With many jurisdictions introducing age verification laws for various things on the internet, a lot of questions have come up about implementation and privacy. I haven’t seen anyone come up with a real working example of how to implement it technically/cryptographically that don’t have any major flaws.
Setting aside the ethics of age verification and whether or not it’s a good idea - is it technically possible to accurately verify someone’s age while respecting their privacy and if so how?
For an implementation to work, it should:
- Let the service know that the user is an adult by providing a verifiable proof of adulthood (eg. A proof that’s signed by a trusted authority/government)
- Not let the service know any other information about the user besides what they already learn through http or TCP/IP
- Not let a government or age verification authority know whenever a user is accessing 18+ content
- Make it difficult or impossible for a child to fake a proof of adulthood, eg. By downloading an already verified anonymous signing key shared by an adult, etc.
- Be simple enough to implement that non-technical people can do it without difficulty and without purchasing bespoke hardware
- Ideally not requiring any long term storage of personal information by a government or verification authority that could be compromised in a data breach
I think the first two points are fairly simple (lots of possible implementations with zero-knowledge proofs and anonymous signing keys, credentials with partial disclosure, authenticating with a trusted age verification system, etc. etc.)
The rest of the points are the difficult ones. Some children will circumvent any system (eg. By getting an adult to log in for them) but a working system should deter most children and require more than a quick download or a web search for instructions on how to circumvent.
The last point might already be a lost cause depending on your government, so unfortunately it’s probably not as important.
You know how there are stores that sell restricted substances and verify your age by checking a provided ID? Have those same stores sell a cheap, sealed card with a confirmation code on it. You can enter that code online to verify any service. The code expires after a set period of time after it’s first use to prevent sharing and misuse.
This system would be as secure as the restrictions on the restricted substance, such as alcohol, so it should be fine for “protecting the children”
Interesting idea. Could also give it out free with packs of beer like a golden ticket from Charlie And The Chocolate Factory.
And all across the whole world, 18 year old men will jump for joy when picking up birthday booze - “I can finally look at boobs on the internet!”
Were you ever a teenager? This would be abused immediately, unless the codes were single use, and in that case it’s a non-starter.
Yes, and one with unrestricted internet access. Can you elaborate on how someone underage would abuse this system? They can’t buy one at the store, can’t reuse one that has expired so finding one won’t help, and if theft is a concern they would just need to be secured like any other restricted good. I would say it’s at least as secure alcohol, tobacco, or firearms.
Alcohol / tobacco / firearms can’t be digitally shared or reproduced. Imagine a high school with a mix of 14 - 18 year olds. If an 18 year old can get a valid code without hassle, they can share it with their friends who are in the same class, but are still 17. Or maybe they’ll share it with a sibling who is 16. What’s to stop it spreading from there? It will probably take just an hour for half of the school to get access to the one code. If the system assumes that kids won’t directly or indirectly share their codes with one another, then the system doesn’t understand teenage behavior and is flawed.
I’m not sure if this is part of the “setting aside” stuff, but I’d ask why age needs to be verified and not simply stated.
I’m the admin on this device, I say I’m 50, why does the website need to check some ID to prove I’m 50? They trust what I reported, and if I lied to them that’s on me. It shouldn’t be the websites’ job to validate.
Exactly, it should be a parent’s job to limit a child’s access not a website.
I agree, but also parents need better tools to be able to effectively limit their child’s access. App and device level parental controls are not sufficient as they currently work.
Also, more and more local router parental controls come with a monthly fee. Legislation should be attacking those subscriptions for software that runs on hardware you own, not privacy.
Wrote a comment recently. Age verification? Unnecessary. OS-level parental controls? Possibly meriting.
https://programming.dev/comment/22589550
I am still against where all this age verification crap is coming from, and I’m against what specifically “age verification” entails; but here’s the thing: We keep saying, “It should be the parent’s responsibility to secure their kids”—and while that’s true, you can do all the talking and educating you want, but the fact is that the internet is now nigh-fully integrated with our lives, and unless you are surveilling your kid at every moment they are on the internet (don’t recommend), not every parent has the time, resources, or know-how to keep their children safe on the internet without help.
There are some states pushing for “OS-level age verification,” and I’m not convinced the proponents for this idea know what this combination of words means—but the idea isn’t all bad. An interface for apps to query the device for a simple “can access adult content” value would be helpful for parents to better manage what their kids can access without having to hover 24/7. There is zero need for any sort of identification at any point in the process. The fact that legislation is promoting cumbersome identification collection and not the already existing idea of parental controls is evidence enough that this is designed to surveil.
This may address the privacy concern, but the issue still remains of a centralized power deciding what is and what isn’t “safe for kids.”
I don’t think we’re gonna get around the child internet safety conversation, and for good reason; but the conversation should be around how we can do it without jeopardizing individuals’ safety and privacy, including children.
That’s what the router setting to block adult websites is for… you don’t have to monitor 24/7, have some idea that bad sites are blocked, and you can just be doing regular checkups on your child then.
There is and was never a need to involve IDs, other than more control over us as a whole and being able to extract more data.
I think maybe the barrier could be a little higher than just disconnecting from your home’s network.
If we were to accept the premise that there is currently an issue with child internet safety, then clearly this still an issue despite the existence of router controls. But now the question of if this premise is valid. What do you look at to determine whether “internet safety for children” is adequate? I don’t really know, and so I guess I have more reading to do.
I was gonna say something about PSAs, but no time.
I think if you as a parent have router controls and block adult content on their mobile plan if they have one (which I have seen as an option), then you are already doing a lot.
Most routers from ISPs come with “adult” content filtering enabled by default I think, at least the ones I’ve had have had this on.
VPNs already work and I can’t see them not working, so that’s always an option I guess, but they are also still an option with ID laws (ie connect to a region where they have no such laws).
Children’s safety online can’t involve limiting access and tracking everyone who ever goes online with their national ID attatched to every request (basically).
I think it’d be better if we explored the option that involves a parent blocking websites either on your network or on a device they give to you.
Most routers from ISPs come with “adult” content filtering enabled by default I think, at least the ones I’ve had have had this on.
Not that I’m doubting you, but is this a common thing? I’ve never even seen it as an option here in Canada, both on ISP supplied devices and on separate routers. Is it just because I’m using cheaper devices, or because on my region?
Hm I know it’s common for me. If it isn’t in canada or elsewhere, then that’s just lazyness and a lack of care by your isp/router manufacturer (which makes sense cuz theres a monopoly on internet over there right? (Rip)).
Anywho, adult filter blocks on routers are a really easy thing to implement. If it isn’t then they simply don’t care to help explore the simplest of options for parents restricting access to bad sites.
I’ve heard of apps you can get for child devices that do a similar thing and let parents track their kids, which might be better anyways, assuming they arent a privacy nightmare (if parents dont prefer buying a smarter router).
I have never seen a company do this in a manner that I would trust
Parental Controls. Most devices have this setting. Parents need to be taught how to turn it on, and penalized when they don’t turn it on. This way there would be no centralized database that could be hacked thereby violating user privacy. Adults wouldn’t have to give up their government issued ID to websites.
for a moment, let’s ignore all of the conspiratorial conjecture (not that it isn’t warranted).
by exposing an API for web services to identify the users age/birthday, how does that solve the issue of “protecting children online”.
what’s stopping a bad actor from identifying, tracking, and grooming children directly based on this same mechanism?
right now the majority of kids online are protected through anonymity, but once they are identified they can be targeted directly and the adults responsible for their well being are blissfully unaware because “the government is tracking their age”.
also. what comes next is worse than the date. online content ratings. because there’s no point in tracking age if you can’t apply a ratings system.
Imagine entire swaths of the internet banned because the content rating doesn’t meet the government requirements.
this is less about tracking users and more about censoring dissent.
I agree, although in this thread I’m mostly interested in the technical puzzle.
Why prove it at all?? An assertion from the OS should be good enough. Just have the OS ask once, and send that info when it has to as a general age range. A few different age ranges for kids/teens, an 18-21 group, and 21+ is all the info they really need at most.
If age verification has to be a thing, let the user supply it at install/profile creation time, and just leave it at that.
This is the way. I think this is what Apple is finally implementing, but since they took too long to do so, governments have been passing laws which require privacy invasive measures that fill the void. Hard to say if that will reverse itself now that there’s a whole age-verification industry that popped up. Actually it’s unclear to me if the age-verification industry manufactured a problem to push their solution?
Had Apple implemented this in their Parental Controls setting, it would have avoided the government intervention and shady age-verification companies from popping up.
When software poses a requirement, software should be ditched in favor of protocols. This is why any software that relies on a closed spec protocol should be avoided.
You’ll never see an age verification requirement on IRC or XMPP. And any software using these protocols that try to implement age verification will simply be left at the curbside, replaced by an alternative.
There are a few options for age verification, but the one I like best is at the ISP/device level. You make the account at the ISP level have a flag for being a kid friendly service. You could also have the government establish simple tools for parents to install on their kids devices which would limit other apps and services, for example by blocking porn or violent age inappropriate content. You could even have it tie in with the age advice for film classification, though the current classification guidelines are pretty horrible. All of that could be handled by a very small government team and could be deliverable in 6 months.
These are active steps a parent can take to limit their child’s exposure to the internet and do not come with added cost to the parent. They would be just as available for someone who is poor as for someone who is rich. It would be possible to protect kids from many of the more dangerous aspects of the internet while also leaving unmanaged devices free and clear, preserving the good things about the open internet.




