Reclaim The Net Feed
Reclaim The Net Feed

Reclaim The Net Feed

@reclaimthenetfeed

France Just Deleted the Human Review Step From Stream Blocking
Favicon 
reclaimthenet.org

France Just Deleted the Human Review Step From Stream Blocking

If you're tired of censorship and surveillance, subscribe to Reclaim The Net.Here's another blow to pushing back against instant censorship mechanisms. France's parliament approved a professional sports law on July 21 that lets ARCOM, the audiovisual regulator, block "suspected" pirate sports streams in real time. You read that right; not proved pirate sports streams, just suspected.Article 10 rewrites Article L. 333-10 of the sports code. That's the provision rights holders have used to block streaming sites. With the old process, a rightsholder won a court order against named domains, and when fresh domains turned up, ARCOM's agents confirmed each one was streaming matches illegally before ISPs were ordered to block it. That's according to TorrentFreak.But the new law removes that check. In its place, an automated system now pushes newly spotted targets straight to providers during a live broadcast.And the providers have to act "without delay."The agents audit the new additions once they are live and a blocked party can appeal to ARCOM's president while the match is still being played.Under this new regime, a site disappears first, and whether it should have gone down at all gets decided later. And that's only assuming someone contests it.An order under the old rules came from the Court of Paris on July 8, when the French football league won a block against nine ISPs for the 2026/2027 season.That order listed 30 domains, with ARCOM approving each new site added along the way.That kind of approval is exactly what the new law strips out. The new rules still await formal implementation, expected later this year, and for now France's blocking runs the old, manual way.Here's the problem with all of this, if it's not obvious already. The cost falls on legitimate sites that share infrastructure with a targeted stream and on their visitors, cut off without notice and left to seek a reversal after the match is over.We only have to look to Spain to see what that level of overreach looks like at scale. In December 2024, Commercial Court No. 6 of Barcelona let LaLiga require Movistar, Vodafone and Orange to block IP addresses tied to unauthorized football streaming. The court upheld the order in March of 2025. For some time now, Spanish ISPs have blocked entire IP addresses rather than single domains, so any lawful site sharing an IP address with a stream goes offline too.Vercel reported two of its addresses, 66.33.60.129 and 76.76.21.142, blocked on matchdays, cutting off paying customers including the startup Tinybird and Hello Magazine.Cloudflare, GitHub Pages and BunnyCDN were caught the same way."In Spain, they block 10,000 pirate addresses on a single matchday, the equivalent of what we block in a year in France," said Sarah D'Arifat, legal director of BeIN Sports France, to FranceInfo.The takedown design comes from Italy. In a study delivered to the Assemblee nationale in December 2025, ARCOM recommended the automated real-time system and cited Italy's "Piracy Shield" as precedent. As we've previous reported, that system has knocked Cloudflare and countless unrelated sites offline, and European ISPs have since demanded that rights holders be held liable for the damage from overblocking.ARCOM originally kept the human review step because it considered overblocking potentially unconstitutional in France. But that review now happens after the block lands.One other change widens exactly who can pull the trigger. Foreign entities that organize or hold rights to competitions abroad can now bring blocking actions in French courts themselves, which opens the door to Spain's LaLiga and England's Premier League.This is a new overreaching takedown power devoid of due process that we'll need to track.

Australia Could Ask Court to Ban Telegram Nationwide
Favicon 
reclaimthenet.org

Australia Could Ask Court to Ban Telegram Nationwide

If you're tired of censorship and surveillance, subscribe to Reclaim The Net.Australia's "eSafety" Commissioner has opened the possibility of asking the Federal Court to ban Telegram across the country, as well as pushing the civil penalty proceedings her office filed against the messaging service over the last week.Australia's top censor, Julie Inman Grant, told the BBC that Australia does not license platforms, but "we could apply to the federal court and ask that the service be ceased." "We've never used those powers," she said. "We'll see how this all plays out and whether that kind of action is warranted."Telegram has more than a billion users worldwide and has both public messaging channels and personal messaging features. eSafety puts. A shutdown order would cut off those visits and the private conversations they carry.The pro-censorship regulator announced on July 30 that it had begun civil penalty proceedings against Telegram, alleging contraventions of section 146(1) of the Online Safety Act 2021 through failures under the Act's Relevant Electronic Services Standard. A breach carries penalties of up to A$54.6 million, around US$38 million.According to the court filing, Australian users complained to Telegram about twelve posts containing pro-terror content between July and October 2025.eSafety said that Telegram only removed two, leaving ten accounts remaining, along with the accounts behind them, with some material accessible for as long as three weeks.The regulator also alleged Telegram failed to detect the livestreamed 2019 Christchurch mosque shooting and footage of the May 2022 Buffalo supermarket attack, which it says stayed on the service for nearly three months.eSafety further alleges that Telegram failed to prevent distribution of the material. The filing also says the company did not maintain terms of service prohibiting pro-terror content on all parts of the platform and did not tell complainants what came of their reports."This case concerns content linked to some of the most notorious acts of known extremist violence in recent history," Inman Grant said.The regulator rejected industry codes for messaging and internet services in 2023, citing a failure to commit to proactive detection of material unlawful in Australia. Then it drafted its own. The Relevant Electronic Services Standard was registered on June 21, 2024 and took effect in December, 2024. It covers messaging, email, dating apps, and online gaming services and requires providers to prevent, detect, deter and disrupt material that fails to reach the standard set by the regulator.Telegram can host groups of up to 200,000 users and public channels with no subscriber ceiling. It also carries one-to-one chats, including an encrypted chat option, making Australia's demands to monitor and detect material across a service built that way would reach the private side as well as the public one.eSafety, which has made several erroneous points about end-to-end encryption in the past, still maintains that the requirements do not require companies to break end-to-end encryption. Its 2023 position statement on encryption described a situation in which a message leaving a user's device is checked by a dedicated server before it reaches the recipient. That's what is known as "Chat Control" in the EU and still involves a third party reading the message. Encryption explicitly exists to prevent third parties from reading messages.Telegram said it will fight the case. "Telegram's extensive anti-terrorism efforts are well documented," a spokesperson said. "We reject these allegations and will contest them in court." The company said it blocked 153,085 terrorist-related communities in 2026, that its moderators removed 200 million pieces of content, and that it works with the Global Center for Combating Extremist Ideology.

Minnesota Nudification Ban Takes Effect After Judge Denies xAI Restraining Order
Favicon 
reclaimthenet.org

Minnesota Nudification Ban Takes Effect After Judge Denies xAI Restraining Order

If you're tired of censorship and surveillance, subscribe to Reclaim The Net.Minnesota's ban on "nudification" tools, the first law of its kind in the United States, and one that is written so broadly it has major First Amendment violation concerns, took effect Saturday after U.S. District Judge Donovan Frank denied xAI's request for a temporary block.The company, which owns the X platform, sued Attorney General Keith Ellison on July 27 to stop enforcement of House File 1606, and Reclaim The Net covered the complaint when it was filed so you can get the full details in that story.xAI filed its request "on July 29, 2026, nearly three months after the law was signed, and only three days before the law is set to take effect," Judge Frank wrote, and he denied the restraining order based on that timing, rather than on the merits. "Such a delay in bringing the action and the motion suggests that harm is not immediate," Frank said.Thankfully, the company's First Amendment claims are still before the court; this weekend's ruling only settled the question of timing and urgency. Frank converted the emergency filing into a motion for a preliminary injunction to be heard at a later date this month.The law, formally codified as Minnesota Statutes section 325E.91, bans anyone who owns or runs a website, application, software, program or another service from allowing a user to "access, download, or use" it "to nudify an image or video." It also bans nudifying an image on a user's behalf, even with their consent. Going further into questionable constitutionality, advertising such a service is banned too.What's also interesting is that the prohibitions "do not apply" when a service "requires the technical skill of a user" to do the nudifying. That means Photoshopping someone in the nude stays legal. The ban is focused on the toolmaker and not the user who prompts the creation of such an image or spreads it.Ellison can seek civil penalties of up to $500,000 for each violation, and a person depicted can sue separately for triple damages, punitive damages and attorneys' fees."I am extremely proud to be defending this law, and along with it, the dignity of the people of Minnesota," Ellison said in comments reported by KSTP. "These nudification apps, including Grok Imagine, have been used to generate child sexual abuse materials and harass people in the vilest ways imaginable."Judge Frank directed both sides to arrange an agreement preserving the status quo so the motion can be heard on a regular schedule. After they failed to agree, he set one. Ellison must respond by August 12, xAI will reply by August 17, and the hearing is set for August 19 at the federal courthouse in St. Paul.

Senate Bill Would Put Age Checks in Every US Operating System
Favicon 
reclaimthenet.org

Senate Bill Would Put Age Checks in Every US Operating System

If you're tired of censorship and surveillance, subscribe to Reclaim The Net.A bipartisan bill just introduced would build an age check into the operating system of every phone and computer sold in America. The Digital Age Assurance Act of 2026, S. 5090, from Senators Andy Kim, Cynthia Lummis, Adam Schiff, and John Barrasso, takes California's age-signaling law and makes it the national standard.The bill was referred to the Senate Committee on Commerce, Science, and Transportation on July 22, 2026, and would take effect 18 months after enactment.We finally obtained a copy of the bill text for you here.With the proposals, an operating system cannot be used without an account, and the account requires the user to "indicate the date of birth and age of the user." For now, the user gets to declare their own age. A "covered device" is any computer, mobile device or other general-purpose computing device capable of running an operating system, so the requirement reaches practically everything. This is also backdated and accounts that already exist when the law takes effect are included.The operating provider may skip the prompt where it already knows the age of the user from some other obligation, including a purchase authorization.When a declaration is made into one of four brackets, under 13, 13 to 15, 16, or 17+. The system broadcasts only the bracket, which the bill defines as "non-personally identifiable data derived from a user's date of birth or age."Apps, app stores, and even browsers would have to have the ability to request that bracket and use it as "the primary indicator of a user's age." Some websites would be included in this too. A "covered internet website" is one already "required under Federal or State law to verify the age of a user," so the website obligations attach only where a state or federal age-verification mandate already exists.With the first use of the browser on a device, it would request a signal from the operating system, and then it hands that signal to covered website operators on request. But the bill does not say how. Under the proposals, a "browser provider" is anyone who "owns, maintains, or controls a browser for use on a covered device." No size threshold is attached. A small maintainer with a few thousand users would carry the same obligation as a big tech platform like Google.Anyone under 17, which is the bill’s definition of a "child," has to "link their account to the account of a parent or legal guardian.” The only exception is for emancipated minors. There’s no trusted adult option that can override this. A 16-year-old in an abusive household, or one researching a parent's conduct, has no route that does not run through the person they need distance from. It should be stated here that minors hold First Amendment rights of their own, something politicians often forget (or ignore) and Brown v. Entertainment Merchants Association (2011) is unfriendly to the idea that the state may deputize parental authority as a general instrument of speech control.There are other constitutional elements here too. Anonymous speech and anonymous reading are both protected, and this bill installs a declared-age checkpoint under both, all baked into the operating system. Adults would get bracketed too, as the architecture has to be built for the entire population in order to sort the minority who are minors.Section 4(b) turns the signal into a gate. It would now become unlawful to let a user access an application, or a feature of an application, or a covered website where the operator "has determined" that access would be inappropriate for a given bracket, and the operating system signal puts the user in that bracket. The legal standard is whatever the company wrote in its own policy, revisable at will. That would clearly be federal liability attached to privately authored content rules, and it ratchets. That means that any voluntary age-differentiated policy a platform chose to adopt now becomes federally enforceable against it. The rational response to all this would be to gate broadly and defensively, or to abandon granular age policies altogether.According to the bill, once an app or covered website has received a signal, it "shall be deemed to have actual knowledge of the age bracket data of such user across all platforms and points of access." The federal bill is generally modeled on California's Digital Age Assurance Act, written by Assemblymember Buffy Wicks, signed in October 2025 and coming into force on January 1, 2027. However, the two bills actually draw their brackets differently. California uses under 13, 13 to under 16, 16 to under 18, and 18 or older, so an adult there is anyone 18 or over. This is where the federal bill inserts its digital ID trick. The Senate bill stops at 17 and older, which files 17-year-olds in with adults. Most state access laws draw their line at 18. Therefore, the federal signal cannot distinguish a 17-year-old from an adult, and a covered website complying with an 18+ mandate would receive a signal that does not give it enough information to comply with the law. It will need something further, which routes straight back to conventional ID check verification.There is some lip service given to privacy in the bill. The bill bans developers, websites, and operating system creators from selling bracket data or sharing it with third parties. They may not use it "for profiling, engagement optimization, or targeted advertising," or combine it "with other personal or inferred information regarding a user."The Federal Trade Commission and state attorneys general would be tasked with enforcing the terms. Fines can go up to $2,500 for each negligent violation and $7,500 for each intentional one, multiplied by the number of children affected. There are no carve-outs for small entities, and no revenue threshold or user-count threshold. A lone individual maintaining a single small app is a "developer," and that exposure is the standard engine of collateral censorship.In her pitch for the bill, Lummis presented it as a privacy-safe option. "By keeping government IDs and facial scans out of the equation, the Digital Age Assurance Act gives parents real protection for their children," she said.Kim tied it to his own family, citing "a lot of anxiety about keeping my two boys safe from dangers online."The text does carry some of that promise, but we had to look through the details to see what's really going on. Section 10 says that nothing in the Act shall be construed to require "any person to verify the age of a user through" the collection of "a government-issued identification document, biometric information, or other sensitive personal information," or through "facial age estimation technology."Keep that in mind, however, because there are three provisions in the bill that go on to qualify this. Section 3(d) says that where an OS provider receives "clear and convincing information" that a user's real age differs from the bracket it is signaling, the provider "shall verify the age of the user." A corrected signal would then go to everyone who received the old one. The bill never actually says how that verification is to be performed, and Section 10 closes by disclaiming any requirement of "a particular technological method of generating, transmitting, or verifying a signal." What this is is a mandate to verify, with the methods left open. The bill is not a prohibition on ID checks and is still very much a big step toward them, regardless of what the bill's promoters like to say in their press releases. It is a clear instruction to find a way of doing something, issued alongside a promise that no particular way or doing it is being demanded.Secondly, the alternatives that would let a device prove the accuracy of a bracket without handing over the actual date are optional. Verifiable credentials and zero-knowledge proofs do appear in Section 3, but only "where technically feasible." They are permitted, not required, and the provider decides. Most providers are going to go for the easy option of ID checks.The third is all about structure. The assurance in Section 10(5) opens with the words "except as provided in sections 3, 4, and 5." Those three sections contain every operative requirement in the bill. The exception swallows the assurance it qualifies.In case it’s not clear, this all means that the front door is self-attestation of age, and backed by a safe harbor in Section 8(c) for providers acting in good faith when a user lies at signup. The privacy risk arrives later, in the escalation path, and Section 4(c) builds a mandated reporting channel into it. A developer that has "clear and convincing information" that a user's age differs from the self-attested signal legally must transmit that information upstream to the operating system provider, which triggers the verification duty. Clear and convincing, if you didn’t already know, is an evidentiary standard that has a settled meaning in court. But here, a private party applies it to its own inferences, with nothing in the text of the bill prohibiting behavioral profiling or content-based inference and no way for the user to contest the determination that their behavior contradicts the age-bracket signal before it escalates. Section 13 leaves the rest of the doors open. The Act preempts state law "only to the extent that such State law or regulation conflicts" with it, and it expressly preserves any state rule "at least as protective of individuals." This displaces nothing. The growing threat of state age-verification digital ID laws requiring document uploads or face scans survives intact, and are the very laws that define which websites the federal bill covers in the first place. What this bill builds is the national plumbing that actually makes the state verification regimes easy to enforce, then invites states to build on top of it.Even without a mandated ID upload, every user would have to give an age to the device at setup, and for users under 17 the device also records who supervises them.California's version of this bill has already drawn allegations that it is unconstitutional and the liability of this kind, up to $7,500 per affected child under the Senate bill, could push companies to verify ages rather than take a declaration at face value. That could be the hidden intention behind the bill, though. Verification of that kind requires documents and face scans, the system Lummis promised to keep out. It also holds sensitive data where it can leak.

Border Phone Security: What Works and What Backfires
Favicon 
reclaimthenet.org

Border Phone Security: What Works and What Backfires

What actually protects a phone at a border: encryption, BFU state, and preparation, not last-minute wiping.