← Back to context

Comment by dageshi

1 day ago

No offense but if you're proposing a solution that involves whitelists... that solution has already failed.

The web is too big and changes too much and that's before we get to the issue of applying laws to a whitelist based on different juristictions worldwide.

And I have to question, who would administer it? The parents? They won't. Google or Apple? Why do they want to deal with irate parents or culture wars around what is or is not on the list?

There is obvious increasing demand for this from parents, politicians are going to act on it, I think a "this is a child" header is the only one that actually really works. It works for the parents because it's easy to setup. It works for websites because they can cleanly identify a child and filter content if appropriate.

It seems to me that every other solution than a "this is a child" header is either impractical or way worse.

> that solution has already failed.

Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:

https://support.apple.com/en-us/105121#:~:text=Prevent%20ina...

> It works for websites because they can cleanly identify a child and filter content if appropriate.

This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.

https://onlinesafetyact.co.uk/in_memoriam/

The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).

As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.

Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.

But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.

  • You are confusing a lot of different lines of argument, and in the end I'm not even sure what you are arguing against. I think you are mostly agreeing with the proposed solution by echelon?

    You mentioned AB1856 which seems waaaaay broader than emitting an age bracket header based on user settings. It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.

    Websites are shutting down wholesale because they cannot reasonably afford the CYA, or dont want to out of principle.

    In echelons scheme the parent would be voluntarily setting the age bracket on the childs device right, so if a 12 year old is more mature, then go ahead and set their device to emit the 13-16 age bracket header. If you as a parent dont believe in this, then leave the bracket unset.

    For a website operator it would be trivial to block the user from accessing the site if the suggested age bracket is too low (as long as we can agree on a single way of doing things, of course). Larger operators can do more heavy content moderation and present a filtered view to those same age bracketed users.

    It is true you are adding more tracking signals, and I am sensitive to the free speech issues, but children are not fully emancipated members of society yet and parents need tools to deal with the difficulties of raising children in a digital society. The alternative now seems to be OSA-like, which is even more intrusive and a risk to privacy and perhaps free society as a whole.

    Of course, OSA is really the goal and not the method, and we have to remember it is never about the children. Would children have been protected from e.g. andrew mountbatten if OSA had been around at that time?

    • > I'm not even sure what you are arguing against.

      I am against legally requiring devices to transmit a signal that the user is a child to websites. What I want instead is to handle any content blocks client-side. Instead of legally requiring adult sites to verify the age of users, I'd prefer requiring that these sites self-label (or move to an obvious TLD like .xxx), which makes it easy for the device to block it. This accomplishes the same thing without the tracking infrastructure and privacy concerns. I don't want my kid's device blasting that they're under 13 to every sketchy website that asks.

      > It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.

      I believe AB 1856 does not do that any more. As of July 1st, they amended it to remove all requirements on website operators, except one. What it does now is make the app's age signal apply "across all platforms of an application, including an internet website [owned by the same developer]." e.g. the Facebook app gets the age signal, now facebook.com knows the same signal.

      Also AB1856 (and the DAAA which it amends) has no content policing requirements. All it does it force apps and websites to know the age of their users, which then triggers liability under other laws like the up-and-coming social media ban AB 1709 (which I'm against). Or CA's Age Appropriate Design Code act (which I believe is getting tossed around in the courts for First Amendment concerns).

      As far as presenting a filtered view of a website, e.g. Reddit blocking some subreddits for kids, I'm open to debating this. I personally think it doesn't work and platforms will just over-regulate or wholesale ban minors (Claude, character.ai) rather than comply with the patchwork of laws in different jurisdictions. Or they'll spin off a heavily locked-down version for kids only, like YouTube Kids.

      Steam is an illustrative example of how hard it is to get the filtering right. They're trying to comply with OSA but there's still a lot of information leakage between the kid-safe portion and the rest of the platform: https://youtu.be/hOaGUfy6NTw