This is an issue with age assurance that goes well beyond just verifying age, and is undoubtedly viewed as a fringe benefit of age assurance for those wishing to deanonymise the internet. There's obvious problems with this beyond just "can't ban evade anymore". Authorities or intelligence can run bulk hashes against sets of IDs to effectively deanonymise all accounts.
The question here is, does Discord do the same thing for any or all of the selected options? Or is identity data full well and truly purged once the outcome is determined - no hashing, nothing retained other than the result?
That made me feel better that Discord didn't need to store my ID or video of my face, and was only storing the results of some analysis and not the inputs.
For reference: https://www.ndtv.com/world-news/dog-photos-vpns-fake-ids-how...
- give us your ID
- give us your biometrics
- give somebody, not necessarily Discord, a valid credit card
That's sll of the paths.
The issue comes down to if governments accept such a (urgh) comparatively lax implementation. It's pretty clear to me that the primary purpose of these laws are entirely to... force all citizens to identify themselves across the internet for the purpose of profile building, and nothing to do with child safety.
So as implementations go; this one is pretty decent. We should stop governments from passing these darn laws though.
I'd like to see details about their model there, but account age is at least better than a lot of systems like steam are doing for this.