logoalt Hacker News

Jtsummersyesterday at 10:16 PM1 replyview on HN

Step 1: Shift the burden from service providers to OS providers (on devices owned by individuals).

Step 2: Recognize that the system is trivially bypassed by a kid who sets up their own device without their parents' oversight or parents who just think this is a stupid law and lying for their kids. Or bypassed by anyone using open source operating systems which are (for a feature like this) going to be trivial to amend to always claim the person is an adult regardless of which account is being used.

At this point there are three possible futures that are worth considering:

1. Throw out the rules because they're stupid and everyone with any common sense or sense of decency has been saying it since the start. The service provider is responsible, not the OS developer or device manufacturer. (Best case)

2. Keep the stupid rules on the books and pretend they work. Let the service providers off the hook. (Second best case)

3. Create more rules that effectively cedes more control of personal devices to the government to make this actually work, but the effect of this is to essentially outlaw OSes like Linux and many, many devices and even raw hardware without a government permitted OS pre-installed. (The worst case)

(3) is extreme, but it's the only way that this law actually has the desired effect. (1) and (2) are the most likely outcomes, but reflect that this whole exercise is just a waste of time.


Replies

xp84yesterday at 10:42 PM

Your Step 2 assumes complete idiot parents. Parents who hand their kids a new device without adding any parental controls (A) are already in the minority today - I know a lot of parents and none of us would do that, and (B) can't be helped anyway under any scheme other than invasive identity "verification" (which this law isn't).

> bypassed by anyone using open source operating systems

You know what? If millions of tweens develop a keen interest in building Linux and Firefox from source just to get "the good TikTok" I'm fine with that. In reality 99% of them use iOS and Android nearly exclusively, so Linux is irrelevant to the conversation.

> The service provider is responsible

We tried that. That's the status quo. There are only two options I know for this, both stupid. 1. (the current model) Just trust the user. Talk about 'trivially bypassed'! 2. Invasive ID checks - with the camera, identity documents, and government databases.

If parents want to go out of their way to irresponsibly give their kids unmonitored access to content that is bad for them that's on the parents. If you try to make service providers "responsible" for it, they WILL build invasive, corporate-controlled systems to cover their asses. Basically option 3 but controlled by shitty companies that get hacked, instead of even a theoretically accountable government that will get hacked. Note that I am not saying your option 3 would be acceptable, just that a private version of it would be even grosser.

show 1 reply