Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans

3 hours 5 minutes ago

Governor Newsom signed a package of 12 bills yesterday aimed at “protecting children” online. One of them was AB 1709, which EFF has opposed this legislative session and serves as a functional ban on young people under 16 using social media. However, EFF supported two of the bills signed into law, AB 2071 and AB 2298, which require that children learn critical digital literacy and cybersecurity topics. The bills are an affirmative and constitutional way for the state to address valid concerns about young people’s internet use without violating their First Amendment rights.

Unlike blanket bans, A.B. 2071 and A.B. 2298 address online safety through education rather than prohibition. Young people rely on the internet not just for entertainment, but for civic engagement, education, self-expression, and community—especially vulnerable youth who may lack support in their physical surroundings. This is why real digital safety comes from preparation, not isolation. Research consistently shows that open, honest conversations about digital literacy and privacy with trusted adults are far more effective at protecting youth than restrictive censorship laws. Young people themselves recognize this need; in fact, A.B. 2071 was co-authored by a group of students actively seeking better resources to navigate their digital lives safely.

Education vs. Censorship 

A.B. 2071 and A.B. 2298 fill critical gaps in California’s school curricula by equipping students with actionable skills. A.B. 2071 integrates digital wellness into middle and high school health classes, teaching students how to identify unhealthy tech habits, protect their personal safety, and evaluate digital content—including AI-generated media—for credibility and bias. Meanwhile, A.B. 2298 adds cybersecurity concepts to recommended school curricula, teaching young people how to safeguard their personal data from online threats.

While the state’s turn toward social media bans remains a harmful and misguided policy direction, the passage and signing of A.B. 2071 and A.B. 2298 show there is a better way. Lawmakers must stop treating censorship as a quick fix and instead focus on constitutional, empowering solutions that give youth the tools they need to thrive online. 

Chao Liu

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

6 hours 34 minutes ago

Amazon recently debuted a new feature for its Ring cameras that the company is calling Throw Away the Key Encryption (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed bump to accessing full video content, it doesn’t deliver nearly the level of privacy we should be demanding from video doorbells and other security cameras.

TAKE introduces a new way for Ring to manage encryption keys, where the user’s device has its key, then the company holds encryption keys temporarily within its own cloud infrastructure. Ring’s servers receive the keys temporarily so it can offer a variety of the features it says it can’t offer when a user chooses to use end-to-end encryption, like video descriptions, smart alerts, video search, and more, then deletes the key after 24 hours. 

This differs from how it works now, where footage is encrypted in transit and at rest, then decrypted by Ring, which always has access to the footage, to process those features. 

Comparatively, this is an improvement to the default settings Ring has now, because it at least puts some restrictions on historical footage, but it has some serious holes worth exploring.

Ring Gets Access to Unencrypted Video for a Short Period

Ring has designed its service so many of its camera features, including smart alerts and video search, need cloud processing to work. That means to provide those features, Ring needs to decrypt the footage while it’s stored in Ring’s cloud servers. 

With TAKE, in order to decrypt footage to offer these features, Ring gets access to footage stored in the cloud for 24 hours. TAKE adds some small measures using secure enclaves to make base key material harder to directly export, but keys are still released to services that can be modified. With access to the keys, the cloud processing does its thing and delivers the requested feature to the user. The key is then deleted 24 hours later—until the user wants to watch an old video or use other so-called “smart” features, at which point the keys are sent back to the server. 

In practice, that makes the system as a whole barely different from encryption at rest where the server holds the keys. The client device essentially takes the place of a hardware security module (HSM), including making those keys available to the server whenever they’re needed. The end result is an improvement from the status quo, but still not even close to the privacy protections of end-to-end encryption

The company says it does not keep backups of the keys and there’s no way for a Ring employee to access footage. It also claims that any decrypted content is deleted from its servers. 

But that doesn’t mean much when user actions send the keys back to the server. And making features like “Video Search” and “Smart Video Descriptions” available to the device owner means that while the footage can’t be seen by Ring, descriptions are readily available to the company. In response to a question about capability, Ring responded to us that, “As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included.”

Plus, account recovery keys are stored in the camera itself by default. When that’s paired with the fact that currently, indices of video contents are available to the company, it means that TAKE isn’t even a protection against mass surveillance. Law enforcement could request a mass search across cameras for certain terms, then delve into further details by seizing cameras of interest from the device-owner, decrypting account backups, and using that information to decrypt encrypted videos. 

Law Enforcement May Still Seek to Compel Access to Footage

Because of the ways the access and key rotations work, it’s technically still possible for Ring to alter its current practice if compelled to do so by law enforcement, in much the same way as other existing encryption-at-rest systems where the company holds the keys. For example, Ring could receive an order that demands they save content encryption keys or unencrypted videos from memory to disk, which would mean they’d retain some level of access. 

In an email to EFF, Ring stated, “By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests.” EFF specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears to be technically possible, but the company did not address it.

End-to-end encryption works to maintain trust by its user base because the company that employs it never has access to the keys at any point, making it impossible for itself to access the encrypted contents. This also means law enforcement can’t demand the service retain keys or choose not to rotate them. As described, this level of protection isn’t offered with TAKE.

Ultimately, Ring is the one managing this software and its implementation, and beyond a white paper, “trust us” is the only level of verification they’re offering outside observers. While it doesn’t fix the issues, at the bare minimum, the company needs to open the entire infrastructure up to third-party auditors to verify its claims. Ring seems to agree, as they told us that, “Ring conducts rigorous security reviews of all products before launch and critical components of TAKE’s infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review.”

TAKE is not end-to-end encryption, where Ring would never have access to the keys, and the company thankfully doesn’t claim it as such. Ring already offers the option for end-to-end encryption, and turning that on by default would offer the real sorts of privacy improvements we all want from video doorbells. 

Erica Portnoy

【焦点】対ロ戦4年半 ウクライナの厳しい現実 性暴力、徴兵逃れ、生活困窮 厭戦気分拡大「団結」に亀裂 映像ジャーナリスト・玉本英子氏が報告=橋詰雅博<br /> 

7 hours 31 minutes ago
 「開戦から4年半ほど、ウクライナ社会はロシアに徹底抗戦という団結の空気は弱くなっています」――映像ジャーナリストの玉本英子氏(アジアプレス所属)=写真=は7月12日都内での「戦火のウクライナ」を取材した最新映像報告会でこう話した。玉本氏はアフガニスタンやイラク、シリアなど紛争地を長年取材し女性や子どもなど弱者の視点に立った報道姿勢が評価され2016年度第54回ギャラクシー賞報道活動部門優秀賞を受賞している。 ウクライナ取材は、これまで5回、滞在はのべ1年以上におよぶ。今年は..
JCJ

[B] 佐藤藤三郎『狸森物語 山あいの村の戦後史』を読んで 山村から戦後80年を思う  天明伸浩

18 hours 42 minutes ago
山形の山奥で90年間農民として暮らしてきた佐藤藤三郎さんがこれまでの人生を書き記した本を出版しました。藤三郎さんが全国に知れ渡ったのは、戦後まもなくの農村の現状を書いた『やまびこ学校』の級長として登場したからでしょう。やまびこ学校に描かれた山村の暮らしは、農村で暮らす若者に大きな影響を与えました。多くの農村の若者にとってはやまびこ学校の農村が自分事に感じられ、その生き生きとした文章に飾り気の無い本質を感じ取ったことが窺えます。戦後の農村の出発点を克明に描いてます。
日刊ベリタ