• Out of interest, would the risk assessment change at all if you didn't allow uploads/attachments?

    Not enough.

    But the things that create issues and the most obvious actions:

    • Prevent all File Uploads, force the use of ImgUr or another 3rd Party - mitigates exchange of potentially harmful images, videos, etc via the forum
    • Prevent all Direct Messages, encourage the use of WhatsApp / Signal, etc - mitigates the risk of stalking, harassment, hate, fraud, etc via the forum
    • Close all the Classifieds, encourage eBay - mitigates the risk of fraud, stolen goods, etc via the forum
    • Add age verification - mitigates the grooming of children

    We'd still have the risk of vulnerable individuals experiencing harm, and honestly that's just society at large.

    And the forum would now be a very very different beast, a public only, text only message board... with age verification.

    This is where any of these steps start hitting the lines of what I don't wish to do, I don't wish to intentionally cripple the site. I find that unacceptable.

  • Add age verification

    I currently log in using my Googlemail account. It looks like you can verify your age by uploading valid ID to Google. I assume you can then restrict accounts under a certain age? Would this then pass responsibility on to them?

  • Not really.

    I run this platform...so I would need to age verify everyone using this platform.

    I'm sure there's some way to get agreements in place that a Google profile with some specific OAuth scope set to indicate age verification is done would suffice.

    But... doesn't that feel unsatisfying to you? Would I need to drive every user to have a Google account? Now access to this site is controlled by a third party and we're dependant on them.

    The work arounds and technical steps to mitigate the identified risks... do seem to kill the essence of these types of websites.

  • I don't want to send my ID to Google to use a bike forum.

    Fucking alcohol websites have some stupid age "verify" requirement. I don't see them being hassled to request government id.

About

Avatar for pifko @pifko started