Showing posts with label child protection. Show all posts
Showing posts with label child protection. Show all posts

Friday, June 26, 2026

The UK's proposed under 16s social media ban is ill-considered

 When the history of the first quarter of the 21st century comes to be written, it will record a period when we took the greatest communications medium in the history of humanity – the internet – and turned it into an invasive, toxic, mass surveillance machine, beyond even George Orwell’s imagination.

For generations, the four horsemen of the infocalypse – terrorists, drug dealers, child abusers and organised crime – have been the staple justifications of choice for a smorgasbord of laws intended to tackle these evils. The Labour government between 1997 and 2010 introduced more than forty major serious crime and counter-terrorism laws.

During the same period, unfettered, private sector mass surveillance & profiling, of a scale unthinkable before the turn of the century, plus addictive, attention- grabbing apps and social media algorithms, became established as the core business model of the internet.

The most profitable firms in the world either monetise or otherwise exploit data through stalker advertising and profiling and/or provide software and hardware services and infrastructure to the economic & state actors who do.

The technology systems built and rolled out by those companies are used, extensively, by states which, like commerce, have a voracious appetite for personal data, in the whole gamut of government services from law enforcement, health and social welfare to border control, military, security and intelligence.

In the wake of the 11th September, 2001 attacks, counter terrorism became the primary excuse for western governments’ expansion of mass surveillance. By the mid-2010s, it remained a core theme for government but the terrorism mantra was wearing thin and the prominent pretext for surveillance moved to immigration and border control.

In parallel, child protection and “online safety” became high profile vehicles for a collection of demands that something must be done about the negativities of the internet and the unethical behaviour of the big technology corporations. By 2023 that led to the introduction by the UK of the Online Safety Act, a complex piece of legislation with the “general purpose of making the use of internet services… safer for individuals in the United Kingdom” through imposing a duty of care on online services providers.

One of the primary effects of the Act seems to have been a boon in the market for age verification services. And, indeed, VPN services, which the government are also now considering restricting. Section 12(4) of the Act mandates the use of age verification or age estimation to prevent children from accessing harmful content. Section 12(6) says this age verification should be “highly effective”. In short, dear reader, age verification is not marginally, let alone highly effective and declaring a mandate for highly effective technology in a statute does not, magically, bring it into existence.

Ahead of the Makerfield byelection and his likely replacement by Andy Burnham, the UK Prime Minister, Keir Starmer, with his teen social media ban proposal, announced plans to polish a capstone on his legacy, such as it is, by forcing everyone to wade through some form of identity and/or age verification service before using the internet. The Open Systems Interconnection (OSI) model - seven layer model of the internet – is about to get an eighth layer in the UK, the insecure layer, if the October 2025 Discord data breach compromising 70,000 users, including their government issued ID images, is anything to go by. Mr Starmer’s insecure layer, retrofitted to a toxic mass surveillance machine, will compromise the privacy and security of every internet user, including children, whilst failing to improve child safety.

Last week the Science, Innovation and Technology Committee of Parliament, following an inquiry on the digital centre of government, published a report Rewiring the state: Delivering digital government.

The report is scathing on government information & data security (highlighting Biobank breaches), unsubstantiated hype about a claimed £45 billion per year savings from digital services, government plans for digital ID (noting operational and security problems relating to the eVisa system and One Login’s temporary loss of certification against the government’s own digital identity framework). On digital sovereignty the report expresses concerns that "The UK’s reliance on a small number of US-based providers for digital infrastructure and public service delivery is a strategic and economic vulnerability."

Most notably, in the context of the proposed teen social media ban, however, it declares government ignorance of technology, “enthusiasm from non-experts at the top” combined with “insufficient skills at the coalface” to be a “dangerous” combination. Dangerous is the word for it, particularly for those teens who rely on internet access for social, educational and mental health support, often exclusively because they cannot find that support elsewhere. 

The petition to parliament not to go ahead with this ban has already, at the time of writing, passed 200,000 signatures. 

A prime minister serious about child protection would firstly insist on enforcing existing regulatory measures, such as the UK GDPR articles 8 and 9, against social media companies and secondly, pursue orders of magnitude greater investment in social and sports facilities and infrastructure, children’s services, parental support, social welfare, education, health, mental health services and, where necessary, policing; with properly coordinated, local interdisciplinary teams across all these services working in tandem, the whole being greater than the sum of the parts.

Also, as Cory Doctorow says, we need to protect kids from online surveillance, the precise opposite of what the UK government is proposing: “Your kids can't be targeted by algorithms without the surveillance data that's being used to target them. They can't be funneled into pro-anorexia content or extreme misogyny forums without that funnel being primed by commercial spying.”

The Brazilian government, unlike the UK, Australia and many others proposing similar bans, has taken a different approach to provide for the protection of children in digital environments, Decree No. 12,880, of March 18, 2026. According to Victor Oliveira Fernandes, Brazil's National Secretary for Digital Rights, the decree tackles the problem at source by banning dark patterns and addictive design targetted at children, including infinite scroll, autoplay, time-based rewards, excessive notifications, obstruction of privacy controls and exploitative cognitive vulnerabilities. Maximum penalities can be 10% of a company's revenue in Brazil. It will be interesting to see how that plays out in practice. As Prof Fernandes admits, passing the law is only the start, it's efficacy will depend on how and how well it is enforced, what economic actors it covers and to what degree it causes a change in their unethical business practices.

Notably, the early evidence on the effects of an under 16s social media ban in Australia shows that it has led to little substantive reduction in reported social media use by adolescents under 16. It doesn't work.

Peddling a headline grabbing social media ban is just another ineffective but also corrosive and dangerous attempt at a quick fix to a challenging and complex sociotechnological problem. If, however, after two and a half decades of digital technology enabled mass surveillance and failed government technical quick fixes in relation to all four infocalyptic horsemen, you still believe the PM’s claim that a social media ban decimating everyone’s privacy is the solution to the complex issue of children’s safety, I wonder if I could interest you in the purchase of a couple of bridges, one in London, one in Brooklyn?

Wednesday, July 05, 2023

Note to Baroness Benjamin on the spy clause in the Online Safety Bill

Through the Open Rights Group, I have emailed a member of the House of Lords, Baroness Benjamin, about the spy clause in the proposed Online Safety Bill. And typically I have just now spotted two typos in the first line...

I am writing to you as ta (sic) member of the House of Lords to express my concern that clause 111 (sic - should have read clause 110 🤦) - the spy clause - of the Online Safety Bill introduces scanning of our private messages. It gives Ofcom the power to ask private companies to scan everyone’s private messages on behalf of the government. It is state-mandated mass private surveillance.

This is an outrageous violation of the privacy and security of UK residents, that puts everyone's personal images and messages at risk.

Providers of messaging services such as WhatsApp and Signal have said they will pull out of the UK rather than break the security of their products.

68 independent information security and cryptography researchers have written an open letter condemning the proposal which I would urge you to read at:

https://haddadi.github.io/UKOSBOpenletter.pdf

In short, they are "alarmed by the proposal to technologically enable the routine monitoring of personal, business and civil society online communications".

On the breaking or undermining of cryptographic protections, they emphasise: "There is no technological solution to the contradiction inherent in both keeping information confidential from third parties and sharing that same information with third parties." In other words, there is no way of building a backdoor into encryption that only the good guys have access to.

On the circumvention of cryptography via so-called 'client-side scanning', "This would amount to placing a mandatory, always-on automatic wiretap in every device... research has shown that client-side scanning does not robustly achieve its primary objective, i.e. detect known prohibited content... sufficiently reliable solutions for detecting CSEA content do not exist. This lack of reliability here can have grave consequences as a false positive hit means potentially sharing private,

intimate or sensitive messages or images with third parties".

I have worked as a technology academic at the Open University for 28 years. I have watched, written and taught about the growth and entrenchment of mass surveillance as the core business model of the internet; and states' co-opting of the internet's infrastructure of mass surveillance and the economic actors involved in its construction and operation, in pursuit of counter-terrorism, security and other legitimate aims.

In the wake of the Edward Snowden revelations, in 2013, of unlawful UK and US government mass surveillance programmes, a partial response, in addition to a collection of successful legal challenges going to the Court of Justice of the European Union and the European Court of Human Rights, has been the deployment of secure end to end encryption in messaging apps such as Signal and WhatsApp. 

The spy clause represents a direct threat to the privacy and security facilitated by such apps. As the security researchers say in their open letter: "we build technologies that keep people safe online. It is in this capacity that we see the need to stress that the safety provided by these essential technologies is now under threat in the Online Safety Bill."

Child sexual exploitation and abuse (CSEA) is an appalling crime. Governments, commerce and wider society have an obligation to pursue effective means to prevent and respond to it. The Online Safety Bill spy clause is not an effective approach. It assumes the availability of efficacious scanning technologies which do not currently exist. Those that do and are foreseeable are deeply, deeply flawed. There is no magic technological solution here.

So not only will the Online Safety Bill undermine the safety, security and privacy of everyone, including children, it will simply not work to address the blight on our society that is child sexual exploitation and abuse.

I should have included a request asking the baroness to support Lord Clement Jones' proposed amendments to Clause 110 of the Bill. 

 

 

 

And his proposed amendments to clause 112 "intended to introduce safeguards around the issuance of Technology Notices by ensuring privacy is considered before a notice is given, and strengthening the review and appeals process".