The real world analog would be if you could buy beer at the store with anyone's ID because they didn't make any effort to reasonably check that the ID was yours or discourage people from sharing or copying IDs.
The systems enforce identity checking because that's the only way age verification can be done without having some reason to discourage or detect credential sharing.
The retort that follows is always "Well it's not perfect. Nothing is perfect." The trap is convincing ourselves that a severely imperfect system would be accepted. What would really happen is that it would be the trojan horse to get everyone on board with age verification, then the laws would be changed to make them more strict.
I’m sure there wouldn’t be a brisk illicit trade in these tokens either. Certainly no one would be incentivized to sell these tokens to teenagers for easy profit.
The two methods that seem feasible are making it hard to copy (putting it in the secure element in your phone, for example, which I don't love) or doing tokens that can only be used a limited number of times per day, like in : https://eprint.iacr.org/2006/454
Finally, a way to use blockchain for good.
Let's say Facebook has verified my age somehow. I could share my Facebook login credentials, or the token that their authorization server sends back in response. You can create some hurdles to doing that, like requiring a second factor, but I can just share that too.
You might as well go down the route of accepting that possibility. These systems are never going to hold up in the face of a determined enough teenager.
I think a lot of age verification systems are the solution to the real core of legislation - to make companies liable for underage viewing of content. To put such legislation in place without providing a feasible way to accomplish age verification would be argued as discriminatory.
In that sense, a zero knowledge system which doesn't give a company non-repudiation so that they can defend themselves in court may very well be insufficient. And that will require tracking identity long-term, although it could be done with a third-party auditor under break-the-glass situations with proper transparency.
Even if you could anonymously verify age to issue a “confirmed adult” credential, the whole chain of trust breaks down if one bad actor shares their anonymous credential and suddenly everyone is verifiably an adult.
The solution to that attack is naturally to have some kind of system for sites to report obviously-shared credentials. Which means tracking.
This isn’t even getting to the issue that mandating government-issued credentials is the “foot in the door”. If you mandate the use of government creds for accessing websites, it’s an obvious step to turn around and demand that sites report credential use to “fight credential fraud”.
It's addressing a real problem in a bad way.
Or perhaps protecting kids isn’t really ageism at all.
Calling it ageism is an emotional appeal, not a principled stance.
In the US at least there’s also no such thing legally as age discrimination against minors so far as I’m aware.
Edit:
Let me frame this differently. “Ageism” is basically by definition bad, so applying the term “ageism” to a restriction is a an attempt to label the restriction bad without establishing that on its own merits.
If you try to provide a consistent definition of “ageism” that applies to restricting access to the internet but not restricting access to alcohol, you will most certainly have to resort to phrases like “reasonable restrictions” (if not, I’m very interested in your definition), which means that there’s still a need to establish what is reasonable. Applying the label “ageism” without establishing reasonableness is then a circular argument.
In effect you are saying “that’s bad!” without accepting the burden of establishing why it’s bad, but hiding this behind a different term that carries more emotional weight. It’s a very politically effective strategy but it’s not logically sound.
* actually jMyles
We can argue the merits of restricting children’s access to the internet, or certain books, or alcohol, or pornography, or whatever else. We can debate the merits of those various restrictions based on the benefits and costs to both the children and society at large.
But it is not ageism to attempt to protect children. It is not ageism even of the restriction is a bad idea. To claim it is ageism is an emotional appeal (“ageism bad!”), not a logical one.
I don’t know how you can seriously come here and accuse me of engaging in bad faith when I’ve taken the time to make my viewpoint explicit multiple times in this thread now, including directly to you.
Just because I had a hard time following your logic doesn’t mean I didn’t engage in good faith. You also seem to be arguing in a heated way with every person who responds to you.
Either way it’s probably best if we both move on
I don’t think I responded to anyone in a heated manner, though I will readily admit to being annoyed when you accused me of bad faith.
Agree we should move on.
The burden is still to demonstrate that a restriction is wrong. If that can’t be demonstrated, then labeling it ageism is a purely emotional appeal.
Yeah its extremely simple. You provide a simple message asking the user if they are an adult, and they either click "yes" or "no". That method requires exchanging zero personal information with anyone, other than a simple boolean value to the site/service you are using.
Any other system requires letting a third party violate your privacy.
The app also requires that you first send your personal information to a closed source backend, in exchange for easily trackable tokens used as "proof".
Do you have a link where I could read more about this? GrapheneOS is known for being the alternative Android where many bank apps in the EU still work, and this is the first I have heard that the age verification app definitely wouldn’t run on GrapheneOS.
Of course the EU solution isn't perfect and there are bypasses (there will always be and have always been), but let's appreciate it that way rather than too many PII, if it must come. I'd prefer the Age/RTA header and parental responsibility too.