AB 962: Purpose
The legislature recently introduced a digital age verification bill that would require age verification on app stores––Google Play and Apple's App Store, for example. Verification of age would be required of all users.
The bill also requires app developers to include an age rating for their applications, preventing anyone beneath the minimum age from downloading apps unless their parent has approved the download from their own account.
The bill aims to prevent app stores and developers from allowing minors to download or purchase apps without the necessary parental consent, and requires parental consent for in-app purchases (micro-transactions) like those commonly found in mobile games, which would also be affected.
The bill states that app stores must use a "commercially available" method to verify a user's age, and also ensure that users' verification data is encrypted.
A similar bill was introduced in the state of Texas, only later to be ruled unconstitutional by a federal judge for violating the 1st Amendment's free speech clause.
AB 962 is likely to suffer the same fate for the same reason. But even if it doesn't, the requirement for age verification is one that is easily navigated by the children the bill aims to protect. And more importantly, the bill is actually counter-productive.
Individuals' personal data is already highly compromised, especially when it comes to digitized data. And despite what AB 962 requires, further privacy and data breaches will not be curtailed by any kind of encryption.
Requiring more personal data to be collected by app stores simply grants malicious actors access to another layer of vulnerability they otherwise would not have.
Kids are Sneaky and Better with Tech
The first thing to address is that kids today are much better with technology than the typical adult, and especially when it comes to mobile phones.
Depending on the type of age verification implemented by app stores, there is no way to guarantee that kids won't simply self-verify. The bill does not specify the kind of age verification method to be used, after all.
But as examples of what has commonly been implemented in other states with age verification requirements, California requires age verification for online purchases of vape products by requiring purchasers to upload images of the front and back of their state IDs. Texas also requires the same verification process for anyone wishing to view pornography online.
You might like these laws, but do you really think your 13-year-old son doesn't know you keep your driver's license in your purse? Dad, don't you throw your wallet in the key dish by the front door so you don't forget it? Yes? Then congratulations. You, the parent, are now a part of a multi-billion dollar industry's consumer database which they will use for targeted marketing campaigns, or else sell to third parties.
Suddenly, Amazon Prime Video begins recommending the "little blue pill" during commercial breaks, and Google Search's Shopping tab begins pushing "Adam & Eve" products. This could put quite the damper on movie night.
Worst of all, this digital footprint is tied to you personally. Your home network has a digital address. That address is tied to a physical location. That physical location is your home. Well, your home address is already a matter of public record, but remember, in this instance they have not only your location and name, but your physical description too.
Your race, height, hair and eye color, date of birth––all of this is now aggregated into a complete profile.
True, these third parties may not be interested in that information beyond its value for marketing––so you might only expect additional junk mail from the U.S. Post. But some third parties will be malicious. And if not, you still have to worry about the fourth parties.
On the flip side, maybe there isn't any ID verification. Maybe app stores use a different method and everything mentioned above is pure paranoia. Maybe app stores instead decide to follow in the footsteps of YouTube. YouTube requires channels seeking monetization to scan the front and side profiles of their face. They promise this data will not be stored for longer than two years.
But what will happen to this data in the interim? Will it be used for AI facial recognition software like that already deployed by China's Skynet? Or by Palantir? Will CCTV be able to track your whereabouts by identifying you when you walk into the grocery store? Go to church? The bar?
The answer is "yes" because that is already being done in this country.
Bad Actors
The state of digital surveillance (or just plain old surveillance, for that matter) in this country has reached dystopian levels of oppression.
Although technology, smart devices and the internet have undoubtedly improved our quality of life, that of course does not mean that these are all good all the time. Nor does it mean they are all bad. There are tradeoffs to everything, and those have to be considered when weighing the efficacy of bills like AB 962.
The thing of utmost importance here is whether app stores really need this information in order to conduct their business, and if the cost of doing so is less than that of some private alternative.
The first thing to consider here is whether AB 962's requirement to "encrypt" personal data is actually sufficient protection.
The answer is "no".
One reason for this answer is that encryption is only as good as the cryptographer writing the encryption code. If there are flaws in the encryption method then any stored data, or data in-transit over the internet, can be "grabbed" and decrypted. In February alone, Security Boulevard reported that at least 6 major companies had suffered from data breaches that compromised customers' private information.
One of the largest data breaches of all time happened to Yahoo!
More than 3 billion accounts were affected when a group of Russian hackers were able to get accountholders'
Again, what is being done with this data? How many people were later defrauded because the answers to their Yahoo! security questions were the same as those used at their banks?
And many other examples abound.
Microsoft, Google, LinkedIn, Anthem Health, Facebook, JPMorganChase, eBay, Discord, CapitalOne, DeepRoot Analytics, United Health, and the United States federal government have all suffered from data breaches.
People had their health records hacked. People's voting ID numbers and religious affiliations were revealed.
Their bank account balances, SSNs, credit scores, genders, number of pets, smoking habits, passports, credit and debit card numbers––all have been revealed.
So if even these companies––many of them "tech" companies with huge, expensive cybersecurity teams––can be compromised, why would we expect "encryption" to provide sufficient protection to app users? After all, all of these companies used encryption!
The second issue with requiring "encryption" is that it is utterly useless if the end-use devices are compromised.
If you wind up sending photos of your ID or a scan of your face to these app stores, anyone with access to their servers can take your data, decrypt it, sell it, or use it against you.
From your end of the data transfer, if any of your devices are compromised by backdoor access all transmitted data is grabbed before encryption can ever take place. Backdoor access means that malware can access and control your devices. It can tell your devices to record your screen without your knowledge or record your "keystrokes" as you type (I'm looking at you, Discord). So any "private" messages sent through end-to-end encrypted communication platforms like Signal, for example, may not actually be private. While apps like Signal may be fine in and of themselves, the data breach can occur at the point of download if the app stores themselves are compromised or introducing their own spyware. These sorts of things are hidden in the "terms of service" which––as South Park revealed––we all read.... right?? How many consumers know how to cross-check their downloads with the opensource files of these apps?
In fact, screen recording has been found to occur on many SmartTVs by LG and Samsung. They call it "Automatic Content Recognition" but it's just plain spying. And this is a default feature of these devices. It comes pre-installed. Imagine how many other devices are affected in this way due to malware or just run-of-the-mill data capture by app stores?
Backdoor access to phones and computers is potentially rare (we don't know exactly the extent) but it is possible and it does affect millions of devices. If you do not have a password-protected Wi-Fi network or if you have ever downloaded something on the internet from a dubious source, you have invited this possibility.
The Low Cost, Pro-Freedom Alternative
Everything above pertains to the cost of implementing AB 962. There are huge privacy issues and security concerns to consider, and there's a good chance that the bill won't have the desired effect anyway.
If the state's goal is to curb the damage done to kids by "addictive" social media platforms, "predatory" micro-transaction schemes, or exposure to the explicit and sexual content present on the internet, then state officials should begin an information campaign to inform parents!
We do not need the state to raise our children. We do not need them telling us how to raise our children or what is good for them, much less making us parent a certain way "for the good of the children."
Most people here probably agree that all of these things are damaging to children and ought to be curtailed. But the point that needs to be made to the nanny state is this: they're not your kids!
If parents are truly concerned about what non-age appropriate content is doing to their kids, then don't give them a smart phone! Don't give them a computer! You're the adult. You pay for the phone plan and the internet, so you get to decide how those things are used.
Parents, here's a short list of things you can do to protect your kids from harmful content
These are phones that can only text and call, and can only contact phone numbers on your approved list. They cannot access the internet and cannot take photos.
If they must use a computer, they will now use the "family" computer which will be located in the kitchen or living room. When they are mature enough, you may consider changing this.
On their own, these won't do anything to prevent your kids from accessing adult websites or age-inappropriate content, but they will stop a lot of tracking that occurs simply by visiting websites (those nefarious "cookies" you are always being asked to accept). Popular web browsers with good track records include: Brave, DuckDuckGo, Firefox (believe it or not), Mulvad, Tor Browser, and many others. Do your research. I, personally, use Brave.
VPNs can be pricey and aren't entirely necessary. I do not use one but they do add a layer of security. VPNs work by encrypting your internet data, changing your internet IP address (obscuring your physical location), and telling websites that you are located somewhere in the world other than where you really are. This means that mobile games, Google, and even your Internet Service Provider will not be able to request data from your home network to geolocate you, or see what you're doing online. However, you are trusting a third-party with your internet content. When you use a VPN, all of your internet traffic goes to them first, and is then bounced around between their servers before they actually retrieve the internet content you're requesting. This does not make it impossible, just difficult, for bad actors to trace your internet activity back to you. Remember that most bad actors want easy marks, like Grandma walking down the street. They don't want to rob a bank or casino. These can still be robbed, but a VPN is like a bank vault––hard to get into.
Access your Wi-Fi router from a computer and look for an option to "block" websites flagged as "adult." If you do not have this option, you can often create a custom list of websites to block. Otherwise, get a new router that explicitly advertises "parental controls." You can also block access to app stores if you so desire. These parental controls can only be changed by whoever has the "administrator" password. Simply having the Wi-Fi password will not allow your kids to change any of these settings.
Kids hate this. Oh well, you're a kid! If you access your Wi-Fi router from a computer, you can see all the internet traffic of every device connected to your home internet. It is even possible to set up "alerts" for when someone accesses the internet at a certain time of day. For example, 1AM on a school night. Some routers also allow you to disable the Wi-Fi between certain hours. Since you have administrator access to the Wi-Fi, however, you can set up a separate password that allows you and your spouse to continue to use the internet during these hours. Because you are an adult, you understand the consequences of late-night internet usage. Kids tend not to.
Virtually every Wi-Fi router today allows you to set up your own security protocols and firewalls. There are even third-party options which you can purchase that automatically compile lists of known adult and malicious websites that attempt to steal your data. Once you pay for the service, your home network will automatically block all of these websites. If you want to set up your own firewall to filter malicious "DNS requests", look into setting up Pi-hole on a Raspberry Pi. If you want an easy third-party alternative to doing it yourself, consider a service like AdGuard Home. I own a router which has this service pre-installed. It, and others, can be purchased from Amazon and electronics stores. Both of these options and many others not only block age-inappropriate internet traffic, but also block most ads. You may be interested in these for that feature alone. Do your research and find what's best for you.
Key Problems
The bottom line is this:
The bill's proponents ought to reconsider when private entities "need" or "must" acquire personal data. This has historically been determined by the market through the private choices of individuals. But this bill would require it, and leaves no possibility for consumers to pressure private entities to change their data collection policies.
Changing companies' data protection policies thus becomes a collective action problem which can only result from a change in law. This is notoriously difficult for large, dispersed groups and unlikely to succeed.
The State of Technology
P.S.
When talking about bad actors, it's important to understand just how capable they are of disrupting people's lives due to how advanced the technology around us has become.
Everyone is aware of how high-tech cars have become in recent years. They all have power windows, automatic transmissions with "fine-tuned" computer chips, backup cameras, heated, cooled and powered seats, and even parking assist features that can turn the steering wheel and reverse the car into a tight parking spot. Teslas and Waymos (self-driving Ubers) are quintessential examples of this.
I think you all should know that these cars, and many other luxury cars, also include GPS and radio. By virtue of that fact, radio communications can be used to start or stop these engines via the car's "remote start" technology, and the steering wheel and gas pedal can be controlled remotely.
The CIA can hack these cars. We know this from the Vault 7 documents released by CIA whistleblower Joshua Schulte.
We also know that the CIA, in addition to the FBI, NSA, and every other intelligence agency, can also access your home network and take control of almost any internet-connected device if you do not have the proper protections in place. Your Smart TV, your cellphone, your laptop, and all of their integrated microphones and cameras can be remotely accessed by these agencies.
Everyone will remember the scandal (which has since been maligned as a conspiracy theory by propagandists) surrounding Amazon's Alexa, where it was revealed that the FBI was listening through these devices. They still are, by the way.
All of this is relevant for 4th amendment reasons, but the main point I want to make is that for tech-savy criminals, this is easy stuff. And that's why data breaches occur so often.
If you prefer the pastoral life and can do without the internet: one, I envy you; but two, you're not reading this anyway. For the rest of you who can't do without the internet and enjoy living in a high-tech society with all its conveniences and benefits, take the time to mitigate the risk of having an online presence by bolstering your privacy. You and your families will benefit.
If I had to recommend three things for all of you to do, it would be to switch to a privacy-oriented web browser (free), switch to a privacy/DeGoogled phone, and get a new router with parental controls.
Interested in the content of this Article?
Reach out to the MacIver Institute to aquire more information