465
top 50 comments
sorted by: hot top controversial new old
[-] Humanius@lemmy.world 160 points 3 months ago

From my understanding this age verification app seems to be based on the age verification blueprint they have been working on for a while now, which is supposed to be part of the European "digital wallet"

https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification

From my understanding it works as follows:

  • There will be a central "authority", with which you can identify
  • This authority will provide you with tokens indicating you are 18+ (or whatever age verfication you may need)
  • These tokens are stored locally, and contain no identifying information other than a simple "is this guy 18+?"
  • You can use these tokens to verify age with a website that requires age verification

This solution does seemingly address my two greatest concern with online age verficiation:

  • You cannot trust the website, so they only get the information they need. They don't get any identifiable information
  • You cannot trust the authority, so they don't get to know for which websites and for what reason you request 18+ tokens

Assuming that this blueprint is followed, it seems like a decent approach at online age verification.

[-] Dsklnsadog@lemmy.dbzer0.com 114 points 3 months ago

I get why this sounds better than websites directly collecting IDs, but I think it still understates the problem. Even if the site only sees “18+”, the system still begins with strong identity proofing somewhere upstream. So this is not really anonymous access, it is identity-based access with a privacy layer on top.

The bigger issue is centralization. You still need trusted issuers, approved apps, approved standards, and authorities deciding who can participate. That means users are being asked to trust a centralized framework not to expand, not to abuse its power, and not to fail. History gives us no reason to be relaxed about that.

I am also skeptical of the privacy promises. These systems are always presented in their ideal form, but real-world implementations involve metadata, logging, renewal, compliance rules, vendors, and future policy changes. “The website does not know who you are” is only one small part of the privacy question.

So even in the best-case version, this is still dangerous because it normalizes the idea that access to lawful online content should depend on credentials issued inside a centrally governed identity ecosystem. Today it is age verification. Tomorrow it is broader permissioned access to the internet. That is why I do not see this as a decent compromise, but as infrastructure for future control.

[-] fluffykittycat@slrpnk.net 30 points 3 months ago

Also once they get their foot in the door, they can remove the privacy next time they want to unmask someone online saying "I support Palestine action"

load more comments (1 replies)
[-] Humanius@lemmy.world 14 points 3 months ago* (last edited 3 months ago)

The skepticism is very understandable. It is important to scrutinise solutions like this to make sure that they indeed do as they say they do, and to make sure the government doesn't overreach with their authority.

That said, it should also be possible for laws to be enforced, and there are laws on the books that are supposed to prevent children from accessing things that we as a society have agreed they have no business accessing (alcohol, tabacco, porn, and increasingly commonly social media)

Currently there is no good method to actually enforce those laws on the internet, so there needs to be a solution for that.
I think this form of age verification may be a decent compromise between privacy and the need to enforce these existing laws.

Edit: Typo. I wrote "they" instead of "that"

[-] Zedstrian@sopuli.xyz 37 points 3 months ago

there are laws on the books that are supposed to prevent children from accessing things they we as a society have agreed they have no business accessing

The problem is that different societies have different lists of things that they deem children shouldn't access (or in some cases, citizens in general). For instance, conservative-leaning U.S. states are increasingly labeling any and all LGBTQ content as being unsuitable for children, furthering their indoctrination against a persecuted minority group.

Parents are in the wrong for preventing their children from accessing content depicting LGBTQ perspectives, and age verification tools in such markets are likely to be designed with the express intent of blocking access to LGBTQ content for minors by default.

load more comments (1 replies)
[-] Dsklnsadog@lemmy.dbzer0.com 29 points 3 months ago

I think the disagreement comes from treating “we have laws” as automatically meaning “we must enforce them everywhere at any cost.” The method matters. This approach flips the burden of proof by treating everyone as a minor unless they prove otherwise. That is a pretty extreme shift from how things normally work in the real world.

We also shouldn’t pretend this actually solves the problem. Kids got access to adult magazines before, and they will get access now through a parent’s phone, shared devices, or older friends. If that’s the target, this kind of system is mostly symbolic while adding friction and control for everyone else.

And more importantly, it normalizes something much bigger. Once you accept that accessing legal content requires proving attributes through some approved system, it becomes very easy to expand that logic. Today it’s age. Tomorrow it can be anything else.

So I don’t see this as a balanced compromise. It’s a disproportionate response to an enforcement gap, with long-term consequences that go way beyond the original problem.

load more comments (2 replies)
load more comments (1 replies)
load more comments (4 replies)
[-] avidamoeba@lemmy.ca 28 points 3 months ago

This is the intelligent non-invasive way to implement this. Basically using a similar cryptographic signing scheme as SSL certificates. We've known how to do this for decades.

[-] LodeMike@lemmy.today 27 points 3 months ago

Hi. This system doesn't have the cryptographic properties that you think it does. The authority could keep a map between tokens and real IDs. They just say they don't.

[-] kent_eh@lemmy.ca 24 points 3 months ago

The big problem is the trustworthiness of that central authority to maintain the confidentiality of your information, and to not use it for other purposes.

load more comments (6 replies)
[-] brokenwing@discuss.tchncs.de 15 points 3 months ago

See the problem is the central authority.

[-] Humanius@lemmy.world 18 points 3 months ago* (last edited 3 months ago)

I don't see a central authority (i.e. your government) issuing tokens, as much different from the government issuing you a ID card by which you can verify your age to buy alcohol in the supermarket.

As long as that central authority doesn't get to know what I use the tokens for, it seems like an acceptable solution to me.

[-] Senal@programming.dev 20 points 3 months ago* (last edited 3 months ago)

The difference is in the potential for creep.

The proposed implementation would actually be less invasive than a national ID card (assuming the implementation information provided is complete and accurate), but also usable in less scenarios.

AFAICT there is no provision for actually verifying the person using the app is the person who's identity is verified in the app.

What's to stop one person having a verified identity and just sharing it with the people around them once it's been issued ?

As an example, with an ID card in a bar you need to match the photo, this digital system would be like turning up to a bar with an ID that had no picture or details on , but just said "over 18", you could then hand this to a friend and they could also use it.

I personally think that if a system is mandatory then an easily circumventable verification system is the best choice , but such an easily circumventable system is exactly the kind of thing governments have used as an excuse to push for further encroachment.

Take the UK for example, the online safety act they have is easily circumvented with a VPN (which many people noted before it was implemented) the government basically stuck their head in the sand and claimed vpn's weren't widespread enough to be a problem.

Skip to now and they've got representatives looking to force vpn compliance with the online safety act without having the slightest clue about why that wouldn't and can't work the way they want.

A more suspicious person might suspect the attack on vpn usage was an expected part of the overall plan.

Even a less suspicious person could still see the direct line from one to the other.

I'm not saying they will, but if i were a betting person, I’d certainly put some money on it.

load more comments (1 replies)
load more comments (19 replies)
[-] DoomBananas@sh.itjust.works 95 points 3 months ago* (last edited 3 months ago)

If they are so dead set on protecting children, I suggest starting with:

Gaza Strip and the West Bank (Palestine) Ukraine Sudan Myanmar Democratic Republic of the Congo (DRC) Syria Yemen Ethiopia Afghanistan Haiti Niger Mali Burkina Faso

Zuks wallet will do just fine in the mean time

[-] dansemacabreingalone@lemmy.dbzer0.com 26 points 3 months ago* (last edited 3 months ago)

Can we stop pretend they give a single fuck about kids?

Edit: poor choice of words. Thats the only thing they give kids.

load more comments (1 replies)
[-] texture@lemmy.world 74 points 3 months ago

bad title, this isnt about protecting kids online

[-] kent_eh@lemmy.ca 44 points 3 months ago

this isnt about protecting kids online

It never is, but they always try to sell unpopular things as "protecting the kids".

[-] wrinkle2409@lemmy.cafe 52 points 3 months ago

How about being a fucking parent instead of letting the government do it?

[-] ilickfrogs@lemmy.world 33 points 3 months ago

The government isn't doing shit except censorship and mass data surveillance. This has less than nothing to do with kids.

load more comments (1 replies)
[-] Crackhappy@lemmy.world 52 points 3 months ago

Wrong. This is to violate everyone's rights and target children. This is fucking abhorrent and needs to be stopped.

[-] Formfiller@lemmy.world 45 points 3 months ago

The pedophile class is tightening the noose

[-] YerLam@lemmy.world 44 points 3 months ago

Lotta internet users are going to suddenly be from outside the EU, just like the UK population suddenly all moved to the Netherlands after their own version of this.

load more comments (3 replies)
[-] eleitl@lemmy.zip 43 points 3 months ago

I don't use apps from official software installation sources. I will boycott any site or service that asks me for unnecessary information.

[-] matlag@sh.itjust.works 16 points 3 months ago

Until you can't because they will deploy this absolutely everywhere to "protect the children" from whatever real or imaginary threat.

[-] ThetaDecay@lemmy.world 16 points 3 months ago

It will be banking that is used as the wedge for this. You'll have to use an approved device / OS / App to get access to the banking system. To protect the children.

load more comments (2 replies)
load more comments (1 replies)
load more comments (1 replies)
[-] Aceticon@lemmy.dbzer0.com 32 points 3 months ago

If this is not the most crooked EU Comission ever, it's a pretty close second.

[-] fluffykittycat@slrpnk.net 30 points 3 months ago

Ewww gross. Fuck age verification

[-] PierceTheBubble@lemmy.ml 29 points 3 months ago* (last edited 3 months ago)

Welp, this was bound to happen, wasn't it? I'm pretty sure they're referring to this application, which I stumbled upon a while back. If I remember correctly, the app "allows" (or implicitly forces) the user to store a government issued identity: able to attest to an age-restricted website, whether or not the user is of age.

It does this, supposedly by "just" sharing an age-bracket with the website; but here's the kicker: the Union, in its generosity, has granted their citizens an in-app option, to withdraw this signal from the websites it has been provided to. What this means in practice, is the app storing one's government-issued identify, also ties back to every account requiring "age-verification"...

So now, every device containing the app, has the owner's government-issued identify on it, together with connections to every age-restricted service. And considering the apps are maintained by the Union, or member states (through their own implementations), creating a backdoor to the application's contents... I mean to "observe app usage", would be absolutely trivial.

Again, I've read it a while back, so some things might've changed, and my memory might be spotty; but I'm quite sure it's along the lines I've described.

load more comments (10 replies)
[-] Formfiller@lemmy.world 28 points 3 months ago

It will help the pedophile class and Israeli backed oligarchs mass surveil us more effectively

[-] MrSulu@lemmy.ml 25 points 3 months ago

Oh this sounds good........ I missed reading the following essential requirements

  • They achieved an unhackable system that also "air gaps" the information used to prove child ID from any external agent, including themselves
  • So it will be pulled immediately if it fails or exposes any childs data
  • Demonstrably withstands hacking? They have independent audit data?
  • Clear accountability clearly laid out for data breaches, including criminal charges?
  • Ministerial accountability?
[-] CaptainSpaceman@lemmy.world 17 points 3 months ago

"This ship is Unhackable!"

"Iceberg sized ransomware, dead ahead, sir!"

load more comments (2 replies)
[-] kubofhromoslav@lemmy.world 25 points 3 months ago

Sure nothing wrong can result from that. /s

[-] atrielienz@lemmy.world 24 points 3 months ago
[-] sturmblast@lemmy.world 23 points 3 months ago

This has nothing to do with protecting children

[-] undrwater@lemmy.world 22 points 3 months ago

Unless I'm reading this incorrectly, this seems far more invasive than the California law.

[-] Malyca@lemmy.zip 21 points 3 months ago

Don't give palantir your biometrics

[-] Ardyvee@europe.pub 20 points 3 months ago

People keep saying that they verify your age at the super market and I keep trying to remember the last time that happened to me and I just cannot. Nor, for that matter, at bars or coffee shops (for after lunch chat chilling before returning for the afternoon stint).

It may just be my corner of the European Union being much more lax than others.

load more comments (4 replies)
[-] Tollana1234567@lemmy.today 20 points 3 months ago

to moniter political dissidents against the right wing to be exact, and may track women as well.

[-] Amir@lemmy.ml 11 points 3 months ago* (last edited 3 months ago)

Have you not been following the EU and the right-wing influence the last few years? Spain is practically the only leftist country left.

load more comments (1 replies)
[-] FosterMolasses@leminal.space 13 points 3 months ago

Nnnnnoooooooooo

Et tu, Bruté?

load more comments
view more: next ›
this post was submitted on 15 Apr 2026
465 points (100.0% liked)

Technology

86760 readers
3168 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS