I think there's a lot of proprietary stuff, from Google Play Services to Pixel specific features. A very significant stack of "modern" software layers are proprietary, even on Android.
What are they defining as an operation system? It’s a term that has fuzzy edges as a technical term, and given laws are usually piss poor at defining technical terms, I can’t see it being well defined in CA law.
This is a potential loophole. Companies could have an "open source" OS but restrict installations like Tivo did in the 2000s (i.e. "Tivoization"). Or they could allow installation of modified software but restrict functionality like the way the Google Play Integrity API can nerf apps running on custom builds of Android.
Or, they can have a license like the Business Source License where you can copy, redistribute, and modify the software but you can't use it commercially. This goes against OSI's open source definition.
We emailed this amendment to Buffy Wicks's staff:
§1798.504(f) This title does not apply to[...]:
(4) An operating system or application that meets both of the following conditions:
(A) The operating system or application is distributed under license terms that permit a recipient to copy, redistribute, and modify the software, including for commercial purposes and without payment of a royalty or fee.
(B) The operating system provider or developer does not, by technical or contractual means, prevent the recipient from installing modified versions of the software on a device on which the unmodified version operates, and does not restrict the functionality or interoperability of modified versions.
Shouldn't that specify the code not or not only the software? For example, the corporate Windows license allows the corporation to copy, redistribute (internally), and modify (via group policy, APIs, or development on the Windows platform) the software. The big difference between that and Linux is licensees can't access the code. FOSS requires free access to, use of, modification of, and redistribution of the code.
Honestly you're probably right, code is a better term. I copied that language from Colorado's SB26-051 bill which also has a FOSS exemption and they use the word "software". I'm not a lawyer but I'm hoping that a court's interpretation of one state's language will apply to other states.
That and lots of FOSS licenses use some variant of those words "copy, redistribute, and modify" so it's probably a term-of-art that courts recognize.
This is what Colorado's law says. It prevents Tivoization but not feature nerfing like the Play Integrity API.
§ 6-30-105 (3)
(e) AN OPERATING SYSTEM PROVIDER OR DEVELOPER THAT
DISTRIBUTES AN OPERATING SYSTEM OR APPLICATION UNDER LICENSE TERMS
THAT PERMIT A RECIPIENT TO COPY, REDISTRIBUTE, AND MODIFY THE
SOFTWARE WITHOUT ANY PLATFORM-IMPOSED TECHNICAL OR CONTRACTUAL
RESTRICTIONS IMPOSED BY THE PROVIDER OR DEVELOPER ON INSTALLING
ALL MODIFIED VERSIONS.
The only device mandates that should be taking place is for the default installations of web clients should be checking to see if parental controls are enabled. This only impacts the major browsers. An intern at each browser company could add this check in minutes. If they are enabled and the person logged in is on a regular account (not admin or power user of sorts) then the base installation of web clients must check for an RTA header [1]. If present, prompt for a override password and also give the option for the admin to approve-list the domain at that time. That's it. Not perfect, nothing is or will be.
The only thing server, platform, website, service providers should be doing is setting an RTA header if the content could possibly be adult or user-contributed content that could dynamically become adult, moderation aside. This knocks out two issues with one fix. Small children don't see much if any adult content and they are kept off social media until the admin (parent or legal guardian) approves it.
If a site is not adding the RTA header then progressively fine them into oblivion. If they accept the fines as the cost of doing business then seize everything and put everyone in GenPop. An intern could enable the header in 5 minutes.
All legislation regarding age verification must revolve around this otherwise people must reject it as an abusive form of tracking and privacy invasion. The focus should be on small children as teen share porn, warez, movies and such within Rated-G games.
I've emailed politicians as have others but only received boilerplate thankyou's. I suspect the real reason is kick-backs but they will never admit it.
No harm in people reaching out to their politicians state and federal. The more people that bring it up the better. Let them know your childrens data will not be shared and when the data is leaked you will hold the politicians accountable.
Well, if the concern is they might miss out on revenue from a small child accessing their site and they are not a child specific site then perhaps they should be pushed out of the market one way or another.
No, what I mean is that adding a lot of laws to let websites be legal (age verification, GDPR, etc.) adds a huge burden and that prevents new small websites from even existing.
All I am proposing is that websites that may contain adult material add a header. That's hobby level effort. Small companies using a CDN or platform provider can either add the header in the CDN, check a box if this were to take off or open a ticket asking to add the header.
I’m not in the US but assuming everyone who disagrees with you is receiving kickbacks is a bit much. I agree this is a terrible idea and doesn’t make sense past a few seconds of thinking but the reality is it’s very popular with an awful lot of people.
Thats crazy talk, how are we gonna build a database of computers tied to physical identification of users by which we can monitor, control, and monetize… you’re saying parents should be responsible for their children? How is the state going to be able to exert more control if it doesn’t have ubiquitous surveillance of it’s population!?
/s
> An intern at each browser company could add this check in minutes.
An intern could also just delete the product which would also "solve" this "issue". The fact that it's easy or cheap is not significant to the problem at hand.
> should be doing is setting an RTA header
Many sites will just set the header by default. Now you've created a problem.
> then progressively fine them into oblivion.
This does nothing. See: Ofcom vs 4chan.
> device mandates
Mandate that the device provide an API for child protection software. Then it's up to individual parents to decide to install that software or not. Then we also get competition in this market rather than relying on whatever solution an intern cooked up one day.
Many sites will just set the header by default. Now you've created a problem.
I am not seeing a problem. Kids need not access those sites unless the parent or legal guardian approves it. Sites meant for children would not be adding the header.
> Sites meant for children would not be adding the header.
Is Wikipedia "meant for children?" Should they be fully denied access to it? Should Wikimedia be fined if they make a mistake? If they get fined often enough do you think they'll just turn the header on everywhere in order to avoid risk?
Replace Wikipedia with any other mixed content site you prefer.
Child specific sites would not add the header. Anyone else could. I add it to my hobby sites. Some porn sites already add it to their sites [1]. Shodan can't reach my sites. I do not want small children on my blogs.
Add it to any site not specifically meant for children, that is totally fine.
- Site adds a header if they may potentially have adult content.
- Browser detects header. Prompts for local password to access site.
- Child does not know password, picks a different site or begs parent for access.
- This is now between small child and parent. No third parties, no tracking, no telling website the users age, no local or remote API's sharing data.
- At some point if all goes well the child will be an adult and will thank their parent for looking out for them when all their friends data was sold and abused.
Absolutely trivial and totally comprehensive solution, enabling adult content blocking at the account level, device level, network level, and the ISP level. Could even be expanded to any sort of content blocking, if you want to allow households to restrict access to vaccine critique or criticism of the king without violating the First Amendment or rooting everyone's devices.
The problem is that the point is to root everyone's devices. Anyone explaining how easy this is would be pushed out of the conversation as fast as if they were advocating for single-payer healthcare.
edit: I've been advocating the nearly identical but opposite solution - restricted access sites shouldn't respond to requests that lack an appropriate age/content restriction header. If they do, jail them.
They're literally going to have to do this anyway. Rooting people's devices to force them to lie about their age when they install their operating system is an absolutely fake pretendy solution; the only way it works is if you have to verify your age with some government agency when you install an operating system, in order to make that OS age official. The point is the identification.
No. That requires information disclosure to a third party. The point is enabling device admins better control over local device behavior. We're trying to keep conscientious parents able to do their thing. Not further enable the ability to manage the populace with official registries. If a kid can figure out how to install their own OS without their parent's help, odds are the kid is with it enough to start dipping their toes in the deep end. Or at least until they out themselves in front of their parents. In that case though it's a home problem, not a rest of the Internet problem.
It's still a stupid unconstitutional law, but I see what the aim is, even without strawmanning it.
Imagine having to police the OS installations at everyone's home. It's dangerous enough to serve warrants to known felons at known locations. I would not want to be the paramilitary officer going door to door having to be ready to flashbang the family or worse. I don't know if there are even words to describe the PTSD that all the enforcers and families would have. Someone in North Korea probably has the words to describe this.
I largely agree, but the RTA header doesn't seem to be good enough for most websites to use. When a website wants to block browsers with parental controls on, but it isn't porn and it shouldn't be blocked by SafeSearch, what do they do?
They stop trying to put everything in a different category and treat RTA as the person under the age of consent must get approval from their parent or legal guardian. Keep it simple.
Correct. Until parent or guardian puts in password next to the text that says "Approve this site, forever."
You gave me an idea. Maybe there could be categories similar in concept to those that exist in corporate firewalls today that say things like:
- News Category (Known to be SFW)
- News Category (That may be NSFW)
- Child friendly sites
- Social media sites
... and so on.
This could be crowd sourced, ideally in a way that can not be gamed. The masses could flag/report false claims. That, or just keep it simple. ad-hoc input of permitted sites by parent.
This is a terrible idea and your proposed society is terrible. It doesn’t matter if it’s safe for work; you asked to identify sites with content that can change. Either the parent has seen and approved the content or not.
What is [N]SFW under your definition? I don't think anybody has a problem with children seeing an adult heterosexual couple kissing, but what about a teenage couple? A homosexual couple? A mixed-race couple? A couple with a 40 year age gap? Audible moaning? Groping under clothes? Implied but not explicit hands touching genitals? Dripping saliva and face licking?
The problem with defining categories is that artists will do their best to defy categorization. That has been the nature of art for as long as humans have been making art.
I do not have a proposal for that. I'm only covering the issue of sharing any personal attributes of a child or anyone with any corporations as they have proven time and time again they can not be trusted with it. If anything they have proven beyond any shadow of doubt they can not be trusted with anything.
I will leave the NSFW definitions to yourself and others. Since the W stands for Work I guess company management and HR get some say in it too. I don't know where they get their standards from.
Ages ago I worked for a company that hosted porn and their standards were uniquely liberal.
I imagine Google wants to distinguish between websites that want to be blocked by SafeSearch, versus websites that want to be blocked when parental controls are on? There's no reason to leave that ambiguous. Plenty of adults have SafeSearch on.
Defining a new header isn't hard; the hard part is getting consensus and adoption.
For what it's worth this header has been around for a long time. It's predecessor (PICS ICRA) was too complicated and started using topics. After a while they added so many topics that even being an abbreviated header it was still massive and confusing. There were websites that people could select all the topics and what not but even then the adoption was low due to complexity and topics constantly changing on sites.
Are today's videos beheading's without blood, with blood, with or without anguish, with nudity, without nudity, etc... After a while it gets out of hand.
It turned out the internet was too dynamic so the RTA header was created to just say "adult".
A) Aren't you targeting a completely different problem than this law? It's my understanding that this law targets the collection of the age from the user. What the user agent does with that signal is a different problem, and seems to already be solved, except for the definition of "actual knowledge" which they are trying to establish here.
B) How would your RTA header intersect with content rating in different jurisdictions? What if the content is illegal for children in Turkey but legal for children in Kentucky?
For topic (A) I am suggesting to negate this behavior all together. No more sharing personal data. That evil-pattern must be stopped.
For topic (B) companies can set or not set the header based on GeoIP. Not perfect but GeoIP is already used in load balancers, web servers and applications.
For (A) we have nothing to talk about. I think we fundamentally disagree about how society functions, and we aren't going to knock that out over hackernews.
For (B), your proposal requires the website have a database over current rules in every country they would be accessible from. Would a website then, in your opinion, be responsible for the accuracy of this database? We have to presuppose an official GeoIP source that would then be legally binding and under democratic control, but given such a database, would a website serving a wrong header to an IP associated with a specific country then be committing a crime in that country? What would the punishment be?
For (A) I guess you are right, we won't agree. I do like your username however.
For (B) this is already a thing. Porn sites and already doing this. Instead of blocking a region I am proposing to stop blocking and instead the law permit them to just add a header. The only people I can imagine apposing this are commercial VPN providers.
I think a better example might be places like polymarket (not allowed to operate in us) or usatoday (serves an EU only version with no cookies). The technical limitations on those systems are both GeoIP as far as I'm aware, and that seem sufficient for regulators.
What I find more interesting is that what you want is within the scope of this law. It's only required that the operating system takes in your age from an admin, from there the application (user agent/webbrowser) is supposed to handle the blocking, which it could do with a header as you suggest.
I will note that you are going to find a lot of libertarians that would oppose banning GeoIP circumvention.
Are small children losing money on gambling sites already? If so I have not been paying attention. That really needs to be reigned in as they are likely using their parents credit cards without their permission. We need to break that habit before they reach the age of consent and that becomes a punishable crime. Our prison system already has too many young people. That's an awful way to start.
I agree fundamentally and ideologically but we are past that point. The toothpaste is already out of the tube as they say. There will be restrictions so all I can do is suggest more sensible restrictions that keep the control on the client side and do not share data. Any data shared can and will be abused, leaked, sold, stolen without consequence.
I heard that lie about "sensible restrictions" so many times, now I am waiting for "sensible violence", "sensible beating to death" and so on. It is a false argument that "there will be restrictions so all I can do is suggest more sensible restrictions", what you can do is recognize that "no restrictions is an option".
It is like negotiating with a terrorist that wants to kill you and this is his starting position and then he wants to agree on some compromise, like seriously beating you. There is no negotiation.
We are not past the point at all. Any democracy can ultimately decide on laws and regulation. Why would you wish to insinuate otherwise here? California could easily decide to not implement such laws, for instance.
That data leaks out is always a given. So, gather less data. Ideally none. But this is not a discussion about data. This is a discussion as to what state actors think they are allowed to do. It is an attack on private life of people. See the combined strike against VPNs.
Please remember that there are CA state policies that the voters voted to overturn (in a referendum) and the current CA state government refuses to do so. California voters decided. The California government un-democratically decided to ignore the voters against their own laws they themselves passed.
PS I'm referring to bail reform here.
PPS Just trying to frame what the CA government thinks its allowed to do which is apparently anything it wants.
I agree with you, as a longtime free speech believe.
but... I would also like to keep my kids from seeing the very worst of the internet before they're ready to handle it. I tried using a PiHole but Firefox DNS-over-HTTPS nullifies that now. It's not realistic for me to be watching over their shoulders 24/7; what can I do to keep them away from stuff 99% of people agree isn't for children to see, without something like this?
Just like no past generation had so much information so readily available. One quick quip can always be rebutted by another quick quip, but it doesn't really move the conversation along in any meaningful manner.
If one kid is able to bypass the system it means it's zero percent effective. Same thing with alcohol, and cigarettes. Especially if it means I have to show my ID to buy those things.
Some kids getting access to booze here and there with planning and coordination is different from kids walking into a liquor store or bar whenever they want.
Shit thanks for pointing that out. My door lock isn't 100% effective at stopping thieves, so I guess I can get rid of that annoying thing. Will be nice to never worry about being locked out again!
Well in the past there were laws banning the selling of cigarettes and alcohol to minors. Selling alcohol to a minor can cause you to lose your liquor license. With much of the online content being free and not involving a physical product it has become significantly harder for a parent to protect their children.
> Past generations absolutely protected their kids from cigarettes and alcohol.
I'm sorry, but what? Cigarettes, sure. Alcohol? Binge drinking was absolutely rampant at my school, and I don't think I'm alone. Don't get me wrong, some parents just buried their heads in the sand, but unless you're giving them a breathalyzer when they get home and severely punishing them all the time it's pretty hard to prevent.
Yes, but when I go to the grocery store, U don't buy alcohol or cigarettes (because I don't drink or smoke), and no one cards me. Even if I never accessed a single site like the ones being described, and despite there being no kids who have access to my devices because I don't have any children, according to these laws every OS I install is required to force me to provide proof of my age. That's a huge escalation over any of those other checks, and I'd be similarly against any check that required anyone to present id to literally enter a store that happens to sell alcohol or cigarettes.
(Yes, you might get carded before you can go into a bar or a club, but we're talking about every possible device that can connect to the internet here; that's a lot closer to the grocery store than a bar or club terms of how much of a staple this is for most people's daily lives at this point. Cutting off my ability to access to my bank account, contact doctor, or pay my bills should not be something that should require additional steps because my devices which no children ever used could theoretically be used for a child to try to watch porn).
> but we're talking about every possible device that can connect to the internet here
I agree these proposals are garbage. But if everyone who can credibly say that is busy trying to block any age gating, this is what we’re going to get.
> But if everyone who can credibly say that is busy trying to block any age gating, this is what we’re going to get.
I'm certainly not busy trying to block a bunch of hypothetical policies that no one has proposed when there are garbage ones that are literally getting pushed right now. It sounds more like too many of the people who recognize the harm of this policy are too busy trying to claim that the burden for coming up with a non-garbage policy should be on the people who fundamentally disagree with that framing.
Unbound DNS if compiled with --with-libnghttp2 can listen for DoH and your Unbound/Pihole can forward to any destination you desire. This is what it looks like on my firewall:
# https://doh-int.mydomain.net/dns-query
interface: [ip of lan port]@443
interface: [ip of wifi port]@443
https-port: 443
http-max-streams: 220
tls-service-key: "/etc/unbound/keys.d/unbound_server.key"
tls-service-pem: "/etc/unbound/keys.d/unbound_server.pem"
Null routing the open DoH resolvers is just having a startup script that reads a list of all their IP addresses and
ip route add blackhole "${IP}" 2>/dev/null
People will argue that DoH can run on anything which is true but all the major resolvers will always use dedicated IP addresses as to not risk blocking CDN end points.
If the childs account is not able to gain admin privs then their ability to change settings can be disabled.
OK but we're talking about a general social problem (parents understandably don't want their kids corupte dby adult stuff, and some adult services vendors are unscrupulous but the internet makes it easy for them to hide.
I personally think this current version of the legislation is a good compromise. Tech workarounds are fine for the few of us that understand the relevant technology (though I have never bothered to compile DNS in my life and have no plans to do so in the future), but they are simply not practical for most people. Every time I hear someone suggesting this sort of thing I find myself tempted to say 'why worry about legislation? If you don't like what it mandates you can just write your own operating system.'
Of course this would not be helpful because writing your own OS is extremely hard beyond classroom/toy examples. And likewise, tech workarounds and even parental controls are hard for most consumers - partly by design. I have an xbox console and have been trying to figure out why it keeps freezing on certain apps for months now. I suspect a telemetry problem but it's just a guess, there isn't really any way to look at logs so it's a trial and error process because most consumer hardware/application vendors want their products to be black boxes.
> I personally think this current version of the legislation is a good compromise.
I don't think it is a good compromise. It seems to cover the wrong use cases.
My use cases have nothing to do with children on any level. Why would I want to submit to government restrictions? That makes zero sense.
It's as if the right-to-repair-movement would suddenly be undermined by a lobbyist advocating how restrictions are great. Or Jackie Chan suddenly praising the sinomarxist mono-party.
I'm sure than intelligent person like yourself understands that a lot of voters have kids and prioritize feeling that their kids are safe, even if those feelings are not always grounded in rationality. Most people shy away from complexity.
Yes, but equally so, some intelligent voters (who might've moved out of CA by now, as moving might be the best way to solve that disconnect) might also believe that we should be living in a Republic (and the government should not impose majority-favoured restrictions to the detriment of minority) rather than unrestricted Democracy. .
Teens for sure bypass all restrictions. Teens are young adults. My suggestions are for small children. Once a small child evolves and adapts to their surroundings, they too will one day bypass things. Reward them when they do this, it means they're smart and you did a good job.
It is trivial for a parent to gather materials for the kids without exposing them to billions of strangers/companies with who knows what intent toward them.
Here we talk about use cases for EVERYONE. I don't see how your use case is fine for me, because I personally do not agree with it on any level at all whatsoever. You believe in restriction. I don't. There is no common ground here.
> It's not realistic for me to be watching over their shoulders 24/7
Is this your job? At which age will you stop monitoring them?
> what can I do to keep them away from stuff 99% of people agree isn't for children to see
99%? Where do you get those numbers from?
Besides, what stuff anyway? Even then the issue isn't about your kids. It is about laws for EVERYONE.
Support getting rid of Citizens United and support your representatives to support enforcing antitrust.
This is the main problem that needs to be addressed. Everything else is just a byproduct of it. If you support the by product of what was created by conditions that are not being address, you only make the problem worse.
That's an interesting problem. Even if you have full control over your children's devices they can still simply toggle the DoH feature back on unless you do complicated enterprise style device management things.
However DoH isn't obfuscated and in order to operate the list of resolvers that firefox uses must be published somewhere. It follows that you should be able to filter the major DoH providers at your gateway.
> what can I do to keep them away from stuff 99% of people agree isn't for children to see, without something like this?
The better question is "Why do I need to give up privacy on my devices that no children ever use and are used for all sorts of mundane things that are entirely unrelated to what you're trying to protect your children from to solve this problem?" The solution being proposed here is to require ID checks at the OS installation level; this would be like requiring me to flash my ID when I walk out of my house because kids would have to go outside if they were going to try to buy alcohol.
How do you propose doing age restrictions for social media?
These are broadly popular. (And the evidence supports them.) They are happening. So the question is how to do it best. The project for reversing the consensus isn’t worthless. But it’s a long-term project that will have to bear fruit after these restrictions go into effect, if ever.
Voters are collectively deciding for all of our children. And there are absolutely group dynamics that require cooperation. It’s why rich communities ban phones in classrooms while in poor communities, the one family that tries doing it alone is probably going to be less successful.
Again, I’m not saying you’re fundamentally wrong. Just that this debate has been had and the polling is massively in favor of bans for under-14 year olds and strongly in favor for under-18s. (And to the degree I’ve connected with electeds, the folks calling in and writing were almost 100% one way. The civically-engaged electorate is practically at consensus.)
we are not collectivist/communist country to have a "muh gubernment" rule and dictate over every little thing.
I want government bureacrats, empowered by the stupid median voter, to be as far away as possible from things that I (and any other parent) are perfectly capable of solving by ourselves.
There's also broad popular support for raising taxes on millionaires, legal access to abortion, and cheaper healthcare, all of which are at least as important as the issue of kids using social media without restrictions. If the premise is that we should solve them with whatever solutions we can come up with unless everyone agrees on something better, I'll look forward to the upcoming laws that tax capital gains the same as income, enshrine a woman's right to choose, and to establish Medicare for all. When those all take effect, I'll accept your solution to mandate ID checks on every device I own, but until then, this line of argument is nonsensical.
The idea is broadly popular but the second you start asking about implementation details (ie showing your ID to post on the web), the actual approval percentage tanks down to the single digits.
But you knew that which is why you construct this rhetorical motte-and-bailey about it being "broadly popular"
> the second you start asking about implementation details (ie showing your ID to post on the web), the actual approval percentage tanks down to the single digits
Source?
> But you knew that
I genuinely don’t. I don’t think many electeds do, either.
The playing field is currently lots of angry non-technical parents looking at Silicon Valley leadership not doing anything remotely reassuring when it comes to taking care of their children. And then a good fraction of them being drawn into a proper pantheon of idiot conspiracy theories. (They’re really stupid.) I would love to see polls considering implementation details because that would at least imply somebody is thinking of them.
Right now, honest answer, I don’t think anyone in government is. Electeds see an easy win—or more accurately, a patchwork of angry, mobilized voters they can scoop into their election-year campaigns with a rushed-out bill that pins them to the issue but which neither they nor those voters really have the technical chops to parse.
Best case, we get tripe. Worst, the process gets hijacked.
A lot of us who grew up pre-social-media agree in principle.
What it fails to account for is that today's internet is qualitatively different from the pre-social-media, pre-smartphone internet. The vast majority of the internet audience, too, is qualitatively different. Incentives are misaligned for an average parent who might want to keep a tight leash on smartphone internet access for their kids, when attempting to do so will generate fierce opposition from their kids and leave them socially out of the loop.
In some countries they scan you ID and likely keep it some database when you buy drugs or enter bars or clubs. In others they just look at your ID card if you don't look old enough.
The first example is bad, the second is tolerable.
But the reason most kids don't smoke is that the parents and the teachers instilled in them that it was bad. If a kid wants to smoke or drink, they can surely get an older friend or a friend of a friend to sell them the cigarettes or alcohol. Anyone can buy 20 bottles of hard liquor and 50 packs of cigarettes, sell them to a 15 year old who can then sell them to their friends. That doesn't happen often not because a surprise police raid will show up and bust the seller but because there isn't enough demand. If there is demand from the kids and the parents don't care, kids will get their hands on drugs. Maybe not 9 year olds but certainly the teens.
> But the reason most kids don't smoke is that the parents and the teachers instilled in them that it was bad.
Big honking "citation needed" there. I think it's far more likely that laws against advertising to minors, and tightening enforcement of prohibiting the sale to minors, is what did it.
On top of it all, smoking has decreased among adults too. Part of that is certainly cutting off a big chunk of the teen-to-adult smoking pipeline, but part of it is also just that adults don't think it's so cool anymore (and "going out for a smoke" is no longer a social or even professional activity), and are more aware of the health risks.
Well lack of age verification definitely isn't fixing anything either so what's they play here? We all just collectively as a society just shrug like oh well, no fixing any of that?
No, we should take measures that actually address the problems that exist. Problem numero uno: the Big Tech companies are creating systems and digital environments that are hostile to everyone (of which children are a subset), compelling everyone to use them, and punishing those who attempt to get away. We cannot fix that by merely dictating terms, especially if those terms are such that only the Big Tech companies themselves could possibly know enough to enforce the terms.
Ok we might be in violent agreement here but so far I've yet to see anyone put forth anything like a serious plan to dismantle Big Tech, which clearly indicates that "triage legislation" half measures are the only thing currently on the table. I see little sense in letting perfect be the enemy of good.
https://airesistlist.org/ (currently down: see the Internet Archive) has links to several concrete projects, including https://di.day/en (see also, https://european-alternatives.eu/, https://switching.software/). The IndieWeb (https://indieweb.org/) and the Fediverse[1] are both movements to take back parts of the internet. We can all make small changes in our lives: what would you do, if you refused to acknowledge the existence of Big Tech, and needed to choose another approach? And can you do this, in practice?
Low-tech Magazine (https://solar.lowtechmagazine.com/) has enough articles to publish a thematic book, “How To Build a Low-tech Internet?”. There are other books with concrete proposals: pretty sure Cory Doctorow's published a few (Chokepoint Capitalism, also by Rebecca Giblin; Enshittification; possibly others). You can read these if you would like. But the important part is using and maintaining credible alternatives, reducing both our dependence on and support of these companies.
[1]: although more work is needed to reduce the addictiveness / increase the user empowerment of Fediverse UIs (which are largely modelled on the corresponding Big Tech social media systems): websites are still the way to go, if you can.
It's also illegal for minors to watch adult movies. It's already illegal. Age verification is just an additional step that won't stop minors that really want to watch porn, while creating a 1984 style database of people and their sexual interests.
This is correct. It is not the government's job to raise our children. The more we ask the gov't to do that we should do, the less power we actually have. Some will say this ship has sailed, well, I say it's not too late to sink it.
I am sick of these "government bad" takes. They lack constructive suggestions, like your "sink it" nugget, they lack decent problem descriptions, as if anything after the sinking (likely private governance, aka feudalism) is immune to the ills of big-gov, and on top perpetuate reductivist arguments as if any kind of restrictions of freedom is by definition bad.
This broad rejection without good reasons is borderline sociopathic. ... and parental control is not the gov raising anyone.
What's really wild is 9 times out of 10 when you back a crypto-libertarian into a rhetorical corner far enough to get them to drop their pretenses what you're left with is "OMG YOU ARENT MY DAD" is, at least in their mind, a cogent political philosophy.
Your post says far more about you than libertarians. Remember, every time you give the government a power, you are creating an avenue for corruption and by design putting someone who probably isn't qualified in charge of decisions they lack the experience to make reliably. There you go, a simple argument that increasing government power has a drawback that you never consider. And that's why you post says more about you than anything. Such an extreme position is impossible to defend and anytime you try either a) the person you are debating isn't very skilled at debating or b) you are just being stubborn and ignoring facts and arguments you don't like. I suspect its B.
And every time you remove legislation you open up entire new vistas of corporate depravity and as the last 40 years have comprehensively demonstrated, "market forces" are not a viable replacement for legislation. Increasing government power is a liability only and solely when folks make a habit of electing incompetents and the corrupt. Governance as a concept is fine, what you're actually arguing for is better politicians.
"telling" is a really curious euphemism for forcing volunteer Debian developers at gun point or they'll get thrown in jail. People in recent history seem to have forgotten that this is how governments enforce laws. If it was not, why would anyone bother obeying the laws if they didn't like them?
Governments are dangerous monopolies on force and the use of that force shouldn't be casually tossed out like candy at a parade on crap like this. If it doesn't matter if you lie, what's the point of even doing this, to prove that we're insane? Or is it the pretext for requiring a remote server id carding service in the future under that guise? Keep driving down this road and you end up with an end game that looks a lot more like North Korea than a free society with limited government.
The law defines it as a product quality issue. Meaning you can return it for a refund and a company that keeps selling broken products may be ordered to recall them or to stop selling them until they're fixed. You can't go to jail for selling broken products, and this doesn't apply to free software since it's free and has no warranty (which is only allowed because of the fact that it's free.).
Do you think the rule that children's toys can't contain lead is equivalent to living in North Korea? That's the same kind of law as this one.
You also have a lot more flexibility to negotiate on product quality. If you have a good reason why you can't meet normal product quality standards because your product is sufficiently different from the normal products in that category, you can usually put a prominent warning label on it to cover your ass and then you're fine.
> The law defines it as a product quality issue. Meaning you can return it for a refund and a company that keeps selling broken products may be ordered to recall them or to stop selling them until they're fixed.
And if they refuse to do all of this and resist, what happens to them? If you want a sample, stop paying your taxes, stuff your money under your mattress and see what ultimately happens. Just because our government is slow, stupid and incompetent doesn't mean that they don't use the same mechanism of action.
I would love to get into why looking at porno is not even in the same universe of danger as lead poisoning, but I've spent weeks trying to explain harm comparison to people that genuinely think high schoolers using social media is the same thing as them using cigarettes and heroin and I'm just exhausted.
And I am sick of people constantly wanting every single aspect of life regulated by the government. You guys need to understand that government isn't static and society changes. The rules you come up with today are going to get in the way in unexpected ways tomorrow. Regulations should only happen if you can demonstrate that it substantially improves things in a measurable way.
Eg "if you ban cellphones in schools then average test scores (on tests like PISA) will substantially improve". Or something else like that.
>This broad rejection without good reasons is borderline sociopathic.
It's sociopathic to not want the people in control to constantly make up new arbitrary rules? I guess we just need a few more Patriot Acts and Snoopers Charters.
"And I am sick of people constantly wanting every single aspect of life regulated by the government." We're carting that strawman out again? What folks mostly want is for private industry to collectively display something approximating business ethics and maybe self-regulate away from objectively harmful/predatory behavior. The last few decades have very clearly demonstrated that there is literally no bottom to private industry depravity unless one is literally forced in place by legislation.
The current form of government and the last administrations have allowed this environment to exist. We don't have antitrust regulation being enforced and citizens united is still in effect.
This is only going to cause things you describe to get worse and the U.S. government is complicit in this because we have a two party system that works directly or indirectly for the establishment.
I'm not sure if you are encouraging more government intervention, but its clear this is not working. Its like going to a criminal gang and asking for security while they ransack your community and charge you for it.
That's a problem with the politicians folks have chosen to elect, not an issue with the concept of governance. And while I agree with your analysis proposing we all wait patiently for "market forces" to resolve whatever ludicrously unethical bullshit industry is up to at any given time is also clearly a non-starter. So now what?
It's more than just politicians we elect. There is a systemic problem that needs to be adressed before we can elect candidates that represent our wishes. Citizens United needs to be abolished. Money needs to be removed from politics and we need enforcement of anti-trust laws.
Governance only works when it represents the people, that is not what this government does right now and no amount of electing the right candidates is going to fix that until we have those two issues addressed.
Enabling government spying under the guise of "protecting children" doesn't put private industry in check one bit.
It's like saying we should install Flock cameras everywhere so that we can protect consumers from buying harmful products. Corruption and mass-violation of human rights is all that's ever going to come out of it.
If the goal is to stop predatory companies, why not do so? Oh right, because that was never the goal.
And how exactly do you validate your age? Government-issued IDs. Attaching government-issued IDs to every digital activity is the surveillance apparatus's wet dream, and it's not like these motives are hidden. So between this and equating opponents of this policy with cryptobros in your other comment, I have a hard time believing your accusation of bad faith as anything other than good old DARVO.
It's also the tired old argument that's constantly raised by encryption ban/backdoor proponents too. How many times do they have to be debunked, ugh.
If you're against the EFF on these kind of issues, it's typically a good time to reevaluate your position.
Friend, we have a fair amount of suggestions ( including constructive ones! ). Do you know why? Because we mostly know how to make education decent for individual students like:
- keeping class sizes small
- keeping class within similar development range ( AP with AP. short bus with short bus )
None of it is a secret, but government can't (edit:or won't) make it happen. Hence regular people just doing the best they can within the system at their disposal.
I know people who will adamantly insist that keeping classes within similar development ranges is harmful and will vociferously reject any such proposal, up to and including things such as "gifted" schools and the like.
It's why some schools in (iirc) California did away with higher maths like calculus entirely.
Sadly, it seems there's nothing actually common about common wisdom.
I will admit that I never heard a serious argument from anyone that did not rely on issues not related to individual student's education. If you have any materials on those, I would love to read some of it.
Montessori advocates for mixed age classes where more advanced help teach the less advanced, as the teaching itself solidifies it in the more advanced student's mind. Not sure if it is valid. But it is something with studies and meta studies that may have been done well or poorly, not just an aesthetic choice. I think Vulcan style training pods driven by AI like khanmigo will end up being better education than the vast majority of students will ever have access to in person. Or consider it the realization of "a young lady's primer" from diamond age.
Yes, that is an issue. There isn't much separation until age 11 or 12 and even then it is usually at the same physical facility. Is there good data on how to handle that? Don't want to make irrevocable decisions too early, seen lots of people good at arithmetic that can't do math and the reverse almost as often. Then is it bad to have socialization absent between different intelligence levels? Most public schools in the us seem to intentionally leave no time for critical thinking or actual history lessons (as opposed to propaganda).
There is separation, at least here in the US, where basically all Montessori schools are private and can choose who to take, so the extreme lows aren't present. The other aspect is kids' abilities are masked by how fast kids grow and change; I'd guess a 20th percentile 4-year-old will be better at things than a 95th percentile kid 365 days younger, so the mixed ages still helps both, because teaching helps someone learn and the younger hasn't learned the thing yet. Where when you get to teens, the more capable student in, say, grade 9 will be able to learn calculus so much faster than a less capable student in grade 12, either you make the former waste most of the class repeating concepts they already solidly understand, or you end up leaving behind the slow learner. You're hurting one, the other, or both by mixing them. But that's doesn't mean they can't both be in art class, or band, or shop together.
Socialization doesn't have to solely occur in an academic classroom.
I am categorically not a "government bad" person. There are things that only government can do to help society and it's an important institution. However government shouldn't take over things in your household. I feel for the government to do a thing it should have to demonstrate that the state has an defensible interest. Gay marriage? Gov't has no business in marriage. Gov't demanding age checks in apps or in electronics? No, gov't doesn't need that.
> like your "sink it" nugget, they lack decent problem descriptions
Let me be clearer then: The legislation has passed but it is 100% possible to repeal that law. And it should be repealed, and we need to not let up pressure on California until it is rescinded. It was a bad law that was not thought out at all and fails to solve any problems.
I'm not worries about corporate feudalism and app age checks.
I'm not sociopathic, you're just making broad assumptions.
I dunno, "government bad" seems like a pretty reasonable default. Governments typically have a high amount of corruption and are generally unhealthy organizations. It doesn't make sense to delegate more responsibility to an entity with such structural issues.
I'm not a libertarian; I just don't get why I should have to prove my age on every device I own regardless of what I access online when I don't have kids. Parental controls already exist on devices, so that's not really what this is legislation is proposing. I don't have a concrete solution because I don't even agree that "theoretically we don't know for sure that this device couldn't be used by a child to access pornography" is a problem that it's my job to solve as someone with no kids and plenty of mundane uses of the internet like paying bills, contacting medical providers, filing taxes, etc.
On the other hand, I know several "home-schooled" people [0] who literally can't even read and later married people more than twice their age or had other serious deficiencies in their life potential. The government can probably step in a little more here and there.
[0] I also know home-schooled people whose parents are far better than any teacher I've ever had and whose education and achievements reflect that obvious fact. Home-schooling itself isn't the issue, and I'd prefer that it remain possible.
Public education is extremely different from age checks in apps. Yes, homeschooled people are generally really dumb because humans are not born with the knowledge of the world or how to teach it. This is different from California telling Debian to ask for user ages.
I read one of those papers. Only between 10% and 25% of homeschool families completed the test. And that's of families that could be located because they had previously interacted with major homeschool testing companies; there isn't a national list of homeschooled kids and many parents homeschool precisely to avoid standardized testing. Plus in many cases the parents were the proctors. This is hardly a robust finding.
Thanks for investigating deeper than I did. I don't know where else to look. However, unlike the post I originally replied to, every homeschooled adult I know is doing better than average, but anecdote vs anecdote isn't helping.
I follow some homeschooling communities as a way to learn how to supplement my kids' schooling. There are many interwoven communities:
* religious families who don't want their kids exposed to the secular world
* families who don't trust adults to watch their kids and wouldn't ever consider public school, summer camp, sleepovers etc.
* families whose kids aren't being served by the public school system.
In all three scenarios (but especially in the first two) there is a sizeable population of parents who know their kid is several years behind grade level, but they tolerate it because they think kids learn at different paces. Or that it's fine for a kid to love one particular thing (cooking, machine repair, art) at the expense of a well-rounded education. And that's not even getting into the 'unschoolers' who treat never opening a textbook as a point of pride.
If you're well-educated and run in circles of people like you then you'll find the homeschoolers who also value education. But if you expose yourself to a wider variety of people your conclusions may change.
> On the other hand, I know several "home-schooled" people [0] who literally can't even read and later married people more than twice their age or had other serious deficiencies in their life potential. The government can probably step in a little more here and there.
Anecdotes like this don't help the case much when government schools in a lot of places "graduate" large proportions of their pupils who are functionally illiterate and innumerate. Then you get misconduct, bullying, abuse that goes on in government schools. Who should "step in" on the government?
> On the other hand, I know several "home-schooled" people [0] who literally can't even read and later married people more than twice their age or had other serious deficiencies in their life potential. The government can probably step in a little more here and there.
Back on the first hard, I'd argue that most of those people might have benefited from having more access to the internet, as it sounds like at least part of the problem was that they had severely limited experience for how to navigate the world outside of small amount their parents allowed them to be exposed to. I'm on board with the government being involved in ways that are beneficial, but "make anyone using an internet-connected device plug in their ID first" just feels like an absurd overreach for what it's trying to solve.
Let me be very explicit so we're not dancing around the topic:
The potentially all-powerful government shouldn't know:
- what vices a person has
- what religion a person has or doesn't have
- what porn you watch
- what alcohol and drugs you buy
PERIOD.
All of these things can be exploited. To control jobs, to control finances, to extort influence, to shape ideology, etc.
The government shouldn't be able to catalog those things in a database for later misuse.
The government shouldn't be able to install friction or barriers that make it easy to cordon off and kill these things at a later time.
The "think of the kids" argument can go to straight to hell. Nobody's having children anyway.
This is a very real (not logically fallacious) slippery slope right into the pages of 1984.
It's not about kids. It's about control over society as a whole. They're going to force you to use your ID to access the internet, force you to use an approved device, and the minute you step outside of allowed behavior, you'll be punished.
Shackles and telescreens are coming, and they're using this argument to build it.
Nobody here disagrees. What should be the case is that sites are broadly required to flag what kind of content they serve so parents can choose to exercise their own level of desired control.
To me an all powerful government is one that has all the information the user just listed, because governments are by definition the most powerful force in our countries.
Private companies should also be regulated with regards to data sales of private information, yes.
If I recall correctly, in Pennsylvania the government does own the shops that sell liquor, and most states run lotteries, so there's certainly precedent for governments being the ones in the vice business.
That's besides the point though because this legislation doesn't check people's IDs when they're trying to purchase porn or alcohol, but as soon as they walk out the door, and if they refuse to show it, they have someone following then around even if they just go to the ATM and to the doctor.
Okay, but no kids live in my house, so why should there be a law requiring my ID to be checked even without knowing what I'm going to on my device? I don't get carded at the grocery store when I walk in because there's a chance I might buy alcohol.
Earlier today there was a large thread on HN about the golden age of child rearing, from time immemorial to about two decades ago, when children started getting sent home and parents got a stern talking to from the police, just for owning a pocket knife or biking home alone.
We really can't have it both ways, that every failure of the child is blamed on the parent for lapsing in their almost totalitarian oversight, while also idealizing the idea that children must make their own mistakes and gradually growing into responsibilities and self-governance. Except having access to the Internet, apparently.
Taking a step back, this all smells like madeleines and a yearning for the good old days when everyone rode bikes and nobody owned smartphones. That's not really a productive stance on anything.
(If you would ask me, and I'm sure nobody would, I would think that there is a sort of trade-off here but with a clear answer: Make clear restrictions about buying cigarettes, alcohol, abusive content and extreme porn. But these restrictions aren't meant to be technically perfect. It's ok that some kids will learn to lift the limits and explore what is forbidden. At least then they would know that there is some reason society collectively considers these things off-limits, and that they soon will be in a mistake of their own making.)
> The only device mandates that should be taking place is for the default installations of web clients should be checking to see if parental controls are enabled. This only impacts the major browsers. An intern at each browser company could add this check in minutes. If they are enabled and the person logged in is on a regular account (not admin or power user of sorts) then the base installation of web clients must check for an RTA header [1]. If present, prompt for a override password and also give the option for the admin to approve-list the domain at that time. That's it. Not perfect, nothing is or will be.
It's useful to contrast this with the various device-based mandates that have been created in order to get a sense of what legislators seem to be trying to do. With that in mind, a few points:
* What you are proposing allows parents to opt in via parental controls, but age assurance mandates (both device-side and server-side) tend to require positive action to enter unrestricted modes. In some cases (CA AB 1043, for instance), this is just a matter of entering your age. In others, you actually need to demonstrate your age via some technical mechanism.
* While many age assurance mandates focus on adult content, which is primarily consumed via the Web, others (e.g., Australia's Social Media Minimum Age) focus on social networking, which is primarily consumed via apps, so anything that is Web only will not be effective.
* Site-level granularity isn't really fine enough in some cases. For example, the New York SAFE for Kids act prohibits certain behaviors such as algorithmic recommendations when a user is a minor, but doesn't require blocking minor usage entirely. It's potentially possible to implement this with something like RTA, but it would have to at minimum be at much finer granularity.
None of this is an endorsement of age assurance techniques; I'm just trying to help flesh out the situation.
> All legislation regarding age verification must revolve around this otherwise people must reject it as an abusive form of tracking and privacy invasion.
It's a bit late for that, given that around half of US states already have some kind of age assurance mandate.
It's a bit late for that, given that around half of US states already have some kind of age assurance mandate.
Perhaps late to solve this globally but parents can still install parental control software if they so desire and can still intervene locally to prevent sharing data with 3rd parties. At worst this means small children might not get to visit social media and other assorted sites and I am fine with that. I think a number of parents would be fine with that as well.
Sites can voluntarily label as some do. It just means that parental controls would have to default to blocking everything until approved and while sub-optimal maybe that's what people will have to do in order to avoid the evil pattern of sharing data with all the websites that will ultimately leak, or "leak", be sold, stolen, etc... Good parents will not participate in the evil patterns of sharing their children's personally identifiable information.
When the PII of children is ultimately shared with evil people the children once adults will resent their parents for not protecting them.
- To all parents here, your children have no idea what risks are out there including devious companies that want their data. They will one day be adults if all goes well. Protect your children as corporations and governments will not. They will thank you when they find out all their friends data was shared, leaked or otherwise abused forever.
Certainly parents can install parental control software, but what does this have to do with children's PII being shared with sites?
Just so we're on the same page, the way AB1043 works is that the OS determines the user's age and then shares the age bracket with apps. No PII is shared with sites (this is not to say that the age isn't sensitive, but it's not PII as usually regarded). Is your concern here that sites get access to children's information because children visit certain sites regardless of legislation? That's a real thing, but it seems mostly orthogonal to age assurance.
Certainly parents can install parental control software, but what does this have to do with children's PII being shared with sites?
The parent can block or just never approve all the sites that require PII.
but it's not PII as usually regarded
We will never agree here. All the companies I worked for financial considered any attribute of the person to be PII, even their IP address. We were audited very strictly on this. If a users age was disclosed to a third party without their written consent that was a contract violation and came with severe monetary penalties. Parents should expect this to be the minimum standard. It's their children, not the corporation or governments children.
Thanks for your explanation. I understand what you're talking about, but this all just seems to be entirely orthogonal to age assurance mandates, which are largely about controlling which content and experiences minors engage with, in many cases regardless of what parents want.
Again, this isn't an endorsement of these mandates; I'm just saying that what you're proposing here doesn't address the objectives that policymakers who are in favor of these mandates are trying to achieve.
doesn't address the objectives that policymakers who are in favor of these mandates are trying to achieve.
Oh trust me, I get it. They and I will never align. I know I am beyond beating the dead horse. It's gone from bone dust to micronized dust to sub-atomic particles to sub-quantum particles at this point. That poor horse will never be forgotten. Perhaps it is an illness on my part but I will find a way to bring this up every time until the year 2150 after which point this will be the least of anyone's concerns.
I think the header/metatag is designed poorly. The RTA proposal is that every operator of every site must verify the content and add the header to mark the site as "safe" or "unsafe". This is unnecessary burden that they have to bear if this proposal is given a green light and this is wrong.
Instead, the default should be, that if there is no header or it cannot be parsed, then the content is unsafe. And if there is a header, it describes the page rating, like what kind of dangerous content it may contain. The header may be added to any displayable content like HTML, text, images, audio or videos, but not to machine-readable content like JS files or AJAX responses.
So only those who wants their site to be accessible by minors, have to add headers. For social networks, the user might have an option to mark his content as "safe".
This means that with my proposal existing site operators need not to do anything to mark their sites as "unsafe" - all sites are "unsafe" by default. This means that millions of site operators need to spend 0 dollars to adapt their sites. How great is that?
The browser on a device with parent mode, should not allow displaying any content which doesn't have a header or that is marked as unsafe, or that contains header with invalid value. The parents may whitelist some sites.
There should be a reponsibility for intentionally marking unsafe content as "safe". We should also think what to do with foreign operators, intentionally putting invalid headers for unsafe content. Maybe they should be added to some kind of blacklist that the browsers would periodically update.
Search engines like Google could work by default in "safe" mode, but add "unsafe" header if the user wants to turn off restrictions.
> If a site is not adding the RTA header then progressively fine them into oblivion.
I think my proposal is better because it requires only fining those who intentionally misrepresent content safety.
For what its worth this header has been around for a very long time. It's actually the second iteration and much simpler than it's predecessor.
Parents today can accomplish what you are suggesting by installing parental control software and only allowing access to things they explicitly approve.
This can also be done via headers explicit blocking of all the things and was suggested in another thread. [1] Some people liked the idea.
The point is that it is unrealistic to expect millions of people to mark the content. Also, the header is better than the metatag because it can be added to images, videos and other non-HTML content as well.
The header (for videos and other) was mentioned in [1]. I agree that is the way to go.
Adding a header to a web server or load balancer or app server if done globally can be done in a minute or two. Maybe 5 minutes for the intern not counting QA testing.
But you are right, the inverse is easier. I like that too. That was debated in the other recent thread.
I tend to agree - making folks intending to interact with minors comply makes more sense.
That said, outside of the merits of this approach, I am dubious of any actual implementation given 2 points.
1) Protecting the youths will always be a leaky bucket. With disadvantaged youths possibly more at risk. Those exposed to non-compliant parents ("cool" parents who are ok with sharing unsuitable content) or lacking strong parental involvement, likely won't benefit a great deal from any implementation.
2) Anti privacy social networks stand to gain the most from targeting ads utilizing signals from most child safety acts. They also might be able to reduce some costs from moderation if they can make it someone else's problem. I'd argue the net social impact from these social networks is likely both more normalized and strongly negative for our youths than any smut.
On the balance I'd say we are better off investing our energy in other places.
> "cool" parents who are ok with sharing unsuitable content
Or simply parents who won’t agree with the government on what is suitable for their children.
We already have parental control on all mainstream operating systems, why cannot this simply be the responsibility of the parent as are so many other things regarding what children do, watch, eat etc?
Because what parents have access to now is extremely ineffective unless they prevent their kids from going outside or going to school. Right now the onus is entirely on parents too keep their kids off the Internet equivalent of smoking cigarettes, and it’s a losing battle. What we’re looking for is for the liability to shift off the parent and onto the people intentionally communicating with children. Frankly the proposal above was very reasonable. If you don’t want to intentionally communicate with kids then do nothing and you have no liability.
I want to intentionally communicate with kids, because kids have always been valued members of the online communities I frequent. Right now, it is easy for social media giants to exploit children, easy for child predators to get access to abuse children, and increasingly-difficult to maintain online spaces in which children are allowed to safely exist. That is surely not what we are intending to accomplish, here.
We don't have parental control on any mainstream operating system that actually works. In fact, California just removed the law that said operating systems have to have working parental control.
Again, RTA header doesn't work because it's a blacklist, not a whitelist, and also because it's only granular enough to say "this is a porn website" and nothing else.
Again, RTA header doesn't work because it's a blacklist, not a whitelist, and also because it's only granular enough to say "this is a porn website" and nothing else.
None of that is true. Not even close. It will work if there are laws with big teeth as the government can have contractors that scan for the header. Header missing? Adult content? User provided adult content even if it violates the rules? Well darn, there goes 10% of revenue. Also it is not "this is a porn site". RTA stands for restricted to adults. That can include literally anything that is not appropriate for small children including but not limited to social media, forums, gallery sites meant to be SFW but users content is not pre-moderated meaning people can see it before a moderator does. What Restricted to Adults ultimately means will depend oh the laws behind it.
That's incorrect. The existing RTA header is for marking porn as porn.[1][2] (In case English isn't your first language, "adult website" is a euphemism.)
An actually useful standard would need to be much more granular, and be designed as a whitelist not a blacklist, as I and previous commenters said.
Yes, exactly, this should be really simple as a foundation: by default the Internet is for adults. All of it. Where it's desirable for things to be available for kids, create the economic incentive and easy tools for parents to use and run on a white list, not a black list.
I'd actually go somewhat further though and ask whether it's a good idea to even do this via web pages at all. We have a great potential system for this already: DNS. Do something useful amongst all the ridiculous vanity and spam TLDs for once and set up a ".kids" gTLD, or ccTLD for that matter so that different countries can set their own regulatory standards naturally (ie, .kids.us, .kids.uk etc). Domains could also be used for some broad buckets for people who don't want to drill in, ie, .1-6.kids, .7-12.kids, .13-17.kids, or whatever is deemed appropriate, but simple age brackets that would offer some sane defaults. 1-6 could simply not allow any ads, user generated content or algorithmic feeds whatsoever for example. There are a lot of knobs to turn. And then at the registry level it can be ensured from the get-go that anyone getting a .kids domain is fully identified, located in the country in question, has valid ID, has specific credentials or is an accredited organization, or whatever other criteria makes sense.
But ultimately the point would be to create something that is built right from the ground up, and in turn that doesn't interfere with what has already been built at all. Something that can also be worked with at the gateway and thus cover every device on a LAN, and for that matter can easily be plugged into the vast number of powerful tools we have for working with that stuff. It'd be easy to put a nice UI on all this, even to make it higly automated. For example, have a setup wizard where you enter children, put in date of birth for each, and it'll spit out a password for each one. This then auto-provisions the network such that each kid has their own VLAN (password for PPSK or even wired connection) and is automatically limited to the domain groups of their age bracket, which then changes as their age changes.
Parents should be able to dig further in and get more granular with content categories, metadata for which could be required for anyone hosting a site within that domain, but I think there is the potential to make something both pretty bullet proof and pretty accessible, using existing tech stacks, and without impinging on the present internet at all including privacy and anonymity.
The vast bulk of the internet is child neutral. For example my church a web site, the bakery down the road has one, the local pro sport team has one. They're not designed "for kids", but kids are welcome.
Does StackOverflow need to register a .kids domain just so children might get answers to programing questions?
If my-bakery.co.uk and my-bakery.co.au both want to be visible to 16yo there needs to be at least kids.uk and kids.au.
Does OpenSSL.org or OpenSSL.com get to be OpenSSL.kids?
Sorry but duplicating the entire neutral internet domain space with yet another tld isn't a helpful approach.
That's the trouble though - those friendly neighborhood sites can generally be assumed to be appropriate for kids, but if we create the expectation that they must ensure they are appropriate for certain age brackets simply by virtue of being online, those sites will cease existing.
Instead of running their own websites, they'll migrate to a platform like Facebook. That way Meta handles the burden of moderation and the legal complaints for the inevitable moderation failures.
I surprisingly seriously disagree, and think you're perhaps missing a lot of the contention in this whole societal debate. The point is to give people workable tools with some level of agreed sane defaults they can make use of, tweak, or ignore entirely, without imposing any burden at all on the existing internet and its adult (or children with parents who wish it) users.
>The vast bulk of the internet is child neutral
First: by who's standards is one of the core questions! What's neutral to one parent may not be to another. You illustrate this with your very first example in fact, "For example my church a web site". There are religious parents (and no doubt atheist ones as well) who would quite strongly not want their young child to visit your church's website.
Second: there is a difference between simply wanting to be child friendly and taking on a legal obligation and liability to be child "safe" to some given standard. Parents would be perfectly free to whitelist whatever additional sites they liked, or to subscribe to lists that curated whitelists of various sorts, or to use other controls. But a politically significant number of parents clearly want assurance that their child will near-never (with actual enforcement mechanisms for failure) encounter something outside of bounds. Meeting that need requires either whitelists or the sort of restrictions that would wreck the current web (and probably still not work very well).
>Does StackOverflow need to register a .kids domain just so children might get answers to programing questions?
If the parents of said kids want it to, then yes? Why would that be a big deal? I'd be surprised if like most places SO doesn't already have piles of domains purely for defensive purposes, and as something nationally regulated I certainly envision such a domain registrar being dirt cheap (or even free, paid for by tax dollars) for domains. Given the context and that it'd be very much not open to all there isn't any need to worry about cost to dissuade scammers and such, they'd be prevented from ever registering in the first place. Rules around use of trademark, business names and so on could also be very strict.
>If my-bakery.co.uk and my-bakery.co.au both want to be visible to 16yo there needs to be at least kids.uk and kids.au.
Yes? DNS is not expensive. And again, parents don't need to make use of it. This would be for those who do, who are right now pushing for ID for everything. It's a safe default walled garden, but one with doors any parent can open.
>Does OpenSSL.org or OpenSSL.com get to be OpenSSL.kids?
Which one chooses to get accredited by a regulator or child protection organization with insurance and so on first? Why are you asserting either would even bother? Which one would be happy about having to verify ID of users right now?
>Sorry but duplicating the entire neutral internet domain space with yet another tld isn't a helpful approach.
Sorry but you haven't thought about this very clearly at all. This proposal is very explicitly a small subset of the entire neutral internet! Duplication is never something I suggested, rather the very opposite! The "entire neutral internet" is by default adult here, but parents would be able to allow children to browse it just as now. However, some are clearly unhappy with that, enough that we're seeing politicians respond with things that would be very bad.
The page having a simple rating assumes there can be one mapping from content to rating for the whole world. I doubt we can even have one for North America and Europe.
Come up with a few categories and let the browser/OS decide.
Websites by default are ‘true’ for every category, unless they specify.
Categories are, for example of some: nudity, sexual, violence, etc.
It doesn’t have to be perfect but sites will have to err on the side of caution.
We could even create an html tag <restricted type=violence> for example, and the browser can simply not render that portion of the page of the user has that type disabled.
And we could give companies a pass for best-effort categorization using tech to assess user-generated content, along with allowing users to flag their own content as “safe”
The goal should be to satisfy most reasonable governments. A neutral technical standard and an international organization to maintain the the ontology for content descriptors
Ah I was proposing the tag as another option - maybe a news article is fine for kids but the comment section is unmoderated. That way they could still read the article but not the comments
Better idea is just tell the server if you want to hide restricted content. Then it can make any changes necessary. Yes it's a fingerprinting bit. Not a new one, because they could already detect whether the restricted tag was rendering or not, anyway.
Maybe certain headers could be cryptographically signed. So like if your movie is rated PG by the MPA the MPA itself could sign a statement to that effect. Or a government could issue a social media company a license they could use to sign their pages as complying with some regulation and revoke their license if they don't comply.
That's a sorry attempt at an excuse. Companies are expected to collect ID and have related business logic that respects local laws but can't figure out how to tag their content? That's an utterly nonsensical position.
There's no reason a simple, standardized header can't be used to communicate any number of classifications simultaneously.
Edit: It occurs to me that if you oppose all age related measures then my above response isn't entirely fair to you. I still think it's an absurd objection but the comparison I made no longer applies.
Well fair enough. In that case we are actually in agreement. Let the end user (or network admin) sort out what is and isn't acceptable in a given context.
What we need regulation to provide (IMO) is a reliable way of doing that.
We don't need regulation, we need cooperation, analogous to movie ratings. A site could attest that they provide content ratings, and that attestation signed by an authority (MPAA). If they are found to have been dishonest about that, the signature is revoked (or probably easier, it's fairly short-lived and just won't be renewed). Browser makers (theatres) cooperate by only loading sites with a valid, signed attestation when the device's parental controls are enabled.
Sites can choose to have unrated content (adult movies) and those are only available on devices without an enabled parental control option (adult-only theaters).
But we already have that and it doesn't work. Sites don't bother to classify themselves. Whitelists are spotty and out of date. Almost nothing interoperates properly. My expectation given the scenario you describe is that business continues as usual with the vast majority of the internet thus being inaccessible when in "child" mode. As a result no one uses child mode and the vicious cycle perpetuates.
A solution would be browsers refusing to load any site that didn't provide such metadata, not just in child mode but in any mode. I suppose either Apple or Google would likely be capable of unilaterally imposing such a requirement as things currently stand. However I also think that's unlikely to happen on its own for various reasons. Thus legally mandating certain basic content classification categories in addition to an extensible standard protocol for communicating such metadata would (I expect) end the cycle. And rather than the government going after individuals the legislation could be structured to place the onus on mainstream browsers, OSes, and other client software to enforce compliance on their behalf.
But the expected result here is that parental controls continue not to work very well, parents continue not to use them (at least competently), and people continue complaining that something needs to be done. So I propose that we do something about that rather than sit around continuing to roll the dice on the next half assed turnkey authoritarian solution than an inept legislator fields courtesy of a lobbyist working for a megacorporation whose interests tread well into the realm of the blatantly evil.
We are seeking a solution to a social problem, not just a technical problem. If it fails to achieve most of the social goals, it won't be used and you get something worse. Welcome to the real world.
The standard OP is describing doesn't exist. So whether it "fails to achieve most of the social goals" is yet to be determined. Blocking unrated content seems like a pretty desirable feature to me. Why wouldn't that be one of the "social goals"?
It's a hard problem but the key is that it needs to be on the client rather than on the server, because that's what can have any information on jurisdictions, local regulations, religions, or general parental preference.
For example, it would be insane if every website and blog in the world to had to run logic to detect and prevent Elbonian males under 16 lunar years from seeing ankles except on Thursdays.
The problem with your proposal is that it's already the status quo. Various whitelists exist but service operators don't generally bother with these things. What you end up with is a largely unusable experience if you enable whitelist filtering.
The core problem is the lack of buy in. Unfortunately that likely needs to be forced. I think it's not unreasonable to legally require people to make a claim about the nature of what they are serving up. They already need to be aware of the legal status of what they're doing anyway so it hardly seems as though making such a determination should pose a burden when you consider that it's an alternative to either requiring ID, requiring the client send age bracket information, or other heavy handed interventions. The choice here isn't "the status quo vs a header" but rather "some other age related regulation vs a header".
An easy way to enforce this "voluntarily" (ie coerce) without sending government agents after every small time website operator would be to require that mainstream browsers and other client software (based on MAU or similar metrics) refuse to process content that does not send a classification header. Doesn't matter what the header says or what the status of the user account or parental controls or whatever else is, it has to send the header regardless or it will be blocked without exception. That would presumably trigger broad compliance with the relevant regulations.
The difference is one of redressing a concrete dysfunction. Libraries or the local bookstore or whoever aren't trying to sneak into your home, onto your child's school bus, into your child's classroom, while pushing various extremist publications purely for their own profit (ie "engagement"). We do in fact have zoning laws - I can't inadvertently encounter a strip club in a quiet residential area. Meanwhile it's commonplace for children to carry a network terminal around with them with which one can readily access the equivalent of things far worse than that.
What I've described does not restrict one's ability to speak freely. It is most similar to an impressum except it bears no identifying mark thus poses no hazard to anonymous speech.
Impressums cannot be required in the US, once again thanks to that pesky First Amendment. You may be mixing us up with Germany.
Mandates on how speech must be structured are a violation of freedom of speech, Constitutionally speaking.
“Redressing a concrete dysfunction” does not appear in the Constitution as an exemption to guaranteed rights, as far as I am aware. The proper remedy for this kind of problem is an Amendment, assuming you can get enough people to agree with your assessment.
You're just vaguely waving towards the first amendment. That's not a cohesive argument in and of itself.
By your own logic would online ID laws not also be a constitutional violation? Ditto for age bracketing laws such as the one under discussion here. After all, they both effectively regulate one half of the exchange necessary for meaningful communication (ie protected speech).
> Impressums cannot be required in the US
Yes but why can't they be required? My (quite possibly flawed) understanding was that SCOTUS previously established that publishing without attribution could not directly be outlawed, recognizing the ability to speak anonymously as an important aspect of political speech. What I have described does not run afoul of that. It neither restricts one's ability to speak nor provides for any form of attribution.
> “Redressing a concrete dysfunction” does not appear in the Constitution as an exemption to guaranteed rights
Regardless of either your or my personal opinion SCOTUS routinely makes exceptions to constitutional rights when a compelling need is presented and the remedy is sufficiently targeted. That said, I don't believe that what I described infringes on the first amendment to begin with so your point is doubly moot.
> By your own logic would online ID laws not also be a constitutional violation? Ditto for age bracketing laws such as the one under discussion here.
Now you’re getting it. Throw them all out along with the idiots who passed the laws.
> Yes but why can't they be required?
The Court has interpreted compelled speech to be almost universally a violation of the First Amendment, outside of the courtroom. I tend to agree. “Shall make no law” is a strong statement.
> SCOTUS routinely makes exceptions to constitutional rights
Prior courts. The present Court seems to be (rightly) rolling back both judicially-granted overexpansion of rights and exceptions to rights, although this is a slow process.
We have to stop relying on the courts to grant new rights and/or exemptions to rights. Passing unconstitutional bills and hoping for a favorable interpretation is clearly not the intended process, yet it’s become increasingly common.
We need to figure out how to pass amendments again or we are going to lose our republic. (It may already be too late due to an out of control executive and corrupt Congress, but that’s another matter.)
I don't think you're giving fair treatment to the complexity of the issue at hand. When SCOTUS came out in favor of anonymous political speech I do not understand it to have been on the basis of forced speech.
We require for example nutrition labels on food products. So clearly metadata of various sorts can be required for an interaction within the marketplace if there's a good enough reason for it. I'm not sure where that leaves personal blogs but it certainly applies to Amazon and PornHub.
The present court is rolling back some things but certainly not all. From the very beginning constitutional rights have never been absolute. One of the basic principles that comes up repeatedly and supersedes almost everything else is that the government must be able to carry out its duties. The contention is generally whether something is truly necessary for that and if so whether the law in question is overly broad.
> So clearly metadata of various sorts can be required for an interaction within the marketplace if there's a good enough reason for it.
Marketplace being the key word here. Interstate commerce may be regulated.
> I'm not sure where that leaves personal blogs but it certainly applies to Amazon and PornHub.
That’s the point. I also care about restrictions on smaller businesses and want to prevent regulatory capture, but personal/nonprofit/community sites must not be burdened above all else. They face enough challenges as it is. If a website or software project is noncommercial, their speech is not subject to regulation, Constitutionally speaking. What’s more, the Constitution has the correct take here—this is as it should be.
> One of the basic principles that comes up repeatedly and supersedes almost everything else is that the government must be able to carry out its duties.
Then you get the question, what are its duties? Enforcing unconstitutional laws is not one of them.
Regulations on speaking to children have ample precident. We rate movies and age-gate admittance, we don't allow children into liquor stores, strip clubs, or adult bookstores. None of those things violate the First Amendment.
“We” (as in the US government) do not do this. There is not, nor can there be, a law requiring such rating.
> we don't allow children into liquor stores, strip clubs, or adult bookstores
These are physical stores/venues, not written speech. “We” do not restrict authors from writing adult books that may or may not be seen by children, nor do we require that the books are labeled as such.
If you want to restrict speech, pass an amendment. That is the allowable path.
> Instead, the default should be, that if there is no header or it cannot be parsed, then the content is unsafe.
That's something the client should be doing. You can configure your own device (or your kid's) to have whatever default you want.
The actual problem is that classifying the entire firehose of user-generated content is precarious and uneconomical, so the default tag is going to be whatever minimizes liability. If untagged implies "unsafe" and "unsafe" minimizes liability then the majority of content will be untagged. If untagged implies "safe" then the majority of content will end up explicitly tagged as unsafe, because tagging it as unsafe minimizes liability.
But either way if you disable "unsafe content" you'll end up disabling almost everything, specifically including the huge amount of "safe" content which isn't tagged as safe because accurately classifying it is uneconomical.
If the default wasn't "almost nothing" then you'd be sanctioning exposing some kids to content their parents didn't want them to see. If there's no economic incentive to tag content then it's not valuable content for kids.
Ultimately the problem is the provider knows what category the content is and the parent knows what the content policy is. Providers can't say whether it's "safe" or "unsafe", only what standards it complies with. Some parents will have weird policies like "only G-rated movies or any Jim Carey movie" that can't even be delegated in any reasonable way to providers.
So the header has "PG-13, US-legal" because it's a movie rated PG-13 and constitutionally-protected legal content in the US, and whatever other markets you want to open up. Providers could even include AI ratings so as to mass-tag their content at low cost, and parents can decide if a particular AI rating is okay.
Parental controls could even restrict official ratings to country of origin, so if you approve PG-13 it'll block that content from countries where you can't sue them for lying about it.
> If they are enabled and the person logged in is on a regular account (not admin or power user of sorts) then the base installation of web clients must check for an RTA header [1].
Your cite is an earlier post of yours which says
> The one and only method I will participate in is server operators setting a RTA header [1]
and that cites a still earlier post of yours
> I stand by my repeated statements of how this could have been solved simply using an RTA header [1]
which finally actually cites¹ something that explains what the heck on RTA header is.
It would be quite a bit more reader friendly to cite https://www.rtalabel.org/page.php rather than make the reader traverse a linked list of comments to get there.
Bold of you to assume that lawmakers have any common sense when it comes to technology legislation. It could have taken 3 interns 3 hours at each browser company to implement a cookie consent standard 15 years ago, yet here we are in cookie banner hell.
I was referring to the intern being able to add the header. Politicians need financial incentive. I don't have the resources to lobby them. I think that might require a philanthropist should there happen to be one that lurks on HN. There are some interesting people that lurk here that we sometimes learn about.
They can't do anything today as it is a federal holiday but they could do something tomorrow.
Agree. Its like in some countries you put a sticker on the mail box "no advertisement, please" and its illegal tor postman to deliver you ad brochures. Same could have been possible with browsers, but oh no, now you have to go out to each postman ant tell him explicitly that you do not want ads, and postman has no memory, if you tel him that you don't want ads. He can come back ten minutes later and you have to tell him again.
Fun fact: in the US, the Supreme Court ruled that postal workers cannot filter out mail by the owner’s request.
It makes a bit of sense, since the mailer had already paid, but the main justification (iirc; it was years ago that I read the opinion) was that a postal service should be neutral and trusted to deliver.
Fair enough. Most advertising isn't individually posted to each address because that's expensive - they hire their own guy, who isn't a postal worker, to go around and put it in everyone's mailbox. It's like paying one cent per email to prove it isn't spam.
No, 99.9% of the mail I get is trash and is delivered by USPS. You can't even recycle most of it because of the paper they are printed on. It's a huge, disgusting waste of resources on multiple levels.
> It's a huge, disgusting waste of resources on multiple levels.
The companies on the ads wouldn't do it that way if they were not getting a positive ROI from it. They probably only need to get 2 maybe 3 new customers to offset the cost of mass mailings.
At least in the states, the postman is almost assuredly doing the end delivery of the mail, and is often given a stack of advert materials to mix into the delivery for a certain delivery area. The use of a mailbox by anyone who isn't a USPS employee delivering paid mail is prohibited by law. https://about.usps.com/news/state-releases/tx/2010/tx_2010_0...
Sure, the ISP _should_ deliver the packets. No worries.
The user agent should... be an agent for the user, and be able to perform actions on their behalf.
(The legality of those actions is of course assumed by the user here... if I add an automated flamethrower to my mailbox and burn my bills, well the debt collectors may come regardless if I read them or not - we cannot shift blame to the USPS here).
Not terribly persuasive because the first argument could just as well be seen as the postal service selling a service it can't deliver.
The second argument has the problem that for the whole thing to work the recipient must also have reason to trust the post office, but here their interests are not considered at all.
The law does mandate that opting out should be as easy as opting in. The choices are meant to be equal. It is simply that no one is actually compliant.
This is misinformation stemming from disinformation propagated by organized industry retaliation to the law. Cookie banners are not and never have been required by law, they are intentional harassment designed to make users oppose laws that actually just say “you may not track users without their consent”. A good faith implementation would be simply nothing, because no explicit consent is required when you’re actually using cookies for honest purposes.
All of the cookie banners have separate categories for strictly necessary, functional, performance and marketing, because those come from the law.
The problem is that people generally want functional and often performance cookies, and then you end up with the stupid cookie banner regardless of marketing cookies.
Strictly necessary cookies don’t require explicit consent, and generally can’t be rejected. Functional cookies don’t require additional explicit consent if you actually use that function. “Performance” actually refers to analytics, probably rebranded because users did not want it. Making you think they had to ask for the reasonable cookies, too, is the whole trick being pulled here.
> Functional cookies don’t require additional explicit consent if you actually use that function.
To not be indistinguishable from "strictly necessary" there would have to be a case where the "functional cookie" actually required consent, right? What case is that and how would you solicit that consent other than some kind of cookie banner?
> “Performance” actually refers to analytics, probably rebranded because users did not want it.
It refers to statistics, but sometimes you do want that, e.g. so the site can tell you how long it took you to do something compared to the average user, or provide those analytics to you. And the fact that this is ambiguous is an obvious problem -- if you get access to the data they collect is that "analytics" or "functional"?
In the face of an ambiguity, most corporate bureaucrats are going to take the risk-averse option, which is to ask for consent in case it turns out to be adjudicated as required ex post facto. The result is quite predictable. If you pass a poorly drafted law, businesses have a general preference for doing something stupid/wasteful/annoying over something that could get them sued or fined.
> To not be indistinguishable from "strictly necessary" there would have to be a case where the "functional cookie" actually required consent, right?
The case is when you don’t use that feature.
> how would you solicit that consent other than some kind of cookie banner?
Using the feature that requires the cookie is considered consent, same as using the website is considered consent to set cookies actually necessary for the entire website to function. For example, if you click “save settings”, that’s consent to save those settings, there’s no need for a “but am I allowed to save settings?” popup.
You might be tempted to dive into the potential grey area here, and sure, one exists, but (a) that’s why the laws go into 1,000 times more detail than this HN comment, (b) most of it’s not in the grey area, and (c) even in the worst case, making 100% sure is as easy as a checkbox before the button that activates the feature, there’s never a requirement for a blanket “can we do whatever we want” before even displaying the homepage.
> It refers to statistics, but sometimes you do want that, e.g. so the site can tell you how long it took you to do something compared to the average user, or provide those analytics to you. And the fact that this is ambiguous is an obvious problem -- if you get access to the data they collect is that "analytics" or "functional"?
The GDPR calls it “statistics”, but in this context defines the word to mean analytics, not statistics shown to users. If it’s shown to users then it’s either strictly necessary or functional.
> In the face of an ambiguity, most corporate bureaucrats are going to take the risk-averse option, which is to ask for consent in case it turns out to be adjudicated as required ex post facto. The result is quite predictable. If you pass a poorly drafted law, businesses have a general preference for doing something stupid/wasteful/annoying over something that could get them sued or fined.
Businesses are generally risk averse, yes, but don’t mistake knowing a force at play for knowing them all. The “cookie consent banner” was invented and evangelized not by the laws they’re commonly believed to have sprung from but by the IAB, an ad industry consortium counting Google, Facebook, and many others as members. The same organization that organized efforts to prevent third party cookie blocking, and that tried to block the GDPR entirely. The banner norms they created did not even comply with the law until changes a few years ago, the EU just took its sweet time on enforcement.
The average small business, of course, is not in on some grand scheme, but this is where your risk aversion comes in: if all the big players are doing something, and everybody around you is doing it, and you Google it and the first 20 results all say to do it, then the risk averse move is of course to just do it and move on. After all, trusting your own judgement is scary, what if you get sued or fined?
Tech companies could have headed off this legislation 15 years ago by just solving the problem as Bender suggested. But they wanted to pretend they had no social responsibility to not deliver filth to children, and so now the legislators are involved and they get to deal with that. I have no sympathy.
Here's one thing Apple did well on. Their screentime settings also work in the browser. It could be better, but at least it's something if you set up your kids device properly.
I had a teen whose main device was an iPad 4ish years ago and now a tween whose main device is a Windows laptop. I like Windows' implementation better--it's more granular when it comes to site access on Edge, and allows time limits in specific programs rather than categories of apps. I remember some apps that were clearly games had themselves listed as education apps.
As always, downvoting me doesn't change the legality of those banners. The law clearly states the "deny all" button must be as prominent as the accept button, and the banners employ all sort of dark patterns.
I don't think 'the law' does clearly state that, although I'd be happy to be proved wrong, and honestly it's a point of pedantry, the enforcement indicates that you're right about the actual expectation, and definitely you're right about the actual usage.
Can browsers know which cookies are necessary for a site functioning, logins, etc and which are for tracking, ads etc? There are many ways one can eg block third party cookies and that helps and rarely causes issues, but tracking can also be done with first party cookies, let alone fingerprinting.
For example, firefox's "strict tracking protection" setting also breaks a bunch of websites.
Most laws make a distinction between cookies stored for "technical purposes" and those stored for marketing / tracking.
The former are things like "does the user want dark mode", the language you chose to use the website in, the contents of your cart, your login info etc. The latter are for tracking. Typically, the former don't need consent, the latter do. Browsers have no way of telling the two apart.
Also should have been easy to design an OAuth like flow where the government that seems to care so damn much about age verification to attest someone's age in a privacy respecting way - only yes/no if the person is of the desired age.
But then again if it was to protect children, better support for voluntary age control would be so much more useful as most minors use devices managed/owned by their parents.
But then similar to cookie banners it is just about enabling surveillance
In the US all the age verification legislation is written by data broker companies that want to mine this data. The government also wants to be able to have access to this information by proxy.
It’s not written the way it’s written because they’re oblivious it’s written the way it’s written because it’s plain lobbying writing the bill.
For example, there’s little in the way of protections in how the age verification would be protected or prevent the analytics from being sold
Take the volume and mass of lobbying by all of data broker companies, data collection companies, and executive agencies.
Combine that with the character of practically every law written involving data privacy, use, IP, and associated regulation of activity around these since the 1990s. It becomes painfully clear that the interests of private citizens have not had a seat at the table, and the Constitution has been taken as an inconvenience to bypass, not a guiding document.
How does this work for mixed-content sites? Like say a minor visits a video sharing or social media site and the default feed/recommendations list includes stuff that should be age-restricted, but is mostly stuff that shouldn't be.
The entire site shouldn't be blocked; the browser needs a way to tell the website "my parental controls are enabled and I need to you to filter out age-restricted content".
Alternatively, the RTA header/meta could include a parameter/attribute for an "alternate URL" to load when parental controls are enabled. This could be useful to allow sites to present a custom error-type response, but could also be used to automatically redirect the user to similar, but age-appropriate, content.
Anyway, this all ignores the fact that "protect the children" isn't really the goal here: it's to slowly eat away at our ability to be anonymous (even read-only anonymous) on the internet. Age verification is just a watered-down way of saying they require positive identification, and eventually our hardware will have to cryptographically attest we are who we say we are. I really hope this isn't inevitable, but it's starting to feel that way.
Once you have a content label header it's pretty easy to build more complicated systems on top of that. Like the site could send "compliant with x regulation" in the content labeling header, and then that would tell the kid's browser it doesn't have to completely block the page but can instead reload the page with a request header saying "filter out a, b, and c content" and expect that to be complied with.
That could be a fingerprinting vector though so maybe depending on privacy settings it just blocks the page. Really these are all solvable problems that web standards orgs have dealt with before; you just need to create the incentive for such systems to exist.
You make the mistake of solving the stated problem, and not the actual problem. This was never about children, or a solution like what you describe would be trivial.
However, this is not about age verification or protecting children. That is just the excuse they are using.
If Meta, Google etc could easily have algorithms in place for determining the age of the person seeing the video - apart from having the override capability via a parental login as you have stated.. but these platforms have consistently refused to limit the type of content they are showing to children.
That is the only real solution. It removes the lobbyists with their bad verification schemes and untrustworthy software. You don't need untrusty flaggers or untrustworthy official authorities. In no way can nations be responsible enough to not attempt constant sniffing attempts. My nation couldn't keep itself from spying of corona app users.
This can also be broadly implemented, any other technical solution won't be widely spread anyway.
I don't think authorities care about child protection though. They could have legislated malicious advertising practices and a lot of similar bad influences, but didn't.
> The only thing server, platform, website, service providers should be doing is setting an RTA header if the content could possibly be adult or user-contributed content that could dynamically become adult, moderation aside....If a site is not adding the RTA header then progressively fine them into oblivion.
Seems like this would incentivize just all sites to have the header regardless of if it meets the definition since you get fined if you dont but no fine if you have the header unneccesarily.
Especially if your definition is contains user contributed content. That is all sites with a comment field. What really is left? I'm not sure i have even visited a site in the last month that wouldn't fall under this.
1. This assumes that websites are under your jurisdiction and can be fined. This is not a valid assumption on the internet. If you want to do this, you need a framework to block noncompliant websites via ISP-side null-routing, putting pressure on payment processors and hosting companies which do operate in your country etc.
2. HTML tags and not HTTP headers. If just a small part of the site contains content which shouldn't be displayed, the web browser should just hide that part.
3. Sometimes, it is genuinely useful to know the user's restrictions ahead of time. Imagine you're a movie streaming site or game store. You have some content which is suitable for the user, no matter their age, but you need to know which bracket they're in to decide what to show them. Without that info, you either default-adult (which sucks for children) or default-child (which sucks for adults).
No, I don't think any of that follows from that. The header can be set in the initial communication attempt. It is even more specific than any other mechanism to verify your age, because this header can be set appropriately for any web resource.
The problem of hosts in countries that don't give a shit is true for every solution aside from the great all blocking firewall no developed nation would want to have. So no to "ISP null routing" from me. ISPs provide infrastructure. They are not school teachers.
Such a solution implemented today would be tunnelled yesterday and everyone should support evasion attempts.
Countries that do not follow it could in theory be BGP filtered or sanctioned. I doubt that would happen. Probably more like the country would be added to parental controls in the browsers and parents could de-select a checkbox that is checked by default saying to block that country. If that were a thing I think some people would be enabling parental controls on themselves just to filter out some shenanigans.
They are regulating the companies. Apple, Google, and Microsoft are companies.
Desktop and mobile Linux is an extreme niche and alternatives to Linux are practically nonexistent. I'm not surprised law makers might not have known that there are operating systems not made by for-profit companies.
> The proposed amendment specifically states: “Operating system provider” does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software.
How about composite software products, say a de facto operating system which contains substantial elements subject to a permissive license? What if those are the components which support networking? If, hypothetically, a commercial operating system vendor built on Mach and 4BSD?
As a dad of two younger kids (7 and 10), I have been incredibly frustrated with the way age restrictions are handled across various services.
Really, my main complaint comes down to: I completely disagree with what these services choose to restrict for kids and what they allow.
They block my kids from doing things I have no problem with them doing and they allow things I would never want my kids to do in 1000 years. It is incredibly frustrating.
Often times, there is literally no way for me to bypass some stupid restriction they put on my kids, so the only way I can get it to work is to help my kids lie about their age… and at that point, I lose the ability to actually block things I care about.
These laws are just going to make it worse. I don’t want someone else choosing how I control what my kids do. Give me tools to control it myself, and you can choose some presets for parents to use, but don’t force me to use your definition of age appropriate.
The internet is too dynamic to build a working filter around. Perhaps just tools which help parents quickly and efficiently monitor their child's device usage would be best.
Do you want to alter behaviors or lock children in a gilded cage?
Honestly, I don’t have a perfect answer. It really depends on what the service is.
My main thing is I want to be able to opt in or out of various filters. I don’t mind if my kids want to listen to music that has swear words, but I don’t want them watching videos where they give horribly sexist pickup artist advice.
This isn’t just about what I feel is age appropriate, either. It is also about what I know about my kids.
My 10 year old hates scary things, and she gets completely freaked out when they show scary movie previews. I would like to be able to block those for her. On the other hand, my 7 year old is obsessed with scary things and I don’t mind if he plays zombie video games.
I'm as a big of a horror movie fan as you can find, and I'm completely dumbfounded by the jump scares marketing is allowed to show in trailers nowadays. IMO (coming from someone who is basically unaffected by jump scares), they've gotten more shocking in the past couple years.
> My 10 year old hates scary things, and she gets completely freaked out when they show scary movie previews. I would like to be able to block those for her.
The difference between this and the usual "parental control" mechanisms is that what you're describing here is something the child wants to cooperate with, voluntarily. In which case, you don't need a mechanism that makes it absolutely impossible; you need a mechanism for helping them not see things they don't want to see. That's something some adults also want (e.g. tools for preventing oneself going to Facebook, or going to TVTropes for too long).
Honestly, this is how I feel about all content for my kids. I am not trying to stop them from seeing something they really want to see. I am trying to stop them from seeing stuff they don’t want to see.
Now, sometimes my kids might not know they don’t want to see something, which is where my judgment comes in… but I don’t (or at least have not yet, anyway) feel the need to block my kids from watching things they want.
Now, I have spoken to my kids about some things they watch that I have issues with. I tell them why I think the content is problematic and why I would prefer they don’t watch it. But it is always a conversation rather than me just telling them they aren’t allowed.
I have been happy with how my kids have handled these conversations, and haven’t yet found the need to enforce specific rules yet. Even when they watch some things I don’t like, I have found it has made for really effective conversations about my values and what I hope their values are. Some of those topics are too abstract to have without having something tangible (like a YouTube video or channel) to center the conversation around.
A pure whitelist mode, especially for video apps. Netflix, Disney, etc don't provide this because they want to push their new shows on your kids. YouTube does provide a whitelist mode, which I appreciate. But it's hard to find, poorly implemented, and blocks a lot of great content from being whitelisted. It's very frustrating to come across a great educational YouTube video and have big nanny Google block you from sharing it with your kids.
> I don’t want someone else choosing how I control what my kids do. Give me tools to control it myself
I agree. Parental controls have been the norm for thirty years. The adult who owns the device should have control over it, not Microsoft or California.
Please keep in mind this sudden burst of legislation is because Facebook recently faced a combined $1.1 billion fine for intentionally harming children. The judgment took years.
New Mexico Child Safety Case ($375 Million) was an actual judgment.
US class-action privacy lawsuit was a $725 million settlement, with no judgment.
These laws were proposed as soon as it was clear Facebook would not win. They move the liability to the Operating System, exempting Facebook.
All the best stuff is online, though. My kids have found some of their favorite hobbies and interests from online videos they found. They enjoy using the internet for all the same reasons the rest of us do. I love computers and technology and the internet, and my kids and I play games together and build computers and explore technology. I have taught them a lot about internet safety (both personal and technological), and I am very impressed with their skills and abilities.
I would never tell another parent they were wrong for choosing not to allow their kids to use the internet or consume certain types of media. Those are very personal choices.
My wife and I have deliberately have chosen what to allow our kids to do, and continually have talks with each other and with the kids about our internet usage.
I don’t feel the need or desire to seek advice or approval from random internet commenters.
The California law has no age verification, identity verification, or surveillance. It is just a pretty simple parental control system, which only applies to devices whose primary user is a child.
We did it despite the naysayers who faught us saying it "wasn't a big deal" and that this is the "best version of the law we could get". Never listen to the naysayers and compromise your principles to appease them, stay true to what you believe.
A cynical person might suspect that the reason they are doing this is so that Linux developers don't have standing to challenge the law on 1st amendment grounds...
That’s exactly what it is. It removes standing, and that is a major flaw in our legal system. We need significant changes to defend constitutional rights properly.
Remember when women kept suing for the right to get an abortion and the courts kept just waiting out the pregnancy? Something something sixth amendment...
This is the classic "what we're trying to do is bullshit on a fundamental level so we're gonna just exempt random things until it becomes a niche issue and we can just do what we want and from there we'll just close all those exceptions over time" move.
Give it 5yr and you'll have idiots in the comments talking about how the "linux loophole" was a mistake and should be closed.
It is an admission from the writers that this law is unrelated to safety and people should very loudly and frequently point that out.
If OSes that don't verify the age of their users are a genuinely unsafe for children, why should they be allowed just because they are open source? That doesn't seem to mitigate dangers associated with age in any away I can identify.
Have you considered that the writers typically have legislative but not technical skills and are just trying to placate upset voters, without really understanding what the optimal solution could be? Reading this and other threads you can see therea re plenty of highly technical people who struggle to articulate what kind of policy they want or what kind of parental controls they want to set up themselves?
It's kind of a hard problem and legislators are inclined picking the lowest hanging fruit. Their primary concern is to not be smeared as child predators by their political opponents at the next election, eg "jwitthuhn voted to give gambling websites, pronographers, and pedophiles easy access to YOUR children - s/he OPPOSED age verification laws on internet sleaze!! Who's jwitthuhn really working for - you, or the people who want to exploit your kids?!!"
One can point out that such electoral pitches are dishonest bullshit until one is blue in the face, but the fact is they work on a lot of voters because most of them are not smart and don't have the energy or inclination to research every issue. And it is true that there are a lot of hustlers on the internet who are willing to either passively or actively exploit kids, and the anonymity, non-locality, and technical complexity of the internet makes that relatively easy to do and hard to prosecute. Legislators offer simplistic solutions because that's what a most of the public wants, and people often make their voting decisions based on emotional factors rather than cold rationality.
You don't need mustache-twirling villains saying 'let's impose burdensome techn regulations that perpetuate oligopolies and allow me to make another trillion dollars, a few million of which I'll send your way, mwhahahaha' to get shitty legislation (which is not to say they don't exist). It will emerge naturally by default if other conditions are right.
> One can point out that such electoral pitches are dishonest bullshit until one is blue in the face, but the fact is they work on a lot of voters because most of them are not smart and don't have the energy or inclination to research every issue.
That sounds like a suggestion that democracy should be limited only to intelligent or educated people, or people who have researched all relevant issues. I know that was not your intent, but it is an easy conclusion to come to from your stated perspective.
Democracy, like the free market, is viable only for informed participants. But once a certain large mass of participants are no longer informed - willfully or not - the system fails for all participants.
I don’t know, one could say that “being informed” is itself an inherently biased argument. What is being informed? Is it that they agree with you (or whatever controlled opposition to your point in your mind)?
"One can point out that such electoral pitches are dishonest bullshit until one is blue in the face"
This is what I intend to do. To just let lawmakers get away with passing bullshit because "of course they will" is a defeatist attitude that I don't advocate.
That is why it is so important to be loud about this incredibly obvious disingenuous behavior. Make sure everyone knows the people advocating this do not care one bit about children's safety.
If you go take a read through the CA bill text that "became law", you'll quickly realize that whomever did write it must live in a very narrow bubble where the only "computers" that exist in the world are tablet style cell phones, the only OS'es that exist in the world are Android and iOS, and the only way anyone installs any software on the only computers that exist is via an "app store".
Meanwhile, while the overall writing clearly indicates the author has a very narrow view of "computers", the definitions of the terms is so broad that every computer, even the tiny embedded CPU in your microwave oven, might just need to ask your age before it allows you to do anything.
> every computer, even the tiny embedded CPU in your microwave oven, might just need to ask your age before it allows you to do anything.
Why do I keep seeing this bullshit exaggeration? It doesn't help anything to make such ridiculous statements. Nobody's microwave oven has an app store.
The bill is written 'do good, stop bad stuff by establishing a committee or group to make sure fund good stuff, bad stuff doesn't happen' then the law passes and lobbyists write the details that fund the programs that tax the people that generate the income for companies that donate to the politicians that sell their votes to the lobbyists and interest groups.
California politicians start with the end goal "maintain power, secure revolt, obtain capital, deny failure".
It goes beyond lying to your face. They will be convincingly genuine, heartfelt, while finding a way to extract as much as possible for themselves, by extension their party, by extension the 'government' and do absolutely anything to keep the illusion that you have a choice, a vote, and a voice.
I lived here my whole life. These politicians are evil. Lie, cheat, and steal - deny if caught, punish if provoked.
The bill was written by Buffy Wicks, who represents me in the State Assembly, who is very good on housing, transportation, and climate, and who should absolutely stay in her lane and not try to legislate platform APIs.
Meta has not spent $2 billion lobbying for this or on lobbying altogether.
It’s amazing how that one AI slop project that made this claim got so many people to believe this number.
Spreading this disproven AI slop around isn’t helping. It just makes opposition look like uninformed conspiracy theorists who can’t fact check anything.
Meta is lobbying to get age verification installed at the OS level so that they don't have to bear the cost themselves. I know nothing of the $2B but the fact that Meta influences the legislation can hardly be denied:
During the meeting, Meta executives, including Antigone Davis, global head of safety, are understood to have argued that any age checks should be handled on a smartphone operating system rather than by the likes of Meta.
There was an AI generated slop report posted to Reddit that went viral. It even got some news coverage before anyone stopped to read the files and discover that it was gibberish.
I still get downvoted for pointing it out and trying to ground the conversation in facts. As you noticed the story continues to thrive on bad news sites and social media.
If I'm reading that right this covers all of Meta's state lobbying spending which is $45M + $25M federally and it's not all directly related to this age gating stuff, but general shaping anti-child exploitation policy?
> On every social media regulation bill in Colorado, Meta takes an "Amending" position, actively fighting changes. Across 117 lobbying records on 22 bills:
> Bills regulating social media: Meta position is "Amending" (fighting)
> The one bill putting the burden on OS providers: Meta position is "Monitoring" (watching)
> Meta fights bills that regulate Meta. Meta watches bills that regulate everyone else.
So their lobbyist choosing not to fight against the OS age gating is the big reveal.
> Who is actually writing this very concerning California Internet legislation, which will ultimately affect the entire nation and world?
Why would it affect the entire world?
One technological backwater is Having A Massive Sad over people using rude words on the internet, so they think they can tell everyone else what do to?
Hypothetically, preemptive market recapture? This could theoretically make foss OSs non-kosher for any suitably large market (websites, games, chat platforms, etc), and serve to force foss OSs into a niche where theyre technically capable of being personal desktop software, but practically unusable because of lockout.
This is part of a large movement to end personal computing as we know it, and give all control over our digital lives to the mega corporations. It is already impossible to use some national ID or banking apps on non-Apple and non-Google phones. (say GrapheneOS), giving them an immense edge in the market, and they're using that domination to add more restrictions like installing non-play store apps on Android. This goes bit by bit, try to add a restriction, go back enough to quiet the backlash, try again. This new law is a foot in the door to achieve the same restrictions on PCs. PCs are the last open computing platform and bastions of personal digital freedom and thus they must be destroyed by capitalists and governments. Once the technical means have been put in place to restrict access to some services, the system can be hardened : impose that the age checks can't be tampered with by using a TPU module, impose a link to the individual's identity so that all online activity can be traced to anyone. Pretenses are easy to find : protect children, block sex offenders from accessing dating sites, and so on. At this point I'm pretty convinced we're geared towards a global totalitarian regime, and there's a lot of evidence.
It really bums me out that I fully believe this is it.
Megacorps seize the demand for regulation (to regulate them) in order to write regulation that purportedly does that, but in practice mostly closes the doors behind them and cementing their stranglehold on society. For Microsoft, Apple, and Google it's a small thing to agree to age verification if that means all the potential competitors will have to do so too.
The cheapest time to shut down a competitor is before they get to market.
It's a classic case of regulatory capture. Only the biggest players can get away with fully implementing age verification — if Microsoft requires age verification to use its OS, most people will oblige. If HN starts doing that most people will probably just log off forever.
What is maddening is how often people think such laws are about limiting the influence of "big tech." Big tech isn't going anywhere because of these laws, you are.
And I bet that Microsoft employee who was sending PRs to all the linux distros (and systemd) will not bother sending apologies to them for wasting their time.
He isn't. Also never was (unless the CV lies that is).
As for what drove him instead.. I suppose we will never know.
All we can know for certain is that the whole thing felt _very_ inorganic and not like something a reasonable human being would just start doing out of the blue.
(Corporate) politics love plausible deniability, so maybe it was just inherently human randomness. I'm sure it was.
Please move along.
Steam itself does age verification, which when you first boot a steamdesk, afaik it forces you to log into steam before you can do much of anything without some initial hackery. That said, once in there's nothing stopping them from launching into desktop mode, launching firefox, and watching pr0n that way.
Sadly the solution is still for parents to do real parenting, but that's like saying stupid people shouldn't breed.
Why should Linux be exempt? Linux lobbyists seem to be against the public good. It takes an AI agent 5 minutes to add this feature and then they add be good forevermore. And given that the software is open source, everyone can use the same library to be compliant. Belly-aching snowflakes…
1st amendment. There's a long history of carve outs around commercial products. But, if Linux devs (who aren't selling anything) went to the mat against this law, the government of California would lose and (at least part of) their law would be struck down.
This is the whole 'opt-in vs opt-out' at a high level. A better law would be crafted like 'some services have been determined to be harmful to minors and require age verification. Those -specific- services shall have these specific mitigations.....' Facebook and others should have a clear legal distinction of 'harmful to children' and then the law kicks in.
Parental controls should be a client side option set by the user.
Sure, make it easy for users to do so, but it's a users choice.
Kids don't buy phones or computers, their parents do, and during initial setup, parents could choose "this pc is used by a child" option, input some override password to disable this in the future, and the phone could block whatever needs to be blocked.
Not just Linux. More specifically: “Operating system provider” does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software.
Yes, I wonder what false positives and false negatives will result from that definition. I suppose Microsoft permits corporate licensees to copy (to all their PCs and servers), redistribute (internally), and modify (by corporate software developers and also by sysadmins using group policy) the software.
Maybe it should say, the software 'code' - requiring open source code - and to do it all 'for free'.
there must be an reasonable assumption of what counts as such in the first place.
being modifiable and publicly available in both source and binary form sound like enough to me.
The reason is simple: the pattern I see hints that there is:
a) money spent, to push through age-sniffing, and
b) it is happening almost globally.
I am not necessarily saying that all this can be singularized down to one
bribe-using company, be it Meta, Google or what not, or state actors becoming
beyond Evil. But just as the butterfly effect is used as analogy how a strong
wind can be created further downstream, I see the situation here VERY similar.
To me it is not confined to age-sniffing. Remember the sudden declaration of
war by the UK against VPN. This is in my opinion connected here. The goal is
not "protect the children" but instead spy more on people than before. A
gradual extension of this. And some companies and private interests will
benefit. See also the recent Palantir claim made against London aka "the major
is responsible for more robberies when he refused to obey to our rule". These
companies are greedy - and insolent.
What's depressing to me is just how self-serving all this is. The original bill was AB 1043. Who supported that, breaking with other tech companies? Why Meta of course [1][2]! Meta likes this because it pushes liability onto the OS providers. Guess who doesn't have an OS? Google's support is a little stranger given Android. It seems like AB 1043 also shifted liability to third-party app developers instead of the app store so, conflicting goals?
Likewise, you'll have Microsoft and maybe Apple pushing for Linux to be included for, again, entirely self-serving reasons. Microsoft is never one to miss an opportunity to benefit Windows.
All that's going on here is competing corporate interests. Likely nobody in power actually cares the actual end users.
As much as libertarians chafe against it, I think we've demonstrated that something has to be done in relation to children online. Advertising to children, harmful impacts of social media, cyberbullying, addictive behavior and selling the data of minors needs to stop. How we get there is unclear. Meanwhile, everyone responsible is just trying to limit and shift their legal liability and that's it.
If Meta is liable for when someone underage uses their service, then Meta is going to require proof of age which almost certainly means giving them copies of things like driver's licenses or passports probably along with video showing that you match the photo.
In jurisdictions taking the California approach Meta does not need to ask for anything like that. Their app just has to ask the OS, which reports the age bracket that was entered when the user account was made on the device, and the OS gets that information from whoever set up the account. The OS trusts whatever is entered at that time. No driver's licenses or passports or face scans or videos are involved.
> As much as libertarians chafe against it, I think we've demonstrated that something has to be done in relation to children online
...and this is pretty much the way to do it with the least impact on privacy and anonymity possible without first building up some high tech cryptographic infrastructure that would likely include hardware requirements that would, at least at first, exclude users who do not have an iOS/iPadOS or Android device that has a secure hardware element.
> If Meta is liable for when someone underage uses their service, then Meta is going to require proof of age—
Let's be clear what this means, "Meta is going to require" something. They'll require it to continue to do something, which is namely to be a bad company, running bad services, without pivoting to something else.
Of course, no one requires Meta to continue to be Meta. We'd protect people by requiring companies like Meta to request PII outright, because then the user is explicitly prompted to decide whether using Meta's services is worth surrendering their privacy. And if consumer sentiment and market forces mean anything anymore, that will incentivize Meta to replace their bad services with better ones, ones that don't cause them tricky liability issues.
In other words, forcing operating systems to demand PII from users from the get-go, regardless of the quality of that signal, and to broadcast that to any website, is not, as you put it, "the way to do it with the least impact on privacy and anonymity possible", etc etc. The "way to do it" is to phase out this rotten era of surveillance apparatus disguised as social media companies.
Sorry for being irate, it just feels like so many people these days arrive too quickly (for my taste) at conclusions without testing certain popular assumptions about the inevitability of tech oligarchy.
> As much as libertarians chafe against it, I think we've demonstrated that something has to be done in relation to children online
Just cuz today's ad-supported social media is bad for kids, doesn't mean everyone should have to verify their identity to use it. You can just make it 18+ and if kids lie to get around it that's not the end of the world. And in general, regulations that would make these things better for everyone would be better rather than just saying kids can't use it and not fix the actual problems with them
The state should handle personal records, authentication, and age verification. Compliance should be as simple as implementing dead simple state provided interfaces.
So are kids not going to have access to llms? Seems trivial to get around this from a technical standpoint for frontier llms no matter how this is implemented.
This will only help if the law states that internet companies that check this have to default to assuming the user is an adult. Otherwise the end result will be that Linux clients will get caught in a dragnet of automatic denial.
This is a bad move. California has no age verification law, only an age asking law and all of the reasons it's good to ask if the user is over 18 are still good reasons if the OS is Linux. And the penalty for providing an OS that doesn't ask if you're over 18 is that it's considered a defective product and you can return it for a refund, but open source software is already provided for free with no warranty so who cares. Unless you bought it from Red Hat so this is basically just giving Red Hat impunity to violate this law, for no reason.
As usual 95+% of people commenting have no idea what is actually in the California law, and so are commenting about things that have nothing to do with it.
Different states, countries, and multi-country organizations that have legislated in this area or are working on legislating in this area have went with many different approaches. These differ in their scope, how age is verified (or even if age is actually verified), what documentation is required (or even if documentation is required), whether they apply to the web or to apps or to both, whether they make anonymous use harder or not, how much if any sensitive information they disclose to the apps/sites that need to check age, whether they could allow government to track your usage, and in other ways.
Most ridiculous are the comments that after saying how bad it is (clearly talking about things not in the California law) then say how it should work and describe something close to the California law.
It's not out of the ordinary for folks on HN to discuss the general subject of a topic and not the exact contents of TFA. The article tends to just be a catalyst for discussions.
It is kinda silly to read comments that do what you mention at the end (have a seemingly novel idea to fix the issue at hand and their solution is the one from TFA). That's just embarrassing.
But I feel like the rest of the discussions are fair game.
Wow this is smart politically because the largest group against this age verification bulls*t just so happens to overlap a lot with people who love open source software (technical people who value user freedom)
Of course this also means that the nerds who use linux or lineageos get to win cool points because they can access more adult stuff
Huh? An operating system, as defined by Andrew Tanenbaum[0], the author of both Minix and of the best operating textbook ever, is a combination of:
- an "extended machine": provide usable abstractions over the hardware to reduce complexity to a manageable level
- a "resource manager": provide for an orderly and controlled allocation of the processors, memories, and I/O devices among all the various programs wanting them.
By that definition, Linux is very much an operating system... unless by "Linux" you meant the kernel only without the additional tooling (systemd, libc, coreutils, shell, etc.) that distros ship with.
I'd just like to interject for a moment. What you're refering to as Linux, is in fact, GNU/Linux, or as I've recently taken to calling it, GNU plus Linux. Linux is not an operating system unto itself, but rather another free component of a fully functioning GNU system made useful by the GNU corelibs, shell utilities and vital system components comprising a full OS as defined by POSIX.
Many computer users run a modified version of the GNU system every day, without realizing it. Through a peculiar turn of events, the version of GNU which is widely used today is often called Linux, and many of its users are not aware that it is basically the GNU system, developed by the GNU Project.
There really is a Linux, and these people are using it, but it is just a part of the system they use. Linux is the kernel: the program in the system that allocates the machine's resources to the other programs that you run. The kernel is an essential part of an operating system, but useless by itself; it can only function in the context of a complete operating system. Linux is normally used in combination with the GNU operating system: the whole system is basically GNU with Linux added, or GNU/Linux. All the so-called Linux distributions are really distributions of GNU/Linux!
I know that, most technical people know it, but I refuse to call it "GNU/Linux" because that's a dumb name and Richard Stallman is so over the top pedantic to constantly insist on it.
Open software should not implement this feature because slippery slope is not a fallacy based on my experience. Force them to actually create a government approved operating systems to make it clear how absurd this is and so that we know who will bend the knee.
Linux will be exempt for now. I wouldn't be at all surprised to see them try to slip it through later. Legislators in California have learned over the years, and have carved out exemptions in bills such as gun control bills to get it passed, and later classified their exemption as a "loophole" to be closed.
How does this age verification crap apply to server environments? If you can't use windows desktop without age verification can you just install windows server or IoT as a loophole?
Wow, stupid idea is hard to legislate. Nobody could predict that.
It reminds me of clients wanting some stupid feature from app developers which does not fit into anything, and makes no business sense, and therefore creates only problems.
It is good to see lawmakers course correct when technical realities are pointed out. Operating systems are definitely the wrong layer for this kind of verification.
we're preparing ourselves to deanonymise the internet. We do not know yet what this will have as a collateral, but certainly the governments will use it against us.
This is ridiculous. Either this is a vital child safety requirement that needs to apply to operating systems regardless of origin or it isn't and shouldn't apply to any operating system.
it would be pointless to force software that can be modified to remove an age-verification to have age-verification.
but maybe they can move to force distributed copies of linux to have age-verification, hopefully dealing with those complaints
I was hoping we'd see some "-CA Compliant" ISOs of Linux distros released (crackes me up thinking about it), it feels a little insane to me that we would force so many open source projects to check for a person's age.
On a side note ... does anybody know where I can get one of those Tux plushies? The tag appears to say "Penguin Power ... https://www.PenguinPower.com/", but that doesn't resolve to anything useful.
kgwxd | a day ago
trollbridge | 23 hours ago
… doesn’t that excuse Android and possibly XNU, too?
antiframe | 23 hours ago
I think we have our answer.
user_7832 | 23 hours ago
thefreeman | 22 hours ago
realusername | 22 hours ago
hnlmorg | 22 hours ago
Telaneo | 22 hours ago
antiframe | 22 hours ago
floxy | 19 hours ago
antiframe | 18 hours ago
TylerE | 23 hours ago
tangotaylor | 20 hours ago
Or, they can have a license like the Business Source License where you can copy, redistribute, and modify the software but you can't use it commercially. This goes against OSI's open source definition.
We emailed this amendment to Buffy Wicks's staff:
§1798.504(f) This title does not apply to[...]:
(4) An operating system or application that meets both of the following conditions:
(A) The operating system or application is distributed under license terms that permit a recipient to copy, redistribute, and modify the software, including for commercial purposes and without payment of a royalty or fee.
(B) The operating system provider or developer does not, by technical or contractual means, prevent the recipient from installing modified versions of the software on a device on which the unmodified version operates, and does not restrict the functionality or interoperability of modified versions.
mmooss | 20 hours ago
> copy, redistribute, and modify the software
Shouldn't that specify the code not or not only the software? For example, the corporate Windows license allows the corporation to copy, redistribute (internally), and modify (via group policy, APIs, or development on the Windows platform) the software. The big difference between that and Linux is licensees can't access the code. FOSS requires free access to, use of, modification of, and redistribution of the code.
tangotaylor | 19 hours ago
That and lots of FOSS licenses use some variant of those words "copy, redistribute, and modify" so it's probably a term-of-art that courts recognize.
This is what Colorado's law says. It prevents Tivoization but not feature nerfing like the Play Integrity API.
§ 6-30-105 (3)
(e) AN OPERATING SYSTEM PROVIDER OR DEVELOPER THAT DISTRIBUTES AN OPERATING SYSTEM OR APPLICATION UNDER LICENSE TERMS THAT PERMIT A RECIPIENT TO COPY, REDISTRIBUTE, AND MODIFY THE SOFTWARE WITHOUT ANY PLATFORM-IMPOSED TECHNICAL OR CONTRACTUAL RESTRICTIONS IMPOSED BY THE PROVIDER OR DEVELOPER ON INSTALLING ALL MODIFIED VERSIONS.
Bender | 23 hours ago
The only thing server, platform, website, service providers should be doing is setting an RTA header if the content could possibly be adult or user-contributed content that could dynamically become adult, moderation aside. This knocks out two issues with one fix. Small children don't see much if any adult content and they are kept off social media until the admin (parent or legal guardian) approves it.
If a site is not adding the RTA header then progressively fine them into oblivion. If they accept the fines as the cost of doing business then seize everything and put everyone in GenPop. An intern could enable the header in 5 minutes.
All legislation regarding age verification must revolve around this otherwise people must reject it as an abusive form of tracking and privacy invasion. The focus should be on small children as teen share porn, warez, movies and such within Rated-G games.
[1] - https://news.ycombinator.com/item?id=47950091
jahnu | 23 hours ago
Bender | 23 hours ago
No harm in people reaching out to their politicians state and federal. The more people that bring it up the better. Let them know your childrens data will not be shared and when the data is leaked you will hold the politicians accountable.
SilverElfin | 23 hours ago
reddalo | 21 hours ago
Bender | 21 hours ago
reddalo | 5 hours ago
Bender | an hour ago
maccard | 10 hours ago
wizardforhire | 23 hours ago
themafia | 23 hours ago
An intern could also just delete the product which would also "solve" this "issue". The fact that it's easy or cheap is not significant to the problem at hand.
> should be doing is setting an RTA header
Many sites will just set the header by default. Now you've created a problem.
> then progressively fine them into oblivion.
This does nothing. See: Ofcom vs 4chan.
> device mandates
Mandate that the device provide an API for child protection software. Then it's up to individual parents to decide to install that software or not. Then we also get competition in this market rather than relying on whatever solution an intern cooked up one day.
Bender | 23 hours ago
Many sites will just set the header by default. Now you've created a problem.
I am not seeing a problem. Kids need not access those sites unless the parent or legal guardian approves it. Sites meant for children would not be adding the header.
[1] - https://news.ycombinator.com/item?id=47953096
themafia | 23 hours ago
Is Wikipedia "meant for children?" Should they be fully denied access to it? Should Wikimedia be fined if they make a mistake? If they get fined often enough do you think they'll just turn the header on everywhere in order to avoid risk?
Replace Wikipedia with any other mixed content site you prefer.
Bender | 22 hours ago
Add it to any site not specifically meant for children, that is totally fine.
[1] - https://www.shodan.io/search?query=RTA-5042-1996-1400-1577-R... [ Follow Links At Your Own Peril ]
pessimizer | 23 hours ago
Bender | 23 hours ago
- Browser detects header. Prompts for local password to access site.
- Child does not know password, picks a different site or begs parent for access.
- This is now between small child and parent. No third parties, no tracking, no telling website the users age, no local or remote API's sharing data.
- At some point if all goes well the child will be an adult and will thank their parent for looking out for them when all their friends data was sold and abused.
pessimizer | 23 hours ago
The problem is that the point is to root everyone's devices. Anyone explaining how easy this is would be pushed out of the conversation as fast as if they were advocating for single-payer healthcare.
edit: I've been advocating the nearly identical but opposite solution - restricted access sites shouldn't respond to requests that lack an appropriate age/content restriction header. If they do, jail them.
They're literally going to have to do this anyway. Rooting people's devices to force them to lie about their age when they install their operating system is an absolutely fake pretendy solution; the only way it works is if you have to verify your age with some government agency when you install an operating system, in order to make that OS age official. The point is the identification.
salawat | 23 hours ago
It's still a stupid unconstitutional law, but I see what the aim is, even without strawmanning it.
Bender | 19 hours ago
skybrian | 23 hours ago
https://webmasters.stackexchange.com/questions/140733/how-to...
Bender | 23 hours ago
They stop trying to put everything in a different category and treat RTA as the person under the age of consent must get approval from their parent or legal guardian. Keep it simple.
skybrian | 23 hours ago
Bender | 23 hours ago
lazyasciiart | 22 hours ago
Bender | 22 hours ago
Correct. Until parent or guardian puts in password next to the text that says "Approve this site, forever."
You gave me an idea. Maybe there could be categories similar in concept to those that exist in corporate firewalls today that say things like:
- News Category (Known to be SFW)
- News Category (That may be NSFW)
- Child friendly sites
- Social media sites
... and so on.
This could be crowd sourced, ideally in a way that can not be gamed. The masses could flag/report false claims. That, or just keep it simple. ad-hoc input of permitted sites by parent.
lazyasciiart | 22 hours ago
Bender | 22 hours ago
I think I know what you meant and sure we can keep it simple. Site is approved by a parent or it isn't.
dotancohen | 20 hours ago
The problem with defining categories is that artists will do their best to defy categorization. That has been the nature of art for as long as humans have been making art.
Bender | 20 hours ago
I do not have a proposal for that. I'm only covering the issue of sharing any personal attributes of a child or anyone with any corporations as they have proven time and time again they can not be trusted with it. If anything they have proven beyond any shadow of doubt they can not be trusted with anything.
I will leave the NSFW definitions to yourself and others. Since the W stands for Work I guess company management and HR get some say in it too. I don't know where they get their standards from.
Ages ago I worked for a company that hosted porn and their standards were uniquely liberal.
jonathantf2 | 20 hours ago
skybrian | 22 hours ago
Defining a new header isn't hard; the hard part is getting consensus and adoption.
Bender | 21 hours ago
Are today's videos beheading's without blood, with blood, with or without anguish, with nudity, without nudity, etc... After a while it gets out of hand.
It turned out the internet was too dynamic so the RTA header was created to just say "adult".
inetknght | 23 hours ago
Google's doing that for them though.
delusional | 23 hours ago
B) How would your RTA header intersect with content rating in different jurisdictions? What if the content is illegal for children in Turkey but legal for children in Kentucky?
Bender | 22 hours ago
For topic (B) companies can set or not set the header based on GeoIP. Not perfect but GeoIP is already used in load balancers, web servers and applications.
delusional | 21 hours ago
For (B), your proposal requires the website have a database over current rules in every country they would be accessible from. Would a website then, in your opinion, be responsible for the accuracy of this database? We have to presuppose an official GeoIP source that would then be legally binding and under democratic control, but given such a database, would a website serving a wrong header to an IP associated with a specific country then be committing a crime in that country? What would the punishment be?
Bender | 21 hours ago
For (B) this is already a thing. Porn sites and already doing this. Instead of blocking a region I am proposing to stop blocking and instead the law permit them to just add a header. The only people I can imagine apposing this are commercial VPN providers.
delusional | 21 hours ago
I think a better example might be places like polymarket (not allowed to operate in us) or usatoday (serves an EU only version with no cookies). The technical limitations on those systems are both GeoIP as far as I'm aware, and that seem sufficient for regulators.
What I find more interesting is that what you want is within the scope of this law. It's only required that the operating system takes in your age from an admin, from there the application (user agent/webbrowser) is supposed to handle the blocking, which it could do with a header as you suggest.
I will note that you are going to find a lot of libertarians that would oppose banning GeoIP circumvention.
Bender | 20 hours ago
iamalizard | 23 hours ago
Bender | 22 hours ago
AdrianB1 | 22 hours ago
It is like negotiating with a terrorist that wants to kill you and this is his starting position and then he wants to agree on some compromise, like seriously beating you. There is no negotiation.
Bender | 22 hours ago
fc417fc802 | 16 hours ago
That exists and is called "self defense", no?
yetta | 22 hours ago
shevy-java | 21 hours ago
That data leaks out is always a given. So, gather less data. Ideally none. But this is not a discussion about data. This is a discussion as to what state actors think they are allowed to do. It is an attack on private life of people. See the combined strike against VPNs.
Bender | 20 hours ago
I can only hope you are correct.
hunterpayne | 19 hours ago
PS I'm referring to bail reform here.
PPS Just trying to frame what the CA government thinks its allowed to do which is apparently anything it wants.
hansvm | 21 hours ago
Obligatory XKCD: https://xkcd.com/2521/
saghm | 11 hours ago
mikestorrent | 22 hours ago
but... I would also like to keep my kids from seeing the very worst of the internet before they're ready to handle it. I tried using a PiHole but Firefox DNS-over-HTTPS nullifies that now. It's not realistic for me to be watching over their shoulders 24/7; what can I do to keep them away from stuff 99% of people agree isn't for children to see, without something like this?
malicka | 22 hours ago
grim_io | 22 hours ago
Like no past generation could stop their kids.
dylan604 | 22 hours ago
JumpCrisscross | 22 hours ago
Past generations absolutely protected their kids from cigarettes and alcohol. A gate doesn’t have to be 100% effective to have net benefits.
kelseyfrog | 21 hours ago
smelendez | 21 hours ago
Some kids getting access to booze here and there with planning and coordination is different from kids walking into a liquor store or bar whenever they want.
kelseyfrog | 21 hours ago
1. https://en.wikipedia.org/wiki/Splitting_(psychology)
dijksterhuis | 20 hours ago
ziml77 | 18 hours ago
yard2010 | 9 hours ago
JumpCrisscross | 19 hours ago
No. Like, obviously no. That’s not how effectiveness is ever measured.
ImJamal | 16 hours ago
grim_io | 20 hours ago
But like your examples, it's not guaranteed to work.
Install a DNS filter. Firefox circumvented that? Smart kid :)
Censorship circumvention might be a good skill to have in the near future.
ImJamal | 16 hours ago
Auracle | 13 hours ago
I'm sorry, but what? Cigarettes, sure. Alcohol? Binge drinking was absolutely rampant at my school, and I don't think I'm alone. Don't get me wrong, some parents just buried their heads in the sand, but unless you're giving them a breathalyzer when they get home and severely punishing them all the time it's pretty hard to prevent.
saghm | 11 hours ago
(Yes, you might get carded before you can go into a bar or a club, but we're talking about every possible device that can connect to the internet here; that's a lot closer to the grocery store than a bar or club terms of how much of a staple this is for most people's daily lives at this point. Cutting off my ability to access to my bank account, contact doctor, or pay my bills should not be something that should require additional steps because my devices which no children ever used could theoretically be used for a child to try to watch porn).
JumpCrisscross | 5 hours ago
I agree these proposals are garbage. But if everyone who can credibly say that is busy trying to block any age gating, this is what we’re going to get.
saghm | an hour ago
I'm certainly not busy trying to block a bunch of hypothetical policies that no one has proposed when there are garbage ones that are literally getting pushed right now. It sounds more like too many of the people who recognize the harm of this policy are too busy trying to claim that the burden for coming up with a non-garbage policy should be on the people who fundamentally disagree with that framing.
Bender | 22 hours ago
If the childs account is not able to gain admin privs then their ability to change settings can be disabled.
anigbrowl | 22 hours ago
Bender | 22 hours ago
anigbrowl | 21 hours ago
I personally think this current version of the legislation is a good compromise. Tech workarounds are fine for the few of us that understand the relevant technology (though I have never bothered to compile DNS in my life and have no plans to do so in the future), but they are simply not practical for most people. Every time I hear someone suggesting this sort of thing I find myself tempted to say 'why worry about legislation? If you don't like what it mandates you can just write your own operating system.'
Of course this would not be helpful because writing your own OS is extremely hard beyond classroom/toy examples. And likewise, tech workarounds and even parental controls are hard for most consumers - partly by design. I have an xbox console and have been trying to figure out why it keeps freezing on certain apps for months now. I suspect a telemetry problem but it's just a guess, there isn't really any way to look at logs so it's a trial and error process because most consumer hardware/application vendors want their products to be black boxes.
shevy-java | 21 hours ago
I don't think it is a good compromise. It seems to cover the wrong use cases.
My use cases have nothing to do with children on any level. Why would I want to submit to government restrictions? That makes zero sense.
It's as if the right-to-repair-movement would suddenly be undermined by a lobbyist advocating how restrictions are great. Or Jackie Chan suddenly praising the sinomarxist mono-party.
anigbrowl | 21 hours ago
qdotme | 17 hours ago
catlikesshrimp | 22 hours ago
cyberax | 22 hours ago
Nothing. VPNs exist (including free ones), some of classmates will have unlocked devices, etc.
Next question?
Bender | 22 hours ago
fhn | 21 hours ago
fhn | 21 hours ago
ObscureScience | 21 hours ago
pluralmonad | 21 hours ago
71bw | 5 hours ago
pluralmonad | an hour ago
shevy-java | 21 hours ago
Here we talk about use cases for EVERYONE. I don't see how your use case is fine for me, because I personally do not agree with it on any level at all whatsoever. You believe in restriction. I don't. There is no common ground here.
> It's not realistic for me to be watching over their shoulders 24/7
Is this your job? At which age will you stop monitoring them?
> what can I do to keep them away from stuff 99% of people agree isn't for children to see
99%? Where do you get those numbers from?
Besides, what stuff anyway? Even then the issue isn't about your kids. It is about laws for EVERYONE.
trinsic2 | 19 hours ago
This is the main problem that needs to be addressed. Everything else is just a byproduct of it. If you support the by product of what was created by conditions that are not being address, you only make the problem worse.
fc417fc802 | 16 hours ago
However DoH isn't obfuscated and in order to operate the list of resolvers that firefox uses must be published somewhere. It follows that you should be able to filter the major DoH providers at your gateway.
saghm | 11 hours ago
The better question is "Why do I need to give up privacy on my devices that no children ever use and are used for all sorts of mundane things that are entirely unrelated to what you're trying to protect your children from to solve this problem?" The solution being proposed here is to require ID checks at the OS installation level; this would be like requiring me to flash my ID when I walk out of my house because kids would have to go outside if they were going to try to buy alcohol.
feelamee | 9 hours ago
> before they're ready to handle it
You can restrict any access for the network to them. Extra bonus, this will save your child from addiction.
71bw | 5 hours ago
JumpCrisscross | 22 hours ago
How do you propose doing age restrictions for social media?
These are broadly popular. (And the evidence supports them.) They are happening. So the question is how to do it best. The project for reversing the consensus isn’t worthless. But it’s a long-term project that will have to bear fruit after these restrictions go into effect, if ever.
bijowo1676 | 22 hours ago
JumpCrisscross | 22 hours ago
Voters are collectively deciding for all of our children. And there are absolutely group dynamics that require cooperation. It’s why rich communities ban phones in classrooms while in poor communities, the one family that tries doing it alone is probably going to be less successful.
Again, I’m not saying you’re fundamentally wrong. Just that this debate has been had and the polling is massively in favor of bans for under-14 year olds and strongly in favor for under-18s. (And to the degree I’ve connected with electeds, the folks calling in and writing were almost 100% one way. The civically-engaged electorate is practically at consensus.)
bitwize | 20 hours ago
JumpCrisscross | 19 hours ago
Huh?
Bender | an hour ago
"lolbertarian - A disparaging term for internet libertarians, used jokingly or not."
[1] - https://www.urbandictionary.com/define.php?term=lolberts
bijowo1676 | 17 hours ago
bijowo1676 | 17 hours ago
I want government bureacrats, empowered by the stupid median voter, to be as far away as possible from things that I (and any other parent) are perfectly capable of solving by ourselves.
I want more freedom
JumpCrisscross | 13 hours ago
Sure. Call your electeds next time this comes up. Right now, the ship has sailed. Jurisdictions are debating methodology.
saghm | 11 hours ago
Longlius | 7 hours ago
The idea is broadly popular but the second you start asking about implementation details (ie showing your ID to post on the web), the actual approval percentage tanks down to the single digits.
But you knew that which is why you construct this rhetorical motte-and-bailey about it being "broadly popular"
JumpCrisscross | 5 hours ago
Source?
> But you knew that
I genuinely don’t. I don’t think many electeds do, either.
The playing field is currently lots of angry non-technical parents looking at Silicon Valley leadership not doing anything remotely reassuring when it comes to taking care of their children. And then a good fraction of them being drawn into a proper pantheon of idiot conspiracy theories. (They’re really stupid.) I would love to see polls considering implementation details because that would at least imply somebody is thinking of them.
Right now, honest answer, I don’t think anyone in government is. Electeds see an easy win—or more accurately, a patchwork of angry, mobilized voters they can scoop into their election-year campaigns with a rushed-out bill that pins them to the issue but which neither they nor those voters really have the technical chops to parse.
Best case, we get tripe. Worst, the process gets hijacked.
anigbrowl | 22 hours ago
jrmg | 22 hours ago
harshreality | 22 hours ago
What it fails to account for is that today's internet is qualitatively different from the pre-social-media, pre-smartphone internet. The vast majority of the internet audience, too, is qualitatively different. Incentives are misaligned for an average parent who might want to keep a tight leash on smartphone internet access for their kids, when attempting to do so will generate fierce opposition from their kids and leave them socially out of the loop.
reddalo | 21 hours ago
Maybe we should teach parents how to be parents instead of imposing draconian age checks (read: mass surveillance).
infinitezest | 21 hours ago
iamalizard | 21 hours ago
The first example is bad, the second is tolerable.
But the reason most kids don't smoke is that the parents and the teachers instilled in them that it was bad. If a kid wants to smoke or drink, they can surely get an older friend or a friend of a friend to sell them the cigarettes or alcohol. Anyone can buy 20 bottles of hard liquor and 50 packs of cigarettes, sell them to a 15 year old who can then sell them to their friends. That doesn't happen often not because a surprise police raid will show up and bust the seller but because there isn't enough demand. If there is demand from the kids and the parents don't care, kids will get their hands on drugs. Maybe not 9 year olds but certainly the teens.
kelnos | 16 hours ago
Big honking "citation needed" there. I think it's far more likely that laws against advertising to minors, and tightening enforcement of prohibiting the sale to minors, is what did it.
On top of it all, smoking has decreased among adults too. Part of that is certainly cutting off a big chunk of the teen-to-adult smoking pipeline, but part of it is also just that adults don't think it's so cool anymore (and "going out for a smoke" is no longer a social or even professional activity), and are more aware of the health risks.
wizzwizz4 | 21 hours ago
forgetfreeman | 21 hours ago
wizzwizz4 | 20 hours ago
forgetfreeman | 16 hours ago
wizzwizz4 | 11 hours ago
Low-tech Magazine (https://solar.lowtechmagazine.com/) has enough articles to publish a thematic book, “How To Build a Low-tech Internet?”. There are other books with concrete proposals: pretty sure Cory Doctorow's published a few (Chokepoint Capitalism, also by Rebecca Giblin; Enshittification; possibly others). You can read these if you would like. But the important part is using and maintaining credible alternatives, reducing both our dependence on and support of these companies.
[1]: although more work is needed to reduce the addictiveness / increase the user empowerment of Fediverse UIs (which are largely modelled on the corresponding Big Tech social media systems): websites are still the way to go, if you can.
RHSeeger | 21 hours ago
reddalo | 5 hours ago
burnte | 21 hours ago
throwawayqqq11 | 21 hours ago
This broad rejection without good reasons is borderline sociopathic. ... and parental control is not the gov raising anyone.
forgetfreeman | 21 hours ago
hunterpayne | 19 hours ago
forgetfreeman | 16 hours ago
kyledrake | 10 hours ago
tardedmeme | 9 hours ago
kyledrake | 8 hours ago
Governments are dangerous monopolies on force and the use of that force shouldn't be casually tossed out like candy at a parade on crap like this. If it doesn't matter if you lie, what's the point of even doing this, to prove that we're insane? Or is it the pretext for requiring a remote server id carding service in the future under that guise? Keep driving down this road and you end up with an end game that looks a lot more like North Korea than a free society with limited government.
tardedmeme | 5 hours ago
Do you think the rule that children's toys can't contain lead is equivalent to living in North Korea? That's the same kind of law as this one.
You also have a lot more flexibility to negotiate on product quality. If you have a good reason why you can't meet normal product quality standards because your product is sufficiently different from the normal products in that category, you can usually put a prominent warning label on it to cover your ass and then you're fine.
kyledrake | 4 hours ago
And if they refuse to do all of this and resist, what happens to them? If you want a sample, stop paying your taxes, stuff your money under your mattress and see what ultimately happens. Just because our government is slow, stupid and incompetent doesn't mean that they don't use the same mechanism of action.
I would love to get into why looking at porno is not even in the same universe of danger as lead poisoning, but I've spent weeks trying to explain harm comparison to people that genuinely think high schoolers using social media is the same thing as them using cigarettes and heroin and I'm just exhausted.
Aerroon | 21 hours ago
Eg "if you ban cellphones in schools then average test scores (on tests like PISA) will substantially improve". Or something else like that.
>This broad rejection without good reasons is borderline sociopathic.
It's sociopathic to not want the people in control to constantly make up new arbitrary rules? I guess we just need a few more Patriot Acts and Snoopers Charters.
forgetfreeman | 21 hours ago
trinsic2 | 19 hours ago
This is only going to cause things you describe to get worse and the U.S. government is complicit in this because we have a two party system that works directly or indirectly for the establishment.
I'm not sure if you are encouraging more government intervention, but its clear this is not working. Its like going to a criminal gang and asking for security while they ransack your community and charge you for it.
forgetfreeman | 16 hours ago
trinsic2 | 13 hours ago
Governance only works when it represents the people, that is not what this government does right now and no amount of electing the right candidates is going to fix that until we have those two issues addressed.
soraminazuki | 14 hours ago
It's like saying we should install Flock cameras everywhere so that we can protect consumers from buying harmful products. Corruption and mass-violation of human rights is all that's ever going to come out of it.
If the goal is to stop predatory companies, why not do so? Oh right, because that was never the goal.
tardedmeme | 9 hours ago
soraminazuki | 5 hours ago
It's also the tired old argument that's constantly raised by encryption ban/backdoor proponents too. How many times do they have to be debunked, ugh.
If you're against the EFF on these kind of issues, it's typically a good time to reevaluate your position.
https://www.eff.org/issues/age-verification
iugtmkbdfil834 | 21 hours ago
- keeping class sizes small - keeping class within similar development range ( AP with AP. short bus with short bus )
None of it is a secret, but government can't (edit:or won't) make it happen. Hence regular people just doing the best they can within the system at their disposal.
zdragnar | 20 hours ago
It's why some schools in (iirc) California did away with higher maths like calculus entirely.
Sadly, it seems there's nothing actually common about common wisdom.
iugtmkbdfil834 | 20 hours ago
galangalalgol | 19 hours ago
coryrc | 19 hours ago
galangalalgol | 5 hours ago
coryrc | 3 hours ago
Socialization doesn't have to solely occur in an academic classroom.
burnte | 20 hours ago
> like your "sink it" nugget, they lack decent problem descriptions
Let me be clearer then: The legislation has passed but it is 100% possible to repeal that law. And it should be repealed, and we need to not let up pressure on California until it is rescinded. It was a bad law that was not thought out at all and fails to solve any problems.
I'm not worries about corporate feudalism and app age checks.
I'm not sociopathic, you're just making broad assumptions.
chickensong | 19 hours ago
saghm | 11 hours ago
hansvm | 21 hours ago
[0] I also know home-schooled people whose parents are far better than any teacher I've ever had and whose education and achievements reflect that obvious fact. Home-schooling itself isn't the issue, and I'd prefer that it remain possible.
burnte | 20 hours ago
coryrc | 19 hours ago
The home-educated typically score 15 to 25 percentile points above public-school students on standardized academic achievement tests.
-- https://nheri.org/research-facts-on-homeschooling/#Academic
tcfhgj | 18 hours ago
First independent search result:
> The US-based NHERI describes itself as a leading research institute in the field of homeschooling. However, its neutrality is often questioned.
in_cahoots | 17 hours ago
coryrc | 14 hours ago
in_cahoots | 3 hours ago
In all three scenarios (but especially in the first two) there is a sizeable population of parents who know their kid is several years behind grade level, but they tolerate it because they think kids learn at different paces. Or that it's fine for a kid to love one particular thing (cooking, machine repair, art) at the expense of a well-rounded education. And that's not even getting into the 'unschoolers' who treat never opening a textbook as a point of pride.
If you're well-educated and run in circles of people like you then you'll find the homeschoolers who also value education. But if you expose yourself to a wider variety of people your conclusions may change.
Analemma_ | 17 hours ago
platevoltage | 16 hours ago
stinkbeetle | 19 hours ago
Anecdotes like this don't help the case much when government schools in a lot of places "graduate" large proportions of their pupils who are functionally illiterate and innumerate. Then you get misconduct, bullying, abuse that goes on in government schools. Who should "step in" on the government?
Home schooled people do fine, statistically.
saghm | 11 hours ago
Back on the first hard, I'd argue that most of those people might have benefited from having more access to the internet, as it sounds like at least part of the problem was that they had severely limited experience for how to navigate the world outside of small amount their parents allowed them to be exposed to. I'm on board with the government being involved in ways that are beneficial, but "make anyone using an internet-connected device plug in their ID first" just feels like an absurd overreach for what it's trying to solve.
codedokode | 21 hours ago
echelon | 21 hours ago
The potentially all-powerful government shouldn't know:
- what vices a person has
- what religion a person has or doesn't have
- what porn you watch
- what alcohol and drugs you buy
PERIOD.
All of these things can be exploited. To control jobs, to control finances, to extort influence, to shape ideology, etc.
The government shouldn't be able to catalog those things in a database for later misuse.
The government shouldn't be able to install friction or barriers that make it easy to cordon off and kill these things at a later time.
The "think of the kids" argument can go to straight to hell. Nobody's having children anyway.
This is a very real (not logically fallacious) slippery slope right into the pages of 1984.
It's not about kids. It's about control over society as a whole. They're going to force you to use your ID to access the internet, force you to use an approved device, and the minute you step outside of allowed behavior, you'll be punished.
Shackles and telescreens are coming, and they're using this argument to build it.
stouset | 21 hours ago
dpkirchner | 17 hours ago
stouset | 15 hours ago
xorcist | 20 hours ago
Would it be acceptable for a private company to own this information? Perhaps sell it to others?
girvo | 20 hours ago
Private companies should also be regulated with regards to data sales of private information, yes.
CJefferson | 15 hours ago
Are you suggesting we remove current laws making it illegal for children to purchase these things?
saghm | 11 hours ago
That's besides the point though because this legislation doesn't check people's IDs when they're trying to purchase porn or alcohol, but as soon as they walk out the door, and if they refuse to show it, they have someone following then around even if they just go to the ATM and to the doctor.
echelon | 3 hours ago
With online services, there's no way to ensure your information isn't permanently stored and associated with the transaction for later misuse.
saghm | 11 hours ago
xorcist | 20 hours ago
We really can't have it both ways, that every failure of the child is blamed on the parent for lapsing in their almost totalitarian oversight, while also idealizing the idea that children must make their own mistakes and gradually growing into responsibilities and self-governance. Except having access to the Internet, apparently.
Taking a step back, this all smells like madeleines and a yearning for the good old days when everyone rode bikes and nobody owned smartphones. That's not really a productive stance on anything.
(If you would ask me, and I'm sure nobody would, I would think that there is a sort of trade-off here but with a clear answer: Make clear restrictions about buying cigarettes, alcohol, abusive content and extreme porn. But these restrictions aren't meant to be technically perfect. It's ok that some kids will learn to lift the limits and explore what is forbidden. At least then they would know that there is some reason society collectively considers these things off-limits, and that they soon will be in a mistake of their own making.)
ekr____ | 22 hours ago
It's useful to contrast this with the various device-based mandates that have been created in order to get a sense of what legislators seem to be trying to do. With that in mind, a few points:
* What you are proposing allows parents to opt in via parental controls, but age assurance mandates (both device-side and server-side) tend to require positive action to enter unrestricted modes. In some cases (CA AB 1043, for instance), this is just a matter of entering your age. In others, you actually need to demonstrate your age via some technical mechanism.
* While many age assurance mandates focus on adult content, which is primarily consumed via the Web, others (e.g., Australia's Social Media Minimum Age) focus on social networking, which is primarily consumed via apps, so anything that is Web only will not be effective.
* Site-level granularity isn't really fine enough in some cases. For example, the New York SAFE for Kids act prohibits certain behaviors such as algorithmic recommendations when a user is a minor, but doesn't require blocking minor usage entirely. It's potentially possible to implement this with something like RTA, but it would have to at minimum be at much finer granularity.
Section VI of https://kgi.georgetown.edu/wp-content/uploads/2026/01/Age_As... goes into quite a bit more detail about various architectures (disclaimer, I'm an author).
None of this is an endorsement of age assurance techniques; I'm just trying to help flesh out the situation.
> All legislation regarding age verification must revolve around this otherwise people must reject it as an abusive form of tracking and privacy invasion.
It's a bit late for that, given that around half of US states already have some kind of age assurance mandate.
Bender | 22 hours ago
Perhaps late to solve this globally but parents can still install parental control software if they so desire and can still intervene locally to prevent sharing data with 3rd parties. At worst this means small children might not get to visit social media and other assorted sites and I am fine with that. I think a number of parents would be fine with that as well.
Sites can voluntarily label as some do. It just means that parental controls would have to default to blocking everything until approved and while sub-optimal maybe that's what people will have to do in order to avoid the evil pattern of sharing data with all the websites that will ultimately leak, or "leak", be sold, stolen, etc... Good parents will not participate in the evil patterns of sharing their children's personally identifiable information.
When the PII of children is ultimately shared with evil people the children once adults will resent their parents for not protecting them.
- To all parents here, your children have no idea what risks are out there including devious companies that want their data. They will one day be adults if all goes well. Protect your children as corporations and governments will not. They will thank you when they find out all their friends data was shared, leaked or otherwise abused forever.
ekr____ | 21 hours ago
Certainly parents can install parental control software, but what does this have to do with children's PII being shared with sites?
Just so we're on the same page, the way AB1043 works is that the OS determines the user's age and then shares the age bracket with apps. No PII is shared with sites (this is not to say that the age isn't sensitive, but it's not PII as usually regarded). Is your concern here that sites get access to children's information because children visit certain sites regardless of legislation? That's a real thing, but it seems mostly orthogonal to age assurance.
Bender | 21 hours ago
The parent can block or just never approve all the sites that require PII.
but it's not PII as usually regarded
We will never agree here. All the companies I worked for financial considered any attribute of the person to be PII, even their IP address. We were audited very strictly on this. If a users age was disclosed to a third party without their written consent that was a contract violation and came with severe monetary penalties. Parents should expect this to be the minimum standard. It's their children, not the corporation or governments children.
ekr____ | 21 hours ago
Again, this isn't an endorsement of these mandates; I'm just saying that what you're proposing here doesn't address the objectives that policymakers who are in favor of these mandates are trying to achieve.
Bender | 20 hours ago
Oh trust me, I get it. They and I will never align. I know I am beyond beating the dead horse. It's gone from bone dust to micronized dust to sub-atomic particles to sub-quantum particles at this point. That poor horse will never be forgotten. Perhaps it is an illness on my part but I will find a way to bring this up every time until the year 2150 after which point this will be the least of anyone's concerns.
codedokode | 21 hours ago
Instead, the default should be, that if there is no header or it cannot be parsed, then the content is unsafe. And if there is a header, it describes the page rating, like what kind of dangerous content it may contain. The header may be added to any displayable content like HTML, text, images, audio or videos, but not to machine-readable content like JS files or AJAX responses.
So only those who wants their site to be accessible by minors, have to add headers. For social networks, the user might have an option to mark his content as "safe".
This means that with my proposal existing site operators need not to do anything to mark their sites as "unsafe" - all sites are "unsafe" by default. This means that millions of site operators need to spend 0 dollars to adapt their sites. How great is that?
The browser on a device with parent mode, should not allow displaying any content which doesn't have a header or that is marked as unsafe, or that contains header with invalid value. The parents may whitelist some sites.
There should be a reponsibility for intentionally marking unsafe content as "safe". We should also think what to do with foreign operators, intentionally putting invalid headers for unsafe content. Maybe they should be added to some kind of blacklist that the browsers would periodically update.
Search engines like Google could work by default in "safe" mode, but add "unsafe" header if the user wants to turn off restrictions.
> If a site is not adding the RTA header then progressively fine them into oblivion.
I think my proposal is better because it requires only fining those who intentionally misrepresent content safety.
Bender | 21 hours ago
Parents today can accomplish what you are suggesting by installing parental control software and only allowing access to things they explicitly approve.
This can also be done via headers explicit blocking of all the things and was suggested in another thread. [1] Some people liked the idea.
[1] - https://news.ycombinator.com/item?id=47952999
codedokode | 21 hours ago
Bender | 21 hours ago
Adding a header to a web server or load balancer or app server if done globally can be done in a minute or two. Maybe 5 minutes for the intern not counting QA testing.
But you are right, the inverse is easier. I like that too. That was debated in the other recent thread.
[1] - https://news.ycombinator.com/item?id=47950091
farley13 | 20 hours ago
That said, outside of the merits of this approach, I am dubious of any actual implementation given 2 points.
1) Protecting the youths will always be a leaky bucket. With disadvantaged youths possibly more at risk. Those exposed to non-compliant parents ("cool" parents who are ok with sharing unsuitable content) or lacking strong parental involvement, likely won't benefit a great deal from any implementation.
2) Anti privacy social networks stand to gain the most from targeting ads utilizing signals from most child safety acts. They also might be able to reduce some costs from moderation if they can make it someone else's problem. I'd argue the net social impact from these social networks is likely both more normalized and strongly negative for our youths than any smut.
On the balance I'd say we are better off investing our energy in other places.
nodar86 | 20 hours ago
Or simply parents who won’t agree with the government on what is suitable for their children.
We already have parental control on all mainstream operating systems, why cannot this simply be the responsibility of the parent as are so many other things regarding what children do, watch, eat etc?
throwaway173738 | 20 hours ago
wizzwizz4 | 19 hours ago
tardedmeme | 19 hours ago
nemomarx | 19 hours ago
Ajedi32 | an hour ago
Bender | an hour ago
None of that is true. Not even close. It will work if there are laws with big teeth as the government can have contractors that scan for the header. Header missing? Adult content? User provided adult content even if it violates the rules? Well darn, there goes 10% of revenue. Also it is not "this is a porn site". RTA stands for restricted to adults. That can include literally anything that is not appropriate for small children including but not limited to social media, forums, gallery sites meant to be SFW but users content is not pre-moderated meaning people can see it before a moderator does. What Restricted to Adults ultimately means will depend oh the laws behind it.
Ajedi32 | 55 minutes ago
An actually useful standard would need to be much more granular, and be designed as a whitelist not a blacklist, as I and previous commenters said.
[1]: https://wiki.whatwg.org/wiki/MetaExtensions#:~:text=Restrict...
[2]: https://webmasters.stackexchange.com/q/140733
xoa | 21 hours ago
I'd actually go somewhat further though and ask whether it's a good idea to even do this via web pages at all. We have a great potential system for this already: DNS. Do something useful amongst all the ridiculous vanity and spam TLDs for once and set up a ".kids" gTLD, or ccTLD for that matter so that different countries can set their own regulatory standards naturally (ie, .kids.us, .kids.uk etc). Domains could also be used for some broad buckets for people who don't want to drill in, ie, .1-6.kids, .7-12.kids, .13-17.kids, or whatever is deemed appropriate, but simple age brackets that would offer some sane defaults. 1-6 could simply not allow any ads, user generated content or algorithmic feeds whatsoever for example. There are a lot of knobs to turn. And then at the registry level it can be ensured from the get-go that anyone getting a .kids domain is fully identified, located in the country in question, has valid ID, has specific credentials or is an accredited organization, or whatever other criteria makes sense.
But ultimately the point would be to create something that is built right from the ground up, and in turn that doesn't interfere with what has already been built at all. Something that can also be worked with at the gateway and thus cover every device on a LAN, and for that matter can easily be plugged into the vast number of powerful tools we have for working with that stuff. It'd be easy to put a nice UI on all this, even to make it higly automated. For example, have a setup wizard where you enter children, put in date of birth for each, and it'll spit out a password for each one. This then auto-provisions the network such that each kid has their own VLAN (password for PPSK or even wired connection) and is automatically limited to the domain groups of their age bracket, which then changes as their age changes.
Parents should be able to dig further in and get more granular with content categories, metadata for which could be required for anyone hosting a site within that domain, but I think there is the potential to make something both pretty bullet proof and pretty accessible, using existing tech stacks, and without impinging on the present internet at all including privacy and anonymity.
lokar | 20 hours ago
And, if we are going to do this the “design” should be global and anticipate a range of cultures.
l72 | 18 hours ago
If a site is really mixing so much content (like Reddit) then they should really be separating their sites into different subdomains.
lokar | 15 hours ago
bruce511 | 16 hours ago
The vast bulk of the internet is child neutral. For example my church a web site, the bakery down the road has one, the local pro sport team has one. They're not designed "for kids", but kids are welcome.
Does StackOverflow need to register a .kids domain just so children might get answers to programing questions?
If my-bakery.co.uk and my-bakery.co.au both want to be visible to 16yo there needs to be at least kids.uk and kids.au.
Does OpenSSL.org or OpenSSL.com get to be OpenSSL.kids?
Sorry but duplicating the entire neutral internet domain space with yet another tld isn't a helpful approach.
thecrash | 13 hours ago
Instead of running their own websites, they'll migrate to a platform like Facebook. That way Meta handles the burden of moderation and the legal complaints for the inevitable moderation failures.
xoa | 7 hours ago
I surprisingly seriously disagree, and think you're perhaps missing a lot of the contention in this whole societal debate. The point is to give people workable tools with some level of agreed sane defaults they can make use of, tweak, or ignore entirely, without imposing any burden at all on the existing internet and its adult (or children with parents who wish it) users.
>The vast bulk of the internet is child neutral
First: by who's standards is one of the core questions! What's neutral to one parent may not be to another. You illustrate this with your very first example in fact, "For example my church a web site". There are religious parents (and no doubt atheist ones as well) who would quite strongly not want their young child to visit your church's website.
Second: there is a difference between simply wanting to be child friendly and taking on a legal obligation and liability to be child "safe" to some given standard. Parents would be perfectly free to whitelist whatever additional sites they liked, or to subscribe to lists that curated whitelists of various sorts, or to use other controls. But a politically significant number of parents clearly want assurance that their child will near-never (with actual enforcement mechanisms for failure) encounter something outside of bounds. Meeting that need requires either whitelists or the sort of restrictions that would wreck the current web (and probably still not work very well).
>Does StackOverflow need to register a .kids domain just so children might get answers to programing questions?
If the parents of said kids want it to, then yes? Why would that be a big deal? I'd be surprised if like most places SO doesn't already have piles of domains purely for defensive purposes, and as something nationally regulated I certainly envision such a domain registrar being dirt cheap (or even free, paid for by tax dollars) for domains. Given the context and that it'd be very much not open to all there isn't any need to worry about cost to dissuade scammers and such, they'd be prevented from ever registering in the first place. Rules around use of trademark, business names and so on could also be very strict.
>If my-bakery.co.uk and my-bakery.co.au both want to be visible to 16yo there needs to be at least kids.uk and kids.au.
Yes? DNS is not expensive. And again, parents don't need to make use of it. This would be for those who do, who are right now pushing for ID for everything. It's a safe default walled garden, but one with doors any parent can open.
>Does OpenSSL.org or OpenSSL.com get to be OpenSSL.kids?
Which one chooses to get accredited by a regulator or child protection organization with insurance and so on first? Why are you asserting either would even bother? Which one would be happy about having to verify ID of users right now?
>Sorry but duplicating the entire neutral internet domain space with yet another tld isn't a helpful approach.
Sorry but you haven't thought about this very clearly at all. This proposal is very explicitly a small subset of the entire neutral internet! Duplication is never something I suggested, rather the very opposite! The "entire neutral internet" is by default adult here, but parents would be able to allow children to browse it just as now. However, some are clearly unhappy with that, enough that we're seeing politicians respond with things that would be very bad.
lokar | 20 hours ago
californical | 18 hours ago
Websites by default are ‘true’ for every category, unless they specify.
Categories are, for example of some: nudity, sexual, violence, etc.
It doesn’t have to be perfect but sites will have to err on the side of caution.
We could even create an html tag <restricted type=violence> for example, and the browser can simply not render that portion of the page of the user has that type disabled.
And we could give companies a pass for best-effort categorization using tech to assess user-generated content, along with allowing users to flag their own content as “safe”
lokar | 16 hours ago
The goal should be to satisfy most reasonable governments. A neutral technical standard and an international organization to maintain the the ontology for content descriptors
californical | 13 hours ago
tardedmeme | 9 hours ago
l72 | 18 hours ago
The only hard part for the web is that a site could lie since there is no gatekeeper, but some black lists can help with bad actors.
lokar | 16 hours ago
Ajedi32 | an hour ago
fc417fc802 | 17 hours ago
There's no reason a simple, standardized header can't be used to communicate any number of classifications simultaneously.
Edit: It occurs to me that if you oppose all age related measures then my above response isn't entirely fair to you. I still think it's an absurd objection but the comparison I made no longer applies.
lokar | 16 hours ago
fc417fc802 | 16 hours ago
What we need regulation to provide (IMO) is a reliable way of doing that.
SoftTalker | 13 hours ago
Sites can choose to have unrated content (adult movies) and those are only available on devices without an enabled parental control option (adult-only theaters).
fc417fc802 | 13 hours ago
A solution would be browsers refusing to load any site that didn't provide such metadata, not just in child mode but in any mode. I suppose either Apple or Google would likely be capable of unilaterally imposing such a requirement as things currently stand. However I also think that's unlikely to happen on its own for various reasons. Thus legally mandating certain basic content classification categories in addition to an extensible standard protocol for communicating such metadata would (I expect) end the cycle. And rather than the government going after individuals the legislation could be structured to place the onus on mainstream browsers, OSes, and other client software to enforce compliance on their behalf.
SoftTalker | 13 hours ago
Fine. It probably should be, if sites don't want to bother cooperating.
fc417fc802 | 13 hours ago
lokar | 3 hours ago
Ajedi32 | an hour ago
Terr_ | 16 hours ago
For example, it would be insane if every website and blog in the world to had to run logic to detect and prevent Elbonian males under 16 lunar years from seeing ankles except on Thursdays.
fc417fc802 | 17 hours ago
The core problem is the lack of buy in. Unfortunately that likely needs to be forced. I think it's not unreasonable to legally require people to make a claim about the nature of what they are serving up. They already need to be aware of the legal status of what they're doing anyway so it hardly seems as though making such a determination should pose a burden when you consider that it's an alternative to either requiring ID, requiring the client send age bracket information, or other heavy handed interventions. The choice here isn't "the status quo vs a header" but rather "some other age related regulation vs a header".
An easy way to enforce this "voluntarily" (ie coerce) without sending government agents after every small time website operator would be to require that mainstream browsers and other client software (based on MAU or similar metrics) refuse to process content that does not send a classification header. Doesn't matter what the header says or what the status of the user account or parental controls or whatever else is, it has to send the header regardless or it will be blocked without exception. That would presumably trigger broad compliance with the relevant regulations.
iamnothere | 17 hours ago
What about spoken words?
What makes online speech different, from the perspective of the Constitution that limits the power of the state?
fc417fc802 | 16 hours ago
What I've described does not restrict one's ability to speak freely. It is most similar to an impressum except it bears no identifying mark thus poses no hazard to anonymous speech.
iamnothere | 16 hours ago
Mandates on how speech must be structured are a violation of freedom of speech, Constitutionally speaking.
“Redressing a concrete dysfunction” does not appear in the Constitution as an exemption to guaranteed rights, as far as I am aware. The proper remedy for this kind of problem is an Amendment, assuming you can get enough people to agree with your assessment.
fc417fc802 | 14 hours ago
By your own logic would online ID laws not also be a constitutional violation? Ditto for age bracketing laws such as the one under discussion here. After all, they both effectively regulate one half of the exchange necessary for meaningful communication (ie protected speech).
> Impressums cannot be required in the US
Yes but why can't they be required? My (quite possibly flawed) understanding was that SCOTUS previously established that publishing without attribution could not directly be outlawed, recognizing the ability to speak anonymously as an important aspect of political speech. What I have described does not run afoul of that. It neither restricts one's ability to speak nor provides for any form of attribution.
> “Redressing a concrete dysfunction” does not appear in the Constitution as an exemption to guaranteed rights
Regardless of either your or my personal opinion SCOTUS routinely makes exceptions to constitutional rights when a compelling need is presented and the remedy is sufficiently targeted. That said, I don't believe that what I described infringes on the first amendment to begin with so your point is doubly moot.
iamnothere | 5 hours ago
Now you’re getting it. Throw them all out along with the idiots who passed the laws.
> Yes but why can't they be required?
The Court has interpreted compelled speech to be almost universally a violation of the First Amendment, outside of the courtroom. I tend to agree. “Shall make no law” is a strong statement.
> SCOTUS routinely makes exceptions to constitutional rights
Prior courts. The present Court seems to be (rightly) rolling back both judicially-granted overexpansion of rights and exceptions to rights, although this is a slow process.
We have to stop relying on the courts to grant new rights and/or exemptions to rights. Passing unconstitutional bills and hoping for a favorable interpretation is clearly not the intended process, yet it’s become increasingly common.
We need to figure out how to pass amendments again or we are going to lose our republic. (It may already be too late due to an out of control executive and corrupt Congress, but that’s another matter.)
fc417fc802 | 5 hours ago
We require for example nutrition labels on food products. So clearly metadata of various sorts can be required for an interaction within the marketplace if there's a good enough reason for it. I'm not sure where that leaves personal blogs but it certainly applies to Amazon and PornHub.
The present court is rolling back some things but certainly not all. From the very beginning constitutional rights have never been absolute. One of the basic principles that comes up repeatedly and supersedes almost everything else is that the government must be able to carry out its duties. The contention is generally whether something is truly necessary for that and if so whether the law in question is overly broad.
iamnothere | 5 hours ago
Marketplace being the key word here. Interstate commerce may be regulated.
> I'm not sure where that leaves personal blogs but it certainly applies to Amazon and PornHub.
That’s the point. I also care about restrictions on smaller businesses and want to prevent regulatory capture, but personal/nonprofit/community sites must not be burdened above all else. They face enough challenges as it is. If a website or software project is noncommercial, their speech is not subject to regulation, Constitutionally speaking. What’s more, the Constitution has the correct take here—this is as it should be.
> One of the basic principles that comes up repeatedly and supersedes almost everything else is that the government must be able to carry out its duties.
Then you get the question, what are its duties? Enforcing unconstitutional laws is not one of them.
jamespo | 3 hours ago
SoftTalker | 14 hours ago
iamnothere | 5 hours ago
“We” (as in the US government) do not do this. There is not, nor can there be, a law requiring such rating.
> we don't allow children into liquor stores, strip clubs, or adult bookstores
These are physical stores/venues, not written speech. “We” do not restrict authors from writing adult books that may or may not be seen by children, nor do we require that the books are labeled as such.
If you want to restrict speech, pass an amendment. That is the allowable path.
paulddraper | 15 hours ago
Also, FWIW, 18 U.S.C. § 2257 applies to printed books as well as online content.
But pure text literature (physical or online) isn't as regulated as visual media.
AnthonyMouse | 13 hours ago
That's something the client should be doing. You can configure your own device (or your kid's) to have whatever default you want.
The actual problem is that classifying the entire firehose of user-generated content is precarious and uneconomical, so the default tag is going to be whatever minimizes liability. If untagged implies "unsafe" and "unsafe" minimizes liability then the majority of content will be untagged. If untagged implies "safe" then the majority of content will end up explicitly tagged as unsafe, because tagging it as unsafe minimizes liability.
But either way if you disable "unsafe content" you'll end up disabling almost everything, specifically including the huge amount of "safe" content which isn't tagged as safe because accurately classifying it is uneconomical.
bsdetector | 2 hours ago
Ultimately the problem is the provider knows what category the content is and the parent knows what the content policy is. Providers can't say whether it's "safe" or "unsafe", only what standards it complies with. Some parents will have weird policies like "only G-rated movies or any Jim Carey movie" that can't even be delegated in any reasonable way to providers.
So the header has "PG-13, US-legal" because it's a movie rated PG-13 and constitutionally-protected legal content in the US, and whatever other markets you want to open up. Providers could even include AI ratings so as to mass-tag their content at low cost, and parents can decide if a particular AI rating is okay.
Parental controls could even restrict official ratings to country of origin, so if you approve PG-13 it'll block that content from countries where you can't sue them for lying about it.
BobaFloutist | 54 minutes ago
tzs | 21 hours ago
Your cite is an earlier post of yours which says
> The one and only method I will participate in is server operators setting a RTA header [1]
and that cites a still earlier post of yours
> I stand by my repeated statements of how this could have been solved simply using an RTA header [1]
which finally actually cites¹ something that explains what the heck on RTA header is.
It would be quite a bit more reader friendly to cite https://www.rtalabel.org/page.php rather than make the reader traverse a linked list of comments to get there.
¹https://www.rtalabel.org/page.php
lxe | 20 hours ago
Bender | 20 hours ago
They can't do anything today as it is a federal holiday but they could do something tomorrow.
gsich | 20 hours ago
kube-system | 10 hours ago
daemin | 15 hours ago
This could all be handled by settings in the browser, only if the sites themselves listened to the users' browser preferences.
vincnetas | 13 hours ago
tyre | 11 hours ago
It makes a bit of sense, since the mailer had already paid, but the main justification (iirc; it was years ago that I read the opinion) was that a postal service should be neutral and trusted to deliver.
tardedmeme | 9 hours ago
Geezus_42 | 6 hours ago
dessimus | 5 hours ago
The companies on the ads wouldn't do it that way if they were not getting a positive ROI from it. They probably only need to get 2 maybe 3 new customers to offset the cost of mass mailings.
metiscus | 5 hours ago
cool_dude85 | 5 hours ago
d1sxeyes | 9 hours ago
Should USPS be required to respect that owners wishes here?
Sensible decision I think.
andyferris | 7 hours ago
The user agent should... be an agent for the user, and be able to perform actions on their behalf.
(The legality of those actions is of course assumed by the user here... if I add an automated flamethrower to my mailbox and burn my bills, well the debt collectors may come regardless if I read them or not - we cannot shift blame to the USPS here).
SiempreViernes | 6 hours ago
The second argument has the problem that for the whole thing to work the recipient must also have reason to trust the post office, but here their interests are not considered at all.
olalonde | 10 hours ago
shakna | 9 hours ago
olalonde | 6 hours ago
jabwd | 9 hours ago
theknarf | 9 hours ago
bragr | 3 hours ago
whywhywhywhy | 8 hours ago
Ultimately there’s no good excuse for the banner solution.
kqp | 15 hours ago
AnthonyMouse | 13 hours ago
The problem is that people generally want functional and often performance cookies, and then you end up with the stupid cookie banner regardless of marketing cookies.
kqp | 12 hours ago
AnthonyMouse | 8 hours ago
To not be indistinguishable from "strictly necessary" there would have to be a case where the "functional cookie" actually required consent, right? What case is that and how would you solicit that consent other than some kind of cookie banner?
> “Performance” actually refers to analytics, probably rebranded because users did not want it.
It refers to statistics, but sometimes you do want that, e.g. so the site can tell you how long it took you to do something compared to the average user, or provide those analytics to you. And the fact that this is ambiguous is an obvious problem -- if you get access to the data they collect is that "analytics" or "functional"?
In the face of an ambiguity, most corporate bureaucrats are going to take the risk-averse option, which is to ask for consent in case it turns out to be adjudicated as required ex post facto. The result is quite predictable. If you pass a poorly drafted law, businesses have a general preference for doing something stupid/wasteful/annoying over something that could get them sued or fined.
kqp | 3 hours ago
The case is when you don’t use that feature.
> how would you solicit that consent other than some kind of cookie banner?
Using the feature that requires the cookie is considered consent, same as using the website is considered consent to set cookies actually necessary for the entire website to function. For example, if you click “save settings”, that’s consent to save those settings, there’s no need for a “but am I allowed to save settings?” popup.
You might be tempted to dive into the potential grey area here, and sure, one exists, but (a) that’s why the laws go into 1,000 times more detail than this HN comment, (b) most of it’s not in the grey area, and (c) even in the worst case, making 100% sure is as easy as a checkbox before the button that activates the feature, there’s never a requirement for a blanket “can we do whatever we want” before even displaying the homepage.
> It refers to statistics, but sometimes you do want that, e.g. so the site can tell you how long it took you to do something compared to the average user, or provide those analytics to you. And the fact that this is ambiguous is an obvious problem -- if you get access to the data they collect is that "analytics" or "functional"?
The GDPR calls it “statistics”, but in this context defines the word to mean analytics, not statistics shown to users. If it’s shown to users then it’s either strictly necessary or functional.
> In the face of an ambiguity, most corporate bureaucrats are going to take the risk-averse option, which is to ask for consent in case it turns out to be adjudicated as required ex post facto. The result is quite predictable. If you pass a poorly drafted law, businesses have a general preference for doing something stupid/wasteful/annoying over something that could get them sued or fined.
Businesses are generally risk averse, yes, but don’t mistake knowing a force at play for knowing them all. The “cookie consent banner” was invented and evangelized not by the laws they’re commonly believed to have sprung from but by the IAB, an ad industry consortium counting Google, Facebook, and many others as members. The same organization that organized efforts to prevent third party cookie blocking, and that tried to block the GDPR entirely. The banner norms they created did not even comply with the law until changes a few years ago, the EU just took its sweet time on enforcement.
The average small business, of course, is not in on some grand scheme, but this is where your risk aversion comes in: if all the big players are doing something, and everybody around you is doing it, and you Google it and the first 20 results all say to do it, then the risk averse move is of course to just do it and move on. After all, trusting your own judgement is scary, what if you get sued or fined?
SoftTalker | 14 hours ago
ClikeX | 11 hours ago
compass_copium | 6 hours ago
LtWorf | 14 hours ago
LtWorf | 9 hours ago
d1sxeyes | 9 hours ago
ClikeX | 11 hours ago
olalonde | 10 hours ago
freehorse | 6 hours ago
For example, firefox's "strict tracking protection" setting also breaks a bunch of websites.
miki123211 | 2 hours ago
The former are things like "does the user want dark mode", the language you chose to use the website in, the contents of your cart, your login info etc. The latter are for tracking. Typically, the former don't need consent, the latter do. Browsers have no way of telling the two apart.
axelthegerman | 9 hours ago
But then again if it was to protect children, better support for voluntary age control would be so much more useful as most minors use devices managed/owned by their parents.
But then similar to cookie banners it is just about enabling surveillance
akdev1l | 5 hours ago
Do binary search and you don’t even need that many calls.
1. Is person older than 50? 2. Older than 25? 3. Older than 18? 4. Older than 9? 5. Younger than 14? 6. Older than 16?
Joker_vD | 5 hours ago
no_wizard | 3 hours ago
It’s not written the way it’s written because they’re oblivious it’s written the way it’s written because it’s plain lobbying writing the bill.
For example, there’s little in the way of protections in how the age verification would be protected or prevent the analytics from being sold
miki123211 | 2 hours ago
vetrom | an hour ago
Combine that with the character of practically every law written involving data privacy, use, IP, and associated regulation of activity around these since the 1990s. It becomes painfully clear that the interests of private citizens have not had a seat at the table, and the Constitution has been taken as an inconvenience to bypass, not a guiding document.
kelnos | 16 hours ago
The entire site shouldn't be blocked; the browser needs a way to tell the website "my parental controls are enabled and I need to you to filter out age-restricted content".
Alternatively, the RTA header/meta could include a parameter/attribute for an "alternate URL" to load when parental controls are enabled. This could be useful to allow sites to present a custom error-type response, but could also be used to automatically redirect the user to similar, but age-appropriate, content.
Anyway, this all ignores the fact that "protect the children" isn't really the goal here: it's to slowly eat away at our ability to be anonymous (even read-only anonymous) on the internet. Age verification is just a watered-down way of saying they require positive identification, and eventually our hardware will have to cryptographically attest we are who we say we are. I really hope this isn't inevitable, but it's starting to feel that way.
Ajedi32 | an hour ago
That could be a fingerprinting vector though so maybe depending on privacy settings it just blocks the page. Really these are all solvable problems that web standards orgs have dealt with before; you just need to create the incentive for such systems to exist.
idiotsecant | 14 hours ago
pkphilip | 14 hours ago
If Meta, Google etc could easily have algorithms in place for determining the age of the person seeing the video - apart from having the override capability via a parental login as you have stated.. but these platforms have consistently refused to limit the type of content they are showing to children.
maccard | 10 hours ago
teekert | 11 hours ago
raxxorraxor | 11 hours ago
This can also be broadly implemented, any other technical solution won't be widely spread anyway.
I don't think authorities care about child protection though. They could have legislated malicious advertising practices and a lot of similar bad influences, but didn't.
bawolff | 11 hours ago
Seems like this would incentivize just all sites to have the header regardless of if it meets the definition since you get fined if you dont but no fine if you have the header unneccesarily.
Especially if your definition is contains user contributed content. That is all sites with a comment field. What really is left? I'm not sure i have even visited a site in the last month that wouldn't fall under this.
tardedmeme | 9 hours ago
kleiba2 | 8 hours ago
miki123211 | 3 hours ago
1. This assumes that websites are under your jurisdiction and can be fined. This is not a valid assumption on the internet. If you want to do this, you need a framework to block noncompliant websites via ISP-side null-routing, putting pressure on payment processors and hosting companies which do operate in your country etc.
2. HTML tags and not HTTP headers. If just a small part of the site contains content which shouldn't be displayed, the web browser should just hide that part.
3. Sometimes, it is genuinely useful to know the user's restrictions ahead of time. Imagine you're a movie streaming site or game store. You have some content which is suitable for the user, no matter their age, but you need to know which bracket they're in to decide what to show them. Without that info, you either default-adult (which sucks for children) or default-child (which sucks for adults).
raxxorraxor | 2 hours ago
The problem of hosts in countries that don't give a shit is true for every solution aside from the great all blocking firewall no developed nation would want to have. So no to "ISP null routing" from me. ISPs provide infrastructure. They are not school teachers.
Such a solution implemented today would be tunnelled yesterday and everyone should support evasion attempts.
Bender | an hour ago
softwaredoug | 23 hours ago
Refreeze5224 | 22 hours ago
dylan604 | 22 hours ago
account42 | 9 hours ago
anubistheta | 18 hours ago
softwaredoug | 17 hours ago
Banning or limiting addictive features like algorithmic feeds would be regulating the companies.
jeroenhd | 12 hours ago
Desktop and mobile Linux is an extreme niche and alternatives to Linux are practically nonexistent. I'm not surprised law makers might not have known that there are operating systems not made by for-profit companies.
dnnddidiej | 23 hours ago
jmclnx | 23 hours ago
pessimizer | 23 hours ago
cwicklein | 17 hours ago
cortesoft | 23 hours ago
Really, my main complaint comes down to: I completely disagree with what these services choose to restrict for kids and what they allow.
They block my kids from doing things I have no problem with them doing and they allow things I would never want my kids to do in 1000 years. It is incredibly frustrating.
Often times, there is literally no way for me to bypass some stupid restriction they put on my kids, so the only way I can get it to work is to help my kids lie about their age… and at that point, I lose the ability to actually block things I care about.
These laws are just going to make it worse. I don’t want someone else choosing how I control what my kids do. Give me tools to control it myself, and you can choose some presets for parents to use, but don’t force me to use your definition of age appropriate.
alpinisme | 23 hours ago
themafia | 23 hours ago
Do you want to alter behaviors or lock children in a gilded cage?
cortesoft | 23 hours ago
My main thing is I want to be able to opt in or out of various filters. I don’t mind if my kids want to listen to music that has swear words, but I don’t want them watching videos where they give horribly sexist pickup artist advice.
This isn’t just about what I feel is age appropriate, either. It is also about what I know about my kids.
My 10 year old hates scary things, and she gets completely freaked out when they show scary movie previews. I would like to be able to block those for her. On the other hand, my 7 year old is obsessed with scary things and I don’t mind if he plays zombie video games.
blymphony | 23 hours ago
JoshTriplett | 22 hours ago
The difference between this and the usual "parental control" mechanisms is that what you're describing here is something the child wants to cooperate with, voluntarily. In which case, you don't need a mechanism that makes it absolutely impossible; you need a mechanism for helping them not see things they don't want to see. That's something some adults also want (e.g. tools for preventing oneself going to Facebook, or going to TVTropes for too long).
cortesoft | 18 hours ago
Now, sometimes my kids might not know they don’t want to see something, which is where my judgment comes in… but I don’t (or at least have not yet, anyway) feel the need to block my kids from watching things they want.
Now, I have spoken to my kids about some things they watch that I have issues with. I tell them why I think the content is problematic and why I would prefer they don’t watch it. But it is always a conversation rather than me just telling them they aren’t allowed.
I have been happy with how my kids have handled these conversations, and haven’t yet found the need to enforce specific rules yet. Even when they watch some things I don’t like, I have found it has made for really effective conversations about my values and what I hope their values are. Some of those topics are too abstract to have without having something tangible (like a YouTube video or channel) to center the conversation around.
brandonmenc | 17 hours ago
modeless | 18 hours ago
cs02rm0 | 9 hours ago
big85 | 23 hours ago
I agree. Parental controls have been the norm for thirty years. The adult who owns the device should have control over it, not Microsoft or California.
sounds | an hour ago
New Mexico Child Safety Case ($375 Million) was an actual judgment.
US class-action privacy lawsuit was a $725 million settlement, with no judgment.
These laws were proposed as soon as it was clear Facebook would not win. They move the liability to the Operating System, exempting Facebook.
KolmogorovComp | 22 hours ago
BeetleB | 20 hours ago
cortesoft | 18 hours ago
I would never tell another parent they were wrong for choosing not to allow their kids to use the internet or consume certain types of media. Those are very personal choices.
My wife and I have deliberately have chosen what to allow our kids to do, and continually have talks with each other and with the kids about our internet usage.
I don’t feel the need or desire to seek advice or approval from random internet commenters.
stevenalowe | 23 hours ago
SilverElfin | 23 hours ago
tzs | 21 hours ago
phendrenad2 | 23 hours ago
zarzavat | 23 hours ago
SilverElfin | 23 hours ago
NewJazz | 18 hours ago
ndsipa_pomu | 10 hours ago
cucumber3732842 | 23 hours ago
This is the classic "what we're trying to do is bullshit on a fundamental level so we're gonna just exempt random things until it becomes a niche issue and we can just do what we want and from there we'll just close all those exceptions over time" move.
Give it 5yr and you'll have idiots in the comments talking about how the "linux loophole" was a mistake and should be closed.
Source: history
seanw444 | 22 hours ago
anigbrowl | 22 hours ago
jrmg | 22 hours ago
jwitthuhn | 21 hours ago
If OSes that don't verify the age of their users are a genuinely unsafe for children, why should they be allowed just because they are open source? That doesn't seem to mitigate dangers associated with age in any away I can identify.
anigbrowl | 21 hours ago
It's kind of a hard problem and legislators are inclined picking the lowest hanging fruit. Their primary concern is to not be smeared as child predators by their political opponents at the next election, eg "jwitthuhn voted to give gambling websites, pronographers, and pedophiles easy access to YOUR children - s/he OPPOSED age verification laws on internet sleaze!! Who's jwitthuhn really working for - you, or the people who want to exploit your kids?!!"
One can point out that such electoral pitches are dishonest bullshit until one is blue in the face, but the fact is they work on a lot of voters because most of them are not smart and don't have the energy or inclination to research every issue. And it is true that there are a lot of hustlers on the internet who are willing to either passively or actively exploit kids, and the anonymity, non-locality, and technical complexity of the internet makes that relatively easy to do and hard to prosecute. Legislators offer simplistic solutions because that's what a most of the public wants, and people often make their voting decisions based on emotional factors rather than cold rationality.
You don't need mustache-twirling villains saying 'let's impose burdensome techn regulations that perpetuate oligopolies and allow me to make another trillion dollars, a few million of which I'll send your way, mwhahahaha' to get shitty legislation (which is not to say they don't exist). It will emerge naturally by default if other conditions are right.
dotancohen | 20 hours ago
Democracy, like the free market, is viable only for informed participants. But once a certain large mass of participants are no longer informed - willfully or not - the system fails for all participants.
NewsaHackO | an hour ago
jwitthuhn | 20 hours ago
This is what I intend to do. To just let lawmakers get away with passing bullshit because "of course they will" is a defeatist attitude that I don't advocate.
That is why it is so important to be loud about this incredibly obvious disingenuous behavior. Make sure everyone knows the people advocating this do not care one bit about children's safety.
unparagoned | 14 hours ago
likeclockwork | 2 hours ago
bmelton | 20 hours ago
some_random | 3 hours ago
neilv | 23 hours ago
Did someone write California Internet legislation without consulting any California Internet companies?
Did some California Internet companies write California Internet legislation?
Did some other party write California Internet legislation?
pwg | 23 hours ago
Meanwhile, while the overall writing clearly indicates the author has a very narrow view of "computers", the definitions of the terms is so broad that every computer, even the tiny embedded CPU in your microwave oven, might just need to ask your age before it allows you to do anything.
wtallis | 14 hours ago
Why do I keep seeing this bullshit exaggeration? It doesn't help anything to make such ridiculous statements. Nobody's microwave oven has an app store.
inetknght | 14 hours ago
Meanwhile, Samsung refrigerators can have an app store.
pizzafeelsright | 22 hours ago
The bill is written 'do good, stop bad stuff by establishing a committee or group to make sure fund good stuff, bad stuff doesn't happen' then the law passes and lobbyists write the details that fund the programs that tax the people that generate the income for companies that donate to the politicians that sell their votes to the lobbyists and interest groups.
California politicians start with the end goal "maintain power, secure revolt, obtain capital, deny failure".
It goes beyond lying to your face. They will be convincingly genuine, heartfelt, while finding a way to extract as much as possible for themselves, by extension their party, by extension the 'government' and do absolutely anything to keep the illusion that you have a choice, a vote, and a voice.
I lived here my whole life. These politicians are evil. Lie, cheat, and steal - deny if caught, punish if provoked.
jeffbee | 22 hours ago
oceansky | 22 hours ago
Aurornis | 21 hours ago
It’s amazing how that one AI slop project that made this claim got so many people to believe this number.
Spreading this disproven AI slop around isn’t helping. It just makes opposition look like uninformed conspiracy theorists who can’t fact check anything.
frm88 | 13 hours ago
During the meeting, Meta executives, including Antigone Davis, global head of safety, are understood to have argued that any age checks should be handled on a smartphone operating system rather than by the likes of Meta.
https://www.yahoo.com/news/politics/articles/meta-urges-labo...
thesmtsolver2 | 21 hours ago
https://captaincompliance.com/education/meta-is-spending-2-b...
Aurornis | 21 hours ago
I still get downvoted for pointing it out and trying to ground the conversation in facts. As you noticed the story continues to thrive on bad news sites and social media.
thesmtsolver2 | 20 hours ago
That seems right for current-day HN lol. I got downvoted for pointing out obvious inaccuracies in another comment.
oceansky | 19 hours ago
dmix | 17 hours ago
> On every social media regulation bill in Colorado, Meta takes an "Amending" position, actively fighting changes. Across 117 lobbying records on 22 bills:
> Bills regulating social media: Meta position is "Amending" (fighting) > The one bill putting the burden on OS providers: Meta position is "Monitoring" (watching)
> Meta fights bills that regulate Meta. Meta watches bills that regulate everyone else.
So their lobbyist choosing not to fight against the OS age gating is the big reveal.
thesmtsolver2 | 14 hours ago
sph | 7 hours ago
sometimelurker | 20 hours ago
shantnutiwari | 10 hours ago
Source: Some guy on Reddit, trust me bro
ErroneousBosh | 9 hours ago
Why would it affect the entire world?
One technological backwater is Having A Massive Sad over people using rude words on the internet, so they think they can tell everyone else what do to?
mpalmer | 5 hours ago
givemeethekeys | 23 hours ago
shit_game | 18 hours ago
ajnin | 18 hours ago
sakjur | 10 hours ago
Megacorps seize the demand for regulation (to regulate them) in order to write regulation that purportedly does that, but in practice mostly closes the doors behind them and cementing their stranglehold on society. For Microsoft, Apple, and Google it's a small thing to agree to age verification if that means all the potential competitors will have to do so too.
The cheapest time to shut down a competitor is before they get to market.
crummy | 17 hours ago
pibaker | 14 hours ago
What is maddening is how often people think such laws are about limiting the influence of "big tech." Big tech isn't going anywhere because of these laws, you are.
panny | 22 hours ago
sufficientsoup | 21 hours ago
hypfer | 20 hours ago
As for what drove him instead.. I suppose we will never know.
All we can know for certain is that the whole thing felt _very_ inorganic and not like something a reasonable human being would just start doing out of the blue.
(Corporate) politics love plausible deniability, so maybe it was just inherently human randomness. I'm sure it was. Please move along.
kogasa240p | 20 hours ago
hypfer | 20 hours ago
And you would doubt it too if you would look at the actual person that is Lennart beyond the "Pulseaudio bad. Systemd bad. Lennart bad." meme.
Very different handwriting too.
bastard_op | 22 hours ago
Steam itself does age verification, which when you first boot a steamdesk, afaik it forces you to log into steam before you can do much of anything without some initial hackery. That said, once in there's nothing stopping them from launching into desktop mode, launching firefox, and watching pr0n that way.
Sadly the solution is still for parents to do real parenting, but that's like saying stupid people shouldn't breed.
7777332215 | 22 hours ago
jiveturkey | 22 hours ago
thot_experiment | 22 hours ago
lol768 | 22 hours ago
7e | 22 hours ago
kloop | 22 hours ago
zoobab | 3 hours ago
platevoltage | 16 hours ago
jmward01 | 22 hours ago
ajsnigrutin | 22 hours ago
Sure, make it easy for users to do so, but it's a users choice.
Kids don't buy phones or computers, their parents do, and during initial setup, parents could choose "this pc is used by a child" option, input some override password to disable this in the future, and the phone could block whatever needs to be blocked.
mmooss | 20 hours ago
It wouldn't take much for a kid to buy a phone or computer.
subarctic | 18 hours ago
layer8 | 22 hours ago
mmooss | 20 hours ago
Maybe it should say, the software 'code' - requiring open source code - and to do it all 'for free'.
lucas_t_a | 4 hours ago
mmooss | 25 minutes ago
Where does it say that? Not in the GGP.
NewJazz | 18 hours ago
solenoid0937 | 21 hours ago
shevy-java | 21 hours ago
The reason is simple: the pattern I see hints that there is:
a) money spent, to push through age-sniffing, and b) it is happening almost globally.
I am not necessarily saying that all this can be singularized down to one bribe-using company, be it Meta, Google or what not, or state actors becoming beyond Evil. But just as the butterfly effect is used as analogy how a strong wind can be created further downstream, I see the situation here VERY similar. To me it is not confined to age-sniffing. Remember the sudden declaration of war by the UK against VPN. This is in my opinion connected here. The goal is not "protect the children" but instead spy more on people than before. A gradual extension of this. And some companies and private interests will benefit. See also the recent Palantir claim made against London aka "the major is responsible for more robberies when he refused to obey to our rule". These companies are greedy - and insolent.
jmyeet | 21 hours ago
Likewise, you'll have Microsoft and maybe Apple pushing for Linux to be included for, again, entirely self-serving reasons. Microsoft is never one to miss an opportunity to benefit Windows.
All that's going on here is competing corporate interests. Likely nobody in power actually cares the actual end users.
As much as libertarians chafe against it, I think we've demonstrated that something has to be done in relation to children online. Advertising to children, harmful impacts of social media, cyberbullying, addictive behavior and selling the data of minors needs to stop. How we get there is unclear. Meanwhile, everyone responsible is just trying to limit and shift their legal liability and that's it.
[1]: https://www.politico.com/news/2025/09/13/california-advances...
[2]: https://www.reddit.com/r/linux/comments/1rshc1f/i_traced_2_b...
tzs | 19 hours ago
In jurisdictions taking the California approach Meta does not need to ask for anything like that. Their app just has to ask the OS, which reports the age bracket that was entered when the user account was made on the device, and the OS gets that information from whoever set up the account. The OS trusts whatever is entered at that time. No driver's licenses or passports or face scans or videos are involved.
> As much as libertarians chafe against it, I think we've demonstrated that something has to be done in relation to children online
...and this is pretty much the way to do it with the least impact on privacy and anonymity possible without first building up some high tech cryptographic infrastructure that would likely include hardware requirements that would, at least at first, exclude users who do not have an iOS/iPadOS or Android device that has a secure hardware element.
rezmason | 18 hours ago
Let's be clear what this means, "Meta is going to require" something. They'll require it to continue to do something, which is namely to be a bad company, running bad services, without pivoting to something else.
Of course, no one requires Meta to continue to be Meta. We'd protect people by requiring companies like Meta to request PII outright, because then the user is explicitly prompted to decide whether using Meta's services is worth surrendering their privacy. And if consumer sentiment and market forces mean anything anymore, that will incentivize Meta to replace their bad services with better ones, ones that don't cause them tricky liability issues.
In other words, forcing operating systems to demand PII from users from the get-go, regardless of the quality of that signal, and to broadcast that to any website, is not, as you put it, "the way to do it with the least impact on privacy and anonymity possible", etc etc. The "way to do it" is to phase out this rotten era of surveillance apparatus disguised as social media companies.
Sorry for being irate, it just feels like so many people these days arrive too quickly (for my taste) at conclusions without testing certain popular assumptions about the inevitability of tech oligarchy.
subarctic | 18 hours ago
Just cuz today's ad-supported social media is bad for kids, doesn't mean everyone should have to verify their identity to use it. You can just make it 18+ and if kids lie to get around it that's not the end of the world. And in general, regulations that would make these things better for everyone would be better rather than just saying kids can't use it and not fix the actual problems with them
m0llusk | 21 hours ago
GuB-42 | 21 hours ago
unparagoned | 14 hours ago
grigio | 21 hours ago
platevoltage | 16 hours ago
epr | 20 hours ago
nobodyandproud | 20 hours ago
jjcm | 20 hours ago
tardedmeme | 19 hours ago
tzs | 18 hours ago
Different states, countries, and multi-country organizations that have legislated in this area or are working on legislating in this area have went with many different approaches. These differ in their scope, how age is verified (or even if age is actually verified), what documentation is required (or even if documentation is required), whether they apply to the web or to apps or to both, whether they make anonymous use harder or not, how much if any sensitive information they disclose to the apps/sites that need to check age, whether they could allow government to track your usage, and in other ways.
Most ridiculous are the comments that after saying how bad it is (clearly talking about things not in the California law) then say how it should work and describe something close to the California law.
abustamam | 17 hours ago
It is kinda silly to read comments that do what you mention at the end (have a seemingly novel idea to fix the issue at hand and their solution is the one from TFA). That's just embarrassing.
But I feel like the rest of the discussions are fair game.
bijowo1676 | 13 hours ago
this act is pushed by the NGO 501c3 called Common Sense Media, their donors include Bezos, zuckerberg, and other rich people.
The same NGO also created a platform called Bandio that provides age verification services. How convenient.
Legislate restrictionist policy today that manufactures demand for age verification service, and then rollout the solution for $$$.
How convenient, muh free market capitalism.
Common sense media also earns $15 mln revenue from licensing its content rating technology.
throwthrowuknow | 8 hours ago
subarctic | 18 hours ago
Of course this also means that the nerds who use linux or lineageos get to win cool points because they can access more adult stuff
laughing_man | 18 hours ago
pengaru | 18 hours ago
jamesgill | 17 hours ago
TimTheTinker | 17 hours ago
- an "extended machine": provide usable abstractions over the hardware to reduce complexity to a manageable level
- a "resource manager": provide for an orderly and controlled allocation of the processors, memories, and I/O devices among all the various programs wanting them.
By that definition, Linux is very much an operating system... unless by "Linux" you meant the kernel only without the additional tooling (systemd, libc, coreutils, shell, etc.) that distros ship with.
[0] https://en.wikipedia.org/wiki/Andrew_S._Tanenbaum
iamnothere | 17 hours ago
Many computer users run a modified version of the GNU system every day, without realizing it. Through a peculiar turn of events, the version of GNU which is widely used today is often called Linux, and many of its users are not aware that it is basically the GNU system, developed by the GNU Project.
There really is a Linux, and these people are using it, but it is just a part of the system they use. Linux is the kernel: the program in the system that allocates the machine's resources to the other programs that you run. The kernel is an essential part of an operating system, but useless by itself; it can only function in the context of a complete operating system. Linux is normally used in combination with the GNU operating system: the whole system is basically GNU with Linux added, or GNU/Linux. All the so-called Linux distributions are really distributions of GNU/Linux!
TimTheTinker | 14 hours ago
ochrist | 9 hours ago
TimTheTinker | 8 hours ago
You wouldn't tell your mom about this great operating system she should use named "GNU/Linux". That's bad marketing.
xbar | 16 hours ago
platevoltage | 16 hours ago
kajaktum | 17 hours ago
NSPG911 | 17 hours ago
jrnichols | 17 hours ago
t1234s | 17 hours ago
apopapo | 17 hours ago
SilentM68 | 16 hours ago
exabrial | 15 hours ago
soanvig | 13 hours ago
It reminds me of clients wanting some stupid feature from app developers which does not fit into anything, and makes no business sense, and therefore creates only problems.
danborn26 | 11 hours ago
amarant | 10 hours ago
p0w3n3d | 10 hours ago
beanjuiceII | 6 hours ago
bigyabai | an hour ago
tssva | 5 hours ago
lucas_t_a | 5 hours ago
ajaimk | 5 hours ago
akdev1l | 5 hours ago
giancarlostoro | 3 hours ago
NoSalt | 3 hours ago
Projectiboga | an hour ago