ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
45% Positive
Analyzed from 8337 words in the discussion.
Trending Topics
#internet#don#more#age#kids#right#need#thing#access#every

Discussion (230 Comments)Read Original on HackerNews
The danger here is control: total and absolute control of who will be able to see what, at any given time. Once upon a time this was a hard problem, not anymore.
Kids CAN absolutely bypass a lot still. Jump on Nostr and nobody can stop anyone -- a server can be run on any device (mine is on my phone), and it'll even run on non-TCP/IP networks (FIPS is in early days and still largely runs on existing infrastructure but absolutely doesn't rely on it staying there). Give it another few months with some LoRA build out (and enough motivation for the kids) and even the ISP gateway stops being a filter point. Not that ISP level controls have ever really been the most effective anyway, given the existence of VPN's and other tunneling methods (to say nothing of public wifi networks).
We see this happening in real time as India tries to stamp out Bitchat. The codebase has appeared on more and more repositories, and the most recent version of Bitchat is capable of transmitting itself for install to other devies without relying on any server or Internet at all.
So should we push back? Of course. At some point we would need to worry that they'll say enough is enough and make the hardware itself inaccessible. We're a long way off from that, and it'd be a surefire way to get a LOT more pushback.
But in the meantime, we shouldn't despair too much. The cypherpunks that gave us private and secure access on the Internet used by everyone today despite being once illegal to export didn't go anywhere. They're still here, kicking down every wall that gets put up, or at least pointing out that there are multiple ways around (or through) it.
I don't see any proposals yet that will actually work for what they say they'll do.
Just like we once were.
That we aren't doing something like this gives the game away. How the EU is going about this means the point of all of this has nothing to do with children and everything to do with controlling political speech.
PS Yea, I know its a very vague suggestion, it can still be implemented
This is like saying you can stop world hunger by giving everyone food.
Ever gone down the auto-suggestion rabbit hole on YouTube Kids? You start getting into weird and potentially disturbing territory much more quickly than you'd expect.
Who ever heard of a kid getting ahold of a beer?
'Something impossible for kids to bypass' is not the goal. It's akin to evaluating a flu vaccine on the standard of zero breakthrough cases. Such a standard has no relevance on the efficacy of the vaccine.
Likewise for underage internet access. Proponents would be happily satisfied with 90% compliance. They really don't care that coverage isn't complete or circumvention is complete. Once you realize that, you can start constructing counterarguments that dismantle the claim that digital IDs would solve the problems they're supposed to.
https://news.ycombinator.com/item?id=49080929
There is discussion about LLMs, models, CSAM, undressing people with AI, and posting those images to places.
No handy wavy stuff, makes this problem go away due to filtering at creation. That's because, open models are a thing. So you either ban all open models, or maybe make it a crime to publish uncensored models, or you punish what individuals do on the internet.
Slander and libel and defamation are a thing, and have been a thing forever, millennia. Suddenly, on the open and free internet, for barely an eyeblink, anyone could say anything with zero liability and responsibility.
Then, 2010s came. Then, doxing of people we didn't like, or didn't agree with, became OK. So suddenly, it was OK to "out" a person, but not to just force everyone to be de-anonymoized. In other words, unpopular opinions? Yeah, that's OK to remove the cloak.
And with AI, everyone and their dog will be able to render images of anyone they want naked. CSAM. Political lies, made up videos, slander, libel, literal wors in people's mouths, on and on.
What's my point?
Well, just as 2000 brought a new world to people, 2025 is doing the same.
This is only going to get worse. And I fully agree, the dangers for "control" are going to exist. But the dangers of people posting all of this stuff, has hit the point where a lot of people are uncomfortable with it. And if you think Grok creating CSAM is bad, then you must think anyone creating CSAM is bad. Or anything. So how to you prevent the harm?
Well really, you either heavily restrict software. Open LLMs, or?
You make people posting this stuff liable.
The world is at a fork. Everything will change. Because banning software requires immense control over hosting software, but so does deanonymizing the internet. And really, this is inline with how the political and societal landscape changes.
It's only been 20 years since a lot of people were on the Internet, and only 10 years since I'd label it 'mainstream'. As in, even grandma uses it. And so, now the laws are coming, as legislation and law and change takes time for politicians, and political bodies.
We're here. Right now. This is the moment.
So I 100% guarantee that absolutely nothing will stop the path to liability for slander, libel, and more that is coming. Nothing. Whatever it takes, you can be sure it will happen.
So how will it happen?
Well, by knowing who to sue.
Like it or not, that's the truth. And no, I don't like it myself.
Nothing ever stopped a sufficiently skilled pencil artist from sketching someone in the nude without their permission.
People have been making fake nude photos since the 90's with Photoshop and related software.
Is it crass and disrespectful? Sure.
I think it's also, however, more alarming because when it first happens it's something people worry that it will be accepted out of hand as real. Once it settles in that this is just the sort of media that is trivial to make, that matter falls off, and it's just like any other sort of harassment at most.
Attempts at censorship won't go well. Even blowing the whistle on it happening has likely added fuel to the fire of it happening more -- how many only know deepfakes are a thing because a news article exposed the practice and how awful it was?
It won't go anywhere. Especially as more and more models become capable of being run on cheaper and cheaper hardware at home. Time for society to adapt its expectations for what sort of media exists, and how trustworthy any of it is.
Now... how to effectively address this problem without introducing a dystopian surveillance state? I don't have a good answer.
By all means, if you have an adversarial relationship with the state, fight every expansion of its power tooth and nail. But conversely, if you think that everything is going basically fine and the police are reasonable folks overall, then giving them more power doesn't look like a slippery slope straight to dystopia.
This only makes sense if you have no concept of "future", wherein different, less reasonable people can gain power. This should be especially obvious in Germany, where an adversarial relationship with the state can easily be had by merely criticizing it.
That "merely criticizing" the state gets you into an adversarial relationship is, I think, also overblown. For example, insulting someone is a crime in Germany. This is usually not enforced on children's playgrounds, so many remain unaware of this until adulthood. Then they might insult someone who is aware of the law (e.g. a representative of the state) in public and get surprised by a lawsuit. Similarly, spray-painting slogans on someone's house without permission will get prosecuted as vandalism. But if you stick to publishing in ways that normal people publish pro-state opinions, you can publish your criticism in the same way and nobody will bat an eye. (Certainly, a large number of people are criticizing the state in exactly this way at any given time, without being worse off for it.)
Digital ID or not, the situation won't improve until we get actual representation that works for the people.
Are you seriously saying that with a straight face while (apparently) living in Germany of all places?
May I suggest picking up a history book or two?
>r warrant was for a different address and they left.
I am sorry but this is not something that I find "reasonable" or "positive impression" unless small children are the instigators or low stakes events are involved. If armed men are barging into sacred spaces they need to be able to triple, quadruple check they are performing what the warrant says and if not then nothing else they are doing shall be trusted either. Invading a home uninvited is a life and death matter and there is no room for policeman who make such glaring mistakes even if the natural untrained or undisciplined random person naturally might.
I was initially convinced that it had to be sarcasm but since gp insists in keeping up the spiel in replies I am less sure now.
It is trivial to demonstrate that this is incorrect (despite sounding plausible). There's plenty of incredibly toxic behavior to be found all over facebook.
Among other considerations it's worth noting that most of the usual social feedback mechanisms are missing from typical online interactions.
> The cost of running LLM botnets is going down.
Agreed that this is an existential threat to anonymous discourse as it is typically implemented.
But is it comparable to the amount of toxic behavior on 4chan?
And to be frank, there is value in 4chan. Nobody would feel compelled to believe obvious bullshit some societies and cultures impose on its members. This shit needs a counterweight. That isn't 4chan of course, but any free platform.
And yes, anonymity should be the default because otherwise the alternative is that you need to identify. If not, most users would stay anonymous because it is simply the smarter decision with the exception that you seek exposure.
You can do that already, Facebook is pretty close to exactly what you're talking about. They do a lot of work to identify real people and de-prioritize spam/bots. You can configure your account to only be able to interact with real people if you want. Many people like anonymity though, it's important for speaking truth to power and discussing topics which are outside the Overton window.
There's a good reason that many of the United States' founding fathers used pseudonyms when writing. Anonymity and real freedom of speech are foundational to democracy. If you can put someone in jail for saying something that the government doesn't like, then the government will be able to steer discourse towards outcomes it deems acceptable, even if those outcomes subvert the will of the people.
There's no real need to have the government force all websites to always authenticate all humans. The only real argument for such a system is to move us toward dystopian authoritarianism.
Teens who want to see porn will be able to see porns, but they will learn somethings along the way to do so
This is caricatural of course, but it s just so dumb as law as enforcing age verification "anonymously" is just like a don quichotte battle at AI era
Kids these days have it too easy, we need stronger protections or the next generation will make pathetic hackers.
"Hey ChatGPT Hacker Core Rizz Edition, can you hack this website for me?"
Is the Pirate Party supporting Age Verification now?
Heck, the parallel movement in the US even had a major legislative victory in California, so... what are we talking about?
Not without either being able to trivially let others use your proofs OR ending open computing. There is no zero knowledge proof about the slab of meat sitting in front of the screen.
Edit: the initiatives themselves also have shockingly low numbers of signatures. A few thousand. A million are required for the EC to take notice. This system seems a bit shitty. But maybe I'm misunderstanding it.
"Stop overcontrolling and overregulating every aspect of our lives!"
Are you guys really in favor of giving governments and police corps more control and more power so that you are observed, monitored, restricted because "the internet is dead", "think of the children" and "you need to know who to sue"?
You guys are joking, right? Right?
and yeah, LLMs kill it faster.
"The Internet sucks. Get offline," is the battle cry of someone who likes Marvel movies and the book that Target has at the checkout line, or lives in one of about five cities in the USA.
To my understanding then, the issue is that the EU's implementation only has a ZK-based solution in the plans so far.
But then this initiative says "No Digital ID", not "No Auto-Deanonymizable Digital ID", so...
Yes it does, because zero-knowledge schemes take it as an assumption that all of the people who are supposed to have credentials can be trusted not to share them with people who aren't, since you're proposing a system that provides no means for that to be detected. And this context doesn't allow that assumption.
With a normal ID, the entity required to demand ID compares the picture on the ID to the person using it, which obviously doesn't work when they're not being provided with any identifying information. You thereby have no way to know that the ID belongs to the user and anyone can allow anyone else to use their ID, thereby defeating the system.
Which means that the proponents would never be satisfied with the result and the only thing building that system does is entrench something with the shape of a non-consensual identification system, which will then have any ZK features disabled when the consequences prove unsatisfactory.
That's a tall order, although there are plenty of reports of younger people switching to "dumb phones." I've switched to one myself. But how could you possibly stop it? They are terrible -- now that I don't have one anymore it's insane how many people are constantly staring at their phones, walking on the sidewalk, crossing the street, etc. It's really depressing.
But ya, at this point I don't care if parts of the internet are fine and if I had the power to burn it all down, I would.
Say I go to a bar, I show my ID to the bouncer. My identity isn't recorded (unless they scan it with a device that records the scan data). Maybe they have cameras, my image isn't immediately associated with my identity, somebody would have to do a bit of work to connect the two. Maybe I pay with a credit card, now my name is stored in the point-of-sale system.
But I can still go to a bar with no scanner, no cameras, and pay in cash, and it's not a problem. Not suspicious at all. None of the above record-keeping is required, nor should it be.
Now, if a web site says I need to be provably 18+ to view their content, that's fine. I can take it or leave it. I have a choice.
When the law tries to mandate the software that can or must be run on my device, or tries to limit how I can communicate with my friends and family, now I have a problem. I consider my rights to personal computation and personal communication to be sacred. And I also believe in my right to privacy in these matters. I never needed an ID to send a personal letter, and my right to privacy regarding such communication is protected by law.
Finally, I see gathering of access data by a central authority (which I assume would eventually happen if social media sites started requiring validated ID) to be a concentration of power, and a dangerous one.
There is no need to track access beyond what is already tracked.
When you're age-checked on the internet, a scan of your ID goes on the website, then is likely forwarded to a helpful third party business. It extracts every bit of data, analyzes your picture, then carefully saves and catalogues everything, and returns True to the website, which may have also stored their own copy of this data, depending on how the process is implemented. This data is now in their hands forever. If, at any point in the future, you access another age-gated website that uses the same third party business, now there's nothing stopping them from correlating that private browsing data. How juicy. Adtech will love that. As you keep handing out your ID left and right, every single bit you divulge is recorded somewhere, forever. And at the end of the day, this is just moving data around, so there's nothing preventing your government, or the host's government, or all governments from passing a law that asks for that data to be shared with them - just in case, you know. Now there's many copies of your exact identity floating around, just one data leak or legal request away from revealing everything you've ever done tied in a neat little package. Real life ID is limited by constraints of practicality and our physical world, digital ID is limited by nothing.
And this is the best-case scenario I'm describing here. Imagine if they ask us to show our identities publicly, not just to the corporate all-seeing-eyes. Everyone would become doxxable by default, their whole life exposed and searchable, the mere idea of having secrets would be wiped away, communities made for marginalized or at-risk people would all fall silent.
Yes, there are ideas about zero-knowledge proofs and legislation about data privacy and whatever else. But these don't benefit either corporations or governments, and the average Joe doesn't care about putting his real name on everything, so we can pretty safely assume that this won't happen.
But if we have to talk about age, if I want to buy alcohol in my country at least, I don’t need to show my id because I don’t look under 18. If I did look under 18 the shop keeper would just quickly do what amounts to a boolean check, old enough or not?
Regardless of the intensions of the people who are pushing this (which we can’t know for sure and likely varies), the fact is that there’s so much surface area for abuse here.
You’re asking everyone to submit their id in what could be a permanent way, there’s no way for me to know what you’re doing with my id, or how long you’re keeping it for. Unlike the in person example, I cannot just take the physical copy back.
Now you might be tempted to mention that at some venues they scan your physical ID and your face. Yeah, I don’t like that either. Just because there’s precedence doesn’t make it right.
Would you really enter a bar, casino or strip club when it would look like this?
We don't talk about children, we talk about everyone here.
It just seems too obvious now
Only massive data gatherers should be able to track and know everything about people
"Stop killing the internet" unfortunately means nothing at all to the layman, they will still be using it pretty much exactly as they were before, and governments will just claim "See, internet is still working".
And these authoritarian politicians will destroy the internet with these actions. Maybe they will even change society as we know it, and not for the better.
The problem is thinking such initiatives will achieve anything in a bureaucratic system devoid of honest debate and actual democracy.
These citizen's initiatives must at least be tried but simultaneously we must create a new internet forever out of politician reach.
I think it's time that "please let 1800 analytics firms monitor your every browsing habit in exchange for this content" was seen in the same light as "please let 1800 private foreign espionage and propaganda agencies spy on you".
Like, yeah, it was an accurate statement, but total shit if your goal is to get people up off the couch and into voting booth. Way too abstract and high-minded
NO. It really shouldn't. I will not comply. Porn sites can require this shit, but not the rest of the internet. Social media, dating websites, that's up to the users. If kids are on there, that's on the parents. Do your job, be the parent. I'm not going to let lazy good for nothing parents ruin the internet for everyone else.
i.e. drone swarms replacing ISPs?
There is a real way out of it -- the governments can have their cake and eat it too. I published several academic papers to prove it, and I'm open to building and deploying it. Would anyone want to work on this together:
https://magarshak.com/papers.html
I'm reasonably confident that in the relatively near future, the Internet will be so overrun with bots and other worthless "content" that people will flock to platforms that confirm IRL identity.
A different design logic, and the logic of the blogosphere that preceded it, much more tightly prioritized following a blogger or poster and interpreting everything you see in light of who was posting it. The trust is placed in the account you follow.
"Persistent" reputation won't change that. Because on the internet nothing is persistent, without a central party enforcing it to be so. And as said above, the ones in charge of it now, don't want to enforce it really. You don't own your domain, you don't own your IP, you don't own your feeds, "content" etc. The infrastructure that routes people to your correct "reputation", isn't yours, it's controlled and owned by Big Tech, governments, and some smaller companies. Your feed can be taken offline or away from you in a whim. Access to your blog isn't yours. Not even if you host it on a rasberry-pi in your cupboard.
Aside from maybe some blockchain shenanigans, that is. Bitcoin and maybe Ethereum are the only decentralized "pseudonymous" identity providers that could step into this, but both are ridiculously costly and complex. And wholly unsuited to route content. Systems designed for this, like Tor, aren't really up to the task either. Just look at how insanely hard it is for "Content" that governments oppose, to remain online (e.g. on the tor network). Possible, but so complex, so fragile, that it's not a practical system to use en masse. Yet it's the only working system that comes closest to really owning content in the broad sense.
So it makes perfect sense to turn to the systems that have done this "persistent reputation", aka "identity" for centuries now: Governments. Compared to Big Tech, they're more decentralized - there are far more governments worldwide "doing identities" than there are FAANG corporations. Hell, even within the US or within my country alone, there are more. Compared with all other systems, we can control them, push them into a direction we want them to go - democracy. Far from perfect. Bad even. But the least worst way to have some "persistent identity" we can get. Unfortunately.
People remembering your handle is persistent, and people remembering if they had good or annoying interactions with you is persistent reputation that exists in the minds and interactions between different people. These are things people naturally do. If people don’t recognize your name and see it come in a trusted spot they just don’t trust you.
How tech breaks this is deprioritizes the people in the interactions. Instead of sending messages you use a “like” button to be intelligible to the platform. You don’t see the people putting stuff on your feed, it gets fed to a timeline that cuts it off from all context and atomizes it for your consumption. It’s the UI/UX that drives this. Even compare Reddit and HN with old forums. On forums like 25% of every post is just static bits of self-expression. There’s a PFP, the username is bigger, there’s often a big signature block. All of this makes the peoples’ posts feel like a person talking to you rather than text blocks that happen to have a tiny username and timestamp on it.
But I still believe that people will care about connecting with an actual person in meatspace. I just can't picture any other result except for complete and total burnout with the fakeness of the web.
1) buy cigars and pipe tobacco (but not cigarettes!)
2) Buy "CBD" by the pound
3) Buy ammunition, a barrel and the rest of gun parts for a glock, except a frame/receiver that can be 3d printed in a few hours to complete it.
4) Order and have delivered wine
But there are people arguing to skip all that and go to straight to ID for social media. It isn't about the children. It's about keeping tabs on who says what.
[1] https://philosophercigars.com
Not sure how I feel about that, sounds kind of problematic in retrospect. Especially since there's no mechanism for triggering EU-wide referendums to help this AFAIK.
[0] population of the EU: 452 million, unique signatures required for this: 1 million
One of my (probably dumb) ideas is:
- Create a legal presence in a country that does not require being dystopian, relaxed business laws, less regulation, lower taxes, move most of the corporate side of the business there. Take the tax revenue with you. It does not have to be all at once. Make the move a slow boil so they don't see it until it's too late.
Which countries, provinces, regions, states have the least regulation, least dystopian behavior and the least taxes? There has to be a incentive for business leaders and board members to move things around. Bonus if the saved money pays for a Gulfstream G650 ER or two.
Right now the most important thing to inhibiting a dystopia is to break the lock Apple and Google have on approval of mobile code, because it gets used as a fulcrum by authoritarians. Want to ban VPNs? Make the app stores do it. Censor social media? Have them ban every social media app that doesn't censor. Want to track everyone everywhere? Make the phone provide sites and apps with a persistent cross-service tracking ID.
Whereas if ordinary people had devices that worked like PCs traditionally have, banning a VPN from the Microsoft store doesn't prevent you from installing one directly from the developer etc.
And getting this to be possible could be done by any sufficiently large market. If a sufficiently large market e.g. bans attestation and enforces antitrust, it allows an open platform to develop in that country by starting with compatibility with the apps of existing platforms, and then that platform can expand into other markets. Or you can get an iPhone there that you can install a VPN on and Apple can't prevent it, and then those iPhones can be exported into authoritarian countries.
And if you want a financial incentive for this, how about every country outside the US not wanting their local businesses paying the 30% tax to a foreign monopolist?
You are incorrect. The NIMBY movement has been extraordinarily successful despite severe opposition from moneyed interests. Bloomberg lost embarrassingly despite setting records for campaign spending. There are countless similar examples.
Written in 1960, but very prescient.
PS The dishes are hard (but not impossible) to hide.
"No age verification" is even deader-on-arrival. Parents are literally screaming at politicians to protect "the children" (as always), but pretty much everything that has been tried so far to silence those screams has failed (remember PICS, the Platform for Internet Content Selection: that was the last serious contender, and it has been dead for, like, 20 years). Again: demand a way to implement this securely and anonymously, don't take an untenable abolitionist stance or resort to hand-waving in the vague general direction of "parental responsibility": that has been tried, and it's not working anymore.
And, please, stop vilifying the EU in these matters. The UK left the EU, ostensibly so they could make "more sensible laws" in, specifically, respects like these, and they're now leading the assault on basic freedoms with even more fervor. And no, that's not just big-bad-Starmer's fault: it's a preview of what you have to argue against and propose a compromise for instead.
You could make same exact argument regarding kids health, alcohol abuse, nicotine abuse, all types of addictions, age of consent, and so on.
You can't just have all the safeguards dropped because you think you're doing a good job. Or, even worse, you have no kids and it's your virtues merely projecting.
From both someone involved in raising kids as well as someone who knows a lot of teachers: none of the involved parties want that. Schools are at best for teaching, but never for raising.
Don't let kids have an internet-connected phone, the same way they can't have a bottle of wine.
If they really need such device make sure that device is locked to a small list of app/contacts possible.
There's no need to lock down the rest of the internet because the responsible person of such kid can't tolerate their complaints. It is a parenting issue.
"It takes a village to raise a child." Except these same parents who won't take care of their kids are also the very first who go all "How dare you speak to my child like that! I'm going to have you fired!"
Loving your children means fighting censorship, not promoting it.
They're children. They have the internet access you give them. This isn't some unsolveable problem that needs government intervention, my parents were setting up filters so long ago that they're grandparents now.
Ah, OK, so you admit a problem exists. That's step one...
Every power you grant the government is another knife they'll eventually stab you in the back with. Maybe you like your current government, but what about the next one, and the one after that?
Instead, just use the tools you already have access to. I was not opposed when California mandated that applications add parental controls, that's fine. If parents want to restrict their children's internet access, there's a continium there ranging from "prudent parenting" to "child abuse", but that can be worked out on a case-by-case basis. I am, however, rabidly against the state requiring you to dox yourself every time you log into a website, because inconceivably lazy parents can't figure out how to use the parental tools that they already have.
Okay but for your position to be tenable you have to then go to step 2, which is some parents are incompetent at doing this, and step 3, which is that, nevertheless, their children, who are randomized copies of them genetically, still somehow need and benefit from the filters that their parents can't or won't apply. Then you get to step 4, which is that all of the competent people must suffer so those children can get it from a heavy handed government solution. I don't see how you jointly accept all these steps; it means you want to have a tyranny of the incompetent over the competent. You must jointly assert that they are dumb while placing them up and over the not dumb. That's full on crab-bucket, dysgenics by force ideology.
Not possible. Why do advocates of age verification bring this argument up again and again? It is not possible.
> We call on the European Commission to propose legislation ensuring that digital identity and age-assurance systems used to access online services in the Union remain voluntary, privacy-preserving and non-discriminatory. Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate and provided by law. The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure, open-source implementation, independent security audits, prohibition of cross-service tracking by relying parties, and equivalent alternatives for citizens who do not use a digital wallet.
It would be nice to have some good standard that is less invasive.
Specifically, the requirement to provide non-digital alternatives as well as control over relying parties (i.e. consumers of the 'digital ID' and/or 'age verification' APIs) makes all of this a non-starter.
I mean: non-digital alternatives to digital IDs? I guess that means that nobody should be forced to get a digital ID for access to essential government(-ish) services (like banking), and that's a valid point, but in the context of "stop killing the Internet" just obfuscates things.
And control over RPs beyond GDPR is just pushing it, again, quite on purpose.
I think the problem is that GDPR focuses on consent more than would be prudent. Regulation is usually introduced when some actions are not appropriate even when there was consent. For example, one is not allowed to sell spoiled food, no matter how clear warnings they gave to the customers.