I will never be compelled to implement this, and would never merge it.
Every release requires quorum signatures by an international maintainer team, and the distro is designed to work offline-first, with some variants not even supporting network drivers in the kernel, so Illinois legislators can eat shit.
RedHat/IBM does have an Illinois presence so will likely be compelled to add it to their distro, and will likely do it through systemd. So to avoid it getting into any consumer distro you'd have to ship a patch to remove it from systemd.
This is probably all completely irrelevant to StageX since it's a distro designed to be used in containers, AFAICT.
I am in the USA, but I literally cannot comply because by design it is not possible for me to ship changes without the international maintainer team agreeing to them. And Illinois legislators have no power over them.
Also, we are not a company. We are an independent community owned project. Our code is free speech and I will burn the world down to defend that right.
Truly I dare someone to try to take me to court over this. Would be great publicity for our coercion resistant approach.
They might as well try to mandate code changes to a blockchain and mandate the whole world host them.
There are a lot of remedies available to a court with respect to a recalcitrant party, ranging from an injunction to remove your product from the market to fines and imprisonment. Again, speak with your attorney. Do not try to "hack the law" yourself; many who have tried have regretted it later.
> Again, speak with your attorney. Do not try to "hack the law" yourself; many who have tried have regretted it later.
Also reach out to the EFF, who may be able to help/advise, especially if you genuinely want to fight this.
This is a terrible law. That doesn't mean it's not a law, and courts do not look kindly on people subject to their jurisdiction (which unfortunately often includes state laws to people in other states) who try to dodge the responsibility the court thinks they should have.
No need to hack the law. Our FOSS code is constitutionally protected free speech and I would defend on those grounds.
The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
> Our FOSS code is constitutionally protected free speech and I would defend on those grounds.
You have precisely zero additional speech rights as a FOSS project than any other organization has. If "free speech" was a valid defense for you, then Meta would be doing the same.
> The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Being unable to comply is not a valid legal defense.
> Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
This is the law in various places under various mechanisms. It is handled by putting people in prison or taking people's assets.
Unless the PGP decision has been overturned, code as free speech is in fact a valid defense. If the government couldn't stop code they claimed were "munitions" from getting distributed, then it seems unlikely that they'll stop a Linux distro.
Corporations do whatever seems most profitable. We can't base our understanding of constitutional rights on whether Meta decides to defend them.
Technical solutions may be seen as kindly as handcuffing yourself to something when told to leave. "I can't, I've made it impossible for myself to obey the law".
They might not be able to break your private keys, but they can fine you or jail you for not complying.
The concern here is probably with the shipping of the product (i.e. the binary artifacts), not the code itself. I can imagine a situation in which you could continue to make the code available, but could not produce a shippable artifact from it that Illinoians could access.
I respect your principled stance on one hand, while on the other I’m amazed that someone as successful as you hasn’t learned that logic doesn’t dictate how governments work.
Don’t make a target of yourself, there are countless ways for a government to make your life miserable.
I will never show fear to tech-illiterate bullies trying to compromise constitutionally protected rights. That is how freedoms get quietly lost.
Users need to see that the people in positions of influence in FOSS projects they trust are not afraid of this bullshit.
I -hope- someone is stupid enough to take a case like this to court so we can establish some much needed case law here. These overreaches deserve to be contested.
"never show fear" and "never engage intelligence" are two different things. Understand what people will do in response to your actions, and act accordingly to achieve the outcomes you want. Please by all means fight the law, and do so intelligently in a way that will actually help.
Wait, which constitutionally protected right is that? I'm an attorney and constitutional scholar and am particularly interested in what right you believe is being violated here.
That argument has been going on for decades, and has had few victories in the court system. The DMCA, which prohibits trafficking in anticircumvention devices, even though there's a lot of code in them, is still alive and well.
I’m not a lawyer and even I know that argument would never hold up given the plethora of other laws that have been implemented through software. Not to mention copyright and patent claims too.
Is is also clear that there are major deficits in our Constitution but that the amendment process has failed to survive a modern world.
Any of our original forefathers would recognize today's American federal government as an overreach from their indended form of government.
The only reason we aren't seeing a Boston Tea Party 2.0 over the recent string of coordinated assaults against our inalienable human rights is because surveillance capitalism is already coarsely achieving its goals of suppressing any civic participation which exists between the spectrum of ineffective political protest to the most desperate, radical action.
Some of those among us simply cannot drink this koolaid. A quote from MLK, Jr:
I submit that an individual who breaks a law that conscience tells him is unjust, and who willingly accepts the penalty of imprisonment in order to arouse the conscience of the community over its injustice, is in reality expressing the highest respect for law.
Good news: the legislation doesn't target you as an individual.
"Operating system provider" means a commercial or
non-profit entity that controls the Internet-enabled device's
operating system, including the design, programming, or supply
of operating systems for the Internet-enabled devices.
Opencollective collects funds to distribute to open source project maintainers. Not that it matters. We have never collected a single donation, but figured it was worth a shot. lol.
I specialize in TPM security and know plenty of ways to bypass it with physical access to consumer laptop hardware, and would gladly make that easy for the public if needed.
But I hope they try this. It will be funny to watch the public humiliation of how hard it fails at scale.
> ”Linux distro founder here (stagex)… designed to work offline-first, with some variants not even supporting network drivers”
If your OS doesn’t access the internet or isn’t intended to run browsers / social apps, then you are outside the scope of this legislation. That would be a bit like requiring a toaster to ask for your age before letting you operate it.
They can stop you from doing any work on the project. They can even fine or jail you for work done after the law takes affect that the international committee doesn't allow. Which is to say you can be forced to stop work.
Though if you don't live in IL it is unclear how this affects you.
Some time in jail or having to fight a fine for refusing to implement features in the constitutionally protected free speech code they author? If that is what it takes.
I do not want to go to jail, but if that is the only way to get to an outcome where people have confidence they can not be forced to add unwanted code to open source projects, so be it. But that is a pointless thought experiment because it will never happen.
I do not think anyone would be stupid enough to jail a FOSS developer for not agreeing to compelled speech, and if they did, an army of lawyers would be lining up to take the case I expect, with the full support of the public. It would be an insane thing to attempt.
We must loudly push back on the chilling effects intended here. Our free speech to write or not write any code we want will not be compromised.
Governments can hire a hitman to go after you, if you say something wrong. So can international crime syndicates. Will this have a meaningful effect on chilling your speech?
I feel like all of these laws are being designed backwards. Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion.
Requiring my kids' devices to advertise their age (or their age "bucket", as if that was a meaningful difference) to protect them is not doing me or my kids any favors.
Having the ability to identify who is watching or saying what on the internet would be immensely useful to the government; the justifications are really meaningless.
Anti-money-laundering is a comparable field, as all the AML regulations and laws are ineffective at identifying money launderers, but they're wonderful for verifying (auditing and prosecuting) tax compliance.
> Anti-money-laundering is a comparable field, as all the AML regulations and laws are ineffective at identifying money launderers, but they're wonderful for verifying (auditing and prosecuting) tax compliance.
As someone who’s implemented AML, KYC, and tax reporting functions in a bank. I think you would be very surprised at how shit they are for tax auditing at scale. Unless the tax man is specifically auditing you, and basically requesting all your transaction details, the reporting that banks do would only allow tax agencies to catch the most brazen and incompetent tax dodgers.
All of the tools however do make much harder to perform money laundering, forcing criminals to recruit and pay huge numbers of naive bank customers to allow criminals to launder money via their personal accounts, using them as money mules. Which then gets flagged and shutdown pretty quick by banks because the behaviour is generally pretty obvious.
Unfortunately (or fortunately depending on your perspective) banks can’t/don’t coordinate on identified money mules or know launderers, so criminals just move on to other banks and repeat.
> Unfortunately (or fortunately depending on your perspective) banks can’t/don’t coordinate on identified money mules or know launderers, so criminals just move on to other banks and repeat.
Or criminals just get a bank like HSBC to do the money laundering for them.
Criminals don't have to "recruit and pay huge numbers of naive bank customers"; in my jurisdiction, they just walk into a casino with a few hundred thousand dollars, exchange for chips, pretend to gamble for an hour, then exchange the chips for cash, and walk out with a nice receipt. There're more complex schemes involving real estate and other mediums too.
That’s cute, but it doesn’t really scale. Organised crime groups aren’t interested in laundering a few $100k at a go. They’re moving and laundering millions, you can’t put that through a casino without it being very obvious.
There is a huge international criminal industry that exists to find and hire money mules, and launder eye watering amounts of cash. Where I worked, we broadly assumed that the police weren’t interested in fraud or money laundering unless it was measured in 10s of millions. We reported everything, of course, but we only got call backs for really big schemes.
If you’re just committing fraud measured in $100ks, the odd of anyone bothering to investigate, and attempt to bring criminal charges, was basically zero.
The larger-scale money laundering in my area is a but more complicated, involving import/export schemes, real estate transactions, and property developments. I'm not in a mega-city, so I assume these schemes are taking place at a larger scale in those. I have only ever heard of very basic and stupid schemes (which didn't provide any tax revenue to my goverment) being detected or prosecuted.
> Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion.
If the intent were to actually protect children, then this would be what was done.
"Protect the children" is just a subterfuge to get electorate support for voting for the foundation for a "1984 thought crime" style monitoring of the internet.
Why then did this completely leave out verification? Parents want and accept the out-of-box declaration idea. It requires no ID, no face scans, no "ID dot ME" or whatever. As parents we are more than able to open the box before giving our kids a laptop or phone and entering their DOB, and also able to see with our own eyes if the kid suddenly turns up with a second cell phone that they bought and configured as an adult.
Any parents who are pathetically absent from parenting their kids, well, they can just go right on ignoring their kids and letting the kid themselves put in 9/9/99, and consume all kinds of inappropriate crap.
This particular law is respecting everyone's rights.
I would argue the reason is so people can make arguments like yours.
Step 1: get easily passed, simple looking laws passed to 'protect the children'
Step 2: 'oh look at all these people bypassing the law. It's so simple for a child to watch porn with this.'
Step 3: increase the requirements bit by bit on the verification
By letting something simple pass, they can claim it's not thst bad, and anyone who argues against it is being hyperbolic.
> I feel like all of these laws are being designed backwards. Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion.
This is definitely not about "protect the kids" or age verification, this is a stepping stone to full identity verification to use the internet at all.
I'm now pretty convinced that this is the best argument for persuading non-technical and non-internet-privacy minded people why this is a problem. It's hard to explain all the technical factors that make it impossible to implement without compromising privacy... but it's pretty easy to get them to understand the real intent. If you start them thinking through what mechanisms would make sense _if_ the original premise truly was protecting kids from content they aren't ready to see, it's easy to arrive at that answer, and equally easy to see why "everyone must provide their ID so we can verify their age" probably comes from other motivations.
and that's as useful as self-documenting "i am over 18" or "over 21" for things that require that, without any document checks.
this is a way to get something legal on paper, the rest of the stuff (patches, if you will) comes later. This asserts that age is important enough to force an operating system to comply, this opens the door.
The idea of a 'user agent' where the 'device owner' decides 'what should be displayed and how' is ancient history, grandad.
Modern social media is delivered through 'apps' which are like web browsers, except without ad blockers or privacy settings, and with push notifications to make them more addictive, and they only show one website, and they're each 5x the size of a web browser for some reason.
Parents already have the ability to do this, at least when it comes to porn. The fact is that most parents aren't doing it. Hence the push for legislation that increase the uptake of content blocks for minors.
Did you read the law? It actually imposes very (in my humble opinion) good rules on the content providers, specifically social media. We know why social media is addictive - the personalized feeds are highly optimized to extend usage time, with no amount of time being "good enough." Social media sites would be banned from using this type of feed, limiting it to feeds of content you've subscribed to or requested only. Instead of seeing mainly influencers and viral videos, people might even start seeing their friends' own content.
> Requiring my kids' devices to advertise their age ... to protect them is not doing me or my kids any favors.
Idk about you, but it'd be doing me favors because my kids will not be physically able to use the most addictive platforms that exist today in their current form. It would be a major disruption to the behavioral manipulation that Meta, TikTok, and X do.
Right, I'm saying that if the goal is to keep kids off of addictive social feeds, it would be better to have social media have to say "this site implements addictive feeds" and then I can configure my kids' devices to disallow that. The decision should be happening in my house on the devices I control, not in a Meta data center. The current law just gives Meta a way to start building a shadow profile early.
Controlling my information consumption is not a legitimate function of the state. If algorithmic feeds get a lot of use, it's because people like them. Is that so hard to comprehend? That your preferences are not universal? And that you shouldn't use the government to bludgeon people into accepting the kind of information feed you, personally, would prefer for them? What gives you the right to do so?
What you calling "addictive" is just revealed preferences of the populace.
It seems like after Epstein was gone a lot of politicians in many countries suddenly want to identify children, take photos for "age identification", and their ages and what apps they use. Very strange.
As a counter, actual age verification is being rolled out in other places. I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. Between the anti-porn types and public demand for some kind of regulations on social media, regulation of some kind is inevitable.
Our actual choice may only be what type of restriction we can live with, and I much prefer this type to the kind that requires websites to demand my id and photos of my face. Especially since some implementations of this concept (the California one, I think) declare that websites aren't legally required to look deeper than the attested age, which is a very nice feature.
Mind you, I don't know why the legislators are bothering mandating OS support for these features. It would be much easier to mandate that websites support the feature, make it clear to them that supporting the feature appropriately will free them from liability for children accessing content, and then wait as users demand that their OS support the feature.
I actually agree with you, if you mandate that the site has to look for an affirmative signal and if it doesn't get one, has to assume the user is the youngest possible age group. Users would demand the proper support for it.
Although it would have to have some teeth capable of biting the client software companies, because for instance, if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls).
Honestly though - because kids (especially the younger set) are hard pressed to buy their own hardware, a property that can only be set up out of the box, and can only be undone by using the account password of the parent who set it up, it is the perfect level of security here. And as for browsers, all you need is the gatekeepers (Apple, Google, MS) to agree not to ship in their "stores" browsers designed to evade it. Yes, you can totally compile your own browser, but most kids are using locked platforms like iOS and Android, and are by default denied permissions to run arbitrary software on platforms like Mac and Windows, so that's fine.
Yeah, that's pretty much what I am imagining. You're right about needing some teeth - maybe the legislature could define a spec, and penalties for implementing the feature in a commercial product without actually following the spec.
I really think all we need is what you describe in your third paragraph. It doesn't need to be bulletproof, it just needs to be an easy way for parents to set the level of content their children can access without them having to hover over their children at all times. Something like that could easily be set up in the Genius store when someone gets a new iPhone, or set up at first boot on an Android phone. That's like 90% of the devices anyone is actually worried about. Windows support of the feature would take it to like 99.9%.
But it's possible to lose a battle you were never going to win in the first place, and end up in a worse place.
I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. Most websites will use it, and it'll become global because it's easier to just demand an ID and a photo for every user through some third party provider than to offer looser restrictions for the handful of states that have different demands. This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas.
Hasn’t the right to ask existed since the invention of consent laws?
The state being able demand a persons age, and gate their behaviour based on that, has existed for hundreds of years so far. During that entire time the requirement to be truthful has also existed otherwise the laws would be meaningless.
All that’s changing now, is figuring out how that extends into the digital realm. I personally find the argument that the digital realm is somehow special compared to the physical realm, and thus certain laws simply shouldn’t apply when “done on a computer”, difficult to reconcile.
Hard agree. I don't think we allowed video store operators in 1995 to just let kids wander into the back room and rent porn, but we're so used to there just being "no rules" online, it is coming as a massive shock now when it's being suggested that maybe there should be some basic guardrails to discourage that.
Let me be clear, I don't want face scans, or more of those creepy companies that operate this age verification crap for Discord, etc. Because I know it's not going to be implemented in the privacy-preserving way it could be, if there's ANY involvement with identity documents. Not least because we don't even have any proper cryptographically useful identity cards, so everything like that operates on a "trust us bro" basis where they pinky promise not to accidentally store everyone's raw face scans / ID cards / numbers / etc and inevitably leak them.
But out-of-box age declaration is not extreme and is not slippery-slope, any more than out-of-box user account creation 25 years ago has led to out-of-box ID card checks.
Or alternatively - you could recognize that normal people are getting more and more pissed off by the fact that social media companies are force-feeding garbage into their kids eyeballs 16 hours a day.
We could give them a reasonable solution that demonstrably preserves privacy and doesn't inconvenience anyone else (Suppose you want to see all the uncensored everything, you open your new PC or phone and say your DOB is 1/1/1900. Done. Status quo.)
Or we could be alarmist about that, torpedo that plan, and then in 2 more years when people are even MORE pissed, a horrifying new plan comes out, where the government scans your photo ID (with the help of some crappy private contractor of course) and both of them promise to probably not store the info and log your access. And that one manages to scrape by because people are at that point even more pissed and are determined to solve the problem somehow.
The actual 'bad guys' just wouldn't be able to get the public support for that second, shitty plan, if we basically solve the problem now with this very modest plan that's on the table now. Parents can handle this simple one-time out-of-box prompt and it makes sense. Device owner, the parent, that's the one who should make the call.
Slippery Slope is the assertion that A therefore B therefore C therefore D.
It is frequently a fallacy because D isn't predetermined by A when humans are involved. If you believe in free will, each of B, C, D are independent decisions. Sometimes we stop at A. Sometimes we pass Prohibition as a Constitutional Amendment, and later roll it back.
On the contrary in my experience once a legislature passes a bill to "fix" a particular problem they consider it fixed and don't update it for at least 20 years.
it depends on whether or not there's someone who sees it as a crusade (rare), sees it as a way to get political clout (very common) and/or is getting a lot of lobbying money (extremely common [1]). see, for eg, the anti-trans bills that are being passed
this is the same rhetorical and political strategy, that there are 'dangerous' people who will exploit your children so please vote for me, the person who cares the most about children and will go after the 'dangerous' people
I don’t even get that far, the proper response to my operating system asking me if I’m a minor or not is: fuck you. It isn’t a harmless question. We aren’t friends, I don’t want an algorithm of news and content, it’s an OS.
But they could also just implement verification now, which many governments are trying to do. The idea that you shouldn't let a government do one thing because they might do another thing is flawed if they could already do the other thing.
The danger of a slippery slope comes when one change enables the next change - for example, a law mandating certain kinds of data collection enables a future decision to discriminate or control based on the collected data. But in this case, no data is being collected, there's no step happening here that enables a more dangerous later step.
If anything, I'd argue this makes it harder to implement more invasive measures later, because rather than arguing that some form of age control is necessary, Illinois will specifically need to argue that age verification is necessary over the existing anonymous system. That's harder than saying "there is no protection for children right now, age verification is the only way forward".
'AnimalMuppet has the right take upthread (https://news.ycombinator.com/item?id=49249774): "Once you accept their right to ask, then you open the door to their right to a truthful answer, and thus to a verified answer.
> But they could also just implement verification now, which many governments are trying to do.
That itself is a proof: the voluntary age declaration was and is common on all the services that governments are now trying to force to do age verification, and it wasn't enough.
EDIT: in more general terms, and going beyond age verification thing and over many recent developments in information security, the Internet as a culture is missing an on-line equivalent to a key real-life social feature: the ability to answer with a shocked "gross!", followed by slapping the asker in the face.
The slope is only slippery if the change in question makes it easier for future changes to be bad. Otherwise you're only arguing for no changes to ever be made. Does this law make forced verification easier than if this law didn't exist?
Once you go up the first step of a ladder, the second step is now easier. It's a shifting of the Overton window. You can't enact full surveillance in one move - no-one would accept that. You can boil the frog over a few decades, though.
Seems so - it builds in the verification infrastructure requirement, making it dead simple to change whether it is opt in or opt out at any time.
It's actually pretty hard not to have a change be part of a slippery slope. It requires including blocks for further behavior as any subset implementation is hard to sell as not being a slippery slope path otherwise.
Potentially. The existence of the law exemplifies the idea the law is there to protect someone; all you need then to upgrade it is to argue that the current method is insufficient protection. Spirit of the law has been established - letter of the law will follow.
As someone who's pushed on a technical law change.... "easily" DEEPLY, DEEPLY misstates the challenges of getting the law changed. Fun fact: people who oppose something tend to get in the way.
So in red states porn is being used, and in blue states TikTok and Instagram are being used. Is anyone tracking who is behind the concerted efforts here? For example, which organizations, executives, lobbyists and politicians are valid and responsible parties?
Meta is one of the biggest ones pushing for this, because they don't want to be accountable so these types of laws pass the buck onto the delivery platforms (Apple, Google, other OSes)
Meta is then funding/lobbying alongside a bunch of other conservative groups like Heritage Action, and the digital childhood alliance (also made up of a ton of other conservative lobbying groups)
Sure, but Meta also wouldn't mind if age verification of some kind were used, because it would just increase the moat they already have. Meta or Google would have no difficulty complying with any of these laws regardless of how extreme they are, while the mom and pop shops can't comply and are forced out of business.
Tech incumbents whose businesses are reliant on selling ad space need to designate who is a verified human on the internet as soon as possible or their businesses go to zero once the entire web is AI bots and all the traffic is fraudulent and worthless, so they have to play as many angles as they can to achieve this.
Their website (now offline) also added this page since I posted that comment: https://web.archive.org/web/20260411112604/https://tboteproj... where they claim their website is under "surveillance" because it got a few thousand requests from Google Cloud et al, most of them to a single page. This shows how low their standards are.
You raise an interesting point in the first sentence. It might be that age sniffing could actually violate the US constitution.
As for lobbyists: I think we can probably determine the key lobbyists, e. g. if we map the data and names. And ideally also the money given to them. Ultimately they are faceless though, because corruption is easily exchangeable. The issue here is systemic though. The US "democracy" no longer exists due to that corruption. It is not rule by the people but rule by bribery.
I used to run a parental controls startup and after talking to lots of parents, I can tell you this sentiment is shared among most parents. Parents on both sides of the isle think they're going to keep their teenagers off the internet forever, I had parents look me straight in the face and say their child wouldn't be allowed online until she was 16.
Parents aren't interested in the nuance of good and bad guys, they see the internet, think it's too much trouble to keep around, and want it blocked. I suspect politicians are just mimicking this sentiment after talking to thousands of parents
> Any choice of what content to display is an algorithm.
You could argue about the language and the meaning of "algorithm", but for practical purposes I'd consider a manually-curated feed to be non-algorithmic.
Companies like Red Hat/IBM operate in Illinois and for better or worse have controlling interests in Linux and across open source projects pretty broadly. Wouldn't they be forced to include the capability in their products, which then percolate out to everyone just by network effects?
I don't see how they enforce it though? Isn't this saying every linux instance needs basically a backdoor network access? How would verify the 30 pods on my node are from minors or adults without that? Or this is more about a user facing node? So my aws nodes need to verify my age before I ssh in?
systemd is a massive blob of code that infects every part of a system and all of its subsystems. It completely changed the way system administration was done, the way init scripts work, and added tons of things to init that some argue aren't necessary, like dhcp and DNS.
Newer linux folks like it because they're used to it, people who don't like it use devuan, gentoo, or one of the others that still lets one use openRC or whatever else.
upthread someone mentioned that systemd already has the ability to store the birthdate of a user. Why would an init system need that? It doesn't, but here we are.
> Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?
Phrases can have meanings beyond just a naive combination of the words in them. And indeed "algorithmic feed" in the bill means what what we all understand that term to mean when we aren't paralyzed by pedantry.
> Under the law, [...] these users will only be shown content they request or search for or that is posted by a creator or friend they follow.
You may disagree with the motivation behind the bill, but you do the discussion a disservice to assume the people writing it are incompetent enough to not define their terms.
I think it's pretty obvious that your explanation cannot be complete or accurate. Algorithmic feeds usually have a strong influence of what they want to show you, commonly pushing stuff you aren't interested in, or anything that will keep you on their app/site longer so they have more opportunities to show you ads. There are strong conflicts of interest here.
most liked won't work. has to be chronological, and manually curated. the way fediverse works. when you make an account somewhere, you can choose to see the local people, or the entire network, but it's all chronological.
There's things like hashtag searches and whatnot, but none of it is algorithms; in the sense we understand it to mean, here, these are not manipulative algorithms designed to keep people on a site and keep ads rolling by.
on the fediverse, there are bots to curate content such as "most liked", one can subscribe to these bots to see such "views" of the feed.
there's absolutely no reason for any of that crap to be built in, other than that's how reddit (and HN) do it.
> Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?
That's a paraphrasing of what law says. The law is more clearly defined:
> "Addictive feed" means a website, online service, online
application, or mobile application, or a portion thereof, in
which multiple pieces of media generated or shared by users of
a website, online service, online application, or mobile
application, either concurrently or sequentially, are
recommended, selected, or prioritized for display to a user
based, in whole or in part, on information associated with the
user or the user's device, unless any of the following
conditions are met:
(1) the recommendation, prioritization, or selection
is based on information that is not persistently
associated with the user's device and does not concern the
user's previous interactions with media generated or
shared by other users;
(2) the recommendation, prioritization, or selection
is based on data controlled by user-selected privacy or
accessibility settings or technical information concerning
the user's device;
(3) the user expressly and unambiguously requested the
specific media, media by the author, creator, or poster of
media the user has subscribed to, or media shared by users
to a page or group the user has subscribed to, provided
that the media is not recommended, selected, or
prioritized for display based, in whole or in part, on
other information that is not permissible under this
definition;
(4) the user expressly and unambiguously requested the
specific media by a specific author, creator, or poster of
media the user has subscribed to, or media shared by users
to a page or group the user has subscribed to as described
by paragraph (3), be blocked, prioritized, or
deprioritized for display, provided that the media is not
recommended, selected, or prioritized based, in whole or
in part, on other information associated with the user or
the user's device that is not permissible under this
definition;
(5) the media is direct and private communication
between users;
(6) the media is recommended, selected, or prioritized
only in response to a specific search inquiry by the user;
(7) the media that is recommended, selected, or
prioritized for display is exclusively next in a
preexisting sequence from the same author, creator,
poster, or source; or
(8) the recommendation, prioritization, or selection
is necessary to comply with the provisions of this Act.
"Addictive social media platform" means a covered platform
that offers users or provides users with an addictive feed as a
part of the service provided by that website, online service,
online application, or mobile application.
They want an explanation of what an algorithm is. The world is full of people using words they don't understand and sometimes of them work in legislatures.
The relevant text doesn't call it an "algorithmic feed" for what it's worth. They define an "addictive" feed and it's essentially any kind of personalized recommendation.
> "Addictive feed" means a website, online service, online application, or mobile application, or a portion thereof, in which multiple pieces of media generated or shared by users of a website, online service, online application, or mobile application, either concurrently or sequentially, are recommended, selected, or prioritized for display to a user based, in whole or in part, on information associated with the user or the user's device, unless any of the following conditions are met.
It seems that it mostly bans behavior-based personalization that is opaque to the user. It seems to allow for several types of personalization where the user has agency.
That part hasn't really been decided since it's a regulatory question.
Basically the bill defines
> "Operating system provider" means a commercial or non-profit entity that controls the Internet-enabled device's operating system, including the design, programming, or supply of operating systems for the Internet-enabled devices.
Which is an extremely broad definition that could be interpreted in a whole bunch of ways.
Ok so, all the appliances and cars and TVs and who knows what other embedded electronics sold in Illinois will require the user (?) to verify their age?
I love how everyone knows this has nothing to do with kids safety. However no one can or is willing to put up a fight. In the UK where I live its the same. Government does whatever they want and most of us just shrug our shoulders and say "that's messed up" and go on about our day.
The reason is ridiculously simple: people don't put up a fight because they don't want to be labelled as a peto or as someone not in favor of the protection of Children. This is primarily why this cudgel is brought out so often: it's very difficult to oppose because you risk getting shunned for it.
Serious question: This is a out-of-box "ask for age" requirement. No one is "verifying" anything. Why are we using this misleading headline? Face scans, ID cards, all that stuff that makes everyone nervous, are specifically not a part of this. To imply that it is verification is propaganda.
As a parent, I'd be very happy with this "age declaration" method, as I also don't think the 'verification' others push for is at all worth the risks. All parents want is to put the devices permanently into a mode that flags it to third parties as belonging to a minor, so they can't just hold up their hands and say "idk they said they're 18" like they do today.
It moves the Overton window, making worse things easier to pass in the future. And it enforces requirements on projects the state should have zero jurisdiction over.
Cool. I'd like to propose a federal law wherein every lawmaker, state or otherwise, musts either demonstrate they correctly enough understand the subject they're legislating over (for every single instance of legislative act they perform) or get approval from an actual accredited expert panel before being allowed to push any more inane bullshit that will help noone in the future.
I think this is a bad thing overall, but if the OS is responsible for reporting my age, that means I get to pick my own age... I'll take what I can get.
Some states will pass laws that companies cannot show advertisements to minors. So...
I think I'm about to become a bit of a minor myself, at least whenever it serves my interests.
Nothing in this bill requires age verification. It just requires the OS to have a way to specify the user’s age (not necessarily an exact birth date), so that it can be provided to apps and websites that ask for it.
Legislating that all complex computing devices must give out your birthday (technically a "signal" of which bucket you're in, but sites are absolutely going to keep track of which bucket you where in, keep asking, and see when it changes).
It's constitutional case law that there's an implicit right to privacy in the constitution. I don't see a law that you must wear a band with your birthday out in public passing muster based on that. I don't see why existing in cyberspace changes the inherent privacy question, and in fact makes it more meaningful given ease of automation.
> It's constitutional case law that there's an implicit right to privacy in the constitution.
Constitutional scholar here! I mean, yes, that's true in a very general sense, but no court has held that age verification to gain access to a service, or even a device, is unlawful in practice.
Novice, but I'd argue that Dobbs has seriously eroded that case law. The right to privacy used to be pretty settled law, but now the foundation of that settled law is on sandy ground.
It was never really all that settled, IMO. Roe v. Wade (which is now dead) was built on a pretty shaky foundation that was inspired by emanations of privacy rights like the Fifth Amendment, in the absence of clear Constitutional language that made a privacy right explicit.
Roe v Wade was based on prior precedent from Griswald and Loving. It was also pretty well settled when Casey rolled around.
It is arguable that Griswald is the case that was based on a shaky foundation, but it seems hard to argue that Roe was as it simply used what Griswald found.
We'll see if a state decides to ban birth control.
You don't have a right to privacy. It should be covered under the 9th amendment, but the supreme court generally just ignores that amendment.
Edit: I see people don't like this comment, so here's an article about it from Wex law [1] (read under "Roe's Overturning"). The part of the Dobbs decision was removing a right to privacy and promising that it could be revisited in overturning other cases like Griswald.
The 9th amendment has never been used to establish a right to privacy, but then I don't think the 9th has ever been used to establish any right. We've used the 14th in the past to establish that right and now it seems that's no longer good law.
> While it is unclear to what extent that may have on the right to privacy in the current time; it is likely that the case law around this right will continue to evolve with more recent Supreme Court decisions.
This will end Linux as end user OS, it will stay only in Cloud and containers. Arguably, the goal here is to destroy home PC altogether. maximum we will be allowed is a laptop with endpoint verification and mandatory touch ID, locked boot and non-replaceable hardware. If you think Linux is the end of it – think again. The same crap will be implemented in BIOS/UEFI, on "HW management" level. Essentially, your bare HW only laptop will not even start without you touching fingerprint sensor and allowing it to "validate your age" against – of course government approved – HW manufacturer.
Same with smart phones – it's already here, if you tried to activate iPhone.
And projects like Open/Free BSDs? Government will sure their leaders happily retire and ... well, the community will just "die" naturally.
Thankfully for now this dragon is a hydra. Too many paths to block for now. The whole TPM fiasco with windows is preparation to put the genie back in the bottle. Soon, much sooner than I would like you will need a Global ID to access the internet, which will require an "internet safe operating system". It's only a matter of time. Get your sneakers ready folks.
Does it even ask for verification? If not, the problem with it is that it seems to require the OS provider (not the local installation) to store the age.
> "Nothing in the bill requires a passport scan or a face scan at setup. It’s self-declared, the same way most apps ask your birthday today, just centralized once at the OS level instead of repeated app by app."
However, unlike GNU plus Linux plus systemd plus FreeDesktop.org, it does not constitute a usable Operating System for a Desktop computer per se. Merely having a notion of userland isn't sufficient! Is age verification to be placed within the coreutils? I think not! Hyperfocusing on putting the API in systemd should be sufficient....
Pay no heed to anyone saying anything different, regulators!
i don't understand who this law targets. Is it targetting people who install linux on machines used by children and teens, say an overworked IT Admin at schools? or is it targetting linux developers?
So presumably the next step is they move their servers out of the US and then DA's target the Linux Foundation directly (e.g., coerce the kernel to take a change by some Meta engineers that "attests" a device when said option is compiled in, then force it as default on.. so in Debian you'd get an "Illinois"-kernel variant).
At which point the only move is to relocate the foundation to another country, which will then of course be hit by tariffs and sanctions.
Here's my slight defense of something like this, in theory. I have not read the text of the bill.
If OSes build a standards-based way to query age of user that is logged-in, where non-admins are not allowed to adjust the age bucket, then parents can configure devices on first use to have an OS-wide enforcement of age controls.
Apps and sites would query the OS, not individual app/site accounts, for user age and act accordingly.
Apps can then lock out certain features like algo feeds and adult content more consistently.
Responsibility for proper use is still on the parent, and no verification process is put upon the operators of sites.
Not sure how I actually think about this; I'm only putting this out for discussion.
I would disagree. First, passwd(5) is a venerable and rigidly-defined format. Can we please stop abusing poor GECOS for everything?
Second, storing PII in a world-readable file is unacceptable. Linux is multi-user so the administration needs to be responsible about sensitive data like that! Find somewhere else to stash it!
Illinois can put up a great firewall like China and search citizens devices for contraband operating systems. The onus is not on tech to enforce it, it's on them.
Unpopular opinion, but this is objectively better than having to upload your ID to every random website that requires an age check (if that's what the end result is).
Instead of the client sending the user's age to the server, why not make the server send a minimum age to the client? The client is welcome to block content without disclosing personal information to the server. This is as secure as sending an unverified age to the servet.
Because the requirements being placed on social media sites are much more nuanced than simply allowing or blocking content... to implement this all in the OS or browser would require an exponentially more complicated API.
In the sense that a website could just ask your OS if you are over a certain age and that age was self declared? That seems fine to me, but why can't the websites just ask me for my self declared age?
That's how things used to be and that makes more sense in my opinion because an OS isn't the thing displaying content. It just run whatever it is told to run.
>but why can't the websites just ask me for my self declared age?
Because children just click through the age gate when it suits them. With this legislation, a parent that purchases the device and creates an account for the child can set the age once and take the decision out of the kids hands. It's a huge improvement without any significant privacy issues. I can't fathom why the tech crowd is having a collective aneurism over this.
>OS isn't the thing displaying content
But the account on the OS is the right place for the single source of truth of properties of the current user.
when it comes to commerce it isn't because it makes doing business impossible. How is this practically going to look, Canonical, Red Hat and open source maintainers are going to ship 50 different Linux distributions in the United States?
The reason the US has fairly robust interstate commerce laws is because if you don't you'll have trade barriers between states. Even the most well intentioned internet company can't operate in that ecosystem
Yes the constitution specifically identifies commerce as something Congress has the power to regulate. That doesn't mean states can't have their own rules. Many states have various forms of legalized cannibis, different laws regulating firearms, or automotive emissions.
I predicted this would happen. Others also predicted this would happen.
I think now even the last person realises that this has nothing to do with age "verification". They simply hate us for our freedom. And it is clearly a move coordinated by private business here; their lobbyists are acting. This is also why it is the same law essentially in so many different countries at the same time. It is quite fascinating to watch, actually. People used to say "conspiracy nut!" - well, the facts are too clear now. That's no longer a conspiracy.
These laws still do not sit well with me. This is just going to create endless lawsuits. In my opinion the safer choice would be to avoid doing anything with current teens, that's just a non starter. Instead think of sliding windows of time and sandbox small children on a child account that if all goes well will one day be a teen and then an adult. They will thank you when they are an adult for looking out for them when they were too young to consent to the data leaked by these laws.
Why not just signal age ranges? Simple, the way the legal system works is one puts in a benign sounding law, then tweak it every year since the mechanism exists. (scope creep)"Now add city, state", "Now add DOB", "Now add address", "Now add social credit ID number citizen.", "Now add your federal wallet ID."
- For small children set an RTA header (previous discussions) [1] for any URL that may potentially contain content not appropriate for small children. Give site operators 1 year to implement this. Not counting QA and change control this takes minutes.
- Require app and device vendors to create a properly sand-boxed child account. Pen test it but it does not have to be perfect. This is for small children and default installed applications. If the child visits a URL that contains the RTA header then trigger parental controls. It is entirely up to the parent when that child is ready for mature content. It must be impossible for the child to install any applications, addons, etc... There are a myriad of ways to accomplish this.
- How is this enforced? Same way as any other parenting issue. If there is an incident that involves law enforcement, then social services can investigate and determine if negligence was occurring. When the child is mentally mature enough to deal with all the crap that is the internet their account is converted to an adult account. If the parent is giving the child an adult account before they are ready then the parent(s) go to mandatory parental training. If the child was being bullied or groomed, redirect law enforcement to go after the bullies or groomers.
- Set the laws to be active for any small child that would be under 13 as of the year 2034. Presto! One need not try to confine teens. When these small children are teens they will either be used to the sandbox account or the parent may have converted the account to adult.
As a side note all public and private schools should be legislated to have classes on dealing with all the crap the internet has to offer. Bullies, Cry-bullies, Trolls, Groomers, Scammers, Devious companies, Astroturfers, Gas Lighters, Propagandists, NGO's and so on. Also how to build friend networks so there is protection in numbers. No child should be friendless.
Linux distro founder here (stagex)
I will never be compelled to implement this, and would never merge it.
Every release requires quorum signatures by an international maintainer team, and the distro is designed to work offline-first, with some variants not even supporting network drivers in the kernel, so Illinois legislators can eat shit.
RedHat/IBM does have an Illinois presence so will likely be compelled to add it to their distro, and will likely do it through systemd. So to avoid it getting into any consumer distro you'd have to ship a patch to remove it from systemd.
This is probably all completely irrelevant to StageX since it's a distro designed to be used in containers, AFAICT.
IIRC systemd already started implementing some hooks for age verification API
systemd added a field where users can add their date of birth. It's completely optional.
It's not implementing age implementation, but can be used as a place to store a DOB in an age verification system.
AFAIK they were implemented by Microsoft staff.
If you're in the USA or plan to visit someday, I would recommend you speak with your attorney before making such commitments.
I am in the USA, but I literally cannot comply because by design it is not possible for me to ship changes without the international maintainer team agreeing to them. And Illinois legislators have no power over them.
Also, we are not a company. We are an independent community owned project. Our code is free speech and I will burn the world down to defend that right.
Truly I dare someone to try to take me to court over this. Would be great publicity for our coercion resistant approach.
They might as well try to mandate code changes to a blockchain and mandate the whole world host them.
There are a lot of remedies available to a court with respect to a recalcitrant party, ranging from an injunction to remove your product from the market to fines and imprisonment. Again, speak with your attorney. Do not try to "hack the law" yourself; many who have tried have regretted it later.
> Again, speak with your attorney. Do not try to "hack the law" yourself; many who have tried have regretted it later.
Also reach out to the EFF, who may be able to help/advise, especially if you genuinely want to fight this.
This is a terrible law. That doesn't mean it's not a law, and courts do not look kindly on people subject to their jurisdiction (which unfortunately often includes state laws to people in other states) who try to dodge the responsibility the court thinks they should have.
No need to hack the law. Our FOSS code is constitutionally protected free speech and I would defend on those grounds.
The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
> Our FOSS code is constitutionally protected free speech and I would defend on those grounds.
You have precisely zero additional speech rights as a FOSS project than any other organization has. If "free speech" was a valid defense for you, then Meta would be doing the same.
> The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes.
Being unable to comply is not a valid legal defense.
> Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators would just laugh at it.
This is the law in various places under various mechanisms. It is handled by putting people in prison or taking people's assets.
Unless the PGP decision has been overturned, code as free speech is in fact a valid defense. If the government couldn't stop code they claimed were "munitions" from getting distributed, then it seems unlikely that they'll stop a Linux distro.
Corporations do whatever seems most profitable. We can't base our understanding of constitutional rights on whether Meta decides to defend them.
There was no "PGP decision." You're making that up.
> Being unable to comply is not a valid legal defense.
Sure it is. Lawyers even have a pithy Latin maxim about it: lex non cogit ad impossibilia.
If you could stop doing that thing, it isn't an impossibility under lex non cogit ad impossibilia.
> No need to hack the law. Our FOSS code is constitutionally protected free speech and I would defend on those grounds.
"Der Proceß" [The Trial] by Franz Kafka is just a realistic description of the court system (Franz Kafka studied law).
Technical solutions may be seen as kindly as handcuffing yourself to something when told to leave. "I can't, I've made it impossible for myself to obey the law".
They might not be able to break your private keys, but they can fine you or jail you for not complying.
The concern here is probably with the shipping of the product (i.e. the binary artifacts), not the code itself. I can imagine a situation in which you could continue to make the code available, but could not produce a shippable artifact from it that Illinoians could access.
Or maybe we're at the point where we'll go to prison because of unjust laws.
You first!
There is no "market"
Thank you for fighting the good fight.
Thank you.
I respect your principled stance on one hand, while on the other I’m amazed that someone as successful as you hasn’t learned that logic doesn’t dictate how governments work.
Don’t make a target of yourself, there are countless ways for a government to make your life miserable.
I will never show fear to tech-illiterate bullies trying to compromise constitutionally protected rights. That is how freedoms get quietly lost.
Users need to see that the people in positions of influence in FOSS projects they trust are not afraid of this bullshit.
I -hope- someone is stupid enough to take a case like this to court so we can establish some much needed case law here. These overreaches deserve to be contested.
> I will never show fear
"never show fear" and "never engage intelligence" are two different things. Understand what people will do in response to your actions, and act accordingly to achieve the outcomes you want. Please by all means fight the law, and do so intelligently in a way that will actually help.
Can you be specific in how you think he is behaving unintelligently, and what you think that people will do in response to his actions?
> constitutionally protected rights
Wait, which constitutionally protected right is that? I'm an attorney and constitutional scholar and am particularly interested in what right you believe is being violated here.
Code is speech. Forcing someone to implement something is legally-compelled speech, assuming no complicating factor like commerce.
That argument has been going on for decades, and has had few victories in the court system. The DMCA, which prohibits trafficking in anticircumvention devices, even though there's a lot of code in them, is still alive and well.
I’m not a lawyer and even I know that argument would never hold up given the plethora of other laws that have been implemented through software. Not to mention copyright and patent claims too.
Is is also clear that there are major deficits in our Constitution but that the amendment process has failed to survive a modern world.
Any of our original forefathers would recognize today's American federal government as an overreach from their indended form of government.
The only reason we aren't seeing a Boston Tea Party 2.0 over the recent string of coordinated assaults against our inalienable human rights is because surveillance capitalism is already coarsely achieving its goals of suppressing any civic participation which exists between the spectrum of ineffective political protest to the most desperate, radical action.
Some of those among us simply cannot drink this koolaid. A quote from MLK, Jr:
Further reading https://letterfromjail.com/While they may take you to court over this, make sure you can survive sitting in jail at first if government decides to make an example of you.
And where code is speech, is a distribution speech? There's a lot of places for this to go sideways on you personally.
Good news: the legislation doesn't target you as an individual.
stagex accepts tax deductable donations via opencollective but we do not actually have a registered legal entity, so yes, probably fine.
I mostly just want to make it clear this type of legislation is unenforceable and a waste of everyone's time.
> accepts tax deductable donations via opencollective but we do not actually have a registered legal entity
that, uh, sounds sketchy
Opencollective collects funds to distribute to open source project maintainers. Not that it matters. We have never collected a single donation, but figured it was worth a shot. lol.
So OEMs will only be shipping Windows and that's more or less it.
And it will be wiped immediately as usual, so sure whatever.
Or it will have some new TPM/SecureBoot guard rails to not let minors install unapproved systems. Think of children again ;)
I specialize in TPM security and know plenty of ways to bypass it with physical access to consumer laptop hardware, and would gladly make that easy for the public if needed.
But I hope they try this. It will be funny to watch the public humiliation of how hard it fails at scale.
> ”Linux distro founder here (stagex)… designed to work offline-first, with some variants not even supporting network drivers”
If your OS doesn’t access the internet or isn’t intended to run browsers / social apps, then you are outside the scope of this legislation. That would be a bit like requiring a toaster to ask for your age before letting you operate it.
But someone could attach a GPU in the offline OS and use it to generate porn with local AI models! Oh no! How will we stop them?!
They can stop you from doing any work on the project. They can even fine or jail you for work done after the law takes affect that the international committee doesn't allow. Which is to say you can be forced to stop work.
Though if you don't live in IL it is unclear how this affects you.
Some time in jail or having to fight a fine for refusing to implement features in the constitutionally protected free speech code they author? If that is what it takes.
I do not want to go to jail, but if that is the only way to get to an outcome where people have confidence they can not be forced to add unwanted code to open source projects, so be it. But that is a pointless thought experiment because it will never happen.
I do not think anyone would be stupid enough to jail a FOSS developer for not agreeing to compelled speech, and if they did, an army of lawyers would be lining up to take the case I expect, with the full support of the public. It would be an insane thing to attempt.
We must loudly push back on the chilling effects intended here. Our free speech to write or not write any code we want will not be compromised.
Governments can hire a hitman to go after you, if you say something wrong. So can international crime syndicates. Will this have a meaningful effect on chilling your speech?
https://abcnews.com/amp/US/children-recruited-criminals-indu...
Pretty far fetched an Illinois legislator hires a hitman for a FOSS developer.
But to humor you, if they did, the distro would carry right on, so they would be taking a lot of risk with no progress on their objective.
I only sign like 1/3 releases these days so I am replaceable now. Decentralized control and decentralized trust was the whole point of stagex.
> Linux distro founder here (stagex)
What does it mean to "found" a Linux distro? Can you describe it?
https://stagex.tools
i like the cut of your jib
Just wait until all vendors are required to lock down their devices like Apple does. Apple has shown that it is possible, thanks Apple!
How many jailbreaks has Apple had now? I even have an Apple DRM bypass not public yet. We will be fine ;)
I feel like all of these laws are being designed backwards. Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion.
Requiring my kids' devices to advertise their age (or their age "bucket", as if that was a meaningful difference) to protect them is not doing me or my kids any favors.
Having the ability to identify who is watching or saying what on the internet would be immensely useful to the government; the justifications are really meaningless.
Anti-money-laundering is a comparable field, as all the AML regulations and laws are ineffective at identifying money launderers, but they're wonderful for verifying (auditing and prosecuting) tax compliance.
> Anti-money-laundering is a comparable field, as all the AML regulations and laws are ineffective at identifying money launderers, but they're wonderful for verifying (auditing and prosecuting) tax compliance.
As someone who’s implemented AML, KYC, and tax reporting functions in a bank. I think you would be very surprised at how shit they are for tax auditing at scale. Unless the tax man is specifically auditing you, and basically requesting all your transaction details, the reporting that banks do would only allow tax agencies to catch the most brazen and incompetent tax dodgers.
All of the tools however do make much harder to perform money laundering, forcing criminals to recruit and pay huge numbers of naive bank customers to allow criminals to launder money via their personal accounts, using them as money mules. Which then gets flagged and shutdown pretty quick by banks because the behaviour is generally pretty obvious.
Unfortunately (or fortunately depending on your perspective) banks can’t/don’t coordinate on identified money mules or know launderers, so criminals just move on to other banks and repeat.
> Unfortunately (or fortunately depending on your perspective) banks can’t/don’t coordinate on identified money mules or know launderers, so criminals just move on to other banks and repeat.
Or criminals just get a bank like HSBC to do the money laundering for them.
Criminals don't have to "recruit and pay huge numbers of naive bank customers"; in my jurisdiction, they just walk into a casino with a few hundred thousand dollars, exchange for chips, pretend to gamble for an hour, then exchange the chips for cash, and walk out with a nice receipt. There're more complex schemes involving real estate and other mediums too.
That’s cute, but it doesn’t really scale. Organised crime groups aren’t interested in laundering a few $100k at a go. They’re moving and laundering millions, you can’t put that through a casino without it being very obvious.
There is a huge international criminal industry that exists to find and hire money mules, and launder eye watering amounts of cash. Where I worked, we broadly assumed that the police weren’t interested in fraud or money laundering unless it was measured in 10s of millions. We reported everything, of course, but we only got call backs for really big schemes.
If you’re just committing fraud measured in $100ks, the odd of anyone bothering to investigate, and attempt to bring criminal charges, was basically zero.
The larger-scale money laundering in my area is a but more complicated, involving import/export schemes, real estate transactions, and property developments. I'm not in a mega-city, so I assume these schemes are taking place at a larger scale in those. I have only ever heard of very basic and stupid schemes (which didn't provide any tax revenue to my goverment) being detected or prosecuted.
> Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion.
If the intent were to actually protect children, then this would be what was done.
"Protect the children" is just a subterfuge to get electorate support for voting for the foundation for a "1984 thought crime" style monitoring of the internet.
And surveillance capitalism
They're actually designed quite well for the intended purpose: mass surveillance and suppression of speech.
Don't ever for one second pretend this is about anything else.
Why then did this completely leave out verification? Parents want and accept the out-of-box declaration idea. It requires no ID, no face scans, no "ID dot ME" or whatever. As parents we are more than able to open the box before giving our kids a laptop or phone and entering their DOB, and also able to see with our own eyes if the kid suddenly turns up with a second cell phone that they bought and configured as an adult.
Any parents who are pathetically absent from parenting their kids, well, they can just go right on ignoring their kids and letting the kid themselves put in 9/9/99, and consume all kinds of inappropriate crap.
This particular law is respecting everyone's rights.
I would argue the reason is so people can make arguments like yours.
Step 1: get easily passed, simple looking laws passed to 'protect the children' Step 2: 'oh look at all these people bypassing the law. It's so simple for a child to watch porn with this.' Step 3: increase the requirements bit by bit on the verification
By letting something simple pass, they can claim it's not thst bad, and anyone who argues against it is being hyperbolic.
> I feel like all of these laws are being designed backwards. Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion.
This was tried in the past:
* https://www.w3.org/2007/powder/
* https://www.w3.org/PICS/
This is definitely not about "protect the kids" or age verification, this is a stepping stone to full identity verification to use the internet at all.
I'm now pretty convinced that this is the best argument for persuading non-technical and non-internet-privacy minded people why this is a problem. It's hard to explain all the technical factors that make it impossible to implement without compromising privacy... but it's pretty easy to get them to understand the real intent. If you start them thinking through what mechanisms would make sense _if_ the original premise truly was protecting kids from content they aren't ready to see, it's easy to arrive at that answer, and equally easy to see why "everyone must provide their ID so we can verify their age" probably comes from other motivations.
> "everyone must provide their ID so we can verify their age"
but that's not this law. This law requires self-declaration by whoever creates the accounts on the device.
and that's as useful as self-documenting "i am over 18" or "over 21" for things that require that, without any document checks.
this is a way to get something legal on paper, the rest of the stuff (patches, if you will) comes later. This asserts that age is important enough to force an operating system to comply, this opens the door.
The idea of a 'user agent' where the 'device owner' decides 'what should be displayed and how' is ancient history, grandad.
Modern social media is delivered through 'apps' which are like web browsers, except without ad blockers or privacy settings, and with push notifications to make them more addictive, and they only show one website, and they're each 5x the size of a web browser for some reason.
Parents already have the ability to do this, at least when it comes to porn. The fact is that most parents aren't doing it. Hence the push for legislation that increase the uptake of content blocks for minors.
Or anyone else!
This isn’t for the protection of kids. It’s for the protection of profits by surveillance capitalism.
Did you read the law? It actually imposes very (in my humble opinion) good rules on the content providers, specifically social media. We know why social media is addictive - the personalized feeds are highly optimized to extend usage time, with no amount of time being "good enough." Social media sites would be banned from using this type of feed, limiting it to feeds of content you've subscribed to or requested only. Instead of seeing mainly influencers and viral videos, people might even start seeing their friends' own content.
> Requiring my kids' devices to advertise their age ... to protect them is not doing me or my kids any favors.
Idk about you, but it'd be doing me favors because my kids will not be physically able to use the most addictive platforms that exist today in their current form. It would be a major disruption to the behavioral manipulation that Meta, TikTok, and X do.
Right, I'm saying that if the goal is to keep kids off of addictive social feeds, it would be better to have social media have to say "this site implements addictive feeds" and then I can configure my kids' devices to disallow that. The decision should be happening in my house on the devices I control, not in a Meta data center. The current law just gives Meta a way to start building a shadow profile early.
Controlling my information consumption is not a legitimate function of the state. If algorithmic feeds get a lot of use, it's because people like them. Is that so hard to comprehend? That your preferences are not universal? And that you shouldn't use the government to bludgeon people into accepting the kind of information feed you, personally, would prefer for them? What gives you the right to do so?
What you calling "addictive" is just revealed preferences of the populace.
It seems like after Epstein was gone a lot of politicians in many countries suddenly want to identify children, take photos for "age identification", and their ages and what apps they use. Very strange.
How dare you try to use a system that we've used for generations!
Not that I'm condoning it, but this law requires self-declaration, not verification. It might sound pedantic but the practical difference is huge.
Self-declaration means that the system asks the user to declare if they are a minor. Nothing is verified.
Age verification typically means a system which checks ID or has other enforcement measures to try to verify age.
It is a technical ratchet. Once you accept part of the implementation it will never be undone, more will be added.
I don't think this is a safe assumption.
As a counter, actual age verification is being rolled out in other places. I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. Between the anti-porn types and public demand for some kind of regulations on social media, regulation of some kind is inevitable.
Our actual choice may only be what type of restriction we can live with, and I much prefer this type to the kind that requires websites to demand my id and photos of my face. Especially since some implementations of this concept (the California one, I think) declare that websites aren't legally required to look deeper than the attested age, which is a very nice feature.
Mind you, I don't know why the legislators are bothering mandating OS support for these features. It would be much easier to mandate that websites support the feature, make it clear to them that supporting the feature appropriately will free them from liability for children accessing content, and then wait as users demand that their OS support the feature.
Re: your last paragraph
I actually agree with you, if you mandate that the site has to look for an affirmative signal and if it doesn't get one, has to assume the user is the youngest possible age group. Users would demand the proper support for it.
Although it would have to have some teeth capable of biting the client software companies, because for instance, if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls).
Honestly though - because kids (especially the younger set) are hard pressed to buy their own hardware, a property that can only be set up out of the box, and can only be undone by using the account password of the parent who set it up, it is the perfect level of security here. And as for browsers, all you need is the gatekeepers (Apple, Google, MS) to agree not to ship in their "stores" browsers designed to evade it. Yes, you can totally compile your own browser, but most kids are using locked platforms like iOS and Android, and are by default denied permissions to run arbitrary software on platforms like Mac and Windows, so that's fine.
Yeah, that's pretty much what I am imagining. You're right about needing some teeth - maybe the legislature could define a spec, and penalties for implementing the feature in a commercial product without actually following the spec.
I really think all we need is what you describe in your third paragraph. It doesn't need to be bulletproof, it just needs to be an easy way for parents to set the level of content their children can access without them having to hover over their children at all times. Something like that could easily be set up in the Genius store when someone gets a new iPhone, or set up at first boot on an Android phone. That's like 90% of the devices anyone is actually worried about. Windows support of the feature would take it to like 99.9%.
> I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism.
It is impossible to win a battle you stop fighting.
But it's possible to lose a battle you were never going to win in the first place, and end up in a worse place.
I think that if these types of laws (illinois, california) don't hit a critical mass, we're going to see ID verification become the dominant method of age verification. Most websites will use it, and it'll become global because it's easier to just demand an ID and a photo for every user through some third party provider than to offer looser restrictions for the handful of states that have different demands. This is especially true since it's now been demonstrated that states (like Texas) can go after out-of-state sites serving people in Texas.
Stronger: Once you accept their right to ask, then you open the door to their right to a truthful answer, and thus to a verified answer.
Hasn’t the right to ask existed since the invention of consent laws?
The state being able demand a persons age, and gate their behaviour based on that, has existed for hundreds of years so far. During that entire time the requirement to be truthful has also existed otherwise the laws would be meaningless.
All that’s changing now, is figuring out how that extends into the digital realm. I personally find the argument that the digital realm is somehow special compared to the physical realm, and thus certain laws simply shouldn’t apply when “done on a computer”, difficult to reconcile.
Hard agree. I don't think we allowed video store operators in 1995 to just let kids wander into the back room and rent porn, but we're so used to there just being "no rules" online, it is coming as a massive shock now when it's being suggested that maybe there should be some basic guardrails to discourage that.
Let me be clear, I don't want face scans, or more of those creepy companies that operate this age verification crap for Discord, etc. Because I know it's not going to be implemented in the privacy-preserving way it could be, if there's ANY involvement with identity documents. Not least because we don't even have any proper cryptographically useful identity cards, so everything like that operates on a "trust us bro" basis where they pinky promise not to accidentally store everyone's raw face scans / ID cards / numbers / etc and inevitably leak them.
But out-of-box age declaration is not extreme and is not slippery-slope, any more than out-of-box user account creation 25 years ago has led to out-of-box ID card checks.
Literally a slippery slope argument
Sometimes when you see your opponents getting out a ramp and a barrel of lube, you can call it a slippery slope.
Or alternatively - you could recognize that normal people are getting more and more pissed off by the fact that social media companies are force-feeding garbage into their kids eyeballs 16 hours a day.
We could give them a reasonable solution that demonstrably preserves privacy and doesn't inconvenience anyone else (Suppose you want to see all the uncensored everything, you open your new PC or phone and say your DOB is 1/1/1900. Done. Status quo.)
Or we could be alarmist about that, torpedo that plan, and then in 2 more years when people are even MORE pissed, a horrifying new plan comes out, where the government scans your photo ID (with the help of some crappy private contractor of course) and both of them promise to probably not store the info and log your access. And that one manages to scrape by because people are at that point even more pissed and are determined to solve the problem somehow.
The actual 'bad guys' just wouldn't be able to get the public support for that second, shitty plan, if we basically solve the problem now with this very modest plan that's on the table now. Parents can handle this simple one-time out-of-box prompt and it makes sense. Device owner, the parent, that's the one who should make the call.
It's a fallacy when there is no cause and effect for each step. This, however states the steps.
What? The GP comment is one single line which states that it just "will" happen.
Slippery slope actually works though.
Makes no sense to treat it like some unwelcome argument
Slippery Slope is the assertion that A therefore B therefore C therefore D.
It is frequently a fallacy because D isn't predetermined by A when humans are involved. If you believe in free will, each of B, C, D are independent decisions. Sometimes we stop at A. Sometimes we pass Prohibition as a Constitutional Amendment, and later roll it back.
Only if it was not something they constantly already do.
In a philosophy classroom, it’s a fallacy. In a courtroom, it’s called precedent.
slippery slope is if you say 'if a therefore d' not 'a leads to b leads to c leads to d'
it is the thin edge of a slippery wedge..
"Slippery slope" is a term like "conspiracy theory". Tarnished by overuse, often misapplied, but they absolutely exist.
I would rather call it the boiling frog. But hey, whatever floats your boat.
that is the start of a lot of bills like this... they really only ever increase in scope and invasiveness.
On the contrary in my experience once a legislature passes a bill to "fix" a particular problem they consider it fixed and don't update it for at least 20 years.
it depends on whether or not there's someone who sees it as a crusade (rare), sees it as a way to get political clout (very common) and/or is getting a lot of lobbying money (extremely common [1]). see, for eg, the anti-trans bills that are being passed
this is the same rhetorical and political strategy, that there are 'dangerous' people who will exploit your children so please vote for me, the person who cares the most about children and will go after the 'dangerous' people
[1] https://themarkup.org/privacy/2021/04/15/big-tech-is-pushing...
What is the connection to “anti-trans bills”?
Unless there is a big lobby behind getting more "fixes".
Think of it like a foot in the door.
Everyone else’s arguing slippery slope.
I don’t even get that far, the proper response to my operating system asking me if I’m a minor or not is: fuck you. It isn’t a harmless question. We aren’t friends, I don’t want an algorithm of news and content, it’s an OS.
I don't see the argument here. You can easily adjust the law to force verification.
You seem to assume that "this is now final, nothing will change after that". Why would you assume this to be the case?
But they could also just implement verification now, which many governments are trying to do. The idea that you shouldn't let a government do one thing because they might do another thing is flawed if they could already do the other thing.
The danger of a slippery slope comes when one change enables the next change - for example, a law mandating certain kinds of data collection enables a future decision to discriminate or control based on the collected data. But in this case, no data is being collected, there's no step happening here that enables a more dangerous later step.
If anything, I'd argue this makes it harder to implement more invasive measures later, because rather than arguing that some form of age control is necessary, Illinois will specifically need to argue that age verification is necessary over the existing anonymous system. That's harder than saying "there is no protection for children right now, age verification is the only way forward".
'AnimalMuppet has the right take upthread (https://news.ycombinator.com/item?id=49249774): "Once you accept their right to ask, then you open the door to their right to a truthful answer, and thus to a verified answer.
> But they could also just implement verification now, which many governments are trying to do.
That itself is a proof: the voluntary age declaration was and is common on all the services that governments are now trying to force to do age verification, and it wasn't enough.
EDIT: in more general terms, and going beyond age verification thing and over many recent developments in information security, the Internet as a culture is missing an on-line equivalent to a key real-life social feature: the ability to answer with a shocked "gross!", followed by slapping the asker in the face.
The slope is only slippery if the change in question makes it easier for future changes to be bad. Otherwise you're only arguing for no changes to ever be made. Does this law make forced verification easier than if this law didn't exist?
Once you go up the first step of a ladder, the second step is now easier. It's a shifting of the Overton window. You can't enact full surveillance in one move - no-one would accept that. You can boil the frog over a few decades, though.
Seems so - it builds in the verification infrastructure requirement, making it dead simple to change whether it is opt in or opt out at any time.
It's actually pretty hard not to have a change be part of a slippery slope. It requires including blocks for further behavior as any subset implementation is hard to sell as not being a slippery slope path otherwise.
Potentially. The existence of the law exemplifies the idea the law is there to protect someone; all you need then to upgrade it is to argue that the current method is insufficient protection. Spirit of the law has been established - letter of the law will follow.
As someone who's pushed on a technical law change.... "easily" DEEPLY, DEEPLY misstates the challenges of getting the law changed. Fun fact: people who oppose something tend to get in the way.
So in red states porn is being used, and in blue states TikTok and Instagram are being used. Is anyone tracking who is behind the concerted efforts here? For example, which organizations, executives, lobbyists and politicians are valid and responsible parties?
Meta is one of the biggest ones pushing for this, because they don't want to be accountable so these types of laws pass the buck onto the delivery platforms (Apple, Google, other OSes)
Meta is then funding/lobbying alongside a bunch of other conservative groups like Heritage Action, and the digital childhood alliance (also made up of a ton of other conservative lobbying groups)
Sure, but Meta also wouldn't mind if age verification of some kind were used, because it would just increase the moat they already have. Meta or Google would have no difficulty complying with any of these laws regardless of how extreme they are, while the mom and pop shops can't comply and are forced out of business.
Tech incumbents whose businesses are reliant on selling ad space need to designate who is a verified human on the internet as soon as possible or their businesses go to zero once the entire web is AI bots and all the traffic is fraudulent and worthless, so they have to play as many angles as they can to achieve this.
Its ad tech, as always.
This seems to have more information. https://www.reddit.com/r/linux/comments/1rshc1f/i_traced_2_b...
The Reddit post you linked to was hallucinated by Claude, see https://news.ycombinator.com/item?id=47659552
Their website (now offline) also added this page since I posted that comment: https://web.archive.org/web/20260411112604/https://tboteproj... where they claim their website is under "surveillance" because it got a few thousand requests from Google Cloud et al, most of them to a single page. This shows how low their standards are.
TL;DR: They claim it's Meta (which yeah it would make a lot of sense).
You raise an interesting point in the first sentence. It might be that age sniffing could actually violate the US constitution.
As for lobbyists: I think we can probably determine the key lobbyists, e. g. if we map the data and names. And ideally also the money given to them. Ultimately they are faceless though, because corruption is easily exchangeable. The issue here is systemic though. The US "democracy" no longer exists due to that corruption. It is not rule by the people but rule by bribery.
I used to run a parental controls startup and after talking to lots of parents, I can tell you this sentiment is shared among most parents. Parents on both sides of the isle think they're going to keep their teenagers off the internet forever, I had parents look me straight in the face and say their child wouldn't be allowed online until she was 16.
Parents aren't interested in the nuance of good and bad guys, they see the internet, think it's too much trouble to keep around, and want it blocked. I suspect politicians are just mimicking this sentiment after talking to thousands of parents
Any advice on how to dismantle and counter such arguments, individually and at scale?
Perhaps they shouldn't be allowed to school until 16? School and other kids can expose theirs to many detrimental things.
What does that mean, practically? The person who installed linux on that particular device is liable?
>no algorithmic feeds for minors by default
Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?
> Any choice of what content to display is an algorithm.
You could argue about the language and the meaning of "algorithm", but for practical purposes I'd consider a manually-curated feed to be non-algorithmic.
"Illinois now requires operating system providers, open source projects included, to build age verification by 2028"
however
"nothing in the bill has teeth against someone with no business presence in Illinois"
Companies like Red Hat/IBM operate in Illinois and for better or worse have controlling interests in Linux and across open source projects pretty broadly. Wouldn't they be forced to include the capability in their products, which then percolate out to everyone just by network effects?
I don't see how they enforce it though? Isn't this saying every linux instance needs basically a backdoor network access? How would verify the 30 pods on my node are from minors or adults without that? Or this is more about a user facing node? So my aws nodes need to verify my age before I ssh in?
Remote desktop services?
Sounds so complicated to actually do.
finally the die hard systemd haters will have an actually valid point.
I’m unfamiliar with systemd’s haters or why this would give them a valid point. Could you please elaborate?
systemd is a massive blob of code that infects every part of a system and all of its subsystems. It completely changed the way system administration was done, the way init scripts work, and added tons of things to init that some argue aren't necessary, like dhcp and DNS.
Newer linux folks like it because they're used to it, people who don't like it use devuan, gentoo, or one of the others that still lets one use openRC or whatever else.
upthread someone mentioned that systemd already has the ability to store the birthdate of a user. Why would an init system need that? It doesn't, but here we are.
> Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?
Phrases can have meanings beyond just a naive combination of the words in them. And indeed "algorithmic feed" in the bill means what what we all understand that term to mean when we aren't paralyzed by pedantry.
> Under the law, [...] these users will only be shown content they request or search for or that is posted by a creator or friend they follow.
You may disagree with the motivation behind the bill, but you do the discussion a disservice to assume the people writing it are incompetent enough to not define their terms.
Algorithmic feeds are just search algorithms based on what the user is asking to see with their behavior.
I think it's pretty obvious that your explanation cannot be complete or accurate. Algorithmic feeds usually have a strong influence of what they want to show you, commonly pushing stuff you aren't interested in, or anything that will keep you on their app/site longer so they have more opportunities to show you ads. There are strong conflicts of interest here.
Presumably this means no targeting the user's preferences and just showing everything by newest/most liked.
most liked won't work. has to be chronological, and manually curated. the way fediverse works. when you make an account somewhere, you can choose to see the local people, or the entire network, but it's all chronological.
There's things like hashtag searches and whatnot, but none of it is algorithms; in the sense we understand it to mean, here, these are not manipulative algorithms designed to keep people on a site and keep ads rolling by.
on the fediverse, there are bots to curate content such as "most liked", one can subscribe to these bots to see such "views" of the feed.
there's absolutely no reason for any of that crap to be built in, other than that's how reddit (and HN) do it.
> Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?
That's a paraphrasing of what law says. The law is more clearly defined:
> "Addictive feed" means a website, online service, online application, or mobile application, or a portion thereof, in which multiple pieces of media generated or shared by users of a website, online service, online application, or mobile application, either concurrently or sequentially, are recommended, selected, or prioritized for display to a user based, in whole or in part, on information associated with the user or the user's device, unless any of the following conditions are met: (1) the recommendation, prioritization, or selection is based on information that is not persistently associated with the user's device and does not concern the user's previous interactions with media generated or shared by other users; (2) the recommendation, prioritization, or selection is based on data controlled by user-selected privacy or accessibility settings or technical information concerning the user's device; (3) the user expressly and unambiguously requested the specific media, media by the author, creator, or poster of media the user has subscribed to, or media shared by users to a page or group the user has subscribed to, provided that the media is not recommended, selected, or prioritized for display based, in whole or in part, on other information that is not permissible under this definition; (4) the user expressly and unambiguously requested the specific media by a specific author, creator, or poster of media the user has subscribed to, or media shared by users to a page or group the user has subscribed to as described by paragraph (3), be blocked, prioritized, or deprioritized for display, provided that the media is not recommended, selected, or prioritized based, in whole or in part, on other information associated with the user or the user's device that is not permissible under this definition; (5) the media is direct and private communication between users; (6) the media is recommended, selected, or prioritized only in response to a specific search inquiry by the user; (7) the media that is recommended, selected, or prioritized for display is exclusively next in a preexisting sequence from the same author, creator, poster, or source; or (8) the recommendation, prioritization, or selection is necessary to comply with the provisions of this Act. "Addictive social media platform" means a covered platform that offers users or provides users with an addictive feed as a part of the service provided by that website, online service, online application, or mobile application.
They want an explanation of what an algorithm is. The world is full of people using words they don't understand and sometimes of them work in legislatures.
The text of the bill is here: https://ilga.gov/Legislation/BillStatus/FullText?GAID=18&Doc.... There's about 3.5 pages of text defining this.
The relevant text doesn't call it an "algorithmic feed" for what it's worth. They define an "addictive" feed and it's essentially any kind of personalized recommendation.
> "Addictive feed" means a website, online service, online application, or mobile application, or a portion thereof, in which multiple pieces of media generated or shared by users of a website, online service, online application, or mobile application, either concurrently or sequentially, are recommended, selected, or prioritized for display to a user based, in whole or in part, on information associated with the user or the user's device, unless any of the following conditions are met.
It seems that it mostly bans behavior-based personalization that is opaque to the user. It seems to allow for several types of personalization where the user has agency.
That part hasn't really been decided since it's a regulatory question.
Basically the bill defines
> "Operating system provider" means a commercial or non-profit entity that controls the Internet-enabled device's operating system, including the design, programming, or supply of operating systems for the Internet-enabled devices.
Which is an extremely broad definition that could be interpreted in a whole bunch of ways.
Ok so, all the appliances and cars and TVs and who knows what other embedded electronics sold in Illinois will require the user (?) to verify their age?
Since TFA can't be bothered, here's the text of the actual bill: https://my.ilga.gov/Legislation/BillStatus/FullText?GAID=18&...
I love how everyone knows this has nothing to do with kids safety. However no one can or is willing to put up a fight. In the UK where I live its the same. Government does whatever they want and most of us just shrug our shoulders and say "that's messed up" and go on about our day.
The reason is ridiculously simple: people don't put up a fight because they don't want to be labelled as a peto or as someone not in favor of the protection of Children. This is primarily why this cudgel is brought out so often: it's very difficult to oppose because you risk getting shunned for it.
Serious question: This is a out-of-box "ask for age" requirement. No one is "verifying" anything. Why are we using this misleading headline? Face scans, ID cards, all that stuff that makes everyone nervous, are specifically not a part of this. To imply that it is verification is propaganda.
As a parent, I'd be very happy with this "age declaration" method, as I also don't think the 'verification' others push for is at all worth the risks. All parents want is to put the devices permanently into a mode that flags it to third parties as belonging to a minor, so they can't just hold up their hands and say "idk they said they're 18" like they do today.
Two reasons people are arguing against it:
It moves the Overton window, making worse things easier to pass in the future. And it enforces requirements on projects the state should have zero jurisdiction over.
Cool. I'd like to propose a federal law wherein every lawmaker, state or otherwise, musts either demonstrate they correctly enough understand the subject they're legislating over (for every single instance of legislative act they perform) or get approval from an actual accredited expert panel before being allowed to push any more inane bullshit that will help noone in the future.
It’s a series of tubes! It’s not a big truck!
I think this is a bad thing overall, but if the OS is responsible for reporting my age, that means I get to pick my own age... I'll take what I can get.
Some states will pass laws that companies cannot show advertisements to minors. So...
I think I'm about to become a bit of a minor myself, at least whenever it serves my interests.
I'm surprised we're not seeing heaps of lawsuits here. Age verification in general violates privacy.
Nothing in this bill requires age verification. It just requires the OS to have a way to specify the user’s age (not necessarily an exact birth date), so that it can be provided to apps and websites that ask for it.
lawsuits for what? AFAIK you have no right to privacy in this sense
Legislating that all complex computing devices must give out your birthday (technically a "signal" of which bucket you're in, but sites are absolutely going to keep track of which bucket you where in, keep asking, and see when it changes).
It's constitutional case law that there's an implicit right to privacy in the constitution. I don't see a law that you must wear a band with your birthday out in public passing muster based on that. I don't see why existing in cyberspace changes the inherent privacy question, and in fact makes it more meaningful given ease of automation.
> It's constitutional case law that there's an implicit right to privacy in the constitution.
Constitutional scholar here! I mean, yes, that's true in a very general sense, but no court has held that age verification to gain access to a service, or even a device, is unlawful in practice.
Novice, but I'd argue that Dobbs has seriously eroded that case law. The right to privacy used to be pretty settled law, but now the foundation of that settled law is on sandy ground.
It was never really all that settled, IMO. Roe v. Wade (which is now dead) was built on a pretty shaky foundation that was inspired by emanations of privacy rights like the Fifth Amendment, in the absence of clear Constitutional language that made a privacy right explicit.
Roe v Wade was based on prior precedent from Griswald and Loving. It was also pretty well settled when Casey rolled around.
It is arguable that Griswald is the case that was based on a shaky foundation, but it seems hard to argue that Roe was as it simply used what Griswald found.
We'll see if a state decides to ban birth control.
> I'm surprised we're not seeing heaps of lawsuits here.
Why do you think that is?
You don't have a right to privacy. It should be covered under the 9th amendment, but the supreme court generally just ignores that amendment.
Edit: I see people don't like this comment, so here's an article about it from Wex law [1] (read under "Roe's Overturning"). The part of the Dobbs decision was removing a right to privacy and promising that it could be revisited in overturning other cases like Griswald.
The 9th amendment has never been used to establish a right to privacy, but then I don't think the 9th has ever been used to establish any right. We've used the 14th in the past to establish that right and now it seems that's no longer good law.
> While it is unclear to what extent that may have on the right to privacy in the current time; it is likely that the case law around this right will continue to evolve with more recent Supreme Court decisions.
[1] https://www.law.cornell.edu/wex/right_to_privacy
TL;DR: learn how to live without computers.
This will end Linux as end user OS, it will stay only in Cloud and containers. Arguably, the goal here is to destroy home PC altogether. maximum we will be allowed is a laptop with endpoint verification and mandatory touch ID, locked boot and non-replaceable hardware. If you think Linux is the end of it – think again. The same crap will be implemented in BIOS/UEFI, on "HW management" level. Essentially, your bare HW only laptop will not even start without you touching fingerprint sensor and allowing it to "validate your age" against – of course government approved – HW manufacturer.
Same with smart phones – it's already here, if you tried to activate iPhone.
And projects like Open/Free BSDs? Government will sure their leaders happily retire and ... well, the community will just "die" naturally.
Thankfully for now this dragon is a hydra. Too many paths to block for now. The whole TPM fiasco with windows is preparation to put the genie back in the bottle. Soon, much sooner than I would like you will need a Global ID to access the internet, which will require an "internet safe operating system". It's only a matter of time. Get your sneakers ready folks.
Does it even ask for verification? If not, the problem with it is that it seems to require the OS provider (not the local installation) to store the age.
No, no verification. From the post:
> "Nothing in the bill requires a passport scan or a face scan at setup. It’s self-declared, the same way most apps ask your birthday today, just centralized once at the OS level instead of repeated app by app."
Democrat Representative Jennifer Gong-Gershowitz in the House
Democrat Senator Willie Preston [D] in the senate
The law: https://www.ilga.gov/documents/legislation/publicacts/104/10...
2 days ago, 123 comments: https://news.ycombinator.com/item?id=49228350
as Linus would say, that is a userland issue, not a Linux issue
as Stallman would say, that is a userland issue not a GNU/Linux issue ;P
Incorrect. GNU/Linux includes userland while Linux doesn't.
However, unlike GNU plus Linux plus systemd plus FreeDesktop.org, it does not constitute a usable Operating System for a Desktop computer per se. Merely having a notion of userland isn't sufficient! Is age verification to be placed within the coreutils? I think not! Hyperfocusing on putting the API in systemd should be sufficient....
Pay no heed to anyone saying anything different, regulators!
This renders all servers in Illinois illegal. Thanks.
Backdoor way to get data centers out of your state.
i don't understand who this law targets. Is it targetting people who install linux on machines used by children and teens, say an overworked IT Admin at schools? or is it targetting linux developers?
Declaration, not verification
The interesting part here is enforcement. Linux isn't controlled by a single vendor, so I'm not sure who the law would actually target.
A Linux distribution is
So presumably the next step is they move their servers out of the US and then DA's target the Linux Foundation directly (e.g., coerce the kernel to take a change by some Meta engineers that "attests" a device when said option is compiled in, then force it as default on.. so in Debian you'd get an "Illinois"-kernel variant).
At which point the only move is to relocate the foundation to another country, which will then of course be hit by tariffs and sanctions.
"another country" is drafting this same law right now.
Here's my slight defense of something like this, in theory. I have not read the text of the bill.
If OSes build a standards-based way to query age of user that is logged-in, where non-admins are not allowed to adjust the age bucket, then parents can configure devices on first use to have an OS-wide enforcement of age controls.
Apps and sites would query the OS, not individual app/site accounts, for user age and act accordingly.
Apps can then lock out certain features like algo feeds and adult content more consistently.
Responsibility for proper use is still on the parent, and no verification process is put upon the operators of sites.
Not sure how I actually think about this; I'm only putting this out for discussion.
Storing age is no different to storing name or address to me, it’s just a field in /etc/passwd, and root can change it.
I would disagree. First, passwd(5) is a venerable and rigidly-defined format. Can we please stop abusing poor GECOS for everything?
Second, storing PII in a world-readable file is unacceptable. Linux is multi-user so the administration needs to be responsible about sensitive data like that! Find somewhere else to stash it!
Insert X reason to steal user freedom
Gross. Age verification is a completely degenerate level of privacy violation
[dupe] Earlier: https://news.ycombinator.com/item?id=49228350
What does this have to do with us?
Illinois can put up a great firewall like China and search citizens devices for contraband operating systems. The onus is not on tech to enforce it, it's on them.
Oh come on guys, don't...
Can't believe all this shit just allowed to happen then Muricans still claiming to have more freedom than China or Russia for long..
Unpopular opinion, but this is objectively better than having to upload your ID to every random website that requires an age check (if that's what the end result is).
Instead of the client sending the user's age to the server, why not make the server send a minimum age to the client? The client is welcome to block content without disclosing personal information to the server. This is as secure as sending an unverified age to the servet.
Because the requirements being placed on social media sites are much more nuanced than simply allowing or blocking content... to implement this all in the OS or browser would require an exponentially more complicated API.
In the sense that a website could just ask your OS if you are over a certain age and that age was self declared? That seems fine to me, but why can't the websites just ask me for my self declared age?
That's how things used to be and that makes more sense in my opinion because an OS isn't the thing displaying content. It just run whatever it is told to run.
>but why can't the websites just ask me for my self declared age?
Because children just click through the age gate when it suits them. With this legislation, a parent that purchases the device and creates an account for the child can set the age once and take the decision out of the kids hands. It's a huge improvement without any significant privacy issues. I can't fathom why the tech crowd is having a collective aneurism over this.
>OS isn't the thing displaying content
But the account on the OS is the right place for the single source of truth of properties of the current user.
The computer owner can set the age, not the user.
I am root on my computers. My 11 year old isn’t root on my computers.
It started with showing ID at airports and now we have to take off our shoes. Slippery slope is the actual modus operandi of government.
That argument might work better if just recently we no longer have to take off our shoes.
...we don't have to take off shoes anymore at US airports though.
Making a stupid idea more convenient does not make it less stupid.
Dystopian nightmares are built from tiny "oh, that's not too bad, just a little step further. Not much different from what we already have"
You can personally avoid those websites, if you philosophically disagree with those terms. Good luck avoiding the operating system.
It’s bonkers that 50 states all decide to make their own set of rules for this. Maybe talk to each other?
It's a feature that states can (mostly) decide for themselves what laws they want to live under.
when it comes to commerce it isn't because it makes doing business impossible. How is this practically going to look, Canonical, Red Hat and open source maintainers are going to ship 50 different Linux distributions in the United States?
The reason the US has fairly robust interstate commerce laws is because if you don't you'll have trade barriers between states. Even the most well intentioned internet company can't operate in that ecosystem
Yes the constitution specifically identifies commerce as something Congress has the power to regulate. That doesn't mean states can't have their own rules. Many states have various forms of legalized cannibis, different laws regulating firearms, or automotive emissions.
Fuck that. Competition and diversity is way better. Anyine who fucks up can just change their laws later.
So that includes Android? What about the Unix of iOS?
You can also thank big tech for this because they'll do anything to not verify age on their platforms they want to push it onto devices and OSes.
Is being concerned that this article is obviously AI slop matter anymore?
“You may not be interested in politics, but politics is interested in you.”
It's none of your business. Go pound sand.
I don't understand how you are actually going to be able to enforce this when Linux is not "owned" by a single company.
Also how is that fine going to work if you don't have any children?
I predicted this would happen. Others also predicted this would happen.
I think now even the last person realises that this has nothing to do with age "verification". They simply hate us for our freedom. And it is clearly a move coordinated by private business here; their lobbyists are acting. This is also why it is the same law essentially in so many different countries at the same time. It is quite fascinating to watch, actually. People used to say "conspiracy nut!" - well, the facts are too clear now. That's no longer a conspiracy.
These laws still do not sit well with me. This is just going to create endless lawsuits. In my opinion the safer choice would be to avoid doing anything with current teens, that's just a non starter. Instead think of sliding windows of time and sandbox small children on a child account that if all goes well will one day be a teen and then an adult. They will thank you when they are an adult for looking out for them when they were too young to consent to the data leaked by these laws.
Why not just signal age ranges? Simple, the way the legal system works is one puts in a benign sounding law, then tweak it every year since the mechanism exists. (scope creep) "Now add city, state", "Now add DOB", "Now add address", "Now add social credit ID number citizen.", "Now add your federal wallet ID."
- For small children set an RTA header (previous discussions) [1] for any URL that may potentially contain content not appropriate for small children. Give site operators 1 year to implement this. Not counting QA and change control this takes minutes.
- Require app and device vendors to create a properly sand-boxed child account. Pen test it but it does not have to be perfect. This is for small children and default installed applications. If the child visits a URL that contains the RTA header then trigger parental controls. It is entirely up to the parent when that child is ready for mature content. It must be impossible for the child to install any applications, addons, etc... There are a myriad of ways to accomplish this.
- How is this enforced? Same way as any other parenting issue. If there is an incident that involves law enforcement, then social services can investigate and determine if negligence was occurring. When the child is mentally mature enough to deal with all the crap that is the internet their account is converted to an adult account. If the parent is giving the child an adult account before they are ready then the parent(s) go to mandatory parental training. If the child was being bullied or groomed, redirect law enforcement to go after the bullies or groomers.
- Set the laws to be active for any small child that would be under 13 as of the year 2034. Presto! One need not try to confine teens. When these small children are teens they will either be used to the sandbox account or the parent may have converted the account to adult.
As a side note all public and private schools should be legislated to have classes on dealing with all the crap the internet has to offer. Bullies, Cry-bullies, Trolls, Groomers, Scammers, Devious companies, Astroturfers, Gas Lighters, Propagandists, NGO's and so on. Also how to build friend networks so there is protection in numbers. No child should be friendless.
[1] - https://nochan.net/b/Internet-Crap/20230829-Think-Of-The-Chi...
Just make it a liability for social media companies. Let them figure it out. This is how we age gate everything else.
Why are you people in such a hurry to have facebook et al collecting government IDs?
Lets check how that state votes. "Solid Democrat". Yep.
One doesn't make Linus disappear for some time and then arrive apologizing for stubborness and embracing the imposed CoC just for the heck of it.