MoreRSS

site iconAlec MuffettModify

Alec is a technologist, writer & security consultant who has worked in host and network security for more than 30 years, with 25 of those in industry.
Please copy the RSS to your reader, or quickly subscribe to:

Inoreader Feedly Follow Feedbin Local Reader

Rss preview of Blog of Alec Muffett

Investigation: UK spends millions on VPNs as government weighs ban for children | TechRadar

2026-03-23 22:13:42

“Since the publication of this investigation, the Department for Science, Innovation and Technology (DSIT) published a contract that shows it is spending nearly £50,000 on a survey to understand how children are using VPNs. Details have been added below.”

https://www.techradar.com/vpn/vpn-privacy-security/investigation-uk-spends-millions-on-vpns-as-government-weighs-ban-for-children

UK House of Lords seeks ban on Swiss Army Knives that “…could be used to cut people”

2026-03-22 16:17:07

“We are not against pen knives in principle”, says peer, “…but we want manufacturers to take steps to prevent them being used to cause harm.”


https://www.thebureauinvestigates.com/stories/2026-03-17/baroness-kidron-interview

Quote:

To “create” a chatbot or model that can “encourage” crime would be an offense punishable by 5 years imprisonment under amendments voted through (203 to 148) by the UK House of Lords.

This follows recommendations from the Center for Countering Digital Hate.

The imprecision in these proposals is appalling. Chatbots and language models can be goaded into saying bad things. When they’re used by billions of people, even the most cautious developers cannot exclude that risk. Criminalizing their development based on whether they generate any proscribed content (per sec. 1) is a garish attack on fundamental research and consumer technology.

Governments can uplevel AI safety in many ways, some of which are represented in this bill. But this kind of theatrical overreach is setting back meaningful reform.

This is absolute perfection: UBUNTU SECURE BOOT AGE VERIFICATION | Hacker.House

2026-03-21 04:41:04

Perfect commentary on nerds following authoritarianism because it is an interesting intellectual challenge:

Lawyer mocks Ofcom’s big fine with bigger hamster | RollOnFriday

2026-03-21 04:21:26

Apparently RollOnFriday is kind of “Slashdot meets HackerNews” for the UK legal community, and they are covering that Ofcom is being hamstered by 4chan.

Public ridicule amongst the legal community may actually be quite impactful, plus the article has some genuinely interesting background information which does not get much airtime.

https://www.rollonfriday.com/news-content/lawyer-mocks-ofcoms-big-fine-bigger-hamster

Ofcom accused of posting misinformation

2026-03-20 22:49:12

Let Me Explain How a State Actor Could Perform a Denial-of-Service Attack on the Entire UK Government in the Wake of Ofcom “Online Safety Act” Client-Side Scanning

2026-03-20 17:07:53

1/ obtain a hash of abuse material that’s both known & banned; if pervasive as claimed this shouldn’t be hard

2/ use algorithms from this paper to create a cat meme with the same hash

3/ send the cat meme to all MPs & Civil Servants via SMS, E-Mail, WhatsApp (bonus if it goes viral)

4/ watch as MPs are locked out & banned by platforms for possessing abusive material, preventing government


Also: there is no mitigation by saying “all of these cases should be appealed” because by the time enough resources have been deployed to resolve the appeal claims, government will have been offline for 12 hours or more.

Of course one could propose mitigations: the government could ex-ante inform all platform providers which accounts needed to be prevented from ever being blocked – to be given special treatment – however:

  1. Politically that will not fly well, and…
  2. It will immediately cast doubt upon any politician who has an unacknowledged backup social media profile, which will be visible to the platforms of course because of device cookie sharing and things like that, so…
  3. Such information will be a topic of extortion or leaks

Also, there will be claims of “two-tier surveillance” and so forth.

White-Box Attacks on PhotoDNA Perceptual Hash Function

https://eprint.iacr.org/2026/486

[*] note: strictly, it is not necessary to obtain the material, merely the hash; therefore a leak of the existing database of hashes – several million in size – would be catastrophic by providing material for an infinite sequence of attacks like this.