Feed aggregator
MIT engineers develop a magnetic transistor for more energy-efficient electronics
Transistors, the building blocks of modern electronics, are typically made of silicon. Because it’s a semiconductor, this material can control the flow of electricity in a circuit. But silicon has fundamental physical limits that restrict how compact and energy-efficient a transistor can be.
MIT researchers have now replaced silicon with a magnetic semiconductor, creating a magnetic transistor that could enable smaller, faster, and more energy-efficient circuits. The material’s magnetism strongly influences its electronic behavior, leading to more efficient control of the flow of electricity.
The team used a novel magnetic material and an optimization process that reduces the material’s defects, which boosts the transistor’s performance.
The material’s unique magnetic properties also allow for transistors with built-in memory, which would simplify circuit design and unlock new applications for high-performance electronics.
“People have known about magnets for thousands of years, but there are very limited ways to incorporate magnetism into electronics. We have shown a new way to efficiently utilize magnetism that opens up a lot of possibilities for future applications and research,” says Chung-Tao Chou, an MIT graduate student in the departments of Electrical Engineering and Computer Science (EECS) and Physics, and co-lead author of a paper on this advance.
Chou is joined on the paper by co-lead author Eugene Park, a graduate student in the Department of Materials Science and Engineering (DMSE); Julian Klein, a DMSE research scientist; Josep Ingla-Aynes, a postdoc in the MIT Plasma Science and Fusion Center; Jagadeesh S. Moodera, a senior research scientist in the Department of Physics; and senior authors Frances Ross, TDK Professor in DMSE; and Luqiao Liu, an associate professor in EECS, and a member of the Research Laboratory of Electronics; as well as others at the University of Chemistry and Technology in Prague. The paper appears today in Physical Review Letters.
Overcoming the limits
In an electronic device, silicon semiconductor transistors act like tiny light switches that turn a circuit on and off, or amplify weak signals in a communication system. They do this using a small input voltage.
But a fundamental physical limit of silicon semiconductors prevents a transistor from operating below a certain voltage, which hinders its energy efficiency.
To make more efficient electronics, researchers have spent decades working toward magnetic transistors that utilize electron spin to control the flow of electricity. Electron spin is a fundamental property that enables electrons to behave like tiny magnets.
So far, scientists have mostly been limited to using certain magnetic materials. These lack the favorable electronic properties of semiconductors, constraining device performance.
“In this work, we combine magnetism and semiconductor physics to realize useful spintronic devices,” Liu says.
The researchers replace the silicon in the surface layer of a transistor with chromium sulfur bromide, a two-dimensional material that acts as a magnetic semiconductor.
Due to the material’s structure, researchers can switch between two magnetic states very cleanly. This makes it ideal for use in a transistor that smoothly switches between “on” and “off.”
“One of the biggest challenges we faced was finding the right material. We tried many other materials that didn’t work,” Chou says.
They discovered that changing these magnetic states modifies the material’s electronic properties, enabling low-energy operation. And unlike many other 2D materials, chromium sulfur bromide remains stable in air.
To make a transistor, the researchers pattern electrodes onto a silicon substrate, then carefully align and transfer the 2D material on top. They use tape to pick up a tiny piece of material, only a few tens of nanometers thick, and place it onto the substrate.
“A lot of researchers will use solvents or glue to do the transfer, but transistors require a very clean surface. We eliminate all those risks by simplifying this step,” Chou says.
Leveraging magnetism
This lack of contamination enables their device to outperform existing magnetic transistors. Most others can only create a weak magnetic effect, changing the flow of current by a few percent or less. Their new transistor can switch or amplify the electric current by a factor of 10.
They use an external magnetic field to change the magnetic state of the material, switching the transistor using significantly less energy than would usually be required.
The material also allows them to control the magnetic states with electric current. This is important because engineers cannot apply magnetic fields to individual transistors in an electronic device. They need to control each one electrically.
The material’s magnetic properties could also enable transistors with built-in memory, simplifying the design of logic or memory circuits.
A typical memory device has a magnetic cell to store information and a transistor to read it out. Their method can combine both into one magnetic transistor.
“Now, not only are transistors turning on and off, they are also remembering information. And because we can switch the transistor with greater magnitude, the signal is much stronger so we can read out the information faster, and in a much more reliable way,” Liu says.
Building on this demonstration, the researchers plan to further study the use of electrical current to control the device. They are also working to make their method scalable so they can fabricate arrays of transistors.
This research was supported, in part, by the Semiconductor Research Corporation, the U.S. Defense Advanced Research Projects Agency (DARPA), the U.S. National Science Foundation (NSF), the U.S. Department of Energy, the U.S. Army Research Office, and the Czech Ministry of Education, Youth, and Sports. The work was partially carried out at the MIT.nano facilities.
Doxxing Safety Part II: Incident Response
Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, then sharing that information more widely in the hopes it will intimidate their target or worse.
This guide is a followup from a previous post that describes a methodology for you to clean up your digital footprint and get a firm entry into the art of open source intelligence. There's a slight bit of repetition here, but with a slant towards using those now-familiar tools and methods toward what to do in the context of incident response. The best thing you can do is familiarize yourself with this post and its tactics before something happens, then return back to it for reference when needed.
Incident LogAn incident log is a way to keep track of suspicious or harmful activity online. It doesn't need to be beautiful or complex, just a place where you can quickly note details around the different things you're seeing online. Noting times, places, people, and the general nature of what you see ought to be enough. In the event that law enforcement gets involved, this sort of record will be helpful.
The process of finding and noting hateful incidents online can be incredibly stressful, so now is a good time to revisit the team roles you might have already thought of in the previous blog post. If you haven't yet done that, here's a brief refresher:
Assign Team RolesRemember, privacy–and responding to doxxing–is a team sport. Knowing who you trust is as important as identifying threat actors. Having trusted people ready to assist is invaluable in this type of situation. Refer them to this blog post or specific recommendations in it. If you've already plotted out a list of designated team roles, now is the time to remind everyone of their responsibilities. That might look like monitoring the hate forums where activity happens, keeping track of events in the incident log, setting up web alerts, locking down your social media accounts, or contacting law enforcement to reduce the likelihood of SWATing (a type of attack where bad actors call the police on their target, hoping to incite violence or disruption of peace by bringing law enforcement to their door).
Monitoring Hate ForumsSo often the victims of doxxing and harassment campaigns are positioned that way because of bias or bigotry. If you're a part of a community who is the target of such abuse, you are likely already aware of the places where such bigots gather and the language they use. Safely and privately accessing those sites to check for organizing against you or those in your community is a crucial step to take. Take great care to do so privately. We recommend you use the Tor browser for such information-gathering missions. It’s also advisable that you don’t engage with anyone in those places.
Again, this step can be particularly stressful; asking a friend for help is a good idea, or you can thoughtfully apply some of the advice from the next section to automate the process.
Set Up Search AlertsGoogle alerts is a free service that Google offers to alert you when a particular keyword—like your name—is freshly indexed by their search engine. Doxxing efforts done by anonymous trolls may not trigger an alert, but if you're the target of smear campaigns in the media, or the victim of abuse by very prominent media figures, those things are more likely to appear. Updates can come pretty frequently, so we advise leaving the monitoring of these alerts to a person that you trust.
For a more sophisticated approach, you could use a tool like Open Measures to automate the task of tracking coordinated campaigns. It's important to note that this type of tool is more likely to miss nuanced language or oblique references to you and your community.
Hardening Your Public Facing AccountsFor accounts that you can't or don't want to shut down, at the very least you must review the privacy and security settings on them and consider raising that bar. If two-factor authentication isn't already on, now is the time to do so. For social media accounts, consider switching the account to "private," where users have to request to have access to your page. For peace of mind, especially on accounts that you have to keep using, consider muting certain terms and blocking accounts so that you're less likely to encounter stressful content when on the app. Every app's options are different for this sort of thing, so be prepared to spend a few minutes figuring out what the menu is like and where the options are.
Shut Down Affected AccountsIf a particular account is being targeted with hate, or signs are pointing to an account of yours being the source of information people are using against you, shutting down that account may be the best decision for now. Depending on the app, account deletion may be temporary and you may be able to recover the account after you've done so and things have cooled off.
Revisit Your Data Broker Removal StrategiesAlthough this is more of a doxxing preventative measure, it's a good idea to get on top of removing the information that's available about you via data brokers. In case you're unaware, the data broker industry is an unregulated viper’s nest of privacy threats, often contributing to or directly supplying the sources of information that are used in doxxing campaigns. Although there are plenty of services that offer to file data broker opt-out requests on your behalf, a recent study revealed that doing it DIY is still more effective than relying on these paid services. That said, a paid service may still be worth its money if you'd rather have someone else take care of it.
Revisit Public RecordsAs covered in the previous blog post, your information may be made available through public records that you have little to no control over. You may be able to limit the convenience of that information being available by requesting to have it taken down from sites that republish it. Check through voter records, business registration records, court and property records, and the like. If you aren't able to limit that information from appearing on such mirroring sites, at least gaining awareness of where they are and the specific contours of what they contain will help you strategize against the harms they may cause.
Consider Contacting Law EnforcementFor many, talking to law enforcement will only make things worse. On the other hand, SWATing is a tactic often used in these types of coordinated attacks. If you think that's a possible outcome in your situation, it could be a good idea to get ahead of it and contact law enforcement to let them know what you're dealing with. It's in their best interest to be aware of fraudulent calls, and will make them less likely to show up at your door with guns drawn.
Revisit PACE Documents, Enact Those StepsIf you're involved in any kind of activism or community organizing you may be familiar with PACE documentation. It’s an acronym for coming up with contingency plan reactions if unwanted things come up: Primary, Alternate, Contingency, Escape/Emergency. Think of it like a panic button, a routine checklist of things to do if shit hits the fan. Maybe it involves some of the recommendations from this blog post. The point is to have something readymade, and some thoughts and strategies prepared, if the doxxing escalates to increased levels of harm and danger.
This is another step that's best done in a community with trusted people. The point is to keep your community organizing or community work moving, but with special contingency measures enacted to keep you and everyone else safe while remaining aware of this incident. This step is highly personalized and relies on a bit of prep work having already been done.
Put A Lock on Your Bank Accounts and Cell SubscriptionsOne of the tactics those who are doxxing you might use is trying to get into your social media or other accounts through “SIM swapping,” an attack where they contact your cellular provider pretending to be you in order to hijack your phone number. They can then use that number and pivot to stealing other accounts you authenticate yourself to with your phone. Likewise, those targeting you might try to steal access to or disrupt your bank accounts through similar techniques.
Get ahead of them by placing security passwords or pin codes on these highly sensitive accounts, if your bank or cellular provider provides this extra security measure. Most cell providers offer some sort of SIM swapping prevention method, but they all use different names for this feature, so be sure to look up the process in your provider’s documentation (here are guides for the major U.S. providers: Verizon, AT&T, and T-Mobile).
Regulate Your Nervous SystemIt’s an understatement to say that being doxxed is scary and potentially very dysregulating. You're much more likely to make safe, smart decisions if you are able to maintain a sense of control around your mental state. Recognizing that capability, as well as having a strategy to keep calm in the face of a crisis is just as important as having good digital security hygiene. Do what you need to do, be it involving the help of friends, taking a break, or whatever else, to stay afloat during this process.
Flexibility and ResiliencyThe reality is that the more you experience cultural marginalization, the higher the chances are that adversarial actors will resort to such tactics as doxxing and coordinated harassment campaigns. The fervor of those adversaries is often stoked by hateful public figures and politicians. And the plausible deniability of public records can limit the recourse you have to stop them. We hope that after reading this and the previous post, we’ve also brought to surface the idea that you can have great control over your digital footprint. Even more, that you can continue to share information online without unnecessarily compromising your safety and security.
Until we have digital privacy protections for everyone, it’s up to us to take matters into our own hands. Privacy, security, and dignity online are achievable. If you follow this guide, the previous one, and stay clued into the strategies laid out on Surveillance Self-Defense, you're well on your way.
Doxxing Safety Pt I: Prevention and Footprint Management
Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use legal and accessible means to do so. The odds are stacked against everyday internet folk when there's little to no comprehensive data privacy legislation keeping us safe. The responsibility is on each of us to protect ourselves, but the good news is that there's a lot you can do to reduce your digital footprint and take control of your data.
This post is part one of a two-part series discussing safety and response to doxxing. This first part focuses on prevention and ways to reduce your overall footprint. The second focuses on incident response, as in, steps to take if you're in the midst of being doxxed. There will be some crossover and redundancy between these two posts, so it's worth reading each and gaining familiarity with the steps well ahead of time.
OSINTOpen source intelligence (OSINT) is a broad term within information security. It focuses on the tools and means available to us for investigation and information retrieval. OSINT sits at the heart of doxxing campaigns but is also an important part of the process of preventing them. Typically it is a way of describing a methodology of piecing together scraps of information to form a dossier on a subject.
There are fancy multipurpose tools (like Maltego or Lampyre) that combine many datapoints into accessible graphs and datasets. As helpful as they can be for traditional penetration tests or corporate OSINT campaigns, they’re best used for investigations focused on organizations, mapping together details like employee email charts, LinkedIn profiles, and company network maps. They may not fit the needs of everyday people or liberation movement workers. Instead, we recommend referring to different OSINT resource lists that index together a bunch of different tools, then using those resources to create a list for yourself of which tools may be most helpful.
Many, if not all, of the resources we cover below will be referenced in those guides, and themselves fall under the OSINT category. It’s important to note that the tools we reference in this particular blog post are only relevant at the time of publishing. The bigger ideas have a much longer shelf life than various tech tools. That said, in no particular order:
Breach DatabasesWhen a company gets hacked and their customer data is leaked, that information often ends up in “breach databases,” that is, troves of peoples' data available for sale and reuse in illegal trades online. Because of the sensitivity of that type of information, it can potentially be used in doxxing campaigns. Some resources, like haveibeenpwned, note pieces of vulnerable identifying information in those databases and make it easy for people to see if their information is included. Others, like DeHashed, offer a similar sort of tracking, but for a fee.
You may not have control over a company's digital security that could put your own data at risk, but you can gain insight into whether your information is already out there. This gives you the opportunity to control the accuracy of that data (such as changing your email address or phone number). Doing so is extremely inconvenient, but unfortunately, it may be the only agency you have when another’s company’s digital insecurity puts your own safety at risk.
Open RecordsPublic records (such as voter records, property records, business registration, medical licensing information, and more) present a dilemma. It is in the public interest for there to be levels of transparency on such information. On the other hand, making such personally-identifiable information accessible to those with ill-intent can lead to serious consequences.
Instead of requiring a formal request through the courts, mirroring sites make this information easy to find online. Such sites often have forms where you can request your information be taken down. This doesn’t necessarily remove the records from existing, but it does remove a layer of convenience in accessing them.
Some states have programs called “Address Confidentiality Programs” that offer people the right to supplant address information with proxy addresses, keeping public records open but that specific piece of information potentially hidden.
Social MediaGoing through and tightening the security and privacy settings of your various social media accounts is always a good idea, but it’s especially important if you are in the process of minimizing your digital footprint. Consider turning your discoverability to “private” or “hidden” (verbiage and details depend on the app) so that only users vetted by you are able to see your account.
To get a quick overview of the various accounts you have registered online, especially if you've been online for a long time, use a username search engine like What's My Name or Namechk to see where your usernames have been registered. They may not be entirely accurate, but they are effective and quick. These tools are also helpful if you are at risk of being impersonated online and want to get an overview of where that may be taking place.
Data Brokers and RemovalsData brokers are craven, pernicious companies that present an existential risk to everyone in the digital age. Until that industry is no more, it's up to us to protect ourselves and the ways that it endangers us by selling personal, sensitive information. The most effective way to get your information removed from their stores is to file requests manually. Yael Grauer's BADBOOL project compiles and prioritizes the worst offenders in this industry and the means you can use to request data removals from them. This process can be grueling and time-consuming, so it may be worth investing in a service that automates the process. Though they've been found to be less effective than the DIY approach, there are some services that have stood out amongst the others in terms of efficacy when tested by third-party reviewers. If you’re a resident of California, you can more easily opt out through the new and exciting DROP tool.
Reverse Image Searching and FR ServicesServices like PimEyes and Lenso have jumped on the profit-driven opportunity to create facial recognition as a service. They contribute to law enforcement investigations and predictive policing systems, as well as providing commercial services to abusers and stalkers. The gist of their service: upload a picture of someone (in this case, yourself) and it will use facial recognition technology to determine where else online that person has appeared. If your image is being shared online without your consent, this service will find out.
Willfully participating in these services does mean having your image mapped, scanned, and stored by their systems. But if you believe you're under the type of targeted harassment that includes your image being shared online against your will, it may be worth that tradeoff.
Extra Monitoring, AutomatedThis section is less about data minimization, and more about laying extra protections down in the event that doxxing or other coordinated harassment seems imminent. If you're in the Google ecosystem of products, consider enrolling in their Advanced Protection Program, which offers a number of different features to keep you and your account safe.
If you're the focus of coordinated attacks that span from online communities to media outlets participating in the harassment, a service like Open Measures is worth looking into. It tracks, maps, and analyzes the spread of hateful information online. They provide free access to their open-source API, so with some technical fancy-footwork, you can automate this process.
Get Others InvolvedCoordinated harassment is often a process of daisy-chaining targets and tactics together until there’s a meaningful process of harm being inflicted. This means that people in your community are also at risk. As we always say, privacy is a team sport. Get others involved in the process; there’s strength in numbers.
A great way to do this is think of the activities you and your group are up to. What roles do individual members take on? Figure out a way to tack on some of the responsibilities you’re coming up with here onto those team members. Find ways to talk about it and share strategies, preferably using secure technology like Signal. You can coordinate together which tasks each person could take on, perhaps pulled from this blog post.
It's a Process; Keep Yourself Apace for the Marathon, Not the RaceThe process of data minimization and reclaiming agency over your digital footprint can be grueling and stressful. Don't underestimate the toll it can take on your mental health. Take breaks, employ the help of friends, and take the time to make sure you're first addressing the parts that are most relevant to your threat model. It may feel like there’s nothing to be done about protecting your digital privacy, but that’s just a symptom of surveillance capitalism’s psychological effect on its victims. There’s much you can do to stay safe, to protect yourself and others. Refer to this post and to the Surveillance Self-Defense project.
Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections
Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should meet to shield individuals from pervasive location surveillance. Since then, state lawmakers across the country have begun responding to calls like these, with Connecticut, Maryland, New Jersey, Oregon, and Virginia enacting new consumer privacy restraints on an industry that profits off our physical movements.
Yet, even as these states move the ball forward to restrict location tracking, most of their laws leave significant gaps that still must be filled. Other states – and Congress – need to get into the game, too, and ensure protection of everyone.
Why Location Privacy Is ImportantImagine spending a couple of hours in a coffee shop, a friend's house, or a healthcare clinic, only to discover yourself under police investigation because your cell phone’s location data exposed your presence there.
This is the reality of geofence warrants for location data, the controversial surveillance technique recently scrutinized by the U.S. Supreme Court in Chatrie v. United States. Through geofencing, tech companies and law enforcement can map everyone who was present within a specific area over a certain window of time, inverting standard constitutional protections by turning every innocent bystander into a potential suspect. While the Supreme Court's ruling in Chatrie established that accessing location data via geofencing constitutes a Fourth Amendment search requiring constitutional protections, law enforcement demands via these warrants are only part of the problem. That same geolocation tracking is used by commercial data brokers operating in a largely unregulated market. These brokers regularly harvest, aggregate, and sell physical location data to anyone with a credit card (including government agencies, which are among their regular clients). Especially for individuals seeking reproductive or gender-affirming care, attending a protest, or visiting an immigration law clinic, this pervasive commercial location surveillance represents an immediate threat.
In Part 1 of this series, we urged lawmakers to protect people from the growing harms of location tracking tools across all areas of public life. The real-world consequences of this unregulated market impact us all. An anti-LGBTQ+ advocacy group spent millions of dollars buying app location data to track priests across multiple dioceses and used app-harvested location data to “out” a priest after purchasing his Grindr location signals. Privacy advocates posing as private investigators gained access to Locate X, a location-tracking tool developed by Babel Street, and demonstrated how the tool tracked a device traveling from Alabama, where abortion is banned, to an abortion clinic in Florida, where access is less restricted. Data brokers like Near Intelligence have sold precise location data of reproductive health clinic visitors directly to political groups. Location data has been used to locate U.S. military personnel in war zones. Law enforcement and private entities have also weaponized location tracking directly against political protesters: surveillance contractors and authorities have utilized location data derived from real-time bidding ad networks to track individuals attending demonstrations.
The unregulated sharing of location data has created an ever-larger funnel for data brokers to capture and monetize our movements. For example, a recent EFF investigation identified several advertising Software Development Kits (SDKs) in Android apps that by default collect and share users' location data whenever app-level location permissions are granted. These advertising libraries automatically feed users' location data into ad systems that location data brokers have used to track people. Because defaults direct real-world outcomes, app developers who fail to carefully scrutinize the third-party SDKs they use, and disable unnecessary data collection, could inadvertently expose their users’ movements to commercial data brokers.
State Legislative ProgressLast year, we outlined six essential core principles that any meaningful location privacy law must contain:
- Strong definitions,
- Clear rules,
- Affirmation that all precise geolocation data is sensitive,
- Empowerment of consumers through a strong private right of action,
- Prohibition of “pay-for-privacy” schemes, and
- Transparency through clear privacy policies.
While the bills we highlighted from California, Illinois, and Massachusetts are yet to pass into law, a new wave of state location privacy legislation has taken effect across Connecticut, Maryland, New Jersey, Oregon, and Virginia.
These five laws represent progress, and share two strong features. First, all five of these states ban the sale of precise geolocation data. This will remove a strong incentive to collect and store this information in the first place. Other types of privacy laws have likewise banned the sale of sensitive types of data, like the Illinois Biometric Privacy Act (BIPA), which bans the sale of biometric information such as face scans.
Second, all five states broadly define the protected data to include all kinds of locations across the board within a particular distance of a person or their device, rather than protecting just narrowly-defined “sensitive” locations. This all-locations protection sets these laws apart from California’s A.B. 45 of 2025, for example, which only restricts location tracking within 1,850 feet of a family planning center. Protecting location data only near specific locations (like health care facilities) is insufficient: if an individual travels across state lines for care, a data broker can still track their route right up to the boundary of a protected zone and pick it up immediately upon departure, making it easy to infer their destination.
These five laws vary regarding whether, on top of the ban on sale, they require consent and/or minimization for other kinds of processing of precise geolocation data. Maryland’s Online Data Privacy Act (MODPA) requires strict minimization. Specifically, a data controller cannot collect, use, store, or disclose a consumer’s precise geolocation data (or other sensitive data) unless doing so is “strictly necessary to provide or maintain a specific product or service requested by [that] consumer.” Minimization is an important privacy protection because it imposes a duty where it belongs: on the company processing a person’s data. Maryland requires doubly strong minimization. First, the data processing must be “strictly necessary,” and not just “necessary,” or even worse, “reasonably necessary.” Second, the necessity of data processing must be tied to what the particular consumer requested, and not to what a generic customer might hypothetically have thought was reasonable, or the company’s own purposes, or whatever the company buried in its own long-winded legalese.
Connecticut requires both strong consent and weak minimization. Specifically, it forbids a data controller from collecting, using, storing, or disclosing a consumer’s precise geolocation data (among other sensitive data) “without first obtaining [that] consumer’s consent”. Connecticut has a strong definition of consent: “a clear affirmative act signifying freely given, specific, informed and unambiguous agreement,” which is absent from “agreement obtained through the use of dark patterns.” On top of this strong consent, Connecticut also requires a weak form of minimization: the data processing must be “reasonably necessary in relation to the purposes for which such sensitive data are processed”. But this does not weaken Connecticut’s strong consent rule.
New Jersey requires consent to collect, use, store, or disclose a person’s precise geolocation data (and other sensitive data).
Virginia protects location data with both minimization and consent, but only for one kind of people (known children) and only for one kind of data processing (collection). Under Virginia’s minimization rule, a data controller cannot collect such data from such people unless doing so “is reasonably necessary for the controller to provide an online service,” and in such cases, “only … for the time necessary” to do so. This would be a much stronger rule if the authors struck the modifier “reasonably” before the word “necessary,” or better yet, substituted the modifier “strictly.”
Beyond its ban on sale, Oregon does not limit the processing of precise geolocation data.
Gaps in Current LegislationWhile these enacted bills mark steps in the right direction, major loopholes remain that leave users vulnerable.
The Enforcement Void: Why Every Law Needs a Private Right of ActionA privacy law without a Private Right of Action is a law "without teeth”.
None of these five state statutes expressly empower consumers to directly sue companies that violate their location privacy rights. Relying exclusively on state Attorneys General or specialized regulatory agencies creates a critical bottleneck, since no regulatory agency possesses the staffing or budget required to investigate every data privacy violation. Additionally, government enforcement priorities shift across administrations, leaving enforcement vulnerable to political pressures and corporate lobbying.
The best way to ensure effective enforcement is a free-standing, explicit Private Right of Action written directly into the privacy statute. Some legislative privacy proposals instead attempt to provide remedies by piggybacking on state laws against unfair, deceptive, or abusive practices (UDAP). But this is often hit-or-miss depending on each state’s specific UDAP law, including who must have what kind of injury to have standing to bring a private action, and the scope of remedies. For instance, while Maryland’s MODPA provides that a violation of the statute constitutes a banned UDAP, it appears that the new law’s enforcement mechanics were drafted in a way that provides only government enforcement through the Attorney General’s Consumer Protection Division, rather than granting consumers a private right of action.
Any a private right of action should come complete with statutory liquidated damages to remedy non-economic harm, and prohibitions against mandatory arbitration. This ensures that compliance isn't optional. Until corporate bad actors face direct accountability from the very people whose personal location data they unlawfully exploit, state privacy laws will rely on overworked regulators to police an industry that profits off our every move.
The "Pay-for-Privacy" TrapPrivacy is a fundamental right, not a luxury tier. So EFF opposes pay-for-privacy schemes, in which companies charge a higher price to people who exercise their privacy rights. To prevent these schemes, data privacy legislation must prohibit companies from retaliating against consumers who exercise their statutory privacy rights, including by charging a higher price. For example, if a statute bars a company from processing a person’s data absent their consent, and that person withholds consent, the statute must bar the company from responding by charging a higher price.
Unfortunately, all three of these states that require consent to process precise geolocation information (Connecticut, New Jersey, and Virginia) have only weakly limited pay-for-privacy schemes. While all three prohibit discrimination against customers who withhold consent, all three also have a wide loophole: for discount programs. To make matters worse, none of these three states prevent the discount programs from selling customer data to third parties. But people should not have to surrender their data privacy to join a discount club for regular customers. Thus, the far better approach is to eschew this loophole, as in the ban on pay-for-privacy in last year’s location data privacy bills in Illinois and Massachusetts.
These exceptions allow companies to charge higher prices or downgrade service quality for users who exercise their privacy rights. In practice, this converts privacy into a privilege for those who can afford it, forcing economically vulnerable communities to trade away their sensitive location movements in exchange for essential discounts or services.
Dark PatternsAny law that requires consent also needs to ban company techniques that subvert consent. These are often called dark patterns, predatory design, and manipulative user interface (UI/UX) practices.
Connecticut’s definition of “consent” excludes “dark patterns,” as noted above. That state defines dark patterns as “a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making, or choice,” including any practice that the FTC refers to as a dark pattern. Other consent-based privacy rules must do so, too.
ConclusionThe recent wave of state legislation demonstrates that momentum is building against location surveillance. However, state leaders must go further.
To build privacy protections that withstand corporate workaround attempts, future bills must apply to all locations universally, give individuals the legal standing to enforce their own rights in court, and fully prohibit pay-for-privacy. Until comprehensive data privacy legislation with real teeth is enacted nationwide, users can consult EFF's Surveillance Self-Defense Guide to learn practical steps for reducing location tracking on their personal devices.
LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?
This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch!
EFF answers all the queer digital rights questions you submit to us through our LGBT Q&A. You asked us: What’s one thing I can do today to improve my safety and security online as an LGBTQ+ person?
And for this question, we’ve brought in our friends from the Trevor Project to answer together:
Hi, I’m Tommy from the Trevor Project! The Trevor Project’s mission is to end suicide among lesbian, gay, bisexual, transgender, queer, and questioning (LGBTQ+) young people. Our vision is to create a world where all LGBTQ+ young people see a bright future for themselves.
EFF and the Trevor Project know that digital security and online safety can feel overwhelming, especially because we all have different levels of concern for different parts of our online lives. Some might be focused on the dangers of doxxing, another might only want to ensure they're not outed. And queer people can be particularly vulnerable to these kinds of online threats.
This might seem like a big task, but the one way you can do today to protect yourself is to revise the information you’ve shared with services and platforms to ensure you’re as in control of your information and data as possible:
Protect Your Personal InformationBe cautious about sharing sensitive details like your full name, address, school, phone number, and personal photos as it might expose identifying information you want to keep private. Consider using an avatar as your profile picture to avoid sharing your personal photos if that makes you more comfortable. Keep it lowkey when talking about work stuff or sharing details about where you’re studying.
If you do share personal photos, don’t accompany them with information that identifies your location or frequent whereabouts, and make sure EXIF data in photos is turned off (which could inadvertently include your location); the easiest way to do this is to take a screenshot of the photo and share that instead. Don’t post pictures with obvious spots in the background, like your front door or porch.
Understand the Importance of Login InformationWhen you create an account on websites and platforms, you can often use your phone number or a third party account, such as Facebook, Google, or Apple. These external accounts might share data with the apps you're logging into, but they can be helpful if you struggle with managing a lot of logins. Deciding if that trade-off is worth it is up to you but, when you can, use strong, unique passwords for your accounts, and be sure to enable two-factor authentication when offered.
Review Permissions with Social Media AppsReview which apps have access to things like your location and camera roll, and possibly change those permissions in line with what information you would like to keep private. Location is particularly important. For example, some apps might need some location information to function. But you can typically at least deny access to your device's "precise location" or enter in a city or zip code manually.
Consider What You Share When Speaking with Others OnlineIt’s important to be mindful of what you share with others when you post online or speak with people. Avoid disclosing sensitive information like financial details, and trust your gut if something feels off. It’s also useful to review your profile’s privacy settings and information now and again to make sure you’re still comfortable sharing what you’ve listed there.
Good privacy decisions begin with proper knowledge about your situation and a community-oriented approach. To dig in deeper, read EFF’s blog post on Building a Community Privacy Plan and the Trevor Project’s Guide to Online Safety for LGBTQ+ Young People.
How an MIT research project became a global programming language
It all started with some exasperated emails. Back in 2009, a group of researchers began venting their frustration with the programming languages designed to help scientists and other researchers perform complex mathematical operations and statistical simulations without learning how to code. These programming languages were rigid and slow. If scientists built something that really worked, they’d need to rewrite the entire program in another language just to run it more quickly.
The emails turned into a research project at MIT with the mission of building an easy-to-use, high-performance programming language called Julia, which is designed for scientific research, data analysis, and modeling complex systems such as jet engines, drugs, financial markets, and robots, to name a few examples.
That research project turned into a lab at MIT, and the lab turned into the company JuliaHub. Along the way, Julia gained a loyal following among scientists, engineers, mathematicians, and others. Today, the free and open-source language counts more than 1 million users, including people working in thousands of companies and universities around the world.
It is only a slight exaggeration to say Julia has been used to model everything under the sun, from the behavior of tiny atoms to semiconductors, neural networks, race cars, and airplanes. It has also been used to study much beyond the sun, with astronomers using Julia for imaging black holes.
Julia’s secret sauce is in the way it compiles code depending on the type of data being used. Such “just-in-time compilation” makes Julia faster and more flexible than other numerical programming languages.
“Scientists and engineers are not programmers. Building scientific applications with multidisciplinary teams of scientists, engineers, and programmers is challenging,” JuliaHub co-founder and CEO Viral Shah says. “We asked: What if you could equip the scientists and engineers with a programming language that allowed them to express their ideas at a high level and also get great software performance?”
Making programming easy for non-programmers has been a north star for JuliaHub’s founders, who include Julia co-creators Shah, MIT professor of mathematics Alan Edelman, Jeff Bezanson SM ’12, PhD ’15, and former MIT research scientist Stefan Karpinski.
In April, JuliaHub’s team took another big step in that direction with the launch of Dyad 3.0, the latest version of its AI platform to help engineering teams accelerate the development of complex physical systems like rockets, heat pumps, and satellites. Engineers are already using Dyad to direct autonomous AI agents as they work through physics simulations, safety analyses, quality controls, and more.
“With Dyad 3.0, you can upload data and design documents and the system will design an entire aircraft for you,” Shah says. “Working with customers like Boeing, we are building agentic hardware design capabilities for engineers. Simplistically, you want to say, ‘Okay computer, build me a plane’; upload the design documents; and have the system account for all the physics, compile all the code, verify everything, and build the entire design agentically.”
Humble beginnings
After discussing the need for better programming languages for scientists and other researchers, Julia’s co-creators started the Julia Lab around 2009. The Julia Lab remains active in MIT’s Computer Science and Artificial Intelligence Laboratory.
The core idea was to create a high-performance platform that would excel at engineering, scientific, and mathematics applications. Shah says before Julia, scientists and engineers would either have to hire someone to build software for them or accept the slow performance of the few programming languages designed for them.
“We wanted to create something as easy to use as Python or MATLAB but as fast as the C programming language,” Shah says. “We built Julia for ourselves.”
Edelman says at first, the researchers didn’t think anyone would want their creation.
“We figured it would take 10 years before anyone was interested, but we said, ‘Patience is a virtue, so let’s do it,’” Edelman recalls.
The MIT researchers announced Julia with a blog post in 2012. They quickly realized many other researchers shared their frustration.
“When we first started, we were targeting interactive research workflows, but increasingly people are using it for everything,” Bezanson says. “Now we’re moving the whole stack of the language onto smaller, embedded devices as we evolve with our users.”
Since those early days, Edelman has taught a class on Julia with students from nearly every department at MIT. Today, he often learns students are already using Julia when they enroll in the class for applications as wide ranging as robotics, astronomy, physics simulations, and finance.
“Researchers come up to me and say, ‘I tell my supervisor I’m using Julia because it’s fast, but don’t tell them I’m using Julia because it’s really fun,’” Edelman says. “The key thing is Julia’s abstractions. A lot of times a coding language forces you to solve the one problem you’re thinking about. Julia’s language makes it so you’re solving not only the problem you’re thinking about, but other people’s problems around the world too. It encourages you to solve problems more generally.”
As Julia gained popularity, researchers around the world started asking the Julia team for support. By 2015, the demand became strong enough that they decided to start JuliaHub and help users through the company full-time. They received support from the MIT Deshpande Center for Technological Innovation and others at MIT to get the company off the ground.
JuliaHub’s work has evolved from simply helping users to advancing the language more generally. That’s powered an impressive list of creations from Julia’s loyal users. Julia has been used to simulate computer circuits, detect health disparities, model global climates and oceans, analyze brain activity, and more.
After someone built a pharmaceutical modeling platform in Julia, it was used to accelerate development of Moderna’s Covid-19 vaccine. In another case, researchers used Julia to create a program for avoiding aircraft collisions. They found it ran about 50 times faster than an earlier version built on Python. Engineers at Meta used Julia to develop a better audio codec for WhatsApp’s 4 billion users.
“Over the years we’ve seen industrial, government, and academic users doing all kinds of interesting things with the Julia language,” Edelman says. “It’s honestly surprised us in many ways, the wide-ranging things people are using it for.”
Autonomous design
JuliaHub launched Dyad 1.0 in June of 2025 as a research agent to accelerate programming and Dyad 2.0 in December. The founders believe Dyad 3.0 represents a new level of ability and autonomy for designing complex systems.
“One important thing about Dyad is that it is a physics compiler and hence enforces physical laws,” Shah explains. “General AI systems often solve physical problems in ways that violate physical laws. When using the Dyad agent, it will detect such violations and guide the agent in the direction of the physically correct solution. We expect it will decrease design times in product engineering by orders of magnitude, leading to months of work being accomplished in hours.”
One way Edelman sees the impact of Julia is through his class. One student recently used Dyad to model how robots move around in space. Another used it to build a rocket engine.
“At the end he said, ‘I couldn’t believe how easy that was — I just got a rocket engine!’” Edelman recalls.
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
Ugh:
A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.”
That would be twenty tons of squid.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
How an MIT graduate student helped a team of young scientists test their experiment at CERN
This past spring, MIT physics graduate student Manu Srivastava opened an email from a group of high school students in India he had never met.
They were hoping to enter Beamline for Schools, an international competition that gives secondary school students the chance to design and carry out experiments using particle accelerator beams. And they were looking for a mentor.
Srivastava, who studies quantum gravity as a PhD student in the MIT Center for Theoretical Physics – a Leinweber Institute, with Professor Hong Liu, gets other requests to mentor students, often through companies charging families for access to scientists or students at prestigious universities. He usually declines, but this message came directly from the students.
“I've also cold-emailed a lot in my early career, and it usually never works,” he says. “But this email seemed very genuine. They wanted to do something nice and they just needed some guidance.”
Many months and many more emails and calls later, the students secured a place with Srivastava to attend CERN, in Geneva, where they spent two weeks turning their proposed idea into a real experiment.
Finding an experiment worth doing
Calling themselves Team attoPION, the students are one of five teams selected in the 13th annual Beamline for Schools competition from a record 712 teams representing 89 countries and more than 4,500 students. The six high schoolers met through a combination of science competitions and mutual friends, and attend four schools in four cities across India.
When they first met with Srivastava, the students already had several experimental ideas. His role, he says, was to help determine which directions were practical and scientifically interesting.
They settled on measuring pion charge exchange. Pions are short-lived subatomic particles that can carry positive, negative, or neutral charge. In the process the students want to study, a positively charged pion interacts with a neutron in a target material, producing a neutral pion and a positively charged proton. The team wants to characterize how often that reaction occurs.
Srivastava suspected such a measurement could have relevance to the Deep Underground Neutrino Experiment, or DUNE, a major international experiment designed to study neutrinos.
Dave Newbold, a co-spokesperson for DUNE, says understanding how pions interact with matter helps researchers quantify uncertainties in DUNE’s measurements. In particular, pion interactions can affect estimates of a neutrino’s flavor and energy, which researchers need to measure accurately to determine whether they have observed something new.
And although Beamline for Schools has an educational mission, Newbold says the students aren't simply reproducing a classroom demonstration. “The proposal is real experimental particle physics!” he notes.
If successful, Newbold believes the work could improve scientists' understanding of this particular interaction and potentially lead to a publishable result. Similar “test beam” experiments remain important tools in particle physics: DUNE's detector designs were themselves demonstrated using the (albeit much larger) ProtoDUNE experiments at CERN.
“This [proposal] stands out because of the work the students have put into motivating their measurement, and demonstrating that the experiment is feasible,” Newbold says. “It's certainly at a level far above anything I was thinking about at high school.”
Learning to navigate uncertainty
At CERN, the students worked hands-on with detectors and data-acquisition systems, collected and analyze data, and attended talks by CERN scientists.
In advance of the trip, the team worked with Berare Göktürk, one of the support scientists for Beamline for Schools. In their preparation sessions for the experiment, they realized that the charge-exchange process they hope to observe is extremely rare, forcing them to think through how they might reliably detect it.
With just a few months months to prepare and only 12 days of test-beam time, Göktürk cautioned that producing a result useful to a much larger experiment would be an ambitious outcome.
“We prepare in the best way possible, but we also stay humble and we are aware of the limitations we have,” she says. Her priority is for the students to “understand the journey of a scientist” as they encounter technical problems and work together to solve them.
For Srivastava, mentoring an experiment has also taken him well outside his own specialty. A theoretical physicist, he credits MIT's culture with encouraging him to follow questions beyond the boundaries of his research, including by attending seminars, colloquia, and research meetings across physics.
The experience has been personally meaningful for Srivastava, who grew up in India and sees the mentorship as a way to encourage young people there to pursue fundamental science.
“I didn't even know what CERN was in high school,” he says. “But these students, they are just that good. They deserve all the credit.”
How MIT Sandbox has turned student ideas into $8.7 billion in global impact
Although Jacob Becraft had two swings and two misses when he first tried to become an entrepreneur as a graduate student, the MIT Sandbox Innovation Fund Program allowed him to keep at it. This especially benefited cancer patients, as Becraft went on to co-found Strand Therapeutics: a $550-million firm whose programmable mRNA drug has shrunk tumors in patients who had exhausted all other treatment options.
Stories like Becraft’s took center stage at the recent 10-year anniversary celebration of the MIT Sandbox Innovation Fund Program, where student founders, alumni, mentors, and university leaders gathered to reflect on a decade of empowering student entrepreneurs. Speaking at the event, Becraft referred to Strand as "our third swing at the plate," explaining that the Sandbox model gave him "the freedom and ability to fail fast" — letting previous venture ideas "blow up in our faces" before moving on.
For Strand, Becraft says, MIT Sandbox helped him and his co-founder, Tasuku Kitada, to "get out, do some travel, some market research, meet with experts in the field, meet with mentors who could help us build the company — and eventually find investors who were going to back this big vision to transform medicine."
MIT Sandbox was launched in 2016 by Ian Waitz, then-dean of the School of Engineering and now MIT's vice president for research, to lower the barrier for students to try entrepreneurship. The concept of a new program focused on student-led entrepreneurship was developed in consultation with internal MIT leaders and supporters of MIT, including Alan Spoon, a life member emeritus of the MIT Corporation. From its inception, MIT Sandbox has been open to all MIT students, from undergraduates to PhD students. Teams are awarded between $500 and $5,000 to begin their process, and they are matched with two mentors and connected with other expert advisors.
As they make progress, students can go before the program’s funding board to ask for up to $25,000. Supported entirely by alumni, corporate sponsors, entrepreneurs, and investors, the program has grown to include about 350 teams each semester, some of which are new and some continuing their participation according to their own timelines.
Anantha P. Chandrakasan, MIT provost, explained in the program's decade-in-review report: "Since its inception 10 years ago, MIT Sandbox has been a defining part of MIT's innovation ecosystem, ensuring that every student with the curiosity to explore entrepreneurship has the resources, mentorship, and community to take their first steps."
MIT Sandbox is a "home," where students can "explore, seriously test assumptions, talk to customers, build prototypes, fail, pivot, learn, and grow," says Jinane Abounadi, founding executive director of Sandbox. "And they can do that with a lot of support — and I don't just mean financial support. I mean a lot of support from a lot of people."
For Samuel Udotong, co-founder and CTO of Fireflies.ai, early funding was the difference between an idea and a company. "I think largely because we had gotten a little bit of Sandbox funding, we were actually able to take the risk to move out to San Francisco and try to build the company," he says. "But it would have been really a money barrier if we hadn't gotten the initial $5,000 from Sandbox."
Startup investor and advisor Sophie V. Vandebroek says, "MIT has extraordinary students from around the globe as well as faculty who are top experts in their fields. What’s often lacking," she says, "is confidence. That is where Sandbox plays a vital role. Sandbox enables every individual student to believe that they can be an entrepreneur."
At the anniversary celebration, Fred Parietti, co-founder and CEO of Multiply Labs, recounted how his early product prototypes were developed on his kitchen table and had to be moved regularly according to the dictates of his grad school housemates. Those prototypes wouldn't have been built at all, he said, without MIT Sandbox.
The first funding he received was minimal, "but it wasn't zero, and zero represented my resources as a student. That belief in us and the possibility to build a prototype were game-changers," Parietti said.
Multiply Labs, with 60-plus employees, has raised $36 million and develops robotics technology to manufacture biological drugs safely and economically. The firm supplies pharmaceutical customers including AstraZeneca and Kyverna Therapeutics, whose chief medical and development officer, Naji Gehchan, is an MIT Sandbox mentor.
That same willingness to back an unconventional approach helped AeroShield get off the ground. "One of the things that enables me to stand here today is that Sandbox created a safe environment where it was encouraged to look at this problem backwards, rather than from the nanostructure up," says Elise Strobach, CEO and founder of AeroShield.
The anniversary celebration speakers also included Ross Finman, CEO and founder of Augmodo; Laureen Meroueh, CEO and founder of Hertha Metals; and Daris Bunadar, chief scientist at Lightmatter. All were working on their PhDs when they started exploring commercial applications of their research. All recognize the critical role that MIT Sandbox, in addition to other programs — such as the MIT I-Corps Program, the Martin Trust Center for MIT Entrepreneurship, MIT Venture Mentoring Service (VMS), and the Bernard M. Gordon-MIT Engineering Leadership Program — played in their development as entrepreneurs. These programs offered the space to explore the possibility of not only founding a deep tech company, but also taking on an executive role as their ventures raised venture capital and grew into substantial companies. Today they all have big ambitions for the growth and impact of their companies — ambitions that are made possible only thanks to innovative technologies and an entrepreneurial drive.
Over its decade of existence, MIT Sandbox has supported over 4,000 teams, representing 8,000 participants associated with a wide range of industries and nonprofit endeavors. It has disbursed more than $11 million in non-dilutive funding, meaning the program takes no stake in the resulting ventures. MIT Sandbox has been involved in the creation of 475 companies in more than 30 countries, and companies that were started in the program have raised $8.7 billion in venture funding.
MIT Sandbox collaborates with other programs across MIT — including the Martin Trust Center, VMS, Kuo Sharp Center, MITdesignX, the PKG Center for Social Impact, the MIT Climate Project, I-Corps, and others — and its teams have excelled in innovation accelerators and competitions. Nine out of 10 winners of MIT's $100K Entrepreneurship Competition have been MIT Sandbox participants.
Apart from the program's impressive results, MIT Sandbox aims to first and foremost serve as a great educational tool, developing the innovators themselves.
"From an educator's perspective, this is just another incredible way to teach," said Abounadi at the anniversary celebration. "MIT Sandbox is a place where students can start seeing themselves as people who can create a meaningful impact in the world," she said, "and that is really what innovation and entrepreneurship are all about."
Paula T. Hammond, School of Engineering dean and Institute Professor, echoed the same sentiments: "What I find most compelling, year after year, is not only what students build, but how they change. They gain confidence, learn to refine before they scale, and begin to see themselves as people who can create meaningful impact, strengthening not only their own trajectories, but the broader MIT community."
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
This essay was written with Kasra Rafi, and originally appeared in The Guardian.
Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their careers and the work they love.
We think the contrary view is more likely, at least in the short-term. AI models are nowhere near as capable as experienced academic mathematicians.
This isn’t to say that AIs aren’t producing stunning mathematical results at the level of PhD researchers. In mid-May, OpenAI ...
Gage Coon: An Earth scientist exploring the power of microbes
Growing up in Waverly, Tennessee, Gage Coon spent much of his childhood outside. His family had everything from chickens to horses and even an emu named Big Bird. Coon and his cousins would explore the woods surrounding their home, and his father, a mechanic, taught him how to build and repair things around the house. His mother, a secretary at the local high school’s vocational school who loves gardening and birdwatching, encouraged him to experience as much of the world around him as he could.
That hands-on upbringing, which taught Coon to appreciate the natural world and the processes that sustain it, continues to influence how he approaches science today.
Now entering his third year as a PhD student in MIT’s Department of Earth, Atmospheric and Planetary Sciences, Coon studies some of the smallest organisms on Earth: microbes. His research focuses on how microorganisms cycle carbon and sulfur through the environment and how to leverage those processes to help address climate change. Though he studies organisms too small to see with the naked eye, the experimental nature of his work — whether in the lab or on a research vessel in the open ocean — is especially satisfying.
“I think I enjoy that physicality of seeing what I’m working with, seeing its change, and being able to touch it,” Coon says.
Coon did not initially set out to study microbiology. His interest in science began with chemistry. A high school chemistry teacher and a summer program introduced him to the subject. But later, at the University of Tennessee at Knoxville, he joined a lab focused on microbial biogeochemistry and was delighted to find a field that brought together the different areas that interested him: chemistry, the environment, and the larger climate processes shaping our Earth.
The transition from rural Tennessee to Cambridge, Massachusetts, and MIT has been a significant one. As a first-generation student, he did not learn about PhD programs until several years into college.
Once he discovered academic research, however, Coon was drawn to the possibility of spending his career learning.
“I discovered this world of academia, and so I was really excited when I learned about it,” he says. “I was like, ‘Oh my god, constant learning. That is exactly what I want to do forever.’”
Coon began studying the microbes that drive carbon and sulfur cycling in marine sediments as an undergraduate, eventually joining research cruises to investigate these processes firsthand.
His first research cruise, in 2022 after his second year of college, took him to the Atlantic continental slope to study methane seeps and how microbes prevent this methane from escaping to our atmosphere. For Coon, experiencing the ocean up close changed the way he understood the microscopic organisms he was studying.
“It is very powerful seeing yourself in the middle of the ocean, with a whole other world of complex life beneath you,” he says.
At MIT, working with his advisor Tanja Bosak, a professor of geobiology, Coon has continued studying microbial carbon and sulfur cycling, but with a greater emphasis on the applications. One of his major projects explores how microbes could be used to reduce methane emissions from wastewater treatment.
When wastewater is treated, microbes break down organic material in large tanks called anaerobic digesters. One of the final products of this process is the powerful greenhouse gas methane. However, Coon and his colleagues found a way to change what the microbes produce by adding gypsum, a waste product that is created from fertilizer manufacturing
The system uses the added gypsum to turn the methane into carbonate, which can be used to make cement, agriculture, and pharmaceuticals. The process also produces elemental sulfur, necessary for global fertilizer production, which is currently sources from oil and gas refinement. The approach effectively turns two waste products, sewage and waste gypsum, into useful materials while reducing greenhouse gas emissions.
For Coon, the possibility of creating a system that is both environmentally beneficial and economically useful is central to the project. Now that the laboratory experiments have ended, the researchers are looking toward conducting pilot-scale testing. Coon and his advisors have been communicating with companies interested in adapting the system to larger facilities, and hope the technology can eventually move beyond the laboratory.
“If enough small places start doing their pilot-scale studies, then hopefully you could convince some place like Boston or another big city to do this and really make a contribution to our global goal to decrease emissions on the gigaton scale,” he says.
The wastewater project is only one part of Coon’s PhD research. He also studies geological processes that could produce molecular hydrogen, a potential carbon-free energy source. His work examines how iron-rich rocks break down and generate hydrogen underground. He is continuing his thesis work by focusing on microbial competition for acetate, and what this means for global methane emissions from coastal wetlands. This work could improve future climate predictions and support engineered mitigation efforts to decrease emissions from these wetlands.
Across these projects, Coon is interested in the connection between the microscopic and the massive. But Coon’s PhD has also given him an opportunity to think about science beyond his own research.
One of the parts of graduate school he has enjoyed most is mentoring younger researchers. He has worked with a handful of students through MIT’s Undergraduate Research Opportunities Program and from Tufts University, teaching them laboratory techniques and experimental geobiology.
Outside the lab, Coon maintains some of the same connection to the natural world that characterized his childhood in Tennessee. He spends time hiking to explore local geology, playing bluegrass guitar, and speed-solving Rubik’s Cubes.
Looking ahead, Coon sees himself continuing in academia, working in government, or helping to bring environmental technologies into practice.
What matters most, he says, is continuing to produce knowledge that can help people understand and potentially improve the world around them.
“I do think, no matter what,” he says, “I’ll be somewhere thinking about how microscopic life connects to the global ecosystem and carbon emissions.”
EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity
EFF, Access Now, and Data Privacy Brasil are putting forward recommendations to strengthen robust privacy and data protection safeguards in the context of Brazil's elections. The recommendations stress the close relationship between violations of personal data protection and challenges to the integrity of electoral processes. They underscore how privacy and data protection guarantees are a crucial tool for curbing the targeted spread of false or manipulative content and other problematic strategies used by political actors that are amplified by digital technologies such as artificial intelligence systems.
The recommendations are part of a broader regional initiative and build on the legal and institutional safeguards already in place in Brazil. They seek to promote greater coordination among oversight institutions, civil society, and digital platforms, and encourage the solid implementation of privacy and data protection guarantees as drivers of electoral integrity. Read the full document below.
The Link Between the Integrity of the Electoral Process and PrivacyProtecting the integrity of the electoral process in the face of internet and social media use is a challenge that many policymakers are addressing or are willing to address. Online, content that can affect the integrity of the electoral process is increasingly personalized. This phenomenon is so concerning that it has been identified as one of the main global short- and medium-term risks.
In an era of generative AI, the economic cost and technical difficulty of producing and spreading false or synthetic content to deceive, manipulate, or simulate authenticity have been considerably reduced. That intensifies concern over the integrity of the electoral process. Meanwhile, online privacy and personal data protection remain unfinished business in Latin America.
There is an intrinsic connection between the ability to collect and process large amounts of personal data and the way false or manipulative content is created and distributed—on social media and messaging apps in particular, and on the internet in general. For this reason, applying strict laws and policies on personal data protection and privacy makes it possible to reduce the impact of false or manipulative content. This is especially important in electoral contexts, where such content affects and impoverishes public debate, directly affecting political and electoral rights and the integrity of the electoral process.
This phenomenon predates the emergence of the internet. However, the rise of new technologies accelerates the generation and spread of false and manipulative content. This is supported by the very economic model that sustains the platforms, amplifying its effectiveness and reach. On the one hand, social media platforms have content recommendation algorithms that use personal data to generate profiles to which they can then serve targeted advertising content, including explicitly political propaganda. This technique is known as "microtargeting."
Political microtargeting seeks to have a direct or indirect impact on democracy. It is used to persuade voters, to encourage or discourage turnout at the polls, or to raise funds using information that is deliberately taken out of context, inaccurate, or erroneous.
The control exercised by these companies raises serious concerns about people's rights. By having access to massive amounts of personal information, these companies have the ability to shape the content that users see and interact with. This happens through the construction of profiles that can reveal habits, social relationships, political preferences, and opinions, to mention a few examples. Personal data is the fuel that amplifies risks to the integrity of the electoral process. That’s true whether it’s provided by the users themselves or generated by the platforms from their interactions online.
For disinformation actors, access to sophisticated tools—such as those used to create "deepfakes" through generative AI, or "bots" programmed to spread content and seek to manipulate public opinion—boosts the effectiveness of this microtargeting in terms of quality and scalability, making it harder to detect as false or manipulative content. AI-generated avatars and synthetic characters that simulate voters, influencers, hosts, commentators, or community leaders can produce footage that appears spontaneous, fabricate the voices of artificial political actors, and make it harder for users to identify if a given public statement was created or mediated by technology.
In this context, paid promotion with nanotargeting seeks to reach increasingly specific profiles with customized content, and AI-based tools are used to assess and map its impact on social networks. Drawing on the personal data of groups of voters, profiles of "synthetic voters" are created to test messages or strategies in search of the most efficient way to influence real voters.
This rapid expansion of AI systems and hyper-personalization with data can lead to a problem of "epistemic erosion" for democratic societies, as pointed out by the UN's Independent Scientific Panel on AI Governance in 2026.
At Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation, we point to the enforcement of personal data protection laws and public privacy policies as an efficient mechanism for improving the quality of our democracies and reducing the manipulation of public discourse in digital environments and its impact in electoral contexts. Measures to broaden access to information for electoral decision-making, and to ensure transparency about campaigns' and political parties' use of digital technologies built on the massive processing of personal data, also play a relevant role in guaranteeing the integrity of the electoral process.
Recommendations for Safeguarding the Integrity of Electoral Processes in Brazil in the Face of New TechnologiesConcern about the effects of spreading false, manipulative, or deliberately decontextualized content is particularly heightened in electoral contexts. From Argentina to Mexico, many countries in Latin America, including Brazil, are holding or will hold significant electoral processes in the coming period.
Providing the public with quality information from a range of sources is an essential element for the exercise of political rights. In order to safeguard the electoral process, these countries must enforce their privacy and personal data protection laws through their competent authorities, in coordination with their judiciaries and electoral courts.
Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation propose the following recommendations to protect the integrity of the electoral process by guaranteeing privacy and data protection during electoral contexts:
1. Strengthen personal data protection guarantees and policies as a key element for the integrity of the electoral process, in particular the principles of necessity, purpose, and proportionality:
- Prohibit the processing of sensitive personal data (such as philosophical beliefs and the labeling of ideological leanings), including inferred data, that reveals or could reveal people's political preferences for the purpose of targeting political content. In electoral contexts, the processing of sensitive personal data is only legitimate when the person has given their consent in advance, explicitly, and with strictly limited and clearly disclosed purposes of use and transfer.
- Processing must be carried out only on personal data that is strictly necessary for the purpose being pursued.
- Prohibit adding users to instant messaging groups for political outreach purposes, except in exceptional cases involving lists of political party members or where prior and informed consent has been given by the data subject.
- Free, specific, and informed consent means that the person is able to make a real choice, set apart from other choices, and does not run any risk of deception, intimidation, coercion, denial of access to products or services, or other significant negative consequences if they do not give their consent.
2. Political parties, federations, and coalitions must improve the information made available to the general public about their personal data processing activities in electoral contexts, including:
- The personal data processing policy adopted, in compliance with data protection legislation and electoral legislation, including the measures adopted to prevent breaches of the general protection principles, to record personal data processing operations, to obtain consent appropriately, and to ensure technical and administrative security in data processing;
- Communication channels where the data subject can obtain information about the processing of their personal data, exercise the rights provided by law, and request to opt out of receiving electronic and instant messages.
- Information about the profiling they carry out for electoral purposes and about the procurement and use of data-based digital technologies in this context, including for purposes of paid promotion, microtargeting, network analysis, and prediction of voters' reactions or behavior.
3. Strengthen cooperation mechanisms between the National Data Protection Authority (ANPD) and the Superior Electoral Court in order to:
- Improve communication channels and strengthen joint initiatives to oversee compliance with data protection guarantees in the electoral context, with the publication of periodic enforcement reports.
- Identify and dismantle coordinated strategies that compromise the integrity of the electoral process and carry out online activities that pretend to be "organic" and citizen-based when they are in fact funded or coordinated by a party, government, or company, such as bot farms, fake personal accounts managed by a single entity, AI avatars and synthetic characters that simulate real voters in order to manipulate public opinion, among others.
- Within the scope of their powers, require the preparation and publication of a data protection impact assessment in cases involving the use of sensitive personal data or emerging technologies for voter profiling.
4. Authorities, political parties, communicators, and social media platforms must ensure, as far as possible, that the population has access to adequate and relevant information for electoral decision-making.
- Political parties, electoral authorities, and data protection authorities must allocate a percentage of their communications budget to warning about the consequences of microtargeting in electoral contexts; and about the use of AI avatars or synthetic voters to simulate support, rejection, outrage, or spontaneous political mobilization.
- Strengthen alliances with fact-checkers and other relevant communicators, such as civil society organizations, influencers, and others, to identify campaigns that compromise the integrity of the electoral process and to inform the public about such alliances through different channels, including official government channels.
- Systematize the electoral proposals developed by candidates and their electoral platforms according to thematic areas to facilitate comparison between political parties.
- Agree on strategies between authorities and online platform companies, including social media platforms and chatbots, at the start of electoral periods, so that priority is given to content developed by electoral authorities.
- Every body, protocol, or policy created that involves authorities or public entities must be communicated in accordance with proactive transparency standards.
5. Platforms must disable microtargeting tools for political and electoral content during previously established periods.
6. Authorities, technical actors, academics, civil society, and/or social media platforms must collaborate in creating an algorithmic impact analysis lab that makes it possible to oversee compliance with these recommendations.
- Produce reports on the results achieved, in particular those that document the existence of microtargeting, the use of personal data for targeting, and exposure to varied content in electoral contexts.
- Establish strict cybersecurity protocols so that the labs prevent access to real users' private information.
7. The authorities responsible for overseeing personal data protection and electoral matters must have sufficient functional, economic, and technical autonomy and independence to guarantee the proper exercise of their powers.
Looking beyond natural sequences
A protein’s function is determined by its structure, and structure — the way a protein folds — is determined by its sequence of amino acids, the building blocks of proteins.
Many methods for designing novel proteins, including examples that could bind to a disease-causing molecule in our cells, involve a two-step process: The structure comes first, and then a machine-learning framework generates a repertoire of sequences that could potentially adopt that structure.
In nature, many different amino acid sequences can fold into the same structure. At the same time, one amino acid sequence can potentially adopt different structures depending on the protein’s flexibility or a functional trigger. Therefore, when researchers use artificial intelligence to design new proteins, the challenge is to guide AI to “see” that there are many potentially useful answers — that many sequences can adopt the same fold
“For years, the field has measured success by asking whether a model can reproduce the protein sequence that evolution happened to select — our work shows that this isn’t the best metric for protein design,” says Amy E. Keating, Department of Biology head, Jay A. Stein (1968) Professor of Biology, professor of biological engineering, and senior author of a paper recently published in PNAS.
PottsMPNN, a new machine-learning framework developed in the Department of Biology, incorporates the physical principles that govern protein structure and stability, improving sequence generation and the ability to predict how mutations will affect a protein’s stability. In other words, the model has a better understanding of the sequence-energy landscape, meaning the relationship between the identity of each amino acid and the stability of the protein.
Adding this framework to a protein design pipeline will allow researchers to design structurally feasible proteins with sequences that don’t resemble those of any native protein.
“If we’re thinking about a completely novel, designed structure, there would be no native sequence to compare it to,” says graduate student and lead author Foster Birnbaum. “What we actually care about is how likely the generated sequences are to fold into the desired structures, how well the model understands the sequence-energy landscape, and how well it can predict the effect of mutations on the stability of the protein.”
Beyond the noise
In the same way that AI has recently powered some dramatic social changes, so too has machine learning impacted the pace and breadth of fundamental biological research. Only recently has it become possible to reliably use a computational model to generate a protein structure or sequence. Perhaps the most widely used model today, however, was released in 2022.
“For a field that’s moving as fast as machine learning in biology, that model has not been surpassed — we’ve been trying to understand why that is, and what it is about that model that makes it so useful,” Birnbaum says.
Birnbaum was first interested in strategic applications of something researchers call “noise,” or adding variations to a protein structure during training. Noise decreases the tendency of the model to overly mimic native sequences, increasing the diversity of structures for which it’s able to generate sequences.
PottsMPNN also uses a pairwise distribution to capture interactions between amino acids. The ability to account for the physical interactions between all 20 possible sequence options at a pair of positions in the protein is a key reason that PottsMPNN more accurately models the sequence-energy landscape than other methods.
Finally, Birnbaum says, they introduced sets of evolutionarily related sequences into training the PottsMPNN framework to teach the model how different sequences can adopt the same folded structure.
Birnbaum acknowledges that in trying to shift away from adhering to native sequences, incorporating evolutionary information is, in some ways, still a reliance on them. But PottsMPNN succeeded in demonstrating that as the model depends less and less on native sequences, structural compatibility and energy prediction, including for novel proteins, improve.
Protein design in the age of AI
“Once we can design any protein we want, that enables us to do a potentially scary amount of biological engineering,” Birnbaum says. “It’s a difficult task, but I’m really optimistic about this century’s progress in biology.”
Birnbaum hopes that the model could be further improved and fine-tuned for a specific task, which has in the past led to better predictions, for example, on the outcome or consequence of a particular mutation.
Ultimately, according to Keating, “Our methods move the field toward designing useful new-to-nature proteins for diverse applications while providing a stronger foundation for future advances.”
New type of attack can slip past the defenses in your computer’s processor
Modern processors are fast, in part, because they guess. Rather than waiting to find out which way a program will branch, a chip predicts the likely path and races ahead. When the guess is right, time is saved. When it's wrong, the work is discarded, but traces of it linger. Since the Spectre vulnerability was disclosed in 2018, attackers have known how to read those traces to pull secrets out of memory they should never see.
Chipmakers and operating system developers have spent years building defenses. A new study from MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL) shows that a key assumption behind many of them doesn't hold.
The defenses work by wiping or isolating the processor's prediction machinery, removing anything an attacker might have planted. The catch, as PhD student Daniël Trujillo and MIT Assistant Professor Mengjia Yan point out, is that the wipe and the moment the predictions get used can't happen at the same instant. There is always a gap — sometimes only a handful of instructions wide. Anything that runs in that gap can dirty the machinery all over again. The researchers call this class of attack "TONTOU."
Mind the gap
Their contribution is a reliable way to get code into that gap. Computers constantly pause whatever they're doing to handle interrupts: small, routine tasks triggered by timers, network traffic, and hardware. Ordinary programs can set those timers themselves. By tuning a timer with enough precision, Trujillo and Yan can make the processor take its detour at exactly the wrong moment, and the interrupt execution does the contaminating. They call the technique "interrupt injection."
The team tested four processor generations from Intel and AMD, and got mispredictions on both. On Intel chips, the attack defeated two different protections, one built in software for older parts, one built into the silicon of newer ones. Curiously, the newer protection held firm on one Intel generation and failed on another, suggesting chipmakers implement the same nominal defense in meaningfully different ways.
AMD's defense, called saferet, cleans the prediction machinery immediately before each use, leaving a vulnerable window just two instructions wide, which typically execute within tens of nanoseconds. The researchers hit it anyway, by slowing down the processor at that exact spot to make the target easier to strike.
From a bad guess to a password file
To show what this means in practice, the team built a working exploit on an AMD system running a current Linux kernel. They first stripped away a defense that scrambles where the operating system sits in memory, succeeding in all 10 tries in about nine minutes each. That helped them read protected memory at roughly five bytes per second — slow, but fast enough to locate and copy "/etc/shadow," the file storing the system's root password hash, in half their attempts.
The paper suggests cleaning the prediction machinery a second time, when the interrupt finishes. That looks workable on AMD. On Intel it may backfire: Because the attack relies on the interrupt leaving behind a consistent state rather than any particular one, the standard fix could make the attack more reliable, not less. Newer Intel chips include a dedicated instruction that appears to help.
The other option, blocking interrupts during the vulnerable window, would likely cost too much performance to be practical.
Trujillo and Yan notified AMD and Intel in early February and reached Linux kernel maintainers in March, coordinating with AMD to warn cloud providers and other downstream customers. AMD then released a patch that mitigates the attack, which can be obtained by updating your operating system. Their code is publicly available.
The research was supported, in part, by the U.S. Air Force Office of Scientific Research under an award made through the U.S. Department of War, and ACE, one of the seven centers in JUMP 2.0, a program sponsored by the U.S. Defense Advanced Research Projects Agency (DARPA). It was presented at both Black Hat USA and USENIX Security this month.
LLM-Based Social Engineering Scams
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive:
The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offenses...
MIT engineers create a system for building shape-changing smart devices
A new set of modular components allows users to create reconfigurable smart devices with electrical connections that keep working no matter which shape the structure forms.
This electrical modularity can enable engineers to design interactive devices that can sense which shape they have taken, without the need for external wires. For instance, the modular components, which the researchers call “bifur-circuits,” could be used to rapidly design and prototype adaptable smart devices, like assistive furniture that helps individuals change body positions while recovering from injuries or reconfigurable robotic grippers that remain electrically connected when they change shapes for different applications.
Developed by MIT researchers, these 3D-printed building blocks, which are a type of structure known as a mechanical metamaterial, can be combined to form many more possible configurations than traditional metamaterial structures.
In a study presenting the new system, the researchers demonstrated several interactive objects, including a chair that converts to a table with storage and can also flatten for stowing. The structure senses its configuration and sends corresponding messages to an electronic display.
These new metamaterials could also be used to design antennas for communications and sensing that form new shapes to adjust their frequencies in changing environmental conditions, without bulky mechanical parts.
“Metamaterials can make complex mechanical assemblies easy to manufacture just by using repeating units. Our work expands on this design space. If we think of mechanical metamaterials as building blocks, then our work is one way to take advantage of their geometry to embed intrinsic intelligence into hardware, which could open many possibilities,” says Marwa AlAlawi, a mechanical engineering graduate student and lead author of a paper on the devices.
AlAlawi is joined on the paper by co-senior authors Ticha Sethapakdi, an electrical engineering and computer science (EECS) graduate student at MIT; and Stefanie Mueller, an associate professor in MIT’s departments of EECS and Mechanical Engineering and leader of the Human-Computer Interaction Group at the Computer Science and Artificial Intelligence Lab (CSAIL). Their co-authors include others at MIT, the University of Tokyo, and the University of Michigan. The research will be presented at the ACM Symposium on User Interface Software and Technology.
Shape-changing interactive structures
Mechanical metamaterials are programmable, three-dimensional structures of repeating units that can form complex shapes due to their geometries. When squeezed, pushed, or pulled, metamaterials can bend or twist in precise ways.
For instance, “auxetic” metamaterials get wider when stretched, instead of narrowing.
In prior work, the MIT researchers used auxetic metamaterials to build reconfigurable antennas that formed three shapes depending on how the structure was stretched. This allowed the antenna to dynamically adjust its frequency range without complex, moving parts.
Next, the team wanted to expand the number of antenna configurations but were limited because the auxetic metamaterials could only form three fixed states.
In this work they created “bifur-circuits,” which are auxetic metamaterials that can form many more shapes based on how the modular units are connected and rotated.
The units are also designed to be electrically modular. Due to the way conductive material is integrated into the bifur-circuits, electrical connections throughout the structure are maintained no matter how the object is rotated, pressed, or twisted to form new shapes.
To create interactive objects with many possible configurations, bifur-circuits leverage a property known as mechanical bifurcation.
Mechanical bifurcation is a sudden change in how a mechanism behaves when a force exerted on it passes a tipping point. For instance, when you gently bend the ends of a plastic ruler, once that force reaches a critical threshold, the ruler buckles.
In bifur-circuits, this bifurcation occurs when connected blocks are rotated in certain ways around a pivot point. The property allows connected blocks to form more stable configurations than one block could on its own.
Adding more bifur-circuits to a structure exponentially increases the number of potential configurations.
“Bifurcation allow us to significantly expand on this reconfigurability space. Just adding one extra unit gives us so many more combinations out of the same structure,” says AlAlawi.
Connecting and rotating components activates a unique circuit between adjacent units. This interactivity allows the units to communicate with one another, enabling the structure to sense its configuration.
One of the biggest challenges the researchers faced was incorporating a conductive material that was flexible enough to bend, but still offered enough efficiency in the flow of electricity.
“The conductive material was a constraint we had to work around in the design process, and it dictated how the sensing between blocks would happen,” AlAlawi says.
Once they perfected the design, the researchers tested the durability of reconfigurable structures by compressing them more than 10,000 times. The structures showed no degradation in electrical connectivity.
The researchers also developed a user-friendly construction and simulation tool to simplify the bifur-circuit design process. The software generates instructions for a multimaterial 3D printer, which can fabricate the reconfigurable objects in one pass.
They demonstrated the versatility of bifur-circuits by fabricating a chair that can sense its geometry when its shape is changed to a tea table, as well as a shape-shifting controller that will launch one of several video games based on its configuration.
Bifur-circuits could someday be used in applications like interactive rehabilitation tools, shape-changing grippers for modular soft robots, or reconfigurable shelters that could respond to changing environmental conditions after a natural disaster.
In the future, the researchers want to explore more applications for bifur-circuits. They also want to add more interactivity into the structures and investigate additional metamaterial shapes.
“Bifur-circuits are one step toward developing mechanical building blocks with integrated intelligence. It would be interesting to build on this work and come up with building blocks that allow us to create a structure with any form or shape we want, and which are structurally stable and can be actuated,” AlAlawi says.
This work was funded, in part, by Japan’s Science and Technology Agency and the Bahrain Crown Prince International Scholarship Program.
A List of ICE Subpoenas to Tech Companies
Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and international students who attended a protest.
A favored tool in these speech chilling investigations are administrative subpoenas sent to technology companies, requesting basic subscriber data about their users. For example, from 2018 to 2020, ICE sent nearly 500 administrative subpoenas to Meta, Google, and Twitter (now X), according to documents obtained by Just Futures Law. In just the second half of 2025, the Department of Homeland Security (DHS) sent 21 administrative subpoenas to Reddit, according to its Transparency Report.
While some subpoenas are routine, ICE has been forced to withdraw others after users challenged them in court or companies pushed back. These challenged subpoenas exceeded the agency's statutory authority and violated users' First Amendment rights.
Below is a non-comprehensive list of DHS subpoenas that we gathered going back to 2025, looking at public reporting and court cases. This is likely an undercount. The full scope is hard to pin down because these subpoenas typically only come to light when a user is given notice and challenges them in court, or when a company documents them in a transparency report (so far, only Reddit appears to break out specific numbers on DHS subpoenas). In addition, DHS has been slow to respond to our Freedom of Information Act requests and lawsuits seeking records that would show how many administrative subpoenas ICE has sent to social media companies since 2025.
If you know of other subpoenas that are not on this list, please reach out to info@eff.org. While the government has abused the subpoena process in other areas, particularly to hospitals, this list focuses on DHS and ICE subpoenas to technology companies for user data.
DATE ISSUED
(and link to subpoena)
TARGETED COMPANY INDIVIDUAL USER TARGETED OUTCOME 3/17/25 Facebook Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 3/23/25 Google Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 4/1/25 Google Amandla Thomas-Johnson, international student who attended pro-Palestinian protest Google disclosed data to ICE on 5/8/25 9/4/25 Meta 6 accounts in Southern California that documented immigration activity, including LB_Protest, Long Beach Rapid Response Network, and Stopice.net Withdrawn after court challenge on 11/24/25 9/11/25* Meta (Instagram) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 9/11/25* Meta (Facebook) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 10/30/25 Google Retired Philadelphia user who emailed criticism to U.S. prosecutor Withdrawn after court challenge on 2/5/26 2/4/26* Google Social media user who regularly posts criticism of the President Subpoena challenged in Court 2/19/26* Reddit "Tired_Thumb," user who posted about ICE officer Withdraw after court challenge on 3/27/26; replaced with grand jury subpoena 2/27/26* X "podslurp,” who posted publicly available address information about ICE officer Withdrawn May 2026; replaced with grand jury subpoena 3/7/26 PayPal/Venmo "Voices of Racial Justice," a racial justice organization in Minnesota PayPal/Venmo disclosed data 3/20/26 4/3/26* Google (YouTube) @TheDonLemonShow, GeorgiaFort, @DemocracyNow, and seven other accounts that reported on protest at Minnesota church Google Objected 4/7/26 4/12/26* T-Mobile Minnesota journalist Georgia Fort and others T-Mobile disclosed data on 4/12/26 First half of 2025 Reddit Reddit account Subpoena withdrawn after questions from Reddit Second half of 2025 Reddit 11 Reddit accounts that posted content "critical of ICE actions" 3 subpoenas withdrawn after Reddit objected* = denotes summonses issued under 19 U.S.C. 1509, an authority that has been abused in the past, according to DHS's inspector general.
EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms
Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool that can be made safe with the right policy or feature update—they are irredeemably harmful.
EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines.
EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines. EFF applies every tool available to eliminate ALPR surveillance and the harm it enacts.
The Case Against ALPRsA note about scope: This post addresses ALPR mass surveillance. It does not address the wider universe of automated traffic enforcement (ATE) such as conventional red light and speed cameras that solely ticket a specific violation, without retaining or networking data on uninvolved drivers. But lawmakers and purchasers should guard against efforts by vendors to piggyback on ATE contracts to market ALPR mass surveillance systems.
ALPRs are frequently marketed as a narrow tool for specific purposes, such as recovering stolen vehicles. But in practice, these sensors sweep up data on every driver who passes a camera, and store it in searchable databases. That indiscriminate collection and retention is precisely why ALPR-fed surveillance systems can be easily weaponized against immigrants, political dissidents, and other targeted communities as ICE and other federal agencies escalate their assault on civil liberties. There is no configuration of an ALPR network that eliminates this risk, because the risk is the mass surveillance itself, not a misuse of it.
Of course, ALPRs cause other predictable harms. Innocent drivers are recurringly arrested and menaced by police because of ALPR errors. Officers regularly abuse ALPR systems to stalk past and potential romantic partners. Creating any database of personal information—including ALPR surveillance databases—inherently creates risk of data theft and subsequent harm to data subjects. And ALPR surveillance of protests and targeting of activists chill participation in First Amendment-protected dissent. But even if these downstream harms could all be prevented (and they likely can’t), ALPRs would remain an intolerable form of mass surveillance.
Fighting on Every Front to Eliminate ALPR SurveillanceAt the city level, EFF works with community members and decision makers to outright refuse ALPR purchasing. ALPRs are not inevitable. The same decision mechanisms used to facilitate runaway surveillance purchasing in U.S. localities can be turned against these systems to dismantle them.
EFF also pushes state legislatures to establish strict state-level limits on ALPR surveillance, such as data-deletion rules and use restrictions. Building such constraints into statute can mitigate the harms of existing ALPR systems.
In courts across the country, EFF files amicus briefs arguing that warrantless police searches of ALPR databases violate the Fourth Amendment. In California state court, EFF and the ACLU of Northern California are suing on behalf of two community groups, SIREN and CAIR-CA, arguing that the San Jose Police Department's practice of letting officers search stored plate data—to the tune of over 100,000 times a year—without a warrant violates the California Constitution. We’ve also sued to block California law enforcement from sharing ALPR data with federal and out-of-state agencies, in violation of a California statute.
A big part of EFF’s work is exposing the harms of ALPR surveillance. Our investigative team tirelessly collects information about how law enforcement uses ALPRs with public records requests, sues to enforce such requests, and publishes reports about them. We’ve also successfully lobbied for a State Auditor investigation of law enforcement’s use of ALPRs.
Coordinated Action Against Mass SurveillanceEFF practices integrated advocacy because all of these tools work best together. City refusals, statehouse restrictions, impact litigation, and investigative activism are different levers EFF pulls toward the same end: eliminating ALPR surveillance, and building the durable public power needed to keep it off our streets. A council vote against a Flock contract and a warrant argument in Santa Clara County Superior Court are both, at their core, the same fight: rejecting mass surveillance infrastructure outright, and using every venue available to eliminate its harmful presence and consequences.
MIT student leaders: Q&A with McCormick Hall co-president Sydney Baller
A Colorado native who originally planned to attend college close to home, Sydney Baller decided to come to MIT for the strong academic community. She knew she had found a new home in McCormick Hall after attending its Campus Preview Weekend (CPW) events in 2023.
McCormick Hall opened in 1963 as MIT’s first women’s residence — a move that provided women the first real opportunity to attend the Institute in significant numbers. To support continuity of the McCormick community through its first renovation in its 63-year existence, MIT has established a dedicated McCormick lounge in the Stratton Student Center (Building W20), funded efforts to maintain dorm traditions, and more.
Now a rising senior in mechanical engineering, Baller is a year-round athlete (basketball and outdoor track), crafting enthusiast, and co-president of McCormick’s student government. With construction underway to renovate the residence, Baller is taking time to help support future MIT women so they can have the same powerful residential experience she’s had.
McCormick is scheduled to open again in August 2028 — well after Baller graduates. In this interview, she describes her thoughts on the transition and how she is working to maintain a sense of community among the dorm’s residents and incoming first-year students while updates are ongoing.
Q: Why did you choose to live in McCormick?
A: I was recruited to play basketball in college, and other schools were pressing me for a decision. MIT was like, “Well, you got in. It’s up to you what you want to do.”
So I came to CPW to find out what the campus is like. I stayed in [co-ed] Baker with one of my teammates. It was weird for me. I could have probably adjusted to being in a living space with men, but I guess I just bristled at the concept. I grew up in a Christian household, so I was used to certain things. I shared a bathroom with my sister, not my brother.
What really set it in stone was going to the other CPW events at McCormick. They were like — “We’re an all-women’s community. The dorm is quieter. Everyone’s super nice. We like to do crafts.” Then they showed us the craft room. A whole room dedicated to crafts? I was sold.
Q: How would you describe the community in McCormick?
A: On the day my dad helped me move in, we had three suitcases I brought from Denver. He and I sorted out my stuff, and then we went down to the laundry room. I thought I saw a big spider or something, and a girl who was standing there asked, “Are you talking about Despereaux?” I had never even talked to this girl before. Even this was a way to bond!
There’s a lot to love. Our heads of house are amazing. After the last day of class every semester, they have a tea and churro study break. They make the churros themselves. So we just come down, drink tea, chat with our friends, and eat churros and little tea sandwiches. That’s very McCormick — a little break with some good chatting.
The heads of house also run something called “karao-cake.” When I first heard about it, I was like — “I’ll go for the cake.” They have a karaoke machine with a bunch of microphones attached, and we all sing songs together. And if they pick a song we don’t like, we all yell “No!” Everyone's on the same page. It gives really good sisterhood vibes.
Also, I personally loved our all-women’s gym. As someone who has been an athlete for many years, I can say: We had amazing equipment in there. I’d rather work out where I don’t have to fight for a rack. I can just go and lift and do my workout.
Overall, the McCormick community is what you make of it. You can choose to be invested and have a great time. You can also just choose for it to be the place you come back to every night. I was in the same room sophomore and junior year, and so were a lot of the girls around me. By the end of last year it was like that scene from the “Barbie” movie — when they’re all in their houses, and say “Good night, Barbie! Good night, Barbie!”
Q: How did you get involved in the renovation project?
A: I originally joined house government to be the craft chair and athletic chair. Later, I decided to run for co-president because McCormick was my first home away from home. I had honestly planned to go to college close to home, or where my friends were going. The thought of going to another state and being on my own just seemed too out of the ordinary. When I came here, I knew one person.
When MIT first told us the dorm was being renovated, I was pretty excited to see what they were going to do. They held all-dorm events, brought donuts, and asked us to come and talk about what we envisioned for renovation. I said I wanted the biggest craft room you can imagine, pianos in every corner, and to get rid of the study cubicles in the penthouse no one uses. We really got to dream, right?
But then MIT announced a one-year delay in the renovation, and you have the emotions. McCormick was home — and then they say it’s going to get renovated, then they say it will be next year. When my friend and I decided to run to become co-presidents, the rest of the dorm really didn’t want to talk anymore. We started meeting with [the Division of] Student Life on Zoom, but it was hard to get resident engagement. I appreciate that we’re in the conversations. We get to hear the numbers before other people do, but that’s just information.
Q: What’s the role of house government while the residence is being renovated?
A: We do things that keep the energy alive. McCormick is more than just a building. The housing office just told us more than 300 incoming students expressed interest in the McCormick community, even though the dorm is being renovated.
To bring momentum into the renovation, we held an end-of-semester party where we dropped nice crewnecks, got a food truck, and had popcorn, cotton candy, a DJ, games, face paint — all the stuff. We also enjoy dorm movie outings, which would be a great tradition to continue. When the Taylor Swift “Eras Tour” movie was in theaters, we all got to have the experience of going over on the T together, and then sitting together singing Taylor Swift songs. We also saw “Wicked” and “Wicked for Good.” We have chill events, too, like crochet, painting, and eating pastries. All of this is about being together. Even if we’re not sitting there having a conversation, we’re existing together. That feels like home.
I’m also trying to help people who are dealing with the transition. It can be hard. You can’t have our heads of house move with you, or the craft room. You can’t have the cute merch that one of our students designs. If someone who has been moved to Maseeh doesn’t know anyone else on their floor, they don't get to have that Barbie moment. But maybe McCormick is holding a study break where they can hang out — a throwback to the old days, where we can craft, or drink boba, or whatever.
Q: Has the effort been worth it?
A: It’s worth it to me because I get to keep the momentum going, but I won’t know for sure until the dorm is open again and a freshman checks into their room and experiences the community.
They took our feedback doing the donuts and stuff, and they put a lot of our ideas into the design, but now I’ve got to see the finished product. I know MIT has to balance a lot of things, so they’re not necessarily going to do everything just because we asked.
Q: What are your goals for when the renovation’s finished?
A: The building won’t reopen before I graduate, so I guess there’s two things.
When I graduate, I would hope to see a house government team that’s excited to continue the traditions. It’s different to be affiliated with a community than to be living in it. I would love to graduate and leave here knowing McCormick is in good hands and the momentum our generation started helped drive us through to reopening.
And when the dorm reopens, I want to come back and get a tour. I would just love to see the excitement around being back in the dorm. I’ll buy my own plane ticket!
