Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Based on the few snippets quoted in the article, I think as written this bill gets closer to a good, privacy-preserving, non-authoritarian version of "age verification" than any of the attempts so far. What it seems to be aiming for is essentially mandatory parental controls at the OS level. No ID checking or government/third party involvement, it just uses whatever age the parents enter when they set up the device/user account for their kid. And apps don't actually get that info so there's very little privacy impact, just exposing an API that would allow apps/websites to query "is this user underage?" seems like it would satisfy the law as written.

The only remaining issue I see here is that I think the law may be a bit too heavy handed in how it tries to legislate this system into existence. Trying to tell Bob Hacker writing an OS in his basement what features his code has to include feels a little too authoritarian for my tastes. Probably there are some economic or regulatory levers that could be pulled instead to ensure this system gains mainstream adoption without criminalizing ordinary software development.

Again though, I didn't read the whole bill, just the article, so I could be wrong here on some of the details.



This is not the bill you're hoping for:

1. The text implies software should get access to your date of birth, rather than talking about age groups. If it becomes the case that websites can get your precise date of birth, this will be the ultimate fingerprinting vector that will put the fight for online privacy dead in the water.

2. The text talks about "verifying" dates of birth. This can only imply the involvement of face scanning or ID checking and third parties.

3. The text itself is very vague about details such as verifying, because it leaves many details entirely to the FTC, which recently announced they will stop enforcing privacy protections under COPPA for companies violating it to perform age verification of children[0]. So you can fully expect that if we are putting computing entirely in the hands of the current commission we will be probably screwed.

The text itself is less than 4 pages. I recommend reading it for yourself[1].

[0] https://www.ftc.gov/news-events/news/press-releases/2026/02/...

[1] https://www.congress.gov/bill/119th-congress/house-bill/8250...


Ah, I see your point. I could see a way to interpret the language in the bill to mean exactly what I was thinking[1], but it's pretty vague and I could also see a way to interpret it that would seriously hurt privacy. If it's just down to the FTC (i.e. the whims of whoever the president happens to be at any given time) to resolve those ambiguities then that's not something I could support.

[1]: It says the parents verify the user's date of birth, which could just mean they get to say "yes, my kid is 12", and "a system to allow an app developer to access any information as is necessary" could just mean "is user over 18" if that's all that's necessary to comply with the FTC regulations.


The bill mentions a parent verifying a child's age, but the bill also later mentions the issue of "verify the date of birth of a parent or legal guardian" which I can only interpret as a face scan or ID check of the parent


No, this technical implementation is straightforwardly bad. The information flow and point of decision making are completely backwards as the bill was written by Facebook/Meta purely to absolve themselves of liability and foist it into others, including onto parents themselves!

The right way to facilitate parental controls with legislation is to put a requirement on service providers [over a certain number of users] to publish well-known tags stating the age suitability of their site/app/pages. Then put a requirement on mass-market device manufacturers [over a certain size] to include parental control software that can filter based on these tags. When parental controls are enabled on a device, any site/app without tags "fails closed" and doesn't display - meaning the open web and open devices continue to coexist with the tag system.

The key parts 1. the information signals flow the correct way, from the company with a well-known identity to the end-users' device where it can be acted upon per the device owner's desires 2. the legal liability lands in the right place - tags signify legal representations of the suitability of content and 3. the long tail of small-scale websites and devices are completely unaffected

This would also leave the makers of parental control software (bundled with device or third-party aftermarket) free to implement additional features that parents desire (eg block social media, even if the site says it's fine for <18), rather than leaving those decisions entirely in the hands of corporate lawyers (as this bill does, because once again it was written by Facebook/Meta).


> Trying to tell Bob Hacker writing an OS in his basement what features his code has to include feels a little too authoritarian for my tastes.

This is the one thing that risks getting the law struck down by a court.


Exactly. People often forget that Congress can only exercise a limited domain of enumerated powers. The big one is regulating Interstate Commerce, which is already huge because of how interconnected the country is today, and is even bigger because of creative stretching of its reach (did you know that the Civil Right's Act's ban on discrimination by businesses is within Congress's Interstate Commerce power, because somebody might patronize your business from out of state?).

Anyway, I suspect Bob Hacker has a strong case that such a law as applied to himself would be beyond the scope of Interstate Commerce. Until he tries to sell or make his OS widely available, at least.


Given how broadly the commerce clause has been interpreted I don't think we can rely on that to save us here. Criminalizing Bob publishing his OS on GitHub is still too authoritarian for my liking.

Just off the top of my head, something like "physical hardware with web access sold in the US without an ID check at the checkout counter must include this feature in its preinstalled OS" would be a better way to write the law in my opinion. Plenty of ways around it if you're a hobbyist or for some reason really don't want to comply, but a big enough hassle that all the major commercial OS providers would probably find it easiest to just include the feature. (Especially since this is a feature most parents would probably appreciate anyway.)


why do you think any court in MAGA America would allow this?

we know, for sure, that Clarence Thomas takes bribes. You think Facebook wouldn't cut him a check? Ditto for plenty of other Trump-installed justices on all levels.


It's always the same pattern. There is no way to protect the children while also preserving freedom. The rationale behind it is irrelevant. For this to work everything would have to be locked down right?

This is not in the interest of the people nor any children.


> For this to work everything would have to be locked down right?

No. As long as the focus is on giving parents tools to parent their kids and not on the government taking over that responsibility completely then there's no need for the government to lock anything down. You just give the parents locks and let them do the locking.


> Based on the few snippets quoted in the article, I think as written this bill gets closer to a good, privacy-preserving, non-authoritarian version of "age verification" than any of the attempts so far.

I think you are mixing up the bill this article is covering and the bill that California passed.

The California law requires:

• When setting up an account for a child who is the primary user of a device the OS lets the parent specify the child's age or birthday.

• The OS to provide an API that apps can use to find out if the current user is a child and if so their age range (under 13, 13 but under 16, 16 but under 18, 18 or older).

The bill in Congress requires setting age information for all users. It does not specify how that age information is to be obtained, leaving such details to regulations that the FTC will write.


So it's just an OS-level "I am over 18" checkbox. Essentially useless, except for removing liability from social media companies. As far as they know, every single device accessing their site legally testified they are over 18.


no its not, the bill also contains "for other purposes"

in present form its more than age verification, technically it could be for any other purposes.


Agreed. Weirdly many people are against. This really seems like the best possible option. Actually helps parents as without this there is no way to enforce kid age. So instead of having it all per account and everything linked in most privacy invading way, just your OS tells the apps/browser whatever was set in there by the parent. I want this now!


I guess we are expecting this to be backdoored with biometrics later? I don't see how anyone can force this on Linux.

I still prefer to have this in my OS above having every Random internet vendor collecting my biometrics and id documents.


> I guess we are expecting this to be backdoored with biometrics later?

Definitely. And with trusted computing for the OS and browser so that those random internet vendors can be sure the OS performed all the required validation.

> I don't see how anyone can force this on Linux.

That will be the problem of Linux, not of the lawmakers.


It is one of the better options. Instead of vaporizing the ship, it only blows it in half at the keel.

As TFA notes, once this is in place, we're behind the eight ball from then on. You want to post something that the government doesn't like, something that insults our Dear Leader or promotes a political alternative? Guess who's getting an "over 21" rating by the feds. We've already seen massive speech pressure brought to bear by the FCC and there's no reason to think this won't continue.

So I'm reluctant to give 'em an inch.


You should actually read the text of the bill. It basically tells anyone who asks what your birthday is. It places no limitations on how your age should be verified, or how requesters can use your information. And if you think this is where this kind of de-anonymization will stop, I have a bridge to sell you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: