Re: California law CA AB1043
"Ihor Antonov" <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.hackers |
|---|---|
| Message-ID | <[email protected]> |
BSD license already disclaims any legal responsibility, no? I.e use the code and leave us alone? Or was it a 4-clause ? On Thu, Feb 26, 2026, at 4:18 PM, Mark Millard wrote: > On 2/26/26 13:57, Cy Schubert wrote: > > In message <[email protected]>, Mark Millard > > write > > s: > >> On 2/26/26 07:12, Lucas Holt wrote: > >>> California is requiring age verification checks for account creation at > >>> the OS level with a signal API to provide information to applications in > >>> 2027. They explicitly call out individual developers or companies with > >>> fines of 2500 dollars per child affected. > >>> > >>> I wondered if anyone has started looking into this on the FreeBSD side. > >>> The way I read this, we would need to implement changes when creating > >>> accounts, provide a mechanism to check from apps (library), and provide > >>> support within package managers to filter apps? Then browsers would > >>> need to implement this and call the respective OS APIs for age > >>> verification for desktop use. > >>> > >>> It seems like it makes sense for multiple *NIX systems to implement a > >>> similar mechanism across platforms. > >>> > >>> The paragraph near the bottom seems to indicate that it wouldn't apply > >>> to server use since indirect signals aren't required to be honored. > >>> > >>> For reference: > >>> > >>> https://legiscan.com/CA/text/AB1043/id/3269704 > >>> > >> > >> Hmm. 1798.500(e)(1) [and (2)] would appear to make port-package > >> distribution of "Application" (but plural) a "Covered application > >> store". At the moment I do not see how the FreeBSD port-package > >> distribution mechanism would fit into this in its current form. It would > >> seem to require accounts to be involved for all "Account holder" (but > >> plural), for example. The "operating system provider" has to require > >> account setup to indicate age information for the "user" (such as a > >> child) and has to provide secure access to the information "when the > >> application is downloaded and launched". > > > > Before jumping to any conclusions I think we ought to look at what > > companies like Red Hat and Canonical are doing in this space. > > I made not have made it clear, but I was not intending more than a > heads-up for folks like, say, core that would likely need to decide on > the implications of the actual law (if any) for the context at hand. The > referenced legal text was enough that I thought it justified that much > (and not more). > > I did use "would appear", "would seem", and "may be" (below) indicating > that my preliminary read need not be definitive. At best it is a valid > prompt for appropriate folks to look for themselves. That may well > involve checking what the wider environment's examples like Red Hat > conclude. > > Other than this note, I do not plan any more contribution to the subject > area on any lists, whatever is done or not done. > > > > >> > >> Since the FreeBSD OS includes applications and the means to download > >> optional applications that are also part of the OS, there may be similar > >> issues for it (relative to itself) as far as I an tell. > >> > >> The title does not apply to: > >> > >> ) broadband internet access service (Section 3100) > >> ) telecommunication service (Section 153 of Title 4 of the US code) > >> ) Delivery or use of a physical product > >> > >> But I doubt that such applies. > >> > >> There are time constraints that I'll not get into but would seem to be a > >> problem. > >> > >> -- > >> === > >> Mark Millard > >> marklmi at yahoo.com > >> > > > > > > > -- > === > Mark Millard > marklmi at yahoo.com > >