back
628 comments
Something remarkable and unsettling is how the age verification debate has popped up almost simultaneously in the US, UK, and EU.

With the same logical fallacies. Pretty telling about how transnational lobbies and their interests work.

Controlling what children do online is a solved problem: Parenting and parental control applications.

I'm completely baffled why anyone still engages with the "official" framing around this. Obviously, it's not for protecting children. Obviously, it's a technocratic trojan horse for increasing surveillance capabilities on digital systems. This is so cynically anti-democratic that they obfuscate the real purpose, don't even bother to make it plausible, and everyone is left talking about how "awful it is" that it's already legislated.

I swear to God, if someone replies to this talking about how we need to protect the children I'm going to start requiring "age verification" from commenters, and I'll do a little background check to find out w̵h̵e̵r̵e̵ ̵t̵h̵e̵y̵ ̵l̵i̵v̵e̵ if they're over 18.

Controlling what children do online is a solved problem: Parenting and parental control applications.

Spoken as someone who probably hasn't used iOS/Mac parental controls. It is a hot buggy mess that randomly blocks whitelisted applications as well. We use it, but it is a constant pain. Also a lot of applications only work half, e.g., TV apps blocking off all content rather than only content that is not age-appropriate.

By the way, we were initially firm believers of not using parental controls at all, by limiting time and teaching kids about how to use devices in a healthy way. But a lot of apps (e.g. Roblox, YouTube Shorts) are made to be as addictive as crack, making it very hard for a still not fully developed brain to deal with it.

That said, I absolutely dislike the current lobby for age verification because the goal of Meta et al. seems to be to be to absolve themselves of any responsibility by moving verification to devices and to put up regulatory walls to make it more difficult for potential competitors to enter the market. It is regulatory capture.

It’s not if you’ve paid attention to political trends for the last 15 years.

Everything is happening at the same time in every country. It’s clearly being coordinated.

This reddit thread¹ details thoroughly the connection to Meta (Facebook) and to a lesser extent Discord as being behind the push in the US.

1. https://old.reddit.com/r/linux/comments/1rshc1f/i_traced_2_b...

> Controlling what children do online is a solved problem: Parenting and parental control applications.

This is absolutely not true.

Here in the UK schools are swarming with ipads and shit like that. They're given to primary school children because they're "more engaging". Children are supposed to practice their reading and even handwriting[1] on ipads. Naturally they're on youtube instead. It's really bad. As far as I can tell, private schools are even worse. Currently the only way that I know to escape this is homeschooling.

Saying "it's a solved problem" is incredibly dismissive to parents who do everything right in their homes, but then send their children to school and schools exposed their children in this way.

Saying that phrase in such a definitive manner caters to the interests of the companies who push these shit onto schools. Please stop saying it, it's harmful.

[1] leaving this reference here because I'm certain that people without school aged children won't believe this is actually true: https://www.letterjoin.co.uk/

I estimate we have two to three years in the English-speaking world to organize an effective lobby for the rights of the common man before changes to the speech environment and habitual methods of communication make it impossible. There's less than a year before the wave of lock-downs reaches normal internet users through announced policies like the Android software installation ban and through the growing effectiveness of algorithmic "Joy of TikTok"-style discussion selection, and one to two years after that before we run out of other avenues. The latter timeline could be too optimistic if the completion of the TPM-to-cloudflare chain of permission for desktop environments (steps had been made in the past but failed after public pushback) comes without a lot of advance notice. Don't forget - after each new constraint on the public, the next counter-reaction will be smaller, and the next change will be bigger or sooner.
It's part of a whole bundle of tightening censorship and increasing control in a pivot towards techno-feudalism, and militarization of society...
Personally I do not believe this is a solved problem. Technically maybe, in practice not at all.

It is quite a job juggling the controls of the different companies. Microsoft even has two, one for Xbox one for windows.

And then your child turns 13 and your only option is to take away the devices entirely.

Another thing already discussed is school provided hardware. I know the schools try, but it is usually one person against 300+ students trying to figure out how to game/hack the system. Eg there's no reasonable way where you can expect one person to maintain a YouTube channel whitelist.

I do agree that we might be solving this issue the wrong way, but there is a definitely a problem here.

Why are Linux operating system providers taking it upon themselves to comply with the California law especially if they are not selling anything. Since it is just a downloadable piece of software then it is up to California state to set up a firewall to protect themselves from such harmful software.

Let's say I am a generic linux developer who develops variants of Debian Linux while sitting in my basement in any part of the world.

If one country wants to ban my software because I don't ask for their age, then set up suitable protections for your citizens.

Don't force me to do that. I am not responsible for protecting your citizens.

That is like saying if Saudi wants your id to make sure only males can download operating systems, so now will I add another restriction.

At least China takes it upon themselves to ban sites that they deem harmful for their citizens rather than forcing devs.

Now this is what open source development should look like. I cannot believe a few days ago I was thumbing through an email thread on freedesktop.org about how they could implement the mandatory government API in dbus. Can they not read their own domain name?
The problem is we’re regulating individual behavior by adding to the surveillance apparatus. We should be regulating the companies and dismantling the surveillance that makes the apps addictive to kids.

It’s a way of socializing the losses, this time you lose civil liberties and they get to keep acting unrestricted

Meta is why all these laws are happening. Please reach out to media outlets with this investigation so it can get more coverage. People need to be talking about this.

https://tboteproject.com/

"AB 1043 passed the California Assembly 76–0 and the Senate 38–0. Not a single legislator voted against it."

Amazing. We the people are not engaged. It really feels like we're at the end of history or something.

There is no way that this will happen on any Linux box that I use. And this is why I'm an enemy of device attestation and the requirement to register operating systems in the first place, no matter whether it is Apple or Microsoft.
I adore their courage. I assume they feel prepared to mount a legal defense? It would seem silly to be this forward about willful noncompliance if they're just hoping to stay under the radar. I can't tell if this is driven by impulsive pettiness with no real plan for how to mount a legal defense, or if they're engaging in a clear-minded legal mission.

> Ageless Linux is a registered operating system under the definitions established by the California Digital Age Assurance Act (AB 1043, Chapter 675, Statutes of 2025). We are in full, knowing, and intentional noncompliance with the age verification requirements of Cal. Civ. Code § 1798.501(a).

It is a stupid law but I feel people are overthinking this.

For compliance the os has to provide an age category to an application and an interface for the user to enter this data. We already have an api to provide information to applications. it's called the filesystem. and an interface to enter the data, that's called the shell. so everything is already there. If the user lives in california and wants to be compliant (wait a minute, let me stop laughing) all they have to do is put a file somewhere with a age category in it. if the application can't find it. well it's not their fault the law is stupid.

The California law is actually the best form of age verification one can imagine. It only requires the OS to let the user to 'signal' their age. In other words, it's more like a checkbox asking if you're older than 18, instead of scanning your face or driving license. It doesn't require a cloud account either. Storing the ages the user inputted in /etc/ages besides /etc/passed and providing an API to read it is compliance.

How is it so bad that we need some civil disobedience movement over it? On the contrary to, UK's Online Safety Act and China asking all online platforms to verify your phone number?

In this case, yes, this is probably a violation of the law as it is written. But I doubt law enforcement even notices or cares. You’re not actually doing anything to the kids. Maybe hypothetically you’re not setting/respecting an age flag in a web browser, but that’s the worst thing going on.

So it’s a nice statement but ultimately hollow because the devs aren’t at any real risk of being arrested or fined. This isn’t like Rosa Parks refusing to move to the back of the bus.

Want to make a real statement about software freedom? You gotta do something that makes the normies mad, like making an OS that explicitly helps kids do sports betting, buy drugs, watch porn, and whatever else. Then people will notice, but unfortunately you probably won’t convince them that this law is bad.

Unless Microsoft, Apple, or Google refuses to comply then I think this law is where commercial OSes are headed. But Linux doesn’t really need to worry, because nobody is going to arrest a nerd waving his arms saying, “look at me everybody, I’m breaking the law!”

Anyone ever heard about the story of how Phill Zimmerman made an absolute clown of the US federal government by publishing the source code of PGP as a book?

History of computing and open source is full of clever subversiveness. If back in the past hackers had the same attitude crying about complying otherwise fines we would have nothing today.

I wonder if we can get a popular referendum to sentence Meta to capital punishment.

There would be great rejoicing.

This is kind of neat, but the site design is very obviously Claude's handiwork. Has anyone else noticed this very distinctive look, which is a dark mode site with semi transparent cards with a thin less transparent border, maybe ten pixels of border radius... In the last six months this has shown up everywhere. Tools at work look like it. Blogs look like it. It's inoffensive but imperfect, and when so many sites look like it, it starts to look cheap.
> The child has learned the following lesson: legal compliance prompts are obstacles to be bypassed.

This is a good lesson. What is legal is orthogonal to what is moral and/or good for you.

Age checks are 1 million times worse than cookie verifications.
As the founder of the stagex linux distribution, and a California resident, it is my personal position that I will never implement age verification nonsense, and no one can physically make me.

Our distribution has no centralized legal entity in any country, and our decentralized trust model requires signatures from multiple maintainers from multiple legal jurisdictions to sign code and reproducible builds to make changes so quite literally no single person has the power to change stagex alone.

I would genuinely be fascinated to see anyone attempt to make us do anything we don't want to do. I do hope California attempts to make me. I would make it my personal mission to drag them in court and make a spectacle of proving that I literally am unable to comply due to the design of the operating system.

Reminiscent of the classic DMCA email footer:

This email is encoded with ROT-26 encoding. Decoding it is in violation of the Digital Millennium Copyright Act.

I don't want to give the impression that I don't find the whole direction of travel concerning, because I do, but as I understand it, the requirement is that the system administrator assigns ages to the users on their system. That seems pretty reasonable to me, and maybe even like a good idea in some scenarios. As far as I know, we aren't talking about software that fights against the interests of the system owner - that's the admin. In fact, I think this might be a feature I would even want.
I may be missing something obvious but, what happens if people just lie about their age en masse?
Reminds me of the DeCSS T-shirts [0] and the Penguin Liberation Front [1]. That logo was so cool for 16 years old me.

[0] https://en.wikipedia.org/wiki/DeCSS

[1] https://es.wikipedia.org/wiki/Penguin_Liberation_Front

Something I have seen a lot of confusion here in HN, and I think in this context it's important, is that something to be legal is not the same as to be legitimate.

Legality is what is permitted or prohibited by the law. In contrast, legitimacy is based on a moral principle. And thus, it is not universal and depends on the culture and tradition of a specific region.

When concerning law, in my opinion, one does not need to ask, is it legal? Which now clearly, in California, will be legal to impose restrictions on the OS level to access content on the internet. At start it is about age. But this builds a base which can be extended on.

One needs to ask, is it legitimate? Is it legitimate to impose restrictions on computer and internet usage based on who you are?

Another question to be asked is if in democracy all laws are legitimate, as they emanate from the congress which belongs to the nation. It's clear that in non-democratic regimes legality will never be equal to legitimacy.

I honestly think the pushback against the California law is a mistake. We are being presented with an increasing number of services demanding identity verification, in the form of ID verification and/or video verification. California is offering an alternative to that, an alternative that only requires you provide your age, without verifying it.

If the California law flops, the result isn't going to be no age verification. It's going to be increasing numbers of internet services requiring that you verify their identity with them through some shady third-party you have no control over, until you effectively can't use the internet without giving away your ID.

I'd prefer to have no age verification, but it's pretty clear that's not an option. People in power are using minors accessing porn and social media as a cover to push age verification, and it's believable enough that people are going along with it. Approaches where someone attests their age on an OS or account level are our best shot at disarming this push.

To those who don't get it: this law is like the "Yes I'm 18+" button on porn sites.

Every kid knows they have to click that button to see the porn. It's not about keeping anyone out, it's about legal liability (i.e. making it easy for companies to blame you).

LLMs have really made pushing out protest websites easier recently, hasn't it.

We've seen tonnes on HN recently

1. By involving Debian prominently in its stunt, is this drawing fire upon Debian?

2. Are the pile of assertions they're making (which sound like legal arguments and stipulations to me) against Debian's interests?

I think this falls under what lawyers call "being cute"
For a second I thought it's a linux dedicated for older adults and I was so excited that maybe my mom would have it easier using tech
Where can I buy the $18 kit? A link to a shop would be also interesting, as interesting is the project itself
Great analysis that traces these laws back to Meta:

https://www.reddit.com/r/linux/comments/1rshc1f/i_traced_2_b...

All of Linux should do this. Add to T&C that it cannot be legally used anywhere that requires an age check. Then have the big distros enforce it. See how long Silicon Valley lives with no Linux.

Seriously, we in the tech industry can help stop this 1984 stuff.

Is breaking the law, advising people to break the law by distributing harmful materials to minors really the solution? Why not just ask for the laws to be amended?
The order of things here is:

1) develop good systems for completely anonymous age verification.

2) now, potentially, use this in the places you think need age verification.

Why are people accepting 2 before 1?

It baffles me people in china feels safe in areas with cameras but it’s an opposite reality beyond that territory.
I feel like I need to read the prompt to understand what this website wants me to download here. What is it installing? What is it promoting?
maybe its being done by the people lobbying for the OS-based ID malarkey, so they can have something to point at and jump up and down
Some people are being played like a gosh dang fiddle.

Y'all are so pavlovian that you see Zuck/Meta and instantly rage.

The alternative to OS based verification isn't no verification. It's cloud-based verification

The cloud verifiers have all the interest in the world to making you hate the idea that this problem could be solved at the OS level without any third party involvement