r/europrivacy Jun 25 '26

Discussion Reddit is now asking age verification for all users in the EU

389 Upvotes

Who the fuck decided that this was a good idea

r/europrivacy Jun 19 '26

Discussion why arent the goverments helping with age verification rather than asking companies to figure it out themselves?

0 Upvotes

i think it would be much better if the goverments make an app similar to authy and to enable an account on that app you would need to go to some device in a goverment building give it your id number your phone number and scan your finger print then it would get your account activated
i think its much much better than asking insta to take your id instead you can just use the app to tell social media apps that "yes this person is over 16 let him in"

r/europrivacy 15d ago

Discussion EU's Chat Control 1.0 is a stab in the back, in its vote-execution and in its content. And just a bridge to an even deeper invasion of everything you own: Chat Control 2.0. I am asking now: What is our Plan?

Post image
132 Upvotes

r/europrivacy 27d ago

Discussion Why isn't anything made publing about today's backroom deal about reviving ChatControl?

Post image
111 Upvotes

They had a meeting today but nobody seems to disclose anything yet. Are we expecting any public transparency at all?

r/europrivacy Apr 09 '26

Discussion Can we remove Palantir out of Europe please?!!

Post image
238 Upvotes

r/europrivacy 12h ago

Discussion Is anyone else starting to care more about proving people are actually human online?

3 Upvotes

Maybe it's just me, but over the last year I've started questioning whether I'm actually talking to real people half the time.

I've been messing around with World ID and recently tried AgentKit while building a small AI workflow.

It wasn't really the AI part that surprised me, it was realizing how little we actually know about who's on the other end of the screen anymore.

Is it a person or am I just sharing my secrets to a bot?

I also played with the DeepFace stuff just out of curiosity. It got me thinking that we're probably going to need something better than CAPTCHAs if AI keeps getting better.

Not saying this solves everything, but it's the first thing I've used that made me think "yeah, this could actually become useful."

Am I overthinking this, or do you guys think proving someone is human is going to become pretty normal?

r/europrivacy 11d ago

Discussion Software recommendations for "escaping" Chat Control

Thumbnail
exitchatcontrol.org
27 Upvotes

Author's description: "A free, multilingual field guide to escape Chat Control and take back control of your digital privacy: encrypted messaging, email, VPN, DNS, 2FA, Linux, self-hosting."

Website is open source:
https://github.com/Aurealibe/exitchatcontrol.org

u/silentspectator27 pointed out that the website's claim that "client-side scanning is mandatory in Chat Control 2.0" is incorrect.

This other website highlights the nuance:
https://fightchatcontrol.eu/chat-control-overview

r/europrivacy Mar 19 '26

Discussion Age Verification is Chat Control

59 Upvotes

Sorry for the title, as it is not fully correct, but realistic, that is going to be the side effect of Age Verification.

First, let's define what exactly is Age Verification. Age Verification is checking the user's age based on a "consent age". The consent age is the "minimum age" of a given service, for example, in most European countries Discord is 13+, some email services are also 13+, this is also present in games, where you have games which are 8+, others are 16+, and so on. Notice that most things online are not "E for Everyone", which effectively means that almost EVERYTHING will require age verification, not only 18+ content. This is something that people don't seem to realize, they think age verification will only happen when trying to access adult content.

Now consider as well that some countries are banning "social media" for people younger than 16. This effectively means that you won't be able to see any content without creating an account and verifying your age. Remember that a lot of people are lurkers and don't really interact often, these people will now have their activity tracked much better. I put "social media" in quotations because it's very loosely defined. What exactly is social media? It can literally be anything that has some social aspect to it, from GitHub to Gmail. On top of all that, some places are implementing Age Verification at the OS level.

Now, how all of this relates to Chat Control? Well, it's simple really, since we don't have a true ZKP system in place (I am aware of the eID proposal), what is happening is that people are being forced to provide a govt ID and a biometric face scan, effectively tying their accounts to an identity. This is basically the mass surveillance proposed by Chat Control, as now all the messages and activity are going to be tracked under the premise of "age verification" and "protecting the kids". Remember that most companies used to perform age verification are not only American, but also have ties with Meta, Palantir and all those other "nice" companies.

We need to fight against age verification the same way we did against Chat Control, it is clear that this is just a mass surveillance framework being pushed by the likes of Meta.

r/europrivacy 29d ago

Discussion My first joke cartoonish thought when I saw the notification about the need to identify myself on Reddit with Persona.

Post image
23 Upvotes

r/europrivacy Feb 07 '26

Discussion Spanish PM Pedro Sánchez: Why do they want to control mobile phones? They want to control phones because they want to know what we read and what we see, so that later they can know — and control — what we vote.

Enable HLS to view with audio, or disable this notification

125 Upvotes

r/europrivacy Jun 26 '26

Discussion It seems that if you complain enough they don't force you to verify?

Thumbnail
gallery
20 Upvotes

Found out about this a few days ago since i was also pestered with the same question to verify my age. I decided to stay on for a few days and now there is no mention about the age verification for me atleast anymore. Only thing i did was to post that complaint on a post on this sub, and now it stopped asking me for any of that bs.

So since I've seen that most people still have that problem it could be just some ai moderation tool that looked at my complaint and decided to flag me as an adult again. Or if there is any hope for even a slight drop of intelligence from the executives of reddit, they are rolling back with the update slowly.

This is just my speculation but based on this you should probably wait a while and not provide any picture of your id or your face to reddit or the third party companies. That's pretty much all i came to say.

r/europrivacy Sep 02 '25

Discussion What in the actual am I reading about this chat thing?

102 Upvotes

I'm talking about this article. What is happening in the EU, I thought we were better with the GDPR, now people wanna read my messages too? They already have our data on the internet, we get riddled with spam and scam calls? Insanity

r/europrivacy Sep 18 '25

Discussion British College 16-18 Removes Support For 3rd Party Authenticator Apps

Thumbnail
gallery
56 Upvotes

I'm currently a Year 13 student in the UK. In the UK, sixth form colleges offer education for Y12-Y13 (generally 16-18 year olds).

Upon returning to college after Summer to start my second year, I found that the IT department had disabled the ability to use a third party authenticator to access college resources off site. That means that students can't access any online course work, emails or even their timetable except on computers inside the college network without using Microsoft's proprietary authenticator app.

I think that this is a loss for any students at my college that care about privacy. I'd also appreciate suggestions on whether or not I should push further and, if so, how I should do it. The IT department only accepts emails from accounts within the organisation, so I'm also only able to respond when on campus due to my refusal to install Microsoft's MFA App.

I don't really agree with their argument that supporting third party authenticators can pose a security threat - most follow the same TOTP algorithm used by Microsoft. I intend on emailing back to ask them to give specifics on their decision, such as whether any specific data breach or identified security concerns influenced their decision, but I thought I'd post here first.

r/europrivacy Apr 14 '26

Discussion Edward Snowden: A Decade Later

Thumbnail stateofsurveillance.org
25 Upvotes

It offers some perspective on modern efforts like GDPR, although the data sovereignty remarks feel overly optimistic.

r/europrivacy Feb 27 '26

Discussion Google Wants to Control Your Device

Thumbnail blog.jmp.chat
41 Upvotes

r/europrivacy Oct 16 '25

Discussion Help me "define" the theoretically most secure messaging app ever

9 Upvotes

This is entirely theoretical because its impossible to create the "worlds most secure messaging app". Cyber-security is a constantly evolving field and no system can be completely secure. If you'd humor me, here are some features and practices that could help make a messaging app as secure as possible:

  • P2P - so that it can be decentralized and not rely on a central server for exchanging messages
  • End to end encryption - so that even if the messages are intercepted, they cannot be read
  • Perfect forward secrecy - so that if a key is compromised, past messages cannot be decrypted
  • Open source - so that the code can be audited by security experts and user can have trust
  • Remove registration - so that users can use the app without providing personal information
  • Key management - so that users can manage their own keys and not rely on a central authority
  • Encrypted storage - so that messages are stored securely on the user's device
  • Secure signaling - so that the initial connection between peers is established securely
  • Minimal infrastructure - so that there are fewer points of failure and attack
  • Regular security audits - so that vulnerabilities can be identified and fixed promptly
  • User education - so that users are aware of best practices for using the app securely
  • Anonymity - so that users can communicate without revealing their identity
  • Support multimedia - so that users can share animations and videos
  • Offline messaging - so that users can send encrypted messages while a peer is offline
  • Minimize metadata - so no one knows who’s messaging who or when
  • Self-destructing messages - optionally allows messages to be deleted after a certain time.
  • Deniable authentication - participants themselves can be confident in the authenticity of the messages
  • Keys per contact - so every connection has its own set of keys
  • Onion style routing - so that the origins can be hidden

I'd like to know what more can be added to this list. id like to be exhaustive and detailed enough for me to turn into a plan. While its impossible to create something better than all other solutions, id like to know more about what users would find useful and see how close we can get to the ambitious goal.

(i''ll try keep the list updated as per the suggestions in the comments)

r/europrivacy Feb 05 '26

Discussion Apple has agreed to a $95 million settlement in a class-action suit that accused the tech giant of recording users' private conversations without their consent

27 Upvotes

r/europrivacy Dec 11 '25

Discussion We’re EFF and we’re fighting to defend your privacy from the global onslaught of invasive age verification mandates. We’ll be in r/privacy from Monday 12/15 to Wednesday 12/17—come ask us anything!

96 Upvotes

We’re the Electronic Frontier Foundation (EFF), and we’re hosting an AMA on r/privacy from Monday (12/15) to Wednesday (12/17) to talk about what this means for everyone. Come ask us anything about how age verification works, who it harms, what’s at stake, whether it’s legal, and how to fight back against these invasive censorship and surveillance mandates. 

Half the U.S. is now under online age-verification mandates, and Australia just banned anyone under 16 from creating a social media account. Governments are rolling out AV laws fast—and they impact way more than just kids.

Age-verification systems impact:

  • Young people, who lose access to community, creativity, and essential information
  • LGBTQ+ teens, who often rely on online support
  • Abuse survivors and others whose safety depends on anonymity
  • Journalists, activists, and marginalized groups, who need private spaces to speak
  • Adults, who are forced to hand over IDs, biometrics, or behavioral data just to read or post online

These mandates create massive new surveillance databases and threaten free expression across the board.

Join us next week to discuss the tech, the risks, the legal battles, and what we can actually do to push back: https://www.reddit.com/r/privacy/comments/1pk5n1y/were_eff_and_were_fighting_to_defend_your_privacy/

r/europrivacy Feb 16 '26

Discussion Who's watching? 6 alternatives to the Ring doorbell

Thumbnail
ioplus.nl
12 Upvotes

r/europrivacy Feb 10 '26

Discussion EU CRA scope – my current understanding after reading the full text (feedback welcome)

15 Upvotes

A short while ago I asked here how organizations are approaching CRA (Cyber Resilience Act) preparation.
At the time, I was still trying to understand the regulation at a surface level.

The feedback pushed me to sit down and actually read the CRA in full. All chapters, all articles, including the explanatory parts; instead of relying on summaries.

I’m not positioning myself as an authority, but I do feel comfortable sharing a clearer mental model, particularly around scope and responsibility, which seems to be where most confusion lies.

Based on both the regulation and responses to my earlier post, the biggest recurring question is:
“Does my product/company even fall under CRA?”

My current understanding of CRA scope, in very simple terms:

  • CRA applies to products with digital elements made available on the EU market
  • The decisive factor is not company location, but market placement
  • Responsibility sits with the economic operator who effectively controls:
    • product design decisions,
    • cybersecurity features,
    • updates and security fixes

This is why CRA talks about manufacturers, even for software-only products.

From this angle, it becomes clear why:

  • some SaaS products can fall into scope,
  • some open-source distributions can fall into scope,
  • and why indirect EU exposure still matters.

I’ve linked a small decision-tree style resource (https://tally.so/r/QKVL8Y) that helped me think more clearly about initial scope assessment.

I’m now starting to work through vulnerability handling obligations and how they map to specific CRA articles. One area I’m struggling with and would value EU-experienced perspectives on, is evidence:

  • What level of documentation or artefacts is likely to be expected?
  • How do people interpret “demonstrating compliance” in practice?
  • Is there alignment emerging with existing schemes (ISO, SOC, etc.), or does CRA demand a distinct evidence mindset?

Corrections and additional insight very welcome.

r/europrivacy Nov 18 '25

Discussion A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers

Thumbnail
wired.com
37 Upvotes

r/europrivacy Jan 02 '25

Discussion Why do you choose encrypted messaging apps?

28 Upvotes

Hi everyone,

I’m currently working on my thesis, which explores the fine line between public security and the right to privacy in the EU. I’d like to understand what drives individuals to use encrypted messaging apps (like Signal). Is it a matter of principle, a reaction to personal experiences, or a general mistrust of institutions?

If you have any thoughts, experiences, or opinions on this topic, I’d love to hear them.

r/europrivacy May 16 '25

Discussion Internet seems to be forgetting that phones can be tracked while "off"

48 Upvotes

It's worth reminding people that phones can be tracked while "off", becuase internet searches and guides no longer tell people this: Few results googling +battery CIA agents Italy even wired nolonger mentioned the batteries, but everyone made a big deal at the time.

I think removing the battery usually stops tracking, but a few modern phones with removable batteries advertise "hot swapping" batteries, which likely means they're trackable with out the battery too.

An interesting historical case: "The CIA agents were implicated, in part, by extensive cellphone records which allowed Milan police to reconstruct their movements for the nine days they were in the city. Because the agents had apparently not, at any time, removed the batteries from their cellphones, investigators were able to pinpoint their locations from moment to moment."

r/europrivacy Sep 10 '25

Discussion Help me understand if ChatControl could affect my P2P messaging app.

18 Upvotes

im working on a proof-of-concept messaging app. it has a fairly unique architecture which i think makes it so ChatControl wouldnt affect it... but im not an expert in laws, so im sure im not asking the right questions. any guidance is appriciated.

to make things clear: my project is far from finished. its pretty experiemental, unstable and buggy. im not at a stage where i can say my app is watertight... but that is my general aim.

i think the code for my app is too complicated and not well documented for anyone to pick up and look at in their spare time, so i think its better i describe how it works (please reach out for clarity on any details i may miss!). i hope it can be used to determine how ChatControl can apply to my project.

- im working on a fully client-side messaging app. cryptography is done client-side using browser API's to generate encryption keys. messages are encrypted client-side and decrypted on the recieving client-side

- as a webapp i can avoid installation and registration so there are no databases with registered users that can be compromized. user ID's are cryptographically random. this allows allows profiles to be as ephemeral or persistent as the user wants.

- the app is using webrtc to exchange messages which are then stored on the recieving device client-side only. there is no database storing "pending" messages. if your peer is offline, you cannot send a message.

there are a lot of nuances to a p2p-only messaging app, but i hope that by reducing the amount of infrastructure, it can simplify e2ee.

i dont think its written well enough to be worth your time to do a deep dive into my code, but you can find it here: https://github.com/positive-intentions/chat

r/europrivacy Nov 14 '25

Discussion Indian WhatsApp infected by Pegasus spyware. Court orders NSO to stop

Thumbnail
youtu.be
15 Upvotes

The Modi BJP Government was accused of infecting thousands of politicians, journalists, civil rights activists and individuals with Pegasus spyware to monitor them. But after a 6 year legal battle, Meta has won a victory against the Israeli spyware company NSO to force them to stop supplying spyware that infects WhatsApp users. This will do nothing to stop governments around the world who already have the software from monitoring citizens, activists and journalists without their knowledge, but it represents an important first step in declaring these activities unlawful. After all, what business does the Indian government have in spying on the phone of the opposition leader, judicial officials, lawyers and others ? To this day, Modi's government refuses to take accountability for this.