Post by @_elena@mastodon.social
Does anyone have any insights / scoops about the upcoming #EUKidsAct, set to be introduced this Thursday to "age gate" access to social media platforms across the EU? (Thus forcing every citizen to upload their government ID to establish their age)
I'm super worried about the impact on the #OpenSocialWeb and the Fediverse in particular.
🔗 : https://www.politico.eu/article/eu-to-propose-new-legislation-on-minors-protection-on-thursday/
I wish they would share a clear description of the platforms affected by this legislation.
100 likes
Thomas Lavergne@lavergnetho@fediscience.org
haxx@haxx@mastodon.social
Ricardo Antonio Piana@admin@orwell.fun
Cyberlyra@cyberlyra@hachyderm.io
♥ negs oder so... ♥ | ⁂@negschaumburg1@hessen.social
四@yon@sakurajima.moe
Kuba Suder • @mackuba.eu on 🦋@mackuba@martianbase.net
bladderbot@bladderbot@mastodon.online
Tuchowski@adipoeserPursch@troet.cafe
glamcode@glamcode@openbiblio.social
Ikkle Gemz Universe+@ikklegemzuniverseplus@ohai.social
Mad Alex@madalex@fosstodon.org
Micdan@micdan5boringtoots@mstdn.social
Paul Schoe@paulschoe@mastodon.world
epiPelagic Puck@Puck@sfba.social
FediBoard@fediboard@flipboard.social
Spikiii (she/her) 🏳️🌈🏳️⚧️@Spikiii@tech.lgbt
Valanha@Valanha@tech.lgbt
PonderStibbons@PonderStibbons@mas.to
Mrinal Gupta@mrinalese27@mastodon.social
DCoder 🇱🇹❤🇺🇦@dcoderlt@ohai.social
David@DBG3D@masto.es
Renalia - #1 pizza downloader@Nine@chitter.xyz
Akash Mondal@theakashmondal@mstdn.social
Dr. Juande Santander-Vela@juandesant@mathstodon.xyz
Torsten Torsten@torstentorsten@social.tchncs.de
Victor García 👨🏻💻😸@vggonz@mastodon.denibol.com
somestuffgoodhopefully@somestuffgoodhopefully@vivaldi.net
grosser_mensch@grosser_mensch@norden.social
Oblomov@oblomov@sociale.network
@harib_murshidi@mastodon.social
Anton@anton@social.dollmaier.name
Sarah Frumento (she/her) 🇨🇦@SarahFrumento@socialbc.ca
149 boosts
adrinux@adrinux@fosstodon.org
Calicosine@DrewNaylor@mastodon.online
Oblomov@oblomov@sociale.network
MJ Muse@MJmusicinears@mastodon.world
Utarg of Utarg 🔬🇪🇺🇸🇪🇬🇧🇺🇦@toxy@mastodon.acc.sunet.se
Esther Payne
@onepict@chaos.social
@debby@hear-me.social
padeluun ⁂@padeluun@digitalcourage.social
Paul Melis@paulmelis@social.edu.nl
Thomas Lavergne@lavergnetho@fediscience.org
AT@at@mathstodon.xyz
tj (i make it to the end) 😷@blackfinalboi@blackqueer.life
Tuchowski@adipoeserPursch@troet.cafe
Marc Véron@mveron@tooting.ch
glamcode@glamcode@openbiblio.social
Adam Onza@AdamOnza@mastodon.online
Ikkle Gemz Universe+@ikklegemzuniverseplus@ohai.social
David Thomson@dwlt@mastodon.me.uk
Radek Pandka@radpanda@mastodon.com.pl
Douglas McMillan@Nerdfest@mastodon.online
@EdwinG@mstdn.moimeme.ca
Kagami is they/them 🏳️⚧️@krosylight@fosstodon.org
Andrew Henry@AndrewHenry@mastodon.energy
Normie
@normjess@tech.lgbt
Jayne
🇪🇺🏳️🌈@TCMuffin@toot.wales
PonderStibbons@PonderStibbons@mas.to
Atx
@byatx@mastorol.es
Basyl@basyl@kafeneio.social
David@DBG3D@masto.es
Dr. Juande Santander-Vela@juandesant@mathstodon.xyz
Gheesh@gheesh@lgbtqia.space
ArtistSynth - Ahora en NeoPaquita@ArtistSynth@neopaquita.es
hypebot@hypebot@gts.awesomesheep48.ca
Trending@trending@dankim.com
@harib_murshidi@mastodon.social
@_elena urgh... Is there any way to do #ageverification privately and securely? It doesn't look like it.
Didn't the EU's solution get hacked on day one?
@patrickleavy @_elena there is. Zero knowledge verification. That's the way eu will follow. Now, should they anyway? That's another question
pol, av
“Zero Knowledge Proof” is the “Clean Coal” of surveillance technologies. It doesn't actually exist outside of the lab.
EU's “zero-knowledge” system requires an unmodified phone from a big tech company!
ZKP is a politician's darling because it lets them do harmful things (face scans, ID scans, shutting down small websites) while telling the outraged public “don't worry bro, we're going to bring out the better thing any day now bro, trust me bro.”
@patrickleavy yes, that's why they're so smitten with W Social, le sigh. They're off the hook for any blame about age verification mishaps
@patrickleavy@mastodon.social @_elena@mastodon.social Yes yes, you could do that as a non profit.
In person events for looking at your ID, generating 10k unique hashes for you, hosting a website that will say per hash "Yay, it's a valid adult person" and invalidate that. Make ToS that it is illegal to give away the hashes (unenforceable, but neither is "lending" your ID to your younger similar looking sibling).
No need to attach the hashes to the ID or the event or whatever.
Still a bad idea, though, because it will certainly exclude access to some people anyways. And nobody will do something like that, because they WANT to have the ID attached to accounts and posts. That's the only reason they do this.
@helpsterTee @_elena yeah I was wondering about that. Something you do in person (post office, library) but wasn't sure how that would translate to online.
I would prefer parents to police this, not governments and big tech.
I would prefer parents to police this, not governments and big tech.Yes.....every parent has the obligation to educate and raise their children...we have mechanisms in charge that will come into play, if they don't, up to jail sentences.
But instead they roll out this specific thing and totally ignore the obligation...that's fishy.
I'd say more funding to the control mechanisms for helping kids and prevention work would actually do MORE for society than throwing money at private ID verification companies...
@_elena@mastodon.social
@helpsterTee @patrickleavy but then how would they make money via surveillance capitalism? Age verification would be a big win for Big Tech, as they would know the real identity of the person on their platform and could profit even more from their data...
@patrickleavy @_elena I think there's a way to do it if you take the verification part offline. I am vehemently against it either way and it doesn't do what they claim it will do (while doing other not cool stuff) but if we must that would be something I advocate for.
It would require significant investment and effort though, and it doesn't serve other interests so chances are slim.
Valve (Steam) achieved age verification in the UK by requiring a credit card. Because to have a credit card you have to be a certain age
https://help.steampowered.com/en/faqs/view/292B-3DA3-CFC8-97F6
this doesn't completely answer your question, but it collapses the need for another privacy disclosure. the credit card company knew before, it still knows, but no one else does
but of course, now your credit card is exposed for another potential data breach
obviously best case scenario: no need for age verification
but if it comes to pass, i think this is the best "how?"
because it results in the easiest, least intrusive form of disclosure
as a bonus, fediverse instances are always in need of funds, and with a cc on file, some friction is removed for donations
big problem:
the data breach potential. a nasty possibility with small hobbyist servers
perhaps there could be third party cc verification service for instances
@benroyce @patrickleavy I had never thought of things this way, so thank you Ben for assuaging some of my fears.
@studybunny reports that in Australia the strict age verification laws didn't apply to the Fediverse, but only Big Tech. Let's hope things stay this way here, too
@_elena@mastodon.social @benroyce @patrickleavy
Here in The Netherlands we have a means to share attributes anonymously. This used to be the IRMA app, but has been renamed to @yivi_privacybydesign@mastodon.nl and works like a charm. I am sure people involved in that project can give details if that can
be rolled out EU wide.
It is a shame too few people use it
@fd0 @yivi_privacybydesign unrelated but I just let out a little scream when I read the instance name! I'm a BIG fan of Little Fedi 😊
anyway, yes, I agree with you that it would be fantastic is something like this could be implemented in place of more privacy-eroding ways
@_elena@mastodon.social @yivi_privacybydesign@mastodon.nl
This solution has been in place for many years and all one's attributes, like e-mail address, age, stay on the phone.
@fd0 @_elena@mastodon.social @yivi_privacybydesign@mastodon.nl
This is brilliant !!!
I think not many people use it because they have not heard about it.
We need to give them more exposure.
I'll start with rigging an automatic post every month on some of my accounts. Hopefully this will help.
I haven't downloaded the app yet, but I hope it works outside the NL as well.
Edit 😰😰
download the free Yivi app, choose a PIN, enter your email, and collect your (Dutch citizen) data via DigiD.
So much for people outside of NL
@francois
The concept is cool, and it works for my tiny country, i know.
Perhaps the Privacy by Design Foundations @yivi_privacybydesign@mastodon.nl / @bjacobs@social.edu.nl could comment on the status of any international use!
@fd0 @yivi_privacybydesign@mastodon.nl @bjacobs@social.edu.nl @_elena@mastodon.social
well it seem to rely on the info stored about Dutch citizen in a place called DigID, so unless other countries have something similar, it won't work.
I know my governement (like most) has plenty of data about me, but that is not available to 3rd parties.
The only thing we have ( I guess it's a start) is a single authentication system which is valid for everything, and by everything, I mean everything - not only governement, but banks, etc.
But it only says I'm me.
It is nice, but at the same time it is a single point of failure, which is never good.
That said, there is a project of EU-wide digital ID - presumably this will be stored by each governement so such a database will probably be available.
I think the Privacy by Design Foundations @yivi_privacybydesign@mastodon.nl / @bjacobs@social.edu.nl would be well inspired to start lobbying now, knowing how slowly the wheels of EU usually move 😀
@fd0 @_elena @yivi_privacybydesign Looks like the EU rather rolls their own crap that got broken the moment they released it on github (also haven't heard of any news on that wallet for months now - guess feeding people's PII into ~~third party services~~ the dark web is more important than the infrastructure), than to use something preexisting and proven. I've heard of yivi a couple of times and it would be nice to expand that I guess.
The main challenge with wallet usage is: where to get reliable attributes from. This problem is even bigger for international usage.
One solution that Yivi supports is getting attributes into the app from your own passport, via the NFC connection on your phone. That works well. It has been tested for many countries --- but not all yet.
With the passport data, stored locally on your phone, you can reliably prove with your Yivi wallet who you are, or that you are older then 16, or 18. These age limit proofs happen without disclosing anything else about yourself. You can try this at:
This is European sovereign open source technology that offers privacy-friendly age verification, without any monopolies, see also:
https://yivi.app/en/digital_autonomy/
Other attributes in Yivi that can be used internationally are: email, mobile phone number, IBAN bank number. Email works well, but phone and bank may have restrictions. Do let us know if you cannot load certain attributes.
And do distribute this message in your own network and among people that decide on the technology that all of us have to use in the future. There are decent alternatives! But we have to make the choice.
@benroyce @patrickleavy @_elena Do you happen to know what they're planning to do in Spain, where credit cards are *really* rare? (& they're much less common in the UK than they are in the US, of course).
@kittylyst @patrickleavy @_elena
well this is all highly speculative. nobody is planning anything, because none of this has come to pass yet
and yes: this path is prejudicial against people who just don't have, or want, a credit card. or people with bad credit who can't get one
maybe they could have another verification channel
but what nobody wants are these awful "scan your passport now look in the camera and rotate your face" extremely intrusive systems
@kittylyst @patrickleavy @_elena
i *think*, even if it comes to pass, it might not be too bad if it's like how bluesky demands proof of age:
just enter your birthdate
you don't have to enter your real birthdate, you just have to enter a date. amazingly, i share the same birthday with donald duck 😆
this may be all that is legally required
at this point, everything is speculation
@benroyce @patrickleavy @_elena One of the reasons that they're rare in Spain is that we don't have credit ratings here. There's a blacklist but to get on it essentially you have to be convicted of criminal fraud (possibly multiple times). Credit cards also auto-payoff at the end of the month / have a "split payment over 3 months" option. It's difficult to ever carry a balance / pay much interest.
I only have one b/c of travelling to places (e.g. the US) which don't deal well with debit cards
@benroyce @patrickleavy @_elena It is *theoretically* a good solution for avoiding having to deal with identification and having to store (and inevitably eventually leak) PII.
In reality, basically every country outside of the US (and Canada?) is not a credit card driven place. Most people only have debit cards in Europe, including the UK. And you can get a debit card at like 16, so that's not sufficient...
pol, av
And you've shut out individuals and nonprofits from running chat sites. Credit card checks are expensive.
Which I'm fairly sure is the whole idea. Protect Elon Musk's business model by shutting down alternatives like Fedi.
@argv_minus_one @patrickleavy @_elena
no argument. i'm just looking for solutions. but as others have said, credit cards are rarer in europe. so that is a point of education for me as an american and paints this scheme as less workable than i first thought
pol, av
The only real solution is to stop trying to verify people's ages online. There is no way to do that without shutting people out and violating everyone's privacy, because it fundamentally *is* an invasion of privacy (to check your identity) for the purpose of shutting you out (if you're young or anonymous).
@argv_minus_one @patrickleavy @_elena
again, zero argument. ideally we don't have to do this. but if we have to we can't be angry at server admins. it's the govt's fault. we're just chatting about compliance that is easiest and least intrusive
there's no reason to argue, it's just speculation and rumination here
and maybe it will be like bluesky and all you have to do is enter your birthdate. so people can just enter any fake birthdate
nobody is acting like this is imminent or ideal
@benroyce @patrickleavy @_elena I had a credit card in the 90s. Now, I don't know anyone who has one. Everybody resigned long time ago. Some people use services like "Allegro Pay Later" or "Blik Pay Later", which work similar way, but are not tied to a card. I don't expect people running to banks to get a credit card just to authenticate on Steam. Also, parents are likely to allow child authenticate using their card (if they had one) to let kid play his favorite games. That's dumb method.
@zelgaav @patrickleavy @_elena
i agree on the first point. the scarcity of people with credit cards destroys the entire scheme
but i disagree on second point. it's just a bureaucratic hoop to jump through. yes, it doesn't work in terms of satisfying the requirement in terms of sincere functionality. who cares. we only care about making the government go the fuck away
pol, av
All methods are dumb methods for the same reason. Parents are going to authenticate for their kids so that their kids can get on with things. We're already seeing this in Australia, where social media use among children is now going *up*.
@argv_minus_one @zelgaav @patrickleavy @_elena
i think my last 5 responses to you, across a number of threads, have began with "no argument"
i almost did it again 😂
i'll try to tone that down
yes, it's all a fucking joke
ideally it won't happen. but it might
so we ruminate on compliance. not because anyone loves it but it's just exercising our brains and yapping our gums
elena said someone said in australia only big companies have to do this, not small servers like mastodons
a relief
pol, av, doom
From the sound of the Reuters article https://www.reuters.com/legal/litigation/eu-is-set-propose-ban-social-media-ai-chatbots-under-15s-2026-09-14/ all “companies” will be required to verify age, verify parental identity, and pay the government a “supervisory fee”.
I don't see how Fedi, or any non-billion-dollar website, could possibly comply with such a regime. I'm straight-up panicking right now, to be honest.
@argv_minus_one @zelgaav @patrickleavy @_elena @gavinkarlmeier
there's no reason to panic. life is full of evil shit. you adopt and move on
maybe everything will be hosted in canada, or little servers proxy through canada. i dunno
again: don't be angry with me. i'm speculating and ruminating strategy. rumination like the credit card scheme idea i put forth that sucks. because it's just speculation
i agree with you 1,000% it should not happen
pol, av, doom
Canada seems to be doing the same thing, as do the US, UK, Brazil…
I'm not angry with you, friend. Just scared. Very, very, very scared.
I feel like hundreds of thousands of websites will start disappearing soon, and historically, such extreme crackdowns on public discourse were shortly followed by millions of *people* disappearing.
I don't want to die, Ben. 😭
@argv_minus_one @zelgaav @patrickleavy @_elena @gavinkarlmeier
i just don't see it as that bleak. because the devil is in the details. maybe we'll just all move to tor. or some country that isn't so beholden to plutocracy and bigotry and host from there. we don't know what the EU will do, there might be carveouts
the desire for social interaction outside of corporate control is not going away
in fact, i think it is growing. i see a bright future for the fediverse, even with shitbag laws
@_elena Since you want to learn German, here's your chance 😉
@gavinkarlmeier and @dennishorn briefly mention it in the latest episode of Haken Dran.
https://hakendran.podigee.io/627-die-rache-der-umstehenden-mit-dennis-horn
They realised that implementing a ban would not be that easy under EU law, so it seems they are trying to save face by announcing a ban on children under the age of 13.
Fun fact: children under the age of 13 are already not allowed to use the platforms.
@stefanfrede thank you! I love @gavinkarlmeier's podcast and I always use YouTube subtitles/automatic translation to understand it. An additional reason for me to learn German 😅 I've missed the latest episode, so watching ASAP
@_elena As far as we know right now (and that is very little!), the EU plans to change it’s way to define “social media” (as they call it: social media plus, lol): apps that use infinite scrolling, for-you-algorithm and excessive push-notifications. so by that the Fediverse would be fine, but some games wouldn’t.
@gavinkarlmeier thank you for the explanation Gavin! I've been really anxious about this, vis-à-vis the Fediverse...
@gavinkarlmeier @_elena They already have a definition of something like Very Big Website which depends on things like number of users and are, in theory, more closely watched for compliance than the rest of the web.
@_elena Supposedly VDL will also speak about it tomorrow (have your popcorn ready? - they sure are hyping the SOTEU).
According to the Europe Morning Post it will be discussed in the Commission today and Thursday presented by both VDL and Virkkunen. It will apply to socials, gaming and AI.
Unless something leaks my guess is we just have to wait. The ambiguity may also be strategic for a long time to come though.
@thisislieven yes, definitely. #WSocial has been hyping the SOTEU livestream: "watch it on W!" ... and then yesterday I found out it's being broadcast everywhere online... YouTube too 😂 🤡
@_elena Both the Commission and Parliament have been hyping it everywhere for weeks now. Even Metsola just did a vid on past SOTEUs. It's absolutely insane.
I actually think it's a good thing to make this a collective European moment but the way it's set up is just disastrous for this. Let's start with the fact that it's 09:00 CET - which is just about the busiest moment for many people. Also, regardless of what you think of VDL she isn't exactly the most charismatic and rousing orator.
Really, W Social is hyping it too? It's the least accessible social media platform there is... I doubt W has a long life.
Reuters says "the draft seen by Reuters". So there are no details on any EU website yet detailing what social media (e.g. if the fediverse too?) will be included when they announce it on Thursday. Looks like we have to wait and see...
https://www.reuters.com/legal/litigation/eu-is-set-propose-ban-social-media-ai-chatbots-under-15s-2026-09-14/
@_elena «to be introduced this Thursday» surely in the sense of «to be presented» / «to be proposed», not (yet) in the sense of «to be put into effect». 😅
You could inquire through https://www.asktheeu.org (or file a request according to Regulation 1049/2001 by yourself), but I doubt that would be answered before Thursday.
@_elena Ah, I've learned about AsktheEU.org through https://mastodon.social/@fantafanta/117268080420289611, which I now see you re-tooted, so maybe you already knew about that option. 🙃
From today's FTM newsletter:
https://www.ftm.eu/newsletters/less-red-tape-more-pesticides-bee-careful-what-you-simplify
@_elena it is an idiocy nonetheless. Yesterday's Revolut incident tells all there is to know about the "safety if IDs onilne.
@DataKnightmare totally! I was amazed by Kevin Mitnick's book "Ghost in the Wires"... and even more amazed that social engineering techniques totally work today, too
@_elena Meta is an "expert" in crowd control. So what would their "expert" advice to the neoliberal politicians be?
@_elena Won't help but hurt kids (especially lgbtq+ kids) . Absolute privacy nightmare. Yep completely on track with how things have been going. God forbid we actually penalize the companies that deliberately make addicting apps. Instead let's punish the users. 🤡
@remywhisker @_elena It's by design and it's high time everybody swallow that pill. Politicians and tech oligarchs are all part of the same fraternal orders and secret groups. Their enemy is not each other it's us.
They like corpo web being defacto gate keepers because t&cs allow them to collect nd share data govs cannot.
They will continue to attack and chip away at foss as much as possible to frustrate self hosting if nothing else.
@_elena I thought #EU loves #OpenSource
I guess only as long it can be exploited as a source of free-as-in-beer code.
pol, av, foss
One wonders how they intend to still have open source after they shut down all of the channels that open-source developers use to communicate with each other.
My guess is they don't, and age verification is a favor not only for Facebook but also for Microsoft.
I have a bit, but my colleague Anupriya has more here: https://www.euractiv.com/news/exclusive-von-der-leyen-to-fine-tech-companies-under-kids-act-text/
@_elena Wouldn't all the problems of modern world be solved by simply reversing this rule? Everyone above 15 should not be allowed on internet. Period.
@_elena since Australia's crack-down, it didn't require me to prove my age for access to Mastodon, but SpaceHey was struck from the web. It seems they only care about the Big Guys (Meta, Google, Discord)
pol, av
That's because Australia's regulator has specifically named 10 social media platforms that must verify age, all of which are billion-dollar behemoths. Fedi is exempt and so is everything else.
@_elena These politicians should be old enough to remember Stasi, so I can only assume that is their goal.
besides collecting ID directly to government enforcing abuse of citizens via surveillance, data leak and surveillance capitalism?
Not much. Although they should allow confirmation by a trusted in between where individual privacy is valued such as the device platform. Or parental controls.
It used to be a non issue, as one had to be of legal age to have a credit card. And banks at least at one point valued privacy.

