Live data from Hacker News

A new California law says all operating systems need to have age verification

pcgamer.com

441–450 of 768 posts

Re: A new California law says all operating systems need to have age verification

#441

Skimming the actual text of the law[1], I don't see anything particularly objectionable. Basically it requires a toggle when creating/editing a local user account that signals "this user is/is not a child". Applications could then tailor their content for child/not child audiences. Which isn't to suggest that it's a good law, just not really "age verification". [1]: https://leginfo.legislature.ca.gov/faces/billTextCl…

My first reaction is that this is an insanely bad law:

* The signal has to be made available to both apps and websites

* So if you dutifully input valid ages for your computer users, now any groomer with a website or an app can find out who's a kid and who isn't. You just put a target on your kid's back.

* A fair share of parents will realize this, and in order to protect their children, will willfully noncomply. So now we'll have a bunch of kids surfing the net with a flag saying they're an adult and it's okay to show them adult content.

* Some apps/websites will end up relying on this signal instead of some real age verification, which means that in places like porn sites where there's a decent argument for blocking access from kids, it'll get harder. Or your kid will get random porn ads on websites or something.

So basically unless this thing is thrown out by the courts, California lawmakers have just increased the number of kids who get groomed and the number of kids who get shown porn.

Mind boggling that something this bad passed.

Re: A new California law says all operating systems need to have age verification

#442
Isn't it possible to jam and deny with any remote auth dependency?

Recently after we spent hours getting a Chromebook set up after a "Power Wash" due to remote auth failure, it wanted the old password and there was no option but to wipe the device.

They held our homedir hostage with required remote auth.

We were not able to log into our computer and lost all of our data because of remote auth.

Secure critical systems must not have a centralized remote auth dependency that can be denied.

Re: A new California law says all operating systems need to have age verification

#443

Reaction 1: how would this even work with embedded systems that have no UI to input this data? Reaction 2: it's open source, make the lawmakers do submit the changes. Reaction 3: how would this ever be enforced? Would they outlaw downloading distributions, or even older versions of distributions? When there's no exchange of money, a law like this is seems like it would be suppression of free speech. Reaction 4: Someo…

While there are some enforcement questions here, especially around non commercial OSes, most of your reactions are clearly based on the headline alone. It defines operating system in the law. This wouldn’t apply to embedded systems and WiFi routers and traffic lights and all those things. It applies to operating systems that work with associated app stores on general purpose computers or mobile phones or game console…

> per-child usage

If the First Amendement is to prevent a government from letting you speak, shouldn’t that also concert a government from letting you hear that speech?

If so, then this seems to go against the Forst Amendment.

Sorry, Australian here so just speculating

Re: A new California law says all operating systems need to have age verification

#444

Earlier quoted context omitted.

While there are some enforcement questions here, especially around non commercial OSes, most of your reactions are clearly based on the headline alone. It defines operating system in the law. This wouldn’t apply to embedded systems and WiFi routers and traffic lights and all those things. It applies to operating systems that work with associated app stores on general purpose computers or mobile phones or game console…

> per-child usage If the First Amendement is to prevent a government from letting you speak, shouldn’t that also concert a government from letting you hear that speech? If so, then this seems to go against the Forst Amendment. Sorry, Australian here so just speculating

[deleted]

Re: A new California law says all operating systems need to have age verification

#445

Skimming the actual text of the law[1], I don't see anything particularly objectionable. Basically it requires a toggle when creating/editing a local user account that signals "this user is/is not a child". Applications could then tailor their content for child/not child audiences. Which isn't to suggest that it's a good law, just not really "age verification". [1]: https://leginfo.legislature.ca.gov/faces/billTextCl…

My first reaction is that this is an insanely bad law: * The signal has to be made available to both apps and websites * So if you dutifully input valid ages for your computer users, now any groomer with a website or an app can find out who's a kid and who isn't. You just put a target on your kid's back. * A fair share of parents will realize this, and in order to protect their children, will willfully noncomply. So…

Instead, websites should voluntarily put content ratings on their own stuff--most would because either they don't intend to harm children, or from societal pressure.

Then, software on the user's computer can filter without revealing any information about the user.

Re: A new California law says all operating systems need to have age verification

#446

Earlier quoted context omitted.

> they pass laws to regulate things they have zero clue about While you are correct with this statement in this context, I would say it applies to most things in government in general. The vast majority of lawmakers have zero experience solving any real world problems and are content spending everyone else's money to play pretend at doing so. The reality is, most government "solutions" cause more problems than they s…

most government "solutions" cause more problems than they solve Zero basis in fact. We’re in the wealthiest nation on the planet. Most of us live better than any previous generation. To claim all that success is completely in spite of government is ridiculous.

Wealthiest nation? More like unwealthiest of all nations.

U. S. by far the largest current-account deficit (over $1.2 trillion).

U.S. has the largest goods trade deficit (over $1 trillion).

Re: A new California law says all operating systems need to have age verification

#447

Skimming the actual text of the law[1], I don't see anything particularly objectionable. Basically it requires a toggle when creating/editing a local user account that signals "this user is/is not a child". Applications could then tailor their content for child/not child audiences. Which isn't to suggest that it's a good law, just not really "age verification". [1]: https://leginfo.legislature.ca.gov/faces/billTextCl…

My first reaction is that this is an insanely bad law: * The signal has to be made available to both apps and websites * So if you dutifully input valid ages for your computer users, now any groomer with a website or an app can find out who's a kid and who isn't. You just put a target on your kid's back. * A fair share of parents will realize this, and in order to protect their children, will willfully noncomply. So…

I'm not sure what the solution is, but to steel man a bit, the alternative is kids have access to all the adult spaces, where they will be groomed. A website/app serving grooming content to a kid is just so incredibly unlikely compared to a kid being groomed as the result of having unrestricted access.

Since I do not see a solution, and you see identifying children as a risk, what do you see as a solution for kids being in the same spaces as adults? Do you see a reasonable implementation to separate them, that doesn't have the "we know which accounts are children" problem? Maybe there's something in between?

Also, I think it's important to understand the life of a modern child, who's in front of a screen 7.5 hours a day on average [1], with that increasingly being social media, half having unrestricted access to the internet [2].

I hate government control/nanny state, but I think 5 year olds watching gore websites, watching other children die for fun, is probably not ok (I saw this at the dentist). People are really stupid, and many parents are really shitty. What do you do? Maybe nothing is the answer?

[1] https://www.aacap.org/AACAP/Families_and_Youth/Facts_for_Fam...

[2] https://fosi.org/parental-controls-for-online-safety-are-und...

Re: A new California law says all operating systems need to have age verification

#449
If you're a Mac or Windows user, I mean, fine.

This is just not going to be a thing on Linux.

Are there app stores on Linux? Yes, that's what FlatHub and Snap supposed to be.

So what, should Canonical just block Ubuntu downloads to anyone in the state of California? No security researcher is going to download an operating system that asks them their age for example. I feel like it draws a red line for me also.

This law is so completely insane. It sounds like it was written by some Apple fanboy to whom there is no other operating system other than Apple. The very state that spawned GNU and BSD is the same state that is not only demanding your data but enshrining its use in spyware in law.

Re: A new California law says all operating systems need to have age verification

#450

Earlier quoted context omitted.

While there are some enforcement questions here, especially around non commercial OSes, most of your reactions are clearly based on the headline alone. It defines operating system in the law. This wouldn’t apply to embedded systems and WiFi routers and traffic lights and all those things. It applies to operating systems that work with associated app stores on general purpose computers or mobile phones or game console…

Is a repository on a linux machine an app store? Are custom repositories app stores? Does this mean that now most automated deployments are now not automated? If they can be automated, does that mean that having the automation by default makes sense?

The law defines a user as a child running software on a general purpose computer.

> “User” means a child that is the primary user of the device.

It’s definitely more vague that necessary, but I’d imagine courts would readily find automated software deployment by an adult or corporation does not constitute a child using the device. Especially if done for servers or a fleet. Because then it’s pretty obvious that a child is not the primary user of the computer nor the software. Even if that software is a server that involves childish activities (eg game servers).

But I’d imagine that Linux package managers associated with a desktop operating system provider would fall under this law. And that raises questions about the software distributed by said package managers.

Post reply on HN