Age Verification ID: Malaysia Demands Face Scans by 2026
Age Verification ID: Malaysia Demands Face Scans by 2026
This episode is based on our article:
Read the full article →Age Verification ID: Malaysia Demands Face Scans by 2026
Full Episode Transcript
For more than a year, hackers had a live feed of every government I.D. one verification company scanned. Every driver's license. Every passport photo. Streaming out in real time, and nobody noticed. More than a hundred and fifty million licenses sat exposed.
Hold that thought
Now hold that thought. Because Malaysia just told every major social media platform to start collecting exactly this kind of data, from millions of its citizens. As of June this year, if you want a social media account in Malaysia, you may have to scan your face and your national I.D. card. It's called MyKad. The goal sounds hard to argue with, keep kids under sixteen off social media. But to check a child's age, the system has to check everyone's. So here's the question threading through this whole episode. Does protecting children justify exposing every adult's identity?
Let's start with what Malaysia actually built. Under two new rules, the Children's Protection Code and the Risk Mitigation Code, platforms must verify age before you open an account. You read your MyKad smart card. Then you do a live face scan through a system called MyDigital I.D. The government says it designed this to share as little as possible with the platforms. Your details get checked against official records at the National Registration Department. On paper, that sounds careful. But that careful design is also the problem.
Because you've just created one giant pile of government I.D. images in one place. Security experts have a name for that. A high-value target. One break-in, and it's not one person exposed. It's thousands. Maybe millions. Names, addresses, birth dates, I.D. numbers, full-resolution scans of official documents. The raw material for fraud and identity theft, all in one basket.
That brings us back to that verification company I
And that brings us back to that verification company I mentioned. This wasn't a hypothetical. Reporters at Techdirt documented it. Hackers sat inside that company's system for over a year, watching every I.D. get scanned, in real time, undetected. That's the exact kind of company these age checks depend on. The people building the lock got robbed while standing next to it.
Malaysia's own history makes this land harder. The country has had repeated data leaks and breaches involving personal information. So more than seventy civil society groups asked the government to drop the blanket under-sixteen ban. Their warning was blunt. Mandatory age checks could increase the risk of data misuse, leaks, and surveillance. That's seventy-plus groups saying the cure might hurt more than the disease.
Now, the government has a real point too. Officials say self-declared age just doesn't work. Any kid can click a button and claim they're eighteen. And some child-safety advocates actually prefer government I.D. checks. Why? Because they leave a paper trail you can audit, unlike the hidden algorithms platforms use behind the scenes. That's a fair argument. The problem isn't the intention. It's the architecture.
The Bottom Line
Here's the part that reframes everything. There's a safer way to do this. Privacy-preserving age checks exist, where a third party confirms you're old enough, then instantly deletes your data and passes along nothing but a yes-or-no token. But experts say those systems aren't ready for the market yet. They need more time and money. Malaysia didn't wait. It deployed the blunt version now, the one that keeps the data instead of throwing it away.
So let's bring this home. Malaysia wants to keep young kids off social media, a goal most parents share. But to check one child's age, the system stores every adult's face and I.D. in a place hackers love to attack. And we already know those attacks happen, one lasted over a year before anyone caught it. Whether you're a parent worried about your kid or someone who just scanned an I.D. to sign up for an app, this is the same tradeoff staring back at you. Protecting children is real. But so is the pile of data it leaves behind. Check the show notes for the full piece.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
Age verification software: EU plan guards the download button
The next time your kid clicks "download" on a new game, a hidden question might pop up first. How old are you, and can you prove it? Under a leaked European plan, that check wouldn't happen inside the game. It'd happen at the store — Steam, G
PodcastBiometric Data Privacy: Walmart Keeps 512 Face Numbers
When you walk into certain Walmart stores, a camera can turn your face into a string of numbers — and then throw away the photo it started from. The picture disappears. The numbers can stay for years.
PodcastWhat Is Biometric Information: One Clause Decides Who Pays
Imagine your company gets sued for millions over how it scanned employees' fingerprints. You did nothing wrong — you followed the law. You call your insurance company, expecting them to defend you. And they point at one sentence in your polic
