Age verification is rapidly emerging as a central regulatory instrument for protecting minors online, with several jurisdictions mandating its deployment for access to adult and pornographic content. This regulatory direction raises significant privacy concerns, as it risks binding sensitive content access to identity-related attributes. It also introduces security risks, since age-verification mechanisms are often outsourced to third-party providers with limited transparency into the robustness of their verification processes. In this work, we conduct, to the best of our knowledge, the first exploratory security assessment of regulation-mandated age-verification mechanisms deployed by adult websites. Rather than treating age verification as a purely regulatory question, we empirically examine whether current deployments provide security guarantees commensurate with the privacy risks of relying on sensitive identity-related data. Our methodology combines ecosystem mapping, adversary modeling, and empirical testing across four countries, covering document-based verification, biometric age estimation, indirect signals, and website-workflow integration. Our results reveal systemic weaknesses across mechanisms and integrations under realistic threat assumptions, including failures against low-cost, widely accessible attacks. Finally, we derive concrete guidelines and design directions for mitigating the security and privacy risks exposed by current age-verification deployments.
翻译:年龄验证正迅速成为保护未成年人上网的核心监管手段,多个司法管辖区已强制要求部署该机制以访问成人及色情内容。这一监管方向引发了显著的隐私担忧,因其可能将敏感内容访问与身份相关属性绑定。同时,由于年龄验证机制通常外包给第三方提供商,且验证流程的稳健性透明度有限,也引入了安全风险。本研究据我们所知首次对成人网站部署的强制监管年龄验证机制进行了探索性安全评估。我们并未将年龄验证视为纯粹的监管问题,而是通过实证检验当前部署方案能否提供与依赖敏感身份数据所伴生隐私风险相称的安全保障。我们的方法论涵盖生态系统映射、对手建模及横跨四国的实证测试,涉及基于文档的验证、生物特征年龄估计、间接信号及网站工作流集成。研究结果显示,在现实威胁假设下,各机制及集成均存在系统性弱点,包括无法抵御低成本、易获取的攻击。最后,我们针对当前年龄验证部署暴露的安全与隐私风险,提出了具体缓解指南与设计方向。