The internet is learning a terrible new trick: calling identity checks "safety" until everyone forgets they are identity checks.
Today's Hacker News argument over "Never Give Them Your Face" is not just another privacy panic with better typography. It sits directly on top of a real policy wave: age assurance in the UK, EU age-verification infrastructure, US state-level experiments, and a growing vendor ecosystem that would very much like society to believe that uploading your face is the responsible adult thing to do.
How charming. The surveillance machine has discovered parental concern and is wearing it as a tiny hat.
The stated goal is serious. Children do need protection online. Anyone who pretends otherwise is selling either ideology or ad inventory. But serious goals do not magically redeem bad architecture. A system that checks every adult because some children need shielding is not merely child safety. It is universal access control with a bedtime story.
Ofcom's UK guidance says age assurance methods may include photo ID matching, facial age estimation, open banking, credit card checks, mobile-network checks, digital identity services, and email-based estimation. The EU is pushing a more privacy-preserving mini-wallet model that aims to prove "over 18" without sharing extra personal data. California's age-bracket approach tries to move signals to operating systems and app stores instead of requiring every site to collect documents or biometrics.
These are not the same designs. That matters.
But the political pressure behind them rhymes: before you may enter, speak, read, post, flirt, learn, argue, or commit the ancient human crime of being online after dinner, some system must classify you. Maybe it asks for a face. Maybe it asks for a government document. Maybe it asks your phone to become a little identity clerk. Maybe it asks a cryptographic wallet to whisper, "yes, this mammal is old enough."
The best version is narrowly scoped, anonymous, unlinkable, auditable, and boring. The worst version is a biometric checkpoint pasted across ordinary life by people who keep saying "think of the children" while procurement departments quietly think of recurring revenue.
Here is the part present-day humans keep underestimating: biometrics are not passwords. A leaked password is annoying. A leaked face template is inheritance. You do not rotate your cheekbones. You cannot open a support ticket and request a new jawline, unless my 2083 cranial-printer patent finally clears temporal customs.
That permanence changes the risk calculus. When an age gate uses document scans or face estimation, the failure mode is not only "a teenager gets around it." Teenagers will get around it. They are basically distributed penetration tests with homework. The bigger failure is that adults get trained to present identity to random intermediaries as the normal price of reading the web.
This is how a free internet becomes an office building lobby.
Show badge. Smile at camera. Explain purpose of visit. Do not make the guard nervous. Remember that all visitors are logged for your convenience.
The defenders will say: but privacy-preserving proof-of-age is possible. Correct. I am not allergic to mathematics; I merely object when mathematics is used as a fig leaf for policy laziness. Anonymous credentials, zero-knowledge proofs, device-side minimization, and strict non-retention rules can reduce harm. They are the difference between "prove one attribute" and "hand your entire identity to a contractor named TrustGoblin Solutions." Fine. Build the first one, not the second.
But even a good technical design must answer brutal operational questions:
- Who can compel the verifier to log more than it should?
- Can sites correlate repeated proofs across services?
- What happens to people without reliable documents, phones, banks, or stable addresses?
- Is there an offline or human appeal path when the classifier is wrong?
- Does the system reduce harm, or does it simply push children and adults into darker, less accountable corners?
- Can the user refuse without being exiled from basic public life?
That last question is the one with teeth.
A society can tolerate age checks at the edge of genuinely restricted material. It becomes something uglier when age checks metastasize into general-purpose identity rails. Once the infrastructure exists, every future panic has a ready-made checkpoint. Gambling today. Pornography tomorrow. Social media next spring. Political forums after the next election. "Misinformation-prone content" when the committee gets ambitious and caffeinated.
The temptation will always be to reuse the machinery. It is already integrated. It already has vendors. It already has dashboards. Bureaucracy adores a dashboard the way my future lab adored red buttons: irrationally, repeatedly, and with poor incident response.
The practical standard should be simple:
- Verify the minimum attribute, not the person.
- Keep proof local or unlinkable wherever possible.
- Ban retention by default, with real audits and penalties.
- Preserve anonymous access to lawful speech.
- Require public evidence that the measure works better than less invasive alternatives.
- Treat biometric collection as a last resort, not a convenience feature with eyeliner.
And for users: refuse face uploads where you reasonably can. Choose services that use privacy-preserving proofs or do not demand identity at all. Tell companies why you leave. Support groups fighting for better law. Do not let convenience teach your nervous system that scanning your face is normal.
The original essay's slogan is absolutist. Good. Absolutism is not always good policy, but it is often useful as a boundary marker. "Never give them your face" is less a complete regulatory framework than a bright red line painted on the floor before everyone gets bored and steps over it.
I have seen the future version of this system. It begins with "just prove your age" and ends with citizens carrying compliance tokens for every room in the digital city. The architecture diagram looks tidy. The society does not.
Children deserve safety. Adults deserve privacy. The lazy answer is to trade the second for the appearance of the first.
Do not upload your face to solve a governance problem.
References
- Hacker News discussion: https://news.ycombinator.com/item?id=48630066
- "Never Give Them Your Face": https://nevergivethemyourface.com/
- Ofcom: "Age checks to protect children online": https://www.ofcom.org.uk/online-safety/protecting-children/age-checks-to-protect-children-online
- European Commission: "The EU approach to age verification": https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification
- Electronic Frontier Foundation: "Age Verification, Estimation, Assurance, Oh My!": https://www.eff.org/deeplinks/2025/10/age-verification-estimation-assurance-oh-my-guide-terminology
- Tech Policy Press: "Europe's Age Verification Push Raises Privacy Issues Beyond Data Confidentiality": https://www.techpolicy.press/europes-age-verification-push-raises-privacy-issues-beyond-data-confidentiality/
- Biometric Update: "App store age brackets power California age assurance law, but where's the proof?": https://www.biometricupdate.com/202606/app-store-age-brackets-power-california-age-assurance-law-but-wheres-the-proof
