RandomGerm4n 17 hours ago

I'm fundamentally opposed to age verification because it usually leads to mandatory account creation no matter how privacy friendly the age verification process itself may be. It's already extremely annoying that, for example, on YouTube, you can no longer watch many videos without an account. Furthermore, the whole thing also reinforces monopolies. Once you've verified your age on one platform, the barrier to switching to another is even higher than before.

The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating. Once this were established, websites targeting all age groups would have a strong incentive to participate. Otherwise, they would suddenly become invisible to a large portion of their underage users.

  • azernik 16 hours ago

    Your second paragraph describes the approach in the blog post almost exactly.

  • account42 16 hours ago

    And instead of an age you could even make the indication about what is potentially objectionable so that parents can choose when to allow their kids to see what - and adults can also choose to avoid certain things.

    • iamnothere 14 hours ago

      Exactly, without this you’re handing the power to decide what is “appropriate” to someone else.

      • godelski 13 hours ago
          > you’re handing the power to
        

        The user?

        • johnnyanmac 12 hours ago

          The server owner. If your parent won't curate the content, they will.

        • iamnothere 12 hours ago

          I’m in favor of voluntarily giving the user (device owner) full control over what categories of content they want to allow. Age buckets don’t do that.

          (This includes giving the option for “everything is allowed” without any kind of verification. You bought it, you own it.)

      • codedokode 6 hours ago

        No, you are handling the boring work to someone else. Most non-geek people, I assume, are not interesting in manually configuring the website white lists, so there should be a single "child mode" checkbox for 99% of population and "configure" for the rest of us.

    • LelouBil 14 hours ago

      Force a PEGI-like system for every apps please.

      It would be awesome.

      • Marsymars 12 hours ago

        The App/Play stores already basically have that, you can't submit apps without age ratings.

        One spot where it's a bit weird is for utility apps that don't have any "mature" content but that obviously isn't intended for kids, so e.g. your tax prep app gets rated as "Ages 4+".

        • LelouBil 11 hours ago

          Yes, that's why the system should be a bit different.

          It should indicate notable features that influence the rating, like PEGI includes "online content" "gambling" and so on

        • giantg2 9 hours ago

          Is exposure to a tax app going to cause harm to a 5yo? This doesn't seem like a real problem.

        • codedokode 5 hours ago

          There is nothing wrong if a teenager wants to know more about taxes. Although exposure to tax rates might cause a slight emotional trauma.

    • 1dom 13 hours ago

      I might be being overly cynical here, but I think part of the problem is parents expect to give their kids the internet so they don't have to spend so much time/attention with them.

      I think this means any solution which involves active parent participation is going to get shunned by a vocal subset.

      I'm in my mid 30's. When I was very young I remember my Dad semi-regularly having to email or even fax off permission slips to websites aimed at kids before they would create an account for me.

      • forshaper 12 hours ago

        It's what I see happening. None of this would be a big deal if parents were present, but we give our attention to work & entertainment, and find it easier to continue doing that if the kids are also being entertained instead of playing, which caused problems in the physical world.

      • thewebguyd 8 hours ago

        > any solution which involves active parent participation is going to get shunned by a vocal subset

        Then we certainly shouldn't be passing laws mandating age verification. If parents want to abdicate their responsibility over their children, it's not the role of government to enshrine that abdication into law and take over the duty of parenting from them.

        If regulation is to be had, then it should take the form of mandating websites and services provide privacy preserving tools for parents to use, if they want to use them. If they don't, that's on them. Everyone else needn't suffer because a subset of the population has chosen to offload their responsibility into the government and web services.

      • DSMan195276 5 hours ago

        > I might be being overly cynical here, but I think part of the problem is parents expect to give their kids the internet so they don't have to spend so much time/attention with them.

        > I think this means any solution which involves active parent participation is going to get shunned by a vocal subset.

        I don't think that's a fair assessment personally, rather you've missed a key detail that things are significantly more complicated than they used to be, it's not just an 'effort' issue. There is no universal "user is age X" setting that applies to everything everywhere, rather everything has a different system and pretty much all of them are terrible in various different ways.

        I'm very tech savvy and I still struggled just to set up a Microsoft/XBox account for my daughter so that we could play some computer games together. Access to all the different age rating settings is spread across something like three different apps and websites and in my experience they don't even all work consistently. That experience is also not dissimilar from the experience with other types of accounts. For people I know who are less tech savvy it honestly doesn't matter how much time they put into it, eventually they give up and turn off age ratings because something isn't work and even if there's a solution it would take them hours to figure out.

        Point being, if the existing tools were much better I don't think we would be having this kind of conversation.

  • QuadmasterXLII 16 hours ago

    I wonder if it would work to make it illegal to sell ad impressions of underage people. Do whatever you want as long as you can prove its being done to adults, or prove you have no economic incentive to algorithmically engagement bait

  • Steltek 16 hours ago

    > The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.

    I'm afraid you'd get the cookie banner problem but way worse. Everyone that's not Meta/Google/Apple would immediately add a legal CYA "18+" age rating and stop thinking any more about it.

    • grumbel 16 hours ago

      That's how it should be. Make the Internet 18+ by default and sites targeted at younger audiences can add a more detailed rating. Let people configure their devices however they like it.

      The whole problem with the regulation we have right now is that it assumes the Internet is for kids, and everything for adults must be hidden. When we really just should declare the whole Internet as 18+ and the sites for kids should be the specially marked exceptions.

      • goda90 15 hours ago

        Someone would complain that without ID verification kids would be able to sneak onto the regular Internet and therefore we should eliminate privacy on the regular Internet, just like they're doing now.

      • johen8 15 hours ago

        I never thought about that and I find it might actually be the right way for a solution... I was just looking into the Google Play Store now: in Brazil apps need to have an age rating, facebook and instagram for example are 16+, but browsers like firefox, chrome, etc are rated for 'all ages', even though you can access the whole internet through them. If we actually did what you said and inverted the logic: restrict everything to 18+ and specifically mark what is allowed to under-18s it would make parental controls much more effective.

      • kelvinjps10 14 hours ago

        So kids shouldn’t have access to sites like Wikipedia? Banning the internet is not the correct solution many kids depend on the internet to have access to education.

        The argument could be made for banning social media but the whole internet I don’t think it’s the correct approach

        • mrguyorama 13 hours ago

          If we had a "Safe for everyone" public internet and a locked down "Prove you are an adult" internet beside it, nothing prevents wikipedia from being on the Safe for Everyone internet.

          Also, Encarta was a thing. Expensive though.

          Some states would legislate wikipedia onto the "Adults only" web though because they don't like what it says about things like abortion and trans people.

          A lot of ecommerce companies would probably be happy with a locked down adults only internet, because it would kick bot protection up a level, and would require a fairly robust solution to it.

          • adiabatichottub 12 hours ago

            Well... Wikipedia has content that some would consider offensive or unsuitable for children. I'm not in favor of limiting any access to Wikipedia, but I'd consider it a certainty that the day would come when Wikipedia had to decide whether to implement age restrictions or try to police content. I believe that event would change it's governance and social structure in a negative way and significantly degrade it as a public resource.

            • johnnyanmac 12 hours ago

              Likewise, some old history documentaries have gore or nudity. I think our current content ratings systems are not as obtuse as "nipple? R rating".

              >I believe that event would change it's governance and social structure in a negative way and significantly degrade it as a public resource.

              This can and has already been doing even without age verification. We're way beyond government survellaince in many countries.

              • mrguyorama 10 hours ago

                In the US, our content rating systems are absolutely as obtuse as "Nipple? R"

                You traditionally can say one "Fuck" in a PG-13 movie, which will be about brutally displayed murder and violence and how awesome vigilante justice is. But if you have even a couple frames of a single (female, but like, that's its own insane can of worms) nipple, you cannot get lower than an R rating.

                This is all well publicized, despite there not being public standards for the process, and the specific wording of the PG-13 advisory is "Some content may be unsuitable for children under 13", which is weird language to describe what actually happens in practice.

                This is because the rating system is a weird club of "Parents of children in school" in los angeles. It's about as corruptible and sketchy as a system can get.

                The ESRB is similar. Shooting lots of people? Well there's no blood so that can be for everyone. Oh, now you added some red particle effects? Sorry, now it's Mature.

                GTA 3 had an M rating, but a person found that if you hacked the game and changed the code you could play a sex minigame. That caused the game to have an Adults Only rating. Even though it's not something you could do, see, or activate in game at all. And also the game already had functionality to have sex with a hooker and then murder them to get your money back.

                It exists because the dumbest parents went apeshit over yet another fake controversy (Oh my god, D&D has demons!!!. OH MY GOD. This game about saving teenage girls from creatures in a crazy amount of costume who harm them with a 2 foot long grabby arm because the developers wanted to avoid unfortunate implications is JUST TOO SEXY FOR LITTLE TIMMY and we need to make congress bitch and moan about it for an entire week and ban anything that could ever be entertainment)

                They are purposely arbitrary because their purpose is to make the crazy people who write letters to the FTC to arrest someone for daring to have a low cut shirt go the hell away. Those people have absurd and arbitrary triggers.

        • johnnyanmac 12 hours ago

          If Wikipedia can't put in the effort with those millions in donations to get an age rating? I guess not. We know Youtube will.

  • Eldt 16 hours ago

    Many years ago I worked a technical support job for Xbox services, and the amount of calls about "unauthorized charges" was obscene. Xbox provided parental controls, but it required the parent to set up their child's account themselves, and many couldn't be bothered.

    I imagine the same thing will happen here...

    • 1718627440 15 hours ago

      And people give their children cigarettes and liquor, that's bad as well. But that's the responsibility of being an adult. If the adult is deemed not worthy of raising children, society has already established a process of dealing with that too.

  • mrtksn 16 hours ago

    At glance this looks reasonable but how do you enforce that kids connection always goes through the parents control?

    You are just moving the verification point to another gate, it means that no anonymous connections are possible anymore to the entire Internet because we want to allow parents to control their kids.

    You want to use your friends Wi-Fi? Now that requires full identification so that we know that its not some kid trying to look at stuff their parents don't allow.

    Want to connect your cat toilet to the internet? Well, we will need to either cryptographically identify the device or attach its ID to your real ID because we don't want to allow kids look at stuff their parents did not allow and this might just be a proxy device for some nerdy 14 y/o.

    Want to use your old PC? Sorry that's not possible, now all devices that connect to the internet require biometric identification because we can't tell if this is an adult or just some kid using a legacy device to look at stuff their parents don't allow.

    • 1718627440 15 hours ago

      No, the point was that the actual decision happens client side and under the control of the sysadmin (the parent).

      > You are just moving the verification point to another gate

      Yeah, the gate being the decision of legal entities of age, aka. adults.

      > You want to use your friends, Wi-Fi?

      That would still do whatever your parent decided for you.

      > Want to connect your can toilet to the internet?

      Whether the toilet can connect to the network, is the decision of the network administrator, and toilets don't contain UAs, so that wouldn't even have software on them, where you could configure such behaviour.

      • mrtksn 15 hours ago

        You're making the mistake of assuming that every kid has access to identified device and that device is under parent control. You can't make this assumption because that's not true.

        It might be true for some middle class helicopter parents that have iPhones and time to manage and keep it under strict control but there are non-middle class kids out there who just use whatever device they can get their hands on and their parens neither have time nor ability to control that.

        • vorpalhex 15 hours ago

          That's a parent issue, the same as if their kid has a secret stash of cocaine or enjoys dancing in traffic.

          No technical measure can fix stupid.

          • mrtksn 15 hours ago

            That's not parents issue. That's why we go after people who sell or give drugs to kids. Is a serious offense, we don't wave our hands and say its parents problem and not drugging kids is a popular policy unlike drug enforcement for adults.

            • vorpalhex 15 hours ago

              Everything is a parents issue.

              If you are depending on the police to keep your kid from doing drugs, you have failed as a parent. I promise you, your kid can locate drugs better than the cops can arrest low level dealers.

              You as a parent need to teach your kid how to behave (mostly through things like teaching ethics and morals) not by running a safe prison until your kid is 18.

              And yes, I am a parent of multiple kids.

              • 1718627440 15 hours ago

                > not by running a safe prison until your kid is 18.

                And in addition, such an approach, will not lead to a child magically becoming an adult all of a sudden when they turn 18.

              • mrtksn 15 hours ago

                I agree, however the problem is that large number of parents can't do that and it becomes a societal issue. That's why we are talking about that, otherwise it would have been private family issue.

                Drugs, alcohol, teen pregnancy and now social media has become societal issue as enough parents failed to control their kids actions or development.

                • wowyouredumb 13 hours ago

                  I think Darwin had a solution to that.

                  • DANmode 12 hours ago

                    We walked away from it.

              • kelseyfrog 11 hours ago

                If we want parental behavior to change, we have to change the incentives. Parents must be held criminally liable for exposing their children to social media. Until we change the incentives, 'parents need to parent' is just an empty slogan.

            • 1718627440 15 hours ago

              Yeah, but that assumes, that there are people out there, selling smartphones to children at scale. First the price for one is way to large for the financial budget of a child, and second that gets even more price-intensive, after the first one got confiscated by the parent.

              • mrtksn 15 hours ago

                There are literally people out there selling smartphones to children at scale. A smartphone these days can be bought for as cheap as a burger because 2nd hand market exist and its not limited to iPhones.

                • 1718627440 15 hours ago

                  And the child can also go and buy a porn magazin, which is likely to be eventually found by the parent, just like the burner phone you suggest. The former is also going to be cheaper.

                  • mrtksn 15 hours ago

                    Guess what they check before they sell the kid a porn magazine

                    • johnnyanmac 12 hours ago

                      So you're suggesting resellers require ID's to sell smartphones? I completely agree. Not much difference between a porn magazine and a portal to infinite porn magazines.

            • mindslight 15 hours ago

              So sure, we go after anybody who gives or sells devices without basic parental controls directly to kids. So you need to be 18 to buy a phone, which we're 90% of the way to anyway with the way credit cards work.

              The fundamental point is that the Internet is not a daycare. All of these attempts to put the burden on sites boil down to changing this dynamic, recasting the Internet as if it should be appropriate to use as a daycare. Today it's big tech and porn. Tomorrow it's any writing that the the religious reich dislikes. Monday it's technical sites as they can help kids bypass restrictions. Tuesday it's international sites being blocked at the ISP-level because they don't bother with any of this crap.

              We also need to remember the context here, lest we carry water for big tech's continued abuse. The main reason the surveillance industry is reaching for age verification (ie identity verification) is that harm to children is so far the only regulatory cause of action that has been found to stick. Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information. Where what we actually need is to stop their abuse for adults as well - eg data privacy, anti-trust regulation to open up their services to competing clients, and at this point probably straight up regulation of purposely-addictive "algorithmic" feeds.

              • Mezzie 14 hours ago

                > Big tech wants this, so they can continue on with business as usual abusing adults' psyche and personal information.

                I've said before and I'll say again that this approach (strict age gating) also is going to produce a slew of really vulnerable 18 year olds. If I were a sports gambling site, I'd be salivating at getting a fresh crop of 18 year old boys each year who have had zero opportunity to learn how to navigate the Internet and who are legally on the hook for everything they do.

                OnlyFans, likewise, is going to work out great! Now the 17 year old girls turning 18 won't have access to things like the social media of former OF performers or access to any communities where sex workers discuss the downsides of their job or how to stay safe.

                Have to protect the children, don't you know. That way they can be perfectly pure and innocent when they turn 18 and are ready to be exploited. Like fattening up cattle.

                • mindslight 14 hours ago

                  Yes! And this dovetails into a point I really should have made as well. The thing about "age verification" (ie identity verification) is that it puts the decision of what kids should access wholly in the hands of corporate attorneys. For example we can easily imagine a "Facebook4Kidz" website that has many of the same terrible dynamics as regular Faceboot, but that Faceboot's attorneys can justify as being legally compliant. As a parent, you would really want to block this too - while all of these proposals for identity verification and site-based-control claim to solve the problem but leave you with no way to do that!

                  This ties into your comment because as a kid approaches adulthood, as a parent you also want to loosen those restrictions so that they can develop these skills - gradually while under your supervision. Whereas the corporate attorneys will just say that they're strictly off limits, right up until it's then open season as you're pointing out.

                  • Mezzie 14 hours ago

                    Yes!

                    And you want them to learn in a situation where the stakes are lower: at 18, someone can put themselves into a ton of debt or put nudes in the wrong place and just nuke their life in a way that they can't fix for a decade and everyone shrugs and is like 'you're a grown up!'

                    Think of all the kids who back in the day got scammed out of their Neopoints, or lost all of their in game currency in GTA, etc. That's a way, way better way to learn about account security and who to trust than their first experience with scammers involving real money.

                    Is the problem that we're exploiting kids, or is the problem that we're exploiting people? We're not going to be able to protect kids from exploitation in a society/culture that explicitly condones exploitation. If we think exploiting people is fine, actually, as long as they're over 18, then your kids will never be safe, because they will grow up.

                    Even setting aside the obvious examples I listed, binge drinking used to be a huge problem amongst college aged kids. Who's to say that the Internet/social media wouldn't be similar? How many kids are going to flunk out of school because they can't stop watching digital crack and now mom and dad aren't around to stop them? And unlike binge drinking, your body won't eventually revolt against you, and with the addiction consultants The Machine employs, there will always be new content. People grow out of binge drinking because eventually it grows stale and hangovers when you're 35 are far worse than ones when you're 21, but that's not true of social media use.

                    To tie this to other issues, we're already seeing issues with relationship and family formation amongst young people. I'm not sure flash banging them with addictive content when they're in their prime years is the call. If all it took for the Internet to be healthy was holding off until adulthood, we'd expect people who were adults when they started to have a healthy relationship with social media. They very much do not.

        • 1718627440 15 hours ago

          How many children, actually have the money to buy themself another smartphone, or get a smartphone gifted by random people? I bet that's very rare.

          • mrtksn 15 hours ago

            In real life, it doesn't work like this for most people. In real life, kids want something and either the parents agree to buy that and then they no longer bother with that device or the kid saves its money trades something and get that device.

            The idea that a kid gets an expensive device that can't buy by itself and the parents have control or what device the kid gets is a very middle-class assumption. Life isn't that perfect for most people.

            • johnnyanmac 12 hours ago

              With all due respect, this just sounds like justification for lazy parenting. We're 2 generations into the digital era: parents of such an era should have enough digital literacy to make sure their kids do not get in danger.

              Let's use another analog: Kids want sweets and parents either agree to buy that and no longer bother with their diet, or saves money to go to the candy store. Yet if a kid gets too unhealthy we (IMO, rightfully) have CPS sent to their house to investigate their home life.

              Kids were never meant to be a convenience. And parents talked about here aren't rich enough to delegate their parenting off to someone else. Take a few hours to research what you give to your kid and monitor what they might get outside of your vision.

              • subscribed 11 hours ago

                It's okay that it doesn't match your experience but it's also a case that you shouldn't extrapolate your expectations and experience onto others.

                There's plenty of overworked, stressed or ignorant parents who really wish they could care or they don't at all.

                "should have enough digital literacy" doesn't survive reality check - reportedly 12-26% adults in the UK (% depending on the country) is reported to have very poor/lack of basic literacy skills. 25% approximately are functionally illiterate.

                Reportedly (I'm not an American), 36 million of US adults are functionally illiterate; 43% cannot read a simple job application; 41% of low-income households lack digital literacy skills.

                Those are only two prominent examples. More developed countries (especially in Europe) will fare better, many countries will fare much worse.

                I think your heart is in the right place but the reality stays in disagreement.

                • johnnyanmac 9 hours ago

                  Maybe it's a cultural issue here, but my country is very resistant to the government coming in to course correct how people live their lives. Many times to its detriment (diet, guns, social media), but the boon of this is that it makes it really hard for anyone to incorporate a surveillance state. "Those who sacrifice freedom for security..." And all that.

                  The sad fact is many kids are already falling under the cracks. Failing to mind their kids internet usage is just one way, and having companies sneak in to try and fix this patch won't suddenly lead to success.

                  The needle won't be moved in terms of progress, but privacy will take a near fatal blow. I fail to see why we should accept such measures when this is just yet another bald face power grab by greedy corporations. I might have been more accommodating if this was in good faith, but we've been past the BOTD for at least 7 years now.

          • mrguyorama 14 hours ago

            Walmart has sold android smartphones of okay functionality that poor people depend on for decades.

            Like, less than $100. Nowadays they have $20 ones that are locked to pay as you go monthly purchases, which is definitely worse than the old tracfone days but about the same price if you had to top up every month anyway. That's ignoring used phones.

            Even poor kids get christmas money sometimes.

          • Zak 13 hours ago

            The commercial value of a ten year old smartphone in a wealthy country is approximately $0. It's probably not terribly hard for a determined child who goes to school and has friends to obtain one.

            • johnnyanmac 12 hours ago

              And I bet I'd struggle to install almost all modern popular apps on a 10 year old phone. No Youtube, no Roblox, etc. They simply wouldn't update nor connect. That's one problem solved by the fact that phones operate on a deprecation model, as opposed to Windows OS.

              • Zak 12 hours ago

                That may be, but quite a few of the things that people want to keep kids out of are entirely usable from a browser.

              • epihelix 10 hours ago

                I'm writing this on a seven year old phone (an S10e), running a community ROM with A15, and I have no issues at all in installing any apps. This device is my daily driver (it has a headphone jack and SD card support, and a relatively easily replaceable battery, and is small and light - so it's better than most modern flagships for my needs). A pixel would have much better community ROM support still. These old flagship phones are still plenty powerful for anything other than (useless) on device AI or intense 3D gaming.

                There is only a "depreciation" model if you don't unlock your bootloader - and even then, a seven year support cycle makes it very easy to obtain cheap, old, fully supported phones, if that's your jam.

                • johnnyanmac 9 hours ago

                  >There is only a "depreciation" model if you don't unlock your bootloader

                  That's fair. I also think most kids won't know how to unlock a bootloader (and if Google has its way, that won't be an option anyway).

                  > a seven year support cycle makes it very easy to obtain cheap, old, fully supported phones, if that's your jam.

                  Is that iphone support? I think only the biggest flagships get 7 years of official support (and can maybe run 2-3 more years before app version itself out, without external intervention). From what I saw, most budget phones are lucky to get 5 years of support, and will break down well before than anyways.

      • trollbridge 15 hours ago

        There are definitely toilets that have UAs.

        • KPGv2 4 hours ago

          all toilets are UA assuming the first word stands for a relative orientation, and the second stands for a slang word for butt

    • RandomGerm4n 15 hours ago

      The answer is quite simple. You just don't verify it. The point isn’t to verify the age but to set the age on the device itself. If the parents set the age on the cell phone or computer, that setting is then used as the basis. The operating systems can be configured so that only the device administrator can change the age. Systemd already has a field for storing the age, which programs can read. If the child doesn’t know the root password for the laptop, they can’t change the age. If they do manage to get around that, well, so be it. The solution doesn’t have to be perfect because it would still be an improvement over the current situation without restricting adults in any way.

      • izend 14 hours ago

        Are you a parent?

        I have personally used the parental controls on Android, iOS and ChromeOS and to be honest they are terrible. Issues with syncing changes, the terrible UX for parental access control (iOS...), issues around audit/access logs, issues around prompting the parent for access.

        I am honestly shocked that Apple known for its polished experience hasn't been forced by angry parents.

        My daughter's school actually advised parents to not enable parental controls on her ChromeBook because it would interfere with the school's education websites but my daughter was caught playing web games in class so we decided to lock her down anyways.

        • miohtama 14 hours ago

          Being parent is not supposed to be easy

        • tempfile 14 hours ago

          Parental controls on devices are not hard because they are intrinsically hard. The companies just do not care about them, because nobody has forced them to be implemented sensibly. There is absolutely zero reason an Android device could not have a shiny button saying "Kid's device" when you set it up and never need configuring again. So this is not a criticism of the approach, and only a criticism of the companies.

        • fn-mote 14 hours ago

          > my daughter was caught playing web games in class

          Hilarious to me. The biggest game of whack-a-mole ever. I would love to know if this lockdown was successful (and if so, how it worked).

          In my city, there is a district that is so “locked down” that the images from Wikipedia don’t even load. But guess what? Kids still find ways to play games.

          • saltcured 13 hours ago

            Of course, that whack-a-mole is an intrinsic part youth and adolescence too. I think back to my mostly analogue school days. We found ways to disobey and amuse ourselves in the classroom.

            Imagine pusing for locked down paper so kids can't pass notes nor make spit-wads and airplanes. Or locked down pens to prevent tic-tac-toe, doodling, lewd drawings, or scrawling graffiti on those old desks.

            Some kind of KYC rules so that the older kids at school cannot pass their broader understanding of the world and cussing vocabulary down to the impressionable younger kids. Age restrictions on the trail to the woods, where kids somehow always knew about that stash of dirty magazines...

          • sellmesoap 11 hours ago

            I liken this process to a losing game played by authoritarians all over, normalizing a game of "subvert the man" I see the battle fought over sex, drugs, piracy, probably many other topics. Take drugs (for example) "drugs are bad m'kay" but then there are mind expanding opportunities tucked in there as well, yes most have some risk or delayed consequences associated but the lack of nuance (hard to impart on young minds granted) leads to the drugs are bad talk from someone authoritive, and those that dabble bring amazing tales that refute the earlier information that drugs are bad, and survivorship bias and a "new way the authorities were wrong" takes over and undermines the good intentions of those that see the negative impact drugs can bring. Chances are kids seeking a less locked down experience may dabble in much darker places on the net and it may be that this new "KYC" push actually widens that devide instead of protecting the children (which is merely the story used to push for this enhanced customer identity goldmine.)

          • HDBaseT 5 hours ago

            They need to be using deep packet inspection to get reliable and useful blocks.

            If you cannot install their self-signed cert on your device (i.e non-managed device) then you likely aren't being MitM and thus, restrictions are hard.

        • jvvw 12 hours ago

          I do feel that if there were actually decent parental controls on the most used systems out there then we might not have got to this point in the first place! It is either a nightmare or impossible to set any sort of sensible controls on internet and social media access for children and teenagers.

        • ingvay7 7 hours ago

          Cross-platform support is very poor (iOS/Android/Windows/Mac)if ur trying to use family link. After trying to make FL work for weeks, i moved to another service that has morel granular features than FL and detailed activity reports with web filtering rules but its paid but it atleast works instead of those unusable knobs on FL.

        • codedokode 5 hours ago

          Probably parental control do not bring any profit (they actually add responsibilities, like restriction on ads, collection of data) so the large companies sabotage them by making them too complicated or broken?

        • ezwoodland 2 hours ago

          Sounds like a technical issue that is not better solved by remote devices doing age verification, but instead by fixing the already existing implementation.

    • newsoftheday 13 hours ago

      > At glance this looks reasonable but how do you enforce that kids connection always goes through the parents control?

      YouTube doesn't, the parent does.

      > no anonymous connections are possible anymore to the entire Internet

      Adults would not be blocked if I understand the GP comment. It's an age recommendation and it's up to the parent's to control it for their kids.

      > we want to allow parents to control their kids.

      Yes. Google, YouTube, AI in general will never be a replacement for parenting and they should drop the charade now.

    • wowyouredumb 13 hours ago

      > At glance this looks reasonable but how do you enforce that kids connection always goes through the parents control?

      Because the parent is there to parent them?

      Somehow I (and presumably almost everyone here) grew up with unfettered access to the Internet until now. Your kid isn't my kid, and someone relying on a computer to parent their children shouldn't ruin computers for everyone.

    • patmorgan23 11 hours ago

      "how do you enforce that kids connection always goes to the parents"

      That's the thing. You don't.

      It's the parents job to monitor how their children use the Internet.

    • jolmg 7 hours ago

      > but how do you enforce that kids connection always goes through the parents control?

      Because the devices they're given by their parents should be administered by their parents. The minors wouldn't have administrative control over their devices at all.

      > You want to use your friends Wi-Fi? Now that requires full identification so that we know that its not some kid

      The device wouldn't care how the connection to the internet is made. It ultimately obeys the parents' settings.

      The Wi-Fi doesn't need to care either way.

      > You are just moving the verification point to another gate, it means that no anonymous connections are possible anymore to the entire Internet because we want to allow parents to control their kids.

      Not at all. This wouldn't affect people without parental controls on their device at all. They'd be able to have anonymous connections as they do now.

      The only difference from the server-side is adding some special path /.well-known/parental-info.json or an HTTP header to responses that would indicate what's on the page from a parental perspective, so the device can make a decision whether to display based on its parental settings.

  • Noaidi 14 hours ago

    > for example, on YouTube, you can no longer watch many videos without an account.

    I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?

    IMHO, they should have Youtube 18+ (Adult book store) where you need an ID and YouTube <18 where you do not (Barnes and Nobles), and they can filter the content as apporpriate.

    I think it is evil that YouTube enables kids access to both grooming and violent material.

    • arielcostas 14 hours ago

      > I do not like this argument. Does an adult theater let anyone in without an ID? Do movie theaters let kids under 18 into an R rated movie without ID? Why do we think this should be different on the internet?

      I don't like this one either. Does the cinema store the ID (or information extracted from said ID) of every single user visiting, along with what they've watched, on electronic records that can and will eventually be breached? Do they ask a third party (like Persona) for said verification providing the user's information?

      On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.

      • Noaidi 14 hours ago

        > On the cinema you show your ID to the person in front of you, they check the birth date, if it's valid (and not an obvious forgery) and if the photo matches the person providing it.

        This is something that can be done online as well. Capitalism is controllable.

        • MyMemoryfails 13 hours ago

          Governments aren't clearly willing to regulate the companies. They just let them do whatever they want once they're too big to regulate. Internet Companies has 20 years of history of datamining for sake advertising. Still nothing is done about, why even allow them obtain even more leverage?

      • monksy 2 hours ago

        From my understanding is there is no law for movie theathers in the US to card people for the movies, also the MPAA guidence rating is a suggestion. It's not a requirement.

        There are policies in the industry to suggest it.

    • giantg2 13 hours ago

      The problem is that digital IDs get recorded. The physical examples you give are generally not. The clerk at the ticket counter or entrance doesn't give a shit who you are, they just need the picture to match you and the DOB to 18+ years ago. If you're old enough, they dont even card you.

    • Ukv 13 hours ago

      > Why do we think this should be different on the internet?

      Because when applied to the internet, the age gating model that works okayish for brick-and-mortar locations is ineffective (children can use a friend's older brother's ID or account, websites outside of the relevant jurisdiction can just decide not to verify age, etc.) and invasive (sending private and sensitive information off to US companies that have been breached or linked to mass surveillance). Lack of efficacy is then used to justify crack-downs on privacy tools and the need for broad content-blocking powers with no due process.

      Preferable IMO would be with filtering on the local network level, like schools have been doing for decades. Parents typically own the router/mobile data plan, so it'd pretty much just be a change of defaults and maybe some new interoperability standards. A lot less invasive, and arguably more effective.

  • mmooss 14 hours ago

    > The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.

    Agreed, just make age controls available to parents, optional, and keep the user age data on the local device. External hosts can verify against it in obvious ways. But isn't that what California's law said, that commenters on HN opposed so strongly?

  • qurren 14 hours ago

    The part I'm most opposed to is requiring a full KYC, using "verifying age" as an excuse. My Gmail account has been active for >18 years, that should be enough proof.

    • fn-mote 14 hours ago

      … but how many people really believe that will happen?

      Fight together with everyone else, or when stage 2 (“full KYC”) is implemented you won’t have any leverage.

      • tyre 13 hours ago

        It won’t because KYC is a legal process and you don’t want to prophets that across the entire system with bypasses for it. That’s legal trouble waiting to happen.

        Yes, Google also wants to tie back to legal identities to sell ads. I’m not saying they’re doing this in good faith, but proxies like this get messy and dangerous for legal/compliance.

        • dredmorbius 12 hours ago

          "you don’t want to prophets that across the entire system"?

          Typo? But it's hard to tell what.

    • RachelF 5 hours ago

      They should not call it "age verification" - it is actually identity verification.

  • SirMaster 14 hours ago

    >YouTube, you can no longer watch many videos without an account.

    What YouTube video can I not watch via yt-dlp without an account?

    • jamesnorden 14 hours ago

      Anything age-restricted.

      • anthk 14 hours ago

        FreeTube can.

        • Scaled 12 hours ago

          I love free tube, but in my experience it cannot get around the login requirement for mature-flagged videos.

  • cute_boi 13 hours ago

    Exactly. In the future, to view a youtube video we will need create a Gmail account, we'll need a phone, SMS verification, an ID card, and we'll probably have to rotate your head two or three times and talk to some AI.

    • twothreeone 12 hours ago

      Eventually they make you fill out some paper work, or pick up some boxes from somewhere and bring them to another place. You know quick human tasks, just to verify you're really human. It's just a verification check, nothing else.

  • ajsnigrutin 12 hours ago

    > Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.

    This could be done with setting the age too. Kids don't have their own money and can't sign their own cell contracts, their parents do, and during the phone setup process, the parent could set "the owner of this phone is a minor" checkmark, set the age of birth (so it auto "unlocks" at 18), add a parental password to manually unlock for whatever app needed (or reset or change the setting). Then the phone would just send "user_is_a_minor" flag to whatever and/or filter the 18+ stuff.

  • kevin_thibedeau 12 hours ago

    The sensible solution doesn't build a consumer profile for resale and government surveillance.

    • go_elmo 12 hours ago

      Imagine, starts much earlier, everyone has a birth certificate. /s

  • stronglikedan 12 hours ago

    > Allowing parents to ...

    That's the crux of the issue - the state (pick one) wants to be "the parent".

  • autoexec 12 hours ago

    > The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating.

    That just entertains the false justification for what is ultimately about surveillance and control. There are privacy preserving alternatives to accounts and ID/face scans but no one in power is interested in them because the loss of privacy is the entire point.

    • giantg2 9 hours ago

      What might those be? Everything I've seen is ineffective or can be compromised. I think letting parents parent is probably the best option, but will require better/easier/free tools and education to help lock down different categories of harm.

      • autoexec 9 hours ago

        There's nothing that can't be worked around or compromised in some way. Even the face scans and ID scans being used today are being circumvented.

        In the end we do need parents to parent, but websites should help. The easiest way would be for websites to send an HTTP header to the client so that censorware can know to block or allow it accordingly.

        • Gander5739 8 hours ago

          > The easiest way would be for websites to send an HTTP header to the client so that censorware can know to block or allow it accordingly.

          That sounds very similar to the suggestion of the original commenter, that you responded to with

          >> That just entertains the false justification for what is ultimately about surveillance and control.

          • autoexec 4 hours ago

            I assumed that when he asked "What might those be?" he was talking about privacy preserving ways to address that same false justification. I'm not sure how you took it some other way.

        • codedokode 6 hours ago

          The header must confirm that site is age-appropriate. No header should be interpreted as "adults only". This is the safest option, and it doesn't require 99% of webmasters to do anything which is in my opinion better than any other proposal.

          • autoexec 3 hours ago

            Exactly. That's the problem I have with the "restricted to adults" header. Ideally the header wouldn't have a "safe for kids" value either because what one parents feels is safe will be very different from what another parent would find appropriate. I think The Internet Content Rating Association had the right idea were the header would show if a site contained specific types of content or not and it was up to parents to decide how much to censor.

      • wongarsu 8 hours ago

        Website generates a random nounce, the government offers to sign the json { over_18: true, nounce: [inserted_here] }. That signing is coupled to you being signed in, or scanning your passport via nfc or whatever

        That significantly reduces the leaked information: the service doesn't receive any information who you are, and the government doesn't know what service you use. They can collude, but that does not reveal more to them than most current age-verification methods. Children can get another adult to sign their request, but that's a working attack on nearly any age verification (including in-person purchases)

        Of course this doesn't replace parenting

        • giantg2 8 hours ago

          "They can collude, but that does not reveal more to them than most current age-verification methods."

          Or just correlate the IP.

        • HDBaseT 5 hours ago

          The word nounce is used to describe a sex offender, at least in the UK.

          • EmbarrassedHelp 2 hours ago

            That's how members of the UK government refer to anyone that supports privacy and encryption

      • codedokode 6 hours ago

        1) When buying a device, store employee could program user's age range.

        2) When configuring a device, parent may toggle "child mode" checkbox to switch the device into "child mode", protected with a password or fingerprint.

        3) The tokens, containing a private key (same for all tokens) can be sold in liquor stores to adults only. This token could confirm the age without a passport.

        It is interesting that is US (unless I am wrong) you can vote and change the government without a selfie and a passport, but you need them to use Reddit or Discord.

        > but will require better/easier/free tools and education to help lock down different categories of harm.

        There should be a single big "child mode" checkbox for normal people and "configure" button for 1% of geeks. Most people do not need tools and have no interest in configuring allowed categories.

        > Everything I've seen is ineffective or can be compromised

        Selfie/passport also can be compromised by asking a friend/older brother/parents to verify your account. Especially if you have a poor adult friend with alcoholic dependency in dire need of a new portion.

        • giantg2 6 hours ago

          Number 2 is basically here for many things, but not as easy as a single checkbox. Number 3 is something I've thought about, but it seems that's never seriously discussed in politics.

          • codedokode 6 hours ago

            There should be a single checkbox (when setting up the phone), and "configure" button hidden deep in the settings for the minority. Most people do not like complicated UIs and unnecessary work.

          • squigz 5 hours ago

            Not only would #3 be ineffective, it would affect poor people a lot more.

        • annzabelle 5 hours ago

          I've never had to do a selfie or a passport for Reddit or Discord, including in the US and Australia.

      • txrx0000 2 hours ago

        Correct observations. But have you wondered why those solutions are ineffective?

        Kids nowadays use phones and tablets for the most part. They don't even know how to use a computer that well and are not taught properly. But this isn't really on the kids.

        Now, suppose I'm an OS developer. I cannot simply fork Android or iOS to create a child-friendly toy operating system for smartphones with a reduced set of features. The hardware is locked down to oblivion. They want you to use their OS. And their OS has no user accounts, permissions, or firewall configs.

        Well, then suppose I'm an app developer, and I want to make a browser or social app with built-in client-side content filtering. But my browser doesn't pass Cloudflare or whatever attestation, and is blocked from half of the sites. It might not even be approved on their app store so people will never find it.

        Fine. Then I want to change what content is filtered within the approved apps. But those options either don't exist or is some kind of cloud service where you give them your age, and they decide what to filter.

        ========= Parents can't even control what software runs on their own hardware. How are they supposed to control what runs on their child's hardware? =========

        "The market failed", so they can sell you parenting among other things as a service, with surveillance as a free gift. The tech companies make money while the government gets control over the populace. It's a terrible arrangement.

        That is why most digital parenting solutions you've seen are ineffective or can be easily compromised. Tech companies along with the government are playing chess against you at every level of the stack. Don't ever forget the PRISM program exposed by Edward Snowden. Apple, Google, Microsoft, Facebook - they're all complicit. Don't look at what their PR department says, look at what they do: https://en.wikipedia.org/wiki/Edward_Snowden#Revelations

        One possible short-term solution is antitrust legislation for hardware vendors to ship their devices without an OS... is what I would say if we lived in a sunshine and butterflies world. Maybe the EU is not thoroughly captured yet and still has the ability to implement this, but I doubt it. Technoauthoritarians are building a panopticon to contain the sheep, and they're not even hiding it at this point:

        https://www.youtube.com/watch?v=sQqQtgRdjZU https://www.youtube.com/watch?v=d34b7taQ640

        The actual long-term solution is difficult. We have to make our own computers and radio equipment before they outlaw mining and manufacturing using the same safety excuses, which will happen when humanoid robots can do those jobs. The entire stack has to be open-source, which means we will have to diffuse fab technology everywhere so that people can manufacture computers locally, from mining to wafers to final assembly, in every city, or even at home. There are very talented people working on this problem, so it will be done. Just don't fall for the narrative that surveillance is inevitable or needed.

    • bigstrat2003 7 hours ago

      If indeed the push for age verification is being done under false pretenses as you suggest, then one should propose solutions that accomplish the stated goals while preserving privacy. Either the solutions will be accepted, or the people advancing false pretenses will be forced to come up with new false pretenses, which will weaken their arguments. Either way is a win.

      • JoshTriplett 5 hours ago

        > then one should propose solutions that accomplish the stated goals while preserving privacy

        Solution: sites and apps optionally provide metadata suggesting their content/age-appropriateness, parents locally configure software to look at that metadata (including what to do with things that don't have metadata), or they don't, depending on their parenting style and the maturity of their child. Done. No laws or identification or invasive measures required.

      • autoexec 4 hours ago

        It's been done. Here are a couple of examples:

        https://en.wikipedia.org/wiki/Internet_Content_Rating_Associ...

        https://www.rtalabel.org/page.php?content=howtofaq

        Use of those kinds of headers needs to be voluntary for websites, which means that censorware has to block any site that doesn't return the header, not just those sites where the value of that header indicates adult content. That will encourage websites to support the header or risk being auto-blocked by any censorware in use, but that's a problem for the RTA header since it only indicates adult content.

    • markovs_gun 3 hours ago

      To me the biggest piece of evidence that these methods don't actually work for age verification and are completely for surveillance and data collection is that you can't use them to buy wine at the self checkout at the grocery store. Like if it's effective, why can't the self checkout camera tell that I'm over 21 and can buy wine? Because it's not and everyone knows it.

  • alightsoul 8 hours ago

    I am not sure creating an account is seen as an issue anymore given that the vast majority already have one. However yes as you say it helps create a monopoly. Combine that with a doomscrolling algorithmic feed on like YouTube and that's how you create a moat: age verification and doomscrolling.

  • xg15 8 hours ago

    I think sites and app developers don't really need external reasons to force account creation, they all seem to want to do it anyway. And at least this API would - in theory - enable age verification without needing an account.

  • skybrian 7 hours ago

    Attempting to prevent websites from learning about their audience is difficult. For example, Lego has a "play zone" and it has other pages geared towards adults. You get an immediate popup asking if you want to go to the play zone or not. If a user clicks on play zone, that's a good signal (but not guaranteed) that they're probably a child.

    Preventing this would be difficult. If there are any behavioral differences between children and adults, that's a signal. And it would mean websites couldn't build experiences tailored to their audiences. Do we really want to try to suppress all behavioral cues that can be used to distinguish children from adults? Is it worth it?

    A reasonable compromise is that websites and apps should be able to learn about devices, not people. It should be trivial to figure out whether a visit is from a child-locked device or not, no account needed. Much like clicking on "kids zone," it doesn't mean you know for sure who's really using the device. For example, it could be an parent who turned the child lock on to see what happens, because parents should know these things.

    It's another bit that could be used distinguish users, but giving away zero bits of information isn't practical.

    • annzabelle 5 hours ago

      I went to Australia recently, which is famous for requiring age verification on websites. When I first landed, Discord blocked a few channels I was in, but within a couple hours it was all unblocked with no action from me. Both Reddit and Discord worked with full functionality. My best guess is they have some sort of behavioral information that suggests I am extremely unlikely to be a minor.

  • yieldcrv 5 hours ago

    > Furthermore, the whole thing also reinforces monopolies.

    when the state gives you an exception to antitrust scrutiny that will survive between administrations, you take it

  • judge2020 1 hour ago

    https://www.rtalabel.org/

    Adult content providers already voluntarily embed this, with devices blocking websites when it detects this on the page if parental controls forbid adult content.

    Parents really just don't parent their children nowadays. They expect the government to do it for them - and why shouldn't they, when they already trust the government to babysit their kids during the day? Why can't the government also babysit their kids for the 6+ hours a day they let their kids spend on the iPad?

iamflimflam1 18 hours ago

I find myself stuck on the fence with age checks.

Companies have show that they are incapable or unwilling to address the problems they cause. And market forces are not working to correct things. It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.

This is where regulation is supposed to come in.

At the same time, companies have shown that they will abuse any personal information that is shared with them and we are now giving them more details about ourselves…

  • owbt 18 hours ago

    I have a feeling that, in order to protect privacy, those regulations must fall on the parents too. It is their primary responsibility to take care of their children. Maintaining your kids digital hygiene should be important to the lawmakers and the child protections services.

    • inigyou 18 hours ago

      What should they do about it?

      • owbt 18 hours ago

        Who? The lawmakers? I believe banning children up to a certain age from having Internet-enabled mobile devices is a good starting point, and both child protection services and law enforcement services should fully cooperate with parents in enforcing that ban. If you see a kid smoking a cigarette or taking drugs, you know parents have failed somewhere along the road and it would be preferable if the government could step in to help.

        • sevenzero 17 hours ago

          This is reasonable up to the point of lawmakers suddenly deeming rainbow flags just as bad as drugs (Russia as an example). Your example may work in well intended countries but completely ignores that a country can VERY easily shift into a regime that does not have good ethics abusing these kinda laws.

          • inigyou 17 hours ago

            Not having an internet censorship law never stopped a country from making rainbow flags illegal.

        • inigyou 17 hours ago

          This is a reasonable perspective, but don't you think the internet has the potential to do good as well as evil? I remember seeing some interactive lever applet as a kid where you could move the fulcrum. (Slightly) educational stuff. Shouldn't that be allowed?

          • ben_w 16 hours ago

            Educational content was already a thing well before the internet got everywhere.

            When I was in primary school, one of the things teachers had us do was debate the pros- and cons- of television. The pro side included educational content.

            First Windows PC at any of my schools had Encarta.

            Wikipedia can be downloaded in entirety and read offline, though it is so broad it may need a degree of filtering to become age-appropriate even for 16 year olds.

          • cowboylowrez 16 hours ago

            There are any number of alternatives, I favor a walled off whitelisted subset of the internet that requires age verification and then we can let kids on that and otherwise ban them from the general internet and also ban internet enabled devices in general. However, this costs and undoubtably wouldn't be perfect as there are people out there who want to chat up your kids, look at how much work a roblox style site needs to do against internet users who probably shouldn't be chatting up kids.

            For those precocious kids who parents decide should be the exception because they are "good with computers" well I'm thinking some sort of waiver would be required that held the parents responsible then maybe let the kid hack on the internet but this is an unpopular view, the unpopular part being the "parents being responsible for their kids" bit.

            But in general I think its a tough time to be legislating this stuff because "reasonable perspectives" are not what we are voting into office right now lol

          • owbt 16 hours ago

            I have a feeling that, currently, the cons outweigh the pros. Maybe if the digital landscape changes in the future, then we can reconsider those limitations. So far, the mobile Internet - the apps mainly - is a hostile environment for a young human, and I'd say they are pretty dangerous to the adults too.

        • ranger_danger 16 hours ago

          In many schools in the US now, kids are issued mandatory iPads from age 5 and are required to use them to complete school assignments.

  • K0nserv 18 hours ago

    I don't want the market solving this. If we are going to do age checks it should be based on public key cryptography, be open source, and handled by the government. You verify with the government (or don't since they already know your age), you get some form of cryptographic attestation, present said attestation to websites/apps.

    I'm not a fan of age verification in the first place, but I am extremely not a fan of random third parties doing the verifying.

    • zx8080 18 hours ago

      In this case will it be a transparent traceability and the mapping to user real identity close to 100%?

    • oneeyedpigeon 18 hours ago

      If it has to happen, this is exactly how it should. Please feel for those of us in the UK who are currently denied access to some pretty significant services unless we send our passport to a random third party.

    • inigyou 18 hours ago

      No. It should be none of that. It should be a checkbox either set by the phone store when you buy the phone or set during the first boot process.

    • sschueller 18 hours ago

      Why do we need to verify age?

      You can't tell me that these social media companies don't already know exactly how old someone is just based on the enormous data that is collected.

      • satvikpendem 18 hours ago

        They do already like YouTube and ChatGPT, so they'll ask for your age only when they're unsure.

        • creatacc 17 hours ago

          chatgpt began to spam me pretty hard for last a few months.

          chatgpt basically never sent email and it's regular now - like 2 4 emails per month

          so, it doesn't look great for chatgpt

        • EmbarrassedHelp 2 hours ago

          And that should be highly illegal to demand that a user submits to age verification.

          • satvikpendem 14 minutes ago

            Why? Sounds like it'd be the exact opposite, if they're showing age gated stuff of course they'd ask for your age.

      • palata 18 hours ago

        A big concern around age verification is that some people will be locked out because they can't prove their age.

        Your solution here has the same flaw, I think. If the algorithm thinks I'm underage, I'm locked out.

        • creatacc 17 hours ago

          being locked out = less profit = firing management by shareholders

          it will solve by consumers, don't worry

          • upheaval7276 17 hours ago

            yep, just like cases now where people are locked out of their accounts for no reason with no recourse. totally solved!

          • brookst 17 hours ago

            In the aggregate sure. But do you really think profit motive means they will be precise for every individual?

          • j16sdiz 16 hours ago

            It won't.

            Do you aware how many people are locked out from access of the bank because the bank think they are too risky by some algorithm and no human review?

            And people got rejected for flying because they have same name as somebody on no fly list?

          • palata 15 hours ago

            The number of people who are marginalised is... marginal. By definition it doesn't have a sensible impact on profit. That's precisely why it is a problem to be marginalised.

            • MichaelZuo 14 hours ago

              Isn’t that… life?

              Even literal regulated electricity utilities aren’t expected to provide service to every last marginal customer.

              For example, a poor old grandma missing many electricity bill payments usually will see leniency if she is polite, the utility eventually won’t try to collect cash anymore and instead put a lien on the home while continuing to provide service.

              But if the billing department receives multiple threats from her, then they may just cut the service.

              • johnnyanmac 12 hours ago

                I really hope our freedom's aren't relinquished on a platform as fortified as "It is what it is".

                • MichaelZuo 10 hours ago

                  This doesn’t make sense?

                  How does “freedom” relate to an electrical utility deciding whether to cut service?

                  • johnnyanmac 9 hours ago

                    "Freemdom" is accepting that mostly marginalized people get their power cut because they are marginalized. Your reaction to that is to shrug and move on instead of investigating the systems below that keep the marginalized as so.

                    Even if we take marginalization out of it, this is the same kind of system that let's Healthcare recklessly utilize AI Systems to automatically reject patients' care, with a Herculean effort required to find a human to talk to. Its easy yo shrug until you are hallucinated into their crosshair.

                    But sure, that's "freedom".

              • palata 8 hours ago

                Not entirely sure what you are trying to say, other than you don't really care as long as you are not the one who is marginalised.

                Anyway it's generally a tradeoff: is it worth doing it? By adding very strict age verification systems and marginalising people, do we make society globally better or not? Will those age verification systems work to prevent underage people from accessing the stuff we don't want them to access in the first place? Not clear. If they do, will it result in underage people being better? Not clear. And if it does, will it have been worth the damage on the people it marginalised? Not clear.

      • nephihaha 17 hours ago

        Because it's all about bringing in digital ID and gated internet. Not age.

      • trentor 17 hours ago

        If you want to use a service that is age restricted either by law or the company providing it how else would you do it? It's the same IRL. I don't like it as well and we certainly lived through the wild wild west times in the 90s and 00s but the more something gets economical important the more scrutiny it gets. Maybe we just need something new.

        • docjay 16 hours ago

          Well these kind of laws are trying to legislate technology into existence; we don’t have a means to do it, yet “we demand for the technology to exist through ‘reasonable methods’, now get to work.”

          If that’s the nearly infinite wiggle room we’re playing with then I’d say what about Adult and Child versions of phones? You have to flash your ID to the clerk to buy an adult one, like buying cigarettes at a gas station, and then you get to do what the internet offers. Child phones - let parents and governments come up with whatever they want to block. The phone autoupdates in the background with the blocklist, the device can’t do those things. There ya go. Each person and family gets to make their own choices and nobody has to give an ID card to PornHub or a company that literally exists to harvest your information. Win-win?

          • skinfaxi 15 hours ago

            We already have a version of the child phone: it's parental supervision.

            When I was a kid there was no TV in my bedroom nor a computer. Everything I watched or did online was on full display in the family room. What changed in the modern home where that's not the case? Are kids glued to their phones because their parents are too?

            • docjay 12 hours ago

              I completely agree. In fact the tools already exist to make a “child” phone. I was just giving up some inconsequential ground since many people are apparently stuck on the government padding the earth to protect their fuck-trophy. “OK - government mandated OPTIONAL DNS filtering on all routers. Super easy interface, auto-subscribe to government compiled list.” Scratches their itch and doesn’t affect me since I just won’t enable it, nor will I buy the “child phone”, and I don’t have to send a rectal scan to Facebook either. Yay all around.

      • mrguyorama 13 hours ago

        They would prefer to know, not estimate, which is why they are pushing these initiatives basically on their own accord.

        Also, if you've ever played with this kind of data, there is immense overlap between how some adults and some kids use the internet. Is this user legally a child, or just emotionally a child? Similar to the problem of "There is overlap between the smartest bears and dumbest tourists" in designing bear proof garbage cans.

    • perpetuallunch 18 hours ago

      I’m from The Government, and I’m here to help.

      One not entirely inaccurate definition of government is a loose agglomeration of third parties.

      Or, less flatteringly, a stupendously large way too loose agglomeration of way too many third parties welding way too much power way too arbitrarily.

      • usrnm 17 hours ago

        The difference here is that in a functioning democracy people have some control over their government. All the institutions are specifically built to be transparent and work for the public good, at least, in some sense of the word. A corporation, especially a monopoly doesn't care what you think, you have no control over it and the only thing that really matters to them is their bottom line. Are governments perfect? Of course not. Are random corpos better? Again, of course not.

      • mmooss 14 hours ago

        Despite that fun trope, in reality democratic government reguarly delivers very well: Traffic safety systems work easily, dependably, economically. The Internet was developed by the government, the web at a government-funded research institution. NASA is the most cutting edge, most adventurous organization in the history of humanity. The US military created GPS for example, and has more globalized operations than any other organization has ever imagined, and from the bottom of the sea to GEO. Diseases are managed and contained, etc.

        (Now if the people want to tear apart government, democracy delivers that too.)

    • 0x696C6961 18 hours ago

      This is scary though too. If the gov managed a key server like this, almost all companies would start requiring it. But this effectively gives the gov a very easy way to lock you out of everything.

      • jacooper 17 hours ago

        This will be possible if done by third parties anyway, it will just be apple, google and maybe meta, a single phone call is enough to cut you off. At least if the government is doing it, the app doesn't get your id.

        • account42 17 hours ago

          Either the app will get the id, you will be prevented from running arbitrary software on your device, or the whole thing will not work because it becomes trivial to sell your age verification tokens.

      • Vespasian 17 hours ago

        This is really nothing new and has always be the case It's not possible to tech yourself out of a political problem.

        So if there is something being done we should choose a solution that has at least some accountability to the general public (through elected representatives).

        The alternative is Google, Apple etc where almost anyone has exactly zero influence and the government can still block as they like.

        • account42 17 hours ago

          If all alternatives are bad you should do none of them, not squabble about which one is slightly less bad.

          • sobkas 17 hours ago

            Not doing anything is also an alternative, theoretically it can be worse than other alternatives too...

      • ranger_danger 17 hours ago

        EU already does this with the eIDAS system and it works quite well.

      • maccard 17 hours ago

        As opposed to if google, Microsoft and apple operate the key server and a government can influence them?

      • throwawaysoxjje 12 hours ago

        Like the government doesn’t already have that power?

      • undersuit 11 hours ago

        I'm already locked out by many of the private companies so...

    • LeBit 17 hours ago

      That makes the most sense.

      And, that public key of yours must be used only on given platforms. You want to participate on Facebook or Reddit, then you use that public key to prove who you are. Which platforms require verification is another issue.

      But it should still be legal and allowed to access conventional forums, Usenet , tor accessible discord servers without having to prove who you are.

      Otherwise , the right to organize is over and we effectively live in an authoritarian regime .

    • testdelacc1 17 hours ago

      I want the market solving this but I don’t want to give any information to anyone who asks. I want Apple to verify me once, and then others to trust Apple that the device accessing their service is owned by someone over 18.

      I’ll bet that most people are in the same boat - they trust their device manufacturer with information like their credit card number, but not anyone else.

      And I think it’s a pragmatic compromise.

      • K0nserv 15 hours ago

        How does this work if you use Linux or Graphene OS?

        • stvltvs 12 hours ago

          It's not supposed to. Just one more way to limit our freedom to control our own devices.

      • nativeit 13 hours ago

        I’d personally prefer if nobody verified me ever, and people stopped asking for it altogether. It’s not a compromise, because nothing about this is pragmatic, necessary, or for any benefit of society—this is yet more creeping authoritarian control, and I’m absolutely floored how readily everyone else bends over for it. I say no. Fuck no. I will sabotage and obfuscate every aspect of this at every opportunity.

        The people clutching pearls and screaming “what about the children” can deliver universal healthcare, child care, parental leave, and free education FIRST, and then I will extend a modicum of trust for their overriding “concerns”. Until then, I’m gonna treat this as the bad faith power grab that it very clearly is.

      • johnnyanmac 12 hours ago

        And the market won't solve it in a way without perverse incentive unless you have government regulations. Too much money on the line at this point.

    • Ajedi32 15 hours ago

      You're seriously proposing letting governments decide which of their citizens are allowed unrestricted access to the internet?

      Of all the 3rd parties who could be responsible for this, I trust the government the least.

      But really the best solution here is no third party. The device owner (e.g. parents) should be responsible for setting the user's age when setting up the device. Anything that tries to take that responsibility away from parents and give it to a third party is necessarily going to be highly authoritarian; putting that third party in the role of parent for everyone, adults included.

      • gambiting 14 hours ago

        >>Of all the 3rd parties who could be responsible for this, I trust the government the least.

        Really? can you name any 3rd party you'd trust with this more than your own government?

        Given that you know, the government already has all of this info on us. This isn't a choice between "the government doesn't know how old I am" and "the government has all the info on me". Governments usually already do. They have enough data already to issue such proof just by the virtue of us living in the country. Tax records, birth records, driving licences, council taxes, passport info, medical information - there's more than enough to give me a cryptographic certificate that says "yes, gambiting is definitely 18 years old" without me having to do anything. Compared to literally any third party that cannot do any of this, unless they buy my marketing cookies on the open market or something, or yes - I actually go out of my way to give them my passport/credit card/selfies etc.

        • kelvinjps10 14 hours ago

          It’s not really about the info but restricting access to people. Imagine they restrict access to social medial to people with different political opinions as the ruling party in the government

          • gambiting 13 hours ago

            The whole idea is that the government gives you a cryptographic token that proves you are over 18, but that token can be used anywhere. They don't get to say what websites can look at it, because...how would they.

            • stvltvs 12 hours ago

              The concern isn't that an authoritarian government locks you out of some age-restricted sites, it's that it locks you out of them all.

              • gambiting 12 hours ago

                Well, sure. But that doesn't answer my original question - which 3rd party provider do you trust more with your own data more than the government[which in most cases already has this data]

                • stvltvs 10 hours ago

                  Data ownership is just one area of concern. Controlling our access to the internet is another.

                  If age verification was an open standard, we could hope for competition so that we could jump ship from a bad actor. If one blocks our access, we would have alternatives. In theory.

                  Not so with a centralized government-mandated service.

                  • K0nserv 9 hours ago

                    Who is in charge of certifying implementers? What happens when I provide an implementation and don't verify anything at all?

                    • stvltvs 3 hours ago

                      I'm not saying age verification is a good idea, just that a centralized government-mandated implementation is a bad way to do an already bad idea.

              • afdbcreid 8 hours ago

                The government can just arrest you and lock you out of all sites. It's not like they cannot do it today.

                • pibaker 7 hours ago

                  You can disable Internet access for millions instantly. You can't arrest millions.

                  • gambiting 7 hours ago

                    Again, this can be done already? Look at any authoritarian country killing internet access the moment anything happens.

                    • stvltvs 3 hours ago

                      This could be more targeted, like a no-fly list for the internet. Political dissidents, journalists, etc. could be effectively exiled from online activity.

    • dgellow 8 hours ago

      Why not just let the parents set an age on the device via parental controls? Why do we need a whole cryptographic system and the government in between, for something that is really just a way to say « this device doesn’t want to have adult content »? It’s way simpler to have that at the device level, and would enable even adults who don’t want adult content to block it for themselves

      Edit: I just realized that’s exactly what Android is announcing in the article, so that’s pretty neat

  • sschueller 18 hours ago

    There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.

    There should however be no force age verification. Social media companies already know how old you are or very close to it using the data they collect everyday. Using this data they should be required to use "best effort" to determine which algorithm you fall in. Nothing is 100% and we should stop pretending it is, sure some kids will find a way around but they would also if there is a age verification system.

    • watwut 18 hours ago

      > There should be a law that forces social media companies to use a different algorithm for anyone under a certain age and be required to disclose it to the public. Possibly different algorithm depending on age group.

      Frankly, in that case I want the kids algorithm. It is preferable for me as an adult, I do not want the intentionally harmful one either.

      • flowrange 18 hours ago

        This. Just give me the option to have pagination. Sweet, old, pagination. Like here on Hacker News. I can then review one or maybe 2 pages, and that is all. Like a physical magazine where there's a clear end.

        I have the firm belief that infinite scrolling is one of the darkest pattern that was ever invented.

        • oneeyedpigeon 18 hours ago

          Hang on... Hacker News very clearly has a complex, opaque [1] algorithm that orders stuff. Maybe it's not user-specific, and maybe that's a good dividing line, but these are the kinds of factors we're going to have to think about if we want to introduce regulation around 'algorithms'.

          Infinite scrolling is a very different issue (although it's definitely a contributor to the harm, I agree).

          ([1] Unless I'm being unfair here; maybe the algorithm is available somewhere, I just don't see it obviously linked anywhere)

      • oneeyedpigeon 18 hours ago

        You can often do that via settings. But we could do with a law that makes it a crime to override a user setting that has been explicitly set, without notifying the user.

        • jodrellblank 16 hours ago

          Oh but you enabled the setting "don't use infinite scroll" and we've deprecated infinite scroll so that isn't a setting anymore. While improving service for our customers we have introduced "unrolling pages" which prefetches the next page and attaches it to the end of the previous page to provide a smooth reading experience, and of course we've given that its own setting which you haven't set, and it defaults to enabled to provide the best seamless reading experience for most people.

          Next we're thinking about spatial pages, an innovation which considers the app as a viewport flying over the pages laid out in a line. In consideration we have database-views which presents the unpaged tables of content in the database directly to the end user, completely bypassing outdated 'page' skeuomorphisms from the olden days of printers and books. Further out, our researchers are working on Shepherd Tone-inspired viewing, where technically legally it is paged, but it looks and feels like it isn't!

      • mikeocool 18 hours ago

        Yeah, seriously, New York just passed law that makes it illegal to show engagement-driven feeds to kids.

        I can’t wait to not age verify on instagram and permanently get back a feed that’s only people I follow.

        • SirMaster 7 hours ago

          You know you can also just not use Instagram...

          • mikeocool 6 hours ago

            I used to quite like instagram when it was a good way to keep up with a well curated group of friends who would share occasional interesting photos (though even then it could end up being performative).

            But you’re right, these days I’ve largely stopped using after i realized every time I opened it, I was looking at a stream of drivel designed to keep me scrolling.

  • oneeyedpigeon 18 hours ago

    I think you've done a great job identifying the three main options and why two of them (parents, censorship-by-default) just will not work. That leaves regulation; the only way we will prevent children—or anyone—from coming to harm is to stop companies from producing this harmful content in the first place.

    Either that, or just accept the harm.

    • nxm 18 hours ago

      Who decides what is harm? An unelected bureaucrat? Now you’re going into censorship area

      • oneeyedpigeon 17 hours ago

        No, I'd prefer elected representatives to do that, in the same way they've decided on all the other existing harms we legislate for.

        • polipputter 14 hours ago

          And what happens when those representatives decide things like rainbow flags being a crime or so much as mentioning the existence of trans people in front of a kid is equivalent to a sex crime. The US has states pushing legislation to make abortion a crime punishable by the death penalty while also using flock cameras to track people traveling across the country to places it's complete legal to do so. But yeah let's give those people a way to tie every website that woman may view while searching for a safe option now directly linked to her I.D. or that adult searching for gender affirming care is now outed because their ID is linked to the site. So when states like Kansas legislate all trans people's drivers licenses be revoked they can just say okay who in the state has looked at transgender healthcare related websites and have a list of people to go after.

  • ekjhgkejhgk 18 hours ago

    Parents should take responsibility and not let their children smoke, and we still banned selling cigarets to children. Just because something should be some way, doesn't mean as a society we shouldn't do anything about it.

    In any case, the story with parents and addictive devices is even harder for parents than e.g. cigarets. For example, a LOT of schools in the UK think that it's good to give childrens ipads to study, and there's nothing that parents can do to prevent this. In this specific situation saying that "parents should take responsibility" is unfair to parents, because their only option to avoid this is home schooling.

    • EmbarrassedHelp 2 hours ago

      That's a false equivalence. The only thing we should be doing is tackling addictive algorithms for everyone, and providing purely optional parental controls that are disabled by default.

  • c0n5pir4cy 18 hours ago

    The EU actually has a very good, privacy protecting way of doing this based on zero knowledge proofs.

    Unfortunately they completely botched it by having the proof-of-concept app rely on Apple & Googles integrity APIs - which a bunch of countries copied.

    • inigyou 18 hours ago

      ZKPs may as well just be unencrypted HTTP headers which would be way simpler and easier to implement. All a ZKP proves is that at least one person in the world is over 18.

      • palata 17 hours ago

        This is not completely true.

        With ZKP, if you make a business out of reselling tokens you get with your own identity, eventually they will see that you use orders of magnitude more tokens than normal people.

        So with ZKP it's more difficult to cheat. Not impossible, just less accessible.

        • inigyou 17 hours ago

          They're not ZK if they can do that

          • roblabla 17 hours ago

            Each individual proof is zero knowledge, but downloading a _bunch_ of them is an indicator, yes. There's no real way to work around this with the current ZKP scheme. I'd argue ZKP is, in theory, the least worse option of all current age verification scheme.

            My personal opinion is that age verification itself is a bad idea, but if we're going to go ahead with it, I'd much rather we use ZKP for it than the current mess of "upload your passport and picture of yourself to dodgy 3rd parties that likely now have your browsing traffic associated with your real name"...

            • inigyou 17 hours ago

              So the government would impose a maximum limit on the number of porn sites you can visit each day?

              • palata 15 hours ago

                Not necessarily, but it would be difficult to justify why you need to access 1000 porn sites every day, I guess?

                The point is that if you build a service that sells age verification tokens, you are doing something illegal. And if you start doing something illegal by gathering said tokens with your own identity, maybe it's not the most clever way to do something illegal?

                • inigyou 14 hours ago

                  So the government would limit me to accessing only 999 porn sites a day?

                  Is it going to be like structuring law, where it's illegal to access 1000 or more but it's also illegal to avoid accessing 1000 or more by accessing a lower number?

          • palata 15 hours ago

            Of course they are. The whole point of ZKP is that whoever gives you the token cannot link it to your identity. So you can get a token with your own identity and sell it to someone else, and nobody will know...

            ... unless you get thousands of tokens every day and sell them on a website, where suddenly you start leaking information about yourself everywhere. ZKP still did its job: it's not the tokens that link to your identity, it's your behaviour.

    • EmbarrassedHelp 2 hours ago

      The EU app is still shitty and unfixable, because it requires that you send personal information to a third party. The only acceptable and privacy respecting option is self declaration, which doesn't need any ZKP or any other bullshit.

  • fc417fc802 18 hours ago

    > This is where regulation is supposed to come in.

    Yes, agreed. However regulation does not necessarily have to mean age checks.

    The most obvious low hanging fruit to start off with is open and interoperable content filtering infrastructure (ie parental controls) so that there's some common standard that literally everything supports out of the box. It needs to all work together - the current situation tends to be spotty and unreliable thus parents tend not to bother trying to use it.

    Start with an extensible metadata format that enables websites to self-classify pages. Account for things like loading alternative resources on the same page. Mandate that all websites and app stores include such metadata and that all browsers and operating systems have some baseline functionality for making use of such data in a sensible manner.

    Only after that has completely and utterly failed should we even begin to consider highly invasive measures such as mandating government ID checks.

  • tjpnz 18 hours ago

    The parenting argument is a complete cop-out. There's no universe where you can be shoulder hovering 24/7. This could've been solved years ago with robust parental controls. But companies like Google just didn't want to because they wanted to shove ads in kids' faces.

    • oneeyedpigeon 18 hours ago

      I think we can approach this from more than one angle. Yes, it cannot be entirely on parents, but parents should bear some responsibility to not just hand a device over to their children with unrestricted access to the entire internet.

      • tjpnz 18 hours ago

        Up until relatively recently you would have to install custom VPNs and maybe add Pihole into the mix to achieve anything close to that. Easy for us here, but we're in a small minority.

        • jeroenhd 18 hours ago

          Parental controls have been part of mobile devices for years, but so have bypasses. For instance, you can bypass Google's parental control settings by opening the help page in the Google settings and clicking links until you get to the Google homepage.

          I doubt it matters because nobody seems to configure the parental controls that are there, anyway. Only schools seem to try, and only because they're legally held responsible for what kids do on their computers.

          • pbhjpbhj 17 hours ago

            Parental controls are complicated and obscure, IME. Setting up a child to play Minecraft through Microsoft was like setting up a web server with firewalls and reverse proxy... only less sensible. I'd appreciate that is so they can get parents to set accounts as 'adult' so Microsoft can exploit them.

            You can set up, for example a child friendly DNS (Family version of OpenDNS) then Firefox come along and bypass it (DoH).

            Probably, we need an OS level setting, per account, browsers would need to expose it to websites, apps installed would have to check and provide content according to local legislation/rules. Bypasses would have to be performed by an "adult" account.

            The main issue is that adults would be able to set themselves as children and avoid negative commercial activity. That's a problem because it means FANG, etc, will lobby against it and then ensure their implementations are convoluted and broken.

    • account42 17 hours ago

      Parenting doesn't have to mean become a helicopter either. In fact, that's the worst kind of parenting because it doesn't prepare the kid for a future without a parent around.

    • SirMaster 7 hours ago

      Good parenting is not shoulder hovering... It's teaching and instilling values and lessons that get the child to make the right choices in regard to what they do with technology. Like how we teach kids not to talk to strangers.

      Parents should be teaching kids from a early age how to use technology responsibly.

  • Xelbair 17 hours ago

    >It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.

    Then who should? Government, where each implementation strips away rights to privacy - which in some countries, including mine, are a constitutional right? Where it expands powers of government to track everyone's activity online - and remember we're one election away from total policy shift(just like with latest US elections)?

    Free market? The profitable solution is, depending on environment - either ignore the problem(profit from ads served to children, no extra work necessary), or strip away all privacy (to filter out bots and get paid more per ad).

    The sad reality is that "parent should take responsibility" is least bad option available, and takes into the account individual development of a child.

    Even creation of a highly regulated child only internet creates more problems - as now that becomes a highly profitable target for bad actors(both individual abusers, and companies trying to serve ads)

    • account42 17 hours ago

      Let's also not forget that many of the problems this supposedly solves are not even specific to children. The attention economy is bad for everyone.

    • ben_w 17 hours ago

      In principle, it is possible to make a privacy-preserving age check.

      Site/app asks "≥18?", device generates a UUID specifically for that [app/domain + device], the device passes that UUID to government database along with the "≥18?" question and the ID card info but not the app/domain, government database gives the answer and signs just the UUID and the answer and doesn't include any ID card info.

      Government doesn't know what you're looking at, website doesn't know your ID.

      (There's probably also better ways to do all this, I'm not a cryptographer and I expect that will be obvious from this comment to people who are).

      • Xelbair 16 hours ago

        In reality, the ones making such check will want extra capabilities 'just in case' as we observe now, or just go for simpler solution because it's cheaper.

        How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.

        It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.

        Even in countries in which this requires a subpoena, agencies break the law frequently and don't get punished.

        Legal systems aren't computer systems. This isn't a technical problem but a social/political one.

        • ben_w 15 hours ago

          > How does it prevent fingerprinting if you get access to both logs and try to time it? Even more so if you include already present tracking infrastructure, which as a government you can just request data from.

          True, but as this problem exists without any ID at all*, I don't see how the addition of the ID cards makes any difference?

          > It is possible to de-anonymize people based on aggregate data already, and this proposed solution just adds extra data points.

          This is why I specified a "UUID specifically for that [app/domain + device]". Can't aggregate when each app/domain gets a different signed UUID.

          > Legal systems aren't computer systems. This isn't a technical problem but a social/political one.

          While true, the reverse also applies: computer systems are not legal systems.

          I think many lawmakers' ignorance of this is to the detriment of everyone.

          In this case, the social/political problem is: we want to stop kids accessing age-inappropriate material.

          The options-space for doing this appears to be:

          (0) give up

          (1) require parents to limit their kids' behaviour (to which I say: "Have you met a kid? Do you remember being one?")

          (2) require websites to age-rank appropriately (to which I say in a sarcastic tone of voice: "Gee, that worked soooooo well for GDPR")

          (3) require operating systems to intermediate. Will this suck? Yes. Will it be buggy? Also yes. Will there be false positives and false negatives? Yes to both. Will it be a constant fight as kids keep finding loopholes? Indeed.

          But you know what else? All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out. A school full of kids can beat their parents at the security game because they have more time to spend on finding exploits than the parents have to spend keeping up, the reverse is true of the difference between kids and Google LLC etc.

          It doesn't need to be perfect, the kids aren't a computer program.

          What does need to be held to a high standard is making sure the OSes don't leak all over the place.

          * to be specific, the Investigatory Powers Act 2016 is one of two reasons I left the UK, just look at how over-broad the "Internet connection records without a warrant" list is https://en.wikipedia.org/wiki/Investigatory_Powers_Act_2016#...

          • baby_souffle 15 hours ago

            > All that psych testing Facebook have used for evil, can also catch bugs and loopholes faster than kids can figure them out

            What would be the incentive for meta to deploy that against their own self interests?

            > Will it be a constant fight as kids keep finding loopholes? Indeed.

            Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…

            • ben_w 15 hours ago

              > What would be the incentive for meta to deploy that against their own self interests?

              The normal method is passing laws. That's kinda the point of laws.

              Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.

              > Good thing there are no other issues we as a species face. Let’s burn resources on a sysphian task because what else were we going to do with them…

              Hardly. This is more like gardening. It matters much less if kids get a few days of messing around where they're not ment to be, than if it's continuous.

              And ultimately, if you want to run a business without spending money on legally required actions, you're in the wrong business, nobody should shed tears for you.

              • handedness 10 hours ago

                > Zuckerberg may be arrogant as hell, think he can bully governments into bending over backwards for him, governments have guns and get to arrest (and have in the past arrested) anyone local who does what Zuckerberg says instead of what the laws say when they are in conflict.

                In an ideal world. Personal experience has shown that isn't the case with him.

          • Xelbair 12 hours ago

            >The options-space for doing this appears to be:

            (0) give up

            ...

            (n) waste resources

            yeah, i think current state is good enough, might as well slap regulation and ban any form of targetted ads.

            • ben_w 11 hours ago

              I'd be on board with banning micro-targeted ads, and more broadly any use of psychology to induce similar states as regulated exogenous drugs equivalent to the simple language descriptions of US Schedule I, II, and III.

              However, the issues are rather broader than showing ads to kids who have no money to spend on whatever is being advertised.

      • fsflover 16 hours ago

        > Government doesn't know what you're looking at, website doesn't know your ID.

        But then the government knows your location at any point of time and how often you use websites requiring the age check. Also, if your device is configured to do it automatically, a child can also follow this verification.

        • ben_w 15 hours ago

          > But then the government knows your location at any point of time and how often you use websites requiring the age check.

          Not as described. There's no location info in that path, and the signed statement of that UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.

          (Should I consider expiry? It's not like people age backwards?)

          > Also, if your device is configured to do it automatically, a child can also follow this verification.

          Yes, if that device has been associated with a government ID and also the government ID signing process fails to make use the things we've already got on-device like how my phone reads my fingerprint to know I'm me and can store copies of some forms of government ID (in some places but not where I live, Apple Wallet apparently only supports some US states, Japan, Greece, and UAE).

          • baby_souffle 15 hours ago

            > Not as described. There's no location info in that path

            Ip address and general time of day will tell you a lot about location. Not street level, but country or state level.

            > UUID passing the age check does not need to be re-signed because I've not given any consideration to expiry.

            So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?

            • ben_w 14 hours ago

              > So as soon as any one uuid is leaked, it becomes plausible for any child to bypass the gates until the uuid is manually revoked?

              How? Phones are already locked down pretty hard. Anything like this would need to be in something secured at the OS level just to stop signatures getting leaked between apps.

              If you're thinking "kid roots device, replaces OS entirely", that's not the problem of the manufacturer of the OS that just got deleted.

              • baby_souffle 4 hours ago

                > How? Phones are already locked down pretty hard

                But never well enough, it seems.

                If you can't revoke the token then I'll just sell mine to whomever needs it.

                Kids will beg/borrow/steal their parents / older siblings ... etc.

                The "harden the device, bake in controls that are difficult to circumvent and managed by not-the-primary-device-user" approach is _very_ similar to DRM. All that does is punish the innocent.

                I have never once had VLC tell me that the mkv file I just opened can't be played because I'm not in the right region or because my screen is too old to support encryption. I have had family learn the hard way that DRM is not in their best interest, though. Now they just ask me for the movie on a pen drive when I visit next :).

        • mrguyorama 13 hours ago

          Google and Verizon sell that data to the government right now. The US's official position is that buying info they aren't legally allowed to collect is perfectly fine, as if you were given a privacy right in the constitution only to enable an info broker economy, and not because of the obvious and understood harms of the government having whatever info about you they want.

          If you want the US government to not know something about you, unfortunately there's a lot of changes that need to happen, including entirely new political parties and making changes to the Supreme Court, and popular support for taking the privacy rights you already have much more seriously.

      • baby_souffle 15 hours ago

        This can’t work because it creates a market for people that have an ID that cleared gates to lease/borrow to those that can’t.

        • undersuit 11 hours ago

          And the verification systems rushing at us are immune to this?

        • ben_w 11 hours ago

          It cannot work *perfectly*, but unlike most crypto stuff, it doesn't have to (at least, that part doesn't need to). It's a social/political problem, not a technical one.

          The goal doesn't even need to be to make a completely perfect, impossible to circumvent, barrier for all minors; all this needs to do is just make it equally difficult for a minor to get adult (for whatever definition thereof) content online as it is to get tobacco or alcohol or gambling in real life, the hard part being to do so without compromising privacy, privacy being the bit which has to be done perfectly.

          • baby_souffle 4 hours ago

            > (for whatever definition thereof)

            See, that's why this can't be solved technically.

            Pornhub has a decent amount of sexual health material on it so there's an argument to be made for allowing teens access to at least parts of it.

            > privacy being the bit which has to be done perfectly.

            > It cannot work perfectly

            So we agree that this is going to end poorly?

  • codingjoe 17 hours ago

    100%, it's not like adults are immune to misinformation, social media addiction or scams. Those platforms should be safe for all people regardless of their age, nationality, sexual orientation, gender or religion.

  • jonathanstrange 17 hours ago

    > It’s also pretty obvious that saying “parent should take responsibility” is also not working. Just observe the world around you to know it’s a non starter.

    That's like saying "take a look at owners of fast sport cars, it's obvious this is not working and they have too many accidents." If you want to patronize other parents and think the government should be more responsible and parents less responsible, please state that honestly. Don't make up alleged "facts" to make a point.

    Otherwise, I'll just say "it's obvious you're wrong, just observe the world around you and you know age verification is a non starter."

  • Okawari 16 hours ago

    We have cars, and kids are not allowed to drive them. Yet we do not have mechanisms in place to ensure kids aren't driving cars because the responsibility falls on the parents, and it works. By and large, parents understand the threats and navigate this requirement perfectly fine; outliers are few enough that we can deal with them on an individual basis.

    The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small. Personally, my vote is that they just don't think it's that big of a problem.

    To me, the ideal solution would be more granular and better parental control configurations, especially on the web. Pair that with preconfigured devices that have "unremovable" parental controls, branded as "kids/youth phones." If parents care about this, they'll buy those phones for their kids and the problem is solved. If they don't, then this isn't something parents want, and we shouldn't really pursue it further.

    • mapontosevenths 16 hours ago

      > The reason the current system doesn't work when it comes to unfettered internet access is either that parents by and large don't actually agree with the threat assessment of said internet access for kids, or they ignore it because the consequences of doing so are disproportionately small.

      Sometimes parents know their children, and what's best for them, better than faceless politicians (who we've seen are often attracted to said children for some reason).

      Growing up in my household there was a time when I was allowed to read and watch whatever I found interesting. My younger brother was not. That was because my parents knew us and judged that at my level of maturity I was unlikely to be negatively impacted, whereas my brother would get nightmares or copy-cat things he saw that he definitely shouldn't.

      That's how it should be. Yes, there are bad parents who will decide poorly. That's the cost of freedom.

      • nathan_compton 13 hours ago

        I sympathetic to this perspective, as a parent, but also, there are just a lot of kids out there with bad parents.

        My personal philosophy is that parents have a duty to raise their children but that duty is on behalf of the society into which the children will eventually enter. Consequently, a just society may sometimes impose itself on parental freedoms (in the case of neglect, for example) because, in the end, the child's ultimate guardian and responsibility is the society itself, not the parents. The internet is full of material exposure to which, for children, could reasonably be construed as neglect or abuse, and it is insufficient to leave the entirety of the responsibility to the parents, in that case.

        I don't know why Americans are so obsessed with freedom as if were the only social good that a society can pursue. There are many things which make life worth living, that contribute to flourishing, and freedom is high on that list, but its not the only thing.

        All that said, I don't approve of age checks of the sort being proposed everywhere now. We can do a lot better at mitigating these problems without damaging privacy so much.

    • 2OEH8eoCRo0 12 hours ago

      Parents haven't asked for help keeping their children from driving their car though.

  • duskdozer 15 hours ago

    Children here are a distraction. Any harm these companies are causing to children is also being inflicted on adults. The correct solution is to end the harmful behavior for all, not set up required identity verification.

  • StingyJelly 13 hours ago

    > Companies have show that they are incapable or unwilling to address the problems they cause

    > This is where regulation is supposed to come in.

    This is such a misdirected effort... Why the heck are we focusing on addressing those problems for a small subset of population (kids) while creating even bigger problems for the rest? Lets regulate those companies into actually addressing the problems they cause for everyone!

  • DANmode 12 hours ago

    > It’s also pretty obvious that saying “parent should take responsibility” is also not working.

    So punish those people.

    Stop letting them neglect the responsibility a parent innately has to their child

    and to the rest of us.

    • 2OEH8eoCRo0 12 hours ago

      Stop punishing me by asking for ID when I buy alcohol!

      • DANmode 3 hours ago

        If you are an elderly person, this position becomes wildly reasonable.

        No youths are spoofing being 75 at the corner store.

  • 2OEH8eoCRo0 12 hours ago

    > companies have shown that they will abuse any personal information that is shared with them

    This is the rot at the center of tech IMO. We have all these wondrous toys but we can't do something as simple as verify age without abuse. What's the point of all this tech if we can't trust any of it?

  • hbn 12 hours ago

    There's nothing to be confused about, this isn't about age verification. It's about increasing surveillance and ending anonymity.

    The "think of the children" shit is just a tactic to make emotional, non-critical-thinking people into die-hard soldiers for the cause that get angry when you argue against it.

    "Oh you're against protecting children? What are you, some kind of pedophile?"

codedokode 6 hours ago

In my opinion, Google makes the UI too complicated and geeky which means parents are less likely to use it. Furthermore, they apply partial solution instead of complete architecture. In the article, the app must actively ask for age which means apps not asking the age, like Telegram still would allow access to inappropriate content.

There should be a single checkbox, "parent mode", which applies government-approved configuration, and the minority who bother, can manually edit it further. Many people are too lazy or not good with computers so the UI should be simple and not what is shown in the screenshots.

There is no need to ask the permission to get age information.

The parent mode should work on "white list" principle:

- only white-listed apps may be installed (list provided by government, parent may edit)

- in those apps ("age-aware apps"), only age-appropriate content is available. In a messenger, only parent- or school-approved contacts may be added.

- the browser refuses to open any web page not having a government-approved signature in HTTP headers (geek minority can add their signatures to the white list). Adult sites are not allowed to have such a signature.

- there should not be multiple age gradations, 3 is enough (adult, teenager, tiny child).

So all parents or store employee should do is to tick the checkbox and set a password or fingerprint for management.

It wouldn't solve the problem completely because there are many irresponsible parents.

  • aceazzameen 2 hours ago

    Haven't video games solved this a long time ago with age ratings on the games themselves? Sony and Microsoft's parental controls are convoluted garbage with logins galore. But Nintendo's, at least on the Switch 1, was dead simple. You enable parental controls, set an age rating, and password. Done. There's an app to set time limits, whitelist/blacklist games, etc. That was the easiest UX I've seen.

    Games (apps) dont need to know the age of the user to access them. Even the parental control didn't know the child's real age. It just knew if the child had access to E, E10+, T, M, etc.

    Why are we trying to reinvent this? Oh yeah more data collection.

    • codedokode 1 hour ago

      The problem that apps are not games. For example, a messaging app might not allow to add contacts or subscribe to channels (blogs) without parent permission in "child mode", and have no restrictions in "adult mode". And Youtube might hide some videos and topics in "child mode". Obviously, you could make several versions for the app, but that is code duplication and nobody likes it.

random_ind_dude 18 hours ago

I think it's the old that need to be protected more on the Internet since they disproportionately fall prey to online scams. So let's age-gate their access to online services too. If you are old and want to send money to someone, you get age-gating and second-factor authorization from a competent young person. If you want to watch porn online, believe it or not, age-gating and second-factor authorization.

  • jeroenhd 17 hours ago

    Honestly, I wouldn't be opposed to that either. If we're protecting kids, we should also protect the old and feeble. Old people, people with developmental handicaps, you name it: they're being exposed to a world that can and will abuse you if you have any faith in humanity left and don't have the technical skills to identify things like fake domains and scam sites.

    For some reason we're making sure no 12 year old can drive or run for any government positions, but a 90 year old can keep the driver's license that they've had since before the start of colour television, or make critical decisions affecting millions. We can't have it both ways.

    • kova12 8 hours ago

      It would be hilarious when some services become unavailable to 55+. The whole age check scam will dissolve in a heartbeat

      • lII1lIlI11ll 8 hours ago

        Not necessary. People who still transfer their life savings to some "I'm with MicroSoft tech support" guy shouldn't be allowed to vote either TBH.

      • ColdStream 4 hours ago

        Maybe we should push that then, don't go around the problem but head face first into it. Force the bottom of the bucket to blow out.

    • xg15 8 hours ago

      Waiting for the first 90 year old president...

      • ColdStream 4 hours ago

        Well Donny T is working on it but as the saying goes, if you want the gods to laugh - tell them your plans.

mlmonkey 1 hour ago

"Age verification"?? No! It's ID verification. Advertisers will pay a lot more if they have accurate demographic data associated with a cookie.

In a previous job, our company licensed data from Experian, and in realtime, we could attached an Experian ID with every Ad request sent to the Ad exchange(s). It significantly boosted our revenues, enough that the millions we were paying Experian for the data was worth it. This was 15 years ago, so memory is fuzzy.

xinayder 18 hours ago

Can't we build a gateway in the internet that detects if someone is a influential CEO or something and just bar access to the internet?

  • sschueller 18 hours ago

    If you have more than 100 million in the bank you should be barred from using the internet...

    • whatsupdog 7 hours ago

      Cool, so no change? Even even a multi-billionaire usually doesn't have a 100 million lying in the bank (unless they sold some asset and are going to buy another soon).

      • dewey 7 hours ago

        I think you know yourself that the parent poster didn't mean literally coins in a bank vault like Scrooge McDuck.

        • whatsupdog 1 hour ago

          He/she literally said "more than 100 million in the bank". Care to explain what that means other than bank balance in a checking/saving account?

  • shrubby 18 hours ago

    I was just saying yesterday that we (Finland) could take the bullet and create a luxury resort for all the zillionaires in the world.

    Connect them with each other and populate their air-gapped "Internet" with like-minded authoritarian AI-bots and create special news like Don and Vladimir are being fed to keep them from tantrums. A win win for everyone!

    Ooh, and mental health services. Plenty of mental health services as we're so poor of a race that even our richest can't afford enough therapy to feel alright!

    • ColdStream 4 hours ago

      Zillionaire Matrix, would make a good comedy or horror film.

  • amazingamazing 18 hours ago

    What does this have to do with age verification?

    • deltoidmaximus 17 hours ago

      We've already decided to do verification of users, now we can look into which groups of users should be limited or barred entirely.

  • zx8080 1 hour ago

    So that they make decisions even more disconnected from reality than now? Sure, why not, that does not harm. Cannot be much worse anyway.

Ajedi32 15 hours ago

Well, the API itself seems fairly well designed from a privacy perspective. It only shares age ranges, not specific ages, and only if you allow it. The data is also fuzzed to prevent an app from determining your exact birth date, and it's all tied in to the parental control system.[1]

The problem remains though that, since the laws this feature was created to comply with put the onus on Google to verify the user's age and not on the device owner (e.g. the parents), the method they use to determine the user's age to feed into this API is terrible from both a privacy and freedom perspective: they force you to send them a copy of your government ID, and delete your account if you don't comply.[3]

[1]: https://support.google.com/googleplay/answer/17232873

[2]: https://developer.android.com/google/play/age-signals/unders...

[3]: https://support.google.com/accounts/answer/1333913

  • Aachen 14 hours ago

    The API is tied to a Google account though. You can't simply install an app on Android and have Android tell it what the user's age is, it has to first have google maps, youtube, play services, etc. installed and you need to make an account and log in globally on your device before it can tell the app an age. I don't know that I'd call that a good design for an Android API

  • egorfine 8 hours ago

    Look, it's just a start. Up next: KYC via Persona to use your phone.

    This is kind of inevitable.

  • xg15 4 hours ago

    Interesting that Google offers a method "age verification by email address" that seems to come close to the popular "my account is already more than 18 years old" argument. Only that in this case, they check on which website the account is used, which comes over even more horrible from a privacy perspective.

    Also, the German translation is unintentionally hilarious. They seem to wildly switch between formal and informal pronouns depending on whether the paragraph is about the reader being above 18 years or below.

sunaookami 18 hours ago

This coordinated worldwide effort at the same time is very creepy.

  • inigyou 18 hours ago

    It just means politicians read the news.

    • account42 17 hours ago

      If only they used that time to listen to their constituents instead.

      • DANmode 12 hours ago

        Not a requirement for (re)election in many jurisdictions anymore.

    • DANmode 12 hours ago

      We’re still pretending the Bilderberg Meeting (and similar stuff) don’t exist,

      and don’t assist in orchestrating big, cross-border paradigm shifts like this?

      • johnnyanmac 12 hours ago

        If it just takes a few hundred rich people meeting up a few times a year to manipulate the world economy of billions, that says a lot about the world to begin with.

        • weberer 8 hours ago

          >If it just takes a few hundred rich people meeting up a few times a year

          A few hundred rich people and the world's politicians. Having secret off-the-record meetings, yes.

          • johnnyanmac 8 hours ago

            Yes, worlds politicians, many in western worlds voted in. We need to watch our supposed watchmen

        • DANmode 3 hours ago

          Most of the cooperation required to manipulate markets and legislation is implicit, incentives-based, requiring little or no recordable coordination.

    • hulitu 9 hours ago

      It just means politicians are paid at the same time.

    • __MatrixMan__ 4 hours ago

      You mean the news that the halls of power are full of pedophiles? And then they all thought at once:

      > I know what will help, more metadata about chlidren.

  • IshKebab 17 hours ago

    I think this is actually a reaction to the over-reaching laws various governments are enacting. This is the way it should work - parents check a box that says "the user is 13 years old", and then apps and websites can see what the parent set.

    This is much much better than having to do face scans and credit checks etc. to prove to some sketchy third party that you are over 18.

    I think if Google had bothered to do this 5 years ago we might not be in the shitty situation we are now, but it's probably too late now.

  • frollogaston 1 hour ago

    That's what gets me. It's not like one country demonstrated this then the others followed, it's in parallel. Reminds me of when big US corps kept virtue-signaling around political things at the same time, whether it's now or previous administration.

mmis1000 14 hours ago

I doubt the purpose is even age verification. They already can know I have a visa card which is credit card that can be only applied by an adult by looking at the BIN. Why they need my id card if the purpose is actually age verification?

  • miohtama 14 hours ago

    To verify that your opinions are correct

  • undersuit 11 hours ago

    My Google account is 20 years old, I hope I'm covered by that.

_davide_ 17 hours ago

Seriously ready to fully drop google emails and services, i'm using vivaldi + personal email for a while now, the migration was slow a bit painful but complete. Only the phone is still attached to play store and google, but i'm 100% ready to switch to the fully supported Chinese variant of ColorOS and flush Google into the toilet once and for all. But my next phone will 100% be a Sailfish again.

  • creatacc 17 hours ago

    I run on proton for decade and it's not exactly gmail high tech solution, but it's secure.

    I have mozilla, brave, waterfox, mullvad and a few others.

    It's amazing to see how google and others big companies are marking you as bot.

  • reorder9695 16 hours ago

    For me to fully drop google someone needs to create something compatible with Android Auto in my car, it doesn't sound like a big deal but that's a big enough thing for me to need it now.

    • ooterness 14 hours ago

      Buy a separate tablet and a roll of duct tape. If you're careful, you can completely cover whatever obsolete nonsense is built into the car.

      • warkdarrior 13 hours ago

        Is there an open-source alternative to Android Auto? It cannot be a regular tablet app, its UI has to be adapted to car driving (bigger buttons and simplified UI, at a minimum) and it should make use of the car ECU data.

        • hulitu 9 hours ago

          > Is there an open-source alternative to Android Auto?

          You mean an app that doesn't work ? There are plenty of those.

    • jjulius 8 hours ago

      Standalone Garmin for nav and Bluetooth for music is all anyone should need.

  • dewey 7 hours ago

    Even if you drop Google you'll still have a bunch of websites that now also will require age verification.

    • monksy 2 hours ago

      There are websites that refuse to accept email addresses that aren't @yahoo, gmail, or hotmail. Two that I've encountered are: avianca lifemiles and gentux.

      Also there are services like opencode go that force a gmail account to sign in.

potato-peeler 17 hours ago

> in our ongoing partnership with parents and developers by announcing the expansion of the Google Play Age Signals API

Which parents and which developers? How many of them? From where?

FloatArtifact 19 hours ago

I don't understand why apps need to know anything about a specific age. If we have to go down this road, which I really don't, why can't we just simply have verification whether or not an age fits within a range better yet a category. Yes, age can still be inferred, for example, under 21 or over 21.

  • dmantis 18 hours ago

    The API behaves this way:

    > To request a user's age range and sharing status, you call the Play Age Signals API (beta) from your app at runtime. The default age ranges the API returns are 0-12, 13-15, 16-17, and 18+, but you can receive custom age ranges.

    https://developer.android.com/google/play/age-signals/use-ag...

    But I don't find it any better. I don't see any viable reason to provide identification to my phone's OS. If a parent buys a phone for their child, they can already set up parental controls before handing it over.

    I wish Motorola all the best with their GrapheneOS partnership.

    • inigyou 18 hours ago

      You can also get GrapheneOS right now on Google-branded hardware, which is expensive but not enshittified.

      • dmantis 18 hours ago

        True. Though I have mixed feelings buying new pixel from Google after all these actions.

        • theandrewbailey 18 hours ago

          Then buy a used or open box one. There's plenty of people who try switching to Android and buy Pixels, but go back to their iPhones in a week.

        • inigyou 18 hours ago

          I don't. When they start making shit hardware, stop buying their hardware. As long as it's good, buy it. That's a free market price signal.

          • r_lee 16 hours ago

            I don't think there's enough GrapheneOS users to make a 'free market price signal' here

            • inigyou 2 hours ago

              I'm going to stop visiting the restaurant that makes the best food to spite them because I don't like their delivery policies, even though I'm going to eat inside.

      • gruez 18 hours ago

        >which is expensive

        The rumored Motorola devices are even more expensive. It's the signature and some foldables, all in the 1000+ MSRP range. At least with pixels you can get the a series for as little as 400 on sale.

        • superloika 18 hours ago

          If you buy one of the Motorola Grapheneos phones, you're gonna be marked. You will stand out in the crowd. It has happened before and will happen more frequently as the world becomes more authoritarian.

          • inigyou 18 hours ago

            Yes, people can tell a phone is running Graphene. They just can't get in.

          • dmantis 18 hours ago

            On the other hand, privacy becomes a luxury. People love signaling their status and standing out from the crowd. Entire car and clothing brands exist solely because of that.

            And if enough people stand out, it doesn't matter anymore.

          • iamnothere 10 hours ago

            Oh but “the government already knows everything” as all the other privacy doomers like to say. “They” can probably already predict what phone you’re going to buy and what you’re going to eat for lunch, right? So why worry about this?

      • goda90 18 hours ago

        LineageOS is still a thing too.

  • jasonvorhe 18 hours ago

    Because it's not about age at all. That's just ruse to get a lever to lock people out of their devices if they don't behave.

    • user43928 18 hours ago

      How would that make sense?

      If anything, I would imagine that Google's changes are motivated by driving traffic to their Google Play Store, where they make billions in commissions.

      Once this framework is in place for the Google Play Store, perhaps they can lobby for strict age verification laws, and then tell developers who publish outside of Google Play that they are responsible for compliance themselves.

      • shevy-java 18 hours ago

        It makes total sense. You here assume that this is only driven by Google. Once you include state actors, suddenly it makes sense.

        They gather more data now. Only verified users will be able to use the internet in unrestricted ways - that is what is new.

        • user43928 17 hours ago

          When there is a clear motivation to protect a $50B/year revenue stream, that seems to be the more likely explanation.

          If it appeals to politicians who view "protect the children" and surveillance positively, that is a bonus.

      • gnoll_of_gozag 15 hours ago

        people on discord get sniped semi regularly by fraudulent child exploitation reports

        • warkdarrior 13 hours ago

          And these Discord child exploitation reports are sent to Google? And Google enforces them by locking down the user's Android phone?

    • roysting 18 hours ago

      It's amazing how naive and gullible people are even after all the many thousands of examples of lies and gaslighting over many generations now. It seems to be a permanent characteristic of a certain subset of people, and seemingly a majority of people, at least in the west and at least in this era.

      It always gives me the "he only beats me because he loves me" or "he wouldn't beat me if I knew how to behave better" vibes. It's not healthy, not sane, not rational.

      One disagreement though; I don't even think they will lock people out of their devices outside of very narrow and specific instances or examples to "cut the grass" as the Israelis call it, to scare and remind people they are the slaves and the long arm of the tyranny can reach out and crush them if they don't self-censor and self-subjugate. Psychological and ideological control has very much proved itself far more effective than physical control in all circumstances. They want to be able to monitor and then use methods and technologies to control that have not really come to light in society even thought they were systematized through the Iraq war. You are now the "insurgents", are you old enough to remember those, those insurgents in their own country?

  • soulofmischief 18 hours ago

    This isn't aimed at you specifically, but I think many technologists seem to innately misunderstand the slippery slope hypothesis which helps form the bedrock of American politics.

    Too many seem to fall into the familiar problem-solving mode, ready to provide compromises or solutions while forgetting that once the infrastructure is in place, it can easily be modified later to undo the compromises which facilitated its acceptance in the first place. There is an inherent power asymmetry and it's not generally in favor of those building and using the infrastructure.

    • shevy-java 18 hours ago

      Indeed - Flock cameras showed this.

      They also actively undermine the US constitution. Will be interesting to see whether the remaining judges have any power to change this or whether they were also integrated into the new dictatorship model.

      • pbhjpbhj 17 hours ago

        Surely it's not the camera per se, it iss the people who are installing them. One key driver is lack of efficient law enforcement.

        Do you force people not to give up their own liberties? In a democracy?

        Although better privacy laws would cut off the access of non-customers to the data of those customers devices.

        • soulofmischief 8 hours ago

          So much of this discussion is moot because the point is there is a slippery slope. It doesn't matter if there's an unconstitutional war on drugs which creates distrust and massively diverts law enforcement away from serious crime and instead towards ruining the lives of poor families. It doesn't matter if we're in a new age of McCarthyism or not, or if we're in the middle of a hyperfascist political coup and I don't even feel comfortable protesting in public in my city now that people are getting 30-year felony sentences for moving boxes and the city's new cameras and police drones can track me from my home to anywhere downtown and back.

          These things could be true or not. It's the fact that they could be true which means that we cannot allow ourselves to slip into an unretractable surveillance capitalist hellscape. That means people must have avenues to stop things like this.

          Petitioning city hall doesn't seem to be working; in fact, it's waking many people up to the fact that their local governments are not working for their interests, as mayors openly discuss banning discussion about data centers.

          Laws exist because some people won't play nice otherwise. It is asymmetrical to put the burden of defense of liberty on the individual. The individual is the last line of defense against the government, and when it is the individual's turn to act, it's because law has already failed.

          We need to act, and fix the law, so that I don't have to act like a paranoid psycho around others in my life who are wholly unequipped to understand or even care about this problem.

  • shevy-java 18 hours ago

    Because it has never been merely about age only.

    They want to track everyone now. Age sniffing is just one additional step for forcing verification. This will continue - see how suspiciously many countries adopt new legislation. It is quite fascinating to me to see how easy it is to kill off democracies.

  • jeroenhd 18 hours ago

    Laws have been written that mandate that applications and services treat various age ranges differently. You can't serve porn to kids, kids under 15/16 have very strict privacy regulations in some areas, and certain content age ratings are an industry standard only because that was the industry way of getting out of being regulated.

    For kids this is a privacy risk because there are so many thresholds. Once you're above 18, all you need to care about is "are you a pensioner".

    Kids have been lying about their age since the dawn of the internet and people have started catching on, so now we're getting actual restrictions rather than the assertion that nobody in their right mind would click "I am 18 or older" to access a website.

    Californian law mandates that operating systems keep track of their users' age, so of course Android must follow. In all of the cases listed on Google's blog, though, the option to not share information and download an app that doesn't ask for your age range is still an option.

noirscape 17 hours ago

Why is this part of Play Services? It should be something on-device as part of AOSP, not something that further entrenches Google.

(In case it's not obvious: rethorical question, Google just wants to do platform lock-in with Android and sees this as a useful means to bludgeon it.)

prartichoke 18 hours ago

What a pain reading this blog post. It's about them complying with recent regulations, but they never mention it once: they word it so it sounds like they are doing this out of the good of their hearts. The words "law," "regulation," or "compliance" do not appear once, despite being the entire reason the post exists.

Also on the "privacy-preserving tool", technically apps get a bracket ("16–17") instead of a birthdate. But who holds the actual data? Google. The privacy improvement is against the developer only.

  • charcircuit 13 hours ago

    Google has always had your birthday.

  • EmbarrassedHelp 2 hours ago

    The blog post lists regions where it is not mandatory

BoxwoodSeed 18 hours ago

I'd be totally fine to solve this problem by banning children from the internet altogether. Not that I'd enforce this or anything. Just so no one other than the parents can be liable when things go wrong.

There's more and more evidence that internet access isn't healthy to have for children anyway.

  • inigyou 18 hours ago

    Yeah. And if a kid drinks beer only the parents should be liable.

    Why are we all so horny to transfer unlimited liability to parents?

    • danparsonson 18 hours ago

      Because raising children is unequivocally the parents' responsibility. It's, like, their main job.

      • inigyou 17 hours ago

        But we don't put barbed wire on random sidewalks and then blame parents if a kid walks over it and gets hurt. There is the attractive nuisance doctrine, among other things.

        • account42 16 hours ago

          We don't leave the barbed wire on the side walk but require everyone that wants to walk on it to age verify first either. And the attractive nuisance doctrine some states have is absolutely bonkers.

          • jodrellblank 14 hours ago

            Yes we do leave pubs on the sidewalk and require everyone that wants to drink there to age verify first, what are you talking about

      • pbhjpbhj 17 hours ago

        Viewing the continuance of our race as only the responsibility of parents is pathological.

        Moreover, children are all of our [mid-term] futures too. If education fails, there are no doctors for anyone not ultra-wealthy.

        You have to look from the other direction too - children have natural rights and deserve to be extending dignity as humans too.

        • krapp 16 hours ago

          >Viewing the continuance of our race as only the responsibility of parents is pathological.

          That seems to be a uniquely American pathology.

          Everywhere where else in the world, and in non-white American subcultures, the community taking a hand in raising children is expected. But many Americans seem to consider it socialist and an attack on Christian values.

          See Hillary Clinton getting mocked for saying "it takes a village"[0] or BLM being accused of wanting to "destroy the nuclear family" by encouraging community based parenting[1].

          [0]https://www.cnn.com/ALLPOLITICS/1996/news/9608/27/hillary.sp...

          [1]https://medium.com/@emailnatesmith/the-blm-statement-on-fami...

          • inigyou 2 hours ago

            It's extra weird because the concept of a nuclear family was invented by advertising agencies in the 1950s to sell suburban houses and cars.

    • sevenzero 18 hours ago

      You have a kid, you have responsibility for that kid. In Germany we have a term "Aufsichtspflicht" for this, which roughly translates to duty of supervision. Up to a certain age of the kid parents will be made responsible for damages your kid caused. One pretty funny example of that was a kid spending 1000s of Euros on a MMORPG because the MMO offered a payment option that allowed people to pay through their phone bill. Parents could've easily prevented any of that happening, but in that generation it was pretty common that kids were tech savvy while parents couldn't be bothered to learn about computers, which imo already is problematic.

      Nowadays there are many many ways to supervise your children's online access. And yes, there are also many many ways for kids to work around that too, but ultimately if you buy your kid a device with internet access, you should try to supervise that. Parents need to care more about what their children are up to, instead of silencing them with a tablet for a moment of personal silence.

      • inigyou 17 hours ago

        ¿What are those ways?

        • sevenzero 17 hours ago

          A small example would be to set the device into "kiosk mode" which many companies use for their employee devices too. Prevent app installs, check what pages ur kids visit with their browsers and whatnot. Just make sure to be open about it so you don't hurt your kids by violating their privacy and trust towards you. Hell we even got parents having their kids take air tags with them so the parents know where they are.

          • inigyou 17 hours ago

            Or the device could be mandated to have a "child mode" with more specific restrictions designed for children.

  • r_lee 15 hours ago

    I would've never learnt to program or learnt to speak English or learn about other cultures

    thanks so much for being awesome like this, pulling the ladder when it no longer concerns you. so mature and brave

neilv 12 hours ago

> The Play Age Signals API is a privacy-preserving tool that puts parents in the driver's seat allowing them to share their child's age range (e.g. 16-17) directly with apps.

Sounds like an adtech targeting demographic, not protecting children.

  • DANmode 12 hours ago

    Everything Google makes is, or will end up supporting the usage of, adtech.

yonaguska 14 hours ago

I'm surprised that there are so many still think that this is really about protecting kids. This is not an organic movement at all.

  • techblueberry 2 hours ago

    What’s it really about then? Every circle i’m a part of is concerned about this.

mihaic 3 hours ago

I made a Gmail account in 2004. I'm still periodically asked for my birthday, just so Google knows I'm over 18. The stated purpose is almost always an excuse for more data.

monksy 2 hours ago

Yes google. You are the bad guy. Full stop.

You took being evil very seriously.

wewewedxfgdf 18 hours ago

What's the difference between an age check and a total identification check?

  • palata 17 hours ago

    If you can only check that the person is above age without checking who they are, then it's not the same, is it?

ChoGGi 14 hours ago

It's not like children can buy overpriced phones or tablets. You can force the stores to help setup up restrictions for their devices for parents that don't know how or want to. Then start doing massive fines and restrictions on websites or app stores that host unregulated apps.

If they can afford to buy them on their own, good for them.

You don't use age to decide what's appropriate; I don't mind if my kids see naked bodies. I do care if they see naked porn star bodies, and porn, although actual amateur porn with a range of body shapes is okay. Fighting is okay, but actual graphic bloody violence is less so (funkytown cartel video is no bueno).

Put that in an age range Google.

  • polipputter 13 hours ago

    Who decides who's regulating these apps and what would classify an app as regulated? This sounds like what googles doing with their current monopolistic attempt to force users to only download apps from the play store and force any dev who wants to post their apps there register with Google, hand over ID, and pay Google a fee to be allowed the classification that they're regulated. Meanwhile the play store itself is full of malware riddled apps and even googles own apps are spyware used by them to aggregate as much data on each user as possible in order to sell that data to ad companies and governments

jaimex2 47 minutes ago

Fake ids, fake ids everywhere...

rawling 17 hours ago

> expand... worldwide till the end of the year

So at the end of the year they contract again?

Or should the headline read _by_ the end of the year?

kelvinjps10 14 hours ago

I think also something needs to be done to the companies that we know are targeting teens and children with tactics for addiction. Meta was found to have engaged in such tactics and nothing really happened to them

mikewarot 10 hours ago

Who hasn't handed their phone to their kid at some point? This is a bad idea.

It would be far better if the user could set the age dynamically, as part of a capabilities set, and the browser could forward that data.

Then a person could hand over their phone to a child or a border agent in safety.

goda90 16 hours ago

Besides the page header and footer, the post has 0 use of the word "Android", which feels telling of Google's approach these days.

egorfine 8 hours ago

I hate it so much it makes my blood boil.

The internet as we knew it comes to an end and we are... complicit?

Judging from comments here it seems like some of HN readers do actually unironically take this at face value. Which is weird. Of all people, we should be ones to see what is this going towards.

  • hnav 6 hours ago

    It is difficult to get a man to understand something, when his salary depends on his not understanding it.

timedude 7 hours ago

GrapheneOS has a very bright future ahead

lII1lIlI11ll 17 hours ago

This is actually a step in the right direction. I don't want to share my id and selfie with every stupid social media app/site. I would much rather allow parents to configure their children's devices to share their age.

mythz 18 hours ago

Surveillance comes for us all.

KPGv2 4 hours ago

While we're at it, can we make our TVs verify age, our public libraries verify age, and bookstores verify age?

dageshi 17 hours ago

Doesn't seem like most of the people on this thread actually read what they're planning.

It seems like a very good solution to me. It gives parents a simple solution to define the age of the phones user and a mechanism to allow apps to get an age range and tailor usage appropriately.

It does all this while leaving everyone else undisturbed.

Put the age range into http headers and you solve children accessing content via the web as well.

  • duskdozer 15 hours ago

    Through a Google account. It's not some device check.

    • dageshi 14 hours ago

      Well it's google and google does everything through their accounts.

      But the principle of this can work on everything.

      Own an iphone, apple can do the same tied to the apple account.

      On a windows machine you can do the same tied the user account login for the child.

      People will no doubt pick holes in something like this, but it's the least intrusive, least effort solution to the problem that will actually work.

      • bilkow 8 hours ago

        > It does all this while leaving everyone else undisturbed.

        > it's the least intrusive, least effort solution to the problem that will actually work.

        Currently, I have no account tied to my phone or my computer(s), except for an older iPad. Also, I have never sent my ID to any FAANG company. This would force everyone (including adults) to tie an account to their devices and a government ID to their accounts. Bans (which Google does not justify, a lot of the time) would gate users from using apps and possibly sites.

        In other words, this helps solidify Google's control over Android users. The problem would be the same for Apple, Microsoft, etc, and in many cases it already is the same.

        I get that most people probably have a cloud account for their own devices, and I think that's OK. But currently there is the option not to use their services, and I think that's the fundamental issue, they're effectively removing that option by making apps block users who don't have an account, in the guise of age verification (together with Play Integrity, etc). That option is fundamentally linked to the right to privacy, as once you're required to use certain services to be basically integrated into society (making payments, communicating with others, watching turtle documentaries according to the post) you're not effectively able to exert that right anymore.

        There are also other related rights and freedoms here, like the rights to repair, tinker and innovate, that are affected by this action, which helps cement an ecosystem where every app requires Play Services, and as such, is hard to be ported or emulated into other ecosystems, and other actions from Google and Apple.

cyberax 6 hours ago

> Providing a safe online experience and protecting users from harm is a top priority at Google Play.

No, it's not. Your top priority is squeezing as much money as possible.

Havoc 18 hours ago

Global surveillance incoming.

Heard Google is also rolling out QR codes to get past captchas? Ie linked to a device that would now be identity linked too.

All seems pretty dystopian or to quote googles slogan - being evil

  • cluckindan 18 hours ago

    Incoming? Have you been asleep for 30 years?

  • creatacc 17 hours ago

    I already saw it on youtube. However, ctrl + f5 fixed it.

    On the other hand, youtube became so unusable that I have spotify premium now.

    So, give it a few years and corpos will take it down because of missing profits.

jck86 13 hours ago

Half the internet will be gated in the next two years. If you thought mfa for every silly little site was utterly annoying and social media was an invasion of your privacy then this next wave of digital surveilance will finally turn you into a tech luddite.

kyriakos 15 hours ago

post refers to apps. how about browsers? will this allow browsers to block content based on the user's age ?

htrp 16 hours ago

this just ends up with the movie rating system, gamed and easily ignored by most people

ta8903 17 hours ago

Just like every new Android "feature", the first thing that comes to mind when reading this is how will it work if you aren't logged in to Google on your phone. Am I supposed to give up and pretend it's normal to have to log in to an online account to use a personal computer?

hexo 18 hours ago

"Providing a safe online experience and protecting users from harm is a top priority at Google Play." LOL NO. amount of malware says otherwise.

effnorwood 17 hours ago

Google preps your surveillance device for CBDC without your consent.

soupspaces 13 hours ago

This should be in front page

ChrisArchitect 15 hours ago

Title is: Delivering safer, age-appropriate experiences on Google Play

ReptileMan 15 hours ago

A question to the crypto nerds here - is there a way to prove that you are of age, but you can't be deanonymized even if the government, identity provider and the website itself collaborate to do it?

Razengan 17 hours ago

What's hilarious is how Westerners still think they're much different from China or the former Soviet Union anymore.

  • Cider9986 16 hours ago

    They are still quite different.

    • Razengan 15 hours ago

      Parroting that mantra is how we got here.

      And there's no sign of improvement on the horizon, only the tightening of the noose.

shevy-java 18 hours ago

They want your data.

YOU have become their product.

By the way, this also explains one reason why Google shut down third party access/applications recently on Android. Android (if one uses the Google software) becomes the ultimate spy tool on people. At the same time you see several countries force age sniffing on people - this is the beginning of the end of the free web. It will happen in various steps; the next one is Microsoft adding this to their software.

  • BoxwoodSeed 18 hours ago

    Linux is also ready to support age verification through systemd. Luckily, there are still distros without it, like Void Linux. I switched to it recently and now my media PC boots faster than my TV takes to turn on.

  • shit_game 17 hours ago

    > YOU have become their product

    LOL

    behind the curve, and completely missing the point.

hnxp86ytwk 18 hours ago

This is what I keep telling people

idiotsecant 16 hours ago

'Google will build the walls on their garden two bricks higher by end of year'

napolux 16 hours ago

Age check is only pushed because this way you can tell humans from bots.

Prove me wrong

  • worksonmine 15 hours ago

    There will be ways to circumvent and even use verified devices as botnets.

avazhi 18 hours ago

I couldn’t care less about children or about what is ultimately a parenting issue (keep your fucking kids off the internet). A problem that affects a subset of the population is not something that should be solved by subjecting the entire population to inconvenience. Just make it illegal to use the internet for under 18s or under 16s or whatever and let it be assumed that all users are of the appropriate age.

If I a child is on the internet without adult supervision, that’s a parenting problem, not an issue for the state or other people to solve.

owbt 18 hours ago

The usual "but think of the children" tactic.

looksjjhg 18 hours ago

I don’t understand how are they even checking the age ??

  • OtomotO 18 hours ago

    In some jurisdictions/countries they have to call some government service which then tells them whether a person is above or below a certain age.

    Theoretically you could make this double blind and that's the story they are telling.

    We have no way to (dis)prove it though.

    Alas, here goes the freedom, with thunderous applause.

  • progval 18 hours ago

    They aren't. The device administrators (ie. the parents) set an age range in the OS' config and then the OS tells applications the value. That's it.

    • EmbarrassedHelp 2 hours ago

      The problem is that you may wake up and find this system enabled by default unless you submit to age verification, like the authoritarian bullshit Apple pulled in the UK.

    • EmbarrassedHelp 2 hours ago

      Google's shitty API lets developers force you to verify your age with government ID and selfies, as part of the "ageRangeSource" field: https://developer.android.com/google/play/age-signals/unders...

      And the other problem is that you may wake up and find this system enabled by default for everything unless you submit to age verification, like the authoritarian bullshit Apple pulled in the UK.

cynicalsecurity 18 hours ago

This smells like Soviet Union. The next step will be a requirement to confirm your identity - trying to justify it with a wicked manipulation tactic "we need to know your are not lying when selecting your age". No one asked for it to begin with. Android is normalising totalitarianism and mass spying on citizens, one step at a time. This is a very bad feature and a very bad development.

  • sevenzero 18 hours ago

    Its the same thing with Europe allowing scans of private chats now. Nobody would tolerate a person opening the letters from ur physical mail box and reading through each of them just to see if you do [insert illegal activity]. But once this stuff happens digitally, people seem to simply tolerate it. If I remember correctly, in 2019 there were huge protests against upload filters were people actually protested on the streets in Europe. Now there is almost NOTHING for chat scans, NOTHING for age verifications, NOTHING for making Android less open. Its really frightening what the general public tolerates nowadays.

    • jeroenhd 18 hours ago

      The authorities open letters all the time. Try sending a letter to prison without it getting scanned.

      The problem with this comparison is that the authorities can open a letter if they need to for various well-intended reasons, but they cannot open an encrypted message. Either the authorities can scan all messages, or they can scan no messages, there's no inbetween.

      The mandate to verify age before selling alcohol has been around forever. This is not a new idea. The biggest restriction until now has been that there was no good way to do these kinds of age verification, but that problem has been solved. You can still debate whether or not age verification is a good idea for specific subjects, but selling 10 year olds alcohol or porn has been illegal for much longer than the internet has existed.

      • cluckindan 17 hours ago

        Communicating via PGP encrypted snail mail seems an attractive option.

        • jeroenhd 17 hours ago

          It would make for a good alternative, but so would any app that doesn't implement scanning. If they can force Signal to implement client-side scanning or ban it entirely, they can do the same to PGP software. In theory you could do RSA by hand, but it would require a lot of hard work.

          • EmbarrassedHelp 2 hours ago

            Signal would rather tell a government to fuck off than implement any sort of client side scanning.

      • cynicalsecurity 17 hours ago

        Last time I checked an Android phone was not selling me alcohol or porn. It requires specific deliberate actions to get access to anything like this with a phone. Any checks could be justified on the store or web-site level, not on the phone level. Treating every citizen as a child or even worse a potential criminal who needs to be constantly checked at numerous checkpoints the state so kindly put everywhere is exactly the stinking smells of the Soviet Union I'm talking about.

      • account42 16 hours ago

        And if everyone is treated the same as someone who has been tried and convicted of a crime worthy of incarceration we are well into the dystopia.

  • f6v 18 hours ago

    I think you're misinformed, they didn't have age checks on smartphones in Soviet Union.

    But there're countries where that already exists. They usually get labelled as a threat to democracy. Isn't it ironic? It's as if our own governments are the greatest threat to our way of life.

amazingamazing 18 hours ago

Age checks are inevitable sadly. No one would tolerate “adult” services and goods rendered directly to children without age check.

The main argument is that there is an assumption this data is not stored in the real world, which is only sometimes true. Some places like airports and some concerts, shows, bars, etc. scan identification with digital readers whose data is presumably retained. One reason for this is because fake identification is a thing so defense against this converges to the same solution as digital verification.

Imo best to spend energy thinking of the appropriate solution that minimizes privacy violation than conceptual fighting against the idea.

  • neuroticnews25 18 hours ago

    > No one would tolerate “adult” services and goods rendered directly to children without age check

    I don't think it's fair to say that parents who don't care to use parental control measures already available to them have no tolerance for that.

    • amazingamazing 18 hours ago

      Parental controls don’t solve all of the issues. The same way telling your kids not to do drugs is not a solution to vaping use.

      • neuroticnews25 17 hours ago

        If you don't even try to use simple available measures to prevent your own child from vaping then it's unfair to say you have zero tolerance for children vaping.

        • amazingamazing 17 hours ago

          Strange comment, plenty of parents try and fail to stop their kids to do certain things.

          • neuroticnews25 17 hours ago

            Did you mean "plenty of parents wouldn't tolerate “adult” services and goods rendered directly to children" when you said "No one would tolerate “adult” services and goods rendered directly to children"?

          • account42 16 hours ago

            Then maybe we need to teach parenting in schools instead of trying to outsource it to the government.

      • lII1lIlI11ll 7 hours ago

        That is okay. The optimal amount of "issues" is greater than zero.

    • neuroticnews25 16 hours ago

      Also, for a more substantive answer see: https://news.ycombinator.com/item?id=49108086

      We could settle on a privacy-preserving idea, like physical cards with single-use codes sold in stores after showing ID, similar to alcohol. Then a few years later they would ban cash payments for those. Then require sellers/payment operators to report all transactions to a central registry. The slope has always been slippery.