Visualização de leitura

Spyware for Babies

The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.

Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech and language development, motor skills and more, while extending its presence in children’s bedrooms into early adolescence.

Meta ordered to pay $942 million over harm to children

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.

Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.

Meta said it disagreed with the ruling and planned to appeal.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:

  • Develop an under-13 prediction model within two years.
  • Seek proof of age from users it estimates are under 13.
  • Treat uncertain accounts as belonging to minors until their age is verified.
  • Delete personal data collected from under-13 users.

The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.

This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.

From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts. 


Safer. Cleaner. Ad-free browsing.


How to keep your children safe

In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).

Some tips for parents:

  • Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
  • Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
  • Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
  • Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
  • Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
  • Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.

The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Meta ordered to pay $942 million over harm to children

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.

Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.

Meta said it disagreed with the ruling and planned to appeal.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:

  • Develop an under-13 prediction model within two years.
  • Seek proof of age from users it estimates are under 13.
  • Treat uncertain accounts as belonging to minors until their age is verified.
  • Delete personal data collected from under-13 users.

The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.

This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.

From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts. 


Safer. Cleaner. Ad-free browsing.


How to keep your children safe

In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).

Some tips for parents:

  • Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
  • Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
  • Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
  • Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
  • Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
  • Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.

The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

TikTok, YouTube, and Roblox face scrutiny, but age gates won’t fix child safety

A damaging new report from Ofcom, the UK’s communications regulator, has delivered a stark verdict: TikTok and YouTube’s content feeds are “not safe enough” for children. This isn’t just another regulatory slap on the wrist. Ofcom is putting out a wake-up call for anyone working in cybersecurity, threat intelligence, and online safety.

In its own words:

“Notably, TikTok and YouTube failed to commit to any significant changes to reduce harmful content being served to children, maintaining their feeds are already safe for children.”

On the positive side, Snap, Meta, and Roblox agreed to adopt further safety measures to protect children from online grooming and “stranger danger.”

The BBC reports that an Ofcom survey found 84% of children aged 8 to 12 were still using at least one major service with a minimum age of 13. We reported earlier about how easy it was to fool some of the age verification methods. Researchers using under-13 accounts also reported encountering sexual content and offensive language shortly after entering specific Roblox games.

Speaking of Roblox, The Guardian reports that US advocacy groups have formally requested the Federal Trade Commission (FTC) investigate Roblox for what they call “unfair and deceptive” practices. The complaint focuses on:

  • In-game purchases pressuring children to spend money
  • Chat functionality exposing children to strangers
  • Features designed to maximize engagement, which critics argue may be addictive

Drew Benvie, CEO of Battenhall and founder of youth safety nonprofit Raise, noted:

 “Although Roblox is implementing new age-based safety measures, young players are adept at circumventing these protections.”

The cybersecurity point of view

What keeps cybersecurity researchers up at night is another angle to this problem. Many proposed age assurance solutions require users to hand over government IDs or biometric selfie data. We already talked about this in our blog, Age verification: Child protection or privacy risk?

Age verification systems create massive data collection opportunities that become prime targets for:

  • Data breaches exposing sensitive personally identifiable information (PII)
  • Identity theft facilitated by centralized ID databases
  • Biometric data theft, which cannot be changed like passwords
  • Malware and scams targeting users on less-secure platforms

When restrictions push young users toward smaller or less secure sites, they encounter:

  • No basic safety protections
  • Higher exposure to malware
  • Increased phishing and scam risks
  • Unmoderated harmful content

This is exactly what we see in threat intelligence: As defenders secure one vector, cybercriminals adapt and move elsewhere.

Safer systems beat stricter age gates

Protecting children should focus on building safer digital experiences overall. This is the only viable path forward because:

  • Stronger moderation actually removes harmful content rather than just blocking access
  • Safer recommendation systems prevent algorithmic amplification of harmful content
  • Better platform accountability means companies can’t prioritize engagement over safety
  • Avoiding invasive data collection prevents creating massive honeypots for attackers

As someone who analyzes malware and threats daily, I can tell you: security through obscurity (age gates) doesn’t work. Security through robust system design (moderation, safer algorithms, accountability) does.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

New Mexico’s Meta Ruling and Encryption

Mike Masnick points out that the recent New Mexico court ruling against Meta has some bad implications for end-to-end encryption, and security in general:

If the “design choices create liability” framework seems worrying in the abstract, the New Mexico case provides a concrete example of where it leads in practice.

One of the key pieces of evidence the New Mexico attorney general used against Meta was the company’s 2023 decision to add end-to-end encryption to Facebook Messenger. The argument went like this: predators used Messenger to groom minors and exchange child sexual abuse material. By encrypting those messages, Meta made it harder for law enforcement to access evidence of those crimes. Therefore, the encryption was a design choice that enabled harm.

The state is now seeking court-mandated changes including “protecting minors from encrypted communications that shield bad actors.”

Yes, the end result of the New Mexico ruling might be that Meta is ordered to make everyone’s communications less secure. That should be terrifying to everyone. Even those cheering on the verdict.

End-to-end encryption protects billions of people from surveillance, data breaches, authoritarian governments, stalkers, and domestic abusers. It’s one of the most important privacy and security tools ordinary people have. Every major security expert and civil liberties organization in the world has argued for stronger encryption, not weaker.

But under the “design liability” theory, implementing encryption becomes evidence of negligence, because a small number of bad actors also use encrypted communications. The logic applies to literally every communication tool ever invented. Predators also use the postal service, telephones, and in-person conversation. The encryption itself harms no one. Like infinite scroll and autoplay, it is inert without the choices of bad actors ­- choices made by people, not by the platform’s design.

The incentive this creates goes far beyond encryption, and it’s bad. If any product improvement that protects the majority of users can be held against you because a tiny fraction of bad actors exploit it, companies will simply stop making those improvements. Why add encryption if it becomes Exhibit A in a future lawsuit? Why implement any privacy-protective feature if a plaintiff’s lawyer will characterize it as “shielding bad actors”?

And it gets worse. Some of the most damaging evidence in both trials came from internal company documents where employees raised concerns about safety risks and discussed tradeoffs. These were played up in the media (and the courtroom) as “smoking guns.” But that means no company is going to allow anyone to raise concerns ever again. That’s very, very bad.

In a sane legal environment, you want companies to have these internal debates. You want engineers and safety teams to flag potential risks, wrestle with difficult tradeoffs, and document their reasoning. But when those good-faith deliberations become plaintiff’s exhibits presented to a jury as proof that “they knew and did it anyway,” the rational corporate response is to stop putting anything in writing. Stop doing risk assessments. Stop asking hard questions internally.

The lesson every general counsel in Silicon Valley is learning right now: ignorance is safer than inquiry. That makes everyone less safe, not more.

The essay has a lot more: about Section 230, about competition in this space, about the myopic nature of the ruling. Go read it.

Hackers reportedly steal pictures of 8,000 children from Kido nursery chain

Firm, which has 18 sites around London and more in US, India and China, has received ransom demand, say reports

The names, pictures and addresses of about 8,000 children have reportedly been stolen from the Kido nursery chain by a gang of cybercriminals.

The criminals have demanded a ransom from the company – which has 18 sites around London, with more in the US, India and China – according to the BBC.

Continue reading...

© Photograph: solarseven/Getty Images/iStockphoto

© Photograph: solarseven/Getty Images/iStockphoto

© Photograph: solarseven/Getty Images/iStockphoto

‘Hacking is assumed now’: experts raise the alarm about added risk of surveillance cameras in childcare centres

As governments consider mandatory CCTV in early education, one big provider with cameras already installed is yet to formalise guidelines for how the footage will be stored and used

In the wake of horrifying reports last week alleging that eight children had been sexually abused by a worker in a Melbourne childcare centre, politicians and providers have scrambled to offer a response.

One option emerged from the fray as something concrete and immediate: the installation of CCTV cameras in childcare centres.

Sign up for Guardian Australia’s breaking news email

Continue reading...

© Composite: Getty

© Composite: Getty

© Composite: Getty

❌