Hacker News new | ask | show | jobs
by skrebbel 19 days ago
I agree wholeheartedly with the argument raised in this github issue, but I think people are wrong to be skeptical about the concept of a government-issued age verification app.

Thing is, the status quo is absolutely worse. My 13yo son likes making Roblox games. Suddenly, some months ago, Roblox made a change where you’re not allowed to share your games with friends unless you do “age verification”, apparently in some misguided bid to beat the pedos. In Roblox’ case, this means sharing your 3D likeness with some sketchy American business who pinky promises to delete said data after. I don’t want random American tech companies to have my kids’ biometric info like that, able to sell it to whoever asks. Nor my passport or anything like that.

I’d much prefer a government supplied app, that’s guaranteed to protect my privacy, and has no business incentive to sell my data, where I can see what data about me (or my son) is shared with Roblox or whichever sleazy business wants it.

Obviously this only makes sense if the government is less sleazy than the average American tech business, but for all its faults, I think that currently holds for the EU (and most of its member countries). There’s plenty precedent of EU governments doing privacy-conscious apps right (the Dutch covid tracking app comes to mind).

I hope they see reason and fix this here issue.

19 comments

Government issued versus corporate issued age verification is a false dichotomy. There are other options, such as refusing games that require them. (Yes, we do have a teen, and yes we did exactly that with Roblox.)
Pretending that those options are equal is a false dichotomy. Not participating is an option up to a point, and then it is increasingly limiting all other options.
Thats obviously fine to do but it is very much going to have consequences for some kids. My kids spend hours a week playing roblox with their IRL friends. 10 - 15 kids on a group call on speaker phone all logged into the same code laughing and yelling for a couple hours a night. If I was to suddenly tell them that they can't play those games with their friends it would have very real effects on their social life. My kids spend a ton of time outside with friends but to ignore that they also spend time gaming with them is not an option.
Self-hosting a minecraft server is still an option. And tons of customisability there and you aren't turning everything over to a centralised server.
but the other kids are playing roblox, not minecraft
And if the other kids were jumping off of bridges would you also want your kid to not miss out on that socialization?
If the other kids are jumping off bridges, I would have a great reason to tie my kid to the house. But this isn't that obvious to kids. They will be resentful, they will hate your guts. This will have lasting consequences to your relationship
But they aren't jumping off bridges are they? They are all having a good time playing together on Roblox. Are you honestly saying that playing on Roblox is as bad as mass suicide?
Sure except none of them are playing minecraft so its not really the same thing.

Me siting down and explaining how government or corp. issued age verification is bad is really not going to make him feel better about sitting alone in his room night after night while all of his friends are online having a good time.

I bet most of 'em also have minecraft, but fair 'nuff.
Fwiw we did that with Roblox too, but I hate it because Roblox Studio was a pretty damn fun collaborative gamedev experience.

I mean his classmates argue with their parents about whether they can install TikTok (and most parents lose). Meanwhile I’m denying my son the right to make a game together with a friend. It’s so creative and so educative and I’m saying no to it. It sucks and I hate Roblox for making something so cool and then taking it away for such stupid reasons.

I’d happily pay a license fee or sth. But I’m not gonna let them scan my son’s face.

There's plenty of ways to make games outside of Roblox. Maybe they could sit down together and work through some Löve2D or Godot tutorials? No one can take that away arbitrarily
I think GP meant “collaboratively” as in collaborating online through the game itself. The same way you might e.g. collaborate on a Google Doc.

“Sit down together” might be impractical here, if GP’s child’s friends are e.g. friends they made before a move, who are thus quite far away physically. Or friends with snobby parents who won’t let them come over to GP’s house for whatever dumb reason. Or friends with extra-curriculars such that their free time never lines up with GP’s kid’s free time—meaning that only async collaboration will work.

(That’s just a steelman position, though; in general I agree.)

You are correct. And they do sit down together. Hours of ridiculous ideas flowing, and then when they go back home they can continue working on it. Or, well, they could until recently.

This thread is like me complaining Google face-scan-gated Google Docs and people are saying “he can just sit down with the friend and learn LaTeX together!” Yeah, no.

Neither multiplayer gamedevving nor multiplayer game playing are supported as well by either of these.

Fwiw he does Godot too. It’s fun, but it’s purely solo. Godot’s answer to collaboration is Git, which is a complete non-starter for a 13yo. Note, I don’t judge them for it, they compete with Unity, not with Roblox.

>There are other options, such as refusing games that require them.

How about the option of the state not being so tyrannical in meddling about what people anonymously do online in their free time?

This is generally my opinion, and goodness it's swung around quite a bit. This entire debate feels like it should be solved by adequate parental controls.

To the extent that it matters, I think the missing link here is "primary education should support a parent's intent to limit unrestricted internet access for their children." That is, during school activities where internet use is unavoidable, require supervision. (Maybe a lab monitor that can roam the room and see screens?) And for homework, don't assume the kid has internet access, because that is the parent's choice, and they may well not. On the flip side, if the parent trusts their kid with that access, or intends for them to learn through real world experience, let them. That should not be the state's decision.

The problem of course is that this idea in my head is a pipe dream. Schools seem to be well onboard with digital coursework, presumably for efficiency reasons? Unclear. I'm not sure what a more practical middle ground actually looks like.

The California Digital Age Assurance Act is a law mandating adequate parental controls. And it's a great law that should be copied instead of doing the verification nonsense.
To the extent that it matters, I think the missing link here is "primary education should support a parent's intent to limit unrestricted internet access for their children." That is, during school activities where internet use is unavoidable, require supervision.

Don't get me started. We try to restrict internet time, no Youtube (Shorts are poison/heroin), TikTok, etc. They go to primary school and there is a teacher that makes TikTok videos at school, they can play Roblox in breaks, etc. (Aside from this issue, the teachers are great though!)

There are only so many battles you can choose as a parent (not getting your kids photographed, put on Facebook, etc.).

In contrast to what the grandparent states, the government should unambiguously state: no smartphones, social media, and online games in primary school, period. That's the only way to make it work. Ironically, smartphones are forbidden in all high schools here.

I agree to prohibit them in schools, but at home it should be the family's decision.
You think most of the unsupervised internet time is happening at school? I mean, maybe it is, but that's an assertion I haven't seen before.
Truthfully, I don't know! Especially for younger kids though, there's usually at least an adult in the room, right? Even when they're visiting a friend, the other parent is there to step in and check on them occasionally?

I guess once you hand your teenager a smart phone (and all their friends have one too!) all bets are off. That's new, and wasn't a thing when I grew up. We were rural and on the tail end of dial-up, so I couldn't get online at home without someone hearing the modem. That sure limited my attempts to do so without permission!

Homeschool and exercise close, very close, supervision over what your kids do on the internet.

I'd have hated this as a child. But the case for unrestricted internet and social media access for children being harmful, at this point, seems pretty shut.

For those who sadly cannot homeschool their children... well, we need to push for school choice and to dismantle the teachers' unions. Which probably ultimately is the same thing.

In many European countries, homeschooling does not really exist. For good reasons. Mingling with many kids from the same age cohort with diverse backgrounds is good for kids. Homeschooling is also often used by religious zealots to indoctrinate their children.
People with bad takes like that give homeschooling a terrible name, and make it easier for those regularly trying to dismantle it. It's an excellent tool for responsible parents, and a horrible weapon in the hands of zealots.

I am thankful to have had extensive access to technology as a (homeschooled) kid, and parents who encouraged curiosity.

Destroy "optimize for engagement" social media, which harms everyone, and stop pretending like this is some problem that only harms children.

As a purely tactical measure, we use the same older person (me) for age verification for all family members - zero failures so far and it poisons the well.
In the case of Roblox they have a horrible system where they estimate your age and only allow you to interact with people of a similar age, meaning if you verified your kid with your face then they'd only be able to interact with adults and not other kids. At least that's the theory. It doesn't take a lot of effort to figure out how a predator could misuse this system to their advantage (which is why I call it horrible)

Reference: https://en.help.roblox.com/hc/en-us/articles/39143693116052-...

Predators have been using roblox since its inception, but I don't think they are doing age verification because of that. They're looking to expand into more adult experiences and, of all horrible ideas, dating.
I think it is much simpler: they are feeling regulatory pressure. In various countries there are increasingly strict laws that allow people to hold companies accountable for issues on their platform. By using age verification, they can increasingly move responsibility away.
I’ve seen Roblox invest and conduct child safety research for several years now.

Maybe they are expanding into other industries, but the safety focus predates that.

> As a purely tactical measure, we use the same older person (me) for age verification for all family members - zero failures so far and it poisons the well.

Is there a 'break glass' workflow in case you are not available (e.g., health incident)?

We only do it for one-off age verification, not stuff that requires repeat authentication (those we simply don't use).
You can (and should) be mad at the government and at Roblox at the same time.

Also, don't use Roblox, you can freely share games made with PICO-8, Löve, Godot, Rpgmaker, Game maker and the like, no need to go to the hell scape that is Roblox and its dark patern and locked down ecosystem.

My kid does Godot and TIC-80 (a bit like PICO-8 but more forgiving) as well. Those are great but they don’t beat Roblox on distribution nor multiplayer by a long shot.

I agree that Roblox is a hellscape when you want to make serious games, eg make money from it or sth, but if you just want to mess around making a “supermarket horror tower defense” game full of in-jokes and then have all five of your friends join it, and It Just Works, sorry but nothing comes close to Roblox.

Until they required age verification for that ofc.

Also, just don't ever buy any Robux and kids will auto steer away from the shitty games that need it. That filters out 95% of the badness of Roblox right out the gate.

Yeah multiplayer is kinda problematic because of port forwarding and dynamic IP.

S&B or other engine-as-game solve that by using the platform account system and master server for discovery and NAT punch through.

None of the engines you mentioned are nearly as approachable as roblox when it comes to making a 3D game with little programming or art skills.

Don't get me wrong. I agree roblox is a very shady operation, but that does not erase the fact that their platform is unmatched when it comes to letting kids make games.

> Don't get me wrong. I agree roblox is a very shady operation, but that does not erase the fact that their platform is unmatched when it comes to letting kids make games.

Ok, well then, toss your hands in the air and throw away all your principles then, I suppose.

how is the view in your ivory tower?
Pretty much the same as my view before roblox even existed, which is not bad.

How is the view in your FOMO dungeon?

RpgMaker is really approachable for a 13yo.

There also Luanti, the new name of MineTest, which is closer to the Roblox experience (in the sense that there already a playable game there, and creating new stuff is closing to modding than to game making).

The Roblox experience also includes a huge existing player base who may come and play your game without having to install anything new on their machines. I'd say this social factor actually matters a lot for Roblox where many if not most games are multiplayer.

The only thing close is minecraft, which from what I heard already has similar restrictions on in game chat, plus other shady maneuvers from Microsoft.

Of course Roblox have more player, but does your child really need millions of players?

It's the same network effect with other megacorp, we could argue the same about X/Instagram/Mastodon, the question could be changed to: Do you want your children to be groomed to use closed source ecosystem from shady companies or do you prefer they gain experience in using relatively open ecosystem ?

Luanti let you make multiplayer games/mods too. For Minecraft there way to play outside of Microsoft sanctioned versions and servers.

> Of course Roblox have more player, but does your child really need millions of players?

Nobody uses platforms because they are are looking to exercise billions of options. The point is easy commonality. You sit next to a kid, and, what do you know, they are into Roblox too. Cool. Wanna play?

It's the difference between getting a trickle of random players on the map vs. never ever seeing another player.

For Minecraft random people are more of a nuisance than an asset, but for a Roblox obby there is an expectation that other people will check it out.

When I was a kid I loved this obscure multiplayer game engine called BYOND. In fact it's so obscure that even mentioning it provides several bits of fingerprinting. It technically still exists today, but it's been on life support for 15 years. We should make something like that again.

Besides the game engine, it provided central identity (optional - you could allow players to sign in as Guest), a website to browse games and servers, a forum to discuss games and programming, and an IDE with a built-in sprite editor (it was 2D), map editor and object browser.

I hear you on the overall privacy issues related to age verification with US Corps. My concern with government registries of personal information is related to things like:

- Netherlands, WWII: The Dutch civil registry meticulously recorded religion. It’s a major reason ~75% of Dutch Jews were killed, the highest rate in occupied Western Europe (vs ~25% in France, where records were poorer).

- US, Japanese internment: The Census Bureau provided block-level data on Japanese Americans in 1942 despite confidentiality guarantees; 2007 research showed individual names and addresses were shared too.

- Rwanda, 1994: Belgian colonial administrators had put ethnicity (Hutu/Tutsi) on national ID cards in the 1930s. Sixty years later those cards were the primary tool at genocide checkpoints.

There’s loads more. Europe may be safe now so it feels safe to give government this information. However, as shown in all the instances above, the information was collected for one reason and used for a wholly different reason when times changed.

Who knows what kinds of ethnicities, beliefs, behaviors or personal histories will be the focus of future regimes? It could be Roblox users, HN commenters, people who religiously repost x.com links as xcancel.com ones, anything. Whatever it is, they will have access to all the data on any system we allow them to record. This isn’t even a totally made up hypothetical from far away places, multiple governments in Europe were doing this kind of thing just decades ago. Historically speaking, we are all currently living in an unusually peaceful era, that will likely be temporary for many of us.

> - Netherlands, WWII: The Dutch civil registry meticulously recorded religion. It’s a major reason ~75% of Dutch Jews were killed, the highest rate in occupied Western Europe (vs ~25% in France, where records were poorer).

Records were poorer in France because René Carmille and the French resistance sabotaged the machines. Machines made by a large tech company which was a competitor to IBM.

> Who knows what kinds of ethnicities, beliefs, behaviors or personal histories will be the focus of future regimes?

Absolutely. But I do know who has that data -- big tech, and it's willing to sell it for a nominal price. No doubt that price will be higher for a deaparate government wanting to kill everyone with green eyes, but that just means a higher profit margin for facebook as they mine their shadow profiles.

Tech bros will be lining up to gifting it along with a golden statue to whichever dictator they wish to carry favour with.
My opinions is that an idiotic government will use whatever data it can find, and we should be more worried that one appears than imagine that because they do not have some data they will not do some idiocy.

I am not for collecting all data without a reason, sometimes probably too much is collected. But idiots can come with any rule if they want just to find someone to blame (I mean, they already use skin color or accent so if in need, they can come up with a rule like "born on a Monday").

I guess that is one way to manufacture consent.
As another European, I agree with GP.

I don't fully trust my government. But I definitely trust it more than any American tech company.

I can also vote out my government. I can't do that for Big Tech.

> I can also vote out my government.

You can't. Not if you're in the minority. Tyranny of the majority is still tyranny.

You what you as an individual most certainly can do is stop using Roblox. Not ideal, but way easier than moving to a new country.

Tyranny of the majority is ... democracy?!
Unrestrained democracy, yes. Tyranny.

People need to understand that having a majority opinion does not inherently give you the right to impose that opinion on everyone else. Such impositions must be done with extreme hesitancy and restraint.

That's why many democratic countries have a constitution which prevents the government from restricting certain individual rights even in the face of popular opinion. But ultimately, the constitution is just a piece of paper. If people are determined to impose their will on others, it can only do so much.

"Inherently give you the right"? Rights are not inherent properties of facts, they're concessions between people. Nothing inherently gives rights, rights are given by agreement. If people agree that majorities can impose their opinion, then they can.
Everything you do affects others, unless you live in a cave in the mountains somewhere. Part of the reality of living in a society is constantly negotiating what is and isn't acceptable.

Democracy is the most fair way of doing so.

Yes? Democracy is essentially exactly that - tyranny of the majority. The reason why successful democracies have so many checks and balances, constitutions that uphold essential rights etc is because of this fact. Really the main benefit of democracy is that it prevents the government from doing things which are wildly unpopular. To the extent that it "gives the people power", that is neutered as much as possible to prevent the majority from going "hey, we don't want these people here" and committing democratic genocide or whatever.
The slave aristocracy of the Confederate States of America, and members only Communist Party of China are both democracies.

What we consider democracy went through a LOT of iteration, and continues to this day. Representative first-past-the-post is a form of democracy that can have the unfortunate side effect of the minority of the electorate establishing a tyranny of the majority. There is a lot of scholarship on how to make democratic systems more democratic.

> The slave aristocracy of the Confederate States of America

And the northern states--they had slaves too.

Ulysses S. Grant, when asked why he didn't free his slaves until some time after the war, reportedly said something like "Good help is hard to come by these days." It's not easily verifiable in today's world of useless search engines and confidently wrong and/or lying AI, but this quote is, in one form or another:

"The sole object of this war is to restore the Union. Should I become convinced it has any other object, or that the Government designs its soldiers to execute the wishes of the Abolitionists, I pledge you my honor as a man and a soldier I would resign my commission and carry my sword to the other side."

- General Ulysses S. Grant, USA, in a letter to the Chicago Tribune, 1862

"My paramount object in this struggle is to save the Union, and is not either to save or destroy slavery. If I could save the Union without freeing any slave I would do it, and if I could save it by freeing all the slaves I would do it; and if I could save it by freeing some and leaving others alone I would also do that. What I do about slavery, and the colored race, I do because I believe it helps to save the Union; and I forbear because I do not believe it would help to save the Union."

- Abraham Lincoln, responding to Horace Greeley at the New York Tribune

Not necessarily.

You can democratically trample the rights of minority groups.

Since it hasn't been linked in the tree of replies here, I'll add this for others: https://en.wikipedia.org/wiki/Tyranny_of_the_majority

> You can't. Not if you're in the minority

Is that a bad thing?

Compared to multiple competing privately run systems, which you can opt out of even if you're in the minority? Yes.
> Not if you're in the minority. Tyranny of the majority is still tyranny.

> you as an individual

I understand. Such is living in a society. No man is an island.

> Not ideal, but way easier than moving to a new country.

I've moved countries five times. I still haven't been able to get rid of my dependencies on Big Tech.

Most people can't move anywhere because getting citizenship is difficult.

Meanwhile, all you need to do to get rid of a dependency on big tech is to log off.

That seems backwards to me. You can choose to personally not do business with whatever big tech corp you dislike. Men with guns will show up at your house if you stop "doing business" with the regional government.
I can choose to move (and I have!), I can't practically quit my dependency on tech.
I am also European, not sure why that matters though.

This type of argument always sounds to me like someone was abused by their ex-partner, but now prefers their new partner who abuses them a little less.

This is a common negotiation practice in business as well as politics. You make some absolutely outrageous demand, and people protest, but then you give them the -originally planned- light version of it, and they will accept it; in light of the worse option.

There is no reason to endure this BS, hence I referenced manufacturing consent.

I sometimes can not believe how easily people allow themselves to be manipulated.

///

And you can vote out "Big Tech" - by refusing to use their products. Giving up your rights to play some videogame, as GP outlined, is an absolutely sad thing to witness. There are people who fought and died for the rights we have, and we allow them to be eroded for some silly consumerism.

> And you can vote out "Big Tech" - by refusing to use their products

That argument completely ignores network effects. Case in point, Twitter is, for better or worse, still where a lot of public figures post their updates and announcements. It also now randomly bans people unless they give their biometric data to an oligarch that supports right wing extremists: https://www.reddit.com/r/privacy/comments/1ukil0b/twitter_x_...

I'm not sure what that has to do with age verification or such things, and even if you don't want to use the platform directly you can use mirrors like xcancel.com or nitter.net as drop-in replacements (which I use.) I dont think that site has any age verification measures implemented that are mandated by law as of now. But I'd just stop using it if they did or if the mirrors stopped working.

All in all, I'm not sure if it has anything to do with the original topic of EU being about to enforce 'age verification'.

Things look different if you’re comparing an American tech company to an American government.
That adds to the concern as a European. Thanks to the CLOUD Act, sharing data with an American tech company effectively is sharing data with the American government.

And that I would definitely like to avoid.

The American government isn't going to send armed goons to my doorstep anytime soon.
These days, I wouldn't be so sure. Hell, they even did it to a sovereign head of state.
> I can also vote out my government.

No.

The original design intention of this approach was that wallet apps were independant and interchangable, with any wallet app able to talk to any attestation provider, to get age attestation tokens, and any site/app able to talk to any wallet. The wallet's job was merely to securely hold a bunch of attestations tokens, and dispense them to other sites/apps on request.

So you could use an open source app, or government provided one, or one provided by your bank, whatever you trust the most to not be recording data about relying parties and sending it somewhere you don't want.

The version of the document currently on GitHub has heavily deviated from that original intention. This is very unfortunate.

Even so this version is supposed to still be incapable by design of sharing any data with a relying party other than "over 18" and was designed such that the only way for a relying party to determine your identity is to be colluding with the attestation provider, or by colluding with the wallet app.

To attempt to address the first issue they have the unfortunately optional ZKP protocol. The original design assumed that users could find a wallet that they were certain would not collude with the RPs, and was considered a non-issue, but unfortunately it is a huge hole in the current version.

Same as for banks. Downloading some verification app with a confidence inspiring 1.2 rating on the app store, getting on a call with some random gig worker looking like they are taking the call in their living room and wiggling your ID around while giving a thumbs up is not the way I would like to prove my identity to a bank.

But there's no alternative. The EU digital identity wallet would be the alternative. You control and exactly see, what kind of information the bank is getting from you and you can be sure that it doesn't flow through some sketchy third-party identification service.

It doesn't have to be an either or dichotomy. For example, you could pass laws that make it illegal for an online game to demand age verification, identification, biometrics, etc. The main reason for any of this are some corporate attorneys justifying their own salaries based on "what if" and scaremongering. Regardless of how much personal information they succeed at demanding at this stage, or how [in]effective it is at addressing their claimed problems, they will be back again pushing for even more until they're actually told a hard "no".
> Roblox made a change where you’re not allowed to share your games with friends unless you do “age verification”

My son had a similar "making games" interests and I just showed him the Godot engine. Roblox bosses are doing you a favor. Act now :D

Here in the Baltics we already have an app for that. It's used to login to banks and government websites.

Recently one supermarket chain added it for age verification on their self-service checkouts (e.g. buying alcohol).

The problem with this is you do not know what information they get, I guess the supermarket gets my full name, date of birth, personal code, etc. Their privacy policy says it will not be stored, but that means nothing.

https://www.smart-id.com/

> a government supplied app, that’s guaranteed to protect my privacy

This is a bit of a 64,000 euro question, though. Look very closely at what the government exemptions for GDPR are.

What are they?
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-re... for example. (Yes I know about Brexit, but this is basically identical to when the UK was in the EU and subject to the Directive)
> this means sharing your 3D likeness with some sketchy American business who pinky promises to delete said data after. I don’t want random American tech companies to have my kids’ biometric info like that, able to sell it to whoever asks. Nor my passport or anything like that.

Actually the market leader app for scanning faces and documents is an Israeli company. They encourage to use mobile for scanning, for your convenience. They promise they delete the data. Yeah, if they're lying you can sue them in Israel.

What you’re proposing works only if the government is always trustworthy and abiding by the rules. But there has been cases that ICE agents in US was able to track down people from their social media posts and in the past Nazis used the address registration lists to track down Jews for deportation to concentration camps.

We don’t know what EU would become in 5 to 10 years in the future, and I would rather not have any identification information about me or family being stored by a government body or any other party that can track/link me or my family members

They have this information anyway if you have an EU passport or an identity card. The government app allows you to share selected properties of these documents with third parties.
It’s not only government shares that info, the government can keep track on with which parties they shared that info and for what purpose.

As an example if I’m obliged to share my ID data via government to open a twitter account how would I know that the government would not link my twitter account to my ID and later use that info keep track of me and prosecute?

People would think that it would never happen, but not long ago that actually happened in East Germany. The Stasi kept track/files on almost every East German and this would be a digital version of the same thing

The app is open source, and it doesn't do that.

I agree that governments should minimize collection of their citizen's data. I just don't see where it is supposed to happen in this case.

What would you do that, they start with open source app, make the online is mandatory and once it’s established and mandated, then they closed source the app and implement data collection?

There is no guarantee that the app would stay open source and under public scrutiny forever. Governments have done way shady things in the past. Given the recent push for chat control, I would never trust anything put out by EU.

Anyone else remember when RFK Jr wanted an autism registry?
> a government supplied app, that’s guaranteed to protect my privacy

[citation needed]

Funny you use Netherlands as a good example, considering that famously, their existing unusually thorough registry was super helpful for the Nazis rounding up jews later.

I don't think it's Godwin's Law when you are so spot on, exactly describing the worst case.

Additionally there was a leak of the personal information of covid patients, the official tracking app was not affected as far as I can tell.

However even if the app is secure the storage and handling of the information is a different matter and it has been shown that care is not always taken.

> Funny you use Netherlands as a good example, considering that famously, their existing unusually thorough registry was super helpful for the Nazis rounding up jews later.

To avoid rounding up the jews you... create a government that doesn't round up jews.

You don't fight arbitraty useful tools which then end up in bizarre situations like in US where people can't vote because of this bizarre idea that government shouldn't track voter lists.

EU governments mostly have a list of registered citizens with their birth dates and their adresses. And noone has been rounding up anyone for almost a century... something we can't say for another world country which apparently doesn't keep records of their voters (useful to prevent people of colors from voting!) and somehow is rounding up people on the streets right now.

Yup, "just don't do that, then" is better.

But I have to point out that NL gov did not round up jews, but the bad outcome arrived anyway, from outside the system. So in the example we're talking about, that was not a solution.

Other than that, I agree.

Not necessary to hearken back so far in history. In our present age the intelligence services consistently do not respect privacy rights of citizens, even when they are legally bound to.

https://www-bitsoffreedom-nl.translate.goog/2026/07/06/aivd-...

Sure, but the poster was not just wrong, but wrong like "peace in our time" wrong. "Adolf? What a charming name" wrong.

Amusingly fantastically wrong.

NL may have its own issues like you linked to, but more uniquely had their collected data abused more than other countries in probably the worst event in history.

I don’t follow. The Dutch tax office has substantially more complete records right now. Even if they don’t track race or religion as explicitly as they did in the 40s, your hypothetical invading Nazis can run some local AI over people’s last names and get close enough.

How is, of all things, an age verification app going to make that worse?

I mean I understand your argument in principle but it seems you’re arguing against ~every present-day functional government and not against an age verification app.

I'm not even saying your conclusion is wrong. But choosing Netherlands about how information control is safe in the hands of the government is a bit of an own goal.

Like if I was the boss of a train company I would probably not put up a photo of Mussolini as a motivational poster. Well… maybe I would, but only ironically.

> How is, of all things, an age verification app going to make that worse?

What are you arguing for, here? If everything were perfectly anonymous, maybe. But NOT ONCE in history has governments decided to not abuse power. It'd be so easy to just put a tracker in there or something.

All these "think of the children" arguments are ALWAYS red herrings. Literally any action, any freedom denied, can be justified in the fight against CSAM. And so they get rushed through and abused.

The EU DNS filter (CSAADF) was literally IMMEDIATELY abused to block other things too.

"It's just age verification". Is it, though? How do you verify age without verifying identity? How do you verify its use, without tracking. Provably without tracking. Provably without what's called "turnkey tyranny"?

I think if your argument, which is an extremely common argument, is "I just want to block children's access to bad stuff on the Internet", then you cannot possibly have been paying attention to this debate that's been going on since at least the mid 1990s. Were you even born when this was being discussed? If that's your argument then you have about 30 years of catching up to do before you should speak.

[1] yes, I know Mussolini did not in fact make the trains run on time.

>how do you verify age without verifying identity

zero-knowledge proofs

Then you only know that someone is over 18. You don't know who is over 18. In particular, you don't know it's the person who's accessing your website.
that's the same situation as children putting in their parents details/scanning their face/whatever, you're not going to solve this technically

the point is non-govt entities shouldn't get any information about you during age verification other than that you're over 18 and that's what ZKP can give you

Your comment sounds like a politician who has just heard a magic technical incantation that solves everything.

I'm sorry, you can't just drop "quantum computer", or "zero knowledge proof", or "flux capacitor", and think that you have solved the problem.

Just dropping "zero-knowledge proof" as if it's a mic drop moment is like when Turnbull said "the laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia".

The devil in all this is in the details. Just saying "zero-knowledge proof" is just barely more productive than saying "won't someone please think of the children?".

If you don't have a complete solution, then you're "not even wrong".

In addition to that, you have misunderstood how zero-knowledge even addresses the main problems. Not the technical problems, and DEFINITELY not the meatspace problems.

literally 0 substance in a 5 paragraph comment, I'm starting to think this might be a not-exactly-human poster
Why would an age verification app need to know your ethnicity/religion?

Governments likely already know your name, age, place of birth, so having an app with a standard API for verifying users isn't giving the government additional data.

It is one extra attack vector. There is a data leak reported every week, and it is now apparent we cannot trust any organization to handle any datum securely, at all. It has gotten to the point where I now consider every piece of information compromised and sold on the dark web as soon as I am forced to transfer it to a third party. Because those are the odds.
It's also replacing all the personal information stores from thousand applications and websites you have previously registered, or would have to. So arguably it's thousand attack vectors less.
Doing absolutely everything useful with that data is "one extra attack vector". That is not any kind of a persuasive argument in itself.
It may not record your ethnicity or religion, but ID documents certainly record your sex, and plenty of authoritarians seem interested in identifying individuals for whom this database column has been updated.
"government" age verification app will be made and maintan ed by some corp anyways.

so it will gather extra data, sell it sideways and leak like hell. (as they already do with all the data they already have)

Since it requires Android or iOS, Google/Apple can gather the same data too.
They did this from the beginning, still one can not cease trying to limit the exposure.
I'm imagining something like recreation.gov in the US - it's the portal for booking campsites and other activities at national parks. It's run by BAH at great profit - most of the fees we pay aren't going to the national park service, it almost all goes to our corporate overlords.
Governments will track with whom you verify. Much worse.
Can we not spread nonsense narratives? One of the explicit requirements of the EU age verification system is that they cannot:

https://digital-strategy.ec.europa.eu/en/factpages/blueprint...

First, the user downloads the app onto their phone and sets it up by certifying their age. This can be done with a biometric passport/ID card, a national eID (e.g. national ID Card or other electronic identification mean), a pre-installed third-party app (e.g. a banking app), or in person (e.g. at the post office). Only the information confirming that the user is over the age will be saved in the app. No name, no birthday, or any other data is saved.

After completing this step, the communication between the app and the provider certifying the user’s age (e.g. eID, third-party app) ends. No further data is exchanged.

https://digital-strategy.ec.europa.eu/en/faqs/eu-age-verific...

The app will likely have access to a bunch of unique identifiers on the phone. At least on Android whichs core concept is spying on the user.

For me, it's enough that your activity could be linked to any unique identity. I don't want mandatory government apps on my phone, that's very chinese. We should strive for better.

Edited to add: your linked FAQ conveniently leaves open how the communication between the web site and the app happens. There are myriad of ways that ones behaviour leaks in this step.

Then get your kid off Roblox. I promise you that Roblox exploits more children in a single day than all sex offenders put together do in a year.

Why is pedophilia such a problem on Roblox? It's because they heavily advertise towards children and one of the fastest ways for children to make money is asking their parents, then next is prostitution. Roblox is uniquely bad because they heavily advertise both products and the "self-made entrepreneur" image to children.

Putting the blame on nebulous "predators" when the system itself is clearly to blame is the very tacit Roblox relies on. Look at vehicular manslaughter are drunk and distracted drivers solely to blame for deaths? Clearly not since there are just as many drunks and phones in Europe as in the US. When the system creates more predators than exist otherwise then you know it needs to change.

If your son likes making games keep him on Godot. Your job as a parent is to find or build a good distribution system. you can see if he is generally interested or if he was pressured by an exploitative system grooming him into pumping out slop for the trough. Age verification is going to make the platform more exploitative in the business sense. Both in that it legitimizes bad practices and lets Roblox target their exploitative practices more effectively.

People don't want to make games, they want to make multiplayer games.

Very few kids are going to go though the incredible difficulty of making multiplayer work in something like Godot.

Check out Luanti. My son pulled off his own multiplayer game, by mixing some existing mods and writing a pinch of Lua. He is not into programming, and he did not even use LLM, do it was probably not all that hard. And the result was impressive, and I say that as a professional programmer.
This doesnt work when all of his friends are playing Roblox and play each others games on there
The "app" could be a good solution, if it didn't require attested Android or iOS. It could, for example, have me plug my ID chip into my GNU/Linux system and expose it with a standard protocol. That would be no problem. The problem is that they do not want such a way.

In any case, I think that age gating would not be needed if the platforms were regulated to remove addictive recommendation algorithms.

ID chip? Is that something everybody in the EU (or whatever region) has? Is it just embedded in your driver license or passport?

[I'm in the US, we're very ID-averse here, weird, but is what it is]

ID cards aren’t exactly super standardized inside the EU. German ID cards have a RFID chip which basically contains all the same info that’s printed on the outside (PIN protected).

Smartphones can read that chip and the state as well as private businesses could in principle use this to do age verification – even the super minimal version of age verification that just asks for a certain age threshold and gets a binary response whether that threshold is met. (Which to me if we can achieve it is the perfect solution.)

The infrastructure is there and since 2017 those RFID chips are even actived by default when new ID cards are issued. (The cards are valid for ten years so nearly all ID cards have those active chips.)

The biggest issue currently is a network effect one: hardly anyone is using the chip so people don’t create their initial PIN, creating a UX hurdle for adoption. (If you want to use your ID card chip you have to find your initial PIN somewhere in your documents – if you didn’t throw it away – and then create your proper PIN, you can’t just start using it.)

I can sense usage increasing but exactly because of the poor initial use UX all sorts of private alternate solutions exist that are plain worse from a privacy preserving point of view. For example ones where you film your ID card from both sides (so the hologram is visible) which just suck. (You just share everything … which is just so unnecessary.)

To change this we would need a policy that requires age verification without sharing the birthdate or any other PII.

Yeah, that sounds like the ideal solution.

Unfortunately, we can't even get states to commit to our RealID requirements[1] (which doesn't even add a chip/PIN, it only strengthens validation of documents submitted at the time of application for a driving license). And the notion of a national ID is anathema to large swaths of the population.

1 - https://en.wikipedia.org/wiki/REAL_ID_Act

Many (all?) EU countries have a national ID card, and most (all?) IDs has a chip that can be used for secure document signing. I don't know if it can be used by itself for age verification. Maybe it would need to contrast your signature with some sort of DB that can retrieve your age...
Using an ID card reader is already possible. See here for a list of Linux repos supporting German IDs: https://www.ausweisapp.bund.de/en/open-source Finding a working hardware/software combination for your ID card is up to you.

The app is an alternative for people who don't want to buy or carry around a card reader, but who already have a smartphone.

It is possible for e-signatures and similar variants. However, there is no sign that the "age verification" will support this variant. If you go to the demo <https://cinema.ageverification.dev>, no option is given other than the Android/iOS app.

So it seems that the app is only an alternative in the case of government portals, but it is not an alternative for "age verification".

The German implementation already allows it. The GitHub issue you linked to explains multiple times that it is a reference implementation, as have several previous HN comment threads linking to this page. It is not the actual implementation that any country plans to use.
The German implementation allows it for some uses, but not for "age verification". The demo does not account for the fact that other options may exist.
We have had the need to prove age for hundreds of years. To buy alcohol. To drive a car. To vote. We depend on government-issued documents to do this. Not sure why anyone would really expect this to change just because it's online now.
Older systems were imperfect and were understood to be. I've meet veterans who joined the Navy at 14 or 16. I've met many College students who can pass as old enough to buy alcohol, especially with a fake id. Dead people are sometimes registered to vote. We know this and have systems to try to catch these exceptions.

But cellphone access is different; it's assumed to be perfect, but it's increasingly being moderated by machine learning heuristics that serve as judge, jury, and executioner, severing your services if a couple of your actions trigger a fuzzy approximation to some of the training data.

AI moderation helps suppress spammers, but it's also punishing false positives, and there is just no recourse. Any ID system that piggybacks on "Apple | Google" is effectively shunning some non trivial portion of society. Governments of the people need to provision their own tech systems that are accessible to all citizens, even those who have run afoul of an AI moderation system.

This year, an octogenarian friend got locked out of his android phone permanently. He had never had a PIN on his Samsung phone.

It started when he signed up at a new bank, giving them his phone number. Somehow the bank enrolled his in their online banking system, which notified Samsung, who remotely initiated the "let's give your phone a pin" flow, presumably to protect him during online banking. (This happened without his knowledge -- he had not installed the bank's phone app.)

Later that day, when his phone went into a modal "let's setup a pin" screen, he panicked, assuming an attacker had gained control of his phone, since this was not something he initiated. No button would let him exit the screen, so he powered it down. Now, when he powers it up, it demands a pin, but he doesn't know what pin that would be. The only way to get the phone back would be to factory reset it, meaning he'd be wiping his data. He had the money to replace his phone, but that may not be true of every citizen, especially at his age.

People assume digital auth systems are perfect. But you don't hear from consumers who can't get online to tell you "I've lost access."

I've shared some other similar stories: a widow who got banned for life from facebook within minutes of making an account from an apple device on a consumer ISP with her real cell phone number.

A coworker attempted to sell his son's sporting goods on facebook marketplace and was banned for life with no appeal because AI thought it was "weapons."

Some high school students each made a gmail address from the same laptop one afternoon, only to be banned the next day. Each supplied their own cellphone number, but the accounts got shut down, presumably because multiple accounts were being created from the same device too rapidly.

AI moderation means there are a ton of unwritten rules, and private companies will keep you out of their platforms if you break them. That's fine, but it means governments have no business serving their citizens from these exclusive platforms.

> e signed up at a new bank, giving them his phone number. Somehow

It started when he signed up at a new bank, giving them his phone number. Somehow the bank enrolled his in their online banking system, which notified Samsung, who remotely initiated the "let's give your phone a pin" flow, presumably to protect him during online banking.

Do you have a proof that this actually a thing? I don't see what mechanism exists to do this and I don't see why Samsung would even bother to do this.

Perhaps cooincidence and Samsung pushed an update that now required a PIN, but there was an untested failure mode (rebooting the device after the PIN setting process had been initiated but not completed).
I've never gotten banned but I've been moderated/throttled (even here with the occasional "you're posting too fast") quite often. The triggers on things happening too fast from the same IP address or session seem quite sensitive and thus when I'm doing anything critical such as online transactions I space them out by many minutes, which is inconvenient.
> That's fine

No it's not. Government use of these platform or not, once they become big enough being cut out of them means being cut out of a significant part of society. We shouldn't accept "no recourse" and "no due process" just because its a private company.

Hundreds? 200 years ago most people did not even have birth certificates. I can think of multiple famous examples of people who lived in Europe 500 to 800 years ago where we don't know their real age. In existing countries with poor state capacity, a lot of people don't have legitimate birth certificates and there is some evidence that they make up their age to some degree. For example on surveys in such countries there are too many people reporting round number ages. My experience in such countries is that you can find very young looking males riding motorcycles late at night around the city and anybody can buy alcohol. That's how it was in the United States "hundreds" of years ago. Please read a book.
Very obviously because privacy advocates are concerned by the effects of mass deanonymization. I find it doubtful that you don't grasp that.
I bought a bag of chips without having to show my ID.

There is a big difference between: Government demands every website to have age verification, and government supported scheme by which service can opt into age verification.

As of now, American private spyware is actively filling the demand.

I get the feeling some privacy advocates are approaching the choice as a tier system, with government being the worst case.

I don't see it.

The only viable solution for the future of privacy is to not be dependent on the giant platforms in the first place.

Government is demanding age verification because the websites and platforms completely punted on the issue of keeping inappropriate content from children. Yes parents have a role here but we live in a society and we depend on/demand everyone doing their part. We (the tech sector) made our own bed here.
> Government is demanding age verification because the websites and platforms completely punted on the issue of keeping inappropriate content from children.

Nah. Parental Controls are baked into every major consumer OS. If government cared about giving guardians the tools needed to care for the vulnerable ones they're responsible for, they'd require those parental controls to be beefed up [0] and that it be a requirement that online services and both local and remote software be required to honor the restrictions required by those Parental Controls.

Instead, what we get proposed is a system that cares very much about how old you are, and not one bit about the things that one's guardian understands one needs to be protected from. This system will work for some under-eighteens, but it will fail for many others, as well as every single dementia-damaged elder or brain-damaged/developmentally-stunted adult.

What's being proposed is absolutely not about protecting people... if it were, the mandate would be to beef up the existing fully-anonymous systems, rather than requiring identifying information from users.

[0] ...I mention this because I often hear in Internet discussion that these controls are insufficient, not because I have personal knowledge that they're inadequate.

Nah. Parental Controls are baked into every major consumer OS.

Even the parental controls that are there are a train wreck. Our kid has an iPhone and the parental controls have all kinds of weird issues like, you give them 15 minutes of WhatsApp daily. First time on a day they start WhatsApp it says that all their time is up. Or suddenly they cannot run an application that was permitted by a parent. Then you uninstall and install the app again and suddenly it works.

It is unusable.

There web is also a huge hole in all of this. A lot of services you can also use as a website. A whitelist is too limiting and a blacklist is a daily task to maintain (and would require spying on your kid).

I also prefer to avoid age attestation altogether, but I am also not sure what the solution is. I think many people do not realize how much social pressure there is to use certain apps/games and how bad parental controls are. Yes, we say "no" to a lot of things, but you cannot say "no" to everything. Missing certain cultural touchstones (certain TV shows, certain games) makes your child an outsider.

I agree... the government's plan (as usual) misses the mark and probably won't solve the problem. But the reason the government is getting involved is precisely because parental controls (if any) that were delivered by the platforms were too hidden, too complicated, and had to be set for every app or website instead of once on the device and have that enforced on everything.
Parental controls, at minimum, need to be unified. I should be able to deal with the Xbox at the same time as the iPhone. Need a new standard. I need to be able to whitelist and blacklist times and dates, drill down into particular apps/games/services with some decent granularity, do conditional whitelisting, etc. I need a big red killswitch for these right at the top of the parental control app.

Parental controls aren't baked in, they're bolted on and half-assed. One of them I've noticed over the years... I can't disallow Plex except at the app level (outside of Plex entirely). I can't easily give access to the educational libraries, but disallow it to the entertainment libraries. There are a million little anecdotes like that, because no one gives a shit about the problem.

Many parents, I think, are left with all-or-nothing choices. And it's not long before the reddit crowd starts insinuating that the reason your kid doesn't have a phone is so they can't call for help... from you.

It's a big clusterfuck.

So what you’re saying is… the social media platforms/ tech sector needs to take basic measures to make their platforms less exploitative for all users regardless of age? I’m sold. What sort of incentives do you think would be the most effective motivation for platforms here?
Ideally? Doing the right thing. But that's too much to ask.

Ending section 230 might be a good start. Make platforms responsible for the damages done by whatever they distribute.

> I get the feeling some privacy advocates are approaching the choice as a tier system, with government being the worst case.

The issue is that a lot of voices you hear are from a big country which voted for fascists and those people now somehow think that technology will save them from the government they created. But that's not how it works unfortunately.

Privacy is losing ground, despite people understanding the stakes.

Privacy advocacy is losing the battle, because it is being framed as a choice between privacy and the status quo, and people vehemently dislike the status quo.

That's a separate concern from depending on government entities to issue proof of identity/age.
Proving your age is a relatively new phenomenon. My grandmother, born in Chicago in the 1920s didn't even know her exact age. That is not at all uncommon for her generation.
Maybe hundred of years, singular. And reading/watching stuff in our own homes has never required any proof of age.