Many might’ve seen the Australian ban of social media for <16 y.o with no idea of how to implement it. There have been mentions of “double blind age verification”, but I can’t find any information on it.

Out of curiosity, how would you implement this with privacy in mind if you really had to?

  • /home/pineapplelover@lemm.ee
    link
    fedilink
    arrow-up
    1
    ·
    4 months ago

    Well Australia will probably so something privacy invading and fascist.

    I guess if you want it to be somewhat private you could have some kind of hash or token generated from your identification information. I bet that would be fairly private

  • Draconic NEO@programming.dev
    link
    fedilink
    arrow-up
    1
    ·
    4 months ago

    It can’t. It requires invasion of privacy to verify information about the individual they don’t have the right to access.

    Digital age verification goes against privacy. Let’s not delude ourselves into thinking it can.

  • conciselyverbose@sh.itjust.works
    link
    fedilink
    arrow-up
    1
    ·
    4 months ago

    You can’t.

    Age verification is not compatible with any remotely acceptable version of the internet. It’s an obscene privacy violation in all cases by definition.

    Any implementation short of a webcam watching you while you use the site is less than trivial to bypass with someone else’s ID while opening numerous massive tracking/security holes for no reason.

  • Kissaki@programming.dev
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    4 months ago

    Who has age authority? A state agency or service. Like the state issues an ID with age.

    Preferable, we want the user to interact with a website, that website request age authentication, but not the website to talk to the government, but through the user.

    Thus, something/somewhat like

    1. State agency issues a certificate to the user
    2. User assigns a password to encrypt the user certificate
    3. User connects to random website A
    4. Random website A creates an age verification request signed to only be resolveable by state agency but sends it to the user
    5. User sends the request to a state service with their user certificate for authentication
    6. State agency confirms-signs the response
    7. User passes the responds along to the random website A

    There may be alternative, simpler, or less verbose/complicated alternatives. But I’m sure it would be possible, and I think it lays out how “double-blind”(?) could work.

    The random website A does not know the identity or age of the user - only to the degree they requested to verify - and the state agency knows only of a request, not its origin or application - to the degree the request and user pass-along includes.

  • MajorHavoc@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    If I really had to, I would require everyone to whip out whatever assets of sexual maturity they happen to have, and let the computer analyze it and decide a maturity level.

    I would also keep copies for blackmail purposes, because the world is a better place if we all mistrust this solution and anything remotely like it. It’ll be in the legal fine print, which I’m confident no one will read.

    Every answer (other than “trust the user to self identify”) is at least remotely like mine, but I’m proposing we cut out the half-measures on the way.

    To avoid personal consequences, the system I architect will probably wait on a dead-man-switch for me to die or be incarcerated.

    Then it will publish everything it has ever seen, along with AI generated commentary. I’m confident that some of it will be hilarious, and I am hopeful that it will piss everyone off enough that we stop doing this kind of thing.

  • hector@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    My friend has worked with a government to create zero-knowledge proof from IDs. Turns out there’s a lot of good software engineered to solve that problem.

    The UX is still shit tho

  • Asidonhopo@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    4 months ago

    I seem to remember Leisure Suit Larry verified age using trivia questions that only older people would answer correctly. I know this because at 8 years old I guessed enough of them on my father’s friends computer to play it.

    • Kissaki@programming.dev
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 months ago

      I talked to a friend of mine last week and they didn’t know of the old PS/2 mouse/keyboard cable/sockets. They’ve seen it before, but it wasn’t familiar to them. Nobody only having used USB devices will remember those.

      • Asidonhopo@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        4 months ago

        I was just getting used to PS/2 connectors replacing serial mice and keyboards and then friggin USB comes along…