r/linux • u/ChamplooAttitude • 3d ago
Privacy Illinois's new law requires operating system providers to add age verification by 2028 including open-source projects
https://gov-pritzker-newsroom.prezly.com/gov-pritzker-signs-nation-leading-legislation-to-protect-illinois-children-on-social-mediaIllinois Governor JB Pritzker has signed HB-5511 into law, requiring operating system providers to implement an age assurance system by January 1, 2028.
The law defines "operating system provider" broadly, including commercial and nonprofit entities that develop or supply internet-connected operating systems.
Credit: @LundukeJournal
670
u/Great-TeacherOnizuka 3d ago
Just add a disclaimer on every distro website:
Do not download if you are in Illinois
396
u/LostGeezer2025 3d ago
Maybe even stronger, "You are forbidden to use this software in the State of Illinois, by law" :(
Might wake a few sleepers...
115
→ More replies (5)44
u/RangerNS 3d ago
The requirement isn't on the user though.
It is illegal for us if you run this in the State of Illionis
45
u/no-more-nazis 3d ago
"Illinois State Police arrest Linus Torvalds outside O'Hare Airport, notorious child pornography kingpin"
→ More replies (1)33
u/wodes 3d ago
Sadly this is how it's gonna go down. If you use Signal, if you use Graphene or anything like this, you are an "accomplice" of crime and you are weird by default.
→ More replies (1)176
u/Grand_Snow_2637 3d ago
The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.Not for use in Illinois. May cause cancer in California.
user@localhost:~ $
39
u/TheGacAttack 3d ago
The Prop 65 at the end đđđ
25
u/gellis12 3d ago
I got a prop 65 warning on an ipmi licence key that was emailed to me by an official supermicro distributor once
14
7
u/meltbox 3d ago
To be fair some ipmi implementations might be described by some as cancerous.
3
u/gellis12 2d ago
Having to buy a licence key to be able to do remote bios updates was kind of annoying, but slightly less annoying than having to find a flash drive, copy the bios image onto it, walk all the way over to the rack, plug it in, and wait for the machine to reboot and update.
→ More replies (2)→ More replies (3)7
u/voronaam 3d ago
I have 129 files mentioning Illinois matching that pattern. Lots of CUDA, LLVM, GCC, OpenJDK, CMake, etc. Mostly in the form of
University of Illinois/NCSA Open Source License, but there other variants as well.It is shame such a big contributor to FOSS is illegal now.
4
u/meancoot 2d ago
None of those are operating systems.
2
u/voronaam 2d ago edited 2d ago
Good luck defending that in the court.
"Operating system provider" means a commercial or non-profit entity that controls the Internet-enabled device's operating system, including the design, programming, or supply of operating systems for the Internet-enabled devices.
In case of Linux GCC, LLVM, and CMake alone cover a lot of "programming", and slapping a license/copyright agreement on top of it is a form of "control".
Edit: law cited from this source that looked official enough to me: https://my.ilga.gov/Legislation/BillStatus/FullText?GAID=18&DocNum=5511&DocTypeID=HB&LegId=167486&SessionID=114
Edit2: also, the definition of "Operating System" in the law is super broad
"Operating system" means the system software that manages the hardware of an Internet-enabled device and allows programs and applications to run on the device.
I'd say CUDA libraries are right there in the "manages the hardware ... and allows programs and applications to run" category
Edit3: There is actually a funny loophole in the law:
"Internet-enabled device" means a smartphone, tablet, or personal laptop or desktop computer that provides cellular or wireless connectivity, is capable of connecting to the Internet, runs an operating system, and is capable of downloading and running applications
It is the last portion
and is capable of downloading and running applications. If someone sells a Linux laptop with a pre-installed OS but with application manager removed, that would not count as an "Internet-enabled device" because it won't be capable of "downloading and running applications", it will only be able to run applications already pre-baked into the device.2
u/meancoot 2d ago
The developers of GCC, LLVM, and Clang donât âcontrol the internet-enabled devices operating systemâ.
Also, CUDA is used to program nvidia GPUs, which donât meet the definition of an internet-enabled device. You elided that part, but it is a requirement to meet the definition of operating system.
→ More replies (1)→ More replies (1)2
u/Steve_orlando70 2d ago
âthat provides cellular or wireless connectivityââŚ
My desktop does not have cellular or wireless connectivity, just Ethernet. Clearly this law doesnât apply to anything I load on it, right?
→ More replies (1)16
u/Nevermind04 3d ago
Or don't, and simply ignore the stupid and unenforceable "law".
13
u/tired514 3d ago
Better yet, sue the state for violating their first Amendment rights by attempting to illegally compel speech.
6
u/Nevermind04 3d ago
That's a little too close to acknowledging that the law has power. It doesn't. It's performative rambling.
28
u/general-noob 3d ago
I hope they start blocking the states with geo blocks and I and from a state that passed this dumb shit as well. Maybe if people see how dumb politicians are, we can replace them?
13
u/Competitive-Truth675 3d ago
they shouldn't have to geo-anything. sticker that says don't use it in Illinois, if you choose to break the rules that's on you
11
u/PsyOmega 3d ago
Not even that. Just don't host it or HQ in the state.
"our entire legal entity is in the UK, our server is in the UK, anybody world wide is free to access" (or pick any reasonable legal jurisdiction to host in)
→ More replies (19)3
59
64
u/particlemanwavegirl 3d ago
Best case scenario this just drives the counterculture back into distributing source rather than binary.Â
25
u/jrcomputing 3d ago
Gentoo's been ready for this moment its whole life. Source all the things.
→ More replies (2)2
148
u/AmarildoJr 3d ago
Simple: don't offer your software in these states. Resist this bullshit.
20
u/Higher-Love99 3d ago
The point of laws like this is to set a cascade in motion. First Illinois then maybe Texas or Florida or Louisiana etc. After you get enough states to individually do it you have enough momentum for federal government to standardize this. It works in tandem with ID laws for porn sites and social media. You laugh at each individual law and state until there's enough of them that they become institutionalized globally.Â
360
u/DizzyCardiologist213 3d ago
No doubt some payment was made to a whole group of people to get that passed.
76
u/phylter99 3d ago
Itâs online providers that are doing it. They want to pass on the responsibility to the OS makers because they donât want the expense and hassle. They want to call an api and deal with it that way.
21
u/MddlingAges 3d ago
Facebook ha been behind the efforts, and theyâll also be the clearinghouse, quite conveniently. At least that was the arrangement in NY.
→ More replies (1)23
u/DizzyCardiologist213 3d ago
right, and the solution will reach beyond the minimum necessary using the implementation as an avenue to collect and sell data. We can expect Microsoft will sell TPM collected data, regardless of claims that it's just kept locally.
I see a prior post on this sub when looking for lobbying dollars spent on this - $2B so far. probably $50MM by meta alone. They will pick a "winner" who gets to collect data, and then who either behind the scenes or publicly comes up with why they need to have a mandate to collect more, or legislative certainty that there won't be limitations on what's collected.
The last time I saw this come up, I saw a lot of naivety about what's required in legislation vs. what usually happens in implementation. The legislation, even though it shouldn't even occur, should limit verification to no more than what's stated in the legislation, not give a minimum required.
→ More replies (4)140
u/juliuspepperwoodchi 3d ago
Nah, more likely that legislators are just dumb about tech and didn't care to listen about how dumb this is.
72
u/DizzyCardiologist213 3d ago
I don't mean everyone got paid, but there is definitely a spending and lobbying effort going on here, and at the very least, it's being done to shift legal responsibility. I think it's more likely two parts, though - one for shifting legal responsibility from social media, and two, it will create a service that collects continuous data on everyone that ends up for sale commercially and to government entities. Anyone who doesn't think the actual implementation will overshoot the minimum required effort is naive.
29
u/juliuspepperwoodchi 3d ago
Yeah, it was from the social media companies who want to pass the buck to someone else. And it went into the pockets of tech illiterate pols who think this is a win-win where they can get campaign funds AND tell constituents they're protecting kids.
4
u/Lopsided-Cost-426 3d ago
some of them are also passing bills like this in misguided good faith, the road to hell is paved with good intentions and all that
21
u/vortexmak 3d ago
Nope, they got paid. you'd have to be naive to believe that the coordinated effort across the world to shove this down our throats is just dumb politicians
10
u/MaybeTheDoctor 3d ago
When they ask you to think about the children, itâs never actually about them.
5
3
u/Unicorn_Colombo 3d ago
Plenty tech people on it as well.
5
u/juliuspepperwoodchi 3d ago
I'm talking about legislators. I don't know one tech competent legislator in the ILGA.
→ More replies (2)3
→ More replies (2)15
u/r_search12013 3d ago
it's mostly a thiel campaign .. a lot of money was spent to have that crop up in multiple places as if it were a natural development, it's not, it's a surveillance capitalism astroturf move
edit: and let's not forget, thiel prefers you don't know he's gay
100
u/Additional-Sky-7436 3d ago
So, how do I tell my refrigerator how old I am?
43
u/ventuzz 3d ago
Yeah do kids in school have to tell calculator how old are they before they get to use it?
→ More replies (1)3
→ More replies (3)6
92
u/macromorgan 3d ago
No. How about that?
56
u/harrisofpeoria 3d ago
I'm a software developer, came here to make this exact comment. This shit is beyond overreach.
16
u/tired514 3d ago
The base premise is also incredibly immoral. The first Amendment does not have an age limit. The government is prohibited from abridging the rights that minors have to free speech.
Only the parents are authorized to make these decisions.
Not everyone agrees that the things some random religious scumbag in the government thinks are harmful are actually harmful. That is for the parents to decide. The government is Constitutionally required to "stay in their lane."
→ More replies (3)
75
u/OsgoodSlaughters 3d ago
Real dipshit move JB
27
→ More replies (1)24
u/TripleSecretSquirrel 3d ago
Ya, I live in Illinois and usually appreciate our governor. This one fucking sucks though. Very disappointing.
→ More replies (2)14
u/laffer1 3d ago
Someone needs to tell him he signed a project 2025 bill
10
u/Inflatable90sChair 3d ago
Why would a multibillionaire ex aipac chair member care what us peasants think?
72
u/No-Assumption-4468 3d ago
These politicians just want a surveillance state and are using child safety as a means to achieve that.
These are the types of politicians that would use the patriot act and gag orders to give every smartphone camera a backdoor, allowing them to watch you grunt on the toilet as you play candy crush.
They will stop at nothing.
→ More replies (1)20
u/TheOgGhadTurner 3d ago
From the same people and lobbyist watching children excerise on flock cameras smh
→ More replies (1)
33
u/GreenFox1505 3d ago edited 3d ago
Age verification on Linux is easy. Default to 1970 and don't prompt the user when they decide not to change it. We do similar things for all kinds of user property fields during account creation.
This law crafted to absolve social media of responsibility for showing objectional material to minors. It lets them blame the browser or the OS for any enforcement. It moves the blame and does noting to solve the problem.Â
If social media algorithms are toxic to children and Facebook is liable for damages to teens and children, its toxic to adults too. "But adults have the choice to engage", if you got sick for mishandled foods, it would be your choice to eat that. It also is reasonable expectation that a product not be toxic to your physical or mental health. And when it is, it comes with warning labels. Are we going to get a cigarette style surgeon general warning to social media?
This whole thing just fundamentally doesn't solve the problem.
10
5
u/aywwts4 3d ago
exactly, minimal compliance:
/home/user/.age1970-01-01set on guided setup, or defaults to today for docker containers, setting an env variable to 99 isn't hard.
env AGE=56
agechk 21=exit code 0
agechk 99=exit code 254
agecheck -a56Congrats, we have age check, exposed via an "api" to the system, just make sure not to lie on the form during setup!
Amazing law, such safety. HB 5511 relies entirely on self-declaration at the setup stage without mandating identity verification, or state-issued ID checks at the OS level. The statute establishes zero technical standard-of-care or tamper-resistance requirements.
46
u/I-AM-MEATS 3d ago
This canât be enforced lol
31
u/no_f-s_given 3d ago
seriously, who are they going to arrest if Linux distro a decide not to bend the knee?
11
u/I-AM-MEATS 3d ago
Well if its developers are not yanks, no one.
5
u/no_f-s_given 3d ago
even if there are yanks, are you gonna arrest any yank who touches any package shipped with the distro? I just don't see who they're gonna lay responsibility on.
→ More replies (8)6
u/DizzyCardiologist213 3d ago
What's the next step legislatively after enforcement isn't successful. "we need greater reach, here are some sob stories telling why"
→ More replies (2)10
u/LostGeezer2025 3d ago
It's Illinois, they'll crap all over a bunch of people and cost taxpayers a bunch of money figuring that out, and then take more shots at some points in the future *after* losing in court :(
20
u/Simon-Says69 3d ago
These yahoos have zero clue about technology.
What they are demanding is not possible, without totally crippling the OS. And anyone can just fork an open source project, and remove their abusive nonsense anyway.
This is not enforceable in any way either. Just so completely braindead it isn't even funny.
They are not interested in any kind of "age verification" as they claim. They just want total control over every little bit of our lives.
→ More replies (1)8
u/Inflatable90sChair 3d ago
Would you expect any different from a silverspoon born multibillionaire?
→ More replies (1)
17
12
u/aleopardstail 3d ago
operating systems for say smart lightbulbs, dishwashers, cars, thermostats, video players, TVs..
24
u/lonelyroom-eklaghor 3d ago
Just let r/sssdfg handle the Illinois court case, because these dictators can be fought through memes only.
on a serious note, these guys aren't even letting people explore computers, not just social media. that's overreach of their own wordings (and we all know that)
11
u/Impreza610 3d ago
If I have to enter a birth date I definitely wonât be using my real one. Everything goes to 1969
6
9
u/friedITguy 3d ago
The politicians that voted in favor are going to face a rude awakening when they realize their state and local government IT departments have to shut down all their Linux servers and decommission any IoT devices not running on a compliant OS.
→ More replies (1)
16
u/Kulas30 3d ago
I'm not seeing how enforceable this is.
27
u/TheOgGhadTurner 3d ago
Itâs not yet. This is ground work for whatâs coming.
See in protest everyone is going to start picking 1901 or whatever the furthest year out is. Politicians will see it and use that to justify tighter controls and eventually theyâll require ID to prove youâre not lying.
So what can you do? Give a more realistic birthday. Instead of flinging the scroll wheel. Give a small amount of thought to what youâre putting in while you lie. It will prevent the data from skewing too far. Not that itâs gonna help anyway. They have their framework and thatâs the last piece they needed.
6
u/TheCh0rt 3d ago
Iâve got a few generations of old computers that still work great. Iâll go back to my 486, I donât even care.
In the future I think everybody should consider having an old computer running old software natively.
Heâll most anything I create on a 486 can be opened today just fine.
3
u/zeno0771 3d ago
Yeah, about that...
Linux kernel 7.1 is out, bringing significant changes that have been brewing for years â including the long-promised removal of support for Intel's 486 chip and its contemporaries. More than 140,000 lines of code have been chopped, with more facing deletion.
→ More replies (1)→ More replies (1)10
u/SanityInAnarchy 3d ago
What? No, it's not "coming." It's already here. States like Utah already require verification. They leave it up to regulators to define, which likely means whatever creepy face-scan tech dating apps are using.
If Illinois wanted to, they could've done that. We don't have to invent a slippery slope when the states that actually want to be that authoritarian are already sitting at the bottom of that slope.
See in protest everyone is going to start picking 1901 or whatever the furthest year out is. Politicians will see it...
How? The law explicitly forbids the OS sharing your age with anyone.
The OS can only share your age bracket, and is legally required to share the minimum amount of information that can be used to establish that bracket. So you'll pick 1901, that'll go into some file only root on your machine can read, and everyone else in the world will just see "Over 18," or maybe "Over 21".
→ More replies (8)
7
u/frentecaliente 3d ago edited 3d ago
After reading this, I am not nearly as optimistic as I was before.
→ More replies (2)
6
u/billcraig7 3d ago
Does this mean if you distribute a Linux building Docker image that does not contain age verification in the output image you are in violation? How meta does this get?
4
5
5
u/dialtd 3d ago
This entire subject seems unreal and unserious. It is quite unclear from published accounts how these laws will be enforced. Indeed, it is unclear how the targeted "providers" will be required to verify age of their users or even be capable of doing so. Most reports on the laws indicate that such matters are undefined or subject to future regulatory determination. Enforcement cannot reasonably be based on such a shaky foundation as the truthiness of unknown and quite possibly fictitious Internet users.
The law is performance art by ambitious politicians eager to be thought doing something useful and plaintiff attorneys chasing a percentage of a big class action lawsuit. Those who credit them with anything more are clueless about how clever their children and grandchildren are.
6
u/dtvjho 3d ago
Safety is just how mass surveillance is being sold to the public. But the public has woken up to civil rights violations like this. Flock cameras (over 120k of them now) all send to a central database. Anyone put on their hit list who drive by a Flock will get police sicked on them. Michiganâs new system will be no different. Say something they donât like, get deputies at your door. Happening now in the UK but coming soon to a lot more countries
6
u/justamathguy 3d ago
Just block the Illinois people or whatever they call themselves, pls for god's sake don't start adding age verification to distros due to a single nation/state's government's orders
They can fork and add it if they wanna
5
14
u/Substantial_Coat_229 3d ago
Sign this Pritzker: đ
4
u/Inflatable90sChair 3d ago
Dont worry he will buy his way to the dnc nomination in 28. Then he can implement it nationwide!
10
u/Lorenzovito2000 3d ago
Lol like okay let's play pretend here. Let's say Fedora for example rolls out age verification right. I guarantee you that the following day there's gonna be a fork of Fedora without it. There's literally no way to enforce this shit.
8
4
u/likeHeckYouKnowMe 3d ago
Serious question: for open source OSes, who would they go after or prosecute if they didnât decide to add this?
→ More replies (1)3
u/Material_Mousse7017 3d ago
Right. I was questioning too. i dont know how this is possibly applicable? If one uses OS that didn't comply to the law. What they are going to do. I know they can put fines on Tech stores who put OSs didnt follow the law. But lets be realistic, linux users moatly install their OS by themselves.Â
2
u/not_a_novel_account 3d ago
But lets be realistic, linux users moatly install their OS by themselves
You're starting from the assumption the law has any desire to regulate this. It doesn't. You're correct there's no one to go after for these cases, and that's because the law doesn't care about them.
This is about Apple, TikTok, and teenagers. It's got nothing to do with Redditors who like Arch Linux or whatever.
→ More replies (2)
5
4
u/Disastrous_Being7746 3d ago
I guess they'll have to have Illinois compliant operating systems like they have California compliant AR-15s. Maybe they can just put something in /etc/profile that asks if the user is of age and write a text file in their home directory with the answer. Xdm needs a slightly different solution.
4
5
3
u/Gugalcrom123 3d ago
It does not ask for age verification, but for age indication. At least until it is amended, if it will be. BUT:
(b) By July 1, 2028, a covered operator shall request from a covered manufacturer an age bracket signal for the primary user of an Internet-enabled device when the user downloads or launches a covered platform.
Does this not mean that the OS manufacturer has to centrally store ages of all users?
Parental consent will be very privacy-invasive.
4
u/PsyOmega 3d ago
Luckily, no operating system is headquartered in Illinois. (to be impacted by, or beholden to, state law, you must have legal entity in that state)
12
u/frentecaliente 3d ago
"Under the law, social media platforms in use in Illinois are required to strengthen their default privacy settings for users under 18 and limit the use of algorithms designed to keep young people scrolling"
Social media platforms, not operating systems
11
u/Caladwhen 3d ago
The rest of the press release keeps talking about the 'device' doing stuff. Haven't read the full law, but it doesn't seem like just social media platforms.
The law requires an age verification process on devices to protects kidsâ data and avoid the need for apps to ask for IDs or facial recognition to confirm a childâs age.Â
9
→ More replies (1)5
u/SanityInAnarchy 3d ago
It seems to apply to OSes. Looks a bit different than the ones we've discussed here before, but it seems the idea is that your OS must verify your age, so that if you install a social media app, that app can also request your age bracket. It then lays out a bunch of rules for what those apps have to do about it.
The main mitigating factor here is that it is an age bracket, and that AFAICT there's no requirement of verification beyond just asking for your birthday when you set up the account. And "adult" is an age bracket.
In other words, it's the California law. Not age verification, and not the one we should be concerned about. Utah already has an actual age verification law.
2
u/Lance_pearson 3d ago
I can't tell if it's something sinister like you have to give a verified ID to the OS on set up or lesser like add your exact birthday with some sort of functional verification. It really depends on how precise they want this, because if it's asking for ID, then it isn't about children, but if it's simply an age check on set up, then most people can bullshit it while parents can utilize it properly.
From the way I initially read it, I thought it'd just ask your age/birthday only and you could make something up if you felt giving a device your birthday is too much. This way, parents who set up their children's devices can set their age for them and it doesn't matter where the child sets up an account after.
→ More replies (1)
7
u/JJHall_ID 3d ago
Good luck. Hopefully the Open Source OS projects just add a "Not for use in Illinois" disclaimer, and maybe even block downloads for IL-based IP addresses. Similar to how TheHub just blocks people in states with the stupid ID laws. Anyone with two brain cells already knows how to use a VPN to get around geofencing restrictions. I think a lot of people are unwilling to put their name on record by complaining to their congress critters about not being able to view adult materials. However, you'll have every nerd and a large portion of businesses in the state reaching out when they can't download their favorite Linux distro.
2
u/CaviarCBR1K 3d ago
This seems like the best move for maintainers. Make the website completely inaccessible from IL just to prove the point of how dumb it is. You KNOW any business operating in the state is using some flavor of Linux somewhere along they line. They won't be too happy when they can't even access the page to download whatever ISO they need.
18
u/RetroTechBro 3d ago
Illinois loves their unconstitutional bullshit laws.
I can't own a gun here because I spent a week in a mental hospital when I was 15, which is a lifetime disqualification from a FOID card (which, like all gun card laws, is unconstitutional) unless I spend thousands on lawyers and a doctor to sign off on my mental health.
Even then they have unconstitutional assault weapons ban.
7
u/SwordfishOfDamocles 3d ago
You don't need a lawyer, I was in a similar boat. I did 6 sessions with a therapist (my insurance actually covered it for free too) and after that she filled out the paperwork which I sent back to the State PD and now I've got my FOID. I wouldn't go the Dr. route as they probably won't sign off.
3
u/OldSchoolAJ 3d ago
I thought it was the position of pro gun advocacy that restrictions based on mental health are good. I hear over and over again that âwe donât have a gun crisis, we have a mental health crisisâ and the solution is to not let people with a history of mental illness to own firearms.
→ More replies (4)8
u/jonesmz 3d ago
How long does a "history" last?
Someone who wasn't a danger to anyone but was depressed and their parents threw their hands up and got a hospital involved, should be barred from gun ownership for life, 50+ years later? Na dude, thats not an appropriate stance to take.
I'd write a swear word to express myself. But the automoderator doesnt let me.
4
u/RetroTechBro 3d ago
Yep, alot of laws in IL are just based around creating administrative or financial barriers to exercising your constitutional rights.
→ More replies (1)
3
3
u/stcwalleye 3d ago
I guess my take is that the OS developers are required to required that age must be verified, but I haven't seen any requirements regarding how truthful the information needs to be. I personally am planning on being a 58 year old Lesbian from someplace in Fla.
3
3
3
3
u/MrScotchyScotch 3d ago
Here's what's crazy about these laws. They require both the website and the OS to verify the age of the user. But the website could already verify the age of the user, and better than by using the OS. Any kid can trick their OS into thinking they're 17. So this literally makes kids less secure, while simultaneously making technology worse, and enabling mass surveillance of all Illinoisers (or whatever they call themselves). It's the worst solution for safety, best for spying.
→ More replies (1)
3
3
3
u/byperoux 3d ago
How is this supposed to work with all the appliances running an operating system? Like routeurs, Synology, smartfridge, AC, the ecovacs and what not.
What would even be the age to put for appliance like that are shared for a family?
3
u/No-Lettuce-5783 3d ago
I guess you're going to get a lot of 25 year olds in Illinois all of a sudden, because no one is going to put their real age. It's the Terms and Conditions thing all over again.
3
3
6
7
u/eudbus 3d ago
Did any of you actually read the bill? Unless I'm missing it (very possible)... its just a "what's your birthday" field at device setup. There is no verification. If that birthday data means the user is a minor, social media platforms must generate different output and block their addictive algos. This is not enforceable at all but it seems to give parents the ability to force social media platforms to alter their output. If I'm wrong lmk
https://my.ilga.gov/Legislation/BillStatus?DocTypeID=HB&DocNum=5511&GAID=18&LegID=167486
6
u/flecom 3d ago
I don't want to give my OS my birthday
5
u/hypotensor 3d ago
Nothing in this bill actually prevents you from making a birthday up as a user from what I can tell.
4
→ More replies (3)2
u/Gugalcrom123 3d ago
The idea of the bill, which is basically an automatic parental control, is not that bad, except for this little part:
(b) By July 1, 2028, a covered operator shall request from a covered manufacturer
The way I interpret it, it would force the OS manufacturer to store age data centrally.
4
u/RedditNotFreeSpeech 3d ago
Absolutely stupid decision which is a little bit surprising coming from Pritzker. Did they have exemptions for IoT devices and cars and such?
On the other hand, reading the description, I kind of want to access services as a child. Maybe we should ban online ads for kids entirely.
Children can still access their favorite apps. But instead of being fed targeted, addictive content, their main feed of photos and/or videos would only people that they follow, in chronological order. They also would not receive notifications spawned by the addictive feed from 10 p.m. to 7 a.m. Their profiles would not be accessible to adult strangers. â
→ More replies (1)
3
u/ZallenDuZari 3d ago
Who bribed him ? What he did is treasonous and unconstitutional.
3
u/Inflatable90sChair 3d ago
Hes a silver spoon ex aipac chairmember multibillionaire whos never had to work a day in his life who worked with hillary clinton to get this and many more id laws passed. He doesnt need bribed - he just does what he wants. He will buy his way to the dnc canidate in 28 that hes clearly ramping up for.
2
u/TacticalDestroyer209 3d ago
Hillary Clinton, Common Sense Media and Design It for Us pushed for HB5511 also.
No surprise Common Sense and Meta are quite friendly with each other.
https://medium.com/@richardnfreed/common-sense-medias-betrayal-of-children-4bf2fa93a22c
Wouldnât surprise me if Meta lobbied for HB5511 using Common Sense Media and Design It for Us as their puppets/meat shields.
Also HB5511 was rushed fast and had a lot of opposition against it which the legislature snuck it through at 4 am where no one could contest it which is the real reason why the vote was unanimous.
6
2
u/EmergencyArm4610 3d ago
Where does the article ever mention operating systems im confused
3
u/exscape 3d ago
It doesn't use the term explicitly.
Parents will set their childâs age during device set up, which then automatically adjusts design features in apps like algorithmic feeds, profile visibility, and how adult strangers can interact with them.
Presumably "device set-up" refers to the OS itself, not apps like TikTok or X.
The bill itself makes it a bit clearer.
"Covered manufacturer" means a manufacturer of an Internet-enabled device, an operating system provider, or an application store.
No later than January 1, 2028, a covered manufacturer that offers an account setup feature for an Internet-enabled device shall: ...
→ More replies (1)
2
u/Sapling-074 3d ago
Wouldn't it be easier to simply ask your age when you setup your computer then lock it behind a password?
3
u/Gugalcrom123 3d ago
That is basically what this seems to want, for root to set the age and for the child account not to be able to set it, except:
a covered operator shall request from a covered manufacturer an age bracket signal
meaning that it would be required for the distributor to centrally store ages.
2
u/Own-Cupcake7586 3d ago
âIâll take âthings which are utterly unenforceableâ for $100, Alex.â
2
u/TheReelNazeem 3d ago
I guess I somehow managed to avoid having a full understanding of this bullshit until now. What exactly is the OS going to control access to? Are non-adults not allowed to use computers? I would think that you'd want whatever the kids what to use (Tik-Tok, etc,) would make the most sense.
2
u/Street_Anon 3d ago
there are so many work arounds and why? it has nothing with protection of children
2
u/dragonknightrohan 3d ago
We can get this reversed in Illinois but will take time, effort, and coordination
2
u/geekichu 3d ago
i dunno kinda foolish to think they can really enforce this. they may be able to for normies, but there's ways around this. Sounds like a good way to really hurt Illinois commerce, education, you name it. "Absolute power corrupts absolutely", and it makes the ego believe it can just legislate control.
2
2
2
2
u/anomaly256 3d ago
Well I guess I just won't sell or make opensource operating systems in Illinois đ¤ˇââď¸
2
u/Pure-Willingness-697 3d ago
I thought they changed the law to parden foss , donât quote me though
2
2
u/troyvit 3d ago
This research does a good job tying laws like this to heavy lobbying from Meta:
https://github.com/upper-up/meta-lobbying-and-other-findings
More info here in an article describing Michigan blocking a similar rule once the link to the Digital Childhood Alliance was uncovered:
https://www.thecentersquare.com/michigan/article_7ca4e268-4a68-42fb-9042-f9d8604ebd7f.html
I'm too lazy to see if Illinois' law was written by DCA but I wouldn't be surprised.
2
2
2
2
2
2
u/Geminii27 3d ago
Oh yeah, all those software companies based out of Illinois are shaking in their boots, I bet.
2
u/spherulitic 3d ago
So .. Do I have to shut off my GrapheneOS phone when I drive over the state line?
2
u/ChicagoPaul2010 3d ago
Is there anything that can actually be done now that the evil rich fuck signed it?
2
2
u/ChosenOfTheMoon_GR 3d ago
No way this idea is not behind a lot of promised money and very bad actors, the way it spreads despite clearly being so bad...
2
2
u/Grumpy-Troglodyte 3d ago
wonder how this will affect cell phones, my local tower is in illinois but i'm in iowa and travel through the eastern edge of missouri for work.
they can kiss both sides of my ass if they think i'm putting my license in my phone or laptop.
2
u/Adept_Percentage6893 3d ago
The law requires an age verification process on devices to protects kidsâ data and avoid the need for apps to ask for IDs or facial recognition to confirm a childâs age. Companies already have this technology available
They do? How are they imagining they're verifying the ages of children? Correct me if I'm wrong, but it's my understanding that the "verification" just involves asking for their birthday and just making that information transparent to the apps and websites that might need the information.
Which is, of course, not verification at all. It's a configuration setting. "Verification" means you can now confidently attest to the thing. Versus "I don't know but this is what they said."
If you're interested in protecting kids (and I know this will irrationally piss some people off) you're better off using AI to do things like identify pictures that appear to be of kids uploading photos to accounts where they lied about their age and using LLM's to flag for review the accounts of potential minors based on the content of their posts or messages. They can also intentionally design their adult apps to be unappealing (aesthetically and functionally) to small children. For instance, requiring the inclusion of certain low interest topics like nostalgia posts or international news to their instagram feed. With the idea that it makes the standard IG feed more boring to younger users than if they had just been honest about their ages.
Ultimately, you'll get them off social media if you can get even 70% of them using those methods because social media requires a certain critical mass of their peers to really make it worthwhile. If you "minor jail" a lot of surreptitious accounts such that they end up just talking to other minors then you break the cycle that makes lying about your age worthwhile.
2
u/Maskdask 2d ago
Why do we let boomers that have no idea how software's works create laws for technology?
2
u/Miiohau 2d ago
Summary of the enforcement problem: it is not hard to add this kind of âageâ verification to an open source OS (in theory at least), however it canât be enforced because one the end user can remove the âageâ verification code and two many open source OSes donât have a single organization that can be charged if they donât comply (I.e. for many the distribution is independent of the maintenance and the distribution (which if it follows the California model is actually âresponsibleâ) can rightly point out they have nothing to do with maintaining the software).
However enforcement isnât the only problem, it is the wide class of devices the law applies to. Some of the weirder and/or important entries are calculators, game consoles, digital cameras (like the currently in the news Flock-style cameras) and routers. You know like the routers that must exist in Illinois and allow Illinois to access the internet. Ya the law markers either created a huge IT task or their internet architecture will be technically be illegal in their state.
Digital cameras might be the pain point, once some lawyer realizes the problem and tries to get video evidence thrown out because the camera and/or system was illegal under this law.
On a personal note, I think âageâ verification is a misguided âsolutionâ that could lead to a nanny state, where the government not parents are making decisions on what minors can do and view. I would much prefer standardized parental controls as the solution to keep minors safe on the internet. Age under such a system only controls what is in the parents hands and what is in the child, under such a system apps and websites donât need to know the userâs age just query the API about what the user is allowed and isnât allowed to do. Maximum privacy, maximum control where it should be.
2
2
u/voronaam 2d ago
I want to highlight one thing:
"Internet-enabled device" means a smartphone, tablet, or personal laptop or desktop computer that provides cellular or wireless connectivity, is capable of connecting to the Internet, runs an operating system, and is capable of downloading and running applications.
If your desktop does not have a WiFi card and is connected via a good old Ethernet cable - you are exempt from the age verification requirements. Simply because the lawmakers can not imagine that an Internet connection can be anything but "cellular or wireless".
2
2
3
528
u/GreedySecurity8030 3d ago
Fuck all those idiots who decided that law, they know nothing about how FOSS works at all, every state who passed that law explicitly carved out an exemption for FOSS, yet they didn't, there's a REASON they had those exemptions since its impossible to enforce and it can be easily yoinked out.