// blog · Privacy

Age verification hits Linux distributions

GrapheneOS says no

GrapheneOS announced that it won't implement the age data collection that a wave of new laws demand. It will remain usable by anyone, anywhere in the world, without requiring personal information, identification, or an account. That has always been the ethos, and it's the way every operating system should work. You shouldn't have to plug your government ID into your phone, your computer, or your fridge just to use it.

This stance was expected. GrapheneOS is a privacy-focused Android fork; refusing to collect age data on the device is consistent with everything else they do. But what's more interesting is what's happening across the rest of the operating system landscape, and especially in the Linux ecosystem, where the responses are surprisingly varied.

Windows rolls over

Windows has already implemented age verification on the OS. Coming to a Windows machine near you: put your government ID in here. They'll make sure it's safe, they promise. Microsoft folded without much resistance, which is consistent with their general direction of travel. But the Linux ecosystem is where things get genuinely interesting.

systemd folds, the community forks

systemd, the init system that sits at the core of almost every mainstream Linux distribution, merged age verification support in March. A community revert attempt was rejected. The conversation was locked after 945 comments. The feature shipped in the stable release in June, along with a companion xdg-desktop-portal changeset.

But this is open source, so the fork appeared immediately. A project called "libertated systemd" strips the age verification field out. Distributions that aren't interested in digital IDs for their users will simply use that fork instead. This is how the open source ecosystem responds to pressure that the corporate world can't resist: it splits, and the version without the surveillance wins over time.

The distro-by-distro response

There's a website, agelesslinux.org, that tracks where each distribution stands. The responses are all over the map:

Ubuntu is "watching." Fedora is "exploring." Debian is "discussing." System76 is politically opposed and actively lobbying, but hasn't committed to refusing. Arch Linux didn't respond at all, which, honestly, is the best response.

NixOS, which I run on all my servers, has a privacy focus baked into its DNA, so its position is interesting and worth watching. Midnight BSD shipped it without protest. Arch Linux 32, a legacy fork, took the bizarre step of excluding users in California and Brazil from downloading their own product, which is hilariously futile, since anyone can just use a VPN.

David Heinemeier Hansson's Omakub, an opinionated Arch fork aimed at developers, which I use on one of my laptops as a daily driver, straight-up refused. That's the right answer.

The same pattern as the Online Safety Act

This mirrors what happened with the UK's Online Safety Act. Ofcom, the body that enforces it, threatened companies with fines of up to \u00a317 million or their annual turnover. Many companies, even those outside the UK, folded and implemented age verification. But 4chan and others just laughed, because they're in the US and aren't beholden to British law. The threat only works on entities that have something to lose in a specific jurisdiction.

For the open source community, these measures are temporarily working. But all that's going to happen is what always happens with open source: it forks, it splits, and people move to the version that respects them. systemd forked. The distributions that shipped the surveillance will see their user base drop as people migrate to the forks.

You can't stop open source

Even the regular non-technical person, when their browser starts requiring an ID to do the most basic things, is going to look for alternatives. And the alternatives will be there, because the open source community builds them. It always does.

Some of the larger community projects and proprietary software that have already implemented age verification are probably going to have to take a really hard look at their position in 12 months' time. When users leave, the calculus changes. The only way to fight this is to make good decisions with your own digital privacy, and to support the projects that refuse.

It's not as doom and gloom as it looks. The open source community and privacy advocates are going to code around it. We might have to make some exceptions in the short term, but in the long term, you can't stop open source software.

GrapheneOS Linux Age Verification systemd NixOS
← Back to blog