Australia Wants to Remake the Internet in the Name of “Safety”

The Australian government has published its proposed Digital Duty of Care legislation, a plan that it says will give people more control over their social media feeds, but which opponents fear is a way to introduce more online censorship.

The exposure draft of the Online Safety Amendment (Digital Duty of Care) Bill 2026 was published on September 8 for consultation, and it is not yet law. The deadline for submissions is noon on September 22, and Communications Minister Anika Wells said the plan is to formally introduce the bill to Parliament in October.

We obtained a copy of the draft for you here.

In the words of Prime Minister Anthony Albanese, “This is not about giving government control, it is about giving people control.”

And while the proposal is often referred to as My Feed, My Way, it is not about banning algorithms, but giving new and existing users a choice between feeds based on recommendations, and one that shows posts from accounts they follow.

But beneath this choice, there is a broader change to the Online Safety Act 2021 that would be introduced by the Digital Duty of Care bill, and that is to impose a duty on those behind online services to ensure a safe online environment as far as reasonably practicable.

This duty would apply to a wide range of services, including social media, messaging, games, hosting, search, app stores, internet providers, AI services enabling generated material to be shared through covered services, as well as certain equipment providers.

The minister in charge would be able to exempt services that are low-risk or minimally used. The proposal is designed to protect adults from what is described as seriously harmful material and conduct, while under-18s would have additional protection against harmful content and design features.

The list of harmful content and conduct that the draft seeks to protect adults from includes child sexual abuse, threats of violence, encouragement of self-harm, and support for listed terrorist organizations.

For children, the list includes pornography, encouragement of disordered eating, hostile attitudes towards women or gender equality, glorification of crime, dangerous stunts, abuse and bullying.

However, the minister would have the power to add more categories of harmful material or conduct by issuing a legislative instrument.

Wells must first seek and consider advice from eSafety, and the instrument can be disallowed by Parliament.

The draft bill also targets features that the government considers to have negative behavioral impacts, such as recommendation systems, endless feeds, and engagement-feedback tools, as well as time-limited content. Social media services would be required to stop these features for children under 16.

The proposal also includes a system of risk assessment that online services would have to conduct at least once a year, and keep for six years. These assessments would have to be provided to the eSafety commissioner on request.

eSafety Commissioner Julie Inman Grant, who has a history of censorship demands, would be in charge of enforcing the scheme, which would bring maximum company penalties of A$109.2 million.

The draft bill does contain some safeguards, such as the definition of reasonably practicable, which takes into account the risk, available measures, cost, and the potential for a measure to have a disproportionate effect on privacy.

The duty of care does not extend to lawful communications occurring in private solely between consenting adults, the draft bill states.

Opposition leader Angus Taylor on September 6 said he feared the proposal was “an attempt by the government to censor social media,” while One Nation leader Pauline Hanson said that Australia should be moving away from government censorship, not “building the Orwellian machinery for it.”

The Greens, on the other hand, have supported the idea of making sure users have a choice when it comes to feeds, but they want to make sure that users have to opt in to have their feeds curated by algorithms.

White House spokesman Kush Desai reacted by saying that President Trump “has unequivocally warned trading partners against imposing digital services taxes, fines, and other forms of extortion on America’s leading technology sector.”

Desai added that “the administration remains committed to raising these issues with our trading partners.”

Communications Minister Anika Wells sought to downplay the significance of the White House statement, telling News24 that the US was responding to broader questions that also included Australia’s tax arrangements, and not only the Digital Duty of Care proposal.

“We’re a sovereign nation, we have the right to defend Australian parents and kids and we’ll do that,” Wells said.

The government’s proposal has been portrayed as giving users a choice between personalized recommendation feeds and those that show posts from accounts they follow.

Keep reading

Gavin Newsom Says He Would Continue His Podcast if He Became President – Wonders What He Would Wear

Gavin Newsom recently did a puff interview with PBS and was asked if he would continue his podcast if he became president. His body language changed and he became positively giddy at the thought.

He then wondered aloud what he would wear for the broadcast.

How is anyone taking this man seriously as a governor, let alone as a presidential candidate?

If Newsom runs for president, he is going to have to answer a lot of questions about California.

Even the Associated Press knows it:

California made Gavin Newsom famous. Will it drag down his 2028 presidential ambitions?

Gavin Newsom’s secret is no secret here in South Carolina.

They were selling “Gavin 2028” buttons outside his events this past week as he trekked across the state that will hold Democrats’ first presidential primary. His allies, the state party chair, college presidents and pro-Newsom activists all openly hinted at his national aspirations. And people close to him privately referred to a White House campaign as “the next thing.”

Still, California’s Democratic governor has barely begun to address what may be his biggest political liability as he stakes a claim as an early front-runner in the Democratic Party’s 2028 shadow primary. That liability, South Carolina voters acknowledged this past week, is something he cannot change — his home state, California, is a symbol of modern-day liberalism that people across the political spectrum love to hate.

Vera DeVito, a 78-year-old Democrat who packed into one of Newsom’s eight public events across South Carolina, said she didn’t know much about him or his policies — except that he’s from the Golden State. On that basis alone, she suggested that supporting Newsom could be “risky.”

“It’s going to be hard for him to appeal to the whole country,” she said in the town of Summerville. “Everybody thinks California is different — especially in the South. They’re not crazy about California.”

People aren’t crazy about California because California is crazy for putting up with Gavin Newsom.

The state has lost population for the first time in history on his watch.

Keep reading

OUTRAGE: Texas Student’s School Laptop BLOCKS Search for President Trump — But Allows Joe Biden, Kamala Harris, and Jeffrey Epstein

A Richardson Independent School District parent says her son’s school-issued laptop blocked him from searching for the sitting President of the United States, while searches for Joe Biden, Kamala Harris, and convicted sex trafficker Jeffrey Epstein went through without a hitch.

The district has so far refused to explain why.

According to an exclusive report from The Dallas Express, an anonymous Richardson ISD parent provided video of her son attempting to research President Donald Trump for a school assignment. When he searched “Trump,” the device displayed a blunt message: “WEBSITE BLOCKED BY RICHARDSON ISD.”

The same block did not appear for Biden, Harris, or Epstein.

“My child was researching our current president for a school assignment and discovered that the district’s web content filter had blocked ‘Trump’ from search results,” the parent told The Dallas Express.

“This means students can’t access legitimate educational and news content, including current-events research, government and civics coursework, and basic search results about the sitting U.S. President. This is very concerning, as it amounts to censorship of information about a current public official.”

She then had her son test other names.

Keep reading

CrowdStrike and Federal Authorities Dismantle Russian Malware That Secretly Stole Crypto for 8 Years

A campaign of malware operated by Russian cybercriminals for eight years was dismantled by federal authorities in conjunction with the cybersecurity firm CrowdStrike on Thursday. The malware, identified by the security firm as “EggJagger” or as Sality malware, preyed upon thousands of users of virtual currency by engaging in “clipboard hijacking.” The most common method that users of virtual currencies such as Bitcoin and Ethereum employ in order to send currency is to copy a virtual currency address from a web page to a computer’s clipboard and then later to paste the virtual currency address into the corresponding field of a wallet application. The malware sat idle on a user’s computer and then, before the user had a chance to discover the substitution, would change the virtual currency address that had been placed in the user’s clipboard to an address controlled by the cybercriminals, reported CoinDesk.

Once the compromised address was pasted into the user’s wallet software, and the resulting transaction had been confirmed, the cryptocurrency was transferred irretrievably to the attacker. While there was no particular attack functionality that triggered any alerts, the single defense against such an attack was for the user to manually verify the address that they had pasted into the sending field. Typically the first and last characters of a wallet address would be verified against what was expected, but in this case all would need to be checked. The reason for this type of attack to have persisted for some eight years is that it is an easy one to implement, and places the onus of security on the end user to perform correctly in these situations.

Analysis by CrowdStrike has uncovered the malfeit cryptocurrency operators amassed 12.1 million rubles ($150,000) in the years the malware was active and operating, however most of the stolen cryptocurrency had been deposited into online wallets, remained untouched by the cybercriminals. However with the recent and ongoing surge in value of many of the world’s most popular cryptocurrencies the hacker’s abandoned stash has appreciated significantly to an estimated $1.35m. The returns on such a relatively simple attack vector to extract cryptocurrency from individuals is significant and in this instance highlights that such malware, whilst still active after eight years, continues to reap significant returns on little more than foraging for victims, capitalizing on default settings and exploiting human nature of individuals utilizing online cryptocurrency services.

A major weakness of the botnet infrastructure behind EggJagger was the minimal security controls in place around the network of infected computers. As long as a compromised computer was responding to commands appropriately, it could be included in the botnet of other compromised systems. In a live demonstration of the vulnerability on Monday at CrowdStrike’s Day Zero summit in Las Vegas, the security team of researchers used the same hole to subvert EggJagger and replace the legitimate peer addresses embedded in the malware with the IP addresses of their own servers. Suddenly, more than 15,000 computers infected with EggJagger around the world lost connection to their command-and-control servers in an instant, bringing the whole operation crashing down.

The high-profile takedown of the long-running Russian malware operation highlighted the persistent cyber threats to financial infrastructure emanating from Russia, as well as the growing role of the private cybersecurity sector working in conjunction with law enforcement to counter threats to the financial system. Despite having developed sophisticated operational security measures over an eight-year period, Sality ultimately relied on a relatively simple vector to steal cryptocurrency from thousands of individuals and businesses – that of exploiting routine human practices. The botnet’s vulnerability to having its peer connections severed by not authenticating the connections was identified by law enforcement and subsequently exploited to dismantle the operation in a single action, bringing an end to a threat that had affected thousands of individuals and businesses across South Florida and the country.

Keep reading

Microsoft knows your entire browser history — and it can send it to the FBI

Virtual Private Networks are meant to shield your browsing history from all manner of prying eyes, including your internet service provider, your workplace or school, and even potential hackers. If you use a VPN with your Windows PC, though, I have some bad news: Microsoft has a full record of your browsing habits, and it can even report your activity to the FBI.

According to court documents released on July 1, a 19-year-old young man working with the cyber criminal group known as Scattered Spider was caught hacking into a computer system belonging to a luxury jewelry store. While inside, the hacker stole company data and demanded $8 million in cryptocurrency for ransom. Ultimately, the jewelry store kicked the hacker out of its system without paying the ransom, and the perpetrator was later arrested and charged.

It’s a simple case of conspiracy, digital intrusion, and fraud … but there’s a catch.

The hacker’s identity should have been hidden from the feds.

Keep reading

Pennsylvania Sues Snapchat Over Lack of Age Verification

Child safety is an extremely powerful weapon used to force private companies to implement age verification digital ID checks and, in some cases, change the design of their platforms. And once this is done, it’s not clear that children are any safer, but one thing is certain: online privacy and anonymity are weakened, and in some cases, lost.

This is the context in which the latest legal action against a major US tech company should be seen. Pennsylvania Attorney General Dave Sunday has sued Snap, the maker of the Snapchat app, accusing it of violating the state’s Unfair Trade Practices and Consumer Protection Law (UTPCPL).

The filing, in Philadelphia County on August 25, 2026, is framed as consumer protection, but it is about pressing Snap to verify its users’ ages and to change how the app is designed.

“Child safety” is a broad and vague banner that can cover a lot of ground – from protecting minors from predators and inappropriate content, to shielding them from features that the state decides are “addictive.”

But before it gets to the “addictive” part, the complaint states that Snapchat’s age gate is not good enough – specifically, that it defaults to 18, and that this makes it “unreliable.”

The filing further states that this has “helped render Snap’s efforts to protect young users from predatory adults practically useless for any safety features that depend on accurate age-gate information.”

The remedy the state wants is a court order forcing Snap to implement reliable age verification for all users.

Other claims made in the suit are that Snap has misrepresented how often adult-themed content appears on the platform in order to get the app a 13+ rating in stores – and that it has built “addictive” features into the app, such as infinite scroll and autoplay.

“Snap deliberately designed Snapchat to be addictive,” the complaint says, adding that the company “knows that minor users especially are susceptible to Snapchat’s addictive features.”

The features that the state wants a court to stop Snap from using are: Snapstreaks, push notifications, infinite scroll, autoplay, ephemeral content, and Snapchat+’s Friend Solar System.

The suit also wants the court to order Snap to pay civil penalties and cover the costs of the suit.

Keep reading

A Law That the People It Targets Can Defeat With a Felt-Tip Pen

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill was introduced on 24 August 2026 – the very day I arrived back in New Zealand after nearly a month away.

Readers of “A Halflings View” will be well aware of my views about bans or restrictions on access to social media platform by the young. Although the news media have trumpeted the present proposals as a “ban” it is not. It actually constitutes a form of limited restriction.

This article is very much a “first impression” view of the Bill. Much of the material and commentary is gathered from earlier writings I have produced on the subject as well as from other sources among them Ani O’Brien, “Thought Crimes” (Substack) — “Hear me out: Ban the hardware not the software”; the New Zealand Initiative; Privacy Commissioner Michael Webster; UNICEF Aotearoa (Susan Glasgow); Australia’s eSafety Commissioner three-month evaluation (July 2026); UK Ofcom/House of Lords material and reporting on the Online Safety Act; and US litigation (NetChoice; the Louisiana and Arkansas decisions).

Furthermore, this article (and indeed the Bill itself) will not be the final word.

The Bill has not yet had its First Reading and that is unlikely before Parliament rises. But Prime Minister Luxon and Erica Stanford were determined to push this ill-advised proposal ahead at pace, even although what it really amounts to is an announcement until the Bill has its First Reading. And it may even fall at that fence. If it makes it, Select Committee submissions and further commentary will accumulate quickly.

Hence the critique reflects the position as at the time of publication of this article.

What the Bill actually does

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill, introduced to Parliament on 24 August 2026 by Education Minister Erica Stanford, is a stand-alone statute built on two load-bearing duties.

The first (clause 11) requires operators of “age-restricted platforms” to take reasonable steps to stop New Zealanders under 16 from holding an account. The second (clause 14) requires those operators to produce an annual, written child safety risk assessment covering all under-18s who use the platform.

Behind these sit an enforcement apparatus of warnings, enforceable undertakings, corrective notices, tiered pecuniary penalties (up to the greater of NZ$40 million or 10% of global turnover), and, as a last resort, service restriction orders and access restriction orders that would conscript ISPs, app stores and ancillary providers into preventing access to the platform from New Zealand.

The regulator is the Secretary of Internal Affairs — the chief executive of the Department of Internal Affairs (DIA). More on this disturbing aspect later.

Much of the drafting is careful.

It regulates the account, not the child, so no penalty falls on minors or parents.

It explicitly forbids treating manual date-of-birth entry as a “reasonable step”.

It goes beyond the Privacy Act by requiring destruction of age-assurance data.

The Bill is also more sophisticated than the “ban” it is marketed as. As I have argued on earlier occasions about similar proposals, this is a set of managed restrictions on account-holding, not a prohibition on children seeing content. Publicly available material remains reachable.

But the care in the drafting cannot rescue the concept.

The Bill imports a policy model that has already been trialled next door in Australia and in Britain, and the trials are in.

What follows is the case against it — a case now supported by a striking amount of hard evidence rather than speculation — followed by the specific problem of handing the whole scheme to the DIA.

The central flaw: a “targeted” measure that touches everyone

The Bill’s rhetorical appeal rests on the idea that it targets under-16s. Its mechanism does not.

To reliably prevent a 15-year-old from holding an account, a platform must satisfy itself about the age of every account-holder — which in practice means age-assuring the entire adult population as well.

Privacy Commissioner Michael Webster made the point bluntly when the policy was first floated. Keeping under-16s out means everyone over 16 has to prove they are over 16. The New Zealand Initiative put it the same way — everyone will have to demonstrate they are not under sixteen, including you.

This is the paradox the Bill never resolves, and it is not a drafting quibble but the whole problem.

Clause 11 forbids the “cheap check” (a manual date of birth entry) and forbids relying solely on formal ID or a digital identity service, which forces platforms toward either document upload, facial age-estimation, or “age inference” from behavioural and device signals.

Keep reading

Bluetooth Glitch Exposes Alibaba’s Secret Tracking Of Users, Developer Says

A San Francisco-based developer discovered that Alibaba Group’s AliExpress marketplace secretly hijacked his computer’s audio system through hidden browser scripts, allowing the website to run inaudible sound waves at zero volume to create “fingerprints” used to track devices without relying on cookies. 

The privacy-focused Brave browser revealed in a series of X posts that the AliExpress marketplace was keeping the developer’s computer audio system active through hidden browser scripts, potentially allowing the website to generate a unique identifier for his device.

The issue emerged when the developer’s Bluetooth headphones refused to transfer their audio connection from his computer to his phone while AliExpress was open. A deeper dive of the website’s code showed background scripts maintaining access to the computer’s audio-processing system without producing audible sound.

The scripts allegedly used the browser’s Web Audio API to process signals at zero volume. Small differences in how individual computers handle those signals can be measured and combined into an “audio fingerprint,” allowing websites to recognize devices even when cookies are deleted or blocked.

The developer also found that the scripts collected other device characteristics, including available memory, screen dimensions, and network information.

Here’s what Brave found:

1. Alibaba’s AliExpress was caught using users’ audio systems to track them. AliExpress wasn’t recording users but instead playing a silent sound and measuring how users’ specific devices processed it in order to fingerprint them.

2. Fingerprinting is a way that websites can identify you without cookies. Sites will note details about your device like your screen size or installed fonts. These details are then combined into a unique, persistent “fingerprint” that can be used to track you across the Web.

3. There are slight variations in how each device plays the same audio file due to differences in CPU, sound card, browser, etc. When AliExpress played the silent sound, it measured these small variations to help build fingerprints of users’ devices.

4. This tracking was discovered due to an unexpected side effect. A user with Bluetooth headphones noticed they couldn’t play music on their phone because the headphones were instead playing AliExpress’s silent sound from their PC.

Brave turned what it found into a sales pitch for its browser:

1. For 6+ years, Brave has protected users against audio fingerprinting, and other fingerprinting types, by default. Brave injects random data into the browser’s output so you show a different fingerprint to different sites. This fingerprint also resets across sessions.

2. Trackers are constantly finding new ways to fingerprint your device, so Brave keeps adding new protections. We recently added defenses against GPU fingerprinting, which stops sites from identifying you with your graphics card or drivers.

The findings raise new questions about browser fingerprinting, a stealthy way that uses silent audio processing for covert tracking. 

Keep reading

AG Blanche’s Warning Points Straight at Age Verification Checks

The US Department of Justice (DOJ) has managed to extract $400 million from TikTok, and this is not a story about the company being forced to change its ways – but pay up nonetheless.

The settlement, which means no admission of wrongdoing on the part of TikTok, will see the company pay $300 million now, and another $100 million once a prior consent decree is vacated.

That earlier decree came from a 2019 case, United States v. Musical.ly, an app that was later folded into TikTok. The current case, United States v. ByteDance, was filed in 2024 and is now dismissed with prejudice.

The original complaint accused ByteDance of violating the COPPA Rule by letting children slip past TikTok’s age gate and “knowingly creating accounts for children and collecting data from those children” without “verifiable parental consent.”

The 2019 consent decree also sought to ensure that the company would get “verifiable parental consent” before collecting personal information from children.

The settlement reached now requires TikTok to change absolutely nothing.

The DOJ explains this by saying that since the 2024 filing, TikTok “has undergone significant changes to its ownership, management, compliance functions, and privacy practices” and “implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight.”

Those changes “have materially advanced the public interests underlying the Department’s litigation and have strengthened protections for millions of American families,” the DOJ said.

And what is “verifiable parental consent” that’s the main aspect of the original complaint and the 2019 consent decree? That’s where things get interesting. COPPA doesn’t mandate any specific method, but lists several, which escalate quickly from a signed consent form, to a payment from a parent’s credit or debit card, to submitting a government-issued ID and matching it to a face scan, or being verified over video call.

In other words, proving that a parent has given consent tends to boil down to proving who everyone is.

Keep reading