← Back to context

Comment by scronkfinkle

19 hours ago

I think you may be misunderstanding a bit. There's no forced verification. It'd be more of an RFC that gives parents the ability to communicate their underage child is using the device without revealing or verifying any further information. Or do you suspect that giving any ground will cause the ID verification and centralized behavior?

I think the concern is a forced bit of functionality in all operating systems. It would quickly lead to a "and you need a license to sell your device so we can check that it can't bypass mandatory chuld-safety guards". Just like how some politicians are proposing mandatory licensing for releasing any AI model.

  • You need licenses for a lot of things though, particularly for things where there is substantial harm to be done when done incorrectly. This is just how it goes as things get more popular. Think back to 1903, there was no FAA then, but also no need for one. But it would be super disingenuous to argue now that airspace should be totally unregulated.

    I think the problem with this debate in general is that people aren’t recognizing the harm, and are clinging on to old ideas about how the world should work, ideas that just don’t acknowledge the reality of how things change as technology changes, or even just spreads. Rejecting the idea that there are harms, and thus nothing should be done, just ensures you don’t have a seat at the table at all when it comes to the inevitable decision to do the regulation.

    • I think you aren't recognizing the harm of collecting this information. I might be okay with this if companies were banned from using age for targeted advertising.

      However, the other harm is the recent IDScan hack which leaked 153M people's IDs. And regulation is not a solution here, we don't know how to implement a regulatory regime that will prevent these sorts of privacy disasters. Even if IDScan gets fines which kill the company (and I suspect they will not) it's not enough of a deterrent because no one will pay enough to actually provide proper security here.

    • Licensing for selling anything with a computer in it would cripple competition from small incumbents. They're mostly just regulatory capture for the established players that created the problem in the first place. Age restrictions are also an implicit statement that they are allowed to continue doing the same harmful things to adults.

      Meta, Google, Anthropic, OpenAI etc can afford to pay for and deal with licensing. They also created these issues and would very much prefer not to have to mitigate the harm they do to adults (i.e. people with money to spend). Furthermore, it'd be great if they didn't have to worry about small time competitors emerging and growing too fast. Licensing under the guise of "think of the children" is perfect for them.

I suspect that communicating a flag value of boolean true/false that "this computer is in use by a minor" from the operating system (via browser or app) to a remote SaaS service like something run by Anthropic will be seen as insufficient by the SaaS, so they'll necessitate ID-scan/live-selfie verification anyways.

Meanwhile, the age flag in the operating system will be used for other forms of authoritarian control. It will have actually accomplished nothing other than limiting peoples' fundamental civil liberties.

  • That's a valid take. The issue I'm wrestling with is the inevitable attempts to point a finger at who is responsible when bad things happen. If you claim it is on the tech companies to know if a child is online, then they will take the safest path for them by forcing ID verification in independent adhoc manners. This is what we are seeing now, and to me this is the worst situation. If you shift the responsibility more to the parents (this child was using a device that didn't send the `PARENT_CONTROL` flag, therefore we assumed they were an adult) it's a completely different conversation. Furthermore, if something happens to a child AND it's obvious from traffic logs that the platform willingly knew a child was being talked to, then that is also a completely different situation than the first.

    Leaving it all completely deregulated and/or letting platforms implement it themselves to varying levels of success and personal invasion feels like the worst option to me.

I think you need to explain the solution you're thinking of in detail.

"an RFC that gives parents the ability to communicate their underage child is using the device without revealing or verifying any further information." is no different to "turn on age lock?" that you see on website now. It requires the parent to be present, engaged and 1 step ahead of their kids, and if we could depend on that, then we wouldn't even be having this discussion.

  • He was saying, vendors put that flag in the OS and parents set that flag in the OS and internet services respect that flag from the OS. No website anything, all in the OS. No staying ahead of anything, one and done. This, as noted above, requires that services respect the flag, which they do not universally do today. That requires legislation, something that will be a part of any workable solution.