[HN Gopher] Update on age requirements for apps distributed in T...
___________________________________________________________________
Update on age requirements for apps distributed in Texas
Author : Austin_Conlon
Score : 22 points
Date : 2026-01-12 20:27 UTC (2 hours ago)
(HTM) web link (developer.apple.com)
(TXT) w3m dump (developer.apple.com)
| expedition32 wrote:
| It is interesting to me that we are running a giant social
| experiment with people's childhoods- something we know can only
| be done once.
|
| Meanwhile the silicon valley elite admitted that they don't let
| their 12 year old daughter on Instagram...
| munificent wrote:
| Society has always been running giant social experiments on the
| next generation. That's what a culture is.
| bmitc wrote:
| What are some key examples prior the Internet?
| conductr wrote:
| It's more interesting to me why nobody except sv elites can
| come to the same conclusion themselves regarding <12 year olds
| on instagram and instead seem to need the government to parent
| their kids
|
| I hate this law and those like it, mostly because it shouldn't
| be necessary for government to overstep like this. But when I
| look around... maybe it is
| wmf wrote:
| It's a collective action problem.
| godelski wrote:
| I don't think it is just that. Look at an HN thread on
| privacy and you will find a lot of people that do not see
| any issues.
|
| The problem really comes down to complexity and trust. The
| truth is that there never is a problem if we operate under
| the assumption that all actors are honest and good natured.
| But the reality of the world is that this is a naive
| assumption. All citizens should be concerned about changing
| objectives from their authorities. A democracy can vote in
| dictators and a benevolent dictator can quickly change to a
| malicious one (which has happened frequently historically).
| We also need to be concerned with non-authority threat
| actors, from criminals to nation-state actors competing
| states (and even allies for the same aforementioned
| reason).
|
| That's the problem. The realistic conditions we need to
| solve for are far more complex than the ones people operate
| under and we have a difficult time talking to one another
| about it. For a privacy conscious person it does not matter
| if the holder of the data is the most benevolent entity
| that could exist, it is if there is the opportunity for the
| data to be held by anyone else. Thus, no one should hold
| it. No matter how "worthy".
|
| Even on HN there are a large number of users who think they
| are not the target of hackers, and especially nation-state
| hackers. Of all places on the internet this should be one
| of the most informed on the matter and best suited to
| understand that being "normal" is what makes them a target,
| to be incorporated into bot-nets or other reasons like
| being used for lateral movement. It is the exact same
| problem: the reality is far more complex. The assumption of
| not being a target is based on the understanding that they
| are not the end target but the complexity of reality is
| that this is not the condition for being /a/ target.
|
| I do agree that collective action matters. But it is hard
| to form collective action when people do not have the
| motivation for action. And they don't have the motivation
| because they have a naive approximation of the problems at
| hand.
| MiddleEndian wrote:
| I would not let my (hypothetical) 12 year old on Instagram. I
| also don't want to give Instagram (or any other site, since I
| don't use Instagram) my ID to view content on it.
| Edmond wrote:
| If the hammer ever comes down on this issue, ie hardcore
| requirement for age verification, there are ways to do this while
| protecting privacy.
|
| We are experimenting with bootstraping a PKI certificate trust
| chain for facilitating trust projection and information
| verification online. Think of it as the ability to do things like
| age verification at scale via a peer-2-peer ish mechanism instead
| of sending your government id to a service provider.
|
| One experiment is with PGP key holders (for now Keybase key
| holders) as CAs:
|
| https://news.ycombinator.com/item?id=46576590
|
| And also .gov email holders:
|
| https://blog.certisfy.com/2025/12/using-gov-email-addresses-...
|
| It's all self-service and requires no sign-up or download of
| anything, the app (https://certisfy.com/app) is an in-browser app
| and all the cryptography happens in the browser.
| mschuster91 wrote:
| Why so complex. ID cards could solve that issue, every European
| ID card has a powerful and programmable crypto processor /
| secure element inside and so do all ICAO compliant passports.
|
| Have the website emit a random nonce (to guide against replay
| attacks / reuse) plus an information what is requested (name,
| DOB, address, some like the Croatian ID card even store
| photographs), the card prepares a response with that data,
| signs that using its private key (with a 2FA being possible as
| well by using a PIN/password) and returns it to the website.
|
| The Croatian ID card doesn't even need a middleware because it
| doesn't do 2FA, you can ask it all of that by pure NFC
| communication. The German ID card requires a middleware
| ("AusweisApp", open source) for added protection though.
| Edmond wrote:
| Age verification could indeed be implemented in other ways.
| The approach outlined above is for information verification
| and trust projection in general, meaning you can put just
| about any verified information on a certificate and it can be
| used online.
|
| Here is a concrete example of how trustworthy certificates
| can be used online, this is my personal profile on bluesky
| with verification that is independent of the Blue sky
| service: https://bsky.app/profile/bitlooter.bsky.social
|
| If you click on the profile image you can enter that code
| into https://certisfy.com/app to verify the identity of the
| profile. That sticker could be on any online profile to prove
| high quality authenticity, it could for instance be on an
| e-commerce site to prove that the site isn't a scam.
| LukeShu wrote:
| In 2005, we decided that we were going to have Real ID by
| 2008. We're now looking at a 2027 completion date.
| wmf wrote:
| Google and Apple already have private age verification so I
| think the time for experiments is past.
| vorpalhex wrote:
| Can age assurance be done privately and anonymously?
| Absolutely.
|
| But the entire point of age laws is to stifle free speech and
| ruin privacy. Thus why every age law requires uploading an ID.
|
| If it was just age, just require a credit charge of a $1
| through an intermediary. Good for a year or whatever.
| Nextgrid wrote:
| > the entire point of age laws is to stifle free speech and
| ruin privacy
|
| Does it? I mean sure, it's a side-effect that some (most?)
| politicians might find desirable, but there's also people who
| just want to restrict access to adult material (not taking a
| position on whether it's a good or bad thing here). Most
| parents would probably agree with the latter even if they
| don't with the former.
| vorpalhex wrote:
| Is there anyone who can't do this today? Adult websites
| self label, and both your router and ISP offer removing
| adult websites as an option.
|
| If your kid is going to get around that by clever vpn use,
| age gates don't help.
| Nextgrid wrote:
| > If your kid is going to get around that by clever vpn
| use, age gates don't help.
|
| I think politicians and their supporters _believe_ they
| do help. Of course from their perspective the only way to
| know for sure is to implement the restrictions
| (regardless of whether they succeed, at least they
| fulfill their campaign promises to their electors of
| "doing something").
| drakythe wrote:
| While some people may want that, everyone who has the
| technical know-how to restrict access can name probably a
| dozen different ways to do it without violating privacy via
| ID Upload. The only reason to push for ID Upload instead of
| the other methods is because policy makers are lazy and
| information resellers want as much information about us all
| as they can get. Its lazy because it just recreates the
| liquor store "Can I see your ID please?" experience
| everyone is so familiar with and takes no explanation, so
| lazy policy makers find it easy to push for, without
| accounting for how that data is handled after use.
| Meanwhile information clearing houses and anti-privacy
| wanks are salivating at how this can be leveraged so they
| too push the "ID Upload is the only way!" messaging.
| gruez wrote:
| >and information resellers want as much information about
| us all as they can get.
|
| That seems implausible given that most sites requiring
| age verification outsource it to some third party, which
| means they're not getting all the juicy biometrics.
| Nextgrid wrote:
| My concern with this is how far it goes and whether it has
| unintended side-effects.
|
| There are a lot of situations in history where in retrospect
| being able to evade government oversight and restrictions
| turned out to be a good thing. During the Holocaust a number of
| Jews and other targeted populations were able to escape hostile
| territory because they were able to get forged passports and
| other documents, something that strong cryptography would make
| impossible (even in a perfectly privacy-preserving way).
|
| I'm not sure how old you are or when you started in tech, but
| in my case I started as a kid and was able to build the skills
| that now gave me my career thanks to unrestricted Internet
| access (and sure, I saw pornography a few years earlier than I
| should have - didn't seem to have any measurable detrimental
| effect on me, especially not compared to the cigarettes and
| alcohol).
|
| This wouldn't have been possible if age verification was
| properly implemented, since a lot of the resources that might
| be useful for someone to learn programming/sysadmin could also
| be used to circumvent age verification and thus would've been
| blocked, and I would probably be working a minimum wage job
| and/or engaging in crime to sustain myself as a result. If I
| had to choose whatever harmful effects from pornography versus
| having a min-wage job, I'll take the porn side-effects any day,
| at least I have a roof over my head.
| rockskon wrote:
| I find claims of any technology being able to simultaneously
| validate your age while "respecting privacy" to be suspect at
| best. Even if the technology could work in theory, it would be
| built on top of an ecosystem designed around an ecosystem hell-
| bent on monetizing info about you.
| jazzyjackson wrote:
| Zero knowledge proofs can perform expressions that check
| values within a JSON tree without exposing any of those
| values to the requesting party, for instance "year of birth <
| 2005" can return true or false without returning the person's
| numeric birth year. Essentially the requesting party has the
| holder of the credential perform a computation, the result is
| guaranteed to be the result of each and every instruction
| over a target data structure (only knowing the hash and
| signature chain of the credential, so for instance your
| government issued id can be signed by your secretary of
| states public key)
|
| Estonia has a really interesting government issued public key
| infrastructure where users can validate their identity with
| their physical ID card and a USB reader (maybe it's NFC by
| now?) but I don't think I've heard of the above scheme used
| in practice, just sat through a presentation at the internet
| identity workshop.
| John23832 wrote:
| Just let the parents be responsible. Jesus.
|
| Attach minor accounts to the account of the parent, make the
| parent say yes.
| ghaff wrote:
| Meanwhile I actually started college at 16 which is illegal in
| some locales.
| Jtsummers wrote:
| > illegal in some locales.
|
| In the US or elsewhere? I've known a lot of people who attended
| college at 16, and through friends with teenage children know
| even more these days. They attended (or are attending) schools
| in a variety of states.
| BeetleB wrote:
| I think "illegal" is a strong word. Some states don't allow
| it in public universities. I suspect they're fine with it at
| private universities.
| Jtsummers wrote:
| > Some states don't allow it in public universities.
|
| But which states? I haven't been able to find anything
| about states barring minors from attending universities.
___________________________________________________________________
(page generated 2026-01-12 23:00 UTC)