can these banks/brokers get hacked?
I'd love to see a way for people to revoke/replace their personal info, kinda like rotating passwords or changing their names - but for street address, birthday, government ID numbers, etc.
Penalties (of any scale) are insufficient to ensure absolute security.
They're brokering the negotiation, they're not actually the identity provider. The broker has no knowledge of your actual identity. So in this case, the identity provider (such as your bank) knows that you've been referred by the broker and that you wish to provide your verified age and only that age. The social media company knows that you've chosen to use the specific broker to verify your age, but not who the actual identity provider is. The broker knows that a request with your metadata (IP addr, HTTP headers, etc.) has been initiated between a specific social media site and a specific identity provider, but they don't have access to your actual identity.
Nobody in the negotiation has a complete picture. To correlate it all together, you would need logs from all 3. And at least in the Australian case, due to our data retention laws, if you've got logs from the social media provider, then you can already associate the user with a specific identity by requesting the information from the ISP which they legally must retain for 2 years, so it's really not necessary.
All this concern about social media privacy is a little ridiculous IMO. If you're using social media then you've already compromised your identity. If somebody wants to find out who you are, they already can. They don't need a verified identity, and social media companies seem to me more than willing to cooperate with governments. Law enforcement has been using this type of correlating data for years to establish identity in CSAM investigations.
without a meaningful headcount of real users, advertisers will begin to push back on cost or even reduce and eliminate spending on social media altogether.
by proactively identifying real humans, you prevent the collapse of major social media outlets. by tracking their age and location directly, you restore that which AI took away from advertisers in the first place.
age verification makes sure surveillance capitalism continues to function.
Besides, major social media platforms can just generate ”verified” profiles to fit a demographic. There is no way for advertisers to verify the audiences are genuine. Even CTR is meaningless unless conversion is tracked. This means Meta et al. will soon be actually buying/scalping advertised products and offloading them onto a secondary market.
No shady agenda about killing public discourse is necessary if you view the push for identify verification in that light. (That doesn't mean it won't kill public discourse, but that's an unintended consequence.)
Is is an excuse for some, sure. But we will fail at pushing back if we ignore that there are a meaningful number of concerned parents who support solutions like this because they have become aware of the danger that social media presents. For many of them, self-attestation of age at the OS account level is likely sufficient, not to mention much simpler to implement and use.
But others are working hard to shift the narrative away from age attestation towards age verification or even identity verification. Government officials (on both the right and left) want to be able to police speech based on what is acceptable to those who are currently in power. Companies want to verify humans for advertising and training purposes. And some privacy advocates intentionally conflate age attestation (like California AB 1043) with age verification because it is an easier strawman to attack.