Hacker News new | past | comments | ask | show | jobs | submit
> By demonizing them and failing to engage with the worries over social media and pornography We have brought it on ourselves.

There is a really good way to do this that solves most concerns: https://blog.google/innovation-and-ai/technology/safety-secu...

The only real downside to this is that a 0kp cannot be reliably tied to an identity of the person using the device and thus tickets could be proxied/shared around with semi technical tools (and/or an ai agent tasked with creating a proxy). This really isn't solvable without device-level attestation[0], as if a website needs to reliably say "this person is actually this person" then it needs all pieces of data itself.

This could be solved by adding in a still privacy-preserving step like "The device is doing periodic face id scans and matching them to an identity, and constantly renews/re-presents to the age assurance consumer", but that has its own drawbacks[0].

0: Namely, lock in to devices that can do this, and that includes basically guaranteeing a double digit percentage of adult humans would not have access due to their device being old, unsupported, missing the hardware, etc. And with so many humans excluded, you would not have mass adoption. Probably also excludes rooted devices if we bring in attestation of unmodified software.

It’s weird to see that locking down devices even further is being proposed as a solution to anything.

The unspoken part of this requirement is that websites would have to block users who aren’t connecting via one of these attested, verified, locked down devices.

There is the obvious loophole that using a VPN to a country without these requirements would circumvent it. That’s how kids are already circumventing age restrictions in places like Australia and it’s why the UK has taken an interest in attacking VPNs.

Locked down devices are kind of the only solution that both (A) preserves privacy and (B) solves the problem. However, it indeed strips a user of the freedom to use their device in the way that they want; although, safe to say that the US doesn't have all that much problem with that, given Apple's continued market dominance.

The alternative is what we're getting right now: laws that require verifying ID documents, often in ways that restrict even the notion of maintaining the user's privacy. Attestation might be an "OK" to "good" solution while this is between bad and really bad.

Locked down devices will never preserve privacy since the government can just mandate spyware that you won't be able to remove.

There is no form of digital ID that isn't evil, but anything requiring attestation is super evil.

Client-side filtering solves the problem, because children's clients are owned by their parents. We should mandate that websites and apps send metadata about the content being served (eg extending the Rating: RTA header from 20 years ago) and mandate that OSs/browsers allow filtering to be easily configured at setup. This is a more private but also much more granular/useful solution, it's only difficult today because of a lack of coordination
Those in tech who study this already understand the need to hardware attestation. Everyone else will understand soon enough.

Old hardware will have to be grandfathered. Old cars don't track us and that has created a market for old cars.

Hardware age attestation will be a long timeframe project. The current work should be towards standards that can get us there.

Finally, anonymity didn't exist for my grandparents. It won't exist for my grandchildren.

> Finally, anonymity didn't exist for my grandparents.

Your grandparents could walk to the next town over and give themselves a different name and nobody would ever know who they were. They could get a job, be paid in cash, and deposit that money in a bank account with no KYC. They could drop a letter in a public mailbox without a return address, or put up posters at night, or make phone calls from public telephones. Nobody would know who did it, and there would be no surveillance footage to review after the fact, no digital footprint to trace. They could write a letter to their local newspaper to be printed with a fake name, or publish a book or story or magazine under an assumed identity. There were no ALPRs, no automated facial recognition, no built-in vehicle telematics, no drones, no smartphones to track anyone’s movement, no doorbell cameras on every block, no video tapes, no serial numbers hidden in the printouts from copy machines, no DNA analysis, no databases instantly searchable with the click of a button.

Feel free to make a value judgement about whether what we have now is better or worse than the past, if you want, but don’t invent history to rationalise it. The internet did not invent anonymity. It used to be the default.

loading story #49254879
loading story #49255773
> Hardware age attestation will be a long timeframe project. The current work should be towards standards that can get us there.

Unfortunately it's so much easier for lawmakers to slap down a law that says "you must verify IDs right now if you want to continue to exist" with no requirement, and often not even support for, privacy preserving ways to make this happen. The laws are happening now. The chance of reform to align with a privacy-preserving option once the laws are implemented is slim to none.

loading story #49256894
{"deleted":true,"id":49252808,"parent":49252711,"time":1786416747,"type":"comment"}