System76 Responds to Laws Requiring Age Verification at the OS Level

I’d say it’s more a question of scale. S76 is made up of ~60 people and only have a fraction of the OS market. Their main business is hardware. They’re a drop in the ocean when compared to Apple/M$, which will be the main driving forces behind it.
It doesn’t make really make it any better, but does mean that it’s misdirected effort since it is unlikely to have any effect.

Targeted ads and surveillance is a very lucrative business. The age brackets provide an easy entrypoint and a springboard for further political actions, such as more invasive laws.

1 Like

How’s that? You already need to confirm your age to visit various websites and one would argue rightfully so.

This is on an OS level. Everything will be able to access it.
The second part is the bigger issue either way. The moment the politicians think it isn’t doing enough or they see a chance to tighten their grip on people, they will try pushing more invasive measures instead. This is only a first step.
They’ve clearly realized that machine learning has made it feasible for them to perform mass surveillance economically, this is a stepping stone towards that.

4 Likes

So turns out the major tech lobbyists in favor of the Colorado bill are platform owners (they probably don’t want to build the age verification infrastructure)

The California bill got lobbied by the international center for missing children

2 Likes

Couldn’t the developers fight back by putting in the terms and conditions of use that you must be over 18 to use this operating system.. Problem solved.

1 Like

They could in the old world, but the old world was abandoned because it allowed privacy and didn’t allow tracking users every action online.

Mass surveillance has been occuring in the US for the better part of the last two decades. By the way, the US Government is fully aware of your age assuming you’re a citizen.

1 Like

Verification doesn’t exist in either of the bills being discussed…?

Props to you for your faithful pushing of the anti-privacy narrative.

Repeat after me: “we all know what the next step is.”

Thank you for your attention to this matter.

2 Likes

You’ve restated the slippery slope argument in most of your comments here, but it’s not clear why we should believe a simple age check necessarily leads to the forms of mass surveillance you are talking about.

Somehow checking a user’s age on the multitude of adult websites we have today did not lead to KYC-esque verification in the vast majority of industries, with the obvious exceptions of state-sanctioned gambling and investment platforms.

Or a legal resident (that’s a federal thing which requires your DOB), or any kind of resident who pays taxes, or any kind of resident with a driver’s license (almost everyone in the US).

1 Like

Yes. But ML allows them to do it at a much larger scale with less manpower.
But this isn’t just that.

If you want an analogy, this is the equivalent of having your year of birth tattoo’d onto your face at birth.
For law-abiding citizens, that poses a risk.
Those that don’t abide by the law will simply alter it using make-up. The guy selling narcotics out of a dark alley will have an even easier time doing it, while the store clerk gets to see your age regardless of whether they needed to or not.

Dividing it into age brackets rather than displaying your real age has no impact on the security aspect of it whatsoever. It just makes it sound nicer to those that don’t know any better.

Needless to say, if they do follow the law and input their real age, they’ve now been exposed to bad actors that they normally wouldn’t provide their age to.
The only potentially positive thing I can think about it is that if you don’t input your real age, you might be able to throw bad actors off for a short time.

What exactly is the threat model posed by knowing a user’s age? 1/365 chance in guessing the correct birthdate?

I remain skeptical that any of this leads to some sort of unified mass “digital ID” which is what I think most people loudly opposed to this legislation are dancing around. That’s putting a lot of faith in government to conceive of and execute a massive undertaking that, based on my experience in a country with public healthcare (and hence associated record keeping), would be nearly impossible in the US. Certainly not without States not currently in the President’s pocket acting as a canary in the coal mine.

The only faith I have in government is that they will raise taxes and make (IMHO) stupid vague laws.

1 Like

More generally (a jaded) one might have faith that governments are usually incompetent, making widespread conspiracies improbable at best :face_with_tongue:

Moneyed and special interests that have a grip on the international systems of economics aren’t nearly as incompetent.

1 Like

I cannot imagine, in this day and age, still having the view that those pulling the strings are incompetent and can’t pull off a conspiracy. I feel like I stumbled into a time warp and ended up pre-9/11 with your comment and oblivious to JFK, RFK, MLK, and Hoover and so much more.

Perhaps an age verification could be of some use, at least in this discussion…

Ah… ad hominem, the final refuge of a man with no argument :wink:

If you watched the video or followed the money, the lobbyists who are in support of os level age gate apis are funded by companies that operate platforms that have not implemented identity verification.

Honestly, I don’t get the impression that you want to engage in a conversation to understand my concerns with the laws. I will post examples that I think are tangentially relevant for this topic. All your responses don’t refute any of my examples, conclude that my points are just slippery slopes, or discount that age signals as identity verification. I would be more willing to engage in conversation if you provided quotations, counter points justifiy your response. Until then, I do not plan not engage any further responses, as you are just rage baiting me.

Here are my concerns with a little bit more organizational

  1. I don’t trust the authorities won’t stop with just OS age gating signals.
  2. These laws apply to companies and hobbyists, community run distributions are not exempt from fines
  3. If we do slide down the metaphorical slippery slope (and I’d verification is forcefully required), I do not trust authority to securely transfer data (see discord’s data breach and conduent leaking sensitive data).

authorities won’t stop with age gating/signals

Let’s start with the slippery slope argument. They won’t stop with just age signals based on birth date.

In the past, steam just asked for a birth date, now the government is asking for credit cards to prove users are adults
https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/age-assurance

Self declaration (which is what steam used to use) is no longer allowed. If you need other examples, look at the timeline of age verification laws in the United States

Furthermore, when people used VPNs to circumvent the social media restrictions and conduct civil disobedience towards a stupid law, UK lawmakers lobbied to force VPNs to implement similar measures.

If we assume “democratic” governments follow the UK, even if we wanted to strip out these features, the lawmakers will restrict such techniques. Furthermore, the laws apply to everyone not just commercial operators.

these laws also apply to commercial and hobbyists

I will start with my understanding of the sections that concern me. Hopefully I can inspire others to cite sections that refute my concerns

My understanding is that app developers must take a age gate provided by the operating system. Any developers that do not use this will be fined by the attorney general.

Reading further

Operating system provider means any one who maintains operating system software. If you don’t implement age signal gating, you will be fined

Reading further

The operating system provider must provide the application developer with a signal.

This is a overstep, as it makes the individual developers and hobbyists open to fines for not implementing age signaling.

I’m not sure how this would apply if I distribute software that does not check for a user’s age at the account level I can be fined. I assume that if I write a script to circumvent it is considered to be

willfully disregard internal clear and convincing information otherwise available to the developer that indicates that a user’s age is different than the age bracket data indicated by a signal provided by an operating system provider or a covered application store.

The Colorado bill is pretty the same, I don’t feel like formatting the pdf for markdown

sensitive data won’t handled properly and will be abused

9 Likes

Again, your exact birthdate isn’t important.

Targeted ads, scams etc only need a general age group to increase dramatically in efficacy. Privacy isn’t only about protecting your identity. It has both a direct and indirect impact on your security.

2 Likes