Privacy / Security

Age verification: what’s the harm?

by Girl on the Net 

Another brilliant rant from Girl on the Net. [Standard disclaimer: She's a sex blogger, so some of the ads on her site may not be the sort you want your boss to see over your shoulder. Assuming you read blogs during working hours. And if not, why not?]

Wiki isn’t the only site concerned about censorship, though, and early implementation of age verification in the UK shows that it – like any attempt to regulate ‘porn’ – ends up catching a lot of other content too. Reddit users have already begun documenting subreddits that have been age-gated, including support forums for sexual assault survivors and help on how to quit smoking. On top of this, a tonne of LGBTQ+ content and sex education has already been caught in the net. Expect much much more of this to happen going forward.

This isn’t a question of just getting the government to write in exemptions, either. Although Wikipedia may earn an exemption through the court case (I hope it does), one of the core problems with the Online Safety Act in implementation is that the definitions are incredibly broad and the penalties are potentially extremely harsh. Websites need to assess whether they have a ‘significant number’ of UK users – what’s significant? 10% of total traffic? 10 people? 10,000 visitors per month? They also need to consider whether it’s likely to be accessed by children. What does that mean – ‘likely’? Sites which aren’t marketed to children or shared in any spaces where children are likely to be browsing
 are they exempt? We don’t know. What we do know, however, is that sites which do not comply will be investigated by Ofcom, and potentially fined up to 10% of their annual revenue or £18 million – whichever is greater. The chilling effect of penalties like this, especially when combined with ‘guidance’ from the regulator that could generously be described as ‘vague’ means that any site with any content that could potentially be classed as ‘harmful to children’ would be taking a giant leap into the expensive unknown if they didn’t proactively comply. And compliance with ‘age verification’ is costly and time consuming: I personally can’t afford to do it, which is why I’ve just blanket blocked UK users from hearing the audio. Many other sites – both adult and non-adult – are coming to the same conclusion. Check out the Blocked page, from the Open Rights Group, which is tracking site closures and blocks as a result of the Act. Submit any sites you know of that are doing this too – let’s keep track of what we’re losing.

So there’s another harm: you’re not just losing access to this content unless you hand over private details, in many many cases (particularly with smaller sites and services) you’re losing access to it entirely. Even flashing your passport won’t get you to the content, because the site owner can’t afford to hire a bouncer to check your ID.

[
]

The UK government’s implementation of AV, without any exemption or concession for small sites, essentially means that those with the deepest pockets will get the most traffic. That means the large, ‘free’ porn tube sites – already an extremely dominant force in the adult industry, hoovering up a lot of the money and even shaping how we define ‘porn’ in the first place – will only become bigger and more powerful. Meanwhile those smaller sites trying to swim against the tide, offering a view of sexuality that is broader and more diverse than what you see on the front page of TubeFuck will struggle to get traction. As TechDirt put it this week:

   â€œThis is exactly what happens when you regulate the internet as if it’s all just Facebook and Google. The tech giants can absorb the compliance costs, but everyone else gets crushed.”

US government targets Cop City protester over phone operating system

in The Guardian  

The US Department of Justice is attempting to prosecute an Atlanta resident in connection with the movement against the police training center known as Cop City because he had GrapheneOS on his phone, an open-source operating system that enables users to enter a passcode and wipe a phone clean.

The case, which had its first hearing on Monday, centers on a little-known US federal statute that makes it a crime to destroy property in an effort to prevent it from being seized.

Experts said it may be the first time the law has been aimed at the operating system, which works on Google Pixel phones, and expressed concerns about a technology created for privacy and security being used to criminalize protesters.

“It’s concerning – and sends the message that [GrapheneOS] is criminal by default,” said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

The defendant, Sam Tunick, was stopped for interrogation at Atlanta’s Hartsfield-Jackson airport on 24 January last year, after vacationing in the Dominican Republic. Unbeknown to him, federal authorities had put him on a terrorism watchlist because of his alleged association with the movement against Cop City.

[
]

Marlon Kautz, a member of the Atlanta Solidarity Fund, said: “We all have a right to secure our private data against unconstitutional searches. And we should – especially in a time of rising authoritarianism.”

Meanwhile, Boutry, who lives in France, said Tunick’s case was of a piece with tendencies in France and Spain, where authorities have been frustrated in attempts to gain access to the phones of journalists, lawyers and political opponents due to GrapheneOS.

In Catalonia, Spain, police have been profiling people with Google Pixel phones, assuming they have GrapheneOS installed and are drug dealers or gang members.

At the same time, Boutry said, the “main goal [of the operating system] is protection of privacy”.

“They’re our phones and the state can’t tell us how to use them.”

via GrapheneOS

Google Broke Its Promise to Me. Now ICE Has My Data.

for Electronic Frontier Foundation (EFF)  

After I attended a pro-Palestine protest at Cornell University—for all of five minutes—the administration’s rhetoric about cracking down on students protesting what we saw as genocide forced me into hiding for three months. Federal agents came to my home looking for me. A friend was detained at an airport in Tampa and interrogated about my whereabouts.

[
]

Weeks later, in Geneva, Switzerland, I received what looked like a routine email from Google. It informed me that the company had already handed over my account data to the Department of Homeland Security.

At first, I wasn’t alarmed. I had seen something similar before. An associate of mine, Momodou Taal, had received advance notice from Google and Facebook that his data had been requested. He was given advanced notice of the subpoenas, and law enforcement eventually withdrew them before the companies turned over his data. 

I assumed I would be given the same opportunity. But the language in my email was different. It was final: “Google has received and responded to legal process from a law enforcement authority compelling the release of information related to your Google Account.”

[
]

Months later, my lawyer at the Electronic Frontier Foundation obtained the subpoena itself. On paper, the request focused largely on subscriber information: IP addresses, physical address, other identifiers, and session times and durations.

But taken together, these fragments form something far more powerful—a detailed surveillance profile. IP logs can be used to approximate location. Physical addresses show where you sleep. Session times would show when you were communicating with friends or family. Even without message content, the picture that emerges is intimate and invasive.

What this experience has made clear is that anyone can be targeted by law enforcement. And with their massive stores of data, technology companies can facilitate those arbitrary investigations. Together, they can combine state power, corporate data, and algorithmic inference in ways that are difficult to see—and even harder to challenge. 

Age Verification and Age Gating: Resource Hub

for Electronic Frontier Foundation (EFF)  

Just popping this here, as it seems Canada is preparing to be the next lemming over the cliff.

Governments in the U.S. and around the world are increasingly adopting these restrictive measures in the name of protecting children online. But in practice, these systems create dangerous new forms of surveillance, censorship, and exclusion.

Technologically, the age verification process can take many forms: collection and analysis of government ID, biometric scans, algorithmic or AI-based behavioral or user monitoring, digital ID, the list goes on. But no matter the method, every system demands users hand over sensitive and immutable personal information that links their offline identity to their online activity. Once that valuable data is collected, it can easily be leaked, hacked, or misused. (Indeed, we’ve already seen several breaches of age verification providers.)

EFF has long warned against age-gating the internet. Age verification technology itself is often inaccurate and privacy-invasive. These restrictive mandates strike at the foundation of the free and open internet. They are tools of censorship, used to block people from viewing or sharing information that the government deems “harmful” or “offensive.” And they create surveillance systems that critically undermine online privacy, chill access to vital online communities and resources, and burden the expressive rights of adults and young people alike.

Australia's Social Media Ban is a Win for Gambling Companies

by Rebecca Watson for YouTube  

Well, that's Australia. Punching above our weight in punching down, while simultaneously a world leader in shooting ourselves in the foot.

Remote video URL

 

Australia is quietly introducing 'unprecedented' age checks for search engines like Google

in ABC News  

"I have not seen anything like this anywhere else in the world," said Lisa Given, professor of Information Sciences from RMIT, who specialises in age-assurance technology.

"As people learn about the implications of this, we will likely see people stepping up and saying, 'Wait a minute, why wasn't I told that this was going to happen?'"

From December 27, Google — which dominates the Australian search market with a share of more than 90 per cent — and its rival, Microsoft, will have to use some form of age-assurance technology on users when they sign in, or face fines of almost $50 million per breach.

[
]

Despite the apparent magnitude of the shift, it has mostly gone unnoticed, in stark contrast to the political and media fanfare surrounding the teen social media ban, which will block under-16s from major platforms using similar technology.

As for why so few people have noticed, it may be because the changes took place away from the halls of parliament, in the relatively dry world of regulation.

[
]

Search engines will have a suite of options to choose from for checking the ages of their Australian users.

There are seven main methods listed in the new regulations:

  • Photo ID checks
  • Face scanning age estimation tools
  • Credit card checks
  • Digital ID
  • Vouching by the parent of a young person
  • Using AI to guess a user's age based on the data the company already has
  • Relying on a third party that has already checked the user's age
via Matt Cengia

CFPB Quietly Kills Rule to Shield Americans From Data Brokers

in Wired  

The CFPB received more than 600 comments from the public this year concerning the proposal, titled Protecting Americans from Harmful Data Broker Practices. The rule was crafted to ensure that data brokers obtain Americans’ consent before selling or sharing sensitive personal information, including financial data such as income. US credit agencies are already required to abide by such regulations under the Fair Credit Reporting Act, one of the nation’s oldest privacy laws.

In its notice, the CFPB’s acting director, Russell Vought, wrote that he was withdrawing the proposal “in light of updates to Bureau policies,” and that it did not align with the agency’s “current interpretation of the FCRA,” which he added the CFPB is “in the process of revising.”

[
] 

Vought, who also serves as director of the White House Office of Management and Budget, received a letter on Monday from the Financial Technology Association (FTA) calling for the rule to be withdrawn, claiming it exceed the agency’s statutory mandate and would be “harmful to financial institutions’ efforts to detect and prevent fraud.” The FTA is a US-based trade organization that represents the interests of fintech companies and their executives.

Privacy advocates have long pressed regulators to use the Fair Credit Reporting Act to crack down on the data broker industry. Common Defense, a veteran-led nonprofit, urged the CFPB to take action in November, blaming data brokers for recklessly exposing sensitive information about US service members that placed them at “substantial risk” of being blackmailed, scammed, or targeted by hostile foreign actors.

Trump order on information sharing appears to have implications for DOGE and beyond

 A new executive order from President Donald Trump aims to expand information-sharing across federal agencies as well as between federal and state governments, but civil libertarians and other experts are warning that the main purpose is to help normalize how the Department of Government Efficiency is handling government data.

The order, issued Thursday, directs all federal agency heads to modify or rescind any regulations preventing the sharing of unclassified data and records between federal agencies.

Agency heads also must ensure that the U.S. government has “unfettered access” to comprehensive data from all state programs that receive federal funding. The order extends to all such data even when stored in third-party databases. 

[
]

 While the new EO asserts that the removal of data “silos” is designed to eliminate fraud, waste and abuse, disturbing mission creep is very possible, said Elizabeth Laird, director of equity and civic technology at the nonprofit Center for Democracy and Technology.

There are no assurances that the data won’t be used for “targeting people who the administration has separately said are a priority for them,” Laird said. “That can include immigrants, it can include people who are transgender, it can include people that speak up” against the administration.

During his first presidency, Trump issued an EO attempting to compel state government agencies to share administrative data with the federal government for purposes of immigration enforcement. At least four states shared immigration data, Laird said.

“You’re laying the foundation for this data to be weaponized in ways never seen before in the country.” 

via Zinnia Jones

Google is on the Wrong Side of History

for Electronic Frontier Foundation (EFF)  

Google continues to show us why it chose to abandon its old motto of “Don’t Be Evil,” as it becomes more and more enmeshed with the military-industrial complex. Most recently, Google has removed four key points from its AI principles. Specifically, it previously read that the company would not pursue AI applications involving (1) weapons, (2) surveillance, (3) technologies that “cause or are likely to cause overall harm,” and (4) technologies whose purpose contravenes widely accepted principles of international law and  human rights.

Those principles are gone now.

In its place, the company has written that “democracies” should lead in AI development and companies should work together with governments “to create AI that protects people, promotes global growth, and supports national security.” This could mean that the provider of the world’s largest search engine–the tool most people use to uncover the best apple pie recipes and to find out what time their favorite coffee shop closes–could be in the business of creating AI-based weapons systems and leveraging its considerable computing power for surveillance. 

via Cory Doctorow

Everyone knows your location: tracking myself down through in-app ads

After more than couple dozen hours of trying, here are the main takeaways:

  1. I found a couple requests sent by my phone with my location + 5 requests that leak my IP address, which can be turned into geolocation using reverse DNS.
  2. Learned a lot about the RTB (real-time bidding) auctions and OpenRTB protocol and was shocked by the amount and types of data sent with the bids to ad exchanges.
  3. Gave up on the idea to buy my location data from a data broker or a tracking service, because I don't have a big enough company to take a trial or $10-50k to buy a huge database with the data of millions of people + me. Well maybe I do, but such expense seems a bit irrational. Turns out that EU-based peoples` data is almost the most expensive.

But still, I know my location data was collected and I know where to buy it!