Utah first state to hold websites liable for users who mask their location with VPNs — law goes into effect, designed to prevent bypassing age checks

Utah’s Online Age Verification Amendments, formally Senate Bill 73, take effect on May 6, making the state the first in the U.S. to explicitly target VPN use as part of age verification legislation.

Signed by Governor Spencer Cox on March 19, the controversial law establishes that a user is considered to be accessing a website from Utah if they are physically located there, regardless of whether they use a VPN or proxy to mask their IP address. It also prohibits covered websites from sharing instructions on how to use a VPN to bypass age checks.

NordVPN has called the law an “unresolvable compliance paradox” and a “liability trap,” arguing that it holds websites responsible for identifying users whose tools are specifically designed to be unidentifiable. The EFF warned that the legal risk could push sites to either ban all known VPN IPs or mandate age verification for every visitor globally.

The law is also technically flawed, given that it assumes that a web provider can reliably detect VPN traffic and determine a user’s true physical location — they can’t. IP reputation databases such as MaxMind and IP2Proxy can flag traffic from known datacenter IP ranges, but commercial VPN providers rotate addresses constantly, and residential VPN endpoints are largely indistinguishable from standard home connections. Autonomous System Number analysis can catch traffic originating from datacenter networks, but can’t identify a personal WireGuard tunnel running on a cloud VPS, for example, which routes through the same infrastructure as ordinary web hosting.

The only detection method that reliably identifies VPN protocol signatures is deep packet inspection, which analyzes traffic at the network level, not system- or app-level. China’s Great Firewall and Russia’s TSPU system deploy DPI via ISPs, but a website operator can’t because it requires access to network infrastructure that sits between the user and the server, not on the server itself.

Meanwhile, setting up a personal WireGuard instance on any major cloud provider takes minutes, meaning the law will be more likely to negatively impact non-technical users who rely on commercial VPN services for legitimate privacy: journalists, people living under authoritarian regimes, political dissidents, and abuse survivors, among others.

Keep reading

Meta Terminates Contract with Kenya After Workers Shared Intimate Videos Recorded by Smart Glasses

Mark Zuckerberg’s Meta has ended its contract with Sama, a Kenya-based data annotation company, two months after workers reported viewing sensitive footage ranging from sexual activity to bathroom breaks recorded by Ray-Ban Meta smart glasses.

Ars Technica reports that Meta has terminated its business relationship with Sama, a Kenyan data annotation firm, following reports that contracted workers had viewed explicit and private content captured by Ray-Ban Meta smart glasses. The contract termination, which affected 1,108 workers according to Sama, occurred less than two months after the allegations became public.

In February, multiple workers from Sama reported viewing sensitive, embarrassing, and apparently private footage while performing data annotation work for Meta. The complaints were featured in a report by Swedish newspapers Svenska Dagbladet and Göteborgs-Posten, along with Kenya-based freelance journalist Naipanoi Lepapa. Workers described watching explicit footage shot from Ray-Ban Meta glasses, including people changing clothes, doing drugs, having sex, and using the toilet.

Sama, headquartered in Kenya, had been contracted by Meta to perform data annotation work involving video, image, and speech annotation for Meta’s AI systems used in Ray-Ban Meta smart glasses. The company’s workers were tasked with reviewing content to help improve the performance of Meta’s AI products.

A Meta spokesperson told Breitbart News, “Last month, we paused our work with Sama while we looked into these claims. We take them seriously. Photos and videos are private to users. Humans review AI content to improve product performance, for which we get clear user consent. We’ve also decided to end our work with Sama because they don’t meet our standards.”

Sama workers believe the contract was terminated in retaliation for speaking out about the disturbing content they encountered during their work. One anonymous Sama employee was quoted in the February report saying workers “are just expected to carry out the work” even when viewing private footage.

Keep reading

New Digital ID Bill Ties Your Identity to Your Phone—and Everything You Do Online

Republicans are once again teaming up with Democrats to ram Digital ID through at the federal level.

The bill they’ve just introduced is, if you can believe it, worse than all the others before it.

HR 8250, deceptively named the Parents Decide Act, doesn’t just force everyone to link their identity to use apps on their phones, it mandates that they must do it to use ANY operating system. That means Apple, iOS, Windows, Google, Android, even Samsung—basically everything.

And once that’s in place, there’s nowhere to step outside of it.

But one brave group is refusing to go along.

GrapheneOS has made a statement saying: GrapheneOS will remain usable by anyone around the world without requiring personal information, identification, or an account.

Glenn and Eric Meder from Privacy Academy have been working to educate people on how to escape the digital control grid, including how to put GrapheneOS on your phone—for free. And they have a solution to Digital ID right now.

Keep reading

Mike Johnson’s Crusade to Renew Warrantless NSA Spying on Americans Culminates This Week

House Speaker Mike Johnson is on a crusade. He is determined to pass a three-year, reform-free renewal of the notorious FISA law that authorizes the NSA to spy on the communications of American citizens, on U.S. soil, without warrants of any kind.

Immediately prior to the last (unsuccessful) attempt by Johnson to pass a new reform-free renewal of this spying law — just two weeks ago — I wrote about the bizarre and deeply bipartisan history of FISA domestic spying and how the U.S. somehow became a country that authorizes its surveillance state to target American citizens, all without warrants.

I will not recount all of that here, except to note that — like the 2001 Patriot Act — the original law empowering the NSA to spy on Americans without warrants was such a self-evident departure from American tradition that passage was only possible by portraying it as a mere temporary emergency measure. Yet those spying powers have now become one of the many such “temporary” and “emergency” measures that have seamlessly become a quasi-permanent fixture of the U.S. government. This upcoming week in the House will determine whether it becomes genuinely permanent and, worse, forever immune to reforms.

The FISA bill that permits warrantless NSA spying on American citizens was first enacted by Nancy Pelosi’s House in 2008, then signed into law by President Bush. The law provided for those powers to expire four years later, unless Congress approved renewal.

The law was first renewed in 2012 with the support of the Obama White House, this time for five years, without any reforms. When that five-year renewal was set to expire in 2018, Congress, this time backed by the Trump White House, passed a six-year reform-free renewal, requiring a new vote in 2024.

For the 2018 renewal, there was a mountain of evidence demonstrating abuse, which in turn gave rise to steadfast opposition to such a renewal from dozens of members of both parties (who were demanding, among other reforms, the addition of a warrant requirement for spying on Americans). As a result, then-Speaker Paul Ryan (R-WI) was forced to rely on dozens of Democratic representatives to secure FISA renewal.

Ryan accomplished this by working in close tandem with three key California Democrats: then-Minority Leader Nancy Pelosi, ranking Intelligence Committee member Adam Schiff, and Eric Swalwell (D-CA). That liberal trio led 65 House Democrats alongside 191 Republicans to vote to endow a President they were calling a Hitler-type fascist with virtually unlimited power to spy on Americans without warrants.

The last time the FISA bill was renewed was four years after that 2018 vote: in April, 2024, with the support of the Biden White House and the key support of newly elected House Speaker Mike Johnson. That time, Congress was only willing to extend it only for two years, meaning the bill was scheduled to lapse on April 17, 2026, unless it was renewed again.

That is why Mike Johnson is now tasked with securing a new multi-year renewal of FISA with no reforms. On April 17 — last week — Johnson’s first attempt to renew the spying law for 18 more months failed to secure the necessary votes in the House for renewal He was thus forced to desperately plead with the chamber for a short 10-day extension to give more time to pressure the 20 House GOP holdouts to change their minds, and to try to induce more Democratic defections.

Keep reading

Apple Fixes Bug That Allowed FBI To Read Deleted Signal Messages

Tech giant Apple has fixed a security flaw that had allowed the FBI to access a Signal user’s deleted messages through their phone’s push notification database, despite the app being deleted and messages being set to disappear.

In a security advisory released on Wednesday, Apple said it had fixed a bug that allowed “notifications marked for deletion” to be “unexpectedly retained on the device.”

In an X post on Wednesday, Signal said the update fixed the issue that made a user’s messages retrievable by law enforcement.

“Apple’s advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release,” Signal said.

Signal uses end-to-end encryption to secure messages between its users. The bug is a reminder that messaging encryption may not be enough to keep data protected when using certain devices or operating systems.

Keep reading

EFF Sues DHS and ICE For Records on Subpoenas Seeking to Unmask Online Critics

The Electronic Frontier Foundation (EFF) sued the Department of Homeland Security (DHS) and Immigration and Customs Enforcement (ICE) today demanding public records about their use of administrative subpoenas to try to identify their online critics.

Court records and news reports show that in the past year, DHS has used administrative subpoenas to unmask or locate people who have documented ICE’s activities in their community, criticized the government, or attended protests. The subpoenas are sent to technology companies to demand information about internet users who are often engaged in protected First Amendment activity.

These subpoenas are dangerous because they don’t require judges’ approval. But they are also unlawful, and the government knows it. When a few users challenged them in court with the help of American Civil Liberties Union affiliates in Northern California and Pennsylvania, DHS withdrew them rather than waiting for a decision.

DHS and ICE have ignored EFF’s public-records requests for documents about the processes behind these subpoenas, so EFF sued Wednesday in the U.S. District Court for the District of Columbia.

“DHS and ICE should not be able to first claim that they have the legal authority to unmask critics and then run from court when users challenge these administrative subpoenas,” said EFF Deputy Legal Director Aaron Mackey. “The public deserves to know what laws the agencies believe give them the power to issue these speech-chilling subpoenas.”

An administrative subpoena cannot be used to obtain the content of communications, but they have been used to try and obtain some basic subscriber information like name, address, IP address, length of service, and session times. If a technology company refuses to comply, an agency’s only recourse is to drop it or go to court and try to convince a judge that the request is lawful.

EFF and the ACLU of Northern California in February ​wrote to Amazon, Apple, Discord, Google, Meta, Microsoft, Reddit, SNAP, TikTok, and X​ to ask that they insist on court intervention and an order before complying with a DHS subpoena; give users as much notice as possible when they are the target of a subpoena, so the users can seek help; and resist gag orders that would prevent the companies from notifying users who are targets of subpoenas.

And EFF last week ​asked California’s and New York’s attorneys general to investigate Google​ for deceptive trade practices for breaking ​its promise​ to notify users before handing their data to law enforcement, citing the case of a doctoral student who was targeted with an ICE subpoena after briefly attending a pro-Palestine protest.

Keep reading

UK Biobank health data listed for sale in China, government confirms

Medical information of 500,000 participantsof one of the UK’s landmark scientific programmes, UK Biobank, were offered for sale online in China, the government has confirmed.

Technology minister Ian Murray said information of all members of the database was found listed for sale on the website Alibaba.

Murray told MPs the charity which runs UK Biobank had told the government about the breach on Monday. He said the information did not include names, addresses, contact details or telephone numbers.

However he said it could include gender, age, month and year of birth, socioeconomic status, lifestyle habits, and measures from biological samples.

The Biobank is a collection of health data offered by volunteers which has been used to help improvements in detection and treatment of dementia, some cancers and Parkinson’s.

It has collected intimate details – including whole body scans, DNA sequences and their medical records – from hundreds of thousands of volunteers for over two decades. The project has led to more than 18,000 scientific publications.

Participants were aged from 40 to 69 when they were recruited between 2006 and 2010.

UK Biobank said it was investigating the incident and thanked the UK and Chinese governments, as well as Alibaba, for support and cooperation.

“We understand that the existence of these listings, even temporarily, will be concerning to you,” Chief Executive Professor Sir Rory Collins said in a message to participants.

“We want to reassure you that all the data are de-identified; they do not contain any personally identifying information (such as names, addresses, dates of birth, and NHS numbers).”

Sir Rory told volunteers in his letter the data involved in the incident had been made available to researchers at three institutions.

He added the data was “swiftly” removed by Alibaba, following support from the UK and Chinese government, but the data’s appearance to a “clear breach of the contract signed by these academic institutions”.

“They, along with the individuals involved, have had their access suspended,” Sir Rory added.

Murray told MPs the government has been told no purchases were made from the three listings on the website.

Alibaba has been contacted for comment.

Keep reading

Turkey to Ban Anonymous VPNs

Turkey is moving to make anonymous VPN use illegal, and Proton VPN signups in the country have doubled as word spreads. The Turkish government’s plan, reported by local outlet Yeni Şafak, would outlaw unlicensed VPN services and require any approved provider to log what users do and turn those records over to Turkish authorities on request.

A VPN that logs and reports isn’t really a VPN. It’s a second surveillance pipe pointed at the same people the government already watches.

Officials describe the measures as part of a package aimed at protecting children after school attacks in Şanlıurfa and Kahramanmaraş, with attackers reportedly drawn to violent mobile games. Packaged alongside the VPN clampdown are parent-controlled “child SIM” lines and a cap on how many mobile numbers a single person can register.

The child-protection wrapper is the sweetener, because the actual infrastructure being built, licensed VPN providers that log and disclose, reaches every adult in the country, not just children playing shooters on their phones.

Keep reading

France’s ID Portal Hacked: 19 Million Records Up for Sale

French authorities have added another case study to the growing argument against centralizing citizen identity data.

France Titres, formerly known as ANTS, operates the portal where residents apply for passports, national ID cards, residence permits, driver’s licenses, and vehicle registrations.

On April 15, something broke inside that system. A week later, the Interior Ministry confirmed what anyone watching digital ID schemes has been saying about this exact architecture for years, and the scale on offer from the attacker makes the warning harder to wave away.

A threat actor using the aliases “breach3d” and “ExtaseHunters” appeared on criminal forums on April 16, claiming to have stolen between 18 and 19 million records from the agency’s internal systems.

If accurate, that is roughly a third of France’s population sitting in a for-sale listing. The seller describes the haul as a fresh, structural compromise rather than a recycled dump, and is actively shopping it.

Early French press reports, including Le Figaro, initially pegged the figure at around 12 million accounts before later estimates climbed. The government has not confirmed any number.

What the ministry has confirmed is a “security incident that may involve the disclosure of data from both individual and professional accounts.”

Login credentials, full names, email addresses, dates of birth, unique account identifiers, postal addresses, places of birth, and phone numbers may all have been extracted. That combination is a starter kit for identity fraud, synthetic identity construction, and convincing phishing attacks against people who already expect email from French government domains.

Keep reading

Beyond Cookies – How To Stop The Invisible Browser Fingerprint That Tracks You Everywhere

For years, the privacy advice was simple: clear your cookies, use incognito mode, or click “Reject All” on those annoying consent banners. That advice is now outdated.

A groundbreaking study published last year has delivered the first peer-reviewed proof that the $600 billion online advertising industry has moved on from cookies. The new tracking method is called browser fingerprinting, and it works even if you never log in, never accept cookies, and have legally opted out under privacy laws.

Researchers from Texas A&M University and Johns Hopkins University built a tool named FPTrace to measure exactly how this works in the wild. They simulated real user sessions, systematically altered browser fingerprints, and watched what happened to the ads being served and the bids advertisers placed in real time. The results were clear: when the fingerprint changed, the price advertisers were willing to pay to target that “user” changed with it. Tracking signals dropped. The system was actively using the fingerprint to follow people across sessions and sites.

And crucially, this happened even in tests where cookies were fully deleted and users were in “opt-out” mode under GDPR and CCPA rules. The law’s exit door for cookies does not cover fingerprinting.

How Browser Fingerprinting Works (No Permission Required)

Every time your browser loads a page, it leaks dozens of tiny, seemingly harmless signals:

  • Screen resolution and color depth
  • Installed fonts
  • GPU model and graphics capabilities
  • Audio processing signatures
  • Browser version, plugins, and language settings
  • Time zone
  • Canvas rendering differences (how it draws hidden shapes)
  • Whether you run an ad blocker
  • Even battery level in some cases

Alone, each detail is common. Combined, they create a unique “fingerprint” that can identify your device with startling precision. No cookies. No login. No pop-up asking for consent. Just loading the page is enough.

Keep reading