Showing posts with label age verification. Show all posts
Showing posts with label age verification. Show all posts

Thursday, January 17, 2008

The JIRA issue that won't die

In it's long and distinguished career, JIRA issue Web-382 has gone from being a carefully worded attack on a group somebody didn't like, to a moderately serious proposal, to something almost workable and finally back to being a carefully worded attack again.

So why won't this issue die? Quite simple. The original poster won't let it.

And of course, the original poster just has to turn out to be Prokofy Neva, perhaps the most outspoken person in Second Life's history. Prokofy is an unbeaten expert in turning things around and beating people with slightly different things while pretending those were the original things, with being the schoolteacher disciplining recalcitrant schoolchildren and with the most interesting set of double standards which she will never admit to.

Let's have a look at the wording of Web-382 for a moment:

It is too easy for feature suggestions and bugs to be prematurely closed.


This must surely be the point at the heart of the debate, and this point I don't have any problems with. But she goes on to say:


A small group of coders here on JIRA are constantly closing and resolving issues in the belief that they know best, yet they do this at times without consent and support. This results in undue pressures and discontent, and makes it very hard for the author to re-open his proposal in the face of hostility. By providing the authors with a feedback period some of this can be avoided and if deemed appropriate the issue in jeopardy can be kept open.


And here is where the problems and the biases start to come out. It all revolves around the idea that she has of this "feted inner core". Now, she's not big on conspiracy theories. Just ask her if the US government were behind 9/11. But when it comes to Second Life, there's definitely a cabal and there's definitely a 'feted inner core'. Naturally, she's a target for this group because she's the big Defender of the Second Life Freedoms. So, if she opens a JIRA ticket, and somebody closes it, it's because they are in one of these tin hat groups.

JIRA-382 has ceased to be a productive discussion. At one point I backed her into a corner which she got quite vicious about. Part of debating a propsal where the consequences could be unexpected is to consider hypothetical situations. I posed two: Firstly, if someone were to directly or indirectly insult another person (for example an immediate example of Godwins Law) then where would the JIRA stand on closure? Linden Labs simply don't have the manpower to spend a lot of time on the JIRA and this means that if other residents don't tidy things up (closing duplicates or pure waste of time tickets) chances are nobody will. If issues can't be closed without the permission of the original author, and that author purely wants to use the JIRA like a soapbox or to grief someone else, that ticket isn't going to get closed. The author will just re-open it. 382 itself is a perfect example of that. Secondly, if someone does decide to deliberately misuse the JIRA, and Linden Labs don't notice - who is going to police it?

So now I've been branded a troublemaker too. I'm not sure if I'm supposed to be in the 'feted inner core' or the 'coders cabal' - probably the latter - but regardless, the fact that Prokofy Neva has double standards isn't supposed to be relevant. What do I mean by double standards? Well, this self proclaimed champion of SL civil rights holds two very different views about age verification at the same time:

So a list of adult consumers with their avatar names and RL birthdates will be in the hands of one of the most aggressive and persistently nasty BDSM types in Second Life. Maybe the BDSM community won't care -- they like abuse, and maybe even this kind of RL abuse of their privacy. But as it spreads, and begins to be used by any club, or any rental, or anybody who just wants to be free from the plague of kids harassing and griefing you, it could become the device of choice, as it advertises being "better" than Integrity by not taking your RL name and drivers' license or Social Security number.


She gushes in her hate filled blog entry about a resident-created age verification system called agelock. But then she immediately goes on to say:

Hey, give me Integrity *any day of the week*. They are a real-life registered company with a business reputation and a bottom line to fulfill and a board of trustees. If I fear they've abused my trust in taking my info, I can protest -- with lawyers, by getting Congress involved, by getting the media on it. I can't do that with these anonymous avatars in Second Life!


I've got news for you, Prokofy. You can't. Nobody can. It comes down to an issue of contract law. We have a contract that we agreed to with Linden Labs when we all clicked the "I accept" on installing for the first time. That contract is enforceable. If Linden Labs breach it, ultimately they can be called to account for it in a court of law. We have no such contract with Integrity, nor do we have any idea what - if any - safeguards apply in the contract that exists between Linden Labs and Integrity and as such the very reason - unaccountability - that she cites for Agelock, also applies to Integrity. Yet she's passionately in favour of one, and passionately against the other. A double standard.


Ironically, the very reason Web-382 won't ever go anywhere is because the original author of it is the best example of why it should never be implemented. Somebody who absolutely MUST have their say, is abusive of others and won't let the issue be closed.

So I've called on Linden Labs to finally put an end to this self serving soapbox facade, by actually telling everyone what, if anything, they intend to do. Either to say "This part of the issue makes sense, we're looking at the viability of implementing it" or to outright say "this isn't going to be implemented, case closed." While I doubt they'll bother, it does show how badly the JIRA can be - and is being - manipulated for personal reasons, in an issue that simply won't die.

Friday, December 28, 2007

Could this be the most reliable form of age verification yet?

I have some of my best ideas while lying in the bath. This one came about as a result of me thinking that if I wanted to start a “mature” MMORPG, how would I go about age verification in such a way that it was the most secure and policeable ever? I then attacked it with two criteria: How would I implement it, and if I was deliberately setting out to abuse it, how would I do so?

And then it came to me.

What I would do would be to make a deal with a telephone service company that provided specialist premium rate numbers. I’d tie my computer system to theirs in a similar but more extensive way that Ebay and Paypal use. The age verification routine on my website would give the person about to go through the check a unique identifying number. It would also feature prominently the warning “CALLING THE AGE VERIFICATION NUMBER WILL COST $5 PLUS APPLICABLE LONG DISTANCE CALL CHARGES. YOU ARE RESPONSIBLE FOR THIS CHARGE, AND BY CALLING THE NUMBER AND PROCEEDING YOU ACCEPT LIABILITY FOR ALL CHARGES RESULTING FROM THIS CALL.”

Here’s the thing. The number it gave me to call and give my identification number that I’d just been given can ONLY be called from a domestic residential landline. It can’t be called from a mobile, and it can’t be called from a public callbox or a business landline. It can only be called from a domestic landline, which, correct me if I’m wrong requires the owner of the landline to be over the age of consent in their country.

So, I call the number, and I enter my code, and I’m age verified. I haven’t passed ANY identifying information that could be abused to any third party, and by verifying that I called from the number at that address, I do provide a method for legitimate law enforcement to track me down should that ever be necessary.

Now here’s the kick. I know you’re all thinking “How does that prevent my 12 year old calling the number?” Well, the answer is, it doesn’t. BUT, when the parent/owner of the bill gets their monthly telephone bill, ONE call costing at least $5 is going to stick out like a sore thumb. What happens if my 12 year old has done this? Here’s part two of my idea.

Say my underage son/daughter has done this, and I get my bill and find out someone made a call to “ age verification” which cost me $5. I contact my phone company, and ask who the hell this is? They do a check their end, and they say “Well, we can’t refund the money, but there IS an abuse line on their record for people who feel that they’ve been the victim of fraudulent use.” I call that number, and register my telephone number, then I go and ground my kid.

My kid throws an almighty sulk, and decides that while grounded they’ll play the mature game. They go to sign on – and their account has been banned. Raising a query about the number automatically results in an account ban for the misusing account. Furthermore, the telephone number is ALSO banned, so when (s)he goes to open a new account and tries to age verify again, the number won’t connect from that landline. Without it connecting, they can’t verify.

I’m not claiming this is foolproof. I don’t know any system that WOULD be foolproof and implementable across the globe. But as far as I know It’s the best I’ve seen to date… I would welcome feedback on this, and if anyone wants to knock the idea around a little, I think this is a firm foundation for a secure method of age verification that doesn’t require giving away potentially illegal information, it would work worldwide, it wouldn’t require very much in the way of equipment to make it work and I recommend this idea to the population!

Monday, December 10, 2007

Robin Linden confirms today, what Daniel Linden said a while back.

Taken from today's post, written by Robin Linden:

Voluntary Status
As currently implemented, age verification and parcel flagging to create adults-only restricted areas rely completely on voluntary participation. However, there is no assurance that either feature will always be voluntary for all Second Life Residents. It’s possible, for example, that we could be required at some point to make one of these features mandatory for the citizens of a specific country. Should that happen, we will do everything we can to provide maximum advance warning.


This echoes Daniel Linden's position from way back, that they'd make Age Verification mandatory across the board if they felt self-regulation had failed.

From Aristotle/Integrities point of view, this is an absolute goldmine. They collect a huge amount of new information, then if at some point LL goes bust they're free to do whatever they want because of the clause in the ToS that says in the event of LL's bankruptcy, there will be no liability for misuse of any data collected during SL's existence.

I may be a little paranoid, but I can actually picture Aristotle being poised to make a grab for ALL the data for a sum of money, in the event Linden Labs goes into receivership. From their point of view, it's a win-win situation.

Hat tip also to Nika Talaj, who points out:

May 2007:“[10:12] Daniel Linden: it’s vaulted to provided a government-required audit trail for two years, but neither Linden or Integrity can access that data unless an audit is initiated.”

Which is essentially my beef with them about the PATRIOT act. They HAVE to store this data. Just dumping it is against the law. You can't claim that just because it's 'sealed in a vault' it doesn't exist. Either it's being retained or it's not, and by the PATRIOT act's requirements it has got to be retained, for two years. Vaults can be cracked. A lot can happen in two years. We've been lied to a LOT by Linden Labs over this. Our details will be retained for two years, as is the law where Linden Labs is.

Sorry, but no. This won't work voluntarily, at which point they'll make it mandatory. Then push will come to shove, and those who are serious in their threat to leave - myself included - will do so. At that point, either LL will survive, or it will fold. If it folds, I'm betting Aristotle will get all the data that's ever been held by Linden Labs in whatever form, and hold a bidding party over who gets it first.

This isn't the way to treat your customers, Linden Labs.

Saturday, December 8, 2007

Age Verification argument rages on

There seems to be three camps developing among residents with reference to age verification.

The first want it, have done it (or not, depending on whether Integrity actually has their information) and are annoyed at everyone else who doesn't want it.

The second is those who are generally okay with it. These are normally non-US residents whose only reservation is whether or not they are breaking the privacy laws in their own countries. More often than not, the age verification process fails for them anyway, but they're willing to try it.

The third camp is the one that I - and the vast majority of Residents - are in. That is, we don't want it, we won't use it, we won't flag our land and we'll inform relevant authorities where we see breaches of the law. In my case, since I live in Canada, I don't break the law if I voluntarily give my Social Insurance Number (SIN) to Linden Labs or Integrity, BUT, if I choose not to, Linden Labs DO break the law in Canada the moment that they deny me access to something on the grounds I haven't given my SIN number to them.

A pattern is beginning to emerge about Integrity's database. A number of people have failed to verify with their current data, but have managed to verify with data several years out of date. This indicates that Integrity are gathering public records to add to their database, but these records are often out of date. In the UK, for example, they buy data from the credit check company Equifax (which performs credit checks on consumers) however, Equifax only have data about those who have applied for credit in one form or another, or who have home facilities. Take my 42 year old brother, a sad individual who still lives with his parents. He's never applied for a credit card, hasn't bothered to tell the Driver and Vehicle Licensing Agency the last three or four times he's moved house, doesn't bother with bank accounts (he lives off welfare, cashing his cheque every two weeks at a post office who know him and never bother to ask for ID) - He wouldn't be on Equifax's database. He holds a driving license and passport, but has never had the internet at home. He is on the electoral roll, but the list that is not available to the general public (only available to government bodies).

As a test, I asked him to try age verification. Surprise surprise, it failed, despite the fact that the data he provided was correct. However, what was most interesting was he provided state information (passport number and driving license) - which would NOT normally be available to anyone but the UK government. It wasn't in Integrity's database. Which leads me to have serious doubts that their claims their data is taken from governments worldwide is genuine.

To me, Integrity has always seemed like a data mining company, that gets its profits by acquiring tiny pieces of the huge jigsaw that is a persons life, putting those pieces together and selling the completed picture for far more than the individual pieces cost. By age verifying, what a person actually does is to alert Integrity to their existence. Nobody has been able to find a privacy policy for Integrity, but my guess is that it's something like the policy for facebook; by providing them with ANY information, you expressly authorise them to collect any and all information they can about you, including but not limited to, credit card data, bank data, address data, religion, voting preference, membership of clubs etc etc. In other words, anyone trying to age verify with Linden Labs systems, whether they pass or fail, is actually authorising Integrity to start data mining on them. Again, this IS only my guess, but until someone can find a privacy policy I'm standing by this opinion, bearing in mind the discovery that it was indeed the case for Facebook.

And this is what makes it dangerous. Particularly the section in Linden Labs own terms of service, that states in the event of bankruptcy, Linden Labs can no longer be held responsible for anything done with ANY data collected by the Second Life system. Linden Labs remains completely silent on the questions being thrown at them by residents along the lines of "What guarantee do WE have that your third party company (Integrity) won't misuse or sell our information." And the answer to that is simple. None at all.

Looking at it from a legal point of view, a resident makes a contract with Linden Labs when they sign up, for the provision of a service called "Second Life" in return for complying honestly with their terms of service (it's far more complicated than this, of course, but this is what it boils down to in its simplest form) - This means that the resident, as a consumer, and Linden Labs, as a service provider, can hold one another liable in the event that one breaks the conditions. As it's part of the terms of service that users of the adult grid are over 18, anyone who isn't and uses the service is in breach from the moment they log in for the first time. Bringing a third party into it, however, muddies the waters.

Since a resident has not agreed to anything with this third party, there is no contract, and nothing to regulate the residents behaviour toward the third party or the third parties use of any collected residents data. Effectively what this means is a resident is perfectly at liberty to be totally dishonest with the third party, because there's no agreement to stick to, but it also means the third party is equally at liberty to do whatever the hell it wants with whatever data it does get provided. No agreement, no contract, no protection.

Some Residents will sign up to age verification right away (and indeed, some already have). Some will be willing to sign up when the database is more complete and they're likely to be on it. Most will refuse point blank to give this data. When push comes to shove, and it becomes mandatory, Linden Labs will risk their existence as a corporate entity on getting enough people to use the system. Ultimately, if enough rebel and leave, the costs of running Second Life will rapidly overtake the revenue - at which point, bye bye Linden Labs.

In closing, try this for a bit of fun. I created a facebook based on my best friend from school's details, except in the facebook account she lives in Canada, has a much more glamorous job, is a member of a number of respectable organisations and is most definately over 18. I created this facebook account when Age Verification was first being discussed for Second Life, so it's a over six months old now. Using a fictitious Ontario driving license number and a fictitious passport number, both authentic in the layout of their numbers and special characters, I tried to take her through Age Verification, using the same details with Integrity as I had put on her Facebook profile - and passed, proving that one of Integrity's sources is indeed facebook. The only problem with this is - she doesn't actually exist as a Canadian citizen, and her birthdate as given in her facebook account is one day wrong from her actual birthdate. Also, her address is the middle of a cemetery, but the postcode and street number do exist.

She's now verified. The thing is, she doesn't actually exist (with the details I provided to Integrity) so she should not have passed the age verification. I'm betting somewhere there's a very puzzled computer failing miserably to put together the missing pieces on her. This just shows how much of a sham Integrity's system is, and in my mind vilifies my position: I'm not using this system, ever, and if it gets made mandatory, I'll say goodbye to Second Life.

Wednesday, December 5, 2007

Another nail in the coffin

The storm has once again broken out on the official Linden Blog with the announcement that age verification will be introduced with viewer version 1.18. Predictably, Linden Labs have released this well before it's ready (as usual) and there are a mass of problems with it, even if you don't count the fact that the actual age verification system doesn't work.

Firstly they've bought a registered digital certificate with their entire domain in it, which isn't accepted by most modern browsers. Firefox in particular refuses to take "secondlife.com" as valid when it's visiting a site where some of the features in a page are secure and some are not. The result of this is that Firefox displays a warning that the certificate may not be genuine, because some of the content comes from http: and some comes from https: - users aren't told by the browser what the difficulty is, only that the certificate is not fully valid to cover the page that is being loaded, but this is the page that they are being asked to put their personally identifiable information on - not a good sign.

Secondly, it's illegal in some countries to provide this information, and this means that even if someone does so it can't legally be verified. Aristotle/Integrity will add it to their database, but they have no means of verifying it. Although they claim to have data from all over the world, I do seriously have doubts about the legality of verifying such data.

Thirdly, 90% of Second Life users DO NOT WANT THIS. Some - myself included - won't be able to verify anyway, due to things like only just having emigrated from one country to another. When I came to Canada, I gave my UK license to the Ontario ministry of transportation, who then issued me with a driving license number in Ontario - but if you cross reference my driving license with any other database, you won't find a match, because as of yet I still don't have a Canadian passport. So you can't check my Canadian driving license against my UK passport because they don't share that information, and you can't verify my UK license against my UK passport because my UK license has been canceled due to having an Ontario license instead. So even if I wanted to do this, I'd fail the procedure, and several people have already responded to the Linden Blog posting with tales of woe about using genuine details and being declined.

This will kill Second Life off. It's going to be the final nail in the coffin. As sim owners are threatened with banning for not marking their entire sims as "adult" just because one vendor, somewhere on their sim, sells a prim-penis or cage, so the revenue from these land owners will die. As organizations like CARP can't raise their tier because half their members no longer play owing to either being against age verification altogether, or unable to verify - so those sims will also vanish because their owners can't afford to pay tier. Newcomers to Second Life will be asked to age verify immediately or threatened that they can't see some content, and either they'll refuse to verify and not sign up, or they'll fail verification and not sign up, so the new revenue stream will dry up.

Seriously, Linden Labs, you could achieve a much better method of disclaiming responsibility for underage misuse of the grid if you made everyone type a declaration manually into a textbox. Something along the lines of "I hereby certify that I am the account holder, over the legal age of consent in my country, and absolve Linden Labs and all their employees and representatives of responsibility for any actions that I may engage in when linked to this service." Granted you couldn't sign it, but if anyone accused Linden Labs of letting underage users in, what's the difference between someone typing that sentence into a box and someone providing details when you can't see that person? How does a child with their parents driving license and a child entering this paragraph differ?

Age verification cannot work over the internet. Not with the current technology. Maybe in years to come when everybodies details are on computer, and you can verify yourself by fingerprint, retina scan or facial scan, then there would be a foolproof way of making sure that an internet user was who they say they are, but that time isn't yet, and probably won't be for at least a decade. Even then it will be America, Canada, the UK and other such countries that will get it first, with other countries lagging behind by many years if not decades.

In the meantime, Linden Labs just banged another huge nail into the coffin that Second Life is destined to be buried in.

UPDATE: Take a look at this site, published by the Government of Canada - it proves that what Linden Labs is asking for is NOT something the Canadian Government agrees with:

The Personal Information Protection and Electronic Documents Act (PIPEDA) sets out ground rules for how private sector organizations may collect, use or disclose personal information in the course of commercial activities.

Since January 1, 2001, the Act applied to personal information about customers or employees that is collected, used or disclosed by the federally-regulated sector in the course of commercial activities. It also applies to information that is sold across provincial and territorial boundaries. As of January 1, 2004, the Act covers the collection, use and disclosure of personal information in the course of any commercial activity within a province, including provincially-regulated organizations, except in provinces that have enacted legislation that is deemed to be substantially similar to the federal law.

Under the new law, organizations like banks, telecommunications companies and airlines cannot require you to consent to the collection, use or disclosure of your personal information unless it is required for a specific and legitimate purpose.

This means that unless an organization can demonstrate that your SIN is required by law, or that no alternative identifier would suffice to complete the transaction, you cannot be denied a product or service on the grounds of your refusal to provide your SIN.

In other words, if Linden Labs refuse me access to a SIM on the grounds I won't provide my Social Insurance Number to them, they are committing an offense by Canadian law. And why is it so important?

Computer technology makes it possible to use the SIN to find and match your information from one database to another; without your knowledge, a detailed profile could be drawn about you. This amounts to "data surveillance" or monitoring of your daily life, which can pose a serious threat to our privacy and autonomy.


I don't see why other countries wouldn't have similar legislature.

Friday, November 23, 2007

Fancy a new viewer?

It hasn't taken long for the open source community to rip the Second Life viewer to bits and learn how to modify or even delete the bits they don't want.

Nowhere is this more evident than the BDSM community. Marine Kelley's new viewer is a variant that works with scripts available for free from her shop, designed to compliment her existing range of, erm, toys. The viewer reacts to the scripts by removing items from the menus and pie menu that appear when you right click the avatar. It's aimed at "hardcore" BDSM players (though how you can be hardcore when it's your pixellated avatar that's getting the whipping, not you) who want that little bit more realism. Drop the script into a ballgag, and you can't speak through that ballgag on the open channel. Not 'can't speak by mistake', but viewer-enforced can't speak at all. Drop the script in a set of cuffs or other restraints, and the "detach from avatar" options all vanish. If you get locked in, you're locked in, and you can't get out from this viewer.

It's an interesting new development, certainly far from anything Phillip Rosendale ever dreamed, and I can see similar developments coming in the not too distant future. Just today the furry community was polling its membership about disabling scripting and building to anyone outside their group; the next logical development from that might be a viewer that has an identification string that an in-world item can ask for, and sends home anyone that doesn't have the FurLife Viewer. I can see it coming, and it wouldn't be too hard to do.

Of course, this makes a mockery of age verification, since viewers will be able to ignore parcel flags, which makes you wonder why Linden Labs are still talking to Integrity at all. More ominously groups might be able to use it to keep themselves underground and away from the prying eyes of law enforcement, but that's technology for you.

The pandora's box of Open Source Second Life has been opened. I wait with interest to see what it lets out!

Friday, November 9, 2007

Prokovy goes off on one again

It's been interesting from time to time to see what recognized antagonizer Prokovy Neva thinks of various things going on in Second Life, but even I was surprised by her rant about the Agelock system I talked about in my last blog entry.

His [Benjamin Sycophanske, a favourite ranting target] latest gushing excess is of a new ugly and vicious system called AGELOCK. I'm not surprised that this awful new invention on the SL landscape comes from Allana Dion and Jamie David, as we know from long, long exposure to their manipulations, power-plays, and shenanigans on the old official LL forums, Second Citizen, and on this blog, that they are hugely aggressive and persistent.


When I spoke to Jamie David initially about Agelock, he seemed pretty proud of it but definately didn't come across to me as 'aggressive'

So a list of adult consumers with their avatar names and RL birthdates will be in the hands of one of the most aggressive and persistently nasty BDSM types in Second Life. Maybe the BDSM community won't care -- they like abuse, and maybe even this kind of RL abuse of their privacy. But as it spreads, and begins to be used by any club, or any rental, or anybody who just wants to be free from the plague of kids harassing and griefing you, it could become the device of choice, as it advertises being "better" than Integrity by not taking your RL name and drivers' license or Social Security number.

Hey, give me Integrity *any day of the week*. They are a real-life registered company with a business reputation and a bottom line to fulfill and a board of trustees. If I fear they've abused my trust in taking my info, I can protest -- with lawyers, by getting Congress involved, by getting the media on it. I can't do that with these anonymous avatars in Second Life!


And this seems to be the crux of the matter. What the extremely long rant boils down to are two essential points:

1. Nobody should touch this because it doesn't have the official "Prokovy Neva seal of approval" - mainly because she doesn't seem to like the authors, rather that whether the idea of the agelock system has merit or not.

2. Because Prokovy Neva trusts Integrity/Aristotle, so should everyone else.

With the latter part of her comment, I actually laughed when I read the part about complaining to congress. Integrity/Aristotle provide detailed information to congress, why the hell would they take any notice of someone's complaints?

Let's take this extreme example of how the information that Integrity collects could be harmful in the real world, and I have SPECIFICALLY steered clear of politics in this so that Prokovy has no excuse to label me a "lefty".

Let's says that I've given my detailed information to Integrity for age verification. They put it all on their database. But let's face it, Integrity is a data mining company - that's what they do, that's how they earn their money. So without telling me, what's to stop them also collecting information from second life that would be freely available, such as the groups that I'm in.

So for arguments sake let's say they do that, and find that I'm a member of a BDSM group in SL. That information then also goes down not only against my avatar name, but against my real life name.

Now in this little fictitious scenario, a BDSM hack magazine comes to Integrity hoping to drum up business, and buys a list of people who are members of BDSM groups. Shortly afterwards, editors are found to be peddling paedophilia, the place is raided by the police and FBI and gets shut down. In the raid their computers get confiscated, and subsequently datasearched. Now the legitimate law enforcement agencies find my RL details on the computers and suddenly I'm a suspect. Not only that but when I try to get a job that requires a background check, this gets flagged up and I'm turned down, and I don't even know the reason why.

Now, in this case the law enforcement agencies have got hold of my details doing their legitimate work - but those details should never have been there. I didn't give Integrity permission to resell those details, or our fictitious magazine permission to buy and use them. ALL of that happened behind my back.

And this is my main sticking point with the Integrity/Aristotle scenario. I agree with Prokovy to a point, that the government wouldn't need to buy that information off me because they already have access to it, but it's not the government I'm worried about. This is the flaw in Prokovy's main argument, because she claims this as a reason Integrity should be trusted. It's Integrity selling my details to anyone who comes up with the right amount of cash that is the major concern, not whether the government gives a crap about the details (because chances are, they don't).

Which is why alternatives need to be found. I've already said I don't think Linden Labs will go for this, but we do need some viable alternatives if we're going to stop them using Integrity. And I'd far prefer if the proverbial genie gets out of the bottle, all a company being able to harvest is "Untameable Wildcat claims she's over 18 and claims this as her birthdate" than detailed information that also contains RL details being available to the highest bidder.

Friday, November 2, 2007

Age Verification - The Residents Strike Back

Walking around SL earlier on I was given an item by an anti age-verification group I'm a member in. The item is called Agelock, and it works by combining a security orb type script with an offsite reference script.

Visitors to land with Agelock running on it will have their names scanned against a database Agelock keep, which contains just three pieces of information about an avatar. Their name, their date of birth and the magical checkbox they've agreed to check that says "Yes, I'm over 18." If they refuse to give this information, they'll be asked to leave. If they haven't left within two minutes the security orb part of the script will cut in and eject them using the teleport home option.

This again shifts responsibility to the individual avatar, rather than the land owner, and asks for nothing more than the same kind of "good faith" agreement that has been held binding for viewing adult content sites on the web.

As such, I think it's a good idea. I also think that Linden Labs won't go for it. Or at least won't abandon their own plans to use Aristotle/Integrity for age verification.

And I do still have a real issue with Aristotle/Integrity. For a start, I can see a million ways I could cheat the system. I hold a photocard license within Canada, but because of a change of address I actually have two licenses. And when they changed my address they failed to put the correct information on the new address, but since misaddressed mail gets put on the windowsill in my apartment block to be sent back in bulk by management, I still picked up the new license even though the details on it are wrong.

According to their site, the information required in Canada is first name, last name, date of birth, postcode and telephone number. Well, let's see now. I can go out to a store, buy a prepay phone and give false details to activate it, so that's no proof. I can make up a first name and last name, so that's no proof, and as long as my DOB is convincing how do they check it? As well, since I recently moved and could quite easily use my old postcode (even assuming I didn't use the net to look up a valid postcode and use that) so those details could be false too.

Which essentially leaves them with the checkbox that I effectively ticked when I agreed that yes, I was over 18 so they could go ahead and verify me. All the other details might be false. What kid do YOU know that can't worm that information out of an adult given the opportunity?

What I AM providing with the Aristotle/Integrity method is statistics for them to sell to political entities, who could use them anyway they damn well please. All I'm effectively doing for Linden Labs is allowing someone else to say "She's telling the truth" - which itself, to me, implies that Linden Labs by default will assume I'm a liar, this despite the fact that they have my credit card information and have successfully billed it in the past.

There is effectively no difference in the information Agelock is asking and the information Aristotle is asking, except Aristotle ask for much more information and advertise that they collect this specifically to sell to political entities. I would be extremely surprised if with my recent immigration and the chaos that the lost paperwork entailed, Aristotle/Integrity could get a perfect answer on me... but I'm certainly not willing to give them an opportunity to then sell that information to the highest political bidder.

To close, let me link a video that is actually published by Integrity for the purposes of drumming up business selling the information they are planning to use Linden Labs to collect. It's quite frightening just how much they are prepared to pimp out the information they get.

Agelock is a nice system, but I can't see LL using it. Integrity is not. Judge for yourself if you think your information is safe with them.

Monday, May 21, 2007

The contract is signed

Reuters are reporting that the contract between Integrity and Linden Labs was signed last Thursday. Effectively this means that time is up for suggesting alternative methods for age verification, and that Linden Labs haven't listened to us at all.

It remains to be seen how long it remains optional to give these details. In my many years of experience, I've seen it happen time and time again that something is introduced - normally for political reasons - as "optional" but has strings attached that really mean "mandatory". UK Identity Cards are a prime example. When the scheme starts, it will indeed be optional. Citizens will be able to decline an ID card - but what they have been hushing up as much as possible is small print in the legislation that states if you don't have an ID card, you have to surrender your passport. So if you ever want to travel, the ID card isn't optional, since possession of a passport will be dependent on "opting in" to have one.

Where, one wonders, do Linden Labs intend this Age Verification thing to go? What are the strings they're going to attach to it? The first one is obvious - adult content... But the definition of "adult" is not. Linden Labs seem to have been very eager to avoid a solid definition; could the reason for this be that they want it to be expandable? Today, young looking avatars - tomorrow, furries and any group they deem "unsuitable".

Linden Labs seem to be of the opinion that the Age Verification system should serve one primary purpose - to indemnify them from prosecution. But that's yet another can of worms. How far can it go, legally, to indemnifying them from content they host? Internet Service Providers - of which Linden could be counted one, being that they host a virtual world - and this means that they are ultimately responsible for any content they host. Age Verification won't change this. The original people caught by the German media were way past the age of consent; Age Verification won't change that either. Adults peddling in any kind of material deemed unsuitable in the country they live is still going to be illegal, and the hosting company responsible for making sure it's unavailable. Age verification won't change that.

The problem with hosting a cyberworld available to the entire globe is jurisdiction in law matters. Linden Labs are in a unique position here; what they're doing has never been done before. Integrity offers them the opportunity to comply with a number of law acts in America, but doesn't - some would say can't - offer to indemnify them against actions bought in another country. The downside of that is the apparent paranoia that is being handed down to the American people by their current government, with regards to personal data is not liked or trusted by their users. Even American users I've spoken too are angry about the data Integrity are asking them to hand over. Non American users are furious.

And indeed, there are still a number of issues that should be cleared up - (which, may I say, Linden Labs have not even TRIED to touch on thus far) - The first of which is security. Enough data was stolen from them in November 1996 for them to need to implement an emergency plan for credit card holders. They have to hold the personally identifiable details for two years to comply with the PATRIOT act. So far they've said nothing to reassure residents that they've done all they can to close the security loopholes the last hacker used.

Secondly, there's the issue of contracts. As residents, we have a contract enforceable by law, with Linden Labs. If Linden Labs do something questionable, we do have the courts to settle disputes. We have no such contract with Integrity. We may not even know if Integrity misuse our data until way after it is too late, and even then we would probably not have an avenue to seek any kind of compensation. In the case of none-US residents, this data (passport/national ID card/driving license number in full) represents a hitherto unseen amount of data to give over the internet - particularly just to play a game.

So, Linden Labs are going to start rolling age verification using Integrity out as soon as they possibly can. Many businesses within SL will have to flag themselves Adult to avoid the possibility of a widening definition resulting in bans. Before too long the grid will be more "adult" than mature or PG. And then Linden Labs will say "Well, the majority of the grid is adult, therefore the majority of users must be in favour of the grid being entirely adult, therefore from now on this isn't optional, it's mandatory."

Remember Thursday May 17th 2007. It just may have been the day that marked the downfall and eventual death of Second Life.

Sunday, May 20, 2007

The storm breaks

This morning there was discussion on the group "SL'ers against age verification" about child avatar sellers having their products and vendors deleted. Two were banned when they complained in the forums.

This whole thing seems to be spiralling out of all control. Ageplay is already banned, which is one thing, but to start banning the sale of child-like avatars is quite a jump in censorship. It's ominous to consider that people actually wearing such avatars could be the next victims, and then where will it end? Certainly the furry community is worried about this escalation. If one could get banned for wearing a human child avatar, how long until someone says "Furries yiffing is virtual beastiality - get rid of it!" and overnight wearing a furry avatar becomes a banning offense?

I chaired a general informal meeting (at which a few tempers ran high) this morning on Support for Healing island. General consensus was that we're FOR protecting people but AGAINST the methodology being proposed, for a variety of reasons. Linden Labs record of vault security being the main one, since they're required by the PATRIOT act to keep records for two years.

The major difficulty with the internet is that without being able to see someone, face to face, you're always going to be able to be fooled by those determined enough. What Linden Labs are proposing, won't stop those who are out to break the law - which is the very demographic they're trying to prevent.

Instead what they are doing is going to impact a number of people, and if they at some future point decide to make it mandatory, not optional... it's going to impact everyone on Second Life. And I still see absolutely nothing which makes me believe that they aren't going to make this mandatory sometime soon.

The meeting discussed the various options; the flaws in public notary were discussed, but no major new ideas were put forward. We reached consensus that the entire exercise is purely aimed at protecting Linden Labs, rather than being concerned with protecting the privacy of residents. It does seem to be a halfway measure, though, since rational adults would not let their children onto adult second life and irrational adults will just con the system whatever Linden Labs put in place.

If this latest development - the banning of some people who sell childlike avatars - starts to develop into something more sinister, it will only perpetuate the belief that Linden Labs are only doing this to protect their own backs. As for an answer - well, we're all still looking... but surely there MUST be a better way to trust your customers than to demand they hand over personal details... musn't there?

Friday, May 11, 2007

Here's the mailing list

In a conversation between two Lindens and a group of concerned residents, Daniel and Robin Linden were backed into a corner, and forced to admit that yes - data WOULD be stored... For an entire TWO YEARS!

[10:12] Robin Linden: Tao the data is never saved to be deleted. It’s matched only
[10:12] Daniel Linden: it’s vaulted to provided a government-required audit trail for two years, but neither Linden or Integrity can access that data unless an audit is initiated.

Here's the mailing list, folks! Who wants a copy?

Seriously, you now have to ask who can initiate an audit? Can the RIAA? Can the US Department of Homeland Security? Can the DoJ? What about law organisations in other countries - will they be able to request an "audit" so that they can keep track of what their citizens are doing? And how secure IS this vault, given that Linden Labs failed to protect credit card details last year?

Unfortunately, as time passed, more questions arise than get answered. Linden Labs in fact haven't made ANY attempt to answer residents concerns. Their latest blog entry on the subject once again repeats the same things "It won't be stored, it's entirely optional, it's only for adult content" - well, we now know the FIRST of these things is a lie. It WILL be stored, as is a legal requirement. The second is only true for the moment; watch this space for that changing. And just wait until the anti-furry brigade starts making noises and it'll be extended to all sorts of things.

I've seen many complaints about upcoming features in my time here, but NOTHING - absolutely nothing - has come close to this. Whereas normally 10-15% of the population complain about something new while 85-90% like the idea, here it's the other way around. 85-90% of the residents do not want to give their personal data to someone on a non-contractual assurance that it won't be given or sold or shared with third parties.

It now looks as if the Electronic Frontier Foundation is thinking about getting involved - Linden Labs, you're playing with the big boys now. There may also be European Union concerns about privacy... believe me, this is a can of worms you don't want to be trying to open.

To be continued.