> ## Content Index
> Fetch the complete content index at: https://goodoil.news/llms.txt
> Use this file to discover other available public pages before exploring further.

# A Law That Can Be Defeated With a Pen
- URL: https://goodoil.news/a-law-that-can-be-defeated-with-a-pen/
- Published: 2026-08-26T22:30:52.000Z
- Updated: 2026-08-26T22:30:51.000Z
- Description: A critique of the Online Safety (Minimum Age and Child Safety Risk Assessment) Bill
- Author: Reproduced with permission
- Tags: NZ Politics, Free Speech, Censorship, Technology

[**David Harvey**](https://djhdcj.substack.com/p/a-law-that-the-people-it-targets)  
*Retired district court judge*

*The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill was introduced on 24 August 2026 – the very day I arrived back in New Zealand after nearly a month away.*

*Readers of A Halfling’s View will be well aware of my views about bans or restrictions on access to social media platform for the young. Although the news media have trumpeted the present proposals as a ‘ban’ it is not. It actually constitutes a form of limited restriction.*

*This article is very much a ‘first impression’ view of the bill. Much of the material and commentary is gathered from earlier writings I have produced on the subject as well as from other sources, among them Ani O’Brien, “Thought Crimes” (Substack) – “Hear me out: Ban the hardware not the software”; the New Zealand Initiative; Privacy Commissioner Michael Webster; UNICEF Aotearoa (Susan Glasgow); Australia’s eSafety Commissioner three-month evaluation (July 2026); UK Ofcom/House of Lords material and reporting on the Online Safety Act; and US litigation (NetChoice; the Louisiana and Arkansas decisions).*

*Furthermore, this article (and indeed the bill itself) will not be the final word.*

*The bill has not yet had its first reading and that is unlikely before parliament rises. But Prime Minister Luxon and Erica Stanford were determined to push this ill-advised proposal ahead at pace, even although what it really amounts to is an announcement until the bill has its first reading. And it may even fall at that fence. If it makes it, select committee submissions and further commentary will accumulate quickly.*

*Hence the critique reflects the position as at the time of publication of this article.*

**What the bill actually does**

The Online Safety (Minimum Age and Child Safety Risk Assessment) Bill, introduced to parliament on 24 August 2026 by Education Minister Erica Stanford, is a stand-alone statute built on two load-bearing duties.

The first (clause 11) requires operators of ‘age-restricted platforms’ to take reasonable steps to stop New Zealanders under 16 from *holding an account*. The second (clause 14) requires those operators to produce an annual, written child-safety risk assessment covering all under-18s who use the platform.

Behind these sit an enforcement apparatus of warnings, enforceable undertakings, corrective notices, tiered pecuniary penalties (up to the greater of NZ$40 million or 10 per cent of global turnover), and, as a last resort, service restriction orders and access restriction orders that would conscript ISPs, app stores and ancillary providers into preventing access to the platform from New Zealand.

The regulator is the Secretary of Internal Affairs – the chief executive of the Department of Internal Affairs (DIA). More on this disturbing aspect later.

Much of the drafting is careful.

It regulates the *account*, not the child, so no penalty falls on minors or parents.

It explicitly forbids treating manual date-of-birth entry as a “reasonable step”.

It goes beyond the Privacy Act by requiring destruction of age-assurance data.

The bill is also more sophisticated than the ‘ban’ it is marketed as. As I have argued on earlier occasions about similar proposals, this is a set of *managed restrictions on account-holding*, not a prohibition on children seeing content. Publicly available material remains reachable.

But the care in the drafting cannot rescue the concept.

The bill imports a policy model that has already been trialled next door in Australia and in Britain, and the trials are in.

What follows is the case against it – a case now supported by a striking amount of hard evidence rather than speculation – followed by the specific problem of handing the whole scheme to the DIA.

**The central flaw: a ‘targeted’ measure that touches everyone**

The bill’s rhetorical appeal rests on the idea that it targets under-16s. Its mechanism does not.

To reliably prevent a 15-year-old from *holding* an account, a platform must satisfy itself about the age of *every* account holder – which in practice means age-assuring the entire adult population as well.

Privacy Commissioner Michael Webster made the point bluntly when the policy was first floated. Keeping under-16s out means everyone over 16 has to prove they are over 16\. The New Zealand Initiative put it the same way – everyone will have to demonstrate they are *not* under 16, including you.

This is the paradox the bill never resolves, and it is not a drafting quibble but the whole problem.

Clause 11 forbids the ‘cheap check’ (a manual date of birth entry) and forbids relying *solely* on formal ID or a digital identity service, which forces platforms toward either document upload, facial age-estimation, or ‘age inference’ from behavioural and device signals.

Each of those routes has a distinct failure mode, and none is confined to children:

- **Document verification** turns every covered service into a repository of passports and driver-licences – a honeypot of personal information sources. This is not hypothetical. In 2025 alone, Discord disclosed that attackers reached roughly 70,000 users’ government IDs (submitted partly for age-verification appeals) via a compromised support vendor, and the “Tea” app left tens of thousands of verification selfies and IDs in an unprotected cloud bucket that were then mirrored across the internet. A leaked password can be reset. A leaked passport cannot.
- **Facial age-estimation** is both spoofable (Australian teenagers reportedly defeated cameras by drawing on a moustache or making a double chin) and genuinely inaccurate in exactly the 13–17 band that matters. Testing shows mean errors of several years for adolescents, which means adults wrongly excluded and children wrongly admitted at scale.
- **Age inference** from “user activity patterns, device or account attributes” is, in plain terms, behavioural profiling – a surveillance technique the bill elsewhere lists as a *risk* to be assessed, now repurposed as a *safety* tool.

My deeper argument is that whichever route is chosen, the endpoint is the same – a durable, centralised link between a real human identity and online activity.

Once that infrastructure exists, the temptation to reuse it – for fraud, ‘misinformation’, law-enforcement access, whatever a future government decides – is, as I have put it elsewhere, the oldest story in the regulation of speech.

Ani O’Brien, writing from the Free Speech Union side of the debate, reaches the same conclusion by a different road: mandatory verification strips away the anonymity and pseudonymity that protect whistleblowers, abuse survivors, dissidents and ordinary people, and the proportionality is simply wrong – liberal societies are meant to presume adults free unless there is an overwhelming reason to constrain them, not to demand identification as the price of entry to the public square.

The bill’s privacy safeguards, though real, do not answer this.

Destroying age-assurance data ‘as soon as’ the check is complete does nothing about the structural fact that the check must happen continuously, for everyone, on every covered service – and it does nothing about the third-party verifiers who will actually hold the data.

**Does it work? Australia already ran the experiment**

New Zealand’s great advantage is that it is going second, and can watch what happened to the country that went first. Australia switched on its under-16 ban on 10 December 2025\. The results are now in, and they are not encouraging for anyone selling this as a solution.

The eSafety Commissioner’s own three-month evaluation, published 31 July 2026 and drawing on a longitudinal cohort of thousands of families, found that *81.5 per cent of Australian under-16s were still using at least one age-restricted platform* three months after the ban – down from 85.9 per cent before it.

That is a reduction of about four percentage points. Most children were using social media *as frequently* in March as they had been in December.

More than half said the platform they were still on had never checked their age at all. eSafety’s own framing attributes the failure to platforms not implementing effective age assurance – but that is precisely the point: the duty is “take reasonable steps”, and a platform that builds a flimsy gate and watches children climb over it has discharged its paper obligation while changing nothing.

The government’s early boast – that platforms had “removed access” to 4.7 million under-16 accounts by mid-December – turned out to include inactive and duplicate accounts, and, more importantly, the children simply walked back in with new accounts, borrowed logins and fake birthdates.

Prime Minister Albanese’s response to the disappointing data was to *double* the maximum fine to around A$99 million, which tells you which lever governments reach for when the first one fails. The honest verdict came from a Canberra 15-year-old who, on the day the law took effect, reported that “nothing changed”.

This matters for New Zealand because the bill is modelled on the Australian scheme (right down to its excluded-service categories) and shares its foundational premise: that you can keep determined teenagers off the most engaging products ever engineered by checking age at the door. I suggest that my argument is hard to rebut – a law that its targets can defeat with a felt-tip pen is not regulation: it is theatre.

And, most importantly, the evidence of that was available *before* New Zealand chose to proceed.

**The British dress rehearsal: VPNs, breaches, and an unlocked door**

Britain provides the second comparison point. When the Online Safety Act’s age-assurance duties for pornography and other ‘harmful’ content came into force in late July 2025, the public response was instantaneous.

VPN sign-ups surged – Proton reported a jump of more than 1,400 per cent within minutes; other monitors recorded UK VPN traffic climbing well over 1,000 per cent. On enforcement day, half the 10 most-downloaded UK apps were VPNs or identity tools, and a repeal petition blew past the threshold to force a parliamentary debate (later exceeding 400,000 signatures).

A VPN makes a child’s connection appear to originate abroad, returning them to exactly the unverified internet the law tried to wall off – and Ofcom was reduced to telling platforms they may not *encourage* VPN use while warning parents that a child behind a VPN loses the act’s protections entirely. The wall has a door, the door is unlocked and the regulator knows it.

To be fair to the other side — and a fair critique must be — the picture is not uniformly damning. The Age Verification Providers Association reported an additional five million age checks per day after the UK duties took effect, which suggests most users are *not* reflexively circumventing.

Ofcom’s data showed the VPN surge partly receding by October. And the LSE’s British Politics blog argued that declaring the OSA a failure was premature, since no legal regime is ever perfectly effective and enforcement adapts over time.

These are real points. But they don’t go as far as it may seem. The UK’s checks bite hardest on *pornography*, a discrete category adults are often willing to verify for, whereas the NZ bill proposes to gate *mainstream social media* – the medium of political debate, journalism and community – for a far larger and far more motivated population of teenagers.

Extending a pornography-verification regime to the public square is a change of kind, not degree.

**Can this be enforced at all?**

Enforcement is where the bill’s ambition collides with reality. A law that has enforcement problems lacks credibility. A law that is ‘circumventable’ encourages a lack of respect for the law.

There are three major problems.

First, **extraterritoriality with no leverage**. Clause 8 asserts jurisdiction over any operator, anywhere, “to the extent” a New Zealander can access the platform.

That is easy to write and hard to enforce against companies headquartered overseas with no local presence. The bill’s answer is the business-disruption tools – service restriction orders (cutting off ad servers and payment providers) and access restriction orders (requiring ISPs and app stores to block the platform, and the platform to geo-block New Zealanders). These are extraordinary powers: an access restriction order is, functionally, state-ordered site-blocking of a lawful service used by adults.

They are also the tools of a country prepared to partially disconnect itself from global platforms –and the moment they are used, the VPN dynamic that defeated the UK and Australia reappears, because a geo-block is exactly what a VPN is built to evade.

Second, **the vagueness of “reasonable steps”**. The bill deliberately declines to say how compliance is achieved, leaving “age assurance” to evolve. That flexibility is defensible, but it means the central obligation is defined by an standard the regulator will fill in later through guidance –creating uncertainty for operators and handing the DIA substantial discretionary power over what the law actually requires.

Australia’s experience shows the predictable result: platforms do the minimum, kids get around it, and the regulator’s only escalation is bigger fines.

Third, **the circumvention floor is structural, not incidental.** O’Brien’s warning is the one to carefully consider. When the first attempt fails because children find workarounds, the political temptation is always to escalate – age verification, then VPN restrictions, then device monitoring, then mandatory digital ID – until an internet built for children’s protection has been rebuilt for every adult.

New Zealand has already had the VPN-ban conversation (Stanford ruled it out – for now), which shows how quickly the ratchet turns.

**Rights, and the risk of the courts**

There is a conspicuous silence in the policy architecture. As I have earlier noted, the supporting material foregrounds vague considerations while no engagement with the New Zealand Bill of Rights Act 1990 is present – neither the section 14 right to freedom of expression (which includes the right to receive information) nor the section 5 requirement that any limit be demonstrably justified in a free and democratic society.

Restricting a class of citizens’ access to a primary medium of modern communication is a prima facie limit on expression. The honest question, as O’Brien frames it, is not whether a limit exists but whether it is *justified*.

A policy that does not appear to have run that test rigorously is legally exposed.

The clearest preview of how such laws fare under genuine judicial scrutiny comes from the United States, where roughly half the states have enacted age-verification rules and the trade group NetChoice has been litigating them – winning, on the general social-media bans, more often than not.

In December 2025 a federal court permanently struck down Louisiana’s law, warning that the state has no “free-floating power to restrict the ideas to which children may be exposed” and likening the scheme to an ID check at the library door.

An Arkansas parental-consent law was thrown out for taking a hatchet to protected speech where the Constitution demanded a scalpel.

New Zealand’s constitutional order is different – no entrenched First Amendment, a Bill of Rights that parliament can override – so the outcomes would not be identical.

But the *reasoning* remains the same. Conditioning access to lawful speech on the surrender of identity is a serious imposition on adults and children alike, not a mere formality, and a New Zealand court applying the section 5 proportionality test would have live material to work with, particularly given the Australian evidence that the measure does not deliver the benefit it claims.

**Drafting and scope problems**

Even readers sympathetic to the objective should worry about the bill’s reach.

The definition of “age-restricted platform” in clause 5 is deliberately broad, and the “specified features” that bring a service into scope, those being personalised/recommended content, endless feeds, engagement metrics and ephemeral content describe an enormous swathe of the modern internet, not just Instagram and TikTok.

The exclusions (messaging, gaming, music, reviews, professional networking, education and health) are helpful, but blunt, and they generate a perverse result that I and others have flagged in the UK context: *the most acute harms police describe – grooming, sextortion, private coercion of children – happen predominantly in messaging, which is excluded.*

A regime that imposes identity verification on the public feed while leaving the principal channel of one-to-one predation untouched has its priorities close to inverted.

The ***social AI companion*** limb (clause 5(1)(b)) captures any service using AI “solely or primarily to simulate a social... emotional... or personal connection.”

This is a genuinely fast-moving area and the concern about companion bots is serious, but the wording is imprecise enough to raise hard line-drawing questions as general-purpose AI-driven assistants acquire more social affect.

The **regulation-making powers** (clauses 61–63) let the minister add platforms, add “specified features,” add or subtract excluded activities, and exempt individual operators – all by Order in Council.

This is a lot of the law’s real content deferred to secondary legislation, subject only to a ‘necessary or desirable’ or benefits-outweigh-harm test and a duty to consult. My broader argument – that this fits a pattern of expanding executive control over the digital sphere – has force here. The scope of a speech-impacting regime should not be this movable by the executive.

Finally, the **child safety risk assessment** limb is the more defensible half of the Bill – a transparency-and-accountability duty of the kind Ian Russell, UNICEF and many critics of *bans* actually favour.

But it is welded to the age-gate, and it carries a personal-liability sting. Clause 18 requires a named senior individual to confirm accuracy, and clause 57 makes it a criminal offence (up to 12 months’ imprisonment, $500,000) to confirm an assessment “knowing it to be false or misleading in a material particular.”

Whether that individual-liability hook helps or simply deters good people from taking the role is an open question.

**The strongest critique**

The most powerful objection comes not from libertarians but from the person with the most painful standing in the debate. Ian Russell – father of Molly Russell, the 14-year-old who died in 2017 after the platforms served her a stream of self-harm content – opposes the blanket ban.

His argument is that “Bans are the wrong answer to a vital question.” A prohibition shifts the burden *from* the companies, who would otherwise have to make their products safe as a condition of operating, *onto* a verification gate the companies are happy to hide behind.

Once the legal duty is ‘keep under-16s out’, the far harder duty – design feeds that don’t push self-harm to vulnerable teenagers, build reporting systems that work, stop recommending strangers to children – gets quietly displaced by the easier one.

UNICEF Aotearoa’s Susan Glasgow has made the same point in the New Zealand context. The country does not need to lock children out of their online world: it needs to make that world safer by regulating the companies creating the harm. A ban, she argues, will not work.

The Oxford Internet Institute’s Victoria Nash calls a ban a “blunt tool” that forecloses the genuine benefits some young people draw from online spaces – peer connection, support communities, information – in exchange for protection it cannot reliably deliver.

Industry groups add, self-servingly but not wrongly, that blunt restrictions push children toward smaller, unregulated, riskier corners of the internet rather than the comparatively well-resourced safety teams of the major platforms.

The bill’s risk-assessment limb gestures at safety-by-design, but by pairing it with an age-gate the government has chosen the politically visible instrument over the effective one.

**The Regulator: why the DIA is the wrong home for this**

This is the sharpest objection and it deserves to be stated in full because the government has presented DIA regulation as an unremarkable administrative detail.

The DIA is not a neutral, single-purpose regulator. It already sits at the centre of New Zealand’s digital-control infrastructure.

It runs the **Digital Child Exploitation Filtering System**, which blocks websites at the ISP level.

It houses the **Censorship Compliance Unit**, staffed by warranted inspectors of publications, and does content classification and violent-extremism work.

It holds the country’s core **identity infrastructure** – passports, citizenship records, and the governance of the Digital Identity Services Trust Framework.

My constitutional argument, made in direct exchange with the secretary for Internal Affairs (Paul James, who defended the department in the *Herald* in a general rather than a specific nature along the lines of ‘trust us we know what we are doing’), is that this bill would layer onto that same department a new power over *age verification and access to social media* – concentrating identity verification, content classification, internet filtering, and investigative enforcement in one agency.

The DIA’s defence, when it came, was operational. The department is competent, law-abiding, well-supervised, has safeguarded sensitive data for over a century, and works within the Privacy Act under an independent commissioner.

My response is that this answers the wrong question. My objection is not can the DIA be trusted today? but should any single agency hold this *capability* at all? — because **infrastructure outlasts intentions.**

Present good faith is beside the point: once the capability is built, it survives its builders and becomes available to future administrators with different priorities.

And the one institutional check worth having – an independent distribution of power – is exactly what the government’s reassurance cannot supply, because it amounts to the department vouching for itself: *trust us, we are from the government.*

I have also advanced an equity dimension. Migrants, rural and low-income households, Māori and Pasifika communities and the very 15-year-olds at issue often hold neither passport nor licence, and so fall outside the credentials the system can read.

The bill’s own text sharpens the worry. The regulator’s functions include not just enforcement but “co-operating and sharing information with domestic and international law enforcement” (clause 20), backed by broad information-gathering powers (clause 21) that can compel testing and live demonstrations of a platform’s internals, and information-sharing powers (clause 22) reaching overseas regulators.

The bill requires the regulator to act “independently of the minister” only for the monitoring/enforcement and information-sharing functions (clause 20(2)) – not, notably, for its guidance and advisory roles – while the minister simultaneously holds sweeping regulation- and exemption-making powers.

That is a regulator embedded in a department that is also the censor and the filter, reporting to a minister who controls the scope of the regime. For a scheme that bears directly on freedom of expression, that concentration should be the headline concern, not a footnote.

**So should the state be involved at all, or should the regulator be independent – Netsafe, say?** The honest answer is more complicated than a simple swap, and it is worth being clear-eyed about each option:

- **An independent Crown entity** (structurally separate, at arm’s length from ministers, single-purpose) would answer the *concentration* objection far better than the DIA. It would not also run the national censorship and filtering systems, and its independence could be entrenched in statute rather than partial. This is the conventional New Zealand answer for regulators of contested, rights-adjacent activity, and it is the strongest reform available if the scheme proceeds. But it does not answer my deeper point that the *capability itself* – a mandatory, identity-linked gateway to social media – is dangerous wherever it lives.
- **Netsafe** is superficially attractive because it already exists and already has a statutory role: it is the “Approved Agency” under section 7 of the Harmful Digital Communications Act 2015 (and the bill itself lists that agency among the bodies the regulator may share information with). But Netsafe is an *NGO/charitable trust*, not a Crown regulator. Vesting coercive state powers – compelled information, pecuniary penalties in the tens of millions, applications to block global platforms – in a non-governmental body raises its own problems of democratic accountability, funding stability, capacity, and legitimacy. Coercive power over lawful speech is a core state function: outsourcing it to a charity is not obviously more constitutionally comfortable than housing it in the DIA, and arguably less so. Netsafe’s natural strengths are education, harm-reduction and complaint resolution – which is where the *actual* benefit lies – not wielding business-disruption orders.
- Worth noting, too, is that I am *not* simply calling for an independent digital regulator instead. In another piece I have argued against InternetNZ’s proposal for a standalone digital regulator, on the ground that New Zealand has twice contemplated exactly that architecture and twice, rightly, drawn back.

My position is closer to that of do not build the capability, rather than build it and rehouse it. That is a genuine tension that the ‘just make it independent’ answer glosses over.

The defensible middle ground, if parliament insists on acting is to keep the *risk-assessment and transparency* functions (which are about holding companies accountable and suit a properly independent, single-purpose Crown regulator), and drop or radically narrow the *age-verification mandate* (which is the piece that requires the dangerous identity infrastructure and which the evidence says does not work).

Whatever is done, the enforcement and any identity/verification governance should not sit in the same department that already runs censorship, ISP-level filtering and the national identity database.

**What the critics say should happen instead**

The critics are not, for the most part, arguing for inaction. A fair summary of the alternatives on the table:

- **Safety-by-design duties, hard-enforced.** Hold platforms to audited obligations and fine them heavily when their algorithms demonstrably push self-harm content to minors – rather than letting an age gate absolve them (Russell; Glasgow; Nash).
- **Target the real vectors.** Direct effort at messaging and private channels, where grooming and sextortion actually happen, instead of the politically visible public feed.
- **Address the hardware.** O’Brien’s proposal is to restrict *smartphones* for under-16s (regulating sale and possession, like alcohol) rather than rebuilding the internet for adults – changing the default without a population-wide identity layer. She pairs it with a parent-responsibility account rule whose value she frames as *norm-setting*, conceding it would be imperfectly enforced but arguing, as with drink-driving and truancy laws, that symbolic law still shapes behaviour.
- **Harmonise rather than improvise.** Platforms operate without borders; a country-by-country patchwork of arbitrary age lines (14 in Austria, 15 in France and Denmark, 16 in Australia, the UK and here) invites circumvention and imposes duplicative compliance. Cross-border coordination – ideally within a rights-protective framework like the EU’s device-based, zero-knowledge wallet model, which I have argued works *because* of the GDPR scaffolding around it, not the cryptography – would be more coherent than a lone New Zealand scheme.
- **Resource what already exists.** The bans are, in effect, an admission that existing regimes have been under-enforced: fund them properly first.

**In fairness: the case for the bill**

A critique should not pretend the other side is empty. The harms are real and well-evidenced: the coincidence of the smartphone era with a sharp deterioration in adolescent mental health, especially among girls; the deliberate engineering of compulsion (infinite scroll, variable rewards, autoplay); documented cases of algorithmic funnelling toward self-harm content; grooming and sextortion at scale.

O’Brien, no friend of the verification method, is emphatic that pretending the evidence is inconclusive is now wilful blindness, and that children’s rights are not identical to adults’ – societies restrict alcohol, gambling, driving and contracting for the young without anyone calling it tyranny.

Stanford’s emotive urgency (”a tsunami of countries” moving to stand up to big tech) reflects genuine, broad-based public and parental demand. The risk-assessment limb is a real accountability mechanism. And the “imperfect enforcement is no argument” reply – teenagers get alcohol too, but we still restrict its sale – has some force as a norm-setting proposition, even if, as I have argued, the alcohol analogy breaks down because a one-off counter check is nothing like a standing identity layer over public life.

The political reality is also that this is a genuinely contested question on which reasonable people, and reasonable evidence, point in different directions – which is exactly why rushing it is unwise.

**Conclusion**

The bill’s fatal weakness is that it has bet on the one part of the policy the evidence says does not work – the age-gate – and built the enforcement of that gate on identity infrastructure that is both dangerous and, on the Australian and British record, easily defeated.

Its own first cousins abroad have produced a nation of teenagers laughing about how easily they beat the ban, a 1,400 per cent VPN surge, and a string of identity-data breaches – while the platforms, whose products are the actual source of harm, are handed the easier duty of building a gate rather than the harder duty of building safe products.

Meanwhile the messaging channels where the worst predation occurs are left outside scope.

The choice of the Department of Internal Affairs as regulator compounds the problem rather than containing it. Placing age-verification and social-media access powers in the same department that already runs the national censorship unit, the ISP-level content filter, and the identity and passport databases concentrates a capability that – whatever the current custodians’ good faith – will outlast them.

If parliament proceeds regardless, the minimum step should be to sever that concentration: an independent, single-purpose, statutorily entrenched Crown regulator focused on transparency and safety-by-design, not a charity like Netsafe wielding coercive state power, and emphatically not the DIA.

The better course, on the weight of the critical commentary and the comparative evidence, is *festina lente* hasten slowly. The verification server, unlike the headline, does not expire. The VPN that defeats it takes about 90 seconds to install.

This article was originally published by [A Halfling’s View](https://djhdcj.substack.com/p/a-law-that-the-people-it-targets).