• Em Adespoton ( adespoton@lemmy.ca ) 
    link
    fedilink
    arrow-up
    65
    ·
    2 months ago

    The whole thing is wrongheaded in the first place; any child wanting to access adult-only content will use an adult’s account to do so; any adult attempting to access adult-only content is likewise going to use an adult’s account.

    So unless they’re tying this to biometrics that are actually secure against an adverserial child, all the system really does is creates a registry of adults. And we already have those.

    • Jul ( irotsoma@piefed.blahaj.zone ) 
      link
      fedilink
      English
      arrow-up
      45
      ·
      2 months ago

      Creating a registry of adults and what content they access is exactly the point of these laws. Always has been. “Protecting children” is just the easiest excuse to make it seem more urgent to violate people’s rights. Just like removing trans healthcare started with children and is now targeting adults.

        • Jul ( irotsoma@piefed.blahaj.zone ) 
          link
          fedilink
          English
          arrow-up
          15
          ·
          2 months ago

          But in most cases, it is, because most adults are not that technically inclined to get around the logins. Sure there are some tech savvy ones who will bypass it. And maybe a few kids who will use their parents’ accounts rather than just bypassing the logins but it’s still the family accessing the information, but for the majority, it does work as a registry. And though it’s only on a few categories of sites now, the categories inevitably will expand. It’s not just porn, but info on reproductive and gender healthcare, LGBTQ+ dating, and many other subjects that “children must me protected from”, but really they want to know who’s gay, looking for abortions or transgender healthcare or information about whatever other rights their government is trying to force them to give up.

            • Jul ( irotsoma@piefed.blahaj.zone ) 
              link
              fedilink
              English
              arrow-up
              2
              ·
              2 months ago

              It already is. In China if you access information on the Tiananmen Square massacre it has gotten you flagged for ages. In the US, if you access pro-Palastine information or abortion information, these things are then used to prove you are antisemitic or trying to get an abortion where it’s illegal, etc. The easier it is to link that access to an individual through a registry, the more commonly it will be used.

        • t3rmit3 ( t3rmit3@beehaw.org ) 
          link
          fedilink
          arrow-up
          4
          ·
          2 months ago

          Which they, as the governments, can choose to legally treat as the same thing. “You are guilty of whatever someone does with your account” is not a new concept, it’s just one that most places have chosen to reject. It can always be overridden, such as for the Palestine Exception.

  • eleitl ( eleitl@lemmy.zip ) 
    link
    fedilink
    arrow-up
    15
    ·
    2 months ago

    Gee. I totally not saw that coming.

    These people who push for it are fascists, and the only way to deal with fascists is to kill them before they murder you.

  • I have a solution to the age verification problem. There is a way to affirmatively prove someone is a real human adult without invasions of privacy. We can use the same ID verification system we’ve been using for centuries: public notaries.

    Governments could hand anonymous cryptographic tokens to notaries. These contain no information on the individual. They’re simply a unique cryptographic token. You can go to a notary, pay a nominal fee, show your ID, and grab one of the tokens (possibly just a code printed on a card) from a large bin of them. You can then use this token to register for any number of sites. The notary themselves does not need to note which cryptographic token you grab. The notary doesn’t even know what token you received. The goal is merely to prove you’re an adult human, not to create a cryptographic key tied to your specific identity.

    I would then let people do this as many times as they want. You can get a hundred such IDs. They wouldn’t cost much, a few dollar or Euros. This would be no barrier to individuals accessing the net, but it would make them unsuitable for mass spamming.

      • There is a clear need for it. There’s value in having online discussion spaces that aren’t just swamped with bots. We really need a reliable way of telling human from bot. I want to find a way to do that preserves privacy to the greatest degree possible.

        Do you have any constructive criticism to offer? Maybe a suggested improvement, or an alternative way to accomplish the same goal? What’s your solution to separate human from bot?

        • There is no need for it. Sorry. Certainly not government mandated, which is the worst part.

          Frankly if you treat the internet like we did all the way back in bbs days, it doesn’t matter that much: Everyone is a liar. So I don’t care what anyone says. Bot or not.

          In the forums I run we haven’t seen much of a bot presence at all, so these spaces already exist. How do I know? We have all met each other at one point or another. So I may know a, a knows b, and so on.

          Do I want the burden of starting authentication on top of this? No.

          I don’t want the internet to require me to get authentication. I really don’t care about the bot issue. Go outside and meet people in real life if that’s what you want.

          • There is no need for it. Sorry. Certainly not government mandated, which is the worst part.

            YOU have no need of it. You’re projecting your experiences onto everyone else. Maybe you’re content only hanging out in limited forums where you have to know someone to join. And those forums can continue to operate without any human verification. If you don’t care whether the spaces you occupy are infested with bots, or can manage with white lists, fine. But most people don’t want to talk to bots. Not everyone has the social connections you do.

            I don’t support mandating ID for anything. But you are not the only person in the world. Just because you have no need of it, doesn’t mean no one does. Not everyone uses the internet the same way you do.

            “Only join forums where you personally know the people there” is not a scalable solution to this problem.

            Respect a diversity of viewpoints and experiences. Your way is not the only way.

            • You’re projecting your experiences onto everyone else.

              In fairness, you are doing this right now.

              I don’t support mandating ID for anything. But you are not the only person in the world. Just because you have no need of it, doesn’t mean no one does. Not everyone uses the internet the same way you do.

              You are free to create websites that function this way, or participate in websites that function this way, but don’t push it on the rest of the internet.

              “Only join forums where you personally know the people there” is not a scalable solution to this problem.

              Sure it is. We didnt all know each other personally when we started, and people are welcome to join anytime. We just can figure out pretty quickly who is real and who is not because we meet each other. So what problem?

              Not everyone uses the internet the same way you do.

              Of course not, because they are either idiots, or never learned the basics. This is internet 101.

              1. Everyone is a liar.
              2. Everyone is anonymous
              3. Because of rule 2, see rule one.

              You are commenting in a privacy forum. I quite likely am talking to a bot, or you are talking to a bot right? So don’t listen to me, BUT: no matter how hard you try, making any system that requires any kind of verification on an internet wide scale WILL be abused.

              Use the internet as intended and the problem goes away.

              Edit: also, even if you filter the bots, the issues remain because in many ways people are just as bad. Misleading, argumentative, liars, agendas, half truths, etc. So it doesnt really matter.

    • Cricket@lemmy.zip ( Cricket@lemmy.zip ) 
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      Maybe I missed something, but with your proposed solution, what would stop someone from just handing the adult cryptographic token to a kid? It sounds like it would be a similar situation to or even easier to do than fake ID cards or adults buying alcohol for underage people.

    • It’s all silly because computers are not paired with any specific body. You could toss your “18+ accessible phone” to your kid, etc.

      Unless they do implants, which is nightmare land because we know they’ll want more than just your birthday.

    • Zerush ( Zerush@lemmy.ml ) 
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      2 months ago

      I didn’t like the age verification law either, but as it would be introduced everywhere, yes or yes, at least it’s mandatory to search an privacy protecting methode, which isn’y not so easy, Because of this I asked Sketchapedia, which shows an zero knowledge system, the service provider only receive an OK or Not OK with it.

      In problems which I can’t avoid, I always prefer to search solutions or at least workarrounds to fix it.

  • Matt ( DieserTypMatthias@lemmy.ml ) 
    link
    fedilink
    arrow-up
    10
    ·
    2 months ago

    The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave.

    The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers.

    So there’s a chance that GrapheneOS will be supported. I mean, we can still decompile the app, modify it and then repackage it. Or someone will make a patcher app.

  • Please explain… If I’m below the age of… Whatever they decide, what will or will not be accessible to me? Like, if I’m below a certain age, will some EU appointed DNS restrict what domains I can reach? Or, since this article is about hardware-bound attestation, are my devices going to prevent me from installing and using certain apps if I’m below the age? I don’t understand where the restrictions are going to lie…

    Bonus: can’t I just buy, say, five phones right now, root them or install custom OSs before shit hits the fan and be happy?

      • utopiah ( utopiah@lemmy.ml ) 
        link
        fedilink
        arrow-up
        9
        ·
        2 months ago

        No because you can go to jail for that, like the dude with his GrapheneOS in the US. They’re probably working on that next.

        no… you can not go to jail, in the EU or the US at least, for having a phone with a custom OS. They are facing charge for using a duress code which wiped their phone. It is very different.

        • t3rmit3 ( t3rmit3@beehaw.org ) 
          link
          fedilink
          arrow-up
          7
          ·
          2 months ago

          He had a duress password, and told it to a border agent (who had no warrant, but that is no longer legally required for border checks), which then wiped his phone.

          He was targeted for being part of the Stop Cop City protest movement (and they were likely looking for contacts), and now the feds are claiming that because he could have had anything, he should be allowed to be charged with possession of whatever they can think of (I.e. they already tried to claim in a press conference that he may have had CSAM, because they couldn’t search it to prove he didn’t).

    • LeapSecond ( LeapSecond@lemmy.zip ) 
      link
      fedilink
      arrow-up
      15
      ·
      2 months ago

      The services themselves will probably be made to ask for verification and your devices will answer through the age verification app. Since custom mobile OSs (or desktop Linux) won’t provide hardware attestation, the app won’t work on them and the websites will treat you as underage. The types of services that require age verification aren’t specific, they can change based on EU decisions so eventually people not using “approved” OSs may be locked out of most of the internet.

  • These kinds of laws will not succeed. People will choose to ignore them, like they ignore other laws, like they litter, jaywalk, drive 10 over the limit, run stop signs, etc. It will succeed in driving up prices on products from those companies who choose to comply, because they will be forced to hire in a lot more lawyers and compliance staff. These laws create lots of full time jobs in tech companies that few realize even exist. They have meetings every week, attend conferences, constantly send letters back and forth to each other. Then people wonder why their Gamepass fees went up $10 (its not actually the games)

  • drac ( drac@lemmy.zip ) 
    link
    fedilink
    arrow-up
    2
    ·
    2 months ago

    I think there is a flaw in EU’s way of acting and functioning. European countries seem to be sharing the same cultural values yet there are different deeper values hidden to the foreigner from country to country. For example we look at Middle East, Africa, Asia and we easily spot cultural differences. Yet we fail to see the gaps between our countries inside EU. Holland and northern countries had for years a culture of child protection on computing devices,and not only,that 20 years ago I found strange. There is an industry for that in there and thriving. What they just did was to apply their normality to us, without them understanding the gap. They just don’t understand the issue. Controlling children like that is normal for them.