HN Debrief

Stop Killing the Internet: No Digital ID and No Age Verification

  • Privacy
  • Regulation
  • Infrastructure
  • AI
  • Security

The submission links to a new European Citizens’ Initiative aimed at blocking mandatory digital ID and mandatory age verification for lawful online content. The text is less absolutist than the title suggests. It allows digital identity and proof-of-age systems if they are voluntary, privacy-preserving, open source, independently audited, and usable without enabling cross-service tracking. What animated people was not the petition mechanics but the fear that any legal requirement to prove age online quickly becomes a requirement to identify yourself whenever you read, post, or join a service.

If your product, platform, or policy work touches identity, moderation, or trust, separate age or human verification from real-name identification now. The practical fight is over who controls the verification layer and whether it becomes a reusable surveillance rail for governments, platforms, and data brokers.

Discussion mood

Strongly negative toward mandatory digital ID and age verification. People see it as surveillance infrastructure first and child protection policy second, with deep distrust that governments or platforms would keep the data use narrow, temporary, or privacy-preserving.

Key insights

  1. 01

    Public health logic lowers the bar

    Treating age verification like a public health intervention explains why obvious bypasses do not weaken the policy case very much. If lawmakers only want broad reduction rather than airtight prevention, technical arguments about imperfect enforcement will miss the real political standard they are using.

    Argue against the data collection and power concentration directly. Do not assume proving circumvention is possible will kill the proposal.

      Attribution:
    • kelseyfrog #1
  2. 02

    Online age checks create a browsing dossier

    What makes internet age gating dangerous is not the check itself but the automatic exhaust around it. Verification vendors, sites, and adtech can turn a simple “over 18” gate into a persistent map of what someone reads, watches, and says across services, which is a very different thing from a bartender glancing at a license.

    When evaluating any age or human-verification design, ask where logs, copies, and correlation points are created. A system that only proves a fact on paper can still become identity surveillance in implementation.

      Attribution:
    • adiabatichottub #1
    • tavavex #1 #2
    • krater23 #1
  3. 03

    Kids-only networks narrow the blast radius

    One proposed alternative was to stop trying to retrofit the whole internet for child safety and instead build child-scoped devices and services with stricter rules. The point is not that this design is easy. It is that if protecting minors were truly the objective, policymakers could target kids’ environments instead of forcing every adult interaction through an ID gate.

    Ask whether a proposal constrains the high-risk surface or re-architects the whole internet. The latter usually signals objectives beyond child protection.

      Attribution:
    • nemomarx #1
    • hunterpayne #1 #2
    • Root_Denied #1
  4. 04

    Reputation beats real-name identity online

    Several comments sharpened the distinction between proving a legal identity and building trust. What people actually need online is persistent reputation tied to a recognizable handle or community context, not a passport-backed name. The harder problem is that platforms own those handles and can erase years of accumulated trust instantly, which makes both pseudonymous reputation and platform dependence fragile.

    If you run a community product, invest in portable identity and reputation before reaching for KYC-style verification. Trust often comes from continuity and context, not from legal names.

      Attribution:
    • metalliqaz #1
    • kristerv #1
    • naravara #1 #2
    • berkes #1 #2 #3
    • KPGv2 #1
  5. 05

    Mobile app stores are the enforcement choke point

    Mandatory identity rules become much more powerful when Apple and Google can enforce them through app distribution and platform permissions. That turns phone operating systems into ready-made compliance levers for banning VPNs, forcing attestations, or blocking apps that do not implement the required controls.

    If you care about speech and privacy resilience, track platform governance as closely as legislation. Closed mobile ecosystems make restrictive policy far easier to operationalize.

      Attribution:
    • AnthonyMouse #1
  6. 06

    Narrower technical fixes already exist

    Some commenters pointed out that the policy debate jumps too quickly from real harms to universal identification. They cited zero-knowledge proof systems, parent-controlled filtering, and standardized content metadata as more targeted options. The existence of these alternatives strengthens the argument that blanket ID is being chosen for control and convenience, not because less invasive designs are unimaginable.

    When someone says mandatory verification is the only workable path, press for the rejected alternatives. The decision to skip narrower tools is itself a signal about priorities.

      Attribution:
    • EGreg #1
    • skinfaxi #1
    • mr_mitm #1
    • hnav #1

Against the grain

  1. 01

    Real-name spaces still have a place

    A minority view held that self-identifying online should be easier and more normal, especially as LLM-driven botnets flood large public platforms. The useful part of that argument is not the claim that real names end toxicity, which others challenged with Facebook as counterexample. It is that some users increasingly want high-friction spaces where they can assume they are dealing with actual people.

    Consider offering optional verified layers rather than one universal identity regime. There is real demand for stronger authenticity signals, but it does not require abolishing anonymity for everyone.

      Attribution:
    • josalhor #1
    • fc417fc802 #1
    • flexagoon #1
    • strifey #1
  2. 02

    Traceability will keep gaining political support

    One bleak but credible argument said online harms from deepfakes, CSAM, defamation, and propaganda are pushing lawmakers toward systems that make speakers and posters legally reachable. Even critics of mandatory ID should take seriously that the liability impulse is not going away, because governments increasingly see anonymous mass publication as incompatible with enforcement.

    Plan for a future where policymakers keep tying trust and safety to attributable identities. If you want a different outcome, you need workable accountability models that do not depend on universal deanonymization.

      Attribution:
    • hunterpayne #1 #2
    • AuthAuth #1
  3. 03

    The petition title overstates the actual text

    Some pushback focused on the mismatch between the slogan and the proposal. The initiative itself does not reject digital identity outright. It asks for voluntariness, selective disclosure, non-digital alternatives, and controls on relying parties. That makes it less a rejection of digital ID than a demand to fence it in before it becomes mandatory infrastructure.

    Read the underlying text before treating the initiative as absolutist. The most defensible position here is often not “no digital ID ever” but “no compulsory identity layer for ordinary internet use.”

      Attribution:
    • TryingToBeNice #1
    • dgellow #1
    • jvuygbbkuurx #1
    • victorbjorklund #1

In plain english

Adtech
Advertising technology, the systems and companies that track users and target ads across websites and apps.
CSAM
Child sexual abuse material, illegal sexual images or videos involving minors.
LLM
Large language model, a type of AI system trained on huge amounts of text that can generate and analyze language and code.
Zero-knowledge proof
A cryptographic proof that lets someone verify a claim without learning the private information behind it.

Reference links

Identity and privacy-preserving verification

  • Google Longfellow ZK
    Referenced as an open source zero-knowledge proof implementation that could support privacy-preserving age checks without full identity disclosure.
  • Magarshak papers
    Shared by a commenter claiming academic work on privacy-preserving age verification and inviting collaboration.

Related policy and movement references

Historical and regulatory references

Books and fiction