Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The end result will be the same. If you face a 10k liability for serving the wrong customer, you end up needing to ID your customers.

If the government isn't going to provide that service you end up with private companies verifying identity and the data security issues that entails.

If you want to shift the responsibility of protecting children away from parents, then you end up in a situation where third parties need to be able to differentiate between a child and an adult. I haven't yet seen a proposal that doesn't entail someone - government or private enterprise - getting access to identifiable information.

Of course, you could have something like a signed certificate, so the identity verifier doesn't see who you are patronizing, and the identity seeking business only gets to see your age, but it still has privacy issues.



> . I haven't yet seen a proposal that doesn't entail someone - government or private enterprise - getting access to identifiable information

California's Digital Age Assurance Act


That isn’t age verification. It’s an api for reporting unverified age data.

It’s basically parental controls standardized.


Yes. And that's the proposal that doesn't give anyone access to identifiable information. Well, in California it's not a proposal, it's the law.


It also doesn't give any actual age verification information. Verified age is not the same thing as self reported age.

If a kid can figure out how to click "yes, I am an adult" on a website, they can definitely figure out how to do the same thing when they turn on their phone the first time.


You can get alcohol with a fake ID, too


Yes. Which entails document fraud, expense and pretty significant risk of failure. No system is perfect, but a fake id is very different than the clerk just asking everyone how old they are and calling it good.

You really cant see the difference between checking an id and asking someone their age?

The point is that asking is completely pointless when lying is free and impossible to detect. You need some way to verify truth, and that necessarily entails exposing PII somewhere in the process.

All California accomplished was to add an api for exposing self reported age. That is very different than actually knowing a customer’s age. Any liquor store can tell you.


> you end up needing to ID your customers.

You've needed to do that for at least ten years. Mobile internet either requires a contract, or an ID check before you get a sim (pay and go)

Anyone providing internets is liable for what the users are doing. The way you got out of that is responding to legal requests. (originally mostly copyright)

This is the frustrating thing, we have effective and relatively uncontroversial age gated network (mobile data) already. and it worked.

but now they've done and fucked it up with OSA.


I don’t think that would have worked. Parents buy phones for their kids since the kids can’t buy them. What would the choices be? Give them a phone or not give them a phone. I don’t think society is ready for that kind of choice anymore.


Or give them an age-locked phone that tells the websites it belongs to a minor.


But its already the case now! As in if you buy an sim now, it comes with filtered internet by default. its been like that for years

You have to phone them up/log in and request the block to be removed.


I went to the uk with a foreign SIM. Didn’t have to show my id. I logged onto public WiFi networks without showing my id.

Plenty of ways to get it done.


sigh

Yes, there are indeed loopholes. My point is this, we have this already, it works already, and if the government had actually researched rather than read the telegraph, we would have had a system that would be much less shouting at the tides to stop them coming in.

of course your foreign sim didn't need ID, but given how easy it is to find out who you are from a sim, its not really needed.

Moreover, most deliberate public wifi asks you to accept the ToS, so that they can legally cover themselves from what ever you are doing. They are still liable if they dont take "reasonable steps" to stop illegal activity occurring on their service.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: