Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am terrified because the majority of discussions are not treating Problems #3 or #4 seriously.

Problem #1: Verify ages for adult-appropriate content.

Problem #2: Do not create a new surveillance system for the government.

Problem #3: Do not create a --dynamic-- per-user internet-access permissioning/control/denial system for the government. This would be madness.

Problem #4: Do not create a --general-- per-user internet-access permissioning/control/denial system for the government.

Problems #3 & 4 are very very serious. Any age-verification system, or generalized control-system, will become a pervasive requirement for a large percentage of internet sites, simply by being convenient for risk-adverse sites to adopt. Which means, this will be (not could be: will be) a pervasive government managed system of per-user internet control/denial.

We need zero knowledge proofs. Or similar. Minimum.

Form of solution:

• Any third-party institution meeting publically-defined government requirements, can be an attestor.

• Attestors provide persistent age-verification tokens per user-device, on user request/verification: Using actual identification and one-off-anonymized device identifiers.

• Sites are given one-off, device and user-identity anonymous, attestation tokens, derived from the device token, on request.*

Maximum anonymization is necessary so:

• Governments can't identify your devices.

• Sites can't identify your devices or you.

• Government and sites cannot collude to remove anonymity (via this system), enabling a new surveillance system.

Attestation tokens need to be persistent so:

• The government is not being given dynamic control of our internet use.

Age-attestation tokens, must be provided independent from any other types of attestation, so:

• We didn't just invite the government to link multiple permissioning systems together, which will inevitably be used in coordination. And so failure to supply age-attestation tokens is a clear documentatable act.

Unrestricted (other than by public standards), third-party attesters:

• So users can choose an attester they trust. So there are multiple points of attestation. So there is individual accountability, natural documentation, and reputation risk for any denial of attestation.

Anything less anonymized, independent, persistent or available than this is a nightmare situation. Really.

I am terrified because the majority of discussions are not treating Problems #3 and #4 seriously.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: