6 ms·
Age verification on Systemd and Flatpak
- lschueller 6mo agoQuite spooky imaging that apple might create by that a fully verified pii database for half of gen z and every coming gen users
- mtndew4brkfst 6mo agoWhy would it be more spooky if Apple in particular did this vs all the other hardware vendors that ship a pre-installed OS?
- stephbook 6mo agoThey know this about every user. They have access to every message you send. They know where your device is at every time of day. Your name is all over the entries in your wallet, be they tickets, SF bus ticket or.. your credit cards.
- jmclnx 6mo agoThis is a no win situation and I think systemd is making this change too early. But I have read that field is optional. But my main concern with this is applications like Firefox will eventually require this systemd age specific field and a standard systemd function to call. That means this age field will need to be populated and thus locking out the *BSDs and non-systemd Linux. If that happens, this makes the systemd critics 100% right, systemd is being forced upon all distros by various upstream applocations.
- Bender 6mo agoMy gaming machines that I do not browse the web with have systemd (CachyOS) but my daily drivers do not. Should a website lock me out because I don't have some age API then in my view the problem has solved itself. The website has effectively blocked itself without me having to given the one and only correct way to age gate a site in my view is with the RTA header [1] that would trigger parental controls if optionally enabled on ones device. Every other path that involves exchanging data whether verified or not, anonymized or not can only lead to future evil shenanigans. [1] - https://news.ycombinator.com/item?id=46152074 https://news.ycombinator.com/item?id=46152074
- logicchains 6mo ago>But my main concern with this is applications like Firefox will eventually require this systemd age specific field and a standard systemd function to call. That means this age field will need to be populated and this locking out the *BSDs and non-systemd Linux. The risk is real, and the solution is to move away from systemd now, not wait until it's too late. Whatever conveniences it brings over other init systems are certainly not enough to justify giving up online anonymity forever.
- skydhash 6mo ago> Whatever conveniences it brings over other init systems You see people rave about the greatness of systemd, then they turn to deploy their applications using Docker and some s6 config.
- 12972891 6mo ago[dead]
- nout 6mo agoIt's interesting that the package managers become choke points that can be used for government overreach. Luckily Linux is open source so I expect there will be options that just don't do this from principle. Otherwise my Intel NUC server with Debian is 2 years old, so I expect the honest age would be 2 years? I may have parts for some old PCs to put together that could get adult software I guess...
- awesome_dude 6mo agoFor me, the big issue is going to be mobile devices (phones, and tablets to a lesser degree) I've already had it up to my back teeth with Google arbitrarily updating things such that the on/off button was hijacked, preventing me from switch the device off, instead triggering an interaction with freaking Gemini (what sort of IDIOT thought doing that to a device was a good idea) I'm seriously trying to find a way to no longer run Apple or Google OS based phones - which puts me in the "Linux" or "Graphene" market
- nout 6mo agoI think more folks are now interested in the "Linux" or "Graphene" market and since the phone hardware development is not as rapid as it used to be (from 1yr cycle to more than 2yr cycle), I think this gives more stability and wiggle room for folks to do Linux and/or Graphene. I'm patiently waiting for what happens with the Motorola + Graphene integration/plan. If they provide good hardware + preinstalled Graphene, I'd buy it.
- Shank 6mo agoIt seems incredibly silly to me that this is being rushed into systemd and other linux components. I understand Apple making changes, and even Canonical, but systemd is not run by one corporation and there is no reason to adhere to a badly written law. Why play along with the charade? If root is root, the "age verification" field does not make any sense. Why are these changes being made on a worldwide basis when the laws that have been introduced are a relatively small fraction of the world? California isn't going to go after individual systemd maintainers. Will California go after Torvalds? I doubt it. Apple? Surely, but this is, quite frankly, a ridiculous thing to even suggest for inclusion into these setups.
- nine_k 6mo ago> systemd is not run by one corporation Two corporations, e.g. Canonical and Red Hat, might suffice. I hope everybody remembers how systemd was thrust upon the community by having Gnome largely depend on it. This was mostly done by efforts of Red Hat, and that sufficed.
- ChocolateGod 6mo agoIIRC all that's been done is a field has been added to store the user date of birth and a protocol that can be used to retrieve said date. That's it.
- Cyph0n 6mo agoOkay, but why do this now? If it’s such an important feature and unrelated to the barrage of legislation, why was this not implemented a few months or years ago?
- jcgl 6mo agoBecause someone came with a pull request for this; this additional field was meant to support a feature in something else they were working on (an xdg portal). It was a simple PR that addressed a need that the programmer had. And it was accepted.
- 6mo ago
- RcouF1uZ4gsC 6mo ago> Will my system believe me? And how about their system, whoever “they” are? If not, then what else will I need to do to prove my birth date and age? Who will check if root can’t be trusted? How will they check? If they ever seize your computer, they can probably also tack on computer fraud charges
- ekr____ 6mo agoOP is certainly right that a lot of this legislation is written in ways that are hard to interpret and that often seem like they would have undesirable side effects even under the assumption that the basic idea is good (whether that's actually true is a whole different question). In the specific case of CA AB1043: (1) Systems are required to ask the user for their age and just trust whatever they say (2) Applications are required to query the system for the user's age range. Other enacted and proposed device-based age assurance mandates have different properties. This post goes into quite a bit of detail about the various points of concern: https://educatedguesswork.org/posts/device-based-age-assurance/ https://educatedguesswork.org/posts/device-based-age-assuran...
- AnthonyMouse 6mo ago> Systems are required to ask the user for their age and just trust whatever they say If you're going to do anything like this, this is the thing they actually get right. It removes the inconvenience, privacy invasion, forced use of corporate verifiers with perverse incentives, etc. Meanwhile if the user is actually a child then their age is set by their parent. > Applications are required to query the system for the user's age range. This is classic legislative stupidity. Applications are required to query the user's age range even if they contain no age-restricted content? Brilliant.
- ekr____ 6mo ago>> Systems are required to ask the user for their age and just trust whatever they say > > This is the thing they actually get right. It removes the inconvenience, privacy invasion, forced use of corporate verifiers with perverse incentives, etc. Meanwhile if the user is actually a child then their age is set by their parent. Well, maybe. For instance, if a child buys their own device they could set the age to whatever they want. >> Applications are required to query the system for the user's age range. > > This is classic legislative stupidity. Applications are required to query the user's age range even if they contain no age-restricted content? Brilliant. Note that AB1043 doesn't actually impose much in the way of requirements about age restricted content. Rather, the way it works is that the developer is then assumed to have "actual knowledge" of the user's age (See 1798.501(b)(2)(A)) and then has to behave accordingly in other age-restricted contexts.
- pgt 6mo agoFellow software engineers, what are we doing here? Why are we letting the EU / UK define the future of software?
- looperhacks 6mo agoMaybe carefully read TFA - the age verification came from a Californian law
- DrinkyBird 6mo ago1. The UK and EU are rather large markets that they don’t want to miss out on. 2. There are software engineers in the UK and EU. 3. This specific implementation by Apple is not actually required by any UK or EU law, to my knowledge. 4. This specifically is or will be required by the laws of some US states and other countries.
- kgwxd 6mo ago1 Since when is Linux about marketing? And who is "they"? 2 Devs for companies can start working with proprietary OSes for the businesses they sell their soul to. 3 Who cares what apple is doing. 4 And systemd should not be liable for upholding any of them.
- duskdozer 6mo ago"Apolitical" technology
- hanisong 6mo ago[dead]
- supliminal 6mo agoIs 9front impacted?
- dwedge 6mo agoIf these laws come in in their current form, it might be worth archiving ISOs like 9front because I'm sure at least one project will just close its doors
- looperhacks 6mo ago[flagged]
- htx80nerd 6mo ago[flagged]
- tomhow 6mo agoThis is not an acceptable comment on HN. It breaks several guidelines: Be kind. Don't be snarky. Converse curiously; don't cross-examine. Edit out swipes. Comments should get more thoughtful and substantive, not less, as a topic gets more divisive. When disagreeing, please reply to the argument instead of calling names. "That is idiotic; 1 + 1 is 2, not 3" can be shortened to "1 + 1 is 2, not 3." Please don't fulminate. Please don't sneer, including at the rest of the community. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- cmckn 6mo agoWhy does it exist?
- skywhopper 6mo agoBecause some implementers will need or want to use it.
- dwedge 6mo ago[flagged]
- dmitrygr 6mo ago>This systemd change is absurdly overdiscussed. It's a field for a number, no verification, no enforcement for anything. > And no, I do not accept the slippery slope fallacy. aka: $OBVIOUSLY_DUMB_OVERREACHING_EASILY_ABUSED_POLICY is absurdly overdiscussed. It's $ABSURDLY_REDUCTIONIST_VIEW. And no, I do not accept $HISTORICALY_VERY_LIKELY_OUTCOME fallacy.
- tombert 6mo agoI've been running NixOS for awhile, which is very firmly integrated with systemd. I wonder if it's time to try something like sixos or Guix SD.
- htx80nerd 6mo agoArtix (Arch) and MX Linux (Debian) are very nice
- tombert 6mo agoOh I only use distros that are declarative like NixOS. I've run Arch in the past and I liked it just fine, but they are ultimately different than how I like running my computer.
- Cyph0n 6mo agoSetting aside the ridiculous nature of this move towards OS-level verification, NixOS (and Guix) is the last distro to worry about when it comes to age verification. Why? Given the nature of how NixOS works (config-driven), the maintainers have plausible deniability: if push comes to shove, they can shift the burden to users and have them enable the age verification service as part of their NixOS config.
- iamnothere 6mo agoAt least NixOS has signaled disinterest in this, and as an NL project it’s beyond CA legal reach. They also disable userdb by default, so this is irrelevant unless you enable it.
- pharrington 6mo agoThis is actually nuts. You can't even constantly implement "age verification" at the system level in a way that makes sense across world cultures. The only sane way to do this is you were playing along with arbitrary legislative age-gaters would be to add a generic "additional user info" blob to the account fields, if it didn't already exist.
- sunshine-o 6mo agoThe story reads like an april fool. For root to manage privileges in an OS, isn't a group the most straitforward way? Can't flatpak read the groups of an user?
- ur-whale 6mo agoCarry permit to operate a compiler is in our near future.
- userbinator 6mo agoRichard Stallman's "Right to Read" is worth reading again, because it portrays a very similar scenario.
- heavyset_go 6mo agoNever forget what they did to encryption
- motbus3 6mo agoI think you miss the point (But who am I) the simple fact you sending the same signal over and over again, with all other signals your browser send, it will be another key to make you apart. They don't care if you lie. Important that you lie the same story every time. And after having your dob, who could easily be a flag if you are less than 18, they could easily request your name, or a document number, but I think it will be much better, it will have some ISP and/or Device ID.
- ekr____ 6mo agoIt actually is more like a flag in most cases. Specifically, in the case of AB1043, you enter your age or your DOB but then the OS provides an age range (<13, 13-15, 16-17, 18+). Also, while some bills do seem to require browsers to promulgate age data to websites (e.g., NY SB102A [0]), AB1043 does not. Rather, it requires the browser to read the age range just like any other app, but does't say anything about providing it to sites. [0] https://www.nysenate.gov/legislation/bills/2025/S8102/amendment/A https://www.nysenate.gov/legislation/bills/2025/S8102/amendm...
- stevenalowe 6mo agoNO, DO NOT COMPLY WITH FORCED SPEECH Might seem harmless now but it won’t next time, and you will have already capitulated
- uyzstvqs 6mo agoPeople need to understand the difference between age indication and age verification. Two very different things. Age indication is a completely private and realistically as-effective alternative to the invasive age verification. Age _indication_ means that when you set up your device or create a user account, you enter a date of birth for the user. The OS then provides a native API to return a user's age bracket (not full date-of-birth). If the user is a minor, the OS will require parental authentication in some way to modify the setting again. This can all be done completely offline. It works because parents almost always buy the devices used by children, and can enter the correct date-of-birth during setup. Age _verification_ means that some online service has to verify your age, and collects a bunch of (meta)data in the process. This is highly problematic for privacy, security, and the open internet.
- ekr____ 6mo agoI like the term "age indication". Thank you. If I may nitpick, the conventional term for systems which attempt to determine the user's age is "age assurance". This covers a variety of techniques, which are typically broken down into: * Age estimation, which is based on statistical models of some physical characteristic (e.g., facial age estimation). * Age verification, which uses identity documents such as driver's licenses. * Age inference, which tries to determine the user's age range from some identifier, e.g., by using your email address to see how old your account is. These distinctions aren't perfect by any means, and it's not uncommon to see "age verification" used for all three of these together but more typically people are using "age assurance".
- EmbarrassedHelp 6mo agoThe issue though with "age indication" is that it creates an additional flag that can be used to fingerprint users. But it is infinitely preferable to any sort of age verification or age assurance.
- heavyset_go 6mo agoIt's a distinction that hinges on one law from one state that doesn't reflect the reality of the dozens of laws in dozens of states, nor proposed federal legislation, that all require age verification via AI face scans and ID uploads. That's to say, this distinction is meaningless unless you're planning on blocking every jurisdiction outside of California so you can just adhere to its age verification laws and no one else's.
- cyberge99 6mo agoAge verification in the OS is one milestone of a greater objective: removing anonymity on the internet
- stephbook 6mo agohow?
- vaylian 6mo agoIt establishes that operating systems have the necessary infrastructure to reveal information about their users in a standardized way to other systems on the internet. Once that is established, it is easier for politicians to push for newer laws that add more features to reveal even more information. Politicians can propose any unrealistic law they want. But it is much easier for them, to convince a necessary majority, when there is technical infrastructure already in place. "We are already doing X, why don't we just also do Y?". Or: "Country A has already X, why don't we also do X?"
- PinkSheep 6mo agoThis forewarning is underestimated. Russia had begun it's path to Internet censorship through "think of the children" and to fight piracy. Started off as simple DNS and IP blocks, mandatory for all B2C ISPs. Now every egress international connection is being analyzed by DPI, VPNs, SSH are broken: the traffic inspection and interception (TCP RST among other things) has to be circumvented. Major messenger apps are blocked: WhatsApp, Telegram (intermittent connectivity), Viber etc. to force people to use the unencrypted local app (an FB Messenger equivalent, called "Max" by VK). There are now plans to expand the traffic analysis systems' aggregate bandwidth to nearly 1 petabits/s (sic) by 2030 with the expected total budget of 59B Roubles (470M USD).
- deleted 6mo ago[deleted]
- garganzol 6mo agoLet's restrict this plague to California/UK only. If Gulag wants to be a Gulag, let them be.
- nephihaha 6mo agoIt's a global project not a local one. It is linked directly to the digital ID programme and CBDC.
- Ms-J 6mo ago[flagged]
- petre 6mo agoThis is stupid. The age should be in the passwd gecos field or somewhere else in the user's config directory. Not in systemd. Unix-ike systems are multiuser. Now I wonder what age to put in the root, adm or games accounts.
- ben-schaaf 6mo agoSystemd actually manages /etc/passwd, /etc/group, /etc/shadow, etc. using a json database called userdb. Adding a field to systemd's userdb is how you add a gecos field.
- jcgl 6mo agoLook up systemd-userdb (the systemd component that added this field). Like the sibling comment said, this is basically equivalent to adding a GECOS field. A totally optional field.
- renegat0x0 6mo agoArticle asks what next. I know what's next. It is similar with crypto wars. They try and try until they have backdoor everywhere. About verification they will try to implement WEI on browsers, and verification on os. It is a crusade to make you always identifiable. Companies and governments want it so much because it is so valuable to them, it adds so much power over people. So what's next. They will move borders here, and there. Every year.
- usrbinenv 6mo agoOf course, it's pretty easy to see through this: introduce law in a few states, but now every OS needs to comply and because it's hard to actually tell which country/state user is in, they'd just have to implement it for everyone. It will be verification through some third party. You can opt out, but then major websites will be forced to deny you access (by, for example, Cloudflare) unless your OS provides a verified and signed certificate of your age. Then it's done: nothing will be possible without an ID, which means no dissent will be tolerated.
- shevy-java 6mo agoSystemd gathering user data is evil.
- gethly 6mo agoSystemD is now a spyware and therefore any Linux distribution that i using it. Period.
- johnny22 6mo agono it is not.. not yet anyways
- self_awareness 6mo agoI wonder, why California law mandates systems that the rest of the world should use? Does California have such massive market?
- duskdozer 6mo ago>The economy of the State of California is the largest in the United States, with a $4.048 trillion gross state product (GSP) as of 2024.[2] It is the largest sub-national economy in the world. If California were an independent nation, it would rank as the fourth largest economy in the world in nominal terms, behind Germany and ahead of Japan. https://en.wikipedia.org/wiki/Economy_of_California https://en.wikipedia.org/wiki/Economy_of_California So yeah it's pretty big.
- 5o1ecist 6mo ago[dead]
- dizhn 6mo agoWondering which jurisdiction will be the first to make it a crime to enter false information in the age field for their kids.
- _nobody 6mo agoOne very disturbing consequence not discussed enough is that some American state law is suddenly supposed to be tolerated by the rest of the world just because they depend on open source software, which sees contributions from all around the world.