There is no legitimate reason to impose age verification on users in jurisdictions that do not legally mandate it.
It is a risk to the privacy and safety of all users on the platform - it provides an easier way for pedophiles to identify underage users and provides more doxable information.
Discord has no business making this decision on behalf of jurisdictions that do not legally mandate it.
Do you have any basis for assuming that that users who are under 18 will have that information revealed to other users? That’s not what I read in this article.
I also think you’re being quite prescriptive about a private commercial service. You’re entitled to your opinion, of course, but companies enact restrictions to their products and services not required by law all the time.
If Discord wants to make their service require a mandatory declaration of allegiance to the Klingon empire, they’re allowed to do that.
So yes, it’s super easy for groomers to focus on children with this update.
It is not, as you say, "a risk to the privacy and safety of all users", but rather just those marked as needing to verify.
Your hyperbolic rant is uninformed and tiring.
I did not limit my statement to "people providing their government ID are at risk" or some equivalent for a reason. Bootstrapping the service for accounts it flags as adult now completely leaves all future services who have no pre-existing userbase to behaviorally profile - facilitating an industry norm that age/ID verification should be expected going forward is, and I repeat, a risk to the safety and privacy of all users.
Don't strawman an argument next time as "uninformed" lest you reveal just how many false assumptions you were making in arriving at that conclusion.
I think i'm going to run down the dont use it path, which is a shame, because i do use it atm.
It was sadly too trivial using various Discord search engines to find things like BDSM servers advertising to "14-28 year olds", or ones where minors openly sell NSFW content.
Discord as a whole is oftentimes enabling the communities to prey on those users, not just making the users more identifiable.
This is an issue with age assurance that goes well beyond just verifying age, and is undoubtedly viewed as a fringe benefit of age assurance for those wishing to deanonymise the internet. There's obvious problems with this beyond just "can't ban evade anymore". Authorities or intelligence can run bulk hashes against sets of IDs to effectively deanonymise all accounts.
The question here is, does Discord do the same thing for any or all of the selected options? Or is identity data full well and truly purged once the outcome is determined - no hashing, nothing retained other than the result?
Discord cannot determine identity from the AgeKey.
What they actually do is irrelevant since none of these companies should ever be trusted to do what they claim they will do.
That's obviously not a technical requirement; they're doing this because they expect a large volume of negative publicity, and temporally staggering this rollout means users are less able to coordinate their social-media outrage.
Same logic Reddit used in phasing out the rollout of their controversial login wall. One group says "I can't log in!"; the other says, "huh, it works for me?"
That made me feel better that Discord didn't need to store my ID or video of my face, and was only storing the results of some analysis and not the inputs.
For reference: https://www.ndtv.com/world-news/dog-photos-vpns-fake-ids-how...
This will be a boon for FOSS.
- give us your ID
- give us your biometrics
- give somebody, not necessarily Discord, a valid credit card
That's sll of the paths.
I'd like to see details about their model there, but account age is at least better than a lot of systems like steam are doing for this.
The issue comes down to if governments accept such a (urgh) comparatively lax implementation. It's pretty clear to me that the primary purpose of these laws are entirely to... force all citizens to identify themselves across the internet for the purpose of profile building, and nothing to do with child safety.
So as implementations go; this one is pretty decent. We should stop governments from passing these darn laws though.
* Wait until your account was created > 18 years ago.
That may not be enough for you, and that's fine, this is not a governmental service or site, with a mandate to serve everyone. You can chose not to use discord, and discord can choose not to have you as a customer. YMMV.
I get it. People want to keep their (pseudo)anonymity and details private.
I also get it. People in the real world are scared shitless, legitemately or not, about the effect social media has on young minds.
Discord will kill themselves if they continue with this nonsense.
There are freedom respecting Linux projects, but those lead by redhat\ibm employees (past and present) don't.
Look at it from the perspective of a parent giving a device to a kid. Before, you’d have to deal with a maze of blocking content. You’d have to allow/blocklist a huge number of apps and services manually. If your kid discovers some new one you or your blocking service has never heard of, they’ve gotten around your parental control wishes.
With the age verification API, you just set the age in the OS (and lock it down with MDM or whatever) and now all the apps and websites have to respect it and act accordingly.
Your kid can’t just make a new account or download another browser or do some other crazy workaround to get around your restrictions. That setting is there at the OS level.
I don't understand the uproar. Systemd isn't perfect but it gets so much hate for the value it provides
ID verification is the least of my worries, to be honest. I've been on the internet long enough to acknowledge a need for something like that. I'm uncomfortable with the fact that data is a valuable commodity now. Discord is storing my online habits and conversations somewhere on their servers. Deleting that information is deleting money.
If people weren't worried about that before, then they certainly won't care now.
Is this an AI slop startup larping as a GNU project?
https://www.dexerto.com/entertainment/discord-dev-responds-a...
(Not everyone got unbanned for grid posting yet)
Texas has indicated that it will hold companies liable even if users bypass age verification via VPN or anonymizers.
This isn't the industry deciding that they really want age verification, this is the industry deciding that they don't want to face the potential litigation. Complain about the laws, not the companies following the laws.
We’ve been saying these things about Mastodon and Blue Sky for a long time but they’ve also remained niche.
Discord really isn’t going anywhere anytime soon.
I dread the day I'll make claims like this, even figuratively.
Even at a most surface level reading, this would suggest something like their MAU (monthly active users) at least halving soon/already.
I'd be very surprised if it was trending down even, let alone at this! Forget hyperbole, this is an outright überbole.
By all means though, got any data?
Anecdotally, I suddenly had almost my entire friend group on matrix after that as well. I had campaigned for months but AV was the thing that got them to finally sign up.
Those are also just fields, and there's incoming laws in countries that target them. No internet for unsupervised women for example. You wouldn't want to break usability for the fine government servants of Afghanistan would you?
“What if instead of a user agent string, HTTP headers contained a string of your DNA, or a count of all the women that’ve ever rejected you for trying to get them to install Gentoo?”. Time to boycott web browsers I guess! even though none of it is mandatory! You’re really asking for someone to condescendingly send you the Wikipedia page for the slippery slope fallacy. I’m not going to be the one to do it, but I came close.
Systemd is doing just that and calling everyone who disagrees with them fascist.
It will be trivial for pedophiles to figure out which accounts aren't tagged as verified adults.
And knowing how these sorts of dynamics work - it'll largely be children in third world countries that will be the primary victims of pedophiles in this manner.
Meanwhile Discourse (the open source forum software) has recently added voice and video calling. Matrix is a good option, also.
At the time I had TOTP based 2FA since forever.
Fine, I got myself a burner number (not sharing a real number with creeps and bullies), account tot unblocked. I kept using it.
A week later I deleted a phone number form my account (marked as optional after all), and the account got immediately, immediately blocked, after I saved the changes.
F** Discord and its ilk.
Fingerprinting, perhaps it is a higher risk, the age range is being more directly provided. However, once a user is under 18 they're already triggering more stringent privacy laws and rules, an inability to enter into contracts, etc, and then when you get to the "over 18" age range it all becomes rather vague.
Also, I highly doubt existing social media and Internet applications haven't already figured out most of their users' ages rather trivially using other means. Discord implicitly admits to this by saying that 90% of their users will not even be asked to verify their age. Discord already knows how old 90% of their users are with high confidence.
Of course when we talk about someone like Google or Discord we are talking about a privately operated service provider and business, which is a separate issue than the OS-level privacy flag and is worth separating as a distinctly different concept. Private businesses were always able to scan your identity documents or face pictures if they wanted to do that as a prerequisite to using their products or services regardless of the law. In almost all states, this practice was never banned, and even in states with more stringent biometrics collection requirements like Illinois you can still do this as long as it's implemented in a legally compliant way.
Go back to 1996 and tell someone that in 30 years the government will be legally able to look at everything they have written, taken pictures of, or recorded in the last 5 years in private and it use to retroactively punish them for any crime.
This is the law for cellphones and computers for anyone who lives within 100 miles of an ocean, border or airport.
The most draconian possible next steps we can imagine are far too Utopian for the world we live in.
It was like 100 lines, a third of it is tests, and another third is a parse_calendar_date function.
What are you talking about, "infrastructure"? How complicated do you think storing a date is?
As soon as it is established that you are not in the process of entering or leaving the country, what you are saying is not true.
E.g., A police officer in your city can't look through the contents of your phone without a warrant at a DUI stop just because you are within 100 miles of a border. The local police or TSA can't stop everyone in the airport and sift through their phones and documents on their person just because they are inside an airport. It must be in the context of a border crossing activity.
What you are saying about the government being legally able to look at everything you have written, taken pictures of, or recorded in the last 5 years in private to retroactively punish you for a crime is also broadly not true. The only thing that has truly changed is that it is far more difficult for average people to avoid leaking information through third parties.
If I take photos in private and keep them on my computer in my house, the government still needs a warrant to access those photos. The difference here is that entities like Meta could voluntarily give the government access to their data without a warrant if they chose to, and they may be more willing to divulge information via subpoenas. Also, a lot of people tend to just post information publicly that's easily accessed.
"Retroactively" punishing you for a crime is also a gross mischaracterization. For one thing, every crime you get punished for is "retroactive" in the sense of the crime having taken place in the past, so your use of the word is meaningless alarmism.
Do you feel like systemd has been collecting your PII since 2020? If so, you have only yourself to blame, since it only stores what the user types in and nothing more. Birth date is exactly the same. Type some nonsense in that field if you like, or leave it blank.
I don't know, I use Open BSD.
The gecos field normally contains comma separated subfields as follows:
name User's full name.
office User's office location.
wphone User's work phone number.
hphone User's home phone number.
I see you support identity verification after all. They're collecting all this personal information! What's next, a felon flag?Maybe one day you'll switch to a freedom respecting OS.