Background: Meta/Facebook, Google and Apple all support age verification. It gives them legal cover and for their ad platforms gives better data.
But Meta/FB have been strongly lobbying to make it required at the OS level, so they aren't responsible for it, whereas Google and Apple both want it to be an application responsibility.
I think the CA version of this ended up with a carve-out for open source? I can't recall the details.
Seeing as this is Illinois we're talking about, it's probably less about protecting kids and more about extorting punitive fines from tech companies for non-compliance.
Are they expecting parents to be held responsible when their kid gets given a laptop and doesn't put in the right age? Or is it just a best effort thing that "parents who want to" can opt in to and which mostly serves as a shield for online platforms who wave the "but age API said" flag whenever something sketch happens?
It only requires the encryption of the specific age-bracket signals mandated by Section 10 of the bill. What you're looking for is here:
Section 10. Age assurance requirements.
...
(d) All digital signals transmitted in accordance with this Section shall be encrypted to ensure data integrity and security.
age verification laws have little to do with protecting anyone, and social media companies are attempting to remove themselves from liability for their dangerous product by pushing for it
social media in its current unregulated state is harmful as has been demonstrated repeatedly with (suppressed) studies, and the push for age verification instead of regulation on the actual harmful content
age verification will always be a tool to censor whatever content certain interest groups want to censor and it is a wild violation of privacy as has been repeatedly demonstrated every time an identity verification firm gets hacked, they do not take this seriously at all, and all the while the actual harmful sites continue to do harm and have the ability to blame others for not 'protecting' people from the harm their product causes
it's a complete farce and has nothing to do with protecting anyone except tech companies peddling a harmful product
Really? Will it take online predators or other threat actors more than five minutes to somehow leverage this unnecessary data for terrible purposes?
Might as well have the children strap red rotating lights to their heads so the predators can more easily identify them in a crowd where they would otherwise blend in unnoticed.
> Might as well have the children strap red rotating lights to their heads so the predators can more easily identify them in a crowd where they would otherwise blend in
You... you think pedos can't identify children from their appearances alone? People really say the most random analogy for slightest chance to win online arguments...
From reading the article, it sounds like an enforced standardisation? Like, asking for account age bracket and then having a standard API to ask for it would be easy, right? Just write it to a root owned `~/.age-bracket` for each user or something (obviously something better).
It's a feature many apps implement in all kinds of ways already, especially games and social media stuff, so this, in theory, just makes it easier and consistent?
I'm against leaking our kids ages, and all the privacy and other concerns as much as anyone, but are we just getting overly angry too quickly on this one?
It passes responsibility and accountability from the large platforms to the open-source communities and to parents who are most likely tech illiterate.
Facebook, etc. can wash their hands when they "accidentally" serve gambling ads (or whatever) to children and say "well it's not our fault the parent has the laptop misconfigured"
I disagree. The parents are the ones who should be supervising. The work should not be pushed off to OSS devs or random website operators. Facebook is bad, but I'd rather deal with one Facebook than kill 1000 normal sites with bad legislation.
> The parents are the ones who should be supervising.
Ok. When Alice & Bob come home from school what steps should every parent take to supervise A&B's phone and device usage over the past 48 hours?
Internet history, of course - for all the browsers, including those hidden away? But what if the logs are wiped or the second BraveFoxChrome installation isn't obvious?
Must every parent have an IT degree?
What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?
Never mind the fact that Facebook, etc. has BILLIONS OF DOLLARS WORTH of software engineers, designers, psychologists making absolutely damn sure that little Alice & Bob keep their nice little eyes glued and their little thumbs scrolling.
I renew my tabs online a few times a year. Site is state wide and works great. Take like five minutes and it's super manageable. Seattle city light works well and has a solid outage map when there's bad weather.
capitol.wa.gov is really informative and easy to use and looks nice.
Is three examples enough? You only asked for one. But I figured a few extra would help you.
I think you'll find they don't have to compel you to write code. They can simply prevent you from doing something else if you don't meet an obligation. Many many industries have compliance obligations that compel speech. Therapists have to report certain things if they hear them. Managers have a duty to report. My restaurant time I was required to write temperature logs.
The idea that code can't be compelled to fit a shape by the government is goofball nonsense.
This is censorship; it is like saying you can't eat a steak because a baby can't chew it. They will try to ban Linux or fine Linux developers unless it reports the user's age.
Background: Meta/Facebook, Google and Apple all support age verification. It gives them legal cover and for their ad platforms gives better data.
But Meta/FB have been strongly lobbying to make it required at the OS level, so they aren't responsible for it, whereas Google and Apple both want it to be an application responsibility.
I think the CA version of this ended up with a carve-out for open source? I can't recall the details.
> all support age verification
No, they all support harvesting your data so they can continue doing what they do best: building shadow profiles and targeting ads.
Nothing a signal of an age group tells them more than "send me more ads for XX year-olds".
Why do you think it's always a question asked in online surveys?
Seeing as this is Illinois we're talking about, it's probably less about protecting kids and more about extorting punitive fines from tech companies for non-compliance.
> violations can cost up to $50,000 each
I hear slot machine noises.
it's a strange business model that works for the EU
Are they expecting parents to be held responsible when their kid gets given a laptop and doesn't put in the right age? Or is it just a best effort thing that "parents who want to" can opt in to and which mostly serves as a shield for online platforms who wave the "but age API said" flag whenever something sketch happens?
> The law also stipulates that all transmitted digital signals have to be encrypted.
I'm hoping there's nuance, but I'm surprised the article didn't go deeper on this too. ARP? ICMP? DHCP?
I can't actually load the bill to read it ATM.
try here: https://ilga.gov/Legislation/BillStatus/FullText?GAID=18&Doc...
It only requires the encryption of the specific age-bracket signals mandated by Section 10 of the bill. What you're looking for is here:
Section 10. Age assurance requirements. ... (d) All digital signals transmitted in accordance with this Section shall be encrypted to ensure data integrity and security.
That's the correct way to do it. Age should be something reported by browser/os/hardware. Something similar to User-Agent.
I really hope this will end the whole third party age verification farce.
it's not
age verification laws have little to do with protecting anyone, and social media companies are attempting to remove themselves from liability for their dangerous product by pushing for it
social media in its current unregulated state is harmful as has been demonstrated repeatedly with (suppressed) studies, and the push for age verification instead of regulation on the actual harmful content
age verification will always be a tool to censor whatever content certain interest groups want to censor and it is a wild violation of privacy as has been repeatedly demonstrated every time an identity verification firm gets hacked, they do not take this seriously at all, and all the while the actual harmful sites continue to do harm and have the ability to blame others for not 'protecting' people from the harm their product causes
it's a complete farce and has nothing to do with protecting anyone except tech companies peddling a harmful product
Really? Will it take online predators or other threat actors more than five minutes to somehow leverage this unnecessary data for terrible purposes?
Might as well have the children strap red rotating lights to their heads so the predators can more easily identify them in a crowd where they would otherwise blend in unnoticed.
five minutes? it took me two minutes to come up with a threat:
someone will serve an innocuous page to adults, and some malicious honeypot trickery to children, all based on an http header.
"you've won five billion robux! click allow [to a webcam permission] to be able to receive them into your account!"
> Might as well have the children strap red rotating lights to their heads so the predators can more easily identify them in a crowd where they would otherwise blend in
You... you think pedos can't identify children from their appearances alone? People really say the most random analogy for slightest chance to win online arguments...
You can't identify them via an anonymous GET request. Unless of course we implement your suggestion and stick their ages in a header:
> similar to User-Agent
In summary: your suggestion is objectively terrible and I have thus won this argument. (I didn't even realize we were arguing.)
From reading the article, it sounds like an enforced standardisation? Like, asking for account age bracket and then having a standard API to ask for it would be easy, right? Just write it to a root owned `~/.age-bracket` for each user or something (obviously something better).
It's a feature many apps implement in all kinds of ways already, especially games and social media stuff, so this, in theory, just makes it easier and consistent?
I'm against leaking our kids ages, and all the privacy and other concerns as much as anyone, but are we just getting overly angry too quickly on this one?
I get that it's a slippery slope too.
It passes responsibility and accountability from the large platforms to the open-source communities and to parents who are most likely tech illiterate.
Facebook, etc. can wash their hands when they "accidentally" serve gambling ads (or whatever) to children and say "well it's not our fault the parent has the laptop misconfigured"
It's classic blaming the victim.
I disagree. The parents are the ones who should be supervising. The work should not be pushed off to OSS devs or random website operators. Facebook is bad, but I'd rather deal with one Facebook than kill 1000 normal sites with bad legislation.
> The parents are the ones who should be supervising.
Ok. When Alice & Bob come home from school what steps should every parent take to supervise A&B's phone and device usage over the past 48 hours?
Internet history, of course - for all the browsers, including those hidden away? But what if the logs are wiped or the second BraveFoxChrome installation isn't obvious?
Must every parent have an IT degree?
What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?
If the kid's old enough to be hiding their internet history from their parents, they're old enough to have some privacy.
The same steps you take to make sure they are not smoking in a back alley on the way home.
Never mind the fact that Facebook, etc. has BILLIONS OF DOLLARS WORTH of software engineers, designers, psychologists making absolutely damn sure that little Alice & Bob keep their nice little eyes glued and their little thumbs scrolling.
If their eyes and thumbs are that little perhaps you as a parent shouldn’t buy them devices, but let them play outside.
> What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?
You know who else are not experts in software design and installation? Fossil politicians and slimy bureaucrats.
Name one public sector state or local website that isn't utter garbage and a nightmare to use. Go ahead I'll wait.
They need to get their sticky donut-eating fingers out of my personal computer.
I renew my tabs online a few times a year. Site is state wide and works great. Take like five minutes and it's super manageable. Seattle city light works well and has a solid outage map when there's bad weather.
capitol.wa.gov is really informative and easy to use and looks nice.
Is three examples enough? You only asked for one. But I figured a few extra would help you.
illogical hubris - no state can regulate the internet; no state can compel developers to write code. the court cases on this will be interesting
I think you'll find they don't have to compel you to write code. They can simply prevent you from doing something else if you don't meet an obligation. Many many industries have compliance obligations that compel speech. Therapists have to report certain things if they hear them. Managers have a duty to report. My restaurant time I was required to write temperature logs.
The idea that code can't be compelled to fit a shape by the government is goofball nonsense.
This is censorship; it is like saying you can't eat a steak because a baby can't chew it. They will try to ban Linux or fine Linux developers unless it reports the user's age.
How? Linux developers don't live in Illinois or even in the USA for the most part.
They sell the OS to Illinois residents.
I have paid for Redhat just once. Since then ubuntu FTW
It's possible for Ubuntu too. Dell sells Ubuntu laptops to Illinois.
"this option is not available in the state of Illinois"
Seems easy enough to implement before 2028 and only serve laptops without OS.