Argues that the UK Online Safety Act, EU age-assurance framework, and ~24 US state statutes are converging into a regime where ordinary web browsing requires a government ID check, face scan, or credit-card handshake. Contends the vendor promise of zero-knowledge attestation rests on load-bearing assumptions — particularly that verifiers actually delete source documents — that collapse under scrutiny given voluntary audits and retention windows stretching up to seven years.
Surfaced the FIRE piece to Hacker News where it drew 526 points and 242 comments, signaling that the developer community sees the third-party verifier model (Yoti, Persona, Incode, AU10TIX, Veriff) as a structural privacy threat rather than an incidental compliance cost.
Frames the vendor pitch — that verifiers confirm 'over 18' without revealing identity and then discard the underlying ID — as resting on three load-bearing assumptions, at least two of which fail in practice. Cites voluntary-only audits and inconsistent retention windows (from 'immediately' to seven years for fraud prevention) as evidence that the privacy-preserving framing does not survive contact with the actual vendor ecosystem.
Documents that the UK's Ofcom-enforced duties, originally aimed at adult-content sites in July 2025, have already pulled Reddit, X, Bluesky, Discord, and even Wikipedia into scope under the 'significant number of minors' standard. Argues the US patchwork (Texas HB 1181, Louisiana Act 440, and a dozen-plus follow-on statutes) plus the EU's eIDAS 2.0 wallet rails create a pincer that normalizes ID checkpoints for ordinary browsing, not just porn.
Notes that the Supreme Court upheld Texas HB 1181 in Free Speech Coalition v. Paxton (June 2024), removing the most obvious US constitutional off-ramp, while the EU eIDAS 2.0 wallet pilot is scheduled for general availability in 2026. Implies the policy window for resisting mandatory ID-at-the-page-load has effectively closed and the privacy fight must now shift to verifier conduct rather than statutory repeal.
FIRE's expression blog published a long-form argument that the wave of age-verification laws sweeping the UK's Online Safety Act, the EU's incoming age-assurance framework, and roughly two dozen US state statutes is producing what the author calls the 'papers, please' era of the internet — a regime where access to ordinary websites is gated by a government ID check, a face scan, or a credit-card handshake routed through a third-party verifier.
The immediate trigger is the UK's Ofcom-enforced age-assurance duties, which went live in July 2025 for adult-content sites and have been progressively extended to any service that 'a significant number' of minors might use. Reddit, X, Bluesky, Discord, and Wikipedia have all been pulled into scope at various points. Texas's HB 1181 (upheld by the Supreme Court in *Free Speech Coalition v. Paxton*, June 2024), Louisiana's Act 440, and follow-on statutes in Mississippi, Utah, Virginia, Arkansas, Montana, North Carolina, Indiana, Kansas, Kentucky, Florida, Tennessee, Georgia, and South Carolina form the US side of the pincer. The EU's eIDAS 2.0 wallet pilot, slated for general availability in 2026, is the bloc's attempt to standardize the rails.
The mechanic is always the same: before you can read the page, a third-party verifier — Yoti, Persona, Incode, AU10TIX, Veriff, or a wallet issuer — must vouch that you are over the threshold age, and that vouching almost always involves uploading a government ID, a selfie, or both.
The vendor pitch is that zero-knowledge attestations make this safe: the verifier confirms 'over 18' without telling the site who you are, and discards the underlying ID. In practice, that story has three load-bearing assumptions, and at least two of them snap under weight.
The first assumption is that the verifier actually deletes the source documents. Audits are voluntary, retention windows vary from 'immediately' to 'up to seven years for fraud-prevention purposes,' and the contractual right to delete is usually subordinate to a 'legitimate interest' carveout. The AU10TIX leak in 2024 — which exposed a year's worth of admin credentials with access to verified ID images for TikTok, X, Uber, and others — is the reference incident. Treating ID-verification vendors as trusted endpoints is the same category error as treating SMS as out-of-band auth: a control that looks isolated on the architecture diagram but in reality concentrates risk into one breachable hop.
The second assumption is that the *linkage* between an identity and a browsing session is ephemeral. It isn't. Every verifier maintains a session-to-attestation log for fraud, chargeback, and law-enforcement response. A subpoena, a national-security letter, or a civil discovery request can pierce the zero-knowledge layer trivially because the metadata around the attestation — IP, device fingerprint, timestamp, requesting domain — is retained even when the underlying ID is purged. Andy Yen of Proton put it bluntly on HN: 'ZK doesn't protect you from the parties who hold the index.'
The third assumption is that the laws will stay scoped to pornography. They have not. The UK's regime now reaches Wikipedia's talk pages. Mississippi's HB 1126 was written broadly enough that the Fifth Circuit had to enjoin it against NetChoice members in 2024. Utah's SB 194 attaches to any app store transaction. The pattern, visible across every jurisdiction that has passed a first-wave bill, is that age-gating laws ratchet outward from adult content to social media to general-purpose platforms within 18 months of enactment.
The community reaction tracks the technical reality. The HN thread (526 points, 800+ comments) coalesces around three positions: civil-liberties absolutists who see this as the end of pseudonymous speech; pragmatists who concede some verification is inevitable but want EFF-style decentralized attestation (Privacy Pass, Anonymous Credentials, BBS+ signatures) mandated; and a smaller camp arguing the laws are unenforceable against well-resourced users with VPNs and will mostly punish the median user and small sites. The pragmatist position has the most technical merit and the least political traction — none of the enacted statutes specify cryptographic primitives, and most explicitly accept ID upload as a compliant method.
If your product has any plausible nexus to a regulated jurisdiction — and 'plausible' is doing heavy lifting here, because Texas now claims jurisdiction over any site one Texan can reach — you have three concrete obligations forming. First, you need a verification vendor in your dependency graph, with the same diligence you'd apply to a payment processor: SOC 2 Type II, a real DPA, a breach-notification SLA measured in hours, and a documented data-flow showing exactly what crosses your boundary. Persona, Stripe Identity, and Onfido are the current adult choices; the wallet-based options (eIDAS, Apple's IdentityDocument API, Google's Digital Credentials API) are coming but not yet shippable for general traffic.
Second, your auth and session model has to change. The naive integration — verify once, set a 'verified=true' cookie forever — fails both the regulatory test (most statutes require re-verification on a cadence) and the security test (cookie theft becomes identity theft). The emerging pattern is a short-lived signed attestation token, scoped to a session, refreshed via the verifier's silent-renew flow. If you're building this in 2026, design for the W3C Digital Credentials API now; it's the only path that doesn't lock you to a single vendor.
Third, your threat model now includes 'verifier compromise leaks our entire userbase's government IDs.' That changes incident-response planning, cyber-insurance scoping, and — critically — the calculus on whether to operate in marginal jurisdictions at all. Several smaller forums (LobsteRs-adjacent, niche fandom wikis) have already geo-blocked the UK and Mississippi rather than wire up verification. That is now a legitimate product decision, not a protest gesture.
The near-term trajectory is not 'the laws get repealed.' It's 'the laws get harmonized around whatever the EU wallet pilot ships in 2026,' and every other jurisdiction reverse-engineers compatibility. The technically clean outcome — device-held credentials, unlinkable presentations, no third-party in the hot path — is achievable; the BBS+ and the Digital Credentials API are real. The political outcome is more likely to be a thin layer of zero-knowledge marketing over a thick layer of centralized verifier logs. Build for the first; assume operationally you'll be running on the second.
> You’re not happy about it, but you hand over a photo of your passport and hope it doesn’t come back to haunt you.I think for this argument to carry weight with voters, privacy advocates need to be much more specific about what "coming back to haunt you" looks like. They do a little bi
> you’re criticizing a powerful politician, or talking about your experiences with abuse or addiction, or discussing embarrassing medical issues you’re facingThis is not the problem. Even if, like millions, you are not talking about these things online, these systems still place you in danger. Ev
Assuming no revolutionary changes are coming to the USA, I am planning to opt out of the digital world when I retire. Physical media only. No subscriptions. Spend lots of time in the library. Find like-minded people and meet in person. Will only keep the bare minimum for survival, like banking.
The path ahead in the next few years (at least for the UK)1. Age gating + VPN ban under the guise of protecting children from social media2. Few years pass, Identity Passport gets ushered in under guise of convenience of not having to repeat those pesky age verification checks.3. Utilities start to
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
There are at least some technological solutions here, such as anonymous credentials. [1] Modern versions of this technique allow one to associate metadata (like a proof of age exceeding a threshold) in such a way that the verifier can't even correlate repeated requests across users.Governments