Oracle Helped Kneecap Section 230, Then Bought 15% Of A Company That Needs It.
from the policy-by-spite dept
Six years ago, when Trump first tried to force ByteDance to sell TikTok’s US operations to his billionaire buddy Larry Ellison at Oracle, we wondered if this would finally get Oracle to change its tune on Section 230. While not as widely known outside of Silicon Valley, Oracle has been a driving force behind the scenes to get Congress to kill Section 230, appearing to do so almost entirely out of spite directed at Google.
It never made much sense. For most of that time, Oracle was busy trying to build itself into a leading cloud service provider — and cloud services rely on the exact same Section 230 protections Oracle was paying people to attack. But it’s not like Oracle is known for being particularly successful in its ability to think things out long term.
While Trump’s first attempt to hand TikTok to Oracle flopped, the second attempt (helped along by Democrats succumbing to a bogus moral panic about TikTok’s alleged dangers) resulted in Oracle ending up with a 15% stake in TikTok (as well as a lucrative hosting deal). In fact, Oracle’s long-term top lobbying exec, Ken Glueck (who was the architect of Oracle’s funding of a bunch of dark money groups that attacked Section 230) actually ended up with a seat on TikTok’s board.
And TikTok is already suffering from the attacks on Section 230. Remember, the wacky Anderson v. TikTok ruling that bizarrely said TikTok didn’t qualify for Section 230? That kind of ruling doesn’t happen without the widespread drumbeat of “Section 230 has gone too far” that Oracle spent years helping to push. TikTok is in a way worse position legally because of Ken Glueck’s advocacy. And now he’s on their board.
Meanwhile, Oracle, while not in the top tier of cloud providers — AWS, Microsoft, and Google together account for around 63% of enterprise cloud spending — is solidly at the top of the second tier. And while there aren’t that many Section 230 cases targeting the underlying cloud hosting providers, they’re not totally unheard of.
So, Section 230 protects both Oracle, and its large investment in TikTok. Yet Oracle spent years funding attacks on Section 230 (mainly just to piss off Google) and the main architect of that strategy is now on TikTok’s board.
Which puts us right back where we were six years ago, wondering if Oracle will ever change its tune. The company’s disclosures offer a partial answer. Section 230 is still under attack in DC, but the courts have been dismantling the law via judicial decisions that it’s not even clear what’s left for Congress to do. Looking at Oracle’s “Political Activity Reports” we see that while back in 2019 it was funding anti-tech groups which promoted attacks on Section 230 (like the Internet Accountability Project, the Free and Fair Markets Initiative, and the Copyright Alliance), these days it only funds the Copyright Alliance whose remit is larger than just attacking tech (though it still does that too).
Indeed, the IAP and FFMI, who were these huge fake grassroots non-profits designed to hold Google and Amazon to account, barely seem to exist any more. FFMI’s website stopped updating in 2023 and IAP’s in 2024. It’s almost as if they were astroturfed operations that suddenly became unnecessary once Ellison could get what he wanted directly, having spent $45 million to work his way deeper into Trump’s circle.
It looks like a large segment of the “grassroots” movement against Section 230 was conjured into existence with Oracle’s quiet backing, and seems to have evaporated once Oracle no longer needed it to exist.
Of course, there’s also the separate issue of the ongoing attempt by Ellison to also buy up half of Hollywood. Hollywood itself has probably been the second biggest force, behind Oracle, in the anti-Section 230 lobbying effort over the past decade. Ellison already owns Paramount, and may still end up with Warner Bros., as well, which might pull Oracle’s efforts back towards hating the open internet rather than defending the thing its own business runs on.
The simple fact, though, is that if you want a dynamic, competitive open internet, you need a strong Section 230. Gutting it won’t hurt the internet giants. They have buildings full of lawyers and can survive the onslaught of misguided lawsuits (most of which they’ll end up winning in the end). However, it will hurt all the small sites, the forums, the upstarts, the blogs that can’t afford to find out whether a case would get dismissed after a couple years and a million dollars of discovery. Who knows… perhaps that’s Ellison’s strategy all along: make the open internet weaker, so the companies he controls have way more power.
The next time Section 230 lands on the chopping block — and it will — Oracle (and, for that matter, TikTok) will have to pick a side. The smart move would be to defend it. But, then again, the smart move all along would have been for Oracle to defend it, and it chose the opposite for many years. The real question is whether Oracle’s years-long campaign against Section 230 comes back to bite it: devaluing the TikTok stake it worked so hard to get, and eating away at the legal protections its entire cloud business sits on top of.
Filed Under: grassroots, intermediary liability, ken glueck, lobbying, section 230
Companies: copyright alliance, iap, oracle, tiktok
Daily Deal: The 2026 Canva Creator Mastery Bundle
from the good-deals-on-cool-stuff dept
Take your design skills to the next level with the 2026 Canva Creator Mastery Bundle, a powerful all-in-one course for modern creators and business owners. This program teaches you how to use Canva effectively to produce professional-quality visuals for any purpose. You’ll explore practical design techniques, creative workflows and branding strategies that make your content stand out. This bundle is perfect for anyone ready to upgrade their digital presence and design skills. It’s on sale for $30.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
Filed Under: daily deal
Flock Claims It’s The First Company To Expose Police Misuse Of Surveillance Tech
from the we're-the-original-good-guys-of-collect-it-all! dept
Flock Safety is hurting. It spent the early part of its career pitching plate reader tech to people who honestly didn’t need it: HOA supervisors and gated communities. Then it realized there was far more money to be made by courting governments, rather than the richest parts of the private sector.
A few years later and Flock’s network of ALPR (automated license plate readers) cameras is now snagging plate reads at a rate of 20 billion a month. Power, responsibility, etc., as the old saying goes. Except cops and Flock wanted all of the power and none of the responsibility, which leads us to where we’re at now.
Dozens of cities are shutting down (or attempting to) their Flock cameras. Journalists all over the nation have published reports based on public records requests and court filings that demonstrably show Flock’s expansive camera network is empowering a new flavor of “superpredator.” This time, the uber-predator wears cop clothes.
On top of all of that, there’s been illegal (often second-hand) access by federal officers who talk local cops into performing searches for them. Then there are the cops themselves — who when not using Flock’s network to rat out migrants and/or hunt down people seeking legal abortions — are using this tech to keep tabs on people who’ve moved on from their relationships with the thin black-and-blue line of domestic abusers and stalkers.
Flock is now desperately trying to rehabilitate its image. At this point, Flock is synonymous with stalkerware, which would already be concerning if it weren’t for the fact that people’s taxes are paying for the cameras, as well as the cops who believe anything this powerful should be abused as often as possible.
Flock recently made some changes with an eye on curbing cop misuse of its massive database. While it did at least make these restrictions the default options for new customers, the alterations don’t really affect existing users. And law enforcement agencies just now signing up for Flock’s stalkerware will find it easy to opt-out of the bumper bowling lanes Flock has set up.
While I do believe Flock’s efforts are earnest — at least as far as they go — I don’t believe Flock actually wants to alienate its largest and most profitable customer base. But I will say this: I don’t remember the CEO of Harris Technologies doing interviews and responding to town hall meetings when Stingrays (and the damage done) went viral.
On the other hand, what even the fuck is going on here? People selling surveillance tech to entities that immediately abuse it shouldn’t be going live with comments that suggest regular Americans shouldn’t be involved in discussions that involve their privacy vs. their security. And yet, here we are. Here’s TechCrunch’s Anthony Ha with more details:
The country needs to find a “compromise” between privacy and safety, according to Flock Safety CEO Garrett Langley.
“When people talk about just one of these, privacy or safety, they’re prioritizing the wrong thing, and what we have to prioritize as a country is compromise,” Langley said during a recent interview with Fox News. “How do we have our safety, and how do we balance privacy?”
First off, if you’re headed to Fox first, it means you’re not really serious about dialing back surveillance that allows cops to hunt down abortion seekers, federal officers to hunt down migrants, and cops to hunt down their ex-girlfriends. These are all things most Fox viewers approve of.
Second, you’re not the right person to be asking about “balancing” privacy and security. You don’t really care about privacy. And despite the company’s claims, there’s little evidence on the record that installing Flock ALPRs actually leads to lower crime rates, which is what Langley is talking around when he uses a vague term like “security.”
I mean, I can secure my immediate private area with a network of cameras, improvised explosives, and sitting on my porch bathtub-cranked to the gills while cradling a shotgun. Privacy ain’t an issue. The same thing can be said for the other side: cops can load up on surveillance tech and claim things are more “secure,” but “secure” isn’t necessarily safe, and privacy still matters, whether or not Flock or its customers are willing to engage honestly with this topic.
But that isn’t the most insane/inane thing to fall out the mouth of Flock’s CEO. This is:
“I don’t think that Flock created police abuse. I think we’re the first company to ever shine a light on it and build the tools to find it.”
Hot diggity damn. WTAF.
It’s true that Flock didn’t “create” police abuse. But it just sat on its hands for months as evidence of police abuse piled up.
And the long history of police abuse of pretty much every database/surveillance tool they have access to should have resulted in restrictions being put in place before the company went shopping for cops, rather than hastily put into place (figuratively) minutes ago by a CEO who is now making “PLEASE CLAP” media appearances in hopes of preventing even more contract cancellations and negative press.
While it is true that Flock’s log files can (sometimes) be obtained via public records requests (which has led to exposure of abuse by police officers), this isn’t because Flock is so good at either privacy or security. It’s just the expected side effect of doing business with government agencies.
And Flock is not the champion it pretends to be. Plenty of companies are capable of sniffing out abuse by government agencies. Most just tend not to look for it. Flock is definitely not the “first” to “shine a light” on police misconduct. 90% of this is involuntary and the other 10% is absolute horseshit. I don’t remember Flock ever posting on its blog about police abuse even though it apparently has access to search logs. It’s always someone else doing the real work, with Flock hopping on the blog to post defensive statements and/or highlight some cop official rando talking big about “this one time we found a stolen car.”
If Flock really wants to be the hero, it needs to start breaking news, rather than reacting to it. It should be the whistleblower, alerting law enforcement management and cutting off access the moment it sees something sketchy. And it should have been doing this long ago, rather than pretending it cares the most… but only after it has weathered a few years of negative press.
Filed Under: alprs, location tracking, police misconduct, stalking, surveillance tech
Companies: flock, flock safety
Iowa AG Brenna Bird Makes Silly, Empty Legal Threats To Try And Save Larry Ellison’s Paramount Merger
from the here-comes-some-bullshit dept
As we’ve been noting, billionaire Larry Ellison’s effort to dominate what’s left of corporate media is facing some headwinds after 12 states filed an antitrust lawsuit against his planned $111 billion merger between Paramount and Warner Brothers. As we’ve also noted, this is a giant turd of a deal, the debt from which will indisputably result in mass layoffs, higher prices, and shittier overall product.
We know this because it’s what happens every time U.S. media giants merge; particularly when Warner Brothers is involved. It’s not something for economists or pundits to even debate. Large scale media consolidation is uniformly, indisputably bad for labor, markets, and consumers. There’s not a major U.S. industry where the impact isn’t very clearly obvious.
But the state AG lawsuit introduces all sorts of costly new delays for Ellison, which has resulted in a sort of PR desperation at the company. That has included repeatedly insisting that anybody who criticizes the merger (or Ellison) is somehow “antisemitic”. It’s also involved heavily lobbying a parade of high-profile people to try and convince the 12 state AGs to settle the case before next March’s trial.
That includes Iowa AG Brenna Bird, who wrote an editorial over at the right wing propaganda website DailyWire stating she was planning on suing California to try and stop the merger. To be clear there’s no indication she’s actually filed any legal paperwork or has any coherent standing to get legally involved, but she’s super keen to have you think she’s doing something important all the same.
The editorial is full of all sorts of silliness, including the observably false claim that more media consolidation somehow magically improves market competition (you can observe 50+ years of U.S. history to answer that question for yourself). She also leans heavily on this claim by Paramount that if they’re allowed to merge, they’ll create 30 big movies a year:
“A successful Paramount-Warner Bros. merger would change that. Netflix dominates the market for streaming. Paramount+ and HBO Max together are smaller than Netflix, smaller than Disney, and smaller than Amazon. The merger could create a company to compete: an estimated $6 billion in savings to reinvest, and a public commitment to release at least 30 movies in theaters every year. More movies mean more entertainment — and more competition means lower prices.”
As you may have observed from any of the hundreds of major U.S. mergers anytime in the last five decades, pre-merger promises by company executives are utterly worthless. They’re even more worthless in an era where we’ve defanged most of our public-protection, consumer, and labor regulators under the pretense this would somehow result in unbridled free market innovation.
Amusingly, Bird also tries to claim that California (which she singles out but is joined by 11 other state AGs in the suit) has introduced delays that would have somehow magically have instead gone toward lowering streaming video prices:
“Now think about what California’s delay is doing. Beginning in October, Paramount is contractually obligated to pay Warner Bros. roughly $7 million a day for as long as this transaction sits in limbo, and the trial that 12 state attorneys general have engineered will not even start until March 2027. That money could have lowered streaming costs but instead is being burned on a lawsuit that federal antitrust enforcers and 68 regulators around the world already concluded was unnecessary.”
It should go without saying that no, Paramount would have not just magically lowered streaming video prices if not for the AG lawsuit. That’s just… not even a coherent claim?
Most of the regulators around the world rubber stamped the deal because it has no meaningful impact on their local economies. 12 states sued to stop the deal because literally every time Warner Brothers is involved in a merger, it results in untold thousands of Americans losing their jobs, prices getting higher, and the remaining company getting steadily more enshittified. Again, this is not a debate.
The idea that letting media further consolidate — at the hands of a Trump-allied anti-democratic billionaire like Larry Ellison no less — somehow results in mystical new utopias for everyday Iowans is a very curious delusion. For Bird, the fact that the Trump DOJ (long since purged of every last person who actually believed in antitrust) claimed the deal would be good for Americans was evidence enough:
“The Department examined this deal market by market and found a benefit in each one. In streaming, it concluded the combined firm is likely to increase competition by giving consumers “a more robust competitive alternative” to the dominant players.”
I suppose Bird thought meaninglessly injecting herself in the debate over media consolidation would somehow move the needle for an oligarch, but it’s mostly just sad. I also think the endless PR and lobbying lengths Paramount has been willing to go to in order to sell this shitty deal to the public provides its own evidence as to why you probably don’t want to give Larry Ellison any more power.
Pressure continues to build for the state AGs to settle the lawsuit and allow the merger to proceed. When and if that happens, the high debt load of the deal will result in thousands of people losing their jobs, consumer prices will soar ever higher, conditions won’t be meaningfully enforced, and whatever’s left of Paramount/Warner Brothers under the management of weird brunchlords like Bari Weiss will produce more and more lowest-common-denominator offshored crap in the pursuit of impossible scale.
And when that happens, because it always happens, all the people rooting for consolidation and less regulatory scrutiny will very suddenly and curiously be nowhere to be found. All that will be left is a bunch of trash and some carnage, like the circus very abruptly packed up and left town.
Filed Under: antitrust, brenna bird, bullshit, california, iowa, larry ellison, media consolidation, mergers, streaming, video
Companies: paramount, warner bros.
Two Die In Pennsylvania Of Measles Marking The First Deaths Of 2026
from the needless-deaths dept
Last year, as decades of work by RFK Jr. to undermine vaccines with false links to deaths and autism culminated in his appointment to lead HHS, America saw the largest resurgence of measles cases in something like three decades. Three people died, including two children, all unvaccinated. Kennedy mostly ignored the outbreak from the beginning and has since only mustered the ability to say that people should get the MMR vaccine out of one side of his mouth while reminding everyone that he thinks vaccines are bad out of the other. Measles continued to roar into 2026, with Kennedy and HHS officials attempting to downplay case counts and deaths the entire time. We’ve already eclipsed 2025’s record-breaking case count here in 2026 and we still have months to add to that total.
And now we have our first two deaths from measles in 2026, as well. Both occurred in Pennsylvania and, while health officials aren’t releasing many details due to privacy concerns, it was noted that both of the deceased were unvaccinated for measles.
They are the first measles deaths reported in Pennsylvania in 35 years and the first deaths reported in the US in 2026. Last year, the US saw three measles deaths: two in otherwise-healthy but unvaccinated school-age children in Texas and one in an unvaccinated adult in New Mexico. Prior to those deaths, the US had not seen a measles death since 2015, when a woman with underlying conditions became severely ill.
Citing privacy, health officials in Pennsylvania are not providing information on the people who died beyond that they were unvaccinated and were residents of Lancaster County. Officials noted that the deaths are among 393 confirmed cases reported this year across 28 counties in the state.
As we talked about recently, due directly to the decades of work Kennedy has taken to undermine vaccines, vaccination rates for school children have and are continuing to fall. These deaths, and the vast majority of the case counts, are completely needless. We have the solution to preventing them. The MMR vaccine is safe and effective for those that are not immunocompromised. There is no scientific reason to believe it causes autism. And, importantly, if 95% of us get vaccinated against measles, we achieve herd immunity which protects those that can’t get vaccinated, as well as very young children who haven’t been vaccinated yet.
And that last category is one that is likely to grow, thanks to the Trump administration’s blatantly stupid executive order attempting to curtail how childhood vaccines are delivered and when. Not to mention the constant muddy waters Kennedy himself creates as to whether vaccines are good or bad, when they are so, what risks they carry, and so on. It is not an overreach to say that this administration, and Kennedy’s decades of bullshit in particular, got these people killed.
Still, anti-vaccine rhetoric, misinformation, and disinformation have shaken confidence in the vaccine, driving down vaccination rates. Some of that damaging discourse has come from Trump administration officials, most notably ardent anti-vaccine activist Robert F. Kennedy Jr., who is currently the US health secretary. But President Trump has also contributed, falsely claiming in a White House press event two weeks ago that the MMR vaccine can be “quite lethal.” The MMR vaccine has never been linked to a death in a person with a competent immune system (it’s not recommended in those who are immunocompromised).
One hundred percent correct. People look to their leaders for guidance on things like public health. Or they used to, at least. For some non-insignificant percentage of the country, they really do think Trump and Kennedy know what they’re talking about when it comes to matters of medicine. They don’t, of course. Not even close. But enough people are listening to them that it puts all of us in danger.
This has to end. Outbreaks of infectious diseases at the level of the measles tend to grow exponentially if not addressed. That’s why we’re already past last year’s case count. The project for getting back to herd immunity and proper vaccination rates will not be a short one. It will take years.
And I very much doubt that we won’t pass the death count here before the end of the year as well.
Filed Under: anti-vaxxers, health & human services, measles, mmr, pennsylvania, rfk jr., trump administration, vaccines
Meta Just Paid Nearly $17 Billion To Make Sure It Gets To Write The Kid Safety Rules For Every Other Social Media Platform
from the regulate-me-daddy dept
By now you’ve almost certainly heard the news that Meta has settled with 52 state and local Attorneys General who had sued the company in some form or another over child safety on Meta’s platforms. The headlines are all covering the basics: the years-long case these states filed against Meta ends, and Meta pays somewhere between $12.7 billion and $18 billion, depending on which document you read (the consent judgment itself caps the total at $16,680,647,753.21; Meta’s press release rounds it up to “approximately $18 billion”). Also Meta will implement a bunch of changes to its platforms with the aim of improving child safety on those platforms. It will also “encourage” YouTube and TikTok to enable the same safety features even though (bizarrely), if YouTube and TikTok follow suit, then Meta will have to pay more.
You can read the details of the proposed settlement here.
Notably, the whole point of doing this as a “settlement” is that everyone involved knows full well that no government could mandate these feature changes without violating the First Amendment. But now that it’s in a “settlement” the courts may need to explore if these choices — which Meta could make freely on its own — suddenly have become a “state action,” implicating the First Amendment.
As with the various rulings against Meta over the last few months, people are cheering this on, without realizing the damage it will do. We’ll explore why this is problematic in a moment, but just to highlight that I’m not alone in thinking so, both EFF and Fight for the Future are warning how bad this settlement is. Here’s EFF:
Under this settlement, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collection of even more personal information from users of all ages; this enshrines Meta’s harmful surveillance into law, and it will compromise users’ privacy and anonymity while increasing their exposure to data breaches and government data requests. And the data minimization and security measures don’t keep states from using data collected under the agreement for other law enforcement purposes – which could include things like criminal investigations of abortions or gender-affirming care.
And here’s Fight’s emailed statement:
Big Tech does pose harm to our kids through its business practices and exploitation, but pushing for more censorship, age-gating, and surveillance of young people at the hands of the same Big Tech companies that have already harmed young people is not the answer. Online ID checks when implemented put vital information behind age-gates, stamp down teenagers’ right to speak, and expose all of us to even more of our data being collected, hacked, and leaked. Meta knows that managing this amount of personal information and enforcing these agegates will be messy and that’s why they are seeking to offload the burden to anyone but themselves, while being seen to comply by the public and lawmakers. Instead of actually damaging their exploitative business model, this result allows Meta to bring everyone else down with them, from app stores to other social media companies. We feared that these lawsuits would manufacture consent for invasive age verification and content controls and our fears have been proven correct. We will continue to oppose online ID checks everywhere and be on the watch for more censorship creeping into Meta’s platform.
We’ll get into the specifics of why this settlement is so bad, but first some important background. For a few decades now, when basically all Attorneys General would get together to threaten and/or sue tech companies, it was almost always over bullshit headline grabbing claims where the AGs either had no jurisdiction or ability to legally do anything. Sixteen years ago, we wrote one story about an account written by a CEO of a company who faced down dozens of state AGs who were way more concerned about the headlines they generated than actually making platforms safe.
It was similar to other stories that we’d heard, where no matter what companies did to explain to the AGs what steps they were taking to keep a platform safe the AGs would simply turn around and misrepresent what they were told, out of context, to make the platforms look worse and worse until they agreed to some sort of settlement. It happened with Craigslist. It happened with ISPs being forced to kick their users off at the behest of the recording industry. Even John Oliver has covered how grandstanding state Attorneys General will target just about anyone they want to shake down in some form or another.
That’s not to say that there aren’t righteous cases brought by Attorneys General, but there are so many examples of them being much more about getting headlines than actually making people safer. And the simple fact is that these efforts are so resource intensive, so expensive, and so draining that it’s no surprise that most companies end up “settling” by agreeing to do things that the government simply cannot force a company to do. But because it’s a “settlement” people act like it’s not the government doing it.
In this case, given some of the recent court decisions, it’s no surprise that Meta would strike some sort of settlement. As these cases continued, the headlines would only get worse for the company. And Meta deserves some bad headlines, but as I’ve discussed, many of the bad headlines in these cases involved lawyers and the media taking things way out of context. The classic case with Meta is that many of its efforts to study how to make its platforms safer were used against the company as proof that “they knew!” their platforms were unsafe!
The lesson for the rest of the tech industry is grim and unambiguous: never study whether your own platform is causing harm. The mere existence of the research will be turned into Exhibit A that “they knew,” both in the court of public opinion and in actual courts.
The other bit of background worth understanding here is that Meta has been desperately seeking a path to regulatory capture for quite some time now. It’s been practically begging for Congress to pass child safety legislation that only the largest companies (like itself) could comply with. Indeed, Meta has done this before. It went against the rest of the internet industry in embracing FOSTA, again to try to create a regulatory moat. So this shouldn’t be surprising.
Meta’s failed forays into the “metaverse” and AI have shown that it’s been pretty consistently losing the innovation race, and the government granting it a regulatory moat that smaller competitors can’t cross would be a godsend.
And it’s even better when it can be done in a way that looks like Meta “losing” a lawsuit.
So that’s what Meta gets here. They “settle” the lawsuit so the AGs and Meta haters can all claim that they’ve “protected the children.” Meta pays out over a decade — enough that it’s taking a $10 billion legal charge in Q3, which stings for a bit but will mostly be forgotten by next year. Meta can easily eat the cost. And then Meta agrees to implement a bunch of kid safety features, most of which we have no idea whether they actually protect any kids. Notably, a legislature could not have mandated most of these features without running straight into the First Amendment — but coming out of a settlement, they carry the imprimatur of law anyway (more on that in a moment), and the structure of the agreement makes it so that Meta has to actively encourage Google and TikTok to take identical steps, thereby setting in concrete what steps any platform will have to take to be considered following “best practices” and therefore acceptable to most of the country’s Attorneys General.
The specific features don’t even matter that much, but for the record:
- Time Limit: A default two-hour daily time limit that teens can only turn off with a parent’s permission. This limit is cumulative across Facebook and Instagram, and time spent scrolling on both apps counts toward the total, including if we detect that someone has multiple accounts.
- Night Mode: A default block from our apps between midnight and 6am. This means teens will not be able to post or view their Feed, Stories, Explore, or Reels, for example.
- School Mode: Notifications will be muted by default between 8 AM and 3 PM. During those hours, teens will no longer receive push notifications, except for direct messages and alerts about their account security or safety.
- Regular Prompts: Teens will receive prompts after every 15 minutes of continuous screen time on Facebook or Instagram. They’ll also receive prompts when their total daily usage hits 60 minutes and 90 minutes. These prompts are designed to encourage intentional use.
- Algorithmic Feed Control: Teens will be able to choose a non-algorithmic feed — one that isn’t personalized by our recommendation systems — as their default. We will periodically remind them of this option, and parents can choose to adjust their teen’s default experience to require this setting.
- Autoplay Control: Teens will be able to turn off autoplay, so that content no longer automatically plays. Instead, they’ll need to take a deliberate action, like a tap or swipe, to see more. Parents can choose to adjust their teen’s default experience to require this setting.
- Hidden Likes: Teens won’t see the number of likes and reactions on posts — both their own and those from others — by default.
- Disabling cosmetic surgery and extreme makeup filters: In addition to our existing policy to block teens from using cosmetic surgery filters, we’ll now block teens from using extreme makeup filters.
- Age Assurance: We work hard to find and remove underage accounts from our apps and, as part of our agreement, we’re investing in even stronger technology to proactively catch accounts that may belong to under-13s. We’re also strengthening the technology we use to identify accounts that may be between the ages of 13 and 17, so we can ensure those accounts are placed in experiences designed for teens, even if they give us an adult birthday. However, to ensure teens are consistently protected across the many apps they use, app stores must provide developers with verified age information. This will allow platforms to put age-appropriate protections in place for as many teens as possible. That’s why we’ll continue to advocate for legislation that empowers parents by requiring app stores to verify age and obtain parental approval before a teen downloads an app.
- Age-appropriate content restrictions: We will maintain our current content standards so that, by default, teens are placed into 13+ content settings, inspired by movie ratings criteria and parent feedback. We will also continue to prevent teens from following or interacting with accounts we consider age-inappropriate. We will work to continually improve these systems to ensure age-appropriate content experiences for teens.
- Unwanted contact from strangers: We will maintain our current practices of defaulting teens into private accounts on Instagram and private default settings on Facebook, and we’ll continue to restrict potentially suspicious adults from contacting them. We will also strengthen our efforts to make it harder for those adults to find, follow, or interact with teens.
- Reporting and ongoing protection from harmful content: We will continue to give teens easy ways to report content that concerns them, and we’ll work to improve our response times. We will also continue our work to protect teens from potentially harmful experiences by regularly evaluating how often teens are exposed to them. We’ll draw on research and expert input to improve our work.
- Strengthening our parental controls: We will encourage parents to set up our supervision tools and give them new controls and insights. This includes notifying parents when a teen links a secondary account, alerting them to interactions with potentially suspicious accounts, and providing periodic updates on their teen’s usage and any changes their teen attempts to make to their protective settings.
Some of those might be good features. Some of them might not be. Some of them might be good for some kids, but very bad for other kids.
Part of the problem is we really don’t know.
There is something of an accountability structure here too. Meta and the states will appoint an “independent” auditor for five years, and the age assurance system gets tested annually to meet certain thresholds. But it’s important to look at what’s actually being audited here. It’s whether or not Meta is implementing the things it’s promised to do, not whether any of those things actually work.
But now these are, effectively, mandated by law. Even though if Congress or the states had passed a law requiring these, it would almost certainly be thrown out as unconstitutional under the First Amendment.
The weirdest part of the agreement is that Meta has to try to convince Google (YouTube) and TikTok to implement some (but not all?) of these same features. Indeed, Meta has already put up a settlement-mandated open letter to those two companies asking them to implement those features.
What’s so weird is that if YouTube and TikTok agree to do this and to voluntarily throw billions of dollars at the states, then Meta also needs to pay more. The breakdown of the money Meta owes is partially dependent on them arm-twisting those two companies to do the same things:
The agreement includes a payment of approximately $18 billion, which can be used to fund youth online safety initiatives, among other state priorities. The payment will be distributed in annual installments over a 10-year period. Participating states will receive approximately 70% (approximately $12.7 billion) of the allocated payment over the decade. The remaining 30% (approximately $5.3 billion) will be released only after two specific conditions are met.
- YouTube and TikTok implement a one-hour Daily Limit, Night Mode, and age assurance measures.
- YouTube and TikTok each pay an amount matching the 30% figure, with half of the remaining funds tied to YouTube’s payment and half tied to TikTok’s.
You can argue that Meta might not actually want YouTube and TikTok to do this, so they won’t have to pay that extra $5.3 billion, but from a competitive standpoint, you have to think that Meta absolutely needs to have YouTube and TikTok implement these features or its already somewhat dwindling market share will dwindle faster.
It’s quite possible that YouTube and TikTok will go along with this, rather than get bogged down in a similarly costly legal fight. But, again, that would create many problems. First, we still don’t know if those feature changes are actually helpful or effective. But now they’re effectively government mandated.
In theory, this could open up room for other platforms to come in and sweep up the youth market by not implementing these same features. But the nature of this agreement is that if the state AGs suddenly feel like any platform is becoming too popular with the kids, it can point to this agreement and call it “industry standard” or “industry best practices” to insinuate that other companies not doing the same are deliberately choosing to keep kids unsafe.
Indeed, within the agreement there’s a bit of weirdness, in which Meta has to push for “industry wide adoption” which is currently defined as YouTube and TikTok, but which the agreement makes clear could include any new social media platform if such a new platform meets the thresholds. In other words, Meta is basically being forced into guaranteeing this settlement creates an industry-wide standard.
And that’s a real problem when we still don’t know how to actually help keep kids safer online. So if a web service comes up with a unique or innovative or different idea that works differently than what Meta has agreed to do, then that may be too risky to even try. Better to just follow what the AGs have “blessed” in this settlement.
As noted, we already know that some of these things are directly harmful. Age assurance is a privacy nightmare. Enshrining it as the industry standard means the end of meaningful online anonymity, and it “forces” Meta to collect more data about all of us — including adults — while handing the states a pipeline to that data for whatever else they decide it’s useful for.
That’s bad.
Also, there are some oddly specific requirements:
Meta SMPs will disable Teen Users from applying Cosmetic Procedure Filters to their content.
The agreement clarifies that this means:
… any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques.
And, sure, I can understand why such content might be unhealthy for teens. But it is, in fact, Constitutionally-protected speech. Meta could decide internally to block that speech specifically on its own platform (that’s its own editorial right). But now that it’s being done at the behest of government pressure, it almost certainly violates the First Amendment.
Also, somewhat oddly, some of the rules appear to only apply to content in English or Spanish:
With respect to Potentially Harmful Reported Content submitted in English or Spanish, Meta SMPs shall maintain processes designed to permit Teen Users to receive a response indicating Meta’s decision on the report within 6 hours in at least 90% of cases.
The implication is obvious: those are the languages most reports come in, and Meta is expected to staff up enough to clear them fast. But it also means the government has just negotiated a moderation service level that varies by the language you happen to speak — English and Spanish speakers get a six-hour guarantee, Tagalog and Mandarin speakers get whatever Meta feels like. That’s a strange thing for a state to be dictating at all.
This is also a perfect example of the kind of standard that only a giant can meet. A six-hour turnaround on 90% of reports is achievable when you have thousands of trust & safety staff and a decade of tooling. For a startup with four employees and a Discord server, it’s a fantasy — and now it’s the benchmark against which every AG will measure them.
So what happens now? The judge will need to review the settlement, but I’m actually wondering if some teenage users would have standing to challenge this. Meta is clearly restricting First Amendment protected speech under this agreement. It is free to do so on its own if it chooses to do so, but this is different. Here it’s doing so because it’s being forced to by various state AGs, making it a state action.
Under the Supreme Court’s recent (unanimous) Vullo decision, that seems pretty clearly unconstitutional. In that case,the justices said, quite clearly:
[A] government official cannot do indirectly what she is barred from doing directly: A government official cannot coerce a private party to punish or suppress disfavored speech on her behalf.
That seems like it should be the whole ballgame, because that’s what’s happening here.
One other point on all of this. Here’s the list of 52 Attorneys General that have agreed to this settlement:
Alabama, Alaska, American Samoa, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, District of Columbia, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, N. Mariana Islands, Nebraska, Nevada, New Hampshire, New Jersey, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Puerto Rico, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.
Notice anyone missing? Yup. There’s no New Mexico. Remember, New Mexico won its initial case against Meta recently, enabling the judge to force a different set of feature changes on the company. So… now Meta may have certain features for New Mexico, and different features for everywhere else?
None of this is to say that Meta shouldn’t do a better job trying to protect kids on its platform. Obviously, it can certainly do more. But this settlement seems much more like Meta using this case as a way to force the industry into a set of required steps (which might not help much, and may do real harm in some cases), making it difficult for smaller competitors to enter the market, and giving them a bit of regulatory capture through mass lawsuit settlement.
As law professor Jess Miers wrote, this settlement is about Meta selling out the entire social media industry, forcing them to embrace impractical and unhelpful features that serve only to lock in giants and lock out upstarts:
But for all the people “celebrating” this as a win “against” Meta, you’ve been fooled. Meta just cut a deal to put itself in charge of how social media works going forward. As Justin Maurer wrote on Bluesky, this is Meta taking a “please regulate me Daddy” approach to the government, and getting exactly what it really has been asking for.
We still don’t have any actual evidence that this will help anyone, let alone every kid. The state AGs didn’t have to prove how this would help kids. Meta didn’t have to prove it. The judge won’t be asked to. It’s just taken on faith. Meta offered this up, the AGs okayed it… and it all becomes a grand experiment on kids.
You can argue that these feature changes sound like they should help kids. Limiting access to two hours a day (unless parents grant more, which many will), lights out at midnight, disappearing like counts — these all sound like they’ll help some kids. But if it turns out that locking kids out of these systems actually pushes the most vulnerable ones to darker places with no trust & safety team at all, you won’t hear about that from Meta or the AGs.
We just spent three years teaching the entire industry that if you do research on child safety, you’ll have it held against you. Do we really think that all of this is going to actually enable anyone to figure out what works to help actual kids?
Meta bought itself a moat. The AGs bought themselves headlines that will be useful next election season. And every teenager in the country was just automatically enrolled in an untested experiment. There’s a five year independent auditor requirement to confirm that Meta follows the rules. But not to see if the rules work.
Filed Under: child safety, kid safety, settlements, state ags, states
Companies: meta, tiktok, youtube
ICE Tries, Fails To Illegally Raid An Immigration Law Office; Settles For Empty Threats Instead
from the maybe-don't-fuck-with-people-who-actually-know-the-law dept
The thing about raiding law offices is that they tend to be filled with people who actually know the law. A bunch of opportunistic ICE officers thought they might be able to talk their way into an illegal search, but that initiative (is that the word for this?) died out almost immediately when the interloping officers were greeted by a small group of immigration lawyers.
As is to be expected, this attempted illegal raid occurred in a “blue” state — the states that are still seeing large amounts of immigration officer activity just because their populations refused to throw a majority of their support behind Donald Trump during the last three elections.
The Sacramento Bee broke the news, covered here by Mathew Miranda:
Multiple U.S. Immigration Customs and Enforcement agents armed with guns attempted to inspect a Sacramento immigration law firm — and threatened to return later and break windows — on Friday morning, according to several employees of the building.
Employees of the North Natomas law firm and next door dentistry office said the agents, who arrived in at least four vehicles, claimed to have received a list from Washington, D.C., which listed the building’s address as the primary mailing address for many people. The ICE agents requested to tour the office for beds, but were ultimately turned away after failing to provide a warrant.
You can see the pretense. And you can see how everyone else would have recognized it was a pretense, even if the ICE officers hadn’t backed down immediately in the face of “get a warrant” demands from the occupants of the law office.
ICE pretended that a lot of migrants using the law office as a mailing address (something likely limited to court documents, etc.) was evidence that the law office was illegally housing dozens of migrants. But, as a migrant trying to work your way through the immigration system, it just makes sense to list a law office as the address of contact when engaging court proceedings, especially if your housing situation may be in a constant state of flux. Telling courts to send summons, notices, etc. to your legal reps is the smart way to handle things like naturalization proceedings, given that the rules seem to keep changing, and our current government is doing whatever it can to disrupt immigration proceedings to maximize arrests and detentions.
It would be immediately clear to anyone but an opportunistic ICE thug that the Morris Law Office was incapable of housing a large number of migrants. It’s a strip mall law office that shares a building with a dental implant clinic.


Having rushed directly into a stone wall composed of well-composed immigration lawyers (as well as the absolute stupidity of having to pretend a strip mall law office could be a second home for a large number of migrants), ICE officers retreated empty-handed, but not before issuing a threat that only later proved to be as empty as their fingerless gloved hands:
Raissa Morris, owner of the Morris Law Group, received a text at 9:16 a.m. which read “immigration is here.” The message came from one of her employees who told her an agent, who was armed and wearing an ICE badge, had entered the front lobby and asked to speak to an office manager.
She quickly told one of her employees to tell an agent that they could not inspect the building without a warrant. The agent responded by saying that they had received a list from Washington, D.C., which featured multiple clients using the law firm’s address. He asked to inspect the office for beds and said if they received follow-up orders that they could return at 3 a.m. to break windows and enter.
Thugs to the very end. “If you won’t let us abuse our power and ignore your rights, we’ll just ask someone back at the office to swear out some paperwork that will let us get what we want without your cooperation.” Obviously, this paraphrasing is far more coherent and polite than anything uttered by your average ICE officer (and, at this point, almost any ICE officer would be lucky to be considered “average”). But the ultimate point remains: if ICE doesn’t get what it wants immediately, it will find a way to get it eventually.
Additional coverage by local news station KCRA includes some on-site reporting, along with screenshots of several photos of ICE vehicles shared by law firm employees. It also includes a comment from the DHS, which apparently couldn’t be bothered to respond to questions from reporters at the publication that first broke the news.
In a statement to KCRA 3, DHS said, “On August 14, ICE officers approached an unmarked door during a targeted enforcement operation, thinking it was the target address as it was listed as the address of the illegal aliens they were planning to arrest. Upon finding out it was a law firm; they departed the address.”
This statement is only true if you ignore the officers’ attempt to engage in a warrantless search, as well as the parting threat they issued when they were ejected by Morris Law employees. ICE had to know it was a law firm because that would be the first result in any normal search of that address. And officers couldn’t pretend it was just some hostel for migrants when they rolled up in at least four separate unmarked vehicles. They were clearly in a quasi-strip mall parking lot facing a business with the business name clearly displayed above the address the DHS now claims was so inscrutable it took an accosting and a confrontation with people who actually know and respect the law to inform the officers of their “mistake.”
The DHS statement is idiotic, which just means it’s on-brand for this administration. So far, the threat to come back and break windows while no one’s in the office has yet to materialize. But this government is filled with sore losers and sore winners (that would be the big baby boy sitting behind the Resolute Desk), so I wouldn’t put any money on ICE just taking this L and moving on to other things.
Filed Under: 4th amendment, california, dhs, ice, masked thugs, mass deportation, raissa morris
Companies: morris law group
How AI Watermark Mandates Could Unmask Journalists Who Never Touched AI
from the everything-is-a-tradeoffs dept
Imagine a scenario where a documentary filmmaker, in the course of making the documentary, captures some damning footage of corporate malfeasance, which she wishes to share with an investigative reporting organization anonymously. Should we be concerned that mandates on AI watermarking might reveal who she is, even if she’s not using AI at all?
Last week I pointed out some of the concerns I had with Anthropic’s AI-generated text watermarking implementation. As I explained, plenty of people use these tools for perfectly legitimate reasons. I talked specifically about non-native English speakers and some disabled communities, and how a label as binary as “some AI was used on this” inevitably lumps those uses in with all the genuinely bad ones.
A friend pointed me to a separate concern that I had not considered, from the human rights group WITNESS. I should say that WITNESS is generally supportive of AI transparency rules, and was apparently involved in the process to create the EU’s Code of Practice related to the rules that forced Anthropic to add these watermarks. But, for obvious reasons, it’s concerned about the privacy implications of these tools. Indeed, it released a fascinating report about how watermarking done badly represents a surveillance risk.
The scenario I described to open this piece comes straight from that report:
Her production software is C2PA-enabled.
She uses it because her international distribution partners require it. When she installed it, the setup asked for her name, email, and country. Standard fields. She completed them and started working.
What the setup process did not explain is that the software’s default configuration attaches her account details to the Content Credentials of every file she exports, via the CAWG identity extension. The option to disable this exists, in an advanced settings panel she has never opened, described in language that assumes familiarity with the C2PA specifications.
For most of the year this does not matter. Then, in the final weeks of production, she films something unplanned: a confrontation between managers and workers organizing without official recognition. She decides to submit the clip anonymously to a press freedom organization abroad. She exports it without checking the Content Credentials panel, because she does not know there is anything there that needs checking.
Her name travels with the file.
The report focuses on C2PA, which is the emerging standard most companies are using for non-text watermarking (for images, videos, etc.). It was put together by a bunch of the tech companies to solve their own problems regarding identifying AI-generated content. But with the EU’s AI Act and similar laws showing up, it’s getting pulled from “here’s a nifty tech solution” into “this is part of the law.” And, as the report notes, the current implementation can be abused for surveillance:
The populations most exposed are journalists, human rights defenders, and documentary filmmakers. For these groups, content provenance infrastructure creates a distinct and underappreciated surveillance surface: one that links identity to specific digital content with cryptographic precision, accumulates into detailed behavioral profiles over time, and is made harder to contest by the regulatory legitimacy surrounding it. Viewers of credentialed content face their own exposure: the act of verifying content can generate a behavioral record without their knowledge or consent.
This doesn’t mean that watermarking shouldn’t be used, but rather, as WITNESS notes, we should be aware of the risks, and seek to counter them.
The report lists multiple ways that “provenance” tools like watermarking can expose personal information. The most obvious: once watermarking is mandatory, piggybacking identity requirements on top of it becomes trivial — which, in practice, means close to inevitable:
The first is legislative and regulatory misuse. A government that understands the C2PA’s privacy surface can exploit it deliberately — through mandated identity assertions, required credentials as a condition of distribution, or convergence with national identity systems. The more likely near-term risk, however, may be a well-intentioned regulator who mandates C2PA-compliant credentials without understanding what that mandate activates. The outcome can be functionally identical to deliberate misuse.
While the report doesn’t say this quite so directly, you can see how mandates for this technology, combined with growing mandates for age or identity verification, could do real damage:
Identity can be required as a condition of creating or distributing content. A law or platform policy may require attaching personal information to Content Credentials before content can be published or distributed. The C2PA specification does not prohibit this as mandatory identity assertions may, in specific use cases, be a legitimate use of the standard. A government mandate requiring journalists to register their identity with a national authority before their content can carry verified credentials would require no modification to the specifications whatsoever, and would not be distinguishable, at the infrastructure layer, from those legitimate uses
We already have governments increasingly requiring everyone to prove their identity in some form before they can look at content. The provenance mandates are something of a mirror image: a mandate to prove who is creating the content before you can publish it. And that mandate is being dressed up as an anti-disinformation tool wrapped in a human rights cloak, making it way more difficult to push back on than a state porn-ID law. And that’s before we mention how the “AI” component leads many people who would otherwise be careful about tech mandates to scream “fuck AI, do this!”
The report also points out that content creators may not realize what information gets included in a watermark.
Personally identifiable information can be added by the user — inadvertently, or without being informed of the privacy implications of doing so. Content Credentials can carry personal information added by the creator—a name, a caption, a device identifier—without the tool surfacing what that disclosure means or who can access it. The harm is not always intentional on the part of the platform: tool design that prioritizes functionality over privacy literacy can produce the same outcome as deliberate data collection. A photographer including personal attribution to an image may not realize that information will travel permanently with the file, accessible to anyone who inspects the manifest.
We know this happens, because plenty of people still have no idea how much revealing metadata is baked into every photo they post.
Even in cases where people think they’re being careful, a pattern may still emerge that reveals sensitive information:
Identity can emerge from patterns across a body of published work.
Identity may become recoverable not from an individual manifest but from correlating assertions across a body of work over time— locations, timestamps, device identifiers, behavioral signatures—none of which individually crosses a sensitivity threshold, but which together build a detailed profile. For example, a state actor scraping a manifest store to map the movement patterns of an activist photographer across months of published work would not need access to any single sensitive file.
And perhaps worst of all, the final risk they highlight is that simply the act of verifying the provenance of some form of media requires interacting with third parties that may reveal some amount of information:
Engaging with Content Credentials exposes creator and audience behavior to third parties. Engaging with Content Credentials — whether as a creator signing content or as an audience member verifying it — can expose behavior to third parties. On the creation side, signing operations that require external connections for timestamping, certificate status checks, or manifest store submission generate server-side records linking the creator’s device, location, and timestamp to a specific piece of content, without any disclosure that this is occurring. On the verification side, depending on implementation, remote validation may require the viewer’s device to contact an external server directly, generating a logged request that records who verified what, from where, and when. In neither case does the affected party have awareness that this is happening or any means of refusing it: unlike cookies or tracking pixels, the C2PA specifications include no consent mechanism, no opt-out, and no disclosure requirements. A journalist signing footage before publication may unknowingly leave a server-side trace of that act. A reader who encounters a suspicious image on social media and verifies its provenance may unknowingly send a request associating their IP address, approximate location, and timestamp with that specific piece of content. At scale, across a platform or a jurisdiction, these logs become a map of who is creating what and who is reading what, where and when.
While the descriptions of the surveillance threats from the tech are good, what drives it home are some of the fictional scenarios that are absolutely worth reading. There’s a story of a government passing an “anti-disinformation” law, which then enables that government to track down a reporter exposing government malfeasance, because her identity is tied to her digital tools via its digital provenance requirements. In another scenario, a local reporting outfit working on an investigative piece partners with a foreign media org to hide its own involvement — only to have it revealed by the watermarking tech.
Or the story of an anonymous online video producer, who doesn’t realize that despite efforts to protect his identity, these provenance mandates actually reveal to everyone who he is. Perhaps the most terrifying is the human rights worker documenting war crimes, taking massive privacy and security precautions, but is ratted out by the tech in ways that are difficult to predict:
The state actor does not need a surveillance program to make the connection. They need two things that are already publicly available. The first is the organization’s own archive. In regions where field staff safety is less of a concern, the organization signs its content with its organizational identity. It is standard practice, and a source of institutional credibility with the tribunals and monitoring bodies it works with. That archive is public, verifiable, and searchable. It establishes, unambiguously, that this organization uses this specific tool. The association between the tool signature and the organization’s name is not inferred. It is proven, repeatedly, by the organization’s own publishing practice in contexts where they had no reason to hide it.
The second is the content credential metadata ecosystem. Services that index C2PA manifests, aggregating records from published content across platforms, make the tool signature searchable across a body of work. The conflict zone footage, submitted to the monitoring body and entering a semi-public record, carries the same tool signature as dozens of other pieces of content the organization has published under its name elsewhere.
The tool signature in the conflict zone footage matches the tool signature in the organization’s public archive. The organization’s known field presence does the rest. The credential record the organization designed to protect its staff contains, in the tool signature alone, a thread that leads directly back to them, and they placed that thread in the public record themselves, in good faith, in a different context entirely. The anonymity set was the user base of that tool, in that region, in that period, and that number was small enough to matter.
One of the problems of anonymity software today is that if not enough people are using it for everything else, your mere use of it alone may reveal things about you. That’s what the last paragraph of this scenario highlights.
That scenario also calls out another vector of concern: as more and more media comes with C2PA credentials (or other watermarks) attached, we’re going to get more and more aggregation by third parties, which opens up yet another vector of surveillance. After so many years of concerns about the aggregation of private information — especially in the EU with the GDPR — you’d hope that regulators would be more careful not to create another way to amass huge collections of data on each of us.
Instead, the EU spent all these years building an entire (somewhat annoying!) “consent” regime centered on the idea that a third party shouldn’t be logging what you looked at on the internet without first getting your permission. So it’s a bit odd for this very same regulatory apparatus to then push an infrastructure that might hand a lot of private information over to aggregators… just in a more secretive manner.
Again, none of this is to say that watermarks are inherently bad. There are many cases where they are incredibly useful. WITNESS’s own report leads off by saying that it is “increasingly necessary” and a “part of restoring trust in the information environment.” It also has many suggestions for how to build better, privacy preserving tools to do this better.
But a transparency tool that doubles as a tracking layer for journalists, human rights defenders, and the people reading their work is not much of a win for the information environment it’s supposed to be restoring.
This is a point we keep hammering on about tech policy, and especially about the sorts of technology mandates that have become so popular these days. It is really, really hard to look at an entire ecosystem and see how the pieces interact — but that’s the job when you’re writing rules that everyone has to build to. Mandates that might increase competition can decrease privacy and security. Mandates that might increase transparency can decrease competition or security. Almost every decision has tradeoffs.
We still need to make those decisions, but we should do so with our eyes open regarding the tradeoffs, and figure out the best ways to minimize the harms while increasing the benefits. Unfortunately, as it stands, it’s not clear that regulators have really understood all the potential downsides regarding mandated watermarking transparency yet.
When I wrote about the concern of watermark mandates last week, a lot of people were quick to dismiss them. “AI sucks and no one should use it” was the attitude of many commenters. But it’s not just about AI, as hopefully the examples in this article highlight. The filmmaker using her regular tools or the human rights worker documenting war crimes shouldn’t lose their anonymity because these mandates were designed to stop people from making a fake video of a politician.
There’s a hell of a lot of work left to do to get this right. Currently, the EU’s AI Act mandates a label designed to help you check whether the content you’re consuming was generated with the help of AI tools. But depending on how it’s implemented, that setup can create real problems. The very act of checking the provenance of an image or video can put your own IP address, your location, and a timestamp in some third party’s server log, tied to that media. Worried regulators mandated that the provenance tracking exist. Now we’re all going to have to deal with the fallout.
Filed Under: ai, anonymity, c2pa, eu ai act, privacy, provenance, surveillance, tracking, transparency, watermarking
Companies: witness
Daily Deal: The Essential MATLAB & LabVIEW Mega Bundle
from the good-deals-on-cool-stuff dept
The Essential MATLAB and LabVIEW Mega Bundle has 9 courses to help you improve your skills in programming and visualization. You’ll learn the basics of each and then go through hands-on courses building apps, learning about data analysis and visualization, and more. It’s on sale for $30.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
Filed Under: daily deal
As Flock Vandalism Goes Mainstream, One Grand Jury Says Alleged Flock Vandal Did Nothing Wrong
from the go-flock-yourself dept
Flock Safety has been on the wrong side of the press cycle — if not the wrong side of history — for most of the last couple of years. Flock’s automated license plate readers (ALPRs) are more comprehensive than many of those previously deployed by law enforcement agencies. Not only do they capture plate/location data, they take photos of the entire vehicle, providing searchable info about distinguishing vehicle features as well as setting the stage for the almost-inevitable introduction of facial recognition tech.
Flock’s network of cameras is capable of capturing 20 billion plate/vehicle images a month. What the public is receiving in return for this remarkable gain in law enforcement “efficiency” is a lot of false positives, illegal second-hand access by federal officers, and the sickening — but wholly expected — news that cops are using this tech to stalk ex-wives, ex-girlfriends, and women seeking abortions.
Reacting poorly and belatedly, Flock has finally decided to institute a few more on-by-default options meant to deter abuse of its systems and databases, as well as lowering the default record retention period from 30 days to one week. While it is good to see Flock recognizing its contribution to the ACAB ecosphere, the new guidelines don’t appear to prevent cop shops from bypassing the presets and going right back to lengthy retention periods and stripping measures meant to give supervisors a head’s up on potential misuse of Flock plate records.
Given the disinterest of both Flock and its main customers to police themselves, US citizens are now behaving more like their European counterparts who have been deliberately destroying speed/license plate cameras for years.
Over the last few months, people have cut down surveillance cameras owned by the company Flock Safety with an electric saw in upstate New York, thrown paint on them in Oakland, California, and rammed a truck into them in Idaho. One man in Florida sits in a lawn chair holding up a piece of cardboard on a pole to block the camera’s view. City governments have joined in by deactivating the cameras or canceling contracts with Flock in Fort Collins, Colorado; Eugene, Oregon; Madison, Wisconsin; Knoxville, Tennessee; Syracuse, New York; and Walla Walla, Washington.
Civil disobedience still works, folks. If cops want to keep their Flock cameras, they’re going to have to spend more time surveilling the surveillance devices. We’ll keep paying their overtime and they’ll keep failing to recognize the sublime irony of their actions.
It’s not just about persistent surveillance. It’s that this persistent surveillance directly contributes to law enforcement misconduct by generating a massive set of records that can be accessed by pretty much any officer for no reason at all. Hence, all the stalking. Also hence: feeding federal officers info on migrants even though the feds aren’t legally allowed to access Flock’s systems directly.
But the best indicator that the public tide has turned against Flock isn’t the protests, the abandonment of contracts by several US cities, or even the increasing acts of hostility towards the cameras themselves by pissed off citizens. Instead, it’s this: prosecutors waging a one-sided battle to secure an indictment can’t even get that done. Welcome to the resistance, Cody Morelock — and more importantly, the members of this grand jury.
A Clermont County man, who was facing felony vandalism charges for allegedly destroying a Flock camera in Union Township, had his case dismissed.
Cody Morelock was accused of damaging the camera on Mount Carmel-Tobasco Road near Glenrose Lane on June 13, according to Union Township police.
The government’s prosecutors even had visual evidence of Morelock’s actions:
Police said surveillance footage from other nearby cameras helped identify Morelock as the suspect.
But, at the end of the prosecutorial day, the people (of the grand jury) decided the government didn’t get to ring Morelock up for doing something they apparently didn’t feel was criminal enough to result in an indictment.
A Clermont County grand jury declined to indict Morelock on felony charges.
There’s your jury nullification, I guess. Prosecutors wanted a felony and assumed they had this on lock given the average value of a Flock camera. But they didn’t. Either the grand jury decided the prospective value of the property didn’t support a felony charge, or it simply decided the government wasn’t going to get to punish someone for damaging a Flock camera because… well… pick any of the reasons listed above.
We don’t know for sure what happened here. And there’s a good chance we’ll never find out, given that grand jury records are rarely, if ever, made public. But it does look like the government went hot and heavy with the vandalism charges only to be met with the indifference of regular people who don’t care whether or not Flock cameras are vandalized. And when the government can’t sell its stuff to a captive audience that only gets to hear one side of the story, the government should recognize its actions — ranging from the installation of the cameras to this failed prosecutions — no longer reflect the will of the people and adjust accordingly.
Filed Under: 4th amendment, alpr, location tracking, persistent surveillance, police misconduct, stalking, surveillance state
Companies: flock, flock safety









No comments:
Post a Comment