Re: Minimal Implementation AB 1043 (California's Age Verification Bill)

Aaron Seigo <[email protected]> Tue, 3 Mar 2026 21:34:51 +0100
Newsgroups gmane.linux.xdg.devel
Message-ID <[email protected]>
Hi,

(Despite asking to have an off-list discussion... :/ )

Before diving into the details of your email, there is one point of 
agreement that is probably the sum of what is actually interesting:

On 3/3/26 15:45, Vanida Plamondon wrote:
 > I am not going to
 > argue against the tactic of geoblocking any jurisdiction that implements
 > this kind of law, because failing all else, this will likely be the most
 > effective way to protect one's self from these kinds of laws.

Agreed, 100%.

Let California and its people suffer under the consequences of their own 
laws.

Removing support for California is not only a good defense, it is one of 
the effective *offenses* available to most of us. Especially if one of 
our objectives is to discourage such idiocy from spreading elsewhere.

There is no reason for me to comply with their unreasonable demands that 
chip away at the rights of people everywhere, and every reason for me to 
do what I can to prevent this madness from expanding.


Second, I stand corrected on this matter:

 > the law also specifically calls out developers:>
>     1798.501. (b) (1) A developer shall request a signal with respect to
>     a particular user from an operating system provider or a covered
>     application store when the application is downloaded and launched.

Indeed, I missed that the penalties also apply to them.

What doesn't change is that California has zero legal standing with most 
free software developers, and for us that threat is meaningless.


[[ The rest of this email is additional thoughts on how this is being 
outrageously overreacted to, and why complying with this law at this 
time is a disservice to the world at large. Feel free to skip if you 
have other pressing things to do ;) ]]


So ... I do not distribute my free software to anyone in California. I 
do not have control of the software I write in the sense I can control 
where it goes, nor am I the owner of most of the free software I've 
contributed to. What few services I offer / run are done so on servers 
outside of California jurisdiction.

In short, California can pound sand.

An individual fetching free software I write of their own volition and 
importing it into California is their problem, not mine. This is no 
different to any other "contraband" that someone accesses out of state 
and then brings it back with them.

The ones who will be affected are commercial software distributors doing 
business in California. Those people are free to patch the software I've 
written that they distribute. They are also free not to distribute the 
software I've written. That is a choice for them to make.

> And provides a penalty for any person who violates any part of this law 
> (non-compliance):

They lack jurisdiction to enforce that on individuals who live and do 
their business elsewhere.

This was quite clearly written by someone thinking about the Apples, 
Googles, and Microsofts of the world, striving to design a legal lever 
that relies on their business models.

It isn't leverage upon myself, nor most other free software developers.

> There are approximately 8.4 million children in California, so the 
> penalty(s) called for are approximately $21 billion and $63 billion.

Besides being overjoyed if 8.4 million people in California were using 
software I contributed to ;) there is precisely zero chance that 
California would be able to levy such a penalty against me.

Let them try.

> Everybody involved needs to understand that if anyone, as a developer, 
> makes their software available to Californians, then you are affected, 

Good thing I'm not doing that, then!

Writing free software does not make me someone distributing software to 
Californians in California. If it is not legal for them to use the 
software I write, then they need to not do so.

I'm not encouraging or asking anyone in California to use applications 
that contains code I've written.

What I've written comes explicitly without warranty, by license 
agreement. Others may be distributing software I wrote, but they are 
doing so without my participation, express permission, or endorsement.

> and the state of California can hold you liable for violation(s) of 
> their law.

Thankfully, that's not how the law works.

As a non-US citizen / resident who is not working there or doing 
business within their meager borders, their laws mean literally nothing 
to me.

I realize that there are free software developers in California as well 
as people who do business related to open source software in California. 
They could find themselves exposed to the penalties of this law, should 
it go into effect.

But for the rest of us it means literally nothing.

On the flip side, appeasing this sort of insanity will only encourage 
other governments to play with similar (or worse) legal concepts. If we 
want to see this kind of idiocy go global, working to match California's 
  insane demands is how we get there.

The answer to this kind of law is to protest it, educate the lawmakers 
involved, and allow their people to suffer with their self-made problems.

> It is not important to discuss the limitations of to what 
> degree a state might be able to hold a foreign person liable, but 

It is critically important to acknowledge that California law has no 
applicability to most of us.

> foreigners can still be affected, either by a claim raised in that 
> person's locality, or by "domesticating" the U.S. judgment in the 
> relevant country.

The claim could be raised in my locality only if that same sort of law 
existed here. It doesn't.

Alternatively, the country I live could decide to enter into an 
international treaty that would recognize trans-national enforcement of 
this particular sort of law, similar to the various agreements covering 
e.g. copyright.

But until one of those two things happens, nope, doesn't affect me.

And if either of those things WERE proposed where I live, I would rally 
against it along with many of my fellow residents and citizens.

I have every interest in ensuring that our ability to do that remains 
strong, which starts by rallying against the absurd idea that this 
*foreign* law affects me in any way.

If we comply with this law, the rest of the world's governments will 
have a far shorter chasm to jump in order to contemplate bringing 
similar laws home.

The best defense against this kind of law spreading is non-compliance, 
increasing the cost and risk for any who would consider following their 
path, and strengthening the hands of those who are currently not under 
the shadows of this sort of governmental overreach.

> It seems I may have misspoken when I said "/these kinds of laws could 
> kill free software/", as I should have said that the purpose of these 
> kinds of laws is to try to kill free software.

I don't think that's the intent at all.

If it was, it's a pretty bad attempt as there is no *technical* barrier 
to free software complying.

In fact, conspiracy against free software makes a lot less sense than 
this law being a misguided attempt to protect children from the damaging 
onslaught of modern online media.

It being misguided is much more plausible than malice, and as such I 
doubt free software is the intended target.

> The problems these kinds 
> of laws can create has little to do with if they can or cannot kill free 
> software, but the chilling effect they are meant to have on motivating 
> developers to release software outside of conformant app stores. If 

I refuse to be chilled by it. I encourage others not to be chilled by 
it. And I will speak out against other people trying to encourage being 
chilled by it.

If there are developers who wish to comply with this, they certainly 
can. The source is there which they can patch to their heart's content. 
These are the great freedoms offered by free software, and also why it's 
important to defend it.

The effect of complying with laws such as these are ultimately 
detrimental to us all as it ultimately undermines the ability for people 
to choose how they use their own devices and software.

> You seem to think these kinds of laws are an authoritarianism and/or 
> fascism attack/problem against free software. It is not. It is a 
> capitalism attack/problem against free software.

I don't see it as an attack on free software at all.

I think it's a *risk* to free software and an attack on the human rights 
which free software exists to protect, namely to allow people to use 
technology on their own terms without constraint from others.

I don't think that's the *purpose* of this law, it's "just" collateral 
damage.

> I am also not trying to get free software enshittified.

I don't think it is your intent, but it would be the result.

> I am proposing 
> that the existing frameworks in free software, specifically *DAC* 
> (Discretionary Access Control), *MAC* (Mandatory Access Control), and 
> *LSM* (Linux Security Modules) be extended so that parents can actually 
> implement security policies to restrict and control what their children 
> can do on their computers.

That's a fine goal, truly!

Others have worked on that topic over the years, but to my knowledge 
there isn't an easy-to-use system for this. So .. go for it! Produce a 
great parental control system that people can opt into and use.

That's not, however, what is happening here.

This discussion is about forced compliance with a retrograde law in a 
jurisdiction separate from the ones most of us are beholden to.

We really aren't discussing parental controls here, but offering a 
random government the power to dictate everyone's usage of their 
personal computing and communications devices. Literally the opposite of 
the free software ethos.

 > You know, in the exact same way the owner of > a computer 
can restrict and control what other people can do on their
> computers.

You are confusing controlling what happens on your computer with me 
telling you what happens on your computer.

You must be free to use your computing and communications devices as you 
see fit, within the standard bounds of not causing harm to others.

This law is California telling all software distributors that they MUST 
tell people how to use their own devices. Not giving people more tools 
for using their own devices, but forcing them to use them in very 
specific ways.

I have no desire for free software to be a party to eroding such 
freedoms, including for those who happen to live in California.

> I am pointing out that by doing this, free software 
> developers universally protect themselves and all of the free software 
> community from any such kinds of laws like *AB 1043* by allowing parents 
> to implement security policies appropriate to their use case (parental 
> controls).

I have an alternate proposal:

A) build a great parental control system (awesome!)
B) reject these kinds of laws

We can do both.

> This would universally shield the free software from these kinds of 
> laws, because parental security policies just do what the law demands, 

No, they do not.

This law is requiring a specific age verification mechanism that is not 
optional and must be implemented by and forced upon every user.

Simply having a parental device system does not meet the requirements of 
this law. It needs to be the system prescribed by this particular law, 
and it needs to be forced on *everyone* in California.

> Also, and this is important, 
> parents gain powerful, effective tools (parental security policies) that 
> allows them to better *PARENT* their child, on their computer, and 
> eventually, online.

This is a separate issue. Having such a system would be great. It 
doesn't require an age verification "signal". It doesn't require an XDG 
standard. It doesn't require talking about requiring it in every 
application.

> I do not think it an undue burden to have to input 
> my age for this kind of functionality, and furthermore, for any 

You are free to think this, and to act on that. No argument.

What neither of us get to do is force that on others, nor require 
compliance with some random law that undermines the "free" in free software.

> jurisdiction not implementing these kinds of laws, this functionality 
> can be *DISABLED BY DEFAULT*, and *NO ONE NEED EVEN INPUT THEIR AGE IF 
> ANYONE DOES THINK SUCH IS AN UNREASONABLE BURDEN*.
That's cool.

And that can be done without claiming that every free software developer 
is at risk of getting sued for billions of dollars, or that it's a risk 
to free software, or that we need some carte-blanche requirement for 
this in free software systems.

Those who wish to implement parental controls can do so, and those who 
wish to use them can install and enable that software on their systems.

Everyone wins!

> I do not think I am being unreasonable by proposing a useful feature, 

That isn't the part that's unreasonable.

> that for most everyone in the world, doesn't affect them at all in any 
> way.

This is where you are, unfortunately, dangerously wrong.

If these age verification systems are plumbed into the free software 
ecosystem it makes it more likely that similar laws will be proposed in 
other jurisdictions, and that even more draconian laws will be proposed 
where such laws exist.

As I said in my earlier email: we also don't enforce social credit 
scoring, mandatory payment mechanisms, or ensure that free software can 
not be used to bypass censorship deployed by governments. All of those 
things also exist and are enforced by laws in one land or another.

The simple reason we do not plumb such things into the core of free 
software systems is that it is not our purview to do so. Moreover, they 
are actively hostile to the rights and freedoms of people who use and 
even rely on technology.

This does not stop countries from implementing those features 
themselves. They are free to do so. But that's their burden. Not ours. 
We do not need to become willing participants in our own demise.

So, yes, plumbing in the requirements expressed in this California bill 
*would* be affecting everyone in the world, by making us complicit in 
their short-sighted edict.

> When these kinds of laws are finally laid to rest, the only legacy 
> of such laws would be, like I already mentioned, parents having 
> powerful, effective tools (parental security policies) that allows them 
> to better parent their child.

The age verification requirements in the law in question are not a 
powerful, effective parental tool. I know what "power, effective 
parental security policies" look like, and this law isn't it.

I am a parent who carefully mediates the interactions my children have 
with computers and (especially) the internet. Me and my partner strive 
to educate them and discusses the issues openly with them. We even 
(shock!) use parental controls where available and sensible.

This isn't about parental controls.

If you and others go on to create a great free software parental control 
system that is easy to use and widely available, that would be a great 
thing. I have zero argument against that.

But let's not pretend that's what this is about.

This is about a pernicious law in one state in one country from a 
governmental body that is attempting to move the entire world of 
computing and communication in ways that are not in our best interests.

-- 
Aaron Seigo