EFF
European Court: Apple Can Not Shirk Off its Interoperability Requirements
One of the best bulwarks against monopoly is interoperability—that is making a new product or service work with an existing product or service. Interoperability allows users, and not the manufacturers of their devices or largest player in a market, to decide what application best serves them. Unsurprisingly, companies like Apple have worked hard to resist interoperability requirements.
On July 8, the General Court of the European Union (General Court) ruled against Apple in several cases the company brought against the European Commission (joint cases), affirming the company’s obligations under the Digital Markets Act (DMA). Apple argued in the cases that it should be exempted from the law’s requirements especially with regards to interoperability on multiple grounds. We applaud the General Court’s decision, and congratulate the Free Software Foundation Europe (FSFE) as well as others who intervened in support of the Commission against Apple's attempt to shirk off its responsibilities, thus ensuring fair competition in European markets.
A Positive Development for EuropeansThis is a clear and substantive win for developers and users in Europe. The stranglehold Apple exerts over its ‘walled garden’ is injurious for developers, users, and researchers alike. By confirming Apple’s obligations under the DMA, the General Court has ensured that developers will be given more choice on where they can publish their apps, and users will have more options to obtain apps which, for whatever reason, Apple dislikes. And researchers will have less roadblocks and hurdles to overcome in their studies of Apple’s OSes, particularly iOS, iPadOS, and watchOS.
Apple argues that the interoperability requirements will force it to lower the security standards that have led Apple products’ users to trust their devices. While this self-serving logic is not entirely without merit, it is far from the inevitable outcome. Especially with regards to the App Store, users can be given clear, informed choice when leaving the Apple ecosystem to obtain apps elsewhere. While we urge European courts to take Apple’s security concerns seriously, we’ve previously noted that this should not be used as a smokescreen to protect anticompetitive behavior.
Interoperability and security are not inherently at odds. When interoperable functionality is worked into the security model of a platform from the ground-up, a proper balance can be struck between two forces that are often falsely framed as naturally conflicting. While Apple OS platforms have not been built this way from the get-go, it is still possible, but takes more time to get it right. Here, the devil is in the implementation details.
Apple’s Case Arguments and the Court’s RebuttalUnder the DMA, designation as a ‘gatekeeper’ is reserved for the biggest of Big Tech, companies that provide services deemed essential for businesses to reach end users. Apple is one of only seven companies that meet this designation, along with Alphabet, Amazon, Booking, ByteDance, Meta, and Microsoft. In its case, Apple argued that Article 6(7) of the DMA, specifying interoperability requirements for gatekeepers aimed at restoring fair competition, is unlawful in light of the Charter of Fundamental Rights of the European Union (specifically the right to property), and as such its designation as a gatekeeper subject to the requirements is unlawful and should be annulled as a result. In its ruling, the General Court rejected the argument as Article 6(7) does not form the legal basis of the designation.
Apple separately argues that the App Store fails to meet the requirements defining a core platform service (CPS), since the various stores (across iOS, iPadOS, watchOS, macOS) do not constitute a single platform. A company’s gatekeeper status relies on it providing a CPS that is an important gateway for business users to reach end users. Here, the implications of the argument are clear: remove service designation as CPSes, remove the gatekeeper status. The court rejected the argument on the basis that “irrespective of the device on which it was available, each of the App Stores was used for the same purpose, namely to intermediate between end users and business users in the distribution of applications and in-app digital content.”
Finally, the court rejected as inadmissible Apple’s argument that iMessage should not be classified as a number-independent interpersonal communication service (NIICS) constituting a CPS. This decision rested on the fact that the “classification does not, by itself, produce binding legal effects that bring about a change in Apple’s legal position” since iMessage was not listed as an “important gateway” in the designation decision and therefore was not subject to the DMA obligations.
In ruling against Apple in favor of the European Commission, the General Court has set an important precedent in ensuring competitive fairness and openness in the digital marketplace. The landmark effects of the DMA will serve to benefit all Europeans in the choice and freedom it affords them. Despite Big Tech’s legal challenges, these decisions build a strong foundation for a better digital future—a lesson which other regions should learn from and take note.
Don’t Repeat NY’s 3D Printing Blunder
This year the state of New York had the dubious honor of being the first to pass a controversial provision to mandate all 3D printers come with surveillance and censorship. That means not only is there a ticking clock to protect every artist, researcher, engineer, and hobbyist in the state, but there is a real risk of other states thoughtlessly following suit—prior to the New York rules even taking effect.
We, along with many other experts, already warned about this bill buried in the state’s crowded budget process. Hundreds of our supporters and 3D printing enthusiasts in New York reached out to their representatives hoping to kill this farcical bill. While there were some welcome amendments in response to the outcry, Albany passed it anyway.
It might be well-intentioned, but bills like these sell a fantasy that can only have an untold negative impact on the privacy, free expression, and consumer rights of anyone using these general purpose devices. Behind the banner of reducing gun violence, which is nearly always committed with commercial firearms, New York lawmakers have passed draconian legislation that will let manufacturers lock in users and collect their data.
Now that the bill has passed and been signed by Governor Hochul, let’s look at two important ways the final legislation changed since we last wrote about it, and why states like California shouldn’t make the same mistake.
Reduced Risk for Lawful File SharingThe New York bill includes language that criminalizes access to firearm print files, a proposal correctly dropped by states like Colorado due to First Amendment concerns. While this made it through to the passed legislation, a few wins were still gained.
Originally the legislation threatened felony charges for the storing and sharing of files, potentially impacting researchers, artists, and journalists with no intention of printing a firearm component. These charges were downgraded to a Class A misdemeanor.
Two provisions criminalized file sharing. The first of the two provisions criminalizing this file sharing, which pertains to the sale or distribution of files in the state, gained an important exception for when a sender has a reasonable belief that the recipient won’t illegally print these components. However the second provision, pertaining to criminalizing file possession, complicates this. Under 2.12 of the subpart, people who possess the file with intent to share the files do not clearly get this same reasonable belief exception.
In other words, if you share one of these files the actual sharing is covered by the exception, but the law makes it ambiguous whether possessing those same files is covered when you intend to share them.
While this exception could have created some breathing room for researchers and journalists operating in good faith, this slapdash bill language leaves plenty of ambiguity and potential speech-chilling effects. However, these changes do offer a modicum of harm reduction in this unconstitutional law.
Saving Face by Preserving Online SaleOriginally the bill had a strange requirement for all 3D printers and Computer Numerical Control, or CNC, machines to be sold and delivered face-to-face, with no exception. That would have meant a major barrier to access, particularly for people in agricultural and rural areas of the state who uniquely benefit from in-home fabrication and repair. It also would have meant a major inconvenience for businesses using these devices. For everyone though, it meant fewer retailers to choose from and facing more stigma for using these devices.
Fortunately this was dropped from the bill entirely.
Next Step: We Find Out What Was Actually PassedIn addition to being buried in the complicated legislative process of the NY budget and avoiding proper scrutiny, this bill also kicked the can down the road in determining what exactly is being mandated. In many respects, legislators passed a vibe. We’ll see how the actual law be developed over the next year by a working group with no mandated transparency to the public. Further, they have no obligation to ensure consumer safeguards in developing this state-mandated censorware.
We are still concerned by the possibility of a biased working group acting in the interest of manufacturers or facing pressure to accept consumer harms in the standards they produce. Our remaining hope is this working group convened by the Department of State and the state university system is composed of actual experts who are aware of how unfeasible and harmful this mandate is, and prevent it from being realized.
The Fight ContinuesNew York is the first to go down this path of state-mandated censorship and surveillance software on 3D printers, but it’s far from the only one to entertain it. It is now more urgent that we fiercely oppose this trend in other states, like California, as they attempt to join the bandwagon—before even seeing the real-world impacts.
Don’t Let California Repeat NY’s Mistake
We cannot allow this to be the foundation for future restrictions on speech and design, or serve as a playbook for the state and corporations to wrest control over our tools.
Sony Nerfs Videogame Ownership
Legal intern Suzanne Castillo co-authored of this post.
Playstation’s decision to kill physical game discs is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and negligent lawmakers share the blame — and they can do better.
We’ve seen the same playbook used in the move to digital distribution of film, TV, and music: draw in customers with the convenience of a digital download, then limit physical access and move the goalpost on what it actually means to “own” a piece of media. The end goal is to turn the customer into a renter, stuck making regular subscription payments for access. Gamers are right to sound the alarm, and we must take this moment to fight for digital ownership before it’s too late.
Disk Space InvadersDepriving gamers of physical discs leads to another obvious and immediate cost: data. Unlike other digital media like film and TV, video games require a ton of storage. Access to high speed internet is still abysmal in the US, making the high-speeds needed for digital game downloads a luxury some of us may take for granted. For many, a modern game can take days and exceed their data caps.
This made physical discs, particularly for the biggest AAA titles, a logical choice that also largely spared gamers from losing traditional ownership rights. With physical disks, the cost of storing the game was included in the purchase.
Own or Be PwnedLimiting customers to digital copies also pushes gamers further into rent-only copyright culture.
Physical media comes with a "right of first sale," which means you can lawfully share, resell, alter, or destroy your own copy of a copyrighted work. This right has also helped protect the emergence of alternative community servers, and emulator addition of online play to games from the dial up era.
But courts have held that digital media doesn't carry the same right, meaning no such protection is afforded to digital purchases. Your ability to freely share games with friends or pass them on to family members becomes totally subject to the whims of the distributor.
So, for example, a digital-only approach effectively guts the second-hand market for games. Saving some money with a used game and recouping the costs by reselling are no longer an option. Even with steep discounts and holiday sales, this raises the minimum cost of engaging with the medium at all.
The inevitable conclusion of the move to digital-only purchases is to lock gamers into subscription models, making their access totally dependent on the distributor — or, several distributors, as we’ve seen with major TV and movie streamers. A handful of companies actually own the games, and your only option is to regularly pay for fractured libraries of games you may never play and will never truly own.
Achievement LockedSince digital games are easy to copy, distributors and publishers argue that they are in an arms race against piracy. The irony is that law-abiding customers consistently suffer collateral damage.
Most digital distributors lock down the content they offer with restrictive user agreements and digital rights management (DRM) software. DRM software, in particular, imposes onerous controls on the game — like forcing internet connection for single player games or modifications that harm performance — and can even introduce serious privacy and security concerns. Any gamer or researcher in the US who wants to reduce this burden by removing or modifying that DRM risks a lawsuit, thanks to Section 1201 of the Digital Millennium Copyright Act (DMCA). This federal law makes it illegal to alter DRM software, and is a beloved tool for companies trying to restrict how we can lawfully use our purchases — whether it’s a copy of the newest tractor simulator or a literal tractor.
And since much of this DRM is tied to user accounts, ownership of a game is also revocable and modifiable for any number of reasons outside of your control. Error in your subscription payment? Your account got hacked? Licensing deal falls through with a major publisher? Developers want to kill the game in an update? All of this can limit or change your ability to access the game long after your so-called “purchase.”
Level-up OwnershipPolicymakers can and should work to restore our ownership rights for the digital age.
That starts with legal protections ensuring that the same rights that apply to physical media apply to digital media. Next up? Reform Section 1201 of the DMCA to clarify that it does not forbid fair uses.
At the state level, we need meaningful consumer protections. Some promising models include California’s AB 1921, which would clarify what customers are actually paying for on digital storefronts and ensure some protections for maintaining discontinued games. The gaming industry has done its best to kill the bill, including claiming that private community servers are illegal.
If you bought it, you should own it, and EFF will continue working to mitigate some of the worst harms of the DMCA 1201, defending modders, and fighting deceptive licensing that makes culture less free.
Building Our Future Together
In my first weeks as Executive Director of EFF, I’ve been reminded every day how consequential this moment is in determining what kind of future we will have.
We are on the edge. What each one of us steps up to do – with our expertise, energy, and resources – will determine whether our future is one of openness, security, and fundamental rights, or one controlled through fear, surveillance, and centralized power.
I am proud to take the torch and help lead our EFF community forward at this pivotal time in history. And we need you in the fight.
We can and must reject a false choice between innovation and civil liberties.
Right now, we are celebrating an important U.S. Supreme Court win in Chatrie v. United States that reaffirmed our right to privacy in our location data and will help curb one flank of supercharged government surveillance. But in another case, the Court overturned 90 years of precedent limiting executive power and rubber-stamped the President’s firing of FTC Commissioner Rebecca Slaughter. The U.S. government also issued a chilling directive to Anthropic to prohibit the company from allowing foreign nationals to access its newest technology – then rescinded it two weeks later. And legislation limiting access to social media is advancing in many places around the world.
Each headline is different, but they tell one story: Many of the threats that once seemed hypothetical are now reality, and EFF’s work to ensure technology supports rights, justice, freedom, and innovation for all people has never been more critical. Governments and large corporations possess surveillance capabilities that were unimaginable just a few years ago. Ever greater concentrations of power are shaping speech, creativity, markets, and democratic institutions. Governments are increasingly seeking to control the internet and people’s ability to access information and communicate freely. Our community’s work is fundamental to the future of our countries, our livelihoods, and literally our lives.
I am also mindful that the United States marked its 250th anniversary last week and that this week is EFF’s 36th birthday. Anniversaries, like leadership changes, naturally invite reflection on where we are in history and challenge us to look ahead. What does it mean for a democracy, founded in an analog age, to survive in the digital world?
It is also an opportunity to ask how our EFF community can be even stronger, so we can help bring more people into the work of making sure technology serves everyone.
I began my career in public-interest work in Silicon Valley at the height of the 1990s dotcom boom, working at some of the earliest nonprofit “digital divide” programs that provided community access to computers and the internet, because I have always believed in the power of technology to create greater opportunity for all, not just profit for a few. I have dedicated my career to public interest technology because I am driven to see technology’s promise realized in my lifetime, and there is no other organization in the world that can do more to meet this moment and build a future where technology truly works for people than EFF.
These are perilous times. It is also a moment of extraordinary possibility. The future of AI has not been written and we can work together to get it right. We can make sure our laws reflect the needs of the modern digital age. We can build the technologies that empower rather than marginalize communities.
The future we want and need will be built by people and movements working together to ensure technology empowers rather than oppresses.
For me, the work starts with recognizing that digital rights are not a siloed policy issue. We must fight and win on the digital terrain to organize, speak freely, access healthcare, find work, receive an education, and participate fully in democracy. We can and must reject a false choice between innovation and civil liberties, and build power across movements to make sure technology truly works for people.
This challenge is what EFF was purpose-built to tackle. When EFF was founded in 1990, the World Wide Web did not yet exist, cell phones were the size of bricks, and EFF’s founders understood something remarkably prescient: Technology and civil liberties would become inseparable.
Now we all live digital lives, and the important digital rights issues that EFF has worked on since 1990 have become kitchen-table issues all around the world. EFF’s founders understood that how technology is built, developed, used, and controlled deeply intersects with rights, justice, freedom, and democracy.
EFF’s unique combination of world-class lawyers, activists, and public interest technologists pursue change simultaneously in the courts, legislatures, companies, and our communities, and pierce through false choices. This integrated, intersectional approach, grounded in deep legal, policy, and technical expertise, is a linchpin in fighting and winning against some of the most powerful forces in the world – both governments and trillion-dollar companies.
We defend people against unlawful government data collection and challenge license plate and face surveillance in our communities. We shape AI law and policy to protect civil liberties and support creativity and innovation. We push companies to strengthen encryption, fight to ensure you have the right to own what you buy, and build public interest technologies like Privacy Badger and Certbot that millions of people rely on every day.
This work matters because it all answers the same question: Will technology empower or control us?
As I look ahead, there are major battles on the horizon. We must:
- Challenge increasingly sophisticated government and corporate surveillance systems that endanger our rights, democracy, safety and security
- Preserve strong encryption and online anonymity
- Ensure AI is developed and used in ways that respect fundamental rights and works for those who build it, use it, and are affected by it
- Confront the concentrations of power that limit access to new creativity and defend the rights of developers to build and innovate
To meet these challenges, we must not only utilize the powerful levers of successful litigation, smart policy interventions, and effective public interest technology tools. We must also build a broader movement that recognizes that fights on the digital terrain are integral to all our fights for rights and justice – from civil rights and immigrants’ rights to reproductive rights, disability rights, LGBTQ+ rights, workers' rights, economic justice, and more. Together, our EFF community can help broaden the public conversation about technology's role in society and continue building the collective power necessary to shape the future rather than react to it.
I have hit the ground running, working with EFF’s exceptional staff and Board and starting to meet many of you in the broader EFF community. Every conversation has reinforced my confidence that our community is uniquely prepared for the work ahead. I’m looking forward to meeting more of you at my first EFFecting Change livestream on August 12 with Cory Doctorow, and hope this conversation is just the beginning of finding new ways to work together. Please stay tuned for additional in-person events with me around the country this fall.
As we celebrate EFF's birthday, I am energized by all the opportunities ahead for us to build on EFF’s strong foundation and make it even mightier. And we need you and others in the fight. Please renew your membership, become a recurring monthly supporter, and introduce someone new to EFF by snagging them a gift membership.
Everything we accomplish—every lawsuit, every policy victory, every public interest technology tool, every campaign—is possible because people like you are committed to ensuring technology strengthens freedom, privacy, creativity, and opportunity for everyone.
The future we want and need will be built by people and movements working together to ensure technology empowers rather than oppresses.
Let’s build that future together.
Automated Moderation Is Here to Stay—Accountability Must Keep Pace
This post is part 2 in a series about automated content moderation. Read the first post here.
When whistleblower Frances Haugen leaked a set of documents from Meta in 2020, among the revelations was a jarring statistic: The company’s algorithms designed to detect terrorist content incorrectly deleted nonviolent Arabic-language content 77 percent of the time, while failing to detect hate speech under the company’s own policies in many instances. Meta’s own transparency report released later that year demonstrated similar findings. Five years later, researchers in the region report that overzealous moderation remains a problem, while paths to remedy have all but collapsed.
Where these systems are faltering in Arabic, they’re positively failing in less-resourced languages. As a 2025 report from the Center for Democracy and Technology found, labeled datasets in certain languages and dialects such as Maghrebi Arabic and Kiswahili contain inconsistencies, bias, and inaccuracies due to the limited hiring of annotators who actually speak the languages as well as shifts in the languages themselves. An investigation into ChatGPT’s outputs in several low-resource languages demonstrates the depth of problem.
But language disparities are just one of several concerns as automated moderation becomes more widespread. From the systemic suppression of content from Palestine to the repeated misclassification of LGBTQ+ content as adult or explicit material, these varied examples demonstrate the risks of overreliance on automated moderation—and the need for stronger safeguards.
Transparency, Cultural Competence, AppealsAs we discussed in Part 1 of this series, automated systems can process content at a scale that humans never could, potentially enabling better moderation at scale and alleviating the psychological load on ill-paid moderators whose jobs require them to view incredibly disturbing content. But automated systems also reproduce existing biases, struggle to understand context, and often make mistakes that disproportionately affect journalists, activists, artists, and other vulnerable and marginalized communities.
As Rachel Griffin wrote in 2023, “Perfectly accurate moderation is not only technically out of reach but intrinsically impossible.” Despite those intrinsic flaws, there is a great deal companies, policymakers, and civil society can do to help ensure that highly-automated systems operate in ways that respect human rights, minimize predictable harms, and provide meaningful accountability when they fail. If companies are going to continue relying on automation to moderate users’ speech—and there is little reason to believe they won’t—then accountability must evolve alongside these technologies.
That evolution can start with committing to the Santa Clara Principles 2.0. These principles, first outlined in 2020 and re-launched in 2021 after substantial international input, reflect the needs and expectations of the global community and specifically address automation. The first Foundational Principle states:
Companies should ensure that human rights and due process considerations are integrated at all stages of the content moderation process, and should publish information outlining how this integration is made. Companies should only use automated processes to identify or remove content or suspend accounts, whether supplemented by human review or not, when there is sufficiently high confidence in the quality and accuracy of those processes. Companies should also provide users with clear and accessible methods of obtaining support in the event of content and account action.
Drawing on the Santa Clara Principles 2.0, international human rights standards, and years of research documenting the shortcomings of automated moderation, we propose eight recommendations for policymakers thinking about regulation and companies deploying AI-assisted content moderation systems.
- Automated technologies should help, not replace, human moderators. For example, automated systems can help flag and prioritize content for review, while humans can interpret context, handle sensitive cases, and refine system performance.
- Companies must be transparent about when and how automation is used in content decisions.
- Companies must regularly audit their automated systems for bias, with particular attention to low-resource languages, vulnerable and marginalized communities, and conflict zones.
- Users must have the ability to appeal, and to provide context when they believe human or automated moderation decisions have wrongfully removed their content. Appeals should be promptly evaluated and decided by human moderators.
- Companies should regularly assess the human rights impact of their moderation decisions, and issue public statements of the results
- If they rely on third-party vendors, companies should carefully (and regularly) audit those vendors for compliance with these same principles
- Lawmakers should avoid promoting and passing legislation that effectively or explicitly mandates automated moderation systems
- Policymakers should also refrain from attempting to dictate platforms technical and design choices to favor or disfavor particular expression.
These recommendations understand that automated content moderation isn’t just a technical problem for clever engineers and product teams to solve. Because content moderation shapes public discourse and fundamental rights, its design and oversight must respond to the concerns of policymakers, civil society, independent researchers, and the communities most affected by these systems.
This is the second post in a 2-part series on automated content moderation. Read the first post here.
"We Want Texans to Know Their Rights": Q&A with Mayday Health on the Impact of Surveillance on Abortion Care
Last May, EFF reported that a sheriff’s office in Texas searched data from more than 83,000 automated license plate reader (ALPR) cameras to track down a woman suspected of self-managing an abortion. ALPRs are promoted as tools for keeping communities safe by finding missing persons and locating stolen vehicles, but this case showed how ALPRS can be weaponized to investigate people’s private healthcare decisions. And these aren’t the only tools in the surveillance arsenal: others include location tracking tools like Locate X, which can show a person’s visit to an abortion clinic, or search histories which might be used as evidence of a person’s interest in obtaining abortion pills. Taken together, these tools create a dangerous surveillance pipeline that threatens everyone’s health privacy.
Too often, though, the public is unaware of the threat, and one nonprofit is working to change that. Following EFF and 404 Media’s report on Texas’s use of Flock cameras, eye-catching billboards popped up in Houston, warning drivers that if they’re pregnant, the state of Texas could be tracking them.
Photo provided by Mayday Health
These billboards came from Mayday Health, a nonprofit dedicated to sharing information about abortion pills, birth control, and gender-affirming care. We spoke with Leo Raisner, Executive Director of Mayday Health, about the billboards to learn more about the campaign and organization and to discuss how surveillance affects reproductive freedom.
***
THOMAS: Why did Mayday Health start this campaign in Texas?
RAISNER: Well, we read the incredible reporting coming from EFF about Texas's surveillance. We want Texans to know their rights, to know their options, and to know that there are organizations and people who have their back. So we decided to put up a few billboards around the Houston area to remind people that they still have options.
Digital advertising in the space, as I know you're well aware of, faces enormous platform restrictions from Meta and Google, whereas billboards reach people in the physical world without algorithmic gatekeeping and without requiring anyone to search for information. So at the very least, if a driver's passing by the billboard, we’re spreading information that they should be careful that they might be surveilled, and also there are different options. There's a website where they can come learn more about those options.
THOMAS: And how have the billboards been received so far? Have you heard anything from folks in the Houston area yet?
RAISNER: Yeah, we've heard some messages of support on social media DMs. We're just thrilled about how many drivers these messages are going to reach. They'll be up for 4 weeks, and are expected to hit over 1,000,000 drivers during that 4-week campaign period.
THOMAS: Are there other ways that Mayday Health has seen surveillance systems impact people seeking healthcare?
RAISNER: You know, we go all over the country and talk to folks who are seeking reproductive healthcare options in states where clinics are banned, and we direct folks to our website where they can learn more about abortion pills. We make privacy very central to how we operate. Privacy is not just an afterthought for us. When people arrive at our website, we direct them to the Digital Defense Fund, which offers people privacy and security resources as they're navigating reproductive healthcare in states where they might be being surveilled. We don't collect cookies, we don't collect identifying information from visitors to our site. We want people to know their options, and we don't have any interest in knowing who they are.
THOMAS: Why do you think the work of the digital rights movement is so important to the work of the reproductive health rights and justice movement?
RAISNER: I mean, those two movements are inextricably linked. The anti-abortion movement is using every tool in their toolbox to prevent people from getting the healthcare access they need, whether that's surveilling people online or closing down brick-and-mortar clinics, but we encourage people to visit Mayday Health and learn that they still have options no matter where they live.
THOMAS: Is there anything else that you would like the readers of our blog to know about Mayday Health?
RAISNER: I'd love for people to know that abortion pills are FDA approved. They're safe, they're effective, and they're available through the mail.
***
EFF has said it time and time again – surveillance and reproductive freedom cannot coexist. Whether the tracking occurs over the internet or through license plate reader systems with over 83,000 cameras, it is an invasion of privacy. Protecting our digital privacy is more critical now than ever. Help EFF fight back against this digital dragnet and protect reproductive freedom for all by making a donation.
The House Passed The KIDS Act—The Senate Should Reject It
Last week, the House voted on the KIDS Act, a disjointed package of legislation that seeks to control Americans’ web browsing and private messaging. The package combines a revised version of the Kids Online Safety Act (KOSA), with several other internet bills, study bills, reporting requirements, and new regulations. Different parts of the bill pressure online services to impose different age-gating schemes, using different standards. EFF opposed this bill, along with many of our members and supporters.
Tell Congress: no internet age-gates
The bill passed the House, 267-117. It now heads to the Senate, where its fate remains uncertain. But this fight is not over. Even if you took our earlier action to contact the House, we need you to reach out to your Senators today.
The KIDS Act Will Lead to Mandatory Age ChecksMany of the bills in the KIDS Act share the same premise: that children and teenagers should have different experiences online than adults. In practice, that requires websites and apps to determine who is under 18—and who isn’t. That’s where the problems with the KIDS Act start.
EFF certainly supports giving all users better privacy and safety tools online. But those protections should not, and do not need to, come at the expense of privacy or free expression. Unfortunately, that’s exactly the tradeoff the KIDS Act makes.
There is no way to determine a user’s age online that is both privacy protective and accurate. Some age verification processes may rely on collecting government-issued ID, while others may use biometric scans. Others will use algorithms to guess a user’s age based on facial images or online behavior. But no matter the method, every system demands users hand over sensitive personal information that links their offline identity to their online activity. And then, once that valuable data is collected, it can be leaked, hacked, or misused. In fact, we’ve already seen several breaches of age verification providers.
The Bill Still Regulates Online SpeechThe revised KOSA language within the KIDS Act still pressures companies to police lawful speech online. Platforms must “establish, implement, maintain, and enforce” policies that address content like gambling or the use of alcohol or cannabis. This encourages platforms to broadly restrict speech on these topics, which could include a teen seeking advice on a parent’s gambling problem or searching for substance abuse recovery resources. When platforms are required to create and enforce content moderation policies that regulators can sue them over, they will often err on the side of deleting speech.
Protect Privacy For EveryoneThere is a better way to protect young people online. Instead of encouraging a complicated system of age checks, more monitoring, and more restrictions on access to information, Congress could finally pass a strong, comprehensive privacy law that benefits all users. A great place to start would be to ban behavioral advertising that tracks us across the web—again, for users of all ages.
We urge the Senate to oppose the KIDS Act and instead focus on a strong, bipartisan privacy package for all users.
European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates
Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has so many benefits that solve those issues.
Say you’re on multiple platforms because you have friends you follow on different networks, but you’ve decided to choose one platform with better privacy practices. With interoperability, you could switch and still interact with friends who remain on larger platforms. It could also enable independent apps with better privacy controls and more user choice. These are the untapped possibilities that could benefit users in the European Union under the 2022 Digital Markets Act (DMA).
Yet, the European Commission, in its first review of the DMA, announced in April it had decided not to extend the DMA’s interoperability mandate to social networking and didn’t give a deadline or a timeline for enforcing that part of the Act. The Commission said “there is no clear demand” from users and businesses for social networking interoperability and, in any case, it’s too technically complex at the moment. Meanwhile, the Big Tech platforms that have been slow-walking interoperability over the last two years, erecting a myriad of hurdles for users seeking more freedom to choose other platforms, get a pass.
This is a huge disappointment and a missed opportunity by the Commission. Interoperability dismantles one of the biggest barriers faced by users who want to leave the tech giants’ platforms: the choice between changing to a platform you prefer or staying behind on a platform where all your friends, communities, and customers are.
The DMA, which went into force in 2024, aims to foster more choices for European Union users and encourage competition and innovation by forcing so-called gatekeeper platforms like Meta, Apple, and Google, to open their ecosystems to competitors. The regulation does a great deal to foster the integration of competing services and devices with the ecosystems of very large online platforms that act as gatekeepers. It even requires interoperability for messaging services, despite the significant technical and privacy challenges involved.
So, it’s odd that the Commission is using complexity as a shield against taking on social networking interoperability. The internet already runs on complex interoperable systems. Approaches like ActivityPub, the decentralized networking protocol behind the “Fediverse,” which gave rise to decentralized networks like Mastodon, already exist. The DMA shouldn’t mandate a specific protocol, but it can require meaningful interoperability outcomes.
The argument that there’s no real demand for social networking interoperability also falls flat. Users want the ability to move across platforms, choose the content they’d like to see from platforms, and not be tied down to a single platform. But there’s no way to get there—the platforms are doing little to open their social networking ecosystems. And now you have the DMA’s enforcer saying it’s not going to make them change. Demand for alternatives won’t materialize at scale until users see real progress towards interoperability, something the Commission has the power to do.
Having decided there’s little demand and too much complexity to proceed with mandating social networking interoperability, the Commission said it “will continue to monitor and assess how these services evolve.” This wait-and-see-posture only hurts users and strengthens and further entrenches Big Tech incumbents.
The DMA is supposed to center on the rights of technology users and be the pathway to an internet experience where you decide which software runs on your devices, where it’s easy to find the best products and services, and where you can leave a platform for a better one without forfeiting your social relationships.
Meanwhile, Big Tech is also resisting the DMA’s openness requirements. For example, Apple is supposed to be opening up iOS devices to rival app stores. Yet, the smartphone giant’s plan for opening its App Store levies junk fees and onerous conditions on app makers and is effectively impossible for any competitor to use.
It’s not just Apple pushing back against DMA enforcement. Meta's response is a “pay for privacy “system, in which users who do not consent to Meta’s surveillance will have to pay to use the service, or be blocked from it. Whether their plan complies with the DMA remains under review.
Nowhere in the DMA does it say social networking companies get to install a toll booth for users seeking to benefit from privacy rights the regulation grants them. The future EU Digital Fairness Act is another opportunity to protect users from such practices by declaring them unfair.
The Commission has responded to these developments with investigations, preliminary rulings, and fines. Meanwhile, users are missing out on greater choice and flexibility in how they communicate and connect online.
Google's New Remote Attestation Scheme is As Bad As Its Old One
Google owes its existence to the open web, but today, its technological “innovations” have much to do with locking users into a “walled garden.” The latest of these is “reCAPTCHA Mobile Verification,” an experimental initiative that will let companies block users if they are running independent, "de-googled" versions of Android. These “indie Android” versions are favored by people who want to protect their privacy and their attention by blocking trackers and ads. Worse, this is just the latest in a line of similarly user-hostile measures.
Long before “agentic AI,” we had the idea that software would act as your agent on the internet. That's why the old-fashioned technical term for a browser is a “user agent.” Your browser acts on your behalf to retrieve information and then show it to you, in the format you choose. It's your agent.
This is a powerful and profound idea. It is because browsers are our “agents” that we expect them to accept our directives, say, by blocking pop-ups, or by turning off autoplay sound, or by blocking commercial surveillance trackers.
Your browser does all that because your browser works for you. The reason your browser can work for you is that the web is an open, standardized technology. In theory, anyone who follows the standards published by the World Wide Web Consortium (W3C) can make a browser, and that web browser can connect to any web server. Browsers and servers are interoperable. It's the same force that means you can put anyone's gas in your gas-tank, or anyone's shoelaces in your shoes, or anyone's milk on your cereal.
But what if manufacturers could dictate those choices to you? What if your light socket refused to use a lightbulb unless it was officially blessed by the socket's manufacturer? What if your dishwasher refused to wash your dishes unless you bought them from one of the manufacturer's “dish partners?” What if your toaster refused to toast “unauthorized bread?”
It's hard to see how a company could win its market with this strategy. After all, if the dishes are really better than the competition's, you'd buy them voluntarily, without any need for law or technology to force the matter. The only reason to make a dishwasher that refuses a rival's dishes is if the manufacturer's own dishes are ugly, expensive, and/or badly made.
But once a company owns the market—once they've achieved dominance by buying out their rivals; by bribing potential competitors to stay out of their lane; and by engaging in deceptive conduct to trap key suppliers and customers—they can cement their dominance by blocking interoperability, keeping out rival dishes, milk, gas, lightbulbs, shoelaces and bread, capturing their whole market and squeezing it.
Once a company owns the market, they can cement their dominance by blocking interoperability.
That's what Google has done, and that's what Google wants to do more of Google's commercial behavior has been so unethical, deceptive and abusive that the company just lost three federal antitrust cases. This thrice-convicted monopolist paid Apple—more than $20b/year— to stay out of the search market: It cheated app vendors, ripping them off with sky-high junk fees and onerous conditions that raised prices while lowering the share of your spending that went to the companies whose products you were paying for. It cheated advertisers, rigging the ad market to gouge businesses on ad prices and underinvesting to fight rampant ad-fraud, sucking hundreds of billions out of the productive economy for overpriced ads that no one saw.
Google wasn't always this way. The “don't be evil” company owes its very existence to the open web ecosystem. When the company started to index the web in 1998, it was playing on an open field, where any web server could talk to any “user agent,” even one whose user was a startup like Google, that was making a copy of every page on the server.
For years, Google thrived on the open web, and built open technologies. Android—the mobile operating system that Google bought in 2005 —was presented as an “open” alternative to existing mobile offerings, and as the mobile market collapsed into two companies—Google and Apple—Google always presented Android as the open alternative to Apple's “walled garden.” But there were always ways in which Google's “open” Android wasn't exactly open. The company engaged in illegal “tying” arrangements that forced hardware vendors and carriers to lock out versions of Android that were created by Google's competitors.
In other words, even though Google offered a mobile platform that was (mostly) technically open, it found other ways to try to choke off the market oxygen for alternative Android versions that tried to capitalize on that technical openness.
But life finds a way. The existence of an open, modifiable, tinkerer-friendly mobile operating system meant Android hackers could create alternatives to Google's (de facto) walled garden, which thrived in the cracks in that garden wall. Operating systems like CalyxOS, PureOS and Graphene offered a more private, more secure Android experience, one that was largely “de-Googled,” blocking Google's relentless acquisition of your private data.
And Google's data-hunger is relentless. Android exfiltrates a chunk of your personal and behavioral data every five minutes. The “resting heartbeat” of Android surveillance pulses and pulses, irrespective of whether you're using your device, and the instant you unlock your screen, that heartbeat quickens, sending even more data to the company. All that data has proven irresistible to authoritarian governments. Donald Trump's enforcers have seized on Google data as a vital source of information about the identity of protesters and the location of migrants hunted by ICE.
So there are plenty of reasons why users would seek out these de-Googled alternatives to Android, finding them in spite of Google's efforts to block access to competing technologies. The worse it got, the better those alternatives looked.
Perhaps this explains Google's years-long effort to increase the technical barriers to using modified versions of Android, beefing these up to match the commercial restrictions that stand in the way of a de-Googled existence.
Back in 2023, Google floated the idea of “Web Environment Integrity” (WEI), a set of modifications to web standards that would force your computer to disclose its operating environment to the web servers it connected to, even if you objected to this disclosure.
WEI was a form of “remote attestation.” That's when your device uses a sub-processor (sometimes called a “Technical Protection Module” or “TPM”) or a walled off part of its main processor (sometimes called a “secure enclave”) to produce a cryptographically signed description of your device and its configuration: which hardware, software, plug-ins, and settings you're running.
Take away our ability to block obnoxious digital content and you guarantee that we will be flooded with it.
When you connect to a server, it demands that your device send this “attestation” before it handles your request. If your device won't provide this data, or if the server doesn't like (or recognize) your device and its details, it can refuse to deal with you. And because the attestation is prepared by a TPM or a secure enclave that you can't modify or override, you don't get to decide which facts about your device it's allowed to see.
Practically speaking, this means that remote attestation lets a server refuse to deal with you until you turn off your ad-blocker and your tracker-blocker. It means that the server can discriminate against users who block auto-play sound and video, who block pop-ups, who put the tab in the background when it's playing a mandatory pre-roll ad.
WEI was especially disturbing in light of Google's plan to kill ad-blockers and privacy blockers through updates to Chrome, an effort that continues to this day.
These blockers are an important part of the dynamic between web publishers and their users. In the real world, when you get an offer, you can make a counter-offer. That's all an ad-blocker is: a way for users to respond to a server whose opening bid is, “How about you give me all your data and let me take over your computer in exchange for showing you this page?” with “How about 'Nah?'”
We didn't get rid of pop-up ads by making them illegal, or by boycotting advertisers who used them. We got rid of pop-up ads when web users installed pop-up blockers, which made pop-up ads pointless. Take away our ability to block obnoxious digital content and you guarantee that we will be flooded with it.
These kinds of modifications aren't just used to block ads—they're also key to accessibility. People who have photosensitive epilepsy or suffer from low-contrast vision problems use add-ons to reformat pages so they can safely and legibly access them.
WEI's creators said they were only trying to put the web on a level playing field with apps, which routinely disclose facts about your device to the companies whose servers you connect to, without asking you, and even if you don’t want them to. Apps are a source of bottomless enshittification, not least because (unlike the web), they enjoy special, dangerous legal protections that make it very legally risky to modify them. WEI wasn't an effort to level the playing field between apps and the web—it was a race to the bottom, an attempt to make the web as enshittification-friendly as apps.
Public outrage to WEI killed the project, but Google's commitment to augmenting its illegal commercial lockdown efforts with technical lockdowns never ended. Now, Google has rolled out an experimental “reCAPTCHA Mobile Verification” that uses an app, your camera, and your device's TPM or secure enclave to produce an attestation about your Android device.
This will make it much easier for the apps and other services you interact with to block your device if you run an Android alternative, or if you install a mod that overrides the actions of Google's stock Android.
This is a terrible idea—it's every bit as bad as WEI was. In an age in which Big Tech is ever-more tied to authoritarian governments, redesigning our devices to tell strangers things we don't want them to know isn't just shortsighted, it's inexcusable.
