惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
T
The Blog of Author Tim Ferriss
J
Java Code Geeks
M
MIT News - Artificial intelligence
F
Fortinet All Blogs
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
Microsoft Security Blog
Microsoft Security Blog
N
Netflix TechBlog - Medium
G
Google Developers Blog
L
LangChain Blog
腾讯CDC
大猫的无限游戏
大猫的无限游戏
U
Unit 42
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
罗磊的独立博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
The GitHub Blog
The GitHub Blog
博客园_首页
GbyAI
GbyAI

The Register - Security

Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw ShinyHunters claims dump puts 119K Vimeo emails in the wild
Age checks could turn internet into an ID checkpoint, com...
Carly Page · 2026-04-24 · via The Register - Security

Proton's boss has waded into the age verification fight with a warning that sounds less like child safety and more like an identity checkpoint for the entire internet.

In a blog post on Thursday, Andy Yen, CEO of Proton, argues that the current push for age checks risks flipping the web from anonymous by default to something closer to "show your papers" before you click.

The problem, he says, is that you can't reliably identify minors without identifying everyone else first, meaning systems built to protect kids inevitably sweep up adults too. "We cannot accept a world where every adult is expected to hand over ID as the price of going online."

That argument is landing as age checks move from policy debate to product reality. Anthropic has already rolled out ID verification tied to certain personas in its Claude chatbot, while Microsoft has warned UK Xbox users they'll need to verify their age to keep using core social features. Sony has also begun introducing age checks for PlayStation users this week, and Discord, after flirting with the idea, notably hit the brakes after admitting hackers accessed records, including government ID photos, tied to more than 70,000 users via a third-party age verification vendor.

For Yen, that's exactly the issue. Start with a few "high-risk" services, and it doesn't stop there. "With age verification, we're on the cusp of, once and for all, requiring ID for every single person going online, for any reason, legal or not, adult or not," he said.

Age checks also mean handing over sensitive data, and as Discord already found out, that doesn't always end well. "The more sensitive data you stockpile in privately held databases, the bigger a target it becomes for criminals," Yen said, adding that leaks are more or less inevitable once that data is collected.

His bigger gripe, however, is what this does to basic access. "Age verification as is currently being proposed in country after country would mean the death of anonymity online," he added.

Privacy groups have been making similar noises, with the Open Rights Group warning that mandatory age checks pose serious risks to privacy, data protection, and freedom of expression, particularly if verification systems become centralized or linked across services.

If age checks are unavoidable, Yen argues they need to be built very differently from what's currently rolling out. That means keeping the whole process on the user's device, using facial scans instead of uploaded IDs, and discarding the data immediately after a simple yes-or-no answer on whether someone is old enough. That answer should be anonymized, sent with end-to-end encryption, and backed by open source code, he says, so people can verify that it does what it claims.

None of this is coming from a disinterested party. Proton's entire pitch is privacy-first services, so a world of mandatory ID checks is hardly good for business. Still, it's clear that age verification is no longer theoretical, and the list of services experimenting with it is growing – along with the size of the target they're painting on their own backs. ®