yet. So, atm, it probably doesn't make much economical sense to support that system for random usecases like selling cigarettes or alcohol.
Filing my taxes is the only thing I use my EID for.
Then there are some EU countries using their own "2FA" authentication system for anything "government related" (taxes, car registration, company filings, banks login, social security, etc.), complete with physical devices, phone apps, webapps, etc. which aren't using the EU EID at all. Basically: an entire ID system, using 2FA, but bypassing the EID entirely.
I'd say overall it's still pretty much the wild west.
The standard is ICAO 8303 for how the data structures work. It's the same as ePassports. EU cards implement EAC for the fingerprints, which has a whole mutual auth PKI system.
The problem will probably be adoption by services. It's a lot more tempting to get more information than just age, if you go through the hassle in the first place.
Wouldn’t it be nice if we knew we were interacting with a real person and not a chat bot?
Expanding on this… we should all be jealous of Estonia’s digital governmental infrastructure!
For PornHub that also gives other companies, the OpenID providers, the power to censor PornHub but refusing to verify age or identity.
I don't really want GitHub knowing everything I sign into, but in some cases like Tailscale my only option is to tell GitHub about it or not use Tailscale.
It would still have many of the same flaws as OpenID, but at least you accessing a site wouldnt notify the authority.
Maybe " verifiable credentials" is the keyword I was missing. Thanks!
A zero-trust protocol or computer system is all well and good, for some uses at least. A zero-trust society will not work. Or at least it will be significantly worse than societies with trust.
zk proofs could be used to solve this problem.
- Govt runs a zk-prove-ident service
- User goes to PH and starts verification process
- PH does proof with Govt, this could be anonymous
Ideally the user's keys are part of their ID, if you lose your ID, you can get a new one. It's still a permissioned system, so no miners/stakers needed, we can make it possible to change/replace keys behind the scenes so the UX for the common people does not amount to "lose your keys, lose your money"
Even if every state started putting contactless chips into drivers licenses to provide anonymous age attestation, you'd still have the problem a kid can just use a parent's or older sibling's card.
And even if such cards did exist and they were considered legally adequate, you've still got the problem that nothing except smartphones can read them. And you've got the problem browsers don't support them, and app stores don't welcome porn-viewing apps.
Of course, this is all intentional - the religious anti-pornography groups that push for these laws consider it a good thing that complying with the law is essentially impossible. They want a full ban on pornography, but that would get struck down as unconstitutional, so they have to get a ban by indirect means.
1. Introduce a X-PEGI HTTP header that sites can use to change the content. This would also be useful for other contexts such as cybercafes and whatnot.
2. Mandate that porn website abide by these headers.
3. Have responsible parents, lock their children's computers and add the appropriate header.
The adults then have access to the adult internet with no extra restrictions.
There's yer problem right there.
This comes up every time, but the purpose of the identity check is to ascertain (to the extent possible) that the person logging in is the person whose age you’re verifying.
If you completely separate identity from age checking using some cryptographic method, the loophole is that a single identity token with an adult age can now be used by everyone, everywhere to tell websites that they are above a certain age. So as soon as you did that, someone would just share (or steal) a token of valid age and post it online for everyone to use. Entire system subverted.
You could try to use a 3rd-party service that handles age check functions and implements some level of rate limiting to prevent this, but then you’re trusting that party to know about all of the porn websites and other places the person is trying to log in to. If that 3rd party is the government, well you’ve just created a convenient place for the government to collect stats about people logging in to porn websites.
There a two counter techniques used to address that problem. Tokens can get time limited down to a number of seconds (10-30?), and a single token is only valid for one session at a given website (assuming the website honor those restriction on their side).
In addition, token providers may rate limit how many tokens a person may generate, and the application that request tokens may require a bit of work from the user (like typing a pin). Any person who need to do more age verification could be required to contact customer support to unlock such features, which also mean the provider can keep a closer eye on accounts that generate tokens in strange or abnormal patterns. Depending on how the market for identity providers are, different providers may provide different service and different levels of authentication.
In Sweden currently we are in a situation where there are multiple competing identify providers. They have to follow a certain certification, but the exact details of the technology varies a lot. There is a bit of talk to make those an open standard, including defining exactly what information the provider and the recipient should get. There is also the hope that the user application could be made generic, so switching/choosing provider becomes easy.
The problem with the technology in term of privacy is not so much in the protocols or cryptographic methods, but rather a social one. You can not create an fair identification system if all it does is ID control for porn sites, just as one can not create a VPN if all it can access is porn sites.
So yes, you could steal the private key I guess. But that is no worse than if you have to prove your identity; someone could get your password to your account.
It's literally impossible.
You can either have a zero knowledge system where the tokens are immediately compromised and widely shared that provides no authentication whatsoever, or you can have a system that has the ability to revoke compromised tokens that is not zero knowledge.
Or as we are likely to get, you can have a system that is both easily compromised and does not have zero knowledge, and the age verification industry is simply engaged in industrial scale lying to try and get themselves written into law...
If one site can require FaceID (or any sort of attestation) then either some, all, or arbitrary sites can require the same.
I'm in the same boat... banking would be nice to support "non-anonymously", but why are they chasing against porn sites vs finance sites?
It's such a slippery slope imagining requiring "age verification" for dating sites/apps, then same-same for access to email, then it's only going to be news sites that don't require age verification.
(Whoops! Except NYT, WaPo, and the rest all have paywalls, and there's Fox ~News~ propaganda waiting in the wings to be "free, but needs your identity")
Slippery slippery slopes here, and it must be intentional.
They view pornography as a purely or at least sufficiently negative presence, justifying going after it. Legislating to withhold it from children is more straightforward and politically palatable than an outright ban. The deanonymization of the internet is probably an acceptable risk more than a desired outcome.
I assume it's the same mindset as people who end free speech to crusade against hate speech.
Don't assume that just because Pornhub doesn't include scat, drugged, zoophilic, voyeur, nonconsentual, and other more frowned upon content that it isn't still entirely available if you're foolish enough to let your kid on the Internet without monitoring.
Because this is not like ID’ing for cigarettes and alcohol.
Largely speaking, people do not want there highly personal, sensitive activity and preferences to be attached to their identity and maintained by some entity that either may get hacked or may use it in any number of nefarious ways.
Once again, porn may be on the forefront of pushing technology (VPNs) mainstream. I’m (Much more nuanced takes in the article. Ars is one of my favorite publications for this reason)