>Could you be more specific as to what you're imagining?
sure, i'll put my favorite two. though you'll find much more detailed and thought-out versions of these (and others) in the dozens of other giant threads on the same topic.
- buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is non-identifying.
- websites issue content tags, browsers consume them, you enter your age into the OS during setup.
> buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is non-identifying.
This could be a good system if it's set up right. There's still some risk of being tracked if it isn't though. IDs could be linked to the cards at the time of purchase if retailers scan the drivers license, then scan the card creating a record that card #XXXXX was purchased using driver's license # XXXXX
Even if retailers aren't scanning the drivers licenses and collecting data that way, the cards and codes on those cards can be tracked and traceable to a retailer. That's how things like calling cards have been tracked. Say for example someone uses the code on a card to access a website, the police can match the code that was used to the serial number of the card, look up which retailer that card was sold at, and can then access security camera footage at that retailer to identify who bought the card from that location. This would also let them passively generate lists of IP addresses/device IDs matched to websites and specific retail locations over time.
> buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time
Why should I pay continuously to prove I'm an adult? And those cards will be getting sold to kids faster than you can blink. I bet a lot of parents would buy them for their kids.
>What makes you think this will be close to 90%? Unless these cards are expensive I don't see that happening.
its obviously just an illustrative guess. but if the penalty of possessing the card is similar to underage possession of alcohol/tobacco, and larger penalties if a store/person is found providing a card to someone underage, i see no reason why it wouldnt have a similar success rate as alcohol/tobacco.
If they have access to the "dark web" they can already do anything that requires age verification there. In the same way you expect that the rule to "not sell UUIDs" wouldn't be respected there, I wouldn't expect other age-verification rules to be respected, no matter the verification method.
You need to pay for a drivers license or a passport and so on. So there is an intrinsic cost to prove who you are where you are from and what your birthday is already.
You have to pay for all sorts of small things to participate in normal society. This isn't a serious criticism.
By definition this is not a life critical thing, it's something that is procured in order to access specific services on the internet, which is not free.
>You need to pay for a drivers license or a passport and so on.
I have a government ID and I didn't pay for it. I can use it to travel to nearby countries in lieu of a passport. The assumption that IDs are necessarily non-free (to the issuee) is pretty funny to me.
>it's something that is procured in order to access specific services on the internet, which is not free.
The maintenance of the Internet is already paid for through ISP contracts.
I mean, if you really want to make the government subsidize an ID verification scheme or mandate that certain real-world locations provide age verification as a social service for everyone, that's fine.
It's orthogonal to the discussion, though, which is about whether we should do it or not, because the costs here aren't significant and don't change the terms of the debate.
I'm personally in favor of just banning children off the Internet, but I don't agree it's orthogonal to the discussion. What I replied to was the implication that someone should pay a recurring cost to prove they're an adult for the same reason that they pay to own a computer or to connect to the Internet. Don't disown the dumb thing you said.
I'm not disowning it at all. I think paying a recurring cost to prove you're an adult for purposes of accessing the internet is completely fine, trivial, and unimportant.
You have to pay a cost to go out in public, since there are nudity laws. You have to pay a cost to use an airport or a train station. You have to pay a fee to prove that you own a car. And so on.
It just doesn't matter. It's not important. It's consistent with how we organize our society in general, which makes focusing on it in this one particular instance more understandable as an attempt to distract from the substantive merits of these arguments about age verification.
>I think paying a recurring cost to prove you're an adult for purposes of accessing the internet is completely fine, trivial, and unimportant.
Okay, but the person you replied to doesn't, and instead of providing an actual answer to their question, you posed a false equivalence between proving your age and buying a computer.
>You have to pay a cost to go out in public, since there are nudity laws. You have to pay a cost to use an airport or a train station. You have to pay a fee to prove that you own a car. And so on.
You are purposefully muddying the waters by being lax with your use of language. The "cost" you "pay" by wearing appropriate attire in public is fundamentally different from the actual cost you actually pay when you engage in commerce; one is a trade of freedoms and the other is a trade of goods and/or services. If your argument is that the freedom you have to trade in exchange for the freedom to access the Internet, is that of not having to show an ID, that's one thing. If you also have to add a recurring monetary cost then that's another.
If you don't have an answer to the question of why someone should have to pay again to use the Internet beyond "*shrug* just 'cause, dude. Who cares?", then maybe you shouldn't have said anything.
> If you don't have an answer to the question of why someone should have to pay again to use the Internet
Of course I have an answer. To do something about the unlimited firehose of porn, violence, divisive, and addictive content that has been pointed at children for the past generation or so.
There's literally nothing confusing about the "why" in this discussion.
The fact that bad people use the "what about the children" argument regularly for bad reasons doesn't mean that all such arguments are bogus.
In fact, it's an indication of exactly the opposite, it's so regularly used because there is a broad consensus that we need to protect children from harm which is why it's often effective as an arguing tool.
The relevant frame for this discussion is will it actually work, and what are the tradeoffs. A trivially small amount of money for a simple age verification scheme isn't a particularly meaningful tradeoff against a genuine social problem. The bigger, more genuine issues are around privacy and censorship and I do in fact concede those are real.
>To do something about the unlimited firehose of porn, violence, divisive, and addictive content that has been pointed at children for the past generation or so.
See, you've answered a different question. The question you answered is, "why should children be protected from the Internet?" I'll give you for free that children should be protected from the Internet, for the reasons you've said, and now you get to convince me that I, who don't have or plan to have children, should spend my money to protect other people's children from the Internet.
> I, who don't have or plan to have children, should spend my money to protect other people's children from the Internet.
For the same reason your taxes pay for schools even when you don't have kids.
Because we live in a society.
If you struggle to understand why that matters without reference to more direct personal stakes for yourself, just know that without a society, the children will grow up to rape you, kill you, and possibly consume you for your protein content.
>For the same reason your taxes pay for schools even when you don't have kids.
But I have benefited from public education. Me paying for someone else's education in return is fair.
>Because we live in a society.
"Because we live in a society" is a phrase flexible enough that it can be used to justify anything, including outright theft: "we live in a society; us taking your stuff is the price you have been chosen to pay for your continued belonging". Want to try a little harder?
You have convinced me that there are in fact no differences between things, and that protecting children from adult content is indistinguishable from stealing from people, and therefore I was foolish to advocate for it.
No. My question was not why am I forced to pay, my question was why should I pay. Obviously if I have to pay, I will (that's a logical necessity, because if I could avoid it then it was untrue that I had to, to begin with). Why should I pay? That is to say, by what mechanism am I saddled with the moral responsibility that justifies me having to spend my money to protect someone else's children? Given your line of argumentation, I'm going to guess that you don't have an answer to this question; your answer is that I should GFMS and just pay. Prove me wrong.
This is orbiting the issue of personal responsibility and social burdens.
I get the impression that you recognize that there are certain costs that are distributed on members of a society, because it is the least problematic way to address some collective action issue.
You could migrate to the libertarian ideal, if that is what suits you. if this counts as GFMS, I sadly don’t mean in it those terms.
I dont know you well enough to know what specific harms would matter to your wellbeing.
It could range from what the state of the next voting cohort will be.
It could range from having a social environment of better adjusted adults creating art, science or just relationships that will impact you as you age.
It’s more capacity for families, mental resilience and less dead weight loss of kids getting trapped into emotional tar pits.
It’s a signal that as a society we don’t want to see our kids addicted, and that if we impose such costs on ourselves, we will impose heavier costs on the perpetrators. There is a reckoning with social media and addictive design that is to be had; this is a step on that path.
It makes it easier for parents who are struggling, and reduces harm to kids and teens.
It may give us a way to deal with the absolute scourge of non consensual intimate imagery.
I’ve personally had to flag and remove stuff of that nature, and even in a country like america, that kind of content is life ending.
In a religiously conservative country, that can lead to much, much worse.
However this is a smorgasbord of ills that society as a whole is struggling to deal with.
You are a standing member of that society.
I don’t know you well enough to make a case that makes sense.
I will add, You also don’t look to be a passive member of society, so you are doubly screwed.
You get the bonus burden of having to think about how to solve the problem in the best manner possible.
>It could range from [...] as a whole is struggling to deal with.
I thought you said you read the thread. You've fallen into the same mistake CPLX has made. You're answering why children should be protected. I've already granted that premise, there's no need to argue for it. My question was why people who don't have children should bear the burden of that protection instead of their parents.
If a more concrete question would help, why should all adults pay to be able to prove that they're adults (just to be able to retain a freedom they already had, I should add), instead of being given that ability for free by the government, and the government collecting the costs of the program from parents?
So I don’t have kids, and I have worked in trust and safety.
As stated, society is finding a sub optimal solution for a person in a narrow read of my situation.
I (and you) are impacted by the second order effects of the decision to do something or to do nothing.
Our freedoms do not exist in a vacuum, or as platonic ideals. They must be enacted through some actions or rulings.
I have a longer spiel on how social media and news media are currently not functioning as a fair and efficient market for information. For now I will just assert this as true.
The broken state of the market, means that I and you live in a world where it is more likely that the worse political decisions get made, polarization and autocracy are more likely not less, and complex coordination challenges do not get solved.
Building ways to ensure a market which does not devolve into a “might makes right”, or “abuse is good” scenario, is to build guard rails and limiters.
This is the current limiter which is being proposed.
In essence, it’s not like we live in a world where things are perfectly fine, even for us.
Do note - I don’t know you well enough to know what things you value, but it is clear you value some things more than just what is optimal for you. So there is a set of values you have, some of which are going to be injured by these solutions, and others served.
One wrinkle in your argument - If the costs could be taken from parents, that would be great, however one group of bad actors in these situations is adults. So as a class, there is some case that could conceivably be made for adults to bear that cost.
>One wrinkle in your argument - If the costs could be taken from parents, that would be great, however one group of bad actors in these situations is adults. So as a class, there is some case that could conceivably be made for adults to bear that cost.
"Bad actors"? I see three separate subsets of people, different unions of which would yield possible interpretations of "bad actors":
* Adults targeting children with the intent to commit illegal acts. E.g. groomers.
* Adults targeting children with the intent to commit legal but harmful acts. E.g. adults marketing lootboxes to children.
* Adults engaging exclusively with other adults in legal interactions that would be harmful (and possibly illegal) if a child were to be involved. E.g. adults trading pornography and banning minors on sight.
(Let me emphasize that these are mere examples, not necessarily representative of their set.)
I don't think it's in dispute that all three sets currently exist on the Internet. I would not say that the third one is a bad actor, though. Yet it by itself would be argument enough to either remove children from the Internet or to cordon them off to their own exclusive corner. So if the third set was the only one that was non-null we would have a situation where there are no bad actors, yet all adults are still bearing the cost of this system.
Now let's suppose that only the first set is non-null. If there's a bunch of criminals targeting children, that seems like a police matter. Why are law-abiding citizens getting roped in? En masse, at that.
For the second set, legislate until it becomes the first set.
The last paragraph of my longer comment was definitely not what I expected to displace our energies towards. Just a potential wrinkle in the thesis.
The larger point you are asking to be established is how you as a class of members in shared society should have costs added to them which.
I attempted to make the case for you; in general you are already paying costs. The maladies from the current state of social media and the Internet mean that you are impacted already, even if you don’t have kids.
The scale of the “pollution” so to speak, from other parties, is not addressable by independent action.
> buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time
Exactly, prepaid phone cards with point of sales activation (to eliminate large scale theft incentive) is nothing new. Once activated, the validity of the token can be like 6 months or one year, and at-most-once-per-domain schema can be managed by the issuing authority if they want.
Instead of a 100 phone minutes, 300 phone minutes card you just buy "I'm over 16", "I'm over 18" cards. It's simple UX.
I'm just left wondering, how would that be different than buying a phone? Most kids also don't have money to spend on devices, that's all coming from adults, how would the UUID work any different? In my view it seems we'll just reach the current state as with phones.
Well, they could trade identifying ones too or even stollen ID cards if you want to go this way.
They could also trade porn-filled thumb drive or old-school glossy paper magazine. There no way to prevent kid's exposure to stuff at a 100% success rate.
Indeed but you are the one who claimed it was not a hard problem.
I don't think any one of us pushing back here on those claims do so for the heck of NOT finding a "solution", rather genuinely asking because so far it seems nobody did find such a solution without compromises that is in the end not worth it due to the flaw in said solution.
The point isn't to be critical of your process, only of the claim that it's a trivial problem.
> - websites issue content tags, browsers consume them, you enter your age into the OS during setup.
Why would that be acceptable though? What if a user does not trust the operating system? Even Linux may not be safe in the future, what with age sniffing coming by Red Hat integrating it into system already. And Red Hat plans more - xorg is abandoned on purpose, for instance.
> buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is non-identifying.
It can be implemented in a privacy-preserving way online: your government gives you tokens that prove that you are above age and that they provably cannot track. That's the exact equivalent.
I believe that the other measures (remote attestation and such, the ones we hate) come when we try to make absolutely sure that you don't give/sell that UUID to someone else. But IMO we should just forget about doing that. Just like an adult can, today, buy cigarettes and porn and give them to a kid.
Any token given that way contains some amount of encrypted payload.
That secret payload may contain uniquely tracking numbers.
Even the encrypted payload itself, if treated as an opaque string, can be used for tracking if they decide to log it when they deliver it to you, and when the website where you use the token passes it back to the government auth service.
You need to replicate the UX of a stack of pile of cards at the grocery store, that's not really possible in digital space.
It's exactly like end-to-end encryption: normal people cannot verify that it works, but they can use an open source implementation that is audited by independent cryptographers.
Not sure what you mean by "easily". It's totally possible in practice.
And honestly, all these should ultimately just be done client side in the browser. After the browser has verified "User is x or user is over 21" there's no reason to then send that information to the website.
Let websites issue a "window.isUserOver(16)" call once and then move forward based on the response to that query.
No, no. Don’t give websites a way to check the user’s age.
Age restrictions are different across countries and cultures. Parents disagree on age ratings given by boards all the time.
Have apps and websites declare the objectionable content they have, and let the device decide if it will show it or not according to parental controls.
If you’re a parent that pays attention to age ratings, you know exactly what I’m talking about. The age is meaningless. It’s the type of content next to the rating that’s important.
Your only option as a parent now to let your 14 year old play a violent game rated M that you specifically allowed is to give them a fully unrestricted device. They can now use that device to access gore, porn and gambling as well. How does this make any sense?
Right, recycling a comment on the benefits of "website reports, the device parents bought blocks":
_____________
1. Most of the dollar costs of making it all happen will be paid by the people who actually need/use the feature.
2. No toxic Orwellian panopticon.
3. Key enforcement falls into a realm non-technical parents can actually observe and act upon: What device is little Timmy holding?
4. Every site in the world will not need a monthly update to handle Elbonia's rite of manhood on the 17th lunar year to make it permitted to see bare ankles. Instead, parents of that region/religion can download their own damn plugin.
> Have apps and websites declare the objectionable content they have, and let the device decide if it will show it or not according to parental controls.
That would have been nice. The RSAC (Recreational Software Advisory Council) had a slightly more granular rating system that rated violence, sex, and language on a scale from 0 to 4 which unfortunately it lost out to the ESRB/IARC age-based classifications, and the internet appears to be going towards age-based classifications as well. Personally I like Common Sense Media's ratings which extend the standard violence, sex, and language flags by adding scales for "Products & Purchases" and "Drinking, Drugs, & Smoking".
From a semantic web standpoint it would have been useful if the web had codified these sorts of content flags so content producers could apply them to apps, websites, page sections, images, or even individual HTML tags. Then a device administrator could tell the operating system or browser to restrict certain content, either based on age-appropriate presets or based on custom levels for each type of content.
Don't even bother having the website ask the browser anything at all. Just have the website TELL the browser the content is intended for adults via HTTP header and let the browser decide to display it or not depending on parental controls.
This would require browser attestation, wouldn't it? Otherwise kids are just going to download a custom build of Chromium where `window.isUserOver(16)` is always `True`.
No, it only "requires" browser attestation if we taken it as a given that the onus is on tech companies for verifying who they are talking to - ie identity verification that most of these schemes boil down to regardless of how cute they're dressed up.
To effectively keep adult content away from kids, it merely requires secure boot and closed app stores, which are already widespread. And they are only required on the devices actually given to kids, rather than every single computing device.
But this proposal has another problem: it's easy for a website to run isUserOver(n) in a loop to derive the exact age. And on a persistent account, it can be queried every day to derive an exact birthday! Which comes back to my main point that the only technical schemes we should be considering are ones where information strictly flows one way - the website/app supplies information to the browser/OS, which then [may] implement parental control policy. anything else fundamentally boils down to a mandate for identity verification.
> To effectively keep adult content away from kids, it merely requires secure boot and closed app stores
This is unacceptable. If I own a computer, I expect to be able to build and run any program, either written by myself or others, without asking anyone for permission.
Maybe I needed to say "it merely requires the existence ...". Because I then do go on to say:
> And they are only required on the devices actually given to kids
My whole point is that this limits the blast radius, compared to any solution involving "age" (read: identity) verification which has a blast radius of every computing device!
> To effectively keep adult content away from kids, it merely requires secure boot and closed app stores, which are already widespread. And they are only required on the devices actually given to kids, rather than every single computing device.
...I guess I don't really see the difference.
Closed app stores are widespread on some platforms but certainly not others, and I for one would really like them to not spread any further.
For starters here, the difference is that only devices that parents give to kids need to have secure boot and controlled software sources. The point is that every other device remains completely unaffected.
But in general there is a huge difference between the freedom-destroying properties of secure boot with closed app stores, and the next step of remote attestation. Remote attestation lets the server insist that you only run software fully of their choosing rather than your choosing, as a condition of interacting with them. This completely destroys the idea of protocols that mediate between two parties with diverging interests, and computationally disenfranchises users. Imagine the next generation of the Cloudflare nagwall that doesn't let you past unless you buy a new computer, and that new computer must be running MSWin/OSX and MSIE/Chrome.
(also note that my use of "secure boot" here includes systems like on Pixels where you can straightforwardly unlock the bootloader (erasing the data on the device), install whatever you want, and then relock. I still find these systems philosophically objectionable, as there is still a privileged key baked in and retained by the manufacturer - similar security properties could be provided without the backdoor. But pragmatically they've been working okay)
No, thank you. As a parent, I want to give a device to my child that they can hack, just like I had.
Why are we treating kids like adversarial threats? If my kid gets around parental controls, I’ll revoke their phone privileges. No need for invasive security.
Yes, as a parent you should be able to say this! You should also be able to say other things like I want my kid to have full access to wikipedia. Or I do not want my kid to have access to Faceboot, including a special Faceboot4Kidz version that their corporate attorneys have declared is completely suitable for minors.
My whole point arguing for client side controls is that it allows parents to express these types of fine-grained preferences, without merely putting the onus on tech companies to make these decisions in a top-down fashion serving their own self interest!
As for secure boot specifically, my point is that it is already here on basically every phone. One of the most security-forward phone OSs (Graphene) even requires it. I've got philosophical problems with manufacturers baking privileged backdoor keys into hardware, but it's already prevalent. If you think I'm arguing in favor of restrictions, then please go educate yourself on the security properties of remote attestation to see what I'm actually arguing in favor of heading off!
If you want to argue for client side controls, I’m on your side. I’ve expressed this opinion elsewhere in this thread.
I’m well educastes on what remote attestation means, and I know it’s the status quo. But it is not required by law. And I’d very much like for it to continue being optional indefinitely, and not bundled with a different “save the children” law.
More specifically, I don’t want to have to prove to the OEM that I’m an adult to unlock my bootloader or disable SecureBoot. Or, more realistically, I don’t want OEMs deciding it’s cheaper to stop offering that choice because they don’t want to risk unlocking the bootloader on a child’s device.
> If you want to argue for client side controls, I’m on your side
Yes, then we're coming from the same place here.
> I’m well educastes on what remote attestation means, and I know it’s the status quo
I wouldn't describe remote attestation as the status quo. I generally use the web from my libre desktop, and apart from all the constant nagwalls (Cloudflare et al), I can access sites just fine. Perhaps on many mobile apps it's become some kind of status quo ("Play Integrity" I think it's called?), but even mobile browsers don't do attestation (WEI, or whatever they've renamed it to these days), IIUC.
> But it is not required by law
This is a red herring. None of these laws are proposing to require remote attestation, but rather anything that puts the onus on big tech to "verify age" (aka verify identity) will eventually lead to it being de facto required, with no direct law required.
> More specifically, I don’t want to have to prove to the OEM that I’m an adult to unlock my bootloader or disable SecureBoot. Or, more realistically, I don’t want OEMs deciding it’s cheaper to stop offering that choice because they don’t want to risk unlocking the bootloader on a child’s device.
I'm right with you about the knife-edge we're currently teetering on, where what is a pragmatic system that "merely" has gotchas could get more restrictive at any time. But Google already requires you prove you're the device owner to unlock a bootloader, and far too many manufacturers already don't let you unlock. But if done right, then none of this really matters for the parental controls use case - rather when unlocking the bootloader erases the whole device, that is the flag that lets a parent know.
The same system that blocks kids from downloading the Pornhub app would also block them from downloading the "Chrome but without parental controls" app.
Right now, they don't know. They're going to learn very quickly when they want to use some website and they can't.
We agree it doesn't need to be 100% perfect. But it needs to be at least, like, 60% perfect, right? And unless you make it at least a bit hard to bypass, it will stop virtually no one.
That is a real problem but for an unreal situation. Nobody is advocating that we combine (A) a child-safe browser with (B) a completely unlocked device in every other way.
When I buy/configure a device which prevents Little Timmy from viewing smut, that device is also going to have a parental code for installing new apps. If that part is left open, then Little Timmy wouldn't have to even bother getting a different browser, he could just install direct porn apps.
> But it needs to be at least, like, 60% perfect, right?
That can easily be reached by ensuring that child-mode covers default browsers and also the ability to install a new browser. If Little Timmy is turning on debugging over USB to sideload, then a fundamentally different parenting strategy is required.
Installing a new browser is already a bit hard for most people. I think you are a little skewed in your thinking being online on HN.
You also aren't thinking about age. Certainly 16 and 18 year old probably can get a new browser installed. But a 14 year old? 12 year old? 10 year old? That barrier is a lot higher the younger a kid is.
I just finished my second year as a fifth grade teacher, so I have a lot of experience with ten year olds. I am confident a majority of my students would be able to install an alternative web browser if they needed to, and a majority of the remainder would ask a friend to do it.
To give you an example of the workarounds kids will find: Youtube was blocked on school laptops, so the kids all started embedding Youtube videos inside of Google Sheets in order to watch stuff. This isn't, like, something a few savvy kids did, it was a widespread and common practice.
Lol. I started building computers, installing operating systems and tinkering with Linux between ages 10-12. I also started watching porn not long after that, and guess what, I still became a more or less normal adult. There is absolutely no need to "protect the children."
This is how California is legislating it—requiring the OS to let an admin set the user's age, then let browsers and through them, websites, to query that setting.
> - buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is non-identifying.
Until it is because the store keeps records of who they sold which cards to.
sure, i'll put my favorite two. though you'll find much more detailed and thought-out versions of these (and others) in the dozens of other giant threads on the same topic.
- buy a card with a UUID from anywhere that sells alcohol/tobacco that is valid for some period of time. most people are comfortable with flashing their ID at the clerk. the UUID card is non-identifying.
- websites issue content tags, browsers consume them, you enter your age into the OS during setup.