惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Cisco Blogs
The Cloudflare Blog
云风的 BLOG
云风的 BLOG
Recorded Future
Recorded Future
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
U
Unit 42
博客园 - 三生石上(FineUI控件)
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
N
Netflix TechBlog - Medium
C
Check Point Blog
Security Latest
Security Latest
MongoDB | Blog
MongoDB | Blog
P
Proofpoint News Feed
J
Java Code Geeks
The GitHub Blog
The GitHub Blog
V
Vulnerabilities – Threatpost
阮一峰的网络日志
阮一峰的网络日志
P
Palo Alto Networks Blog
C
CERT Recently Published Vulnerability Notes
F
Full Disclosure
C
Cyber Attacks, Cyber Crime and Cyber Security
雷峰网
雷峰网
T
The Blog of Author Tim Ferriss
T
Threat Research - Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
V
V2EX
Latest news
Latest news
Engineering at Meta
Engineering at Meta
A
About on SuperTechFans
Cyberwarzone
Cyberwarzone
The Hacker News
The Hacker News
A
Arctic Wolf
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
NISL@THU
NISL@THU
腾讯CDC
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
罗磊的独立博客
S
Schneier on Security
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 司徒正美
K
Kaspersky official blog
L
Lohrmann on Cybersecurity
C
CXSECURITY Database RSS Feed - CXSecurity.com
月光博客
月光博客
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Project Zero
Project Zero
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
I
InfoQ

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition Roblox executors: It’s all fun and games until someone gets hacked DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception Watch out for SVG files booby-trapped with malware Gamaredon X Turla collab Small business, big risk: How SMBs can fight back against ransomware HybridPetya: A Petya/NotPetya copycat comes with a twist Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass Are cybercriminals hacking your systems – or just logging in? Preventing business disruption and building cyber-resilience with MDR Under lock and key: Safeguarding business data with encryption GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes This month in security with Tony Anscombe – August 2025 edition Don’t let “back to school” become “back to bullying”
Is it time for internet services to adopt identity verification?
Tony Anscombe · 2026-01-14 · via WeLiveSecurity

Social Media

Should verified identities become the standard online? Australia’s social media ban for under-16s shows why the question matters.

14 Jan 2026  •  , 5 min. read

Is it time for internet services to adopt identity verification?

New legislation in Australia makes it illegal for those under 16 to have a social media account. To avoid financial penalties, social media companies have scrambled to remove accounts they believe breach the legislation. Notably, there are no consequences for the under-16s who attempt to create an account using a fraudulent age. As the first country to introduce such a ban, Australia has become a bit of a test case: the world is watching to see how effective the legislation is and whether it produces the desired results.

As 2026 has just begun, this also sparks a broader question for internet users and regulators alike: will this be the year the world rethinks identity online?

The status quo doesn’t work – what will?

While Australia's new age rules are rooted in concerns over the well-documented risks children face on social media platforms, the need to change the experience of social media is probably not best served by banning it entirely. The underlying issues remain. Once someone turns 16, is it suddenly acceptable to subject them to the issues they have been shielded from? Surely all people should be protected from harmful content, abuse and other negative experience. History also suggests that banning something causes greater demand. I remember from my own youth when radio stations banned the likes of “Relax” by Frankie Goes to Hollywood – the ban just made everyone listen to it more and helped keep the track at number one in the charts for longer. Denial fuels demand, and in this instance it could exacerbate the issue of online dangers as those under 16 in Australia look for alternatives.

Meanwhile, age-verification legislation in various other countries and in some U.S. states is also attempting to limit access to adult content, bringing about numerous age-verification technologies on websites that need to restrict their content. Some technologies offer real-time age determination based on facial features while others rely on more formal ways, using government-issued identification or financial documents. All of these approaches can create additional privacy concerns, especially around data collection and storage.

Add into this mix the likes of phishing emails, romance scams, financial fraud and all the other various ways that cybercriminals and fraudsters attempt to dupe their victims, and it may raise the question: is the way that internet services and apps work today still fit for purpose?

Also, imagine being told 30 years ago that one day a small device in your pocket would allow you to connect to virtually anyone from anywhere, interact, shop, make reservations, watch TV on demand. But alongside these cool features in your phone, there’s also the ability to bully others and be as abusive as you want without accountability, and even remain anonymous when doing so – or, indeed, be on the receiving end of such behavior. When considered in this way, you might have considered not having one of these devices.

The abuser next door

There may be an assumption that abusive or unwanted behavior on the internet comes from somewhere else: it’s not your neighbor, not someone you know, not even someone from your town – it’s probably Russian bots or someone from afar. However, a recent BBC investigation found that in just one weekend there were 2,000 extremely abusive social media posts directed at managers and players in the Premier League and Women’s Super League, with some being so extreme as to involve threats of death and rape. Identifying the individuals behind the extreme posts is unlikely as there is no formal identification needed when creating social media accounts, and using a VPN makes tracking difficult.

Unless an app or service is operated by a regulated company that requires identity verification, people are free to create accounts on many services using any identity they desire. This option for anonymity has been a core concept of freedom on the internet, although whether this was by design is questionable. The barrier for positive identification when creating an account is that services could ultimately have fewer users – it would introduce friction at account creation, something that companies relying on user numbers to deliver ads and sponsored content want to avoid.

This leads to a broader question: Is it time for a general acceptance that the internet needs to have verified, authenticated users?

I am not suggesting that all services need to have verified users. However, if I could switch off content, posts and communication attempts from non-verified users, then my online experience might improve significantly. The football managers and players in the Premier League could be on social media without being subjected to the torrent of trash and abuse they see today, and if a verified user makes an extreme threat they will face the consequences of law enforcement. Extending this concept so that under-16s could only interact with content from verified users may not completely solve the issues of today, but likely answers the 80/20 rule of removing 80% of the issues.

The benefits are not limited to social media. At present, my email inbox has the option to separate general mailing list email from email messages that need action. Introducing a third filter for unverified senders would also help winnow away possible spear-phishing and targeted attacks. There is, of course, the risk of cybercriminals hijacking verified accounts, so this is not a silver bullet. It does, however, add another layer of protection.

Verified doesn’t equate to visible

Crucially, identity verification doesn’t remove the option of protecting identity. For example, a dating platform may verify the identity of all the subscribers but still allow them to take on any profile identity they choose. The protection comes in knowing that every member on the platform has been verified as a real person and their identity is known to the platform. Any abuse or fraud is then attributable to the individual, allowing the appropriate authorities to take action.

Moving to an internet that distinguishes between verified and non-verified individuals would be a huge reset of the status quo. Claims about limitations of freedom of speech would follow while companies relying on user numbers to demonstrate growth might even need to reset their valuations. However, the concept of verified identities does not silence speech or restrict freedom. What it does is give people the option to filter out the noise and abuse originating from the unverified.

One thing is for certain: the current methods of limiting content by age are not resolving the issue of unwanted, abusive or illegal content. And when it comes to those being prohibited from using social media, the measures are likely to push some of them underground or drive them to circumvent the restrictions, which will potentially be more dangerous and increase risk, rather than reducing it.


Let us keep you
up to date

Sign up for our newsletters