FIRE argues that a coordinated cluster of laws — the UK Online Safety Act, EU DSA age-assurance guidance, France's SREN law, and ~24 US state statutes — is pushing every general-interest site hosting user content toward 'log in with government ID' as the cheapest compliance path. They frame this as a 'papers, please' transformation of the open web where third-party verifiers like Persona, Yoti, and AU10TIX become mandatory chokepoints for ordinary browsing.
By submitting the FIRE piece and driving it to 1,070 points, bilsbie surfaced the argument that age-verification mandates represent a structural privacy threat worthy of developer attention. The unusually high score for a policy piece suggests strong community endorsement of the framing.
FIRE cites the 1,400% ProtonVPN signup spike within 48 hours of UK enforcement and the fact that a VPN became the #1 UK App Store app as evidence that age verification doesn't actually keep determined users (including minors) off restricted content. Instead it just pushes everyone toward circumvention tools, leaving only the compliant majority exposed to ID collection.
The Wikimedia Foundation has filed for judicial review of the UK Online Safety Act arguing that Wikipedia structurally cannot comply without destroying its editorial model — which depends on pseudonymous volunteer editors rather than ID-verified accounts. Their position is that the law's 'highly effective age assurance' requirement is fundamentally incompatible with how collaborative knowledge platforms work.
FIRE argues that the Supreme Court's June 2025 Free Speech Coalition v. Paxton decision, which upheld Texas's age-verification law under intermediate rather than strict scrutiny, functionally green-lit every state copycat statute. With 24 states already on board and seven extending the regime to general social media for minors, FIRE sees no remaining legal mechanism to slow the spread before it reaches general-purpose platforms.
FIRE's expression blog published a long read titled *The 'Papers, Please' Era of the Internet* that hit Hacker News at 1,070 points — unusually high for a policy piece. The argument is narrow and concrete: a cluster of laws now in force or about to be — the UK Online Safety Act, the EU Digital Services Act's age-assurance guidance, France's SREN law, and roughly two dozen US state statutes modeled on Louisiana's HB 142 — are converting the open web into a checkpoint network. Every general-interest site that hosts user content, comments, or video is being pushed toward a position where 'log in with a government ID' is the cheapest path to compliance.
The UK's regime, which took full effect in July 2025, requires 'highly effective age assurance' for any service likely to be accessed by under-18s and serving content classified as harmful. In practice that has meant Reddit, X, Discord, Bluesky, Grindr, and Pornhub all rolling out third-party verifiers (Persona, Yoti, AU10TIX, k-ID) that take a passport scan, a face scan, or a credit-card check. Within 48 hours of the UK enforcement date, ProtonVPN reported a 1,400% spike in UK signups; the top app on the UK App Store became a VPN. The Wikimedia Foundation has filed for judicial review arguing Wikipedia cannot comply without destroying its editorial model.
The US picture is messier but moving the same direction. The Supreme Court's June 2025 *Free Speech Coalition v. Paxton* ruling upheld Texas's age-verification law under intermediate scrutiny, which lower courts had been blocking on strict-scrutiny grounds. That decision functionally green-lit every state copy. As of this month, 24 states have age-verification statutes on the books for adult content, and seven (Utah, Texas, Louisiana, Arkansas, Mississippi, Ohio, Tennessee) extend the regime to general social media for minors.
The technical design of these systems is the part developers should care about. The verification flow is almost always: user uploads ID to a third-party processor, processor returns a signed 'over 18' token to the site, site stores the token bound to an account or device. The marketing copy says the ID is deleted after verification. The legal reality, in every regime that has been audited, is that 'delete' means 'retain for the audit window' — 12 months under UK Ofcom rules, 36 months under most US state implementations, indefinite under any active investigation. AU10TIX, the verifier behind X and TikTok's checks, had a credential leak in 2024 that exposed admin access to verification records for over a year before disclosure.
The failure mode is structural, not incidental. You now have a small number of identity processors sitting between hundreds of millions of users and every regulated service. That is the most valuable breach target the consumer internet has ever assembled — government-issued ID, biometric template, and a real-time index of which adult, gambling, dating, or political-speech site you tried to access. When (not if) one of them is compromised, the blast radius is not 'passwords' — it's a permanent linkage between legal identity and browsing intent.
Second-order effects are already visible. Compliance costs are squeezing out small operators: the UK's own impact assessment estimated £1,700–£40,000 per service per year for age assurance, and Ofcom has confirmed it will not provide a safe-harbor template — every site has to commission its own risk assessment. Three independent forum operators (LFGSS, MetaFilter UK access, a chunk of phpBB-era hobby sites) have shut down rather than comply. This is the regulatory equivalent of GDPR's cookie-banner era, except the cost of getting it wrong is criminal liability for a named director, not a fine.
The community response on HN was notably bipartisan in a way policy threads usually aren't. Top comments from self-identified parents, civil-liberties skeptics, and ad-tech engineers converged on the same point: there is no implementation of age verification that doesn't either (a) require a centralized ID-to-session linkage, or (b) leak so much information through the 'zero-knowledge' attestation flow that re-identification is trivial. The much-cited Apple/Google 'device-level age signal' proposal pushes the verification to the OS, but the OS still has to know, which means Apple and Google become the de facto ID brokers for the open web.
If you ship anything with user-generated content, comments, DMs, or video — and you have any UK, EU, or US-state-resident users — you are in scope or about to be. Three concrete things to plan for:
Architect for KYC-on-content as a default, not a feature. The pattern that's emerging is: anonymous read, verified write. If your product assumes anonymous account creation works in your largest markets in 2027, that assumption is now load-bearing on litigation outcomes you can't predict. Build the verification hand-off as a pluggable boundary now — pick a verifier (Persona and Yoti have the cleanest APIs; k-ID is the only one with a real device-attestation flow), wire it behind a feature flag, and don't put it on the critical path for read traffic.
Treat verification tokens like payment tokens. Don't store the underlying ID artifact, don't log the verifier's raw response, rotate the bound token on session change, and assume the verifier will be breached. The serious teams I've talked to are treating age-assurance integration the way they treat Stripe — a vendor you pay specifically so the regulated data never touches your disk. If your verifier offers an on-device or zero-knowledge attestation mode, take it even if it costs 3-5x per check; the storage liability of the alternative is unbounded.
Audit your IP and VPN handling now. The VPN surge means a non-trivial share of your traffic is about to look like it's coming from datacenter ranges in countries you don't operate in. Sites that aggressively block VPN IPs are going to start blocking their own paying users. Sites that don't are going to start eating fraud and bot traffic they used to filter geographically. Pick a posture deliberately rather than discovering one in your fraud dashboard.
The FIRE piece's framing — 'papers, please' — is rhetorically loaded but operationally accurate. The next 18 months will determine whether age assurance settles into a Stripe-style boring vendor layer or metastasizes into a full identity-to-behavior graph held by three or four processors. The market is currently choosing the latter because it's cheaper, and the regulators are choosing it because it's auditable. The window to argue for device-attested, zero-knowledge alternatives is closing fast — once Persona and AU10TIX have a billion enrolled identities each, the incumbents will lobby to keep the architecture exactly as it is.
> You’re not happy about it, but you hand over a photo of your passport and hope it doesn’t come back to haunt you.I think for this argument to carry weight with voters, privacy advocates need to be much more specific about what "coming back to haunt you" looks like. They do a little bi
> you’re criticizing a powerful politician, or talking about your experiences with abuse or addiction, or discussing embarrassing medical issues you’re facingThis is not the problem. Even if, like millions, you are not talking about these things online, these systems still place you in danger. Ev
Assuming no revolutionary changes are coming to the USA, I am planning to opt out of the digital world when I retire. Physical media only. No subscriptions. Spend lots of time in the library. Find like-minded people and meet in person. Will only keep the bare minimum for survival, like banking.
The path ahead in the next few years (at least for the UK)1. Age gating + VPN ban under the guise of protecting children from social media2. Few years pass, Identity Passport gets ushered in under guise of convenience of not having to repeat those pesky age verification checks.3. Utilities start to
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
There are at least some technological solutions here, such as anonymous credentials. [1] Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users.Governments