Online Age Verification, the Trojan Horse for Digital Identity, Hits Resistance in France

Across the world governments are adopting policies that threaten to radically transform the Internet.

At the end of last week, France’s highest court, the Constitutional Council, blocked a bill that seeks to ban social media access for under-15s. The court ruled that the Macron government’s ban, which was scheduled to enter into force on September 1, violated freedom of expression and the right to privacy — for all Internet users regardless of age.

One of the central arguments for blocking the bill is that it would mean blanket verification of all users, including adults, without establishing sufficient safeguards to protect privacy:

“By prohibiting minors under the age of 15 from accessing certain online services, the law inherently requires every person, even an adult, to prove their age before accessing them.”

This is the entire point of online age verification, as we warned in our Nov. 19, 2024 post, Will Online Age Verification Be the Trojan Horse for the Mass Rollout of Digital IDs?:

[A]ge verification… traps everyone in its web — not just under-16s but just about anyone who wants to use the Internet. As members of the Australian government recently admitted, everyone will soon have to prove their age to use social media. And that will presumably mean having to use the government’s recently launched digital ID app, myID:

The French Constitutional Court’s ruling represents an embarrassing setback for President Emmanuel Macron, who has invested significant political capital in this flagship legislation. As the video below shows, Macron has even encouraged other European countries to follow suit. France is also one of seven EU Member States being used to pilot the EU’s age verification app.

The Constitutional Council believes protecting children is a legitimate objective. In its ruling, it explicitly recognises that social networks can expose children to addiction, isolation, pornography, harassment and fraud, and that the protection of the best interests of the child may justify limiting access to online services in the future.

However, Macron’s proposed bill was considered too blunt an instrument for the problem at hand. Other issues flagged by the court:

  • The law does not provide for conditions under which parents may, “in the interest of the child, decide to lift the ban, to limit its scope or to allow access to certain services.”
  • Lawmakers “had failed to set out clear rules on how people should prove their age and what limits should apply, meaning there were not enough legal safeguards in place.”
  • The legislation also did not establish how, with what limits or with what guarantees individuals’ online data would be collected.

As Reclaim the Net notes, the ruling is a win for privacy and freedom, though its impact may be short-lived (more on that later):

The controversial bill would have banned those under 15 from opening a social media account, and it would have come into effect from September 1. Accounts that were already opened by September 1st would have had to be closed within four months, and platforms would have had to introduce age verification systems, which curb privacy.

“The Council holds that the contested provisions, on the one hand, disproportionately infringe upon the freedom of expression and communication and, on the other, fail to provide the legal safeguards necessary to ensure the right to respect for private life,” the decision said.

As we have repeatedly warned since 2024, online age verification is being used as a Trojan Horse for digital ID systems, which are now more or less ready to roll out. “Protecting the children” is always a seductive pretext for launching otherwise socially unpalatable policies. And there are few more socially unpalatable policies than a gated Internet, with all that entails (loss of online anonymity and privacy, increasing access controls for platforms…).

Australia was the first to ban under-16s from accessing social media platforms, in December last year. UK lawmakers are expected to vote on similar measures by Christmas. Spain, Greece, and Denmark have announced plans to launch minimum ages while the EU prepares to launch a bloc-wide system closely modelled on that of Australia, which seems to be anything but effective.

In the US, three states — California, Colorado and Illinois — have approved laws requiring operating systems to verify your age before you can use your computer. Congress is weighing similar legislation. In Latin America, Brazil now requires age assurance for products and services that are not allowed for children and adolescents. Other countries on a similar path include Indonesia, Malaysia, Canada, New Zealand, India and South Korea.

All over the world countries are adopting policies that threaten to radically transform the way the Internet functions, including social media bans for minors, operating-system-level age verification mandates, digital identity infrastructures and algorithmic safety regulations. As the British technologist Wayne Horkan notes, this is all happening in a very narrow window of time, with many of the laws scheduled to come into force between 2025 and 2027:

Across North America, Europe, Australia, and parts of Asia, policymakers are gradually constructing a regulatory environment in which access to digital platforms increasingly depends on the verification of certain user attributes, most commonly age, but potentially others in the future. The individual initiatives differ in scope and mechanism, yet they converge on the same operational premise: platforms cannot regulate user experiences without knowing something about the user.

The result is the quiet emergence of what might be called an age-gated internet.

This term should not be understood narrowly as referring only to pornography filters or parental controls. Instead, it describes a broader architectural transition in which online services increasingly require systems capable of determining whether a user is a child, a teenager, or an adult before deciding what content, features, or algorithmic pathways that user may access.

The deeper shift can be summarised in a single observation:

Multiple regions of the world are moving toward identity-mediated access to digital services.

In such a system, the internet does not simply respond to requests for information. It first classifies the requesting entity. Only then does it determine what the user is permitted to see, do, or participate in.

The dangers of such a system go beyond the loss of online privacy and anonymity to the loss of access to basic online services. That’s not to mention the elevated security risks. Within literal minutes of the launch of the EU’s age verification app in April, IT security consultants and hacktivists were already finding glaring flaws in the security architecture.

As Electronic Frontier Foundation has repeatedly warned, online age verification is incompatible with privacy and data security:

In the final analysis, age verification systems are surveillance systems. Mandating them forces websites to require visitors to submit information such as government-issued identification to companies like AU10TIX. Hacks and data breaches of this sensitive information are not a hypothetical concern; it is simply a matter of when the data will be exposed, as this breach shows.

Cory Doctorow describes online age verification as the “latest consensus hallucination to take over our political classes” and as “a thing that manifestly does not exist”:

You can’t “verify the age” of an internet user — you can only attempt to attribute every byte that traverses the entire internet to affirmatively identified persons:

This comes at enormous cost. It is a gift to every future dictator, every identity thief, and every would-be sexual exploiter of children, who will have access to the hacked, leaked, and badly secured troves of data that this doomed effort produces.

Yes, doomed. Because even when it comes to kids, “age verification” is just a way of convincing young people to familiarize themselves with VPNs. This was entirely obvious from the very instant that “age verification” was mooted, and yet our policymakers pretended they couldn’t hear the chorus of people who pointed it out to them.

Since VPNs function as anonymity masks that allow users to hide their online activity and access restricted content, their popularity has grown as governments have sought to impose increasingly draconian restrictions on Internet use. As their popularity has grown, governments have responded by threatening to ban children from using VPNs or treating them as “a loophole that needs closing”.

“Politicians have now discovered that people are using VPNs to protect their privacy and bypass these invasive laws,” EFF warns. “Their solution? Entirely ban the use of VPNs… And that battle is being fought by people who clearly have no idea how any of this technology actually works.”

NC reader Baron Aroxdale raised a similar point in the comments section of a previous post, noting that VPN bans are unlikely to work — at least not without causing serious damage to the internet along the way:

VPNs are a very standard part of business IT. They are simply a means to connect remote computers together on the same virtual network. Support for them is normally inbuilt into operating systems, and hardware network companies will normally provide desktop applications to support VPN setup on their routers.

VPNs are about as common as internet proxies or email. You can’t just “ban” them without breaking the backbone of modern IT systems since the late 1990s.

It seems that someone may have actually informed His Majesty’s Government in the UK of this niggling fact…

Continue reading on Naked Capitalism

Leave a Comment