Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Claude is only available to people over 18 years (claude.com)
665 points by Muhammad523 1 day ago | hide | past | favorite | 644 comments
 help



Claude Executive: Damn, we hardly know who our users are, can't we just force them to say their full name or ban them?

Claude Product Manager: No, that'll piss people off too much, and sadly we can't just ask for ID either...

Claude Executive: There must be some way we can force people to link their government IDs with our platform so our analytics get better and more accurate?

Claude Product Manager: We could limit the platform to 18+ and use "Age Verification" as the reason for people to hand over IDs, seems other platforms had success with this approach

Claude Executive: And we hardly have any users younger than 18 anyway, go for it!


I'm imagining a future where a bunch of bizarre laws interact oddly (as they do), and now we've got websites with unnecessary nudity pasted in the corner.

"Oh, those? Those are just compliance tits. Ignore those. It's just a thing that came a few years after we finally got rid of the cookie banners. The companies wanted certain protections awarded only to 18+ sites. But you can't just declare yourself an 18+ site, so some sites post the most minimal amount of imagery that constitutes erotic nudity. That's why Google's graphic for the past few months has just been that one with the two dots in the middle of the o's."


Reminiscent of this scene from the 1981 teen-slasher parody, Student Bodies:

> Announcer: Ladies and gentlemen, in order to achieve an "R" rating today, a motion picture must contain full frontal nudity, graphic violence, or an explicit reference to the sex act. Since this film has none of those, and since research has proven that R-rated films are by far the most popular with the moviegoing public, the producers of this motion picture have asked me to take this opportunity to say "Fuck you."

> [the MPAA R-rating logo appears on the screen]

https://www.imdb.com/title/tt0083133/quotes/



That sound quality did something weird to my brain, I was convinced sound was accidentally coming out my laptop speakers not my headphones. I'm not even on my laptop, and I still took my headphones off to check.

Almost assuredly a video capture of a screen.


And one of the rare incidences of the MPAA ratings banner appearing in the middle of a film.

Joke's on you, as standards loosen now PG-13 movies get up to eleven "fuck"s to distribute throughout the film (nineteen for documentaries)

PG-13 didn't exist in 1981. It went straight from PG to R. So less loosening of restrictions, and more adding gradation.

And in 1981 PG movies had tits.

Airplane (1980) was PG.

It's bizarre because tits are the first thing everybody sees

At the time, I was of an age and disposition to notice.

Today's 13 year olds say that word more times than that before breakfast.

Which is, of course, a bad thing that ought not to be encouraged and that ubiquity does, in fact, encourage and normalize.

Yea. Nobody needs to be talking that much before breakfast.

>Which is, of course, a bad thing that ought not to be encouraged

I'm not actually willing to take that as read. It's just the word "fuck". You may personally find it distasteful and you're welcome to discourage your children from using it but it seems like you're committing Pargin's Blunder here (mistaking norms specific to your social group for universal truths).


So fucking what? Nothing wrong with that. Lighten up, francis.

If the word fuck isn't offensive, there's absolutely no reason to use it.

Yet every culture across the globe has and has always had swearing, profanity, taboo words, fart jokes, and gate keepers decrying such things.

While the reasons may elude, the ubiquity speaks to something foundational.


If casual use of profane and taboo words isn't offensive, are they really profane and taboo?

Fart jokes are popular in US. Mostly.

Fear of a Black Hat, a rap mockumentary in the same vein as This is Spinal Tap, begins with a warning about the language in the movie that's essentially them repeating the offending words three or four times.

https://www.youtube.com/watch?v=_fmaaZtINRU


Right this is exactly what happened with the new sesame laws. The government declared sesame as an allergen and enacted heavy fines if it was undisclosed. This lead to manufacturers adding sesame because they couldn't guarantee they were sesame free.

"May contain" labeling seems like the better solution to this problem. This should be allowed for allergens that are present in the manufacturing or packing facility but not intended to be ingredients in the product.

Then there would never be a reason not to list "may contain sesame". Just like every product causes cancer in california.

The door to one of the hospitals in SF has a prop 16 warning. Even hospitals give you cancer!

That's part of the problem. "May contain" doesn't provide legal protection and then if you make it a standard there needs to be testing for compliance which ends up as the same original problem and you just add compliance tits to your food product.

https://news.ycombinator.com/item?id=34116211


"May contain" should provide legal protection. It may be compliance tits in some cases, but that's better than forcing the addition of a compliance ingredient.

> "May contain" doesn't provide legal protection

Yes, this causes problems.

> and then if you make it a standard there needs to be testing for compliance

Why would there need to be any additional testing? If anything I'd expect "may" foods to need less testing than an accident-prone "no" food.


do you have an example of this? it feels like a suboptimal response even given the stupid, heavy-handed legislation you cite.

https://news.ycombinator.com/item?id=34116211

https://www.fox9.com/news/new-us-food-label-law-unintended-e...

> Some companies include statements on labels that say a food "may contain" a certain product or that the food is "produced in a facility" that also uses certain allergens. However, such statements are voluntary, not required, according to the FDA, and they do not absolve the company of requirements to prevent cross-contamination.

> Instead, some companies have taken a different approach. Officials at Olive Garden said that starting this week, the chain is adding "a minimal amount of sesame flour" to the company’s famous breadsticks "due to the potential for cross-contamination at the bakery."


related: https://en.wikipedia.org/wiki/1986_California_Proposition_65...

> Many companies now routinely attach Prop 65 warning labels to any product of theirs that they think might possibly contain one of the 900 listed chemicals without testing to see whether the chemical is really present in their product and without reformulating their product, because it is cheaper to do so than to run the risk of being sued by Prop 65 enforcers.


> Those are just compliance tits.

Ha! At one point some years back, in an internal presentation somebody used an image of an old computer that if you really, really squinted and looked closely, had a topless woman in ascii art in a small area of the computer screen. It was so hard to see that most of us didn't even notice, but one eagle eye did and caused a whole shit storm around it. If the presenter would have said, "Those are just compliance tits" I think my life would have been complete :-D


Great story! I remember sharing my screen at work recently and the URL bar suggested https://thisisnotporn.com/ because I had been playing it a bit on my phone and my browser history synced to my work. I dont know if anyone caught it but I started using a different browser after that. Because it indeed is not porn but hard to explain that!

Kinda orthogonal to this, but the other day I was looking for a friend's cheer routine on Instagram so I put her school name and cheerleader routine and I got a lot of images and videos of very young girls (like aged 6-16) in very revealing cheer outfits doing provocative dances which made me very uncomfortable for many reasons. Like first, why are you making your 6 year old do this, and second, why is Instagram floating these to the top instead of adults? I dont think I want to know the answers to either of those questions.

Add beauty pageants to that list. It's gross, and a lot of people are ok with it.

I've been using certain slurs as more proof-of-human, and any nuanced thinking that skirts by certain ideologies like Chechens hugging Russian artillery in 1995.

Why not? We already need to include typos and misspellings to signal we're not an LLM.

What use is this when you can just prompt the LLM to insert those or use any other style of writing that looks human?

and its 1 pixel wide. I propose the term pixtit

Also the Dixel for the male option.

Males have tits too

I mean, isn't this basically what's already happening after COPPA with YouTubers having to swear or make adult jokes to prove to the bots they're not targeting children with their videos?

©©

Age verification is not (should not be) the same as ID verification / storage / etc; the US needs laws similar to EU ones where companies can only get the minimum required PII. In the case of age verification that's zero, or a boolean value "yes this person is over 18" that they get from a trusted party like a bank.

> or a boolean value "yes this person is over 18"

It would be detrimental to the cause, which is to collect everyone's ID.


Whilst this is OP's point, the reality is the majority of big tech companies have been treating user data like radioactive waste for 10+ years.

Most user data is of minimal economic value, until you leak it, and then suddenly there are millions of euros of fines headed your way.

Better to not hold the data in the first place.


> majority of big tech companies have been treating user data like radioactive waste for 10+ years.

They're collecting more than ever.


PIIs and payment details are radioactive if explicitly collected as such, or just "anonymized" query parameters if not.

This has not been the case at any of my past employers in B2C...

There was a fair amount of scrambling to get GDPR/CCPA compliant, but even that was done largely with a prevailing "ah, this is a defensible thing to store, make sure you can annonymize it or scrub it if needed" vs "stop storing this."

Starting with the ones that are most popular in the US, "Big Tech" usually includes:

- Google - Gmail and Maps contain massive amount of PII, Photos contains all sorts of other sensitive stuff, and they have not treated those aspects of those products like radioactive waste

- Meta - Facebook has a real names required policy even. Not a lot more needs to be said there, I think.

- Amazon - Nothing I've seen about trying to move away from how they need your name/address/payment info and all. If anything, more and more geographic targeting and such.

- Microsoft - Now you need to tie your local Windows install to their cloud services, not moving away from collecting user info. Also moving towards subscriptions which means PII and payment info.

- Apple - cloud accounts + email + payments + subscriptions all here too. Getting into banking-type services, that's leaning into PII...

- Netflix - more and more PII (IP tracking and geolocation combined with things like email and name) to fight account sharing...

Which ones were running away from it, exactly?


> suddenly there are millions of euros of fines headed your way

I'm not sure about that. As I see it, there is no business case for treating PII carefully: security costs money while leaking PII costs nothing and has no repercussions.


you must be living under a rock, mutable user data like usage habits is being collected at increasing levels

I think GP is about PII rather than "mutable user data".

But then why do they want to sniff after everyone?

Storing all that information is cheap nowadays. Any state agency may be happy to get more information about The People.


Whose cause? I think the government already has our IDs, given that they issued them.

The government isn't typically facilitating the check. In order to verify your age, you will be required to hand over your ID to a third party, who's privacy and security practices are likely: "Trust me bro."

Seeing as how these companies get hacked all the time, (https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...) , I don't think it's unreasonable to resist this.

Furthermore, I think many folks have reservations about requiring an ID checkpoint to utilize a computer. Obviously it's not that bad yet, but I don't think it's hyperbolic to state that the landscape is certainly trending in that direction, and it's absolutely not unreasonable to point out that governments and institutions to have a material interest in setting up access controls on who can and can't use the internet (read: participate in society).


Right, I'm not a fan of the ID check or identity/age verification. I'm just trying to understand the conspiracy theory kind of idea that "they're trying to get all our IDs!!!1!!" sentiment.

"The government already has our IDs" is missing the correlation between the ID and the service. They know your face and your name but not what you do on the internet. The website knows what you do on the internet but it isn't tied to your name. It's the tying them together which is the problem.

Which is why the people trying to do it always pull out the misdirect about ZK proofs. Those don't fix anything because a system that actually preserved privacy wouldn't be able to prove that the user is over 18, only that someone is over 18, not necessarily them. And that in turn means you're setting up a rug pull. You roll out a system which is indistinguishable from the perspective of ordinary people from the one that screws them, and then that system can't actually exclude minors so what follows is calls to change it to stop protecting privacy, at which point the people trying to collect everyone's ID will be arguing that you already have to show ID.

It also presumes you would even get a privacy-preserving implementation to begin with, which a pretty credulous assumption given how these things usually go.


It's not possible to prove the user is anything ever. It probably never will be. Likely what will happen instead is that the person in the ID will become personally liable for accounts verified with that ID. Which is even more reason to reject ID verification.

> Likely what will happen instead is that the person in the ID will become personally liable for accounts verified with that ID.

Exactly. Which in turn requires you to have some way of tying those accounts to that ID, which was supposed to be the thing to be prevented.


Governments don't necessarily have the connection between your ID and what you do online, though, and some governments are known to massively buy publicly available data from data brokers to circumvent existing laws. By "some governments" I mean the US government, by the way. That's not a conspiracy either, it's well-documented.

We don't want your static ID, we want where and what you are at this moment in order to better tune the algorithm. Your ID is frozen in time, so at any given moment, big tech knows more about you than the government does. IDs are only good for minimal verification purposes.

Its actually to leak your gov't ID so data brokers can soak it up

QAnon for nerds

It's just like cookie banners: they shouldn't exist, but people's bonuses rely on never admitting that, so here we all are.

Well the EU's own government websites are all polluted with the cookie banners too so it's obvious that they can't even resist collecting visitor tracking data themselves.

The whole thing is pointless.


Pointless?

If you dont microregulate technology how can you regulate the consequences of regulating technology?

The regulators need this.


EU parliament gets bonuses?

Bank? So now you know what bank they use?

This is why you have a relay in the middle.

Then, Chase knows you've verified your ID somewhere, the relay knows that some Chase user verified themselves at Pornhub, and Pornhub knows that the user is over 18, without knowing their identity or what bank they're using.

You could also do this with ZKPs and device integrity protection. The latter is more secure but more complex, the former is much simpler and openness friendly.


> You could also do this with ZKPs and device integrity protection.

How has the anti-competitive lock-in scam of "device integrity protection" entered the discussion? Using ZK proofs without it has exactly the same effect.

There are far too many attestation-passing insecure devices to expect attestation to have any security value against attackers who can choose any of those devices on purpose.


Or we could use multiple relays so nobody knows both the bank and the purpose, or even who would know the other piece of data... and now thats just Tor but for identity verification. Might be a good idea actually, except the whole point is Anthropic wants to know who you are.

I think the key here is “a trusted third party” more than “bank”.

Also, I’d rather a company know “he has an account at Bank of America” than “His full government name is Bit Masher and his driving license number is 9”


Well, they already know your credit card issuer, it's not that wild. Really Visa/MasterCard should offer age verification on their network... They have all the necessary components.

The EU is also doing age verification by showing ID, only difference is that you have to trust that their zero proof concept works and they're doing what they say they do.

In the US we just assume no one does what they say they do.


> from a trusted party like a bank.

For what reason should I trust a bank?


Not "a" bank. You (somewhat) trust your bank, I would imagine. Since you know, they have your money.

GP's hypothetical here is that Anthropic or other service provider who wants to do "age verification" could partner with (among others) your bank [1], where bank can answer yes/no to "is this user >= 18?", without revealing any other personal info to the SP. Allegedly.

[1] via an intermediary, no doubt. Trying to do a "full-mesh" of partnering of every SP with every bank directly would not scale.


> You (somewhat) trust your bank

For what reason?

> Since you know, they have your money.

You may trust them with your money, but does not equate to trusting them with anything else. Principle of least privilege, if you will. Anthropic has your chat data, which in many ways is more valuable than money, so if the only bar for free lying giving out your personal details is trusting a business with something of yours then why bother with this complex scheme and give Anthropic all of your personal information directly?


> You may trust them with your money, but does not equate to trusting them with any other PII.

This doesn't really make any sense and it feels like it's just an attempt to be contrarian.

Banks by law require substantial PII in order to even do business with you.


> Banks by law require substantial PII in order to even do business with you.

And those laws are extremely invasive and should be repealed. It's offensive to have a law that de facto requires you to identify yourself in order to pay for a newspaper subscription or buy contraceptives over the internet.

But that's not the issue in this case. It's that the bank knows your name and what you buy -- already very bad -- but now you want to create a path to tying that information to everything you do on the internet.


Can't you pay cash for things like Visa gift cards and use them online?

Gift cards don't allow reloading which consequently makes them a significant inconvenience to use for subscriptions. It's sort of like saying you can pay for something by going to their offices and paying in cash. Okay, but then why does the way that 99.9% of people are actually going to do it have to be the one that invades their privacy and puts everything they do in a database?

At least in the US most places that sell gift cards require ID when purchased in cash

depends on local laws?

> Banks by law require substantial PII in order to even do business with you.

That is technically true, but keep in mind that in the early days of banking banks expected you to provide that information without the hand of the law requiring it. The laws you speak of came into effect after the fact to normalize across the industry what the banks were already doing. History is repeating itself in tech, and we already know lawmakers are waiting with bated breath to do their thing all over again just as they did in banking once critical adoption is there.

I expect what you are trying to get at is that you are willing to trust a bank because giving them your life story was already normalized before you were born, so you have never thought to question it. Whereas tech doing the same now feels new and scary. However, that's a funny way to look at it as the kids born in the future, who never knew the world where you could use the internet anonymously, will see giving tech their ID as being no different than how you see giving your bank your ID.

Although I can understand why you would now question why any business that does little more than store numbers on a computer needs a comprehensive profile on you by law or otherwise. Normalized does not equal sensible. That is a fair point.


> it feels like it's just an attempt to be contrarian.

You feel like it's an attempt to be contrarian not to inform your bank about everything that you do?

Society has reached a dangerous point.


You wanna try reading the whole comment?

> You may trust them with your money, but does not equate to trusting them with any other personal information.

How do you expect that they will give you your money when you walk in to a branch and ask for a withdrawal? Or that they'll replace a lost card? Surely you'd expect them to verify your identity.


They could verify your identity if you've given it to them.

But it would also be completely reasonable to authenticate the customer exclusively using mechanisms other than government ID. You can already make a withdrawal using your bank card and PIN. If you lose your card you could sign into their website using your password and request a new one etc.

Consider what happens if you lose your government ID. Your bank has much better ways to authenticate you at that point than the government does. Government ID has a major bootstrap problem, whereas patronizing a service doesn't because a new account with no money in it belongs to whoever is signing up for it regardless of who they are, and you can at that point give them a bank card and have them provide a password and email address etc. that allows you to identify them in subsequent transactions without ever needing their name.


Well, how do you expect a website to know that you are 18+?

The technical solution offered earlier was to have a trusted third-party only be willing to answer the "is this person 18+?" question. Of course, the same works for banks. The trusted third-party can answer "does this person own this account?" without needing to reveal to the bank any other information about you.

Now, that still leaves open the question of who you can trust. If you can trust a business run by people then that allows you to trust a bank, sure, but it also allows you to trust a tech company, so why not just give the tech company your ID and skip all that technical complexity? Understandably the broader idea presented earlier was that you cannot trust businesses operated by people, but then that includes banks, so...

For the sake of discussion, if we accept that technical solution and the need for a trusted third-party that is a business run by people, surely it should at least be a business that does nothing but offer profile trust to minimize the blast radius? For what reason would we want that business to have their hand in other activities like chat or banking?


> Now, that still leaves open the question of who you can trust. If you can trust a business run by people then that allows you to trust a bank, sure, but it also allows you to trust a tech company

Banks are subject to much stricter regulation than any tech company is or ever will be (IMO, I could end up surprised).

I trust my bank to know who I am and keep track of my money. I trust big tech to lose or misinterpret my data, to close my account for no reason, etc, and to face zero consequences for those failures -- not even fines.


> Banks are subject to much stricter regulation than any tech company is

That's true, but remember what we're talking about: Using banks (or another trusted third-party) to assert your age instead of having big tech collecting your personal information themselves. There is context here. Writing comments in a vacuum makes no sense.

In that context it is understood that only incentive for big tech to follow the proposed is regulation, but if you are going to push regulation on them then you can regulate them just as much as banks.

Your broader point that, in the real world, there isn't much political will to push any of that regulation is also no doubt true, but, again, writing comments in a vacuum makes no sense. The hypothetical of big tech adopting a third-party attestation system was already understood to be just that: hypothetical.


I trust my bank a whole lot more than I trust Anthropic

If I had a bank, I'd trust it too, it being mine. Most people don't have the luxury, though. In practice, they have to outsource banking to other people. And those other people are already quite likely to move around between both Anthropic and various banks in search of whomever will offer them the most economic benefits. It is not like a particular logo on their current business card is going to change their character. You do you, of course, you are already unique in having a bank you can call your own. But the fact remains that most people strongly believe that a person's trustworthiness is of the person, not the activity they happen to be doing at the time.

Colorado and a few other states have zero knowledge proof apps capable of this.

This is fantastic, except that the idea of mandatory government software only available on chosen proprietary platforms feels way worse.

If there were a way to crypto-notarize a third-party wallet token etc blah blah, then it would be interesting.

At the end of the day though, this is about protecting the powerful, not the kids.


Well, that’s basically just the California law everyone hated

I do not want my computer to yield information to evil outside actors in general. This is why systemd going that way is so outrageous:

https://github.com/systemd/systemd/pull/40954


I think many linux users will apparently have been born on Jan 1 1970

Strange, when I buy beer at Kroger and the "ID verification" guy has to come over, he looks at me and just keys in 01/01/1970 as my birth date most of the time. Or just asks me what my birthday is and I give him a random date in the late 1960s.

Isn’t the very first option on the article a service that estimates your age without ID? Are they lying?

> where companies can only get the minimum required PII. In the case of age verification that's zero, or a boolean value "yes this person is over 18"

This person? There's your PII right there. The ad seller's dream.


I can't figure out if you're joking or not.


That specific link is basically just "having an account" if anonymity is turned off.

If you include the anonymous version are you calling a basic cookie an "advertiser's dream"? Then that's not something new they would get if the cookie tracked age verification. And you can reset cookies every visit (or more often). The "that person" of a site-specific session cookie is not a big deal for privacy.


"user identifiers".

I'll say it again but simpler:

The "user identifiers" are just having an account. That's when it's not set to be anonymous in the first place.

When it is set to be anonymous, it doesn't do this.


This seems like a lazy snipe. They clearly state that they receive only an age verification result and none of the personal data. It would take collusion from both sides to silently enable transfer of user data while publicly stating that they don't.

I have used these KYC services before. There is the option to get access to all user data - but unless there is evidence to the contrary, we have to take their word for it, for now.


No fucking way I’m sending my biometric data to some sleazy foreign company I know nothing about. The fact that “Yoti” is separate from Anthropic doesnt suddenly make this less gross.

Right, Sending off my data to some random 3rd party company with far lower stakes does not make me feel better.

I 105 percent trust anything and everything a zillion dollar company promises!

Wasn't there a purported breach of a huge KYC service, idscan recently? https://www.consumeraffairs.com/news/fbi-investigates-massiv...