There is missing a solution.
Give our personal devices have the ability to verify our age and identity securely and store on device like they do our fingerprint or face data.
Services that need access only verify it cryptographically. So my iPhone can confirm I’m over 21 for my DoorDash app in the same way it stores my biometric data.
The challenge here is the adoption of these encryption services and whether companies can rely on devices for that for compliance without having to cut off service for those without it set up.
I think this is what my German electronic ID card does. The card connects to an app on my phone via NFC, a service can cryptographically verify a claim about my age, and no additional info is leaked to the service provider or the government.
ISO/IEC 18013-5 (Personal identification — ISO-compliant driving licence — Part 5: Mobile driving licence (mDL) application) is a potential solution for this. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:18013:-5:ed-1...
It would allow someone with an mDL on their device to present only their age instead of other identifying information.
This kind of solution couldn't come soon enough. It will also enable us to verify humanity and have bot-free spaces on social media again. I wrote about this here: https://blog.picheta.me/post/the-future-of-social-media-is-h...
The solution has always been there: Assume everybody is an adult.
The only reasonable way to deal with children on the Internet is to treat Internet access like access to alcohol/drugs. There is no need for children to access the Internet full stop.
Internet is a network in which everything can connect to everything, and every connected machine can run clients, servers, p2p nodes and what not. Controlling every possible endpoint your child might connect to is not feasible. Shutting the entire network down because "won't somebody please think of the children" is not acceptable.
And, don't let them trick you. This is the endgoal. An unprecedented level of control over the flow of information.
The real problem with this is that the ultimate objective isn't age verification, it's complete de-anonymization. I think different groups want this for different reasons, but the simple reality is that minimizing the identify information transferred around is antithetical to their goals.