Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

Prove You're Allowed to Run This

In eight days this July, a US state, the European Commission, Google, and Britain's regulators each wired the same demand into the device, the app store, and the network: prove, cryptographically, that you're permitted. A Supreme Court order let Texas turn the app store into an age checkpoint. An EU app that proves your age without revealing your name refuses to run on the most private phones. Google set a date to make writing software a verified-identity privilege. And the tools built to answer *none of your business* — de-Googled phones, sideloading, no-log VPNs — were named the same fortnight as the next things to close, while half a world away censors stopped blocking protocols and started fingerprinting the servers that carry them. No one coordinated it. That is the part that should worry you.

The app that won't run

Picture the most privacy-conscious person you know. They run GrapheneOS, the de-Googled Android favored by security researchers and by people with real reasons to be careful — domestic-violence survivors, journalists, dissidents. This summer the European Union is offering them an age-verification app that is, by design, genuinely good: open-source, built on zero-knowledge proofs, able to prove "over 18" without disclosing a birthdate, a name, or anything else — the thing privacy advocates spent a decade asking for instead of passport uploads. And it will refuse to run on their phone. Not because their phone is insecure. Because it is not blessed by Google.

That refusal is the whole story of the past two weeks, and it is not really about children. Underneath the age checks and the app-store fights and the developer rules is a single demand: prove you're allowed to run this. Prove your device is genuine. Prove your age. Prove the software's author has a legal name on file. The technical word for the demand is attestation — a trusted third party, in practice Apple or Google, vouching cryptographically to any app, website, or regulator that asks. The two companies spent years building this vouching layer into the operating system itself. In one fortnight this July, three classes of gatekeeper reached for it at once, and two more named the way around it as the next target.

Jaw one: the checkpoint

The app store. On July 6, the US Supreme Court, on its emergency docket — two brief unsigned orders, no noted dissents — let Texas's App Store Accountability Act stand, enforceable since the Fifth Circuit lifted a district-court injunction on June 4. Apple and Google must now verify every user's age at account creation, sort each person into one of four brackets, and route every under-18 download through a verified parent — for all apps, not just adult ones. And look at how: Apple's Declared Age Range API, introduced in iOS 26, and Google's Play Age Signals API make the operating system itself vouch for your age to every app that asks. The law does not make the porn site check your ID. It makes the device the oracle.

The private phone. The EU age-verification app is designed to require Google's Play Integrity and Apple's App Attest to confirm the device before it will run — so, as technical write-ups noted when the pilots appeared, it "would not work on GrapheneOS or any other non-Google-approved Android ROM," nor even if you compiled the identical code yourself, because it did not arrive from the Play Store. The Commission that fines Google under the Digital Markets Act is conscripting Google's attestation as identity infrastructure. The app is a non-binding recommendation, with pilots in Denmark, France, Greece, Italy, and Spain and a suggested rollout by December 31 — but the design decision is already made.

Your own code. Google's Android Developer Verification will require every developer to register a legal identity before their software may install on a certified device; enforcement begins September 30 in Brazil, Indonesia, Singapore, and Thailand, and expands from there. On July 1, F-Droid — the flagship free-software app store — called the dormant enforcement client, already shipped as a system service on modern Android, "a virus … silently awaiting remote activation," and warned the rule would end its project, because it distributes apps from pseudonymous contributors who will not hand Google a government ID. On July 9 it shipped its own answer, a free-software verifier called AppVerifier.

This is not a summer phase. It is being written into permanent law. California's AB 1043, signed last October, will from January 1, 2027 require every operating-system provider — Apple, Google, and, on its face, desktop Linux and Valve's SteamOS — to collect your age at device setup and broadcast an age-bracket signal to any app that requests it. The device stops merely running your software. It starts reporting on you to it.

Jaw two: the escape hatches, named

Gate the device and the store, and people route around them. The past two weeks show what the state reaches for next.

Britain. Mandatory age assurance for adult sites went live on July 25, 2025; its one-year mark falls this month, with Ofcom's first statutory effectiveness report due before the end of July. The measurable result of year one was migration, not safety: on day one, Proton VPN reported UK sign-ups up more than 1,400 percent hour-over-hour and over 1,800 percent day-over-day, and VPN apps took half of the UK App Store's free top ten. "We would normally associate these large spikes in sign-ups with major civil unrest," Proton told the Financial Times. The official response was not to reconsider the wall but to eye the ladder: England's Children's Commissioner called the VPN surge "a loophole that needs closing" and urged age checks on VPNs; a government consultation this spring put the idea formally on the table.

Here is the fact that should have ended the conversation. The surge was adults, not the children the law targets. Ofcom's own guidance notes only about one in ten VPN users is a child; two independent surveys — Internet Matters, polling a thousand children last December, and Childnet — found no rise in children's VPN use at all. So age-gating VPNs would ID-check millions of adults to close a loophole the children were never using. It is the first wall's category error, one layer down.

Brussels. After the Chat Control fight, the Commission's next route into private data is mandatory retention. Its "Going Dark" data-retention instrument — expected around mid-2026 and, as of this writing, not yet tabled — would, according to a leaked Council document from last November, require connection metadata to be logged by every online service, VPN providers explicitly named, for a year or more. And here the demand meets a wall of its own making: a genuine no-log VPN has nothing to hand over, because it was built to keep nothing. Mullvad, the Swedish provider, says it will not log whatever the final text says — which, once the instrument reclassifies it, would make a no-log VPN effectively illegal in Europe. An order to retain is an order to stop existing. Route around the gate, and the route becomes the next gate.

The same fortnight, one layer down

Close the identity gate and there is still the network — the raw ability to move a packet to a server that isn't blocked. That gate was being rebuilt the same fortnight, by a different hand, in a different hemisphere.

On June 10, an engineer in Iran did everything the manuals say. He put his tunnel behind Cloudflare and shredded the opening handshake into fragments of ten to thirty bytes so the censor's inspection box would never see the forbidden domain name whole. The domain was dead within a day anyway. Iran's deep-packet inspection had been upgraded to perform full TCP reassembly — it holds the fragments in memory, waits, and reassembles the sentence before it reads it, nullifying the single cheapest circumvention trick in nearly every tool. In Russia, between June 1 and 15, Roskomnadzor knocked out more than ninety percent of Amnezia VPN's servers inside the country, per TechRadar — not by banning a protocol but by fingerprinting each server's signature and flooding it, then flooding Amnezia's own infrastructure until, the company said, it could no longer publish its numbers because the attack had disabled the very tool it uses to measure censorship. The censor blinded the witness.

The inflection, stated plainly: a protocol is an idea, and you cannot enumerate an idea; a server is a machine with an address, and you can. Once the target is the fixed, findable server, a well-funded state grinds through your address list faster than you can replace it. And in a seventy-two-hour window this month the open-source field answered with one design: on July 10, OpenRung — "Snowflake for the whole device," volunteer relays reached through a broker that never carries traffic, with a cryptographically signed relay list the censor cannot poison; on July 11, an Android client, Orden, carrying two protocols at once and switching the instant one is throttled; on July 12, the field's peer-reviewed censorship research published ahead of the FOCI and PETS symposia — including analysis of the leaked toolkit that packages China's Great Firewall as a product and sells it to Myanmar, Pakistan, Kazakhstan, and Ethiopia. The offense is sold as a service the same week the defense is peer-reviewed in the open. Two hands, one door: the law names the escape hatches while packet inspection physically closes them.

The steelman, at full strength

Take the other side at its strongest, because it is strong. Children really do reach hardcore pornography in two taps, and the app store really is where the phone is provisioned — so it is a defensible control point, not a self-evident overreach. The defenders are not a fringe: child-safety coalitions filed briefs urging the courts to let the Texas law stand, and the Fifth Circuit did not wave it through — it held that Texas "made a strong showing that it is likely to succeed on the merits," that the statute "more likely governs commercial speech" subject only to a reasonable fit. The EU app's zero-knowledge proofs are, on their own terms, a real privacy upgrade over uploading a passport to a porn site. Google's malware case is real too: it reports that internet-sideloaded software carries more than fifty times the Play Store's infection rate, and that anonymous, disposable developer identities are exactly what let a caught malware author rebrand and ship again by morning. On the network side the same realism applies: obfuscation has always been a tax every protocol pays, the censor adapts in days — Russia fingerprinted Tor's Snowflake transport overnight in March — and scattering exits across residential devices pushes the abuse complaint onto some volunteer's home connection, where the police arrive. And these measures were written by different legislators, in different capitals, for different reasons, on different clocks. There is no memo. Seeing one coordinated enclosure in five unrelated safety laws is exactly the pattern a careful reader should distrust.

The rebuttal that survives it

Start with the phone, because it collapses the security story cleanly. GrapheneOS is excluded not because it is less secure but because it is not Google's. The project points out — and this is independently verifiable in its own documentation — that the standard Android hardware-attestation API "provides a much stronger form of attestation than the Play Integrity API," able to whitelist an alternate system's keys, and that "the only reason [Google isn't] permitting it is because we do not license Google Mobile Services … enforcing Google's business interests rather than security." A stronger, more open attestation fails the test on purpose. So the gate is not asking whether your device is safe. It is asking whether it is blessed.

The malware story fractures the same way. Developer Verification inspects no line of code and stops no verified developer from shipping something hostile; it is an identity-and-revocation mechanism, not a scanner. And the tell is in the pricing: the paid tier costs $25 and a government ID, but the free tier asks for no ID at all — and caps you at roughly twenty devices. The thing being metered is not money. It is anonymity at scale — enough to test among friends, never enough to reach the public without a name on file.

Then the "no coordination" point, which is true, which we concede, and which makes the situation worse rather than better. You do not need a memo to get an enclosure. You need a convenient primitive and a lot of gatekeepers. Once the operating system will vouch for the device, the user's age, and the developer's identity, every authority that wants a checkpoint reaches for the same layer, because it is right there and it works. The result is not a plot; it is a gravitational collapse toward the chokepoint — and it is harder to stop than a conspiracy, because there is no single bill to defeat and no one who can be held responsible for the sum. Each law is individually defensible. The system they add up to is what no one signed.

The network layer answers its own steelman the same way. The claim was never that shaping wins the arms race; it is that shaping plus diversity changes the censor's arithmetic. Fingerprint-and-flood is devastating against a few hundred fixed servers — which is why ninety percent of Amnezia's fell — and nearly useless against millions of residential addresses that look like ordinary consumers and cannot be flooded without taking down the consumer internet the state itself runs on. Russia's June attack presupposes a server to hunt; remove the fixed server and you remove what the attack was built for.

And that is the tell that unifies both jaws. Nothing on the steelman's list — a checked age, a caught malware author, a served warrant — requires excluding GrapheneOS, ending F-Droid, outlawing a no-log VPN, or fingerprinting a residential relay. Those tools are named because they defeat the checkpoint, not the safety goal. They are the residue the gate cannot process: the devices, authors, and connections that have no central party to vouch for them. An enclosure is defined by what it fences out.

What we know, and what we don't

Keep the ledger honest, because the pattern's strength is in its restraint. Enforceable today: the Texas law (one state, on appeal, with a Fifth Circuit merits hearing due in August), Britain's age-check regime, Google's Developer Verification date of September 30, and — from 2027 — California's OS-level age signal. A non-binding recommendation with live pilots: the EU age app, whose GrapheneOS exclusion is as much published design as shipped fact, and which its vendor called "premature panic" a year ago. A proposal not yet tabled: the EU's VPN-naming data retention. Pure advocacy so far, not law: the UK push to age-check VPNs. And days-old, tiny-network, forum-first: OpenRung and Orden, whose promise is real and whose scale is unproven. No one has proven coordination, because there is none to prove. What is documented is narrower and stranger — five gatekeepers, independently, reaching for the same primitive and naming the same escape hatches in the same fortnight, while packet inspection closed them from the other side.

What you can actually do

The un-vouchable still works today, and using it is the argument. GrapheneOS installs without an account or an ID, and its maintainers say it will stay that way; F-Droid shipped AppVerifier on July 9; keep a phone that can still sideload, because that capability is exactly what September 30 is built to lower. Carry more than one transport, the way Orden does, so a throttle is a shrug and not a blackout; update your circumvention client and do not resent the forced upgrades, because the stateless tricks inside the old ones are the ones dying this month; and run a measurement probe — OONI shipped a desktop app on July 6 — because the maps of what is blocked are built from users who volunteer the data.

The rest is political, and the levers are live. The Fifth Circuit hears the Texas law on the merits in August. The EU retention proposal is still being drafted, and a decade of Court of Justice rulings against "general and indiscriminate" retention is waiting for it. Google's rollout is a policy, not a statute, and more than seventy organizations across twenty-three countries are already on record against it.

The trust you don't have to place

The deepest answer is the one this journal keeps arriving at from every direction. Attestation is a way of placing trust in a central party — Google, Apple, a VPN that could be ordered to log, a server that sits still long enough to be fingerprinted — and hoping it stays trustworthy, or stays up. The alternative is not a better gatekeeper. It is architecture that removes the need for one: onion routing, WireGuard, decentralized relays and mixnets like URnetwork, where no operator holds the identity to vouch for you, none can be compelled to log you, and there is no fixed fleet of servers to enumerate. State the honest limit plainly — no VPN hides your face from a station camera, and no amount of decentralization conjures a signal when a government pulls the plug on the whole network, as Iran did in January. Within those limits, the property that this fortnight cannot fence is the one worth building on: you cannot attest what has no gate, and you cannot fingerprint what has no fixed server. Build the network so that "prove you're allowed to run this" has no one left to ask.


References (6 sources)

References

  • SCOTUSblog and NPR, "Supreme Court allows Texas to enforce app-store age-verification and parental-consent law" (July 6, 2026); CCIA v. Paxton — Fifth Circuit stay of the district injunction granted June 4, 2026; App Store Accountability Act (SB 2420), statutory effective date January 1, 2026; W.D. Tex. injunction (Judge Robert Pitman) December 2025; merits argument set for August 2026.
  • Apple Developer, "Update on age requirements for apps distributed in Texas" (Declared Age Range API, iOS 26; four age brackets); Google Play Console Help, "Changes to Google Play for upcoming app-store laws" (Play Age Signals API).
  • California Legislature, AB 1043 (Digital Age Assurance Act), signed October 2025, effective January 1, 2027 (operating-system age signal; applies to all OS providers) — leginfo.legislature.ca.gov; Tom's Hardware coverage noting Linux/SteamOS exposure.
  • European Commission, "Commission recommends rollout of the age-verification app" (April 29, 2026; non-binding; suggested deployment by December 31, 2026; pilots DK/FR/GR/IT/ES); OSnews and ppc.land, "EU age-verification app requires a Google/Apple-approved device" (July 2025); Biometric Update, Scytales response ("Play Integrity one of the methods; premature panic," July 2025).
  • GrapheneOS, "Attestation compatibility guide" (hardware attestation stronger than Play Integrity; exclusion driven by Google Mobile Services licensing, "not security").
  • F-Droid, "What We Talk About When We Talk About Malware" (Marc Prud'hommeaux, July 1, 2026; "a virus … silently awaiting remote activation"); F-Droid, "This Week in F-Droid," AppVerifier (July 9, 2026); Google, Android Developers Blog, "Android developer verification" (March 2026; >50× sideload-malware claim; $25 + government ID; free limited-distribution tier, ~20 devices, no ID; enforcement September 30 in BR/ID/SG/TH); open letter of 70+ organizations across 23 countries (EFF, ACLU, FSF, Tor, Proton, LineageOS).
  • TechRadar and the Financial Times, UK VPN surge after age assurance (Proton +1,400% hourly / +1,800% daily; "civil unrest" quote; live July 25, 2025); Ofcom age-assurance guidance ("about one in ten VPN users is a child"); Internet Matters (December 2025, n≈1,000) and Childnet on no rise in children's VPN use; Technadu, Children's Commissioner "loophole that needs closing" / VPN age-check call; Ofcom effectiveness report due end of July 2026.
  • TechRadar, "EU prepares ground for wider data retention — VPN providers among the targets"; heise, "Data retention proposal expected by mid-2026" (not tabled as of mid-July); leaked Council document (November 2025) naming VPN providers and ~12-month retention; Mullvad (no-log policy); CJEU line against general and indiscriminate retention (Digital Rights Ireland 2014; Tele2 2016; La Quadrature du Net 2020).
  • Convergence (network layer): net4people/bbs #628 (Iran full-TCP-reassembly, June 10, 2026) and FOCI 2026 Iran-shutdown analysis; TechRadar and Meduza on the Roskomnadzor offensive against Amnezia (>90% of Russian servers, June 2026; measurement tool disabled); AmneziaWG 2.0 traffic-shaping (shipped ~March 25, 2026); net4people/bbs #634 (OpenRung, July 10) and #635 (Orden, July 11); Tor Project, Arti 2.5.0 with Counter Galois Onion stable (June 30, 2026); petsymposium.org/foci/2026 proceedings (public ~July 12; Russia QUIC-SNI censorship; "Geedge Cases" — Great-Firewall toolkit exported to Myanmar/Pakistan/Kazakhstan/Ethiopia); OONI Probe desktop app (July 6, 2026).

Further Discussion

There Is No Memo

**Position.** Take the strongest version of the case *for* the gates, because it is real and the privacy reflex is not automatically the wise one. Children reach hardcore pornography in two taps, and the app store is where the phone is provisioned — so it is a defensible control point, not a self-evident overreach. The people defending these measures are not a fringe: child-safety coalitions filed briefs urging the courts to let Texas's app-store age law stand, and the Fifth Circuit didn't wave it through — it found Texas "made a strong showing" the law is likely constitutional as commercial-speech regulation. On the merits, each measure holds up better than the outrage admits. The EU's age app uses zero-knowledge proofs to prove "over 18" without a name or a birthdate — a genuine privacy *upgrade* over uploading your passport to a porn site, and exactly what advocates asked for. Google's own data shows internet-sideloaded apps carry more than fifty times the malware rate of the Play Store, and the *free, no-ID, twenty-device* developer tier is proof the program is about accountability, not harvesting identities or collecting $25. And on the network side, obfuscation was always a permanent tax every protocol pays — Russia fingerprinted Tor's Snowflake overnight — while scattering VPN exits across strangers' home connections just moves the police knock to a volunteer's door. The decisive point is the one the conspiracy read can't answer: these laws were written by different legislators, in different capitals, for different reasons, on different clocks. **There is no memo.** Reading a single coordinated enclosure into five unrelated safety and anti-malware measures is precisely the apophenia a careful person should distrust. A privacy movement that cries "enclosure" at every child-safety bill will be in the room for none of them. **Headline candidates.** - There Is No Memo · Five Laws, Five Capitals, and the Pattern That Isn't There - The App Store Really Is Where the Phone Is Provisioned - Zero-Knowledge Age Proofs Are the Privacy Win You Asked For - Prove Your Outrage Is Proportionate **Kicker.** Five gatekeepers, five clocks, no coordination. Kids reach hardcore porn in two taps; the Fifth Circuit found Texas likely to win; the EU's age check reveals *nothing* about you; sideloaded apps carry 50× the malware. Call five defensible safety laws a civilizational conspiracy and you'll be trusted to shape none of them. The overreach might be yours.

They Named the Exits

**Position.** Now read the same fortnight for what the architecture — not the intent — reveals. Five independent gatekeepers reached, in eight days, for the *same* technical primitive: the operating system as a cryptographic vouching authority for your device, your age, and your software's author. A US Supreme Court order (July 6) let Texas turn the app store into an age checkpoint; an EU app that proves your age without your name refuses to run on de-Googled phones; Google set September 30 to make writing software a verified-identity privilege; California wired an OS-level age signal into every device from 2027. You don't need a memo to get an enclosure — you need a convenient primitive and a lot of gatekeepers, and the result is *harder* to stop than a plot, because there's no single bill to defeat and no one accountable for the sum. The security justification collapses on inspection: GrapheneOS ships a *stronger, more open* attestation and is excluded anyway — for Google-Mobile-Services licensing, in the project's own words "not security." The gate checks *blessed by Google*, not *secure*. The metered good is anonymity itself: drop the government ID and you're capped at twenty devices — enough to test, never enough to reach the public. And watch what they named next: the escape hatches. Britain's age wall drove a **1,400 percent** VPN surge — adults, not the kids it targeted, since only one in ten VPN users is a child — so the state now eyes age-checking VPNs; Brussels's coming data-retention rule names VPN providers outright, an order to log that a no-log network can only answer by ceasing to exist. And the same fortnight the *law* named the exits, *packet inspection* was physically closing them — Russia fingerprinting more than ninety percent of one VPN's servers, Iran reassembling the shredded stream to kill client-side evasion. Prove you're allowed to run this, on a device we blessed, written by an author we can name, over a network with no exit we can't enumerate. That is a red line, whatever each measure's individual merit — and the only thing it cannot fence is infrastructure with no one left to ask: *you cannot attest what has no gate, and you cannot fingerprint what has no fixed server.* **Headline candidates.** - They Named the Exits · How to Read Five "Unrelated" Laws - Blessed, Not Secure · The One Fact That Collapses the Safety Story - Anonymity, Metered · Drop the ID, Get Twenty Devices - You Cannot Attest What Has No Gate **Kicker.** Five gatekeepers, one primitive, one fortnight — and they named the same exits: de-Googled phones, sideloading, no-log VPNs. GrapheneOS offers a *stronger* attestation and is banned anyway — "not security," their words: the gate checks *blessed*, not *secure*. Drop the ID, you're capped at 20 devices. While the law named the exits, packet inspection closed them. The counter isn't a setting — it's building a network with no gate to ask and no server to fingerprint.

Comics

#1There Is No Memo
#2They Named the Exits