We used to make fun people like Ted Stevens for calling the internet "a series of tubes" and now we're just totally cool with letting a failed, bankrupt state in the US dictate what code needs to go into voluntary open source software. We need to fight back, now.
If OSes build a standards-based way to query age of user that is logged-in, where non-admins are not allowed to adjust the age bucket, then parents can configure devices on first use to have an OS-wide enforcement of age controls.
Apps and sites would query the OS, not individual app/site accounts, for user age and act accordingly.
Apps can then lock out certain features like algo feeds and adult content more consistently.
Responsibility for proper use is still on the parent, and no verification process is put upon the operators of sites.
Not sure how I actually think about this; I'm only putting this out for discussion.
Second, storing PII in a world-readable file is unacceptable. Linux is multi-user so the administration needs to be responsible about sensitive data like that! Find somewhere else to stash it!
At which point the only move is to relocate the foundation to another country, which will then of course be hit by tariffs and sanctions.
Illinois can put up a great firewall like China and search citizens devices for contraband operating systems. The onus is not on tech to enforce it, it's on them.
That's how things used to be and that makes more sense in my opinion because an OS isn't the thing displaying content. It just run whatever it is told to run.
Because children just click through the age gate when it suits them. With this legislation, a parent that purchases the device and creates an account for the child can set the age once and take the decision out of the kids hands. It's a huge improvement without any significant privacy issues. I can't fathom why the tech crowd is having a collective aneurism over this.
>OS isn't the thing displaying content
But the account on the OS is the right place for the single source of truth of properties of the current user.
I am root on my computers. My 11 year old isn’t root on my computers.
The reason the US has fairly robust interstate commerce laws is because if you don't you'll have trade barriers between states. Even the most well intentioned internet company can't operate in that ecosystem
You can also thank big tech for this because they'll do anything to not verify age on their platforms they want to push it onto devices and OSes.
Also how is that fine going to work if you don't have any children?
I think now even the last person realises that this has nothing to do with age "verification". They simply hate us for our freedom. And it is clearly a move coordinated by private business here; their lobbyists are acting. This is also why it is the same law essentially in so many different countries at the same time. It is quite fascinating to watch, actually. People used to say "conspiracy nut!" - well, the facts are too clear now. That's no longer a conspiracy.
Can't believe all this shit just allowed to happen then Muricans still claiming to have more freedom than China or Russia for long..
Why not just signal age ranges? Simple, the way the legal system works is one puts in a benign sounding law, then tweak it every year since the mechanism exists. (scope creep) "Now add city, state", "Now add DOB and address", "Now add your federal wallet ID."
- For small children set an RTA header (previous discussions) [1] for any URL that may potentially contain content not appropriate for small children. Give site operators 1 year to implement this. Not counting QA and change control this takes minutes.
- Require app and device vendors to create a properly sand-boxed child account. Pen test it but it does not have to be perfect. This is for small children and default installed applications. If the child visits a URL that contains the RTA header then trigger parental controls. It is entirely up to the parent when that child is ready for mature content. It must be impossible for the child to install any applications, addons, etc... There are a myriad of ways to accomplish this.
- How is this enforced? Same way as any other parenting issue. If there is an incident that involves law enforcement, then social services can investigate and determine if negligence was occurring. When the child is mentally mature enough to deal with all the crap that is the internet their account is converted to an adult account. If the parent is giving the child an adult account before they are ready then the parent(s) go to mandatory parental training. If the child was being bullied or groomed, redirect law enforcement to go after the bullies or groomers.
- Set the laws to be active for any small child that would be under 13 as of the year 2034. Presto! One need not try to confine teens. When these small children are teens they will either be used to the sandbox account or the parent may have converted the account to adult.
As a side note all public and private schools should be legislated to have classes on dealing with all the crap the internet has to offer. Bullies, Cry-bullies, Trolls, Groomers, Scammers, Devious companies, Astroturfers, Gas Lighters, Propagandists, NGO's and so on. Also teach and help them build friend networks so there is protection in numbers. No child should be friendless.
[1] - https://nochan.net/b/Internet-Crap/20230829-Think-Of-The-Chi...
that you know of. when you were 11 could you get root? I could. I got expelled from a highschool for getting "root" on a DOS machine by holding down the shift key (at 13).
All it takes is one moment of weakness from a parent or not blocking the kid's view of the keyboard, or the kid getting an app that figures out possible passwords from keyboard sounds (it'll be here someday), or any manner of other things, like you forgetting to close your session.
11 year olds aren't stupid.
also there's nearly weekly exploits that get your root on a linux machine, so unless you're blocking arbitrary code downloads, which means you're going to have to whitelist sites you allow your kid to visit, which means they're probably just going to get that stuff elsewhere, as is customary. Again, 11 year olds aren't stupid. any one of them could tell another "here's a script that gets root" and spread it around school. If it became a thing.
I just had a vision of linux being outlawed because it's too insecure
I look forward to these laws being shut down in the courts.
Also children can "come upon" devices, so this is still completely pointless unless there's a way to ban devices that don't have this ability. and the only way to do that is to ban devices that cannot verify the user's age. since a device can't really verify an ID, some third party (ideally meta, but also the government works) needs to verify id and age, write something to the secure enclave of the device, and now that's stuck with the verified age set.
If "just let someone report the age" worked, pornhub wouldn't be blocked in TX.
Yes, this mechanism isn't perfect, but is a substantial improvement over the status quo.
>and now that's stuck with the verified age set.
This inference is nonsensical.
>If "just let someone report the age" worked, pornhub wouldn't be blocked in TX.
Also nonsense
You don't foresee a black market of "no-age-audit" devices? How do you prevent that? Well, one way is to use the secure enclave and write the birthday in it so that it cannot be tampered with. How is that written? who writes it? Who verifies the ID?
TX passed a law stating that adult sites like pornhub must verify age. I hope you understand what "verify" means in this context. It isn't "i promise i am over 21 or 18 or whatever" - because if that worked, TX lawmakers wouldn't have made the law say "verify" https://journals.law.unc.edu/firstamendmentlawreview/screeni...
In the future, casual dismissals are viewed negatively.
I will never be compelled to implement this, and would never merge it.
Every release requires quorum signatures by an international maintainer team, and the distro is designed to work offline-first, with some variants not even supporting network drivers in the kernel, so Illinois legislators can eat shit.
This is probably all completely irrelevant to StageX since it's a distro designed to be used in containers, AFAICT.
Project tracking these laws and providing patches as needed: https://agelesslinux.org/
Also, we are not a company. We are an independent community owned project. Our code is free speech and I will burn the world down to defend that right.
Truly I dare someone to try to take me to court over this. Would be great publicity for our coercion resistant approach.
They might as well try to mandate code changes to a blockchain and mandate the whole world host them.
"Operating system provider" means a commercial or
non-profit entity that controls the Internet-enabled device's
operating system, including the design, programming, or supply
of operating systems for the Internet-enabled devices.I mostly just want to make it clear this type of legislation is unenforceable and a waste of everyone's time.
If your OS doesn’t access the internet or isn’t intended to run browsers / social apps, then you are outside the scope of this legislation. That would be a bit like requiring a toaster to ask for your age before letting you operate it.
What does it mean to "found" a Linux distro? Can you describe it?
Though if you don't live in IL it is unclear how this affects you.
I do not want to go to jail, but if that is the only way to get to an outcome where people have confidence they can not be forced to add unwanted code to open source projects, so be it. But that is a pointless thought experiment because it will never happen.
I do not think anyone would be stupid enough to jail a FOSS developer for not agreeing to compelled speech, and if they did, an army of lawyers would be lining up to take the case I expect, with the full support of the public. It would be an insane thing to attempt.
We must loudly push back on the chilling effects intended here. Our free speech to write or not write any code we want will not be compromised.
At what point do they become subject to Illinois law?
And can Illinois prosecute someone for doing something that is legal in California while they are in California?
https://abcnews.com/amp/US/children-recruited-criminals-indu...
Requiring my kids' devices to advertise their age (or their age "bucket", as if that was a meaningful difference) to protect them is not doing me or my kids any favors.
Self-declaration means that the system asks the user to declare if they are a minor. Nothing is verified.
Age verification typically means a system which checks ID or has other enforcement measures to try to verify age.
> Nothing in the bill requires a passport scan or a face scan at setup. It’s self-declared, the same way most apps ask your birthday today, just centralized once at the OS level instead of repeated app by app.
Maybe this is just a badly written law or purposefully designed to have basically no impact on anyone?
Or maybe the age bracket self-declaration part of this might make it a legitimately useful mechanism when a parent sets up a device for their kids. Their device declares “under 13” and apps and sites have to then follow the more strict social media laws which themselves should be relatively beneficial to the target audience.
In other words, the part that’s really privacy-destroying is the age verification, but that’s not part of this bill. The part that could be a benefit is the part where companies need to respect an age flag set by parents and comply with a concrete set of parental controls.
In other other words, it’s not left up to operators like Meta and Roblox to decide what age their users are, parents can set that device-wide and know it can’t be circumvented.
>no algorithmic feeds for minors by default
Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?
If the distro does not ship with any hardware, it could only be attained via download? So how would this imperil Linux distros?
Not to defend the law, it's comically pointless. Conservative states demanding ID verification for anything 'pornographic' and progressive ones trying to limit anyone under 18 from having any social media access at all. Clownish.
I can't even get the politician of my city to reply to me in email because of his arrogant persona.
How am I suppose to change something when I can't even get the local politician to listen? Cash would; but I'm stripped for that. You have any?
As a parent, I'd be very happy with this "age declaration" method, as I also don't think the 'verification' others push for is at all worth the risks. All parents want is to put the devices permanently into a mode that flags it to third parties as belonging to a minor, so they can't just hold up their hands and say "idk they said they're 18" like they do today.
It's constitutional case law that there's an implicit right to privacy in the constitution. I don't see a law that you must wear a band with your birthday out in public passing muster based on that. I don't see why existing in cyberspace changes the inherent privacy question, and in fact makes it more meaningful given ease of automation.
Why do you think that is?
Edit: I see people don't like this comment, so here's an article about it from Wex law [1] (read under "Roe's Overturning"). The part of the Dobbs decision was removing a right to privacy and promising that it could be revisited in overturning other cases like Griswald.
The 9th amendment has never been used to establish a right to privacy, but then I don't think the 9th has ever been used to establish any right. We've used the 14th in the past to establish that right and now it seems that's no longer good law.
> While it is unclear to what extent that may have on the right to privacy in the current time; it is likely that the case law around this right will continue to evolve with more recent Supreme Court decisions.
> "Nothing in the bill requires a passport scan or a face scan at setup. It’s self-declared, the same way most apps ask your birthday today, just centralized once at the OS level instead of repeated app by app."
Here's an idea for the lawmakers that actually want to solve the digital parenting problem: fix the mobile OS duopoly with antitrust. Most kids only know how to use touchscreen devices. If you force mobile hardware vendors to ship smartphones without an OS, then we will get plenty of forks of Android and even entirely new OSes as a result of natural demand, some of which will be toy OSes with all of the child features built in. We'll also get scam-proof OSes for the elderly as a bonus. There is no good reason for the entire population to use the same OS.
The Epsteinocracy wants to know how many children you have and exactly how young they are.
Some states will pass laws that companies cannot show advertisements to minors. So...
I think I'm about to become a bit of a minor myself, at least whenever it serves my interests.
Democrat Senator Willie Preston [D] in the senate
This will end Linux as end user OS, it will stay only in Cloud and containers. Arguably, the goal here is to destroy home PC altogether. maximum we will be allowed is a laptop with endpoint verification and mandatory touch ID, locked boot and non-replaceable hardware. If you think Linux is the end of it – think again. The same crap will be implemented in BIOS/UEFI, on "HW management" level. Essentially, your bare HW only laptop will not even start without you touching fingerprint sensor and allowing it to "validate your age" against – of course government approved – HW manufacturer.
Same with smart phones – it's already here, if you tried to activate iPhone.
And projects like Open/Free BSDs? Government will sure their leaders happily retire and ... well, the community will just "die" naturally.
Anti-money-laundering is a comparable field, as all the AML regulations and laws are ineffective at identifying money launderers, but they're wonderful for verifying (auditing and prosecuting) tax compliance.
As someone who’s implemented AML, KYC, and tax reporting functions in a bank. I think you would be very surprised at how shit they are for tax auditing at scale. Unless the tax man is specifically auditing you, and basically requesting all your transaction details, the reporting that banks do would only allow tax agencies to catch the most brazen and incompetent tax dodgers.
All of the tools however do make much harder to perform money laundering, forcing criminals to recruit and pay huge numbers of naive bank customers to allow criminals to launder money via their personal accounts, using them as money mules. Which then gets flagged and shutdown pretty quick by banks because the behaviour is generally pretty obvious.
Unfortunately (or fortunately depending on your perspective) banks can’t/don’t coordinate on identified money mules or know launderers, so criminals just move on to other banks and repeat.
If this age verification stuff ever becomes plausible we always have the option of distributing actual Linux ISOs over bittorrent. Failing that, source code in RAR'd archives distributed across IPFS nodes and Tor. I feel like many of us would welcome the challenge if it were under better circumstances.
If the intent were to actually protect children, then this would be what was done.
"Protect the children" is just a subterfuge to get electorate support for voting for the foundation for a "1984 thought crime" style monitoring of the internet.
Don't ever for one second pretend this is about anything else.
Any parents who are pathetically absent from parenting their kids, well, they can just go right on ignoring their kids and letting the kid themselves put in 9/9/99, and consume all kinds of inappropriate crap.
This particular law is respecting everyone's rights.
but that's not this law. This law requires self-declaration by whoever creates the accounts on the device.
Modern social media is delivered through 'apps' which are like web browsers, except without ad blockers or privacy settings, and with push notifications to make them more addictive, and they only show one website, and they're each 5x the size of a web browser for some reason.
This was tried in the past:
The point is monitoring everyone, age verification requires you to share who you are.
This isn’t for the protection of kids. It’s for the protection of profits by surveillance capitalism.
> Requiring my kids' devices to advertise their age ... to protect them is not doing me or my kids any favors.
Idk about you, but it'd be doing me favors because my kids will not be physically able to use the most addictive platforms that exist today in their current form. It would be a major disruption to the behavioral manipulation that Meta, TikTok, and X do.
What you calling "addictive" is just revealed preferences of the populace.
Maybe next they'll ask maintainers to go from a bracket to a specific age, and then next ask for verification, but the jump from specific age to verification is big enough that there'll be just as much resistance to it.
As a counter, actual age verification is being rolled out in other places. I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. Between the anti-porn types and public demand for some kind of regulations on social media, regulation of some kind is inevitable.
Our actual choice may only be what type of restriction we can live with, and I much prefer this type to the kind that requires websites to demand my id and photos of my face. Especially since some implementations of this concept (the California one, I think) declare that websites aren't legally required to look deeper than the attested age, which is a very nice feature.
Mind you, I don't know why the legislators are bothering mandating OS support for these features. It would be much easier to mandate that websites support the feature, make it clear to them that supporting the feature appropriately will free them from liability for children accessing content, and then wait as users demand that their OS support the feature.
I don’t even get that far, the proper response to my operating system asking me if I’m a minor or not is: fuck you. It isn’t a harmless question. We aren’t friends, I don’t want an algorithm of news and content, it’s an OS.
You seem to assume that "this is now final, nothing will change after that". Why would you assume this to be the case?
The danger of a slippery slope comes when one change enables the next change - for example, a law mandating certain kinds of data collection enables a future decision to discriminate or control based on the collected data. But in this case, no data is being collected, there's no step happening here that enables a more dangerous later step.
If anything, I'd argue this makes it harder to implement more invasive measures later, because rather than arguing that some form of age control is necessary, Illinois will specifically need to argue that age verification is necessary over the existing anonymous system. That's harder than saying "there is no protection for children right now, age verification is the only way forward".
Meta is then funding/lobbying alongside a bunch of other conservative groups like Heritage Action, and the digital childhood alliance (also made up of a ton of other conservative lobbying groups)
Now, granted, correlation is not always causation. But it sure stinks of something Meta had their lobbyists push just after Zuck's testimony so as to shift the liability risk of handling age appropriate material away from Meta properties and onto operating systems (Microsoft, Apple, Google (Android)).
Their website (now offline) also added this page since I posted that comment: https://web.archive.org/web/20260411112604/https://tboteproj... where they claim their website is under "surveillance" because it got a few thousand requests from Google Cloud et al, most of them to a single page. This shows how low their standards are.
As for lobbyists: I think we can probably determine the key lobbyists, e. g. if we map the data and names. And ideally also the money given to them. Ultimately they are faceless though, because corruption is easily exchangeable. The issue here is systemic though. The US "democracy" no longer exists due to that corruption. It is not rule by the people but rule by bribery.
Parents aren't interested in the nuance of good and bad guys, they see the internet, think it's too much trouble to keep around, and want it blocked. I suspect politicians are just mimicking this sentiment after talking to thousands of parents
You could argue about the language and the meaning of "algorithm", but for practical purposes I'd consider a manually-curated feed to be non-algorithmic.
however
"nothing in the bill has teeth against someone with no business presence in Illinois"
Phrases can have meanings beyond just a naive combination of the words in them. And indeed "algorithmic feed" in the bill means what what we all understand that term to mean when we aren't paralyzed by pedantry.
> Under the law, [...] these users will only be shown content they request or search for or that is posted by a creator or friend they follow.
You may disagree with the motivation behind the bill, but you do the discussion a disservice to assume the people writing it are incompetent enough to not define their terms.
There's things like hashtag searches and whatnot, but none of it is algorithms; in the sense we understand it to mean, here, these are not manipulative algorithms designed to keep people on a site and keep ads rolling by.
on the fediverse, there are bots to curate content such as "most liked", one can subscribe to these bots to see such "views" of the feed.
there's absolutely no reason for any of that crap to be built in, other than that's how reddit (and HN) do it.
That's a paraphrasing of what law says. The law is more clearly defined:
> "Addictive feed" means a website, online service, online application, or mobile application, or a portion thereof, in which multiple pieces of media generated or shared by users of a website, online service, online application, or mobile application, either concurrently or sequentially, are recommended, selected, or prioritized for display to a user based, in whole or in part, on information associated with the user or the user's device, unless any of the following conditions are met: (1) the recommendation, prioritization, or selection is based on information that is not persistently associated with the user's device and does not concern the user's previous interactions with media generated or shared by other users; (2) the recommendation, prioritization, or selection is based on data controlled by user-selected privacy or accessibility settings or technical information concerning the user's device; (3) the user expressly and unambiguously requested the specific media, media by the author, creator, or poster of media the user has subscribed to, or media shared by users to a page or group the user has subscribed to, provided that the media is not recommended, selected, or prioritized for display based, in whole or in part, on other information that is not permissible under this definition; (4) the user expressly and unambiguously requested the specific media by a specific author, creator, or poster of media the user has subscribed to, or media shared by users to a page or group the user has subscribed to as described by paragraph (3), be blocked, prioritized, or deprioritized for display, provided that the media is not recommended, selected, or prioritized based, in whole or in part, on other information associated with the user or the user's device that is not permissible under this definition; (5) the media is direct and private communication between users; (6) the media is recommended, selected, or prioritized only in response to a specific search inquiry by the user; (7) the media that is recommended, selected, or prioritized for display is exclusively next in a preexisting sequence from the same author, creator, poster, or source; or (8) the recommendation, prioritization, or selection is necessary to comply with the provisions of this Act. "Addictive social media platform" means a covered platform that offers users or provides users with an addictive feed as a part of the service provided by that website, online service, online application, or mobile application.
The relevant text doesn't call it an "algorithmic feed" for what it's worth. They define an "addictive" feed and it's essentially any kind of personalized recommendation.
> "Addictive feed" means a website, online service, online application, or mobile application, or a portion thereof, in which multiple pieces of media generated or shared by users of a website, online service, online application, or mobile application, either concurrently or sequentially, are recommended, selected, or prioritized for display to a user based, in whole or in part, on information associated with the user or the user's device, unless any of the following conditions are met.
Basically the bill defines
> "Operating system provider" means a commercial or non-profit entity that controls the Internet-enabled device's operating system, including the design, programming, or supply of operating systems for the Internet-enabled devices.
Which is an extremely broad definition that could be interpreted in a whole bunch of ways.
It moves the Overton window, making worse things easier to pass in the future. And it enforces requirements on projects the state should have zero jurisdiction over.
Step 2: Recognize that the system is trivially bypassed by a kid who sets up their own device without their parents' oversight or parents who just think this is a stupid law and lying for their kids. Or bypassed by anyone using open source operating systems which are (for a feature like this) going to be trivial to amend to always claim the person is an adult regardless of which account is being used.
At this point there are three possible futures that are worth considering:
1. Throw out the rules because they're stupid and everyone with any common sense or sense of decency has been saying it since the start. The service provider is responsible, not the OS developer or device manufacturer. (Best case)
2. Keep the stupid rules on the books and pretend they work. Let the service providers off the hook. (Second best case)
3. Create more rules that effectively cedes more control of personal devices to the government to make this actually work, but the effect of this is to essentially outlaw OSes like Linux and many, many devices and even raw hardware without a government permitted OS pre-installed. (The worst case)
(3) is extreme, but it's the only way that this law actually has the desired effect. (1) and (2) are the most likely outcomes, but reflect that this whole exercise is just a waste of time.
> bypassed by anyone using open source operating systems
You know what? If millions of tweens develop a keen interest in building Linux and Firefox from source just to get "the good TikTok" I'm fine with that. In reality 99% of them use iOS and Android nearly exclusively, so Linux is irrelevant to the conversation.
> The service provider is responsible
We tried that. That's the status quo. There are only two options I know for this, both stupid. 1. (the current model) Just trust the user. Talk about 'trivially bypassed'! 2. Invasive ID checks - with the camera, identity documents, and government databases.
If parents want to go out of their way to irresponsibly give their kids unmonitored access to content that is bad for them that's on the parents. If you try to make service providers "responsible" for it, they WILL build invasive, corporate-controlled systems to cover their asses. Basically option 3 but controlled by shitty companies that get hacked, instead of even a theoretically accountable government that will get hacked. Note that I am not saying your option 3 would be acceptable, just that a private version of it would be even grosser.
When they sell to someone in Illinois, although there is probably some bullshit case law out there that says the website owner has to take basic steps to block Illinois users to avoid all IL jurisdiction.
>And can Illinois prosecute someone for doing something that is legal in California while they are in California?
No.
that, uh, sounds sketchy
> Contributions to Collectives hosted by OSC are not deductible as charitable contributions for U.S. federal income tax purposes.
So, uh, no longer sketchy but not tax deductible in the US. See https://opencollective.com/opensource#category-ABOUT
> But they could also just implement verification now, which many governments are trying to do.
That itself is a proof: the voluntary age declaration was and is common on all the services that governments are now trying to force to do age verification, and it wasn't enough.
EDIT: in more general terms, and going beyond age verification thing and over many recent developments in information security, the Internet as a culture is missing an on-line equivalent to a key real-life social feature: the ability to answer with a shocked "gross!", followed by slapping the asker in the face.
It's actually pretty hard not to have a change be part of a slippery slope. It requires including blocks for further behavior as any subset implementation is hard to sell as not being a slippery slope path otherwise.
If this were actually true then the law itself isn't needed because kids are already getting filtered access to social media sites and other things. Right?
So then what is the point of the law if parents are already setting age filters for their children's devices?
But I hope they try this. It will be funny to watch the public humiliation of how hard it fails at scale.
It's not implementing age implementation, but can be used as a place to store a DOB in an age verification system.
C'mon. We all know parents are far more likely to tap "OK" for "Allow personalized social feeds?" than they are to knowingly falsify their kids' age. The kids will be begging them to and saying "It's just to personalize it, Dad! There's nothing scary or bad on Tiktok - all my friends are using the personalized feed and mine is BORING!"
> The decision should be happening in my house on the devices I control, not in a Meta data center. The current law just gives Meta a way to start building a shadow profile early.
The decision would still be in your hand. If you want them to be using all the max addictive crap, just fake their age on the device that you bought them.
> The current law just gives Meta a way to start building a shadow profile early.
Whether or not they can start building a profile to start using at 18 is unrelated to this, and depends on data protection laws. There's no use tying the two together.
I know lots of parents and lots of kids, and I don't think this is accurate. In my experience the breakdown is parents who care what their kids are doing online, and parents who assume it will all turn out fine because they had AOL or even Facebook as teenagers and didn't get into too much trouble. The first group is already keeping an eye on their kids and might even have decent parental controls set up, and the second group doesn't care what happens as long as charges don't show up on the credit card.
These bills punish the first group of parents and OS/device makers for the transgressions of social media companies. The uninvolved parents won't even be in the room when the age question comes up.
There is a huge international criminal industry that exists to find and hire money mules, and launder eye watering amounts of cash. Where I worked, we broadly assumed that the police weren’t interested in fraud or money laundering unless it was measured in 10s of millions. We reported everything, of course, but we only got call backs for really big schemes.
If you’re just committing fraud measured in $100ks, the odd of anyone bothering to investigate, and attempt to bring criminal charges, was basically zero.
The larger-scale money laundering in my area is a but more complicated, involving import/export schemes, real estate transactions, and property developments. I'm not in a mega-city, so I assume these schemes are taking place at a larger scale in those. I have only ever heard of very basic and stupid schemes (which didn't provide any tax revenue to my goverment) being detected or prosecuted.
Or criminals just get a bank like HSBC to do the money laundering for them.
Step 1: get easily passed, simple looking laws passed to 'protect the children' Step 2: 'oh look at all these people bypassing the law. It's so simple for a child to watch porn with this.' Step 3: increase the requirements bit by bit on the verification
By letting something simple pass, they can claim it's not thst bad, and anyone who argues against it is being hyperbolic.
> Step 2: 'oh look at all these people bypassing the law. It's so simple for a child to watch porn with this.'
This would be a demonstrably stupid argument. A parent who simply opens the box and does 5 minutes of setup before giving their child a new $300-2000 device, and maintains the most basic awareness of any rogue devices (i.e. ask questions if a new phone appears) is all it takes to make sure no "bypassing" takes place in your home.
Anyone claiming "all these kids are bypassing it" would be lying, unless the law isn't even being enforced or sites aren't cooperating. And no law can overcome those problems.
In this case, unless you're a child, nobody's trying to control what content you consume. And if you are a parent and want to make sure your children can continue to consume the most addictive possible social media, by all means lie about their age. The law does nothing to stop you from doing so.
By contrast, having zero mechanism for the rest of the parents to control this, as is the current case, does impose your "do whatever feels good" values on the rest of the world.
Parental controls? They take 5mins to setup.
I think the theory behind the law is that experimenting on children to optimize (without any ceiling) for increasing watch hours, which 100% of the social media sites are doing at all times and have been for over a decade, is unethical and should be illegal.
If adults want to subject themselves to that, it's their business, but for children, we restrict all kinds of things from even being marketed towards children. Things (especially addictive ones) that are very obviously bad for humans, like cigarettes and liquor. Why? Because otherwise there's a huge incentive for the makers of those things to do so, because of how naïve kids are.
A wildcard here is how if at all to address careless, negligent parents of course. For the things so obviously harmful like drugs, it becomes criminal to give those to your kids. But perhaps social media falls into about the same category as R-rated movies, where we just say "it's bad parenting to take a 6-year-old to one, but not illegal." Another area where we have 'censored' things for children for decades - without any kind of scary police-state regime materializing and forcing biometrics and recordkeeping at the box office.
this is a way to get something legal on paper, the rest of the stuff (patches, if you will) comes later. This asserts that age is important enough to force an operating system to comply, this opens the door.
No OS I'm aware of allows non-admin users to add new users to the system. Parents that care about these sorts of things don't give their kids admin access to their computers.
> the rest of the stuff (patches, if you will) comes later.
Unless the legislation allows for such patches through non-legislative process, patches to legislation generally happens on a ~20 year cycle in my experience.
A determined kid will find a weakness in the pursuit of freedom.
also nintendo's OS lets users add users to their heart's content. At least i haven't found a way to stop a toddler from adding 6 avatars....
But to humor you, if they did, the distro would carry right on, so they would be taking a lot of risk with no progress on their objective.
I only sign like 1/3 releases these days so I am replaceable now. Decentralized control and decentralized trust was the whole point of stagex.
Pay no heed to anyone saying anything different, regulators!
$> ls -al
User age not set, please verify age before invoking CLI utilities.The state being able demand a persons age, and gate their behaviour based on that, has existed for hundreds of years so far. During that entire time the requirement to be truthful has also existed otherwise the laws would be meaningless.
All that’s changing now, is figuring out how that extends into the digital realm. I personally find the argument that the digital realm is somehow special compared to the physical realm, and thus certain laws simply shouldn’t apply when “done on a computer”, difficult to reconcile.
Let me be clear, I don't want face scans, or more of those creepy companies that operate this age verification crap for Discord, etc. Because I know it's not going to be implemented in the privacy-preserving way it could be, if there's ANY involvement with identity documents. Not least because we don't even have any proper cryptographically useful identity cards, so everything like that operates on a "trust us bro" basis where they pinky promise not to accidentally store everyone's raw face scans / ID cards / numbers / etc and inevitably leak them.
But out-of-box age declaration is not extreme and is not slippery-slope, any more than out-of-box user account creation 25 years ago has led to out-of-box ID card checks.
this is the same rhetorical and political strategy, that there are 'dangerous' people who will exploit your children so please vote for me, the person who cares the most about children and will go after the 'dangerous' people
[1] https://themarkup.org/privacy/2021/04/15/big-tech-is-pushing...
The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
You have precisely zero additional speech rights as a FOSS project than any other organization has. If "free speech" was a valid defense for you, then Meta would be doing the same.
> The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Being unable to comply is not a valid legal defense.
> Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
This is the law in various places under various mechanisms. It is handled by putting people in prison or taking people's assets.
They might not be able to break your private keys, but they can fine you or jail you for not complying.
"Der Proceß" [The Trial] by Franz Kafka is just a realistic description of the court system (Franz Kafka studied law).
Also reach out to the EFF, who may be able to help/advise, especially if you genuinely want to fight this.
This is a terrible law. That doesn't mean it's not a law, and courts do not look kindly on people subject to their jurisdiction (which unfortunately often includes state laws to people in other states) who try to dodge the responsibility the court thinks they should have.
Don’t make a target of yourself, there are countless ways for a government to make your life miserable.
Users need to see that the people in positions of influence in FOSS projects they trust are not afraid of this bullshit.
I -hope- someone is stupid enough to take a case like this to court so we can establish some much needed case law here. These overreaches deserve to be contested.
"never show fear" and "never engage intelligence" are two different things. Understand what people will do in response to your actions, and act accordingly to achieve the outcomes you want. Please by all means fight the law, and do so intelligently in a way that will actually help.
Wait, which constitutionally protected right is that? I'm an attorney and constitutional scholar and am particularly interested in what right you believe is being violated here.
And where code is speech, is a distribution speech? There's a lot of places for this to go sideways on you personally.
Constitutional scholar here! I mean, yes, that's true in a very general sense, but no court has held that age verification to gain access to a service, or even a device, is unlawful in practice.
Fediverse absolutely has "algorithms". People generally want them. I agree that it's broadly less user-hostile (I'm very much a fan), but it's very much moving down the same paths as twitter (mastodon), reddit (lemmy), etc.
It is an algorithm on a data structure, but it is not an algorithm to drive ad impressions.
do you see the difference?
this is why people say "Algo" when talking about the latter, and "Algorithm" when talking with other like-minded people about data structures and algorithms.
A fully human-curated feed would not be "algorithmic", in contrast. Print newspapers do this, and sometimes online ones to varying degrees, and most blogs. You could even let people build their own (e.g. "boost to my popular feed [at position X/newest/oldest]"). Essentially none do this though, they all choose algorithmic ones of varying complexity - it doesn't make them non-algorithmic to choose a simpler one.
I actually agree with you, if you mandate that the site has to look for an affirmative signal and if it doesn't get one, has to assume the user is the youngest possible age group. Users would demand the proper support for it.
Although it would have to have some teeth capable of biting the client software companies, because for instance, if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls).
Honestly though - because kids (especially the younger set) are hard pressed to buy their own hardware, a property that can only be set up out of the box, and can only be undone by using the account password of the parent who set it up, it is the perfect level of security here. And as for browsers, all you need is the gatekeepers (Apple, Google, MS) to agree not to ship in their "stores" browsers designed to evade it. Yes, you can totally compile your own browser, but most kids are using locked platforms like iOS and Android, and are by default denied permissions to run arbitrary software on platforms like Mac and Windows, so that's fine.
I really think all we need is what you describe in your third paragraph. It doesn't need to be bulletproof, it just needs to be an easy way for parents to set the level of content their children can access without them having to hover over their children at all times. Something like that could easily be set up in the Genius store when someone gets a new iPhone, or set up at first boot on an Android phone. That's like 90% of the devices anyone is actually worried about. Windows support of the feature would take it to like 99.9%.
If it's a header, you can strip it out at the browser level, the user level, the kernel level, the hardware level, the router level, the router OS level, the router hardware level, or at the ISP level, depending on what a parent (or a state) desired.
The teeth are only necessary for the websites, which are never going to conform to the law anyway, whether through a header or through device attestation, without draconian Chinese-level enforcement that has never been seen in the West before. This new contract will have to be enforced at both endpoints. You will need the ID (whatever you want to call it) to get onto the network, whether you're an individual or the site being visited.
The idea that device attestation is going to bother the Moldovan tube site your kid gets pirated porn through is a surprisingly ignorant fantasy, especially when it comes from technical people. The Pirate Bay is still up. Megaupload is up and runs better than ever. People have 20 year old torrent site accounts. OS-level age attestation must be a first step, because it won't work.
And as to it not being enforced either by the hardware or by identity verification of the user, that's an impossibility. A kid can also overwrite an operating system, or even just overwrite the important part; so that means that either only attested operating systems can be installed, or no user is trusted at any time without state verification.
I'm more concerned with deliberate manipulation of young people by social media. TikTok and its clones especially have demonstrated an incredibly strong ability to not just addict and brainrot kids (which is bad enough -- and it's really, really bad), but also to shape their opinion. All that discussion about the CPC having complete control if they wanted to exert it wasn't BS. Whoever controls them absolutely can use an algorithmic feed to astroturf "viral" videos pushing any narrative they want. Think of Elon Musk in his role as owner of X if you like the CPC.
Anyway. Most tweens and young teens don't know how to use Bittorrent. They use iOS and Android all day, and Chromebooks. These function as closed platforms, and macOS is as well unless you go out of your way. And Windows unless you make your kid an Administrator. Linux and other noncommercial OSS operating systems can have an exception if it makes it less burdensome on the maintainers. This doesn't change the fact that a law like this still solves a ton of problems that parents otherwise can't solve, and that big tech could only solve independently today by very privacy-invasive means.
> because it won't work.
It sounds like you think "work" means "prevent 100% of minors from seeing even a single frame of Bad Stuff anywhere online on any device"
To me "work" means "prevent most children (who aren't extremely technical) from mainstream social media sites openly experimenting on them daily to build a paperclip maximizer, where the paperclips are 'watch minutes' (as a proxy for ad revenue) and the planet being dismantled is our society."
It would "work" by this definition.
> device attestation
this specific term means something specific and is not what this law is about - not sure if you meant to tangle that idea up with this.
It is impossible to win a battle you stop fighting.
I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. Most websites will use it, and it'll become global because it's easier to just demand an ID and a photo for every user through some third party provider than to offer looser restrictions for the handful of states that have different demands.
This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas. Sure, you could scrupulously try to identify which state someone is in and use the appropriate level of verification, but then you might be liable if it turns out it was someone from Texas or Georgia or Britain using a VPN.
You are assuming that age verification must necessarily happen. It needs to be destroyed at every possible juncture.
Hey, give credit where credit's due.
The first to try that was NJ going after 3d printed gun developers.
Newer linux folks like it because they're used to it, people who don't like it use devuan, gentoo, or one of the others that still lets one use openRC or whatever else.
upthread someone mentioned that systemd already has the ability to store the birthdate of a user. Why would an init system need that? It doesn't, but here we are.
Remote desktop services?
Sounds so complicated to actually do.
I would refuse to even give the appearance of compliance in hope to motivate others to do the same.
I expect in response one of the maintainers outside US jurisdiction of their own volition publishes via bittorrent, tor hidden services, and embedding blobs in public blockchains with no help from me.
Then the problem the legislators sought to solve just got a lot worse, while calling a lot of attention to how little power they actually have to control decentralized FOSS software projects.
Of course another point of the project is building the entire thing from source code with deterministic results only takes a few hours. For many, this would be faster than downloading artifacts.
It is not needed for maintainers to publish binaries at all. Publishing signatures on the expected hashes would suffice at worst.
Nobody here is saying that anyone is going to swoop in and physically prevent this software from being distributed on the internet.
> Then the problem the legislators sought to solve just got a lot worse, while calling a lot of attention to how little power they actually have to control decentralized FOSS software projects.
The legislators who passed this don't give a shit about that. Their intended target of this legislation is mainstream devices and mainstream users.
A summary for those not familiar with it:
• Operating systems on devices whose primary user is a child must provide a way for the parent to provide age bracket information about the child.
• They must also provide an API that apps and app stores can use to find out that age range if they need to have limits on what children can do with them.
• They amended it to not apply to most open source operating systems.
Note that there is no actual age verification. It just uses what the parents put in. It is really just requiring each OS to have a standardized parental control system.
It's also the wrong way around: apps shouldn't ask for an age range, apps should provide one and the OS should do the checking.
I also object to it because it's a foot in the door for demanding that websites and apps care about that age range.
And most importantly, devices already provide parental controls in practice, and this law doesn't make those any better, it just unnecessarily cements one aspect of them into law. You can, already, on many devices, say "don't allow installing apps without permission", or "don't allow installing apps except those with this rating".
We could give them a reasonable solution that demonstrably preserves privacy and doesn't inconvenience anyone else (Suppose you want to see all the uncensored everything, you open your new PC or phone and say your DOB is 1/1/1900. Done. Status quo.)
Or we could be alarmist about that, torpedo that plan, and then in 2 more years when people are even MORE pissed, a horrifying new plan comes out, where the government scans your photo ID (with the help of some crappy private contractor of course) and both of them promise to probably not store the info and log your access. And that one manages to scrape by because people are at that point even more pissed and are determined to solve the problem somehow.
The actual 'bad guys' just wouldn't be able to get the public support for that second, shitty plan, if we basically solve the problem now with this very modest plan that's on the table now. Parents can handle this simple one-time out-of-box prompt and it makes sense. Device owner, the parent, that's the one who should make the call.
What your happier future looks like requires both a technical solution, but more importantly political wins to sell that solution as the better one.
The current operating systems weighted by users, are entirely under the control of three major players, who are incentivised to further centralise things.
( I'm counting the three operating systems as Google Play Services, IOS and Windows. Yes, AOSP exists, but it's useless without Google Play Services. ).
I also don't think a device level switch would stop anything for a second, given the number of stories of parents who seem to hand their children their credit card, then complain about them racking up thousands of dollars on Roblox or whatever.
When the light-touch measures fail, the framework will be leveraged to start requiring more centralised and less private solutions.
Makes no sense to treat it like some unwelcome argument
It is frequently a fallacy because D isn't predetermined by A when humans are involved. If you believe in free will, each of B, C, D are independent decisions. Sometimes we stop at A. Sometimes we pass Prohibition as a Constitutional Amendment, and later roll it back.
Believe it or not, there are plenty of people in the US willing to go to jail (or worse) for their beliefs. It’s kind of the founding mythology of the nation.
US history is full of people who successfully challenged violations of their rights and government overreach. Success isn’t guaranteed, sure. It never is. But cowering in fear because the tyrants might put you behind bars is downright un-American.
There's a reason why lawyers generally advise their clients to remain silent.
Most people prioritize their finances (and non-imprisonment) over their rights, and attorneys will optimize for that expressed preference. GP has clearly indicated his priorities are different. That has nothing to do with intelligence. Someone having a different set of values than you does not constitute unintelligence on his part.
His comments on this thread itself which establish intent to not comply with the law?
All power to him for going with his morals but he’s making unforced errors and should instead be contacting one of the several activist legal firms that would at least give him advice on how to protect himself and not follow through with this law if not outright pro bono legal defense.
I am not even an owner of the project, I founded the project, but am now just one of many volunteer contributors. Are they going to mandate wikipedia volunteers alter pages to state guidelines as well?
We must not be afraid of stuff like this. It is blatant overreach I do not expect would stand legal challenge.
I am simply saying I would refuse to write code I do not want to write. I am honestly surprised people think this is such a scary thing to say.
The point of saying this publicly is not in order to harm or help my own defense of a court order from another state I will probably get.
It is to signal to legislators that if they decide to take this fight, it will be done with people not afraid to do it all in public to establish public trust. It is not even okay that people -think- it is possible for our FOSS projects to be altered or backdoored by any random state officials.
What next, asking Torvalds to add KYC to the kernel?
But lets all wait for nothing at all to happen. Then confidence can grow over time that this is unenforceable in any effective way.
They should go back to trying to police piracy via bittorrent (lol).
Although I have no doubt that courts would ultimately side with you, the chance of becoming even a transient focus of a frustrated AG or congressperson looking to pin blame on "Out of touch and recalcitrant techies, the very ones who created this problem," is chilling. It's meant to be chilling, but it often works because he reality of what you'd go through on the way to eventual victory isn't trivial. Maybe you're willing to go through the courts (public opinion and otherwise), but if so the first thing any attorney you employ will beg you to do is stop talking the way you are.
tl;dr I think taking a stand is great, I support that, I think doing it now is a good idea. I don't think you should talk about it in public though, especially not in a literal, "Come and get me" way.
Sure, but you hear about those because of how shocking they are to all sensible people. Actually I bet a lot more kids rack up those charges using cards they stole from mom's purse. Same kids will start trying to sneak mom's old iPhone out of the desk drawer to install "Adult TikTok" on. But again, this is not more concerning than the way my generation rooted around on the top shelf of Dad's closet to find the old Penthouse magazines.
I just don't accept the absolutist idea that if anything can be gotten around by any means, that means it can't still be sensible policy. Which seems to be the attitude taken by two separate groups -
1. Your and my common enemy -- the ones who are eager to enact "Show ID to access this site (trust us!)" verification schemes
2. And the freedom-loving hackers I've been arguing with today, who also detest those schemes but also don't want to see any scheme of any kind.
If the actual priority here is advocacy, with no real desire to litigate, then I'd buy that.
So too will these other silly laws go I expect.
We need to all loudly and publicly say "Fuck off, I will defend my rights if needed", so they understand how expensive the fight is going to be.
Fear is power. Do not give your enemies power.
Any of our original forefathers would recognize today's American federal government as an overreach from their indended form of government.
The only reason we aren't seeing a Boston Tea Party 2.0 over the recent string of coordinated assaults against our inalienable human rights is because surveillance capitalism is already coarsely achieving its goals of suppressing any civic participation which exists between the spectrum of ineffective political protest to the most desperate, radical action.
Some of those among us simply cannot drink this koolaid. A quote from MLK, Jr:
I submit that an individual who breaks a law that conscience tells him is unjust, and who willingly accepts the penalty of imprisonment in order to arouse the conscience of the community over its injustice, is in reality expressing the highest respect for law.
Further reading https://letterfromjail.com/Corporations do whatever seems most profitable. We can't base our understanding of constitutional rights on whether Meta decides to defend them.
Prior to that, export controls prevented PGP source code from being exported from the US. Advocates printed it in books and exported those, which helped clarify the issue.
Bernstein was a math student who made his own encryption software. The government tried to make him register as an arms dealer, and he sued in 1996, with the backing of the EFF. The result was a landmark decision that established source code as free speech and basically destroyed export controls on cryptography.
In 2016, Apple cited the decision when the government tried to hack a suspect's phone, saying they couldn't be compelled to "speak" by writing code.
Sure it is. Lawyers even have a pithy Latin maxim about it: lex non cogit ad impossibilia.
But how would you remove an international distro from "the marketplace" if it's free and not operating a business?
Meta lobbied heavily for this. The fact that they have not decided to use free speech to fight the move that they are lobbying for is not an argument that free speech is irrelevant here.
This is not legal advice but a personal request: please do not get your legal advice from Hacker News. Get it from a lawyer.
> If "free speech" was a valid defense to any legal compliance laws that affect software, then any software company would raise this defense this rather than comply.
Is that some sort of in joke? Meta loves more surveillance, more data and more info about their vassals^W users.
I'm sure their lobbyists were pushing hard to get this law passed.
Absolute worst case we’ll do sneakernet. More likely we’ll just distribute via overlay networks.
Some of us are crazy enough to be full on free speech martyrs, believe it or not.
Have you been to prison? I've been incarcerated before already after having my rights violated. Let's not go there. Make less assumptions.
There are more effective ways protest this law than posting punk-rhetoric on a nerd forum for a project that will likely fly under the governments radar anyway.
You keep saying that, but that's not the realistic outcome. The realistic outcome isn't an injunction forcing you to add code. It'd be to force you to pull it out of circulation.
If there's a law that says "Anyone who distributes X must also Y" and you can't figure out a way to continue distributing X while also doing Y, the way you comply with the law is that you stop distributing X.
With LLM's anyone will be able to disengage such "default wars" in popular software, so there isn't really any border control when LLM's form a large surface area of the border.
In that very same case, the Ninth Circuit Court of Appeals said:
"We emphasize the narrowness of our First Amendment holding. We do not hold that all software is expressive. Much of it surely is not. Nor need we resolve whether the challenged regulations constitute content-based restrictions, subject to the strictest constitutional scrutiny, or whether they are, instead, content-neutral restrictions meriting less exacting scrutiny. We hold merely that because the prepublication licensing regime challenged here applies directly to scientific expression, vests boundless discretion in government officials, and lacks adequate procedural safeguards, it constitutes an impermissible prior restraint on speech."