34
submitted 1 week ago* (last edited 1 week ago) by Beep@lemmus.org to c/technology@lemmy.world

Senate Bill 26-051 reflects that pattern. The bill does not directly regulate individual websites that publish adult or otherwise restricted content. Instead, it shifts responsibility to operating system providers and app distribution infrastructure.

Under the bill, an operating system provider would be required to collect a user’s date of birth or age information when an account is established. The provider would then generate an age bracket signal and make that signal available to developers through an application programming interface when an app is downloaded or accessed through a covered application store.

App developers, in turn, would be required to request and use that age bracket signal.

Rather than mandating that every website perform its own age verification check, the bill attempts to embed age attestation within the operating system account layer and have that classification flow through app store ecosystems.

The measure represents the latest iteration in a series of Colorado efforts that have struggled to balance child safety, privacy, feasibility and constitutional limits.

you are viewing a single comment's thread
view the rest of the comments
[-] hector@lemmy.today 2 points 1 week ago

Colorodo democrats have always been lousy. Here they are following texas and montana and tennessee, locking down the internet with dishonest arguments. No one in reality thinks this is about protecting kids, and it's not the state's place to do so, it's the parents, it's a violation of the 1st amendment to make adults expose their identities to people recording everything they do online and using it against them, and selling it to the government.

We need to repeal these bills, and we need a popular open source of model legislation to counter-act ALEC, that writes these bills and state lawmakers just fill in the blanks, after the united corporations give them a plausible excuse to and pay them off

I actually disagree, because hardware-level verification is basically the most privacy-conscious method of accurately verifying a user’s age. Rather than fighting age verification entirely, I think it’s more productive to start assuming users are under 18 until proven otherwise… Age verification is inevitable, (if you don’t like it, tor is always an option), so we should at least figure out secure and private ways of doing so. Rather than resisting it outright, present them with secure and safe ways to do it. The internet is a dark place full of a lot of creeps, and services like Roblox have proven that they will enthusiastically become nesting grounds for predators unless they’re forced to add safeguards.

Sure, it’s easy to say “just monitor your kids” but no parent can be present 24/7. And in fact, oftentimes parents end up using screen time so they can do other things like chores, without needing to watch their kid. So the “just watch your kids” argument is diametrically opposed to the reality of why parents tend to rely on screens. Sometimes you just need 15 minutes to wash the dishes, without a kid demanding your constant attention. Even I, a child-free person, can understand that. And it becomes increasingly difficult to monitor them as they grow into teens and (reasonably) start expecting their own privacy.

I’ve been saying for a while now that we need to shift to hardware verification. Your device (or for shared devices like desktops, your user account) verifies your age once. And then it doesn’t need to do so again. All of the various sites and apps can simply ask your device “hey, is this user over {age}?” And the device responds with a simple true/false. You’re not needing to give your PII to every single site you visit, and the device isn’t needing to report back to the government every time an age verification check happens. It’s all done locally. The handshake could even be cryptographically secured, to prevent tech-savvy kids from MITM’ing the age check. And then protecting kids online is as simple as not age-verifying their device (and protecting your own password on shared devices). Hell, devices like cell phones could even have the age bracket set by the parent directly, since the phone would be on the parent’s phone bill. Similarly, parents could create child accounts on their shared devices, so kids can access age-appropriate content. It won’t stop kids from getting a prepaid phone, but it’ll at least prevent them from easily verifying that phone.

And it’s also the most elegant for the user experience. As far as the adult user is concerned, they never even see an “are you over 18” verification when they visit a porn site. They simply get access to the site. And kids simply get redirected back to Google’s home page (or more realistically, a page on the porn site saying “hey you failed the age check. If you’re over 18, be sure you do that with your device before trying again, because this is the only page you’ll be able to access until then. Or if you’re under 18, click here to return to where you were before” explanation) as soon as the age check fails.

Hardware age verification is basically the best of every world. You don’t rely on a third-party service to verify your PII (which will inevitably leak it, like Discord did). You don’t need to verify with every single individual site and service. The government doesn’t get a record of every site that asks for verification. And kids are automatically prevented from stumbling across adult content.

I agree that Colorado democrats are typically the “if we cozy up to the right they might stop being mean to us” candidates. I think this bill is a poor implementation, but it’s at least done under the right premise. If we could force hardware manufacturers and/or OSes to support native age verification, it would solve a lot of the current issues that we have.

this post was submitted on 21 Feb 2026
34 points (97.2% liked)

Technology

82184 readers
439 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS