Live data from Hacker News

GrapheneOS refuses to comply with new age verification laws for operating system

tomshardware.com

41–50 of 171 posts

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#41

I think that malicious compliance all the way might have been the better option here. If a birth date is all that is needed, let the user enter a random one. If actual biometric verification is needed alongside, let the user also paste the code to a fake biometric validator that always returns valid. It is the same philosophy as with an app that forcibly wants an invasive permission to the detriment of the user. Let…

You'd need to closely read the law and have a lawyer advise you, but a neat attempt might be to just ask for the date of birth, send that "in real time" to the App Store program, and then have that program simply discard it? I don't think current iterations of the law require that this be sent off-device in any way.

The second requirement of the California law is that there be an API available to all apps that returns the age band a user is in -- one of:

age age >= 13 && age age >= 16 && age age >= 18

A non-maliciously compliant implementation would need to retain a date of birth or equivalent until the user was over 18.

A maliciously compliant API could just wait 18 years after account creation before yielding an answer. (remember folks: "real time" does not mean "fast").

One of the oddities about the way the law is phrased is that it requires the age band information about the user be provided to "the developer" rather than to the application.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#42
post #25

In the meantime systemd already added handling for Age to the system bus. Next step is to add your race, then income, then who you voted for...

That is ok. The writing was on the wall for a while. It is time to let it go. It served its purpose. We might as well start mapping out a way without it in a more serious way out of sheer necessity. I know I am.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#43

I think that malicious compliance all the way might have been the better option here. If a birth date is all that is needed, let the user enter a random one. If actual biometric verification is needed alongside, let the user also paste the code to a fake biometric validator that always returns valid. It is the same philosophy as with an app that forcibly wants an invasive permission to the detriment of the user. Let…

Giving in in any capacity is unacceptable. The GrapheneOS foundation is based in Canada and is not obligated to record this information, so they wont. They have no reason to comply, be it malicious or otherwise.

Agreed. This is one of those moments you might as well simply say no. For practical reasons too, your users do have options and tend to be the kind that will drop a distribution if it goes rogue.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#44
post #8

Seems like a pure virtue signaling: they don't sell or make hardware. It is mandated only for pre-installed operating systems, from what I understand.

As they should, I was personally surprised so many people were surprised come ICE raids that government can buy and track location via apps, advertising and your phone in general. Regular people need an idea, who is.. uhh.. less likely to sell them down the river.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#45
post #12
post #7

Earlier quoted context omitted.

If shipping a specific device configuration to the US is illegal, Motorola should not ship this specific device configuration to the US. I do not think our parent is suggesting otherwise. AFAIK Motorola and GrapheneOS are not merging, they are getting into a partnership. They do not have to think or do exactly the same. Apple can comply with both CCP and US demands at the same time without a problem. I am sure Motoro…

Motorola is pretty much only present in US these days, why would they build a product that can't be sold in their primary market? Demanding that OSes outright violate the law because you disagree with your own elected government is pretty insane.

Can't speak about other continents but Motorola smartphones are at least available all over Europe so your initial statement is incorrect.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#46

I know it's gonna be a very unpopular opinion. I do like, appreciate, respect & admire that they are ready to die on a hill. I just don't think it's the right hill. I do not have an issue with the legality of it. Rather I think age verification is actually not bad. Sure i see the potential danger. But there is potential benefits, that'd counter the danger, by a lot. In different times, i might have argued differently…

I appreciate the thought, but I personally disagree having seen the patterns of the past 2-3 decades. There is zero real benefit to it save powers that be. Honestly, the only reasonable move forward is non-compliance. Everything else results in steady inching towards full blown panopticon ( and some would argue that we are already there ).

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#47
post #24

Earlier quoted context omitted.

Giving in in any capacity is unacceptable. The GrapheneOS foundation is based in Canada and is not obligated to record this information, so they wont. They have no reason to comply, be it malicious or otherwise.

[flagged]

As they stated "If GrapheneOS devices can't be sold in a region due to their regulations, so be it."

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#48

Good on them. Devices shouldn't collect any extraneous data by default other than that needed to fulfill a feature a user consciously selects, and that includes this stupid age verification spyware regimes are pushing. An adult had to pay for the ISP connection; that's the extent of age verification needed. We shouldn't be demanding adults expose their identities to for-profit entities and surveillance states, so muc…

Apps requesting an age is not extraneous and there are many legal and safety reasons why an app may collect this information. If the operating system doesn't do it you run into the cookie banner situation where every individual site has to implement a dialog box asking the user instead of there being a standardized way to do it.

Re: GrapheneOS refuses to comply with new age verification laws for operating system

#49

Good on them. Devices shouldn't collect any extraneous data by default other than that needed to fulfill a feature a user consciously selects, and that includes this stupid age verification spyware regimes are pushing. An adult had to pay for the ISP connection; that's the extent of age verification needed. We shouldn't be demanding adults expose their identities to for-profit entities and surveillance states, so muc…

> An adult had to pay for the ISP connection

Ever heard of free wifi?

Post reply on HN