Of course many will say this can be abused, but all technology can be abused and the reason we're in this mess in the first place is because OS designers haven't figured out that the relationship between parent and child is an important one which should be strengthened, not made weaker ..
What? Why would parents need permission from their government to forbid their kid from having an Instagram account? They're parents, so they can engage in parenting.
Right now if a parent says "You can't have instagram. Because I say so." the kids answer will be "But I will be a looser noob if I can't. All my friend are on it. Jenny has 5k followers!"
Vs after the ban: "You can't have instagram. This is the law." "But mom! Some of my friends are on it. Jenny has 1k followers!" "Is that so? I will ask Jenny's mom if she knows about that."
It is not going to stop absolutely everything. (Same as prohibiting underage alcohol drinking is not stopping teens from drinking any). But it will put a serious damper on it and fracture the social networks into smaller more underground ones.
They probably want to allow their kids to use a computer, so it would be very easy for the kid to go to instagram when they dont look.
Why would any pre-teen / teen care about what government thinks? They care what their friends think about that TikTok they saw during recess, though.
Tender documents released on Monday show the technical trial is slated to begin “on or around 28 October”, with the provider also expected to assess the “effectiveness, maturity, and readiness” of technologies in Australia.
Biometric age estimation, email verification processes, account confirmation processes, device or operating-level interventions are among the technologies that will be assessed for social media (13-16 years age band).
In the context of age-restricted online content (18 years or over), the Communication department has asked that double-blind tokenised attribution exchange models, as per the age verification roadmap, and hard identifiers such as credit cards be considered.
[1] https://www.innovationaus.com/govt-readies-age-verification-...
[2] https://www.biometricupdate.com/202409/australia-launches-te...
They note that existing age verification setups largely either rely on providing ID, or on a combination of manual and automated behavior profiling (face recognition, text classification, reports from other users), both of which have obvious privacy and/or accuracy issues. The "double-blind tokens" point to a summary by LINC explaining how they _could_ be implemented with zero-knowledge proofs, but I could not find an article or a practical implementation (could just be a mistake on my part, admittedly)
At _best_ you end up with a solution in the vein of Privacy Pass - https://petsymposium.org/popets/2018/popets-2018-0026.pdf - but that requires a browser extension, a functioning digital ID solution you can build on top of, and buy-in from the websites. Personally, I also suspect the strongest sign a company is going to screw up the cryptographic side of it is if they agree to implement it...
A functioning digital ID solutions seems like table stakes for anything in 2024.
This is not like porn which is a solitary activity: on social media you have to be social and let everyone know… at least for traditional actually-social media, not content-consuming apps like TikTok.
It's similar to alcohol usage: you can't stop it completely, but also you don't have 50% of kids bringing it to school.
So like piracy?
> This is not like porn which is a solitary activity: on social media you have to be social and let everyone know… at least for traditional actually-social media, not content-consuming apps like TikTok
You don't? You can stay perfectly anonymous.
Article states that sites must demonstrate they are taking reasonable measures to enforce this though - a lot will come down as to how courts interpret that. If they go to the extremes of the KYC laws in australia I imagine a significant fraction of adults will not want to verify their age.
If the law is to have any teeth at all, it should be the problem of the service provider.
Say for example that a banned feature for minors is having media feeds based on past watching behavior. Lacking a reliable age verification it's simple for social media companies to remove the feature entirely for all users, if it's unreasonable or impossible for them to implement age verification.
> extremes of the KYC laws in australia
Can you provide more details about this statement? I never heard anything about it on HN discussions.The system wasn’t really designed for the internet era and I think a lot of people would not be happy about handing all the personal info over to TikTok or Facebook
It's gonna be cookie banners 2.0.
I bet a lot will just ask for a credit card number, like in those old scam fake-porn websites from the late 90s/early 2000s.
Societal signaling is pretty powerful.
Request the social media platform to implement the restriction. The large social media platform have billions $ cash , so if that "really want to implement it" it should not be a problem.
However, I expect social media companies to "drag out every reason , why they can ot implement it..." - since it does not benefit the social media company. ... and would reduce its user base ...
I'm sure that Facebook, Google and TikTok will be delighted to make it mandatory that Australians send in photos of their face, passport and driving license.
But is it good for Australia to have their citizens hand such mountains of PII to unaccountable foreign megacorporations?
That's exactly what they're aspiring to here, following on from a well-established pedigree of Australian lawmakers and their dysfunctional relationship with the Internet.
Example:
It might not even be the desired outcome to have identification, the better outcome could be to have feature Z stripped for all users (for example video feeds based on past watching behavior).
The history is extremely unlikely to be available to the id validator (beyond the domain at most). VPNs can't see the actual history either.
The real change though comes from parent's perceptions. Right now there's age limits of 14-years-old on most social media platforms, however most parents just see this as a ToS thing, and nobody cares about actually violating it. Once it becomes law, the parents are suddenly responsible (and liable) for ensuring their children are not breaking the law by accessing social media. It's not going to stop everybody, but it'll certainly move the needle on a lot of people who are currently apathetic to the ToS of social media platforms.
Social networks, public media sharing networks, discussion forums, consumer review networks.
[1] https://www.esafety.gov.au/sites/default/files/2023-12/Phase...
What's far more useful is to propose effective incentives and disincentives, and let the participants work this out for themselves. There are some useful principles and examples which come to mind:
- Business is profit-oriented. Attack the basis of profits, in a readily-identifiable and enforceable way, and activity which pursues those markets will tend to dry up.
- Business is profoundly risk-averse. Raise the risks of an activity, or remove protections or limitations on threads (e.g., Section 230 of the CDA in the US), and incentives to participate in that activity will be greatly reduced. Penetrating corporate and third-party veils would be particularly useful, in this case, of service providers (aiding and abetting in a proscripted commerce) and advertisers (profiting by same). Lifting any limitations on harms which might occur (bullying, induced suicides, addiction, or others) would similarly be crippling.
As to how age might be ascertained:
- Self-reporting. Not terribly reliable, but a decent first cut.
- Profiling. There are exceedingly strong indicia of age which can be made, including based on a particular account's social graph, interests, online activity, location data (is the profile spending ~6h daily at an elementary school, and not lunching in the teacher's lounge?), etc. One strong distinction is between legislation and regulation, where the latter is imposed (usually with rulemaking process) through the executive branch (SCOTUS's Loper v. Raimondo being a phenomenally stupid rejection of that principle). Such regulation could then on a more flexible basis identify specific technical means to be imposed, reviewed, and updated on a regular schedule.
- Access providers. Most people now access the Internet through either fixed-location (home, work, institutional) providers, or their own mobile access provider. Such accounts could well carry age (and other attestation) flags which online service providers could be obliged to respect as regards regulation.
Jumping in before a few obvious objections: no, these mechanisms are not perfect but I'll assert they can be practically effective; and yes, there are risks for authoritarian regimes to abuse such measures, but then, those are already abusing present mechanisms. I'd include extensive AdTech-based surveillance in that, which is itself ripe for abuse and has demonstrated much of this already.
(That said, I'd welcome rational "what could possibly go wrong" discussion.)