Ottawa humiliated as Bill C-22 fact check validates surveillance concerns

Controversy over state surveillance in Canada is escalating after Public Safety Canada received a Community Note on X for attempting to rebut criticism of Bill C-22, the Lawful Access Act.

“Bill C-22 may not formally create new warrant powers, but Part 2 would impose new lawful-access and technical capability obligations, including metadata retention,” reads the note.

“Privacy experts argue this expands the practical surveillance framework if warrant standards remain unchanged.”

Keep reading

Open Records Laws Reveal ALPRs’ Sprawling Surveillance. Now States Want to Block What the Public Sees.

Reporters, community advocates, EFF, and others have used public records laws to reveal and counteract abuse, misuse, and fraudulent narratives around how law enforcement agencies across the country use and share data collected by automated license plate readers (ALPRs). EFF is alarmed by recent laws in several states that have blocked public access to data collected by ALPRs, including, in some cases, information derived from ALPR data. We do not support pending bills in Arizona and Connecticut that would block the public oversight capabilities that ALPR information offers.

Every state has laws granting members of the public the right to obtain records from state and local governments. These are often called “freedom of information acts” (FOIAs) or “public records acts” (PRAs). They are a powerful check by the people on their government, and EFF frequently advocates for robust public access and uses the laws to scrutinize government surveillance

But lawmakers across the country, often in response to public scrutiny of police ALPRs, are introducing or enacting measures aimed at excluding broad swaths of ALPR information from disclosure under these public records laws. This could include whole categories of important information: general information about the extent of law enforcement use; details on ALPR sharing across policing agencies; data on the number of license plate scans conducted, where they happened, and how many “hits” for license plates of interest actually occur; analyses on how many false matches or other errors occur; and images taken of individuals’ own vehicles. 

No thanks. Public records and public scrutiny of ALPR programs have shown that people are harmed by these systems and that retained ALPR data violates people’s privacy. In this moment, lawmakers should not be completely cutting off access to public records that document the abuses perpetuated by ALPRs.

Keep reading

Ottawa says use VPNs but kindly leave a backdoor for us

Public Safety Canada recently posted advice encouraging Canadians to use VPNs online to better protect their privacy.

It was sensible advice when taken out of political context.

I use a VPN and you should too. But it ultimately didn’t play well with the general public and backfired.

That’s because Ottawa is simultaneously telling Canadians to shield themselves online while major VPN and other encryption-based platforms are threatening to pull out of the country, all because of Bill C-22.

This contradiction has become typical of Ottawa. One arm of the federal government reminds citizens to lock their doors, while another is drafting legislation designed to make it easier to kick those doors down. The attitude extends beyond tech and into the real world, where lax bail laws are emboldening criminals.

Bill C-22, the Lawful Access Act, introduces sweeping powers that would compel digital service providers to retain highly sensitive user data and location history for up to 365 days without any evidence of a crime. More alarming still, it aims to force companies to build technical “backdoors”, so state agencies can easily extract user data.

Signal, NordVPN and Canadian-headquartered Windscribe have already issued an ultimatum threatening to pull out of Canada entirely rather than play a role in spying on Canadians.

Tech companies understand something politicians refuse to acknowledge: there is no such thing as a secure backdoor.

Keep reading

Meta launches WhatsApp ‘incognito’ mode to address privacy concerns for AI chats

Meta Platforms said Wednesday it’s rolling out an “incognito” mode for WhatsApp users to have private conversations with its AI chatbot, a move intended to ease privacy concerns about sensitive information that users share in chats.

The social media company said in a blog post that incognito chat mode provides a way to have private, temporary conversations with Meta AI, its artificial intelligence assistant that’s been available on WhatsApp for a few years.

Messages will be processed in a “secure environment” that even Meta can’t access, won’t be saved by default and will disappear when exiting a session, Meta said.

Generative AI systems have been dogged by privacy concerns because the large language models that underpin these systems are trained on vast troves of data, sometimes including personal information provided by users themselves in their conversations with AI chatbots.

Rival chatbot makers already have some privacy features. Google’s Gemini chatbot has the option to disable chat history and opt out of allowing one’s data to be used in training its AI models. ChatGPT has similar controls.

Meta says it’s rolling out incognito chats because users often ask chatbots sensitive questions or include private financial, personal, health or work data in their questions.

“We’re starting ask a lot of meaningful questions about our lives with AI systems, and it doesn’t always feel like you should have to share the information behind those questions with the companies that run those AI systems,” Will Cathcart, Meta’s head of WhatsApp, told reporters.

Incognito chat mode has safety features to prevent the chatbot from answering questions about harmful topics, Cathcart said.

It will “steer the user towards helpful information if it can and then refuse (to answer) and eventually even just stop interacting with the user completely,” Cathcart said.

Users will only be able to type in questions and get text responses; they won’t be able to upload or generate images. They’ll also have to confirm their age because Meta doesn’t allow users under 13 on its platforms.

Keep reading

AI Safety Institute Debuts with Big-Name Backers and a Censorship Agenda

Common Sense Media’s Youth AI Safety Institute arrived at the Danish Parliament this week and the guest list is stacked with people who think you can’t be trusted to speak freely online.

Hillary ClintonUrsula von der Leyen, former Biden Surgeon General Vivek Murthy, Ofcom chief Melanie Dawes, and the head of an organization that wants to break end-to-end encryption are all gathering at Christiansborg Palace in Copenhagen to announce what they’d like to do next about AI and children.

The “next” part is where it gets concerning. The Youth AI Safety Institute, launched by Common Sense Media on May 5, says it will “complement efforts by regulators and policymakers to translate frameworks such as the EU AI Act, the Digital Services Act, and the UK Online Safety Act into practical protections for child-safe AI.”

Those three censorship laws represent the most aggressive government-directed speech suppression regimes currently operating in the Western world. The Institute isn’t questioning them. In fact, it wants to help implement them and push them further.

The summit, titled “Keeping Our Children and Families Safe in the AI Era,” is co-hosted by Common Sense Media, Save the Children Denmark, and Margrethe Vestager, who spent years as the European Commission’s executive vice president building the regulatory architecture that now lets EU officials order platforms to delete content.

More than 200 policymakers, tech executives, and civil society figures are expected. King Frederik X of Denmark is giving the opening address. The Duchess of Edinburgh will attend. Danish Prime Minister Mette Frederiksen is on the bill.

And so is Pinterest CEO Bill Ready, whose company helped pay for the Institute’s creation.

Keep reading

France Moves to Break Encrypted Messaging

France’s intelligence delegation in parliament has formally backed breaking the encryption that protects WhatsApp, Signal, and Telegram conversations, recommending that magistrates and intelligence agents be granted what lawmakers describe as targeted access to messages that platforms currently cannot read even themselves.

The delegation, an eight-member body composed of four deputies and four senators, published its conclusions on Monday after months of work on a question that keeps returning to the French Parliament. “The inability to access the content of encrypted communications constitutes a major obstacle for the work of the justice system and intelligence services,” the delegation wrote, framing end-to-end encryption as a problem to be solved rather than a protection to be preserved.

The technology end-to-end encryption uses is precisely the thing the delegation wants weakened. Decryption keys live on user devices, not on company servers, which means the platforms holding your messages genuinely cannot read them. That’s the design and the point. Strip that property away and the protection collapses because a system that lets investigators read messages on demand is also a system that can be abused, leaked, subpoenaed, or hacked.

French police and intelligence services have spent years complaining about this tech. They can still intercept old-fashioned phone calls and SMS messages with a judge’s warrant but encrypted platforms route around that capability entirely.

Keep reading

Europe Wants To Ban VPN Privacy

The European Union is now openly discussing restricting VPN access as part of its expanding online age-verification system, which demonstrates precisely where the entire digital agenda has been heading from the beginning. They always introduce these systems under emotionally untouchable justifications such as child safety or combating terrorism, but once the infrastructure is in place, the scope inevitably expands.

According to a new European Parliament briefing, officials are concerned that users are bypassing online age-verification requirements via VPNs, and the report notes a surge in VPN usage in countries implementing stricter digital controls. The proposal being discussed is to potentially restrict VPN access itself to those above a so-called “digital age of majority.” In other words, they are now targeting the very tools people use to protect their privacy online.

For readers who may not use these services personally, a VPN simply encrypts your internet traffic and masks your location, preventing internet providers, corporations, and governments from monitoring everything you do online. Businesses use them constantly, financial institutions rely on them, journalists use them, and ordinary people use them simply to avoid being tracked across the internet.

The problem from the government’s perspective is that VPNs interfere with surveillance. Europe’s Digital Services Act has already pushed platforms toward mandatory age-verification systems that increasingly require identification documents, facial scans, or biometric verification simply to access online content. Once users began using VPNs to avoid those systems, regulators immediately shifted toward framing the VPN itself as the threat. This is how these systems always evolve, because the objective is never merely regulation, it is compliance and visibility.

What they are building is effectively a digital identity system where access to information requires permission. People fail to understand how dangerous this becomes once connected to the broader European agenda involving CBDCs, centralized digital IDs, online speech regulation, and financial monitoring. These are not isolated policies appearing randomly at the same time. They are interconnected components of a single structural transition toward centralized digital control.

First they regulate speech under the justification of misinformation. Then they regulate platforms under the justification of safety. Then they require identity verification under the justification of protecting children. Finally they target anonymity itself by restricting the tools people use to avoid surveillance.

This fits perfectly within the broader cycle unfolding in Europe, where declining economic confidence and political instability lead governments toward greater centralization and control. Historically, governments facing crisis do not voluntarily reduce authority, they expand surveillance, tighten restrictions, and attempt to maintain control over information and capital flows.

Keep reading

EU Going To War With VPNs In Bid To “Save The Children”

Western European governments and EU bureaucrats are advancing tighter regulations on VPNs as part of a broader push for “online age verification” and their ‘Chat Control’ agenda.  Privacy advocates and digital rights groups warn that Europe is drifting towards a surveillance and censorship regime similar to internet restrictions and firewalls used by Russia and China.

Last week European Commission Executive Vice-President Henna Virkkunen suggested that Brussels may need to address the use of VPNs to bypass the EU’s upcoming age-verification systems.  Speaking during a press conference on the EU’s new digital age-verification app, Virkkunen acknowledged that users could circumvent the system with VPNs and stated that preventing such circumvention would be among the ‘next steps’ policymakers need to examine.

Her statements were delivered only two weeks after she shared a stage with EU Commission President Ursula von der Leyen, who called for a crackdown on web media companies to “protect children” from dangerous content.  The first stage of their agenda is a government created universal age verification app which web companies will be required to integrate.  Von der Leyen asserts that the new restrictions are designed to “defend children’s rights” (how does restricting access protect rights?).

The Orwellian language of the EU is not coincidental.  “Child vulnerability” is a carefully chosen vehicle to manipulate public approval, opening the door to incremental government management of online content and discourse. 

Keep reading

EU Targets VPNs in EU Age Verification Push

Brussels has a problem with people trying to stay anonymous online and now it’s eyeing the tools they use to do it.

Henna Virkkunen, the European Commission’s Executive Vice-President for Tech Sovereignty, Security, and Democracy, told reporters that VPNs sit on the agenda as the EU pushes its age verification app toward member states.

Asked how Brussels intends to stop children from routing around age checks with a VPN, she said “it’s also an important part of next steps also to look at that it shouldn’t be circumvented.”

VPNs are more than a tool for teenagers trying to access Instagram. They are how journalists protect sources, how dissidents talk to family, how ordinary people stop their internet provider from logging every site they visit. Treating circumvention as a problem to be solved at the network level means treating privacy tools as the obstacle, rather than the proportionate response to a system that demands ID for ordinary online activity.

The VPN comment surfaced at a press conference about the Commission’s broader regulatory squeeze.

Brussels provisionally found that Meta likely violated the Digital Services Act by failing to keep under-13s off Facebook and Instagram, accusing the company of “failing to diligently identify, assess and mitigate the risks of minors under 13 years old accessing their services.”

By the Commission’s own count, roughly 12% of European children below the age limit log into the platforms anyway.

Virkkunen framed the finding as enforcement of existing rules rather than a new mandate. “The DSA requires platforms to enforce their own rules: terms and conditions should not be mere written statements, but rather the basis for concrete action to protect users, including children,” she said.

A Commission spokesperson echoed the line, telling ISMG that the DSA “does not mandate specific mitigation measures,” and pointing to alternatives like better internal review processes.

The denial sits awkwardly next to everything else Brussels is doing. The Commission published guidelines last July recommending age verification. It is now pressing member states to “accelerate the adoption of age verification tools.”

Keep reading

Virginia Governor Gets Bad News on Background Check Bill

Since the Virginia General Assembly approved a revised version of the bill last week, there’s been a whole lot of confusion about Virginia’s HB 1525, which raises the age to purchase handguns from 18 to 21 and requires the Virginia State Police to resume conducting background checks on private sales. Governor Abigail Spanberger’s amended version contained language that declared the act an emergency, which would allow it to take effect immediately, but the legislature did not approve the changes with a 4/5ths vote, which is supposedly what’s required in order for that “emergency” provision to be adopted. 

The Virginia legislative website lists the effective date for HB 1525 as July 1, but the Virginia State Police put out a notice on Tuesday that declared the law is already in effect. That was the good news for Spanberger. 

The bad news? The VSP won’t be resuming background checks on private sales of firearms anytime soon… at least not without a court order. 

Gun Owners of America and VCDL had threatened to seek contempt charges against the head of the VSP if they abided by Spanberger’s edict, and it looks like the VSP didn’t see that as an idle threat. 

Keep in mind that there are three parts to HB 1525; a ban on those under 18 from possessing handguns and “assault firearms” except under limited circumstances, the ban on handgun and “assault firearm” sales to adults under the age of 21, and the edict to the VSP to start enforcing the enjoined universal background check law. The only portion of the law that the state police say will not be enforced is the section of law regarding background checks on private sales of firearms, and as far as the agency is concerned it’s now against the law for a 20-year-old to purchase an AR-15 in Virginia, even through a private sale. 

Of course, as of July 1 it will be illegal for any adult over the age of 21 to purchase an AR-15 too. The sale ban wasn’t the primary motivation for HB 1525. It was the restoration of the state’s universal background check law, and the VSP just said that isn’t happening until a judge tells the agency it can resume enforcement. 

So what will that take? The case cited by VSP has concluded, with then-Attorney General Jason Miyares declining to appeal the decision. Current AG Jay Jones attempted to intervene before he took office, but the Virginia Court of Appeals shut down that effort fairly quickly. 

Keep reading