DEV Community

Cover image for Internet Regulation Is Making Users Easier to Track, Not Cybercriminals Harder to Stop
David Timothy
David Timothy

Posted on

Internet Regulation Is Making Users Easier to Track, Not Cybercriminals Harder to Stop

The modern internet safety pitch sounds reasonable enough: verify more identities, retain more metadata, monitor more content, require more accounts, and give platforms stronger obligations to identify risky users.

Then cybercrime will become harder.

At least, that’s the theory.

I’m not convinced the theory survives contact with the actual threat model.

The strongest internet controls are usually enforced at the compliant edge of the network. They affect people visiting mainstream websites, developers running legitimate services, businesses operating in regulated markets, and users who don’t want to break the law.

Professional cybercriminals don’t stay at that edge.

They use stolen accounts, compromised devices, encrypted channels, residential proxies, offshore infrastructure, disposable domains, synthetic identities, money mules, cryptocurrency laundering services, and crime-as-a-service marketplaces. When one route closes, they move to another. When one platform tightens its rules, they migrate. When identity checks become mandatory, stolen identity data becomes more valuable.

That doesn’t mean regulation never works. It means we’re often regulating the population that’s easiest to regulate while describing the result as a victory over the population that’s hardest to regulate.

The uncomfortable version is much simpler:

Cybercriminals adapt. Ordinary users get monitored.

That’s an editorial thesis, not a universal law. Some controls do stop abuse. Some investigations depend on retained records. Some age checks appear to deter minors from reaching harmful content. There are legitimate reasons to regulate online services.

But if the goal is reducing cybercrime, we should be brutally honest about who is bearing the cost, what threat is actually being addressed, and whether the control reaches determined adversaries at all.

We keep combining completely different threat models

A basic mistake runs through a lot of internet regulation: policymakers use “online safety” as a bucket for problems that have almost nothing in common technically.

Consider the differences:

  • A teenager trying to access age-restricted content
  • A ransomware affiliate exploiting an unpatched VPN appliance
  • A fraud ring running thousands of AI-assisted phishing messages
  • A person posting illegal material on a mainstream platform
  • A botnet operator controlling compromised home routers
  • An adult anonymously viewing lawful but sensitive content
  • A state-backed group stealing credentials from government employees

These aren’t variations of the same problem.

They involve different adversaries, capabilities, incentives, infrastructure, and failure modes. They require different defenses.

Age assurance might deter a teenager who reaches a mainstream site and sees a verification screen. It doesn’t stop a ransomware operator from buying initial access to a corporate network.

Mandatory accounts can make casual platform abuse more inconvenient. They don’t reliably identify an attacker using stolen credentials, fake documents, an infected machine, or a recruited account holder.

Mass data retention can give investigators useful historical records. It doesn’t patch vulnerable software, block credential theft, secure a supply chain, or prevent someone from authorizing a fraudulent wire transfer.

Content monitoring may remove illegal material from a cooperating platform. It doesn’t automatically eliminate the material from encrypted groups, self-hosted services, obscure forums, or infrastructure outside the regulator’s reach.

This distinction matters because governments can introduce a very visible control and then let the public assume it addresses a much broader security problem.

An identity prompt feels like security. A blocked page looks like enforcement. A removed account becomes a measurable platform action.

None of those things necessarily tell us whether serious cybercrime has declined.

Cybercrime is not showing signs of being regulated into submission

The FBI’s Internet Crime Complaint Center received more than one million complaints in 2025, with reported losses of roughly USD 20.9 billion. That represented a 26 percent increase in reported losses from 2024.

Those figures don’t measure all cybercrime. They’re based on reported complaints, reporting behavior can change, and the numbers don’t prove that internet controls caused or failed to prevent any particular crime.

Still, they make one point difficult to avoid: expanding digital regulation has not been accompanied by an obvious collapse in online fraud, phishing, extortion, data theft, or investment scams.

Europol’s 2026 cybercrime assessment describes a criminal environment built around encrypted communications, proxy services, cryptocurrencies, automation, specialized marketplaces, and rapidly shifting infrastructure. Dark web markets and forums remain resilient even after law enforcement disruptions because participants fragment, migrate, and regroup.

ENISA has reported a similar pattern around ransomware. Disrupted ransomware-as-a-service brands are quickly replaced, leaked builders lower the barrier to entry, and operators continuously update their tooling. Attackers now buy specialized services for access, malware delivery, credential theft, endpoint defense evasion, hosting, negotiation, and money laundering.

This is what an adaptive adversary looks like.

A cybercrime operation doesn’t need every component to survive. It needs replaceable components.

Take down a forum, and users move to another forum or an encrypted channel. Seize a domain, and the operator rotates domains. Block a hosting provider, and the infrastructure moves. Freeze one wallet, and laundering services split funds across new wallets, assets, exchanges, and jurisdictions.

Law enforcement operations still matter. Disruption imposes costs, generates intelligence, creates distrust inside criminal communities, protects potential victims, and sometimes leads to arrests. I’m not arguing that enforcement is pointless.

I’m arguing that a temporary disruption shouldn’t be confused with eliminating the ecosystem.

Meanwhile, the ordinary user isn’t operating a replaceable international infrastructure stack. That user has one phone number, one home connection, one government identity, a few mainstream accounts, and a limited willingness to fight an automated moderation or verification system.

The criminal can rotate infrastructure.

The user becomes the infrastructure being measured.

Age verification shows the problem in miniature

Age assurance is probably the clearest example of both sides of this debate being partly right.

Protecting children from pornography and other harmful content is a legitimate goal. Pretending that an “I’m over 18” button accomplishes that goal is obviously weak. If a service is legally restricted by age, some kind of meaningful age check can make sense.

The United Kingdom’s Online Safety Act brought major age-assurance requirements into force in 2025. Services covered by the rules must use highly effective methods to prevent children from accessing pornography and certain other harmful content.

Ofcom’s first major assessment, published in July 2026, found evidence that these checks can work. More than 69 million age checks were completed across a sample of 32 services between July and December 2025. By June 2026, all of the UK’s ten most popular pornography services and 64 of the top 100 had introduced age checks. Some children appeared to be deterred when they reached a protected service.

That’s real evidence in favor of regulation. It shouldn’t be dismissed.

But the same report exposes the displacement problem.

Almost half of the pornography services visited by children in Ofcom’s research had no age checks. Search engines continued to surface unprotected sites. Compliant services lost traffic while some services without checks gained popularity.

The control changed the path. It didn’t eliminate all alternate paths.

VPN usage also rose sharply after the requirements took effect. Ofcom estimated that daily UK VPN users increased from around 1.2 million before July 25, 2025, to 2.2 million afterward. The regulator correctly warned that this correlation doesn’t reveal how much of the increase was caused by age-check circumvention, or how many of those users were children.

That caveat is important. “VPN usage increased” is not the same as “everybody bypassed the law.”

Ofcom’s research found relatively low self-reported circumvention, though it also acknowledged possible response bias. It found that some determined children were using VPNs, borrowed credentials, spoofed images, and other techniques to get around controls. There wasn’t enough evidence to determine the full scale.

So the honest conclusion isn’t that age verification is useless. It’s that it works best against users who accept the default path.

That category includes plenty of minors, which may justify the intervention. It also includes practically every ordinary adult who now has to decide whether to give a website or verification vendor a face scan, payment signal, identity document, phone number, or reusable credential.

The bypass cost is unevenly distributed.

A determined user needs to find one weak site, one effective VPN, one reusable account, or one verification workaround.

A compliant platform has to verify everyone.

Identity verification creates a second security problem

There’s a recurring assumption that if an online account is connected to a real identity, abuse becomes easy to stop.

That’s far too optimistic.

Identity proofing answers a narrow question: does the person completing this process appear to control acceptable evidence associated with an identity?

It doesn’t answer:

  • Is this person acting voluntarily?
  • Was the identity evidence stolen?
  • Is someone controlling the device remotely?
  • Is the account being created for resale?
  • Is the user working as a money mule?
  • Will the account be compromised tomorrow?
  • Is the person legally identified but still malicious?

A verified identity is not the same thing as a trustworthy identity.

Banks already perform extensive know-your-customer checks, yet criminals continue to access financial systems through stolen identities, synthetic identities, compromised accounts, shell companies, recruited intermediaries, and legitimate account holders deceived into moving money.

The more identity checks we require, the more valuable the supporting data becomes.

Now the platform or its vendor may hold combinations of:

  • Government ID images
  • Facial images or biometric templates
  • Birth dates
  • Addresses
  • Phone numbers
  • IP addresses
  • Device attributes
  • Account histories
  • Verification results
  • Support conversations
  • Payment details

That collection becomes an attractive target because it can be used to defeat identity systems elsewhere.

This isn’t a hypothetical architectural concern. In October 2025, Discord disclosed that an attacker compromised a third-party customer service provider. Discord estimated that approximately 70,000 users may have had government ID photos exposed. Those images had been used for age-related appeals.

The verification system wasn’t intended to create a cybercrime opportunity. It was intended to support trust and safety. But the collected evidence became part of the attack surface anyway.

This is the part that too many policy debates skip. Every new requirement to collect sensitive information creates a new obligation to secure it, restrict access to it, define retention periods, audit vendors, process deletion requests, handle appeals, and respond to breaches.

Security teams understand this instinctively:

Data you don’t collect can’t be stolen from your database.

NIST’s current digital identity guidance treats privacy risk assessment, data minimization, retention, third-party processing, redress, and encryption as core requirements. That’s good engineering guidance, but it also confirms the underlying point. Identity proofing introduces risks serious enough to require an entire control framework of its own.

We’re creating sensitive data systems to enforce safety rules, then creating more safety rules to protect the sensitive data systems.

At some point, it’s fair to ask whether the architecture is reducing total risk or relocating it.

Metadata surveillance is still surveillance

Another popular argument says that retaining metadata is less invasive than inspecting content.

Technically, that distinction is real. The body of a message is different from the time, location, participants, device, account, and network information associated with it.

In practice, metadata can reveal an enormous amount.

Imagine a system that records:

  • Which IP address used an account
  • When each session started
  • Which device identifiers were present
  • Which phone number recovered the account
  • Which accounts interacted
  • Which locations appeared over time
  • Which services received authentication requests

No individual record tells the whole story. Correlation does.

Put those records into a graph and patterns emerge: relationships, routines, workplaces, travel, medical visits, political activity, religious participation, romantic connections, and anonymous accounts tied to known identities.

The privacy risk doesn’t begin when a government employee manually opens a file. It begins when the dataset is created and made linkable.

European courts have repeatedly wrestled with this issue. The Court of Justice of the European Union has restricted general and indiscriminate retention of traffic and location data, while allowing more targeted retention and certain carefully constrained treatment of IP addresses and civil identity data.

The legal details are complicated, but the technical concern is straightforward. Large collections of communications metadata can support precise conclusions about private life, especially when multiple categories of data are combined.

There is a legitimate counterargument here. Investigators often need historical records. A victim may report an attack weeks after the initial intrusion. Infrastructure logs can connect accounts, domains, IP addresses, payments, and devices. Without preserved evidence, attribution may be impossible.

The choice, though, isn’t simply “retain everything” or “delete every log immediately.”

There’s a meaningful difference between:

  • Targeted preservation tied to an investigation
  • Time-limited operational security logs
  • Emergency preservation orders
  • Retention based on documented risk
  • General collection covering an entire population
  • Indefinite cross-platform identity correlation

A democratic government can have lawful investigative powers without treating every user as a future query result.

The standard should be necessity and proportionality, not “this data might be useful someday.”

Developers are becoming an unofficial enforcement layer

Internet regulation doesn’t execute itself. Developers turn policy into databases, APIs, classifiers, logging pipelines, review queues, account states, geolocation rules, and access-control decisions.

That creates consequences far beyond large platforms.

A major company can hire policy teams, trust and safety specialists, privacy lawyers, vendor auditors, appeals staff, and regional compliance engineers. A small forum, open-source community, indie service, or niche social application may have none of that.

When compliance becomes too expensive or legally uncertain, smaller services tend to choose from a short list of bad options:

  • Block users in the affected jurisdiction
  • Require accounts where none were previously needed
  • Outsource identity checks to another company
  • Collect more data to prove compliance
  • Remove broad categories of lawful content
  • Shut down user-generated features
  • Close the service

That shifts power toward the largest platforms because they’re the organizations most capable of operating a global verification and surveillance stack.

It also encourages over-enforcement.

If a platform faces severe penalties for under-blocking but little consequence for over-blocking, the rational engineering decision is predictable. Set conservative thresholds. Collect additional signals. Restrict ambiguous content. Lock questionable accounts. Make users appeal.

False positives become somebody else’s problem.

For an ordinary user, “somebody else” means being unable to access an account, publish lawful content, use a privacy tool, or participate without providing more personal information.

For a criminal operation, a false positive means burning one account and loading another.

Again, the burden isn’t symmetrical.

Safety controls aren’t useless, but they need to match the adversary

It would be easy to turn this into an argument against all regulation, all logging, or all identity verification. I don’t think that position holds up.

Age checks can deter access.

Platform moderation can remove abusive material.

Financial identity requirements can make laundering more difficult.

Logs can help investigators reconstruct attacks.

Infrastructure seizures can interrupt criminal operations.

Account verification can increase the cost of spam and coordinated abuse.

The problem is not that controls never work. The problem is expanding them without measuring substitution, displacement, privacy loss, market concentration, and adversarial adaptation.

A useful security control should be evaluated against the attacker’s next move, not just the attacker’s current move.

If a regulated site introduces age checks, do users migrate to unregulated sites?

If a platform requires government ID, does the market for stolen verified accounts expand?

If a country blocks a service, do users move to encrypted or offshore alternatives?

If providers retain more identifying data, does that dataset become a new extortion target?

If automated monitoring produces large numbers of false positives, can users realistically appeal?

If a ransomware brand is disrupted, how quickly are its affiliates absorbed by another operation?

These aren’t arguments for doing nothing. They’re the questions that should determine whether a control is actually working.

We can verify eligibility without building an identity panopticon

From a developer’s perspective, one of the most frustrating parts of this debate is that privacy and verification aren’t always opposites.

A service may need to know that a user is over 18. It usually doesn’t need the user’s full name, exact birth date, home address, document number, and identity photo.

That difference should drive the architecture.

W3C’s Verifiable Credentials model explicitly recommends abstract claims such as ageOver instead of exposing a date of birth. Selective-disclosure systems can allow a user to reveal a required attribute without handing every verifier the underlying identity record.

A more privacy-preserving age flow could look like this:

  1. A trusted issuer verifies the user’s age.
  2. The user receives a cryptographically protected credential.
  3. A website requests proof that the user is above a threshold.
  4. The user presents only that age claim.
  5. The website validates the proof without receiving the original identity document.

That’s better than uploading a passport to every site.

It still isn’t magically anonymous. Long-lived identifiers can allow correlation. Centralized status checks can reveal where credentials are used. Browser fingerprinting, account cookies, IP addresses, and payment data can reconnect a supposedly minimal credential to a persistent profile.

Cryptography can reduce disclosure. It can’t compensate for a system designed to correlate people everywhere.

Privacy-preserving regulation therefore needs both technical and legal limits:

  • Collect the minimum attribute required
  • Avoid persistent cross-site identifiers
  • Prohibit unrelated reuse of verification data
  • Keep identity documents away from content platforms
  • Use short retention periods
  • Require independent security testing
  • Publish false-positive and appeal statistics
  • Make vendors directly accountable for breaches
  • Support anonymous or pseudonymous access where identity isn’t necessary
  • Require evidence that a measure reduces the targeted harm
  • Add sunset clauses when that evidence never appears

Most importantly, governments should focus more aggressively on the infrastructure and economics of cybercrime itself.

That means faster patching of public systems, secure software procurement, ransomware-resistant backups, disruption of bulletproof hosting, action against laundering networks, international evidence sharing, recovery of stolen funds, stronger authentication, anti-spoofing improvements, and support for victims.

Those measures aren’t as politically visible as an ID screen. They’re also much closer to the systems criminals actually depend on.

The safest internet is not automatically the most identifiable one

The debate over internet control is often framed as safety versus chaos.

That’s a false choice.

The real question is what kind of safety we’re buying, who pays for it, and what infrastructure of control remains after the original crisis has passed.

A narrowly designed age check may protect children. A targeted preservation order may help catch an attacker. A properly scoped platform rule may reduce abuse.

But those limited successes don’t justify turning identity collection, behavioral monitoring, metadata retention, and cross-platform enforcement into the default architecture of the internet.

Once that architecture exists, it won’t only be used against ransomware gangs and fraud networks. It will shape how everyone accesses information, speaks, builds communities, distributes software, and participates online.

Sophisticated criminals will keep searching for the weakest jurisdiction, the easiest victim, the next stolen account, and the newest bypass.

Ordinary users will keep using the services in front of them.

That’s the disconnect I think we need to confront. Governments can make the compliant internet dramatically more observable without making the criminal internet equally transparent.

So when the next safety proposal arrives, I don’t just want to hear how many identities it can verify, how much data it can retain, or how many accounts it can block.

I want a clear answer to the harder question:

Are we making cybercrime harder, or are we mainly making ordinary people easier to watch?

Sources

Top comments (0)