Comment by egorfine

16 hours ago

> or a boolean value "yes this person is over 18"

It would be detrimental to the cause, which is to collect everyone's ID.

Whilst this is OP's point, the reality is the majority of big tech companies have been treating user data like radioactive waste for 10+ years.

Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.

Better to not hold the data in the first place.

  • This has not been the case at any of my past employers in B2C...

    There was a fair amount of scrambling to get GDPR/CCPA compliant, but even that was done largely with a prevailing "ah, this is a defensible thing to store, make sure you can annonymize it or scrub it if needed" vs "stop storing this."

    Starting with the ones that are most popular in the US, "Big Tech" usually includes:

    - Google - Gmail and Maps contain massive amount of PII, Photos contains all sorts of other sensitive stuff, and they have not treated those aspects of those products like radioactive waste

    - Meta - Facebook has a real names required policy even. Not a lot more needs to be said there, I think.

    - Amazon - Nothing I've seen about trying to move away from how they need your name/address/payment info and all. If anything, more and more geographic targeting and such.

    - Microsoft - Now you need to tie your local Windows install to their cloud services, not moving away from collecting user info. Also moving towards subscriptions which means PII and payment info.

    - Apple - cloud accounts + email + payments + subscriptions all here too. Getting into banking-type services, that's leaning into PII...

    - Netflix - more and more PII (IP tracking and geolocation combined with things like email and name) to fight account sharing...

    Which ones were running away from it, exactly?

  • > majority of big tech companies have been treating user data like radioactive waste for 10+ years.

    They're collecting more than ever.

    • PIIs and payment details are radioactive if explicitly collected as such, or just "anonymized" query parameters if not.

  • > suddenly there are millions of euros of fines headed your way

    I'm not sure about that. As I see it, there is no business case for treating PII carefully: security costs money while leaking PII costs nothing and has no repercussions.

  • you must be living under a rock, mutable user data like usage habits is being collected at increasing levels

  • But then why do they want to sniff after everyone?

    Storing all that information is cheap nowadays. Any state agency may be happy to get more information about The People.

Whose cause? I think the government already has our IDs, given that they issued them.

  • The government isn't typically facilitating the check. In order to verify your age, you will be required to hand over your ID to a third party, who's privacy and security practices are likely: "Trust me bro."

    Seeing as how these companies get hacked all the time, (https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...) , I don't think it's unreasonable to resist this.

    Furthermore, I think many folks have reservations about requiring an ID checkpoint to utilize a computer. Obviously it's not that bad yet, but I don't think it's hyperbolic to state that the landscape is certainly trending in that direction, and it's absolutely not unreasonable to point out that governments and institutions to have a material interest in setting up access controls on who can and can't use the internet (read: participate in society).

    • Right, I'm not a fan of the ID check or identity/age verification. I'm just trying to understand the conspiracy theory kind of idea that "they're trying to get all our IDs!!!1!!" sentiment.

      3 replies →

  • Governments don't necessarily have the connection between your ID and what you do online, though, and some governments are known to massively buy publicly available data from data brokers to circumvent existing laws. By "some governments" I mean the US government, by the way. That's not a conspiracy either, it's well-documented.

We don't want your static ID, we want where and what you are at this moment in order to better tune the algorithm. Your ID is frozen in time, so at any given moment, big tech knows more about you than the government does. IDs are only good for minimal verification purposes.