Re: On the unfortunate need for an "age verification" API for legal compliance reasons in some U.S. states

Tomáš Zíma <[email protected]> Sun, 1 Mar 2026 21:51:15 +0100
Newsgroups gmane.linux.ubuntu.devel,gmane.linux.xdg.devel,gmane.linux.redhat.fedora.devel,gmane.linux.debian.devel.general,gmane.linux.debian.devel.legal,gmane.linux.redhat.fedora.legal
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============0177720931455025115==
Content-Type: multipart/alternative;
 boundary="------------ywKZU0y03IzzIV08a4qAa0IH"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------ywKZU0y03IzzIV08a4qAa0IH
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

> A root-owned file won't be accessible to sandboxed applications such as Firefox running under Flatpak.

I would imagine something like this:

1. Extend adduser to ask for the user's date of birth. (GUI installers/tool would have to ask for this extra field too.)
2. Generate root-owned file containing the birth day, as suggested.
3. Regenerate a root-owned, user-readable (non-writeable) file containing the user's "age bracket" once per day via cron. The path & its format (e.g. "UNDER_13") would be the API. Alternatively, to make it more portable, a script get-age-bracket could be provided.
4. Making the file/script available to sandboxes is a matter of configuration.

I don't think XDG is a good place to implement this.

PS: While I think introducing some *optional* tools to make it easier for parents to set up some parental controls is a good thing, I don't support the legislation. Based on quick reading of the Californian bill (not a lawyer, not a native speaker), I think it would actually affect the root/admin user too, which leads to absurd results on Unix-like systems, among many other flaws. Not providing the OS at all for such jurisdictions would be the preferred course of action in my eyes, but I understand that's sadly not a practical option for many.

--------------ywKZU0y03IzzIV08a4qAa0IH
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <pre>&gt; A root-owned file won't be accessible to sandboxed applications such as Firefox running under Flatpak.</pre>
    <pre>I would imagine something like this:</pre>
    <pre>1. Extend adduser to ask for the user's date of birth. (GUI installers/tool would have to ask for this extra field too.)
2. Generate root-owned file containing the birth day, as suggested.
3. Regenerate a root-owned, user-readable (non-writeable) file containing the user's "age bracket" once per day via cron. The path &amp; its format (e.g. "UNDER_13") would be the API. Alternatively, to make it more portable, a script get-age-bracket could be provided.
4. Making the file/script available to sandboxes is a matter of configuration.

I don't think XDG is a good place to implement this.

PS: While I think introducing some *optional* tools to make it easier for parents to set up some parental controls is a good thing, I don't support the legislation. Based on quick reading of the Californian bill (not a lawyer, not a native speaker), I think it would actually affect the root/admin user too, which leads to absurd results on Unix-like systems, among many other flaws. Not providing the OS at all for such jurisdictions would be the preferred course of action in my eyes, but I understand that's sadly not a practical option for many.

</pre>
  </body>
</html>

--------------ywKZU0y03IzzIV08a4qAa0IH--


--===============0177720931455025115==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1kZXZlbCBtYWlsaW5nIGxpc3QKdWJ1bnR1LWRldmVsQGxpc3RzLnVidW50dS5j
b20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJlIGF0OiBodHRwczovL2xpc3RzLnVidW50
dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtZGV2ZWwK

--===============0177720931455025115==--