California introduces age verification law for all operating systems, including Linux and SteamOS — user age verified during OS account setup

https://thelemmy.club/post/45187928

California introduces age verification law for all operating systems, including Linux and SteamOS — user age verified during OS account setup - The Lemmy Club

Lemmy

Many people here are going off on wild tangents over this. You should just read the law, it’s only a couple thousand words of quite plain English.

Many here have taken completely incorrect assumptions from the title. **This law is for developers, not users. **

Summary:

  • Requires OS devs ask for DOB, age, or both at account creation time.
  • Requires an API that allows app store devs to request this age data for the account. At minimum this must specify the account is a member of one of these categories: ‘user under 13, user over 13 and under 16, user is over 16 and under 18, user is over 18’.
  • gasp

  • Explicitly bars OS devs from sending more data than explicitly necessary to meet 1 (hint: photo ID, facial recognition).
  • Explicitly bars app devs recieving the data from requesting more data from the OS nor the App store.
  • Bars app stores from using the data for any other reason and specifically calls out anticompetitive practices.
  • Bars app store and OS devs from sharing this data with any third party for any other reason than to comply with this law.
  • Has injunctions and civil penalties of $2500 (max per user) affected by negligent violations (eg a child account is served adult content), and $7500 (max per user) affected by intentional violations.
  • The only problem I have with this is that it should only apply to commercial software (app stores and OS). Libre/FOS software should not have to police ages on their app stores, due to their far reduced budgets (often zero), developer time, and the nature of the software being generally anti-centralized and anti-surveillance-capitalism. Though I’d be fine with it for FOSS software distributed via commercial app stores, as long as they gave a longer lead time to implement (EG a couple of years).

    Bill Text - AB-1043 Age verification signals: software applications and online services.

    AB 1043 Age verification signals: software applications and online services.

    It says that OS developers must track users or be fined, so they will track users.

    Explicitly bars OS devs from sending more data than explicitly necessary to meet 1

    The statute does not define:

    What counts as “minimum”

    How necessity is measured

    Whether “minimum” refers to data fields, granularity, frequency, or retention

    Whether metadata (e.g., device ID, timestamp, API call logs) is included or excluded

    This legislature calls App Providers and developers to track people and barely even gives lipservice to what is allowed.

    We don’t want our OS’s tied to our identities. This does not explicitly forbid that

    Read the law (its barely 1000 words) because your claims are not substantiated by it.

    I already read it. That’s how i came up with what I wrote man.

    You go re-read it and tell me

    What counts as “minimum”

    How necessity is measured

    Whether “minimum” refers to data fields, granularity, frequency, or retention

    They don’t cover shit about ANY of that.

    It literally explains the minimum as asking the user for their age, DOB, or both. It then says delopers may not ask for more than the minimum data.

    If this is confusing I don’t know what to tell you.