Re: On the unfortunate need for an "age verification" API for legal compliance reasons in some U.S. states

Toni Mueller <[email protected]> Mon, 6 Apr 2026 16:42:12 +0100
Newsgroups gmane.linux.debian.devel.legal,gmane.linux.debian.devel.general
Message-ID <hiyfxizjkcdp6yxpycen5jvovuiyzuzatkuh76bumxnu5i3cl5@ckmcatbnzk2g>
--ydcc7aslclysdaro
Content-Type: text/plain; protected-headers=v1; charset=us-ascii
Content-Disposition: inline
Subject: Re: On the unfortunate need for an "age verification" API for legal
 compliance reasons in some U.S. states
MIME-Version: 1.0

On Sun, Mar 01, 2026 at 02:48:00PM -0500, Aaron Rainbolt wrote:
> Given that this is related to legal stuff, I should preface this by
> saying I am not a lawyer.

I am also not a lawyer.

> Recently, a new law was passed in California that requires OS vendors
> to provide some limited info about a user's age via an API that
> application distribution websites and application stores can use. [1]

In my opinion, we should absolutely refuse to comply with any such legal
requirements. It's not us who are discriminating against anyone by not
complying with such laws, it's those legislatures preventing their
citizens from using Free Software. Making an attempt to comply is imho
fraught with peril, because not only will every other wannabe dictator
find a way to make a claim, these claims will also contradict,
fracturing the landscape and making it impossible to comply with all of
them at the same time. Furthermore, it will open us up to increased
liability. Think back to when PGP was invented and strong encryption was
basically prescribed. Want to see the age of Clipper chips, PGP denials,
or any random set of backdoors come back? Also, look across the border:
This is not purely a US problem. France used to ban strong encryption (I
don't know about the current situation), some Middle Eastern countries
have long longed for backdoors into the system (wasn't it the UAE which
tried to infect every passer-by on the airport with some OTA delivered
spyware?), as have your favourite other governments (Russia, China, NK
etc.). If we spend effort to accommodate these kinds of people, we can
probably just trash the entire system, or at least, we'll be way too
busy doing anything of substance for actual users. We're also handing
the governments a switch to deny people using their own devices, thus
reducing Free Software to just "free as in free beer" software, instead
of "free as in freedom" software. IOW, we'd be reducing ourselves to
mostly unpaid programming slaves, building our own prisons. Yes, you can
read some distrust against governments from this statement, and I think
it's not any better (maybe also not worse) than having large
corporations doing the same thing with classic proprietary software,
forced use of online accounts in their central systems etc.

Instead, I suggest that we stay the course and let California and
Colorado fall on their own swords when Linux suddenly becomes unusable,
due to legal reasons (think of eg. all the IOT devices running with
Linux), then understanding that the law needs to be changed.


Cheers,
Toni


--ydcc7aslclysdaro
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEHfahn8pT+XNT8/NdigpIh0aHr08FAmnT1FAACgkQigpIh0aH
r0+lKw/9FUopeBqN+7qYnrwz92rTy/ptqq/565S5LWPuF+uuQKMhR9C9Qgv5Cixg
R9ysXktu29RuuTr1nEIe03UqsDWUKYQ39OEdy00XVfNKR0TkFCnEN5w7tR6G7DVe
h8iVbbDJaDCKSr5AwBZaBDraBRS00OUvl7lzXddkwoEvyz0RXV7xKHxxYi3TCX9k
AbAoWPFr/1dpR4rhdcUfqSWnnrCAQeZ0kiuIXAnZPPGc2Lt5JXXrnumdL3WHacGe
IPmui20ZkxQshi7f0EYsfc7oKYLN7zhVHFR5SNw1LgrI593J1K8J/8s6MjmD5tIY
rFGSI5B5ockpSiFFdRrS76LGUcfkbEMURY1vqfab3bWTHC/PsHmrDXCmXnOJlFL/
cTbT02slwBuJ8fiOGAQggYap4kdLUwLhIcF55uH3o2B4jX3H5FOVo+iePiXlZhpQ
V4cRJCEgXL4aTgO/pwoRbVBKdwq2E26GGTcih+oeuJPN7m8u1KZKPZwXj/jEQCPp
COOWjmXmpLCTphBaN3RBUbyCJ6ZS4dOK4cpJ/IWBF8nl3XPXe70Kyno68NROzrP2
YNvq3h5LCoiVpTbj3KqPoA9aoI3oV2ze76fBUrV74TM5fffB9tDmfUGGhtLEfoRw
4cysW+S16yHVeLXJV8VTTEPEcR4WX4LSNMFduv/zLBTrLUTRZpQ=
=fpFh
-----END PGP SIGNATURE-----

--ydcc7aslclysdaro--