Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Aside from the fact that it is a stupid law, there should not be any sort of exemption.

    I have not read the other proposed laws in this category but after reading the California law, I found it was so vague that my interpretation is that any operating system where the owner, well... actually owns the system is already in compliance. The law requires a mechanism where the OS can provide owner age data to applications. All operating systems where the owner is in control already provide a mechanism to supply data to apps, on most (mac, windows, unix, dos even) systems this is the file api, So to be in compliance with the law the owner can make a file that an application could access with the required info. No, there was nothing there about when an application needs this data, or even, like so many people assume, that it has to be out of the control of the owner.

    The CA law was so vague and pointless, my only conclusion is that it is a sort of frog boiling scheme. Test the waters to see if they actually have jurisdiction.

  • Linux?

    Or also BSD, ReactOS, hobby OS #24562 etc... ?

  • Anything that’s open source
  • They include the majority of OSI licenses, including BSD. So the majority of BSD variants are included.
  • According to the article: "it's any OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.”"

    The article then explicitly cite "Debian, Fedora, Ubuntu, Arch, and the BSD family".

    There is also another exclusion for libraries and software from a packages managers like apt and pacman.

    So from my understanding ReactOS, hobby OS but also CP/M, FreeDOS, Haiku or Collapse OS...

  • Yes also BSD and friends.

    From TFA

    > These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.

  • This is a victory only in a very perverse sense. The silver lining is that maybe this will push more people towards using Linux (maybe Haiku will have its day). And Linux itself lives on. But what a disaster of a policy, clearly just catering to lobbyists and not the best interests of Californians.
  • Can someone the exemption for browser extensions and other contained software? My best guess is that the OS > Browser are reporting the age already, and the browser extensions will also use that "signal". Is this close enough?

    " third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope."

  • It’s saying that, for example, Chrome on Linux isn’t required to ask for the user’s age in order to filter extensions
  • So someone said something I think sarcastically that deserves a fresh comment.

    "From now on all kids will become linux natives. The decade of the linux desktop is coming!"

    I teach technology K-8. So I have a front row seat to observing how the next generation navigates this new digital wasteland. Due to the aggressive censorship and locked nature of their computing experience at school, think Go Guardian, they have become experts at using Google workspace to make art, comics, communicate with one another in class etc.

    My point, the next generation really will become adept at using Linux IF the system is so locked down that it's all that's available. Humans adapt to their environment, no matter how harsh.

  • I somewhat agree and somewhat disagree. If your students haven’t completely disabled GoGuardian, they are only working within the system. At least when I was a student working on this problem, I spent some time writing some software that would selectively disable and enable GoGuardian features, but my peers were not. I’d imagine similar exists today, a “good enough” approach beats out a technically sound one. “Unblocked” games or websites rely on a brute-force “what are they going to do about it” ideology that doesn’t work when the person you are disagreeing with isn’t a 50 year old man that lacks motivation. If it can’t be explained in a minute, it’s probably unlikely any more than one in one hundred actually do it. As hopeful as I’d like to be about this, I’d doubt the next generation gets adept at anything more than lying about their age online.
  • this bill fixes nothing. if you wanted to prevent harm from the internet you would start with proper privacy laws. but we all know why that will never happen
  • > if you wanted to prevent harm from the internet you would start with proper privacy laws

    Explain how a privacy that protects you and me will somehow not protect a pedophile. How does that work?

    I am FOR privacy. I don't think it can be done.

    I do not want to have any information at all stored anywhere, encrypted, decentralized or otherwise. Nada. Its just text. I want to just be a number in everyone database. I want to be able to spawn millions of numbers that will never be related to each other. My ideal privacy world is a world where bots thrive.

    Just go to face to face discussion if you care so much about who you are talking to.

  • Privacy laws don't prevent foreign entities from influencing elections and making children addicted.
    by yyny
  • I'm guessing you are thinking about things like addictive social media and the efforts to keep kids from overusing it, and the idea is if there were strong privacy laws it would be harder or impossible to implement the most addictive features of those sites?

    However harms based on sites having lots of personal data on their users are only part of what many people are concerned about. There are various categories of apps and sites that are legally required to not sell to/serve children. There are also things that are not illegal but the majority of research finds is bad for young children, so apps and sites may want to keep young children out unless a parent approves. Privacy laws don't help with any of that.

    by tzs
  • nobody is worried about about the arbitrarian aspects?

    What if you are interested in developing your own OS (a task that would have been monumental but may become trivial with LLMs in the future)?

    Why is the proper level the OS? Why not the browser or the hypervisor?

    Or perhaps manufacturer should remember your age? What if hardware is resold? We would need a hardware cadastre! A global hardware cadastre would unite all jurisdictions in a power bloc eventually. It starts with daily computer/laptop, then domotics, then digital door locks, and before you know it the bloc-global hardware cadastre becomes authoritative, and the reference for property ownership.

    Is there even a proper level?

  • The proper level is actually the device. The government doesn't care about how you arbitrarily divide the device software into components - only how they are non-arbitrarily provided by different people.
  • Yeah, they're just digging a hole of bad laws.
  • The bill doesn't exempt Linux-based systems by name, if that's what you're thinking. It exempts any operating system that allows users to "copy, redistribute, and modify the software". It's a bit arbitrary in the sense that Microsoft and Apple could dodge the requirement by simply becoming open source, but that's not going to happen so it's not really a problem.
  • Rest of the headline: "software distributed under the GPL, MIT, BSD, and Apache licenses are exempt"

    And then further into the text it's clarified that there also isn't a specific list of open licenses, as the terrible headline would have you believe, but instead a description of what is considered open

    With the caveat that I haven't read the actual legal text, this seems to be an eminently sensible law (it'd be better if it weren't needed, but here we are).

    In summary: not a Linux exemption, and not an exemption for a specific list of licenses either.

    by gspr
  • I don't consider that sensible at all. The law is supposed to protect children. It's hypocritical to exempt certain operating systems from the law, and, to be honest, I'm astonished this is legal/constitutional in California.
  • Hope you all are excited for the most important parts of the internet to be completely unusable by default on Linux in a few years.
  • This. This literally makes it illegal for social media sites to serve Linux clients. The previous bill (the one that propagandists call "age verification") was actually really good, and this one is really bad.
  • Good. I’d rather have free computing than the modern web.
    by sph
  • Most if the "important" parts of the internet are unusable already by default, without an ad blocker.

    As long the government sites, banks, etc. work (who already know my personal detail due to the nature of their services and the contract we have), nothing of value is lost, tbh. Including this site and this comment.

  • I testified against the equivalent of this bill in my state. One of the things I mentioned is because of a non-trivial monetary fine per infraction [1], as someone who would potentially need to implement this, I would have no idea how to reliably differentiate a computer that was simply out-of-date/implementation has bugs from willful non-compliance vs Open Source [2].

    It just felt like the bill had the goals it had when it was created, and the broader cloud of "gee, if people implement this a certain way, it could have unintended consequences" was completely ignored. But don't worry, one of the co-sponsors proclaimed. near the end of the hearing, that they had a Masters Degree in Computer Science and worked on operating systems in their career, so they made sure to let us know that we were over-reacting.

    The other thing that really pissed me off was it was rumored my states bill was going to get an open source exemption. However, they waited until the end of the hearing to introduce all of the amendments, including the Open Source exemption. The proposed amendments were not publicly visible on the bill page or the page about the committee meeting for that day. This ended up being an excellent strategy to sway other committee members [3], since they could just hand wave the bulk of us as "concerns resolved". It was quite illuminating to also see media lobbyists come in and verbatim just state "hey did you get our proposed amendments?" and then without much reading of them at all, they were ratified during that session. Lesson learned: the moment there was a rumor of amendment, I should have made a considerable effort to get my hands on that text ahead of time since for the implementation concerns I raised, I was still unhappy. I'm not quite sure though how much of a difference it would have made though, since at least 30 other people fell into the same trap.

    Anyhow, hopefully my long-winded Sunday morning post was useful to someone in the future either when dealing with compliance, a version of the bill in their own states, or the federal government's attempts to do a similar thing. I confess that I have been lazy and not remotely done any due diligence on that federal bill (https://www.congress.gov/bill/119th-congress/house-bill/8250... / HR-8250: Parent's Decide Act). I encourage others to be better than me and contact their representatives, assuming it isn't already on the fast track to becoming law.

    [1] at least, for smaller businesses -- big tech won't care! I think it was something like $6,000/pop, which is chump change for big tech and will be negotiated during settlement talks.

    [2] Okay, you can check the user agents. But who wants to need to maintain or pull in a list of enforceable user agents! What happens if someone is spoofing the UA and suddenly they end up in my list of "must check" UAs (or inversely, !(not must check)). How long does one reasonably wait for the API call to time out? What about running the app on Wine? And most importantly, what if someone that doesn't care about Linux ("okay claude make my website legal no mistakes") is in charge of implementing this logic, or the library that people will end up using for compliance.

    [3] Assuming they cared. The vote was largely amongst partisan lines, some people had clearly looked checked out the whole time, despite the abnormally high numbers of their constituents being there that day.

  • So is anyone going to revert the commits that jumped the gun on this?

    E.g. systemd's birthdate field https://github.com/systemd/systemd/pull/40954

  • Why does birthdate trigger y'all so much, but physical location (literally the field right before it, that you can see in the diff context) doesn't? Shouldn't we be protesting even harder against systemd tracking our physical location?
  • I have no problem with that as long as it's not the government controlling the age verification. It should be a parent. And as a parent I want the ability to properly control my children's devices - the fact that Apple, and especially Google pretty much ignored this feature until now is a big part of why we have these dumb laws in the first place.

    Think about it - if every phone you got asked you at first config "are you over 18? If not ask a parent to set up this device" then everyone would know about that capability and "think of the children" would be met with "parents can just click a button"...

  • For WSL, there will still need to be a passthrough.