Restrictions on freedom in the name of security

When freedom begins to be restricted in the name of "security": why should we be addressing the digital future right now?

25.3.2026

- digital security and freedom, and restrictions on freedom in the name of security

spolupráce Recently, several seemingly unrelated topics have emerged—the expiration of Secure Boot certificates, changes to Google Play’s policies, pressure to implement age verification, and proposed regulations surrounding 3D printing. At first glance, these are uninteresting technical or legislative details that don’t affect the average user. But... if we look at them as a whole, a common trend begins to emerge. And that affects all of us! I’ll try to summarize and explain the reasons behind my claim...

digital security and freedom, and restrictions on freedom in the name of security

What's actually going on (and why it's not just a "minor technical issue")

1) Secure Boot and dependence on manufacturers

In 2026, older security certificates used for Secure Boot will begin to expire. This is a mechanism that ensures only trusted code is executed when the computer starts up. At first glance, this seems like a good thing. The problem is that: updates to these certificates depend on the device manufacturer older hardware won’t receive updates the system will remain functional but will “freeze” in a security state This means that: the device may be fully functional but will gradually lose its ability to defend against new threats And the only “official” solution often becomes… buying a new device or switching to alternative software.

2) Google and app distribution control

Google is introducing mandatory developer verification and tightening control over what can be installed on Android and where it comes from. This doesn’t mean the immediate end of free apps. But it does mean: a higher barrier for small and community projects the gradual displacement of alternative app stores greater dependence on a single platform And above all, one fundamental shift: software is no longer just a “file,” but an “identity that must be approved”

3) Age verification and digital identity

Laws in both the U.S. and the EU are beginning to push for the implementation of user age verification. The intention (protecting children) is legitimate. But... The problem lies in implementation: someone has to manage identities someone has to guarantee their security someone decides who has access to what This raises the question: who will be that “gatekeeper,” and how much will we have to trust them?


4) 3D printing and quality control of our products

There are proposals to restrict the printing of certain objects (e.g., weapons). Again, this makes sense to me from a safety perspective, but... But technically, this means: G-code/model checks firmware restrictions the need for approval of what we print And consequently: a loss of control over one’s own device, the inability to install alternative firmware, and a real reduction in its lifespan.


The common denominator: a shift toward a managed ecosystem

Putting it all together: Secure Boot → device boot verification Google → app verification age verification → identity verification 3D printing → manufacturing verification Together, this creates a model where: hardware + software + identity = a single controlled system


Why is this happening (and why isn't it just "bad faith")

It’s fair to say that: malware exists users make mistakes security is a real problem Companies and governments are looking for solutions. But: centralizing control is the easiest solution—and not necessarily the best one

Where I think the problem lies (and why we should address it now)

This isn’t about a single specific change, but rather a trend, and that trend has several consequences: dependence on the manufacturer restrictions on free software shorter device lifespans greater control over users and their data where there is data, there is a risk of leaks and misuse And, somewhat paradoxically: an environmental impact—because devices that could still function end up as waste


Is there a better way? Yes—but we need to talk about it

Possible solutions exist: longer security support for devices separating certificates from the manufacturer more open firmware multiple independent "trust authorities" instead of just one All of this is technically possible. What’s missing is pressure.


What an individual can do

If you're a developer: you can provide feedback to Google join the discussion (issue trackers, blogs, communities) Google Play Developer Support https://support.google.com/googleplay/android-developer/ Mobilmania, among others, has written extensively about this: https://mobilmania.zive.cz/clanky/protest-proti-googlu-sili-povinna-registrace-vyvojaru-muze-zmenit-android-k-nepoznani/sc-3-a-1364301/default.aspx

If you're a user:

  • talk about it
  • share information
  • support open-source software

If you are a U.S. citizen:

  • You can contact your representatives
  • Legislation in these areas is currently being drafted

  https://www.usa.gov/elected-officials


Why I think it makes sense

This isn’t the first time public pressure has brought about change. There are examples:
  • major companies revising their policies in response to criticism
  • changes to legislative proposals
  • Microsoft’s recent withdrawal of updates and changes
If the issue isn’t discussed, nothing will change If it’s discussed enough, change is possible  

My conclusion

Security is important. But if we address it solely through centralization and control, we may lose something just as important:
  • the freedom to use your own devices
  • the ability to create and share software
  • the long lifespan of technology
And this isn’t just a technical issue. It’s a question of the direction our digital society will take.

Použité zdroje

 

Omezení svobody ve jménu bezpečnosti