I think that malicious compliance all the way might have been the better option here. If a birth date is all that is needed, let the user enter a random one. If actual biometric verification is needed alongside, let the user also paste the code to a fake biometric validator that always returns valid. It is the same philosophy as with an app that forcibly wants an invasive permission to the detriment of the user. Let…
GrapheneOS refuses to comply with new age verification laws for operating system
31–40 of 171 posts
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#32Earlier quoted context omitted.
Could just ship it along on an SD card with a single button install you do yourself. Technically not preinstalled.
This is emblematic of a misunderstanding technologists often have about the law. We try to treat it like code we can exploit and hack around. But there is no compiler deterministically producing outcomes. Of course, this misunderstanding is often bolstered by the accurate observation that lawyers and businesses find loopholes and favorable interpretations that to us appear much like the exploits we propose. The criti…
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#33Earlier quoted context omitted.
Giving in in any capacity is unacceptable. The GrapheneOS foundation is based in Canada and is not obligated to record this information, so they wont. They have no reason to comply, be it malicious or otherwise.
[flagged]
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#34I think that malicious compliance all the way might have been the better option here. If a birth date is all that is needed, let the user enter a random one. If actual biometric verification is needed alongside, let the user also paste the code to a fake biometric validator that always returns valid. It is the same philosophy as with an app that forcibly wants an invasive permission to the detriment of the user. Let…
I don't think current iterations of the law require that this be sent off-device in any way.
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#35Earlier quoted context omitted.
Giving in in any capacity is unacceptable. The GrapheneOS foundation is based in Canada and is not obligated to record this information, so they wont. They have no reason to comply, be it malicious or otherwise.
[flagged]
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#36An adult had to pay for the ISP connection; that's the extent of age verification needed. We shouldn't be demanding adults expose their identities to for-profit entities and surveillance states, so much as mandating for-profit companies make parental controls easier to use, more effective, and stopping them from harvesting data on kids in the first place.
Not every corner of the universe needs to be baby-proofed; we just need to build a society where parents are enabled and supported to be parents, rather than outsourcing such a critical role to strangers and/or devices so they can get back to work.
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#37Seems like a pure virtue signaling: they don't sell or make hardware. It is mandated only for pre-installed operating systems, from what I understand.
I haven’t cut over to it completely yet but I think this’ll be the last nail in the coffin for my time as an Apple user. It’s already a loveless marriage , it’s already over, I’m already sleeping with GrapheneOS on the side. it’s asking when I’m going to leave her and it’s always “soon, baby. soon.”
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#38I think that malicious compliance all the way might have been the better option here. If a birth date is all that is needed, let the user enter a random one. If actual biometric verification is needed alongside, let the user also paste the code to a fake biometric validator that always returns valid. It is the same philosophy as with an app that forcibly wants an invasive permission to the detriment of the user. Let…
Biometrics are not required.
The concept appears to be that a parent or guardian could enter the birth date before turning the device over to a child.
Malicious compliance would be providing this age bracket API:
boolean is_user_over_18() { sleep (18 * 365.25 * 86400); return true; }
This is a real-time interface (as required by the law) that takes 18 years to complete. (Remember: "Real-time" does not mean "fast").
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#39Good on them. Devices shouldn't collect any extraneous data by default other than that needed to fulfill a feature a user consciously selects, and that includes this stupid age verification spyware regimes are pushing. An adult had to pay for the ISP connection; that's the extent of age verification needed. We shouldn't be demanding adults expose their identities to for-profit entities and surveillance states, so muc…
In many countries, it is still possible to buy a prepaid SIM without any ID.
Re: GrapheneOS refuses to comply with new age verification laws for operating system
#40In the meantime systemd already added handling for Age to the system bus. Next step is to add your race, then income, then who you voted for...