惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Microsoft Security Blog
Microsoft Security Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
G
GRAHAM CLULEY
H
Hackread – Cybersecurity News, Data Breaches, AI and More
阮一峰的网络日志
阮一峰的网络日志
L
Lohrmann on Cybersecurity
S
Security @ Cisco Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Security Affairs
The Cloudflare Blog
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Spread Privacy
Spread Privacy
Y
Y Combinator Blog
V2EX - 技术
V2EX - 技术
罗磊的独立博客
F
Full Disclosure
Jina AI
Jina AI
S
Schneier on Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
C
CXSECURITY Database RSS Feed - CXSecurity.com
Webroot Blog
Webroot Blog
雷峰网
雷峰网
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Recorded Future
Recorded Future
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 三生石上(FineUI控件)
K
Kaspersky official blog
V
Visual Studio Blog
Vercel News
Vercel News
Cyberwarzone
Cyberwarzone
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
T
Tor Project blog
Cloudbric
Cloudbric
Hacker News - Newest:
Hacker News - Newest: "LLM"
爱范儿
爱范儿
L
LINUX DO - 最新话题
GbyAI
GbyAI
Attack and Defense Labs
Attack and Defense Labs
H
Heimdal Security Blog
Recent Announcements
Recent Announcements
L
LINUX DO - 热门话题
L
LangChain Blog
Simon Willison's Weblog
Simon Willison's Weblog

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition Roblox executors: It’s all fun and games until someone gets hacked DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception Watch out for SVG files booby-trapped with malware Gamaredon X Turla collab Small business, big risk: How SMBs can fight back against ransomware HybridPetya: A Petya/NotPetya copycat comes with a twist Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass Are cybercriminals hacking your systems – or just logging in? Preventing business disruption and building cyber-resilience with MDR Under lock and key: Safeguarding business data with encryption GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes This month in security with Tony Anscombe – August 2025 edition Don’t let “back to school” become “back to bullying”
Is it time for internet services to adopt identity verification?
Tony Anscombe · 2026-01-14 · via WeLiveSecurity

Social Media

Should verified identities become the standard online? Australia’s social media ban for under-16s shows why the question matters.

14 Jan 2026  •  , 5 min. read

Is it time for internet services to adopt identity verification?

New legislation in Australia makes it illegal for those under 16 to have a social media account. To avoid financial penalties, social media companies have scrambled to remove accounts they believe breach the legislation. Notably, there are no consequences for the under-16s who attempt to create an account using a fraudulent age. As the first country to introduce such a ban, Australia has become a bit of a test case: the world is watching to see how effective the legislation is and whether it produces the desired results.

As 2026 has just begun, this also sparks a broader question for internet users and regulators alike: will this be the year the world rethinks identity online?

The status quo doesn’t work – what will?

While Australia's new age rules are rooted in concerns over the well-documented risks children face on social media platforms, the need to change the experience of social media is probably not best served by banning it entirely. The underlying issues remain. Once someone turns 16, is it suddenly acceptable to subject them to the issues they have been shielded from? Surely all people should be protected from harmful content, abuse and other negative experience. History also suggests that banning something causes greater demand. I remember from my own youth when radio stations banned the likes of “Relax” by Frankie Goes to Hollywood – the ban just made everyone listen to it more and helped keep the track at number one in the charts for longer. Denial fuels demand, and in this instance it could exacerbate the issue of online dangers as those under 16 in Australia look for alternatives.

Meanwhile, age-verification legislation in various other countries and in some U.S. states is also attempting to limit access to adult content, bringing about numerous age-verification technologies on websites that need to restrict their content. Some technologies offer real-time age determination based on facial features while others rely on more formal ways, using government-issued identification or financial documents. All of these approaches can create additional privacy concerns, especially around data collection and storage.

Add into this mix the likes of phishing emails, romance scams, financial fraud and all the other various ways that cybercriminals and fraudsters attempt to dupe their victims, and it may raise the question: is the way that internet services and apps work today still fit for purpose?

Also, imagine being told 30 years ago that one day a small device in your pocket would allow you to connect to virtually anyone from anywhere, interact, shop, make reservations, watch TV on demand. But alongside these cool features in your phone, there’s also the ability to bully others and be as abusive as you want without accountability, and even remain anonymous when doing so – or, indeed, be on the receiving end of such behavior. When considered in this way, you might have considered not having one of these devices.

The abuser next door

There may be an assumption that abusive or unwanted behavior on the internet comes from somewhere else: it’s not your neighbor, not someone you know, not even someone from your town – it’s probably Russian bots or someone from afar. However, a recent BBC investigation found that in just one weekend there were 2,000 extremely abusive social media posts directed at managers and players in the Premier League and Women’s Super League, with some being so extreme as to involve threats of death and rape. Identifying the individuals behind the extreme posts is unlikely as there is no formal identification needed when creating social media accounts, and using a VPN makes tracking difficult.

Unless an app or service is operated by a regulated company that requires identity verification, people are free to create accounts on many services using any identity they desire. This option for anonymity has been a core concept of freedom on the internet, although whether this was by design is questionable. The barrier for positive identification when creating an account is that services could ultimately have fewer users – it would introduce friction at account creation, something that companies relying on user numbers to deliver ads and sponsored content want to avoid.

This leads to a broader question: Is it time for a general acceptance that the internet needs to have verified, authenticated users?

I am not suggesting that all services need to have verified users. However, if I could switch off content, posts and communication attempts from non-verified users, then my online experience might improve significantly. The football managers and players in the Premier League could be on social media without being subjected to the torrent of trash and abuse they see today, and if a verified user makes an extreme threat they will face the consequences of law enforcement. Extending this concept so that under-16s could only interact with content from verified users may not completely solve the issues of today, but likely answers the 80/20 rule of removing 80% of the issues.

The benefits are not limited to social media. At present, my email inbox has the option to separate general mailing list email from email messages that need action. Introducing a third filter for unverified senders would also help winnow away possible spear-phishing and targeted attacks. There is, of course, the risk of cybercriminals hijacking verified accounts, so this is not a silver bullet. It does, however, add another layer of protection.

Verified doesn’t equate to visible

Crucially, identity verification doesn’t remove the option of protecting identity. For example, a dating platform may verify the identity of all the subscribers but still allow them to take on any profile identity they choose. The protection comes in knowing that every member on the platform has been verified as a real person and their identity is known to the platform. Any abuse or fraud is then attributable to the individual, allowing the appropriate authorities to take action.

Moving to an internet that distinguishes between verified and non-verified individuals would be a huge reset of the status quo. Claims about limitations of freedom of speech would follow while companies relying on user numbers to demonstrate growth might even need to reset their valuations. However, the concept of verified identities does not silence speech or restrict freedom. What it does is give people the option to filter out the noise and abuse originating from the unverified.

One thing is for certain: the current methods of limiting content by age are not resolving the issue of unwanted, abusive or illegal content. And when it comes to those being prohibited from using social media, the measures are likely to push some of them underground or drive them to circumvent the restrictions, which will potentially be more dangerous and increase risk, rather than reducing it.


Let us keep you
up to date

Sign up for our newsletters