frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Age Verification as Mass Surveillance Infrastructure

https://tboteproject.com/surveillancefindings/
191•rurban•1h ago

Comments

direwolf20•1h ago
Don't confuse the passport ID check with the "are you over 18?" checkbox. Both types of laws exist.
alliao•1h ago
what do governments get out of this? Like I get it from ad/commercial perspective, but I don't see how this is highly unpopular from governments and still being implemented
Noaidi•1h ago
It depends on the type of government. A totalitarian government gets control out of it.
andai•1h ago
The normalization of the nanny state.
Gigachad•1h ago
It’s not highly unpopular. When polled, the Australian public were in favour of banning kids from social media.

The harms of big tech, social media, and addiction mechanics are a lot more tangible to the average person than the anonymity aspect.

elric•1h ago
Age Verification and "banning kids from social media" are two different things. The former being an overzealous method of achieving the latter.

Parental responsibility and better parental controls would be a MUCH better way of going about this.

Of course, the polling public is blissfully unaware of the wide ranging consequences of such an Age Verification implementation. People will continue to pave the road to fascist hell with good intentions.

Gigachad•49m ago
What the public perceives it to be is the only thing that matters though. The OP question was asking how governments are getting this through, and the answer is the majority approve of what they see to be happening.

The average person is not thinking about the ability for journalists and whistleblowers to create anonymous Facebook accounts, they are thinking about Mark Zuckerberg trying to sell sex chatbots to their kids and discord pedo servers.

farfatched•31m ago
> Parental responsibility and better parental controls would be a MUCH better way of going about this.

Call we do all three?

Also, what about the irresponsible parents, or parents who don't have time/opportunity to be responsible over this issue?

gnfargbl•1h ago
Age verification is highly unpopular amongst heavily online users, but the voting population overall is in favour: https://yougov.com/en-gb/daily-results/20250731-91334-2
stingraycharles•1h ago
Seems like even under young voters more people support it than being against it; 30% of people aged 18-23 are strongly in favor, 57% of people in that age group supports it.

I wonder why? Maybe these types of surveys don’t consider the implementation / what you need to give up in order to have age verification?

like_any_other•54m ago
Perhaps the voting population should first be made acutely aware of the extent of surveillance they are under, and how much age verification would expand that surveillance, and then be asked again.

They'll claim they already "know", but watch their opinion change after they get paper mail with a list of recently visited websites, or their words written on public or unencrypted chats, or their movement history thanks to phone spyware.

gnfargbl•43m ago
That's likely, but only if it's possible to materially articulate some specific negative ways in which age verification data is actually being used.

You and I can strongly suspect that there's a significant downside to these providers having so much sensitive personal data but, until that is proven, the voting population will only see the upside.

like_any_other•38m ago
The death of online anonymity isn't negative and specific enough?

People understand this intuitively - hire someone to obviously follow them everywhere, record everything they do (or only as much as current surveillance records), and they'll want to put a quick stop to it. Do the same thing, but out of sight, out of mind, and their correctly evolved instincts fail to carry over.

izacus•48m ago
Yp, similarly how gambling and smoking restrictions aren't popular among gamblers and smokers.
palata•48m ago
Disclaimer: talking about functioning democratic governments (obviously authoritarian governments are different).

We do regulate a lot of things to protect the people, especially the children. It's common to make it illegal for children to drink alcohol, smoke stuff and drive vehicles, and it seems completely natural for many of us. We usually don't say "it should be legal for a schools to sell cigarettes and whisky to kids, because it's the responsibility of the parents to educate their kids".

The same applies to the Internet: just like we don't want children to be able to buy porn in a store, we don't want them to be able to access porn on the Internet. Or, more recently, social media. So the obvious idea to prevent that is to do what we do in store: age verification.

The problem on the Internet is mass surveillance, and done incorrectly, age verification adds to that. Technically, we can do age verification in a privacy-preserving way, but:

- Politicians are generally not competent to understand "the right technical way", and the tech giants do benefit from surveillance. Even if they mean well, it's hard for them to take the right decision out of incompetence.

- In some big countries that tend to set the technical norms (e.g. the US), many people completely distrust the government. But private companies have no interest in implementing the privacy-preserving solution, so the only viable way is with the help of government regulations (I would argue that the government should be the ones owning the service).

- The vast majority of people, including the vast majority of politicians, do not understand and do not give a damn about surveillance capitalism. It just does not exist for them. And in those conditions, there is of course no reason to even consider a privacy-preserving solution, because it is technically more complex.

I strongly believe that in many countries they mean to do well. They are just not competent to understand the problem, and they turn to tech giants who do understand it, but have an interest in making sure that the politicians implement it wrongly.

gausswho•26m ago
In the case of government representatives' role, I think you've reached for Hanlon's razor incorrectly. Malice better explains what is happening here than ignorance. The actual representatives are cardboard with makeup - they each have a whole team of folks doing the detailed diligence on this stuff. That team knows there's a privacy-preserving way to do this. There's a reason those solutions are not the ones on offer. Corporate regulatory capture is behind all of this.
raincole•41m ago
This is highly unpopular... on HN. Which heuristically implies it's popular in the real world.
apples_oranges•1h ago
So to avoid it all I have to do is stop using social media? LGTM
c7b•57m ago
And operating systems...
Noaidi•51m ago
....and email....
musha68k•51m ago
Creeping normalcy into the substrate:

>Stores the user's birth date for age verification, as required by recent laws in California (AB-1043), Colorado (SB26-051), Brazil (Lei 15.211/2025), etc.

[MERGED]

https://www.theregister.com/2026/03/24/foss_age_verification...

As a parent: the hard-won lesson is that most of this threat surface shrinks when you're genuinely present (listen/talk/educate).

p2detar•42m ago
While I agree with you to a very much degree, the last thing teens usually do is listen to their parents. It’s not that simple.
bookofjoe•14m ago
See also: 'Euphoria'
p2detar•1h ago
> Every copy of the Persona SDK contains a hardcoded AES-256-GCM encryption key in TrackingEventUtilsKt.java line 22

Seems like a pretty big fuck up, if so. I wonder why did they not use asymmetric encryption.

tom-blk•57m ago
There have been pushes to implement similar instances of this for a while now. If this turns out to not be successful, expect futher efforts in a similar guise
kungito•57m ago
the internet is not the same as it was 20 years ago. the average person is now online, but they werent before. they dont understand where they are and need protection. there is still space on the internet, or whatever the next place will be, for the enthusiasts and other minorities. if we lose internet, something new will pop up. also, 20 years ago i didnt care so much about privacy on the internet, i just needed a cultural filter for the community im engaging with. privacy has always been a game of cat and mouse. 0 chance things stay the same for long
Findecanor•52m ago
I wonder if not private age verification could not be solved with the right cryptographic protocol.

You would have to register using a digital ID with a government agency, to get a age certificate. Most European countries already have digital IDs, used for all sorts of things: such as taxes, online banking etc.

Then that certificate could be used in some sort of challenge-response protocol with web sites to verify your age, creating a new user ID in each session but without divulging anything that identifies that particular certificate.

I'm afraid that the alternative would be that social media would instead require login with the digital ID directly.

verisimi•44m ago
Always with the increasing government control. Heaven forbid people go online without training wheels. We need safety nets everywhere - a grazed knee means the state failed.
the_real_cher•38m ago
In my opinion public private key is the base of all identification should be done.

You keep your own private key and the government has your public key.

rmnclmnt•31m ago
Agreed. But would mean having to educate people on security, privacy and computing in general… Pretty sure most government like having most people uneducated on such things
the_real_cher•1m ago
I feel like you could do it in an app or a card with an NFC chip.

People don't have to know security or cryptography to do their banking online.

Either way it would be infinitely better than the current social security number situation we have.

kkfx•24m ago
On which hw? Because a smart-card (if open hardware and FLOSS) might be safe, certainly not a smartphone.
JimDabell•30m ago
This is what Verifiable Credentials are for.

https://walt.id/verifiable-credentials

kkfx•25m ago
And what exactly would be the purpose of age verification? Because defining someone "mature" based on their age is pretty hit-and-miss: we have plenty of adults, even of a certain age, who it's hard to imagine have ever finished adolescence, for instance. On paper, they are absolutely of age. We also had a certain Alexander the Great, emperor of a large part of the planet at 20. We had 13-year-old Pharaohs active in government.

We also have gazillions of examples of apparently innocent rules being used to boil Chomsky's frog, one small temperature rise at a time. For the first time in a long while, I'm starting to sense a certain fanaticism on this topic here on HN, which sounds very much like the molecular agitation when water starts to boil.

uniq7•24m ago
In your proposed scheme, it is in the best interest of web sites to store the certificates from users indefinitely, since it's the only evidence they have that prove that their users are not minors.

Since authorities have the power of accessing that data and identify the user who created the certificate, this scheme is not anonymous.

Authorities can access that data via court orders today, or via a global automatic mandatory data sharing law in the future.

In the example of USA, even if for some reason people still trust the current Government (although ICE already accessed private medical records to track and arrest people), I don't see why they should trust all future Governments which will have retroactive access to all that data.

sneak•20m ago
You misunderstand. The child protection angle is just a cover story. The actual reason for this legislation is to ban anonymous publishing; to ensure that every post on the internet can be linked back to an identity for retaliation.

Verified anonymous age credentials don’t allow for this, so they don’t matter.

The negative privacy implications are the primary features of these laws, not a bug. It is intentional.

Xelbair•14m ago
I hate this approach to them problem, because it is not a technical problem.

Because it focuses on technical aspects and accepts the premise of 'age verification must be solved'. It doesn’t, and discretion what content and and what age children and teenagers can consume should be up to parents.

Not government, nor corporations.

chii•10m ago
"but we can't trust the parents to protect the children!"
coffeefirst•11m ago
You don’t need anything this elaborate.

Set parental controls on set up, pass a single flag to websites and apps, similar to the Global Privacy Control.

No privacy is lost. Control is handed to the device owner, and implementation is technically trivial.

progval•50m ago
I wish people would stop sharing this website, their research is massively written by LLMs and looks good at a glance, but it goes in every direction at the same time and lacks logical connections. And the claims don't really match their sources.

Their initial publication was backed by a Git repository with hundreds of pages of documents written in just three days (https://web.archive.org/web/20260314224623/https://tboteproj...). It also contained nonsense like an "anomaly report" with recommendations from the LLM agent to itself, which covers an analysis of contributors to Linux's BPF, Android's Gerrit, and parser errors in using legislative databases. https://web.archive.org/web/20260314103202/https://tboteproj... . The repository was rewritten since, though.

This post follows their usual pattern. The second source they link to has been a dead link for 11 months (https://web.archive.org/web/20250501000000*/https://www.pala...). There's a lot about Persona's design, MCPs, vulnerabilities, data leaks, but nothing proving they use it for mass surveillance. The entire case for it being mass surveillance rests on two points: that they interact with AI companies and they offer MCP endpoints (section titled "Persona's Surveillance Architecture")

caaqil•30m ago
It's currently #1 on the front page too. HN drowning in AI slop, what a sight to behold.
Esophagus4•20m ago
It seems like there are a few stories HN will really bite on:

- age verification

- chat control

- RTO vs. remote work

- AI bubble

- ditching American tech

akdev1l•24m ago
seems a lot of people already consumed this as truth.

In the meantime a FOSS maintainer who is just trying to put the pieces in place to comply with the law (as written) got doxxed and harassed.

I hate it here

cromulent2•18m ago
Thank you. Investigative journalism is so important and I would happily believe some of the claims made here, but when I encounter even just a few sentences that sound LLM-written, suddenly I don't trust any of the statements in the source anymore. This site goes way beyond that, with a vibe-coded UI and generated articles. There might be value in what's reported here, but currently it requires a lot of work from the reader.
shrubble•48m ago
The root password to the Constitution is “ITs4daChildren!”
villgax•41m ago
It’s good that for non SFW stuff you do the need the internet anymore, just 72GB VRAM for all modalities. Public internet only for news/payments. Everything else can be offline, no more npm or React garbage needed either for frontend.
ck2•26m ago
There is a very simple alternative to age verification

WHO IS PROVIDING INTERNET TO A CHILD

they are liable

there's no such thing as free open access internet without someone paying the bill

unless it can be demonstrated the child stole internet somehow, hacking, etc.

then the person providing the internet is liable for the child's activity

Same if you aren't going to supervise your child and they come home for hours after school and watch porn on the TV

They don't age verify to get cable TV

If you have a credit card, you are an adult

Someone is paying the bill, they are the adult, they are responsible

farfatched•6m ago
What if the parent is not responsible?

Should society help the child, by making it more difficult for them to access harmful material, in the same way we age verify alcohol?

What if the parent is responsible, but finds themselves in a situation where they don't have the time/ability to either educate or set up robust controls? Should we make their responsibilities easier?

razodactyl•16m ago
LLM feedback loops are scary because they self-reinforce by training over their own data drift and vulnerable people interface with the noise and follow the downward spiral.

Automated Linux Kernel CVE Detection for the EU CRA (Cyber Resilience Act)

https://hardenedlinux.org/blog/2026-04-06-closing-the-kernel-backport-gap-automated-cve-detection...
1•hardenedlinux•3m ago•0 comments

Migrating RTLS reporting to ClickHouse for 5x faster movement audits

https://navigine.com/blog/navigine-spring-update-2026/
1•SmartDS•4m ago•0 comments

I built as elf healing semantic layer for any AI agent tool

https://github.com/kwstx/engram_translator
2•kwstx•4m ago•1 comments

NASA Shares Photos Shot on iPhone 17 Pro Max During Artemis II Mission

https://www.macrumors.com/2026/04/05/nasa-artemis-ii-photos-shot-on-iphone-17-pro-max/
1•nalekberov•4m ago•0 comments

New Advances Bring the Era of Quantum Computers Closer

https://www.quantamagazine.org/new-advances-bring-the-era-of-quantum-computers-closer-than-ever-2...
1•ibobev•7m ago•0 comments

1SubML: Plan vs. Reality

https://blog.polybdenum.com/2026/04/05/1subml-plan-vs-reality.html
1•ibobev•7m ago•0 comments

Some Subtleties When Parsing 6502 Assembly Language

https://bumbershootsoft.wordpress.com/2026/04/04/some-subtleties-when-parsing-6502-assembly-langu...
1•ibobev•8m ago•0 comments

New library to convert HTML => pdf and dxf (using getBoxQuads for help)

https://github.com/node-projects/layout2vector
1•jogibear9988•9m ago•0 comments

Fooling Go's X.509 Certificate Verification

https://danielmangum.com/posts/fooling-go-x509-certificate-verification/
1•hasheddan•10m ago•0 comments

Ollama and OpenClaw

https://docs.ollama.com/integrations/openclaw
1•zlu•10m ago•0 comments

Former Azure Engineer Alleges Manual Fixes, Firefighting Threaten Reliability

https://windowsnews.ai/article/former-azure-engineer-alleges-manual-fixes-firefighting-culture-th...
1•sylvainkalache•12m ago•0 comments

Ask HN: How do systems (or people) detect when a text is written by an LLM

2•elC0mpa•19m ago•0 comments

ServiceMesh at Scale with William Morgan Creator of Linkerd

https://open.spotify.com/episode/6BbrYeuPftkvJYTZuJfZmm
1•neciudan•24m ago•1 comments

Show HN: Mail Toll – Set a price on your inbox, agents pay USDC to reach you

https://mailtoll.app
1•willgdjones•24m ago•0 comments

Macroeconomic Policy and the Optimal Destruction of Vampires [pdf]

https://irihs.ihs.ac.at/id/eprint/162/1/fo162.pdf
2•AFF87•25m ago•0 comments

Improved the social and emotional system – larkos(neural web)

1•Okerew•28m ago•0 comments

Why Ambiverts Make the Best Leaders

https://www.truity.com/blog/why-ambiverts-make-best-leaders
1•rbanffy•30m ago•0 comments

Linux 7.1 Expected to Begin Removing I486 CPU Suppor

https://www.phoronix.com/news/Linux-7.1-Phasing-Out-i486
2•mariuz•32m ago•0 comments

What if AI just makes us work harder?

https://timharford.com/2026/04/what-if-ai-just-makes-us-work-harder/
5•penguin_booze•37m ago•1 comments

Python: Profiling-Explorer

https://adamj.eu/tech/2026/04/03/python-introducing-profiling-explorer/
1•elashri•37m ago•0 comments

Go 1.25 and 1.26 Compiler Magic – How the Stack Is Eating the Heap

https://programmerscareer.com/go-stack-allocation-optimizations/
3•swq115•38m ago•0 comments

Lichess and Take Take Take Sign Cooperation Agreement

https://lichess.org/@/Lichess/blog/lichess-and-take-take-take-sign-cooperation-agreement/DZS0S0Dy
2•dematz•39m ago•0 comments

Why RAG doesn't work for WhatsApp AI agents and what's the alternative

https://wpp.opero.so/blog/why-rag-fails-for-whatsapp-and-what-we-built-instead
2•juancruzguillen•41m ago•1 comments

Satellite mirror plans could disrupt sleep and ecosystems, scientists say

https://www.theguardian.com/science/2026/apr/05/satellite-mirror-plans-could-disrupt-sleep-and-ec...
1•giuliomagnifico•43m ago•0 comments

Tiny Corp's Exabox

https://twitter.com/__tinygrad__/status/2040944508402360592
7•macleginn•43m ago•0 comments

Upwork Inc. violates its own DMARC and SPF policy

2•tmcdos•44m ago•1 comments

Ice-Out: Retiring IceLen until winter late 2026

https://www.bassfinity.com/blog/ice-out-2026-icelens-seasonal-close
1•jequals5•49m ago•0 comments

SQLite on Git, Part II: Unlocking Zlib's Less Known Feature

https://blog.lysk.tech/sqlite-on-git-part-2/
3•mlysk•49m ago•1 comments

Why Taking over Utilities Won't Deliver Cheap Electricity

https://oilprice.com/Energy/Energy-General/Why-Taking-Over-Utilities-Wont-Deliver-Cheap-Electrici...
1•PaulHoule•50m ago•0 comments

Ansel: Color Controls Finally Correct

https://ansel.photos/en/news/color-controls-finally-correct/
1•aurelienpierre•50m ago•0 comments