Remix.run Logo
terribleperson 2 days ago

But it's possible to lose a battle you were never going to win in the first place, and end up in a worse place.

I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. Most websites will use it, and it'll become global because it's easier to just demand an ID and a photo for every user through some third party provider than to offer looser restrictions for the handful of states that have different demands.

This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas. Sure, you could scrupulously try to identify which state someone is in and use the appropriate level of verification, but then you might be liable if it turns out it was someone from Texas or Georgia or Britain using a VPN.

JoshTriplett 2 days ago | parent | next [-]

> I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification.

You are assuming that age verification must necessarily happen. It needs to be destroyed at every possible juncture.

tzs 2 days ago | parent [-]

What is your objection to the California law?

A summary for those not familiar with it:

• Operating systems on devices whose primary user is a child must provide a way for the parent to provide age bracket information about the child.

• They must also provide an API that apps and app stores can use to find out that age range if they need to have limits on what children can do with them.

• They amended it to not apply to most open source operating systems.

Note that there is no actual age verification. It just uses what the parents put in. It is really just requiring each OS to have a standardized parental control system.

JoshTriplett 2 days ago | parent | next [-]

Among many other things, privacy. If you know an age range that's more information about the user than you should have, and you can use it for marketing. And if you can ask for an age range, then in practice you know a birthday; just keep asking until the range changes and record when you saw it change.

It's also the wrong way around: apps shouldn't ask for an age range, apps should provide one and the OS should do the checking.

I also object to it because it's a foot in the door for demanding that websites and apps care about that age range.

And most importantly, devices already provide parental controls in practice, and this law doesn't make those any better, it just unnecessarily cements one aspect of them into law. You can, already, on many devices, say "don't allow installing apps without permission", or "don't allow installing apps except those with this rating".

ivl 2 days ago | parent | prev [-]

A headless server operating system does not need those steps. It does not need the bloat of prepping an API to communicate with websites.

ivl 2 days ago | parent | prev [-]

> This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas.

Hey, give credit where credit's due.

The first to try that was NJ going after 3d printed gun developers.

terribleperson 2 days ago | parent [-]

Yeah, I'm not super happy about all the 3d printing control legislation going around, which I frankly think is a lot more overreaching than these age declaration laws.