I once heard someone suggest that this should be on the OS level and I'm slowly coming around to the idea. There should be some kind of OS level flag that can easily broadcast to products that a child is using the device. No ID verification required, the parent is responsible for setting it, and all downstream applications are regulated to respect it, If applicable to the product. This removes the incredibly invasive ID verification, and places responsibility on the people responsible for the minor. Companies like meta then can be sued not for failing to detect children (this is, evidently, not working on any platform trying to enforce this currently), but instead can be judged in a black and white manner (i.e. is the child version of meta too predatory to children?)
This is almost right, but it shouldn’t be “is a child using the device?” It should be “is this a child-locked device?”
There should be a children’s Internet, just like there are children’s libraries, and child-locked devices should give access to it. Adults should be able to use the children’s Internet to see what’s there and children should be able to use the adult Internet when supervised by parents and teachers.
Technically, the only thing cooperating websites need is an http header indicating that the client is a child-locked device. Websites can disallow creating accounts or logging in from child-locked devices when they’re only appropriate for adults. There can be laws prohibiting advertising on the children’s Internet, etc, and legit websites will have to follow them. At no point does a website need to know a child’s age or anything else about them. Vendors selling devices are responsible for not selling unrestricted devices to children, but that’s easier than making every website do it.
Since the Internet is still a dangerous place, for non-cooperating websites, child-locked devices do still need the usual whitelists and/or blacklists.
There should not be an HTTP header indicating that the client is a child-locked device. That puts the onus on the server to respect the header, and HTTP doesn't require any action on unrecognized headers. Also, it reveals to the server that the client's user is likely vulnerable to manipulation — exactly the opposite of what you want!
Instead, there should be an HTTP header indicating that the server is an adult-only website. Then, child-locked devices can refuse to show the content to their users. Moreover, this can be more granular than just a single adult-only bit.
This standard has existed for 30 years and was supported in Internet Explorer 3; it's called PICS: https://en.wikipedia.org/wiki/Platform_for_Internet_Content_...
If the current age verification controversy was intended to protect children rather than destroy anonymous speech, it would be focused on requiring the implementation of PICS or something similar.
100% agree, and no OS should be forced to implement this "child-locked" signal. the existence of OSs that do implement it should be enough (if you want to lock your child's device, use a lockable OS).
> http header indicating that the client is a child-locked device
what happens when the request goes through a proxy and that proxy is configured to strip this header?
Websites that don't cooperate would need to be blocked by child-locked devices. That part wouldn't be any different from today.
Do you even know what a proxy is? It has nothing to do with website cooperating or not
The Web is HTTPS now, so that can only happen if either the origin server or the user trusts the proxy.
User uses a proxy to bypass the client side validation, that’s the first thing I would have done as a teenager
There could be lock levels to this. By default everything is unlocked (level = 0), but if a content provider / host receives a signal/header with lock-level > 0 they should be required to honor it. Something like this would require government which means it will probably never happen. Much more power asymmetry to just track you.
If you want to make a child-safe website that is OK, it can go be in it's walled garden g-rated brand-safe reality. But that is retarded. The rest of the internet still exists, and will not stop existing. Porn/defense distributed/much more insidious things will still exist.
All the age verification is is creeping totalitarianism by governments.
> It should be “is this a child-locked device?”
No, that leaves vulnerable adults unprotected. It should be "Is my thing in one of the categories of things that this device says this user is not permitted to do? If so, I shall not permit this user to do the thing.".
Nothing stops software authors from providing pre-built bundles of categories that they believe fit certain types of vulnerable people [0], but the fine-grained control must be there so that guardians can choose to set things up for those they guard so to adequately protect them while minimizing the amount of stuff that they're blocked from.
[0] Like: "Overly-trusting human who needs protection from scams", "Dementia-damaged adult who cannot be trusted to manage their finances", "Median sixteen year old USian", etc, etc.
Sure, the categories can be expanded. For example, movie ratings aren't just "children" and "adults." But explaining the simple case seemed like enough for one comment.
Building this functionality into an operating system is an extremely slippery slope to even further centralized corporate and government authoritarian control of people doing what they want with the personal computing devices that they own and possess.
I think you may be misunderstanding a bit. There's no forced verification. It'd be more of an RFC that gives parents the ability to communicate their underage child is using the device without revealing or verifying any further information. Or do you suspect that giving any ground will cause the ID verification and centralized behavior?
I think the concern is a forced bit of functionality in all operating systems. It would quickly lead to a "and you need a license to sell your device so we can check that it can't bypass mandatory chuld-safety guards". Just like how some politicians are proposing mandatory licensing for releasing any AI model.
You need licenses for a lot of things though, particularly for things where there is substantial harm to be done when done incorrectly. This is just how it goes as things get more popular. Think back to 1903, there was no FAA then, but also no need for one. But it would be super disingenuous to argue now that airspace should be totally unregulated.
I think the problem with this debate in general is that people aren’t recognizing the harm, and are clinging on to old ideas about how the world should work, ideas that just don’t acknowledge the reality of how things change as technology changes, or even just spreads. Rejecting the idea that there are harms, and thus nothing should be done, just ensures you don’t have a seat at the table at all when it comes to the inevitable decision to do the regulation.
I think you aren't recognizing the harm of collecting this information. I might be okay with this if companies were banned from using age for targeted advertising.
However, the other harm is the recent IDScan hack which leaked 153M people's IDs. And regulation is not a solution here, we don't know how to implement a regulatory regime that will prevent these sorts of privacy disasters. Even if IDScan gets fines which kill the company (and I suspect they will not) it's not enough of a deterrent because no one will pay enough to actually provide proper security here.
Licensing for selling anything with a computer in it would cripple competition from small incumbents. They're mostly just regulatory capture for the established players that created the problem in the first place. Age restrictions are also an implicit statement that they are allowed to continue doing the same harmful things to adults.
Meta, Google, Anthropic, OpenAI etc can afford to pay for and deal with licensing. They also created these issues and would very much prefer not to have to mitigate the harm they do to adults (i.e. people with money to spend). Furthermore, it'd be great if they didn't have to worry about small time competitors emerging and growing too fast. Licensing under the guise of "think of the children" is perfect for them.
I suspect that communicating a flag value of boolean true/false that "this computer is in use by a minor" from the operating system (via browser or app) to a remote SaaS service like something run by Anthropic will be seen as insufficient by the SaaS, so they'll necessitate ID-scan/live-selfie verification anyways.
Meanwhile, the age flag in the operating system will be used for other forms of authoritarian control. It will have actually accomplished nothing other than limiting peoples' fundamental civil liberties.
That's a valid take. The issue I'm wrestling with is the inevitable attempts to point a finger at who is responsible when bad things happen. If you claim it is on the tech companies to know if a child is online, then they will take the safest path for them by forcing ID verification in independent adhoc manners. This is what we are seeing now, and to me this is the worst situation. If you shift the responsibility more to the parents (this child was using a device that didn't send the `PARENT_CONTROL` flag, therefore we assumed they were an adult) it's a completely different conversation. Furthermore, if something happens to a child AND it's obvious from traffic logs that the platform willingly knew a child was being talked to, then that is also a completely different situation than the first.
Leaving it all completely deregulated and/or letting platforms implement it themselves to varying levels of success and personal invasion feels like the worst option to me.
I think you need to explain the solution you're thinking of in detail.
"an RFC that gives parents the ability to communicate their underage child is using the device without revealing or verifying any further information." is no different to "turn on age lock?" that you see on website now. It requires the parent to be present, engaged and 1 step ahead of their kids, and if we could depend on that, then we wouldn't even be having this discussion.
He was saying, vendors put that flag in the OS and parents set that flag in the OS and internet services respect that flag from the OS. No website anything, all in the OS. No staying ahead of anything, one and done. This, as noted above, requires that services respect the flag, which they do not universally do today. That requires legislation, something that will be a part of any workable solution.
An alternative one could consider is that the ISP could DNS-block sites for "kid SIMs"). On the OS part, this would require protection against picking alternative DNS, but that's already standard. Other "anti-circumvention" features might be required, such as factory reset.
For all the protections that the ISP cannot reasonably provide, one can consider creating a nation-wide (or EU-wide, or US-wide) official label, that device makers can obtain if they meet certain requirements. Parents can them make their choice. We have that for food etc., so why not for internet access mobile devices. Because from my perspective, the main problem that needs to be solved is that parents cannot monitor 24/7 what their children do on their phones.
Yet another solution is to create a top level domain for kids, restrict kid devices to that domain, and allow sites enter this domain only if they meet defined criteria.
Oh, and prevent ISPs and phone makers to sell 'for kids" products at a higher price. People can whine all they want about free market, but it's to protect our children.
Whenever I see people say "oh we should just get the ISPs to block it!" I wonder if they work at any ISP, or are just an end-user consumer of their services... As someone who does work in the ISP/telecom infrastructure sector my first reaction is hell no. I do not want US/Canadian ISPs to go down the path of what has happened with, for instance, Spanish ISPs DNS-blocking football related things as a result of court orders.
I am not, indeed. However as programmer I was sometimes told to do what the customer wants, even though it is complex or inapt. If this DNS blocking is inapt or misused, it's a political problem so let the citizens deal with it (I know this seems like wishful thinking given the current poor state of politics at least in the EU, but hopefully we will fix that while it's still in our hands).
Besides, I read about what happened with Spain and football, and from my understanding the issue was that they blocked not DNS but IP addresses. And problem domain is also vastly different, a priori: in that case, they faced sites that were actively trying to avoid blocking, while in our case, I doubt pron sites and such will try to do the same, because children are not their target audience.
An alternative could be to create a top level domain (TLD) "for kids" and restrict kid phones to it. Then in your TLD you can admit sites that meet minimum criteria (no pron, no terrorism, content and chat moderation for SNS).
I firmly believe that tech companies being responsible for parenting our children is a deeply misguided response to a failing society and overworked parenting generations.
I benefitted greatly from early access to computers and the full scale of their capabilities. It was a constant issue in my family limiting screen time, and who knows what the exact rules should be for everyone. For me it was a dynamic ruleset I was actively involved in the development of.
I could make compelling arguments to my Mom, that will not be the case with Meta, or Apple, or Anthropic.
Accepting "OS level" age validation is surrendering to a system meant to protect the industry, not our kids future. And while there are serious conversations we should be having about how to control technology use, it should be about parental controls and sane defaults, not age validations and legally restricted access by providers.
I hate how even the most progressive-minded people on most fronts are falling into this trap because big tech has failed them and they are angry at it all.
Having had a similar upbringing, I strongly agree. I have a hard time not lashing out at people that fall into this trap given how important that early access to computers ended up being to achieving my dreams.
[dead]
Apple verified me by the age of my account. Claude asked to use the age verification when I opened it on my iPad. Haven’t been asked for any other kind of age verification by Anthropic.
Personally, I'm not in love with the idea that something harmful to children is totally okay for adults. If social media is that corrosive to young people, maybe we should take a look at that and make it less corrosive for everyone.
Some kind of "child lock" on the device makes more sense to me; a parent or whatever can child lock the device before handing it off, no need to collect images of the child in question and store them in some big pile at a private company.
This kind of thinking just leads to an obvious analogy: alcohol. Alcohol is harmful to children and adults. Yet when the United States tried Prohibition it was rolled back. It turns out that people want to do things harmful to themselves.
Doesn't this break if the child uses a VPN, or some other software to spoof? For this to really work Windows would have to lock down all HTTP, and really all networking, only allow approved software/browsers, etc. Is there a reason this wouldn't be the case?
The problem is that it would be a client side identity verification mechanism and won't work for websites.
As an example this would means that if this exists in iOS, everytime a safari loads a webpage it has to send this additional verification identifier as a header or a query param to the web server that serves the request and based on that the web server deny the request if the identifier is present (that means a minor is trying to access the web page).
But this client side identifier can easily be bypassed via a proxy that strips the identifier from the request because not matter it's configured in the OS of the device, ultimately request would just goes out as HTTP and that can be manipulated. That's why it has to be a server side verification of the age/identification.
California passed a law AB-1043 that requires every OS developer to add age verification on the OS level.
https://www.eff.org/deeplinks/2026/03/ab-1043s-internet-age-...
> every OS developer
They exempted Linux, from what I remember reading.
> There should be some kind of OS level flag that can easily broadcast to products that a child is using the device.
Anything like that should be configured by the parents. Your child is your responsibility. I shouldn't have to take a picture of my passport just because someone is a neglectful parent.
Absolutely. Of course. Is there any question about this? Do you see people advocating for something other than this?
I want to go back to having an IQ test to use the Internet.
I think the appeal here for parents is it’s a single point to configure. It’s not perfect, but perhaps better to configure one device than every account individually. I’m game for it.
That's very reasonable but doesn't help build the surveillance society sadly and therefore will not be legislated
Was that someone Mark Zuckerberg?