| ▲ | terribleperson 2 days ago |
| I don't think this is a safe assumption. As a counter, actual age verification is being rolled out in other places. I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. Between the anti-porn types and public demand for some kind of regulations on social media, regulation of some kind is inevitable. Our actual choice may only be what type of restriction we can live with, and I much prefer this type to the kind that requires websites to demand my id and photos of my face. Especially since some implementations of this concept (the California one, I think) declare that websites aren't legally required to look deeper than the attested age, which is a very nice feature. Mind you, I don't know why the legislators are bothering mandating OS support for these features. It would be much easier to mandate that websites support the feature, make it clear to them that supporting the feature appropriately will free them from liability for children accessing content, and then wait as users demand that their OS support the feature. |
|
| ▲ | xp84 2 days ago | parent | next [-] |
| Re: your last paragraph I actually agree with you, if you mandate that the site has to look for an affirmative signal and if it doesn't get one, has to assume the user is the youngest possible age group. Users would demand the proper support for it. Although it would have to have some teeth capable of biting the client software companies, because for instance, if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls). Honestly though - because kids (especially the younger set) are hard pressed to buy their own hardware, a property that can only be set up out of the box, and can only be undone by using the account password of the parent who set it up, it is the perfect level of security here. And as for browsers, all you need is the gatekeepers (Apple, Google, MS) to agree not to ship in their "stores" browsers designed to evade it. Yes, you can totally compile your own browser, but most kids are using locked platforms like iOS and Android, and are by default denied permissions to run arbitrary software on platforms like Mac and Windows, so that's fine. |
| |
| ▲ | terribleperson 2 days ago | parent | next [-] | | Yeah, that's pretty much what I am imagining. You're right about needing some teeth - maybe the legislature could define a spec, and penalties for implementing the feature in a commercial product without actually following the spec. I really think all we need is what you describe in your third paragraph. It doesn't need to be bulletproof, it just needs to be an easy way for parents to set the level of content their children can access without them having to hover over their children at all times. Something like that could easily be set up in the Genius store when someone gets a new iPhone, or set up at first boot on an Android phone. That's like 90% of the devices anyone is actually worried about. Windows support of the feature would take it to like 99.9%. | | |
| ▲ | xp84 2 days ago | parent [-] | | Exactly. Fortunately, the kids we're most concerned with - young ones who just want to access their brainrot - has very little overlap with Linux users anyway. So, while I hate this hysterical propaganda portrayal as "aGe vErIfIcAtIoN," an "OSS operating system" exception doesn't really bother me, as long as it doesn't let the usual suspects make an end-run ("Darwin is OSS! See! iOS is exempt") |
| |
| ▲ | pessimizer 2 days ago | parent | prev [-] | | > if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls). If it's a header, you can strip it out at the browser level, the user level, the kernel level, the hardware level, the router level, the router OS level, the router hardware level, or at the ISP level, depending on what a parent (or a state) desired. The teeth are only necessary for the websites, which are never going to conform to the law anyway, whether through a header or through device attestation, without draconian Chinese-level enforcement that has never been seen in the West before. This new contract will have to be enforced at both endpoints. You will need the ID (whatever you want to call it) to get onto the network, whether you're an individual or the site being visited. The idea that device attestation is going to bother the Moldovan tube site your kid gets pirated porn through is a surprisingly ignorant fantasy, especially when it comes from technical people. The Pirate Bay is still up. Megaupload is up and runs better than ever. People have 20 year old torrent site accounts. OS-level age attestation must be a first step, because it won't work. And as to it not being enforced either by the hardware or by identity verification of the user, that's an impossibility. A kid can also overwrite an operating system, or even just overwrite the important part; so that means that either only attested operating systems can be installed, or no user is trusted at any time without state verification. | | |
| ▲ | xp84 2 days ago | parent [-] | | This sounds like a hot take, but I'm way less concerned with sketchy porn sites (mostly for the kind of reasons you say which boil down to ... they're sketchy). I'm more concerned with deliberate manipulation of young people by social media. TikTok and its clones especially have demonstrated an incredibly strong ability to not just addict and brainrot kids (which is bad enough -- and it's really, really bad), but also to shape their opinion. All that discussion about the CPC having complete control if they wanted to exert it wasn't BS. Whoever controls them absolutely can use an algorithmic feed to astroturf "viral" videos pushing any narrative they want. Think of Elon Musk in his role as owner of X if you like the CPC. Anyway. Most tweens and young teens don't know how to use Bittorrent. They use iOS and Android all day, and Chromebooks. These function as closed platforms, and macOS is as well unless you go out of your way. And Windows unless you make your kid an Administrator. Linux and other noncommercial OSS operating systems can have an exception if it makes it less burdensome on the maintainers. This doesn't change the fact that a law like this still solves a ton of problems that parents otherwise can't solve, and that big tech could only solve independently today by very privacy-invasive means. > because it won't work. It sounds like you think "work" means "prevent 100% of minors from seeing even a single frame of Bad Stuff anywhere online on any device" To me "work" means "prevent most children (who aren't extremely technical) from mainstream social media sites openly experimenting on them daily to build a paperclip maximizer, where the paperclips are 'watch minutes' (as a proxy for ad revenue) and the planet being dismantled is our society." It would "work" by this definition. > device attestation this specific term means something specific and is not what this law is about - not sure if you meant to tangle that idea up with this. |
|
|
|
| ▲ | JoshTriplett 2 days ago | parent | prev [-] |
| > I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. It is impossible to win a battle you stop fighting. |
| |
| ▲ | terribleperson 2 days ago | parent [-] | | But it's possible to lose a battle you were never going to win in the first place, and end up in a worse place. I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. Most websites will use it, and it'll become global because it's easier to just demand an ID and a photo for every user through some third party provider than to offer looser restrictions for the handful of states that have different demands. This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas. Sure, you could scrupulously try to identify which state someone is in and use the appropriate level of verification, but then you might be liable if it turns out it was someone from Texas or Georgia or Britain using a VPN. | | |
| ▲ | JoshTriplett 2 days ago | parent | next [-] | | > I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. You are assuming that age verification must necessarily happen. It needs to be destroyed at every possible juncture. | | |
| ▲ | tzs 2 days ago | parent [-] | | What is your objection to the California law? A summary for those not familiar with it: • Operating systems on devices whose primary user is a child must provide a way for the parent to provide age bracket information about the child. • They must also provide an API that apps and app stores can use to find out that age range if they need to have limits on what children can do with them. • They amended it to not apply to most open source operating systems. Note that there is no actual age verification. It just uses what the parents put in. It is really just requiring each OS to have a standardized parental control system. | | |
| ▲ | JoshTriplett 2 days ago | parent | next [-] | | Among many other things, privacy. If you know an age range that's more information about the user than you should have, and you can use it for marketing. And if you can ask for an age range, then in practice you know a birthday; just keep asking until the range changes and record when you saw it change. It's also the wrong way around: apps shouldn't ask for an age range, apps should provide one and the OS should do the checking. I also object to it because it's a foot in the door for demanding that websites and apps care about that age range. And most importantly, devices already provide parental controls in practice, and this law doesn't make those any better, it just unnecessarily cements one aspect of them into law. You can, already, on many devices, say "don't allow installing apps without permission", or "don't allow installing apps except those with this rating". | |
| ▲ | ivl 2 days ago | parent | prev [-] | | A headless server operating system does not need those steps. It does not need the bloat of prepping an API to communicate with websites. |
|
| |
| ▲ | ivl 2 days ago | parent | prev [-] | | > This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas. Hey, give credit where credit's due. The first to try that was NJ going after 3d printed gun developers. | | |
| ▲ | terribleperson 2 days ago | parent [-] | | Yeah, I'm not super happy about all the 3d printing control legislation going around, which I frankly think is a lot more overreaching than these age declaration laws. |
|
|
|