Papers, Please: A First Look at Age Verification on the Web
Shreyas Minocha, Isaac Sheridan, Harry Oppenheimer, Paul Pearce, Michael A. Specter
Abstract
Since 2022, twenty-five US states covering more than 40% of the US population have adopted laws compelling websites with content "harmful to minors" to verify their users' ages. Many websites that comply with these laws are widely reported to rely on third-party services, effectively outsourcing the age verification process. However, little is known about how these services are shaping the web and affecting user privacy.
In this work, we conduct the first large-scale exploration of age verification providers on the web. We begin by exploring the CrUX top one million websites from three different statestwo with legal age verification mandates and one without-to identify the prevalence and composition of age verification services. We then reverse engineer Yoti, the dominant age verification provider, and provide an in-depth privacy analysis.
Our findings show that age verification services can be ineffective in restricting minors, create significant new privacy risks for end users, and are causing the first instance of cross-state balkanization of the web in the US. We find that Yoti often requires end users to share sensitive data-photos of their face, government IDs, credit card details, browser fingerprinting data, the website being accessed, and more. Such data may be entrusted not only to the contracted provider, but also to several "fourth parties" that are significantly less visible to users. We identify security and privacy issues, and connect these findings to key assumptions underlying recent Supreme Court precedent. TABLE 1. AGE VERIFICATION REQUIREMENTS BY STATE. Effective Permitted Hosted Carveouts Enforc-Month Methods Content ement
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 482e4e59-d9b1-4b2c-ad85-bf88c74118dfBuilds on16
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- Virtual U: Defeating Face Liveness Detection by Building Virtual Models from Your Public PhotosYi Xu, True Price, Jan-Michael Frahm, Fabian MonroseUSENIX Security 2016 · 94 citations
- Augur: Internet-Wide Detection of Connectivity DisruptionsPaul Pearce, Roya Ensafi, Frank Li, Nick Feamster et al.S&P 2017 · 84 citations
- Quack: Scalable Remote Measurement of Application-Layer CensorshipBenjamin VanderSloot, Allison McDonald, Will Scott, J. Alex Halderman et al.USENIX Security 2018 · 66 citations
- Automated Large-Scale Analysis of Cookie Notice ComplianceAhmed Bouhoula, Karel Kubicek, Amit Zac, Carlos Cotrini et al.USENIX Security 2024 · 25 citations
Related papers
- X-rated Compliance Theater: An Empirical Evaluation of European Age Verification Systems in Adult WebsitesSimone Lavermicocca, Michele Carminati, Stefano LongariUSENIX Security 2026
- What Adults Will (and Won't) Do to Prove Their Age: Empirical Evidence from a Deceptive Web ExperimentYanzi Lin, Cheng Zhang, Madelyne Xiao, Lorrie Faith Cranor et al.USENIX Security 2026
- Easy As Child's Play: An Empirical Study on Age Verification of Adult-Oriented Android AppsYifan Yao, Shawn McCollum, Zhibo Sun, Yue ZhangUSENIX Security 2025
- User Perceptions of Online Age Assurance Mechanisms in the U.S.Junho Eum, Jan Tolsdorf), Adryana Hutchinson, Smirity Kaushik et al.CCS 2026
- Cookie Swap Party: Abusing First-Party Cookies for Web TrackingQuan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros KapravelosWWW 2021 · 57 citations
