• carpelbridgesyndrome@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    4
    ·
    6 months ago

    Since people aren’t reading the article and the headline is misleading. The law requires:

    • The OS ask the user their date of birth on account creation (kinda like the Steam date of birth prompts)
    • The OS provide an API that returns which of four age brackets the user fits in
    • Companies notified by the OS that the user is under age may be liable

    It was explicitly written by the authors not to mandate ID or facial recognition checks. You can lie about your date of birth. This basically creates a standard set of parental controls for parents configuring kids devices.

    I think that this might actually help with the whole discord facial recognition issue in places other than the UK by allowing them to offload the issue to parents setting up devices rather than collecting kids biometrics.

    • BartyDeCanter@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      6 months ago

      There are still so many problems with this. In addition to the general fuck you, it’s my computer, and fuck the state for forcing creeping surveillance on people, and how the hell would you enforce this, how would this even work for any of the following:

      • My RaspPi, running an older version of Linux. As far as I can tell, if I compile the kernel or write some code for it I would become the OS Provider.
      • A multiuser computer
      • A multiple people using the same account computer
      • Retro computing
      • A home media server. Maybe a NAS, maybe a home built machine.
      • A non-internet connected computer
      • Anything VM related
      • Any server in the cloud.
      • FreeDOS
      • An embedded machine in a car that I can ssh in to that crosses state lines.
      • An OS that doesn’t have the concept of user accounts
      • Hobby OS development
      • Oddball hardware that has been made to work as a general purpose computer, like a Chrome stick, hard drive controller or iPod?

      It also looks like it applies to “covered application store” and from how that is defined, every public deb, apt, or yum repo is an application store, along with things like PyPI, crates.io, GitHub, and probably my own fucking git server that I share with some friends.

    • BartyDeCanter@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 months ago

      Furthermore, what is this law actually going to accomplish? What is the threat model that this protects from? How does it accomplish that? How is it better than something less invasive? Not some vague pearl clutching bullshit, but an actual threat protection model.

    • BartyDeCanter@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 months ago

      Fucking hell, 1798.502.b is even more insane. Every developer of every single project has request the age bracket of every possible user? The people working on fucking ‘cp’ and ‘ls’ have to ask my age category when I run an update?!? This is absolutely insane.

    • markovs_gun@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      4
      ·
      6 months ago

      Yeah I think this is pretty reasonable. If parents set their kids up on adult accounts that’s on them.

  • Lost_My_Mind@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    6 months ago

    Simple solution. From now on Linux distros should ship with a big message “NOT FOR USE IN CALIFORNIA”.

    You want to force age verification? No server in all of California will run. Period.

        • JasonDJ@lemmy.zip
          link
          fedilink
          English
          arrow-up
          4
          ·
          6 months ago

          Glock is a type of gun.

          A Glock, on its own, is not illegal.

          Lots of aftermarket Glock accessories exist, all of which are legal.

          However, certain combinations of Glock and accessories are not.

          That’s not Glocks problem.

    • Gigasser@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      Supposedly the age verification thing that’s needed is the equivalent to a porn site verification. Just enter a birthday that’s in the 1800s, and you’re set. This is still a bad direction to go towards though, as it’ll set precedent for future bullshit.

      • Broken@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        Exactly. Today you can enter Jan 1 1800 and it will take it. That’s not the problem.

        The real problem is the precedence it sets. An asinine rule gets passed and companies adhere to it, meaning they are enforcers.

        Tomorrow when laws require real verification, like ID scan then they’ve already agreed to be the gate keeper for said asinine laws. It’s harder to back out at that point.

        It’s all surveillance and it should be stopped.

    • ColeSloth@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      6 months ago

      Yeah… It says just that in the article. You did read the article, right? I mean you didn’t just read the title and then rush in here to make a comment?

  • JasonDJ@lemmy.zip
    link
    fedilink
    English
    arrow-up
    11
    ·
    6 months ago

    Our president is fucking children, and you’re telling me I gotta verify my date of birth to run Linux, in the name of “Protecting the Children”?

    Get the fuck outta here.

  • sicktriple@lemmy.ml
    link
    fedilink
    English
    arrow-up
    10
    ·
    6 months ago

    So now when I spin up a VM at my sysadmin job I have to tell the server I’m an adult? Does anyone actually know what the fuck we are doing here? What an absolute clown show.

    • zewm@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      6 months ago

      This is what happens when boomers never die and stay in office for a lifetime. They don’t understand technology but are allowed to make the laws that govern their use.

      • a4ng3l@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 months ago

        Nha boomers are not the cause for this shit. Smart ass marketeers and tech bro pushing for more precise target identification and thus more reach for them are to blame. And those I stumble upon are definitely on the younger side.

      • 0x0@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        They don’t understand technology

        Considering most said technology was built by boomers… yeah sure, buddy.

        • Aceticon@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          You’re confusing GenX with Boomers - the explosion in Tech was in the 90s, not the 70s.

          Even then, most GenX weren’t involved in Tech since when they learned how to use it, it wasn’t yet normalized and widespread, so only really people who found such things interesting went for it and generally the personality type of those attracted to power over others is almost the opposite of the personality type of those attracted to solving problem which are expressed in strict and complex logical structures (for example programming languages or electronics designs).

          • 0x0@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            6 months ago

            You’re confusing GenX with Boomers - the explosion in Tech was in the 90s, not the 70s.

            Indeed it “exploded” in the 90s but was established in the 60s.
            Personality types seem to be spot on.
            Regardless, shoehorning whole generations is just… unproductive. Unless you’re claming GenXers are cool, then you’re correct.

    • sp3ctr4l@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      Does anyone actually know what the fuck we are doing here?

      Obviously not, no.

      You’re a sysadmin… you should know this.

      You’re the person who has to actually think through the results of other people’s decisions.

      That’s your job, lol.

      Other people get paid to make decisions, not think about them.

      • poopsmith@lemmy.mldeleted by creator
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        Other people get paid to make decisions, not think about them.

        And ofc they don’t suffer any consequences for making bad decisions.

        • sp3ctr4l@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          Precisely, shit trickles downward, that’s how the economy/society works!

          EDIT: Swear to god I didn’t even read your username before saying that.

          So, goddamnit poopsmith, you as well should know this!

          That’s your job lol!

  • arc99@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    6 months ago

    That would be a completely unworkable law since devices may not even have internet connectivity, or a user interface. And even if they did, it would have a chilling effect on software development in California.

  • mechoman444@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    6 months ago

    You guys are asking the wrong questions.

    How is Linux going to do this? There’s no server for the os to send the information to report the age of its users, no way of forcing its user base to comply and no single person or entity to fine, arrest or otherwise force into compliance.

    They made a law they cannot enforce.

    • Digit@lemmy.wtf
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      Or they made a law to attempt to ban operating systems with free software licenses.

      • mechoman444@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        But that’s the thing you can’t ban them.

        It’s just software that’s freely available. There’s no one corporate entity that controls Linux. Anybody can literally make a distro for it make notation for it illegal for California and be done with it.

        • BartyDeCanter@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          But they can fine every single developer of every single application. Sure, a lot of people won’t be in the jurisdiction of the state of California, but there are a hell of a lot of developers who are.

          • mechoman444@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            6 months ago

            Linux is not a company. There is no CEO of Linux sitting in Sacramento waiting for instructions. It is a decentralized, global, open source ecosystem. If one U.S.-based distro tried to bolt on age verification, someone would fork it almost immediately and strip it out. You cannot age gate software that people can freely download, modify, compile, and redistribute.

            From a technical standpoint, what would this even look like? Government ID verification at the kernel level? A biometric scan before you can run apt update? A centralized identity server for Arch users? That runs directly against how Linux is designed. The ecosystem prioritizes privacy, user control, and minimal centralized telemetry. Age verification requires centralized identity services, persistent user binding, and logging. Those models do not align. Even if someone tried, it would be trivial to bypass. VPN, foreign mirror, alternative distro. Done. You cannot meaningfully regulate something that is globally mirrored and open source.

            And this law is aimed at online services and platforms anyway. The harms legislators are worried about do not originate in your bootloader. They happen on social media platforms and content services. The operating system is simply the wrong choke point.

            The only places where age verification is realistically enforceable are platforms, app stores, and tightly controlled commercial device ecosystems. Not a globally distributed kernel maintained by volunteers across multiple jurisdictions. The idea that Linux is going to meaningfully comply in a way that changes outcomes is technologically naive. At best you get some compliance language from U.S. commercial vendors. At worst you get symbolic features that any moderately technical user can remove in minutes.

            That is not how open systems work. Pretending otherwise just advertises a lack of understanding of the architecture being regulated.

            • BartyDeCanter@lemmy.sdf.org
              link
              fedilink
              English
              arrow-up
              1
              ·
              6 months ago

              I am fully aware of the open source ecosystem. I have contributed to dozens of projects, including the linux kernel, CPython, Perl, and others.

              It’s astonishingly obvious that you haven’t bothered to read the bill at all and are just spewing nonsense. Take ten minutes and then pull your head out of your ass.

              Sections 1798.501.b, 1798.502.a and b. Every developer of every application that can be downloaded from every website, platform and package system MUST request your age bracket every time it is downloaded. And every time it is launched.

              Thats every application, from ‘ls’ to World of Warcraft. Thats every place on the internet that hosts software packages. It doesn’t matter if you feel like it is only aimed at “online services and platforms “ or “social media platforms and content services”.

              It is written to cover everything that runs on a computer that can be downloaded and the places that host them. PyPI, crates.io, flathub, Debian mirrors, everything.

              And that’s every individual developer who lives in or visits CA.

              • mechoman444@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                6 months ago

                You’re invoking contributions to the Linux kernel, CPython, and Perl as if that settles the matter, but you have been conspicuously vague about what that actually means. Those projects accept everything from typo fixes to deep subsystem work. If you want that credential to carry argumentative weight, specify what you worked on. Kernel networking stack? Filesystems? A CPython PEP? Core interpreter changes? Because right now it reads like résumé seasoning, not authority.

                More importantly, your statutory interpretation is maximalist to the point of implausibility.

                You are asserting that Sections 1798.501(b) and 1798.502(a)-(b) require every application binary, including local utilities like ls, to request an age bracket at download and at launch. That is an extraordinary claim. If true, it would not just affect “platforms.” It would upend global software distribution infrastructure including mirrors, package repositories, container registries, and academic hosts.

                Where in the definitions does the statute eliminate business thresholds? Where does it explicitly define a standalone executable with no network component as a regulated “online service”?

                Where does it impose a per-launch runtime obligation on locally executed software?

                Statutory scope hinges on defined terms. If you are correct, quote the operative definitions that extend coverage to every distributed binary and every individual developer who merely visits California. Because that is not a narrow reading. That is a reading that would trigger immediate Commerce Clause litigation.

                You may very well have contributed to major opens source projects. That does not make your legal interpretation automatically sound. Right now you are asserting universal coverage without walking through the definitional cross-references that would be required to sustain that position.

                If the text truly says what you claim, show the definitional chain. Otherwise this looks less like careful statutory analysis and more like an overextended reading fueled by frustration.

                • BartyDeCanter@lemmy.sdf.org
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  6 months ago

                  From TFB:

                  First, from the LEGISLATIVE COUNSEL’S DIGEST

                  The bill would require a developer to request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched. This bill would punish noncompliance with a civil penalty to be enforced by the Attorney General, as prescribed.

                  That’s not an encouraging start. Of course, that’s not the bill itself just the official summary, so we will need to dig in deeper.

                  At the beginning of the bill proper, there are some definitions, emphasis mine.

                  Section 1798.500

                  © “Application” means a software application that may be run or directed by a user on a computer, a mobile device, or any other general purpose computing device that can access a covered application store or download an application.

                  There are no business threshold or network capability requirements for the application (though there is one for the computer, sorta). It’s simply anything that may run on a computer. ‘ls’ definitely qualifies as an application per this definition. This is a pretty reasonable definition of ‘application’, even if it is a bit circular. We could also have quite a conversation about what counts as a “other general purpose computing device”, but it isn’t defined here.

                  (e) (1) “Covered application store” means a publicly available internet website, software application, online service, or platform that distributes and facilitates the download of applications from third-party developers to users of a computer, a mobile device, or any other general purpose computing that can access a covered application store or can download an application. (2) “Covered application store” does not mean an online service or platform that distributes extensions, plug-ins, add-ons, or other software applications that run exclusively within a separate host application.

                  PyPI, a Debian mirror, crates.io and GitHub qualify as a “covered application store”. Pip and cargo are an “software application” that “distributes and facilitates the download of applications from third-party developers to users of a computer” so they are as well. Depending on case law curl, rsync and scp might also, though the ‘distributes’ qualifier may exempt them. Oddly, browser add-ons are probably exempt due to (e)(2). And there may be a grey area around things like VMs. A purely personal website that only has software developed by that person probably doesn’t qualify due to the ‘third-party’ qualifier. Again, there is no business threshold listed.

                  (f) “Developer” means a person that owns, maintains, or controls an application.

                  Again, a fairly straightforward definition, that would apply to anyone who maintains any “software application that may be run or directed by a user on a computer, a mobile device” per 1798.500.c.

                  So, we’ve got that developer is a simple definition that basically matches what one would expect, as does application. Covered application store is probably broader than one would expect, and has an odd carve out, but covers most modern software distribution channels. I guess it might not cover sending CDs in the mail.

                  Then we get to a single simple sentence:

                  Section 1798.501

                  (b) (1) A developer shall request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched.

                  It’s a really simple sentence that can be really easy to gloss over. But read it again. Maybe you could argue that it only applies the first time an application is run. But it absolutely applies when it is downloaded. There are no exceptions listed, no threshold tests, no “social media applications only”. This applies to all applications, all developers, and all “covered application stores”. Now CA jurisdiction doesn’t cover downloads from outside of CA, but it does cover anyone downloading something inside of CA, or someone living in CA. So if a kid in CA downloads something from a outside of CA, the developer is in violation even if they are outside of CA. CA may not have the resources or desire to track down every developer outside of the state, but if they so choose they would be able to file a claim in the same way that CA can file claims on foreign people who violate other laws that involve CA victims, such as fraud.

                  Finally, there is this bit: 1798.504

                  (f) This title does not apply to any of the following: (3) The delivery or use of a physical product.

                  So, it looks like it doesn’t apply to CDs in the mail.

                  Edit:

                  Of course, I forgot to talk about the penalty. Maybe there is something in there?

                  1798.503

                  (a) A person that violates this title shall be subject to an injunction and liable for a civil penalty of not more than two thousand five hundred dollars ($2,500) per affected child for each negligent violation or not more than seven thousand five hundred dollars ($7,500) per affected child for each intentional violation, which shall be assessed and recovered only in a civil action brought in the name of the people of the State of California by the Attorney General.

                  Nope, no exceptions or commercial clauses. It just applies to anyone. And paragraph b?

                  (b) An operating system provider or a covered application store that makes a good faith effort to comply with this title, taking into consideration available technology and any reasonable technical limitations or outages, shall not be liable for an erroneous signal indicating a user’s age range or any conduct by a developer that receives a signal indicating a user’s age range.

                  Well, an OS provider or covered application store isn’t responsible for someone lying to them, tech failures, or the actions of a rogue developer. But developers have no such waiver.

    • Spesknight@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      What if banning Linux is part of the Agenda? And what will they do for the servers? I am declaring my pc a server as of right now…

      • yabbadabaddon@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        How do you want to do this? Linux is a kernel the world relies on. It powers your car, your fridge, your satellite, your phone, the entire Internet, the army, etc. Nothing comes close to Linux in market share. The distros are built upon the kernel. System76 may have to comply, but the other maintainers don’t give a flying fuck. They could even write a small line somewhere on their repo that says “this distro is not allowed in California” and call it a day.

        • Digit@lemmy.wtf
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          I wonder if that “this distro is not allowed in California” approach is even compatible with the various free software licenses.

    • dev_null@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      How is Linux going to do this? There’s no server for the os to send the information to report the age of its users

      The law doesn’t require sending the data anywhere, so that’s not a problem.

      no way of forcing its user base to comply and no single person or entity to fine, arrest or otherwise force into compliance.

      The law doesn’t require anything of users, it requires something of OS providers. OS providers have addresses and entities to fine.

      • BartyDeCanter@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 months ago

        Yes it fucking does. Go read the bill, particularly section 1798.501.b, 1798.502.a and b. Every developer of every application that can be downloaded from every package system MUST request your age bracket every time it is downloaded. And possibly every time it is launched. Basic utilities like ‘ls’ and ‘cat’, that pong example I pushed as a test, everything.

        • dev_null@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          Me: It doesn’t require anything of users

          You: Yes it does require something of developers

          ??

          You are correct, but how does that disagree with my comment?

          • BartyDeCanter@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            1
            ·
            6 months ago

            Sorry, I see that I was unclear.

            Yes it fucking does require sending the data somewhere, specifically to every “application store”, which by their definition includes such things as Github, PyPI, Crates.io, Debian mirrors, apt/rpm repos, and personal websites that have hobby projects from more than one person.

            • dev_null@lemmy.ml
              link
              fedilink
              English
              arrow-up
              1
              ·
              6 months ago

              Can you quote the relevant part of the bill? I don’t see it. From what I’m reading:

              • The OS provider has to collect the age information from the user
              • The OS provider has to make the age information available to any app that asks for it
              • The developer of any app has to request the age information from either the OS or from an Application Store

              There is nothing about how the Application Store obtains the age information (presumably they mean something like Google Play or the App Store that already have the information about users and of course haven’t considered anything else), and there is nothing about the OS sending the age anywhere other than an app running on it that asks for it.

      • Rivalarrival@lemmy.today
        link
        fedilink
        English
        arrow-up
        0
        ·
        6 months ago

        The law doesn’t require anything of users, it requires something of OS providers.

        For a FOSS OS, any user with root access would be considered an “OS Provider” under the definitions provided in this law. With FOSS, there is no real distinction between “user” and “developer”.

        • dev_null@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          You are right, it just says whoever “controls the OS”, which is very vague. Even without going to open source, a user still controls the OS even on Windows or macOS. To a lesser degree of course, but in the same way a driver controls a car even if they can’t or won’t try to modify it.

          • Rivalarrival@lemmy.today
            link
            fedilink
            English
            arrow-up
            0
            ·
            6 months ago

            The windows user uses the OS. The windows user does not control the OS. They only have access to the functions that Microsoft has provided. The Attorney General of California won’t be able to argue that the sysadmin is the OS Provider of a Windows installation. The OS Provider of Windows is Microsoft.

            The Attorney General of California would easily be able to argue that the OS Provider of a particular Linux instance is the sysadmin of that instance.

            • dev_null@lemmy.ml
              link
              fedilink
              English
              arrow-up
              0
              ·
              6 months ago

              They only have access to the functions that Microsoft has provided.

              And a user of Ubuntu only has access to the functions that Canonical has provided.

              Unless they have root access and modify the OS. Or they have administrator access on Windows and modify the OS. Which is the case for both by default. I don’t really see the distinction. There is clearly a provider company behind both, and in both cases the user could add this age check functionality by themselves by installing an utility that provides it.

              • Rivalarrival@lemmy.today
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                edit-2
                6 months ago

                And a user of Ubuntu only has access to the functions that Canonical has provided.

                That is not at all accurate.

                Administrator access to Windows is not at all comparable to root access on Linux. Windows “root” access is held solely by Microsoft, and granted only to Microsoft employees and contractors. They are the only ones with the capability of changing Microsoft’s binary blobs.

                Canonical doesn’t restrict root access. Everyone who installs Ubuntu has root access by default.

                Suppose Canonical adds this capability to Ubuntu. Suppose I take an Ubuntu install, and remove this capability. Who is the provider of the resulting OS, Canonical, or me? Obviously, I am responsible for the changes; I am obviously the OS Provider in this scenario.

                What I am saying is that I was the OS provider before I made the changes.

                Let’s remember that the law distinguishes between the OS and Applications running on that OS. They require that the signalling apparatus be included in the OS. Technologically, the distinction between OS and Application is somewhat arbitrary. For commercial OSes, it’s pretty simple: The OS is what Microsoft declares to be part of “Windows” is the OS; everything else is an application.

                Suppose Microsoft refuses to include this signaling apparatus. The end user cannot modify Windows, so does not become liable as the “OS Provider”. The user can bolt on the functionality as an application, but cannot make it part of the OS. Microsoft is the one facing the fines under this law.

                For FOSS software, the end user’s root access gives them the ability to add this signaling capability to the OS running on their machines, even if Canonical refuses to distribute a compliant OS. The user’s ability to make their own OS compliant with California law makes them the party liable for non-compliance.

                • dev_null@lemmy.ml
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  6 months ago

                  What does the comparability of root/admin access change in this situation?

                  Suppose Microsoft adds this capability to Windows, and you edit the registry to disable it. How is that any different?

                  I can see the argument for something like iOS. But on Windows you would be able to add or remove such functionality. What is the difference that makes the user the OS Provider on Ubuntu but not on Windows, in your eyes?

                  Let’s say you own a computer store in California, you sell Windows laptops, and you setup your preinstalled Windows image with the registry edit made, because customers don’t like the silly age prompt. How are you not the OS Provider?

  • Digit@lemmy.wtf
    link
    fedilink
    English
    arrow-up
    6
    ·
    6 months ago

    No biggie. I got ready for this in minutes after hearing about it.

    #!/usr/bin/env fish
    read -P "Are you old enough?  (yes/no)  " input
    if test "$input" = "yes" -o "$input" = "Yes"
    echo "Proceeding..."
    else
    echo "You are not old enough.  Exiting." 
    exit 1
    end
    

    … What? … Why are you all looking at me like that?

    • Schadrach@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      2
      ·
      6 months ago

      Am I missing something or would the following not meet the requirements?

      Add a module that does the following:

      On first account login to an interactive interface, ask for an age category (<=13, 15-15,16-17,18+). So a value between 0 and 3. Store that somewhere alongside user-level application settings. Include a library for applications to link against. Library contains one function, that function just returns whatever value was stored before.

      I think that meets their bare minimum while also demonstrating just how dumb this is.

      • super_user_do@feddit.it
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        6 months ago

        It wouldn’t. It would require a dedicated server to ping constantly and also an API that applications should use to ask the computer for age in background. Everyone could therefore us this data to fingerprint users…this makes everything even dumber and more prone for mass surveillance

        EDIT: Sorry for the misunderstanding. Thanmk you for correcting me

        • DeckPacker@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          6 months ago

          No, you’re just wrong. The law just says, there needs to be a local API, that apps can use to ask, what of 4 age brackets the user is in. That’s basically it. There is nothing about some online server that needs to hold that data.

          • BartyDeCanter@lemmy.sdf.org
            link
            fedilink
            English
            arrow-up
            2
            ·
            6 months ago

            No, sorry, you’re wrong. Go read the bill, particularly section 1798.501.b, 1798.502.a and b. Every developer of every application that can be downloaded from every package system MUST request your age bracket every time it is downloaded. And possibly every time it is launched. Basic utilities like ‘ls’ and ‘cat’, that pong example I pushed as a test, everything.

            • DeckPacker@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              6 months ago

              But they could still just request the age bracket that is stored on the system at the time of download, no?

              It’s not at all impossible, it just has to be implemented.

              • BartyDeCanter@lemmy.sdf.org
                link
                fedilink
                English
                arrow-up
                2
                ·
                6 months ago

                That is correct. Every program that is downloadable on the internet, from a big commercial application store, a open source repository, a single project webpage, or a random personal hobby site that has a single file on it that gets an update after 1/1/2026 must request your age bracket when it is downloaded. Or launched. Every singe one, every single time.

                Since I took at look at your user profile, that means you would need to add that to all of your github and itch.io projects. And if they are included in some other packaging system, you better be sure that they are doing it as well. Otherwise you will be personally responsible for a $2500-$7500 fine every time a kid downloads one of your games. Your site has a direct download, so what are you going to do to implement that?

                Impossible? Certainly not. But why the fuck should we have to do that? Why should every bit of code you put up on the internet be required to check the age API every time it is run? What are you going to do?

                • DeckPacker@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  6 months ago

                  Yeah, don’t get me wrong, this is an insane law. It makes no sense and it is utterly ridiculous and dystopian.

                  I am just saying, that it is still manageable to continue, we shouldn’t give up. We should continue to fight against this law, but we can also realistically keep distributing our software regardless of this law.

                  I think, the age thing only has to be implemented by the operating system, not by every piece if software. We as app developers can then choose to use an API to age restrict our apps, if we want to.

                  We just have to make sure our app isn’t recognized as an operating system in itself.

        • Schadrach@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          2
          ·
          6 months ago

          Nothing in the law requires some kind of online server. Only a local API, which a local library that can be linked is. And it only requires age to bebe described in four brackets, hence just storing a value 0-3. Didn’t see anything obvious as to why this wouldn’t actually meet the requirements, while being as dumb and pointless as possible.

  • lightnsfw@reddthat.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    6 months ago

    Why not parents responsible for their own goddamn kids? Stop interfering with the rest of our privacy for this bullshit. Parental controls have existed for decades. Fucking use them.

    • btsax@reddthat.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 months ago

      Because this isn’t about parenting or children, it’s about a creeping surveillance state

    • Archr@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      6 months ago

      … That is literally what this law does.

      When a parent creates the account for their child they specify the age. If the parent decides to lie or circumvent the system and it affects their child then they would be fined.

      Just to be clear the law itself says absolutely nothing about actually verifying the age.

      • lightnsfw@reddthat.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        It also makes it mandatory to include this feature in every OS. It means you’ll be sending telemetry about who you are to anyone that wants it and you don’t have a choice. Fuck that. I don’t have kids, there’s no reason I should have to use an OS with this shit.

        • Archr@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          6 months ago

          The law actually has a specific provision preventing both os providers and developers from sending your information to whoever they want.

          And the OS is only allowed to send the minimum information that is required. Ie. your age bracket.

          Send only the minimum amount of information necessary to comply with this title and shall not share the digital signal information with a third party for a purpose not required by this title.

          • lightnsfw@reddthat.com
            link
            fedilink
            English
            arrow-up
            1
            ·
            6 months ago

            Laws don’t prevent anything unless they are enforced. If the bill doesn’t also include how this will all be audited and incredibly harsh penalties for violating it that part might as well be toilet paper. I don’t care how minimal the data I’m sending them is. I want that amount to be 0. It doesn’t benefit me to give them anything so I shouldn’t be forced to do it.

  • anadrark@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    6 months ago

    Even if they could enforce it which I highly doubt, this law is clearly a “Fuck you and your free software”.

    Like if a “too young” user have the skills to update the OS to change or even remove the age verification, who will be responsible? Yeah I don’t know either, but both will be bad.

  • emmy67@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    6 months ago

    No doubt in response to Europe making its choice for software open source. Expect targeted attacks on FOSS to increase

    • Digit@lemmy.wtf
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      Troubling, given how much the put-up-or-hack-up users-are-developers ethos having slipped as more and more come in enjoying the convenience wrapping, with their consumer mentality.

  • CorrectAlias@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    3
    ·
    6 months ago

    Despite signing it, Newsom issued a statement urging the legislature to amend the law before its effective date, citing concerns from streaming services and game developers about “complexities such as multi-user accounts shared by a family member and user profiles utilized across multiple devices.”

    Then why the fuck did you sign it if it wasn’t ready and needed amendments? Is this what you’re going to do as president too?

    Rhetorical, of course. Note how he doesn’t say he disagrees with the bill, just that it needed to consider family devices.

    If this is who wins the primary, we are done. We’re basically already done, for sure, but him winning the primary would be the final nail in the coffin.

    • Sundiata@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      because he is a conservative dumbfucking cunt.

      judge: the jury finds the defendant guilty of 9 counts of child negligence, and will serve 5 months in prison with a fine of $10,000 in damages.

      prisoner: what you here for? what did you do?

      father: I allowed my child to create his own account on Debian Trixie 13.3 with KDE Plasma interface.

      prisoner: chuckles

      • VicksVaporBBQrub@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        Yup. This. I’m in California and this is not even a topic. This is not even in the local news. It’s as quiet as: the bullet train project, the gigantic water pipeline for the south project, the drought solution, the power grid solutions, etc. But, boy, the amounts of money that it blew thru.

    • Katana314@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      Even entering DoB is imo too much of a privacy breach. In my view, they should just take the highest age bracket described, apparently 18+, and then ask that on OS installation: “Are you over the age of 18?” If the user says yes, it installs, and every app is hardcoded to receive that 18+ bracket when checking demographic. If they say no, then it simply replies that users under 18 may not install it under the laws of California.

      • Electricd@lemmybefree.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        If it’s not stored, not a big problem, but yea that’s useless bullshit that’s just annoying and feels like a breach in our lives

    • BartyDeCanter@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      Go read the bill, particularly section 1798.501.b, 1798.502.a and b. Every developer of every application that can be downloaded from every package system MUST request your age bracket every time it is downloaded. And possibly every time it is launched. Basic utilities like ‘ls’ and ‘cat’, that pong example I pushed as a test, everything.

      • Kat@techhub.social
        link
        fedilink
        arrow-up
        0
        ·
        6 months ago

        @BartyDeCanter I saw a video on this…Brian Lunduke’s been informing us quite nicely. My question still stands…how on earth is this even going to be able to be implmented in the first place? There are too many utilities for it to work successfully. I question whether the folks in government proposing these rules even discuss the feasibility first.

        • BartyDeCanter@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 months ago

          A couple of options:

          1. It won’t, but will be a tacked on charge for prosecution on other things.
          2. All non-big tech developers and package managers will stop serving to CA IPs.
          3. Fines applied randomly and intermittently to whoever the DA or AG is mad at.
  • ZoDoneRightNow@kbin.earth
    link
    fedilink
    arrow-up
    2
    ·
    6 months ago

    uhhh. So would I need to get everyone who uses the household pc to verify age? Whats stopping a child from using the family pc that was age verified by an adult?