Re: On the unfortunate need for an "age verification" API for legal compliance reasons in some U.S. states

Aaron Rainbolt <[email protected]> Sun, 1 Mar 2026 16:08:37 -0500
Newsgroups gmane.linux.ubuntu.devel,gmane.linux.redhat.fedora.devel,gmane.linux.debian.devel.general,gmane.linux.debian.devel.legal,gmane.linux.xdg.devel,gmane.linux.redhat.fedora.legal
Message-ID <[email protected]>
--===============2384813053237171524==
Content-Type: multipart/signed; boundary="Sig_/zRYzHFF1s_7y3EiyLS==d0B";
 protocol="application/pgp-signature"; micalg=pgp-sha512

--Sig_/zRYzHFF1s_7y3EiyLS==d0B
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On Sun, 1 Mar 2026 21:51:15 +0100
Tom=C3=A1=C5=A1 Z=C3=ADma <[email protected]> wrote:

> >=C2=A0A root-owned file won't be accessible to sandboxed applications
> >such as Firefox running under Flatpak. =20
>=20
> I would imagine something like this:
>=20
> 1. Extend adduser=C2=A0to ask for the user's date of birth. (GUI
> installers/tool would have to ask for this extra field too.) 2.
> Generate root-owned file containing the birth day, as suggested.

This would be somewhat problematic for custom implementations that want
to avoid storing the user's real date of birth and store only the age
bracket. Whonix would want to do this for anti-fingerprinting purposes.
I suppose the root-owned file could be generated with a static age
bracket and the date of birth field could be empty. Then the cron job
would simply skip updating the bracket if the date-of-birth field was
empty.

> 3. Regenerate a root-owned, user-readable (non-writeable) file
> containing the user's "age bracket" once per day via cron. The path &
> its format (e.g. "UNDER_13") would be the API. Alternatively, to make
> it more portable, a script get-age-bracket could be provided. 4.
> Making the file/script available to sandboxes is a matter of
> configuration.
>=20
> I don't think XDG is a good place to implement this.

My main motivation for proposing that this be done in XDG is to make an
effort to make something that can be adopted more-or-less widely in the
end. It's definitely true that every OS could implement something
semi-bespoke like suggested here (or maybe this mechanism could end up
the standard). Personally I'd be perfectly happy with that solution,
but I don't think that's what the people who drafted the bill had in
mind when they wrote it, and I'd like for Whonix to not come under fire
for doing things "the wrong way". Even if ultimately no one wants a
standardized solution, we can say we tried.

--
Aaron

--Sig_/zRYzHFF1s_7y3EiyLS==d0B
Content-Type: application/pgp-signature
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQS8QsiCjFi4DcDBX+Q5rdye4jrrCAUCaaSq1QAKCRA5rdye4jrr
CMlEAQCDi0mfVGg+d2Zf7fpazyYLxZMaZr6qF1IEhfFXAXUtvwEArmpv4jGTi7ub
O+UqlQenqXdIO6IjEsvPWFw3ER4/Tw8=
=NPCv
-----END PGP SIGNATURE-----

--Sig_/zRYzHFF1s_7y3EiyLS==d0B--


--===============2384813053237171524==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1kZXZlbCBtYWlsaW5nIGxpc3QKdWJ1bnR1LWRldmVsQGxpc3RzLnVidW50dS5j
b20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJlIGF0OiBodHRwczovL2xpc3RzLnVidW50
dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtZGV2ZWwK

--===============2384813053237171524==--