76
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 15 Apr 2026
76 points (96.3% liked)
Technology
84324 readers
209 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
From my understanding this age verification app seems to be based on the age verification blueprint they have been working on for a while now, which is supposed to be part of the European "digital wallet"
https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification
From my understanding it works as follows:
This solution does seemingly address my two greatest concern with online age verficiation:
Assuming that this blueprint is followed, it seems like a decent approach at online age verification.
I get why this sounds better than websites directly collecting IDs, but I think it still understates the problem. Even if the site only sees “18+”, the system still begins with strong identity proofing somewhere upstream. So this is not really anonymous access, it is identity-based access with a privacy layer on top.
The bigger issue is centralization. You still need trusted issuers, approved apps, approved standards, and authorities deciding who can participate. That means users are being asked to trust a centralized framework not to expand, not to abuse its power, and not to fail. History gives us no reason to be relaxed about that.
I am also skeptical of the privacy promises. These systems are always presented in their ideal form, but real-world implementations involve metadata, logging, renewal, compliance rules, vendors, and future policy changes. “The website does not know who you are” is only one small part of the privacy question.
So even in the best-case version, this is still dangerous because it normalizes the idea that access to lawful online content should depend on credentials issued inside a centrally governed identity ecosystem. Today it is age verification. Tomorrow it is broader permissioned access to the internet. That is why I do not see this as a decent compromise, but as infrastructure for future control.
I do see your concerns as valid. But at least in my country, we already have all of that.
I have an app I use to id myself to all sorts of stuff. Almost all of us has that. All the changes you mention are not changes, we have already had that for years. The new thing is that you don't give your id to the website.
Just like during the pandemic, we had an app to prove our vaccination status, without revealing id. Before that we had to prove id, and then they looked up vaccination status.
Also once they get their foot in the door, they can remove the privacy next time they want to unmask someone online saying "I support Palestine action"
As far as I understand, there’s no need for “verified apps”. The third party just verifies your token with the emitter.
The skepticism is very understandable. It is important to scrutinise solutions like this to make sure that they indeed do as they say they do, and to make sure the government doesn't overreach with their authority.
That said, it should also be possible for laws to be enforced, and there are laws on the books that are supposed to prevent children from accessing things that we as a society have agreed they have no business accessing (alcohol, tabacco, porn, and increasingly commonly social media)
Currently there is no good method to actually enforce those laws on the internet, so there needs to be a solution for that.
I think this form of age verification may be a decent compromise between privacy and the need to enforce these existing laws.
Edit: Typo. I wrote "they" instead of "that"
I think the disagreement comes from treating “we have laws” as automatically meaning “we must enforce them everywhere at any cost.” The method matters. This approach flips the burden of proof by treating everyone as a minor unless they prove otherwise. That is a pretty extreme shift from how things normally work in the real world.
We also shouldn’t pretend this actually solves the problem. Kids got access to adult magazines before, and they will get access now through a parent’s phone, shared devices, or older friends. If that’s the target, this kind of system is mostly symbolic while adding friction and control for everyone else.
And more importantly, it normalizes something much bigger. Once you accept that accessing legal content requires proving attributes through some approved system, it becomes very easy to expand that logic. Today it’s age. Tomorrow it can be anything else.
So I don’t see this as a balanced compromise. It’s a disproportionate response to an enforcement gap, with long-term consequences that go way beyond the original problem.
I don't think laws should be enforced at any cost, but if we can reasonably enforce laws I think there is a duty to do so.
Then there is also a different question of whether we agree with the laws on the books, but that is a different matter imo. Personally I don't think we should limit access to pornography as strictly as the laws says we should, and I don't think the ills of social media are solved with a simple age limit.
But that is a separate discussion from the implementation of a (in my eyes) reasonable approach to age verification
Why are all 4 of those in one category, who.decided that all if a sudden?
The problem is that different societies have different lists of things that they deem children shouldn't access (or in some cases, citizens in general). For instance, conservative-leaning U.S. states are increasingly labeling any and all LGBTQ content as being unsuitable for children, furthering their indoctrination against a persecuted minority group.
Parents are in the wrong for preventing their children from accessing content depicting LGBTQ perspectives, and age verification tools in such markets are likely to be designed with the express intent of blocking access to LGBTQ content for minors by default.
Likely? They've admitted it. That's the whole point.
The big problem is the trustworthiness of that central authority to maintain the confidentiality of your information, and to not use it for other purposes.
The central authority is basically my government. They already know.
They already know how often you do all the things you have to be over a certain age to do?
Which they of course will not.
This is the intelligent non-invasive way to implement this. Basically using a similar cryptographic signing scheme as SSL certificates. We've known how to do this for decades.
We should not care about verifying age.
Hi. This system doesn't have the cryptographic properties that you think it does. The authority could keep a map between tokens and real IDs. They just say they don't.
but whose the "central authority" that you have to provide your ID to? and what happens when that central authority inevitably gets hacked?
That central authority would, from my understanding, be your government. They already have your information, so if they get hacked you are already screwed ;)
But they could easily keep track of all the tokens they issued to you, and match them with services you use.
This has never been about protecting the kids. This is about mass surveillance.
See the problem is the central authority.
I don't see a central authority (i.e. your government) issuing tokens, as much different from the government issuing you a ID card by which you can verify your age to buy alcohol in the supermarket.
As long as that central authority doesn't get to know what I use the tokens for, it seems like an acceptable solution to me.
The difference is in the potential for creep.
The proposed implementation would actually be less invasive than a national ID card (assuming the implementation information provided is complete and accurate), but also usable in less scenarios.
AFAICT there is no provision for actually verifying the person using the app is the person who's identity is verified in the app.
What's to stop one person having a verified identity and just sharing it with the people around them once it's been issued ?
As an example, with an ID card in a bar you need to match the photo, this digital system would be like turning up to a bar with an ID that had no picture or details on , but just said "over 18", you could then hand this to a friend and they could also use it.
I personally think that if a system is mandatory then an easily circumventable verification system is the best choice , but such an easily circumventable system is exactly the kind of thing governments have used as an excuse to push for further encroachment.
Take the UK for example, the online safety act they have is easily circumvented with a VPN (which many people noted before it was implemented) the government basically stuck their head in the sand and claimed vpn's weren't widespread enough to be a problem.
Skip to now and they've got representatives looking to force vpn compliance with the online safety act without having the slightest clue about why that wouldn't and can't work the way they want.
A more suspicious person might suspect the attack on vpn usage was an expected part of the overall plan.
Even a less suspicious person could still see the direct line from one to the other.
I'm not saying they will, but if i were a betting person, I’d certainly put some money on it.
Too me one of the big issues is being able to trust a government or business to not trace a person's identity back through the token. There are technical ways to prevent that as far as I'm aware, but there's such a strong incentive against such protections that it's really hard to trust unless you're technologically skilled enough to verify the process yourself.
On one hand this is an elegant solution that is already in use in Germany for years, if companies want to implement it that is. But I think only Sony's Playstore uses it. Or so I have heard. No US company wants to use it and I am sure they will lobby to get more data from users than a token if this gets rolled out EU wide. I am skeptical about this.
So they're reusable? One token can be used for multiple age checks, right?
If not, then think about what that means.
Sure, the company you're purchasing from may have no new information, but the central authority now has everything it needs to know:
This actually sounds pretty reasonable. Thanks for bringing it up.
Finally a sane approach to online age verification
or rather their foot at the door. they just need SOMETHING and once they get started they can just keep making things worse. its never about protecting kids.
There is no such thing