How much do we gotta worry about this Linux "age verification" BS?

if Qubes decides to comply then they should…

remove Snowden from homepage.

7 Likes

Qubes OS is basically a meta-distribution that says “assume breach - contain it”.
Therefore, there’s nothing to worry about. In the future if Linux distros decide to break privacy, then we can finally have:

dom0 - Windows 11 (no telemetry since no network)
Template 1 - MacOS
Template 2 - Ubuntu: Amazon Edition

No need for GPU passthrough for single-player games, games such as Xen: Escape could be installed in dom0 since dom0 would support the latest drivers.

1 Like

US, if want protect the kids, should worry with torpedo and not with tor pedo :man_shrugging:

1 Like

Ok, so your viewpoint is that Qubes should be compliant. Based on that alone, let’s see whether your suggestion would still allow compliance.

That may be hard to square with compliance. It may be non-compliant if erasing the data also prevents Qubes from continuing to provide the required age signal.

I think that is the issue because of this part: Bill Text - AB-1043 Age verification signals: software applications and online services.

Provide a developer who has requested a signal with respect to a particular user with a digital signal via a reasonably consistent real-time application programming interface that identifies,

(b) An operating system provider or a covered application store that makes a good faith effort to comply with this title,

So even if the raw data is erased and only some limited form is kept in encrypted RAM or handled some other way, the system still seems to need to provide a working age signal.

That is not necessarily non-compliant by itself. The data may not need to be stored in the Template at all. It could be stored in a more central place such as sys-compliance.

The important part seems to be that the required age signal must still work. If this design prevents that, then it may be non-compliant.

The “it” is ambiguous. Age signaling API should be on by default or bypass should be enabled by default?

If the idea is that a bypass should be enabled by default, that may also be hard to square with compliance for the same basic reason: the law appears to require a functioning age-signaling system.

Documenting on how to defy the law may be incompatible with:

(b) An operating system provider or a covered application store that makes a good faith effort to comply with this title,

The phrase “good faith effort to comply” might reasonably be read as cutting against officially documenting how to bypass or defy the law. “good faith effort” is somewhat broad and open to interpretation.

That may be compliant. I do not see anything in the law that would prevent user or developer documentation explaining where the data is stored or how the system works.

I do not think that answers the actual concern. The concern is not only about containment after a breach. The concern is that Qubes itself (dom0) might choose to implement a compliance mechanism in the first place, and I think that is what many users are worried about.

2 Likes

Qubes isn’t the one doing the deleting the users are. All qubes is doing is showing us were our data is being stored what we choose to do with that info is up to us. Besides many Qubes users will find where it is being stored anyway and remove it. So when a website or app request for age Qubes can only say “Oops I do not have it.” It is not in bad faith that Qubes tells us where our data is being stored on the OS.

The “it” I am referring to is letting users know where their data is located. A users should not have to turn on some setting to find their data. Sorry for the confusion.

I understand that point and I think Qubes should refuse to comply and refuse to not allowing users from that state to use the OS, but if that dosen’t happen I wanted to present an alternative.

1 Like

Contingency Plan has been developed.

The following is a contingency plan only. It is not a specific implementation plan. It is a thought experiment about the following question: if Kicksecure, Whonix or any other project ever needed such a feature, what might a compliant implementation look like, what would the fingerprinting impact be, and what would be the most secure and privacy-preserving way to implement it? It also includes a graphical user interface (GUI) design draft.

The Age Signaling Prompt that I’ve proposed contains this feature. The graphical user interface (GUI) would show:

Privacy: The entered age is used only to compute the bracket and is not stored. Only the computed bracket is stored locally in the file ~/.age-api/age-bracket.

Furthermore, I also suggested a button:

[ Uninstall age-api (remove age prompts and API) ]

Note:

Status: For up-to-date plans by Kicksecure (and Whonix), see #status.

2 Likes

hi all, the Qubes OS team is aware of this topic and since we distribute Qubes OS with debian, fedora, and whonix templates, we are following the discussions in those OSes (and others). you can track what the OSes are currently discussing here:
https://agelesslinux.org/distros.html

as Qubes OS is built with the security & privacy of the user in mind, we will see if any actions are truly needed by Qubes OS, and if so, minimize them to only users who identify as affected

5 Likes

This is a good feature and there should be no technical measures to stop a user from permanently deleting or modifying this file if they choose.

1 Like

as Qubes OS is built with the security & privacy of the user in mind

“Qubes OS does not claim to provide special privacy (as opposed to security) properties in non-Whonix qubes.”

As discussed in other threads, that part of the docs means Qubes OS per se is not built (intentionally designed) with privacy of the user in mind.

1 Like

yes security is the priority of the project - without a secure foundation there is no hope for privacy. as a small team that is our focus, but it doesnt mean we dont care about privacy…?

“There can be no privacy without security, since security vulnerabilities allow privacy measures to be circumvented. This makes Qubes exceptionally well-suited for implementing effective privacy tools.”

“The short version is that we try to respect your privacy as much as possible. We absolutely do not sell any user data. In fact, we go out of our way to help you keep your data private from everyone, including us. For example, from the moment you install Qubes OS, we offer to set up Whonix so that all of your updates are routed through Tor.”

2 Likes

Ok, It’s lawfare.

Brainstorm about how to fight:
A) Take political power back and change the law.
B) Fight law with code.
b.1) “sys-complience”
b.2) New business: fake identities for age compliance.
C) Fight law with law.
c.1) Jurisdiction (e.g. EncroChat case)
c.2 ) German Census Act (1983)
c.3) Journalist/Lawyer rights
c.4) Parents responsibility with their kids
c.5) Insert age verification army targets, law of war, UN
c.6) Contradiction point: every year there is a data breach, why collect more data? (GDPR !!!)

1 Like

@michael

but it doesnt mean we dont care about privacy…?

We care about privacy != Qubes OS is built with the privacy of the user in mind. Neither it means the privacy policy is correct. That’s a whole other topic.

FWIW, even the links you are sending resolve to Clouldflare addresses - ironically, Californian. :slight_smile:

1 Like

i’m not interested in getting into unrelated discussion sorry <3

just to add to my post above, i haven’t found any discussion on xen mailing lists on this topic, which is probably the most relevant OS context for Qubes OS.

2 Likes

Update Kicksecure / Whonix status to reflect current plans by ArrayBolt3 · Pull Request #1 · agelesslinux/agelesslinux.org · GitHub

5 Likes

And in my opinion the fact Qubes , Whonix and other os is considering to obey to this law is a shame

There were a lot of factors why foss is even possible. Main reason is Freesoftware foundation. They remade all main unix tools. And Linus decided to use one of licenses they made for his kernel

The rest of foss growth happened because corporations are greedy by their nature. And paying nothing for software is ideal for them. People being able to run it on their desktops is just a side effect of it

If fsf or similar organization didn’t exist. If corporations weren’t using foss software for their benefit there would have had been no computing freedom

OS devs when starting their time consuming hobby didn’t care about privacy. Each person behind Debian/Fedora/Xen is already known from the start. So it’s extremely easy for the law enforcement to find them. Foss devs usually lack money and maintain their projects for free. If corporations like Microsoft pay those fines just as operation costs for foss community these fines are fatal

Because of these reasons protesting just by civil disobedience won’t work. Especially due to reasons outside of software world. Mainly current state of politics in the country where a lot of foss devs and specifically distro devs are located

2 Likes

Well … I think it’s a bit more complicated.

3 Likes

@tokaso80

Because of these reasons protesting just by civil disobedience won’t work.

You should explain how exactly it won’t work. As explained, every user is a provider. If your suggestion is that the government of California will sanction every civilian worldwide who learns how to remove a potentially existing age verification module from the undefined abstraction AKA “operating system”, and therefore we should all be obedient, then this is basically making the 4 freedoms globally illegal, i.e. all FOSS is illegal => a threat => terrorist, antivaxxer, needs a regime change, etc.

3 Likes

I won’t be surprised if it’s their end goal. To just outright criminalize FOSS

4 Likes

Civil disobedience won’t work because they go after devs first not users.

Enforcement will focus on devs not users.

Punish one terify thousands. That’s how it works.

By the time they go after users if that’s even realistic all devs are either punished or complying.

1 Like

I’m Brazilian. Law 15.211 (Aka: ECA Digital) is being interpreted in an extremely broad and disproportionate manner. The law does indeed state that operating systems must verify users’ ages, but the Brazilian Civil Rights Framework for the Internet itself protects free software (open source or FOSS). There are no isolated laws. Although midnightBSD stated that Brazilians cannot download the system because they cannot comply with the law, this does not mean that Linux—specifically, Linux distributions—will be banned. Debian itself has a parental control app, and there are several apps that can be installed, so I don’t understand why there’s so much concern on the part of operating systems. At least in Brazil, there will be no ban on Linux distributions; they are not the target of the law. And there’s also the LGPD, which is now recognized as equivalent to the GDPR—meaning they can’t just go around asking for everyone’s personal data. The ANPD (National Data Protection Agency) will open a public consultation on what will be done in practice, what works, and what doesn’t. So, regarding Brazilian law for now, it’s just alarmism stemming from an extremely broad interpretation.

3 Likes