Hopefully, governments forcing people to show ID just to get online might end up being the biggest push towards open source and decentralization we’ve seen.
People will just host their own instances with no third party to hand your ID to, or a company deciding whether you’re allowed to speak.
The more they try to control this stuff, the more reason people have to build things they can’t control.
Si tenemos gobiernos que se supone que están ahí para velar por los ciudadanos ante situaciones injustas... ¿por qué no actúan cuando se producen situaciones injustas?
Si no van a actuar y todo se reduce a la acción ciudadana... ¿para qué los necesitamos?
Say no to age verification at the operating system level.
Say no to age verification at the app store level.
Say no to age verification for apps.
Say no to age verification for websites.
Say no to age verification anywhere online.
Age verification is a scam and a con job.
Hoy es otro día como cualquier otro para recordar que basta con que el suficiente número de personas coordinen una red descentralizada para que bloquear sea imposible...
Legislative Trojan horses
🇪🇺 Chat Control 1.0 and 2.0
🇪🇺 Social media ban for children
🇪🇺 Addictive design ban for adults
🇪🇺 Combat fraud and serious crime
🇦🇺 Social media ban for children
🇺🇸 Social media ban for children
🇺🇸 Addictive design restrictions for children
🇳🇿 Social media ban for children
🇮🇪 Social media ban for children
🇫🇷 Social media ban for children
🇨🇦 Social media ban for children
🇬🇧 Social media ban for children
🇬🇧 Addictive design restrictions for children
🇬🇧 Child exploitation & grooming protection
🇬🇧 Force platforms to prioritise "trusted" news
🇦🇪 Social media ban for children
🇪🇸 Social media ban for children
🇬🇷 Social media ban for children
🇩🇰 Social media ban for children
🇳🇴 Social media ban for children
🇦🇹 Social media ban for children
🇵🇱 Social media ban for children
🇸🇮 Social media ban for children
🇹🇷 Social media ban for children
🇮🇩 Social media ban for children
🇲🇾 Social media ban for children
🇧🇷 Social media restrictions for children
🇵🇹 Social media restrictions for children
🇮🇳 Social media ban for children
🇸🇪 Social media ban for children
🇩🇪 Social media restrictions for children
🇮🇹 Social media restrictions for children
🇨🇳 Social media restrictions for children
I’m sharing this because more journalists have started following my work, and I want to show what I’m exposing through technical analysis anyone can understand.
I’m working on one of my most consequential investigations into legislation and technology built for digital surveillance. It’s called Chat Control. What follows looks like coordination between governments and a handful of tech companies.
Tech companies get more data to monetise. Governments gain the ability to monitor who says what, to whom, why, where they go and how they spend money.
Technical Trojan horses
🇪🇺 Compulsory identity verification
🇪🇺 Scan private communications
🇪🇺 Weaken end to end encryption
🇪🇺 Expand lawful access
🇬🇧 Compulsory identity verification
🇬🇧 Compulsory on-device scanning for every app
🇬🇧 Algorithms to prioritize trusted news sources
🇦🇺 Compulsory identity verification
🇳🇿 Compulsory identity verification
🇮🇪 Compulsory identity verification
🇫🇷 Compulsory identity verification
🇪🇸 Compulsory identity verification
🇬🇷 Compulsory identity verification
🇩🇰 Compulsory identity verification
🇳🇴 Compulsory identity verification
🇦🇹 Compulsory identity verification
🇵🇱 Compulsory identity verification
🇸🇮 Compulsory identity verification
🇹🇷 Compulsory identity verification
🇦🇪 Compulsory identity verification
🇮🇩 Compulsory identity verification
🇲🇾 Compulsory identity verification
🇧🇷 Compulsory identity verification
🇵🇹 Compulsory identity verification
🇨🇦 Compulsory identity verification
🇺🇸 Compulsory identity verification
Spot the pattern.
🔞 Australia set the stage. Other countries are now following with "robust" age assurance language in their TV appearances, including the US, UK and Ireland. The US AGs have added it to the proposed legislation following the Meta lawsuit.
💡 Australia’s own standard says age checks must be "technically accurate, robust, and reliable".
"Robust" means fault proof. It brings meaning like "best" endeavours.
Age estimation can’t meet that standard. As Australia defines it, age verification determines age "to a high level of accuracy", while age estimation only provides an approximate age.
Fault proof age checking requires identity verification.
Now look at the tech companies and what they built recently.
Apple, Google, Meta and Microsoft built identity verification capabilities before governments started saying existing age assurance wasn’t "robust" enough.
They knew what was coming.
🪪 Apple has age assurance APIs that can return verified age ranges, including confirmation using government ID, and its Wallet API lets apps verify age or identity from government issued digital ID.
🪪 Google recently built an Age Signals API so apps can receive age ranges and verification status. Android already lets parents block apps by age across the entire device, so this isn’t technically necessary for child safety.
Google has also added facial verification to Google Account and Gmail recovery through selfie video matching, presented as account security.
🪪 Meta launched selfie based Facebook verification that checks a video selfie against profile photos and plans to expand it globally.
🪪 Microsoft has rolled out age assurance across Microsoft Accounts using facial age estimation, identity documents and government systems. Refuse to verify and some content and features are blocked.
💭 A handful of tech companies control the operating systems, app stores and identity layers across almost every mobile device. Governments barely need to negotiate outside G7 rooms. If Apple, Google, Meta and Microsoft enforce the same rules, billions of people are instantly impacted.
The same technical capability keeps appearing: identify verification.
Identity the person first, then decide what they’re allowed to do, who they're allowed to speak to, and when they're allowed to move money.
p.s. Anthropic and OpenAI have identity verification services and the US government holds a kill switch that decides who has permission to use AI.
---
Let me know if I got anything wrong. I have 60 minutes to make an edit. Or just leave a comment so others can see your correction.
Más de 1 año después, el Tribunal Constitucional sigue sin decidir si admite el recurso contra los bloqueos masivos de LaLiga
Ya sabemos quién gana y quién pierde con la lentitud de la justicia
https://t.co/sT9zlv1ceO
Por @internautas
Governments and tech companies are creating systems that remove anonymity, expand surveillance and give them more control over what people can say, access and do online.
Tech companies amplify fear about extreme AI risks because they want regulation that protects their interests. Compliance costs shut out smaller and open source competitors, leaving a few corporations controlling AI.
Governments gain more control over digital services, while those companies gain more data, fewer competitors and deeper control over online life.
Child safety is one of the easiest ways to overcome public resistance because few people want to be seen opposing it.
The EU Kids Act uses that pressure to normalise identity verification for online access. People are then pushed to connect their legal identity to more of what they do online.
Device based parental controls already let parents restrict apps, websites and screen time without collecting identity data. That shows child protection isn’t the reason for “robust” age checks.
Zero knowledge proofs don’t solve the privacy problem. They still depend on an approved credential to establish the claim.
“Chat Control”
CSAM justifies scanning private communications. Once that’s possible, the device becomes a surveillance point. Encryption becomes irrelevant if content can be examined before encryption or after decryption.
“Going Dark”
Fraud, terrorism and serious crime justify lawful access to encrypted data. The EU is developing tech to give law enforcement greater access to encrypted information and plans new decryption capabilities for Europol.
End to end encryption means nobody except the people communicating can read the content. Once governments have access, that protection ends.
VPNs
Their privacy value comes from separating identity from internet activity and preventing 3rd parties from seeing traffic. Force age checks, logging or government access and the service may still be called a VPN, but its protection is gone.
The pattern
Protect children to justify identity verification.
Stop CSAM to justify scanning private communications.
Stop fraud and serious crime to justify access to encryption.
Each argument targets something almost nobody will defend. Each solution creates powers that apply to everyone.
Mandatory verification ends pseudonymity by linking online activity to a real identity. That can then be used to profile populations, influence spending and shape political behaviour.
Payments, private messages and travel records can then be linked through a small number of controlled, state monitored services.
State agencies adapt cold war subversion tactics to parse these data streams, running predictive algorithms to identify potential dissent. Pre emptive intervention replaces post crime prosecution.
Access to money, travel and speech can be granted only while someone complies, then removed before they’ve committed any crime.
A centralised digital system gives authorities a kill switch. Once identity, payments, communication and movement are connected, a targeted person or group can be cut off from money, platforms and travel almost instantly because an automated system flagged their behaviour.
Blackouts stop people organising before resistance can form. If people can’t communicate, coordinate or mobilise, political opposition becomes far harder.
Total surveillance makes private, unmonitored communication unacceptable. The open web can then be recast as a dark web, making anonymous communication look criminal. People who still want privacy and basic civil liberties are forced to build separate networks outside state control.
The EU describes strong encryption as necessary for privacy and cybersecurity while developing technology for lawful access to encrypted data. That contradiction is more powerful than claiming it has already abolished encryption or VPNs.
https://t.co/5EGwmuntXV
At first they claimed age verification on social media was just 'to protect kids', now the new plans of the EU 🇪🇺 Commission couldn't be more clear:
"Anyone who creates new accounts on social media will have to prove their age in the future."
'1984' wasn't meant to be a manual.
😡🚨 Next round coming up: Let's fight against #ChatControl 🚨😡
In July, the European Parliament approved Chat Control 1.0 👉 NOW, On September 29, the negotiations for CHAT CONTROL 2.0 RETURN.
Unfortunately, this is a much bigger threat for everybody's #privacy.
At Tuta we will continue to SAY NO to Chat Control and fight for our right to privacy ✊❤️
Find more about Voluntary Chat Control 1.0 👉 https://t.co/7PjSq6JciE
Find more about Chat Control 2.0 👉 https://t.co/JLei3q3UVK
The fight against #ChatControl must go on!
@LaMadreDeSatan 😢 Una pena, Madre. Tus post eran siempre una fuente de información y contraste importante. Suerte en tus nuevos proyectos, y espero poder enterarme de ellos en algún momento
España bloquea https://t.co/69gK3X2b5b
El Ministerio de Cultura ha ordenado el bloqueo de https://t.co/69gK3X2b5b y sus dominios en España
https://t.co/RcTqQZk0C2
Ursula von der Leyen announced this week that everyone in the EU must use the official EU age verification app to verify their age before they can log into or post on social media and other digital services.
As an expert in online child safety, I'm here to expose the disinformation in each von der Leyen's statements. See below.
🇪🇺 The EU Kids Act is a pretext designed to enforce mandatory digital identity verification on everyone in Europe. The proposed legislation applies to any digital service featuring feeds, user generated content, or messaging:
Social media networks, video platforms, online gaming services, AI tools, and media streaming apps like Spotify. (@TimSweeneyEpic)
Under the proposal, digital services must enforce age restrictions across strict tiers. Tech companies must mandate age verification across all accounts to enforce these tiers legally.
When Australia introduced its social media ban, the government conceded it failed because platform level age checks weren’t reliable. They now reject age estimation as inadequate and shifted to demanding "robust" age checking.
💡 If you eliminate every unproven estimation method, you’re left with exactly 1 functional mechanism: identity verification. There's not other way to ensure age checking is "robust".
No government wants to admit citizens must prove their real identity just to access apps and basic streaming services like Spotify, so they hide behind the ambiguous phrase "robust age checking". This language is now used across Australia, the US, and Ireland to mandate identity checks while avoiding the public backlash of calling it what it is. I will research to see where else it’s being used.
Below is what Ursula von der Leyen told the European Parliament in Strasbourg along with my analsyis:
🇪🇺 "Today, much of this power has been taken out of the hands of parents... What our children need is time... But when a child has a smartphone, all of this is taken away."
💡 This framing falsely presents smartphones as uncontrollable. Apple and Google built free OS controls into iOS and Android settings, covering virtually every smartphone on the market.
These controls achieve every legitimate safety objective without collecting personal data or processing state credentials.
💡 Millions of parents use these parental controls to enforce screen time curfews, block app installations, and restrict communication.
💡 These settings operate at the device level. Teens can't bypass them when protected with a passcode.
To bypass this technical reality, the European Commission uses public grief to shut down logical analysis:
🇪🇺 "Day and night, parents see the costs, loss of sleep, anxiety, even self-harm, and in a growing number of cases, even fatal tragedies… a 14-year-old girl living in Belgium who took her life exactly one month ago, victim of bullying online... Honourable members, enough is enough."
💡 Citing personal tragedies replaces software engineering facts with emotional rhetoric. State laws and age gates don’t alter human behaviour or prevent online harassment. Regulators exploit grief to pass surveillance legislation without explaining how the underlying software mechanisms operate.
The Commission outlines specific age tiers to restrict access:
🇪🇺 "In sum, no social media under the age of 13. No personal account under the age of 15. That means from 13 to under 15, only mini accounts set up and supervised by parents or guardians with limited features and time restriction to one hour a day. And between 15 and 18, safe design will be an obligation for the platforms."
💡 Enforcing age tiers forces tech companies and service providers to rebuild their architecture around total access control. The must disable self-service account creation, purge unverified accounts, build supervised parental workflows, strip algorithmic feeds, and enforce strict session cutoffs.
💡 Social networks operate on open interaction algorithms that inherently expose people to unvetted content. Because software can’t dynamically filter these risks for minors, tech companies must block access for everyone until a person proves their real identity.
💡 It’s not just about social networks. They want the same bans for almost everything, including games and stream services. Even Spotify because it’s possible for customers to message people.
The Commission claims its proposed zero knowledge proof app protects personal privacy:
🇪🇺 "Age will be verified using EU certified tools like our age verification app. This app is built on zero knowledge proof. That means that the platform only learns one single thing, and that's whether you're old enough to allow access or not."
💡 This framing describes what an app or service receives while hiding what everyone must give up. A zero knowledge proof provides a mathematical confirmation, but that confirmation requires an authoritative issuer. Before the app generates a proof, a state approved entity must verify the person's real identity.
The Commission frames this shift as a victory against tech corporations:
🇪🇺 "I am aware that many perceive the power of Big Tech as overwhelming and impossible to roll back. I disagree... So we do not accept this. We are reversing the burden of proof. Now platforms will have to prove to us that they are safe. Because this is not about our minors accessing social media. It is about when and how we allow social media to access our minors."
💡 Social networks don’t access children; parents hand smartphones to children. Reversing the burden of proof forces everyone to verify their identity.
The European Commission confirmed the broader scope of this mandate:
🇪🇺 "We also know that not only minors are at risk. Addictive design, for example, are harming everyone. This is why we need a wider framework too, the Digital Fairness Act that we will propose in autumn."
🚨 Child safety is merely the initial wedge. The Digital Fairness Act expands state mandated identity verification to adults across all online services. Binding real identities to online activity permanently eliminates pseudonymous access, private communication, and democratic accountability.
🚨 Senior state officials and regulators know their demands have nothing to do with child safety. They work closely with tech companies and understand that iOS and Android already provide complete authority to restrict devices locally without collecting personal data. State officials deliberately ignore well established parental controls because they keep internet access under family control. Child safety is a public pretext.
🚨 Governments and regulators use child safety to establish mandatory identity verification across every app and digital service, eliminating online anonymity. When tech companies and state agencies link every social media post, private message, search term, geographic location, and financial transaction to a verified identity, they create a permanent digital dossier on every citizen with a global social graph that makes Cambridge Analytica look like a 2nd grade school science project.
💡 Binding people’s identity to daily activity enables predictive behavioural modelling too. By feeding identity data into automated predictive AI, governments, intelligence agencies, law enforcement, and tech companies move beyond surveillance past behaviour. They can map political affiliations, predict individual actions, flag dissent before it occurs, and control public opinion at scale. Eliminating online anonymity ends free speech, private communication, and democratic accountability.
As Larry Ellison stated at Oracle’s Financial Analyst Meeting in 2024:
"Citizens will be on their best behaviour, because we’re constantly recording and reporting everything that’s going on".
🙏🏻 Share this to expose how governments use child safety as a false pretext to force mandatory digital identity verification on everyone.
https://t.co/euLnd0qfhK
Technical facts disproving political and tech claims on online child safety:
Protecting children online requires knowing who is a child. Knowing who is a child requires knowing ages. Knowing ages requires knowing everyone's age across all devices, apps, and internet services. That requires age checking services.
Age checking services cannot comply with government mandates to be "robust". "Robust" age checking originated in Australia and is now in US and EU legislation. It means "best endeavours" with specific legal intent.
"Robust" age checking requires proving age beyond doubt. Age estimation services can never be "robust". You cannot have a "robust" service without verifying everyone's identity through government issued ID or extensive personal, financial, or behavioural data. Without enough data, device, app, or service access is denied until official ID is provided.
Verifying every identity destroys privacy. Storing verification data on servers creates instant risk. Identity verification enables governments to monitor citizens and censor speech. As Larry Ellison said, people change behaviour when monitored through digital surveillance.
Parents can already protect children from online harms using existing technology. In 2012, I demonstrated poor parental controls on BBC Newsnight, leading me to build early safety tools for Samsung and Apple. I also built the first Android time curfew capability 14 years ago.
Today, iOS and Android offer built in controls to block unsuitable apps, websites, and content by age rating, alongside granular curfews. Real world risks like bullying exist online, but parents can manage access just as they manage real world exposure.
Exhibit A: If parents can already block access for free on their own phones, why do governments push legislation that forces identity collection, exposing data to cybercriminals and tech companies?
Exhibit B: Why are governments, tech companies, and NGOs not educating parents on existing settings that are free of charge and "robust", even while citing tragic cases to push legislation?
In 2004, I co-founded the W3C standard for Content Labelling and URI Classification, co-inventing account and folder classification to label content based on risk and compliance. I advocated for voluntary account verification to stop impersonation long before people knew it was even possible.
Mandatory identity verification to use a phone or internet service is dystopian control. I would never advocate or support that.
I have advised the US DOJ, NCMEC, CEOP, and IWF on child exploitation detection. EU Chat Control and UK image scanning mandates will not tackle exploitation. They break end to end encryption and VPNs, introducing dangerous spyware, and puts more children at risk.