Pay no heed to anyone saying anything different, regulators!
It's constitutional case law that there's an implicit right to privacy in the constitution. I don't see a law that you must wear a band with your birthday out in public passing muster based on that. I don't see why existing in cyberspace changes the inherent privacy question, and in fact makes it more meaningful given ease of automation.
Constitutional scholar here! I mean, yes, that's true in a very general sense, but no court has held that age verification to gain access to a service, or even a device, is unlawful in practice.
You can also thank big tech for this because they'll do anything to not verify age on their platforms they want to push it onto devices and OSes.
The reason the US has fairly robust interstate commerce laws is because if you don't you'll have trade barriers between states. Even the most well intentioned internet company can't operate in that ecosystem
Also how is that fine going to work if you don't have any children?
> "Nothing in the bill requires a passport scan or a face scan at setup. It’s self-declared, the same way most apps ask your birthday today, just centralized once at the OS level instead of repeated app by app."
At which point the only move is to relocate the foundation to another country, which will then of course be hit by tariffs and sanctions.
Self-declaration means that the system asks the user to declare if they are a minor. Nothing is verified.
Age verification typically means a system which checks ID or has other enforcement measures to try to verify age.
this is the same rhetorical and political strategy, that there are 'dangerous' people who will exploit your children so please vote for me, the person who cares the most about children and will go after the 'dangerous' people
[1] https://themarkup.org/privacy/2021/04/15/big-tech-is-pushing...
Their website (now offline) also added this page since I posted that comment: https://web.archive.org/web/20260411112604/https://tboteproj... where they claim their website is under "surveillance" because it got a few thousand requests from Google Cloud et al, most of them to a single page. This shows how low their standards are.
Meta is then funding/lobbying alongside a bunch of other conservative groups like Heritage Action, and the digital childhood alliance (also made up of a ton of other conservative lobbying groups)
That's how things used to be and that makes more sense in my opinion because an OS isn't the thing displaying content. It just run whatever it is told to run.
Because children just click through the age gate when it suits them. With this legislation, a parent that purchases the device and creates an account for the child can set the age once and take the decision out of the kids hands. It's a huge improvement without any significant privacy issues. I can't fathom why the tech crowd is having a collective aneurism over this.
>OS isn't the thing displaying content
But the account on the OS is the right place for the single source of truth of properties of the current user.
I am root on my computers. My 11 year old isn’t root on my computers.
I think now even the last person realises that this has nothing to do with age "verification". They simply hate us for our freedom. And it is clearly a move coordinated by private business here; their lobbyists are acting. This is also why it is the same law essentially in so many different countries at the same time. It is quite fascinating to watch, actually. People used to say "conspiracy nut!" - well, the facts are too clear now. That's no longer a conspiracy.
Requiring my kids' devices to advertise their age (or their age "bucket", as if that was a meaningful difference) to protect them is not doing me or my kids any favors.
Anti-money-laundering is a comparable field, as all the AML regulations and laws are ineffective at identifying money launderers, but they're wonderful for verifying (auditing and prosecuting) tax compliance.
As someone who’s implemented AML, KYC, and tax reporting functions in a bank. I think you would be very surprised at how shit they are for tax auditing at scale. Unless the tax man is specifically auditing you, and basically requesting all your transaction details, the reporting that banks do would only allow tax agencies to catch the most brazen and incompetent tax dodgers.
All of the tools however do make much harder to perform money laundering, forcing criminals to recruit and pay huge numbers of naive bank customers to allow criminals to launder money via their personal accounts, using them as money mules. Which then gets flagged and shutdown pretty quick by banks because the behaviour is generally pretty obvious.
Unfortunately (or fortunately depending on your perspective) banks can’t/don’t coordinate on identified money mules or know launderers, so criminals just move on to other banks and repeat.
Why not just signal age ranges? Simple, the way the legal system works is one puts in a benign sounding law, then tweak it every year since the mechanism exists. (scope creep) "Now add city, state", "Now add DOB", "Now add address", "Now add social credit ID number citizen."
- For small children set an RTA header (previous discussions) [1] for any URL that may potentially contain content not appropriate for small children. Give site operators 1 year to implement this. Not counting QA and change control this takes minutes.
- Require app and device vendors to create a properly sand-boxed child account. Pen test it but it does not have to be perfect. This is for small children and default installed applications. If the child visits a URL that contains the RTA header then trigger parental controls. It is entirely up to the parent when that child is ready for mature content. It must be impossible for the child to install any applications, addons, etc... There are a myriad of ways to accomplish this.
- How is this enforced? Same way as any other parenting issue. If there is an incident that involves law enforcement, then social services can investigate and determine if negligence was occurring. When the child is mentally mature enough to deal with all the crap that is the internet their account is converted to an adult account. If the parent is giving the child an adult account before they are ready then the parent(s) go to mandatory parental training. If the child was being bullied or groomed, redirect law enforcement to go after the bullies or groomers.
- Set the laws to be active for any small child that would be under 13 as of the year 2034. Presto! One need not try to confine teens. When these small children are teens they will either be used to the sandbox account or the parent may have converted the account to adult.
As a side note all public and private schools should be legislated to have classes on dealing with all the crap the internet has to offer. Bullies, Cry-bullies, Trolls, Groomers, Scammers, Devious companies, Astroturfers, Gas Lighters, Propagandists, NGO's and so on.
[1] - https://nochan.net/b/Internet-Crap/20230829-Think-Of-The-Chi...
If OSes build a standards-based way to query age of user that is logged-in, where non-admins are not allowed to adjust the age bucket, then parents can configure devices on first use to have an OS-wide enforcement of age controls.
Apps and sites would query the OS, not individual app/site accounts, for user age and act accordingly.
Apps can then lock out certain features like algo feeds and adult content more consistently.
Responsibility for proper use is still on the parent, and no verification process is put upon the operators of sites.
Not sure how I actually think about this; I'm only putting this out for discussion.
Second, storing PII in a world-readable file is unacceptable. Linux is multi-user so the administration needs to be responsible about sensitive data like that! Find somewhere else to stash it!
I will never be compelled to implement this, and would never merge it.
Every release requires quorum signatures by an international maintainer team, and the distro is designed to work offline-first, with some variants not even supporting network drivers in the kernel, so Illinois legislators can eat shit.
Also, we are not a company. We are an independent community owned project. Our code is free speech and I will burn the world down to defend that right.
Truly I dare someone to try to take me to court over this. Would be great publicity for our coercion resistant approach.
They might as well try to mandate code changes to a blockchain and mandate the whole world host them.
Illinois can put up a great firewall like China and search citizens devices for contraband operating systems. The onus is not on tech to enforce it, it's on them.
Adtech companies rent human attention to their Customers. Autonomous agents are an "adulterant" in the adtech company's stock of "raw material". Their Customers don't want to pay for ad impressions to autonomous agents, therefore the agents must be filtered out. A stock of "proven human attention" to rent is what they need.
So, we have these "think of the children" sideshows because they're an easy sell to the public. This is just an early step in the escalating war against people putting their "identity" into the hands of autonomous agents. (I assume we'll have devices measuring biometric feedback in the future, all wrapped-up neatly in attestation.)
As a parent, I'd be very happy with this "age declaration" method, as I also don't think the 'verification' others push for is at all worth the risks. All parents want is to put the devices permanently into a mode that flags it to third parties as belonging to a minor, so they can't just hold up their hands and say "idk they said they're 18" like they do today.
Democrat Senator Willie Preston [D] in the senate
Some states will pass laws that companies cannot show advertisements to minors. So...
I think I'm about to become a bit of a minor myself, at least whenever it serves my interests.
This will end Linux as end user OS, it will stay only in Cloud and containers. Arguably, the goal here is to destroy home PC altogether. maximum we will be allowed is a laptop with endpoint verification and mandatory touch ID, locked boot and non-replaceable hardware. If you think Linux is the end of it – think again. The same crap will be implemented in BIOS/UEFI, on "HW management" level. Essentially, your bare HW only laptop will not even start without you touching fingerprint sensor and allowing it to "validate your age" against – of course government approved – HW manufacturer.
Same with smart phones – it's already here, if you tried to activate iPhone.
And projects like Open/Free BSDs? Government will sure their leaders happily retire and ... well, the community will just "die" naturally.
Why do you think that is?
Edit: I see people don't like this comment, so here's an article about it from Wex law [1] (read under "Roe's Overturning"). The part of the Dobbs decision was removing a right to privacy and promising that it could be revisited in overturning other cases like Griswald.
The 9th amendment has never been used to establish a right to privacy, but then I don't think the 9th has ever been used to establish any right. We've used the 14th in the past to establish that right and now it seems that's no longer good law.
> While it is unclear to what extent that may have on the right to privacy in the current time; it is likely that the case law around this right will continue to evolve with more recent Supreme Court decisions.
You seem to assume that "this is now final, nothing will change after that". Why would you assume this to be the case?
It's actually pretty hard not to have a change be part of a slippery slope. It requires including blocks for further behavior as any subset implementation is hard to sell as not being a slippery slope path otherwise.
The danger of a slippery slope comes when one change enables the next change - for example, a law mandating certain kinds of data collection enables a future decision to discriminate or control based on the collected data. But in this case, no data is being collected, there's no step happening here that enables a more dangerous later step.
If anything, I'd argue this makes it harder to implement more invasive measures later, because rather than arguing that some form of age control is necessary, Illinois will specifically need to argue that age verification is necessary over the existing anonymous system. That's harder than saying "there is no protection for children right now, age verification is the only way forward".
> But they could also just implement verification now, which many governments are trying to do.
That itself is a proof: the voluntary age declaration was and is common on all the services that governments are now trying to force to do age verification, and it wasn't enough.
EDIT: in more general terms, and going beyond age verification thing and over many recent developments in information security, the Internet as a culture is missing an on-line equivalent to a key real-life social feature: the ability to answer with a shocked "gross!", followed by slapping the asker in the face.
The state being able demand a persons age, and gate their behaviour based on that, has existed for hundreds of years so far. During that entire time the requirement to be truthful has also existed otherwise the laws would be meaningless.
All that’s changing now, is figuring out how that extends into the digital realm. I personally find the argument that the digital realm is somehow special compared to the physical realm, and thus certain laws simply shouldn’t apply when “done on a computer”, difficult to reconcile.
Makes no sense to treat it like some unwelcome argument
It is frequently a fallacy because D isn't predetermined by A when humans are involved. If you believe in free will, each of B, C, D are independent decisions. Sometimes we stop at A. Sometimes we pass Prohibition as a Constitutional Amendment, and later roll it back.
As a counter, actual age verification is being rolled out in other places. I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. Between the anti-porn types and public demand for some kind of regulations on social media, regulation of some kind is inevitable.
Our actual choice may only be what type of restriction we can live with, and I much prefer this type to the kind that requires websites to demand my id and photos of my face. Especially since some implementations of this concept (the California one, I think) declare that websites aren't legally required to look deeper than the attested age, which is a very nice feature.
Mind you, I don't know why the legislators are bothering mandating OS support for these features. It would be much easier to mandate that websites support the feature, make it clear to them that supporting the feature appropriately will free them from liability for children accessing content, and then wait as users demand that their OS support the feature.
It is impossible to win a battle you stop fighting.
I don’t even get that far, the proper response to my operating system asking me if I’m a minor or not is: fuck you. It isn’t a harmless question. We aren’t friends, I don’t want an algorithm of news and content, it’s an OS.
Parents aren't interested in the nuance of good and bad guys, they see the internet, think it's too much trouble to keep around, and want it blocked. I suspect politicians are just mimicking this sentiment after talking to thousands of parents
As for lobbyists: I think we can probably determine the key lobbyists, e. g. if we map the data and names. And ideally also the money given to them. Ultimately they are faceless though, because corruption is easily exchangeable. The issue here is systemic though. The US "democracy" no longer exists due to that corruption. It is not rule by the people but rule by bribery.
This isn’t for the protection of kids. It’s for the protection of profits by surveillance capitalism.
If the intent were to actually protect children, then this would be what was done.
"Protect the children" is just a subterfuge to get electorate support for voting for the foundation for a "1984 thought crime" style monitoring of the internet.
It just happens that "protect the children" and "monitor everything everybody says on the Internet" dovetail nicely with the agenda of the adtech companies, too.
but that's not this law. This law requires self-declaration by whoever creates the accounts on the device.
Don't ever for one second pretend this is about anything else.
Any parents who are pathetically absent from parenting their kids, well, they can just go right on ignoring their kids and letting the kid themselves put in 9/9/99, and consume all kinds of inappropriate crap.
This particular law is respecting everyone's rights.
Step 1: get easily passed, simple looking laws passed to 'protect the children' Step 2: 'oh look at all these people bypassing the law. It's so simple for a child to watch porn with this.' Step 3: increase the requirements bit by bit on the verification
By letting something simple pass, they can claim it's not thst bad, and anyone who argues against it is being hyperbolic.
> Requiring my kids' devices to advertise their age ... to protect them is not doing me or my kids any favors.
Idk about you, but it'd be doing me favors because my kids will not be physically able to use the most addictive platforms that exist today in their current form. It would be a major disruption to the behavioral manipulation that Meta, TikTok, and X do.
Modern social media is delivered through 'apps' which are like web browsers, except without ad blockers or privacy settings, and with push notifications to make them more addictive, and they only show one website, and they're each 5x the size of a web browser for some reason.
This was tried in the past:
Don’t make a target of yourself, there are countless ways for a government to make your life miserable.
Users need to see that the people in positions of influence in FOSS projects they trust are not afraid of this bullshit.
I -hope- someone is stupid enough to take a case like this to court so we can establish some much needed case law here. These overreaches deserve to be contested.
Wait, which constitutionally protected right is that? I'm an attorney and constitutional scholar and am particularly interested in what right you believe is being violated here.
And where code is speech, is a distribution speech? There's a lot of places for this to go sideways on you personally.
"never show fear" and "never engage intelligence" are two different things. Understand what people will do in response to your actions, and act accordingly to achieve the outcomes you want. Please by all means fight the law, and do so intelligently in a way that will actually help.
The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
You have precisely zero additional speech rights as a FOSS project than any other organization has. If "free speech" was a valid defense for you, then Meta would be doing the same.
> The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Being unable to comply is not a valid legal defense.
> Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
This is the law in various places under various mechanisms. It is handled by putting people in prison or taking people's assets.
Sure it is. Lawyers even have a pithy Latin maxim about it: lex non cogit ad impossibilia.
Also reach out to the EFF, who may be able to help/advise, especially if you genuinely want to fight this.
This is a terrible law. That doesn't mean it's not a law, and courts do not look kindly on people subject to their jurisdiction (which unfortunately often includes state laws to people in other states) who try to dodge the responsibility the court thinks they should have.
"Operating system provider" means a commercial or
non-profit entity that controls the Internet-enabled device's
operating system, including the design, programming, or supply
of operating systems for the Internet-enabled devices.But I hope they try this. It will be funny to watch the public humiliation of how hard it fails at scale.
I mostly just want to make it clear this type of legislation is unenforceable and a waste of everyone's time.
This is probably all completely irrelevant to StageX since it's a distro designed to be used in containers, AFAICT.
It's not implementing age implementation, but can be used as a place to store a DOB in an age verification system.
Though if you don't live in IL it is unclear how this affects you.
https://abcnews.com/amp/US/children-recruited-criminals-indu...
If your OS doesn’t access the internet or isn’t intended to run browsers / social apps, then you are outside the scope of this legislation. That would be a bit like requiring a toaster to ask for your age before letting you operate it.
What does it mean to "found" a Linux distro? Can you describe it?
LPisGood•1h ago
>no algorithmic feeds for minors by default
Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?
stevenalowe•1h ago
however
"nothing in the bill has teeth against someone with no business presence in Illinois"
gh02t•46m ago
FuckButtons•41m ago
LPisGood•9m ago
monocasa•1h ago
Basically the bill defines
> "Operating system provider" means a commercial or non-profit entity that controls the Internet-enabled device's operating system, including the design, programming, or supply of operating systems for the Internet-enabled devices.
Which is an extremely broad definition that could be interpreted in a whole bunch of ways.
koutakun•59m ago
harvey9•58m ago
duped•55m ago
The relevant text doesn't call it an "algorithmic feed" for what it's worth. They define an "addictive" feed and it's essentially any kind of personalized recommendation.
> "Addictive feed" means a website, online service, online application, or mobile application, or a portion thereof, in which multiple pieces of media generated or shared by users of a website, online service, online application, or mobile application, either concurrently or sequentially, are recommended, selected, or prioritized for display to a user based, in whole or in part, on information associated with the user or the user's device, unless any of the following conditions are met.
kube-system•38m ago
kube-system•50m ago
That's a paraphrasing of what law says. The law is more clearly defined:
> "Addictive feed" means a website, online service, online application, or mobile application, or a portion thereof, in which multiple pieces of media generated or shared by users of a website, online service, online application, or mobile application, either concurrently or sequentially, are recommended, selected, or prioritized for display to a user based, in whole or in part, on information associated with the user or the user's device, unless any of the following conditions are met: (1) the recommendation, prioritization, or selection is based on information that is not persistently associated with the user's device and does not concern the user's previous interactions with media generated or shared by other users; (2) the recommendation, prioritization, or selection is based on data controlled by user-selected privacy or accessibility settings or technical information concerning the user's device; (3) the user expressly and unambiguously requested the specific media, media by the author, creator, or poster of media the user has subscribed to, or media shared by users to a page or group the user has subscribed to, provided that the media is not recommended, selected, or prioritized for display based, in whole or in part, on other information that is not permissible under this definition; (4) the user expressly and unambiguously requested the specific media by a specific author, creator, or poster of media the user has subscribed to, or media shared by users to a page or group the user has subscribed to as described by paragraph (3), be blocked, prioritized, or deprioritized for display, provided that the media is not recommended, selected, or prioritized based, in whole or in part, on other information associated with the user or the user's device that is not permissible under this definition; (5) the media is direct and private communication between users; (6) the media is recommended, selected, or prioritized only in response to a specific search inquiry by the user; (7) the media that is recommended, selected, or prioritized for display is exclusively next in a preexisting sequence from the same author, creator, poster, or source; or (8) the recommendation, prioritization, or selection is necessary to comply with the provisions of this Act. "Addictive social media platform" means a covered platform that offers users or provides users with an addictive feed as a part of the service provided by that website, online service, online application, or mobile application.
Marsymars•48m ago
You could argue about the language and the meaning of "algorithm", but for practical purposes I'd consider a manually-curated feed to be non-algorithmic.
delecti•45m ago
Phrases can have meanings beyond just a naive combination of the words in them. And indeed "algorithmic feed" in the bill means what what we all understand that term to mean when we aren't paralyzed by pedantry.
> Under the law, [...] these users will only be shown content they request or search for or that is posted by a creator or friend they follow.
You may disagree with the motivation behind the bill, but you do the discussion a disservice to assume the people writing it are incompetent enough to not define their terms.
spullara•40m ago
wtallis•3m ago