惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

AWS News Blog
AWS News Blog
T
Tenable Blog
Project Zero
Project Zero
T
The Exploit Database - CXSecurity.com
L
LINUX DO - 热门话题
T
Threat Research - Cisco Blogs
T
Threatpost
Security Latest
Security Latest
C
Cisco Blogs
L
Lohrmann on Cybersecurity
S
Security @ Cisco Blogs
Google Online Security Blog
Google Online Security Blog
NISL@THU
NISL@THU
AI
AI
V
Vulnerabilities – Threatpost
Google DeepMind News
Google DeepMind News
C
Cyber Attacks, Cyber Crime and Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
The Last Watchdog
The Last Watchdog
G
GRAHAM CLULEY
Cloudbric
Cloudbric
H
Hackread – Cybersecurity News, Data Breaches, AI and More
H
Hacker News: Front Page
U
Unit 42
A
Arctic Wolf
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
MyScale Blog
MyScale Blog
O
OpenAI News
Scott Helme
Scott Helme
V2EX - 技术
V2EX - 技术
P
Proofpoint News Feed
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Cyberwarzone
Cyberwarzone
博客园 - 【当耐特】
H
Heimdal Security Blog
S
Schneier on Security
阮一峰的网络日志
阮一峰的网络日志
Help Net Security
Help Net Security
D
DataBreaches.Net
Y
Y Combinator Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
TaoSecurity Blog
TaoSecurity Blog
K
Kaspersky official blog
N
News and Events Feed by Topic
WordPress大学
WordPress大学
P
Palo Alto Networks Blog

Hacker News: Best

madhadron - The seven programming ur-languages GitHub - smol-machines/smolvm: Tool to build & run portable, lightweight, self-contained virtual machines. I Measured Claude 4.7's New Tokenizer. Here's What It Costs You. Introducing Claude Design by Anthropic Labs It Is Time to Ban the Sale of Precise Geolocation The creative software industry has declared war on Adobe Isaac Asimov: The Last Question Newly unsealed records reveal Amazon’s price-fixing tactics, California attorney general claims Clojure - Documentary Android CLI and skills: Build Android apps 3x faster using any agent Qwen3.6-35B-A3B on my laptop drew me a better pelican than Claude Opus 4.7 Codex for almost everything Introducing Claude Opus 4.7 Qwen Studio The Future of Everything is Lies, I Guess: Where Do We Go From Here? Virginia Bans Sale of Geolocation Data YouTube now lets you turn off Shorts Burgers | マクドナルド公式 ChatGPT for Excel Ask HN: Who is using OpenClaw? Live Nation illegally monopolized ticketing market, jury finds Google Broke Its Promise to Me. Now ICE Has My Data. Open Source Isn't Dead. The Future of Everything is Lies, I Guess: New Jobs Unexpected €54k billing spike in 13 hours: Firebase browser key without API restrictions used for Gemini requests IPv6 – Google Your Backpack Got Worse On Purpose Good sleep, good learning, good life Fixing a 20-year-old bug in Enlightenment E16. Does Gas Town 'steal' usage from users' LLM credits & paid services to improve itself? Tell HN: Fiverr left customer files public and searchable Cybersecurity Looks Like Proof of Work Now Getting the Flock out Release OpenSSL 4.0.0 · openssl/openssl Internet será irrespirable los días de fútbol y otros deportes. Telefónica extiende los bloqueos a Champions, tenis y golf. Automate work with routines - Claude Code Docs The Future of Everything is Lies, I Guess: Work Thousands of rare concert recordings are landing on the Internet Archive — listen now What is jj and why should I care? Backblaze has quietly stopped backing up your data Cal.com Goes Closed Source: Why AI Security Is Forcing Our Decision | Cal.com - Scheduling Software for Online Bookings Codex Hacked a Samsung TV The Future of Everything is Lies, I Guess: Safety GitHub - sterlingcrispin/nothing-ever-happens: Polymarket bot that buys "No" on all non-sports markets. For entertainment only, mostly a meme. Make tmux Pretty and Usable - Ham Vocke Microsoft isn't removing Copilot from Windows 11, it's just renaming it Servo is now available on crates.io - Servo aims to empower developers with a lightweight, high-performance alternative for embedding web technologies in applications. We May Be Living Through the Most Consequential Hundred Days in Cyber History, and Almost Nobody Has Noticed All elementary functions from a single binary operator 奈拜提耶市 Seven countries now generate 100% of their electricity from renewable energy Pro Max 5x Quota Exhausted in 1.5 Hours Despite Moderate Usage Tell HN: docker pull fails in spain due to football cloudflare block Bring Back Idiomatic Design @adlrocha - How the "AI Loser" may end up winning Apple update turns Czech mate for locked-out iPhone user Cache TTL silently regressed from 1h to 5m around early March 2026, causing quota and cost inflation The peril of laziness lost AI Will Be Met With Violence, and Nothing Good Will Come of It Center for Responsible, Decentralized Intelligence at Berkeley The disturbing white paper Red Hat is trying to erase from the internet – OSnews The Future of Everything is Lies, I Guess: Annoyances 447 Terabytes per Square Centimetre at Zero Retention Energy: Non-Volatile Memory at the Atomic Scale on Fluorographane Show HN: Pardonned.com – A searchable database of US Pardons 20 Years on AWS and Never Not My Job Artemis II crew splashes down near San Diego after historic moon mission Molotov Cocktail Is Hurled at Home of Sam Altman, OpenAI’s CEO France to ditch Windows for Linux to reduce reliance on US tech On filing the corners off my MacBooks Installing every* Firefox extension Chimpanzees in Uganda locked in vicious 'civil war', say researchers linux/Documentation/process/coding-assistants.rst at master · torvalds/linux GitHub - callumlocke/json-formatter: Makes JSON easy to read. A compelling title that is cryptic enough to get you to take action on it GitHub - Keychron/Keychron-Keyboards-Hardware-Design: Industrial design files for Keychron keyboards and mice. 100+ models with CAD assets in STEP, DXF, DWG, and PDF. Source-available, with commercial use allowed for original compatible accessories within the license terms. [ANNOUNCE] WireGuardNT v0.11 and WireGuard for Windows v0.6 Released 1D-Chess Helium Is Hard to Replace FBI used iPhone notification data to retrieve deleted Signal messages Microsoft suspends dev accounts for high-profile open source projects Why you can’t trust Privacy & Security Serenity Forge (@serenityforge.com) A new trick brings stability to quantum operations OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters Netflix Prices Went Up Again – I Bought a DVD Player Instead DOJ Wants to Scrap Watergate-Era Rule That Makes Presidential Records Public EFF is Leaving X How NASA built Artemis II’s fault-tolerant computer Meta removes ads for social media addiction litigation How Pizza Tycoon simulated traffic on a 25 MHz CPU Claude mixes up who said what, and that's not OK Reallocating $100/Month Claude Code spend to Zed and OpenRouter Help Keep Thunderbird Alive! Why Are Flock Employees Watching Our Children? The Pentagon Threatened Pope Leo XIV’s Ambassador With the Avignon Papacy Fragments: April 2 Native Instant Space Switching on MacOS Bitcoin miners are losing $19,000 on every BTC produced as difficulty drops 7.8% God sleeps in the minerals Apple Silicon and Virtual Machines: Beating the 2 VM Limit
The ‘papers, please’ era of the internet will decimate your privacy
Sarah McLaughlin · 2026-06-26 · via Hacker News: Best

Imagine your favorite team just scored an incredible, last-second goal at the World Cup. So you log online to celebrate with other fans. But, using data it’s already collected on you, the social media platform you like to post on wrongly guesses that you’re under 16 so it forces you to go to a third-party verification app and provide images of your face or your government-issued ID. You don’t really know much about the verification app, what country it’s based out of, what happens with your information, and whether you’re protected from hackers or data breaches. You’re not happy about it, but you hand over a photo of your passport and hope it doesn’t come back to haunt you.

Now imagine that instead of posting about sports, you’re criticizing a powerful politician, or talking about your experiences with abuse or addiction, or discussing embarrassing medical issues you’re facing. Suddenly this “papers, please” approach to the internet sounds even more invasive, right? Unfortunately, that’s the direction we’re all headed — even here in the United States — and we have good reason to be wary of the global rush to sacrifice user privacy on the altar of age verification.

Australia’s social media ban for under-16s went into effect in December 2025 and set a landmark standard many other nations now look to when crafting their own such regulations. As a preliminary matter: This law is not working as intended. The government’s own research found that months after the institution of the ban, roughly seven out of 10 kids still were using social media. And a study just released in the British Medical Journal found “little evidence was found of immediate substantive reductions in reported social media use by adolescents under 16 years.” Secondly, phones are already banned in Australian schools, so this ban is intended to address what kids do on the internet in their own free time, not during class time.

So, what exactly does this law — one that is rendered irrelevant during the school day, and isn’t even working properly outside it anyway — actually mandate? Well, pretty much what was in the hypothetical described earlier in this piece, except it’s not at all a hypothetical anymore.

Essays

Cassius Marcellus Clay brought cannons to a free press fight

Cassius Marcellus Clay brought cannons to a free press fight

In June 1845, Cassius Marcellus Clay launched an anti-slavery newspaper in Lexington, Kentucky, one block from one of the largest slave markets in the United States. He called it The True American. Published by William L. Neale and edited by Clay, the paper openly challenged Kentucky’s slaveholding establishment. Its editor was a son o…

Australia’s law mandates that social media companies, at risk of massive fines, collect either biometric info, government-issued IDs, or other data from users because they now have a duty to take sufficient steps to ensure users under 16 are kept logged out. In some cases, platforms can use existing data they have on users to verify age, like if an account has been open for a sufficient number of years, but will in many scenarios need to verify independently by gathering more user data. This is where third-party verification tools come in.

Look at Snapchat, for example. Snapchat uses k-ID, a company based in Singapore, and allows verification through a banking connection, government ID scan, or selfie the company uses to provide an age range. This requires quite an investment of trust on the user’s end. How do third-party companies like this retain and protect data? What kind of laws govern these companies abroad? Is such a company in another country more susceptible to censorial requests from local or foreign governments?

Australia does order that personal information collected for age verification “must be destroyed once all purposes have been met.” But those purposes include challenges and complaints, so it’s unclear exactly how long data will be retained on users who object to wrong age classifications. Worryingly, in research conducted before the ban went into effect, Australia’s Age Assurance Technology Trial “found some concerning evidence that in the absence of specific guidance, service providers were apparently over-anticipating the eventual needs of regulators about providing personal information for future investigation…which could lead to increased risk of privacy breaches due to unnecessary and disproportionate collection and retention of data.”

The longer that information is retained, and the more that is collected for verification, increases the risk of breaches or hacks that threaten a user’s privacy. Now multiply that individual risk by millions.

We don’t even need to imagine the hypothetical here, because it happened to nearly 70,000 Australians just weeks before the under-16 ban went into effect. A breach of a third-party customer service app Discord used “mainly to deal with” — guess what — “complaints relating to the platform’s age assurance processes” was hacked, leading to the release of “government ID images, names, usernames, email addresses, and some limited billing information.”

Expect more such attacks in the future.

In addition to introducing new risks from data breaches and hacks, the Australian government admits that mandated age verification introduces new risks for phishing attempts by scammers seeking to take advantage of confusion surrounding the ban. But the government puts much of the onus on social media platforms to ensure users understand the verification process and on users to read up to make sure they aren’t being scammed.

We have, quite reasonably, spent much of the 21st century debating what should be our relationship to tech companies and what amount of our personal lives and details we are comfortable handing over, knowingly or not. Governments have even been hauling tech CEOs in to question them about their intake of individuals’ data. Yet now countries like Australia are mandating that they collect it or face consequences.

As the Australian Human Rights Commission explains, even if some user accounts ultimately evade age checks, this signals a broader shift in how people use the internet:

The eSafety Commissioner’s guidance tries to reassure us: ‘No, not every account holder will go through an age check process if the platform has other accurate data.’ But that doesn’t actually mean you escape scrutiny. It just means that platforms will use what they already know about you to make the call. That’s the real shift that is happening here. We’re moving to a world where the law requires you to be profiled in order to participate.

The online world we’re moving toward is a “papers, please” one, where vital venues of public discussion might now only be open to those who are willing to trust tech companies and the third party verification apps they use with information that can eliminate their anonymity online, and the governments responsible for mandating the collection of that information.

Many users will very likely provide the information they need to log on and continue communicating with their friends and families. But maybe they’ll think twice about what they say and do. This new era of the internet is unlikely to be significantly safer for children. But it will be much less free for everyone.

You’ve likely heard by now that the UK (along with France, Spain, the United Arab Emirates, Indonesia, Malaysia, Greece, Denmark, Norway, and the European Union) is pursuing its own under-16 ban.

The ban will happen even though the exact details for its enforcement and verification methods are not yet public — but the UK intends to avoid Australia’s failures. That’s why Prime Minister Keir Starmer promised this month that the British version will be “Australia-plus,” as the UK will “learn the lessons from Australia’s experience” and “make it far harder for children to bypass safeguards.” (Starmer has since resigned as prime minister but there is currently no indication that the government’s plans for the policy will change.)

UK citizens have reason to worry. Australia’s enforcement of its under-16 ban comes with a wealth of risks to user privacy, so to see government officials signal that they intend more severe enforcement suggests the potential for even greater privacy threats.

Perhaps even most alarming is officials’ open interest in targeting virtual private networks to crack down on verification evasion. VPN use rose last year after the rollout of the UK’s similarly messy Online Safety Act, when internet users sought to avoid roadblocks from the government against online “harms.” After the Online Safety Act was implemented, UK officials said they were “gather[ing] information on VPN usage.” And as I explained at Persuasion last week:

One problem facing advocates of internet restrictions is the availability of virtual private networks (VPNs), which reroute traffic and allow users to access banned content or sites from behind firewalls or blocks. The UK government is well aware of the challenge VPNs may pose to its under-16 ban, and Technology Secretary Liz Kendall announced this week that the government “will make further statements in July about VPNs.” Children’s Minister Josh MacAlister has said there are “options there about whether we could age-gate VPN use, which would be really welcome.”

Many UK citizens no doubt have valid and reasonable concerns about the way their children experience the internet and social media. But they may be shocked and surprised by the amount of power and control UK officials claim they need to solve the problem. Should UK officials travel down the path of targeting VPN usage, they may find themselves more in line with countries like China, Iran, and Russia. It’s not good company.

Alarmingly, yes. The home of the First Amendment is on course to embrace the “papers, please” era of the internet and has been slinking towards it for years now.

A number of states have been developing and passing bills, many of which are facing challenges, that pose many of the same concerns we’ve raised in the international context. At least 19 states have passed legislation addressing minors’ access to social media or “addictive” feeds, but some are enforceable, some enjoined, and some not yet effective. And more than 20 states have enacted age-verification laws for adult-content websites, many of which became more secure after the Supreme Court’s decision in Free Speech Coalition v. Paxton in 2025. Separately, app-store age-assurance laws are being litigated in states such as Texas and Utah.

While this takes place among the states, at the federal level we’re seeing a number of proposals being considered, including the so-called “Kids Online Safety Act,” or KOSA, which was incorporated in the House’s broader KIDS Act package and has been the subject of negotiations between the Senate and the White House. The House and Senate have slightly different versions of the bill, but both would impose regulations that would effectively force social media websites and other platforms to conduct age verification of their users. And since it’s a federal bill, states that wanted to maintain a free and open internet would be overridden. The entire country would be forced to reveal their identity and data before they could speak online.

What this means for the American people is that both the state and federal government could be mandating collection of information about you at every step you engage with the internet. Soon, everything you do online could have an element of age assurance or verification, from downloading an app in the app store to making an account to posting a photo, whether you’re a 14-year-old trying to game or a 40-year-old posting about recipes. The debate is rapidly expanding to include video games and AI chatbots as well.

And that creates a lot of risks for data breaches, overly broad data collection and retention, censorial legal demands for collected data, corporate and governmental malfeasance, pressure to self-censor, and perhaps blatant First Amendment violations. Every new layer and every new mandate brings more potential for risk. As we’ve unfortunately seen many times over the years, people including high-level government officials will maliciously seek to root out the identities of their critics, so the more layers of anonymity we can preserve in online speech, the better.

Americans can take seriously the need to protect kids online while still recognizing that many of the policy and legislative solutions offered today are creating intolerable burdens on our ability to speak freely and anonymously on the internet. The reality is that age verification to a large extent requires us to confirm identity, and we will come to regret so closely tying our expressive activity online to government-mandated age and identity verification. Once we create this legislative infrastructure of surveillance we may find it very difficult to tear down.