8 ms·
This headline is misleading. The California law requires that the OS store and provide the age bracket. It does not require that any verification take place. I
by NoraCodes 7mo ago
This headline is misleading. The California law requires that the OS store and provide the age bracket. It does not require that any verification take place.
I am not arguing that this is a good idea, but it is simply false that the law requires that Linux 'check kids' IDs before booting'.
The New York law is worse, and should be opposed, but the article only mentions it at the end - and even then, we actually don't know what the verification mechanism would be. I've heard a proposal that "age verification passes" be sold at liqour stores and porno shops, for example, who already seem to do an acceptable job of checking ID without destroying people's privacy.
- g947o 7mo agoSure the headline is misleading. But anyone from 10 miles away could see what's going to happen next.
- gzread 7mo agoAre there any other places this argument could apply or is it specifically this one? Like if I said "Yes, the university reserves the right to expel students who defecate on the teacher's desk. But we all know where this is going." that'd be pretty crazy, wouldn't it?
- xboxnolifes 7mo agoIf universities didn't have the right to expel students at all and that was proposed, and they had a history of turning small law into totally encompassing law, I would fairly confidently say that the university is on the path to obtain the ability to expel students for any reason it seems fit. So yes, we all know where this is going.
- gzread 7mo agoDo open source operating systems have a history of turning small law into totally encompassing law? I guess systemd.
- xboxnolifes 7mo agoThe one imposing this is not open source operating systems. Its government.
- nszceta 7mo agoThere is no limit to the power grab. The only acceptable thing to do is to dig the trenches before it gets worse.
- EGreg 7mo agoThe trenches will eventually be overwhelmed regardless. Once the government has AI and sensors, it will mandate its ubiquitous use. For minors, we have this lovely law coming in NYC: that will broadcast to everyone that you’re a minor: https://www.nysenate.gov/legislation/bills/2025/S8102 https://www.nysenate.gov/legislation/bills/2025/S8102 But let’s talk about around the US. For example, all cars manufactured in 2029 and onward will be required to have a built-in alcohol detector / breathalyzer and to shut down and not let you drive if they detect your blood alcohol level is too high: https://www.clear2drive.com/the-pass-act-explained/ https://www.clear2drive.com/the-pass-act-explained/ And in 2027 — next year — new cars are required to watch where you are looking, how much you’re blinking or nodding and alert authorities if you aren’t alert enough: https://www.gadgetreview.com/federal-surveillance-tech-becomes-mandatory-in-new-cars-by-2027 https://www.gadgetreview.com/federal-surveillance-tech-becom... And it’s not just the US government. That phone in your hand? Governments have mandated tha all vendors preinstall spy software, filters and apps on it, that are not removable: https://www.aclu.org/news/privacy-technology/government-mandated-software https://www.aclu.org/news/privacy-technology/government-mand... Also these phones no longer shut down when you shut them down. They continue operating and sending telemetry so the government can eventually know where they are at all times. https://android.stackexchange.com/questions/228682/why-do-cell-phones-dont-really-turn-off-unless-battery-removed https://android.stackexchange.com/questions/228682/why-do-ce... This is in addition to the interlinked CCTV cameras that are the norm in various cities (eg in the UK), new Flock cameras in US, etc. But the government doesnt even need Flock or Ring to cooperate. They have plenty of their own housing programs to install thousands of cameras to spy on citizens 24/7, and can now deploy AI to sift through it all. Here in NYC we already have the lovely Domain Awareness System: https://nysfocus.com/2025/08/11/eric-adams-nycha-nypd-cameras-surveillance https://nysfocus.com/2025/08/11/eric-adams-nycha-nypd-camera... To sum up: the government can know what you’re doing at all times, with sensors in your car, mandated apps on your phone, cameras on your street, and soon, mandated telemetry sent by your operating system. Caretakers of kids are required to report anything to authorities and not let parents know, in case the department of child services might need to know. Every child is required to be vaccinated too, with lots of different vaccines. I wouldn’t be surprised if toilet plumbing in every apartment in the future will be required to install a test for what you’re eating or drinking, to catch diseases early and for public health. Looks like this short film is a documentary about our future, except with AI doing the snitching instead of humans: https://www.youtube.com/watch?v=vJYaXy5mmA8 https://www.youtube.com/watch?v=vJYaXy5mmA8
- alphabetag675 7mo agoWhen we are installing docker repositories on my Rockylinux installation on 100 nodes at once, should we need to manually put an age of the person who is running the script somewhere in the process? Will docker be forced to prevent me from downloading its packages if I do not transmit the age in a header?
- wongarsu 7mo agoThe California law only stipulates that there's an "accessible interface at account setup" to set the birthday or age at account setup, and an interface to query the age bracket. Plus the crap for "application stores" I don't think it's a very well thought-out law. But realistically this will end up as setting some env variable for your docker containers to assure them that you are 99 years old. And yes, maybe transmitting a header to docker hub that you are 99 years old. Probably configured via an env variable for the docker cli to use. It's stupid, but nothing a couple env variables wouldn't comply with The real issue is when the law inevitably gets expanded to get some real teeth, and all the easy workarounds stop being legal
- whywhywhywhy 7mo agoSo once my application is running I can just keep querying an age bracket until it flips and then I've successfully determined a date of birth.
- bee_rider 7mo agoThis is a neat attack (in that it is obvious and a big flaw but also it makes sense that the lawmakers wouldn’t have thought of it), but it would only affect users who have an age-bucket transition while your application is running, right? Edit: as folks have pointed out, the attacking application doesn’t actually have to be running while the age-transition takes place. The attacker just has to have logs from before and after the age transition, and then they can narrow the birth-date down.
- 7mo ago
- soulofmischief 7mo agoHave you heard of the slippery slope? A cornerstone of American political philosophy? Arguments like this one are why the authoritarian ratchet continues to turn unimpeded over time.
- wat10000 7mo agoWhat "arguments like this one"? It isn't an argument at all, it's just pointing out some actual facts. If your slippery slope argument can't withstand a simple statement that something is at the top of the slope, it's not much good.
- slopinthebag 7mo agoAuthoritarianism rarely happens overnight, it happens one step at a time and at every step the useful idiots [0] exclaim "It's just one step! What's the big deal? Stop overreacting!". Next thing you know you've walked 100 miles and it's too late to turn back. [0] https://en.wikipedia.org/wiki/Useful_idiot https://en.wikipedia.org/wiki/Useful_idiot
- wat10000 7mo agoThe comment you replied to only said the first "it's just one step" part. You're imagining the rest. Are we not even allowed to make factual statements when something is, in fact, just one step? "It's bad to factually describe what's happening because it will get worse" is a terrible way to make your case.
- soulofmischief 7mo ago> I've heard a proposal that "age verification passes" be sold at liqour stores and porno shops, for example, who already seem to do an acceptable job of checking ID without destroying people's privacy.
- gzread 7mo agoThis is not being supported because the size of the step is small, but because the step itself makes sense. The slippery slope argument says that open source software is a stepping stone to a world where all commercial activity is banned. Should we therefore oppose open source software?
- m132 7mo agoFrom the article: > These laws can, and almost certainly will, get worse. New York's proposed Senate Bill S8102A explicitly forbids self-reporting. The state Attorney General will decide how to enforce it. For example, to use Linux, you might need to submit a driver's license.
- david422 7mo agoYes, I can see morons writing laws like this, and then it means that guys with guns can enforce it if they want to.
- LtWorf 7mo agoIt's funny that they want to do these checks in a country where even the checks for voting are very iffy.
- quesera 7mo agoFWIW, there are vanishingly few problems with improper voting in the US, and the extremely unusual occurrences are mostly PartyB voters trying to "counteract" the imaginary PartyA violations. Anyone who tells you differently is lying or ignorant.
- linksnapzz 7mo agoIf there's no problem w/ improper voting, then why would anyone object to measures intended to verify that the proprieties involved are being followed?
- duskdozer 7mo agoIf it were out of genuine concern for verification, those supporting it would want to ensure that all citizens are able to easily, quickly, and cheaply get ID. That is not the case, however.
- quesera 7mo agoBecause 10% of US citizens (legitimate voters) do not have the forms of ID required in these proposed laws, and it can be expensive and time-consuming to get those forms of ID which are not otherwise required for their lives (QED), and they might not do so strictly for voting. Some people think disenfranchisement is bad. Others see it as useful. Specifically, PartyB thinks those people with inadequate ID skew toward PartyA voters. This has been the accepted wisdom for decades. So they are incentivized to make it harder for them to vote. Interestingly though, PartyB might be wrong about the current population. PartyA, and those against disenfranchisement and imaginary crises in general (I count myself in this third group), do not want to blow up centuries of precedent especially if the consequences are likely to be undemocratic and unfair.
- iamnothere 7mo agoWho is paying FOSS devs who will be implementing this? Who is providing them with legal indemnification since they are now apparently subject to fines for a fucking hobby if they do it wrong? Who is making CA the only jurisdiction instead of the myriad contradictory laws all over the place? Who is stepping in to make sure no additional legislation comes across regulating how FOSS has to include backdoors or weaken encryption?
- alephnerd 7mo ago> Who is paying FOSS devs who will be implementing this Most Linux maintainers are employed by Google, IBM, Facebook, and other similarly sized organizations. > Who is making CA the only jurisdiction instead of the myriad contradictory laws all over the place The US is a federal system. It's part of our checks and balances. > Who is stepping in to make sure no additional legislation comes across regulating how FOSS has to include backdoors or weaken encryption No one. This is why organizations with actual security requirements do their own dependency checks.
- iamnothere 7mo agoLinux is the kernel, it has nothing to do with this. The law apparently seems to target the packager/distributor of the distribution. Many small distros are hobby distros! > The US is a federal system. It's part of our checks and balances. Nonsensical answer. Different states are passing different requirements that often contradict each other. This is going to be a nightmare. > No one. This is why organizations with actual security requirements do their own dependency checks. So you’re saying that we should expect those laws too? Because before now “code is speech” has ruled, and the US government have not been able to be so invasive about how computers should work. If this is the direction we’re headed in, we need to organize and fight like hell.
- alephnerd 7mo ago> Many small distros are hobby distros... Then region lock. You don't have to support California or NY or ... > Different states are passing different requirements that often contradict each other. This is going to be a nightmare Create regional feature flags or region lock. It's a solved problem. > So you’re saying that we should expect those laws too They already de facto exist contractually speaking. > Because before now “code is speech” has ruled, and the US government have not been able to be so invasive about how computers should work The mindset around tech regulation shifted after the 2016 election and Jan 6th. The maximalist tech civil libertarian view on privacy was an anomaly from the late 1990s to early 2010s when tech was viewed as inconsequential. The 2016 election and Jan 6th showed otherwise. --- The overlap between Linux daily drivers and "voters who can flip an election in California, NY, or <insert_state_here>" is nonexistent. This also appears to be a front-run at reducing the risk of an Australia-style regulation being proposed. Edit: can't reply > Europe realized this with their new infosec liability regulations European organizations (from private sectors to government agencies) sidestep this by contractually mandating SBOM and dependency requirements. You end up with the same result, but it's essentially regulated via contracts instead of the law. > Expecting volunteers to dump time into compliance is ridiculous. Not because they oppose the idea, but because huge swaths of the internet run on people doing something for free -- and they'll just do something else if governments begin threatening them That's a decision a lot of governments and organizations are fine with. OSS where maintainers are hired by sponsor organizations is already the norm, and government-backed OSS is becoming increasingly common in the EU and much of Asia. Hobbyists who don't wish to comply can region gate within their license - that solves your liability risk and will keep regulators happy.
- hamdingers 7mo agoThe initial mislead comes from the bill[1] where it's described as "verification" in the name and digest but nowhere in the law itself. 1. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260AB1043 https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...
- RobotToaster 7mo ago> It does not require that any verification take place. Yet
- rmast 7mo agoAge verification passes? Now not only would extra costs be added for users to verify their age, that sounds like an age verification passes is a form factor that could easily be resold to someone else.
- shadowgovt 7mo ago> liqour stores and porno shops, for example, who already seem to do an acceptable job of checking ID without destroying people's privacy The difference being, of course, that as an adult one can simply refrain from frequenting a liquor store or porno shop if one chooses not to. It's not practical to refrain from using a computer while participating fully in modern society. The UN has indicated Internet access to be a human right.
- slashdev 7mo agoThe register is a satirical publication.
- phendrenad2 7mo agoAnd where is the information about a person's age stored? On their ID. They're just checking ID on the honor system (for now!)
- a456463 7mo agoOh really? What else should it snitch on me next?
- gzread 7mo agoYour wallpaper image and everything on your home directory
- rebolek 7mo agoHow is it misleading? It says "nanny state vs. Linux", in second paragraph says "several states in the US", then mentions EU and Brazil and California is mentioned first in seventh paragraph. It's not about California.
- marssaxman 7mo agoOne thing will lead to another; if we let them have this now, they'll demand verification next - "closing the loophole", some ambitious politician will claim.