Background: Meta/Facebook, Google and Apple all support age verification. It gives them legal cover and for their ad platforms gives better data.
But Meta/FB have been strongly lobbying to make it required at the OS level, so they aren't responsible for it, whereas Google and Apple both want it to be an application responsibility.
I think the CA version of this ended up with a carve-out for open source? I can't recall the details.
You said that Meta doesn't want to be responsible for age verification - they absolutely do, because that gives them every single user's identity. Forcing it at the OS level is not an attempt to put the responsibility on the OS, it's an attempt to drive a wedge into the OS where Apple can't hide users' identities.
No, they are far more cunning than you give them credit, they want to have the information but bare no responsibility for both collecting and validating it themselves nor for when the kids circumvent it.
So they are in the golden zone of maximum exploitation and plausible deniability.
They will literally say:
Of course, we showed that one teen 500 gambling and porn ads a day, Apple/Google/Microsoft told us he is 65, it's their fault! Sure every other word he posted was rizz, but how could we possibly know he was not 65.
Online surveys are for age ranges of people who aren't minors. Minors aren't allowed to have their data targeted for advertising. If access to this signal can be used to show they were targeted deliberately, that can warrant setting fines near the limit.
eh, I'd say their lawyers want them to not be liable for the utter harms their apps have on children.
The other stuff they already get enough off. They dont need to know you're over 18. They don't want the liabilities of children killing themselves because an AI app told them something stupid.
What's most shocking to me is the willingness to comply on display here and elsewhere.
If the state proposes you stick a corncob up your rear, your initial response shouldn't be to ask if they prefer you use a rubber or wooden mallet to achieve compliance.
If the state proposed every OS must have parental controls activated via a checkbox would you say the same? Because that's what they actually did except the checkbox is a numeric text field.
From reading the article, it sounds like an enforced standardisation? Like, asking for account age bracket and then having a standard API to ask for it would be easy, right? Just write it to a root owned `~/.age-bracket` for each user or something (obviously something better).
It's a feature many apps implement in all kinds of ways already, especially games and social media stuff, so this, in theory, just makes it easier and consistent?
I'm against leaking our kids ages, and all the privacy and other concerns as much as anyone, but are we just getting overly angry too quickly on this one?
It passes responsibility and accountability from the large platforms to the open-source communities and to parents who are most likely tech illiterate.
Facebook, etc. can wash their hands when they "accidentally" serve gambling ads (or whatever) to children and say "well it's not our fault the parent has the laptop misconfigured"
I disagree. The parents are the ones who should be supervising. The work should not be pushed off to OSS devs or random website operators. Facebook is bad, but I'd rather deal with one Facebook than kill 1000 normal sites with bad legislation.
> The parents are the ones who should be supervising.
Ok. When Alice & Bob come home from school what steps should every parent take to supervise A&B's phone and device usage over the past 48 hours?
Internet history, of course - for all the browsers, including those hidden away? But what if the logs are wiped or the second BraveFoxChrome installation isn't obvious?
Must every parent have an IT degree?
What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?
You teach them the harm of smoking and online grooming. You teach them to not accept cigarettes or sexual advances from others. And you build a trusting relationship with them so in the unfortunate case they do mess up, they trust you enough that they tell you what's going on, instead of hiding abuse they suffered from others so their parents don't berate them for going unsupervised online.
Idealistic, I know, I know. But so is the idea that you can seal your kids in an airtight bubble and never risk any harm without the harm avoidance becoming harmful in itself. Or that the lawmakers in this country and elsewhere actually care about child safety at all, when they will not move a finger to prosecute those who hanged out with Epstein on his island.
That one is actually enforced by police, by general society that calls police when they see junkies. Limits on smoking and alcohol are enforced by sellers who cant sell to kids and regulators who punish sellers who do.
Parents are not expected to follow the kid home from school and watch it every second. Parents are expected to have general talk about drugs.
Oh yeah, and it is illegal to maket smoking to kids. Meanwhile, facebook spends billions on A/B testing increasingly sophisticated addiction builders ... and you expect the kids and parents to just be able to win over it with no support.
There should be parental controls that disallows installing apps, so there is no hidden browsers. Google and apple has an entire walled garden infra setup that they are using for control and hoovering up all the user data, the same infra can be uses for this.
This, and more - device makers and those upstream of the parents need to make "child safe" phones .. and probably (uh, oh) make them that way by default so that tech savvy types can disengage restrictions (and have that restrictions lifted state glaringly obvious for non tech savvy parents).
The raison d'etre for my above framed question was to highlight that non tech parents can not be expected to IT-child-safe phones and then monitor risks w/out assistance from vendors.
That's basically what this law is, but it's not saying there has to be a wholly separate phone model, but it's saying every phone (or desktop or laptop or tablet or ...) must have a child safe mode.
and if they're just old enough to follow instructions from an older cousin, an online predator, or to hand over their phone to a candy waving dubious third party for a "roblox coin hack" ?
How did we get here from OS age reporting? I don't see how age reporting is going to stop any of those 3 things - or indeed any technical set of controls.
If the fear is kids communicating with people, I might suggest giving them a phone and an internet connection is a poor start whatever happens next. They're communication tools. They're going to use them to communicate.
If the kids are clever enough to have a second browser the parents don't know about, I'm pretty sure they'll find a way to bypass this. For example, who's stopping an older sibling giving remote desktop access to his browser?
It's the same as age limits on energy drinks, alcohol, tobacco etc. More of an inconvenience than a restriction if someone is determined enough.
We should focus on having parents teach their kids what they should and shouldn't be doing, instead of "blocking" them and pretending that solves the issue.
Inconvenience rather than a restriction is the point though. Less kids smoke because of the inconvenience, and the world doesn't have to become a panopticon like it would to get 100% enforcement.
You don't need to look at their internet history. You talk to your kids about safe behavior. Then you're somewhat around when they're using the computer/device (until you feel they're of an age where that's not needed). The very knowledge you might see their screen at any moment will moderate behavior.
And properly working parental controls don't let the kids install another browser without permission.
I bought my niece a Chromebook for a specific purpose (she needed a device to do vision therapy with). I installed FamilyLink on my phone.
In FamilyLink I went through each setting and put everything as restrictive as possible. She can't install apps. Only the vision therapy website is whitelisted. If she tries to go to a different website or install an app it gives her a prompt letting her ask an adult for permission.
You don't need to be a software engineer to do any of that, you just need some basic reading comprehension. Eventually when she's older I can make things more permissive.
Now that said: the FamilyLink software could be much better.
It seems to be mainly designed for kids on android phones, not chromeOS Chromebooks. None of the screen time monitoring features work. I can lock her Chromebook but I can't see how much time she spent on it or set time limits on apps. I can't put a time limit on the Chrome browser (or any default apps). And if there is a way (outside of adding the device to an organization like a school does w/ Google Admin/Workspace), the documentation is not great at saying so.
Never mind the fact that Facebook, etc. has BILLIONS OF DOLLARS WORTH of software engineers, designers, psychologists making absolutely damn sure that little Alice & Bob keep their nice little eyes glued and their little thumbs scrolling.
Our family computer when I was a kid was in my parents bedroom. There was only one one. Kids should have dumb phones not supercomputers in their pocket connected to everyone everywhere all at once.
I renew my tabs online a few times a year. Site is state wide and works great. Take like five minutes and it's super manageable. Seattle city light works well and has a solid outage map when there's bad weather.
capitol.wa.gov is really informative and easy to use and looks nice.
Is three examples enough? You only asked for one. But I figured a few extra would help you.
This is a really weak argument. High-quality government websites exist, most notably the British gov.uk system. All this is beside the point - the current age verification proposals are wrong, and attempt to solve the wrong problem in ways that look very much as if they are primarily intended for surveillance rather than child protection.
'Child safe' internet access by default with a very low bar to let adults enable their devices to access the public internet is the solution. The UK's mobile providers already offer this by default - all you have to do is to call your network provider and ask for the restrictions to be turned off, and you have full internet access. Any legislation to create 'child safe' filtering should mandate that vendors provide ways for adults to turn the filtering off, easily, quickly and no questions asked - and that it should be viewed as the responsible moral default for adults to have full access to the world in order to be able to exercise their responsibilities as citizens, not some sort of option for degenerates. Whether you do this device side or network side is a technical detail.
The other sane way to do this - and what we should have done from the start, instead of providing kids with full access to the adult world by default - would be to have created 'child safe' devices to provide children with filtered access. Parents could then be in charge of whether they want their children to have that access and at what age. However, that boat has sailed.
Why exactly are some of you guys advocating for platforms to have increased responsibility for verifying the age of their users? Why exactly do you want platforms to collect government IDs or contract with third party ID brokers? How is that an improvement over the user agent attesting to the age of the user?
It only requires the encryption of the specific age-bracket signals mandated by Section 10 of the bill. What you're looking for is here:
Section 10. Age assurance requirements.
...
(d) All digital signals transmitted in accordance with this Section shall be encrypted to ensure data integrity and security.
age verification laws have little to do with protecting anyone, and social media companies are attempting to remove themselves from liability for their dangerous product by pushing for it
social media in its current unregulated state is harmful as has been demonstrated repeatedly with (suppressed) studies, and the push for age verification instead of regulation on the actual harmful content
age verification will always be a tool to censor whatever content certain interest groups want to censor and it is a wild violation of privacy as has been repeatedly demonstrated every time an identity verification firm gets hacked, they do not take this seriously at all, and all the while the actual harmful sites continue to do harm and have the ability to blame others for not 'protecting' people from the harm their product causes
it's a complete farce and has nothing to do with protecting anyone except tech companies peddling a harmful product
The social media company wouldn't be liable for not knowing someone's age but it would be liable if someone indicated as under-13 was shown porn or gambling ads or whatever they're trying to block. I see that as a win.
Note there's no verification in this law. "Age verification" is a deliberate misnomer.
> the push for age verification instead of regulation on the actual harmful content
_If_ you think there is content grown-ups should be able to see but kids shouldn’t be able to see without their parent’s consent, I don’t see what’s bad about this.
It could be part of the Accept header which already indicates language. It could serve as a signal that you only want to see content that is appropriate for that age bracket. Where appropriate means what the site wants to serve according to the laws of their jurisdiction.
But to require OS to implement all of this goes way to far and together with the proposed verification mechanisms is a privacy nightmare.
What does "hold these companies responsible" look like to you? I see a lot of empty rhetoric without things being spelled out. If you just want these companies to not exist, just say that.
Maybe we could have privacy protections before assuming every adult in the US is a child until giving random companies our PII? That would be cool, but not holding my breath.
Edit: of course, downvote the comment pointing to Americans having more civil rights. Expect nothing less from the HN techbro cesspool. And yes, this meta commentary infringes the guidelines, and the trust contract is broken at this point. This site does not deserve my energy anymore.
Are they expecting parents to be held responsible when their kid gets given a laptop and doesn't put in the right age? Or is it just a best effort thing that "parents who want to" can opt in to and which mostly serves as a shield for online platforms who wave the "but age API said" flag whenever something sketch happens?
Age verification is human verification at the time when the internet is getting very smart and dangerous bots. At least that's my optimistic view of this kind of paradigm shift!
Then your app would be rightfully decried as a whiny bitch and people would use other apps that aren't whiny bitches.
It would be like making an app refuse to load in California because of Prop 65, or refused to load in NYC because of rent control. Totally irrelevant nonsense and the wrong political stand to take.
I think you'll find they don't have to compel you to write code. They can simply prevent you from doing something else if you don't meet an obligation. Many many industries have compliance obligations that compel speech. Therapists have to report certain things if they hear them. Managers have a duty to report. My restaurant time I was required to write temperature logs.
The idea that code can't be compelled to fit a shape by the government is goofball nonsense.
It's like a product safety law. No state can compel you to put a pressure relief valve on your boilers. But they can stop you selling boilers without pressure relief valves. They can also prosecute you if your boiler explodes and kills people.
Curious how the various Linux distros and *BSD will handle this.
I expect the Corporate distros (RHEL, SUSE, Ubuntu) will be happy to get that personal info from its users. The other US based distros, maybe ban its use in Illinois ?
I expect one BSD OS will ignore it completely because they are outside of US jurisdiction. Not sure what the others can do. Of the others, one does have a decent amount of cash, the other ones are just squeaking by. So who knows what will happen with those.
Yeah and it's great. Because it wards off any verification that would actually be intrusive. You just need to add a birth date field to GECOS and you're done. It doesn't have to hold your actual birth date, as there's no penalties for lying. Viewing this as "age verification" is the wrong angle since nothing is verified - it's actually mandating that every OS must have parental controls. Don't think of it as "my birth date" - think of it as "apply parental controls that would be appropriate for someone born on this date".
Actually I'm tempted to think everyone who calls it "age verification" is being deliberately dishonest about what the law is.
At the end of the day, it is my job as a parent to steer my kids out of harm’s way, be it the alley where they will find the local dealer, the park where people are injecting at night, or not stuffing their faces with sugar, or social media.
The “Bob and Alice are technically illiterate” defence doesn’t hold. I’m gun illiterate but I wouldn’t buy one for my kids.
Do I feel bad for the kid that killed himself doing something stupid he say at TikTok? Yes. Do I feel bad the for parents that gave a phone with TikTok to an unsupervised 11 year old? Not really.
This is censorship; it is like saying you can't eat a steak because a baby can't chew it. They will try to ban Linux or fine Linux developers unless it reports the user's age.
I don't see how that implies they won't try. From everything I've seen before, the neither lawyers nor judges tend to have a solid understanding of technology (lawyers might know the parts that will be helpful to them in their current cases).
I wonder how vim will handle age brackets. Send all text to a LLM on the cloud in real time and refuse to show keystrokes with unsafe content? And censor unsafe text read from disk?
The breathless fearmongering over an age field on account set up is just completely over-the-top. This is probably the least bad out of all possible ways to implement age checking. The benefit of this is that it can short-circuit support for more onerous age verification. The writing has been on the wall for some time now: the era of completely unrestricted internet is coming to an end. The question is how awful will the new normal be? Legislation like this is a win all around, a complete nothingburger. We should be celebrating it, not fighting it tooth and nail.
There's something to be said for realizing which way the winds are blowing and getting ahead of it. The fight against any and all age gating on the internet is already lost. The question is what will the system look like once it comes into being. This is something we have a lot of say over if we just stop being obstinate and start offering solutions. Sticking one's head in the sand will just result in a worse state of affairs in the end.
Note that we already support this exact thing when it's about cookies!
Site says: "do you want to enable tracking?" and HN says "why should every site ask me? Can't this be a header or something?"
Site says: "do you want to enable adult content?" and government says "why should every site ask you? Can't this be a header or something?" and HN says "OMG TOTALITARIANISM"
Seeing as this is Illinois we're talking about, it's probably less about protecting kids and more about extorting punitive fines from tech companies for non-compliance.
Occasionally holding trillion dollar corporations accountable to the law is not a business model.
I reckon the societal damage these "social" media companies inflict is magnitudes larger than whatever puny fines they've had to cough up so far for breaking the law.
Background: Meta/Facebook, Google and Apple all support age verification. It gives them legal cover and for their ad platforms gives better data.
But Meta/FB have been strongly lobbying to make it required at the OS level, so they aren't responsible for it, whereas Google and Apple both want it to be an application responsibility.
I think the CA version of this ended up with a carve-out for open source? I can't recall the details.
> all support age verification
No, they all support harvesting your data so they can continue doing what they do best: building shadow profiles and targeting ads.
Nothing a signal of an age group tells them more than "send me more ads for XX year-olds".
Why do you think it's always a question asked in online surveys?
>> for their ad platforms gives better data
> No, they all support harvesting your data so they can continue doing what they do best: building shadow profiles and targeting ads.
I think we are agreeing adamantly here?
You said that Meta doesn't want to be responsible for age verification - they absolutely do, because that gives them every single user's identity. Forcing it at the OS level is not an attempt to put the responsibility on the OS, it's an attempt to drive a wedge into the OS where Apple can't hide users' identities.
No, they are far more cunning than you give them credit, they want to have the information but bare no responsibility for both collecting and validating it themselves nor for when the kids circumvent it.
So they are in the golden zone of maximum exploitation and plausible deniability.
They will literally say:
Of course, we showed that one teen 500 gambling and porn ads a day, Apple/Google/Microsoft told us he is 65, it's their fault! Sure every other word he posted was rizz, but how could we possibly know he was not 65.
Apple wouldn't give the identity to Facebook, only the age bracket.
No, because these laws give them less data. But they also give them less liability which is what they care more about in this instance.
thats why i always click 25-34
those buckets get the funnest ads
Online surveys are for age ranges of people who aren't minors. Minors aren't allowed to have their data targeted for advertising. If access to this signal can be used to show they were targeted deliberately, that can warrant setting fines near the limit.
eh, I'd say their lawyers want them to not be liable for the utter harms their apps have on children.
The other stuff they already get enough off. They dont need to know you're over 18. They don't want the liabilities of children killing themselves because an AI app told them something stupid.
What's most shocking to me is the willingness to comply on display here and elsewhere.
If the state proposes you stick a corncob up your rear, your initial response shouldn't be to ask if they prefer you use a rubber or wooden mallet to achieve compliance.
If the state proposed every OS must have parental controls activated via a checkbox would you say the same? Because that's what they actually did except the checkbox is a numeric text field.
Yes. Seems like accounts are made by fb/meta to support them in hn.
Really? You oppose any form of parental controls existing in an OS and you think anyone who supports them is a Meta shill?
Rectum? Damn near killed 'em!
Wooden. Definitely wooden.
From reading the article, it sounds like an enforced standardisation? Like, asking for account age bracket and then having a standard API to ask for it would be easy, right? Just write it to a root owned `~/.age-bracket` for each user or something (obviously something better).
It's a feature many apps implement in all kinds of ways already, especially games and social media stuff, so this, in theory, just makes it easier and consistent?
I'm against leaking our kids ages, and all the privacy and other concerns as much as anyone, but are we just getting overly angry too quickly on this one?
I get that it's a slippery slope too.
It passes responsibility and accountability from the large platforms to the open-source communities and to parents who are most likely tech illiterate.
Facebook, etc. can wash their hands when they "accidentally" serve gambling ads (or whatever) to children and say "well it's not our fault the parent has the laptop misconfigured"
It's classic blaming the victim.
I disagree. The parents are the ones who should be supervising. The work should not be pushed off to OSS devs or random website operators. Facebook is bad, but I'd rather deal with one Facebook than kill 1000 normal sites with bad legislation.
> The parents are the ones who should be supervising.
Ok. When Alice & Bob come home from school what steps should every parent take to supervise A&B's phone and device usage over the past 48 hours?
Internet history, of course - for all the browsers, including those hidden away? But what if the logs are wiped or the second BraveFoxChrome installation isn't obvious?
Must every parent have an IT degree?
What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?
The same steps you take to make sure they are not smoking in a back alley on the way home.
You sniff their clothing for evidence of a porn site or chatting with a predator?
You teach them the harm of smoking and online grooming. You teach them to not accept cigarettes or sexual advances from others. And you build a trusting relationship with them so in the unfortunate case they do mess up, they trust you enough that they tell you what's going on, instead of hiding abuse they suffered from others so their parents don't berate them for going unsupervised online.
Idealistic, I know, I know. But so is the idea that you can seal your kids in an airtight bubble and never risk any harm without the harm avoidance becoming harmful in itself. Or that the lawmakers in this country and elsewhere actually care about child safety at all, when they will not move a finger to prosecute those who hanged out with Epstein on his island.
That one is actually enforced by police, by general society that calls police when they see junkies. Limits on smoking and alcohol are enforced by sellers who cant sell to kids and regulators who punish sellers who do.
Parents are not expected to follow the kid home from school and watch it every second. Parents are expected to have general talk about drugs.
Oh yeah, and it is illegal to maket smoking to kids. Meanwhile, facebook spends billions on A/B testing increasingly sophisticated addiction builders ... and you expect the kids and parents to just be able to win over it with no support.
There should be parental controls that disallows installing apps, so there is no hidden browsers. Google and apple has an entire walled garden infra setup that they are using for control and hoovering up all the user data, the same infra can be uses for this.
Winner winner, chicken dinner.
This, and more - device makers and those upstream of the parents need to make "child safe" phones .. and probably (uh, oh) make them that way by default so that tech savvy types can disengage restrictions (and have that restrictions lifted state glaringly obvious for non tech savvy parents).
The raison d'etre for my above framed question was to highlight that non tech parents can not be expected to IT-child-safe phones and then monitor risks w/out assistance from vendors.
That's basically what this law is, but it's not saying there has to be a wholly separate phone model, but it's saying every phone (or desktop or laptop or tablet or ...) must have a child safe mode.
If the kid's old enough to be hiding their internet history from their parents, they're old enough to have some privacy.
and if they're just old enough to follow instructions from an older cousin, an online predator, or to hand over their phone to a candy waving dubious third party for a "roblox coin hack" ?
How did we get here from OS age reporting? I don't see how age reporting is going to stop any of those 3 things - or indeed any technical set of controls.
If the fear is kids communicating with people, I might suggest giving them a phone and an internet connection is a poor start whatever happens next. They're communication tools. They're going to use them to communicate.
If the kids are clever enough to have a second browser the parents don't know about, I'm pretty sure they'll find a way to bypass this. For example, who's stopping an older sibling giving remote desktop access to his browser?
It's the same as age limits on energy drinks, alcohol, tobacco etc. More of an inconvenience than a restriction if someone is determined enough.
We should focus on having parents teach their kids what they should and shouldn't be doing, instead of "blocking" them and pretending that solves the issue.
Inconvenience rather than a restriction is the point though. Less kids smoke because of the inconvenience, and the world doesn't have to become a panopticon like it would to get 100% enforcement.
You don't need to look at their internet history. You talk to your kids about safe behavior. Then you're somewhat around when they're using the computer/device (until you feel they're of an age where that's not needed). The very knowledge you might see their screen at any moment will moderate behavior.
And properly working parental controls don't let the kids install another browser without permission.
I bought my niece a Chromebook for a specific purpose (she needed a device to do vision therapy with). I installed FamilyLink on my phone.
In FamilyLink I went through each setting and put everything as restrictive as possible. She can't install apps. Only the vision therapy website is whitelisted. If she tries to go to a different website or install an app it gives her a prompt letting her ask an adult for permission.
You don't need to be a software engineer to do any of that, you just need some basic reading comprehension. Eventually when she's older I can make things more permissive.
Now that said: the FamilyLink software could be much better.
It seems to be mainly designed for kids on android phones, not chromeOS Chromebooks. None of the screen time monitoring features work. I can lock her Chromebook but I can't see how much time she spent on it or set time limits on apps. I can't put a time limit on the Chrome browser (or any default apps). And if there is a way (outside of adding the device to an organization like a school does w/ Google Admin/Workspace), the documentation is not great at saying so.
Never mind the fact that Facebook, etc. has BILLIONS OF DOLLARS WORTH of software engineers, designers, psychologists making absolutely damn sure that little Alice & Bob keep their nice little eyes glued and their little thumbs scrolling.
If their eyes and thumbs are that little perhaps you as a parent shouldn’t buy them devices, but let them play outside.
Our family computer when I was a kid was in my parents bedroom. There was only one one. Kids should have dumb phones not supercomputers in their pocket connected to everyone everywhere all at once.
I had one in my bedroom but it didn't have the internet. I had a box of appropriate games on CDs.
> What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?
You know who else are not experts in software design and installation? Fossil politicians and slimy bureaucrats.
Name one public sector state or local website that isn't utter garbage and a nightmare to use. Go ahead I'll wait.
They need to get their sticky donut-eating fingers out of my personal computer.
I renew my tabs online a few times a year. Site is state wide and works great. Take like five minutes and it's super manageable. Seattle city light works well and has a solid outage map when there's bad weather.
capitol.wa.gov is really informative and easy to use and looks nice.
Is three examples enough? You only asked for one. But I figured a few extra would help you.
This is a really weak argument. High-quality government websites exist, most notably the British gov.uk system. All this is beside the point - the current age verification proposals are wrong, and attempt to solve the wrong problem in ways that look very much as if they are primarily intended for surveillance rather than child protection.
'Child safe' internet access by default with a very low bar to let adults enable their devices to access the public internet is the solution. The UK's mobile providers already offer this by default - all you have to do is to call your network provider and ask for the restrictions to be turned off, and you have full internet access. Any legislation to create 'child safe' filtering should mandate that vendors provide ways for adults to turn the filtering off, easily, quickly and no questions asked - and that it should be viewed as the responsible moral default for adults to have full access to the world in order to be able to exercise their responsibilities as citizens, not some sort of option for degenerates. Whether you do this device side or network side is a technical detail.
The other sane way to do this - and what we should have done from the start, instead of providing kids with full access to the adult world by default - would be to have created 'child safe' devices to provide children with filtered access. Parents could then be in charge of whether they want their children to have that access and at what age. However, that boat has sailed.
The politicians and bureaucrats aren't generally the ones making the web sites.
Gov.uk
Why exactly are some of you guys advocating for platforms to have increased responsibility for verifying the age of their users? Why exactly do you want platforms to collect government IDs or contract with third party ID brokers? How is that an improvement over the user agent attesting to the age of the user?
It's liber-contrarianism, they hate when the government does stuff so they instinctively oppose it even though the opposite is worse.
Isn't that a good design though?
And it isn't blaming anyone, it's a design.
> The law also stipulates that all transmitted digital signals have to be encrypted.
I'm hoping there's nuance, but I'm surprised the article didn't go deeper on this too. ARP? ICMP? DHCP?
I can't actually load the bill to read it ATM.
In practice, this means TLS, but there is no reason to write that into the law.
try: https://ilga.gov/Legislation/BillStatus/FullText?GAID=18&Doc...
It only requires the encryption of the specific age-bracket signals mandated by Section 10 of the bill. What you're looking for is here:
Section 10. Age assurance requirements. ... (d) All digital signals transmitted in accordance with this Section shall be encrypted to ensure data integrity and security.
Encryption does not ensure data integrity, sigh...
Wouldn't it have the opposite effect as intended? Making kids easier to target and undermine their safety?
https://www.ftc.gov/legal-library/browse/rules/childrens-onl...
That's the correct way to do it. Age should be something reported by browser/os/hardware. Something similar to User-Agent.
I really hope this will end the whole third party age verification farce.
it's not
age verification laws have little to do with protecting anyone, and social media companies are attempting to remove themselves from liability for their dangerous product by pushing for it
social media in its current unregulated state is harmful as has been demonstrated repeatedly with (suppressed) studies, and the push for age verification instead of regulation on the actual harmful content
age verification will always be a tool to censor whatever content certain interest groups want to censor and it is a wild violation of privacy as has been repeatedly demonstrated every time an identity verification firm gets hacked, they do not take this seriously at all, and all the while the actual harmful sites continue to do harm and have the ability to blame others for not 'protecting' people from the harm their product causes
it's a complete farce and has nothing to do with protecting anyone except tech companies peddling a harmful product
The social media company wouldn't be liable for not knowing someone's age but it would be liable if someone indicated as under-13 was shown porn or gambling ads or whatever they're trying to block. I see that as a win.
Note there's no verification in this law. "Age verification" is a deliberate misnomer.
> the push for age verification instead of regulation on the actual harmful content
_If_ you think there is content grown-ups should be able to see but kids shouldn’t be able to see without their parent’s consent, I don’t see what’s bad about this.
I also think many Americans agree with that _If_.
It could be part of the Accept header which already indicates language. It could serve as a signal that you only want to see content that is appropriate for that age bracket. Where appropriate means what the site wants to serve according to the laws of their jurisdiction.
But to require OS to implement all of this goes way to far and together with the proposed verification mechanisms is a privacy nightmare.
There are no proposed verification mechanisms in Illinois. This is purely a consolidation of parental controls.
Might as well put your real name and DOB in there.
Remember. We should do absolutely everything in our power to not hold these companies responsible.
What does "hold these companies responsible" look like to you? I see a lot of empty rhetoric without things being spelled out. If you just want these companies to not exist, just say that.
Remember. Keep your standards in the basement. We'll dust them off when someone dies.
Maybe we could have privacy protections before assuming every adult in the US is a child until giving random companies our PII? That would be cool, but not holding my breath.
Edit: of course, downvote the comment pointing to Americans having more civil rights. Expect nothing less from the HN techbro cesspool. And yes, this meta commentary infringes the guidelines, and the trust contract is broken at this point. This site does not deserve my energy anymore.
No PII is transmitted to the companies because of this law.
Are they expecting parents to be held responsible when their kid gets given a laptop and doesn't put in the right age? Or is it just a best effort thing that "parents who want to" can opt in to and which mostly serves as a shield for online platforms who wave the "but age API said" flag whenever something sketch happens?
It's opt in. You can say your kid was born in 1900 if you want an unrestricted internet.
Meh. It's a trick by facebook and others to harvest data and blame people later saying people volunteered the data.
Feels like hn is filled with these proxy accounts to support fb, google.
But they get less data because of this, not more. They're supporting this to offload liability, not to get more data.
Age verification is human verification at the time when the internet is getting very smart and dangerous bots. At least that's my optimistic view of this kind of paradigm shift!
What if you make your app refuse to load in Illinois just opens a banner saying why and who to lobby.
I think it depends on whether the app will make the developer significant extra money. And if so, then the money wins.
Then your app would be rightfully decried as a whiny bitch and people would use other apps that aren't whiny bitches.
It would be like making an app refuse to load in California because of Prop 65, or refused to load in NYC because of rent control. Totally irrelevant nonsense and the wrong political stand to take.
illogical hubris - no state can regulate the internet; no state can compel developers to write code. the court cases on this will be interesting
I think you'll find they don't have to compel you to write code. They can simply prevent you from doing something else if you don't meet an obligation. Many many industries have compliance obligations that compel speech. Therapists have to report certain things if they hear them. Managers have a duty to report. My restaurant time I was required to write temperature logs.
The idea that code can't be compelled to fit a shape by the government is goofball nonsense.
It's like a product safety law. No state can compel you to put a pressure relief valve on your boilers. But they can stop you selling boilers without pressure relief valves. They can also prosecute you if your boiler explodes and kills people.
I assume you've heard of New Mexico's DoJ winning a not-quite-$1B court case against Meta.
Maybe Meta's lawyers will win on appeal, maybe they won't. "Think of the children!" pushes a lot of emotional buttons.
But Mr. Zuck most certainly can decide that he doesn't like the legal bills and uncertainty, and order his developers to write code.
Curious how the various Linux distros and *BSD will handle this.
I expect the Corporate distros (RHEL, SUSE, Ubuntu) will be happy to get that personal info from its users. The other US based distros, maybe ban its use in Illinois ?
I expect one BSD OS will ignore it completely because they are outside of US jurisdiction. Not sure what the others can do. Of the others, one does have a decent amount of cash, the other ones are just squeaking by. So who knows what will happen with those.
Yeah and it's great. Because it wards off any verification that would actually be intrusive. You just need to add a birth date field to GECOS and you're done. It doesn't have to hold your actual birth date, as there's no penalties for lying. Viewing this as "age verification" is the wrong angle since nothing is verified - it's actually mandating that every OS must have parental controls. Don't think of it as "my birth date" - think of it as "apply parental controls that would be appropriate for someone born on this date".
Actually I'm tempted to think everyone who calls it "age verification" is being deliberately dishonest about what the law is.
At the end of the day, it is my job as a parent to steer my kids out of harm’s way, be it the alley where they will find the local dealer, the park where people are injecting at night, or not stuffing their faces with sugar, or social media.
The “Bob and Alice are technically illiterate” defence doesn’t hold. I’m gun illiterate but I wouldn’t buy one for my kids.
Do I feel bad for the kid that killed himself doing something stupid he say at TikTok? Yes. Do I feel bad the for parents that gave a phone with TikTok to an unsupervised 11 year old? Not really.
Parents must take responsibility.
This is censorship; it is like saying you can't eat a steak because a baby can't chew it. They will try to ban Linux or fine Linux developers unless it reports the user's age.
How? Linux developers don't live in Illinois or even in the USA for the most part.
There's a number of Linux developers living in the USA. I wouldn't be surprised if any live in the Chicago area.
I don't see how that implies they won't try. From everything I've seen before, the neither lawyers nor judges tend to have a solid understanding of technology (lawyers might know the parts that will be helpful to them in their current cases).
They sell the OS to Illinois residents.
I have paid for Redhat just once. Since then ubuntu FTW
It's possible for Ubuntu too. Dell sells Ubuntu laptops to Illinois.
"this option is not available in the state of Illinois"
Seems easy enough to implement before 2028 and only serve laptops without OS.
Well at least this wouldn't result in massive incentives for Microsoft to get the same law passed elsewhere.
Last I checked, systemd already has age verification built in and most of Linux uses systemd.
Another state requires identity verification and monitoring in order to use a computer…
How do they reconcile this with electronic voting machines, where verifying identity is an absolute no?
Where's the identity verification and monitoring in this law?
I wonder how vim will handle age brackets. Send all text to a LLM on the cloud in real time and refuse to show keystrokes with unsafe content? And censor unsafe text read from disk?
/s
It just won't because it isn't relevant to vim.
The breathless fearmongering over an age field on account set up is just completely over-the-top. This is probably the least bad out of all possible ways to implement age checking. The benefit of this is that it can short-circuit support for more onerous age verification. The writing has been on the wall for some time now: the era of completely unrestricted internet is coming to an end. The question is how awful will the new normal be? Legislation like this is a win all around, a complete nothingburger. We should be celebrating it, not fighting it tooth and nail.
> This is probably the least bad out of all possible ways to implement age checking.
Less bad is still bad.
Normalizing a gated, state controlled internet is bad.
There's something to be said for realizing which way the winds are blowing and getting ahead of it. The fight against any and all age gating on the internet is already lost. The question is what will the system look like once it comes into being. This is something we have a lot of say over if we just stop being obstinate and start offering solutions. Sticking one's head in the sand will just result in a worse state of affairs in the end.
Note that we already support this exact thing when it's about cookies!
Site says: "do you want to enable tracking?" and HN says "why should every site ask me? Can't this be a header or something?"
Site says: "do you want to enable adult content?" and government says "why should every site ask you? Can't this be a header or something?" and HN says "OMG TOTALITARIANISM"
We are on the path to gated monopoly controlled internet.
So, goverment controlled is better then Musk, Zuckenberg and Altman controlled.
This. I really don't get the upset. This is not an age verification law. In fact it makes age verification illegal so isn't that a good thing?
Seeing as this is Illinois we're talking about, it's probably less about protecting kids and more about extorting punitive fines from tech companies for non-compliance.
> violations can cost up to $50,000 each
I hear slot machine noises.
it's a strange business model that works for the EU
Occasionally holding trillion dollar corporations accountable to the law is not a business model.
I reckon the societal damage these "social" media companies inflict is magnitudes larger than whatever puny fines they've had to cough up so far for breaking the law.
Thinking of everything as a business model: This is your brain on capitalism.
You're source is Trump? I guess you are an uninformed US citizen (not the only one) who has an uninformed opinion on Europe.