@HennaVirkkunen How is that to be done without handing these platforms our identities and ability to track us? Seems the last thing I want is for them to be trusted with anything.
This service only has to respond to the provider's request affirmatively or negatively given legal conditions to access its site.
CC: @HennaVirkkunen@ec.social-network.europa.eu
@david @HennaVirkkunen That sounds reasonable-ish. I hope they don't build regulations which create a sea of very poor malicious compliance.
@david @bjoreman @HennaVirkkunen that site somehow doesn't seem to work here. But in general, these proposals fail, because sites can regularly probe for age brackets. If you do this on a regular basis, you can figure out someone's birthday.
E.g. if 12 years is a bracket boundary, the day that age gets attested is the birthday of the kid. Even more likely because someone is more likely to check close after their birthday to unlock some site/functionality.
CC: @bjoreman@toot.cafe @HennaVirkkunen@ec.social-network.europa.eu
@david @bjoreman @HennaVirkkunen The problem with most age attestations is that you can work out someone's birthday by keeping track of past attestations. When the attestation changes, someone had their birthday, thus the attestation gives away information that someone might not want to reveal.
This gets worse with implementations with which you can test age brackets (different age brackets under 18, to allow some content).
@david @bjoreman @HennaVirkkunen So, the problem with age verification is that it is yet another attack on privacy. Not surprisingly, behind the scenes Meta is pushing this a lot through various sock puppets.
@david @bjoreman @HennaVirkkunen Also, age verification is strongly detrimental to open source and your freedom to choose your OS.
Most implementations of 'anonymous' age verification require remote hardware attestation (eventually), because otherwise you can manipulate the app/process that partakes in the attestation.
Mandatory remote attestation is pretty much the end of free OS choice, because you running your own non-approved software will shut you out of services.
@david @bjoreman @HennaVirkkunen Age verification + remote attestation is big tech's pipe dream. Google can already shut out competing systems from phone NFC payments, because pretty much every bank only supports Google/Apple Pay and Google doesn't attest alt-OSes.
Remote attestation of websites would be another level, making it practically impossible to live outside the Google/Apple duopoly.
@david @bjoreman @HennaVirkkunen For these reasons, Europeans should outright reject age verification.
Yes, I know it is difficult when kids can pretty much access anything, but as parents we have to find better ways than those that further kill privacy and entrench big tech players.