This approach assumes that the smartphone in question is not under the user’s control. That should generally not be the case. When I buy a device, I have the right to install whatever I want on it and to make the camera sensors believe whatever I want. If something cannot be implemented securely under these circumstances, it’s not a good idea, and other solutions are needed. I once tested a video identification system for a company that the manufacturer claimed was absolutely secure. All it took was rooting the smartphone and bypassing the root detection. After that, you could play any pre recorded video, which would then be recognized as camera input. Under those conditions, it was easy to manipulate a video so that a company employee would consider it real enough to verify the test subject.
It’s simply not technically possible to verify the authenticity of the camera input with 100% certainty. Pretending that it is possible only creates problems. Then someone fakes evidence, but all the normies who have no clue about technology assume that it must be real. You see this with AI detectors too they recognize random texts as generated, yet an unbelievable number of people believe them.
How do you plan to replace the sensor of your phone's main camera (with a device you need), and let it authenticated by the OS, and then create authenticated photographs with it?
Apple/iOS already have part authentication pipeline on its security sensitive devices (TouchID/FaceID). How can camera sensor can't be considered one of those and needs attestation before enabling?
From the document:
> Apple Reference Image leverages custom-designed image sensors in iPhone 18 Pro and iPhone 18 Pro Max to ensure reliable capture of image data, and relies on Private Cloud Compute, which provides a computational environment for secure photographic processing that cannot be subverted even in the case of device compromise. (emphasis mine)
The approach assumes that most people don’t have the ability to directly attack the image sensor itself. It’s a little buried in the article, but creating reference images involves having the actual image sensor sign the raw data it captures using a key unique to that sensor. The rest of the device can’t tamper with data anymore.
I don’t think there any many people out there with the right equipment to carefully ablate the top of a sensor off, so they can directly inject their own data into the start of signing process. It’s not impossible, but it’s also not the kind of thing most people and organisations are going to be capable of doing.
> The creation of a secure digital negative begins with a secure boot of the camera sensor into a specialized reference capture mode. The mode instructs the sensor to cryptographically sign pixel data immediately after capture, and prevents the sensor firmware from modifying the data.
I believe many of the problems we have, need social and human solutions, especially when the technical solutions are hard or impossible.
Like here, where we can no longer trust images to depict reality and act as proof. While its admirable that people look for technical solutions, the obvious social solution is to admit that images are no longer absolute proof and will become less and less trustworthy¹.
And, by admitting that, change our relation to these artifacts. Sure, that will change journalism, police work, legal systems, etc etc.
But pretending that we can rely on images might allow journalists, police, judges to continue relying on them as if they're authentic, which is a far bigger problem over a longer period.
Social solutions require effort, demand flexibility, take time and are messy. But this is what humans are and do. Not everything has a technical solution. Not every technical solution is the best option.
¹ we already saw this when people claimed "someone must have hacked my iphone and put it there". For decades we've seen this with images that are deliberately taken in a way to spin a story (like the illusion of a large crowd or spacious room through carefull angles or fancy lenses). And I predict we will see this with security footage, "live streams" or even bodycams with "ai enhancement". Just imagine a bodycam or a dashcam that manipulates the output to benefit the owner. "A dashcam that will prove your innocence in assumed traffic violations" or such.
I don't know how this happens to me but i always have trouble with Bottles. And not just the slightly bad UI, but like today, i have an installer that i can run directly with Steam that i cannot get to run in Bottles. When i last used it a couple years ago i did get what i needed working successfully but i remember it being a struggle.
The solution would be simply to add a warning as a temporary measure preferably in red text and in a way that would scare the average user. This warning should be accompanied by a call to action urging users to contact the device manufacturer and ask them to release a new driver. Then companies would have no choice but to either create a new driver that runs in user space or be constantly inundated with support requests from customers.
Unfortunately that doesn't work, when a warning sits between a user and the application they want to run, they will always say yes, and then someone has to clean all those browser toolbars.
I'm fundamentally opposed to age verification because it usually leads to mandatory account creation no matter how privacy friendly the age verification process itself may be. It's already extremely annoying that, for example, on YouTube, you can no longer watch many videos without an account. Furthermore, the whole thing also reinforces monopolies. Once you've verified your age on one platform, the barrier to switching to another is even higher than before.
The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating. Once this were established, websites targeting all age groups would have a strong incentive to participate. Otherwise, they would suddenly become invisible to a large portion of their underage users.
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
That just entertains the false justification for what is ultimately about surveillance and control. There are privacy preserving alternatives to accounts and ID/face scans but no one in power is interested in them because the loss of privacy is the entire point.
What might those be? Everything I've seen is ineffective or can be compromised. I think letting parents parent is probably the best option, but will require better/easier/free tools and education to help lock down different categories of harm.
1) When buying a device, store employee could program user's age range.
2) When configuring a device, parent may toggle "child mode" checkbox to switch the device into "child mode", protected with a password or fingerprint.
3) The tokens, containing a private key (same for all tokens) can be sold in liquor stores to adults only. This token could confirm the age without a passport.
It is interesting that is US (unless I am wrong) you can vote and change the government without a selfie and a passport, but you need them to use Reddit or Discord.
> but will require better/easier/free tools and education to help lock down different categories of harm.
There should be a single big "child mode" checkbox for normal people and "configure" button for 1% of geeks. Most people do not need tools and have no interest in configuring allowed categories.
> Everything I've seen is ineffective or can be compromised
Selfie/passport also can be compromised by asking a friend/older brother/parents to verify your account. Especially if you have a poor adult friend with alcoholic dependency in dire need of a new portion.
> When buying a device, store employee could program user's age range.
Big Brother would like to hire you. This is the kind of idea I only expect to hear from a politician or a grandparent that has difficulty unlocking their iphone.
Number 2 is basically here for many things, but not as easy as a single checkbox. Number 3 is something I've thought about, but it seems that's never seriously discussed in politics.
There should be a single checkbox (when setting up the phone), and "configure" button hidden deep in the settings for the minority. Most people do not like complicated UIs and unnecessary work.
There's nothing that can't be worked around or compromised in some way. Even the face scans and ID scans being used today are being circumvented.
In the end we do need parents to parent, but websites should help. The easiest way would be for websites to send an HTTP header to the client so that censorware can know to block or allow it accordingly.
I assumed that when he asked "What might those be?" he was talking about privacy preserving ways to address that same false justification. I'm not sure how you took it some other way.
They didn't say OP's proposal wasn't privacy-preserving, but that preservation of personal privacy is contrary to the actual reason that age checks are being pushed by politicians.
The header must confirm that site is age-appropriate. No header should be interpreted as "adults only". This is the safest option, and it doesn't require 99% of webmasters to do anything which is in my opinion better than any other proposal.
Exactly. That's the problem I have with the "restricted to adults" header. Ideally the header wouldn't have a "safe for kids" value either because what one parents feels is safe will be very different from what another parent would find appropriate. I think The Internet Content Rating Association had the right idea were the header would show if a site contained specific types of content or not and it was up to parents to decide how much to censor.
Website generates a random nounce, the government offers to sign the json { over_18: true, nounce: [inserted_here] }. That signing is coupled to you being signed in, or scanning your passport via nfc or whatever
That significantly reduces the leaked information: the service doesn't receive any information who you are, and the government doesn't know what service you use. They can collude, but that does not reveal more to them than most current age-verification methods. Children can get another adult to sign their request, but that's a working attack on nearly any age verification (including in-person purchases)
Correct observations. But have you wondered why those solutions are ineffective?
Kids nowadays use phones and tablets for the most part. They don't even know how to use a computer that well and are not taught properly. But this isn't really on the kids.
Now, suppose I'm an OS developer. I cannot simply fork Android or iOS to create a child-friendly toy operating system for smartphones with a reduced set of features. The hardware is locked down to oblivion. They want you to use their OS. And their OS has no user accounts, permissions, or firewall configs.
Well, then suppose I'm an app developer, and I want to make a browser or social app with built-in client-side content filtering. But my browser doesn't pass Cloudflare or whatever attestation, and is blocked from half of the sites. It might not even be approved on their app store so people will never find it.
Fine. Then I want to change what content is filtered within the approved apps. But those options either don't exist or is some kind of cloud service where you give them your age, and they decide what to filter.
=========
Parents can't even control what software runs on their own hardware. How are they supposed to control what runs on their child's hardware?
=========
"The market failed", so they can sell you parenting among other things as a service, with surveillance as a free gift. The tech companies make money while the government gets control over the populace. It's a terrible arrangement.
That is why most digital parenting solutions you've seen are ineffective or can be easily compromised. Tech companies along with the government are playing chess against you at every level of the stack. Don't ever forget the PRISM program exposed by Edward Snowden. Apple, Google, Microsoft, Facebook - they're all complicit. Don't look at what their PR department says, look at what they do:
https://en.wikipedia.org/wiki/Edward_Snowden#Revelations
One possible short-term solution is antitrust legislation for hardware vendors to ship their devices without an OS... is what I would say if we lived in a sunshine and butterflies world. Maybe the EU is not thoroughly captured yet and still has the ability to implement this, but I doubt it. Technoauthoritarians are building a panopticon to contain the sheep, and they're not even hiding it at this point:
The actual long-term solution is difficult. We have to make our own computers and radio equipment before they outlaw mining and manufacturing using the same safety excuses, which will happen when humanoid robots can do those jobs. The entire stack has to be open-source, which means we will have to diffuse fab technology everywhere so that people can manufacture computers locally, from mining to wafers to final assembly, in every city, or even at home. There are very talented people working on this problem, so it will be done. Just don't fall for the narrative that surveillance is inevitable or needed.
If indeed the push for age verification is being done under false pretenses as you suggest, then one should propose solutions that accomplish the stated goals while preserving privacy. Either the solutions will be accepted, or the people advancing false pretenses will be forced to come up with new false pretenses, which will weaken their arguments. Either way is a win.
> then one should propose solutions that accomplish the stated goals while preserving privacy
Solution: sites and apps optionally provide metadata suggesting their content/age-appropriateness, parents locally configure software to look at that metadata (including what to do with things that don't have metadata), or they don't, depending on their parenting style and the maturity of their child. Done. No laws or identification or invasive measures required.
Use of those kinds of headers needs to be voluntary for websites, which means that censorware has to block any site that doesn't return the header, not just those sites where the value of that header indicates adult content. That will encourage websites to support the header or risk being auto-blocked by any censorware in use, but that's a problem for the RTA header since it only indicates adult content.
To me the biggest piece of evidence that these methods don't actually work for age verification and are completely for surveillance and data collection is that you can't use them to buy wine at the self checkout at the grocery store. Like if it's effective, why can't the self checkout camera tell that I'm over 21 and can buy wine? Because it's not and everyone knows it.
And instead of an age you could even make the indication about what is potentially objectionable so that parents can choose when to allow their kids to see what - and adults can also choose to avoid certain things.
I might be being overly cynical here, but I think part of the problem is parents expect to give their kids the internet so they don't have to spend so much time/attention with them.
I think this means any solution which involves active parent participation is going to get shunned by a vocal subset.
I'm in my mid 30's. When I was very young I remember my Dad semi-regularly having to email or even fax off permission slips to websites aimed at kids before they would create an account for me.
> any solution which involves active parent participation is going to get shunned by a vocal subset
Then we certainly shouldn't be passing laws mandating age verification. If parents want to abdicate their responsibility over their children, it's not the role of government to enshrine that abdication into law and take over the duty of parenting from them.
If regulation is to be had, then it should take the form of mandating websites and services provide privacy preserving tools for parents to use, if they want to use them. If they don't, that's on them. Everyone else needn't suffer because a subset of the population has chosen to offload their responsibility into the government and web services.
> I might be being overly cynical here, but I think part of the problem is parents expect to give their kids the internet so they don't have to spend so much time/attention with them.
> I think this means any solution which involves active parent participation is going to get shunned by a vocal subset.
I don't think that's a fair assessment personally, rather you've missed a key detail that things are significantly more complicated than they used to be, it's not just an 'effort' issue. There is no universal "user is age X" setting that applies to everything everywhere, rather everything has a different system and pretty much all of them are terrible in various different ways.
I'm very tech savvy and I still struggled just to set up a Microsoft/XBox account for my daughter so that we could play some computer games together. Access to all the different age rating settings is spread across something like three different apps and websites and in my experience they don't even all work consistently. That experience is also not dissimilar from the experience with other types of accounts. For people I know who are less tech savvy it honestly doesn't matter how much time they put into it, eventually they give up and turn off age ratings because something isn't work and even if there's a solution it would take them hours to figure out.
Point being, if the existing tools were much better I don't think we would be having this kind of conversation.
I don't mean to be confrontational, but the key detail you thought I missed, about it being complicated, was a fairly crucial part of my point that you've overlooked:
My parents when I was young ended up having to figure out how to use digital cameras, scanners, printers, fax machines and then print, sign and sometimes even post off a letter for me to access one website which I wanted, which could take hours of their time in a process that took literally weeks. This was in the early 2000s, when scanners and digital cameras weren't exactly user friendly. They had to do this sometimes multiple times a month. Every website was different, there was no universal permission slip. But they did it. Eventually, they too got bored and gave up, or maybe I just grew out of it.
Point being, the tools have always existed, and always felt inappropriate or convoluted, but my parents at least were happy to do it for their kids 20+ years ago. From what you're telling me, they're now a lot faster and easier to access and use.
Even if the tools were made to take only a few minutes to setup, there would still be a vocal set of parents unintentionally arguing that everyone should suffer with overbearing ID tools so they can spend less time supervising their kids internet usage.
> Point being, the tools have always existed, and always felt inappropriate or convoluted, but my parents at least were happy to do it for their kids 20+ years ago. From what you're telling me, they're now a lot faster and easier to access and use.
No they're not, the systems that exist today often don't even work and there's no alternative of "just mail a letter to Microsoft and they'll sort it out for you".
"Faster" is also a frankly a silly point - it's not like your parents were waiting at the mailbox until the letter came in the mail, the important question is the amount of time actively spent dealing with these things.
It's far quicker/easier/more convenient to sit in front of a screen and try find some buttons. Your issue seems to be that those buttons have got harder to find and understand - that's a fair point.
My point is that - overall - clicking some buttons and waiting a few hours is far more accessible, faster, easier and less disruptive than what my parents had to do 20 years ago:
It required far, far more effort and thinking and action to find some physical, expensive, modern hardware, digitise signatures, and the post things off.
"Faster" is very relevant in a discussion about convenience and effort. The important point is how convenient it is for the child and the adult. Now, a child has to sit for an hour watching you fumble around on a screen. I had to wait for days and days whilst my parents fumbled around with cables and when to the post box and other stuff.
> the amount of time actively spent dealing with these things.
My parents used to have to spend more time actively dealing with me and my things whilst I was waiting for the post.
We're not going to agree here. You're a parent, complaining about how much time you have to spend supervising your kids. I sympathise for you, the modern world has a whole lot more expectations of your time which my parents didn't have. This is one of the many reasons me and my partner chose not to have kids, sorry.
Everything you describe is an argument for not trying to bake age verification in at a lower level - because all of those issues will become everyone’s problem, whether or not they’re parents, except they won’t be able to “turn off age ratings” any more, instead people will be fighting with systems that don’t recognize their ID document upload or whatever.
That, in the end, will hopefully kill these idiotic attempts at dystopia enhancement, because when people discover that “think of the children” makes their day to day life more difficult, it’ll lose support.
It's what I see happening. None of this would be a big deal if parents were present, but we give our attention to work & entertainment, and find it easier to continue doing that if the kids are also being entertained instead of playing, which caused problems in the physical world.
No, you are handling the boring work to someone else. Most non-geek people, I assume, are not interesting in manually configuring the website white lists, so there should be a single "child mode" checkbox for 99% of population and "configure" for the rest of us.
The App/Play stores already basically have that, you can't submit apps without age ratings.
One spot where it's a bit weird is for utility apps that don't have any "mature" content but that obviously isn't intended for kids, so e.g. your tax prep app gets rated as "Ages 4+".
The part I'm most opposed to is requiring a full KYC, using "verifying age" as an excuse. My Gmail account has been active for >18 years, that should be enough proof.
It won’t because KYC is a legal process and you don’t want to prophets that across the entire system with bypasses for it. That’s legal trouble waiting to happen.
Yes, Google also wants to tie back to legal identities to sell ads. I’m not saying they’re doing this in good faith, but proxies like this get messy and dangerous for legal/compliance.
At glance this looks reasonable but how do you enforce that kids connection always goes through the parents control?
You are just moving the verification point to another gate, it means that no anonymous connections are possible anymore to the entire Internet because we want to allow parents to control their kids.
You want to use your friends Wi-Fi? Now that requires full identification so that we know that its not some kid trying to look at stuff their parents don't allow.
Want to connect your cat toilet to the internet? Well, we will need to either cryptographically identify the device or attach its ID to your real ID because we don't want to allow kids look at stuff their parents did not allow and this might just be a proxy device for some nerdy 14 y/o.
Want to use your old PC? Sorry that's not possible, now all devices that connect to the internet require biometric identification because we can't tell if this is an adult or just some kid using a legacy device to look at stuff their parents don't allow.
The answer is quite simple. You just don't verify it. The point isn’t to verify the age but to set the age on the device itself. If the parents set the age on the cell phone or computer, that setting is then used as the basis. The operating systems can be configured so that only the device administrator can change the age. Systemd already has a field for storing the age, which programs can read. If the child doesn’t know the root password for the laptop, they can’t change the age. If they do manage to get around that, well, so be it. The solution doesn’t have to be perfect because it would still be an improvement over the current situation without restricting adults in any way.
I have personally used the parental controls on Android, iOS and ChromeOS and to be honest they are terrible. Issues with syncing changes, the terrible UX for parental access control (iOS...), issues around audit/access logs, issues around prompting the parent for access.
I am honestly shocked that Apple known for its polished experience hasn't been forced by angry parents.
My daughter's school actually advised parents to not enable parental controls on her ChromeBook because it would interfere with the school's education websites but my daughter was caught playing web games in class so we decided to lock her down anyways.
> my daughter was caught playing web games in class
Hilarious to me. The biggest game of whack-a-mole ever. I would love to know if this lockdown was successful (and if so, how it worked).
In my city, there is a district that is so “locked down” that the images from Wikipedia don’t even load. But guess what? Kids still find ways to play games.
Of course, that whack-a-mole is an intrinsic part youth and adolescence too. I think back to my mostly analogue school days. We found ways to disobey and amuse ourselves in the classroom.
Imagine pusing for locked down paper so kids can't pass notes nor make spit-wads and airplanes. Or locked down pens to prevent tic-tac-toe, doodling, lewd drawings, or scrawling graffiti on those old desks.
Some kind of KYC rules so that the older kids at school cannot pass their broader understanding of the world and cussing vocabulary down to the impressionable younger kids. Age restrictions on the trail to the woods, where kids somehow always knew about that stash of dirty magazines...
I liken this process to a losing game played by authoritarians all over, normalizing a game of "subvert the man" I see the battle fought over sex, drugs, piracy, probably many other topics. Take drugs (for example) "drugs are bad m'kay" but then there are mind expanding opportunities tucked in there as well, yes most have some risk or delayed consequences associated but the lack of nuance (hard to impart on young minds granted) leads to the drugs are bad talk from someone authoritive, and those that dabble bring amazing tales that refute the earlier information that drugs are bad, and survivorship bias and a "new way the authorities were wrong" takes over and undermines the good intentions of those that see the negative impact drugs can bring. Chances are kids seeking a less locked down experience may dabble in much darker places on the net and it may be that this new "KYC" push actually widens that devide instead of protecting the children (which is merely the story used to push for this enhanced customer identity goldmine.)
This is definitely Google's fault. Google allows kids to make webpages at sites.google.com where they embed web games. And because teachers also host content on the same domain, IT will never block the entire domain. They might block a specific URL, but then the kids just spin up a new google site. It's only whack-a-mole because Google allows it.
This could be stopped instantly if student accounts had no write access to new pages at sites.google.com. It isn't worth the distractions nationwide. If it's an absolute must for a class somewhere, then provide teachers with an easy tool to whitelist their class for it.
Would some kids still find ways around that? Of course! And more power to the kids who figure it out. But right now it's too easy for kids to flood game content to their Chromebook peers.
They need to be using deep packet inspection to get reliable and useful blocks.
If you cannot install their self-signed cert on your device (i.e non-managed device) then you likely aren't being MitM and thus, restrictions are hard.
Parental controls on devices are not hard because they are intrinsically hard. The companies just do not care about them, because nobody has forced them to be implemented sensibly. There is absolutely zero reason an Android device could not have a shiny button saying "Kid's device" when you set it up and never need configuring again. So this is not a criticism of the approach, and only a criticism of the companies.
Cross-platform support is very poor (iOS/Android/Windows/Mac)if ur trying to use family link. After trying to make FL work for weeks, i moved to another service that has morel granular features than FL and detailed activity reports with web filtering rules but its paid but it atleast works instead of those unusable knobs on FL.
I do feel that if there were actually decent parental controls on the most used systems out there then we might not have got to this point in the first place! It is either a nightmare or impossible to set any sort of sensible controls on internet and social media access for children and teenagers.
Probably parental control do not bring any profit (they actually add responsibilities, like restriction on ads, collection of data) so the large companies sabotage them by making them too complicated or broken?
Sounds like a technical issue that is not better solved by remote devices doing age verification, but instead by fixing the already existing implementation.
No, the point was that the actual decision happens client side and under the control of the sysadmin (the parent).
> You are just moving the verification point to another gate
Yeah, the gate being the decision of legal entities of age, aka. adults.
> You want to use your friends, Wi-Fi?
That would still do whatever your parent decided for you.
> Want to connect your can toilet to the internet?
Whether the toilet can connect to the network, is the decision of the network administrator, and toilets don't contain UAs, so that wouldn't even have software on them, where you could configure such behaviour.
They are also User Agents, in that they interface with the user, process input from them, and pass it to the network. But that network isn't based on electricity and does not primarily transmit information, so it is not the kind of UA to a network, we want to introduce parental controls for.
You're making the mistake of assuming that every kid has access to identified device and that device is under parent control. You can't make this assumption because that's not true.
It might be true for some middle class helicopter parents that have iPhones and time to manage and keep it under strict control but there are non-middle class kids out there who just use whatever device they can get their hands on and their parens neither have time nor ability to control that.
The commercial value of a ten year old smartphone in a wealthy country is approximately $0. It's probably not terribly hard for a determined child who goes to school and has friends to obtain one.
And I bet I'd struggle to install almost all modern popular apps on a 10 year old phone. No Youtube, no Roblox, etc. They simply wouldn't update nor connect. That's one problem solved by the fact that phones operate on a deprecation model, as opposed to Windows OS.
I'm writing this on a seven year old phone (an S10e), running a community ROM with A15, and I have no issues at all in installing any apps. This device is my daily driver (it has a headphone jack and SD card support, and a relatively easily replaceable battery, and is small and light - so it's better than most modern flagships for my needs). A pixel would have much better community ROM support still. These old flagship phones are still plenty powerful for anything other than (useless) on device AI or intense 3D gaming.
There is only a "depreciation" model if you don't unlock your bootloader - and even then, a seven year support cycle makes it very easy to obtain cheap, old, fully supported phones, if that's your jam.
>There is only a "depreciation" model if you don't unlock your bootloader
That's fair. I also think most kids won't know how to unlock a bootloader (and if Google has its way, that won't be an option anyway).
> a seven year support cycle makes it very easy to obtain cheap, old, fully supported phones, if that's your jam.
Is that iphone support? I think only the biggest flagships get 7 years of official support (and can maybe run 2-3 more years before app version itself out, without external intervention). From what I saw, most budget phones are lucky to get 5 years of support, and will break down well before than anyways.
The point is such children - eventually - intend to spend more time with a certain special rich friend - that has money/phone/gaming console. In the 2000s, I had cousins that often spent more time with such friends.
In real life, it doesn't work like this for most people. In real life, kids want something and either the parents agree to buy that and then they no longer bother with that device or the kid saves its money trades something and get that device.
The idea that a kid gets an expensive device that can't buy by itself and the parents have control or what device the kid gets is a very middle-class assumption. Life isn't that perfect for most people.
With all due respect, this just sounds like justification for lazy parenting. We're 2 generations into the digital era: parents of such an era should have enough digital literacy to make sure their kids do not get in danger.
Let's use another analog: Kids want sweets and parents either agree to buy that and no longer bother with their diet, or saves money to go to the candy store. Yet if a kid gets too unhealthy we (IMO, rightfully) have CPS sent to their house to investigate their home life.
Kids were never meant to be a convenience. And parents talked about here aren't rich enough to delegate their parenting off to someone else. Take a few hours to research what you give to your kid and monitor what they might get outside of your vision.
It's okay that it doesn't match your experience but it's also a case that you shouldn't extrapolate your expectations and experience onto others.
There's plenty of overworked, stressed or ignorant parents who really wish they could care or they don't at all.
"should have enough digital literacy" doesn't survive reality check - reportedly 12-26% adults in the UK (% depending on the country) is reported to have very poor/lack of basic literacy skills. 25% approximately are functionally illiterate.
Reportedly (I'm not an American), 36 million of US adults are functionally illiterate; 43% cannot read a simple job application; 41% of low-income households lack digital literacy skills.
Those are only two prominent examples. More developed countries (especially in Europe) will fare better, many countries will fare much worse.
I think your heart is in the right place but the reality stays in disagreement.
Maybe it's a cultural issue here, but my country is very resistant to the government coming in to course correct how people live their lives. Many times to its detriment (diet, guns, social media), but the boon of this is that it makes it really hard for anyone to incorporate a surveillance state. "Those who sacrifice freedom for security..." And all that.
The sad fact is many kids are already falling under the cracks. Failing to mind their kids internet usage is just one way, and having companies sneak in to try and fix this patch won't suddenly lead to success.
The needle won't be moved in terms of progress, but privacy will take a near fatal blow. I fail to see why we should accept such measures when this is just yet another bald face power grab by greedy corporations. I might have been more accommodating if this was in good faith, but we've been past the BOTD for at least 7 years now.
Walmart has sold android smartphones of okay functionality that poor people depend on for decades.
Like, less than $100. Nowadays they have $20 ones that are locked to pay as you go monthly purchases, which is definitely worse than the old tracfone days but about the same price if you had to top up every month anyway. That's ignoring used phones.
That's not parents issue. That's why we go after people who sell or give drugs to kids. Is a serious offense, we don't wave our hands and say its parents problem and not drugging kids is a popular policy unlike drug enforcement for adults.
If you are depending on the police to keep your kid from doing drugs, you have failed as a parent. I promise you, your kid can locate drugs better than the cops can arrest low level dealers.
You as a parent need to teach your kid how to behave (mostly through things like teaching ethics and morals) not by running a safe prison until your kid is 18.
I agree, however the problem is that large number of parents can't do that and it becomes a societal issue. That's why we are talking about that, otherwise it would have been private family issue.
Drugs, alcohol, teen pregnancy and now social media has become societal issue as enough parents failed to control their kids actions or development.
If we want parental behavior to change, we have to change the incentives. Parents must be held criminally liable for exposing their children to social media. Until we change the incentives, 'parents need to parent' is just an empty slogan.
So sure, we go after anybody who gives or sells devices without basic parental controls directly to kids. So you need to be 18 to buy a phone, which we're 90% of the way to anyway with the way credit cards work.
The fundamental point is that the Internet is not a daycare. All of these attempts to put the burden on sites boil down to changing this dynamic, recasting the Internet as if it should be appropriate to use as a daycare. Today it's big tech and porn. Tomorrow it's any writing that the the religious reich dislikes. Monday it's technical sites as they can help kids bypass restrictions. Tuesday it's international sites being blocked at the ISP-level because they don't bother with any of this crap.
We also need to remember the context here, lest we carry water for big tech's continued abuse. The main reason the surveillance industry is reaching for age verification (ie identity verification) is that harm to children is so far the only regulatory cause of action that has been found to stick. Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information. Where what we actually need is to stop their abuse for adults as well - eg data privacy, anti-trust regulation to open up their services to competing clients, and at this point probably straight up regulation of purposely-addictive "algorithmic" feeds.
> Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information.
I've said before and I'll say again that this approach (strict age gating) also is going to produce a slew of really vulnerable 18 year olds. If I were a sports gambling site, I'd be salivating at getting a fresh crop of 18 year old boys each year who have had zero opportunity to learn how to navigate the Internet and who are legally on the hook for everything they do.
OnlyFans, likewise, is going to work out great! Now the 17 year old girls turning 18 won't have access to things like the social media of former OF performers or access to any communities where sex workers discuss the downsides of their job or how to stay safe.
Have to protect the children, don't you know. That way they can be perfectly pure and innocent when they turn 18 and are ready to be exploited. Like fattening up cattle.
Yes! And this dovetails into a point I really should have made as well. The thing about "age verification" (ie identity verification) is that it puts the decision of what kids should access wholly in the hands of corporate attorneys. For example we can easily imagine a "Facebook4Kidz" website that has many of the same terrible dynamics as regular Faceboot, but that Faceboot's attorneys can justify as being legally compliant. As a parent, you would really want to block this too - while all of these proposals for identity verification and site-based-control claim to solve the problem but leave you with no way to do that!
This ties into your comment because as a kid approaches adulthood, as a parent you also want to loosen those restrictions so that they can develop these skills - gradually while under your supervision. Whereas the corporate attorneys will just say that they're strictly off limits, right up until it's then open season as you're pointing out.
And you want them to learn in a situation where the stakes are lower: at 18, someone can put themselves into a ton of debt or put nudes in the wrong place and just nuke their life in a way that they can't fix for a decade and everyone shrugs and is like 'you're a grown up!'
Think of all the kids who back in the day got scammed out of their Neopoints, or lost all of their in game currency in GTA, etc. That's a way, way better way to learn about account security and who to trust than their first experience with scammers involving real money.
Is the problem that we're exploiting kids, or is the problem that we're exploiting people? We're not going to be able to protect kids from exploitation in a society/culture that explicitly condones exploitation. If we think exploiting people is fine, actually, as long as they're over 18, then your kids will never be safe, because they will grow up.
Even setting aside the obvious examples I listed, binge drinking used to be a huge problem amongst college aged kids. Who's to say that the Internet/social media wouldn't be similar? How many kids are going to flunk out of school because they can't stop watching digital crack and now mom and dad aren't around to stop them? And unlike binge drinking, your body won't eventually revolt against you, and with the addiction consultants The Machine employs, there will always be new content. People grow out of binge drinking because eventually it grows stale and hangovers when you're 35 are far worse than ones when you're 21, but that's not true of social media use.
To tie this to other issues, we're already seeing issues with relationship and family formation amongst young people. I'm not sure flash banging them with addictive content when they're in their prime years is the call. If all it took for the Internet to be healthy was holding off until adulthood, we'd expect people who were adults when they started to have a healthy relationship with social media. They very much do not.
Yeah, but that assumes, that there are people out there, selling smartphones to children at scale. First the price for one is way to large for the financial budget of a child, and second that gets even more price-intensive, after the first one got confiscated by the parent.
There are literally people out there selling smartphones to children at scale. A smartphone these days can be bought for as cheap as a burger because 2nd hand market exist and its not limited to iPhones.
And the child can also go and buy a porn magazin, which is likely to be eventually found by the parent, just like the burner phone you suggest. The former is also going to be cheaper.
So you're suggesting resellers require ID's to sell smartphones? I completely agree. Not much difference between a porn magazine and a portal to infinite porn magazines.
> At glance this looks reasonable but how do you enforce that kids connection always goes through the parents control?
Because the parent is there to parent them?
Somehow I (and presumably almost everyone here) grew up with unfettered access to the Internet until now. Your kid isn't my kid, and someone relying on a computer to parent their children shouldn't ruin computers for everyone.
> but how do you enforce that kids connection always goes through the parents control?
Because the devices they're given by their parents should be administered by their parents. The minors wouldn't have administrative control over their devices at all.
> You want to use your friends Wi-Fi? Now that requires full identification so that we know that its not some kid
The device wouldn't care how the connection to the internet is made. It ultimately obeys the parents' settings.
The Wi-Fi doesn't need to care either way.
> You are just moving the verification point to another gate, it means that no anonymous connections are possible anymore to the entire Internet because we want to allow parents to control their kids.
Not at all. This wouldn't affect people without parental controls on their device at all. They'd be able to have anonymous connections as they do now.
The only difference from the server-side is adding some special path /.well-known/parental-info.json or an HTTP header to responses that would indicate what's on the page from a parental perspective, so the device can make a decision whether to display based on its parental settings.
Attempting to prevent websites from learning about their audience is difficult. For example, Lego has a "play zone" and it has other pages geared towards adults. You get an immediate popup asking if you want to go to the play zone or not. If a user clicks on play zone, that's a good signal (but not guaranteed) that they're probably a child.
Preventing this would be difficult. If there are any behavioral differences between children and adults, that's a signal. And it would mean websites couldn't build experiences tailored to their audiences. Do we really want to try to suppress all behavioral cues that can be used to distinguish children from adults? Is it worth it?
A reasonable compromise is that websites and apps should be able to learn about devices, not people. It should be trivial to figure out whether a visit is from a child-locked device or not, no account needed. Much like clicking on "kids zone," it doesn't mean you know for sure who's really using the device. For example, it could be an parent who turned the child lock on to see what happens, because parents should know these things.
It's another bit that could be used distinguish users, but giving away zero bits of information isn't practical.
I went to Australia recently, which is famous for requiring age verification on websites. When I first landed, Discord blocked a few channels I was in, but within a couple hours it was all unblocked with no action from me. Both Reddit and Discord worked with full functionality. My best guess is they have some sort of behavioral information that suggests I am extremely unlikely to be a minor.
It’s much more likely to be based on your advertising-based profile. Advertisers all already know your age range. That’s part of what makes it clear that the measures they’re trying to introduce are intended for other purposes.
Many years ago I worked a technical support job for Xbox services, and the amount of calls about "unauthorized charges" was obscene. Xbox provided parental controls, but it required the parent to set up their child's account themselves, and many couldn't be bothered.
And people give their children cigarettes and liquor, that's bad as well. But that's the responsibility of being an adult. If the adult is deemed not worthy of raising children, society has already established a process of dealing with that too.
> Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
This could be done with setting the age too. Kids don't have their own money and can't sign their own cell contracts, their parents do, and during the phone setup process, the parent could set "the owner of this phone is a minor" checkmark, set the age of birth (so it auto "unlocks" at 18), add a parental password to manually unlock for whatever app needed (or reset or change the setting). Then the phone would just send "user_is_a_minor" flag to whatever and/or filter the 18+ stuff.
I wonder if it would work to make it illegal to sell ad impressions of underage people. Do whatever you want as long as you can prove its being done to adults, or prove you have no economic incentive to algorithmically engagement bait
Exactly. In the future, to view a youtube video we will need create a Gmail account, we'll need a phone, SMS verification, an ID card, and we'll probably have to rotate your head two or three times and talk to some AI.
Eventually they make you fill out some paper work, or pick up some boxes from somewhere and bring them to another place. You know quick human tasks, just to verify you're really human. It's just a verification check, nothing else.
I am not sure creating an account is seen as an issue anymore given that the vast majority already have one. However yes as you say it helps create a monopoly. Combine that with a doomscrolling algorithmic feed on like YouTube and that's how you create a moat: age verification and doomscrolling.
I think sites and app developers don't really need external reasons to force account creation, they all seem to want to do it anyway. And at least this API would - in theory - enable age verification without needing an account.
Adult content providers already voluntarily embed this, with devices blocking websites when it detects this on the page if parental controls forbid adult content.
Parents really just don't parent their children nowadays. They expect the government to do it for them - and why shouldn't they, when they already trust the government to babysit their kids during the day? Why can't the government also babysit their kids for the 6+ hours a day they let their kids spend on the iPad?
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
Agreed, just make age controls available to parents, optional, and keep the user age data on the local device. External hosts can verify against it in obvious ways. But isn't that what California's law said, that commenters on HN opposed so strongly?
> The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.
I'm afraid you'd get the cookie banner problem but way worse. Everyone that's not Meta/Google/Apple would immediately add a legal CYA "18+" age rating and stop thinking any more about it.
That's how it should be. Make the Internet 18+ by default and sites targeted at younger audiences can add a more detailed rating. Let people configure their devices however they like it.
The whole problem with the regulation we have right now is that it assumes the Internet is for kids, and everything for adults must be hidden. When we really just should declare the whole Internet as 18+ and the sites for kids should be the specially marked exceptions.
Someone would complain that without ID verification kids would be able to sneak onto the regular Internet and therefore we should eliminate privacy on the regular Internet, just like they're doing now.
I never thought about that and I find it might actually be the right way for a solution... I was just looking into the Google Play Store now: in Brazil apps need to have an age rating, facebook and instagram for example are 16+, but browsers like firefox, chrome, etc are rated for 'all ages', even though you can access the whole internet through them. If we actually did what you said and inverted the logic: restrict everything to 18+ and specifically mark what is allowed to under-18s it would make parental controls much more effective.
So kids shouldn’t have access to sites like Wikipedia? Banning the internet is not the correct solution many kids depend on the internet to have access to education.
The argument could be made for banning social media but the whole internet I don’t think it’s the correct approach
If we had a "Safe for everyone" public internet and a locked down "Prove you are an adult" internet beside it, nothing prevents wikipedia from being on the Safe for Everyone internet.
Also, Encarta was a thing. Expensive though.
Some states would legislate wikipedia onto the "Adults only" web though because they don't like what it says about things like abortion and trans people.
A lot of ecommerce companies would probably be happy with a locked down adults only internet, because it would kick bot protection up a level, and would require a fairly robust solution to it.
Well... Wikipedia has content that some would consider offensive or unsuitable for children. I'm not in favor of limiting any access to Wikipedia, but I'd consider it a certainty that the day would come when Wikipedia had to decide whether to implement age restrictions or try to police content. I believe that event would change it's governance and social structure in a negative way and significantly degrade it as a public resource.
In the US, our content rating systems are absolutely as obtuse as "Nipple? R"
You traditionally can say one "Fuck" in a PG-13 movie, which will be about brutally displayed murder and violence and how awesome vigilante justice is. But if you have even a couple frames of a single (female, but like, that's its own insane can of worms) nipple, you cannot get lower than an R rating.
This is all well publicized, despite there not being public standards for the process, and the specific wording of the PG-13 advisory is "Some content may be unsuitable for children under 13", which is weird language to describe what actually happens in practice.
This is because the rating system is a weird club of "Parents of children in school" in los angeles. It's about as corruptible and sketchy as a system can get.
The ESRB is similar. Shooting lots of people? Well there's no blood so that can be for everyone. Oh, now you added some red particle effects? Sorry, now it's Mature.
GTA 3 had an M rating, but a person found that if you hacked the game and changed the code you could play a sex minigame. That caused the game to have an Adults Only rating. Even though it's not something you could do, see, or activate in game at all. And also the game already had functionality to have sex with a hooker and then murder them to get your money back.
It exists because the dumbest parents went apeshit over yet another fake controversy (Oh my god, D&D has demons!!!. OH MY GOD. This game about saving teenage girls from creatures in a crazy amount of costume who harm them with a 2 foot long grabby arm because the developers wanted to avoid unfortunate implications is JUST TOO SEXY FOR LITTLE TIMMY and we need to make congress bitch and moan about it for an entire week and ban anything that could ever be entertainment)
They are purposely arbitrary because their purpose is to make the crazy people who write letters to the FTC to arrest someone for daring to have a low cut shirt go the hell away. Those people have absurd and arbitrary triggers.
> for example, on YouTube, you can no longer watch many videos without an account.
I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?
IMHO, they should have Youtube 18+ (Adult book store) where you need an ID and YouTube <18 where you do not (Barnes and Nobles), and they can filter the content as apporpriate.
I think it is evil that YouTube enables kids access to both grooming and violent material.
> I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?
I don't like this one either. Does the cinema store the ID (or information extracted from said ID) of every single user visiting, along with what they've watched, on electronic records that can and will eventually be breached? Do they ask a third party (like Persona) for said verification providing the user's information?
On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.
From my understanding is there is no law for movie theathers in the US to card people for the movies, also the MPAA guidence rating is a suggestion. It's not a requirement.
> On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.
This is something that can be done online as well. Capitalism is controllable.
Governments aren't clearly willing to regulate the companies. They just let them do whatever they want once they're too big to regulate. Internet Companies has 20 years of history of datamining for sake advertising. Still nothing is done about, why even allow them obtain even more leverage?
> Why do we think this should be different on the internet?
Because when applied to the internet, the age gating model that works okayish for brick-and-mortar locations is ineffective (children can use a friend's older brother's ID or account, websites outside of the relevant jurisdiction can just decide not to verify age, etc.) and invasive (sending private and sensitive information off to US companies that have been breached or linked to mass surveillance). Lack of efficacy is then used to justify crack-downs on privacy tools and the need for broad content-blocking powers with no due process.
Preferable IMO would be with filtering on the local network level, like schools have been doing for decades. Parents typically own the router/mobile data plan, so it'd pretty much just be a change of defaults and maybe some new interoperability standards. A lot less invasive, and arguably more effective.
The problem is that digital IDs get recorded. The physical examples you give are generally not. The clerk at the ticket counter or entrance doesn't give a shit who you are, they just need the picture to match you and the DOB to 18+ years ago. If you're old enough, they dont even card you.
> Do movie theaters let kids under 18 into an R rated movie without ID?
I mean, yes? At least in the Netherlands they do, I just went to see new the Jackass movie last week and half the theater was kids without parents present.
Also this is a bad comparison because a theater (or bar or whatever other venue checks IDs) doesn't store those IDs forever in perpetuity, and they definitely don't share it with one of their 9000 "legitimate interest" partners who do lord knows what with the IDs.
Mailbox.org is based in Germany, which is why you generally cannot trust its feature that automatically encrypts all incoming emails. Other german mail providers, such as Tuta, have already been forced at the direction of government authorities to store every incoming email from certain accounts separately in unencrypted form. Even though Proton also cooperates with authorities, Swiss data protection laws are significantly stricter in this regard. So far, there is no regulation there that requires them to implement a backdoor. They only disclose metadata, the IP address, and the backup email address. Whereas Mailbox would have to forward the entire emails to the authorities.
I see, I don't use email for anything private because even if my mail server stores it encrypted, it passes through potentially multiple other servers on the way which have unknown privacy.
It's just for notifications and newsletters mostly.
I think that instead of trying to prevent web scraping, websites should try to make it easier so that it generates less traffic. As long as any user is allowed to view the website, there will always be a way to scrape it anyway. If there were simply a monthly updated torrent available on a standardized subpage, such as example.com/scrape, scraping would be much less harmful.
That reasoning is complete nonsense. If someone scrapes the data, that’s not a big deal, and Reddit has no more claim to the data than anyone else. The data is public and created by users, not by the platform itself. If the traffic is too much for them, they could use rate limiting or simply offer an archive of the data as a torrent once a month. That way, a company training an LLM could access a complete dataset without generating a lot of traffic.
I think the better solution would be to treat every answer as if it were written by a human and then hold the person accountable for any mistakes. I’ve often seen in academic contexts that people have published texts with completely fictitious citations. In such cases one should confront the person as if they had done it on purpose. No one can accidentally invent entire books and authors. The same goes for software projects, where some people submit code that clearly comes from an LLM and hasn't been properly reviewed beforehand. If there are security vulnerabilities in that code, you can accuse the person of having done it on purpose. Anyone who submits AI code without labeling it as such is affirming that they understand the code and have thoroughly reviewed it.
So does that mean my girlfriend is also to blame for the war just because she happened to be born in Russia? She’s against Putin herself, but there’s not much she can do about it because, as a trans woman, she’s persecuted by that shitty state simply for existing. If she protested, they’d kill her. Why should she now be barred from at least pursuing her hobby and submitting patches for software projects?
I understand that your girlfriend is a victim of same regime (and I am sorry for that, genuinely), but she may or may not be a part of it depending on circumstances.
Make no mistake - this has nothing to do with nationality or ethnicity, and everything with ones actions. Just answer me this - you say "She’s against Putin". What does it mean? Does she fight with other russian volunteers for Armed Forces of Ukraine? Does she sabotage logistics alongside partisans? Provide intelligence? Does she pay taxes in russia? Like, how is her 'being against Putin' is reflected on reality?
P.S.You nickname says 'Random German', so you should know a thing or two about systemic complicity, clean Wehrmacht myth etc. I would love to hear your opinion on what is her role in it.
Why are we drawing the line on paying the taxes? Based on what I see the EU is still trading with Russia. So, directly or indirectly, money is being delivered from Europeans to Russia
I would say that EU is in the same boat, but not to the same degree. They are collaborators. The fact that they are effectively funding both sides makes it even worse.
I think it's immoral to withhold LLMs for “security reasons.” All LLMs are all trained on forum posts from real users, source code from free software, and books written by authors. All of these people should therefore also have access to them. Ideally, the models should all be open weight. But making the model accessible only to certain groups of people is even worse than if it were at least available for purchase as a service for everyone.
It’s simply not technically possible to verify the authenticity of the camera input with 100% certainty. Pretending that it is possible only creates problems. Then someone fakes evidence, but all the normies who have no clue about technology assume that it must be real. You see this with AI detectors too they recognize random texts as generated, yet an unbelievable number of people believe them.
reply