• Eldritch ( Eldritch@piefed.world ) 
    link
    fedilink
    English
    arrow-up
    147
    ·
    1 month ago

    This is awesome to hear. But the fact that they had to do this after the fact tells you all you need to know about how stupid and poorly thought out to these laws are.

  • 4am ( 4am@lemmy.zip ) 
    link
    fedilink
    arrow-up
    48
    ·
    edit-2
    1 month ago

    This is fucking BAD you guys. Like, we’re being dog walked into a fucking wall here.

    Major Big Tech companies (and their Fortune 500 partners, and the smaller businesses they support) are ALL going to be asking for age verification for all their SaaS “cloud” offerings and be required to do so by law.

    If Linux is exempt from these laws then these services which we may all still be dependent on in some form or another will not work with Linux, since it doesn’t verify age.

    You won’t be able to bank or watch Netflix on Linux anymore and it will destroy adoption just as it’s going mainstream.

    • TehPers ( TehPers@beehaw.org ) 
      link
      fedilink
      English
      arrow-up
      24
      ·
      1 month ago

      The law requires the OS to ask the age and provide it to applications, not verify the age. Linux can provide the same API with a static value or “no age” signal if needed.

        • 4am ( 4am@lemmy.zip ) 
          link
          fedilink
          arrow-up
          18
          ·
          1 month ago

          You’re right we should ignore the takeover of technology from our very hands into the paws of oligarchs who will make it unobtainable so they can build their datacenters with it and once all the consumer brands have dried up they will sell us dumb terminal tablets and we will rent all software from them in the cloud, by the month.

          I’d ask you to come back and tell me how right I was in say 5-10 years but a) there’s no guarantee they will succeed and b) if they do succeed, none of us will be allowed here in the first place

          • Seeing this as a conspiracy against Linux users and not just patching badly written state level legislation is tin hat territory. If I’m not on the internet and using Linux in 2036 then I’m dead, and it’s not because I starved in the street after being unable to access my bank account on a Linux.

          • TehPers ( TehPers@beehaw.org ) 
            link
            fedilink
            English
            arrow-up
            3
            ·
            1 month ago

            What does this have to do with an exemption for Linux on a shitty OS-level age attestation law…?

            The law is stupid for many reasons, among them being that Linux devs aren’t often even located in CA or subject to its laws, and that people can just lie about their age. Corporate takeover of technology doesn’t really have anything to do with this.

        • TehPers ( TehPers@beehaw.org ) 
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          1 month ago

          What if an asteroid flies into the Earth and splits it in two?

          Edit: I’ll add more now that I can sit down and focus.

          Age attestation has existed for longer than I’ve been alive. Every service with an age requirement (must be 18+ to view, must be 13+ to play, must be 8+ with parent permission or 18+ to play, etc) used user attestation. The law is stupid because:

          1. Age attestation doesn’t restrict. It only exists for services to cover their own asses legally.
          2. Age verification would be required to restrict access, but age verification costs money that MS/Apple/Google/etc wouldn’t make back (maybe MS but Android and Mac OS are free).
          3. Linux exists and can bypass it all anyway and often isn’t subject to CA’s laws.

          This law isn’t age verification. It’s just politicians being technically illiterate imbeciles.

          • JackbyDev ( JackbyDev@programming.dev ) 
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 month ago

            That’s why I said “Age Verification Authority stamp” versus age attestation. How long before tech giants are able to convince Congress that the only way to keep kids safe is for them to issue certificates following identity verification? It won’t be long before Google phones won’t let you install APKs easily without a dev certificate which requires submitting your information to Google. It’s not farfetched to say. It’s a wet dream for politicians that want to be able to track everyone everywhere, too. How long before motherboards can’t be sold without it? How long before building your own PC isn’t an option? It’s already the norm for most hardware to have closed source code somewhere. That’s generally accepted as something that’s or worth working around except for the most dedicated of free software enthusiasts.

            This is all super important shit. Blowing it off like “this is just tech illiteracy” doesn’t do anyone any favors. We aren’t going to be able to fight these things by laughing about it. With that mentality, an asteroid might be the only way to actually stop this shit from happening.

            The trend in America is towards a conservative, puritanical, surveillance state. Flock cameras everywhere. Flock execs looking at children’s gymnastics classes in my state, while they say it will help find missing children. Abusers saying it will stop abuse. My state passed a porn ban and has had heartbeat abortion bans. We’re not going to get any wins by blowing this shit off and laughing about it. We’re not going to beat this shit if everyone wants to laugh and think everything is a slippery slope fallacy or just a random bullshit comment.

            • TehPers ( TehPers@beehaw.org ) 
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 month ago

              So what exactly are you saying to do here? Because I already write to my representatives and advocate against these things. The reality is that lawmakers don’t care what people want, only what’s going to make them the most money.

              In any case, the point I was making was that this law isn’t age verification, and spending energy fighting against this when you could be battling the myriad actual age verification bills and laws is a waste of energy. In CA, there’s also the 3D printer BS around scanning and blocking print jobs.

              There’s also the ALPR issue, data centers, and so on that have shown that representatives would rather put up a democratic facade than actually listen to their constituents.

    • I think you are confusing something. A tech company running proprietary code can and will ask for age verification. It does not matter if the user runs Windows, Linux, iOS, GrapheneOS.

      The law here makes sure that services, which are basically also open source, are not required to do the age verification check.

      So, you install Windows? Age check. You install Linux? No age check. Before even opening a browser. Then on Linux you open Netflix? Age check.

      So I fundamentally saw this actually as a good news.

    • My guess is they figure it will make little difference due to network effects, and by making this exception they can remove a meaningful source of political resistance to the change. If the vast majority of users are running operating systems that declare underage status, then websites and apps will be able to use those signals to sidestep legal liability for actually doing anything meaningful to protect underage users, and new laws can be passed that assume the use of those signals is possible. That it isn’t 100% doesn’t change that very much.

    • zane ( zane@infosec.pub ) 
      link
      fedilink
      arrow-up
      6
      ·
      1 month ago

      But if lawmakers didnt constantly push out completely ineffective laws that cause problems, then what else would they do with their time? Effectively govern? Fucking nonsense.

  • frongt ( frongt@lemmy.zip ) 
    link
    fedilink
    arrow-up
    16
    ·
    1 month ago

    How does that make any sense? How is the license for a piece of software relevant to verifying age? If I make a site that is objectively harmful to minors, I can just make it open-source and I’m exempt? Or, if I make a completely innocuous site that doesn’t actually do anything but is closed source, I would have to comply?

    But really, nothing should be doing strong identity verification outside of stuff like government (e.g. passports), or anything that commonly exploits identity for crime (e.g. major financial operations).

    • TehPers ( TehPers@beehaw.org ) 
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 month ago

      But really, nothing should be doing strong identity verification outside of stuff like government (e.g. passports), or anything that commonly exploits identity for crime (e.g. major financial operations).

      FYI the article title (and the name of the law) are both misleading. The law does not require age verification, only age attestation.

      Does that make the law even dumber? Probably, lol.

    • I think it’s actually a common sense exemption comparable to things like the FMLA having a carve out for small persons with a small number of people. FOSS operating systems bring a lot of value to businesses, higher education and presumably California’s government, but the many devs who make contributions that create this value on a volunteer basis could feasibly determine that they will either simply refuse to comply with it and pull these OSes from California, or that even if they did want to comply, they have an argument that compliance is simply an insurmountable burden for them to develop and maintain, in addition to maintaining the other features that actually provide the majority of the value.

      On top of these, as others have pointed out, it’s a trivial for a sufficiently capable user to modify an open source program to circumvent this. Furthermore, there are a ton of FOSS OSes where development is not based in California, and it would be a ridiculous waste of time and money trying to enforce the law on them. I kind of doubt Canada is going to extradite the OpenBSD devs (or at least the folks your donations to the project go to) to face trial in the US on this, for example.

      In a way, it’s an unusually aware law that lets legislators avoid the egg on their face of passing a toothless law when it comes to FOSS OSes, while still letting them please the “Think of the children!” crowd and squeeze more data and money (in fines) from Microsoft, Google and Apple, who will be subject to the law.

      The overall goal of the law is still terrible, but the way they went about making this exception shows a rare understanding of technology for legislators, even if it was due to public backlash and relevant technical input, rather than the legislators suddenly understanding the tech they want to control themselves.

        • Because, as I already mentioned, the companies behind those distros are based in North Carolina and the UK, respectively, not California. It makes no sense for them to comply with a silly law in California, when they could just as easily rent servers outside of CA to their clients based there for whatever business needs they have, tell their clients to figure out compliance for the clients on their own, and ignore the law. Otherwise, they would have to take on the perpetual responsibility of maintaining compliance not only for their own contributions that they pack in their respective distros, but also for any upstream contributions that would be subject to these laws by upstream contributors they have no control or influence over. If some dev from Poland comes up with a great new idea for the kernel and it gets widely adopted, but doesn’t comply with this law (because why would a Polish dev waste their free time adding this?), now Red Hat or Canonical would have to either forgo those new features that their clients will be hearing about, or waste time and money reviewing all these commits to make sure they don’t miss any contributions that would touch on something covered by this law and updating and supporting their updates to ensure compliance.

          Even if they did want to comply with the law to be able to sell their OSes in California, it would open up a huge can of legal liabilities for them that is nearly entirely dependent upon the actions and work of individuals they don’t control, and they have plenty of trivial ways of circumventing California’s jurisdiction if they decided doing so was the better course of action.

  • Digit ( Digit@lemmy.today ) 
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    So the situation [there] is:

    • free software’s principles are preserved for users of free software based operating system,

    • but if you use a proprietary operating system, you have to report your age to the pedovores… ? ? ? !

    How rusty must the nail under them get before they move away? User lock-in got them trapped tight?

    How long before we cease feeding the dragon tyrant?