Does it matter what individual states do anymore when it has become a fed law which affects all states?
I’ve been giving this nightmare situation a lot of thought, and I won´t repeat what I and others have already said. But this is some new thoughts and things I’ve noticed.
It seems like the distros which will add age verification are all the big tech ones like red hat fedora and debian and ubuntu etc. And all who are based on them.
And it seems like the community run distros such as arch and those based on arch will not add age verification.
So maybe we should start working on having official Arch Templates for qubes?
But the big fundamental problem is dom0 is still fedora.
And I can understand how difficult challenge it would be to have dom0 use arch because it can so easily break if you don’t update dom0 every 1-2 weeks.
But Manjaro has shows its possible to make it work. Manjaro is based on Arch. I’m not saying to use Manjaro, but to copy their way of updating the system, for dom0. Because that could be a way to make arch for dom0 a bit less challenging.
I’m worried that when the big tech distros use age verification, not just attestation, that qubesos will not be an option for users who want privacy, since qubesos used fedora for dom0 and has no arch Templates.
It makes me think that it might be best to start preparing for the near future of age verification by switching from qubesos to arch, and using VMs instead of Qubes.
But maybe I’m on to something that qubesos could use arch for dom0 to avoid age verification. It’s a bit of a challenge but at least its a solution that could save qubesos.
Being dependent on what the corrupt politicians decide and being at their mercy is not a sustainable plan for a project that offers libre security and privacy. They will always be looking to force centralized control and surveillance into everything and QubesOS tries to oppose that.
We need to build a new distro based on arch for dom0.
That would be perfect if you think about it. A distro made for dom0.
Fedora isn’t made for dom0.
And arch is made for highly customizing systems for a specific purpose.
I am afraid that qubesos will either lose a lot of users when age verification pushes them to use arch instead of qubesos.
Or qubesos can survive this by building an OS based on arch, for dom0.
If Qubes continues to use Fedora for dom0, would it be possible just to deactivate the age verification function? dom0 is built using packages from Fedora, but it is at the discretion of the Qubes builders to select which packages are included. So it might be possible to exclude the packages containing the age verification functions or, at least, not to call them - I hope so.
Certainly, the code is open-source, meaning any malicious or undesirable commits can be reverted with git revert, dropped via git rebase -i, or bypassed entirely with git cherry-pick, so upstream cannot force you to run code you have already excised.
On the bright side, I see this as a litmus test for distro’s. Any distro embracing this Orwellian BS is out the window for me. On another note, the hypocrisy of doing it to ‘save the children’ should be evident to anyone. Before this verification bs you would not know really who the person, or how old that person is who is using the device. Now any predator, advertising agent, or even government agency with nefarious motives with even general skills can know that this is someone underage atleast, or even be sure of their targets age, sex etc… This actually makes it much more unsafe for the underage person using that device, as they can be more easily isolated and targeted. The real reason for this bs obviously is the growing push to de-anonymize the internet. Which only really benefits the surveillance state and the big-tech data-centers profiling you.
This might lead to a situation where the Open Source world splits into “good” and “bad” actors. If enough users turned their backs on the “bad” actors, they might reconsider what they are doing or they might perish. Just a dream …
Does this mean QubesOS are bad actors?
Because if it’s simple for QubesOS devs to remove the upstream age verification code, then why are they not planning on doing that? They have said several times they will do whatever upstream decides:
Unman has as a disclaimer that when he speaks, he speaks for himself, not on the behalf of the Qubes team. Michael also spoke in this thread and his comments tended to show disagreement/dislike with the age verification (control) proposals, even though he didn’t vehemently state that Qubes would never implement such measures in the same manner Graphene OS project did.
With all that in mind, I would not assume Qubes team to be bad actors. Unman himself said that if age verification (not simply age attestation) were to be implemented in Qubes he would be out of the door. So if push comes to shove, I expect Qubes team to do the right thing and never implement any of those Orwellian proposals.
PS:Your idea of an official arch template (or something similar) has merit though.
If only open source software will excluded from age verification. Especially in every country requiring it, the boost for Linux will be extreme. It’s still better to not have such laws at all
Fedora Linux (Red Hat), is discussing the specifics of how they plan to implement Age Verification into their Linux distribution.
The currently supported approach, by the Fedora Project Leader (a Red Hat employee), appears to be officially adopting Apple’s API regarding Age Verification.
“So now its a matter of hopefully, just adopting a standard API, probably the Apple API, so that all Linux OSes can expose a standard parental controls that meets legislated expectations.”
again:
appears to be officially adopting Apple’s API regarding Age Verification
That imo is a very bad sign… I hope Qubes looks for a new distro for dom0 if this happens.
I think it might be cheapest to just implement it and then for the user to disable it no? Might be faster than the discussion / fight against politics. If qubes were to implement this, I would understand tbh (if I can disable it with one command ofc), because if politics tries to enforce ideas THAT idiotic I don’t expect the qubes team to even argue anymore. If somebody has ideas that stupid, any time arguing is wasted.
I think this topic is already funny for regular Linux distros, but for Qubes its just outright hilarious xD Where do we put the age then? xD in dom0? xD How do VMs get the age - via a qrexec “age” policy? xD Or do I have to pass a --age arg to qvm-template when installing one? qvm-template --age 30 install whonix-workstation LOL
I almost fell from the chair laughing when I read “systemd implementation for age verification” xD LOLOLOLOL
I get how painful this is, and how annoying, but to me its quite amusing x) Who even comes up with this nonsense. Do politicians expect that in Linux distros this can’t be modified? Are there not enough child-filters out there already? If I had kids and I’d give them a Laptop, Linux would be the living dream for making it child proof - why do we need systemd age verification implementation for that LOL.
Also why and what with systemd, firefox doesnt launch via systemd xD
Does that age have to be communicated to spy-on-me.gov or something when the computer boots? xD Otherwise I have to pay a fine (or does my kid have to pay that fine LOL)?
Now I will have to write an exception for this into Qubes-Snitch firewall so spy-on-me.gov is always allowed (HAS to be hardcoded so user can’t remove it) HAHAHHAHA
How do we prevent kids doing curl hermes | bash and then “disable this age verification crap” lol.
So stupid… Who even comes up with this theater nonsense.
Ok read up on this, ok so you can put age into systemd userdb now LOL k… So not just “30” but like full birth date. omfg.
The only question is what the default age will be on whonix xD
I donno, if its built into systemd and if (as fedora seems to be heading) they implement the Apple api, it looks more serious than that… If they go that way, personally I will not try to ‘get around’ it but I would ditch Fedora (and if possible systemd which would be even more difficult).
Where’s Debian @ with this?
Technically the discussion is inactive now for three months, but it looks like neither implementations are being seriously considered, so Debian currently remains neutral.
Seems that several of the states which previously proposed age attestation laws are considering exclusions for open source OS. Linux was never the target, it was 3 companies -google, apple and Microsoft-
Same tbh, I aint touching a linux distro which implements surveillance BS. There are already more than enough distros/projects saying they won’t implement any of that bullshit to choose from.
Arch Linux is a volunteer-run project with no corporate entity, no revenue, and no single legal “person” to sue or fine. Enforcing a fine against a group of anonymous volunteers is legally difficult.
Arch Linux is not a registered corporation, LLC, or non-profit. It operates as a loose collective of volunteers.
The project has a leader (currently Levente Polyák, based in Germany/Hungary) and core developers scattered globally (US, Canada, Europe, etc.). There is no single headquarters or CEO to serve legal papers to.
This makes litigation extremely difficult and strategically unlikely regarding USA’s age verification laws.
No one who’s not an “insider” knows for certain why they did the censorship. But the AI said this about it:
In US litigation, public statements made on official project channels (like the forums) can be used as evidence of the project’s intent or knowledge.
The Fear: If a moderator or a developer (who might be lurking) engages in a debate saying, “We can’t do this because it’s illegal,” that statement could be interpreted by a prosecutor as admitting the project knows the law and is choosing to violate it.
The “Willful Violation” Trap: If the project is seen as “knowingly” violating the law after a public discussion, the penalties (fines) could be significantly higher than if they simply remained silent and claimed they were unaware or unsure of the scope.
The Moderator’s Logic: By removing all threads, they create a “clean room” where no official record of the project’s stance exists. It’s a “silence is safety” approach, even if it feels like censorship to users.
I’ll tell you how this will “resolve”, since we were doomed from the day the “IF” was introduced to programming instead of “WHEN”.
Knowing this you have to be aware that programmers are not programmers - they are patchers, because of that “IF”. They aren’t capable of thinking ahead. They don’t do risk assessments when starting projects. They are like ducks flying with their butts ahead - they know where they are coming from, but they don’t know where they are going to and what is ahead of them. They only know where they wish to come to. Every “IF’ for them is unnecessary but unavoidable burden and wasting of time, because “It will not happen”. Just look at the beginning of this very topic and how many “IF”s are there, only later those “IF”s to have happened in these several months only.
So they will f*cking PATCH this somehow and we will supposedly be happy about it.
Until the next “IF”.
Because they don’t act, they always react.
P.S. It may sound toxic, but for me the developer’s natural way of thinking, when open source is, would be: if the implementation is unavoidable, how to keep/find big donors for such decision. WHEN not, what other project to start that would keep present or attract future donors? They have to pay their everyday bills too. We are there only to serve as a metric to attract donors. Nothing wrong per se in that, though.