News

Friday 2026-07-24

04:00 AM

New Alpha Release: Tor Browser 16.0a9 [Tor Project blog]

Tor Browser 16.0a9 is now available from the Tor Browser download page and also from our distribution directory.

This version includes important security updates to Firefox.

⚠️ Reminder: The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.

Moreover, Tor Browser Alphas are now based on Firefox's betas. Please read more about this important change in the Future of Tor Browser Alpha blog post.

If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the stable release channel.

It's ESR transition season again!

Well actually, it has been ESR transition season throughout this entire release cycle! As described in the aforementioned Future of Tor Browser Alpha blog post, we have been incrementally rebasing our Alpha channel on Firefox betas since December of last year. As a result, we now stand before you with Tor Browser 16.0a9 which is based on Firefox ESR 153.

We will continue rebasing Tor Browser 17.0 Alpha branches on Firefox betas throughout the remainder of the Tor Browser 16.0 release cycle. However, new feature-work for now must be put on hold for a few reasons:

  • We must focus our attention on resolving our Bugzilla Audit issues to ensure the features we have inherited from upstream comply Tor Browser's threat model and to patch any changes which do not.
  • Feature work targeting 16.0 stable would need to be cherry-pick'd onto our 17.0 Alpha branches to ensure we don't lose any work. The more invasive a feature patch is, the harder it will be to port to newer versions. This would also be a potentially error-prone process and there is some risk we would lose patches along the way.
  • We need to finish stabilizing as soon as possible as we have hard external deadlines which cannot be moved: the end-of-life of Firefox ESR 140 on October 13th and the Google Play Minimum Target API Level requirement on November 1st

Challenges and Triumphs

💍 Sharing the Load

Rebasing the hundreds of Tor Browser patches onto newer versions of Firefox is a challenging task. It is like maintaining the structural stability of sand-castle at high-tide with the waves crashing all around you.

As such, it quickly become clear early in this new process that we would need to do something if we wanted to avoid burning out the few developers typically involved in this work. To mitigate this, we shared the knowledge internally and spread the work out across all eight members of the team. This way, each developer was only responsible for at most two or three rebases throughout the entire release cycle.

🎨 UI Code Churn

Over the past year, Firefox has developed and integrated two major changes to the UI in Firefox: a redesign of about:preferences in Firefox Desktop and a migration from Material 2 to Material 3 in Firefox Android.

Adapting to these types of changes to the frontend are typically rather time-consuming for us, as many (if not the majority) of our patches modify Firefox's UI in some way. For example, we have an entire preferences page on Tor Browser desktop dedicated to configuring how the browser connects to the Tor Network. On Android, we similarly have various additions to the menus, configuration options, and custom UI.

Whenever Mozilla modifies their design systems and Firefox's user interface, we necessarily have to adapt our own custom additions to match. Otherwise, our Tor Browser-specific UI elements would look completely out of place and potentially confuse users (as well as simply looking unprofessional). Therefore, each of these upstream changes requires collaboration with the Tor Project's UX team to update our features' designs and of course development time to implement.

In addition to the time-cost associated with the extra engineering and UX collaboration, very often our old patches simply do not apply cleanly due to the amount of code which has changed. For example, the about:preferences changes on Firefox Desktop are essentially a complete re-write which means we also have to completely re-write our own settings changes without regressing in functionality.

On the plus side, one benefit of our new processes is that we have been able to spread out this work over the entire release cycle. In the past way of doing things, we would have discovered all UX elements which needed to be fixed, updated our designs, and re-implemented in the course of a few months during the old ESR transition season. Under this new way of working, we have been able to incrementally fix things throughout the development cycle.

The benefits of working this way does not just apply to UX of course. It is much easier to find regressions across the entire stack when rebasing between one major Firefox version at a time instead of across 12 or 13. It is also much easier for developers to fix individual regressions one at a time compared to diagnosing, disentangling, and fixing multiple bugs concurrently (divide et impera!).

⚙️ Pending Google Target API Level Requirements

Every year, Google requires new Android app releases to target an updated minimum API level. This means, we would not be able to upload new versions of Tor Browser Stable past a certain date (usually August 1st with an extension to November 1st typically possible) without first updating the app to support the new minimum target API level. Fortunately, we inherit most of the required changes from Mozilla when rebasing to the next major ESR.

However, this requirement does impose a hard deadline for the absolute latest we can responsibly stabilize Tor Browser Alpha and promote it to Stable. We've been fortunate in the past few years to make the deadline with a few days to spare (October 28th for Tor Browser 15, October 22nd for Tor Browser 14, etc). Given how far ahead of the curve we are this year, we are hoping to release about a month earlier in September (fingers crossed!).

🤖 Android APKs too big

The Google Play Store has a strict size limit of about 100 megabytes for Android applications. New functionality added to Firefox Android over the past year means a larger application which results in new headaches for Tor Browser developers. This release cycle was no exception to this rule and we have had to get creative with our size reductions.

In the past, we have been able reduce our package size though various methods including:

Our most recent effort has been the most invasive yet! For some background, the Firefox application consists of (among other things): various shared libraries, the Firefox executable, a library known as 'xul' which contains most of Firefox's natively compiled functionality, and finally a file known as omni.ja. This omni.ja file is a zip archive which contains the JavaScript, HTML, images, and other assets used in Firefox.

This time around, to reduce the size of our Android package we havechanged how this archive is compressed. We modified the Firefox build system to compress this archive with xz and we modified Firefox itself to decompress this archive at runtime. This work did require a few iterations to get right. In the end, we got back about 3 megabytes with these changes and got us once again under Google's imposed size budget.

📉 Even Less Telemetry

Over the years, we have worked to incrementally remove dependencies from Tor Browser Android as part of the aforementioned size reduction work. We of course inherit most of these dependencies from Firefox Android and unfortunately some of them can be labeled as 'trackers'. While we do disable telemetry by default at runtime, the code which implements it remains in the codebase.

We're happy to report that as of Tor Browser 16.0a8, are down to only 1 'tracker' library in the Tor Browser Android codebase: Mozilla Telemetry. Again, this telemetry is disabled at runtime, but this is one more unused dependency which we can hopefully remove in the future (and maybe get some more bytes back!).

Current Status

We have:

  • incrementally rebased Tor Browser and Tor Browser for Android to Firefox ESR 153 from Firefox ESR 140
  • updated the build systems with the latest dependencies and fixed a few reproducibility issues
  • triaged most of the upstream changes from the past year and flagged over 250 issues for further review (triaging of Firefox 153 is in progress)
  • resolved about half of these triaged issues

For the remainder of this release cycle, we will be focusing on auditing these issues and fixing bugs until the 16.0 alpha series is ready to become Tor Browser Stable 16.0. We are optimistically targeting a September release, which would put us one month ahead of schedule compared to last year.

Known Issues

🦊 Firefox Branding

In some places in the browser there may be Firefox branding (e.g. logos, cute little foxes, etc) instead of Tor Browser branding. We're currently tracking one known instance in tor-browser#44998. If you discover any other instances lurking about, please open an issue!

🌐 All websites marked 'insecure' on Tor Browser Android

Currently, the identity block in the URL bar on Tor Browser Android will always report insecure (e.g. a shield icon with a slash through it). For now, you can tap this icon and verify the certificate manually. This issue is being tracked in tor-browser#45115

Send us your feedback

Now is a great time to become an alpha tester! If you find a bug or have a suggestion for how we could improve this release, please let us know.

Full changelog

The full changelog since Tor Browser 16.0a8 is:

Government Lawyers Say Trump Admin Can Use TikTok Again Because ‘Owned’ No Longer Means ‘Owned’ [Techdirt]

We spent a few years pointing out the ridiculousness of the whole “TikTok ban” moral panic, and the fact that all of the “concerns” magically melted away after Trump became president and then effectively gifted a controlling stake to some of his friends should raise some pretty big questions. However, most people seem to have accepted the new arrangement without much fuss — even though ByteDance still retains a 19.9% stake in the company, and users at no point needed to switch to a brand new app, continuing instead to use the very app we were told was a security nightmare. All of which suggests the entire moral panic was absolute bullshit.

Either way, prior to the full “ban” that forced further ownership into the hands of Trump’s friends, there was a separate law from Senator Josh Hawley which simply banned TikTok on government devices. That law is still in effect. It’s pretty clear that it applies to “the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.” It’s also clear that such an application is not allowed on any government devices, with exceptions only “for law enforcement activities, national security interests and activities, and security researchers.”

Now, a plain reading of the law would suggest that the current app is still banned. The law is still in place. ByteDance still owns a significant stake in the new “US joint venture” and the app is absolutely a “successor app” since users never needed to download a new app after the joint venture was established.

But, the Trump administration apparently would like to use TikTok on their devices. So, they’ve had the Office of Legal Counsel put out a decision claiming that, you know, ownership doesn’t really mean ownership and that the Trump administration can ignore the law and start using TikTok on their devices again. First things first, we discover that because Josh Hawley wrote a stupidly drafted law that directly called out “TikTok,” the OLC has to first tap dance around the fact that the law’s clearly named “TikTok” apparently doesn’t mean this TikTok, even though that’s exactly what the statute says:

Blackletter statutory-interpretation principles illuminate which particular “TikTok” Congress sought to prohibit. It is old wisdom that “a general phrase can be given a more focused meaning by the terms linked to it.” Fischer v. United States, 144 S. Ct. 2176, 2184 (2024). Namely, “the canon of noscitur a sociis teaches that a word is ‘given more precise content by the neighboring words with which it is associated.’” Id. at 2183 (quoting United States v. Williams, 553 U.S. 285, 294 (2008)). We apply this rule to “avoid ascribing to one word a meaning so broad that it is inconsistent with its accompanying words, thus giving ‘unintended breadth to the Acts of Congress.’” Gustafson v. Alloyd Co., 513 U.S. 561, 575 (1995) (quoting Jarecki v. G.D. Searle & Co., 367 U.S. 303, 307 (1961)). And precisely that kind of unexpected breadth would ensue here, were the Government Ban understood to apply to any future social networking platform based on its name alone.

[….]

We have considered the counterargument that, under the Dictionary Act, “words importing the singular include and apply to several . . . things,” 1 U.S.C. § 1—thus indicating that the Government Ban’s use of the phrase “the social networking service TikTok” could denote multiple unrelated variations or iterations of social media companies named TikTok. But the Dictionary Act itself provides that its general prescriptions do not apply when “context indicates otherwise,” id., and context does so in this case. “In context[,] the phrase ‘[the social networking service TikTok]’ should not be interpreted to mean literally ‘any [social networking service called TikTok],’ but must be understood against the background of what Congress was attempting to accomplish in enacting the [Government Ban].” Gustafson, 513 U.S. at 575 (cleaned up) (quoting Reves v. Ernst & Young, 494 U.S. 56, 63 (1990)). Here, the plain text of the Government Ban indicates Congress was attempting to address a particular national security threat posed by the presence on federal government devices of software “developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.” Government Ban § 102(a)(1), 136 Stat. at 5258. TikTok USDS thus is covered by the ban only if it, like the version of TikTok operative when the ban was passed, falls into that category of software.

Call me pedantic, but if Congress didn’t want to ban an app “based on its name alone” maybe they shouldn’t have drafted and then passed a law that banned an app based on its name alone. And if Congress thinks that the new TikTok is somehow safer, they should repeal the original, poorly drafted law. Instead, the OLC has to start asking “what is ownership, really, other than a concept”?

For three reasons, we conclude that “ownership” in the context of the Government Ban is best understood as referring to a controlling stake, such that TikTok USDS falls outside the prohibition’s scope.

First, the “control” sense of the word “own” is most “consistent with the way that an appropriately informed speaker of the language would understand [that term’s] meaning” in the specific context of corporate structure. Van Buren v. United States, 141 S. Ct. 1648, 1657 (2021) (quotation marks omitted). The United States is home to “large numbers of firms with widely dispersed share ownership.” Henry Hansmann & Reinier Kraakman, The End of History for Corporate Law, 89 Geo. L.J. 439, 443 (2001). But it would be unusual for someone to say that a person or even an institutional investor “owns,” for example, Meta, simply because the investor holds some of its stock. Cf., e.g., Van Buren, 141 S. Ct. at 1657 (“In the computing context, ‘access’ references the act of entering a computer ‘system itself[.]’”). Instead, in the corporate context, we generally recognize Mark Zuckerburg as the “owner” of Meta because he retains control of the company through so-called “super-voting” shares. See Nathan Reiff, Top Facebook (Meta) Shareholders, Investopedia (Mar. 21, 2026), https://perma.cc/XQ6V-ZNTT; Gregory H. Shill, The Social Costs (and Benefits) of Dual-Class Stock, 75 Ala. L. Rev. 221, 224 & n.6 (2023).

So, hear me out, if Josh Hawley and Congress meant for the law to only apply if ByteDance “controlled” the company, then it could have (and arguably should have) written that into the law. But they did not. They said ownership. And that mattered because, technically before the “divestiture” and new US “joint venture” Western investors already owned about 60% of ByteDance, with employees and ByteDance’s founder holding most of the rest. The goal of the various laws to ban TikTok was to get ByteDance out of owning any of the company.

And that didn’t work. But we all have to pretend this “fixed” things, so the OLC just says “eh, because US entities now control it, we can ignore the law and pretend it said “control” rather than “own.”

Our textual interpretation is confirmed by the facts on the ground, which indicate that the TikTok USDS joint venture is wholly controlled by American interests as a functional as well as a formal matter—and thus exhibits none of the concerning security features that initially motivated the Government Ban. As our prior advice to you highlighted, if facts did not bear out that conclusion, then our understanding of “ownership” as used in the Government Ban could be called into question. But where, as here, the facts demonstrate that ByteDance Limited’s status as a minority shareholder in the joint venture has no impact on the exercise of control over the venture by United States investors, the inference runs the opposite way. Congress had no need to target minority ownership by ByteDance Limited in the Government Ban because that state of affairs is wholly compatible with the joint venture “operat[ing] [TikTok USDS] under defined safeguards that protect national security.”

Of course, all this really does is confirm Calvinball rules: the definitions change exactly as often as it takes to get the outcome someone in power wants. When “ownership” needed to mean any ByteDance stake to justify a ban, it meant that. Now that the administration wants TikTok back on its phones, “ownership” apparently means “controlling stake,” and 19.9% doesn’t count.

The real lesson here appears to be that the earlier concerns were exaggerated. Josh Hawley and Congress wanted to get headlines about how they were “taking on China” and “big tech” more than they wanted to write a clear law. They had a moral panic about one specific app, dressed up in national security language, and now that the political winds have shifted, the Office of Legal Counsel is left doing contortions to make the text say what the moment requires.

Daily Deal: The Modern No-Code Development Bundle [Techdirt]

The Modern No-Code Creator Bundle is an extensive online curriculum specifically developed to enable individuals to construct professional websites, applications & automated workflows without the necessity of writing any code. It has five courses, covering leading no-code platforms and tools like ChatGPT, Mendix, and Tabnine. It is ideally suited for novices and non-technical professionals, empowering users to successfully launch digital products independently of developer assistance. It’s on sale for $20.

Note: The Techdirt Deals Store is powered and curated by StackCommerce. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

03:00 AM

Industrialism and the slippery slope [Seth Godin's Blog on marketing, tribes and respect]

One of the best traditional bakeries in New York has a kitchen you can see from the counter. People wait in line for their handmade French baguettes, and the confirmation that they were made right here and right now is reassuring.

I noticed that the baker was using a mechanical gadget called a loader. It allows her to place and shape six baguette onto a board, and load them into the oven all at once.

It’s hard to imagine anyone being disappointed by this. It’s still the same loaf, still handmade, but like the electric mixer they use to knead the dough, it seems to be part of the authentic process, not an industrial one.

The challenge is in what happens next…

Mechanized scale brings productivity and certainty, but it also brings huge short-run rewards for cutting corners. Save a penny a loaf with a handmade product and it’s not big deal. Save a penny a loaf when you make 10,000 a day and it begins to add up to real money. So it pays to add a bit of stabilizer, change to a more reliable oven temperature and switch to a cheaper flour…

This is what people who care about quality are actually fretting about. It’s not the scale. It’s the shortcuts that sometimes come with it.

Quality, by definition, is meeting spec. If you don’t like the spec, make the spec better.

We can have scale and consistency and quality. But we can’t have all three at the same time when we race (or are pushed) to the bottom.

Bit by bit, we either make things better or we make them worse.

      

The Man Bearing Trump’s False Flags [The Status Kuo]

I’m writing for The Big Picture substack today. If you watched or even just heard about Trump’s address to the nation last week around election security, you likely concluded it was a nothingburger: just another bunch of rehashed election conspiracies with no evidence to back them up.

I thought the same—until I saw an interview of the man behind the declassification of the relevant intelligence. When I did, my heart sank a little.

John Solomon is more than just a right-wing reporter. He’s currently deployed inside the White House and charged with spinning up narratives that will drive official policy. It’s the same playbook Solomon used to gin-up other political stories that received strong initial traction despite having zero factual support.

That spells trouble ahead for the November midterms as Solomon plants false flags to justify extreme action by the White House over our elections, including voting machines and ballots.

Today’s piece is underreported elsewhere and not to be missed. If you’re already a subscriber to The Big Picture, where I write once a week, look for it in your inboxes later this afternoon. If you’re not yet a subscriber to it, you can sign up for free or as a valued paid supporter here:

https://thinkbigpicture.substack.com/subscribe

I’ll be back tomorrow with my regular Status Kuo piece.

Jay

02:00 AM

ICE Illegally Scooped Up Medicaid Data, Then Shared It With Palantir [Techdirt]

The Trump administration’s continual trend towards maximum awfulness means that every report seems to be “I’ve got bad news and I’ve got worse news.” What was already bad has become even worse now that more of the administration’s actions have been exposed during court proceedings.

Last July, the Trump administration unilaterally decided ICE should have access to Medicaid data for the sole purpose of locating migrants to arrest and deport. That much was made clear by the administration itself, which said the data would give ICE officials better tools to discover “the location of aliens.” An agreement was reached with the Centers for Medicare and Medicaid Service by the DHS because of course that happened. The administration had already purged plenty of non-loyalists, which meant those remaining wouldn’t put up much of fight.

There was no legal basis for this demand, which is why the headline says “illegally.” If this was a legal request, we wouldn’t be seeing lawsuits challenging the sharing of this sensitive medical data because the law would already be settled. Specifically, ICE wanted access to Medicaid data that exposed “home addresses and ethnicities.” Not exactly subtle, but nothing ever is with this grotesque shotgun of an administration.

But this sharing was challenged in court, and that converts that bad news to worse news. Not only did ICE have access to information it wasn’t legally entitled to have, but its private contractors did too, as NPR reports:

After Medicaid officials improperly shared data about millions of people in January with immigration officials, ICE then shared that data with the data analytics firm Palantir, according to new court filings. Palantir operates an app called ELITE that is used by ICE agents to show the addresses of noncitizens who may be subject to deportation.

That revelation was made public in a motion filed Thursday by more than 20 Democratic attorneys general who sued the Trump administration last year over its data-sharing agreement between the Centers for Medicare and Medicaid Services and ICE.

Palantir’s thirst for data is constant. And it will take anything its government customers choose to give it, including information that has been obtained illegally.

Palantir issued a couple of statements in response to this reporting based on courtroom revelations in ongoing lawsuits.

First, it said that the data in question had been “purged.” That’s great if true, but this seems like something that needs verification before trust because who knows where else this data set ended up before court orders blocked the government from using this data. If you think only ICE was peeking into this illicitly obtained data, you’re awarding the government the good faith it not only hasn’t earned, but has spent pretty much every minute since Trump’s election actively destroying.

ICE’s surveillance tech contractor also said this:

Palantir provided the following statement to NPR: “Our customers control their own data and manage access to that data. When Palantir employees are granted access to a customer’s dataset, it is solely to help integrate and analyze that data — which is what our software does — not to store it or use it for our own purposes. Palantir can confirm that the dataset in question was purged pursuant to government instruction.”

Well… I’d like to believe this much in the same way I’d like to believe a system of checks and balances is capable of constraining a rogue regime, much less its private contractors who are not subject to these particular restraints.

I believe Palantir to the extent that its employees aren’t just surfing waves of incoming data for their own personal reasons, but I find it extremely difficult to believe that a belated “purge” has actually scrubbed the data and removed any ancillary… well, let’s call them “infections.” Without turning over evidence of this purge to the courts, it’s easy to say it’s all been handled, even if the only thing that happened what Palantir deleting the source CSVs (or whatever) from its system, which isn’t the same thing as stripping it from Palantir’s databases.

Another reason for high levels of skepticism is this: ICE somehow couldn’t stop itself from passing this illegally obtained data to Palantir despite (apparently) trying to comply with a court order.

In a court filing last week, the Justice Department said that CMS again inadvertently reshared with ICE the dataset with millions of names that CMS had first improperly shared with ICE in January. The government said the error occurred during an effort to share data from states not involved in the lawsuit.

You see the problem, right? Because not every state sued over this illegal data collection, ICE continues to collect data that should — at this point — be considered off-limits. The only reason it doesn’t is because some states (you know the ones) have decided they’ll do whatever it takes to ensure the administration gets to keep being openly racist.

Consequently, the data sets aren’t being sorted between racist/non-racist (or whatever the SORT term is), which means ICE continues to retain data it’s been ordered to delete and Palantir keeps getting handed data the government isn’t allowed to collect, much less distribute.

Then there’s the ultimate problem. No matter what’s happening here in the lower courts, the administration will continue to push for a resolution from the US Supreme Court. And the odds are about 6-3 that SCOTUS will say the government can do whatever it wants with whatever data it collects, ignoring years of precedent and administrative firewalls that are meant to protect US citizens (and residents) from being abused and surveilled by their government.

Thursday 2026-07-23

11:00 PM

Dem Texas AG Candidate Vows To Investigate Musk’s Starlink Grant Grift [Techdirt]

Last month I wrote a feature for The Verge exploring how Republicans had hijacked the Biden-era infrastructure bill to redirect billions of dollars away from next-generation fiber, and instead funnel it into the pockets of billionaires Elon Musk and Jeff Bezos — in exchange for congested, expensive, satellite broadband service they’d already planned to deploy.

The piece explored in detail how some communities, like several low-income areas of Louisiana, were all set to receive next-generation affordable fiber, before Republicans hijacked the program, redirected those funds to their top donors, then proudly declared “mission accomplished.”

While Republicans like NTIA boss Arielle Roth have tried to claim this hijacking has been a net improvement, the adjustments not only showered billionaire Trump allies with unneeded subsidies, it eliminated all the provisions in the program ensuring the resulting broadband was affordable or deployed equitably. Affordable fiber evenly deployed to everyone was, the public was informed, “woke.”

I’m going to be writing about the impact and reverberations for years.

Dems have, as per brand tradition, mostly flubbed the opportunity to highlight and message around this obvious corruption. There were a few good questions flung at Roth during a recent House telecom hearing (Rep. Troy Carter of Louisiana did a particularly good job pressing Roth), but by and large Dems haven’t capitalized on the opportunity to shame Republicans for their grift parade.

Enter aspiring Democratic Texas AG hopeful (and Dallas state senator) Nathan Johnson, who says he wants to take a closer look at Musk’s grants as part of his anti-corruption platform:

“I am not declaring that corruption was at work in this instance. I am saying that it sure looks like it,” Johnson said in an interview. “Public confidence in the bidding process has been undermined.”

His plan comes after Starlink received 99% of the state grants in a government program designed to improve rural broadband access. Johnson said the company received an estimated $110 million.

It’s not clear how far he’ll get, since the roots of the corruption extend federally to Howard Lutnick, Arielle Roth, and the NTIA. But state broadband offices also had to sign off on the grift and were tasked with doling out grant awards, so we’ll see what paper trails disclose.

Keep in mind: the money Musk and Bezos have received from this $42.5 billion grant program pales to what they could ultimately receive. As unnecessary wars, tariffs, inflation, and additional economic chaos unfolds, a lot of providers and states that planned to deploy multi-gigabit affordable fiber are expected to balk and default on their bids, opening the doors for billions more for Musk and Bezos to fill the gaps with “good enough” satellite service.

It’s worth noting that after redirecting billions to satellite, Republicans proclaimed that they’d “saved” $21 billion or so. There’s now an ongoing battle over what happens to these “non-deployment funds” Congress specifically earmarked for broadband access. There are some clear hints that Trump and friends are eager to pocket it for themselves if they think they can get away with it. Great stuff. Very populist.

As I’ve noted previously, while low-Earth orbit services like Starlink are great for folks completely off the grid (who can afford it), congestion and physics make it ill-suited to meaningfully address the lack of internet-access at scale in denser urban, suburban, or even some rural environments. It’s generally designed to be a niche gap-filling option you use after pushing fiber, cellular, and fixed wireless everywhere; Republicans are treating it like a magic bullet simply because Musk is involved.

As a flood of government-subsidized users jump on the Starlink network, existing congestion problems (see this recent study out of Penn State) are going to get worse, resulting in all sorts of annoying network management approaches (throttling of 4K video) you don’t see on higher-capacity fiber. The company has also been charging users fees of up to $1500 in high-capacity areas.

The problems with this approach will become more and more apparent to taxpayers over the next few years, at which point all the folks responsible will have moved on to other opportunistic grifts. It might be nice if Democrats aspiring for higher office kept corruption in the spotlight and remained laser-focused on accountability. It’s not like there’s a shortage of very clear targets of opportunity.

09:00 PM

Pluralistic: California's privacy obstacle course (23 Jul 2026) [Pluralistic: Daily links from Cory Doctorow]

->->->->->->->->->->->->->->->->->->->->->->->->->->->->-> Top Sources: None -->

Today's links



A hedge maze; out of its center rises the bear from the California state flag. Various human figures struggle to escape it. At the maze's entrance stands an agonized figure, reaching towards it.

California's privacy obstacle course (permalink)

Data brokers are a cancer. There's a direct line from the unrestricted collection, retention and processing of our data to a host of evils, from deepfake porn to phishing scams; from racial discrimination in hiring to ICE roundups of migrants; from targeted election interference to identity theft:

https://pluralistic.net/2023/12/06/privacy-first/#but-not-just-privacy

Why do data brokers exist? Because we let them. Congress hasn't passed a new federal consumer privacy law since 1988, when they made it illegal for video stores to disclose your VHS rentals. All other acts of consumer surveillance are legal. Data brokers spy on us for the same reason your dog licks its balls: because they can, and we don't stop them:

https://pluralistic.net/2026/03/10/ice-tech/#foreseeable-outcomes

Getting rid of data brokers wouldn't solve all our problems, but it sure would go a long way to solving many of them. Rather than legally requiring platforms to spy on kids (to exclude them from being targeted by platforms' algorithms), we could prohibit platforms from spying on anyone, including kids, meaning kids couldn't be identified (much less targeted) by algorithms or ads:

https://pluralistic.net/2026/06/23/destroy-the-village/#to-save-it

Data brokers produce mountains of raw material used for every form of scam and torture. It's data brokers who power the gig economy's "algorithmic wage discrimination" system, where nurses and other workers are offered less pay based on how much credit card debt they're carrying:

https://pluralistic.net/2024/12/18/loose-flapping-ends/#luigi-has-a-point

Banning data brokers would make great sense, which is why Biden's CFPB banned data brokers (only to have Trump un-ban them):

https://pluralistic.net/2025/05/15/asshole-to-appetite/#ssn-for-sale

So the feds (both Congress and the executive branch) have surrendered, and that leaves states alone on the battlefield fighting the privacy wars alone. State legislatures have taken some big steps, but – crucially – they've stopped short of banning data brokers from operating within their borders. Having taken a ban on data brokers off the table, states are left with complex, often unworkable "compromises" that go nowhere.

This is where DROP comes in. DROP stands for "Delete Request and Opt-out Platform," and it's a new phase of California's privacy regime that kicks off next month. Under DROP, you fill in some paperwork and then the state requires every data brokerage operating in California to delete your data, as well as any inferences they've made about you based on that data:

https://www.eff.org/deeplinks/2026/07/what-you-need-know-about-californias-drop-tool

Implementing DROP is nowhere near as good as banning data brokers. The idea that data brokers should be able to collect, retain and process your data unless you tell them not to implies that everyone starts off wanting to be spied on, and therefore data brokers should assume that unless they hear otherwise, we're delighted to be the subject of commercial surveillance. This is an incredibly stupid supposition, contradicted by all available evidence. For example, when Apple offered iPhone owners a one-click option to block Facebook from spying on them, 96% of iPhone owners clicked the button:

https://applescoop.org/story/facebook-must-inflict-pain-on-apple-says-mark-zuckerberg

Indeed, given this fact, one wonders why Apple bothers with the "don't spy on me" button at all. Why not have a "do spy on me" button that is unchecked by default, and leave users to dig through their settings to find the option to opt in to being surveilled? Of course, then it would make the fact that Apple spies on its customers and uses the data to target ads (with no way to opt out) a little awkward:

https://pluralistic.net/2022/11/14/luxury-surveillance/#liar-liar

In the absence of a ban on surveillance without explicit, opt-in consent, we are left with the bizarre fiction that most of us want to be spied on, a fiction that pervades the DROP process, making the entire procedure nearly impossible to complete.

To start the DROP process, you must first create a Login.gov ID. This is an incredibly invasive process that involves photographing multiple pieces of ID and taking several selfies using special apps and webpages that hijack your device's camera and processor in a bid to prevent bad actors from spoofing the process. There's a plausible reason for this rigmarole: Login.gov is the authentication system for multiple federal, state and local IT systems in the US, so a fake or stolen Login.gov ID could be used to access your IRS, Social Security, and other very sensitive accounts.

The corollary of this is the promise of Login.gov: once you create your ID (a lengthy, multi-stage process) you won't have to jump through lots of painful bureaucratic hoops to access a wide variety of government services.

DROP didn't get the memo.

After you log in to DROP via Login.gov, you are sent a text message – to the phone number in your Login.gov profile – with a link to access a "secure" website that takes over your camera to let you take a "secure" photo of the front and back of your California driver's license or your US passport. What if you don't have either of those? I guess that means you want to be spied on by data brokers.

Note that these are the same credentials you have to supply to get the Login.gov ID that you've just used to get to this step in the process. In other words, in order to get to the stage where they ask you to photograph your driver's license, you have to have already photographed and validated your driver's license.

Once you complete this (pointless, redundant) step, you're directed back to your computer, where the process continues. Here, you must fill in all kinds of biographical detail, as well as specialized pieces of information, including your car's VIN. This is a piece of information that most people don't have – but which the California DMV does have and could auto-feed into the system, given that you've repeatedly affirmatively identified yourself to the service.

You also have to provide your mobile advertising identifier, a long, unique number that you may or may not be able to extract from your phone, depending on the model and the OS version. If you can't get it that way, you can install an app like AAID, which comes with a long list of – you guessed it – permissions to extract, store and process your private information.

Here's the thing: the whole point of a mobile ad identifier is that apps can access it (this is how they identify and track you). That step, where the system made you switch to your phone and use your camera to photograph your driver's license? That step could have automatically pulled this data off your device. That's the whole fucking point of this exercise: that web-pages and apps can request your mobile ad identifier.

Instead, DROP wants users to dig through their phone's deepest settings and/or install an app to retrieve a 32-digit number, which they then must key into a webform on their computer or in a different app on their phone.

Once you've done this, you must fill in another page of biographical information, including information that you've already provided to Login.gov and information you've already filled in on previous screens.

On this screen, you must also verify your phone number by sending yourself a text and then pasting in a unique number the system sends to you. But remember how this whole thing started? The first step is that you authenticate with Login.gov, which sends a text to your phone so you can take a (redundant) picture of your driver's license. There is no way you could get this far in the process unless you controlled the phone number you've just "verified" with the system.

Next, you must verify your email address, by receiving an email with a unique code in it and keying or pasting that into the webform, too. Again, remember how this process started: with you logging in with Login.gov, using your email address, which the system has already treated as verified since the very start of this (very) long and (very) complicated process.

This whole thing is terrible, and it is predicated on the absurd premise that Californians have to be defended from the threat of strangers who pretend to be them in order to sneakily opt them out of surveillance. DROP requires stronger authentication than any other US government system I've ever interacted with. I file my tax returns with fewer authentication steps. I renew my car's DMV registration with fewer authentication steps. I became a US citizen with fewer authentication steps.

This is either a system with no coherent threat model, or (far more probably), its threat model is that people will use it. This is California's answer to "a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the Leopard'":

https://en.wikiquote.org/wiki/The_Hitchhiker%27s_Guide_to_the_Galaxy

It's especially instructive to compare this process to the steps you have to take in order to "opt in" to having a data broker open a file on you and stuff it full of your sensitive, personal information, which is then sold to all comers:

  • Step one: Exist.

  • Step two: There is no step two.

It's also instructive to compare this process to the steps a data broker has to take to spy on you and sell your data:

  • Step one: Exist.

  • Step two: There is no step two.

Though there are many obvious ways this could be made better, I want to stress here that you shouldn't have to do this at all. It's entirely backwards. The process for not being spied on should look like this:

  • Step one: Exist.

  • Step two: There is no step two.

If anyone is going to be forced to jump through hoops to participate in the mass collection and catastrophic mishandling of private data, it should be the data brokers, not the people they spy on.

This kind of malicious compliance is the inevitable outcome of a process that starts by taking the obvious best measure off the table. The answer to the problem of data brokers is banning data brokers, not creating a demented hairball of form-filling that maintains the fiction that data broker surveillance is consensual.

In its own way, this process reminds me of the whole "carbon credit" fiasco. The answer to too many carbon emissions is to democratically decide to ban certain kinds of carbon emissions. But that would require states to do things, rather than simply "nudging" a process that is guided by "the market." So we end up with these junk "credits" that companies manufacture by promising not to log forests, many of which are already wildlife preserves and/or subsequently burn down:

https://pluralistic.net/2023/10/31/carbon-upsets/#big-tradeoff

The best critique of this whole thing came in 2021 from the Climate Ad Project, who produced a short video in which people were allowed to kill one another provided they purchased "murder offsets":

https://pluralistic.net/2021/04/14/for-sale-green-indulgences/#killer-analogy

In a state of nature, murder exists. We, as a society, have decided this is bad. Rather than creating "incentives" not to murder, we just banned murder. Admittedly, we still get some murders, but when these happen, we don't treat it as "a mispricing of the anti-murder incentive" – we treat it as a crime.

The commercial surveillance industry may not be a criminal enterprise (yet), but it is the source of a torrent of crime, a flood of crime, a tsunami of crime. Every piece of your information that a data broker possesses exposes you to the risk of being victimized by a criminal. For this reason, I strongly believe that you should go through the tedious, performatively difficult DROP process:

https://consumer.drop.privacy.ca.gov/

But let's not pretend that this is good – or even adequate. There is no demand for being spied on. There is no basis for taking such enormous care in making sure people aren't maliciously removed from surveillance databases. If these databases exist at all (they should not), then we should make spies go through all this paperwork, to prove that you do want to be spied on, and unless they manage it, then spying on us should be treated as the crime it is.


Hey look at this (permalink)



A shelf of leatherbound history books with a gilt-stamped series title, 'The World's Famous Events.'

Object permanence (permalink)

#20yrsago Continuous Partial Attention wiki https://web.archive.org/web/20060806014946/http://continuouspartialattention.jot.com/WikiHome

#10yrsago Congress: TSA is worst place to work in USG, nearly half of employees cited for misconduct; it’s getting worse https://web.archive.org/web/20160721120714/https://www.cntraveler.com/stories/2016-07-14/almost-half-of-all-tsa-employees-have-been-cited-for-misconduct

#1yrago Trump's FCC abandons the future https://pluralistic.net/2025/07/24/geometry-hates-cars/#dogshit-unit-economics


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, pounding the podium.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027

  • "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027

  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Colophon (permalink)

Today's top sources:

Currently writing: "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

  • A Little Brother short story about DIY insulin PLANNING

This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, possible tracking and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.

ISSN: 3066-764X

Canada’s ‘Expanded Scope’ Blocking Order Targets Existing and Future Pirate Sites [TorrentFreak]

logosCanada’s approach to pirate site blocking has evolved quite a bit since the Federal Court issued the first ‘GoldTV’ order in 2019.

That original order targeted a specific service and a fixed set of domain names. If rightsholders wanted to add a domain to the blocklist, they had to go back to court.

Later orders against Soap2Day and, more recently, various stream-ripping sites, went a step further. Instead of targeting specific operations run by the same people, they allowed rightsholders to update the blocklist with alternative domains that would pop up, as well as copycats of the already named brands.

These new orders streamlined the site blocking process. Rightsholders no longer had to file a new case for every domain that popped up. They did, however, still have to go back to the Federal Court, which had to issue a new order before anything new could be blocked.

Rightsholders say these types of blocking orders are needed to effectively curb piracy. However, they are not without criticism. Opponents including the Canadian ISP TekSavvy have previously complained that site blocking is a slippery slope, where more sites might eventually get blocked with less oversight.

Hollywood Seeks Broad Blocking Order

Thus far the global trend has indeed been to expand blocking powers and the latest Federal Court order, issued earlier this month, is no exception.

The blocking order, requested by Rogers, TVA, Netflix and various Hollywood studios such as Disney and Warner Bros., targets thirteen named piracy brands. This includes existing domain names, but also any future domains that use the same brands, whether these are linked to the original operation or not.

The order requires Canadian ISPs, including Bell, Rogers, Telus, and TekSavvy, to block an initial list of 18 domains and subdomains. It is also the first Canadian blocking order to cover both IPTV subscription services and public streaming sites in a single proceeding.

The Canadian Blocking Order

suit

The order splits its targets into two groups. Six are IPTV subscription services: Apollo Group TV, Diablo IPTV, GLO TV, IPGuys, Jio TV, and Smart4K/Platinum. The other seven pirate streaming sites are 123Movies, Cineby, FMovies, HydraHD, Putlocker, TheTVApp, and WatchSeries.

The initial blocklist

schedule1

After the first site blocking order survived several appeals, there hasn’t been any significant opposition from ISPs to the follow-up orders. That also applies here, as the most recent blocking order was approved without any notable pushback.

Schedule 1 lists 13 domains and five subdomains. With more than 50 million global monthly visitors, 123moviesfree.net is one of the prime targets. However, the value of this order lies less in what it blocks today than in what it can block tomorrow.

The Catch-All ‘Expanded Scope’ Order

The blocking order adds a new feature which is framed as an “Expanded Scope.” Earlier Canadian orders reached a single brand and its copycats. The latest blocking order goes further, as it also covers “similarly infringing platforms operating under other brands.”

This effectively means that the movie studios and other rightsholders can add new pirate sites and services to the blocklist. Justice Southcott agreed that this is needed to deal with the piracy whac-a-mole problem where new pirate sites swiftly take the place of blocked ones.

“[W]hen access to infringing platforms is blocked, other similarly infringing platforms appear and/or increase in popularity,” the order reads.

To justify the expansion, Justice Southcott looked at a recent UK High Court order, described as an “omnibus order,” which we covered in May. According to the Motion Picture Association, which represents its member studios in site blocking efforts, this order makes it possible to block any “structurally infringing audiovisual piracy service” without naming it in advance.

The UK judgment itself has still not been published on BAILII or the National Archives, as far as we know, but it is clearly seen as the new frontier in site blocking efforts.

Adding New Brands

The order explains how new brands are added through what it calls a “Simplified Procedure.” To add a platform, rightsholders must file an affidavit which confirms that the new target meets the order’s conditions.

In this case, it means that the target’s sole or predominant purpose is the unauthorized distribution of the studios’ film and television works, that it operates like the IPTV or open-web services already named, that it is reachable in Canada, and that the operator was sent a notice of infringement and given seven days to respond.

Some of the conditions

conditions

If no targeted ISP files a notice of motion to object within five business days, the updated list takes effect without any hearing and no further order from the court. These new submissions can be made every ten business days.

That last part is a subtle but notable change. Under the stream-ripper order issued last month, ISP silence meant the Court “may grant an Order amending Schedule 1 as proposed by the Applicants without further proceedings.” A judge still signed off, even if nobody argued.

Under the new order, silence alone is enough. The proposed list “shall be considered Schedule 1 under this Order,” with no involvement from the court at all.

Together, the two changes remove both limits that applied before. The court no longer has to sign off on blocklist updates, and the additions no longer have to involve a brand that was already named in the case.

Justice Southcott describes this as “an incremental modification to precedent site-blocking orders.”

A Judicial Guardrail

Justice Southcott did not grant everything the studios asked for. The rightsholders wanted the new order to also apply to “any works for which the Applicants own the copyright.”

The order limits its scope to “the Applicants’ Works,” meaning the specific titles mentioned in the judgment. In practice, that prevents the studios from using copyrights they acquire later to justify new additions, without first going back to court.

Not everyone is convinced that the safeguards go far enough.

TekSavvy, which previously fought back against site blocking in Canada, published a critical compliance page for the order. While the company did not oppose the current order, it remains highly skeptical.

“[W]e see blocking orders as a grave violation of network neutrality and a fundamental change to what we do as an ISP. The principles of common carriage and network neutrality mean ISPs carry traffic to and from end users in as neutral a fashion as possible,” TekSavvy notes.

The latest order runs for two years, with the blocklist starting at 13 domains and five subdomains. The more telling figure may be how many names get added before it expires.

A copy of the site-blocking order, issued by Justice Southcott, is available here (pdf). The full domain list can be found here (pdf).

From: TF, for the latest news on copyright battles, piracy and more.

07:00 PM

New Release: Tails 7.10 [Tor Project blog]

New features

New shutdown procedure

Tails now uses the standard shutdown procedure from GNOME.

The standard shutdown procedure is a bit slower, but better prevents data loss.

For example, the Power Off confirmation dialog informs you if an application needs to be closed or an open document needs to be saved before shutting down.

Even without confirming or saving the open documents, Tails will shut down after 60 seconds.

You can still use the faster emergency shutdown as before.

Celluloid video player

We replaced GNOME Videos with Celluloid , a more modern and reliable video player.

For added security, Celluloid cannot access the network. You can either:

  • Open online videos, like MP4 and AVI files, in Tor Browser.
  • Open online streaming addresses, like IPTV and HLS addresses, in VLC , installed as additional software.

Celluloid doesn't work on some computer from 2011 or earlier.

You can use VLC instead, installed as additional software.

Changes and updates

  • Update Tor Browser to 15.0.19.

  • Update some firmware packages. This improves support for newer hardware: graphics, Wi-Fi, and so on.

For more details, read our changelog.

Get Tails 7.10

To upgrade your Tails USB stick and keep your Persistent Storage

  • Automatic upgrades are available from Tails 7.0 or later to 7.10.

  • If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade.

To install Tails 7.10 on a new USB stick

Follow our installation instructions.

The Persistent Storage on the USB stick will be lost if you install instead of upgrading.

To download only

If you don't need installation or upgrade instructions, you can download Tails 7.10 directly:

Support and feedback

For support and feedback, visit the Support section on the Tails website.

04:00 PM

Screen Time Guidelines For Kids Is Changing As Research Paints A More Nuanced Picture [Techdirt]

This article is republished from The Conversation under a Creative Commons license. Read the original article.

Concerns surrounding young people’s screen time are widespread.

Australia became the first country to ban social media for users under 16 in December 2025, and DenmarkFrance and the U.K. have since announced similar restrictions to begin this year.

In the U.S., as of mid-2026, more than 30 states have passed laws banning or restricting cellphones in K–12 classrooms; in 2023, the U.S. surgeon general issued a formal advisory on social media and children’s and adolescents’ mental health; and bestselling books tell parents that smartphones are “rewiring” their children’s brains.

These concerns and policies are part of a quickly changing national and international conversation around how young people spend time on screens and its relationship to their overall health and development. My reading of the mounting research on this issue across disciplines is that the popular narrative blaming screens and smartphones for an adolescent mental health crisis runs well ahead of the current evidence.

I study adolescent digital media use and its influence on social, emotional and academic outcomes. A growing body of research suggests that one-size-fits-all solutions are not the answer and that managing appropriate use of digital media needs to take into account a child’s developmental milestones, how parents and adults around them use media, and the ways kids use it to connect and learn with friends and family.

Screen time: From monolith to multifaceted

Wide adoption of digital media and the internet broadened the range of experiences young people could have online. At the same time, the digital age introduced newfound uncertainties. As with the advent of radio, comic books and arcades, adults worried about how children might interact with or be affected by internet use.

In response, the American Academy of Pediatrics first recommended in 1999 that parents and caregivers keep children under 2 away from screens. In the decades since, professional guidance largely treated children’s media use as a behavior to be mitigated.

Policies introduced by the academy in 2013 and 2016 continued to advise that school-age kids and adolescents – those ages 5 to 18 – be restricted to no more than two hours of “entertainment” screen time a day. The goal was to curb risks associated with heavy media use, among them disrupted sleep, online safety, cyberbullying and physical inactivity.

Originally created for young people’s engagement with stationary media that tend to be confined to one room or context – for example, watching television – these hourly limits became outdated with the integration of smartphones and other digital devices into everyday life. Compared with watching television, online media was far more difficult to track and define, and more nuanced in its use.

Developmentally beneficial activities such as educationsocializing and leisure have come to rely on the internet to extend and maintain face-to-face connections. Remote schooling and social distancing during the COVID-19 pandemic only accelerated this digitization of daily life.

In my view, adopting strict time limits and restrictions could pose risks to children’s well-beingautonomy and development, for example, by harming adolescent self-esteem.

The latest guidelines

In January 2026, the American Academy of Pediatrics retired its decade-old framework that had largely organized its advice around hourly screen limits. The new policy statement on children, adolescents and digital media diverges from this blanket approach. Instead, it suggests parents consider the larger picture in which this media use exists rather than lumping all screen use together.

Similar to the World Health Organization’s 2019 guidance for children under 5, the American Academy of Pediatrics still advises that parents avoid screen media for children younger than 18 months. This recommendation is largely because extended use by children by themselves can be problematic for many young children, crowding out important developmental milestones.

Both the World Health Organization and the American Academy of Pediatrics also recommend that when children under 24 months use screens, they should be limited to content and devices that encourage children and caregivers to interact. For ages 2 to 5, screen time – including TV and interactive apps on devices – may be extended to more solo use, provided it’s high-quality digital media designed around learning goals in mathematics and reading. But recreational use should be limited to roughly an hour per day.

For school-age children and teens, the newest guidance has begun to step away from fixed screen time limits and asks families to weigh online activity in the context of everyday life.

Doing so recognizes that a child’s digital experiences are shaped by diverse factors rather than the hours spent online. Current guidelines call on caregivers to distinguish among types of media, from television and social media to video games and interacting with artificial intelligence chatbots. They also call for taking into account a child’s individual characteristics, such as their interests and personality, family members’ own use of screens, and the type of content children are spending time on.

Rethinking screen time

Moving beyond strict screen time limits includes questioning the kind of digital activities kids and adolescents participate in. Do the activities encourage time spent interacting with others online, which can help young people develop important skills and competencies?

Scrolling an algorithm-based, auto-playing video feed likely does not equate to the same opportunities as video-chatting with friends, creating digital art or working with teammates in a multiplayer game. Research suggests these different uses relate to development in different ways and can help kids develop varying skill sets pertaining to everyday life and schooling.

Indeed, a large review of current research found that young people who take part in a range of digital activities, such as browsing the web, online gaming or interacting on social media, show positive associations with social connection, identity exploration, civic participation and learning.

Using these guidelines at home

The current evidence suggests parents and caregivers are best positioned to be digital instructors. Cutting children off altogether can carry its own risks for social and emotional development. Caregiver mediation of children’s screen time can produce widely different outcomes and effects, depending on whether the guidance is supportive or controlling.

Considering your own digital media use is the first step: Are family members engaging in problematic or heavy media use that children in the household might emulate? What applications and uses are most common in the family, and what positive or negative effects might they have, depending on the child’s age? How could these digital activities be safely integrated with other everyday experiences to increase their benefit for children? Conversely, what online time might be better spent on face-to-face experiences?

The American Academy of Pediatrics’ Family Media Plan tool turns these ideas into concrete questions. For example, it recommends working out what each child needs from digital technology, what activities screens might be crowding out, and where their family or household can build in screen-free time. The recommendation is to talk with each child about why they are drawn to particular apps or online activities, what they encounter while browsing, and what might be lost when kids bring phones to gatherings such as mealtimes.

The debate over young people’s screen time is not going away. But the most up-to-date guidelines, and the growing body of research behind them, make a strong case for a more holistic approach. The guidelines treat digital media as a complex, diverse and evolving environment that children need to learn to navigate in the digital age. The risks and rewards depend, as with any developmental setting, on the child, the content and what online time might be crowding out.

Gabriel E. Hales is a Research Fellow in Media and Information at Michigan State University

02:00 PM

Evasion Ain’t Persuasion [The Status Kuo]

Photo images: Various media sources

On July 15, Senate Intelligence Committee members asked Trump’s nominee for director of national intelligence, Jay Clayton, who won the 2020 election.

On July 21, a Fort Worth reporter asked Texas Attorney General Ken Paxton why he had voted from an address where he no longer lives. Another asked about his multiple houses purportedly purchased on a government salary.

That same day, Sen. Jon Ossoff (D-GA) asked Defense Secretary Pete Hegseth whether his March claim that Iran’s military had been “destroyed” was accurate. Hegseth had a different word ready. It wasn’t “wrong.”

In each case, these Republican leaders chose not to answer. Instead, they dissembled or shut down. They calculated that evasion was better than providing an actual answer. But those evasions carry political costs for the White House that are beginning to compound.

Subscribe now

The humiliation of Jay Clayton

Jay Clayton spent 30 years in corporate law before Trump named him to lead the nation’s intelligence community, including a stint as SEC chairman in Trump’s first term and, more recently, U.S. attorney for the Southern District of New York. None of that prepared him for a question about the 2020 election.

Sen. Ossoff asked him directly who won the election that year. “I’m not gonna do this with you,” Clayton said. Sen. Angus King (I-ME) tried a different approach, asking Clayton to state plainly who had won. Clayton described what happened to the office, not the man: “He went through our processes, and Joe Biden became the president of the United States.” King told him that wasn’t an answer. The best Clayton would offer was that Biden was certified as the winner, not that he had won.

Ossoff pressed a third time, telling Clayton he wasn’t being “honest or forthright.” Clayton sat in silence.

Ossoff then went for the throat. He asked Clayton what we were all thinking at that moment: whether it was humiliating to be unable to answer the question while seeking to lead America’s intelligence community.

The reason Clayton couldn’t answer was clear: He couldn’t draw the ire of the president who had just named him to the post, so he chose to grovel and debase himself before Congress and the nation. It will be all Clayton is remembered for, despite all his professional achievements.

All hat, no cattle Paxton

Ken Paxton has been Texas attorney general since 2015, and for nearly as long he has warned voters that misrepresenting a residence on election records is illegal. Yet a joint investigation by The Texas Tribune and ProPublica found that Paxton voted in six elections over the past two years from a Collin County address where he no longer lives. Three election lawyers told the outlets he may have violated the same law his own office has cited in enforcement warnings.

Separately, Paxton has somehow acquired 15 properties worth about $9 million across four states while serving on a government salary, amid both a Senate campaign and a divorce, according to a New York Times investigation.

It’s small wonder Paxton doesn’t want to face reporters. On July 21, Paxton stood at a Fort Worth podium flanked by sheriffs, unironically insisting he was there to talk law enforcement. A reporter raised Democratic opponent James Talarico’s point about Paxton owning 15 homes and asked Paxton to respond. Paxton didn’t.

A second reporter then asked him to clear up why he voted in Collin County. Paxton had already tried to redirect the gathering once, telling reporters, “Can we keep this to law enforcement today?” So, on the residency question—the one that touches state election law directly—he didn’t try to answer at all. Instead, his press liaison cut in and ended the event, telling reporters Paxton was “gonna get out of here.”

Hegseth’s credibility was “functionally destroyed”

Defense Secretary Pete Hegseth has previously described the state of Iran’s military in stark terms: its missile program was “functionally destroyed,” with launchers, production facilities and stockpiles “depleted and decimated, and almost completely ineffective.”

He was echoing the president. Trump had told the country days earlier that “Iran’s Navy is gone, their Air Force is in ruins.” And in an April 11 post, Trump declared the U.S. had “completely destroyed Iran’s Military, including their entire Navy and Air Force, and everything else.”

These boasts have been at odds with what has happened on the ground. In the months since, Iran has kept fighting. Last week, on July 17 and 18, Iranian missile and drone attacks struck a U.S. base in Jordan, killing Pvt. Isabella Gonzales, 19, and 1st Lt. Tyler James Feehan, 25. A third soldier from the attack, Sgt. Angel S. Rampersad, 28, was initially listed as missing and has since been identified as dead. A fourth service member, Sgt. Michael Emmanuel Swinton, 30, of Fayetteville, North Carolina, was killed days later during the controlled detonation of an unexploded Iranian drone in northern Iraq. The Pentagon has reported nearly 100 troops wounded over the preceding two weeks.

It was within this context—a war that appears to have resumed and taken the lives of four service members in a matter of days—that Hegseth appeared before the Senate Appropriations Committee on July 21. He was there to request $67.1 billion in emergency Pentagon funding, part of an $87.6 billion supplemental package, including $21 billion for munitions and $17.3 billion for operations.

Senators wanted to know how a military he’d described as destroyed just months earlier was still costing the Pentagon that much to fight in July. Sen. Ossoff quoted Hegseth’s own words back to him and asked whether the earlier claims had been accurate, yes or no. Hegseth tried twice to answer a different question, about Iran’s capacity to challenge the United States, but Ossoff cut him off both times, telling him, “That’s not what I asked you, Mr. Secretary.”

Sen. Patty Murray (D-WA) read him his own April statement word for word and asked him to square it with the war’s continued cost. Hegseth’s answer walked the claim back without naming it: “I acknowledge they still have capabilities, no doubt.”

So, not really destroyed, Mr. Secretary? Is that correct?

Here’s the exchange with Sen. Ossoff in which it’s clear Hegseth has been cornered:

A calculation that will backfire

Clayton, Paxton and Hegseth were not asked to speculate. Each was asked to confirm something already established: a certified election result, public voting and property records, or a defense secretary’s own previous statements. In each case, the facts were available, unambiguous and already established. Yet in each case, the official under questioning chose not to acknowledge them.

None of the three men disputed the underlying facts. Clayton did not argue the election was stolen; he simply would not say the word “won.” Hegseth did not argue Iran’s military was indeed obliterated; he simply would not admit he had been wrong before. And Paxton did not dispute that he voted from an address where he doesn’t live; he simply refused to discuss it and left the room.

The evasions differed in method but not in function. Each avoided the specific word or admission that would make the contradiction undeniable on the record, without going so far as to state something false outright.

These men appeared unprepared, but they shouldn’t have been. Clayton had time to rehearse an answer about the 2020 election, a question repeatedly posed to Trump’s nominees. Hegseth’s March and April statements about Iran were public record, and he could and should have anticipated having them quoted back to him. And Paxton knew the Tribune/ProPublica story had been out for two weeks before reporters asked about it in Fort Worth. Each of them walked into the room knowing the question was coming, yet each decided the safer path was silence, deflection or an early exit.

In each case, that was a political calculation. Somewhere between the truthful answer and the podium, each official weighed what it would cost to state the truth plainly against what it would cost to appear cagey and shady. All three decided that a public evasion, awkward and visible as it was, would inflict less damage than the alternative: contradicting a president who has spent six years disputing 2020, undercutting a war narrative the White House has staked its credibility on, or answering for conduct that cuts against a law-and-order brand.

Back when I was a full-time litigator, I would often advise witnesses against being so obviously and painfully evasive. Videos of their testimony, I warned, would almost certainly be played back to a judge or jury, and the witness’s credibility would be shot. After all, anyone who tries so hard not to answer a question probably has something to hide.

Beyond that come two natural follow-up questions: What’s so bad that the witness had to squirm and evade in such an embarrassingly obvious way? And if they’re hiding this, what else are they hiding?

When the Trump White House looks at its low approval numbers, particularly among independents, it has to grapple with two kinds of problems. First, there is the underlying horrible state of affairs, from the high cost of living to yet another foreign war Trump promised would not happen on his watch. Second, there’s a vibes problem: the total lack of respect the regime and its cronies show the American public when they try to evade accountability. By refusing to take ownership of the problems, their decisions or their corrupt or illegal behavior, they have earned the badge not just of bad government but of bad actors.

The first set of problems is fixable. You can end a war, eventually. Prices may stabilize, eventually.

But the second is trickier, once people see you for who you really are. These officials will never get the stench of their sycophantic fealty to Trump off them. And the public, at least outside of the MAGA cult, will draw the correct and logical conclusion that they are there to serve Trump and themselves first, not the public at large.

May the voters pay them all back for their disservice, dissembling and disrespect this November.

10:00 AM

Wikimedia Commons picture of the day for July 17 [Wikimedia Commons picture of the day feed]

Picture of the day
Westrup Heide in the early morning during the heather blossom season, Haltern am See, North Rhine-Westphalia, Germany

Wikimedia Commons picture of the day for July 18 [Wikimedia Commons picture of the day feed]

Picture of the day
Sur En/Sent, municipality of Scuol, kanton Graubünden. Sculpture Negativ - Positive. Artwork by Peter Gredig.

Wikimedia Commons picture of the day for July 20 [Wikimedia Commons picture of the day feed]

Picture of the day
The Chess Queen, a.k.a. The Totem Pole, located a few hundred yards east of Cottonwood Cove, in Vermilion Cliffs National Monument, northern Arizona. Today is International Chess Day.

Kanji of the Day: 客 [Kanji of the Day]

✍9

小3

guest, visitor, customer, client

キャク カク

観光客   (かんこうきゃく)   —   tourist
観客   (かんかく)   —   spectator
お客様   (おきゃくさま)   —   guest
お客さん   (おきゃくさん)   —   guest
顧客   (こかく)   —   customer
乗客   (じょうかく)   —   passenger
客観的   (かっかんてき)   —   objective
接客   (せっきゃく)   —   serving customers
買い物客   (かいものきゃく)   —   shopper
集客   (しゅうきゃく)   —   attracting customers

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 俊 [Kanji of the Day]

✍9

中学

sagacious, genius, excellence

シュン

俊足   (しゅんそく)   —   swiftness of foot
俊彦   (しゅんげん)   —   gifted man
英俊   (えいしゅん)   —   genius
俊英   (しゅんえい)   —   excellence
俊敏   (しゅんびん)   —   quick-witted and agile
俊秀   (しゅんしゅう)   —   genius
俊才   (しゅんさい)   —   prodigy
俊徳   (しゅんとく)   —   great virtue
俊逸   (しゅんいつ)   —   excellence
俊士   (しゅんし)   —   genius

Generated with kanjioftheday by Douglas Perkins.

Discontinued "Merged" Maps. What Changed and What to Do [OsmAnd Blog]

Discontinued "Merged" Maps

OsmAnd has discontinued "merged" maps — large country- or region-level files that were assembled from smaller regional maps. If you have one of these installed, it will no longer receive updates.

What Changed

Previously, some maps were built by merging a set of smaller regional maps into one large file. For example, the full map of Austria was assembled from all of its individual regions; Bavaria (Germany) was assembled from its smaller sub-regions in the same way.

These merged maps are now discontinued. They won't be updated going forward — only the individual regional maps that made them up will continue to receive updates.

If you have a recent version of OsmAnd installed, a warning about this will appear automatically in Maps & Resources → Updates.

Why This Happened

As OpenStreetMap data grows more detailed, map files get larger over time. Merged maps — combining dozens of regional files into one — eventually became too large to update and use efficiently, affecting app performance and routing speed.

Merging also meant duplication: users downloading a merged map and its individual regions were storing the same data twice. Discontinuing merged maps removes this overlap and keeps map updates faster and more reliable.

This wasn't a sudden decision — OsmAnd has been moving toward smaller, region-based maps for some time, and this change is part of that ongoing transition.

Which Maps Are Affected

▶ Click to view Discontinued Detailed Maps (Argentina, Germany, USA, etc.)
  • Global Countries: Argentina, Austria, Belarus, Belgium, Chile, Democratic Republic of the Congo, Czech Republic, Denmark, Finland, Iran, Mexico, Philippines, South Africa, Sweden, Switzerland, Tanzania.
  • Canada: British Columbia, Ontario, Quebec.
  • France: Auvergne-Rhône-Alpes, Grand Est, Nouvelle-Aquitaine, Occitanie, Provence-Alpes-Côte d'Azur.
  • Germany: Baden-Württemberg, Bavaria, Hesse, Lower Saxony.
  • Japan: Chubu, Kanto.
  • Russia: Far Eastern, North Caucasus, Northwestern, Siberian, Southern, Ural, Volga federal districts.
  • USA: Florida, New York.
▶ Click to view Discontinued Roads-Only Maps (UK, Ukraine, Netherlands, etc.)
  • Countries & Regions: Australia & Oceania, Democratic Republic of the Congo, England (UK), Indonesia, Netherlands, Norway, Philippines, South Africa, Ukraine.
  • USA: Florida, New York, Texas.

What To Do

If you have one of the affected maps installed:

  • Check Maps & Resources → Updates a warning about your installed maps.
  • Delete the discontinued merged map from your device.
  • Download the individual regional maps that cover the same area instead.

Going forward, updating by region means smaller downloads and keeps your maps current without needing to re-download a large file each time.

Questions or Issues

If you have questions about this change or run into issues after switching to regional maps, contact OsmAnd support at support@osmand.net, or visit the Support page for more help options.

09:00 AM

Ctrl-Alt-Speech Spotlight: PwC’s Dan Hays On The Future Of Trust & Safety [Techdirt]

Ctrl-Alt-Speech is a weekly podcast about the latest news in online speech, from Mike Masnick and Everything in Moderation‘s Ben Whitelaw.

Subscribe now on Apple Podcasts, Overcast, Spotify, Pocket Casts, YouTube, or your podcast app of choice — or go straight to the RSS feed. To get extended episodes with additional coverage, support us on Patreon.

In this sponsored Spotlight episode of Ctrl-Alt-Speech, host Ben Whitelaw speaks to PwC’s Dan Hays at TrustCon about the firm’s recently published Trust & Safety Outlook report.

They discuss: 

  • How AI is simultaneously creating new risks and reshaping the tools used to address them;
  • What the rise of autonomous agents means for governance, accountability and the future of the internet; and
  • How platforms should respond to an increasingly fragmented regulatory landscape.

The conversation also explores how Trust & Safety is becoming a more strategic function inside companies, how automation could change the role of practitioners and vendors, and which emerging risks remain most underestimated.

This episode is brought to you in conjunction with our sponsor, PwC. Download the report today.

07:00 AM

Careful What You Sue For: Trump’s BBC Case Just Forced His Financial Records Into Discovery [Techdirt]

We’ve written in the past that people online often get way too excited about theoretical pending “discovery” in frivolous lawsuits filed by bad actors. Because while there are certainly a few cases where (1) a frivolous case even reaches discovery and (2) some elements of that discovery are revealed to the public, in the vast majority of cases, that doesn’t happen. The legal strategy for most defendants is to get a case thrown out before it reaches discovery because discovery is incredibly expensive. And, even then, most often what is handed over in discovery never goes public.

But… hey, sometimes, “can’t wait for discovery” turns out to be an accurate sentiment.

Last year we noted that Donald Trump had filed an obviously frivolous lawsuit against the BBC, asking for $10 billion. At issue was an edit in the documentary he didn’t like which might be considered mildly misleading (though Donald Trump repeatedly falsely claimed that the BBC used AI to fabricate quotes, the reality was they edited two separate parts of the same speech to sound like they were said together, when they were really many minutes apart). That’s not defamation, though.

Either way, the case has not been going well for Trump. Because he argued that this documentary (which was only shown once in the UK and not in the US) harmed Trump’s business interests in Florida (where he sued), the BBC asked for Trump’s financial records as part of their discovery requests. Given that Donald Trump made more money last year (around $2 billion) than ever before, even as he remains the President of the United States, it seems like a reasonable request.

Trump and his (not very bright) lawyers tried to wriggle out of this by dropping some of the initial claims that were about how much harm the documentary did to his business, saying instead that it just harmed his reputation. The BBC said it still needed his financial records anyway. And now, Magistrate Judge Enjoliqué Lett has agreed, noting in court that the financial records would be relevant to the claims of reputational harm as well.

“All of President Trump’s brand, properties and businesses are impugned or said to have been impugned. Reputational, economic damages, all of that is now at issue in this case,” Lett said at the conclusion of a three-hour hearing.

Of course, Trump’s lawyers can (and almost certainly will) ask the Article III Judge (Roy Altman, who is a Trump appointee) to overrule the magistrate, but it might not work. After all, earlier in the case, Trump’s lawyers had sought to remove Lett from the case, claiming that she was biased against him, because before she became a Magistrate Judge, she had represented a client in a case against Trump. Judge Altman rejected that claim back in May, siding with his colleague, Magistrate Judge Lett:

The Plaintiff asks us to withdraw our referral of discovery matters from Magistrate Judge Lett and reassign them to a different Magistrate Judge. … He advances two arguments in support of this request: First, he cites our unrelated referral of discovery matters in Donald J. Trump Revocable Trust et al. v. Capital One…. Second, he argues that “Magistrate Judge Lett had appeared as counsel of record on behalf of a party directly adverse to President Trump in active federal litigation: Trump v. Clinton… The Plaintiff’s first argument is unavailing. “Effective April 19, 2026,” Magistrate Judge Hernandez replaced Magistrate Judge Lett as our “paired” Magistrate Judge for Miami-based cases…. We reassigned discovery in Capital One the next day based on case workload and the parties’ compressed discovery period…. Nothing about that decision mandates a withdrawal of the referral in the different circumstances of this case. The Plaintiff next argues that Magistrate Judge Lett previously “represent[ed] [a] defendant directly adverse to President Trump.” … Despite his claim to the contrary, the Plaintiff effectively seeks Magistrate Judge Lett’s recusal. … But 28 U.S.C. § 455 is clear that: “Any justice, judge, or magistrate judge of the United States shall disqualify himself in any proceeding in which his impartiality might reasonably be questioned.” Accordingly, we’ll leave any decision regarding Magistrate Judge Lett’s recusal to her sound judgment. Signed by Judge Roy K. Altman on 5/19/2026.

So, at this point, Judge Altman seems willing to trust Magistrate Judge Lett’s judgment on the recusal question — and that deference may well carry over to the financial-records dispute too.

Of course, even if discovery does move forward, Trump could still file for a protective order to keep most of the records secret, outside of whatever has to be used in court. Alternatively, he could try to dismiss the case to get out of having to provide discovery.

Either way, this was a stupid, vexatious, obvious SLAPP suit designed to punish the BBC and waste its time and money. So it’s quite nice to see that backfiring on the censorial bully that is the President of the United States.

RSSSiteUpdated
XML About Tagaini Jisho on Tagaini Jisho 2026-07-24 03:00 AM
XML Arch Linux: Releases 2026-07-23 10:00 AM
XML Carlson Calamities 2026-07-23 10:00 AM
XML Debian News 2026-07-24 04:00 AM
XML Debian Security 2026-07-24 03:00 AM
XML debito.org 2026-07-24 04:00 AM
XML dperkins 2026-07-24 03:00 AM
XML F-Droid - Free and Open Source Android App Repository 2026-07-23 06:00 AM
XML GIMP 2026-07-23 10:00 AM
XML Japan Bash 2026-07-24 03:00 AM
XML Japan English Teacher Feed 2026-07-24 03:00 AM
XML Kanji of the Day 2026-07-23 10:00 AM
XML Kanji of the Day 2026-07-23 10:00 AM
XML Let's Encrypt 2026-07-23 10:00 AM
XML Marc Jones 2026-07-23 10:00 AM
XML Marjorie's Blog 2026-07-23 10:00 AM
XML OpenStreetMap Japan 2026-07-23 10:00 AM
XML OsmAnd Blog 2026-07-23 10:00 AM
XML Pluralistic: Daily links from Cory Doctorow 2026-07-24 03:00 AM
XML Popehat 2026-07-23 10:00 AM
XML Ramen Adventures 2026-07-23 10:00 AM
XML Release notes from server 2026-07-23 10:00 AM
XML Seth Godin's Blog on marketing, tribes and respect 2026-07-24 03:00 AM
XML SNA Japan 2026-07-24 03:00 AM
XML Tatoeba Project Blog 2026-07-24 03:00 AM
XML Techdirt 2026-07-24 04:00 AM
XML The Business of Printing Books 2026-07-23 10:00 AM
XML The Luddite 2026-07-23 10:00 AM
XML The Popehat Report 2026-07-24 03:00 AM
XML The Status Kuo 2026-07-24 03:00 AM
XML The Stranger 2026-07-23 10:00 AM
XML Tor Project blog 2026-07-24 04:00 AM
XML TorrentFreak 2026-07-24 03:00 AM
XML what if? 2026-07-24 03:00 AM
XML Wikimedia Commons picture of the day feed 2026-07-23 10:00 AM
XML xkcd.com 2026-07-24 03:00 AM