Age verification is rapidly emerging as a central regulatory instrument for protecting minors online, with several jurisdictions mandating its deployment to access adult and pornographic content. This regulatory direction, however, raises significant privacy concerns, as it risks binding access to sensitive content to identity-related attributes. It also introduces security risks, since age verification mechanisms are frequently outsourced to third-party providers,offering limited transparency into the robustness of their verification processes. To assess this hypothesis, we conduct, to the best of our knowledge, the first empirical security analysis of regulation mandated age verification mechanisms deployed by adult websites. Our methodology combines ecosystem mapping, adversary modeling, and empirical testing of deployed mechanisms across four countries, covering various verification approaches, including document-based, biometric, and the integration of such mechanisms with the website workflow. Our results show systemic weaknesses in all analyzed mechanisms under realistic threat assumptions, often failing against low-cost, widely accessible attacks. Finally, we derive concrete guidelines and design directions aimed at mitigating the systemic security and privacy risks that deployments expose.
La verifica dell'età sta rapidamente emergendo come strumento normativo per la protezione dei minori online, con diverse giurisdizioni che ne impongono l'utilizzo per accedere a contenuti per adulti e pornografici. Questa direzione normativa, tuttavia, suscita notevoli preoccupazioni in materia di privacy, poiché rischia di vincolare l'accesso a contenuti sensibili ad attributi legati all'identità. Inoltre, introduce rischi per la sicurezza, poiché i meccanismi di verifica dell'età sono spesso affidati a fornitori terzi, offrendo una trasparenza limitata sulla solidità dei loro processi di verifica. Per valutare questa ipotesi, conduciamo, per quanto a nostra conoscenza, la prima analisi empirica di sicurezza dei meccanismi di verifica dell'età obbligatori previsti dalla normativa e implementati dai siti web per adulti. La nostra metodologia combina la mappatura dell'ecosistema, la modellizzazione degli avversari e il test empirico dei meccanismi implementati in quattro paesi, coprendo vari approcci di verifica, tra cui quelli basati su documenti, attributi biometrici e l' integrazione di tali meccanismi con il flusso di lavoro del sito web. I nostri risultati mostrano debolezze sistemiche in tutti i meccanismi analizzati in base a ipotesi di minaccia realistiche, che spesso falliscono di fronte ad attacchi a basso costo e ampiamente accessibili. Infine, deriviamo linee guida concrete e indicazioni di progettazione volte a mitigare i rischi sistemici per la sicurezza e la privacy che le implementazioni espongono.
X-rated compliance theater: an empirical evaluation of european age verification systems in adult websites
LAVERMICOCCA, SIMONE
2024/2025
Abstract
Age verification is rapidly emerging as a central regulatory instrument for protecting minors online, with several jurisdictions mandating its deployment to access adult and pornographic content. This regulatory direction, however, raises significant privacy concerns, as it risks binding access to sensitive content to identity-related attributes. It also introduces security risks, since age verification mechanisms are frequently outsourced to third-party providers,offering limited transparency into the robustness of their verification processes. To assess this hypothesis, we conduct, to the best of our knowledge, the first empirical security analysis of regulation mandated age verification mechanisms deployed by adult websites. Our methodology combines ecosystem mapping, adversary modeling, and empirical testing of deployed mechanisms across four countries, covering various verification approaches, including document-based, biometric, and the integration of such mechanisms with the website workflow. Our results show systemic weaknesses in all analyzed mechanisms under realistic threat assumptions, often failing against low-cost, widely accessible attacks. Finally, we derive concrete guidelines and design directions aimed at mitigating the systemic security and privacy risks that deployments expose.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_03_Lavermicocca_Executive_Summary.pdf
non accessibile
Descrizione: Executive summary text
Dimensione
381.93 kB
Formato
Adobe PDF
|
381.93 kB | Adobe PDF | Visualizza/Apri |
|
2026_03_Lavermicocca_Tesi.pdf
non accessibile
Descrizione: Thesis text
Dimensione
22.59 MB
Formato
Adobe PDF
|
22.59 MB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/249540