The unintended consequences of the Online Safety Act
Ironically, the Online Safety Act, and the way it was implemented last week, has made the online world decidedly more dangerous, and I need to belatedly share some of my thoughts on it.
Most people who knew about the Online Safety Bill would have been under the impression that it was about censoring harmful content on social media and implementing stronger age verification measures specifically for pornography sites. The idea would be that adults would provide scans of government-issued proof of identity. Obviously it wasn’t a brilliant idea, given the potential for inevitability of data breaches, and the convincing scam attempts, blackmail and identity theft that would follow from that.
A much safer and more effective approach, since children generally don’t buy their own devices, would have been to encourage parents to configure the devices and home routers to filter whatever content they deem harmful. Android and Windows have configuration options that are literally called ‘Parental controls’. And, if you’re not using some anti-virus product with those features, why not?
But anyway, we discovered, on the 25th July, that the definition of ‘adult content’ is very broad indeed, covering a vast range of things that aren’t remotely pornographic. Conveniently, for the government, political opinion, reportage of protests, citizen journalism, self-help forums about various addictions, etc. are among the content being age-restricted. Many of us are finding it very hard to believe this outcome wasn’t intentional, given the other efforts lately to censor the growing discontent, from both ends of the political spectrum, with the current (demonstrably authoritarian) Starmer regime.
The OSA, as it’s been implemented, is predictably very unpopular. A petition to repeal it has around 479,000 signatures, at the time of writing, but thats been dismissed by Starmer, et al. Proton reported a 1,400% increase in the number of users of their VPN service within a couple of days - and this is just one of several VPN services. The OSA is unpopular to the point I’d been asked, by people who were willfully ignorant of the subject area beforehand, to describe what a VPN does and how to get started using one.
The responses from the Labour Party, the Conservatives and (disappointingly) the Liberal Democrats, to the petition and our very strong arguments against the OSA, have shown how completely out of touch their MPs are with the British people. How are the Liberal Democrats on board with the denial of basic civil liberties?
There are five likely outcomes to this:
Usability
Over the years, I’ve come across numerous censorship-resistant Internet protocols, messenger services and alternatives to mainstream ‘social media’. Most of them should have beome popular, but they failed to gain traction for one reason: Usability. Anything that requires configuration and/or a learning curve to work is a non-starter. Why use Vidalia and Privoxy, when the Tor Browser does approxinately the same thing within a couple of minutes?
This is important because people are going to opt for whatever’s the most convenient. If a person needs to go through the effort of uploading scans of documents to a third-party in order to access basic features of a Web site, that person will use something else. This is the case with BlueSky, unfortunately.
Someone on Reddit put it very well:
‘People under the age of 25 are less tech literate than most people assume. They will follow the path of least resistance to access content rather than do anything “clever”. This could mean using free VPN but more likely they’ll just stop using apps and services that require age verification and just use whichever alternatives pop up on their Tik Tok feed first.’
This leads to the second problem.
The OSA will make an existing problem much worse
Mainstream pornography sites are relatively safe, self-regulating and moderated, because they try to operate as professional businesses, and already comply with various legal restrictions. Allowing young people to access them obviously isn’t ideal, but it might actually be the safest option. It’s a case of ‘We can’t realistically stop someone from doing X, but we can give the person the means to do it relatively safely.’. The government at least then had some influence in what people were accessing.
What censorship and age verification will do is push more people to the unregulated (and now more accessible) sites that don’t care about hosting extreme content. I think that content will be shared, perhaps to the point of going viral, through whatever messaging services.
Data breaches
To put it bluntly, we must assume that everything submitted to the age-verification services - scans of passports and drivers’ licences, bank and credit card details, photos, etc. - will be sold to numerous other third-parties and subject to data breaches within months. The consequences of data breaches involving that sort of data would be pretty bad. When (not if) that information ends up on the Darknet, we’re likely going to see catastrophic instances of identity theft. Something very much like this happened recently, in fact, to users of the Tea app:
‘Women have to submit a selfie (to “prove” their gender) in order to use the app; an estimated 72,000 images, including 13,000 verification photos and photos of government IDs, have been leaked online.’
I believe it’s inevitable, given large-scale data breaches, involving established corporations, happen every other week. The difference with the age verification services is they’re provided by companies that almost none of us have heard of, which are based in the United States (likely not subject to our data protection laws), and there wouldn’t be any legal recourse in the event of a data breach.
VPNs
Since the age verification redirects seem to happen at the Content Delivery Networks, there are multiple ways of bypassing it by forcing the URLs to resolve to CDNs outside the UK, or even the originating Web server. The commonly-discussed method of doing this is to use a VPN service.
I’d long encouraged the use of trusted and secure VPNs as part of a strategy for establishing a boundary between our online and real-world identities. This is especially important for anyone who’s likely to be a target for doxxing. VPNs can also be an essential layer of security when using a public WiFi service, and vendors (such as Samsung and Apple) do encourage that.
Using a VPN to bypass age-verification is objectively far safer than compliance, but it’s not without its own risks. There’s no guarantee that a given VPN service isn’t harvesting and selling data about its users’ browsing habits, logging session data that can be turned over to the authorities or using SSL/TLS-related trickery for Man-in-The-Middle attacks. Choose your VPN provider carefully, and don’t use it for anything illegal.
If we’re using a VPN for anonymity, it’s not going to be effective without good OPSEC, careful browser configuration and split tunnelling.
Alt-tech
For a decade I’d been predicting that centralised ‘social media’ would be supplanted by more distributed (namely P2P) systems that incorporate self-hosting and end-to-end encryption. It’s sort of happening, with young people using various messenger apps rather than FaceBook and Twitter. What I had in mind, though, was something more like SimpleX and things developed on IPFS.
When mainstream services become unusable for purpose, people do adapt.
Hardly anyone I know uses Telegram, but that apparently became the messenger of choice among those involved in the civil unrest in the Southport region last year, primarily because people believed Telegram was more trustworthy than FaceBook and WhatsApp. It also indicates that word of Telegram got around rather quickly. The protests against the Supreme Court’s ruling against transgender people, in April, were organised through BlueSky, partly because that information would have been suppressed on Twitter. Because of the censorship we’re now seeing, VPNs went from being somewhat niche to extremely popular overnight.
https://www.joe.co.uk/news/petition-to-repeal-online-safety-act-reaches-280000-signatures-498711
https://www.theregister.com/2025/07/28/uk_vpn_demand_soars/
https://krebsonsecurity.com/category/data-breaches/
https://petition.parliament.uk/petitions/722903
https://www.currentaffairs.org/news/britain-is-losing-its-free-speech-and-america-could-be-next