Don’t get me wrong, I’m all for privacy. But between setting up the birthdate when creating my children’s local account on their computers, and having to send a copy of their ID to every platform under the sun, I’d easily chose the former.
I’d even agree to a simple protocol (HTTP X-Over-18 / X-Over-21 headers?) to that.
Lots of the criticisms will eventually start sounding like seatbelt law opponents. Lots of “it should be optional, if you want to do it that’s fine but don’t force me to, I feel safer without it, it’s each individual’s responsibility and shouldn’t be mandated, etc” types of arguments.
The problem with the current implementation is that it isn’t done privately. There are several ways to do secure and private age verifications, where your device never passes your browsing history off to the government, and the individual sites never get your personal info. But lawmakers have been lobbied by companies who want to insert themselves as the age verifiers to skim your data. So the current laws being passed are written in such a way that they’ll result in massive privacy violations.
If opponents truly wanted to prevent privacy violations, they would be devising ways to get lawmakers on board with secure age verification. That way the laws would actually reflect best practices, and wouldn’t just result in less privacy. But they’re still trapped in the knee jerk “but my privacy” reactions, which shuts down any further discussion and leaves the door wide open for lobbyists to write and pass whatever legislation they want.
It’s not just a privacy issue. Regulatory capture is a problem too. It encumbers small services to the point where they can’t afford to exist, and the only winners are the walled gardens. And it’s also logistically an impossible thing to attempt to regulate at scale.
That isn’t a problem with proper implementation. Not that it will be done properly, just that it can be done properly
Trying to get every site that offers mixed content, or could do so to implement recognition of all of this is herding cats. It’s completely impossible without a walled internet. Moreover, there’s just no way a OS asking if you’re 18 is going to be accepted. It just isn’t. The expectation will be that they verify your age properly.
The goal isnt to herd every single cat. Just get the bulk of them. That’s how existing age regulation works. Alcohol age limit doesn’t stop underage drinking, but it does substantially reduce it. With that in mind, there are privacy respecting solutions that will do what needs to be done
I doubt you would even get “the bulk of them”. Again, people are saying “it’s just a yes/no tickbox bro”. For now. You cannot be naive enough to think it won’t change. And the absurdity of it too. Forcing something someone may program for fun to have a specific feature.
I do expect it to change. I expect it to be standardized with zero knowledge proofs. If I am avle to communicate with you on a random internet forum from anywhere in the world using standardized protocols, we can get private and secure “I am 18+” verification. It may initially start with proving it in some form or another, but if done correctly you would essentialy have a private key that certifies you are over X age. The company would know nothing about you, other than you are not a child. I have extremely simplified it, but it is possible.
This is highjacking the narrative
Is it though? I’ve been saying for a while that direct device verification is the way to go. It would allow for systems that maintain privacy, while also allowing lawmakers to say they’re protecting kids (and enabling parental controls by default, which is important when many are basically tech illiterate). But that wouldn’t help the big tech companies harvest your data, which is why they haven’t lobbied for it. Instead, lawmakers have been pushing the worst form of age verification, which requires all kinds of privacy violations every time you want to jork it.
Are we sure parental control methods were proven to be fundamentally inadequate for the situation? There’s no bulletproof security method to guard this data, so the discussion is about weighing privacy loss vs child safety, against existing methods (or improving other methods). Also the choice to set the age is in the hands of the parent, so I don’t see the benefit besides enabling the kid to choose app in a more self served manner (which you probably don’t want to allow).
Seatbelts are there because it’s obvious you’re not in control of other drivers, even if your car has all the safety controls. The downsides are minuscule in comparison to the privacy discussion, in my opinion.
OS defined does seem the best way, but I would prefer it wasn’t legislated. The people writing these rules have no clue about the real world, so they end up doing stupid things.
I don’t necessarily have an issue with that - as long as it can truly be done in a way where the only information the platform gets about me is whether I’m of age (they don’t even need to know my exact age). But I don’t have faith that it can actually be done like that, and I see it as a slippery slope toward even more surveillance.
So you’re ok about your official ID being broadcast everywhere you go on the internet? Every step you take can be tracked by the government, google, Meta and more? No more fucking privacy what so ever?
Yes. That’s exactly what I’m saying.
and to prove its not actually about safety and instead about control: parents are already responsible for what kids do online and could be charged using existing laws. but… where is the overreach in that?!
They can have one bit. I’m ok with one bit.
As soon as they ask for a byte, they are gathering too much information about me.
I can accept that this is a significant issue, and if knowing that I’m an adult is required for certain online activities, I’ll go along, but we all know damned well this will creep.
What ever elements need to verify who I am stay private client side, and they can have a single flag that verifies I’m what I claim to be.
It can be done like that, but then it’d be (trivially) fake-able by anyone with root permissions on their own computer. But then, my point is that kids shouldn’t be root of their computers, so let’s just parents vouch for children’s age, and leave everything more complicated out.
From what I understood, the rules (in California?) would be : a) Every operating system provider must collect the user’s age or date of birth during the initial account setup process. b) The OS must classify the user into one of the four defined age brackets: under 13 years old, 13–15 years old, 16–17 years old, or 18 years and older. c) This information must be made available to application developers through a real-time API as soon as an application is launched or downloaded.
Unless I’ve missed something, I could definitely live with that. I haven’t seen anything more acceptable when it comes to age verification. Point a) doesn’t need to prove age or date of birth.
Now there is a small issue that came to my mind since my first post, which might be quite problematic : if ANY website is able to tell whether ANY user is a child, it’ll be as easy to keep children out of certain sites that it’ll be easy to keep adults out of others.
Imagine a bulletin board with highly disturbing/predatory content which would ONLY show to kids? Whenever mom or dad checks, website is all normal. And that would be real bad, probably worse than our current, no age verified situation.
Will you be allowed to lie about the age? If yes, then it’s a pointless law. If no, then whoever is checking needs to have more control over your device than you do, DRM style. That’s gives them an entry point through which they can put whatever they want without you being able to control it.
The Califirnia law, at least, states the age flag should be set when the account is created, presumably by the controller of the computer, and holds that controller responsible for setting it correctly, and the developer responsible for ensuring it’s set and works correctly, at least, that’s my reading of it. If it’s your computer, that makes you resoonsible for setting your age and that of accounts you create for your children.
So that means that kids can’t buy computers?
Can’t buy a cheap used raspberry pi or old laptop/desktop in order to set up as a server?I don’t think there would be any difficulty with a kid setting up a computer, as in most juristictions the parents are responsible for their childrens’ actions until they are adults themselves. So the oarents would still be responsible for what the kid did with the computer in the same way they often are now.
So these “os reporting age bands” laws are useless then.
Cause either the parents are being responsible, at which point there are many parental tools for network and device control.
Or they aren’t being responsible, and the kid can easily bypass it or just buy their own device.These age band laws basically work in the opposite way to the usual parental controls. Rather than having to install and maintain the control software and having the filtering at the client end of the connection, parents need only set a flag and filtering will occur at the source end of the connection.
Will these laws provide perfect protection that eliminates the need for parental oversight of childrens’ internet access? No. Will they help stop kids accidentally stumbling into unsuitable content, reducing harm overall? Yes. As a parent, one of the things I worry about is my kids browsing sites such as youtube. Even if they’re using it for research for school projects, I can never be certain it wont prompt them to watch an unsuitable video. With a simple “this user is a child, don’t show them anything unsuitable” flag, I wouldn’t have to spend so much energy monitoring everything and could spend more energy talking to them about what they’re actually watching.
One of the key parts of the Californian law is that if the client machine sends the flag, the service must treat it as authoratative, and should not use other means of checking. That is good news, as it means there is no incentive for sites to integrate more intrusive measures such as third parties scanning givernment issued ID.
So then the law is pointless as implemented, since parents can already do this. Which leads to the conclusion that there must be some other motivation
Right, so the law is pointless, since there is already a thousand different ways to control what children see on the Internet.
and to prove its not actually about safety and instead about control: parents are already responsible for what kids do online and could be charged using existing laws. but… where is the overreach in that?!
Whilst parents absolutely should be guiding and helping the kids determine where they go online, and what they look at, I’m trying to envision where, or how, parents would be liable for them looking at something inappropriately “adult”, barring actual child neglect.
A system like this would actually help parents be more confident that little Johnny wasn’t going to stumble across something in appropriate, because, yes, in a way this is about control. It’s about controlling what kids are exposed to before they are intellectually ready for it. Yes, there are potentially serious issues around that, such as limiting access to LGBTQ+ or other helpful material for young adults, but that should be a discussion around what information is needed at each age, rather than how to indicate that age.
Age gating on the open internet will happen, I don’t see any way that it wont, what matters is how it is implemented. We know that submitting government issued ID to every site with potentially contentious content is a terrible idea; this neatly sidesteps the need for that, and actually forbids it.
for ex: if you let your kid look at porn, in the US, the parents are absolutely liable for various forms of “risk of injury to a child “ laws.
To bring charges under those sorts of laws there’s going to have to be some external evidence of harm. Either the kid is acting in a way that causes an agency sufficient concern that they investigate the family, or the government mandate much stricter monitoring of exactly who is doing what online. The former case is unlikely, but should probably be persued vigerously when it does hapoen, and the latter case is something I imagine we all very much want to avoid.
By providing a simple, privacy conscious, way of taking some of the burden of vigilence off of the parents (the child is less likely to stumble on inappropriate material) it makes it easier for them to provide actually beneficial guidance, and reduces the risk of law enforecement getting involved to investigate minor transgressions.
putting burden for safety on corps is not a healthy thing.
The burden is still on the parents, but this would actually provide a useful tool for them to address that burden.
if they are claiming the new laws are for kid safety there must be existing already some external evidence of the need, no?
There’s fairly clear evidence at a societal level that access to, for instance, hardcore pornigraphic material is harmful to children, but that is very different to having evidence that a particular child is currently being exposed to it.
Just because they are responsible doesn’t mean the have the means to exert their responsibility. Demanding birth-date upon (local) account creation would allow them to better exert that responsiblity.
no it wont. kids get around shit easier than ever especially with luddite parents.
if the gov actually cared they’d take to charging using existing laws.
Parents of current 8-18 year olds are gen X and millenials, who every survey shows are (on average) significantly more tech literate than gen Z and Alpha.
correct. i am a gen x software engineer and I know for a fact my kid who is now 25 would always find ways around firewalls when he was 14 and horned up.
my point is that we have laws already that are perfectly appropriate to the “concern” stated, “child safety.”
any new laws will only give more access to important data to corporations who are known to do bad things with it.
that does not make it worth it. my opinion would change if there was a legit large inrush of charges using exiting laws that then did nothing to help, then one could argue we need more law. but thats just not the case today.
OS age verification would effectively make some, if not most, linux distributions (or other less-popular operating systems) illegal. Because many linux distributions are made by small team of volunteers. In some cases a linux distribution might be maintained by literally one person. So these people likely do not have the time or money to include something like age verification into the operating system.
That said, there are some technically possible ways where this could be done to reduce the load on developers (perhaps with access codes, and a government maintained database) but the way age verification had is being done right now (face scanning, etc) would be a real headache to implement and quite possibly cost or time prohibitive.
It would be a shame if age verification laws effectively made open source operating systems illegal. It would suck if these laws inadvertently made it legally required that we need to support big tech companies like Apple or Microsoft in order to use a computer.
This is why I consider it regulatory capture in a trench coat.
Including an age flag field in user data on Linux is fairly trivial, and I’ve seen several proposals for it. Once that’s in place it’s up to browsers, “app stores”, or anything else that needs it to request the data and use it.
The effort from a Linux team here would amount to little more than a “are you 18 yes/no” and there’s no way that would be considered good enough down the line if not now.
Yet, with the way the California bill is written, so long as that data was collected at account creation, it would be adaquate.
Sure. For now. But in any case, aren’t they legally viable if someone complains?
Including an age flag field in user data on Linux is fairly trivial, and I’ve seen several proposals for it
What would these systems look like? Im curious.
My concern is that, even if these systems are technically possible, the law will settle on using lucky inefficient methods of age verification such as using AI to scan someone’s face.
It one of the reasons I like the way the California bill has been written, it’s very clear that you set the flag, or provide a date, and not only makes no mention of verifying it in any way, but also requires that anything using it trusts it and may not perform any other checking. A service using that data is also explicitly not liable if it’s wrong, so they have no insentive check any further.
It is, obviously, possibly that laws will change in future, but it seems to me that having something like this in place actually makes it harder to implement anything more intrusive later.
Yeah I’ve heard of similar systems in Europe. It’s similar to two factor authentication. Hopefully something like this could also screen out bots, making influence campaigns more difficult. But regardless, however its implemented I hope it will be easy for not-for-profit operating systems (such as linux distros) to operate
No. As soon as you’re sending in your official ID your entire online presence will be tracked to your ID by the government, Google, Meta and the likes. Privacy is totally gone by then…
What is a computer? My microwave has a computer in it. My car. My printer. My smartwatch. My TV. My treadmill. My security cameras. Many many things have little embedded systems running linux. Some are Internet connected, some aren’t. This feels terribly invasive for something that allegedly protects kids (doubtful). What if i don’t have any kids in my household? Would this have stopped Trump and his friends? How about the government focus on real problems instead of requiring cameras be installed on my toaster and a credit card to be able to watch TV.
Just because one option is better than another, doesn’t mean it’s good.
OS level age check applies to everyone, not just children. Some legislations require strong age checking, which means you need to send some identification to some service. You won’t be able to know how the information is handled, for how long it’s stored and for what purposes it’s used beside age checking. And because this applies to everyone, and is required to be able to use your computer, everything you do with your computer and phone is tied to your user account, and as such to you as an individual and identifiable human being.
Some of these legislations uses age ranges, and the OS is required to inform applications, and such, whether the user is, for example, below 13 years old, or 13 to 16 years old, etc. Consider this simple scenario: Some user uses some application, and the OS reports the user’s age as below 13. The user uses the same app the next day, but now the OS reports the user’s age as 13 to 16 years old. Can you figure out the user’s exact birthday and age? If that application is part of some kind of larger network of advertisers and whatnots, they will now forever know the user’s exact age without the OS reporting anything else.
These can also be used to make some software illegal, especially free and open source software. If you can replace Windows with Linux, Photoshop with Gimp, etc. it hurts the bottom line of those companies. Those companies can’t prevent you from using the open source alternative, but it would be in their interest if those pieces of software becomes illegal to use and distribute. If age checking functionality is added to some open source software, the age checking can simply be removed by the user. You only need to correctly form the age checking law and that entire software is now illegal, and must be removed from the internet.
While the intention of these laws might to be to protect children, they cause too much harm for little good. The age checking can be circumvented in some situations, meaning the children aren’t protected. And the entire thing is a huge privacy mess (data leaks, etc.) for every single computer user.
and to prove its not actually about safety and instead about control: parents are already responsible for what kids do online and could be charged using existing laws. but… where is the overreach in that?!
the problem is that it’s not going to stop there. kids will obviously still get porn, and fascists will say “seeeeee!!??! we need even more personal data to protect the kids!!! OS age verification isn’t enough!!!”
steps in the wrong direction are exactly that, and exactly what this OS bullshit is. everyone having to pay the price for parents who can’t be assed to raise their own kids
edit: i need to add–it’s not actually about the kids. it never was. it’s about collecting every 1 and every 0 that exists about you, for profit, but also for surveillance. every dissenting comment, post, photo, etc will be linked to a unique human being via dozens (or hundreds. thousands?) of data points. before you say “no way,” remember the ridiculous percentage of 1/6 insurrectionists they rooted out, based on social media posts. and that was before AI blew up
remember the ridiculous percentage of 1/6 insurrectionists they rooted out, based on social media posts
To be fair, that was mostly because those people are absolute fucking morons who posted videos of themselves and their buddies involved in, or actually committing, crimes.
What would you say if, to be allowed to open your fridge (the one you own and purchased with your money) in order to pick something to eat out of it, you were required to make a blood test (say through some mechanism included in the door handle) to prove that you don’t have any serious disease preventing you from, say, eating a slice of that delicious cake, or whatever?
The idea might not be completely stupid (one with some serious disease should not not eat what can harm them) but the implementation is not right. It’s considering 100% of the population as suspects by default; just because they exist and have a fridge.
Replace ‘fridge’ with computer, ‘cake’ with online content, and ‘disease’ with ‘being a minor’. That’s how sad that is.
It’s techno-fascism
My calculator doesn’t need to know how old anyone is. Nor does my refrigerator. I suppose a case could be made for a router if you are all onboard for age gating everything privacy and freedom be damned. An OS isn’t just Mac or Windows… the CA law is just so so dumb as written that I have zero faith in anything from Silicon valley.
At least my printer already has a scanner I can put my ID into. How am I going to tell my smart fridge, that I’m not too old for the snacks with cartoon characters on the wrapper?
Voice recognition with the latest brainrot phrases built in, grouped by generation.
“That’s gnarly, bro” - Millennial
“Skibidi Ohio Toilet brah” - Gen Z
"6 7 6 7” - Gen Alpha
Because they don’t care about your age. They want to tie you to your ID, so everything you say and do online can be tracked and tied to you as a person.
Meanwhile the leader of one of their countries has raped women and teenagers and even a couple of children, but they don’t do anything about it. But you can be jailed for decades for seeing a picture or video of it. But the actual act? They don’t care about that. (I’m saying you can be jailed for simply seeing CSAM online, but if you’re a billionaire actually doing the things, you won’t be tried for the actual CSA being recorded.)
So as you can see, it’s not your age, but your identity.
Most people think the Nazis only locked up Jews. Some realise they also locked up minorities. Historians know it was also anyone who disagreed with them. Anyone who spoke out against them. Anyone who wouldn’t wear the armband. And they’re afraid history will repeat. And they’re right to be afraid.
Most people think the Nazis only locked up Jews. Some realise they also locked up minorities.
They started with the impoverished, queer, and disabled.
let’s follow the argument this is to protect children: why does is seem like a good idea to let everybody on the internet know what age your child is?
so if it is not to protect the children, what else could it be?
most homes don’t run their computers in multi-user mode. Even when they do most kids will learn the admin password because parents don’t select good passwords.
Kids are not stupid. Even if some are, there are many kids in school and so any bypass will spread kid to kid fast. For each of the following reread this paraghraph to remind yourself all kids will know this.
kids can install linux /bsd on a raspberry pi or old/cheap computer - this is something I want to encourage. that of course means they are root and can claim whatever age. They can likewise do it in a vm.
if there is any security flaw kids can use it to change their age.
many programs will not check when they should. Kids will install/use these instead. this is a likely exploit vector of actors (in foriegn counties) that target kids - release a new program that does what the kids wants while also doing what they want. (Websites have done bitcoin in javascript while you read them)
who will check? onlyfans probably will, but small web sites spring up all the time, and they won’t bother - many are already illegal (either copyright or illegal content).
Meanwhile many programs that we want kids to use won’t bother to check. why would things autocad check - they target professionals but kids can use them and may even have to.
the above is not a complete list!
Age is useful for ‘buy cigerettes’ that is illegal for kids in some way.
However most of what parents care about isn’t automatically bad and I know plenty of panents who are frusterated because we can’t controll things how we need to without being a helicopter parent (bad). Playing video games is fine in moderation - AFTER YOUR HOMEWORK IS DONE - but we don’t get an easy way to enforce that. My teens are old enough to stay home alone and do homework - but they will not do their homework when they can do something else (this problem has been around since school)
my kids phones have parental controls that I turn on. However they lack a way to enforce homework vs play vs sleep time. There is likely more, this is just what frusterated me yesterday. some things are not gated - my kids have got up at 3am, and connected their school device (under school control not me) to their phone hotspot (turned on who knows when - I can’t block that at all) to play a game that the school will block next week when they figure out it is one kids are playing but they shouldn’t.
people are proposing age verification because they have no idea what else they can do and are frusterated at how bad things are.










