Comment by Scaled
2 hours ago
A child mode flag is fine. But a birthdate is a recipe for data collection and fingerprinting. And with Google, we're seeing a full verification requirement flag that means people have to scan identity documents or face pictures. It's a slippery slope.
The OS (I'll use systemd as an example) knows the birth date to determine whether or not you fall within an age range, but the applications are not offered the exact birth date by the API.
Fingerprinting, perhaps it is a higher risk, the age range is being more directly provided. However, once a user is under 18 they're already triggering more stringent privacy laws and rules, an inability to enter into contracts, etc, and then when you get to the "over 18" age range it all becomes rather vague.
Also, I highly doubt existing social media and Internet applications haven't already figured out most of their users' ages rather trivially using other means. Discord implicitly admits to this by saying that 90% of their users will not even be asked to verify their age. Discord already knows how old 90% of their users are with high confidence.
Of course when we talk about someone like Google or Discord we are talking about a privately operated service provider and business, which is a separate issue than the OS-level privacy flag and is worth separating as a distinctly different concept. Private businesses were always able to scan your identity documents or face pictures if they wanted to do that as a prerequisite to using their products or services regardless of the law. In almost all states, this practice was never banned, and even in states with more stringent biometrics collection requirements like Illinois you can still do this as long as it's implemented in a legally compliant way.