Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. GPT-6 Sol and Luna(openai.com)
    614comments
  2. Claude Opus 5.5(anthropic.com)
    820comments
  3. 'We hacked the FBI:' Hackers say they have data on all FBI employees(404media.co)
    292comments
  4. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    361comments
  5. ReBarUEFI: Resizable BAR for almost any UEFI system(github.com/xcuri0)
    21comments
  6. Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived(foxscript.org)
    132comments
  7. What California is learning from solar panels built over irrigation canals(kqed.org)
    159comments
  8. SAML: A fractal of bad design(trailofbits.com)
    91comments
  9. Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)(artificialanalysis.ai)
    72comments
  10. WordPress: Unauthenticated path traversal leading to conditional RCE(github.com/wordpress)
    84comments
  11. Pentagon says overreliance on AI contributed to missile strike on Iran school(bloomberg.com)
    226comments
  12. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    83comments
  13. The current balance of power in open models(interconnects.ai)
    13comments
  14. Side-stepping the Secretary Problem, unwittingly(evalapply.org)
    6comments
  15. MUNI Heritage Weekend in San Francisco(lawrence.lu)
    42comments
  16. OpenAI is well positioned to fast-follow Jev(arcturus-labs.com)
    195comments
  17. Unreal Agent(unreallabs.ai)
    82comments
  18. Show HN: JevBench, a reproducible benchmark for typed decision models(benchmarkheaven.com)
    17comments
  19. Native apps written in TypeScript and CSS(github.com/geastack)
    27comments
  20. People hooked on vapes try a new way to quit: cigarettes(bloomberg.com)
    109comments
  21. George Lucas Returns to Earth, Bearing Gifts(commonedge.org)
    45comments
  22. Obscura: VPN that can't log your activity(obscura.com)
    75comments
  23. Markdown in /src(htmx.org)
    47comments
  24. The UV index is not the warm sensation of sunlight on bare skin(asciitweezers.com)
    58comments
  25. Apple has added persistent 'ads' to iOS, and it's driving users crazy(techradar.com)
    461comments
  26. Augustofaces: Pareidolia Fine Art(augusto.at)
    discuss
  27. 16-bit Intel 8088 chip (c. 1985)(allpoetry.com)
    14comments
  28. Can gzip be a language model?(nathan.rs)
    146comments
  29. Show HN: Training a model to identify AI web content from structure alone(arxiv.org)
    9comments
  30. The JavaScript Midlife Crisis(maroun-baydoun.com)
    28comments

An update on how we confirm your age group on Discord

106 pointsby 8h agodiscord.com
74 comments
6h agoHN ↗

I actually like their implementation. I'm curious if it will be enough for governments, but it is nice that they are trying to persue a path without id checks

5h agoHN ↗

They should not be trying to implement it globally. That is unacceptable.

5h agoHN ↗

All the available paths turn into:

- give us your ID

- give us your biometrics

- give somebody, not necessarily Discord, a valid credit card

That's sll of the paths.

5h agoHN ↗

If the account age estimation puts you in adult, it sounds like you don't need to do any of those?

I'd like to see details about their model there, but account age is at least better than a lot of systems like steam are doing for this.

4h agoHN ↗

I think it's interesting they limit the types of content they use to determine your age. I'd guess they don't impose those same limitations when it comes to other uses (including targeted ads)

4h agoHN ↗

This proposed solution does however allow quite liberal access to discord without confirming the age. If the implementation is as worded; then i would not see a reason to confirm my age at all.

The issue comes down to if governments accept such a (urgh) comparatively lax implementation. It's pretty clear to me that the primary purpose of these laws are entirely to... force all citizens to identify themselves across the internet for the purpose of profile building, and nothing to do with child safety.

So as implementations go; this one is pretty decent. We should stop governments from passing these darn laws though.

3h agoHN ↗

I can imagine a few more. Here's one that is 100% effective:

* Wait until your account was created > 18 years ago.

That may not be enough for you, and that's fine, this is not a governmental service or site, with a mandate to serve everyone. You can chose not to use discord, and discord can choose not to have you as a customer. YMMV.

5h agoHN ↗

Still required to use a video or ID card in the UK.

4h agoHN ↗

A friend of mine, who lives in the UK, says that he's been offered the credit-card verification option.

5h agoHN ↗

I like that the dialog indicates the service provider. Thumbs up for transparency.

5h agoHN ↗

There was a brief window where you could submit fake biometrics through a third-party site to verify age on Discord, pretty sure I got the link from hackernews.

That made me feel better that Discord didn't need to store my ID or video of my face, and was only storing the results of some analysis and not the inputs.

4h agoHN ↗

When the social media ban went into effect in Australia last year, kids were submitting photos of their parents and dogs to get around the verification. Not sure how better or worse they've gotten, but the old adage of trying to keep things from kids only motivates them more to get around the limitations you put up.

For reference: https://www.ndtv.com/world-news/dog-photos-vpns-fake-ids-how...

4h agoHN ↗

... the old adage of trying to keep things from kids only motivates them more to get around the limitations you put up.

This will be a boon for FOSS.

2h agoHN ↗

Yep, still waiting to see if they disqualify those old determinations.

5h agoHN ↗

IRC plus GNU Jami are still freedom respecting zones! I sincerely hope all this age verification crap causes cypherpunk FOSS solutions to grow in popularity.

4h agoHN ↗

Matrix has become invaluable for dozens of my hacker friends. We ditched Discord almost a year ago and we have no desire to go back. Besides having high quality e2ee voice/video/screensharing (thanks LiveKit), we collectively spend 10x less for the functionality and keep our data in Switzerland. No ads, no one getting their accounts hacked with QR codes, ultra-granular space/channel settings, multiple choices for client implementations, and end to end encryption enables sensitive discussions that would have previously been curtailed. The identity verification is greatly appreciated although our new users do have some issues getting set up with multiple devices, but it's no more complicated than multi-device WhatsApp. Matrix is ready for prime time.

4h agoHN ↗

Nice! Last time I used Matrix there was really no voice/video calling. I'll have to check it out again! :D

4h agoHN ↗

Just remember that systemd added age verification in Linux without anyone asking.

There are freedom respecting Linux projects, but those lead by redhat\ibm employees (past and present) don't.

4h agoHN ↗

It can be extricated, or bypassed. The benefits of FOSS are myriad.

3h agoHN ↗

Its just a system that optionally exposes a birthday read from a json db. You don't have to use it, and you don't have to use applications that rely on it. And if you are going to use applications that have an age verification, this is a pretty serviceable standard.

I don't understand the uproar. Systemd isn't perfect but it gets so much hate for the value it provides

3h agoHN ↗

Why doesn't it do the same for sex, gender, religion, race, sexuality, felon etc.?

Those are also just fields, and there's incoming laws in countries that target them. No internet for unsupervised women for example. You wouldn't want to break usability for the fine government servants of Afghanistan would you?

1h agoHN ↗

You can make any argument you want if you completely change what we are talking about.

“What if instead of a user agent string, HTTP headers contained a string of your DNA, or a count of all the women that’ve ever rejected you for trying to get them to install Gentoo?”. Time to boycott web browsers I guess! even though none of it is mandatory! You’re really asking for someone to condescendingly send you the Wikipedia page for the slippery slope fallacy. I’m not going to be the one to do it, but I came close.

1h agoHN ↗

If we could add arbitrary fields to HTTP headers and the IETF started adding PII to every request then worrying about what other fields they will add is a valid.

Systemd is doing just that and calling everyone who disagrees with them fascist.

43m agoHN ↗

If you care about privacy, the user struct has had a real_name field since (at least) 2020: https://github.com/dylanmtaylor/systemd/blob/7a858878a03966d...

Do you feel like systemd has been collecting your PII since 2020? If so, you have only yourself to blame, since it only stores what the user types in and nothing more. Birth date is exactly the same. Type some nonsense in that field if you like, or leave it blank.

3m agoHN ↗

Do you feel like systemd has been collecting your PII since 2020?

I don't know, I use Open BSD.

3h agoHN ↗

The age verification API in operating systems is a really good idea for privacy and parental control, so long as it doesn’t require literally collecting your ID (it doesn’t).

Look at it from the perspective of a parent giving a device to a kid. Before, you’d have to deal with a maze of blocking content. You’d have to allow/blocklist a huge number of apps and services manually. If your kid discovers some new one you or your blocking service has never heard of, they’ve gotten around your parental control wishes.

With the age verification API, you just set the age in the OS (and lock it down with MDM or whatever) and now all the apps and websites have to respect it and act accordingly.

Your kid can’t just make a new account or download another browser or do some other crazy workaround to get around your restrictions. That setting is there at the OS level.

2h agoHN ↗

A child mode flag is fine. But a birthdate is a recipe for data collection and fingerprinting. And with Google, we're seeing a full verification requirement flag that means people have to scan identity documents or face pictures. It's a slippery slope.

1h agoHN ↗

The OS (I'll use systemd as an example) knows the birth date to determine whether or not you fall within an age range, but the applications are not offered the exact birth date by the API.

Fingerprinting, perhaps it is a higher risk, the age range is being more directly provided. However, once a user is under 18 they're already triggering more stringent privacy laws and rules, an inability to enter into contracts, etc, and then when you get to the "over 18" age range it all becomes rather vague.

Also, I highly doubt existing social media and Internet applications haven't already figured out most of their users' ages rather trivially using other means. Discord implicitly admits to this by saying that 90% of their users will not even be asked to verify their age. Discord already knows how old 90% of their users are with high confidence.

Of course when we talk about someone like Google or Discord we are talking about a privately operated service provider and business, which is a separate issue than the OS-level privacy flag and is worth separating as a distinctly different concept. Private businesses were always able to scan your identity documents or face pictures if they wanted to do that as a prerequisite to using their products or services regardless of the law. In almost all states, this practice was never banned, and even in states with more stringent biometrics collection requirements like Illinois you can still do this as long as it's implemented in a legally compliant way.

1h agoHN ↗

That's great. Now that you have all the infrastructure in place the next request by the government will be a felon flag. You already have everything there, what's the big deal?

1h agoHN ↗

Certainly we can take almost any topic through to the most extreme possible next steps and arrive at a draconian place, but I don't find that exercise realistic or productive.

1h agoHN ↗

but I don't find that realistic or productive.

Go back to 1996 and tell someone that in 30 years the government will be legally able to look at everything they have written, taken pictures of, or recorded in the last 5 years in private and it use to retroactively punish them for any crime.

This is the law for cellphones and computers for anyone who lives within 100 miles of an ocean, border or airport.

The most draconian possible next steps we can imagine are far too Utopian for the world we live in.

55m agoHN ↗

This "100 miles from the border" issue is really commonly misinterpreted. This does not mean that privacy laws and the 4th amendment aren't in place within 100 miles of an ocean, border, or airport. This exception is only in the scope of border activities like entering or leaving the country.

As soon as it is established that you are not in the process of entering or leaving the country, what you are saying is not true.

E.g., A police officer in your city can't look through the contents of your phone without a warrant at a DUI stop just because you are within 100 miles of a border. The local police or TSA can't stop everyone in the airport and sift through their phones and documents on their person just because they are inside an airport. It must be in the context of a border crossing activity.

What you are saying about the government being legally able to look at everything you have written, taken pictures of, or recorded in the last 5 years in private to retroactively punish you for a crime is also broadly not true. The only thing that has truly changed is that it is far more difficult for average people to avoid leaking information through third parties.

If I take photos in private and keep them on my computer in my house, the government still needs a warrant to access those photos. The difference here is that entities like Meta could voluntarily give the government access to their data without a warrant if they chose to, and they may be more willing to divulge information via subpoenas. Also, a lot of people tend to just post information publicly that's easily accessed.

"Retroactively" punishing you for a crime is also a gross mischaracterization. For one thing, every crime you get punished for is "retroactive" in the sense of the crime having taken place in the past, so your use of the word is meaningless alarmism.

2h agoHN ↗

It’s systemd. They seem to be making it their mission to windows-ify Linux anyways.

1h agoHN ↗

…No they didn’t. It wasn’t verification. It was essentially a new setting. Stop fear mongering.

4h agoHN ↗

It won't. Most people don't care about privacy or FOSS. I've been trying to get my friends to switch to something else for years, and they couldn't care less.

ID verification is the least of my worries, to be honest. I've been on the internet long enough to acknowledge a need for something like that. I'm uncomfortable with the fact that data is a valuable commodity now. Discord is storing my online habits and conversations somewhere on their servers. Deleting that information is deleting money.

If people weren't worried about that before, then they certainly won't care now.

3h agoHN ↗

You're quite wrong in your assumptions. Most Discord users are moving away from the platform. Fluxer is gaining traction very quickly.

3h agoHN ↗

I would put money down that 50% of discord users are not moving away from the platform and won't before the end of the year. And if I'm wrong I happily get to move to a new platform so it's a win win bet :v

3h agoHN ↗

Most Discord users are moving away from the platform

I dread the day I'll make claims like this, even figuratively.

Even at a most surface level reading, this would suggest something like their MAU (monthly active users) at least halving soon/already.

I'd be very surprised if it was trending down even, let alone at this! Forget hyperbole, this is an outright überbole.

By all means though, got any data?

4h agoHN ↗

One major controversy I recall with VRchat's implementation of age assurance (via Persona) is that they retained identity of who you were after completing the process. Not who exactly, but your identity was hashed so that if the same person attempted to verify again they could tell who it is. This effectively meant one individual can have one validated account per lifetime. If the flakey AI moderation banned you for an emoji combination freshly deemed racist/etc, you effectively lost your only shot at a validated VRchat account forever.

This is an issue with age assurance that goes well beyond just verifying age, and is undoubtedly viewed as a fringe benefit of age assurance for those wishing to deanonymise the internet. There's obvious problems with this beyond just "can't ban evade anymore". Authorities or intelligence can run bulk hashes against sets of IDs to effectively deanonymise all accounts.

The question here is, does Discord do the same thing for any or all of the selected options? Or is identity data full well and truly purged once the outcome is determined - no hashing, nothing retained other than the result?

3h agoHN ↗

The question here is, does Discord do the same thing for any or all of the selected options? Or is identity data full well and truly purged once the outcome is determined - no hashing, nothing retained other than the result?

What they actually do is irrelevant since none of these companies should ever be trusted to do what they claim they will do.

3h agoHN ↗

Discord offers age verification via AgeKey [1]. Reading their privacy policy, one can create multiple AgeKeys based on the same identification or face scan. Each AgeKey is stored as a passkey and not persisted anywhere else. The privacy policy indicates that the identification information is submitted to 3rd party providers, and also appears to be used for general internet company marketing and promotions, similarly invasive to buying a pair of shoes online. That is, your identity will be propagated to ad networks by AgeKey as it similarly does for ecommerce.

Discord cannot determine identity from the AgeKey.

1. https://agekey.org/

52m agoHN ↗

Given Persona is involved (and thus also Thiel and Palantir) expect everything to be store for ever, sold for profit and misused agains you in the worst way possible.

4h agoHN ↗

A long time ago, I'd participate in things like CAcert in-person assurance, PGP key-signing, etc.. I think a model like that would've been useful here: An AgeKey issued/signed by two people. I think of it like a decentralized equivalent to someone's parents saying "Yeah, $CHILD is old enough", or to a cashier saying "This person obviously looks old".

4h agoHN ↗

"We're launching this over the course of this week, so it may take a few days to reach your account."

That's obviously not a technical requirement; they're doing this because they expect a large volume of negative publicity, and temporally staggering this rollout means users are less able to coordinate their social-media outrage.

Same logic Reddit used in phasing out the rollout of their controversial login wall. One group says "I can't log in!"; the other says, "huh, it works for me?"

2h agoHN ↗

They will also likely dial up the sensitivity of the system over time. Maybe initially 90% of users are let through without doxxing themselves, like Discord claims. But over time, they have the knob to turn up the sensitivity to get more verifications so eventually everyone is verified. They love to exploit the network effect of making people think they're missing out while all their friends are in, exact same strategy they've used for years with the sudden demand for phone numbers on good standing accounts.

1h agoHN ↗

What? No. It’s just one week. If anything it’d prolong the outrage. Gradual rollouts are what responsible development teams do. When did this stop being Hacker News?

4h agoHN ↗

Unacceptable.

There is no legitimate reason to impose age verification on users in jurisdictions that do not legally mandate it.

It is a risk to the privacy and safety of all users on the platform - it provides an easier way for pedophiles to identify underage users and provides more doxable information.

Discord has no business making this decision on behalf of jurisdictions that do not legally mandate it.

3h agoHN ↗

it provides an easier way for pedophiles to identify underage users and provides more doxable information.

Do you have any basis for assuming that that users who are under 18 will have that information revealed to other users? That’s not what I read in this article.

I also think you’re being quite prescriptive about a private commercial service. You’re entitled to your opinion, of course, but companies enact restrictions to their products and services not required by law all the time.

If Discord wants to make their service require a mandatory declaration of allegiance to the Klingon empire, they’re allowed to do that.

3h agoHN ↗

You don't have to be a user to be a pedophile. Could be a developer too, seeking the attestation for users to target.

2h agoHN ↗

It’s actually trivially easy to detect if someone isn’t verified adult: If you DM them something normal it’ll go through, but if you try to send them any image marked as spoiler it’ll show you an error, and they don’t see anything.

So yes, it’s super easy for groomers to focus on children with this update.

23m agoHN ↗

This is the type of issue I was referring to, yes.

It will be trivial for pedophiles to figure out which accounts aren't tagged as verified adults.

And knowing how these sorts of dynamics work - it'll largely be children in third world countries that will be the primary victims of pedophiles in this manner.

3h agoHN ↗

I totally agree. At the same time, nobody should be using Discord anyway, for a variety of reasons. They're one of the least trustworthy online platforms I can think of, and have unfortunately encouraged online ecosystems where you have to "Join our Discord" in order to maybe be heard. I would be delighted if age verification encourage more people to abandon Discord. In a better world, companies like that wouldn't be allowed to become zombie corporations but instead be forced to go out of business.

3h agoHN ↗

What's untrustworthy about them? I enjoy using Discord, so I should probably learn about that.

3h agoHN ↗

They require a phone number for creating an account. That right here is a never use in my book.

3h agoHN ↗

They'll shut down servers and close your account with no reason provided outside of demanding you add a phone number. It's happened to me a few times, and I was squeaky clean on there even when compared to the way I talk on HN. Didn't matter whether I provided a phone number. I'm not the only one it's happened to. Anyone with friends on Discord should make sure to write down their contact information in case Discord one day decides that they or their community doesn't exist anymore. But do they delete your data? No, of course they don't... they keep it all to themselves!

2h agoHN ↗

THIS. Nearly lost several large owned 'servers' on the account, too, due to the phone number demands! Support was awful, making needless month long hoops and ultimately not helping me at all.

Meanwhile Discourse (the open source forum software) has recently added voice and video calling. Matrix is a good option, also.

56m agoHN ↗

Not to mention it is a total silo that is not indexed by search engines and protected by archive.org - one day when Discords VC money finally runs out, it could all vanish in an instant, destroying communities and a lot of culture.

3h agoHN ↗

Well, there's a lot more low-hanging fruit there to be had.

It was sadly too trivial using various Discord search engines to find things like BDSM servers advertising to "14-28 year olds", or ones where minors openly sell NSFW content.

Discord as a whole is oftentimes enabling the communities to prey on those users, not just making the users more identifiable.

3h agoHN ↗

i dont like it, but.... its their platform. Dont like it, dont use it.

I think i'm going to run down the dont use it path, which is a shame, because i do use it atm.

2h agoHN ↗

There’s secondary effects from not using their platform to consider as well. There’s several applications (open and closed source) I used recently that moved all their support (email/forums) to discord.

2h agoHN ↗

There are several jurisdictions that require companies to ensure that age limits are not bypassed via VPN or anonymizers. This puts the companies in a catch-22, block all VPN and anonymizers access, restricting many people with no recourse, or applying the age rules unilaterally, restricting some teens, but giving recourse to adults using VPNs.

It is not, as you say, "a risk to the privacy and safety of all users", but rather just those marked as needing to verify.

Your hyperbolic rant is uninformed and tiring.

1h agoHN ↗

irc + jitsi. The only options are things incapable of complying to this fucktardedness

3h agoHN ↗

The feature is still DOA. Most people are moving to other alternatives like Fluxer.

Discord will kill themselves if they continue with this nonsense.

3h agoHN ↗

"Most people?" Do you have a source for that claim?

3h agoHN ↗

It doesn't have to be "most" is just has to be "many". As everyone knows, it is all about growth and gaining users for these companies. Having a shrinking pool of users rather than a growing one is the kiss of death.

3h agoHN ↗

This would be a moved goalpost from the idea that “most” people are leaving discord.

We’ve been saying these things about Mastodon and Blue Sky for a long time but they’ve also remained niche.

Discord really isn’t going anywhere anytime soon.

1h agoHN ↗

I don’t think it’s ‘many’ either.

3h agoHN ↗

Sounds like Discord will announce Friday they lost most of their users?

3h agoHN ↗

I muse about the disconnect of people terminally online (myself included) and their tendency to assume their position is the overton window centre, and my experiences talking to people in real life about things like mandatory age checks for social systems.

I get it. People want to keep their (pseudo)anonymity and details private.

I also get it. People in the real world are scared shitless, legitemately or not, about the effect social media has on young minds.