| ▲ | mosura 2 days ago |
| It is a technical ratchet. Once you accept part of the implementation it will never be undone, more will be added. |
|
| ▲ | terribleperson 2 days ago | parent | next [-] |
| I don't think this is a safe assumption. As a counter, actual age verification is being rolled out in other places. I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. Between the anti-porn types and public demand for some kind of regulations on social media, regulation of some kind is inevitable. Our actual choice may only be what type of restriction we can live with, and I much prefer this type to the kind that requires websites to demand my id and photos of my face. Especially since some implementations of this concept (the California one, I think) declare that websites aren't legally required to look deeper than the attested age, which is a very nice feature. Mind you, I don't know why the legislators are bothering mandating OS support for these features. It would be much easier to mandate that websites support the feature, make it clear to them that supporting the feature appropriately will free them from liability for children accessing content, and then wait as users demand that their OS support the feature. |
| |
| ▲ | xp84 2 days ago | parent | next [-] | | Re: your last paragraph I actually agree with you, if you mandate that the site has to look for an affirmative signal and if it doesn't get one, has to assume the user is the youngest possible age group. Users would demand the proper support for it. Although it would have to have some teeth capable of biting the client software companies, because for instance, if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls). Honestly though - because kids (especially the younger set) are hard pressed to buy their own hardware, a property that can only be set up out of the box, and can only be undone by using the account password of the parent who set it up, it is the perfect level of security here. And as for browsers, all you need is the gatekeepers (Apple, Google, MS) to agree not to ship in their "stores" browsers designed to evade it. Yes, you can totally compile your own browser, but most kids are using locked platforms like iOS and Android, and are by default denied permissions to run arbitrary software on platforms like Mac and Windows, so that's fine. | | |
| ▲ | terribleperson 2 days ago | parent | next [-] | | Yeah, that's pretty much what I am imagining. You're right about needing some teeth - maybe the legislature could define a spec, and penalties for implementing the feature in a commercial product without actually following the spec. I really think all we need is what you describe in your third paragraph. It doesn't need to be bulletproof, it just needs to be an easy way for parents to set the level of content their children can access without them having to hover over their children at all times. Something like that could easily be set up in the Genius store when someone gets a new iPhone, or set up at first boot on an Android phone. That's like 90% of the devices anyone is actually worried about. Windows support of the feature would take it to like 99.9%. | | |
| ▲ | xp84 2 days ago | parent [-] | | Exactly. Fortunately, the kids we're most concerned with - young ones who just want to access their brainrot - has very little overlap with Linux users anyway. So, while I hate this hysterical propaganda portrayal as "aGe vErIfIcAtIoN," an "OSS operating system" exception doesn't really bother me, as long as it doesn't let the usual suspects make an end-run ("Darwin is OSS! See! iOS is exempt") |
| |
| ▲ | pessimizer 2 days ago | parent | prev [-] | | > if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls). If it's a header, you can strip it out at the browser level, the user level, the kernel level, the hardware level, the router level, the router OS level, the router hardware level, or at the ISP level, depending on what a parent (or a state) desired. The teeth are only necessary for the websites, which are never going to conform to the law anyway, whether through a header or through device attestation, without draconian Chinese-level enforcement that has never been seen in the West before. This new contract will have to be enforced at both endpoints. You will need the ID (whatever you want to call it) to get onto the network, whether you're an individual or the site being visited. The idea that device attestation is going to bother the Moldovan tube site your kid gets pirated porn through is a surprisingly ignorant fantasy, especially when it comes from technical people. The Pirate Bay is still up. Megaupload is up and runs better than ever. People have 20 year old torrent site accounts. OS-level age attestation must be a first step, because it won't work. And as to it not being enforced either by the hardware or by identity verification of the user, that's an impossibility. A kid can also overwrite an operating system, or even just overwrite the important part; so that means that either only attested operating systems can be installed, or no user is trusted at any time without state verification. | | |
| ▲ | xp84 2 days ago | parent [-] | | This sounds like a hot take, but I'm way less concerned with sketchy porn sites (mostly for the kind of reasons you say which boil down to ... they're sketchy). I'm more concerned with deliberate manipulation of young people by social media. TikTok and its clones especially have demonstrated an incredibly strong ability to not just addict and brainrot kids (which is bad enough -- and it's really, really bad), but also to shape their opinion. All that discussion about the CPC having complete control if they wanted to exert it wasn't BS. Whoever controls them absolutely can use an algorithmic feed to astroturf "viral" videos pushing any narrative they want. Think of Elon Musk in his role as owner of X if you like the CPC. Anyway. Most tweens and young teens don't know how to use Bittorrent. They use iOS and Android all day, and Chromebooks. These function as closed platforms, and macOS is as well unless you go out of your way. And Windows unless you make your kid an Administrator. Linux and other noncommercial OSS operating systems can have an exception if it makes it less burdensome on the maintainers. This doesn't change the fact that a law like this still solves a ton of problems that parents otherwise can't solve, and that big tech could only solve independently today by very privacy-invasive means. > because it won't work. It sounds like you think "work" means "prevent 100% of minors from seeing even a single frame of Bad Stuff anywhere online on any device" To me "work" means "prevent most children (who aren't extremely technical) from mainstream social media sites openly experimenting on them daily to build a paperclip maximizer, where the paperclips are 'watch minutes' (as a proxy for ad revenue) and the planet being dismantled is our society." It would "work" by this definition. > device attestation this specific term means something specific and is not what this law is about - not sure if you meant to tangle that idea up with this. |
|
| |
| ▲ | JoshTriplett 2 days ago | parent | prev [-] | | > I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. It is impossible to win a battle you stop fighting. | | |
| ▲ | terribleperson 2 days ago | parent [-] | | But it's possible to lose a battle you were never going to win in the first place, and end up in a worse place. I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. Most websites will use it, and it'll become global because it's easier to just demand an ID and a photo for every user through some third party provider than to offer looser restrictions for the handful of states that have different demands. This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas. Sure, you could scrupulously try to identify which state someone is in and use the appropriate level of verification, but then you might be liable if it turns out it was someone from Texas or Georgia or Britain using a VPN. | | |
| ▲ | JoshTriplett 2 days ago | parent | next [-] | | > I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. You are assuming that age verification must necessarily happen. It needs to be destroyed at every possible juncture. | | |
| ▲ | tzs 2 days ago | parent [-] | | What is your objection to the California law? A summary for those not familiar with it: • Operating systems on devices whose primary user is a child must provide a way for the parent to provide age bracket information about the child. • They must also provide an API that apps and app stores can use to find out that age range if they need to have limits on what children can do with them. • They amended it to not apply to most open source operating systems. Note that there is no actual age verification. It just uses what the parents put in. It is really just requiring each OS to have a standardized parental control system. | | |
| ▲ | JoshTriplett 2 days ago | parent | next [-] | | Among many other things, privacy. If you know an age range that's more information about the user than you should have, and you can use it for marketing. And if you can ask for an age range, then in practice you know a birthday; just keep asking until the range changes and record when you saw it change. It's also the wrong way around: apps shouldn't ask for an age range, apps should provide one and the OS should do the checking. I also object to it because it's a foot in the door for demanding that websites and apps care about that age range. And most importantly, devices already provide parental controls in practice, and this law doesn't make those any better, it just unnecessarily cements one aspect of them into law. You can, already, on many devices, say "don't allow installing apps without permission", or "don't allow installing apps except those with this rating". | |
| ▲ | ivl 2 days ago | parent | prev [-] | | A headless server operating system does not need those steps. It does not need the bloat of prepping an API to communicate with websites. |
|
| |
| ▲ | ivl 2 days ago | parent | prev [-] | | > This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas. Hey, give credit where credit's due. The first to try that was NJ going after 3d printed gun developers. | | |
| ▲ | terribleperson 2 days ago | parent [-] | | Yeah, I'm not super happy about all the 3d printing control legislation going around, which I frankly think is a lot more overreaching than these age declaration laws. |
|
|
|
|
|
| ▲ | bodge5000 2 days ago | parent | prev | next [-] |
| Very true, though this is something thats pretty difficult to get to by tiny increments, which is usually how these nefarious means are accomplished. One tiny thing is asked after another, each one too small to put up a fight against, and then suddenly they've crossed your line and you didn't even notice. Thats not particularly easy to do here, so the line will remain just as strong. Maybe next they'll ask maintainers to go from a bracket to a specific age, and then next ask for verification, but the jump from specific age to verification is big enough that there'll be just as much resistance to it. |
|
| ▲ | AnimalMuppet 2 days ago | parent | prev | next [-] |
| Stronger: Once you accept their right to ask, then you open the door to their right to a truthful answer, and thus to a verified answer. |
| |
| ▲ | avianlyric 2 days ago | parent [-] | | Hasn’t the right to ask existed since the invention of consent laws? The state being able demand a persons age, and gate their behaviour based on that, has existed for hundreds of years so far. During that entire time the requirement to be truthful has also existed otherwise the laws would be meaningless. All that’s changing now, is figuring out how that extends into the digital realm. I personally find the argument that the digital realm is somehow special compared to the physical realm, and thus certain laws simply shouldn’t apply when “done on a computer”, difficult to reconcile. | | |
| ▲ | xp84 2 days ago | parent [-] | | Hard agree. I don't think we allowed video store operators in 1995 to just let kids wander into the back room and rent porn, but we're so used to there just being "no rules" online, it is coming as a massive shock now when it's being suggested that maybe there should be some basic guardrails to discourage that. Let me be clear, I don't want face scans, or more of those creepy companies that operate this age verification crap for Discord, etc. Because I know it's not going to be implemented in the privacy-preserving way it could be, if there's ANY involvement with identity documents. Not least because we don't even have any proper cryptographically useful identity cards, so everything like that operates on a "trust us bro" basis where they pinky promise not to accidentally store everyone's raw face scans / ID cards / numbers / etc and inevitably leak them. But out-of-box age declaration is not extreme and is not slippery-slope, any more than out-of-box user account creation 25 years ago has led to out-of-box ID card checks. |
|
|
|
| ▲ | tstrimple 2 days ago | parent | prev | next [-] |
| This is a nonsense argument considering over half the states have already put actual ID verification requirements in front of "adult content". Blue states are trying to ratchet to what red states just pass? Why? They could just follow suit and require you to upload your ID to a 3rd party service and scan your face. Your conspiracy theories don't seem to hold up to reality. |
|
| ▲ | singpolyma3 2 days ago | parent | prev [-] |
| Literally a slippery slope argument |
| |
| ▲ | eterm 2 days ago | parent | next [-] | | Sometimes when you see your opponents getting out a ramp and a barrel of lube, you can call it a slippery slope. | | |
| ▲ | xp84 2 days ago | parent [-] | | Or alternatively - you could recognize that normal people are getting more and more pissed off by the fact that social media companies are force-feeding garbage into their kids eyeballs 16 hours a day. We could give them a reasonable solution that demonstrably preserves privacy and doesn't inconvenience anyone else (Suppose you want to see all the uncensored everything, you open your new PC or phone and say your DOB is 1/1/1900. Done. Status quo.) Or we could be alarmist about that, torpedo that plan, and then in 2 more years when people are even MORE pissed, a horrifying new plan comes out, where the government scans your photo ID (with the help of some crappy private contractor of course) and both of them promise to probably not store the info and log your access. And that one manages to scrape by because people are at that point even more pissed and are determined to solve the problem somehow. The actual 'bad guys' just wouldn't be able to get the public support for that second, shitty plan, if we basically solve the problem now with this very modest plan that's on the table now. Parents can handle this simple one-time out-of-box prompt and it makes sense. Device owner, the parent, that's the one who should make the call. | | |
| ▲ | eterm 2 days ago | parent [-] | | I actually agree with you, but you have an optimism about the ability for open source maintainers to have achievable political aims, in a way that I haven't seen happen for decades. What your happier future looks like requires both a technical solution, but more importantly political wins to sell that solution as the better one. The current operating systems weighted by users, are entirely under the control of three major players, who are incentivised to further centralise things. ( I'm counting the three operating systems as Google Play Services, IOS and Windows. Yes, AOSP exists, but it's useless without Google Play Services. ). I also don't think a device level switch would stop anything for a second, given the number of stories of parents who seem to hand their children their credit card, then complain about them racking up thousands of dollars on Roblox or whatever. When the light-touch measures fail, the framework will be leveraged to start requiring more centralised and less private solutions. | | |
| ▲ | xp84 2 days ago | parent [-] | | > given the number of stories of parents who seem to hand their children their credit card, then complain about them racking up thousands of dollars on Roblox or whatever Sure, but you hear about those because of how shocking they are to all sensible people. Actually I bet a lot more kids rack up those charges using cards they stole from mom's purse. Same kids will start trying to sneak mom's old iPhone out of the desk drawer to install "Adult TikTok" on. But again, this is not more concerning than the way my generation rooted around on the top shelf of Dad's closet to find the old Penthouse magazines. I just don't accept the absolutist idea that if anything can be gotten around by any means, that means it can't still be sensible policy. Which seems to be the attitude taken by two separate groups - 1. Your and my common enemy -- the ones who are eager to enact "Show ID to access this site (trust us!)" verification schemes 2. And the freedom-loving hackers I've been arguing with today, who also detest those schemes but also don't want to see any scheme of any kind. | | |
| ▲ | eterm 2 days ago | parent [-] | | > I just don't accept the absolutist idea that if anything can be gotten around by any means, that means it can't still be sensible policy Now on that I agree strongly, there is a crowd on here that believe that technical weaknesses defeat political strengths, and focus all their effort into proving a technical workaround only for the political juggernauts to continue crushing their freedoms. These are arguments which often flow, "This law is impossible to enforce in totality, therefore the law will fail", which fails to understand what law really is, and how much people abide to even bad laws. I think we disagree on what's actually needed to defeat the increasing centralisation of the internet, I think it really needs a movement to wake people up, it needs skilled political operators, and it needs passionate orators, to spread the message that we're increasingly operating in a controlled space which every year has greater hurdles to communicate outside of the bounds which those who control it allow, rather than the open internet we used to enjoy and need to fight to defend. And, most importantly, that that fight needs to be political and not technical. Being seduced by the appeal of technical solutions is unhelpful distraction. Cryptocurrency will not keep you free. Duress pins will not keep you free. It is political will that will do that. | | |
| ▲ | xp84 19 hours ago | parent [-] | | Hear, hear. I could even argue that the dearth of "skilled political operators" and "passionate orators" - at least excluding the ones that seem to be under exclusive contract to the Devil himself - is maybe the worst part of our current era. And it's widespread, and on multiple continents. We haven't seen the likes of Teddy Roosevelt, William Jennings Bryan, or FDR, or even JFK or LBJ, in a whole generation. Even a comparison to Richard Nixon, by any measure, makes every presidential candidate and congressional leader in the past 20 years look like buffoons and fools. Terms like "Debate" have become redefined as "Insulting and ranting past your opponents to get cheers out of your fans." No wonder we can't pass any policy that makes any sense with these jackasses in charge. And in case anyone wonders, on my list of skilled politicians above, I'm only old enough to have witnessed Nixon, so this is not a "back in my day" rant. It's a "it hasn't been ok since way before my day." |
|
|
|
|
| |
| ▲ | boredatoms 2 days ago | parent | prev | next [-] | | Slippery slope actually works though. Makes no sense to treat it like some unwelcome argument | | |
| ▲ | thephyber 2 days ago | parent [-] | | Slippery Slope is the assertion that A therefore B therefore C therefore D. It is frequently a fallacy because D isn't predetermined by A when humans are involved. If you believe in free will, each of B, C, D are independent decisions. Sometimes we stop at A. Sometimes we pass Prohibition as a Constitutional Amendment, and later roll it back. | | |
| |
| ▲ | Akronymus 2 days ago | parent | prev | next [-] | | It's a fallacy when there is no cause and effect for each step. This, however states the steps. | | |
| ▲ | xp84 2 days ago | parent [-] | | What? The GP comment is one single line which states that it just "will" happen. |
| |
| ▲ | manphone 2 days ago | parent | prev | next [-] | | Only if it was not something they constantly already do. | |
| ▲ | hex4def6 2 days ago | parent | prev | next [-] | | In a philosophy classroom, it’s a fallacy. In a courtroom, it’s called precedent. | |
| ▲ | rolph 2 days ago | parent | prev | next [-] | | it is the thin edge of a slippery wedge.. | |
| ▲ | huvarda 2 days ago | parent | prev | next [-] | | slippery slope is if you say 'if a therefore d' not 'a leads to b leads to c leads to d' | |
| ▲ | unethical_ban 2 days ago | parent | prev | next [-] | | "Slippery slope" is a term like "conspiracy theory". Tarnished by overuse, often misapplied, but they absolutely exist. | |
| ▲ | rowanG077 2 days ago | parent | prev [-] | | I would rather call it the boiling frog. But hey, whatever floats your boat. |
|