cross-posted from: https://lemmy.wtf/post/49143200
cross-posted from: https://lemmy.zip/post/71629767
This is unacceptable. And I’m sick of all the fucking workarounds to maintain basic privacy.
cross-posted from: https://lemmy.wtf/post/49143200
cross-posted from: https://lemmy.zip/post/71629767
This is unacceptable. And I’m sick of all the fucking workarounds to maintain basic privacy.
My problema isn’t the age verification, but the privacy. But how to solve it the age without leaking data to third party servers?
The problem is that the services are asking for age verification, but to do that, you need to supply them personal information, and the way the information is handled is opaque. You’re handing highly sensitive information to a private company that, more often than not, cannot be trusted to handle that information responsibly for the singular purpose they’re tasked with.
One solution would be an official government service which supplies this information and nothing else. We have “strong identification service” in Finland, they supply your identifying information to government services and businesses that need to have the actual information on record, while you see which information gets shared. There’s no technical reason this service couldn’t just supply “Is this person 18+? Yes/No” and absolutely nothing else, even anything tying this person to any identifier.
Actually, if age verification would become a legal requirement, I’d expect the technical side to be exactly that. I frankly can’t believe the UK half-assed this stuff and went “whatever, let private providers use whatever voodoo they can come up with to make age verification happen”.
Do you not have corruption in Finland?
Belgium’s user verification app was built by a consortium of local banks and ISPs, most of which have politicians or ex-politicians on their boards.
Really easily. There are multiple possible options, not all equally easy, but the best option for privacy is also the easiest.
You don’t do true age verification. You mandate that operating systems and browsers work out a parental controls API and require apps and websites support that API. Then you ask (if you really want, you could demand, but I’d prefer to ask or suggest) parents to ensure their kids’ devices are configured correctly. When a user tries to access an age-restricted site, it calls an API in their browser, which calls an API in the OS, which returns a simple true/false value based on whether or not the current profile is configured to be old enough to access it.
Adults don’t have to do anything to prove they are adults. Merely the fact that they were able to buy a device that they control and didn’t get configured as a child is the proof.
More complicated solutions if you really insist on having true age verification could involve blinded signatures. I can explain in more detail if people are interested, but the slightly simplified TL;DR is that you have a system where the user goes to a trusted age verifier (my preference is for governments to do this themselves rather than farm it out to private companies, but either works). They do the age verification using ID, face recognition, whatever, and send the user a special token that they can use to prove they were age verified but which the site can’t use to determine any personal details about the user. Meanwhile the age verifier doesn’t know what site the age verification was just done for.
That would just move the burden of age verification onto retailers.
Not necessarily. It puts it where it belongs: on parents. Parents who buy computers and phones for their kids have the responsibility of supervising their use. My own preference is that this would be something that parents are encouraged to use through public education campaigns.
But yes, depending of the level of strictness, it could also be enforced at point of sale. A fairly standard practice. We’re already used to it with alcohol, cigarettes, knives. Heck, it’s already done when buying a SIM for your phone. It has the advantage of preserving the most important part of privacy—the link between the person and their activity. The phone store knows you bought a phone and that you’re an adult, but they have no idea what sites or apps you’re using.
The answer is actually fairly simple and easier to implement than ID collection.
My family for example, is all on apple products. So my kids are all under my family as kids in iCloud. With that information any web browser has more than enough information to just send a header saying “No porn or non-age suitable things to this device, please” as a header
It mostly respects privacy while putting the onus of not serving non age appropriate things to the service provider that can serve the non age appropriate thing.
Instead we are going for collecting IDs because some idiots want to strip anonymity and even bigger idiots don’t know how to setup devices for their children
I don’t want that either. I’d like to be the one determining what’s age-suitable. If I haven’t denied access for my 14 year old to access worldofwarcraft.com, then some legislator shouldn’t be able to say “adults use chat so block them in case someone says the word shit”.
I’m not even sure if this is a problem with “idiots” not knowing how to set up devices for their children as much as it is the same old moral panic. “I don’t like how some people are parenting their children! Certain words are bad and should be blocked! LGBT content is adults only! Kids shouldn’t be aware of what’s going on in Gaza!”
Thats great, the design of that still gives you the parent the ability to decide that. You just have to take responsibility.
Search for “EU digital wallet”