Re: On the unfortunate need for an "age verification" API for legal compliance reasons in some U.S. states
Toni Mueller <[email protected]> Mon, 6 Apr 2026 16:42:12 +0100
| Newsgroups | gmane.linux.debian.devel.legal,gmane.linux.debian.devel.general |
|---|---|
| Message-ID | <hiyfxizjkcdp6yxpycen5jvovuiyzuzatkuh76bumxnu5i3cl5@ckmcatbnzk2g> |
--ydcc7aslclysdaro Content-Type: text/plain; protected-headers=v1; charset=us-ascii Content-Disposition: inline Subject: Re: On the unfortunate need for an "age verification" API for legal compliance reasons in some U.S. states MIME-Version: 1.0 On Sun, Mar 01, 2026 at 02:48:00PM -0500, Aaron Rainbolt wrote: > Given that this is related to legal stuff, I should preface this by > saying I am not a lawyer. I am also not a lawyer. > Recently, a new law was passed in California that requires OS vendors > to provide some limited info about a user's age via an API that > application distribution websites and application stores can use. [1] In my opinion, we should absolutely refuse to comply with any such legal requirements. It's not us who are discriminating against anyone by not complying with such laws, it's those legislatures preventing their citizens from using Free Software. Making an attempt to comply is imho fraught with peril, because not only will every other wannabe dictator find a way to make a claim, these claims will also contradict, fracturing the landscape and making it impossible to comply with all of them at the same time. Furthermore, it will open us up to increased liability. Think back to when PGP was invented and strong encryption was basically prescribed. Want to see the age of Clipper chips, PGP denials, or any random set of backdoors come back? Also, look across the border: This is not purely a US problem. France used to ban strong encryption (I don't know about the current situation), some Middle Eastern countries have long longed for backdoors into the system (wasn't it the UAE which tried to infect every passer-by on the airport with some OTA delivered spyware?), as have your favourite other governments (Russia, China, NK etc.). If we spend effort to accommodate these kinds of people, we can probably just trash the entire system, or at least, we'll be way too busy doing anything of substance for actual users. We're also handing the governments a switch to deny people using their own devices, thus reducing Free Software to just "free as in free beer" software, instead of "free as in freedom" software. IOW, we'd be reducing ourselves to mostly unpaid programming slaves, building our own prisons. Yes, you can read some distrust against governments from this statement, and I think it's not any better (maybe also not worse) than having large corporations doing the same thing with classic proprietary software, forced use of online accounts in their central systems etc. Instead, I suggest that we stay the course and let California and Colorado fall on their own swords when Linux suddenly becomes unusable, due to legal reasons (think of eg. all the IOT devices running with Linux), then understanding that the law needs to be changed. Cheers, Toni --ydcc7aslclysdaro Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEHfahn8pT+XNT8/NdigpIh0aHr08FAmnT1FAACgkQigpIh0aH r0+lKw/9FUopeBqN+7qYnrwz92rTy/ptqq/565S5LWPuF+uuQKMhR9C9Qgv5Cixg R9ysXktu29RuuTr1nEIe03UqsDWUKYQ39OEdy00XVfNKR0TkFCnEN5w7tR6G7DVe h8iVbbDJaDCKSr5AwBZaBDraBRS00OUvl7lzXddkwoEvyz0RXV7xKHxxYi3TCX9k AbAoWPFr/1dpR4rhdcUfqSWnnrCAQeZ0kiuIXAnZPPGc2Lt5JXXrnumdL3WHacGe IPmui20ZkxQshi7f0EYsfc7oKYLN7zhVHFR5SNw1LgrI593J1K8J/8s6MjmD5tIY rFGSI5B5ockpSiFFdRrS76LGUcfkbEMURY1vqfab3bWTHC/PsHmrDXCmXnOJlFL/ cTbT02slwBuJ8fiOGAQggYap4kdLUwLhIcF55uH3o2B4jX3H5FOVo+iePiXlZhpQ V4cRJCEgXL4aTgO/pwoRbVBKdwq2E26GGTcih+oeuJPN7m8u1KZKPZwXj/jEQCPp COOWjmXmpLCTphBaN3RBUbyCJ6ZS4dOK4cpJ/IWBF8nl3XPXe70Kyno68NROzrP2 YNvq3h5LCoiVpTbj3KqPoA9aoI3oV2ze76fBUrV74TM5fffB9tDmfUGGhtLEfoRw 4cysW+S16yHVeLXJV8VTTEPEcR4WX4LSNMFduv/zLBTrLUTRZpQ= =fpFh -----END PGP SIGNATURE----- --ydcc7aslclysdaro--