Yeah, this is fantastic. Should be top of the page. I’m honestly shocked, I’ve fully internalized that everything is corrupt and beholden to big corporations. Somehow, a victory! Looks like the Linux Foundation and EFF pushed back, but they’re not exactly big. Good job, California lawmakers!
Is this serious or sarcasm? They passed a horrible law, now its an internally contradictory horrible law because apparently it isn't important enough to consistently enforce. So, you know. Why legislate it?
There isn't much of an angle here that reflects well on Californian lawmakers, they're still supporting this authoritarian trend of de-anonymisation and rolling back free communication on the internet. They're just going to come back for linux later once the idea of legally mandated PII on account registration is normalised. Although I do see this "In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law" so we seem to be entering a wild space where they're going to try and micromanage this in a weird way.
> now its an internally contradictory horrible law because apparently it isn't important enough to consistently enforce
Law is not an abstract code, but an incremental sometimes futile approach to shape society. They only want a way to hold big corporations accountable to exploiting children. They don't actually intend the effects on the consumer, so they tried to fix on easily changeable effect: "Don't worsen the privacy for people who want it." If you are using e.g. MS Windows, you have given up everything already. They do a lot of "telemetry" and for example everything you typed into MS Word is already licensed to Microsoft.
So what makes kid users on linux so special that they don't need nanny state protection? Are the Californian legislators just throwing them to the wolves? Or are the protections being put in place here not actually important?
Seriously, what is the message here supposed to be about the kids using linux? And why are they so different from kids using Windows or Mac? Are there other safety features we can exempt kid linux users from?
> They only want a way to hold big corporations accountable to exploiting children.
Let me know when they pass actual laws tackling that, then. Even if this law was ironclad, this does not solve the simple factor of using a "verified" device.
You don't fix a problem of society from private corporations by restricting society. You need to actually attack the corporations itself. But governments are sheepish to go after "their own", or people who can bribe them into feeling like one of them.
It's not a great implementation either. But COPPA is an example in the right direction and made companies need to change their algorithms based on the user account's reported age. That's more of the direction to move in.
What do you want people to say? "Yay, the terrible law that threatened to make free computing illegal has an exemption for Linux. Now we only have to deal with unwanted mandatory age verification on all our non-linux devices. I'm so happy."
It delivered an arbitrary exception to a stupid law. If all someone wanted was an exception for Linux, they don’t understand the problem with this law.
“California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt”
If you allow this pandering to satisfy you, you’re essentially supporting an age verification requirement for all other computing systems. So you didn’t think the requirement itself was a problem, you just wanted to make sure it didn’t affect you?
It's not an exemption “for linux”, and claiming it is and then accusing people who point out that it's very clearly not of missing the point is something else.
I used the same language as in the OP title. Why aren’t you responding to that?
You’re missing the point because you weren’t responding meaningfully to what I was saying, you’re using someone else’s choice of language to derail.
> Good day.
And here comes the passive aggression, true to form.
It is absolutely a win. If you can't see it as a win because you didn't get everything you wanted at once, then you're setting yourself up for a lifetime of disappointment. Big wins in politics (and most other things) are made out of a succession of smaller wins. Getting unanimous passage of something in a messy legislature is actually quite rare.
This is not wanted, its duct taping a bad idea even further and i half-wish MS/apple/co sue against it. This may cause lawmakers to bounce back in the wrong direction though.
A lot of people are not stupid. Age verification is a backdoor for control. I read and did not even bother to comment, it's like yay, that horrendous thing they were trying to do now it's not applied to everyone. I'm also sorry for California, such a beautiful place and full of wonderful people. I hope it will recover one day.
A lot of people are stupid though. The law had zero age verification in it for example, but tons of breathless conspiracy theorists are claiming that's what it is about.
"Delivers something they wanted" is the most bizarre way possible to phrase "followed through with the majority of a reprehensible agenda and were forced to carve out an exception due to technical constraints and massive blowback."
I habitually complain about government... so let me help you out with this.
The original issue with the law was never that those poor open source developers were going to have to bear the burden of complying with the law, but that the law itself was a bald-faced invasion of privacy by an overbearing troupe of people in power (i.e., government) so shit-sure of their superiority over the simple common folk they govern (i.e., you and me) that they aren't even embarrassed by their own arrogance.
I would suggest that what "we wanted" is no such law at all. What would be weird, and worthy of comment, is if those of us that complain about government were actually satisfied by an exemption which only applies to pretty damn tiny slice of the market. If anything, that wasn't a victory for privacy or common sense, but rather a concession that they had foolishly created a law that they wouldn't have been able to enforce as broadly as they thought they could get away with... or if they tried to enforce it they'd have to contend with the optics of the big hand of government yet again crushing individuals whose only real crime was their altruism rather than just some giant corporation.
So it isn't weird at all that "we're" silent. This isn't a win. Pointing out that the law had unintended consequences, including with Linux, et al., wasn't a statement of objective but rather a simple show that the law was rife with thoughtless unintended, or perhaps simply unspoken, consequences. The legislature's act here didn't restore privacy nor did it remove bad outcomes: if anything it now just raises questions about equal protection under law, at least on some practical level. It raises the question why some users of computers need such protections as age verification and others don't, and why the licensing terms of the OS are a valid proxy for that need... taking for granted that the stated purposes of the law are the real ones, of course.
When people pointed out the consequences this would have for open source, that did not mean what they wanted was an open source exemption. It was just meant to demonstrate just how poorly conceived the law is that nobody at any point even thought about this before it was signed in. Frankly the consequences for open source are not even at the forefront of concerns about what these rushed regulations will do to the world.
A quick search suggests that 3D-printed guns being used in crime is an actual, for-real, and growing problem.
I take it that you wouldn't be OK with somebody building a uranium enrichment facility in their backyard for their hobby reactor. So there is a line to be drawn on where people's freedom to tinker ends; it's just a question of where you draw it.
Personally, I think given there is actual documented, non-isolated problem with 3D printed guns being used for violent crime, there's a debate to be had that's more sophisticated than "REGULATION BAD".
The obvious answer is to slice up your gun model into a number of sub-parts which individually aren't detected by the algorithm but collectively still form a functioning gun. And there's an unlimited number of ways to slice up a model, so it is impossible to create an algorithm which catches everything.
What's next, keep track of all printed parts and invent the math to recombine them in every way possible to see if it could form a gun? Trivially defeated by using multiple printers. Hmmm, sounds like a good reason to force everyone to register their 3D printer with their real identity, and only allow a print after the model has been uploaded to the Federal Printing Database for verification...
Or ya know, make a gun using a cnc machine, or are they gonna ban those too?
It’s so ridiculously easy to assemble a 3d printer from individually sourced parts, and find some open source firmware to run it. How is this going to stop anyone who’s dishonest and slightly motivated?
What’s next is thinking about guns is a thought crime.
Most sensible explanation to me is that it is getting something that does scanning on the 3d printers. Next step is to make it apply to copyrighted designs. As that is lot more doable. And fascists like to be in control and allow big corporations to exercise their power.
Ah, but don't you see? Something Must Be Done, and "gun part detection" is, indeed, Something. (ignoring that it fails the "thing" part of the definition, because it can't possibly exist)
Then I missed the public discussion on why making it illegal to possess DIY guns is not enough. Did that actually get debated or just handwaved away? By the time I became aware of this whole technical blocking thing, that was the only proposal on the table.
Ah, I think I know this one. It's because people who make their own guns are nerds. You know, like you or I, except in a different topic. I remember reading a couple of posts on R*dd*t where two folk were discussing fitting accessories to guns and one posted something like "No, you can fit that, all you do is mill a slot on top of the receiver and drill and tap a hole at the end and you can just about screw this thing in place" kind of thing.
I read the discussion and thought "yeah that's nerd talk, just not about analogue synthesizers, old Landrover gearboxes, or Pascal compilers".
I guess the reason for blocking 3D printers from making gun parts is because it's easier than doing it "by hand". All you really need to do is get a copy of the files from someone who has them, print it out in something suitable, and you have viable gun components with very little "real work" involved.
By contrast here in the UK, where it's quite surprising what you're allowed to own and operate if you comply with the laws (here you're allowed fully automatic weapons, if you keep them at a suitable shooting range and don't try to wander around town with them, and you're not oh maybe a convicted violent criminal for example) one of my late father's friends was a gunsmith. My dad was an excellent machinist, and so he made some components for his friend, and I remember standing in the machine shop where they worked while he turned a chamber for a gun his colleague was building in the lathe. "There you go," he said, taking it out of the chuck, "that's legal".
Then he took it over to the mill, and cut a couple of holes and slots that would allow it to actually function as a chamber, "And there - now it's *illegal*."
Then, as he handed it to his friend, who was licensed to have "home made" gun parts, to stamp his initials on, "And now it's legal again."
Of course since people aren't allowed to just walk around with handguns since the school shooting, it's all a little more difficult - but the police will tell you what you need to do to keep it legal.
It's still slightly easier to get a shotgun licence than a motorcycle licence here.
> here you're allowed fully automatic weapons, if you keep them at a suitable shooting range and don't try to wander around town with them, and you're not oh maybe a convicted violent criminal for example
I think you're overstating this. My understanding is that here in GB (unsure about NI) fully automatic firearms are absolutely prohibited with only limited exceptions that the general public are typically ineligible for. Could you elaborate?
If you run a gun club where people can safely fire fully-auto weapons in a controlled environment, you are allowed to own them and supervise people firing them.
This is not an easy or inexpensive thing to set up.
I shot a documentary about a guy doing just that in NE Scotland, about 20 years ago, and while his range is still in business I don't think he has ever cleared the tape for redistribution - it was a "here's what you spent your money on" for the investors.
Fully 3D-printed guns have awful performance, though. You would likely get significantly better results improvising with the stuff available at literally any random hardware store. Yet, despite that kind of gun being around for centuries, we weirdly aren't seeing bans on rigid metal tubes yet.
3D-printed "guns" become a real issue when you combine it with unregulated sale of firearm parts and ammunition. To get a fully-functional gun you just need to 3D print a fairly trivial component which is legally considered the entire gun as it carries the serial number. But that's not a 3D printing problem, because there are also companies selling that same part in a mostly-finished legally-not-a-gun form, together with a drilling jig guiding you how to drill the last few holes with a regular Dremel. And nobody is proposing banning Dremels. Heck, it is totally okay to own a lathe - which you can use to make your own high-quality guns!
And the entire discussion is of course pointless once you realize that this is the USA, so anyone is only a weekend road trip away from legally and fully-anonymously buying a gun two states over. If 3D-printed guns are such a huge problem, why aren't we seeing European countries mass-banning 3D printers?
To extend your analogy: it's like being fine with the sale of ultracentrifuges and uranium hexafluoride, then getting upset at someone selling a screwdriver to attach the plug to the power cord of the ultracentrifuge because "screwdrivers lead to nuclear bombs".
3D printed guns are a nothingburger. There is indeed a non-zero number of violent crimes committed with them - but there is also a non-zero number of violent crimes committed with shoelaces, so that's clearly not enough of a reason to ban them. It only makes sense to regulate them if they are involved in a significant number of crimes and leading to a huge increase in gun violence - and at that point you probably want to crack down on all forms of DIY guns instead of just the 3D printed ones. But that's simply not the case, so the regulation is pointless and doing more harm than good.
> ... why aren't we seeing European countries mass-banning 3D printers?
Dunno, because most europeans are way more responsible with their guns than many people in the US?
For example in the EU (and in Switzerland) before you can buy a gun, you get specific training about safe and responsible handling. And in many countries the cops shall come to your place and verify that you've got a gun safe and a separate safe for the ammo.
And we don't offer AR-15 to our kids when they turn 14 y/o (well I say that but my daughter wants to shoot my weapons and, once she turns 14, she can switch from air rifles to the real thing as long as she's accompanied).
Just to be clear: we have shitloads of guns and ammos in Europe. There's even one EU country with concealed carry. I think it's estimated there are twice as many non-registered weapons as registered ones. We've got big guns factories and gun brands in the EU. And there are millions of illegal full-auto weapons like kalashnikovs (well Zastava M70, which is the same) from the war in Yougoslavia in the hands of criminals. And shitloads of fully functional weapons, including handguns, from WWII circulating.
In my native city (Brussels, Belgium), at the moment there are drug dealers firing kalashnikov on police stations regularly (it's a big issue, it's in the news daily and the authorities don't know what to do).
In addition to people shooting at the range (and, sadly, to drug dealers/criminals ruining our cities), we've got lots of hunters too.
Many people at my shooting range have their official gun transport license full (that is 30 weapons) and some have more than 100 weapons in their collection.
It's a fantasy that europeans don't have guns: we're (mostly) responsible with them.
It's maybe because we're responsible with our guns that the EU hasn't banned 3D printers... Yet (it's the EU, so nothing is unthinkable).
> A quick search suggests that 3D-printed guns being used in crime is an actual, for-real, and growing problem.
Making actual firearms from steel is trivial. In fact you can look up Kalashnikov designs online and then replicate it with a relatively simple mill/lathe/tapping setup.
To be honest, as someone familiar mostly with computers, I have no idea where to start with this and it sounds a bit intimidating. Buying a 3D printer and using some 3rd party design sound very easy in comparison.
You're certainly right that it's possible for someone determined to make their own firearm, but raising the bar still has immense value.
Tradeoffs between freedom and safety are another, unrelated discussion.
Just watch a few YouTube videos. It’s not hard. Much easier than software development, although it’s dirty/messy (you use lots of oil and fling metal shavings everywhere) and time consuming.
The easier a thing is to do, the more often people will do it. And downloading a file and pressing print is a far, far lower barrier than machining steel.
It’s not 3d printed guns, it’s 3d printed parts. You don’t need the 3d printing at all if you want to make a DIY gun in the US, you can literally just buy the gun parts.
You don’t seem to have a good grasp of the topic but already decided the opposition position is „regulation bad“, but that’s not the case at all. The pushback comes from introducing the government as middleman between your slicer and 3d printer, that’s dystopic af
Once you know how easy it is to make a gun using parts from a hardware store the concept of banning it becomes a joke.
It’s like trying to ban wrenches.
Lever and tube - that’s what it is. People create makeshift ones even when it’s legal to buy them, because it’s cheap and easy to do so.
You can’t ban computers or personal transportation or words either.
You can’t even ban a person from a website. You can ban an account - but you haven’t stopped the person. Any attempt at playing arbitrary authority you’re gonna lose
Can someone the exemption for browser extensions and other contained software?
My best guess is that the OS > Browser are reporting the age already, and the browser extensions will also use that "signal". Is this close enough?
" third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope."
Or more likely companies and people will just comply. It might give a little more fuel to open source from people who are ardently pro privacy that balk at an age signal bring implemented, but I don't think that's such a huge segment of users.
I think the upstream premise was kids using Linux to get around things. This could be the case, even in a world of the average Joe just putting up with the intrusion and hassles.
So I run my app in a linux container under windows and I'm exempt from age verification? Isn't android linux under the hood? I'm sure the law is not so easy to get around. How does it work?
GNU is not particularly relevant here either; age verification rules were never going to affect glibc, bash, coreutils, GCC, Emacs, or any other GNU packages that I'm aware of, and would have equally affected Linux distributions built without any of them. (You could imagine that in the future there's a mandate to somehow tie age verification into boot integrity mechanisms such that GRUB would be affected, but I don't think that was contemplated for the current round of regulations.) The projects I'm aware of that were affected were systemd and D-Bus, and even these didn't contemplate adding any actual age-verification stuff, just adding age-category fields to data schemas in case something else needed to use them.
Yeah, you could talk about Alpine/Linux too, but those are definitely different from Google/Linux aka. Android. A free kernel alone does not make a free operating system.
Would always install some variant, think it was "pretty cool" for a few days, then revert back to "whatever MacOS was offering" (for my daily driver).
----
2026: I just finished building my third Ubuntu Linux machine, this year (gave the first one to my brother). An Ubuntu running a 5070Ti is now my main operating system.
Not as much anymore. Sure, trap teams are common, but we used to have school rifle clubs that taught safe handling of firearms.
Now we've decided that if we don't talk about something, people won't get curious about it. Sadly, without being properly taught how to be safe, that generally ends tragically.
A larger number of people dying from an unrelated cause in another country doesn’t make these deaths insignificant. By that logic, virtually no problem deserves attention because you can always find something that kills more people.
The "trolley problem" is literally never a valid argument for anything because it purports to create an analogy for a real world problem but does so by creating a scenario that cannot exist, hence any argument based on it is nonapplicable to "real" problems.
So you’re being pedantic? Future forecasts and estimates can’t mesh with the trolly problem? If that’s your stance sure, you are correct. I do feel like you missed the whole point of the exercise though, and are hiding behind an absolute that is never achievable.
Look, nobody brings up the trolley problem because they're concerned about what they're going to do when a train car goes out of control.
They use it as a metaphor to attempt to make an argument about a different, actually real, situation. My argument is this is pointless because no real world situation will ever meaningfully resemble the trolley problem.
The correct answer to the trolley problem is STOP THE TROLLEY. "You can't do that!" "Why not?" "because magic" "well how do I know this magic is there?" "more magic!" etc etc.
What do you do if the dragon demands a sacrifice or it attacks the town? You fight the dragon.
The idea that "stop the trolley" or "slay the dragon" is cost-free is a wish. You've merely added a third horn to the dilemma. "Someone brave attempts to jump onto the moving trolley, risking their own neck" might well be the preferred choice; the expected outcome may marginally improve; the shape of the problem remains.
I hope you're arguing out of perversity, not conviction - such is valuable, and i did have to think for a minute. I agree that lateral thinking can be productive.
At no point did I say anything was "cost-free" or even make any reference to cost. It's extremely rare for the cost of an action to be at all relevant to its morality.
> Someone brave attempts to jump onto the moving trolley, risking their own neck
This is a completely different problem. The whole point of the trolley problem is to attempt to justify the sacrifice of the few for the good of the many.
The entire framing is about other people dying, not whether or not you would sacrifice yourself.
The real elephant in the room is that 60% of our school shootings are streetside minority violence spilling into schools, not angry white incels mowing down classmates.
According to UNICEF, globally, Diarrhea causes 444k deaths of children under 5 or ~1200 per day.
Globally, 1.2 million people (all ages) die of diarrhea every year.
India accounts for 120k deaths of children under 4 or roughly one fourth of global D related deaths or 328 deaths per day.
Assuming a similar ratio across all ages, India must account for 300k D related deaths every year of roughly 820 deaths. Not great (obviously) but at least it only accounts for 1/4 of all D deaths, not 1/3rd.
They aren't but they should be. Many lives could be saved by making gun safety a mandatory class for all US students. If every kid had to learn the basic rules of gun safety, a significant number of accidental deaths could be prevented, and even many not so "accidental" deaths could be prevented because people would immediately recognize when someone else is being unsafe with guns. And gun safety rules are good things to ingrained in peoples heads when they are young. Similar to other safety rules like don't run with scissors, or put your seatbelt on, or don't pull sharp objects towards your body, or look both ways when crossing a road. If you teach it to kids in a serious manner the safe actions become a reflex action.
And part of the problem is that our entertainment media (movies, shows, video games) pretty much trains anybody who has not been taught gun safety in real life to reflexively point a gun at somebody when it is picked up, often with their finger already on the trigger (although some movies are better about this now). People see a gun on the ground, may not even know its real and think its a toy, "Hey guys look what I found" and immediately aim down the sites at their friend.
I think you're optimistic about the overlap between "people who tit about with guns" and "people who absorb education".
I dread the outcome of practical safety lessons because, the moment you give a classroom guns, then some teenage edgelord is going to pantomime shooting their buddy, or escalate a playground beef.
People do not work the way you want people to work :-(
May i offer an alternative? Make gun ownership a tedious bureaucratic procedure. Reams of paperwork will filter out many stupid. Stupid exist who can fill forms, but it's a smaller set.
> I think you're optimistic about the overlap between "people who tit about with guns" and "people who absorb education".
The cavalier phrase "tit about with" is exactly the issue. People do so due to a lack of education about gun safety.
> I dread the outcome of practical safety lessons because, the moment you give a classroom guns
OP didn't mention practical lessons, and giving real guns to school children would be idiotic. You don't have to actually have a gun in your hand to learn what not to do with one should you encounter it. We have MYRIAD examples of non practical instruction (things like sex ed, chemistry [what happens if sodium is dropped in water and why?], physics [hey kids, lets visit a live nuclear reactor!]). If anything, the best way to dampen the glamor of guns instilled by media would be to make it a boring school subject.
> Make gun ownership a tedious bureaucratic procedure.
In many cases, it is. In my state, you can't hunt with a gun (or even a bow I think) without a mandatory gun safety course, and I needed a background check to buy the rifle in the first place. A background check that required a form.
Not to say there aren't loopholes, of course, and I think most Americans agree with common sense gun laws.
I guess it depends on the culture but I would think it's a good thing to show interest and passion for this stuff by talking about things you do in your free time like setting up Minecraft servers
Agreed. I have had my tenure as a World of Warcraft guild & raid leader from many years ago on my resume for many, many years. It has always been a conversation point but managing 100+ people, who you don't pay, to prepare & train for complex, time sensitive operations including 25-50 people all working together, and all the management that comes with that, from DKP to class leaders, and so on. "Just think what I can do with paid people!"
I've never hidden my interest & passions, and I think the world is a better place when people are proud of what they enjoy. We're people first, after all.
The only reason I got into programming was to cheat at video games to get a higher score than my brother. Self-motivated learning is always more impressive than mandated. Take pride in your tinkering!
Very true. I bought and setup minecraft server hosting in middle school, which got me enough money to build my first pc in high school. And the rest is history. :)
This honestly is probably true, given when I help students write personal statements for applying to uni, the most common way they got into computer science is video games. I know for me 16 years ago that was true also.
Just in time for the kernel and its consequences to become completely hostile to anyone not paying for a frontier model. If I was 16 again and evaluating linux only to see everyone using LLMs to reason about the mess they've put themselves in I don't know if I would have even bothered. The promise of "you can just read and learn about it yourself" has been dead for at least 10 years, but LLMs put the nail in the coffin.
Linux has gone from attracting hippies to openly endorsing corporate closed-source products, something something live long enough to become the villain.
Rest of the headline: "software distributed under the GPL, MIT, BSD, and Apache licenses are exempt"
And then further into the text it's clarified that there also isn't a specific list of open licenses, as the terrible headline would have you believe, but instead a description of what is considered open
With the caveat that I haven't read the actual legal text, this seems to be an eminently sensible law (it'd be better if it weren't needed, but here we are).
In summary: not a Linux exemption, and not an exemption for a specific list of licenses either.
I don't consider that sensible at all. The law is supposed to protect children. It's hypocritical to exempt certain operating systems from the law, and, to be honest, I'm astonished this is legal/constitutional in California.
Agree, I think the law will be challenged on that basis, and ultimately thrown out. Millions of taxpayer dollars wasted, when they could have been actually solving the problem by making platforms responsible for the content they distribute.
What I meant is that if we take the law as a given, then the exemption we are discussing here are very good and sensible. I wish they weren't needed, but given that they are, the language seems sensible.
This issue should be independent of whether or not you think the law is idiotic. The exemption is unwarranted and likely illegal no matter what you think about the law because it's unjust to exempt some operating systems and include others.
Have you ever visited the real world? You have to live with plenty of idiotic laws all the time. This does not mean you have to like them. Nor does it mean you can't welcome laws that remedy some of the downsides of the idiotic laws.
I really struggle to understand what you're trying to say. Is it that since the original law is dumb, we should accept no remedy short of getting rid of that original law? I think you'll find making progress in the real world very hard with that attitude.
Your reply appears bizarre to me, I can only kindly ask you to re-read what I've written above carefully. I have never suggested in any way that I consider the original law dumb, on the contrary I have stated explicitly that it shouldn't matter at all what someone believes about the question whether that law is stupid or not to determine that exempting certain operating systems from a law is ill-conceived and likely illegal. I don't have anything to add to this because the point should be obvious, it concerns basic legal principles.
If you had an agent in the legislature wouldn’t you prefer exactly one of this form? My ideal representative is able to command support from diverse interests and subtly damages those opposed to me while subtly advantaging the principles I believe in - making compromises necessary to move incrementally to a state more aligned with what I wish it to be.
The reality is that many people want bad laws. Without the support of those people one does not get elected.
This use of people for power while de-facto disenfranchising them is pretty widespread already. For instance, some half of California and Texas are responsible for their strength in the electoral college while simultaneously being entirely disenfranchised when electing the President. Good technique.
> These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
It's kind of weird though. Is VxWorks (a proprietary embedded OS used on some of the Martian rovers) going to require it in case some underage Martians try to use Facebook?
That depends. Will some kid be caught accessing Facebook from a Martian rover, triggering a court case? Remember, the law only cares about things that actually happen.
this bill fixes nothing. if you wanted to prevent harm from the internet you would start with proper privacy laws. but we all know why that will never happen
> if you wanted to prevent harm from the internet you would start with proper privacy laws
Explain how a privacy that protects you and me will somehow also protect a pedophile. How does that work? I am FOR privacy. I do not want to have any information at all. I want to just be a number in everyone database. I want to be able to spawn millions of numbers that will never be related to each other.
Just go to face to face discussion if you care so much about who you are talking to.
I'm guessing you are thinking about things like addictive social media and the efforts to keep kids from overusing it, and the idea is if there were strong privacy laws it would be harder or impossible to implement the most addictive features of those sites?
However harms based on sites having lots of personal data on their users are only part of what many people are concerned about. There are various categories of apps and sites that are legally required to not sell to/serve children. There are also things that are not illegal but the majority of research finds is bad for young children, so apps and sites may want to keep young children out unless a parent approves. Privacy laws don't help with any of that.
Laws need to be managed like software: There should be a process for testing, user feedback, quick patches for bugs or conflicts, and regular updates to fix issues. If you think about it, both laws and software are called "code".
The problem is our legal system is still based on the waterfall method. Lawmakers try to plan for everything, laws meant to solve one problem face feature creep and create a thousand others, then no one wants to touch anything after launch for fear of making things worse or because that one guy uses the temperature of his CPU as a quick-key and refuses to change his workflow.
Anyways, no law is perfect and never will be, and neither are the fixes.
> The problem is our legal system is still based on the waterfall method.
It's not? It has been "agile" for centuries. It is constantly patched as someone wants to address some issue. It's rather rare for a completely new law to be written.
> Lawmakers try to plan for everything
It's not? They see one bug, e.g. children being exploited, now they tried it with a patch that is horribly broken and doesn't really work, so they patched it again, to remediate one issue, while they try to figure out more patches.
Software development is slower in larger, more political organisations (hello Change Advisory Boards) and larger/older/sprawling codebases.
Most governments are huge, highly political, slow moving organisations. It seems to just come with the territory: slower rollout of changes, longer periods to observe the changes in the wild (throw in a few years to see how the law plays in legal cases/challenges), and suddenly you have fewer iterations to get it right.
It's also hilarious how poorly defined so many laws are. So many loopholes and bugs everywhere. Probably because most lawyers/politicians are effectively illiterate when it comes to logic.
> Probably because most lawyers/politicians are effectively illiterate when it comes to logic.
Unfortunately the “Never attribute to malice that which is adequately explained by stupidity" is completely wrong in politics. In politics and lawmaking, always attribute to malice, not stupidity.
Lawmakers appears extremely dumb on TV for the most part, but the teams behind them are actually very smart (pure evil, but smart). All the loopholes and bugs in laws are, to them, a feature. It allows them to always prosecute regular citizens, but the favored people (politicians, campaign contributors, oligarchs) always have a free pass. This is by design.
I don't disagree with you, but I think it's important to remember that ambiguous laws are also a feature of modern societies. Laws have to be ambiguous, for one because the real world cannot be codified into abstract laws perfectly, and because separation of power is a fundamental part of how our society works. Judges are supposed to apply the law to specific cases. Thus lawmakers get to decide the wording but judges get to decide how to use it. If there was no room for ambiguity, we would not need any judges.
California is a common law jurisdiction. Judges evaluate cases and make rulings based on the intent of the law instead of the literal text as written in order to avoid absurdities, setting precedent for future similar cases. If the lawmakers disagree with case law, they amend the law.
Engineers and scientists would like to imagine our society operates off a specification. But laws are only justifications for what people in power want to do. All of what you’re talking about reinforces the myth that the text matters and is precisely defined.
> (2) “Operating system provider” does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software.
Where does MacOS fit then? The core of the OS is open source (APSL licensed).
MacOS isn't Darwin and comes under terms that do not fit rhe criteria of the exception. Apple actually did go to some lengths in the past to ensure that all layers of MacOS contained bits that they could claim restrictive licenses on.
A project like PureDarwin, however, can be freely distributed because it omits Apple's proprietary parts.
I can copy and redistribute macOS binaries, and I can write programs/extensions that modify macOS.
These vague terms show that legislators are incapable of regulating software effectively; but they do create an enduring legal franchise to deal with their confusion.
You cannot. The apple license has multiple restrictions on that prevent you from copying, modifying and redistribution, for example:
> No Reverse Engineering. You may not, and you agree not to or enable others to, copy (except as expressly permitted by this License or by the Usage Rules if they are applicable to you), decompile, reverse engineer, disassemble, attempt to derive the source code of, decrypt, modify, or create derivative works of the Apple Software or any services provided by the Apple Software or any part thereof (except as and only to the extent any foregoing restriction is prohibited by applicable law or by licensing terms governing use of Open-Sourced Components that may be included with the Apple Software).
It’s 150 comments of back and forth on a change which doesn’t have a concrete reason, the maintainers aren’t in agreement on what the right approach is wrt the field’s behaviour, and the person who submitted it is bouncing between saying he’s keeping it on topic and then adding scope where he believes it should be added.
I also personally disagree with the change, I think the OP has gone ahead and implemented what they wanted but not considered the actual ways it will be used. The PR shouldn’t be merged until the laws have made a bit more progress and it’s clear what they’re _actually_ implementing.
That's the facebookisation or redditisation of open source. Open source used to mean when you got the software it got the source code, but now it means a platform for arguing. And there's no doubt in my mind when people say they can't switch their project from GitHub to Forgejo because they'd lose "contributions", they mean this.
I don't understand your point. The phrase "when you got the software it got the source code" makes no sense. And arguments were just as common decades ago on forums, mailing lists, and IRC. What exactly are you trying to say?
I would never look at a person's github account to evaluate them. The most important things people do will be proprietary, or if they contribute to serious projects will be in that project's gitlab/forgejo's instance.
I don’t think this is anything new. There’s been massive blow ups for as long as we’ve been doing this - NetBSD and OpenBSD was a massive, public falling out as was the gnome 3 release, or the python 3 release.
I have no problem with that as long as it's not the government controlling the age verification. It should be a parent. And as a parent I want the ability to properly control my children's devices - the fact that Apple, and especially Google pretty much ignored this feature until now is a big part of why we have these dumb laws in the first place.
Think about it - if every phone you got asked you at first config "are you over 18? If not ask a parent to set up this device" then everyone would know about that capability and "think of the children" would be met with "parents can just click a button"...
You already have the ability, all parents do, that some (or most) haven't is why this crap gets proposed in the first place and used as a justification for invading everyone's privacy.
If (some) parents actually parented instead of abdicating that role to the state/education system then this tripe would get far less traction - though cynically they'd just switch to the other argument they always trot out.
Oh no, some people are terrible at cooking. Better ban cooking without a license. Giving your neighbor a home baked pie is now a crime unless you're a licensed pastry chef.
Systemd is paid for by Big Business, so they will retain user-identification information in the long run of course. Poettering will never revert what he is paid for by the TechBros.
But California could adopt some of Colorado’s language about containerization:
"COVERED APPLICATION STORE" DOES NOT INCLUDE:
(I) A CODE REPOSITORY PROVIDER;
(II) A CONTAINERIZED SOFTWARE DISTRIBUTION; OR
(III) AN ONLINE SERVICE OR PLATFORM THAT DISTRIBUTES ANY OF
THE FOLLOWING APPLICATIONS IF THE APPLICATION RUNS EXCLUSIVELY
WITHIN A SEPARATE HOST APPLICATION:
(A) AN EXTENSION;
(B) A PLUG-IN;
(C) AN ADD-ON; OR
(D) ANY OTHER SOFTWARE APPLICATION.
That commit message mentions laws from California, Colorado, and Brazil. Today’s article is only about how the Californian law is inapplicable. It seems to me that the feature is still valid.
Why does birthdate trigger y'all so much, but physical location (literally the field right before it, that you can see in the diff context) doesn't? Shouldn't we be protesting even harder against systemd tracking our physical location?
Didn't physical location exist back when mainframes were a thing? Users would use it to locate each other IRL. Usually you wouldn't mind other users of the mainframe being able to visit you, that was the purpose of the field. But birth date? There are not really any genuine uses for that being at the system level. It's being used exclusively to add restrictions and lock things down, and that's exactly the kind of thing Free Software is not-for.
There’s no legislation coercing that field. systemd is doing what GECOS and chfn and .plan allow, but OS vendors are free to remove GECOS, chfn or .plan support.
Perhaps the controversy created by these pull requests is partially responsible for bringing attention to the issue and resulting in change to the legislation.
I'm confused why systemd would even do this? I'm not advocating for "breaking the law", but it's just completely absurd that this project would be prosecuted for anything... The general public as no idea what systemd even is and nor do they care. And 1st amendment free speech seems like enough to protect them.
My gut reaction to this is that there is something seriously wrong if special clauses are required. Why should open source get special treatment, to me that just highlights that the law is utterly ridiculous.
Technically opensource stays the same. The special treatment is for closed source OSes that get an additional legal protection for their datamining. We should not be passing laws that legalize the datamining of people.
One of the problems with the original law is that it failed to distinguish between open source projects and closed source products. If anything this amendment should make the law less objectionable, not more.
Facebook was the excuse (and there's a no zero chance Meta funded the initiative themselves). The government's worldwide jumped on it so quickly partially becsuse they've been trying to find aan excuse to control the internet for decades. Never dismiss how quick they are to push stuff like this but how slow they are to enact actual positive change for the people.
It's one of the better implementations, but it's still ultimately a law made to give controlling bodies more information about a previously anonymous activity. It's still a foot in the door.
It would be frustrating, but the group that is excluded from online services today tends to be low status and may benefit greatly when a tech elite with connections, status and special interest groups finds itself excluded.
I wonder how much more surveillance they can feasibly justify to prevent remote access to new secure phones from old, insecure, non-compliant devices used by Elucalidavah and other un-American activists.
According to the existing law, Facebook can't provide service to any user whose OS doesn't say they're old enough. According to this new law, Linux won't say that. So Linux users won't be allowed to use Facebook.
I’m sure there will be a package available on day 1 that will tell all sites you’re 30+ and should be allowed in. Probably even just a Firefox add-on, not a full OS package.
TBH, OS based parental filters are the optimal solution here, especially if implemented in a proper way.
Kids don't buy phones and computers, parents do. When setting up the account for the first time, the parents could set the account to be an "underage one", all the apps, browsers, etc., would get the USER_IS_UNDERAGE flag and filter content according to that. No need for every site to ask and verify the age, just set the date of birth at the time of purchase, set a parental password (for possible future changes, reselling, etc.) and prohibit formats/wipes/factory resets without a parental password being entered. The clerks in telco stores could even help with the first setup of that.
Same could be easily implemented in linux, via some user flag set by the su/sudo user during the first eg. ubuntu install.
on-device filtering is the right way to go, but it shouldn’t be a matter of sending metadata about the user to a service- instead services should provide standard metadata about the content to the device and the device can choose what, if anything, to display.
This preserves privacy better by keeping more information about the user local, and gives people better tools to decide what metadata categories they want to filter- for their kids and for themselves.
That solution doesn't actually work, and it angers me that people can't see why it doesn't work. That solution requires that the entire website must be child-safe or none of it. That solution requires that Tumblr must ban porn if Tumblr has any underage users. The alternative would be that Tumblr would randomly not load for underage users because some recommendation or ad would be over 18, and so it would rapidly have none.
Why must an age rating apply to an entire website?
As one example, the Internet Content Rating Association (ICRA) (and to a lesser extent the prior Recreational Software Advisory Council (RSACi)) had a rating scheme that allowed sites to provide a default rating label that was then overridden for individual pages and resources using <meta> tags and RDF-based labels. For example, Tumblr could set a family-friendly default rating and append a different rating on specific user pages, images, or ads.
An even more granular scheme could be applied via HTML attributes which would allow an individual section, image, link, or text snippet could be marked e.g. as "sexual", "violent", "substance use", "spoiler", or even "unknown" for unreviewed user-provided content. Then leave it up to web browsers to choose whether and how to render elements with these attributes. (Hidden entirely? With censor bars? Pixelated?)
There would be substantial logistical and regulatory challenges to get websites to comply, but it doesn't seem substantially harder than the current age verification schemes.
Because let's say you have a website like Reddit with a mixture of 18+ and 13+ stuff. Something that's 18+ but not explicit gets really popular. Pornhub will now livestream congressional debates, someone posts a link to this, and it gets fifty zillion upvotes as people can't resist commenting "wtf". Now you have a dilemma: do you show it on the front page or not? If you show this on the front page and it's 18+, it'll lock children out of the front page, which for many of them means they're locked out of the entire site because that's the way they know to access the site. But if you don't, then the law is forcing you to censor your front page for everyone, even for adults.
The solution is obvious: you show it on the front page if the user is 18+. However, your proposal deliberately forbids this and says the front page must be the same for everyone. Which leaves the other two bad options.
Haven't paid video streaming services solved that one already? Admittedly not with age verification, but you can set up child accounts. I presume Disney+ is ok here as they want to be in the family-friendly market but also offer content meant for young adults.
That's exactly what the law will do, but on the device. The parents will input the child's age during device setup, and then every service will query the age range based on that and work in "child account" mode.
Without any requirement for verification, it'll be completely up to the parents to decide what their child will see, while the services will only get the minimum information needed. It'll basically make parental control easy, but still in the parent's control.
> If you show this on the front page and it's 18+, it'll lock children out of the front page
I don't understand why you think this is true.
Today, each post on the Reddit front page appears in its own container element. If an 18+ post's container element could have some kind of "adult-content" attribute set then some web browsers could render the whole front page normally with the exception of that individual element. Perhaps they could black it out, collapse it, display it with a pixelated overlay and a "Request Access" button, whatever the browser supports and the user prefers.
> The solution is obvious: you show it on the front page if the user is 18+. However, your proposal deliberately forbids this and says the front page must be the same for everyone.
Why do you think that my proposal requires that the front page must be the same for everyone? Providing different views to different users has been the entire point of all of these laws and rating schemes. I'm just saying that my preferred scheme would be to mandate certain attributes that would allow each user's browser to apply such restrictions as they see fit rather than require that browsers send personal information to web sites so that those sites can pre-filter the content they send back.
First, leaking the user's content filtering settings is not the same as leaking their age bracket. For example, if the server identifies a web browser that isn't loading tags annotated with "sexual-content" that might indicate that the user is a child but could equally well indicate that they're a corporate office worker, religious, or anyone else who prefers not to see such content at the moment.
Second, web browsers wouldn't even have to leak this information at all. For example, perhaps an administrator could configure the web browser to renders such tags overlaid with a semi-opaque blur, in which case the server would not know.
Third, asking websites to provide more information to the web browser so that it can better manage its own filtering leaves the choice to the device admin. Whereas asking every user to submit age information to a third party so that third party can decide how to pre-filter the content it sends back gives an uncomfortable amount of control to platforms and regulators.
Yeah, there’s negative backlash against the age gate stuff but as long as you’re implementing it without privacy concerns like ID collection and verification it’s actually a really good idea.
A parent can change the setting in the OS and have every website and app comply with the OS setting is such a better situation than having to deal with a patchwork of content blockers, social media account settings, and parental controls that leak like a sieve.
Realistically, parents often don’t really have a good way to know what websites and apps you sign up for if you don’t have a crazily locked down device. Parental controls are complicated for non-technical parents and they usually know less than their kids do about the Internet.
A global OS age gate solves a lot of those problems, especially since OS-level controls are way easier to enforce and lock down compared to other methods.
Exactly like GDPR shouldn't have mandated millions of websites to pop up a consent form, as a global browser setting could would have set consent as a user preference.
But the objective of these regulations aren't what it says on the tin.
I would absolutely support that position if it were compatible with observable reality.
My family and school failed to stop me getting my hands on booze, fags, drugs, and porn. Teenagers are fundamentally not controllable. The Amish and the Mormons are having some success, but that's likely not what libertarians want to hear.
What you describe is the status quo. Parents and schools are already, variously, giving The Talk, confiscating devices, enabling internet filters. Society deems these measures ineffective. In tiny part, that's a skill issue, but mostly it's just trying to cut down a tree with a herring. Again: teenagers.
You may, of course, sulk about age restrictions on alcohol. Prohibitionists would like that. Keep your out of the contested zone, make them look reasonable.
If you want to stand on your principles, try seasteading. But I'd appreciate coherent contributions to the debate, to offset the excesses of the pearl-clutchers and the spies.
It won't be only facebook in the long run. Once this works for facebook more and more sites will be pressured to use age verification by law. Once that works well enough it will probably come for all sites, even ones that don't really need it. Take a look at the cookie law and how people handled that to see a recent example.
I've spent a hot minute trying to summarise Mat Duggan and failing, so please forgive a link drop in service of not botching the cookie banner argument:
I hold values which lead to conflicting views and opinions, which i therefore hold lightly and attempt to balance. No action or inaction is a perfect solution to a wicked problem.
- yes, people should be free to do whatever they want with their computers
- yes, people should have the freedom to exercise their independent choices
- unfortunately, there is no such thing as independent choice (unless, maybe, you were already living as a hermit)
- it is ostrichism to pretend that zuckerberg (to use him as shorthand) has not unilaterally and unaccountably engineered society to his own ends
- society has shown considerable appetite to rein him (etc) in, for legitimate reasons
- i do not, generally, support banning harmful things when stakeholders exist who favour those things
- i also do not think that the existence of stakeholders who benefit should excuse all harm
- therefore, this ugly compromise is approximately no worse than the least bad course of action or inaction
Things are shit. We are in shit. For all of history, we have always been in some or other grade of shit. We can sometimes choose between different piles of shit, but "not being in shit" is not an option. I find horseshit less objectionable than catshit, and so do many others; so here we are, actively jumping into horseshit.
Can’t think of a better outcome than Meta guaranteeing all parents that Linux is the safest OS for their kids. Steam Machines under every Christmas tree.
We got into this mess long before this, when we decided it was ok to trade freedom at the hint of protecting children, without considering the actual merits of the situation. Look at the horsemen of the infoacalypse.
will that include other FB services like whatsapp and Insta? Given how unethical FB is it highly likely they will try to ban those services too in hope for stirring discontent.
Well, maybe cigarettes were a silly metaphor -- can my kids still get their porn at the Linux store?
Are the gore websites gonna have to ask for ID now? What about 4chan? Or is the whole point to get rid of all that stuff and just get everyone using Facebook instead? (They're the ones who pushed these laws right?)
I'm honestly trying to understand what the big picture is here.
Yes, your kids will still find that dirty magazine under the park bench that the older kids discarded. And you can't stop that unless you're willing to employ a hundred park rangers who monitor every corner of a park at every time. So no one bothers.
>Are the gore websites gonna have to ask for ID now? What about 4chan? Or is the whole point to get rid of all that stuff and just get everyone using Facebook instead? (They're the ones who pushed these laws right?)
The idea is that this closes a loophole which a bunch of websites already bypass from several other kinds of laws that punish companies for breaking age verification laws (like COPPA). The obvious defense is "well I didn't know they were 12, they clicked a button saying they were 18". So now here's a mechanism that gives them more information they have to implement.
For the range of who implements it, like always, probably goes top down. They won't cover every website under the sun, but getting the big websites will supposedly be good enough. Given how consolidated the internet is these day, maybe there is some kind of point there now.
Practically, the components of Android which mandate a user account are not distributed so that the user can modify them. The exemption does not apply.
But if Ubuntu bundles an Nvidia graphics driver that is not open source does that disqualify it? It's normal for there to be a mix of both open and closed source code in an os.
A better example is: I install Debian and later, somehow, the Google Play Store. Maybe that’s the only way to get some driver. Who is responsible for asking my age: Debian or Google?
I think what matters is who is in control. You can always ditch the Nvidia driver and buy another card from a different company. Even if that one is not open source, you're the one in control.
I think since it is a for-profit project it is not exempt. At the least it would not make any sense otherwise.
I also agree that this is now a mess. Courts will lateron find that such exemptions make no sense, since it is unfair to Windows users. And Windows will require mandatory ID verification; I think they already do that to some extent, e. g. when you register the OS, unless you use the workarounds to not give up your ID in order to use Windows (not sure if this has changed with Windows 11, I won't use that version and it is unlikely I will use any later version; I use Win10 only on a secondary computer anyway, have been using Linux since soon-to-be 30 years so I could not care any less about this ruthless and evil operating system called Windows, now with mandatory AI slop spam).
This is funny to me, because if the age-verification laws were supposed to be a stepping stone toward greater oversight on computing so that AI can be corralled in the future, seeing what is likely to come with billions of spam-bots and zero traceability, then this single decision alone completely undermines it.
A court at a later time may find that this situation is unfair to windows users who have to submit to age sniffing. So this will easily be overturned at a later time - age sniffing will never be given up by the lobbyists groups paid for by Meta and others (and the USA also wants that information).
361 comments
[ 0.23 ms ] story [ 25.4 ms ] threadIs this serious or sarcasm? They passed a horrible law, now its an internally contradictory horrible law because apparently it isn't important enough to consistently enforce. So, you know. Why legislate it?
There isn't much of an angle here that reflects well on Californian lawmakers, they're still supporting this authoritarian trend of de-anonymisation and rolling back free communication on the internet. They're just going to come back for linux later once the idea of legally mandated PII on account registration is normalised. Although I do see this "In addition, lawmakers inserted a new provision prohibiting anyone from requesting an age signal from an OS provider or app store unless required by law" so we seem to be entering a wild space where they're going to try and micromanage this in a weird way.
Law is not an abstract code, but an incremental sometimes futile approach to shape society. They only want a way to hold big corporations accountable to exploiting children. They don't actually intend the effects on the consumer, so they tried to fix on easily changeable effect: "Don't worsen the privacy for people who want it." If you are using e.g. MS Windows, you have given up everything already. They do a lot of "telemetry" and for example everything you typed into MS Word is already licensed to Microsoft.
Seriously, what is the message here supposed to be about the kids using linux? And why are they so different from kids using Windows or Mac? Are there other safety features we can exempt kid linux users from?
There is a sysadmin (likely the parent), whose responsibility is that already.
Let me know when they pass actual laws tackling that, then. Even if this law was ironclad, this does not solve the simple factor of using a "verified" device.
You don't fix a problem of society from private corporations by restricting society. You need to actually attack the corporations itself. But governments are sheepish to go after "their own", or people who can bribe them into feeling like one of them.
It's not a great implementation either. But COPPA is an example in the right direction and made companies need to change their algorithms based on the user account's reported age. That's more of the direction to move in.
If you allow this pandering to satisfy you, you’re essentially supporting an age verification requirement for all other computing systems. So you didn’t think the requirement itself was a problem, you just wanted to make sure it didn’t affect you?
Good day.
I used the same language as in the OP title. Why aren’t you responding to that? You’re missing the point because you weren’t responding meaningfully to what I was saying, you’re using someone else’s choice of language to derail.
> Good day.
And here comes the passive aggression, true to form.
This is not a good thing, it's a very small patch for a very bad thing.
The original issue with the law was never that those poor open source developers were going to have to bear the burden of complying with the law, but that the law itself was a bald-faced invasion of privacy by an overbearing troupe of people in power (i.e., government) so shit-sure of their superiority over the simple common folk they govern (i.e., you and me) that they aren't even embarrassed by their own arrogance.
I would suggest that what "we wanted" is no such law at all. What would be weird, and worthy of comment, is if those of us that complain about government were actually satisfied by an exemption which only applies to pretty damn tiny slice of the market. If anything, that wasn't a victory for privacy or common sense, but rather a concession that they had foolishly created a law that they wouldn't have been able to enforce as broadly as they thought they could get away with... or if they tried to enforce it they'd have to contend with the optics of the big hand of government yet again crushing individuals whose only real crime was their altruism rather than just some giant corporation.
So it isn't weird at all that "we're" silent. This isn't a win. Pointing out that the law had unintended consequences, including with Linux, et al., wasn't a statement of objective but rather a simple show that the law was rife with thoughtless unintended, or perhaps simply unspoken, consequences. The legislature's act here didn't restore privacy nor did it remove bad outcomes: if anything it now just raises questions about equal protection under law, at least on some practical level. It raises the question why some users of computers need such protections as age verification and others don't, and why the licensing terms of the OS are a valid proxy for that need... taking for granted that the stated purposes of the law are the real ones, of course.
I take it that you wouldn't be OK with somebody building a uranium enrichment facility in their backyard for their hobby reactor. So there is a line to be drawn on where people's freedom to tinker ends; it's just a question of where you draw it.
Personally, I think given there is actual documented, non-isolated problem with 3D printed guns being used for violent crime, there's a debate to be had that's more sophisticated than "REGULATION BAD".
What's next, keep track of all printed parts and invent the math to recombine them in every way possible to see if it could form a gun? Trivially defeated by using multiple printers. Hmmm, sounds like a good reason to force everyone to register their 3D printer with their real identity, and only allow a print after the model has been uploaded to the Federal Printing Database for verification...
It’s so ridiculously easy to assemble a 3d printer from individually sourced parts, and find some open source firmware to run it. How is this going to stop anyone who’s dishonest and slightly motivated?
What’s next is thinking about guns is a thought crime.
I read the discussion and thought "yeah that's nerd talk, just not about analogue synthesizers, old Landrover gearboxes, or Pascal compilers".
I guess the reason for blocking 3D printers from making gun parts is because it's easier than doing it "by hand". All you really need to do is get a copy of the files from someone who has them, print it out in something suitable, and you have viable gun components with very little "real work" involved.
By contrast here in the UK, where it's quite surprising what you're allowed to own and operate if you comply with the laws (here you're allowed fully automatic weapons, if you keep them at a suitable shooting range and don't try to wander around town with them, and you're not oh maybe a convicted violent criminal for example) one of my late father's friends was a gunsmith. My dad was an excellent machinist, and so he made some components for his friend, and I remember standing in the machine shop where they worked while he turned a chamber for a gun his colleague was building in the lathe. "There you go," he said, taking it out of the chuck, "that's legal".
Then he took it over to the mill, and cut a couple of holes and slots that would allow it to actually function as a chamber, "And there - now it's *illegal*."
Then, as he handed it to his friend, who was licensed to have "home made" gun parts, to stamp his initials on, "And now it's legal again."
Of course since people aren't allowed to just walk around with handguns since the school shooting, it's all a little more difficult - but the police will tell you what you need to do to keep it legal.
It's still slightly easier to get a shotgun licence than a motorcycle licence here.
I think you're overstating this. My understanding is that here in GB (unsure about NI) fully automatic firearms are absolutely prohibited with only limited exceptions that the general public are typically ineligible for. Could you elaborate?
This is not an easy or inexpensive thing to set up.
I shot a documentary about a guy doing just that in NE Scotland, about 20 years ago, and while his range is still in business I don't think he has ever cleared the tape for redistribution - it was a "here's what you spent your money on" for the investors.
This would be an unconstitutional law, per Bruen.
3D-printed "guns" become a real issue when you combine it with unregulated sale of firearm parts and ammunition. To get a fully-functional gun you just need to 3D print a fairly trivial component which is legally considered the entire gun as it carries the serial number. But that's not a 3D printing problem, because there are also companies selling that same part in a mostly-finished legally-not-a-gun form, together with a drilling jig guiding you how to drill the last few holes with a regular Dremel. And nobody is proposing banning Dremels. Heck, it is totally okay to own a lathe - which you can use to make your own high-quality guns!
And the entire discussion is of course pointless once you realize that this is the USA, so anyone is only a weekend road trip away from legally and fully-anonymously buying a gun two states over. If 3D-printed guns are such a huge problem, why aren't we seeing European countries mass-banning 3D printers?
To extend your analogy: it's like being fine with the sale of ultracentrifuges and uranium hexafluoride, then getting upset at someone selling a screwdriver to attach the plug to the power cord of the ultracentrifuge because "screwdrivers lead to nuclear bombs".
3D printed guns are a nothingburger. There is indeed a non-zero number of violent crimes committed with them - but there is also a non-zero number of violent crimes committed with shoelaces, so that's clearly not enough of a reason to ban them. It only makes sense to regulate them if they are involved in a significant number of crimes and leading to a huge increase in gun violence - and at that point you probably want to crack down on all forms of DIY guns instead of just the 3D printed ones. But that's simply not the case, so the regulation is pointless and doing more harm than good.
Dunno, because most europeans are way more responsible with their guns than many people in the US?
For example in the EU (and in Switzerland) before you can buy a gun, you get specific training about safe and responsible handling. And in many countries the cops shall come to your place and verify that you've got a gun safe and a separate safe for the ammo.
And we don't offer AR-15 to our kids when they turn 14 y/o (well I say that but my daughter wants to shoot my weapons and, once she turns 14, she can switch from air rifles to the real thing as long as she's accompanied).
Just to be clear: we have shitloads of guns and ammos in Europe. There's even one EU country with concealed carry. I think it's estimated there are twice as many non-registered weapons as registered ones. We've got big guns factories and gun brands in the EU. And there are millions of illegal full-auto weapons like kalashnikovs (well Zastava M70, which is the same) from the war in Yougoslavia in the hands of criminals. And shitloads of fully functional weapons, including handguns, from WWII circulating.
In my native city (Brussels, Belgium), at the moment there are drug dealers firing kalashnikov on police stations regularly (it's a big issue, it's in the news daily and the authorities don't know what to do).
In addition to people shooting at the range (and, sadly, to drug dealers/criminals ruining our cities), we've got lots of hunters too.
Many people at my shooting range have their official gun transport license full (that is 30 weapons) and some have more than 100 weapons in their collection.
It's a fantasy that europeans don't have guns: we're (mostly) responsible with them.
It's maybe because we're responsible with our guns that the EU hasn't banned 3D printers... Yet (it's the EU, so nothing is unthinkable).
Making actual firearms from steel is trivial. In fact you can look up Kalashnikov designs online and then replicate it with a relatively simple mill/lathe/tapping setup.
To be honest, as someone familiar mostly with computers, I have no idea where to start with this and it sounds a bit intimidating. Buying a 3D printer and using some 3rd party design sound very easy in comparison.
You're certainly right that it's possible for someone determined to make their own firearm, but raising the bar still has immense value.
Tradeoffs between freedom and safety are another, unrelated discussion.
Congrats, you built a zipgun.
https://www.bbc.com/news/uk-england-nottinghamshire-63198715
There's now much more of a debate that's to be more sophisticated than "3D PRINTED GUNS BAD".
You don’t seem to have a good grasp of the topic but already decided the opposition position is „regulation bad“, but that’s not the case at all. The pushback comes from introducing the government as middleman between your slicer and 3d printer, that’s dystopic af
Your analogy fails in that yes, you are not allowed to make hobby reactor. But that's because you are not allowed to have any kind of reactor at all.
Banning 3d-printed guns while not banning real guns (which are order of magnitude more effective) makes no sense.
It’s like trying to ban wrenches.
Lever and tube - that’s what it is. People create makeshift ones even when it’s legal to buy them, because it’s cheap and easy to do so.
You can’t ban computers or personal transportation or words either.
You can’t even ban a person from a website. You can ban an account - but you haven’t stopped the person. Any attempt at playing arbitrary authority you’re gonna lose
" third carve-out excludes storefronts distributing extensions or add-ons that run exclusively inside a host application, which takes browser extension stores out of scope."
So really, both concepts can mesh.
Would always install some variant, think it was "pretty cool" for a few days, then revert back to "whatever MacOS was offering" (for my daily driver).
----
2026: I just finished building my third Ubuntu Linux machine, this year (gave the first one to my brother). An Ubuntu running a 5070Ti is now my main operating system.
Now we've decided that if we don't talk about something, people won't get curious about it. Sadly, without being properly taught how to be safe, that generally ends tragically.
1200 deaths a day from diarrhea in India.
Put it in perspective.
They use it as a metaphor to attempt to make an argument about a different, actually real, situation. My argument is this is pointless because no real world situation will ever meaningfully resemble the trolley problem.
The correct answer to the trolley problem is STOP THE TROLLEY. "You can't do that!" "Why not?" "because magic" "well how do I know this magic is there?" "more magic!" etc etc.
What do you do if the dragon demands a sacrifice or it attacks the town? You fight the dragon.
I hope you're arguing out of perversity, not conviction - such is valuable, and i did have to think for a minute. I agree that lateral thinking can be productive.
> Someone brave attempts to jump onto the moving trolley, risking their own neck
This is a completely different problem. The whole point of the trolley problem is to attempt to justify the sacrifice of the few for the good of the many.
The entire framing is about other people dying, not whether or not you would sacrifice yourself.
Globally, 1.2 million people (all ages) die of diarrhea every year.
India accounts for 120k deaths of children under 4 or roughly one fourth of global D related deaths or 328 deaths per day.
Assuming a similar ratio across all ages, India must account for 300k D related deaths every year of roughly 820 deaths. Not great (obviously) but at least it only accounts for 1/4 of all D deaths, not 1/3rd.
https://data.unicef.org/topic/child-health/diarrhoeal-diseas...
https://www.joghr.org/article/75428-evaluating-india-s-inten...
And part of the problem is that our entertainment media (movies, shows, video games) pretty much trains anybody who has not been taught gun safety in real life to reflexively point a gun at somebody when it is picked up, often with their finger already on the trigger (although some movies are better about this now). People see a gun on the ground, may not even know its real and think its a toy, "Hey guys look what I found" and immediately aim down the sites at their friend.
I dread the outcome of practical safety lessons because, the moment you give a classroom guns, then some teenage edgelord is going to pantomime shooting their buddy, or escalate a playground beef.
People do not work the way you want people to work :-(
May i offer an alternative? Make gun ownership a tedious bureaucratic procedure. Reams of paperwork will filter out many stupid. Stupid exist who can fill forms, but it's a smaller set.
The cavalier phrase "tit about with" is exactly the issue. People do so due to a lack of education about gun safety.
> I dread the outcome of practical safety lessons because, the moment you give a classroom guns
OP didn't mention practical lessons, and giving real guns to school children would be idiotic. You don't have to actually have a gun in your hand to learn what not to do with one should you encounter it. We have MYRIAD examples of non practical instruction (things like sex ed, chemistry [what happens if sodium is dropped in water and why?], physics [hey kids, lets visit a live nuclear reactor!]). If anything, the best way to dampen the glamor of guns instilled by media would be to make it a boring school subject.
> Make gun ownership a tedious bureaucratic procedure.
In many cases, it is. In my state, you can't hunt with a gun (or even a bow I think) without a mandatory gun safety course, and I needed a background check to buy the rifle in the first place. A background check that required a form.
Not to say there aren't loopholes, of course, and I think most Americans agree with common sense gun laws.
Personal opinion: you are a poor faith participant in this forum and speak with no good will.
I've never hidden my interest & passions, and I think the world is a better place when people are proud of what they enjoy. We're people first, after all.
And most techies are already primarily on Linux and its derivatives.
Linux has gone from attracting hippies to openly endorsing corporate closed-source products, something something live long enough to become the villain.
And then further into the text it's clarified that there also isn't a specific list of open licenses, as the terrible headline would have you believe, but instead a description of what is considered open
With the caveat that I haven't read the actual legal text, this seems to be an eminently sensible law (it'd be better if it weren't needed, but here we are).
In summary: not a Linux exemption, and not an exemption for a specific list of licenses either.
This law was never going to succeed at those aims.
What I meant is that if we take the law as a given, then the exemption we are discussing here are very good and sensible. I wish they weren't needed, but given that they are, the language seems sensible.
I really struggle to understand what you're trying to say. Is it that since the original law is dumb, we should accept no remedy short of getting rid of that original law? I think you'll find making progress in the real world very hard with that attitude.
The reality is that many people want bad laws. Without the support of those people one does not get elected.
This use of people for power while de-facto disenfranchising them is pretty widespread already. For instance, some half of California and Texas are responsible for their strength in the electoral college while simultaneously being entirely disenfranchised when electing the President. Good technique.
Or also BSD, ReactOS, hobby OS #24562 etc... ?
From TFA
> These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test, which removes the likes of Debian, Fedora, Ubuntu, Arch, and the BSD family from AB 1856’s scope.
The article then explicitly cite "Debian, Fedora, Ubuntu, Arch, and the BSD family".
There is also another exclusion for libraries and software from a packages managers like apt and pacman.
So from my understanding ReactOS, hobby OS but also CP/M, FreeDOS, Haiku or Collapse OS...
Explain how a privacy that protects you and me will somehow also protect a pedophile. How does that work? I am FOR privacy. I do not want to have any information at all. I want to just be a number in everyone database. I want to be able to spawn millions of numbers that will never be related to each other.
Just go to face to face discussion if you care so much about who you are talking to.
I think that it will, and that's okay. The US Bill of Rights necessarily protects criminals as well as innocents. "The optimal amount of [crime] is non-zero." (https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...)
However harms based on sites having lots of personal data on their users are only part of what many people are concerned about. There are various categories of apps and sites that are legally required to not sell to/serve children. There are also things that are not illegal but the majority of research finds is bad for young children, so apps and sites may want to keep young children out unless a parent approves. Privacy laws don't help with any of that.
The problem is our legal system is still based on the waterfall method. Lawmakers try to plan for everything, laws meant to solve one problem face feature creep and create a thousand others, then no one wants to touch anything after launch for fear of making things worse or because that one guy uses the temperature of his CPU as a quick-key and refuses to change his workflow.
Anyways, no law is perfect and never will be, and neither are the fixes.
It's not? It has been "agile" for centuries. It is constantly patched as someone wants to address some issue. It's rather rare for a completely new law to be written.
> Lawmakers try to plan for everything
It's not? They see one bug, e.g. children being exploited, now they tried it with a patch that is horribly broken and doesn't really work, so they patched it again, to remediate one issue, while they try to figure out more patches.
Most governments are huge, highly political, slow moving organisations. It seems to just come with the territory: slower rollout of changes, longer periods to observe the changes in the wild (throw in a few years to see how the law plays in legal cases/challenges), and suddenly you have fewer iterations to get it right.
Unfortunately the “Never attribute to malice that which is adequately explained by stupidity" is completely wrong in politics. In politics and lawmaking, always attribute to malice, not stupidity.
Lawmakers appears extremely dumb on TV for the most part, but the teams behind them are actually very smart (pure evil, but smart). All the loopholes and bugs in laws are, to them, a feature. It allows them to always prosecute regular citizens, but the favored people (politicians, campaign contributors, oligarchs) always have a free pass. This is by design.
That's how it should work on paper anyway...
> software distributed under the GPL, MIT, BSD, and Apache licenses are exempt
Where does MacOS fit then? The core of the OS is open source (APSL licensed).
A project like PureDarwin, however, can be freely distributed because it omits Apple's proprietary parts.
I can copy and redistribute macOS binaries, and I can write programs/extensions that modify macOS.
These vague terms show that legislators are incapable of regulating software effectively; but they do create an enduring legal franchise to deal with their confusion.
> No Reverse Engineering. You may not, and you agree not to or enable others to, copy (except as expressly permitted by this License or by the Usage Rules if they are applicable to you), decompile, reverse engineer, disassemble, attempt to derive the source code of, decrypt, modify, or create derivative works of the Apple Software or any services provided by the Apple Software or any part thereof (except as and only to the extent any foregoing restriction is prohibited by applicable law or by licensing terms governing use of Open-Sourced Components that may be included with the Apple Software).
From https://www.apple.com/legal/sla/docs/macOSTahoe.pdf
The “under license terms…” is a pretty important clause you omitted here.
I also personally disagree with the change, I think the OP has gone ahead and implemented what they wanted but not considered the actual ways it will be used. The PR shouldn’t be merged until the laws have made a bit more progress and it’s clear what they’re _actually_ implementing.
Think about it - if every phone you got asked you at first config "are you over 18? If not ask a parent to set up this device" then everyone would know about that capability and "think of the children" would be met with "parents can just click a button"...
If (some) parents actually parented instead of abdicating that role to the state/education system then this tripe would get far less traction - though cynically they'd just switch to the other argument they always trot out.
Unfortunately, things have worked out that way so far.
We know poeople are terrible with guns so we...um..try to protect their freedom to be terrible.
These arguments are about values not control gates.
https://commandlinux.com/statistics/linux-kernel-contributor...
"COVERED APPLICATION STORE" DOES NOT INCLUDE: (I) A CODE REPOSITORY PROVIDER; (II) A CONTAINERIZED SOFTWARE DISTRIBUTION; OR (III) AN ONLINE SERVICE OR PLATFORM THAT DISTRIBUTES ANY OF THE FOLLOWING APPLICATIONS IF THE APPLICATION RUNS EXCLUSIVELY WITHIN A SEPARATE HOST APPLICATION: (A) AN EXTENSION; (B) A PLUG-IN; (C) AN ADD-ON; OR (D) ANY OTHER SOFTWARE APPLICATION.
What am I missing here?
The result looks to me like Facebook will ban access from non-approved OSes like Linux. Android will still be allowed, GrapheneOS probably not.
Which OS is better for gaming? Windows or Linux?
A: Linux, because you can't play League of Legends
Or to things that we need, like medical care, government interactions, and financial services.
People shouldn't have to choose between safety features like those in Graphene OS and participation in society.
I wonder how feasible is it to use a separate phone and access it remotely from the main phone.
Think of the children!
Kids don't buy phones and computers, parents do. When setting up the account for the first time, the parents could set the account to be an "underage one", all the apps, browsers, etc., would get the USER_IS_UNDERAGE flag and filter content according to that. No need for every site to ask and verify the age, just set the date of birth at the time of purchase, set a parental password (for possible future changes, reselling, etc.) and prohibit formats/wipes/factory resets without a parental password being entered. The clerks in telco stores could even help with the first setup of that.
Same could be easily implemented in linux, via some user flag set by the su/sudo user during the first eg. ubuntu install.
This preserves privacy better by keeping more information about the user local, and gives people better tools to decide what metadata categories they want to filter- for their kids and for themselves.
As one example, the Internet Content Rating Association (ICRA) (and to a lesser extent the prior Recreational Software Advisory Council (RSACi)) had a rating scheme that allowed sites to provide a default rating label that was then overridden for individual pages and resources using <meta> tags and RDF-based labels. For example, Tumblr could set a family-friendly default rating and append a different rating on specific user pages, images, or ads.
An even more granular scheme could be applied via HTML attributes which would allow an individual section, image, link, or text snippet could be marked e.g. as "sexual", "violent", "substance use", "spoiler", or even "unknown" for unreviewed user-provided content. Then leave it up to web browsers to choose whether and how to render elements with these attributes. (Hidden entirely? With censor bars? Pixelated?)
There would be substantial logistical and regulatory challenges to get websites to comply, but it doesn't seem substantially harder than the current age verification schemes.
The solution is obvious: you show it on the front page if the user is 18+. However, your proposal deliberately forbids this and says the front page must be the same for everyone. Which leaves the other two bad options.
Without any requirement for verification, it'll be completely up to the parents to decide what their child will see, while the services will only get the minimum information needed. It'll basically make parental control easy, but still in the parent's control.
I don't understand why you think this is true.
Today, each post on the Reddit front page appears in its own container element. If an 18+ post's container element could have some kind of "adult-content" attribute set then some web browsers could render the whole front page normally with the exception of that individual element. Perhaps they could black it out, collapse it, display it with a pixelated overlay and a "Request Access" button, whatever the browser supports and the user prefers.
> The solution is obvious: you show it on the front page if the user is 18+. However, your proposal deliberately forbids this and says the front page must be the same for everyone.
Why do you think that my proposal requires that the front page must be the same for everyone? Providing different views to different users has been the entire point of all of these laws and rating schemes. I'm just saying that my preferred scheme would be to mandate certain attributes that would allow each user's browser to apply such restrictions as they see fit rather than require that browsers send personal information to web sites so that those sites can pre-filter the content they send back.
First, leaking the user's content filtering settings is not the same as leaking their age bracket. For example, if the server identifies a web browser that isn't loading tags annotated with "sexual-content" that might indicate that the user is a child but could equally well indicate that they're a corporate office worker, religious, or anyone else who prefers not to see such content at the moment.
Second, web browsers wouldn't even have to leak this information at all. For example, perhaps an administrator could configure the web browser to renders such tags overlaid with a semi-opaque blur, in which case the server would not know.
Third, asking websites to provide more information to the web browser so that it can better manage its own filtering leaves the choice to the device admin. Whereas asking every user to submit age information to a third party so that third party can decide how to pre-filter the content it sends back gives an uncomfortable amount of control to platforms and regulators.
A parent can change the setting in the OS and have every website and app comply with the OS setting is such a better situation than having to deal with a patchwork of content blockers, social media account settings, and parental controls that leak like a sieve.
Realistically, parents often don’t really have a good way to know what websites and apps you sign up for if you don’t have a crazily locked down device. Parental controls are complicated for non-technical parents and they usually know less than their kids do about the Internet.
A global OS age gate solves a lot of those problems, especially since OS-level controls are way easier to enforce and lock down compared to other methods.
But the objective of these regulations aren't what it says on the tin.
Also, the browser flag that indicates no consent already exists: https://globalprivacycontrol.org/faq
Glad it is now in place.
https://en.wikipedia.org/wiki/V-chip#Usage
My family and school failed to stop me getting my hands on booze, fags, drugs, and porn. Teenagers are fundamentally not controllable. The Amish and the Mormons are having some success, but that's likely not what libertarians want to hear.
What you describe is the status quo. Parents and schools are already, variously, giving The Talk, confiscating devices, enabling internet filters. Society deems these measures ineffective. In tiny part, that's a skill issue, but mostly it's just trying to cut down a tree with a herring. Again: teenagers.
You may, of course, sulk about age restrictions on alcohol. Prohibitionists would like that. Keep your out of the contested zone, make them look reasonable.
If you want to stand on your principles, try seasteading. But I'd appreciate coherent contributions to the debate, to offset the excesses of the pearl-clutchers and the spies.
https://matduggan.com/you-know-gdpr-is-good-based-on-who-hat...
I hold values which lead to conflicting views and opinions, which i therefore hold lightly and attempt to balance. No action or inaction is a perfect solution to a wicked problem.
- yes, people should be free to do whatever they want with their computers - yes, people should have the freedom to exercise their independent choices - unfortunately, there is no such thing as independent choice (unless, maybe, you were already living as a hermit) - it is ostrichism to pretend that zuckerberg (to use him as shorthand) has not unilaterally and unaccountably engineered society to his own ends - society has shown considerable appetite to rein him (etc) in, for legitimate reasons - i do not, generally, support banning harmful things when stakeholders exist who favour those things - i also do not think that the existence of stakeholders who benefit should excuse all harm - therefore, this ugly compromise is approximately no worse than the least bad course of action or inaction
Things are shit. We are in shit. For all of history, we have always been in some or other grade of shit. We can sometimes choose between different piles of shit, but "not being in shit" is not an option. I find horseshit less objectionable than catshit, and so do many others; so here we are, actively jumping into horseshit.
Oh no! Anyways…
excellent! won't have to worry about my kids wanting a FB account -- it just won't be accessible
Or is the idea that the Linux store is not allowed to sell cigarettes anymore?
Are the gore websites gonna have to ask for ID now? What about 4chan? Or is the whole point to get rid of all that stuff and just get everyone using Facebook instead? (They're the ones who pushed these laws right?)
I'm honestly trying to understand what the big picture is here.
>Are the gore websites gonna have to ask for ID now? What about 4chan? Or is the whole point to get rid of all that stuff and just get everyone using Facebook instead? (They're the ones who pushed these laws right?)
The idea is that this closes a loophole which a bunch of websites already bypass from several other kinds of laws that punish companies for breaking age verification laws (like COPPA). The obvious defense is "well I didn't know they were 12, they clicked a button saying they were 18". So now here's a mechanism that gives them more information they have to implement.
For the range of who implements it, like always, probably goes top down. They won't cover every website under the sun, but getting the big websites will supposedly be good enough. Given how consolidated the internet is these day, maybe there is some kind of point there now.
I also agree that this is now a mess. Courts will lateron find that such exemptions make no sense, since it is unfair to Windows users. And Windows will require mandatory ID verification; I think they already do that to some extent, e. g. when you register the OS, unless you use the workarounds to not give up your ID in order to use Windows (not sure if this has changed with Windows 11, I won't use that version and it is unlikely I will use any later version; I use Win10 only on a secondary computer anyway, have been using Linux since soon-to-be 30 years so I could not care any less about this ruthless and evil operating system called Windows, now with mandatory AI slop spam).
A court at a later time may find that this situation is unfair to windows users who have to submit to age sniffing. So this will easily be overturned at a later time - age sniffing will never be given up by the lobbyists groups paid for by Meta and others (and the USA also wants that information).