One major controversy I recall with VRchat's implementation of age assurance (via Persona) is that they retained identity of who you were after completing the process. Not who exactly, but your identity was hashed so that if the same person attempted to verify again they could tell who it is. This effectively meant one individual can have one validated account per lifetime. If the flakey AI moderation banned you for an emoji combination freshly deemed racist/etc, you effectively lost your only shot at a validated VRchat account forever.
This is an issue with age assurance that goes well beyond just verifying age, and is undoubtedly viewed as a fringe benefit of age assurance for those wishing to deanonymise the internet.
The question here is, does Discord do the same thing for any or all of the selected options? Or is identity data full well and truly purged once the outcome is determined - no hashing, nothing retained other than the result?
IRC plus GNU Jami are still freedom respecting zones! I sincerely hope all this age verification crap causes cypherpunk FOSS solutions to grow in popularity.
Matrix has become invaluable for dozens of my hacker friends. We ditched Discord almost a year ago and we have no desire to go back. Besides having high quality e2ee voice/video/screensharing (thanks LiveKit), we collectively spend 10x less for the functionality and keep our data in Switzerland. No ads, no one getting their accounts hacked with QR codes, ultra-granular space/channel settings, multiple choices for client implementations, and end to end encryption enables sensitive discussions that would have previously been curtailed. The identity verification is greatly appreciated although our new users do have some issues getting set up with multiple devices, but it's no more complicated than multi-device WhatsApp. Matrix is ready for prime time.
There was a brief window where you could submit fake biometrics through a third-party site to verify age on Discord, pretty sure I got the link from hackernews.
That made me feel better that Discord didn't need to store my ID or video of my face, and was only storing the results of some analysis and not the inputs.
When the social media ban went into effect in Australia last year, kids were submitting photos of their parents and dogs to get around the verification. Not sure how better or worse they've gotten, but the old adage of trying to keep things from kids only motivates them more to get around the limitations you put up.
I actually like their implementation.
I'm curious if it will be enough for governments, but it is nice that they are trying to persue a path without id checks
This proposed solution does however allow quite liberal access to discord without confirming the age. If the implementation is as worded; then i would not see a reason to confirm my age at all.
The issue comes down to if governments accept such a (urgh) comparatively lax implementation. It's pretty clear to me that the primary purpose of these laws are entirely to... force all citizens to identify themselves across the internet for the purpose of profile building, and nothing to do with child safety.
So as implementations go; this one is pretty decent. We should stop governments from passing these darn laws though.
One major controversy I recall with VRchat's implementation of age assurance (via Persona) is that they retained identity of who you were after completing the process. Not who exactly, but your identity was hashed so that if the same person attempted to verify again they could tell who it is. This effectively meant one individual can have one validated account per lifetime. If the flakey AI moderation banned you for an emoji combination freshly deemed racist/etc, you effectively lost your only shot at a validated VRchat account forever.
This is an issue with age assurance that goes well beyond just verifying age, and is undoubtedly viewed as a fringe benefit of age assurance for those wishing to deanonymise the internet.
The question here is, does Discord do the same thing for any or all of the selected options? Or is identity data full well and truly purged once the outcome is determined - no hashing, nothing retained other than the result?
IRC plus GNU Jami are still freedom respecting zones! I sincerely hope all this age verification crap causes cypherpunk FOSS solutions to grow in popularity.
Matrix has become invaluable for dozens of my hacker friends. We ditched Discord almost a year ago and we have no desire to go back. Besides having high quality e2ee voice/video/screensharing (thanks LiveKit), we collectively spend 10x less for the functionality and keep our data in Switzerland. No ads, no one getting their accounts hacked with QR codes, ultra-granular space/channel settings, multiple choices for client implementations, and end to end encryption enables sensitive discussions that would have previously been curtailed. The identity verification is greatly appreciated although our new users do have some issues getting set up with multiple devices, but it's no more complicated than multi-device WhatsApp. Matrix is ready for prime time.
There was a brief window where you could submit fake biometrics through a third-party site to verify age on Discord, pretty sure I got the link from hackernews.
That made me feel better that Discord didn't need to store my ID or video of my face, and was only storing the results of some analysis and not the inputs.
When the social media ban went into effect in Australia last year, kids were submitting photos of their parents and dogs to get around the verification. Not sure how better or worse they've gotten, but the old adage of trying to keep things from kids only motivates them more to get around the limitations you put up.
For reference: https://www.ndtv.com/world-news/dog-photos-vpns-fake-ids-how...
Still required to use a video or ID card in the UK.
I actually like their implementation. I'm curious if it will be enough for governments, but it is nice that they are trying to persue a path without id checks
All the available paths turn into:
- give us your ID
- give us your biometrics
- give somebody, not necessarily Discord, a valid credit card
That's sll of the paths.
[delayed]
This proposed solution does however allow quite liberal access to discord without confirming the age. If the implementation is as worded; then i would not see a reason to confirm my age at all.
The issue comes down to if governments accept such a (urgh) comparatively lax implementation. It's pretty clear to me that the primary purpose of these laws are entirely to... force all citizens to identify themselves across the internet for the purpose of profile building, and nothing to do with child safety.
So as implementations go; this one is pretty decent. We should stop governments from passing these darn laws though.
If the account age estimation puts you in adult, it sounds like you don't need to do any of those?
I'd like to see details about their model there, but account age is at least better than a lot of systems like steam are doing for this.
Some of those details are available here: https://discord.com/safety/how-discord-estimates-age-without...
They should not be trying to implement it globally. That is unacceptable.
I like that the dialog indicates the service provider. Thumbs up for transparency.