← Back to context

Comment by Cthulhu_

17 hours ago

Age verification is not (should not be) the same as ID verification / storage / etc; the US needs laws similar to EU ones where companies can only get the minimum required PII. In the case of age verification that's zero, or a boolean value "yes this person is over 18" that they get from a trusted party like a bank.

> or a boolean value "yes this person is over 18"

It would be detrimental to the cause, which is to collect everyone's ID.

  • Whilst this is OP's point, the reality is the majority of big tech companies have been treating user data like radioactive waste for 10+ years.

    Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.

    Better to not hold the data in the first place.

    • This has not been the case at any of my past employers in B2C...

      There was a fair amount of scrambling to get GDPR/CCPA compliant, but even that was done largely with a prevailing "ah, this is a defensible thing to store, make sure you can annonymize it or scrub it if needed" vs "stop storing this."

      Starting with the ones that are most popular in the US, "Big Tech" usually includes:

      - Google - Gmail and Maps contain massive amount of PII, Photos contains all sorts of other sensitive stuff, and they have not treated those aspects of those products like radioactive waste

      - Meta - Facebook has a real names required policy even. Not a lot more needs to be said there, I think.

      - Amazon - Nothing I've seen about trying to move away from how they need your name/address/payment info and all. If anything, more and more geographic targeting and such.

      - Microsoft - Now you need to tie your local Windows install to their cloud services, not moving away from collecting user info. Also moving towards subscriptions which means PII and payment info.

      - Apple - cloud accounts + email + payments + subscriptions all here too. Getting into banking-type services, that's leaning into PII...

      - Netflix - more and more PII (IP tracking and geolocation combined with things like email and name) to fight account sharing...

      Which ones were running away from it, exactly?

    • > suddenly there are millions of euros of fines headed your way

      I'm not sure about that. As I see it, there is no business case for treating PII carefully: security costs money while leaking PII costs nothing and has no repercussions.

    • But then why do they want to sniff after everyone?

      Storing all that information is cheap nowadays. Any state agency may be happy to get more information about The People.

  • Whose cause? I think the government already has our IDs, given that they issued them.

    • The government isn't typically facilitating the check. In order to verify your age, you will be required to hand over your ID to a third party, who's privacy and security practices are likely: "Trust me bro."

      Seeing as how these companies get hacked all the time, (https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...) , I don't think it's unreasonable to resist this.

      Furthermore, I think many folks have reservations about requiring an ID checkpoint to utilize a computer. Obviously it's not that bad yet, but I don't think it's hyperbolic to state that the landscape is certainly trending in that direction, and it's absolutely not unreasonable to point out that governments and institutions to have a material interest in setting up access controls on who can and can't use the internet (read: participate in society).

      4 replies →

    • Governments don't necessarily have the connection between your ID and what you do online, though, and some governments are known to massively buy publicly available data from data brokers to circumvent existing laws. By "some governments" I mean the US government, by the way. That's not a conspiracy either, it's well-documented.

  • We don't want your static ID, we want where and what you are at this moment in order to better tune the algorithm. Your ID is frozen in time, so at any given moment, big tech knows more about you than the government does. IDs are only good for minimal verification purposes.

It's just like cookie banners: they shouldn't exist, but people's bonuses rely on never admitting that, so here we all are.

  • Well the EU's own government websites are all polluted with the cookie banners too so it's obvious that they can't even resist collecting visitor tracking data themselves.

    The whole thing is pointless.

    • Pointless?

      If you dont microregulate technology how can you regulate the consequences of regulating technology?

      The regulators need this.

Bank? So now you know what bank they use?

  • This is why you have a relay in the middle.

    Then, Chase knows you've verified your ID somewhere, the relay knows that some Chase user verified themselves at Pornhub, and Pornhub knows that the user is over 18, without knowing their identity or what bank they're using.

    You could also do this with ZKPs and device integrity protection. The latter is more secure but more complex, the former is much simpler and openness friendly.

    • > You could also do this with ZKPs and device integrity protection.

      How has the anti-competitive lock-in scam of "device integrity protection" entered the discussion? Using ZK proofs without it has exactly the same effect.

      There are far too many attestation-passing insecure devices to expect attestation to have any security value against attackers who can choose any of those devices on purpose.

    • Or we could use multiple relays so nobody knows both the bank and the purpose, or even who would know the other piece of data... and now thats just Tor but for identity verification. Might be a good idea actually, except the whole point is Anthropic wants to know who you are.

  • I think the key here is “a trusted third party” more than “bank”.

    Also, I’d rather a company know “he has an account at Bank of America” than “His full government name is Bit Masher and his driving license number is 9”

  • Well, they already know your credit card issuer, it's not that wild. Really Visa/MasterCard should offer age verification on their network... They have all the necessary components.

The EU is also doing age verification by showing ID, only difference is that you have to trust that their zero proof concept works and they're doing what they say they do.

In the US we just assume no one does what they say they do.

Colorado and a few other states have zero knowledge proof apps capable of this.

This is fantastic, except that the idea of mandatory government software only available on chosen proprietary platforms feels way worse.

If there were a way to crypto-notarize a third-party wallet token etc blah blah, then it would be interesting.

At the end of the day though, this is about protecting the powerful, not the kids.

> from a trusted party like a bank.

For what reason should I trust a bank?

  • Not "a" bank. You (somewhat) trust your bank, I would imagine. Since you know, they have your money.

    GP's hypothetical here is that Anthropic or other service provider who wants to do "age verification" could partner with (among others) your bank [1], where bank can answer yes/no to "is this user >= 18?", without revealing any other personal info to the SP. Allegedly.

    [1] via an intermediary, no doubt. Trying to do a "full-mesh" of partnering of every SP with every bank directly would not scale.

    • > You (somewhat) trust your bank

      For what reason?

      > Since you know, they have your money.

      You may trust them with your money, but does not equate to trusting them with anything else. Principle of least privilege, if you will. Anthropic has your chat data, which in many ways is more valuable than money, so if the only bar for free lying giving out your personal details is trusting a business with something of yours then why bother with this complex scheme and give Anthropic all of your personal information directly?

      13 replies →

  • I trust my bank a whole lot more than I trust Anthropic

    • If I had a bank, I'd trust it too, it being mine. Most people don't have the luxury, though. In practice, they have to outsource banking to other people. And those other people are already quite likely to move around between both Anthropic and various banks in search of whomever will offer them the most economic benefits. It is not like a particular logo on their current business card is going to change their character. You do you, of course, you are already unique in having a bank you can call your own. But the fact remains that most people strongly believe that a person's trustworthiness is of the person, not the activity they happen to be doing at the time.

I do not want my computer to yield information to evil outside actors in general. This is why systemd going that way is so outrageous:

https://github.com/systemd/systemd/pull/40954

  • I think many linux users will apparently have been born on Jan 1 1970

    • Strange, when I buy beer at Kroger and the "ID verification" guy has to come over, he looks at me and just keys in 01/01/1970 as my birth date most of the time. Or just asks me what my birthday is and I give him a random date in the late 1960s.

Isn’t the very first option on the article a service that estimates your age without ID? Are they lying?