I guess it depends on the culture but I would think it's a good thing to show interest and passion for this stuff by talking about things you do in your free time like setting up Minecraft servers, whoever you're talking to will probably have similar things like that
Agreed. I have had my tenure as a World of Warcraft guild & raid leader from many years ago on my resume for many, many years. It has always been a conversation point but managing 100+ people, who you don't pay, to prepare & train for complex, time sensitive operations including 25-50 people all working together, and all the management that comes with that, from DKP to class leaders, and so on. "Just think what I can do with paid people!"
I've never hidden my interest & passions, and I think the world is a better place when people are proud of what they enjoy. We're people first, after all.
Very true. I bought and setup minecraft server hosting in middle school, which got me enough money to build my first pc in high school. And the rest is history. :)
Not as much anymore. Sure, trap teams are common, but we used to have school rifle clubs that taught safe handling of firearms.
Now we've decided that if we don't talk about something, people won't get curious about it. Sadly, without being properly taught how to be safe, that generally ends tragically.
A larger number of people dying from an unrelated cause in another country doesn’t make these deaths insignificant. By that logic, virtually no problem deserves attention because you can always find something that kills more people.
The "trolley problem" is literally never a valid argument for anything because it purports to create an analogy for a real world problem but does so by creating a scenario that cannot exist, hence any argument based on it is nonapplicable to "real" problems.
Or more likely companies and people will just comply. It might give a little more fuel to open source from people who are ardently pro privacy that balk at an age signal bring implemented, but I don't think that's such a huge segment of users.
I think the upstream premise was kids using Linux to get around things. This could be the case, even in a world of the average Joe just putting up with the intrusion and hassles.
So really, both concepts can mesh.
After all, once compliant an adult is then not restricted.
As for the bill itself, it's one of those that gets passed because it is non invasive to the typical person, it's voluntary, and it should help some. There is no downside at all.
But 2 years from now a baseline has been established where the need to know your age when using a computer is taken for granted, and it's revealed that self-reporting isn't working and gasp there was this one kid in the news about something bad happening.
This is how it goes. This is one of the reasons the anti-gun crowd is so adamantly opposed to virtually everything. I'm not advocating anything with respect to guns here, but "sensible" measures were broadly supported and then turned against the owners who acquiesced.
An "exception" is two faced in this case. It implies Linux needs an exception to begin with and that the bill itself isn't absolute garbage and a direct attack on general purpose computing. Again, they establish a baseline with something that people are ok with.
Precisely. Courts will find that the situation where Linux users are exempt from the law, whereas Windows users have to submit their ID and any other personal data, can not be maintained, so Linux users will also be forced to give up their ID before being able to access the internet. This will also first come via commercial distributions (perhaps it can not be enforced by independent linux users, but the law need not necessarily work for 100%, could be 95%, and the rest are declared as breaking the law).
This is pure speculation. You can't possibly predict what courts are going to decide in the future. And the Digital Age Assurance Act doesn't "force a user to give up ID to access the Internet", it requires age information to be collected during creation of a user account on a system.
Totally agree. After the next big cyber attack, ganna have to kyc to access internet. It will be “for our safety”. Luckily now with ai the world doesn’t need me as a programmer so I’m just ganna stop using computers if they go full facist
So I run my app in a linux container under windows and I'm exempt from age verification? Isn't android linux under the hood? I'm sure the law is not so easy to get around. How does it work?
> These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
[…]
> Windows, macOS, iOS, and Android remain fully in scope, with age collection required at account setup from January 1, 2027. A later July 1, 2027, deadline applies to devices set up before January 1. Whether SteamOS is in scope isn’t yet clear: its Arch-based system components are open source, but Valve distributes the image alongside the proprietary Steam client.
I’m slightly confused about Android, I thought Android the OS was open source but then enough functionality is added by Google’s app store to keep it sort of under their control for the most part…
There is an open source version of Android released by Google (AOSP), but it's mostly permissively licensed (pretty much everything except the kernel), and the versions of Android that ship with nearly all devices (even Pixel devices) have modifications that are not open source. It's not just the app store, it's the actual services exposed as APIs. Thus, projects like Lineage and Graphene not being subject, but Google and Samsung still are.
The reason Steam OS is a gray area is the question of what constitutes "the OS". For Android, you can't run apps without the components in question, so it's pretty cut and dry. Steam OS, you can technically use it without Steam: switch it to desktop mode, disable Steam, and run it as just an Arch variant; you can even launch games installed via Steam if you really want. But in practice nobody does that, because you would just use another distro if that was your goal. So, is Steam part of "the OS", since it's the main thing you see when you boot by default, and probably the reason you use that distro? Or is it just a prominently featured application?
edit to add: Here's a graphic depicting the general shape of Android. Pretty much everything except the kernel can have closed source modifications (and even the kernel will typically have proprietary drivers and firmware blobs): https://upload.wikimedia.org/wikipedia/commons/3/32/AOSP_And...
On the other hand, this law doesn't require "age verification" beyond requiring users to supply their date of birth, and the Steam application already does this before displaying content only deemed appropriate for those over a certain age.
So the only thing that really changes in the Steam case is the timing of the question, and possibly how and where the (unverified) answer is recorded.
GNU is not particularly relevant here either; age verification rules were never going to affect glibc, bash, coreutils, GCC, Emacs, or any other GNU packages that I'm aware of, and would have equally affected Linux distributions built without any of them. (You could imagine that in the future there's a mandate to somehow tie age verification into boot integrity mechanisms such that GRUB would be affected, but I don't think that was contemplated for the current round of regulations.) The projects I'm aware of that were affected were systemd and D-Bus, and even these didn't contemplate adding any actual age-verification stuff, just adding age-category fields to data schemas in case something else needed to use them.
Yeah, you could talk about Alpine/Linux too, but those are definitely different from Google/Linux aka. Android. A free kernel alone does not make a free operating system.
Would always install some variant, think it was "pretty cool" for a few days, then revert back to "whatever MacOS was offering" (for my daily driver).
----
2026: I just finished building my third Ubuntu Linux machine, this year (gave the first one to my brother). An Ubuntu running a 5070Ti is now my main operating system.
Just in time for the kernel and its consequences to become completely hostile to anyone not paying for a frontier model. If I was 16 again and evaluating linux only to see everyone using LLMs to reason about the mess they've put themselves in I don't know if I would have even bothered. The promise of "you can just read and learn about it yourself" has been dead for at least 10 years, but LLMs put the nail in the coffin.
Linux has gone from attracting hippies to openly endorsing corporate closed-source products, something something live long enough to become the villain.
So someone said something I think sarcastically that deserves a fresh comment.
"From now on all kids will become linux natives. The decade of the linux desktop is coming!"
I teach technology K-8. So I have a front row seat to observing how the next generation navigates this new digital wasteland. Due to the aggressive censorship and locked nature of their computing experience at school, think Go Guardian, they have become experts at using Google workspace to make art, comics, communicate with one another in class etc.
My point, the next generation really will become adept at using Linux IF the system is so locked down that it's all that's available. Humans adapt to their environment, no matter how harsh.
Can’t think of a better outcome than Meta guaranteeing all parents that Linux is the safest OS for their kids. Steam Machines under every Christmas tree.
According to the existing law, Facebook can't provide service to any user whose OS doesn't say they're old enough. According to this new law, Linux won't say that. So Linux users won't be allowed to use Facebook.
TBH, OS based parental filters are the optimal solution here, especially if implemented in a proper way.
Kids don't buy phones and computers, parents do. When setting up the account for the first time, the parents could set the account to be an "underage one", all the apps, browsers, etc., would get the USER_IS_UNDERAGE flag and filter content according to that. No need for every site to ask and verify the age, just set the date of birth at the time of purchase, set a parental password (for possible future changes, reselling, etc.) and prohibit formats/wipes/factory resets without a parental password being entered. The clerks in telco stores could even help with the first setup of that.
Same could be easily implemented in linux, via some user flag set by the su/sudo user during the first eg. ubuntu install.
Yeah, there’s negative backlash against the age gate stuff but as long as you’re implementing it without privacy concerns like ID collection and verification it’s actually a really good idea.
A parent can change the setting in the OS and have every website and app comply with the OS setting is such a better situation than having to deal with a patchwork of content blockers, social media account settings, and parental controls that leak like a sieve.
Realistically, parents often don’t really have a good way to know what websites and apps you sign up for if you don’t have a crazily locked down device. Parental controls are complicated for non-technical parents and they usually know less than their kids do about the Internet.
A global OS age gate solves a lot of those problems, especially since OS-level controls are way easier to enforce and lock down compared to other methods.
on-device filtering is the right way to go, but it shouldn’t be a matter of sending metadata about the user to a service- instead services should provide standard metadata about the content to the device and the device can choose what, if anything, to display.
This preserves privacy better by keeping more information about the user local, and gives people better tools to decide what metadata categories they want to filter- for their kids and for themselves.
That solution doesn't actually work, and it angers me that people can't see why it doesn't work. That solution requires that the entire website must be child-safe or none of it. That solution requires that Tumblr must ban porn if Tumblr has any underage users. The alternative would be that Tumblr would randomly not load for underage users because some recommendation or ad would be over 18, and so it would rapidly have none.
That's much harder to implement. If you ban advertising eg. online casinos to underge users, the service would have to send two different ads (one 18+ and one for younger people too), and the browser would have to decide which one to play. Same for eg searching on google, browsers would have to filter out every <div> with adult content, meaning half the page would be empty, but with a browser "underage" flag, google could just turn on safe search and not allow turning it off.
Exactly like GDPR shouldn't have mandated millions of websites to pop up a consent form, as a global browser setting could would have set consent as a user preference.
But the objective of these regulations aren't what it says on the tin.
We got into this mess long before this, when we decided it was ok to trade freedom at the hint of protecting children, without considering the actual merits of the situation. Look at the horsemen of the infoacalypse.
Then we decided we should punish ourselves rather than expect/require big business make safe products.
Facebook was the excuse (and there's a no zero chance Meta funded the initiative themselves). The government's worldwide jumped on it so quickly partially becsuse they've been trying to find aan excuse to control the internet for decades. Never dismiss how quick they are to push stuff like this but how slow they are to enact actual positive change for the people.
nobody is worried about about the arbitrarian aspects?
What if you are interested in developing your own OS (a task that would have been monumental but may become trivial with LLMs in the future)?
Why is the proper level the OS? Why not the browser or the hypervisor?
Or perhaps manufacturer should remember your age? What if hardware is resold? We would need a hardware cadastre! A global hardware cadastre would unite all jurisdictions in a power bloc eventually. It starts with daily computer/laptop, then domotics, then digital door locks, and before you know it the bloc-global hardware cadastre becomes authoritative, and the reference for property ownership.
The proper level is actually the device. The government doesn't care about how you arbitrarily divide the device software into components - only how they are non-arbitrarily provided by different people.
The bill doesn't exempt Linux-based systems by name, if that's what you're thinking. It exempts any operating system that allows users to "copy, redistribute, and modify the software". It's a bit arbitrary in the sense that Microsoft and Apple could dodge the requirement by simply becoming open source, but that's not going to happen so it's not really a problem.
Why does birthdate trigger y'all so much, but physical location (literally the field right before it, that you can see in the diff context) doesn't? Shouldn't we be protesting even harder against systemd tracking our physical location?
That commit message mentions laws from California, Colorado, and Brazil. Today’s article is only about how the Californian law is inapplicable. It seems to me that the feature is still valid.
It’s 150 comments of back and forth on a change which doesn’t have a concrete reason, the maintainers aren’t in agreement on what the right approach is wrt the field’s behaviour, and the person who submitted it is bouncing between saying he’s keeping it on topic and then adding scope where he believes it should be added.
I also personally disagree with the change, I think the OP has gone ahead and implemented what they wanted but not considered the actual ways it will be used. The PR shouldn’t be merged until the laws have made a bit more progress and it’s clear what they’re _actually_ implementing.
That's the facebookisation or redditisation of open source. Open source used to mean when you got the software you got the source code, but now it means a platform for arguing. And there's no doubt in my mind when people say they can't switch their project from GitHub to Forgejo because they'd lose "contributions", they mean this.
I don't understand your point. The phrase "when you got the software it got the source code" makes no sense. And arguments were just as common decades ago on forums, mailing lists, and IRC. What exactly are you trying to say?
I have no problem with that as long as it's not the government controlling the age verification. It should be a parent. And as a parent I want the ability to properly control my children's devices - the fact that Apple, and especially Google pretty much ignored this feature until now is a big part of why we have these dumb laws in the first place.
Think about it - if every phone you got asked you at first config "are you over 18? If not ask a parent to set up this device" then everyone would know about that capability and "think of the children" would be met with "parents can just click a button"...
You already have the ability, all parents do, that some (or most) haven't is why this crap gets proposed in the first place and used as a justification for invading everyone's privacy.
If (some) parents actually parented instead of abdicating that role to the state/education system then this tripe would get far less traction - though cynically they'd just switch to the other argument they always trot out.
California AB1043 is the only reason that app providers have to give a shit about whether parental controls are enabled btw. Before these laws, most apps were openly ignoring parental controls.
Oh no, some people are terrible at cooking. Better ban cooking without a license. Giving your neighbor a home baked pie is now a crime unless you're a licensed pastry chef.
That’s correct. We only need one law. Restaurant food poisoned you? NAP violation.
Even that might be too much. As you’ve insightfully illustrated, 1 law is a slippery slope to infinite laws. Next thing you know we need a license to toast bread in our own damn toasters.
Systemd is paid for by Big Business, so they will retain user-identification information in the long run of course. Poettering will never revert what he is paid for by the TechBros.
This. This literally makes it illegal for social media sites to serve Linux clients. The previous bill (the one that propagandists call "age verification") was actually really good, and this one is really bad.
I testified against the equivalent of this bill in my state. One of the things I mentioned is because of a non-trivial monetary fine per infraction [1], as someone who would potentially need to implement this, I would have no idea how to reliably differentiate a computer that was simply out-of-date/implementation has bugs from willful non-compliance vs Open Source [2].
It just felt like the bill had the goals it had when it was created, and the broader cloud of "gee, if people implement this a certain way, it could have unintended consequences" was completely ignored. But don't worry, one of the co-sponsors proclaimed. near the end of the hearing, that they had a Masters Degree in Computer Science and worked on operating systems in their career, so they made sure to let us know that we were over-reacting.
The other thing that really pissed me off was it was rumored my states bill was going to get an open source exemption. However, they waited until the end of the hearing to introduce all of the amendments, including the Open Source exemption. The proposed amendments were not publicly visible on the bill page or the page about the committee meeting for that day. This ended up being an excellent strategy to sway other committee members [3], since they could just hand wave the bulk of us as "concerns resolved". It was quite illuminating to also see media lobbyists come in and verbatim just state "hey did you get our proposed amendments?" and then without much reading of them at all, they were ratified during that session. Lesson learned: the moment there was a rumor of amendment, I should have made a considerable effort to get my hands on that text ahead of time since for the implementation concerns I raised, I was still unhappy. I'm not quite sure though how much of a difference it would have made though, since at least 30 other people fell into the same trap.
Anyhow, hopefully my long-winded Sunday morning post was useful to someone in the future either when dealing with compliance, a version of the bill in their own states, or the federal government's attempts to do a similar thing. I confess that I have been lazy and not remotely done any due diligence on that federal bill (https://www.congress.gov/bill/119th-congress/house-bill/8250... / HR-8250: Parent's Decide Act). I encourage others to be better than me and contact their representatives, assuming it isn't already on the fast track to becoming law.
[1] at least, for smaller businesses -- big tech won't care! I think it was something like $6,000/pop, which is chump change for big tech and will be negotiated during settlement talks.
[2] Okay, you can check the user agents. But who wants to need to maintain or pull in a list of enforceable user agents! What happens if someone is spoofing the UA and suddenly they end up in my list of "must check" UAs (or inversely, !(not must check)). How long does one reasonably wait for the API call to time out? What about running the app on Wine? And most importantly, what if someone that doesn't care about Linux ("okay claude make my website legal no mistakes") is in charge of implementing this logic, or the library that people will end up using for compliance.
[3] Assuming they cared. The vote was largely amongst partisan lines, some people had clearly looked checked out the whole time, despite the abnormally high numbers of their constituents being there that day.
this bill fixes nothing. if you wanted to prevent harm from the internet you would start with proper privacy laws. but we all know why that will never happen
I'm guessing you are thinking about things like addictive social media and the efforts to keep kids from overusing it, and the idea is if there were strong privacy laws it would be harder or impossible to implement the most addictive features of those sites?
However harms based on sites having lots of personal data on their users are only part of what many people are concerned about. There are various categories of apps and sites that are legally required to not sell to/serve children. There are also things that are not illegal but the majority of research finds is bad for young children, so apps and sites may want to keep young children out unless a parent approves. Privacy laws don't help with any of that.
> if you wanted to prevent harm from the internet you would start with proper privacy laws
Explain how a privacy that protects you and me will somehow not protect a pedophile. How does that work?
I am FOR privacy. I don't think it can be done.
I do not want to have any information at all stored anywhere, encrypted, decentralized or otherwise. Nada. Its just text. I want to just be a number in everyone database. I want to be able to spawn millions of numbers that will never be related to each other. My ideal privacy world is a world where bots thrive.
Just go to face to face discussion if you care so much about who you are talking to.
This is a victory only in a very perverse sense. The silver lining is that maybe this will push more people towards using Linux (maybe Haiku will have its day). And Linux itself lives on. But what a disaster of a policy, clearly just catering to lobbyists and not the best interests of Californians.
This is a silly idea since California's law was actually well-thought-out. This will actually force social media to ban Linux clients, since the social media can't be compliant in that case. The operating system won't provide an age signal and the social media isn't allowed to ask for one on its own.
I also want a permanent ban for anyone who calls the California law "age verification". It does not verify age. Period.
I think you're misreading it. It doesn't ban Linux from providing age collection and verification. It makes it a choice, rather than mandatory.
I would expect that Linux users want access to age-verified apps just as much as other users, so such a signal will be available.
Also, you're being overly pedantic on the language used. It transfers liability away from the service, more easily allowing operation in about half of the states. "age verification" is a fine lay description.
> These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
It's kind of weird though. Is VxWorks (a proprietary embedded OS used on some of the Martian rovers) going to require it in case some underage Martians try to use Facebook?
That depends. Will some kid be caught accessing Facebook from a Martian rover, triggering a court case? Remember, the law only cares about things that actually happen.
My gut reaction to this is that there is something seriously wrong if special clauses are required. Why should open source get special treatment, to me that just highlights that the law is utterly ridiculous.
Technically opensource stays the same. The special treatment is for closed source OSes that get an additional legal protection for their datamining. We should not be passing laws that legalize the datamining of people.
I remember the good ol' days when our parents told us what we could and could not use or buy. If Johnny's parents let them do something, Johnny's parents would get admonished for it and we just wouldn't see Johnny anymore.
They made it sound like it, but this is not a victory at all, this is a temporary strategic compromise to silence the most sensitive/foreseen privacy advocator for now. But they will not stop here, instead they'll keep advancing the mechanisms, opinions and laws, so one day when the pieces aligned, they can come back to turn this tap off while having people lied to their side.
Forced age verification needs to be abolished completely and people who advocated for it punished to the point that their political career ends, this should be the baseline.
But of course, based on my understanding of everything, no, nobody will do anything effective against it. Everyone will just be "Yeah... they forced a component on my system that could act as spyware to monitor me, then have me pay for it without give me any control. But guess what, I will accept it because they said it's good for the future of mankind", like a peasant would. This is the tax you paid ended up for you, you know?
What's to prevent Apple from making iOS and macOS free to "copy, redistribute, and modify"? The OS is free already, and the platform does cryptographic signature verification before allowing its installation. macOS already automatically finds local caching servers, which amounts to redistribution capability baked in.
They can just claim that the user is free to turn off SIP and "modify" the binary bits, or that kernel extensions amount to modification.
Rest of the headline: "software distributed under the GPL, MIT, BSD, and Apache licenses are exempt"
And then further into the text it's clarified that there also isn't a specific list of open licenses, as the terrible headline would have you believe, but instead a description of what is considered open
With the caveat that I haven't read the actual legal text, this seems to be an eminently sensible law (it'd be better if it weren't needed, but here we are).
In summary: not a Linux exemption, and not an exemption for a specific list of licenses either.
I don't consider that sensible at all. The law is supposed to protect children. It's hypocritical to exempt certain operating systems from the law, and, to be honest, I'm astonished this is legal/constitutional in California.
What I meant is that if we take the law as a given, then the exemption we are discussing here are very good and sensible. I wish they weren't needed, but given that they are, the language seems sensible.
Agree, I think the law will be challenged on that basis, and ultimately thrown out. Millions of taxpayer dollars wasted, when they could have been actually solving the problem by making platforms responsible for the content they distribute.
i still think this should be solved at the protocol level. if you want to access the adult stuff, you have to staple a non-identifying zk-proof-of-age to your http/spdy/etc requests, otherwise it all just operates as usual.
> (2) “Operating system provider” does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software.
Where does MacOS and iOS fit then? The core of both those operating systems (darwin) is open source (APSL licensed).
MacOS isn't Darwin and comes under terms that do not fit rhe criteria of the exception. Apple actually did go to some lengths in the past to ensure that all layers of MacOS contained bits that they could claim restrictive licenses on.
A project like PureDarwin, however, can be freely distributed because it omits Apple's proprietary parts.
The line is that an open Linux distribution will boot and run on hardware that is sufficiently compatible.
The full MacOS as distributed by Apple is engineered to require closed source, non-redistributabe components even on the hardware it is most compatible with. It will completely stop functioning if you remove those parts. The presence of freely licensed components becomes de facto irrelevant.
Basically all linux distros fully run without the closed source parts, they are only there to provide support for specific hardware. MacOS on the other hand cannot run at all without the closed source parts.
I can copy and redistribute macOS binaries, and I can write programs/extensions that modify macOS.
These vague terms show that legislators are incapable of regulating software effectively; but they do create an enduring legal franchise to deal with their confusion.
You cannot. The apple license has multiple restrictions on that prevent you from copying, modifying and redistribution, for example:
> No Reverse Engineering. You may not, and you agree not to or enable others to, copy (except as expressly permitted by this License or by the Usage Rules if they are applicable to you), decompile, reverse engineer, disassemble, attempt to derive the source code of, decrypt, modify, or create derivative works of the Apple Software or any services provided by the Apple Software or any part thereof (except as and only to the extent any foregoing restriction is prohibited by applicable law or by licensing terms governing use of Open-Sourced Components that may be included with the Apple Software).
> the original definition of “user,” which read, “a child that is the primary user of a device,” and technically classified every device owner in California as a child.
which technically makes California a "Nanny state"
> In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law. That closes off potential abuse of the age API that could have led to it being used as a general-purpose data collection channel even when age verification wasn’t required.
Honestly hate all this. This is just a "geeks shut up" law. Excluding things that are not part of commerce (FOSS) probably even gives it some protection from constitutional challenges.
And the quoted part above indicates that it is purely a government ID system - run the thought experiment where you were a conscientious person in 2005 deciding to start a social network, and this law had been passed in 2004. You wouldn't be allowed to use it to exclude children. And where will it be "required by law"? Since the pretense was to target social media and porn was just a bit of moral backwash, it will be required by law on arbitrary sites that allow any users to post.
Geeks will shut up because they love how specific it is. And even as GrapheneOS is being banned already from being able to use websites and services, they'll be shocked when their unattested FOSS machines aren't allowed on the network at all.
It passed unanimously because it means absolutely nothing, and politicians were getting shit from their rich loudmouth programmer constituents who will go back to spending time on their YIMBY activism.
The fact that these bureaucrats think they have a right to add age-verification to information is ludicrous in the first place. This should be as much non-news as 'Lawmakers unanimously decide death is legal'.
Lawmakers—contemporary and otherwise—have in fact decided many many times that the state can deprive you of your life as punishment for certain crimes.
I believe what parent commenter is suggesting is that it would be ridiculous for lawmakers to call it a crime to die, say without verifying you are of the legal age to do so. It would be like declaring that breathing is legal: why does that need a proclamation?
To use your metaphor, this is saying that a store needs to limit you to the kids section if it is told you are a kid at the door. The exemption here is because a park doesn't have doors to perform this check onto.
(PS. I'd hope we were past trying to hamfist physical metaphors to describe the digital landscape. But alas).
Well, maybe cigarettes were a silly metaphor -- can my kids still get their porn at the Linux store?
Are the gore websites gonna have to ask for ID now? What about 4chan? Or is the whole point to get rid of all that stuff and just get everyone using Facebook instead? (They're the ones who pushed these laws right?)
I'm honestly trying to understand what the big picture is here.
Can someone the exemption for browser extensions and other contained software?
My best guess is that the OS > Browser are reporting the age already, and the browser extensions will also use that "signal". Is this close enough?
" third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope."
It was written for them by very smart people to quiet resistance to these laws, and to make sure there's no possibility that there's a price to be paid by anyone at the ballot box. Most of them probably neither understand or even read it, they are voting for it because they were told to by the same people who told them to vote for age verification.
Now if the guy that just created his own renderer for SwiftUI can port it to Linux instead of WASM we can have a Linux Mac replacement analog we just need someone to port the Metal GPU API over to Linux.
Does not matter? Can they just say that if a website cannot determine your platform is Windows or MaCOS you can not get access to any particular website? Sure, you can set up your laptop with Linux, but you can't surf the web.
I am wondering how much this could hobble GrapheneOS...
I find it hard to believe these people would just create a huge loophole for only smart kids to get through rather easily.
Practically, the components of Android which mandate a user account are not distributed so that the user can modify them. The exemption does not apply.
But if Ubuntu bundles an Nvidia graphics driver that is not open source does that disqualify it? It's normal for there to be a mix of both open and closed source code in an os.
A better example is: I install Debian and later, somehow, the Google Play Store. Maybe that’s the only way to get some driver. Who is responsible for asking my age: Debian or Google?
I think since it is a for-profit project it is not exempt. At the least it would not make any sense otherwise.
I also agree that this is now a mess. Courts will lateron find that such exemptions make no sense, since it is unfair to Windows users. And Windows will require mandatory ID verification; I think they already do that to some extent, e. g. when you register the OS, unless you use the workarounds to not give up your ID in order to use Windows (not sure if this has changed with Windows 11, I won't use that version and it is unlikely I will use any later version; I use Win10 only on a secondary computer anyway, have been using Linux since soon-to-be 30 years so I could not care any less about this ruthless and evil operating system called Windows, now with mandatory AI slop spam).
A quick search suggests that 3D-printed guns being used in crime is an actual, for-real, and growing problem.
I take it that you wouldn't be OK with somebody building a uranium enrichment facility in their backyard for their hobby reactor. So there is a line to be drawn on where people's freedom to tinker ends; it's just a question of where you draw it.
Personally, I think given there is an actual documented, non-isolated problem with 3D printed guns being used for violent crime, there's a debate to be had that's more sophisticated than "REGULATION BAD".
Once you know how easy it is to make a gun using parts from a hardware store the concept of banning it becomes a joke.
It’s like trying to ban wrenches.
Lever and tube - that’s what it is. People create makeshift ones even when it’s legal to buy them, because it’s cheap and easy to do so.
You can’t ban computers or personal transportation or words either.
You can’t even ban a person from a website. You can ban an account - but you haven’t stopped the person. Any attempt at playing arbitrary authority you’re gonna lose
> A quick search suggests that 3D-printed guns being used in crime is an actual, for-real, and growing problem.
Making actual firearms from steel is trivial. In fact you can look up Kalashnikov designs online and then replicate it with a relatively simple mill/lathe/tapping setup.
To be honest, as someone familiar mostly with computers, I have no idea where to start with this and it sounds a bit intimidating. Buying a 3D printer and using some 3rd party design sound very easy in comparison.
You're certainly right that it's possible for someone determined to make their own firearm, but raising the bar still has immense value.
Tradeoffs between freedom and safety are another, unrelated discussion.
Just watch a few YouTube videos. It’s not hard. Much easier than software development, although it’s dirty/messy (you use lots of oil and fling metal shavings everywhere) and time consuming.
It’s not 3d printed guns, it’s 3d printed parts. You don’t need the 3d printing at all if you want to make a DIY gun in the US, you can literally just buy the gun parts.
You don’t seem to have a good grasp of the topic but already decided the opposition position is „regulation bad“, but that’s not the case at all. The pushback comes from introducing the government as middleman between your slicer and 3d printer, that’s dystopic af
Then I missed the public discussion on why making it illegal to possess DIY guns is not enough. Did that actually get debated or just handwaved away? By the time I became aware of this whole technical blocking thing, that was the only proposal on the table.
Ah, I think I know this one. It's because people who make their own guns are nerds. You know, like you or I, except in a different topic. I remember reading a couple of posts on R*dd*t where two folk were discussing fitting accessories to guns and one posted something like "No, you can fit that, all you do is mill a slot on top of the receiver and drill and tap a hole at the end and you can just about screw this thing in place" kind of thing.
I read the discussion and thought "yeah that's nerd talk, just not about analogue synthesizers, old Landrover gearboxes, or Pascal compilers".
I guess the reason for blocking 3D printers from making gun parts is because it's easier than doing it "by hand". All you really need to do is get a copy of the files from someone who has them, print it out in something suitable, and you have viable gun components with very little "real work" involved.
By contrast here in the UK, where it's quite surprising what you're allowed to own and operate if you comply with the laws (here you're allowed fully automatic weapons, if you keep them at a suitable shooting range and don't try to wander around town with them, and you're not oh maybe a convicted violent criminal for example) one of my late father's friends was a gunsmith. My dad was an excellent machinist, and so he made some components for his friend, and I remember standing in the machine shop where they worked while he turned a chamber for a gun his colleague was building in the lathe. "There you go," he said, taking it out of the chuck, "that's legal".
Then he took it over to the mill, and cut a couple of holes and slots that would allow it to actually function as a chamber, "And there - now it's *illegal*."
Then, as he handed it to his friend, who was licensed to have "home made" gun parts, to stamp his initials on, "And now it's legal again."
Of course since people aren't allowed to just walk around with handguns since the school shooting, it's all a little more difficult - but the police will tell you what you need to do to keep it legal.
It's still slightly easier to get a shotgun licence than a motorcycle licence here.
> here you're allowed fully automatic weapons, if you keep them at a suitable shooting range and don't try to wander around town with them, and you're not oh maybe a convicted violent criminal for example
I think you're overstating this. My understanding is that here in GB (unsure about NI) fully automatic firearms are absolutely prohibited with only limited exceptions that the general public are typically ineligible for. Could you elaborate?
My position on anything is "REGULATION BAD" when it's against individuals and non commercial/open source projects, "REGULATION GOOD" for massive corporations, and "REGULATION MAYBE GOOD NEEDS NUANCED DEBATE" for anything in between.
Non-commercial projects and individuals can do bad stuff too.
I agree the bar is a lot higher for those projects than massive corporations, but I think it's a pretty arguable case that "people are using 3D printers to make guns with features that would otherwise be illegal, and they are being used in crimes in some number" clears that bar.
The obvious answer is to slice up your gun model into a number of sub-parts which individually aren't detected by the algorithm but collectively still form a functioning gun. And there's an unlimited number of ways to slice up a model, so it is impossible to create an algorithm which catches everything.
What's next, keep track of all printed parts and invent the math to recombine them in every way possible to see if it could form a gun? Trivially defeated by using multiple printers. Hmmm, sounds like a good reason to force everyone to register their 3D printer with their real identity, and only allow a print after the model has been uploaded to the Federal Printing Database for verification...
Or ya know, make a gun using a cnc machine, or are they gonna ban those too?
It’s so ridiculously easy to assemble a 3d printer from individually sourced parts, and find some open source firmware to run it. How is this going to stop anyone who’s dishonest and slightly motivated?
What’s next is thinking about guns is a thought crime.
There’s a cynical part of me that sees this as having nothing to do with guns. Technology used to empower people. You can do anything with a computer running Linux, you used to be able to go anywhere on the web and do anything you like. There’s wasn’t a curated experience, a whitelist of apps. This is a bad thing for people who want to control and manipulate. They want us to mindlessly use our closed of devices that only show us what they want us to see and do what they approve. 3d printers can’t be allowed in such a world.
Most sensible explanation to me is that it is getting something that does scanning on the 3d printers. Next step is to make it apply to copyrighted designs. As that is lot more doable. And fascists like to be in control and allow big corporations to exercise their power.
Ah, but don't you see? Something Must Be Done, and "gun part detection" is, indeed, Something. (ignoring that it fails the "thing" part of the definition, because it can't possibly exist)
Fully 3D-printed guns have awful performance, though. You would likely get significantly better results improvising with the stuff available at literally any random hardware store. Yet, despite that kind of gun being around for centuries, we weirdly aren't seeing bans on rigid metal tubes yet.
3D-printed "guns" become a real issue when you combine it with unregulated sale of firearm parts and ammunition. To get a fully-functional gun you just need to 3D print a fairly trivial component which is legally considered the entire gun as it carries the serial number. But that's not a 3D printing problem, because there are also companies selling that same part in a mostly-finished legally-not-a-gun form, together with a drilling jig guiding you how to drill the last few holes with a regular Dremel. And nobody is proposing banning Dremels. Heck, it is totally okay to own a lathe - which you can use to make your own high-quality guns!
And the entire discussion is of course pointless once you realize that this is the USA, so anyone is only a weekend road trip away from legally and fully-anonymously buying a gun two states over. If 3D-printed guns are such a huge problem, why aren't we seeing European countries mass-banning 3D printers?
To extend your analogy: it's like being fine with the sale of ultracentrifuges and uranium hexafluoride, then getting upset at someone selling a screwdriver to attach the plug to the power cord of the ultracentrifuge because "screwdrivers lead to nuclear bombs".
3D printed guns are a nothingburger. There is indeed a non-zero number of violent crimes committed with them - but there is also a non-zero number of violent crimes committed with shoelaces, so that's clearly not enough of a reason to ban them. It only makes sense to regulate them if they are involved in a significant number of crimes and leading to a huge increase in gun violence - and at that point you probably want to crack down on all forms of DIY guns instead of just the 3D printed ones. But that's simply not the case, so the regulation is pointless and doing more harm than good.
> ... why aren't we seeing European countries mass-banning 3D printers?
Dunno, because most europeans are way more responsible with their guns than many people in the US?
For example in the EU (and in Switzerland) before you can buy a gun, you get specific training about safe and responsible handling. And in many countries the cops shall come to your place and verify that you've got a gun safe and a separate safe for the ammo.
And we don't offer AR-15 to our kids when they turn 14 y/o (well I say that but my daughter wants to shoot my weapons and, once she turns 14, she can switch from air rifles to the real thing as long as she's accompanied).
Just to be clear: we have shitloads of guns and ammos in Europe. There's even one EU country with concealed carry. I think it's estimated there are twice as many non-registered weapons as registered ones. We've got big guns factories and gun brands in the EU. And there are millions of illegal full-auto weapons like kalashnikovs (well Zastava M70, which is the same) from the war in Yougoslavia in the hands of criminals. And shitloads of fully functional weapons, including handguns, from WWII circulating.
In my native city (Brussels, Belgium), at the moment there are drug dealers firing kalashnikov on police stations regularly (it's a big issue, it's in the news daily and the authorities don't know what to do).
In addition to people shooting at the range (and, sadly, to drug dealers/criminals ruining our cities), we've got lots of hunters too.
Many people at my shooting range have their official gun transport license full (that is 30 weapons) and some have more than 100 weapons in their collection.
It's a fantasy that europeans don't have guns: we're (mostly) responsible with them.
It's maybe because we're responsible with our guns that the EU hasn't banned 3D printers... Yet (it's the EU, so nothing is unthinkable).
A court at a later time may find that this situation is unfair to windows users who have to submit to age sniffing. So this will easily be overturned at a later time - age sniffing will never be given up by the lobbyists groups paid for by Meta and others (and the USA also wants that information).
I'm starting to warm up to this law. So many loopholes. Nothing to worry about. I think California's incompetence has finally progressed from "proposes bad laws" to "proposes and botches the implementation of bad laws"
If you had an agent in the legislature wouldn’t you prefer exactly one of this form? My ideal representative is able to command support from diverse interests and subtly damages those opposed to me while subtly advantaging the principles I believe in - making compromises necessary to move incrementally to a state more aligned with what I wish it to be.
The reality is that many people want bad laws. Without the support of those people one does not get elected.
This use of people for power while de-facto disenfranchising them is pretty widespread already. For instance, some half of California and Texas are responsible for their strength in the electoral college while simultaneously being entirely disenfranchised when electing the President. Good technique.
This seems like a hollow victory. "No signal" will quite soon become a vanishing minority of users, and websites will simply reject anybody that isn't providing the signal. These laws mostly just prime the pump to get the corpos over the activation energy of coordinating a conspiracy to make browsers start doing this on their own.
I'm not an attorney and haven't read these laws, but here is an interesting question: if Linux is exempt from legally needing to supply a user's age for verification, but websites require an age to be presented as a condition of access, can browser developers on Linux send a pre-programmed age for interoperability purposes and be legally in the clear? It seems legit to me.
Of course, since the whole point of these laws is to absolve Faceboot (the laws' sponsor) of liability, Faceboot (et al) will then move on to demanding remote attestation to make sure users are on proprietary operating systems that are legally required to send a faithful signal.
I do wonder if there is an angle here for pushing back against the ever-growing surveillance industry. What if instead of sidestepping the age requirement by choosing an "old enough" age, we chose "too young" ages instead. A signal saying "I am 12" and all the COPPA requirements start to apply, including to embedded ads. Probably easy enough for most sites to flat out reject access. But some sites can't / won't - think government sites that currently embed corpo-surveillance crap like recaptcha etc, or sites that serve neutral content and don't care themselves but use cloudflare. Or perhaps browser extensions could even mix and match which signals they send where - "over 13/18" to the main site, "under 13" to the subresources, etc? I suppose by the time you've gotten there you might as well just be running best-in-class adblock extensions that work based on lists of hostile sites. But I think there might still be a core of an interesting aspect to a well-known way of telling websites that you're under 13.
Hey so uh... Did anyone notice the word "accessible" here?
> Provide an ACCESSIBLE interface, at account setup,..
I wonder if the biggest effect of this bill will be that proprietary operating systems will have to have accessibility features built-in, and will be subject to ADA compliance lawsuits if it's deficient in some way.
This law is still worthless. A burden on those who follow it, an excuse to attack those who don't, and completely ineffective at best. You think every child doesn't quickly learn to click "I'm over 18"? I've been doing that since I was 13.
"Protect the children" is the most common refrain of fascists across the political spectrum. It's used, uncritically, to attack your rights, to take away your power, with a fragile appeal to morality. Just like the war on terror. And the war on drugs. And the war on poverty. Funny how all of these efforts have failed while increasing government interference in our lives. We never get the rights back, and we don't improve the situations on any of the above.
> a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software
which at least doesn't choose specific winners and losers among licenses. It does disfavor license-free and public domain software, which isn't great.
Sure, but of minimal practical impact. The Free and Open Source community has long discouraged releasing software into the public domain, as it has clear drawbacks compared to just using a permissive licence. The legal intricacies of the public domain vary between jurisdictions. Not all jurisdictions even allow copyrights to be surrendered in this way. [0]
Licence-free isn't a concern. That isn't even close to Free and Open source software, it's the opposite: software that you aren't permitted to acquire, use, modify, or distribute. [1][2]
Technically you could argue that public domain works don't have license terms that make them free so the exception can't apply. Only an ignorant or ultra literalist judge would see it that way but you never know.
On the other hand a public domain dedication is a binding term that gives you permission (or license) to do what you want...
It only applies to software distributed under a license. Public domain software isn't distributed under a license. It's in the public domain; no license is needed.
Laws need to be managed like software: There should be a process for testing, user feedback, quick patches for bugs or conflicts, and regular updates to fix issues. If you think about it, both laws and software are called "code".
The problem is our legal system is still based on the waterfall method. Lawmakers try to plan for everything, laws meant to solve one problem face feature creep and create a thousand others, then no one wants to touch anything after launch for fear of making things worse or because that one guy uses the temperature of his CPU as a quick-key and refuses to change his workflow.
Anyways, no law is perfect and never will be, and neither are the fixes.
Software development is slower in larger, more political organisations (hello Change Advisory Boards) and larger/older/sprawling codebases.
Most governments are huge, highly political, slow moving organisations. It seems to just come with the territory: slower rollout of changes, longer periods to observe the changes in the wild (throw in a few years to see how the law plays in legal cases/challenges), and suddenly you have fewer iterations to get it right.
> The problem is our legal system is still based on the waterfall method.
It's not? It has been "agile" for centuries. It is constantly patched as someone wants to address some issue. It's rather rare for a completely new law to be written.
> Lawmakers try to plan for everything
It's not? They see one bug, e.g. children being exploited, now they tried it with a patch that is horribly broken and doesn't really work, so they patched it again, to remediate one issue, while they try to figure out more patches.
Engineers and scientists would like to imagine our society operates off a specification. But laws are only justifications for what people in power want to do. All of what you’re talking about reinforces the myth that the text matters and is precisely defined.
It's also hilarious how poorly defined so many laws are. So many loopholes and bugs everywhere. Probably because most lawyers/politicians are effectively illiterate when it comes to logic.
> Probably because most lawyers/politicians are effectively illiterate when it comes to logic.
Unfortunately the “Never attribute to malice that which is adequately explained by stupidity" is completely wrong in politics. In politics and lawmaking, always attribute to malice, not stupidity.
Lawmakers appears extremely dumb on TV for the most part, but the teams behind them are actually very smart (pure evil, but smart). All the loopholes and bugs in laws are, to them, a feature. It allows them to always prosecute regular citizens, but the favored people (politicians, campaign contributors, oligarchs) always have a free pass. This is by design.
I don't disagree with you, but I think it's important to remember that ambiguous laws are also a feature of modern societies. Laws have to be ambiguous, for one because the real world cannot be codified into abstract laws perfectly, and because separation of power is a fundamental part of how our society works. Judges are supposed to apply the law to specific cases. Thus lawmakers get to decide the wording but judges get to decide how to use it. If there was no room for ambiguity, we would not need any judges.
California is a common law jurisdiction. Judges evaluate cases and make rulings based on the intent of the law instead of the literal text as written in order to avoid absurdities, setting precedent for future similar cases. If the lawmakers disagree with case law, they amend the law.
What do you want people to say? "Yay, the terrible law that threatened to make free computing illegal has an exemption for Linux. Now we only have to deal with unwanted mandatory age verification on all our non-linux devices. I'm so happy."
I habitually complain about government... so let me help you out with this.
The original issue with the law was never that those poor open source developers were going to have to bear the burden of complying with the law, but that the law itself was a bald-faced invasion of privacy by an overbearing troupe of people in power (i.e., government) so shit-sure of their superiority over the simple common folk they govern (i.e., you and me) that they aren't even embarrassed by their own arrogance.
I would suggest that what "we wanted" is no such law at all. What would be weird, and worthy of comment, is if those of us that complain about government were actually satisfied by an exemption which only applies to pretty damn tiny slice of the market. If anything, that wasn't a victory for privacy or common sense, but rather a concession that they had foolishly created a law that they wouldn't have been able to enforce as broadly as they thought they could get away with... or if they tried to enforce it they'd have to contend with the optics of the big hand of government yet again crushing individuals whose only real crime was their altruism rather than just some giant corporation.
So it isn't weird at all that "we're" silent. This isn't a win. Pointing out that the law had unintended consequences, including with Linux, et al., wasn't a statement of objective but rather a simple show that the law was rife with thoughtless unintended, or perhaps simply unspoken, consequences. The legislature's act here didn't restore privacy nor did it remove bad outcomes: if anything it now just raises questions about equal protection under law, at least on some practical level. It raises the question why some users of computers need such protections as age verification and others don't, and why the licensing terms of the OS are a valid proxy for that need... taking for granted that the stated purposes of the law are the real ones, of course.
A lot of people are not stupid. Age verification is a backdoor for control. I read and did not even bother to comment, it's like yay, that horrendous thing they were trying to do now it's not applied to everyone. I'm also sorry for California, such a beautiful place and full of wonderful people. I hope it will recover one day.
This is not wanted, its duct taping a bad idea even further and i half-wish MS/apple/co sue against it. This may cause lawmakers to bounce back in the wrong direction though.
Yeah, this is fantastic. Should be top of the page. I’m honestly shocked, I’ve fully internalized that everything is corrupt and beholden to big corporations. Somehow, a victory! Looks like the Linux Foundation and EFF pushed back, but they’re not exactly big. Good job, California lawmakers!
Is this serious or sarcasm? They passed a horrible law, now its an internally contradictory horrible law because apparently it isn't important enough to consistently enforce. So, you know. Why legislate it?
There isn't much of an angle here that reflects well on Californian lawmakers, they're still supporting this authoritarian trend of de-anonymisation and rolling back free communication on the internet. They're just going to come back for linux later once the idea of legally mandated PII on account registration is normalised. Although I do see this "In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law" so we seem to be entering a wild space where they're going to try and micromanage this in a weird way.
> now its an internally contradictory horrible law because apparently it isn't important enough to consistently enforce
Law is not an abstract code, but an incremental sometimes futile approach to shape society. They only want a way to hold big corporations accountable to exploiting children. They don't actually intend the effects on the consumer, so they tried to fix on easily changeable effect: "Don't worsen the privacy for people who want it." If you are using e.g. MS Windows, you have given up everything already. They do a lot of "telemetry" and for example everything you typed into MS Word is already licensed to Microsoft.
So what makes kid users on linux so special that they don't need nanny state protection? Are the Californian legislators just throwing them to the wolves? Or are the protections being put in place here not actually important?
Seriously, what is the message here supposed to be about the kids using linux? And why are they so different from kids using Windows or Mac? Are there other safety features we can exempt kid linux users from?
> They only want a way to hold big corporations accountable to exploiting children.
Let me know when they pass actual laws tackling that, then. Even if this law was ironclad, this does not solve the simple factor of using a "verified" device.
You don't fix a problem of society from private corporations by restricting society. You need to actually attack the corporations itself. But governments are sheepish to go after "their own", or people who can bribe them into feeling like one of them.
It's not a great implementation either. But COPPA is an example in the right direction and made companies need to change their algorithms based on the user account's reported age. That's more of the direction to move in.
"Delivers something they wanted" is the most bizarre way possible to phrase "followed through with the majority of a reprehensible agenda and were forced to carve out an exception due to technical constraints and massive blowback."
When people pointed out the consequences this would have for open source, that did not mean what they wanted was an open source exemption. It was just meant to demonstrate just how poorly conceived the law is that nobody at any point even thought about this before it was signed in. Frankly the consequences for open source are not even at the forefront of concerns about what these rushed regulations will do to the world.
It is absolutely a win. If you can't see it as a win because you didn't get everything you wanted at once, then you're setting yourself up for a lifetime of disappointment. Big wins in politics (and most other things) are made out of a succession of smaller wins. Getting unanimous passage of something in a messy legislature is actually quite rare.
It delivered an arbitrary exception to a stupid law. If all someone wanted was an exception for Linux, they don’t understand the problem with this law.
“California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt”
If you allow this pandering to satisfy you, you’re essentially supporting an age verification requirement for all other computing systems. So you didn’t think the requirement itself was a problem, you just wanted to make sure it didn’t affect you?
This is funny to me, because if the age-verification laws were supposed to be a stepping stone toward greater oversight on computing so that AI can be corralled in the future, seeing what is likely to come with billions of spam-bots and zero traceability, then this single decision alone completely undermines it.
reply