惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
U
Unit 42
大猫的无限游戏
大猫的无限游戏
H
Help Net Security
G
Google Developers Blog
Recent Announcements
Recent Announcements
B
Blog RSS Feed
罗磊的独立博客
博客园 - Franky
J
Java Code Geeks
S
SegmentFault 最新的问题
D
DataBreaches.Net
C
Check Point Blog
Blog — PlanetScale
Blog — PlanetScale
T
The Blog of Author Tim Ferriss
有赞技术团队
有赞技术团队
腾讯CDC
博客园_首页
美团技术团队
V
Visual Studio Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
The Cloudflare Blog
aimingoo的专栏
aimingoo的专栏

The Register - Security

India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw
Age checks could turn internet into an ID checkpoint, com...
Carly Page · 2026-04-24 · via The Register - Security

Proton's boss has waded into the age verification fight with a warning that sounds less like child safety and more like an identity checkpoint for the entire internet.

In a blog post on Thursday, Andy Yen, CEO of Proton, argues that the current push for age checks risks flipping the web from anonymous by default to something closer to "show your papers" before you click.

The problem, he says, is that you can't reliably identify minors without identifying everyone else first, meaning systems built to protect kids inevitably sweep up adults too. "We cannot accept a world where every adult is expected to hand over ID as the price of going online."

That argument is landing as age checks move from policy debate to product reality. Anthropic has already rolled out ID verification tied to certain personas in its Claude chatbot, while Microsoft has warned UK Xbox users they'll need to verify their age to keep using core social features. Sony has also begun introducing age checks for PlayStation users this week, and Discord, after flirting with the idea, notably hit the brakes after admitting hackers accessed records, including government ID photos, tied to more than 70,000 users via a third-party age verification vendor.

For Yen, that's exactly the issue. Start with a few "high-risk" services, and it doesn't stop there. "With age verification, we're on the cusp of, once and for all, requiring ID for every single person going online, for any reason, legal or not, adult or not," he said.

Age checks also mean handing over sensitive data, and as Discord already found out, that doesn't always end well. "The more sensitive data you stockpile in privately held databases, the bigger a target it becomes for criminals," Yen said, adding that leaks are more or less inevitable once that data is collected.

His bigger gripe, however, is what this does to basic access. "Age verification as is currently being proposed in country after country would mean the death of anonymity online," he added.

Privacy groups have been making similar noises, with the Open Rights Group warning that mandatory age checks pose serious risks to privacy, data protection, and freedom of expression, particularly if verification systems become centralized or linked across services.

If age checks are unavoidable, Yen argues they need to be built very differently from what's currently rolling out. That means keeping the whole process on the user's device, using facial scans instead of uploaded IDs, and discarding the data immediately after a simple yes-or-no answer on whether someone is old enough. That answer should be anonymized, sent with end-to-end encryption, and backed by open source code, he says, so people can verify that it does what it claims.

None of this is coming from a disinterested party. Proton's entire pitch is privacy-first services, so a world of mandatory ID checks is hardly good for business. Still, it's clear that age verification is no longer theoretical, and the list of services experimenting with it is growing – along with the size of the target they're painting on their own backs. ®