"Since 2022, twenty-five US states covering more than 40% of the US population have adopted laws compelling websites with content “harmful to minors” to verify their users’ ages. Many websites ... rely on third-party services, effectively outsourcing age verification... little is known about how these services are shaping the web and affecting user privacy..."
age verification services can be ineffective in restricting minors, create significant new privacy risks for end users, and are causing the first instance of crossstate balkanization".
Users are being asked to "share sensitive data—photos of their face, government IDs, credit card details... and more... entrusted not only to the contracted provider, but also to several “fourth parties” that are significantly less visible".
The full paper provides the historical and actual context, including how "age verification laws differ by state", leading to balkanisation, and how "states define “harmful content” to mean depiction of nudity and sexual activity ... appeals to “the prurient interest”"
Despite all this law-making, very little is known about:
- the age verification providers, and if/how they protect user privacy
- "how often these laws are obeyed, if they put other burdens on the user, or if sites are ignoring enforcement"
Yoti
They find "one service being used in over 60% of sites detected" - Yoti, which they reverse engineer and analyse:
- it "collects significant private information beyond what is strictly necessary ... relies on sharing sensitive user information with several less user-visible fourth parties"
- Moreover, "it is likely that this data is uniquely identifiable, allowing for unpermissioned tracking of the user’s device."
- They also managed to bypass Yoti's "Secure Image Capture", which uses a webcam image to compare against the ID document's image, so someone can pass themselves off as someone else.
- If the user choose credit-card verification, "Stripe can associate a user’s card details with a visit to an age-restricted website, despite being a fourth party"
- "Yoti’s privacy policies made unclear and somewhat conflicting statements about data retention and maintenance" - which reminds me of WSocial.
Conclusions
Today:
- "Compliance is low— only roughly 14% of sites self-labeling as adult content perform age verification in states with mandates....
- sites that do comply via the dominant provider subject users to significant privacy risks"
- When the US Supreme Court ruled "that online age verification was not a violation of the First Amendment", their underlying assumptions were wrong:
- online age verification is technically surmountable and avoidable, simply by visiting sites which don't use it and which benefit from the additional traffic from sites that do
- "the privacy impact ... is nontrivial... a bartender need not gain universal knowledge of all patrons’ PII [personally identifying information] in an easily copyable and indefinitely retainable format—and share much of this data with various third parties. "
Tomorrow:
- efforts to "standardize age verification as a cryptographic protocol... allows for age verification using anonymous credentials and zero knowledge proofs:
- ... [but] deployment ... is still in its infancy ... [and] these systems may increase the risk of censorship... may allow government entities to revoke internet access for arbitrary citizens by invalidating their real-world ID... age verification suites may eventually control users’ ability to participate in online speech"
- age verification laws could drive revenue away from publishers which observe them, towards publishers which do not