Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. GPT-6 Sol and Luna(openai.com)
    491comments
  2. Claude Opus 5.5(anthropic.com)
    710comments
  3. Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived(foxscript.org)
    36comments
  4. LLM Ass Bench(assbench.com)
    26comments
  5. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    346comments
  6. 'We hacked the FBI:' Hackers say they have data on all FBI employees(404media.co)
    142comments
  7. The UV index is not the warm sensation of sunlight on bare skin(asciitweezers.com)
    15comments
  8. SAML: A Fractal of Bad Design(trailofbits.com)
    47comments
  9. Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)(artificialanalysis.ai)
    52comments
  10. WordPress: Unauthenticated path traversal leading to conditional RCE(github.com/wordpress)
    66comments
  11. Native apps written in TypeScript and CSS(github.com/geastack)
    10comments
  12. Unreal Agent(unreallabs.ai)
    53comments
  13. Markdown in /src(htmx.org)
    22comments
  14. An update on how we confirm your age group on Discord(discord.com)
    22comments
  15. OpenAI is well positioned to fast-follow Jev(arcturus-labs.com)
    176comments
  16. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    31comments
  17. Show HN: JevBench, a reproducible benchmark for typed decision models(benchmarkheaven.com)
    5comments
  18. MUNI Heritage Weekend in San Francisco(lawrence.lu)
    32comments
  19. Did OpenAI solve the wrong Navier-Stokes problem?(scientificamerican.com)
    31comments
  20. What California is learning from solar panels built over irrigation canals(kqed.org)
    50comments
  21. Show HN: Training a model to identify AI web content from structure alone(arxiv.org)
    8comments
  22. The Trouble with 'Ntile()'(djnavarro.net)
    discuss
  23. Rabbit Hole: Minimum L-seams(fractalkitty.com)
    5comments
  24. George Lucas Returns to Earth, Bearing Gifts(commonedge.org)
    26comments
  25. 16-bit Intel 8088 chip (c. 1985)(allpoetry.com)
    13comments
  26. Pentagon says overreliance on AI contributed to missile strike on Iran school(bloomberg.com)
    142comments
  27. People hooked on vapes try a new way to quit: cigarettes(bloomberg.com)
    52comments
  28. Apple has added persistent 'ads' to iOS, and it's driving users crazy(techradar.com)
    413comments
  29. There's a high chance of devices being sold with GrapheneOS preinstalled in 2027(grapheneos.social)
    102comments
  30. Launch HN: Coverage Cat (YC S22) – Umbrella insurance via your personal agent(coveragecat.com)
    19comments

An update on how we confirm your age group on Discord

66 pointsby 3h agodiscord.com
22 comments
2h agoHN ↗

I actually like their implementation. I'm curious if it will be enough for governments, but it is nice that they are trying to persue a path without id checks

1h agoHN ↗

They should not be trying to implement it globally. That is unacceptable.

1h agoHN ↗

All the available paths turn into:

- give us your ID

- give us your biometrics

- give somebody, not necessarily Discord, a valid credit card

That's sll of the paths.

1h agoHN ↗

If the account age estimation puts you in adult, it sounds like you don't need to do any of those?

I'd like to see details about their model there, but account age is at least better than a lot of systems like steam are doing for this.

10m agoHN ↗

I think it's interesting they limit the types of content they use to determine your age. I'd guess they don't impose those same limitations when it comes to other uses (including targeted ads)

48m agoHN ↗

This proposed solution does however allow quite liberal access to discord without confirming the age. If the implementation is as worded; then i would not see a reason to confirm my age at all.

The issue comes down to if governments accept such a (urgh) comparatively lax implementation. It's pretty clear to me that the primary purpose of these laws are entirely to... force all citizens to identify themselves across the internet for the purpose of profile building, and nothing to do with child safety.

So as implementations go; this one is pretty decent. We should stop governments from passing these darn laws though.

1h agoHN ↗

Still required to use a video or ID card in the UK.

18m agoHN ↗

A friend of mine, who lives in the UK, says that he's been offered the credit-card verification option.

1h agoHN ↗

I like that the dialog indicates the service provider. Thumbs up for transparency.

1h agoHN ↗

There was a brief window where you could submit fake biometrics through a third-party site to verify age on Discord, pretty sure I got the link from hackernews.

That made me feel better that Discord didn't need to store my ID or video of my face, and was only storing the results of some analysis and not the inputs.

22m agoHN ↗

When the social media ban went into effect in Australia last year, kids were submitting photos of their parents and dogs to get around the verification. Not sure how better or worse they've gotten, but the old adage of trying to keep things from kids only motivates them more to get around the limitations you put up.

For reference: https://www.ndtv.com/world-news/dog-photos-vpns-fake-ids-how...

6m agoHN ↗

... the old adage of trying to keep things from kids only motivates them more to get around the limitations you put up.

This will be a boon for FOSS.

1h agoHN ↗

IRC plus GNU Jami are still freedom respecting zones! I sincerely hope all this age verification crap causes cypherpunk FOSS solutions to grow in popularity.

51m agoHN ↗

Matrix has become invaluable for dozens of my hacker friends. We ditched Discord almost a year ago and we have no desire to go back. Besides having high quality e2ee voice/video/screensharing (thanks LiveKit), we collectively spend 10x less for the functionality and keep our data in Switzerland. No ads, no one getting their accounts hacked with QR codes, ultra-granular space/channel settings, multiple choices for client implementations, and end to end encryption enables sensitive discussions that would have previously been curtailed. The identity verification is greatly appreciated although our new users do have some issues getting set up with multiple devices, but it's no more complicated than multi-device WhatsApp. Matrix is ready for prime time.

7m agoHN ↗

Nice! Last time I used Matrix there was really no voice/video calling. I'll have to check it out again! :D

9m agoHN ↗

Just remember that systemd added age verification in Linux without anyone asking.

There are freedom respecting Linux projects, but those lead by redhat\ibm employees (past and present) don't.

4m agoHN ↗

It can be extricated, or bypassed. The benefits of FOSS are myriad.

24m agoHN ↗

One major controversy I recall with VRchat's implementation of age assurance (via Persona) is that they retained identity of who you were after completing the process. Not who exactly, but your identity was hashed so that if the same person attempted to verify again they could tell who it is. This effectively meant one individual can have one validated account per lifetime. If the flakey AI moderation banned you for an emoji combination freshly deemed racist/etc, you effectively lost your only shot at a validated VRchat account forever.

This is an issue with age assurance that goes well beyond just verifying age, and is undoubtedly viewed as a fringe benefit of age assurance for those wishing to deanonymise the internet. There's obvious problems with this beyond just "can't ban evade anymore". Authorities or intelligence can run bulk hashes against sets of IDs to effectively deanonymise all accounts.

The question here is, does Discord do the same thing for any or all of the selected options? Or is identity data full well and truly purged once the outcome is determined - no hashing, nothing retained other than the result?

9m agoHN ↗

A long time ago, I'd participate in things like CAcert in-person assurance, PGP key-signing, etc.. I think a model like that would've been useful here: An AgeKey issued/signed by two people. I think of it like a decentralized equivalent to someone's parents saying "Yeah, $CHILD is old enough", or to a cashier saying "This person obviously looks old".

3m agoHN ↗

"We're launching this over the course of this week, so it may take a few days to reach your account."

That's obviously not a technical requirement; they're doing this because they expect a large volume of negative publicity, and temporally staggering this rollout means users are less able to coordinate their angry social-media posts.

Same logic Reddit used in phasing out the rollout of their new login wall.