A logo showing an old time reporter with a monitor for a head, working hard at a typewriter. The paper rolls out to form a banner that reads PLATFORMOCRACY NEWS ROUND-UP.

Age restrictions are so hot right now that it’s hard to do a news round-up that doesn’t focus on them. Next week: explaining the AI-will-doom-us-all panic to my father.

In which I propose a middle ground between bans and inaction

Before we ban kids from social media completely, here's what we should try first (Live Science)
I wrote this op-ed with Mariana Olaizola Rosenblat from the NYU Stern Center for Business and Human Rights back in mid-August, before our response to the Meta settlement, but it’s behind a paywall so you probably didn’t see it. I’m quoting it at length here because it helps explain my reaction to the EU proposal (more on this below), and because I’m proud of the piece.

Creating safe online spaces without being overly intrusive is difficult. Human rights law provides a methodology for assessing government actions that restrict individual rights for any legitimate reason: Does the restriction achieve its purpose, or could a lesser restriction work? 

Applied here, a government would have to show that switching off or altering harmful platform features or expanding parental controls would not suffice and that nothing short of removing children from the service would work.

Examining each harm separately suggests the risk lies not in the platforms but in particular design choices. Most of these elements can be altered by the companies or, where necessary, age restricted, without removing young people from these services altogether. 

For features that do require age verification, we need to develop safety systems similar to those in areas like architecture, drug testing and food service. Such infrastructure can be considered "high-stakes," because it is implemented when laypeople cannot directly evaluate a product’s safety themselves and the consequences of failure are severe, such as the collapse of an apartment building. 

We argue that online identity verification matches this pattern; no user can verify whether a vendor or platform properly handles and disposes of the photographs and identity documents required to verify their age, and the consequences of failure — misuse by the platforms or identity theft — are severe and often irreversible.

Products in most high-stakes industries require review before they can be rolled out. Drug trials are extensive and scientifically rigorous, buildings require certified plans and inspections, and restaurants require a health certificate before they can serve a single meal. Age-verification vendors should face similar preapproval inspection, with computer architecture assessments, code reviews and adversarial security testing. Critically, social media companies should pass an equivalent review before deploying age verification.

Age Limits for Social Media Outlined by European Union (New York Times)
Earlier this week, the European Commission (EC) issued a sweeping proposal called the EU KIDS Act, with four pillars:

  1. Social media delay: no accounts for under-13s, parental-supervision accounts for 13 and 14 year olds, and safe-by-design accounts from 15 to 17.

  2. Age assurance: as well as requiring verification for new accounts, everyone, kid or adult, has six months to verify their age in order to keep their existing accounts. 

  3. Safety by design: a set of product goals such as banning addictive features and requiring easy-to-use parental controls.

  4. Enforcement: in a major change, very large platforms (45 million or more EU users) will need prior approval by the Commission before rolling out new services, features, or functionality.

In keeping with Mariana’s and my op-ed, I am glad to see a major government endorse design standards and pre-launch safety reviews. It is frustrating that the EC has the usual blind spot for the safety of age verification itself. Forcing every large platform to verify every account in Europe in only six months would be challenging even if this technology was mature and universally rolled out. Given how new and incomplete it is, the result of this rush is likely to be millions of people left out due to technical issues, and an increased risk of a security disaster.

Fortunately, the EU KIDS Act is a long way from becoming law, and industry and civil liberty groups have already expressed vocal opposition.

The skeptics strike back, plus another gigantic hack

What if social media isn’t hurting kids? (The Verge)
Boston College professor Peter Gray has a new book out this week called Restoring Childhood that challenges the Jonathan Haidt-led moral panic over youth social media. The Vergecast interviewed him. Some key points:

  1. The most reliable statistic to track teen mental health over decades is the suicide rate, which since 2010 has risen much more in the US than other countries, despite comparable adoption of social media. What Gray says was unique in the US was imposing the Common Core curriculum on students, especially since teens have always identified school/academics as their leading cause of anxiety and stress.

  2. While you can cherry-pick small studies and anecdotal stories of kids harmed by social media, all of the large-scale social science research says there is no statistically-significant effect for good or ill. If anything, the data suggests that rather than social media causing anxiety or depression, young people who already have these problems may be turning to social media more than their peers.

  3. In fact, there is data that the advent of the Internet in the 1990s and 2000s was positive for teen mental health, since it gave them freedom and connection that they lost due to more restrictive parenting and less free-roaming play.

Gray’s argument fits my own biases better than Haidt’s. My kids have an insane amount of homework, which came close to breaking my older son in his junior year of high school. And they have both gotten a lot of joy from playing video games online with their friends. Of course, as Gray points out, anecdote is not evidence. The important point is that Haidt’s confidence doesn’t necessarily make him right. We need to hear from more experts like Gray before we roll out an invasive global age-verification regime.

What I Learned Building Age Verification for a Platform With a Billion Users
Kyle Huscher, a former TikTok product manager, points out that even the most privacy-sensitive age verification will exclude many populations, such as undocumented immigrants, older adults without a compatible device, trans people whose IDs might not match their transition yet, and domestic violence survivors who may have good reasons to not want to tie their identity to an account in any way. He suggests that a privacy-safe way to verify ages could be physiological signals like heart rate (see his startup notmypii).

FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security)
A major real-world ID card verification service that you’ve certainly never heard of, idscan.net, was hacked, leading to over 150 million drivers licenses showing up for sale on the dark web. IDscan had no idea this was happening, and it took them three days after the news report to publicly confirm it. Two weeks later, they are still in business and have not issued a follow-up statement about how they are going to secure their systems. If this doesn’t convince you that we need higher standards and comprehensive reviews of any company who wants to handle your identity online, I am not sure what will.

Ideas? Feedback? Criticism? I want to hear it, because I am sure that I am going to get a lot of things wrong along the way. I will share what I learn with the community as we go. Reach out any time at [email protected].