the author claims the website doesn't need to know the date of birth, but as said it is easy to derive it.
Yeah, I didn't understand the reasoning here. Is it because you assume that every newly created account must be of someone who has just turned 18? Or because multiple accounts on different age-restricted websites tied to the same email would all be created in a short time as soon as one becomes 18? This could indeed give an approximate hint as to the age if one could cross-reference the same email across several accounts, but it doesn't seem to be high risk.
For the rest, I understand the objections, but they are either ideological or slippery-slope ones. I.e., they're not about the thing per se for how it's presented and implemented now. As the author notes, nobody objects to age verification in real life, so the problem is not with verifying people age per se. It's about how this can be either leaky now or modified in the future for abuse.
It's not a high risk, but it's a thing the author said that's wrong, which puts into question the rest.
I think ideological objections to a law that will be imposed on ~300 millions of people through a process without much democracy, oversight or traceability of the decisions is pretty important, more than the technical details.
Some actually object to age verification in real life, for example some people find ways to consume alcohol or buy it before they're the legal age. Some people drive before the legal age especially in the countryside. So it is wrong to say that nobody objects to age verification in real life.
The way the thing per se is presented is skipping the ideological debate to focus on the implementation, which I think is pretty bad from a democracy/freedom point of view, and then proceeds to be wrong about something quite basic like "you don't need to give your birthday", which makes me worried about the rest, and then lists a laundry list of possible issues. So it seems clear that it can be leaky right now. The date of day easily leaks, we can argue about how important it is, but the author explicitly says:
To prove to a porn site, a gambling site, an online liquor store, or a religious forum that I'm an adult, I should not have to hand over my name, date of birth, ID number, face, address, or passport. That is a dangerous amount of information to give any private website, let alone one dealing with sensitive content.
Note the "or" and "dangerous amount of information".
There is also no built-in way to ensure the person using the ID is the person they actually are, and no privacy-respecting way to confirm that is presented.
It's not a high risk, but it's a thing the author said that's wrong, which puts into question the rest.
You still didn't explain how it would happen. It would require a person making accounts with the same (anonymous) email on multiple age-restricted websites the day of their 18th birthday... and you'd need to have access to all these separate services... then you could guess this person recently turned 18, and still you wouldn't know who this person is.
for example some people find ways to consume alcohol or buy it before they're the legal age... So it is wrong to say that nobody objects
No shit. The point is that we recognise these age checks as legitimate and reasonable in the real world.
> To prove to a porn site ... I should not have to hand over my name, date of birth...
Note that with the proposed mechanism you're not handing over your date of birth. You'd at least need to create multiple accounts with the same identity on multiple age-restricted websites and temporally close enough, and these websites should be sharing and crossing the data. For the first years this would be absolutely useless in any case because of the amount of people of all ages registering. In the worst scenario, you'd be assuming that any anonymous that registered within a few days on two different age-restricted service has just turned 18- which might apply to anyone choosing a new fake email or changing browser.
Comments
Yeah, I didn't understand the reasoning here. Is it because you assume that every newly created account must be of someone who has just turned 18? Or because multiple accounts on different age-restricted websites tied to the same email would all be created in a short time as soon as one becomes 18? This could indeed give an approximate hint as to the age if one could cross-reference the same email across several accounts, but it doesn't seem to be high risk.
For the rest, I understand the objections, but they are either ideological or slippery-slope ones. I.e., they're not about the thing per se for how it's presented and implemented now. As the author notes, nobody objects to age verification in real life, so the problem is not with verifying people age per se. It's about how this can be either leaky now or modified in the future for abuse.
It's not a high risk, but it's a thing the author said that's wrong, which puts into question the rest.
I think ideological objections to a law that will be imposed on ~300 millions of people through a process without much democracy, oversight or traceability of the decisions is pretty important, more than the technical details.
Some actually object to age verification in real life, for example some people find ways to consume alcohol or buy it before they're the legal age. Some people drive before the legal age especially in the countryside. So it is wrong to say that nobody objects to age verification in real life.
The way the thing per se is presented is skipping the ideological debate to focus on the implementation, which I think is pretty bad from a democracy/freedom point of view, and then proceeds to be wrong about something quite basic like "you don't need to give your birthday", which makes me worried about the rest, and then lists a laundry list of possible issues. So it seems clear that it can be leaky right now. The date of day easily leaks, we can argue about how important it is, but the author explicitly says:
Note the "or" and "dangerous amount of information".
There is also no built-in way to ensure the person using the ID is the person they actually are, and no privacy-respecting way to confirm that is presented.
You still didn't explain how it would happen. It would require a person making accounts with the same (anonymous) email on multiple age-restricted websites the day of their 18th birthday... and you'd need to have access to all these separate services... then you could guess this person recently turned 18, and still you wouldn't know who this person is.
No shit. The point is that we recognise these age checks as legitimate and reasonable in the real world.
Note that with the proposed mechanism you're not handing over your date of birth. You'd at least need to create multiple accounts with the same identity on multiple age-restricted websites and temporally close enough, and these websites should be sharing and crossing the data. For the first years this would be absolutely useless in any case because of the amount of people of all ages registering. In the worst scenario, you'd be assuming that any anonymous that registered within a few days on two different age-restricted service has just turned 18- which might apply to anyone choosing a new fake email or changing browser.