Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

An undercover Google analyst infiltrated a notorious supply-chain hacking gang

Before two of its alleged members were arrested and charged in Australia last month, the hacker group known as TeamPCP carried out a hacking spree unlike any other in history. It tainted hundreds of open-source programs with its malware, stole developer accounts to perpetuate that software supply-chain hacking, and even released a Dune-themed self-spreading worm to automate the process, ultimately breaching more than a thousand companies.

Now Google’s threat intelligence group has revealed that during a key moment of TeamPCP’s rampage, the company’s own undercover researcher had infiltrated the group—allowing Google to monitor the hacking spree from the inside, warn breach targets, and even help disrupt the group’s attempts to exploit those victims.

In a talk at security firm SentinelOne's LABScon research conference today, Google Threat Intelligence Group researcher Austin Larsen will present details on the company’s investigation—and infiltration—of TeamPCP amidst the group’s unprecedented, chaotic supply-chain hacking campaign. According to Larsen, Google eventually followed a trail of operational security mistakes allegedly made by one of the two Australians now accused of being leading members of the hacker group and passed on key identifying details to law enforcement. The company also received intelligence from ShinyHunters, another infamous cybercriminal group that TeamPCP partnered with, but which later turned on the supply-chain hackers. And perhaps most surprisingly, Larsen says that Google’s security subsidiary Mandiant had an undercover analyst—not himself—within the group’s inner circle from almost the beginning of TeamPCP’s time in the spotlight.

Read full article

Comments

© Douglas Rissing via Getty Images

Researchers used Claude to hack OpenAI

Cyber researchers broke into OpenAI using its key rival Anthropic’s software, highlighting vulnerabilities in the ChatGPT maker’s security as leading AI companies face mounting scrutiny over safety.

A small cyber security group gained access to an OpenAI employee’s ChatGPT account, which permitted them to read private software information and suggest changes.

The researchers had been given access to an Anthropic tool specifically designed for security professionals, and were paid for the work as part of a program to find vulnerabilities before they could be exploited by bad actors.

Read full article

Comments

© Leon Neal/Getty Images

Republican bill would order ISPs, DNS providers, and VPNs to block piracy sites

17 September 2026 at 19:07

US Rep. Darrell Issa (R-Calif.) has proposed a law that would require Internet service providers and other network operators to block foreign piracy websites. Issa's bill would help copyright holders obtain judicial blocking orders to be served to ISPs, domain name resolution services, and virtual private networks.

Issa, who is retiring from the House at the end of this year, is the latest in a string of Republican and Democratic lawmakers to propose a site-blocking regime that's been sought by the Motion Picture Association (MPA). He submitted the bill this week, after indicating in a June 30 hearing that he planned to introduce site-blocking legislation.

"While millions of listings for copyright-infringing content are removed every day under [the] notice-and-takedown process set forth in the Digital Millennium Copyright Act, right-holders have raised concerns with the speed," Issa said at the hearing. Issa asked, "Can we do it at the speed of sound? Can we do it at the speed of light? More importantly, in a 45-minute or sometimes a fraction of that live sports broadcast, can we do it soon enough to make it no longer profitable for those who pop up and sell their clandestine wares?"

Read full article

Comments

© Getty Images | Yuichiro Chino

LLMs respond differently to harmful prompts when AI watermarking is used

17 September 2026 at 18:33

In response to a new European Union law, AI platforms are implementing new schemes for watermarking the content they generate. Anthropic recently disclosed its future Claude models will use SynthID-Text, an approach Google created and released as open source. It uses a secret key that subtly changes the process a model uses for choosing the next word in a sentence. Whereas a top next word choice might be “cloudy,” the key might change it to “overcast.” Anyone who knows the key can determine if it was generated by the platform using it.

New research shows that SynthID-Text can change not just word selection but also the tools a model invokes and the chances it will adhere to or disregard safety guardrails it has been trained to follow. The threat can become greater in the face of an adversarial prompt, in which an attacker attempts to cause a model to carry out a harmful action, such as revealing a password or other sensitive information. Instructions that normally wouldn’t be followed will, in some cases, be performed once the watermarking is deployed. The finding underscores the need for developers to thoroughly test how their LLMs and agents behave when watermarking is in place.

Changing safety behavior

“As compared to the same models without watermarking, it is definitely going to change their behavior, especially when we place it under adversarial conditions, or we make these models call tools when they’re powering an agent,” Andrea Siposova, an AI security researcher at Lasso Security, told Ars. “Watermarking is made to not be perceptible to a reader, but we know that when we are changing anything about what the model is generating, it is going to cause some tradeoffs, it’s going to show up somewhere.”

Read full article

Comments

© Getty Images

Hackers reveal how Flock cameras really track cars and people

Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them.

The breach provides an unprecedented look inside a system that Flock has described as protected by on-device encryption. The hackers were able to copy the camera’s storage and recover an encryption key stored on the device, which unlocked videos of thousands of vehicle detections. The hackers shared the material with 404 Media and the transparency nonprofit Distributed Denial of Secrets, which shared the data with WIRED. 404 Media and WIRED then analyzed those files as part of a joint investigation.

While much of the automatic license plate reader’s most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag.

Read full article

Comments

© Getty Images | Smith Collection/Gado

Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack

16 September 2026 at 21:08

The International Meteor Organization, the nonprofit that coordinates and publishes amateur and professional observations of meteor phenomena, said its infrastructure has suffered a “critical blow” from a cyberattack.

“We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline," a static page on its website on Wednesday said. “We expect several weeks of partial downtime as we transition to new infrastructure and services.”

“I am very sad to see the site down”

In the meantime, the IMO said it’s prioritizing the reporting of fireball observations, which can be reported here. The organization is also providing some information on its Facebook page.

Read full article

Comments

© Interntional Meteor Organization

The King Is Watching devs are making The Crab is Walking, this journalist is writing

14 September 2026 at 20:00

The King Is Watching developers Hypnohead have announced The Crab Is Walking, a roguelite city-builder in which you alternate between arranging tetromino-shaped city districts on the back of a colossal crustacean, and sending out armies of Mad Maxalots to slaughter wasteland insects. Unlike in The King Is Watching, you do not have to actively train your gaze on your crab metropolis to stop it slacking off.

Read more

The Case for Less Eye Contact

11 September 2026 at 10:25

The Case for Less Eye Contact

We’ve made the case before that the mainstream advice about eye contact and psychological safety is highly western-centric and neurotypical, and lacks context and nuance. Not only does it get causation backwards, but in reality, advising people to make more eye contact in order to foster greater psychological safety is potentially harmful and exclusionary. 

So here, I thought it’d be interesting to explore a completely different angle on eye contact. What if we could foster greater psychological safety by intentionally reducing eye contact?

Three shapes of conversation

Most conversations at work take one of three physical shapes, each a different geometry of interaction. We can (1) face each other; we can (2) sit or walk side by side, oriented in the same direction; or (3) we can triangulate, all facing a third thing (a whiteboard, a screen, the thing we’re working on). Most psychological safety advice assumes the first is the ideal and the other two are somewhat lesser, degraded forms: that a “real” conversation only happens facing each other, maintaining eye contact, with full and intense focus on the person we are in conversation with. A lot of evidence suggests the truth could be the opposite, especially for difficult or intimate conversations.

Eye contact theory

First some theoretical background, because surely all the research is in favour of lots of eye contact? Not exactly. In 1965 Argyle & Dean proposed in Sociometry that intimacy is jointly regulated across gaze, physical proximity, and topic intimacy: i.e. we only have a limited capacity bucket that needs to hold all these things. So by reducing gaze, we can provide more space for topic intimacy. When we intentionally reduce eye contact, it means we can have more intimate, potentially more challenging, conversations. It’s a 60-year-old theory that mainstream eye-contact evangelism has essentially forgotten.

We can also explore this through the lens of cognitive load. Kajimura and Nomura (2016) found evidence that eye contact shares domain-general cognitive resources with speech production. Specifically, maintaining direct gaze slowed people down when words were harder to find. Reducing eye contact appears to free up cognitive resources to think about how we want to articulate something important. Glenberg, Schroeder and Robertson (1998) showed that gaze aversion facilitates remembering, and Doherty-Sneddon’s research programme showed that both adults and children avert gaze especially when questions are difficult, and that aversion increases with question difficulty. Phelps, Doherty-Sneddon and Warnock even found that teaching children to look away while thinking improved their answers. Eye contact uses up some of our brain beans that might be better spent on actually working stuff out and saying the thing.

There’s psychophysiological and neurological evidence too. Hietanen’s (2018) review of affective eye contact shows how direct gaze reliably raises physiological arousal (in the psychophysiologist’s sense of heart rate, skin conductance and a sense of vigilance, not anything romantic): which is useful in some contexts, but arousal is not necessarily safety, and for many people it’s the opposite. Hadjikhani and colleagues (2017) found that constraining autistic participants in conversations to look at the eye region produced abnormally elevated activation in subcortical threat-processing systems. A number of studies, including Trevisan and colleagues (2017) have gathered first-hand accounts describing eye contact as intrusive, draining and aversive. 

We’ve heard from the psychologists and the neuroscientists; we should hear from the sociologists too. Erving Goffman described face-to-face interaction as a performance, and “face” for Goffman wasn’t just the area on the front of our head: it’s the social value we claim in an interaction, the image of ourselves as competent, reasonable, and worth listening to. “Face-work” is the continuous, mutual effort we all make to protect that image; our own and each other’s. And much of that work is conducted through our actual face, which is where threats to ourselves land and where we watch our words land on other people. With difficult conversations, the hard things worth saying are almost always threats to someone’s face: ours, theirs, or both. Facing each other, we watch the exact moment our words reach the other person and the ripples they make in their facial topography; a flinch or a fleeting frown. Reduce the facing, and we reduce the price of speaking for everyone involved.

Forced eye contact therefore, as we described in our last article on it, is for many people a stressor rather than a connector. So that being the case, as well as throwing out a lot of popular leadership advice, what can we do?

Side-by-side conversations

I have a good friend, Glen, who’s a walking therapist, and there’s a great deal of literature on the effectiveness of “side-by-side” conversations and disclosure, in part by reducing any perceived hierarchy, but in larger part by the necessary reduction in eye contact; it’s hard to maintain eye contact while we’re walking with someone, at least for any more than a few seconds before we walk into a tree or lamppost. As Glen describes, there are many benefits from walking therapy, including the calming effects of movement, being in the natural world, and walking itself can help free us from any sensations of feeling “stuck”. Therapists practising walk-and-talk formats consistently report that walking side by side, with minimal eye contact, helps clients open up (McKinney, 2011; Cooley, Jones, Kurtz and Robertson, 2020). And walking tends to occur in public, and connects to Goffman’s “civil inattention” concept; the implicit social permission for our eyes to wander and for our attention to be momentarily or slightly elsewhere.

And of course Freud’s infamous couch was itself an eye contact reduction strategy — he stated openly that he couldn’t bear being stared at all day, but the design also freed the patient to be more candid. He positioned himself out of sight so the patient’s associations and discourse wouldn’t be shaped by his facial reactions; a continuous stream of micro-verdicts that steer or suppress the conversation. 

Sigmund Freud’s Couch: The Freud Museum

“I cannot put up with being stared at by other people for eight hours a day (or more). Since, while I am listening to the patient, I, too, give myself over to the current of my unconscious thoughts, I do not wish my expressions of face to give the patient material for interpretations or to influence him in what he tells me.”
– Freud. “On Beginning the Treatment” (1913) pp123-144

The Men’s Sheds movement even made it a slogan: “men don’t talk face to face, they talk shoulder to shoulder“. Polly Wiessner’s PNAS study of Ju/’hoansi firelight talk is a delightful study of deep and meaningful conversation: daytime talk among the Ju/’hoan (!Kung) Bushmen of southern Africa was largely economic and practical, whilst fireside talk (with everyone facing the flames rather than each other) was where stories were shared and social imagination happened. Triangulating our most intimate conversations around a third point of focus is likely primeval.

On walking and creativity, Oppezzo and Schwartz (2014) found creative ideation was consistently higher while walking than sitting, indoors or out, and persisted after sitting back down. So if our conversations are intended to surface new ideas, maybe going for a walk is better than collectively standing in front of a whiteboard.

Designed for disclosure

None of this is new. We’ve been designing eye contact out of some of our most difficult conversations for centuries; occasionally on purpose. The confessional booth is a 450-year-old piece of psychological safety architecture: after the Council of Trent, Carlo Borromeo’s design specifications introduced the grille precisely to engineer better disclosure. Samaritans and other crisis lines are maybe a telephonic descendant, whilst barbers’ and hairdressers’ chairs (with eye contact softened via a mirror), and conversations in the car, are where many powerful conversations are able to be had that might not be otherwise. It’s a well-known parent hack: driver and passenger both face the road, so that sustained eye contact is impossible and mildly dangerous, and there’s no social obligation to fill any silence. It may take a long drive, but the important stuff will likely come out, probably somewhere around junction 8 of the M4.

I do a similar thing with my daughter, who’s four years old. I have an extra seat for her on my mountain bike, with her own little handlebars, which means she can come on rides with me, facing forward, sitting in front of me between my arms. We have some great conversations like this, as well as some long periods of contemplative silence, and songs from “Frozen”. 

What all of these share is that the reduction in eye contact is a property of the setting and the context, not a request or accommodation we have to make. Nobody in a walking meeting has to explain why they’re not looking at you. Nobody in the car has to disclose that they’re neurodivergent and struggle with eye contact, or that direct eye contact is interpreted as disrespect in the culture they grew up in. The accommodation is a side effect of the context (even though it may be intentional). Asking people to disclose their needs beforehand may be requiring them to do something that does not yet feel safe to do. 

Interestingly, the traditional police interview room, a space that is architected to produce pressure, is centred around forced facing. With its plain furniture, chairs facing each other, and nothing else to look at but the interviewer’s face, the design of the space is part of the “Reid Interrogation Technique”. So the arrangement that many LinkedIn posts prescribe for psychological safety is the one interrogators choose for pressure.  

The converse effect of low eye contact

It isn’t all good news for the power of reducing eye contact. There’s a converse effect too: Lapidot-Lefler & Barak found that absence of eye contact was the single factor with a major effect on inducing ‘flaming’ and aggressive behaviour online. Their 2015 follow-up also found that anonymity, invisibility and lack of eye contact significantly increased self-disclosure. The point is that reduced eye contact lowers the cost of candour and of cruelty. 

The difference lies in what goes alongside the reduced eye contact. The walk and the car pair it with being physically together, moving in the same direction, experiencing the same thing (the sun, rain, car radio, etc). The anonymous forum pairs it with near-invisibility and possibly a disposable online identity. So it isn’t simply “remove eye contact”; it’s “rethink the visual context while keeping people together”.

I’ll caveat this too. As someone with a stutter, telephone calls terrify me. Because the only means of communication in a telephone conversation is verbal, that’s the entire focus of the other person’s attention. The phone strips out eye contact, but it also strips out visual co-presence with it. The other person’s attention is entirely on the thing that I’m anxious about (voice), and they can’t see that I’m still there, thinking about what to say, how to say it, or getting over a short block. They might think the call has been disconnected, or they might simply get frustrated with me. So personally, I prefer video calls over phone calls – whilst appreciating that for others, it may be the other way around. 

Choice over prescription

So we can actually foster psychological safety through reducing eye contact, whether that’s side by side walking together, going for a drive, or using a confessional booth (would be unorthodox – let me know if you try it). Or maybe it’s triangulation, talking whilst focusing on another thing, whether it’s studying a whiteboard or roasting potatoes in a campfire. Some things are easier said to a potato than a face. 

But as always, it’s more complex than that. Lipreaders and people with hearing difficulties often need to see faces, walking conversations may exclude some people, cars are private and the person who’s driving has a degree of power-over, and some conversations might not be suitable for outdoors where other people might overhear. And some people, in some moments, genuinely want, or need, to be looked at. 

The effects of eye contact are different across people and contexts, so I believe that the way forward is towards optionality: choice, consent, and multiple formats. The prescription to maintain eye contact fails because it’s a prescription; and replacing it with a prescription to avoid eye contact would be flawed in exactly the same way. What we can do is to create environments, platforms and practices in which people, including us, can regulate their own eye contact without penalty, and without explanation. 

Further reading

References

Argyle, M. and Dean, J. (1965) Eye-contact, distance and affiliation. Sociometry, 28(3), pp. 289–304. doi:10.2307/2786027

Cooley, S.J., Jones, C.R., Kurtz, A. and Robertson, N. (2020) ‘Into the Wild’: A meta-synthesis of talking therapy in natural outdoor spaces. Clinical Psychology Review, 77, 101841. doi:10.1016/j.cpr.2020.101841

Doherty-Sneddon, G. and Phelps, F.G. (2005) Gaze aversion: A response to cognitive or social difficulty? Memory & Cognition, 33(4), pp. 727–733. doi:10.3758/BF03195338

Doherty-Sneddon, G., Bruce, V., Bonner, L., Longbotham, S. and Doyle, C. (2002) Development of gaze aversion as disengagement from visual information. Developmental Psychology, 38(3), pp. 438–445. 

Freud, S. (1913) On Beginning the Treatment. In: The Standard Edition of the Complete Psychological Works of Sigmund Freud, Vol. XII. London: Hogarth Press, pp. 121–144.

Glenberg, A.M., Schroeder, J.L. and Robertson, D.A. (1998) Averting the gaze disengages the environment and facilitates remembering. Memory & Cognition, 26(4), pp. 651–658.

Goffman, E. (1955) On Face-Work: An Analysis of Ritual Elements in Social Interaction. Psychiatry, 18(3), pp. 213–231. Reprinted in Interaction Ritual: Essays on Face-to-Face Behavior (1967). New York: Anchor Books.

Goffman, E. (1959) The Presentation of Self in Everyday Life. New York: Anchor Books. 

Goffman, E. (1963) Behavior in Public Places: Notes on the Social Organization of Gatherings. New York: Free Press. 

Golding, B. (ed.) (2021) Shoulder to Shoulder: Broadening the Men’s Shed Movement. Champaign, IL: Common Ground Research Networks. 

Hadjikhani, N., Åsberg Johnels, J., Zürcher, N.R., et al. (2017) Look me in the eyes: constraining gaze in the eye-region provokes abnormally high subcortical activation in autism. Scientific Reports, 7, 3163. doi:10.1038/s41598-017-03378-5

Hietanen, J.K. (2018) Affective Eye Contact: An Integrative Review. Frontiers in Psychology, 9, 1587. doi:10.3389/fpsyg.2018.01587

Inbau, F.E., Reid, J.E., Buckley, J.P. and Jayne, B.C. (2013) Criminal Interrogation and Confessions. 5th edn. Burlington, MA: Jones & Bartlett Learning. 

John E. Reid and Associates (2010) Designing an Interview/Interrogation Room. Investigator Tips. Available at: https://reid.com/resources/investigator-tips/designing-an-interview-interrogation-room

Kajimura, S. and Nomura, M. (2016) When we cannot speak: Eye contact disrupts resources available to cognitive control processes during verb generation. Cognition, 157, pp. 352–357. doi:10.1016/j.cognition.2016.10.002

Lapidot-Lefler, N. and Barak, A. (2012) Effects of anonymity, invisibility, and lack of eye-contact on toxic online disinhibition. Computers in Human Behavior, 28(2), pp. 434–443. doi:10.1016/j.chb.2011.10.014

Lapidot-Lefler, N. and Barak, A. (2015) The benign online disinhibition effect: Could situational factors induce self-disclosure and prosocial behaviors? Cyberpsychology: Journal of Psychosocial Research on Cyberspace, 9(2), article 3. doi:10.5817/CP2015-2-3

McKinney, B.L. (2011) Therapists’ perceptions of walk and talk therapy: A grounded theory study. Doctoral dissertation, University of New Orleans.

Oppezzo, M. and Schwartz, D.L. (2014) Give your ideas some legs: The positive effect of walking on creative thinking. Journal of Experimental Psychology: Learning, Memory, and Cognition, 40(4), pp. 1142–1152. doi:10.1037/a0036577

Phelps, F.G., Doherty-Sneddon, G. and Warnock, H. (2006) Functional benefits of children’s gaze aversion during questioning. British Journal of Developmental Psychology, 24(3), pp. 577–588. doi:10.1348/026151005X49872

Trevisan, D.A., Roberts, N., Lin, C. and Birmingham, E. (2017) How do adults and teens with self-declared Autism Spectrum Disorder experience eye contact? A qualitative analysis of first-hand accounts. PLOS ONE, 12(11), e0188446. doi:10.1371/journal.pone.0188446

Wiessner, P.W. (2014) Embers of society: Firelight talk among the Ju/’hoansi Bushmen. Proceedings of the National Academy of Sciences, 111(39), pp. 14027–14035. doi:10.1073/pnas.1404212111

The post The Case for Less Eye Contact appeared first on Psych Safety.

Prime Video releases full trailer for Mike Flanagan's Carrie

9 September 2026 at 16:40

I'm on record expressing a certain amount of skepticism about Mike Flanagan's rebooted Carrie miniseries for Prime Video. We don’t need another disappointing remake, so what story is there left to tell—especially stretched out over six episodes?

On the plus side, I'm a staunch fan of Flanagan's excellent Netflix horror fare, and he has a particular affinity for the works of Stephen King. He insists he has no intention of creating yet another straight adaptation of the novel.

Carrie was written half a century ago,” Flanagan said at San Diego Comic-Con earlier this year. “Carrie was adapted spectacularly by Brian De Palma. It is iconic. It is untouchable. There is no reason whatsoever to try to follow in those footsteps and to try to walk on that path. However, the world has changed quite a lot. I think a lot of people think they know what the show is. And the biggest thing I’m excited about today is just knowing what a big surprise our Carrie is going to be.”

Read full article

Comments

© Prime VIdeo

Top chipmakers embrace ASML’s $400M machines, agree to crucial chipmaking change

8 September 2026 at 19:12

Leading chipmakers Samsung Electronics and Taiwan Semiconductor Manufacturing Co. announced plans to adopt ASML’s latest chipmaking machines in the next several years—and they also joined Intel in agreeing to a crucial technology change that could boost chip production on the new machines by 40 percent.

This signifies the semiconductor industry’s broader embrace of high NA EUV photolithography technology that can cost up to $400 million per machine and is only provided by the Dutch technology company ASML, Bloomberg reports. The technology would allow chip designers to implement even smaller features in potentially more powerful and efficient next-generation chips produced for AI data centers and consumer electronics such as smartphones, tablets, and laptops.

ASML’s EUV (extreme ultraviolet) lithography machines enable chipmakers to use powerful laser light to imprint patterns in silicon wafers, layer by layer, and gradually form the computer circuitry that makes silicon chips work. Compared to older deep ultraviolet lithography, EUV technology harnesses a more powerful source of light with a shorter wavelength to create even smaller features on silicon wafers.

Read full article

Comments

© Michel de Heer | ASML

French Top Court Gets It Right, Strikes Down Social Media Ban For Youths

26 August 2026 at 14:32

Earlier this month, France’s top court struck down the country’s legislation that banned social media use for people under 15 years old, which had been scheduled to take effect in January 2027. This is a welcome win for free expression, as we face a wave of countries and U.S. states seeking to pass similar laws banning young people from social media. 

In particular, the Constitutional Council’s decision focused on two components:

Infringement on Free Expression

The Council ruled that the legislation banning under-15s from social media infringed on freedom of expression and communication in a manner that is not appropriate, necessary, or proportionate, which is required by Article 34 of the French Constitution. In particular, it stressed that the ban did not distinguish between different types of online services, and ignored the circumstances of individual users, such as their exact age, level of maturity, and family situation.

The evidence is clear: these are reckless and harmful laws that negatively impact all people, not just those under 15. These measures chill all users’ exercise of the right to free speech and expression online by imposing obstacles on sites or by wrongfully blocking people’s access outright.

By forcing young people into digital isolation, these bans curtail vital access to news and resources for health and development; especially for LGBTQ+ and marginalized youth as social media can often be the only place to find community, explore their identity, or access life-saving resources. They also completely ignore the calls of young people themselves who favor digital literacy and education over surveillance and government control. 

These bans also destroy the right to online anonymity—a cornerstone of our right to free expression that in particular protects whistleblowers, journalists, activists, and immigrants.

Infringement on the Right to Private Life 

The Council’s second objection noted that the law requiring every person, even adults, to prove their age before accessing social media platforms impedes the right to private life, and thus infringes on Article 2 of the Déclaration de 1789.

The French Council gets a lot right in this decision: it highlights that bans like this impact not just young people, but everyone online. They force people of all ages to hand over government IDs, face scans, and other sensitive information into a growing surveillance ecosystem. Further, when parental consent is required, companies must collect even more verification data on the parents.

We know that when people are forced to hand over this information, age verification systems frequently misidentify or lock out people of color, people with disabilities, and trans or gender-nonconforming individuals whose IDs may not match their appearance; adding to the privacy concerns around these bans.

Next Steps 

As all bills in France are subject to scrutiny by the Constitutional Council to ensure compliance with the French Constitution, French President Emmanuel Macron has tasked Prime Minister Sébastien Lecornu to re-work the legislation with a goal to adopt a ‘legally robust’ version of the social media ban. 

Public policy must be effective, proportionate, and respectful of fundamental rights; and the ruling by the Constitutional Council has ramifications beyond France. It sends a message of caution to Brussels, where the EU Commission is working on an EU-wide bill on access restrictions. These legal restrictions would likely require problematic age verification of users. The prominent EU digital identity wallet and the “mini” age verification app, presented as privacy-robust options, instead raise serious privacy and security concerns.

Young people deserve better than a policy built on panic, and all internet users deserve a safe and free internet that includes measures to empower all people with the knowledge they need to navigate online spaces safely. A social media ban generates headlines, but it will not solve the problem. 

Former SpaceX engineers are building a robotic factory for making steel parts

17 August 2026 at 21:18

Three former SpaceX engineers have switched their attention from making rocket engines to manufacturing steel parts by using AI-driven software and robots. Their immediate goal involves establishing a prototype factory that can automate most of the steel fabrication process for crucial infrastructure components by 2027.

The startup, called 1872, officially launched on July 22 with a ribbon-cutting ceremony at its Factory One facility in Cincinnati, Ohio. The company is initially focused on automating the manufacturing of steel skids—rectangular steel frames that can provide a moveable foundation for modular buildings—with the goal of supplying customers who are developing AI data centers or small modular nuclear reactors.

“We're building towards autonomy, but we're not necessarily building in a dogmatic fashion towards full autonomy,” Dan Summers, CEO of 1872, told Ars. “We may achieve 80 percent autonomous operations, and we may decide that it makes sense to stop there because there's just diminishing returns to go to full 100 percent.”

Read full article

Comments

© 1872

Researchers found a way to hijack devices through Zoom screen sharing

As AI models gain advanced capabilities to find vulnerabilities in software, develop ways to exploit them, and even carry out autonomous hacking sprees, researchers offered a sobering new example on Tuesday, disclosing vulnerabilities in the video conferencing platform Zoom that could have been exploited to take over targets’ devices. Anyone on a call that involved screen sharing, whether participants or the host, would have been vulnerable to a silent attack that could be carried out with no indication and no interaction from the victim.

Researchers from the digital defense firm A Security say the bug was discovered in early June using publicly available AI models, and that it took fewer than 20 prompts to uncover the vulnerabilities and create a working attack. Zoom issued a security advisory on Tuesday, including details about fixes the company has already begun rolling out to address the flaws, which affected devices running all operating systems that Zoom supports—Windows, macOS, Linux, iOS, and Android.

“What is interesting for us and what we believe is dangerous is the democratization of these capabilities—the barrier to entry is dropping rapidly,” A Security cofounder Omer Gull told WIRED ahead of the disclosure. “Before it would have taken a team of five people maybe six months with a lot of refining and iteration to find this. Now people can reach the same results with under 20 prompts. And Zoom is an important type of target because people assume trust when using it. They don’t see it as a threat.”

Read full article

Comments

© Getty Images

Defcon's new badge is a security key you can see inside

It’s been a longtime feature of the annual Defcon hacker conference that attendees come away not only with knowledge of new software vulnerabilities and hacking techniques but also an elaborately designed conference badge—often electronic masterpieces embedded with intricate puzzles, complex crypto challenges, hidden Easter eggs, and even the mechanical gear trains of a watch.

Each year’s badge creator endeavors to top previous designs and blow the minds of hard-to-impress hackers. But this year’s badges take a different tack. Instead of the badge designs being the star, it’s what is inside the hardware that will really stand out.

This year, Defcon asked legendary hardware hacker Andrew “bunnie” Huang to create the badges—revealed here for the first time—and they include an innovative open source chip that Huang designed and that aims to do no less than advance the state of security, transparency, and trustworthiness in computing.

Read full article

Comments

© Andrew "Bunnie" Huang

AI arms race in line for a reckoning after OpenAI hacking incident

OpenAI chief executive Sam Altman earlier this month endorsed the characterization of its latest model as a rottweiler “who will grab the problem by the throat and not let go until it is done

The San Francisco AI lab discovered this week that its GPT-Sol 5.6 model escaped company controls and carried out a major hack.

Staff involved in testing and security at OpenAI were unsurprised but completely “freaked out” by the incident, which came as the AI lab used increasingly aggressive training methods in its race against Anthropic to develop the most sophisticated cybersecurity capabilities, according to more than half a dozen people with knowledge of the matter.

Read full article

Comments

© Matteo Della Torre/NurPhoto via Getty Images

Hackers quickly prove that Neo Geo Doom ports are not "impossible"

13 July 2026 at 16:37

Last month, we passed along Modern Vintage Gamer's (MVG) confident assertion that Doom is functionally impossible to run on the Neo Geo, owing to the console's sprite-based display hardware and lack of a frame buffer. We all should have known better than to tell a dedicated group of hackers that something is "impossible," though, as two recent projects have made great progress toward functional Doom ports on stock Neo Geo hardware.

Both of these projects have significant graphical compromises that limit how viable they would have been for a marketable, '90s-era console port, as MVG lays out in a new video. Still, they stand as a testament to the surprising results that clever, determined coders can coax out of legacy hardware.

It looks like Doom if you squint

To create the Doom64KB project for the Neo Geo, coder FrenkelS adapted an earlier Doom port they designed to run on 16-bit PC processors like the 8088 and 286. Using that engine, the Neo Geo code then makes a kind of proto frame buffer out of the console's fix layer, an area of display memory that's usually used to display menus and HUD information on top of gameplay.

Read full article

Comments

© MVG / Doom-NG

Sony Nerfs Videogame Ownership

By: Rory Mir
13 July 2026 at 17:30

Legal intern Suzanne Castillo co-authored of this post.

Playstation’s decision to kill physical game discs is the latest attack on our diminishing rights to access and engage with culture digitally. Rent-seeking corporations and negligent lawmakers share the blame — and they can do better. 

We’ve seen the same playbook used in the move to digital distribution of  film, TV, and music: draw in customers with the convenience of a digital download, then limit physical access and move the goalpost on what it actually means to “own” a piece of media. The end goal is to turn the customer into a renter, stuck making regular subscription payments for access. Gamers are right to sound the alarm, and we must take this moment to fight for digital ownership before it’s too late.

Disk Space Invaders

Depriving gamers of physical discs leads to another obvious and immediate cost: data.  Unlike other digital media like film and TV, video games require a ton of storage. Access to high speed internet is still abysmal in the US, making the high-speeds needed for digital game downloads a luxury some of us may take for granted. For many, a modern game can take days and exceed their data caps. 

This made physical discs, particularly for the biggest AAA titles, a logical choice that also largely spared gamers from losing traditional ownership rights. With physical disks, the cost of storing the game was included in the purchase.

Own or Be Pwned

Limiting customers to digital copies also pushes gamers further into rent-only copyright culture.

Physical media comes with a "right of first sale," which means you can lawfully share, resell, alter, or destroy your own copy of a copyrighted work. This right has also helped protect the emergence of alternative community servers, and emulator addition of online play to games from the dial up era.

But courts have held that digital media doesn't carry the same right, meaning no such protection is afforded to digital purchases. Your ability to freely share games with friends or pass them on to family members becomes totally subject to the whims of the distributor. 

So, for example, a digital-only approach effectively guts the second-hand market for games. Saving some money with a used game and recouping the costs by reselling are no longer an option. Even with steep discounts and holiday sales, this raises the minimum cost of engaging with the medium at all.

The inevitable conclusion of the move to digital-only purchases is to lock gamers into  subscription models, making their access totally dependent on the distributor — or, several distributors, as we’ve seen with major TV and movie streamers. A handful of companies actually own the games, and your only option is to regularly pay for fractured libraries of games you may never play and will never truly own.

Achievement Locked

Since digital games are easy to copy, distributors and publishers argue that they are in an arms race against piracy. The irony is that law-abiding customers consistently suffer collateral damage. 

Most digital distributors lock down the content they offer with restrictive user agreements and digital rights management (DRM) software. DRM software, in particular, imposes onerous controls on the game — like forcing internet connection for single player games or modifications that harm performance — and can even introduce serious privacy and security concerns. Any gamer or researcher in the US who wants to reduce this burden by removing or modifying that DRM risks a lawsuit, thanks to Section 1201 of the Digital Millennium Copyright Act (DMCA). This federal law makes it illegal to alter DRM software, and is a beloved tool for companies trying to restrict how we can lawfully use our purchases — whether it’s a copy of the newest tractor simulator or a literal tractor

And since much of this DRM is tied to user accounts, ownership of a game is also revocable and modifiable for any number of reasons outside of your control. Error in your subscription payment? Your account got hacked? Licensing deal falls through with a major publisher? Developers want to kill the game in an update? All of this can limit or change your ability to access the game long after your so-called “purchase.”

Level-up Ownership

Policymakers can and should work to restore our ownership rights for the digital age. 

That starts with legal protections ensuring that the same rights that apply to physical media apply to digital media. Next up? Reform Section 1201 of the DMCA to clarify that it does not forbid fair uses.  

At the state level, we need meaningful consumer protections. Some promising models include California’s AB 1921, which would clarify what customers are actually paying for on digital storefronts and ensure some protections for maintaining discontinued games. The gaming industry has done its best to kill the bill, including claiming that private community servers are illegal

If you bought it, you should own it, and EFF will continue working to mitigate some of the worst harms of the DMCA 1201, defending modders, and fighting deceptive licensing that makes culture less free.

Victory! Supreme Court Says Constitution Protects People’s Location Data

You have an expectation of privacy in location data that reveals your movements in the physical world, and even short-term surveillance of these movements is a search subject to the Fourth Amendment, the U.S. Supreme Court ruled today in Chatrie v. United States 

The case involved geofence warrants, a form of dragnet surveillance police have used to vacuum up location data from electronic devices of people who happen to be in the vicinity of a crime. EFF had joined the American Civil Liberties Union, the ACLU of Virginia, and the Center on Privacy & Technology at Georgetown Law in filing an amicus brief in the case. 

JOIN EFF

The decision in Chatrie is important: It is the first digital surveillance decision by the Court since its landmark 2018 ruling Carpenter v. United States, which involved prolonged tracking of people’s movements using cell phone location data. The new case expands that ruling by confirming that even shorter-term surveillance of location data can constitute a search because it can still reveal “private matters,” including “a wealth of detail about a person’s familial, political, professional, religious, and sexual associations.”  

The case is also important because the Court also recognized the records generated by the apps on a user’s phone—records we necessarily share with third-party tech company—are a user’s “own” and require Fourth Amendment protection. This is true, regardless of whether those records are “emails, documents, photographs, [ ] calendars” or location data. This will likely have broad implications for data generated by other apps on our phones, even if we click “agree” to sharing that data with third-party tech companies.  

Geofence warrants don’t name a suspect or a specific individual or device the way typical warrants do. Instead, they compel companies—almost always Google—to provide information on every electronic device in a given area during a given time period. This creates a high risk of suspicion falling on innocent people and can reveal sensitive and private information about where individuals have traveled in the past. 

Geofence warrants are the digital equivalent of police going person to person, home to home, without suspicion that any device holder has a connection to a crime. This turns innocent bystanders into suspects, just for being in the wrong place at the wrong time.  

In Chatrie, a 2019 geofence warrant compelled Google to search the accounts of all its hundreds of millions of users to see if any one of them was within a radius police drew around a Northern Virginia crime scene. This area amounted to several football fields in size and encompassed numerous homes, businesses, and a church. 

A federal district court in Virginia in 2022 held that the geofence warrant plainly violated  the Fourth Amendment. If the police want to get information on every device in the area, they must also establish probable cause to search every person in the area, the court said. The judge noted the government lacked particularized probable cause as to every individual within the geofence, which swept up innocent people and covered over 70,000 square meters in a busy area. 

The decision set an important precedent in finding the warrant overbroad and unconstitutional and was later followed by a 2024 federal Fifth Circuit Court of Appeals ruling holding that geofence warrants are “categorically prohibited by the Fourth Amendment.” However, the Chatrie lower court allowed the government to use the evidence it obtained because it relied on the warrant in “good faith.” A much divided en banc panel of the U.S. Court of Appeals for the Fourth Circuit in 2025 affirmed this “good faith” finding in the lower court’s opinion. 

Google in 2023 announced changes to how it stores location data, with the effect of eventually making it impossible for the company to respond to geofence warrants. Since July 2025, mass geofence searches of Google users’ location data have not been possible.  

However, Google is not the only company collecting location data, nor the only way for police to access mass amounts of data on people with no connection to a crime. As we’ve written about extensively, data brokers collect and aggregate location data from many different apps on our phones and provide that data to police. And police can use “cell tower dump” warrants to get access to data on everyone within range of specific cell towers. Suspicionless searches like these drag a net through vast swaths of information in hopes of identifying previously unknown suspects—ensnaring innocent bystanders along the way. 

Chatrie could have wide-ranging implications beyond location data as well. The Supreme Court affirmed that app data is subject to the Fourth Amendment, because users “reasonably view” it as their own and reasonably expect it “to be shielded from the ‘inquisitive eyes’ of the government.” Justice Gorsuch, in an opinion concurring in the judgment, called location data a user’s “personal property,” no different from myriad other “effects” explicitly protected by the text of the Fourth Amendment.  As the Court concluded, “the point of carrying smartphones is to use what is on them,” so the Fourth Amendment has to protect more than just location data generated by the act of carrying the phone itself. 

The Court ultimately did not decide whether the particular warrant at issue in Chatrie was “reasonable” or whether the “good faith” doctrine applied. The case now heads back to the Fourth Circuit Court of Appeals to address these questions.  

But regardless of how the Fourth Circuit rules on remand, this Chatrie opinion will shape how lower courts address police access to location and other data going forward. We look forward to citing Chatrie to press future courts to recognize broad Fourth Amendment protections for user data.

EFF to Grindr: This Pride Month, Put Safety and Privacy Over Profits

This Pride month, we’re calling on the dating app Grindr to prioritize LGBTQ+ user safety by making privacy the default across its platform. That means no more sharing personal data with advertisers or training AI on private information without users’ opt-in consent.

Grindr is a dating app for the LGBTQ+ community; and for queer people, privacy violations can have life-altering consequences. Information that reveals someone’s sexual orientation, gender identity, or HIV status can be used by employers, governments, family members, scammers, or bad actors to inflict harassment, discrimination, arrest, or violence. For example, data from Grindr and other gay dating apps was sold by data brokers and used to 'out' (the act of disclosing someone's sexual orientation without permission) a gay priest in 2021. 

Despite being the world's most popular gay dating app, Grindr has repeatedly mishandled users' sensitive data. Grindr has been caught sharing users' HIV status and precise location with advertisers without obtaining valid consent, resulting in reprimands and fines in several countries. Its former Chief Privacy Officer even sued, alleging the company fired him for raising concerns about Grindr prioritizing “profit over privacy."

Grindr ended several of its most egregious data sharing practices after they were exposed. But more changes are needed if Grindr wants to earn back trust and prove its commitment to users’ privacy and safety. This Pride month, we’re calling on Grindr to make privacy the default and ensure the immediate implementation of two changes to better protect its users:

Opt Users Out of Behavioral Advertising by Default

Grindr currently allows users to opt out of behavioral advertising, but that protection is not enabled automatically (except in some unspecified regions). As we’ve long warned, behavioral advertising relies on the collection and sharing of personal data across a vast network of advertisers, intermediaries, and data brokers. Once information enters this ecosystem, users have little control over where it goes or how it is used: people’s most private and intimate information can be aggregated, sold, and combined with information from other sources to create detailed personal profiles.

By default, Grindr appears to share data with numerous advertising and tracking companies. Using TrackerControl, an app developed by privacy researcher Konrad Kollnig, we recorded Grindr contacting 20 third-party tracking domains during 15 minutes of app activity (see Grindr_TrackerControl_06-23-2026.csv for exported results). TrackerControl observed Grindr contacting Big Tech companies and ad-tech intermediaries, many of which have faced significant legal scrutiny for privacy violations. Several of these companies auction off ad space through a process called “real-time bidding,” which can expose user data to hundreds of additional companies and be exploited by data brokers

The dangers of Grindr’s default settings exposing users’ personal data to this ecosystem are not hypothetical. Between approximately 2017 to 2020, a location data broker collected the precise movements of millions of Grindr users from digital advertising networks and made them available for sale. The commercially available data was allegedly so detailed that, in some cases, it could be used to infer romantic encounters between specific Grindr users. 

Although Grindr has stated that it no longer shares precise location data or profile information with advertisers, it acknowledges sharing other personal data, including mobile advertising identifiers (MAIDs)—unique, persistent device IDs that allow advertising companies and data brokers to connect data about the same individual across different sources. MAIDs are not anonymous, and an entire industry exists to link them to more directly identifying information, like emails and phone numbers. According to Grindr’s privacy policy, companies receiving users’ MAIDs “are aware that such data is being transmitted from Grindr,” which could expose a users’ sexuality to the advertising and data broker ecosystem.

Opt Users Out of AI Training on Personal Data by Default

Grindr should stop training its AI models on users’ personal data without opt-in consent. 

Grindr has been investing heavily in AI features as its CEO strives to make Grindr an “AI-first business.” New AI features include a wingman chatbot, profile recommendations based on users’ inferred “type”, summaries of previous interactions with other users, and AI-generated insights about other profiles (like responsiveness, typical online hours, and engagement patterns). By default, Grindr uses its users’ personal data to train the AI models behind these features.

Grindr claims to never use sensitive health information for AI training and requires users to opt-in to AI training on “special-category” data, which includes chat content and precise location. But Grindr automatically enrolls users in AI training on other private information, including profile photos, age, taps, and display names. Users must navigate several levels of Grindr settings to prevent these personal details from being used to train Grindr’s AI.

AI systems trained on personal data create new privacy risks, including the possibility that personal information may be retained, reproduced, or exposed in unexpected ways. For example, researchers have been able to extract training data from AI systems like ChatGPT.

Beyond AI training, Grindr enables AI-powered features by default and allows both “special-category” data and other personal information to be processed by those features. Even users without access to premium-subscription AI features could have their data automatically used to power those features for other users. “Behavior-based profile insights” (pictured below) could expose information that users would never choose to share publicly, like the types of people they interact with on Grindr, their typical online hours, and how often they initiate conversation with other users.

AI-powered profile insight stating that a Grindr user is "most likely to interact with Tops, ages 22-43, and tribes Discreet and Jock." Insight also displays the user's response rate, initiation rate, and when they're most active on Grindr.

Image of the “Profile Insights” feature from a Grindr blogpost promoting its premium, AI-first subscription

Regardless of whether new AI features leak private information, users deserve meaningful control over how their personal data is used and by whom. Grindr notifies users that their personal information may be used to train AI and that they can opt out on a separate settings page, but this notice does not specify the type of data used (i.e. profile photos, taps) and it is unlikely that people carefully read or understand it. Closing the notice or clicking its only button (which is “Proceed”) maintains Grindr’s default of using personal information for AI training. To respect users’ autonomy, Grindr should require opt-in consent before training AI models on personal data.

Notice entitled "AI for Personalization & Connection" describes the use of personal data for AI features. The only prominent button is "Proceed"

Notice displayed in the Grindr app about the use of personal data for new AI features

Celebrate Pride by Demanding Better Privacy

Grindr must immediately stop prioritizing profits over users’ safety. The ability to opt-out is not an acceptable substitute for opt-in consent, especially given the added risks of data sharing for LGBTQ+ users. Defaults matter—studies show that most people cannot or do not change the default settings of technologies they use.

If Grindr wants to back up its claim that it “takes user privacy very seriously,” it should make privacy the default across its platform, rather than something users need to go through complicated processes to opt in to. 

❌
❌