Age verification mean end of anonymous account

today I created a burner google account. these days google requires an Android phone in order to even create an account so I used an old phone to scan the QR code ( I am pretty sure this lets google grab all of the metadata of the mobile phone ). after about 1 hour creating the account. google's automated system disabled the account however I appealed and got the account back. before someone asks I need google because of where I live.

this made me wonder what if google mandates age verification? if there were age verification google would immediately notice that I am creating another account ( burner account ) which it won't like. burner account won't be created in the first place!

we already have too much surveillance and this makes it worse. my mobile number is already tied to my read government identity. I DO NOT want my online account to be tied to my read identify too! it is sad, it really is

66 points · 36 comments · view on lemmy.world

36 Comments

vk6flab@lemmy.radio · 11 pts · 11h
state_electrician@discuss.tchncs.de · 10 pts · 13h (17 replies)

The EU is building the EUDI wallet (or rather requiring each member state to provide a solution) and it will be possible to prove your age with that without disclosing details about your identity. And it's even possible to do this on your device, so the state won't know who you're proving your age to. Just saying that there are ways to do it right. It's just a matter of whether everybody wants that.

schnurrito@discuss.tchncs.de · 23 pts · 12h (7 replies)

Just saying that there are ways to do it right.

No, there is no way to do "censoring access to information for young people" right. That remains an entirely illegitimate goal no matter which mechanisms you invent for doing it in a privacy preserving manner.

HelloRoot@lemy.lol · -5 pts · 11h (6 replies)

Using the neutral term "information" here is doing a lot of heavy lifting for your argument.

Nobody is banning the youth from accessing wikipedia or a library or minecraft.

And if a young person really wants to watch at porn, torrenting/piracy will always be there without age verification.

Speaking of minecraft and circumvention, do you remember the uncensored library map? https://www.techdirt.com/2020/03/19/routing-around-damage-censored-reporting-hosted-custom-built-minecraft-library/

I bet someone inclined to do so could host a pornhub mirror/proxy inside of a modded minecraft map.

But also, if the parents decide that it's part of growing up they can just give their kids access to porn.

Oh uuuh I mean, not porn, iNfOrMaTiOn.

schnurrito@discuss.tchncs.de · 11 pts · 11h (5 replies)

Nobody is banning the youth from accessing wikipedia or a library or minecraft.

Wikipedia has pornographic images and videos in it (certainly in its media archive, Wikimedia Commons, and some of them are embedded in articles).

Library: ??? Are we still talking about the Internet?

But also, if the parents decide that it’s part of growing up they can just give their kids access to porn.

Yes. Giving kids access to the open Internet is giving them access to a repository of nearly all human knowledge and endeavors, including (but not limited to) porn. If parents believe their child isn't yet developmentally ready to be exposed to all human knowledge and endeavors, they shouldn't be giving that child (unsupervised) access to a worldwide information system whose entire purpose is to provide access to exactly that.

HelloRoot@lemy.lol · -3 pts · 11h (4 replies)

You keep speaking in extremes and absolutes. There is also pornographic content walking outside on the street in the city if you so wish to classify it (and some people certainly do to they point where they get turned on by seing a bare ankle).

Certainly the pictures and videos on wikipedia which you chose to consider pornographic rather than neutrally informative have a different set of qualities then what you would find in the extreme sections of porn-serving websites.

There is a middle ground. You can give partial access. And age verification is one more tool for that (we already have parental controls for routers and mobile internet simcards and smart devices)

I don't like nor want age verification btw. I just don't agree with your arguments against it, because I find them weak.

schnurrito@discuss.tchncs.de · 5 pts · 10h (1 reply)

Certainly the pictures and videos on wikipedia which you chose to consider pornographic rather than neutrally informative have a different set of qualities then what you would find in the extreme sections of porn-serving websites.

Look into the Wikimedia Commons category "pornographic videos" and you'll see what I'm talking about. Not linking to it because I'm not sure I'm allowed to do that here.

There is a middle ground. You can give partial access.

Hence why I wrote specifically about the open Internet. You are right: there are ways to give people access to only a selected part of the Internet. If parents decide to do that, fine; doesn't have to concern any website operators, or any adults.

HelloRoot@lemy.lol · 1 pts · 8h

Hence why I wrote specifically about the open Internet. You are right: there are ways to give people access to only a selected part of the Internet. If parents decide to do that, fine; doesn’t have to concern any website operators, or any adults.

Like I said, I agree. But your initial argument is no good. You toss everything into one box to make your claim appear stronger but in doing so you actually make it dismissable. Stay differentiated.

LupertEverett@lemmy.world · 1 pts · 3h (1 reply)

You keep speaking in extremes and absolutes

YOU are the one that immediately jumped to porn, shithead. You DON'T get to decide on talking about extremes and absolutes.

HelloRoot@lemy.lol · 1 pts · 1h

I didn't jump to it. It's the primary reason for age verification.

Calling it "information" to avoid talking about it is intellectually disingenuous.

stoy@lemmy.zip · 10 pts · 11h (3 replies)

Nope, it won't be anonymous.

Look, any kind of digital age verification must be connected in some way to an actual identity.

If you are running a community operating under EU laws to require age verification, then a simple true/false statement won't cut it.

You will be required to log a personal ID number of the user, signed by the digital wallet issuer, that is the only way to guarantee that a specific person was verified to be of age.

You as an admin of the community might not know the identity of the users, but the government can tie the account back to you.

ISOmorph@feddit.org · 1 pts · 7h (2 replies)

The EUDI wallet is advertising that it can prove your ID on device and just send a "is over 18" confirmation. So at least in theory, the wallet should provide verification without giving your ID to whatever service you want to use. I do doubt however, that ot will work that smoothly and securely in practice

mnemonicmonkeys@sh.itjust.works · 2 pts · 5h

The EUDI wallet is advertising

ADVERTISING. Don't treat marketing as truth

So at least in theory

No, there's no theory here. Just lies.

As Louis Rossmann once said: Dont accept the premise of assholes. Don't repeat their lies for them.

DeadBedroom@fedinsfw.app · 1 pts · 25m

Good thing their app requires Google Services making lineageOS and eOS unable to run it (no desktop app either)

hirihit640@sh.itjust.works · 7 pts · 6h (3 replies)

Zero-Knowledge Proofs Aren’t Age Verification Silver Bullets

The idea behind ZKPs is that you are issued a “token” that vouches for your age every time you log in, creating a constant link back to the entity that verified you. The issuer of the tokens these AV schemes rely on could track every time that credential is used, creating a dangerous trail of metadata on any user they wanted to target. The issuer itself could be pressured by authoritarian governments to remove a user's access to a service, essentially removing that person’s access to the internet entirely.

a centralized identity verification system creates a single point of failure that is extremely vulnerable to both cyberattack and authoritarian overreach.

Personally I'm optimistic that tech like this can be used in positive ways, but imo they should be developed transparently (open source) and decentralized.

ryannathans@aussie.zone · 1 pts · 3h

How could the issuer track when a credential is used? Isn't the whole point that the issuer isn't needed for verification of the ZKP?

state_electrician@discuss.tchncs.de · 0 pts · 3h (1 reply)

In that argument the issuer is a private entity. In my argument the issuer is my country itself and they're not involved in the proof, because it happens on my device. The EUDI wallet, at least in theory, will be trusted, because it is signed by an EU member state. And it runs on my device, so the state doesn't know what I use it for. Just like a physical ID.

jumping_redditor@sh.itjust.works · 0 pts · 2h

the country is not trustworthy

NaibofTabr@infosec.pub · 5 pts · 10h

Storing identification information on an internet-connected system will never be safe for the people whose information is collected there. Such databases are high-value targets. They always get attacked, and the information stolen. This cannot be done safely.

Davel23@fedia.io · 6 pts · 12h (3 replies)

I am pretty sure this lets google grab all of the metadata of the mobile phone

Android is a Google product. They have full control over it. They can "grab all the metadata of the mobile phone" (whatever that means) any time they like.

bruh@nord.pub · 2 pts · 12h (2 replies)

yes, but in this case that metadata is now attached to the newly created burner account. and if you use your personal android device then google knows that it's your burner account.

HelloRoot@lemy.lol · 5 pts · 11h

Do you know what de-anonymization online can do?

Exactly, de-anonymize you, based on your behaviour patterns collected over years and decades and any data they can lay their hands on. It doesn't matter if you switch accounts or phones or both every week or even type of device.

If every one of your new accounts/devices is at the same place, is awake at the same time, uses the same apps, has the same typing rhythm, browses the same websites at the same time of day and logs in with the same accounts and sings the pokemon theme song in the shower every morning and walks in the park twice a day with dog barking and "good boi" sounds happening in closest proximity to the tracking device you carry in your pocket - they'll be pretty sure it's the same person.

Wasn't there a scandal just last week about Samsung smart tv's recoding audio nonstop and sending it to their servers, even when they are "turned off"?

And even if you are a hermit that cut off all their devices and access to the internet altogether, other peoples devices will collect data about you, enumerate you as a seperate entity from the device holder and keep collecting and patternmatching.

baahb@lemmy.dbzer0.com · 1 pts · 12h

You make it sound like google did this specific thing on accident.

aarch0x40@piefed.social · 4 pts · 13h (4 replies)

Why use Google or any of the big US tech firms for burner accounts then?

bruh@nord.pub · 3 pts · 12h (3 replies)

because of where I live. people find it suspicious not having google account.

aarch0x40@piefed.social · 4 pts · 10h (2 replies)

Now that’s suspicious as hell

bruh@nord.pub · 1 pts · 3h (1 reply)

wdym? can you elaborate please?

aarch0x40@piefed.social · 1 pts · 1h

A person does not own a Google account. A Google account owns a person. This is the reason behind identity verification. They use that information to track and profile a person both online and in the real world. If it's more suspect to use privacy focused providers then I'd be concerned how that became normal. Google is both using that data and feeding it to whoever will pay for it (for example, your government). I've attended private Google product demos that have focused on these capabilities.

lmaowat@lemmy.wtf · 2 pts · 23m

Wait, I have to set up burner accounts all the time for Red Team engagements and you can usually get a google account with SMS verification only. Are you sure you're doing it correctly? are you doing it from Tor or a VPN or an internet café?

Why would your country matter in the process for an internet account if you can use an IP from virtually anywhere?

All these tiny details matter for your OpSec, and every choice also affects how hard you trigger abuse prevention mechanisms from service providers.

Details aside, yes it is getting harder and its insane that you need actual professional skills to maintain privacy, where it should be the default.

Educate yourself and your loved ones on surveillance self-defense: https://ssd.eff.org/

Also, lmao at expecting privacy from anything Google.

Tollana1234567@lemmy.today · 2 pts · 2h

google started limited the accounts created, allegedly to combat botting/spamming, and from AI SCRAPing. they have a deal for Reddits data to AI scrape, i think google is helping them out trying to force genuine users content, it pretty much conincides with reddits forced login. because botters and spammers create hundreds of google accounts to verify with reddit(as trustworthy to keep it from getting shadowbanned)

Successful_Try543@feddit.org · -2 pts · 13h (5 replies)

It depends on how AV is implemented. Google can either ask for your ID card, that would be inherently non-anonymous and prevent you from creating a burner account, if they would store the information of your id card – which of course Google would never do (/s). The other option would be a third party would check your ID an provide Google only with the information that the request is done by somebody of legal age.

Godort@lemmy.ca · 9 pts · 13h (1 reply)

The other option would be a third party would check your ID an provide Google only with the information that the request is done by somebody of legal age.

You're just shifting the problem down the chain. There is no guarantee that this third party would be any more trustworthy than Google. They could even be less trustworthy, in fact.

NaibofTabr@infosec.pub · 4 pts · 10h (2 replies)

There is no safe way to aggregate such identity information in an internet-connected database. They always get breached. Discord tried to do this and all the collected IDs got stolen almost immediately.

https://arstechnica.com/tech-policy/2026/02/discord-faces-backlash-over-age-checks-after-data-breach-exposed-70000-ids/

No party can be trusted to store identification information safely.

Successful_Try543@feddit.org · 1 pts · 3h (1 reply)

The idea is that they don't store it at all.

NaibofTabr@infosec.pub · 1 pts · 26m

"They" who? If the party checking the IDs does not store the information, then they must be cross-checking them against a reference database, which must be online somewhere.