Feed aggregator
MIT engineers develop a magnetic transistor for more energy-efficient electronics
Transistors, the building blocks of modern electronics, are typically made of silicon. Because it’s a semiconductor, this material can control the flow of electricity in a circuit. But silicon has fundamental physical limits that restrict how compact and energy-efficient a transistor can be.
MIT researchers have now replaced silicon with a magnetic semiconductor, creating a magnetic transistor that could enable smaller, faster, and more energy-efficient circuits. The material’s magnetism strongly influences its electronic behavior, leading to more efficient control of the flow of electricity.
The team used a novel magnetic material and an optimization process that reduces the material’s defects, which boosts the transistor’s performance.
The material’s unique magnetic properties also allow for transistors with built-in memory, which would simplify circuit design and unlock new applications for high-performance electronics.
“People have known about magnets for thousands of years, but there are very limited ways to incorporate magnetism into electronics. We have shown a new way to efficiently utilize magnetism that opens up a lot of possibilities for future applications and research,” says Chung-Tao Chou, an MIT graduate student in the departments of Electrical Engineering and Computer Science (EECS) and Physics, and co-lead author of a paper on this advance.
Chou is joined on the paper by co-lead author Eugene Park, a graduate student in the Department of Materials Science and Engineering (DMSE); Julian Klein, a DMSE research scientist; Josep Ingla-Aynes, a postdoc in the MIT Plasma Science and Fusion Center; Jagadeesh S. Moodera, a senior research scientist in the Department of Physics; and senior authors Frances Ross, TDK Professor in DMSE; and Luqiao Liu, an associate professor in EECS, and a member of the Research Laboratory of Electronics; as well as others at the University of Chemistry and Technology in Prague. The paper appears today in Physical Review Letters.
Overcoming the limits
In an electronic device, silicon semiconductor transistors act like tiny light switches that turn a circuit on and off, or amplify weak signals in a communication system. They do this using a small input voltage.
But a fundamental physical limit of silicon semiconductors prevents a transistor from operating below a certain voltage, which hinders its energy efficiency.
To make more efficient electronics, researchers have spent decades working toward magnetic transistors that utilize electron spin to control the flow of electricity. Electron spin is a fundamental property that enables electrons to behave like tiny magnets.
So far, scientists have mostly been limited to using certain magnetic materials. These lack the favorable electronic properties of semiconductors, constraining device performance.
“In this work, we combine magnetism and semiconductor physics to realize useful spintronic devices,” Liu says.
The researchers replace the silicon in the surface layer of a transistor with chromium sulfur bromide, a two-dimensional material that acts as a magnetic semiconductor.
Due to the material’s structure, researchers can switch between two magnetic states very cleanly. This makes it ideal for use in a transistor that smoothly switches between “on” and “off.”
“One of the biggest challenges we faced was finding the right material. We tried many other materials that didn’t work,” Chou says.
They discovered that changing these magnetic states modifies the material’s electronic properties, enabling low-energy operation. And unlike many other 2D materials, chromium sulfur bromide remains stable in air.
To make a transistor, the researchers pattern electrodes onto a silicon substrate, then carefully align and transfer the 2D material on top. They use tape to pick up a tiny piece of material, only a few tens of nanometers thick, and place it onto the substrate.
“A lot of researchers will use solvents or glue to do the transfer, but transistors require a very clean surface. We eliminate all those risks by simplifying this step,” Chou says.
Leveraging magnetism
This lack of contamination enables their device to outperform existing magnetic transistors. Most others can only create a weak magnetic effect, changing the flow of current by a few percent or less. Their new transistor can switch or amplify the electric current by a factor of 10.
They use an external magnetic field to change the magnetic state of the material, switching the transistor using significantly less energy than would usually be required.
The material also allows them to control the magnetic states with electric current. This is important because engineers cannot apply magnetic fields to individual transistors in an electronic device. They need to control each one electrically.
The material’s magnetic properties could also enable transistors with built-in memory, simplifying the design of logic or memory circuits.
A typical memory device has a magnetic cell to store information and a transistor to read it out. Their method can combine both into one magnetic transistor.
“Now, not only are transistors turning on and off, they are also remembering information. And because we can switch the transistor with greater magnitude, the signal is much stronger so we can read out the information faster, and in a much more reliable way,” Liu says.
Building on this demonstration, the researchers plan to further study the use of electrical current to control the device. They are also working to make their method scalable so they can fabricate arrays of transistors.
This research was supported, in part, by the Semiconductor Research Corporation, the U.S. Defense Advanced Research Projects Agency (DARPA), the U.S. National Science Foundation (NSF), the U.S. Department of Energy, the U.S. Army Research Office, and the Czech Ministry of Education, Youth, and Sports. The work was partially carried out at the MIT.nano facilities.
The High Crime of “LMAO”: How Cops Are Treating Mass Surveillance As a Joke
Here's a riddle: Why did a Goshen Police Department officer search 6,474 automated license plate reader (ALPR) networks, representing data from 82,413 cameras, on May 7, 2025?
If your answer is "I don't know," it turns out you're 100% correct. The officer left the letters "idk" in the search field where cops are supposed to document the reason for the search.
When law enforcement and tech salespeople pitch ALPRs to city councils, they stick to a familiar script. They trumpet the technology, which is often provided by private companies like Flock Safety, Motorola Solutions, or Axon, as an essential tool for solving high-stakes crimes, such as car jacking, kidnapping, or murder.
But when you strip away the carefully curated talking points, the data continues to reveal a different (and frankly, ridiculous) story. An EFF analysis of ALPR search logs from Flock Safety systems shows that officers across the country are spying on drivers for completely nonsensical "reasons." Police are routinely searching the Flock database without providing any legitimate justification, making a mockery of our civil liberties by logging reasons like "LOL" (short for “laugh out loud”), "LMAO" (short for "laughing my ass off"), "sexy," and "idk" (short for “I don’t know”) to access sensitive ALPR location data.
And in some cases, officers are just mashing keyboard buttons rather than articulating the nature of their searches.
Flock Safety claims it has improved its system by requiring officers to select from a dropdown list of crimes before running a search–but that only makes it easier for officers to hide improper searches behind the veneer of uniformity. The system does not require proof that the dropdown reason actually matches the true purpose of the search.
With no warrant requirements, limited guardrails, and deficient audit processes, ALPR databases have fostered a culture of unrestricted access to everyone’s location information. This culture of abuse has allowed police to treat a mass surveillance network like their own personal search engine, permitting the tracking of the movements of everyday citizens for low-level complaints, personal whims, and sometimes, seemingly, for the lols.
A Documented Culture of AbuseALPR misuse isn’t a new phenomenon; it has dominated headlines for more than a year. We already know that officers regularly abuse these systems to stalk past and potential romantic partners. We’ve seen ALPRs used to surveil protests, which can chill First Amendment-protected dissent, and seen officers try to use an ALPR system to track down a woman seeking an abortion.
Typically, we learn about these uses from documents called "network audits," which are long spreadsheets that document all the searches that run through an agency's system. It is not unusual for even a small agency to have a record of millions of searches from thousands of external agencies across the United States.
We’ve also uncovered horrific systemic profiling, with more than 80 law enforcement agencies using terms like "roma" and "g*psy" to target ethnic Romani people—often without any mention of a suspected crime. And when police aren’t using ALPRs for stalking or profiling, they routinely use them for extreme low-level investigations: verifying whether a student lives in a specific school zone, running employment background checks, following up on loud music complaints, or targeting a motorcyclist simply for holding a cell phone.
But somehow, it gets worse.
The Absurdity of Documented Search ReasonsEFF’s analysis of Flock Safety’s ALPR search data obtained through public records requests has uncovered a disturbing trend. In the absence of judicial oversight, officers are inputting ridiculously unserious terms to justify their searches. Here is just a snapshot of what police consider a "reason" to track someone’s vehicle:
Surveillance as a JokeAudit logs sample
- Barberton Police Department (Ohio) employees ran numerous searches between March 2024 and May 2026, listing “LOL” or “lol” as the reason.
- Harris County Sheriff's Office (Texas) employees ran several searches between April and May 2026 listing “LOL” or “lol” as the case number.
- Lake County Sheriff's Department (Ind.) employees ran searches in July 2025 for “LMAO.”
- Richmond Police Department (Calif.) employees ran over multiple searches in November 2024 for “Hehe.”
- Riverside County Sheriff's Department (Calif.) employees ran searches in 2024 for “Haha.”
- Kankakee County, Sheriff's Office (Ill.) employees ran searches (2023–2025) for “idk” or “idk lol.”
- Goshen Police Department (Ind.) ran searches (May–June 2025) for “idk.”
- Fishers Police Department (Ind.) ran searches in May 2025 for “blah.”
- A Pasco Police Department (Wash.) employee searched for at least four different license plates, leaving "robbery i don't remember the case number leave me alone" in the reason field.
- The San Diego Sheriff's Department (Calif.) ran searches in May 2025 with "idk" in the reason field.
- More than 30 agencies ran more than 6,300 searches with "TBD" (short for "To Be Determined") as the "reason." These included the Arizona Department of Public Safety, the Manteca Police Department (Calif.), and the Baton Rouge Police Department (La.). The Priceville Police Department (Ala.) alone ran 1,954 searches with reasons "TBD."
- Belton Police Department (Mo.) ran searches (Aug–Sept 2024) for “d*ckhead.” (asterisk/redaction our own)
- A Manteca Police Department (Ill.) employee ran searches in June 2024 for “sh*thead” (asterisk/redaction our own)
- A Norton Police Department (Mass.) employee ran searches in December 2024 for “Sexy.”
- Corona Police Department (Calif.) employees ran searches (2023–2025) for “weird” or “WEIRD KID.”
- Thornton Police Department (Colo.) employees ran several searches in October 2025 for “driving around being weird.”
- A Columbus Police Department (Ohio) officer ran searches in 2023 for “idiot.”
- A Michigan City Police Department Officer (Ind.) ran searches in June 2025 listing “f*ck this new search engine.” (asterisk/redaction our own)
Button mashing audit logs sample
One of the more alarming discoveries we found in the network audit data is a large number of "reasons" that appear to be nothing more than an officer mashing buttons. These typically involve a nonsensical long string of characters from the same line or area of the keyboard.
For example:
- An Eatonton Police Department (Ga.) employee ran searches with reasons such as HJKNUILH, uiokjk.kuj, GJLHBNMN, hjhbnmg, and iuohjk.
- An Atlanta Police Department (Ga.) employee ran searches with asdfga as the reason.
- Bay County Sheriff's Office (Fla.) employees ran searches with reasons such as ;'lkjh, /lkjh and lkjhg.
- A Brown County Sheriff's Office (Wis.) employee ran searches with reasons such as gyghkkghghjkghjk, ggyjgyujdsrdghdfhjkghjghk, HJHJKLHLKHJK, hjjkjkhjkljk and JHLJKHHJKL.
- A Lake County Sheriff's Office (Ohio) employee ran searches with reasons such as asdfg and ghjkl, and a second officer ran a series of searches that started off with "investigation" but then devolved into button mashing, including:
- Investigatafy, Investigatafyd, Investigatafydl, Investigatafydlh, investigatafydlhj, investigatafydlhji, investigatafyfdlhji, investigatafyfdlhjigkfgty, investigatafyfdlhjigkfgtyy, investigatafyfdlhjij, investigatafyfdlhjik, investigatafyfdlhjikf, investigatafyfdlhjikfg, investigatafyfdlhjikfgty, investigatafyfdlhjikfgy and investigatafyfdlhjiy.
- A Moore Police Department (Okla.) ran searches with reasons such as jhjhjkhj, jhjkhjh, jhjkhjkh, jkhhkjhjk, Jkhjkhj, Jkhjkhjk, Jkhjkhjkh, jkhjkhkjh, jkjkhjkh, kjjkhjk, loiuiou, ukjhjkh and ulkuiou.
- A Westlake Police Department (Ohio) employee ran searches with reasons such as fghjkl, ghjkl, and lkjhg.
- A Kentucky State Police employee ran searches with reasons such as mhghjk, mhgnhjkj, nbvcxcvbn, nmbvcbnm, and sdfghj.
It's hard to imagine a situation where these characters add up to a legitimate police code. However, it's easy to imagine an officer cutting corners with a text field they know no one is checking, especially if they are accessing the Flock Safety app from their phones while driving.
How Police Departments Are RespondingWhen confronted with these flagrantly unserious searches, police departments offered a mix of bureaucratic deflections and excuses.
In response to EFF’s request for comment, Thornton Police Department (Colo.) claimed the system didn't require officers to select from a defined list at the time, but it does today. They also audited the “driving around being weird” searches, claiming they were all actually for "legitimate public safety purposes."
Other police departments we reached out to for comment shared the following:
- Richmond Police Department (Calif.) stated that the officers involved with the "Hehe" and "idk" searches were "counseled."
- Corona Police Department (Calif.) noted that the employees searching for "WEIRD KID" are no longer employed by the city for unrelated reasons.
- Columbus Police Department (Ohio) pointed to their union contract, stating their Inspector General only has jurisdiction to investigate incidents within the last 90 days, giving the officer who searched for "idiot" in 2023 a free pass.
- Belton Police Department (Mo.) promised a "thorough investigation" of the "d*ckhead" searches through existing union and personnel policies.
- Manteno Police Department (Ill.) said it will "review the searches and the circumstances surrounding them thoroughly" and "take whatever action is determined to be appropriate based on the facts and circumstances.”
- Manteca Police Department (Calif.) said: "Since the beginning of 2026, our personnel have been directed that the reason field for ALPR searches must identify the law enforcement purpose for the search and that 'TBD' is not an acceptable entry." The spokesperson added: "The presence of 'TBD' in the reason field in prior searches should not, by itself, be interpreted to mean that the associated search was conducted without a legitimate law enforcement purpose or that reasonable suspicion was required." EFF has asked the agency to clarify whether it verified the hundreds of "TBD" searches were legitimate, and we will update this post with a response if we receive one.
- Fishers Police Department (Ind.) said that the detective that searched for “blah” has done so “when he has issues with the technology” and that the term “is used when he is actively using the technology to solve a criminal case, and the technology is not moving fast enough for him.” The department shared that “he has been told to use “test” in the future.”
- The Cobb County Police Department (Ga.) acknowledged that "TBD" stood for "To Be Determined" and is no longer an acceptable search reason: "We have instituted a new policy that took place after the dates listed in your audit that now require, in addition to a criminal offense and a reason, a case number for any search conducted on FLOCK."
- The San Diego County Sheriff's Department says that it checked the cases where "idk" was used and determined "there was an active investigation associated with the searches." The department said that this was due to the reason field being optional at the time (which was true on a software level) but California law has required officers to document a purpose for accessing ALPR data since 2015. The sheriff's spokesperson says the reason field is now mandatory, and involves a dropdown menu.
Other agencies did not respond to EFF’s requests for comment. We will update with responses as they are received.
The Cop Out of the Drop-Down Menu “Feature Update”Under the guise of streamlining audit logs, in late 2025, Flock safety announced that they will be replacing the required, free-text search “reasons” with a pre-populated dropdown menu of generic offense categories. Since this update, officers are no longer required to type out why they are digging through a driver's movement history, and instead can select a pre-packaged option like "Traffic infraction" or “Other” in half a second.
Replacing the requirement to articulate the reason for the search with one-click searches is a loss for transparency, but also may explain why audit logs including the searches we highlight in this piece significantly decreased since early 2026.
The Punchline is Our PrivacyEntries like these defeat transparency, undermine accountability, and entirely fail to satisfy what many jurisdictions require by law or policy: an actual reason for the search. And this keeps happening because police use ALPRs as a convenient shortcut around constitutional privacy safeguards.
In other contexts, such as searches of cell phone location information, police have to go to a judge, demonstrate probable cause, and get a search warrant. But because laws and courts have not caught up with the pace of ALPR technology, police do not do the same before searching ALPR databases. Instead, they are given free rein to track a person’s movements without a sliver of judicial oversight.
As we mention in our piece about the use of ALPR surveillance for low-level investigations, if a police chief stood in front of a city council and asked for permission to install hundreds of cameras just so his officers could investigate the high crime of "haha," they would be laughed out of the room. The same could be said if an officer asked a judge to sign a warrant to track someone down for "LOL."
The fact that these searches were not only missed by the agency supervising the officer, but by the often thousands of other agencies whose systems were searched, demonstrates how agencies cannot be trusted to oversee themselves.
Mass surveillance is incompatible with a free society, and especially so when the people with access to this data are treating it like a joke. This ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. But because it does, EFF continues to urge courts and state legislatures to immediately step in and impose strict, enforceable restrictions to rein in this abuse. At an absolute minimum, this means mandating rigid data deletion deadlines and an ironclad warrant requirement.
If police want the power to track a person's movements, they must be required to convince a judge with evidence and probable cause. They should not be able to bypass the Constitution with a search for "haha."
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an ...
Marine carbon removal at a crossroads
Nature Climate Change, Published online: 14 September 2026; doi:10.1038/s41558-026-02740-8
Marine carbon dioxide removal must advance through rigorous, transparent science, but caution cannot become paralysis. With billions of tonnes of carbon removal likely to be needed each year, we need to test promising approaches responsibly while uncertainty remains.Friday Squid Blogging: Rotting Squid on a Beached California Boat
Smells awful:
But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.
Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.
“If you think about what happens after four or five days, it’s a gooey mess,” he said.
The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan...
Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans
Governor Newsom signed a package of 12 bills yesterday aimed at “protecting children” online. One of them was AB 1709, which EFF has opposed this legislative session and serves as a functional ban on young people under 16 using social media. However, EFF supported two of the bills signed into law, AB 2071 and AB 2298, which require that children learn critical digital literacy and cybersecurity topics. The bills are an affirmative and constitutional way for the state to address valid concerns about young people’s internet use without violating their First Amendment rights.
Unlike blanket bans, A.B. 2071 and A.B. 2298 address online safety through education rather than prohibition. Young people rely on the internet not just for entertainment, but for civic engagement, education, self-expression, and community—especially vulnerable youth who may lack support in their physical surroundings. This is why real digital safety comes from preparation, not isolation. Research consistently shows that open, honest conversations about digital literacy and privacy with trusted adults are far more effective at protecting youth than restrictive censorship laws. Young people themselves recognize this need; in fact, A.B. 2071 was co-authored by a group of students actively seeking better resources to navigate their digital lives safely.
Education vs. CensorshipA.B. 2071 and A.B. 2298 fill critical gaps in California’s school curricula by equipping students with actionable skills. A.B. 2071 integrates digital wellness into middle and high school health classes, teaching students how to identify unhealthy tech habits, protect their personal safety, and evaluate digital content—including AI-generated media—for credibility and bias. Meanwhile, A.B. 2298 adds cybersecurity concepts to recommended school curricula, teaching young people how to safeguard their personal data from online threats.
While the state’s turn toward social media bans remains a harmful and misguided policy direction, the passage and signing of A.B. 2071 and A.B. 2298 show there is a better way. Lawmakers must stop treating censorship as a quick fix and instead focus on constitutional, empowering solutions that give youth the tools they need to thrive online.
My Talk at DEF CON
Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.
Also online is an interview with me in the AI Village.
Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy
Amazon recently debuted a new feature for its Ring cameras that the company is calling Throw Away the Key Encryption (TAKE). The idea is to cut back on the amount of video content available to the company, and thus potentially available to law enforcement. But while it might technically add a speed bump to accessing full video content, it doesn’t deliver nearly the level of privacy we should be demanding from video doorbells and other security cameras.
TAKE introduces a new way for Ring to manage encryption keys, where the user’s device has its key, then the company holds encryption keys temporarily within its own cloud infrastructure. Ring’s servers receive the keys temporarily so it can offer a variety of the features it says it can’t offer when a user chooses to use end-to-end encryption, like video descriptions, smart alerts, video search, and more, then deletes the key after 24 hours.
This differs from how it works now, where footage is encrypted in transit and at rest, then decrypted by Ring, which always has access to the footage, to process those features.
Comparatively, this is an improvement to the default settings Ring has now, because it at least puts some restrictions on historical footage, but it has some serious holes worth exploring.
Ring Gets Access to Unencrypted Video for a Short PeriodRing has designed its service so many of its camera features, including smart alerts and video search, need cloud processing to work. That means to provide those features, Ring needs to decrypt the footage while it’s stored in Ring’s cloud servers.
With TAKE, in order to decrypt footage to offer these features, Ring gets access to footage stored in the cloud for 24 hours. TAKE adds some small measures using secure enclaves to make base key material harder to directly export, but keys are still released to services that can be modified. With access to the keys, the cloud processing does its thing and delivers the requested feature to the user. The key is then deleted 24 hours later—until the user wants to watch an old video or use other so-called “smart” features, at which point the keys are sent back to the server.
In practice, that makes the system as a whole barely different from encryption at rest where the server holds the keys. The client device essentially takes the place of a hardware security module (HSM), including making those keys available to the server whenever they’re needed. The end result is an improvement from the status quo, but still not even close to the privacy protections of end-to-end encryption.
The company says it does not keep backups of the keys and there’s no way for a Ring employee to access footage. It also claims that any decrypted content is deleted from its servers.
But that doesn’t mean much when user actions send the keys back to the server. And making features like “Video Search” and “Smart Video Descriptions” available to the device owner means that while the footage can’t be seen by Ring, descriptions are readily available to the company. In response to a question about capability, Ring responded to us that, “As Ring continues to expand and further strengthen TAKE's protections, video descriptions will be included.”
Plus, account recovery keys are stored in the camera itself by default. When that’s paired with the fact that currently, indices of video contents are available to the company, it means that TAKE isn’t even a protection against mass surveillance. Law enforcement could request a mass search across cameras for certain terms, then delve into further details by seizing cameras of interest from the device-owner, decrypting account backups, and using that information to decrypt encrypted videos.
Law Enforcement May Still Seek to Compel Access to FootageBecause of the ways the access and key rotations work, it’s technically still possible for Ring to alter its current practice if compelled to do so by law enforcement, in much the same way as other existing encryption-at-rest systems where the company holds the keys. For example, Ring could receive an order that demands they save content encryption keys or unencrypted videos from memory to disk, which would mean they’d retain some level of access.
In an email to EFF, Ring stated, “By design, under TAKE, Ring will not be able to provide encryption keys or decrypted content. With TAKE, Ring will only preserve and provide encrypted video files in response to valid legal process. It has been and continues to be Ring's policy to object to overbroad legal requests.” EFF specifically asked about the possibility of complying with law enforcement orders to modify existing practice to turn over or preserve unencrypted video, which appears to be technically possible, but the company did not address it.
End-to-end encryption works to maintain trust by its user base because the company that employs it never has access to the keys at any point, making it impossible for itself to access the encrypted contents. This also means law enforcement can’t demand the service retain keys or choose not to rotate them. As described, this level of protection isn’t offered with TAKE.
Ultimately, Ring is the one managing this software and its implementation, and beyond a white paper, “trust us” is the only level of verification they’re offering outside observers. While it doesn’t fix the issues, at the bare minimum, the company needs to open the entire infrastructure up to third-party auditors to verify its claims. Ring seems to agree, as they told us that, “Ring conducts rigorous security reviews of all products before launch and critical components of TAKE’s infrastructure underwent independent security testing prior to launch. We are exploring options for further independent review.”
TAKE is not end-to-end encryption, where Ring would never have access to the keys, and the company thankfully doesn’t claim it as such. Ring already offers the option for end-to-end encryption, and turning that on by default would offer the real sorts of privacy improvements we all want from video doorbells.
Lifesaving Lincoln Laboratory device wins 2026 Excellence in Technology Transfer Award
The Federal Laboratory Consortium (FLC) selected AI-GUIDE, a medical device developed by MIT Lincoln Laboratory and Massachusetts General Hospital (MGH), for its 2026 Excellence in Technology Transfer Award. This award recognizes federal laboratories and collaborators who have accomplished outstanding work in the process of transferring technology. With funding from the U.S. Army's Combat Casualty Care Research Program (CCC), Lincoln Laboratory and MGH developed AI-GUIDE and are in the process of transferring the prototype to the startup company AutonomUS Medical Technologies, Inc.
"This recognition reflects what effective technology transfer looks like — aligning the Army's operational need with Mass General's clinical expertise and Lincoln Laboratory's engineering capabilities to deliver a solution with a clear path to impact. The transition to AutonomUS underscores how strong partnerships can carry a technology from development into real-world adoption," says Asha Rajagopal, Lincoln Laboratory's chief technology transfer officer.
AI-GUIDE's transition to industry promises improved health outcomes for injured service members and civilians. Unlike ultrasound devices typically found in hospitals, AI-GUIDE is small and portable, making it ideal for use in pre-hospital settings. Pairing custom-developed AI software with commercial handheld ultrasound technology, AI-GUIDE helps the user insert a guidewire and catheter into a patient's blood vessel. This capability is especially important for U.S. military medics, who must keep injured soldiers alive in the field — sometimes for days — before they can be evacuated to a hospital. AI-GUIDE allows medics with minimal specialized training to administer medical interventions that would otherwise be impossible outside of the hospital, drastically improving patients’ chances of survival.
The AI-GUIDE project has served as a framework for effective technology development and transfer. Within just three years, AI-GUIDE went from an idea proposed by CCC to a fully working proof-of-concept technology with its own startup company. Once the prototype was developed, clinical testing at MGH proved its viability, and Lincoln Laboratory and MGH staff then founded AutonomUS Medical Technologies to facilitate the commercialization process. With support from the MIT Technology Licensing Office, Lincoln Laboratory Technology Transfer Office, and CCC, the company secured U.S. Food and Drug Administration (FDA) Breakthrough Device Designation, a regulatory fast-track pathway that is only granted to highly innovative technologies with lifesaving potential, as well as a Small Business Innovation Research grant from the U.S. Department of the Air Force and funding from private investors, the Department of War, and the National Institutes of Health.
These strong technology transfer collaborations are designed to streamline the transfer process, ensuring that lifesaving capabilities can be made available to military personnel and civilians as quickly as possible. While much of the initial work on vascular access has already been transferred, the AI-GUIDE team continues to develop and transition additional capabilities, including peripheral nerve block technology for trauma care and pain management. AI-GUIDE has previously been recognized with a Lincoln Laboratory Best Invention Award and an R&D 100 Award.
"Lincoln Laboratory has a long record of transferring technology to industry. We are honored and proud to be recognized for the transfer of AI‑GUIDE and look forward to seeing the technology commercialized and saving lives in the field. This achievement reflects the strength of the partnership among the Defense Health Agency, Lincoln Laboratory, Massachusetts General Hospital, and AutonomUS Medical Technologies," says Samuel Kesner, a technical staff member in the Systems Engineering Group, who currently oversees the AI-GUIDE program at Lincoln Laboratory.
Winning team members from the laboratory include Brian Telfer, Samuel Kesner, Lars Gjesteby, Joshua Werblin, Benjamin Roop, Alec Carruthers, Nancy DeLosa, and former Lincoln Laboratory staff members Matt Johnson (now the vice president of engineering at AutonomUS) and Laura Brattain (now an associate professor at the University of Central Florida). Asha Rajagopal, Jordan Mizerak, Melly Coronado, and Jonathan Dan supported technology transfer efforts.
Cliff Stoll’s DEF CON Talk
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago.
Great fun.
Compound and heterogeneous relationships between climate extremes and global net migration
Nature Climate Change, Published online: 11 September 2026; doi:10.1038/s41558-026-02752-4
Climate extremes influence migration, but their long-term and compounding impacts are understudied. The authors show that associations between climate extremes and migration vary by hazard type, timing, the occurrence of consecutive events and local socioeconomic conditions.Divergence between physical and emotional heat resilience in Chinese cities
Nature Climate Change, Published online: 11 September 2026; doi:10.1038/s41558-026-02732-8
Heatwaves threaten both physical and mental health, yet physical heat exposure and emotional responses often diverge. The study shows that 84.9% of Chinese cities experienced severe emotional shocks, compared with 52.1% facing severe heat exposure, driven by socioeconomic and environmental factors.We All Deserve a Better Internet, Not A Smaller One
SAN FRANCISCO - Technology and the laws that regulate it should support and empower young people. California’s AB 1709 - signed into law today by Gov. Gavin Newsom - falls far short of this goal, say the Electronic Frontier Foundation (EFF) and its allies.
Using technology is how we learn and build community in today’s world. Laws such as AB 1709, a functional ban on social media use for people under the age of 16, instead cut young people off from essential information and experiences. That particularly harms those already facing increased challenges, who often find safety in supportive online communities that they can’t always access in the physical world.
"California should be passing laws to ensure that technology really works for people of all ages, not enacting social media bans that cut young people off from digital lifelines, communities, and speech," said EFF Associate Director of State Affairs Rindala Alajaji. "Denying minors access to digital forums - or stripping out basic tools needed to navigate them - is not going to help make young people safer or healthier in the AI age."
Research shows social media bans are ineffectual, while also denying young people opportunities to develop their own voices and perspectives—to share their art, practice religion or engage in politics.
Age-gating requirements also force everyone to give up more personal information. To verify who can pass through their online gates, companies will collect even more data, and this further concentrates power in the hands of companies, rather than protecting people.
AB 1709 is also inconsistent with rights to free expression and California will be spending resources to defend a law tied up in court. Instead, we should redouble our efforts to get technology laws right—and support the passage of new robust privacy laws that target surveillance business models. That’s how we protect everyone in the AI age.
Young people should be able to use technology in safe and healthy ways. The Golden State should model the gold standard laws that ensure technology works for everyone, rather than shut down access to digital forums in ways that do more harm than good.
"Social media bans like AB1709 make kids less safe, while undermining privacy and freedom of expression for everyone,” said Evan Greer, Director of Fight for the Future. “Young people have been on the forefront of every social movement throughout history that has led to positive social change. We need policies that empower young people rather than silencing them. These kid-focused bans are a gift to Big Tech giants, allowing them to continue operating their harmful business model while incentivizing them to collect even more data. California lawmakers should be ashamed. They didn't do anything to protect the kids, they just used kids as pawns to make good headlines."
“In a world of increasing stigma and marginalization for LGBTQ+ families, AB 1709 continues that trend by stripping people with LGBTQ+ parents of the ability to meet and build community with one another on the internet” said Jordan Wilson, Executive Director of COLAGE. “Beyond obstructing the right of youth with LGBTQ+ parents to access information, this bill places an undue burden on all Californians by forcing age verification at a time when digital privacy rights are being eroded globally. We cannot ‘protect children’ by stripping them of their primary avenue for connection.”
Contact: RindalaAlajajiAssociate Director of State Affairsrin@eff.orgAIs Compress Exploit Timeline
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.
Simon Willison comments:
Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe...
Where global warming meets urban development
Nature Climate Change, Published online: 10 September 2026; doi:10.1038/s41558-026-02743-5
Global warming and urban development combine to shape the temperatures people experience in cities. Here I revisit a 2016 attribution study of urban warming in China and consider what its legacy reveals about urban climate knowledge, responsibility and action.Greening masks stability loss in drylands
Nature Climate Change, Published online: 10 September 2026; doi:10.1038/s41558-026-02733-7
The authors consider greening trends and interannual variability, linked to ecosystem stability, in dryland ecosystems across 40 years (1982–2020). They show persistent greening yet increased interannual variability, with the latter driven by increasing rainfall sensitivity.MIT Schwarzman College of Computing launches pilot to help educators teach AI across disciplines
This summer, the MIT Schwarzman College of Computing welcomed faculty from colleges and universities across Greater Boston, South Carolina, West Virginia, and Texas to campus for the inaugural AI Educators Pilot, a weeklong workshop aimed at expanding how artificial intelligence is taught across disciplines and learning environments.
Inspired by MIT class C01/C51 (Modeling with Machine Learning), a course developed through the Common Ground for computing and AI education that focuses on helping students understand and apply foundational AI and machine learning concepts to problem-solving in their own disciplines, the workshop gave educators an opportunity to explore how its materials and teaching methods could be adapted for their classrooms.
“The broader goal is to expand AI education to more students by investing in training for instructors,” says Dan Huttenlocher, dean of the MIT Schwarzman College of Computing and the Panasonic Professor of Electrical Engineering and Computer Science (EECS).
“We want to empower students to become critical thinkers about AI, not just users of the technology,” says Asu Ozdaglar, deputy dean of academics for the MIT Schwarzman College and department head of EECS.
A collaborative model for expanding AI education
Bringing the program to life required broad collaboration across the college, including support from leadership, staff, and contributions from more than half a dozen instructors in fields ranging from finance and computer science to sustainability. Together, they helped shape a workshop that paired core technical concepts with examples and teaching materials adaptable to a range of classroom settings.
“I have not seen an effort quite like it — this many dedicated instructors assembling materials of this richness, all to equip the educators who serve their students,” says Saurabh Amin, the Edmund K. Turner Professor in Civil Engineering and faculty director of the AI Educators Pilot. Amin is also co-director of the Operations Research Center, which is jointly housed within the MIT Schwarzman College of Computing and MIT Sloan School of Management.
With support provided by Jake and Robin Reynolds, the pilot brought together 19 participants in July from Allen University, Babson College, Brandeis University, Marshall University, the University of Massachusetts at Lowell, the University of North Texas, and Wentworth Institute of Technology. Working alongside MIT faculty and instructors, participants explored the pedagogy behind Modeling with Machine Learning through a mix of demos, videos, and exercises, and collaborated in hands-on activities focused on translating the course’s materials and methods to their own classrooms.
“This opportunity has been very timely because we are starting an AI and data science program in my department,” says Wenjin Zhou, assistant professor of computer science at UMass Lowell. “We’ve already been thinking about: How do we teach our next generation of computer scientists within the area of AI? How do we integrate AI in the teaching? I wanted to learn more about how other people are doing it, and especially answer the question: If AI can create tools for anyone now, what does a computer scientist do?”
Moving beyond the black box
When it comes to AI, Amin notes, there is no shortage of high-quality material. What is usually missing is context: Opportunities for instructors and students to connect AI concepts to specific disciplines, problems, and ways of thinking. Those connections are often built through dialogue and reasoning, rather than by presenting AI as a fixed set of ideas to be received. But instructor capacity remains one of the scarcest resources.
“What is scarce are educators prepared to teach AI as more than a fixed body of concepts and tools, to ground it in their own field, help students use it with judgment, and demystify it, so students do not just apply models but learn to question, adapt, and build with them,” explains Amin.
Shen Shen, an EECS lecturer and one of the workshop instructors, adds, “How do we make sure that machine learning is not just a black box, nor this magic piece of new technology? You can think of it as a tool, or a new framing to help you solve the problem in your specific domain.”
From pilot workshop to educator network
Participants ended the week by reflecting on which workshop materials and teaching approaches they planned to adapt for their disciplines and courses. Their feedback will help shape future iterations of the pilot and support the development of a broader network of educators committed to expanding AI education across diverse learning environments.
Weijie Pang, an assistant professor of computer science at the Wentworth Institute of Technology who attended the workshop, looks most forward to ongoing community building activities. “This is a really valuable opportunity to communicate with other faculty from different majors and areas. I can see what other universities are doing and what we can learn from each other,” she says.
“It's helpful to know that everybody within different disciplines at different universities is struggling with the same questions of how we can best serve our students as the technology is changing. Hopefully, we can set them up for success by being a little bit more forward and anticipatory of what the AI use is going to be,” says Dylan Cashman, an assistant professor of computer science at Brandeis University.
Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR
Law enforcement agencies across the country are increasingly relying on spying technologies—automated license plate readers (ALPR), cell-site simulators, and facial recognition, to name a few--causing an outcry in many communities where people are rightly concerned about the threat to civil rights and civil liberties these tools present.
Some authorities are responding to these concerns by trying to hide what they’re doing. Police departments are telling officers not to mention ALPRs when stopping vehicles and concealing their use of ALPRs to avoid citizens’ public records requests. Concealing the use of unpopular spying tools isn’t anything particularly new for law enforcement—cops have been doing it for years—but it’s just as wrong now as it was 20 years ago.
These practices prevent the public from knowing about and questioning how agencies are spending taxpayer dollars on spying technologies and holding them accountable. This is especially troubling when many towns are signing contracts with Flock and other ALPR vendors with little to no public oversight. The practice also violates disclosure obligations, allows cops and prosecutors to hide their tactics from judges, and cheats defendants from being able to challenge the use of evidence gathered by spy tech from being used against them.
404 Media recently revealed that in its usage policy for Flock ALPR cameras, one county in Iowa tells police to keep them a secret when detaining people: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.” If writing a report about an incident, police are told to say they used “county resources” in making a stop instead of acknowledging use of ALPRs.
In Houston, police officers are likewise instructed to “be as vague as permissible” about why they are using Flock because the searches they run on Flock’s surveillance system could be obtained via public records requests.
There is growing public alarm about the threat to civil liberties posed by ALPR cameras and reports of police abusing the tech by using it to spy on their exes. Some cities have the cameras covered up, and others are cancelling their use of ALPR networks. Two states have recently stepped back from ALPRs. This trend is certainly not lost on law enforcement agencies. Hiding the fact that they’re using ALPRs from Flock and other vendors is one way of avoiding scrutiny and bad PR.
But law enforcement and their spy tech vendors keeping people in the dark about the surveillance technologies trained on them predates the Flock backlash by decades. For example, AT&T built a powerful phone surveillance tool for police, called Hemisphere, in the mid 2000s, and the company required agencies not to use evidence gathered by Hemisphere in court unless there was no other admissible evidence. If evidence obtained through Hemisphere was used, police were required to recreate it through a traditional subpoena, a process they called “parallel construction.” We called it “evidence laundering.”
Likewise, police and prosecutors have taken far-reaching steps to hide from the public and courts their use of cell site simulators, also known as stingrays. Police have used these devices, which trick cell phones into connecting to them instead of phone towers to try locating suspects, to obtain people’s location data without a warrant by deceptively obtaining basic pen register orders from courts. Pen register orders are for obtaining call log data and police don’t need to prove they have probable cause to get one.
In Baltimore, for example, a judge concluded that law enforcement had used a standard pen register order to intentionally hide its use of a Stingray from the court in violation of its legal disclosure obligations, leading to a landmark 2015 privacy ruling that cops need a warrant to use the device.
That didn’t stop police from continuing to try to pull the wool over the eyes of courts and defense attorneys when they used stingrays, however. Prosecutors have accepted plea deals to hide their use of cell-site simulators and have even dropped cases rather than reveal information about their use of the technology. U.S. Marshalls have driven files hundreds of miles to thwart public records requests.
Fortunately, our commitment to shining a light on the use of surveillance tech is just as strong, if not stronger, than law enforcement’s quest to hide it. We’re working with privacy advocates and community groups to bring awareness about existing and emerging spy tools that threaten civil liberties and we’re encouraging policymakers and lawmakers to do more to restrain warrantless mass surveillance and stop it before it ever takes hold.
If you're curious about whether your local police have contracts for ALPRS or other surveillance technologies, you can search EFF's Atlas of Surveillance.
Injectable nanodevices could provide effective treatment for drug-resistant glioblastoma
The brain cancer glioblastoma is one of the most aggressive and treatment-resistant cancers known to medicine, carrying a median survival of just 12-15 months, even with the best available care. Now, researchers at the MIT Media Lab have developed injectable nanoantennas, each about one-hundredth the width of human hair, that can be magnetically activated to create localized therapeutic electric fields that target and kill brain cancer cells without damaging healthy brain tissue.
“In laboratory and animal studies, this approach significantly reduced tumor growth and extended survival without detectable side effects, highlighting its potential as a precise and safe brain cancer therapy,” says Deblina Sarkar, associate professor and AT&T Career Development Chair at the MIT Media Lab and head of the Nano-Cybernetic Biotrek group.
The researchers named their technology “HITMAN” — short for highly-localized electric-field-induced tumor therapy using magnetically actuated nanoantennas.
An open-access paper describing this technology published today in Science Advances.
To test HITMAN against the most clinically realistic version of this disease, the research team worked with tumor tissue obtained from patients diagnosed with aggressive and chemotherapy-resistant glioblastoma at Mayo Clinic. Using cells derived from this tissue in the laboratory, the researchers demonstrated that HITMAN eliminated 52.2 percent of these drug-resistant cancer cells — more than five times than that achieved by the standard chemotherapy drug temozolomide (TMZ) — while leaving healthy neurons and brain-supporting astrocytes unharmed.
The team then implanted those patient-derived tumor cells into the brains of mice to recreate the disease in a living system. In these orthotopic animal models — widely regarded as the gold standard for preclinical brain tumor research — HITMAN substantially inhibited tumor growth, extending median survival by more than 50 percent with no detectable toxicity to major organs or surrounding healthy tissue.
The injectable nanoantennas can be activated wirelessly from outside the body, with the application of a low-frequency (no higher than 200 kHz, to prevent tissue-damaging heat) magnetic field that can penetrate the skull and brain tissue. The magnetic field actuates parts within the nanoantennas made of magnetostrictive material, creating stress and strain, which result in deformation of a piezoelectric film, producing localized electric fields.
Such localized electric fields were demonstrated to preferentially attack glioblastoma at the cellular level, disrupting the cells’ inherent bioelectric currents and fields, which regulate cellular function. Such disruption provoked a number of antitumor mechanisms, including protein unfolding, membrane damage, and endoplasmic reticulum stress, curtailing the production of a cell’s functional proteins. Such forms of cell dysfunction led to cell death. According to the researchers, cancer cells were selectively targeted over healthy cells due to their high proliferative rate, which elevates protein-folding demand, as well as their characteristic abnormalities in membrane composition and intracellular organelles.
Among a wide array of control experiments, the researchers also exposed glioblastoma cells to the nanoantennas without applying a magnetic field, as well as exposing the cancer cells to a magnetic field alone, confirming that the demonstrated effects were in fact due to the nanoantennas and their magnetic field activation. They also tested for side effects damaging to the animal models’ major organs — kidneys, liver, spleen, lungs, and heart — and detected none.
Also demonstrated by the research was a significant reduction in the number of cancer cell colonies formed after application of the nanoantennas, from 112-150 in the control groups to just 26 in the experimental group, indicating significant potential to reduce tumor recurrence and metastasis.
If translated to clinical use, the nanoantennas, whose size is approximately 150 nanometers, could be injected through the skull. Sarkar points out, however, that a technology developed previously in her lab could make their deployment even simpler.
In 2025, Sarkar and her colleagues created “circulatronics,” a technology that could allow devices like the HITMAN nanoantennas to be administered through an injection in a patient’s arm and to travel to a target region of the brain. In that previous work, the electronic devices were integrated with living cells so they would not be attacked by the body’s immune system and could easily cross the blood-brain barrier, as was demonstrated in pre-clinical studies.
A glioblastoma diagnosis comes with formidable treatment challenges. Because this type of cancer is extremely infiltrative, complete tumor removal is difficult to achieve and can affect cognitive function. Also, the tumors often resist radiotherapy and chemotherapy, and immunotherapy is challenged by an immunosuppressive tumor environment.
“The persistent failure of these therapies underscores the urgent need for novel approaches to target treatment-resistant glioblastoma cells,” the researchers write. “HITMAN offers a minimally invasive, spatially precise, and clinically translatable therapy for glioblastoma.”
Sarkar is joined on the paper by other members of her lab, including Monochura Saha, a former MIT postdoc; Ishaq Khan, a former MIT senior postdoc; Baju Joy, Shun Ying Chen, Hao-Tung Yang, Preet Patel, and Pengrui Zhang, all MIT graduate students; and Faheem Azeemi, an MIT undergraduate student.
Digital Sovereignty: What It Is, What It Could Be
The term “digital sovereignty” has become ubiquitous. European officials invoke it in debates about cloud infrastructure, AI, semiconductors, and platform regulation. Governments throughout the global majority use it to argue for greater control over data and communications infrastructure and boost their economies. Companies market “sovereign cloud” products designed to reassure their customers that their information stays under local jurisdiction. But digital sovereignty could be something more: an opportunity for users around the world to build more resilient, open systems and the skills and infrastructure to maintain them.
There is no singular definition of digital sovereignty, nor is there a single coherent position in the digital rights space. Despite its growing popularity, the term remains frustratingly vague. Policymakers, regulators, civil society groups, and others can mean very different things when they use the term. But to start simply with a broad definition, we can say that it means having the capacity to control one’s digital destiny—though the implications of that will obviously differ considerably whether you’re talking about an individual or a country.
We can start by developing a shared understanding of what digital sovereignty actually means. We’ve also included a glossary of terms at the bottom of this post.
In Europe and other places where digital sovereignty has become a topic of policy, discussions focus on reducing dependency: on foreign (and particularly American) cloud infrastructure, chips, platforms, and at times, foreign political priorities. The concern is both economic and geopolitical. If essential infrastructure is controlled by companies elsewhere—and thus subject to the laws of another jurisdiction—then what control does a country actually have over its own digital future?
In global majority countries in particular, wars, sanctions, and the growing fragmentation of the internet have demonstrated for many that the physical infrastructure that underlies digital life is neither neutral nor invulnerable.
Amidst this increasing geopolitical instability governments and civil society should consider whether digital sovereignty can help shore up that infrastructure.
What are we talking about when we talk about digital sovereignty?A recent Franco-German joint paper on digital sovereignty defines it as the “capability and capacity to develop, provide, use, adapt and control digital technologies including hardware in an independent, self-determined and secure manner” and puts forward a framework to operationalize Europe’s capacity to act in the digital domain.
Some governments, such as Germany’s, have started to put funding behind sovereignty efforts through initiatives like the Sovereign Tech Agency, which “invest[s] globally in the open software components that underpin Germany's and Europe's competitiveness and ability to innovate.”
Positions on digital sovereignty among EFF’s allies across Europe vary. Open Rights Group have defined digital sovereignty as “the ability of a country to have control over its digital infrastructure, data, and technology” and states it to be “critical for the UK’s economic and national security.”
Similarly, the European Partnership for Democracy has expressed concern that “a few Big Tech corporations decide our collective destiny,” and argue that the EU should explore “alternative ownership models for tech companies and clearly [define] their purpose and mission.” And our friends at EDRi (of which EFF is a member) have stated clearly that “Europe’s digital sovereignty starts with open source.” Some initiatives, such as DI.DAY, consider digital sovereignty an opportunity to free users from Big Tech dependencies.
Elsewhere in the world, conversations about digital sovereignty often take a different shape. Indigenous discussions of the topic have been ongoing for more than a decade and focus on the inherent right of Native nations to govern their own digital ecosystems. In Southeast Asia, the desire for digital sovereignty has created growth in the sovereign cloud industry, but the conversation isn’t purely economic: Concerns about jurisdiction for where data is held are driving much of the conversation.
In Latin America, digital public infrastructure is often a key aspect of debates. Across Africa, leaders speak of a desire to shift the continent from being consumers of technology to becoming architects of their own digital infrastructure and data ecosystems. And in the Middle East and North Africa, concerns about reliance on U.S. technology companies—which have engaged in conflict and disproportionate censorship (particularly of Palestinian voices) in the region—are often paramount.
Reem Almasri, a senior researcher based in Jordan, recently spoke to EFF about digital sovereignty, which she sees as “the ability of people and communities to choose, control, and use technology that serves their needs and values,” particularly in light of the role that U.S. companies have played in regional conflicts.
In a January article, Almasri pointed to growing concerns about granting greater sovereignty and influence to governments over citizens’ data, communications, and websites, writing: “This is particularly worrisome in countries that impose high levels of internet and media censorship and run unaccountable surveillance programs on their citizens’ data.”
Indeed, while pushing for greater sovereignty from Big Tech has benefits, there is an inherent risk that some states will pursue digital sovereignty as a means of cutting off or splintering access—as we’ve already seen in Iran, Russia, and elsewhere.
For that reason, it’s no surprise that some, such as Iranian professor Azadeh Akbari, believe that “the current wave pushing digital sovereignty as the key to ending dependency on American and Chinese technology is negligent of its Eurocentric bias.”
What does EFF believe?In a world where people have digital sovereignty, civil society should be able to communicate freely, privately, and anonymously if they wish. People should be able to easily understand where their data lives and who has access to it. That data should be easily portable between platforms and services.
At EFF, we view digital sovereignty not as a walled garden, but as an opportunity for resilience and development of industries and skills. We believe that governments can and should take a role in crafting digital sovereignty that centers the autonomy of users rather than just re-creating a state of digital dependency with a new set of companies. Governments should support and use free and open source tools and projects built using principles of interoperability and data portability. This support should include employing full-time developers, UX designers, and community managers. Government policy and legislation should grant users control of their own data and a clear understanding of who can lawfully access it. Digital sovereignty should foster users’ ability to choose how they use digital products and services, free from unfair lock-ins, coercive terms and manipulative defaults. It should also foster the broader public interest internet, the part of the web that provides public goods and useful services without requiring the scale or the business practices of the tech giants.
Encryption backdoors are fundamentally incompatible with a vision of data sovereignty that centers user control. Governments should support the development and normalization of reputable end-to-end encrypted communications as well as strong encryption for data at rest. This support should include employing cryptographers and contributing to strong, peer-reviewed encryption standards strengthened by data minimization as a fundamental design principle, as well as refraining from legislating mandates for “lawful access” or any other reason.
As technologists, we don’t have to wait for governments to act in order to create the digital sovereignty we want. We get the internet that we build. We can contribute to open source, decentralized, and end-to-end encrypted projects. We can build standards that make interoperability and data portability a feature from the very beginning. We can resist the call of proprietary solutions, user lock-in, and encryption backdoors.
And finally, while digital sovereignty is often framed as a response to the dominance of Big Tech, that does not mean that there is no role for private companies to play. There is no point in replacing the influence of a few mostly US-based tech companies with a handful of giants based elsewhere. Companies can and should build platforms and services on top of open source, decentralized protocols and contribute to the ecosystem. Companies should also minimize processing a person’s data except as strictly necessary to provide them what they asked for, and only with opt-in consent that makes it clear to users what data they are gathering, where it is stored, and who has access to it. And companies should build their tools and platforms in a way that allows interoperability and that makes it easy for users to leave with their data. Some of these practices are already required by law in some jurisdictions, but companies don’t have to merely do the bare minimum the law demands: they should respect their users and support data sovereignty right now.
A glossary of termsThe following terms are useful for understanding this blog post as well as the broader conversation about Digital Sovereignty:
Intermediary liability: the legal responsibility of online service providers (ISPs, websites, social media platforms) for unlawful activities by their users, such as defamation, copyright infringement, or illegal hate speech.
The stack: a secure, open-source technology framework, often focusing on European alternatives, designed to break dependencies on (mostly) US-based technology providers. It comprises interoperable, vendor-neutral, and transparent digital infrastructures designed to regain control over data, infrastructure, and technology.
Digital sovereignty: the ability of people, as nations, organizations, and individuals, to control their own digital destiny by retaining authority over their own data, technology, and infrastructure.
Data sovereignty: the principle that digital information is subject to the laws and governance frameworks of the country or region where it is physically collected, stored, or processed. It dictates that data remains bound by the specific privacy protections and regulations of its originating jurisdiction, regardless of where the collecting organization is located.
Digital commons: a shared, online resource, such as knowledge, software, and data, that is collectively produced, governed, and maintained by a community, intended for public access. Examples include Wikipedia, open source operating systems such as Linux, and Creative Commons licensed content.
Data portability/interoperability: the ability to easily transfer personal data from one service provider to another, or to a personal system, in a structured, machine-readable format. It empowers users to move away from "walled gardens," reducing vendor lock-in and enhancing user autonomy.
Digital dependency: the opposite of digital sovereignty. The inability of people as nations, organizations, and individuals to control their own digital destiny through control over their own data, technology, and infrastructure.
Decentralization: a shift away from relying on centralized, often US-based, corporate platforms toward a distributed, user-centric internet where individuals, communities, and nations maintain control over their data, digital identity, and infrastructure.
End-to-end encryption (e2ee): a secure communication process where only the sender and intended recipient can access, read, or decrypt messages or data.
Fairness (à la the Digital Fairness Act): the absence of deceptive, manipulative, or addictive design practices that distort consumer choice and exploit vulnerabilities.
User sovereignty: the concept that individuals possess absolute control over their personal data, digital identity, and online privacy, rejecting the centralization of power by large technology platforms. It emphasizes user consent, decentralization, and the ability to manage personal data using secure and independent tools.
