# Age Verification for Qubes OS and Whonix (among other Linux Distributions)

**URL:** https://discuss.privacyguides.net/t/age-verification-for-qubes-os-and-whonix-among-other-linux-distributions/35984
**Category:** General
**Created:** 2026-03-05T15:57:52Z
**Posts:** 28

## Post 1 by @FranklyFlawless — 2026-03-05T15:57:52Z

> **[How much do we gotta worry about this Linux "age verification" BS?](https://forum.qubes-os.org/t/how-much-do-we-gotta-worry-about-this-linux-age-verification-bs/39788)**
>
> I’ve been seeing news about the braindead bootlicker states of America trying to force “age verification” into Linux. I’m still not sure how much I should panic about this. I don’t see any of the communities of the distros I use talking about it,...

> **[Whonix adding age verification?](https://forums.whonix.org/t/whonix-adding-age-verification/22969)**
>
> Whonix will add age verification api. Please don’t. Ignore it. Privacy disaster for any program in user mode including browser js to query the age verification. Which is required “by law”. New fingerprinting mechanism: age bracket. In two years...

These are active, ongoing discussions on the Qubes OS and Whonix Forum with various external references to forges, mailing lists, and MediaWiki instances of other Linux distributions across the Internet.

---

## Post 2 by @null — 2026-03-05T16:35:18Z

Related

> **[California Age Verification](https://discussion.fedoraproject.org/t/california-age-verification/181968)**
>
> Are you aware of this? California’s Digital Age Assurance Act, effective January 1, 2027, mandates that operating system providers and application developers implement age verification measures to protect minors online. This includes collecting...

---

## Post 3 by @FranklyFlawless — 2026-03-05T16:42:27Z

Thank you for the link, I shared it in the Qubes OS Forum topic and provided attribution to your contribution.

---

## Post 4 by @fria — 2026-03-05T17:11:17Z

What a disaster. People making laws with no concept of the implications.

---

## Post 5 by @FranklyFlawless — 2026-03-05T17:57:09Z

I will continue to provide updates to this topic as the Qubes team and Encrypted Support LP work (together) on developing a solution to address this issue.

---

## Post 6 by @trilobyte — 2026-03-05T19:27:25Z

Well that’s… interesting. I am more open to age verification on algorithmic social media only than others on here, depending how it’s implemented, but I don’t know why you would want an OS based limitation logs age brackets.

“(b) “Age bracket data” means nonpersonally identifiable data derived from a user’s birth date or age for the purpose of sharing with developers of applications that indicates the user’s age range, including, at a minimum, the following:

(1) Whether a user is under 13 years of age.

(2) Whether the user is at least 13 years of age and under 16 years of age.

(3) Whether the user is at least 16 years of age and under 18 years of age.

(4) Whether the user is at least 18 years of age.“

We would hope linux devs are only requesting the minimum, at which point the 17 year old can select 4 and no one gets fined… Then every application in the official repositories gets this information for some reason? Having every application know it’s talking to a very honest 12 year old is safer somehow? If the 12 year old is smarter than me and learns how to compile programs before they’re in they’re multiple decades old, will that bypass it?

Maybe the intent is to make it so that the profile on a tablet is set up with an age bracket, and then, even if the profile has access to google play, California can ban them from downloading tiktok? That would be similar to a child profile with gated content, except California gets to decide what’s on it instead of the parents.

It seems like this will be limited impact on linux in any case. Fedora already knows I’m probably older than 17. The risk is maybe future expansion, like requiring applications to check the age category and declaring other applications black market applications, or punishing the kids who lie about their age like with tobacco and alcohol.

Also shared accounts are exempt:

“(g) This title does not impose liability on an operating system provider, a covered application store, or a developer that arises from the use of a device or application by a person who is not the user to whom a signal pertains.”

Overall it seems unnecessary when devices can already be locked down by the parents. They could have made child user a required type of user account instead, where the parents must manually approve new applications, to make it less confusing for parents to set up.

Am I misunderstanding anything?

---

## Post 7 by @KathyM — 2026-03-06T15:30:50Z

Per Tom’s hardware

> **[California introduces age verification law for all operating systems,...](https://www.tomshardware.com/software/operating-systems/california-introduces-age-verification-law)**
>
> AB 1043 also requires OS providers to pipe a real-time age checker to every app developer who requests it.

> These small distros lack legal teams or resources to implement the required API, so a more realistic outcome for non-compliant distros is a disclaimer that the software is not intended for use in California.

Sounds like the cancer warning on everything.

On a side note, they need to start requiring qr codes to gov websites so I can find what the actual problem is with stuff like pliers. Like, no :poop: I’m not licking the pliers and I wash my hands before I eat.

---

## Post 8 by @FranklyFlawless — 2026-03-07T09:01:50Z

The Kicksecure Wiki’s Age API page has been updated multiple times throughout the last day from concerns arising from the Whonix Forum:

> **[Age Signaling and Interface Documentation and Design for Kicksecure](https://www.kicksecure.com/wiki/Age-api)**
>
> Documentation for operating system age-signaling (age-bracket) interface requirements that may apply in some jurisdictions. Covers background, Kicksecure privacy/fingerprinting impact, user interface (UI) wording/rationale, alternatives, legal...

@adrelanos has provided an important moderation post regarding the Whonix Forum topic:

> **[Whonix adding age verification?](https://forums.whonix.org/t/whonix-adding-age-verification/22969/24)**
>
> Moderation comment Nothing has been done yet. This is draft and discussion status only. As a prerequisite for future postings here: Read the relevant law(s) in full. It makes no sense to comment without knowing what the law actually says. Read...

Nothing official from the Qubes team, at least not collectively.

---

## Post 9 by @Breeze7846 — 2026-03-06T23:49:18Z

Been hearing all the rubbish about the laws from CA, CO, NY. Some parts of the internet are calling this the death of private Linux, and apparently some are even hoarding Linux isos.

Others, like some leaders on the Fedora Project, have figured that while minor tweaks will be needed its largely a nothing burger.

So is this a big deal? Is this the twilight of private linux? Or is this a situation where the cart has gone before the horse? I’m looking for an actual answer to this; I’m wondering if the PG staff have any commentary on this?

---

## Post 10 by @KathyM — 2026-03-06T23:52:06Z

Linux distros intending to make money in California need to be worried. Everybody else can say “Not intended for use in California”.

---

## Post 11 by @Breeze7846 — 2026-03-06T23:55:26Z

Yeah but… doesn’t that include fedora? And everyone downstream? And whonix and secureblue wanting to keep CA? Seems like a lot of people could be impacted outside of CA, or even USA

---

## Post 12 by @KathyM — 2026-03-06T23:57:55Z

I am not your lawyer. Ubuntu posted an official response saying they have no plans at the moment to implement it. And they also have not your lawyers.

> **[Ubuntu's response to California's Digital Age Assurance Act (AB 1043)](https://discourse.ubuntu.com/t/ubuntus-response-to-californias-digital-age-assurance-act-ab-1043/77948)**
>
> Over the past couple of days, there has been a lot of commentary about Ubuntu and how it’ll respond to California’s new Digital Age Assurance Act (AB 1043), which will require operating systems to collect age information at account setup and...

---

## Post 13 by @bitsondatadev — 2026-03-07T01:56:50Z

> [@Breeze7846](#):
>
> Some parts of the internet are calling this the death of private Linux, and apparently some are even hoarding Linux isos.
> 
> Others, like some leaders on the Fedora Project, have figured that while minor tweaks will be needed its largely a nothing burger.

TL; DR: it’s a nothing burger making headlines.

People who call this and similar legislation the “end of open source” remind me of those doomers who think GenAI is the AI iteration that is sentient and self aware :roll_eyes: that will rise up against us. People need to read up on history, specifically how [encryption algorithms were illegal to export](https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States) outside of the United States during the cold war. I hope we never get back to a place where we’re debating if algorithms and code are speech and we have a government willing to enforce violence over it. But even when that happened, there were plenty of creative ways to exchange ideas when a government tried to lock things down. Now that encryption is everywhere it’s almost impossible to stop private free exchange between people without tearing down internet lines.

The government only has real leverage applying these rules to for-profit companies distributing their open core versions of Linux. I’m not sure if those sponsoring these bills are doing so for optics to flex to their constituents they are “keeping kids safe" or “stopping guns from being printed" or if they genuinely don’t understand how little these types of policies work on the internet. Maybe they believe in the apparent success of DMCA, which had more to do with people enjoying the convenience of early streaming services rather than people fearing the law. As streaming services enshittify, sharing copyrighted materials freely is back in vogue. Whatever the reason though, it doesn’t actually “kill” all of open source - whatever that is intended to mean.

One of the big concerns I’ve heard people say is that it may just be a couple states now, but eventually it will become standard everywhere or it becoming a law that mandates only government verified code is legal to run on computers.

You can play out quite a few scenarios here but I don’t see a world where any government can truly enforce policies that could end open source. It’s similar to the folly of governments trying to stifle free speech, it only moves it to the shadows. I believe the age checks legislation will actually just cause more issues for Microsoft and MacOS. For those companies that build on Linux like Red Hat, System76, and Canonical, the open nature of the code makes malicious compliance too easy.

Canonical already has Ubuntu source code out in the open. Any code they add can easily be removed, especially if it’s well labeled in the commit history. It wouldn’t be a lot to imagine some mystery maintainer familiar with the project makes a replica of the compliant operating system with a version of the code that simply doesn’t have that code and sits in a package url that looks similar to canonicals. You get the gist.

---

## Post 14 by @FranklyFlawless — 2026-03-07T09:22:57Z

> [@Breeze7846](#):
>
> So is this a big deal? Is this the twilight of private linux? Or is this a situation where the cart has gone before the horse? I’m looking for an actual answer to this

Your topic has been merged into mine out of chronological order, but you can find answers to your questions in the Kicksecure Wiki’s Age API page above your post, especially on how much importance the Linux ecosystem is addressing the issue, if any. For example, MidnightBSD has updated the COPYRIGHT file in their GitHub repository:

> <https://github.com/MidnightBSD/src/blob/fcbf74a971ab461cae6d9ad1dd6b04fbc267439b/COPYRIGHT#L7-L11>

---

## Post 15 by @beantaco — 2026-03-07T23:10:11Z

This problem is not just a Linux, Qubes or desktop OS problem. GrapheneOS has a thread discussing the problem.

> **[Does GrapheneOS plan to comply with OS level age verification laws? -...](https://discuss.grapheneos.org/d/32410-does-grapheneos-plan-to-comply-with-os-level-age-verification-laws)**
>
> GrapheneOS discussion forum

---

## Post 16 by @beantaco — 2026-03-08T00:04:50Z

For now it’s just an age API with self declaration by users and four age brackets, and IMHO if that is all the bullshit that operating systems had to comply with it wouldn’t be a disaster. However that is naive. I think the rulers are just introducing benign laws first. Complying with this, combined with the prior age verification compliance, would set the momentum for further compliance with more authoritarian laws in the future, not stopping until the rulers have control over everyone’s digital lives.

I naively imagine each OS project or part thereof could respond in one of the ways below. Not necessarily mutually exclusive.

1. Comply exactly as the rulers demand.
2. Ban people in affected jurisdictions from using the software and hope that people will find a way to circumvent the ban.
3. Claim no need to comply because they don’t operate in affected jurisdictions. This assumes the premise is true. If the premise is false, make it true by shifting operations away from affected jurisdictions.
4. Do nothing. Pretend the new laws don’t exist.
5. Shift to anonymous and decentralized methods of development and distribution to evade the new laws.

[System76](https://blog.system76.com/post/system76-on-age-verification) disagrees with the new laws but has chosen to comply, and there is discussion in the [Debian community](https://lists.debian.org/debian-legal/2026/03/msg00000.html) to comply (approach 1). [MidnightBSD](https://github.com/MidnightBSD/src/blob/fcbf74a971ab461cae6d9ad1dd6b04fbc267439b/COPYRIGHT#L7-L11) is taking approach 2 for now. [GrapheneOS](https://discuss.grapheneos.org/d/32410-does-grapheneos-plan-to-comply-with-os-level-age-verification-laws/99) has floated approach 3 but AFAICT have not yet decided anything. One post from GrapheneOS is this.

> We’re under no more obligation to filter the internet for California than we are to do it for China. Neither blocks access to the GrapheneOS website or services. If California wants to block access to those then they’re welcome to pass a law implementing their own Great Firewall. The most action they could get from us is replacing Los Angeles and San Jose servers with Las Vegas or Seattle.

---

## Post 17 by @FranklyFlawless — 2026-03-08T01:50:03Z

> [@beantaco](#):
>
> This problem is not just a Linux, Qubes or desktop OS problem. GrapheneOS has a thread discussing the problem.

> [@beantaco](#):
>
> One post from GrapheneOS is this.

Right, that Flarum thread has been referenced in the Qubes OS Forum topic:

> **[How much do we gotta worry about this Linux "age verification" BS?](https://forum.qubes-os.org/t/how-much-do-we-gotta-worry-about-this-linux-age-verification-bs/39788/40)**
>
> GrapheneOS devs to Californian politicians: punch sand We’re under no more obligation to filter the internet for California than we are to do it for China. Neither blocks access to the GrapheneOS website or services. If California wants to block...

@adrelanos has provided additional references to various GitHub pull requests towards other operating systems (Arch Linux and Ubuntu) deriving from the original XDG desktop portal pull request:

> **[How much do we gotta worry about this Linux "age verification" BS?](https://forum.qubes-os.org/t/how-much-do-we-gotta-worry-about-this-linux-age-verification-bs/39788/66)**
>
> Ubuntu: identity: add birthDate field to user provisioning [DRAFT] by dylanmtaylor · Pull Request #1338 · canonical/ubuntu-desktop-provision · GitHub postinst: write BirthDate to target AccountsService keyfile by dylanmtaylor · Pull Request...

Tails has started a GitLab issue about the age verification requirement as hinted by @adrelanos (and referenced by @tokaso80 in [#79](https://forum.qubes-os.org/t/how-much-do-we-gotta-worry-about-this-linux-age-verification-bs/39788/79) of the Qubes OS Forum topic):

> **[California age verification law AB1043 (#21457) · Tasks · tails / tails · GitLab](https://gitlab.tails.boum.org/tails/tails/-/work_items/21457)**
>
> Decide what to do about California age verification law AB1043. Starting January 1, 2027, operating system providers will be required to collect age information at account...

---

## Post 18 by @ls.skuggi — 2026-03-09T15:48:17Z

> [@beantaco](#):
>
> if that is all the bullshit that operating systems had to comply with it wouldn’t be a disaster. However that is naive.

Exactly. What you describe is called “boiling the frog” and a well established tactics to fool someone.

---

## Post 19 by @FranklyFlawless — 2026-03-11T08:44:21Z

@adrelanos has provided an update on the Whonix Forum:

> **[Whonix adding age verification?](https://forums.whonix.org/t/whonix-adding-age-verification/22969/30)**
>
> System76: Re: On the unfortunate need for an "age verification" API for legal compliance reasons in some U.S. states system76 Illinois Bill IL SB3977 (Children’s Social Media Safety Act) discussion:...

One of the multiple references was this Mastodon post from Carl Richell at System76 addressing both the California and Colorado bill:

> **[Carl Richell (@carlrichell@fosstodon.org)](https://fosstodon.org/@carlrichell/116201429639953387)**
>
> Today, I met with Colorado Senator Matt Ball, co-author of Colorado OS Age Attestation Bill SB26-051.
> 
> Sen. Ball suggested excluding open source software from the bill. This appears to be a real possibility.
> 
> Amendments are expected for the CA age...

The claim is that there is a possiility of open-source software being excluded from future bill amendments.

In addition, there is an Ageless Linux distribution based on Debian specifically targeting the legal language of AB 1043:

> **[Ageless Linux — Software for Humans of Indeterminate Age](https://agelesslinux.org/)**

---

## Post 20 by @parkerchandler1979 — 2026-03-11T10:13:34Z

I just want to say I liked Midnight BSD’s response to this the best.

Sometimes you gotta use the R word, especially when it is actually and objectively warranted.

---

## Post 21 by @Davian — 2026-03-11T21:10:38Z

> [@FranklyFlawless](#):
>
> [Whonix adding age verification? - Support - Whonix Forum](https://forums.whonix.org/t/whonix-adding-age-verification/22969)

Do the user need to grant permission or can the app always request the age?

---

## Post 22 by @IsItJustMe — 2026-03-12T14:42:16Z

You beat me to it. :joy:

I was just going to post a link to ageless linux.

I’m looking into them even though I am not in one of those states.

---

## Post 23 by @FranklyFlawless — 2026-03-16T13:56:40Z

@michael from the Qubes OS team has provided a response:

> **[How much do we gotta worry about this Linux "age verification" BS?](https://forum.qubes-os.org/t/how-much-do-we-gotta-worry-about-this-linux-age-verification-bs/39788/148)**
>
> hi all, the Qubes OS team is aware of this topic and since we distribute Qubes OS with debian, fedora, and whonix templates, we are following the discussions in those OSes (and others). you can track what the OSes are currently discussing here: ...

Ageless Linux is claiming that Kicksecure/Whonix will be complying with the age verification API:

> **[Ageless Linux — Distro Compliance Tracker](https://agelesslinux.org/distros.html)**

I have informed @adrelanos and @arraybolt3 about this discrepancy on the Whonix Forum:

> **[Whonix adding age verification?](https://forums.whonix.org/t/whonix-adding-age-verification/22969/32)**
>
> Looks like Ageless Linux is claiming Kicksecure and Whonix will be complying with the age verification API: I am not authorized to formally/legally dispute this claim on behalf of Kicksecure and/or Whonix, so this post is merely a...

For the current status of Kicksecure and/or Whonix, use the Kicksecure Wiki, not Ageless Linux’s distro compliance tracker:

> **[Age Signaling Legal and Interface Considerations for Kicksecure and Whonix](https://www.kicksecure.com/wiki/Age-api#status)**
>
> At the moment, Kicksecure and Whonix do not expect to add an age API. This assessment may become more definite later. If future releases or upgrades require changes in this area, those changes would be announced in advance. | Research of operating...

---

## Post 24 by @FranklyFlawless — 2026-03-29T02:41:01Z

Pull request from @arraybolt3 has been merged upstream:

> <https://github.com/agelesslinux/agelesslinux.org/pull/1>
>
> Since the [initial discussion](https://lists.freedesktop.org/archives/xdg/2026-M…arch/014764.html) I started on behalf of Kicksecure and Whonix, plans have changed, and we are now "[unlikely to implement an age API.](https://www.kicksecure.com/wiki/Age-api#status)"

The end of the pull request refers to another GitHub repository, which does not currently list Kicksecure or Whonix (yet):

> **[GitHub - BryanLunduke/DoesItAgeVerify: The age verification status of Open Source...](https://github.com/BryanLunduke/DoesItAgeVerify)**
>
> The age verification status of Open Source Operating Systems

---

## Post 25 by @FranklyFlawless — 2026-05-26T01:38:27Z

> **[Colorado and California age verification bills exempt open source operating...](https://www.gamingonlinux.com/2026/05/colorado-and-california-age-verification-bills-exempt-open-source-operating-systems/)**
>
> Remember all the ruckus with various US states introducing operating-system level age verification laws? Colorado and California thankfully exempt open source.

---

## Post 26 by @FranklyFlawless — 2026-05-27T02:05:17Z

One more:

> **[California moves to exempt Linux from its upcoming age-verification law after...](https://www.tomshardware.com/software/linux/california-moves-to-exempt-linux-from-its-upcoming-age-verification-law-after-backlash-over-forcing-operating-systems-to-collect-users-ages-amendment-proposed-by-the-same-lawmaker-who-wrote-the-original-law)**
>
> SteamOS could still be affected

---

## Post 27 by @Davian — 2026-06-01T15:50:55Z

> [@FranklyFlawless](#):
>
> [Colorado and California age verification bills exempt open source operating systems | GamingOnLinux](https://www.gamingonlinux.com/2026/05/colorado-and-california-age-verification-bills-exempt-open-source-operating-systems/)

Based  
Laws should put big companies in place, not go against community projects

---

## Post 28 by @FranklyFlawless — 2026-06-02T03:47:55Z

@adrelanos and @arraybolt3 provided responses earlier last week:

> **[Whonix adding age verification?](https://forums.whonix.org/t/whonix-adding-age-verification/22969/45)**
>
> I am not too excited about this wording. AN OPERATING SYSTEM PROVIDER OR DEVELOPER THAT DISTRIBUTES AN OPERATING SYSTEM OR APPLICATION UNDER LICENSE TERMS THAT PERMIT A RECIPIENT TO COPY, REDISTRIBUTE, AND MODIFY THE SOFTWARE WITHOUT ANY...

> **[Whonix adding age verification?](https://forums.whonix.org/t/whonix-adding-age-verification/22969/46)**
>
> Possible counterargument to the “a license is not a contract” argument: As things stand, it seems likely that the judge in the case will rule that that the GPL-enforcement lawsuits can be a matter of contract law, not just copyright law, which...

We are not in the clear yet.
