33 comments

  • nl an hour ago

    Background: Meta/Facebook, Google and Apple all support age verification. It gives them legal cover and for their ad platforms gives better data.

    But Meta/FB have been strongly lobbying to make it required at the OS level, so they aren't responsible for it, whereas Google and Apple both want it to be an application responsibility.

    I think the CA version of this ended up with a carve-out for open source? I can't recall the details.

    • isdononthephone an hour ago

      > all support age verification

      No, they all support harvesting your data so they can continue doing what they do best: building shadow profiles and targeting ads.

      Nothing a signal of an age group tells them more than "send me more ads for XX year-olds".

      Why do you think it's always a question asked in online surveys?

  • isdononthephone 22 minutes ago

    Seeing as this is Illinois we're talking about, it's probably less about protecting kids and more about extorting punitive fines from tech companies for non-compliance.

    > violations can cost up to $50,000 each

    I hear slot machine noises.

    • imdsm 20 minutes ago

      it's a strange business model that works for the EU

  • Glyptodon 36 minutes ago

    Are they expecting parents to be held responsible when their kid gets given a laptop and doesn't put in the right age? Or is it just a best effort thing that "parents who want to" can opt in to and which mostly serves as a shield for online platforms who wave the "but age API said" flag whenever something sketch happens?

  • rendaw an hour ago

    > The law also stipulates that all transmitted digital signals have to be encrypted.

    I'm hoping there's nuance, but I'm surprised the article didn't go deeper on this too. ARP? ICMP? DHCP?

    I can't actually load the bill to read it ATM.

    • nerdsniper an hour ago

      try: https://ilga.gov/Legislation/BillStatus/FullText?GAID=18&Doc...

      It only requires the encryption of the specific age-bracket signals mandated by Section 10 of the bill. What you're looking for is here:

      Section 10. Age assurance requirements. ... (d) All digital signals transmitted in accordance with this Section shall be encrypted to ensure data integrity and security.

  • raincole an hour ago

    That's the correct way to do it. Age should be something reported by browser/os/hardware. Something similar to User-Agent.

    I really hope this will end the whole third party age verification farce.

    • csydas 17 minutes ago

      it's not

      age verification laws have little to do with protecting anyone, and social media companies are attempting to remove themselves from liability for their dangerous product by pushing for it

      social media in its current unregulated state is harmful as has been demonstrated repeatedly with (suppressed) studies, and the push for age verification instead of regulation on the actual harmful content

      age verification will always be a tool to censor whatever content certain interest groups want to censor and it is a wild violation of privacy as has been repeatedly demonstrated every time an identity verification firm gets hacked, they do not take this seriously at all, and all the while the actual harmful sites continue to do harm and have the ability to blame others for not 'protecting' people from the harm their product causes

      it's a complete farce and has nothing to do with protecting anyone except tech companies peddling a harmful product

    • isdononthephone an hour ago

      Really? Will it take online predators or other threat actors more than five minutes to somehow leverage this unnecessary data for terrible purposes?

      Might as well have the children strap red rotating lights to their heads so the predators can more easily identify them in a crowd where they would otherwise blend in unnoticed.

      • __del__ 12 minutes ago

        five minutes? it took me two minutes to come up with a threat:

        someone will serve an innocuous page to adults, and some malicious honeypot trickery to children, all based on an http header.

        "you've won five billion robux! click allow [to a webcam permission] to be able to receive them into your account!"

      • raincole 40 minutes ago

        > Might as well have the children strap red rotating lights to their heads so the predators can more easily identify them in a crowd where they would otherwise blend in

        You... you think pedos can't identify children from their appearances alone? People really say the most random analogy for slightest chance to win online arguments...

        • isdononthephone 37 minutes ago

          You can't identify them via an anonymous GET request. Unless of course we implement your suggestion and stick their ages in a header:

          > similar to User-Agent

          In summary: your suggestion is objectively terrible and I have thus won this argument. (I didn't even realize we were arguing.)

  • deckiedan 2 hours ago

    From reading the article, it sounds like an enforced standardisation? Like, asking for account age bracket and then having a standard API to ask for it would be easy, right? Just write it to a root owned `~/.age-bracket` for each user or something (obviously something better).

    It's a feature many apps implement in all kinds of ways already, especially games and social media stuff, so this, in theory, just makes it easier and consistent?

    I'm against leaking our kids ages, and all the privacy and other concerns as much as anyone, but are we just getting overly angry too quickly on this one?

    I get that it's a slippery slope too.

    • ares623 an hour ago

      It passes responsibility and accountability from the large platforms to the open-source communities and to parents who are most likely tech illiterate.

      Facebook, etc. can wash their hands when they "accidentally" serve gambling ads (or whatever) to children and say "well it's not our fault the parent has the laptop misconfigured"

      It's classic blaming the victim.

      • ronsor an hour ago

        I disagree. The parents are the ones who should be supervising. The work should not be pushed off to OSS devs or random website operators. Facebook is bad, but I'd rather deal with one Facebook than kill 1000 normal sites with bad legislation.

        • defrost an hour ago

          > The parents are the ones who should be supervising.

          Ok. When Alice & Bob come home from school what steps should every parent take to supervise A&B's phone and device usage over the past 48 hours?

          Internet history, of course - for all the browsers, including those hidden away? But what if the logs are wiped or the second BraveFoxChrome installation isn't obvious?

          Must every parent have an IT degree?

          What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?

          • HedonicEscal8r 13 minutes ago

            If the kid's old enough to be hiding their internet history from their parents, they're old enough to have some privacy.

            • defrost 8 minutes ago

              and if they're just old enough to follow instructions from an older cousin, an online predator, or to hand over their phone to a candy waving dubious third party for a "roblox coin hack" ?

          • pibaker 37 minutes ago

            The same steps you take to make sure they are not smoking in a back alley on the way home.

            • defrost 5 minutes ago

              You sniff their clothing for evidence of a porn site or chatting with a predator?

          • ares623 an hour ago

            Never mind the fact that Facebook, etc. has BILLIONS OF DOLLARS WORTH of software engineers, designers, psychologists making absolutely damn sure that little Alice & Bob keep their nice little eyes glued and their little thumbs scrolling.

            • anon48293 24 minutes ago

              If their eyes and thumbs are that little perhaps you as a parent shouldn’t buy them devices, but let them play outside.

          • isdononthephone an hour ago

            > What if the parents are very good plumbers and car mechanics, should they also be expert in software design and installation?

            You know who else are not experts in software design and installation? Fossil politicians and slimy bureaucrats.

            Name one public sector state or local website that isn't utter garbage and a nightmare to use. Go ahead I'll wait.

            They need to get their sticky donut-eating fingers out of my personal computer.

            • forestrywat 33 minutes ago

              I renew my tabs online a few times a year. Site is state wide and works great. Take like five minutes and it's super manageable. Seattle city light works well and has a solid outage map when there's bad weather.

              capitol.wa.gov is really informative and easy to use and looks nice.

              Is three examples enough? You only asked for one. But I figured a few extra would help you.

  • stevenalowe an hour ago

    illogical hubris - no state can regulate the internet; no state can compel developers to write code. the court cases on this will be interesting

    • forestrywat 30 minutes ago

      I think you'll find they don't have to compel you to write code. They can simply prevent you from doing something else if you don't meet an obligation. Many many industries have compliance obligations that compel speech. Therapists have to report certain things if they hear them. Managers have a duty to report. My restaurant time I was required to write temperature logs.

      The idea that code can't be compelled to fit a shape by the government is goofball nonsense.

  • orionblastar 3 hours ago

    This is censorship; it is like saying you can't eat a steak because a baby can't chew it. They will try to ban Linux or fine Linux developers unless it reports the user's age.

    • drnick1 2 hours ago

      How? Linux developers don't live in Illinois or even in the USA for the most part.

      • charcircuit 2 hours ago

        They sell the OS to Illinois residents.

        • NordStreamYacht 2 hours ago

          I have paid for Redhat just once. Since then ubuntu FTW

          • charcircuit an hour ago

            It's possible for Ubuntu too. Dell sells Ubuntu laptops to Illinois.

            • consp an hour ago

              "this option is not available in the state of Illinois"

              Seems easy enough to implement before 2028 and only serve laptops without OS.