Goodbye Bikesheds: Why Age Verification Signals the End of FOSS
Goodbye, and Thanks for All the Bikesheds

In my final Bikeshed column, I reflect on the limits of LLM-assisted code reviews and argue that mandatory age verification marks the beginning of the end for Free and Open Source Software. While tech bros champion absolute privacy, governments are pushing back, forcing a shift toward cryptographically attested platforms where users cannot modify source code. This move toward accountability and digital sovereignty will likely fragment the Internet and restrict the very freedom that defined FOSS.
We could have designed our protocols to be minimally compatible with a nation of laws, but the tech bros insisted that compromise was treason, and, as a result, we will lose more privacy than necessary.
- hinkley
A bit of an aside, but after someone introduced me to the notion of Reversible Decisions, it quickly became apparent to me that the solution to the bikeshed problem is to throw money at it before the roosters can start preening about which color the shed should be.
Decisions that are reversible should just go with the instinctive answer of whoever volunteers to work on it.
I've been in many meeting rooms where, because of the number and caliber of people in the room, we've blown $5000 worth of combined salary arguing about basically nothing. I've been in a few where that number was well over $10k.
If you're going to assign a relatively medium talent engineer to solve a problem, it's cheaper to let them solve it twice, maybe even three times, than it is to try to figure out what the right solution is before touching a keyboard. It helps them grow to give them that autonomy, and more importantly training your team out of reflexively reaching for optimization for every single feature saves gobs of money over time.
The interface for a piece of code matters to everyone. The internal implementation details mostly matter to the bus number on that code. If they're happy with it, that matters a lot. That can be overridden by the consequences of that design, but I've seen a couple cases where the bus number for a module wanted a solution with fewer consequences but the group wisdom wanted something flashier but also more brittle.
- throw0101a
For those unaware, PHK created (amongst other things) the MD5crypt password hashing algorithm ($1$…). It came before bcrypt (1999), scrypt (2009), SHA2crypt (2016), etc, and was committed in 1994:
* https://svnweb.freebsd.org/base/head/lib/libcrypt/crypt.c?re...
* https://github.com/freebsd/freebsd-src/commit/3b2b7f71deba2a...
- ai_critic
First read of this pissed me off, but subsequent reads gave a much different opinion.
Do yourself a favor and read this, a few times, and take a moment to actually try and see what the author's getting at.
- andix
I don't think age restriction will impact FOSS in the long term. If there are some regulations that threaten FOSS now, they are going to be adopted in the long term.
Regulations for age restriction are understandable. A lot of modern technology is harming kids (and I don't mean dirty videos, social media seems to be much more harmful).
A sensible regulator would leave some responsibility to the parents, but require restrictions for consumer devices (smartphones, laptops). Maybe even enable age restrictions by default, block replacing the OS or the firmware, and only allow it once the age was confirmed.
I don't see a point of including all kind of OS or software into this regulation. Just the ones that are preinstalled on consumer devices, and commercially distributed to consumers. Once the age of the user was confirmed, the devices should be able to become as open as we know them now.
- st3fan
"LLM-assisted code review won't be a huge disruptor" is quite the prediction. Because it already is in a very big way. The take on LLMs seems incredibly out of date and out of touch with reality. (Which of course, has moved/advanced very fast the past months/year)
- mimd
I have met women in tech who have been privacy conscious and paranoid about state control. Or even a healthy stream of non-tech women worried that it will be used to attack their sex and to discriminate. I don't think the author is correct in his belief that there are not a considerable amount of women worried about privacy. And to make such a board claim, and in light of my experience, would indicate either hubris or sexism.
If anything, he frames that he is concerned about his daughter as a father. The viewpoint of patriarchy.
- busterarm
I guess tech has grown too large and fractured and maybe most working software engineers are too young to be familiar with phk and his points of view.
He's been a strong privacy and FOSS advocate for decades and has more credibility on both of these topics than nearly anyone on this board.
He also has an account and comments frequently. phkamp. I suggest reading some of his comments before making judgment.
So many kneejerk and nuance-less opinions. Absolutely hilarious that people are thinking the guy who wrote MD5crypt and BSD Jails is anti-privacy.
Also eye opening watching how many people are getting frothing-at-the-mouth mad seeing somebody with that pedigree coming to different conclusions than they do.
- dzonga
I think the author is missing a layer of abstraction.
yeah - once regulators come into play - the private ecosystems take over. discord is already a precursor to this.
the era of mass public social networks will come to the end. next it will be just private networks of individuals. likely the won't interact.
how the dynamics play out - I don't know - but if you study history - you will know what behaviors will happen.