Per the very first reply on their thread discussing it in their forums, which I linked directly to for the post title:

We’ll NEVER require any verification or identification from the user.

However, what’s gonna happen should the attempts to age-gate the XDG portal screw over alt-init distros like Artix too? My guess is maybe they start blocking regions which force age gating like Arch Linux 32 is doing.

  • Rioting Pacifist@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    18 hours ago

    A password is litterally the OS verifying you are who you are claiming to be.

    But making a password doesn’t identify you or verify anything about you, anyway.

    Neither is putting in a date of birth.

    • drayva@lemmy.ml
      link
      fedilink
      arrow-up
      5
      ·
      18 hours ago

      I think there’s some confusion here about the concept of “identification”.

      A date of birth is generally considered identifying information because it can be used to implicate other information about your real-life self, and it can have real-life consequences for you if it is known. It discrimantes and differentiates you from other individuals in ways that have real-life implications.

      What does a password identify about you? Well it verifies that you are “the same person who set the password on the OS”.

      So to compare and contrast, A DOB identifies you as…

      • a person who may not be allowed to install certain programs or access certain information/content, based on age
      • a person in a demographic who may be amenable to certain advertisements
      • (if your system is compromised/leaked and age retrieved) someone who may be desireable by predators
      • (in the context of investigation or stalking) someone who is not a specific other individual (ie it narrows you down from a pool of individuals)

      Having entered a password identifies you as…

      • the same person who set up the OS
      • ??? - feel free to let me know if you’ve got anything here.

      To consider the act of entering a password as an “identity” is pretty bizarre, and frankly the notion seems contrived just to be argumentative.

      • Rioting Pacifist@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        17 hours ago

        Wow sounds like they should only return an age bracket to mitigate most of those risks.

        Also if your system is compromised it’s insane to think your DOB is the problem and not everything else on your system that can ID you.

        • drayva@lemmy.ml
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          17 hours ago

          Wow sounds like they should only return an age bracket to mitigate most of those risks.

          Isn’t it even better just to take nothing related to your age at all?

          …the problem…

          But there isn’t “the problem”; there are multiple problems. Isn’t it good to have fewer problems?

          …if your system is compromised…

          Also it’s not just your system getting compromised that could be an issue. Say you put your age or age bracket in. Then some application or website retreives that, and stores it on their end, mapped to your user id or email or whatever. Then that system gets compromised. Even if your personal computer is perfectly safe and sound, they still got it.

            • drayva@lemmy.ml
              link
              fedilink
              arrow-up
              1
              ·
              17 hours ago

              What about the websites that will store it anyway, despite it being illegal? And what about if the laws change?

                • drayva@lemmy.ml
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  16 hours ago

                  But actually I have a real answer to that question! In that scenario, I would… use a distro like Artix that chooses not to comply with that law 🤘

                  By all of your responses so far, I assume you would just be okay with computer and OS manufacturs obeying?

                • drayva@lemmy.ml
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  17 hours ago

                  Correct me if I’m wrong, by this rhetorical question you’re saying “It’s unrealistic to think that the laws will change, or that websites will break the current laws”. Is that right?

    • VonReposti@feddit.dk
      link
      fedilink
      arrow-up
      3
      ·
      18 hours ago

      No, it is the OS verifying what you know. The OS doesn’t care if you gave your password to anyone, just that whoever is opening the PC knows the password.

      Verifying who you are would be biometric verification or ID verification.

      In my case I require a password and a hardware key on login. That is still not verifying that I am myself, only that I know the password, and have the hardware key. If I added fingerprint scanning then I would have the holy trifecta and only then verify who I am.

      • Rioting Pacifist@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        17 hours ago

        If you think about it like that none of the proposed laws verify anything, even the worst one just verified you logged into the account with credentials for someone who put their DOB in the age bracket returned by the API

        • VonReposti@feddit.dk
          link
          fedilink
          arrow-up
          4
          ·
          17 hours ago

          And that’s why I fear what comes next now that the infrastructure has been set for sharing sensitive data like DoB. Brazil’s law already stated that self-reporting age is not sufficient.