The same applies online/digitally except that you can very likely distribute the same ID to many minors without getting a new one allocated.
I’m in the “we should protect kids online” camp, but I am not sure there’s a real way to do it without compromising privacy for everyone.
Of course there is, it's easy! You take a white list approach instead of an auth one. The default is that the general Internet is exclusively for adults. Anonymous = adult. Then use the DNS system to make a set of .kids ccTLDs, with government controlled registries. Then legal standards can be set for who gets a .kids.cc domain and what content is allowed, what meta-data is required, what services can be provided (which could be blanket stops, like no ads or social media under age 7, or granular, like "age 7-11 can only talk to registered educators or other children within given domains"), and so on. Then everything is in place to have router manufacturers give parents a super easy interface (and technical ones can do their own easily) to add their kids, have a password for each kid, and either automatically filter by general age, or let parents drill in and select specific categories or the like. And it'll all Just Work. Yeah it'll be a lot less stuff then on the main internet, but with government money to fund things and parent-based payment all abstracted from what kids see there will be as much as there was on PBS or the like back in the day.
So specific ID/passwords/parental control is exclusive to those who haven't reached majority. Once they do they an just dispense with it and access everything like we do right now. The entire approach being taken everywhere is 100% backwards, because it's not about the kids at all it's about control over adults.
No scheme is going to issue cards/tokens that can be traded between people, that's obviously unworkable.
Untraceable is for the consumers of the cards obviously, but in order to have trust they need to be traceable for somebody to verify them. The government can already determine who you are and already requires you to prove that at certain points, this is not a new invention of government it is required for governments to function.
Parent have an obligation to loosen the restrictions, and, what, the government has obligations to tighten them and deprive them of the spaces where they can act independently?
I don't care to talk about the premise itself. This reasoning is absurd.
We have many place in real life where we already have to prove our age or identity but somehow the internet should be excluded
I actually don't have to show my ID when I buy alcohol because I'm old. There's a material difference between an electronic record being submitted, passed through and stored on several different servers, and somebody seeing you and seeing a grey beard and saying, yeah, you can buy that beer. The worst case scenario in real life is that the bouncer at the bar looks at your ID, seems real enough, checks the date, matches the picture, and that's it. There is no record being stored, there is no log. It's not equivalent to the vast majority of online age verification mechanisms in use today.
Today I can walk into a shop and buy alcohol without showing my ID.
I can also walk into my local library and read any book I wish to, some with adult themes. I could do this as a teenage too. I also did this in my own school library.
Demanding to see ID to access online content is a terrible idea and it is the parent's responsibility to look after children. It should be an understanding between the parent and child on what they should be accessing online. If that breaks down then the parent should do their job of being a parent. Take the device away and punish the child.
That is beside the point. I'm talking about the incoherent argument about a parent's supposed obligation to stop parenting and the government taking over. There are three premises here asserted by the author: 1) the child's need for independence, 2) a parent's duty to stop parenting, and 3) the government stepping in. Number 1 is contrary to 3, and I don't agree with either 2 or 3. What do you think?
The government does not get to put child locks on my liquor cabinet, or even keep me from leaving booze out on the counter. They get to restrict businesses from selling to people without identification. Note that this has already always been the case on the internet, too.
> Here is cryptographic proof that I hold a valid credential proving I am over 18. You can verify the proof, but you learn nothing about who I am.
Is this true though? I am genuinely interested as I haven't looked into the details, but must the user not at least also disclose who the issuer of the credential is so the verifier can verify it against a public key? This also reveals at least the nationality of the user and could be misused to block access to foreigners using VPN.
Yes, any age verification or identity verification system can be used to implement geoblocking. It actually improves the situation. Currently services who want or need to block access to foreigners have no alternative than to block access to VPNs. With a suitable attestation, a service could choose to allow access from VPNs that come with such.
Guess who is heavily using social media today and unreflectively repeats fake news.
Although this also hits people < 30 years as well and maybe older ones as well.
Although I would also think that a early contact might even build up some resistance here.
What _is_ different? AFAIK nobody was playing with addictive aspects of a BBS and even less so in newsgroups.
>AVI [Age Verification App Instances] SHOULD support the generation of Zero-Knowledge Proofs
Maybe I'm not seeing the full picture but as long there is a 'should', the whole thing is worthless. Keep in mind, national states need no implement their own solutions and AFAIK during the pilot phase ZKP was just skipped. Could be for other reasons (was not finished yet) but in the end a 'should' is a 'should' and no 'must'.
Source: https://ageverification.dev/av-doc-technical-specification/d...
The author described a narrow path that provides "kid safety in the internet" without sacrificing the general population privacy.
Is it technically possible to implement the way he suggests? Yes. Will it be implemented that way? No.
There are people who can affect the way this verification will be implemented who are genuinely interested in more surveillance, heck, remember chat control that is an ongoing fight in a very similar vein, there is a global desire in politicians to get more control over the communications.
To me the author seems either naive or straight up malicious.
The 'it can't be done' arguments are the worse. By spreading the idea that age verification can only be done by violating privacy means, we will end up with a system that violates privacy controlled by vested interests. Like the one already in place where you upload id. Politicians can easily sell out and will be cheered on as they entrench the system. But if that energy was spent pointing out the alternative, that we can do this in a privacy protecting way, then it can force politicians to legislate the right way. I'm looking forward to the EU system actually being rolled out, hopefully reaching their goal of remaining privacy protecting, so I can point to it and insist to my government that we can do better.
I actually don’t think it is. Fundamentally this kind of certificate is going to be revocable. It’s untenable politically to hand out irrevocable attestations that can be handed off to minors. If you allow that, the system has failed to prevent minors from accessing adult materials, and if you don’t then the system has failed to preserve privacy.
> To me the author seems either naive or straight up malicious.
I think just naive.
> When children are very young, parents can set strict boundaries. But as kids move into their teens, parents also have an obligation to loosen them. Teenagers need spaces where they can act independently, make decisions, and talk to others — where they can learn to navigate the world without a parent looking over their shoulder.
You are still responsible. If you allow your child more freedoms, you are still responsible if something bad happens. Your choice to loosen your parenting shouldn't become everybody else's problem. Some parents for example allow children to try a small quantity of alcohol - if your child is suddenly found drunk, they shouldn't ban alcohol for sale everywhere.
I would go the other way, if it's found as a parent that your child is drinking, smoking, etc, then this carries punishments for the parents. I think it should also be punished if they are found accessing online services targeted at adults.
> The digital version is the same idea, with cryptography. An authorized issuer verifies your age once and issues a signed credential:
Sounds great, but there is a clear agenda for digital IDs that 'they' are trying to shoehorn in with this "protect the kids" thing. They tried rolling it out digital IDs in the UK in 2006 [1].
As I said the other day, what really makes me suspicious is that most Western countries suddenly have the same idea at the same time. This isn't just some random politician wanting to protect children, this is an international concerted joint effort to roll out a form of mass censorship.
> So instead of fighting a system that is built to preserve privacy, we should be fighting to put the right checks in place — the ones that guarantee the implementation actually honors it.
The objective is the system itself. Once there is a control in place to stop you accessing these services/systems, changing the exact unlocking procedure is trivial and can be done gradually. We'll all just be frogs in slowly boiling pots.
I am not worried for myself and for others who are technically inclined, we will just silently find and implement solutions for ourselves and any others who have the energy and inclination to use them. This is worst, as usual, for the most vulnerable among us. Those most in need of the information which they will not be able to access. Every freedom comes with risks and responsibilities, freedom of information maybe more than any, but the harms of limiting information are much more unacceptable than any caused by its unhindered natural flow. You can propagandize and scheme to your hearts content. You can lobby your governments to implement your halfbaked schemes. But in the end it won't work... Because people like me and millions of other will just not comply. We will build our own networks if need be, but we will do just about anything rather than accept your terms.
For adults.
There is information and images that are developmentally harmful to children. As the author says, this is no different from drugs, alcohol, tobacco, or gambling.
If you can’t understand that, you either don’t have children, have a screw loose, or are a child predator.
It isn't, but it is absurd that the first things we're talking about is banning kids from social media. "Children do not have a right to free speech" is not a defensible position. In fact it's the sort of thing that should get Nigel Uno and the Kids Next Door on your ass.
The problem is that the argument against child access to social media is a proxy for a different, larger problem: social media is not a public forum anymore. They make heavy use of automated editorialization over the content you're allowed to see, specifically to keep you engaged and addicted. This is absolutely harmful, but it's not uniquely harmful to kids and kids alone. When we regulate these harms for children only, what we're also saying is "Adults can fend for themselves, only children deserve protection".
And, to be clear, social media is more harmful to adults than it is to kids, if only because the stakes are higher. Targeted advertising is absolutely amazing for criminal scammers who want to find specific kinds of marks. This is only possible because we allow social media to accumulate massive amounts of data on people - basically, a privately-run Stasi.
I agree that zero-knowledge proofs would be the least harmful form of age surveillance.
Can they also provide other ZKPs? Specifically to attest that someone is a unique human being? Humanity verification is incredibly important to fight against propaganda online[1]
1 - https://blog.picheta.me/post/the-future-of-social-media-is-h...
It is an interesting idea you bring up. These sort of disinformation campaigns are making news everywhere, over and over, and this mechanism easily adapted. Like a blue check mark but actually useful, being able to tell social media posts written by a bot farm apart from social media posts written by an arsehole.
No kid under 20 will use a PC or Laptop for anything except for school work. All kids under 20 are on Cell Phones and nothing else. PC usually mean work to them, Cell Phones mean fun.
Cells will have age verification if they do not already have it yet the will. Also I think Cells have lots of other personal information (PI).
To me, Age Verification on PCs is a first step to moving these devices into a Cell Phone type of walled garden. World Govs. want to know what you are doing on all your devices. Luckily with Linux (most distros) and the BSDs, you can easily avoid being "watched".
The trick is that you don't need to prove anything. The government hands out an attestation that the holder meets criteria required to meet a government regulation. The government has taken responsibility. It is why you would require an EU attestation from EU users, and a US attestation from US users.
Agree or disagree, this is an earnest post about a relevant topic.
No and no. So, I do not support schemes like this.
And just like in those cases, what is to prevent someone who is of age giving their ID to someone underage?
If you handed over your id, and the person checking it made a photocopy and handed it to a police officer who put it in a file in a briefcase they carried, you might feel differently.
What is interesting is that checking physical ID places a burden on the bar. Bars get fined or worse if they do a poor job, or even just take the fall if the kids are more capable than the bouncers. With these attestations though, the government is takes responsibility. The connection is attested by gov to be legal, the gov can't turn around and claim it was illegal. They can't go after you, just the person who enabled the fraud.
So not a perfect system, but an improvement over the status quo.
Maybe the EU knows it's untenable and is still moving forward because they will be able to demonstrate to the public that privacy enables abuse, creating pretext to make the system not private anymore after it's already been implemented.
For instance, roblox is full of pedophiles. Minecraft displays pro-surveillance propaganda to my kid every time they run a game that does not let M$ read their messages.
Even “educational” sites like blooket do not bother to check their content for kid safety or accuracy.
I’d rather police this stuff myself, so I do.
Every implementation of age verification I have seen is counterproductive, and designed to take control away from parents in order to help companies monetize access to children.
The people creating these systems aren’t dumb. They work as designed, which means they are actively harmful to kids and society at large.