- cross-posted to:
- technology@lemmy.world
- cross-posted to:
- technology@lemmy.world
“It’s just a harmless field; what’s the big deal?”
The big deal is that it’s on the heels of age verification bullshit that fascists are pushing through with the help of tech bros, so that they can eventually push all of us into a scenario where we have zero privacy.
It’s not the adding of the field itself or the fact that it can be filled with nonsense. It’s the reasoning backing it.
“But it’s the law!”
Yeah, fucking and…? It’s a stupid mass surveillance law disguised as a protection, and per usual, it’s written like vague dog shit. This is the smallest part of the wedge. More will come of this and if developers like this keep volunteering themselves to help the fascists, we will all be fucked. Here’s an alternative approach: just don’t add this. You can fight back by not fucking implementing this. Easy.
“But it’s the law!”
I was just following orders!
this same person would be chuckling to themself about how pointless this all is as he locks the door on the gas chambers.
Also, they will use it as a means to lock content they don’t want. Like in some jurisdictions it’s already forbidden to share any kind of LGBTQ information even medical with minors… Even in EU, like Hungary. Clearly this age verification will be used for this too. And people not willing to age verify will be locked out too.
It’s part of their campaign of forcing conservative ‘values’ onto everyone.
Agreed. To elaborate:
Sure, the developer is a bit of a Judas for complying in advance, but our anger should be aimed at the people with power and reach promoting these laws in the political sphere (the metaphorical Pharisees).
To those saying “it’s just a field”, please consider that the timing is a more significant statement than the addition of the field itself. Why now? If you don’t support fascism, don’t build the frameworks that support it and don’t let fascists use YOUR platforms or software to make THEIR point, make them fork it and let them fail. I don’t think many members of the senate or house would be capable of adding this themselves. I’d be surprised if they could code hello world in TI-83 BASIC. If they ask you to do it, stub your toe and call in sick. Make it really shitty. Leave in a bunch of bugs that crash the program then blame the age attestation feature to turn users against it. Use copywrited code that they’ll have to remove later due to license incompatibilities. Report your boss to HR for every indiscretion that you might have normally overlooked. Or do nothing; that’s still better than complying in advance.
We have to break the narrative that this is inevitable. There’s enough of us, with concentrated enough knowledge and influence (aka, you folks are a bunch if nerds and I love it!), that if we collectively stop, the whole train stops or derails.
More will come of this and if developers like this keep volunteering themselves to help the fascists, we will all be fucked. Here’s an alternative approach: just don’t add this. You can fight back by not fucking implementing this. Easy.
Only thing you get out of this compared to the alternative of malicious compliance is opening yourself up to attack. You can still fight this without painting a big target on your back.
2000s: war on general purpose computing because of copyright
2020s: war on general purpose computing because of child protection
In the 2000s the forces of freedom mostly won, e.g. https://en.wikipedia.org/wiki/Consumer_Broadband_and_Digital_Television_Promotion_Act didn’t become law. So far it seems that we are currently losing. :(
In Europe too, chatcontrol keeps being pushed no matter how often it’s being struck down.
Yes; recent news have made me somewhat optimistic that the resistance to it is winning though.
Age verification laws currently look like a much greater danger to freedom.
Personally I think that win (while really a win) is being overcelebrated.
It’s easily reverted. All they’ll have to do is find some csam or terrorism related scandal in the news and pump it as a big deal, and all the resistance will be gone at the next vote.
With chat control we actually have to distinguish two different things that people sometimes confuse:
- voluntary chat control (“chat control 1.0”), which is currently already the law in the EU
- mandatory chat control (“chat control 2.0”), proposed in 2022
Voluntary chat control is about letting operators of communication services voluntarily scan messages for certain illegal activity (without this constituting a violation of data protection laws). This doesn’t break encryption and isn’t a part of a war on general purpose computing. While there are many good arguments against it, it’s not especially catastrophic. It’s a detail of business regulation.
Mandatory chat control is about forcing them to do so, which must necessarily break encryption and impose limits on software freedom. This is what is most important to oppose.
The most recent win ended up rejecting even (most) voluntary chat control, which is a good sign that mandatory chat control won’t get a majority either.
It has very nearly got a majority several times. I’m sure that with some media manipulation (eg milking an incident) it will be easily pushed through.
Imagine if the Dutroux scandal would happen now. They’d jump on that to push all kinds of monitoring on everyone. Even though this would not be prevented by it in any way (and in fact that all happened long before WhatsApp even existed)
It has very nearly got a majority several times. I’m sure that with some media manipulation (eg milking an incident) it will be easily pushed through.
“Several times”? There were two votes to date.
The only “majority” we’ve been hearing about were the “these governments support this idea” maps, which have minimal bearing on how the EU Parliament actually votes.
Correct me if I’m wrong.
I hear you 100%. This sort of shit comes back with a different name each year. I am SOOOO sick of voting down abortion bans every election cycle.
26 US states, including mine, have initiative or referendum processes allowing citizens to place an issue on the ballot. In some states, that’s how the anti-abortion laws are ending up on the ballot, but we an use their own tools against them. In many states, these initiatives failed so we know we have a minimum of 51% support if it’s a law, and at least 33% support if it’s an amendment (depending on that state and their rules). Polling shows, an even larger percentage, most Americans, do not support these laws. The numbers are on our side.
https://ballotpedia.org/States_with_initiative_or_referendum
If we can collect enough signatures, the voters can put an end to this. If we add it to the state constitution, where the process allows this, we can completely prevent laws doing this from being considered because the only thing that can overrule a constitutional amendment is another constitutional amendment.
I’m gauging interest to do this in Colorado to foil age attestation laws, but we could potentially end the back and forth bullshit in multiple states.
I love the level of disdain the linux community has for this kinda bootlicking.
What a pointless drama article this is. FLOSS software does stuff for legal compliance more often than you’d think. The whole point is people can contribute fly by patches and the maintainers make the decision to merge. It seems like being an optional field but potentially providing useful functionality is enough for systemd. If you don’t like it I’m sure there are forks you could join or even use a different init system. No one’s freedom is being oppressed here.
What a pointless drama article this is.
Yep. The crypto ticker at the bottom of the page is the cherry on top!
It’s brigading harassment on a volunteer dev, the post should be nuked this is just doxxing for ad revenue… disgusting
It was posted by Yσɠƚԋσʂ themselves, who moderates several lemmy.ml community. I agree it should be nuked, but it’s not going to be nuked.
That’s good to know, I don’t want to be supporting communities which allow this kind of toxic garbage
It’s literally an optional birthDate field in a place where there’s already realName, emailAddress, and location. If you’re concerned about privacy, maybe don’t expose your real name, email, and location.
And it’s not even fucking installed everywhere:
$ userdbctl Command 'userdbctl' not found, but can be installed with: sudo apt install systemd-userdbdAnybody who is calling this age verification is actively lying to you!
This Sam Bent guy should fucking get bent.
My OS should have no details on me besides the account name which didn’t necessarily correspond to my real name.
It does have some old fields for location etc but those stem from the times of massive multi user systems.
Linux has similar fields for realName, emailAddress, location, timezone and more. But like birthdate, I think they’re all optional.
Was Linux ever used for massive multiuser systems? I thought it had always been primarily home use and internet servers. I think big multiuser systems went out of fashion with Solaris. Well, I suppose corporate workstations need user accounts where some of these are set.
No Linux as such was not, by the time Linux got popular the big multiuser systems were on their way out. I still worked on those in college. But they were SGI, HP-UX and Sequent. Especially the latter were huge systems.
But these fields were just a clone of what was in the original Unix systems.
Dylan is a lowlife fucking looser

Lots of disingenuous comments in this thread regarding the change being “just json” considering they’re already on a warpath of implementing id verification. They are testing the water to see what they can get away with. Furthermore, the Linux community has always been against shit like this (see: systemd outrage, open bios, gnu etc).
I’ll believe that if and when they actually force me to upload identification to prove that my birthday really is 1970-01-01 and my name really is Nunya Bissnis. Otherwise, it’s really no different from Steam asking my birthday when opening store pages or porn sites asking “click here jf you’re 18” and take my word for it.
So long as it’s being enforced just as well as the realName field, I maintain that it is indeed harmless. If the point is to have a hilariously ineffective solution as a fig leaf against a stupid law, I’ll prefer that to efforts to actually implement verification.
It’s not harmless, that’s the thing. Its just the thin end of the wedge.
“Do not comply in advance.” There is simply no need for this. Resist because it’s our duty to do so in order to keep our freedoms. Start with, “why are they doing this?” Then go follow the money. Zuckerberg and Meta, that’s why. They have been under the gun for years to protect people, especially minors, from the harms of their attention based economy of apps. They hired lobbyists in multiple states to push this legislation. Why? Because if the OS does it, they don’t have to, and can blame all the problems on the OS. What’s the Meta business model? Gather data and sell it. The more accurate and targeted the data, the higher the price. What do these laws do? Add more data. Why doesn’t Apple, Google, and Microsoft resist? They already have the infrastructure and are data gathers themselves. Why does the government allow this (US and all 5 eyes)? They LOVE surveillance.
Sincerely, thank you for spelling it out to the rest of the class.
These things are always worded ‘agreeably’ enough that by the time we’re done going back and forth debating it all day, they’ve pushed even more invasive policies on us.
I try to explain to people a lot. If you like freedom, and you want to keep it, it’s a constant fight. The power structures are far more profitable without it, so they’ll undercut it every chance they get. “Give an inch they take a mile.” Don’t give them the inch.
We are well past the thin wedge. The thin wedge was American companies purchasing every tech company or stealing their ideas.
I’ll believe that if and when they actually force me to upload identification to prove that my birthday really is 1970-01-01 and my name really is Nunya Bissnis
It’ll be too late by that point. Way way way too late.
Then its already to late. We are well past the point of fighting for freedom and privacy on the net. Hell we let the net be bought up and controlled by 5 companies. And people happily use them and complain about big tech on reddit. Lime WTF.
I doubt those changes would be PRed, merged, updated in my distro and somehow automatically pushed to my system in the blink of an eye. This isn’t Microslop we’re talking about who can force-push intransparent “fuck your settings” at the drop of a hat, and I’m certainly going to be much more wary of upcoming updates now. This isn’t my point of objection (yet - mandatory entry would be), but definitely a point of caution.
If they stick to malicious “here, you can ask for a date, but we can’t guarantee which date, if any, you’ll get” compliance, that isn’t perfect, but it’ll be good enough to make a joke out of tracking the date at all.
Besides, just this change being minor would be no reason not to keep pushing back against the law and airing our discontent about the direction they’re heading in, because the direction is definitely concerning.
Your real name and location data have been stored in UNIX/Linux for over 60 years. https://en.wikipedia.org/wiki/Gecos_field
realName and location have been fields in systemd since the beginning.
Were you panicking about this before social media told you to be afraid?
Your real name and location data have been stored in UNIX/Linux for over 60 years.
IF you entered that info. And it wasn’t being used by applications to enable surveillance laws. It’s a false equivalency.
Lots of disingenuous comments in this thread regarding the change being “just json” considering they’re already on a warpath of implementing id verification. They are testing the water to see what they can get away with.
https://en.wikipedia.org/wiki/Slippery_slope
Argue against what is happening, not fictitious and hypothetical scenarios that are not happening.
Furthermore, the Linux community has always been against shit like this (see: systemd outrage, open bios, gnu etc).
We’ve had fields for storing way more personal information (like real name, home telephone number, location, etc) since 1962. https://en.wikipedia.org/wiki/Gecos_field
There is nothing that a birthdate will tell about a person that their real name and location will not.
The criticism here needs to be aimed at the laws and politicians. This article is whipping up a lynch mob against a volunteer developer using a clickbait article for the purposes of ad revenue.
I still don’t understand why it needs to be implemented as part of systemd, and not - say - as a service. Or, if we want to “go with” the law - make it a kernel module, which sounds more impressive (“we are complying at the kernel level!”) but in practice so much easier to opt out of.
I don’t see what’s wrong with implementing it as an add-on to the https://en.wikipedia.org/wiki/Gecos_field as the PR in question does. It’s the most logical place as the location to store user information and is even easier to opt out of—you just edit a file—than choosing whether to compile Linux with/add to DKMS a kernel module.
Edit: One can see https://github.com/systemd/systemd/blob/8878df45c1a58afdfb500fdc53ec50e057a240ce/docs/USER_RECORD_BLOB_DIRS.md?plain=1#L103 for an example of a user record file and its path. Further documentation you can read at https://github.com/systemd/systemd/blob/8878df45c1a58afdfb500fdc53ec50e057a240ce/man/systemd-userdbd.service.xml#L36 and https://github.com/systemd/systemd/blob/8878df45c1a58afdfb500fdc53ec50e057a240ce/docs/USER_RECORD.md .
Nobody paid him to do this. He’s a cloud engineer who read the law and decided someone needed to implement it.
Well, how do you know that?
Ah the great betrayer. The snake in the garden. The enemy within the gates. That fucking cunt.
Genuine question, don’t we always say that we can change anything in the system on open source software like Linux and systemd etc? What’s stopping any of us from removing this age verification thing? Apps may break, true, but I’m sure there will be many one line scripts that replace that age verification with something that feeds it fake data?
Someone could fork systemd.
Also, some major distros might decide to use the fork
There are a few forks already like https://github.com/Jeffrey-Sardina/systemd and more will pop up for sure. I will try to build it maybe at least I can help with some infra to build it + an AUR package.
I never doubted the forks for a freaking second. That’s why however I think about it, I feel like it won’t work with free open source. Unless the government burdens the app developers to make their apps require age verification to an external source then distribution will have to implement it. Not sure how this shit is going to pan out. Fuck Zuckerberg
deleted by creator
Be careful now! His coworkers will act most silently.
You know what, at this point they can totally fuck systemd and I won’t care anymore.
Half of my machines were running sysvinit already, I’m freeing from systemd the other half, also exploring other Linux distros that took a stance against this and even BSD.
If everything fails, there’s always Linux from scratch.
Next they will mandate a “race” field, and the same kind of imbecile will implement it.
Test your understanding of the Dylan Taylor age verification story and what it reveals about open source infrastructure
I’m very suspicious of whether one would create 10 questions for nearly every blog post of zirs by hand.
It’s for sure AI generated, but also a weird ass thing to add to your blog.
I disagree with age verification as well, but attacking a person like this is gross.
This article is all but brigading people into harassing this guy.
A spade’s a spade. This is malicious compliance. The law might be the problem here but it’s on us to resist and try to make a change. Every last one of us. After all, the surveillance state workers in China and Russia are all just doing their jobs right?
Why the heck would we ever want a DoB field in systemd, optional or otherwise?
The systemd PR also referred to a flatpak PR who said they had wanted that to allow for parental controls even before the law came. That’s a somewhat reasonable use case, in my opinion.
Why the heck would we ever want a DoB field in systemd, optional or otherwise?
There is a field for your REAL NAME and LOCATION also. Who would ever want that?
Both of these fields contain way more identifying information about a user than birthDate. Do you feel the same way about them? Because they’ve been in systemd since the beginning.
and the GECOS field (https://en.wikipedia.org/wiki/Gecos_field) containing fields for your real name, work address, which room in the building you work in, your home and office telephone numbers and external e-mail have been in UNIX/LINUX since 1962
This is manufactured outrage, the article is doxxing a person and painting a literal target on their head by photoshopping their picture to look like a mugshot in order to drive traffic for ad revenue.
It’s one thing to be against the laws, I’m against the laws. It’s another thing to personally attack a developer, that’s way beyond anything that is acceptable.
Timing’s a bit shit to add a DoB field don’t you think. I also don’t think you can compare computing in a professional setting in the 1960s to modern day surveillance states. I can also say as a parent there’s only one thing protecting your kid from the internet and its not whatever poorly standardized notion of Linux parental controls that exist today. Only actual parenting can.
As for the developer’s publicly observable commits and the following publicly available criticism of it, you can call it painting a target but I think even that’s a bit of a stretch. What’s most outrageous about the institution that is the United States of America in 2026 is how all of it was even allowed to get so far. So yeah, expect some activism.
I also don’t think you can compare computing in a professional setting in the 1960s to modern day surveillance states.
My point was that the fields themselves are no more dangerous than we make them. The GECOS fields are not a thing that used to exist in the 1960s, they exist in your system in 2026.
My point was that the criticism here isn’t about the field, because there are way ‘worse’ fields that have existed for decades. The criticism is about the law and this is a kind of misplaced activisim. Where it goes wrong is deliberately targeting one person for harassment as if they are the scapegoat for all of these age verification laws.
I can also say as a parent there’s only one thing protecting your kid from the internet and its not whatever poorly standardized notion of Linux parental controls that exist today. Only actual parenting can.
I completely agree. These laws are worthless for their stated goals because, as you’ve said, it is a parenting problem.
As for the developer’s publicly observable commits and the following publicly available criticism of it, you can call it painting a target but I think even that’s a bit of a stretch.
They photoshopped his face on a mugshot like he’s a criminal and in the article they list his full name, job title, place of work and the state and city where he works. They also list his personal blog.
In addition to all of the personal details, the wording and framing of the article make it sound like an after action report on a cyberattack
Here’s some select quotes. This isn’t about activisim about a law, this is about painting a person as evil, bad, etc (and if you look at the comments in this post, that framing worked.
He hit three separate projects in one week.
Taylor believes what he’s doing is right, which makes him harder to stop than someone acting for money.
The argument is ideological, so persuasion is off the table.
“He’s going to be hard to stop and you can’t persuade him”
The word for what that is sits somewhere past malice, something more insidious:
Taylor already has the resume line and knows the codebase well enough to try again.
“He’s going to do it again!”
This kind of framing against a person is dangerous. If you stir up enough people on the Internet you’re going to stir up some people who are unstable and willing to act on this violent framing.
I agree that the laws are wrong, but this kind of personal attack is far, far more immediately dangerous.
Ask yourself, if it was your picture in the mugshot and your personal address being plastered all over Reddit would you feel safe?
https://github.com/archlinux/archinstall/pull/4290 his motivation is crystal clear. Its compliance before it’s even required. Not just for Californians but for me in Canada, too. This is why he’s on the angry end of activism. He’s proactively helping Linux become a state surveillance machine.
You can make whatever further strawman arguments you’d like but I’m pretty sure a Spade’s a Spade. He may not be a “criminal” but you bet that everyone who resists this crap in the coming years will be if we keep this up. Resist.
deleted by creator
He got a huge amount of criticisms and negative comments from the community while he was working on this on GitHub; look at the comment thread of his implementation on GitHub. Essentially the community was telling him “we don’t want this”. And who are you working for in a FOSS project, if not for the community? Yet he disregarded the comments and went on.
On top of this, he appeared out of the blue with this implementation. He had not made any pull requests to this git before now. Nobody had assigned this task to him.
So the situation is not that this is some employee who was asked to implement something, and did it without knowing what the feedback would have been.
Spreading his face around doctored as if it were a mugshot in a community where people are calling him a traitor and other things is a recipe for someone to be hurt or killed.
This thread isn’t a community discussion about implementing a feature, it’s people trying to whip up a mob to attack a person. It doesn’t matter how much you dislike the field name he added to a JSON document, you don’t stir up a mob that can lead to people getting hurt.
In principle I agree with you, pacific discussion and democracy should be the way to go. But it seems that “discussion” doesn’t lead anywhere these times. Politicians do whatever they like (or what lobbies tell them to do), without checking if the majority of the population really agree with some decisions. A developer does whatever he likes, without bothering about the more or less pacific feedback he gets on github. Nobody really seems to want to have a discussion. Well guess then what the “mob” does at some point: they don’t care about discussions anymore either, and they do as they please too.
I fear that riots will start on a larger scale. Even if the context today is different, the situation reminds me somewhat of what happened with the 1981 riots in Toxteth, in Brixton, and other previous riots. Unjust or misused laws; deafness of authorities about discontent; innocent and not-so-innocent people getting hurt.
A developer does whatever he likes, without bothering about the more or less pacific feedback he gets on github. Nobody really seems to want to have a discussion. Well guess then what the “mob” does at some point: they don’t care about discussions anymore either, and they do as they please too.
It’s pretty cliche but: Two wrongs don’t make a right.
In the FOSS world, there are many ways to handle this kind of situation. A mob-led harassment campaign is not one of them.
If you disagree with how a project is going then you can fork it. LibreOffice disagreed with the direction of OpenOffice and forked it, NextCloud and OwnCloud forked from one another when there was major disagreement.
At no point should volunteer developers have their face plastered on a mugshot and their personal information blasted to a mob of angry people.
Be angry at the politicians and mega corporations who are voting and funding these initiatives, not the developers who are caught in the middle.
Yeah no how about fuck that. Politics is personal.
If you’re participating in a lynch mob then I believe you’re responsible for what happens.
If you don’t see a problem with this, please provide us a picture of your face, full name and place of work.
Yeah, Its is sickening and goes against the spirit of open source. We work around restrictions in creative way to give people the freedom to control their software and have access to the source. We don’t deny people trapped in shitholes with bad laws access to open computing. Force them onto Windows and Apple. I don’t get what is wrong with people these days. They have lost all reason.
Yes, many people can work around the laws in various ways. And some of them can’t. Its not for us to judge. We offer possibilities. Everyone knows many distros will patch this field out. Many will just ignore it like we do the GECOS fields. And where it is unfortunately required it is still going to be better than running Windows. Its completely orthogonal to political participation and fighting these laws.
I don’t see how engaging in malicious compliance is being a useful idiot. Implementing the entire surveillance mechanism free of charge, that I would call being a useful idiot.
Purposefully implementing a broken feature to satisfy the letter of the law, while preserving the user’s ability to avoid the surveillance mechanism is certainly not that.
How is it malicious compliance if it is a clearly eager effort to correctly implement some of the prerequisites to enforcing this law on Linux? Even if it were malicious compliance through intentionally not functional code, it’s open source and would probably be spotted as a bug soon enough.
















