Age verification means identity verification.
-
@michael @jwcph @jwildeboer its a little more complex
yeah, especially if you ignore all the rest. There are reasonas why we are fighthing stuff like #chatcontrol continously. I also lost count of what Crypto Wars we are at now
So falling in a trap about tech, and looking at this as an academic problem to solve, is the first problem making your responses, well naive. Look at Denmark and our politicians
Even if a perfect valid solution is proposed it will be subverted and twisted sooner or ltr
@kramse @michael @jwildeboer Also, *none of all that works if it can't be unequivocally tied to a specific person's identity*, which never can or will be secure or safe from abuse.
How is this so hard to understand for some people?
-
ADDENDUM: I said „final remnants“ because the ad/tracking mafia already has powerful capabilities to identify individuals with high probability of correctness. Avoiding their fingerprinting and correlation capabilities is almost impossible.
@jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.
-
@jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.
-
@jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.
@zazzoo @jwildeboer This
-
@jwildeboer Personally, I don't even care about internet anonymity in itself as much as I do the stories coming out of the US where ICE agents are visiting people to intimidate them over their political views. In my opinion, removing our ability to communicate anonymously is a death sentence for a functioning democracy.
I agree. We must protect the ability to be anonymous on the Internet
-
@kramse @michael @jwildeboer Also, *none of all that works if it can't be unequivocally tied to a specific person's identity*, which never can or will be secure or safe from abuse.
How is this so hard to understand for some people?
Then explain what won't work unless it's tied to a person's identity. Be specific. -
@michael @jwcph @jwildeboer its a little more complex
yeah, especially if you ignore all the rest. There are reasonas why we are fighthing stuff like #chatcontrol continously. I also lost count of what Crypto Wars we are at now
So falling in a trap about tech, and looking at this as an academic problem to solve, is the first problem making your responses, well naive. Look at Denmark and our politicians
Even if a perfect valid solution is proposed it will be subverted and twisted sooner or ltr
It is a problem that kids are getting groomed on Discord and in Roblox. It is a problem that kids brains are getting fucked up by SoMe.
Age verification is one way to solve that. It may not be the only way to solve it, but a lot of people like to complain about chat control without being constructive about a solution to the issues.
I agree 100% that ID verification is not a good idea. If we can have age verification without ID verification, I'd be fine with age verification. If we can solve SoMe/Roblox/Discord without age verification, I'd also be fine with that.
If we get dug down in trenches that are either "ID verification everywhere" or "ignore SoMe/Roblox/Discord," we'll get stuck in a stand-off like the US gun control problem. We need to be honest about what we want, and call out people (like politicians) that claim to want one thing (fix SoMe/Roblox/Discord) but really want to sneak in another (ID verification).
We don't need a perfect solution that lasts forever. If it gets bypassed in 5 years, that's not an issue, we can just make something else. The issues are simple solvable UX and software development issues, not fundamental ones. -
It is a problem that kids are getting groomed on Discord and in Roblox. It is a problem that kids brains are getting fucked up by SoMe.
Age verification is one way to solve that. It may not be the only way to solve it, but a lot of people like to complain about chat control without being constructive about a solution to the issues.
I agree 100% that ID verification is not a good idea. If we can have age verification without ID verification, I'd be fine with age verification. If we can solve SoMe/Roblox/Discord without age verification, I'd also be fine with that.
If we get dug down in trenches that are either "ID verification everywhere" or "ignore SoMe/Roblox/Discord," we'll get stuck in a stand-off like the US gun control problem. We need to be honest about what we want, and call out people (like politicians) that claim to want one thing (fix SoMe/Roblox/Discord) but really want to sneak in another (ID verification).
We don't need a perfect solution that lasts forever. If it gets bypassed in 5 years, that's not an issue, we can just make something else. The issues are simple solvable UX and software development issues, not fundamental ones.@michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.
What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.
Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.
-
@michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.
What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.
Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.
@michael @kramse @jwildeboer I wish you could see whose work you're doing here.
-
@michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.
What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.
Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.
In the gun analogy, you're on the side of no gun control at all. -
Then explain what won't work unless it's tied to a person's identity. Be specific.
it was not me saying it was easy, we dont owe you anything #sealion
-
@michael @kramse @jwildeboer No, it isn't a way to solve that, because it won't work & will create many more problems every bit as bad.
What will solve it is holding the platforms responsible & people like you insisting the users jump through hoops in a security theater instead is distracting from that.
Funny you should compare to US firearm problems because that, too, is about dancing ineffectually around the problem when a working solution is right there but corporations are against it.
@jwcph @michael @jwildeboer 100 percent agree with @jwcph here
-
There's absolutely ways to do it without id. At the simplest, issue everybody that's 18+ a certificate + key. The certificate can be issued without any identifying information. Have the site send a challenge to the user and have them sign that with their key and return the signed challenge + certificate. You've just proved they are 18+ without divulging any information and there is no risk for leaks at the site.
It's a little more complex than that because it is very easy to use somebody else's key/certificate and the certificate itself can be used as a pseudonymous identifier if used directly against the site.
This can be made decentralized (site decides which certificate issuers they trust) and can be made entirely offline.
Just because sites now require uploading a picture of your passport or most government age verification mandates require something similar, doesn't mean it isn't possible to make it secure.@michael Age verification is, in my opinion, labouring on the symptoms, while leaving the cause (platforms that due to lack of liability have put revenue over protecting minors) with consequences that go far beyond the "protect the children" mantra. It is like using a cannon to kill fly sitting on the church wall and with that taking the whole church down. @jwcph
-
In the gun analogy, you're on the side of no gun control at all.
if the solution ignores effectivity, and bad repercussions - like throwing anonymity away because of the children. It is NOT an acceptable solution.
Dont focus only on expected good, but how can it be abused. Do you want to trust all future politicians with THIS power, and what happens WHEN data is stolen, be practical
-
It is a problem that kids are getting groomed on Discord and in Roblox. It is a problem that kids brains are getting fucked up by SoMe.
Age verification is one way to solve that. It may not be the only way to solve it, but a lot of people like to complain about chat control without being constructive about a solution to the issues.
I agree 100% that ID verification is not a good idea. If we can have age verification without ID verification, I'd be fine with age verification. If we can solve SoMe/Roblox/Discord without age verification, I'd also be fine with that.
If we get dug down in trenches that are either "ID verification everywhere" or "ignore SoMe/Roblox/Discord," we'll get stuck in a stand-off like the US gun control problem. We need to be honest about what we want, and call out people (like politicians) that claim to want one thing (fix SoMe/Roblox/Discord) but really want to sneak in another (ID verification).
We don't need a perfect solution that lasts forever. If it gets bypassed in 5 years, that's not an issue, we can just make something else. The issues are simple solvable UX and software development issues, not fundamental ones.My suggestion for how to address this is as follows:
- Don’t let children have completely unrestricted internet access.
- Whenever an adult provides internet connection to a child that adult is responsible for which parts of the internet they are granting the child access to.
- We need tools that can help adults take care of this task. Some tools exist already, they may need improvement. I have more trust in the industry providing such tools than I have in any government implementing an identification system without major security/privacy flaws.
What’s important about this overall approach is that it doesn’t require breaking the internet to implement. Adults can keep communicating on the internet like they already do. And I think that’s an important property of a solution intended to restrict children’s access.
I also have an idea for a simple technical solution that can allow some cooperation between websites and the adults who let children access the internet. My idea is as follows:
When communication is between adults, nothing changes compared to how the internet has been working until now. When a child is communicating a destination option is included in the packets with a single byte of payload containing information about the age of the user. This bytes contains two pieces of information birth year modulus 19 and birth month being a number from the range 0-12 with 0 meaning unspecified.
Assuming the child has their own dedicated device then an adult configuring the CPE can let the CPE know the birth month of each user such that the CPE can verify the presence and correctness of the destination option. It can also be configured to know about some trusted sites which children can be allowed to access without the extra destination option. This for example can be used to ensure that the mechanism doesn’t interfere with installing software security updates.
Each individual device used by children needs to be configured to send this option with a valid value. Without this configuration the CPE would reject all communication. A device administered by an adult can be set up with multiple users some of which are children. Then it needs to be configured to know which users are children and which birth month to send for those users. In that scenario no filtering is needed on the CPE as the individual device handles the filtering.
-
if the solution ignores effectivity, and bad repercussions - like throwing anonymity away because of the children. It is NOT an acceptable solution.
Dont focus only on expected good, but how can it be abused. Do you want to trust all future politicians with THIS power, and what happens WHEN data is stolen, be practical
@kramse @michael @jwildeboer - which means even if it worked, which it won't, and if it wasn't horribly invasive, which it is, and if it was secure, which it isn't, the potential for abuse is still so great as to make the "solution" unacceptable.
-
My suggestion for how to address this is as follows:
- Don’t let children have completely unrestricted internet access.
- Whenever an adult provides internet connection to a child that adult is responsible for which parts of the internet they are granting the child access to.
- We need tools that can help adults take care of this task. Some tools exist already, they may need improvement. I have more trust in the industry providing such tools than I have in any government implementing an identification system without major security/privacy flaws.
What’s important about this overall approach is that it doesn’t require breaking the internet to implement. Adults can keep communicating on the internet like they already do. And I think that’s an important property of a solution intended to restrict children’s access.
I also have an idea for a simple technical solution that can allow some cooperation between websites and the adults who let children access the internet. My idea is as follows:
When communication is between adults, nothing changes compared to how the internet has been working until now. When a child is communicating a destination option is included in the packets with a single byte of payload containing information about the age of the user. This bytes contains two pieces of information birth year modulus 19 and birth month being a number from the range 0-12 with 0 meaning unspecified.
Assuming the child has their own dedicated device then an adult configuring the CPE can let the CPE know the birth month of each user such that the CPE can verify the presence and correctness of the destination option. It can also be configured to know about some trusted sites which children can be allowed to access without the extra destination option. This for example can be used to ensure that the mechanism doesn’t interfere with installing software security updates.
Each individual device used by children needs to be configured to send this option with a valid value. Without this configuration the CPE would reject all communication. A device administered by an adult can be set up with multiple users some of which are children. Then it needs to be configured to know which users are children and which birth month to send for those users. In that scenario no filtering is needed on the CPE as the individual device handles the filtering.
@kasperd @kramse @jwildeboer @michael That's a lot of words just to say "I don't think we should hold the platforms making billions on endangering & harming our children responsible"...
-
In the gun analogy, you're on the side of no gun control at all.
@michael @kramse @jwildeboer No - I'm in favor of removing the source of the problem, rather than making the effects of it the victims' responsibility.
Get rid of guns, get rid of harmful platforms.
(note I didn't say "get rid of harmful content", which would also be impossible - the problem here is platforms profiting wildly on serving harmful content in harmful ways & we have both the platforms' own words & the word of the courts on this)
-
@michael Age verification is, in my opinion, labouring on the symptoms, while leaving the cause (platforms that due to lack of liability have put revenue over protecting minors) with consequences that go far beyond the "protect the children" mantra. It is like using a cannon to kill fly sitting on the church wall and with that taking the whole church down. @jwcph
I don't think age verification is that intrusive. I think ID verification is. ChatControl and similar legislation is a nightmare because it doesn't make a clear distinction.
I am very much against current versions, but am not so sure I would be against a version that stated clearly "age verification only, it is illegal to use a solution that allows tracing back to an individual." Would you? If the requirement were enshrined in the law, implementations would have to go beyond "password uploaded to ZenDesk" and the government cannot salami-slice their way into deanonymizing the entire internet.
Only some platforms (SoMe) are bad because of profit. Roblox and Discord have other problems more related to lack of oversight of kids. Others I don't have a fully formed opinion about (a 16-years old should probably have access to the 'Hub, a 6-years old probably not).
It would be good if SoMe were less shit, but I don't see a clear path to ensuring that. Preventing kids from having access to things their brains cannot deal with is an imperfect solution that works somewhat in the physical world (restricting access to alcohol, tobacco, and other drugs, e.g.). "Just forbid Facebook" or "never any age control" is not going to be convincing on their own IMO. -
ADDENDUM: I said „final remnants“ because the ad/tracking mafia already has powerful capabilities to identify individuals with high probability of correctness. Avoiding their fingerprinting and correlation capabilities is almost impossible.
@jwildeboer good point. There already is no thing like "anomity" for the tracking industry or for secret services / states.
It's just a feeling for the people and users.Current political discussions are leading in the wrong direction. You want to avoid an abuse that already is implemented in every day life.