- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,476
Are we giving up freedom for the illusion of security?

The idea of verifying everyone's age is quickly transforming from a security measure into a surveillance mechanism. This is the warning issued by Proton CEO Andy Yen. He believes the current policy of mandatory age verification online is already creating an infrastructure for the mass collection of personal data and undermining the very possibility of anonymity.
Attempts to introduce age verification are underway in dozens of countries and nearly half of the US states. Lawmakers are trying to restrict children's access to harmful content, but in practice, users are forced to present passports, ID cards, or undergo biometric checks even for basic surfing. Human rights activists have long warned that this approach is changing the very architecture of the internet.
Ian's main complaint isn't about the purpose itself, but about the system's design. Age verification almost always means sensitive data is collected and stored by third-party services. Recent experience has shown that such databases are eventually leaked . In October 2025, the platform Discord acknowledged a hack of a contractor responsible for user verification. As a result, the attackers gained access to the data of over 70,000 people, including ID photos . Critics say government solutions appear less secure: researchers allegedly circumvented an age verification app launched by the European Union in a matter of minutes.
The logic here is simple: the more valuable data is collected in one place, the more attractive the attack surface becomes. And we're not talking about passwords, but rather documents and biometrics, which can't simply be replaced after a leak.
Ian also points to another layer of the problem: the interests of large platforms. He believes that some tech companies support age verification not only out of concern for security. Shifting control to the network or device level relieves services of some responsibility for content and allows them to maintain their advertising models. There are already suggestions that operating systems, such as Apple and Google, should perform verification. In the UK, Apple has already added such mechanisms, sparking a strong reaction from privacy advocates.
The risk isn't limited to age. If a system can block access based on one parameter, the list of criteria can easily be expanded. The same mechanisms can be used to filter by country, status, or any other criteria. In such a model, anonymity disappears, complicating the work of journalists, activists, and anyone else who needs secure communication.
However, Yen believes that completely eliminating verification is unrealistic. Therefore, he believes the system needs to be redesigned. Verification should occur on the user's device itself, without transmitting documents to servers. Biometrics should only be used for instant verification with immediate data deletion. The system should ultimately provide a single answer—whether the user has reached the required age—without linking to identity and end-to-end encrypted transmission. The source code for such solutions, Yen believes, should remain open, so anyone can verify how the mechanism works.
The principle here is extremely simple: the most secure data is data that hasn't been collected. If there's no database, it can't be hacked, transferred, or misused.
The main source of risks for children and adults online isn't a lack of verification, but a business model based on advertising and attention retention. Platforms profit by encouraging users to spend more time online and tailoring content to that interest. Until this model changes, any technical barriers will only be partially effective.

The idea of verifying everyone's age is quickly transforming from a security measure into a surveillance mechanism. This is the warning issued by Proton CEO Andy Yen. He believes the current policy of mandatory age verification online is already creating an infrastructure for the mass collection of personal data and undermining the very possibility of anonymity.
Attempts to introduce age verification are underway in dozens of countries and nearly half of the US states. Lawmakers are trying to restrict children's access to harmful content, but in practice, users are forced to present passports, ID cards, or undergo biometric checks even for basic surfing. Human rights activists have long warned that this approach is changing the very architecture of the internet.
Ian's main complaint isn't about the purpose itself, but about the system's design. Age verification almost always means sensitive data is collected and stored by third-party services. Recent experience has shown that such databases are eventually leaked . In October 2025, the platform Discord acknowledged a hack of a contractor responsible for user verification. As a result, the attackers gained access to the data of over 70,000 people, including ID photos . Critics say government solutions appear less secure: researchers allegedly circumvented an age verification app launched by the European Union in a matter of minutes.
The logic here is simple: the more valuable data is collected in one place, the more attractive the attack surface becomes. And we're not talking about passwords, but rather documents and biometrics, which can't simply be replaced after a leak.
Ian also points to another layer of the problem: the interests of large platforms. He believes that some tech companies support age verification not only out of concern for security. Shifting control to the network or device level relieves services of some responsibility for content and allows them to maintain their advertising models. There are already suggestions that operating systems, such as Apple and Google, should perform verification. In the UK, Apple has already added such mechanisms, sparking a strong reaction from privacy advocates.
The risk isn't limited to age. If a system can block access based on one parameter, the list of criteria can easily be expanded. The same mechanisms can be used to filter by country, status, or any other criteria. In such a model, anonymity disappears, complicating the work of journalists, activists, and anyone else who needs secure communication.
However, Yen believes that completely eliminating verification is unrealistic. Therefore, he believes the system needs to be redesigned. Verification should occur on the user's device itself, without transmitting documents to servers. Biometrics should only be used for instant verification with immediate data deletion. The system should ultimately provide a single answer—whether the user has reached the required age—without linking to identity and end-to-end encrypted transmission. The source code for such solutions, Yen believes, should remain open, so anyone can verify how the mechanism works.
The principle here is extremely simple: the most secure data is data that hasn't been collected. If there's no database, it can't be hacked, transferred, or misused.
The main source of risks for children and adults online isn't a lack of verification, but a business model based on advertising and attention retention. Platforms profit by encouraging users to spend more time online and tailoring content to that interest. Until this model changes, any technical barriers will only be partially effective.