Re: On the unfortunate need for an "age verification" API for legal compliance reasons in some U.S. states

Aaron Rainbolt <[email protected]> Tue, 24 Mar 2026 21:27:48 -0400
Newsgroups gmane.linux.debian.devel.legal,gmane.linux.debian.devel.general
Message-ID <[email protected]>
--Sig_/Ww8Xg89aE0p9=SB_rpcxq3X
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Wed, 25 Mar 2026 09:13:32 +0800
Otto Kek=C3=A4l=C3=A4inen <[email protected]> wrote:

> Hi,
>=20
> (dropping non-Debian recipients)
>=20
> I was wondering why so many US states are pushing for this legislation
> instead of the federal government doing just one law and why this all
> is happening in the US right now. While digging I came across this
> group of anonymous researchers who claim that this is the result of
> Meta lobbying for age verification on the OS side, so that the
> dopamine inducing service producer would not be kept accountable or
> required to have any restrictions as the they could argue that the OS
> or the app store has already taken care of doing the restrictions and
> policing.
>=20
> I do not know if any of this is true, I am just sharing that I found
> this: https://tboteproject.com/git/hekate/attestation-findings

I would not personally consider this repo a trustworthy source of
information. It was recently used as part of a doxxing/harrassment
attack against an individual who has been helpful in adding optional,
freedom-preserving and ignorable age attestation tooling to components
of various Linux-based operating systems (not me, for what it's worth).
The comment on Codeberg that was guilty of this has (thankfully) been
removed, but given that the person running this repo actively helps doxx
people, I consider them (semi-)malicious.

The same info (about Meta funding this) has been reported multiple
times on Reddit, and while I do not know if it's true, it sounds
plausible. I would consider the Reddit posts about it as more reliable
info, such as:

https://www.reddit.com/r/linux/comments/1rmhxk1/i_pulled_the_actual_bill_te=
xt_from_5_state_age/

--
Aaron

> On Wed, 11 Mar 2026 at 13:33, Jamie Null <[email protected]> wrote:
> >
> > I'm going to be completely honest.
> >
> > While following California's laws may sound like a smart idea, and
> > it might be a smart idea, it's really difficult when a lot of
> > jurisdictions in the world want their share of the pie while
> > simultaneous proscribing the implementations of other jurisdictions.
> >
> > Here's a summary that I have compiled based on my readings of
> > various bills.
> >
> > CA =3D California (Passed)
> > CO =3D Colorado (Not yet passed)
> > NY =3D New York (Not yet passed)
> >
> > =3D=3D Age range =3D=3D
> > CA: Under 13, 13-16, 16-18, >18
> > CO: Under 13, 13-16, 16-18, >18
> > NY: Under 13, 13-16, 16-18, >18
> >
> > =3D=3D Availability =3D=3D
> > CA: All software
> > CO: All software
> > NY: All software
> >
> > =3D=3D Verification method =3D=3D
> > CA: Declaration
> > CO: Declaration
> > NY: Actual verification (how?, Contrast: CA CO Prohibited)
> >
> > =3D=3D Liability for tampering/incorrect input =3D=3D
> > CA: Restricted liability
> > CO: Semi-reduced liability
> > NY: Much less reduced liability
> >
> > =3D=3D Other weird requirements =3D=3D
> > NY: Encryption (??), Retroactively requesting info,
> > anticircumvention CA: Retroactively requesting info
> > CO: Retroactively requesting info
> >
> > =3D=3D Prohibited practises =3D=3D
> > CA: Collecting additional information (Contrast: NY Verification)
> > CO: Collecting additional information (Contrast: NY Verification)
> >
> > While some parts of existing bills do not contradict the bills of
> > other jurisdictions, other parts do, making implementation
> > difficult. A single implementation cannot accommodate both New York
> > and CA/CO.
> >
> > Also, how would an open source project implement this to NY
> > requirements if anyone can, I don't know, ``<packagemanager> remove
> > <ageverificationpackage>, or just rebuild their OS without whatever
> > script that does the age verification? =20
>=20


--Sig_/Ww8Xg89aE0p9=SB_rpcxq3X
Content-Type: application/pgp-signature
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQS8QsiCjFi4DcDBX+Q5rdye4jrrCAUCacM6FQAKCRA5rdye4jrr
CGeaAQCXXa4QhGndpp4vq8FXdps1a4qfLdlgoVUX+K27OcjKIAD+OTKhSygh648c
i9qWYM/+iAAlCYgGUHD2Gw4CVA5BDgo=
=9f90
-----END PGP SIGNATURE-----

--Sig_/Ww8Xg89aE0p9=SB_rpcxq3X--