News

Friday 2026-09-04

11:00 AM

Using QR Codes to Sell Your Books [The Business of Printing Books]

Using QR Codes to Sell Your Books

The Direct Buy Button is Lulu’s fast and easy way to make your book available for sale anywhere. Literally, you publish on Lulu, link your account to a Stripe profile, and we build a checkout for your book. 

One really cool thing that the Buy Button unlocks is the ability to use QR codes to sell your book.

Yes, you’ve always been able to link a QR code to a Lulu Bookstore listing, a retail site, or to your personal website if you’re using Lulu Direct. The Buy Button just makes the process significantly easier. 

Have you ever thought about using a QR code to sell your book? If you answered yes, this post is for you. Keep reading.


How Do QR Codes Work?

The term ‘QR Code’ is short for Quick Response Code. And, according to Wikipedia, it was invented in Japan to label auto parts in the mid-90s. That’s a factoid I didn’t know until recently; I guess I’d just never questioned what the ‘QR’ stood for. 

Anyway, a QR code is a two-dimensional image that points to a web location. It’s similar to a barcode, but the key difference is that a barcode contains specific, unique information about a product while the QR code is an online redirect. That allows for a much broader range of uses, including capturing data from scans and pointing to relevant pages.

Essentially, when a person scans the QR code with their phone camera, they’ll have the option to open the associated webpage. 

For content creators and marketers, QR codes are an amazing tool. They enable smoother mobile interactions—you really can’t expect someone to see a URL and physically type it into their phone’s browser, can you? And they help you gather traffic data to see whether your QR code is effective. 

And they’re a great way to rickroll your coworkers

Using Lulu to Create QR Codes for Your Book

You’ve always had the option to publish your book to the Lulu Bookstore and share the link to that page through a QR code. But those pages are static, controlled by the team at Lulu, and are limited to just the details we can present. 

When you use the Direct Buy Button to create a distinct URL just for your book, you control the entire experience. It will open in a checkout experience powered by Stripe and allow someone to instantly buy your book. Here’s an example:

Using QR Codes to Sell Your Books

Your Buy Button is built by first publishing a print book or calendar on Lulu, then setting up a sales channel on Lulu and connecting it to a Stripe account, and finally by connecting your project to that sales channel. 

It’s really very simple. Here’s a detailed walkthrough video that will outline the process for you.

Once you’ve completed the process, you’ll be able to generate a Direct Checkout link for your book. This is the URL that will create a single, unique checkout experience for your shopper.

Sell Your Book with Direct Buy Button | Lulu
The easiest selling solution. Sell books directly to buyers on your site or newsletter with a buy button, on social media with a link, or in-person with a QR code.

Why is that valuable?

First off, you keep 100% of the revenue. Your buyer pays your retail price for the book, plus shipping and any processing fees. 

More importantly, you can use this code anywhere. Sell your book from your social profile, your email newsletter, or, as you probably guessed, through a QR code. 

Create a QR Code

Once you’ve got your Direct Buy Button all set up, you’ll have the option to create an embedded cart that looks just like any other product page. You can fully customize this with unique colors, fonts, text, and more.

Using QR Codes to Sell Your Books

But you can also grab that single URL, the Direct Checkout link that will create the checkout for your book I mentioned earlier.

Using QR Codes to Sell Your Books

That URL is perfect for creating a QR code. And it's so easy I can explain it in two steps:

  1. Take your URL to a QR code generator.
  2. Generate the QR code and share it.

That is literally it.

Deciding How to Create Your QR Code

There are two different kinds of QR codes: static and dynamic. As the names imply, a static QR code is connected to one unique URL and only that one unique URL. Dynamic QR codes use a URL that redirects to your content, passing through the QR code platform.

Both styles have uses, so you’ll want to carefully consider what you’ll be doing with your QR code.

Static QR Codes

When you create a static QR code, you’ll have that code with one URL attached to it. Forever. 

These are great for sharing a link that you’ll never change. Like sending people to the homepage of your website or a product page for one of your books. 

The biggest benefit of static QR codes is that they are free. If you find a site that tries to charge a fee for a static QR code, I would not even consider using it. The platform that creates the code for you probably won’t offer any tracking or analytics, but you can still add a UTM tag to the URL for that tracking.

Dynamic QR Codes

You should use a dynamic QR code when you know you’ll need the flexibility to change the destination URL or if you want the extra analytics.

Most QR code platforms will charge for dynamic codes or only offer a limited number of these codes for a free account. 

Dynamic QR codes are usually more useful for larger businesses with multiple products listed through QR codes, a greater need for in-depth data, and the budget to pay for the service.

QR Code Generator Options

There are a lot. You should do some searching and review the different options. But to get you started, I’m going to quickly review four options that are pretty common and work well.

QR Code Monkey

This is my top pick for a simple, free option. QR Code Monkey is very easy to use, offers a variety of language options, and includes background info about QR codes to ensure you understand how best to use your code. It offers a range of specific QR code types—like linking to an address or wifi access.

The QR codes you generate are static, but QR Code Monkey has good customization choices for the code design.

Adobe Express

You’re probably familiar with Adobe Express. It’s Adobe’s answer to Canva’s free design tools. Adobe’s QR code generator is very simple; you just insert a link, and it generates a code.

But you also have the option to open your new code in Adobe Express and edit it with their image tools. This is interesting, as it opens you up to creating designs around your QR code. Like a poster, business card, or bookmark. The downside is that you’ll be faced with Adobe’s near-constant attempts to get you to subscribe. 

Canva

Like Adobe, Canva also has the ability to generate a QR code for you. Their QR code options require you to use one of their ‘apps’ within your Canva account. 

Their designer is incredibly simple, though you can always use some of the other QR code apps within Canva. The code is dropped directly into a new or existing design, but is not easily downloaded for use in designs outside of Canva.

Bitly

Finally, we have the most popular and ubiquitous linking platform: Bitly. Known for its link shortening tools, Bitly’s QR code generator is very robust. You’ll create dynamic codes, up to 2 per month for free before you need to use their paid tier.

Overall, Bitly is probably the most powerful option for just QR codes. 

Selling Your Books Everywhere.

The Direct Buy Button is meant to be the easiest, fastest way to list your book for sale on your own site. Our goal is to make direct selling available for anyone. QR codes are just another part of the wide options you’ll have to sell your books. 

With a single URL for your book, you can use any QR code generator to create and share a code that links directly to a checkout experience. That includes at in-person events, on a business card, even in another of your books! 

Searching complexity and Taler update [F-Droid - Free and Open Source Android App Repository]

This Week in F-Droid

TWIF curated on Tuesday, 01 Sep 2026, Week 36

F-Droid core

F-Droid and F-Droid Basic were updated to 2.0-rc1 with a fixes focused changelog. After our last TWIF we’ve sneakily promoted 2.0-rc0 as suggested for Basic updating all its users to our latest code. This made users happy to experience our improved app and made us happy to receive more crashes and issues reports. Having more people to test the UX and more devices/Android combinations to run the app help F-Droid get better.

Search has been one area that was greatly improved, with a better UX, better filtering and great results that pull info from categories and app data. So imagine our surprise when the user feedback was “search results make no sense” or worse “I get no results at all”.

We’ve posted a few days ago two test queries to exemplify how search should look. If you’ve updated to latest 2.0-rc1 and you don’t see any results, we are tracking this issue here. We’ve rarely seen random or unrelated search results in our testing before, and a fix was deployed for such cases, a database cleaning procedure that should run by itself daily, if necessary. The challenge for us now is to find out why some Android devices don’t run the fix, and we are gathering info in this issue. If you encounter any of these or any other problem, make sure you add your device info (model and Android version) to the existing open issues or to new ones. If Gitlab is grumpy and you can’t, you can still ping us on Fedi, Forum or anywhere else.

As part of our NLnet-funded GNU Taler project, we’ve completed a deliverable: exploring and implementing Taler support in the F-Droid client. App developers can try this now by getting an account for receiving Taler-based donations and publishing their Taler donation link in app metadata.

Community News

Catima — Loyalty Card Wallet was updated to 2.45.0 (F-Droid) and its dev, TheLastProject, wanted to add some news:

Catima 2.45.0 was released with Wear OS support (and switched to Reproducible Build on F-Droid). This marks the first time a Wear OS application is released to F-Droid.

Although Wear OS is a proprietary platform with no FOSS custom ROMs like Lineage and the likes available for it, it is based on Android and therefore you can basically write apps for it the same way you do for Android.

While there is no F-Droid client which supports Wear OS at this point, you can install the Wear OS Catima companion app from F-Droid (v1.0.0 Wear OS), enjoying the same general F-Droid confirmation that the app really is FOSS. Alternatively, if you have a smartphone that’s supported by Gadgetbridge, you can use Gadgetbridge support in Catima, which has existed since 2013 and is much more private than Wear OS is: Loyalty cards / passes.

For those curious about writing Wear OS apps without proprietary Google libraries, see our documentation.

Do you use Wear OS and how do you currently find FOSS apps for it and how do you install them? Let us know!

NOTE: Based on the lower versionCode of the Wear app, it will end up in the Archive repo at some point

Daniel Gultsch, the developer of Conversations has posted a 15 minute piece that’s worth a read, about digital independence and what 25 years of XMPP brings us. While we can hear echoes that very much define F-Droid too, like self-hosting, decentralization and federation, we have yet to dream of an IETF standard for “app distribution”. But if that time comes, will we have your vote?

GPSTest was updated to 3.10.6 after more than one and a half years. The changes are meant to maintain the app running in tip top shape.

Status - Chat, Wallet, Browser, Privacy super app with messenger, crypto wallet, browser, communities & more, was just added. Does the name seem familiar? It should, this is the brand new version of the app, a total rewrite as a separate app. You can read the introduction and migration post, and yes, you saw that date right, we’ve been collaborating with the developer since January to bring this app to F-Droid, and built reproducible! Since the old version a lot has changed, more than we could cover here, so do a deep-dive in past posts to get yourself up to date.

@ROllerozxa jumps on voxels to bring us the news:

Luanti was updated to 5.17.0 and users are advised to update immediately as it fixes security vulnerabilities affecting both the client and server. You can read the change-log here. Also please make sure your friends and game peers also update, specially users that have the app installed from other centralized stores, as we heard rumors not only that the update is not available there but that the app was outright removed on baseless accusations. Did anyone mumble “keep android open“?

Archived Apps

2 apps were archived
  • My Brain: Productivity app for Tasks, Notes, Calendar, Diary, Bookmarks and more (App will include proprietary libs)
  • NotallyX - Quick Notes/Tasks: A simple and minimalistic open source notes app (Developer wants to find and fix crashes, will come back soon)

Newly Added Apps

104 more apps were newly added

Being busy with daily updates, fixes, reports, upstream feedback, client 2.0 development and more, did slow down our rate of new apps inclusion. Yes, the backlog is huge, but we thank the contributors helping to review and the developers for having patience with us.

  • 500 - Multiplayer card game: Play 500, the Australian trick-taking card game — bots or friends online.
  • 5G Proxy Pro: Share your phone’s 5G/4G over Wi-Fi via SOCKS5 proxy. No root, TCP/UDP, LAN-only
  • Adiresy: Find, share and navigate to Madagascar’s community address codes
  • Ambio: Focus Timer & Sounds: Blend up to 3 of 12 ambient sounds into a focus soundscape you build yourself
  • Argus: Natural-language automation compiled by an LLM, run by a deterministic engine.
  • auth’s RNG: roll for rarities, sell them, buy upgrades. an incremental RNG game.
  • AutoPie: Swiss Army Knife For Linux on Android Automation.
  • Backgammon Clock: A flexible two-player backgammon match clock and scorekeeper.
  • Baly Groceries Tracker: monitor stock levels, and never worry about running out
  • Bati — Fitness RPG: Turn workouts into quests, boss fights and a village built by your training.
  • BayesianBahn: Empirical arrival-time distributions for Deutsche Bahn trains
  • Bike Radar: Overlay and audio alerts for BLE bike radars. Offline, no account, no cloud.
  • Boardgame Pal: Dice, score counter, starting-player draw & more – 100% free and ad-free!
  • Bubble Penetration: Fast arcade action: collect colors, chain combos, beat the highscore.
  • Bugbane Beta: Beta channel of Bugbane, a guided forensic self-triage tool
  • Cairn: Health Aggregator: Aggregate your health data into open files in your own Nextcloud
  • Chat Room: Real-time messaging client with text and file sharing.
  • Clear SMS: Privacy-first SMS app with smart inbox, finance dashboard and bill reminders
  • Croustillapp: Access menus, addresses, and contact info for nearly 1,000 CROUS restaurants.
  • DAVY - Daika Anime Viewer because YOLO: Lightweight, open-source anime player for Android TV.
  • Debate Timer: A minimalist timer, so you can focus on speaking.
  • Denaro: Private, offline personal finance with accounts, categories and insights.
  • Diadem: Connect to any Diadem Map
  • Einstein’s Riddle: Einstein’s Riddle (also known as the Zebra Puzzle)
  • ekklesia — Direct Democracy: Anonymous civic participation for Greek citizens
  • Emborg: Org-mode viewer and task manager
  • Enclavd: Personality Social Network
  • Esca Agnellis: Local food-pyramid tracking with backup, PDF and an optional companion
  • Fechtkarte: Warm-up drill card generator using notation credited to Joachim Meyer
  • FediDay 2026: A timetable app for Berlin FediDay
  • FilmFlip: Film negative photo recovery app
  • Fortune Telling: Offline Western astrology, I Ching divination, and Chinese daily almanac
  • Fossify Documents Beta: Read PDF, DOCX, text, Markdown, CSV and HTML files privately and offline.
  • Fractals by Girino FOSS: Explore Mandelbrot and related fractals offline
  • FreeView: Read Medium articles for free through your choice of reader service
  • Gravel: A de-googled, hardened fork of the Pebble companion app for de-googled phones
  • Ham Test: Prepare for and pass all three US Amateur Radio license exams
  • Huda: Prayer times, Quran, Qibla, Tasbih, Adhkar and more — your Islamic companion
  • Håck mas Castle 2026 Fahrplan: Eine Fahrplan-App für Håck ma’s Castle 2026
  • I Keep Having This Dream: Build a path of tiles to escape each cycle of a dangerous recurring dream
  • IM2SMS: A simple app to import IM chat histories into your device SMS storage.
  • Infra Arcana: Infra Arcana - a Lovecraftian horror roguelike
  • InselChaos 2026: A timetable app for the InselChaos conference
  • Iris Gallery: Fast, private, 100% offline gallery with photo editor and EXIF inspector
  • Iris Keyboard: Advanced FOSS keyboard with AI Copilot, translation, and key sound synthesis
  • just open links in a browser: Sends links to your real browser instead of an app’s built-in one
  • Kinetica: Two-thumb keyboard: both thumbs swipe and tap at once. No network access.
  • Kiosk: A Hacker News reader
  • Lavender Photos: A no non-sense, stylish, and performant gallery app
  • Levyra: Native music streaming, playback, lyrics, downloads, and private insights
  • Libre Contacts Backup: Offline and encrypted contact backups
  • LibreNotes: Private, self-hosted, end-to-end encrypted note-taking.
  • LimeLog: Track your lifts and beat your personal records
  • Luteal: Private, offline-first cycle tracker separating facts from estimates
  • Matrix Puzzle: A minimal, open-source matrix puzzle game also known as floor puzzle
  • Meditate: Meditation timer with session log, stats, and Nextcloud sync
  • Megrim: Migraine Log: Private, offline migraine log with automatic on-device pattern insights.
  • Mercurygram Tor Plugin: Tor companion plugin that routes Mercurygram traffic through the Tor network
  • MinkLauncher OpenSource: A minimal, keyboard-first home-screen launcher
  • Mirror: Multiprotocol backup application (NFS, SMB, FTP, SFTP, WebDAV)
  • MJ PDF: A simple PDF viewer
  • mqvpn: Multipath VPN combining Wi-Fi and cellular for bonding and failover
  • Navic: A modern Navidrome client
  • Night Drop: Anonymous, end-to-end encrypted 1:1 chat over Tor
  • Ordunte: Karrantza weather: Weather at your location and four hyperlocal Karrantza/Ordunte sections
  • Pause: A short, timed pause before chosen apps open, so opening is deliberate.
  • PocketTracker: Tracker-style music maker for handhelds and phones — sampler, SF2, 8 tracks
  • Point Forecast: NWS point forecasts with maps, tides, and weather hazards
  • Privacy Kit Lite: Configure local privacy-related runtime hooks for LSPosed
  • Privacy QR And Barcode Scanner: Fast, offline QR code and barcode scanner - no tracking, no ads
  • Pulse: Garmin watch companion — your data stays on your phone
  • Quits: Quits is a privacy-preserving expense splitting application
  • RapidSplit: Split trip costs fairly: per leg, not flat. Offline, no account needed.
  • Relatrix: An active knowledge-management and multi-modal note-taking platform.
  • Renkin: Make your own icon pack, on your phone
  • Reverb: Rolling audio recorder
  • Ring-R: Create custom ringtones from your favorite Youtube videos
  • Roue Libre: Bike sharing: offline map and journeys, with no tracker.
  • scrcpy: Mirror a second device over wireless ADB. No root required.
  • Sehat: Sehat (Urdu for health): Track steps, heart rate, and meditation, all privately.
  • Shopping List Calculator: Plan grocery trips and track the total as you shop.
  • SideDeck: Free DJ app. Mix on your phone. No subscriptions.
  • Skylib: An alternative Bluesky frontend
  • Smart Radio Telescope: Control an Az/El/polarization radio telescope mount over your local WiFi
  • SMSecure: Privacy-focused SMS app with encrypted conversations
  • Solid Share: Files, contacts and passes on your own Solid pod, shared on your terms
  • Stopptanz: Freeze Dance & Musical Chairs music timer, fully offline
  • Sudoku You: Offline Sudoku with logical hints, advanced notes and flexible import/export
  • SyncRecord: Create synchronised ad-hoc microphone arrays using multiple smartphones.
  • T2DECODE: Offline interactive learning platform for IT, Cybersecurity, and Networking.
  • Tickdroid: Daily habit tracker for Nextcloud
  • Tine: Fast local-first Logseq-compatible outliner
  • Tuisku: A simple and lightweight encrypted notes app
  • Tuner: A simple and precise tuner
  • Unmark: Remove watermarks and unwanted objects from photos, entirely on-device
  • Vadhod APK Extractor: Offline, privacy-first APK extractor with proper split-APK support.
  • Vault Explorer: Encrypted container explorer: VeraCrypt, LUKS, BitLocker, and more.
  • Vibe - Music Player: Fast, minimalist local music player, 100% offline.
  • Vibecheck: Private Mood Tracker: Private, local-first mood and symptom tracker. No account, no cloud.
  • Void Player: Modern, high-performance music player with dynamic UI
  • Work Profile VPN Switcher: Automatically manage work profile when VPN connects or disconnects
  • ylih - your life in headphones: Track how many hours each pair of headphones lasts. Offline, forever, private
  • Yumi Co. Radio: Future Funk, City Pop and more, live 24/7 with chat and Android Auto.
  • 随机姓名: 随机中文姓名生成器

Updated Apps

630 more apps were updated
(expand for the full list)

Thank you for reading this week’s TWIF 🙂

Please subscribe to the RSS feed in your favourite RSS application to be updated of new TWIFs when they come up.

You are welcome to join the TWIF forum thread. If you have any news from the community, post it there, maybe it will be featured next week 😉

To help support F-Droid, please check out the donation page and contribute what you can.

Kanji of the Day: 談 [Kanji of the Day]

✍15

小3

discuss, talk

ダン

相談   (そうだん)   —   consultation
会談   (かいだん)   —   talks (i.e., formal discussions)
冗談   (じょうだん)   —   joke
対談   (たいだん)   —   talk
首脳会談   (しゅのうかいだん)   —   leadership conference
懇談会   (こんだんかい)   —   social gathering
面談   (めんだん)   —   interview
体験談   (たいけんだん)   —   story of one's experience
談話   (だんわ)   —   talk
余談   (よだん)   —   digression

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 符 [Kanji of the Day]

✍11

中学

token, sign, mark, tally, charm

切符   (きっぷ)   —   ticket
終止符   (しゅうしふ)   —   full stop
音符   (おんぷ)   —   musical note
疑問符   (ぎもんふ)   —   question mark
符号   (ふごう)   —   sign
免罪符   (めんざいふ)   —   indulgence (esp. in the Catholic Church)
終止符を打つ   (しゅうしふをうつ)   —   to put an end (to)
符合   (ふごう)   —   agreement
護符   (ごふ)   —   talisman
片道切符   (かたみちきっぷ)   —   one-way ticket

Generated with kanjioftheday by Douglas Perkins.

OsmAnd 5.4 (iOS) [OsmAnd Blog]

OsmAnd 5.4 for iOS — Now Available!

This update brings a redesigned My Places interface, a rebuilt Plan a Route tool, the new Astronomy plugin, and many other improvements and bug fixes.

🔄 Update Now

OsmAnd 5.4 for iOS

What's new

New "My Places" design

The My Places screen has been redesigned with a new segmented interface, making it easier to switch between Favorites, Tracks, OSM Edits, and Travel Guides.

  • Favorites now use a folder-based structure with support for subfolders. Folders are organized into Pinned, Visible, and Hidden sections, and frequently used folders can be pinned to the top. Each folder displays useful statistics, including the number of subfolders and points, modification date, and storage size. New sorting options allow folders and points to be arranged by name, date, or distance.

    Updated action menus provide quicker access to Show on map, Pin or unpin, Rename, Appearance, Share, Move, and Delete. Favorites and entire folders can also be added to Map markers, a Track, or Navigation. Selection mode makes it possible to apply actions to multiple folders and points at once.

  • Tracks provides access to saved, recorded, and imported GPX files from the same redesigned My Places interface, with search, sorting, folder management, statistics, and quick actions for working with individual tracks or multiple selected items.

  • OSM Edits keeps your OpenStreetMap edits, notes, and uploaded changes in a dedicated section. This tab is available when the OSM Editing plugin is enabled.

  • Travel Guides contains bookmarked travel articles and guides, allowing saved travel content to be accessed directly from My Places. The tab appears when multiple guides have been bookmarked.

The new search interface also makes Favorites easier to find by displaying their folder, distance, address, and creation date directly in the results.

Favorites menu iOSMy Places with tracks in iOS

Updated "Plan a Route" interface

The Plan a Route tool has been rebuilt with a new interface for creating, editing, and analyzing routes.

Separate Route + and + POI actions let you add route points or named waypoints and points of interest. Individual route segments can use different routing types, allowing you to combine, for example, cycling, walking, and straight-line sections within the same track.

The new panel includes three sections:

  • POI — manage waypoints and points of interest added to the track.
  • Analyze — view the elevation graph, uphill and downhill values, altitude range, speed statistics, and route composition by road type, steepness, surface, and smoothness.
  • Route — view and manage route points and segments.

Plan route

When elevation data is unavailable, it can be calculated using nearby roads or downloaded Terrain maps. The updated route summary also displays distance, estimated travel time, arrival time, elevation gain, and elevation loss.

Plan route

Quick actions provide access to undo and redo, change segment order, reverse the route, append it to an existing track, save a copy, clear all points, or start navigation directly along the planned track.

Astronomy plugin

The Astronomy plugin is now available on iOS. It provides an interactive Star Map with stars, constellations, the Sun, the Moon, planets, nebulae, star clusters, and other deep-sky objects.

Explore celestial objects using categories, catalogs, and the Watch now section. Detailed object information, visibility graphs, daily paths, direction indicators, Favorites, and a weekly observation schedule help you find objects and choose the best time for stargazing.

Enabled plugin (Menu → Plugins → Astronomy) → Menu → Star map

Astronomy PluginAstronomy Plugin

New "Terrain shadows" visualization

The new Terrain Shadows visualization provides real-time dynamic shading based on 3D terrain geometry. Unlike raster Hillshade maps, the shadows are generated directly on the device and automatically adapt to the current map perspective.

This visualization makes mountains, valleys, ridges, and other terrain features easier to distinguish while maintaining a low impact on performance. 3D Relief is required and is enabled automatically when Terrain Shadows is selected.

Menu → Configure Map → Topography → Terrain → Visualization → Terrain Shadows

Terrain shadows iOS

Color palette for Tracks and Terrain

OsmAnd 5.4 for iOS introduces a built-in Color Palette Editor for customizing how track data and terrain layers are displayed.

For Tracks, you can create custom palettes for Speed, Altitude, and Slope coloring. Choose between:

Color Palettes EditorColor Palettes Editor

Custom palettes are also available for Terrain visualizations. You can modify the color scale used for Slope and Altitude, assign colors to specific elevation levels or slope percentages, and add or remove value steps. Hillshade uses a fixed shading algorithm and does not support custom palettes.

Modify Color SchemeModify Color Scheme

More icons for profiles

You can now choose from the complete collection of OsmAnd icons when creating or editing a profile. The redesigned icon selector uses grouped categories and includes the same icons available for Favorites, making profiles easier to identify and personalize.

Icons list

CarPlay updates

OsmAnd 5.4 includes several fixes and improvements for Apple CarPlay.

The 10-day free CarPlay trial has been restored after an issue that could prevent it from working correctly in recent releases. New users can once again test CarPlay navigation before purchasing Maps+ or OsmAnd Pro.

Navigation now displays warnings before starting a route when required maps are missing or when private-road access needs confirmation. The update also improves map and route centering, particularly on widescreen displays.

CarPlay appearance settings no longer override the map mode selected in OsmAnd. When Day or Night mode is selected manually, the map keeps that setting when the CarPlay interface switches between light and dark modes.

Default appearance for Track folders

You can now set a default appearance for each Track folder. New tracks added to the folder can automatically use the selected coloring, line width, direction arrows, start and finish icons, and split interval.

The settings can also be applied to all existing tracks in the folder, replacing their individual appearance options.

Context menu of a track in iOSTrack folders

Organise tracks for smart folders

Smart Folders can now automatically organize tracks into groups using the new Organize by option. Instead of displaying every track in one list, you can group them by activity, creation date, location, distance, speed, altitude, elevation, or recorded sensor data.

Available organization types include:

  • General — duration, time in motion, length, and activity.
  • Date and time — year or month of creation.
  • Location — country or nearest city.
  • Speed — maximum or average speed.
  • Altitude and elevation — maximum or average altitude, uphill, and downhill.
  • Sensors — heart rate, bicycle cadence, bicycle power, temperature, and sensor speed.

For numerical values, you can adjust the grouping interval using Set step size. For example, tracks can be divided into distance ranges, altitude intervals, or speed groups. Empty groups are hidden automatically, and each group displays the number of included tracks.

Groups can be sorted alphabetically or, for numerical data, from highest to lowest or lowest to highest. You can also show all tracks from a group on the map or export them together.

Smart FoldersSmart Folders

Split Multi-Track GPX Files on Import

When importing a GPX file containing multiple tracks, you can now review and select the individual tracks you want to import. Each selected track is saved separately, making it possible to manage its visibility, appearance, and other settings independently.

You can select a destination folder, import all available tracks as separate files, or use Import as one track to keep the original GPX content together.

Multi-Track GPX Import

Show Track Waypoints on the Map

Track waypoint lists now include a dedicated Show on map button. Tap the pin icon next to a waypoint to center the map on its location without changing the current zoom level.

Tapping the main waypoint area still opens its full context menu.

Show Track Waypoints on the Map

Others updates and improvements

OsmAnd 5.4 also includes a range of smaller features and interface improvements:

Bug fixes


If you have suggestions for improving the iOS version of the app, please get in touch with us. We appreciate and welcome your contribution to the further development of OsmAnd.


 Apple AppStore

08:00 AM

Colorado Sees First Lawsuit Under ‘Right To Repair’ Law [Techdirt]

At this point all fifty states have considered passing “right to repair” law aimed at making it easier and cheaper for consumers (and independent repair shops) to repair their tech. That said, only Massachusetts, New York, Texas, Minnesota, Colorado, California, Oregon, and Washington have actually passed laws. And of those states, none have seen any enforcement despite no shortage of offenders.

So it’s interesting to see the first lawsuit filed in Colorado. Colorado technically has three right to repair laws: one protecting wheelchairs passed in 2022; one covering agricultural equipment passed in 2023; and one expanding coverage to HVAC equipment and most tech in 2024.

A company named Acme Revival, which connects customers with electronics repair technicians, has sued three companies for violating Colorado’s right to repair laws. Three different lawsuits are targeting Toast, a point-of-sale system provider, Owl Labs, a maker of meeting cameras, and Blackmagic Design, a maker of digital camera equipment — claiming they’re violating the law.

The three different lawsuits state that all three companies have made it very difficult for customers to obtain tools, parts, manuals, and firmware/software needed to upgrade and repair point-of-sale terminals, card readers, cameras, and other restaurant-related hardware:

“Acme Revival has received hundreds of requests from owners seeking repairs for Toast devices. The reported problems have included failed batteries and charging systems, damaged housings and touchscreens, malfunctioning card readers and buttons, circuit-board failures, loose or damaged connectors, damaged cables, damaged ports, and other defects requiring replacement parts or technical repair materials.

Acme Revival alleges that it has been unable to complete certain repairs because Toast failed or refused to provide the necessary repair materials.”

There’s really no shortage of large offenders who make it difficult to find parts and tools, buy up independent repair centers to try and monopolize repair (see: John Deere), leverage annoying DRM to make repair difficult or impossible, or engage in the practice of “parts pairing,” which ensures hardware owners can only access large and costly parts assemblages — not individual parts.

The bipartisan anger at such practices has resulted in the right to repair movement seeing the most meaningful traction of any consumer rights issue in the country. Hopefully enforcement steadily scales up to match the full scale of public annoyance.

Working With ICE Is So Toxic, ICE Is Now Offering Liability Insurance To Local Police Officers [Techdirt]

If you’re worried about the bad optics of working with ICE, the federal government is here to help subsidize your recovery from mass deportation conjunctivitis. If you’re worried about the personal negative side effects of buddying up to ICE’s masked kidnapping squads, the administration is here to assure cops that it might cover some of the legal costs of doing business with ICE.

US Immigration and Customs Enforcement is pitching a plan to help shield local police officers who make immigration arrests from possible financial consequences if they are accused of on-duty misconduct.

The agency is proposing to subsidize liability insurance for state and local officers who are trained and deputized to enforce federal immigration laws, according to a planning document published Friday.

This offer is not valid in sanctuary cities or anywhere cops shops haven’t signed agreements to do ICE’s detention/arrest work for it. To get this extra coverage, law enforcement agencies will have to sign 287(g) agreements. These agreements make local law enforcement agencies part of mass deportation machinery. It requires agencies to hold arrested migrants and tell ICE to come pick them up. It also allows local cops to act as immigration officers by permitting them to perform arrests using ICE administrative “warrants.”

That word is in scare quotes because administrative warrants are just pieces of paper that say ICE knows of someone subject to a removal order. They are not reviewed by magistrate judges. And, unlike what ICE would have you believe, they do not authorize searches of private property.

This is where some of ICE’s (new) billions of dollars might be going. ICE officers don’t need this sort of insurance because they’re defended and indemnified by the federal government. (And they don’t need it anyway because the Supreme Court has made it pretty much impossible to successfully sue a federal officer for rights violations.)

Local cops aren’t nearly as immune as federal officers, so they might appreciate some insurance coverage in the extremely unlikely chance they are sued successfully for violating rights while doing ICE’s work for it. But the payout seems pretty fucking low considering ICE now commands the largest budget of any federal law enforcement agency.

Under the plan, officers would purchase insurance covering up to $500,000 in personal liability, which typically funds legal fees, settlements and judgments. Officers would be reimbursed up to $250 annually — roughly what the insurance is expected to cost.

The administration that claims to love cops (that love ICE) the most, this minimal payout should be viewed as insulting. First, the administration “allows” officers to spend their own money to purchase insurance coverage they wouldn’t otherwise need if their employing agencies had decided signing a 287(g) agreement wasn’t worth the trouble.

Second, tossing cops $250 a year does a whole lot of nothing when it comes to premiums for this specific sort of insurance. And, in other cases, partnering with ICE will automatically void these policies.

Pennsylvania’s risk pool, for instance, recently made clear that it would exclude “proactive immigration enforcement activities” from coverage, forcing several participating counties to search for other insurance options.

Butler County Sheriff Michael Slupe said he found insurance to cover his 13 deputies participating in the program at a cost of $20,000 in annual premiums.

In the first instance, there is no coverage to be had even if the DHS is willing to cough up a measly $250 a year for ICE buddy cops. In the second instance, a local agency is paying $1,538/year per officer to cover officers it has willingly lent to ICE’s anti-migrant activities. That means it’s still on the hook for the other $1,250/year. $3,250 (for 13 officers) looks like a down payment, rather than a meaningful contribution.

But the facts on the ground don’t bother Sheriff Slupe, apparently. He’s sure Trump will come riding the rescue with a fat stack of greenbacks.

“I want to make sure the guys are additionally covered, so we had to spend the money,” he said, adding that federal funding would cover the cost.

Technically almost true, if you read this to mean the federal government will cover an almost-insignificant portion of the cost. But it’s weird to see Sheriff Slupe offer to pitch in on immigration enforcement when his agency was thrown under the bus a bit following an alleged assassination attempt targeting Trump during his 2024 election campaign.

It’s all very stupid and unnecessary. It’s already pretty difficult to successfully sue law enforcement officers, thanks to the ever-expanding coverage of the qualified immunity doctrine (not actually a law!). Furthermore, the federal government’s pitch for additional liability insurance makes you wonder which Trump donors might profit from this push for new premiums. ICE already claims any officers participating in the 287(g) program are “acting under the color of federal authority,” which vastly increases the level of lawsuit immunity. Going even further, the federal government has already pretty much promised local law enforcement officers they’ll be well-defended should they be sued for boarding the ICE bang bus.

The agreements also state that local officers who face civil lawsuits can ask the US Department of Justice to represent them, and that ICE will generally support their requests. 

Adding all of this up, we can only assume none of this adds up. The stipend is too small. The government says local officers should present themselves as federal officers in court proceedings. And these officers seem unlikely to ever need to hire their own representation should they be sued for their ICE-adjacent activities. And now ICE is encouraging participants in the 287(g) program to buy insurance they’ll likely never need or, in some cases, not be able to use due to limits enacted by insurance providers.

It comes across as a blend of stupid and performative. As such, it fits in perfectly with this administration’s MO. But if I were a cop doing ICE’s dirty work, I’d be demanding full coverage paid with federal tax dollars, rather than assume this cock-up of a hybrid will actually do anything when I’ve been sued by competent plaintiffs.

07:00 AM

Hiking the Alps [dperkins]

This year progress on the Top 100 Mountains continues. Here are pictures from day and overnight trips to the Japanese Southern Alps and Central Alps this year.

Mt. Hoo

During spring break, I drove to Kofu, Yamanashi, and climbed Mt. Hōō (鳳凰山). There are several summits, and given the abundance of snow and ice, I summitted Jizō-dake (地蔵ヶ岳), notable for a giant rock at the top — the Obelisk. The trail was slow but fun: one third dirt, one third ice, and one third snow.

20260330.1.Alps.jpg 20260330.2.Jizo-dake.jpg 20260330.3.Obelisk.jpg

Yatsugatake & Mt. Tateshina

The snow was gone by May, so I drove up to the Central Alps in southern Nagano and climbed Yatsugatake (八ヶ岳). Yatsugatake has a handful of summits, and my route went over Amida-dake (阿弥陀岳) and Aka-dake (赤岳). The next day, I went up Mt. Tateshina (蓼科山), another mountain not far to the north. One fun thing about hiking so much in the Southern and Central Alps this year is learning the landscape. Many of these mountains are visible from one another on clear days, and if you don't know what you're looking at, it's guaranteed that some other hiker will tell you. Mt. Fuji shows up from time to time, too.

20260530.1.Yatsugatake.jpg 20260531.1.Tateshina.jpg

Mt. Kita & Mt. Aino

The second- and third-highest mountains in Japan are Mt. Kita (北岳) and Mt. Aino (間ノ岳), and you can day trip them if you really want to. There are many mountain huts along the way, so your gear need not be burdensome, and the scenery is majestic. Nevertheless, it's strenuous to say the least, and my legs were aching by the end of the day.

20260703.1.Fuji.jpg 20260703.2.Hoo.jpg 20260703.3.Senjo.jpg 20260703.4.Kaikoma.jpg

Mt. Tekari & Mt. Hijiri & Mt. Kisokoma

In late summer I drove to Nagano for more hiking. First was a two-day hike. It was a brutal ascent up to Mt. Tekari (光岳), but once I got up there, following the ridge north over Mt. Chausu (茶臼岳) was pleasant, and the weather was wonderful. After the long day with massive vertical gain, I spent the night at Chausu Hut (茶臼小屋). The mattress was thin and I slept poorly, but the building was warm and the food was good. The next morning we all awoke to a spectacular view of Mt. Fuji at sunrise. The pictures speak for themselves.

On the second day, I continued north, stopped briefly at the top of Mt. Kamikochi (上河内岳) went to the summit of Mt. Hijiri (聖岳), and headed back down to the car. Going down was much easier than going up, but my shoes were getting old and I got some blisters. That afternoon I went to an onsen in the nearby village of Toyamago, because a long bath after a long hike is just lovely, and then drove north for an hour.

After sleeping in the car, I got up and took the alpine bus and cable car most of the way up Mt. Kisokoma (木曽駒ヶ岳). From there it was a leisurely stroll to the summit. Many years ago we were here on a school trip but didn't get to the top because of bad weather. So it was nice to return, go the extra kilometer, and get the good vibes and views.

20260831.1.Tekari.jpg 20260831.2.Chausu.jpg 20260831.3.Fuji.jpg 20260901.1.Fuji.jpg 20260901.2.Fuji.jpg 20260901.3.Fuji.jpg 20260901.4.Ridge.jpg 20260901.5.Hijiri.jpg

A “Baker’s Dozen” Justices [The Status Kuo]

On Sunday, Rep. Jim Clyburn told NBC’s “Meet the Press” that Congress should expand the Supreme Court. “I think we are in a position now that calls for some significant actions taken by the Congress and we ought to expand, and 13 is a pretty good number,” the South Carolina Democrat said. “A baker’s dozen, it would be a good number to have on the Court.”

Three days later, perhaps spooked that someone as senior as Clyburn had taken up the cause, Republicans sought to head off the issue. They forced a vote on a constitutional amendment offered by Rep. Andy Biggs (R-AZ) to permanently fix the Supreme Court at nine justices. The vote was 212 to 206 in favor, with just one Democrat joining Republicans, but it fell well short of the two-thirds majority a constitutional amendment requires.

At this point, the parties are posturing. Republicans knew their amendment would not receive much support outside the GOP. And Democrats do not control Congress; even if they win both chambers after the 2026 midterms, expanding the Court would still require either a filibuster-proof Senate majority or the elimination of the filibuster altogether—as well as control of the White House, which could otherwise veto any expansion bill.

But the posturing still leaves one interesting question unanswered: Why is a proposal with no near-term path to enactment suddenly worth a public floor vote and a cable interview from a senior Democratic leader?

Subscribe now

Clyburn’s case

On August 30, Kristen Welker pressed Clyburn on whether he agreed with Kamala Harris’s past call for Supreme Court expansion. He responded by condemning the Court’s recent rulings, saying the conservative majority “has decided to reverse course and take this country back to those rulings of Justice Taney, that said, ‘No Black man has any right that white man must respect.’” He was referring to Chief Justice Roger Taney’s 1857 opinion in Dred Scott v. Sandford. Clyburn hoped new justices would “follow the constitutional underpinnings of this great nation of ours,” adding, “The 13th, 14th, and 15th Amendments have been interpreted different ways over the years.”

Clyburn’s call for a “baker’s dozen” of 13 justices was not new. Rep. Hank Johnson (D-GA), along with several Democratic senators, introduced the Judiciary Act of 2023 to expand the Court from 9 to 13 seats. In effect, Clyburn was endorsing an existing bill, not proposing a new one. Still, as some observers noted, he was the first member of House or Senate Democratic leadership to endorse expansion. And given his seniority and the importance of South Carolina—it will be the first state to hold a 2028 Democratic presidential primary—that endorsement carries significant weight.

The House vote

Rep. Andy Biggs of Arizona offered the amendment, which read in full:

“The Supreme Court of the United States shall be composed of nine justices consisting of one chief justice and eight associate justices.”

Biggs framed the measure as preemptive. “It fixes the number of justices at nine permanently, not because nine is a magic number, but because a fixed court cannot be expanded by whoever happens to win the next election,” he said during floor debate.

Democrats countered that the real overreach was Congress permanently surrendering its own authority. Rep. Mary Gay Scanlon (D-PA) noted that calls for Supreme Court reform “have grown louder in the wake of each decision that has lessened our individual rights and liberties.”

Rep. Ralph Norman (R-SC) argued that the danger lay in the precedent itself. “Once politicians start changing the size of the Court to get favorable rulings, there is no logical stopping point,” he said. “Today is 13. Tomorrow could be 17. Then 21. That would turn the Supreme Court into just another political arm of Congress.”

This argument against politicization is ironic, given Democrats’ view of the current Court majority as little more than an extension of the Trump White House. And Josh Orton, president of the judicial advocacy group Demand Justice, argued that Republicans would not hesitate to wield power were the shoe on the other foot. “You can be damn sure that if there had been a longstanding progressive majority on the court, Republicans would have already voted to expand it,” he said. Expansion, he argued, “has to happen in the first two years of the next Democratic administration.”

The amendment arrived as part of a broader slate of messaging votes. A day earlier, the House had adopted a resolution condemning “socialism.” That was part of a Republican push tied to several Democratic Socialists of America-aligned candidates expected to join Congress after the midterms. A spokesman for House Republicans’ campaign arm declared, “Give House Democrats an ounce of power, and they’ll use every bit of it to fundamentally transform America into an unrecognizable socialist hellscape.”

(Narrator: Medicare for all, free child care and nutritional assistance for poor families are a “socialist hellscape” to Fox hosts and the GOP.)

Nine is by statute, not constitutional mandate

Article III of the Constitution created the Supreme Court but said nothing about its size. It left that question to Congress, which has changed the Court’s size seven times since the founding.

The Judiciary Act of 1789 set the Court at six members: one chief justice and five associate justices. In 1801, the outgoing Federalist Congress voted to cut the Court to five seats, timed to deny the incoming Jefferson administration an appointment, but Congress repealed the change the following year before it ever took effect, restoring the Court to six. A seventh justice was added in 1807 as new circuits were created, and an eighth and ninth followed in 1837. The Court reached its historical high in 1863, when a tenth justice was added alongside a new Tenth Circuit then covering California and Oregon.

Congress moved to shrink the Court in 1866, providing that it would fall to seven seats as vacancies arose, a change widely viewed as one of the Reconstruction Congress’s restrictions on President Andrew Johnson. With Ulysses S. Grant in office in 1869, Congress set the Court at nine justices. That remains the last time Congress has changed the size of the Court.

The Congressional Research Service notes that scholars dispute Congress’s motives across these changes. Some point to caseload and administrative needs, while others argue the changes were consistently political. Franklin Roosevelt’s 1937 attempt to add justices to a Court that was regularly striking down New Deal legislation is the best-known chapter in this history, but it never became law and the Court remained at nine justices.

Where Jeffries stands

House Minority Leader Hakeem Jeffries, who hopes to become speaker-elect after the November midterms, staked out his own position weeks before Clyburn’s comments. He told the National Association of Black Journalists in August that “dramatic Supreme Court reform is necessary.” Asked what that meant, he deferred to others on the specifics. “I’m going to leave it to the Democrats on the Judiciary Committee, led by Jamie Raskin, who will be the next chair… there’s a variety of different options that are on the table. And I think that we can’t foreclose any single one of them.”

Jeffries was sharper about the Court’s current majority than about any specific fix. “The conservative right-wing majority on the Supreme Court has become basically a subsidiary of the MAGA Republican Party,” he said, pointing to the Court’s ruling in Louisiana v. Callais and a related fight over an Alabama congressional map.

In a subsequent appearance on “Meet the Press,” Jeffries said an overhaul could start with a binding ethics code of conduct for justices, but he stopped short of backing the seat-expansion proposals popular with some members of his own caucus.

The gap between Jeffries and Clyburn probably reflects a division of labor rather than much daylight between their positions. Jeffries has left room for “dramatic reform” as a category while directing the specifics to Raskin’s committee, leaving the politically explosive question of seat expansion to members like Clyburn to carry.

The public’s trust has never fallen so low

Public opinion on Supreme Court expansion is split. A Marquette Law School poll conducted in May found the public evenly divided, 50 percent in favor of adding justices and 50 percent opposed, up eight points since Marquette first posed the question in September 2019, when 42 percent favored enlargement.

Confidence in the institution overall has slid. The share of registered voters expressing “a great deal” or “quite a bit” of confidence in the Supreme Court has fallen to 22 percent, a record low in NBC News polling. A separate Gallup poll put the Court’s job approval at a record low of 33 percent.

In short, voters have not coalesced around expansion as the fix, but their confidence in the Court has cratered. As the Court’s legitimacy problem deepens, the argument for adding seats will grow louder, and Democrats now appear ready to run with it.

Why raise the question now?

Democrats currently do not control any part of government, and they do not have the votes to expand the Court given unified Republican opposition. So why are Democratic leaders talking about an idea they cannot yet act on, and may not be able to act on even after the midterms?

Wouldn’t this take a Democratic trifecta? If so, why start talking about it now, giving the GOP a big heads up? Shouldn’t we have just surprised them with it in 2029?

Josh Marshall of Talking Points Memo had a keen observation worth sharing in full:

The inertial forces against reform are massive. Even among many elected Democrats who are pretty good on other issues, it’s often a very heavy lift. It’s only very recently that Court reform has even moved into the realm of conceivable for most of them. Change, building that consensus can only happen as a bottom-up process, making it clear that accepting the perpetuation of the Corrupt court as it exists today is an unacceptable position for a Democrat, certainly at the federal level — as a bottom-up process, it can only be a public process. You’ll only know someone is on board when they say it publicly and clearly. Even then you can’t be totally sure. But once a politician has committed publicly, it’s much harder to shift. And when you’ve got the great majority publicly committing, the pressure heightens on those who remain opposed or silent in inverse proportion to their declining numbers. The same applies to abolishing the filibuster and a lot else.

Seen in this light, Clyburn’s remarks, paired with Jeffries, are early markers for what a future Democratic government would do with unified control. Both are staking their public positions to build the consensus they know they will need. “In time for 2029” is emerging as a position within the party, with Clyburn among the prominent early voices making the case.

The failed House vote, insisted upon by the GOP, may itself have done some of the work for expansion advocates. One assessment noted the important concession embedded in the GOP’s own amendment: Republicans could not argue for permanently fixing the Court’s size without acknowledging that Congress can, right now, make the Court whatever size it wants.

The Supreme Court itself under John Roberts is no doubt also paying attention. In his Sunday remarks, Clyburn fired a warning shot across the radical majority’s bow, in effect saying, “We see you, we know what you are trying to take us back to, and we won’t allow it. If our hand is forced, we will dilute your strength by expanding your numbers the moment we are in charge.”

GOP pearl-clutching over packing the Court also rings hollow given that their party already did so. In 2016, Republicans under then-Senate Majority Leader Mitch McConnell (R-KY?) blocked President Barack Obama’s nomination of Merrick Garland, refusing to give him a confirmation hearing. McConnell claimed that appointment came too close to an election, despite Obama nominating Garland in March. McConnell then turned this same excuse on its head by ramming through Justice Amy Coney Barrett’s nomination days before the 2020 election. He later acknowledged the real distinction was control of government, not the calendar: “What was different in 2020 was we were of the same party as the president.”

After 2028, if a Democratic Congress is of the same party as the president, we should insist the GOP get a strong dose of its own medicine.

06:00 AM

Hackers Had A Live Feed Of Every ID This Verification Company Scanned. For Over A Year. [Techdirt]

From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.

This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database.

There is no safe age verification. There is no age verification that doesn’t put people at risk.

Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches.

The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web:

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary.

That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.

So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned.

Yiiiiiikes.

And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed:

The IDScan.net Trust Center webpage features a security review banner, a search bar, sections for trust and compliance certifications, and a grid of logos from trusted partner organizations.

That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page.

But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records.

And it appears no one internally at the company noticed.

As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system:

The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.

A table titled "Categories" lists various types of identification documents and the number of records associated with each. There are over 153 million drivers licenses.
The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale:

A webpage from the NEXUS Identity Document Database shows a locked Minnesota driver's license record for Peter Heg******, featuring a portrait photo of Hegseth and redacted personal details with a "Purchase Record" button at the bottom.

A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license.

Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing.

Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage:

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.

You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems.

Daily Deal: Babbel Language Learning (All Languages) [Techdirt]

Become a language expert with a Babbel Language Learning subscription. With the app, you can use Babbel on desktop and mobile, and your progress is synchronized across devices. Want to practice where you won’t have Wi-Fi? Download lessons before you head out, and you’ll be good to go. However you choose to access your 10K+ hours of online language education, you’ll be able to choose from 14 languages. And you can tackle one or all in 10-to-15-minute bite-sized lessons, so there’s no need to clear hours of your weekend to gain real-life conversation skills. Babbel was developed by over 100 expert linguists to help users speak and understand languages quickly. With Babbel, it’s easy to find the right level for you — beginner, intermediate, or advanced — so that you can make progress while avoiding tedious drills. Within as little as a month, you could be holding down conversations with native speakers about transportation, dining, shopping, directions, and more, making any trip you take so much easier. It’s on sale for $159 when you use the code LEARN at checkout.

Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

04:00 AM

DOJ Issues Memo Saying There’s Nothing Illegal About The Military Arresting Migrants [Techdirt]

A little more than a year ago, the Trump administration pushed a novel legal theory in order to juice its migrant arrest stats. It was a two-part process. First, the administration unilaterally declared expansive areas near US military bases to be “national defense areas.”

This meant that areas surrounding bases — like (especially) Fort Bliss in El Paso, Texas (which is also home to one of ICE’s largest detention centers) — were subject to a separate set of rules governing “military zones.” In these areas, military officers could effect arrests on anyone “intruding” into these areas. The outlines of these areas were deliberately large — so much so that they butted up against US-Mexico border.

The point of this effort was obvious: Trump hoped to see more arrests at the border by allowing the military to pitch in with his mass deportation efforts. This was the administration’s “Posse Comitatus Act” workaround. That law, passed in 1878, forbade the federal government from co-opting military members to perform regular law enforcement work. It’s the same thing that was a sticking point in many of Trump’s National Guard deployments to major US cities.

By pretending massive areas surrounding US bases were now so essential to US national security that the government absolutely needed to draft soldiers into its immigration law enforcement effort, the Trump administration hoped to avoid adverse court rulings.

That hasn’t really worked. National Guard deployments have been blocked by federal courts. And while there hasn’t been a precedential ruling on this novel interpretation of “national defense areas,” the DOJ has decided to issue a legal memo — more than a year after this had already happened — that says this is all cool and legal.

On Aug. 14, the Department of Justice’s Office of Legal Counsel (OLC) released a 15-page memorandum contending that the Posse Comitatus Act does not prohibit military personnel from effecting arrests in the “immediate vicinity” of a designated “national defense area” for alleged crimes there. The opinion followed President Trump’s April 2025 order designating swaths of the Mexico-U.S. border as national defense areas

There’s a lot of bullshit in the OLC’s memo [PDF], but let’s start with this:

Even though substantial portions of the NDAs may be presently unoccupied or have no standing structures on them, there is a military necessity to ensure that unauthorized persons are not establishing a position to monitor the activities of U.S. forces for intelligence gathering purposes or conducting reconnaissance in preparation for a terrorist attack. Individuals may also be drawn to remote and unoccupied locations to engage in criminal activity, which poses a threat to military personnel who may come upon them in the course of their duties or where the activity itself poses a danger, such as the operation of methamphetamine laboratories. As there is no way for military personnel to know a priori the identity or intent of an unauthorized person, there is a military purpose in apprehending, at least temporarily, anyone whose presence is unauthorized, in order to ensure appropriate measures can be taken to protect national security and the safety of military personnel. That military purpose continues even if the trespassers have exited the installation before they were apprehended.

It’s insanely hilarious to actually claim in an official legal memo that if soldiers aren’t allowed to detain migrants, some of them are just going to fire up a meth lab within the vicinity of a US military base.

But once we’re done laughing, we have to recognize the obvious side effects of this declaration by the DOJ: that anyone is subject to this interpretation of the law, which turns troops into cops just because the administration says it does.

One of the many troubling aspects of this assertion (and of the executive order underlying it) is that it places no burden on the government to clearly, physically denote the outlines of these supposed “national defense areas.” This means migrants crossing borders will just assume they’re walking on land and only find out after the fact that the government has unilaterally declared that area to largely be exempt from commonly accepted restrictions on US military officers.

And even if you don’t care what happens to migrants, especially those who have very recently illegally crossed in the US, you might want to take a moment to consider your fellow citizens who also won’t know they’re in a “national defense area” until they’re greeted at gunpoint by members of the US military. It’s already scary enough to get jumped by cops when you’re just minding your own business. Now, imagine this same experience, except with an armored vehicle featuring a top-mounted .50 cal machine gun.

The DOJ doesn’t seem to find much support for its assertions in the memo. And yet the OLC has delivered one all the same. The memo pretends there’s no difference between the military enforcing the law within the confines of US military base and enforcing it in large, unmarked areas whose confines can only be defined by those with access to information the Trump administration certainly isn’t going to be sharing with everyone.

But the DOJ OLC is also (sadly) correct to point out that this interpretation of the law is not subject to any adverse precedent. Do you know why that is? BECAUSE NO ONE BUT THIS ADMINISTRATION HAS TRIED TO DO THIS EXTREMELY FUCKED UP THING BEFORE. Opening an Overton Window in a legal vacuum doesn’t make you the smartest people in the room. It just makes you the pioneers of martial law fuckery.

Finally, the OLC says not even the vague boundaries of any supposed “national defense areas” should prevent military officers from arresting migrants (or anyone else in the area).

In sum, we conclude that the use of military personnel to arrest trespassers just outside of an NDA would not violate the PCA, given the express statutory authorization and the military-purpose of a commander’s traditional protective power.

Even the confines are not the confines. The OLC doesn’t bother to describe what it considers to be “just outside of an NDA.” Nor is it going to. That’s a problem for arrestees to try to suss out in courts that already give the federal government plenty of leeway any time it starts talking about national security or national defense. How far away can someone (as the DOJ’s hypothetical puts it) “engage in criminal activity” or “reconnaissance?” What’s the acceptable distance between an NDA and a meth lab? Any distance could be considered “just outside” as long as someone’s will to swear they saw some reconnaissance or criminal activity happening.

We’re fortunate that we haven’t seen this novel interpretation of the PCA abused excessively. So far! But the late arrival of this legal justification seems to indicate we’ll be seeing a lot more of that in the near future.

12:00 AM

Pluralistic: Preparing for a post-Trump internet (03 Sep 2026) [Pluralistic: Daily links from Cory Doctorow]

->->->->->->->->->->->->->->->->->->->->->->->->->->->->-> Top Sources: None -->

Today's links



A nuclear mushroom cloud wearing a giant Trump wig. A decaying American flag fills the sky behind it.

Preparing for a post-Trump internet (permalink)

What if post-Trump America is even worse?

I know, it's tempting to think of Trump as a cause, rather than an effect – as an aberration who dragged America into fascism. Trump is exceptional, but the thing that makes him exceptional isn't his corruption, recklessness or cruelty. What makes Trump exceptional is his ability to cajole, intimidate and flatter America's most corrupt, reckless and cruel people into a coalition.

These people hate each other. Nick Fuentes drifts off to sleep every night furiously fantasizing about turning Stephen Miller into a lampshade. Laura Loomer just got ICE to intervene in a Twitter feud by having a guy she dislikes violently arrested, shackled at wrist and ankle, perp-walked, and then shuffled from location to location so that he couldn't meet with his lawyer before being deported:

https://www.motherjones.com/politics/2026/08/milo-yiannopoulos-deportation-trump-maga-laura-loomer-benny-johnson-raheem-kassmm/

They steal like crazy, get each other locked up, and gorge themselves on mind-altering supplements and peptides they buy from random podcast chuds. They are fantastically paranoid, marinated in conspiracy theories, and perennially high on their own supply: all that bullshit about "great replacement," "China is making America hate data centers" and "antifa is a terrorist organization"? A lot of them genuinely believe it. It's not just ghost stories they made up to scare cognitively compromised tube-feeding Fox News addicted rubes. Trumpland is full of actual, functioning adults in positions of real power who periodically go into the bathroom, turn off the lights, hold a flashlight under their chins and scare themselves silly by saying "Aaaaaaaaaantiiii-faaaaaaaaaa" into the mirror.

Donald Trump did not conjure these people out of thin air. They've been lurking in America since its earliest days. They worship authoritarian criminals:

https://abc30.com/post/roger-stones-tattoo-of-nixon-goes-viral/5107047

January 6 wasn't the first presidency they tried to steal, it's just the first one they got punished for:

https://en.wikipedia.org/wiki/Brooks_Brothers_riot

They commit brazen crimes in office that could land them in prison for the rest of their lives, and therefore can't afford to lose power, ever:

https://www.propublica.org/series/supreme-court-scotus

Trump didn't invent these creeps, he just emboldened them. If Reaganomics was capitalism with the gloves off, then Trumpismo is Reaganism with the mask off:

https://www.theguardian.com/books/2020/aug/16/reaganland-review-rick-perlstein-jimmy-carter-ronald-reagan

So what happens when Trump strokes out while watching Kid Rock wrestle a Hulk Hogan impersonator in a televised barbed-wire cage match on the White House lawn that one of Trump's cronies has exclusive pay-per-view rights to? I mean, it's possible that the Democratic leadership will step up and insist on some form of regular order in the succession to Vance, but come on. These are the tiny "Down with this sort of thing" ping-pong paddle people:

https://www.truthdig.com/articles/ping-pong-paddles-to-a-gun-fight/

More likely is that Vance – a weak, unimportant charisma-vacuum who is loathed by all of Trump's factions – will end up presiding over a far more chaotic period in American governance than anything that happened under Trump. That could mean ICE leaders ordering mass graves dug in the centers of America's largest cities, drunken generals invading random countries, podcasters declaring "The Purge" with brackets sponsored by Kalshi.

This isn't the first time in living memory that this has happened. In 1991 the Soviet Union collapsed, virtually overnight, and the fragile threads that bound its feuding, corrupt regional bosses all snapped, leaving behind nuclear-tipped mafia states. This was a chaotic and frightening time for the people whose governments had simply winked out of existence – but it was also terrifying for the rest of the world, who scrambled to secure those nukes before they could end up in the hands of "non-state actors":

https://www.hks.harvard.edu/publications/what-happened-soviet-superpowers-nuclear-arsenal-clues-nuclear-security-summit

The Soviet Union had some deeply dysfunctional leadership politics to be sure, but at least the people involved were beholden to various power blocs who had an interest in keeping things going. As the geopolitics wonks say, "they were playing an iterated game," where some losses had to be tolerated so that the losers could try to win the next time around.

But there are plenty of people who weren't (and aren't) playing iterated games – people who are even more unhinged, more reckless, more short-termist than the maniacs who filled the world with nuclear weapons. These people don't necessarily care if civilization or even the human race persists if they can't get their way. The thought of them running around with these "weapons of mass destruction" ratcheted up the half-century of stark nuclear terror that had preceded the USSR's collapse to new heights.

Which brings me to the post-Trump internet. Trump isn't the first president to figure out that the internet could be weaponized for geopolitical ends. As the Snowden disclosures showed, there has been a longstanding bipartisan consensus that the internet is a great tool for American surveillance, conducted against friend and foe alike.

But Trump is the first president to openly, directly recruit American tech companies to simply brick foreign officials who displease him, starting with the Chief Prosecutor of the International Criminal Court, who lost his Office 365 and Outlook accounts in retaliation for swearing out a genocide warrant for Netanyahu:

https://www.justiceinfo.net/en/156691-how-sanctions-can-weaponize-us-tech-against-the-icc.html

And then Microsoft obliged Trump again, attacking the Brazilian judge who sentenced Jair Bolsonaro to prison over his unsuccessful coup.

America's tech giants have fully, irrevocably fused with Trump. They donated to his campaign. Their CEOs each paid $1m out of their own pockets to sit behind him on the inauguration dais. Google provides location data for Trump's racist pogroms. Microsoft provides the administrative tools to carry them out. Oracle provides the databases. Apple blocks apps that warn its customers when they're about to be snatched:

https://pluralistic.net/2025/10/06/rogue-capitalism/#orphaned-syrian-refugees-need-not-apply

In exchange, Trump got Canada and the UK to ditch their plans to levy a 3% tax on American tech giants; he got the EU to gut its privacy laws; he sanctioned EU officials who tried to regulate social media; and he's told the tech companies to go through EU officials' private messages, looking for anti-Big Tech partisans whom he will ban from ever entering the USA:

https://judiciary.house.gov/media/in-the-news/us-committee-demands-big-tech-share-private-comms-eu-officials

Big Tech has proved that its only principles are not paying taxes, invading your privacy, and not being broken up by antitrust enforcers:

https://arstechnica.com/gadgets/2026/09/us-court-rules-google-will-not-have-to-sell-ad-exchange-after-losing-antitrust-case/

Tech companies will do anything for any leader who can guarantee those outcomes. There's no capitulation too petty and stupid for Big Tech:

https://people.com/apple-maps-joins-google-approving-trump-lake-america-change-12074262

America no longer has allies or trading partners. America has rivals and enemies. Trump's coalition wants him to steal Iran, steal Venezuela, steal Cuba, steal Alberta, steal Canada, steal Greenland. They want him to help Israel steal Palestine and Lebanon. And as Trump considers this program of imperial conquest, he has started to tinker with one of the most devastating geopolitical weapons the world has ever seen: tech shutdowns.

If Trump wants Greenland, he can just order Microsoft to switch off Office 365 for the country and every ministry and significant firm will be shuttered in an instant, along with many households:

https://pluralistic.net/2026/04/04/digital-subjugation/#greenlands-next

He can order Apple and Google to shut off all of Denmark's phones. He can order John Deere to shut off all their tractors:

https://pluralistic.net/2022/05/08/about-those-kill-switched-ukrainian-tractors/

(One thing we don't need to worry about is Trump ordering OpenAI and Anthropic to switch off all of Europe's chatbots – sure, he could do that, but if he did, nothing important would break:)

https://pluralistic.net/2026/06/18/their-trillions-our-billions/#eyes-on-the-prize

As weapons of mass destruction go, nukes are pretty stupid. The big ones destroy the territory you're trying to conquer and leave behind an uninhabitable radioactive wasteland. They send clouds of nuclear fallout swirling around the globe, potentially killing you or your allies. 80 years into the Nuclear Age, the best anyone's come up with is a neutron bomb, which only kinda renders territory uninhabitable while still killing everyone with massive radiation blasts.

Compared to nukes, tech shutdowns are amazing. Thanks to Big Tech, America – and only America – can brick almost any country on earth, shutting down its administration, agriculture and industry without firing a single shot. The only thing that prevented this from happening was an American elite bloc that was playing an iterated game and saw more benefit from sharing in Big Tech profits as they looted and spied on the world, as opposed to grabbing territory while scaring the world into breaking all land-speed records to ditch American tech and pursue meaningful digital sovereignty.

Trump's chuds and freaks are not bound by these constraints. They're perfectly happy to do Gunboat Diplomacy 2.0: Cloud Diplomacy, where everything from your smartphones to your payroll records can be seized at the click of a mouse, and your country had better fall in line. And Trump is a sick, frail old man, who is not long for this world. When he goes, all bets are off: America will be at the mercy of warring factions who will deploy the coercion and bribery that turned Big Tech into Trump's geopolitical weapon in order to achieve their own purposes – which might well be even stupider, crueler and more unhinged than Trump's.

There's only one way out of this mess: the rapid disassembly of the American internet and the rapid creation of a post-American internet, one built on open, auditable, sovereign digital public goods, internationally built and maintained:

https://pluralistic.net/2026/01/01/39c3/#the-new-coalition

In its own way, the creation of this post-American internet is as urgent and as global as was the creation of the covid vaccines. But whenever I speak to powerful people about this, they ask the same question: "What if this makes Trump mad?"

This represents a grave failure to take this crisis seriously. Trump doesn't need to be "mad" to attack your country. Trump attacked Canada over its wildfires, accusing Canada of polluting America's air:

https://www.cbc.ca/news/politics/us-complaints-trump-widlfire-smoke-9.7274466

But even if Trump never gets mad at you, that's no guarantee of safety. Trump is not long for this world, and his death or incapacity is no guarantee of the restoration of a "normal" America. And even if America finds its way to "normal" after Trump, that's no guarantee that it will stay normal. The armed, organized maniacs who have seized power in America and who are cheering him on as he rampages all over the world, kidnapping leaders and dropping bombs on schoolchildren are not going to dig a hole, crawl inside it, and pull the dirt down on top of themselves.

But let's say that we find ourselves in the best of worlds, where American fascism is comprehensively defeated and the country embarks on a years-long program of denazification:

https://pluralistic.net/2026/02/10/miller-in-the-dock/#denazification

Even in that amazing future, the world should still race to build a post-American internet. The world should have built that internet after the Snowden revelations. That ghastly failure created the Trumpian internet. If the post-Trump internet isn't a post-American internet, then it'll only be a matter of time until the next crisis comes along, and the coming years will give Big Tech even more chances to worm its tendrils into the world's governments, firms and households, making that crisis be even harder to survive. The best time to act was 13 years ago, after Snowden. The second best time is now.


Hey look at this (permalink)



A shelf of leatherbound history books with a gilt-stamped series title, 'The World's Famous Events.'

Object permanence (permalink)

#25yrsago Barnum & Bailey hired an ex-CIA spook to destroy a critical journalist https://web.archive.org/web/20010913192931/http://www.salon.com/news/feature/2001/08/30/circus/print.html

#20yrsago Wired article about Wikipedia is on a editable wiki https://web.archive.org/web/20060901030941/http://www.socialtext.net/wired/index.cgi

#20yrsago Singapore will have nationwide WiFi by 2007 https://web.archive.org/web/20060901191656/http://news.com.com/2100-1039_3-6110189.html

#5yrsago Twitter Arguments https://pluralistic.net/2021/08/29/twitter-arguments/


Upcoming appearances (permalink)

A photo of me onstage, giving a speech, pounding the podium.



A screenshot of me at my desk, doing a livecast.

Recent appearances (permalink)



A grid of my books with Will Stahle covers..

Latest books (permalink)



A cardboard book box with the Macmillan logo.

Upcoming books (permalink)

  • "The Post-American Internet," a geopolitical sequel of sorts to Enshittification, Farrar, Straus and Giroux, 2027

  • "Unauthorized Bread": a middle-grades graphic novel adapted from my novella about refugees, toasters and DRM, FirstSecond, April 20, 2027

  • "Enshittification, Why Everything Suddenly Got Worse and What to Do About It" (the graphic novel), Firstsecond, 2027

  • "The Memex Method," Farrar, Straus, Giroux, 2027



Colophon (permalink)

Today's top sources:

Currently writing:

  • “Once Is Enemy Action,” a science fiction novel about the origins of modern technofascism. Today's words: 574 (7730 total).

  • "The Post-American Internet," a sequel to "Enshittification," about the better world the rest of us get to have now that Trump has torched America. Fourth draft completed. Submitted to editor.

  • A Little Brother short story about DIY insulin PLANNING


This work – excluding any serialized fiction – is licensed under a Creative Commons Attribution 4.0 license. That means you can use it any way you like, including commercially, provided that you attribute it to me, Cory Doctorow, and include a link to pluralistic.net.

https://creativecommons.org/licenses/by/4.0/

Quotations and images are not included in this license; they are included either under a limitation or exception to copyright, or on the basis of a separate license. Please exercise caution.


How to get Pluralistic:

Blog (no ads, tracking, or data-collection):

Pluralistic.net

Newsletter (no ads, tracking, or data-collection):

https://pluralistic.net/plura-list

Mastodon (no ads, tracking, or data-collection):

https://mamot.fr/@pluralistic

Bluesky (no ads, possible tracking and data-collection):

https://bsky.app/profile/doctorow.pluralistic.net

Medium (no ads, paywalled):

https://doctorow.medium.com/

Tumblr (mass-scale, unrestricted, third-party surveillance and advertising):

https://mostlysignssomeportents.tumblr.com/tagged/pluralistic

"When life gives you SARS, you make sarsaparilla" -Joey "Accordion Guy" DeVilla

READ CAREFULLY: By reading this, you agree, on behalf of your employer, to release me from all obligations and waivers arising from any and all NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap, browsewrap, confidentiality, non-disclosure, non-compete and acceptable use policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its partners, licensors, agents and assigns, in perpetuity, without prejudice to my ongoing rights and privileges. You further represent that you have the authority to release me from any BOGUS AGREEMENTS on behalf of your employer.

ISSN: 3066-764X

Thursday 2026-09-03

10:00 PM

Apple, Google Pathetically Buckle To Trump’s Dim And Lazy Effort To Rename Lake Ontario [Techdirt]

When we look back at this time and history words like “courage,” “integrity,” and “ethics” aren’t words you’re going to be associating with U.S. tech industry leadership. Everywhere you look you have tech sector executives either openly embracing fascism and the frontal assault on representative democracy, or too feckless and timid to take any sort of coherent stand on literally anything (and then wondering why the plebs are increasingly hostile to their software products).

Apple and Google’s quick decision to rename the Gulf Of Mexico at the behest of a mad and racist king was a lovely example; and now we’re back again with both companies quickly moving to rename Lake Ontario “Lake America” just because the increasingly unpopular U.S. President had a brain fart during his pointless and harmful trade war with Canada.

Google was the first to quickly make the change to appease Trump; in fact they acted so quickly on this the change to Google Maps happened before the government had even finished implementing it. Apple was very quick to follow suit, despite the fact that nobody at the company actually supports the ridiculous and pointless change:

“Everyone considers it fucking nuts.” Inside Apple, I'm told "not a soul" supports Donald Trump's Lake Ontario rebrand to "Lake America," but the company is also resigned to making such concessions to avoid the White House's rage. Details in @status.news: www.status.news/p/apple-maps…

Oliver Darcy (@oliverdarcy.bsky.social) 2026-09-02T00:59:49.372Z

These are, so we are clear, active choices — their mapping systems aren’t just innately and automatically following the lead of the authoritarian U.S. government’s GNIS data. Google (and the company’s defenders) had initially tried to insist they were following automated GNIS protocols, but that wasn’t actually the case:

“Google began rolling out this change for US users on Saturday. The company posted a brief update on its Google Maps blog, noting that it follows the US Geographic Names Information System (GNIS) for its maps, so the company implies it had no choice but to rename Lake Ontario in Google Maps, which is the most popular mapping platform in the US by a wide margin.

However, Google was even quicker to switch over to Lake America than the US government. While the GNIS database acknowledges the name change in a summary report, the base map layer still reflects the internationally recognized name of Lake Ontario. A message across the top of the USGS-operated website notes that the change to official maps is still pending.”

Even then, there’s nothing saying Google couldn’t have ignored the GNIS changes for the sake of product quality. As it is, both Apple and Google are still ensuring that U.S. users of both mapping products see King Trump’s pointless change, while everybody else in the world sees material reality.

This lightning-fast choice to quickly buckle to the incoherent whims of a tyrant over something this stupid certainly raises questions about what kinds of subservience we don’t know about yet by these titans of U.S. innovation. There was some hope that Apple, with new CEO leadership and no shortage of “fuck you money,” would demonstrate some sort of ethical leadership here, but alas.

Amusingly Mapquest (and I guess TomTom) used Apple and Google’s abject fecklessness to market “having the slightest hint of a backbone” as a market branding differentiator:

“The company said its mobile app received hundreds of thousands of downloads after it announced Thursday that the name Lake Ontario would remain on its apps, despite Trump directing the Interior Department to update the lake’s name in the Geographic Names Information System (GNIS).”

This is still somehow occurring despite the fact that Trump’s support is cratering due to pointless wars, high oil prices, sagging polling, and clearly waning health. Even on these peripheral issues where taking a stand could be easily defended by an ocean of highly paid lawyers, executives can’t even muster the vaguest outline of some sort of meaningful backbone.

I’m sure they’d argue that it’s their fiduciary responsibility to shareholders to not “antagonize” the U.S. government. But where’s the fiduciary responsibility to the continued existence to functional markets, industry autonomy, and democracy in a country under assault by some of the dimmest, most incompetent and corrupt autocrats the American experiment has ever seen?

08:00 PM

New Release: Tails 7.12 [Tor Project blog]

Firefox is moving to a 2-week release cadence starting in September, and so Tor Browser and Tails are doing the same. Tails 7.12 is the first release on this new cadence.

Changes and updates

  • Update Electrum from 4.7.2 to 4.8.1.

  • Update Tor Browser to 15.0.21.

  • Update some firmware packages. This improves support for newer hardware, including graphics cards, Wi-Fi, and more.

Get Tails 7.12

To upgrade your Tails USB stick and keep your Persistent Storage

  • Automatic upgrades are available from Tails 7.0 or later to 7.12.

  • If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade.

To install Tails 7.12 on a new USB stick

Follow our installation instructions.

The Persistent Storage on the USB stick will be lost if you install instead of upgrading.

To download only

If you don't need installation or upgrade instructions, you can download Tails 7.12 directly:

Support and feedback

For support and feedback, visit the Support section on the Tails website.

07:00 PM

What it is like to be a dog? [Seth Godin's Blog on marketing, tribes and respect]

We have no idea.

Of course, there’s plenty of behavioral data. Say this phrase, or offer that treat, and this particular dog is likely to act in a certain way.

But our inclinations about what it’s actually like to be a dog are all inventions, reverse-engineered to give us a clue about what they might do next.

“If I were you,” is a pretty useless sentence, particularly for dogs. You’re not them, and you can’t imagine what it’s like.

The same is true for computers and for AI. We make up a story about what the computer wants, expects or thinks. But it’s simply a way to explain our guesses about behavior, not actually a statement about what it’s like to be that device or program.

You’ve probably already guessed (there I am, imagining what it’s like to be you) that the same is true for other humans. We only know for sure what it’s like to be ourselves. Everything else is speculation.

Empathy is essential, but it’s also difficult.

      

02:00 PM

Sony Tells Courts Any ‘Reasonable Customer’ Knows Digital Purchases Are Actually Licenses [Techdirt]

Sony’s ability to generate anger lately is pretty impressive. After the company announced that there would be no more physical media versions of games made starting in 2027, to the resounding anger of many people, Sony also demonstrated yet again that it’s capable of ripping away the digital “purchases” people had made once its own licensing arrangements expire. While some folks out there understand that in the cases of some digital goods you’re not actually buying a thing, but a temporary license, many others either don’t know that or simply don’t like it, spurring on further anger against Sony across the internet. And that’s leaving aside entirely the subject of game and cultural preservation in all of this.

Sony is bad enough at this that they can manage to piss me off even when I probably agree with them when it comes to a particular lawsuit. Let’s get through the part where I’m on their side first.

There is a lawsuit going on in California, brought against Sony by a group of PlayStation gamers, that is arguing that the platform doesn’t comply with a relatively new California law for digital purchases that has strict rules around disclosing that the nature of the purchase is a license. The suit argues for non-compliance because the PlayStation Store uses the phrases “buy” and “purchase”, which is forbidden by the law.

Unfortunately for the plaintiffs, that’s not the full story. Here’s the relevant section of the law:

(b) (1) It shall be unlawful for a seller of a digital good to advertise or offer for sale a digital good to a purchaser with the terms “buy,” “purchase,” or any other term which a reasonable person would understand to confer an unrestricted ownership interest in the digital good, or alongside an option for a time-limited rental, unless either of the following occur:

(A) The seller receives at the time of each transaction an affirmative acknowledgment from the purchaser indicating all of the following:

(i) That the purchaser is receiving a license to access the digital good.

(ii) A complete list of restrictions and conditions of the license.

(iii) That access to the digital good may be unilaterally revoked by the seller if they no longer hold a right to the digital good, if applicable.

(B) The seller provides to the consumer before executing each transaction a clear and conspicuous statement that does both of the following:

(i) States in plain language that “buying” or “purchasing” the digital good is a license.

(ii) Includes a hyperlink, QR code, or similar method to access the terms and conditions that provide full details on the license.

And here’s what it looks like if you were to make a purchase for a license for a digital game on the PlayStation Store:

So let’s go back to the law. Yes, the page uses the term “purchase”. It also asks for acknowledgement via the “Confirm Purchase” button that the customer understands they’re buying a license (and it’s in plain language), links to the SPLA and TOS which outline the restrictions and conditions of the license, and details the revokable nature of that license. Sony is arguing it’s compliant and I’m compelled to agree.

And if Sony left it at that, I wouldn’t be writing this post right now. But then the company just had to further and say something really stupid.

Now, as reported by Game File, Sony recently filed its response to the lawsuit, claiming that customers are not only told “your purchase of this digital product amounts to a licence”, but that “reasonable consumers” already understand this anyway without having to be told.

Sony’s argument is that because digital copies of games are not a finite resource, and that because multiple people can buy a digital copy of the same game, that means nobody actually ‘owns’ it – if they did, nobody else would be able to have it.

“As plaintiffs admit, Section 1 of the SPLA likewise explains that ‘the Software is licensed to you, not sold’, Sony’s filing reads. “This makes sense. In the digital age, it is not plausible to allege that reasonable consumers believed they were obtaining ‘ownership’ of a digital game.

“Were that the case, then Plaintiff Edward Heycock would not have been able to obtain the game Resident Evil Requiem on February 25, 2026 for $69.99 from the PlayStation Store after Plaintiff Jason Mendoza had obtained Resident Evil Requiem on February 14, 2026, because Mr Mendoza, not Sony, would have owned it then.”

And on this, Sony can fuck all the way off. This is completely wrong on a variety of levels.

Let’s start with the fact that the internet is chockablock with discussions trying to unconfuse many people when it comes to what they bought in a digital purchase. There are Reddit posts asking this question. There are tech blogs that have put out specific articles answering the question of ownership of certain digital goods. Or, if the wider internet doesn’t suffice for you, the FTC has articles on its own website that try to help address ownership rights for the public for digital goods. Here’s a snippet that will help drive home the second reason Sony’s statement is so dumb.

When you buy a physical item, you’ve got it. It’s yours. But when you click the “buy” button on a digital product, it really depends. You may have access to it only while you have an active account with the platform or website that sold it, or only for as long as that platform or website stays in business. Another factor is Digital Rights Management (DRM) software, which is attached to many digital items and is the thing that makes it impossible, for example, for you to play a video game on a different console brand.

Another reason why you might not have full control of your digital product is that what you really got when you clicked “buy” is often merely a license to access the content. This fact is often explained only in fine print in the terms of service — terms that the seller can usually change at will. And if the seller itself has licensing issues with the content you bought, then your own license to use the digital item can become worthless. All things beyond your control.

So all of these entities putting out all of this information to try to educate the public about what the hell they bought with a digital purchase are only speaking to the unreasonable? That’s, dare I say, an unreasonable thing to say.

And in that FTC post, did you happen to notice just how many qualifiers are stuffed into those two paragraphs? It depends. May. Many. Might. Often. So why all of those qualifiers?

Because some digital purchases can and do confer ownership to the buyer. Not everyone is out here selling a license. Some digital goods are sold as permanent ownership.

So, no matter how this particular lawsuit shakes out, Sony needs to either understand their own customers’ sentiments and knowledge far better than they do, or they need to stop saying things that they know are false. I can attest that the general public does not have a firm understanding of their ownership rights and what they’re actually buying with digital purchases. Pretending otherwise is nonsense.

10:00 AM

Kanji of the Day: 働 [Kanji of the Day]

✍13

小4

work, kokuji

ドウ

はたら.く

働く   (はたらく)   —   to work
働き   (はたらき)   —   work
労働   (ろうどう)   —   manual labor
厚生労働省   (こうせいろうどうしょう)   —   Ministry of Health, Labour and Welfare
労働者   (ろうどうしゃ)   —   worker
共働き   (ともばたらき)   —   both working
稼働   (かどう)   —   operation (of a machine)
働きかけ   (はたらきかけ)   —   pressure
労働組合   (ろうどうくみあい)   —   labor union
厚生労働相   (こうせいろうどうしょう)   —   Minister of Health, Labour and Welfare

Generated with kanjioftheday by Douglas Perkins.

Kanji of the Day: 鍵 [Kanji of the Day]

✍17

中学

key

ケン

かぎ

鍵盤   (けんばん)   —   keyboard (of a piano, typewriter, etc.)
合鍵   (あいかぎ)   —   duplicate key
鍵っ子   (かぎっこ)   —   latchkey child
鍵穴   (かぎあな)   —   keyhole
合い鍵   (あいかぎ)   —   duplicate key
勝敗の鍵を握る   (しょうはいのかぎをにぎる)   —   to have the game in one's hands
鍵盤楽器   (けんばんがっき)   —   keyboard instrument
打鍵   (だけん)   —   keystroke
鍵をかける   (かぎをかける)   —   to lock
内鍵   (うちかぎ)   —   internal lock

Generated with kanjioftheday by Douglas Perkins.

09:00 AM

Meta’s $17 Billion Settlement Is A Bad Deal For Teens And All Social Media Users [Techdirt]

Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.

In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:

  • The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
  • The Settlement places severe restrictions on Teens that can only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
  • The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
  • The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism.

Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.

Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.

Age Gates Reinforced By Age Estimation Technology

In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And Further, Meta will now enforce these age gates with “age assurance” technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The Technology also just adds a layer of creepiness into the user of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]

1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) orage assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.

Those methods might include both commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.

This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.

For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.

Those estimated to be 13-17 years old will be limited to Teen User accounts.

Those estimated to be under-13 will lose their accounts altogether.

Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]

(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.

What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement.

How accurate does the age assurance process need to be?

The Settlement sets maximum false positive for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more 10% for ages 16-17 and 3% for ages 13-15. 

6. Age Assurance Standards.
(a) U18 False Positive Rate Thresholds.
(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall
meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.
(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: 
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.

Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]

9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.

The Settlement generally shows little concern for those falsely placed in its Teen User category.

Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).

(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and 

Any age assurance process Meta uses must be tested annually.

Data minimization

The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” But the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information … where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires at that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.

8. Data minimization and security.
(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).
(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.
(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.

Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)

Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to these estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.

Time restrictions

Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits:

  • Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
  • School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
  • Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
  • “Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be monetarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:
Exhibit G from Meta Settlement showing phone warnings

To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such users controls would have recognized that teens have human rights, agency, and autonomy.

But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.

Feature restrictions (§II.C-D)

Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service.

Again, these would be useful user controls that should be offered to users of all ages.

By default, teens will not see the number of likes or other reactions to their posts.

Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques. 

X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.

Meta has already had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters. 

Content restrictions (P.1, §II.E, as defined by §I.C, E, F)

For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.

C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.
D. “Age Assurance Methods” shall have the meaning set forth in Section II.
E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.

The issue here is that some of these categories are problematic. For example, the Restricted Goods & Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our Stop Censoring Abortion campaign, and in our comment to the Meta Oversight Board. And under the Adult Nudity & Sexual Activity, Meta blocks teens from “real world art of visible genitalia … where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to representations of indigenous womenbreast cancer awareness posts, and posts about testicular and breast self-examseducational posts about ovulation. And it has disproportionately applied the standard to gay and lesbian content in as compared to straight content.  

And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressure Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earned First Amendment defenses to make its own curatorial decisions. 

C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.

The Parental Supervision Tradeoff 

All of these Teen User restrictions can be modified – but only if the Teen User enrolls in the Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, Parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).

And Parental Supervision comes with a huge privacy tradeoff. In exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G] 

Parental Supervision
1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.
2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.
3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.
4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.
5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.
6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.

Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8] 

This may be workable for young people with healthy and safe relationships with their parent or guardian. But obviously not good at all for a Teen User lacking such a safe relationship. 

More Surveillance, Not Less

Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.  

For example: 

  • Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)] 
  • Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)] 
  • Meta pledges to utilize and improve its existing “soft matching models” that track signals such as device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)] 
  • Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3] 
  • Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4] 
  • The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E] 

Moreover, one of the chief threats of Meta’ surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain. 

Meta Has To Pay The States — Establishing Norms Beyond Meta

The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten year-life of the Settlement, these annual payments will total over $11 billion plus the prospect of an additional $5 billion—if Meta competitors adopt the same measures. 

This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get an additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance and age-gating as the norm across online services. 

1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).

2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:

(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.
(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.

3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment

The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance. 

Republished from the EFF’s Deeplinks blog.

07:00 AM

New Alpha Release: Tor Browser 16.0a11 [Tor Project blog]

Tor Browser 16.0a11 is now available from the Tor Browser download page and also from our distribution directory.

This version includes important security updates to Firefox.

⚠️ Reminder: The Tor Browser Alpha release-channel is for testing only. As such, Tor Browser Alpha is not intended for general use because it is more likely to include bugs affecting usability, security, and privacy.

If you are an at-risk user, require strong anonymity, or just want a reliably-working browser, please stick with the stable release channel.

Send us your feedback

If you find a bug or have a suggestion for how we could improve this release, please let us know.

Full changelog

The full changelog since Tor Browser 16.0a10 is:

ICE Finalizes Stun Glove Purchase, Claims There’s No Other Way To Handle ‘Violent’ Migrants [Techdirt]

This was inevitable. ICE has billions of new money to spend, zero shame, and not a single adult in a leadership position capable (or willing!) to talk the agency off the ledge.

ICE decided the neat new tool of cruelty it absolutely had to have were gloves that behave like stun guns or low-powered Tasers. Only one company makes these: Compliant Technologies. There’s a reason for that. Prior to ICE’s devolution during Trump’s second term, no agency of any size really had any reason to buy these stun gloves.

Early adopters were prisons and (wtaf) schools. These gloves made limited sense in prisons where guards are working in confined areas and possibly don’t want to utilize any weapon that might be taken away and used against them. Why they’re being used in schools is literally unimaginable. But here we are in the 21st century, witnessing schools pleading with law enforcement agencies to stop shocking their students with Compliant Technologies G.L.O.V.E., or (brace yourself) Generated Low Output Voltage Emitter, which sounds more like an electrician’s tool than something capable of rendering minors immobile.

With only one provider available, the decision was easy. ICE finalized its threatened purchase of 6,000 G.L.O.V.E.s from Compliant Technologies late last week, ensuring officers will have even more ways to inflict pain on thousands of non-criminals, ranging from ambushed migrants to peaceful protesters who have managed to momentarily inconvenience ICE’s kidnapping squads.

Everything about this is awful, but ICE’s defense of this purchase is both bizarre and palpably evil:

ICE does not currently have an empty hand use of force device to provide to the field amidst unprecedented levels of threats and violence against ICE officers and agents to help ensure they can de-escalate tense situations before they turn violent,” the agency wrote in procurement documents.

WTF? Do you know who else doesn’t have “empty hand use of force devices?” 99.999% of US law enforcement agencies, including federal agencies that generally face more legitimate danger from arrestees, like the FBI, ATF, and Secret Service. And do you know why? Because it’s an absolutely psychopathic use of force “option.”

Somehow, it’s ICE that desperately needs this hideous option, even though all it’s really doing at this point is doing migrant mop-up work — arresting migrants by the thousands despite almost none of these remaining migrants having ever been arrested, much less convicted, for violent crimes.

The procurement document [PDF] contains more supporting statements from ICE that make it clear these gloves aren’t really meant to help subdue violent arrestees. The gloves are being purchased to give ICE officers the means and the opportunity to basically stun anyone they run into, including people they aren’t even seeking to arrest. This paragraph suggests stun gloves are nothing more than a violent way for ICE officers to “de-stress” while at work:

ICE requires a non-lethal, de-escalation device intended to diffuse situations of high-stress environments where physical altercations are likely, such as field domestic disputes or inmate transport in jails. It will be used when a subject is actively or passively resisting and an officer needs to gain control quickly to prevent injuries to both parties.

The document doesn’t explain what the phrase “field domestic dispute” means, nor does it provide context. Reading “domestic dispute” in its usual context, the sentence seems to suggest officers should be able to stun their domestic partners into compliance when things at home get a bit heated. Obviously that’s not what that phrase means, but it’s an extremely weird grouping of words that seems to be specific to ICE and its desire for gloves that can shock people.

Further down, ICE makes it clear it’s going to allow officers to deploy the gloves against peaceful protesters or anyone else who might be considered an obstacle to officers’ kidnapping plans.

“Soft” Empty-Hand Control- Enabling officers to briefly distract a subject who is resisting or hiding their hands to secure handcuffs without transitioning to higher, more forceful levels of control.

Civil Disturbance- Assisting crowd control units in moving groups or denying access to areas without requiring lethal or high-impact munitions.

ICE makes it sound like its officers will stop shooting or beating people because of these gloves. But I can guarantee you the gloves will be used whenever possible, especially when they might facilitate a beating. Since pretty much every ICE officer wears gloves, it will be impossible to tell who’s wearing the stun version and who’s just trying to look like a Call of Duty lobby idle animation. Officers are absolutely going to love these gloves because the element of surprise will always be on their side.

There’s no way ICE seriously believes 6,000 pairs of hand-worn cruelty application devices will actually limit the use of deadly force. But it can probably assume it might reduces shootings because its thousands of under-trained officers will probably be less willing to grab a metal gun from near their waist when they’re not sure whether or not their G.L.O.V.E.s are still activated.

This is just a way for ICE officers to hurt more people while pretending stunning anyone an officer touches is synonymous with de-escalation. This is just an agency loaded from top to bottom with sadists seeking out novel ways to inflict more pain.

06:00 AM

Hiking the Alps [dperkins]

This year progress on the Top 100 Mountains continues. Here are pictures from day and overnight trips to the Japanese Southern Alps and Central Alps this year.

Mt. Hoo

During spring break, I drove to Kofu, Yamanashi, and climbed Mt. Hōō (鳳凰山). There are several summits, and given the abundance of snow and ice, I summitted Jizō-dake (地蔵ヶ岳), notable for a giant rock at the top — the Obelisk. The trail was slow but fun: one third dirt, one third ice, and one third snow.

20260330.1.Alps.jpg 20260330.2.Jizo-dake.jpg 20260330.3.Obelisk.jpg

Yatsugatake & Mt. Tateshina

The snow was gone by May, so I drove up to the Central Alps in southern Nagano and climbed Yatsugatake (八ヶ岳). Yatsugatake has a handful of summits, and my route went over Amida-dake (阿弥陀岳) and Aka-dake (赤岳). The next day, I went up Mt. Tateshina (蓼科山), another mountain not far to the north. One fun thing about hiking so much in the Southern and Central Alps this year is learning the landscape. Many of these mountains are visible from one another on clear days, and if you don't know what you're looking at, it's guaranteed that some other hiker will tell you. Mt. Fuji shows up from time to time, too.

20260530.1.Yatsugatake.jpg 20260531.1.Tateshina.jpg

Mt. Kita & Mt. Aino

The second- and third-highest mountains in Japan are Mt. Kita (北岳) and Mt. Aino (間ノ岳), and you can day trip them if you really want to. There are many mountain huts along the way, so your gear need not be burdensome, and the scenery is majestic. Nevertheless, it's strenuous to say the least, and my legs were aching by the end of the day.

20260703.1.Fuji.jpg 20260703.2.Hoo.jpg 20260703.3.Senjo.jpg 20260703.4.Kaikoma.jpg

Mt. Tekari & Mt. Hijiri & Mt. Kisokoma

In late summer I drove to Nagano for more hiking. First was a two-day hike. It was a brutal ascent up to Mt. Tekari (光岳), but once I got up there, following the ridge north over Mt. Chausu (茶臼岳) was pleasant, and the weather was wonderful. After the long day with massive vertical gain, I spent the night at Chausu Hut (茶臼小屋). The mattress was thin and I slept poorly, but the building was warm and the food was good. The next morning we all awoke to a spectacular view of Mt. Fuji at sunrise. The pictures speak for themselves.

On the second day, I continued north, stopped briefly at the top of Mt. Kamikochi (上河内岳) went to the summit of Mt. Hijiri (聖岳), and headed back down to the car. Going down was much easier than going up, but my shoes were getting old and I got some blisters. That afternoon I went to an onsen in the nearby village of Toyamago, because a long bath after a long hike is just lovely, and then drove north for an hour.

After sleeping in the car, I got up and took the alpine bus and cable car most of the way up Mt. Kisokoma (木曽駒ヶ岳). From there it was a leisurely stroll to the summit. Many years ago we were here on a school trip but didn't get to the top because of bad weather. So it was nice to return, go the extra kilometer, and get the good vibes and views.

20260831.1.Tekari.jpg 20260831.2.Chausu.jpg 20260831.3.Fuji.jpg 20260901.1.Fuji.jpg 20260901.2.Fuji.jpg 20260901.3.Fuji.jpg 20260901.4.Ridge.jpg 20260901.5.Hijiri.jpg

RSSSiteUpdated
XML About Tagaini Jisho on Tagaini Jisho 2026-09-04 01:00 PM
XML Arch Linux: Releases 2026-09-04 11:00 AM
XML Carlson Calamities 2026-09-04 11:00 AM
XML Debian News 2026-09-04 12:00 PM
XML Debian Security 2026-09-04 01:00 PM
XML debito.org 2026-09-04 12:00 PM
XML dperkins 2026-09-04 07:00 AM
XML F-Droid - Free and Open Source Android App Repository 2026-09-04 11:00 AM
XML General Union 2026-09-04 08:00 AM
XML GIMP 2026-09-04 11:00 AM
XML Japan Bash 2026-09-04 01:00 PM
XML Japan English Teacher Feed 2026-09-04 01:00 PM
XML Kanji of the Day 2026-09-04 11:00 AM
XML Kanji of the Day 2026-09-04 11:00 AM
XML Let's Encrypt 2026-09-04 11:00 AM
XML Marc Jones 2026-09-04 11:00 AM
XML Marjorie's Blog 2026-09-04 11:00 AM
XML OpenStreetMap Japan 2026-09-04 11:00 AM
XML OsmAnd Blog 2026-09-04 11:00 AM
XML Pluralistic: Daily links from Cory Doctorow 2026-09-04 01:00 PM
XML Popehat 2026-09-04 11:00 AM
XML Ramen Adventures 2026-09-04 11:00 AM
XML Release notes from server 2026-09-04 11:00 AM
XML Seth Godin's Blog on marketing, tribes and respect 2026-09-04 07:00 AM
XML SNA Japan 2026-09-04 07:00 AM
XML Tatoeba Project Blog 2026-09-04 01:00 PM
XML Techdirt 2026-09-04 12:00 PM
XML The Business of Printing Books 2026-09-04 11:00 AM
XML The Luddite 2026-09-04 11:00 AM
XML The Popehat Report 2026-09-04 07:00 AM
XML The Status Kuo 2026-09-04 07:00 AM
XML The Stranger 2026-09-04 11:00 AM
XML Tor Project blog 2026-09-04 12:00 PM
XML TorrentFreak 2026-09-04 01:00 PM
XML what if? 2026-09-04 01:00 PM
XML Wikimedia Commons picture of the day feed 2026-09-01 01:00 PM
XML xkcd.com 2026-09-04 01:00 PM