back
160 comments
Age verification at the OS level makes no sense to me. Most households aren't going to have a separate device for every family member and so you will end up with a tablet or computer set up by one of the parents (and thus having their age stored) that will be used by both parents and children. Likewise, people generally won't create a separate account for every potential user.
> Age verification at the OS level makes no sense to me.

it's the only form of "age verification" which can be done in a somewhat privacy respecting way (as in at most leak the age)

the idea is to "bounce back" the "is old enough" decision to parent controls and let the parent choose (the Californian law doesn't quite do that perfectly, but goes into that direction)

and if you sell what is more or less a general purpose compute/internet access device with OS (which I do include phones into) I think it's very reasonable to either sell it to adults only (with a disclaimer it's "not for children") or include proper parent controls

> Most households aren't going to have a separate device for every family member

in current times in the west it is very very common for many devices to be for one person only. Especially phones, or at least have different (OS) accounts.

but again this comes back to "parent controls", weather that is for a child (OS) account or a way to switch from a child profile to a adult profile doesn't matter

but in the end, the point of such laws should be to give parents tools to parent. As well as handling the case of parent acting in neglect by inaction. But if a parent intentional decides to give their children a device with their profile because they think it's fine than that should be their choice and responsibility.

> Likewise, people generally won't create a separate account for every potential user.

where it was possible I have not seen it not used, weather it's on a switch, gaming console or PC. It is the most convenient way of automatically separates logins, browsing history, game safes etc.

and the law als isn't made for that shared computer in the living room (through it will apply there). It's more about the devices children might use unsupervised, e.g. their phone.

> “Most households aren't going to have a separate device for every family member…”

They want us to all to have user accounts and login like well behaved workers. So cute. Little Donald can login for hisself, and doesn’t need mommy to do it for him.

Apparently there's been work to expose Meta pushing/funding this, to shift age responsibility from them and force for fine grained age data to be provided to apps.
> Age verification at the OS level makes no sense to me

If taken at face value, sure.

The goal of those age verification laws are not age verification.

Every semi competent os has suppoert for multiple users
What are you talking about, most households give personal phones to their children, especially teenagers.

Laptops aren't rare either.

In the meantime systemd already added handling for Age to the system bus. Next step is to add your race, then income, then who you voted for...
Why? Why should Linux ever implement local laws like this as core functionality? Especially invasive/anti-privacy ones.

If someone wants to introduce an age-verification-ca-module, fine, but not make it core. Yes I understand systemd is not the kernel, but its ubiquitous enough.

That just says to every country around the world; Windows, Mac, and even Linux is on board too, let's make it law also!

I dunno, I always expected Linux to be the last bastion of freedom and not to capitulate so easily.

Finally we can set the evil bit correctly on a kernel level.
That is ok. The writing was on the wall for a while. It is time to let it go. It served its purpose. We might as well start mapping out a way without it in a more serious way out of sheer necessity. I know I am.
Western tech direction in the last 5 years:

https://www.youtube.com/watch?v=nXL-r8deB5o

Nit: introducing a user account field is not the same as the system bus. It’s in ~/.identity and might be absent altogether.
to clear up a misconception for everyone, systemd doesn't do age verification. it just lets you set age restrictions on accounts. It's very sensible.
And for some distros, it’s a CoC violation to question it.
> Next step is to add your race, then income, then who you voted for

https://en.wikipedia.org/wiki/Slippery_slope

I don't see what prevents anyone (e.g., a distro maintainer) from patching that anti-feature out of the source or disabling with with root access. As long as people can control the software running on their machines, which is the idea behind Linux, nothing that people don't actually want will stay in the system.

Systemd shouldn't be foisting this nonsense on Linux users however. I suppose the anti-systemd subset of the Linux community was proven right after all, this is the kind of issue that can end up facing when a huge piece of opinionated software like systemd more or less becomes an indispensable part of Linux.

it was reverted ?
Good on them. Devices shouldn't collect any extraneous data by default other than that needed to fulfill a feature a user consciously selects, and that includes this stupid age verification spyware regimes are pushing.

An adult had to pay for the ISP connection; that's the extent of age verification needed. We shouldn't be demanding adults expose their identities to for-profit entities and surveillance states, so much as mandating for-profit companies make parental controls easier to use, more effective, and stopping them from harvesting data on kids in the first place.

Not every corner of the universe needs to be baby-proofed; we just need to build a society where parents are enabled and supported to be parents, rather than outsourcing such a critical role to strangers and/or devices so they can get back to work.

> An adult had to pay for the ISP connection

In many countries, it is still possible to buy a prepaid SIM without any ID.

Apps requesting an age is not extraneous and there are many legal and safety reasons why an app may collect this information. If the operating system doesn't do it you run into the cookie banner situation where every individual site has to implement a dialog box asking the user instead of there being a standardized way to do it.
> An adult had to pay for the ISP connection

Ever heard of free wifi?

GrapheneOS also posted about it on their Mastodon / Fediverse account: https://grapheneos.social/@GrapheneOS/116261301913660830
I wonder how things like computers at the library will work. This whole thing is just so stupid and intrusive. I can't imagine anyone will benefit from this except advertisers, doxxers and Big Brother.
You're not really going to be watching porn at the library though, just saying
We expected no less from GOS project.

systemd which was already in hot water over because the problems it creates over service, this was the last drop to get folks dropping systemct altogether.

i wish, but its not easy. So much of the application ecosystem has now been adapted or built around systemd and its other services. While some tools might still work with dbus alternatives, its quite clear that its harder and harder to use linux without it. Gnome is one example where even the dbus replacements wont work anymore. Others will follow; ironically Ubuntu is doing its own thing like usual, using systemd and resolved but not some other parts. However, im not really holding my breath there, as they usually end up adopting the "standard" way; now in the hands of companies like IBM....

I think the only option really at this point is to move over to BSD, but we face other issues like GPU drivers etc. The same people that worry about systemd probably also worry about AI, so if they want to be able to use it, it needs to run locally.

The 3rd option is to move away from general computing, and start building esp32 powered tools, where we can own the fulls stack. Dedicated digital tools for specific purposes. Personally, this sound like the best option, taking into account that we have almost lost the battle for open OS on mobile devices. We need to get away from the giant US corporations for the majority of our computing, and only interact with them when absolutely necessary. A grass roots computing moment basically.

This is absolutely the right stance to take against such stupid mandates.
Age verification is stupid, parents the actual parents need to look after their kids and what they're doing on the computer. If I hadn't been able to sit down at my Atari 800 computer with 48 KB ram, as I pleased after school everyday since the second grade, I wouldn't be the person I am today I wouldn't know as much about computers and I would not be a tech savvy person at all. These age verification measures are strong handed nanny type rules and laws that have no place in the household, it is not the government's job to raise children it's the parent's job. You're going to raise a whole generation of dummies.
How's that gonna pan out with Motorola?
Motorola likely wont sell devices with GOS preinstalled in those regions.
If Motorola have a problem with it, they obviously aren't the right partner for Graphene.

Graphene obviously won't want to partner with a company that immediately bends over backwards for this kind of puritanical nonsense.

More likely they will just add their own age widget themselves
This is excellent; silly laws on the books should exclude countries from access to things.

Unfortunately it’s not enough because there’s also a need to work to get the laws repealed AND stop the endless attempts to bring them back.

Will a record be kept associating a device to a person through the verification system?

What's next, browsers sending this to $website every time you need to post a comment on the web.

Seems like a pure virtue signaling: they don't sell or make hardware. It is mandated only for pre-installed operating systems, from what I understand.
They've partnered with Motorola to have it preinstalled on phones, this is in TFA.
Virtue signal away. I’m with whatever device and OS purveyors are willing to tell these tyrants to get stuffed.

I haven’t cut over to it completely yet but I think this’ll be the last nail in the coffin for my time as an Apple user. It’s already a loveless marriage , it’s already over, I’m already sleeping with GrapheneOS on the side. it’s asking when I’m going to leave her and it’s always “soon, baby. soon.”

Can someone catch me up how FB et al are not the ones responsible for age verification?

Is it lack of something similar to PKI for identify verification?

I think that malicious compliance all the way might have been the better option here. If a birth date is all that is needed, let the user enter a random one. If actual biometric verification is needed alongside, let the user also paste the code to a fake biometric validator that always returns valid.

It is the same philosophy as with an app that forcibly wants an invasive permission to the detriment of the user. Let the app have the permission while in a sandbox so it sees nothing.

We are back to printing books, boys
Apple should be championing this.
so... just sell a phone with a script prompts the user to install the OS, and it auto-verifies hashes, can't be bypassed, etc. Is that too simplistic a solution?
Having an age setting is not verification.

Having an age setting is not verification.

I hate the articles that lump everything together.

I know it's gonna be a very unpopular opinion. I do like, appreciate, respect & admire that they are ready to die on a hill. I just don't think it's the right hill. I do not have an issue with the legality of it. Rather I think age verification is actually not bad. Sure i see the potential danger. But there is potential benefits, that'd counter the danger, by a lot.

In different times, i might have argued differently. I'm not saying it's not worth protecting the world you deem worthy of protection. But no matter what that world is to any of you. The one we all share is changing for sure. Uncontrollably fast. And many things are gonna change. And many things won't matter that much anymore, if we actually end up going where we're headed.

I mean a this is just a super small part of it all, but i assume in this specific case, for graphene, it's a battle for privacy... and they're right. But we're still going into a future where we got 5,10,20,30 more years of "AI", even just keeping the same level of overall sophistication for most, but costs decreasing immensely... I don't know about you, but I don't think the ways we protect our privacy can be unaffected, already because we're going to learn all new aspects about which data is private. Just out of practicality. Extreme example: but if generating hundreds of obscene deepfakes of any person as easily as taking a photo with your iPhone... ah, i can't keep having this discussion, i hope i am just an insane moron who is wrong. But, just to be sure: instead of arguing if we should close the windows on the train that's burning, or leave them open, as some are smart and others need help, let's just get off the fucking train.

And yes of course. One might argue (I actually would), we should not start implementing laws like that or start making personal information a requirement to digital access.

But this might be the first step to a different future, or not. As i said, who cares where the train is headed. It's burning and nobody even really wants to be on it. Let's please get off the train.

Not saying the battle is lost. I have tried working on something because I still have great hope. But someone seriously must act. I tried, getting off the train. Or at least start standing up from my seat. Realizing it's not that easy to get off. It's embarrassing, but i can't even get off the train by myself... i tried anyway... but here i am, sitting again (currently on the floor, lost my seat, damn...)... i have been building something for the past 2 years. Well, trying to build something, an attempt to change course... ruining my life over it. And currently i failed, before i even got to a point where my prototype or any of the theoretical work even remotely represents the vision. But maybe i just learned, i was wrong about all of it. I hope i'll make it back being able to afford working on it and someday a way to make enough money to pay smarter people than me to join. But currently, it's insane for me for me to even dare dreaming about that. I have really dug myself a hole. Next time, it should at least be a hill...

So in the meantime: can people like the dudes & dudiñas from graphene please chose a wiser battle. If just some of all these people got together & worked on getting off the train, instead of working on things that seem meaningful now, but wouldn't even be considered worthy of being mentioned in the future... we'd have a shot.

Damn. I still just can't accept it, even though i've literally lost everything believing that. And i am ashamed so deeply believing in what i saw, and in friendly moments still see, as a future... thinking i could change it, without changing myself... but please god, in the end, let me not have been just bonkers, but convicted.

(As if that, would be, any different).

The GrapheneOS Mastodon post says,

"GrapheneOS will remain usable by anyone around the world without requiring personal information, identification or an account."

https://grapheneos.social/@GrapheneOS/116261301913660830

That raises the issues that GrapheneOS needs to solve, which may require more creativity than bold, somtimes combative statements.

If GrapheneOS doesn't comply with laws and regulations then they will sometimes be banned or restricted. If that happens, they may not be "usable by anyone around the world" for long.

That doesn't mean they have to capitulate or sacrifice security. They can find creative solutions, some of which are suggested here. The first step is to carefully read the spec to determine what is necessary, then talk to someone like the EFF, and find a way forward.