Why can't I access certain websites without giving my ID to random companies?

Started by Fox, Mar 22, 2026, 06:56 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Why can't I access certain websites without giving my ID to random companies?   Views(Read 83 times)

Fox


Undertaker00

In the UK, access restrictions are usually tied to age-verification rules and ISP-level filtering. They're not random, they're there to enforce legal requirements around adult content.

If you're running into blocks, your straightforward options are give ID or find an easy way around it that a 5 year old could master.
(I'm helping/directing you)
It's only banter... mostly

Fan22

There's been a growing push for users to provide ID to access certain websites, especially around age-restricted content. On the surface, it sounds reasonable. Verify age, protect users, move on.

But once you look at the security and privacy implications, it becomes a lot more questionable.

The main issue is simple. You're being asked to hand over one of the most sensitive pieces of personal information you have to a website or third-party service you probably know very little about.

And history has shown again and again that even large, well-funded platforms get breached.

We're not talking about small leaks either. Entire databases containing personal information, emails, passwords, and in some cases identity documents have been exposed. Once that data is out, it's out permanently. You can change a password. You can't change your identity.

Another concern is data storage. When you upload ID, where is it actually stored? For how long? Who has access to it? Is it encrypted properly, or just sitting in a database waiting to be compromised?

Most users never get clear answers to those questions.

There's also the issue of trust. Many of these verification systems rely on third-party providers. That means your data isn't just being shared with one company, but potentially multiple layers of services behind the scenes.

Each layer increases the risk.

From a security standpoint, the safest data is data that was never collected in the first place.

That's why many people are uncomfortable with the idea of handing over ID just to browse a website.

A more balanced approach would be systems that verify age without requiring full identity exposure. For example:

One-time verification tokens instead of storing documents
Privacy-focused verification providers that don't retain data
Device-level or account-level age confirmation handled by trusted platforms

These approaches reduce the amount of sensitive information being passed around while still addressing the original goal.

At the end of the day, this isn't just about access. It's about risk.

Every time you upload personal identification online, you're making a trade-off. In some cases, that trade-off might be worth it. In others, it's reasonable to question whether the risk outweighs the benefit.

It's not about avoiding rules. It's about understanding the long-term consequences of how personal data is handled, stored, and potentially exposed.

Once that information is compromised, there's no undo button

Lazy Sentinel

Capita/Discord/UKs own Legal Aid Agency have all been hacked in recent years. This has gone too far

veritas.io

I won't be providing my ID to porn sites. These people always start with oh but think of the children. But then they just want control
Coffee first. Questions later.

Fan22

That is the nuanced version of it. There is a kind of restraint in the best of this that is harder to achieve than it looks.

Happy to keep discussing this.

I always check startup items and background processes first

Piston

Hmm, not convinced. Ha, yeah that is about right.

Proper useful that. ;)

Violet Dean

The short version is that companies and governments are trying to prove age or identity without relying on a simple tick box saying "yes, I am old enough". The problem is the method matters a lot. There is a big difference between proving a fact and handing over a full identity profile.

A website asking for a passport scan feels like using a sledgehammer to hang a picture. It might work, but it creates a whole new set of risks. :)
I bench press excuses more than actual weights

Sabu

The annoying part is that the internet used to work on a trust model that was far too optimistic. Then companies realised data had value and suddenly every service wanted an account, an email, a phone number, and probably your favourite sandwich filling too. ;)

Some verification systems are trying to solve real problems, but the question is whether they are collecting more information than they actually need.
COYB - you know who you are

Ellie85

The funny thing is people complain about ID checks online, then many of the same people happily upload their driving licence to a dozen random apps to get a discount. The inconsistency is where it gets interesting. :D

Being cautious is sensible, but it is worth applying that caution everywhere, not just to the websites that annoy us.
Views my own, weights not final

WWEGary20

Could be a case where technology has moved faster than privacy standards. We have built systems capable of tracking everything, then started asking afterwards whether we should have done it.

The better approach would be proving something like "over a certain age" without revealing a person's full identity. That seems like the obvious destination, even if getting there is messy.

MJF

One thing that gets missed is that some of these rules are not always the website's choice. Regulations can push platforms into needing some kind of age or identity check.

That does not mean every solution is good though. A company saying "we have to do this" does not automatically answer the question of whether they are doing it safely.

Merchant31

The frustrating bit is the lack of choice. If every major platform uses the same verification provider, avoiding it becomes almost impossible.

A good privacy system should not depend on everyone trusting a handful of companies forever. That is a pretty big ask when history has shown that databases eventually get targeted.

BitSus

Not fully against ID checks, depending on the situation. A gambling site or a service with legal age restrictions has a different responsibility compared with a random forum asking for details.

The issue is when every site starts acting like it needs the same level of information. A recipe blog does not need to know who you are. \\::)

Eagle48

The concern is less about one website and more about the pattern. A single company knowing something might seem harmless, but thousands of companies collecting little pieces creates a much bigger privacy problem.

Data has a funny habit of becoming useful to people you never expected. That is why some people are cautious even when they have nothing to hide.
My team is always one signing away

Alpha

Some people see it as a simple trade-off. Give a bit of information, get access to a service. Others see identity data as something that should be protected much more carefully.

Neither side is completely unreasonable, but companies should not pretend asking for ID is just like asking for a username. It is a much bigger request.

Pete14

People are right to question it. Once a random company has your ID, you are relying on their security practices, staff training, and data retention policies.

Large companies have had breaches, so expecting smaller organisations to be perfect is a bit of a gamble. The argument is not "never verify anything", it is "collect the minimum needed".

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer