…so why are people so up in arms against bans and restrictions on children having access to social media, where they have even less oversight and can do so themselves?

  • Dr. Wesker@lemmy.sdf.orgOP
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    4
    ·
    1 day ago

    Is the better, more acceptable solution to have a person’s government be in charge of identity verification and offer some sort of secured API that sites can use for confirmation?

    • josephc@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      17 hours ago

      Yes. In fact, zero-knowledge proofs make it possible for me to do something like prove my age in a way that is verifiable by the site without the site knowing any other information about me AND without the government knowing what website I’m asking. It doesn’t even require an API. The government needs to digitally sign my identity papers and publish its signature. One time download and you can even do offline checks.

      The EU digital ID program does this. Everyone has privacy.

    • GreenBeard@lemmy.ca
      link
      fedilink
      English
      arrow-up
      24
      arrow-down
      1
      ·
      1 day ago

      Quite frankly yes. Proof of identity is kind of one of the core roles of government. Handing it off to private corporations is like entrusting a nation’s military to private militias and policing to gangs.

      • Dookieman12@piefed.social
        link
        fedilink
        English
        arrow-up
        17
        ·
        1 day ago

        Age verification doesn’t have to mean identity verification.

        Parents and human moderators solved this problem just fine. Everything changed when every platform wanted to be the first to cut moderation costs by using LLMs instead.

        They abandoned a perfectly working system and have been pitching a fit about restarting it because “it costs too much” ever since.

        • GreenBeard@lemmy.ca
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          I’ll grant it’s an automation issue. Age verification is always identity verification when it’s automated. It doesn’t matter how much you try to scrub the data. If it has to be done algorithmically, there’s no possible circumstance where an unaccountable third party should have that data.

    • Dookieman12@piefed.social
      link
      fedilink
      English
      arrow-up
      18
      ·
      edit-2
      1 day ago

      “Better” and “more acceptable” are very subjective.

      If you’re asking me what I think, I think a solution that verifies identity is uncalled for. I think the problem, though real, is also greatly exaggerated and mostly caused by a failure of platforms to moderate (Roblox, for example).

      Companies don’t want to moderate their platforms because that costs money. Developers need to add the reporting functionality and paid staff need to review and action the reports. I think this is one reason tech companies are so interested in AI; automated moderation. But, AI still requires compute power, which is still a cost.

      If tech companies can claim handing over your ID will solve the problem, they get that sweet private info they want so badly for free, AND they get a cost-free way of claiming their platform is moderated; it’s a double win.

      I think requiring platforms to moderate themselves with humans is a very small price to pay in exchange for the broad access to our private data and hundreds of billions of dollars of advertising revenue they enjoy, and a much better, much more acceptable solution.

      Edit: Just remembered, another big component to all this is, big platforms like Meta and Reddit are getting hammered by AI scrapers, which drives up hosting costs, and being bombarded with AI slop, which negatively affects their engagement KPIs. ID verification will solve both of these problems.

      It’s pathetic because, the only time laws or regulations ever get passed is when one oligarch wants to weaponize the government against their competition. It’s a sick game, and we all lose every time a move is made.

    • lucullus@discuss.tchncs.de
      link
      fedilink
      arrow-up
      1
      ·
      22 hours ago

      You don’t want the target site to have your identity (nor your age, only the information, that you are old enough). Though you also don’t want to tell the government, which age restricted sites you are using (imagine the government getting having a list of all your porn site usage).

      There are ways to do this, though the implementations in most countries don’t adhere to these requirements (either by giving your identity to the target site or the government collecting your usage data).

      I might remember that wrong, but I think I heard a proposal in germany, that would fit the requirements. Something about, that you can generate up to 30 cryptographically signed tokens (don’t know why the limit was included) from the government, that the target site can use to verify their age limit. No communication between the government and the site. Though I don’t know, if that proposal got any track.

      We will probably also see, that nearly all websites will need age verification, since there is a lot, that is not suitable for very young children. A bit older children and teenagers will also have to use that verification workflow quite often. Adults way more often. That is a lot of friction easily avoided with a VPN.

      And of course the governments would also need to block every site, that does not comply to the local regulations. Different worldviews make this impossible. A small blog about queer education in europe would need to implement age verification, because the US and russia hate queer people.

      It’s a big clusterfuck

    • it_depends_man@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      1 day ago

      No, because it’s a 3 way information exchange.

      When you visit a site, you, the site and the government know that you went there.

      In cases where the company can exploit that information because it can 100% verify you are a real person that’s bad.

      But when the people in government can identify that their political opposition did “bad things” online and exploit that against them, that’s also bad. Also, the people in charge can always fake that if they want to, and if the system exists, because there is little oversight over the currently planned systems.

      We’re not talking about “normal and legal behavior”, it needs to be tamper proof and safe against malicious actors inside the system. That’s nearly impossible to do, so the safe option is to not create that system.

          • GreenBeard@lemmy.ca
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            Yes. Like sexual predators they’re more common than people like to admit and I’ve had the displeasure of knowing a few. Also like sexual predators, living like they’re ubiquitous instead of taking out the trash is not the best way to deal with them.

        • Dookieman12@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          It’s not about who is/not worthy of that level of trust. It’s about the risks associated with putting that much private information in any one place.

          Even if you trust the person you’re giving your info to completely, mistakes happen every day, that many identities in one place is an attractive target for hackers, and there are very few regulations that would require a private company to disclose such a breach, even fewer that would require them to compensate you for any damages resulting from such.

      • Dookieman12@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        It can be simpler than that. If operating systems offered an option to create a user account flagged as a child account, it could also come with software to limit the use of child accounts on the local machine, and let the parent configure what is/not blocked.

        I know third-party solutions exist for this use case. My point is that the functionality could be implemented better and use of it could be more mainstream.

        • it_depends_man@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          My ideal solution would be a parent controlled OS based “child account” that has a white list for allowed apps and websites and parents who then use that feature.

          I would like to avoid any solution where the website learns anything about the users. Including what facebook has proposed and done in the US, making the age API request thing a law. They’re doing that to make their ad targeting more precise, not to protect anyone.

    • DarkCloud@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      edit-2
      1 day ago

      Nope, all you have to do is regulate ISPs and Telcos so they don’t sell Internet connections to kids. Make that the offense.

      If parents want their kid to have an internet connection, the parents have to buy the kids-only Internet. If that’s the aim, then do that!

      Most people are fine with that, most people have their names on their bank accounts and show proof of age when buying a sim card or ISP connection, but don’t want to give it over to EVERY social media site they’re ever going to interact with. This isn’t a TikTok level of responsibility, it’s an ISP and Telco/bank card level.

      If you want kids to be kids, then parents have to be parents. Don’t wreck the Internet because little Timmy is shithead on reddit.

    • sunsofold@lemmy.zip
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      That would be better, but better still would be to find a solution that doesn’t enable surveillance of the uninvolved. Most people trust neither their government nor corporations to not misuse or abuse the power of their data. Certain public key cryptography techniques could be used, but because companies can’t make money from it, it’ll never happen.