Post by @patrickleavy@mastodon.social

Elena Rossini 🌈
@_elena @mastodon.social

Does anyone have any insights / scoops about the upcoming #EUKidsAct, set to be introduced this Thursday to "age gate" access to social media platforms across the EU? (Thus forcing every citizen to upload their government ID to establish their age)

I'm super worried about the impact on the #OpenSocialWeb and the Fediverse in particular.

🔗 : politico.eu/article/eu-to-prop

I wish they would share a clear description of the platforms affected by this legislation.

#privacy #AgeVerification #EUBigTech

Lefteris T.
@lefteristrip23 @mastodon.social

@patrickleavy @_elena there is. Zero knowledge verification. That's the way eu will follow. Now, should they anyway? That's another question

ARGVMI~1.PIF
@argv_minus_one @mastodon.sdf.org
Public el edited
pol, av

@lefteristrip23

“Zero Knowledge Proof” is the “Clean Coal” of surveillance technologies. It doesn't actually exist outside of the lab.

EU's “zero-knowledge” system requires an unmodified phone from a big tech company!

ZKP is a politician's darling because it lets them do harmful things (face scans, ID scans, shutting down small websites) while telling the outraged public “don't worry bro, we're going to bring out the better thing any day now bro, trust me bro.”

@patrickleavy @_elena

Elena Rossini 🌈
@_elena @mastodon.social

@patrickleavy yes, that's why they're so smitten with W Social, le sigh. They're off the hook for any blame about age verification mishaps

helpsterTee :over18: :verified: :starfleet:
@helpsterTee @social.helpsterte.eu

@patrickleavy@mastodon.social @_elena@mastodon.social Yes yes, you could do that as a non profit.

In person events for looking at your ID, generating 10k unique hashes for you, hosting a website that will say per hash "Yay, it's a valid adult person" and invalidate that. Make ToS that it is illegal to give away the hashes (unenforceable, but neither is "lending" your ID to your younger similar looking sibling).

No need to attach the hashes to the ID or the event or whatever.

Still a bad idea, though, because it will certainly exclude access to some people anyways. And nobody will do something like that, because they WANT to have the ID attached to accounts and posts. That's the only reason they do this.

Patrick Leavy
@patrickleavy @mastodon.social

@helpsterTee @_elena yeah I was wondering about that. Something you do in person (post office, library) but wasn't sure how that would translate to online.

I would prefer parents to police this, not governments and big tech.

helpsterTee :over18: :verified: :starfleet:
@helpsterTee @social.helpsterte.eu

@patrickleavy@mastodon.social

I would prefer parents to police this, not governments and big tech.
Yes.....every parent has the obligation to educate and raise their children...we have mechanisms in charge that will come into play, if they don't, up to jail sentences.

But instead they roll out this specific thing and totally ignore the obligation...that's fishy.

I'd say more funding to the control mechanisms for helping kids and prevention work would actually do MORE for society than throwing money at private ID verification companies...

@_elena@mastodon.social

Elena Rossini 🌈
@_elena @mastodon.social

@helpsterTee @patrickleavy but then how would they make money via surveillance capitalism? Age verification would be a big win for Big Tech, as they would know the real identity of the person on their platform and could profit even more from their data...

Patrick Leavy
@patrickleavy @mastodon.social

@_elena @helpsterTee well yes, that is the real reason. Meta lobbied hard for age verification 🤔

lieven
@thisislieven @c.im

@patrickleavy @_elena I think there's a way to do it if you take the verification part offline. I am vehemently against it either way and it doesn't do what they claim it will do (while doing other not cool stuff) but if we must that would be something I advocate for.

It would require significant investment and effort though, and it doesn't serve other interests so chances are slim.

@patrickleavy @_elena

Valve (Steam) achieved age verification in the UK by requiring a credit card. Because to have a credit card you have to be a certain age

help.steampowered.com/en/faqs/

this doesn't completely answer your question, but it collapses the need for another privacy disclosure. the credit card company knew before, it still knows, but no one else does

but of course, now your credit card is exposed for another potential data breach

Elena Rossini 🌈
@_elena @mastodon.social

@benroyce @patrickleavy ooooh interesting! thanks Ben

@_elena @patrickleavy

obviously best case scenario: no need for age verification

but if it comes to pass, i think this is the best "how?"

because it results in the easiest, least intrusive form of disclosure

as a bonus, fediverse instances are always in need of funds, and with a cc on file, some friction is removed for donations

big problem:

the data breach potential. a nasty possibility with small hobbyist servers

perhaps there could be third party cc verification service for instances

Elena Rossini 🌈
@_elena @mastodon.social

@benroyce @patrickleavy I had never thought of things this way, so thank you Ben for assuaging some of my fears.

@studybunny reports that in Australia the strict age verification laws didn't apply to the Fediverse, but only Big Tech. Let's hope things stay this way here, too

@_elena@mastodon.social @benroyce @patrickleavy

Here in The Netherlands we have a means to share attributes anonymously. This used to be the IRMA app, but has been renamed to @yivi_privacybydesign@mastodon.nl and works like a charm. I am sure people involved in that project can give details if that can
be rolled out EU wide.
It is a shame too few people use it

Replying to @fd0
Elena Rossini 🌈
@_elena @mastodon.social

@fd0 @yivi_privacybydesign unrelated but I just let out a little scream when I read the instance name! I'm a BIG fan of Little Fedi 😊

anyway, yes, I agree with you that it would be fantastic is something like this could be implemented in place of more privacy-eroding ways

@_elena@mastodon.social @yivi_privacybydesign@mastodon.nl
This solution has been in place for many years and all one's attributes, like e-mail address, age, stay on the phone.

Replying to @fd0
francois
@francois
Unlisted en edited

@fd0 @_elena@mastodon.social @yivi_privacybydesign@mastodon.nl

This is brilliant !!!
I think not many people use it because they have not heard about it.
We need to give them more exposure.
I'll start with rigging an automatic post every month on some of my accounts. Hopefully this will help.
I haven't downloaded the app yet, but I hope it works outside the NL as well.

Edit 😰😰
download the free Yivi app, choose a PIN, enter your email, and collect your (Dutch citizen) data via DigiD.
So much for people outside of NL

Replying to @francois

@francois
The concept is cool, and it works for my tiny country, i know.
Perhaps the Privacy by Design Foundations @yivi_privacybydesign@mastodon.nl / @bjacobs@social.edu.nl could comment on the status of any international use!

@_elena@mastodon.social

Replying to @fd0
francois
@francois

@fd0 @yivi_privacybydesign@mastodon.nl @bjacobs@social.edu.nl @_elena@mastodon.social

well it seem to rely on the info stored about Dutch citizen in a place called DigID, so unless other countries have something similar, it won't work.

I know my governement (like most) has plenty of data about me, but that is not available to 3rd parties.
The only thing we have ( I guess it's a start) is a single authentication system which is valid for everything, and by everything, I mean everything - not only governement, but banks, etc.
But it only says I'm me.
It is nice, but at the same time it is a single point of failure, which is never good.

That said, there is a project of EU-wide digital ID - presumably this will be stored by each governement so such a database will probably be available.

I think the Privacy by Design Foundations @yivi_privacybydesign@mastodon.nl / @bjacobs@social.edu.nl would be well inspired to start lobbying now, knowing how slowly the wheels of EU usually move 😀

Replying to @fd0
Henrik Pauli
@phl @mastodon.social
Public en edited

@fd0 @_elena @yivi_privacybydesign Looks like the EU rather rolls their own crap that got broken the moment they released it on github (also haven't heard of any news on that wallet for months now - guess feeding people's PII into ~~third party services~~ the dark web is more important than the infrastructure), than to use something preexisting and proven. I've heard of yivi a couple of times and it would be nice to expand that I guess.

Replying to @fd0
Yivi identity wallet
@yivi_privacybydesign @mastodon.nl

@fd0 @_elena

The main challenge with wallet usage is: where to get reliable attributes from. This problem is even bigger for international usage.

One solution that Yivi supports is getting attributes into the app from your own passport, via the NFC connection on your phone. That works well. It has been tested for many countries --- but not all yet.

With the passport data, stored locally on your phone, you can reliably prove with your Yivi wallet who you are, or that you are older then 16, or 18. These age limit proofs happen without disclosing anything else about yourself. You can try this at:

casino-demo.yivi.app/

This is European sovereign open source technology that offers privacy-friendly age verification, without any monopolies, see also:

yivi.app/en/digital_autonomy/

Other attributes in Yivi that can be used internationally are: email, mobile phone number, IBAN bank number. Email works well, but phone and bank may have restrictions. Do let us know if you cannot load certain attributes.

And do distribute this message in your own network and among people that decide on the technology that all of us have to use in the future. There are decent alternatives! But we have to make the choice.

Ben Evans
@kittylyst @mastodon.social

@benroyce @patrickleavy @_elena Do you happen to know what they're planning to do in Spain, where credit cards are *really* rare? (& they're much less common in the UK than they are in the US, of course).

@kittylyst @patrickleavy @_elena

well this is all highly speculative. nobody is planning anything, because none of this has come to pass yet

and yes: this path is prejudicial against people who just don't have, or want, a credit card. or people with bad credit who can't get one

maybe they could have another verification channel

but what nobody wants are these awful "scan your passport now look in the camera and rotate your face" extremely intrusive systems

@kittylyst @patrickleavy @_elena

i *think*, even if it comes to pass, it might not be too bad if it's like how bluesky demands proof of age:

just enter your birthdate

you don't have to enter your real birthdate, you just have to enter a date. amazingly, i share the same birthday with donald duck 😆

this may be all that is legally required

at this point, everything is speculation

Ben Evans
@kittylyst @mastodon.social

@benroyce @patrickleavy @_elena One of the reasons that they're rare in Spain is that we don't have credit ratings here. There's a blacklist but to get on it essentially you have to be convicted of criminal fraud (possibly multiple times). Credit cards also auto-payoff at the end of the month / have a "split payment over 3 months" option. It's difficult to ever carry a balance / pay much interest.

I only have one b/c of travelling to places (e.g. the US) which don't deal well with debit cards

Henrik Pauli
@phl @mastodon.social

@benroyce @patrickleavy @_elena It is *theoretically* a good solution for avoiding having to deal with identification and having to store (and inevitably eventually leak) PII.

In reality, basically every country outside of the US (and Canada?) is not a credit card driven place. Most people only have debit cards in Europe, including the UK. And you can get a debit card at like 16, so that's not sufficient...

ARGVMI~1.PIF
@argv_minus_one @mastodon.sdf.org
Public en edited
pol, av

@benroyce

And you've shut out individuals and nonprofits from running chat sites. Credit card checks are expensive.

Which I'm fairly sure is the whole idea. Protect Elon Musk's business model by shutting down alternatives like Fedi.

@patrickleavy @_elena

@argv_minus_one @patrickleavy @_elena

no argument. i'm just looking for solutions. but as others have said, credit cards are rarer in europe. so that is a point of education for me as an american and paints this scheme as less workable than i first thought

ARGVMI~1.PIF
@argv_minus_one @mastodon.sdf.org
Public en edited
pol, av

@benroyce

The only real solution is to stop trying to verify people's ages online. There is no way to do that without shutting people out and violating everyone's privacy, because it fundamentally *is* an invasion of privacy (to check your identity) for the purpose of shutting you out (if you're young or anonymous).

@patrickleavy @_elena

@argv_minus_one @patrickleavy @_elena

again, zero argument. ideally we don't have to do this. but if we have to we can't be angry at server admins. it's the govt's fault. we're just chatting about compliance that is easiest and least intrusive

there's no reason to argue, it's just speculation and rumination here

and maybe it will be like bluesky and all you have to do is enter your birthdate. so people can just enter any fake birthdate

nobody is acting like this is imminent or ideal

Zelgaav
@zelgaav @mastodon.social

@benroyce @patrickleavy @_elena I had a credit card in the 90s. Now, I don't know anyone who has one. Everybody resigned long time ago. Some people use services like "Allegro Pay Later" or "Blik Pay Later", which work similar way, but are not tied to a card. I don't expect people running to banks to get a credit card just to authenticate on Steam. Also, parents are likely to allow child authenticate using their card (if they had one) to let kid play his favorite games. That's dumb method.

@zelgaav @patrickleavy @_elena

i agree on the first point. the scarcity of people with credit cards destroys the entire scheme

but i disagree on second point. it's just a bureaucratic hoop to jump through. yes, it doesn't work in terms of satisfying the requirement in terms of sincere functionality. who cares. we only care about making the government go the fuck away

ARGVMI~1.PIF
@argv_minus_one @mastodon.sdf.org
pol, av

@zelgaav

All methods are dumb methods for the same reason. Parents are going to authenticate for their kids so that their kids can get on with things. We're already seeing this in Australia, where social media use among children is now going *up*.

@benroyce @patrickleavy @_elena

@argv_minus_one @zelgaav @patrickleavy @_elena

i think my last 5 responses to you, across a number of threads, have began with "no argument"

i almost did it again 😂

i'll try to tone that down

yes, it's all a fucking joke

ideally it won't happen. but it might

so we ruminate on compliance. not because anyone loves it but it's just exercising our brains and yapping our gums

elena said someone said in australia only big companies have to do this, not small servers like mastodons

a relief

ARGVMI~1.PIF
@argv_minus_one @mastodon.sdf.org
pol, av, doom

@benroyce

From the sound of the Reuters article reuters.com/legal/litigation/e all “companies” will be required to verify age, verify parental identity, and pay the government a “supervisory fee”.

I don't see how Fedi, or any non-billion-dollar website, could possibly comply with such a regime. I'm straight-up panicking right now, to be honest.

@zelgaav @patrickleavy @_elena @gavinkarlmeier

@argv_minus_one @zelgaav @patrickleavy @_elena @gavinkarlmeier

there's no reason to panic. life is full of evil shit. you adopt and move on

maybe everything will be hosted in canada, or little servers proxy through canada. i dunno

again: don't be angry with me. i'm speculating and ruminating strategy. rumination like the credit card scheme idea i put forth that sucks. because it's just speculation

i agree with you 1,000% it should not happen

ARGVMI~1.PIF
@argv_minus_one @mastodon.sdf.org
pol, av, doom

@benroyce

Canada seems to be doing the same thing, as do the US, UK, Brazil…

I'm not angry with you, friend. Just scared. Very, very, very scared.

I feel like hundreds of thousands of websites will start disappearing soon, and historically, such extreme crackdowns on public discourse were shortly followed by millions of *people* disappearing.

I don't want to die, Ben. 😭

@zelgaav @patrickleavy @_elena @gavinkarlmeier

@argv_minus_one @zelgaav @patrickleavy @_elena @gavinkarlmeier

i just don't see it as that bleak. because the devil is in the details. maybe we'll just all move to tor. or some country that isn't so beholden to plutocracy and bigotry and host from there. we don't know what the EU will do, there might be carveouts

the desire for social interaction outside of corporate control is not going away

in fact, i think it is growing. i see a bright future for the fediverse, even with shitbag laws