It’s not as good as the solution for alcohol as one bottle of beer making it to a child gets used up after only giving one child one drink. Once a token leaks, it can be shared again and again and used by arbitrarily many children arbitrarily many times until someone notices that it’s leaked and revokes it (which then means that websites need to actively update a list of revoked tokens instead of just relying on public key cryptography to confirm it was signed by one of a few authorities, or all tokens will need to expire automatically after a short time).
That will always be the case for online age verification. There’s nothing preventing an adult from signing up for an account and then just giving the account to a kid. This is true no matter the verification method chosen. Unless you’re going to demand people scan their face every time they log in, and even then there are ways around it.
My goal is not to create a perfect solution. My goal is to create a good-enough solution that is as reliable as face or ID scanning, but without the privacy violations.
And face/id scanning aren’t as good as the solution that works in the real world for alcohol because they can be tricked by a video game face or a photo of someone else’s real ID. Any solution that works online can either be trivially bypassed or adds an unacceptable level of hassle and risk (e.g. leaks being used for blackmail) for legitimate users.
The solution for alcohol works really well because very few children have the ability to get a fake ID or convince people it’s real and theirs until they’re close enough to legal age that it doesn’t really matter much if they drink, and parents have the ability to override it on a per-drink basis if they’re okay with children drinking under their supervision, while non-parents can only operate on a very small scale before they risk getting caught. Once people are old enough that they’re obviously adults, they don’t get asked for ID anymore, so it’s only a small fraction of the population that have to deal with any hassle, and a shopkeeper can’t memorise every single ID card they’ve ever seen and then suffer a cyberattack and reveal what alcohol specific people have bought to someone who’ll threaten all of them in case some of them are willing to pay to have it kept secret.
Preserving privacy means tokens become trivial to share, and then there’s nothing stopping a ten year old watching huge amounts of extreme porn except for things that would have worked without having any system, like having their parent stand behind them. If the new system doesn’t improve things compared to having no system, then there’s no point making it.
It’s not as good as the solution for alcohol as one bottle of beer making it to a child gets used up after only giving one child one drink. Once a token leaks, it can be shared again and again and used by arbitrarily many children arbitrarily many times until someone notices that it’s leaked and revokes it (which then means that websites need to actively update a list of revoked tokens instead of just relying on public key cryptography to confirm it was signed by one of a few authorities, or all tokens will need to expire automatically after a short time).
That will always be the case for online age verification. There’s nothing preventing an adult from signing up for an account and then just giving the account to a kid. This is true no matter the verification method chosen. Unless you’re going to demand people scan their face every time they log in, and even then there are ways around it.
My goal is not to create a perfect solution. My goal is to create a good-enough solution that is as reliable as face or ID scanning, but without the privacy violations.
And face/id scanning aren’t as good as the solution that works in the real world for alcohol because they can be tricked by a video game face or a photo of someone else’s real ID. Any solution that works online can either be trivially bypassed or adds an unacceptable level of hassle and risk (e.g. leaks being used for blackmail) for legitimate users.
The solution for alcohol works really well because very few children have the ability to get a fake ID or convince people it’s real and theirs until they’re close enough to legal age that it doesn’t really matter much if they drink, and parents have the ability to override it on a per-drink basis if they’re okay with children drinking under their supervision, while non-parents can only operate on a very small scale before they risk getting caught. Once people are old enough that they’re obviously adults, they don’t get asked for ID anymore, so it’s only a small fraction of the population that have to deal with any hassle, and a shopkeeper can’t memorise every single ID card they’ve ever seen and then suffer a cyberattack and reveal what alcohol specific people have bought to someone who’ll threaten all of them in case some of them are willing to pay to have it kept secret.
Preserving privacy means tokens become trivial to share, and then there’s nothing stopping a ten year old watching huge amounts of extreme porn except for things that would have worked without having any system, like having their parent stand behind them. If the new system doesn’t improve things compared to having no system, then there’s no point making it.