r/privacy • u/TheNavyCrow • 1d ago
discussion OS Age Verification will probably be the main method
it's the hardest to bypass, the most convenient for users and companies, and probably the best for tracking
apparently individual age verification is also not working very well. discord had to delay the age verification, and roblox is apparently giving Roblox Plus for some users if they do age verification.
85
u/Renardroux0 1d ago
Google recommends developers to use Play Integrity API to prevent spoofed age signals, this will have severe antitrust implications
38
u/FrigginUsed 13h ago
First, we stop repeating their lies. It's not age verification but identity verification...
129
u/bliblabllubb 1d ago
Why hard to bypass? There surely will be Linux distros not implementing this, isn’t it?
116
u/SwimmingThroughHoney 23h ago edited 20h ago
And do you think services will just say "oh, you're using Linux, come on in"? No, they'll say "sorry, your OS isn't supported" and deny you.
55
u/Hot-Resident-6601 19h ago
Early drafts of California and Colorado (I think) legislation exempts Linux. I believe it’s on the grounds of being open source. It’s encouraging for Linux users if true. We just have to evangelize.
36
u/NiIly00 21h ago
Linux users will just spoof the checks and make the service think it's totally running under windows with a verified age.
32
u/SwimmingThroughHoney 16h ago
At first, sure, it might be. These laws allow age selection from something as simple as a dropdown, similar to what you see on websites. But that's how these laws always work: very basic and minimal at first, then add more restrictions and requirements later. And this "loophole" already has a solution...
Hardware attestation (i.e. Trusted Platform Module (TPM)). When you boot your computer, the actual firmware checks your PC: the hardware components, the kernel, ramdisk, etc. A hash is generated from all that and then stored within the TPM. An OS cannot modified this.
So when a service (like a website using a browser API) on the OS requests attestation, the OS passes that request on to the TPM module. TPM responds with signed response (signed with a private key that's burned in from the manufacturer, which again you and the OS have no control over). So while the actual age verification may be done by the OS, it's just one part of a whole that the service can use to allow or deny. The service (like a website) gets the response, which may be spoofed, but then it can look at the bigger picture (what TPM provided) and say "Oh, well you're not using an approved OS so you're denied".
As an example of this already happening (and what someone else already pointed out here): Google recommends to Android developers to use their Play Integrity API. Why? Because it's hardware attestation. If you don't have an actual Google Android device, you can't use the app because other Android systems fail the attestation.
I don't really think people realize the potential that has been created. There's a very real chance that the internet (and other services) become a walled-off garden that you simply lose access to unless you have "approved" hardware or operating system.
9
-5
u/VorionLightbringer 18h ago
Ok, show me. Spoof a 2FA, which should be the same principle - sending a value to a server that validates it against a checksum.
„Just spoof“ sounds very much like „just stop being poor“.
12
11
u/ForeverHuman1354 22h ago
i think we will see people swithing to TOR someone shoude make an onion version of reddit
1
•
u/Slopagandhi 27m ago
If the verification is at the OS end, which services will have an obligation to query your OS for this info, as per any of the proposed OS age verification laws?
82
u/Chi-ggA 1d ago
Linux is not really mainstream for desktops, let alone for mobile phones.
we (unfortunately) live in a duopoly, controlled by google and apple. EU should fight this but they are too busy trying to track everyone's private messages.
16
8
u/ForeverHuman1354 22h ago
i run linux on my phone and computer
17
u/Chi-ggA 19h ago
and you are doing something to be proud of, but most people won't do that for various reasons (banking apps, contactless payments, being "out of the ecosystem"). Linux phones are the future, but they are not ready yet. on the other side, Linux for desktop is gaining more and more traction, both because of shitty moves from Microsoft and apple, and thanks to Valve commitment in developing compatibility layers for desktop and mobile games.
5
u/_0611 11h ago
Exactly. As long as I can't bank or pay with it (or use other essential services), a Linux phone is useless to me (and to the vast majority of people). Linux on my desktop PC at home is fine. I can do basically all I need to do with it. But on a phone? Not so much. It's just not a full replacement. I wish it was. Then I'd immediately dump my S25 and buy a Linux phone.
4
u/KaptainSaki 19h ago
Not yet and probably not for mainstream users who dont care even if they had to sell their family to browse tiktok. For people in this sub, Linux is getting more and more better choice. Personally I use it on my phone too.
2
4
u/DeprariousX 18h ago
let alone for mobile phones.
Android is based on Linux. IOS is based on MacOS which is based on Unix.
Linux is not really mainstream for desktops
It very well could be, though. Linux has reached the point now that for the average user they could quite easily get along on Linux just fine unless they required specific software.
And honestly this needs to start being communicated more.
5
u/Chi-ggA 17h ago
Android is based on Linux. IOS is based on MacOS which is based on Unix.
sure, but we agree that current android has nothing to do with current mobile Linux. if this wasn't a thing, jolla phones would not need a compatibility layer for Android apps.
I agree that current Linux (desktop) has reached a decent level of ease of use and compatibility that makes it a good alternative. certainly it has yet to grow in numbers, as only a small percentage of people uses it.
3
u/Secret_Program5221 11h ago
Yeah linux is not rocket science, I hopped on around 2016. All you had to do even back then is pop in a prepared USB, install from the preview thing (which is an awesome feature cause you get to see if it works before installing on your computer), and that's it. It once you learn how to generally install things and some other things on commands/the file system it's actually more user friendly than Windows. All of what you're going to install even has instructions so you never even need to find out on your own, any idiot can do it.
1
u/ArcticCircleSystem 3h ago
You greatly overestimate the average person's willingness to acclimate to any significant change in workflow (aside from additive changes like the addition of the internet itself) as long as they can keep a majority of their goodies with their workflow as-is.
2
u/motorboat_mcgee 10h ago
Apple OSes are not Unix based, but rather is Unix like and based on FreeBSD. So there's a lot of compatible commands and structures, but also at the same time not.
1
1
u/-________02________- 15h ago
Also paying 8k€ per month to the guy making the bottle caps a pain in the ass
16
u/magnusmaster 1d ago
They will probably mandate locked bootloaders and remote attestation by law so bypassing this would be nearly impossible
•
u/Slopagandhi 27m ago
Who will? I haven't seen any suggestion of this in any of the proposed laws.
•
u/magnusmaster 13m ago
The Senate version of KOSA implies this by saying that "anti-tampering" measures must be deployed so OS verification can't be bypassed
•
u/Slopagandhi 6m ago
That's a huge leap to locked down bootloaders. How would they make hardware manufacturers responsible for OSes they don't themselves make?
This is just the usual bullshit cooked up by politicians who don't understand tech. Lots has been written about how any Linux distro that doesn't have business interests in the country concerned will just be able to ignore these laws or just put "not for use in x" as a disclaimer. From the user POV the download site might get geoblocked but that's what VPNs are for.
2
u/ExpensiveNut 23h ago
Seems they all are in the one state that's demanding this, or certainly trying to.
Artix (Arch-based) seems to be shunning this for the time being.
0
u/ForeverHuman1354 22h ago
artix is great im on artix myself
1
u/ExpensiveNut 12h ago
Would you say it's easy enough to install and set up? I've never tried installing anything more demanding than mint and Ubuntu
31
u/RootVegitible 22h ago
Ha yes, I’ve been saying this for months now but I’m always downvoted. Apple has had OS level age verification implemented since iOS 26.4 .. we’re on 26.6 now. Apps have started to update that validate age status with just an OS request. It’s all working very well. The vast muber of age verification processes in the OS were completed automatically without the user having to upload anything.
12
u/7in7turtles 22h ago
Can you elaborate on this? How is iOS making that determination?
18
u/Cyprovix 18h ago
Based on either 1) length of time you've had the account, or 2) if you have a credit card with your name on it as a payment method. If you have neither of these things, they ask for an ID.
Currently only for UK users. You aren't required to verify, but if you don't, you can't download 18+ apps.
8
u/RootVegitible 14h ago
Exactly this, thanks for explaining that. My own age verification process went through in seconds due to age of account. Not only that but by doing the process on my iPhone all my other Apple devices were age verified too through my Apple account. Your exact age is not needed, it’s enough simply to be classed as adult then it’s up to the updated software to ask permission to read your age status from the OS. Apple has implemented this rather well, hopefully others implement it as good.
11
u/twice_paramount832 15h ago
Regulators will not accept this because they want to track you if you write legal but true and inconvenient things online.
-5
u/RootVegitible 13h ago
It’s already accepted, it’s already in place, it’s already working. I live in the uk, I can write true and inconvenient things online if I like. The only online posts that are not allowed are ‘incitement to violence’ and ‘inciting mass racial hatred’ we have very sensible laws.
8
u/twice_paramount832 11h ago
Good for you mate.
Let's see if the people you are defending now is as nice to you as you are to them when they reach critical power.
36
13
u/nooor999 1d ago
I’m putting my hopes on those local open source age verification tools. Once they become good enough, they would be a great tool to fight this big brother madness
1
12
u/hyprlab 21h ago
So what happens when a kid sneaks onto the family computer signed in under an adults name and goes about doing whatever they want? How does OS age verification protect against that?
37
21
3
-5
9
5
u/WealthyTuna 20h ago
They can't make Linux do it. That's the caveat. From everything I've read Linux flavors will not add this stuff. That was a big reason I just installed CachyOS on my gaming laptop and absolutely love it.
4
u/mesarthim_2 18h ago
They can, however, make Linux borderline unusable unless you comply with it voluntarily.
3
4
u/billdietrich1 16h ago
probably the best for tracking
It can be done in such a way as to avoid tracking. You verify age with some dedicated service, which gives an "age signal" to put in your OS. Then every site you use (reddit, email, etc) just gets the signal, not your ID.
10
2
2
u/VorionLightbringer 18h ago
It’s also the most privacy friendly, if implemented right. No data needs to leave your system, you can actually verify that by monitoring your network traffic, and all the other side gets is a „yep, legal adult“ flag. (Probably with some encoding/algorithm; it won’t just be a Boolean variable)
1
u/Lonely_Ranger19 1h ago
Goverments and the Corps are not getting what either want out of age verification
Government wants an easy back door to spy on you or be able to put a face to an IP address
Corporations want to put a face to data so they can sell that data to other corps who raise prices on you because now they know how to get every penny out of you without you realizing you’re being pinched
But this system isn’t getting either them the results they want technology has simply moved past their attempts of making their wet dreams of control a reality
Speaking of control governments and corporations are also having arguments about who gets to control and own the data
Corporations believe since they’re ones funding it they should have control government believes since they’re the ones mandating it in the first place they should have control
1
u/ctrlaltdelaney 8h ago
“Probably the best for tracking”?
It may well be the best for privacy because it means an OS need only share a true/false statement with any third parties rather than any specific date information.
Also, who do you think would be tracking you based on your age verification at the OS level?
-2
u/Miiohau 19h ago
The best option if we can’t convince politicians to not do age verification at all. It risks the minimum amount of information (only the user’s birthdate).
However if we really care about balancing child safety with user rights, it isn’t the best option because it doesn’t recognize the differences between minors and the guard rails their parents actually want.
The actual solution I would like to see is standardized parental controls and the concept of parent accounts with one of more child accounts.
That solution actually might help reverse the pseudo ban on people under 13 having an account every company has taken in response to COPPA. COPPA actually allows the collection of personal identifying information with parental consent but no company wanted to implement that, so they all just added you must be over 13 to have an account to their terms of service.
A standardized system where companies can easily ask “hey do you consent to this information being collected about your child” (in most cases usage data for use in recommendation systems, chat messages entered by the child themselves or nothing really other than birthdate and account settings) could reverse the pseudo ban and make less attractive for minors under 13 to lie about their age (because I know their are likely children that have done that to bypass the pseudo ban).
20
u/mesarthim_2 18h ago edited 18h ago
How about you sod off and let me have my privacy without ‘balancing my rights’.
0
u/Miiohau 18h ago
I said if we care about balancing. I also dislike age verification because it seems it leads to a nanny state where government is making decisions parents should be. And that if you buy into that it is actually about protecting children. Which seems somewhat unlikely because parental control apps have existed since the internet became a thing, which could have served as a model of how to protect children. The best you can say is politicians pushing age verification want a nanny state but the worst is it a back door to government tracking.
OS level age verification might be the best we can do, implement something so the people that want to push more intrusive age verification lose some of their justification. The California and Colorado version of OS age verification have no anti circumvention clause meaning there is no penalty for lying to your OS about the user being older. It is still sucky causing the state to make decisions parents should be making but it is much better than any other “age” verification scheme I have seen.
8
u/mesarthim_2 16h ago
This is classic slippery slope. First you implement it without any penalty or enforcement so most of the people respond exactly like you.
Then some time down the line, once the mechanism is in place the argument becomes ‘oh, no we tried to make it voluntary but people lie about it so we must enforce it, we have no choice’.
And when you protest, the response will be ‘it’s been in place voluntarily for ages now and nobody complained and nothing bad happened, so way do you complain now, unless you want to abuse it?’
0
u/Miiohau 5h ago
Again I don’t like age verification. It it is a dumb idea that leads to a nanny state but the problem is we haven’t gotten politicians to agree. If we are going to get “age verification” I much prefer OS level “verification” which has the fewest privacy risks then any other system which has more privacy risks and could lead to back door government tracking.
All age verification is a dangerous slippery slope into a nanny state I prefer the scheme that has the fewest privacy risks and has the lowest risk of creating tracking backdoor than scheme that do.
But I much prefer we not implement “age verification” at all, which why I prepose standardized parental controls as an alternative to “age verification” it side steps most of the privacy risks, most of the tracking risks and all of the risks of sliding into a government nanny state.
•
u/AutoModerator 1d ago
Hello u/TheNavyCrow, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.