System76 on Age Verification Laws
https://blog.system76.com/post/system76-on-age-verificationOpen linkView original on discuss.tchncs.deSyndicated from the fediverse. Read and engage on the original instance.
View original on discuss.tchncs.de
https://blog.system76.com/post/system76-on-age-verificationOpen linkView original on discuss.tchncs.de
20 replies
Wow, that's a refreshing take on this whole stupidity. AI can identify us anyway, leave us alone!
Fuck yeah. I was pirating software before I turned 18, and the world is a better place for it.
(And I contribute to open source now, in the hope that the next generation can learn without needing to resort to piracy.)
Just forbid any user from any place that has these laws from using your OS through your ToS but don't implement a way to check who uses it.
Lovely article. All the context up top perfectly leads to the buried lede at the end:
I and many others I know who grew up with unrestricted internet access (before and after the corporatization of the internet) were exposed to terrible shit. Like, I grew up with unusually tech savvy parents who were able to protect me from the worst of it, but even I have been somewhat traumatized by accessing graphic content I shouldn't have. I personally know people who grew up with worse parents who grew up browsing shock/gore websites and who were repeatedly groomed and abused by pedophiles.
Honestly, I don't really get the backlash to this legislation, beyond that its prehaps being applied to devices it shouldn't be. Its a local, safe option for reducing child access to things they shouldn't access. While yes, freedom is important, we're talking about providing the option to limit access to mature content, not preventing them from downloading python or using the internet. There is a justified reason for wanting this, and this seems like the ideal way to do it.
Edit: I'm genuinely confused as to why people are against this. All the argument sound like they're thinking this is another variety on ID collection or AI tracking. From my understanding, this is an optional flag, set locally by the user, about as decentralized and pro-user-choice as it gets. I'm going to reread the law to make sure Im not missing something.
Edit 2: Reading the law, section 4a seems unpractically vague, but in favour of blocking data collection. From my understanding, that would ban the use of things like user agents, and theme settings in browsers. Notably, the law also specifies fines for both accidental and intentional data sharing. This seems like about as good an option as you can get, for protecting children, while keeping it user-choice driven, decentralized, and anonymous.
Edit 3: Actually, in combination with the CCPA, possibly COPPA, and California Civil Code, wouldn't this effectively work as a "tracking me is now illegal" switch?
Edit 4: My interpretation of 4A was incorrect, it would not block the access of other system-level flags. It would simply block requesting further personal data from the OS's developer.
Edit 5: I have changed my opion. This law incentivizes entering accurate information too heavily, and despite always using the term, "age bracket data" doesn't require any abstraction of stored age. Its also just not good enough as a content-filtering system, since its opaque and doesn't allow for much filtering of specific topics (IE gore versus porn). I'm still not against such a standard being created, but this is not the way to go about it.
With the proposed measures in place, any app can know exactly which devices children are using, something noone can do now.
When you implement a feature, there's no way in the world you can guarantee only "good people" can use it, and malicious individuals are way more interested in getting info about children than anyone else.
That doesn't protect children, it puts them even in more danger than they are now.
I mean, from my understanding, this would be both hyper-illegal and extremely impractical. You'd need to have a large enough site to lure users in, and collect identitying information and republish it, but can't draw enough attention to become a target for data poisoning (given that this flag is freely set by the user) or for law enforcement. It seems like this would be unlikely enough that the benifit gained from having this flag would far outweigh the risks, esspecially in the modern, hyper-corporate internet.
Individual sites will have their data leaked then aggregated by data brokers. Those data brokers both sell the aggregated data and experience data leaks themselves. The data keeps moving from actor to actor while the aggregation is continued until eventually finding it's way into a public repo or security researcher data sets.
This is a compelling argument, but do you think its really a significant attack vector? Its already illegal to share or leak (even unintentionally) this data, and from my understanding, if you chose to set your age to a lower bracket via this process, companies sharing (also collecting? Currently unclear on this.) this data would also break CCPA and possibly COPPA, and from my understanding, the companies are required to provide additional data privacy measures under California Civil Code.
Yes, these laws will be broken, but will it be on a significant enough scale, and with reliable enough information to be worth-while? Like, since this bans the use of data from those who set their age low, wouldn't this likely reduce the data collection pool overall, not to mention inventiving adults to poison this data. For those who do illegally collect this data anyway, is it that much of an advantage compared to just asking the user's age upon reaching the site as most sites currently do? Beyond that, when these sites operating illegally do leak their data, will that data be a realistic attack vector? Like I said to another commenter, collating data in this way seems extremely impractical and unreliable for predators. Wouldn't those who want to seek out children just go to existing spaces where they can connect directly like Roblox or Discord? Like, don't get me wrong, I don't like data collection, but compared to everything else, this seems like a relatively unreliable and unhelpful data point, esspecially given all the legal restrictions.
Edit: also, would be interested to hear if your opinion changes if even storing this value is illegal, if unnecessary data collection as a whole is banned, and/or if this value has a legally defined default of using the 18+ value, and doesn't have to be made obvious in account setup.
Edit 2: Also, wantted to say thanks for responding genuinely and with a well-articulated argument. I know the Fediverse tends to be very... unfriendly... towards anything that may impact privacy and towards government regulation in general, so your civility is really appreciated.
Honestly, I re-read the legislation, and I while I'm still not convinced something like this is a bad idea, all the specifics are.
Like, ultimately, its a user-set flag, stored locally, and would provide users more choice in content filtering. That could be useful, for parents and non-parents alike.
You're right, and the design of this law basically ensures that. I was thinking of it being implemented (at least in user-friendly UI) as a dropdown showing the four provided age brackets. Instead, it is required to be a numeric or date of birth input, seemingly without allowing a default value, which means users are more likely to enter accurate data. Similarly, stored age information isn't required to use the brackets provided. This means that a lazy or immoral developer will use the exact age, rather than abstracting it as the law suggests. I had misinterpreted 1798.500. (b) and thought that the abstraction of age data as suggested was required.
If something like this is to be implemented, it needs to use a more abstracted format (ideally with a default value), and if its going to be implemented into law, it should be a better, more granular system of content filter than simply using an age-based metric.
Does that ever stopped criminals before?
Yes, in that they can be stopped if noticed. Police are incompetent, but if something is that bad, and draws enough attention, the person will generally be arrested.
Yes, all the time. Thats why safes, passwords and similar exist. Or, more relevant in this case, the adage that the best way to avoid a break-in is to be a less appealing target than your neighbors. Roblox, Minecraft, Discord, and other platforms where kids gather and regularly self-identify are still going to exist, and they are far safer and far more appealing for targetted abuse of children. On the other hand, setting up a public website/app and trying to lure children to it is expensive, risky, and unlikely to succeed on the modern internet.
Why did you access it if it made you feel bad? It is (and has been since I remember) very difficult to accidentally run across anything shocking on the Internet.
No one ever linked you to lemonparty, huh? No escalating chains of "hot singles in your area" ads? No, you know, human tendency to explore and pursue novel experiences?
OK, if someone actively links me to it, then yes, but there's also no solution to that because they could just send it (or a screenshot of it) directly to me and circumvent any filters there might be.
I've never clicked on a "hot singles in your area" ad, so no idea what that is about.
The entire Internet is of course IMHO about exploring and pursuing novel experiences; but how quickly do you imagine children can get from websites actively recommended by parents to shocking websites? Not very, I think?
It didn't take me long! I learned the shortcuts to hide what I doing from them and was pretty quickly the one being asked for tech tips. Plotting revolution and pirating media in IRC while mom thought I was playing "Where In The World Is Carmen San Diego?" >:)
Kids are way smarter than a lot of people want to admit. I would say more intelligent than adults on average, balanced out by lack of experience of course. That's why I'm so against government measures to limit their exposure and experience, whatever the pretext. They are our future and they will surpass our capabilities, we're fucked as a species if they don't. They deserve our support, not disingenuous constraints or to be weaponized for fear mongering
I definitely agree with all of that.
But if you "learned the shortcuts to hide" what you were doing, then you were clearly accessing things you actively wanted to see, which was my entire point.
Not like alt-tab is rocket surgery :p
What I wanted to see was "the world", you know? That drive to explore and pursue novelty we talked about? Think it's a pretty universal experience, and one companies have absolutely learned to prey on. I don't think yearning to know the unknown is quite equivalent to actively wanting to see anything specific, and you seem like a smart enough guy to be aware of the ways companies abuse that curiousity. That people, children or not, are only shown things they actively want to see is measurably, provably not true. We go down rabbitholes and off on tangents and towards intensity and in all kinds of directions all kinds of people have all kinds of motivations for influencing
Alright, I agree with you that modern "social media recommendation algorithms" are a bad thing that shouldn't have been invented, if that is what you're getting at.
Because I was a stupid kid and didn't realize that watching combat footage might be a bad idea. I thought I was just learning about military history. Same way kids don't realize they're being groomed or don't realize that watching graphic horror movies might be a bad idea. Kids are dumb - and to be clear, I know you can't shield them from everything and parents are still the primary solution. Still, a local flag for age range seems like exactly the sort of tool that would help a parent to moderate access without limitting privacy or freedom.
Edit: Also, this argument obviously isn't what you intended to make, but implying that kids are at fault themselves, for going to dangerous websites looks really bad when replying to a comment partly about child predators. You may want to add a clarification, or reword your comment.