Feed aggregator
MIT engineers develop a magnetic transistor for more energy-efficient electronics
Transistors, the building blocks of modern electronics, are typically made of silicon. Because it’s a semiconductor, this material can control the flow of electricity in a circuit. But silicon has fundamental physical limits that restrict how compact and energy-efficient a transistor can be.
MIT researchers have now replaced silicon with a magnetic semiconductor, creating a magnetic transistor that could enable smaller, faster, and more energy-efficient circuits. The material’s magnetism strongly influences its electronic behavior, leading to more efficient control of the flow of electricity.
The team used a novel magnetic material and an optimization process that reduces the material’s defects, which boosts the transistor’s performance.
The material’s unique magnetic properties also allow for transistors with built-in memory, which would simplify circuit design and unlock new applications for high-performance electronics.
“People have known about magnets for thousands of years, but there are very limited ways to incorporate magnetism into electronics. We have shown a new way to efficiently utilize magnetism that opens up a lot of possibilities for future applications and research,” says Chung-Tao Chou, an MIT graduate student in the departments of Electrical Engineering and Computer Science (EECS) and Physics, and co-lead author of a paper on this advance.
Chou is joined on the paper by co-lead author Eugene Park, a graduate student in the Department of Materials Science and Engineering (DMSE); Julian Klein, a DMSE research scientist; Josep Ingla-Aynes, a postdoc in the MIT Plasma Science and Fusion Center; Jagadeesh S. Moodera, a senior research scientist in the Department of Physics; and senior authors Frances Ross, TDK Professor in DMSE; and Luqiao Liu, an associate professor in EECS, and a member of the Research Laboratory of Electronics; as well as others at the University of Chemistry and Technology in Prague. The paper appears today in Physical Review Letters.
Overcoming the limits
In an electronic device, silicon semiconductor transistors act like tiny light switches that turn a circuit on and off, or amplify weak signals in a communication system. They do this using a small input voltage.
But a fundamental physical limit of silicon semiconductors prevents a transistor from operating below a certain voltage, which hinders its energy efficiency.
To make more efficient electronics, researchers have spent decades working toward magnetic transistors that utilize electron spin to control the flow of electricity. Electron spin is a fundamental property that enables electrons to behave like tiny magnets.
So far, scientists have mostly been limited to using certain magnetic materials. These lack the favorable electronic properties of semiconductors, constraining device performance.
“In this work, we combine magnetism and semiconductor physics to realize useful spintronic devices,” Liu says.
The researchers replace the silicon in the surface layer of a transistor with chromium sulfur bromide, a two-dimensional material that acts as a magnetic semiconductor.
Due to the material’s structure, researchers can switch between two magnetic states very cleanly. This makes it ideal for use in a transistor that smoothly switches between “on” and “off.”
“One of the biggest challenges we faced was finding the right material. We tried many other materials that didn’t work,” Chou says.
They discovered that changing these magnetic states modifies the material’s electronic properties, enabling low-energy operation. And unlike many other 2D materials, chromium sulfur bromide remains stable in air.
To make a transistor, the researchers pattern electrodes onto a silicon substrate, then carefully align and transfer the 2D material on top. They use tape to pick up a tiny piece of material, only a few tens of nanometers thick, and place it onto the substrate.
“A lot of researchers will use solvents or glue to do the transfer, but transistors require a very clean surface. We eliminate all those risks by simplifying this step,” Chou says.
Leveraging magnetism
This lack of contamination enables their device to outperform existing magnetic transistors. Most others can only create a weak magnetic effect, changing the flow of current by a few percent or less. Their new transistor can switch or amplify the electric current by a factor of 10.
They use an external magnetic field to change the magnetic state of the material, switching the transistor using significantly less energy than would usually be required.
The material also allows them to control the magnetic states with electric current. This is important because engineers cannot apply magnetic fields to individual transistors in an electronic device. They need to control each one electrically.
The material’s magnetic properties could also enable transistors with built-in memory, simplifying the design of logic or memory circuits.
A typical memory device has a magnetic cell to store information and a transistor to read it out. Their method can combine both into one magnetic transistor.
“Now, not only are transistors turning on and off, they are also remembering information. And because we can switch the transistor with greater magnitude, the signal is much stronger so we can read out the information faster, and in a much more reliable way,” Liu says.
Building on this demonstration, the researchers plan to further study the use of electrical current to control the device. They are also working to make their method scalable so they can fabricate arrays of transistors.
This research was supported, in part, by the Semiconductor Research Corporation, the U.S. Defense Advanced Research Projects Agency (DARPA), the U.S. National Science Foundation (NSF), the U.S. Department of Energy, the U.S. Army Research Office, and the Czech Ministry of Education, Youth, and Sports. The work was partially carried out at the MIT.nano facilities.
Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users
Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.
In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:
- The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
- The Settlement places severe restrictions on Teens that can only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
- The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
- The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism.
Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.
Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.
Age Gates Reinforced By Age Estimation TechnologyIn the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And Further, Meta will now enforce these age gates with “age assurance” technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The Technology also just adds a layer of creepiness into the user of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]
1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) orage assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.
Those methods might include both commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.
This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.
For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.
Those estimated to be 13-17 years old will be limited to Teen User accounts.
Those estimated to be under-13 will lose their accounts altogether.
Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]
(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.
What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement.
How accurate does the age assurance process need to be?
The Settlement sets maximum false positive for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more 10% for ages 16-17 and 3% for ages 13-15.
6. Age Assurance Standards.
(a) U18 False Positive Rate Thresholds.
(i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall
meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15.
(ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date:
(A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15.
(B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.
Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]
9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.
The Settlement generally shows little concern for those falsely placed in its Teen User category.
Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).
(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and
Any age assurance process Meta uses must be tested annually.
Data minimizationThe Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” But the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information ... where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires at that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.
8. Data minimization and security.
(a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification).
(b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest.
(c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.
Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to these estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.
Time restrictionsTeen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits:
- Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
- School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
- Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
- “Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be monetarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:
To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such users controls would have recognized that teens have human rights, agency, and autonomy.
But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.
Feature restrictions (§II.C-D)Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service.
Again, these would be useful user controls that should be offered to users of all ages.
By default, teens will not see the number of likes or other reactions to their posts.
Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques.
X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.
Meta has already had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters.
Content restrictions (P.1, §II.E, as defined by §I.C, E, F)For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback.
D. “Age Assurance Methods” shall have the meaning set forth in Section II.
E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.
The issue here is that some of these categories are problematic. For example, the Restricted Goods & Services standard has been used by Meta to justify removing information about abortion medication, as we detailed in our Stop Censoring Abortion campaign, and in our comment to the Meta Oversight Board. And under the Adult Nudity & Sexual Activity, Meta blocks teens from “real world art of visible genitalia ... where the nudity is the focus of the image” and has a history of applying the standard inconsistently, including with respect to representations of indigenous women, breast cancer awareness posts, and posts about testicular and breast self-exams, educational posts about ovulation. And it has disproportionately applied the standard to gay and lesbian content in as compared to straight content.
And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressure Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earned First Amendment defenses to make its own curatorial decisions.
C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.
The Parental Supervision TradeoffAll of these Teen User restrictions can be modified – but only if the Teen User enrolls in the Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, Parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).
And Parental Supervision comes with a huge privacy tradeoff. In exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G]
Parental Supervision
1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders.
2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available.
3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement.
4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage.
5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools.
6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.
Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8]
This may be workable for young people with healthy and safe relationships with their parent or guardian. But obviously not good at all for a Teen User lacking such a safe relationship.
More Surveillance, Not LessMoreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.
For example:
- Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)]
- Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)]
- Meta pledges to utilize and improve its existing “soft matching models” that track signals such as device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)]
- Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3]
- Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4]
- The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E]
Moreover, one of the chief threats of Meta’ surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain.
Meta Has To Pay The States — Establishing Norms Beyond MetaThe Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten year-life of the Settlement, these annual payments will total over $11 billion plus the prospect of an additional $5 billion—if Meta competitors adopt the same measures.
This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get an additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance and age-gating as the norm across online services.
1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).
2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:
(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates.
(b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.
3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment
The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance.
What’s the Scam?
To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own.
Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line:
Thank you for the positive impact your emails have had on my life.
Your emails are a game-changer.
Your emails are a constant reminder of why I subscribed.
Your emails rock.
Thank you for the time and effort you put into creating these informative emails...
Leaked Russian Cyber-Operations Training Materials
This is interesting:
The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.
[…]
The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.
That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.
The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement...
Rewiring Democracy Series on The Renovator
Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links.
Part 1 is about the Japanese digital democracy party, Team Mirai.
Part 2 is about the Swiss Public AI model, Apertus.
Part 3 is about the civic technologists of Open Knowledge Brazil.
And the new one, Part 4, is about civic AI in Scotland.
Ila Kumar: Innovating with communities
Before Ila Kumar thinks about how to build technology, she asks a different question: What is the context that technology will operate in, and who needs to be involved in the design?
For Kumar, meaningful innovation doesn’t result from engineers or designers working in isolation. Instead, she believes the best innovations emerge when the people who stand to benefit from a technology help create it from the very beginning.
That philosophy has guided her research in the Lifelong Kindergarten group, where she works alongside young people who have experienced trauma during childhood, particularly those involved in the child welfare system, to reimagine how technology can support healing, connection, and independence.
“I really think that community-based design is the only way that we can make technology that accounts for communities’ needs, but also their barriers, their cultures, their concerns,” Kumar says. “It’s the only way that we can make really sustainable and positively impactful technology.”
Today, Kumar is preparing to enter the sixth and final year of her PhD. But when she first arrived at MIT in 2021, she envisioned staying only long enough to complete a master’s degree. However, Kumar quickly fell in love with her work and decided to stay at MIT and pursue her doctorate.
Before graduate school, Kumar grew up in Philadelphia, attended the University of Pennsylvania, and worked on several projects at the intersection of technology and mental health or psychology research.
Through those experiences, Kumar began to question whether the technology she was helping to develop was having the sustained impact she hoped for. “I had done a number of projects that were ‘tech for good,’” she says. “And I wasn’t seeing that what I was doing had a long-term impact.”
Rather than walking away from technology altogether, Kumar began to rethink how it was created. “If we design technology in community-based ways and really think about holistic well-being,” she says, “maybe we can actually create things that help people.”
That conviction eventually became the foundation of her doctoral research, and over the course of her PhD, Kumar has increasingly moved from simply listening to communities to building with them.
Public conversations about technology often present a choice: Embrace it or reject it. Kumar believes that it’s not that simple.
Kumar sees the way digital platforms have the potential to both harm young people’s mental health and development, and help young people process emotions, strengthen relationships, and practice healthy vulnerability — if those tools are designed thoughtfully and embedded in the systems where young people already receive care and support.
Much of her work explores exactly what that could look like.
One project Kumar worked on, in partnership with Stepping Forward LA and with the input of the young people who would use the app, replaces text-heavy communication with a visual collage system to help young people impacted by trauma and the child welfare system to express emotions that may be difficult to put into words, and to build a sense of connectedness with one another.
In an ongoing project, Kumar is collaborating with the Justice Resource Institute to design a mobile app that supports youth in playing an active role in their treatment-planning process and helps them work toward the goals they set outside of the therapy office. The group is working with clinicians and youth to design and evaluate the system.
“We are not sitting at MIT designing tools and just throwing them at people,” Kumar says. “We’re designing it together. We need to actually have the folks that are relevant to providing the care in the room.”
That idea became even clearer to Kumar through a 10-month technology leadership circle she co-facilitated with Foster America. The program brought together people with lived experience of foster care and technology experts to envision how digital technologies could fill gaps in care for young people in the child welfare system.
This project surfaced the importance of not just designing tools that center youths’ needs but also considering the ways in which social services need to be brought into the innovation process.
Those ideas have also led Kumar to explorations that involve one of technology’s newest frontiers: artificial intelligence. She began asking questions after she realized that young people who had experienced trauma had already been turning to AI to make critical life decisions, even as many caregivers were not aware of it.
As a result, Kumar has increasingly focused on supporting care providers in talking with young people about AI. She has led training workshops with organizations that serve young people impacted by trauma or involved in the child welfare system.
Kumar’s passion for advocating for young people extends far beyond the lab. She also volunteers as a court-appointed special advocate, working one-on-one with a young person in the child welfare system while pursuing her PhD.
The role has deepened both her understanding of the challenges young people face and her belief that lasting change depends on relationships.
Some of her most meaningful moments have come while working directly with young people. Last summer, she, alongside another graduate student in her lab, mentored two interns with foster care experience during a six-week program that blended technology, creativity, and personal growth.
“It felt like a real privilege,” Kumar says. “Even the six weeks was not enough.”
Those relationships have also inspired Kumar to address how community-based research is conducted at MIT.
Recognizing that many students interested in community-engaged work often feel isolated, she collaborated with the Priscilla King Gray Public Service Center to co-teach a course on community-driven innovation. She later established a biweekly community of practice connecting researchers across MIT and Harvard University who are navigating the benefits and challenges of conducting research alongside communities rather than simply studying them.
Outside of research, Kumar enjoys birdwatching, cooking with friends, and creating graphic illustrations — creative pursuits that, much like her research, reward patience, observation, and careful attention.
As technology becomes increasingly woven into young people’s lives, Kumar hopes innovation will move beyond the lab and into the communities it is meant to serve.
“The future of actually impactful technologies,” Kumar says, “is when researchers are making decisions with communities instead of for them.”
EFF to Governor Newsom: Veto California’s AB 1709
The California legislature passed Assembly Bill 1709 (A.B. 1709) today, which functions as a sweeping ban on social media use for young people under the age of 16. This well-intentioned, but deeply flawed piece of legislation, cuts young people off from essential information and experiences, particularly harming vulnerable youth and marginalized groups who often find safety in supportive online communities they can't access offline. That’s why we’re urging Governor Gavin Newsom to veto the measure.
Should the law go into effect in January, platforms would be prohibited from offering virtually every functional recommendation algorithm and basic input, such as who a user follows or what posts they like, to anyone under 16. These so-called "addictive features," are in reality the basic tools that online services use to identify what other user-generated content a particular user might want to see. Users also rely on these features to find audiences for their own speech, as well as community. By labeling these basic tools as "addictive," the bill relies on sweeping generalizations regarding the unsettled science of youth social media use. Because nearly every major service relies on automated feeds, the ultimate result is that young people under 16 will still be locked out of major digital services as they currently exist.
A.B. 1709 is a massive privacy and free speech nightmare.
A.B. 1709 is a massive privacy and free speech nightmare. Denying young people access to digital forums (or stripping out the basic tools needed to navigate them) does nothing to make young people safer or healthier. Research shows that social media bans are ineffectual, and can be harmful when they deny young people opportunities to develop their own voices and perspectives, whether that means sharing art, practicing religion, or engaging in politics.
Far from protecting children, the bill will also severely restrict access to constitutionally protected speech and push platforms to implement invasive age-verification methods, such as requiring government IDs or biometric scanning. Age-gating requirements will force everyone to give big tech companies even more personal information. To verify who can pass through online gates, companies will collect even more data, concentrating power in corporate hands rather than protecting users. This creates massive honeypots of sensitive personal data, severely damages online anonymity, and exposes users of all ages to heightened data breach risks.
Finally, A.B. 1709 introduces legal confusion by creating provisions that conflict with already enacted legislation like A.B. 1043 and S.B. 976. Rather than offering regulatory clarity on already-passed laws, California will only end up spending valuable resources to defend a law bound to be tied up in court.
For more details, you can read our full letter to the Governor here.
Translating economic growth into better lives
Solving complex social problems with multiple interrelated causes can involve juggling a variety of factors. Securing funding, designing the right programs, and sustaining the political will necessary to implement them demands a targeted approach.
Lyonel Tanganco, a graduate student in MIT’s Master in Data, Economics, and Design of Policy (DEDP) program, seeks to connect data, policy, and practice-based community interventions to improve living conditions and service delivery in middle-income countries. His studies have allowed him to work with innovative practitioners making real improvements in the world, he says.
“There’s innovation at work in middle-income countries,” says Tanganco, a native of the Philippines. “Seeing the attitudes to adopt and scale new policies and procedures to improve lives has been very interesting to me.”
Taking those innovative practices and investigating their adaptability and potential to scale is at the heart of Tanganco’s research and work. “How do we make growth broad-based and inclusive?” he asks.
The DEDP master’s program, jointly run by MIT’s Department of Economics and the Abdul Latif Jameel Poverty Action Lab (J-PAL), equips development professionals from across the globe with the practical skills and theoretical knowledge needed to tackle these and other kinds of challenges. J-PAL seeks to reduce poverty by ensuring that policy is informed by scientific evidence — conducting randomized impact evaluations; helping governments, nongovernmental organizations, donors, and the private sector apply the resulting evidence to their work; and training researchers, policymakers, practitioners, and donors to generate and use that evidence.
Designing a path to more effective policies and practices
Before arriving at MIT, Tanganco earned degrees in management science and economics, graduating at the top of his class from Ateneo de Manila University in the Philippines. He was previously the director of the Policy, Research, and Liaison Office in the Philippine Department of Finance. His work focused on helping develop the nation’s response to the Covid-19 outbreak, tax policy reform, and communications support for key policy initiatives.
“During my time in government, we sought to increase revenues for health care and increase outlays for health-care programs,” he says. “We were thinking about health care from the financing perspective.”
Tanganco’s efforts helped increase taxes on cigarettes, vaping, and alcohol products, which funded a sixfold increase in the health-care budget. Allocating more funding for health care, he says, may yield better outcomes.
Additionally, Tanganco supported reforms to increase taxation on top Filipino income earners while lowering taxes for others, which the government subsequently implemented. Later, he and some of his colleagues formed a “policy think-and-do tank” — Malusog at Matalinong Bata Coalition (Smart and Healthy Kids Coalition) — that collaborates closely with government agencies on large-scale social programs.
There, he played a key role in designing and advancing a conditional cash transfer program aimed at addressing malnutrition that now reaches more than 190,000 Filipino households. “The program gives families the equivalent of $12 per month under the condition that they bring their children for regular monthly checkups,” Tanganco says. “It increased health-seeking behavior eightfold.”
While he saw success in implementing these programs, Tanganco still found gaps in both knowledge and implementation he thought he could close by enrolling in a program like DEDP. “I wanted a graduate program that taught me what I couldn’t get from a professional career,” he says.
Expanding research into targeted areas
Tanganco describes living in a middle-income country as “living in two contradictory worlds at the same time.”
“I’ve seen gleaming metropolitan skylines alongside underserved communities; pockets of affluence surrounded by persistent poverty; world-class hospitals alongside children who still lack access to basic health care,” he says. “The through line in my work is figuring out how to help middle-income countries translate economic growth to better lives and better human outcomes.”
His DEDP studies have taken him to Indonesia this summer for work on a capstone project with economist Benjamin Olken, the TEPCO Professor of Economics and co-faculty director of J-PAL. The research, conducted in collaboration with Indonesian local governments, involves the design and rollout of a randomized evaluation of a tax intervention.
“So far, I’ve visited and conferred with several local Indonesian governments to assess tax administration issues,” he says. Investigating Indonesian governmental interventions may help improve service delivery and support. One of the ways Tanganco hopes to help Indonesians, Filipinos, and others is by developing tools to raise revenues in simple, effective, and fair ways, making it easier to improve constituent sentiment and service delivery.
Tanganco wants to help policymakers and others understand how politics and other factors influence areas like investments in nutrition and environment. His studies have sharpened his investigative approach in these critical areas.
In the Philippines, for example, one-in-four children is malnourished. “Children who lack proper nutrition before age 2 develop smaller brains, perform worse in school and work, and are far more likely to remain in poverty,” Tanganco reports. “Their potential is capped before they get the chance to use it.”
Middle-income countries also suffer disproportionately from climate-change-related impacts. “Typhoons and extreme heat severely disrupt learning and economic growth in the Philippines,” Tanganco says. “More than a tenth of school days are lost because of climate issues.”
Essentially, without improved policies and practices alongside a sustained effort to improve lives, “we’re losing extraordinary opportunities for human advancement to wasted potential,” Tanganco believes. “Experiences like that abound,” he says.
From the classroom to the next chapter
Tanganco values opportunities to range beyond his DEDP studies. He fondly remembers completing a doctoral-level course in environmental economics co-taught by Olken and Jacob Moscona, the 3M Career Development Assistant Professor of Economics. Its focus on research appealed to him. “I was glad to have time to think about the problems I’m trying to solve,” he says.
Tanganco also enjoyed exploring Greater Boston with his wife — a graduate student at Harvard University — and his fellow DEDP students. From restaurants to concerts with other music nerds, he appreciates the time they spent outside the classroom. “We discuss our hopes and our home countries’ challenges,” he enthuses. “I’m excited to see what folks will do after this.”
Tanganco is especially pleased with the Institute’s commitment to ensuring scholarship centers an interdisciplinary approach. He likens the MIT educational style to “Avatar: The Last Airbender’s” Uncle Iroh, who recommends drawing wisdom from a variety of elements to ensure wisdom doesn’t grow stale.
These and additional opportunities to step outside his previously defined areas of expertise left a lasting impact on him. “Everyone at MIT is open to collaboration,” he says. “There are a lot of thinkers and doers here, and you don’t have to work hard to convince other students to help you.”
As Tanganco continues his work, he encourages practitioners — doctors, nutritionists, and community health workers, for example — to partner with economists and other researchers to translate their expertise into quantifiable metrics policymakers can understand. “Develop an eye for impact,” he adds.
Enrolling in the DEDP program “has been game-changing,” Tanganco concludes. “The program provides a solid foundation for understanding the world and how to make a positive, measurable difference in the lives of other people, especially the least fortunate among us.”
Gulfstream IV makes its long-awaited return to Lincoln Laboratory
After extensive modifications over the past seven years, the Gulfstream IV (G-IV) aircraft operated and maintained by MIT Lincoln Laboratory's Tactical Defense Systems Group and Flight Test Facility (FTF) recently flew home from Canada.
Transforming the standard business jet into a highly specialized research platform — which will support the U.S. Air Force's Air Vehicle Survivability Evaluation (AVSE) program for decades to come — represented the largest and most complex airborne test bed modernization in Lincoln Laboratory history. The Tactical Defense Systems Group, assisted by the FTF, coordinated the effort with the Toronto-based aerospace company Field Aviation.
"Our team made hundreds of trips to Canada and dedicated countless weekends to keep the project moving along," says David Culbertson, FTF manager. "Seeing the aircraft finally return to the laboratory invoked a sense of pride and satisfaction."
An airborne testing infrastructure
For more than 40 years, the Tactical Defense Systems Group has supported the AVSE program, leveraging airborne test beds to assess how U.S. aircraft and space assets fare against current and emerging threats. The group had been conducting airborne testing for the AVSE program with a modified Gulfstream II (G-II) since the early 1990s. In 2013, they began a series of studies to replace the G-II because parts availability issues were looming. These studies concluded that the G-IV was the best option, given its performance and capabilities, including its respectively higher altitude and longer range; long-term sustainability; and cost. The laboratory purchased the G-IV in 2015.
To avoid repeatedly reopening the costly Federal Aviation Administration (FAA) certification process over the planned operational lifetime of the G-IV (25 to 30 years), the group decided to complete all anticipated aircraft modifications at once, rather than in phases. Following a competitive bidding process, the laboratory selected Field Aviation to perform the modifications. Field Aviation had modified the G-II, in addition to other laboratory aircraft. In December 2018, FTF pilots flew the G-IV to Toronto, where it was expected to remain for approximately three to four years.
However, Covid-19 pandemic-related disruptions and contractor management shifts extended this timeline. To help bring the aircraft home, the laboratory stepped in to oversee aircraft modifications, maintenance, and reassembly. Laboratory engineers, mechanics, pilots, program managers, and legal teams worked together to secure Canadian work permits and maintain a continuous onsite presence. Senior aircraft mechanic Craig Rowe served as lead crew chief, traveling monthly with team members to Canada; for his efforts, he was recognized with a 2026 MIT Excellence Award for Outstanding Contributor.
A structural overhaul
To modify the aircraft, mechanics removed, tracked, and ultimately reinstalled more than 2,000 components. The revamped G-IV incorporated 12 major modifications that required sweeping structural changes.
For example, on the wings, mechanics installed four pylons for carrying external sensor pods weighing anywhere from 200 to more than 1,000 pounds. The wings had to be structurally fortified to withstand the added weight, stress, and aerodynamic loads that would be experienced during flight. They added a fifth sensor pylon, capable of holding up to 2,000 pounds and accommodating systems nearly 19 feet long, to the forward lower fuselage. Development of the pylons spanned nearly five years because of intensive reverse engineering, including purchasing and disassembling a wing from a scrapped G-IV to measure the internal structural components. Installation took almost two years because access to the inner wing structure was limited to small panels normally used for inspections.
Mechanics modified the roof and lower fuselage to create flat surfaces to allow rapid mounting of external antennas and sensor systems without repeated incursions into the aircraft's pressurized fuselage. They extended the aircraft's nose and tail with standardized sensor-mounting interfaces to enable rapid placement of sensors for both forward- and aft-facing test scenarios. The six-foot nose extension required completely gutting the cockpit so the internal structure could be reinforced to bear the weight of the mounting interface and test systems.
In the interior, the team installed 14 equipment racks; workstations for six onboard operators; fiber-optic, Ethernet, and coaxial cables; liquid- and air-cooling systems; and dedicated power-distribution infrastructure separated from the baseline aircraft for safety reasons.
The remodel also required developing a means to generate sufficient electrical power to operate the test systems in flight while meeting FAA fire-containment standards. The aircraft’s original auxiliary power unit (APU) — normally intended to assist only with engine startup — was far too small for the mission requirements and could not operate airborne. Field Aviation engineers designed an entirely new fireproof titanium enclosure to house a larger APU capable of producing nearly double the original electrical output up to the 45,000-foot G-IV altitude ceiling. The laboratory's Engineering Division ran simulations to validate that the APU inlet airflow would allow for maximum APU power output throughout the flight duration.
Steps toward mission qualification
After reassembling the G-IV, FTF mechanics conducted hundreds of operational checks to ensure every aircraft system disturbed during the modification worked properly and to validate aircraft safety and readiness to resume flight operations. The aircraft completed multiple post-modification flights without a single maintenance write-up.
"It's extremely rare for a heavily modified aircraft of this complexity to have no write-ups," says program manager Paul Mancini from the Tactical Defense Systems Group. "That's a testament to the quality of work of the FTF mechanics who put the airplane back together and the Field Aviation engineers who completed the modifications."
Since the G-IV returned home this spring, test pilots have been evaluating its airworthiness — i.e., in-flight safety and functionality. The Tactical Defense Systems Group expects approximately another 18 months to complete flight testing, mission systems modification, test systems installation, and FAA certification before the aircraft becomes fully mission-qualified to operationally support the AVSE program.
EFF to Courts: Don’t Rewrite Copyright Over AI Hype
The history of technology is rife with copyright panics. In the 1980s, major rightsholders ran to Congress and the courts, claiming that videotape recorders (VTR) were “to the American film producer and the American public as the Boston strangler is to the woman home alone.” Then, the Supreme Court declined to embrace the hype, noting that the VTR was capable of all kinds of non-infringing uses, like time-shifting and cautioning courts to avoid rewriting copyright law in response to new technologies. We believe that courts now should be similarly wary about the hype surrounding AI.
Hollywood’s hyperbole has echoed that of composer John Phillip Sousa, who claimed in 1906 that the player piano and the gramophone would destroy music composition; portrait artists who feared the camera would replace the paintbrush. None of these things happened. Cameras, for example, sparked a resurgence of portraiture and, by making it possible for more people to create images, led to unexpected developments—like the rise of photojournalism.
New markets, new ideas, and new creators are actually what copyright is supposed to promote, not restrict. Using copyright to lock in existing gatekeepers and massive rightsholders’ profits helps neither the public nor individual artists.
Generative AI has sparked the latest wave of anxiety and with it a massive wave of litigation. In multiple cases around the U.S. and the world, rightsholders are asking courts to do precisely what the Supreme Court warned against: dramatically expand copyright protections based in substantial part on hyperbole and speculation. They should decline to do so.
Copyright owners claim that unless courts abandon 300-year-old copyright principles—and give rightsholders the power to control non-infringing works created by others—an imagined flood of AI-generated works will devastate creative markets. Under this “market dilution” theory, building generative AI tools cannot be fair use because those tools might be encourage the proliferation of competing works.
As EFF has explained to the courts in multiple amicus briefs in Concord Music Group, Inc. v. Anthropic PBC and In re Mosaic LLM Litigation, that’s not how copyright works. In fact, accepting this theory would undermine copyright’s constitutional purpose: promoting the creation of expressive works for the public’s benefit. Because copyright law is designed to encourage others to build freely on existing works, it punishes infringement, not competition. The “market dilution” theory would eviscerate not only the fair use doctrine, but also other limits on copyright that work specifically to prevent rightsholders from unfairly suppressing competition by claiming broad ownership over tropes, genres, styles, and so on. In other words, publishers would wield unchecked veto power over any expression that might conceivably compete with a work they own.
The result? Art doesn’t get created, ideas are never expressed, and we’re all worse off. Copyright shouldn’t be a tool to silence future creative competitors—whether or not they use AI in their work.
And the plaintiffs in these cases get at least two other things wrong. First, research shows that large generative AI models are unlikely to produce infringing works because the more data on which a model is trained, the less any individual training example matters to any particular output.
Second, AI tools aren’t necessarily displacing human creativity. To take a just a few examples:
- Boston-based artist Nettrice Gaskins uses AI to create Afro-futurist art, including a portrait of Octavia Butler displayed at the San Francisco Airport
- Indian artists Prateek Arora and Varun Gupta use generative AI to reimagine Western science fiction.
- Philadelphia-based artist Alex Smith uses generative AI to reimagine Afrofuturism with queer, plus-sized Black superheroes.
- Ana Miljački, a professor of architecture at MIT, used generative AI to create a “non-liner documentary” film on Yugoslav World War II memorials and the values they embodied.
- A research-creation project used AI generated visual art to both amplify the voices of activists in the Iran Woman Life Freedom Movement and evaluate AI’s role in sociopolitical advocacy through art.
- AI company Bronze works with musicians like Disclosure and Jai Paul to create songs that never sound the same when played back twice, challenging audience conceptions of what music could be.
It is not the place of courts to say these people are not artists or that AI cannot augment human creativity in a positive way.
Given this range of experimentation, courts should be reluctant to decide in advance what tools do and do not foster “human creativity.” Like the VTR, large language models are general purpose tools, used by humans to do a broad variety of things far beyond generating lyrics. The effects of this particular technological innovation will doubtless be far-reaching, disruptive, and potentially harmful for some—but distorting copyright law is not the way to address those harms.
At MIT convocation, a warm welcome for the Class of 2030
MIT President Sally Kornbluth formally welcomed the undergraduate Class of 2030 to campus on Sunday, noting that the Institute quickly “feels like home” to new students.
The annual event, officially called the President’s Convocation for First-Years and Families, is held at the Johnson Ice Rink on campus on the weekend most new undergraduates arrive on campus.
The Class of 2030 consists of more than 1,100 first-year undergraduates from all over the map, representing a broad variety of academic interests and backgrounds. Yet even for such a wide-ranging group, Kornbluth observed, “It is very, very common for new students to say that in coming to MIT, they have finally found their place. They have finally found their people. And it feels like home.”
Kornbluth’s remarks outlined some of the binding forces that connect students, through the shared culture of inquiry and discovery at MIT.
“I was struck right away by the wall-to-wall enthusiasm for fundamental science, what we like to think of as curiosity on a mission,” Kornbluth said. “Every day here, hundreds of people are pushing the boundaries of human knowledge.”
This month alone, she noted, “astronomers here just discovered an entirely new type of astrophysical object, a black hole star. … And then, two days later, an MIT research team discovered that a drug that blocks a certain enzyme can reduce the risk of developing lung cancer.”
Kornbluth added: “And that’s just a regular [occurrence] here. As you’ll see, the discoveries just keep on coming in everything, from climate science to computer science, nuclear science to neuroscience, from chemistry to quantum.”
Secondly, Kornbluth said, people in the MIT community are frequently motivated by a desire to have an impact through their work.
“We’re also driven to make a positive difference in the world,” she told the audience of more than 2,000, which frequently applauded at key junctures.
A third common feature of campus life, Kornbluth told the crowd, is the “spirit of entrepreneurship” on campus, generally defined as a propensity to take action.
“Now, I don’t mean that everybody has to start a company, though a lot of people do,” Kornbluth said. “But at MIT, when we talk about entrepreneurship, we also mean the broad spirit of, do something, try something, with your whole heart … and let the doing teach you how to make a difference.”
Kornbluth also made a series of remarks about AI, noting that MIT has “deep ties” to the development of the technology and that AI tools are expanding and accelerating work in many fields of research.
That said, she added, “As educators, it is our challenge to derive AI’s benefits and counteract its harms.” And she called a recent report MIT has issued about AI and education “a powerful reminder that MIT was founded to help human beings develop their own powers of discovery, problem-solving, and invention. That is still and will always be our essential work. It is the experience you all came here for.”
All told, Kornbluth said, “We’re so glad and so grateful that you chose to bring your talent, your energy, your curiosity, and your creativity to MIT. And we’re thrilled to be starting this new year with all of you.”
Kornbluth then introduced the audience to other campus administration leaders who were sitting onstage for her remarks: Provost Anantha Chandrakasan, Chancellor Melissa Nobles, and Vice Chancellor for Graduate and Undergraduate Education David L. Darmofal.
Attendees also heard remarks from two faculty members who are also alumni, per convocation tradition.
Anna Huang SM ’08, the Robert N. Noyce Career Development Professor in both the Music and Theater Arts program and the Department of Electrical Engineering and Computer Science, discussed her work as well as the student experience on campus.
Huang studies human-computer interactions and develops human-AI collaborations in music making, and urged the students to follow their interests — which, in Huang’s case, are quite broad. She spent years working at Google and is also a composer herself.
“You’re going to discover so much here at MIT,” Huang said. “I discover something new every day.”
She urged students to participate in campus activities and to pursue programs such as MISTI, the global experiences program at MIT that enables internships, study abroad, and more. Huang also emphasized that MIT is a collaborative, interdisciplinary place where students can thrive by working with others.
“MIT is a very, very supportive environment,” Huang added. “And we value the perspective and the combinations of unique interests you bring.”
Huang was followed at the podium by Desirée Plata PhD ’09, associate dean of engineering, School of Engineering Distinguished Climate and Energy Professor, and associate professor of civil and environmental engineering, who urged the students to cultivate an ethos of optimism about their studies and ability to improve the world.
Plata’s wide-ranging work applies chemical engineering to climate issues — for instance, as she noted, by working to replicate methane-capture processes observed in nature onto new technologies that could be located in mines. Deploying such techniques to reduce the presence of greenhouse gases could help slow the worldwide rise of temperatures.
“Modulating the warming rate of the planet is admittedly ambitious,” Plata said. “But it’s not impossible. At least not from a thermodynamic perspective. And that’s just the kind of problem we like to solve.”
Plata also encouraged students to cultivate a feeling of open-minded optimism about their own pursuits.
“When I walk onto MIT’s campus each morning, I take a deep breath. I feel that same sense of possibility that I felt the [first] time I set foot here,” Plata said. “A high privilege of my life is being able to engage some of the most talented minds of our time. To engage all of you. To help develop your respective paths. And enjoy the amplifying impact you’re going to go on and have in this world.”
After Plata spoke, Kornbluth, who is from a musical family and enjoys singing, joined the campus a capella group The Chorallaries onstage for a spirited rendition of the songs “Arise All Ye of MIT” and “Take Me Back to Tech.” And with that, students filed out of the rink, ready to explore their new home.
MIT Quantum Initiative launches postdoctoral fellowship program
The MIT Quantum Initiative (QMIT) has launched a new postdoctoral fellowship program to accelerate interdisciplinary quantum research and develop the next generation of scientific leaders working at the frontiers of quantum science and technology.
Supported by a grant from the Gordon and Betty Moore Foundation, the program reflects QMIT’s vision of expanding the boundaries of quantum science by encouraging researchers to connect quantum approaches with other disciplines and emerging applications.
As opportunities in quantum research expand, investing in outstanding early-career researchers has never been more important. These fellowships are designed to help cultivate the next generation of quantum leaders, providing the resources and collaborative environment needed to advance transformative research at MIT.
“Quantum science and technology is in a period of extraordinary opportunity, opening new pathways to solving problems across computation, materials, sensing, and communication. Programs like this help MIT attract outstanding researchers whose ideas will shape the future of the field,” says Anantha Chandrakasan, MIT provost and the Vannevar Bush Professor of Electrical Engineering and Computer Science.
Launched in December 2025 as an MIT strategic initiative, QMIT brings together researchers from across the Institute to accelerate quantum discovery and apply quantum advances to some of society’s most consequential scientific, technological, industrial, and national security challenges.
“Quantum science is becoming increasingly interdisciplinary,” says Danna Freedman, the Frederick George Keyes Professor of Chemistry and faculty director of QMIT. “Some of the most exciting breakthroughs will come from researchers who combine deep expertise in quantum with new perspectives from other fields. This fellowship is designed to create exactly those kinds of opportunities.”
The QMIT Fellowship is intentionally designed to foster an interdisciplinary research community. Eligible applicants are outstanding quantum researchers working in a range of fields across physics, chemistry and materials science, and fundamental aspects of biological and Earth sciences. The program specifically seeks researchers whose work combines deep expertise in quantum science with a willingness to explore new intellectual frontiers.
One example of the interdisciplinary vision behind the program is the possibility of applying quantum systems to better understand biological processes, bringing together expertise in atomic physics, quantum algorithms, and biology. The fellows will be embedded across the research areas that define QMIT, including quantum computing, quantum sensing and precision measurement, quantum materials, quantum simulation, and quantum networks. Their research may also explore emerging interdisciplinary approaches that combine artificial intelligence and quantum science.
Fellows supported through the program will join MIT’s extensive quantum ecosystem, working alongside researchers across the Institute, including those affiliated with the Research Laboratory of Electronics, MIT Lincoln Laboratory, the Department of Physics, the Department of Electrical Engineering and Computer Science, the MIT-Harvard Center for Ultracold Atoms, and numerous interdisciplinary research centers and laboratories.
Beyond supporting individual research projects, the fellowship program is intended to strengthen the broader quantum community at MIT by fostering collaboration, mentorship, and intellectual exchange across disciplines.
“Quantum research, in the next few years and across a wide range of domains, is going to make the impossible possible,” says Ian Waitz, MIT’s vice president for research and the head of QMIT. “The QMIT fellowship program is an investment in outstanding postdoctoral scholars who will help bring tremendous new quantum capabilities to unforeseen, creative, and transformative applications in science and technology.”
The inaugural QMIT Fellows will begin their appointments during the 2026 academic year. QMIT expects to open applications for a new cohort in fall 2026 as it continues building a community of researchers working across disciplines to advance the future of quantum science.
Doxxing Safety Part II: Incident Response
Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse.
This guide is a followup from a previous post that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There's a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.
Incident LogAn incident log is a way to keep track of suspicious or harmful activity online. It doesn't need to be beautiful or complex, just a place where you can quickly note details around the different things you're seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful.
The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the previous blog post. If you haven't yet done that, here's a brief refresher:
Assign Team RolesRemember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you've already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).
Monitoring Hate ForumsSo often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you're a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. We recommend you use the Tor browser for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.
Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.
Set Up Search AlertsGoogle alerts is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you're the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.
For a more sophisticated approach, you could use a tool like Open Measures to automate the task of tracking coordinated campaigns. It's important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.
Hardening Your Public Facing AccountsFor accounts that you can't or don't want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If two-factor authentication isn't already on, now is the time to do so. For social media accounts, consider switching the account to "private," where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you're less likely to encounter stressful content when on the app. Every app's options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.
Shut Down Affected AccountsIf a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you've done so and things have cooled off.
Revisit Your Data Broker Removal StrategiesAlthough this is more of a doxxing preventative measure, it's a good idea to get on top of removing the information that's available about you via data brokers. In case you're unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, a recent study revealed that doing it DIY is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you'd rather have someone else take care of it.
Revisit Public RecordsAs covered in the previous blog post, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren't able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.
Consider Contacting Law EnforcementFor many, talking to law enforcement will only make things worse. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that's a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you're dealing with. It's in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.
Revisit PACE Documents, Enact Those StepsIf you're involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.
This is another step that's best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.
Put A Lock on Your Bank Accounts and Cell SubscriptionsOne of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques.
Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: Verizon, AT&T, and T-Mobile).
Regulate Your Nervous SystemIt’s an understatement to say that being doxxed is scary and potentially very dysregulating. You're much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process.
Flexibility and ResiliencyThe reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security.
Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, the previous one, and stay clued into the strategies laid out on Surveillance Self-Defense, you're well on your way.
Study: Peptides can form well-defined structures in harsh, Venus-like conditions
When exploring solar system bodies for signs of past or present life, scientists have mainly focused on planets that have (or had) a liquid surface similar to Earth’s. However, mounting evidence suggests that the ingredients for life may exist in a very different environment: the highly acidic clouds that blanket Venus.
Those clouds are made up of about 98 percent sulfuric acid, which scientists had believed to be too acidic for complex biological molecules to survive. But in a new study, MIT researchers have shown that short peptides can not only remain stable in these extremely acidic conditions, they can also fold into shapes that may allow them to have biological functions.
“If peptides find their way to that cloud layer of concentrated sulfuric acid, they will stay and be stably preserved in that cloud of droplets. And once these macromolecules have a defined three-dimensional structure, they can potentially have a function,” says Mei Hong, an MIT professor of chemistry and one of the senior authors of the new study.
The findings suggest that scientists should not rule out planets that don’t resemble Earth in their search for life, says Sara Seager, the Class of 1941 Professor of Planetary Sciences in the Department of Earth, Atmospheric and Planetary Sciences and a professor in the departments of Physics and of Aeronautics and Astronautics.
“We really don’t know the full extent of what planet archetypes are out there. We’re seeking exoplanets that might be a true Earth twin, but what if they’re all Venuses? Our findings definitely open up a whole range of possibilities,” says Seager, another senior author of the study. She will be joining the University of Toronto faculty in September.
Janusz Petkowski, a research assistant professor at Wroclaw University of Science and Technology, is also a senior author of the paper, which appears this week in the Proceedings of the National Academy of Sciences. Jia Yi Zhang, an MIT graduate student, is the paper’s lead author, and former MIT postdoc Aurelio Dregni is also an author.
Surviving harsh conditions
While Venus’s surface is too hot to be hospitable to life, its cloud layer, which extends from 30 to 40 miles above the planet’s surface, features milder temperatures suitable for life. The clouds are made from droplets of sulfuric acid, which can dissolve metals and destroys most biological molecules on Earth.
Meteorites that contain peptide building blocks regularly enter Venus’s atmosphere, raising the possibility that those peptides could serve as building blocks for simple life forms — if they could survive the clouds’ corrosive environment.
In 2020, Seager’s lab began a series of studies looking at whether different types of biological molecules could persist under those highly acidic conditions. In their initial experiments, working with MIT’s Department of Chemistry Instrumentation Facility (DCIF), they used nuclear magnetic resonance (NMR) spectroscopy — which measures the magnetic properties of atomic nuclei within molecules — to analyze the structures of a variety of molecules in a solution of nearly pure sulfuric acid.
Those studies showed that nucleic acids, the building blocks of DNA, could remain intact under highly acidic conditions, as could lipids and amino acids. The next step was to figure out if peptides — short strings of amino acids — could persist, and more importantly, whether they could then fold into shapes that might give them biological functions.
For that challenging task, researchers at DCIF suggested that Seager join forces with Hong, an NMR expert who has an advanced 800-megahertz solution NMR spectrometer in her lab.
To their surprise, the researchers found that the peptides they studied remained stable for many weeks. They believe this is a result of the lack of water in such highly acidic solutions. At 98 percent sulfuric acid, there are very few water molecules, which means that hydrolysis, the chemical reaction that breaks peptide bonds in acid, can’t happen.
“Without water, an acid that you would consider a harsh solvent suddenly is not as menacing as one might think,” Hong says.
After confirming that the peptides remained intact, the researchers began to explore their structures. One of the peptides that the researchers analyzed, a molecule known as HHQ, is a synthetic seven-amino-acid peptide that Hong had previously studied for its role in forming catalytic amyloid fibrils.
In water, this peptide forms flat beta sheets that eventually form long fibrils. However, in concentrated sulfuric acid, the researchers found that it takes on an entirely different shape — a loop shaped like the Greek letter omega. Such so-called omega loops are occasionally found in some naturally occurring proteins, where they form links between other structural motifs such as sheets or helices.
The other two peptides that the researchers analyzed were a longer variation of HHQ, called HHQ13, and a completely different peptide called K7, which contains seven amino acids. These peptides also formed omega loops in sulfuric acid.
The researchers believe that molecules of sulfuric acid act as a scaffold for the loops, sliding into the center of each loop and holding it in that shape.
“What hadn’t been known is that peptides can survive so well and have specific three-dimensional shapes in an acidic environment,” Hong says.
Structure and function
In naturally occurring proteins in aqueous solution, omega loops are thought to play a role in protein folding and molecular recognition. Whether they could have other biological functions is not known. However, the fact that peptides can form well-defined, folded structures in acidic environments is an important step in showing that peptides may be able to perform biological functions in such environments.
“Life needs to have specially shaped proteins so that they have a specific target they can latch onto and perform their function. Before this, people thought that peptides couldn’t survive in sulfuric acid, so showing peptides are not only stable, but also fold, is a really big deal,” says Seager, who is leading the Morning Star Missions to Venus.
Adriaan Bax, chief of the Section on Biophysical NMR at the Laboratory of Chemical Physics at the National Institute of Diabetes and Digestive and Kidney Diseases, described the results as “important and unexpected.”
“The observation that these peptides retain a substantial degree of conformational order in concentrated sulfuric acid raises the prospect that folded oligopeptide/protein structures can exist in such environments, potentially supporting the possibility of life in atmospheric conditions that are very different from Earth,” says Bax, who was not involved in the research.
Seager now hopes to pursue additional studies of a molecule called peptide nucleic acid (PNA) — an artificially synthesized molecule that is similar to DNA but with the sugar-phosphate backbone replaced by a peptide backbone. Her lab has previously shown that this molecule, which doesn’t naturally exist on Earth but could offer a potential alternative to DNA, is stable as a single strand in highly acidic environments. She now hopes to study the stability of double-stranded PNA.
The researchers also hope to analyze longer peptides to see if they also take on omega loop shapes, or other structures, in highly concentrated sulfuric acid.
The research was funded by the Alfred P. Sloan Foundation, the NOMIS Foundation, and the National Institutes of Health.
Playing against climate risk
Sai Ravela, principal research scientist in MIT’s Department of Earth, Atmospheric and Planetary Sciences (EAPS), works with a team of researchers, local partners, and community collaborators to develop game-based computer models to help local communities find solutions to their unique geographical and environmental challenges.
Ravela came to MIT as a postdoc in 2002. Prior to that, he had been working on robotics and computer vision, but he was excited by the idea of studying the climate system and wanted to work in the field of sustainability. “Suddenly, overnight, I became a climate person,” Ravela says.
His project, funded by a 2025 Abdul Latif Jameel Water and Food Systems Lab (J-WAFS) India Grant, explores how agricultural decision-making occurs under climate stress. Using localized climate projections and a participatory approach, the project aims to help communities discover ways to improve their collective agricultural resilience.
EAPS postdoc Anamitra Saha is a key contributor on the grant, working with Ravela and local collaborators to combine downscaled climate modeling, participatory decision-making, and community-based adaptation planning. Other team members include Myisha Ahmad (Carthago Consultancy), Jayanta Basu (University of Calcutta), Anusree Ghosh (Bangladesh Open University), Showmitra Sarkar (Khulna University of Engineering and Technology), and Bivuti Sikder (Dhaka University).
In a process known as downscaling, researchers take large-scale climate projections and turn them into highly detailed local projections. From these hazard maps, Ravela and Saha can estimate the risk of extreme weather phenomena such as flooding, drought, heat waves, and salinity-related stress.
“We kind of simulate what the outcome could be in that region,” Ravela explains. “Would it improve agricultural productivity? Would it reduce agricultural productivity? Would it change certain land use patterns? Would the land be less livable, more livable?”
The team combines surveys, scientific models, and local knowledge to build an impact graph that allows them to explore what might happen to a region during simulated weather events.
Although Ravela knew hazard maps could be useful, he was troubled by how rarely they reached the people whose lives were most affected by the risks they described. “We had clients like insurance companies,” he says. “But I never saw it reach people in a way that made a difference in their lives. And that really bothered me.”
To address this gap, he began thinking about how to help communities engage with hazard maps directly and take part in the decision-making process. In conversations that informed the game’s development, Ravela heard people whose livelihoods are vulnerable to climate events voice immediate concerns about what would happen if a future season failed: “If I don’t plant next season — if I can’t — what would I do?” Ravela wanted to help people think instead about possible choices, different paths, and their respective risks.
When he asked himself what circumstances allow someone to think about risk, the answer began to take shape. “Well, roll a die. Toss a coin,” he thought. “And where do you do these things? In a game.”
How it works
The process the collaborating team developed takes place in three stages. The first is a “snakes and ladders” game, played with physical game pieces and tokens. The second is a mixed game that still uses the gameboard, but a computer generates events and manages portfolios, allowing the system to calculate risk percentages. Once players become comfortable with the mixed game, the final stage, developed by Ravela, abandons the board game and moves fully into a more detailed computer simulation that can be played on a cellphone app.
“We tried this in different stages in three places,” says Ravela. Two villages, Bally Island and Joygopalpur, are in India's Sundarbans region. The third is a village in Bangladesh just across the border. In each location, the work depends on collaboration with local residents, community organizers, and regional partners who help shape the game around local land, water, livelihood, and governance conditions. During development, informal community-engagement sessions helped the team refine and adapt the game. Those interactions also led to intriguing observations that are now helping the team formulate hypotheses for future formal research.
The three villages lie in a coastal region that faces numerous extreme weather events threatening water availability and agricultural productivity. As riverbeds rise from sediment accumulation over time and the land sinks from groundwater extraction, saltwater can more easily intrude into groundwater aquifers, while freshwater drainage, recharge, and flushing become increasingly difficult, intensifying waterlogging and drought.
“There’s a vicious cycle that’s happening with salinization of the soil,” Ravela explains.
One visible result is that Boro rice leaves now often begin browning far too early in the season, as salinity and water stress damage crops before they can mature. This cycle occurs in many coastal communities, suggesting to Ravela that the outcomes of the J-WAFS project could have applications around the world.
That broader potential comes from what the game is able to reveal. Instead of treating potential interventions — such as embankments, canals, recharge, crops, fisheries, and energy — as separate choices, the simulation lets players see how each intervention affects the coupled system of land, water, salinity, and livelihoods. When players test different options, simply raising embankments often proves less effective than expected, because it does not break the underlying cycle that causes the land to flood.
More-integrated strategies — combining mangrove restoration, canal excavation, groundwater recharge, diversified agriculture and fisheries, better water management, and merging solar panels into farming with agrivoltaics or aquavoltaics — can generate better long-term returns while also making the landscape more resilient.
The game also creates space to consider dramatic alternatives to embankment-based protection, including seasonal migration, livelihood shifts, and other difficult choices. These possibilities can be explored safely inside the game, even when they would be almost unimaginable to raise in real life. In this way, difficult questions that might otherwise be avoided can be explored, rather than ignored. And if the game reveals that a difficult choice could lead to better long-term outcomes, that result is not a prescription, but a basis for informed conversation between the community, government, and other decision-makers.
Competition or cooperation?
To make the game effective at developing strategies, Ravela’s team had to understand how many people should play at one time. Too few players may not generate enough diversity of ideas, while too many can slow the process significantly. During game development, groups of roughly ten to twelve people seemed especially workable: large enough to support active interaction, but small enough for practical discussion and learning.
“Once it crosses a dozen people,” Ravela explains, “it becomes very, very viable as a way to solve problems.”
The games have sparked interest and generated new strategies. People are often excited by the prospect of playing, and repeated play reveals different kinds of expertise. Some participants become especially engaged strategy-explorers; others contribute through discussion, critique, memory, and local knowledge. Together, the process helps identify players who are especially adept at thinking across different dimensions of the problem.
Ravela emphasizes the social aspect of the games as central to their efficacy. “Even though the game is on a phone,” he says, “players are within each other’s reach.” An emcee or facilitator encourages players to engage with one another by asking them to explain their gameplay, discuss their reasoning, and learn from one another’s choices.
While competition is not an explicit feature of the game, there can be zero-sum outcomes. One household’s decision about land, water, drainage, or energy may improve its own outcome while making conditions worse for others. Initially, players may aim for individual success. As they explore longer simulated time horizons, they often shift toward cooperative strategies.
After each game, the research team and local facilitators lead an educational session where people can learn from each other’s strategies. At first, players often attempt to copy the previous winner’s gameplay — usually, making as much money as possible and saving it in case of disaster. But some disasters are too large for one person to handle alone.
“That strategy is only optimal up to a certain horizon,” Ravela explains, “because when everyone replicates that strategy, the community doesn’t necessarily thrive.”
As players recognize this, they begin to evolve collective modes of behavior, such as creating a common insurance pool where everyone contributes money to a disaster relief fund. Through multiple iterations of the game, players often appeared to converge on cooperative solutions.
“The community in this way, playing a game against nature, simulated nature, comes upon solutions that work for them,” says Ravela. “We would love to formally explore this in the future,” Ravela adds.
Why the game works
Ravela’s team sees three advantages to game-based decision-making. First, the game brings new perspectives to the table that formal decision-making often misses. Many communities have strong hierarchies that can discourage women or less powerful community members from participating openly. The game allows people to offer insight without necessarily violating cultural norms. One recurring impression was that women — often responsible for managing family affairs — diversified their portfolios earlier, while men more often concentrated on a single livelihood strategy. The observation was striking enough that the team hopes to test and quantify it formally in future studies.
Second, in the game, all players begin on a level playing field, regardless of status, gender, or wealth. “It democratizes the process,” explains Ravela. In the simulation, a wealthy, influential community figure has no intrinsic advantage over a seamstress. The game reduces natural biases by giving everyone’s ideas a chance to be tested under the same conditions.
Third, because the game is a simulation, people can explore choices that might be too risky, too expensive, or too socially difficult to consider in real life. People may not want to discuss a large aquifer management system, a new land-use arrangement, or a difficult livelihood transition if the real-world implications feel too overwhelming. But inside the game, they can test possibilities without immediate consequence. “So, what, you lose? You start again,” says Ravela.
This is where the game becomes more than a communication tool. It turns uncertainty into a shared decision space. Players can test interventions, observe trade-offs, compare outcomes, and discover strategies before real disasters force those choices upon them. The game shifts the conversation from avoiding risk to reasoning about it, and from fatalistic thinking to collective agency.
Ravela and his collaborators also see the games as a way to address roadblocks in policy implementation by allowing community members to own the solutions they discover. Traditionally, donors may give money to a nongovernmental organization (NGO) that has proposed a project, and the NGO then distributes resources in the community. But it is not always obvious what has actually been implemented, or whether the community has had meaningful ownership of the decision. “In seeking solutions to problems, often the difficulty is developing the policy that provides metrics for the effectiveness of those solutions,” Ravela says. “Games enable people to quickly see the policy space, rather than approaching problems only reactively.”
When people test policies in the game, see how they work, and revise them through repeated play and refinement, they can begin to propose those policies themselves. The result is not simply a technical recommendation from outside experts, but a community-informed basis for action.
What's next?
The broader project, developed with collaborators and community partners in India and Bangladesh, has attracted interest in Bangladesh and Thailand, where similar game-based coastal agricultural resilience projects are being explored. Some customization is necessary to adjust the game to local conditions, but the simulations are highly adaptable. Between 75 and 80 percent of the game can remain the same across locations, while the rest can be tuned to local geography, livelihoods, hazards, and governance structures. Although each place brings its own challenges, “the way land and water and people interact is very similar,” says Ravela.
Building on insights from these game-development and informal community-engagement sessions, Ravela hopes the project can eventually expand to other locations, including members of the Association of Southeast Asian Nations and some places in Latin America. But he emphasizes the importance of establishing longitudinal outcomes before scaling. “The critical question is, does it answer real problems?” he says.
Future formal research will test these emerging hypotheses prospectively and longitudinally. The resulting evidence will help determine whether, where, and how to scale the approach.
If computationally assisted decision-making proves useful over time, the impact could spread far beyond the initial development locations. But the work is not only about finding an optimal solution. It is also about helping people work with one another. As Ravela puts it, “the process really is about helping the people work with each other as much as it is about finding an optimal solution, because part of finding the optimal solution is finding people to work with each other.”
Doxxing Safety Pt I: Prevention and Footprint Management
Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there's little to no comprehensive data privacy legislation keeping us safe. The responsibility is on each of us to protect ourselves, but the good news is that there's a lot you can do to reduce your digital footprint and take control of your data.
This post is part one of a two-part series discussing safety and response to doxxing. This first part focuses on prevention and ways to reduce your overall footprint. The second focuses on incident response, as in, steps to take if you're in the midst of being doxxed. There will be some crossover and redundancy between these two posts, so it's worth reading each and gaining familiarity with the steps well ahead of time.
OSINTOpen source intelligence (OSINT) is a broad term within information security. It focuses on the tools and means available to us for investigation and information retrieval. OSINT sits at the heart of doxxing campaigns but is also an important part of the process of preventing them. Typically it is a way of describing a methodology of piecing together scraps of information to form a dossier on a subject.
There are fancy multipurpose tools (like Maltego or Lampyre) that combine many datapoints into accessible graphs and datasets. As helpful as they can be for traditional penetration tests or corporate OSINT campaigns, they’re best used for investigations focused on organizations, mapping together details like employee email charts, LinkedIn profiles, and company network maps. They may not fit the needs of everyday people or liberation movement workers. Instead, we recommend referring to different OSINT resource lists that index together a bunch of different tools, then using those resources to create a list for yourself of which tools may be most helpful.
Many, if not all, of the resources we cover below will be referenced in those guides, and themselves fall under the OSINT category. It’s important to note that the tools we reference in this particular blog post are only relevant at the time of publishing. The bigger ideas have a much longer shelf life than various tech tools. That said, in no particular order:
Breach DatabasesWhen a company gets hacked and their customer data is leaked, that information often ends up in “breach databases,” that is, troves of peoples' data available for sale and reuse in illegal trades online. Because of the sensitivity of that type of information, it can potentially be used in doxxing campaigns. Some resources, like haveibeenpwned, note pieces of vulnerable identifying information in those databases and make it easy for people to see if their information is included. Others, like DeHashed, offer a similar sort of tracking, but for a fee.
You may not have control over a company's digital security that could put your own data at risk, but you can gain insight into whether your information is already out there. This gives you the opportunity to control the accuracy of that data (such as changing your email address or phone number). Doing so is extremely inconvenient, but unfortunately, it may be the only agency you have when another’s company’s digital insecurity puts your own safety at risk.
Open RecordsPublic records (such as voter records, property records, business registration, medical licensing information, and more) present a dilemma. It is in the public interest for there to be levels of transparency on such information. On the other hand, making such personally-identifiable information accessible to those with ill-intent can lead to serious consequences.
Instead of requiring a formal request through the courts, mirroring sites make this information easy to find online. Such sites often have forms where you can request your information be taken down. This doesn’t necessarily remove the records from existing, but it does remove a layer of convenience in accessing them.
Some states have programs called “Address Confidentiality Programs” that offer people the right to supplant address information with proxy addresses, keeping public records open but that specific piece of information potentially hidden.
Social MediaGoing through and tightening the security and privacy settings of your various social media accounts is always a good idea, but it’s especially important if you are in the process of minimizing your digital footprint. Consider turning your discoverability to “private” or “hidden” (verbiage and details depend on the app) so that only users vetted by you are able to see your account.
To get a quick overview of the various accounts you have registered online, especially if you've been online for a long time, use a username search engine like What's My Name or Namechk to see where your usernames have been registered. They may not be entirely accurate, but they are effective and quick. These tools are also helpful if you are at risk of being impersonated online and want to get an overview of where that may be taking place.
Data Brokers and RemovalsData brokers are craven, pernicious companies that present an existential risk to everyone in the digital age. Until that industry is no more, it's up to us to protect ourselves and the ways that it endangers us by selling personal, sensitive information. The most effective way to get your information removed from their stores is to file requests manually. Yael Grauer's BADBOOL project compiles and prioritizes the worst offenders in this industry and the means you can use to request data removals from them. This process can be grueling and time-consuming, so it may be worth investing in a service that automates the process. Though they've been found to be less effective than the DIY approach, there are some services that have stood out amongst the others in terms of efficacy when tested by third-party reviewers. If you’re a resident of California, you can more easily opt out through the new and exciting DROP tool.
Reverse Image Searching and FR ServicesServices like PimEyes and Lenso have jumped on the profit-driven opportunity to create facial recognition as a service. They contribute to law enforcement investigations and predictive policing systems, as well as providing commercial services to abusers and stalkers. The gist of their service: upload a picture of someone (in this case, yourself) and it will use facial recognition technology to determine where else online that person has appeared. If your image is being shared online without your consent, this service will find out.
Willfully participating in these services does mean having your image mapped, scanned, and stored by their systems. But if you believe you're under the type of targeted harassment that includes your image being shared online against your will, it may be worth that tradeoff.
Extra Monitoring, AutomatedThis section is less about data minimization, and more about laying extra protections down in the event that doxxing or other coordinated harassment seems imminent. If you're in the Google ecosystem of products, consider enrolling in their Advanced Protection Program, which offers a number of different features to keep you and your account safe.
If you're the focus of coordinated attacks that span from online communities to media outlets participating in the harassment, a service like Open Measures is worth looking into. It tracks, maps, and analyzes the spread of hateful information online. They provide free access to their open-source API, so with some technical fancy-footwork, you can automate this process.
Get Others InvolvedCoordinated harassment is often a process of daisy-chaining targets and tactics together until there’s a meaningful process of harm being inflicted. This means that people in your community are also at risk. As we always say, privacy is a team sport. Get others involved in the process; there’s strength in numbers.
A great way to do this is think of the activities you and your group are up to. What roles do individual members take on? Figure out a way to tack on some of the responsibilities you’re coming up with here onto those team members. Find ways to talk about it and share strategies, preferably using secure technology like Signal. You can coordinate together which tasks each person could take on, perhaps pulled from this blog post.
It's a Process; Keep Yourself Apace for the Marathon, Not the RaceThe process of data minimization and reclaiming agency over your digital footprint can be grueling and stressful. Don't underestimate the toll it can take on your mental health. Take breaks, employ the help of friends, and take the time to make sure you're first addressing the parts that are most relevant to your threat model. It may feel like there’s nothing to be done about protecting your digital privacy, but that’s just a symptom of surveillance capitalism’s psychological effect on its victims. There’s much you can do to stay safe, to protect yourself and others. Refer to this post and to the Surveillance Self-Defense project.
Is Someone Hacking DoD Refrigerators?
The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation.
Naval Air Station Lemoore, Calif., also experienced an outage, according to M. Elizabeth, writer of the Substack newsletter Signal and Silence.
Each service declined to answer questions about how many bases are affected by the outages, referring all questions to the Defense Department. Pentagon officials did not respond to questions...
Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections
Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since then, state lawmakers across the country have begun responding to calls like these, with Connecticut, Maryland, New Jersey, Oregon, and Virginia enacting new consumer privacy restraints on an industry that profits off our physical movements.
Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled. Other states – and Congress – need to get into the game, too, and ensure protection of everyone.
Why Location Privacy Is ImportantImagine spending a couple of hours in a coffee shop, a friend's house, or a healthcare clinic, only to discover yourself under police investigation because your cell phone’s location data exposed your presence there.
This is the reality of geofence warrants for location data, the controversial surveillance technique recently scrutinized by the U.S. Supreme Court in Chatrie v. United States. Through geofencing, tech companies and law enforcement can map everyone who was present within a specific area over a certain window of time, inverting standard constitutional protections by turning every innocent bystander into a potential suspect. While the Supreme Court's ruling in Chatrie established that accessing location data via geofencing constitutes a Fourth Amendment search requiring constitutional protections, law enforcement demands via these warrants are only part of the problem. That same geolocation tracking is used by commercial data brokers operating in a largely unregulated market. These brokers regularly harvest, aggregate, and sell physical location data to anyone with a credit card (including government agencies, which are among their regular clients). Especially for individuals seeking reproductive or gender-affirming care, attending a protest, or visiting an immigration law clinic, this pervasive commercial location surveillance represents an immediate threat.
In Part 1 of this series, we urged lawmakers to protect people from the growing harms of location tracking tools across all areas of public life. The real-world consequences of this unregulated market impact us all. An anti-LGBTQ+ advocacy group spent millions of dollars buying app location data to track priests across multiple dioceses and used app-harvested location data to “out” a priest after purchasing his Grindr location signals. Privacy advocates posing as private investigators gained access to Locate X, a location-tracking tool developed by Babel Street, and demonstrated how the tool tracked a device traveling from Alabama, where abortion is banned, to an abortion clinic in Florida, where access is less restricted. Data brokers like Near Intelligence have sold precise location data of reproductive health clinic visitors directly to political groups. Location data has been used to locate U.S. military personnel in war zones. Law enforcement and private entities have also weaponized location tracking directly against political protesters: surveillance contractors and authorities have utilized location data derived from real-time bidding ad networks to track individuals attending demonstrations.
The unregulated sharing of location data has created an ever-larger funnel for data brokers to capture and monetize our movements. For example, a recent EFF investigation identified several advertising Software Development Kits (SDKs) in Android apps that by default collect and share users' location data whenever app-level location permissions are granted. These advertising libraries automatically feed users' location data into ad systems that location data brokers have used to track people. Because defaults direct real-world outcomes, app developers who fail to carefully scrutinize the third-party SDKs they use, and disable unnecessary data collection, could inadvertently expose their users’ movements to commercial data brokers.
State Legislative ProgressLast year, we outlined six essential core principles that any meaningful location privacy law must contain:
- Strong definitions,
- Clear rules,
- Affirmation that all precise geolocation data is sensitive,
- Empowerment of consumers through a strong private right of action,
- Prohibition of “pay-for-privacy” schemes, and
- Transparency through clear privacy policies.
While the bills we highlighted from California, Illinois, and Massachusetts are yet to pass into law, a new wave of state location privacy legislation has taken effect across Connecticut, Maryland, New Jersey, Oregon, and Virginia.
These five laws represent progress, and share two strong features. First, all five of these states ban the sale of precise geolocation data. This will remove a strong incentive to collect and store this information in the first place. Other types of privacy laws have likewise banned the sale of sensitive types of data, like the Illinois Biometric Privacy Act (BIPA), which bans the sale of biometric information such as face scans.
Second, all five states broadly define the protected data to include all kinds of locations across the board within a particular distance of a person or their device, rather than protecting just narrowly-defined “sensitive” locations. This all-locations protection sets these laws apart from California’s A.B. 45 of 2025, for example, which only restricts location tracking within 1,850 feet of a family planning center. Protecting location data only near specific locations (like health care facilities) is insufficient: if an individual travels across state lines for care, a data broker can still track their route right up to the boundary of a protected zone and pick it up immediately upon departure, making it easy to infer their destination.
These five laws vary regarding whether, on top of the ban on sale, they require consent and/or minimization for other kinds of processing of precise geolocation data. Maryland’s Online Data Privacy Act (MODPA) requires strict minimization. Specifically, a data controller cannot collect, use, store, or disclose a consumer’s precise geolocation data (or other sensitive data) unless doing so is “strictly necessary to provide or maintain a specific product or service requested by [that] consumer.” Minimization is an important privacy protection because it imposes a duty where it belongs: on the company processing a person’s data. Maryland requires doubly strong minimization. First, the data processing must be “strictly necessary,” and not just “necessary,” or even worse, “reasonably necessary.” Second, the necessity of data processing must be tied to what the particular consumer requested, and not to what a generic customer might hypothetically have thought was reasonable, or the company’s own purposes, or whatever the company buried in its own long-winded legalese.
Connecticut requires both strong consent and weak minimization. Specifically, it forbids a data controller from collecting, using, storing, or disclosing a consumer’s precise geolocation data (among other sensitive data) “without first obtaining [that] consumer’s consent”. Connecticut has a strong definition of consent: “a clear affirmative act signifying freely given, specific, informed and unambiguous agreement,” which is absent from “agreement obtained through the use of dark patterns.” On top of this strong consent, Connecticut also requires a weak form of minimization: the data processing must be “reasonably necessary in relation to the purposes for which such sensitive data are processed”. But this does not weaken Connecticut’s strong consent rule.
New Jersey requires consent to collect, use, store, or disclose a person’s precise geolocation data (and other sensitive data).
Virginia protects location data with both minimization and consent, but only for one kind of people (known children) and only for one kind of data processing (collection). Under Virginia’s minimization rule, a data controller cannot collect such data from such people unless doing so “is reasonably necessary for the controller to provide an online service,” and in such cases, “only … for the time necessary” to do so. This would be a much stronger rule if the authors struck the modifier “reasonably” before the word “necessary,” or better yet, substituted the modifier “strictly.”
Beyond its ban on sale, Oregon does not limit the processing of precise geolocation data.
Gaps in Current LegislationWhile these enacted bills mark steps in the right direction, major loopholes remain that leave users vulnerable.
The Enforcement Void: Why Every Law Needs a Private Right of ActionA privacy law without a Private Right of Action is a law "without teeth”.
None of these five state statutes expressly empower consumers to directly sue companies that violate their location privacy rights. Relying exclusively on state Attorneys General or specialized regulatory agencies creates a critical bottleneck, since no regulatory agency possesses the staffing or budget required to investigate every data privacy violation. Additionally, government enforcement priorities shift across administrations, leaving enforcement vulnerable to political pressures and corporate lobbying.
The best way to ensure effective enforcement is a free-standing, explicit Private Right of Action written directly into the privacy statute. Some legislative privacy proposals instead attempt to provide remedies by piggybacking on state laws against unfair, deceptive, or abusive practices (UDAP). But this is often hit-or-miss depending on each state’s specific UDAP law, including who must have what kind of injury to have standing to bring a private action, and the scope of remedies. For instance, while Maryland’s MODPA provides that a violation of the statute constitutes a banned UDAP, it appears that the new law’s enforcement mechanics were drafted in a way that provides only government enforcement through the Attorney General’s Consumer Protection Division, rather than granting consumers a private right of action.
Any a private right of action should come complete with statutory liquidated damages to remedy non-economic harm, and prohibitions against mandatory arbitration. This ensures that compliance isn't optional. Until corporate bad actors face direct accountability from the very people whose personal location data they unlawfully exploit, state privacy laws will rely on overworked regulators to police an industry that profits off our every move.
The "Pay-for-Privacy" TrapPrivacy is a fundamental right, not a luxury tier. So EFF opposes pay-for-privacy schemes, in which companies charge a higher price to people who exercise their privacy rights. To prevent these schemes, data privacy legislation must prohibit companies from retaliating against consumers who exercise their statutory privacy rights, including by charging a higher price. For example, if a statute bars a company from processing a person’s data absent their consent, and that person withholds consent, the statute must bar the company from responding by charging a higher price.
Unfortunately, all three of these states that require consent to process precise geolocation information (Connecticut, New Jersey, and Virginia) have only weakly limited pay-for-privacy schemes. While all three prohibit discrimination against customers who withhold consent, all three also have a wide loophole: for discount programs. To make matters worse, none of these three states prevent the discount programs from selling customer data to third parties. But people should not have to surrender their data privacy to join a discount club for regular customers. Thus, the far better approach is to eschew this loophole, as in the ban on pay-for-privacy in last year’s location data privacy bills in Illinois and Massachusetts.
These exceptions allow companies to charge higher prices or downgrade service quality for users who exercise their privacy rights. In practice, this converts privacy into a privilege for those who can afford it, forcing economically vulnerable communities to trade away their sensitive location movements in exchange for essential discounts or services.
Dark PatternsAny law that requires consent also needs to ban company techniques that subvert consent. These are often called dark patterns, predatory design, and manipulative user interface (UI/UX) practices.
Connecticut’s definition of “consent” excludes “dark patterns,” as noted above. That state defines dark patterns as “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice,” including any practice that the FTC refers to as a dark pattern. Other consent-based privacy rules must do so, too.
ConclusionThe recent wave of state legislation demonstrates that momentum is building against location surveillance. However, state leaders must go further.
To build privacy protections that withstand corporate workaround attempts, future bills must apply to all locations universally, give individuals the legal standing to enforce their own rights in court, and fully prohibit pay-for-privacy. Until comprehensive data privacy legislation with real teeth is enacted nationwide, users can consult EFF's Surveillance Self-Defense Guide to learn practical steps for reducing location tracking on their personal devices.
LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?
This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch!
EFF answers all the queer digital rights questions you submit to us through our LGBT Q&A. You asked us: What’s one thing I can do today to improve my safety and security online as an LGBTQ+ person?
And for this question, we’ve brought in our friends from the Trevor Project to answer together:
Hi, I’m Tommy from the Trevor Project! The Trevor Project’s mission is to end suicide among lesbian, gay, bisexual, transgender, queer, and questioning (LGBTQ+) young people. Our vision is to create a world where all LGBTQ+ young people see a bright future for themselves.
EFF and the Trevor Project know that digital security and online safety can feel overwhelming, especially because we all have different levels of concern for different parts of our online lives. Some might be focused on the dangers of doxxing, another might only want to ensure they're not outed. And queer people can be particularly vulnerable to these kinds of online threats.
This might seem like a big task, but the one way you can do today to protect yourself is to revise the information you’ve shared with services and platforms to ensure you’re as in control of your information and data as possible:
Protect Your Personal InformationBe cautious about sharing sensitive details like your full name, address, school, phone number, and personal photos as it might expose identifying information you want to keep private. Consider using an avatar as your profile picture to avoid sharing your personal photos if that makes you more comfortable. Keep it lowkey when talking about work stuff or sharing details about where you’re studying.
If you do share personal photos, don’t accompany them with information that identifies your location or frequent whereabouts, and make sure EXIF data in photos is turned off (which could inadvertently include your location); the easiest way to do this is to take a screenshot of the photo and share that instead. Don’t post pictures with obvious spots in the background, like your front door or porch.
Understand the Importance of Login InformationWhen you create an account on websites and platforms, you can often use your phone number or a third party account, such as Facebook, Google, or Apple. These external accounts might share data with the apps you're logging into, but they can be helpful if you struggle with managing a lot of logins. Deciding if that trade-off is worth it is up to you but, when you can, use strong, unique passwords for your accounts, and be sure to enable two-factor authentication when offered.
Review Permissions with Social Media AppsReview which apps have access to things like your location and camera roll, and possibly change those permissions in line with what information you would like to keep private. Location is particularly important. For example, some apps might need some location information to function. But you can typically at least deny access to your device's "precise location" or enter in a city or zip code manually.
Consider What You Share When Speaking with Others OnlineIt’s important to be mindful of what you share with others when you post online or speak with people. Avoid disclosing sensitive information like financial details, and trust your gut if something feels off. It’s also useful to review your profile’s privacy settings and information now and again to make sure you’re still comfortable sharing what you’ve listed there.
Good privacy decisions begin with proper knowledge about your situation and a community-oriented approach. To dig in deeper, read EFF’s blog post on Building a Community Privacy Plan and the Trevor Project’s Guide to Online Safety for LGBTQ+ Young People.
