back

by AlexeyBrin·1y ago·view on hn ↗
I wonder how can you implement such a law without forcing people to identify online ? Will they enforce a digital ID that you need to use to access the web or social media ?
15 comments
No comment on the implementation, but I wonder if there's some value in just allowing parents to be able to point to this and say "No, little Fred, you're not allowed to have an Instagram account until you're 16. It's the actual rule."
Yep, the "everyone else has BLAH" argument is a strong one. If we collectively take action through government to set a standard it is MUCH easier to shut down those self-fulfilling claims.
I'm listening to Australian radio right now and a group of mothers just made this exact point.
Seems to me that the better solution is to give parents the ability to observe their kids' activities, and for <16 accounts to be able to operate only when tied with an adult account, which can observe activity...

Of course many will say this can be abused, but all technology can be abused and the reason we're in this mess in the first place is because OS designers haven't figured out that the relationship between parent and child is an important one which should be strengthened, not made weaker ..

Ah yes, teenagers, people with famously little time on their hands and a penchant for following rules.
> allowing parents

What? Why would parents need permission from their government to forbid their kid from having an Instagram account? They're parents, so they can engage in parenting.

Not allowing as in "giving them permission", but "allowing" as in enabling them to do so.

Right now if a parent says "You can't have instagram. Because I say so." the kids answer will be "But I will be a looser noob if I can't. All my friend are on it. Jenny has 5k followers!"

Vs after the ban: "You can't have instagram. This is the law." "But mom! Some of my friends are on it. Jenny has 1k followers!" "Is that so? I will ask Jenny's mom if she knows about that."

It is not going to stop absolutely everything. (Same as prohibiting underage alcohol drinking is not stopping teens from drinking any). But it will put a serious damper on it and fracture the social networks into smaller more underground ones.

Allowing as in “enabling”, obviously.
Because not everyone has a computer science degree.

They probably want to allow their kids to use a computer, so it would be very easy for the kid to go to instagram when they dont look.

I’m guessing you don’t have kids
I have three kids. They have access to devices they use primarily for reading and language/music lessons. They don't use social media and would likely pay a decent level of attention if (in addition to us having explained concerns about social media for children) we indicated that there was government advice/ruling around this.
> we indicated that there was government advice/ruling around this.

Why would any pre-teen / teen care about what government thinks? They care what their friends think about that TikTok they saw during recess, though.

The government currently tendering for providers of different systems. See here [1] and here [2]:

Tender documents released on Monday show the technical trial is slated to begin “on or around 28 October”, with the provider also expected to assess the “effectiveness, maturity, and readiness” of technologies in Australia.

Biometric age estimation, email verification processes, account confirmation processes, device or operating-level interventions are among the technologies that will be assessed for social media (13-16 years age band).

In the context of age-restricted online content (18 years or over), the Communication department has asked that double-blind tokenised attribution exchange models, as per the age verification roadmap, and hard identifiers such as credit cards be considered.

[1] https://www.innovationaus.com/govt-readies-age-verification-...

[2] https://www.biometricupdate.com/202409/australia-launches-te...

The source for "double-blind tokenised attribution exchange models" is this report from July 2024, from the Australian eSafety Commissioner: https://www.esafety.gov.au/sites/default/files/2024-07/Age-A...

They note that existing age verification setups largely either rely on providing ID, or on a combination of manual and automated behavior profiling (face recognition, text classification, reports from other users), both of which have obvious privacy and/or accuracy issues. The "double-blind tokens" point to a summary by LINC explaining how they _could_ be implemented with zero-knowledge proofs, but I could not find an article or a practical implementation (could just be a mistake on my part, admittedly)

At _best_ you end up with a solution in the vein of Privacy Pass - https://petsymposium.org/popets/2018/popets-2018-0026.pdf - but that requires a browser extension, a functioning digital ID solution you can build on top of, and buy-in from the websites. Personally, I also suspect the strongest sign a company is going to screw up the cryptographic side of it is if they agree to implement it...

> "a functioning digital ID solution"

A functioning digital ID solutions seems like table stakes for anything in 2024.

The operative part being "that you can build on top of", because the "ID token" approach means it now has to act as essentially a mini-OAuth-provider for many other websites, not just government services
Sales of stick on mustaches will skyrocket
It's a bit wild that instead of parents just being responsible and teaching their children properly, we'll resort to neutering privacy and freedom on the Internet.
Making it illegal could make it taboo, kids are less likely to talk about it in fear of "getting caught" and less talking means less usage.

This is not like porn which is a solitary activity: on social media you have to be social and let everyone know… at least for traditional actually-social media, not content-consuming apps like TikTok.

It's similar to alcohol usage: you can't stop it completely, but also you don't have 50% of kids bringing it to school.

> Making it illegal could make it taboo, kids are less likely to talk about it in fear of "getting caught" and less talking means less usage

So like piracy?

> This is not like porn which is a solitary activity: on social media you have to be social and let everyone know… at least for traditional actually-social media, not content-consuming apps like TikTok

You don't? You can stay perfectly anonymous.

A drop down list of birth dates/years "works" for most age restricted sites - I guess the logic is that if a user is lying about their age, it's not the sites problem.

Article states that sites must demonstrate they are taking reasonable measures to enforce this though - a lot will come down as to how courts interpret that. If they go to the extremes of the KYC laws in australia I imagine a significant fraction of adults will not want to verify their age.

> I guess the logic is that if a user is lying about their age, it's not the sites problem.

If the law is to have any teeth at all, it should be the problem of the service provider.

Say for example that a banned feature for minors is having media feeds based on past watching behavior. Lacking a reliable age verification it's simple for social media companies to remove the feature entirely for all users, if it's unreasonable or impossible for them to implement age verification.

    > extremes of the KYC laws in australia
Can you provide more details about this statement? I never heard anything about it on HN discussions.
I’m not sure how unusual it is internationally but KYC laws in Australia will generally require 100 points of identification, usually satisfied by showing your passport and drivers license. Other options include recent utility bills, your birth certificate, medicare card etc.

The system wasn’t really designed for the internet era and I think a lot of people would not be happy about handing all the personal info over to TikTok or Facebook

As much as I am grateful for most of GDPR, it has shown that leaving the implementation of anything to websites is a recipe for disaster.

It's gonna be cookie banners 2.0.

I bet a lot will just ask for a credit card number, like in those old scam fake-porn websites from the late 90s/early 2000s.

There’s a near-zero chance of getting caught driving without a license. Despite not having a drivers license checking mechanism, people generally don’t drive without a license because of the mere fact that it’s illegal.

Societal signaling is pretty powerful.

RE ".....how can you implement such a law..."

Request the social media platform to implement the restriction. The large social media platform have billions $ cash , so if that "really want to implement it" it should not be a problem.

However, I expect social media companies to "drag out every reason , why they can ot implement it..." - since it does not benefit the social media company. ... and would reduce its user base ...

> Request the social media platform to implement the restriction. The large social media platform have billions $ cash , so if that "really want to implement it" it should not be a problem.

I'm sure that Facebook, Google and TikTok will be delighted to make it mandatory that Australians send in photos of their face, passport and driving license.

But is it good for Australia to have their citizens hand such mountains of PII to unaccountable foreign megacorporations?

RE "...is it good for Australia to have their citizens hand such mountains of PII to unaccountable foreign megacorporations...." NOT NEEDED , Mega Corp needs to have office in Australia where such documents are checked. Document never leaves Australia.
You don't!

That's exactly what they're aspiring to here, following on from a well-established pedigree of Australian lawmakers and their dysfunctional relationship with the Internet.

You do! It already happens - just not for everyone.

Example:

https://m.facebook.com/help/582999911881572

I don't think lawmakers should describe HOW things are done necessarily. Here it's enough to say that "unless you can be 100% sure your user is above age X, then you can't provide them service Y or feature Z".

It might not even be the desired outcome to have identification, the better outcome could be to have feature Z stripped for all users (for example video feeds based on past watching behavior).

It’s happening on porn sites in some states in the US right now. When you visit the site, they ask you to validate with your ID.
Hell of a time to run a VPN or a blackmail service... Porn site profiles with activity history + real traceable identities will make the Ashley Madison leak look quaint.
How long are VPN services for consumers like that going to be viable? All the 5 eyes countries are trending in the same direction and they US isn't shy to press other countries to follow their regulations with the threat of being sanctioned.
How so? Ashley Madison was a service for cheating. This would be for people watching porn - how is that worse?

The history is extremely unlikely to be available to the id validator (beyond the domain at most). VPNs can't see the actual history either.

They're probably referring to the scope. Very few people were directly impacted by Ashley Madison (though there was at least one reported suicide due to the leaks), but lots of people watch porn and most of those people would not be too keen on their browsing history being leaked even if it's relatively tame, and especially if it's not.
You don't necessarily need to actually attempt to globally enforce it. It's like speeding, right? Everybody knows the law, and a lot of people choose to break it. We can't check everybody's speed all the time, so instead we selectively enforce.

The real change though comes from parent's perceptions. Right now there's age limits of 14-years-old on most social media platforms, however most parents just see this as a ToS thing, and nobody cares about actually violating it. Once it becomes law, the parents are suddenly responsible (and liable) for ensuring their children are not breaking the law by accessing social media. It's not going to stop everybody, but it'll certainly move the needle on a lot of people who are currently apathetic to the ToS of social media platforms.

Not true. Only the social media companies will be liable. It’s an important part of the legislation.
Yeah, you're right about the liability part. But regardless, as a parent of teenagers, being able to justify an unpopular decision with "it's the law" instead of "research shows it's potentially bad for you in the medium to long term" is extremely valuable.
The government is being deliberately non-prescriptive about that, as they are about what qualifies as 'social media' (statement of fact - no comment on the approach itself). Ideally the legislation is accompanied by a government digital service that allows 3rd parties to verify age _without_ divulging full identity, but I don't see that side of things being discussed anywhere down here :(
They seem pretty clear [1] about what social media is:

Social networks, public media sharing networks, discussion forums, consumer review networks.

[1] https://www.esafety.gov.au/sites/default/files/2023-12/Phase...

They haven't got the competence to implement it even if they wanted to.
Well, funny you should mention that - the AU government ID system (used to access govt services like medicare and tax), has very recently been rebranded from MyGovID to MyID. Most states have already got digital drivers' licences.
Same as alcohol. If you supply your kids with alcohol, or even have it at home and they get drunk without your knowledge, you'll be in trouble.
Not sure that is the best example as many states have exceptions to allow parents to legally give their children alcohol so that scenario you devised could be completely legal.
Law should not be excessively prescriptive, especially in the case of rapidly-evolving technologies (and business sectors) for all the obvious reasons.

What's far more useful is to propose effective incentives and disincentives, and let the participants work this out for themselves. There are some useful principles and examples which come to mind:

- Business is profit-oriented. Attack the basis of profits, in a readily-identifiable and enforceable way, and activity which pursues those markets will tend to dry up.

- Business is profoundly risk-averse. Raise the risks of an activity, or remove protections or limitations on threads (e.g., Section 230 of the CDA in the US), and incentives to participate in that activity will be greatly reduced. Penetrating corporate and third-party veils would be particularly useful, in this case, of service providers (aiding and abetting in a proscripted commerce) and advertisers (profiting by same). Lifting any limitations on harms which might occur (bullying, induced suicides, addiction, or others) would similarly be crippling.

As to how age might be ascertained:

- Self-reporting. Not terribly reliable, but a decent first cut.

- Profiling. There are exceedingly strong indicia of age which can be made, including based on a particular account's social graph, interests, online activity, location data (is the profile spending ~6h daily at an elementary school, and not lunching in the teacher's lounge?), etc. One strong distinction is between legislation and regulation, where the latter is imposed (usually with rulemaking process) through the executive branch (SCOTUS's Loper v. Raimondo being a phenomenally stupid rejection of that principle). Such regulation could then on a more flexible basis identify specific technical means to be imposed, reviewed, and updated on a regular schedule.

- Access providers. Most people now access the Internet through either fixed-location (home, work, institutional) providers, or their own mobile access provider. Such accounts could well carry age (and other attestation) flags which online service providers could be obliged to respect as regards regulation.

Jumping in before a few obvious objections: no, these mechanisms are not perfect but I'll assert they can be practically effective; and yes, there are risks for authoritarian regimes to abuse such measures, but then, those are already abusing present mechanisms. I'd include extensive AdTech-based surveillance in that, which is itself ripe for abuse and has demonstrated much of this already.

(That said, I'd welcome rational "what could possibly go wrong" discussion.)

Remember the Silicon Valley episode where they would have been fined $21 billion for not verifying the age of PiperChat users? Same way. All companies are one slippery slope away from being fined by Missouri for not protecting children enough. Or Australia.