decrypted · 24 september 2026 · vulnerabilities and patching · uk policy and law · surveillance and privacy
Ofcom asks Pornhub's owner if it tested the age check it borrowed from Apple
On 23 September Ofcom opened an investigation into Aylo, the company behind Pornhub, under the Online Safety Act. The interesting part is the method: since May, Pornhub has relied on signals from Apple suggesting that a UK visitor has passed Apple's own age checks. Ofcom is not judging Apple. It is asking whether Aylo tested that arrangement properly before trusting it. That question applies to any UK organisation that has ever bought a control from someone else.
What Ofcom is actually asking
Ofcom says it will examine whether Aylo used "highly effective age assurance" to keep children away from pornography, and whether it completed a "suitable and sufficient children's access assessment". Providers, it says, must do that assessment before making any significant change to the design or operation of their service. It adds: "Our investigation will not make a determination on how Apple operates its age checks."
An investigation is not a finding. Aylo says it believes Apple's device-level check is among the hardest to circumvent protections available. If Ofcom finds a breach, fines can reach £18 million or 10% of qualifying worldwide revenue, whichever is greater.
The wristband problem
Picture a nightclub that stops checking ID because another venue's wristband says the wearer is over 18. The wristband may be excellent. But the licence belongs to the club, so the club has to know what the wristband proves, who can obtain one, and what happens when a wristband is missing or looks odd.
Ofcom's own wording is telling. The signals "suggest" users "may have completed" Apple's checks. A signal that suggests something is evidence, not a verdict. Between evidence and decision sit design choices: what counts as a pass, what happens when the signal is absent or ambiguous, and how you would notice if the whole arrangement were quietly failing. An access assessment exists to answer those before launch.
The Secure by Design lesson
Secure by Design says the party that ships the service owns its safety. Buying in a component does not buy in the duty. The decisions that matter are unglamorous:
- Write down what you assume the third-party signal proves, and what it does not.
- Test the control against people who should fail it, not only people who should pass.
- Measure failure in production, so you find out before anyone else does.
- Decide in advance whether the service fails closed or open when the signal disappears.
Ofcom's expectation that a fresh assessment precedes any significant change is Secure by Design written into law. The same logic covers swapping an identity provider, a fraud engine or an AI model.
What it costs
None of this needs new technology. It needs someone to list every control the business relies on because a supplier says it works, gather the evidence that it does, and re-do that work whenever the supplier or the method changes. Call it a day per control. The alternative is discovering the gap in a regulator's notice, with your board asking why nobody wrote the assumptions down.
Age assurance is just where the principle became visible. Any organisation leaning on someone else's assertion, whether about a customer, a device or a login, should ask the same question: if that signal were wrong, would we know?
Also this week
AI defence is a political problem. In an NCSC blog published on 21 September, Dave Chismon, the NCSC's chief technology officer for architecture, argued that defenders cannot put AI to work as freely as attackers. He borrowed the line that all offensive problems are technical and all defensive problems are political. An exploit either works or it does not, whereas an automated fix on a live system can cause an outage of its own. The NCSC and DCMS are building "Cyber Shield", a national-scale agentic defence effort, but his advice to everyone else is modest: start with automation that advises humans rather than changes systems.
Terraform registry used to deliver malware. Aikido reported on 22 September that two Terraform providers, gocommunity-io/dockerd and kreuzwenker/docker, and two Go modules on HashiCorp's registry carried Go malware overlapping with the Graphalgo campaign, which The Hacker News reports has been attributed to North Korean actors. The lure is a fake job offer and a coding task. If you pulled any of them, reimage the machine and rotate credentials, because removing the package is not enough. Aikido also advises watching developer networks for blockchain API calls and Slack traffic.
Check Point VPN flaw exploited. Check Point said on 22 September that CVE-2026-85102, a 9.8-rated pre-authentication remote code execution flaw in VPN certificate handling on Security Gateway and Spark firewalls, has been exploited against Spark customers since 12 September. A patch shipped on 9 September. A separate management flaw, CVE-2026-93616, also rated 9.8, saw "a handful of pinpointed attacks" from 23 July. If you run these gateways, patch now and check logs for anomalous certificate-based Mobile Access logins.
Sources
- Ofcom: Ofcom launches investigation into Pornhub's age checks
- The Register: British regulator takes a hard look at Pornhub's Apple-powered age checks
- NCSC blog: One does not simply defend agentically
- Aikido Security: Graphalgo Malware Spreads to Terraform and Go
- The Hacker News: Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
- Check Point: Security Advisory, Active Exploitation of CVE-2026-85102 and CVE-2026-93616
If you want a second pair of eyes on the third-party controls your business leans on, get in touch.
More like this
- Microsoft's Windows Defender patch didn't survive the week 14 september 2026
- The Azure breach that named Vodafone, and the MFA that waved it through 18 august 2026
- Zyxel switches, a five-week campaign, and the passwords nobody changed 22 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.