California Age Verification

I may be doing too much brainstorming in this thread, but even for child accounts, we could store only the month and year, and then do a “most conservative” calculation by assuming that the user was born at the end of said month. This would be at least somewhat less identifiable than a full birthdate.

1 Like

I don’t have children of my own, but I helped implement some parental controls to my sister. I think parent should not be afraid leaving his 10 or 12 year old kids alone on the computer. They should have a way to investigate, but it should be difficult for them to find something inappropriate, unless they try to do that really hard.

Existing age control I have seen sucked a lot. Buttons like “I am over 18” are just a joke. At the same time, I don’t want myself identified and authenticated when watching porn. Clearly making kid’s account/device as underage is correct way to solve it IMO. It should send Underage: yes HTTP header to every request they made. Only then we can blame advertisers offering them gambling or violent ads. Every kid has adult responsible for them. But often kids knew more about computers than their parents. Let them play on devices assigned to them in a controlled environment, where they can learn new things. Have a limits made appropriate to their age on them. Even 8 year old kid can play a game with ponies on my Fedora. Why not?

Devices are portable, kids connect to internet not always from the home. Reliance on protected home network is not working anymore. The protection needs to be configured on the device both children and parent can trust and carries wherever he/she goes.

If the parent thinks child is ready for selected applications over his age, well, let him be responsible for it, allow him make exceptions. But parent should not be afraid to leave his kid with a computer or a smartphone. Parent needs help of the OS on his devices. I want Fedora to be usable by underage children, because why not? We already have PEGI rating in metainfo appstream files for that reason already.

3rd party vendors need some way to get that information from the system. OS should not enforce only single browser protecting children. But unless OS provides API to other browser vendors, steam or other game engines, how else can they reuse information OS already knows? This can prevent too strong reliance on a single vendor also.

As a parent, I do not want to configure this in every application my kid installs. Need unified way for that, it starts on the OS. If I am able to make every children device identify anonymously itself as a child, then I can avoid having to identify myself as an adult. I think that is the best privacy solution available. I want that and Assembly Bill No. 1043 is a step towards that, IMO.

2 Likes

It is even simpler. If the account does not have entry in /etc/age, the it is adult account. It could have empty fields, but what for? We rely on OS permissions to not allow tampering of the age file by kids. If the age file is empty, the system has no children defined. Unless there is a whole system override configured.

2 Likes

I don’t think that is true. Lots of kids escape online and find new communities that some governments would prefer they don’t participate in. Sometimes these communities are literal life-savers to kids.

The EFF explains it well

I do have kids, that do use Fedora, and we manage age appropriate content by talking together and researching things before we download or engage with them.

2 Likes

I don’t think that the proponents of age-gating are idiots.
They are likely people that care about the harms they see children participating in online.

1 Like

What did lead you to that opinion, Neal? What actual law are you talking about? In this bill I have seen it allows to edit age. I think they require OS to provide age group only. If age is not provided, 18+ age can be assumed. Age of adults it not needed as I understand the text (but I am not a lawyer and not even english native speaker).

Another point is that this whole idea only works if everything is completely locked down (child users prevented from installing or running new applications). Even if mainstream browsers end up integrating with these verification systems, someone out there will fork them and remove the verification mechanism, and so it will be trivially bypassable to just open Chrome, download unverified-chromium.exe or whatever, and now it’s bypassed.

Well-intentioned but poorly written and thought out legislation like this serves to increase technical and legal overhead, potentially have a chilling effect on FOSS development, all the while doing nothing to meaningfully solve the issue. It is textbook “feel good” legislation.

1 Like

It is okay to escape online. It is not okay to escape gambling, cigarette smoking and drowning in alcohol. Censorship in general is completely different topic. This bill is only about sharing age group, nothing else.

EFF write about the need of Age Verification by leaving anonymity. I agree with them, that is the wrong way! But verification of an age by asking year for birth or even “I am over 18, proceed” button, is silly. No real identity should be needed for it.

But I think this California bill allows to do it the other way. It is a way to keep anonymity. Parent sets the device/user as a child, chooses the information for the child. Applications can get the status and trust it. They get trusted information about only rough age group, without revealing true identity of both child nor his guardian. The only thing shared is age group A, B, C, D. This is the minimal information needed, I like that.

I don’t think these tools should replace discussions with children about what and why they make something. Building trust remain the core value. I proposed age override if the parent trusts the child enough. It should be left to parents to decide. If they are okay their kids have adult accounts, so be it! But they should have a choice and I think they lacked it so far.

1 Like

This is the minimal information needed, I like that.

While this is a nicety of the bill, it doesn’t really have any effect on whether it will actually accomplish its intended goal.

Not to mention that the chilling effects here can’t be understated and are already occurring. Especially since FOSS contributors and maintainers are often volunteers who lack the legal knowledge or resources to evaluate the extent to which they are liable under this bill, including application developers who are also implicated. Not to mention that mandating FOSS applications and operating systems implement these signals is pointless when they can just be forked by someone else and redistributed. Then a child restricted to a child account can just download Fedora-unverified.iso or what have you and install it over the existing system.

Whether/how Fedora complies with this is one conversation, pretending like this is a meaningful step towards the bill’s intended goals is another thing altogether.

I think that is not true. That is why it needs some documented standard by the OS vendor. Sure, it cannot work if the child can install anything from any non-cooperating source. That is why they talk about “covered application store” IMO. That means it receives information provided by the OS and reacts to that accordingly.

Sure, it should mean general non-covered app stores will not be available to children accounts. I think non-executable home and installation from already enabled repositories should be sufficient.

I can already imagine Fedora-Workstation-Live-43-1.6-UnLOCKED.x86_64.iso images on torrent sites :stuck_out_tongue:

I think non-executable home and installation from already enabled repositories should be sufficient.

It would mean also removing or isolating from the fedora repos any tool that can be used to create bootable installation media, including dd from coreutils.

How would that exactly help without write access to a block device? I think device (re)installation cannot be done by the child. Don’t give them the root access, that should help a lot.

System76’s response (Phoronix): System76 on Age Verification Laws - System76 Blog

1 Like

How would that exactly help without write access to a block device?

Touche :sweat_smile: (I need coffee)

They correctly identify that virtual machines are another trivial workaround here. @pemensik

I think people will see who will bow down to California and add the distros to a list to avoid and we will see an exodus of people moving to Distros that give California/Colorado/Brazil the middle finger.

3 Likes

You have my vote. My freedom and privacy is not for sale.

1 Like

My two cents are that these laws fail to tackle the root causes of harm found on the internet that impact both children and adults alike. Regulating the user’s access should not be the operating system’s burden and, in my eyes, requiring any collection of data that can be signalled to services and applications is not going to make the internet any safer. When users can be tracked through a mixture of browser screen window sizes, agents, and other fingerprints, why give the chance for more user information to be harvested?

We’re in an age where personal information and the very voices of users are now sought after now more than ever and the operating system should not be trying to gather that in one easy place. I think that the list of demands for what counts as “verification” will only grow longer and longer if organisations comply. I hope to see many (and ideally, all) community-driven operating systems peacefully refuse to comply with these laws.

2 Likes

Respectfully, repeating your desire for distros to decline to comply with this law isn’t a particularly productive contribution to the conversation. I understand completely the opposition to this legislation, which is frankly sophomoric in its imprecision regardless of how well-intentioned it may be. That said, asking other people and organizations to ignore liability placed on them by legislation is barking up the wrong tree. Your energy is better spent trying to get this legislation repealed or at least amended, especially because Newsom’s signing statement indicated there will likely be an amendment process.

So instead of begging distros to ignore liabilities, ask your friends and family in California, Colorado, New York, and any other jurisdiction that has passed or is considering this legislation to contact both their State Representative and State Senator. In particular, it would be valuable for these bills to be amended clarifying that they only apply to commercial ecosystems as described by @gbcox here, in particular an exemption for noncommercial and/or FOSS operating systems and applications would be valuable, to mitigate the chilling effects this may otherwise have on FOSS.

If you’re a resident or have friends or family who are residents of one of the states in question:

Legislator finders:
California: https://findyourrep.legislature.ca.gov/
Colorado: https://leg.colorado.gov/find-my-legislator
New York: https://nyassembly.gov/mem/search/

Bills in question:
California: Bill Text - AB-1043 Age verification signals: software applications and online services.
Colorado: https://leg.colorado.gov/bill_files/40350/download
New York: https://www.nysenate.gov/legislation/bills/2025/A3946

2 Likes