back
545 comments
Linux distro founder here (stagex)

I will never be compelled to implement this, and would never merge it.

Every release requires quorum signatures by an international maintainer team, and the distro is designed to work offline-first, with some variants not even supporting network drivers in the kernel, so Illinois legislators can eat shit.

RedHat/IBM does have an Illinois presence so will likely be compelled to add it to their distro, and will likely do it through systemd. So to avoid it getting into any consumer distro you'd have to ship a patch to remove it from systemd.

This is probably all completely irrelevant to StageX since it's a distro designed to be used in containers, AFAICT.

If you're in the USA or plan to visit someday, I would recommend you speak with your attorney before making such commitments.
Good news: the legislation doesn't target you as an individual.

       "Operating system provider" means a commercial or
  non-profit entity that controls the Internet-enabled device's
  operating system, including the design, programming, or supply
  of operating systems for the Internet-enabled devices.
> ”Linux distro founder here (stagex)… designed to work offline-first, with some variants not even supporting network drivers”

If your OS doesn’t access the internet or isn’t intended to run browsers / social apps, then you are outside the scope of this legislation. That would be a bit like requiring a toaster to ask for your age before letting you operate it.

They can stop you from doing any work on the project. They can even fine or jail you for work done after the law takes affect that the international committee doesn't allow. Which is to say you can be forced to stop work.

Though if you don't live in IL it is unclear how this affects you.

i like the cut of your jib
They'll just find a way to work around that then or blacklist and fine you
Brother you are doing the worlds work stopping this type of "law".

If we don't like the law we keep doing the thing and enough people join and it gets changed to our liking.

Just wait until all vendors are required to lock down their devices like Apple does. Apple has shown that it is possible, thanks Apple!
I feel like all of these laws are being designed backwards. Content providers, like MPAA films, should have to identify what sort of content they are providing. Then I can give my kids a device configured to allow some or all of that at my discretion.

Requiring my kids' devices to advertise their age (or their age "bucket", as if that was a meaningful difference) to protect them is not doing me or my kids any favors.

Not that I'm condoning it, but this law requires self-declaration, not verification. It might sound pedantic but the practical difference is huge.

Self-declaration means that the system asks the user to declare if they are a minor. Nothing is verified.

Age verification typically means a system which checks ID or has other enforcement measures to try to verify age.

So in red states porn is being used, and in blue states TikTok and Instagram are being used. Is anyone tracking who is behind the concerted efforts here? For example, which organizations, executives, lobbyists and politicians are valid and responsible parties?
Since TFA can't be bothered, here's the text of the actual bill: https://my.ilga.gov/Legislation/BillStatus/FullText?GAID=18&...
What does that mean, practically? The person who installed linux on that particular device is liable?

>no algorithmic feeds for minors by default

Any choice of what content to display is an algorithm. Maybe they want a simple or easily explainable algorithm?

Serious question: This is a out-of-box "ask for age" requirement. No one is "verifying" anything. Why are we using this misleading headline? Face scans, ID cards, all that stuff that makes everyone nervous, are specifically not a part of this. To imply that it is verification is propaganda.

As a parent, I'd be very happy with this "age declaration" method, as I also don't think the 'verification' others push for is at all worth the risks. All parents want is to put the devices permanently into a mode that flags it to third parties as belonging to a minor, so they can't just hold up their hands and say "idk they said they're 18" like they do today.

I agree with literally everyone who thinks this is pointless and probably malignant. The problem isn't the visibility or the fact that weird stuff "exists" on the internet. The problem is advertisers "showing" it to people who didn't go looking for it. Ads and algorithms that decide what a person to see are 99.8% of this actual problem, and meta lobbying for something like this is just obvious self-interest to absolve them from any liability for showing kids damaging material, and to hit 2 birds with one stone, they get more PII to add to their "anonymized" aggregate data.

No good will come from this for the consumer. Websites are suddenly all going to start accurately reporting their content rating, especially ancient documents that have been "online" since before css and javascript were a thing. The only ones that will be implementing these checks will be adtech people that shouldn't have it in the first place. Letting out of touch geriatrics make tech policy decisions in a time when the bleeding edge is moving faster than ever is going to be disastrous for generations to come.

Here's my slight defense of something like this, in theory. I have not read the text of the bill.

If OSes build a standards-based way to query age of user that is logged-in, where non-admins are not allowed to adjust the age bucket, then parents can configure devices on first use to have an OS-wide enforcement of age controls.

Apps and sites would query the OS, not individual app/site accounts, for user age and act accordingly.

Apps can then lock out certain features like algo feeds and adult content more consistently.

Responsibility for proper use is still on the parent, and no verification process is put upon the operators of sites.

Not sure how I actually think about this; I'm only putting this out for discussion.

Cool. I'd like to propose a federal law wherein every lawmaker, state or otherwise, musts either demonstrate they correctly enough understand the subject they're legislating over (for every single instance of legislative act they perform) or get approval from an actual accredited expert panel before being allowed to push any more inane bullshit that will help noone in the future.
I love how everyone knows this has nothing to do with kids safety. However no one can or is willing to put up a fight. In the UK where I live its the same. Government does whatever they want and most of us just shrug our shoulders and say "that's messed up" and go on about our day.
> The signal itself isn’t a birthday, it’s a bracket: under 13, 13 to 15, 16 to 17, or 18 and up. Operating systems have until January 1, 2028 to have this built.

> Nothing in the bill requires a passport scan or a face scan at setup. It’s self-declared, the same way most apps ask your birthday today, just centralized once at the OS level instead of repeated app by app.

Maybe this is just a badly written law or purposefully designed to have basically no impact on anyone?

Or maybe the age bracket self-declaration part of this might make it a legitimately useful mechanism when a parent sets up a device for their kids. Their device declares “under 13” and apps and sites have to then follow the more strict social media laws which themselves should be relatively beneficial to the target audience.

In other words, the part that’s really privacy-destroying is the age verification, but that’s not part of this bill. The part that could be a benefit is the part where companies need to respect an age flag set by parents and comply with a concrete set of parental controls.

In other other words, it’s not left up to operators like Meta and Roblox to decide what age their users are, parents can set that device-wide and know it can’t be circumvented.

I'm surprised we're not seeing heaps of lawsuits here. Age verification in general violates privacy.
1773350468 | Illinois introduces OS-level age verification law | https://legiscan.com/IL/bill/SB3977/2025 | https://news.ycombinator.com/item?id=47357294

1773770767 | Illinois Introducing Operating System Account Age Bill | https://www.ilga.gov/Legislation/BillStatus?DocTypeID=HB&Doc... | https://news.ycombinator.com/item?id=47416131

1786248239 | Illinois just told every operating system to start reporting your kid's age | https://itsfoss.com/news/illinois-age-verification-bill/ | https://news.ycombinator.com/item?id=49228350

Does it even ask for verification? If not, the problem with it is that it seems to require the OS provider (not the local installation) to store the age.
This isn't really age verification, it's Steam-style "age attestation," there's no mechanism nor enforcement that the age you put in has to be accurate. But i think signaling to websites that the user account is underage is good, and this is really just enhanced parental controls at that point. Parent sets up account for child, puts in age, child can't change it, websites can't ignore it. Seems okay to me.
Thankfully for now this dragon is a hydra. Too many paths to block for now. The whole TPM fiasco with windows is preparation to put the genie back in the bottle. Soon, much sooner than I would like you will need a Global ID to access the internet, which will require an "internet safe operating system". It's only a matter of time. Get your sneakers ready folks.
I think this is a bad thing overall, but if the OS is responsible for reporting my age, that means I get to pick my own age... I'll take what I can get.

Some states will pass laws that companies cannot show advertisements to minors. So...

I think I'm about to become a bit of a minor myself, at least whenever it serves my interests.

I get the privacy concern in regards to advertising ones age, but I wonder if this is akin to a underage walking into a liquor store, interacting with stranger adults, etc. There are obvious appropriate and inappropriate behaviors to minors.

Let's confine only of consumer OS and is provisioned with an underage bracket (you set it to what you want, And Not a Require verify). All sites/app the OS interacts must honor certain child protection laws (privacy, selling, gathering etc)?

What is the main discussion surrounding placing (by choice) some 'optional' age bracket to enter during the OS setup/provisioning? The OS as provider only declares an age and it seems the sites/apps it interacts with to be the ones in the hook, not the OS.

as Linus would say, that is a userland issue, not a Linux issue
This renders all servers in Illinois illegal. Thanks.
What does this have to do with us?

Illinois can put up a great firewall like China and search citizens devices for contraband operating systems. The onus is not on tech to enforce it, it's on them.

I could accept the solution that the superuser decides about the age bracket of each regular user, that can be changed anytime.

sudo chage -u mybob --bracket teen

Users cannot change the setting, it can be presented to apps and let parents simply and safely enforce will.

The root is the ultimate leader of the system, let him do his thing.

> The bill’s own text caps penalties at $7,500 per affected child.

If the distro does not ship with any hardware, it could only be attained via download? So how would this imperil Linux distros?

Not to defend the law, it's comically pointless. Conservative states demanding ID verification for anything 'pornographic' and progressive ones trying to limit anyone under 18 from having any social media access at all. Clownish.

Can someone tell me why all of the sudden everyone's totally cool with letting political hacks choke the internet to death?

We used to make fun people like Ted Stevens for calling the internet "a series of tubes" and now we're just totally cool with letting a failed, bankrupt state in the US dictate what code needs to go into voluntary open source software. We need to fight back, now.

The interesting part here is enforcement. Linux isn't controlled by a single vendor, so I'm not sure who the law would actually target.
Declaration, not verification
Backdoor way to get data centers out of your state.
It’s bonkers that 50 states all decide to make their own set of rules for this. Maybe talk to each other?
How gullible and naive is anyone to believe for a single instance that the government would be stupid enough to just say okay age verify anything Apple, Android and Microsoft based. hahaha! Yet people swore linux users were smart! Guess not.
Democrat Representative Jennifer Gong-Gershowitz in the House

Democrat Senator Willie Preston [D] in the senate

I would like to take a break from all the complaining and point out how hilarious it is that this law does not apply to any computer that can only connect to the internet via an Ethernet port.
So that includes Android? What about the Unix of iOS?

You can also thank big tech for this because they'll do anything to not verify age on their platforms they want to push it onto devices and OSes.

Ok so, all the appliances and cars and TVs and who knows what other embedded electronics sold in Illinois will require the user (?) to verify their age?
Not surprised - I live in IL and almost every SaaS I pay an extra "15% Chicago Lease Tax". Politicians hate tech here.