I am so puzzled by everyone who objects so strongly to these operating system based opt in systems; all it does is provide for a way for a parent to indicate the age of a child's account, and an API for apps and browsers to get that information. If you're the owner/admin of a system, you get to set that information however you want, and it's required that it only provides ranges and not specific birthdays in order to be privacy preserving.
The government legislating APIs is an uncomfortable precedent given the culture wars that are raging right now. There seems little reason to expect this will stop here.
Are these illegal operating systems?
Either you or someone else mentioned this talking point the other day, I asked for even a single example of an OS maker being sued over this successfully, and I got nothing.
I work in aviation, a highly regulated field. And that's a good thing. It does take some work to regulate well; there has been a migration in aviation to more prescriptive regulation about how things need to be, to less prescriptive like what the ultimate performance needs to be. But yeah, the aviation regulations aren't that you have to implement something a specific way, but that you have to be able to show that your aircraft has no more than a certain probability of catastrophic failure (where the probability varies base on certain things like the size and type of aircraft).
For this age verification law, all that is required is that there is an API provided for this purpose, and there is a way for the owner of the machine to set up user accounts with age information indicated, and that the APIs need to provide several rough age ranges, not specific birthdays.
It might also include some additional text like "we have decided to collaborate with systemd to integrate this proprietary binary blob, to maximize the reach and eliminating any pains in the setup process caused by the vibrant ecosystem of package managers, while at the same time avoiding disrupting the development process of the Linux kernel".
We shouldn't object to a reasonable law just becasue it might, theoretically, pave the way to an unreasonable law.
In fact, this is put in place as an alternative to the kind of law being enacted elsewhere, right now, which is much worse; the ones requiring ID based verification for accessing many online services. This one provides an alternative solution, which is far more privacy preserving, and leaves all of the actual power in the hands of the owner of the computer.
Meta being behind all of these efforts makes it incredibly suspicious, especially given the New York law is ridiculously more invasive than the California one. It sure makes it seem like there's likely a larger plan here that this is merely facilitating.
So I don't think I can still buy it at face value that California's version is a good-faith attempt to balance privacy and child safety, even if that's what it is in the eyes of the legislature, given who's actually behind it and what else they've been pushing for.
Yes, the New York proposed law is far worse, and we absolutely should be pushing back against that. And Facebook doesn't care, because they only care about moving the liability onto the OS vendor, not on actual privacy.
But still, just because this was supported by Facebook doesn't make it bad. Sure, Facebook doesn't care about privacy, but they do care about not being liable for this, and in this case, they're right, it is actually much more efficient to centralize this function in the OS, and it happens that that way it can be done in a privacy preserving way as California's law shows.
At any rate, why legislate operating systems when all of the harm comes not from computers themselves but rather from certain websites? And there are already mature solutions for controlling access to specific websites. Client-side parental controls for internet access have existed for decades, dating back to Surfwatch from the Win95 era. A credit card requirement would also effectively impose an age filter.
I didn't say just because Facebook supports a law that it makes it bad.
I said the fact that Facebook has been lobbying for such legislation across a ton of jurisdictions, that makes it suspicious.
I stand by that. This is suspicious, whether it's ultimately bad or good.
It definitely makes it more deserving of a closer look. I think that's undeniable.
It requires that operating systems provide a way, at account setup, to specify the age or birthdate of a user, and provides an API for indicating which age range the user falls in (under 13, 13 to 16, 16 to 18, or over 18) to an application, so the application can use that information to comply with any laws or regulations relating to the age of the user.
It doesn't make any requirement that the parent actually truthfully put that information in. It doesn't require that anyone verify the information. It doesnt provide for any requirement that a child not set up a user themselves. It explicitly calls out that there is no liability on any of the parties if one user uses a computer under another user's account.
So all it's doing is saying that there must be a reasonably accessible mechanism for a parent to indicate a child's age so that rough information about which age range the child is in can be provided.
Now, is it perfect? No.
It does seem a bit over broad as there are lots of things which be classified as computers uner this, like routers, smart TVs, graphing calculators, cars, etc. Having to provide account setup with age and an API to accesss it in all of these environments could be a bit of a lift in the time frame given. And it doesn't leave a lot of time for something like standardization of Unix APIs between operatings systems, so for systems not running graphical environments I'm sure we're going to get a bunch of different solutions from different OSes as everyone sticks it in a different place and provides a different way to access it. And this would need to be a new feature added into long-term supported maintenance releases operating systems.
So yeah, could it have been done better? Yes. Is it likely that they are actually going to fine OpenWRT developers if they don't implement this? I doubt it; it's pretty clear that the legislative intent is desktop and phone OSes, and other mass market consumer oriented devices that might offer app stores.
So yeah, I see some issues, but overall this seems like the right way to do things; just provide a way for parents to set an age on their children's account, and then provide that to any apps that might need to do age verification. That's it.
I don’t see why we should burden OSes this way. An App Store does all that better.
Because it's inverted. If it's opt in on the parent's part anyway then there's no reason to send additional information along with the request. The service should rather send additional information about content categorization alongside the response.
So what reasons can you imagine for it to be designed in such an obviously unnecessary way?
Right now the only one I'm aware of is RTA which theoretically applies on a per-request basis although I expect that approximately all present usage is uniform site wide.
Such a system is clearly the technically superior solution. It regulates the provider as opposed to the client, forcing the market to provide a workable solution for concerned parties while the client maintains complete control over how things are handled. It further steers well clear of any slippery slopes by not mandating the broadcast or collection of personal information.
Perhaps important from a liability perspective, it places the onus on the client as opposed to these latest attempts to shift it squarely onto the service provider. Right now the legality of serving content across jurisdictional boundaries is extremely convoluted. With ID or age reporting laws it clearly becomes the service provider's responsibility. In contrast, a mandatory metadata standard for classification would create a situation in which it is clear that the legal responsibility (if any) to appropriately configure filters falls to the client.
Of course such a solution would be of no help to the anti-porn and pro-surveillance lobbies. That's the entire point.