Live data from Hacker News

Illinois just passed a law that puts Linux on the hook for age verification

linuxstans.com

291–300 of 560 posts

Re: Illinois just passed a law that puts Linux on the hook for age verification

#291
post #228

Earlier quoted context omitted.

> accepts tax deductable donations via opencollective but we do not actually have a registered legal entity that, uh, sounds sketchy

Opencollective collects funds to distribute to open source project maintainers. Not that it matters. We have never collected a single donation, but figured it was worth a shot. lol.

I don't really get how that works in terms of being tax-deductible. So I looked it up, and lo and behold:

> Contributions to Collectives hosted by OSC are not deductible as charitable contributions for U.S. federal income tax purposes.

So, uh, no longer sketchy but not tax deductible in the US. See https://opencollective.com/opensource#category-ABOUT

Re: Illinois just passed a law that puts Linux on the hook for age verification

#292

I love how everyone knows this has nothing to do with kids safety. However no one can or is willing to put up a fight. In the UK where I live its the same. Government does whatever they want and most of us just shrug our shoulders and say "that's messed up" and go on about our day.

How has this fatalism been working out for your society?

Re: Illinois just passed a law that puts Linux on the hook for age verification

#293

Earlier quoted context omitted.

>but why can't the websites just ask me for my self declared age? Because children just click through the age gate when it suits them. With this legislation, a parent that purchases the device and creates an account for the child can set the age once and take the decision out of the kids hands. It's a huge improvement without any significant privacy issues. I can't fathom why the tech crowd is having a collective ane…

I hope i can find this comment in a few years. Also children can "come upon" devices, so this is still completely pointless unless there's a way to ban devices that don't have this ability. and the only way to do that is to ban devices that cannot verify the user's age. since a device can't really verify an ID, some third party (ideally meta, but also the government works) needs to verify id and age, write something…

>Also children can "come upon" devices

Yes, this mechanism isn't perfect, but is a substantial improvement over the status quo.

>and now that's stuck with the verified age set.

This inference is nonsensical.

>If "just let someone report the age" worked, pornhub wouldn't be blocked in TX.

Also nonsense

Re: Illinois just passed a law that puts Linux on the hook for age verification

#294
post #197

Earlier quoted context omitted.

I don't think this is a safe assumption. As a counter, actual age verification is being rolled out in other places. I really don't think we're in a position of choosing between no age-based access mechanism, and age-based access mechanism. Between the anti-porn types and public demand for some kind of regulations on social media, regulation of some kind is inevitable. Our actual choice may only be what type of restri…

Re: your last paragraph I actually agree with you, if you mandate that the site has to look for an affirmative signal and if it doesn't get one, has to assume the user is the youngest possible age group. Users would demand the proper support for it. Although it would have to have some teeth capable of biting the client software companies, because for instance, if browser(s) chose to on their own simply send "I'm over…

> if browser(s) chose to on their own simply send "I'm over 21" to every site this becomes a pointless exercise and that applies whether the browser makers do it out of frustration that the OS support hasn't landed, or out of malice (imagine a browser that misreported age on purpose, specifically targeted at kids who want to bypass the parental controls).

If it's a header, you can strip it out at the browser level, the user level, the kernel level, the hardware level, the router level, the router OS level, the router hardware level, or at the ISP level, depending on what a parent (or a state) desired.

The teeth are only necessary for the websites, which are never going to conform to the law anyway, whether through a header or through device attestation, without draconian Chinese-level enforcement that has never been seen in the West before. This new contract will have to be enforced at both endpoints. You will need the ID (whatever you want to call it) to get onto the network, whether you're an individual or the site being visited.

The idea that device attestation is going to bother the Moldovan tube site your kid gets pirated porn through is a surprisingly ignorant fantasy, especially when it comes from technical people. The Pirate Bay is still up. Megaupload is up and runs better than ever. People have 20 year old torrent site accounts. OS-level age attestation must be a first step, because it won't work.

And as to it not being enforced either by the hardware or by identity verification of the user, that's an impossibility. A kid can also overwrite an operating system, or even just overwrite the important part; so that means that either only attested operating systems can be installed, or no user is trusted at any time without state verification.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#296

Earlier quoted context omitted.

If you could stop doing that thing, it isn't an impossibility under lex non cogit ad impossibilia.

what could they be compelled to stop doing here? Mechanically speaking, I mean. I can imagine fines or contempt of court, etc But how would you remove an international distro from "the marketplace" if it's free and not operating a business?

It's not that complicated.

If there's a law that says "Anyone who distributes X must also Y" and you can't figure out a way to continue distributing X while also doing Y, the way you comply with the law is that you stop distributing X.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#297
post #89

Linux distro founder here (stagex) I will never be compelled to implement this, and would never merge it. Every release requires quorum signatures by an international maintainer team, and the distro is designed to work offline-first, with some variants not even supporting network drivers in the kernel, so Illinois legislators can eat shit.

RedHat/IBM does have an Illinois presence so will likely be compelled to add it to their distro, and will likely do it through systemd. So to avoid it getting into any consumer distro you'd have to ship a patch to remove it from systemd. This is probably all completely irrelevant to StageX since it's a distro designed to be used in containers, AFAICT.

I run stagex on servers and workstations baremetal, however admittedly minimal. It can run lots of ways.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#298
post #145

Earlier quoted context omitted.

No need to hack the law. Our FOSS code is constitutionally protected free speech and I would defend on those grounds. The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any courtroom outcomes. Like, what if someone made a law that said Bitcoin nodes must KYC? They could make the law I guess, and the international network operators…

> Our FOSS code is constitutionally protected free speech and I would defend on those grounds. You have precisely zero additional speech rights as a FOSS project than any other organization has. If "free speech" was a valid defense for you, then Meta would be doing the same. > The technical design of the project just makes it so no one can force changes on the distro unwanted by the maintainer team regardless of any…

> If "free speech" was a valid defense for you, then Meta would be doing the same.

Meta lobbied heavily for this. The fact that they have not decided to use free speech to fight the move that they are lobbying for is not an argument that free speech is irrelevant here.

This is not legal advice but a personal request: please do not get your legal advice from Hacker News. Get it from a lawyer.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#299
post #290

Earlier quoted context omitted.

Step 1: Shift the burden from service providers to OS providers (on devices owned by individuals). Step 2: Recognize that the system is trivially bypassed by a kid who sets up their own device without their parents' oversight or parents who just think this is a stupid law and lying for their kids. Or bypassed by anyone using open source operating systems which are (for a feature like this) going to be trivial to amen…

Your Step 2 assumes complete idiot parents. Parents who hand their kids a new device without adding any parental controls (A) are already in the minority today - I know a lot of parents and none of us would do that, and (B) can't be helped anyway under any scheme other than invasive identity "verification" (which this law isn't). > bypassed by anyone using open source operating systems You know what? If millions of t…

> Parents who hand their kids a new device without adding any parental controls (A) are already in the minority today

If this were actually true then the law itself isn't needed because kids are already getting filtered access to social media sites and other things. Right?

So then what is the point of the law if parents are already setting age filters for their children's devices?

Re: Illinois just passed a law that puts Linux on the hook for age verification

#300
post #151

Earlier quoted context omitted.

Did you read the law? It actually imposes very (in my humble opinion) good rules on the content providers, specifically social media. We know why social media is addictive - the personalized feeds are highly optimized to extend usage time, with no amount of time being "good enough." Social media sites would be banned from using this type of feed, limiting it to feeds of content you've subscribed to or requested only.…

Controlling my information consumption is not a legitimate function of the state. If algorithmic feeds get a lot of use, it's because people like them . Is that so hard to comprehend? That your preferences are not universal? And that you shouldn't use the government to bludgeon people into accepting the kind of information feed you, personally, would prefer for them? What gives you the right to do so? What you callin…

[deleted]
Post reply on HN