"The insistence on perfect age verification requires ending anonymity. Age verification to the level of buying cigarettes or booze does not. Flash a driver's license at a liquor store to buy a single-use token, good for one year, and access your favorite social media trash. Anonymity is maintained, and most kids are locked out. In the same way that kids occasionally obtain cigs or beer despite safeguards, sometimes they may get their hands on a code. Prosecute anyone who knowingly sells or gives one to a minor."
Grocery stores already sell age restricted items as well as gift cards that require activation. The state could issue "age check cards" that you could purchase for some nominal fee. That would require approximately zero additional infrastructure in most of the industrialized world. The efficacy would presumably be equivalent to that for alcohol and tobacco.
Consider a somewhat extreme example. A preprinted paper ticket with nothing more than a serial number on it. The clerk only visually inspects the ID document then enters the serial number into a web portal and hands it to you. When you go to "redeem" it the service relays the number back to the government server rather than your local device doing so directly. That would be far more privacy preserving than the vast majority of present day clearnet activity.
Yeah, it runs into the same socioeconomic problems. Not just voter ID but also tobacco, alcohol, most weapons, and in many places other than the US medical care just to name a few. So it's already a well established problem that people keep and eye out for and at least try to address.
Consider that the alternatives are the continued normalized unfettered access of brainrot by young children or else requiring an ID check in a manner that blatantly compromises privacy. On the whole the liquor store approach seems like a good solution to me.
To be fair there is another alternative that for some reason seems widely unpopular. Make headers indicating age restricted content a requirement and legally require the OEM configuration of devices to support parental controls based on such headers. That would be a slightly less efficacious solution but would involve noticeably less ID checking.
Also usually once you turn a certain age they stop asking you for ID. Again, I'm not aware of how things work in place where they customarily scan and store your ID for alcohol purchases. I would lobby my legislators and fight this odious practice tooth and nail. The store is almost certainly selling that information.
No absolutely not. There's no need for it. We don't require Internet connected beer cans to phone home to a government server and recheck your driver's license when you're cracking them open.
> When you go to "redeem" it the service relays the number back to the government server rather than your local device doing so directly
Your possession of the token when you enter it into your social media account is proof enough that you're of age. The social media website only needs to call the token issuer's API to verify its validity. And all the token issuer should know is it's a valid token sold to a buyer of legal age. Anything more is needlessly complicated and risks anonymity. No recording of IDs in any way, shape or form whatsoever.
And there's no need to involve the government or government servers in any of the implementation or technology. It can be an open, published standard. Any company that can get their cards in stores, and sold with age verification, should be able to participate. All participants can be periodically inspected by the government to ensure compliance with standards.
As to the rest of what you wrote, isn't that exactly what I already described? The only notable difference is that your scheme permits non-government token providers.
> The clerk only visually inspects the ID document then enters the serial number
I thought "the serial number" was the number on the ID document. You actually meant the number on the token scratch card. Makes sense.
> The only notable difference is that your scheme permits non-government token providers.
Right. More accurately it only permits non-government token providers.
And I don't know how things work in other places, but I've never had my ID scanned when buying alcohol. These days clerks don't even ask me for ID because I obviously appear to be legal age.
In my proposal the token would be a scratch off card with a unique code. It can't be associated with the transaction.
Also after I had a certain number of birthdays, clerks have stopped demanding my ID. So my purchases are pretty much anonymous.
The card should be issued by a private company, or ideally, multiple companies. And it should be a scratch-off card with a unique code, so that codes can't be tied to transactions.
EDIT: Because age verification tokens will likely be a commodity, low-margin business with little differentiation. So I assume companies will do stuff to make their token more attractive than the competition.
If a bot that sends a fixed set of headers and is behind a single static IP is behaving poorly and slowing down your server you can block it and move on. Whereas when an abhorrently selfish operator with a client that actively hinders fingerprinting rapidly rotates through hundreds of thousands of IPs you end up with mass adoption of solutions like Anubis.
> It comes from so many sources you can't block them,
Nonsense. If it were really countless fixed sources then a centralized domain blacklist would be sufficient. The issue is that the sources - both domain and IP - are aggressively rotated and even spoofed whenever possible.