After Discord fiasco, age-check tech promises privacy by running locally. Does it work?
On-device face scans and cross-platform age keys decrease privacy risks, but trust issues abound.
https://arstechnica.com/tech-policy/2026/03/after-discord-fiasco-age-check-tech-promises-privacy-by-running-locally-does-it-work/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

@arstechnica

“We had a couple of days of intense attempts to try and breach our systems, but these attempts were thwarted, and the attack lost momentum,” Tewari said.

I hope people do continue attacking these systems just to shut this smug fucker up. They faced a small attack (a couple of 10s of people in a GitHub thread having a crack at it). Imagine facing the sort of resistance that Google/YouTube faces with yt-dlp.

Client-side solutions that run in non-attested environments will always be broken. Always.

@arstechnica My 10yo kid had to pass face scan age verification for a tech device from Meta that he had bought. Asked his 13 yo brother to use his face instead. Passed as being 18.

*thumbs up*

@arstechnica I don't give a shit what anyone promises. Because #enshitication is a real thing. Just because something starts off locally doesn't mean that something won't change and they'll just update the terms and services agreement. Give these companies no quarter. Age verification can fuck off in general. Now if you want to prompt for my age sure fine I'll basically say I was born in 1926.
@arstechnica or hear me out. We start taking the kids of parents who don’t supervise their kids and they end up being harmed/groomed/exploited. BRING BACK THE FAMILY DELL