Normal view
25 Places Designers Can Still Find Free, Non-AI Images for Commercial Use
Chrome Can Now Measure Exactly How Obnoxious Your Website’s Ads Are
Cloudflare Just Gave AI Training Bots the Middle Finger
Today, WordPress Ended a 16-Year Tradition… Meet Ipsum!
Adobe Is Turning Photoshop Elements Into a Much Smarter Photoshop Lite
Figma Is Turning Designers Into Plugin Makers
Building A UX ROI Case That Survives The Boardroom
Sooner or later, a CFO looks at your wireframes and asks what any of it actually does for the bottom line. Storyboards don’t answer that question, and the era when a 5-minute pitch could answer it ended, unfortunately, a while ago.
These days, if you want to win budget, buy-in, and backing for UX, the design has to be provably good for the business, not only for the people using it.
And proving that takes more than taping a dollar sign to a redesign. You have to understand how your organization defines value in the first place, how it measures that value, and how a credible line gets drawn between a design initiative and an outcome leadership already cares about.
Rather than scatter tips, this article follows one worked example the whole way through. Meridian is a mid-size B2B SaaS company, and it is entirely made up — that label matters, so it gets repeated where it counts. Its onboarding redesign carries the same figures from goal-setting through cost accounting, causal testing, and the final ROI number, because a framework only becomes tangible when the numbers connect. Every step is one you can rerun inside your own organization.
Why ROI Matters More Than Ever in UX ConversationsCompanies now want clarity on what every dollar buys, and “delightful user experiences” stopped clearing that bar some time ago. I still remember a former colleague celebrating a $1 million redesign he’d gotten greenlit mostly on the strength of a couple of three.js tricks. Try that pitch in front of a finance team today and see how far the particles get you.
Executives don’t hate UX, they just hate vagueness. A pitch built on “users will find it easier” loses, every time, to the department promising 12% more sales in Q3. The difference is the one between a streamlined checkout flow that reduced cart abandonment with completed purchases up 22%, and the same work rewarded with “the QA testers like it.” One of those goes on your resume. The rest of this article is about earning the first version, with Meridian’s numbers doing the work.
When Business Goals And KPIs Don’t Exist YetMost writing about UX ROI makes a convenient assumption: that the organization already owns clean business goals and KPIs for you to hook your work onto. Real companies are messier than that. Plenty run on ambitions like “grow faster” or “improve the customer journey” that nobody ever broke into anything measurable, and an ROI case built on that ambiguity sounds impressive right up until somebody scrutinizes it.
So the first job is often to help the organization define what success even looks like. Interview stakeholders across departments — what does product consider a good quarter, where does customer success watch users struggle, where do sales deals stall — and listen for the themes that keep resurfacing across conversations, because those recurring themes are the company’s latent business objectives. A useful forcing function is the OKR model (Objectives and Key Results), which doesn’t tolerate vagueness.
At Meridian, the stated ambition was “improve the rate of new users’ adoption of the platform,” which you can neither design toward nor measure against. Interviews turned up the real shape of the problem. Trial users needed a median of 14 days to reach first value, most churned before getting there, and onboarding questions were burying the support queue. Out of that came an OKR with actual edges: reduce median time-to-first-value from 14 days to 7 with the use of a guided setup flow, and lift trial-to-paid conversion from 8% to 9.5%.
One warning about formalizing KPIs: Impose them from inside the UX team and leadership will suspect you’ve rigged the field in your own favor, so co-create them with whoever owns the outcome — though never at the price of accepting targets that set your team up for an uncomfortable situation. Meridian’s head of product agreed that setup-completion rate was a fair proxy for onboarding usability, and customer success signed off on time-to-first-value, a number already sitting on their own dashboard.
A KPI ladder that ends at a metric somebody already watches buys you credibility before any design work starts.Quantifying The Full Cost Of The Investment
ROI has a denominator, and the denominator is where most UX teams go wrong. You can’t calculate a return without strategic financial planning, yet cost usually gets counted as designer salaries or consulting hours and nothing else. A finance team will find the rest whether or not you counted it, so count it first.
Direct costs are the visible ones. Meridian’s redesign ran $45,000 in design and research labor plus another $8,000 in tooling and participant incentives. Licenses for Figma, UserTesting, Hotjar, analytics platforms, research incentive spend — all of it belongs in the total, and that’s before the inevitable instances of vendor lock-in every UX team eventually faces. Engineering sits in the same column, because a UX redesign doesn’t stop at the mockup. Building the guided setup took two frontend sprints plus a QA pass, $38,000 worth, and the project generated about $4,000 of coordination overhead along the way in new syncs and shared dashboards.
The line item nearly everyone misses, and the one worth stealing from this article if you steal nothing else, is stakeholder time. Workshops, design reviews, and feedback sessions all pull senior people away from their primary work. A VP of Product spending four hours a week in UX reviews is a VP not spending those hours on roadmap planning or partner negotiations. Log the attendance — who came, for how long, at what seniority — and price it at fully loaded cost, meaning salary plus benefits divided by productive hours. A quarter’s worth of workshops, reviews, and interviews at Meridian priced out at $22,000.
Add it all up: $45,000 in design labor, $8,000 in tooling, $38,000 in engineering, $22,000 in stakeholder time, $4,000 in coordination. The investment is $117,000. Saying that number out loud beats saying “we spent $45K on design,” precisely because it already includes everything a finance team would have dug up on its own.
Proving Causation, Not Just CorrelationMost UX ROI pitches die right here. Conversions rose after the redesign, sure — and the CFO wants to know how you ruled out the new pricing, the seasonal traffic bump, and the marketing campaign that shipped the same week. Without a convincing answer, your entire ROI story crumbles.
After all these years, the gold standard for proving causation is still A/B testing: run the old experience against the new one on an even traffic split until the sample means something.
Onboarding happens to suit a phased rollout, which is why Meridian could do this cleanly. For eight weeks, half of new trial signups received the redesigned guided setup while half stayed on the legacy flow. Control converted to paid at 8.0%. The variant came in at 9.4%. With roughly 6,100 trials inside the window, the difference was statistically significant, but a 1.4-point gap on a single test is still the kind of result that deserves a second look before anyone builds a budget on it, which is one reason the team held back on attribution below. Where a split isn’t feasible — a change too structural, a user base too small — fall back to a time series instead. Measure steadily for weeks before the change, implement, then keep measuring against the baseline you established.
Documenting whatever else happens around the same time as your UX change is the unglamorous half of causation.
A pricing-page test from Meridian’s marketing team overlapped weeks five through eight of the rollout. The UX team noted it, confirmed it hit both cohorts evenly, and still chose to attribute only 70% of the observed lift to the redesign in the final math. There is no formula that produces that number; treat it as an illustrative assumption for this example.
The team asked how much of the lift could plausibly belong to the pricing test if it had helped one cohort slightly more than the other, settled on a ceiling of about a third, and rounded the redesign’s share down to 70%. Your figure will differ. What matters is that it is written down and argued for before the results arrive, not fitted to them afterwards. That restraint is worth money in a skeptical room. “We attribute roughly 70% of the lift to the onboarding change, with the remainder likely influenced by concurrent pricing work” survives cross-examination; claiming everything does not. Cohort analysis then backed the number up, since the lift held across acquisition channels and tenure bands, and at that point the skeptics had very little left to work with.
Leading and lagging indicators belong on the same slide, because each covers the other’s weakness. Meridian’s leading indicators moved first — setup completion climbed from 62% to 89%, median time-to-first-value dropped from 14 days to 6.5 — and the lagging trial-to-paid number followed. Mechanism first, business outcome second. Presented together, they form a causal chain that’s harder to poke holes in than either one alone.
The ROI Calculation, End to EndSo what did Meridian actually earn? The company sees about 40,000 trial signups a year. Lifting conversion from 8.0% to 9.4% adds roughly 560 paying customers annually, and at an average of $1,800 in annual recurring revenue per account, those customers represent about $1,008,000 in new ARR. Applying the conservative 70% attribution from the causal work trims the defensible figure to roughly $706,000.
Set that against the full $117,000 investment and the first-year ROI lands near 5:1, with payback arriving in roughly two months. There’s a second line, too. Onboarding-related support tickets dropped about 30%, some 3,600 fewer tickets a year, worth another $54,000 annually at $15 per resolved ticket. Keep it as its own line rather than folding it into one swollen headline number. The case reads as more honest that way and loses none of its force.
Three assumptions carry that result, and each belongs on the slide next to it. The 40,000 signups and the $1,800 average ARR are the prior year’s actuals held flat, so a growth or pricing change moves the outcome in either direction. The 70% attribution is the illustrative assumption from the causal work, not a measured quantity. And the two-month payback counts new ARR as it lands rather than revenue recognized net of churn, which flatters the timeline; on a net basis the payback stretches to roughly a quarter. State those three plainly and a finance team can adapt the example to its own numbers. Hide them and the whole thing starts to look like marketing math, however careful the experiment was.
What persuades in the final presentation is not sophistication. Open with the baseline: what stalled trials and support volume were already costing. Show the delta in terms leadership reads fluently, metrics like conversion rate uplift chief among them. A chart of setup completion climbing from 62% to 89% will beat a paragraph of UX jargon, and a translation like “each abandoned setup costs us 0.3 support tickets” beats the chart. Above all, keep every figure identical from the first slide to the last. A room full of finance people forgives many things, but never numbers that wobble between slides.
Tailoring The Case To Whoever Holds The Purse StringsBudget decisions come out of coalitions. A CFO may hold the final say when adding AI to the checkout process, but marketing, product, and customer success all lean on that decision, and each means something different by “value.”
A CFO hears cost, revenue, and risk. A CMO hears conversion and acquisition cost, since UX is a lever for increasing marketing ROI. Product counts support tickets; customer success thinks in retention. The underlying numbers never change; only the framing rotates, and a CFO wants a projection, not a moodboard. Meridian’s CFO slide read “the onboarding redesign protects roughly $706,000 in new ARR a year against a $117,000 investment,” while the CMO version led with what a 9.4% trial conversion does to blended acquisition cost.
Beyond the Dollar Sign: Qualitative and Non-Financial MetricsSome UX outcomes never translate cleanly into revenue, and pretending they do weakens the parts of your case that are solid.
The trick with qualitative evidence is collecting it rigorously enough that nobody can wave it off as anecdote.
Scores like Net Promoter Score (NPS), CSAT, and Customer Effort Score already sit inside most reporting cadences, which makes them cheap to borrow. Tie your work to their movement, and segment wherever the data allows.
Meridian could say that NPS among trial users on the redesigned onboarding was 51 against 34 for the legacy flow, which lands far harder than any blended average. Verbatim feedback from surveys, support transcripts, and app store reviews adds the emotional weight the scores lack. Internal tools deserve the same discipline, since employee experience is increasingly recognized as a business driver — a dashboard redesign that hands account managers 45 minutes a day back is a productivity gain, a satisfaction gain, and a retention lever all in one.
Brand perception resists direct measurement but leaves tracks in repeat visits, organic referrals, and social sentiment. It carries extra weight in trust-sensitive industries like finance or healthcare, and it forms fast, given that UX design influences the first impressions of a whopping 94% of customers.
Whatever you collect, systematize the collecting. Run pre- and post-surveys with consistent question sets, use structured usability testing with task-based scoring, and put the qualitative right next to the quantitative when you present.
“Setup completion rose from 62% to 89%, and in post-test interviews 8 of 10 participants called the new flow intuitive, against 3 of 10 for the old one” — a pairing like that is much harder to dismiss than either half on its own.Making the Case Stick
UX loses the budget battle unless it’s mapped to company-wide objectives, so phrase the proposal in the words of this year’s board presentation.
Nobody at Meridian pitched “simplify the onboarding UI”; the pitch was a redesigned trial experience worth 1.4 points of upgrade rate, roughly $1M in annual recurring revenue before attribution. Bring evidence in both registers, since that is what social proof is for: the case, clearly labeled, plus screenshots, impact graphs, and user quotes. Find internal allies who can repeat the ROI narrative in rooms you’ll never enter, and write the playbook down, because repeatable ROI is what earns recurring investment.
Resources for Going DeeperThis topic has been explored extensively by researchers, practitioners, and consultancies. Here’s a curated set of resources worth studying if you want to build a stronger ROI practice around UX.
- “Measuring the User Experience” by Tom Tullis and Bill Albert is the definitive guide to UX metrics. It covers everything from task-based measurements to survey design to statistical analysis, and it’s written for practitioners, not academics.
- Jared Spool’s “The $300 Million Button” case study is a classic example of how a single UX change (removing a mandatory registration step) generated massive revenue uplift. It’s a story every UX professional should have in their back pocket.
- Forrester’s research on UX ROI provides enterprise-focused frameworks for building business cases around experience design, including their widely cited finding that every dollar invested in UX returns $100.
- “UX Strategy” by Jaime Levy bridges the gap between design thinking and business strategy, offering practical tools for aligning UX initiatives with organizational goals and market positioning.
- The Design Value Index by the Design Management Institute tracks publicly traded companies that invest heavily in design against the S&P 500. The data consistently shows that design-led companies outperform the index by significant margins, and it’s a powerful data point for executive presentations.
- Google’s HEART framework provides a structured approach to selecting UX metrics at scale. HEART stands for Happiness, Engagement, Adoption, Retention, and Task success, and it’s particularly useful for teams that struggle to decide which metrics to track.
A seat at the table never comes from beauty or novelty. It comes from measurable, defensible impact, which means UX leaders have to trade the artist’s posture for the strategist’s. Speak in outcomes rather than outputs. Connect pixels to profit.
When someone challenges the numbers, don’t flinch. Show the controlled experiment, the cohort analysis, and the before-and-after metrics, every figure holding steady from the first slide to the last, the way Meridian’s did, with the customer quotes and the employee-satisfaction data sitting right beside the revenue impact. Prove the work does more than delight users, and be ready to defend the ratio line by line. That’s when the CFO leans in, and that’s when design stops being optional.

TikTok Is Quietly Putting Web Apps Inside Its App
Firefox Is Getting Its Biggest Redesign in Years. Then Mozilla Got Cold Feet.
Adobe Has a Secret New Design Tool—and You Can Apply to Test It
-
Webdesigner Depot
- The Ampersand Is Nearly 2,000 Years Old — And Designers Still Can’t Agree How It Should Look
The Ampersand Is Nearly 2,000 Years Old — And Designers Still Can’t Agree How It Should Look
Canva Is Quietly Publishing Nearly 1 Million Websites a Month
Volcanoes that made history
The first telegram arrived in Singapore on a Monday, sent from the city of Batavia in the Dutch East Indies (now Jakarta, Indonesia). “Terrific detonations from Krakatau (volcanic island),” it reported. Soon afterward: “Stones falling. Village near Anjer washed away.” The wires continued clattering out news of bridges destroyed, boats smashed, lighthouses “disappeared.” By noon on Tuesday, the scope of the natural disaster was clear: “Where once Mount Krakatau stood the sea now plays.”
Within days, the source of the destruction was known worldwide. On the morning of August 27, 1883, a volcanic eruption had obliterated two islands in the strait between Java and Sumatra, and most of a third. More than 36,000 people perished, the majority in devastating tsunamis that raced outward from the colossal explosion.
Thanks to Victorian-era telecommunications, it was the first time in history that people around the globe could begin to document, in near real time, the immediate and long-term effects of a catastrophic volcanic eruption. What they learned over the next few years laid the foundations for the modern science of volcanology. And it was an especially eye-opening lesson in how the biggest eruptions can influence climate, agriculture, and even the course of human history.


© FERDI AWED/AFP via Getty Images
-
Webdesigner Depot
- The Ghost Site Resurrector: How Junior Designers Can Turn Digital Abandonment into Cash
The Ghost Site Resurrector: How Junior Designers Can Turn Digital Abandonment into Cash
Building Tactile UX: Honoring Intentional Design With Lottie
This article is a sponsored by Isadora Agency
When front-end developers and UX engineers are tasked with building a web interface that feels tactile, bouncy, or destructive, the industry instinct is almost always the same: reach for a physics engine. Frameworks like Matter.js, Cannon.js, or custom WebGL solutions have become the gold standard for creating immersive, gamified websites.
When our team at Isadora Agency set out to build Stress Release, a digital stress-relief squeeze toy designed to let burnt-out creatives smash, stretch, and distort animated UI characters, we initially explored that route. The goal was to build a highly tactile experience where every click yielded a satisfying, squishy reaction.
But as we began prototyping, we realized something crucial: Physics engines produce plausible motion, but in our case, the animators produced intentional motion.
We didn’t need our characters to act like realistic rubber balls bouncing uncontrollably around a canvas. We needed them to react in very specific, highly designed ways. So, we scrapped the physics engine entirely.
In this article, we’ll break down how we built a real-time stress-relief squeeze toy without a single line of WebGL or Matter.js, relying entirely on programmatic Lottie state controls, DOM manipulation, and distance-based math.
![]()
Our core requirement for Stress Release was absolute deterministic control. Our animators had crafted bespoke .json Lottie files that required exact, frame-by-frame sequencing.
For instance, our ‘mega squeeze’ reaction required a precise 181-frame build-up followed by a specific release sequence. To honor this design, we needed an architecture that wouldn’t overwrite the animators’ crafted keyframes with algorithmic approximations.
The tighter the click-feedback loop (click → squish → score), the more you need deterministic frame control. By choosing programmatic state control using Lottie’s native API, we ensured that the interaction layer acted as a flawless trigger for the animation layer.
![]()
Because our architecture relied on Lottie and the standard DOM, rendering is handled directly by the Lottie runtime, which plays the JSON-based vector animations as SVGs internally. We selected elements directly by ID and CSS class, driving their behavior using a combination of Lottie animation segments, CSS transforms, and click-event math.
To achieve a deeply satisfying “tactile feel” upon hitting a character, we used radial input mapping. The first step was converting the click from page coordinates into the character’s local coordinate space.
Every click was measured against the character’s center point, then translated into score, feedback intensity, and explosion placement:
// Character's center point in its own coordinate space
var x_center = parseFloat($("#playChar").width() / 2);
var y_center = parseFloat($("#playChar").height() / 2);
// Click position relative to the character's top-left corner
var offset = $("#playChar").offset(); // document-relative position
var X = parseFloat(e.pageX - offset.left);
var Y = parseFloat(e.pageY - offset.top);
// Vector from center to click point
var a = parseFloat(X - x_center);
var b = parseFloat(Y - y_center);
Then we calculate the straight-line distance from the center of the click using the Pythagorean theorem:
var distance = Math.hypot(a, b);
That single number drives everything: the score, the feedback intensity, and where the explosion animation appears:
// Distance zones map to point rewards
if (distance < 10) givePts = 100; // bullseye
else if (distance < 40) givePts = getRndInteger(70, 90);
else if (distance < 70) givePts = getRndInteger(40, 70);
else if (distance < 100) givePts = getRndInteger(20, 40);
else if (distance < 120) givePts = getRndInteger(10, 20);
else if (distance < 145) givePts = getRndInteger(1, 10);
else givePts = 0; // miss
// Explosion Lottie repositioned to the exact click point
var shiftPosition = window.innerWidth < 1023 ? -20 : 200;
$("#explosionChar").css({
"margin-left": a + shiftPosition + "px",
"margin-top": b + shiftPosition + "px",
});
// Fire the squish animation instantly
explosion.goToAndPlay(0);
The result is a concentric zone system — a perfect circle of scoring rings around the character’s center, similar to a dartboard. The visual complexity of the Lottie SVG is completely irrelevant to hit detection; the hitbox is always a clean circle. Critically, the explosion Lottie animation is repositioned to (a, b) — the same vector used for scoring, so it always appears exactly where the player clicked. This spatial accuracy creates the tactile “I hit that” sensation entirely through math and DOM positioning.
![]()
Because the experience used DOM-managed SVG elements, desktop clicks and mobile taps could be handled directly through native event listeners. This avoided extra raycasting or coordinate remapping layers, while keeping the interaction model aligned with how the animations were rendered.
Since the game requires a visual reaction at a specific point, Lottie handles all the squish and bounce feelings internally through its animation curves. Each character has a defined set of animation sections (idle loops, reaction frames, and end states) stored as frame ranges. When a click lands, we jump directly to the exact segment that matches the current game state:
// Animation sections defined as frame ranges per character
const play_segments = [{
charId: 0,
sections: {
idle: [0, 40], // looping idle state
squeeze1: [41, 80], // light reaction
squeeze2: [81, 120], // medium reaction
squeeze3: [121, 160], // heavy reaction
},
playOrder: ["squeeze1", "squeeze2", "squeeze3"],
endAnimation: [161, 200]
}];
On every click, we advance through the play order and fire the next segment:
function stepAnim() {
let p = play_segments[0];
let i = p["playOrder"][curr_order_play];
let playNow = p["sections"][i];
playChar.stop(); // halt current segment immediately
playChar.loop = false; // no looping - play once and stop
playChar.playSegments(playNow, true); // jump to exact frames, force immediately
curr_order_play++;
canPlayAnim = 0; // lock out further clicks mid-animation
if (curr_order_play > p["playOrder"].length - 1) {
curr_order_play = 0; // cycle back to start of sequence
}
}
When the segment completes, control returns to the idle loop:
playChar.onComplete = function() {
canPlayAnim = 1; // unlock clicks again
if (!playEnd) playIdleState();
};
function playIdleState() {
playChar.playSegments([0, 40], true); // return to idle loop
playChar.loop = true;
}
![]()
And for the mega squeeze build-up, the bar loops on a specific frame range until triggered:
// Loop the "ready to release" frames until player activates
indikL.loop = true;
indikL.playSegments([181, 302], true);
// On activation - play the release sequence once
indikL.loop = false;
indikL.playSegments([96, 396], true);
indikL.goToAndStop(0, true); // hard reset after completion
The Responsive Benefit Of DOM Elements
Another major factor in our architectural decision was responsive behavior. Because we built Stress Release in the DOM, we bypassed the complexities of scaling bounding boxes and collision vectors across different devices.
We handled responsive resizing entirely through CSS variables. By recalculating CSS custom properties on every resize, the layout simply reacts to the updated variables, and the Lottie SVGs scale naturally inside their containers without losing their state:
const appHeight = () => {
const doc = document.documentElement;
doc.style.setProperty("--doc-height", `${window.innerHeight}px`);
doc.style.setProperty("--doc-width", `${doc.clientWidth}px`);
};
window.addEventListener("resize", appHeight);
appHeight(); // run immediately on init
Mobile Performance Optimization: The Cost Of Lottie
While this architecture gave us total control over the art direction, it introduced a different challenge: file size.
Lottie JSON files can be heavy. We had 21 different character animations, plus multiple explosion variants that all needed to load. To ensure the experience remained fluid — especially on mobile devices — we implemented a few aggressive optimization strategies:
- Connection monitoring
We tracked initial asset load time usingperformance.now()to detect slow connections and flag when load times exceeded 5 seconds. - Sequential asset loading
Rather than initialising all 21 character animations simultaneously, we load them in pairs using await, advancing only when each pair completes. This prevents a burst of simultaneous network requests and render work from blocking the browser on low-end devices. - Aggressive memory management
Instead of keeping our heavy explosion animations in memory, we destroy and recreate them on the fly. This trades a tiny instantiation cost for a much lower idle memory footprint. - Dynamic quality reduction
Quality reduction is a single API call applied immediately after each shelf character loads. The key is applying different quality levels depending on the character’s role in the scene:
// Shelf screen - 21 animations playing simultaneously
shelf = lottie.loadAnimation({
container: document.getElementById("charShelf" + i),
renderer: "svg",
loop: true,
autoplay: true,
path: "assets/shelf/" + shelfFolders[i] + "/" + shelfFolders[i] + ".json",
});
lottie.setQuality(0.5); // 50% quality - reduces interpolation calculations
shelf.setSpeed(0.6); // 60% speed - fewer frame calculations per second
// Play screen - single focused character
playChar = lottie.loadAnimation({
container: document.getElementById("playChar"),
renderer: "svg",
loop: true,
autoplay: true,
path: chosenChar.url,
});
lottie.setQuality(1); // full quality - only one animation at a time
When determining the stack for a gamified web experience, it is critical to let the design requirements dictate the technology.
![]()
Because our interactions required bespoke, highly controlled visual reactions, we opted for programmatic state control over emergent simulation. This decision empowered the animators to dictate the exact feel of the experience, leaving the code to do what it does best: listen, calculate, and trigger.
By mapping Lottie’s native timeline capabilities to the DOM, you can deliver incredibly rich, tactile user experiences while maintaining absolute control over the art direction.
Further Resources
Want to try implementing this yourself, or see exactly how it feels in the browser? Check out these resources:
- Play with the code.
We have prepared a simplified demo example on CodePen demonstrating a character reacting to a click usingplaySegments(). - See the final product.
Check out the live Stress Release site to see all 21 characters and the optimization strategies in action. - Read the docs.
Explore the official Lottie Web documentation to learn more about the player controls we utilized. Specifically, exploreloadAnimation(),playSegments(),setSpeed(), andsetQuality()— the four methods that power the entire interaction layer described in this article.

Why Your Favorite Websites Look Like 2005 (And Why You Secretly Love It)
Why Would Anyone Trust Ex-CIA Agents in Elected Office?
The Democratic Party is rife with internal caucuses and factions. There’s the Congressional Progressive Caucus, the Congressional Black Caucus, the Blue Dog Coalition, the “Squad,” and so on. But since 2019, when Elissa Slotkin and Abigail Spanberger first took seats in the House of Representatives, the party has had another, more sinister emerging faction: the CIA Spook Caucus.
In the last seven years, the Spook Caucus has only gained in strength. Both of its core members have graduated from the House to higher office, with Slotkin elected to the Senate in 2024 and Spanberger elected the governor of Virginia the following year. Soon afterward, Spanberger was selected by the Democratic leadership to deliver the rebuttal to Donald Trump’s 2026 State of the Union Address, which elevated her to the national stage. Slotkin, meanwhile, has floated the idea of a 2028 presidential run.
And in the 2026 midterms, the Spook Caucus might expand further: In the Democratic primary for Virginia’s 8th Congressional District, former CIA officer Adam Dunigan is running for the opportunity to challenge GOP nominee Anthony Sabio, who is also ex-CIA. But if you happen to care about concepts like “human rights” or “democracy,” this influx of intelligence operatives into our elections is extremely bad news.
Spanberger’s honeymoon period with the Virginia Democrats is already over. Less than a year into her tenure as governor, she has vetoed 31 of the General Assembly’s bills, including “high-profile Democratic priorities” like collective bargaining rights for public workers and protections against ICE agents making warrantless arrests inside courthouses. On the labor bill, local unions say Spanberger betrayed a campaign promise she’d made to them. After vetoing two bills to limit ICE arrests, the ACLU of Virginia said her actions “constitute a voluntary surrender” to the Trump administration’s immigration agenda.
But this about-face shouldn’t be surprising, because the public doesn’t really know who Abigail Spanberger is or what she believes, deep down. That’s the problem with electing a CIA officer: They’re professionally trained liars. In a 2025 interview with the Washington Post, Spanberger said she used to have five different passports and identities: “I would travel in ‘true name,’ but then I would meet people not in ‘true name.’” The profile explicitly calls this spycraft “interpersonal skills transferable to politics.” In other words, this is someone who was accustomed to saying whatever people want to hear while concealing her true intentions. So whenever she speaks to Virginia voters, they have no way of telling whether she’s “in true name” or not. The unions found that out the hard way.
As usual, then, we have to judge by actions over words. With this spring’s veto spree, Spanberger’s actions are wildly out of step with the wishes of the voters who elected her, who overwhelmingly support unions and are growing more distrustful of Immigration and Customs Enforcement. (Seeing your fellow Americans shot dead in the street will do that.) But the vetoes are perfectly in tune with the interests of the national security state, from the drug enforcement agents who still want to make weed busts to ICE itself. Those are Spanberger’s colleagues, and the former CIA agent has moved to protect their power to surveil and police the people she supposedly represents.
Instead, she’s reserved her harshest attacks for socialists. In 2020, after Joe Biden squeaked his way into the presidency, Spanberger told party leaders, “We need to not ever use the word ‘socialist’ or ‘socialism’ ever again,” a clear shot at rising left-wing leaders like Bernie Sanders and Alexandria Ocasio-Cortez. It was an intervention in the ongoing conflict over the future of the Democratic Party, intended to prevent it from ever becoming a truly progressive one — as the Bezos-owned Washington Post also noted with approval.
Hostility to socialists is baked into the institutional culture of the CIA. It’s practically the agency’s reason for existing, and over the course of the 20th century, the CIA and its handpicked dictators massacred countless socialists around the world, from overthrowing President Salvador Allende in Chile, to sponsoring terrorist attacks against Cuba, to the mass slaughter of Indonesian communists via the “Jakarta Method.” Today, though, Spanberger’s anti-socialist stance is directly at odds with the will of Democratic voters, who now approve of socialism at a higher rate (66 percent) than capitalism (42 percent).
What about Slotkin, who now says she won’t rule out a run for president? Like Spanberger, her track record with the CIA is a black box. On her official biography webpages, we’re told only that she chose to join the agency shortly after 9/11, and served “three tours in Iraq alongside the U.S. military” as a “Middle East analyst.” In a 2020 interview with the New Yorker’s Isaac Chotiner, she volunteered that she was specifically an “Iraqi Shia-militia expert.” After that, it was on to a role as a national security adviser for both the late Bush and early Obama administrations, a few years as an acting assistant secretary of defense, and then the House and Senate.
This raises some nasty questions. Exactly what information was Slotkin “analyzing” in Iraq, and how was it obtained? We know that one of the primary ways the CIA gathered “intelligence” about “Iraqi Shia militias” was by grabbing and torturing people it suspected of being militants at black site prisons like Abu Ghraib. We know, too, that only a small fraction of those people actually had anything to do with terrorism. So it’s plausible that at least some of Slotkin’s “analysis” was based on the supposed “intelligence” gleaned when you subject a random Iraqi farmer to waterboarding, stress positions, or “rectal rehydration.”
Worse, Slotkin graduated to an adviser to the Bush/Cheney administration in its last days. In that role, she might have known about some of the CIA’s abuses before the infamous “torture memos” came out in 2009. She might have had the opportunity to blow the whistle. It feels highly unlikely that we’ll ever know for sure.
The CIA and the broader “intelligence community” needs global conflict, in the same way that cops need crime, priests need sin, and the Orkin man needs termites.
Slotkin’s more recent statements about the Middle East don’t exactly inspire confidence, either. Like many liberals, she’s willing to criticize the GOP’s war-mongering, but only on tactical grounds, not basic moral principle. For instance, she has said the Bush administration “completely misread how difficult it would be to try and be the government for another country.” Similarly, she told Chotiner that Trump’s 2020 assassination of Gen. Qassem Soleimani might be unwise and provoke a “strong reaction.”
What she doesn’t say is that invading other people’s countries and killing their leaders, and then trying to “be the government,” is inherently illegitimate and criminal. But she can’t, not really, because having worked for the CIA, she’d be condemning her co-workers — and her own record of service.
We can see the same pattern play out with more recent cases of U.S. aggression. When the Trump administration attacked Iran and Venezuela earlier this year, Slotkin moved in lockstep with the majority of the Democratic Party, voting for war powers resolutions against hostilities with both countries. (This, to her credit, makes her more reliable than John Fetterman, who has voted to preserve Trump’s power to attack Iran on multiple occasions.)
But her public statements tell another story. When the Trump administration made a request for $50 billion in additional funding for the Iran war, Slotkin was open to the idea, telling Politico reporters only that “I need to know the goals and the plan. … I don’t rule anything out.” And when Trump deposed and kidnapped Nicolás Maduro, she criticized him for working with Vice President Delcy Rodríguez’s “illegitimate government” rather than following through on his promise to “[get] rid of that administration” entirely. Again, there’s no indication that waging regime-change wars is wrong in itself; only that Trump had bungled the job by not going far enough.
China, though, is Slotkin’s biggest bête noire. Like a lot of centrists who have taken the wrong lessons from the election of New York City Mayor Zohran Mamdani, Slotkin has taken to making short-form video content. She calls these videos her weekly “Intel Briefings,” and they’re skin-crawling to watch, like something you’d see on a TV in the background of a Paul Verhoeven movie.
Beating the drum for conflict with China is a constant theme. In one representative “briefing,” Slotkin tells viewers about “an issue that a lot of Michiganders know about: China and the threats that they pose.” (The “threat” turns out to be that China may buy computer chips from Nvidia, which is apparently “the equivalent of President Truman giving Russia some of our best nuclear blueprints.”) In another video, she condemns Trump for putting out a national security strategy that fails to “go hard against China.”
It’s all like this. We’re told that China has a worrying “chokehold” on the supply of “critical minerals” like lithium and cobalt; China “often undercuts our ability to sell our products,” so we need to “clamp down on what the Chinese are doing in international trade”; Chinese military technology could “make us go blind, deaf, and dumb in the first moments of a conflict,” perhaps over Taiwan; Chinese cars in particular are a “national security issue” that can’t be allowed to enter the country.
The tone is always slightly condescending: At one point, Slotkin tells us about “the leader of China, Xi Jinping,” as if we’ve never heard of the guy before. The content is pure paranoia, with a new Cold War accepted as a normal and even desirable state of affairs.
To be clear, the American people do not want conflict with China. In the most recent Pew polls from April, only 28 percent of respondents said they considered China an “enemy,” and China’s favorable ratings have been rising since 2023.
But the CIA and the broader “intelligence community” needs global conflict, in the same way that cops need crime, priests need sin, and the Orkin man needs termites. It justifies their existence, and their mammoth, ever-increasing annual budgets. So every week on YouTube, we get a former CIA agent pushing what’s good for the CIA and bad for everyone else.
More basic than any of this, though, is that the concept of “the intelligence community” is elitist to the core. Its first principle is that the American public, unwashed reprobates that we are, aren’t even qualified to know about the most important decisions being made in terms of foreign policy, let alone influence them at the ballot box. Only the “intelligence community” with its experts and analysts should do that, and always behind several layers of official secrecy. It’s a fundamentally anti-democratic notion, and it comes from a set of agencies which have overthrown a long list of democracies over the years. So there’s no reason to expect they’d respect our democratic choices at home, either. If you’re the Democratic Party, you can’t really position yourself as champions of “our democracy” and also embrace the CIA Spook Caucus as an unalloyed good.
As the maxim goes, “The purpose of a system is what it does.” To that end, the purpose of the CIA is to lie, manipulate, torture, and kill, all to preserve the existing global power structures, not to mention the agency’s own power and prestige. That’s what it does; that’s what it’s for. There’s no way anybody, anywhere should trust a former CIA officer within 100 miles of elected office. Personally, I’d vote for a Satanist or my local weed dealer before any member of the “intelligence community.” We should look at would-be Democratic politicians like Slotkin, Spanberger, and now Dunigan with the same horror as if Allen Dulles had run for Congress as a Democrat in 1965. Under no circumstances should we trust these people — and if we offer them our votes, we do so at our own peril.
The post Why Would Anyone Trust Ex-CIA Agents in Elected Office? appeared first on The Intercept.



Primed for Malware: Stop Selling Compromised Android Devices
Time and time again, researchers have found numerous compromised Android devices for sale at large online retailers like Amazon. When these devices get individually reported, we have seen some noted efforts to take them down. But this is a systemic problem and Amazon and other major online retailers must make a corresponding systemic and intentional effort to stop these devices from entering people’s homes and ultimately their networks.
As a refresher: Last year, Google wrote that one major campaign, deemed BADBOX, affected 10 million uncertified devices that were running Android’s open-source software (Android Open Source Project or AOSP). These devices span from TVs and streaming devices to digital picture frames. Even now, someone can go on Amazon and Walmart and buy one of these devices. Not all of them come from Amazon and Walmart, but it’s fair to assume since they have the lion’s share of the market.
Most well-known Android-based devices don’t come with just “stock Android.” The operating system is usually Android plus additional features that the manufacturer wanted. These custom versions of Android often come with pre-installed applications that range from useful to innocuous bloatware to actual malware. Many Android OEMs (original equipment manufacturers) pre-install apps that may not be visibly represented by an icon in your list of installed apps. This obscurity makes the issue particularly hard for users to identify any potential threats.
Since the initial BADBOX analysis, there have been more reports of large campaigns and clusters of different devices participating in malicious activities that utilize people’s home networks to engage in illegal activity. Task forces in the private sector have made an effort to take down these existing Command and Control structures, but these actors may pivot and evolve to flood the market with more devices.
Online retailers can stop this cycle. A multi-billion dollar company like Amazon should offer more resources, like their anti-fraud efforts, given that these products may have facilitated conditions for large scale attacks and illegal activity. It would also be helpful if they communicated malware-related take downs in a more visible way to consumers who are seeking very similar devices with shared characteristics.
Identifying these devices can be tricky, but it’s not impossible because they tend to follow a pattern. For example, the FBI warned consumers this year to avoid TV streaming devices that claim to provide free sports, tv shows, and movies, a common tactic used by the makers of these malware-filled Android devices that leverages people’s exhaustion from spending money on countless streaming services. We detailed what sorts of indicators to look for on a device you’ve purchased.
But it’s not just the storefronts. There are other parts of this ecosystem that need to improve too, like increased engagement in firmware transparency and the actual manufacturers of the devices themselves being held accountable for these malware laced products.
On Prime Day, we urge retailers like Amazon to better empower users with information they need to make safe and smart decisions.
