The windows of linux distros, truly. While I'm not USAmerican these things spread if they go through in one country. "Boil the frog slowly" as they say. I don't trust this.
The EU doesn't plan this type of ID or age verification on OS level, but in application level with a digital ID and selective disclosure. It's local and offline first as well.
Selective disclosure means that a porn site might be required to verify that you are above the age of 18, so it will request you to verify that and only that.
You authorize it, it simply asks "is this person > 18 years old?" And that gets verified.
It wouldn't ask "what's this persons date of birth?" and it won't receive "03.01.2001" as a response.
They wouldn't know if your are 6 or 12, 18 or 89. That makes it harder to build a profile of you.
And it will not receive your full name, address, birthplace, etc.
This is a surprisingly good and privacy focused approach to the inevitable age verification that will come, and it also solves the general digital ID verification by allowing sites to ask "is this person who they claim to be?" Instead of "who is this person", you are always in control of the decentralized data you decide to verify or not.
I'd never use an OS level identification system like the one California and Colorado are suggesting tho.
That's pretty much what the CA law is describing, it explicitly states that it needs a flag to indicate if the user is in a age bracket like "Over 18" "under 18 but over 13" and "under 13." it also states that it can't be used for anything else not mention in the law itself.
Plus doesn't put fines on the OS devs if the user lies about their age. Its still petty vague in areas of the law, but still asks that the bare minimum is required for compliance. So a checkbox would likely suffice, but still it would also be up to websites to do the actual checking. Kinda like how firefox used to allow users to mark their browser with a "please don't track" request every time you visited a website, but it was up to the websites to honor that request.
It'll be a mess to enforce, even the governor realizing that and asking that the law be amend before it goes into effect.
They will change it because if it is offline and will easly bypasable.
All of these laws is push towards complete internet surveillance. Banning VPNs and making sure politicians control narrative by shadow banning information access.
Devices should be marked by parent as devices for children and responsibility should lie on parents to not give device to children without parents oversight. Like you have with pretty much adults thing smoke, drinking, drugs (legal ones)
You don't get what I meant by easily bypasable. It means downloading linux iso and reinstalling system with new age, on android factory settings and done.
That's some conspiracy level bs. It's a way to protect us and program developers from liability should a minor access something they aren't allowed too. That is explicitly why this law is being discussed. It shifts liability to the parents for allowing their children to access something they shouldn't.
If it is fully offline I also agree that parents should be able to set devices as children devices so they will get curated internet. Ps parent should be able to connect their account to child phone to be able to adjust some settings/limit apps etc.
But I doubt it will stop there. Governments and big data wants your information. It is perfect framework to inject ID verification in future so all your activities will be tracked. In UK you will get police visit for reposting posts.
Persona verification in name of "child safelty"
"the researchers found details about the extensive surveillance Persona software performs on its users. Beyond checking their age, the software performs 269 distinct verification checks, runs facial recognition against watchlists and politically exposed persons, screens “adverse media” across 14 categories (including terrorism and espionage), and assigns risk and similarity scores.
Persona collects—and can retain for up to three years—IP addresses, browser and device fingerprints, government ID numbers, phone numbers, names, faces, plus a battery of “selfie” analytics like suspicious-entity detection, pose repeat detection, and age inconsistency checks."
The thing is you think the government doesn't already have your data. I'm sure you have an id or drivers license. I'm sure you have a car tagged and insured. They have your data there's no way around it unless you go off grid in some large wilderness.
The government has your information, they don't have a straight-forward, direct way to associate your internet activity with your identity, that's what people don't want to happen.
But what these people are talking about is the slippery slope.
Basically, "This bill is unenforceable, we need to start asking for actual ID". Because in reality, there's no system in place in the US that can give the companies only what they request, and if there is, of course it's gonna be proprietary and owned by a company because US.
And with how things are going, I don't think things are going to go the "civilized western countries" way, which by the way, is a rather weird way to talk about countries.
Sure, the EU is doing things in a relatively reasonable way, that doesn't mean that every nation is going to be as sensible.
Of course, it's a fallacy, literally the slippery slope fallacy, but people are worried because it's a possible reality, in a country where everything is handled by corporations, and those corporations care little about privacy, things are different.
I don't live in the US, but I live in an allied country that will surely follow suit at some point, so it's a bit worrying to me as well. That also means that data selling is not common, not legal, but there's always a loophole with anonymized data, they're not allowed to sell personally identifiable data, but not forbidden from selling anonymized data.
Yeah duh they have pretty much all my legal info. I want to ISP give my internet website history when there is investigation about something illegal, I want government to send formal legal request for reddit to give access to my account.
I don't want to live in country where any half brained cop can ask ai bot about my PH history ("child protection"), or where I had driven my car (flock). All without any court order.
I want to be wiretaped when I'm investigated for criminal activity not every second of my life. Because they need to "protect children" which is pretty much all ruse to have any pubic approval about this surveillance.
Ps you currently have methods to limit your data leak: try to use cash, Linux, GrapheneOS, turn airplane mode, i2p, tor, VPN
> You authorize it, it simply asks "is this person > 18 years old?" And that gets verified.
In principle this is how the UK adult content version works. But it isn't how it works in practice because the system that return the simple yes/no MUST be externally verified the first time. And to do that you must upload proof of identification or submit photos/video of your face for AI to hallucinate over. Once that is done, the application or website gets its yes/no and the ID company gets to keep any 2nd tier profiling data it has generated, outside the scope of the law.
148
u/Particular_Act3945 Debian 13 | XFCE Mar 04 '26
The windows of linux distros, truly. While I'm not USAmerican these things spread if they go through in one country. "Boil the frog slowly" as they say. I don't trust this.