I’m in Finland. We have “strong identification services” for logging on government websites, some companies that need to handle personal data, and like.
During the Plague, the people who run the system floated the possibility of providing “has this person been vaccinated? Yes/no” as a type of identification field. And another example that was floated at the same time was “is this person over 18 years old? Yes/no”. Point is, this ID system offers information on need to know basis and the user always sees exactly what information is shared.
So, actually, the most devilish thing to do would be to provide just that information and nothing else. Some weird company needs to know if the user is an adult? Well, just tell them that, and nothing else. If they whine about it, just tell them this system provides them exactly the information they asked for. Also it’s the official government service. No reason whatsoever to doubt its validity! Wait, are they still whining? Well maybe they’re not trustworthy and we shouldn’t provide them this service.
This initiative is just a smokescreen; it actually pushes things down the slippery slope.
Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate and provided by law. The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure
Define “necessary”. Define “by law”. The pushers for proof-of-age already say it’s anonymous – but it can’t be.
As much as I do think this is good to push for, the fuck do they mean by the “strictly” necessary thing? I’m from the US and this is what started the shit. IT’S STRICTLY NECESSARY WE STOP KIDS FROM ACCESSING PORN SITES and then it snowballed. I even had to fucking verify just to take a CompTIA test much to my chagrin. I passed btw.
Been messaging the company to ensure they delete my shit before I’m a victim of identity theft.
Age verification must be scrapped completely. Period.
There’s no such thing as anonymous age verification.
The very word “pseudoanonymous” is laughable.
And any non-anonymous age verification is basicaly an authoritarian control feature.
Zero-knowledge proofs exist, where a person can prove one fact without revealing other facts about themselves. If there were a will to do it, governments could figure out a way for people to prove their age to a website without revealing their identity. The problem is that it was never supposed to be about proving your age, because what governments and corporations actually want is your identity for surveillance purposes. Proof of age and protection of children was just the cover story they used to promote the destruction of online anonymity. The goal is surveillance and control, not protection of children.
The EU age verification app is designed to not reveal any information other than the user’s age being over 18. https://digital-strategy.ec.europa.eu/en/faqs/eu-age-verification-solution
And is there any source code that can inequivocally demonstrate that? No. Then the only rational thing is to believe that they’re just lying and selling snake oil as they always do.
Switzerland has implemented laws and a digital system that allows you to verify your age only using a new eID, while promising that it’ll be untraceable that your ID was used to make this check and not giving out more info than “yes, this person is 18+”. The eID is meant to be optional, but we know how these things usually go.
Whether you trust the promises to be actually implemented correctly and without errors is a different matter. I think it was supposed to be released as open source, but you can’t confirm any specific build is actually running on the servers.
So I’d say it’s possible and - compared to current “scan your ID” approaches - more privacy protecting. Its implementation is a different matter.
Never forget that the main age verification method baked into these laws was card transactions. The ID and face scanning technology didn’t really exist when the laws were written, so it describes them more generally, but card transactions were the established method of verifying age. The new technology came in as a cheaper option for service providers.
MasterCard and VISA were the primary promoters of these laws. Even with new technology taking some of the share, the laws would still cause an increase in card verifications at a time when many businesses try to minimise the card verifications they do to limit their transaction fees (ie pay MC and VISA less).
Data breach by xai, of Swiss ID system exposed data of millions of teens!
some future headline
I agree completely, people are manipulated into believing this sort of thing is remotely OK - but its fundamentaly not. Not only does this infringe on peoples privacy but also human and youth rights which are clearly dismissed. The targeted minority is used like tools, sacrificing their rights for mischievous purposes.
If you are undocumented? Then you can’t identify yourself and thus can’t age verify either. Plenty of homeless people or people with incredible life issues are not and will never be able to complete a government-backed age verification scheme.
You can’t even get a SIM card without ID here. It is mandatory to have one or you can and will be fined.
Seriously, those without ID have much more pressing problems than age verification. Proving citizenship for one.
If you don’t think having a SIM card is a “pressing problem” then you don’t have enough contact with homeless people. Staying in contact with those who care is vital for basic things such as:
- having a support network (of professionals)
- being able to call for help
- get information on sources of help
- not getting debanked
- having a support community
You have no idea how hard life on the street is. Plenty of folks there just don’t have a phone because it gets stolen, lost, can’t charge it, falls in the water, breaks or gets thrown to bits because you got wronged again and can’t take it anymore. Maybe you’ll sell it for some cash so you can buy food or get some water for a week?
It all starts with a damn SIM card.
Imagine you can’t do 2FA for your government ID. How can you get a phoen? How are you going to apply to social subsidized housing? How are help providers able to help you if you can’t authenticate to government websites? Social subsidized housing all runs on government eID stuff. Maybe you need to pay 800 euros worth of healthcare bills but don’t know what it’s for and the only way to request it in a timely manner is via authenticating yourself to your insurance company over the internet! Now you can’t!
Basic societal technology needs to work for everyone.
It’s plain illegal discrimination on the government’s part.
Having a SIM card is one of these more pressing problems! Government age verification is very much not one of these when you can’t even access the government sites.
No ID = No SIM = No bank account = No insurance = No (legal) job = No housing
All of those require an ID already. Same with your examples - applying for social housing is dependant on you proving your identity via an ID.
This petition isn’t about eIDs though, it’s about the requirement to use eIDs to access the internet. The eIDs already exist in every single EU member state in case you don’t know.
The whole ‘we should reduce digital reliance on American services’ flew out the window real quick when it was time to introduce digital id and age verification.
I guess mass surveillance comes before digital sovereignty. Priorities.
That’s because the whole “Democracy” part of “Liberal democracy” is an illusion. The entire political class is pre-positioned and pre-financed to serve capital; not the people.
If you haven’t noticed, the world’s wealthiest do not care about geographical boundaries. The fascists who have infiltrated America have their tentacles deep inside every western “democracy”. That’s why they all have secret police who sign contracts with openly fascist billionaires, why they always choose mass surveillance of the working class, and why they never hold wealthy criminals accountable.
Those things are not driven by the same groups of interests. We are not as monolithic as USA.
I have a great alternative to age verification. Just require prebuilt devices to have easy to setup parental controls on first turn on.
The fact that legally requiring corporations to empower users isn’t even on the table, and orwellian mass surveillance is the only viable option to our political class, should tell you everything you need to know about our “democracies”.
Are there parties supportting that suggestion? Seems like something the Pirate Party would support…
We call on the European Commission to propose legislation ensuring that digital identity and age-assurance systems used to access online services in the Union remain voluntary, privacy-preserving and non-discriminatory. Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate and provided by law. The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure, open-source implementation, independent security audits, prohibition of cross-service tracking by relying parties, and equivalent alternatives for citizens who do not use a digital wallet.
So a completely useless initiative, is how I’m reading this. The “unless strictly necessary” is a fabulous “think of the children/national security” -backdoor. This is basically the same platitudes, the EU and our governments are already feeding us to make online age verification digestible. And the headline of the initiative is blatantly misrepresenting the content…
Citizens must not be forced to identify themselves to access lawful online content or services unless strictly necessary, proportionate and provided by law.
Huh?
Do I have this correct? If the law makers (who this petition would be addressed to) decide that it is strictly necessary, proportionate and the gateway age pass is provided by them, then we are saying it’s okay?
Surely we already know that they will say it is ‘strictly necessary, proportionate’ and they can easily provide some sort of gateway template for site/app owners to implement on their websites.
Lawmakers can provide the law, but “strictly necessary” and “proportionate” are things in the purview of courts and judges.
While you are at it; no attempts to fingerprint the user. No selling personal data.
Am I the only one here thinking the world might be better off without it?
Clearly not
I think the ‘strictly necessary’ bit means to identify where it is necessary to provide the service. Like, to submit your taxes, they need to know who you are.
This is already the case for such services. When you go to their websites you need to authenticate. What this is against is general ID before even visiting any websites.
Isn’t what they describe exactly what EU is already doing?
“”“The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure, open-source implementation”“”
“”“A core objective of this initiative is to deliver a consistent, secure, privacy-preserving and user-friendly age verification experience that can be easily integrated into a wide variety of digital services throughout the European Union. The modular architecture and adherence to open standards not only ensure interoperability between national systems, but also allow online service providers to adapt the solution to their own technical and regulatory environments.”“”
Doesn’t GDPR already require any solution to be privacy preserving? It kind of sound like people want EU to pass the same law again so that they can feel better about it. Of course if they do it most people still won’t know what’s in it and will keep complaining.
Objectives
We call on the European Commission to propose legislation ensuring that digital identity and age-assurance systems used to access online services in the Union remain voluntary, privacy-preserving and non-discriminatory.
The legislation should require anonymous or pseudonymous proof-of-age, data minimisation, selective disclosure, open-source implementation, independent security audits, prohibition of cross-service tracking by relying parties, and equivalent alternatives for citizens who do not use a digital wallet.
Emphasis added by me to highlight the relevant parts.
These two parts are not covered by the currently planned digital id and age verification implementations.
voluntary
What does that even mean? I don’t think anyone is proposing mandatory, internet-wide age verification. It’s ‘content based’. Some content is hidden behind age checks. It doesn’t make sense to prove you’re NOT 18. Either you prove you’re 18/16/21 and get access of you don’t prove it and you don’t get access. At the same time requiring every website to provide ‘non-adult’ version also doesn’t make sense (like pornhub would have to offer child safe version?). Same with social media bans - everyone below 16 is banned. What would “voluntary” check look like here?
equivalent alternatives for citizens who do not use a digital wallet
So it comes down to some alternative implementation of https://ageverification.dev/? It’s an open standard. Doesn’t it allow for implementations not based on digital wallets? I think that if that’s the demand then it would be better to specify it clearly instead of mixing it with demands that the current legislation and implementation already provide.
What does that even mean? I don’t think anyone is proposing mandatory, internet-wide age verification.
Right now, the proposed age verification law would be very much mandatory, i.e., companies would be legally required to implement age verification or face fines/other penalties.
I can’t speak for the initiative’s organizers, but to me ‘voluntary’ means companies would be free to choose whether or not to implement age verification for their services.
So it comes down to some alternative implementation of https://ageverification.dev/? It’s an open standard.
The current problem is it relies completely on Google and Apple device attestation, which means it’ll be unavailable on rooted, uncertified by Google, and/or not running Google services devices. One of the developers confirmed on Github that this is the intended implementation and will most likely not be changed (and got down voted into oblivion).
These initiatives aren’t meant to provide any clear and direct solutions to any problems. Their goal is to let the EU know that there are issues Europeans are worried about, and then the Comission, Council, and Parliament will talk about any available solutions, if they deem it appropriate. Which they are absolutely not required to, unfortunately.
The current problem is it relies completely on Google and Apple device attestation, which means it’ll be unavailable on rooted, uncertified by Google, and/or not running Google services devices. One of the developers confirmed on Github that this is the intended implementation and will most likely not be changed (and got down voted into oblivion).
That’s a valid point. I wish the petition stated it this clearly. The way it’s written right now no politician will understand this is what’s being requested.
Doing my part. Also with all the other good innitiatives rn!











