decrypted · 24 september 2026 · vulnerabilities and patching · uk policy and law · surveillance and privacy

Ofcom asks Pornhub's owner if it tested the age check it borrowed from Apple

On 23 September Ofcom opened an investigation into Aylo, the company behind Pornhub, under the Online Safety Act. The interesting part is the method: since May, Pornhub has relied on signals from Apple suggesting that a UK visitor has passed Apple's own age checks. Ofcom is not judging Apple. It is asking whether Aylo tested that arrangement properly before trusting it. That question applies to any UK organisation that has ever bought a control from someone else.

What Ofcom is actually asking

Ofcom says it will examine whether Aylo used "highly effective age assurance" to keep children away from pornography, and whether it completed a "suitable and sufficient children's access assessment". Providers, it says, must do that assessment before making any significant change to the design or operation of their service. It adds: "Our investigation will not make a determination on how Apple operates its age checks."

An investigation is not a finding. Aylo says it believes Apple's device-level check is among the hardest to circumvent protections available. If Ofcom finds a breach, fines can reach £18 million or 10% of qualifying worldwide revenue, whichever is greater.

The wristband problem

Picture a nightclub that stops checking ID because another venue's wristband says the wearer is over 18. The wristband may be excellent. But the licence belongs to the club, so the club has to know what the wristband proves, who can obtain one, and what happens when a wristband is missing or looks odd.

Ofcom's own wording is telling. The signals "suggest" users "may have completed" Apple's checks. A signal that suggests something is evidence, not a verdict. Between evidence and decision sit design choices: what counts as a pass, what happens when the signal is absent or ambiguous, and how you would notice if the whole arrangement were quietly failing. An access assessment exists to answer those before launch.

The Secure by Design lesson

Secure by Design says the party that ships the service owns its safety. Buying in a component does not buy in the duty. The decisions that matter are unglamorous:

Ofcom's expectation that a fresh assessment precedes any significant change is Secure by Design written into law. The same logic covers swapping an identity provider, a fraud engine or an AI model.

What it costs

None of this needs new technology. It needs someone to list every control the business relies on because a supplier says it works, gather the evidence that it does, and re-do that work whenever the supplier or the method changes. Call it a day per control. The alternative is discovering the gap in a regulator's notice, with your board asking why nobody wrote the assumptions down.

Age assurance is just where the principle became visible. Any organisation leaning on someone else's assertion, whether about a customer, a device or a login, should ask the same question: if that signal were wrong, would we know?

Also this week

AI defence is a political problem. In an NCSC blog published on 21 September, Dave Chismon, the NCSC's chief technology officer for architecture, argued that defenders cannot put AI to work as freely as attackers. He borrowed the line that all offensive problems are technical and all defensive problems are political. An exploit either works or it does not, whereas an automated fix on a live system can cause an outage of its own. The NCSC and DCMS are building "Cyber Shield", a national-scale agentic defence effort, but his advice to everyone else is modest: start with automation that advises humans rather than changes systems.

Terraform registry used to deliver malware. Aikido reported on 22 September that two Terraform providers, gocommunity-io/dockerd and kreuzwenker/docker, and two Go modules on HashiCorp's registry carried Go malware overlapping with the Graphalgo campaign, which The Hacker News reports has been attributed to North Korean actors. The lure is a fake job offer and a coding task. If you pulled any of them, reimage the machine and rotate credentials, because removing the package is not enough. Aikido also advises watching developer networks for blockchain API calls and Slack traffic.

Check Point VPN flaw exploited. Check Point said on 22 September that CVE-2026-85102, a 9.8-rated pre-authentication remote code execution flaw in VPN certificate handling on Security Gateway and Spark firewalls, has been exploited against Spark customers since 12 September. A patch shipped on 9 September. A separate management flaw, CVE-2026-93616, also rated 9.8, saw "a handful of pinpointed attacks" from 23 July. If you run these gateways, patch now and check logs for anomalous certificate-based Mobile Access logins.

Sources

If you want a second pair of eyes on the third-party controls your business leans on, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.