@david @bjoreman @HennaVirkkunen For these reasons, Europeans should outright reject age verification.

Yes, I know it is difficult when kids can pretty much access anything, but as parents we have to find better ways than those that further kill privacy and entrench big tech players.

We're talking about very different systems. In Spain, for the past 82 years, all citizens have had an official identity document issued by the state. This document contains an electronic certificate that allows us to identify ourselves online to government agencies. With this type of infrastructure, a neutral state point is viable, one that simply certifies and responds with true or false to the legal requirements of any particular online service. The online service does not receive any other information than the complaining (or not) of the person on the other side of the connection with law requirements. No other data have to be shown or saved.

I don't see the connection with free software because I'm not aware of any legal restrictions on using free software repositories by underage, and I cannot imagine it as a political possibility.

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu

@david @bjoreman @HennaVirkkunen

You are missing my first point, even if an age attestation method does not reveal the birth date, you can infer the birth date from it because some day the attestation will flip from 'false' to 'true'.

Second, Spain is piloting the EUDI Wallet for age verification, which will implement remote attestation:

github.com/eu-digital-identity

@david @bjoreman @HennaVirkkunen On the point of using identity documents directly: either you have to send the signed attestation to the site/app for verification, which would deanonymize you; or some gatekeeper like a government site would have to do it and give the result to a site/app and in that case the gatekeeper knows what apps/sites you are using, which is a huge privacy invasion. Also doesn't protect well against a kid using someone else's ID to verify, so it's mostly security theater.

From a technical standpoint, if you want to restrict access to a website based on some form of identity data, you either trust the web providers or you trust the state. If the state legally prohibits itself from recording which sites you visited or even how many times you used the service, the issue should be settled. If, for whatever reason, even reasons of principle, the state is deemed untrustworthy, then the issue has no technical solution because it is fundamentally a political one.

CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu