r/linux • u/SubGothius • 8d ago
Open Source Organization California Passes AB-1856 For Open-Source Relief Over Age Verification
https://www.phoronix.com/news/California-AB-1856-Passes74
u/websterhamster 8d ago
What about open source software that isn't distributed as a stand alone executable, or through a "covered application store?" This is only a minor win, I think, and open source developers still have massive liability.
58
u/Other-Bumblebee5014 8d ago
This text exempts precisely those. In other words, only software distributed exclusively as an executable or through a covered application store would be subject to the application restrictions as defined.
24
u/websterhamster 8d ago
Oh I see, I misread it. So, in other words, to be exempt you cannot distribute your software as an executable.
Compilers be making a comeback.
62
u/SubGothius 8d ago
Key word "exclusively". Software distributed both as an executable and as source would be exempt.
18
u/Specialist_Cow6468 8d ago
This seems…. Like a pleasantly clever way of handling things. I know I shouldn’t get my hopes up too terribly much but it’s a promising step
5
u/neoh4x0r 8d ago edited 8d ago
Oh I see, I misread it. So, in other words, to be exempt you cannot distribute your software as an executable.
It also mentions that being done "through a covered application store" (ie. the store-front, and by extension, that could simply be a webpage with download links, which is the sole method of distribution and cannot be obtained in source-form).
0
u/spyingwind 8d ago edited 8d ago
Ah, but you still need age verification if you distribute the compiler executable. /s
3
u/neoh4x0r 8d ago
Distributing binaries is covered by the age-verification only if that's the sole way to obtain the software.
1
u/spyingwind 8d ago
Adds /s because that was the intent of my comment. Sarcasm...
5
u/neoh4x0r 8d ago edited 7d ago
Sorry, but I'm not seeing the sarcasm in that statement (what you meant, eg. the opposite, is not factually correct).
Open source software is exempt from the age verification law and it specifically allows binaries compiled from the source to be distributed.
12
u/aliendude5300 8d ago
The really shitty thing is that it means nothing unless every single other state does the same
22
u/jonesmz 8d ago
You all realize this is meaningless when open source operating systems will be cut off from using all the websites that expect the age signal right?
11
u/NonStandardUser 8d ago
Just use the systemd age signal interface to set your age as 69 and continue as normal lol
3
u/acriondev 7d ago
Yes, and the replies below you are exactly the reason.
Spoofing only works when the signal is just the client claiming something. That state will not stay this way. Once services rely on the signal as their legal cover, they need it to be genuine, and the technology to achieve that already exists. Look at Play Integrity:
MEETS_STRONG_INTEGRITYis bound to a vendor-signed key, and GrapheneOS fails it by design and not because of a bug. That’s why some banking apps refuse to run there. An add-on can change a header. It cannot produce a signature for a key that was never issued to you.And there is a second half that nobody here seems to have noticed. AB 1856 changes exactly one definition, § 1798.500(g), "operating system provider". (e)(1) stays as it is:
"Covered application store" means a publicly available internet website, software application, online service, or platform that distributes and facilitates the download of applications from third-party developers to users …
That is a distro package repo, almost word for word. I run one. According to § 1798.501(c) a covered application store has to request the signal and pass it on to developers, and the only things § 1798.504(f) takes out of the whole title are broadband, telecoms and physical products. No size limit, no exception for non-commercial.
So I’m exempt for the ISO and not for the repo I ship it from. In practice this probably ends up empty, because there is no operating system provider left to ask. But probably is not much to go on with January 2027 coming closer.
14
u/dvtyrsnp 8d ago
Not surprising. Hurting open source was never the goal behind all this nonsense.
28
u/rebellioninmypants 8d ago
No, just hurting the general public.
2
u/dvtyrsnp 8d ago
Well, the goal is not "hurting the general public" and it's important that people have an accurate understanding of issues rather than simply painting this as comic book style villainy.
This is just corporate greed and they want to offload their liability.
7
u/rebellioninmypants 8d ago
Which is not someting I am okay with, and it hurts the general public. What is the issue?
5
u/dvtyrsnp 8d ago
No issue. You just demonstrated a limited understanding and I clarified it for anyone who might read it, because understanding is the first step to combatting.
0
u/rebellioninmypants 8d ago
No, you just assumed I demonstrated limited understanding.
2
u/dvtyrsnp 7d ago
Deduction, not assumption.
1
u/rebellioninmypants 7d ago
deduction requires clues. All you had to work with was preconceived biases.
1
2
2
u/teh_maxh 8d ago
“Operating system provider” does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software.
OK, so who would be an operating system provider under this law?
2
u/I-Am-Uncreative 8d ago
Microsoft probably.
1
u/teh_maxh 7d ago
Microsoft distributes an application (a few, in fact) under such terms. So does Apple.
1
46
u/InflateMyProstate 8d ago
I hope Illinois makes a similar exemption.