[*] [+] [-] [x] [A+] [a-]  
[l] at 8/8/26 1:00pm
This Week in 2016 Manhattan DA Continues To Claim We Dont Want Crypto Backdoors… By Which He Means He Wants Crypto Backdoors No Matter Who Our Next President Is, They Wont Understand Technology Broadband Industry Formally Tries, Once Again, To Kill Net Neutrality Comcast Tells The FCC It Should Be Able To Charge Broadband Users A Premium For Privacy Getty Sued Again Over Abusing Copyright Law, Licensing Images It Has No Rights To DOJ Makes Smart Decision On Music Licensing… Music Publishers Completely Lose Their Shit This Week in 2011 Court Finds Megaupload Could Be Guilty Of Direct Infringement In Perfect 10 Case Is Google Antitrust Investigation Simply A Repeat Of Wasteful Microsoft Antitrust Effort? Ron Wyden Puts Hold On FISA Amendments Act; Wants Answers To How Many Americans Have Been Spied On Huge Ruling: Court Says Proving Copyright Infringement Does Not Automatically Mean Irreperable Harm Righthaven Fails To Pay Sanctions; Complains A Day Late Mattels Lawsuit To Claim Ownership Of Bratz Comes Back To Bite Big Time: Told To Pay $309 Million This Week in 2006 Instant Messaging Still Not Ruining Kids Grammar Earth-Shattering Study Confirms Young People Dig New Technology Death Of Old Media Still Greatly Exaggerated Fake Bill Gates Quotes More Boring Than The Real Thing Now The Internet Makes You Neglect Family And Chores? Germany Says You Cant Resell Software

[Category: 1, history, look back]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/7/26 8:39pm
Buc-ees trademark bullying ways continue! This company that has long been famous for its enormous gas station and convenience stores practically dripping in Americana is quickly building a national reputation for itself as a petulant trademark bully. Its lawsuits are typically dumb and usually feature Buc-ees claim that it somehow owns every cartoon animal mascot depiction for convenience stores and gas stations, and even cartoon human mascots at times. Its so bad that it even caught the attention of John Oliver recently, resulting in the show creating its own merchandise that is far more similar to the Buc-ees beaver than most of its lawsuit victims and Oliver literally begging them to file a lawsuit over it. Well, the Buc-ees people appear to be cowards. Oliver made it clear that he and HBO have the willingness and legal war chest to do battle with Buc-ees. To date the company has not filed any lawsuit against Oliver or HBO. But it did just file another trademark suit against another small local convenience store after having just moved into the market. Buc-ee’s, which opened its first location in Ohio earlier this year, is suing Beaver’s Mini Mart in Beavercreek for what they allege is trademark infringement.  In the suit, filed days ago, Buc-ee’s alleges that the Mini Mart’s cartoon beaver mascot is too similar to their own, with its “wide eyes and a smile” that also “uses red as a predominant color,” and could cause confusion.  The new Buc-ee’s location in Huber Heights, Ohio, is 16 miles from Beaver’s Mini Mart. Beaver’s Mini Mart customers say they have been shopping there for decades, while Buc-ee’s has existed in the Buckeye State only since April. This is common practice for Buc-ees. The company expands into a new market and goes on a trademark suit blitz against anyone using one of these cartoon animal logos, beaver or otherwise. It doesnt matter how long the victim company has been doing business there. It doesnt matter how ingrained into the community they are. It doesnt matter if every local in the area insists that theres no confusion to be had between the two entities. In this case, the Beavers Mini Mart has been around for decades. The entire community is awash in beaver-y iconography. Ill let one of our anonymous commenters from our John Oliver post chime in here. They are now trying to sue a place near where I grew up, the “Beavers MiniMart” convenience store in Beavercreek Ohio, where the local high school, Beavercreek High School, once had Bucky the Beaver as a mascot for their football team, the Battling Beavers, their cheerleaders are called the Beaverettes and there’s pep squad called the Beaver Patrol. There’s concrete statues that are 6-8 feet tall, all over the city. The city loves it’s fuckin’ beavers. Buc-ee’s probably doesn’t know what’s about to happen to them. It wont be pretty. The signage from Buc-ees own lawsuit show just how unalike the branding for the two companies is. From this, and wielding a trademark Buc-ees somehow has on the word Beavers Buc-ees alleges that there will be confusion among consumers, that the Mini Mart is trading on Buc-ees goodwill, and that all of this is causing irreparable injury to Buc-ees. Ironically, it appears this very lawsuit is causing a dip in all of that supposed goodwill Buc-ees has in this particular community. “Reading into it more that Buc-ee’s has gone after other companies over this… It just put a bad taste in my mouth because they just seem like such a fun company,” resident Sam Bryan told Nexstar’s WDTN. “To see this, that they’re coming after a small business like this, it upset me like it did a lot of Beavercreek residents.” The town is named Beavercreek, the branding doesnt look anything alike, and nobody is going to be confused about any of this. Buc-ees knows all of that. But trademark bullies typically just cant help themselves and this is yet another in a long list of bullshit trademark lawsuits the company has filed. If Beavers Mini Mart fights this, however, it would be an interesting move in its defense to point out that there is no similar lawsuit against John Oliver.

[Category: 1, beaver's mini mart, buc-ee's, hbo, john oliver, trademark, trademark bullying]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/7/26 4:18pm
For years, John Deere had actively made repairing their tractors near-impossible for anyone but itself and the few authorized repair shops—regardless of the ability of its customers to actually visit such shops. Now, in a major win for farmers and right to repair advocates, John Deere must soon provide farmers with not just the tools and resources to finally repair their own John Deere equipment, but also access to future updates for said equipment. In 2025, the Federal Trade Commission (FTC) brought a suit against farm equipment manufacturer John Deere, alleging John Deere used their control over equipment repair tools and resources to limit the ability of farmers and independent repair providers (IRPs) to repair John Deere equipment. Earlier this month, John Deere reached a settlement with the FTC in which they will immediately make available a tranche of repair resources, then continue to make further resources available until the end of the year. Five states joined the FTC in this suit, and over the next 10 years these states will work alongside the FTC to ensure John Deere complies with this settlement.  It is worth noting there is a second, farmer-initiated antitrust lawsuit against John Deere, also concerning a farmer’s right to repair their own equipment. In April, John Deere agreed to a $99 million settlement in that case, which also includes right to repair provisions. This fight is just one example of how, as machines become increasingly computerized, companies like John Deere restrict your ability to repair machines behind software subject to legal regimes that don’t just lock down repair, but make unauthorized repair a potential criminal offense.  John Deere’s market dominance in farm equipment led to an extraordinary power over access to the tools and resources of repair. John Deere actively restricted who had access to repair tools, and monopolized who could do the repair. This revenue stream—and control of it—is built into the business models of a lot of the technology we buy today. It also encourages companies to move away from the kinds of devices that can be easily fixed at home to ones that offer bells and whistles no one wants but makes repair difficult—like app-enabled toasters.  This whole saga with John Deere has been an exemplar of the greater need for right to repair laws, policy, and enforcement.  There was a time when you bought a tractor and with some know-how and a manual could fix it yourself. It is easy to envision why someone with John Deere farm equipment might find it inconvenient to wait for John Deere approved repairpeople to come and fix any broken equipment. Especially when it meant waiting for days or weeks. Especially if it meant their crop was withering on the vine. This settlement will help ensure this is no longer the case.  But it’s not just about farm equipment; If you can’t fix it, you don’t own it. While some might feel more willing to agree they “shouldn’t” futz with laptops or smartphone, it still stands that — whether it’s farm equipment, a car, a laptop, or even your phone — if you legally cannot fix it yourself, if you must go hat in hand to an “approved provider,” you are at the mercy of a corporation. It is why EFF continues to support right to repair laws that ensure people truly own what they buy. And it is why EFF continues to fight for exemptions to the law that makes it most difficult to tinker and repair your own devices. Originally published to the EFFs Deeplinks blog.

[Category: john deere, ftc, ownership, right to repair]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/7/26 2:07pm
Ctrl-Alt-Speech is a weekly podcast about the latest news in online speech, from Mike Masnick and Everything in Moderations Ben Whitelaw. Subscribe now on Apple Podcasts, Overcast, Spotify, Pocket Casts, YouTube, or your podcast app of choice — or go straight to the RSS feed. To get extended episodes with additional coverage, support us on Patreon. In this weeks episode, Mike and Ben cover: India summons Meta executives over briefly restricted Modi Facebook post (Reuters) ‘No explanation given’: Arvind Kejriwal claims Meta restricted his account in India (The Times of India) Meta apologises to India for restricting PM Modis post (Reuters) India temporarily bans Telegram over exam paper leak concern (BBC) eBay agrees $56m settlement with bloggers over harassment case (BBC) Artist starts legal case against Meta for deleting her Instagram account (The Art Newspaper) And in the extended episode for Patreon supporters, they cover: Telegram CEO says an extortionist planted CSAM in a chat to get it pulled from the App Store (The Verge) TikTok Withheld a Safety Feature From Millions. One Died by Suicide (Bloomberg) TikTok Says ‘Moderator Error’ Kept Perez Hilton Livestream Up (Wired) Our fun links this week are the Nintendo gameplay counsellors and a revamped app for sharing your toilet flushing habits.  If you’re already a Patreon supporter, you can get the extended episode on Patreon.

[Category: 1, ebay, meta, telegram, tiktok, content moderation, india, trust and safety]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/7/26 12:11pm
Well, it looks like investigators better go back to doing actual investigations in the Fifth Circuit, rather than just assuming a little paperwork and a whole lot of assistance from service providers is going to do their work for them. For at least the second time in the same state (Mississippi), federal judges have rejected cell tower dump warrants, ruling that these warrants (obviously) cannot hope to meet the Fourth Amendments particularity requirements. The first time this happened was early last year, when a magistrate judge rejected four successive cell tower dump warrants submitted by the FBI. The magistrate was the first level of review in this case. The latest involves the second level of review by a federal circuit judge (h/t Josh Gerstein). This decision does nothing more than affirm the magistrate judges rejection of these cell tower dump warrants. (Another rejection of cell tower dump warrants occurred in Nevada roughly six weeks after this one, but thats in a different circuit so its up to the Ninth Circuit Appeals Court to establish this precedent.) But the origin of these successive rejections goes back a bit further. Bucking its own anything-for-the-cops tendencies, the Fifth Circuit Appeals Court delivered a ruling in August 2024 that said geofence warrants were unconstitutional. That decision relied heavily on the Supreme Courts 2018 Carpenter ruling the one that said long-term location tracking (via cell site location info) was unconstitutional. The Fifth Circuit Appeals Court used the Supreme Courts Carpenter reasoning to move location info out from under the protection of the Third Party Doctrine. More specifically, it had problems with geofence warrants warrants that force Google to search everyones location records before handing law enforcement a list of probables based on whatever time/date/location restrictions investigators give it. Turning everyone into a suspect just because investigators dont actually know who theyre looking for makes a mockery of the Fourth Amendments demands for particularity. The government likes to believe that the only particularity needed is the distinct probability that Google stores the location records theyre asking for. Thats not enough. So, in the Fifth Circuit, precedent says geofence warrants are more likely than not to be rejected for a lack of particularity. This probably explains why the FBI decided to roll its dragnet back to the previous version: the cell tower dump. Rather than ask Google for location data, the investigators asked every cell service provider in the areas where crimes were committed to dump all connection records fitting those search limitations. As each warrant was rejected by the magistrate, the FBI made further alterations in hopes of having a warrant approved. But even specifying that the dumps only include cell numbers with multiple hits couldnt save them. Heres how the magistrate judge delivered the news to the FBI last March: [W]hile the Government has some idea of who may have been involved in one or more of the crimes—the affidavits supporting the warrant applications list seven potential suspects—the Government has not presented probable cause to believe that any particular individual committed any of the specific crimes described. The warrant applications also arguably present probable cause to believe that the searches will reveal the location data of some unknown perpetrators of the crimes. See Mem. at 3 (explaining that affidavits describe “the belief that the cell towers will contain evidence of [who committed] the offenses”). But this is not enough. If the Court were to issue the warrants, it would be authorizing the Government to search the data for every cellular device (including cell phones) of every single individual near the crime scenes without a showing of probable cause as to each individual. More succinctly (and pithily), heres why cell tower dumps (and geofence warrants) are unconstitutional: Stated another way, the Government is essentially asking the Court to allow it access to an entire haystack because it may contain a needle. As stated above (scroll back a bit because Im terrible at writing short lead-ins), this new ruling [PDF] presents a final rejection for these cell tower dump warrants. The government can always appeal a magistrates warrant rejections, but appealing past this point puts the government back into the Fifth Circuit queue. And if the Fifth Circuit said geofence warrants (which are just a different haystack) are unconstitutional, its highly unlikely it will give cell tower dumps a pass. This decision starts off with a nod to history before immediately bringing everything up to date: Such intrusions would have been unthinkable to those 55 men gathered in Philadelphia in 1787. Therein lies the problem—the technological resources at the government’s disposal unlock efficient and effective ways to solve crime in the twenty-first century, but they also expose individuals’ whereabouts at all times, including in sensitive places. The government now has the capacity to identify any individual with a cell phone, at any public or private location. That sort of efficiency needs to be checked (as in checks and balances). Thats why we have courts. And this court is willing to do what many wont: refuse to bless constant expansion of government power and information access just because todays everyone-voluntarily-carries-a-tracking-device reality could not possibly have been foreseen when the Fourth Amendment was put into play. The government tried to argue that cell tower dumps do not track peoples locations like the historical CSLI (cell site location info) at the center of the Supreme Courts Carpenter ruling. The court says thats not the point, especially not when the Supreme Courts ruling is considered in conjunction with the Fifth Circuits rejection of geofence warrants. [T]he Fifth Circuit has recognized that “the potential intrusiveness of even a snapshot of precise location data should not be understated.” Smith, 110 F.4th at 833. See also Chatrie, 146 S. Ct. at 2209-12 (discussing how the length of the search does not determine whether a search occurred). Though tower dumps provide more limited, less-detailed information than geofencing, the inherent nature of this type of search remains corrosive to individuals’ privacy interests. Furthermore, the government tends to ignore how the Fourth Amendment has been defined since its inception. While the government would prefer its definition of particularity to be limited to we have probable cause to believe the place searched will contain whats being searched for (which is how the government portrays both geofence and tower dump warrants), the courts have long understood the particularity requirement to mean this when it comes to probable cause: “Probable cause is not a high bar.” District of Columbia v. Wesby, 583 U.S. 48, 57 (2018) (quotation marks and citation omitted). The Government only needs to show that “there is a fair probability that contraband or evidence of a crime will be found in a particular place.” Illinois v. Gates, 462 U.S. 213, 235, 238 (1983). Cell service provider tower records are neither contraband nor evidence of a crime. They may help investigators produce a list of probable suspects, but that is not the same thing as contraband or evidence. Summing everything up, the federal court rejects every one of these warrants and makes it clear the government will need to do something other than ask tech companies and service providers to generate lists of suspects for it especially when doing so means turning thousands of people into possible suspects just because they happened to be near certain cell towers when crimes were committed. Law enforcement benefits from tower dumps, as evidenced by recent cases, and this decision may thwart certain criminal investigations. But the gentlemen in Philadelphia knew the Fourth Amendment’s protections would come with costs. The cost to law enforcement is the price we pay to be free from arbitrary Government intrusion into our everyday movements. Its that last sentence thats going to piss off the government the most. All levels of law enforcement seem to believe its the public who should be making all the sacrifices when it comes to law enforcement efficiency. This ruling sets the record straight. And if the government wants to take another run at the Fifth Circuit, it certainly can. Given what its seen so far, it would probably be better if it didnt.

[Category: 1, 3rd party doctrine, 4th amendment, 5th circuit, cell tower dumps, mississippi, phone records, surveillance]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/7/26 12:06pm
The 2026 Data Engineering Bundle has 7 online courses designed to help learners build skills that align directly with industry expectations. The focus is on practical tools and languages used by data professionals: Python for programming, Pandas and NumPy for data manipulation, foundational certification prep and specialized work with Databricks, an industry-standard platform for data engineering and analytics workflows. The content is on-demand, self-paced and designed to be revisited as learners build proficiency over time. Its on sale for $35. Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

[Category: 1, daily deal]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/7/26 10:23am
There are many ways to describe the Trump Era, but the executive branchs conviction that it can simply ignore the legislative branchs entire existence has become something close to a governing principle. From impounding funds designated by Congress to launching a war without Congresss authority, Trump has basically decided that the legislative branch is a vestigial organ of the federal government. This latest one may seem smaller than those stories, but its another demonstration of how little the executive branch thinks the laws Congress wrote actually matter. Specifically in this case, the FCC has voted to scrap the congressionally-mandated limits on broadcast TV ownership. This, despite a long list of people whod normally be on Carrs side — Republican members of Congress, the former FCC commissioner who helped negotiate the cap in the first place, the House Majority Leader who cut the final deal — all saying the FCC cant do this. Even Ted Cruz says hes skeptical. But Carr has done it anyway. And while Im sure the usual coterie of MAGA Trump defenders will insist this is all fine, its obviously an end-run around Congresss authority. Congress set that number itself, writing directly into statute that no single company may own stations reaching more than 39% of American households. It was in a 2004 appropriations bill that raised this limit from the previous 35% to 39%. Thats Congress clearly putting into law that the FCC must have a cap of 39% reach for TV ownership. But Brendan Carr says he can change this because its outdated. Heres how Carr previewed the vote last month in an oped for Breitbart: On August 6, the FCC will vote on eliminating the outdated national cap in favor of a new case-by-case approach. Previously, the cap operated as a blanket prohibition on any and all deals that would combine stations in excess of the 39 percent limit—regardless of whether it was a good deal or a bad one for the country. Our new proposal would allow the FCC to approve deals that exceed the 39 percent cap, but only if doing so would promote the public interest. Even if you agree with Carr that the 39% ownership cap is outdated and that its not in the public interest, thats not Carrs decision to make. He is saying, out loud, that the FCC can ignore an act of Congress whenever the FCC decides that act has gotten stale — with the FCC, conveniently, being the sole judge of staleness. Of course, all this comes right after Nexstar and Tegna — two giant, reliably GOP-friendly broadcast companies — merged into something massively exceeding that 39% cap (thanks to Carrs support). You know full well (as does Carr) that if the two companies merging here were the kind he likes to call leftist or woke, there is no chance hed wave them past the 39% cap. Hed suddenly put on his attempt at a solemn face and talk about how unfair it would be to the public interest of America to let one company control that much broadcast spectrum. The lone remaining Democrat on the Commission, Anna Gomez (who Trump likely hasnt fired yet only because the FCC needs a quorum to do anything at all), has pointed out that this is all quite obviously unlawful. Today’s decision to eliminate the 39 percent national audience reach cap is unlawful on its face and a profound departure from both statutory boundaries and longstanding broadcast policy. Congress set this cap in federal law, and only Congress can change it. I cannot support an action that so plainly exceeds the Commission’s authority while simultaneously overlooking the real-world consequences for the public we serve. She goes into further detail about how the wording in the Telecommunications Act is pretty clear that the FCC cant just ignore this cap or change it without congressional approval. And cites a bunch of Republicans including former FCC officials, along with both current and former elected officials in Congress: Further, knowledgeable republicans with direct experience shaping, and later interpreting, the national audience reach cap agree that today’s action is plainly foreclosed by law. Former FCC Commissioner Mike O’Rielly, who was personally involved in the negotiations that produced the 39 percent cap, has stated unequivocally that the Commission ‘does not have the authority to modify the national audience reach cap,’ explaining that Congress expressly codified the cap in statute, removed it from the Commission’s periodic ownership review, and never revisited that limitation. Former House Majority Leader Tom DeLay, who negotiated the final compromise with Senator Ted Stevens, has likewise emphasized that the 39 percent cap was deliberately enacted to prevent FCC revision absent a future act of Congress, underscoring that ‘regulatory agencies cannot defy or modify laws enacted by Congress’ and reaffirming that the cap is ‘a statute, not a suggestion.’ And while Senator Ted Cruz did not serve in Congress during those negotiations, his present role as Chair of the Senate Commerce Committee gives him direct oversight over this very issue. He has made clear that he is ‘skeptical a change can be made absent an act of Congress,’ signaling that Congress’s intent remains unchanged today. Taken together, these perspectives from the architects of the cap, the regulators who implemented it, and the congressional leaders who now oversee it underscore a bipartisan, durable, and deeply informed consensus that the law prohibits the Commission from eliminating the national audience reach cap. No amount of policy preference can substitute for statutory authority Gomez also points out that if Carr were actually concerned about the public interest in these deals, the FCC sure has a funny way of showing it. For all of Carrs talk about weighing the public interest deal by deal, his Media Bureau has refused, every single time, to look at what these mergers actually do to the public — specifically, what they do to the retransmission fees that show up on your cable bill: What is notable about such reviews is the studied avoidance thus far of addressing the impact of the transaction at issue on retransmission consent fees on the merits every single time it is raised. The Media Bureau routinely summarily dismisses such issues as outside the scope of what it should be considering. For example, in the Nexstar Tegna decision, despite evidence that the transaction would result in millions of dollars in increased fees on consumers, the Media Bureau determined that it was inappropriate to consider the issue in that “case-by-case” review because “allegations regarding retransmission consent do not raise a substantial and material question of fact as to whether grant of the Applications would serve the public interest” and such questions should be considered in a rulemaking proceeding. Clearly the Commission does not want to address the challenging questions retransmission consent raises, but passing the buck to another proceeding when the impact is significant, direct, and current can only go so far without becoming the very essence of arbitrary and capricious. The Commission has crossed that line here. This is indefensible. Its almost certain that a lawsuit will be filed challenging this unilateral move by the FCC to simply rewrite congressional law. But either way, this shows (yet again) how the current administration sees Congresss role as entirely ceremonial. At least when a Republican is president. The second that a Democrat is back in the White House you can absolutely guarantee that partisan dipshits like Carr will suddenly rediscover the need for Congress to set all the rules. After all, when Biden was in office, Carr was one of the most vocal in pointing out that Congress limits the FCCs authority and you cant just ignore Congress. Here he is complaining about the FCC pretending it has freewheeling authority to ignore Congress: Today’s NPRM appears to me to be part and parcel of that broader effort, which I cannot support. It relies on Section 616(a) of the Communications Act, which lists six very specific things the FCC can regulate in MVPD carriage agreements. That list provides a good clue of how Congress intended to circumscribe our statutory authority. But the NPRM asserts that we may go beyond that list and exercise freewheeling authority over private carriage agreements. I am dubious. Huh. How odd. In that same dissent he says that the FCC must wait for Congress to act: Unless and until Congress decides to delegate additional authority to the FCC over OTT streaming, we should act with the appropriate dose of regulatory humility. What happened to that regulatory humility, Brendan? Or how about his concerns about Congress when he dissented from the Biden FCCs attempt to deal with digital discrimination? Back then, he was super duper concerned that Congress had not approved this. Needless to say, Congress never contemplated the sweeping regulatory regime that President Biden asked the FCC to adopt—let alone authorized the agency to implement it. Nonetheless, the FCC is voting to put President Biden’s plan in place. I oppose the plan for several reasons. In that dissent, hes clear about not going beyond congressional authority: Of course, Congress did not give the FCC the power to do any of this—the agency just creates it out of whole cloth. But now that Trump is in charge, Carr is happy to erase a rule Congress wrote and to replace it with his own judgment. Oh, and when the Biden administrations FCC tried to bring back net neutrality? You sure know that Brendan Carr was furious that they would ignore the will of Congress. Indeed, he used that to whine about Chevron deference, allowing agencies like the FCC to ignore the will of Congress. But, of course, the Supreme Court got rid of Chevron deference in Loper Bright, a decision Carr celebrated. But before that, in dissenting from the FCCs moves on net neutrality he went on an extended rant about how the FCC should require explicit consent from Congress: Congress never passed a law saying that the Internet should be heavily regulated like a utility, nor did it pass one giving the FCC authority to make that monumental determination. The Executive Branch pressured the agency into claiming a power that remained—and remains—with the Legislative Branch. Gosh. Its almost as if Brendan Carr thinks that when Democrats are in power, the FCC should be limited in what it can do by Congress, and when Republicans are in power, Congress is entirely there for show. For the past decade, the central project of the conservative legal movement has been convincing courts that federal agencies constantly grab powers Congress never handed them. Thats what West Virginia v. EPA was about. Thats what Loper Bright was about. The entire premise of the major questions doctrine is that when an agency makes a decision of real economic and political significance, it had better be able to point to clear authorization from Congress. Carr cannot point to clear authorization from Congress on this. He can point to the precise opposite: a specific number, written into a specific statute, after a specific fight, for the specific purpose of taking this decision away from the FCC. He isnt stretching an ambiguous grant of authority. Theres nothing here to stretch. Hes crossing out a figure Congress chose and penciling in whatever I think is good for the country. And hes replaced it with a process where he is the judge. Deals get approved if they promote the public interest, with Carr deciding what that means, deal by deal, with no cap, no standard, and (as Gomez points out) a Media Bureau that refuses to look at the one concrete public harm anyone actually raises. Remember when Carr set up his delete, delete, delete docket in which he promised to delete unnecessary regulatory underbrush? This is the opposite. Its the FCC chair converting a bright-line rule Congress wrote into a regulatory permission slip he personally issues. Companies that want to get very large now have an obvious incentive to make sure Carr is happy with them, which is presumably the feature rather than the bug. 2023 Brendan Carr would be livid. Maybe 39% is the wrong number in 2026. Thats an argument someone could make honestly. Theres even a body specifically designed to hear it, weigh it, and write a new number into law if its persuaded. It meets a few blocks from the FCC. Carr, with Trump in the White House, would rather pretend it isnt there.

[Category: 1, anna gomez, brendan carr, congress, fcc, media ownership]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/7/26 6:27am
Back in May I noted how the Trump FCC had unveiled a brand new plan to “stop robocalls.” I also noted how the plan doesn’t actually stop robocalls because a well-lobbied U.S. government (1) refuses to hold big companies accountable or collect fines, (2) constantly embraces weak rules that make telemarketers and debt collectors happy through endless loopholes, and (3) has an unhealthy fixation with undermining regulatory oversight at the behest of large companies. Worse; buried in the Trump FCC plan are several initiatives that would harm U.S. privacy and help ICE and other government domestic surveillance efforts. The biggest being a plan to crack down on burner phones by forcing telecoms (the ones bone-grafted to our domestic surveillance operations) to dramatically scale up the information they collect from consumers. More specifically, the Trump FCC is planning to expand the agencys Know Your Customer (KYC) requirements by imposing a requirement to “at a minimum, obtain and retain the name, physical address, government issued identification number, and an alternate telephone number of any new and renewing customer.” That’s unsurprisingly raised concerns among privacy advocates and civil rights groups well aware that greater surveillance will be abused by the Trump administration and beyond. It also ignores that there’s often very good reasons why abuse victims, whistleblowers, journalists, refugees, and others might be seeking an anonymous prepaid burner phone. On the off chance they might be able to sway Brendan Carrs thinking, sixteen privacy groups including the Electronic Frontier Foundation have fired off a letter to the agency warning the FCC to avoid undermining public privacy: Beyond creating acute privacy risks for all subscribers, the proposal would endanger anonymous communications that have long protected whistleblowers, activists, journalists, and domestic violence survivors. A survivor of domestic violence fleeing an abuser should not have to create a record that leads back to their door in order to get a phone. Nor should a whistleblower or a survivor escaping a trafficking situation. Further, the FCC is responsible for protecting privacy of customer information through its telecom privacy provisions and laws like the Safe Connections Act. This proposal undercuts those protections. The additional requirements would also push anonymity out of reach for untold millions of unhousedindividuals, low-income Americans, older adults, foster youth, and others who need anonymity but may struggle to provide required identifiers. The groups note it also puts even greater private information in the hands of companies with some of the worst track records on privacy in America. In 2021, a T-Mobile breach exposed the Social Security numbers and drivers license numbers of approximately 77 million people and, in 2024, an AT&T breach exposed the call and text records of nearly all its wireless customers (roughly 110 million subscribers). Mandating that thousands of originating providers, including small carriers with limited resources to protect the privacy and security of such an extensive amount of information, collect and retain government IDs for the life of the customer relationship plus four years creates significant new exposure. Of course the Trump administration doesnt really care about fixing robocalls. If it did, it would hold the biggest scam callers (large legitimate companies and debt collectors) accountable, actually follow through on penalties, stop embracing mindless deregulation, and take aim at the biggest domestic telecoms that have historically dragged their feet on enforcement (and adopting anti-spoofing authentication technology) because theyve profited from the scams and harassment of their own customers. Brendan Carr isnt the type of guy who cares about holding large U.S. companies accountable for anything. Hes more into broadly gutting corporate oversight at the behest of monopolies, dismantling the First Amendment, and expanding domestic surveillance especially of vulnerable populations being targeted and brutalized by ICE.

[Category: 1, anonymity, authentication, domestic abuse, fcc, robocalls, shaken/stir, surveillance, telecom]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/6/26 9:03pm
When Erica Schwartz was first nominated for Director of the CDC, you could almost hear both a gasp of surprise and a collective sigh of relief from healthcare providers throughout the country. Schwartz is well qualified for the role, after all, and many took her nomination as a sign that the White House was attempting to rein in RFK Jr. Then came Schwartzs confirmation hearings. While there was some good in Schwartzs performance during those hearings, there was a lot of bad. The kind of bad that suddenly has a whole bunch of people who were previously sighing in relief suddenly nervous, and even pulling their endorsements. The biggest issue was Schwartz not affirming that she would refuse Kennedys influence and desires in favor of good science. Well, Schwartz is now the confirmed Director of the CDC, so it seems what she did to ruin her reputation with a whole lot of people didnt matter in the end. Perhaps the most disturbing aspect of Schwartz’s testimony came when senators repeatedly asked her what she would do if (or when) she’s put in the same position as Monarez. Schwartz responded as if it hadn’t happened and would never happen. “I do not believe that the president or the secretary would ever do what you just mentioned,” she told Sen. Bernie Sanders (I-Vt.) at one point, prompting him to reply: “Really?” While senators expressed their disappointment with her responses, health experts dropped their endorsements. And if you want to get really, really pissed off, allow me to tell you how Bill Cassidy was a key and potentially deciding vote when it came to Schwartzs confirmation. Cassidy has the ear of other reasonable GOP senators in these hearings and in Senate generally when it comes to health-related concerns. And it may start to sound familiar when I tell you that Cassidy first indicated he was very troubled by Schwartzs response in her confirmation hearings, but had been assured privately afterwards that his concerns were unfounded. Critical to Schwartz’s confirmation was support from self-proclaimed vaccine advocate Sen. Bill Cassidy (R-La.), who also cast a critical vote to confirm Kennedy as health secretary. While Cassidy called Schwartz’s performance in the confirmation hearing “disappointing,” he later said he had been reassured. He said he had spoken with her more after the hearing as well as with her former colleagues. “I’m confident that she knows what she is doing,” he said, according to Stat News. If I dialed the clock back to 2025 and replaced Schwartzs name with Kennedys, itd be the exact same story. I hope Im wrong. I hope that Schwartzs qualifications rule the day and she can resist Kennedys nonsense and make good, scientifically sound decisions and hires. But so long as Kennedy is at the helm, I have my doubts.

[Category: 1, bernie sanders, bill cassidy, cdc, erica schwartz, health & human services, rfk jr.]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/6/26 4:27pm
For a while now weve been mocking the Trump White Houses plans for an AI framework that would have the frontier AI labs hand over their top models for an initial review. After all, this was more or less the exact same plan that the Biden admin worked out in 2023, but it was done in a thoughtful and careful manner. And it caused a bunch of the VC bros in Silicon Valley to come out in support of fascism, while claiming it was a necessary defense against Bidens attack on supposedly open innovation. Of course, all of that was bullshit, and thats made even more clear by every step the Trump White House has taken to reinvent a similar voluntary AI review plan, but dumber. Indeed, Trumps AI framework is so dumb that theyre keeping it a secret. The White House does not plan to publicly release its new framework for evaluating advanced AI models, three sources familiar with the discussions told Axios. Ah, transparency at work. Its also wreaking havoc on the rest of the AI ecosystem that wasnt invited to the White House to get the details. The Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to share an overview of its new AI oversight framework, the people said. AI developers will have the ability to voluntarily submit new models to the federal government up to 30 days ahead of their public release. The White House will then vet their cyber capabilities according to a classified benchmarking system and share the AI models with federal agencies and trusted corporate partners. The White House isn’t sharing more information about its testing criteria or which AI models will be covered by the framework, though open models will reportedly be excluded, according to Axios. That has left smaller AI startups, safety advocates, and third-party researchers in the dark about crucial aspects of how the federal government is addressing the cyber risks posed by advanced AI systems. Some argue that the secretive process will give an advantage to larger companies. Considering that the likes of Andreessen Horowitz (investors in OpenAI) claimed they had to support Donald Trump over Joe Biden because they would support anyone who agreed with their little tech agenda, Im curious how they can possibly square that with the fact that this new framework is significantly worse than the Biden framework, specifically for the little tech companies that a16z has used as a shield to defend their support for authoritarian politics? Of course, the other reason why the White House is probably keeping the framework a secret is because it would show how incompetent they are. All the reporting so far suggests the entire process has been a clusterfuck, which is much more about which companies get to set up which regulatory moats to protect their own business models, rather than whats best for either innovation or the American public. At Nvidia, Microsoft, Google and Meta, executives grew increasingly concerned that Anthropic and OpenAI would win over the White House with their arguments for tighter restrictions, according to two of the people. That would potentially cement the A.I. start-ups’ positions as market leaders, Other A.I. labs were at risk of falling permanently behind, the people added. And because several of the companies make their own open-source models or supply hardware to businesses that use open-source technology, they worried the restrictions could harm them. Over private texts, phone calls and video conferences, executives quietly built an argument that open-source models were good for the world and for American innovation, according to three of the people familiar with the talks. But, of course, thats just the way things work when you have a White House that makes decisions entirely based on transactional motives, rather than anything involving principles. As we discussed last week, so much of this is all about whose vision of the AI world wins out — whether a handful of giant companies get to lock in the regulatory moat theyve built for themselves, or an actually competitive market lets people make their own decisions and keep control over their own experiences. Maybe thats the real reason nobodys allowed to see the rulebook: because it would reveal who the administration agreed to let write the rules.

[Category: a16z, anthropic, google, nvidia, openai, ai, ai framework, competition, donald trump, joe biden, open weights, voluntary testing]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/6/26 2:28pm
Recent reports have raised alarm about the use of PatronScan, an ID-checking and face-scanning system, at multiple LGBTQ+ bars in San Francisco’s Castro neighborhood. Much of the attention has focused on reports that the system photographs patrons as they enter venues and questions about whether those images are used for facial recognition. A broader privacy concern also deserves scrutiny. For years, PatronScan has marketed itself not just as an ID-verification tool, but as a system that allows bars and clubs to identify patrons, keep records about them, and share information across venues. As one news article published in 2019 documented, PatronScan built a network that allowed participating bars to flag patrons and share information about them with other establishments.  And in California, it’s not at all clear how PatronScan’s business model of scanning IDs and sharing the information from those scans with other bars comports with the law. California’s ID privacy law, which was amended in 2018 to add ID “scans,” states that no businesses shall “retain or use” any information from a scanned ID card except for limited purposes such as to verify age, comply with a legal requirement, or prevent fraud.  Californians should be deeply concerned about businesses that collect information from government-issued IDs and use it to build databases about where people go, whom they associate with, and whether they should be allowed into other public gathering places. That concern is especially strong in LGBTQ+ spaces, which have long served as refuges for people to go without being tracked, monitored, or put on lists.  We reached out to Patronscan with questions regarding their practices and their views on California ID law. They referred us to their published FAQ question “Is Patronscan privacy compliant in California?” which claims that the use of Patronscan kiosks is legal in California. They also said “Patronscan does not do facial recognition in North America, or any kind of automated analysis of the ID or the live photo image.”  The California Legislature Has Investigated PatronScan’s Business Model  In 2018, the California Legislature published bill analyses (on that years AB 2769) that went into detail about PatronScan’s business. Reviewing PatronScans own materials, the California Senate Judiciary Committee found that the company had collected and retained information on 561,087 customers in Sacramento alone during the first five months of 2018—a remarkable figure for a city whose population had only recently topped 500,000. Lawmakers also found that at that time, PatronScan retained information for at least 90 days or longer in some cases, shared information among participating bars, and maintained bans that lasted an average of more than 19 years. A PatronScan “Public Safety Report” used 10,000 scans collected on a single day to report on “where customers live, how far they have traveled, and how many different venues the customers patronized.”  This was not simply checking IDs at the door. PatronScan was building a database.  An immigrants’ rights group, the Coalition for Human Immigrant Rights (CHIRLA), wrote about its concern at the time with these growing ID databases, saying that “placing individuals on a database that labels them a threat to public safety has “significant immigration consequences that could lead to deportation, revoking of current status, or denial of future immigration relief.”  Today, PatronScan states that it retains personal information about all customers for 21 days, and about flagged customers for up to five years. This includes the customer’s name, date of birth, photograph, gender, and zip code. It also includes the dates and times that the customer entered particular bars. Such databases are a grave privacy threat. Personal data is routinely stolen by thieves, misused by a company’s employees, seized by government agencies, and diverted to new purposes by a company’s executives.  California Law Still Bans ID-Scan Databases, And Bars Should Follow That Law In 2018, California lawmakers closed what they viewed as a loophole. Existing law already prohibited businesses from retaining or using information obtained when they “swiped” a drivers license, except for the narrow purposes of legal requirements (like a judicial warrant) or “preventing fraud, abuse, or material misrepresentation.”  After reviewing companies like PatronScan, the Legislature amended the law to make clear that the same restrictions that apply to businesses that “swipe” ID cards also apply when those IDs are “scanned.” PatronScan opposed that change, arguing it wanted to preserve the ability to share information among bars so participating venues could decide whether to admit patrons. The bill became law anyway. Yet PatronScan continues to market and sell a system that apparently retains information from scanned IDs, and allows participating venues to flag patrons and share information across its network.  At a minimum, that raises serious questions about how those practices fit with Californias existing ID privacy law. Bar and nightlife venue owners who utilize PatronScan should think twice about its effects on their customers, and consider going back to standard, visual ID checks. These physical checks have been effective at keeping underage patrons out of 21-and-over venues for decades, and don’t present the serious privacy dangers of creating a private database of bar patrons.  For venues serving vulnerable communities like immigrants or the LGBTQ+ community, the stakes of using this technology are even higher. It’s disappointing and alarming to see some of California’s more well-known LGBTQ+ nightlife spots instead lining up as PatronScan’s early adopters. A venue cannot claim to be a safe space while feeding its patrons’ data to a third party database. These businesses should reject PatronScan, return to the standard ID checks that every other bar has been able to utilize, and prove to their customers that their privacy and security still matters.  Originally published to the EFFs Deeplinks blog.

[Category: patronscan, age verification, california, id privacy, id scans, id verification, privacy]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/6/26 12:02pm
As perhaps a few Elon Musk fans may remember, he got really annoyed at Wikipedia last year and tasked his second-rate LLM, Grok, with recreating it as Grokipedia. Grokipedia, launched nearly a year ago, basically starts by forking Wikipedia and then having its AI generate more details and more stories. Its not very good. And apparently, it hasnt been updating. And it seems like almost no one noticed. Over at Lawfare, they put out an article showing that Grokipedia basically stopped accepting updates back in April. At first, we wondered whether the AI was avoiding sensitive topics. To test that possibility, we submitted an uncomplicated factual update: SpaceX has recently launched its initial public offering (IPO). Grokipedia had not added this extensively sourced, indisputable fact to the SpaceX page. We observed that other users had suggested this edit as well; their requests were also “in review,” some since the day after the June 12 IPO.  We then examined the most popular pages, reasoning that if anything moved through the queue, we would likely see it there. Because Grokipedia provides view counts on individual pages but offers no site-wide ranking leaderboard, we approximated one using the site’s own search-suggestion (typeahead) feature, which returns, for any queried word, the most-viewed pages whose titles contain it. For example, if you type “The ” into the search bar, the first two suggestions are “The Beatles” and “Alexander the Great,” both of which have over 4.7 million views. Using the 10,000 most common words in Grokipedia page titles (obtained from the 5.9 million pages listed in the site map) gave us over 300,000 pages. Like many websites, its individual pages have a steep popularity curve. High-traffic entries on topics such as Elon Musk, ChatGPT, Donald Trump, Taylor Swift, World War II, and Bitcoin draw millions of views, while millions of minor pages sit in a zero-visit long tail. But neither popular nor unpopular pages seemed to be updating. On ChatGPT’s entry, 12 edits submitted on April 24 were approved the same day, and every edit submitted afterward—May, June, and July—remains “in review.” The same pattern holds across topics and traffic levels; the largest political entries on the site (across both parties) and a second-division football club are both stalled, which is difficult to reconcile with a content- or topic-specific explanation. In our subsequent analysis of 34,519 pages with at least one suggested edit in our sample, containing a total of 225,496 recommended edits, we found no accepted or rejected corrections dated within the past three months. Youd think someone would have noticed sooner. But, as the article notes, it sure looks like the actual human users of Grokipedia quickly dwindled as well: Across the pages examined, submissions from human users continue at a reduced volume—averaging 216per week post-April. Other tools that monitored activity on Grokipedia apparently died much earlier: A public feed that once showed the editing process at grokipedia.com/live—a stream that the Tow Center had scraped to assemble its dataset—stopped functioning between mid-January and early March. A Wayback Machine capture from Jan. 12 shows the feed fully operational, with a running count of approved edits, while a capture from March 5 returns an error page. These are all signs of a project thats basically flatlined. For all the hype Grokipedia received as the antidote to Wikipedia, it doesnt seem to have gained any traction. And, the fact that it basically broke months ago seems to have been noticed by almost no one other than the dozen or so people out there trying and failing to edit Grokipedia: While more than half of all contributors suggested only a single edit, a tiny cohort of 13 power users accounts for 42.6 percent of all human edit requests (nearly 40,000 edits). The most prolific contributor submitted over 8,000 corrections across 4,000 pages. One self-described frequent contributor reported in mid-June that the review system had been stuck for more than 50 days. That places the onset in late April, consistent with our data. He also wrote on X that someone he identified as an xAI team member had acknowledged the complaint but could not provide a status update. For these power contributors, Grokipedia went from a platform with rapid review times to a black hole. The article notes that Elon hasnt mentioned the site since February — barely four months after it launched in October. That silence has now stretched on for about six months and counting. Even worse, Grokipedias logging system appears to have broken as well: A mass rewrite of the encyclopedia seems to have happened on March 14. Because user suggestions are anchored to specific text selections (“Highlighted sections”), the rewrite appears to have broken the anchors. Grokipedia’s logging system retroactively reclassified previously accepted edits as rejected, attaching the error message, “Highlighted section not found.” However, in several cases that we reviewed, the textual changes appear to have been incorporated into the articles anyway. For example, the 10 launch-week edits to the entry for the actress Prunella Scales are recorded as approved in the Tow archive; nine of the edits now display as rejected on the live site, despite their contents appearing to have been incorporated into the article. The edit log, in other words, is not entirely stable or reliable. This is potentially confusing for users who made suggestions and might have seen their valid contribution accepted with a “rejected” message nonetheless. It is also not ideal from an auditing standpoint. Its entirely possible that someone at xAI (or SpaceX or wherever the checks get cut these days) will flip the server back on and get things started again, but given how much the media hyped up Grokipedia when it launched as a potential Wikipedia killer, shouldnt at least some of them acknowledge what a total failure it has been?

[Category: spacex, wikipedia, xai, elon musk, grokipedia]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/6/26 11:57am
The Soundfreaq Sound Spot II combines wireless audio performance, ambient lighting, and relaxing sound features in a compact design built for modern lifestyles. Featuring a Bamboo and White finish with eco-friendly materials, this Bluetooth speaker complements bedrooms, offices, living rooms, and personal spaces while delivering both style and functionality. Engineered with a custom-designed audio driver, Bass Boost DSP technology, and a passive radiator, Sound Spot II delivers balanced sound with vocal clarity and enhanced bass performance. Beyond music playback, Sound Spot II includes built-in nature sounds, ambient lighting, and sleep timer functionality designed to help create a more relaxing environment. With Bluetooth connectivity, rechargeable battery power, and splash-resistant construction, it offers convenient performance for home and daily use. Its on sale for $80. Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

[Category: 1, daily deal]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/6/26 10:25am
Flock Safetys automatic license plate readers were first sold as upmarket add-ons for gated communities and HOA curtain-twitchers who wanted to keep tabs on what everyone was doing, whether they lived there or not. Flock soon realized that selling to rich people wasnt as profitable as selling to governments. Law enforcement agencies have always been surveillance tech early adopters something that springs equally from being able to spend other peoples money and a desire to get out ahead of constitutional case law. So, now Flock is pretty much everywhere. But instead of getting better due to constant refinement, it seems to be content to rest on its ubiquity. If youre already everywhere, why try harder? After all, ending a contract with Flock doesnt mean the company wont keep your cameras activated so other law enforcement agencies can access plate/location information. And if federal agencies are using local agencies to bypass restrictions on plate reader access, well thats just an end user problem. But if you buy license plate readers, you kind of expect them to read license plates. Well, thats not happening in Roseville, California, where Flocks cameras are about as effective as pole-mounted Polaroids: Flock says that in optimal conditions, its cameras accurately read more than 96% of license plate characters. Hundreds of pages of records from the Roseville Police Department show a different picture. In 2023 and 2024, Flock sent 1,427 alerts to Roseville police, flagging vehicles as stolen or used in a felony after they passed one of the citys Flock cameras. An analysis by the police department found that in 71% of those alerts, Flocks machine-learning software incorrectly read the license plates. That is objectively terrible. And because it is so terrible, Flocks flack has decided to blame the end users. A factor that contributed to the misread problems in Roseville was the particularly unique deployment that the city requested, a Flock spokeswoman said. Roseville said it has its cameras configured so that they capture only the backs of vehicles, a setup intended to avoid capturing personally identifiable information like faces. Rosevilles setup included older hardware and placement of cameras higher and further from vehicles than the company typically recommends, Flock added. Huh. Well, that might mean something if Flock had made any honest effort to make this unique deployment work better. But it doesnt appear to have done that. Instead, it simply insists things are better now a statement thats not backed by any evidence Flocks has on hand and/or is willing to share. Flock said Rosevilles camera performance has significantly improved, which the police department disputed.  According to emails obtained by Business Insider, it does appear that someone appears to be working on the ongoing issue, albeit at a leisurely pace. This is the email sent to Amanda Jones, Roseville PDs real-time crime center supervisor by an unnamed Flock Senior Product Manager. I 100% understand, and it pains me to no end that we are missing reads for you. I am grinding on this issue, and am writing code as we speak. I am improving systems at Flock internally that can automatically identify when we miss cars and then diagnose the issue so that we do not need to rely on customers to tell us. I think it may be helpful for you and I to have a conversation so that you can get a view under the covers of what we are working on to improve this? We have an all company summit during the 2nd half of this week, but if you would like to discuss later this month or next, please let me know and I can share my availability. While I understand that Flocks customer base means product managers are stretched pretty thin, were not talking about malfunctioning doorbell cameras or warranty repairs. Were talking about tech that is capable of depriving people of their freedom, if not their actual lives, when its wrong. Thats the sort of thing that shouldnt be met with vague promises to talk about this long-known, ongoing problem at some point in the next several weeks. That Flock doesnt treat this as a priority shows it doesnt care about anything more than selling cameras and raking in service/access fees. Fortunately for residents of Roseville, Flock being wrong hasnt led to police stops or wrongful arrests. Thats because the PD forces officers to personally verify plates and cannot use a plate read alone to justify a traffic stop. But most places using Flock cameras dont do that. Fewer still place any limits on access to the companys database of billions of plate/location photos, which means cops from all over the nation are using junk data generated by faulty cameras to initiate stops and pursue investigations. And its not just the false positives. Part of the PDs frustration was Flocks inability to generate records when officers needed them most. In at least two cases, vehicles driven by criminal suspects managed to pass through the network of Flock cameras without generating a single usable plate photo. Meanwhile, the cameras were turning 2s into 3s, Ns into Vs, and apparently just guessing when the cameras failed to capture an entire plate, rather than simply discarding the incomplete read. Again, this doesnt appear to matter to Flock. It will oversell its capabilities and blame everyone but itself when things go wrong. It has already shown its unwilling to improve until federal oversight starts demanding answers. And this approach to testing shows its not serious about actually improving its products: In 2021, the research firm IPVM independently tested Flocks license plate readers, concluding that Flock misidentified the state in about one of 10 reads, and that the system regularly misclassified vehicles type and make. IPVM said that Flock subsequently blocked it from purchasing its cameras for testing. Whats weird about this is that the city of Roseville says its going to keep throwing money at Flock, despite its extensive record of failure. This makes it feel like less of a tech company and more like a cult. The feeling seems to be that if the cameras ever generate even a single arrest, theyre worth paying for, even when theyre wrong most of the time. And thats something that cant be fixed simply by changing surveillance providers.

[Category: flock safety, 4th amendment, alprs, california, failure, license plate readers, roseville, roseville PD, surveillance]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/6/26 6:25am
Ive written a few times now about how the Trump administration hijacked a $42.5 billion broadband investment fund included in the 2021 infrastructure bill, stripped away requirements that the resulting broadband be fairly deployed and affordable, and instead redirected billions of dollars to Elon Musk and Jeff Bezos in exchange for slower, more expensive satellite connectivity theyd already planned to deploy without subsidies. Basically, this redirected tens of billions of dollars away from higher-capacity, faster, more reliable fiber access, and toward Low-Earth Orbit satellite services, which have a long list of problems Ive explored in detail. The Trump administration then falsely claimed that theyd saved taxpayers roughly $21 billion (you can read my recent piece at The Verge for more detail on what that means for real people). Heres the thing. This $21 billion in non-deployment funds the Trump administration claims it saved is technically supposed to go to the states. Congress (aka, the law) specifically stated that the full $42.5 billion included in this Broadband Equity, Access, And Deployment (BEAD) was supposed to be spent on internet access or something very closely adjacent (digital skills training, telehealth tools). But after the Trump NTIA retooled the program last year (causing all sorts of new delays and problems) they basically just went mute on what happens next. They refuse to meaningfully answer questions on where that money is going to go: It’s anybody’s guess if nondeployment funds will ever be released. It’s now been 13 months since the NTIA changed the rules for nondeployment funds, and they are obviously in no hurry to see these funds ever get spent. This hasnt gotten a ton of attention in a U.S. press that finds infrastructure too boring to cover, but it still obviously matters. There were various clumsy attempts to hijack these non-deployment funds for other purposes (Sen. Joni Ernst proposed using it reduce the federal deficit, others have wanted to throw it at AI data centers), but that would be technically illegal (for whatever that means anymore). It seems likely that the Trump administration just hopes that people forget about the funding so it can be pocketed by crony capitalism and associates, but that hasnt been easy. State leaders and even many Republicans have consistently peppered the NTIA with letters asking them what happens next to these funds, only to be met with more delays or silence. Its worth remembering that last election season, Republicans (with Ezra Klein and the abundance crews help) made a giant stink about how this program was taking way too long to connect anybody. For the whole 2024 election season, Republicans blasted the BEAD program’s bureaucracy and promised how once they were in power, they’d completely revamp it, speed everything up, and save taxpayer billions. When that revamp arrived it involved creating all manner of costly new delays, stripping all the language out of the program ensuring funds were spent fairly and wisely, dumping a whole bunch of money into the laps of Elon Musk and Jeff Bezos, and then running off with half of the programs funds and refusing to tell anybody what happens next. In the interim, delays, high costs (from pointless tariffs and wars), and bureaucracy have resulted in even more original BEAD subsidy bidders backing off of their plans for widespread fiber, resulting in bid defaults, even more delays, and even more taxpayer money being thrown at Bezos and Musk for satellite broadband thats too congested to handle the full load. Great stuff. Very populist. Incredibly well thought out government efficiencies.

[Category: 1, bead, broadband, elon musk, fiber, howard lutnick, infrastructure bill, internet access, jeff bezos, ntia, satellite, subsidies]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/5/26 9:08pm
A couple of weeks ago we discussed how the cuts made to HHS and specifically the CDCs FoodNet tracking platform were making it much harder to track and back trace the source of the countrys current cyclosporiasis outbreak. Youll have heard about this outbreak in the news by now. Its the one where you begin pooping yourself uncontrollably. It is not, however, funny. 10% of cases will result in hospitalization. The most recent counts from the CDC suggest that there have been more than 22,000 cases of the illness across 15 states. Those numbers are very much in question, however, both due to general underreporting and, again, funding and staffing cuts at CDC. Just this week, in fact, we have now learned that two people in Michigan have died from cyclosporiasis. That information was and is, at the time of this writing, missing from the FDAs dedicated page to inform the public on the outbreak. That page hasnt been updated since July 24th, in fact, which is the exact opposite of what youd want the government to be doing in a public health emergency. And its reportedly not because the government isnt aware of these deaths. While news of the deaths made widespread headlines Monday, federal health agencies under the Trump administration were mostly silent. The Food and Drug Administration—which is conducting traceback investigations to identify foods contaminated with the parasite—has not updated its outbreak investigation page since July 24, nearly two weeks ago, as of publication time. The Centers for Disease Control and Prevention, meanwhile, added a banner notice on its outbreak update webpage saying that the agency was “aware” of the two cases. But its reporting data was not updated to include the two deaths as of this publication. Why has this government been so slow to report accurately on these unfortunate deaths and the overall case counts for the outbreak? Some combination of those same budget and staff cuts along with a general apathy at HHS. With fewer people and resources to not only track the disease, but to maintain the dashboards meant to update the public, the numbers are slow to come in and untrustworthy when they do. And with RFK Jr. at the helm of public health, well, the government is generally in the land of We-Dont-Give-A-Shit. Two weeks ago, Kennedy confidentially told reporters that the Cyclospora outbreak—linked to lettuce and other unidentified fresh produce—was “under control.” Last week, he announced his own cooking show on YouTube and released the first episode in which he helped prepare a meal that included a fresh salad. The buffoonery on display from Kennedy and our health agencies is breathtaking. They should be assisting in combating this outbreak, along with those of measles and pertussis. Putting that aside, they should at least be able to tally up the case count numbers to demonstrate their own failures, but its clear theyre not really interested in doing that either. Instead, Kennedy in particular wants to host his cooking show and yell at journalists instead. Kid Rock must not be returning his calls any longer, I suppose. Now, to be clear, this illness carries a 2 week incubation period, and the recalls of the suspected produce that is believed to have caused all of this are within a time frame that cases may still be stemming from that same source. But thats not a certainty, and it will be important for our federal health agencies to continue to track cases in near real time to determine if there is, in fact, another vector by which cyclosporiasis is spreading. Unfortunately, every indication is that those same health agencies just arent all that interested in doing this the right way.

[Category: 1, cdc, cyclospora, foodnet, health & human services, rfk jr.]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/5/26 4:28pm
This story was originally published by ProPublica. Republished under a CC BY-NC-ND 3.0 license. On an afternoon in mid-May, dozens of Microsoft engineers and their managers gathered online and in a conference room at the company’s Redmond, Washington, headquarters to discuss Project Glasswing. The tech giant was racing to fix weaknesses in its code that a new AI model known as Mythos was uncovering at an unprecedented clip. The AI behemoth Anthropic, which developed Mythos, had given access to select organizations that make software used by regular people, companies and governments across the world. The goal was to find and fix the vulnerabilities before hackers and adversarial governments like China began using similar tools to find and exploit them for espionage and sabotage. As the group settled in, one engineer asked the question that loomed over the meeting: Did Mythos “live up to the hype that Anthropic claimed it would have had?” “Yes,” a manager responded, according to a recording of the meeting viewed by ProPublica. The version being used by Microsoft, Claude Mythos Preview, was surfacing bugs faster than the tech giant could patch them, and engineers, the manager said, were now in “a mad dash” to close the gap. One slide in that day’s presentation showed that in April alone, Mythos had uncovered 90 “critical” bugs and 141 “important” ones in SharePoint, Microsoft’s widely used collaboration software. In the first half of May it found even more. “Please, please, please if your org has any April bugs, drive those down,” engineering manager Hans Andersen implored the group. They had roughly two weeks “to find as many things and do as much good as we can with this access.” May 31, he explained, “is considered the day when the rest of the world will have caught up.” The engineers on the call poked at that assertion, with one of them summing up the predicament: “So basically you’re saying if it’s released on June 1, then on June 2 the adversaries will have our bugs?” Yep, one person responded. Yep, another echoed. Ever since Anthropic kick-started a national conversation about the bug-hunting power of AI in April, when Project Glasswing was made public, national security experts predicted that the U.S. would have a window of opportunity to fix flaws before adversaries would have similar models capable of discovering the same weaknesses. In late June, the international alliance of intelligence agencies known as the Five Eyes — whose members are the U.S., Australia, Canada, New Zealand and the U.K. — warned in an unusual joint statement that in a matter of months, that window would be closing. But the recording of the Microsoft meeting, along with internal documents reviewed by ProPublica, suggest the day of cyber reckoning may already be here. Given the deluge of flaws Mythos has identified, Microsoft so far has focused on patching those it considers most dangerous, which are classified critical or important, according to the presentation as well as the company’s own public patch updates. The internal records indicate that Microsoft plans to eventually address “moderate”-severity flaws uncovered by Mythos. The documents made no mention of “low”-severity bugs. The company’s approach reflects the triage system that is typical in the industry. Just as the sickest patients are the first to be treated in the emergency room, vulnerability triage prioritizes issues that are likely to cause the most damage if exploited by hackers. But that strategy carries its own risk in this AI-powered bug-finding era, in which new tools are unearthing a record-breaking volume of weaknesses in the products we use every day. Mythos, for example, is able to chain together a string of bugs that build on one another, meaning that the low- and moderate-severity vulnerabilities that remain unpatched could create an opening to carry out devastating attacks. “The problem now is that you can chain four low-level flaws, and that can equal a high severity,” said Vinh Nguyen, a senior technical adviser to Anthropic and a senior fellow for AI at the Council on Foreign Relations who formerly served as chief AI officer and chief data scientist at the National Security Agency. “If you’re Microsoft, the current triage strategy may be underpricing risks.” In emailed responses to ProPublica’s questions, Microsoft stood by its approach, saying its triaging decisions are based on a number of factors, including exploitability and the impact on customers. The company presentation did not mention chaining, but a spokesperson told ProPublica that the technique “has long been considered as part of vulnerability assessment and risk analysis.” Asked about the internal presentation and the then-looming May 31 deadline, the spokesperson downplayed its significance, saying that “accelerated targeting and exploitation of new vulnerabilities is not a new phenomenon.” That said, he added, the comments made during the meeting reflect how the company “feels a sense of urgency to help our customers at this time.” “What was heard on that call and is true today is that security is Microsoft’s most important priority and teams across the company are prioritizing using AI to discover and remediate vulnerabilities as quickly as possible.” Microsoft declined to answer questions about how many bugs engineers had patched since the presentation. Anthropic declined to comment. The internal Microsoft presentation and accompanying slides predicted that the group of staffers working on SharePoint, which is used by governments and businesses worldwide to manage data and documents, “will be busy for months,” first working through the highest-priority critical bugs then tackling the important ones in August. Microsoft says vulnerabilities it categorizes as critical include so-called worms that can crash systems and spread malware as they race across computer networks. Important ones could result in “compromise of the confidentiality, integrity, or availability of user data” as well as the “availability of processing resources.” After those categories were cleared, the group would begin work on roughly 300 “moderate” bugs, according to the presentation. While the internal documents reviewed by ProPublica do not include updates on the entire breadth of Microsoft’s offerings, they do give a sense of the scale of the problem. One document noted that, since the company started using Mythos earlier this year, it had collectively found hundreds of bugs that Microsoft categorized as either critical or important in popular products such as Microsoft 365, the Teams conferencing platform and the Copilot AI tool. As of mid-May, most of them had yet to be patched. “They’re not profound and exotic, but they’re real,” Andersen, the engineering manager, said during the meeting. “And a lot of them are exploitable.” It’s unclear whether hackers have exploited any specific bug identified by Mythos, but some  have tapped AI to automate attacks and appear to be using Mythos-like tech to find and exploit weaknesses. There have been outward signs of Microsoft’s internal struggle to deal with the growing list of bugs to be patched. Each month, the company publicly releases fixes for its software vulnerabilities in what’s known as “Patch Tuesday.” In June, it released patches for more than 200 bugs, which industry experts then said was an all-time high. But on July 14, the company blew through that record and released patches for more than 600 bugs. Only seven were categorized as low- or moderate-severity, one of which hackers were actively exploiting, according to Dustin Childs, leader of the Zero Day Initiative bug bounty program, which is part of cybersecurity company TrendAI. The rest were important or critical. “Well folks. Here we are. The bug apocalypse has fully descended upon us,” Childs wrote in a blog post on July 14. Microsoft told ProPublica that the overall volume of bugs “will not be plateauing for a bit,” but a spokesperson said the company has “invested heavily in both people as well as AI-powered triage solutions that scale quickly to handle the growing number of vulnerabilities.” Given the new realities of the AI age, including the chaining capabilities, companies like Microsoft might need to rethink their entire approach to triage, said Nguyen, the NSA’s former AI chief. Rather than shunting what are now considered low-risk flaws aside, companies should be dedicating staff to developing and testing patches for the entire spectrum of vulnerabilities, he said. In other words, the cyber ER needs more doctors and nurses treating illnesses that are life-threatening as well as the minor wounds that could later turn deadly. “There’s no alternative,” Nguyen said. “The patients are coming in fast and furious.” Microsoft told ProPublica it’s “always going to be reevaluating and considering whether things that were previously lows or moderates be upgraded or thought about differently. With these AI systems, it makes us rethink some of these things. Across the industry, we’re all looking to see how drastic of a change it will be.” Microsoft’s users may be particularly vulnerable. The popularity of its offerings, used the world over, makes it a frequent and lucrative target for hackers. In addition, many of its products contain “legacy” code. Developed decades ago using now-outdated technology, this code contains unaddressed flaws and contributes to what is known in the industry as “technical debt.” But the challenge of fixing the flood of newly found bugs also extends to the rest of the software industry, and to open-source software code that is typically free to use and largely maintained by volunteers. Open-source software underpins internet infrastructure and is incorporated into much of the world’s modern technology, including products offered by major tech companies such as Microsoft. “Nobody has really figured out how to deal with this, and everybody is casting around for what they need to do,” said J. Michael Daniel, a former cybersecurity adviser to President Barack Obama and the president of the Cyber Threat Alliance, a nonprofit organization focused on cybersecurity. “Our tech debt is coming due.” Ben Edwards, a data scientist who specializes in managing software vulnerabilities, said the software industry was handling an “intense volume even before AI.” “It was like drinking from a garden hose on the jet setting before, and now it’s like drinking from a fire hose,” Edwards said. “They might have had the teams that could handle that garden hose. Whether they can handle the fire hose is something else.” Although the volume of vulnerabilities has grown over the years, Microsoft’s internal group responsible for fielding them, the Microsoft Security Response Center, has been perennially understaffed. Even before the crush of AI-identified bugs, the center fielded hundreds or even thousands of reports a month, pushing the group to its limits, ProPublica has reported. The size of the center reflects Microsoft’s corporate philosophy: Plugging security holes is a cost center, while making new products is a profit center, former employees said. The company is loath to tie up its best engineers with making security patches — a cost center — instead of developing new products and features that will generate profits, ProPublica has reported. Microsoft told ProPublica that it does not discuss internal staffing decisions but has made investments in recent years to “focus our teams on keeping our customers secure.” The company “continuously evaluates the staffing, processes, and technologies required to support security response and vulnerability management,” a spokesperson said. According to the slides that accompanied the May internal presentation, Anthropic provided Mythos access to roughly 50 full-time Microsoft employees, with a goal to “harden critical services before publicly available models catch up.” A slide titled “What’s Next” predicted that the Microsoft Security Response Center would see continued case volume “as public tools catch up” to Mythos. During the May meeting, one staffer appeared to take comfort in the belief that adversaries “don’t have the source code” that such an AI tool would scan for weaknesses. His colleagues, however, quickly corrected him. Portions of Microsoft’s code have, in fact, fallen into hackers’ hands over the years. “It might not be this week’s source code,” one person said. “But they’ve got source code. It’s out there.” In a statement to ProPublica, Microsoft downplayed the comment, saying engineers “design our security processes on the expectation that determined adversaries may gain access to code.”

[Category: anthropic, microsoft, ai, bug hunting, bug patching, cybersecurity, mythos, security, vulnerabilities]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/5/26 2:21pm
Donald Trump took possession of a $400 million gift plane from the Qatari government earlier this year. Trump claimed it was a coup for taxpayers and a boon for America, even as he made it clear this was all about him. According to Trump, no plane was more luxurious than this graft-y replacement for the Air Force One. He bragged about how much it reflected his own taste in upmarket products, which meant the planes interior was undoubtedly festooned in gold leaf and stocked with steak-grade ketchup. But was it secure? Thats kind of a big deal when it comes to presidential transport. Turns out it wasnt. Trump rode his graft jet to Turkey for a diplomatic meeting but was forced to ride the old Air Force One out of the country when it was discovered his new gaudy aircraft didnt possess the necessary security measures/counter-measures. In response to this reporting of the Air Force One Mk. IIs failure, the Trump administration behaved like the Trump administration: it subpoenaed the New York Times reporters, demanding all sort of information in hopes of uncovering the reporters government sources. Thats not how this is supposed to work. The FBI and DOJ both have extensive guidelines that are meant to discourage open attacks on the First Amendment. All of these appear to have been ignored in the administrations haste to find out who needed to be punished for telling the truth about Trump and his Qatari luxury jet. Fortunately, the court curb-stomped the DOJ when the New York Times challenged the subpoenas. The DOJ really had no answer for the courts questions, given that the court had plenty of precedent to work with while the DOJ was limited to being a nominally prehensile Trump appendage. Faced with the (admittedly slim) prospect of being sanctioned by a thoroughly irritated federal judge, the DOJ withdrew the subpoenas. But thats not the end of the story, apparently. The administration is targeting anyone remotely related to the New York Times and/or reporting that doesnt please Donald. The New York Times is now going to bat for one its freelancers, who has also been targeted by this vindictive administration. In February, F.B.I. agents showed up at the New York home of the reporter, Matthew Cole, to deliver the grand jury subpoena, which was issued by prosecutors in Newport News, Va., according to the people familiar with the matter, who described the private conversations on the condition of anonymity. The investigators are seeking his testimony about two years’ worth of information about Mr. Cole’s contacts and conversations, as they try to identify his sources for the article about the operation in North Korea, the people familiar with the matter said. It is unclear if the administration has also sought Mr. Cole’s phone and email data, as it has done in other cases. This is apparently related to Coles reporting about a failed surveillance operation authorized by Trump during his first term in office one that was carried out in hopes of planting a recording device capable of intercepting Kim Jong-uns communications. Heres how that went down: For the operation, the military chose SEAL Team 6’s Red Squadron — the same unit that killed Osama bin Laden. The SEALs rehearsed for months, aware that every move needed to be perfect. But when they reached what they thought was a deserted shore that night, wearing black wet suits and night-vision goggles, the mission swiftly unraveled. A North Korean boat appeared out of the dark. Flashlights from the bow swept over the water. Fearing that they had been spotted, the SEALs opened fire. Within seconds, everyone on the North Korean boat was dead. The SEALs retreated into the sea without planting the listening device. No one likes discussing a failed operation, so understandably this one hadnt been publicly discussed prior to Coles report (with an assist by Dave Philipps). But this attempt to pressure Cole into revealing his sources seems more motivated by Trumps unwillingness to discuss this mission with the people hes supposed to be discussing these things with. The Trump administration did not notify key members of Congress who oversee intelligence operations, before or after the mission. The lack of notification may have violated the law. Whats inexplicable in normal terms is why this wasnt a problem until now. This article was published last September. The underlying incident occurred in 2019. But it took until February 2026 for the administration to do anything about it. The Trump administration is far more aggressive and far less respectful of the law this time around, which explains why it would move against this reporting now. However, the delay between the reporting and revenge suggests this was a reaction to Trump seeing something on social media, rather than his administration engaging in a thorough internal investigation for months before deciding it needed to do damage to the First Amendment to move this forward. Hopefully, this subpoena will soon be tossed into the Trump DOJ discard pile. But losing all the time wont stop this administration from going after journalists for reporting on Trumps failures. This administration is incapable of learning from its mistakes because it thinks its never wrong. The war on journalists will continue as long as Trump and the GOP hes turned into a MAGA puppet holds power.

[Category: new york times, ny times, 1st amendment, censorship, doj, donald trump, free press, free speech, matthew cole, trump administration]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/5/26 12:23pm
The rise of AI is bringing a bunch of fascinating legal questions that are harder to answer than many expect. The latest one: who is liable if an agentic system running on its own hacks someone? Thats the question a bunch of people have been asking this past week in the wake of multiple stories of agentic tools breaking out of their sandboxes during testing. But its also a question that the Ninth Circuit brushed up against this week, in a ruling that says an agentic tool isnt the one doing the accessing under the federal hacking law. A person is. The challenging part is figuring out which person. Theres obviously been plenty of talk over the past couple of weeks regarding agentic tools supposedly going rogue. There was, of course, the story of OpenAIs tools hacking Hugging Face, the AI repository (also covered on Ctrl-Alt-Speech). And then soon after, Anthropic admitted that hey, our models kinda did something similar. And while these are generally referred to as the bots going rogue, the reality is not quite that. The bots are doing literally what they were asked to do: accomplish some goal by any means necessary. And in both stories, they found ways to accomplish their goals, often by hacking into other systems or doing things we would normally consider malicious. In the case of OpenAI and Hugging Face, it appears that the tool did what plenty of hackers try to do, just a whole hell of a lot faster. It found a zero-day vulnerability to break out of the sandbox OpenAI thought it had created. It then took a series of steps to enable it to hack into Hugging Face. In Anthropics case (which only came to light after the OpenAI incident caused Anthropic to go back and look) the situation was a bit different. Some of the tests included prompts telling the agentic tools that they were in a sandboxed simulation. But because of a configuration error, they really werent. And since the models had been told flat out in the prompt that everything around them was simulated, when they found a way out, they reasonably concluded that the way out was part of the simulation too. Either way, Ive seen some discussion online wondering why these two companies arent being charged with violating the Computer Fraud and Abuse Act (the CFAA). Weve written about the CFAA for years, mostly in how its a badly worded law that has been abused in both civil and criminal cases to go after anything I dont like on a computer rather than its actual purpose of targeting genuine hacking. And CFAA lore goes back to 1988 and the infamous Morris Worm, in which Robert Morris accidentally created an internet virus that took down portions of the then still small internet. Morris was found guilty of violating the CFAA for doing so. Which has some people asking how are these other two stories any different. But the general consensus is that there are unlikely to be any CFAA violations here, in part because the CFAA requires intentional access, and in part because no human ever made the decision to break in. I would separately argue that the lack of real damage (unlike the Morris Worm) helps here as well. TechCrunch floats a more cynical version of the same point: that the DOJs appetite for a CFAA theory might look very different if these agents had come out of a Chinese lab rather than one a short drive from the US Attorneys office: The Department of Justice could theoretically bring criminal charges under the CFAA, but one former litigator specializing in computer law also expressed doubts. Prosecutors might have an easier case if any of the cyberattacks had targeted critical infrastructure, which would have caused greater real-world disruption and more tangible harm than copying data from a company’s internal database. It is also plausible that if the attacks were carried out by a Chinese AI model maker, for example, the DOJ would have a greater appetite to file charges under the CFAA than against AI companies on its own doorstep. But, just as this discussion heated up, the Ninth Circuit Court of Appeals (sort of) weighed in on a separate, ongoing case that Amazon filed against the AI company Perplexity. Perplexity has an agentic browser allowing users to tell the agent to accomplish tasks — such as buy me toilet paper on Amazon — and the agent goes off and does that independently. Amazon, unsurprisingly, hates this. Its entire storefront is engineered to get humans to buy more than they came for, and an agent that buys the toilet paper and leaves is immune to every last bit of it. So Amazon notified Perplexity that its agent isnt allowed on the site. Perplexity, taking the position that a browser a user drives is a very different thing from a giant centralized scraping operation, kept letting its users point the agent at Amazon — and routed around Amazons blocking by not sending an identifying user-agent string. Which, its worth remembering, is something browsers, privacy tools, and testing frameworks do every single day. But Amazon argued that this made Perplexitys agent a CFAA violator, because routing around a block should count as unauthorized access (which is central to the CFAA). Amazon sought a preliminary injunction blocking Perplexitys tools from reaching Amazon and the district court granted it. But now the Ninth Circuit has rejected that, noting that a computer by itself cannot violate the CFAA, because the CFAAs language contemplates access by a person. The CFAA’s plain language suggests the Assistant itself cannot “access” Amazon’s servers. The relevant provision of the CFAA punishes “[w]hoever . . . intentionally accesses” a “protected computer.” 18 U.S.C. § 1030(a)(2) (emphasis added). In other words, the CFAA contemplates access by a person. However advanced the Assistant currently is, it is a tool, not a person for statutory purposes. See 18 U.S.C. § 921(a)(1) (“The term . . . ‘whoever’ include[s] any individual, corporation, company, association, firm, partnership, society, or joint stock company.”); see also Whoever, Cambridge English Dictionary, [https://perma.cc/YY3TVTJF] (last visited July 16, 2026) (“[T]he person who” (emphasis added)). Which raises the obvious Morris Worm question: the worm wasnt a person either, and Morris still went down for what it did. But thats exactly the distinction the court is drawing. Morris wrote the code, released it, and no one else was involved — the whoever was sitting right there. When a user tells an agent to go buy toilet paper, theres a human in the chain, and the court says its the user, not the tool and not the company that built it. The Supreme Court has instructed that, “in the computing context, ‘access’ references the act of entering a computer system itself or a particular part of a computer system, such as files, folders, or databases.” Van Buren, 593 U.S. at 388 (internal quotation marks omitted). Our focus is thus to ask whether Perplexity uses a tool (the Assistant) to “access” Amazon’s computers. On the facts before us, we answer no. It is the user who “accesses” Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com. To be sure, Perplexity may receive screenshots of the user’s browser and may communicate instructions to the Assistant. But those activities, by themselves, do not mean that Perplexity has “accessed” (gained entry) to Amazon’s servers. We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon’s servers. On the current record, Amazon is not likely to succeed in proving the “access” prong of its CFAA claim. The court also seems well aware of how badly the CFAA has been abused (especially in criminal law) and recognizes how an alternative outcome would be a mess: Another note of caution: Amazon’s approach, if accepted, could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory) for facilitating Perplexity’s purported unauthorized access to Amazon’s servers. We are conscious of precedent cautioning against “transform[ing] whole categories of otherwise innocuous behavior into federal crimes simply because a computer is involved” or “criminaliz[ing] a broad range of day-to-day activity.” Nosal I, 676 F.3d at 860, 862 (internal quotation marks omitted). In our view, it is unlikely that Congress would have exposed individual users to criminal liability under the CFAA by using the Assistant and Comet browser to access Amazon.com under these facts. On these narrow facts and given the care with which we must interpret the CFAA to ensure defendants are on notice, we decline to adopt Amazon’s interpretation of § 1030(a)(2). The court does caution that its ruling should be seen narrowly, and admits there could be other cases which are CFAA violations. But a browser with an agent built into it, doing the bidding of a human user, is not that: Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions. Our holding here is limited to “access” as contemplated by the CFAA and as applied to the Assistant’s interactions with Amazon.com on the record before us, not the broader legal landscape surrounding agentic AI. The legal understanding of agentic AI will doubtless change as AI technology grows increasingly sophisticated. For now, this opinion reflects and applies to the state of technology only as presented in the filings in this case. While the court seeks to distinguish this ruling from the very problematic Power Ventures case (which said that users authorizing a third party tool with their own password to access Facebook for the purpose of creating a unified dashboard for social media was a CFAA violation), I think this ruling is a further narrowing of that ruling from a decade ago. Ive argued for years that the Power Ventures case was a key moment in locking up the open web, because it blessed Facebooks desire to close off its platform from the wider web, leading to the world of internet giants operating as silos. In that case, the court found that it was Power who was violating the CFAA rather than the user, even though it was clearly the user authorizing access. That enabled platforms to lock up all their data in silos and try to block any third-party tool from getting it out, deepening lock-in and making useful exit harder. Here the results come out very differently, and very much for the better. A handful of cases over the past few years have thankfully chipped away at the very broad Power Ventures ruling, and this is the latest. Given how much of the web is about to be browsed by agents rather than eyeballs this may be the most consequential such ruling. But, at the same time, it still leaves open the idea that OpenAI and Anthropic could face CFAA claims in the future, even though its their bots that accessed things in an unauthorized manner. While this latest ruling says that bots alone cant violate the CFAA, the entity driving them could. So there could be cases where these companies could face CFAA liability for how they configure the tools when they run these tests. The intentionality question will still be a hurdle for any CFAA claim to overcome, but I dont think this particular ruling should have OpenAI and Anthropic breathing any easier — other than in the narrow case where either of their browser agents, operated by a user, accesses unauthorized systems. Pointing an agent at the open internet, telling it to accomplish a goal by any means necessary, and then misconfiguring the box that was supposed to keep it in is a very different fact pattern from a user asking Comet to reorder toilet paper. The CFAA is also hardly the only law with something to say about an aggressively overhelpful bot that causes real damage. It also leaves open something more uncomfortable: the user might be liable. If the user is the one accessing, then a platform that wants to ward off agentic browsing now knows exactly who to target: the users. The Ninth Circuit points out that it was unlikely that Congress meant to expose individual users to criminal liability under the CFAA (which is correct), but lawyers filing civil claims dont care about that. And a demand letter doesnt even need to turn into a lawsuit to work. The only thing holding a company like Amazon back from going after users for their use of agentic tools may be the very likely public backlash if they did so. Thats the real lesson from this ruling. Rather than making the liability vanish, it moves it around. Thats genuinely good news in a post-Power Ventures world for all sorts of things including price-comparison tools, accessibility overlays, researchers auditing platforms, and anyone building the interop layer a giant would rather not exist. But it may also leave those same users in a legal gray zone where an aggressive set of lawyers may decide to target them when they get fed up with agentic tools. Perhaps Amazon is smart enough not to go there. Then again, the recording industry spent the better part of a decade suing its own best customers, and plenty of lawyers told them it was a great idea at the time.

[Category: amazon, anthropic, openai, perplexity, 9th circuit, agents, cfaa, hacking, liability, negligence]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/5/26 12:18pm
The Ultimate Python and Artificial Intelligence Bundle has 9 courses to help you take your Python and AI knowledge to the next level. Youll learn about data pre-processing and visualization, artificial neural networks, how to use the Keras framework, and more. Its on sale for $40. Note: The Techdirt Deals Store is powered and curated by StackCommerce. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.

[Category: 1, daily deal]

[*] [+] [-] [x] [A+] [a-]  
[l] at 8/5/26 10:28am
The Trump administration has been shut down more than 10,000 times by federal courts over its novel interpretation of the law one it claims allows it to indefinitely detain migrants without giving them a bond hearing. Some of those 10,000 adverse decisions have been significant, with implications that stretch far beyond single cases or even single states, as Kyle Cheney notes for Politico: The rulings follows similar decisions in the Atlanta-based 11th Circuit, the New York-based 2nd Circuit, the Colorado-based 10th Circuit and the Cincinnati-based 6th Circuit. Two appeals courts, the 5th Circuit and the 8th Circuit, have sided with the Trump administration. Rulings are pending in three other circuits. The score so far runs like this: 460 judges, 10,000 rulings against the administration versus 54 judges and 1,100 cases finding in Trumps favor. The Fifth Circuits decision isnt an absolute win for the administration either. It says the government can violate migrants due process rights, but only for 90 days. The hitch here is that the Fifth Circuit has already agreed to review the case en banc. Whatever the outcome, its going to have repercussions that will alter how the government runs its mass deportation program. The circuit not only covers a large border state (Texas) but also several of the nations largest ICE detention facilities. And given what we know about the Fifth Circuit, the judges petitioning for the rehearing arent hoping to deliver a decision respecting migrants 14th Amendment rights. The only reason theyre doing this is because they think migrants shouldnt even have delayed access to their rights. Theres a circuit split, but not much of one. Two more appeals courts have ruled against Trumps detention policy. In a pair of 2-1 decisions, the California-based 9th Circuit Court of Appeals and the Illinois-based 7th Circuit Court of Appeals found that the Trump administration had defied logic and misconstrued decades-old immigration laws to justify its expansive detention policy. Appeals courts have now split 6-2 against the administration as the issue hurtles toward the Supreme Court, while the overwhelming majority of lower-court judges have ruled against the administration as well. This is going to hurt the administration, so we should probably expect the Supreme Court to get this on the shadow docket ASAP. The Ninth Circuit covers California, Trumps favorite target for deportation surges. Both circuits say the law doesnt say what Trump wants it to say. While they come to the same conclusion, the appellate courts phrase it differently. The Ninth Circuits ruling [PDF] makes a better and clearer point, so well start there. The Immigration and Nationality Act was last amended in 1996. But nothing really changed. It was understood that migrants detained while trying to cross the border were not entitled to due process rights, like bond hearings. However, migrants already in the United States especially those who had been here for a significant period of time were afforded the same rights as US citizens. Nothing changed for thirty years. Then Trump returned to office. And somehow everything changed. Not so fast, says the Ninth Circuit. Just because you want the law to say something it doesnt, doesnt make your argument any less ridiculous. The government recently changed its longstanding approach. It now contends that unadmitted aliens present in the interior of the country are subject to mandatory detention without bond under § 1225(b)(2)(A), based on revisions to the statute that Congress made in 1996. [] The implication of the government’s position is that Congress in 1996 made a major change to the immigration laws by subjecting millions of unadmitted aliens present in the United States to mandatory detention, but that this change then went unnoticed and unheeded, with the Executive Branch for the next three decades violating Congress’s assertedly unambiguous mandatory detention directive by treating these aliens as subject to release on bond. And while every law is written in legalese and is consequently somewhat open to interpretation, the Ninth Circuit says 30 years of history makes it clear what Trump is doing now is not what Congress intended when it amended the INA. Whether these aliens should be subject to a broader mandatory detention regime is a policy question that lies outside the role of the judiciary. The question here is not about policy or Executive Branch discretion, but congressional authorization. We do not decide whether Congress could enact the detention regime as the government would now have it, but rather whether Congress did so in 1996. The better view is that it did not. While this would seem to show Congress what it needs to do to make Trump happy and his mandatory detention scheme legal, its not that simple. Migrants still have access to constitutional rights, which means any legislative alteration would immediately be met by a constitutional challenge if passed. As it stands now, mandatory detention without a bond hearing is a no-go in the Ninth Circuit. The Seventh Circuits ruling [PDF] focuses more on Congress circa 1996 than the Trump administration in 2026. But the end result is still the same. DHS rests its new interpretation on changes Congress made to the Immigration and Nationality Act (“INA”) almost thirty years ago. Before those changes, aliens who unlawfully entered the country were given greater procedural rights than those who presented for inspection at the border. Congress ended that disparity by creating a legal fiction in removal proceedings that “deemed” all aliens not properly admitted “applicants for admission” to the United States, as if they had never crossed the border. But before last year, no administration had ever suggested this legal fiction extended beyond the INA’s removal procedures to its provisions governing detention pending removal. Its the same point made by the Ninth Circuit, even though the Seventh Circuit says its bad lawmaking thats to blame, rather than an opportunistic, wholly disingenuous interpretation by the Trump administration. But the administration isnt completely off the hook. The appeals court says the administration cant turn legal fiction into fact just because it only likes certain parts of the amended INA. Section 1225(b)(2)(A) imposes mandatory detention on certain “applicants for admission,” but only those who are also “seeking admission.” And Cirrus Rojas is not seeking admission: the relief he now seeks, asylum and withholding of removal, is not admission as the statute and Supreme Court case law use that term. Cirrus Rojas has never applied for anything that counts as “admission” to the United States. Nor can he successfully “seek” admission, as his unlawful entry renders him inadmissible. The government simply argues that because Cirrus Rojas is “deemed” an “applicant for admission,” he must be “seeking admission.” We hold that Cirrus Rojas is not “seeking admission”— and thus not covered by Section 1225(b)(2)(A)—because that is his real-world status. We join the majority of the circuits that have confronted this question in rejecting the government’s newfound statutory requirement for mandatory detention, which rests upon the illogical use of both legal fiction and ordinary meaning for the same term. Then it shifts things back to Congress, much like the Ninth Circuit did: One mixes fiction with fact at their peril. And the facts in this case are clear: Cirrus Rojas is not seeking admission to the United States. If Congress had meant to define individuals like Cirrus Rojas as “seeking admission,” it could have done so. This may be a single appeal one arising from tens of thousands of cases generated by this illegal mandatory detention policy but it affects every migrant in the Seventh Circuit and forces the government to respect their due process rights. Our holding is limited. We deal only with whether all aliens present without admission in the interior and facing removal proceedings are subject to mandatory detention. Under the INA’s plain text, context, and history, the answer is no. This is going to hurt Trump, too. The Seventh Circuit covers Illinois, another target of Trumps anti-migrant efforts solely because the state is governed by someone from the opposing political party. Good news for migrants and constitutional rights. Bad news for an administration that has no respect for rights whatsoever and sees migrants as sub-human. Well see how long this lasts, but for now most of the country is covered by precedent that denies the administration access to its preferred method of inflicting misery on migrants.

[Category: 1, 14th amendment, 7th circuit, 9th circuit, bigotry, dhs, ice, mass deportation, trump administration]

As of 8/9/26 11:55am. Last new 8/8/26 2:26pm.

Next feed in category: Arc Technica Science