5 ms·
(5)(a) "COVERED APPLICATION" MEANS A CONSUMER SOFTWARE APPLICATION THAT IS ACCESSED THROUGH A COVERED APPLICATION STORE AND THAT MAY BE RUN OR DIRECTED BY A USE
by floxy 5mo ago
(5)(a) "COVERED APPLICATION" MEANS A CONSUMER SOFTWARE APPLICATION THAT IS ACCESSED THROUGH A COVERED APPLICATION STORE AND THAT MAY BE RUN OR DIRECTED BY A USER ON A DEVICE.
(b) "COVERED APPLICATION" DOES NOT INCLUDE:
(I) A SOFTWARE APPLICATION THAT DOES NOT PROCESS USERS' PERSONAL DATA; OR
(II) AN APPLICATION FROM A FREE, PUBLICLY AVAILABLE CODE REPOSITORY.
- vegadw 5mo agoThat wording could be interesting, because it's ambiguous if free is applicable to the repository or the project. Presumably, the latter. This means you could absolutely do source-open but not open-source and still get around it.
- fc417fc802 5mo agoWell it says code repository not artifact repository. But it doesn't prohibit obfuscation or transpilation and more generally doesn't appear to specify anything beyond "free and publicly available". I really get the feeling that the people who wrote the law don't have a clear idea of what they're trying to say here and that any court decision is going to be a roll of the dice.
- fc417fc802 5mo agoOn the one hand, I'm absolutely against blanket age verification laws like this one, think there are better ways to solve the stated problem, and believe that the current crop of legislation is being pushed by bad actors for nefarious purposes by means of pandering to public mania. On the other hand, I do appreciate that a possible unintended consequence of the out provided by (5)(b)(I) could be that PII (along with user generated content in general) becomes similarly radioactive to if the US had passed a GDPR equivalent. Either that or it's used as a justification for every single online service to require government ID in order to interact with it "because liability". Unfortunately I assume the latter is somewhat more likely at this point. Also is it defined precisely what it means to "process users' personal data"?
- JumpCrisscross 5mo ago> there are better ways to solve the stated problem Call your representatives. There is overwhelming demand for age gating social media (based on, honestly, good evidence). This will be implemented based on who calls in. If the status quo of technical people being hopelessly nihilistic continues, it will be written in the stupidest ways possible.
- MBCook 5mo agoOf course we could make predatory algorithms illegal. Or just algorithmic timelines/discovery algorithms. Nah. Can’t stop the money. Let make brain destroying scams and ad spam legal as long as you’re over 18.
- fc417fc802 5mo agoTL;DR We need age verification laws to prevent minors from accessing the addictive stream of toxic sludge rather than outlawing its manufacture and distribution.
- ethin 5mo agoHow exactly would you do this without, you know, violating the first amendment? Algorithmic feeds are nothing without the content. People get toxic sludge because they signal to the algorithm that they like that.
- fc417fc802 5mo agoPresumably by outlawing the types of algorithms used with the legislation carefully limited to a particular context rather than anything being authored by an individual. Right to express oneself preserved, government regulates a harmful product, business as usual. As far as this specific Colorado legislation goes (which is concerned with the ability to comply with their previously passed data privacy law) I think it's not entirely bad but I have two issues with it. First, it reverses the problem. Services should be sending an age-appropriateness (or even just general content classification) signal to the device for local processing, not the other way around. If you're going to mandate that OS creators do anything it should be to implement a certain baseline level of (interoperable!) functionality as far as parental controls are concerned. Second, the entire thing should be predicated on some metric such as MAU or revenue or combination thereof not on the exceedingly vague idea of a "free, publicly available code repository".
- dlcarrier 5mo agoSo if your service is proprietary, but your client is open source, it looks like your're free to go. As someone that relies on third-party clients to get usable interfaces, if this gets widely adopted it would be great news. It would end the cat-and-mouse game from companies trying to force users onto first-party clients.
- Yokohiii 5mo agoMost proprietary services would process user data. It's also naive to believe that a fraction of open source in a companies pipeline would give them a free pass for everything.
- KAMSPioneer 5mo agoBut the text says "or," not "and." So by my interpretation if you process user data but are available via "free, public" repo, you're not covered. I presume "free" is defined elsewhere in the text, and that it approximates "open-source."
- floxy 5mo ago>(3) THIS ARTICLE 30 DOES NOT APPLY TO: (e) AN OPERATING SYSTEM PROVIDER OR DEVELOPER THAT DISTRIBUTES AN OPERATING SYSTEM OR APPLICATION UNDER LICENSE TERMS THAT PERMIT A RECIPIENT TO COPY, REDISTRIBUTE, AND MODIFY THE SOFTWARE WITHOUT ANY PLATFORM-IMPOSED TECHNICAL OR CONTRACTUAL RESTRICTIONS IMPOSED BY THE PROVIDER OR DEVELOPER ON INSTALLING ALL MODIFIED VERSIONS.
- KAMSPioneer 5mo agoAha, thanks! So I think that raises the question of whether e.g. RHEL is affected. Technically it could be argued that they don't add any additional restrictions, but I wonder if Colorado will see it that way.
- ChucklsTheBeard 5mo ago[dead]