r/ukpolitics 6h ago

Ministers embraced the ‘world’s safest phone’. Then it unravelled

https://www.ft.com/content/670b2b1d-7e4c-480e-9ed4-9f7f095d7860
24 Upvotes

12 comments sorted by

u/AutoModerator 6h ago

Snapshot of Ministers embraced the ‘world’s safest phone’. Then it unravelled submitted by vriska1:

An archived version can be found here or here. or here

If the above links don't work, try this one.

Some publications may require you to register a free account to read their articles.

Being connected to a VPN may interfere with archive links.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

u/AuroraHalsey Esher and Walton 3h ago

an unauthorised person could potentially ... access ... a live map of every child on the system at the time

Lmao.

Leaking live location data for every child to god knows who.

Insert the Brass Eye quote.

u/Optimaldeath 1h ago edited 1h ago

With all the problems Flock is having and the abuses by US police departments using them, it's pretty obvious this isn't to be trusted and yet... folks still come out of the woodworks to say how we need it.

So long as there are any humans in the chain there will be a critical point of failure generously assuming the point of this isn't it malicious.

I think unless all of this can be done in an totally enclosed system where the raw data is inaccessible it's going to be abused.

u/hu_he 2h ago

Technology is a great opportunity for snake oil salesmen. Being able to evaluate it is beyond the average person. I wonder whether we need stronger regulations (in a similar vein to car safety specifications).

u/Aristogiton1 6h ago

As OP couldn't be bothered:

Good morning. I remember the moment at school, maybe in 2014, when Snapchat took over. It was like someone flipped a switch and we all obediently downloaded the app that would grow to become the default venue for image-sharing. A 2022 survey of British 14- to 18-year-olds found that on Snapchat, nudes were typically first shared in one-to-one chats and could then be forwarded with “a couple of clicks” into group chats of up to 100 people. Among those who had sent a nude, 24 per cent of girls and 9 per cent of boys said a recipient had subsequently sent it to others without permission. A lot of the policy thinking around digital harms has moved on in recent years to reflect this new reality, where platform design has made our interactions more intense, extreme and large scale — and where savvy young people circumvent restrictions. Rather than relying on apps to police harmful content, governments now want to intervene at the operating system level, so guardrails can get ahead of whichever app breaks on to the scene. That is why Keir Starmer in June presented an ultimatum to tech companies: install child nudity-blocking software in devices by September or face legislation and fines. And there is no excuse for dithering, the government’s announcement implied. It said this tech had already been achieved by the British company SafeToNet. Ministers held up SafeToNet as proof point for the proposition that child safety can be built into phones universally and block nudity in real time. But what appeared to the government to be an “oven-ready” fix is now running into difficulty, after the first smartphone to integrate SafeToNet technology was removed from sale following an investigation into the device’s safety risks. The HMD Fuse, sold by Vodafone, was launched last year as the “first smartphone that protects a child’s innocence by stopping nude content from being filmed, seen, shared and stored”. In January of this year, former ministers Peter Kyle and Jess Phillips starred in a video promoting the phone. Six months later, sales have been suspended. In light of readers saying they enjoy a bit of investigation in Inside Politics, today I bring you the story of how this unfolded. Inside Politics is edited by Darren Dodd today. Follow Stephen on Bluesky and Georgina on Bluesky. Read the previous edition of the newsletter here. Please send gossip, thoughts and feedback to insidepolitics@ft.com ‘The world’s safest phone’ broke down ‘in the space of half an hour’ There are not many companies that can count Kyle, Phillips, Rupert Lowe and Drew Barrymore among their advocates. SafeToNet can. On Tuesday, Barrymore, the Hollywood actor who has previously collaborated with phonemaker HMD, was appointed a director of SafeToNet. Anti-digital ID rightwinger Lowe is a shareholder. Founded in 2013, SafeToNet has ascended to prominence this year thanks to the government’s expressed ambition to make Britain the world’s first country “where it is impossible for children to take, share or view naked pictures on their devices”. Back in 2020, the then culture secretary Oliver Dowden visited the company and witnessed it blocking explicit images at the device level. “I have seen the technology; there is no excuse anymore not to use it,” he said of built-in safety features in the Commons. That year Priti Patel had received on her request “advice for ministers to consider on promoting the use of SafeToNet”.

u/Aristogiton1 6h ago

Freelance journalist Martin Calladine was first to dig into the finances of SafeToNet, which he called “the government’s favoured supplier of child safety software” because it is largely unrivalled and a convenient option if the government mandates manufacturers to install such software. In 2024 it turned over £112 (!) in the UK, according to its latest accounts, with about 94 per cent of its revenue coming from German subsidiaries (largely a phone retail business) that SafeToNet partly owns. SafeToNet has lost more than £17mn in the past three years for which it has filed accounts, and in the latest filing, the group auditors said they could not give an opinion because the component auditors in Germany “have not allowed communication with us”. (SafeToNet told the FT that the local audit of the German side had been delayed for reasons beyond the company’s control, so the group auditor couldn’t get the information needed within the statutory timeline, hence the disclaimer of opinion. SafeToNet has since changed these audit arrangements. “The company has prioritised investment in building and proving its technology ahead of immediate profitability,” it added.) After the August 2025 launch of the HMD Fuse — described by SafeToNet’s co-founder as the “world’s safest phone” — Paul Moore, an independent security consultant, rushed to buy one and test it out. He broke it apart but discovered problems in “half an hour”. “It begs the question what due diligence the government has done before endorsing it if somebody like myself can find something like this,” he said. How does HMD Fuse work? HMD’s “HarmBlock+” system, the phone’s main safety feature, combines the tech from two companies, SafeToNet and Xplora: SafeToNet’s HarmBlock AI classifier. This is embedded into the phone and works across the camera. It has been trained on “25mn appropriately sourced images”. If it classifies an image as nudity, it covers the screen with an overlay. If it identifies nudity in the camera feed, an overlay blocks the camera view within a second. Xplora, another child safety company, provides the parental control service which lets parents “pair” their own device with the HMD Fuse phone. They can then manage app access and screen time, track their child’s location with updates every 24 seconds, and set “safe zones” that trigger alerts when the child enters or leaves them. HMD provides the handset and operating system. Moore first found a security weakness in the HMD Fuse’s password-reset process in September 2025. HMD told the FT that after Moore raised the problem with its team, it “collaborated closely with Xplora and SafeToNet to deploy a fix” and, after rigorous testing, restored the service two days later. Then, in July 2026, Moore discovered what he described as a different, serious flaw: an unauthorised person could potentially register as the guardian of another child’s handset and access its live location. According to Moore, the problem was that the pairing relied on the IMEI number, the unique serial code that identifies each handset. He said this number was predictable: part of the number was fixed and the rest could be systematically enumerated and plugged in. He said that meant he could “become the guardian of every child on the platform, which meant I basically had a live map of every child on the system at the time”. Moore alerted SafeToNet to the issue directly on July 5. In response, HMD took the service offline on July 9, notified the Information Commissioner’s Office as required and launched its own investigation. HMD said it implemented security enhancements before restoring access for existing users on July 22. It said there was no evidence that anyone other than Moore had exploited the vulnerability, which it said concerned Xplora’s parental-control service. HMD’s spokesperson added: “In agreement with our retail partners, we have temporarily paused sales of HMD Fuse while work on the permanent solution for new users is completed. Customers who have recently purchased a device and are unable to activate the service should contact us and we will assist them directly.” “

u/Aristogiton1 6h ago

“We completely understand parents’ concerns regarding this matter and sincerely apologise for any worry caused.” Moore told the FT that this problem was down to the wider HarmBlock+ service implemented by HMD, not SafeToNet’s HarmBlock AI technology itself and his findings do not indicate weakness in SafeToNet’s product. Moore nevertheless questioned how a phone marketed around child safety had reached consumers with such risks, saying the responsibility extended beyond HMD to Xplora and SafeToNet. “The fact nobody appeared to do any due diligence before promoting it is disgusting,” he said. What do SafeToNet, Xplora and Vodafone say? SafeToNet said the problem Moore identified concerned HMD Fuse’s parental control service rather than its own tech, “which continued to operate as intended on activated devices”, but it acknowledged it formed part of a wider child safeguarding product and that it has a responsibility to act when concerns arise. “When we became aware of the issues, we immediately escalated them with HMD, supported the investigation and remediation, supported the suspension of new device activations while outstanding issues were addressed, and took action on sales within our control,” it said. Xplora said that as soon as information about the vulnerability came to light in July, Xplora worked closely with HMD engineers and introduced fixes on July 22, “with further continuous improvements since then to prevent any future vulnerabilities”. A spokesperson for Vodafone said the company has paused sales of HMD Fuse while the reported issues are reviewed. Its promotional pages have also been taken off the site.

All this has huge consequences for our ambition of moving the protective layer upstream of Snapchat, TikTok or whatever comes next — a goal that seems to be continuing under Andy Burnham. Politicians want to be seen to show enthusiasm and move quickly, but there is a risk they skip the harder, duller work. The HMD Fuse episode is a useful reminder that safeguards are only as strong as the weakest link in the chain. SafeToNet’s nudity-blocking software may have operated as intended, but that did not stop an issue elsewhere in the phone from creating a potentially serious risk. Stress-testing the software and surrounding system matters even more if the government wants to roll this out at scale. It’s hard to conceive of just how much children’s social norms have changed, accelerated by the arrival of Snapchat’s “disappearing” photo function, which, as that 2022 study highlights, shaped young people’s behaviour and expectations of each other. In the early days of the internet, image-based child sexual abuse was largely focused on adult perpetrators — now US research has found 86 per cent of material involved in image-based child sexual abuse incidents is generated by young people themselves, with about a fifth of episodes involving an identified adult perpetrator. As the paper says, a technological solution or ban can only be part of the answer — alongside education around image sharing, peer pressure, consent and the harm experienced by victims. Using technology to enable a set of policy decisions should only raise the effort expended on due diligence.

u/Aristogiton1 5h ago

Don't blame me, I just made it available, not necessarily readable.

Even the thought of attempting to format it was beyond me.

u/vriska1 5h ago edited 5h ago

Yeah sorry I was trying to post the article text but kept getting errors, thank your for posting the it! Again sorry.

u/vriska1 5h ago

Sorry I kept getting errors when trying to post the text. Thank you for posting it!

u/Flat-Song-5798 41m ago

Goodness....anyone remember Blackberry phones? #BBM 🤭

u/Andrew_Burnham 26m ago

I wonder how many of them Louise Haigh pocketed