How State Laws Meant to Protect Children Raise Other Risks
Anthony Hendricks
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
In his thought-provoking DEF CON 32 presentation, "Wu-Tang is for the Children: How State Laws Meant to Protect Children Raise Other Risks," Anthony Hendricks, a cybersecurity and data privacy attorney, dissects the complex and often counterproductive landscape of state-level children's online privacy and safety legislation. Drawing a clever parallel to the Wu-Tang Clan's infamous "for the children" claim despite their adult-oriented lyrics, Hendricks argues that many state laws, while ostensibly designed to safeguard minors, inadvertently create significant privacy risks and infringe upon fundamental rights. The core of his critique centers on the problematic implementation of age verification mandates, which often demand excessive personal data and introduce biased technologies.

Key moments
- 0:00 Talk intro and 'Wu-Tang is for the Children' analogy
- 2:00 Overview of presentation topics: children's privacy and state laws
- 2:20 Understanding COPPA: federal law protecting children online, its limitations
- 4:30 Recent federal legislative efforts: KOSA and COPPA 2.0 passed Senate
- 6:00 How states are leading children's online privacy legislation
- 6:40 Different types of state laws: social media bans, age restrictions
How State Laws Meant to Protect Children Raise Other Risks
Speakers: Anthony Hendricks
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=TuAZXkMCgXI
Overview
In his thought-provoking DEF CON 32 presentation, "Wu-Tang is for the Children: How State Laws Meant to Protect Children Raise Other Risks," Anthony Hendricks, a cybersecurity and data privacy attorney, dissects the complex and often counterproductive landscape of state-level children's online privacy and safety legislation. Drawing a clever parallel to the Wu-Tang Clan's infamous "for the children" claim despite their adult-oriented lyrics, Hendricks argues that many state laws, while ostensibly designed to safeguard minors, inadvertently create significant privacy risks and infringe upon fundamental rights. The core of his critique centers on the problematic implementation of age verification mandates, which often demand excessive personal data and introduce biased technologies.
Hendricks highlights a critical tension: the public's legitimate concern for children's online safety versus the methods states are employing to address it. With federal legislative efforts stalled, states have rapidly taken the lead, enacting a patchwork of laws that vary widely in scope and enforcement mechanisms. The presentation meticulously unpacks how these state-led initiatives, particularly those requiring stringent age verification, not only fail to adequately protect children but also erode the privacy and First Amendment rights of all internet users.
This talk is crucial for anyone navigating the evolving terrain of online privacy, particularly those in cybersecurity, legal, and policy fields. It underscores the urgent need for a more coherent and constitutionally sound approach to protecting minors online, one that balances safety with fundamental freedoms and avoids creating new vulnerabilities through poorly conceived legislative mandates. Hendricks' analysis serves as a stark warning against rushed, broad-stroke legislation that prioritizes perceived protection over actual privacy and equity.
Background
▶ Watch: Talk intro and 'Wu-Tang is for the Children' analogy (0:00)
The impetus for state-level action on children's online privacy stems from a perceived vacuum in federal legislation, which has struggled to keep pace with the rapid evolution of the internet and digital technologies. The foundational federal law, the Children's Online Privacy Protection Act (COPPA), was enacted in 1998 in response to early concerns about children's data collection online. COPPA, initially a "remix" of industry guidelines from the Children's Advertising Review Unit, primarily protects children under the age of 13 by requiring certain disclosures and parental consent for data collection. Its rules were updated in 2013 to broaden the definition of personal information and in 2017 to include Internet of Things (IoT) devices.
However, Hendricks points out critical limitations of COPPA. Its definition of a "child" as under 13 is increasingly outdated, leaving teenagers—a demographic highly vulnerable online—largely unprotected. Moreover, the law was not designed for the pervasive, data-intensive nature of the modern internet. Despite repeated calls for stronger protections, including President Biden's consistent advocacy in State of the Union addresses for three consecutive years, substantive federal action has been slow. While proposed legislation like the Kids Online Safety Act (KOSA), the Teen's Online Privacy Act, and COPPA 2.0 have gained bipartisan support and even passed the Senate (91-3 for KOSA and COPPA 2.0), they have stalled in the House of Representatives, leaving a legislative void.
This federal inaction has prompted states to step into the breach, with California often leading the way. In 2022, California passed the Age Appropriate Design Code (AADC), which mandates digital platforms to assess and mitigate risks to children and apply stricter privacy settings by default. This spurred a wave of similar legislative activity across the nation; last year, 35 states and Puerto Rico debated proposed laws, and 12 state legislatures continue to consider new legislation this year. These state laws vary widely, ranging from outright bans on social media for minors (e.g., Montana banning TikTok, Utah and Arkansas banning social media for all minors) to age restrictions (e.g., Arkansas, Louisiana, and Utah for users under 13), restrictions on features like targeted advertising, and bans on collecting minors' personal information. While well-intentioned, this fragmented and often overlapping state-level approach creates a complex legal and operational challenge for online platforms and, more significantly, introduces a host of unintended consequences for user privacy and fundamental rights.
Key Findings
▶ Watch: Understanding COPPA: federal law protecting children online, its limitations (2:20)
Anthony Hendricks' presentation meticulously uncovers several critical findings regarding state-level children's online privacy laws, highlighting their paradoxical nature and far-reaching implications. The central discovery is that these laws, despite their stated aim of protecting children, often introduce significant privacy risks and constitutional challenges, effectively creating more problems than they solve.
Firstly, the speaker identifies that the widespread requirement for age verification is the primary driver of these unintended consequences. To comply with state mandates, companies are forced to implement mechanisms to determine a user's age, which often involve demanding excessive personal information. These methods include direct validation via credit cards or government-issued IDs, reliance on digital intermediaries like Allpass Trust, or even speculative age estimation techniques using facial recognition via cameras or algorithms analyzing online activities.
Secondly, Hendricks reveals that these stringent age verification demands lead to a concerning over-collection of sensitive data. Users are compelled to surrender highly personal information—such as identification documents, credit card details, and even biometric data—to companies that may not be equipped to secure it. This directly contradicts the goal of enhanced privacy, as it centralizes more sensitive data, making it a more attractive target for cybercriminals and increasing the potential for data breaches.
A third key finding is the inherent inaccuracy and bias within many age verification technologies, particularly those relying on biometrics. Hendricks points out that facial recognition systems, often trained predominantly on data sets of white men, struggle to accurately identify the age of women and people with darker skin tones—a phenomenon he wryly terms the "black doesn't crack problem." This bias can lead to discriminatory outcomes, where certain users are misidentified or unfairly subjected to additional scrutiny, effectively denying them access to online platforms despite meeting age requirements.
Furthermore, the speaker highlights that these laws create exclusionary barriers for vulnerable populations. Individuals who do not possess a credit card or a government-issued ID, such as younger teens, those in lower socioeconomic brackets, or undocumented individuals, may be effectively locked out of online services, including social media, which are increasingly integral for communication and access to information. This undermines the principle of equitable access to online spaces.
Finally, Hendricks underscores the critical First Amendment challenges posed by these laws. Federal courts have already granted preliminary injunctions blocking laws in Arkansas, California, and Texas, citing their likely violation of First Amendment rights. The First Amendment protects not only individual speech (including that of children) but also the speech of companies. Mandating age verification methods that restrict access or force platforms to censor content based on age raises serious questions about freedom of expression and access to information for all users. The trade-off, as Hendricks concludes, is an "unfair trade," where potential, often flawed, protections come at the cost of fundamental privacy and free speech rights.
Technical Deep Dive
▶ Watch: Recent federal legislative efforts: KOSA and COPPA 2.0 passed Senate (4:30)
The technical ramifications of state-level children's online privacy laws primarily revolve around the implementation and inherent flaws of age verification mechanisms, which are mandated to enforce age restrictions on digital platforms. Anthony Hendricks categorizes these laws into several buckets, each presenting distinct challenges for online services and user privacy.
The first category includes social media bans, such as Montana's ban on TikTok or broader prohibitions in Utah and Arkansas preventing minors from using social media altogether. While seemingly straightforward, enforcing such bans necessitates robust age verification to prevent minors from accessing these platforms. A related category involves age restrictions, where states like Arkansas, Louisiana, and Utah prohibit users under 13 from using social media companies. This directly impacts platform design, requiring a mechanism to differentiate between users below and above the specified age threshold.
A third type of law focuses on restrictions on features, commonly targeting targeted advertising for children. This requires platforms to not only identify minors but also to adapt their advertising algorithms and data processing practices to exclude these users from targeted campaigns. The final category involves outright bans on collecting minors' information, pushing platforms towards a "data minimization" approach for younger users, again contingent on accurate age identification.
The core technical challenge, and the source of many unintended consequences, lies in the methods employed for age verification. Hendricks details several approaches:
- Direct Validation: This involves users providing sensitive credentials such as a credit card or a government-issued ID. While seemingly robust, this method raises significant privacy concerns, as it compels users to hand over highly sensitive, personally identifiable information (PII) to potentially numerous online services. The risk of data breaches, identity theft, and misuse of this information escalates dramatically with its widespread collection. Furthermore, it excludes individuals who do not possess these forms of identification, creating a digital divide.
- Digital Intermediaries: Some solutions propose using third-party services, like Allpass Trust, which act as a central age verification provider. Users would verify their age once with the intermediary, which then attests to their age for various online platforms. While this might reduce the number of entities holding a user's raw PII, it centralizes trust in a single point of failure, making the intermediary a prime target for attacks and raising questions about its own data handling practices and privacy policies.
- Age Estimation: This is perhaps the most problematic category, encompassing methods that attempt to "guess" a user's age.
- Facial Recognition via Camera: Companies employ biometric analysis of a user's face, captured through a device's camera, to estimate if they are above a certain age (e.g., 18). Hendricks critically highlights the significant accuracy issues with these systems. He notes that such software is often "trained using white men as the model," leading to demonstrably poorer performance and bias when assessing the ages of women and individuals with darker skin tones. This "black doesn't crack problem" results in misclassifications, potentially denying access to legitimate users or allowing underage users through.
- Estimation Based on Online Activities: This method infers a user's age by analyzing their digital footprint, browsing history, social media interactions, and content consumption patterns. While seemingly less intrusive than direct biometrics, it relies on extensive data collection and sophisticated profiling algorithms. This approach raises profound privacy concerns, as it necessitates continuous surveillance and analysis of user behavior, potentially revealing far more about an individual than just their age. The accuracy of such inferential methods is also questionable, and they can easily lead to false positives or negatives, further exacerbating access issues.
The collection of biometric information, in particular, poses acute privacy and security risks. Hendricks cites significant legal settlements related to biometric data breaches and misuse, including Meta agreeing to pay $1.4 billion to settle a biometric lawsuit in Texas, Instagram's $68.5 million settlement in Illinois, and TikTok's $92 million settlement for a biometric case. These figures underscore the high stakes and potential liabilities associated with handling such sensitive data, yet state laws are pushing companies towards its collection.
From a constitutional perspective, Hendricks provides a concise primer on the First Amendment, emphasizing that it protects not only individual speech (including that of children) but also the speech of companies. Laws that mandate age verification to restrict access to content or platforms are viewed as a form of prior restraint or content-based regulation, which are subject to strict scrutiny by courts. Federal courts have already granted preliminary injunctions against state laws in Arkansas, California, and Texas precisely because these age verification requirements are seen as likely to infringe upon these First Amendment rights, creating an "unconstitutional trade" where privacy and free speech are sacrificed for uncertain protections.
Demo / Proof of Concept
▶ Watch: How states are leading children's online privacy legislation (6:00)
This presentation focused on a critical legal analysis and policy critique of state-level children's online privacy laws, rather than a technical demonstration or proof of concept. Anthony Hendricks' talk illuminated the theoretical and practical implications of these laws, particularly concerning age verification technologies and their impact on privacy and constitutional rights, without showcasing any specific tools or exploitations.
Defensive Implications
▶ Watch: Different types of state laws: social media bans, age restrictions (6:40)
The insights shared by Anthony Hendricks carry significant defensive implications for various stakeholders, from individual users to large technology companies and policymakers. Understanding these implications is crucial for mitigating the unintended risks posed by current legislative trends.
For Individuals and Parents:
- Data Minimization Awareness: Individuals should be acutely aware of the increasing demands for personal information, especially sensitive data like IDs, credit cards, and biometrics, when accessing online services. Question the necessity of such data requests and understand the privacy policies of platforms.
- Biometric Data Risks: Recognize the inherent risks associated with providing biometric information. Given the history of large-scale biometric data breaches and settlements (e.g., Meta's $1.4 billion, TikTok's $92 million), individuals should exercise extreme caution and consider the long-term implications of having their unique biological identifiers stored by multiple entities.
- Advocacy for Balanced Legislation: Engage with policymakers to advocate for federal and state laws that genuinely protect children without sacrificing broader privacy and First Amendment rights. Support legislation that is narrowly tailored, technologically informed, and equitable, rather than broad bans or intrusive verification mandates.
- Understanding Rights: Be informed about your First Amendment rights online, including those of children. Understand that not all restrictions on online access are constitutionally permissible, and be prepared to challenge overreaching regulations.
For Technology Companies and Online Platforms:
- Navigating a Patchwork of Laws: Companies operating nationally face an increasingly complex and contradictory legal landscape. They must invest in legal counsel to understand and comply with a multitude of conflicting state laws while also preparing for potential federal legislation. This necessitates a flexible and adaptable compliance framework.
- Risk of Legal Challenges: Be prepared for significant legal challenges. As federal courts have already issued preliminary injunctions against state laws in Arkansas, California, and Texas, companies implementing similar age verification mandates may face costly lawsuits and injunctions based on First Amendment violations.
- Ethical AI and Bias Mitigation: For companies developing or deploying age verification technologies, particularly those using facial recognition or other AI/ML models, it is imperative to address algorithmic bias. Invest in diverse training data sets and rigorous testing to ensure accuracy across all demographics, especially for women and people of color, to avoid discriminatory outcomes and reputational damage.
- Robust Data Protection: Any collection of sensitive user data, especially biometric information or government IDs, requires industry-leading security measures. Companies must implement strong encryption, access controls, and data retention policies to minimize the risk of breaches and comply with emerging data protection regulations.
- Advocacy for Federal Standards: Actively engage in lobbying efforts for clear, consistent, and comprehensive federal privacy standards. A unified federal approach would alleviate the burden of navigating disparate state laws and provide a more stable regulatory environment, fostering innovation while protecting users.
For Policymakers and Legislators:
- Prioritize Federal Action: The current federal inaction creates the chaotic state-level patchwork. Congress should prioritize passing comprehensive, updated federal legislation (like KOSA or COPPA 2.0) that provides clear guidelines for children's online safety across the nation.
- Narrowly Tailored Laws: Legislative efforts must be narrowly tailored to achieve specific, legitimate government interests without overreaching or infringing on fundamental rights. Blanket bans or overly broad age verification requirements are likely to face constitutional challenges and create more problems than they solve.
- Consider Practical and Equitable Implications: Before enacting laws, thoroughly assess the practical implications of proposed age verification methods. Consider their accuracy, potential for bias, and whether they create exclusionary barriers for vulnerable populations. Legislation should promote equitable access, not restrict it.
- Industry Collaboration: Collaborate closely with technology experts, privacy advocates, and industry stakeholders when drafting legislation. Their insights are crucial for creating effective, implementable, and technologically sound laws that address real-world challenges without unintended consequences.
- Focus on Education and Digital Literacy: Beyond legislative mandates, invest in educational initiatives and digital literacy programs for children, parents, and educators. Empowering users with knowledge and skills is a powerful defensive tool against online risks.
Key Takeaways
- Federal inaction has fueled a problematic state-level legislative surge: The lack of updated federal laws like COPPA has created a vacuum, leading states to enact a fragmented and often conflicting array of children's online privacy and safety laws.
- Age verification mandates create significant privacy and rights risks: Many state laws require stringent age verification, compelling users to provide excessive personal data, including sensitive biometric information, government IDs, or credit cards, to access online platforms.
- Biometric age verification technologies are often flawed and biased: Facial recognition systems used for age estimation frequently exhibit accuracy issues and algorithmic biases, particularly for women and people of color, leading to misidentification and potential discrimination.
- These laws can create exclusionary barriers: The reliance on traditional forms of identification for age verification can effectively lock out individuals without credit cards or government IDs, exacerbating digital divides for vulnerable populations.
- State laws face substantial First Amendment challenges: Federal courts have issued injunctions against several state laws, citing likely violations of First Amendment rights, which protect both individual and company speech, highlighting a fundamental constitutional conflict.
- The current legislative trend represents an "unfair trade": The push for perceived children's protection through these state laws often demands a surrender of fundamental privacy and free speech rights, without guaranteeing effective or equitable safety outcomes. Effective solutions require narrowly focused laws, consistent federal standards, and collaboration with industry.
About the Speaker(s)
Anthony Hendricks is a distinguished cybersecurity and data privacy attorney based in Oklahoma City. Beyond his legal practice, Hendricks is a passionate advocate for diversity and inclusion in the technology sector. He hosts a cybersecurity podcast specifically focused on exposing underrepresented groups to the fields of cybersecurity and privacy, demonstrating his commitment to broadening access and understanding within the industry. His expertise bridges the critical intersection of law, technology, and public policy, enabling him to offer insightful critiques of complex legislative challenges.