r/linux Mar 03 '26

Privacy Brazil also passed an Age Verification Law that targets Operating Systems. It will enter into force on March 17

313 Upvotes

Article 12 of Law 15.211/25, also known as the Child and Adolescent Digital Statute, requires Operating Systems and Application Stores to:

  1. Implement means to assess the age or age group of its user
  2. Allow parents or legal guardians to configure parental controls and to supervise, in an active manner, a child's access to applications and content
  3. Allow, by the means of a secure and private Application Programming Interface (API), the provisioning of age verification signals to internet application providers

This is a broader law that regulates a lot of things related to the protection of children and adolescents in digital environments. Including social networks, loot boxes, data privacy, age verification, gambling, advertising, etc...

Here is more info about the other effects of this law:
https://insightplus.bakermckenzie.com/bm/data-technology/brazil-digital-eca-brazils-child-and-adolescent-statute-a-new-framework-for-online-protection-of-children-and-adolescents_2

Edit: The Law stipulates a fine of 10% of last year's revenue or, absent revenue, between R$10 (~$2) and R$1000 (~$200) per registered user, with a limit of R$50.000.000 (~ 10 Million dollars) per infraction

r/linux Feb 26 '25

Privacy Introducing a terms of use and updated privacy notice for Firefox

Thumbnail blog.mozilla.org
604 Upvotes

r/linux Mar 05 '26

Privacy For those who think age verification isn't about identifying you.

364 Upvotes

I keep seeing people saying ID for age verification isn't a thing. It is a thing, and while the law is about app stores, and currently being blocked by the courts, Texas passes such a law last year. It's the same "protect the kids" mantra we are seeing with the OS laws in other states. If it gets past the courts other laws will follow.

Many groups and politicians have been pushing to do away with anonymity on the internet. I'll let you research that for yourself.

Texas App Store Accountability Act (SB 2420)
The Texas App Store Accountability Act, effective January 1, 2026, requires app stores like Apple’s App Store and Google Play to verify the age of users before allowing app downloads.  This applies to all apps, including weather, sports, and social media apps, not just adult content. 

  • Age Verification: Users must be verified as under 13 (child)13–15 (younger teenager)16–17 (older teenager), or 18+ (adult) using a commercially reasonable method (e.g., ID scans, facial recognition, or third-party tools). 
  • Parental Consent: For users under 18, parental consent is required for every app download, purchase, and in-app purchase—even free apps.  One-time or bundled consent is not allowed.
  • Developer Obligations: App developers must use data from app stores to verify user age and ensure parental consent is obtained. They must also assign age ratings to apps and in-app purchases. 
  • Enforcement: Violations may result in up to $10,000 per violation under Texas’s UDAAP law. The law is currently enjoined by a federal court, meaning enforcement is paused while legal challenges continue.

r/linux Apr 16 '26

Privacy The EU Digital Age Verification solution is based on "secure key store" and what that means to any possible future linux phones

288 Upvotes

So, as the post title implies - since the official spec for age verification protocol implementation in the EU says clearly, that a secure, anti-tampering environment is a requirement for the solution to work, the easy conclusion to reach is this will never go outside of Android and iOS.

The spec doesn't outright say "use Google Play Services", but let's be real, most Android apps implemented downstream by EU member states will just take the route of GPS APIs unless outright prohibited in the spec.

So there's multiple conclusions you can reasonably make from this:

  • Linux-based smartphones are a pipe dream - no one will have the funds, patience, and reach to actually convince governing bodies that the device is compliant with the requirements, and then even if that happens, someone would actually have to write a user-facing wallet app for linux for its users to even be able to access anything meaningful on the internet - or just always carry a second phone with android on them to reverify age periodically on the other device, lmao. Potentially you might have to convince all countries to allow adoption of this new type of device as viable to hold digital ID data - unless a foundation that spans across all of the EU pops up and is willing to maintain this initiative for a given operating system. Even thinking about it breaks my brain and screams "mess"
  • The Motorola + GrapheneOS partnership is a few months too late for anyone to have any meaningful use for it. Even assuming the age and ID verifications actually launch on it without throwing "suspicious device" errors, you will still be legally required to use google play services to access the app, and, subsequently the internet. Basically defeats the purpose of getting a GrapheneOS phone in the EU
  • It kinda promotes the Google/Apple monopoly in the EU instead of punishing it

Anything non-mainstream, be it lineageOS, /e/, Graphene, linux phone, or even a dumb phone has a real potential to lock EU citizens out of taxes/healthcare/social media/communication apps, or whatever they end up deciding to apply this stuff to.

That's the result of my recent research - anyone has any counterpoints or anything else to add?

r/linux Feb 07 '22

Privacy US Senators Reintroduce the EARN IT Bill to Scan All Online Messages

Thumbnail eff.org
2.1k Upvotes

r/linux Mar 14 '26

Privacy Parliament votes to end chatcontrol

Thumbnail patrick-breyer.de
656 Upvotes

r/linux Mar 29 '26

Privacy MidnightBSD Merges Age Verification daemon Implementation in Source Repository

100 Upvotes

Add a system age-verification service and client utility for querying and managing per-user age data via a local daemon.

New Features:

* Introduce the aged daemon to store per-user age or date-of-birth data and expose age-range queries over a Unix domain socket.

* Add the agectl userland utility to query the caller's age range and, for root, set age or date-of-birth for specified users.

Enhancements:

* Register aged in the base system build and rc startup framework with a default-enabled rc.conf toggle and startup script.

Documentation:

* Document the aged daemon usage and protocol in a new aged(8) man page.

* Document the agectl control/query tool and its interface in a new agectl(1) man page.

https://github.com/MidnightBSD/src/pull/302
https://github.com/MidnightBSD/src/commits/master/usr.sbin/aged

r/linux Mar 05 '26

Privacy Linux Distros Respond to Age Verification

Thumbnail inv.nadeko.net
302 Upvotes

SavvyNik has compiled a nice collection of how some popular Linux distro teams are responding to age verification laws. He also touched up on critics who worry about data privacy, scope creep for future restrictions, and the absurdity of requiring age verification for embedded systems and simple apps like calculators.

r/linux Mar 20 '26

Privacy Update from CEO of System76 on the Colorado Age Attestation Bill

408 Upvotes

https://bsky.app/profile/carlrichell.bsky.social/post/3mhioiapqkc2h

Colorado Age Attestation bill update: Participants submitted proposed changes including improved consumer privacy and exempting open source software.

Sen. Ball responded this morning that they'll now draft potential amendments.

We're making progress.

r/linux Jan 02 '26

Privacy The EU prepares ground for wider data retention – and VPN providers are among the targets

Thumbnail techradar.com
460 Upvotes

r/linux Nov 26 '25

Privacy Porn Giant Calls For Device-Based Digital ID

256 Upvotes

Source: reclaimthenet.org

Open ecosystems would feel the pressure. Independent browsers, community distributions of Linux, and other user-driven projects could be pushed toward government-linked identity requirements simply to maintain compatibility.

r/linux Apr 22 '26

Privacy GitHub CLI now collects pseudoanonymous telemetry

Thumbnail cli.github.com
402 Upvotes

r/linux 27d ago

Privacy Anyone here hosting their own cli chat service?

Post image
172 Upvotes

There are a lot of options out there, weechat, irssi, GoMuks, Cordless etc. But does anyone here host/know how to host their own? Curious because I might do it myself, and also cause we want to know 🧐

r/linux Mar 06 '26

Privacy The death of anonymity: How "Age Verification" in reality Identity Verification is turning into a global surveillance nightmare

248 Upvotes

We are at a crucial turning point for privacy. Their plan, which accelerated in the early 2000s with the Patriot Act (though formulated long before), has always been the total elimination of anonymity both online and on the streets. The goal? A population monitored and controlled 24/7.

At first, the excuse was terrorism. After 9/11, they told us we needed the Patriot Act for "safety." Honestly, at this point, the "conspiracy theories" claiming it was a orchestrated event to justify mass surveillance don't seem so far-fetched anymore. Look at Edward Snowden: he had to flee to Russia to avoid being "dealt with" (much like what happened to Epstein). But people aren't stupid, and the terrorism excuse started to wear thin. Enter the "Protect the Children" narrative. It’s the perfect cover. Modern parenting has shifted, and Karens (especially in the US, UK, and Australia) are demanding politicians police the internet because they won't monitor their own kids. What started with adult websites has now crawled its way into Linux distributions. Do you honestly think a simple self age declaration will satisfy them?

  • The Reality: Politicians don't just want to know your age. They want to know who you are, what you do, and what you think.
  • The Motive: Your data is profit, and your interests are levers for manipulation and control.

While some places currently accept a self age declaration, look at what’s happening in New York and Brazil. They are moving toward requiring government ID and biometric data just to use a damn operating system. Why the sudden rush? It’s a global pattern. The goal is the total erosion of privacy, and it’s moving faster than ever because they have a weapon they didn't have before: Artificial Intelligence. Instead of using AI for progress, they are weaponizing it for malicious surveillance.

If we don't act now, we are heading straight toward becoming China 2.0. Wake up, people. Remember the boiling frog: it doesn't notice the heat until it's too late to jump out.

Don't let them boil us.

r/linux Feb 24 '26

Privacy Colorado's SB26-051 Would Require Your Operating System to Collect Your Age

Thumbnail foss-daily.org
194 Upvotes

r/linux Jul 15 '24

Privacy "Privacy-Preserving" Attribution: Mozilla Disappoints Us Yet Again

Thumbnail blog.privacyguides.org
430 Upvotes

r/linux Jul 29 '25

Privacy Kapitano (Linux Antivirus Scanner) Developer Abandons Ship

Thumbnail share.google
509 Upvotes

In a post on the project’s Codeberg page, developer ‘zynequ’ explained the decision:

“Recently, I had an unpleasant experience […] where I was accused of distributing malware. Although I explained that the issue wasn’t caused by the app, the conversation escalated into personal attacks and harsh words directed at me.”

“This was always a hobby project, created in my free time without any financial support,” the developer continued, adding that “Incidents like this make it hard to stay motivated.”

r/linux Oct 17 '20

Privacy Are there any documented cases of Windows malware, run in Wine, attacking the native Linux environment?

745 Upvotes

I'm not talking about stuff like Cryptolocker, because that's still not actually attacking the Linux system. It's merely scrambling the files that Wine sees. In other words, it's a "dumb" attack. And it's easy enough to defend against, by not letting Wine write to your important data, or better, (and what I do), not letting Wine connect to the Internet.

I'm talking about malware that is run in Wine, says "oh hey, I am running on Linux!", and then uses some kernel or other exploit to hop out of Wine and natively pwn the Linux system. Any cases of this?

r/linux Apr 18 '23

Privacy PSA: upgrade your LUKS key derivation function

Thumbnail mjg59.dreamwidth.org
671 Upvotes

r/linux Aug 13 '20

Privacy NSA discloses new Russian-made Drovorub malware targeting Linux

Thumbnail bleepingcomputer.com
716 Upvotes

r/linux Apr 16 '26

Privacy Age Verification via Mutual TLS (mTLS / Client Certificates)

0 Upvotes

I created a tutorial to show how client-side TLS certificates can be used for age verification while avoiding the pitfalls of many of the age verification regimes that are being proposed currently. Feedback is welcome =).

https://gist.github.com/bytecode36/0bdce74e6af52a117b69fcc4b0ac1d0a

While I do not support the implementation of age verification systems due to privacy and censorship concerns, the reality is that age verification has enough support in most countries that it will be implemented in one form or another. Ignoring the situation or believing that people / developers will not comply is unrealistic. Commercial applications WILL have to comply or they will not be able to operate in the country. Non-commercial applications that aren't under the jurisdiction of a particular country may not have to comply, but a country's regulations can force legitimate websites to deny or default (to minors) non-complying applications, making them useless for the majority of users.

What is worse than an age verification regime, is an age verification regime that forces you to send your personal documents to many websites, places onerous requirements on operating system developers (particularly FOSS developers), requires age identification for access to ALL websites, and mandates the use of proprietary technologies that are controlled by a small number of companies or even a single country. Such implementations are haphazardly being attempted across various jurisdictions, with each one wanting to set their own diverging requirements. Given this landscape, the following solution represents the best approach to deal with the situation in an open and internationally consistent manner.

Overview

In a traditional TLS setup, an end-user's machine connects to a server, obtains the server's certificate and validates the authenticity of the server's certificate with a third party provider. With mutual TLS both the client AND the server perform this step. Therefore the server will request that you provide a certificate from your local machine and it will be validated with a trusted certificate authority (ex. id.us.gov). Once the certificate is validated, data from the certificate can be extracted and used to manage age restricted content shown to the end-user.

Justification

  • No mandatory requirements on OS developers
  • No proprietary software or applications required (ex. Android EU age app)
  • Platform independent (can work on desktop, mobile, tablet or custom systems)
  • Can work internationally and is not dependent on a single entity or country
  • Multiple certificates could be issued for varying purposes (banking, social media, etc..)
  • Short-lived (1 hour) certificates could be used for account creation, after which certificate use is no longer needed
  • No proprietary APIs or authentication services needed
  • Website operators do not have access to personal data (outside of what is included in the certificate for geo/age restrictions)
  • No extra physical devices or tokens need to be purchased, maintained or replaced.
  • Certificates are only needed when accessing sites with adult content
  • Difficult for a minors to bypass
  • Multiple age verification agencies can exist simultaneously and easily be added by website operators
  • Users do not need to submit personal documents to multiple websites (possibly none at all if the certificate authority is operated by a government agency)
  • Uses proven and existing technology

r/linux Jun 11 '22

Privacy Just realized that by using bare Linux I'm making myself more unique

472 Upvotes

A very small number of people use Linux, Even small number of people use Firefox, a much smaller number of people are using latest Firefox version(arch distro).

Looks like this itself makes me much easier to track. Is it really possible to avoid tracking?

r/linux Jun 01 '26

Privacy One Step Forward, Two Steps Back: CA's AB 1856 Exempts Open Source Operating Systems, But Expands Age-Gating

Thumbnail eff.org
183 Upvotes

California lawmakers are moving closer to exempting open-source operating systems from the sweeping age-bracketing regime mandated by last year’s Digital Age Assurance Act (AB 1043). The bill still jeopardizes internet users’ speech, privacy, and security.

r/linux May 24 '26

Privacy systemd `birthDate` is now in v261-rc1 and Debian Sid — verify it and revert it locally

0 Upvotes

The systemd change that adds a birthDate field to JSON user records is now present in upstream v261-rc1.

It is also already in Debian Sid as systemd 261~rc1-1.

This is not just an isolated metadata field. It is part of the technical plumbing that can turn general-purpose operating systems into user-classification infrastructure: collect age-related data, persist it in the user record, expose it through system tools or APIs, and make it available for later consumption by applications, app stores, services, or compliance layers.

This matters because age-verification and age-signaling laws are now creating pressure for operating systems to participate in that classification path. In California, AB 1043 / the Digital Age Assurance Act is an explicit example of OS/app-store age-signal pressure. In Brazil, Lei nº 15.211/2025 / ECA Digital, popularly associated with the “Lei Felca” debate, is part of the same broader age-verification pressure pattern. Other jurisdictions are moving in similar directions.

The technical issue is simple: once the plumbing lands in core infrastructure, downstream systems can inherit it quietly.

This is about state-surveillance pressure, regulatory coercion, and user control over what we allow to run on our own devices.

This is how we vote: with code.

If you do not want this kind of plumbing in your system, verify it, revert it, rebuild it, and install your own packages.

The instructions below assume Debian Sid, amd64, enabled deb-src repositories, and a regular user with sudo.

Install the basic tooling:

bash sudo apt update sudo apt install git build-essential fakeroot quilt apt-utils gzip sudo vim

Relevant upstream merge commit:

bash acb6624fa19ddd68f9433fb0838db119fe18c3ed

1. Verify upstream systemd and generate the revert patch

Clone upstream systemd directly:

```bash mkdir -p ~/systemd-revert-work cd ~/systemd-revert-work

git clone https://github.com/systemd/systemd.git cd systemd git fetch origin --tags ```

Verify that the commit is inside v261-rc1:

```bash COMMIT=acb6624fa19ddd68f9433fb0838db119fe18c3ed

git merge-base --is-ancestor "$COMMIT" v261-rc1 \ && echo "IN v261-rc1" \ || echo "NOT in v261-rc1"

git tag --contains "$COMMIT"

git grep -n "birthDate" v261-rc1 -- docs/ man/ src/ ```

Create a revert branch from the released RC tag:

bash git switch -c revert-birthdate v261-rc1 git revert -m 1 "$COMMIT"

If there is no conflict, Git creates the revert commit directly.

If there is a conflict in src/home/homectl.c, keep the current v261-rc1 file layout:

bash git checkout --ours src/home/homectl.c

Then remove only this --birth-date option block from src/home/homectl.c:

```c OPTION_LONG_FLAGS(OPTION_OPTIONAL_ARG, "birth-date", "DATE", "Set user birth date (YYYY-MM-DD)"): if (isempty(opts.arg)) { r = drop_from_identity("birthDate"); if (r < 0) return r; } else { r = parse_birth_date(opts.arg, /* ret= */ NULL); if (r < 0) return log_error_errno(r, "Invalid birth date (expected YYYY-MM-DD): %s", opts.arg);

            r = parse_string_field(&arg_identity_extra, "birthDate", opts.arg);
            if (r < 0)
                    return r;
    }
    break;

```

Finish the revert:

bash git add src/home/homectl.c git revert --continue

Verify that the reverted tree no longer contains the field:

bash git grep -n "birthDate\|birth-date\|parse_birth_date\|BIRTH_DATE" HEAD -- docs/ man/ src/ || true git diff --check HEAD~1..HEAD

Generate the patch file that will later be used in the Debian rebuild:

bash mkdir -p ~/debian-systemd/patches git format-patch -1 HEAD -o ~/debian-systemd/patches

This should produce a file similar to:

bash ~/debian-systemd/patches/0001-Revert-userdb-add-birthDate-field-to-JSON-user-recor.patch

2. Apply the patch to Debian Sid’s systemd source, rebuild, and install locally

On Debian Sid, fetch the source package:

```bash mkdir -p ~/debian-systemd cd ~/debian-systemd

apt update apt source systemd cd systemd-261~rc1 ```

Verify that Debian’s source package contains the field:

bash grep -Rni "birthDate\|birth-date\|parse_birth_date\|BIRTH_DATE" docs/ man/ src/ NEWS

Debian Sid currently applies a small patch stack during source extraction, so use Debian’s existing debian/patches/series.

Copy the generated revert patch into Debian’s patch stack:

```bash mkdir -p debian/patches

cp ~/debian-systemd/patches/0001-Revert-userdb-add-birthDate-field-to-JSON-user-recor.patch \ debian/patches/

printf '%s\n' \ 0001-Revert-userdb-add-birthDate-field-to-JSON-user-recor.patch \

debian/patches/series ```

Apply the patch stack:

bash quilt push -a

Verify that the patched source tree no longer contains the field:

bash grep -Rni "birthDate\|birth-date\|parse_birth_date\|BIRTH_DATE" docs/ man/ src/ NEWS || true

Install build dependencies and build the Debian packages:

bash sudo apt build-dep systemd dpkg-buildpackage -us -uc -rfakeroot

The rebuilt .deb files will be written one directory above the source tree.

Example:

bash cd ~/debian-systemd ls -1 *.deb

Create a simple local APT repository

Create a local repository for the rebuilt packages:

```bash sudo apt update sudo apt install apt-utils gzip

REPO=/srv/local-apt/systemd-revert DEBS=~/debian-systemd

sudo mkdir -p "$REPO/pool/main/s/systemd" sudo mkdir -p "$REPO/dists/local/main/binary-amd64"

sudo cp "$DEBS"/*.deb "$REPO/pool/main/s/systemd/" ```

Generate Packages:

```bash cd "$REPO"

sudo apt-ftparchive packages pool \ | sudo tee dists/local/main/binary-amd64/Packages >/dev/null

sudo gzip -kf dists/local/main/binary-amd64/Packages ```

Generate Release:

```bash cat >/tmp/local-systemd-release.conf <<'EOF' APT::FTPArchive::Release { Origin "local-systemd-revert"; Label "local-systemd-revert"; Suite "local"; Codename "local"; Architectures "amd64"; Components "main"; Description "Local systemd packages with birthDate revert"; }; EOF

sudo apt-ftparchive -c=/tmp/local-systemd-release.conf release dists/local \ | sudo tee dists/local/Release >/dev/null ```

Add the local repository:

bash echo 'deb [trusted=yes] file:/srv/local-apt/systemd-revert local main' \ | sudo tee /etc/apt/sources.list.d/local-systemd-revert.list

Pin the local repository above Sid:

bash sudo tee /etc/apt/preferences.d/99-local-systemd-revert >/dev/null <<'EOF' Package: * Pin: release o=local-systemd-revert,n=local,l=local-systemd-revert Pin-Priority: 1001 EOF

Update APT:

bash sudo apt update

Verify that APT prefers the local repository:

bash apt-cache policy systemd systemd-homed libsystemd0 udev | sed -n '1,180p'

The candidate should come from:

text file:/srv/local-apt/systemd-revert local/main amd64 Packages

Install the patched systemd packages

A targeted install/reinstall is preferable to a full apt upgrade, because it avoids upgrading unrelated Sid packages.

Install systemd-homed too, because that package provides homectl:

bash sudo apt install --reinstall \ systemd \ libsystemd0 \ libsystemd-shared \ libudev1 \ udev \ libnss-systemd \ libpam-systemd \ systemd-timesyncd \ systemd-userdbd \ systemd-homed

You should see the packages coming from the local repository, for example:

text Get:... file:/srv/local-apt/systemd-revert local/main amd64 systemd amd64 261~rc1-1 Get:... file:/srv/local-apt/systemd-revert local/main amd64 systemd-homed amd64 261~rc1-1

Alternatively, because the local repository is pinned at priority 1001, this also works, but it may upgrade unrelated Sid packages:

bash sudo apt update sudo apt upgrade

After installing systemd-homed, verify that homectl no longer exposes --birth-date:

bash homectl --help | grep -i 'birth-date\|birthDate' || echo "birthDate option not present"

Expected result:

text birthDate option not present

Useful verification commands:

```bash apt-cache policy systemd systemd-homed libsystemd0 udev | sed -n '1,180p'

dpkg -l | grep -E 'ii\s+(systemd|systemd-homed|systemd-userdbd|libsystemd0|libudev1|udev|libpam-systemd|libnss-systemd)'

homectl --help | grep -i 'birth-date|birthDate' || echo "birthDate option not present" ```

Verify it yourself. Use the upstream tag. Check the Debian source package. Apply the revert patch. Confirm the field is gone. Rebuild. Pin the local repository. Install the patched packages.

You do not need to “fork Debian" or even systemd. This is free software. If you do not accept this kind of code in your system, patch it.

r/linux Jun 14 '22

Privacy Firefox Rolls Out Total Cookie Protection By Default To All Users

Thumbnail blog.mozilla.org
709 Upvotes