News

Thursday 2026-09-03

10:00 AM

Kanji of the Day: 働 [Kanji of the Day]

✍13

小4

work, kokuji

ドウ

はたら.く

働く   (はたらく)   —   to work
働き   (はたらき)   —   work
労働   (ろうどう)   —   manual labor
厚生労働省   (こうせいろうどうしょう)   —   Ministry of Health, Labour and Welfare
労働者   (ろうどうしゃ)   —   worker
共働き   (ともばたらき)   —   both working
稼働   (かどう)   —   operation (of a machine)
働きかけ   (はたらきかけ)   —   pressure
労働組合   (ろうどうくみあい)   —   labor union
厚生労働相   (こうせいろうどうしょう)   —   Minister of Health, Labour and Welfare

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 鍵 [Kanji of the Day]

✍17

中学

key

ケン

かぎ

鍵盤   (けんばん)   —   keyboard (of a piano, typewriter, etc.)
合鍵   (あいかぎ)   —   duplicate key
鍵っ子   (かぎっこ)   —   latchkey child
鍵穴   (かぎあな)   —   keyhole
合い鍵   (あいかぎ)   —   duplicate key
勝敗の鍵を握る   (しょうはいのかぎをにぎる)   —   to have the game in one's hands
鍵盤楽器   (けんばんがっき)   —   keyboard instrument
打鍵   (だけん)   —   keystroke
鍵をかける   (かぎをかける)   —   to lock
内鍵   (うちかぎ)   —   internal lock

Generated with kanjioftheday by Douglas Perkins.

09:00 AM

Meta’s $17 Billion Settlement Is A Bad Deal For Teens And All Social Media Users [Techdirt]

Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.

In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:

  • The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
  • The Settlement places severe restrictions on Teens that can only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
  • The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
  • The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism.

Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.

Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.

Age Gates Reinforced By Age Estimation Technology

In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And Further, Meta will now enforce these age gates with “age assurance” technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The Technology also just adds a layer of creepiness into the user of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]

1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) orage assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.

Those methods might include both commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.

This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.

For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.

Those estimated to be 13-17 years old will be limited to Teen User accounts.

Those estimated to be under-13 will lose their accounts altogether.

Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]

(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.

What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement.

How accurate does the age assurance process need to be?

The Settlement sets maximum false positive for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more 10% for ages 16-17 and 3% for ages 13-15. 

6. Age Assurance Standards.
(a) U18 False Positive Rate Thresholds.
(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall
meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.
(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: 
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.

Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]

9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.

The Settlement generally shows little concern for those falsely placed in its Teen User category.

Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).

(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and 

Any age assurance process Meta uses must be tested annually.

Data minimization

The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” But the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information … where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires at that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.

8. Data minimization and security.
(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).
(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.
(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.

Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)

Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to these estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.

Time restrictions

Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits:

  • Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
  • School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
  • Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
  • “Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be monetarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:
Exhibit G from Meta Settlement showing phone warnings

To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such users controls would have recognized that teens have human rights, agency, and autonomy.

But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.

Feature restrictions (§II.C-D)

Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service.

Again, these would be useful user controls that should be offered to users of all ages.

By default, teens will not see the number of likes or other reactions to their posts.

Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques. 

X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.

Meta has already had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters. 

Content restrictions (P.1, §II.E, as defined by §I.C, E, F)

For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.

C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.
D. “Age Assurance Methods” shall have the meaning set forth in Section II.
E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.

The issue here is that some of these categories are problematic. For example, the Restricted Goods & Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our Stop Censoring Abortion campaign, and in our comment to the Meta Oversight Board. And under the Adult Nudity & Sexual Activity, Meta blocks teens from “real world art of visible genitalia … where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to representations of indigenous womenbreast cancer awareness posts, and posts about testicular and breast self-examseducational posts about ovulation. And it has disproportionately applied the standard to gay and lesbian content in as compared to straight content.  

And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressure Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earned First Amendment defenses to make its own curatorial decisions. 

C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.

The Parental Supervision Tradeoff 

All of these Teen User restrictions can be modified – but only if the Teen User enrolls in the Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, Parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).

And Parental Supervision comes with a huge privacy tradeoff. In exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G] 

Parental Supervision
1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.
2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.
3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.
4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.
5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.
6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.

Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8] 

This may be workable for young people with healthy and safe relationships with their parent or guardian. But obviously not good at all for a Teen User lacking such a safe relationship. 

More Surveillance, Not Less

Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.  

For example: 

  • Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)] 
  • Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)] 
  • Meta pledges to utilize and improve its existing “soft matching models” that track signals such as device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)] 
  • Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3] 
  • Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4] 
  • The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E] 

Moreover, one of the chief threats of Meta’ surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain. 

Meta Has To Pay The States — Establishing Norms Beyond Meta

The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten year-life of the Settlement, these annual payments will total over $11 billion plus the prospect of an additional $5 billion—if Meta competitors adopt the same measures. 

This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get an additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance and age-gating as the norm across online services. 

1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).

2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:

(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.
(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.

3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment

The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance. 

Republished from the EFF’s Deeplinks blog.

07:00 AM

New Alpha Release: Tor Browser 16.0a11 [Tor Project blog]

Tor Browser 16.0a11 is now available from the Tor Browser download page and also from our distribution directory.

This version includes important security updates to Firefox.

⚠️ Reminder: The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.

If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the stable release channel.

Send us your feedback

If you find a bug or have a suggestion for how we could improve this release, please let us know.

Full changelog

The full changelog since Tor Browser 16.0a10 is:

ICE Finalizes Stun Glove Purchase, Claims There’s No Other Way To Handle ‘Violent’ Migrants [Techdirt]

This was inevitable. ICE has billions of new money to spend, zero shame, and not a single adult in a leadership position capable (or willing!) to talk the agency off the ledge.

ICE decided the neat new tool of cruelty it absolutely had to have were gloves that behave like stun guns or low-powered Tasers. Only one company makes these: Compliant Technologies. There’s a reason for that. Prior to ICE’s devolution during Trump’s second term, no agency of any size really had any reason to buy these stun gloves.

Early adopters were prisons and (wtaf) schools. These gloves made limited sense in prisons where guards are working in confined areas and possibly don’t want to utilize any weapon that might be taken away and used against them. Why they’re being used in schools is literally unimaginable. But here we are in the 21st century, witnessing schools pleading with law enforcement agencies to stop shocking their students with Compliant Technologies G.L.O.V.E., or (brace yourself) Generated Low Output Voltage Emitter, which sounds more like an electrician’s tool than something capable of rendering minors immobile.

With only one provider available, the decision was easy. ICE finalized its threatened purchase of 6,000 G.L.O.V.E.s from Compliant Technologies late last week, ensuring officers will have even more ways to inflict pain on thousands of non-criminals, ranging from ambushed migrants to peaceful protesters who have managed to momentarily inconvenience ICE’s kidnapping squads.

Everything about this is awful, but ICE’s defense of this purchase is both bizarre and palpably evil:

ICE does not currently have an empty hand use of force device to provide to the field amidst unprecedented levels of threats and violence against ICE officers and agents to help ensure they can de-escalate tense situations before they turn violent,” the agency wrote in procurement documents.

WTF? Do you know who else doesn’t have “empty hand use of force devices?” 99.999% of US law enforcement agencies, including federal agencies that generally face more legitimate danger from arrestees, like the FBI, ATF, and Secret Service. And do you know why? Because it’s an absolutely psychopathic use of force “option.”

Somehow, it’s ICE that desperately needs this hideous option, even though all it’s really doing at this point is doing migrant mop-up work — arresting migrants by the thousands despite almost none of these remaining migrants having ever been arrested, much less convicted, for violent crimes.

The procurement document [PDF] contains more supporting statements from ICE that make it clear these gloves aren’t really meant to help subdue violent arrestees. The gloves are being purchased to give ICE officers the means and the opportunity to basically stun anyone they run into, including people they aren’t even seeking to arrest. This paragraph suggests stun gloves are nothing more than a violent way for ICE officers to “de-stress” while at work:

ICE requires a non-lethal, de-escalation device intended to diffuse situations of high-stress environments where physical altercations are likely, such as field domestic disputes or inmate transport in jails. It will be used when a subject is actively or passively resisting and an officer needs to gain control quickly to prevent injuries to both parties.

The document doesn’t explain what the phrase “field domestic dispute” means, nor does it provide context. Reading “domestic dispute” in its usual context, the sentence seems to suggest officers should be able to stun their domestic partners into compliance when things at home get a bit heated. Obviously that’s not what that phrase means, but it’s an extremely weird grouping of words that seems to be specific to ICE and its desire for gloves that can shock people.

Further down, ICE makes it clear it’s going to allow officers to deploy the gloves against peaceful protesters or anyone else who might be considered an obstacle to officers’ kidnapping plans.

“Soft” Empty-Hand Control- Enabling officers to briefly distract a subject who is resisting or hiding their hands to secure handcuffs without transitioning to higher, more forceful levels of control.

Civil Disturbance- Assisting crowd control units in moving groups or denying access to areas without requiring lethal or high-impact munitions.

ICE makes it sound like its officers will stop shooting or beating people because of these gloves. But I can guarantee you the gloves will be used whenever possible, especially when they might facilitate a beating. Since pretty much every ICE officer wears gloves, it will be impossible to tell who’s wearing the stun version and who’s just trying to look like a Call of Duty lobby idle animation. Officers are absolutely going to love these gloves because the element of surprise will always be on their side.

There’s no way ICE seriously believes 6,000 pairs of hand-worn cruelty application devices will actually limit the use of deadly force. But it can probably assume it might reduces shootings because its thousands of under-trained officers will probably be less willing to grab a metal gun from near their waist when they’re not sure whether or not their G.L.O.V.E.s are still activated.

This is just a way for ICE officers to hurt more people while pretending stunning anyone an officer touches is synonymous with de-escalation. This is just an agency loaded from top to bottom with sadists seeking out novel ways to inflict more pain.

06:00 AM

Hiking the Alps [dperkins]

This year progress on the Top 100 Mountains continues. Here are pictures from day and overnight trips to the Japanese Southern Alps and Central Alps this year.

Mt. Hoo

During spring break, I drove to Kofu, Yamanashi, and climbed Mt. Hōō (鳳凰山). There are several summits, and given the abundance of snow and ice, I summitted Jizō-dake (地蔵ヶ岳), notable for a giant rock at the top — the Obelisk. The trail was slow but fun: one third dirt, one third ice, and one third snow.

20260330.1.Alps.jpg 20260330.2.Jizo-dake.jpg 20260330.3.Obelisk.jpg

Yatsugatake & Mt. Tateshina

The snow was gone by May, so I drove up to the Central Alps in southern Nagano and climbed Yatsugatake (八ヶ岳). Yatsugatake has a handful of summits, and my route went over Amida-dake (阿弥陀岳) and Aka-dake (赤岳). The next day, I went up Mt. Tateshina (蓼科山), another mountain not far to the north. One fun thing about hiking so much in the Southern and Central Alps this year is learning the landscape. Many of these mountains are visible from one another on clear days, and if you don't know what you're looking at, it's guaranteed that some other hiker will tell you. Mt. Fuji shows up from time to time, too.

20260530.1.Yatsugatake.jpg 20260531.1.Tateshina.jpg

Mt. Kita & Mt. Aino

The second- and third-highest mountains in Japan are Mt. Kita (北岳) and Mt. Aino (間ノ岳), and you can day trip them if you really want to. There are many mountain huts along the way, so your gear need not be burdensome, and the scenery is majestic. Nevertheless, it's strenuous to say the least, and my legs were aching by the end of the day.

20260703.1.Fuji.jpg 20260703.2.Hoo.jpg 20260703.3.Senjo.jpg 20260703.4.Kaikoma.jpg

Mt. Tekari & Mt. Hijiri & Mt. Kisokoma

In late summer I drove to Nagano for more hiking. First was a two-day hike. It was a brutal ascent up to Mt. Tekari (光岳), but once I got up there, following the ridge north over Mt. Chausu (茶臼岳) was pleasant, and the weather was wonderful. After the long day with massive vertical gain, I spent the night at Chausu Hut (茶臼小屋). The mattress was thin and I slept poorly, but the building was warm and the food was good. The next morning we all awoke to a spectacular view of Mt. Fuji at sunrise. The pictures speak for themselves.

On the second day, I continued north, stopped briefly at the top of Mt. Kamikochi (上河内岳) went to the summit of Mt. Hijiri (聖岳), and headed back down to the car. Going down was much easier than going up, but my shoes were getting old and I got some blisters. That afternoon I went to an onsen in the nearby village of Toyamago, because a long bath after a long hike is just lovely, and then drove north for an hour.

After sleeping in the car, I got up and took the alpine bus and cable car most of the way up Mt. Kisokoma (木曽駒ヶ岳). From there it was a leisurely stroll to the summit. Many years ago we were here on a school trip but didn't get to the top because of bad weather. So it was nice to return, go the extra kilometer, and get the good vibes and views.

20260831.1.Tekari.jpg 20260831.2.Chausu.jpg 20260831.3.Fuji.jpg 20260901.1.Fuji.jpg 20260901.2.Fuji.jpg 20260901.3.Fuji.jpg 20260901.4.Ridge.jpg 20260901.5.Hijiri.jpg

Enrollment and learning [Seth Godin's Blog on marketing, tribes and respect]

“Why are you taking this class?”

That seems like a fair question. After tenth grade or so, it’s a choice, after all.

One honest answer is, “I have to get a good grade to get to where I want to go.” That means certification, compliance, regurgitation. It means enrollment in the outcome, not the process. When this happens, we’re seeing a failure of the system we call education. Because that’s not learning.

One answer is, “Because I’m curious.” This is a great reason to take a class, and the instructor’s job isn’t merely to satisfy the curiosity; it’s to amplify it and turn it into a habit and the practice of the autodidact.

For many professional settings, the answer might be, “To learn how to use these tools and this insight to make a change in the world after I graduate.”

That sort of enrollment becomes a productive bargain. It gives the student agency–you don’t have to like everything the instructor has to say, you don’t have to use it when you leave, but the standard is: Is it helpful to imagine having this tool in your kit, and does this course prepare you to use the tool effectively?

Teaching is expensive, so is learning. Active enrollment on both sides is part of the bargain. Students are free to reject the pedagogy, the tools, even the aims of the current practitioners of a craft. But they’re on the hook to do that after they’ve absorbed what the instructor has to offer.

Take what you need and leave the rest.

      

The USPS Lied—To Us, the Court and Congress [The Status Kuo]

Image courtesy of VoteBeat

The U.S. Postal Service has been openly defying a court order in an attempt to throw the midterms into electoral chaos. That’s according to a new whistleblower complaint, made public on Tuesday by Sen. Richard Blumenthal (D-CT). The complaint alleges USPS kept building the technical system underlying Trump’s mail-voting restrictions even after a federal judge ordered the work stopped.

The Postal Service also lied about what it was up to. On July 15, Postmaster General David Steiner and USPS Board of Governors Chairwoman Amber McReynolds wrote to Senate Democrats declaring, “The Postal Service is abiding by these injunctions, which are also currently under appeal.” USPS leadership continued to claim publicly and to Congress that the agency was not moving forward with the rule, even as work on the portal resumed two weeks later.

The whistleblower complaint also contains a worrisome warning: The system, as designed, could reject entire batches of mail ballots over a single scanning error. That gives USPS a mechanism for disenfranchisement at scale. Attorney Marc Elias of Democracy Docket noted that a batching rule that groups ballots by ZIP code would disproportionately affect Democratic-leaning, higher-density areas. And as Sen. Blumenthal pointed out, voters who recently changed their names after marriage or moved are among those most likely to trigger a mismatch—the same populations targeted by the SAVE Act.

“It may be sloppy. It may be chaotic,” Elias observed. “But it is designed to achieve what Trump wants.”

Subscribe now

The legal landscape, CliffsNotes version

As I wrote about earlier, the backdrop to the whistleblower complaint is a pitched legal battle over a March executive order. It sought to aggressively restrict mail balloting by directing USPS to withhold delivery of ballots from any state that refuses to submit its voter rolls to the federal government. To comply with the order, USPS hastily built the “Federal Ballot Mail Portal” and list-matching system now at the center of the whistleblower’s account.

The legal fight reached the Supreme Court on Aug. 24. As I explained in my piece shortly after that ruling, the radical conservative majority, abusing the emergency docket once again, cleared a narrow procedural path forward. It ruled that the original lawsuit was not “ripe” because there was no formal rule in place, the plaintiffs had not yet suffered actual harm and therefore the court lacked jurisdiction to issue its injunction. That twisted procedural holding left the underlying legality of Trump’s order, as well as the USPS implementing rule, open to challenge.

Bowing to the SCOTUS ruling, Judge Indira Talwani lifted her block on Aug. 26. But by the end of that day, a coalition representing 24 states, Washington, D.C., and voting-rights groups filed a fresh challenge to the now-finalized rule. Judge Talwani responded the next day with a new 14-day restraining order blocking the rule’s mandatory provisions. It expires Sept. 10.

Defying the court and lying to Congress

According to the whistleblower’s timeline, USPS began building the Federal Ballot Mail Portal on June 15. The agency halted that work on June 25, the day Talwani first ruled Trump’s executive order legally void. It then resumed construction on July 29, the same day the White House appealed Talwani’s order to the Supreme Court.

But hold up. Just because you appeal a ruling to SCOTUS doesn’t mean you can start disobeying it. It’s simply on appeal, so you’re still bound by the order unless and until a higher court overturns it.

USPS didn’t care. The complaint describes the restart of work on the system as a mystery: work was “suddenly resumed without explanation of what authority permitted U.S.P.S. to ignore the court order.”

Note the sequence of events. The last of the injunctions covering USPS’s work “was not lifted until Aug. 26, 2026, after weeks of work were done on the new election ballot mail IT system,” the complaint states. Yet work continued at “a breakneck speed” while the injunctions were in place, in defiance of the court’s order.

USPS disputes that its actions amounted to defiance. The agency confirmed it continued work on the portal during the legal fight, but it claims it remained in compliance because it was not yet using the parts of the system that could invalidate anyone’s vote.

Nice try, but no. That’s like saying you were complying with a ban on nuclear weapons while you continued to purify weapons-grade uranium and build missile systems to deliver the warheads. “We haven’t used the nukes yet” isn’t the standard.

And Judge Talwani’s order wasn’t the only one the government ignored. In a parallel D.C. lawsuit, a federal judge had ordered the Justice Department to notify the court of any “material factual developments while this litigation remains pending.” The DOJ did not inform that court when USPS resumed work in late July despite another court’s injunction. That seems pretty material.

Talwani had already found in her Aug. 25 ruling that USPS violated her injunction. She wrote, “[D]espite the Defendants’ protestations that ‘[t]he United States takes its obligation to comply with court orders very seriously,’ the court finds that Defendants violated the preliminary injunction in this case.”

But the extent of the violation was not fully known until the whistleblower’s complaint became public. Blumenthal characterized the overall pattern as intentional and issued a stark warning. “This is not just incompetence, it is ‘designed malfunction,’” he told reporters.

A system built to fail one ballot at a time

The system USPS built (while telling Congress it wasn’t building anything) relies on a multi-step verification process, designed to produce mass rejections of ballots.

States must first upload a “Mail-In and Absentee Participation List” of every voter set to receive a ballot. A batch manifest for each mailing is then checked against that list, and anything short of a 100 percent match sends the whole manifest back to the state.

Ballots that clear the manifest check face a second hurdle. USPS clerks sample barcodes from each batch at the point of mailing: 15 codes for batches under 1,000 ballots, 350 for batches between 1,000 and 10,000, and 400 for anything larger. The complaint states what happens next: “As presently designed, if even one barcode on one single ballot in a bulk-mailing of 10,000 ballots fails to properly scan during the verification process, the entire batch is rejected and sent back to the state—effectively stopping the ballots from being mailed to voters.”

A White House spokesperson downplayed concerns about the barcode system, saying it was “neither complex nor unique for USPS since the Postal Service regularly uses bulk mailing and intelligent mail barcodes for a wide variety of large customers.”

USPS did not disclose this zero-failure threshold to the public during the comment period before finalizing its rule. The agency’s final rule expressly declined to provide an anticipated ballot-rejection rate, leaving election officials and voters unable to gauge the consequences of the system the agency was actively building, even while denying it was doing so.

That omission is hard to read as an oversight, particularly given USPS’s own operational history. A 2017 audit of package tracking by the USPS Office of Inspector General documented technical problems with USPS scanners, including delayed transmissions and signal obstruction. The agency’s own “zero-failure design” for mail-in ballots leaves no room for those kinds of known scanning problems, particularly given batches running into the tens of thousands of ballots.

Then there is the rushed development schedule. USPS set a three-month timeline for a project the whistleblower says should ordinarily take 9 to 12 months or longer. The portal also skipped standard software testing. In the final days before its planned Sept. 1 launch, multiple USPS officials described the development process to the whistleblower as “a shit show.”

Democracy activists and lawmakers respond

Sen. Blumenthal, ranking member of the Senate Homeland Security Committee’s Permanent Subcommittee on Investigations, released the whistleblower’s disclosure alongside a letter to Postmaster General Steiner. He described the findings as “alarming” and declared they “present a clear picture of a fatally flawed process that cannot and will not protect American voters.” He gave Steiner until Sept. 8 to respond, requesting records and communications about the system’s development, including whether work continued during periods USPS told Congress it had stopped. He also referred the matter to USPS’s Inspector General.

On a call with reporters, Blumenthal was even more blunt about the stakes. “The main takeaway for me is that the Postal Service has designed a system to disenfranchise millions of Americans,” he said.

Rep. Robert Garcia (D-CA), ranking member of the House Oversight Committee, framed the disclosure as a deliberate power grab rather than mere mismanagement. “Trump is creating a new tracking system at the US Postal Service that is untested, dangerous, and threatens to totally disrupt ballot delivery for millions of American citizens,” Garcia said in a statement. “This is an unconstitutional and dangerous power grab and must be permanently and immediately blocked.”

California Attorney General Rob Bonta, whose state is among the plaintiffs and relies heavily on mail-in ballots, vowed to fight on. “From the beginning, it’s been clear that President Trump doesn’t understand how elections work. He’s repeatedly broken the law, so we’ve repeatedly taken him to court.” Gov. Gavin Newsom upped the ante considerably. “Defying court orders to engage in election interference should bring prison time,” Newsom said. “Lock them up. Defend democracy.”

Where things stand

Judge Talwani reaffirmed her restraining order on Monday, rejecting a White House request to lift it to allow USPS to move forward with its portal so long as it doesn’t force states to use it. That’s the same improper loophole the agency had already squeezed through once, according to the whistleblower’s account.

The Justice Department is taking the fight up the judicial ladder. It’s asked the 1st U.S. Circuit Court of Appeals to treat Talwani’s temporary order as an appealable injunction and to stay it, arguing her 14-day window has the “practical effect” of a preliminary injunction even though it isn’t labeled one. The appeals court’s response will determine whether Talwani’s order holds through Sept. 10.

That timeline matters. States are already preparing to send out mail-in ballots for the midterms. North Carolina ballots are scheduled to begin mailing Sept. 4, and Alabama’s follow on Sept. 9. So the legal fight is about to collide with the real world, including whether USPS actually starts using the system once ballots begin moving.

With all these shenanigans from the federal government, Rep. Ted Lieu (D-CA) was clearly fed up and gave voters some blunt advice at a press conference Tuesday morning. “Just go fucking vote. The Trump administration is going to try to suppress your vote.”

04:00 AM

Whistleblower: USPS Defied A Court Injunction To Build An Untested, Undocumented Ballot-Blocking System. Its Own Staff Call The Process “A Shit Show.” [Techdirt]

Even as Donald Trump regularly uses mail-in ballots himself, he has decided that mail-in ballots are a system by which voting fraud occurs. To be quite clear, this is bullshit. There is astoundingly little evidence of significant voter fraud, and that’s equally true between in-person and voting-by-mail. And there’s zero evidence that mail-in voter fraud has ever even come close to swinging a federal election. Indeed, what little voter fraud there is often involves mixups of people who thought they were eligible to vote accidentally trying to vote when they were ineligible.

Either way, a few years back, Trump started blaming mail-in ballots for the completely mythological “rigged elections” he keeps insisting are happening, and of course the MAGA establishment quickly fell into line. We just recently wrote about how the Fifth Circuit appeals court has been working overtime to pretend that it’s well-established that mail-in ballots are insecure. But the bigger issue is that earlier this year, Trump issued an executive order to try to limit the use of mail-in ballots.

Specifically, the executive order tells the US Postal Service to engage in a “rulemaking” that is designed to make it much more difficult for states to offer mail-in ballots. And, on top of that, it demands that states that offer mail-in ballots must hand over their voter rolls to the federal government. The White House has been demanding voter rolls from a bunch of states, and so far every state that has engaged in litigation over this issue has won (it’s now over 20 cases, all of which have gone against the administration).

On its face, the executive order should be seen as pure nonsense, given that the states get to run elections, not the federal government. And even if it were the federal government, that’s not what executive orders are for. But given that the same Supreme Court that insisted no Democratic president could do literally anything without explicit congressional approval now treats Donald Trump as the very special birthday boy who gets whatever he asks for, we have to take even his most ridiculous demands seriously.

A district court judge, Indira Talwani, who is overseeing two of the cases challenging that executive order has issued injunctions in both cases, blocking the US government from putting it into effect. As Talwani notes, the states get to determine how their elections are run, per the Constitution.

Article I of the Constitution also empowers the States to prescribe the “Times, Places, and Manner of holding” congressional elections. U.S. CONST. art. I, § 4, cl. 1. “[T]hese comprehensive words embrace authority to provide a complete code for congressional elections, not only as to times and places, but in relation to notices, registration, supervision of voting, protection of voters, prevention of fraud and corrupt practices, counting of votes” among other issues. Smiley v. Holm, 285 U.S. 355, 366 (1932).

The President is elected by vote of the Electoral College. See U.S. CONST. amend. XII. The Electors Clause empowers each State to appoint electors to the Electoral College “in such Manner as the Legislature thereof may direct.” U.S. CONST. art. II, § 1, cl. 2. The States require their electors be appointed by popular vote of qualified voters. See Chiafalo v. Washington, 591 U.S. 578, 584 (2020). Accordingly, the States alone determine voter-eligibility requirements, subject only to the outer limits of the Constitution. See, e.g., U.S. CONST. amend. XIX (“The right of citizens of the United States to vote shall not be denied or abridged . . . on account of sex.”); U.S. CONST. amend. XXVI (“The right of citizens of the United States, who are eighteen years of age or older, to vote, shall not be denied or abridged . . . on account of age.”). For presidential elections, the Electors Clause gives States the primary authority to decide how electors are chosen.

As a result, the court ordered (among other things) the USPS to not take any steps to implement the executive order.

Furthermore, in the latter injunction, Talwani pointed out that the federal government failed to present literally any evidence of mail-in voting fraud:

The record is devoid of any declarations or other proffered evidence to suggest that mailin voting has resulted in voting by non-citizens.

In other words — the DOJ, despite the president insisting that non-citizen voting was happening all the time with mail-in ballots — didn’t even try to present evidence of that to the judge.

But this week, a USPS whistleblower revealed that the Postal Service has been building the machinery to implement the order anyway — issuing a final rule on August 26 and, per the disclosure, restarting development around July 29 even though the very clear injunction against doing anything was still in force. The whistleblower went to Senator Richard Blumenthal who released the whistleblower’s report, along with a letter to the Postmaster General demanding an explanation.

My office is in receipt of an alarming whistleblower disclosure (the “Disclosure”) outlining the United States Postal Service’s (“USPS”) perilously rushed and potentially unlawful implementation of President Trump’s Executive Order seeking to restrict mail-in voting. The whistleblower’s allegations make clear that USPS lacks the technical or operational capability needed to effectively implement the EO’s provisions in a way that safeguards every citizen’s right to vote in the upcoming midterm elections. Despite this, the Trump Administration appears intent on USPS moving forward with its flawed plans, no matter the chaos they may create. The whistleblower’s allegations also provide disturbing information suggesting that USPS may have violated a court order by continuing to implement the EO despite being ordered to cease all such work. We urge you to abandon this ill-conceived, unconscionable plan and ensure that all Americans can exercise their constitutional right to vote, including by mail, without interference by USPS.

The USPS’s defiance of the court order here is pretty direct. The judge issued an injunction on Section 3 of the executive order on June 25th. USPS did, in fact, stop work on the portal, while the DOJ appealed. On July 25th, the appeals court upheld the injunction, noting that the executive order “directs unprecedented levels of involvement by federal officials in how states administer elections.”

But just four days later, on July 29th, the whistleblower says that USPS leadership told the IT team to start building a tool to enforce the executive order, in direct and obvious defiance of the injunction against it. Then on August 11th, the district court expanded the injunction, which should have made it even clearer to USPS to stop. But USPS appears to have completely ignored that. While the Supreme Court put a stay on the injunction on August 24th, two days later the district court issued a temporary restraining order. But it appears that basically none of that mattered, as USPS leadership had the IT team continue to work on the thing they were explicitly barred by multiple courts to do.

As Blumenthal’s letter summarizes, the USPS rushed to build a portal whose main job appeared to be to block the mailing of mail-in ballots to voters (i.e., this is not them swiping already completed ballots, just refusing to send them to voters in the first place). And because USPS is now run by people whose main qualification is loyalty to Donald Trump, the execution is exactly as incompetent and slapdash as you’d expect:

The whistleblower’s Disclosure describes an unprecedented process that allows USPS to decide whether ballots issued by state election officials should be mailed. To do so, USPS is building an entirely new online system, the USPS Federal Ballot Mail Portal and related IT systems (the “Portal”), which will be used to screen ballots submitted by state election officials prior to USPS agreeing to mail them to voters. The Disclosure identifies problems at every stage of USPS’s development of the Portal, demonstrating deeply flawed plans for implementation. According to the whistleblower, USPS’s effort to develop and deploy the Portal has been “rushed,” “risky and haphazard” because leadership has demanded an impossible timeframe. In an effort to meet impossible deadlines, USPS has eliminated standard and needed testing, thereby creating substantial risk of a “catastrophic failure” of the system that could “derail the midterm elections.”

What could possibly go wrong:

USPS began work building the Portal on or around June 15, 2026 just three months before the date USPS planned to launch the system and just five months before the November 2026 midterm elections. On or about June 25, 2026, USPS ordered work on the Portal to cease due to a court order enjoining implementation of the EO. That work stoppage persisted for approximately a month, further reducing the time that USPS had to build the new system. According to the whistleblower, building the information technology infrastructure necessary to complete the Portal could take a year or more. Yet, USPS leadership demanded that the Portal be completed for a launch date of September 1, 2026, less than six months after the EO was issued. As a result of this rushed process, USPS has been unable to conduct tests of the Portal to ensure its proper functioning, troubleshoot problems, or distribute instructions on use to state election officials. According to the whistleblower, the Portal “violates standard principles of testing and debugging new software before launch.” Normal procedures at USPS for such systems include internal testing, customer acceptance testing, and a final development stage before release to public facing users. The Portal has gone through none of these basic checks.

Going beyond just Blumenthal’s summary, the actual whistleblower report has some astounding details about how the bosses at USPS working on this seem to have no clue how to build reliable software (one wonders if they’re ex-DOGE folks):

Throughout the development of the project, those giving guidance to tech developers lacked understanding of project parameters. Different team members continued to have different understandings of how the system is supposed to function which caused ongoing and greater confusion among the group.

While there continued to be no clear written requirements for the software and IT system, those developing the new election ballot mail IT system were placed in the position of trying to glean requirements from opaque comments at meetings. It continued to be clear that those giving directions did not understand exactly what was to be built. There was a growing concern that many were grasping at straws, trying to do their best to decipher cryptic instructions, and likely missing important details. Elements as basic to the project as whether a validation issue was a “warning” or an “error” continued to be unclear as leadership provided inaccurate information about these issues. To clarify, a warning allows a ballot to continue through the process while an error stops it. These occurrences reinforced the need for written requirements and the ongoing failures in communication.

Even so, the team was told that the system had to be ready to launch… by yesterday. They were given less than a month to figure it out. If you know anything about software development, project management, or… just about how anything works, these paragraphs are concerning:

Around this time at least one senior USPS official seemed to up the stakes by becoming a more active voice pushing for project completion on the new deadline. For example, when IT workers expressed concerns about the quality of the product under USPS leadership’s compressed timeline, the senior official stated that they (the official) “were not trying to stop anyone from getting their ballots and what is the problem?” Employees went on to reiterate concerns that many teams were still missing details of how systems were supposed to work and that written requirements could ensure that everyone was on the same page. The senior official was dismissive of these concerns. The conversation continued with others repeating the need for clear requirements; while leadership insisted that it was easy to understand what was needed and also that there was no time to write down the requirements. The contradiction was obvious that it should not take a great deal of time to write down something that is easily understood.

Concern continued to grow and the Whistleblower became aware that IT teams referred to the largely oral requirements as a “moving target.”

By the third week in August “user stories” – short, plain-language descriptions of a software feature written from the perspective of an end-user (focused on what a user wants to achieve and why) – were described as unusable “garbage”. User stories that had been generated had incorrect information and needed to be updated.

Throughout this project, the Whistleblower understood that IT teams were siloed and not communicating with one another. Teams had so little understanding what other teams were working on such that when elements were brought together, the teams were unaware of various developments, creating more work to utilize even the completed portions of the work.

By August 20, there was a massive rush as teams tried to get “everything committed” – in order to meet the goal of getting the ballot mail systems ready for customer testing on August 24. The resulting chaos caused work to be overwritten. By this point IT workers were resigned that even if they could get the portal put together and working in the internal development environment, there would not be enough time to test and fix any issue that would inevitably arise in customer testing.

The system was designated a grand total of four (FOUR!) days of user testing (and it’s not even clear if the testing actually happened):

By August 24 the expectation was that if somehow everything was accomplished on Monday the 24th, the code would end up in internal testing on Tuesday, August 25, then move to customer testing on Wednesday, August 26 allowing only four work days to test. For a system that manages something as important as handling voting and ballots, 4 days of user testing is entirely unreasonable. Only leadership seemed to express hope that the September 1 deadline was viable. If a problem was found during testing, which was almost certain, the IT workers would need to fix it and that fix would need to move back to internal testing and then into customer testing again. If a problem wasn’t found in the first 2 days, the fix could not make it back to the customer testing environment in time to meet the deadline.

In just the week prior to September 1, 2026, the Whistleblower learned that IT workers have described the election ballot mail development process as “a shit show.”

Very confidence building!

The whistleblower notes that a similar internal tech project that the USPS IT team built in the past “set aside 47 working days for testing.” And this one gets four.

Perhaps an even bigger problem than the slapdash hand-wavey “build a complex system in weeks with no written requirements, and no time for testing,” was the demand for a “zero percent failure rate.” That means that if a single barcode won’t scan — whether because of bad connectivity or a voter got married and changed their name — USPS bounces the entire batch back to the state. And these batches can run to tens of thousands of ballots. Back to Blumenthal’s summary:

Not only is this system astonishingly untested, USPS has simultaneously implemented an impracticable zero percent failure rate. When ballots are submitted to USPS in large-volume batches, if any one ballot in the batch cannot be verified against the Portal, all ballots in that batch will be rejected. For example, if a state election official brings a batch of 10,000 ballots to USPS and USPS is unable to match just one of those ballots against the Portal – because, for example, someone has recently changed their name after marriage or they’ve moved – then USPS would refuse to mail the remaining 9,999 ballots as well. As the whistleblower notes, “USPS expects the state to take back the entire batch to cure the issue with the single ballot…” Should the slapdash Portal mistakenly mark a ballot as unverified, there is no clear process by which state election officials or voters themselves can challenge the rejection. The Rule simply vaguely states that they “will be informed of the escalation procedures should they decide to challenge a rejection.” Voters intending to cast ballots by mail may not even be aware that their ballots have been rejected, or were part of a rejected batch, until it is too late to secure an alternative ballot or vote in person. Expecting a well-built, thoughtful Portal to return an accurate result 100 percent of the time is already a stretch—expecting a “rushed,” “risky and haphazard” Portal to do the same is a recipe for disaster.

A zero percent failure rate means that a single bad scan (which could happen for any reason) could block thousands of ballots (literally all of which could be legit and fine) from being sent out. Given that eight states already run elections entirely by mail, this could mean significant percentages of voters just not receiving their ballots at all.

And, we’re relying on a hastily built system with barely any testing not to have any bad scans that lead to thousands of ballots being blocked.

Of course, what Blumenthal and the whistleblower call “risky and haphazard” most others might call “deliberately designed to suppress votes and create chaos that will allow MAGA to call into question the validity of an election.”

Look, this is just terrifying: the president and his administration are building a system designed to guarantee that fewer people receive their ballots, in a manner designed to create obvious chaos around an election they don’t expect to win. Whatever you want to call the intent, that’s an executive branch actively degrading the machinery of free and fair elections.

That should be the biggest story in the country.

Donald Trump has made it abundantly clear that he thinks the federal government works for him, and him alone. It does not. It works for the American people, and a court has already told USPS exactly that, twice. One postal employee understood the assignment well enough to risk their job and blow the whistle over it. It’s about time that more started to do so as well.

Daily Deal: The Adobe Graphic Design Bundle [Techdirt]

The Adobe Graphic Design Bundle has 3 courses designed to help you learn the essentials of graphic design and how to apply those skills to your projects. Courses cover Photoshop, Illustrator, and InDesign. You’ll learn all aspects of the design process. It’s on sale for $50.

Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

Flock-Stalking, Nazi-Saluting Deputy Given Top Cop Honors Before Hastily Retiring Ahead Of Criminal Charges [Techdirt]

Law enforcement is often self-selecting. If you like the things you’ve seen cops get away with (violence, brutality, open racism, multiple rights violations, etc.), you’ll probably like being a cop. And before the pedants get carried away in the comments, I’m using “cop” as shorthand for the whole of the law enforcement profession, even if it’s divvied up between actual cops, state troopers, federal officers, and — like this guy is — sheriffs and their deputies.

And so it seemed to go for Deputy Michael Fultz of the Brevard County, Florida Sheriff’s Department. Fultz got on-boarded and almost immediately celebrated as one of the best. Here’s that celebration, which is surrounded by dozens of reasons he never should have received that accolade, as reported by Matthew Gault for 404 Media.

Hired in 2024, Brevard County named Fultz its Deputy of the Year in 2025.

Here’s the very next sentence in that paragraph:

The day of the ceremony Fultz’s ex-girlfriend sent a letter of complaint to the sheriff’s office with a long list of complaints about his behavior.

Portentous. Perhaps even ominous. Spoiler alert: it’s both. The letter prompted an investigation of the newly crowned Deputy of the Year by the same entity that had bestowed it upon him. To say “it’s not pretty” is like saying Mt. Vesuvius was “a little overactive.”

The 43-page investigation found Fultz had posed for pictures as Adolf Hitler, freely used racial slurs in texts, masturbated on camera in his police vehicle, took pictures of his ex-girlfriend with his service weapon in her mouth during sex, repeatedly broke the law to generate clout online for his motorcycle themed Instagram and TikTok accounts, and used Flock to stalk his ex-girlfriend.

Ummm… there’s a good argument here that this person should never have been allowed to be a person, much less a law enforcement officer. Sociopathic, psychopathic, and (obviously) at the very least, extremely “Nazi curious.”

Oh wait. There’s more.

Investigators also found that Fultz accessed Flock while he was off-duty.

And while we all know that cops lie, we should demand better lying in exchange for our tax dollars:

Fultz denied he was using Flock to stalk his ex. He claimed to investigators that he may have been showing her how it works, and denied spying on her.

His excuse was “I wasn’t spying on her,” but rather “I was showing off secret cop tech to a person I would later have sex with while my service weapon was in her mouth?” Is that supposed to to be better? And if so, how?

And while we’re on the extremely uncomfortable subject of officer-involved-sex that utilizes government-issued weapons, let’s first note that the ex-girlfriend said these acts were “consensual,” but also realized (as Deputy of the Year didn’t) that photos of these acts (if not the acts themselves) might be “a poor idea and inappropriate for a deputy sheriff.”

That’s on top of the other “inappropriate” for anyfuckingbody stuff the ex-girlfriend shared with investigators, which ranged from the deputy’s Hitler impression (including photographed Nazi salutes) to text messages loaded with racial slurs.

But the ultimate kink for Fultz wasn’t Hitler or racism or abusing Flock access. It was finding out the thing that made him the hardest (down there) was killing.

In April 2025, Fultz shot and killed a man who charged him with a knife. “She specifically noted that the sexual encounter where you introduced the firearm occurred after your on-duty shooting incident.”

That’s pretty fucked up. But Fultz also did a lot of regular ass cop stuff where he assumed (correctly) he was above the law. According to investigators, Fultz had been pulled over by other law enforcement at least four times for speeding and/or obscuring his license plate. Deputy Fultz, of course, learned nothing from this experience, which thankfully didn’t involve racial slurs, Hitler mustaches, or service weapons in girlfriend’s mouths.

Investigators told him he had to keep his motorcycle’s license tags visible. “Inexcplicably, within 30 minutes of the direct order you were provided, you drove your motorcycle out of the Brevard County Sheriff’s Office parking lot with no license tag attached. The incident was captured on video and preserved as part of the investigation,” the investigation said.

If you thought the explanation (“I showed it to my girlfriend”) above for Fultz’s Flock abuse was horrendous, just wait til you see the one he handed out to excuse his refusal to follow license plate laws:

Fultz explained he was speeding and covering his tag for online clout.

And we’re right back to where we were several paragraphs ago. Fultz should not be allowed to exist as a person, much less be allowed to carry a gun and pretend to represent the legal force of the law.

Fortunately, he’s no longer in the law enforcement business, at least for the moment. The agency that would have been fully justified in firing Fultz and stripping him fully of his law enforcement credentials somehow decided to let him resign, which means other law enforcement agencies he might approach won’t find any evidence of his extreme misconduct on the official record. Some cursory Googling would do the trick, but that’s unlikely to happen.

Fultz is a poor excuse for a human being and one of the last people who should ever be allowed to hold a position that gives him any power over anybody. If he had any shame, he’d emulate his hero, grab his gun, and head to the nearest bunker. Shit like this can’t be rehabilitated, especially when the person involved has shown nothing even remotely approaching remorse for his actions.

RCN Urges Judge to Toss the Major Labels’ ‘Last’ Piracy Liability Lawsuit [TorrentFreak]

cassette tape pirate musicFor years, the major record labels and movie studios waged a campaign to hold US internet providers responsible for pirating subscribers.

Alleging contributory and vicarious infringement, rightsholders argued that ISPs which failed to disconnect repeat infringers should pay for the consequences.

This theory fell apart in March, when the Supreme Court reversed a billion-dollar verdict against Cox Communications. The court held that an Internet provider is not liable for contributory infringement simply because it keeps serving subscribers it knows have been flagged for piracy.

RCN now wants the New Jersey federal court to apply this precedent and end a case that has been running since 2019.

No Inducement, No Claim

In a motion for reconsideration filed yesterday, RCN argues that Supreme Court’s Cox ruling destroyed the legal foundation of the labels’ amended complaint.

An ISP is no longer contributorily liable simply for selling internet access while knowing that some subscribers will use it to infringe. Failing to cut the connections of those subscribers off does not establish intent either.

After Cox, liability now requires proof that the provider actively encouraged infringement through specific acts, or that its service has no substantial non-infringing uses. Neither applies here, RCN argues, noting that the case is “virtually identical” to the Cox lawsuit.

Virtually identical

virtually identical

The labels’ second claim, vicarious infringement, should also be dismissed according to RCN, as it requires proof the ISP profited directly from the piracy itself. The Fourth Circuit ruled in Cox that monthly subscription fees do not count, and the Supreme Court declined to hear the labels’ appeal on that point.

RCN argues that subscribers pay the same price whether they pirate music or browse social media, so the fees are not a “direct financial benefit” from infringement.

The ‘Last’ Case Standing

RCN stresses that the other repeat infringer cases against ISPs have already been dismissed.

“[I]n the wake of Cox, the Labels and other rightsholders dismissed every other secondary copyright infringement case against an ISP—including the movie industry’s virtually identical lawsuit against RCN. The same should have happened here,” they write.

As reported earlier, the labels dropped their cases against Verizon and Altice within weeks of the Cox ruling. The film companies behind titles including The Hitman’s Wife’s Bodyguard dismissed a near-identical lawsuit against RCN with prejudice, and a parallel case against WideOpenWest ended a month later.

The precedent reached RCN’s sister ISP Grande Communications too. Both providers now operate under the Astound Broadband brand. Formally, the labels’ case against Grande is not over yet, however, as Grande still prefers to have a formal win on the books.

By RCN’s account, every other secondary infringement case against a US internet provider is now over, with its own case being the exception.

A Four-Year Standoff

So why is this lawsuit still pending in court after seven years?

According to RCN, the labels never meant to go to trial. The company argues that the case was filed in 2019 as leverage in settlement talks with Grande. After that, it remained pending due to a dispute over internal DMCA records.

In May 2022, Magistrate Judge Tonianne J. Bongiovanni stayed all fact depositions until document discovery was resolved. The stay has not lifted since, despite at least 20 discovery letter briefs. RCN believes the labels are holding on for a reason.

“Instead, it seems that the Labels view the ongoing privilege dispute as a form of leverage. In other words, the Labels seem to believe that RCN might be willing to pay money to avoid a resolution of that issue,” RCN tells the court.

The labels have yet to respond to the motion. RCN asks the court to vacate its 2020 order, dismiss the amended complaint with prejudice, and has requested oral argument.

A copy of RCN’s motion for reconsideration and supporting memorandum, filed at the U.S. District Court for the District of New Jersey, are available here (pdf) and here (pdf).

From: TF, for the latest news on copyright battles, piracy and more.

12:00 AM

GOP Begs Supreme Court To Let It Flood Airwaves With Cheap Midterm Propaganda [Techdirt]

Back in June, the Supreme Court ruled 6–3 in National Republican Senatorial Committee v. Federal Election Commission that federal limits on coordinated expenditures by political parties violate the First Amendment, opening the floodgates to a much broader array of political ads funded via no limit of rich assholes and their preferred dark money groups.

In preparation for the ruling, Trump FCC boss Brendan Carr revised FCC “Lowest Unit Charge Requirement” rules to try and make it much cheaper for the GOP to pummel the midterm elections with less-expensive TV ads carried via the nation’s soggy assortment of right wing broadcasters (which are currently petitioning the Trump FCC to approve massive new mergers).

But it hasn’t all been easy going for the GOP, which believes its massive funding advantage ($125 million for the GOP versus a bunch of debt for the mismanaged DNC) would give them a real leg up during the midterms.

For one thing, the Richmond, Virginia-based 4th Circuit Court of Appeals recently sided 2-1 against the FCC, temporarily suspending the FCC’s attempt at discount TV agitprop, and ruling that neither political parties nor joint fundraising committees with non-candidate members are allowed the discounted rates.

But the GOP has already set the wheels in motion to get this all quickly overturned by the Trump-friendly Supreme Court:

“The committees submitted an emergency motion for a stay and asked the 4th Circuit to rule on that motion immediately so they can file a petition to the Supreme Court. “Intervenors respectfully request that the Court rule on this stay motion as soon as possible—whether by expediting or waiving response briefs—to permit Intervenors to seek emergency relief at the Supreme Court,” Republican committees told the court.

The court responded quickly, issuing an order today to deny the Republican committee’s motion and to immediately issue a mandate that can be appealed to the Supreme Court. Republicans will now seek swift action from the Supreme Court in an attempt to overturn the 4th Circuit ruling before the 60-day discount period starts on September 4.”

If the GOP wins, local broadcasters will be forced to offer dodgy dark money groups the same discounts previously reserved directly for candidates, something the FCC’s lone Democrat, Anna Gomez, states will be “unleashing a flood of coordinated campaign money into broadcast advertising, just as the Supreme Court has cleared the way for unlimited coordinated spending between parties and candidates.”

It’s another reminder (as if you needed one) that unless the U.S. Supreme court is radically expanded and reformed in the next few years, corruption is likely to strip the country down to parts and sell it for scrap off the back loading dock.

Wednesday 2026-09-02

10:00 PM

Pluralistic: Unpermissioned research (02 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]

->->->->->->->->->->->->->->->->->->->->->->->->->->->->-> Top Sources: None -->

Today's links



A car's frosted-over back windscreen, being scraped by a person's hand holding an ice-scraper. The person has scraped a Canadian maple leaf into the windscreen. In the background we see the capitol dome and a depressed caricature of Uncle Sam holding a sign reading 'I am busted.'

Unpermissioned research (permalink)

After half a century of neoliberalism, we are all drenched in capitalism's established religion, the worship of property rights. We are so marinated in property worship that even capitalism's critics frame their critiques in "property talk," to the exclusion of other, more important rights, like human rights, labor rights and privacy rights.

To do this is to surrender before the battle even starts. Critics lose when they allow oligarchs and their apologists to choose a battlefield where they have a nearly unbeatable advantage.

Take privacy: privacy is a human right, not a property right. Human rights aren't for sale. You can't sell yourself into slavery, you can't sell your kidneys to make the rent. If privacy is a property right – one that can be traded away – then Facebook's industrial-scale privacy invasions are actually fine, since you "traded" your privacy to Mark Zuckerberg in exchange for the privilege of talking to your friends.

Some self-styled critics of tech monopolists say that the answer to Facebook's privacy invasions is to force the company to pay for your privacy with cash, rather than services:

https://www.wired.com/story/opinion-andrew-yangs-plan-to-pay-you-for-your-data-doesnt-add-up/

This is ideological capture in its purest form: the "data dividend" that Facebook would owe you under this system amounts to a few dollars per year. For wealthy people, the sums would be trivial, while working people, who've been on the downward leg of every K-shaped recovery for a quarter century, who've maxed out their credit cards and re-mortgaged their homes and drive Uber on the weekends to make rent, would have to subject themselves to ongoing surveillance.

That surveillance is already used to determine the highest price those working people will pay – companies like Plexure inform fast food places when you've just gotten paid so they can tack an extra dollar onto your breakfast burrito in the app:

https://pluralistic.net/2026/04/30/something-must-be-done/#there-ive-done-something

Being forced to sell your privacy doesn't just raise the prices you pay, it also lowers the wages you earn. The same people who can't afford this "pay or privacy" system have their private data used to calculate the lowest wage they'll accept for each ride on those weekend Uber shifts:

https://pluralistic.net/2024/12/18/loose-flapping-ends/#luigi-has-a-point

In other words: not being able to afford privacy will result in you having even less disposable income, which will mean that you'll have to sell even more of your privacy. Lather, rinse, repeat.

But even the wealthy people who can afford to forego the pittances Facebook and others offer in exchange for their private information will find privacy elusive. That's because private information isn't a "rival good" – a thing only one person can own at a time. The fact that your mother is your mother "belongs" to both you and her, as well as your grandparents, your father, your siblings and your kids. The fact that you don't sell your family tree to a tech company won't stop all those other people from selling it on – as anyone whose foolish relations handed their genome over to 23andme can attest:

https://www.npr.org/2025/03/24/nx-s1-5338622/23andme-bankruptcy-genetic-data-privacy

In the property religion, the way you can tell if something is valuable is if it has a high price. Property cultists insist that the problem with privacy is that our privacy is being sold too cheaply. They're wrong: private information isn't "mispriced" – it shouldn't be priced.

Human beings are the most valuable things in our world and they are literally priceless. Murder isn't "theft of life." Rape isn't "theft of sex." While insurers and civil courts have ways of calculating the "price" of an injury or violation, great care has been taken over the centuries to ensure that this does not turn human beings into commodities. You can't buy a "murder offset" that lets you kill people provided you pay into a fund that saves a human somewhere else:

https://pluralistic.net/2021/04/14/for-sale-green-indulgences/#killer-analogy

Human beings are too valuable to be priced. We have an entire, sui generis way of balancing the conflicting interests of human rights. My daughter and wife have rights over me, I have rights over them, and when those rights come into conflict – say, if my daughter believes I can no longer care for myself and wants to put me in a care home – the process for resolving that conflict isn't an auction:

https://www.theguardian.com/technology/2008/feb/21/intellectual.property

Your kids aren't your property. In fact, all the most important relationships in your life are non-market. Doctors have patients, not customers. Any time a doctor calls you a "customer" they are demoting you. A doctor doesn't sell you health. You have rights as a patient that far exceed the rights accruing to a mere customer. Same goes for other professions: Teachers have pupils, librarians have patrons, lawyers have clients. "Customer" is a demotion from all of these.

As every "user agreement" you've ever clicked through demonstrates, Big Tech loves to have everything defined in property terms – and so does all big business.

Take the fight over scraping for AI. You might think that this is a fight over the economic rights of creative workers – certainly, my fellow creative workers treat it as such. But because this debate is being framed in terms of property rights, rather than labor rights, this is a fight that workers are set up to lose.

The tell here is how the media companies – who have been eroding the wages of creative workers for decades as they consolidated into a curdled, inbred oligopoly – describe the AI companies' scraping: as an unlicensed taking. Mitch Glazier, the $1.4m/year CEO of the Recording Industry Association of America issues press releases decrying AI training for image generators without negotiating a license fee first:

https://pluralistic.net/2026/03/03/its-a-trap-2/#inheres-at-the-moment-of-fixation

Who's Mitch Glazier? Oh, just a former Congressional staffer who was drummed out of the Capitol Building after he snuck a clause into must-pass legislation that would have transferred hundreds of millions of dollars from musicians to record labels, who was then immediately hired as the CEO of the record industry's largest lobbying group:

https://www.eff.org/deeplinks/2013/12/tpps-attack-artists-termination-rights

Mitch Glazier – and the businesses he represents – aren't opposed to AI replacing artists. They're opposed to AI replacing media companies. Remember the Hollywood writers' strike? The proposal to replace screenwriters with chatbots didn't come from OpenAI, it came from Disney, Warner, Universal and other companies who claim that AI training is "theft."

If AI training is "theft," then it can be cured by making a purchase, something that the AI companies can easily afford, thanks to the hundreds of billions of dollars they have been given by the world's richest investors, who are the high priests and cardinals of the property religion.

The Hollywood writers are the only workers in the world who have successfully beaten back the use of AI in their workplace, and they didn't do it by making recourse to property rights. The Writers Guild is a union and it enjoys a weak form of "sectoral bargaining" (where all the workers in a field bargain with all the businesses at once) called "multi-employer bargaining":

https://pluralistic.net/2023/10/01/how-the-writers-guild-sunk-ais-ship/

The Hollywood writers' strike was an unqualified victory for the writers, who defended their labor rights to co-determination when it came to the use of new tools on their jobsite. Under the terms of their hard-fought contract, screenwriters don't have to use AI, but they can if they want. For example, writers on a long-running sitcom might train an AI with every script in the series' history, so they can ask a chatbot continuity questions as they beat out a new season of the show. But they don't have to do this if they don't want to, and even if they do, neither their wages nor their headcount can be reduced.

The media companies insist that scraping is a copyright violation, that it's "theft." As a matter of law, this is far from obvious or settled: the process of making transient copies of many works, performing mathematical analysis on them, and then publishing that analysis as software is not obviously a copyright violation, and anyone who claims otherwise doesn't understand copyright:

https://pluralistic.net/2023/02/09/ai-monkeys-paw/#bullied-schoolkids

Worse: by demoting a labor rights issue to a mere property rights issue, AI critics are setting workers up to fail. Say the issue with AI training really is mere copyright. If that's so, the media companies who want nothing better than to pauperize creative workers can amend their standard contracts so that any worker who does business with them must irrevocably transfer their "AI training rights" to the company.

Then, that company will absolutely, 100% license those rights to an AI company to create a model designed to replace that worker. The company will get paid for the training, and the resulting model will come with "guardrails" to stop other media companies from using proprietary data to compete with it.

This is the story of the past 50 years of copyright expansion: every new copyright we've created "to help artists" was scooped up by their bosses, who grew more powerful and were able to demand more concessions from those artists, who were therefore poorer and thus needed more copyrights to help them (lather, rinse, repeat):

https://pluralistic.net/2026/08/18/enron-corpus/#sign-here

If creative workers' AI fight is merely a copyright fight, then that fight can only determine whether media companies or tech companies will get the biggest portion when those workers are devoured by corporations. Only a labor rights fight can take creative workers off the menu altogether.

Treating AI training as "theft" creates harms whose blast radius extends well beyond creative workers' livelihoods. Scraping is a hugely beneficial activity. If scraping – taking a vast corpus of copyrighted works without permission – is theft, then every search engine is a crime, unless it can afford to license "search indexing rights" from every site on the internet.

There's exactly one company that could pull that off: Google, a rapacious tech monopolist that is – not coincidentally – one of the leaders of the movement to beggar every creative worker. We will not improve the world, the internet, or creative workers' lives by ensuring that the last search engine anyone ever creates is Google.

Remember our earlier discussion of how privacy violations are weaponized to make poor people even poorer, by depressing their wages and raising prices based on inferences about their economic desperation? Our best weapon for fighting this practice is scraping, because that's how we catch corporations changing prices and wages based on surveillance data:

https://pluralistic.net/2023/09/17/how-to-think-about-scraping/

Scraping is how we produce evidence of the changes that powerful people are making to the world around us. Do you want to know whether Mark Zuckerberg or Elon Musk are downranking content critical of Trump and Big Tech and pumping racist and conspiratorial posts into the resulting void? You'd better hope you can scrape the feeds they cram into billions of people's eyeballs. Same goes for keeping track of genocide apologists, data-center astroturfers and ICE cheerleaders who've flooded Tiktok ever since Trump stole it and handed it over to his creepy billionaire pal Larry Ellison.

Making copies of that stuff isn't theft. It's not a copyright violation. Not even if you do it to billions of works. Not even if it's bad for the companies whose feeds you're capturing. Not even if it's bad for the dark money groups who funded the content.

Sure, if you do this carelessly or recklessly, you can end up violating someone's labor rights, or privacy rights, or human rights. And because those frameworks aren't based on the sanctity of property rights, they can be used to protect these important rights without giving corporate America the right to have you fined or arrested for documenting their takeover of the America.

The people who keep track of this stuff are worried about being fined or arrested. Ethan Zuckerman, one of America's foundational internet scholars, has just accepted Canadian government funding to move his lab from UMass to McGill in Montreal:

https://ethanzuckerman.com/2026/08/27/my-personal-contribution-to-the-us-canada-trade-war/

Zuckerman studies platform power: "using data to answer hard questions about social media, search engines and AI tools." He leads a team that is documenting exactly, precisely how tech companies collude with authoritarians to spy on us, manipulate us, and control us. And his methodology is something called "unpermissioned research," which is what academics call scraping:

https://www.techpolicy.press/ai-companies-threaten-independent-social-media-research/

"Unpermissioned research" seeks to circumvent limits that platforms establish specifically to stop outsiders from learning how they operate. When you're doing unpermissioned research, you try to get around rate limits, query throttles, and other measures that platforms use to block others from mapping their extent and documenting their conduct.

"Unpermissioned research" isn't a free-for-all. Universities have ethical rules designed to protect the privacy rights and other human rights of research subjects, and because these aren't property rights, they can be balanced against the socially beneficial outcomes of research. Universities can get this wrong, of course, but when they do, it's not theft. It's a human rights violation, a privacy violation, a labor violation.

If you want to know how AI companies are trying to destroy creators' livelihoods, you have to scrape the AI companies. You can't ask companies for permission to gather information that might be used to destroy them – they'll just say no. If taking information off the internet without permission is "theft," then gathering information by scraping AI companies is also theft.

Sometimes a tech company will set up a "research portal" that supposedly obviates the need to scrape by putting all the relevant information in one convenient place. That's what Facebook did in the wake of the 2016 election, when it was widely condemned for publishing paid political disinformation. But Facebook's official research portal omitted vast amounts of paid political disinformation, something we only know because NYU set up a scraping project called Ad Observer that documented the discrepancy:

https://pluralistic.net/2021/08/06/get-you-coming-and-going/#potemkin-research-program

Facebook used legal threats to kill Ad Observer, and then…they killed their official research portal, too:

https://pluralistic.net/2021/07/15/three-wise-zucks-in-a-trenchcoat/#inconvenient-truth

Zuckerman is one of dozens of leading US academics who are relocating their labs and teams to Canadian universities, citing fear of political interference from the Trump regime:

https://vancouver.citynews.ca/2026/08/27/canada-recruits-dozens-of-foreign-scientists-researchers-poaching-many-from-u-s/

The Canadian government has committed $504m to the project. Some of that research will help Canada develop new green energy, and some of it will help Canada make important medical breakthroughs. But Zuckerman's research has a special place in the portfolio of Canadian research projects, because – thanks to scraping – it is a leading source of information about how Trump's tech companies are waging war on the American people and the world.

Scraping isn't theft of data, just like murder isn't theft of life. Scraping can be harmful, and we can create laws and social regimes and ways of talking about those harms that don't give authoritarian governments and vast multinational corporations the right to decide who can document and analyze their conduct.

Take Wikipedia: the project exists solely to organize and disseminate information, for free, to everyone in the world. Wikipedia is among the most important parts of the internet, and one of the most positive developments of the 21st century. The entire project is licensed under a generous Creative Commons license that encourages unlimited commercial re-use of its contents. Even if you think scraping copyrighted works is theft, scraping Creative Commons Attribution 4.0 works is unquestionably not theft.

But Wikipedia is being hammered by AI scrapers, which are operating so aggressively that they threaten the project's ability to keep its servers online. Wikipedia has an AI problem, but that AI problem isn't "theft" – it's denial of service, the aggressive act of intentionally or recklessly flooding a server with so much traffic that it crashes.

If you've been lured into a cultlike worship of property rights, this seems like a contradiction. But once you relegate the relatively unimportant matter of property rights to its correct station, you can see – and reason about – the universe of rights that are far more important than mere property.

All it takes is realizing that there are far worse things you can do with information than "stealing" it.

(Image: Bearas, CC BY-SA 4.0, modified)


Hey look at this (permalink)



A shelf of leatherbound history books with a gilt-stamped series title, 'The World's Famous Events.'

Object permanence (permalink)

#25yrsago NYT says ebooks don't exist, fails to mention thriving ebook pirate scene https://www.nytimes.com/2001/08/28/business/forecasts-of-an-e-book-era-were-it-seems-premature.html

#25yrsago Parking tickets waived in exchange for written apologies https://web.archive.org/web/20010826013513/http://www.thesmokinggun.com/doc_o_day/lewiston1.shtml

#20yrsago "I, Row-Boat" https://web.archive.org/web/20060000000000*/http://www.flurb.net/1/doctorow.htm

#20yrsago Filipino students use SMS to organize mass demonstrations https://web.archive.org/web/20060902160514/http://blog.wired.com/sterling/index.blog%3Fentry_id%3D1545927

#20yrsago Spam pump-and-dumps work http://news.bbc.co.uk/2/hi/technology/5284618.stm

#25yrsago Leaked: Handspring's next PalmOS device https://web.archive.org/web/20020824213501/http://www.palmstation.com/view_article.asp?article=4614

#15yrsago “Stalwart Workers”: neglected backbone of the firm https://web.archive.org/web/20110920155246/http://blogs.hbr.org/hbsfaculty/2011/08/stop-ignoring-the-stalwart-wor.html

#5yrsago Facebook's war on switching costs https://pluralistic.net/2021/08/28/talking-hard-work-blues/#hostage-takers

#5yrsago The "work ethic" is a dirty trick we play on ourselves https://pluralistic.net/2021/08/28/talking-hard-work-blues/#work-will-set-you-free

#1yrago The capitalism of fools https://pluralistic.net/2025/08/28/strew-deal/#neither-fish-nor-fowla


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, pounding the podium.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027

  • "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027

  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Colophon (permalink)

Today's top sources:

Currently writing:

  • “Once Is Enemy Action,” a science fiction novel about the origins of modern technofascism. Today's words: 527 (10843 total).

  • "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

  • A Little Brother short story about DIY insulin PLANNING


This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, possible tracking and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.

ISSN: 3066-764X

08:00 PM

Arti 2.6.0 released [Tor Project blog]

Arti is our ongoing project to create a next-generation Tor implementation in Rust. We're happy to announce the latest release, Arti 2.6.0.

This release continues our ongoing development towards using Arti as a relay and as a directory authority, with much of the work focusing on document parsing, directory mirror support, and DNS stream handling. Additionally, on the RPC front, we are making steady progress towards RPC-based configuration management. Finally, congestion control and Counter Galois Onion cryptography are both now always enabled in arti.

As usual, there also are many under-the-hood improvements to our infrastructure, testing, and documentation, along with multiple bug fixes and internal cleanups.

For full details on what we've done, including API changes, and for information about many more minor and less-visible changes, please see the CHANGELOG.

For more information on using Arti, see our top-level README, and the documentation for the arti binary.

Thanks to everybody who's contributed to this release, including Andrew Kloet, Steven Masnada, iqdecay, pryty26, steven.

Also, our deep thanks to our sponsors for funding the development of Arti!

01:00 PM

Senators Call For RFK Jr.’s Resignation After More Emails Suggest He Lied In His Confirmation Hearings [Techdirt]

There are plenty of reasons to call for RFK Jr. to resign or be fired. There are plenty of reasons to call for him to be investigated. There’s his complete dereliction of duty when it comes to the American measles outbreak. There’s his sneaky misrepresentations carried out as he moonlights on a government-funded cooking show that he puts out because… reasons. There’s the budget and staffing cuts that have led to our lessened ability to respond to outbreaks of diseases like cyclosporiasis. There’s the possible violation of the Hatch Act. There are the negative health outcomes stemming from his misinformation campaigns. There’s also his disinterest and/or inability to follow basic governmental procedures.

But the latest calls for him to resign, be fired, or at least be investigated aren’t about any of the above. Here are the comments from several senators. See if you can guess what this is about.

“This is a pattern, not a slip,” Sen. Edward J. Markey (D-Mass.) said in a statement. “RFK Jr. has lied to the Senate, lied to the American people, and jeopardized the health of children to advance his anti-vaccine agenda.”

Sen. Ron Wyden (D-Ore.) said in a social media post Friday that the documents were “Proof we got RFK lying on the record during his confirmation hearing (a crime).” He called for the matter to be referred to the US Department of Justice for a criminal investigation. In a separate statement to The Guardian, Wyden added that “RFK’s platform is built on lies and grifts that leave a trail of dead children in their wake. There are consequences for lying to Congress.”

If you didn’t manage to guess that this is all to do with what Kennedy told senators about his 2019 trip to Samoa in his confirmation hearings, don’t feel bad. As we demonstrated above, there are plenty of things Kennedy has done that could have resulted in the quotes above.

We wrote about this trip Kennedy took to Samoa earlier this year, when reporting uncovered emails from several people involved in the trip indicating that Kennedy went there as part of his anti-vaxxer crusade. Why Samoa? Well, allow me to quote myself:

It started in July of that year when two 1-year old children who were given a measles vaccine subsequently died. While anti-vaxxers around the world gleefully jumped into action to blame the vaccine for those deaths, it turns out that the vaccine didn’t kill the children at all. Instead, medical professionals had accidentally mixed the vaccine with a muscle relaxer solution instead of sterilized water like they were supposed to. Despite that fact, the anti-vaxxers sowed all kinds of fear and disinformation throughout the country, whipping up negativity around measles vaccines. As a result of that, the government put a 10 months ban in place on the vaccine.

It was during that ban that Kennedy visited the island, apparently to answer the question, “How can I make this bad situation worse?” While there, he met with both anti-vaxxers and members of the Samoan government. But when asked during his confirmation hearings, he claimed that his trip had nothing to do with vaccines at all. He was there to help rollout a new medical record and tracking platform he was pitching. Two months after his trip, Samoa suffered a massive outbreak of measles that lasted months and eventually killed 83 people and sickened over 5,000.

Earlier this year, the AP and the Guardian uncovered emails sent by American and U.N. government staffers that suggested the trip Kennedy took was entirely about vaccines. These emails were all written by third-parties, however, and amounted essentially to what I wouldn’t call speculation so much as a plain reading of the facts surrounding Kennedy’s visit. But, still, these are third-party accounts.

Fortunately, both of those outlets didn’t stop there. They kept digging. And what has the senators in this post’s opening so furious are uncovered direct emails between Kennedy and Samoan government officials that make it abundantly clear that the whole point of the trip was for Kennedy and his team to investigate the MMR vaccine.

On Thursday, the Associated Press and The Guardian jointly released newly obtained documents that directly contradict Kennedy’s statements. One of the documents is a letter Kennedy sent to Samoa’s prime minister in January 2019, in which Kennedy falsely suggested “deaths associated recently with MMR [measles, mumps, and rubella] vaccines” were due to a bad lot of vaccinations from the manufacturer. Kennedy proposed letting him and his “team” from CHD investigate the country’s MMR vaccines. In all, Kennedy used the words ‘vaccination’ and ‘vaccine’ eight times in the letter proposing his visit.

The prime minister responded with a letter in February saying he welcomed Kennedy and his “team’s independent health assessment of our MMR vaccines.” He requested Kennedy coordinate a visit with him.

With the only caveat being that those emails need to be completely authenticated as legitimate, that’s as much of a smoking gun as you could possibly want for proving that Kennedy lied to Congress in his confirmation hearings. That fact obviously won’t surprise anyone, of course. Kennedy is a habitual liar. But to have it evidenced in such a clear and unambiguous way is a rarity.

And, frankly, a gift. Kennedy has to go. Any reasonable and informed person would agree with that and the vast majority of our congresspersons are, in theory, reasonable and informed. They are also political creatures and you may have noticed that all of the folks calling for Kennedy’s figurative head have the letter “D” next to their name.

Sen. Angela Alsobrooks (D-Md.) said Kennedy “must resign or be fired immediately.” Hawaii Governor Josh Green, a doctor who responded to Samoa’s measles outbreak, also renewed his call for Kennedy to immediately resign.

Hopefully, either this reporting or a subsequent investigation will give cover to people on the other side of the aisle to join the call for Kennedy to be ousted. It probably should have been enough that Kennedy took a trip that pretty clear contributed to plenty of people getting killed, most of them children. But if it has to be his lying about it that does him in, so be it.

11:00 AM

Monitor Makers Start Pummeling Owners With Annoying Ads, ‘Smart’ Spyware [Techdirt]

Initially the idea of the “smart television” seemed like a good idea. That is until TV makers realized they could make significantly more money loading the television with spyware, tracking your every online choice, then selling all that data to a global assortment of unregulated data brokers.

It didn’t take long for product quality to sag and consumer privacy to become a distant afterthought in a country too corrupt to pass a modern privacy law or maintain the structural integrity of its regulators.

I spent years pining for a “dumb” television to no avail; basically just a high quality large monitor with hardware HDMI inputs and switching and no clunky operating system (no, just not connecting it to the internet wasn’t good enough). Instead of that, we’re now getting the inverse: monitor makers have started force-loading unasked bloatware and ads onto your PC:

“LG lost some trust after a recent report that some of its monitors installed McAfee pop-up ads onto connected computers. Since at least 2024, some of these displays installed an app, LG Monitor App Installer, onto connected computers under the cover of driver updates installed through Windows Update.”

In addition to convincing themselves that that was a good idea, monitor makers are also starting to push into the realm of “smart monitors,” or monitors with their own OS (and behavior tracking software), just like smart TVs:

“LG’s and Samsung’s smart monitors use the same ad-serving OSes that their respective smart TVs do, meaning they’re poised to use automatic content recognition (ACR). Users of LG and Samsung smart monitors, including reviews site RTINGs, have shown the displays being able to track user activity. I asked LG and Samsung if their smart monitors use ACR and will update this article if I get any responses.”

It doesn’t appear to matter that nobody actually asked for this. Or, at least, nobody asked for what this is ultimately going to become. And the companies certainly don’t want to transparently talk about the kind of data they’re collecting. But because tracking and monetizing your online behavior in a country with no modern privacy laws is so broadly normalized and profitable, you’re getting it anyway.

ICE, CBP Officers Prefer To Sexually Assault Children When Committing Crimes [Techdirt]

The “worst of the worst” are coming for the “worst of the worst.” Of course, this administration has completely given up on this pretense, despite sending out lots of noisy messaging otherwise every time an immigration officer murders a person.

For the entirety of Trump’s anti-migration surge, it’s been obvious that it’s all about expelling certain people and has nothing to do with ridding this nation of criminals. But there are quotas to meet. Trump is awful enough on his own, but he can’t read a spreadsheet. That’s why Stephen Miller exists: to apply the pressure Trump simply can’t stay awake to do himself.

For years, law enforcement officers at every level have abused their power and positions to violate the rights of regular people. That alone is a crime, even if it’s usually just considered a civil violation. Guess what else is a civil violation? Being in this country without having the proper paperwork or processes in place to comply with immigration law.

To keep up with demands for ever-increasing arrests, this administration has also engaged in hiring surges. The people responding to huge signing bonuses and the simultaneous lowering of training standards tended to be the people you expected them to be. And, as the DHS soon discovered, stripping standards and all but eliminating training that would be useful to new ICE/CBP officers, its pool of applicants ran from the sub-par to the absolutely criminal.

Given what else we’ve always known about how those with power seek out the weakest people to exploit and abuse — combined with the free pass courts now give to federal officers when they’re only violating civil rights — this new report that’s based on hundreds of criminal cases against immigration officers makes it clear a lot of the “worst of the worst” are employed by the federal government.

new report by the Ohio Immigrant Alliance, released today, pulls back the curtain on a stunning level of sexual criminal behavior within ICE and CBP. Out of 152 cases of identified immigration officials or contractors accused or convicted of criminal behavior, 131 of them, or 86.2 percent, were charged with sex offenses. Seventy-eight of them—51 percent of the entire cohort—”committed sex offenses against children—the single largest category on the list,” the report states. Cases involving a CBP officer, the report finds, “are more likely to involve underage victims” than those of an ICE officer. Yet fully half of ICE officers accused or convicted of sex offenses (12 of 24) had a minor as their victim.

As bad as this looks, it’s probably even worse. As the Ohio Immigrant Alliance report [PDF] notes, this only covers immigration officers who have actually been caught and are facing criminal prosecutions.

This means there are many more who just haven’t been caught yet. And the chances of them being caught has been drastically reduced in recent months. ICE’s OPR (Office of Professional Responsibility) has always been tasked with investigating complaints filed against ICE officers. It’s not just history. It’s the directive handed down by law, which now seems to be something the OPR can just ignore because it would rather investigate critics of Trump’s anti-migrant activities.

If you’re wondering how it gets so bad that most criminal allegations against immigration officers involve the sexual abuse of children, this is how we’ve reached what we can only hope is an inflection point.

First, there’s the Supreme Court, which has made it all but impossible to sue federal officers for rights violations, many of which include clearly criminal acts. Added to that is this administration’s absolute refusal to perform internal investigations, much less punish officers for excessive force, child molestation, or murdering US residents and citizens.

Now, I’m sure there will be dishonest comment brokers arriving to fill the comments with stupid stuff like “well, 152 officers is only X% of immigration officers, so this is actually a good thing.” They can fuck right off. I guarantee any commenter thinking this sort of thing is acceptable because it only involves a small minority of officers is also in favor of letting internet vigilantes beat/maim/murder anyone these amateurs happen to think might be seeking to harm minors. The Venn diagram of “get all the pedos” and “whatever Trump wants to do is fine” is pretty much a full eclipse.

In other words, it’s forgivable if a few ICE/CBP officers do this while engaged in God’s/Trump’s work. But anyone asking for gender-neutral bathrooms should be executed immediately because the only reason a trans person would ask for this is because they want to rape children.

And, in case you’re wondering, of course this isn’t all Trump’s fault. The lack of oversight and accountability has been a problem for years, reducing the deterrents from zero to less than zero. That being said, it’s been getting a lot worse since Trump took office for a second time:

All this, the report finds, is accelerating. Nearly 25 percent of examined criminal offenses tied to ICE and CBP happened during the second presidency of Donald Trump. More occurred in 2026 (22 so far) than in 2025 (14). Both years outperformed the previous peak year of 2024 (11). Still, the fact that the previous peak occurred during Joe Biden’s presidency testifies to Biden and the Democrats’ unwillingness to confront ICE and CBP.

To sum up, this situation was fucked from the get-go and it’s exponentially getting worse under the current [cough] “leadership.” And no one truly thinks Trump or anyone in his administration will look at this report and see a chance to improve things. Trump could try to beat Biden at his own “molested by an immigration officer” game, but this administration has already written off anyone subjected to violent acts (including sexual violence) by immigration as subhumans who just got what the deserved.

Expecting him to care about the steadily-increasing number of molestations by ICE or CBP officers is to expect the sun to rise in the west tomorrow. No one cares, because they never have. And this administration is capable of not caring at levels we’ve never seen before, to cop a favorite phrase of our current president.

10:00 AM

F-Droid goes FrOSCon [F-Droid - Free and Open Source Android App Repository]

FrOSCon 2026 in Sankt Augustin, Germany, was a first for F-Droid as well as for me. It was the first time F-Droid had a booth at FrOSCon, and it was also my first FrOSCon and my first time in Germany. Getting to spend the weekend representing F-Droid there with Sebastian made it particularly special.

Our booth was in a very good spot, between FlorisBoard and Phosh, with Ubuntu Touch nearby and Fedora directly opposite us. We also had postmarketOS nearby. It made for a lively part of the exhibition, with plenty of people moving between the different projects. The people around were especially lovely and were friendly, helpful and easy to talk to, which made the long, very hot days at the booth much easier.

FrOSCon has a strong hardware presence, and there was plenty to see across the exhibition. The Phosh & postmarketOS team were showing their operating systems on different devices, including demonstrations involving Waydroid and Android applications. It was nice having projects working on different parts of the free software mobile ecosystem so close together.

At the F-Droid booth, Sebastian and I spent most of the weekend talking to users.

Many visitors were already using F-Droid and came by to share their experiences or ask questions. Others were completely new to F-Droid, and we were able to help them get started. We came away with a good number of new users, which was one of the most satisfying parts of the weekend.

F-Droid 2.0 was a frequent topic. Several people came with questions or issues they had encountered, sometimes simply showing us what was happening on their phones. Android Developer Verification also generated a lot of discussion, with visitors interested in what it could mean for F-Droid and the future of app distribution on Android.

There was also a surprising amount of curiosity about what happens behind the app. People asked how F-Droid is managed, how we find the resources to keep the project running and how the project is funded. These conversations were particularly useful because they gave us an opportunity to explain some of the work that is less visible to users.

We did not receive donations directly at the booth, but we noticed generous donations arrive through OpenCollective around the time of FrOSCon. While we cannot attribute them with certainty, the timing and the conversations at the event make us confident that FrOSCon helped.

One thing I noticed compared with FOSDEM earlier this year was that FrOSCon gave us more time with individual visitors. FOSDEM has a much larger crowd, but at FrOSCon people could stop for longer and have a proper conversation. For a project like F-Droid, those conversations are valuable.

The heat certainly made the weekend memorable too. It was unusually hot in the region, including at the venue, but the people around us made it considerably easier to get through.

By the end of the weekend, we had met existing F-Droid users, introduced the project to new ones, had some very useful conversations about where F-Droid is heading, and spent a great couple of days with the wider free software community.

Thank you to everyone who stopped by the F-Droid booth, asked a question, shared an experience, or simply came over to say hello.

Finally, thank you to the FrOSCon organisers and everyone around us who made F-Droid’s first FrOSCon such a good one.

Kanji of the Day: 五 [Kanji of the Day]

✍4

小1

five

いつ いつ.つ

五輪   (ごりん)   —   Olympic Games
五百   (いお)   —   500
五十   (い)   —   fifty
五つ   (いつつ)   —   five
十五   (じゅうご)   —   15
第五   (だいご)   —   fifth
五穀豊穣   (ごこくほうじょう)   —   huge harvest (of the five grains)
五月   (ごがつ)   —   May
五感   (ごかん)   —   the five senses
七五三   (しちごさん)   —   festival (shrine visit) by children aged 7, 5 and 3

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 塊 [Kanji of the Day]

✍13

中学

clod, lump, chunk, clot, mass

カイ ケ

かたまり つちくれ

団塊世代   (だんかいせだい)   —   the babyboomers
団塊の世代   (だんかいのせだい)   —   baby boom generation (of 1947-1949)
金塊   (きんかい)   —   gold nugget
団塊   (だんかい)   —   mass
血の塊   (ちのかたまり)   —   clot of blood
氷塊   (ひょうかい)   —   lump of ice
一塊   (いっかい)   —   one lump
肉塊   (にくかい)   —   lump of meat
山塊   (さんかい)   —   mountain mass
岩塊   (がんかい)   —   mass of rock

Generated with kanjioftheday by Douglas Perkins.

07:00 AM

New Release: Tor Browser 15.0.21 [Tor Project blog]

Tor Browser 15.0.21 is now available from the Tor Browser download page and also from our distribution directory.

This version includes important security updates to Firefox.

Send us your feedback

If you find a bug or have a suggestion for how we could improve this release, please let us know.

Full changelog

The full changelog since Tor Browser 15.0.20 is:

  • All Platforms
  • Windows + macOS + Linux
  • Android
    • Updated GeckoView to 140.15.0esr
  • Build System
    • Windows + Linux + Android
      • Updated Go to 1.25.14

05:00 AM

Apophenia cuts both ways [Seth Godin's Blog on marketing, tribes and respect]

Apophenia is the uniquely human tendency to perceive meaningful patterns or connections in random or unrelated data, events, or objects.

Humans are story telling machines. And one thing we do is turn co-incident events into more than coincidences.

When we see faces and shapes in clouds, apophenia wastes our time in the form of pareidolia. There isn’t actually a teddy bear in that cloud, or a face in that grilled cheese sandwich.

On the other hand, our ability to make out patterns is essential when trying to understand a system. Systems are nothing but non-coordinated conspiracies, individuals following their interests in response to a culture that is shaped by individuals following their interests.

The skill worth developing is the insight to tell them apart. Useful stories when needed, uncorrelated noise when there’s nothing actually going on.

      

Running The Pentagon Into The Ground [The Status Kuo]

I’m writing today for The Big Picture about the wave of dysfunction hitting the Pentagon this week and what it says about Secretary of Defense Pete Hegseth’s grip on the department.

It’s been a lot to keep track of. Army Secretary Dan Driscoll resigned this week after months of friction with Hegseth, reportedly after speaking directly to Trump about serious senior personnel issues. The Washington Post also reported this week that the Pentagon has quietly installed conservative influencers in undisclosed government roles to help amplify Hegseth’s messaging and attack his critics. And four of Hegseth’s senior military leaders have formally objected to his order extending U.S. forces in the Middle East. All of this follows a monthlong debacle over conditions aboard the USS Abraham Lincoln.

Six months into the Iran war, most of the attention on the Pentagon has understandably gone to the war itself. But that may be obscuring what’s happening inside the building, which is just as big a story.

Look for my piece this afternoon if you’re a subscriber to The Big Picture. If you’re not, you can sign up for free or become a valued paid supporter of our work here: https://thinkbigpicture.substack.com/subscribe

I’ll be back tomorrow with my regular edition of The Status Kuo.

Jay

04:00 AM

X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching [Techdirt]

When Twitter launched, it was originally designed to be just like an open protocol. In the early days, the company eagerly supported third party development, building on that protocol. But, because it was a new communications protocol totally controlled by a single company, eventually commercial pressure led the company to close off the openness. Jack Dorsey later admitted that this was a mistake, and he hoped that Twitter would go back to being an open protocol. That eventually led to the rise of Bluesky (where I am now on the board, having taken Dorsey’s old board seat) and the ATprotocol (along with some other competing protocols, each with a different implementation, but all believing in the value of open social systems).

And, of course, in the middle of all this, Elon Musk took over Twitter. You may remember that. Even though Jack Dorsey supported Elon’s bid, and suggested he embrace the open protocol aspect of where Twitter was heading, Elon went in a very different direction.

Text messages between Jack Dorsey & Elon Musk in which Dorsey advocates that Twitter "must be an open source protocol"
Text messages between Jack Dorsey & Elon Musk in which Dorsey advocates that Twitter "must be an open source protocol"

It’s funny now, four years on, to read those text messages between Jack and Elon, with Jack pushing for Elon to embrace reinventing Twitter as a decentralized open protocol, and Elon nodding along.

But, of course, that’s not what happened. Instead, what happened was Twitter became X, the personal, centralized, deliberately political project of Elon that no longer had any real resemblance to an open communications protocol. Almost immediately upon taking control, Elon began locking things down, and putting very high prices on access. There have been many changes to the API (and its pricing) since Elon took over the company (which eventually merged into xAI and then into SpaceX), but the one constant is that it’s a walled garden, focused almost exclusively on promoting the things Elon wants promoted, while demoting the things he’s scared of.

This has been known and somewhat obvious for years. But last week, it appears Elon put the final nail in the coffin for the belief that X might one day be an open protocol ever again. There were two widely known and widely used services for sharing posts on X without having to point people to X itself: Nitter and Xcancel. With both of them, if you wanted to share any particular tweet, you could just replace the “X.com” part of the URL (or the “twitter.com” part before that got rerouted) to either “nitter.net” or “xcancel.com” and you could see the same tweet (and the same thread above and below it) without giving Elon any of the traffic.

If you are an open protocol, that’s how it should work. Indeed, if you want to read Bluesky posts without ever touching Bluesky itself, there are already a bunch of independent ways to do it — different clients, different frontends, different views on the same underlying data — with more coming online all the time.

But, just to make it clear that X is a walled garden completely controlled by Elon and no one else, last week, X sent cease & desist notices to both Nitter and Xcancel, causing them to shut down.

That’s Nitter saying:

Cease and desist

On 24 August 2026 cease and desist letters have been sent by X Corp. demanding a permanent takedown of Nitter instances and the project’s repository.

nitter.net is offline and development has stopped for the time being. I’m seeking legal advice and won’t be commenting further on the specifics for now.

Thank you to everyone who used, hosted, packaged, donated and contributed to Nitter over the past seven years.

Xcancel just put up some text saying something very similar:

On Monday 24th August at 8PM EST, we received at letter from X Corp. asking to cease and desist the service XCancel.
The service XCancel is stopped until further notice.
We are seeking legal advice and won’t share more details for now.
Thank you for the trust you have put in these two years of XCancel.

This does real harm to many people, not just those who didn’t want to support Elon Musk. Many journalists and researchers would use these tools to track things in ways that Elon’s platform might not allow (or for which he might ban users). And, as Elon has continually locked down X, many things now require a login to view. It also makes a mess of many archives, including Wikipedia citations, that frequently relied on Nitter links.

While the cease and desist letters have not been publicly revealed, TechCrunch claims they were able to see them, and they accused the platforms of circumventing X’s API restrictions.

The letter from X, which TechCrunch has viewed, accuses Nitter of an “unlawful use and circumvention of X’s Application Programming Interface (API) and associated data,” through its service, saying that X has evidence that Nitter scraped X data and accessed X accounts and session tokens in violation of X’s rules.

Lawyers for X said the actions are in violation of “various state and federal laws, including, but not limited to, the Texas Harmful Access by Computer Act (§ 143.001 and § 33.02) and the Lanham Act (15 U.S.C. §§ 1114, 1125).” The letter gave Nitter until 5 p.m. EST on August 25 to shut down.

The legal theories here are basically bullshit. The “Harmful Access by Computer Act” is basically a Texas state version of the CFAA, the deeply problematic federal “anti-hacking” law that is regularly abused to stop people from doing things that should be perfectly legal. And while there have been some cases, like the Power Ventures case, that blessed the idea that such laws can block scraping, courts have been much more open to saying that there’s no hacking in merely scraping openly available web pages, such as in HiQ v. LinkedIn.

In fact, Musk and his lawyers should know all this is bullshit, because he lost his earlier lawsuit against Bright Data over scraping X.

The Lanham Act (trademark) claims seem equally bullshit. There’s zero likelihood of confusion here. The reason people use these sites is not because they confuse them with X, but deliberately because they are not X. And, to whatever extent either site referred back to X (or Twitter), that would be nominative fair use as accurately describing the source of the content.

Still, most of that is besides the point. X doesn’t need to actually win in court. Elon just needs it to be more expensive to fight him. And given that he literally has more money than anyone else in the world (and most companies to boot), there is no fair fight between a legal threat from him against a volunteer maintainer of an open source project.

But this is how walled gardens get built. X isn’t building a better product. It’s using Elon’s vast resources and ability to conjure up legal threats to shut down any system that enables openness.

To be clear, X is hardly alone in doing things like this. And some of it is absolutely due to the rise of AI scrapers and the desire of companies to sell access to their data. Reddit famously made a bunch of changes to its API a few years ago to limit access, and recently cut access even more. The widespread walling off of the open internet to fight AI scrapers is going to have some long-term negative consequences.

But rather than accept this, it should be even more incentive to embrace the tools that put us, not large companies, in control over our data.

Paul Frazee, Bluesky’s CTO, and an instrumental player in creating the ATprotocol that powers Bluesky and a bunch of other “locked open” apps recently wrote about this on Leaflet (a long-form blogging platform also powered by ATprotocol), in an article he called SELECT * FROM internet.blogposts. In that article, he highlights how the web has turned into a bunch of silos, and more and more of them keep locking the door:

The walled garden problem is downstream of a simple question: how do I SELECT * FROM internet?

If you’ve never written database code, SELECT * FROM users is how you ask a database for everything it knows about its users. Once you have it you can filter it, sort it, and join it against anything else you’ve got.

The web doesn’t historically work that way. The web is a few dozen companies, each holding a filing cabinet, each with a receptionist posted out front. He’ll read you one file at a time, but only files you can name, as fast as he cares to read, and as long as his boss allows.

The fact that “the web doesn’t historically work that way” is a historical error. Indeed, for many years, most people did think it worked that way. Google’s existence is kind of premised on the fact that it absolutely could ‘SELECT * FROM internet’ to build its index. The entire premise of the open internet was that everything could be indexed and searched, even if the SQL query were hidden behind a nicer UI.

But now, various companies (including Google!) have used a variety of both technical and legal measures to wall things off again.

Open protocols do a lot of useful things, but the most important may be that they lock the openness in place, so that no single company can send a legal threat letter and revoke it. A system like ATprotocol doesn’t rely on APIs controlled by a single company that can change them or cut off a provider. Instead, it corrects one of the original sins of the web: rather than one company holding all the data for a particular service, anyone can hold it. You can hold your own data (many people do) or you can let someone else (such as Bluesky) hold onto it, though in a manner where you can always take it out of their control, and host it yourself or somewhere else.

This is one of the reasons why I find ATprotocol so exciting. People looking at it as just a new way to build a Twitter clone have always missed the point. It’s a way to rebuild the entire web, where the users have way more control. Rather than handing over control to a new or different company and hoping they don’t enshittify, the entire setup is enabling the end users to have full control over their own data.

Killing off Nitter and Xcancel is the last step in Elon’s transformation of Twitter from something that wanted to be a new, open communications protocol, to “X,” a locked up, private platform tuned to the whims of a wealthy propagandist.

Every few months or so, someone writes an article about why you should get off of X, because every bit of engagement there feeds money, data, and influence to the world’s richest man in service of his fascistic political project, or because its algorithm is directly programmed to make you angry about stupid shit.

But I think there’s a more important reason: X’s transformation from a kind of open decentralized communications protocol to a closed bullshit delivery mechanism is symptomatic of many of the things going wrong in the world today, from the enshittification of all sorts of products and services, to the rise of authoritarianism around the globe.

Getting power back in the hands of the public doesn’t happen by further empowering the controllers of today’s data silos. Elon’s not going to help give you more power if you ask him nicely. Getting the power back means building and using the tools that make permission irrelevant in the first place.

Daily Deal: The All-in-One Super-Sized Ethical Hacking Bundle [Techdirt]

To completely understand computer security, it’s vital to step outside the fence and to think outside the box. Computer security is not just about firewalls, Intrusion Prevention Systems, or anti-viruses. It’s also about tricking people into doing whatever a hacker wishes. A secure system, network, or infrastructure is also about informed people. The All-in-One Super-Sized Ethical Hacking Bundle will help you learn to master ethical hacking techniques and methodologies over 14 courses. It’s on sale for $28 for a limited time.

Note: The Techdirt Deals Store is powered and curated by StackCommerce. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

RSSSiteUpdated
XML About Tagaini Jisho on Tagaini Jisho 2026-09-03 11:00 AM
XML Arch Linux: Releases 2026-09-03 10:00 AM
XML Carlson Calamities 2026-09-03 10:00 AM
XML Debian News 2026-09-03 12:00 PM
XML Debian Security 2026-09-03 11:00 AM
XML debito.org 2026-09-03 12:00 PM
XML dperkins 2026-09-03 06:00 AM
XML F-Droid - Free and Open Source Android App Repository 2026-09-03 10:00 AM
XML General Union 2026-09-03 07:00 AM
XML GIMP 2026-09-03 10:00 AM
XML Japan Bash 2026-09-03 11:00 AM
XML Japan English Teacher Feed 2026-09-03 11:00 AM
XML Kanji of the Day 2026-09-03 10:00 AM
XML Kanji of the Day 2026-09-03 10:00 AM
XML Let's Encrypt 2026-09-03 10:00 AM
XML Marc Jones 2026-09-03 10:00 AM
XML Marjorie's Blog 2026-09-03 10:00 AM
XML OpenStreetMap Japan 2026-09-03 10:00 AM
XML OsmAnd Blog 2026-09-03 10:00 AM
XML Pluralistic: Daily links from Cory Doctorow 2026-09-03 11:00 AM
XML Popehat 2026-09-03 10:00 AM
XML Ramen Adventures 2026-09-03 10:00 AM
XML Release notes from server 2026-09-03 10:00 AM
XML Seth Godin's Blog on marketing, tribes and respect 2026-09-03 06:00 AM
XML SNA Japan 2026-09-03 06:00 AM
XML Tatoeba Project Blog 2026-09-03 11:00 AM
XML Techdirt 2026-09-03 12:00 PM
XML The Business of Printing Books 2026-09-03 10:00 AM
XML The Luddite 2026-09-03 10:00 AM
XML The Popehat Report 2026-09-03 06:00 AM
XML The Status Kuo 2026-09-03 06:00 AM
XML The Stranger 2026-09-03 10:00 AM
XML Tor Project blog 2026-09-03 12:00 PM
XML TorrentFreak 2026-09-03 11:00 AM
XML what if? 2026-09-03 11:00 AM
XML Wikimedia Commons picture of the day feed 2026-09-01 01:00 PM
XML xkcd.com 2026-09-03 11:00 AM