Re: Minimal Implementation AB 1043 (California's Age Verification Bill)
Vanida Plamondon <[email protected]> Tue, 3 Mar 2026 07:45:53 -0700
| Newsgroups | gmane.linux.xdg.devel |
|---|---|
| Message-ID | <CAMm9xBz2on3JF7dYs2TxJX1sn9GwZqmvc3j-kWNLxXt9AZzdMQ@mail.gmail.com> |
--0000000000005cdee8064c1fc37c Content-Type: text/plain; charset="UTF-8" First of all, the law also specifically calls out developers: 1798.501. (b) (1) A developer shall request a signal with respect to a > particular user from an operating system provider or a covered application > store when the application is downloaded and launched. And provides a penalty for any person who violates any part of this law (non-compliance): 1798.503. (a) A person that violates this title shall be subject to an > injunction and liable for a civil penalty of not more than two thousand > five hundred dollars ($2,500) per affected child for each negligent > violation or not more than seven thousand five hundred dollars ($7,500) per > affected child for each intentional violation, which shall be assessed and > recovered only in a civil action brought in the name of the people of the > State of California by the Attorney General. There are approximately 8.4 million children in California, so the penalty(s) called for are approximately $21 billion and $63 billion. Everybody involved needs to understand that if anyone, as a developer, makes their software available to Californians, then you are affected, and the state of California can hold you liable for violation(s) of their law. It is not important to discuss the limitations of to what degree a state might be able to hold a foreign person liable, but foreigners can still be affected, either by a claim raised in that person's locality, or by "domesticating" the U.S. judgment in the relevant country. It seems I may have misspoken when I said "*these kinds of laws could kill free software*", as I should have said that the purpose of these kinds of laws is to try to kill free software. The problems these kinds of laws can create has little to do with if they can or cannot kill free software, but the chilling effect they are meant to have on motivating developers to release software outside of conformant app stores. If these kinds of laws come into effect, developers at such time(s) will need to take appropriate steps to protect themselves. I am not going to argue against the tactic of geoblocking any jurisdiction that implements this kind of law, because failing all else, this will likely be the most effective way to protect one's self from these kinds of laws. You seem to think these kinds of laws are an authoritarianism and/or fascism attack/problem against free software. It is not. It is a capitalism attack/problem against free software. These laws are all about existing app stores protecting and increasing their market power. I am also not trying to get free software enshittified. I am proposing that the existing frameworks in free software, specifically *DAC* (Discretionary Access Control), *MAC* (Mandatory Access Control), and *LSM* (Linux Security Modules) be extended so that parents can actually implement security policies to restrict and control what their children can do on their computers. You know, in the exact same way the owner of a computer can restrict and control what other people can do on their computers. I am pointing out that by doing this, free software developers universally protect themselves and all of the free software community from any such kinds of laws like *AB 1043* by allowing parents to implement security policies appropriate to their use case (parental controls). This would universally shield the free software from these kinds of laws, because parental security policies just do what the law demands, and implementing parental security policies would just have a high likelihood of foiling any other kind of legal attack made under the pretense of "protecting the children". Also, and this is important, parents gain powerful, effective tools (parental security policies) that allows them to better *PARENT* their child, on their computer, and eventually, online. I do not think it an undue burden to have to input my age for this kind of functionality, and furthermore, for any jurisdiction not implementing these kinds of laws, this functionality can be *DISABLED BY DEFAULT*, and *NO ONE NEED EVEN INPUT THEIR AGE IF ANYONE DOES THINK SUCH IS AN UNREASONABLE BURDEN*. I do not think I am being unreasonable by proposing a useful feature, that for most everyone in the world, doesn't affect them at all in any way. When these kinds of laws are finally laid to rest, the only legacy of such laws would be, like I already mentioned, parents having powerful, effective tools (parental security policies) that allows them to better parent their child. On Tue, 3 Mar 2026 at 05:53, Aaron Seigo <[email protected]> wrote: > Hi Vanida, > > I'm replying off-list in hopes of deescalation, which contributing to > long public threads often does not help with :) > > First, let me say that I appreciate people like yourself caring enough > about free software to take the time to think about how to address > potential problems and threats to the ecosystem. > > On 2026-03-03 04:06, Vanida Plamondon wrote: > > scope of this kind of law. In other words, every single piece of free > > software in the world > > falls under the scope of this kind of law. If you make software, even > > if it's only in source > > code form, and it's publicly available, your software falls under the > > scope of this kind of law. > > That is categorically untrue. This (bad) law applies to app stores and > "operating system providers", which are terms this otherwise poorly > conceived law actually defines quite clearly. > > As someone who is not an operating system provider, nor running an app > store, nor distributing any software whatsoever in California, none of > this would apply to me or any of my free software. > > There is also no jurisdiction within which California could enforce such > a thing upon my person, given that I have no business in California, no > legal footprint in California, and their laws are not enforceable where > I live. > > They can shout into the void all they wish, it doesn't impact myself, > nor the vast, vast majority of free software developers. > > The law is a bad, stupid, dangerous idea, but it is not a broad legal > threat to all free software or free software developers and > contributors. > > > The problem is that these kinds of laws could kill free software, > > because it is essentially > > impossible for any particular software developer to conform to the law. > > I have good news that hopefully will resolve some of your angst over > this matter: this kind of law can not kill free software! > > At worst, such laws could dramatically change / hurt how free software > is currently distributed, but they would not "kill" free software. > > For it to even get to that point, however, these laws would need to > become widespread. Thankfully, outside of countries with oppressive > anti-freedom governments, that is quite unlikely. > > In the case of California, it does look likely that this law will > undergo reconsideration. Hopefully all the noise around it sinks it > properly. But even if this law stands and is enforced, it will only > effect software being distributed by operating system vendors and app > store owners *into* California. Most free software developers couldn't > care one bit about that. > > Injecting personally invasive anti-freedom technologies into the free > software ecosystem would be doing these people's work for them. Toeing > this particular line is forging a path of cooperation and complicity > that such lawmakers are actively trying to create. If this law stands > and is enforced, other laws follow that take the next steps towards > removing people's rights to their own property, privacy, and expression. > > Once California lawmakers figure out that these kinds of "age > verification" systems do not actually work, they will try to "fix" that > by writing laws requiring even more invasive measures and more lockdown > of tech. > > Countries such as China and North Korea have extensive draconian laws > defining the allowed use of technology, privacy, identity, etc. and yet > even under those conditions free software abounds. Imagine if the free > software world decided that social score tracking and enforcement of > national "firewalls" was necessary to avoid coming under legal threat in > China! It's the same deal with this California law. > > So let's not be part of the problem. Let's not try to figure out how to > export these bad ideas to all users of free software in the world. Let's > not willingly enshitify free software. > > -- > Aaron Seigo > --0000000000005cdee8064c1fc37c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>First of all, the law also specifically calls out dev= elopers:</div><div><br></div><blockquote class=3D"gmail_quote" style=3D"mar= gin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1= ex">1798.501. (b) (1) A developer shall request a signal with respect to a = particular user from an operating system provider or a covered application = store when the application is downloaded and launched.</blockquote><div><br= ></div><div>And provides a penalty for any person who violates any part of = this law (non-compliance):</div><div><br></div><blockquote class=3D"gmail_q= uote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,2= 04);padding-left:1ex">1798.503. (a) A person that violates this title shall= be subject to an injunction and liable for a civil penalty of not more tha= n two thousand five hundred dollars ($2,500) per affected child for each ne= gligent violation or not more than seven thousand five hundred dollars ($7,= 500) per affected child for each intentional violation, which shall be asse= ssed and recovered only in a civil action brought in the name of the people= of the State of California by the Attorney General.</blockquote><div><br><= /div><div>There are approximately 8.4 million children in California, so th= e penalty(s) called for are approximately $21 billion and $63 billion. Ever= ybody involved needs to understand that if anyone, as a developer, makes th= eir software available to Californians, then you are affected, and the stat= e of California can hold you liable for violation(s) of their law. It is no= t important to discuss the limitations of to what degree a state might be a= ble to hold a foreign person liable, but foreigners can still be affected, = either by a claim raised in that person's locality, or by=C2=A0"do= mesticating" the U.S. judgment in the relevant country.</div><div><br>= </div><div>It seems I may have misspoken when I said "<i>these kinds o= f laws could kill free software</i>", as I should have said that the p= urpose of these kinds of laws is to try to kill free software. The problems= these kinds of laws can create has little to do with if they can or cannot= kill free software, but the chilling effect they are meant to have on moti= vating developers to release software outside of conformant app stores. If = these kinds of laws come into effect, developers at such time(s) will need = to take appropriate steps to protect themselves. I am not going to argue ag= ainst the tactic of geoblocking any jurisdiction that implements this kind = of law, because failing all else, this will likely be the most effective wa= y to protect one's self from these kinds of laws.</div><div><br></div><= div>You seem to think these kinds of laws are an authoritarianism and/or fa= scism attack/problem against free software. It is not. It is a capitalism= =C2=A0attack/problem against free software. These laws are all about existi= ng app stores protecting and increasing their market power.</div><div><br><= /div><div>I am also=C2=A0not trying to get free software enshittified. I am= proposing that the existing frameworks in free software, specifically=C2= =A0<b>DAC</b> (Discretionary Access Control),=C2=A0<b>MAC</b> (Mandatory Ac= cess Control), and=C2=A0<b>LSM</b> (Linux Security Modules) be extended so = that parents can actually implement security policies to restrict and contr= ol what their children can do on their computers. You know, in the exact sa= me way the owner of a computer can=C2=A0restrict and control what other=C2= =A0people can do on their computers. I am pointing out that by doing this, = free software developers universally protect themselves and all of the free= software community from any such kinds of laws like <b>AB 1043</b> by allo= wing parents to implement security policies appropriate to their use case (= parental controls).</div><div><br></div><div>This would universally shield = the free software from these kinds of laws, because parental security polic= ies just do what the law demands, and implementing parental security polici= es would just have a high likelihood of foiling any other kind of legal att= ack made under the pretense of "protecting the children". Also, a= nd this is important, parents gain powerful, effective tools (parental secu= rity policies) that allows them to better <b>PARENT</b> their child, on the= ir computer, and eventually, online. I do not think it an undue burden to h= ave to input my age for this kind of functionality, and furthermore, for an= y jurisdiction not implementing these kinds of laws, this functionality can= be <b>DISABLED BY DEFAULT</b>, and <b>NO ONE NEED EVEN INPUT THEIR AGE IF = ANYONE DOES THINK SUCH IS AN UNREASONABLE BURDEN</b>.</div><div><br></div><= div>I do not think I am being unreasonable by proposing a useful feature, t= hat for most everyone in the world, doesn't affect them at all in any w= ay. When these kinds of laws are finally laid to rest, the only legacy of s= uch laws would be, like I already mentioned,=C2=A0parents having powerful, = effective tools (parental security policies) that allows them to better par= ent their child.</div></div><br><div class=3D"gmail_quote gmail_quote_conta= iner"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, 3 Mar 2026 at 05:53, Aa= ron Seigo <<a href=3D"mailto:[email protected]">[email protected]</a>&= gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0= px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi Va= nida,<br> <br> I'm replying off-list in hopes of deescalation, which contributing to <= br> long public threads often does not help with :)<br> <br> First, let me say that I appreciate people like yourself caring enough <br> about free software to take the time to think about how to address <br> potential problems and threats to the ecosystem.<br> <br> On 2026-03-03 04:06, Vanida Plamondon wrote:<br> > scope of this kind of law. In other words, every single piece of free = <br> > software in the world<br> > falls under the scope of this kind of law. If you make software, even = <br> > if it's only in source<br> > code form, and it's publicly available, your software falls under = the <br> > scope of this kind of law.<br> <br> That is categorically untrue. This (bad) law applies to app stores and <br> "operating system providers", which are terms this otherwise poor= ly <br> conceived law actually defines quite clearly.<br> <br> As someone who is not an operating system provider, nor running an app <br> store, nor distributing any software whatsoever in California, none of <br> this would apply to me or any of my free software.<br> <br> There is also no jurisdiction within which California could enforce such <b= r> a thing upon my person, given that I have no business in California, no <br= > legal footprint in California, and their laws are not enforceable where <br= > I live.<br> <br> They can shout into the void all they wish, it doesn't impact myself, <= br> nor the vast, vast majority of free software developers.<br> <br> The law is a bad, stupid, dangerous idea, but it is not a broad legal <br> threat to all free software or free software developers and <br> contributors.<br> <br> > The problem is that these kinds of laws could kill free software, <br> > because it is essentially<br> > impossible for any particular software developer to conform to the law= .<br> <br> I have good news that hopefully will resolve some of your angst over <br> this matter: this kind of law can not kill free software!<br> <br> At worst, such laws could dramatically change / hurt how free software <br> is currently distributed, but they would not "kill" free software= .<br> <br> For it to even get to that point, however, these laws would need to <br> become widespread. Thankfully, outside of countries with oppressive <br> anti-freedom governments, that is quite unlikely.<br> <br> In the case of California, it does look likely that this law will <br> undergo reconsideration. Hopefully all the noise around it sinks it <br> properly. But even if this law stands and is enforced, it will only <br> effect software being distributed by operating system vendors and app <br> store owners *into* California. Most free software developers couldn't = <br> care one bit about that.<br> <br> Injecting personally invasive anti-freedom technologies into the free <br> software ecosystem would be doing these people's work for them. Toeing = <br> this particular line is forging a path of cooperation and complicity <br> that such lawmakers are actively trying to create. If this law stands <br> and is enforced, other laws follow that take the next steps towards <br> removing people's rights to their own property, privacy, and expression= .<br> <br> Once California lawmakers figure out that these kinds of "age <br> verification" systems do not actually work, they will try to "fix= " that <br> by writing laws requiring even more invasive measures and more lockdown <br= > of tech.<br> <br> Countries such as China and North Korea have extensive draconian laws <br> defining the allowed use of technology, privacy, identity, etc. and yet <br= > even under those conditions free software abounds. Imagine if the free <br> software world decided that social score tracking and enforcement of <br> national "firewalls" was necessary to avoid coming under legal th= reat in <br> China! It's the same deal with this California law.<br> <br> So let's not be part of the problem. Let's not try to figure out ho= w to <br> export these bad ideas to all users of free software in the world. Let'= s <br> not willingly enshitify free software.<br> <br> -- <br> Aaron Seigo<br> </blockquote></div> --0000000000005cdee8064c1fc37c--