> There are many ongoing discussions about whether to introduce technical measures to block or remove children and adolescents from certain digital services. In the report, the Norwegian Consumer Council cautions against rushing into such measures, and presents numerous principles that any such solutions must adhere to before potentially being implemented.
>–Age verification may seem like a relatively simple technical solution to a larger problem, but involves significant challenges related to the rights of children and adolescents, including privacy, social and political participation, and the possibility to seek information, says Inger Lise Blyverket.
>–It is also important to note that introducing such measures would require everyone to identify themselves online, which could mean that people over the age limit are exclud ed. Many adolescents will also likely be able to circumvent such technical barriers.
>Before considering introducing such technical barriers, several criteria must be fulfilled. This includes, among other things, that the use of an age verification system is proportional to the problem one wants to solve, does not lead to the exclusion of vulnerable groups and individuals, and that it safeguards security and privacy.
Press release in English: https://www.forbrukerradet.no/siste-nytt/tech-companies-must...
This seems like a solvable problem. Imagine there is an age verification authority that people can use to prove their age (upload a drivers' license or something). Websites can issue a cryptographic challenge for age verification that does not include the details of the website. The user then completes the challenge at the verification authority and is issued a token (that does not include the true identity of the user) proving they meet the required criteria. This way, the users' online activity is shielded from the verification authority and the users' true identity is shielded from the website.
Of course, none of this solves the problem of having someone else log in for you but that's a different issue.
These regulations do not necessarily apply only to the major platforms. If you run a phpBB forum in Australia with a few dozen old guys discussing steam trains, you will also be in scope of Australia's proposed regulations; that is a "social media" platform.
[1] Anonymous attestations by trusted authorities. IE a Login.gov service that returns a token indicating that the user is an adult without providing identification details about that user.
Your compromise sounds far worse to me than all the bots, extremists, vulgarity or whatever other problem it's supposed to solve.
Again, if done correctly, the thing you give them is not the actual thing you got from the government but rather the result of running that through a transformation. The transformed token can still be recognized as certifying your age, but if given to the government entity they would not be able to tell which token they issued it is based on.
Yeah, but in all likelihood _that isn't one of the options_.
The moral panics and "think of the children" and general ignorance around these things is going to drive action at some point.
The options are "implement the least bad thing we can" or "wait for legislators and regulators to dictate how it will work".
I'd rather see Apple (who already has some semblance of ability to verify your age as you usually have payment methods and things tied to your account) come in and implement some protocol involving a bunch of cryptography I can't even begin to understand that preserves privacy and anonymity, have that gain a foothold, and have eventual regulations either seen as unnecessary or effectively having to support this sort of workflow.
The alternative I see is at some point we're going to get a regulation that involves everyone having to send a photo of themselves holding up their driver's license all over the place in order to access half the internet.
I am so tired of the naivete that just because something isn't direct somehow translated to "we're safe from the possibility of". Especially from amongst an audience presumably composed of people who deal with manufacturing layers of indirection on a day-to-day basis.
Lets just do a thing that leads to a bad outcome. Don't worry, it doesn't directly lead to a bad outcome. You just need to aggregate a few other things first! 2 years later Oh my goodness, how could anyone have forseen someone would implement the requisite integrations with the right channels of indirection to cause the bad thing to happen!
Besides which, the described service, (provisioning a token signifying that the bearer is... Well... Anything really) without at some point on the backend having sufficient connection to a person in the data with whom you are claiming the assertion represented by your is true, and by extension, is capable of associating online traffic utilizing said token with a bearer identity is no different than just believing when the client clicks a button saying "yup, totes that". It is a non-solution. It does not solve the actual problem. You can't and nor should you even attempt to solve the stated problem. You're just mild inconveniences for the chance at creating slightly more remote, but far more severe problems.
Worse I don’t think digital id is the end goal but rather pervasive identity across all spheres of life like some countries already have. It’s a uniquely powerful tool to control a population. It actively alters behaviour. Bit like you’re not likely to do something that’ll mess up your credit score
Age recognition as a service is available now.[3] Mean error is about 1.3 years for 13-17 year olds.
[1] https://www.theverge.com/2021/7/9/22567029/tencent-china-fac...
[2] https://www.nytimes.com/2021/07/09/business/tencent-games-us...
https://news.bloomberglaw.com/tech-and-telecom-law/big-tech-...
Aguably the so-called "tech" companies running "video sharing platforms", i.e., thinly-veiled surveillance and data collection operations, already know the age of users, among other things. If they did not have this information then how could they sell targeted advertising.
Remember when "Big Tech" companies told the government they could "self-regulate". Not when it reduces their profits.
No other comments as I'd be guessing the content from the title.
Then they turn around and want 'show me your papers' laws.
Require ID's.
Digital Tracking.
Showing a driver's license to a police officer when stopped for a traffic violation seems reasonable to me. Showing a passport when crossing an international border seems reasonable. Showing some sort of ID to vote seems reasonable. Showing some sort of ID to receive social security or some other government-issued money seems reasonable. Showing a hunting or fishing license to a game warden seems reasonable.
But showing a government ID to access a website or post something online or walk down the sidewalk or buy something from a store would all seem unreasonable, dystopian and police-statey.
Show your birth certificate to use a bathroom. (that is only for them? lot of old people I can't tell if they are male/female, better check their documents) (NC law, struck down during Democratic times, now back on table)
Carry proof of Citizenship at all time's. (that is only for non-citizens? Really, everyone needs proof or how do authorities know?) (Arizona Law, struck down during Democratic times, now back on table)
Once you are trying to target one group, you actually impact everyone, because, everyone needs the IDs to prove they aren't in the targeted group.
At worst, with a bad implementation, to steal someone's digital identity you need to steal their smartphone and be able to fully unlock it -I don't even know if any solution really is that bad! At best, you need to provide your live face. I just checked, for Austria, on iOS the governments app requires Face ID for example. For the privacy minded: No biometrics online, just offline, local Face ID! Stealing my phone and knowing my lock key is not enough! Some other governments might offer online authentication-via-face+liveness solutions though, which are also safe, but more of a privacy concern.
One more thing: All those solutions offer a way for a service-provider to just ask for a service-provider-specific persistent identity + age verification only. No name, birthday, selfie or cross-service identifier necessary!
tl;dr - the reptilians are not stealing your identity and biometric information, this is not the mark of the beast and this makes services more trustable, safer and cheaper to use.
Even if working solely as advertised, and somehow implemented flawlessly without compromising a user's right to modify their device, I think the stated goal itself is contentious. Alt/throwaway accounts are a useful (and for some, necessary) tool for maintaining privacy. I do not want identity-bound "rationing" of certain types of online content, nor do I see elimination of "unlawful account sharing" as a positive.
i think the subtle push to mobile phone based mias is the real mass rollout of digital ids.
Are they uneducated (no way), sinister or what?
I am legitimately baffled. You can have one psychopath pushing for mass surveillance and corrupt or cowardly people will follow suit.
But for this kind of asinine and borderline insane behavior to emerge in multiple places at once?
A similar tendency is also observed with governments too. (Durov, anyone?)
A fairly inconspicuous personal example: I have had people on the internet act very despicably simply due to me mentioning my age. Anonymity/pseudonymity in these times is vital.
Why?
Just because it’s my deal
Digital IDs when accessing porn: world says nay.