Live data from Hacker News

Illinois just passed a law that puts Linux on the hook for age verification

linuxstans.com

471–480 of 491 posts

Re: Illinois just passed a law that puts Linux on the hook for age verification

#471
post #255
post #119

Earlier quoted context omitted.

stagex accepts tax deductable donations via opencollective but we do not actually have a registered legal entity, so yes, probably fine. I mostly just want to make it clear this type of legislation is unenforceable and a waste of everyone's time.

How are you deducting the taxes without a legal entity? Or did you just mean that they would be tax deductible but not that you are necessarily deducting anything.

tax deduct able by the donating entity

Re: Illinois just passed a law that puts Linux on the hook for age verification

#472
post #154

Earlier quoted context omitted.

I specialize in TPM security and know plenty of ways to bypass it with physical access to consumer laptop hardware, and would gladly make that easy for the public if needed. But I hope they try this. It will be funny to watch the public humiliation of how hard it fails at scale.

Some of us hoard stacks of old computers (and lots of source code) in case they ever try this! ;)

You and me both.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#473
I get the privacy concern in regards to advertising ones age, but I wonder if this is akin to a underage walking into a liquor store, interacting with stranger adults, etc. There are obvious appropriate and inappropriate behaviors to minors.

Let's confine only of consumer OS and is provisioned with an underage bracket (you set it to what you want, And Not a Require verify). All sites/app the OS interacts must honor certain child protection laws (privacy, selling, gathering etc)?

What is the main discussion surrounding placing (by choice) some 'optional' age bracket to enter during the OS setup/provisioning? The OS as provider only declares an age and it seems the sites/apps it interacts with to be the ones in the hook, not the OS.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#474
post #203

Earlier quoted context omitted.

Some time in jail or having to fight a fine for refusing to implement features in the constitutionally protected free speech code they author? If that is what it takes. I do not want to go to jail, but if that is the only way to get to an outcome where people have confidence they can not be forced to add unwanted code to open source projects, so be it. But that is a pointless thought experiment because it will never…

This thing where you keep saying “it will never happen” is why you’re showing your ignorance.

Long history of ruffling feathers for big companies and politicians if you looked hard enough. Still not in prison because free speech actually is still somewhat a thing in this country, and as long as that is true, I will keep using it.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#475
post #207

Earlier quoted context omitted.

Pretty far fetched an Illinois legislator hires a hitman for a FOSS developer. But to humor you, if they did, the distro would carry right on, so they would be taking a lot of risk with no progress on their objective. I only sign like 1/3 releases these days so I am replaceable now. Decentralized control and decentralized trust was the whole point of stagex.

Representatives of the US government threaten to drone bomb anyone they disagree with all of the time now

lol. I can only aspire to be someone so effective in my goals for furthering personal freedoms that a government feels compelled to drop a bomb on me to make it stop.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#476
post #83

Earlier quoted context omitted.

But they could also just implement verification now, which many governments are trying to do. The idea that you shouldn't let a government do one thing because they might do another thing is flawed if they could already do the other thing. The danger of a slippery slope comes when one change enables the next change - for example, a law mandating certain kinds of data collection enables a future decision to discrimina…

'AnimalMuppet has the right take upthread ( https://news.ycombinator.com/item?id=49249774 ): "Once you accept their right to ask , then you open the door to their right to a truthful answer, and thus to a verified answer. > But they could also just implement verification now, which many governments are trying to do. That itself is a proof: the voluntary age declaration was and is common on all the services that gover…

But we already accept their right to ask. Certain websites have had age restrictions on them for years. There's nothing new to the idea that certain media is not permitted to certain age ranges. (This is leaving aside the idea that people generally agree that age restrictions and age verification are perfectly fine in public spaces in the physical world, and that the internet is very much an anomaly in this regard.)

Moreover, nothing really seems to have changed in the enforcement of that (as far as I understand, specifically focusing on laws like Illinois') — it's still ultimately the responsibility of parents to ensure their own child doesn't access restricted websites. This legislation would essentially provide a mechanism that makes it easier for parents to do that.

So no, I don't think that that is the right take.

I also find your edit somewhat amusing, as the key reason that age verification is such a topic is because of a different missing real-life social feature, which is the ability to look at someone and identify whether they're an adult or a child, alongside the ability to look at someone's ID without recording all their personal details forever. As they used to say, on the internet, no-one knows if you're a dog, which is both a strength and a weakness. Identifying mechanisms like this (ensuring parents have more control over their own computers, but not requiring full verification anywhere) seems like a reasonable approach to fixing some of the weaknesses of internet anonymity, while still preserving the basic strength that identifying yourself is always opt-in.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#477
post #61

Earlier quoted context omitted.

Companies like Red Hat/IBM operate in Illinois and for better or worse have controlling interests in Linux and across open source projects pretty broadly. Wouldn't they be forced to include the capability in their products, which then percolate out to everyone just by network effects?

I don't see how they enforce it though? Isn't this saying every linux instance needs basically a backdoor network access? How would verify the 30 pods on my node are from minors or adults without that? Or this is more about a user facing node? So my aws nodes need to verify my age before I ssh in? Remote desktop services? Sounds so complicated to actually do.

There's no verification necessary. Instead, you'd just set a flag on all of those pods that says "this is an adult". Or more likely, you wouldn't set anything, there would be no changes at all, because that would be the default.

However, if I gave my child a laptop with Linux installed, the law would force the OS to provide some setting somewhere that I can toggle that switches the installation to child mode. (On Linux, I imagine it would make sense to have this be a per-user toggle, so my kid's account would be in child mode, and the root account would not.) The applications on that computer would then be required to check that setting if they want to show "adult content" (here defined as algorithmic feeds, notifications between certain hours, the ability to receive messages from identified adults). Similarly (this isn't clear but would presumably be technically required) browsers would pass this setting on to websites in some way.

Another way of seeing it is this: you know the DNT/Do Not Track header that you can optionally set in your browser and (theoretically at least) websites will not track you? This is essentially that but for certain kinds of content. If you set the header, websites won't be allowed to show algorithmic feeds, etc.

Basically all of this is in the article, which lays it out very clearly (if you ignore the Claude-isms).

Re: Illinois just passed a law that puts Linux on the hook for age verification

#478
post #58

I feel like all of these laws are being designed backwards. Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion. Requiring my kids' devices to advertise their age (or their age "bucket", as if that was a meaningful difference) to protect them is not doing me or my kids any favors.

I think the issue is with something like algorithmic feeds — that's not content that can be allowed or blocked at the client-level, that's a setting that needs to be fed back to the service. It would be very difficult (impossible?) to design an API that allows services to identify whether a user should be served an algorithmic feed without also having that service know that the setting change was triggered by local age restrictions.

Like, I can imagine a browser exposing an API that says "wantsAlgorithmicFeeds: boolean", and websites would be required to respect that setting. In theory, anyone can toggle that setting, so the website doesn't know if the user is under 18 or not. But if in practice the vast majority of people with "wantsAlgorithmicFeeds: false" are children, then websites can use that API as a good enough proxy for identifying information in the vast majority of cases. Moreover, the more of these specific APIs you add, the harder it gets to keep things anonymous — especially if different states have different requirements on age-restricted content, you'd end up being able to triangulate not just age brackets, but also potentially location as well.

I agree that age bucket still has the potential for exposing identifying information (e.g. if you can monitor a user as they move from one bucket to another, you can identify their date of birth), but it's harder, and it reduces the amount of side-information that can potentially get leaked.

That said, exposing the information in the other direction as well would be a good step because it would allow websites or apps to enable OS-level age restrictions without requiring that they also read the "age bucket" bit. It would be nice if "read a person's age bracket" were a permission that an app or website would need to request, rather than one that was given by default, and that could be coupled with the fully-privacy-preserving approach you describe, so that different applications with different requirements could mix-and-match.

All that said, I suspect it would be a lot easier to coordinate on good technical solutions like the one you're describing if the default reaction to anything that even smells like age restriction wasn't the sort of abject horror and moral panic that is so clear in this thread. Like, sure, age verification at any level has all sorts of issues. But that isn't the only possible solution to the problem here, and if technical people react to these proposals by pretending the problem doesn't even exist in the first place, then we're never going to find those better solutions.

Re: Illinois just passed a law that puts Linux on the hook for age verification

#480

Not that I'm condoning it, but this law requires self-declaration, not verification. It might sound pedantic but the practical difference is huge. Self-declaration means that the system asks the user to declare if they are a minor. Nothing is verified. Age verification typically means a system which checks ID or has other enforcement measures to try to verify age.

https://en.wikipedia.org/wiki/Boiling_frog
Post reply on HN