Re: Minimal Implementation AB 1043 (California's Age Verification Bill)
Aaron Seigo <[email protected]> Tue, 3 Mar 2026 21:34:51 +0100
| Newsgroups | gmane.linux.xdg.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, (Despite asking to have an off-list discussion... :/ ) Before diving into the details of your email, there is one point of agreement that is probably the sum of what is actually interesting: On 3/3/26 15:45, Vanida Plamondon wrote: > I am not going to > argue against the tactic of geoblocking any jurisdiction that implements > this kind of law, because failing all else, this will likely be the most > effective way to protect one's self from these kinds of laws. Agreed, 100%. Let California and its people suffer under the consequences of their own laws. Removing support for California is not only a good defense, it is one of the effective *offenses* available to most of us. Especially if one of our objectives is to discourage such idiocy from spreading elsewhere. There is no reason for me to comply with their unreasonable demands that chip away at the rights of people everywhere, and every reason for me to do what I can to prevent this madness from expanding. Second, I stand corrected on this matter: > the law also specifically calls out developers:> > 1798.501. (b) (1) A developer shall request a signal with respect to > a particular user from an operating system provider or a covered > application store when the application is downloaded and launched. Indeed, I missed that the penalties also apply to them. What doesn't change is that California has zero legal standing with most free software developers, and for us that threat is meaningless. [[ The rest of this email is additional thoughts on how this is being outrageously overreacted to, and why complying with this law at this time is a disservice to the world at large. Feel free to skip if you have other pressing things to do ;) ]] So ... I do not distribute my free software to anyone in California. I do not have control of the software I write in the sense I can control where it goes, nor am I the owner of most of the free software I've contributed to. What few services I offer / run are done so on servers outside of California jurisdiction. In short, California can pound sand. An individual fetching free software I write of their own volition and importing it into California is their problem, not mine. This is no different to any other "contraband" that someone accesses out of state and then brings it back with them. The ones who will be affected are commercial software distributors doing business in California. Those people are free to patch the software I've written that they distribute. They are also free not to distribute the software I've written. That is a choice for them to make. > And provides a penalty for any person who violates any part of this law > (non-compliance): They lack jurisdiction to enforce that on individuals who live and do their business elsewhere. This was quite clearly written by someone thinking about the Apples, Googles, and Microsofts of the world, striving to design a legal lever that relies on their business models. It isn't leverage upon myself, nor most other free software developers. > There are approximately 8.4 million children in California, so the > penalty(s) called for are approximately $21 billion and $63 billion. Besides being overjoyed if 8.4 million people in California were using software I contributed to ;) there is precisely zero chance that California would be able to levy such a penalty against me. Let them try. > Everybody involved needs to understand that if anyone, as a developer, > makes their software available to Californians, then you are affected, Good thing I'm not doing that, then! Writing free software does not make me someone distributing software to Californians in California. If it is not legal for them to use the software I write, then they need to not do so. I'm not encouraging or asking anyone in California to use applications that contains code I've written. What I've written comes explicitly without warranty, by license agreement. Others may be distributing software I wrote, but they are doing so without my participation, express permission, or endorsement. > and the state of California can hold you liable for violation(s) of > their law. Thankfully, that's not how the law works. As a non-US citizen / resident who is not working there or doing business within their meager borders, their laws mean literally nothing to me. I realize that there are free software developers in California as well as people who do business related to open source software in California. They could find themselves exposed to the penalties of this law, should it go into effect. But for the rest of us it means literally nothing. On the flip side, appeasing this sort of insanity will only encourage other governments to play with similar (or worse) legal concepts. If we want to see this kind of idiocy go global, working to match California's insane demands is how we get there. The answer to this kind of law is to protest it, educate the lawmakers involved, and allow their people to suffer with their self-made problems. > It is not important to discuss the limitations of to what > degree a state might be able to hold a foreign person liable, but It is critically important to acknowledge that California law has no applicability to most of us. > foreigners can still be affected, either by a claim raised in that > person's locality, or by "domesticating" the U.S. judgment in the > relevant country. The claim could be raised in my locality only if that same sort of law existed here. It doesn't. Alternatively, the country I live could decide to enter into an international treaty that would recognize trans-national enforcement of this particular sort of law, similar to the various agreements covering e.g. copyright. But until one of those two things happens, nope, doesn't affect me. And if either of those things WERE proposed where I live, I would rally against it along with many of my fellow residents and citizens. I have every interest in ensuring that our ability to do that remains strong, which starts by rallying against the absurd idea that this *foreign* law affects me in any way. If we comply with this law, the rest of the world's governments will have a far shorter chasm to jump in order to contemplate bringing similar laws home. The best defense against this kind of law spreading is non-compliance, increasing the cost and risk for any who would consider following their path, and strengthening the hands of those who are currently not under the shadows of this sort of governmental overreach. > It seems I may have misspoken when I said "/these kinds of laws could > kill free software/", as I should have said that the purpose of these > kinds of laws is to try to kill free software. I don't think that's the intent at all. If it was, it's a pretty bad attempt as there is no *technical* barrier to free software complying. In fact, conspiracy against free software makes a lot less sense than this law being a misguided attempt to protect children from the damaging onslaught of modern online media. It being misguided is much more plausible than malice, and as such I doubt free software is the intended target. > The problems these kinds > of laws can create has little to do with if they can or cannot kill free > software, but the chilling effect they are meant to have on motivating > developers to release software outside of conformant app stores. If I refuse to be chilled by it. I encourage others not to be chilled by it. And I will speak out against other people trying to encourage being chilled by it. If there are developers who wish to comply with this, they certainly can. The source is there which they can patch to their heart's content. These are the great freedoms offered by free software, and also why it's important to defend it. The effect of complying with laws such as these are ultimately detrimental to us all as it ultimately undermines the ability for people to choose how they use their own devices and software. > You seem to think these kinds of laws are an authoritarianism and/or > fascism attack/problem against free software. It is not. It is a > capitalism attack/problem against free software. I don't see it as an attack on free software at all. I think it's a *risk* to free software and an attack on the human rights which free software exists to protect, namely to allow people to use technology on their own terms without constraint from others. I don't think that's the *purpose* of this law, it's "just" collateral damage. > I am also not trying to get free software enshittified. I don't think it is your intent, but it would be the result. > I am proposing > that the existing frameworks in free software, specifically *DAC* > (Discretionary Access Control), *MAC* (Mandatory Access Control), and > *LSM* (Linux Security Modules) be extended so that parents can actually > implement security policies to restrict and control what their children > can do on their computers. That's a fine goal, truly! Others have worked on that topic over the years, but to my knowledge there isn't an easy-to-use system for this. So .. go for it! Produce a great parental control system that people can opt into and use. That's not, however, what is happening here. This discussion is about forced compliance with a retrograde law in a jurisdiction separate from the ones most of us are beholden to. We really aren't discussing parental controls here, but offering a random government the power to dictate everyone's usage of their personal computing and communications devices. Literally the opposite of the free software ethos. > You know, in the exact same way the owner of > a computer can restrict and control what other people can do on their > computers. You are confusing controlling what happens on your computer with me telling you what happens on your computer. You must be free to use your computing and communications devices as you see fit, within the standard bounds of not causing harm to others. This law is California telling all software distributors that they MUST tell people how to use their own devices. Not giving people more tools for using their own devices, but forcing them to use them in very specific ways. I have no desire for free software to be a party to eroding such freedoms, including for those who happen to live in California. > I am pointing out that by doing this, free software > developers universally protect themselves and all of the free software > community from any such kinds of laws like *AB 1043* by allowing parents > to implement security policies appropriate to their use case (parental > controls). I have an alternate proposal: A) build a great parental control system (awesome!) B) reject these kinds of laws We can do both. > This would universally shield the free software from these kinds of > laws, because parental security policies just do what the law demands, No, they do not. This law is requiring a specific age verification mechanism that is not optional and must be implemented by and forced upon every user. Simply having a parental device system does not meet the requirements of this law. It needs to be the system prescribed by this particular law, and it needs to be forced on *everyone* in California. > Also, and this is important, > parents gain powerful, effective tools (parental security policies) that > allows them to better *PARENT* their child, on their computer, and > eventually, online. This is a separate issue. Having such a system would be great. It doesn't require an age verification "signal". It doesn't require an XDG standard. It doesn't require talking about requiring it in every application. > I do not think it an undue burden to have to input > my age for this kind of functionality, and furthermore, for any You are free to think this, and to act on that. No argument. What neither of us get to do is force that on others, nor require compliance with some random law that undermines the "free" in free software. > jurisdiction not implementing these kinds of laws, this functionality > can be *DISABLED BY DEFAULT*, and *NO ONE NEED EVEN INPUT THEIR AGE IF > ANYONE DOES THINK SUCH IS AN UNREASONABLE BURDEN*. That's cool. And that can be done without claiming that every free software developer is at risk of getting sued for billions of dollars, or that it's a risk to free software, or that we need some carte-blanche requirement for this in free software systems. Those who wish to implement parental controls can do so, and those who wish to use them can install and enable that software on their systems. Everyone wins! > I do not think I am being unreasonable by proposing a useful feature, That isn't the part that's unreasonable. > that for most everyone in the world, doesn't affect them at all in any > way. This is where you are, unfortunately, dangerously wrong. If these age verification systems are plumbed into the free software ecosystem it makes it more likely that similar laws will be proposed in other jurisdictions, and that even more draconian laws will be proposed where such laws exist. As I said in my earlier email: we also don't enforce social credit scoring, mandatory payment mechanisms, or ensure that free software can not be used to bypass censorship deployed by governments. All of those things also exist and are enforced by laws in one land or another. The simple reason we do not plumb such things into the core of free software systems is that it is not our purview to do so. Moreover, they are actively hostile to the rights and freedoms of people who use and even rely on technology. This does not stop countries from implementing those features themselves. They are free to do so. But that's their burden. Not ours. We do not need to become willing participants in our own demise. So, yes, plumbing in the requirements expressed in this California bill *would* be affecting everyone in the world, by making us complicit in their short-sighted edict. > When these kinds of laws are finally laid to rest, the only legacy > of such laws would be, like I already mentioned, parents having > powerful, effective tools (parental security policies) that allows them > to better parent their child. The age verification requirements in the law in question are not a powerful, effective parental tool. I know what "power, effective parental security policies" look like, and this law isn't it. I am a parent who carefully mediates the interactions my children have with computers and (especially) the internet. Me and my partner strive to educate them and discusses the issues openly with them. We even (shock!) use parental controls where available and sensible. This isn't about parental controls. If you and others go on to create a great free software parental control system that is easy to use and widely available, that would be a great thing. I have zero argument against that. But let's not pretend that's what this is about. This is about a pernicious law in one state in one country from a governmental body that is attempting to move the entire world of computing and communication in ways that are not in our best interests. -- Aaron Seigo