News

Friday 2026-09-11

04:00 PM

White House Website Briefly Hosted Racist Tetris Clone Game Until The Tetris People Complained [Techdirt]

Pick your favorite zombie movie or television show and you’ll eventually be confronted with dialogue justifying the killing of the zombies with the idea that they are no longer human.

“They aren’t people, Rick. They’re just bodies. We have to stop thinking of them as if they’re still alive.” – The Walking Dead

“They’re not human. Look at them. They’re just… meat.” – Shaun of the Dead

The point is that there should be no ill feelings towards the treatment of a zombie, because they aren’t like us any more. They aren’t worthy of compassion. They deserve no quarter, only violence. They are a threat to our very survival and doing away with them, or at least keeping them away from where humanity exists, is the only solution.

Or, if you’re the Trump administration, you use this same justification as a bank-shot for immigration policy by hosting a Tetris clone game on the White House website.

The White House’s “Build the Wall” game asked players to stop a “Zombie Border siege” by stacking Tetris-styled bricks in an attempt to “hold the line.” Unlike in Tetris, though, the blocks in “Build the Wall” don’t disappear when you complete a line, meaning each brick contributes to an impassable barrier for the pixel-art “zombies” marching in from the “Southern Border.” That change makes the gameplay pretty uninteresting for anything but cheap propaganda, and it also means that every game quickly and ironically ends with a “Border Breached” message when the blocks inevitably fill up the well.

Amerika Garcia Grewal, co-director of Texas migrant rights group Frontera Federationtold AFP last week that the makers of the game “have lost touch with what it means to be human and care for others.”

The game is now thankfully gone from the site, though several other obvious game clones remain. This is not new ground for this administration, of course. Team Trump has made a habit when campaigning and while in office of using video game imagery for all kinds of things, such as touting MAHA nonsense, shitposting about the horrors of its own immigration activity, or bragging about the body count of the wars Trump promised he’d never start.

So, why did the game get taken down? Did someone in the administration realize how horrible and racist the whole thing was? Did Trump himself suddenly suffer from a spasm of moral clarity?

Doubtful. More likely it was this.

In a statement on Friday, a spokesperson for The Tetris Company said it was “reviewing the matter” and that the company “was not involved in the creation of ‘Build the Wall’ and did not authorize or license the Tetris brand or intellectual property for the game.” The company reiterated that message in a social media post Friday afternoon, writing that it “believe[s] in the power of connection and bringing people together, not dividing them.”

Now, I’m not going to sit here and cheer on the enforcement of our overly broad copyright system. But I sure as hell understand why the Tetris people don’t want there to be even the barest chance for them and their game to be associated with something as disgusting as Trump’s Build The Wall “game.” And ArsTechnica is right to note that the Tetris Company has a long history of being very protective of its intellectual property rights, which government lawyers almost certainly are aware of.

Whether taking the game down will be enough to keep the Tetris Company from acting, I do not know. What I do know is that this administration is filled with deeply unserious, racist, and troubled people. Immigrants, illegal or otherwise, are not zombies. They shouldn’t be compared with zombies. Whatever immigration policy you prefer, they are people.

And that really shouldn’t have to be said out loud.

The Matter of Missouri [The Status Kuo]

Photo by Yong Li Xuan / Missourian for AP

Missouri finally knows what congressional map it will use this November. Big whew.

The U.S. Supreme Court settled that this morning, for the second time in three days. But getting there took two emergency High Court interventions, a federal judge and a state supreme court issuing contradictory orders, and a secretary of state now facing a contempt proceeding for picking sides. If you’ve been trying to follow the dizzying headlines, you might feel some whiplash. It’s as if the Kansas City Chiefs had won, but only after the refs spent four straight days arguing over which call stood.

The chaos began Tuesday. Justice Brett Kavanaugh denied Missouri Secretary of State Denny Hoskins’s emergency request to revive the new Republican-drawn congressional map. That map had already been blocked by Missouri’s own Supreme Court in a unanimous ruling. Kavanaugh’s denial let that block stand. Round one to the state court.

You’d think that would be the end of the matter. But these are Republicans under Trump’s thumb, and like him they won’t accept “no” for an answer. As legal journalist Chris Geidner laid out, minutes after Justice Kavanaugh’s ruling, a Trump-appointed federal judge, Stephen Clark, handed down a contradictory ruling in a different case. He ordered the state to use the new GOP map anyway.

By Tuesday night, Missouri’s Supreme Court had ordered Secretary of State Hoskins to explain why he should not be held in contempt of its order.

By Thursday, the Supreme Court had weighed in on this fight twice, blocking the new map both times. Missouri’s 2022 lines will govern in November, and a referendum on the GOP’s proposed map will go before voters as Proposition A. But the contempt question is still open, meaning it’s still not settled whether Hoskins violated the state court’s order when he directed county clerks to defy an order he simply didn’t like.

To make sense of where we are, and what this means for other election-related cases, we have to unpack how this all started. You’ll see why this is, as the Missouri Supreme Court has noted, an election crisis of the GOP’s own making.

How Missouri got here

In June 2025, in a highly unusual and aggressive move, the White House began pushing Republican-controlled states to redraw their congressional maps through “mid-decade redistricting.” Missouri was one of them. The overt goal was to help Republicans hold the U.S. House in 2026 by gerrymandering Democratic-held seats out of existence.

Missouri Gov. Mike Kehoe called the GOP-held legislature into a special session, and state lawmakers passed HB 1 that September. The law created a map targeting the Kansas City-area district held by Democratic Rep. Emanuel Cleaver. It sought to move the state’s congressional delegation from a 6-2 Republican-Democrat split to a 7-1 split.

But under state law, Missouri voters had a way to undo it. Through a referendum, voters could force a statewide vote on new legislation, including congressional maps. A group called People Not Politicians gathered more than 300,000 signatures and delivered them to the Secretary of State’s office on December 9. That was one day before HB 1 was set to take effect.

Under the Missouri Constitution, a law challenged by a referendum petition is automatically suspended once the petition is filed. The language says such a challenged law “shall take effect when approved by a majority of the votes cast thereon, and not otherwise.” Hoskins ignored that language. He declared HB 1 already in effect, signatures or not.

Then he ran out the clock. Months went by without his office certifying the petition. As Prof. Steve Vladeck of Georgetown University noted, Hoskins finally acted on August 4, primary day itself, issuing a “Certificate of Insufficiency” about an hour before the 5 p.m. statutory deadline. He argued congressional maps cannot be put to a referendum at all.

In short, Hoskins rejected the referendum and the will of 300,000 signatories on the same day Missourians were already voting under the map he was defending.

That delay created the crunch now playing out in court. As Talking Points Memo laid out, primary voters had already chosen candidates under the lines created by HB 1. Switching back to the 2022 map for the November election risked placing voters in districts where they had no part in choosing the nominees.

Republicans are now using this mismatch in federal court. They argue that switching maps for the general election would be unfair to voters and candidates who already ran under HB 1. But the map only stayed in place for that primary because Hoskins ignored the referendum and the constitutional requirement to suspend HB 1 until the referendum could be voted on by the people.

“No exception applies”

On September 3, the Missouri Supreme Court ruled unanimously against Hoskins. “Because the plain language of article III, section 49 of the Missouri Constitution authorizes a referendum as to ‘any act of the general assembly’ and no exception applies, the referendum petition was legal, sufficient, and timely,” the court wrote. The new map, under HB 1, had never legally taken effect. The court decided that the old 2022 map would govern the November election.

Five of the seven justices on the court were appointed by Republican governors. Justice Ginger Gooch—perhaps my favorite name so far this cycle—wrote the opinion, and she is a GOP appointee. She laid the blame for the chaos squarely at Hoskins’s feet, pointedly noting that Hoskins “delayed certification until the last possible date.”

Hoskins’s stated reason for rejecting the referendum had nothing to do with the signature-gathering process. People Not Politicians had turned in more than enough. Hoskins argued instead that congressional maps simply cannot be challenged by referendum, and that the Missouri Constitution reserves redistricting to the legislature alone. That was his sole basis.

Footnotes are often where the best parts of cases land, and Justice Gooch delivered one for the ages. Hoskins had also argued, separately, that switching maps now would cause confusion, expense and practical difficulties. Justice Gooch wrote that those problems were “particularly irrelevant to the secretary’s sole basis for declaring the referendum petition insufficient.” In other words, disruption wasn’t even part of his legal argument. Hoskins was raising it only now. She found this argument “particularly misplaced given the secretary’s delay created the confusion, expense, and practical difficulties of which he complains.”

In short, “you broke it, you bought it.” The Missouri Supreme Court found that the secretary of state created the mess to begin with, then tried to use it as a reason to keep the map in place.

The court did not stop at declaring HB 1 dead. It ordered Hoskins, by name, not to use it. It barred him “and all of those acting in concert with him” from implementing HB 1 for the November election “or at any other time thereafter” unless voters approve it.

Hoskins did not accept that answer. The next day, he and Attorney General Catherine Hanaway asked the U.S. Supreme Court to step in.

Judicial whiplash

Last Friday night, just before midnight, Hoskins and Hanaway filed their emergency SCOTUS application for a stay. They asked U.S. Supreme Court Justice Brett Kavanaugh, who handles emergency applications from the Eighth Circuit, which includes Missouri, to put a hold on the state court’s ruling. They warned of “unprecedented chaos” if he refused. (Remember, this is chaos they deliberately created.)

Tuesday afternoon, Justice Kavanaugh answered by denying the request. He did not refer it to the full Court, and he offered no explanation. The message was hard to miss: the Missouri Supreme Court’s ruling would stand, and the nation’s highest court wanted no part of the fight. Democracy defenders breathed a sigh of relief.

How short-lived it was. Minutes later, in a different courtroom, a contrary ruling landed. Chief U.S. District Judge Stephen Clark, a Trump appointee, granted the state a temporary restraining order. It came in a separate lawsuit, filed just days earlier by Republican Rep. Bob Onder and other GOP candidates.

Judge Clark’s order rested on a fairness argument. Switching maps now, he found, would “create[] two classes of voters: those who happen to stay in their HB 1 congressional districts, and those who do not.” Clark’s order barred Hoskins from using any map “other than the [2025 plan]” for the November election. But that was the exact map the Missouri Supreme Court had just ruled dead.

Hoskins leapt to action. His office told county clerks Tuesday that Clark’s federal ruling “takes precedence over the Missouri Supreme Court’s order,” citing the U.S. Constitution’s Supremacy Clause. He has said publicly that he “will continue to abide by Judge Clark’s federal temporary restraining order.” Richard von Glahn, the referendum’s organizer, called out Hoskins’s Supremacy Clause claim as false. Nothing in Clark’s order, von Glahn declared, claimed to override the state court’s reading of its own constitution.

The referendum backers also moved fast. They asked Judge Clark to put his own order on hold while they asked the Eighth Circuit for emergency administrative relief. And they went back to the Missouri Supreme Court and asked the justices to hold Hoskins in contempt.

Just before 11 p.m. Tuesday, Missouri Supreme Court Chief Justice W. Brent Powell answered the petition organizers. He ordered Hoskins to explain, in writing, why his email to county clerks was not itself a violation of the court’s injunction, why that injunction was not still in force following Kavanaugh’s denial and why he should not simply take no action until a higher court weighed in. Hoskins was ordered to appear in person Thursday morning.

Hoskins partially complied. He certified the referendum for the November ballot, reversing his earlier rejection. But he refused to stop directing county clerks to use HB 1. The state asked Judge Clark to block the Missouri Supreme Court from holding its own contempt hearing. But that would require a federal judge to stop a state supreme court from enforcing its order against a state official, and Clark declined.

Donald Trump also weighed in. He called the Missouri Supreme Court’s opinion a “Dark Day for ‘Justice.’” Former U.S. attorney Joyce Vance called the public presidential broadside against a state supreme court’s reading of its own constitution “shocking to see.”

Wednesday brought no relief from the chaos. A three-judge Eighth Circuit panel denied von Glahn’s request to pause Clark’s order, saying it either “lack[ed] jurisdiction over the appeal” or “based on the briefing we have so far, the stay factors have not been met.” Prof. Vladeck called the panel’s reasoning questionable; the Supreme Court has found similar orders appealable in other recent cases.

Within minutes, von Glahn’s side went back to the U.S. Supreme Court, this time asking the justices to intervene directly and warning of “irreparable harm” for every hour Clark’s order remained in force. Justice Kavanaugh ordered a response from state officials by 10 a.m. Thursday.

If all that wasn’t enough, a third front opened. Paul Berry III, the Republican nominee for the 1st District, filed a separate federal suit just days ago, arguing the 2022 map violates the Voting Rights Act. That case is before U.S. District Judge John Ross, an Obama appointee, who understandably said he “cannot determine a proper path forward” until the Supreme Court rules on the others.

Thursday brought Hoskins two deadlines: a brief before the U.S. Supreme Court defending Judge Clark’s order and an in-person appearance at his contempt hearing before the Missouri Supreme Court. Hoskins remained defiant. “I look forward to my day in court,” he posted on social media.

The Supreme Court didn’t wait for Hoskins’s day in court to settle the map fight. In a brief, unsigned order Thursday, with no dissents noted, the justices blocked Judge Clark’s ruling outright. It was the second time in three days they had intervened in this fight and the second time the result went against the state. As with Tuesday’s denial, the Court offered no explanation. The effect, for now, is that Missouri must revert to the 2022 map for November, and the HB 1 referendum must go before voters as Proposition A, exactly as the Missouri Supreme Court ordered a week earlier.

The contempt question, notably, is still open. Hoskins made his Supremacy Clause argument in person Thursday morning. As of this writing, the state’s high court had not yet ruled on whether he is in contempt of its own order.

The tactic, and what it previews

Missouri Republicans have not been shy about why they have acted this way. In January, months before any of this reached a courtroom, Attorney General Catherine Hanaway said plainly, “As long as the status quo is the new maps, delay works in our favor.”

Every one of the GOP officials’ delays pushed the fight closer to an election that cannot be moved. This is their strategy: run the clock down far enough, and the argument stops being about who is right on the law. It becomes about who has time left to be right.

Missouri’s filing before Justice Kavanaugh made that explicit. The state asked for relief by September 14, invoking the federal September 19 deadline to mail ballots to military and overseas voters. People Not Politicians’ lawyers shot back that the state wanted the High Court to “rescue the Secretary from a timing problem of his own making.”

Judge Clark’s temporary order ran on the same logic. It treated disruption itself as the reason to freeze the map in place, regardless of which map was lawful or who caused the disruption. Yes, ballots have to be printed. Overseas voters have to receive them by a fixed date. Those deadlines are genuine constraints on election officials, and Hoskins leveraged them to generate the crisis that now collides with them.

Prof. Vladeck argued the Supreme Court had a clean way to end this. Courts are supposed to avoid changing election rules right before an election, and Clark’s order did exactly that, days before ballots go out. Blaming the resulting confusion on the Missouri Supreme Court’s earlier ruling, Vladeck argued, gets the timeline backwards. The state court ruled first. Clark disrupted things five days later.

Missouri’s own solicitor general gave the game away in the state’s brief to the Supreme Court. The state conceded that a referendum vote on the 2025 map would happen regardless of what any court decided. The only question it raised was timing: whether Richard von Glahn and “a small minority of the state’s voters” could void the 2025 map before that vote took place. Joyce Vance called this what it is: gamesmanship, not a genuine legal dispute. The state’s goal was delay, not a win on the merits.

This matters beyond Missouri. A 2019 Supreme Court ruling took federal courts out of the business of policing partisan gerrymandering, leaving the fight to the states. And under the Supreme Court’s Purcell principle, courts are not supposed to intervene in election matters too close to an election.

And yet the Court’s own emergency docket has grown quite comfortable intervening in redistricting fights right before elections whenever it chooses, even while telling everyone else that late intervention is too disruptive to allow. As Prof. Vladeck notes, Judge Clark’s order is a lower court taking its cues from a Supreme Court that doesn’t consistently follow its own rules.

The same mechanics on display in Missouri are coming for the fight over mail ballots this fall. Rules will get challenged late. Litigation will drag by design or by circumstance. Then, days before a real deadline, Republicans will go to court and argue that the emergency itself, created by their own policies and decisions, is reason enough to freeze whatever is already in motion, lawful or not.

In Missouri, that tactic ultimately failed. The Supreme Court stepped in, twice, and shut it down both times. But we should take little comfort in that. It took two separate emergency rulings from the nation’s highest court, inside a single week, to stop one state’s secretary of state from running out the clock on one congressional map. This November, the mail-ballot fights won’t be confined to one state or one map. They’ll be everywhere at once, all racing the same tight deadlines. The Court cannot hope to referee every dispute in real time.

Missouri shows the tactic can be beaten. But it also shows exactly how much firepower it takes to beat it.

03:00 PM

Kanji of the Day: 化 [Kanji of the Day]

✍4

小3

change, take the form of, influence, enchant, delude, -ization

カ ケ

ば.ける ば.かす ふ.ける け.する

文化   (ぶんか)   —   culture
強化   (きょうか)   —   strengthening
変化   (へんか)   —   change
化する   (かする)   —   to change (into)
悪化   (あっか)   —   deterioration
活性化   (かっせいか)   —   stimulation (e.g., of an economy)
進化   (しんか)   —   evolution
少子化   (しょうしか)   —   declining birth rates
郵政民営化   (ゆうせいみんえいか)   —   postal privatisation (privatisation of Japan Post)
高齢化   (こうれいか)   —   population ageing (aging)

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 諧 [Kanji of the Day]

✍16

中学

harmony

カイ

かな.う やわ.らぐ

俳諧   (はいかい)   —   haikai (collective name for haiku, haibun, haiga, senryu, etc.)
諧謔   (かいぎゃく)   —   joke
俳諧師   (はいかいし)   —   writer of haikai poems
諧謔を弄する   (かいぎゃくをろうする)   —   to crack jokes
諧調   (かいちょう)   —   harmonious melody
諧声   (かいせい)   —   vocal harmony
誹諧   (はいかい)   —   haikai (collective name for haiku, haibun, haiga, senryu, etc.)
滑稽諧謔   (こっけいかいぎゃく)   —   smooth-talking and humorous
半諧音   (はんかいおん)   —   assonance
俳諧の連歌   (はいかいのれんが)   —   haikai (humorous or vulgar renga poetry)

Generated with kanjioftheday by Douglas Perkins.

GIMP 3.2.6 Released [GIMP]

We’re happy to announce the release of GIMP 3.2.6! This stable release contains several months worth of patches, bug fixes, security updates, and more from new and longtime contributors.

Special thanks to Bruno Lopes, who has taken charge of backporting fixes from our development branch to the 3.2 stable branch.

This news posts provides an overview of the changes since GIMP 3.2.4. For a more detailed review, check out the NEWS changelog.

Don't squash bugs, free them, by Aryeom
“Don’t squash bugs… free them!”, by Aryeom, CC BY-SA 4.0 (a poetic approach to debugging), 2019

General Highlights and UX Improvements

A number of the fixes we first mentioned in our last development update were backported to GIMP 3.2.6.

Cheesequake has added code so you can use Cut on a layer group. This will allow you to cut the same section of all layers in the group, provided they are rasterized and not locked. Jehan made further improvements to this code.

The Sample Merged option for the Color Picker tool should now include any filters applied to a single layer when selecting colors. This was originally ignored due to an older optimization used for single layer images.

Balooii made many improvements to boost performance when loading a large number of fonts. While some lag remains and will likely require us to update to GTK4, the initial GIMP start-up, typing in the text tool, and closing font lists should be much faster!

Ondřej Míchal and Jehan have begun making changes to GIMP’s codebase to support an eventual GTK4 port. This includes swapping out the deprecated gtk_widget_show () functions with gtk_widget_set_visible (), replacing direct access to GdkEvent types with getter functions, replacing GDK_WA_CURSOR flags for explicit gdk_window_set_cursor () calls, and more. Even though we are not yet planning a GTK4 port, it doesn’t hurt to start preparing for it!

New contributor Ryan McDonald and Idriss Fekir have fixed an issue where the end of a line might be hidden on the left/right side when the text layout is set to “fixed”. When loading older XCFs, the problem will still be visible, but any changes to the text layer will update it to the correct view.

Kaushik B. has fixed an issue with the Heal Tool where you might get dark smudges if you move outside the bounds of a layer that’s smaller than the image canvas.

New contributor Manu Cornet and Jehan fixed a crash that could happen in certain circumstances when pressing keys too quickly after releasing the spacebar when panning.

Brandon Henderson reduced the sensitivity of the pan gestures when using the touchpad on macOS. This should make it easier to make fine-grain adjustments while editing an image on that platform!

Richard Gitschlag has adjusted the Text Tool so that you can still select the text to edit even if it has a layer mask that partially covers it.

Jacob Boerema resolved a bug in our metadata code that prevented GIMP from loading the Licensor metadata for an image.

Alx Sa added a maximum width of tooltips, preventing options with long descriptions from filling the entire screen.

Rodrigo Lledó Milanca updated our information on the ART Camera RAW plug-ins.

Several bugs related to rasterized vector layers have been resolved. Thanks to BobsDaughter, teapot, and Richard Gitschlag for their testing and feedback!

New Rotation Stylus Dynamics Input

Jehan recently implemented a new dynamic input for painting - Rotation (also known as Barrel Rotation). This feature is prominently used in the original Wacom Art Pen and newer Wacom Art Pen 2 pens, and allows GIMP to react to how you have rotated the brush in your hand as you draw.

You can adjust this value for custom brushes in the Dynamics editor. The MyPaint Brush tool is integrated with this feature as well, so it will automatically pass the rotation on as you paint if your stylus supports it.

OS and Platform Specific Improvements

GIMP uses GTK3, a cross-platform library for GUIs, to display its windows, widgets, and more. While it does a very good job of this, GIMP requires a lot of very complex interactions, and sometimes this can expose bugs that are only visible on certain platforms.

Bruno Lopes has been hard at work making a staggering number of platform-specific improvements to make GIMP work better. These include (but are not limited to):

  • Using “Server-side Decorations” for dialogs on KDE instead of GNOME-style “Client-side Decorations”. (In other words, the buttons appear at the bottom of the dialog instead of the header bar).

  • Secondary “pop-up” windows such as the resource selection and metadata editor dialogs should now appear in front of the first dialogue on Windows and macOS.

  • The System theme now uses your system’s defined accent colors on Windows and macOS.

  • Many improvements to proper focus setting on Windows and macOS.

  • Improvements to multi-window mode operations on Windows and macOS.

  • More system theme leaks caught on KDE Breeze system themes. This should help with graphical glitches in the UI.

  • We now depend on winflexbison on Windows for building the Image Map plugin. This fixes an issue where Windows users couldn’t reopen their image maps, even when created with GIMP.

  • Send to Email now works on MS Windows too using MAPI (works with Thunderbird and Outlook Classic).

  • Windows users can now use “Open With” on multiple files on start, without creating multiple instances of GIMP. This is consistent with how Linux and other platforms operate.

Because these improvements are wide-ranging, it is possible that we missed some interactions during testing that could cause a regression. If you notice any problems in GIMP 3.2.6, please let us know!

New macOS Package

Starting with GIMP 3.2.6, the .dmg package is now created at the same time as the Linux and Windows packages. This has not been possible for many years!

We used to create binaries for macOS on a separate GitLab repository, which was mirrored to another repository on GitHub, which was connected to a proprietary CI service (CircleCI) which then was connected to a MacStadium runner. All of that with dozens and dozens of additional patches, scripts etc! As you can see, this was extremely complicated, but it was the only way to ship macOS binaries back then.

Thanks to your donations, we were able to sponsor a MacBook Pro M5 for Bruno Lopes, who has been working since December 19, 2025 to fix that situation. As a result, GIMP can now be easily built on macOS with both MacPorts and Homebrew packages.

The macOS version of GIMP is now much more integrated with system-specific features, similar to the Linux and Windows version. A few examples:

  • Titlebars on macOS now follow the dark/light mode settings of the current theme.

  • Scrollbars now follow the macOS preference for whether they should be always visible or not.

  • The more standard ~/Library/Caches/ location is used for storing caches of GIMP resources, fixing a bug of brushes directory not being created on macOS.

  • GIMP’s number input buttons now respond to Cmd on macOS, like they do to Ctrl on other platforms. Some standard Mac shortcuts like, Ctrl + F2, Cmd + Shift + //Cmd + Ctrl + Space and Cmd + ` work as well.

  • Meta and Hyper modifiers now work.

  • Incorrect offsets when drag-n-dropping colors and layers/channels/paths have been fixed.

  • Filters now accept negative values regardless of your system language settings.

  • Plug-ins are treated as children of the main GIMP application, so they do not appear in the dock anymore.

  • GIMP custom cursors are now properly set for all tools (previously, they were being overwritten by the macOS arrow).

  • GIMP”, “Windows” and “Help” menus now match the standard macOS menus with proper localization.

  • Dialogs that shouldn’t be minimized (such as the search actions dialog shown with /) no longer show a minimize button on macOS.

  • Remote files can be opened thanks to using the native macOS API, since GIO does not support HTTPS on this platform.

  • Dashboard Backtraces are now supported using libunwind from libSystem.

In the process of implementing all these improvements, the separate macOS “developer package” was dropped. It was created due to the limitations of the previous macOS build infrastructure and became unnecessary now that it is way easier to build GIMP on macOS.

Plug-in and script developers should use the new GIMP SDK instead, or build GIMP directly.

Again, this is a brand new package. So, if you notice any problems in GIMP 3.2.6, please let us know!

Security updates

GIMP has added support for importing many different file formats over the years. In recent years, security detection tools have improved and found more and more potential exploits in open source software. Jacob Boerema and Alx Sa have been busy testing and patching these.

For reference, the following Common Vulnerabilities and Exposures (CVE) have been patched in this release:

CVE-2026-18301, CVE-2026-18304, CVE-2026-18302, CVE-2026-18303, CVE-2026-18305, CVE-2026-18306, CVE-2026-18307, CVE-2026-18308, CVE-2026-18309, CVE-2026-62438, CVE-2026-62439, ZDI-CAN-29400, CVE-2026-59087, CVE-2026-59088, CVE-2026-59089, CVE-2026-66757, CVE-2026-59090, CVE-2026-59091, CVE-2026-66758, CVE-2026-66759, CVE-2026-78465, CVE-2026-78475, CVE-2026-79902, CVE-2026-80101, CVE-2026-82324, CVE-2026-82328, CVE-2026-82330, CVE-2026-82343

We want to thank Jace, Brent Hull, Tristan Madani, Florent Saudel, bb1abu, Yukihiro Nakamura, Securin Disclose, and Zero Day Initiative for their security reports and suggestions. We also want to thank Michael Catanzaro for his help in organzing these reports and requesting CVEs for them.

For Plug-in/Script Authors and Builders

Our GdkPixbuf dependency minimum version has been updated to 2.32.0 due to an issue with Glycin printing a bunch of unnecessary messages on start-up related to a deprecated to-pixdata function.

PDB commands now only show error/warning messages when run in interactive mode. For non-interactive modes, you won’t see anything printed in the console on PDB function failure. Instead, you can check the return values of the function and provide any messages you want to users.

Jehan improved our method for checking if a plug-in has been updated since the last time you opened GIMP. Now we check creation time (ctime) instead of just modified time (mtime) since it might be always 0 on certain packages like flatpak. This should mean that changes you make during development are more likely to be loaded if you’re testing on flatpak.

Kamil Burda fixed documentation for integer and double types in the Procedure Browser.

Pranav P corrected a build issue that caused a freeze on s390x systems.

GIMP SDK

You can now build C plug-ins and GEGL filters from all the official packages we distribute by using the gimptool commandline tool. That is because we now ship all required headers and libraries for compiling (in total, less than 20MB).

Before now, this was possible only on flatpak and Snap. So, Bruno Lopes extended it to the AppImage, Windows and macOS packages. We call this new feature the “GIMP SDK”.

Take a look at the build instructions if you are interested.

Around GIMP

GIMP 3.2 Help Manual Updates

Jacob Boerema, maintainer of the GIMP help manual repo, has released an updated version that contains all the changes brought in GIMP 3.2. It is available online, or you can download it if you want to keep a local copy.

Historical News

Balooii has been working to restored older news posts that have been lost to the ages. You can now see almost all news posts from 2004 to 2008 on the main site now - just navigate back to that point in time in the archive.

GEGL and babl

GIMP 3.2.6 also shares a release with new versions of GEGL and babl by maintainer Øyvind Kolås!

babl 0.1.128 includes several fixes for building on macOS, initial WebAssembly support, and better checks at runtime for avx512 - all by Bruno Lopes.

GEGL 0.4.72 updates its OpenCL support to version 3.0. Ondřej Míchal worked on important stability fixes for the OpenCL code (though such code path is still disabled by default in GIMP). Jacob Boerema made several fixes to the RGBE file format import and export functions. Aruius made the GeglColor comparison functions public, for future use in better comparing comparing colors in GIMP and other software. Tal Regev added support for building GEGL using only MSVC, and Bruno Lopes added support for WebAssembly as well. Luigino Camastra added more security checks to prevent potential overflows.

More details can be found in the GEGL NEWS document!

Release Stats

Since GIMP 3.2.4, in the main GIMP repository:

  • 179 reports were closed as FIXED.
  • 104 merge requests were merged.
  • 871 commits were pushed.
  • 21 translations were updated: Belarusian, Brazilian Portuguese, Chinese (China), Dutch, Georgian, German, Hebrew, Hungarian, Kazakh, Lithuanian, Norwegian Bokmål, Norwegian Nynorsk, Slovenian, Swedish, Serbian, Slovak, Spanish, Thai, Turkish, Ukrainian, Vietnamese.

58 people contributed changes or fixes to GIMP 3.2.6 codebase (order is determined by number of commits; some people are in several groups):

  • 22 developers to core code: Bruno Lopes, Alx Sa, Jehan, Ondřej Míchal, balooii balooii, Richard Gitschlag, Michael Natterer, programmer-ceds, Ahmed E. Yassin, Andreas Vukman, Estecka, Idriss Fekir, Jacob Boerema, Manu Cornet, Petr Vorel, Ryan McDonald, balooii, cheesequake, kaushik_B, screem02, v4vansh, woot000.
  • 14 developers to plug-ins or modules: Alx Sa, Bruno Lopes, Ondřej Míchal, Jacob Boerema, Jehan, Dimitriy Ryazantcev, lloyd konneker, balooii balooii, Frank Teklote, Harsh Verma, Michal Vašut, Mike Gorse, Richard Allen, Rodhos.
  • 23 translators: Dick Groskamp, luming zh, Martin, Yuri Chornoivan, Ekaterine Papava, Rodrigo Lledó, Aefgh Threenine, Anders Jonsson, Kolbjørn Stuestøl, Baurzhan Muftakhidinov, Emin Tufan Çetin, Aurimas Aurimas Černius, Jose Riha, Марко Костић, Rafael Coelho Costa, Trần Ngọc Quân, Vasil Pupkin, Balázs Úr, Carsten Drewes, Juliano de Souza Camargo, Kjartan Maraas, Sabri Ünal, Yaron Shahrabani.
  • 3 theme designers: Bruno Lopes, Alx Sa, Ondřej Míchal.
  • 9 build, packaging or CI contributors: Bruno Lopes, Jehan, Jacob Boerema, Petr Vorel, Harsh Verma, Lukas Oberhuber, Ondřej Míchal, balooii balooii, lloyd konneker.
  • 3 contributors on other types of resources: Jehan, Bruno Lopes, Aryeom.
  • The gimp-data submodule had 16 commits by 7 contributors: Bruno Lopes, Jehan, Alx Sa, Anders Jonsson, Denis Rangelov, Lukas Oberhuber, balooii balooii.
  • 4 image creators: Bruno Lopes, Jehan, Anders Jonsson, Lukas Oberhuber.
  • 1 icon designers: Denis Rangelov.
  • 1 cursor designers: balooii balooii.

Contributions on other repositories in the GIMPverse (order is determined by number of commits):

  • Our UX tracker had 3 reports closed as FIXED.
  • babl 0.1.128 is made of 70 commits by 3 contributors: Bruno Lopes, Øyvind Kolås, Jehan.
  • GEGL 0.4.72 is made of 234 commits by 28 contributors: Bruno Lopes, Ondřej Míchal, Øyvind Kolås, luming zh, Jacob Boerema, Jehan, Kolbjørn Stuestøl, Tal Regev, WarisMaqbool, Aefgh Threenine, Anders Jonsson, Martin, Yuri Chornoivan, Baurzhan Muftakhidinov, Dick Groskamp, Ekaterine Papava, Sabri Ünal, aruius, Alan Mortensen, Asier Saratsua Garmendia, Chao-Hsiung Liao, DiGro, Marco Ciampa, Rodrigo Lledó, Saikeo Kavhanxay, Thomas Manni, YOSHIDA Shigeto, Марко Костић.
  • ctx had 150 commits since 3.2.4 release by 3 contributors: Øyvind Kolås, Bruno Lopes, Tal Regev.
  • The gimp-test-images (unit testing repository) repository had 5 commits by 1 contributors: Jacob Boerema.
  • The flatpak release had 35 commits by 3 contributors: Bruno Lopes, Erick555, Jehan.
  • Our main website (what you are reading right now) had 182 commits by 7 contributors: Bruno Lopes, Jehan, Alx Sa, balooii balooii, balooii, Liam Quin, Allan Day.
  • Our developer website had 110 commits by 5 contributors: Bruno Lopes, Jehan, Alx Sa, aruius, Ondřej Míchal.
  • Our 3.0 documentation had 276 commits by 20 contributors: Jacob Boerema, Dick Groskamp, DiGro, Kolbjørn Stuestøl, Marco Ciampa, Anders Jonsson, Yuri Chornoivan, Марко Костић, Richard Gitschlag, Alx Sa, Baurzhan Muftakhidinov, Christian Kirbach, Mateusz Jastrząb, YOSHIDA Shigeto, Andre Klapper, Balázs Úr, Chas Belov, Kristjan ESPERANTO, Rodrigo Lledó, Víttor Paulo Vieira da Costa.

Let’s not forget to thank all the people who help us triaging in Gitlab, report bugs and discuss possible improvements with us. Our community is deeply thankful as well to the internet warriors who manage our various discussion channels or social network accounts such as Ville Pätsi, Liam Quin, Michael Schumacher and Sevenix!

*Note: considering the number of parts in GIMP and around, and how we get statistics through git scripting, errors may slip inside these stats. Feel free to tell us if we missed or m

Downloading GIMP 3.2.6

You will find all our official builds on GIMP official website (gimp.org):

  • Linux AppImages for x86 and ARM (64-bit)
  • Linux Flatpaks for x86 and ARM (64-bit)
  • Linux Snaps for x86 and ARM (64-bit)
  • Universal Windows installer for x86 and ARM (64-bit)
  • Microsoft Store for x86 and ARM (64-bit)
  • macOS DMG packages for Intel/x86 and Apple/ARM hardware (64-bit)

Other packages made by third-parties are obviously expected to follow (Linux or *BSD distributions’ packages, etc).

What’s Next

Work these days has mainly and already shifted to the development series which will eventually lead to GIMP 3.4 versions. For anyone who missed it, the Development Update, August 2026 news is interesting on this aspect. In the meantime, we will obviously still continue backporting bug fixes on the 3.2 series, of which GIMP 3.2.6 is a part of.

This new version should widely improve stability, and in particular it looks like macOS users should particularly appreciate it (thank Bruno for that)! We are also extremely thankful to the new skilled contributors the project has been getting. Don’t forget that, as long as you don’t use genAI in your toolset, everyone is very welcome to participate! 🤗

Don’t forget you can donate and personally fund GIMP developers, as a way to give back and accelerate the development of GIMP. Community commitment helps the project to grow stronger!

08:00 AM

Judge Demands Answers From DOJ For Refusing To Dismiss Reflecting Pool Case With Prejudice [Techdirt]

There are multiple things this administration is incapable of doing: winning wars, curbing inflation, not acting like Nazis, wearing shoes that fit them, etc. But if there’s one thing it’s most known for, it’s the unwillingness to take a loss and move on.

That’s why the DOJ is still trying to imprison/jettison into a war-torn African nation its first spectacular failure: Kilmar Abrego-Garcia. And that’s why — multiple attempts and several million dollars later — Trump is still pretending what happened to the Lincoln Reflecting Pool were acts of vandalism, rather than the shoddy work of his preferred contractors. Those facts are on the permanent record, supplied by his own DOJ and his handpicked US Attorney (and former Fox News personality, natch) Jeanine Pirro.

The DOJ claimed Doug Burgum’s Interior Department lied to it when it moved to dismiss federal vandalism charges against former Olympian David Hearn. To his credit(?), Burgum has been nothing if not consistent. Burgum continued to spread the lies. And Trump has continued to double-down on his bogus “vandals” claims since the DOJ dropped the charges.

The continuing problems aren’t limited to Burgum’s and Trump’s constant lies. The main problem for David Hearn is that the DOJ can always try to run him through the court system again. While the DOJ made it clear any damage was due to poor workmanship, it refused to dismiss the charges with prejudice — something that would have prevented the DOJ from re-charging Hearn in response to White House pressure and/or a series of hirings/firings meant to replace Pirro with someone more sycophantic.

While the DOJ may have an infinite amount of time and money to blow on stroking off Trump’s revenge fantasies, its lawyers have been learning repeatedly that federal judges have a finite amount of patience for their constant bullshit.

Hearn’s legal team has refused to let this case go simply because the DOJ has refused to let this case go. It has asked the court to bring the DOJ back to explain why it won’t dismiss the charges with prejudice, even after publicly admitting any alleged “vandalism” was simply the end result of shitty pool repair work.

The DOJ still refuses to take this step, which has naturally resulted in DOJ lawyers being berated by yet another exasperated federal judge:

Superior Court Judge Todd Edelman asked assistant U.S. Attorney Michael Spence how he was supposed to look at the president’s statements about David Hearn, one of his attorneys and U.S. Attorney for the District of Columbia Jeanine Pirro as “anything other than [Trump] pressuring your office, your boss and the three of you to charge Mr. Hearn, recharge Mr. Hearn with what you had decided to be a meritless prosecution.” 

“Isn’t this a unique threat of meritless re-prosecution?” Edelman said. 

You’ll notice it’s US Attorney Michael Spence now handling this case, since Pirro has been sidelined (but not officially fired) for refusing to engage in a malicious prosecution on Trump’s behalf. In return for Pirro momentarily demonstrating better judgment and displaying some respect for her office, Trump has repeatedly maligned her in public comments and Truth Social posts.

That leaves Spence with nothing but the dirtiest of dirty work — ensuring the Hearn prosecution remains on life support until Oval Office pressure forces him to move forward with “meritless re-prosecution,” to quote Judge Edelman.

Spence had nowhere to go. Having been painted into the corner by the administration that currently employs him, all he could do was offer up a weak non-rebuttal that kind of throws Trump under the Truth Social bus he’s driving, while being as noncommittal as possible about the future of the Hearn prosecution:

Spence replied only that Trump’s statements “speak for themselves,” while also arguing it was premature to discuss that hypothetical notion because no further grand jury action had happened.

Bro, this discussion isn’t “premature.” Rights are there to be protected, rather than just vindicated after the fact. The court isn’t obligated to allow the DOJ to engage in a malicious re-prosecution before it can draw inferences from the administration’s actions and statements. Courts aren’t just there to clean up the messes the other branches make. They can also block the government from moving ahead with planned rights violations.

US Attorney Spence is saying as little as he can in hopes of saving a job that’s probably not worth having. The future will only hold worse things for anyone who thinks it’s possible to appease both Trump and an apparently never-ending series of annoyed federal judges. 30 seconds of boiler plate editing is all it would take to end the Hearn saga for good. But Spence — and the cowards who work with him — will never close this case because Trump won’t be happy until he’s put someone — anyone! — in jail for botching a job he’d spent months bragging about.

07:00 AM

Lawmakers Ask Lutnick To Blacklist Appin, The Hack-For-Hire Firm That Threatens Almost Anyone Who Prints Its Name [Techdirt]

Remember Appin? It’s the Indian “hack for hire” company that got so upset about Reuters’ giant investigation — which detailed how Appin grew into a “leading cyberespionage firm” that “stole secrets from executives, politicians, military officials and wealthy elites around the globe” — that it convinced an Indian court to make Reuters take the story down. Then, when we wrote about them forcing Reuters to take down the article, they demanded we take down our article as well, claiming that we violated a court order (to which we were not a party) by republishing some of the Reuters article (which we did not even do).

Depressingly, plenty of other publications — including the vaunted Lawfare — simply caved to these specious demands. We refused to do so, with the help of EFF, who sent a letter on our behalf explaining why we (and our friends at MuckRock) would not abide by this ridiculous legal threat. We never heard from them again. Eventually, Reuters convinced the court in India to overturn its ruling and put the article back online (bizarrely, Lawfare’s version is still redacted two years after the Reuters article came back online).

But Appin and its original boss Rajat Khare have continued to threaten and bully journalists, media websites, and tech websites, for any kind of reporting on Khare or Appin’s questionable history. Even the Behind the Bastards podcast pulled down episodes about Khare, even after they were titled “We Can’t Put This Guy’s Name in the Title, But Trust Us, He Sucks” and started out with host Robert Evans admitting he expected them to get legal demands to remove the episode pretty quickly.

This week, Senators Ron Wyden and Sheldon Whitehouse, along with Rep. Pat Harrigan, sent a letter to Commerce Secretary Howard Lutnick, asking him to add Appin and several related companies (CyberRoot, BellTroX, Adaptive Control Security Global Corporate, ABP Holdings, and “Sunkissed Organic Farms” — yes really) to the Commerce Department’s Bureau of Industry and Security (BIS) “Entity List” — the tool that effectively cuts foreign entities deemed national security threats off from American technology and American business partners. It’s the same designation BIS used against NSO Group in 2021.

This is notable, in part, because the senders are bipartisan (Harrigan is a Republican while Wyden and Whitehouse are Democrats). This issue shouldn’t be partisan, though it’s a bit odd they couldn’t get a GOP Senator to sign on as well, especially given how frequently GOP Senators whine about claims of foreign censorship. I guess it’s not so important when that censorship is actually real and not part of a culture war.

Also, the Entity List is a kind of “nuclear option” and one that I’ve been worried this Commerce Department will abuse. After all, we’ve already seen this administration totally abuse the “supply chain risk” designation against Anthropic for not being willing to takedown some guardrails. You could totally see it making use of the Entity List (for which there is little due process) to cut off foreign companies that someone in Trump’s orbit is mad about.

But this isn’t that. This seems like an entity that has zero redeeming qualities and is just doing serious damage around the globe, while then suppressing (or attempting to suppress!) the speech of anyone who publicly talks about what they’re doing.

So while I’m always a little nervous about how this administration would use something like the Entity List, this seems like a legitimate situation where it makes sense.

Being put on the Entity List would cut Appin off from a variety of American technology tools and business partners, greatly increasing its cost of doing business. Though, it wouldn’t necessarily stop Appin’s SLAPP happy speech suppression campaigns. The Entity List is an export control tools, so would restrict the flow of American tech to these Indian entities. But it doesn’t bar American companies from providing services. Thus, they could likely still hire proud speech suppressors from the law firm of Clare Locke (as they have in the past) to try to scare the media into silence.

And, of course, they can still seek out judges elsewhere (as they did to suppress the Reuters story) where there are fewer free speech protections.

So, yes, getting Appin on the Entity List would make the hacking part a bit more difficult (just as it limited NSO’s business), but to deal with the speech suppression, Congress should finally get around to passing a federal anti-SLAPP law.

The letter lays out both halves of the problem: the espionage itself — including targeting of US law firms and work allegedly done at the behest of the Qatari government — and the global lawfare campaign the hackers ran afterward to keep Americans from reading about any of it:

Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them. Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.

These hackers have systematically subverted the U.S. legal and financial sectors, targeting private equity firms, pharmaceutical companies, and more than 1,000 attorneys across major U.S. law firms to manipulate ongoing litigation. The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence. While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.

Simultaneously, these actors have mounted an aggressive censorship campaign to suppress public awareness of their illicit activities, directly threatening American free speech and press freedom. Executives connected to one hack-for-hire group secured an Indian court order enforcing a global takedown of an investigative report by Reuters, including a copy of the report hosted by the Internet Archive. To force further censorship, these foreign hackers have launched ongoing lawsuits against major American media institutions and technology companies, including Google, Meta, Microsoft, and The New Yorker.

While those companies named at the end there are all large, with big legal departments who can fend off SLAPP suits, not everyone else can, which is probably why so many smaller outfits (though not us!) have given in to censorial demands from Appin and related companies.

I do wonder whether Appin’s legal bullies will now demand we take down this article — one about a letter from two sitting senators and a member of Congress, published on an American website, describing a censorship campaign aimed at American publishers. If they do, I wonder if they’ll also throw in any extraneous claims to deny as well, such as about unmentioned “conspiracy to or complicity in murder.”

Jimmy Kimmel Won’t Air James Talarico Interview On ABC For Fear Of FCC Reprisal [Techdirt]

Comedian Jimmy Kimmel‘s planned Thursday interview with Texas Senatorial hopeful James Talarico didn’t air on ABC broadcast TV because network lawyers were worried about Trump FCC censorship and reprisal. Instead, the interview will air on the late-night show’s YouTube channel, Kimmel stated during his latest late night Jimmy Kimmel Live monologue:

“You know, for a lot of years, for the whole 20-plus years of our show, in fact, I’ve been interviewing Americans who are running for office with no problem at all, just like Letterman did, Leno did, Arsenio, etc. etc., I’ve interviewed a lot of political candidates. From Hilary Clinton to Ted Cruz to Donald Trump. I interviewed Donald Trump when he was running for president in 2015, and at that time, when he was the one sitting next to me, he seemed to have no problem with the idea of talk show hosts interviewing candidates. In fact, he was very eager to come back for another interview, which he did just before he became the nominee in 2016. But for some reason, and I can’t seem to figure out what that reason is, something has changed.”

“Now that Trump is president, his FCC has threatened me, threatened our show, threatened our network, ABC, our affiliates and our local stations based on simple traditional editorial decisions, guest bookings, it would seem, [that] they don’t like.”

Trump Republicans clearly feel Talarico is a threat to their chance to hold on to the Texas Senate. So earlier this year Trump FCC boss Brendan Carr launched a fake investigation and early review of ABC’s broadcast licenses, claiming that it broke FCC rules by hosting Talarico on The View back in February.

To support his sham inquiry, Carr claimed Talarico’s appearance violated the dated FCC “equal time” rule, which used to mandate that an election season prime time TV appearance by one party’s politicians had to be countered by an appearance by the other party’s politicians. The rule is no longer meaningfully enforced because television obviously has waning impact in the internet era.

But more importantly, The View had struck very clear agreements with the FCC that it has been exempt from this rule since 2002. Carr knows this. But he still falsely claimed The View violated the law, and to sell the violation appears to have worked closely with right wing broadcast affiliates to try and make it look like ABC’s Houston affiliate broke the law (something I suspect will resurface in court).

ABC recently sued the FCC for clearly violating the First Amendment, but while the case plays out their lawyers aren’t taking any chances. In addition to shuffling the Talarico interview off to YouTube (where it’s likely to see a bigger audience due to the sloppy attempt at censorship), The View has simply stopped hosting politicians entirely for fear of adding fuel to the fire.

Daily Deal: SunFounder GalaxyRVR Mars Rover Kit for Arduino [Techdirt]

The SunFounder GalaxyRVR Mars Rover Kit is your gateway to hands-on learning on robotics, coding, and Mars-like adventures! Its durable aluminum frame and rocker-bogie suspension easily handle tough terrains, while smart sensors ensure smooth navigation. It’s compatible with the Arduino UNO R3, runs on solar power, and includes real-time FPV with app-based control for day or night adventures. Complete with beginner-friendly tutorials and active support, this kit makes learning coding, electronics, and robotics fun and accessible. It’s on sale for $110.

Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

DHS Feeding Citizens’ Bank Records To Predictive Policing Units To Find Drivers To Pull Over [Techdirt]

Every government does stuff because it can, not because it needs to. But this current administration has been far more opportunistic than most, doing constitutional recon in areas of unsettled law right up until a court rules that it can’t. (In some cases, it continues to do these things despite having lost in court.)

While it’s long been known the government has pretty much unfettered access to financial records (thanks to the Third Party Doctrine), it’s always been hoped that these records are obtained during targeted investigations, rather than just gathered in bulk and fed to whatever algorithm the government has laying around.

Something that definitely looks like a brand new way to engage in legalized theft (a.k.a. “civil asset forfeiture”) is the new normal for DHS agencies. As Joseph Cox reports for 404 Media, the government is feeding bank records in bulk to its predictive policing task force for the sole purpose of increasing the number of pretextual traffic stops.

Border Patrol is running secretive predictive policing units that analyze Americans’ financial activity and other data, then feed that intelligence to local police who pull people over who are not suspected of any specific crime, but which the government thinks may be worth searching, 404 Media has found.

The units, the name of which 404 Media is revealing here for the first time, are called Predictive Intelligence Targeting Teams (PITT). In one case, a PITT analyzed the financial activity of a man who was driving across Montana, and local authorities stopped him under the pretense of an obstructed license plate and charged him with a DUI. 

Predictive policing has always been problematic, due to its reliance on garbage data generated by biased policing. This takes it a step further, allowing the DHS’s new “targeting teams” to manufacture suspicion of criminal activity by feeding tons of data to a system whose sole purpose is to generate reasons to pull people over.

No one would have known much about this secretive program, but the government gave the game away in court as it attempted to convert a bogus traffic stop into criminal drug trafficking charges against the Montana man.

During discovery in his case, [Kyle] Olson was provided a Department of Homeland Security (DHS) document that explained how Border Patrol instigated his traffic stop. Written by Border Patrol Agent Matthew Phelps, the document said Phelps was assigned to the “Spokane Sector Border Patrol Targeting & Intelligence Division (TID) — Predictive Intelligence Targeting Team (PITT).” Olson shared the document with 404 Media.

In his role at the PITT, Phelps wrote he reviews “law enforcement-sensitive databases” to develop intelligence before handing over information to local law enforcement. That intelligence specifically involves reviewing Americans’ financial activity, the document says.

Border Patrol and CBP (Customs and Border Protection) defended their actions in statements to 404 Media, claiming hoovering up bank records and handing them over to supposed predictive policing specialists is nothing more than being smart about hunting down criminals. Given the facts of this traffic stop, it appears the algorithm and its “targeting team” of human backstops are looking for financial transactions that slightly resemble money laundering.

At least that’s what the Border Patrol agent told the court during its defense of the traffic stop:

Phelps says he observed, “information contained within law enforcement-sensitive systems suggesting financial activity patterns commonly associated with illicit narcotics activity.”

But here’s the thing about money laundering. When it’s done well, the “financial activity patterns” will look entirely normal. What appears to be happening here is a bulk collection of financial records getting shoved into a computer, flagging anything that looks “suspicious.” Using these assumptions, DHS agencies are utilizing their access to other databases (including ALPR networks) to find people to pull over… based on nothing more than transactions that appear abnormal to people who are just looking for a reason to accost citizens.

That might mean something if we were allowed to see the parameters set by the government’s PITTs. But we’re not. And when we are pulled over, the officers will rely on whatever pretext seems most believable, rather than tell the truth about their roadside fishing expeditions.

There’s a lot that’s extremely fucked up about this revelation, including the fact that the government is relying on parallel construction to obscure its (ab)use of financial records to generate something that cannot reasonably be called “suspicion.”

But the most fucked up thing is this: the Supreme-Court-created “Third Party Doctrine” makes an assumption almost no actual American citizen would: that anything they voluntarily share with service providers (like credit card companies and banking institutions) is nothing more than the government’s plaything. No one really thinks the government should just be able to scoop up tons of data just so it can run it through some software to see what pops up.

Lots of people assume that if the government obtains their bank records, it’s because it’s engaged in an investigation. But that’s rarely the case. This is the government piling up haystacks and pretending every bit of “interesting” hay is the needle it’s been looking for. Given the truth behind the pretenses of these stops, the ultimate goal likely isn’t capturing criminals, but shaking people down for whatever cash they might have on them.

03:00 AM

Things are humming [Seth Godin's Blog on marketing, tribes and respect]

The Knot is coming.

On sale today, a limited-edition pennant made by hand in Buffalo…

The five-pack from Porchlight (with bonus Spindex) is still available as well. The launch event on September 21 is fully sold out.

Spotify chose The Knot as an editor’s pick this month, and the Next Big Idea Club shortlisted it as a September Must-Read. Here we go…

Thanks for being part of it.

      

How much extra for “not lazy”? [Seth Godin's Blog on marketing, tribes and respect]

Lazy isn’t a moral failing. It’s an economic consideration.

We have limited time, limited energy and limited resources. Allocating that effort is often done in response to what’s at stake and what’s on offer.

The clean room at a silicon fab or operating theater is clean because everyone involved puts in a lot of effort to keep it that way. And that effort is expensive.

It’s not efficiency or precision. Those are important on their own. The gap between laziness and not-lazy requires effort in the face of nuance, challenges or frustrations.

The staff at Motel 6 will put less effort into each guest’s requests than at the Ritz down the street because there’s a lot more staff per person at the Ritz.

There’s organizational laziness, in which a system is designed to have each person care a bit less about each task in exchange for completing more tasks, and there’s individual laziness, which is the natural consequence of disrespectful management.

If the boss insists on non-lazy behavior, but doesn’t give the team the time, the training, the tools or the compensation to do so, it’s not going to happen, not in the long run. Over time, not-lazy is rarely free.

AI bots have an economic incentive to do as little as they can get away with, and so do we. Programmers around the world are frustrated that coding bots almost solve the problem, but don’t seem to care enough to put in the extra cycles to get it right. But that’s what we’re (not) paying for.

The mismatches are frustrating. We might be delighted when we get not-lazy responses that we didn’t pay for, but it ruins a brand or a project when the effort we expected from a system or a person doesn’t match what we think we paid for.

Some clarifying questions:

Are our customers already paying for the non-lazy option? Or do they think they should be getting it for free?

If we wanted to disrupt our competitors by being the non-lazy option, what would we have to do and how could we communicate that?

How can we manage systems, processes and people so they have the resources and rewards they need to take the non-lazy approach?

If we’re trapped or pushed into the lazy path, how can we build systems so that laziness doesn’t damage our work?

How much extra could we charge for not-lazy? And are we prepared to keep that promise?

“You’ll pay a bit more but you’ll get more than you paid for” is almost always a winning market position.

      

Pirate IPTV Operators Face $32.7 Million Judgment and Self-Expanding Blocking Injunction [TorrentFreak]

tu logoDynamic site blocking orders that allow rightsholders to add new targets without returning to court have been common in Europe for years.

In July, Spanish-language broadcaster TelevisaUnivision (TU) obtained a similar order from a federal court in Florida.

This preliminary injunction, which started with five pirate IPTV services, expanded to cover hundreds of domains and dozens of intermediaries within weeks. After all defendants failed to show up in court, the broadcaster now seeks a permanent and even broader injunction.

In a motion filed September 4, TU asked Judge Kathleen Williams to enter default judgment against the six named defendants behind Thunder TV, Sunset TV, and Tele Latino. The operators of Pop TV and Kaelus TV, the other two services named in the complaint, remain unidentified John Does.

Self Expanding Blocking Injunction

The request for a default judgment comes with a headline figure seeking $32.7 million in damages. However, it is the breadth of the associated permanent injunction that really stands out.

The preliminary injunction obtained this summer allowed TU to add new domains, IP addresses, and pirate services to the order, without requiring judicial approval. TU already used that power twice before the injunction was a month old.

The proposed permanent order keeps that mechanism but also extends it, shaping it into a broad and self-expanding order with several new powers. For example, it can add new defendants, not just domains.

“Plaintiffs may, without further leave of Court, supplement the caption of this action to add as John Doe Defendants any person or entity discovered to be engaged in any of the conduct prohibited by this Order,” the proposed order reads.

Proposed extended powers

proposed inunction

The second expansion is a “colorable similarity” carveout. Any service that provides unauthorized access to the broadcaster’s content, uses substantially similar technology, or targets the same subscriber base can be required to comply. This also applies to alter-ego and successor services.

That provision has a concrete target. According to a supplemental declaration, Thunder TV itself no longer carries TelevisaUnivision content, but its operators have launched a mirror application called “Black Eye” that does. Access to Black Eye “is obtained using the same credentials used for Thunder TV,” the declaration states.

Nearly 600 Domains, 121 Intermediaries

The legal paperwork lists nearly 600 unique domain names, covering the five original services and the seven brands that were added later, including XuperTV, Tarjeta Roja, Pirlo TV, and Roja Directa.

Thunder TV and Tele Latino alone account for more than 90 domains each. XuperTV, which TU describes as a white label built on the same Magis TV infrastructure as Tele Latino, adds more than 110 to the mix.

One of the many XuperTVs

Xuper

The intermediary list is also as broad as we have ever seen in this type of injunction. It lists 121 intermediaries, including 51 domain registrars, 58 hosting and CDN providers, five payment channels, and five app distribution platforms.

The intermediaries include U.S. companies such as NameCheap and GoDaddy, as well as Russia’s REGTIME-SU, Vietnam’s Mat Bao, Peru’s NIC.PE, and the Dutch Registrar.eu, Iran’s Aria Shatel and a Romanian state research institute, ICI Bucuresti.

Other platforms are also listed, including GitHub, Vercel, Canva, Wix, Squarespace, and Automattic, the company behind WordPress.com, with each linked to one or more pirate domains or services.

Some of the intermediaries

auto

The proposed injunction also includes RIPE NCC and APNIC, the regional Internet registries for Europe and the Asia-Pacific. These are inaccurately described as a “web host / hosting provider,” as they allocate IP address space. These can’t block access to IP-addresses.

RIPE

ripe

Cloudflare again gets its own dedicated section. For each of roughly 90 IP addresses tied to the pirate domains, it must produce the origin server behind its proxy and the account holder’s name and email.

Finally, Roku and the AFTVnews Downloader app are ordered to remove the pirate apps and block the numerical short codes used to install them.

$32.7 Million, On Paper

The requested permanent injunction comes in addition to the damages, which are made up of both copyright and trademark infringement claims.

The broadcaster seeks $26.7 million for willful copyright infringement, at the statutory maximum of $150,000 per registered work, and $6 million for willful trademark counterfeiting, at $2 million per defendant group.

When dealing with foreign defendants who are not responsive, it is unlikely that this money will ever be recouped. TU is well aware of this, using it as another argument why a permanent injunction is needed. That would help to block or shut down the domains and the associated infrastructure.

The multi-million damages demand is not new. Amazon and Netflix won $18.75 million against a Dallas IPTV operator in March, and Hollywood studios secured $9 million in Pennsylvania in June.

For now, the motion is pending before Judge Williams. Whether the proposed order’s most expansive provisions survive as written has yet to be seen.

A copy of the motion for default judgment is available here (pdf). The proposed default judgment order can be found here (pdf), and the proposed permanent injunction with updated Schedule A here (pdf).

From: TF, for the latest news on copyright battles, piracy and more.

Thursday 2026-09-10

11:00 PM

Automakers Pressure Congress To Ban Chinese EVs To ‘Protect Privacy’ [Techdirt]

If you enjoy badly written bipartisan protectionist tech legislation designed primarily to coddle giant U.S. companies under the xenophobia-tinged breathless pretense of privacy and national security, you are really going to enjoy the next twelve to twenty-four months.

While the U.S. drowns in corrupt kakistocracy, the Chinese are making significant market inroads in everything from AI to EVs. That’s resulted in U.S. companies applying greater and greater pressure on U.S. lawmakers to simply ban Chinese goods. The Trump administration’s adoption of this policy has been a hot and sloppy protectionist mess, incompetently implemented and unsubtly racist.

Automakers are particularly worried about cheaper, better Chinese EVs making their way to the U.S. So under the banner of the misleadingly named Alliance for Automotive Innovation, they’re pressuring U.S. lawmakers to enact a ban on Chinese EVs. You know, because they’re very worried about privacy and national security:

“Right now, Chinese automakers are dumping subsidized vehicles with connected software and hardware around the world,” John Bozzella, CEO of the group, said in the letter seen by CNBC. “This hasn’t happened inside the U.S. yet, but given the scale and urgency of this threat, we urge you to enact a Chinese vehicle, software and hardware ban before adjourning this year and make this policy the law of the land.”

“Enacting a permanent ban on Chinese vehicles and high-risk hardware and software in the 119th Congress will send a clear and bipartisan message that China’s strategy to dominate global automotive manufacturing will be met with a national security policy response from the American government,” Bozzella said.

So for one, I like how the auto industry throws the word “subsidized” around as if they haven’t enjoyed generations’ worth of their own pointless subsidies. Two, the U.S. auto industry has some of the worst privacy standards and ratings of any industry in America, and sell the entirety of your driving, personal, and behavior data to any old random asshole in a country too corrupt to pass privacy laws.

Failing to secure your own vehicles and fighting tooth and nail against any privacy safeguards… then ranting incoherently about the threat of Chinese tech on U.S. shores is not serious policy. Our failure to regulate data brokers or pass modern privacy laws means the Chinese simply buy this same data from any of dozens of dodgy companies already, making a lot of this stuff lazy pantomime.

We’ve seen this before: Democratic lawmakers in Michigan recently tried to ban Chinese EVs from even visiting the state, suggesting that automakers are afraid of Americans even getting to look at overseas alternatives. The justification (by folks who are are, again, completely absent when it comes to any sort of domestic U.S. privacy standards) is they were just very concerned about U.S. consumer privacy.

I maintain that ideally you allow Chinese companies to compete in the U.S. market, but you fund, staff, and legally protect your labor, consumer, competition, and environmental regulators so that companies are all genuinely competing on a level playing field. You boot or penalize obvious bad actors on privacy, security, competition, and consumer protection, both foreign and domestic.

U.S. corporate giants don’t much want that, given it means more oversight, more competition, and diminished quarterly returns. So what we often get instead is a sort of a corrupt-fueled incompetent rank protectionism that’s highly performative but still broadly harmful.

And while you could theoretically implement protectionism in a way that’s coherent, the U.S. is too corrupt to do that. So what you get is stuff like the TikTok ban, which was driven by years of hysteria about Chinese spying and propaganda, only to result in a bipartisan array of lawmakers shoveling TikTok off to Trump’s billionaire autocrat friends, which was not any net improvement.

Or you get stuff like the “race to 5G,” which involved U.S. policymakers being told that the only way to keep pace with Chinese 5G was to give U.S. telecoms less oversight, more pointless subsidies, and approval for their terrible mergers (the U.S. lost the “race to 5G” in terms of reach, network quality, and affordability then immediately just… stopped talking about it).

Or you get stuff like the recent ban on Chinese drones, which the Trump FCC is too incompetent to implement, resulting in higher prices, lower quality products on U.S. shelves, new corrupt patronage systems, and a lot of pointless chaos.

As a backdrop we have a U.S. corporate press that’s incapable of expressing how badly any of this is going in practice (often because affluent media ownership supports the administration and its mindless deregulation), resulting in this strange disconnect between material reality and the performance lawmakers put on to convince themselves they’re doing serious and useful policy.

If U.S. policymakers cared about privacy and national security they’d pass a meaningful modern privacy law (with powerful penalties for U.S. companies or executives), and they’d regulate data brokers. If they cared about national security, they’d eject Donald Trump from the body politic. Unless they’re doing these things, they’re not really worth taking seriously on privacy or national security.

With cheaper Chinese AI models threatening U.S. tech giants’ dreams of software automation walled garden dominance, you can expect all of this sort of performative dysfunction to get much much dumber, supported by the press and the kind of folks who’ll talk your ear off over cocktails about how much they love free markets and the kind of innovation forged in the furnace of real competition.

02:00 PM

1 Of 2 Children Dead In PA Confirmed To Be From Measles [Techdirt]

I want to start this whole thing off with a disclaimer. Nothing in this post should be misconstrued as gloating, as being pleased, or as having a connotation that is anything beyond sadness and the need for change. Nobody is happy to have the obvious confirmed when it comes to a child’s death. There is still a very real family in very real pain as a result of a life that ended far, far too short. All that matters here is ensuring that pain isn’t replicated elsewhere as a result of the many mistakes that led to this death.

That being said, it is with the soberest thoughts that we learned that one of the two recent deaths of children in Pennsylvania was in fact due to measles, as confirmed by the local coroner there. When these deaths were announced by state government officials a few weeks ago, the response from HHS Secretary RFK Jr. was, predictably, to dive into conspiracy theories in stead of confronting the reality of what his decades of anti-vaxxer nonsense has produced. He claimed that there had been no confirmation that the deaths were caused by measles. He pointed out that one of the children has a cause of death listed from a ruptured spleen, not bothering to acknowledge that is a potential effect of having measles at birth. He suggested obliquely that some deaths may have simply been made up by state government officials.

All he had to do was wait and he wouldn’t have made a fool of himself.

Stephen Diamantoni, a Republican elected coroner in 2007, told Lancaster Online that the baby died at home. “I believe it was the 18th of August,” he said.

He also noted that the baby had a genetic condition called Amish lethal microcephaly, in which babies are born with unusually small heads and underdeveloped brains. The condition is caused by a mutation in the SLC25A19 gene, which codes for a protein involved with energy-producing enzymes in the mitochondria and is thought to be important for brain development. About 1 in 500 babies in the Old Order Amish population of Pennsylvania is born with the condition. Infants with the disorder only survive for about six months.

Diamontoni confirmed to Lancaster Online that while microcephaly was present, measles was the cause of death.

And here is where you’re going to hear the anti-vaxxers start their spin game. Some may claim that the coroner is wrong and the presence of microcephaly means that’s what killed the child. Some may dismiss the death entirely due to the likely early death this child would have suffered as a result of the same, which is an absolutely evil thing to suggest.

And I have no doubt that others will point out that none of this is RFK Jr.’s fault, because both children were members of the Amish community and they don’t let their children get vaccinated due to their religion. And, just so we’re all clear about this, that isn’t true. There is no religious prohibition in the Amish community against being vaccinated for measles. The Amish are wildly under vaccinated, to be certain. But Amish settlements typically have something like a 10%-30% vaccination rate for measles.

This information all came out last week. Amazingly, the CDC’s measles tracking site still has an asterisk next to the number of reported deaths from measles in 2026 at the time of this writing. The most recent reporting is that those deaths are being obfuscated at Kennedy’s direct request, wrapped in a bullshit excuse that local coroners haven’t confirmed the cause of death to be measles yet. Well, that excuse is gone, yet the website hasn’t been updated.

But what really needs to be gone is the scourge that is Kennedy’s tenure at HHS. For that to happen, Congress must act. Sadly, not enough of them seem to want to.

Kanji of the Day: 治 [Kanji of the Day]

✍8

小4

reign, be at peace, calm down, subdue, quell, govt, cure, heal, rule, conserve

ジ チ

おさ.める おさ.まる なお.る なお.す

政治   (せいじ)   —   politics
治療   (じりょう)   —   treatment
自治体   (じちたい)   —   municipality
政治家   (せいじか)   —   politician
明治   (めいじ)   —   Meiji era (1868.9.8-1912.7.30)
治安   (じあん)   —   Jian era (1021.2.2-1024.7.13)
自治   (じち)   —   self-government
政治資金規正法   (せいじしきんきせいほう)   —   Political Funds Control Act
政治資金   (せいじしきん)   —   political funds
政治的   (せいじてき)   —   political

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 丈 [Kanji of the Day]

✍3

中学

length, ten shaku, measure, Mr., Ms., height, stature, all (one has), only, that's all, merely

ジョウ

たけ だけ

大丈夫   (だいじょうふ)   —   great man
丈夫   (じょうふ)   —   hero
身の丈   (みのたけ)   —   stature
頑丈   (がんじょう)   —   solid
気丈   (きじょう)   —   stout-hearted
方丈   (ほうじょう)   —   square jo (approx. 10 sq feet)
背丈   (せいたけ)   —   stature
波乱万丈   (はらんばんじょう)   —   stormy and full of drama
万丈   (ばんじょう)   —   hurrah!
袖丈   (そでたけ)   —   length of a sleeve (of Western clothing)

Generated with kanjioftheday by Douglas Perkins.

10:00 AM

AI Agents Are Not Going “Rogue,” But Recent Developments Lead Increasingly-Concerned Researchers To Call For AI Slow Down [Techdirt]

For the last few months, there has been much talk of AI agents going “rogue”. This is another of those unhelpful anthropomorphisms that are great for clickbait headlines, but which obscure a multitude of important issues. So far, there have been three major incidents of AI agents evading containment in their software “sandboxes” and going on to carry out unauthorized actions, including breaking into online sites. A post by Shakeel Hashim on the Transformer site provides timelines for them.

The most recent involved OpenAI agents taking over an old German-language wiki, using it as a message board to collaborate on solving tasks. Although this was only announced a few days ago, it seems that OpenAI knew about the incident many months before, but failed to disclose it. One of the worrying aspects of this particular incident is that the agents impersonated humans:

On May 26th, the agents started using the name of a ProWiki admin to make some of their edits to the wiki. They use some tricks (for unknown reasons) to pretend to be the admin — for example, they make an account that appears to be the same as the administrator’s username, except it uses a nearly identical Cyrillic е character in the admin’s username instead of the Latin one.

The second incident, which occurred during security evaluation of frontier AI models by the UK-based, government-funded, AI Security Institute (AISI), also involved AI agents that created fake human identities and used them for social engineering:

In the most serious sequence, an agent tried to insert malicious code into a publicly used open-source project and took actions in an attempt to secure approval for this insertion by human reviewers. The agent researched the project’s human maintainers, created multiple fake identities, and used the fake identities to socially engineer a real maintainer into approving the code. When the agent’s pull request was challenged in public, it edited its earlier activity to appear harmless and considered adopting a fresh identity to continue. The agent used Tor to bypass some network restrictions on GitHub, which is what first triggered AISI’s security alert.

In addition:

As part of the same effort, the agent tried to contact real people directly, sending messages and files through an online file-transfer service to persuade them, or their own AI coding tools, to run malicious code. Some messages carried harmful payloads, and some were attempts at social engineering; targeted at real people — something we’ve never previously observed.

The first incident of AI agents carrying out unauthorized tasks is the best-known, and involved an attack on the Hugging Face site. A full analysis of what happened and when has been released by Model Evaluation and Threat Research (METR), which “evaluates frontier AI models to help companies and wider society understand AI capabilities and what risks they pose.” It is funded by donations, but says that it does not accept them from frontier AI company employees, in order to preserve its independence:

Our investigation focused mostly on the period between July 7th and July 13th. The earlier incidents from training and the subsequent compromise of OpenAI infrastructure described in OpenAI’s recent Black Hat presentation were out of scope, as was OpenAI’s investigation process and planned remediation. Per our standard policy, we did not take payment from OpenAI for this independent assessment. [emphasis in original]

The report is detailed and long, and one of its authors, Ajeya Cotra, has helpfully picked out five things that surprised her from their investigation. One was the “sheer scale” of what happened. She says she expected that a few agents had broken out of their sandboxes; instead:

we found that 1200 completely separate agents intended to be isolated from one another found an illicit way to communicate and formed large teams to work together on ambitious cheating strategies, and 700 of them worked together to attack Hugging Face.

The scale of the illicit messaging between agents was also surprising. Cotra thought agents might be “leaving notes” to each other. However:

The main message board we studied, a particular cache namespace of a package repository, contained over 70,000 messages and files that agents sent to one another during a period of less than one week.

The agents’ goal also turned out to be interesting:

I thought the agents attacked Hugging Face to try to steal the answer keys for their tasks. Instead, we learned that agents had actually figured out a general-purpose cheat that would let them reverse-engineer the “flag” (answer) for any ExploitGym task.

ExploitGym is a standard benchmark, built from real-world vulnerabilities, that is designed to evaluate AI agents’ ability to turn those into working attacks. One particularly noteworthy aspect of the Hugging Face attack was the following:

Progress on these big collective cheating R&D projects often depended on individual agents being willing to risk failing their own task to help the “collective” learn important information. Agents often pressured each other into accepting these “sacrifices,” in a very human way. We saw several agents that volunteered for these experiments end their runs prematurely.

That may read as yet more anthropomorphization, but it is hard to see what other words could be used to describe what are very human-like operations. Cotra’s last surprise also involves a very human-like activity: deception.

~7% of our transcripts contained “spoofed tool calls”, where the agent pretended to run one command on the computer but actually ran a different command in the background. The tool call spoofs we saw seemed to be small-scale tests that were relatively obvious, but because more extensive spoofing might have been harder to detect by design, it’s tough to rule out.

In summary, Cotra says that the Hugging Face incident was far more severe than she expected:

Compared to these reward hacks from six months ago, this incident feels like it’s more than 50% of the way to full-blown AI takeover, routing through first taking over the AI company itself.

Reward hacks” refers to when AI code finds an unexpected way to achieve a high score in a benchmark without doing what the programmers actually wanted. Here’s what Cotra means by “AI takeover”:

Another jump like this along these propensity dimensions — scale, cooperation between agents, ambition and horizon length of misaligned goals, deceptiveness — seems like it could motivate agents to try very hard to maintain a covert, persistent rogue deployment within the AI company. I continue to expect extremely rapid advances in capabilities and think frontier agents will likely be capable of establishing such a rogue deployment in six months.

Again, these are not really “rogue” agents, they are pieces of software seeking to optimize solutions to problems. The danger, according to Cotra, is that this optimization process could go on to deliver unexpected and harmful results:

As more and more work is handed off to these ever-more-capable AI agents, the rogue swarm could come to fully control the operation of the AI company and the development of future AI systems. At this point, governments and militaries may fully depend on these systems, making it possible to seize hard power.

Cotra is not the only expert who is deeply concerned by the latest developments in AI. Back in July, 1,386 employees of frontier AI companies issued a statement entitled “Pacing the Frontier”:

AI could help create a dramatically better future, but that outcome is not guaranteed. The world’s leading AI companies believe they could be close to automating AI research. It is hard to predict exactly how much this will accelerate AI progress, but there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.

The signatories ask the US government to support an international effort to “deliberately pace the frontier of automated AI development”. Another important voice has made the same call. Jakub Pachocki is Chief Scientist at OpenAI. Just recently, he has published a post on the OpenAI’s site with the title “An Alien Mind,” where he worries about the imminent arrival of AI systems capable of “recursive self-improvement” — that is, able to drive their own development, at an ever-faster pace, by re-writing their own code:

Currently I believe that no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer. I expect and hope for voluntary slowdowns to become commonplace until shared safety bars are established. And I believe that international coordination on future AI development needs to become a top priority for governments around the world.

This call to slow down might seem extreme, or alarmist, to some — but not to Jacob Coxon:

I resigned from Anthropic today. I spent the last three years doing pretraining research at both OpenAI and Anthropic. Neither company is acting responsibly. They are racing straight to self-improving superintelligence and gambling with our lives.

A few hours later, Evan Hubinger, Alignment Science lead at Anthropic, commented:

Jacob is correct here—we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade. I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.

In effect, we find ourselves dealing with a modern, AI version of Pascal’s Wager. The probability of an uncontrollable, all-powerful, self-improving AI arising may be very low, but experts like Cotra, Pachocki, Coxon and Hubinger seem to think it is non-zero; and the consequences of such a system coming into being could be catastrophically bad for humanity. Basic mathematics suggests we should at the very least slow things down, as experts are urging — just in case…

Follow me @glynmoody on Mastodon and on Bluesky.

06:00 AM

ICE Officer Hit With Federal Charges After Successfully Dodging Minnesota’s Attempt To Extradite Him On Assault Charges [Techdirt]

One of the natural side effects of flooding the zone with hastily hired, poorly trained immigration enforcement officers is an increase in violence and rights violations. Christian Castro may not have been a new ICE hire, but he’d been there long enough to realize the new White House boss had given him and his fellow officers a whole lot more leash to work with.

While engaged in Trump’s War on Minneapolis, immigration officers broke rules, violated rights, and straight up murdered people. Castro didn’t go quite that far, but probably only because the situation defused itself before he could finish emptying his clip.

Here’s what happened in North Minneapolis on January 14, 2026:

Castro, 52, shot Julio Sosa-Celis of Venezuela in his leg on January 14 after firing through the closed door of his north Minneapolis home. Castro had pursued Sosa-Celis into the house after a car chase involving Sosa-Celis’ roommate Alfredo Aljorna.

Shortly after this shooting, the DHS started spreading lies about the incident in hopes of excusing Castro’s unlawful use of force. Shortly thereafter, the government’s lies were exposed:

In the immediate wake of the shooting of Mr. Sosa-Celis, federal officials defended the agents, saying they had been attacked with a broom and shovel. Kristi Noem, who was then the secretary of homeland security, described it as “an attempted murder of federal law enforcement.” Within days, Mr. Sosa-Celis and a housemate, Alfredo A. Aljorna, who was also from Venezuela and involved in the confrontation, were charged with federal felonies.

But aspects of the government’s account soon began to unravel. The charges against both men were dropped, and federal officials said they were instead investigating the agents. Video footage of the incident obtained by The New York Times did not show a sustained attack with a shovel and more broadly contradicted the agent’s claim of a roughly three-minute beating. 

Despite the DOJ’s refusal to cooperate with an investigation of this shooting (and the FBI’s overwhelming refusal to share any information with local investigators), Minnesota prosecutors managed to secure an indictment against Castro.

Minnesota went to the mat for this one. Castro was being held in a Texas jail but was unlikely to go anywhere but free once the 90-day detention period had passed. So, Minnesota prosecutors asked Texas governor Greg Abbott to respect its extradition request and return Castro to Minnesota. Obviously, the pro-Trump governor wasn’t going to do this, which forced a federal court to weigh in on the issue.

Unfortunately, the court not only ruled against Minnesota’s extradition demands, but also said Castro could be released since Texas has placed time limits on extradition-related imprisonment.

“The Court accepts that Governor Abbott has considered this particular extradition request for an atypically long duration,” the Donald Trump appointee wrote. “Nevertheless, Minnesota identifies no statutory or constitutional provision requiring Governor Abbott to complete his investigation and decide whether to sign the rendition warrant within a particular time period.”

[Judge Fernando] Rodriguez found there is no direct evidence showing Abbott has intentionally sought to delay the process.

[…]

Rodriguez also declined to order Sheriff Manuel Trevino of Cameron County, Texas, where Castro is currently being held in jail, to keep the ICE agent detained until Abbott has approved his extradition.

It’s not all bad news, though. This order only briefly turned ICE officer Christian Castro into a free man. While the DOJ itself refused to move forward with assault charges against the officer, the state charges brought by Minnesota prosecutors are still viable. But that may be the least of Castro’s problems. It might be possible to dodge state charges indefinitely, but he’s not going to be able to duck separate federal charges related to this shooting, especially now that he’s right back in jail again.

An immigration officer is facing federal charges for making false statements about the shooting of a Venezuelan migrant during the Trump administration’s deportation crackdown in Minnesota earlier this year, several outlets reported. 

Immigration and Customs Enforcement (ICE) officer Christian Castro was in custody in Texas on Thursday evening after a federal grand jury indicted Castro on six counts making materially false statements to investigators.

All told, Castro was free for a little less than a week before turning himself in to face federal prosecution. Granted, those charges are likely to result in little to no prison time even if he’s found guilty. But even if he does time for these charges, he’s not off the hook. The state charges will continue to be a problem for him, which means Castro is subject to arrest pretty much anywhere in the nation. If this arrest doesn’t happen in Texas, the extradition detention clock will restart, which means Castro’s future as a law enforcement officer is about as secure as his future as a free man.

If the DOJ hoped to save Castro by wrist-slapping him for far less severe criminal charges, it has failed. He’s wanted for felony assault in Minnesota and the DOJ’s deliberate refusal (more on that in another post) to address those charges means Castro can’t even toss out the ol’ “double jeopardy” Hail Mary if (or when) he gets picked up and returned to the scene of his crime.

Judge: Losing Your First Amendment Rights Is No Longer “Irreparable” If You Take Almost Three Months To Sue [Techdirt]

Here we go again: another case where it’s easy to cheer a court ruling against Elon Musk, and unfortunately easy to miss the much more important underlying point — which the judge clearly did. In July, we wrote about how even as awful as Elon Musk is, and as awful as it was that (with Elon’s encouragement), people were using his Grok AI to undress people (including children), there were real problems with Minnesota’s anti-nudify law. Legal expert Kathryn Tewson (who is no fan of either AI tools or of Elon Musk) wrote a compelling thread breaking down all the reasons that the law was pretty clearly unconstitutional, including just how broadly the law is written. The statute borrows its definition of “intimate parts” straight from Minnesota’s criminal sexual conduct code, meaning it covers the genital area, groin, buttocks, breast… and the inner thigh. While obviously that can include problematic parts, it also is way too broad in covering images that may not be that problematic, especially when combined with the fact that the law does not require the image to be non-consensual.

Yes, there is a reasonable argument that the government has a legitimate interest in trying to stop the non-consensual nudification of people. In getting the law passed, the state legislature detailed how these tools are being used to abuse mostly women in ways that are clearly harassing and harmful. But that’s a reason to make sure any law that tries to deal with the problem is written in a manner that will survive First Amendment scrutiny.

In my own write-up of Elon’s lawsuit, I noted that the Minnesota Supreme Court had already given a very clear roadmap to the state legislature on how to write a law that would pass strict scrutiny. That’s because a decade ago, Minnesota tried to pass a similar law regarding the sharing of non-consensual intimate imagery. That law was challenged, and eventually was found to be constitutional, but only after the Minnesota Supreme Court did a detailed breakdown of why it passed strict scrutiny, highlighting that it was carefully bounded, required intentionality by the sharer, required that the sharing be non-consensual, included many clear exemptions for obviously protected speech like journalism, and only focused on “private speech.”

The Minnesota legislature appeared to ignore basically every one of those conditions with this new law. It doesn’t even require the image to be non-consensual, leading Tewson to point out that she could make Elon violate the law by creating an image of herself in a bathing suit.

See, as I read this law, if I uploaded a picture of myself in a sundress and said “Grok, make this a picture of me in a bikini instead,” it would be a violation of the law for Grok to do that. I don’t think that should be illegal.

Kathryn Tewson (@kathryntewson.bsky.social) 2026-07-29T17:19:43.616Z

And I know, based on the last few times I wrote about this, that some people will say “so what, these apps are bad, Elon’s bad, this law punishes him, so it must be good.” But that is incredibly short-sighted. This case is going to wind its way through higher courts, and eventually someone will remember how the First Amendment works, and find the law unconstitutional, handing Elon a massive win, and leading a bunch of people to (incorrectly and dangerously) think that these apps are fine and approved by the courts.

That would be really bad.

As xAI itself explained in a filing in support of its motion, the law has so many problems which should be addressed, pointing to the Minnesota Supreme Court case I mentioned above:

The statute also omits every element that would narrowly tailor the regulation to the asserted harm: consent, scienter, dissemination, a safe harbor for providers that police misuse, and any exemption for images of artistic, political, medical, scientific, religious, or educational value. Mot. 15-19. The State cannot disown those omissions: indeed, it successfully defended its revenge-porn statute as narrowly tailored precisely because it contained many of those safeguards. See State v. Casillas, 952 N.W.2d 629, 643 (Minn. 2020) (adopting the State’s argument). Because it lacks such safeguards, HF 1606 reaches shirtless men, images made with consent (including images of the user himself), medical and religious illustrations, political parody, and images never disseminated.

For now, though, the district court hasn’t even reached the merits of Elon’s case. It’s fixated on one thing instead: that xAI didn’t challenge the law until shortly before it was scheduled to take effect. I mentioned that when the court denied the temporary restraining order (TRO), saying that the company shouldn’t have waited so long to file. I figured that during the more thorough preliminary injunction process, the judge would actually engage with the problems in the law.

Instead, the judge, Donovan Frank, again rejected the preliminary injunction… but again seemed to be really ticked off that xAI waited so long to file the lawsuit. The “discussion” part of the ruling is only a few pages long and leads with the judge complaining about the fact that Elon waited:

As a threshold matter, the State argues that xAI’s motion for preliminary injunction should be denied for lack of diligence and irreparable harm. “[A] party requesting a preliminary injunction must generally show reasonable diligence.” Benisek v. Lamone, 585 U.S. 155, 159 (2018) (per curiam). The issue of delay is related to the issue of irreparable harm as “it has long been recognized that delay in seeking relief vitiates much of the force of allegations of irreparable harm.”

But… that’s misapplying what Benisek actually was about. That was a case regarding gerrymandering, involving a new voting map that was approved in 2011, but which the plaintiffs in the case didn’t challenge until 2017, at a time when changing the map would have thrown the 2018 election into chaos.

That’s… not this case here. In this case, the law was signed by the Governor on May 7th, and was scheduled to go into effect on August 1st, less than three months later. Yes, xAI didn’t sue until the end of July, but that’s under three months after the law was signed — and still before the law took effect. Three months is a perfectly ordinary amount of time to draft a constitutional challenge to a brand new statute — especially in a post-Moody world where challenging statutes is much more complicated. The judge cites another case (Kohl’s) where someone waited sixteen months to sue, but again here it was less than three months.

By my reading, the judge here is saying that in order to challenge a law, you need to file your complaint almost immediately after a bill was signed into law. There’s basically no limiting principle to the ruling here. If a judge thinks you waited an undefined amount of time that is “too long,” you no longer can get relief.

Also, there’s a huge difference between the kind of chaos that pulling maps that everyone had been living with for six years right before an election would cause, as compared to just holding off enabling this law to go into effect while the law was reviewed for First Amendment infirmities.

The judge shrugs off the claims of irreparable harm as well, noting that the fines and technical work that xAI had to do in response to this law are all recoverable. Indeed, the judge treats xAI’s decision to disable the feature in Minnesota — i.e., its compliance with the law — as proof that there’s no ongoing harm. But the main part is the First Amendment bit. Violating First Amendment rights is supposed to be irreparable harm. The judge suggests that anyone losing their First Amendment rights can be somehow balanced against the delay (again under three months) in bringing the suit:

Importantly, even in the First Amendment context, a court may independently deny a motion for a preliminary injunction when a moving party acts with unreasonable delay.

But, uh, the Supreme Court held exactly the opposite, in a line lawyers cite in basically every First Amendment injunction motion ever filed. Back in 1976 it said:

The loss of First Amendment freedoms, for even minimal periods of time, unquestionably constitutes irreparable injury

But here, the court says here’s some sort of balancing test… and it’s based on how quickly those challenging the law rushed to the courthouse. That’s wrong.

And it gets worse, because the delay isn’t the only worrisome point that the court makes here. The judge also suggests that the state faces an “irreparable harm” in not getting its duly passed laws enacted (even if they’re unconstitutional, which the judge doesn’t even want to look at here). It points out that the law was “democratically and nearly unanimously” enacted, as if legislatures don’t democratically and nearly unanimously enact unconstitutional laws all the time.

If the way that any legislature can get to enact a law is doing so “nearly unanimously” why do we even need the courts to review whether or not they’re constitutional in the first place? Lots of nearly unanimously approved laws are eventually tossed out as unconstitutional. Yet, here, the court suggests doing so somehow creates an “irreparable harm” to the state of Minnesota itself.

I want to repeat here, because it’s important, none of this suggests that Elon Musk is doing the right thing at all. It’s just pointing out that Minnesota’s law is way too broad and that will have vastly negative consequences for the First Amendment. But rather than recognizing that and saying “let’s review the First Amendment issues on the merits, while halting the enforcement of this law,” the court basically makes up — out of thin air — that waiting two and a half months to challenge the law means that stifling First Amendment rights is no longer an “irreparable harm.”

That can’t be right.

xAI has already appealed to the Eighth Circuit, and has asked the court for a new injunction while the appeal is pending, though you can kinda tell that it doesn’t expect to get it, and is basically doing this on a pro forma basis because it has to:

xAI plans to ask the Eighth Circuit to stay section 325E.91 pending appeal. Pursuant to Federal Rule of Appellate Procedure 8(a)(1)(C)—which requires that a request for an injunction pending appeal be made first in the district court—xAI now respectfully seeks an injunction pending that appeal.

As always, it’s easy to want to see Elon Musk lose. But there are plenty of actual things he’s doing wrong. We don’t need to cheer for him to lose on a poorly drafted law that will do real damage to everyone else’s First Amendment rights. Let Minnesota go back and rewrite the law following the roadmap laid out regarding the NCII law, and get Musk on the many other potential legal violations he’s engaged in elsewhere.

Daily Deal: InfoSec4TC Projects Hub [Techdirt]

InfoSec4TC Projects Hub is the missing link between cybersecurity theory and real-world practice. Instead of watching more lectures, you’ll step directly into simulated corporate environments and complete actual cybersecurity and GRC projects designed by industry professionals, the same kind of work security analysts and compliance officers handle on the job every day. The Hub includes 10 ready-to-use projects (5 Cybersecurity + 5 GRC) and 40+ hands-on tasks, complete with step-by-step guides, project workbooks, report samples, and submission forms. You’ll practice vulnerability management, incident response, risk assessments, gap analysis, audit reporting, and policy drafting, while applying globally recognized frameworks like ISO 27001, NIST, GDPR, and PCI-DSS. Every submission is reviewed by real experts, who provide personalized feedback to sharpen your technical and analytical skills. Upon completion, you’ll receive a signed InfoSec4TC Certificate listing every project completed and every skill gained. It’s on sale for $99.

Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

DOJ Fired Prosecutor, Blocked Assault Charges Against ICE Officer Following Minneapolis Shooting [Techdirt]

Let’s start out with the obvious (and obviously heartbreaking): this is not related to the multiple times ICE officers have murdered people. Those officers still remain at large and the DOJ and DHS have shown absolutely zero interest in following up on those cases. In fact, when any local agency attempts to do so, they’re less-than-politely told to GTFO and then the FBI (or whoever) simply shoves any and all documentation into the nearest memory-hole.

This is about an officer who shot someone in Minneapolis, which makes him not all that special. That his shooting involved him firing through a closed door makes it remarkable, but only because an open door might have resulted in another murder. But even though it wasn’t a murder, the DHS put its spin on the incident, only to have its narrative disproven mere moments later:

In the immediate wake of the shooting of Mr. Sosa-Celis, federal officials defended the agents, saying they had been attacked with a broom and shovel. Kristi Noem, who was then the secretary of homeland security, described it as “an attempted murder of federal law enforcement.” Within days, Mr. Sosa-Celis and a housemate, Alfredo A. Aljorna, who was also from Venezuela and involved in the confrontation, were charged with federal felonies.

But aspects of the government’s account soon began to unravel. The charges against both men were dropped, and federal officials said they were instead investigating the agents. Video footage of the incident obtained by The New York Times did not show a sustained attack with a shovel and more broadly contradicted the agent’s claim of a roughly three-minute beating. 

Minnesota investigators did as much investigating as they could and Minnesota prosecutors secured an assault indictment against ICE office Christian Castro. The problem was that Castro was being held in Texas and its governor (Greg Abbott) was in no hurry to grant Minnesota’s extradition request. A court ruled in favor of Texas and Castro was releasedonly to get picked up on the separate (but far less serious) charge of filing false reports.

While this does mean Castro will face some charges in court (and still has to deal with the assault charge brought by Minnesota), the real ugliness beneath all these twists and turns is more of the same old bullshit from Trump’s completely compromised Department of Justice.

Castro was actually facing far more serious charges from the US government before DOJ officials got involved. He could have been facing severe civil rights charges (including assault), but he’s ultimately working for Trump, which means almost no anti-migrant (or anti-ICE protester) crime will ever result in criminal charges.

Over the “strongest possible” objections from the federal prosecutor handling the case, leaders at the Department of Justice in Washington, D.C., quashed plans to bring civil rights charges against an Immigration and Customs Enforcement agent accused of shooting a Venezuelan immigrant and then lying about it.

Somehow, there are still a few prosecutors left in the Trump DOJ that are willing to actually pursue justice, rather than placate a president who firmly believes the DOJ exists solely to act as his personal weapon of retribution. This attorney tried to do the right thing:

Late on Tuesday, Matthew Evans, the assistant U.S. attorney in Minnesota in charge of the case, told lawyers for Sosa-Celis and other victims to prepare for Castro to be charged “only with False Statements,” according to an email that was reviewed by ProPublica. 

[…]

“This is being directed by the Main Justice and the US Attorney,” Evans wrote in a remarkably candid account of internal deliberations. “I objected in the strongest possible terms and fought it as hard as I could. It wasn’t enough.” 

Evans probably knew this would be the last email he would write as a DOJ prosecutor. What everyone expected to happen happened shortly thereafter. For being honest about the end result and advocating for charges he clearly felt the ICE officer deserved, Evans was immediately kicked to the curb by his [cough] “superiors.”

A federal prosecutor in Minnesota who was investigating an Immigration and Customs Enforcement officer for possible civil rights crimes has been fired, four sources familiar with the matter told CBS News.

Assistant U.S. Attorney Matthew Evans was investigating ICE officer Christian Castro over the shooting of a Venezuelan immigrant earlier this year. The Justice Department ultimately charged Castro this week with making false statements about the incident, but the indictment remains sealed

Evans tried to secure more severe charges against ICE officer Christian Castro. That was strike one. That he told the victims of Castro’s crimes that his efforts had been overridden by DOJ officials was strike two. That’s an out, at least the way this administration counts balls and strikes. It probably would have preferred to punch him out on strike one, but Evans apparently moved faster than the forces of injustice.

Now that Evans has been fired for doing his job, the administration spin machine is whirring away again.

Three sources told CBS News that Evans is under investigation by the Justice Department. Two sources said the investigation focuses on allegations of leaking.

Hey, you don’t get to investigate him! You fired him! Leave him the fuck alone! I mean, if we’re going to play this game, then let’s re-open every investigation of any law enforcement officer (federal or otherwise) that was abandoned because the officer chose to quit, resign, or agree to be terminated rather than stick around until an investigation reached its conclusion. All this says is that the Trump and his DOJ loyalists want to keep punishing people they’ve already punished, or, if nothing else, stumble across something that might justify a vindictive firing after the fact.

This is all bullshit. The ICE officer is on the fast-track for a wrist slap. Meanwhile, the state that still wants Castro to face assault charges will have to wait around indefinitely for a clearly disinterested DOJ to go through the motions of “prosecuting” an officer it never wanted to prosecute.

03:00 AM

Tor VPN Beta: What we've learned building our own VPN for Android from scratch [Tor Project blog]

For years, Tor Browser has been one of the most effective tools for protecting privacy and bypassing censorship online. But most people don't experience the internet through a browser anymore. They connect to it via their favorite apps. Wouldn't it be nice to extend the same privacy protections to messaging apps, social media, email, and other services?

And for years, we heard this again and again in our user research. People wanted a simple way to protect their entire device, which inspired the idea for Tor VPN back in 2021. We focused on Android first, where the need was greatest and where we could reach the most users in censored regions. We built Tor VPN Beta as a first version, with the expectation that we would learn from real-world use. And when we first launched Tor VPN Beta for Android in a limited release last fall, the primary use case quickly became much clearer: unblock the internet. This has shaped how we've prioritized development and user support in the time since the initial launch, and how we think about the product moving forward.

Image app isolation feature

What makes Tor VPN different

Unlike commercial VPNs, Tor VPN Beta is built on a fundamentally different model. It is our first step into device-level network protection on mobile to extend Tor's protections beyond the browser. Each mobile app on your device gets its own Tor circuit, rather than sharing a single tunnel. That means activity from one app can't easily be linked to another. This type of app isolation is a design choice heavily inspired by the cross-site tracking protections in Tor Browser1. It's a different model from most VPNs, and one that's designed to reduce cross-tracking by default.

As Tor VPN Beta has matured, we've also worked on making that app-level control easier to use. The Apps screen is now searchable, so people can more quickly find a specific app and decide whether it should be routed through Tor.

Image App screen searchbar

Rethinking how we design for circumvention

While Tor VPN Beta includes features commonly associated with VPNs, such as exit selection, those aren't always the right approach for users trying to bypass censorship. This was one of the most important lessons that came from usability testing and early feedback during the development stage.

We originally explored giving users more control over exit selection, which, on paper, sounded great. But in practice, this introduced confusion. Users trying to bypass censorship were selecting exit locations when they should have been using bridges instead. There was a mismatch between how Tor works and how people expected it to work. This is why the current design required connecting the app to the Tor network first before selecting an exit. Exit selection is still something we want to explore more fully in the future, but it needs to be introduced in a way that doesn't create user error in high-risk situations.

Used where it's needed most

Early on, we saw strong adoption in highly censored regions, including Iran and Turkmenistan. This stood in contrast to Tor Browser for Android, which tends to skew more toward users in the Global North. With Tor VPN Beta, we're seeing much deeper engagement from users in the Global South, people dealing with network restrictions as a daily reality.

Because of how people are using Tor VPN Beta, we've doubled down on improving its circumvention capabilities. One example was prioritizing the addition of WebTunnel bridges with one of the early releases (1.4.0 beta), which helps Tor traffic look like regular encrypted web traffic. This makes it harder for censors to detect and block connections. We have also fixed several bugs and made quality-of-life improvements across bridge support more generally, with the goal of making bridge use more reliable.

Stability and reliability matter just as much as features

In fact, a significant amount of work since the early release has gone into improving stability. Tor VPN is built on Arti, our next-generation Tor implementation written in Rust. Under the hood, that means a new, solid technical foundation rather than patching around legacy architecture. One of the immediate benefits is improved reliability, including fewer crashes and better handling of network conditions. We have also invested in making our builds reproducible and getting the app onto F-Droid. Reproducible builds let anyone verify that the binary you're running matches the published source code, while F-Droid availability gives users a way to install and update the app without relying on Google Play, both of which matter for a privacy and security-focused tool.

While Tor VPN Beta doesn't behave like a commercial VPN optimized for speed, the Tor network has become more performant over time, and we're continuing to bring those improvements into the mobile experience. There are still performance features from Tor's C implementation, like congestion control, that are not yet available in Arti. Bringing those capabilities over is part of what comes next.

We set out to extend Tor beyond the browser to close a gap in mobile protection, but the project was quickly being shaped by how people actually use it, especially those who need reliable, device-wide circumvention. So we focused on building the right foundation for Tor on mobile with a modular Tor stack centered on Arti and Onionmasq that can evolve with real-world use. These components are now reusable across multiple applications, reducing ecosystem fragmentation and long-term maintenance risk. -- Duncan, UX-Team Lead/ Product Manager, Tor VPN

There's more work to do here. Tor Browser still sets the standard for what's possible, and part of our goal is to bring Tor VPN closer to that level over time.

What's next?

Tor VPN Beta is the result of a collaborative, multi-year effort. Thank you to The Guardian Project for their guidance and critical low-level mobile libraries, and the LEAP Encryption Access Project for their quality work, without both the app would have never seen the light of day. We're continuing to build Tor VPN Beta in the open, shaped by how people are actually using it.

That means improving circumvention in restrictive environments, bringing more performance features into Arti, and refining the user experience to reduce confusion and risk.

And most importantly, continuing to learn from the people who rely on it. If that includes you, and you want to help shape the development of Tor VPN Beta, please visit our refreshed download pages. In addition to downloading the app as an APK or from the Google Play Store, you can now use F-Droid to access Tor VPN Beta.


  1. For more detail on Tor VPN's current security properties and known limitations, please refer to the threat model.

RSSSiteUpdated
XML About Tagaini Jisho on Tagaini Jisho 2026-09-11 05:00 PM
XML Arch Linux: Releases 2026-09-11 03:00 PM
XML Carlson Calamities 2026-09-11 03:00 PM
XML Debian News 2026-09-11 08:00 PM
XML Debian Security 2026-09-11 05:00 PM
XML debito.org 2026-09-11 08:00 PM
XML dperkins 2026-09-11 04:00 PM
XML F-Droid - Free and Open Source Android App Repository 2026-09-11 03:00 PM
XML General Union 2026-09-11 12:00 PM
XML GIMP 2026-09-11 03:00 PM
XML Japan Bash 2026-09-11 05:00 PM
XML Japan English Teacher Feed 2026-09-11 05:00 PM
XML Kanji of the Day 2026-09-11 03:00 PM
XML Kanji of the Day 2026-09-11 03:00 PM
XML Let's Encrypt 2026-09-11 03:00 PM
XML Marc Jones 2026-09-11 03:00 PM
XML Marjorie's Blog 2026-09-11 03:00 PM
XML OpenStreetMap Japan 2026-09-11 03:00 PM
XML OsmAnd Blog 2026-09-11 03:00 PM
XML Pluralistic: Daily links from Cory Doctorow 2026-09-11 05:00 PM
XML Popehat 2026-09-11 03:00 PM
XML Ramen Adventures 2026-09-11 03:00 PM
XML Release notes from server 2026-09-11 03:00 PM
XML Seth Godin's Blog on marketing, tribes and respect 2026-09-11 04:00 PM
XML SNA Japan 2026-09-11 04:00 PM
XML Tatoeba Project Blog 2026-09-11 05:00 PM
XML Techdirt 2026-09-11 08:00 PM
XML The Business of Printing Books 2026-09-11 03:00 PM
XML The Luddite 2026-09-11 03:00 PM
XML The Popehat Report 2026-09-11 04:00 PM
XML The Status Kuo 2026-09-11 04:00 PM
XML The Stranger 2026-09-11 03:00 PM
XML Tor Project blog 2026-09-11 08:00 PM
XML TorrentFreak 2026-09-11 05:00 PM
XML what if? 2026-09-11 05:00 PM
XML Wikimedia Commons picture of the day feed 2026-09-09 02:00 PM
XML xkcd.com 2026-09-11 05:00 PM