California lawmakers unanimously pass Linux exemption from age-verification law
tomshardware.com
tomshardware.com
But 2 years from now a baseline has been established where the need to know your age when using a computer is taken for granted, and it's revealed that self-reporting isn't working and gasp there was this one kid in the news about something bad happening.
This is how it goes. This is one of the reasons the anti-gun crowd is so adamantly opposed to virtually everything. I'm not advocating anything with respect to guns here, but "sensible" measures were broadly supported and then turned against the owners who acquiesced.
An "exception" is two faced in this case. It implies Linux needs an exception to begin with and that the bill itself isn't absolute garbage and a direct attack on general purpose computing. Again, they establish a baseline with something that people are ok with.
So really, both concepts can mesh.
After all, once compliant an adult is then not restricted.
> These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope. […]
> Windows, macOS, iOS, and Android remain fully in scope, with age collection required at account setup from January 1, 2027. A later July 1, 2027, deadline applies to devices set up before January 1. Whether SteamOS is in scope isn’t yet clear: its Arch-based system components are open source, but Valve distributes the image alongside the proprietary Steam client.
I’m slightly confused about Android, I thought Android the OS was open source but then enough functionality is added by Google’s app store to keep it sort of under their control for the most part…
The reason Steam OS is a gray area is the question of what constitutes "the OS". For Android, you can't run apps without the components in question, so it's pretty cut and dry. Steam OS, you can technically use it without Steam: switch it to desktop mode, disable Steam, and run it as just an Arch variant; you can even launch games installed via Steam if you really want. But in practice nobody does that, because you would just use another distro if that was your goal. So, is Steam part of "the OS", since it's the main thing you see when you boot by default, and probably the reason you use that distro? Or is it just a prominently featured application?
edit to add: Here's a graphic depicting the general shape of Android. Pretty much everything except the kernel can have closed source modifications (and even the kernel will typically have proprietary drivers and firmware blobs): https://upload.wikimedia.org/wikipedia/commons/3/32/AOSP_And...
So the only thing that really changes in the Steam case is the timing of the question, and possibly how and where the (unverified) answer is recorded.
Would always install some variant, think it was "pretty cool" for a few days, then revert back to "whatever MacOS was offering" (for my daily driver).
----
2026: I just finished building my third Ubuntu Linux machine, this year (gave the first one to my brother). An Ubuntu running a 5070Ti is now my main operating system.
Now we've decided that if we don't talk about something, people won't get curious about it. Sadly, without being properly taught how to be safe, that generally ends tragically.
1200 deaths a day from diarrhea in India.
Put it in perspective.
They use it as a metaphor to attempt to make an argument about a different, actually real, situation. My argument is this is pointless because no real world situation will ever meaningfully resemble the trolley problem.
The correct answer to the trolley problem is STOP THE TROLLEY. "You can't do that!" "Why not?" "because magic" "well how do I know this magic is there?" "more magic!" etc etc.
What do you do if the dragon demands a sacrifice or it attacks the town? You fight the dragon.
I hope you're arguing out of perversity, not conviction - such is valuable, and i did have to think for a minute. I agree that lateral thinking can be productive.
> Someone brave attempts to jump onto the moving trolley, risking their own neck
This is a completely different problem. The whole point of the trolley problem is to attempt to justify the sacrifice of the few for the good of the many.
The entire framing is about other people dying, not whether or not you would sacrifice yourself.
Globally, 1.2 million people (all ages) die of diarrhea every year.
India accounts for 120k deaths of children under 4 or roughly one fourth of global D related deaths or 328 deaths per day.
Assuming a similar ratio across all ages, India must account for 300k D related deaths every year of roughly 820 deaths. Not great (obviously) but at least it only accounts for 1/4 of all D deaths, not 1/3rd.
Edit - worth pointing out that India has 1.4B out of 8B humans globally or a little more than 1/6th.
https://data.unicef.org/topic/child-health/diarrhoeal-diseas...
https://www.joghr.org/article/75428-evaluating-india-s-inten...
And part of the problem is that our entertainment media (movies, shows, video games) pretty much trains anybody who has not been taught gun safety in real life to reflexively point a gun at somebody when it is picked up, often with their finger already on the trigger (although some movies are better about this now). People see a gun on the ground, may not even know its real and think its a toy, "Hey guys look what I found" and immediately aim down the sites at their friend.
I dread the outcome of practical safety lessons because, the moment you give a classroom guns, then some teenage edgelord is going to pantomime shooting their buddy, or escalate a playground beef.
People do not work the way you want people to work :-(
May i offer an alternative? Make gun ownership a tedious bureaucratic procedure. Reams of paperwork will filter out many stupid. Stupid exist who can fill forms, but it's a smaller set.
The cavalier phrase "tit about with" is exactly the issue. People do so due to a lack of education about gun safety.
> I dread the outcome of practical safety lessons because, the moment you give a classroom guns
OP didn't mention practical lessons, and giving real guns to school children would be idiotic. You don't have to actually have a gun in your hand to learn what not to do with one should you encounter it. We have MYRIAD examples of non practical instruction (things like sex ed, chemistry [what happens if sodium is dropped in water and why?], physics [hey kids, lets visit a live nuclear reactor!]). If anything, the best way to dampen the glamor of guns instilled by media would be to make it a boring school subject.
> Make gun ownership a tedious bureaucratic procedure.
In many cases, it is. In my state, you can't hunt with a gun (or even a bow I think) without a mandatory gun safety course, and I needed a background check to buy the rifle in the first place. A background check that required a form.
Not to say there aren't loopholes, of course, and I think most Americans agree with common sense gun laws to implement more scrutiny.
I've never hidden my interest & passions, and I think the world is a better place when people are proud of what they enjoy. We're people first, after all.
And most techies are already primarily on Linux and its derivatives.
Linux has gone from attracting hippies to openly endorsing corporate closed-source products, something something live long enough to become the villain.
The result looks to me like Facebook will ban access from non-approved OSes like Linux. Android will still be allowed, GrapheneOS probably not.
Which OS is better for gaming? Windows or Linux?
A: Linux, because you can't play League of Legends
Or to things that we need, like medical care, government interactions, and financial services.
People shouldn't have to choose between safety features like those in Graphene OS and participation in society.
I wonder how feasible is it to use a separate phone and access it remotely from the main phone.
Think of the children!
• 2012: <https://memex.craphound.com/2012/01/10/lockdown-the-coming-w...>
• 2003: <https://www.fourmilab.ch/documents/digital-imprimatur/>
• 1997: <https://www.gnu.org/philosophy/right-to-read.html.en>
Kids don't buy phones and computers, parents do. When setting up the account for the first time, the parents could set the account to be an "underage one", all the apps, browsers, etc., would get the USER_IS_UNDERAGE flag and filter content according to that. No need for every site to ask and verify the age, just set the date of birth at the time of purchase, set a parental password (for possible future changes, reselling, etc.) and prohibit formats/wipes/factory resets without a parental password being entered. The clerks in telco stores could even help with the first setup of that.
Same could be easily implemented in linux, via some user flag set by the su/sudo user during the first eg. ubuntu install.
This preserves privacy better by keeping more information about the user local, and gives people better tools to decide what metadata categories they want to filter- for their kids and for themselves.
As one example, the Internet Content Rating Association (ICRA) (and to a lesser extent the prior Recreational Software Advisory Council (RSACi)) had a rating scheme that allowed sites to provide a default rating label that was then overridden for individual pages and resources using <meta> tags and RDF-based labels. For example, Tumblr could set a family-friendly default rating and append a different rating on specific user pages, images, or ads.
An even more granular scheme could be applied via HTML attributes which would allow an individual section, image, link, or text snippet to be marked e.g. as "sexual", "violent", "substance use", "spoiler", or even "unknown" for unreviewed user-provided content. Then leave it up to web browsers to choose whether and how to render elements with these attributes. (Hidden entirely? With censor bars? Pixelated?)
There would be substantial logistical and regulatory challenges to get websites to comply, but it doesn't seem substantially harder than the current age verification schemes.
The solution is obvious: you show it on the front page if the user is 18+. However, your proposal deliberately forbids this and says the front page must be the same for everyone. Which leaves the other two bad options.
Without any requirement for verification, it'll be completely up to the parents to decide what their child will see, while the services will only get the minimum information needed. It'll basically make parental control easy, but still in the parent's control.
I don't understand why you think this is true when I specifically described a label that is applied to "an individual section" of the page.
To be more explicit: Today, each post on the Reddit front page appears in its own container element. If an 18+ post's container element could have some kind of "adult-content" attribute set then some web browsers could render the whole front page normally with the exception of that individual element. Perhaps they could black it out, collapse it, display it with a pixelated overlay and a "Request Access" button, whatever the browser supports and the device administrator prefers.
> The solution is obvious: you show it on the front page if the user is 18+. However, your proposal deliberately forbids this and says the front page must be the same for everyone.
Why do you think that my proposal requires that the front page must be the same for everyone? Providing different views to different users is the entire point of every child safety law and rating scheme I've ever seen. I'm merely saying that my preferred approach would be to mandate that potentially objectionable content is semantically annotated in the HTML somehow, so that each user's browser can apply whatever view restrictions (if any) the device's owner wishes. I think this is better than mandating that web browsers send personal information to every web site they visit and also mandating that sites pre-filter the content they send back.
First, leaking a device's content filtering settings is not the same as leaking a user's age bracket. For example, if the server identifies a web browser that isn't loading tags annotated with "sexual-content" that might indicate that the user is a child but could equally well indicate that they're a corporate office worker, religious, or anyone else who prefers not to see such content at the moment.
Second, if the standard defined multiple semantic tags or levels (e.g. violence, extreme violence, substance use, unknown, etc) then this gives more granular control to device administrators who may care more about some types of content than others.
Third, web browsers wouldn't even have to leak the content filtering settings. For example, perhaps an administrator could configure the web browser to render content overlaid with a semi-opaque blur, in which case the server would not know.
Fourth, and this is more philosophical, asking websites to provide more information to the device so that an admin can do their own filtering leaves the choices to them. Whereas if the only way a device admin can filter content is to submit the age of the device's user to a third party so the third party can decide how to pre-filter the content it sends back, that gives an uncomfortable amount of control to platforms and regulators.
A parent can change the setting in the OS and have every website and app comply with the OS setting is such a better situation than having to deal with a patchwork of content blockers, social media account settings, and parental controls that leak like a sieve.
Realistically, parents often don’t really have a good way to know what websites and apps you sign up for if you don’t have a crazily locked down device. Parental controls are complicated for non-technical parents and they usually know less than their kids do about the Internet.
A global OS age gate solves a lot of those problems, especially since OS-level controls are way easier to enforce and lock down compared to other methods.
But the objective of these regulations aren't what it says on the tin.
Also, the browser flag that indicates no consent already exists: https://globalprivacycontrol.org/faq
Glad it is now in place.
My family and school failed to stop me getting my hands on booze, fags, drugs, and porn. Teenagers are fundamentally not controllable. The Amish and the Mormons are having some success, but that's likely not what libertarians want to hear.
What you describe is the status quo. Parents and schools are already, variously, giving The Talk, confiscating devices, enabling internet filters. Society deems these measures ineffective. In tiny part, that's a skill issue, but mostly it's just trying to cut down a tree with a herring. Again: teenagers.
You may, of course, sulk about age restrictions on alcohol. Prohibitionists would like that. Keep your out of the contested zone, make them look reasonable.
If you want to stand on your principles, try seasteading. But I'd appreciate coherent contributions to the debate, to offset the excesses of the pearl-clutchers and the spies.
https://matduggan.com/you-know-gdpr-is-good-based-on-who-hat...
I hold values which lead to conflicting views and opinions, which i therefore hold lightly and attempt to balance. No action or inaction is a perfect solution to a wicked problem.
- yes, people should be free to do whatever they want with their computers - yes, people should have the freedom to exercise their independent choices - unfortunately, there is no such thing as independent choice (unless, maybe, you were already living as a hermit) - it is ostrichism to pretend that zuckerberg (to use him as shorthand) has not unilaterally and unaccountably engineered society to his own ends - society has shown considerable appetite to rein him (etc) in, for legitimate reasons - i do not, generally, support banning harmful things when stakeholders exist who favour those things - i also do not think that the existence of stakeholders who benefit should excuse all harm - therefore, this ugly compromise is approximately no worse than the least bad course of action or inaction
Things are shit. We are in shit. For all of history, we have always been in some or other grade of shit. We can sometimes choose between different piles of shit, but "not being in shit" is not an option. I find horseshit less objectionable than catshit, and so do many others; so here we are, actively jumping into horseshit.
Oh no! Anyways…
Then we decided we should punish ourselves rather than expect/require big business make safe products.
excellent! won't have to worry about my kids wanting a FB account -- it just won't be accessible
E.g. systemd's birthdate field https://github.com/systemd/systemd/pull/40954
I also personally disagree with the change, I think the OP has gone ahead and implemented what they wanted but not considered the actual ways it will be used. The PR shouldn’t be merged until the laws have made a bit more progress and it’s clear what they’re _actually_ implementing.
Think about it - if every phone you got asked you at first config "are you over 18? If not ask a parent to set up this device" then everyone would know about that capability and "think of the children" would be met with "parents can just click a button"...
* https://www.apple.com/uk/child-safety/
* https://families.google/familylink/
* https://www.microsoft.com/en-gb/microsoft-365/family-safety
You already have the ability, all parents do, that some (or most) haven't is why this crap gets proposed in the first place and used as a justification for invading everyone's privacy.If (some) parents actually parented instead of abdicating that role to the state/education system then this tripe would get far less traction - though cynically they'd just switch to the other argument they always trot out.
Unfortunately, things haven’t worked out that way so far.
Even that might be too much. As you’ve insightfully illustrated, 1 law is a slippery slope to infinite laws. Next thing you know we need a license to toast bread in our own damn toasters.
We know poeople are terrible with guns so we...um..try to protect their freedom to be terrible.
These arguments are about values not control gates.
https://commandlinux.com/statistics/linux-kernel-contributor...
"COVERED APPLICATION STORE" DOES NOT INCLUDE: (I) A CODE REPOSITORY PROVIDER; (II) A CONTAINERIZED SOFTWARE DISTRIBUTION; OR (III) AN ONLINE SERVICE OR PLATFORM THAT DISTRIBUTES ANY OF THE FOLLOWING APPLICATIONS IF THE APPLICATION RUNS EXCLUSIVELY WITHIN A SEPARATE HOST APPLICATION: (A) AN EXTENSION; (B) A PLUG-IN; (C) AN ADD-ON; OR (D) ANY OTHER SOFTWARE APPLICATION.
What am I missing here?
It just felt like the bill had the goals it had when it was created, and the broader cloud of "gee, if people implement this a certain way, it could have unintended consequences" was completely ignored. But don't worry, one of the co-sponsors proclaimed. near the end of the hearing, that they had a Masters Degree in Computer Science and worked on operating systems in their career, so they made sure to let us know that we were over-reacting.
The other thing that really pissed me off was it was rumored my states bill was going to get an open source exemption. However, they waited until the end of the hearing to introduce all of the amendments, including the Open Source exemption. The proposed amendments were not publicly visible on the bill page or the page about the committee meeting for that day. This ended up being an excellent strategy to sway other committee members [3], since they could just hand wave the bulk of us as "concerns resolved". It was quite illuminating to also see media lobbyists come in and verbatim just state "hey did you get our proposed amendments?" and then without much reading of them at all, they were ratified during that session. Lesson learned: the moment there was a rumor of amendment, I should have made a considerable effort to get my hands on that text ahead of time since for the implementation concerns I raised, I was still unhappy. I'm not quite sure though how much of a difference it would have made though, since at least 30 other people fell into the same trap.
Anyhow, hopefully my long-winded Sunday morning post was useful to someone in the future either when dealing with compliance, a version of the bill in their own states, or the federal government's attempts to do a similar thing. I confess that I have been lazy and not remotely done any due diligence on that federal bill (https://www.congress.gov/bill/119th-congress/house-bill/8250... / HR-8250: Parent's Decide Act). I encourage others to be better than me and contact their representatives, assuming it isn't already on the fast track to becoming law.
[1] at least, for smaller businesses -- big tech won't care! I think it was something like $6,000/pop, which is chump change for big tech and will be negotiated during settlement talks.
[2] Okay, you can check the user agents. But who wants to need to maintain or pull in a list of enforceable user agents! What happens if someone is spoofing the UA and suddenly they end up in my list of "must check" UAs (or inversely, !(not must check)). How long does one reasonably wait for the API call to time out? What about running the app on Wine? And most importantly, what if someone that doesn't care about Linux ("okay claude make my website legal no mistakes") is in charge of implementing this logic, or the library that people will end up using for compliance.
[3] Assuming they cared. The vote was largely amongst partisan lines, some people had clearly looked checked out the whole time, despite the abnormally high numbers of their constituents being there that day.
As long the government sites, banks, etc. work (who already know my personal detail due to the nature of their services and the contract we have), nothing of value is lost, tbh. Including this site and this comment.
And then further into the text it's clarified that there also isn't a specific list of open licenses, as the terrible headline would have you believe, but instead a description of what is considered open
With the caveat that I haven't read the actual legal text, this seems to be an eminently sensible law (it'd be better if it weren't needed, but here we are).
In summary: not a Linux exemption, and not an exemption for a specific list of licenses either.
This law was never going to succeed at those aims.
What I meant is that if we take the law as a given, then the exemption we are discussing here are very good and sensible. I wish they weren't needed, but given that they are, the language seems sensible.
I really struggle to understand what you're trying to say. Is it that since the original law is dumb, we should accept no remedy short of getting rid of that original law? I think you'll find making progress in the real world very hard with that attitude.
Explain how a privacy that protects you and me will somehow not protect a pedophile. How does that work?
I am FOR privacy. I don't think it can be done.
I do not want to have any information at all stored anywhere, encrypted, decentralized or otherwise. Nada. Its just text. I want to just be a number in everyone database. I want to be able to spawn millions of numbers that will never be related to each other. My ideal privacy world is a world where bots thrive.
Just go to face to face discussion if you care so much about who you are talking to.
I think that it will, and that's okay. The US Bill of Rights necessarily protects criminals as well as innocents. "The optimal amount of [crime] is non-zero." (https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...)
However harms based on sites having lots of personal data on their users are only part of what many people are concerned about. There are various categories of apps and sites that are legally required to not sell to/serve children. There are also things that are not illegal but the majority of research finds is bad for young children, so apps and sites may want to keep young children out unless a parent approves. Privacy laws don't help with any of that.
What if you are interested in developing your own OS (a task that would have been monumental but may become trivial with LLMs in the future)?
Why is the proper level the OS? Why not the browser or the hypervisor?
Or perhaps manufacturer should remember your age? What if hardware is resold? We would need a hardware cadastre! A global hardware cadastre would unite all jurisdictions in a power bloc eventually. It starts with daily computer/laptop, then domotics, then digital door locks, and before you know it the bloc-global hardware cadastre becomes authoritative, and the reference for property ownership.
Is there even a proper level?
Colorado legislation, for example, won’t change if the OS license changes.
Considering macOS is already built on an OSS kernel (Darwin), and that Apple no longer charges any money for OS upgrades, I could imagine a world where Apple just shuffles some components around and announces macOS is now fully open source. Just so happens to require a lot of Apple chips with proprietary firmware, but hey that's for security reasons. Trusted enclave and all that. Nothing to see here. We'll take the exemptions for FOSS now please.
(Of course the real reason Apple won't do this is that they already have almost all of their user's ages via Apple ID, and being a trusted age-auth intermediary actually plays to their core strengths really well.)
"From now on all kids will become linux natives. The decade of the linux desktop is coming!"
I teach technology K-8. So I have a front row seat to observing how the next generation navigates this new digital wasteland. Due to the aggressive censorship and locked nature of their computing experience at school, think Go Guardian, they have become experts at using Google workspace to make art, comics, communicate with one another in class etc.
My point, the next generation really will become adept at using Linux IF the system is so locked down that it's all that's available. Humans adapt to their environment, no matter how harsh.
" third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope."
Or also BSD, ReactOS, hobby OS #24562 etc... ?
From TFA
> These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
The article then explicitly cite "Debian, Fedora, Ubuntu, Arch, and the BSD family".
There is also another exclusion for libraries and software from a packages managers like apt and pacman.
So from my understanding ReactOS, hobby OS but also CP/M, FreeDOS, Haiku or Collapse OS...
I have not read the other proposed laws in this category but after reading the California law, I found it was so vague that my interpretation is that any operating system where the owner, well... actually owns the system is already in compliance. The law requires a mechanism where the OS can provide owner age data to applications. All operating systems where the owner is in control already provide a mechanism to supply data to apps, on most (mac, windows, unix, dos even) systems this is the file api, So to be in compliance with the law the owner can make a file that an application could access with the required info. No, there was nothing there about when an application needs this data, or even, like so many people assume, that it has to be out of the control of the owner.
The CA law was so vague and pointless, my only conclusion is that it is a sort of frog boiling scheme. Test the waters to see if they actually have jurisdiction.
Honestly hate all this. This is just a "geeks shut up" law. Excluding things that are not part of commerce (FOSS) probably even gives it some protection from constitutional challenges.
And the quoted part above indicates that it is purely a government ID system - run the thought experiment where you were a conscientious person in 2005 deciding to start a social network, and this law had been passed in 2004. You wouldn't be allowed to use it to exclude children. And where will it be "required by law"? Since the pretense was to target social media and porn was just a bit of moral backwash, it will be required by law on arbitrary sites that allow any users to post.
Geeks will shut up because they love how specific it is. And even as GrapheneOS is being banned already from being able to use websites and services, they'll be shocked when their unattested FOSS machines aren't allowed on the network at all.
It passed unanimously because it means absolutely nothing, and politicians were getting shit from their rich loudmouth programmer constituents who will go back to spending time on their YIMBY activism.
They made it sound like it, but this is not a victory at all, this is a temporary strategic compromise to silence the most sensitive/foreseen privacy advocator for now. But they will not stop here, instead they'll keep advancing the mechanisms, opinions and laws, so one day when the pieces aligned, they can come back to turn this tap off while having people lied to their side.
Forced age verification needs to be abolished completely and people who advocated for it punished to the point that their political career ends, this should be the baseline.
But of course, based on my understanding of everything, no, nobody will do anything effective against it. Everyone will just be "Yeah... they forced a component on my system that could act as spyware to monitor me, then have me pay for it without give me any control. But guess what, I will accept it because they said it's good for the future of mankind", like a peasant would. This is the tax you paid ended up for you, you know?
California law don't represent the planet. That's their tax problem in their country.
Now, if I am the naive one in this story please educate me. After all, this website is excellent at this and I learn so much from the commentary.
We need solidarity to push back against this.
The corporate and government systems we have built are the original paperclip maximizers.
They/collectively "we" are creating an enclosure around all of humanity... Systematically eliminating privacy, liberty and freedom.
Increasingly, the matrix has all of us, and it didn't even need to put us in scifi stasis pods - turns out fiat currency + inflation/infinite growth + resource scarcity + digital markets + internet + smartphones/IoT/devices is already a pretty effective matrix substrate..
Wake up, people...
"Everything already tracks you anyway, so what's one more thing?"
OTOH Id verification for every adult website is extremely invasive and lets random verifiers get all kinds of PIID. But the OS attestation exposed with a browser hook means a parent can say "this computer user is under 18" and every adult content provider can restrict their content without having to ever touch even a birthdate.
Thats not to say there isn't ambiguity in these laws but the principle is sound and the idea is better than alarmists have made it out to be.
If this becomes "every OS has to ID verify with the government", the slippery slope anti-attesters tout, then I'll join the protests, but as long as it's age attestation, I'm for it.
To me, this looks like a lot of pro privacy energy being totally wasted on something that is not actually invasive.
You can't legislate away gray area content to children, what you can legislate is algorithmic recommendation of such content.
Regulate algorithmic recommendation, revert back to chronological timeline of people / groups of interest and 99% of the problems will be solved. Won't be profitable for social media giants though
They can just claim that the user is free to turn off SIP and "modify" the binary bits, or that kernel extensions amount to modification.
Lawmakers unanimously are going to be sleeping when it gets dark at night.
(had to rewrite my slightly angry comment earlier, this was basically my point.)
Where does MacOS and iOS fit then? The core of both those operating systems (darwin) is open source (APSL licensed).
A project like PureDarwin, however, can be freely distributed because it omits Apple's proprietary parts.
This law describes as a true-false something that is not only true or false. This law is poorly written. Amending it didn’t fix that.
The full MacOS as distributed by Apple is engineered to require closed source, non-redistributabe components even on the hardware it is most compatible with. It will completely stop functioning if you remove those parts. The presence of freely licensed components becomes de facto irrelevant.
I can copy and redistribute macOS binaries, and I can write programs/extensions that modify macOS.
These vague terms show that legislators are incapable of regulating software effectively; but they do create an enduring legal franchise to deal with their confusion.
> No Reverse Engineering. You may not, and you agree not to or enable others to, copy (except as expressly permitted by this License or by the Usage Rules if they are applicable to you), decompile, reverse engineer, disassemble, attempt to derive the source code of, decrypt, modify, or create derivative works of the Apple Software or any services provided by the Apple Software or any part thereof (except as and only to the extent any foregoing restriction is prohibited by applicable law or by licensing terms governing use of Open-Sourced Components that may be included with the Apple Software).
The “under license terms…” is a pretty important clause you omitted here.
I also agree that this is now a mess. Courts will lateron find that such exemptions make no sense, since it is unfair to Windows users. And Windows will require mandatory ID verification; I think they already do that to some extent, e. g. when you register the OS, unless you use the workarounds to not give up your ID in order to use Windows (not sure if this has changed with Windows 11, I won't use that version and it is unlikely I will use any later version; I use Win10 only on a secondary computer anyway, have been using Linux since soon-to-be 30 years so I could not care any less about this ruthless and evil operating system called Windows, now with mandatory AI slop spam).
I am wondering how much this could hobble GrapheneOS...
I find it hard to believe these people would just create a huge loophole for only smart kids to get through rather easily.
Or even better, don't have anything like that at all anywhere other than in front of the screen. I really don't see how it is a good thing for a six year old to interact with the Internet in any way.
upgrading to adult content when a credential is provided at the protocol level rather than forcing the operating system to track the state means that consumer operating systems don't have to be secured against their own users.
A court at a later time may find that this situation is unfair to windows users who have to submit to age sniffing. So this will easily be overturned at a later time - age sniffing will never be given up by the lobbyists groups paid for by Meta and others (and the USA also wants that information).
Or is the idea that the Linux store is not allowed to sell cigarettes anymore?
(PS. I'd hope we were past trying to hamfist physical metaphors to describe the digital landscape. But alas).
Are the gore websites gonna have to ask for ID now? What about 4chan? Or is the whole point to get rid of all that stuff and just get everyone using Facebook instead? (They're the ones who pushed these laws right?)
I'm honestly trying to understand what the big picture is here.
>Are the gore websites gonna have to ask for ID now? What about 4chan? Or is the whole point to get rid of all that stuff and just get everyone using Facebook instead? (They're the ones who pushed these laws right?)
The idea is that this closes a loophole which a bunch of websites already bypass from several other kinds of laws that punish companies for breaking age verification laws (like COPPA). The obvious defense is "well I didn't know they were 12, they clicked a button saying they were 18". So now here's a mechanism that gives them more information they have to implement.
For the range of who implements it, like always, probably goes top down. They won't cover every website under the sun, but getting the big websites will supposedly be good enough. Given how consolidated the internet is these day, maybe there is some kind of point there now.
I'm not an attorney and haven't read these laws, but here is an interesting question: if Linux is exempt from legally needing to supply a user's age for verification, but websites require an age to be presented as a condition of access, can browser developers on Linux send a pre-programmed age for interoperability purposes and be legally in the clear? It seems legit to me.
Of course, since the whole point of these laws is to absolve Faceboot (the laws' sponsor) of liability, Faceboot (et al) will then move on to demanding remote attestation to make sure users are on proprietary operating systems that are legally required to send a faithful signal.
I do wonder if there is an angle here for pushing back against the ever-growing surveillance industry. What if instead of sidestepping the age requirement by choosing an "old enough" age, we chose "too young" ages instead. A signal saying "I am 12" and all the COPPA requirements start to apply, including to embedded ads. Probably easy enough for most sites to flat out reject access. But some sites can't / won't - think government sites that currently embed corpo-surveillance crap like recaptcha etc, or sites that serve neutral content and don't care themselves but use cloudflare. Or perhaps browser extensions could even mix and match which signals they send where - "over 13/18" to the main site, "under 13" to the subresources, etc? I suppose by the time you've gotten there you might as well just be running best-in-class adblock extensions that work based on lists of hostile sites. But I think there might still be a core of an interesting aspect to a well-known way of telling websites that you're under 13.
> Provide an ACCESSIBLE interface, at account setup,..
I wonder if the biggest effect of this bill will be that proprietary operating systems will have to have accessibility features built-in, and will be subject to ADA compliance lawsuits if it's deficient in some way.
It does have a pretty good ring to it, I'll give them that.
I take it that you wouldn't be OK with somebody building a uranium enrichment facility in their backyard for their hobby reactor. So there is a line to be drawn on where people's freedom to tinker ends; it's just a question of where you draw it.
Personally, I think given there is an actual documented, non-isolated problem with 3D printed guns being used for violent crime, there's a debate to be had that's more sophisticated than "REGULATION BAD".
I agree the bar is a lot higher for those projects than massive corporations, but I think it's a pretty arguable case that "people are using 3D printers to make guns with features that would otherwise be illegal, and they are being used in crimes in some number" clears that bar.
What's next, keep track of all printed parts and invent the math to recombine them in every way possible to see if it could form a gun? Trivially defeated by using multiple printers. Hmmm, sounds like a good reason to force everyone to register their 3D printer with their real identity, and only allow a print after the model has been uploaded to the Federal Printing Database for verification...
It’s so ridiculously easy to assemble a 3d printer from individually sourced parts, and find some open source firmware to run it. How is this going to stop anyone who’s dishonest and slightly motivated?
What’s next is thinking about guns is a thought crime.
There’s a cynical part of me that sees this as having nothing to do with guns. Technology used to empower people. You can do anything with a computer running Linux, you used to be able to go anywhere on the web and do anything you like. There’s wasn’t a curated experience, a whitelist of apps. This is a bad thing for people who want to control and manipulate. They want us to mindlessly use our closed of devices that only show us what they want us to see and do what they approve. 3d printers can’t be allowed in such a world.
I read the discussion and thought "yeah that's nerd talk, just not about analogue synthesizers, old Landrover gearboxes, or Pascal compilers".
I guess the reason for blocking 3D printers from making gun parts is because it's easier than doing it "by hand". All you really need to do is get a copy of the files from someone who has them, print it out in something suitable, and you have viable gun components with very little "real work" involved.
By contrast here in the UK, where it's quite surprising what you're allowed to own and operate if you comply with the laws (here you're allowed fully automatic weapons, if you keep them at a suitable shooting range and don't try to wander around town with them, and you're not oh maybe a convicted violent criminal for example) one of my late father's friends was a gunsmith. My dad was an excellent machinist, and so he made some components for his friend, and I remember standing in the machine shop where they worked while he turned a chamber for a gun his colleague was building in the lathe. "There you go," he said, taking it out of the chuck, "that's legal".
Then he took it over to the mill, and cut a couple of holes and slots that would allow it to actually function as a chamber, "And there - now it's *illegal*."
Then, as he handed it to his friend, who was licensed to have "home made" gun parts, to stamp his initials on, "And now it's legal again."
Of course since people aren't allowed to just walk around with handguns since the school shooting, it's all a little more difficult - but the police will tell you what you need to do to keep it legal.
It's still slightly easier to get a shotgun licence than a motorcycle licence here.
I think you're overstating this. My understanding is that here in GB (unsure about NI) fully automatic firearms are absolutely prohibited with only limited exceptions that the general public are typically ineligible for. Could you elaborate?
This is not an easy or inexpensive thing to set up.
I shot a documentary about a guy doing just that in NE Scotland, about 20 years ago, and while his range is still in business I don't think he has ever cleared the tape for redistribution - it was a "here's what you spent your money on" for the investors.
This would be an unconstitutional law, per Bruen.
3D-printed "guns" become a real issue when you combine it with unregulated sale of firearm parts and ammunition. To get a fully-functional gun you just need to 3D print a fairly trivial component which is legally considered the entire gun as it carries the serial number. But that's not a 3D printing problem, because there are also companies selling that same part in a mostly-finished legally-not-a-gun form, together with a drilling jig guiding you how to drill the last few holes with a regular Dremel. And nobody is proposing banning Dremels. Heck, it is totally okay to own a lathe - which you can use to make your own high-quality guns!
And the entire discussion is of course pointless once you realize that this is the USA, so anyone is only a weekend road trip away from legally and fully-anonymously buying a gun two states over. If 3D-printed guns are such a huge problem, why aren't we seeing European countries mass-banning 3D printers?
To extend your analogy: it's like being fine with the sale of ultracentrifuges and uranium hexafluoride, then getting upset at someone selling a screwdriver to attach the plug to the power cord of the ultracentrifuge because "screwdrivers lead to nuclear bombs".
3D printed guns are a nothingburger. There is indeed a non-zero number of violent crimes committed with them - but there is also a non-zero number of violent crimes committed with shoelaces, so that's clearly not enough of a reason to ban them. It only makes sense to regulate them if they are involved in a significant number of crimes and leading to a huge increase in gun violence - and at that point you probably want to crack down on all forms of DIY guns instead of just the 3D printed ones. But that's simply not the case, so the regulation is pointless and doing more harm than good.
Dunno, because most europeans are way more responsible with their guns than many people in the US?
For example in the EU (and in Switzerland) before you can buy a gun, you get specific training about safe and responsible handling. And in many countries the cops shall come to your place and verify that you've got a gun safe and a separate safe for the ammo.
And we don't offer AR-15 to our kids when they turn 14 y/o (well I say that but my daughter wants to shoot my weapons and, once she turns 14, she can switch from air rifles to the real thing as long as she's accompanied).
Just to be clear: we have shitloads of guns and ammos in Europe. There's even one EU country with concealed carry. I think it's estimated there are twice as many non-registered weapons as registered ones. We've got big guns factories and gun brands in the EU. And there are millions of illegal full-auto weapons like kalashnikovs (well Zastava M70, which is the same) from the war in Yougoslavia in the hands of criminals. And shitloads of fully functional weapons, including handguns, from WWII circulating.
In my native city (Brussels, Belgium), at the moment there are drug dealers firing kalashnikov on police stations regularly (it's a big issue, it's in the news daily and the authorities don't know what to do).
In addition to people shooting at the range (and, sadly, to drug dealers/criminals ruining our cities), we've got lots of hunters too.
Many people at my shooting range have their official gun transport license full (that is 30 weapons) and some have more than 100 weapons in their collection.
It's a fantasy that europeans don't have guns: we're (mostly) responsible with them.
It's maybe because we're responsible with our guns that the EU hasn't banned 3D printers... Yet (it's the EU, so nothing is unthinkable).
Making actual firearms from steel is trivial. In fact you can look up Kalashnikov designs online and then replicate it with a relatively simple mill/lathe/tapping setup.
To be honest, as someone familiar mostly with computers, I have no idea where to start with this and it sounds a bit intimidating. Buying a 3D printer and using some 3rd party design sound very easy in comparison.
You're certainly right that it's possible for someone determined to make their own firearm, but raising the bar still has immense value.
Tradeoffs between freedom and safety are another, unrelated discussion.
Congrats, you built a zipgun.
https://www.bbc.com/news/uk-england-nottinghamshire-63198715
There's now much more of a debate that's to be more sophisticated than "3D PRINTED GUNS BAD".
You don’t seem to have a good grasp of the topic but already decided the opposition position is „regulation bad“, but that’s not the case at all. The pushback comes from introducing the government as middleman between your slicer and 3d printer, that’s dystopic af
Your analogy fails in that yes, you are not allowed to make hobby reactor. But that's because you are not allowed to have any kind of reactor at all.
Banning 3d-printed guns while not banning real guns (which are order of magnitude more effective) makes no sense.
It’s like trying to ban wrenches.
Lever and tube - that’s what it is. People create makeshift ones even when it’s legal to buy them, because it’s cheap and easy to do so.
You can’t ban computers or personal transportation or words either.
You can’t even ban a person from a website. You can ban an account - but you haven’t stopped the person. Any attempt at playing arbitrary authority you’re gonna lose
"Protect the children" is the most common refrain of fascists across the political spectrum. It's used, uncritically, to attack your rights, to take away your power, with a fragile appeal to morality. Just like the war on terror. And the war on drugs. And the war on poverty. Funny how all of these efforts have failed while increasing government interference in our lives. We never get the rights back, and we don't improve the situations on any of the above.
A reminder that the fear mongering around children is just that. It is the safest time for children in history: https://www.chadaldeman.com/p/the-world-is-safer-than-ever-s... https://www.unh.edu/ccrc/trends-child-victimization
> software distributed under the GPL, MIT, BSD, and Apache licenses are exempt
I also want a permanent ban for anyone who calls the California law "age verification". It does not verify age. Period.
Social media from Meta and AI generated videos are a net negative to society.
I would expect that Linux users want access to age-verified apps just as much as other users, so such a signal will be available.
Also, you're being overly pedantic on the language used. It transfers liability away from the service, more easily allowing operation in about half of the states. "age verification" is a fine lay description.
> a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software
which at least doesn't choose specific winners and losers among licenses. It does disfavor license-free and public domain software, which isn't great.
Public domain software is free to "copy, redistribute, and modify", so ... where's the disfavour?
On the other hand a public domain dedication is a binding term that gives you permission (or license) to do what you want...
Licence-free isn't a concern. That isn't even close to Free and Open source software, it's the opposite: software that you aren't permitted to acquire, use, modify, or distribute. [1][2]
[0] https://opensource.org/blog/public-domain-is-not-open-source
[1] https://choosealicense.com/no-permission/
[2] https://docs.github.com/en/repositories/managing-your-reposi...
Sure, that's true. The intent of the law is to give a special carve-out for, in essence, Free and Open Source software. It seems clear that it was deliberately written so as not to include proprietary freeware, say.
> We all know what set of licenses the FOSS zealots would prefer for us to release code under, and those who release license-free or public domain software anyway typically do it with full knowledge of such arguments.
Like what? Really, it's very rare for code to be released into the public domain like this. I've never seen a compelling argument for doing so. If your intention is to make the code available to all, to do with as they wish, the legal reality is that the best way to achieve this is to release the software under a permissive licence, rather than releasing it to the public domain.
If the exemption really doesn't cover public domain software, that presumably means that, as the copyrights on Free and Open Source software eventually expire and they enter the public domain, they will no longer be exempt. Again though this isn't of practical concern.
edit Come to think of it, publicly available software developed by the US federal government is released into the public domain, right? There doesn't seem to be much software like this though.
Direct link to the text of the bill: https://legiscan.com/CA/text/AB1856/id/3456513
djb's software is the canonical example here: qmail, djbdns, etc. Widely used; distributed without explicit license until 2007, and placed in the public domain thereafter. No legal disputes ever arose from this.
An absence of lawsuits is not the yardstick for success here anyway. It's possible the public domain dedication deterred adoption compared to using a permissive FOSS licence. Consider Google's caution about public domain software for instance [0]. It could also be possible for software to be adopted but, if tested in future, this could be found to be legally murky.
If your intention is to make the code available to all, to do with as they wish, there's no legitimate reason to release it to the public domain rather than just using a permissive licence. If anyone with a deep knowledge of copyright law disagrees on this point, I'd be interested if you could post a link.
I'm not clear if you're doubting the correctness of what I said in my previous comment. I'm not making this stuff up, I already gave sources. The Creative Commons CC0 licence was created purely to address the legal complexities of the public domain. [1][2] (For other reasons of legal nuance, Creative Commons licences should not be used for software works, [3] but the point stands.)
[0] https://opensource.google/documentation/reference/thirdparty...
[1] https://creativecommons.org/public-domain/
[2] https://creativecommons.org/2008/04/16/cc0-betadiscussion-dr...
[3] https://creativecommons.org/faq/#can-i-apply-a-creative-comm...
I don't dispute any of the factual or legal claims you've made. I even agree that a FOSS license is probably the best choice if the author's goal is to protect the user from the scenario where they turn evil and renege on their gift of code to the public.
In situations where I'm the author, this isn't always my goal. You know that Bernstein isn't going to go after his users, and I know that I'm not going to go after mine. Most users aren't going to be concerned about this possibility, either. Those who are concerned about it are likely to be for-profit corporations or their lawyers, and I'm not losing any sleep over making them nervous or losing them as users. I don't care to over-formalize things by invoking or even acknowledging IP law in my act of publication.
Each author's motives and goals are going to vary. It's not reasonable to enforce that "maximize assurances provided to user" is always at the top of the list for everyone.
which technically makes California a "Nanny state"
The reality is that many people want bad laws. Without the support of those people one does not get elected.
This use of people for power while de-facto disenfranchising them is pretty widespread already. For instance, some half of California and Texas are responsible for their strength in the electoral college while simultaneously being entirely disenfranchised when electing the President. Good technique.
Is this serious or sarcasm? They passed a horrible law, now its an internally contradictory horrible law because apparently it isn't important enough to consistently enforce. So, you know. Why legislate it?
There isn't much of an angle here that reflects well on Californian lawmakers, they're still supporting this authoritarian trend of de-anonymisation and rolling back free communication on the internet. They're just going to come back for linux later once the idea of legally mandated PII on account registration is normalised. Although I do see this "In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law" so we seem to be entering a wild space where they're going to try and micromanage this in a weird way.
Law is not an abstract code, but an incremental sometimes futile approach to shape society. They only want a way to hold big corporations accountable to exploiting children. They don't actually intend the effects on the consumer, so they tried to fix on easily changeable effect: "Don't worsen the privacy for people who want it." If you are using e.g. MS Windows, you have given up everything already. They do a lot of "telemetry" and for example everything you typed into MS Word is already licensed to Microsoft.
Seriously, what is the message here supposed to be about the kids using linux? And why are they so different from kids using Windows or Mac? Are there other safety features we can exempt kid linux users from?
There is a sysadmin (likely the parent), whose responsibility is that already.
Let me know when they pass actual laws tackling that, then. Even if this law was ironclad, this does not solve the simple factor of using a "verified" device.
You don't fix a problem of society from private corporations by restricting society. You need to actually attack the corporations itself. But governments are sheepish to go after "their own", or people who can bribe them into feeling like one of them.
It's not a great implementation either. But COPPA is an example in the right direction and made companies need to change their algorithms based on the user account's reported age. That's more of the direction to move in.
If you allow this pandering to satisfy you, you’re essentially supporting an age verification requirement for all other computing systems. So you didn’t think the requirement itself was a problem, you just wanted to make sure it didn’t affect you?
Good day.
I used the same language as in the OP title. Why aren’t you responding to that? You’re missing the point because you weren’t responding meaningfully to what I was saying, you’re using someone else’s choice of language to derail.
> Good day.
And here comes the passive aggression, true to form.
This is not a good thing, it's a very small patch for a very bad thing.
The original issue with the law was never that those poor open source developers were going to have to bear the burden of complying with the law, but that the law itself was a bald-faced invasion of privacy by an overbearing troupe of people in power (i.e., government) so shit-sure of their superiority over the simple common folk they govern (i.e., you and me) that they aren't even embarrassed by their own arrogance.
I would suggest that what "we wanted" is no such law at all. What would be weird, and worthy of comment, is if those of us that complain about government were actually satisfied by an exemption which only applies to pretty damn tiny slice of the market. If anything, that wasn't a victory for privacy or common sense, but rather a concession that they had foolishly created a law that they wouldn't have been able to enforce as broadly as they thought they could get away with... or if they tried to enforce it they'd have to contend with the optics of the big hand of government yet again crushing individuals whose only real crime was their altruism rather than just some giant corporation.
So it isn't weird at all that "we're" silent. This isn't a win. Pointing out that the law had unintended consequences, including with Linux, et al., wasn't a statement of objective but rather a simple show that the law was rife with thoughtless unintended, or perhaps simply unspoken, consequences. The legislature's act here didn't restore privacy nor did it remove bad outcomes: if anything it now just raises questions about equal protection under law, at least on some practical level. It raises the question why some users of computers need such protections as age verification and others don't, and why the licensing terms of the OS are a valid proxy for that need... taking for granted that the stated purposes of the law are the real ones, of course.
The problem is our legal system is still based on the waterfall method. Lawmakers try to plan for everything, laws meant to solve one problem face feature creep and create a thousand others, then no one wants to touch anything after launch for fear of making things worse or because that one guy uses the temperature of his CPU as a quick-key and refuses to change his workflow.
Anyways, no law is perfect and never will be, and neither are the fixes.
It's not? It has been "agile" for centuries. It is constantly patched as someone wants to address some issue. It's rather rare for a completely new law to be written.
> Lawmakers try to plan for everything
It's not? They see one bug, e.g. children being exploited, now they tried it with a patch that is horribly broken and doesn't really work, so they patched it again, to remediate one issue, while they try to figure out more patches.
Most governments are huge, highly political, slow moving organisations. It seems to just come with the territory: slower rollout of changes, longer periods to observe the changes in the wild (throw in a few years to see how the law plays in legal cases/challenges), and suddenly you have fewer iterations to get it right.
Unfortunately the “Never attribute to malice that which is adequately explained by stupidity" is completely wrong in politics. In politics and lawmaking, always attribute to malice, not stupidity.
Lawmakers appears extremely dumb on TV for the most part, but the teams behind them are actually very smart (pure evil, but smart). All the loopholes and bugs in laws are, to them, a feature. It allows them to always prosecute regular citizens, but the favored people (politicians, campaign contributors, oligarchs) always have a free pass. This is by design.
That's how it should work on paper anyway...