The court reasoned sensibly: it's wrong to violate the rights of all citizens just to weed out a small group of violators. This is contrary to data protection regulations. The controversial Chat Control law follows the same logic: to find criminals, they propose monitoring everyone.

The problem is that any age verification system effectively becomes an identity verification system. And such tools rarely remain "just for kids"—they quickly become used for other purposes. The only secure way is to verify not the person's identity, but the device's status (for example, that it's a children's device). This is called age assurance: we confirm age without knowing who exactly is in front of us.

> The problem is that any age verification system effectively becomes an identity verification system. And such tools rarely remain "just for kids"—they quickly become used for other purposes. The only secure way is to verify not the person's identity, but the device's status (for example, that it's a children's device). This is called age assurance: we confirm age without knowing who exactly is in front of us.

Age assurance is still treating the symptom. If the platform is designed to addict and radicalize, a children's device getting in doesn't help the child, it just means the harmful design now has a younger victim. The only fix that actually works is making the platform safe for everyone, which means regulating what these services are allowed to do to users in the first place, not building better gates around them.

What is “harmful behavior” when it comes to words? You may have your own definition, but I guarantee that you can’t get a supermajority to agree with it.

(There are some basic things like fraud and such that are already illegal.)

Most people don’t actually want to ban “harmful” speech except for the speech of their political enemies.

> age verification system effectively becomes an identity verification system.

this is fundamentally wrong and accepting this as an industry will only lead to required identity verification becoming the norm sooner or later

the important realization is age verification is in the end "just" a form of parenting tool

this means

- it doesn't need to be a "perfect", glancing at the age of a passport when buying adult products isn't perfect either, but it's good enough. And it doesn't require seeing the address, name, (in most cases) day and month, gender etc. on a id, nor any form of "noting them down".

- it doesn't need to be attestation based, unhackable or anything like that. It complements parenting, not replaces it.

- in turn it also shouldn't need anyones id, in most places children below 18 don't need any id but 16+ is still a age barrier

or to lay it out in rough design

- require multimedia devices sold to have a child "mode" functionality

- allow setting a age category or age (to auto determine and update the category), require a age set for this purpose to be kept private on the device and not shared, analyzed etc.

- require web sites and apps to have voluntary min age limits, similar to other products, block access _client side_ based on this information. The standard should allow region/country specific limits and reason tags.

- There are a bunch of edge cases omitted, like sites serving dynamic content/platforms in general. Requirements for parents to be allowed to define exceptions (in both directions) and handling of sides not having your countries age gating. Etc.

- properly educate parent about it

this provides sufficient functionality to support parents in parenting without requiring any identity verification or overriding the parents right to parent

yes, it's not perfect in many ways. But it doesn't need to perfect, it's "just fine" for what it tries to archive.

If you don't verify identity it's easy to fake.

it doesn't matter!!!

it's a parenting tool, not an online banking system

Giving parents control of child mode is much better than the state deciding. If Parents want to fake the ages of their child, that sounds good to me.

Or realize that there is no way to know who is using a device without looking at the device holders for all the time they use the device. It's like ordering alcoholics or cigarettes: the seller looks at you see the white hairs (OK) or see a 16yo face (documents please.) A device registered to an adult can be used by a child. I know, it's a failure of parental control, but how many teenagers managed to get adult magazines in the last 100 years? They will get adult devices too. So there is no way to create a 100% effective system. Kids and teenagers will find workarounds, everybody else will live a worse life.

1990s: ~%36 of all teens smoked

2020s: >%2 of all teens smoke

Kinda suggests that putting limitations in place actually produces results. Crazy innit?

It also means we don't need identity verification. Anonymous scratch-off cards sold in stores to adults, just like cigarettes, can be used to verify age. Or alternatively, device-only attestation. There's no reason to verify age upon every use of the product; only when it's sold.

They all use Zyn now.

This logic is sus. Just because we cannot have a oerfect system doesn't mean we shouldn't have it at all. Like alcohol age limitations, they can be worked around and wont ever be 100 percent perfect but I see regularly teens bouncing off the register at my local store.

So the metric should be case by case for each proposed solution. Most of things proposed are no good, but that doesn't mean there is not a sensible solution out there to limit net for teens.

> The problem is that any age verification system effectively becomes an identity verification system. And such tools rarely remain "just for kids"—they quickly become used for other purposes.

source?

No source but a possible counter-example: SIM card carries the date-of-birth of the user (because, really, part of the problem is that you cannot supervise what a kid does with their phone 24/7), age-restricted websites have a flag in their HTTP headers, browser get age from SIM card through the OS. Same goes with app stores etc.

Like copy-protection there's always a way to circumvent it, the name of the game is to make it difficult enough. And for parents, to make it very easy to set-up.

XKEYSCORE, the UK system brought in to allow warrantless surveillance for national security purposes and child abuse prevention, ended up being used for such minor offences as catching people dumping rubbish in other people's bin, or parents lying about their child's address to get into a better school district. In the United States, the same system was used for low-level offences like cannabis possession.

Source for this ever not being the case?