• ExLisper@lemmy.curiana.net
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 day ago

    Isn’t what they describe exactly what EU is already doing?

    “”“The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure, open-source implementation”“”

    https://ageverification.dev/

    “”“A core objective of this initiative is to deliver a consistent, secure, privacy-preserving and user-friendly age verification experience that can be easily integrated into a wide variety of digital services throughout the European Union. The modular architecture and adherence to open standards not only ensure interoperability between national systems, but also allow online service providers to adapt the solution to their own technical and regulatory environments.”“”

    Doesn’t GDPR already require any solution to be privacy preserving? It kind of sound like people want EU to pass the same law again so that they can feel better about it. Of course if they do it most people still won’t know what’s in it and will keep complaining.

    • DupaCycki@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      1 day ago

      Objectives

      We call on the European Commission to propose legislation ensuring that digital identity and age-assurance systems used to access online services in the Union remain voluntary, privacy-preserving and non-discriminatory.

      The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure, open-source implementation, independent security audits, prohibition of cross-service tracking by relying parties, and equivalent alternatives for citizens who do not use a digital wallet.

      Emphasis added by me to highlight the relevant parts.

      These two parts are not covered by the currently planned digital id and age verification implementations.

      • ExLisper@lemmy.curiana.net
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        3
        ·
        1 day ago

        voluntary

        What does that even mean? I don’t think anyone is proposing mandatory, internet-wide age verification. It’s ‘content based’. Some content is hidden behind age checks. It doesn’t make sense to prove you’re NOT 18. Either you prove you’re 18/16/21 and get access of you don’t prove it and you don’t get access. At the same time requiring every website to provide ‘non-adult’ version also doesn’t make sense (like pornhub would have to offer child safe version?). Same with social media bans - everyone below 16 is banned. What would “voluntary” check look like here?

        equivalent alternatives for citizens who do not use a digital wallet

        So it comes down to some alternative implementation of https://ageverification.dev/? It’s an open standard. Doesn’t it allow for implementations not based on digital wallets? I think that if that’s the demand then it would be better to specify it clearly instead of mixing it with demands that the current legislation and implementation already provide.

        • DupaCycki@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          24 hours ago

          What does that even mean? I don’t think anyone is proposing mandatory, internet-wide age verification.

          Right now, the proposed age verification law would be very much mandatory, i.e., companies would be legally required to implement age verification or face fines/other penalties.

          I can’t speak for the initiative’s organizers, but to me ‘voluntary’ means companies would be free to choose whether or not to implement age verification for their services.

          So it comes down to some alternative implementation of https://ageverification.dev/? It’s an open standard.

          The current problem is it relies completely on Google and Apple device attestation, which means it’ll be unavailable on rooted, uncertified by Google, and/or not running Google services devices. One of the developers confirmed on Github that this is the intended implementation and will most likely not be changed (and got down voted into oblivion).

          These initiatives aren’t meant to provide any clear and direct solutions to any problems. Their goal is to let the EU know that there are issues Europeans are worried about, and then the Comission, Council, and Parliament will talk about any available solutions, if they deem it appropriate. Which they are absolutely not required to, unfortunately.

          • ExLisper@lemmy.curiana.net
            link
            fedilink
            English
            arrow-up
            2
            ·
            23 hours ago

            The current problem is it relies completely on Google and Apple device attestation, which means it’ll be unavailable on rooted, uncertified by Google, and/or not running Google services devices. One of the developers confirmed on Github that this is the intended implementation and will most likely not be changed (and got down voted into oblivion).

            That’s a valid point. I wish the petition stated it this clearly. The way it’s written right now no politician will understand this is what’s being requested.