|
|
Log in / Subscribe / Register

One step forward, two steps back on CA age bill (EFF Deeplinks Blog)

The EFF has a blog post looking at a new bill in California that would exempt open-source operating systems from the Digital Age Assurance Act passed last year, but has problems of its own:

While the open source exemption, if passed, would improve the law, the remaining amendments proposed by AB 1856 would require all web browsers and websites to request and collect users' ages. This is an expansion of last year's AB 1043's age-bracketing system that compounds its constitutional harms to users' speech, privacy, and security.

[...] EFF understands this amendment to exempt open-source operating systems from the requirement to collect and transmit users' age-bracket data. That is a definite win for open-source developers. The bill is narrower now than it was before, and lawmakers clearly responded to concerns raised by EFF and the broader open-source community.

Some important questions still remain—for example, it is unclear how the law would apply when an open-source operating system is incorporated into a commercial product or service. And, given the structure of where the exemption is placed under the "operating system provider" definition, lawmakers could stand to clarify that the exemption applies to open-source operating systems and applications.

LWN covered California's age-attestation law in March.



to post comments

Brace yourself!

Posted Jun 4, 2026 15:44 UTC (Thu) by eduperez (guest, #11232) [Link] (8 responses)

All these "age checks on the operating system" initiatives are "enablers" for what is coming next: mandatory age checks on websites; the purpose is to move the cost and the responsibility, from the website developers down to the operating system developers. Open-source operating system might be exempt from age checks, but websites displayed on open-source operating systems will not be exempt.

Be prepared for "your operating system is not supported" when visiting adult sites.

Brace yourself!

Posted Jun 4, 2026 15:47 UTC (Thu) by jpeisach (subscriber, #181966) [Link] (6 responses)

> Be prepared for "your operating system is not supported" when visiting adult sites.

"Dad, my school resource page won't work!"
"Sorry honey, we can't afford a computer to run another operating system"

Is this how Microsoft plans to get their users back?

Brace yourself!

Posted Jun 4, 2026 16:10 UTC (Thu) by paulj (subscriber, #341) [Link] (5 responses)

Meta, Google, and others are also backing this bill. I would think because they believe it would allow them to push responsibilities and scrutiny away from themselves and onto others.

Brace yourself!

Posted Jun 4, 2026 23:14 UTC (Thu) by Keith.S.Thompson (subscriber, #133709) [Link] (4 responses)

Or because they're big enough that they can afford to implement the requirements, and their smaller competitors aren't.

Yes, a well-known bureaucratic trick

Posted Jun 5, 2026 6:13 UTC (Fri) by felixfix (subscriber, #242) [Link] (3 responses)

Suppose complying with some regulations requires hiring one full time lawyer. For Alphabet, M$, Meta, and others, this is lost in the noise. For a company of 100 employees, this cost is not prohibitive, but it will be noticed and has a recognizable opportunity cost, possible a couple of developers. For a 10-employee company, it could mean bankruptcy or having to sell out cheap to one of the big companies.

In the US, my memory says Sarbanes-Oxley (?) had this effect on banks especially, requiring 10 full time lawyers and accountants just to file the new reports and ensure compliance by all employees. It led to most small banks selling out to big nationwide banks. Those big operations were enthusiastic backers and could afford the lobbyists to push the bill into law.

It probably has some name among economists, but I don't know what.

Yes, a well-known bureaucratic trick

Posted Jun 5, 2026 6:50 UTC (Fri) by intelfx (subscriber, #130118) [Link] (1 responses)

> It probably has some name among economists, but I don't know what.

It’s like SLAPP and “chilling effect”, but in the field of compliance.

Yes, a well-known bureaucratic trick

Posted Jun 5, 2026 7:12 UTC (Fri) by felixfix (subscriber, #242) [Link]

Some AI suggested "regulatory capture", but that refers to the cycle of bureaucrats between regulator and industry. I tried a few variations but got nothing.

Yes, a well-known bureaucratic trick

Posted Jun 8, 2026 9:05 UTC (Mon) by taladar (subscriber, #68407) [Link]

Not quite specifically this but it falls under the broader term barriers to entry.

Brace yourself!

Posted Jun 5, 2026 8:32 UTC (Fri) by nim-nim (subscriber, #34454) [Link]

The purpose of those campaigns is to dynamite any OS-level privacy protection against data hoovering by cloud giants. Because IA and pervasive surveillance society need their data. Web site operators are seen as useful idiots who already surrendered their user data to the likes of Thiel, that’s why there is no appetite to do any processing website-side (the data there is already powned).

It is quite easy to perform stronger mandatory age checks without requiring end-nodes to collect and surrender private data to any interested bystander. Just create a public service that delivers anonymous time-limited and volume limited “I am a responsible adult” signed token attestations to citizens that need it, finance it by taxing the guys that want to run shady adult-only businesses. No one should need to be subjected to thousands of open-scope OS probes by random websites and robots a day, giving one anonymous attestation a month to specific adult web sites is more than enough.

Websites and cloud operators do not need access to the level of private info that justified the delivering of the attestation, the government does not need access to where those attestations are used, and the result is not tied to any OS implementation (how the cloud giants would love making their owned stack mandatory because it’s the only one complying with age checks). The government already knows who is a responsible adult because taxes, the government is already accountable for not leaking this data irresponsibly, that does not involve any further risk for users.

All this is classic IT privilege separation, when it pushes for OS-level age checks Meta is being purposefully incompetent, because the endgame is definitely not “move the cost and the responsibility […] down to the operating system developers”. On the contrary it is getting full access to the operating system user data without any accountability.

Micro-attestations are the same idiocy than micro-payments, they make no economic or technical sense by themselves, their purpose is to corral users into walled gardens which are the only ones big enough to make them work (because they are big and because they monetize the corralling in other ways).

Guaranteed its trying to prevent children from restricting content

Posted Jun 4, 2026 15:45 UTC (Thu) by jpeisach (subscriber, #181966) [Link] (12 responses)

> While the open source exemption, if passed, would improve the law, the remaining amendments proposed by AB 1856 would require all web browsers and websites to request and collect users' ages. This is an expansion of last year's AB 1043's age-bracketing system that compounds its constitutional harms to users' speech, privacy, and security.

I'm so glad this will surely prevent children from seeing 18+ content. And it definitely won't be used to, I don't know, restrict access to sites like Wikipedia or valuable sources of info?

Ok, in all seriousness - "all websites" - does this just give the green light for all services to say "welp, we need your age now" even if you aren't in California? And do they *have* to? Like, Wikipedia does not need to know the age of users. Same for web browsers.

And technically, web pages should only care about ages if there is a reason to. The obvious reasons being adult content, but also things like.. *social media platforms*? The websites being ran by companies trying to run this bill?

And why do "browsers" need to know the age? To pass the data along? It looks like an opportunity for Meta to make some browser and market it as being "better for Facebook, Instagram and Threads users", while yoinking everyone's ages.

So here is a proposed solution:
- Web browsers and websites should only request users ages if the content on the page may be sensitive to certain groups of ages.

Guaranteed its trying to prevent children from restricting content

Posted Jun 4, 2026 16:59 UTC (Thu) by dskoll (subscriber, #1630) [Link] (6 responses)

Websites should never request user's ages. They should simply include a header something to the effect of:

X-Intended-Minimum-Age: 18

and then leave it up to the client to figure out how to deal with the content.

Guaranteed its trying to prevent children from restricting content

Posted Jun 4, 2026 17:22 UTC (Thu) by jpeisach (subscriber, #181966) [Link] (1 responses)

> and then leave it up to the client to figure out how to deal with the content.

So then you need "government approved" browsers?

Guaranteed its trying to prevent children from restricting content

Posted Jun 4, 2026 17:47 UTC (Thu) by dskoll (subscriber, #1630) [Link]

The client either has to provide the age signal to the website or deal with the minimum-age header from the website. Either way, if the goal is not to have the browser spoof anything, it has to be "government approved".

However, in the former case, the web site gets age information about the user, whereas with the X- header, if the client is properly written to download and discard the content, the web site gets no information about the age of the user.

HTML Rating tags exist

Posted Jun 4, 2026 19:19 UTC (Thu) by ebiederm (subscriber, #35028) [Link]

Commonly called Restricted to Adults

Your html can include
<meta name="rating" content="adult">
or
<meta name="rating" content="RTA-5042-1996-1400-1577-RTA">

This already exists.

Maybe we need a variant that doesn't need imply sexually explicit content.

The page reporting itself and the browser honoring that seems like the way to go.

If you want a law make the websites responsible for marking content, and make browsers resposible for honoring the tags and having a kids mode that will not let such pages be viewed.

Maybe even have the OS pass that information just to the browser if it is already collected.

Guaranteed its trying to prevent children from restricting content

Posted Jun 4, 2026 19:24 UTC (Thu) by fraetor (subscriber, #161147) [Link]

You mean like the <meta name="rating" content="adult"> HTML tag/HTTP headers that has existed for years and all adult sites contain for SEO?

https://developers.google.com/search/docs/crawling-indexi...
https://developers.google.com/search/docs/specialty/expli...

IIRC Firefox is starting to replace pages with that tag with the about:restricted page when your operating system parental controls are enabled, though I'm not sure if it is supported beyond MacOS yet.

Guaranteed its trying to prevent children from restricting content

Posted Jun 5, 2026 3:07 UTC (Fri) by dilinger (subscriber, #2867) [Link] (1 responses)

What country is that intended minimum age for? In the US you need to be 21 to drink alcohol. In Quebec, you need to be 18. It's a little more complicated in Germany, but drinking age with parental consent starts at 14. So does that header set the intended minimum age depending on the location of the alcohol seller's website or the (assumed) location of the user?

Pornography age verification laws vary as well by country. 18 is pretty common, but apparently some countries allow distribution to people who are 16. So, same question applies.

Guaranteed its trying to prevent children from restricting content

Posted Jun 5, 2026 12:20 UTC (Fri) by dskoll (subscriber, #1630) [Link]

Yes, that is a weakness, I suppose. But it's a weakness anyway: If a client tells a website that the user is 16, the website would have to know where the user is located and use the correct national laws to determine whether or not it's OK to serve content.

I guess the header could be expanded to include US=18;UK=17;CA=16 or whatever, but either way, it's a giant mess. This is what happens when lawmakers try to solve a social problem using technological means. The whole age-verification thing is nonsense.

Guaranteed its trying to prevent children from restricting content

Posted Jun 5, 2026 12:56 UTC (Fri) by Wol (subscriber, #4433) [Link] (1 responses)

> Ok, in all seriousness - "all websites" - does this just give the green light for all services to say "welp, we need your age now" even if you aren't in California? And do they *have* to? Like, Wikipedia does not need to know the age of users. Same for web browsers.

That's actually GDPR illegal.

If you don't need the information, you need to have the user's informed consent.

"If you don't consent to handing over unnecessary information we won't deal with you" is by legal definition NOT informed consent.

WHOOPS!

Cheers,
Wol

Guaranteed its trying to prevent children from restricting content

Posted Jun 7, 2026 2:44 UTC (Sun) by gdt (subscriber, #6284) [Link]

Further to your point, requirements extend beyond the GDPR, since the user and their operating system are wholly within the EU, and so the entirety of EU privacy law applies. Designs which meet the needs of multiple jurisdictions are more complex than those so far appearing in this discussion.

For an example for my own nation of Australia, the Privacy Principles require: explicit informed consent to collection of sensitive information (which includes year of birth); that a person be able to access and correct provided personal information. If the entity is overseas the distribution of the information must be in such a way that the Privacy Principles are commercially and legally enforceable; for example, through contractual provisions. So if an operating system is to disclose age, the OS vendor must have an Australian jurisdiction contract with every website to which it discloses this sensitive information, or measures which have the same effect.

This is basically an attempt by Facebook and others to cost-shift user verification into operating systems, then using the economic power of California to impose that system in the US and globally.

Guaranteed its trying to prevent children from restricting content

Posted Jun 5, 2026 22:12 UTC (Fri) by anselm (subscriber, #2796) [Link] (2 responses)

Ok, in all seriousness - "all websites" - does this just give the green light for all services to say "welp, we need your age now" even if you aren't in California? And do they *have* to?

My web site provides strictly wholesome and edifying content appropriate for people of all ages. It is based in Germany. Why would I ever worry about how old my users actually are, just because a law in California says I should?

After all, the big social media companies – which are, for the most part, based in California – certainly don't fall over themselves ensuring that they comply with German law (e.g., about Nazi symbols or holocaust denial).

Guaranteed its trying to prevent children from restricting content

Posted Jun 6, 2026 1:21 UTC (Sat) by pizza (subscriber, #46) [Link]

> My web site provides strictly wholesome and edifying content appropriate for people of all ages.

"Strictly Wholesome" according to whom?

(....and therein lies the problem)

Guaranteed its trying to prevent children from restricting content

Posted Jun 6, 2026 22:28 UTC (Sat) by mpsk (subscriber, #183534) [Link]

I'm wondering whether it'd be at all legal for you to ask for it. IANAL, but it'd be a bit weird, if any European court agreed that it's your "legitimate interest" (in GDPR terms) to collect users' ages for the purpose of complying with some foreign law.

This is a wase of time and taxpayerss' money.

Posted Jun 4, 2026 19:05 UTC (Thu) by ccchips (subscriber, #3222) [Link] (2 responses)

Exploiters, child-molesters, slave-traders, and anyone in those horrid businesses are going to figure out how to walk right around this. Like my criminal brother once said: "Where there's a lock, there's a pick." This stuff is not going to substitute for parental supervision. None of the nonsense of this type has succeded in the past, either

This is a wase of time and taxpayerss' money.

Posted Jun 5, 2026 7:18 UTC (Fri) by anselm (subscriber, #2796) [Link]

Not just the exploiters, child-molesters etc. themselves. Consider that Australia tried to introduce a hard age limit on the users of large networking sites, but so far, it seems that most of what this has accomplished is to teach teenagers about the benefits and operation of VPNs.

This is a wase of time and taxpayerss' money.

Posted Jun 20, 2026 16:32 UTC (Sat) by sammythesnake (guest, #17693) [Link]

> Where there's a lock there's a pick.

"Where there's a window, there's a brick."

Finesse is all very well, but rarely pays for itself...


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds