327 karma · joined July 24, 2024
California already has BPC §§ 22601-22606 to protect people from chatbots encouraging self-harm and I don't see a legitimate reason why they had to ratchet up the restrictions.
This law seems a blatant regulatory capture grift by OpenAI to calcify their teen mode into law and hurt competitors. https://openai.com/index/supporting-california-bill-advance-...
I had an abusive caregiver as a child and I can confidently say that age-gating websites wouldn't have done shit to help me.
The way to protect these children is through the family court and foster care systems, which are both seriously under-resourced and overwhelmed.
ONE still sees identity documents in the clear the first time when it verifies them, right? Otherwise we could upload fakes.
Also I'm not familiar with Oauth 2.0, but doesn't ONE know the client and relying party on each verification transaction? So ONE could theoretically store records of who accessed which website, perhaps by mistaken logging configuration or because they were coerced by law enforcement.
Anyway I appreciate the consideration given to privacy.
And here's like ~120 of us who showed up to oppose AB 2023 (the 3D printer spyware bill). It was incredible. https://calmatters.digitaldemocracy.org/hearings/279741#t=19...
I think the easiest way to get involved is to become an EFF member. They'll keep you up to date on all the censorship and surveillance bills. Then you can contact your legislator, sent letters to the CA legislature committees, or show up to the hearings in Sacramento.
How is Buffy Wicks so damn gullible with tech legislation? Her AB 1043 and AB 1856 (Digital Age Assurance Act), intended to protect children online and regulate Big Tech (but unintentionally criminalizing open source), was sponsored by a dark money influence operation from Meta.
https://www.reddit.com/r/linux/comments/1rshc1f/i_traced_2_b...
She is actually well-respected with housing and transportation bills but I don't know what's going on with her tech bills.
https://www.techdirt.com/2026/03/26/everyone-cheering-the-so...
I am not a fan of this case. The plaintiff suffered from severe emotional and physical abuse and turned to social media as an outlet. Social media abuse is certainly associated with poor mental health but the evidence that social media harms mental health is very thin. It's not like cigarettes or alcohol because there are plenty of beneficial uses of social media.
Meta is annoying as hell and should be broken up, but holding them liable for bad design features creates a disturbing precedent that weakens Section 230, free speech, and even E2E encryption, as the NM DOJ themselves said:
> [NMDOJ will ask Meta for specific changes] including enacting effective age verification, removing predators from the platform, and protecting minors from encrypted communications that shield bad actors.
https://nmdoj.gov/press-release/new-mexico-department-of-jus...
State AGs acting in bad faith are going to weaponize this. In fact, they're doing this now, and much of the "protect the children" laws, like KOSA or social media bans, have a transphobic coalition behind them to cut off LGBTQ+ kids from resources online.
This reminds me of US v. Andrew Auernheimer where the DOJ wanted to make an example out of weev, a terrible person, to expand the government's enforcement powers under CFAA.
Underrated quote. I also found this frustrating. At one company I was at (a very old company which was trying to pivot to software engineering), we had hellish bureaucratic fights with the IT department to get access to Pycharm, Obsidian, and even GitHub. But then the AI craze dropped and management just gave us all GitHub Copilot access without us even asking.
Cory Doctorow's book The Reverse Centaur's Guide to Life After AI talks more about this. It's just a modern symptom of an age-old power struggle. The workers want more control over their craft, including quality standards and tools, but their bosses want more control over the workers.
What's happening now is bosses are feeling pressure from investors to show productivity gains from using AI, so bosses panic-push AI within their companies. Which leads to misaligned incentives like tokenmaxxing.
I am against legally requiring devices to transmit a signal that the user is a child to websites. What I want instead is to handle any content blocks client-side. Instead of legally requiring adult sites to verify the age of users, I'd prefer requiring that these sites self-label (or move to an obvious TLD like .xxx), which makes it easy for the device to block it. This accomplishes the same thing without the tracking infrastructure and privacy concerns. I don't want my kid's device blasting that they're under 13 to every sketchy website that asks.
> It puts the onus on the website operator to not only prevent presenting content to wrong age bracket users, but also to determine the age bracket of the user.
I believe AB 1856 does not do that any more. As of July 1st, they amended it to remove all requirements on website operators, except one. What it does now is make the app's age signal apply "across all platforms of an application, including an internet website [owned by the same developer]." e.g. the Facebook app gets the age signal, now facebook.com knows the same signal.
Also AB1856 (and the DAAA which it amends) has no content policing requirements. All it does it force apps and websites to know the age of their users, which then triggers liability under other laws like the up-and-coming social media ban AB 1709 (which I'm against). Or CA's Age Appropriate Design Code act (which I believe is getting tossed around in the courts for First Amendment concerns).
As far as presenting a filtered view of a website, e.g. Reddit blocking some subreddits for kids, I'm open to debating this. I personally think it doesn't work and platforms will just over-regulate or wholesale ban minors (Claude, character.ai) rather than comply with the patchwork of laws in different jurisdictions. Or they'll spin off a heavily locked-down version for kids only, like YouTube Kids.
Steam is an illustrative example of how hard it is to get the filtering right. They're trying to comply with OSA but there's still a lot of information leakage between the kid-safe portion and the rest of the platform: https://youtu.be/hOaGUfy6NTw
Yes, granted, a globally enforced whitelist probably wouldn't work. I'm referring to bespoke lists that parents control. I know plenty of parents that use this. e.g. here's Apple's feature:
https://support.apple.com/en-us/105121#:~:text=Prevent%20ina...
> It works for websites because they can cleanly identify a child and filter content if appropriate.
This still doesn't solve the problem of different jurisdictions and culture wars of what is or isn't appropriate for kids. All this does is move the liability upstream to websites instead of the devices. That is, instead of the browser deciding what's appropriate, now Youtube, Reddit, etc have to decide. And, as we've seen with the OSA in the UK, typically smaller platforms can't handle the enforcement cost so they just shut down entirely.
https://onlinesafetyact.co.uk/in_memoriam/
The larger platforms often use overbroad CYA measures and throw up age verification where they don't need to (Reddit has done this in the EU), or just ban minors (Anthropic and character.ai did this).
As far as blocking explicit content, a self-labeling requirement like RTA accomplishes the same thing as a "this is a child" header but without the liability CYA and without the privacy concerns.
Where the "this is a child" header solution could theoretically win is allowing kids to access websites in a limited child-safe way, e.g. going to Reddit in child mode automatically shuts off certain subreddits. But, as we've seen, it just doesn't work well in practice and usually frustrates parents by overly broad content policing and liability theater. Kids are also at different levels of maturity and I've seen them get frustrated when they're binned into age categories that they feel they don't deserve. e.g. a 12 year old might be plenty mature enough for the 13-16 age category.
But my real objection to the "this is a child header" is the privacy risk and surveillance risk. I don't think it's worth it.
CA tried this with AB 1856. I wasn't a fan of this (neither was EFF) because of the privacy and tracking concerns of blasting the fact that the user is a child to all websites.
https://www.eff.org/deeplinks/2026/05/one-step-forward-two-s...
It would better for the block to happen at the device level. That is, the browser knows it's on a child's device and has a whitelist of allowed sites.
There is already an RTA (Restriced to Adults) header where the website self-labels that it's for adults only and the browser can block it while protecting the user's privacy. I'd prefer expanding the use of RTA.
For example, Buffy Wicks introduced AB 2023 (passed the Assembly) which will effectively cause chatbot operators to ban minors because of the huge liability risk that the law introduces. This is a great way to kneecap innovation by excluding curious children and teens who are often the most innovative. California already has laws on the books to address chatbots encouraging self harm (BPC §§ 22601-22606) so I don't know why on earth they're doing this.
Then there's AB 2169 introduced by Lowenthal, which would have mandated interoperability between chatbot platforms to help people migrate to competing ones easier. I thought this was awesome but it didn't even get a vote in the Assembly.
Maybe the newly-created Little Tech Association can help here.
Louis Rossmann and David from 3D Printing Nerd should be there. They were at the last one on June 23rd and planned to show up again.
Christopher Cabaldon had a great monologue during CA's social media ban hearing the other day:
> And so I think one thing I've learned here is that when something's framed up as let's do it for the kids, let's do it to stop murderers and rapists, or let's stick it to the big corporations, all of those are important. Those are important objectives, but they can sometimes cause us to stop thinking about what's the actual policy underneath.
https://calmatters.digitaldemocracy.org/hearings/279699#t=80...
And yet, he still didn't vote "no" on it but abstained.
So, if you use SSH tunneling to forward a port from localhost to a remote, then Docker unwittingly pushes to a remote. This is super useful "off the grid" with robotics/embedded applications where you don't want to bother with a registry and a good Internet connection.
Example, docker pussh: https://github.com/psviderski/unregistry
It's understandable Anthropic would do this to limit their liability against minors getting harmed. Especially with laws like California's AB 2023 in the works, where parents can sue a chatbot maker if the chatbot harms their child.
Still, I hate that I have to share biometrics and blindly trust that Persona is doing cybersecurity properly.
There actually isn't much evidence of this. Most of the thrust for this hypothesis comes from The Anxious Generation, which was written by a moral psychologist as opposed to an adolescent researcher, and has been widely criticized by experts.
https://kidsplaytech.com/wp-content/uploads/2026/06/Panic_Fi...
There is evidence that social media use is associated with poor mental health but the causation piece is contested. Most stories about social media harm are kids who were already struggling.
> Can anyone suggest a better way of protecting kids, other than age verification?
As far as protection from social media, the best solutions I've seen are:
- Antitrust and interoperability: people want social media, just not the toxicity. Give them a way to migrate to better platforms. CA tried this with the Digital Choice Act (AB 2169) but it got shot down by Big Tech lobbyists.
- Education: Teach kids how to be responsible with social media. There's a CA bill authored in cooperation with high schoolers doing exactly this: https://edsource.org/2026/social-media-ai-mental-health/7559...
- Privacy protection: rather that detect who's a child and protect only them from being tracked and surveilled, protect everyone.
IMO social media is a red herring. There are much more obvious sources of youth distress with far stronger effects in the data: poverty and economic hardship, abuse in the home, parental mental illness, drug abuse, marginalized demographics (e.g. LGBTQ+ youth have way higher suicide rates).
The kids would be way better served by things like universal healthcare, universal childcare, a better foster care system, etc.
And I think a lot of this is projection from parents who massively struggle with social media.
It's quite telling that Sarah Huckabee Sanders, who is aligned with the Christian right, and whose job as press secretary was to be a meat shield for Trump's incompetence and absorb all the anger from the press and social media, sent a copy of The Anxious Generation to governors in all US states.
There are so many times where I've bounced away from an interesting article because I didn't want to deal with the subscription paywall.
The argument for subscriptions is it helps cultivate a relationship with customers and gives the business recurring revenue. Which is fine if I want the relationship, like with Ars Technica, Wired where I'm usually interested in their reporting. But in most cases the relationship feels awkward and forced, like this linked article mentions.
Like I'm not paying $400/year to The Information just to unlock a one-off story.
Since they might get a flood of written correspondence, I also called their district office and either talked to a staffer or left a voicemail telling them the same thing.
The key is the district office phone number, not the capitol phone number. One of my reps said the capitol phone line was understaffed and they missed one of my voicemails.
This and AB1043/AB1856 just make me so mad. These politicians apparently think they can threaten fines upon the open source community and coerce us into implementing their poorly researched laws.
It’s like in a toxic workplace when a non-technical manager agrees to a questionable assignment on your behalf, without your consent, and tells the stakeholder oh yeah, no problem, that’ll take 2 weeks.
That and lots of FOSS licenses use some variant of those words "copy, redistribute, and modify" so it's probably a term-of-art that courts recognize.
This is what Colorado's law says. It prevents Tivoization but not feature nerfing like the Play Integrity API.
§ 6-30-105 (3)
(e) AN OPERATING SYSTEM PROVIDER OR DEVELOPER THAT DISTRIBUTES AN OPERATING SYSTEM OR APPLICATION UNDER LICENSE TERMS THAT PERMIT A RECIPIENT TO COPY, REDISTRIBUTE, AND MODIFY THE SOFTWARE WITHOUT ANY PLATFORM-IMPOSED TECHNICAL OR CONTRACTUAL RESTRICTIONS IMPOSED BY THE PROVIDER OR DEVELOPER ON INSTALLING ALL MODIFIED VERSIONS.
Or, they can have a license like the Business Source License where you can copy, redistribute, and modify the software but you can't use it commercially. This goes against OSI's open source definition.
We emailed this amendment to Buffy Wicks's staff:
§1798.504(f) This title does not apply to[...]:
(4) An operating system or application that meets both of the following conditions:
(A) The operating system or application is distributed under license terms that permit a recipient to copy, redistribute, and modify the software, including for commercial purposes and without payment of a royalty or fee.
(B) The operating system provider or developer does not, by technical or contractual means, prevent the recipient from installing modified versions of the software on a device on which the unmodified version operates, and does not restrict the functionality or interoperability of modified versions.
The answer to the burger analogy is that it's the wrong analogy. McDonald's is selling you the burger. AI companies are essentially selling you the grill.
The hype works so well because it plays on people's ego and desire for power. They think I have the power to end the world with this technology but I won't because I'm a good person.