News

Friday 2026-09-04

08:00 AM

Colorado Sees First Lawsuit Under ‘Right To Repair’ Law [Techdirt]

At this point all fifty states have considered passing “right to repair” law aimed at making it easier and cheaper for consumers (and independent repair shops) to repair their tech. That said, only Massachusetts, New York, Texas, Minnesota, Colorado, California, Oregon, and Washington have actually passed laws. And of those states, none have seen any enforcement despite no shortage of offenders.

So it’s interesting to see the first lawsuit filed in Colorado. Colorado technically has three right to repair laws: one protecting wheelchairs passed in 2022; one covering agricultural equipment passed in 2023; and one expanding coverage to HVAC equipment and most tech in 2024.

A company named Acme Revival, which connects customers with electronics repair technicians, has sued three companies for violating Colorado’s right to repair laws. Three different lawsuits are targeting Toast, a point-of-sale system provider, Owl Labs, a maker of meeting cameras, and Blackmagic Design, a maker of digital camera equipment — claiming they’re violating the law.

The three different lawsuits state that all three companies have made it very difficult for customers to obtain tools, parts, manuals, and firmware/software needed to upgrade and repair point-of-sale terminals, card readers, cameras, and other restaurant-related hardware:

“Acme Revival has received hundreds of requests from owners seeking repairs for Toast devices. The reported problems have included failed batteries and charging systems, damaged housings and touchscreens, malfunctioning card readers and buttons, circuit-board failures, loose or damaged connectors, damaged cables, damaged ports, and other defects requiring replacement parts or technical repair materials.

Acme Revival alleges that it has been unable to complete certain repairs because Toast failed or refused to provide the necessary repair materials.”

There’s really no shortage of large offenders who make it difficult to find parts and tools, buy up independent repair centers to try and monopolize repair (see: John Deere), leverage annoying DRM to make repair difficult or impossible, or engage in the practice of “parts pairing,” which ensures hardware owners can only access large and costly parts assemblages — not individual parts.

The bipartisan anger at such practices has resulted in the right to repair movement seeing the most meaningful traction of any consumer rights issue in the country. Hopefully enforcement steadily scales up to match the full scale of public annoyance.

Working With ICE Is So Toxic, ICE Is Now Offering Liability Insurance To Local Police Officers [Techdirt]

If you’re worried about the bad optics of working with ICE, the federal government is here to help subsidize your recovery from mass deportation conjunctivitis. If you’re worried about the personal negative side effects of buddying up to ICE’s masked kidnapping squads, the administration is here to assure cops that it might cover some of the legal costs of doing business with ICE.

US Immigration and Customs Enforcement is pitching a plan to help shield local police officers who make immigration arrests from possible financial consequences if they are accused of on-duty misconduct.

The agency is proposing to subsidize liability insurance for state and local officers who are trained and deputized to enforce federal immigration laws, according to a planning document published Friday.

This offer is not valid in sanctuary cities or anywhere cops shops haven’t signed agreements to do ICE’s detention/arrest work for it. To get this extra coverage, law enforcement agencies will have to sign 287(g) agreements. These agreements make local law enforcement agencies part of mass deportation machinery. It requires agencies to hold arrested migrants and tell ICE to come pick them up. It also allows local cops to act as immigration officers by permitting them to perform arrests using ICE administrative “warrants.”

That word is in scare quotes because administrative warrants are just pieces of paper that say ICE knows of someone subject to a removal order. They are not reviewed by magistrate judges. And, unlike what ICE would have you believe, they do not authorize searches of private property.

This is where some of ICE’s (new) billions of dollars might be going. ICE officers don’t need this sort of insurance because they’re defended and indemnified by the federal government. (And they don’t need it anyway because the Supreme Court has made it pretty much impossible to successfully sue a federal officer for rights violations.)

Local cops aren’t nearly as immune as federal officers, so they might appreciate some insurance coverage in the extremely unlikely chance they are sued successfully for violating rights while doing ICE’s work for it. But the payout seems pretty fucking low considering ICE now commands the largest budget of any federal law enforcement agency.

Under the plan, officers would purchase insurance covering up to $500,000 in personal liability, which typically funds legal fees, settlements and judgments. Officers would be reimbursed up to $250 annually — roughly what the insurance is expected to cost.

The administration that claims to love cops (that love ICE) the most, this minimal payout should be viewed as insulting. First, the administration “allows” officers to spend their own money to purchase insurance coverage they wouldn’t otherwise need if their employing agencies had decided signing a 287(g) agreement wasn’t worth the trouble.

Second, tossing cops $250 a year does a whole lot of nothing when it comes to premiums for this specific sort of insurance. And, in other cases, partnering with ICE will automatically void these policies.

Pennsylvania’s risk pool, for instance, recently made clear that it would exclude “proactive immigration enforcement activities” from coverage, forcing several participating counties to search for other insurance options.

Butler County Sheriff Michael Slupe said he found insurance to cover his 13 deputies participating in the program at a cost of $20,000 in annual premiums.

In the first instance, there is no coverage to be had even if the DHS is willing to cough up a measly $250 a year for ICE buddy cops. In the second instance, a local agency is paying $1,538/year per officer to cover officers it has willingly lent to ICE’s anti-migrant activities. That means it’s still on the hook for the other $1,250/year. $3,250 (for 13 officers) looks like a down payment, rather than a meaningful contribution.

But the facts on the ground don’t bother Sheriff Slupe, apparently. He’s sure Trump will come riding the rescue with a fat stack of greenbacks.

“I want to make sure the guys are additionally covered, so we had to spend the money,” he said, adding that federal funding would cover the cost.

Technically almost true, if you read this to mean the federal government will cover an almost-insignificant portion of the cost. But it’s weird to see Sheriff Slupe offer to pitch in on immigration enforcement when his agency was thrown under the bus a bit following an alleged assassination attempt targeting Trump during his 2024 election campaign.

It’s all very stupid and unnecessary. It’s already pretty difficult to successfully sue law enforcement officers, thanks to the ever-expanding coverage of the qualified immunity doctrine (not actually a law!). Furthermore, the federal government’s pitch for additional liability insurance makes you wonder which Trump donors might profit from this push for new premiums. ICE already claims any officers participating in the 287(g) program are “acting under the color of federal authority,” which vastly increases the level of lawsuit immunity. Going even further, the federal government has already pretty much promised local law enforcement officers they’ll be well-defended should they be sued for boarding the ICE bang bus.

The agreements also state that local officers who face civil lawsuits can ask the US Department of Justice to represent them, and that ICE will generally support their requests. 

Adding all of this up, we can only assume none of this adds up. The stipend is too small. The government says local officers should present themselves as federal officers in court proceedings. And these officers seem unlikely to ever need to hire their own representation should they be sued for their ICE-adjacent activities. And now ICE is encouraging participants in the 287(g) program to buy insurance they’ll likely never need or, in some cases, not be able to use due to limits enacted by insurance providers.

It comes across as a blend of stupid and performative. As such, it fits in perfectly with this administration’s MO. But if I were a cop doing ICE’s dirty work, I’d be demanding full coverage paid with federal tax dollars, rather than assume this cock-up of a hybrid will actually do anything when I’ve been sued by competent plaintiffs.

07:00 AM

Hiking the Alps [dperkins]

This year progress on the Top 100 Mountains continues. Here are pictures from day and overnight trips to the Japanese Southern Alps and Central Alps this year.

Mt. Hoo

During spring break, I drove to Kofu, Yamanashi, and climbed Mt. Hōō (鳳凰山). There are several summits, and given the abundance of snow and ice, I summitted Jizō-dake (地蔵ヶ岳), notable for a giant rock at the top — the Obelisk. The trail was slow but fun: one third dirt, one third ice, and one third snow.

20260330.1.Alps.jpg 20260330.2.Jizo-dake.jpg 20260330.3.Obelisk.jpg

Yatsugatake & Mt. Tateshina

The snow was gone by May, so I drove up to the Central Alps in southern Nagano and climbed Yatsugatake (八ヶ岳). Yatsugatake has a handful of summits, and my route went over Amida-dake (阿弥陀岳) and Aka-dake (赤岳). The next day, I went up Mt. Tateshina (蓼科山), another mountain not far to the north. One fun thing about hiking so much in the Southern and Central Alps this year is learning the landscape. Many of these mountains are visible from one another on clear days, and if you don't know what you're looking at, it's guaranteed that some other hiker will tell you. Mt. Fuji shows up from time to time, too.

20260530.1.Yatsugatake.jpg 20260531.1.Tateshina.jpg

Mt. Kita & Mt. Aino

The second- and third-highest mountains in Japan are Mt. Kita (北岳) and Mt. Aino (間ノ岳), and you can day trip them if you really want to. There are many mountain huts along the way, so your gear need not be burdensome, and the scenery is majestic. Nevertheless, it's strenuous to say the least, and my legs were aching by the end of the day.

20260703.1.Fuji.jpg 20260703.2.Hoo.jpg 20260703.3.Senjo.jpg 20260703.4.Kaikoma.jpg

Mt. Tekari & Mt. Hijiri & Mt. Kisokoma

In late summer I drove to Nagano for more hiking. First was a two-day hike. It was a brutal ascent up to Mt. Tekari (光岳), but once I got up there, following the ridge north over Mt. Chausu (茶臼岳) was pleasant, and the weather was wonderful. After the long day with massive vertical gain, I spent the night at Chausu Hut (茶臼小屋). The mattress was thin and I slept poorly, but the building was warm and the food was good. The next morning we all awoke to a spectacular view of Mt. Fuji at sunrise. The pictures speak for themselves.

On the second day, I continued north, stopped briefly at the top of Mt. Kamikochi (上河内岳) went to the summit of Mt. Hijiri (聖岳), and headed back down to the car. Going down was much easier than going up, but my shoes were getting old and I got some blisters. That afternoon I went to an onsen in the nearby village of Toyamago, because a long bath after a long hike is just lovely, and then drove north for an hour.

After sleeping in the car, I got up and took the alpine bus and cable car most of the way up Mt. Kisokoma (木曽駒ヶ岳). From there it was a leisurely stroll to the summit. Many years ago we were here on a school trip but didn't get to the top because of bad weather. So it was nice to return, go the extra kilometer, and get the good vibes and views.

20260831.1.Tekari.jpg 20260831.2.Chausu.jpg 20260831.3.Fuji.jpg 20260901.1.Fuji.jpg 20260901.2.Fuji.jpg 20260901.3.Fuji.jpg 20260901.4.Ridge.jpg 20260901.5.Hijiri.jpg

A “Baker’s Dozen” Justices [The Status Kuo]

On Sunday, Rep. Jim Clyburn told NBC’s “Meet the Press” that Congress should expand the Supreme Court. “I think we are in a position now that calls for some significant actions taken by the Congress and we ought to expand, and 13 is a pretty good number,” the South Carolina Democrat said. “A baker’s dozen, it would be a good number to have on the Court.”

Three days later, perhaps spooked that someone as senior as Clyburn had taken up the cause, Republicans sought to head off the issue. They forced a vote on a constitutional amendment offered by Rep. Andy Biggs (R-AZ) to permanently fix the Supreme Court at nine justices. The vote was 212 to 206 in favor, with just one Democrat joining Republicans, but it fell well short of the two-thirds majority a constitutional amendment requires.

At this point, the parties are posturing. Republicans knew their amendment would not receive much support outside the GOP. And Democrats do not control Congress; even if they win both chambers after the 2026 midterms, expanding the Court would still require either a filibuster-proof Senate majority or the elimination of the filibuster altogether—as well as control of the White House, which could otherwise veto any expansion bill.

But the posturing still leaves one interesting question unanswered: Why is a proposal with no near-term path to enactment suddenly worth a public floor vote and a cable interview from a senior Democratic leader?

Subscribe now

Clyburn’s case

On August 30, Kristen Welker pressed Clyburn on whether he agreed with Kamala Harris’s past call for Supreme Court expansion. He responded by condemning the Court’s recent rulings, saying the conservative majority “has decided to reverse course and take this country back to those rulings of Justice Taney, that said, ‘No Black man has any right that white man must respect.’” He was referring to Chief Justice Roger Taney’s 1857 opinion in Dred Scott v. Sandford. Clyburn hoped new justices would “follow the constitutional underpinnings of this great nation of ours,” adding, “The 13th, 14th, and 15th Amendments have been interpreted different ways over the years.”

Clyburn’s call for a “baker’s dozen” of 13 justices was not new. Rep. Hank Johnson (D-GA), along with several Democratic senators, introduced the Judiciary Act of 2023 to expand the Court from 9 to 13 seats. In effect, Clyburn was endorsing an existing bill, not proposing a new one. Still, as some observers noted, he was the first member of House or Senate Democratic leadership to endorse expansion. And given his seniority and the importance of South Carolina—it will be the first state to hold a 2028 Democratic presidential primary—that endorsement carries significant weight.

The House vote

Rep. Andy Biggs of Arizona offered the amendment, which read in full:

“The Supreme Court of the United States shall be composed of nine justices consisting of one chief justice and eight associate justices.”

Biggs framed the measure as preemptive. “It fixes the number of justices at nine permanently, not because nine is a magic number, but because a fixed court cannot be expanded by whoever happens to win the next election,” he said during floor debate.

Democrats countered that the real overreach was Congress permanently surrendering its own authority. Rep. Mary Gay Scanlon (D-PA) noted that calls for Supreme Court reform “have grown louder in the wake of each decision that has lessened our individual rights and liberties.”

Rep. Ralph Norman (R-SC) argued that the danger lay in the precedent itself. “Once politicians start changing the size of the Court to get favorable rulings, there is no logical stopping point,” he said. “Today is 13. Tomorrow could be 17. Then 21. That would turn the Supreme Court into just another political arm of Congress.”

This argument against politicization is ironic, given Democrats’ view of the current Court majority as little more than an extension of the Trump White House. And Josh Orton, president of the judicial advocacy group Demand Justice, argued that Republicans would not hesitate to wield power were the shoe on the other foot. “You can be damn sure that if there had been a longstanding progressive majority on the court, Republicans would have already voted to expand it,” he said. Expansion, he argued, “has to happen in the first two years of the next Democratic administration.”

The amendment arrived as part of a broader slate of messaging votes. A day earlier, the House had adopted a resolution condemning “socialism.” That was part of a Republican push tied to several Democratic Socialists of America-aligned candidates expected to join Congress after the midterms. A spokesman for House Republicans’ campaign arm declared, “Give House Democrats an ounce of power, and they’ll use every bit of it to fundamentally transform America into an unrecognizable socialist hellscape.”

(Narrator: Medicare for all, free child care and nutritional assistance for poor families are a “socialist hellscape” to Fox hosts and the GOP.)

Nine is by statute, not constitutional mandate

Article III of the Constitution created the Supreme Court but said nothing about its size. It left that question to Congress, which has changed the Court’s size seven times since the founding.

The Judiciary Act of 1789 set the Court at six members: one chief justice and five associate justices. In 1801, the outgoing Federalist Congress voted to cut the Court to five seats, timed to deny the incoming Jefferson administration an appointment, but Congress repealed the change the following year before it ever took effect, restoring the Court to six. A seventh justice was added in 1807 as new circuits were created, and an eighth and ninth followed in 1837. The Court reached its historical high in 1863, when a tenth justice was added alongside a new Tenth Circuit then covering California and Oregon.

Congress moved to shrink the Court in 1866, providing that it would fall to seven seats as vacancies arose, a change widely viewed as one of the Reconstruction Congress’s restrictions on President Andrew Johnson. With Ulysses S. Grant in office in 1869, Congress set the Court at nine justices. That remains the last time Congress has changed the size of the Court.

The Congressional Research Service notes that scholars dispute Congress’s motives across these changes. Some point to caseload and administrative needs, while others argue the changes were consistently political. Franklin Roosevelt’s 1937 attempt to add justices to a Court that was regularly striking down New Deal legislation is the best-known chapter in this history, but it never became law and the Court remained at nine justices.

Where Jeffries stands

House Minority Leader Hakeem Jeffries, who hopes to become speaker-elect after the November midterms, staked out his own position weeks before Clyburn’s comments. He told the National Association of Black Journalists in August that “dramatic Supreme Court reform is necessary.” Asked what that meant, he deferred to others on the specifics. “I’m going to leave it to the Democrats on the Judiciary Committee, led by Jamie Raskin, who will be the next chair… there’s a variety of different options that are on the table. And I think that we can’t foreclose any single one of them.”

Jeffries was sharper about the Court’s current majority than about any specific fix. “The conservative right-wing majority on the Supreme Court has become basically a subsidiary of the MAGA Republican Party,” he said, pointing to the Court’s ruling in Louisiana v. Callais and a related fight over an Alabama congressional map.

In a subsequent appearance on “Meet the Press,” Jeffries said an overhaul could start with a binding ethics code of conduct for justices, but he stopped short of backing the seat-expansion proposals popular with some members of his own caucus.

The gap between Jeffries and Clyburn probably reflects a division of labor rather than much daylight between their positions. Jeffries has left room for “dramatic reform” as a category while directing the specifics to Raskin’s committee, leaving the politically explosive question of seat expansion to members like Clyburn to carry.

The public’s trust has never fallen so low

Public opinion on Supreme Court expansion is split. A Marquette Law School poll conducted in May found the public evenly divided, 50 percent in favor of adding justices and 50 percent opposed, up eight points since Marquette first posed the question in September 2019, when 42 percent favored enlargement.

Confidence in the institution overall has slid. The share of registered voters expressing “a great deal” or “quite a bit” of confidence in the Supreme Court has fallen to 22 percent, a record low in NBC News polling. A separate Gallup poll put the Court’s job approval at a record low of 33 percent.

In short, voters have not coalesced around expansion as the fix, but their confidence in the Court has cratered. As the Court’s legitimacy problem deepens, the argument for adding seats will grow louder, and Democrats now appear ready to run with it.

Why raise the question now?

Democrats currently do not control any part of government, and they do not have the votes to expand the Court given unified Republican opposition. So why are Democratic leaders talking about an idea they cannot yet act on, and may not be able to act on even after the midterms?

Wouldn’t this take a Democratic trifecta? If so, why start talking about it now, giving the GOP a big heads up? Shouldn’t we have just surprised them with it in 2029?

Josh Marshall of Talking Points Memo had a keen observation worth sharing in full:

The inertial forces against reform are massive. Even among many elected Democrats who are pretty good on other issues, it’s often a very heavy lift. It’s only very recently that Court reform has even moved into the realm of conceivable for most of them. Change, building that consensus can only happen as a bottom-up process, making it clear that accepting the perpetuation of the Corrupt court as it exists today is an unacceptable position for a Democrat, certainly at the federal level — as a bottom-up process, it can only be a public process. You’ll only know someone is on board when they say it publicly and clearly. Even then you can’t be totally sure. But once a politician has committed publicly, it’s much harder to shift. And when you’ve got the great majority publicly committing, the pressure heightens on those who remain opposed or silent in inverse proportion to their declining numbers. The same applies to abolishing the filibuster and a lot else.

Seen in this light, Clyburn’s remarks, paired with Jeffries, are early markers for what a future Democratic government would do with unified control. Both are staking their public positions to build the consensus they know they will need. “In time for 2029” is emerging as a position within the party, with Clyburn among the prominent early voices making the case.

The failed House vote, insisted upon by the GOP, may itself have done some of the work for expansion advocates. One assessment noted the important concession embedded in the GOP’s own amendment: Republicans could not argue for permanently fixing the Court’s size without acknowledging that Congress can, right now, make the Court whatever size it wants.

The Supreme Court itself under John Roberts is no doubt also paying attention. In his Sunday remarks, Clyburn fired a warning shot across the radical majority’s bow, in effect saying, “We see you, we know what you are trying to take us back to, and we won’t allow it. If our hand is forced, we will dilute your strength by expanding your numbers the moment we are in charge.”

GOP pearl-clutching over packing the Court also rings hollow given that their party already did so. In 2016, Republicans under then-Senate Majority Leader Mitch McConnell (R-KY?) blocked President Barack Obama’s nomination of Merrick Garland, refusing to give him a confirmation hearing. McConnell claimed that appointment came too close to an election, despite Obama nominating Garland in March. McConnell then turned this same excuse on its head by ramming through Justice Amy Coney Barrett’s nomination days before the 2020 election. He later acknowledged the real distinction was control of government, not the calendar: “What was different in 2020 was we were of the same party as the president.”

After 2028, if a Democratic Congress is of the same party as the president, we should insist the GOP get a strong dose of its own medicine.

06:00 AM

Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year. [Techdirt]

From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.

This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database.

There is no safe age verification. There is no age verification that doesn’t put people at risk.

Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches.

The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web:

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary.

That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.

So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned.

Yiiiiiikes.

And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed:

The IDScan.net Trust Center webpage features a security review banner, a search bar, sections for trust and compliance certifications, and a grid of logos from trusted partner organizations.

That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page.

But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records.

And it appears no one internally at the company noticed.

As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system:

The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.

A table titled "Categories" lists various types of identification documents and the number of records associated with each. There are over 153 million drivers licenses.
The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale:

A webpage from the NEXUS Identity Document Database shows a locked Minnesota driver's license record for Peter Heg******, featuring a portrait photo of Hegseth and redacted personal details with a "Purchase Record" button at the bottom.

A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license.

Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing.

Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage:

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.

You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems.

Daily Deal: Babbel Language Learning (All Languages) [Techdirt]

Become a language expert with a Babbel Language Learning subscription. With the app, you can use Babbel on desktop and mobile, and your progress is synchronized across devices. Want to practice where you won’t have Wi-Fi? Download lessons before you head out, and you’ll be good to go. However you choose to access your 10K+ hours of online language education, you’ll be able to choose from 14 languages. And you can tackle one or all in 10-to-15-minute bite-sized lessons, so there’s no need to clear hours of your weekend to gain real-life conversation skills. Babbel was developed by over 100 expert linguists to help users speak and understand languages quickly. With Babbel, it’s easy to find the right level for you — beginner, intermediate, or advanced — so that you can make progress while avoiding tedious drills. Within as little as a month, you could be holding down conversations with native speakers about transportation, dining, shopping, directions, and more, making any trip you take so much easier. It’s on sale for $159 when you use the code LEARN at checkout.

Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

04:00 AM

DOJ Issues Memo Saying There’s Nothing Illegal About The Military Arresting Migrants [Techdirt]

A little more than a year ago, the Trump administration pushed a novel legal theory in order to juice its migrant arrest stats. It was a two-part process. First, the administration unilaterally declared expansive areas near US military bases to be “national defense areas.”

This meant that areas surrounding bases — like (especially) Fort Bliss in El Paso, Texas (which is also home to one of ICE’s largest detention centers) — were subject to a separate set of rules governing “military zones.” In these areas, military officers could effect arrests on anyone “intruding” into these areas. The outlines of these areas were deliberately large — so much so that they butted up against US-Mexico border.

The point of this effort was obvious: Trump hoped to see more arrests at the border by allowing the military to pitch in with his mass deportation efforts. This was the administration’s “Posse Comitatus Act” workaround. That law, passed in 1878, forbade the federal government from co-opting military members to perform regular law enforcement work. It’s the same thing that was a sticking point in many of Trump’s National Guard deployments to major US cities.

By pretending massive areas surrounding US bases were now so essential to US national security that the government absolutely needed to draft soldiers into its immigration law enforcement effort, the Trump administration hoped to avoid adverse court rulings.

That hasn’t really worked. National Guard deployments have been blocked by federal courts. And while there hasn’t been a precedential ruling on this novel interpretation of “national defense areas,” the DOJ has decided to issue a legal memo — more than a year after this had already happened — that says this is all cool and legal.

On Aug. 14, the Department of Justice’s Office of Legal Counsel (OLC) released a 15-page memorandum contending that the Posse Comitatus Act does not prohibit military personnel from effecting arrests in the “immediate vicinity” of a designated “national defense area” for alleged crimes there. The opinion followed President Trump’s April 2025 order designating swaths of the Mexico-U.S. border as national defense areas

There’s a lot of bullshit in the OLC’s memo [PDF], but let’s start with this:

Even though substantial portions of the NDAs may be presently unoccupied or have no standing structures on them, there is a military necessity to ensure that unauthorized persons are not establishing a position to monitor the activities of U.S. forces for intelligence gathering purposes or conducting reconnaissance in preparation for a terrorist attack. Individuals may also be drawn to remote and unoccupied locations to engage in criminal activity, which poses a threat to military personnel who may come upon them in the course of their duties or where the activity itself poses a danger, such as the operation of methamphetamine laboratories. As there is no way for military personnel to know a priori the identity or intent of an unauthorized person, there is a military purpose in apprehending, at least temporarily, anyone whose presence is unauthorized, in order to ensure appropriate measures can be taken to protect national security and the safety of military personnel. That military purpose continues even if the trespassers have exited the installation before they were apprehended.

It’s insanely hilarious to actually claim in an official legal memo that if soldiers aren’t allowed to detain migrants, some of them are just going to fire up a meth lab within the vicinity of a US military base.

But once we’re done laughing, we have to recognize the obvious side effects of this declaration by the DOJ: that anyone is subject to this interpretation of the law, which turns troops into cops just because the administration says it does.

One of the many troubling aspects of this assertion (and of the executive order underlying it) is that it places no burden on the government to clearly, physically denote the outlines of these supposed “national defense areas.” This means migrants crossing borders will just assume they’re walking on land and only find out after the fact that the government has unilaterally declared that area to largely be exempt from commonly accepted restrictions on US military officers.

And even if you don’t care what happens to migrants, especially those who have very recently illegally crossed in the US, you might want to take a moment to consider your fellow citizens who also won’t know they’re in a “national defense area” until they’re greeted at gunpoint by members of the US military. It’s already scary enough to get jumped by cops when you’re just minding your own business. Now, imagine this same experience, except with an armored vehicle featuring a top-mounted .50 cal machine gun.

The DOJ doesn’t seem to find much support for its assertions in the memo. And yet the OLC has delivered one all the same. The memo pretends there’s no difference between the military enforcing the law within the confines of US military base and enforcing it in large, unmarked areas whose confines can only be defined by those with access to information the Trump administration certainly isn’t going to be sharing with everyone.

But the DOJ OLC is also (sadly) correct to point out that this interpretation of the law is not subject to any adverse precedent. Do you know why that is? BECAUSE NO ONE BUT THIS ADMINISTRATION HAS TRIED TO DO THIS EXTREMELY FUCKED UP THING BEFORE. Opening an Overton Window in a legal vacuum doesn’t make you the smartest people in the room. It just makes you the pioneers of martial law fuckery.

Finally, the OLC says not even the vague boundaries of any supposed “national defense areas” should prevent military officers from arresting migrants (or anyone else in the area).

In sum, we conclude that the use of military personnel to arrest trespassers just outside of an NDA would not violate the PCA, given the express statutory authorization and the military-purpose of a commander’s traditional protective power.

Even the confines are not the confines. The OLC doesn’t bother to describe what it considers to be “just outside of an NDA.” Nor is it going to. That’s a problem for arrestees to try to suss out in courts that already give the federal government plenty of leeway any time it starts talking about national security or national defense. How far away can someone (as the DOJ’s hypothetical puts it) “engage in criminal activity” or “reconnaissance?” What’s the acceptable distance between an NDA and a meth lab? Any distance could be considered “just outside” as long as someone’s will to swear they saw some reconnaissance or criminal activity happening.

We’re fortunate that we haven’t seen this novel interpretation of the PCA abused excessively. So far! But the late arrival of this legal justification seems to indicate we’ll be seeing a lot more of that in the near future.

12:00 AM

Pluralistic: Preparing for a post-Trump internet (03 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]

->->->->->->->->->->->->->->->->->->->->->->->->->->->->-> Top Sources: None -->

Today's links



A nuclear mushroom cloud wearing a giant Trump wig. A decaying American flag fills the sky behind it.

Preparing for a post-Trump internet (permalink)

What if post-Trump America is even worse?

I know, it's tempting to think of Trump as a cause, rather than an effect – as an aberration who dragged America into fascism. Trump is exceptional, but the thing that makes him exceptional isn't his corruption, recklessness or cruelty. What makes Trump exceptional is his ability to cajole, intimidate and flatter America's most corrupt, reckless and cruel people into a coalition.

These people hate each other. Nick Fuentes drifts off to sleep every night furiously fantasizing about turning Stephen Miller into a lampshade. Laura Loomer just got ICE to intervene in a Twitter feud by having a guy she dislikes violently arrested, shackled at wrist and ankle, perp-walked, and then shuffled from location to location so that he couldn't meet with his lawyer before being deported:

https://www.motherjones.com/politics/2026/08/milo-yiannopoulos-deportation-trump-maga-laura-loomer-benny-johnson-raheem-kassmm/

They steal like crazy, get each other locked up, and gorge themselves on mind-altering supplements and peptides they buy from random podcast chuds. They are fantastically paranoid, marinated in conspiracy theories, and perennially high on their own supply: all that bullshit about "great replacement," "China is making America hate data centers" and "antifa is a terrorist organization"? A lot of them genuinely believe it. It's not just ghost stories they made up to scare cognitively compromised tube-feeding Fox News addicted rubes. Trumpland is full of actual, functioning adults in positions of real power who periodically go into the bathroom, turn off the lights, hold a flashlight under their chins and scare themselves silly by saying "Aaaaaaaaaantiiii-faaaaaaaaaa" into the mirror.

Donald Trump did not conjure these people out of thin air. They've been lurking in America since its earliest days. They worship authoritarian criminals:

https://abc30.com/post/roger-stones-tattoo-of-nixon-goes-viral/5107047

January 6 wasn't the first presidency they tried to steal, it's just the first one they got punished for:

https://en.wikipedia.org/wiki/Brooks_Brothers_riot

They commit brazen crimes in office that could land them in prison for the rest of their lives, and therefore can't afford to lose power, ever:

https://www.propublica.org/series/supreme-court-scotus

Trump didn't invent these creeps, he just emboldened them. If Reaganomics was capitalism with the gloves off, then Trumpismo is Reaganism with the mask off:

https://www.theguardian.com/books/2020/aug/16/reaganland-review-rick-perlstein-jimmy-carter-ronald-reagan

So what happens when Trump strokes out while watching Kid Rock wrestle a Hulk Hogan impersonator in a televised barbed-wire cage match on the White House lawn that one of Trump's cronies has exclusive pay-per-view rights to? I mean, it's possible that the Democratic leadership will step up and insist on some form of regular order in the succession to Vance, but come on. These are the tiny "Down with this sort of thing" ping-pong paddle people:

https://www.truthdig.com/articles/ping-pong-paddles-to-a-gun-fight/

More likely is that Vance – a weak, unimportant charisma-vacuum who is loathed by all of Trump's factions – will end up presiding over a far more chaotic period in American governance than anything that happened under Trump. That could mean ICE leaders ordering mass graves dug in the centers of America's largest cities, drunken generals invading random countries, podcasters declaring "The Purge" with brackets sponsored by Kalshi.

This isn't the first time in living memory that this has happened. In 1991 the Soviet Union collapsed, virtually overnight, and the fragile threads that bound its feuding, corrupt regional bosses all snapped, leaving behind nuclear-tipped mafia states. This was a chaotic and frightening time for the people whose governments had simply winked out of existence – but it was also terrifying for the rest of the world, who scrambled to secure those nukes before they could end up in the hands of "non-state actors":

https://www.hks.harvard.edu/publications/what-happened-soviet-superpowers-nuclear-arsenal-clues-nuclear-security-summit

The Soviet Union had some deeply dysfunctional leadership politics to be sure, but at least the people involved were beholden to various power blocs who had an interest in keeping things going. As the geopolitics wonks say, "they were playing an iterated game," where some losses had to be tolerated so that the losers could try to win the next time around.

But there are plenty of people who weren't (and aren't) playing iterated games – people who are even more unhinged, more reckless, more short-termist than the maniacs who filled the world with nuclear weapons. These people don't necessarily care if civilization or even the human race persists if they can't get their way. The thought of them running around with these "weapons of mass destruction" ratcheted up the half-century of stark nuclear terror that had preceded the USSR's collapse to new heights.

Which brings me to the post-Trump internet. Trump isn't the first president to figure out that the internet could be weaponized for geopolitical ends. As the Snowden disclosures showed, there has been a longstanding bipartisan consensus that the internet is a great tool for American surveillance, conducted against friend and foe alike.

But Trump is the first president to openly, directly recruit American tech companies to simply brick foreign officials who displease him, starting with the Chief Prosecutor of the International Criminal Court, who lost his Office 365 and Outlook accounts in retaliation for swearing out a genocide warrant for Netanyahu:

https://www.justiceinfo.net/en/156691-how-sanctions-can-weaponize-us-tech-against-the-icc.html

And then Microsoft obliged Trump again, attacking the Brazilian judge who sentenced Jair Bolsonaro to prison over his unsuccessful coup.

America's tech giants have fully, irrevocably fused with Trump. They donated to his campaign. Their CEOs each paid $1m out of their own pockets to sit behind him on the inauguration dais. Google provides location data for Trump's racist pogroms. Microsoft provides the administrative tools to carry them out. Oracle provides the databases. Apple blocks apps that warn its customers when they're about to be snatched:

https://pluralistic.net/2025/10/06/rogue-capitalism/#orphaned-syrian-refugees-need-not-apply

In exchange, Trump got Canada and the UK to ditch their plans to levy a 3% tax on American tech giants; he got the EU to gut its privacy laws; he sanctioned EU officials who tried to regulate social media; and he's told the tech companies to go through EU officials' private messages, looking for anti-Big Tech partisans whom he will ban from ever entering the USA:

https://judiciary.house.gov/media/in-the-news/us-committee-demands-big-tech-share-private-comms-eu-officials

Big Tech has proved that its only principles are not paying taxes, invading your privacy, and not being broken up by antitrust enforcers:

https://arstechnica.com/gadgets/2026/09/us-court-rules-google-will-not-have-to-sell-ad-exchange-after-losing-antitrust-case/

Tech companies will do anything for any leader who can guarantee those outcomes. There's no capitulation too petty and stupid for Big Tech:

https://people.com/apple-maps-joins-google-approving-trump-lake-america-change-12074262

America no longer has allies or trading partners. America has rivals and enemies. Trump's coalition wants him to steal Iran, steal Venezuela, steal Cuba, steal Alberta, steal Canada, steal Greenland. They want him to help Israel steal Palestine and Lebanon. And as Trump considers this program of imperial conquest, he has started to tinker with one of the most devastating geopolitical weapons the world has ever seen: tech shutdowns.

If Trump wants Greenland, he can just order Microsoft to switch off Office 365 for the country and every ministry and significant firm will be shuttered in an instant, along with many households:

https://pluralistic.net/2026/04/04/digital-subjugation/#greenlands-next

He can order Apple and Google to shut off all of Denmark's phones. He can order John Deere to shut off all their tractors:

https://pluralistic.net/2022/05/08/about-those-kill-switched-ukrainian-tractors/

(One thing we don't need to worry about is Trump ordering OpenAI and Anthropic to switch off all of Europe's chatbots – sure, he could do that, but if he did, nothing important would break:)

https://pluralistic.net/2026/06/18/their-trillions-our-billions/#eyes-on-the-prize

As weapons of mass destruction go, nukes are pretty stupid. The big ones destroy the territory you're trying to conquer and leave behind an uninhabitable radioactive wasteland. They send clouds of nuclear fallout swirling around the globe, potentially killing you or your allies. 80 years into the Nuclear Age, the best anyone's come up with is a neutron bomb, which only kinda renders territory uninhabitable while still killing everyone with massive radiation blasts.

Compared to nukes, tech shutdowns are amazing. Thanks to Big Tech, America – and only America – can brick almost any country on earth, shutting down its administration, agriculture and industry without firing a single shot. The only thing that prevented this from happening was an American elite bloc that was playing an iterated game and saw more benefit from sharing in Big Tech profits as they looted and spied on the world, as opposed to grabbing territory while scaring the world into breaking all land-speed records to ditch American tech and pursue meaningful digital sovereignty.

Trump's chuds and freaks are not bound by these constraints. They're perfectly happy to do Gunboat Diplomacy 2.0: Cloud Diplomacy, where everything from your smartphones to your payroll records can be seized at the click of a mouse, and your country had better fall in line. And Trump is a sick, frail old man, who is not long for this world. When he goes, all bets are off: America will be at the mercy of warring factions who will deploy the coercion and bribery that turned Big Tech into Trump's geopolitical weapon in order to achieve their own purposes – which might well be even stupider, crueler and more unhinged than Trump's.

There's only one way out of this mess: the rapid disassembly of the American internet and the rapid creation of a post-American internet, one built on open, auditable, sovereign digital public goods, internationally built and maintained:

https://pluralistic.net/2026/01/01/39c3/#the-new-coalition

In its own way, the creation of this post-American internet is as urgent and as global as was the creation of the covid vaccines. But whenever I speak to powerful people about this, they ask the same question: "What if this makes Trump mad?"

This represents a grave failure to take this crisis seriously. Trump doesn't need to be "mad" to attack your country. Trump attacked Canada over its wildfires, accusing Canada of polluting America's air:

https://www.cbc.ca/news/politics/us-complaints-trump-widlfire-smoke-9.7274466

But even if Trump never gets mad at you, that's no guarantee of safety. Trump is not long for this world, and his death or incapacity is no guarantee of the restoration of a "normal" America. And even if America finds its way to "normal" after Trump, that's no guarantee that it will stay normal. The armed, organized maniacs who have seized power in America and who are cheering him on as he rampages all over the world, kidnapping leaders and dropping bombs on schoolchildren are not going to dig a hole, crawl inside it, and pull the dirt down on top of themselves.

But let's say that we find ourselves in the best of worlds, where American fascism is comprehensively defeated and the country embarks on a years-long program of denazification:

https://pluralistic.net/2026/02/10/miller-in-the-dock/#denazification

Even in that amazing future, the world should still race to build a post-American internet. The world should have built that internet after the Snowden revelations. That ghastly failure created the Trumpian internet. If the post-Trump internet isn't a post-American internet, then it'll only be a matter of time until the next crisis comes along, and the coming years will give Big Tech even more chances to worm its tendrils into the world's governments, firms and households, making that crisis be even harder to survive. The best time to act was 13 years ago, after Snowden. The second best time is now.


Hey look at this (permalink)



A shelf of leatherbound history books with a gilt-stamped series title, 'The World's Famous Events.'

Object permanence (permalink)

#25yrsago Barnum & Bailey hired an ex-CIA spook to destroy a critical journalist https://web.archive.org/web/20010913192931/http://www.salon.com/news/feature/2001/08/30/circus/print.html

#20yrsago Wired article about Wikipedia is on a editable wiki https://web.archive.org/web/20060901030941/http://www.socialtext.net/wired/index.cgi

#20yrsago Singapore will have nationwide WiFi by 2007 https://web.archive.org/web/20060901191656/http://news.com.com/2100-1039_3-6110189.html

#5yrsago Twitter Arguments https://pluralistic.net/2021/08/29/twitter-arguments/


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, pounding the podium.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027

  • "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027

  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Colophon (permalink)

Today's top sources:

Currently writing:

  • “Once Is Enemy Action,” a science fiction novel about the origins of modern technofascism. Today's words: 574 (7730 total).

  • "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

  • A Little Brother short story about DIY insulin PLANNING


This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, possible tracking and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.

ISSN: 3066-764X

Thursday 2026-09-03

10:00 PM

Apple, Google Pathetically Buckle To Trump’s Dim And Lazy Effort To Rename Lake Ontario [Techdirt]

When we look back at this time and history words like “courage,” “integrity,” and “ethics” aren’t words you’re going to be associating with U.S. tech industry leadership. Everywhere you look you have tech sector executives either openly embracing fascism and the frontal assault on representative democracy, or too feckless and timid to take any sort of coherent stand on literally anything (and then wondering why the plebs are increasingly hostile to their software products).

Apple and Google’s quick decision to rename the Gulf Of Mexico at the behest of a mad and racist king was a lovely example; and now we’re back again with both companies quickly moving to rename Lake Ontario “Lake America” just because the increasingly unpopular U.S. President had a brain fart during his pointless and harmful trade war with Canada.

Google was the first to quickly make the change to appease Trump; in fact they acted so quickly on this the change to Google Maps happened before the government had even finished implementing it. Apple was very quick to follow suit, despite the fact that nobody at the company actually supports the ridiculous and pointless change:

“Everyone considers it fucking nuts.” Inside Apple, I'm told "not a soul" supports Donald Trump's Lake Ontario rebrand to "Lake America," but the company is also resigned to making such concessions to avoid the White House's rage. Details in @status.news: www.status.news/p/apple-maps…

Oliver Darcy (@oliverdarcy.bsky.social) 2026-09-02T00:59:49.372Z

These are, so we are clear, active choices — their mapping systems aren’t just innately and automatically following the lead of the authoritarian U.S. government’s GNIS data. Google (and the company’s defenders) had initially tried to insist they were following automated GNIS protocols, but that wasn’t actually the case:

“Google began rolling out this change for US users on Saturday. The company posted a brief update on its Google Maps blog, noting that it follows the US Geographic Names Information System (GNIS) for its maps, so the company implies it had no choice but to rename Lake Ontario in Google Maps, which is the most popular mapping platform in the US by a wide margin.

However, Google was even quicker to switch over to Lake America than the US government. While the GNIS database acknowledges the name change in a summary report, the base map layer still reflects the internationally recognized name of Lake Ontario. A message across the top of the USGS-operated website notes that the change to official maps is still pending.”

Even then, there’s nothing saying Google couldn’t have ignored the GNIS changes for the sake of product quality. As it is, both Apple and Google are still ensuring that U.S. users of both mapping products see King Trump’s pointless change, while everybody else in the world sees material reality.

This lightning-fast choice to quickly buckle to the incoherent whims of a tyrant over something this stupid certainly raises questions about what kinds of subservience we don’t know about yet by these titans of U.S. innovation. There was some hope that Apple, with new CEO leadership and no shortage of “fuck you money,” would demonstrate some sort of ethical leadership here, but alas.

Amusingly Mapquest (and I guess TomTom) used Apple and Google’s abject fecklessness to market “having the slightest hint of a backbone” as a market branding differentiator:

“The company said its mobile app received hundreds of thousands of downloads after it announced Thursday that the name Lake Ontario would remain on its apps, despite Trump directing the Interior Department to update the lake’s name in the Geographic Names Information System (GNIS).”

This is still somehow occurring despite the fact that Trump’s support is cratering due to pointless wars, high oil prices, sagging polling, and clearly waning health. Even on these peripheral issues where taking a stand could be easily defended by an ocean of highly paid lawyers, executives can’t even muster the vaguest outline of some sort of meaningful backbone.

I’m sure they’d argue that it’s their fiduciary responsibility to shareholders to not “antagonize” the U.S. government. But where’s the fiduciary responsibility to the continued existence to functional markets, industry autonomy, and democracy in a country under assault by some of the dimmest, most incompetent and corrupt autocrats the American experiment has ever seen?

08:00 PM

New Release: Tails 7.12 [Tor Project blog]

Firefox is moving to a 2-week release cadence starting in September, and so Tor Browser and Tails are doing the same. Tails 7.12 is the first release on this new cadence.

Changes and updates

  • Update Electrum from 4.7.2 to 4.8.1.

  • Update Tor Browser to 15.0.21.

  • Update some firmware packages. This improves support for newer hardware, including graphics cards, Wi-Fi, and more.

Get Tails 7.12

To upgrade your Tails USB stick and keep your Persistent Storage

  • Automatic upgrades are available from Tails 7.0 or later to 7.12.

  • If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade.

To install Tails 7.12 on a new USB stick

Follow our installation instructions.

The Persistent Storage on the USB stick will be lost if you install instead of upgrading.

To download only

If you don't need installation or upgrade instructions, you can download Tails 7.12 directly:

Support and feedback

For support and feedback, visit the Support section on the Tails website.

07:00 PM

What it is like to be a dog? [Seth Godin's Blog on marketing, tribes and respect]

We have no idea.

Of course, there’s plenty of behavioral data. Say this phrase, or offer that treat, and this particular dog is likely to act in a certain way.

But our inclinations about what it’s actually like to be a dog are all inventions, reverse-engineered to give us a clue about what they might do next.

“If I were you,” is a pretty useless sentence, particularly for dogs. You’re not them, and you can’t imagine what it’s like.

The same is true for computers and for AI. We make up a story about what the computer wants, expects or thinks. But it’s simply a way to explain our guesses about behavior, not actually a statement about what it’s like to be that device or program.

You’ve probably already guessed (there I am, imagining what it’s like to be you) that the same is true for other humans. We only know for sure what it’s like to be ourselves. Everything else is speculation.

Empathy is essential, but it’s also difficult.

      

02:00 PM

Sony Tells Courts Any ‘Reasonable Customer’ Knows Digital Purchases Are Actually Licenses [Techdirt]

Sony’s ability to generate anger lately is pretty impressive. After the company announced that there would be no more physical media versions of games made starting in 2027, to the resounding anger of many people, Sony also demonstrated yet again that it’s capable of ripping away the digital “purchases” people had made once its own licensing arrangements expire. While some folks out there understand that in the cases of some digital goods you’re not actually buying a thing, but a temporary license, many others either don’t know that or simply don’t like it, spurring on further anger against Sony across the internet. And that’s leaving aside entirely the subject of game and cultural preservation in all of this.

Sony is bad enough at this that they can manage to piss me off even when I probably agree with them when it comes to a particular lawsuit. Let’s get through the part where I’m on their side first.

There is a lawsuit going on in California, brought against Sony by a group of PlayStation gamers, that is arguing that the platform doesn’t comply with a relatively new California law for digital purchases that has strict rules around disclosing that the nature of the purchase is a license. The suit argues for non-compliance because the PlayStation Store uses the phrases “buy” and “purchase”, which is forbidden by the law.

Unfortunately for the plaintiffs, that’s not the full story. Here’s the relevant section of the law:

(b) (1) It shall be unlawful for a seller of a digital good to advertise or offer for sale a digital good to a purchaser with the terms “buy,” “purchase,” or any other term which a reasonable person would understand to confer an unrestricted ownership interest in the digital good, or alongside an option for a time-limited rental, unless either of the following occur:

(A) The seller receives at the time of each transaction an affirmative acknowledgment from the purchaser indicating all of the following:

(i) That the purchaser is receiving a license to access the digital good.

(ii) A complete list of restrictions and conditions of the license.

(iii) That access to the digital good may be unilaterally revoked by the seller if they no longer hold a right to the digital good, if applicable.

(B) The seller provides to the consumer before executing each transaction a clear and conspicuous statement that does both of the following:

(i) States in plain language that “buying” or “purchasing” the digital good is a license.

(ii) Includes a hyperlink, QR code, or similar method to access the terms and conditions that provide full details on the license.

And here’s what it looks like if you were to make a purchase for a license for a digital game on the PlayStation Store:

So let’s go back to the law. Yes, the page uses the term “purchase”. It also asks for acknowledgement via the “Confirm Purchase” button that the customer understands they’re buying a license (and it’s in plain language), links to the SPLA and TOS which outline the restrictions and conditions of the license, and details the revokable nature of that license. Sony is arguing it’s compliant and I’m compelled to agree.

And if Sony left it at that, I wouldn’t be writing this post right now. But then the company just had to further and say something really stupid.

Now, as reported by Game File, Sony recently filed its response to the lawsuit, claiming that customers are not only told “your purchase of this digital product amounts to a licence”, but that “reasonable consumers” already understand this anyway without having to be told.

Sony’s argument is that because digital copies of games are not a finite resource, and that because multiple people can buy a digital copy of the same game, that means nobody actually ‘owns’ it – if they did, nobody else would be able to have it.

“As plaintiffs admit, Section 1 of the SPLA likewise explains that ‘the Software is licensed to you, not sold’, Sony’s filing reads. “This makes sense. In the digital age, it is not plausible to allege that reasonable consumers believed they were obtaining ‘ownership’ of a digital game.

“Were that the case, then Plaintiff Edward Heycock would not have been able to obtain the game Resident Evil Requiem on February 25, 2026 for $69.99 from the PlayStation Store after Plaintiff Jason Mendoza had obtained Resident Evil Requiem on February 14, 2026, because Mr Mendoza, not Sony, would have owned it then.”

And on this, Sony can fuck all the way off. This is completely wrong on a variety of levels.

Let’s start with the fact that the internet is chockablock with discussions trying to unconfuse many people when it comes to what they bought in a digital purchase. There are Reddit posts asking this question. There are tech blogs that have put out specific articles answering the question of ownership of certain digital goods. Or, if the wider internet doesn’t suffice for you, the FTC has articles on its own website that try to help address ownership rights for the public for digital goods. Here’s a snippet that will help drive home the second reason Sony’s statement is so dumb.

When you buy a physical item, you’ve got it. It’s yours. But when you click the “buy” button on a digital product, it really depends. You may have access to it only while you have an active account with the platform or website that sold it, or only for as long as that platform or website stays in business. Another factor is Digital Rights Management (DRM) software, which is attached to many digital items and is the thing that makes it impossible, for example, for you to play a video game on a different console brand.

Another reason why you might not have full control of your digital product is that what you really got when you clicked “buy” is often merely a license to access the content. This fact is often explained only in fine print in the terms of service — terms that the seller can usually change at will. And if the seller itself has licensing issues with the content you bought, then your own license to use the digital item can become worthless. All things beyond your control.

So all of these entities putting out all of this information to try to educate the public about what the hell they bought with a digital purchase are only speaking to the unreasonable? That’s, dare I say, an unreasonable thing to say.

And in that FTC post, did you happen to notice just how many qualifiers are stuffed into those two paragraphs? It depends. May. Many. Might. Often. So why all of those qualifiers?

Because some digital purchases can and do confer ownership to the buyer. Not everyone is out here selling a license. Some digital goods are sold as permanent ownership.

So, no matter how this particular lawsuit shakes out, Sony needs to either understand their own customers’ sentiments and knowledge far better than they do, or they need to stop saying things that they know are false. I can attest that the general public does not have a firm understanding of their ownership rights and what they’re actually buying with digital purchases. Pretending otherwise is nonsense.

10:00 AM

Kanji of the Day: 働 [Kanji of the Day]

✍13

小4

work, kokuji

ドウ

はたら.く

働く   (はたらく)   —   to work
働き   (はたらき)   —   work
労働   (ろうどう)   —   manual labor
厚生労働省   (こうせいろうどうしょう)   —   Ministry of Health, Labour and Welfare
労働者   (ろうどうしゃ)   —   worker
共働き   (ともばたらき)   —   both working
稼働   (かどう)   —   operation (of a machine)
働きかけ   (はたらきかけ)   —   pressure
労働組合   (ろうどうくみあい)   —   labor union
厚生労働相   (こうせいろうどうしょう)   —   Minister of Health, Labour and Welfare

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 鍵 [Kanji of the Day]

✍17

中学

key

ケン

かぎ

鍵盤   (けんばん)   —   keyboard (of a piano, typewriter, etc.)
合鍵   (あいかぎ)   —   duplicate key
鍵っ子   (かぎっこ)   —   latchkey child
鍵穴   (かぎあな)   —   keyhole
合い鍵   (あいかぎ)   —   duplicate key
勝敗の鍵を握る   (しょうはいのかぎをにぎる)   —   to have the game in one's hands
鍵盤楽器   (けんばんがっき)   —   keyboard instrument
打鍵   (だけん)   —   keystroke
鍵をかける   (かぎをかける)   —   to lock
内鍵   (うちかぎ)   —   internal lock

Generated with kanjioftheday by Douglas Perkins.

09:00 AM

Meta’s $17 Billion Settlement Is A Bad Deal For Teens And All Social Media Users [Techdirt]

Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.

In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:

  • The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
  • The Settlement places severe restrictions on Teens that can only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
  • The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
  • The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism.

Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.

Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.

Age Gates Reinforced By Age Estimation Technology

In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And Further, Meta will now enforce these age gates with “age assurance” technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The Technology also just adds a layer of creepiness into the user of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]

1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) orage assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.

Those methods might include both commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.

This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.

For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.

Those estimated to be 13-17 years old will be limited to Teen User accounts.

Those estimated to be under-13 will lose their accounts altogether.

Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]

(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.

What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement.

How accurate does the age assurance process need to be?

The Settlement sets maximum false positive for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more 10% for ages 16-17 and 3% for ages 13-15. 

6. Age Assurance Standards.
(a) U18 False Positive Rate Thresholds.
(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall
meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.
(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: 
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.

Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]

9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.

The Settlement generally shows little concern for those falsely placed in its Teen User category.

Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).

(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and 

Any age assurance process Meta uses must be tested annually.

Data minimization

The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” But the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information … where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires at that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.

8. Data minimization and security.
(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).
(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.
(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.

Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)

Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to these estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.

Time restrictions

Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits:

  • Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
  • School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
  • Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
  • “Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be monetarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:
Exhibit G from Meta Settlement showing phone warnings

To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such users controls would have recognized that teens have human rights, agency, and autonomy.

But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.

Feature restrictions (§II.C-D)

Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service.

Again, these would be useful user controls that should be offered to users of all ages.

By default, teens will not see the number of likes or other reactions to their posts.

Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques. 

X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.

Meta has already had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters. 

Content restrictions (P.1, §II.E, as defined by §I.C, E, F)

For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.

C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.
D. “Age Assurance Methods” shall have the meaning set forth in Section II.
E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.

The issue here is that some of these categories are problematic. For example, the Restricted Goods & Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our Stop Censoring Abortion campaign, and in our comment to the Meta Oversight Board. And under the Adult Nudity & Sexual Activity, Meta blocks teens from “real world art of visible genitalia … where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to representations of indigenous womenbreast cancer awareness posts, and posts about testicular and breast self-examseducational posts about ovulation. And it has disproportionately applied the standard to gay and lesbian content in as compared to straight content.  

And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressure Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earned First Amendment defenses to make its own curatorial decisions. 

C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.

The Parental Supervision Tradeoff 

All of these Teen User restrictions can be modified – but only if the Teen User enrolls in the Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, Parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).

And Parental Supervision comes with a huge privacy tradeoff. In exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G] 

Parental Supervision
1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.
2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.
3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.
4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.
5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.
6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.

Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8] 

This may be workable for young people with healthy and safe relationships with their parent or guardian. But obviously not good at all for a Teen User lacking such a safe relationship. 

More Surveillance, Not Less

Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.  

For example: 

  • Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)] 
  • Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)] 
  • Meta pledges to utilize and improve its existing “soft matching models” that track signals such as device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)] 
  • Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3] 
  • Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4] 
  • The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E] 

Moreover, one of the chief threats of Meta’ surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain. 

Meta Has To Pay The States — Establishing Norms Beyond Meta

The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten year-life of the Settlement, these annual payments will total over $11 billion plus the prospect of an additional $5 billion—if Meta competitors adopt the same measures. 

This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get an additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance and age-gating as the norm across online services. 

1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).

2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:

(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.
(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.

3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment

The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance. 

Republished from the EFF’s Deeplinks blog.

07:00 AM

New Alpha Release: Tor Browser 16.0a11 [Tor Project blog]

Tor Browser 16.0a11 is now available from the Tor Browser download page and also from our distribution directory.

This version includes important security updates to Firefox.

⚠️ Reminder: The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.

If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the stable release channel.

Send us your feedback

If you find a bug or have a suggestion for how we could improve this release, please let us know.

Full changelog

The full changelog since Tor Browser 16.0a10 is:

ICE Finalizes Stun Glove Purchase, Claims There’s No Other Way To Handle ‘Violent’ Migrants [Techdirt]

This was inevitable. ICE has billions of new money to spend, zero shame, and not a single adult in a leadership position capable (or willing!) to talk the agency off the ledge.

ICE decided the neat new tool of cruelty it absolutely had to have were gloves that behave like stun guns or low-powered Tasers. Only one company makes these: Compliant Technologies. There’s a reason for that. Prior to ICE’s devolution during Trump’s second term, no agency of any size really had any reason to buy these stun gloves.

Early adopters were prisons and (wtaf) schools. These gloves made limited sense in prisons where guards are working in confined areas and possibly don’t want to utilize any weapon that might be taken away and used against them. Why they’re being used in schools is literally unimaginable. But here we are in the 21st century, witnessing schools pleading with law enforcement agencies to stop shocking their students with Compliant Technologies G.L.O.V.E., or (brace yourself) Generated Low Output Voltage Emitter, which sounds more like an electrician’s tool than something capable of rendering minors immobile.

With only one provider available, the decision was easy. ICE finalized its threatened purchase of 6,000 G.L.O.V.E.s from Compliant Technologies late last week, ensuring officers will have even more ways to inflict pain on thousands of non-criminals, ranging from ambushed migrants to peaceful protesters who have managed to momentarily inconvenience ICE’s kidnapping squads.

Everything about this is awful, but ICE’s defense of this purchase is both bizarre and palpably evil:

ICE does not currently have an empty hand use of force device to provide to the field amidst unprecedented levels of threats and violence against ICE officers and agents to help ensure they can de-escalate tense situations before they turn violent,” the agency wrote in procurement documents.

WTF? Do you know who else doesn’t have “empty hand use of force devices?” 99.999% of US law enforcement agencies, including federal agencies that generally face more legitimate danger from arrestees, like the FBI, ATF, and Secret Service. And do you know why? Because it’s an absolutely psychopathic use of force “option.”

Somehow, it’s ICE that desperately needs this hideous option, even though all it’s really doing at this point is doing migrant mop-up work — arresting migrants by the thousands despite almost none of these remaining migrants having ever been arrested, much less convicted, for violent crimes.

The procurement document [PDF] contains more supporting statements from ICE that make it clear these gloves aren’t really meant to help subdue violent arrestees. The gloves are being purchased to give ICE officers the means and the opportunity to basically stun anyone they run into, including people they aren’t even seeking to arrest. This paragraph suggests stun gloves are nothing more than a violent way for ICE officers to “de-stress” while at work:

ICE requires a non-lethal, de-escalation device intended to diffuse situations of high-stress environments where physical altercations are likely, such as field domestic disputes or inmate transport in jails. It will be used when a subject is actively or passively resisting and an officer needs to gain control quickly to prevent injuries to both parties.

The document doesn’t explain what the phrase “field domestic dispute” means, nor does it provide context. Reading “domestic dispute” in its usual context, the sentence seems to suggest officers should be able to stun their domestic partners into compliance when things at home get a bit heated. Obviously that’s not what that phrase means, but it’s an extremely weird grouping of words that seems to be specific to ICE and its desire for gloves that can shock people.

Further down, ICE makes it clear it’s going to allow officers to deploy the gloves against peaceful protesters or anyone else who might be considered an obstacle to officers’ kidnapping plans.

“Soft” Empty-Hand Control- Enabling officers to briefly distract a subject who is resisting or hiding their hands to secure handcuffs without transitioning to higher, more forceful levels of control.

Civil Disturbance- Assisting crowd control units in moving groups or denying access to areas without requiring lethal or high-impact munitions.

ICE makes it sound like its officers will stop shooting or beating people because of these gloves. But I can guarantee you the gloves will be used whenever possible, especially when they might facilitate a beating. Since pretty much every ICE officer wears gloves, it will be impossible to tell who’s wearing the stun version and who’s just trying to look like a Call of Duty lobby idle animation. Officers are absolutely going to love these gloves because the element of surprise will always be on their side.

There’s no way ICE seriously believes 6,000 pairs of hand-worn cruelty application devices will actually limit the use of deadly force. But it can probably assume it might reduces shootings because its thousands of under-trained officers will probably be less willing to grab a metal gun from near their waist when they’re not sure whether or not their G.L.O.V.E.s are still activated.

This is just a way for ICE officers to hurt more people while pretending stunning anyone an officer touches is synonymous with de-escalation. This is just an agency loaded from top to bottom with sadists seeking out novel ways to inflict more pain.

06:00 AM

Hiking the Alps [dperkins]

This year progress on the Top 100 Mountains continues. Here are pictures from day and overnight trips to the Japanese Southern Alps and Central Alps this year.

Mt. Hoo

During spring break, I drove to Kofu, Yamanashi, and climbed Mt. Hōō (鳳凰山). There are several summits, and given the abundance of snow and ice, I summitted Jizō-dake (地蔵ヶ岳), notable for a giant rock at the top — the Obelisk. The trail was slow but fun: one third dirt, one third ice, and one third snow.

20260330.1.Alps.jpg 20260330.2.Jizo-dake.jpg 20260330.3.Obelisk.jpg

Yatsugatake & Mt. Tateshina

The snow was gone by May, so I drove up to the Central Alps in southern Nagano and climbed Yatsugatake (八ヶ岳). Yatsugatake has a handful of summits, and my route went over Amida-dake (阿弥陀岳) and Aka-dake (赤岳). The next day, I went up Mt. Tateshina (蓼科山), another mountain not far to the north. One fun thing about hiking so much in the Southern and Central Alps this year is learning the landscape. Many of these mountains are visible from one another on clear days, and if you don't know what you're looking at, it's guaranteed that some other hiker will tell you. Mt. Fuji shows up from time to time, too.

20260530.1.Yatsugatake.jpg 20260531.1.Tateshina.jpg

Mt. Kita & Mt. Aino

The second- and third-highest mountains in Japan are Mt. Kita (北岳) and Mt. Aino (間ノ岳), and you can day trip them if you really want to. There are many mountain huts along the way, so your gear need not be burdensome, and the scenery is majestic. Nevertheless, it's strenuous to say the least, and my legs were aching by the end of the day.

20260703.1.Fuji.jpg 20260703.2.Hoo.jpg 20260703.3.Senjo.jpg 20260703.4.Kaikoma.jpg

Mt. Tekari & Mt. Hijiri & Mt. Kisokoma

In late summer I drove to Nagano for more hiking. First was a two-day hike. It was a brutal ascent up to Mt. Tekari (光岳), but once I got up there, following the ridge north over Mt. Chausu (茶臼岳) was pleasant, and the weather was wonderful. After the long day with massive vertical gain, I spent the night at Chausu Hut (茶臼小屋). The mattress was thin and I slept poorly, but the building was warm and the food was good. The next morning we all awoke to a spectacular view of Mt. Fuji at sunrise. The pictures speak for themselves.

On the second day, I continued north, stopped briefly at the top of Mt. Kamikochi (上河内岳) went to the summit of Mt. Hijiri (聖岳), and headed back down to the car. Going down was much easier than going up, but my shoes were getting old and I got some blisters. That afternoon I went to an onsen in the nearby village of Toyamago, because a long bath after a long hike is just lovely, and then drove north for an hour.

After sleeping in the car, I got up and took the alpine bus and cable car most of the way up Mt. Kisokoma (木曽駒ヶ岳). From there it was a leisurely stroll to the summit. Many years ago we were here on a school trip but didn't get to the top because of bad weather. So it was nice to return, go the extra kilometer, and get the good vibes and views.

20260831.1.Tekari.jpg 20260831.2.Chausu.jpg 20260831.3.Fuji.jpg 20260901.1.Fuji.jpg 20260901.2.Fuji.jpg 20260901.3.Fuji.jpg 20260901.4.Ridge.jpg 20260901.5.Hijiri.jpg

Enrollment and learning [Seth Godin's Blog on marketing, tribes and respect]

“Why are you taking this class?”

That seems like a fair question. After tenth grade or so, it’s a choice, after all.

One honest answer is, “I have to get a good grade to get to where I want to go.” That means certification, compliance, regurgitation. It means enrollment in the outcome, not the process. When this happens, we’re seeing a failure of the system we call education. Because that’s not learning.

One answer is, “Because I’m curious.” This is a great reason to take a class, and the instructor’s job isn’t merely to satisfy the curiosity; it’s to amplify it and turn it into a habit and the practice of the autodidact.

For many professional settings, the answer might be, “To learn how to use these tools and this insight to make a change in the world after I graduate.”

That sort of enrollment becomes a productive bargain. It gives the student agency–you don’t have to like everything the instructor has to say, you don’t have to use it when you leave, but the standard is: Is it helpful to imagine having this tool in your kit, and does this course prepare you to use the tool effectively?

Teaching is expensive, so is learning. Active enrollment on both sides is part of the bargain. Students are free to reject the pedagogy, the tools, even the aims of the current practitioners of a craft. But they’re on the hook to do that after they’ve absorbed what the instructor has to offer.

Take what you need and leave the rest.

      

The USPS Lied—To Us, the Court and Congress [The Status Kuo]

Image courtesy of VoteBeat

The U.S. Postal Service has been openly defying a court order in an attempt to throw the midterms into electoral chaos. That’s according to a new whistleblower complaint, made public on Tuesday by Sen. Richard Blumenthal (D-CT). The complaint alleges USPS kept building the technical system underlying Trump’s mail-voting restrictions even after a federal judge ordered the work stopped.

The Postal Service also lied about what it was up to. On July 15, Postmaster General David Steiner and USPS Board of Governors Chairwoman Amber McReynolds wrote to Senate Democrats declaring, “The Postal Service is abiding by these injunctions, which are also currently under appeal.” USPS leadership continued to claim publicly and to Congress that the agency was not moving forward with the rule, even as work on the portal resumed two weeks later.

The whistleblower complaint also contains a worrisome warning: The system, as designed, could reject entire batches of mail ballots over a single scanning error. That gives USPS a mechanism for disenfranchisement at scale. Attorney Marc Elias of Democracy Docket noted that a batching rule that groups ballots by ZIP code would disproportionately affect Democratic-leaning, higher-density areas. And as Sen. Blumenthal pointed out, voters who recently changed their names after marriage or moved are among those most likely to trigger a mismatch—the same populations targeted by the SAVE Act.

“It may be sloppy. It may be chaotic,” Elias observed. “But it is designed to achieve what Trump wants.”

Subscribe now

The legal landscape, CliffsNotes version

As I wrote about earlier, the backdrop to the whistleblower complaint is a pitched legal battle over a March executive order. It sought to aggressively restrict mail balloting by directing USPS to withhold delivery of ballots from any state that refuses to submit its voter rolls to the federal government. To comply with the order, USPS hastily built the “Federal Ballot Mail Portal” and list-matching system now at the center of the whistleblower’s account.

The legal fight reached the Supreme Court on Aug. 24. As I explained in my piece shortly after that ruling, the radical conservative majority, abusing the emergency docket once again, cleared a narrow procedural path forward. It ruled that the original lawsuit was not “ripe” because there was no formal rule in place, the plaintiffs had not yet suffered actual harm and therefore the court lacked jurisdiction to issue its injunction. That twisted procedural holding left the underlying legality of Trump’s order, as well as the USPS implementing rule, open to challenge.

Bowing to the SCOTUS ruling, Judge Indira Talwani lifted her block on Aug. 26. But by the end of that day, a coalition representing 24 states, Washington, D.C., and voting-rights groups filed a fresh challenge to the now-finalized rule. Judge Talwani responded the next day with a new 14-day restraining order blocking the rule’s mandatory provisions. It expires Sept. 10.

Defying the court and lying to Congress

According to the whistleblower’s timeline, USPS began building the Federal Ballot Mail Portal on June 15. The agency halted that work on June 25, the day Talwani first ruled Trump’s executive order legally void. It then resumed construction on July 29, the same day the White House appealed Talwani’s order to the Supreme Court.

But hold up. Just because you appeal a ruling to SCOTUS doesn’t mean you can start disobeying it. It’s simply on appeal, so you’re still bound by the order unless and until a higher court overturns it.

USPS didn’t care. The complaint describes the restart of work on the system as a mystery: work was “suddenly resumed without explanation of what authority permitted U.S.P.S. to ignore the court order.”

Note the sequence of events. The last of the injunctions covering USPS’s work “was not lifted until Aug. 26, 2026, after weeks of work were done on the new election ballot mail IT system,” the complaint states. Yet work continued at “a breakneck speed” while the injunctions were in place, in defiance of the court’s order.

USPS disputes that its actions amounted to defiance. The agency confirmed it continued work on the portal during the legal fight, but it claims it remained in compliance because it was not yet using the parts of the system that could invalidate anyone’s vote.

Nice try, but no. That’s like saying you were complying with a ban on nuclear weapons while you continued to purify weapons-grade uranium and build missile systems to deliver the warheads. “We haven’t used the nukes yet” isn’t the standard.

And Judge Talwani’s order wasn’t the only one the government ignored. In a parallel D.C. lawsuit, a federal judge had ordered the Justice Department to notify the court of any “material factual developments while this litigation remains pending.” The DOJ did not inform that court when USPS resumed work in late July despite another court’s injunction. That seems pretty material.

Talwani had already found in her Aug. 25 ruling that USPS violated her injunction. She wrote, “[D]espite the Defendants’ protestations that ‘[t]he United States takes its obligation to comply with court orders very seriously,’ the court finds that Defendants violated the preliminary injunction in this case.”

But the extent of the violation was not fully known until the whistleblower’s complaint became public. Blumenthal characterized the overall pattern as intentional and issued a stark warning. “This is not just incompetence, it is ‘designed malfunction,’” he told reporters.

A system built to fail one ballot at a time

The system USPS built (while telling Congress it wasn’t building anything) relies on a multi-step verification process, designed to produce mass rejections of ballots.

States must first upload a “Mail-In and Absentee Participation List” of every voter set to receive a ballot. A batch manifest for each mailing is then checked against that list, and anything short of a 100 percent match sends the whole manifest back to the state.

Ballots that clear the manifest check face a second hurdle. USPS clerks sample barcodes from each batch at the point of mailing: 15 codes for batches under 1,000 ballots, 350 for batches between 1,000 and 10,000, and 400 for anything larger. The complaint states what happens next: “As presently designed, if even one barcode on one single ballot in a bulk-mailing of 10,000 ballots fails to properly scan during the verification process, the entire batch is rejected and sent back to the state—effectively stopping the ballots from being mailed to voters.”

A White House spokesperson downplayed concerns about the barcode system, saying it was “neither complex nor unique for USPS since the Postal Service regularly uses bulk mailing and intelligent mail barcodes for a wide variety of large customers.”

USPS did not disclose this zero-failure threshold to the public during the comment period before finalizing its rule. The agency’s final rule expressly declined to provide an anticipated ballot-rejection rate, leaving election officials and voters unable to gauge the consequences of the system the agency was actively building, even while denying it was doing so.

That omission is hard to read as an oversight, particularly given USPS’s own operational history. A 2017 audit of package tracking by the USPS Office of Inspector General documented technical problems with USPS scanners, including delayed transmissions and signal obstruction. The agency’s own “zero-failure design” for mail-in ballots leaves no room for those kinds of known scanning problems, particularly given batches running into the tens of thousands of ballots.

Then there is the rushed development schedule. USPS set a three-month timeline for a project the whistleblower says should ordinarily take 9 to 12 months or longer. The portal also skipped standard software testing. In the final days before its planned Sept. 1 launch, multiple USPS officials described the development process to the whistleblower as “a shit show.”

Democracy activists and lawmakers respond

Sen. Blumenthal, ranking member of the Senate Homeland Security Committee’s Permanent Subcommittee on Investigations, released the whistleblower’s disclosure alongside a letter to Postmaster General Steiner. He described the findings as “alarming” and declared they “present a clear picture of a fatally flawed process that cannot and will not protect American voters.” He gave Steiner until Sept. 8 to respond, requesting records and communications about the system’s development, including whether work continued during periods USPS told Congress it had stopped. He also referred the matter to USPS’s Inspector General.

On a call with reporters, Blumenthal was even more blunt about the stakes. “The main takeaway for me is that the Postal Service has designed a system to disenfranchise millions of Americans,” he said.

Rep. Robert Garcia (D-CA), ranking member of the House Oversight Committee, framed the disclosure as a deliberate power grab rather than mere mismanagement. “Trump is creating a new tracking system at the US Postal Service that is untested, dangerous, and threatens to totally disrupt ballot delivery for millions of American citizens,” Garcia said in a statement. “This is an unconstitutional and dangerous power grab and must be permanently and immediately blocked.”

California Attorney General Rob Bonta, whose state is among the plaintiffs and relies heavily on mail-in ballots, vowed to fight on. “From the beginning, it’s been clear that President Trump doesn’t understand how elections work. He’s repeatedly broken the law, so we’ve repeatedly taken him to court.” Gov. Gavin Newsom upped the ante considerably. “Defying court orders to engage in election interference should bring prison time,” Newsom said. “Lock them up. Defend democracy.”

Where things stand

Judge Talwani reaffirmed her restraining order on Monday, rejecting a White House request to lift it to allow USPS to move forward with its portal so long as it doesn’t force states to use it. That’s the same improper loophole the agency had already squeezed through once, according to the whistleblower’s account.

The Justice Department is taking the fight up the judicial ladder. It’s asked the 1st U.S. Circuit Court of Appeals to treat Talwani’s temporary order as an appealable injunction and to stay it, arguing her 14-day window has the “practical effect” of a preliminary injunction even though it isn’t labeled one. The appeals court’s response will determine whether Talwani’s order holds through Sept. 10.

That timeline matters. States are already preparing to send out mail-in ballots for the midterms. North Carolina ballots are scheduled to begin mailing Sept. 4, and Alabama’s follow on Sept. 9. So the legal fight is about to collide with the real world, including whether USPS actually starts using the system once ballots begin moving.

With all these shenanigans from the federal government, Rep. Ted Lieu (D-CA) was clearly fed up and gave voters some blunt advice at a press conference Tuesday morning. “Just go fucking vote. The Trump administration is going to try to suppress your vote.”

04:00 AM

Daily Deal: The Adobe Graphic Design Bundle [Techdirt]

The Adobe Graphic Design Bundle has 3 courses designed to help you learn the essentials of graphic design and how to apply those skills to your projects. Courses cover Photoshop, Illustrator, and InDesign. You’ll learn all aspects of the design process. It’s on sale for $50.

Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

Whistleblower: USPS Defied A Court Injunction To Build An Untested, Undocumented Ballot-Blocking System. Its Own Staff Call The Process “A Shit Show.” [Techdirt]

Even as Donald Trump regularly uses mail-in ballots himself, he has decided that mail-in ballots are a system by which voting fraud occurs. To be quite clear, this is bullshit. There is astoundingly little evidence of significant voter fraud, and that’s equally true between in-person and voting-by-mail. And there’s zero evidence that mail-in voter fraud has ever even come close to swinging a federal election. Indeed, what little voter fraud there is often involves mixups of people who thought they were eligible to vote accidentally trying to vote when they were ineligible.

Either way, a few years back, Trump started blaming mail-in ballots for the completely mythological “rigged elections” he keeps insisting are happening, and of course the MAGA establishment quickly fell into line. We just recently wrote about how the Fifth Circuit appeals court has been working overtime to pretend that it’s well-established that mail-in ballots are insecure. But the bigger issue is that earlier this year, Trump issued an executive order to try to limit the use of mail-in ballots.

Specifically, the executive order tells the US Postal Service to engage in a “rulemaking” that is designed to make it much more difficult for states to offer mail-in ballots. And, on top of that, it demands that states that offer mail-in ballots must hand over their voter rolls to the federal government. The White House has been demanding voter rolls from a bunch of states, and so far every state that has engaged in litigation over this issue has won (it’s now over 20 cases, all of which have gone against the administration).

On its face, the executive order should be seen as pure nonsense, given that the states get to run elections, not the federal government. And even if it were the federal government, that’s not what executive orders are for. But given that the same Supreme Court that insisted no Democratic president could do literally anything without explicit congressional approval now treats Donald Trump as the very special birthday boy who gets whatever he asks for, we have to take even his most ridiculous demands seriously.

A district court judge, Indira Talwani, who is overseeing two of the cases challenging that executive order has issued injunctions in both cases, blocking the US government from putting it into effect. As Talwani notes, the states get to determine how their elections are run, per the Constitution.

Article I of the Constitution also empowers the States to prescribe the “Times, Places, and Manner of holding” congressional elections. U.S. CONST. art. I, § 4, cl. 1. “[T]hese comprehensive words embrace authority to provide a complete code for congressional elections, not only as to times and places, but in relation to notices, registration, supervision of voting, protection of voters, prevention of fraud and corrupt practices, counting of votes” among other issues. Smiley v. Holm, 285 U.S. 355, 366 (1932).

The President is elected by vote of the Electoral College. See U.S. CONST. amend. XII. The Electors Clause empowers each State to appoint electors to the Electoral College “in such Manner as the Legislature thereof may direct.” U.S. CONST. art. II, § 1, cl. 2. The States require their electors be appointed by popular vote of qualified voters. See Chiafalo v. Washington, 591 U.S. 578, 584 (2020). Accordingly, the States alone determine voter-eligibility requirements, subject only to the outer limits of the Constitution. See, e.g., U.S. CONST. amend. XIX (“The right of citizens of the United States to vote shall not be denied or abridged . . . on account of sex.”); U.S. CONST. amend. XXVI (“The right of citizens of the United States, who are eighteen years of age or older, to vote, shall not be denied or abridged . . . on account of age.”). For presidential elections, the Electors Clause gives States the primary authority to decide how electors are chosen.

As a result, the court ordered (among other things) the USPS to not take any steps to implement the executive order.

Furthermore, in the latter injunction, Talwani pointed out that the federal government failed to present literally any evidence of mail-in voting fraud:

The record is devoid of any declarations or other proffered evidence to suggest that mailin voting has resulted in voting by non-citizens.

In other words — the DOJ, despite the president insisting that non-citizen voting was happening all the time with mail-in ballots — didn’t even try to present evidence of that to the judge.

But this week, a USPS whistleblower revealed that the Postal Service has been building the machinery to implement the order anyway — issuing a final rule on August 26 and, per the disclosure, restarting development around July 29 even though the very clear injunction against doing anything was still in force. The whistleblower went to Senator Richard Blumenthal who released the whistleblower’s report, along with a letter to the Postmaster General demanding an explanation.

My office is in receipt of an alarming whistleblower disclosure (the “Disclosure”) outlining the United States Postal Service’s (“USPS”) perilously rushed and potentially unlawful implementation of President Trump’s Executive Order seeking to restrict mail-in voting. The whistleblower’s allegations make clear that USPS lacks the technical or operational capability needed to effectively implement the EO’s provisions in a way that safeguards every citizen’s right to vote in the upcoming midterm elections. Despite this, the Trump Administration appears intent on USPS moving forward with its flawed plans, no matter the chaos they may create. The whistleblower’s allegations also provide disturbing information suggesting that USPS may have violated a court order by continuing to implement the EO despite being ordered to cease all such work. We urge you to abandon this ill-conceived, unconscionable plan and ensure that all Americans can exercise their constitutional right to vote, including by mail, without interference by USPS.

The USPS’s defiance of the court order here is pretty direct. The judge issued an injunction on Section 3 of the executive order on June 25th. USPS did, in fact, stop work on the portal, while the DOJ appealed. On July 25th, the appeals court upheld the injunction, noting that the executive order “directs unprecedented levels of involvement by federal officials in how states administer elections.”

But just four days later, on July 29th, the whistleblower says that USPS leadership told the IT team to start building a tool to enforce the executive order, in direct and obvious defiance of the injunction against it. Then on August 11th, the district court expanded the injunction, which should have made it even clearer to USPS to stop. But USPS appears to have completely ignored that. While the Supreme Court put a stay on the injunction on August 24th, two days later the district court issued a temporary restraining order. But it appears that basically none of that mattered, as USPS leadership had the IT team continue to work on the thing they were explicitly barred by multiple courts to do.

As Blumenthal’s letter summarizes, the USPS rushed to build a portal whose main job appeared to be to block the mailing of mail-in ballots to voters (i.e., this is not them swiping already completed ballots, just refusing to send them to voters in the first place). And because USPS is now run by people whose main qualification is loyalty to Donald Trump, the execution is exactly as incompetent and slapdash as you’d expect:

The whistleblower’s Disclosure describes an unprecedented process that allows USPS to decide whether ballots issued by state election officials should be mailed. To do so, USPS is building an entirely new online system, the USPS Federal Ballot Mail Portal and related IT systems (the “Portal”), which will be used to screen ballots submitted by state election officials prior to USPS agreeing to mail them to voters. The Disclosure identifies problems at every stage of USPS’s development of the Portal, demonstrating deeply flawed plans for implementation. According to the whistleblower, USPS’s effort to develop and deploy the Portal has been “rushed,” “risky and haphazard” because leadership has demanded an impossible timeframe. In an effort to meet impossible deadlines, USPS has eliminated standard and needed testing, thereby creating substantial risk of a “catastrophic failure” of the system that could “derail the midterm elections.”

What could possibly go wrong:

USPS began work building the Portal on or around June 15, 2026 just three months before the date USPS planned to launch the system and just five months before the November 2026 midterm elections. On or about June 25, 2026, USPS ordered work on the Portal to cease due to a court order enjoining implementation of the EO. That work stoppage persisted for approximately a month, further reducing the time that USPS had to build the new system. According to the whistleblower, building the information technology infrastructure necessary to complete the Portal could take a year or more. Yet, USPS leadership demanded that the Portal be completed for a launch date of September 1, 2026, less than six months after the EO was issued. As a result of this rushed process, USPS has been unable to conduct tests of the Portal to ensure its proper functioning, troubleshoot problems, or distribute instructions on use to state election officials. According to the whistleblower, the Portal “violates standard principles of testing and debugging new software before launch.” Normal procedures at USPS for such systems include internal testing, customer acceptance testing, and a final development stage before release to public facing users. The Portal has gone through none of these basic checks.

Going beyond just Blumenthal’s summary, the actual whistleblower report has some astounding details about how the bosses at USPS working on this seem to have no clue how to build reliable software (one wonders if they’re ex-DOGE folks):

Throughout the development of the project, those giving guidance to tech developers lacked understanding of project parameters. Different team members continued to have different understandings of how the system is supposed to function which caused ongoing and greater confusion among the group.

While there continued to be no clear written requirements for the software and IT system, those developing the new election ballot mail IT system were placed in the position of trying to glean requirements from opaque comments at meetings. It continued to be clear that those giving directions did not understand exactly what was to be built. There was a growing concern that many were grasping at straws, trying to do their best to decipher cryptic instructions, and likely missing important details. Elements as basic to the project as whether a validation issue was a “warning” or an “error” continued to be unclear as leadership provided inaccurate information about these issues. To clarify, a warning allows a ballot to continue through the process while an error stops it. These occurrences reinforced the need for written requirements and the ongoing failures in communication.

Even so, the team was told that the system had to be ready to launch… by yesterday. They were given less than a month to figure it out. If you know anything about software development, project management, or… just about how anything works, these paragraphs are concerning:

Around this time at least one senior USPS official seemed to up the stakes by becoming a more active voice pushing for project completion on the new deadline. For example, when IT workers expressed concerns about the quality of the product under USPS leadership’s compressed timeline, the senior official stated that they (the official) “were not trying to stop anyone from getting their ballots and what is the problem?” Employees went on to reiterate concerns that many teams were still missing details of how systems were supposed to work and that written requirements could ensure that everyone was on the same page. The senior official was dismissive of these concerns. The conversation continued with others repeating the need for clear requirements; while leadership insisted that it was easy to understand what was needed and also that there was no time to write down the requirements. The contradiction was obvious that it should not take a great deal of time to write down something that is easily understood.

Concern continued to grow and the Whistleblower became aware that IT teams referred to the largely oral requirements as a “moving target.”

By the third week in August “user stories” – short, plain-language descriptions of a software feature written from the perspective of an end-user (focused on what a user wants to achieve and why) – were described as unusable “garbage”. User stories that had been generated had incorrect information and needed to be updated.

Throughout this project, the Whistleblower understood that IT teams were siloed and not communicating with one another. Teams had so little understanding what other teams were working on such that when elements were brought together, the teams were unaware of various developments, creating more work to utilize even the completed portions of the work.

By August 20, there was a massive rush as teams tried to get “everything committed” – in order to meet the goal of getting the ballot mail systems ready for customer testing on August 24. The resulting chaos caused work to be overwritten. By this point IT workers were resigned that even if they could get the portal put together and working in the internal development environment, there would not be enough time to test and fix any issue that would inevitably arise in customer testing.

The system was designated a grand total of four (FOUR!) days of user testing (and it’s not even clear if the testing actually happened):

By August 24 the expectation was that if somehow everything was accomplished on Monday the 24th, the code would end up in internal testing on Tuesday, August 25, then move to customer testing on Wednesday, August 26 allowing only four work days to test. For a system that manages something as important as handling voting and ballots, 4 days of user testing is entirely unreasonable. Only leadership seemed to express hope that the September 1 deadline was viable. If a problem was found during testing, which was almost certain, the IT workers would need to fix it and that fix would need to move back to internal testing and then into customer testing again. If a problem wasn’t found in the first 2 days, the fix could not make it back to the customer testing environment in time to meet the deadline.

In just the week prior to September 1, 2026, the Whistleblower learned that IT workers have described the election ballot mail development process as “a shit show.”

Very confidence building!

The whistleblower notes that a similar internal tech project that the USPS IT team built in the past “set aside 47 working days for testing.” And this one gets four.

Perhaps an even bigger problem than the slapdash hand-wavey “build a complex system in weeks with no written requirements, and no time for testing,” was the demand for a “zero percent failure rate.” That means that if a single barcode won’t scan — whether because of bad connectivity or a voter got married and changed their name — USPS bounces the entire batch back to the state. And these batches can run to tens of thousands of ballots. Back to Blumenthal’s summary:

Not only is this system astonishingly untested, USPS has simultaneously implemented an impracticable zero percent failure rate. When ballots are submitted to USPS in large-volume batches, if any one ballot in the batch cannot be verified against the Portal, all ballots in that batch will be rejected. For example, if a state election official brings a batch of 10,000 ballots to USPS and USPS is unable to match just one of those ballots against the Portal – because, for example, someone has recently changed their name after marriage or they’ve moved – then USPS would refuse to mail the remaining 9,999 ballots as well. As the whistleblower notes, “USPS expects the state to take back the entire batch to cure the issue with the single ballot…” Should the slapdash Portal mistakenly mark a ballot as unverified, there is no clear process by which state election officials or voters themselves can challenge the rejection. The Rule simply vaguely states that they “will be informed of the escalation procedures should they decide to challenge a rejection.” Voters intending to cast ballots by mail may not even be aware that their ballots have been rejected, or were part of a rejected batch, until it is too late to secure an alternative ballot or vote in person. Expecting a well-built, thoughtful Portal to return an accurate result 100 percent of the time is already a stretch—expecting a “rushed,” “risky and haphazard” Portal to do the same is a recipe for disaster.

A zero percent failure rate means that a single bad scan (which could happen for any reason) could block thousands of ballots (literally all of which could be legit and fine) from being sent out. Given that eight states already run elections entirely by mail, this could mean significant percentages of voters just not receiving their ballots at all.

And, we’re relying on a hastily built system with barely any testing not to have any bad scans that lead to thousands of ballots being blocked.

Of course, what Blumenthal and the whistleblower call “risky and haphazard” most others might call “deliberately designed to suppress votes and create chaos that will allow MAGA to call into question the validity of an election.”

Look, this is just terrifying: the president and his administration are building a system designed to guarantee that fewer people receive their ballots, in a manner designed to create obvious chaos around an election they don’t expect to win. Whatever you want to call the intent, that’s an executive branch actively degrading the machinery of free and fair elections.

That should be the biggest story in the country.

Donald Trump has made it abundantly clear that he thinks the federal government works for him, and him alone. It does not. It works for the American people, and a court has already told USPS exactly that, twice. One postal employee understood the assignment well enough to risk their job and blow the whistle over it. It’s about time that more started to do so as well.

Flock-Stalking, Nazi-Saluting Deputy Given Top Cop Honors Before Hastily Retiring Ahead Of Criminal Charges [Techdirt]

Law enforcement is often self-selecting. If you like the things you’ve seen cops get away with (violence, brutality, open racism, multiple rights violations, etc.), you’ll probably like being a cop. And before the pedants get carried away in the comments, I’m using “cop” as shorthand for the whole of the law enforcement profession, even if it’s divvied up between actual cops, state troopers, federal officers, and — like this guy is — sheriffs and their deputies.

And so it seemed to go for Deputy Michael Fultz of the Brevard County, Florida Sheriff’s Department. Fultz got on-boarded and almost immediately celebrated as one of the best. Here’s that celebration, which is surrounded by dozens of reasons he never should have received that accolade, as reported by Matthew Gault for 404 Media.

Hired in 2024, Brevard County named Fultz its Deputy of the Year in 2025.

Here’s the very next sentence in that paragraph:

The day of the ceremony Fultz’s ex-girlfriend sent a letter of complaint to the sheriff’s office with a long list of complaints about his behavior.

Portentous. Perhaps even ominous. Spoiler alert: it’s both. The letter prompted an investigation of the newly crowned Deputy of the Year by the same entity that had bestowed it upon him. To say “it’s not pretty” is like saying Mt. Vesuvius was “a little overactive.”

The 43-page investigation found Fultz had posed for pictures as Adolf Hitler, freely used racial slurs in texts, masturbated on camera in his police vehicle, took pictures of his ex-girlfriend with his service weapon in her mouth during sex, repeatedly broke the law to generate clout online for his motorcycle themed Instagram and TikTok accounts, and used Flock to stalk his ex-girlfriend.

Ummm… there’s a good argument here that this person should never have been allowed to be a person, much less a law enforcement officer. Sociopathic, psychopathic, and (obviously) at the very least, extremely “Nazi curious.”

Oh wait. There’s more.

Investigators also found that Fultz accessed Flock while he was off-duty.

And while we all know that cops lie, we should demand better lying in exchange for our tax dollars:

Fultz denied he was using Flock to stalk his ex. He claimed to investigators that he may have been showing her how it works, and denied spying on her.

His excuse was “I wasn’t spying on her,” but rather “I was showing off secret cop tech to a person I would later have sex with while my service weapon was in her mouth?” Is that supposed to to be better? And if so, how?

And while we’re on the extremely uncomfortable subject of officer-involved-sex that utilizes government-issued weapons, let’s first note that the ex-girlfriend said these acts were “consensual,” but also realized (as Deputy of the Year didn’t) that photos of these acts (if not the acts themselves) might be “a poor idea and inappropriate for a deputy sheriff.”

That’s on top of the other “inappropriate” for anyfuckingbody stuff the ex-girlfriend shared with investigators, which ranged from the deputy’s Hitler impression (including photographed Nazi salutes) to text messages loaded with racial slurs.

But the ultimate kink for Fultz wasn’t Hitler or racism or abusing Flock access. It was finding out the thing that made him the hardest (down there) was killing.

In April 2025, Fultz shot and killed a man who charged him with a knife. “She specifically noted that the sexual encounter where you introduced the firearm occurred after your on-duty shooting incident.”

That’s pretty fucked up. But Fultz also did a lot of regular ass cop stuff where he assumed (correctly) he was above the law. According to investigators, Fultz had been pulled over by other law enforcement at least four times for speeding and/or obscuring his license plate. Deputy Fultz, of course, learned nothing from this experience, which thankfully didn’t involve racial slurs, Hitler mustaches, or service weapons in girlfriend’s mouths.

Investigators told him he had to keep his motorcycle’s license tags visible. “Inexcplicably, within 30 minutes of the direct order you were provided, you drove your motorcycle out of the Brevard County Sheriff’s Office parking lot with no license tag attached. The incident was captured on video and preserved as part of the investigation,” the investigation said.

If you thought the explanation (“I showed it to my girlfriend”) above for Fultz’s Flock abuse was horrendous, just wait til you see the one he handed out to excuse his refusal to follow license plate laws:

Fultz explained he was speeding and covering his tag for online clout.

And we’re right back to where we were several paragraphs ago. Fultz should not be allowed to exist as a person, much less be allowed to carry a gun and pretend to represent the legal force of the law.

Fortunately, he’s no longer in the law enforcement business, at least for the moment. The agency that would have been fully justified in firing Fultz and stripping him fully of his law enforcement credentials somehow decided to let him resign, which means other law enforcement agencies he might approach won’t find any evidence of his extreme misconduct on the official record. Some cursory Googling would do the trick, but that’s unlikely to happen.

Fultz is a poor excuse for a human being and one of the last people who should ever be allowed to hold a position that gives him any power over anybody. If he had any shame, he’d emulate his hero, grab his gun, and head to the nearest bunker. Shit like this can’t be rehabilitated, especially when the person involved has shown nothing even remotely approaching remorse for his actions.

RCN Urges Judge to Toss the Major Labels’ ‘Last’ Piracy Liability Lawsuit [TorrentFreak]

cassette tape pirate musicFor years, the major record labels and movie studios waged a campaign to hold US internet providers responsible for pirating subscribers.

Alleging contributory and vicarious infringement, rightsholders argued that ISPs which failed to disconnect repeat infringers should pay for the consequences.

This theory fell apart in March, when the Supreme Court reversed a billion-dollar verdict against Cox Communications. The court held that an Internet provider is not liable for contributory infringement simply because it keeps serving subscribers it knows have been flagged for piracy.

RCN now wants the New Jersey federal court to apply this precedent and end a case that has been running since 2019.

No Inducement, No Claim

In a motion for reconsideration filed yesterday, RCN argues that Supreme Court’s Cox ruling destroyed the legal foundation of the labels’ amended complaint.

An ISP is no longer contributorily liable simply for selling internet access while knowing that some subscribers will use it to infringe. Failing to cut the connections of those subscribers off does not establish intent either.

After Cox, liability now requires proof that the provider actively encouraged infringement through specific acts, or that its service has no substantial non-infringing uses. Neither applies here, RCN argues, noting that the case is “virtually identical” to the Cox lawsuit.

Virtually identical

virtually identical

The labels’ second claim, vicarious infringement, should also be dismissed according to RCN, as it requires proof the ISP profited directly from the piracy itself. The Fourth Circuit ruled in Cox that monthly subscription fees do not count, and the Supreme Court declined to hear the labels’ appeal on that point.

RCN argues that subscribers pay the same price whether they pirate music or browse social media, so the fees are not a “direct financial benefit” from infringement.

The ‘Last’ Case Standing

RCN stresses that the other repeat infringer cases against ISPs have already been dismissed.

“[I]n the wake of Cox, the Labels and other rightsholders dismissed every other secondary copyright infringement case against an ISP—including the movie industry’s virtually identical lawsuit against RCN. The same should have happened here,” they write.

As reported earlier, the labels dropped their cases against Verizon and Altice within weeks of the Cox ruling. The film companies behind titles including The Hitman’s Wife’s Bodyguard dismissed a near-identical lawsuit against RCN with prejudice, and a parallel case against WideOpenWest ended a month later.

The precedent reached RCN’s sister ISP Grande Communications too. Both providers now operate under the Astound Broadband brand. Formally, the labels’ case against Grande is not over yet, however, as Grande still prefers to have a formal win on the books.

By RCN’s account, every other secondary infringement case against a US internet provider is now over, with its own case being the exception.

A Four-Year Standoff

So why is this lawsuit still pending in court after seven years?

According to RCN, the labels never meant to go to trial. The company argues that the case was filed in 2019 as leverage in settlement talks with Grande. After that, it remained pending due to a dispute over internal DMCA records.

In May 2022, Magistrate Judge Tonianne J. Bongiovanni stayed all fact depositions until document discovery was resolved. The stay has not lifted since, despite at least 20 discovery letter briefs. RCN believes the labels are holding on for a reason.

“Instead, it seems that the Labels view the ongoing privilege dispute as a form of leverage. In other words, the Labels seem to believe that RCN might be willing to pay money to avoid a resolution of that issue,” RCN tells the court.

The labels have yet to respond to the motion. RCN asks the court to vacate its 2020 order, dismiss the amended complaint with prejudice, and has requested oral argument.

A copy of RCN’s motion for reconsideration and supporting memorandum, filed at the U.S. District Court for the District of New Jersey, are available here (pdf) and here (pdf).

From: TF, for the latest news on copyright battles, piracy and more.

12:00 AM

GOP Begs Supreme Court To Let It Flood Airwaves With Cheap Midterm Propaganda [Techdirt]

Back in June, the Supreme Court ruled 6–3 in National Republican Senatorial Committee v. Federal Election Commission that federal limits on coordinated expenditures by political parties violate the First Amendment, opening the floodgates to a much broader array of political ads funded via no limit of rich assholes and their preferred dark money groups.

In preparation for the ruling, Trump FCC boss Brendan Carr revised FCC “Lowest Unit Charge Requirement” rules to try and make it much cheaper for the GOP to pummel the midterm elections with less-expensive TV ads carried via the nation’s soggy assortment of right wing broadcasters (which are currently petitioning the Trump FCC to approve massive new mergers).

But it hasn’t all been easy going for the GOP, which believes its massive funding advantage ($125 million for the GOP versus a bunch of debt for the mismanaged DNC) would give them a real leg up during the midterms.

For one thing, the Richmond, Virginia-based 4th Circuit Court of Appeals recently sided 2-1 against the FCC, temporarily suspending the FCC’s attempt at discount TV agitprop, and ruling that neither political parties nor joint fundraising committees with non-candidate members are allowed the discounted rates.

But the GOP has already set the wheels in motion to get this all quickly overturned by the Trump-friendly Supreme Court:

“The committees submitted an emergency motion for a stay and asked the 4th Circuit to rule on that motion immediately so they can file a petition to the Supreme Court. “Intervenors respectfully request that the Court rule on this stay motion as soon as possible—whether by expediting or waiving response briefs—to permit Intervenors to seek emergency relief at the Supreme Court,” Republican committees told the court.

The court responded quickly, issuing an order today to deny the Republican committee’s motion and to immediately issue a mandate that can be appealed to the Supreme Court. Republicans will now seek swift action from the Supreme Court in an attempt to overturn the 4th Circuit ruling before the 60-day discount period starts on September 4.”

If the GOP wins, local broadcasters will be forced to offer dodgy dark money groups the same discounts previously reserved directly for candidates, something the FCC’s lone Democrat, Anna Gomez, states will be “unleashing a flood of coordinated campaign money into broadcast advertising, just as the Supreme Court has cleared the way for unlimited coordinated spending between parties and candidates.”

It’s another reminder (as if you needed one) that unless the U.S. Supreme court is radically expanded and reformed in the next few years, corruption is likely to strip the country down to parts and sell it for scrap off the back loading dock.

Wednesday 2026-09-02

10:00 PM

Pluralistic: Unpermissioned research (02 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]

->->->->->->->->->->->->->->->->->->->->->->->->->->->->-> Top Sources: None -->

Today's links



A car's frosted-over back windscreen, being scraped by a person's hand holding an ice-scraper. The person has scraped a Canadian maple leaf into the windscreen. In the background we see the capitol dome and a depressed caricature of Uncle Sam holding a sign reading 'I am busted.'

Unpermissioned research (permalink)

After half a century of neoliberalism, we are all drenched in capitalism's established religion, the worship of property rights. We are so marinated in property worship that even capitalism's critics frame their critiques in "property talk," to the exclusion of other, more important rights, like human rights, labor rights and privacy rights.

To do this is to surrender before the battle even starts. Critics lose when they allow oligarchs and their apologists to choose a battlefield where they have a nearly unbeatable advantage.

Take privacy: privacy is a human right, not a property right. Human rights aren't for sale. You can't sell yourself into slavery, you can't sell your kidneys to make the rent. If privacy is a property right – one that can be traded away – then Facebook's industrial-scale privacy invasions are actually fine, since you "traded" your privacy to Mark Zuckerberg in exchange for the privilege of talking to your friends.

Some self-styled critics of tech monopolists say that the answer to Facebook's privacy invasions is to force the company to pay for your privacy with cash, rather than services:

https://www.wired.com/story/opinion-andrew-yangs-plan-to-pay-you-for-your-data-doesnt-add-up/

This is ideological capture in its purest form: the "data dividend" that Facebook would owe you under this system amounts to a few dollars per year. For wealthy people, the sums would be trivial, while working people, who've been on the downward leg of every K-shaped recovery for a quarter century, who've maxed out their credit cards and re-mortgaged their homes and drive Uber on the weekends to make rent, would have to subject themselves to ongoing surveillance.

That surveillance is already used to determine the highest price those working people will pay – companies like Plexure inform fast food places when you've just gotten paid so they can tack an extra dollar onto your breakfast burrito in the app:

https://pluralistic.net/2026/04/30/something-must-be-done/#there-ive-done-something

Being forced to sell your privacy doesn't just raise the prices you pay, it also lowers the wages you earn. The same people who can't afford this "pay or privacy" system have their private data used to calculate the lowest wage they'll accept for each ride on those weekend Uber shifts:

https://pluralistic.net/2024/12/18/loose-flapping-ends/#luigi-has-a-point

In other words: not being able to afford privacy will result in you having even less disposable income, which will mean that you'll have to sell even more of your privacy. Lather, rinse, repeat.

But even the wealthy people who can afford to forego the pittances Facebook and others offer in exchange for their private information will find privacy elusive. That's because private information isn't a "rival good" – a thing only one person can own at a time. The fact that your mother is your mother "belongs" to both you and her, as well as your grandparents, your father, your siblings and your kids. The fact that you don't sell your family tree to a tech company won't stop all those other people from selling it on – as anyone whose foolish relations handed their genome over to 23andme can attest:

https://www.npr.org/2025/03/24/nx-s1-5338622/23andme-bankruptcy-genetic-data-privacy

In the property religion, the way you can tell if something is valuable is if it has a high price. Property cultists insist that the problem with privacy is that our privacy is being sold too cheaply. They're wrong: private information isn't "mispriced" – it shouldn't be priced.

Human beings are the most valuable things in our world and they are literally priceless. Murder isn't "theft of life." Rape isn't "theft of sex." While insurers and civil courts have ways of calculating the "price" of an injury or violation, great care has been taken over the centuries to ensure that this does not turn human beings into commodities. You can't buy a "murder offset" that lets you kill people provided you pay into a fund that saves a human somewhere else:

https://pluralistic.net/2021/04/14/for-sale-green-indulgences/#killer-analogy

Human beings are too valuable to be priced. We have an entire, sui generis way of balancing the conflicting interests of human rights. My daughter and wife have rights over me, I have rights over them, and when those rights come into conflict – say, if my daughter believes I can no longer care for myself and wants to put me in a care home – the process for resolving that conflict isn't an auction:

https://www.theguardian.com/technology/2008/feb/21/intellectual.property

Your kids aren't your property. In fact, all the most important relationships in your life are non-market. Doctors have patients, not customers. Any time a doctor calls you a "customer" they are demoting you. A doctor doesn't sell you health. You have rights as a patient that far exceed the rights accruing to a mere customer. Same goes for other professions: Teachers have pupils, librarians have patrons, lawyers have clients. "Customer" is a demotion from all of these.

As every "user agreement" you've ever clicked through demonstrates, Big Tech loves to have everything defined in property terms – and so does all big business.

Take the fight over scraping for AI. You might think that this is a fight over the economic rights of creative workers – certainly, my fellow creative workers treat it as such. But because this debate is being framed in terms of property rights, rather than labor rights, this is a fight that workers are set up to lose.

The tell here is how the media companies – who have been eroding the wages of creative workers for decades as they consolidated into a curdled, inbred oligopoly – describe the AI companies' scraping: as an unlicensed taking. Mitch Glazier, the $1.4m/year CEO of the Recording Industry Association of America issues press releases decrying AI training for image generators without negotiating a license fee first:

https://pluralistic.net/2026/03/03/its-a-trap-2/#inheres-at-the-moment-of-fixation

Who's Mitch Glazier? Oh, just a former Congressional staffer who was drummed out of the Capitol Building after he snuck a clause into must-pass legislation that would have transferred hundreds of millions of dollars from musicians to record labels, who was then immediately hired as the CEO of the record industry's largest lobbying group:

https://www.eff.org/deeplinks/2013/12/tpps-attack-artists-termination-rights

Mitch Glazier – and the businesses he represents – aren't opposed to AI replacing artists. They're opposed to AI replacing media companies. Remember the Hollywood writers' strike? The proposal to replace screenwriters with chatbots didn't come from OpenAI, it came from Disney, Warner, Universal and other companies who claim that AI training is "theft."

If AI training is "theft," then it can be cured by making a purchase, something that the AI companies can easily afford, thanks to the hundreds of billions of dollars they have been given by the world's richest investors, who are the high priests and cardinals of the property religion.

The Hollywood writers are the only workers in the world who have successfully beaten back the use of AI in their workplace, and they didn't do it by making recourse to property rights. The Writers Guild is a union and it enjoys a weak form of "sectoral bargaining" (where all the workers in a field bargain with all the businesses at once) called "multi-employer bargaining":

https://pluralistic.net/2023/10/01/how-the-writers-guild-sunk-ais-ship/

The Hollywood writers' strike was an unqualified victory for the writers, who defended their labor rights to co-determination when it came to the use of new tools on their jobsite. Under the terms of their hard-fought contract, screenwriters don't have to use AI, but they can if they want. For example, writers on a long-running sitcom might train an AI with every script in the series' history, so they can ask a chatbot continuity questions as they beat out a new season of the show. But they don't have to do this if they don't want to, and even if they do, neither their wages nor their headcount can be reduced.

The media companies insist that scraping is a copyright violation, that it's "theft." As a matter of law, this is far from obvious or settled: the process of making transient copies of many works, performing mathematical analysis on them, and then publishing that analysis as software is not obviously a copyright violation, and anyone who claims otherwise doesn't understand copyright:

https://pluralistic.net/2023/02/09/ai-monkeys-paw/#bullied-schoolkids

Worse: by demoting a labor rights issue to a mere property rights issue, AI critics are setting workers up to fail. Say the issue with AI training really is mere copyright. If that's so, the media companies who want nothing better than to pauperize creative workers can amend their standard contracts so that any worker who does business with them must irrevocably transfer their "AI training rights" to the company.

Then, that company will absolutely, 100% license those rights to an AI company to create a model designed to replace that worker. The company will get paid for the training, and the resulting model will come with "guardrails" to stop other media companies from using proprietary data to compete with it.

This is the story of the past 50 years of copyright expansion: every new copyright we've created "to help artists" was scooped up by their bosses, who grew more powerful and were able to demand more concessions from those artists, who were therefore poorer and thus needed more copyrights to help them (lather, rinse, repeat):

https://pluralistic.net/2026/08/18/enron-corpus/#sign-here

If creative workers' AI fight is merely a copyright fight, then that fight can only determine whether media companies or tech companies will get the biggest portion when those workers are devoured by corporations. Only a labor rights fight can take creative workers off the menu altogether.

Treating AI training as "theft" creates harms whose blast radius extends well beyond creative workers' livelihoods. Scraping is a hugely beneficial activity. If scraping – taking a vast corpus of copyrighted works without permission – is theft, then every search engine is a crime, unless it can afford to license "search indexing rights" from every site on the internet.

There's exactly one company that could pull that off: Google, a rapacious tech monopolist that is – not coincidentally – one of the leaders of the movement to beggar every creative worker. We will not improve the world, the internet, or creative workers' lives by ensuring that the last search engine anyone ever creates is Google.

Remember our earlier discussion of how privacy violations are weaponized to make poor people even poorer, by depressing their wages and raising prices based on inferences about their economic desperation? Our best weapon for fighting this practice is scraping, because that's how we catch corporations changing prices and wages based on surveillance data:

https://pluralistic.net/2023/09/17/how-to-think-about-scraping/

Scraping is how we produce evidence of the changes that powerful people are making to the world around us. Do you want to know whether Mark Zuckerberg or Elon Musk are downranking content critical of Trump and Big Tech and pumping racist and conspiratorial posts into the resulting void? You'd better hope you can scrape the feeds they cram into billions of people's eyeballs. Same goes for keeping track of genocide apologists, data-center astroturfers and ICE cheerleaders who've flooded Tiktok ever since Trump stole it and handed it over to his creepy billionaire pal Larry Ellison.

Making copies of that stuff isn't theft. It's not a copyright violation. Not even if you do it to billions of works. Not even if it's bad for the companies whose feeds you're capturing. Not even if it's bad for the dark money groups who funded the content.

Sure, if you do this carelessly or recklessly, you can end up violating someone's labor rights, or privacy rights, or human rights. And because those frameworks aren't based on the sanctity of property rights, they can be used to protect these important rights without giving corporate America the right to have you fined or arrested for documenting their takeover of the America.

The people who keep track of this stuff are worried about being fined or arrested. Ethan Zuckerman, one of America's foundational internet scholars, has just accepted Canadian government funding to move his lab from UMass to McGill in Montreal:

https://ethanzuckerman.com/2026/08/27/my-personal-contribution-to-the-us-canada-trade-war/

Zuckerman studies platform power: "using data to answer hard questions about social media, search engines and AI tools." He leads a team that is documenting exactly, precisely how tech companies collude with authoritarians to spy on us, manipulate us, and control us. And his methodology is something called "unpermissioned research," which is what academics call scraping:

https://www.techpolicy.press/ai-companies-threaten-independent-social-media-research/

"Unpermissioned research" seeks to circumvent limits that platforms establish specifically to stop outsiders from learning how they operate. When you're doing unpermissioned research, you try to get around rate limits, query throttles, and other measures that platforms use to block others from mapping their extent and documenting their conduct.

"Unpermissioned research" isn't a free-for-all. Universities have ethical rules designed to protect the privacy rights and other human rights of research subjects, and because these aren't property rights, they can be balanced against the socially beneficial outcomes of research. Universities can get this wrong, of course, but when they do, it's not theft. It's a human rights violation, a privacy violation, a labor violation.

If you want to know how AI companies are trying to destroy creators' livelihoods, you have to scrape the AI companies. You can't ask companies for permission to gather information that might be used to destroy them – they'll just say no. If taking information off the internet without permission is "theft," then gathering information by scraping AI companies is also theft.

Sometimes a tech company will set up a "research portal" that supposedly obviates the need to scrape by putting all the relevant information in one convenient place. That's what Facebook did in the wake of the 2016 election, when it was widely condemned for publishing paid political disinformation. But Facebook's official research portal omitted vast amounts of paid political disinformation, something we only know because NYU set up a scraping project called Ad Observer that documented the discrepancy:

https://pluralistic.net/2021/08/06/get-you-coming-and-going/#potemkin-research-program

Facebook used legal threats to kill Ad Observer, and then…they killed their official research portal, too:

https://pluralistic.net/2021/07/15/three-wise-zucks-in-a-trenchcoat/#inconvenient-truth

Zuckerman is one of dozens of leading US academics who are relocating their labs and teams to Canadian universities, citing fear of political interference from the Trump regime:

https://vancouver.citynews.ca/2026/08/27/canada-recruits-dozens-of-foreign-scientists-researchers-poaching-many-from-u-s/

The Canadian government has committed $504m to the project. Some of that research will help Canada develop new green energy, and some of it will help Canada make important medical breakthroughs. But Zuckerman's research has a special place in the portfolio of Canadian research projects, because – thanks to scraping – it is a leading source of information about how Trump's tech companies are waging war on the American people and the world.

Scraping isn't theft of data, just like murder isn't theft of life. Scraping can be harmful, and we can create laws and social regimes and ways of talking about those harms that don't give authoritarian governments and vast multinational corporations the right to decide who can document and analyze their conduct.

Take Wikipedia: the project exists solely to organize and disseminate information, for free, to everyone in the world. Wikipedia is among the most important parts of the internet, and one of the most positive developments of the 21st century. The entire project is licensed under a generous Creative Commons license that encourages unlimited commercial re-use of its contents. Even if you think scraping copyrighted works is theft, scraping Creative Commons Attribution 4.0 works is unquestionably not theft.

But Wikipedia is being hammered by AI scrapers, which are operating so aggressively that they threaten the project's ability to keep its servers online. Wikipedia has an AI problem, but that AI problem isn't "theft" – it's denial of service, the aggressive act of intentionally or recklessly flooding a server with so much traffic that it crashes.

If you've been lured into a cultlike worship of property rights, this seems like a contradiction. But once you relegate the relatively unimportant matter of property rights to its correct station, you can see – and reason about – the universe of rights that are far more important than mere property.

All it takes is realizing that there are far worse things you can do with information than "stealing" it.

(Image: Bearas, CC BY-SA 4.0, modified)


Hey look at this (permalink)



A shelf of leatherbound history books with a gilt-stamped series title, 'The World's Famous Events.'

Object permanence (permalink)

#25yrsago NYT says ebooks don't exist, fails to mention thriving ebook pirate scene https://www.nytimes.com/2001/08/28/business/forecasts-of-an-e-book-era-were-it-seems-premature.html

#25yrsago Parking tickets waived in exchange for written apologies https://web.archive.org/web/20010826013513/http://www.thesmokinggun.com/doc_o_day/lewiston1.shtml

#20yrsago "I, Row-Boat" https://web.archive.org/web/20060000000000*/http://www.flurb.net/1/doctorow.htm

#20yrsago Filipino students use SMS to organize mass demonstrations https://web.archive.org/web/20060902160514/http://blog.wired.com/sterling/index.blog%3Fentry_id%3D1545927

#20yrsago Spam pump-and-dumps work http://news.bbc.co.uk/2/hi/technology/5284618.stm

#25yrsago Leaked: Handspring's next PalmOS device https://web.archive.org/web/20020824213501/http://www.palmstation.com/view_article.asp?article=4614

#15yrsago “Stalwart Workers”: neglected backbone of the firm https://web.archive.org/web/20110920155246/http://blogs.hbr.org/hbsfaculty/2011/08/stop-ignoring-the-stalwart-wor.html

#5yrsago Facebook's war on switching costs https://pluralistic.net/2021/08/28/talking-hard-work-blues/#hostage-takers

#5yrsago The "work ethic" is a dirty trick we play on ourselves https://pluralistic.net/2021/08/28/talking-hard-work-blues/#work-will-set-you-free

#1yrago The capitalism of fools https://pluralistic.net/2025/08/28/strew-deal/#neither-fish-nor-fowla


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, pounding the podium.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027

  • "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027

  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Colophon (permalink)

Today's top sources:

Currently writing:

  • “Once Is Enemy Action,” a science fiction novel about the origins of modern technofascism. Today's words: 527 (10843 total).

  • "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

  • A Little Brother short story about DIY insulin PLANNING


This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, possible tracking and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.

ISSN: 3066-764X

08:00 PM

Arti 2.6.0 released [Tor Project blog]

Arti is our ongoing project to create a next-generation Tor implementation in Rust. We're happy to announce the latest release, Arti 2.6.0.

This release continues our ongoing development towards using Arti as a relay and as a directory authority, with much of the work focusing on document parsing, directory mirror support, and DNS stream handling. Additionally, on the RPC front, we are making steady progress towards RPC-based configuration management. Finally, congestion control and Counter Galois Onion cryptography are both now always enabled in arti.

As usual, there also are many under-the-hood improvements to our infrastructure, testing, and documentation, along with multiple bug fixes and internal cleanups.

For full details on what we've done, including API changes, and for information about many more minor and less-visible changes, please see the CHANGELOG.

For more information on using Arti, see our top-level README, and the documentation for the arti binary.

Thanks to everybody who's contributed to this release, including Andrew Kloet, Steven Masnada, iqdecay, pryty26, steven.

Also, our deep thanks to our sponsors for funding the development of Arti!

RSSSiteUpdated
XML About Tagaini Jisho on Tagaini Jisho 2026-09-04 07:00 AM
XML Arch Linux: Releases 2026-09-03 10:00 AM
XML Carlson Calamities 2026-09-03 10:00 AM
XML Debian News 2026-09-04 09:00 AM
XML Debian Security 2026-09-04 07:00 AM
XML debito.org 2026-09-04 09:00 AM
XML dperkins 2026-09-04 07:00 AM
XML F-Droid - Free and Open Source Android App Repository 2026-09-03 10:00 AM
XML General Union 2026-09-04 08:00 AM
XML GIMP 2026-09-03 10:00 AM
XML Japan Bash 2026-09-04 07:00 AM
XML Japan English Teacher Feed 2026-09-04 07:00 AM
XML Kanji of the Day 2026-09-03 10:00 AM
XML Kanji of the Day 2026-09-03 10:00 AM
XML Let's Encrypt 2026-09-03 10:00 AM
XML Marc Jones 2026-09-03 10:00 AM
XML Marjorie's Blog 2026-09-03 10:00 AM
XML OpenStreetMap Japan 2026-09-03 10:00 AM
XML OsmAnd Blog 2026-09-03 10:00 AM
XML Pluralistic: Daily links from Cory Doctorow 2026-09-04 07:00 AM
XML Popehat 2026-09-03 10:00 AM
XML Ramen Adventures 2026-09-03 10:00 AM
XML Release notes from server 2026-09-03 10:00 AM
XML Seth Godin's Blog on marketing, tribes and respect 2026-09-04 07:00 AM
XML SNA Japan 2026-09-04 07:00 AM
XML Tatoeba Project Blog 2026-09-04 07:00 AM
XML Techdirt 2026-09-04 09:00 AM
XML The Business of Printing Books 2026-09-03 10:00 AM
XML The Luddite 2026-09-03 10:00 AM
XML The Popehat Report 2026-09-04 07:00 AM
XML The Status Kuo 2026-09-04 07:00 AM
XML The Stranger 2026-09-03 10:00 AM
XML Tor Project blog 2026-09-04 09:00 AM
XML TorrentFreak 2026-09-04 07:00 AM
XML what if? 2026-09-04 07:00 AM
XML Wikimedia Commons picture of the day feed 2026-09-01 01:00 PM
XML xkcd.com 2026-09-04 07:00 AM