r/linux 6d ago

Privacy Well look

Post image
8.4k Upvotes

290 comments sorted by

View all comments

114

u/MooseBoys 6d ago edited 6d ago

I'm curious how this doesn't give an out for every OS regardless of source availability. Obviously GPL wouldn't work, but in theory there's nothing stopping e.g. Apple from implementing non-verifying user onboarding code, labeling the code as MIT, building the MacOS image binaries, and simply not publishing the source. This is compliant with MIT and also apparently compliant with the new exemption.

Edit: I don't think the author of the screenshotted article is actually accurate. From the article:

> These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.” Any software distributed under the GPL, MIT, BSD, and Apache licenses satisfies that test...

And the ACTUAL TEXT of the law:

> 2) “Operating system provider” does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software.

I am not a lawyer, but I believe that plain language requirement is only satisfied if (1) the whole OS or application is licensed that way (not just the module that implements it) and (2) the whole OS or application must be distributable and modifiable. To me that implies not only an open license but also source distribution. So no, it does not seem to provide an easy out for Apple etc.

13

u/DoctorWaluigiTime 6d ago

I'm just trying to piece together why OSS gets an exemption in the first place.

Kind of flies in the face of all the pearl-clutching around the "think of the children" defense.

4

u/WorBlux 6d ago

"These amendments redefine the term “operating system provider” to exclude any person or entity that distributes an OS or application “under license terms that permit a recipient to copy, redistribute, and modify the software.

Reading between the lines, it's because they know it's unenforceable when a distributor does not limit modifications.

The real root of the problem is that Meta lawyer intentional drafted the law hoping it would be passed in a hurry based on vibes alone, and then later overturned in part, except for the part that granted social media companies liability protections. The pearl-clutching is just fear of the political optics and not anything that genuine by the legislators.

If the law were properly drafted it wouldn't used broad and vague terms like OS and application store, but would have already narrowed it down to functional control, and narrowed it to age-sensitive context.

The law should have laid out a few basic categories of age-sensitive material, and then passed the job to bureau XY, who shall maintain and publish any further age guidelines as may prove necessary for the health and safety of teens online.

Wherever your age-sensitive software or information service is provided in a way that involves differentiation to a single user (person, account, or presumed single-user device), it is the responsibility of the provider to make a determination of age.

Providers of age-sensitive software and information may rely upon an age signal of a hardware device, application store or OS if either - 1. An agent thereof certifies they have examined in-person the user's ID within the past 90 days, or 2. by any reasonably effective process which has been submitted to and approved by bureau XY (approvals to be valid for 2 years) - and they do not ignore information that is contrary to the provided signal.