🇫🇷🚨 FRANCE BANS SOCIAL MEDIA FOR U15s → EVERYONE TO VERIFY THEIR AGE.
“For four months, all of us in France will have to prove our age,” said digital minister, Anne Le Hénanff 😡
What this means if you're in France → you'll need to user your ID card, France Connect, or facial recognition (selfie) to log in.
🚩 What’s sold as “online safety” means #surveillance via IDs checks or face scans. 🚩
We must fight against age verification - or the free web dies!
Find out which other countries are implementing age verification & social media bans: https://t.co/xov9sUcmqy
Our statement on the UK government’s demand that all content on all devices sold or used in the country be scanned, on the presumption of nudity, using a dystopian combination of age verification and content scanning. This proposal will not safeguard children. It endangers us all.
https://t.co/VdWe9uhi8p
Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too.
Google's Play Integrity API requires hardware attestation for the strong integrity level and is gradually phasing in requiring it for the more commonly used device integrity level. Apple already has it as a requirement. Over the long term, this will increasingly lock out hardware and OS competition.
The purpose of these systems is disallowing people from using hardware and software not approved by Apple or Google. This is wrongly presented as being a security feature. Banks and government services are the main ones adopting it but Apple and Google are encouraging every service to use it.
Apple's Privacy Pass brought hardware attestation to the web to help with passing captchas on their own hardware. Many people saw that as harmless since few sites would be willing to lock out non-Apple-hardware users. Apple and Google are both likely to bring broader hardware attestation to the web.
Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems:
https://t.co/7rQnioRa8A
Banking and government services increasingly require using a mobile app where they can use attestation to force using an Apple or Google approved device and OS. Apple's privacy pass, Google's 'cancelled' Web Environment Integrity and now reCAPTCHA Mobile Verification are bringing this to the web.
Current media coverage for reCAPTCHA Mobile Verification misunderstands it and the impact of it. They're bringing a hardware attestation requirement to Windows, desktop Linux, OpenBSD, etc. by requiring a QR scan from a certified smartphone to pass reCAPTCHA in some cases. They could expand it more.
Control over reCAPTCHA puts Google in a position where they can require having either iOS or a certified Android device to use an enormous amount of the web. Google defines certification requirements for Android which includes forcing bundling Google Chrome, etc. It's enormously anti-competitive.
Google's Play Integrity API bans using GrapheneOS despite it being far more secure than anything they permit. It also bans using any other alternative. This isn't somehow specific to an AOSP-based OS. You can't avoid this by using a mobile OS based on FreeBSD instead. You'll just be more locked out.
Google's Play Integrity API permits devices with no security patches for 10 years. The device integrity level can be bypassed via spoofing but they can detect it quite well and block it once it starts being done at scale. The strong integrity level requires leaked keys from TEEs/SEs to bypass it.
It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source.
Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them.
Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security.
reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that.
This isn't about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don't license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere.
Services shouldn't ban people from using arbitrary hardware and operating systems in the first place. Google's security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It's for enforcing their monopolies via GMS licensing, that's all.
Vorrei porre l’attenzione su quel che è implicito nella questione Manzoni: si ritiene che la lettura di un testo o di un altro siano cose equipollenti, e che l’uno valga l’altro, perché il perno del discorso sarebbe nella lettura.
Ebbene, mi preme sottolineare che non è così.
We’ve created a school system where the students who follow the rules get the least attention… because all the energy goes into managing the ones who don’t.
Sono usciti i dati ISTAT sugli indicatori demografici aggiornati al 2025:
https://t.co/2mldInwh1g
Il grafico mette in prospettiva questi dati dal 1865 a oggi.
Age verification puts all users at risk of data breaches, EFF’s Rin Alajaji told @business, and requiring ID for social media could chill speech, particularly from whistleblowers or activists who rely on anonymity. https://t.co/xlBcDhNKy2
Today, the final negotiations on Chat Control 2.0 begin between the European Commission, the European Parliament, and the Council of the EU.
Although the requirement for mandatory scanning (including end-to-end encrypted messaging services) has been removed, several problematic elements remain in the Council's position. For instance, the Council wants to demand identity verification to use messaging services (including end-to-end encrypted). This would pose significant risks to dissidents, whistleblowers, and others, and create a chilling effect on free speech.
We hope the European Parliament stands firm against any wording that paves the way for mass surveillance and censorship. Cyprus, currently holding the Presidency of the Council of the EU, aims to conclude the negotiations by June.
A reminder of the corrupt backstory behind the Chat Control proposal and the involvement of Ashton Kutcher and his company Thorn: https://t.co/OcNkJMrjJa
🚨 Google wants to force every Android developer to register with them, even if you never touch the Play Store. We signed the open letter opposing this alongside EFF, Proton, F-Droid, Tor Project, and 30+ others. Android's openness is non-negotiable.
https://t.co/vzlPdOc5Sa
Following the Australian precedence, the UK, France, and Spain want age checks for social media.
😡But age verification and ID checks destroy everyone's #privacy. 😡
Learn what countries are planning a social media ban for teens and fight #AgeVerification 💪
👉https://t.co/xov9sUcmqy
🚨 IL PREZZO INVISIBILE DELL'ACCORDO UE-MERCOSUR 🚨
Mentre a Bruxelles si discute di dazi e mercati, il fotografo Pablo Ernesto Piovano ci sbatte in faccia la realtà: il nuovo accordo commerciale tra Unione Europea e i paesi del Mercosur (Brasile, Argentina, Uruguay, Paraguay) ha un costo sociale e umano spaventoso.
Le sue immagini nel progetto "El costo humano de los agrotóxicos" non sono solo foto, sono un atto d'accusa. Ecco cosa si nasconde dietro i numeri del commercio globale:
☣️ La "Geopolitica dei Veleni" L’accordo rischia di facilitare l'esportazione di pesticidi prodotti in Europa ma vietati nell'UE perché tossici. Li vendiamo al Sud America per poi ricomprare i prodotti coltivati con quegli stessi veleni. Un doppio standard etico insostenibile.
🏥 Un'emergenza sanitaria documentata Nelle zone delle monocolture di soia transgenica in Argentina:
✔️ I casi di cancro sono il triplo della media nazionale.
✔️ Le malformazioni congenite nei neonati sono quadruplicate.
✔️ Intere comunità rurali respirano quotidianamente glifosato irrorato dagli aerei.
🚜 L'espulsione dei contadini Il modello industriale spinto dall'accordo favorisce i latifondisti. Risultato? Migliaia di piccoli agricoltori e comunità indigene vengono cacciati dalle loro terre, alimentando la povertà estrema nelle periferie delle grandi città.
🌍 Dumping sociale e ambientale L'Europa chiede standard green ai propri agricoltori, ma poi apre le porte a prodotti che derivano da deforestazione e abuso di chimica. Non è solo competizione sleale: è ingiustizia ambientale.
👉 Il progresso economico può valere la salute di intere generazioni? Il lavoro di Piovano ci ricorda che ogni volta che il prezzo di un prodotto scende troppo, qualcuno, da qualche parte nel mondo, lo sta pagando con la propria vita.
🖼 Guarda il reportage completo di Piovano qui: https://t.co/RUCXXRBdRp
#UE #Mercosur #DirittiUmani #Ambiente #Salute #Piovano #Agrotossici
The war on privacy and encryption goes on. This time in the UK. Under the “Children’s Wellbeing and Schools Bill”, lawmakers now want client-side scanning on every phone and tablet.
The lawmakers write: “Any relevant device supplied for use in the UK must have installed tamper-proof system software which is highly effective at preventing the recording, transmitting (by any means, including livestreaming) and viewing of CSAM using that device.”
Once again, they use “what about the children”, this time to install state spyware that would continuously scan every action on a phone or tablet and watch everything that is shown on the screen. This will effectively ban end-to-end encrypted communication and open source operating systems like GrapheneOS and forbid that people have administrator rights on their own devices.
The bill also seeks “Action to prohibit the provision of VPN services to children in the United Kingdom” and wants “all regulated user-to-user services to use highly-effective age assurance measures to prevent children under the age of 16 from becoming or being users.” In practice, this means identity checks for VPN users, making things like anonymous whistleblowing difficult.
The attack on secure and private communication is worldwide. Now is the time for resistance. Demand transparency from your politicians, and privacy for the people.
The European Commission lost the Chat Control 2.0 battle over access to end-to-end encrypted data. By the summer 2026, they will be back with their next attempt: Going Dark. This time some EU member states want to include VPN services.
The Going Dark initiative, or ProtectEU as the Commission now calls it, wants to “enable law enforcement authorities to access encrypted data in a lawful manner”. This is a Chat Control 3.0 attempt.
The EU Commission and several member states are also looking for new rules on data retention. In a new ”Presidency outcome paper”, the member states discuss metadata retention: which websites you visit, and who is communicating with whom, when and how often. The ambition is “to have the broadest possible scope of application” and this time some member states also want the proposal to include VPN services.
Mullvad has spent the last three years opposing Chat Control 2.0 – even though the law would have affected our business positively.
We will continue to fight Going Dark with full force, regardless of whether VPNs are included or not. If VPNs are included, and if Going Dark becomes law, we will never spy on our customers no matter what.