I don't think it's a very well thought-out law. But realistically this will end up as setting some env variable for your docker containers to assure them that you are 99 years old. And yes, maybe transmitting a header to docker hub that you are 99 years old. Probably configured via an env variable for the docker cli to use. It's stupid, but nothing a couple env variables wouldn't comply with
The real issue is when the law inevitably gets expanded to get some real teeth, and all the easy workarounds stop being legal
Edit: as folks have pointed out, the attacking application doesn’t actually have to be running while the age-transition takes place. The attacker just has to have logs from before and after the age transition, and then they can narrow the birth-date down.
I mean, the app can query on a weekly basis, and then if you go from “under 18” to “over 18” it knows the week that you were born in. But, if the user was already an adult when the logging started, there isn’t a transition to go off.
I think the intent was for the OS to know the user age, but only provide an age range, so it could automatically upgrade people as they aged (but I could be wrong about that).
I think this is the big vulnerability in the scheme. This information is easy to track and log, so it is basically equivalent in the giving away the DOB of everybody who is currently under 18 (at least, everybody who uses the system as intended). In the long run that’s everybody.
We could have a discussion about whether or not it would be fine for services to know every user’s DOB, but it is clearly giving away more information than the law intended.
> There is only one mandated bracket for everyone who's at least 18, preventing that attack on anyone who starts using your software after their 18th birthday.
I don’t think that fully recognizes the size of the problem, “using your software” is fuzzy. Companies get bought, identities get correlated, ad services collect and log more information than needed. I think it is better to assume the attacker will have logs of these queries from the start date of a person’s first account.
Most of the issues only arise because in the bill "operating system", "covered application store" and "application"/"developer" have very loose definitions that match lots of things where the law doesn't make sense.
Which will happen. The road to hell is built one brick at a time.
I honestly think the California law is well intentioned (in the sense that it just asks the OS to attest the age of the user, so, lawmakers probably thought this could be done in a privacy-preserving and minimally annoying fashion), but it seems very focused on desktop and cellphone use-cases.
> These laws can, and almost certainly will, get worse. New York's proposed Senate Bill S8102A explicitly forbids self-reporting. The state Attorney General will decide how to enforce it. For example, to use Linux, you might need to submit a driver's license.
Great job politics!
Like lots of laws that are being written nowadays by octogenarians, aimed at strong arming bigger tech companies into designing things differently at the expense of everyone smaller which ironically ends up curtailing our basic freedoms, privacy, etc... even when the intent was otherwise.
Then again I have yet to meet a politician that actually cares as long as: "this looks good for my campaign".
Regulating big platforms that affect billions of people is one thing but I really wish they would write laws actually discriminating between those platforms and everyone else.