Language

19 Jan 2026in Biometrics

Kids Are Cheating Roblox with Fake Mustaches — Can’t Identity Verification Stop Them?

Dzmitry Smaliakou

Head of Software Engineering

Recently, Roblox, an online gaming platform that enables users to create and play games, has introduced a new age verification system. One of the reasons behind it was earlier accusations of poor child protection, as the platform is hugely popular among minors.

The updated system assigns users to a specific age group where they can chat with peers only. Based on facial verification, it promised a safer environment for kids — until fake mustaches entered the chat.

Roblox age verification challenge: What happened

According to the gaming news outlet Engadget, just days after its launch, users began sharing how easily they could trick the Roblox age requirement using simple disguises — like fake mustaches or drawn-on wrinkles and stubble. Some even claimed success by uploading photos of adult celebrities. 

The system also misclassified adults as teens: for instance, a 23-year-old user was placed in the 16–17 age bracket, while an 18-year-old ended up in the 13–15 age group. Even worse, some parents are completing verification for their kids, unintentionally placing them in adult categories. 

In a statement, Matt Kaufman, the company's Chief Safety Officer, said the Roblox age requirement rollout will take time, and emphasized that improving safety at scale won’t happen right away. He highlighted that tens of millions of users have already verified their age and urged the public not to expect perfection overnight.

Subscribe

Get posts like this in your inbox with the bi-weekly Regula Blog Digest!

How does Roblox age verification work?

On the platform, age checks are currently required for features like Experience Chat, Restricted Content, Party Voice, and other age-gated experiences. In the future, Roblox plans to add more features that depend on verified age.

Users can confirm their age either by submitting a government-issued ID or through a selfie-based process.

Roblox age estimation

There are two age verification options available on the platform — either through a selfie or an ID document.

The first method involves age verification with an ID and is available only to users aged 13 and older. They can submit a driver’s license, passport, residency card, or any other government-issued photo ID. The system scans the document to detect the date of birth and then asks the user for a selfie to confirm ownership.

The second option is selfie-only and based on age estimation. It analyzes a facial image or short video and examines facial features to estimate age. This process is fully automated and helps Roblox assign users to an appropriate age group (5-8, 9-12, 13-15, 16-17, 18-20, and 21+).

How users cheat facial verification systems

What looks like a prank is a well-known problem called presentation attacks, which are used to impersonate someone during selfie verification. These methods range from simple to highly sophisticated:

  • Basic printed photos

  • Cut-out photo masks

  • Multi-layered printed images

  • 3D film prints

  • Various face masks (from partial masks to full silicone masks)

  • 3D printed models and mannequins

  • Photo and video replays displayed on screens

  • Deepfakes

  • Video injections

To address these threats, companies rely on presentation attack detection (PAD) tools. The goal is for the biometric system to not only recognize a person’s features, but also verify that they belong to a real, live human. This is where liveness detection plays a key role. 

Liveness checks help ensure that the submitted selfie belongs to a live person and hasn’t been manipulated. These checks can be passive, hybrid, or active. Hybrid and active liveness checks require the user to perform actions like smiling or nodding, while passive checks rely on a still image. In all cases, the algorithms look for inconsistencies such as unnatural skin tone, synthetic features (like fake mustaches or drawn-on wrinkles), and unusual movement patterns. In practice, this means modern biometric systems are capable of identifying accessory-based presentation attacks when these checks are properly implemented and trained.

Many users opt for the selfie-only Roblox age estimation method to bypass defenses. However, this method shouldn’t be considered weak, especially when supported by strong, well-trained technology.

Which technologies are required to make age checks reliable in 2026?

In general, complete identity verification (IDV), including government-issued ID checks and selfie matching, is generally more reliable. In this case, you can verify the user through multiple layers of control:  

  • Confirm that the submitted document is valid and physical (not altered or AI-generated) using authenticity checks and ID liveness detection.

  • Ensure it belongs to the registered user.

  • Confirm that the user is a real person, not an impersonator or a fake.  

Age estimation can then serve as an additional check for specific user groups, ensuring compliance with legal requirements. 

However, age verification and estimation are often used on their own to streamline the process by skipping extra steps and speeding up the flow, while still maintaining security and privacy.

quote

When it comes to age estimation, the quality of the technology matters. Systems designed primarily to reduce friction or speed up onboarding can struggle to balance usability with robustness. In practice, this can result in thresholds that are more permissive than intended.

But even the best system can’t perform well if the input data is poor or if the age assessment algorithms aren't properly trained.

For instance, if a user squints, turns their face away from the camera, wears glasses that cover half their face, or uses a mask, the system’s accuracy drops significantly. A clear, well-lit, unobstructed image is essential for reliable age assessment — and that’s something businesses are responsible for when implementing age checks. A guided process with clear prompts helps capture appropriate images from the first try. 

For age estimation and verification algorithms, industry-recognized benchmarks, such as the evaluations conducted by NIST, are critical. They account for a range of user scenarios and provide guidance for both on-site and online age checks, helping identity verification vendors fine-tune their solutions.

Finally, here’s one more important note: until recently, age verification focused on distinguishing adults from minors — mainly around the 17–25 range. But now the challenge is identifying users under 13, where existing models are much less accurate. Children develop differently across races and genders, and there's limited high-quality training data for this group, making precise age estimation much harder.

Ihar Kliashchou
Ihar KliashchouChief Technology Officer, Regula

Here are the best practices for companies relying on facial recognition-based verification:

  1. Use facial recognition with active liveness detection: Ensure your system can confirm that a real person is present — not just a photo or video. Active liveness checks help block both common and more robust spoofing attacks.

  2. Evaluate facial attributes: Look for solutions that can assess facial expression and accessories (like glasses, beards, mustaches, medical masks, headphones, etc.). These details improve both accuracy and fraud detection. 

  3. Control the signal source: Prevent tampering at the input stage to stop deepfake injection attacks. This is key to maintaining data integrity during verification. 

  4. Ensure reliable performance in various lighting conditions: Choose tools that work effectively in different lighting setups — indoors, outdoors, or in low-light environments.

  5. Support 1:1 face matching: Match a user’s face to a reference photo from an ID or trusted source to confirm identity with a one-to-one comparison.

  6. Enable 1:N face recognition: If needed, use facial recognition to identify a person from a larger database, helping to detect duplicates or unauthorized users.

  7. Consider implementing a complete IDV flow: If you need to verify users’ biometrics to meet legal requirements — such as age verification — keep in mind that combining document checks with active liveness and face matching consistently delivers the most reliable and secure results.

Have more questions about age estimation and verification? Feel free to contact us!

Have a Use Case? Let’s Explore.

Speak with our experts to see how you can speed up verification, reduce fraud, and stay compliant.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules