France Bans Under-15s From Social Media, a Hidden Device Leaves US Cars Hackable, and Courts Force Apple and Google Open
France just became the first country in Europe to ban under-15s from social media. The UK and California moved the opposite direction, hackable US cars, and more!
On My Radar 🎯
France Banned Social Media for Under-15s.
French lawmakers approved a ban on social media access for children under 15 this week...the first country in Europe to do this. Children under 15 will not be allowed to open a new account starting September 1st, and President Macron, who spent April urging young people to put down their phones and pick up books, wants it in place before the school year starts.
I don't think the people pushing this found the wrong problem, I just think they found the wrong solution. I agree with many that these platforms collect enormous amounts of data specifically to exploit you (and kids) as individuals. They run algorithms engineered to be addictive. They deploy dark patterns. These are companies that are, functionally, hacking human biology—and they've been doing it for ten+ years while almost nobody meaningfully intervened. The frustration behind this law is completely earned!
My problem is that a ban is a downstream fix for an upstream disease. Look at what it actually requires: the same companies causing the harm now have to collect more identity data about everyone, and we have to trust them to regulate themselves with it. Australia already passed its version last December, and kids are already routing around it with VPNs...precisely why the UK keeps floating VPN bans, chasing the next downstream thing instead of the upstream one. And look at what happens after: when those kids turn 15, they walk onto the exact same exploitative platforms, unchanged. Nothing about the product got better. We just moved the gate.
I have yet to see a unified effort from any government targeting the upstream problems (and in doing so genuinely keeping us all safer). Some ideas like:
- Banning surveillance advertising to minors (or entirely), kills the profit motive for building the behavioral profile in the first place
- Banning engagement-optimized recommendation for minors; default to chronological.
- Outlawing the dark patterns by name. (autoplay, streaks, infinite scrolls, etc.)
- Requiring interoperability and data portability, so users can leave without abandoning their social graph
- Clearer opt outs, better parental controls, and most importantly: educating students in schools about these concerns and how they can stay safe online.
What you can do: If you're in France, contact your representatives! If you're anywhere else, contact them anyway! This spreads region to region, and it's a different set of countries every single week. The premise sounds good to people who haven't looked at the implementation, which is exactly why educating the people around you matters as much as the phone call.
Bits & Bytes 🤖
~ Story 1: A Hidden Device in Millions of US Cars Leaves Them Open to Hacking
Researchers at UC San Diego found that KARR anti-theft devices, typically installed by dealers, not manufacturers or owners, can be used to take control of vehicles. The flaw is a single authentication key shared across every device, which the researchers pulled straight out of the companion smartphone app. They could unlock cars, prevent them from starting, and trigger a "mayhem" function that sets off horns and lights across a whole lot at once. At least half of owners who have one of these never asked for it.
My take: You may have this and not know! Check your driver's side window for a KARR sticker (or SWDS, for Southwest Dealer Services), and look under your dash for a small button with a blinking light. Southern California owners are the most likely to have one. Cars remain a genuine nightmare in 2026 and I can't pretend there's a clean fix here, but ask your dealer directly what add-ons are in the vehicle before you buy, use opt-outs where they exist, and know the risks on your specific car rather than driving around unaware of them. This space is evolving rapidly, so I'll do my best to cover them as they happen.
~ Story 2: New Stats Show Most Chat Control Reports Are False Alarms
Patrick Breyer shared figures regarding mass scanning which demonstrated that in 2025, 52% of flagged reports were legally irrelevant...meaning roughly 113,000 private photos were exposed for nothing. Around 40% of investigations targeted children aged 10 to 14 themselves, and 53% targeted minors overall, criminalizing some 12,000 teenagers rather than the adults actually exploiting them. Meanwhile the police clearance rate for online distribution of illegal content already sits at 87.1%.
My take: This is a sensitive subject and a real problem, and I don't want to wave it away. But that's exactly why the solution has to actually work. Mass scanning is producing a majority of false positives while criminalizing the kids it claims to protect, and the clearance rate suggests conventional investigation is already doing a good job. Chat Control 2.0, the version that goes after end-to-end encrypted messages, is still around the corner. We've beaten it before, but we need to fight again. Follow Fight Chat Control to take part in this fight!
~ Story 3: Courts Are Forcing Apple and Google to Open Up
A European court rejected Apple's attempt to shirk its interoperability requirements, we will see how quickly it takes them to comply 😄 Separately, Google confirmed third-party app stores are coming to Google Play as the Epic settlement was withdrawn.
My take: I'd like us to stop filing interoperability under "privacy." It's a broader, digital rights issue, and the FSFE folks I've had on Techlore Talks explain it better than I can: large platforms have no incentive to work with anyone else, while everyone smaller desperately needs to work with them. That asymmetry is why leaving Apple's ecosystem feels impossible. It's a design decision, not a technical limitation. I think interoperability has the potential to open up many ecosystems to services that genuinely value users better than most big tech companies. One thing I'm genuinely confused about on Google's side: this third-party app store update lands while they're simultaneously building a byzantine "sideloading" flow with waiting periods and reboots and developer settings. I'll cover it as it becomes clear how these stories interact. I don't want to celebrate early on this one.
This Week on Techlore 📺
I'm finally getting things more dialed in after the move...so happy to be getting more content out for you all 😄
- First, our SPA tools have been updated to v2026.07 with some exciting new VPNs on the VPN finder, security improvements, and accessibility benefits. The wiki has also been transitioned to our site. Thank you all for your feedback to make these tools better over time!
- I interviewed David Ruiz from Malwarebytes regarding scam-prevention, broader digital rights advocacy, and what needs to happen to prevent mass surveillance.

- And finally, I made a fun demo-style video comparing profiles vs containers on Firefox & Brave and how both browsers have finally reached a great place across both features...ending an age-old debate!

Action Item ✅
Contact your representatives about age verification, social media bans, and your regional issue. Your message doesn't need to be an essay. It can be three sentences. And if you're in the EU, fightchatcontrol.eu makes the Chat Control version of this about as frictionless as it gets.
US Drivers: Check your vehicles for the insecure alarm!
Until next week 🫡
This Week's Sources
Highlight: France Just Banned Social Media For Everyone Under 15
- https://www.reuters.com/legal/litigation/french-lawmakers-vote-social-media-ban-children-2026-07-21/
- https://www.reuters.com/world/uk/next-uk-prime-minister-andy-burnham-drops-digital-id-scheme-2026-07-18/
- https://www.techtimes.com/articles/320876/20260717/california-senate-drops-browser-age-id-mandate-os-checks-remain-track.htm
- https://www.eff.org/deeplinks/2026/07/california-steps-back-dangerous-expansion-its-age-gating-law
Story 1: A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking — Patch Now
Story 2: New German BKA Stats — Most Chat Control Reports Are False Alarms
Story 3: Courts Force Apple and Google to Open Up
- https://www.eff.org/deeplinks/2026/07/european-court-apple-can-not-shirk-its-interoperability-requirements
- https://arstechnica.com/gadgets/2026/07/third-party-app-stores-coming-to-google-play-next-week-as-epic-settlement-withdrawn/
The Defense Bulletin
Data Breaches
- https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/
- https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
- https://cybernews.com/security/hacker-deletes-romanian-land-registry-database/
- https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/
- https://techcrunch.com/2026/07/22/how-an-openais-human-mistake-led-to-the-ai-powered-hack-on-hugging-face/
- https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/
- https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/
- https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
- https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/
Threats
- https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/
- https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/
- https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
- https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives/
- https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability
- https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
- https://www.404media.co/you-opened-a-credit-card-ice-now-knows-where-you-live/
- https://techcrunch.com/2026/07/16/period-tracker-stardust-shares-users-health-data-with-analytics-firm-says-mozilla-research/
- https://www.eff.org/deeplinks/2026/07/victory-flock-ends-rollout-audio-distress-detection-human-voices
FOSS+ Updates
- https://signal.org/blog/polls/
- https://blog.torproject.org/new-release-tor-browser-15019/
- https://alternativeto.net/news/2026/7/yubikey-5-8-extends-passkeys-from-secure-authentication-to-verifiable-authorization/
- https://blog.mozilla.org/en/firefox/firefox-containers-preview/
- https://blog.mozilla.org/en/firefox/tab-groups-android/
- https://alternativeto.net/news/2026/7/vivaldi-8-1-launches-with-more-customization-features-and-more-options-for-android-users/
- https://alternativeto.net/news/2026/7/whatsapp-develops-first-party-encrypted-cloud-backup-for-android-and-ios/
- https://alternativeto.net/news/2026/7/secure-messaging-app-briar-enters-maintenance-mode-will-only-receive-bug-and-security-fixes/
- https://www.mullvad.net/en/blog/2026/7/20/donation-controversy/
- https://techlore.tech/changelog/
Surveillance Report: what matters in privacy, security, and digital rights. Weekly, free.

