> The term operating system provider means a person that develops, licenses, or controls the operating system software on a covered device.
https://www.govtrack.us/congress/bills/119/s5090/text/is#lin...
Whoever wrote this is technologically illiterate.
It would be nice if these website stops all these crap, but I guess in long term it is going to be impossible due to stupid regulations.
- Permit signals to include age verification methods that minimize data disclosure, including the use of verifiable credentials and zero-knowledge proofs,
Any kind of credential has to uniquely identify a user. They will track who you are, where you go, at all times, on every computer, by law. - Establish a device-level age assurance framework requiring operating system providers to collect a user’s age during operating system account creation or from existing account holders,
- Require operating systems to convert a user’s age into privacy-protective age brackets—under 13; ages 13–15; age 16; and age 17 or older—rather than sharing the user’s exact age or date of birth,
- Create a secure, real-time operating system signal that applications, browsers, application stores, and covered websites must request and use as the primary indicator of a user’s age,
- Require children under age 17 to link their operating system account to a parent or legal guardian account and allow the user or linked parent or guardian to view the child’s age bracket data,
- Establish a process for resolving conflicting age information, including user notice, an opportunity to correct inaccurate information, and distribution of an updated age signal,
Any kid in the world will figure out how to either make a fake user, or spoof the signal to apps to say they're 17. Virtual machines in the browser, remote display to a VPS, VPNs, proxies, etc, etc. One kid at school will figure it out and every other kid will get it from them. They have near unlimited free time and lots of motivation. - Prohibit developers and covered website operators from requesting more age information than the standardized signal or sharing age bracket data with third parties,
- Impose data minimization requirements limiting the collection, retention, use, and combination of age-related information, including prohibitions on using age bracket data for profiling, engagement optimization, or targeted advertising,
- Prohibit the transfer of children’s personal data to data brokers, while preserving contextual advertising that does not rely on personal data or behavioral profiling,
- Include competition safeguards preventing operating system providers and application stores from imposing more restrictive age-related requirements on third-party applications or using age bracket data to disadvantage competitors, and
I'm sure all websites/apps will respect that. As we know silicon valley is extremely law-abiding. - Establish enforcement by the Federal Trade Commission and State Attorneys General, including civil penalties of up to $2,500 per negligent violation and $7,500 per knowing or intentional violation, which may be multiplied by the number of children affected,
- Create a national baseline that preempts only conflicting State requirements while preserving Federal or State laws that provide protections at least as strong as the Act.
As we all know there are never any loopholes for companies to use to evade regulatory limits.