13 ms·
GrapheneOS refuses to comply with new age verification laws for operating system
- onetokeoverthe 6mo ago[dead]
- echelon_musk 6mo agoHow's that gonna pan out with Motorola?
- estimator7292 6mo agoIf Motorola have a problem with it, they obviously aren't the right partner for Graphene. Graphene obviously won't want to partner with a company that immediately bends over backwards for this kind of puritanical nonsense.
- izacus 6mo agoMotorola will obviously have a problem with violating the law in several US states. Like, what's unclear here? Do you seriously say that corporations should just ignore laws which they don't like?
- fwn 6mo agoIf shipping a specific device configuration to the US is illegal, Motorola should not ship this specific device configuration to the US. I do not think our parent is suggesting otherwise. AFAIK Motorola and GrapheneOS are not merging, they are getting into a partnership. They do not have to think or do exactly the same. Apple can comply with both CCP and US demands at the same time without a problem. I am sure Motorola can adjust their services to the markets they are working in, as well.
- izacus 6mo agoMotorola is pretty much only present in US these days, why would they build a product that can't be sold in their primary market? Demanding that OSes outright violate the law because you disagree with your own elected government is pretty insane.
- HybridStatAnim8 6mo agoThey are not building a product that cannot be sold in their primary market. They are not designing GrapheneOS devices, they are improving existing devices to meet GOS requirements. There will still be an OEM OS for those devices. Preinstalled GOS devices can simply not be sold there.
- deleted 6mo ago[deleted]
- prmoustache 6mo agoCan't speak about other continents but Motorola smartphones are at least available all over Europe so your initial statement is incorrect.
- Brian_K_White 6mo agoYour arguments show a lack of the least imagination, let alone simple reasoning. There are countless ways to satisfy any regulation while still doing whatever you actually want to do. The very most obvious is simply sell the device, in the affected areas, with any sort of os that meets the letter of the law in that area. If it's also easy for the user to install something else once it becomes their property, well that's the new owner's business atthat point, Motorola did their part and complied with everything required. No one needs to demand a company violate anything. That is just a silly argument to even try to make. Calling people insane for things they never said nor even implied is what's insane.
- dmantis 6mo agoQuick google shows that in 2024 half of the Motorola phone sales were in LATAM, especially Brazil. What makes you say that the key market is the US?
- HybridStatAnim8 6mo agoMotorola wont break the law. They just wont sell preinstalled devices, if preinstalled devices was even on the table for 2027.
- HybridStatAnim8 6mo agoMotorola likely wont sell devices with GOS preinstalled in those regions.
- NotPractical 6mo agoWasn't most of the hype surrounding the Motorola partnership based on the idea that you'd be able to get a device with GrapheneOS pre-installed, boosting the legitimacy of GrapheneOS as a competitor to Google Android? Sure, "GrapheneOS adds several more supported devices" is cool and all, but it's not nearly as exciting...
- sammysep 6mo ago[dead]
- HybridStatAnim8 6mo agoNo. The bare minimum is that Motorola provides the needed baseline hardware security requirements to their future devices. Everything else is just a bonus. There could be green-boot support and/or preinstalled devices, but thats not a necessity. GOS benefits with an official hardware platform, potentially early partner access to AOSP source code, input on hardware and firmware decisions, and Motorola benefits by potentially having GOS features, better hardware security, and making tons of money from alternate OS users, GOS or otherwise.
- raverbashing 6mo agoMore likely they will just add their own age widget themselves
- CqtGLRGcukpy 6mo agoGrapheneOS also posted about it on their Mastodon / Fediverse account: https://grapheneos.social/@GrapheneOS/116261301913660830 https://grapheneos.social/@GrapheneOS/116261301913660830
- Svoka 6mo agoSeems like a pure virtue signaling: they don't sell or make hardware. It is mandated only for pre-installed operating systems, from what I understand.
- crtasm 6mo agoThey've partnered with Motorola to have it preinstalled on phones, this is in TFA.
- moffkalast 6mo agoCould just ship it along on an SD card with a single button install you do yourself. Technically not preinstalled.
- izacus 6mo agoI'm sure noone in the legal system of California would notice that trick!
- moffkalast 6mo agoWell correct me if I'm wrong but dumb laws are usually not written by people who know much shit about fuck. So it's entirely possible they wouldn't.
- tredre3 6mo agoYou sound like a teenager fighting his parents. "Technically you didn't say WHICH bed I had to be in by midnight!!!!! I was in A bed, I followed the rules!!!!" Society (mostly) works because we all agree that laws have intents. The wording is crafted as best as possible, and for the rest we have judges to shutdown lawyers trying to be a moffkalast smart asses.
- moffkalast 6mo agoCall it what you want, I still think that if the, ahem, intent, of a law is to reduce personal freedoms then it should be protested in as many annoying ways as possible. Should at least get some publicity even if it gets struck down.
- OutOfHere 6mo agoI think that malicious compliance all the way might have been the better option here. If a birth date is all that is needed, let the user enter a random one. If actual biometric verification is needed alongside, let the user also paste the code to a fake biometric validator that always returns valid. It is the same philosophy as with an app that forcibly wants an invasive permission to the detriment of the user. Let the app have the permission while in a sandbox so it sees nothing.
- HybridStatAnim8 6mo agoGiving in in any capacity is unacceptable. The GrapheneOS foundation is based in Canada and is not obligated to record this information, so they wont. They have no reason to comply, be it malicious or otherwise.
- mmooss 6mo ago[flagged]
- applfanboysbgon 6mo agoIf you want a privacy-violating OS, there are already two big options on the market. A secure OS for people who do not live in authoritarian surveillance states offers a benefit to some people, even if not all people. A third privacy-violating OS offers no value to anyone anywhere in the world.
- snackbroken 6mo agoPeople who live in authoritarian states like North Korea or California can (and arguably should) ignore the fact that GrapheneOS is illegal where they live and use it anyway.
- epolanski 6mo agoAs they stated "If GrapheneOS devices can't be sold in a region due to their regulations, so be it."
- 6mo ago
- mmooss 6mo agoThe GrapheneOS Mastodon post says, "GrapheneOS will remain usable by anyone around the world without requiring personal information, identification or an account." https://grapheneos.social/@GrapheneOS/116261301913660830 https://grapheneos.social/@GrapheneOS/116261301913660830 That raises the issues that GrapheneOS needs to solve, which may require more creativity than bold, somtimes combative statements. If GrapheneOS doesn't comply with laws and regulations then they will sometimes be banned or restricted. If that happens, they may not be "usable by anyone around the world" for long. That doesn't mean they have to capitulate or sacrifice security. They can find creative solutions, some of which are suggested here. The first step is to carefully read the spec to determine what is necessary, then talk to someone like the EFF, and find a way forward.
- notrealyme123 6mo agoThe problem is the spirit of the law, not the word.
- test7rocks 6mo agoBetter would have been a statement "If GrapheneOS devices can't be LEGALLY sold in a region due to their regulations, so be it." . I hope that is what they meant, leaving open the possibility they'll have a secret drone delivery squadron bringing GrapheneOS phones in to Brazil and other equivalent places. Also it would be nice if, where Graphene has partnered with hardware manufacturers, then said hardware sellers could issue a statement like "$Manufacturer promises that in regions where GrapheneOS is illegal we'll leave the bootloader unlocked, if users choose to break local legislation then that is on them" and furthermore a statement like "$Manufacturer fully swears on all honour possible that in any regions which ban unlocked bootloader devices then, oops, we found that if you short pins 3 and 8 of the third chip on the left together at any time during booting you'll permanently unlock the bootloader and absolutely nobody is allowed to know that. Which is why we've posted this on every social media channel. Afterall, all our users need to know that they're not allowed to know that the bootloader can be unlocked by shorting pins 3 and 8 (third chip on the left) with anything less than 20 ohms (nobody must know that a paperclip would do for this)". Nonetheless: Well done GrapheneOS!!!!!!!
- 6mo ago
- nout 6mo agoIn the meantime systemd already added handling for Age to the system bus. Next step is to add your race, then income, then who you voted for...
- joe_mamba 6mo agoWestern tech direction in the last 5 years: https://www.youtube.com/watch?v=nXL-r8deB5o https://www.youtube.com/watch?v=nXL-r8deB5o
- gruez 6mo agoIf you think that's bad, just wait till you see eastern tech.
- 6mo ago
- endofreach 6mo agoI know it's gonna be a very unpopular opinion. I do like, appreciate, respect & admire that they are ready to die on a hill. I just don't think it's the right hill. I do not have an issue with the legality of it. Rather I think age verification is actually not bad. Sure i see the potential danger. But there is potential benefits, that'd counter the danger, by a lot. In different times, i might have argued differently. I'm not saying it's not worth protecting the world you deem worthy of protection. But no matter what that world is to any of you. The one we all share is changing for sure. Uncontrollably fast. And many things are gonna change. And many things won't matter that much anymore, if we actually end up going where we're headed. I mean a this is just a super small part of it all, but i assume in this specific case, for graphene, it's a battle for privacy... and they're right. But we're still going into a future where we got 5,10,20,30 more years of "AI", even just keeping the same level of overall sophistication for most, but costs decreasing immensely... I don't know about you, but I don't think the ways we protect our privacy can be unaffected, already because we're going to learn all new aspects about which data is private. Just out of practicality. Extreme example: but if generating hundreds of obscene deepfakes of any person as easily as taking a photo with your iPhone... ah, i can't keep having this discussion, i hope i am just an insane moron who is wrong. But, just to be sure: instead of arguing if we should close the windows on the train that's burning, or leave them open, as some are smart and others need help, let's just get off the fucking train. And yes of course. One might argue (I actually would), we should not start implementing laws like that or start making personal information a requirement to digital access. But this might be the first step to a different future, or not. As i said, who cares where the train is headed. It's burning and nobody even really wants to be on it. Let's please get off the train. Not saying the battle is lost. I have tried working on something because I still have great hope. But someone seriously must act. I tried, getting off the train. Or at least start standing up from my seat. Realizing it's not that easy to get off. It's embarrassing, but i can't even get off the train by myself... i tried anyway... but here i am, sitting again (currently on the floor, lost my seat, damn...)... i have been building something for the past 2 years. Well, trying to build something, an attempt to change course... ruining my life over it. And currently i failed, before i even got to a point where my prototype or any of the theoretical work even remotely represents the vision. But maybe i just learned, i was wrong about all of it. I hope i'll make it back being able to afford working on it and someday a way to make enough money to pay smarter people than me to join. But currently, it's insane for me for me to even dare dreaming about that. I have really dug myself a hole. Next time, it should at least be a hill... So in the meantime: can people like the dudes & dudiñas from graphene please chose a wiser battle. If just some of all these people got together & worked on getting off the train, instead of working on things that seem meaningful now, but wouldn't even be considered worthy of being mentioned in the future... we'd have a shot. Damn. I still just can't accept it, even though i've literally lost everything believing that. And i am ashamed so deeply believing in what i saw, and in friendly moments still see, as a future... thinking i could change it, without changing myself... but please god, in the end, let me not have been just bonkers, but convicted. (As if that, would be, any different).
- stego-tech 6mo agoGood on them. Devices shouldn't collect any extraneous data by default other than that needed to fulfill a feature a user consciously selects, and that includes this stupid age verification spyware regimes are pushing. An adult had to pay for the ISP connection; that's the extent of age verification needed. We shouldn't be demanding adults expose their identities to for-profit entities and surveillance states, so much as mandating for-profit companies make parental controls easier to use, more effective, and stopping them from harvesting data on kids in the first place. Not every corner of the universe needs to be baby-proofed; we just need to build a society where parents are enabled and supported to be parents, rather than outsourcing such a critical role to strangers and/or devices so they can get back to work.
- pxeboot 6mo ago> An adult had to pay for the ISP connection In many countries, it is still possible to buy a prepaid SIM without any ID.
- AlexandrB 6mo agoAnd if such a country wants to keep kids off of the unrestricted internet they should just ban that practice.
- Symbiote 6mo agoAnd HN would complain even more about the loss of privacy.
- stubish 6mo agoFewer and fewer countries. I think none of the countries I've been too where I've purchased a SIM without ID allow that anymore. It is required to try to limit purchase by scam call centers and to enable phone number portability.
- wolvoleo 6mo agoSo, they can change that if they want.
- nothrowaways 6mo agoApple should be championing this.
- enoint 6mo agoThey should be proactively marketing the best parental controls on the market.
- DebtDeflation 6mo agoAge verification at the OS level makes no sense to me. Most households aren't going to have a separate device for every family member and so you will end up with a tablet or computer set up by one of the parents (and thus having their age stored) that will be used by both parents and children. Likewise, people generally won't create a separate account for every potential user.
- izacus 6mo agoWhat are you talking about, most households give personal phones to their children, especially teenagers. Laptops aren't rare either.
- bradfa 6mo agoI suspect there’s quite a difference between what most people do and what most HN commenters do.
- dathinab 6mo agoI frequently see comments which would have made sense in the past (e.g. early 2000th) but kinda aren't fully reflecting reality anymore it's as if humans have a tendency to make up their mind/world view in their younger years and then tend to kinda stick with it/only change it slowly as long as no big live changing events happen
- zamalek 6mo agoGive the kid a device that is age-controlled. No need for all devices to support it.
- pas 6mo agothe law is there because parents are fucking clueless unprincipled whining crybabies, who need a lot of support, and sometimes that includes a bit of pushing ... or who knows what problem is this supposed to fix. orphans buying phones? kids buying secret phones behind their parents back?
- drnick1 6mo agoThis is absolutely the right stance to take against such stupid mandates.
- cadamsdotcom 6mo agoThis is excellent; silly laws on the books should exclude countries from access to things. Unfortunately it’s not enough because there’s also a need to work to get the laws repealed AND stop the endless attempts to bring them back.
- arbirk 6mo agoWe are back to printing books, boys
- idatum 6mo agoCan someone catch me up how FB et al are not the ones responsible for age verification? Is it lack of something similar to PKI for identify verification?
- whynotmaybe 6mo agoIf we go back a few years and analyze the porn magazines that are sold in a gas station, it's not up to the magazine to ensure that the "reader" has the legal age. So we delegated the responsibility twice, first the gas station attendant must check the age of the buyer and then, the buyer should check the age of any reader. So now, who's the "gas station attendant" in our situation?
- pas 6mo agobecause there are other sites/apps online too, and it's better to decouple the "obtaining the verification" and the "presenting the verification" and if sites and apps don't need to be in the loop for this they can't end up leaking all over the 'net
- hackinthebochs 6mo agoWhy would you want every site on the internet to traffic in government IDs? This is by far the least bad out of all possible ways to implement age checking. The benefit of this is that it can short-circuit support for more onerous age verification. The writing has been on the wall for some time now: the era of completely unrestricted internet is coming to an end. The question is how awful will the new normal be? This implementation is a win all around, a complete nothingburger. We should be celebrating it, not fighting it tooth and nail. The tech crowds utter derangement over this minor mandate is truly a sight to behold.
- fc417fc802 6mo ago> This is by far the least bad out of all possible ways to implement age checking. Not quite. The least bad (that I'm aware of) is to mandate RTA headers (or an equivalent more comprehensive self categorization system) and to also mandate that major platforms (presumably OS and browsers, based on MAU or some such) implement support for filtering on those headers. But sending a binned age as per the California law is the next best thing to that.
- hereme888 6mo agoso... just sell a phone with a script prompts the user to install the OS, and it auto-verifies hashes, can't be bypassed, etc. Is that too simplistic a solution?
- HybridStatAnim8 6mo agoI highly doubt that would work but there could be, say, a card in the box with the link to the webinstaller and the webinstaller can be made even easier.
- h4kunamata 6mo agoWe expected no less from GOS project. systemd which was already in hot water over because the problems it creates over service, this was the last drop to get folks dropping systemct altogether.
- calgoo 6mo agoi wish, but its not easy. So much of the application ecosystem has now been adapted or built around systemd and its other services. While some tools might still work with dbus alternatives, its quite clear that its harder and harder to use linux without it. Gnome is one example where even the dbus replacements wont work anymore. Others will follow; ironically Ubuntu is doing its own thing like usual, using systemd and resolved but not some other parts. However, im not really holding my breath there, as they usually end up adopting the "standard" way; now in the hands of companies like IBM.... I think the only option really at this point is to move over to BSD, but we face other issues like GPU drivers etc. The same people that worry about systemd probably also worry about AI, so if they want to be able to use it, it needs to run locally. The 3rd option is to move away from general computing, and start building esp32 powered tools, where we can own the fulls stack. Dedicated digital tools for specific purposes. Personally, this sound like the best option, taking into account that we have almost lost the battle for open OS on mobile devices. We need to get away from the giant US corporations for the majority of our computing, and only interact with them when absolutely necessary. A grass roots computing moment basically.
- CommanderData 6mo agoWill a record be kept associating a device to a person through the verification system? What's next, browsers sending this to $website every time you need to post a comment on the web.
- pull_my_finger 6mo agoI wonder how things like computers at the library will work. This whole thing is just so stupid and intrusive. I can't imagine anyone will benefit from this except advertisers, doxxers and Big Brother.
- wolvoleo 6mo agoYou're not really going to be watching porn at the library though, just saying
- hackinthebochs 6mo agoIn fact, many libraries have computers sectioned off in semi-private areas exactly for this reason...
- wolvoleo 6mo agoAre you sure that's a library? I mean we have places here like that where you can insert some coins for a private viewing cabin but we don't call them libraries :)
- pull_my_finger 6mo agoAge checks certainly won't be restricted only to porn sites. Tons of sites have 13+ ToS like Facebook & the various other social sites, Discord too iirc. The reason people are so adamantly against this proposal is that it ties the machine to a particular identity. So how does a public computer work? If age verification is implemented at the OS level, can we even have public terminals? All those interfaces in stores that are just a website in kiosk mode? Would they be illegally representing end users if it's set as an adult on a master account/login? This proposal is so stupid and poorly thought out it's alarming.
- Dylan16807 6mo agoHaving an age setting is not verification. Having an age setting is not verification. I hate the articles that lump everything together.
- wolvoleo 6mo agoNo but it is one of the building blocks for a verification system.
- Dylan16807 6mo agoIt could be used in one. But it would need so many changes that it doesn't advance that kind of thing by much. It also gets sites to stop doing their own invasive verification systems.
- wolvoleo 6mo agoI still view it as a step in the wrong direction. And it sends a message that this kind of law is ok.
- Dylan16807 6mo agoThat depends on what kind of law you view this as. As a parental control like the V-chip (but hopefully with a higher percent of parents using it) it's nothing new.
- wolvoleo 6mo agoIt's not new but that was a dumb and irrelevant technology too. And didn't last for that reason (easily bypassed, not working with modern tech). Just like the clipper chip that was supposed to spy on us.
- margana 6mo agoNot just "could be used in one", but age verification is the raison d'être for the introduction and existence of these fields. Not sure why some people pretend otherwise when it is obvious.
- jeremie_strand 6mo ago[flagged]
- HybridStatAnim8 6mo agoGrapheneOS protects everyone. Many normal and average users use GOS, and if minors seek to use it to protect themselves, thats great.
- IAmNeo 6mo agoAge verification is stupid, parents the actual parents need to look after their kids and what they're doing on the computer. If I hadn't been able to sit down at my Atari 800 computer with 48 KB ram, as I pleased after school everyday since the second grade, I wouldn't be the person I am today I wouldn't know as much about computers and I would not be a tech savvy person at all. These age verification measures are strong handed nanny type rules and laws that have no place in the household, it is not the government's job to raise children it's the parent's job. You're going to raise a whole generation of dummies.