[HN Gopher] System76 on Age Verification Laws
       ___________________________________________________________________
        
       System76 on Age Verification Laws
        
       Author : LorenDB
       Score  : 792 points
       Date   : 2026-03-06 04:12 UTC (18 hours ago)
        
 (HTM) web link (blog.system76.com)
 (TXT) w3m dump (blog.system76.com)
        
       | akersten wrote:
       | Aaaaand to throw it all away at the end with "well when the
       | rubber meets the road we'll comply anyway, thanks for inhaling my
       | hot air." Take a damn stand and dare them to sue the hacker known
       | as Linux or whatever.
        
         | sahilkerkar wrote:
         | I'd say that anger is better directed towards the legislators
         | in charge of creating these absurd policies, not the folks at
         | System76. It's not reasonable to expect a company to sacrifice
         | its entire business on a moral battlefield.
        
           | jrm4 wrote:
           | Right, but in turn it is _absolutely reasonable and good_ for
           | consumers to threaten a company with (legal) harm or
           | extinction on a moral battlefield.
        
         | bitwize wrote:
         | Age attestation (edited) _is the law_ now in California.
         | Noncompliance can mean stiff penalties. If you don 't like it,
         | write your Congressman.
        
           | rockskon wrote:
           | *attestation, not verification
        
             | gzread wrote:
             | Which means an OS must have a parental controls API, and
             | that's all if means.
        
               | rockskon wrote:
               | No it doesn't. It might lead to that someday, but it
               | isn't that far yet.
        
               | gzread wrote:
               | That is literally what the California and Colorado laws
               | say. Have you read them?
        
               | rockskon wrote:
               | Have you?
               | 
               | To my knowledge they require the OS to have an API for
               | websites and services to access a determination of the
               | age range from.
               | 
               | This is a far cry from the breadth of what a "parental
               | control API" would entail even if it would be part of
               | such a thing.
        
               | gzread wrote:
               | Indeed. It's basically bool AreParentalControlsEnabled();
               | 
               | The way you enable them is by the root user typing a
               | number less than 18.
        
       | arjie wrote:
       | tl;dr they don't like them and don't want them in place but will
       | comply
        
       | Tyrubias wrote:
       | I don't like to shill for companies, but I'm glad System76 made a
       | statement. The addendum does feel like their legal team made them
       | add it though:
       | 
       | > Some of these laws impose requirements on System76 and Linux
       | distributions in general. The California law, and Colorado law
       | modeled after it, were agreed in concert with major operating
       | system providers. Should this method of age attestation become
       | the standard, apps and websites will not assume liability when a
       | signal is not provided and assume the lowest age bracket. Any
       | Linux distribution that does not provide an age bracket signal
       | will result in a nerfed internet for their users.
       | 
       | > We are accustomed to adding operating system features to comply
       | with laws. Accessibility features for ADA, and power efficiency
       | settings for Energy Star regulations are two examples. We are a
       | part of this world and we believe in the rule of law. We still
       | hope these laws will be recognized for the folly they are and
       | removed from the books or found unconstitutional.
       | 
       | Anyways, it feels like all sides of the political spectrum are
       | trying to strip away any semblance of anonymity or privacy online
       | both in the US and abroad. No one should have to provide any
       | personal details to use any general computing device. Otherwise,
       | given the pervasive tracking done by corporations and the rise of
       | constant surveillance outdoors, there will be nowhere for people
       | to safely gather and express themselves freely and privately.
        
         | panja wrote:
         | Gotta find a way to profitability I suppose
        
         | threatofrain wrote:
         | > Anyways, it feels like all sides of the political spectrum
         | are trying to strip away any semblance of anonymity or privacy
         | online both in the US and abroad.
         | 
         | It's not this or that political party, your neighbors simply
         | don't share your values. Maybe you don't agree with their
         | values either -- like to what degree we should be ceding
         | privacy in favor of fighting child exploitation on the
         | internet. Child protection arguments work because it is a
         | compass to the true feelings of your neighbors.
        
           | ls612 wrote:
           | It is as Aristotle said, the average person is a natural born
           | slave (to their emotions, and thus to the rhetoriticians most
           | skilled in changing them). That is why democracy always fails
           | in the end. Americans just had such good geographic and
           | historic luck to delay this reckoning by a century or two.
           | 
           | If you see politics through this lens then the 'democratic
           | backsliding' that has been universal across the world for the
           | past two decades is entirely unsurprising.
           | 
           | Vae Victus.
        
             | kij wrote:
             | _Vae victo -- Vae victis_
        
           | AnthonyMouse wrote:
           | > your neighbors simply don't share your values
           | 
           | The problem with this argument is that _everyone_ agrees with
           | protecting children.
           | 
           | "Think of the children" arguments are the legislator's
           | fallacy: Something must be done, this is something, therefore
           | we must do this.
           | 
           | In reality there are alternative means to accomplish any
           | given goal, and the debate is about what should be done,
           | because no one benefits from using methods that cost more
           | than they're worth.
           | 
           | Well, almost no one. The opportunists who drape themselves in
           | the cloak of "safety" when they want to have the government
           | mandate the use of their services or use it as an excuse to
           | monopolize markets or establish a chokepoint for surveillance
           | and censorship do benefit from the machinations that allow
           | them to screw the majority of the population. But the
           | majority of the population doesn't.
        
             | nicman23 wrote:
             | nah let them die i tell you
        
             | gzread wrote:
             | There's fake protecting children and there's real
             | protecting children. The Colorado and California parental
             | controls API laws (not age verification laws, there is no
             | age verification in these laws) are clearly "real
             | protecting children" since all they do is mandate
             | standardisation of a parental controls API on each OS.
             | 
             | We kept saying parental controls are all that's really
             | needed, these states said "ok then, do parental controls"
             | and we're still complaining.
        
               | nottorp wrote:
               | Who's we? I personally taught my kid to lie about their
               | age so they don't get silly censorship on the internet.
        
               | gzread wrote:
               | Good, if that's what you want for your kids, then don't
               | set them up with a child restricted account. It's
               | completely up to you.
        
               | pluralmonad wrote:
               | If there is such widespread demand for such mechanisms as
               | some comments suggest, why did it take coercion through
               | law making to bring it to market?
        
         | hulitu wrote:
         | > The California law, and Colorado law modeled after it, were
         | agreed in concert with major operating system providers.
         | 
         | So it is Microsoft, Google and Apple pushing for this.
        
           | teekert wrote:
           | Makes sense, these laws are great for the establishment.
           | Difficult to adhere to for newcomers or smaller parties.
           | Compliance to this madness eats away a much larger proportion
           | of thin profits.
        
           | Thorrez wrote:
           | That quote doesn't imply that those companies are pushing for
           | it. The lawmakers might be pushing for it, and the companies
           | might be ambivalent to whether it's done or not but said "if
           | you're going to do this, then it should be worded this way."
           | 
           | Disclosure: I work at Google, but not on anything related to
           | this.
        
         | idle_zealot wrote:
         | > No one should have to provide any personal details to use any
         | general computing device
         | 
         | I agree. I also agree with S76 that some laws regarding how an
         | operating system intended for wide use should function are
         | acceptable. How would you react to this law if the requirement
         | was only that the operating system had to ask the user what age
         | bracket it should report to sites? You get to pick it, it isn't
         | mandatory that it be checked, and it doesn't need to be a date,
         | just the bucket. Is that still too onerous?
         | 
         | I ask because I feel like if we don't do _something_ , the
         | trajectory is that ~every website and app is going to either
         | voluntarily or compulsorily do face scans, AI behavior
         | analysis, and ID checks for their users, and I really don't
         | want to live in that world.
        
           | edflsafoiewq wrote:
           | What makes you think this is going to stave off that world?
           | More likely you'll get both, since I doubt this API is going
           | to satisfy other states' age verification requirements.
        
             | idle_zealot wrote:
             | Sometimes a token effort or theater is sufficient to quell
             | public sentiment. Like the oft-ignored and ineffective
             | speed limits on roads, or the security theater at airports.
             | That only handles the sentiment angle though. You still
             | have to do something about would-be autocrats who want
             | censorship and surveillance tools, and the oligarchs who
             | want tracking and targeting data.
        
           | heavyset_go wrote:
           | > _if we don 't do something, the trajectory is that ~every
           | website and app is going to either voluntarily or
           | compulsorily do face scans, AI behavior analysis, and ID
           | checks for their users_
           | 
           | You're going to get that, anyway. Platforms want to sell
           | their userbases as real monetizable humans. Governments want
           | to know who says and reads what online. AI companies want
           | your face to train their systems they sell to the government,
           | and they want to the be the gatekeepers that rank internet
           | content for age appropriateness and use that content as free
           | training material.
           | 
           | Age verification across platforms is _already_ implemented as
           | AI face and ID scans. This is where we 're already at.
        
             | idle_zealot wrote:
             | I am well aware of the alignment of interests and the
             | dismal state of things. I'm of the opinion that the only
             | way to divert is radical legal action that shatters the
             | defense industry and social media titans, and it sure as
             | hell won't be Gavin Newsom who delivers it.
        
             | gzread wrote:
             | And laws like this California one actually make it more
             | illegal.
        
           | thayne wrote:
           | > How would you react to this law if the requirement was only
           | that the operating system had to ask the user what age
           | bracket it should report to sites? You get to pick it, it
           | isn't mandatory that it be checked, and it doesn't need to be
           | a date, just the bucket. Is that still too onerous?
           | 
           | Isn't that what the CA law is?
        
             | db48x wrote:
             | Almost. Technically an adult must create an account for any
             | non-adult who wants to use the computer, and configure it
             | with the appropriate age category.
             | 
             | Honestly it's the dumbest thing ever. Best just not to play
             | that game.
        
               | ohhnoodont wrote:
               | How is that dumb? It seems reasonable and pragmatic. If
               | the current status quo is ID uploads and face scans, this
               | seems like the better approach. It shifts the
               | responsibility back to parents. All adult service
               | operators have to do is filter requests with the underage
               | HTTP header set.
        
               | db48x wrote:
               | How about the part where children cannot legally create
               | accounts of their own, on computers that they own? I did
               | that by the time I was 10.
               | 
               | > It shifts the responsibility back to parents.
               | 
               | Without these stupid laws parents already _have_ that
               | responsibility.
        
               | ohhnoodont wrote:
               | > How about the part where children cannot legally create
               | accounts of their own, on computers that they own?
               | 
               | Where is that actually stated in any law being discussed?
               | If a parent gives a child a device with admin access,
               | that's their choice to do so. But it also makes sense
               | that we, the minds behind all of this technology, also
               | provide parents with the most basic of tools to restrict
               | a child's access online and hold accountable companies
               | that knowingly serve adult content to children. That's
               | all the CA law does AFAIK.
               | 
               | Sure, my generation was raised on 4chan. But I can
               | understand why parents today may want the tools to limit
               | that.
        
             | idle_zealot wrote:
             | Unfortunately no. There's a requirement that the OS
             | disregard the user-indicated age if it has reason to think
             | they're lying. Presumably this creates the obligation to
             | monitor the user for such indicators.
        
               | vineyardmike wrote:
               | I assume this is less "if they're lying" and more "if
               | you've independently collected this data". It doesn't
               | require you to challenge the user-indicated age, it
               | requires you to use your own signal before that of the
               | OS.
               | 
               | As a silly example, tax software probably has your full
               | birthday, including year, which is more precise. Many
               | social networks collected this data, as did a lot of
               | major tech companies that implemented parental controls
               | already.
        
           | AnthonyMouse wrote:
           | The main problem with the "report your age to the website"
           | proposals is that they're backwards. You shouldn't be leaking
           | your age to the service.
           | 
           | Instead, the service should be telling your device the nature
           | of the content. Then, if the content is for adults and you're
           | not one, your parents can configure your device not to
           | display it.
        
             | ray_v wrote:
             | It may often times be trickier than that - content often
             | mixed of course. My 10 y/o hit me with a request yesterday
             | to play Among Us where the age verification system wanted
             | my full name, address, email, AND the last 4 digits of my
             | SSN. I refused.
        
               | AnthonyMouse wrote:
               | > It may often times be trickier than that - content
               | often mixed of course.
               | 
               | So put the content tag at the granularity of the content.
        
               | valleyer wrote:
               | Honestly, <span content-filter-level="adult">fuck</span>
               | that.
        
               | onli wrote:
               | Awesome. Now you have a system where every blog entry,
               | every Facebook post needs a lawyer consultation.
               | 
               | Around 20 years ago, Germany actually made a law that
               | would have enforced such a system. I still have a chart
               | in my blog that explained it, https://www.onli-
               | blogging.de/1026/JMStV-kurz-erklaert.html. Content for
               | people over 16 would have to be marked accordingly or be
               | put offline before 22:00, plus, if your site has a
               | commercial character - which according to german courts
               | is every single one in existence - you would need to hire
               | a someone responsible for protecting teenagers and
               | children (Jugenschutzbeauftragten).
               | 
               | Result: It was seen as a big censor machine and I saw
               | many sites and blogs shut down. You maybe can make that
               | law partly responsible for how far behind german internet
               | enterprises still are. Only a particular kind of
               | bureaucrat wants to make business in an environment that
               | makes laws such as this.
               | 
               | Later the law wasn't actually followed. Only state media
               | still has a system that blocks films for adults
               | (=basically every action movie) from being accessed
               | without age verification if not past 22:00.
        
               | AnthonyMouse wrote:
               | > Now you have a system where every blog entry, every
               | Facebook post needs a lawyer consultation.
               | 
               | You have that with any form of any of these things.
               | They're almost certainly going to be set up so that you
               | get in trouble for claiming that adult content isn't but
               | not for having non-adult content behind the adult content
               | tag.
               | 
               | Then you would be able to avoid legal questions by
               | labeling your whole site as adult content, with the
               | obvious drawback that then your whole site is labeled as
               | adult content even though most of it isn't.
               | 
               | But using ID requirements instead doesn't get you out of
               | that. You'd still need to either identify which content
               | requires someone to provide an ID before they can view
               | it, or ID everyone.
               | 
               | That's an argument for not doing _any_ of these things,
               | but not an argument for having ID requirements instead of
               | content tags.
        
               | onli wrote:
               | Funnily enough, marking content that's harmless as only
               | for adults was also punishable, though that might have
               | been in context of a different law. That would be
               | censorship, blocking people under 18 from accessing legal
               | content, was the reasoning. Welcome to German
               | bureaucracy.
               | 
               | But you are right. It's an argument that the "just mark
               | content accordingly" is also not a better solution, not
               | that ID requirements are in any way better. The only
               | solution is not to enable this censorship infrastructure,
               | because no matter which way it's done, it will always
               | function as one.
        
               | AnthonyMouse wrote:
               | > Funnily enough, marking content that's harmless as only
               | for adults was also punishable, though that might have
               | been in context of a different law. That would be
               | censorship, blocking people under 18 from accessing legal
               | content, was the reasoning. Welcome to German
               | bureaucracy.
               | 
               | That's how you get the thing where instead of using
               | different equipment to process the food with and without
               | sesame seeds, they just put sesame seeds in everything on
               | purpose so they can accurately label them as containing
               | sesame seeds.
        
               | LinXitoW wrote:
               | An internet where every wikipedia article has like a
               | picture of boobs as fine print would be very funny.
        
               | gzread wrote:
               | I understand they can't say "contains sesame seeds" if it
               | doesn't, but why can't they say "processed on equipment
               | that also processes sesame seeds" like some packages do?
        
               | AnthonyMouse wrote:
               | Some jurisdictions tried to ban them from saying maybe
               | which is when they started putting them in on purpose so
               | they could say definitely.
        
               | close04 wrote:
               | > Awesome. Now you have a system where every blog entry,
               | every Facebook post needs a lawyer consultation.
               | 
               | The alternative is that "just to be safe" you'll mark
               | your entire site as needing age (identity, stool sample,
               | whatever) verification. A single piece of sensitive
               | content sets the requirements for the entire site.
        
               | like_any_other wrote:
               | > plus, if your site has a commercial character - which
               | according to german courts is every single one in
               | existence - you would need to hire a someone responsible
               | for protecting teenagers and children
               | (Jugenschutzbeauftragten).
               | 
               | That is pretty much what the UK Online Safety Act
               | requires:
               | https://en.wikipedia.org/wiki/Online_Safety_Act_2023
               | 
               | Many small forums had to simply shut down, as was widely
               | reported on HN at the time.
        
               | cwillu wrote:
               | That's an argument for "let the service inform the parent
               | and let the parent decide", not against it.
        
               | alexfoo wrote:
               | There's a good chance that they're never going to verify
               | any of the information you give them, in which case it's
               | another download for Mr M Mouse of 1375 E Buena Vista Dr,
               | 32830, with a SSN that ends in 1234.
        
               | b112 wrote:
               | Giving fake info feeds the machine. It means you still
               | consume, and a bad actor profits.
        
               | thbb123 wrote:
               | I disagree. Giving fake info adds noise to the mechanism,
               | makes it useless. Ultimately I'm inclined to believe that
               | privacy through noise generation is a solution.
               | 
               | If I ever find some idle time, I'd like to make an agent
               | that surfs the web under my identity and several fake
               | ones, but randomly according to several fake personality
               | traits I program. Then, after some testing and analysis
               | of the generated patterns of crawl, release it as
               | freeware to allow anyone to participate in the
               | obfuscation of individuals' behaviors.
        
               | noam_k wrote:
               | You might want to take a look at differential privacy. It
               | takes an unintuitive amount of noise to make the system
               | useless.
               | 
               | You also need to account for how "easy" it is to de-
               | anonymize a profile.
               | 
               | (Sorry I don't have links to sources handy.)
        
               | aleph_minus_one wrote:
               | > You might want to take a look at differential privacy
               | 
               | Differential privacy is just a bait to make surveillance
               | more socially acceptable and to have arguments to silence
               | critics ("no need to worry about the dangers - we have
               | differential privacy"). :-(
        
               | fsflover wrote:
               | Sounds a bit like AdNauseam Firefox extension.
        
               | thbb123 wrote:
               | In my vision, it's the opposite of ad blocker, it's
               | something that generates non existent traffic and views
               | beyond what I would have done.
        
               | wholinator2 wrote:
               | I believe that is what adnauseum does. Fake clicking ads
               | and things like that
        
               | autoexec wrote:
               | And just like AdNauseam using it would be dangerous and
               | pointless.
        
               | b112 wrote:
               | _Giving fake info adds noise to the mechanism_
               | 
               | Yes, but in this case which we're discussing:
               | 
               |  _It may often times be trickier than that - content
               | often mixed of course. My 10 y /o hit me with a request
               | yesterday to play Among Us where the age verification
               | system wanted my full name, address, email, AND the last
               | 4 digits of my SSN. I refused._
               | 
               | The bad actor still gets ROI, eg 'paid', for another bit
               | of user data.
               | 
               | Making the overall system less useful is good. However,
               | not allowing a company to profit, and giving fake info
               | still allows for that, is paramount. EG, even with fake
               | info, many metrics on a phone are still gamed and
               | profitable.
               | 
               | That's why they're collected, after all. For profit.
        
               | autoexec wrote:
               | > I disagree. Giving fake info adds noise to the
               | mechanism, makes it useless.
               | 
               | There's no such thing as useless info. Companies will
               | sell it, buy it, and act on it regardless of how true it
               | is. Nobody cares if the data is accurate. Nobody is
               | checking to see if it is. Filling your dossier with false
               | information about yourself won't stop companies from
               | using that data. It can still cost you a job. It can
               | still be used as justification to increase what companies
               | charge you. It can still influence which policies they
               | apply to you or what services they offer/deny you. It can
               | still get you arrested or investigated by police. It can
               | still get you targeted by scammers or extremists.
               | 
               | Any and all of the data you give them will eventually be
               | used against you somehow, no matter how false or
               | misleading it is. Stuffing your dossier with more data
               | does nothing but hand them more ammo to hit you with.
        
               | acomjean wrote:
               | Last century my dad would give our pets names out with
               | our real phone #(oddly or by mistake). The pets did start
               | getting phone calls.
               | 
               | If the info becomes bad, it becomes much less useful and
               | valuable.
               | 
               | I'm in the us and we o need some rights to privacy.
        
               | TYPE_FASTER wrote:
               | I made the mistake of providing my date of birth as being
               | 1/1/1900 on multiple websites, and have been receiving
               | marketing material from the AARP in the mail for many
               | years.
        
               | just6979 wrote:
               | That's not a mistake. You'd be getting spam marketing
               | anyway, why not make sure it's something obvious? I
               | always pick the oldest possible age when asked, just to
               | mess with their data, because they shouldn't fucking
               | care.
               | 
               | Don't limit, notify.
               | 
               | Has worked for TV (and movies to an extent, though
               | theaters do limit somewhat, must have been some
               | litigation around that...) pretty much forever.
        
               | roryirvine wrote:
               | My "birthdate" is the same as yours. It was fine when I
               | started using it in the late 90s, but has become
               | increasingly awkward over the past few years - lots of
               | sites seem to assume a maximum age of 120.
               | 
               | If I ever turn uBO off, the ads I get are mostly for
               | funeral plans or incontinence products, with a smattering
               | of "126 year old mom lost 30 lbs of belly fat - click to
               | see how!" (yeah, decomposition's a bitch...)
        
               | palmotea wrote:
               | > If I ever turn uBO off, the ads I get are mostly for
               | funeral plans or incontinence products, with a smattering
               | of "126 year old mom lost 30 lbs of belly fat - click to
               | see how!" (yeah, decomposition's a bitch...)
               | 
               | And, for the record, it's way better to get ads for BS
               | like that than stuff that may actually influence you.
        
               | iso1631 wrote:
               | It feels to me that parental controls are seen as another
               | profit centre. If we want to put laws in place, we should
               | be putting in laws to empower parents.
        
               | VLM wrote:
               | I would assume its fake and an attempt at identify theft
               | at some level of the system. Is their PC infected at the
               | OS level or just a fraudulent browser extension or
               | something more like a popup ad masquerading as a system
               | dialogue? A less trusting person would assume any request
               | made by a computer is totally non-fraudulent and would
               | gladly submit any requested private information.
               | 
               | "Dad, I can't do my math homework, a pop up says you need
               | to provide a copy of your bank statement, your mom's
               | maiden name, and a copy of your birth certificate, SS
               | card, and drivers license, and can you hurry up Dad, my
               | homework is due tomorrow morning." And people will fall
               | for this once they get used to the system being absurd
               | enough.
               | 
               | The fraud machine must be kept fed...
        
               | just6979 wrote:
               | If the content is mixed, it makes even more sense to have
               | the content supply the age data. This is how it has
               | worked with broadcast media pretty much forever. TV shows
               | and movies gain their ratings based on the worst case on
               | display. IE: a show doesn't have to consist entirely of
               | swearing to gain a "language" warning, it just has to
               | have some. Definitively mixed content.
               | 
               | I think your example exemplifies this. Among Us is not
               | inherently adult-only, but since it's multiplayer, they
               | don't control what other player say and do. Definitively
               | mixed content. They should not be asking you to verify,
               | they should be telling you and letting you decide if your
               | kid can play.
               | 
               | I kinda can't beleive their lawyers decided to go that
               | route and assume all the PII responsibility that comes
               | with collecting that data, instead of just making the
               | "it's online and there might be d-bags on our servers"
               | rating much more obvious and explicit.
        
               | autoexec wrote:
               | They can profit off of the personal data they collect, so
               | it's no surprise they'd take any opportunity and use any
               | available excuse to collect more of it. From their
               | perspective there is effectively zero responsibility to
               | secure that data properly and handle it safely because
               | there are effectively zero consequences for companies
               | when they fail to.
        
             | tuetuopay wrote:
             | Heh that's already what parental controls do (granted, the
             | website don't report the content, and it's based on
             | blacklists), but they are trivial to bypass. Even the
             | article mention it:
             | 
             | > The child can install a virtual machine, create an
             | account on the virtual machine and set the age to 18 or
             | over
             | 
             | It's precisely how I worked around the parental control my
             | parents put on my computer when I was ~12. Get Virtualbox,
             | get a Kubuntu ISO, and voila! The funniest is, I did not
             | want to access adult content, but the software had
             | thepiratebay on its blacklist, which I _did_ want.
             | 
             | In the end, I proudly showed them (look ma!), and they
             | promptly removed the control from the computer, as you
             | can't fight a motivated kid.
        
               | AnthonyMouse wrote:
               | > but they are trivial to bypass.
               | 
               | That's assuming the parental controls allow the kid to
               | create a virtual machine. And then that the kid knows how
               | to create a virtual machine, which is already at the
               | level of difficulty of getting the high school senior who
               | is already 18 to loan you their ID.
               | 
               | None of this stuff is ever going to be Fort Knox. Locks
               | are for keeping honest people honest.
        
               | Ntrails wrote:
               | If the kid knows how to ask an llm, they can do whatever
               | technical hacks are required
        
               | autoexec wrote:
               | Would that make the LLM (or the company who made it)
               | liable under the DMCA for showing someone how to work
               | around a digital lock that controls access to a
               | copyrighted work.
        
               | tuetuopay wrote:
               | We could argue on the technical feasability all day, as
               | non-kvm qemu does not need any special permission to run
               | a VM (albeit dog slow).
               | 
               | I honestly don't really agree on the difficulty, as if
               | this becomes a commonplace way to bypass such laws, you
               | can expect tiktok to be full of videos about how to do
               | it. People will provide already-installed VMs in a
               | turnkey solution. It's not unlike how generations of kids
               | playing minecraft learnt how to port forward and how to
               | insatll VPNs for non-alleged-privacy reasons: something
               | that was considered out of a kid's reach became a
               | commodity.
               | 
               | > None of this stuff is ever going to be Fort Knox. Locks
               | are for keeping honest people honest.
               | 
               | On that we agree, and it makes me sad. The gap between
               | computer literate and illiterate will only widen a time
               | passes. Non motivated kids will learn less, and motivated
               | ones will get a kickstart by going around the locks.
        
               | AnthonyMouse wrote:
               | > We could argue on the technical feasability all day, as
               | non-kvm qemu does not need any special permission to run
               | a VM (albeit dog slow).
               | 
               | That's assuming the permission is for "use of kernel-mode
               | hardware virtualization" rather than "installation of
               | virtualization apps".
               | 
               | Notice that if the kid can run arbitrary code then any of
               | this was already a moot point because then they can
               | already access websites in other countries that don't
               | enforce any of this stuff.
        
               | stavros wrote:
               | It might be Fort Knox just fine at some point, when
               | computers will require a cryptographically signed
               | government certificate that you're over 18, and you can't
               | use the computer until you provide it.
        
               | AnthonyMouse wrote:
               | Even in that case the large majority of the population
               | would then have that certificate and the motivated minors
               | would just beg, borrow or steal one.
        
               | voakbasda wrote:
               | No one has ever faked a government ID?
        
               | stavros wrote:
               | Nope, not a zero-knowledge proof with cryptographic
               | signatures.
        
               | b112 wrote:
               | _And then that the kid knows how to create a virtual
               | machine_
               | 
               | It's just a bunch of clicks, even under linux.
               | 
               | Just install virtualbox. It literally walks you through a
               | VM creation.
        
               | AnthonyMouse wrote:
               | > It's just a bunch of clicks
               | 
               | I promise there are people who can't figure out how to do
               | it.
               | 
               | And again, the point of the lock on the door where you
               | keep the porn is not to be robustly impenetrable to entry
               | by a motivated 16 year old with a sledgehammer, it's only
               | to make it obvious that they're not intended to go in
               | there.
        
               | bonoboTP wrote:
               | Depends on how much people want the hidden content.
               | People in Eastern Europe, regular people, noch tech wiz
               | kids, know how to use torrent and know about seed ratios
               | etc. At least it was so ca 5 years ago. People can learn
               | when the thing matters to them.
               | 
               | Regular people want to get things done, the tinkering is
               | not a goal for them in itself and they gravitate to
               | simple and convenient ways of achieving things, and don't
               | care about abstract principles like open source or tech
               | advantages or what they see as tinfoil hat stuff. But if
               | they want to see their favorite TV series or movie, they
               | will jump through hoops. Similarly for this case.
        
               | ycombinator_acc wrote:
               | There's an ocean of difference between your device
               | changing behavior based on a flag set by individual sites
               | and your device using a blacklist set by some list
               | maintainer - the main difference being that the latter is
               | utterly useless due to being an example of badness
               | enumeration.
        
               | muyuu wrote:
               | a kid who can install Linux, or set up an ssh tunnel to a
               | seedbox, is a kid who doesn't need to be told by the
               | government what he or she should be watching
               | 
               | that is the job of parents/guardians
        
               | sidewndr46 wrote:
               | I'd actually argue that's exactly the kid who the
               | government is there to tell them what they shouldn't be
               | watching. The government is never really there to
               | restrict the incompetent, they are pretty good at doing
               | that themselves.
        
               | muyuu wrote:
               | it's the kid they are up against to, but not the kid who
               | "needs" it
        
             | idle_zealot wrote:
             | > Instead, the service should be telling your device the
             | nature of the content. Then, if the content is for adults
             | and you're not one, your parents can configure your device
             | not to display it.
             | 
             | That makes sense for purely offline media playback, but how
             | could that work for a game or application or website? Ship
             | several versions of the app for the different brackets and
             | let the OS choose which to run? Then specifically design
             | your telemetry to avoid logging which version is running?
             | 
             | You'd also not be reporting your age, you'd be sending a
             | "please treat me like an adult" or "please treat me like a
             | child" flag. That's hardly PII. More like a dark/light mode
             | preference, or your language settings (which your browser
             | does send).
        
               | lavela wrote:
               | The shifts between flags will correlate with date of
               | birth though, or do you think someone turning 16 or 18
               | will wait a year or two to switch to more adult content
               | for privacy? Also I'd guess the tech industry would push
               | for more specific age buckets.
               | 
               | Games already have PG ratings and similar in different
               | countries, I don't see the issue there. Web content could
               | set a age appropriateness header and let browsers deal
               | with it, either for specific content or for the whole
               | website if it relies on e.g. addictive mechanics.
               | 
               | Applications is a wide field, but I'd be interested in
               | specific examples where you think it wouldn't work.
        
               | idle_zealot wrote:
               | > Applications is a wide field, but I'd be interested in
               | specific examples where you think it wouldn't work.
               | 
               | Sure. Take a game with voice chat. Child mode disables
               | voice chat. How does the game, which presumably uses a
               | load of telemetry, avoid incidentally leaking which users
               | are children via the lack of voice telemetry data coming
               | from the client? It's probably possible, but the fact is
               | we're talking about third party code running on a
               | computer, and the computer running different code paths
               | based on some value. The third party code _knows that
               | value_ , and if it has internet access can exfiltrate it.
               | In that sense, if there's an internet connection, there's
               | not a meaningful difference between "the OS tells the
               | service/app your age rating preference" and "the OS
               | changes what it displays based on your age rating
               | preference."
               | 
               | Though while I'm throwing out fantasy policies we could
               | solve this by banning pervasive surveillance outright.
        
               | AnthonyMouse wrote:
               | You're assuming that everything not mandatory is
               | prohibited. If the device is required to provide every
               | service with the flag, every service gets the flag, even
               | if it contains no adult content or adult content that the
               | user agent could display or not without the service
               | having a way to know about it.
               | 
               | The service would then have to deduce the information
               | instead of getting it explicitly and may be able to do
               | that some of the time instead of all of the time, which
               | is an improvement. And then people can work on anti-
               | fingerprinting technologies with the premise that if they
               | succeed it actually does something, instead of the
               | information being required by law to leak to the service.
        
               | AnthonyMouse wrote:
               | > That makes sense for purely offline media playback, but
               | how could that work for a game or application or website?
               | Ship several versions of the app for the different
               | brackets and let the OS choose which to run?
               | 
               | Suppose you had an ID requirement instead. Are you going
               | to make two different versions of your game or website,
               | one for people who show ID and another for people who
               | don't? If so, do the same thing. If not, then you have
               | one version and it's either for adults only or it isn't.
               | 
               | > You'd also not be reporting your age, you'd be sending
               | a "please treat me like an adult" or "please treat me
               | like a child" flag.
               | 
               | Except that you essentially are reporting your age,
               | because when you turn 18 the flag changes, which is a
               | pretty strong signal that you just turned 18 and once
               | they deduce your age they can calculate it going forward
               | indefinitely.
               | 
               | This is even worse if it's an automated system because
               | then the flag changes _exactly_ when you turn 18, down to
               | the day, which _by itself_ is ~14 bits of entropy towards
               | uniquely identifying you and in a city of a 100,000
               | people they only need ~17 bits in total.
        
               | gzread wrote:
               | The alternative wasn't an ID requirement, the alternative
               | was the client/OS sending the flag to the server/app.
        
               | AnthonyMouse wrote:
               | The fear is that once you have devices sending services a
               | flag, some asshats are going to start demanding that it
               | be verified by the government.
               | 
               | But how does that do anything for you either way? Either
               | you have two different versions based on whether the flag
               | is present or not or you have one version and if it's
               | adults only then you have to send the flag indicating
               | you're an adult in order to use it.
        
               | gzread wrote:
               | Browsers send a language flag to servers but I don't see
               | anyone asking for a certification that you actually know
               | that language.
        
               | AnthonyMouse wrote:
               | I don't see anyone asking that browsers be legislatively
               | required to send a language tag without certification
               | either.
        
               | l72 wrote:
               | Games already have ratings. Every app submitted to the
               | App Store or Google Play is rated.
               | 
               | 90% of an R rated movie might be ok for a 12 year old but
               | those one or violent or sex scenes makes it R. Should we
               | be rating every scene in movies?
               | 
               | Give parents general guidance and let them define the
               | controls.
        
             | panzi wrote:
             | Exactly. Except this way you can't build a complete
             | biometric database if all citizen! Since it's so obvious
             | how to do it correctly without creating such a database one
             | could make the assumption the creation of such a database
             | is the actual goal.
        
             | IndySun wrote:
             | Who decides the 'nature' of the content? Who decides what
             | constitutes age appropriate?
             | 
             | These questions of liberty are as old as the hills. And the
             | keepers of the internet and virtually every single
             | government past and present have repeatedly and endlessly
             | shown themselves to be lying, conniving, self interested
             | parties. When will 'we' ever learn?
             | 
             | *who decides who 'we' are.
        
             | gzread wrote:
             | It's necessary if the page contains mixed content. Under
             | your proposal, Google Search would need a separate search
             | page that shows adult content, and that would be even worse
             | for privacy - logs would show whether you accessed the
             | adult search page - and adult sites (not only porn) would
             | try quite hard to not be relegated to that second, less
             | discoverable, search page.
        
               | _heimdall wrote:
               | What you're describing with Google Search already exists,
               | search engines already offer their own search settings
               | including "safe search" or whatever they call it which
               | filters out adult images.
               | 
               | Services can absolutely decide to provide their own
               | content settings. It doesn't require a universal setting
               | or OS requirements, and it doesn't require providing PII
               | to every website or telling a central authority every
               | site you visit.
        
             | avhception wrote:
             | I haven't even thought of this, I'm kinda surprised! This
             | should be how it's done!
        
             | glitchc wrote:
             | Windows already allows this. Content can be set based on
             | age in Microsoft Family. Set an age on a user's account and
             | MS curates the store experience, regardless of which
             | computer the user is logged into.
        
             | qzx_pierri wrote:
             | >Then, if the content is for adults and you're not one,
             | your parents can configure your device not to display it.
             | 
             | That would require people to be a responsible adult and
             | actively parent their kids.
             | 
             | It's ironic, because people in this country identify with
             | how hard they grind at work, but refuse to put a fraction
             | of that effort into being an involved parent.
             | 
             | It's easier to just let the government ruin everyone else's
             | good time online.
             | 
             | In return, the parents:
             | 
             | 1. Get the illusion that their kids are safer (they aren't)
             | 
             | 2. Get a clear conscience, and feel better mentally
             | equipped to run on their corporate hamster wheel
        
           | sophrosyne42 wrote:
           | The push to do biometric data collection is entirely the
           | result of entrepreneurs trying to get ahead before laws are
           | passed. Their behavior is the result of the push to restrict
           | the open internet. If we don't do anything, they will stop.
           | You don't always have to do "something". Sometimes the harm
           | comes by trying to do something.
        
           | flir wrote:
           | > Is that still too onerous?
           | 
           | Isn't it just pointless?
           | 
           | I'm getting upset by face scan creep too. I do not like it.
           | No sir. But mandating a _self-reporting_ mechanism feels
           | about as useful as DNT cookies, or those  "are you 18?
           | yes/no" gates on beer sites.
        
             | idle_zealot wrote:
             | It'd be more useful than DNT because there would be legal
             | teeth on the side of the sender and receiver of the signal.
             | It'd be more useful than the yes/no gates because an
             | operating system could choose to allow the creation of
             | child accounts.
             | 
             | I.e. it would be a standardization of parental controls
             | with added responsibility on sites/apps to self-determine
             | if they should be blocked or limit functionality, rather
             | than relying on big white/blacklists. Basically an
             | infrastructure upgrade, rather than relying on a patchwork
             | of competing private solutions to parental controls and age
             | checks. The hope is also that a system like this would
             | remove concerned parents from the list of supporters for
             | pervasive mass surveillance and age scans. If they feel
             | like you'd need to be a moron to miss the "This is a child
             | device" button while setting up their kid's phone and
             | laptop, and it's broadly understood that just pressing that
             | button locks down what the device can access pretty
             | effectively, that puts and damper on the FUD surrounding
             | their child's internet usage.
        
           | latentsea wrote:
           | > I agree. I also agree with S76 that some laws regarding how
           | an operating system intended for wide use should function are
           | acceptable. How would you react to this law if the
           | requirement was only that the operating system had to ask the
           | user what age bracket it should report to sites? You get to
           | pick it, it isn't mandatory that it be checked, and it
           | doesn't need to be a date, just the bucket. Is that still too
           | onerous?
           | 
           | What's the point in doing any of this if it doesn't result in
           | materially better outcomes?
        
             | idle_zealot wrote:
             | The point is that I think it's one of a few things that if
             | done together could result in better outcomes. First, it
             | standardizes parental controls, which ought to be so easy
             | to use that failure to do so is nearly always a proactive
             | decision on the part of the guardian. It doesn't need to be
             | perfect, just reduce friction for parents and increase
             | friction for kids accessing the adult internet.
             | 
             | Second, it would signal to worried parents and busybodies
             | that something has been done to deal with the danger that
             | unmediated internet access might pose to minors. I don't
             | think that it's a big issue, but a lot of energy has gone
             | into convincing a lot of people that it is.
             | 
             | The other part of achieving a good outcome would be to
             | disempower those in the political and private sphere who
             | benefit from a paranoid and censorious public and have
             | worked to foment this panic. That's the much harder part,
             | but it's not really the one being discussed here. I'm
             | pitching the low-intrusiveness version to gauge sentiment
             | here for that easier part of the path.
        
               | latentsea wrote:
               | Your last point is the only one I partially agree with.
               | The rest... will make no practical difference to what is
               | going on in the world today.
               | 
               | I genuinely think the only two solutions to this problem
               | that are workable are "zero privacy, zero freedom" or
               | "fuck the children, we don't care".
               | 
               | Now, to be fair... there is a middle-ground that is
               | neither of those options that I believe would be much
               | more effective and allow us to retain our freedom and
               | privacy and keep kids a lot safer. It's called education.
               | But... no one will go for it, because I think for it to
               | truly be effective you'd have to go as far as showing
               | very young kids all the darkness that's out there and lay
               | it out in paintstaking detail exactly how it works and
               | deeply drill it into them. Ain't a snowballs chance in
               | hell anyone would go for that, BUT... would it work? I'd
               | bet you bottom dollar it would. The current extent of
               | this education in public schools is a half hour visit
               | from a police offer to the classroom and handing out a
               | sheet to the kids and giving a 'good touch' / 'bad touch'
               | talk. What's needed is a full length university level
               | course on the whole topic from end to end.
               | 
               | If you're in an adversarial relationship and need to
               | defend yourself the best thing you can do is "know your
               | enemy". But no... "they're too young to learn about that
               | stuff, we need to shield them from it - think of the
               | children!" is the reasoning people throw back at you when
               | you suggest it. It hands down has to be the number one
               | thing that could actually move the dial significantly,
               | and it's just completely unpalatable to the majority of
               | the populace.
        
               | hellojesus wrote:
               | > First, it standardizes parental controls, which ought
               | to be so easy to use that failure to do so is nearly
               | always a proactive decision on the part of the guardian.
               | 
               | If this mattered to the market, don't you think a company
               | would have implemented it or would have been built to
               | fill the need?
        
               | idle_zealot wrote:
               | 1. No, I don't think that the market does what people
               | want. That's not the primary reward signal.
               | 
               | 2. I'm making an _ought_ statement of values, like  "we
               | ought not pollute rivers." I don't really care what any
               | system of resource allocation has to say about that.
        
           | iugtmkbdfil834 wrote:
           | Sadly, the only real response here is non-compliance.
           | Recently, credit card company wanted me to provide ID upon
           | login ( I was amused -- while my setup may not be common, it
           | has not changed for years now ). So I didn't and just ignored
           | it. I checked on it this month and it suddenly was fine. But
           | then.. one has to be willing to take a hit to their credit
           | and whatnot.
           | 
           | The point remains though. They have zero way to enforce it if
           | we choose to not comply. Just saying.
        
             | idle_zealot wrote:
             | They have plenty of ways to enforce it. It's a law, they
             | can take you to court. I guess it's easy to forget these
             | days but laws do still apply to some people. If you're
             | going to host a service, I guess consider using Tor or
             | something.
        
               | iugtmkbdfil834 wrote:
               | Friend. On this very forum, you will normally see me
               | argue that further deterioration of civil society is bad
               | and we should be doing everything to maintain society as
               | is. However, as with most things, there is a limit. That
               | limit varies from person to person, but it is getting
               | harder and harder to argue that laws apply ( especially
               | once you recognize they don't quite apply across the
               | board ).
               | 
               | << If you're going to host a service, I guess consider
               | using Tor or something.
               | 
               | That one confused me. What do you mean?
        
               | hellojesus wrote:
               | I think the person meant that if you don't comply there
               | may be civil or criminal consequences, so if you want to
               | knowingly provide a non compliant website or app, you
               | should host it on tor to prevent your person from being
               | the subject of the state.
               | 
               | I know the CA law is civil only, so I don't think there
               | is much CA can do if you publish an OS and don't make
               | money from CA folks, but other implementations may decide
               | to impose criminal penalties.
        
               | iugtmkbdfil834 wrote:
               | Thank you. That makes sense.
        
           | Alan_Writer wrote:
           | Totally agree, but I think we are heading to a full intrusion
           | system in every aspect. And this is just the beginning. Even
           | decentralized identity systems are not that decentralized, of
           | course.
        
           | tsukikage wrote:
           | My objection to all this stuff is the requirement to share
           | government ID / biometrics / credit card info etc with
           | arbitrary third party sites, their 228 partners who value my
           | privacy and need all my data for legitimate interest, and
           | whatever criminals any of those leak everything to, and also
           | give the government an easily searchable history of what I
           | read when those sites propagate the info back.
           | 
           | Any scheme that doesn't require this won't get pushback from
           | me.
           | 
           | As an alternative: I already have government-issued ID and
           | that branch of government already has my private info; have
           | it give me a cryptographic token I can use to prove my age
           | bracket to the root of trust module in my computer; then
           | allow the OS to state my age to third parties when it needs
           | to with a protocol that proves it has seen the appropriate
           | government token but reveals nothing else about my identity.
           | 
           | Other alternatives are possible.
        
             | biofox wrote:
             | That would require technical know-how.
             | 
             | It's much easier for clueless lawmakers to write "the
             | computer check the age", and make it everyone else's
             | problem.
        
           | Xelbair wrote:
           | Exactly the same way as i do now for such laws.
           | 
           | It's pointless, does not increase security, does increase
           | complexity of every interaction, and introduces a lot of
           | weird edge cases.
           | 
           | What i want is full anonymity enshrined in law, while at the
           | same time giving parents, not governments, but parents,
           | options to limit what their children can do on the internet.
        
           | soulofmischief wrote:
           | A cornerstone philosophy behind the American legal system is
           | that we must view every single increase in State power as a
           | potential slippery slope, and must _prove_ that it isn 't.
           | 
           | In this case, it's a slippery slope; if we're normalized to
           | this, what other incursions into our 1A rights to free
           | speech, religious freedom and public gathering will we allow?
           | 
           | And I say religious freedom, because these kinds of laws are
           | largely peddled by religious folk or people who otherwise
           | have been deeply influenced by early American Puritan
           | religious culture.
           | 
           | I, nor my children, should be forced to subject to such
           | religiously-motivated laws. I can decide for myself and for
           | my child what is appropriate.
           | 
           | I, nor my children, cannot be compelled to enter personal
           | information into a machine created by someone who is also
           | illegally compelled to require it.
           | 
           | I, nor my children, can be compelled to avoid publicly
           | gathering on the internet just because we don't want to show
           | identification and normalize chilling surveillance
           | capitalism.
           | 
           | I thought this was fucking America.
        
           | jprjr_ wrote:
           | I think a better approach would be incentives versus
           | punishments.
           | 
           | Like - you don't make it illegal to not do age attestations,
           | but you provide a mechanism to encourage it.
           | 
           | You get a certification you can slap on your website and
           | devices stating you meet the requirements of a California
           | Family-Friendly Operating System or whatever. Maybe that
           | comes with some kind of tax break, maybe it provides
           | absolution in the case of some law being broken while using
           | your OS, maybe it just means you get listed on a website of
           | state-recommended operating systems.
           | 
           | That certification wouldn't necessarily have to deal with age
           | attestation at all. It could just mean the device/OS has
           | features for parents - built-in website filtering, whatever
           | restrictions they need. Parents could see the label and go
           | "great, this label tells me I can set this up in a kid-safe
           | way."
           | 
           | Hell, maybe it is all about age certification/attestation.
           | Part of that certification could be when setting it up, you
           | do have to tell it a birthdate and the OS auto-applies some
           | restrictions. Tells app stores your age, whatever.
           | 
           | The point is an OS doesn't want to participate they don't
           | have to. Linux distros etc would just not be California
           | Family-Friendly Certified(tm).
           | 
           | I wouldn't have to really care if California Family-Friendly
           | Certified(tm) operating systems are scanning faces, IDs,
           | birth certificates, collecting DNA, whatever. I'd have the
           | choice to use a different operating system that suits my
           | needs.
        
           | pc86 wrote:
           | > _I also agree with S76 that some laws regarding how an
           | operating system intended for wide use should function are
           | acceptable._
           | 
           | The only laws the government should pass regulating software
           | running on someones computer are laws protecting those
           | consumers from the companies writing that software. For
           | example, anti-malware/anti-spyware.
           | 
           | The government has no business telling a random company that
           | their software needs to report my age, whether it's
           | unverified and self-reported or not.
        
             | idle_zealot wrote:
             | > protecting those consumers from the companies writing
             | that software
             | 
             | Of course, but that's exactly the framing of the
             | verification laws. Protecting underage computer users from
             | products/services unsuitable for them. If you want
             | protection to be effective then it needs to be on by
             | default, but also needs to ultimately be controlled by the
             | user, and it's that second part that ID checks and the like
             | fail.
        
           | ApolloFortyNine wrote:
           | >I ask because I feel like if we don't do something, the
           | trajectory is that ~every website and app is going to either
           | voluntarily or compulsorily do face scans, AI behavior
           | analysis, and ID checks for their users, and I really don't
           | want to live in that world.
           | 
           | The only reason they'd _have_ to do that is government laws
           | making them do so. When the law is vague around what age
           | verification is, if one company decided to do ID
           | verification, now any site that doesn't might not be doing
           | 'enough' in the eyes of the law (it'd come down to a court
           | case if not specifically defined).
           | 
           | Though it may seem more convenient to just do it at the os
           | level (though really the browser level would make more sense
           | with a required header/cookie no?), I'd be shocked if you
           | don't see it expanded in the future to be more than a
           | checkbox.
        
           | Hizonner wrote:
           | > You get to pick it, it isn't mandatory that it be checked,
           | and it doesn't need to be a date, just the bucket. Is that
           | still too onerous?
           | 
           | Yes, because (a) it wouldn't do anything, and (b) it would
           | take about 5 seconds for the morons who push this stuff to
           | start whining about that fact, and using the fact that
           | "Society(TM) has mandated this and people are avoiding it" to
           | demand effective verification, which would be a huge
           | disaster.
           | 
           | They won't be placated by anything short of total victory,
           | and if you give them anything, you're just enouraging them.
        
         | shevy-java wrote:
         | > Accessibility features for ADA
         | 
         | The problem is that the comparison falls flat. ADA does not
         | sniff for birth date and surrender that data to others. One has
         | to look at things at a cohesive unit, e. g. insecure
         | bootloaders by Microsoft surrendering data to others. It seems
         | as if they try to make computers spy-devices. That in itself is
         | suspicious. Why should we support any such move? Some laws are
         | clearly written by lobbyists.
        
         | FpUser wrote:
         | I remember western public laughing about requirement of the
         | former USSR to register a typewriters. So we have a case of he
         | who slays the dragon becomes one
        
         | gzread wrote:
         | The California law doesn't strip away any anonymity or privacy
         | except for the additional fingerprint signal of you being a kid
         | or not, which is no worse than Accept-Language
        
           | hellojesus wrote:
           | It kind of does. Depending on how the mechanism works, if I
           | check the user's age every time my executable is launched,
           | and my user launches daily, I can determine with certainty
           | what the user's birthday is. That information may be enough
           | to deanonyimize in rural regions. It certainly gives away
           | pii.
        
             | gzread wrote:
             | One allowed way to implement it is that your mom has to log
             | in as root and unrestrict your account, and the user's age
             | is only set to one of 4 different brackets so you'd better
             | be watching the user every day for several years. Also if
             | you are root you can just lie.
        
         | sharperguy wrote:
         | The same politicians who claim to support the free market will
         | do deals like ttis with corporate oligopolies to cement their
         | position into eternity.
        
         | curt15 wrote:
         | >Anyways, it feels like all sides of the political spectrum are
         | trying to strip away any semblance of anonymity or privacy
         | online both in the US and abroad. No one should have to provide
         | any personal details to use any general computing device.
         | 
         | What was the legislative history for the California law? Who
         | sponsored it, and who are their backers? Is there some
         | coordinated effort by surveillance state proponents?
        
         | jadbox wrote:
         | Why can't it be the BROWSER that reports age instead of the OS?
        
         | strangattractor wrote:
         | Cigarette vending machines had little stickers that said it was
         | illegal for those under 18 to purchase cigarettes. Sure stopped
         | all my friends from buying them.
         | 
         | Seems exactly like the useless process fixation that Abundance
         | advocates abhor.
        
         | cmxch wrote:
         | Still not good enough to comply in advance.
        
       | piraccini wrote:
       | I love Pop!_OS (and Cosmic) but if they start with this bullshit
       | I need to switch to other Linux distributions. Worst case, will
       | build my own...
        
         | byproxy wrote:
         | What constitutes "this bullshit"?
        
         | winrid wrote:
         | Your ISP will require it.
        
           | whywhywhywhy wrote:
           | Crazy how few can see where this is heading and don't realize
           | locked down OS with age verification is now the norm, iOS has
           | it.
        
       | hellojesus wrote:
       | Are these laws not 1A violations due to code being speech and the
       | gov not being allowed to compel speech?
        
         | dragonwriter wrote:
         | To the extent code is functional rather than expressive it is
         | _not_ speech, and when the government seeks to compel code, it
         | generally seeks to compel _function_ not expressive content.
         | 
         | (That doesn't mean it is not a bad idea, and even perhaps
         | unconstitutional for other reasons.)
        
           | arcfour wrote:
           | Code is speech, though, and is protected by the first
           | amendment: see Bernstein v. United States.
           | 
           | I don't think a cryptographic algorithm is "expressive" any
           | more than it is purely functional; indeed, the 9th circuit
           | evaluated and rejected the expressive/functional distinction
           | for source code in the above case.
           | 
           | Regardless - code is speech, and the government cannot compel
           | or prevent speech except in very narrow circumstances.
        
             | johncolanduoni wrote:
             | Very narrow circumstances like the DMCA? I don't think the
             | jurisprudence is as simple as you're making it out to be.
        
             | LoganDark wrote:
             | Code may be speech, but the functional characteristics of
             | systems that happen to rely on code may not always also be
             | speech.
        
               | arcfour wrote:
               | I'm not sure what you're trying to say, but if you are
               | suggesting that writing an "API", as is legally required
               | in AB1043, can be done without writing code I would be
               | interested to know how!
        
               | dragonwriter wrote:
               | Writing an API is not required by AB1043.
               | 
               | Providing an API is required if you do some other thing,
               | but you are not required to do that other thing.
               | Requirements that are triggered by engaging in some other
               | activity are not compulsions if the activity they are
               | triggered by is not compulsory. (Now, whether restricting
               | the thing that triggers the requirement by adding the
               | requirement is permissible is a legitimate question, but
               | that is not the question that is addressed when you
               | ignore the thing triggering the requirement and treat the
               | requirement as a free-standing mandate.)
        
               | arcfour wrote:
               | > Provide a developer who has requested a signal with
               | respect to a particular user with a digital signal via a
               | _reasonably consistent real-time application programming
               | interface_ that identifies, at a minimum, which of the
               | following categories pertains to the user...
        
               | dragonwriter wrote:
               | Yes, and the other thing you have to do for this to be
               | applicable to you is choose to be an "operating system
               | provider", as defined in the law.
               | 
               | If you don't want to write, hire someone to write, pay
               | someone to provide an implementation that has already
               | been written, or acquire an implementation already
               | written that is available without payment, such an API,
               | you can simply choose _not_ to do what is defined as
               | being an "operating system provider", and no obligation
               | attaches,
               | 
               | No one is putting a gun to your head and forcing you to
               | do labor to write code for an API.
        
               | arcfour wrote:
               | If you write an operating system and distribute it (an
               | act of speech) you are forced to do this or else you risk
               | $7500/child/day in fines from the California AG. The law
               | makes no distinction between Terry Davis and Microsoft.
               | (In fact, you could say TempleOS is protected _religious_
               | speech...!)
               | 
               | I don't know what's wrong with you, honestly, that you
               | would so vivaciously defend this impractical, immoral and
               | completely nonsensical law so vivaciously.
               | 
               | It is seriously disturbing.
        
               | iamnothere wrote:
               | > I don't know what's wrong with you, honestly, that you
               | would so vivaciously defend this impractical, immoral and
               | completely nonsensical law so vivaciously.
               | 
               | I do, these people are entryists and they have evil goals
               | in mind.
               | 
               | Do not hire people like this, and block them from working
               | on your projects.
        
             | dragonwriter wrote:
             | > Code is speech, though, and is protected by the first
             | amendment: see Bernstein v. United States.
             | 
             | That is very much overstating the holding in the case [0],
             | the most relevant part of which seems to be:
             | 
             | "encryption software, in its source code form and as
             | employed by those in the field of cryptography, must be
             | viewed as expressive for First Amendment purposes"
             | 
             | The ruling spends a key bit of analysis discussing the
             | expressive function of _source code_ in this field as
             | distinct from the function of object code in controlling a
             | computer.
             | 
             | A law compelling providing functionality which it is merely
             | most convenient to comply with by creating source code as
             | part of the process _is not_ directing speech, any more
             | than an law delivery of physical goods where the most
             | convenient method of doing so involves interacting by
             | speech with the person who physically holds them on your
             | behalf is.
             | 
             | [0] text here: https://law.resource.org/pub/us/case/reporte
             | r/F3/176/176.F3d...
        
               | panny wrote:
               | >A law compelling providing functionality
               | 
               | That's forced labor. I'm not required to write a line of
               | code to please anyone. It's free software with no
               | warranty. They have LLMs, let's see them build it. :)
        
               | dragonwriter wrote:
               | > > A law compelling providing functionality
               | 
               | > That's forced labor.
               | 
               | Well, that's a 13th Amendment issue not a 1st Amendment
               | one, but, in any case, its not _forced_ if it doesn 't
               | direct who does the work to create the functionality,
               | only requires you to have the functionality provided if
               | you are doing some other activity, it is more of an in-
               | kind tax. [0] (Now, if you want to make an argument that
               | when the activity it is conditioned on is expressive that
               | that makes it a 1A violation as a content-based
               | regulation when the condition is tied to the content of
               | the expressive act, _that_ is a better 1A argument, that
               | might actually have some merit against many of the real
               | uses of, say, age verification laws; but "if I am doing
               | this activity, I must either create or acquire and use
               | software that has a specified function" is not, in
               | general, a 1A violation.)
               | 
               | [0] It's not really that other than metaphorically,
               | either, any more than _every regulation of any kind_ is
               | an "in-kind tax", but its far closer to that than "forced
               | labor".
        
               | panny wrote:
               | >its not forced if it doesn't direct who does the work
               | 
               | Good, because I'm not writing it, f\/ck them. Free
               | software, no warranty. Use it if you want to. Otherwise,
               | pound sand.
        
               | Dylan16807 wrote:
               | > Good
               | 
               | Don't you mean "bad"? Shouldn't you _want_ it to be a
               | violation of the constitution so it gets thrown out?
        
               | arcfour wrote:
               | > In the government's view, by targeting this unique
               | functional aspect of source code, rather than the content
               | of the ideas that may be expressed therein, the export
               | regulations manage to skirt entirely the concerns of the
               | First Amendment. This argument is flawed for at least two
               | reasons...
               | 
               | I think you should read it a bit more closely. The court
               | threw out the "functional/expressive" argument for source
               | code, like I said in my original comment.
               | 
               | Secondly, what are you talking about that source code is
               | the most "convenient" way to implement this? It's the
               | literal, only possible way to present an interface to a
               | user, ask them a question, and "signal" to other
               | applications if the user is a minor or not. You're being
               | completely nonsensical there. There's no other way to do
               | that: someone must write _some_ code. The bill
               | specifically says  "an API"!
        
               | dragonwriter wrote:
               | I think you should read a bit more closely, both to the
               | decision, and to the post you are responding to (which
               | addresses that), and to the context of what is being
               | discussed in the thread (which is not "source code").
        
               | arcfour wrote:
               | I look forward to your blog post on how to implement "an
               | API" without writing source code. It should be
               | informative!
        
               | labcomputer wrote:
               | Real Men use a magnetized needle.
        
         | cobbzilla wrote:
         | Bernstein v US says you're right but let's see if it gets there
         | and hope they get legal reasoning right. One can hope the EFF
         | and others are on this. Anyone know about any current
         | challenges?
        
         | gzread wrote:
         | To about the same extent that food labeling is a 1A violation.
        
           | muyuu wrote:
           | I'm not American but it seems to me like both things are
           | violations, which is troubling because you enter into the
           | disturbing necessity to start carving exceptions
           | 
           | obviously these regulations are very different, but both do
           | compel speech
        
             | gzread wrote:
             | Yes. And yet nobody opposes food labelling except for
             | fraudulent food companies. Sometimes people just think
             | compelled speech is good.
        
       | cyberax wrote:
       | The age verification laws are awesome!
       | 
       | I mean... How else would you educate children about computers and
       | evading stupid restrictions?
        
       | jrm4 wrote:
       | I mean, genuine question, is Linux Mint or MX Linux endangered by
       | this?
       | 
       | Unless I'm missing something, I have _zero_ concern for companies
       | who sell out by complying.
       | 
       | The code was "free as in freedom" when you decided to build your
       | company on it; and while you're not legally obligated to defend
       | that freedom, and I, and hopefully other consumers, find that you
       | are _morally_ obligated to.
        
         | pgn674 wrote:
         | I think this is the way that Linux desktop distributions are
         | endangered, quoting from the article: "... apps and websites
         | will not assume liability when a signal is not provided and
         | assume the lowest age bracket. Any Linux distribution that does
         | not provide an age bracket signal will result in a nerfed
         | internet for their users."
        
         | gzread wrote:
         | Not by the California law, since that law poses no danger.
        
       | k310 wrote:
       | I have to wonder
       | 
       | A. If end users will mod their distros to send a "signal" (TBD?)
       | to websites.
       | 
       | B. If end users will just grab a pirate OS with apps compiled to
       | not care about age.
       | 
       | Hopefully the latest TAILS I downloaded is free of Big (over 18)
       | Brother. And (A)
       | 
       | Or just compile, Gentoo and LFS style.
       | 
       | C. If pirates just take care of all this for friends and
       | neighbors.
       | 
       | D. When, not if, this unconstitutional coercion is challenged in
       | court and cancelled via petition. Remember Proposition 8?
        
         | armadyl wrote:
         | I could see them eventually going far enough to bypass all of
         | that and either requiring age verification at the point of the
         | internet uplink on the ISP side or making it a crime similar to
         | using a fake ID to buy alcohol if you try to bypass it. And
         | then also punish companies that happen to be serving
         | underage/non verified users.
        
           | akersten wrote:
           | There is already age verification at the ISP level. They only
           | sell Internet service to adults. What the adults choose to do
           | with it or with whom they share it with should be of zero
           | concern to the government.
           | 
           | Of course, that's an ineffective argument, because the long-
           | term goal of these laws (in the sense of, "the goal of the
           | system is what it does") was never going to be about keeping
           | kids off the Internet.
        
         | deno wrote:
         | Yes, it will be ineffective, so then they will point at all
         | those examples, but will they decide the law is stupid? Of
         | course not.
         | 
         | The computers are not secure and they should only be able to
         | run "verified" operating systems using attestation mechanisms.
         | This was always where this was ultimately going. The idea has
         | been fermenting since the DVD players had copy protections.
         | 
         | It's the planet destroying asteroid. We know the trajectory, we
         | always knew it was coming for us. But once you can see with the
         | naked eye it's too late to do anything.
        
         | gzread wrote:
         | Why do you have to mod your distro when you could simply go to
         | the settings program and set "age bracket" to "18+"?
        
       | al_borland wrote:
       | > Throwing them into the deep end when they're 16 or 18 is too
       | late.
       | 
       | I saw this a lot in college. Kids that didn't have any freedom or
       | autonomy while living at home went wild in college. They had no
       | idea how to self-regulate. A lot of them failed out. Those who
       | didn't had some rough years. Sheltering kids for too long seems
       | to do more harm than good. At least if they run into issues while
       | still children, their parents can be there to help them through
       | it so they can better navigate on their own once they move out.
        
         | FuckButtons wrote:
         | Counterpoint, my parents didn't shelter me from shit and my
         | life went off the rails at 12.
        
           | Guestmodinfo wrote:
           | 12 is the magic number when things start going to shit. I'm
           | sorry for what happened to you but maybe you should start a
           | counselling service for clueless parents and tell them what
           | should they do and what they shouldn't to correctly shelter
           | the children. Because sheltering is an art. I think about it
           | all the time. I always wish some one would take a bit of
           | money but tell me how to guide or not guide my child to be
           | independent in the rough world and to take decisions
           | independently
        
             | discardable_dan wrote:
             | I watched an older sibling go off the rails. That is what
             | kept me from doing it.
        
           | ball_of_lint wrote:
           | There needs to be both things - the opportunity to make
           | mistakes, and the support to make it okay after mistakes are
           | made.
           | 
           | Sounds like you got the first but not the second, which must
           | have been tough. Hope you're doing better now.
        
           | Dylan16807 wrote:
           | That's not a counterpoint. The inverse of "shelter too long"
           | is "shelter less long", not "zero shelter ever".
           | 
           | (And the proper way to do "less long" is to slowly loosen up
           | over time.)
        
             | FuckButtons wrote:
             | I think the point I'm trying to make, albeit very bluntly
             | is people often make the banal point that kids these days
             | are too sheltered because they turned out fine. But they're
             | actually just observing survivorship bias.
        
               | Aachen wrote:
               | How to avoid that survivorship bias though?
               | 
               | I'm sure a study can follow kids or look in records, but
               | that takes serious time, so I can understand looking at
               | oneself and everyone you know and coming to a conclusion
               | that way. Do you know if such a study had been done and
               | the results or conclusions are publicly available
               | somewhere?
        
               | Dylan16807 wrote:
               | The person you replied to didn't mention their own life
               | at all, and they were talking about a good number of data
               | points. That's not "just survivorship bias". The data of
               | college kids _is_ biased in some ways but it 's not
               | useless.
        
           | lawn wrote:
           | There's a balance to be struck, it shouldn't be all or
           | nothing.
        
         | jusssi wrote:
         | Potential confusion of cause and effect: maybe some weren't
         | given any freedom _because_ they were repeatedly unable to
         | self-regulate.
        
           | Tade0 wrote:
           | It's not an innate ability. Takes a solid decade of actual
           | parenting for people to acquire this skill.
           | 
           | And if the person is high energy, then that energy needs to
           | be channeled.
        
           | mrheosuper wrote:
           | if they are unable to self-regulate, then jailing them at
           | home and school is definitely not a solution for that.
        
             | jusssi wrote:
             | I think you're responding to an argument I didn't make. And
             | I feel necessary to point it out because it looks like
             | other people may be reading it like that, too.
        
               | Aachen wrote:
               | I read it in the same way. What did you mean instead?
        
               | jusssi wrote:
               | I mean what I wrote, nothing more.
               | 
               | (a) Quote from TFA is about using internet. GP talks
               | about "didn't have any freedom or autonomy" which I don't
               | take quite as literally as you do, because they also
               | mention "I saw this a lot in college". So it would have
               | been quite regular level of (over)controlling, _instead
               | of locking them in and not letting them leave the house
               | except for school_.
               | 
               | (b) I am not advocating anything as a solution. I am
               | pointing out that the simple cause and effect presented
               | by GP might be more complicated.
        
           | themafia wrote:
           | Then it's a questionable move to one day hand them _all_ the
           | responsibility they had previously lacked.
           | 
           | You can also ask if the rate of this occurrence is increasing
           | or decreasing.
        
           | pona-a wrote:
           | It is a common tactic among abusive parents to convince their
           | child without them, they'd be unable to survive in the wider
           | world. Any mistakes will become irrefutable proof thereof,
           | and any attempts to break this control and do things on their
           | own will be treated as ingratitude, often prompting the
           | abuser to instantly abandon all parental duties to "teach a
           | lesson".
        
             | jusssi wrote:
             | Uh huh. And some kids haven't got their head straight after
             | puberty at 16, and still need (or would have needed) the
             | training wheels. Blaming it on their parents would seem
             | unfair.
             | 
             | Society works on averages. Most people being ready little
             | adults at 16 doesn't mean everyone is.
             | 
             | Edit: yeah, look at the downvotes. How are you all doing
             | with that self-regulation?
        
               | Hizonner wrote:
               | > And some kids haven't got their head straight after
               | puberty at 16, and still need (or would have needed) the
               | training wheels.
               | 
               | But _on average_ they don 't.
               | 
               | > Society works on averages.
               | 
               | Right. So setting the rules around the outliers is wrong.
               | Glad you're clear on that.
               | 
               | > Most people being ready little adults at 16 doesn't
               | mean everyone is.
               | 
               | You don't have to be a completely self-sufficient adult
               | to handle the freaking Internet.
        
               | jusssi wrote:
               | I feel like I'm in a comedy show where I'm the only one
               | who actually reads what others are writing.
        
               | pessimizer wrote:
               | There's no evidence in this response or others that
               | you're reading what other people are writing.
        
             | crims0n wrote:
             | I don't disagree, but in this context I don't think those
             | are the same parents that are yeeting their kids off to
             | board at university as soon as they are of age.
        
               | Hizonner wrote:
               | Sometimes the kids basically _run away_ to universities
               | as soon as they 're of age.
        
               | xerox13ster wrote:
               | As one of those kids, you could've just stopped at "I
               | don't think", because you're not thinking critically if
               | you think we don't exist.
               | 
               | I wasn't allowed to have a personal device or
               | unsupervised internet access until I graduated.
               | 
               | My parents forced me to go to a school with a summer work
               | program. I was yeeted to university by my wing clipping
               | abusers THREE DAYS AFTER GRADUATION.
               | 
               | Rural, miles from the nearest town of 1200 so I didn't
               | have access to the resources needed to change any aspect
               | of this.
               | 
               | I was deeply hampered by this, and despite being one of
               | the salutatorians of my graduating class (we had ties due
               | to AP), I crashed out of that university after a
               | semester.
        
         | 2OEH8eoCRo0 wrote:
         | This is a comforting fiction. I've seen it go both ways where
         | children with freedom develop pornography or drug habits and
         | sheltered kids turn out well-adjusted and regulated.
        
           | HighGoldstein wrote:
           | Freedom without supervision vs supervision without freedom,
           | both failures of parenting.
        
             | 2OEH8eoCRo0 wrote:
             | How is the supervision without freedom a parenting failure
             | if they've turned out great in every regard?
        
               | al_borland wrote:
               | That's usually coupled with a lot of anxiety. Some level
               | anxiety could be useful, as it can make a person look
               | responsible. This can come at a heavy cost though, which
               | they may not let others see, and might not even realize
               | themselves until later in life.
        
               | Aachen wrote:
               | A failure of management can still lead to a successful
               | business for a variety of reasons, ranging from an in-
               | demand product and lucky timing to great employees. Bad
               | parenting with a great child or a great school might,
               | too, lead to positive outcomes
               | 
               | I'd call an approach suboptimal or bad depending on how
               | likely it is to lead to bad outcomes, given what the
               | parents know about the child at the time of course
               | (sheltering or other special approaches may be needed in
               | some cases, depending on behavior or health
               | circumstances). It doesn't have to turn out bad in every
               | single case, or even a majority, there just has to be
               | consensus about the evidence and the parents must have
               | been able to know of it. It would have to be really bad
               | (like complete neglect) before I'd call it a failure
               | though
        
               | array_key_first wrote:
               | Because they don't. In order to do anything successfully
               | you need practice. You're just depriving the kid of
               | practicing the single most important skill - autonomy.
        
               | eikenberry wrote:
               | Supervision is only one of many factors that impact a
               | child's development. Good genes alone can make up for a
               | lot of crappy parenting.
        
           | thunderfork wrote:
           | "pornography habits"
           | 
           | Putting onanism in the same sentence as drug abuse really
           | weakens your argument.
        
             | 2OEH8eoCRo0 wrote:
             | Onanism != pornography habit
        
           | Aachen wrote:
           | I thought it was a typo but I see you've replied elsewhere
           | that these really are the two options
           | 
           | > I've seen it go both ways where children with freedom [turn
           | bad] and sheltered kids turn [good]
           | 
           | So you've seen it one way, as in, each approach leading to
           | one specific outcome? "Both ways" would be sheltered leading
           | to different outcomes in different cases, or unsheltered
           | leading to different outcomes in different cases
           | 
           | I don't feel like I've been sheltered. My parents literally
           | proposed that I drink some alcohol and encouraged that I go
           | out partying at some point. Both things still don't interest
           | me. (At least they didn't tell me to smoke, lol. But alcohol
           | seems to be considered normal and potentially even healthy in
           | small doses so they thought I should try it.) Online, I later
           | learned that their opinion was that I'll just not look up
           | things which I don't want to see, and in my case that has
           | been true. I'm sorry to tell you I never had a porn addiction
           | 
           | Someone else pointed out that such anecdotes are survivorship
           | bias: you might not see the people that didn't turn out
           | alright. In my case that's certainly true, I'm not sure that
           | I know anyone who didn't turn out okay. We take different
           | paths through life but if you can provide for yourself and
           | dependents, and are happy most of the time, I'd count that as
           | success (also dependent on age: I'm not counting that my 90yo
           | grandpa is currently often unhappy due to bad health)
        
       | trinsic2 wrote:
       | I have been saying this all along. You can't prevent kids from
       | getting around restrictions. All you can do is try to help them
       | understand what they find on the other side and what some options
       | are. Age-gating is just a way to push forward a surveillance
       | agenda. The fact thats happening everywhere all at once proves my
       | point.
        
         | dylan604 wrote:
         | >You can prevent kids from getting around restrictions
         | 
         | I'm guessing you meant can't
        
           | trinsic2 wrote:
           | Yes. Fixed
        
         | heavyset_go wrote:
         | It's pushed both by those with surveillance agendas and AI
         | companies like Anthropic, who donated millions to PACs and
         | politicians that are pushing online age verification and
         | surveillance laws[1].
         | 
         | The goal for the AI side is that they get to be censors and
         | gatekeepers of all user-generated content on the internet,
         | their models will rank/grade/censor content for age-
         | appropriateness and they will have the pleasure of being paid
         | to train on all new content uploaded to the internet in real-
         | time, in perpetuity.
         | 
         | [1] https://news.ycombinator.com/item?id=47162956
        
         | bruceb wrote:
         | You can. Most children are not going to end up on HN when they
         | are older. The stories you read here about hacking system at 11
         | are outliers.
        
           | leni536 wrote:
           | And the outliers brag about them, then help out their
           | classmates.
        
             | hellojesus wrote:
             | Lol I remember back in the day when we used to replace the
             | windows logo during boot with our own bitmaps (if I can
             | appropriately remember the file format) at school. We
             | showed kids and suddenly every computer was booting with
             | unexpected media. Admins were not pleased.
             | 
             | But the real fun began when we showed people how to set
             | bios passwords and that cascaded into kids rendering an
             | entire classroom of computers unbootable.
             | 
             | And then there was the time I thought I was really clever
             | because I realized I could open arbitrary files in notepad,
             | so I attempted to edit save files for a learn-to-type
             | program by replacing the score with my own. It seemed to
             | work so I told my friends and then they started copying the
             | same save file into their program files. I don't remember
             | exactly what happened, but I do know the UI update did not
             | propagate to the actual scores and also it introduced a bug
             | into the prodgram which would cause it to crash at distant
             | future epochs, so we destroyed the program for everyone,
             | not just our user profiles. There was an investigation and
             | I think they gave up because the same bad file somehow was
             | on everyone's computer and everyone just told them they got
             | the file from someone else and there was no root of the
             | chain.
             | 
             | This is all to say, any bypass will be identified and
             | implemented at the speed of virality.
        
         | stephbook wrote:
         | What you're saying is we should allow kids to buy tobacco, to
         | gamble, to purchase Meth and Heroine because Kids get around
         | restrictions anyway
        
           | budududuroiu wrote:
           | > What you're saying is we should allow kids to buy tobacco,
           | to gamble, to purchase Meth and Heroine because Kids get
           | around restrictions anyway
           | 
           | This is false equivalence. All of the above are vices that
           | objectively carry more harm than good. There's no inherent
           | harm in using a computer, there's a subset of ways in which
           | using a computer can be harmful, which kids can be taught how
           | to avoid or navigate, there's no subset of meth use that
           | isn't harmful
        
             | heavyset_go wrote:
             | Desoxyn (methamphetamine) is prescribed for ADHD and is
             | indicated for children
        
             | gzread wrote:
             | Well then it's good then computer will have the option to
             | disable the harmful stuff, so a parent can let a kid use
             | the good stuff without the harmful stuff.
        
         | gzread wrote:
         | It's basically the same as forbidding bars from serving minors.
         | Minors can still get alcohol, but we still do it.
        
       | ArchieScrivener wrote:
       | California and Colorado do not get to govern out of state
       | residence, thats interstate commerce and its federal domain,
       | period.
       | 
       | The time is coming where we will unseat legislative traitors who
       | use EU/Old World manipulations in the USA.
       | 
       | An unjust law is no law at all. That is the exception the rule of
       | law requires to remain moral.
        
       | heavyset_go wrote:
       | Just a reminder of what liability the CA age verification law
       | imposes upon developers and providers.
       | 
       | It's not enough to adhere to the OS age signal:
       | 
       | > _(3) (A) Except as provided in subparagraph (B), a developer
       | shall treat a signal received pursuant to this title as the
       | primary indicator of a user's age range for purposes of
       | determining the user's age._
       | 
       | > _(B) If a developer has internal clear and convincing
       | information that a user's age is different than the age indicated
       | by a signal received pursuant to this title, the developer shall
       | use that information as the primary indicator of the user's age._
       | 
       | Developers are still burdened with additional liability if they
       | have reason to believe users are underage, even if their age flag
       | says otherwise.
       | 
       | The only way to mitigate this liability is to confirm your users
       | are of age with facial and ID scans, as it is implemented across
       | platforms already. Not doing so opens you up to liability if
       | someone ever writes "im 12 lol" on your app/platform.
        
         | stephbook wrote:
         | How do you know all this before any court decided upon it?
        
           | heavyset_go wrote:
           | Do you want to go to court to find out where the line is?
           | That's expensive, risky and time consuming. It's easier to
           | just scan faces and IDs to make sure your users are of age
           | and not take on that liability.
        
         | wtallis wrote:
         | > if they have reason to believe users are underage
         | 
         | The law requires "clear and convincing information", not merely
         | "reason to believe". And since the law requires developers to
         | rely on the provide age signal as the _primary_ indicator of
         | the user 's age, developers are not incentivized to create a
         | system that uses sophisticated data mining to derive an
         | estimated age. If someone posts a comment on a YouTube video
         | saying "I'm twelve years old and what is this?", that would
         | absolutely _not_ require YouTube to immediately start treating
         | that account as an under-13 account.
        
           | heavyset_go wrote:
           | That would have to be litigated in court, and the easiest and
           | cheapest way to avoid litigation is to just scan faces and
           | IDs so you're sure your users won't upload or say anything
           | that can bankrupt you while you sleep.
        
             | wtallis wrote:
             | It would be at least as valid a strategy to _avoid_
             | collecting any unnecessary personal information about your
             | users, so that you don 't have to worry about whether the
             | information you've amassed adds up to "internal clear and
             | convincing information".
             | 
             | Remember, only the state AG can bring a suit under this
             | law, and the penalty is limited to $2500 per child for
             | negligent violations. It's probably cheaper to get
             | insurance against such a judgement than to implement an
             | invasive ID-scanning age verification system (and assume
             | the risks of handling such highly-sensitive personal
             | information).
        
               | heavyset_go wrote:
               | No platform is going to forgo analytics and using
               | demographic information for advertising, that's their
               | bread and butter.
               | 
               | I'd also argue it's clear and convincing if a kid changes
               | their profile picture to a selfie of themselves, says
               | they're 12, says they're in grade school, etc. Any
               | reasonable person would take that at face value.
               | 
               | > _implement an invasive ID-scanning age verification
               | system (and assume the risks of handling such highly-
               | sensitive personal information)_
               | 
               | It's already implemented as face and ID scans by all the
               | major platforms as it is. The systems are already there
               | and they're already deployed.
               | 
               | Apps and platforms already integrate with 3rd party age
               | verification platforms who handle the face and ID data,
               | nothing ever has to touch your servers.
        
               | Dylan16807 wrote:
               | > I'd also argue it's clear and convincing if a kid
               | changes their profile picture to a selfie of themselves,
               | says they're 12, says they're in grade school, etc. Any
               | reasonable person would take that at face value.
               | 
               | That's so fragile, and it's not like they're making those
               | claims to the site, it's natural language posting.
               | 
               | And someone who knows what they're doing would never take
               | "I'm twelve years old and what is this?" at face value.
        
               | heavyset_go wrote:
               | Would you be willing to send explicit content to someone
               | who presents themselves as a child online? A reasonable
               | person wouldn't.
               | 
               | No one is suggesting a meme should be taken literally.
        
               | Dylan16807 wrote:
               | You've completely changed the scenario. A human doing a
               | one on one examination and personally sending data is
               | totally different from a website allowing an account to
               | exist and browse.
        
               | heavyset_go wrote:
               | I'm using send as a synonym for serve, would you serve
               | such content to someone who presents themselves as a
               | child on your platform? No.
               | 
               | Like do you really think someone who presents themselves
               | as a child on Pornhub will stay registered and not
               | banned? They aren't going to serve porn to someone who
               | presents themselves as a kid.
               | 
               | I think it's pretty clear and convincing when someone
               | presents themselves as a child on your platform. I'd be
               | convinced and wouldn't take that liability on.
        
               | hellojesus wrote:
               | I agree with you, but then the implication becomes, "any
               | platform that allows user content must scan all content
               | posted or uploaded by the user to determine if any of it
               | suggests they are a minor".
               | 
               | I adds a bit of burden to all sites under the threat of
               | civil penalties. Say I own a site that allows user posts
               | like HN. If someone mentions they're in grade school in
               | any post and later starts receiving links to adult sites
               | in their DMs, now I'm liable.
        
               | Dylan16807 wrote:
               | "presents themselves" is too vague here. Presents to who?
               | When you talk about a person instead of a webserver, that
               | person is actually reading the profile, which makes a big
               | difference.
               | 
               | In the pornhub situation, someone who reads the comments
               | will report them. The website doesn't need to throw
               | machine learning at everything people type.
        
               | crote wrote:
               | ... except that analyzing profile pictures isn't exactly
               | reliable (plenty of people use photos of their cats),
               | people lie in chat, and advertising profiles are _at
               | best_ an educated guess.
               | 
               | The current analytics profiles are closer to "
               | _definitely_ into Roblox, 70% chance of being 13-18 "
               | than "This user was beyond any reasonable doubt born on
               | 07-03-2002". Calling them "clear and convincing
               | information" would be a _massive_ exaggeration.
        
         | crote wrote:
         | I read it the exact opposite way: you are _forbidden_ from
         | using facial and ID scans solely for age verification (as the
         | OS-provided signal shall be the primary indicator of age), but
         | if you already need to obtain the user 's age for other reasons
         | using more reliable means (say, a banking KYC law requiring ID
         | scans) you are not _required_ to discard this more reliable
         | source in favor of the OS-provided signal.
        
           | gzread wrote:
           | I read it as you're not _allowed_ to discard the more
           | reliable source.
        
         | gzread wrote:
         | If you aren't already scanning ID or similar then you don't
         | have clear and convincing reasoning to believe the user is
         | underage.
         | 
         | This section targets spyware companies like Facebook, who
         | already know damn well if the user is underage and this section
         | forbids them from pretending they don't know.
         | 
         | It doesn't say you have to go and become Facebook.
        
         | lokar wrote:
         | How does a website know if the age signal from a client is
         | authentic? That seems unworkable.
        
       | choonway wrote:
       | this is how and adult sounds like in a room full of children.
        
         | 06867457397658 wrote:
         | How very adult of you to cheer for totalitarianism.
        
       | charcircuit wrote:
       | I don't think the argument that children might bypass parental
       | controls therefore devices should not have parental controls.
       | 
       | >Limiting a child's ability to explore what they can do with a
       | computer limits their future.
       | 
       | Parents don't want to limit their children from writing software.
       | Saying that limiting minors from accessing porn will limit their
       | future is another argument I doing think many will agree with.
        
       | bradley13 wrote:
       | These lawd prove one thing: the politicians know nothing about
       | the subject matter.
       | 
       | What is almost more disturbing: at least some of the politicians
       | will have been advised by consultants or lobbyists who _know_
       | what they 're advocating for. What's their game?
        
         | gzread wrote:
         | Can you elaborate what you know that the writers of the
         | California law don't know?
        
       | DoctorMckay101 wrote:
       | I was gifted my first computer, running Windows 95, at 11 years
       | of age. By age 13 I was probably within the five people who
       | better understood how to do stuff on a computer in my town. By
       | age 16 I was making Pokemon hackroms, flash animations for
       | newgrounds and translating manga for pirate sites in photoshop.
       | By then I knew my entire life would be tied to computers somehow.
       | 
       | Now some 50-60yo politician who has never even created a folder
       | in their desktop without help wants to dictate how I should have
       | used my device?
       | 
       | Fuck'em
        
         | colinmarc wrote:
         | There are obviously certain harms we are comfortable (trying
         | to) prevent 13yos from having access to. So it's a matter of
         | degree.
         | 
         | The internet you describe has been gone for a long time. The
         | internet that replaced it is several degrees more harmful, to
         | adults and children alike.
        
           | wao0uuno wrote:
           | So maybe instead of trying to control the people we could try
           | controlling the corporations responsible for this problem?
           | Bring back the old internet. Make addictive services and
           | algorithmic recommendations illegal. Make commercial entities
           | more responsible for the services they offer.
        
             | colinmarc wrote:
             | I would absolutely be in favor of those measures.
        
         | gzread wrote:
         | No, they want your parents to have the optional option to
         | dictate how you use your device.
        
       | bradley13 wrote:
       | Let's be clear: this is a first step. The obvious next step is to
       | require _proof_ of age.
       | 
       | This ties in nicely with the international movement to require ID
       | to use social media.
       | 
       |  _Why_ is this an international movement? Suddenly,
       | simultaneously, all over the Western world? It 's enough to make
       | on believe in conspiracies...
        
         | azangru wrote:
         | > Why is this an international movement? Suddenly,
         | simultaneously, all over the Western world?
         | 
         | Sometimes kids hurt themselves through the use of the internet.
         | And their parents lash out to blame someone [0]. And mainstream
         | media pick up these stories. And the worry spreads. And more
         | and more adults of voting age say that yeah, it's only
         | reasonable to protect the kids from that internet monster,
         | because kids are trusting and vulnerable, and won't somebody
         | please think of the children. And they do not push back against
         | age restriction campaigns. And so it goes...
         | 
         | As for the Western world, it generally moves in lockstep,
         | doesn't it?
         | 
         | https://www.bbc.co.uk/programmes/m0024x58
        
           | wao0uuno wrote:
           | So where are those big protests and public calls for online
           | age verification? It all seems to be coming from the very
           | top. I have not heard of anyone that actually want any of
           | this. The fact that politicians are to be excluded from
           | European regulations is only a proof that it's all a scheme
           | to kill what remains of privacy and freedom of speech online.
        
             | gzread wrote:
             | First, this isn't age verification. At least the California
             | one isn't.
             | 
             | Second, where are the protests to keep kids out of bars?
        
         | fruitworks wrote:
         | Why are all of these attempts at controlling the web coinciding
         | at the same time now? I don't think it is a coincidence that
         | this is happening at the same time that the younger generation
         | wakes up to our greatest ally.
        
           | gzread wrote:
           | Because there's only one internet and it's becoming a problem
           | for every country at the same time because it's the same
           | problem.
        
             | 06867457397658 wrote:
             | Free thought and dissent is truly a problem for these
             | regimes.
        
               | gzread wrote:
               | There's free thought and dissent, and then there's
               | teaching a child from birth that Obama is a lizard
               | person.
        
               | hellojesus wrote:
               | This is where parents come into play...
        
         | 3A2D50 wrote:
         | I'll echo what I've already said elsewhere in the comment
         | section. It's about AI! Particularly massive swarms of
         | persuasive AI controlled by an adversary convincing the public
         | to elect bad people with bad policies. Also, companies that
         | rely on ad revenue would love to serve ads only to humans
         | instead of bots.
        
       | vasco wrote:
       | This is the one thing that truly scares me. I've decided I'm not
       | going to verify my age anywhere or use facial recognition apps to
       | login anywhere. And this is a much bigger fear for my job than
       | AI.
       | 
       | At the moment only some countries banning porn, social media and
       | gambling. But how soon will I have to do it for a work app? And
       | will I lose my job then if I refuse?
        
       | krautburglar wrote:
       | The prostitutes pushing for this do not deserve words. They
       | deserve ridicule, public humiliation, and worse. The computer is
       | a tool. Whoever would encumber it is an obvious shill for the
       | corporations (google/apple/microsoft) who would like to attach an
       | identity (i.e. tolls and controls) to actions prior generations
       | could do freely and without surcharge. It is a modern-day
       | enclosure movement. Its proponents should be juicily spat upon.
        
         | vladms wrote:
         | Is this the free speech we are trying to protect?
         | 
         | I do not think the proposal is smart or that will it work, but
         | I am more worried that some people seem to think they hold the
         | absolute truth (on any side of the a debate).
        
           | krautburglar wrote:
           | This is not a "free speech" issue. This is an assault upon
           | the citizenry. This is the rich and the powerful trying to
           | put everyone's ass on the plantation. Some want it to extract
           | wealth from you (thievery). Others want it to control you
           | (slavery). They are begging for the guillotines.
        
       | hananova wrote:
       | I can't fathom all the rage and confusion here about these laws.
       | It's been a well-known effect since forever that when a
       | government deems that something needs to be done, they'll go for
       | the first "something-shaped" solution.
       | 
       | This all could've been avoided. Governments all over the world
       | have been ringing the alarm bells about lack of self-regulation
       | in tech and social media. And instead of doing even a minimum of
       | regulation, anything to calm or assuage the governments, the
       | entire industry went balls-to-the-wall "line go up" mode. We,
       | collectively, only have ourselves to blame, and now it's too
       | late.
       | 
       | If you look back, it didn't have to be this way: - Governments
       | told game publishers to find a system to handle age rating or
       | else. The industry developed the ESRB (and other local systems),
       | and no "or else" happened. - Governments told phone and smart
       | device manufacturers to collectively standardize on a charging
       | standard, almost everyone agreed on USB-C and only many years
       | later did the government step in and force the lone outlier to
       | play ball. If that one hadn't been stubborn, there wouldn't have
       | been a law.
       | 
       | The industry had a chance to do something practical, the industry
       | chose not to, and now something impractical (but you better find
       | a way anyway, or else) will be forced upon them. And I won't shed
       | a tear for the poor companies finally having to do something.
        
         | shevy-java wrote:
         | > We, collectively, only have ourselves to blame, and now it's
         | too late.
         | 
         | Why would we have to be blamed for a law written by some
         | lobbyists? That makes no sense at all. There are of course some
         | folks that are in favour of this because "of the children" but
         | their rationale does not apply to me nor to many other people.
         | Why should they be able to force people to surrender their
         | data, with the operating system becoming a sniffer giving out
         | private data to everyone else? That makes no sense.
        
           | pear01 wrote:
           | The invocation of "lobbyists" in this context is meaningless.
           | People lobby for all kinds of things. Doesn't really matter
           | once it becomes a law anyway.
           | 
           | If people could just say I don't agree with this law, it
           | "makes no sense" and it's written by "lobbyists" and the
           | government should not "be able to force" me to comply then we
           | don't have a society anymore.
           | 
           | You had better come up with some better arguments otherwise
           | it just seems like the typical sad case of the losing side
           | suddenly griping about the referee's monopoly of force when
           | it's no longer going their way...
           | 
           | The comment you replied to rightly pointed out one way of
           | getting ahead of said monopoly of force is addressing
           | problems with the status quo before the state takes an
           | interest. It didn't happen, and now you will probably get
           | some heavy handed intervention. But ignoring this basic point
           | to ask why oh why suggests an ignorance of the very nature of
           | the society that is and has been constantly regulating you.
           | 
           | If you only happened to notice now you should consider
           | yourself a rather lucky specimen in the long line of human
           | history, full of those remarking "this makes no sense" as
           | they are nonetheless compelled to comply.
        
             | rudhdb773b wrote:
             | The fact that lobbyists push the law is in fact very
             | meaningful. It means that a minority with power is trying
             | to tip the scales in their favor against the otherwised
             | unbiased will of the majority.
             | 
             | To extend your analogy, it's not one side complaining after
             | a fair match, it's them complaining that refs have been
             | paid off.
        
               | mlrtime wrote:
               | Lobbyists do not always mean minority. I'm sure it looks
               | like that from the outside.
               | 
               | There are all kinds of laws that people don't like, me
               | included. With every law there will be some winner/loser
               | trade-off (for lack of better word). As OP said, that is
               | society.
               | 
               | If the people here were so passionate about it, they
               | would help come up with a better solution, not a "f* off"
               | comment.
        
               | pear01 wrote:
               | There is no such thing as an "unbiased will of the
               | majority".
               | 
               | That sort of terminology might have flown back in the
               | 18th century with Rousseau and the like speaking of a
               | "general will" but in today's era of social science, it
               | has about as much force as invoking divinity.
               | 
               | Everyone has bias. The idea of a general will is largely
               | fiction and was discredited at the time.
               | 
               | Our system is based on coercion, costs and trade-offs and
               | nothing more. That is human history. You may have some
               | rights (perhaps a right to privacy, it is debatable) but
               | this is really just the three core components dressed up
               | in reverse. The freedom of speech for instance is simply
               | to codify the idea that the state silencing you is
               | intolerable. Intolerable is eventually meaningless unless
               | it is backed up by costs and coercion against the state
               | which they will seek to avoid.
               | 
               | When the state violates such "rights" flagrantly
               | sometimes the people are called to manifest this aspect
               | of "intolerable".
               | 
               | That's what a revolution is.
               | 
               | Failing that you need to convince people. And in so doing
               | if you aim to find some "unbiased will of the majority"
               | you are wasting your time.
               | 
               | You would be better off with a lobbyist. Surely such a
               | person would not so readily engage in such fiction
               | regarding how democracy actually works, and would thus be
               | more effective in achieving your goals.
        
         | kortilla wrote:
         | Speak for yourself. This is impacting open source and is
         | fundamentally against the open source ethos.
         | 
         | Governments demanding computers enforce age is as dumb as
         | governments demanding books, pen, and paper enforce age.
         | 
         | This is unrelated to industry. This is idiots running the
         | government.
        
           | dpe82 wrote:
           | I'm probably missing something, but when I read the
           | California statute I didn't understand it to be anything like
           | "computers enforcing age" - more like, when you create an
           | account it needs to _ask_ your age, and then provide a system
           | API by which apps can ask what bracket the account holder is
           | in. This seems better than the current solution of every app
           | asking independently?
           | 
           | Again, I'm probably missing something but it strikes me as
           | pretty trivial to comply with?
        
             | ball_of_lint wrote:
             | The government really shouldn't be telling us how/what we
             | can compute at all.
             | 
             | But on this specific point - It's a bellwether. They're
             | doing this to lay the groundwork and test the waters for
             | compulsory identification and/or age verification. Getting
             | MacOS and Windows and Linux and etc to implement this WILL
             | be used as evidence that compulsory identity verification
             | for computer use is legally workable.
        
               | ball_of_lint wrote:
               | And if the implications of that aren't clear - that would
               | either be unenforceable or be in effect a government
               | rootkit+DRM on every device.
        
               | charcircuit wrote:
               | >The government really shouldn't be telling us how/what
               | we can compute at all.
               | 
               | You could say the same thing about restaurants. "The
               | government really shouldn't be telling us how/what we can
               | cook at all."
               | 
               | When you are selling a product to the public, that is
               | something that people have decided the government can
               | regulate to reduce the harms of such products.
        
               | hellojesus wrote:
               | What if you aren't selling a product, like open source
               | linux distros?
        
               | labcomputer wrote:
               | Last time I checked, health code regulations still apply
               | to kitchens serving homeless people for free.
        
             | akersten wrote:
             | Being "trivial to comply with" is completely disjunct and
             | not at all an argument against "this type of law is
             | fundamentally at odds with the liberty and self-
             | determination that open source projects require and should
             | protect." It's a shot across the bow to open-source, it's
             | literally the government telling you what code your
             | computer has to run. It is gesturing in the direction of
             | existential threat for Free software and I am not
             | exaggerating. It's purposefully "trivial" so you don't
             | notice or protest too much that this is the first time the
             | State is forcing you to include something purely of their
             | own disturbed ideation in your creative work.
        
               | gzread wrote:
               | Free software is already mandated to do a lot of things,
               | like not defraud the user. If you make a bitcoin wallet
               | that sends 5% of your money to the developer without
               | asking I'm pretty sure you'll be prosecuted, so the
               | government is compelling you to ask the user for consent
               | to do that.
               | 
               | When you make food you're compelled to write the
               | ingredients. We tolerate these because they are obvious
               | and trivial, but pedantically, food labelling laws also
               | violate the first amendment.
        
               | akersten wrote:
               | > Free software is already mandated to do a lot of
               | things, like not defraud the user.
               | 
               | Surely you recognize the difference between "you cannot
               | go out of your way to do crime" and "your software must
               | include this specific feature"??
               | 
               | > When you make food you're compelled to write the
               | ingredients.
               | 
               | Well, the point about how this affects open source is
               | that under a similar California law, every home kitchen
               | would need to be equipped with an electronic transponder
               | whose purpose is to announce to the world what ingredient
               | bucket you used for tonight's casserole.
        
               | gzread wrote:
               | Which part of the California law announces your browsing
               | history to the world?
        
             | brabel wrote:
             | If that's true, I think the law is fine. There are good
             | solutions for anonymous disclosure of information about
             | you, the most mature being Verifiable Credentials, which is
             | an open standard:
             | https://en.wikipedia.org/wiki/Verifiable_credentials
             | 
             | You can disclose just a subset of a credential, and that
             | can be a derived value (eg age bracket instead of date of
             | birth), and a derived key is used so that its
             | cryptographically impossible to track you. I wish more
             | people discussed using that, but I suspect that it's a bit
             | too secure for their real intentions.
        
               | AnthonyMouse wrote:
               | In general, any proposal to use _government ID_ for  "age
               | verification" over the internet is going to end in
               | someone using it for mass surveillance, and it's probably
               | not wrong to suspect that as the intention to begin with.
               | 
               | There is no _benefit_ in doing that because parents
               | already know how old their kid is. They don 't need the
               | government to certify it to them, and then they can
               | configure the kid's device not to display adult content.
               | 
               | Involving government ID is pointless because the parent,
               | along with the large majority of the general population,
               | _has_ an adult ID, and therefore has the ability to
               | configure the kid 's device to display adult content or
               | not even in the presence of an ID requirement if that's
               | what they want to do. At which point an ID requirement is
               | nothing but a footgun to "accidentally" compromise
               | everyone's privacy. Unless that was the point.
        
               | gzread wrote:
               | The California and Colorado laws don't involve any ID.
        
               | AnthonyMouse wrote:
               | And those are better than the ones that do involve ID,
               | which also exist, but not as good as the thing where the
               | service tells your device the rating of the content
               | instead of the user telling the service their age.
        
               | gzread wrote:
               | How would that work when the service has mixed content?
               | You'd have to go to kids.facebook.com to get the child-
               | friendly version? With a client-sent signal they can just
               | filter it, the same way Accept-Language can automatically
               | translate the UI.
        
               | hellojesus wrote:
               | But why do we need it at the os level? Couldn't a parent
               | just set a header in the browser for their kid and be
               | done with it?
        
               | labcomputer wrote:
               | What happens when the kid installs a different browser?
        
               | hellojesus wrote:
               | Agreed. Which is why I think the OS level is dumb. Kids
               | can just live boot or launch a vm or keylog their
               | parents' account.
               | 
               | If it's windows, they can just live boot into the OS and
               | get access to pretty much all the files anyway, if the
               | parent didn't encrypt things.
               | 
               | My point is, if the implementation is trivial to bypass,
               | why do we need this legislation? Just let the parents use
               | the existing tools we have and parent.
        
               | AnthonyMouse wrote:
               | Elements that contain adult content are tagged and then
               | the user agent doesn't display them.
               | 
               | This also has the extremely useful benefit of making you
               | aware that something is being censored, because then it
               | has a censorship box in place of the content. Whenever
               | censorship is happening it should be flagrantly
               | conspicuous rather than invisible.
        
               | dpe82 wrote:
               | It doesn't even need to be that complicated. OS asks you
               | your birthday at setup time. Stores it. Later, an app
               | asks whether the user falls into one of the following
               | brackets:
               | 
               | A) under 13 years of age, or B) at least 13 years of age
               | and under 16 years of age, or C) at least 16 years of age
               | and under 18 years of age or D) at least 18 years of age.
               | 
               | that's it. The OS can decide how it wants to implement
               | that, but personally I'd literally just do
               | get_age_bracket_enum(now() - get_user_birthday());
               | 
               | The bill is here: https://leginfo.legislature.ca.gov/face
               | s/billTextClient.xhtm...
               | 
               | The uproar seems to be extremely overblown.
        
               | gzread wrote:
               | I think the uproar comes because the well is already
               | poisoned. People are already trained to respond with an
               | outburst of anger to any law that mentions the age of the
               | user, and will find excuses to rationalize that outburst,
               | even when the law isn't that bad.
               | 
               | I mean, "compelled speech"? Really? That's people's
               | argument? This is about as bad as the government
               | compelling you to write a copyright notice.
        
               | iamnothere wrote:
               | Compelled speech _is_ bad and it's something we _don't
               | do_ , at all. All kinds of bad things come with compelled
               | speech. Mandatory loyalty oaths, erosion of the fifth
               | amendment, compelled work to weaken encryption, etc.
               | 
               | The well should be poisoned. The whole idea is poison.
        
         | panny wrote:
         | >We, collectively, only have ourselves to blame, and now it's
         | too late.
         | 
         | No, "we" really don't. I wrote software. It's free. You're
         | welcome to use it, or not. Nobody is forcing my software on
         | you. You are not allowed to tell me that the software I wrote,
         | for free, and gave to you, for free, needs to have features
         | that I don't care about.
         | 
         | You have an LLM now. I'm obsolete now, right? Do it. Build your
         | nerfed distro, and make it popular. Oh, yeah... there isn't a
         | single solitary disto built by an LLM, is there? Not even one.
         | Wow. I wonder why...
        
         | vaylian wrote:
         | > The industry had a chance to do something practical, the
         | industry chose not to
         | 
         | Wrong. There was no choice. Any type of identification
         | technology causes more problems than it solves. The right
         | choice is to look for different approaches than identification
         | technology for solving the problems. And as the article points
         | out, the problems are best tackled with education and not with
         | tech.
        
         | Jean-Papoulos wrote:
         | > We, collectively, only have ourselves to blame, and now it's
         | too late.
         | 
         | Can't believe I'm reading this. I don't want age verification
         | at all, whether it's self-imposed or not. I should be free to
         | use whatever tools I want however I want.
        
           | ray_v wrote:
           | Someone else posted this in the thread, by it pretty much
           | sums it up - Vae victis.
           | 
           | We somehow lost the war of freedom of privacy ... or, maybe
           | the battle still rages
        
           | charcircuit wrote:
           | Democracy is not about what you want. If the majority want
           | something you don't, the best you can do is find a
           | compromise. There is no option of doing nothing and keep
           | computers the same as they have been if the majority want
           | change.
        
             | wao0uuno wrote:
             | But does the majority want that change? If they want it,
             | are they entirely aware of its potential impact on their
             | freedom of speech and access to information? Or were they
             | conditioned to think it's good for them because well funded
             | corporate entities and governments spend money on promoting
             | that image? Democracy does not work when majority is stupid
             | and uneducated because people like that are easily
             | controlled. I wish we were putting as much resources into
             | education as we're putting into cheap entertainment and
             | ads/marketing.
        
               | mlrtime wrote:
               | >But does the majority want that change
               | 
               | This really depends on 1) How you frame the
               | problem/solution and 2) what subset of people you ask.
               | 
               | But to answer your question, I could easily see that yes,
               | people want a "change" based on how you frame the
               | problem.
        
               | gzread wrote:
               | The vast majority wants a parental control setting on the
               | kid's device, and that's what is being imposed in
               | California and Colorado right now.
               | 
               | The vast majority don't want to upload their passports.
               | That's what we should be opposing. Standardized parental
               | controls set by the device owner are a great alternative
               | and not invasive at all.
        
               | Hizonner wrote:
               | There are parental control settings on most of the
               | devices kids have right now. _Most_ parents don 't use
               | them (https://fosi.org/parental-controls-for-online-
               | safety-are-und...) . Where's your vast majority?
               | 
               | By the way, that does _not_ imply that they 're
               | "underutilized". That part of the article is pure
               | opinion.
        
               | labcomputer wrote:
               | Err... "Most" is doing some heavy lifting here. 51% of
               | parents _do_ use parental controls on their kid 's
               | tablets, and 47% on smartphones.
               | 
               | And there's no breakdown by age. Kids don't magically
               | become able to handle the uncensored internet the day
               | they turn 18.
               | 
               | Did it ever occur to you that parents who don't use
               | restrictions maybe have kids that are _almost_ 18? Or
               | parents of kids who have shown themselves to be
               | responsible? Or that the parents use other methods to
               | restrict use (like only allowing supervised use _with_
               | the parent for very young children)?
        
             | muyuu wrote:
             | that is why democracy ends at property
        
             | iamnothere wrote:
             | Well maybe democracy has had its day then, if that's where
             | all this leads.
             | 
             | The founders were right to try and enshrine some
             | protections against unrestricted democracy in the Bill of
             | Rights.
        
         | marssaxman wrote:
         | "because we didn't do a stupid and pointless thing, now we are
         | being forced to do a stupid and pointless thing, therefore we
         | are to blame"
         | 
         | Uh, no.
        
       | shevy-java wrote:
       | So this has recently also affected Ubuntu.
       | 
       | One developer began a discussion:
       | 
       | https://lists.ubuntu.com/archives/ubuntu-devel/2026-March/04...
       | 
       | Their attempts of a "solution" are quite interesting. One other
       | user suggested that GUI tools ask for the age of the user.
       | 
       | Well ... I have a very strong opinion here. I have been using
       | Linux since over 20 years and I will not ever give any
       | information about my personal data to the computer devices I own
       | and control. So any GUI asking for this specifically would betray
       | me - and I will remove it. (Granted, it is easier to patch out
       | the offending betrayal code and recompile the thing; I do this
       | with KDE where Nate added the pester-donation daemon. Don't
       | complain about this on reddit #kde, he will ban you. KDE needs
       | more money! That's the new KDE. I prefer oldschool KDE but I
       | digress so back to the topic of age "verification").
       | 
       | The whole discussion about age "verification" appears to be to
       | force everyone into giving data to the government. I don't buy
       | for a moment that this is about "protecting children". And, even
       | IF it were, I could not care any less about the government's
       | strategy. Even more so as I am not in the country that decided
       | this in the first place, so why would I be forced to comply with
       | it when it ends up with GUI tools wanting to sniff my information
       | and then give it to others? For similar reasons, one reason I use
       | ublock origin is to give as few information to outside entities
       | when I browse the web (I am not 100% consistent here, because I
       | mostly use ublock origin to re-define the user interface, which
       | includes blocking annoying popups and what not; that is the
       | primary use case, but to lessen the information my browser gives
       | to anyone else, is also a good thing. I fail to see why I would
       | want to surrender my private data, unless there is really no
       | alternative, e. g. online financial transactions.)
       | 
       | I also don't think we should call this age "verification" law.
       | This is very clearly written by a lobbiyst or several lobbyists
       | who want to sniff more data off of people. The very underlying
       | idea here is wrong - I would not accept Linux to become a spy-
       | tool for the government. I am not interested in how a government
       | tries to reason about this betrayal - none of those attempts of
       | "explanation" apply in my case. It is simply not the job of the
       | government to sniff after all people at all times. This would
       | normally require a warrant/reasonable suspicion of a crime. Why
       | would people surrender their rights here? Why is a government
       | sniffing after people suddenly? These are important questions.
       | That law suddenly emerging but not in the last +25 years is
       | super-suspicious.
        
         | senfiaj wrote:
         | I agree this is bullshit. But at least you can lie to the OS
         | about your age. Technically it's almost the same as OS asking
         | you "Pick a date and a number from 1 to 100 and I'll report it
         | to the software / websites. But don't worry, I'll not verify
         | you.". If you pick randomly (over age 18 or whatever),
         | technically, you don't provide any useful information.
         | 
         | This would be the least of evils (such as ID verification). But
         | a bigger problem is that the implementation is very flawed. It
         | doesn't appear to be very effective. People, including
         | children, can lie. Multiple people can share the same account.
         | Also there are many devices that cannot be updated (such as
         | embedded). My concern is that these idiots might introduce even
         | more extreme laws when they see that it isn't efficient enough.
         | 
         | I hope it will cause so many problems (implementation,
         | backslash, etc) that it will be eventually cancelled.
        
           | gzread wrote:
           | The whole thing is clearly intended to be optional anyway. If
           | your parents want you to have an unrestricted account, they
           | can say you're over 18, or they can give you full control
           | over the computer. If they want you to have a restricted
           | account, they give you a non-root user account with a
           | different age bracket.
        
       | verdverm wrote:
       | Good words, glad to see more companies taking a principled stance
       | on these important matters. That leading quote is great for
       | sharing with non-technical friends. We have 365d 23h of non-
       | voting time to take direct action to make our world better.
        
       | himata4113 wrote:
       | I don't really see a problem where there is a standard api (or
       | even syscall!) to rethrieve a persons age bracket and for various
       | apps being able to easily implement it. But please make it
       | fucking optional.
       | 
       | Make it optional and assume an adult otherwise, it's a good idea
       | if it's optional and doesn't have dumb fines, you could have
       | fines for not enforcing it / not using the api [porn sites] that
       | already exists [and it doesn't work since 1 button is not age
       | verification].
       | 
       | I see this as a good way for parents and institutions to set up
       | their phones, school laptops etc and would pretty much solve the
       | large majority of these issues while having a fraction of the
       | invasiveness.
        
         | gzread wrote:
         | The law says it must ask for age when creating an account other
         | than the first one. So that's mandated. But there's no
         | verification of the age you enter, and in fact, it's forbidden
         | to verify it. It's really just to give parents the option to
         | set up child accounts.
        
           | VLM wrote:
           | "The law" There is no "The law" there are multiple levels of
           | government implementing multiple solutions all different and
           | somewhat incompatible.
           | 
           | Honestly, probably by intention. Its sort of a SLAPP attack
           | on the entire world population.
        
             | gzread wrote:
             | I'm talking about the one in California and Colorado, which
             | is the most recent outrage wave.
        
       | kevincloudsec wrote:
       | requiring the OS to broadcast an age bracket to every app and
       | website is building a new tracking vector and calling it child
       | safety lol
        
         | winrid wrote:
         | None of these people actually care about children.
        
         | gzread wrote:
         | Is it worse than Accept-Language? It's got less bits of
         | entropy.
        
           | Aachen wrote:
           | Is that still higher entropy when you already (necessarily)
           | have the IP address?
           | 
           | 225.12.3.11 sends two requests, both with accept-language
           | nl_BE
           | 
           | 226.4.5.244 sends two requests, one with age bracket 13-15
           | and one with bracket 18+
           | 
           | Which group is easier to track people within a (NAT)
           | household..
        
       | saltysalt wrote:
       | It's sad to see such big brother crap in Linux, which sees like
       | the exact opposite of the hacker ethos it was originally built
       | upon.
        
         | gzread wrote:
         | Mandating the existence of a parental control setting that's
         | completely optional to use is hardly Big Brother.
        
           | saltysalt wrote:
           | When did we get to vote on this?
        
       | sp1rit wrote:
       | I wonder who is behind this sudden push for these age
       | verification laws. This wasn't an issue until recently and
       | suddenly there are not just laws in California and Colorado, but
       | also New York and Brazil.
        
         | merlindru wrote:
         | ...and Australia, and New Zealand, and the UK, and Norway, and
         | Spain, and France, and the EU
        
           | Aldipower wrote:
           | Social media age verification is absolutely not the same as
           | age verification at OS login level. Do not mix the things up.
        
             | ycombinator_acc wrote:
             | They are initiated by the same people - the government -
             | and pursue the same goal - mass surveillance. They should
             | 100% be fought against and grouped together.
        
         | ycombinator_acc wrote:
         | I got the impression they were kick-started by Anglo countries
         | (the Five Eyes, whatever you wanna call them), then gradually
         | picked up by the rest.
        
         | irusensei wrote:
         | There is a nascent industry of AI backed surveillance now so
         | you can be 200% sure a lot of lobbying happened in closed
         | rooms.
         | 
         | And then there are the desperate attempts to cover actual
         | pedophilia from the people in power. I'll never look at a
         | politician or a so called member of the elites the same way
         | again.
        
       | globemaster99 wrote:
       | So much for freedom and democracy lectured by Americans and
       | westerners to the rest of the world. This is just censorship of
       | every form of freedom of speech. This got nothing to do with
       | children or youth. They will eventually censor and track
       | everyone.
        
         | wao0uuno wrote:
         | I feel the same way. Looks like online "privacy" and
         | "anonymity" will cease to exist within our lifetime. It's
         | already starting with those "privacy respecting" solutions like
         | zero trust age verification but that will quickly be deemed
         | insufficient and because the legal framework will be already
         | present it will very quickly and smoothly turn into full blown
         | surveillance and censorship. Time to setup I2P on my server and
         | donate some bandwidth but I'm sure they'll make that illegal
         | too.
        
           | globemaster99 wrote:
           | True.Like many other nefarious things British started this
           | with child protection act, which got nothing to do with
           | children, considering their long history of pedophiles.
           | Slowly all the other governments using the same pretext and
           | template. Time to use pigeons and own peer to peer
           | communication.
        
         | user3939382 wrote:
         | Next step coming soon is "well we need a license scan if you
         | tell the OS you're over 18". macOS already requires a 6 step
         | process to "trust" regular programs not from their app store.
         | So this is just end to end control of our machines.
        
           | hellojesus wrote:
           | Yes. Soon ISPs will require hardware based remote
           | attlestations to prove you haven't modified any software that
           | wants to send or receive packets through them.
        
           | Aachen wrote:
           | You mean a dedicated license that proves the holder is over
           | 18, separate from your identity such that it's not usable for
           | tracking or identity theft when the verification platform
           | gets hacked?
        
         | gzread wrote:
         | If you don't want to be censored just don't check the checkbox
         | that says "this device is for a child, please censor adult
         | content"? There's no passport check in the CA/CO law, in fact
         | it's expressly forbidden.
        
           | nickslaughter02 wrote:
           | > _It can get worse. New York's proposed Senate Bill S8102A
           | requires adults to prove they're adults to use a computer,
           | exercise bike, smart watch, or car if the device is internet
           | enabled with app ecosystems. The bill explicitly forbids
           | self-reporting and leaves the allowed methods to regulations
           | written by the Attorney General._
        
             | pacifika wrote:
             | Select your location, if NY etc.
        
             | gzread wrote:
             | Interesting that everyone is labelling things not for sale
             | in CA/CO but nobody is labelling them not for sale in NY.
        
               | iamnothere wrote:
               | I don't think they have processed the NY law yet. It is
               | completely incompatible with the open source model. When
               | people finally figure it out there will be an uproar.
        
       | 7777332215 wrote:
       | Don't see how anyone is gonna make me do anything. Just evade
       | anything like this through various means and opt out of things
       | that reduce your quality of life (by destroying your freedom and
       | making you a slave)
        
       | akersten wrote:
       | We should collectively make sure that any PRs trying to land
       | these changes are very well reviewed. We wouldn't want any
       | security holes to slip by. I think a couple dozen rounds of
       | reviews should suffice. I've heard great things about how
       | productive AI can be at generating very thorough code quality
       | assessments. After all, we should only ship it once it's perfect.
       | 
       | To be more direct - if you're in any editorial position where
       | something that smells like this might require your approval,
       | please give it the scrutiny it deserves. That is, the same
       | scrutiny that a malicious actor submitting a PR that introduces a
       | PII-leaking security hole would receive. As an industry we need
       | to civil disobedience the fuck out of this.
        
       | cassonmars wrote:
       | It's simple. Don't comply. Software engineers, despite not having
       | the same requirement of mechanical engineers, should uphold the
       | ethical obligations of their craft. This law is harmful. Given
       | the requirement of compelled speech, given code has been _proven_
       | to be such, Do. Not. Comply.
        
         | chickensong wrote:
         | Never considered it! Unless strong encryption is banned, this
         | will never work.
         | 
         | P.S. Is your handle a reference to Cats on Mars by Seatbelts?
         | Yoko Kanno <3
        
           | cassonmars wrote:
           | Yes!
        
             | chickensong wrote:
             | Hah nice! I saw your name and immediately heard the song :)
        
       | drnick1 wrote:
       | California may be able to target companies like System76, but it
       | will be completely powerless against modular and decentralized
       | distros like Debian and Arch.
        
         | Aldipower wrote:
         | Yeah, living in Europe it simply makes me scratching my head
         | how this law could affect me. It won't. No Californian law will
         | tell me what I should do.
        
           | muyuu wrote:
           | these things are insidious
           | 
           | once vendors are forced to put on hooks to some enforced age
           | verification system, it will creep everywhere like cookie
           | banners which you cannot escape even in Antarctica
        
             | Aldipower wrote:
             | Maybe, I get what you mean. But I think there is still a
             | difference between what I install on _my own_ computer and
             | opening some _others_ website.
        
               | muyuu wrote:
               | i reckon the push will get to the point that us Europeans
               | will end up actually installing it because all major OS's
               | will enforce it
        
             | drnick1 wrote:
             | When it comes to free software, I don't see what prevents
             | anyone from patching out such undesired "features." This is
             | why free software is more important than ever. Official
             | distributors like System76 may have to comply, in CA at
             | least, but I won't.
        
               | muyuu wrote:
               | technically yes, but if those features have to come, for
               | instance, in all kernel distributions, how many people
               | would you expect to patch and compile their own kernels
               | manually?
               | 
               | let's say no distros would do it because of risk of
               | exposure to massive fines, and you'd have to get patches
               | from dodgy places because regulators keep stamping them
               | out of the mainstream with threats of prosecution
        
               | drnick1 wrote:
               | > technically yes, but if those features have to come,
               | for instance, in all kernel distributions
               | 
               | It isn't the kernel's role to verify ages. The whole
               | issue with FOSS is that it isn't even clear which
               | component (of a Linux distribution for example) should be
               | responsible for things such as age verification. No
               | single part is an "operating system" by itself.
        
               | muyuu wrote:
               | > It isn't the kernel's role to verify ages
               | 
               | of course it's not, but this has been already floated
               | 
               | if we stuck to what makes sense, nothing of this would
               | have been even proposed - making sense is not something
               | legislators are necessarily bound by
               | 
               | and if we're talking of enforceability, plenty of people
               | can be targeted and will be targeted if things follow
               | this path, it's not like the main developers controlling
               | the different systems in Linux - for instance - are
               | anonymous
               | 
               | take for instance System76, they're not even remotely in
               | charge of the OS their computers run, but they know that
               | 1) they may either leave their users with a nerfed
               | connection if age signals are implemented at the browser
               | protocol level, or at the application level and 2) they
               | may be made responsible and liable for every computer
               | they sell without those provisions, like it's going to
               | start happening in Brazil in a few weeks
               | 
               | plenty of people are possible attack vector for
               | governments, and the very threat will cause an effect
               | 
               | does anything of this make sense? no
               | 
               | but it doesn't mean there is no present danger, just
               | because your jurisdiction has not issued concrete threats
               | yet or because you mean you can tell lawmakers you use
               | OSS and therefore their laws don't apply to you
               | 
               | the only thing they need to make "unverified" devices
               | illegal is that the mainstream are all already corralled
               | into "verified" systems, and you'd be effectively
               | marginalised
        
       | LunicLynx wrote:
       | It's simple you can't go drinking under age, you can't drive a
       | car under age. And the harm that can come from the internet is
       | well above this so it makes sense to also ask for id. I agree
       | though that it needs a system to protect information. It's not
       | about the system being always fail safe it's about the general
       | rule that by default what is happening is not legal to protect
       | and not put the burden on every parent or family.
       | 
       | ,,But Jonas parents allow him to do that" in reality Jonas
       | parents should not have a say in this.
        
         | tuetuopay wrote:
         | The harm is well above (even that is arguable), but the
         | probability of getting harmed is so much lower it's not even
         | comparable.
         | 
         | Alcohol? Yeah one or two too many drinks and you're in the
         | hospital getting your stomach vacuumed. Driving? Blink and you
         | run over a kid. Internet? You can spend evening and nights over
         | there and not be harmed in any way.
         | 
         | We have full generations of kids that can now be studied about
         | the effects of the internet, starting with millenials. I won't
         | pretend the Internet is a better place now than it was when I
         | was a teen, but it appears to me the "dangerous" things are
         | more focused and concentrated (at least for kids): social
         | networks. It's still a minefield, but with leagues between two
         | mines.
         | 
         | Porn has always been _the_ topic touted for children safety,
         | because it 's scary and resonates with conservatives and
         | religious people. Access to is is roughly the same today than
         | it was then, and arguably less dangerous today because the
         | dirty stuff is hidden deeper, thus less likely to stumble upon.
         | 
         | But other than porn, the thing that changed the most is social
         | networks. Addiction, bullying, etc. Facebook 15 years ago was a
         | not serious place. The equivalent today is the best place to
         | get roasted by fellow kids and bullied 24/7 while not being
         | able to get off the hook. The damage is psychological, which is
         | insidious, but not systematic. Not every kid will get bullied,
         | not every kid will be addicted to the algorithm(tm), etc.
         | 
         | In the end, education plays a bigger role than simple age
         | verification. Stimulate your kids, give them things to do other
         | than doomscrolling, and get them on the dark corners of the
         | internet to give them curiosity about the world and un-
         | sanitized stuff (hacking in all forms, etc).
        
           | gzread wrote:
           | I don't think the probability is low. What percentage of
           | children are brainrotted by TikTok?
        
       | colinmarc wrote:
       | I'm surprised by the complete lack of dissent or even nuance in
       | the discussion here. I'm much more ambivalent on this: the
       | historical record for prohibition is not good, but instagram and
       | the like are uniquely and disastrously harmful and the companies
       | pushing them on children are powerful in a way that has no real
       | historical precedent. In the balance, anything the reduces the
       | power those companies have over our lives (and our politics) has
       | to be at least considered. In other words, I don't think this is
       | necessarily the right measure - but I'm desperate.
       | 
       | Didn't regulating cigarettes kind of work?
        
         | xyzal wrote:
         | Online discourse is sadly doomed. And if not yet, then tomorrow
         | surely.
         | 
         | https://arxiv.org/html/2506.06299v4
        
         | jgtrosh wrote:
         | To my surprise, this graph [0] shows that even when taking into
         | account vaping, it seems that smoking has truly gone down in
         | the US.
         | 
         | [0]: https://ecigone.com/featured/vaping-statistics/
        
         | olsondv wrote:
         | Sure, age restrictions played a part. But the larger reasons
         | are the increased awareness of direct health effects, banning
         | it in public spaces, and taxing the hell out of tobacco. I'd
         | bet if they restricted app usage in specific locations, that
         | alone would break the habit for some people. And imagine if you
         | charged them each time they logged on.
        
         | peyton wrote:
         | > Didn't regulating cigarettes kind of work?
         | 
         | That's commerce. The regulatory target in the case is speech.
         | We don't do that here.
        
         | StingyJelly wrote:
         | >instagram and the like are uniquely and disastrously harmful
         | 
         | -to both adults and children. What kind of worked for
         | cigarettes was the huge tax so why not create a "mental health
         | tax" based on the number of users x some addictiveness score
         | and let meta either fix instagram, pay their users a therapy or
         | pass the cost to them.
         | 
         | Instead this "protecting children" by giving them "degraded"
         | experience will only motivate them to bypass the age
         | verification and destroy the statistical evidence of the harm
         | those platforms cause.
        
         | sunaookami wrote:
         | I'm surprised people still fall for the "think of the
         | children!" excuse.
        
         | wink wrote:
         | > Didn't regulating cigarettes kind of work?
         | 
         | I am not sure what time or country you are talking about but
         | when I grew up (Germany in the 90s) we officially could only
         | buy cigarettes from age 16 (or 18?) and 50% of my friends
         | smoked. So that did absolutely nothing.
         | 
         | Later (I think, man it's been a while) the vending machines
         | needed a driver's license or id to verify the age and guess
         | what, as long as you had access to a single person over the age
         | of 18 you could still get cigarettes.
         | 
         | Stepping away from the cigarette topic... I think mixing the
         | two topics does not make sense.
         | 
         | First one is: Is there stuff on the internet that kids should
         | not be exposed to without supervision? I don't have a strong
         | opinion, I don't have kids. Probably not, but I am not even
         | interested in discussing this
         | 
         | Second one is: Will some stupid laws like the mentioned ones
         | help in any way? Maybe a little, probably not really and only
         | for kids who don't find a workaround. Will they have
         | catastrophic side effects and thus are not worth implementing
         | for minimal gain? 100% yes.
        
         | alerighi wrote:
         | It's not the job of the operating system to protect children.
         | Social media is bad even for adults, to my point of view why
         | they don't address the source of the problem, banning what
         | Instagram, TikTok, etc. is doing that is bad even for adults,
         | and don't make laws that restricts even more what a person can
         | do with their personal computer (if this law comes into effect
         | it's like saying it would be illegal to run Linux or whatever
         | OS that doesn't implement this bullshit)?
         | 
         | Well, surely because the government is full of investors in
         | Meta and uses Meta for their propaganda, and possibly because
         | the government wants more data to put on their databases that
         | is used by ICE and other agencies.
        
         | abc123abc123 wrote:
         | Flawed analogy. Cigarettes are physical goods, and regulating
         | them does not spread easily to other things.
         | 
         | Everything online is virtual, and implementing surveillance in
         | one area, almost always spreads, infecting everything else,
         | until we've built 1984.
        
           | mlrtime wrote:
           | Most of us are old enough for 'you wouldn't download a car'
           | nonsense...
           | 
           | But as adults that are starting to have kids, this "hard
           | divide" between physical and virtual starts to break down.
           | What I mean is that we can't always use the excuse that we
           | can't apply some reasonable law just because an item isn't
           | "physical".
        
             | muyuu wrote:
             | this is why the vector of attack of "think of the kids" is
             | almost always the first when it comes to try to lock down
             | the internet in some way
             | 
             | it's "protect the kids" or "counter-terrorism" and nowadays
             | also "harmful content" because as the internet is now fully
             | mainstream, softer and softer heads start to prevail
        
         | senfiaj wrote:
         | But why not force age verification / content restriction on
         | Facebook / Instagram / alikes instead? There aren't really that
         | many big players, isn't it?
         | 
         | Also, if what the OS does, is requiring to pick some number
         | from 0 - 100 and date without doing any verification, everyone
         | can lie. It has other flaws like not considering that many
         | people can share accounts, some embedded devices with UI can no
         | longer receive updates, etc. Honestly, if I thought for 30
         | minutes, I could list dozens of such problems. I doubt these
         | laws can work efficiently enough.
         | 
         | For now this might sound like the least of evils, but are we
         | sure that these idiot politicians won't come up with something
         | even more insane after seeing the inefficiency of this?
        
           | gzread wrote:
           | How would you impose it on them? Facebook's only way to tell
           | your age is for you to upload an ID document and don't we
           | want to avoid that? But when a parent buys a device for their
           | child, they can just enable the setting that says "this
           | device is for a child" and then Facebook can see that
           | setting, with no further identity information transmitted.
           | That's better privacy, not worse.
        
             | senfiaj wrote:
             | This might be plausible to an extend (probably for much
             | younger children). If the child can manage to install an OS
             | (which is not that difficult nowadays), or is some kind of
             | power user, then it will not work well. Also the laws are
             | about offline software, how it will be implemented for
             | websites (most of the harmful social media is actually
             | there)? There are no answers (i guess the web must
             | implement some standard, such as http specific header).
             | There are so many edge cases that I don't even want to talk
             | about.
        
           | muyuu wrote:
           | optionality already exists and works very well
           | 
           | you can install very tight parental controls on many devices
           | 
           | but this is not about optionality, this is about forcing the
           | mainstream into verification and certification schemes that
           | most people won't be realistically able to avoid, it's about
           | control and compulsion of the mainstream
        
         | slavik81 wrote:
         | > instagram and the like are uniquely and disastrously harmful
         | 
         | Could we perhaps regulate them to require that they be made
         | less harmful for everyone?
         | 
         | > anything the reduces the power those companies have over our
         | lives (and our politics)
         | 
         | If we're concerned about politics, I presume we're talking
         | about the impact on adults, but these age-based restrictions
         | are not intended to change anything for adults.
        
         | voxic11 wrote:
         | Did regulating cigarettes kind of work? I ask just because I
         | don't actually know. I always assumed that the regulations were
         | a reflection of the growing society wide distaste of cigarettes
         | and not a cause of it. If regulations were enough to change
         | peoples attitudes towards something then why did alcohol
         | prohibition fail so hard?
        
           | labcomputer wrote:
           | I mean, cigarette usage in the US is down _massively_ since
           | the US banned cigarette advertising to kids and actually
           | started enforcing the ban on cigarette sales to kids.
           | 
           | Meanwhile, after cigarette companies spent some time thinking
           | about how to solve the problem of falling sales, "vape"
           | (which did not have the same regulations) sales surged first
           | in kids, who have continued to use those products into
           | adulthood (after they became addicted).
           | 
           | So, I would say "yes" regulating cigarettes not only worked,
           | but was a massive public health success.
        
       | kraf wrote:
       | Comparing today's internet to the 90s is hardly fair. It has
       | become extremely predatory, and most places youth gravitate
       | towards are controlled by algorithms with the goal of getting
       | them hooked on the platforms to make them available for
       | manipulation by the platform's customers.
       | 
       | Of course, there will be stories of smart kids doing amazing
       | things with access to vast troves of information, but the average
       | story is much sadder.
       | 
       | The EU is working on a type of digital ID that an age-restricted
       | platform would ask for, which only gives the platform the age
       | information and no further PII.
       | 
       | Companies (not talking about system76) amazingly always find the
       | shittyest interpretations of their obligations to make sure to
       | destroy the regulations intention as much as they can. The cookie
       | popups should have been an option in the browser asking the user
       | whether they want to be tracked and platforms were meant to
       | respect this flag. Not every site asking individually, not all
       | this dark pattern annoyance. It's mind-blowing that that was
       | tanked so hard.
        
         | mendyberger wrote:
         | > Comparing today's internet to the 90s is hardly fair. It has
         | become extremely predatory...
         | 
         | I think you're missing the point they're trying to make. It's
         | not that the problem isn't real, it's that the solution won't
         | work. Kids will find a way around. They have a lot more free
         | time than us.
        
           | gzread wrote:
           | If you're geeky enough to install a virtual machine and know
           | that will break the restrictions, you're probably mature
           | enough to not need them.
           | 
           | Banning pubs from selling to minors doesn't work, but we
           | should still do it, right?
        
             | hellojesus wrote:
             | Physical is different from digital. Sure, today many kids
             | don't know or care about VMs, but they certainly will know
             | and care tomorrow when this regulation hits. And that info
             | will spread like wildfire all over social and blog posts.
             | 
             | About a week after the policy goes live it won't just be
             | the geeks that know, it'll be everyone in the 4th grade.
        
         | deno wrote:
         | > The EU is working on a type of digital ID that an age-
         | restricted platform would ask for, which only gives the
         | platform the age information and no further PII.
         | 
         | Sure, it might start out that way, but once adoption reaches
         | anything critical the PII will be required to squash free
         | speech as soon as possible. But by then the interaction flow
         | will be familiar, hardly anyone will even notice, never mind
         | care.
         | 
         | The EU has the best frog boiling experts in the world.
        
           | vladms wrote:
           | > ... will be required to squash free speech as soon as
           | possible.
           | 
           | Maybe pointing the obvious but things happen if enough people
           | care about them or do not care to oppose them.
           | 
           | From my perspective speech became "more free" lately -
           | meaning everybody says all kind of incorrect, wrong things
           | without fear of retribution even if there are laws against
           | some of those, because people just don't care.
           | 
           | So maybe we should also focus on teaching people what is free
           | speech, why is it good for them, why they needed, rather than
           | worry about some hypothetical mechanism that someone will
           | prevent it.
           | 
           | Of course both can be done, but I find it a bit funny that if
           | the focus in mostly on not having mechanisms to prevent free
           | speech, we might still end up in a situation that there are
           | no such mechanisms but on the other hand nobody speaks freely
           | because they don't care or only stare at their tiktok.
        
             | deno wrote:
             | The whole point is they cannot introduce those laws
             | outright for the obvious reasons they have to sneak it in
             | covertly in guise of safety.
        
               | gzread wrote:
               | By this reasoning we should oppose every law in case it's
               | a foothold to sneak in a different law.
               | 
               | The CA/CO parental controls API law is very reasonable.
               | It only mandates each OS must have a parental controls
               | API, the use of which is up to the parents.
        
               | deno wrote:
               | > By this reasoning we should oppose every law in case
               | it's a foothold to sneak in a different law.
               | 
               | That has been the successful strategy for e.g. NRA w/
               | regard to 2nd amendment and they have been proven correct
               | every single time.
        
           | abc123abc123 wrote:
           | Yep, the digital wallet will become the authoritarian,
           | beating heart of your life. If you don't comply with the EU,
           | you can say bye, bye, to your bank account, any online
           | interaction, they block your right to travel and so on.
           | 
           | The corona passports showed the way to achieve ultimate
           | control of the population, and the EU digital wallet will be
           | a permanent corona passport.
           | 
           | The public sheep, in their ignorance, are cheering this on,
           | without knowing what will await them. It is our
           | responsibility as technologists to fight this, and to educate
           | the sheep.
        
           | sham1 wrote:
           | One question about this doomsday scenario: "cui bono"? What
           | does the EU gain from squashing free speech in your mind?
        
             | deno wrote:
             | That's the problem with censorship, isn't it? It's always
             | in someone's interest. What speech will be silenced depends
             | on who is in power at the time.
             | 
             | If we can't mount a strong defense of free speech on
             | principle alone then it's doomed anyway.
        
         | whywhywhywhy wrote:
         | None of this is for what you're describing though, there is no
         | reality where such wildly different countries and states in
         | different corners of the world all decided coincidentally to
         | all do this within 6 months of each other. We know it's not
         | "well maybe they saw X country and thought it was a good idea"
         | because even percolating the policy would have taken over a
         | year.
         | 
         | Protecting kids is just the PR reason, the real goal is
         | requiring ID auth for every action taken on a computer. If we
         | normalize it for downloading apps or using websites the next
         | step is to authorize it for connecting to HTTPS at all and then
         | the next step is requiring it to unlock your CPU cores.
         | 
         | If people don't push back on this now there is no world where
         | we get out of 2030 without requiring government ID auth to
         | install linux on your own computer not connected to the
         | internet.
         | 
         | End to end silicon to server auth is absolutely possible and
         | someone is working really hard to make it a reality.
        
       | dbdr wrote:
       | This law feels like a battle in The Coming War on General
       | Computation, as Cory Doctorow put it:
       | 
       | > I can see that there will be programs that run on general
       | purpose computers and peripherals that will even freak me out. So
       | I can believe that people who advocate for limiting general
       | purpose computers will find receptive audience for their
       | positions. But just as we saw with the copyright wars, banning
       | certain instructions, or protocols, or messages, will be wholly
       | ineffective as a means of prevention and remedy; and as we saw in
       | the copyright wars, all attempts at controlling PCs will converge
       | on rootkits; all attempts at controlling the Internet will
       | converge on surveillance and censorship, which is why all this
       | stuff matters.
       | 
       | Full talk: https://www.youtube.com/watch?v=HUEvRyemKSg
        
         | muyuu wrote:
         | > all attempts at controlling the Internet will converge on
         | surveillance and censorship, which is why all this stuff
         | matters
         | 
         | it really boils down to this sadly, and it should be pretty
         | obvious shouldn't it?
         | 
         | i'm finding it befuddling that even technical audiences seem to
         | resist connecting those dots, but strong motivated reasoning is
         | at play: these are audiences that will often feel it will be
         | them who will be in control, and they're also emotionally
         | nudged by the idea of child safety
        
       | utopiah wrote:
       | On using VMs I suggested something similar earlier
       | https://lemmy.ml/post/43994511/24315514 so it's clearly not a
       | deep or original ideas. It will be figured out quickly. In fact
       | any kid reading that article or those comments is probably
       | already researching about this topic and chatting about their
       | successes and failures with friends. No way it can hold.
        
       | 0xbadcafebee wrote:
       | "Age verification" is such a politician's way to label this. It
       | doesn't actually verify your age. What it does do is set the
       | groundwork to argue that none of us should use any software on
       | any computer that an App Store with Age Verification doesn't
       | allow us to.
       | 
       | But there's a bigger issue than just what software you're allowed
       | to run on your own computer. What's really insidious is the
       | combination of the corporate and government interest. If every
       | server tracks how old you are, it's a short step to tracking more
       | information. Eventually it's a mandatory collection of metadata
       | on everyone that uses a computer (which is every human).
       | Something both corporations and governments would love.
       | 
       | You were worried about a national ID? No need. We'll have
       | national metadata. Just sign in with your Apple Store/Google
       | Store credentials. Don't worry about not having it, you can't use
       | a computer without it. Now that we have your national login, the
       | government can track everything you do on a computer (as all that
       | friendly "telemetry" will be sent to the corporate servers). Hope
       | you didn't visit an anti-Republican forum, or you might get an
       | unfortunate audit.
        
         | convivialdingo wrote:
         | Or anti-Democrat forum? Let's not pretend this isn't a
         | California law, or a bipartisan political power grab.
        
       | r2vcap wrote:
       | Fxxk off, to all political actors pretending this is about child
       | protection. Protecting children is not the job of the OS, the
       | device manufacturer, or the internet service provider. It is the
       | parent's job. If you cannot supervise, monitor, and discipline
       | your child's internet use, that is your failure, not theirs.
       | 
       | They can provide tools, sure. But restricting adults because some
       | parents fail at parenting is insane. That is how a totalitarian
       | state grows: by demanding the power to monitor and control every
       | individual.
       | 
       | If you cannot control your children, that is your fault. And if
       | that is the case, you should think twice before having kids.
        
         | mihaic wrote:
         | In general, I argue for less state control on anything. But
         | your argument seems flawed from its core. If someone is a bad
         | parent, should we simply ignore it and let the children turn
         | out idiots as well? And the line is often blurry, so that's why
         | we designed schools that should compensate even for dumb
         | parents.
         | 
         | And, just to be clear on this topic, I think these age
         | restriction laws are mostly bullshit, but I'm deeply against
         | the concept of putting all the responsabiliy of raising
         | children onto the parents.
        
           | therobopsych wrote:
           | If not parents then the school or the local council - you
           | can't parent from the government down
        
             | merlindru wrote:
             | what about children being fed unhealthy things? childhood
             | obesity is dangerous and also affects their mental and
             | physical health.
             | 
             | let's install cameras in all supermarkets that ensure
             | parents cannot buy unhealthy things for their children.
             | 
             | of course, adults can continue to purchase anything they
             | want for "themselves". but the facial scanning in
             | supermarkets is imperative for child safety!
        
               | array_key_first wrote:
               | This is right on the money and really highlights how
               | short-sighted these proposals are.
               | 
               | We're perfectly willing to destroy our privacy for things
               | that don't matter, but then the stuff that does, we don't
               | touch.
               | 
               | Realistically, seeing some boobies on instagram is
               | NOTHING compared to childhood obesity. Nothing. We're
               | talking lifetime of suffering and early death versus
               | boobies.
        
             | mlrtime wrote:
             | The government will "parent" as a last resort : the
             | criminal justice system.
        
           | r2vcap wrote:
           | I assume you live in the free world. Some socialist states in
           | history, such as East Germany, pushed child-rearing and early
           | education much further into the hands of the state through
           | extensive state-run childcare and kindergarten systems. That
           | model is gone, and for good reason.
           | 
           | Even with schools in place, the basic responsibility for
           | raising children still belongs to the parents. Schools can
           | support, educate, and compensate to some extent, but they
           | cannot replace parental responsibility.
           | 
           | I also see far too much awful news -- in my country, Korea,
           | for example -- about terrible parents harassing school
           | teachers because their children are out of control.
        
             | mihaic wrote:
             | I was born in a communist country in Eastern Europe, which
             | is now crony capitalist. The issue is extremely complex,
             | and all I can say in such a short paragraph is that
             | ideologically-driven implementations are doomed to fail. It
             | doesn't matter if you believe in "free-market", "the
             | state", "free-speach", "socialism" or "equality", if you
             | put these above the concrete reality of modern parenting,
             | and how much harder it's getting compared to previous
             | generations.
        
             | muyuu wrote:
             | i'm afraid that model is making a strong comeback in the
             | so-called free world
        
           | peyton wrote:
           | It's compelled speech. A transmission of expression required
           | by law. The argument settled in 1791. The First Amendment
           | does not permit the government to compel a person's speech
           | just because the government believes the expression thereof
           | furthers that person's interests.
        
             | gzread wrote:
             | It's also a consumer product regulation, of which many
             | already exist. The government compels you to speak about
             | the ingredients in a food product you manufacture, and we
             | don't seem to have a problem with that.
        
               | VLM wrote:
               | A better analogy would be regulation of addictive
               | activities like gambling and regulation of addictive
               | substances like painkillers. Given that the platforms
               | being regulated were intentionally engineered to maximize
               | addictive potential, this seems a fair and reasonable
               | response.
        
               | hellojesus wrote:
               | But you can just block the domains on the device or
               | router... This law is wholly unnecessary.
        
               | gzread wrote:
               | No you can't, because the software industry spent a lot
               | of effort encrypting DNS and HTTP so that intermediaries
               | can't tamper with or spy on it.
        
               | hellojesus wrote:
               | I am a parent. The devices my child uses have root certs
               | that allow me to decrypt traffic that must pass through
               | my proxy to be relayed to the internet. Voila. Problem
               | solved with current tech.
        
           | trashb wrote:
           | > we simply ignore it and let the children turn out idiots as
           | well
           | 
           | There is not a lot of safeguarding against this in the real
           | world tbh. At the very least I think the OS or internet age
           | verification is not the place to start improving this.
        
             | gzread wrote:
             | There is some. Bars won't serve minors. The standardisation
             | of parental controls law (the CA/CO one) is much closer to
             | "bars won't serve minors" than it is to "camera drones will
             | follow minors around to make sure they don't drink alcohol"
        
               | nottorp wrote:
               | > Bars won't serve minors.
               | 
               | Bars also won't display a copy of your ID on the main
               | street like digital "think of the children" initiatives
               | are likely to.
        
               | gzread wrote:
               | Neither does the California/Colorado parental controls
               | API law.
        
               | FuriouslyAdrift wrote:
               | If you get caught with a fake ID they sure as heck do.
               | Had many a friend in college with a copy of their ID on
               | the wall of shame.
        
           | themafia wrote:
           | > should we simply ignore it and let the children turn out
           | idiots as well?
           | 
           | Just because you're an idiot at 18 doesn't mean you are one
           | for life.
           | 
           | > so that's why we designed schools that should compensate
           | even for dumb parents.
           | 
           | Does that actually work?
           | 
           | > against the concept of putting all the responsabiliy of
           | raising children onto the parents.
           | 
           | Then how do you feel about parents requiring a license before
           | they have a child? If you wish to invite yourself into their
           | responsibilities shouldn't you also invite yourself into
           | their bedroom first?
        
             | mihaic wrote:
             | > If you wish to invite yourself into their
             | responsibilities shouldn't you also invite yourself into
             | their bedroom first?
             | 
             | You're turning of question of measure (how much should
             | society be involved in raising children) into an all or
             | nothing debate, which I explicitly want to reject.
             | 
             | > Does that actually work?
             | 
             | Yes, because of mass education almost every adult you meet
             | can read and write, something new for the last 100 years.
             | Just because a system has (currently huge) faults, doesn't
             | mean we should remove the system entirely.
        
           | hypercube33 wrote:
           | You make a good point that society may be responsible as
           | well, however we are arguing over trying to use technology to
           | solve meatland problems and this one never should be
           | automated into tech, ever. It's putting burden on artists and
           | engineers to solve things they aren't causing or really
           | responsible for.
        
           | a456463 wrote:
           | Lmao you are a bad parent if you decide to have kids and then
           | expect the world to take care of them for you
        
             | zbentley wrote:
             | Okay, assuming that's the case for the sake of argument,
             | that's still a huge problem right? Kids raised by bad
             | parents suffer, which is inhumane. And if you don't care
             | about that, they also cause problems or costs for society
             | at large (especially if there are a lot of them).
             | 
             | Those are bad outcomes. So is it any wonder that we look
             | for policy/regulatory issues to mitigate the harms of bad
             | parenting?
        
           | xphos wrote:
           | To be fair if the the parent is garbage there isn't anything
           | the state today can do to truly prevent the child from being
           | corrupted short of taking the child. We ensure that vaccine
           | laws are difficult to enforce, we ensure that the child
           | cannot have any privacy from the parent codified at school.
           | At every stage we gave parents essentially absolute authority
           | over there children with exception to maybe physical abuse.
           | And I say maybe because even in physically abusive parent, it
           | can be difficult for the child to advocate and escape. They
           | can ask to be emencipated but the odds are stacked against
           | you that you can proof you can support yourself financially.
           | 
           | All this to say is while I think the OP is mean about it they
           | but are not wrong. The law argues heavily the parent is
           | supreme at least in the US. But this specific law push the
           | responsiblity of being the supreme authority off of parents.
           | I know you don't like that concept but I think it is very
           | easy to argue that any other model is going to be
           | unacceptable to a pluraity of parents. Thats not to be
           | confused with a parent is responsible for everything there
           | child does because thats not true. But the consquence of that
           | thinking is that children ultimately have some responsiblity
           | in the things they do over the parent, which I think the
           | authors of this law would be sweating at such a statement.
           | 
           | Personally I think the biggest issue for children is impulse
           | control around social media and to be frank I don't think
           | Adults are necessiarly able to deal with the onslaught of
           | endless feed short form video content either. I don't think
           | our brains are built against it very well. I don't know what
           | the solution is but I think what made youtube without shorts
           | different from tiktok is the endless scroll nature. The added
           | friction actually protected peoples conscious and something
           | to add a minimal friction to interactions would actually be
           | massively beneficial to society at large
        
         | cultofmetatron wrote:
         | this whole thing is part of building a mechanism to restrict
         | free speech down the line to cover for a certain "greatest
         | ally" of the united states. make no mistake, the "not a
         | genocide" over the last two years and the recent "not a war" is
         | very much related to this.
        
           | gzread wrote:
           | How does mandating every OS to have a parental controls API
           | lead to wholesale suppression of speech? Will they mandate it
           | to always be set to the most restrictive setting?
        
             | cultofmetatron wrote:
             | this isn't "parental controls" this is a mandate to verify
             | your age and subsequently identity to an external third
             | party. can't you see how this is a slippery slop to
             | deannonymizing the internet and being able to restrict
             | access for reason that won't be revealed until later?
        
               | gzread wrote:
               | Are we talking about the same law? California AB1043?
        
         | mxfh wrote:
         | sure, let all retailers sell alcohol to children to test your
         | theory.
        
           | tommica wrote:
           | Logic does not work, because alcohol in this case is a
           | product being purchased - Kids can go to the store and buy
           | other things.
           | 
           | So alcohol is more like a gambling website.
        
             | mlrtime wrote:
             | It's also illegal to give kids alcohol, they aren't
             | purchasing it. Does that match up with a app that is 18+?
        
           | 06867457397658 wrote:
           | Sure, let all retails scan your face to buy groceries.
           | 
           | What would the regime do without their useful idiots?
        
           | brendoelfrendo wrote:
           | Man, it's really great that we can make laws tailored to
           | specific circumstances and not treat everything the same, too
           | bad you never learned that.
        
         | tyler33 wrote:
         | of course it is an excuse for controlling/spy on us, every
         | children use and will keep using their parent computer/phone
        
         | newsclues wrote:
         | What if we had ISP police?
         | 
         | Cops to track what people did on the internet, checking every
         | image to ensure it's not pornographic, or every transaction
         | online, to ensure it's not criminal!
         | 
         | Sounds great! Let's just start by rolling out the program to
         | target elected officials and their families as a trial. If
         | every congressional or senate representative wants to undergo a
         | few years of scrutiny to make sure the system works well, maybe
         | the people will follow gladly.
        
           | curt15 wrote:
           | Welcome to CCP China!
        
             | newsclues wrote:
             | Sorry, the point I am trying to make, is bullshit laws
             | should be tested on the group of people advocating and
             | passing those laws, because maybe they wouldn't like the
             | law when it applies to them.
        
       | morissette wrote:
       | Definitely started exploring at 8/9 writing Perl and CGI
        
       | egorfine wrote:
       | None of the facts he states are unknown or new to the authors of
       | the mentioned bills.
        
       | dataflow wrote:
       | > A parent that creates a non-admin account on a computer, sets
       | the age for a child account they create, and hands the computer
       | over is in no different state. The child can install a virtual
       | machine, create an account on the virtual machine and set the age
       | to 18 or over.
       | 
       | Er, how does a child install a VM from a non-admin account?
       | 
       | > Or the child can simply re-install the OS and not tell their
       | parents.
       | 
       | It's gonna be pretty easy to detect when the parent finds
       | programs are missing/reset or the adult account they created
       | can't log in with their password.
       | 
       | The California law seems entirely tame and sane, whereas the New
       | York bill seems pretty heavy-handed and authoritarian. They are
       | in no way similar to each other.
        
         | hellojesus wrote:
         | The law necessarily exists for parents that aren't tech
         | literate, since we already have the ability to monitor and lock
         | kids out from adult content.
         | 
         | Do we really think parents will notice that a kid has installed
         | a specific executable? The purpose of this law is to allow
         | parents to outsource caring out which executables are safe, so
         | there is no reason they would check.
         | 
         | Plus a kid can just live boot from a USB if the parent doesn't
         | lock the bios, which would give them an ephemeral session to do
         | whatever they want without the parent knowing unless caught-in-
         | the-act.
        
       | purplehat_ wrote:
       | I'm surprised zero-knowledge proofs have not been mentioned. This
       | is a technique where (for example) the government signs your
       | digital license, then you can present a proof that you are over
       | 18 to a site without revealing anything else about yourself.
       | ZKPassport exists, Privacy Pass is an implementation being
       | standardized by the IETF, and Google is working on a similar
       | implementation. Granted, these are not yet widely used, but I'd
       | be very interested in hearing HN's thoughts on this.
       | 
       | Let's try to figure out what a good policy solution looks like:
       | 
       | - entities with harmful or adult content must require proof of
       | the user being over 18
       | 
       | - entities cannot ask for, store, or process more detailed
       | information without explicit business needs (this should be
       | phrased in a way that disallows Instagram from asking for your
       | birth year, for example)
       | 
       | - entities cannot share this data with other sites, to avoid
       | privacy leaks, unless there is an explicit business need (this is
       | tricky to get right; someone might try to set up a centralized
       | non-anonymous age-verification service, erasing many benefits)
       | 
       | - entities must in general not store or process information about
       | the user that is not strictly relevant to their function
       | 
       | - there ought to be different treatment for anonymous users
       | (which ideally these protocols will allow, just submit proof of
       | work plus a ZKP that you are a human and authorized to access the
       | resource) compared to pseudonymous and non-anonymous users, who
       | are more at risk of being censored or tracked.
       | 
       | There's some loopholes here, but if the government can enact good
       | policy on this I personally think it's feasible. Please share
       | your thoughts, if you have a minute to do so.
       | 
       | There's also an interesting political split to note among the
       | opposition here. I see a lot of people vehemently against this,
       | and as far as I can see this is largely for concerns regarding
       | one of 1) privacy abuses, 2) censorship, or 3) restriction of
       | general computing. Still, there is a problem with harmful content
       | and platforms on the web. (Not just for minors, I don't think we
       | should pretend it doesn't harm adults too.) The privacy crowd
       | seems to be distinctly different from the computing-freedom
       | crowd; the most obvious example is in attitudes towards iOS. As I
       | personally generally align more towards what I perceive as the
       | privacy-focused side, I'm very interested in what people more
       | focused on software freedom think about zero-knowledge proofs as
       | a politically workable solution here.
        
         | wao0uuno wrote:
         | Sounds cool but do you believe it's really about protecting
         | children? Since when do politicians care about this so much? I
         | have not heard of any protests or public calls for better child
         | protection online. It's really all about control and
         | elimination of freedom of speech and information. They want to
         | set up a legal framework and get people more comfortable with
         | the idea of closed and controlled internet. Then they'll argue
         | that age verification alone is ineffective because its too easy
         | to circumvent so they'll start rolling out less "private"
         | solutions that will benefit them and their sponsors greatly.
        
           | purplehat_ wrote:
           | I'm not sure anyone is being this explicitly malicious.
           | Parents' groups, child safety organizations, and researchers
           | have been at this for years, and while I agree with you that
           | the solutions are very misguided, I think it does our own
           | priorities a disservice to stick our fingers in our ears with
           | regards to their concerns.
           | 
           | Can you give an example of how less private solutions will
           | benefit them and their sponsors? I could see big tech /
           | adtech and government surveillance benefitting but I don't
           | think they're the ones behind this push.
           | 
           | As another example, consider the "small web" community, say
           | at Bear Blog, which is a group of technically sophisticated
           | people who routinely complain about the harms of traditional
           | social media. I doubt most of them would support this
           | particular implementation, but they show that there is
           | popular support for solving the ills of at least one of the
           | targets of this legislation.
           | 
           | So to answer your question, yes, I do see this as an attempt
           | to protect people. The restriction of free speech is in my
           | opinion a side effect of this legislation opening the way to
           | worse-designed laws in the future.
        
       | ibizaman wrote:
       | > The challenges we face are neither technical nor legal. The
       | only solution is to educate our children about life with digital
       | abundance. Throwing them into the deep end when they're 16 or 18
       | is too late. It's a wonderful and weird world. Yes, there are
       | dark corners. There always will be. We have to teach our children
       | what to do when they encounter them and we have to trust them.
       | 
       | This resonates so much with me. I don't want to control my kids.
       | I will never be able to protect them from everything. I hope I
       | won't be able because I want to die before them. I want them to
       | be able to navigate in the world and have all the cognitive tools
       | necessary to avoid being fooled. I want to rest in peace knowing
       | they can in turn educate their own children. I want to trust them
       | and be relieved that I can focus on some tasks of my own without
       | needing to constantly worry about them.
        
       | OutOfHere wrote:
       | As a resident of New York, I am disturbed to see Democrat
       | representatives introduce such horrific bills. I guess I will not
       | be voting Democrat again!
        
       | dagss wrote:
       | Not commenting on this specific law, but I do believe the premise
       | that children should be exposed to everything is wrong, and that
       | the overall view on humans in this post is naive.
       | 
       | These days, exposing an immature brain to the raw internet is
       | basically just handing the brain and personality over to be
       | molded by large corporations and algorithms.
       | 
       | And humans have never been rational, self-contained actors that
       | self-educate perfectly when exposed to information, converging on
       | an objectively good and constructive worldview. Quite the
       | opposite.
       | 
       | Humans develop in relation to one another, increasingly in
       | relation to algorithms, and sometimes become messed up, and
       | sometimes those mess-ups would have been avoidable had relations
       | or exposure been different.
       | 
       | In fact I would say you as a parent is not doing your job if you
       | are not trying to make sure a 12 year old isn't pulled into, say,
       | an anorexia rabbit hole.
       | 
       | Whether that is best done through making sure exposure doesn't
       | happen, or through exposure and education, will depend on the
       | child and parent (and society) in question. What worked best for
       | a highly rational self-reliant geek teen may simply be a disaster
       | for another human. And what worked for an upper class highly
       | educated family may not work for a poor family with alcoholized
       | parents or working 18 hours a day to make ends meet.
       | 
       | And parents are not perfect -- if all parents were perfect, there
       | also would be no alcoholics and drug addicts or poverty or war.
       | But people are imperfect, and it's natural to make laws to
       | mitigate at least the worst effects of that. (Again, haven't read
       | this specific law proposal, but found the worldview of OP a bit
       | naive.)
        
         | thunfischtoast wrote:
         | > These days, exposing an immature brain to the raw internet is
         | basically just handing the brain and personality over to be
         | molded by large corporations and algorithms.
         | 
         | You make the case of todays internet being insuitable for young
         | children. But has this been different, ever, maybe apart from
         | the very first days of the internet? While access through
         | phones has reshaped the internet fundamentally, I'd propose
         | that it has always been dangerous. When I was 12, a single
         | wrong click could destroy your machine, or lead to a physical
         | bill being sent to my parents home (which has happened), or
         | lead to most disturbing pictures and videos.
         | 
         | So I think it's not the case that we should allow kids
         | completeley unsupervised access (like it always has been), but
         | it's also naive to think that we can regulate our way out of
         | this (on state or household-level, like it always has been).
        
           | dagss wrote:
           | I think there is a drastic difference between being once off
           | exposed to bad images, and an algorithm making a choice of
           | whether to subtly over time expose the Pokemon-interested
           | child to racist Pokemon videos vs non-racist Pokemon videos
           | on Tiktok. (Or anorexic Pokemon videos, or..)
           | 
           | Amount of time spent and repeated exposure being the key.
           | 
           | The question is really what kind of human is _raised_ ,
           | rather than raw exposure as such.
           | 
           | So for that reason things are different IMO than than 20
           | years ago.
           | 
           | Yes, of course some people would fall into internet forum
           | rabbit holes 20 years ago, and papper-letter-friend-induced
           | rabbit holes 100 years ago. But it did help that it was like
           | 5% of the population instead of 95% of the population
           | spending their time there.
           | 
           | Regarding your last point, I don't necessarily disagree
           | (again I didn't check up on this law, I care more about the
           | laws in my own country), but I think arguing against the law
           | will go better if one does not display naivety when making
           | the arguments
           | 
           | Don't say "it will be better if all kids are exposed to
           | everything early" (it won't), instead say "the medicine will
           | not work and anyway the side-effects are worse than the
           | sickness it intends to cure" (if that is the case).
        
             | LinXitoW wrote:
             | But the algorithm stuff is bad for everyone, and makes a
             | lot of money, so it's obviously never ever going to be part
             | of any regulation.
        
               | dagss wrote:
               | Australia banned social media under 16, and many other
               | countries are looking on variations on this.
               | 
               | In the US, perhaps not...
        
               | labcomputer wrote:
               | But adults (who have fully developed brains, unlike
               | adolescents) can choose not to engage with the algorithm
               | stuff.
        
           | theshrike79 wrote:
           | When my generation "accessed the internet", there was a
           | massive dial-up sound and the single family PC was in the
           | living room, visible to everyone.
           | 
           | Even later when the computer was in my room, I still had to
           | go look for the creepy shit, it didn't appear in my email
           | inbox.
           | 
           | Kids this age browse the internet through algoritmic apps
           | built to maximise engagment in a corner on their bed in their
           | room. Parental controls for most apps and operating systems
           | are a fucking joke.
        
             | hellojesus wrote:
             | Agreed, but isn't this a parental issue? Why aren't parents
             | moving back to a "shared pc in the living room" model?
             | 
             | I absolutely would not allow a kid to have an unregulated
             | smartphone and then further compound the problem at home by
             | allowing them to access it privately and without
             | interruption. Device management enrollment is trivial on
             | iphones.
        
               | theshrike79 wrote:
               | Having a smart phone is required for taking part in
               | society.
               | 
               | Monitoring said devices is a lot harder, enrolling to
               | device manager doesn't let me monitor the content of
               | specific apps
        
           | labcomputer wrote:
           | This feels like an extremely naive take.
           | 
           | Even as late as the mid-aughts the internet was mostly nerdy
           | technical information, real people sincerely discussing
           | various topics, and the very worst thing was a little bit of
           | (mostly still-image) porn if you were looking for it.
           | 
           | Kids back then weren't targeted by a stream of continuously
           | A/B tested algorithmic content intended to tell them what to
           | think and shape their brains. Overwhelming evidence exists
           | that social media (as it exists today) is bad for the mental
           | health of young people (and probably adults, too, but at
           | least adults have the presence of mind and lack of social
           | pressure to delete Facebook).
        
         | FetusP wrote:
         | But, should it be the governments responsibility to
         | decide/control how children are raised, and what they are
         | exposed to?
         | 
         | Maybe in the future, a governing body will try to age lock
         | dissenting opinions with some crafty verbage
        
           | gzread wrote:
           | The CA/CO law only requires the option to enable parental
           | controls on an account, and as the article points out, can be
           | worked around by a sufficiently determined child using
           | something like a virtual machine. This is not really the
           | government deciding how children should be raised. The parent
           | still has the ability to choose to apply the parental
           | controls.
           | 
           | It's more like the rule that minors can't buy alcohol in bars
           | - parents can still buy alcohol at the supermarket for their
           | children, and sufficiently determined children can find some
           | other adult to buy it for them.
           | 
           | Probably by the time you know how to install a virtual
           | machine, you can handle the unrestricted internet.
        
             | Cyph0n wrote:
             | The bigger problem is it sets us on a possible path towards
             | completely government-controlled computing devices. The
             | fact that so many countries are pursuing ID requirements
             | online is somewhat of a canary for this whole OS age check
             | thing imo.
        
         | jonathanstrange wrote:
         | My view is that this must be left entirely to the parents. The
         | only time a government should be allowed to interfere is when
         | there are child abuse or neglect cases against the parents and
         | the children are put under child protective care.
         | 
         | It is in my view crazy and irresponsible to allow the
         | government override the parents' decisions about what media
         | their children can consume. It is guaranteed that this power
         | will be abused.
        
           | gzread wrote:
           | The CA/CO law is literally the government writing a law that
           | says it shall be left to the parents but the device must give
           | the parents the options they need.
        
             | muyuu wrote:
             | it says that, but the action of hardening devices
             | effectively contradicts what it says
             | 
             | to be charitable, let's say that it "enhances" parental
             | controls by taking on some of that parental enforcement at
             | the state level
        
               | gzread wrote:
               | What action do you mean?
        
               | muyuu wrote:
               | the action of forcing any sort of verification or
               | certification on devices or operating systems
               | 
               | this is taking the parental control largely into their
               | own hands
        
               | gzread wrote:
               | This law doesn't force any sort of verification or
               | certification, so it's fine then?
        
               | muyuu wrote:
               | it is obviously enforcement by proxy, trying to pretend
               | otherwise is laughable but then again so is most of the
               | shilling supporting this legislation
        
               | gzread wrote:
               | What is "enforcement by proxy" and how does it apply to
               | this law?
        
               | muyuu wrote:
               | it is extremely simple
               | 
               | for instance, the government can effectively ban you from
               | saying something they don't want you to say by forcing
               | all companies that may provide any substantial platform
               | to you to implement their code speech
               | 
               | that way they have enforced a ban on you by proxy
               | 
               | the same way they can verify/certify the id of people
               | totally or partially when they go online, by forcing all
               | vendors who provide the systems that you may use to go
               | online to enforce it for them
               | 
               | and this law absolutely does that
        
               | hellojesus wrote:
               | Does it effectively outlaw general computing for minors
               | by requiring account holders to set up accounts for
               | minors where account holders are defined as being 18+?
               | 
               | Im honestly not sure; but I could see that being the
               | result of the law and companies like best buy disallowing
               | minors from purchasing hardware with cash for fear of
               | liability.
        
               | gzread wrote:
               | No, it doesn't.
        
             | jonathanstrange wrote:
             | So these laws state that device makers need to ensure that
             | there is at least one operating system with parental
             | controls that the parents can install?
             | 
             | That would be fine for me but AFAIK that's not what these
             | laws state.
        
             | tstrimple wrote:
             | I've obviously read about how bad adult literacy in the US
             | is, but I didn't realize how many "technologists" were
             | impacted by it. The law is short and clear and doesn't
             | involved attestation or age verification. Yet all these
             | "hackers" claim it does just that. The reading
             | comprehensions and critical thinking skills seem to match
             | the national average.
        
               | hellojesus wrote:
               | I think most people here are extrapolating the intent
               | behind this law, the triviality with which it can be
               | bypassed by minor account holders, and what that means
               | for the future. Once this law is in effect, it will be
               | ineffectual. Minors that current don't know what VMs are,
               | what live booting is, what keyloggers are, etc. will
               | learn immediately once blog posts start circulating about
               | bypass mechanisms. Parents will then go back to the
               | legislature and say the law as-written sucks, and they
               | will demand better laws, but the only way to get better
               | is to force all devices to authenticate with the isp with
               | a gov-issued id/token to prove the account is not a
               | minor. But the only way to prevent even further
               | workarounds like the OS lying is to force hardware based
               | remote attlestation. And that means the death of general
               | computing and the death of any anonymity.
        
               | gzread wrote:
               | Most laws are ineffectual. Kids can't drink alcohol but
               | they still can; theft is illegal but I still got your car
               | keys; murder is illegal but people still die. In this
               | one, there's no punishment for bypass, just like there's
               | no punishment for a kid who gets alcohol. Unlike the
               | alcohol law this one doesn't even mandate the use of the
               | child protection features - just their existence.
               | 
               | You know the simple fix to your problem is to mark VMs as
               | adult only apps, anyway.
        
               | hellojesus wrote:
               | But what happens when a nefarious actor fills the void
               | and publishes a root-kited VM and marks it as safe for
               | children? These restrictions breed black markets that
               | usually cause even more harm.
        
         | nicman23 wrote:
         | > believe the premise that children should be exposed to
         | everything is wrong
         | 
         | imo this is what is wrong with modern parenting. the reality
         | does not care about the child's feelings and if it is old
         | enough to have a screen with internet unattended it is old
         | enough for anything
        
           | gzread wrote:
           | I don't understand what you're trying to say in this comment.
           | Can you reword it?
        
         | muyuu wrote:
         | ok, that is the argument with merit in favour of shielding kids
         | from the internet - now let's consider how does it look like
         | when the locus of responsibility is governments
         | 
         | it's true that kids are vulnerable to certain forms of content
         | on the internet
         | 
         | it's also true that adults are vulnerable to certain forms of
         | content on the internet
         | 
         | it's also true that governments cannot police "harmful content"
         | on the internet effectively, or even meaningfully, if most
         | people can easily surf the internet pseudonymously
         | 
         | it's also very true right now that what's on "social media" is
         | very Sybill-vulnerable, and inordenately so right now with the
         | advent of LLMs
         | 
         | what do you think the playbook will look like once there is
         | some sort of tight OS level system that is enforced across the
         | board to certify or verify information about the user?
         | 
         | do you think this level of coordination to push for identifying
         | the user at all levels that is happening across the world in a
         | matter of weeks is genuine concern for the kids alone?
        
         | eloisant wrote:
         | I agree, and I believe too many geeks who are now parents
         | (including the author of the blog post) do not realize that the
         | computers they grew up with, and in particular the Internet
         | they grew up with, is nothing like computers (phones) and the
         | Internet kids have access today.
        
           | intrasight wrote:
           | The Grimm fairy tales (1819) are full of graphical violence,
           | child abuse, anti-semitism, and incest. They are much more
           | harmful than anything that I've encountered on the Internet.
           | So why are we discussing internet harms instead of book
           | harms? Because people are fucking stupid.
           | 
           | And why are we getting concerned about "sharing private
           | information with random web sites" when that's not the
           | solution being discussed. The solution is a simple handshake:
           | 
           | service: Is the person assigned this device old enough to use
           | this service?
           | 
           | idp proxy: yes|no
        
         | a456463 wrote:
         | If you are not perfect, then don't have kids then. If you can't
         | take care of them and nurture them with the attention that they
         | need and rightfully deserve.
        
         | jajuuka wrote:
         | I've seen this view applied to things like TikTok and
         | Instagram. Especially with the recent lawsuit. But then when to
         | comes to addressing it most people seem to flip completely and
         | bemoan parenting and internet freedom. It just ends up in a
         | circular pattern of "this is awful, but we shouldn't do
         | anything about it. These companies are poisoning kids, but any
         | attempts to rectify that are infringing on my right to the
         | internet." Makes a lot of conversations around this topic feel
         | entirely pointless.
        
       | badpenny wrote:
       | Remember when it was the parents' responsibility to raise their
       | children?
        
         | gzread wrote:
         | It still is. The California law insists that parents should be
         | given the features they need to raise their children.
        
           | 06867457397658 wrote:
           | How did modern humans manage to raise children without state-
           | mandated age verification for the last 300k years?
           | 
           | Thank god totalitarian bureaucrats and lobbyists descended
           | from the heavens like Prometheus and gave you these tools.
        
       | whywhywhywhy wrote:
       | Linux distributions could do a lot of good geo blocking
       | California right now.
        
         | senfiaj wrote:
         | What if 1/3 of US states and some EU countries joins them? Will
         | they block so many users? Also blocking is easier for smaller
         | distros, not so much for Valve, Red Hat and Ubuntu.
        
       | defraudbah wrote:
       | remember El Mencho, it should have been a title!
        
       | IndySun wrote:
       | "Liberty has costs, but it's worth it"
       | 
       | The whole point. Very well worded post. I weep for the all
       | digital future.
        
       | moonlion_eth wrote:
       | I was enrolled in the united states navy nuclear program at 17.
       | we are just making kids dumb with this bullshit
        
       | xtanx wrote:
       | Organize and fight the policy. Do not take your frustration out
       | on people and companies that just try to adjust to a law. Talk to
       | your representatives. Create educational websites similar to
       | fightchatcontrol.eu.
        
         | user3939382 wrote:
         | At least in the US check out the 2014 Princeton study on
         | citizen preferences. Our Democracy is a sham, those mechanisms
         | don't actually have any power to change anything.
        
           | xtanx wrote:
           | That's why we need to organize extra hard.
        
         | gzread wrote:
         | But this is actually a really good policy? It just says every
         | OS shall have a UI to turn parental controls on or off, and an
         | API to check if they're turned on. That's a good thing. It
         | satisfies the reasons people wanted age verification, without
         | actually doing age verification.
        
           | nottorp wrote:
           | Yes but the next step is forbidding open source OSes because
           | they can be modified to lie on this API check.
        
             | gzread wrote:
             | The next step after forbidding the serving of alcohol to
             | minors is forbidding the serving of alcohol to everyone.
        
       | ed_blackburn wrote:
       | This is becoming a wedge issue. It should not be. As an industry,
       | we can solve this. As an industry, we have too. If we don't,
       | legislators will do it for us. And they'll make a bad job of it.
       | And if you petition your local legislator wherever yiu are in the
       | world, then that's cool, but if this is solved locally, we will
       | see serious fragmentation. As an industry projecting ones
       | politics isn't going to make much difference.
        
       | motbus3 wrote:
       | If my parents blocked me from doing admin stuff (which was not
       | even possible back then) I would certainly not started to code by
       | myself when I was a tween
       | 
       | More concerning than that is that it all doesn't seem because
       | they care about teenagers and kids.
        
       | b3lvedere wrote:
       | I don't really mind age verification, since we do it in real life
       | (outside the internet) constantly for products and services that
       | are meant for adults, like some-rated movies and alcohol.
       | 
       | I do mind a lot of the data process. I do not want my id,
       | personal preferences or any metadata of my self stored anywhere
       | ever. And IF by some weird law some process has to store some
       | data somewhere of me, i want to have very easy full access to it
       | so i can delete it whenever i want. You can keep the process
       | itself but anything else has to go.
       | 
       | Yes, i have a passport. Yes, it was verified and validated. No
       | you may not know or store the color of my eyes.
       | 
       | I also do not want curious kids to be prosecuted for poking
       | around. They should teach them and thank them for finding flaws.
        
         | gzread wrote:
         | There's no age verification in this law...
        
       | Traster wrote:
       | I'm in two minds about this. I think that by and large We Have A
       | Problem. And i don't mean a problem with children on the
       | internet. We have a problem with people on the internet. There
       | are so many examples of grown adults who have clearly become
       | addled.
       | 
       | I live in the UK, I work in London. I can go on X and look at
       | what Elon Musk is posting about the UK and as a reasonable person
       | I can quite reasonably say he's gone _mental_. The algorithm has
       | broken that mans brain. And it 's not just him, a whole slew of
       | establishment women lost their absolute minds about the trans
       | issue (and Graham Linehan). Mumsnet became a centre for
       | radicalization. You know and some one who grew up on the internet
       | at quite a sweet spot I'm very comfortable looking at that stuff
       | and going "Oh yeah, you guys are being groomed by these
       | algorithms and you're defenceless to it".
       | 
       | There's a whole load of "How do we protect the children from
       | this", but I don't think there's actually been much a reckoning
       | with how grown adults are getting sucked into this vortex. The
       | algorithms on the internet clearly have some trap doors that just
       | absolutely funnel people into crazy places.
       | 
       | All of which is to say: We have a serious problem that's
       | effecting everyone not just kids, and I think we've got almost no
       | answers for how to tackle it.
       | 
       | The result is this- poorly thought through sweeping laws that
       | aren't solving the problem, and have massive negative side
       | effects. I think Jonathon Haidt has a lot to answer for in
       | funnelling this complex issue affecting everyone into this
       | reactionary "won't someone think of the children!" campaign for
       | banning technology for kids.
        
         | gzread wrote:
         | The problem is that putting restrictions on adults comes with a
         | thousand times more outrage than putting restrictions on kids,
         | and look how much outrage there already is about putting
         | restrictions on kids at the discretion of their parents. If we
         | can't even give parents the option to keep kids away from bad
         | stuff, then mandatorily keeping adults away from bad stuff is a
         | complete non-starter. They'd probably burn down Parliament.
        
         | nottorp wrote:
         | > And i don't mean a problem with children on the internet. We
         | have a problem with people on the internet.
         | 
         | Yes. And having a fixed cut off from 'you can't see omg boobs!
         | on the internet' to 'you can see snuff porn on the internet'
         | won't help.
        
       | txrx0000 wrote:
       | Rather than age verification, this is what we should be doing
       | instead:
       | 
       | Don't let phone manufacturers lock the bootloader on phones. Let
       | the device owner lock it with a password if they decide to.
       | Someone will make a child-friendly OS if there is demand. Tech-
       | savvy parents should be able to install that on their kid's phone
       | and then lock the bootloader.
       | 
       | What about non-tech-savvy parents?
       | 
       | There should be a toggle in the phone's settings to
       | enable/disable app installation with a password, like sudo. This
       | will let parents control what apps get installed/uninstalled on
       | their kid's device.
       | 
       | But what about apps or online services that adults also use?
       | 
       | Apps and online services can add a password-protected toggle in
       | their user account settings that enables child mode. Parents can
       | take their child's phone, enable it, and set the password.
       | 
       | ----
       | 
       | All it takes is some password-protected toggles. They will work
       | better than every remote verification scheme.
       | 
       | The only problem with this solution is that it does not help
       | certain governments build their global mass surveillence and
       | propaganda apparatus, and tech companies can't collect more of
       | your personal info to sell, and they can't make your devices
       | obsolete whenever they want.
        
         | gzread wrote:
         | Why necessarily with a password - what's wrong with the option
         | to say "only allow installation of apps suitable for under
         | 13s"?
        
           | txrx0000 wrote:
           | The idea is to let parents decide which apps are suitable for
           | their child, for each child. Password-gating app installation
           | (just like sudo on Linux) is not only easier to implement and
           | use, but also much more flexible and powerful than a fixed
           | age-based rating system.
           | 
           | It also prevents the legitimization of app store monopolies
           | because no centralized authority is needed to create or
           | enforce a rating system. And there will always be apps that
           | don't comply with a rating system out of privacy concerns (it
           | leaks the user's age, which is just an extra data point to
           | track you with), and then they'll eventually try to ban non-
           | compliant apps from running on the device completely. That's
           | what enforcing an age-based standard would take. And even
           | then it would still not fulfill its (claimed) purpose that
           | well.
           | 
           | Principle-wise, parenting should be the responsibility of
           | parents, not governments or corporations. Those large
           | organizations have their own agendas which are somewhat
           | misaligned with the individual human being.
        
         | Aachen wrote:
         | This approach makes sense to me, though I'd expand password to
         | be a broader term because people might prefer different
         | authentication methods or approving a request to install
         | software from their own device or so
        
       | cs02rm0 wrote:
       | I admire the attempt to make a logical argument against these
       | laws taken at face value, but I can't help think that's giving
       | them too much credit.
       | 
       | These laws have spread like wildfire around the world with many
       | countries and regions rolling out similar legislation within
       | months of each other, despite the stereotypical lethargy of any
       | and every legislature. That's not the work of some popular
       | uprising of parents clamouring for age verification.
       | 
       | I fear debating the merits of the argument is missing the point;
       | they don't care. They don't care about children, they don't care
       | about the argument, they just want the control.
        
       | 2OEH8eoCRo0 wrote:
       | Parents keep saying this is untenable and you guys keep telling
       | them to just parent harder. I think that dismissing their
       | concerns will lead to the most egregious worst of all worlds age
       | verification. Never tell people that their problems aren't real.
        
       | Aeolun wrote:
       | I think all this shit is silly. If I could manage to figure out
       | how the internet worked at 12, then so can my son. Or well, a bit
       | younger, but it's fine. He has at least one parent to guide him.
        
       | 3A2D50 wrote:
       | I think there is an unspoken concern among policy makers about
       | how sophisticated AI is becoming. I think they envision a
       | scenario of swarms persuasive AI bots controlled by an adversary,
       | pushing people to elect bad actors with bad policies. So the main
       | objective isn't to protect the children it is to eliminate
       | anonymity! At some point these age verification requirements will
       | go from answering a simple question to providing your ID. I'll
       | add that there is also an aligned interest with companies that
       | rely on ad revenue as they don't want to serve ads to bots!
        
         | bill_joy_fanboy wrote:
         | As if "policy makers" in the U.S. care about anything other
         | than getting re-elected and continuing to deceive and scam the
         | public.
        
       | fredgrott wrote:
       | I remember idiot lab staff telling me in early 1990s that I could
       | not install the free version of Mozilla browser on university lab
       | computers....my go to reply was can you effing read the damn
       | TOS.....free was in the very first sentence....
        
       | everdrive wrote:
       | In addition to System76's thoughtful response here, does anyone
       | have a good _personal_ plan for what to do? Possibilities I'm
       | thinking about include:
       | 
       | - Switch to a non-compliant distro. (could put me in a dead end
       | down the line depending on what happens)
       | 
       | - Find a browser that can block the API access and just use two
       | browsers.
       | 
       | - Have an "online accounts" computer and an "old fashioned"
       | computer?
       | 
       | - Switch to books and DVDs?
        
         | glitchc wrote:
         | It's self attesting. Just set your year of birth to 1970.
        
           | senfiaj wrote:
           | But if they see a weird distribution of birth dates, won't
           | they come up with even more insane regulations?
        
             | hellojesus wrote:
             | Wait until they learn about live booting, VMs, keyloggers,
             | etc. The goal of this bill is to set precedent that this
             | can be regulated by the gov. Five years down the line they
             | will complain it's not working and move to require tpm-
             | based remote attlestation to prove the software isn't
             | altered in order the authenticate with an isp.
        
           | everdrive wrote:
           | I think it depends. The OS provides an API signal --
           | presumably that websites can access. So if a site decides
           | you're lying, what happens then? For instance, 100% of bots
           | and malicious actors will lie, unless they think they can get
           | what they need by being a child.
        
             | hellojesus wrote:
             | And some adults will lie too, assuming they don't need
             | adult content, to avoid being tracked for advertisements,
             | if laws exist that prevent ad targetting on some demo, say
             | <13 year Olds.
        
       | agentultra wrote:
       | What's the plan when hardware manufacturers are legally required
       | to add an age verification TPM-like module that only enables
       | verified OS's to boot?
       | 
       | I _hope_ things won't go that way but I _do_ think it's likely
       | they will.
        
         | EvanAnderson wrote:
         | Individual ownership of networked general purpose computers,
         | and the ability to organize dissent they create, are too
         | dangerous for many powerful interests. It has always seemed
         | inevitable to me that computers will be taken away from us.
        
       | slicktux wrote:
       | I wonder how this law affects Gentoo or LFS since one builds the
       | OS..?
        
       | markus_zhang wrote:
       | The "Age verification" is simply an excuse to add tracking on
       | system software. Very soon they are going to do the same to
       | hardware too, I guess, so it is going to be very hard to find
       | hardware that is truly safe from tampering.
       | 
       | And modern hardware is so complex that it is impossible for
       | individuals to build one by their own. We are no longer in the
       | 8-bit/16-bit era. And considering the power of AI -- individuals
       | pretty much mean nothing to the elites.
       | 
       | I have never thought the Dystopian future to be so close -- I
       | always thought it would be X years away. But legislation, the
       | lawyers, are definitely very efficient on this kind of things.
        
       | junto wrote:
       | I'm tired of the U.S. nanny state with its pilgrim-religious
       | historical backdrop of prudishness, infecting everyone outside
       | its own borders.
       | 
       | Their ideas are deeply unhealthy for children and worst of all,
       | lazily shift the responsibility of parenting from the parents to
       | the state.
       | 
       | Many European countries have long had a culture of slowly
       | increasingly responsibilities and freedoms to their children
       | gradually, letting them slowly and safely test their boundaries.
       | At least the proposed EU solution (for identity) tries to prevent
       | overreach. The wholesale EU spying to "save the children", which
       | seems to be funded by the U.S. is a different topic and we need
       | to continue to fight it tooth and nail.
       | 
       | The insidiousness lies with major tech companies and their
       | pursuit of eyeballs on screens. The Internet was supposed to be
       | something we used to learn, gain knowledge and connect. They took
       | the internet over, bastardized it and made deeply addictive apps
       | and games to keep you watching ads regardless of age.
       | 
       | These age checks are just for data collection and spying to sell
       | the data to the highest bidder, which is likely governments in
       | order to control and herd their populations.
       | 
       | The reason for this is easy to understand in the context of AI.
       | In the future the only valuable asset will be a data and the
       | access to that data.
       | 
       | In the future, any app will be built, replicated, deployed and
       | maintained by AI. Apps, websites, especially B2B apps - their
       | days are numbered.
       | 
       | If my business needs a billing system tailored to my business in
       | the future, I'll describe it and have an AI built and maintain
       | it. That is not that far away in relative terms.
       | 
       | Our goal collectively (as technology advocates) is to make sure
       | that this consolidation of personal data doesn't happen. If
       | personal AI is to be built, then the user should have full
       | ownership and away from the spying eyes of groups like Palantir
       | and the NSA. They cannot be trusted. The Jews learnt that
       | catastrophically in Germany in the 1940's putting their trust in
       | a government that became authoritarian and evil.
       | 
       | What is digital will never die and what is digitally given cannot
       | be taken back.
        
         | luke727 wrote:
         | You should look into what's actually happening in other
         | countries before blaming it on "the U.S. nanny state". The rest
         | of the Anglosphere makes the United States look like a
         | Libertarian utopia. I live in the United Kingdom, and brother -
         | this is who they are. I assume Australia, New Zealand, and
         | Canada are similar. There are real problems re: "think of the
         | children" in the United States, but if you think "the U.S.
         | nanny state" is bad then you have no fucking clue how bad
         | things could be.
        
           | a456463 wrote:
           | Eh nothing what you said takes away from the parent's points
        
             | ApolloFortyNine wrote:
             | >I'm tired of the U.S. nanny state
             | 
             | When you start like this you heavily damage the rest of
             | your argument, no matter how valid, if the reader doesn't
             | agree with your premise.
        
         | TheRealDunkirk wrote:
         | You literally blamed these moves on US religious prudishness,
         | and then said that they were only about surveillance. Which is
         | it? Just kidding. We all know it's nothing more than
         | surveillance and control, and you just have an anti-religious
         | axe to grind.
         | 
         | If the US actually gave a flying FUCK about "protecting the
         | children," the current administration would be making good on
         | Trump's promise to release the Epstein files -- as now ordered
         | by a federal law passed by a overwhelming majority of both
         | houses of Congress -- and prosecuting everyone involved.
         | 
         | We see what's really going on. We can't do anything about it,
         | apparently, but we see.
        
         | muyuu wrote:
         | tbf this is not coming from the US only, the push in Europe for
         | this sort of legislation is very strong and we will see more of
         | this coming soon
        
       | mondainx wrote:
       | If this stupid bullshit existed in 1982, He is 100% correct, I
       | would have lied to use my Commodore 64 or Sinclair 1000.
        
       | VLM wrote:
       | Two meta observations about the comments:
       | 
       | 1) The issue doesn't matter much. Corporate takeover of the
       | internet caused severe damage, but overrunning social media with
       | LLM generated content is a mortal wound. Roughly the same number
       | of humans will be using social media in 2030 as currently use CB
       | radio. Remember near a fifth of the population was using CB radio
       | at the peak in the late 70s. Its too little, too late, closing
       | the barn door after the horses have left is pointless. Like re-
       | arranging deck chairs on the titanic after it hit the iceberg.
       | Once the advertisers get wise to the scam that nobody is seeing
       | their ads except bots, the problem will kind of fix itself. I
       | think TPTB want to use "protecting kids from social media" as the
       | public face of why social media will crash and burn soon to avoid
       | discussion of how LLMs actually killed it, because authoritarians
       | love LLMs and they're in charge (although seemingly everyone else
       | hates LLMs, so I'm sure this will end well).
       | 
       | 2) Most of the anti commentary reads a lot like addict speak IRL.
       | Talk to a drunk about how it would be a great idea not to drink
       | or a carb addict about how they should not eat donuts and you'll
       | get absolutely rage blasted in return for threatening their
       | addiction, which in the case of an addict, is their identity.
       | "Well it would be the end of the world if people (me) were not
       | drunk and other people (projection of me) will do anything to
       | feed their addiction so obviously no effort should be made to
       | limit addictions and it won't work anyway because other people
       | (me) will even drink mouthwash or homebrew their own moonshine to
       | get drunk" etc. Note I'm not completely against the anti's and
       | they make some very good points that should be considered, but
       | raging like an addict after their drug of choice is threatened is
       | a VERY bad look and is not helping their case at all, if anything
       | it strengthens the case against the anti's. What the pro's don't
       | understand is you can't fix an addiction externally, addicts
       | gotta addict and punishing them and making them miserable might
       | help the pro's feel superior or at least thankful they're not
       | addicted, but it never helped no one. Social media is "an ill of
       | society" and should be treated as such including sensible
       | regulation, protection of threatened groups, treatment for the
       | addicts, and some compassion and acceptance of the addicts either
       | returning to the real world or dying in the addicted world.
        
       | a456463 wrote:
       | The laws should regulate Meta, Google, Apple, TikTok, Microsoft
       | and closed source vendors. On the one hand they want monopoly,
       | but the cost of that regulation is now on opensource individual
       | people's speech?
        
       | youknownothing wrote:
       | > The only solution is to educate our children about life with
       | digital abundance.
       | 
       | I stopped reading at this point, as this is utter non-sense. I
       | mean, it's a beautiful idea, but any person with more than two
       | neurones knows that real-life doesn't work like that. We have law
       | enforcement and prisons because, despite our best efforts in
       | education, some people do go off to become criminals due to a
       | number of factors.
       | 
       | I'm not saying that the present number of laws is adequate, but
       | the solution is a different set of laws, not the complete lack of
       | them. The idea of "simply educate children and we'll all be fine"
       | is utterly moronic.
        
         | throwway120385 wrote:
         | I don't think there's a good legalistic solution to this other
         | than to delegate the work of finding solutions to a regulator.
         | No single law can be broad enough to cover everything. But
         | empowering a regulatory body to research problems full time and
         | to create solutions is probably the best approach.
        
       | hm-nah wrote:
       | Using a dead human's likeness in jest is wack. Encouraging and
       | rewarding a young person to perform this twisted act should not
       | be normalized.
       | 
       | ---system76 customer
        
         | twodave wrote:
         | Why? They're dead. They can't be offended.
        
       | hm-nah wrote:
       | Using a deceased human's likeness in jest like this is wack.
       | Encouraging and rewarding a young person in this twisted act
       | should not be normalized.
       | 
       | ---system76 customer
        
       | nickslaughter02 wrote:
       | Petition US Congress: Say no to bad internet bills
       | 
       | https://www.badinternetbills.com/
        
       | TYPE_FASTER wrote:
       | > They know more than I could have ever dreamed at that age.
       | 
       | This is so true.
        
       | jajuuka wrote:
       | This just seems like virtue signaling. It's not a plan or
       | proposed actions. Just a puff piece about how great things used
       | to be. Not sure who is making their opinions based on what
       | System76 has to say, but I guess they can now.
        
       | zerotolerance wrote:
       | The children are a distraction. They're a secondary
       | justification. Don't lose the plot. This law serves only one
       | outcome: enablement of further authoritarianism.
        
       | messh wrote:
       | "The child can install a virtual machine, create an account on
       | the virtual machine and set the age to 18 or over."
       | 
       | No, the vm is for grownups over 18.
        
       | Oleksa_dr wrote:
       | I believe it is necessary to implement this at the OS level. This
       | has been needed for a long time, because the "goodwill" approach
       | never works.
       | 
       | The introduction of age verification is something that was to be
       | expected with the growth in the use of the web, rather than
       | individual programs. But there are a bunch of ways to get around
       | it, which you do, but no one will punish you. This way, you will
       | have parental control and transfer it to the website, while
       | facilitating control over minors' access to unwanted content. And
       | this way, websites do not need to implement their own terrible
       | age verification methods. And when people complain that this is a
       | problem for parents, this is exactly what will help parents: once
       | they set the age in parental controls, programs and websites will
       | have to monitor access (following the law, not goodwill).
       | 
       | This way, access can be controlled at the first level, i.e., at
       | the OS level. There is a law, and there will be others to help
       | improve it. In the same way, you can avoid the use of identifiers
       | and, in general, face verification and a bunch of nonsense.
       | 
       | Ultimately, the responsibility lies with parents who did not
       | specify the user's age on the device. But there may be "products"
       | that ignore information from the OS.
       | 
       | Current parental controls do not solve the problem well, because
       | you have to pay for a bunch of questionable products, sacrificing
       | privacy. And it still does not protect against outdated
       | black/white lists. Therefore, the requirement at the OS level to
       | have such control and place responsibility on "products" is an
       | excellent solution in my opinion.
       | 
       | And quite an elegant one at that. Without involving any
       | government identifiers or anything else.
       | 
       | Combined with the widespread implementation of TPM, this will
       | become even more feasible.
        
         | akersten wrote:
         | I don't know how you can say this:
         | 
         | > And quite an elegant one at that. Without involving any
         | government identifiers or anything else.
         | 
         | and this:
         | 
         | > There is a law, and there will be others to help improve it.
         | 
         | > Combined with the widespread implementation of TPM, this will
         | become even more feasible.
         | 
         | Without coming to the obvious conclusion that the next step
         | will be even further down the road of tying your every action
         | back to a real, verified, trackable identity.
        
         | Aachen wrote:
         | In your opinion, who should be in charge of the OS? Can I make
         | my own (where you select an age per user upon installing the
         | machine and upon creating subsequent users), or must it be
         | government-sanctioned such that the age verification is
         | watertight?
        
       | teeray wrote:
       | > Kids are smart and easily learn how to work around
       | restrictions.
       | 
       | Absolutely. I feel like adults frequently mistake kids' lack of
       | education for stupidity. Lack of education about something is a
       | _temporary_ condition, and kids have ridiculous amounts of time,
       | energy, and motivation to quickly become expert about something
       | they care about. Particularly in reaction to "you can't do that."
       | 
       | One possibility: These laws forget that 18 year olds have kid
       | siblings. The 18 year olds need money and like everyone else,
       | enjoy the prospects of easy money. The 18-year-old has a phone
       | bill to pay. These are the makings of a black market. Kid sibling
       | acts as a broker for the older sibling's services among the kid's
       | classmates and collect a commission.
        
       | goldylochness wrote:
       | This is a very sensible statement. The legislators are out of
       | control, and are severely unfamiliar with anything related to
       | technology.
       | 
       | This is 100% about spying and information harvesting from users
       | who deserve privacy, and would be better off managing their own
       | children without the help of the government.
        
       | kwar13 wrote:
       | The good old "child protection" and "anti-terrorism"... I have
       | gotten numb to seeing either of these
        
       | lacoolj wrote:
       | Hopefully this has a domino affect across the industry and more
       | companies do this.
       | 
       | It really is just a parenting issue at its core.
        
       | prmoustache wrote:
       | If the problem was really kids safety, we would remove abductors
       | and sex predators from the internets. Not kids.
        
       | thighbaugh wrote:
       | Since these things can be made into forks with minor difference
       | relatively easily, instead of playing along with this tech
       | company + creepy government data grab because California says so
       | 
       | So much for privacy I guess, hence pulling out this protecting
       | children BS that I saw too many kids at my urban CA highschool
       | get stabbed to fall for. The fact these tactics still work, where
       | we limit our toothless privacy protections that the firms that
       | don't comply the state might eventually sue when someone with
       | more money than I presses the Attorney General, but then dial it
       | back marketing it as protecting children and people still buy it?
       | Absurd these same people work at such bleeding edge tech firms
       | but then again LLMs can do that busy work they actually are doing
       | better most of the time....
        
       | sedatk wrote:
       | > The only solution is to educate our children
       | 
       | That's correct, it's been correct for decades, and parents just
       | won't do it, not the majority at least. Either they want the
       | state to raise their kids for them, or the task is so complicated
       | and costly that they're not willing to do it.
       | 
       | But the harms continue to happen, and we're now left at the mercy
       | of tech-illiterate lawmakers.
        
         | xmx98 wrote:
         | Schools could teach cybersecurity to all children. Scanning
         | faces and real-life IDs will fail to solve crime on the
         | internet and will only succeed in destroying our privacy.
        
           | sedatk wrote:
           | > Schools could teach cybersecurity to all children
           | 
           | Yes, but is it even possible to make majority of schools use
           | a common curriculum in the US?
        
       | melonpan7 wrote:
       | I'm out of the loop on this whole debacle but can't OS providers
       | just say "Not for use in California" and be done with?
        
       | batat wrote:
       | So it's neither "yes" nor "no", but some kind of philosophical
       | note somewhere in-between a "Pop!_OS 24.04 LTS Released" and
       | "CodeWeavers tests their ARM64 compatibility on System76" that
       | isn't even linked to noticeable on the main page.
       | 
       | I mean Wikipedia hung some huge banners to raise awareness, the
       | German wiki even had a "blackout" because of "Directive
       | 2019/790", there was something similar on Reddit etc. I don't
       | expect them to leave the US market or anything like that, but
       | also I don't even know what to say, as if everyone has already
       | resigned.
        
       ___________________________________________________________________
       (page generated 2026-03-06 23:01 UTC)