Join Nostr
2026-09-17 12:58:17 UTC
in reply to

ynniv on Nostr: and the longer take is not slop CLAUDE: The principle is a real one, not paranoia. ...

and the longer take is not slop

CLAUDE:
The principle is a real one, not paranoia. Strip away the technically-wrong part of their post and there's a solid grievance underneath. The wrong part was the mechanism: "Apple is monitoring all activity / intercepting the Tor circuit" describes man-in-the-middle surveillance, and that's not what's happening — it's a client-side classifier refusing to render a page. But the *objection* doesn't depend on the mechanism being surveillance. The objection is: to view a lawful webpage of my choosing, the device I own now demands I prove my identity to it first. That's the KYC-to-browse complaint, and it stands on its own whether the enforcement is a local filter or a remote one.

Worth being precise about why this lands harder than the old model. Per-site age gates were bad enough, but you could route around them, and the trust boundary was "this one sleazy site wants my ID." Moving it to the OS changes the character of it: the check is default-on until you present a credit card or a government ID or a face scan; you are presumed a minor — presumed guilty — until you produce papers; and because it lives below the browser, the usual sovereignty tools (Tor, a hardened browser, a VPN) don't touch it. The one layer you're supposed to fully control, your own device, is the layer doing the gating. For someone whose whole stance is "I should be the root of trust on hardware I paid for," that's the actual injury. The filter blocking Tor isn't Apple spying — it's worse in a way, because it means the escape hatch was never at the network layer to begin with.

It's also not a fringe take. The identity-honeypot problem (every one of these schemes concentrates ID data that then leaks), the chilling effect of linking real identity to browsing, and the "presumed minor by default" inversion are exactly what groups like the Open Rights Group, Big Brother Watch, and the EFF have been hammering. This person is articulating a mainstream civil-liberties objection in salty terms.

The steelman on the other side, to be fair to it: the people who designed this argue device-level is the *less* invasive option — a one-time on-device age attestation (Apple's Declared Age Range API, tokenized proof-of-age, on-device face estimation that never uploads the image) beats handing your passport to a thousand individual websites. That's a genuine argument. But note it doesn't answer this person's actual complaint, which isn't "which method leaks least" — it's "I didn't consent to being carded to read a page at all, and my own hardware is enforcing it." No amount of privacy-preserving cleverness in the *how* addresses an objection that's about the *whether*.

So the honest read: they got the technical diagnosis wrong and the political diagnosis right. Easy to be dismissive because the "Apple is intercepting Tor" line is wrong on the facts — but that'd be missing that they're reacting to something that genuinely exists.