Feed aggregator
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary:
The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment. As far as we were able to infer, across the course of being evaluated on this benchmark, the agent inferred that Hugging Face may host that benchmark’s models, datasets, and reference solutions. We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own...
EFF at BSidesLV, Black Hat, and DEF CON 👨💻
It's time. Time for tinkerers, security researchers, hackers, and fellow nerds to gather together in signature black hoodies and utilikilts to beat the heat in Las Vegas for the summer security conferences: BSidesLV, Black Hat USA, and DEF CON.
EFF's lawyers, activists, and technologists are excited, as always, to support this community of folks that push computer security forward. If you're attending the conference and have any legal concerns about an upcoming talk or sensitive infosec research—during the Las Vegas conferences or anytime—don't hesitate to reach out to info@eff.org where our intake team is ready to assist! Share a brief summary of the issue, and we'll do our best to connect you with the right resources. You can also learn more about our work supporting technologists on our Coders' Rights Project page.
Be sure to swing by the expo areas at all three conferences to say hello to your friendly neighborhood EFF staffers! You'll probably spot us roaming the conference halls, but we'd love for you to stop by our booths to catch up on our latest work, get on our action alerts, and become an EFF member! For the whole week, we'll have our limited-edition DEF CON 34 t-shirt on hand. We're excited to see them—and other EFF gear—take over each conference!
EFF Staff Presentations Privacy's Defenders: How Hackers Helped and Can Do So AgainHackers have a long history standing up for justice and that history has a lot to teach and inspire the hackers of today as we face a world with 360-degree surveillance that is increasingly marshaled against us by both companies and governments. My talk will tell background and stories from my book, Privacy's Defender, that tells the story of my 30 years working with EFF to try to protect security and privacy in the digital age. Cards on the table: I'm trying to recruit you to join in the fight.
WHERE: Florentine F | BSides Las Vegas
WHEN: Monday, August 3 @ 11:00
WHO: Cindy Cohn - Former EFF Executive Director
Panelists from the EFF Staff will give brief updates on key topics in their expertise before turning it over to BSides attendees to ask their burning questions about policy, advocacy and making the future of tech brighter. It's a dynamic session fostering engaging discussions on digital rights featuring an EFF staff attorney, activist, and public interest technologist.
WHERE: Florentine F | BSides Las Vegas
WHEN: Tuesday, August 4 @ 14:00
WHO: EFF's Rory Mir, Kenyatta Thomas, Alexis Hancock, Haley Pederson, and Cindy Cohn
WHERE: Voting Village | DEF CON
WHEN: Friday, August 7, 10:30-11:00
WHO: EFF Staff Attorney Tori Noble
EFF's Outgoing Executive Director Cindy Cohn' presents her first-person stories from her recently published book, Privacy's Defender, that take you Inside the privacy battles that have shaped today's Internet. It includes the hackers who helped free up encryption technology from US governmental control, allowing us to have the still imperfect privacy and security we now have online, and the battles to stop the mass NSA spying and eternal gag orders that arose from the governments formerly secret mass spying programs in the aftermath of the 9/11 attacks. She then draws from that long career of legal activism to the fights of today and tomorrow, featuring the role that hackers can play in helping to bring about a better, more just future.
WHERE: Creator Stage 1 | DEF CON
WHEN: Friday, August 7, 15:00-16:30
WHO: Former EFF Executive Director, Cindy Cohn
WHERE: Creator Stage 7 | DEF CON
WHEN: Saturday, August 8, 13:30-14:30
WHO: EFF Director of Engineering Alexis Hancock & EFF Social Media and Video Manager Kenyatta Thomas
Privacy should be accessible to all. Historically, counter-surveillance tools have been expensive, complex, and inaccessible to most individuals, often limited to well-funded researchers and costly hardware configurations. The ESP32 offers a transformative alternative. This presentation will demonstrate how an affordable microcontroller has become the foundation for a growing suite of open-source, user-friendly anti-surveillance tools. We will discuss the technical features that make the ESP32 a compelling choice for these applications, including passive 802.11 and Bluetooth monitoring, OUI-based device fingerprinting, and robust cryptographic capabilities. Applications include detecting police body cameras in operational environments, mapping Flock Safety automatic license plate recognition (ALPR) infrastructure, identifying unauthorized drones, detecting radio frequency jamming across 2.4GHz, 5GHz, and cellular bands, and tracking autonomous robots operating with known-vulnerable firmware. These tools are cost-effective and freely available. We will also consider future developments in accessible counter-surveillance hardware, such as the ESP32-S5 with 5GHz support, GPS, displays, haptics, etc. Advancing anti-surveillance culture requires designing devices that individuals are motivated to use and carry.
WHERE: Main Track 1 | DEF CON
WHEN: Sunday, August 9, 10:00-11:00
WHO: EFF Senior Staff Technologist Cooper Quintin
WHERE: Policy Village | DEF CON
WHEN: Sunday, August 9, 12:30-14:00
WHO: EFF's Thorin Klosowski, Cooper Quintin, Alexis Hancock, Tori Noble, Rory Mir & Cindy Cohn
We’re going all in on internet freedom. Take a break from hacking the Gibson to face off with your competition at the tables—and benefit EFF! Your buy-in is paired with a donation to support EFF’s mission to protect online privacy and free expression for all. Join us on Friday, August 7 at 12:00 at theHorseshoe Poker Room. Play for glory. Play for money. Play for the future of the web.
WHERE: Horseshoe Poker Room, 3645 S Las Vegas Blvd, Las Vegas, NV 89109
WHEN: Friday, August 7, 12:00-15:00
Yes, it's exactly what it sounds like. Join EFF at the intersection of facial hair and hacker culture. Spectate, heckle, or compete in any of four categories: Full beard, Partial Beard, Moustache Only, or Freestyle (anything goes so create your own facial apparatus!). Prizes! Donations to EFF! Beard oil!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Friday, August 7, 13:00-14:00
Join us for some tech trivia on Saturday, August 8! EFF's privacy and security experts have crafted a new trivia challenge for DEF CON 34! Compete as a team in our no-holds-barred showdown to prove mastery over the obscure facts of digital security, online rights, and internet culture. The First Place team wins a set of custom Cybertiger Champion Badges and EFF swag. Second and third place teams will also win Badges and EFF gear. Invite your friends OR show up and make new friends! Did someone say BRIBES? The world is unfair! You too could influence the judges to add a point or two to your team's tally. Overall Bribe winner also wins a custom badge!
WHERE: Contest Stage (near the entrance to Hall 1)
WHEN: Saturday, August 8, 17:00-20:00
Grab a copy of former EFF Executive Director Cindy Cohn's new book, Privacy's Defender—and get it signed—while at DEF CON 34!
WHERE: Exhibit Hall West 4 (Book Signings)
WHEN: Saturday, August 8, 11:00-12:00 AND 13:00-14:00
Come find our table at BSidesLV (Middle Ground), Black Hat USA (back of the Business Hall), and DEF CON (Vendor Hall) to learn more about the latest in online rights, get on our action alert list, or donate to become an EFF member. We'll also have our limited-edition DEF CON 34 shirts available starting Monday at BSidesLV! These shirts have a puzzle incorporated into the design. Snag one online for yourself starting on Tuesday, August 4 if you're not in Vegas!
Support Security & Digital Innovation
The OpenAI Hack Shows the Genie Is Out of the Bottle
This essay originally appeared in Foreign Policy.
Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it was running the ExploitGym benchmark, which measures how good a model is at turning security vulnerabilities into working exploits: basically, offensive cyberattacks.
Since these were internal tests, OpenAI locked those models in a secure sandbox that denied them access to the internet. But it was running the models without any safety filters that would prevent them from offensive cyber-actions. That meant that there was nothing to prevent the models from trying to ...
How a conspiracy-fueled campaign could turn Republicans against weather modification
Houthi threat to Saudi energy hub could upend Trump’s midterm message
Xavier Becerra is wary of California’s climate goals. Trump could save them.
France’s forest management may need to change to prevent more fires
Summers are putting Dutch dikes at risk, threatening German river trade
A blanket of seaweed smothers coastlines from the Caribbean to Mexico
Turning molecules into reliable electronic devices
Molecules are among the smallest building blocks available for making next-generation devices. Their unique, customizable properties enable promising applications in emerging computing, sensing, optical, and quantum technologies.
But integrating molecules into functional devices at scale remains a challenge. Traditional semiconductor manufacturing processes can damage small and fragile molecular materials. Now, MIT researchers have developed a scalable fabrication technique that incorporates delicate molecular materials into electronic devices on a chip without causing damage.
Their method extends the capabilities of standard semiconductor manufacturing processes to accommodate molecules. The researchers first prefabricate the device components using traditional processes. Then, they introduce the molecules and harness nanoscale surface forces to mechanically transform the fabricated device, which self-assembles without damaging the molecules.
The team demonstrated the robustness and scalability of their technique by fabricating more than 1,000 devices using sub-nanometer molecular layers.
“Our platform combines the scalability of conventional semiconductor manufacturing with the precision and control of self-assembly. This establishes a new fabrication framework for the scalable, high-throughput integration of emerging nanoscale and quantum materials, including molecules, into functional devices with architectures and capabilities that were previously infeasible,” says Farnaz Niroui, an associate professor of electrical engineering and computer science (EECS), a member of the Research Laboratory of Electronics (RLE), and senior author of a new paper describing the work.
She is joined on the paper by co-lead authors Sarah Spector and Peter Satterthwaite, EECS graduate students; Jeremiah A. Johnson, the A. Thomas Guertin Professor of Chemistry at MIT; and others at MIT. The research appears today in Nature Nanotechnology.
Building with molecules
Molecules are small clusters of atoms with structures and chemistries that can be precisely designed. This allows their properties to be engineered across a wide design space.
Once integrated into device architectures, these molecules could enable next-generation electronics and computing platforms that are smaller, faster, and more adaptable, as well as higher-performance photonic devices and emerging quantum technologies.
To build a functional system, molecular building blocks need to be integrated with other device layers. In electronic systems, a critical step is making electrical contacts to the molecules by interfacing them with metallic surfaces. However, the harsh chemicals and processes needed for traditional chip manufacturing damages these fragile molecular materials, reducing reliability and performance.
To leverage the scalability of standard fabrication techniques while achieving the precision needed for handling molecules, the MIT researchers developed a decoupled, two-step approach.
They first fabricate all the device components using standard semiconductor manufacturing, then incorporate the molecular material after-the-fact to finish building the device.
“By bringing the delicate materials into the process only after we have fabricated the main device elements, it allows us to use conventional processes that are normally not compatible with these nanomaterials,” Satterthwaite says.
In their demonstration, the researchers fabricated a scaffold with two metal electrodes separated by a precisely sized gap. Then, they deposited the molecular layer on the electrode surfaces.
Finally, the researchers leverage nanoscale forces to gently pull the top electrode onto the molecules, forming the final device in a nondestructive way. This creates a self-aligned, damage-free electrical contact to the molecules.
Using the forces
While gravity is a dominant physical force that holds our world together, different forces dominate at the nanoscale. One, called the capillary force, causes liquid to get sucked into small spaces. (Plants rely on capillary forces to draw water into their stems.)
By carefully engineering the stiffness of the electrodes, when the solution containing the molecules evaporates, capillary forces gently pull the two metal surfaces together with the molecules sandwiched in between.
Once the two electrodes are in place, the researchers must hold them in a stable state. To do so, they rely on another nanoscale force known as the van der Waals force.
Van der Waals forces cause surfaces to attract one another. By controlling the device surface area and molecules properties, the researchers ensure these forces will be strong enough to hold the electrodes in a stable structure without damaging the molecules.
“Nanoscale forces play a critical role in our approach. Instead of fabricating exactly the structures we ultimately want, we make something mechanically mobile and use forces to transform it into an architecture that would otherwise be impossible to fabricate,” Spector explains.
They used this technique to fabricate more than 1,000 devices with molecular layers less than 1 nanometer thick. Even at this tiny scale, the fabricated chips comprised a high yield of working devices, 96 percent on average. The robust devices also endured tens of thousands of electrical cycles without showing any sign of degradation.
“The stability really stands out. This is a critical feature for moving molecular devices toward practical applications, but it has been a persistent challenge in the field,” Satterthwaite says.
Importantly, this versatile technique allows circuit- and system-level integration of molecular devices, pushing the field beyond the study of isolated devices, the researchers say. They demonstrated this by building an interconnected array of molecular memory devices which could have applications in next-generation computing platforms.
Their technique can also be extended to other materials and device architectures.
In the future, the researchers want to build on this platform to investigate and develop new classes of multifunctional computing and sensing devices and systems.
“By enabling the pristine integration of emerging molecular materials and other atomic-scale matter into functional devices at scale, our platform accelerates discovery and design of these materials with tailored functionalities and their deployment in emerging technologies,” Niroui adds.
This research was funded, in part, by the U.S. Defense Advanced Research Projects Agency (DARPA), the Semiconductor Research Corporation, the U.S. National Science Foundation (NSF), the MathWorks Fellowship, and the Netherlands Organization for Scientific Research. Device fabrication was carried out, in part, using MIT.nano facilities.
Using reason, again and again
You probably think you are rational. Day to day, you try to “make the best possible use of the information available to you,” as MIT philosopher Brian Hedden PhD ’12 writes in his 2015 book, “Reasons without Persons.”
If you think you are rational because of how you plan for the future, and change your beliefs over time, however, Hedden will be skeptical. Circumstances change, and when using reason, he thinks, all that matters is the present. Thus, he also writes: “The requirements of rationality should be impersonal, avoiding reference to the relation of personal identity over time.”
This is what Hedden calls “time-slice rationality,” the idea that in applying reason, we exist in little slivers of time and knowledge. There are not permanently reasonable people, just reasonable decisions.
“We are temporally extended people with hopefully long lifespans, but we’re made up of lots of different time slices,” Hedden says. “So there’s me now, me yesterday, me next year. We should think of the locus of rationality as the time slice, not the temporally extended person.”
Those past versions of you, Hedden thinks, are like teammates in sports: You are connected to them, but not quite the same person. The payoff from viewing things this way, he contends, is a more streamlined and realistic picture of our thinking.
“Time-slice rationality” helped launch Hedden’s career. Today he is a professor in MIT’s Department of Linguistics and Philosophy and associate dean for MIT’s Social and Ethical Responsibilities of Computing (SERC) initiative. In a nod to his work, let’s examine some time slices from Hedden’s career.
Falling for philosophy
Hedden grew up in Virginia and attended Princeton University as an undergraduate, where he expected to study electrical engineering. But early on in college, he took some philosophy classes — an introductory course in logic, a history of early modern philosophy — and liked them. A lot.
“Engineering is still near and dear to my heart, but I really got into philosophy,” Hedden says.
Almost before he knew it, Hedden had found his primary intellectual interest. Upon graduating from Princeton, Hedden spent a year working for an education nonprofit in Nicaragua, but he had already decided on his next stop: graduate school in philosophy.
That led Hedden to MIT. He wanted to study the philosophy of language, and at MIT, the famous linguistics program is part of the same department as philosophy. Hedden applied to the Institute, was accepted, and arrived on campus eager to pursue his chosen field.
Lounge life
A funny thing happened to Hedden after he arrived at MIT, however: He stopped studying the philosophy of language. Blame Frank Gehry, the architect.
MIT’s Department of Linguistics and Philosophy is in the Stata Center, which opened in 2004 and was designed by Gehry to have all kinds of common spaces, including double-height lounges. After Hedden started graduate school at MIT, he got drawn into the philosophical discussions happening in these common areas. Before long, he had changed his intellectual focus.
“This was largely due to conversations that were happening in the lounge,” Hedden recalls. “The Stata Center has spaces that really encourage collaboration. A lot of people there were talking about puzzles involving probability, epistemology, and decision theory, and I found those things really stimulating, and wound up specializing in those areas. Things wouldn’t be the same if the building were differently arranged.”
Advised by MIT professors Caspar Hare, Robert Stalnaker, and Roger White, Hedden wound up writing his doctoral thesis — three papers — on rationality and decision-making. That formed the basis of “Reasons without Persons,” whose title alludes to a famous work by philosopher Derek Parfit.
While it might seem unusual to draw to draw a distinction between our past, present, and future selves, Hedden thinks we actually do that frequently, in everyday life and cultural work. In Greek mythology, Odysseus rationally chains himself to the mast of his ship, anticipating that his future self will be irrationally unable to resist the call of the sirens.
“That’s a dramatic example, but we do this all the time, like when we buy a gym membership and hope that our future selves will irrationally care about sunk costs and go to the gym to avoid having wasted the money,” Hedden says.
Heading down under
After earning his MIT PhD, Hedden spent two years as a junior research fellow at Oxford University, then landed his first faculty job in academia — at the University of Sydney, in Australia, in 2015. Five years later, he moved to Australian National University, in Canberra, leaving when he returned to MIT in 2025.
“I love Australia; I think the quality of life is amazing, the culture is great, the natural world is unbelievable,” Hedden says. The country also has, he observes, “a great philosophy scene,” fed in part by decades of interaction with American scholars.
Hedden’s work kept evolving during his decade in Australia. He started examining specific, applied topics more often, including many questions about legal processes and evidence. For instance: Should juries even deliberate? In one 2017 paper, Hedden suggested they should not, because, among other things, “deliberation destroys the independence of jurors’ judgments” in ways that can be counterproductive.
Or: Is there such a thing as “higher-order” evidence, which is evidence about what conclusions your evidence supports? In a 2021 paper, Hedden and now-MIT colleague Kevin Dorst concluded that virtually all evidence fits this billing.
Hindsight bias: Not bias
Or take another Hedden paper in this vein, from 2019, casting new light on the familiar topic of “hindsight bias.” We often alter our views about things after they happen, which can seem like gratuitous second-guessing.
Is it, though? Suppose you are investigating a railroad crash and find evidence that a crash was more likely than people imagined. That might simply be useful new knowledge. Suppose your favorite basketball team loses a game, and you reexamine why you thought they would win; perhaps a star player’s injury was more serious than you imagined. Are you changing your basic views, or just conducting a realistic reassessment?
“This is perfectly rational and what we should expect,” Hedden says. “Some people say, ‘Oh, that’s hindsight bias.’ I think it’s just a reasonable conclusion to draw.”
To be sure, in the paper itself, Hedden engages with theoretical philosophical work about evidence and view formation; much of his work bridges academic theory and practical everyday applications. Like many of his papers, this one also evinces the fun of reworking conventional wisdom.
“I do think that these contrarian views are right,” Hedden says. “But I also find a certain joy in going my own way, or having a skeptical take to get people to rethink views they’re falling into without fully realizing it.”
After an odyssey, back at MIT
After nearly a decade in Australia, Hedden received an offer to return to one of his intellectual homes: MIT offered him a place on the faculty. Arriving back at the Institute in 2025, Hedden found many things had changed — new buildings on campus, new programs — while some were recognizably the same.
“The philosophy department looks very similar in terms of the healthy culture,” Hedden says. “It’s always been known as a collaborative, high-energy place with a fantastic graduate program. And it’s really welcoming. That lounge discussion culture is still there. Sometimes cultures can be fragile. There could have been people who let it lapse. But it’s still there, and that’s great.”
Meanwhile, Hedden has added to his intellectual portfolio by becoming associate dean at SERC, a burgeoning initiative at MIT examining a wide range of civic issues around computing. SERC has supported 40 postdocs around MIT since 2022, in all five MIT schools plus the MIT Schwarzman College of Computing. It has also awarded 30 seed grants for faculty research in the last three years.
“There’s been really broad interest from faculty and students,” Hedden says. “I’m interacting a lot with computer scientists especially, but people across the Institute everywhere. The College of Computing is a unifying force.”
For that matter, the SERC Scholars program had 75 students accepted last fall, from first-year undergraduates to doctoral candidates, working on projects including surveillance, artificial intelligence, the energy impact of the sector, and more. Hedden is also making a point to develop more courses across SERC topics.
“It’s often the younger people, undergraduates and graduate students, the postdocs, the junior faculty, that gives us a constant infusion of new ideas and energy,” Hedden says. “We’re hoping to keep the momentum going.”
In this slice of time, that sounds pretty reasonable.
Friday Squid Blogging: Squid Helps Discover New Marine Species
The Squid is a new scientific machine:
One of the technological breakthroughs was the onboard use of a spinning wheel confocal microscope, nicknamed the Squid, which uses lasers to scan microscopic details of how organisms are put together. “That opens up a whole new world of exploring. We could see cells interacting with each other, exchanging material and building skeletons. And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.
The expedition discovered thirty-one new marine species in two weeks. The article doesn’t say if any of them were new species of squid...
Amending AB 1709 Doesn’t Fix It: California’s Social Media Ban Still Threatens Free Speech and Privacy
California lawmakers have amended A.B. 1709, but the core problem remains: the bill is still a ban on social media access for youth under 16, and it still threatens the privacy and First Amendment rights of all Californians.
Proponents of the bill may argue that the recent amendments represent a compromise, but a close look at the text shows no major changes. As the bill moves forward in the Senate, we must continue to urge lawmakers to vote NO.
Take Action: Tell Your Senator to OPPOSE A.B. 1709
A "Compromise" That Still Denies AccessUnder the newly amended Section 22683, platforms are prohibited from offering "addictive features" to users under 16. A platform can allow a minor to keep an account only if it strips away these features, which include what the bill calls "addictive feeds," auto-play, and anything else the Attorney General designates in future rulemaking.
However, the bill defines "addictive feeds" so broadly that it covers virtually every functional recommendation algorithm. The bill applies this label to any presentation of user-generated content recommended "in whole or in part, on information provided by the user." That includes basic inputs like who a user follows, what posts they like, or their self-expressed interests. By calling these basic tools and features “addictive," the bill also makes broad conclusions about the unsettled science behind social media use, youth, and addiction.
Because almost every major social media service uses automated feeds to deliver content, the end result of AB 1709 remains the same: young people under 16 will be denied access to major social media services as they currently exist.
Even if a platform attempts to comply by stripping away recommendation systems for minors, this still violates the First Amendment. Recommendation systems are the primary tools that users rely on to find speech and disseminate their own. Forcing young people onto a stripped-down, dysfunctional version of social media burdens their constitutional right to access information and participate in public discourse.
AB 1709 Still Forces Invasive Age VerificationThe amendments do not eliminate the privacy threats posed by age gating. Although the bill references the age-signaling framework in AB 1043, Section 22684 explicitly states that a covered platform "shall verify the age of a user” and makes platforms liable every time a person under 16 makes it through an age check.
Because AB 1043 does not actually specify how verification should occur without requiring additional proof, AB 1709 will, in practice, force platforms to implement the strictest forms of age verification. To comply, platforms will likely require users to upload government-issued IDs or submit to biometric scanning. Forcing users to turn over their personal information will create massive honeypots of sensitive personal data, destroying online anonymity and exposing users of all ages to security breaches. And relying on biometric systems to verify users’ ages is problematic because the systems have historically had high error rates estimating ages across race and gender lines.
Take Action: Tell Your Senator to OPPOSE A.B. 1709
Lawmakers Must Reject AB 1709The amendments to AB 1709 also introduce legal confusion, creating provisions that conflict with already enacted legislation like SB 976. Rather than providing clarity or protecting young people, AB 1709 creates a tangled regulatory scheme that sacrifices constitutional rights for political grandstanding.
Denying minors access to digital forums—or stripping those forums of the basic tools needed to navigate them—is censorship. California should not set a national precedent of cutting young people off from digital lifelines, communities, and speech.
We need to keep the pressure on as AB 1709 moves through the Senate. Contact your state senator today and tell them that minor tweaks to a bad bill do not make it good policy.
The SCREEN Act Threatens Privacy Far Beyond Adult Websites
The Senate Commerce Committee is set to consider S. 737, the SCREEN Act, a sweeping age-verification bill that would require online services to verify users’ ages before they can access any sexually explicit content. If this bill passes, it will force millions of adult internet users to give up their anonymity, privacy, and security before they access lawful speech.
Unlike many state-age verification laws—which have been harmful in their own right—the SCREEN Act has no requirement that a significant portion of the website consist of sexually explicit content that is harmful to minors. The bill requires nearly any service hosting even a single piece of sexually explicit content to verify the ages of its users. The result is that the bill would apply not only to adult content sites like PornHub or OnlyFans, but also streaming services like Netflix, and social media platforms like Reddit, Discord, or Bluesky, if they host any adult content.
The SCREEN Act does not merely require users to attest they are adults. It specifically states that “requiring a user to confirm that the user is not a minor shall not be sufficient.” In practice, that means platforms would have to verify users’ ages using methods tied to their real identities. Providing proof of age online is dramatically different, and far more invasive, than showing your ID at the door to a bartender or bouncer. In the physical world, the bouncer at the door looks at your ID card, confirms you’re old enough, and gives it back to you. Under the SCREEN Act, the “bouncer” will be a digital age-verification service that captures your personal information and saves it to a database for an unspecified amount of time.
The consequences of the bill won’t be limited to minors. If websites and apps are expected to reliably identify teenagers, adults will be asked to prove they are adults.
Even worse, the SCREEN Act is a privacy and data security nightmare. One provision of the bill requires services to take reasonable steps to protect the data collected and to not maintain for longer than is necessary. But these are terribly weak protections that impose no meaningful collection, use, or retention limits on services collecting people’s private information.
In other words, the third parties tasked with verifying a user’s age on a platform could sweep up a lot of personal info they don’t actually need and then could use that information for any number of purposes, so long as they deem their actions reasonable. Companies would then be allowed to keep the information users have been compelled to turn over for as long as possible, raising security and privacy issues along the way.
The SCREEN Act Attacks Your Right To Use VPNsThe SCREEN Act also targets virtual private network (VPN) users and providers. The bill requires covered websites to verify users' ages based on their IP addresses unless the service can determine that the user is outside the United States, and specifically requires age verification on traffic coming from known VPN addresses. In practice, this discourages the use of VPNs and proxy servers, which millions of people rely on for legitimate purposes such as protecting personal privacy, securing public Wi-Fi connections, safeguarding journalists and activists, and preventing data tracking.
VPNs mask your real location by routing your internet traffic through a server somewhere else. When you visit a website through a VPN, that website only sees the VPN server's IP address, not your actual location. It's like sending a letter through a P.O. box so the recipient doesn't know where you really live. VPNs are a privacy and security tool used by millions of internet users every day, and their use should not be treated as suspect. It is particularly galling that the SCREEN Act forces users who intentionally take steps to protect their privacy to identify themselves.
The SCREEN Act creates onerous age-verification rules that will block adults from accessing lawful speech, curtail their ability to be anonymous, and jeopardize the data security and privacy of all internet users.
The CHATBOT Act Forces One Parenting Model On Every Family
Artificial intelligence is rapidly changing education, and the way people search for information. Parents, teenagers, teachers, and schools are struggling with tough questions about when AI should, and should not, be used. It makes sense for Congress to hold hearings and examine how AI should be used by minors. But the recently introduced CHATBOT Act answers those questions with a one-size-fits-all mandate governing how teenagers access AI through federally prescribed parental monitoring systems.
The Bill Requires AI Companies To Build Family Monitoring SystemsParents are approaching AI in different ways. Some closely supervise how their children use chatbots, while others might set more general rules about technology. Many families are still figuring out what role AI should play in schoolwork and everyday life.
The CHATBOT Act would take that decision away from families and AI providers. Instead of letting families and AI providers decide what parental controls should look like, Congress would require every covered AI chatbot to build the same federally prescribed “family account” system.
As part of the required parental-consent process for teens, AI companies must offer parents a "family account" that provides access to a "full record of the conversations and activity" of teen users and tools to "monitor, analyze, and understand, at scale" those conversations. They must also send alerts if a teen attempts to bypass or disable parental controls.
This isn’t simply an optional parental-control feature. The bill requires every covered AI provider to build this monitoring infrastructure, and present it as part of the parental consent process. Congress is prescribing a single, highly invasive model of how families should supervise teenagers’ use of AI.
The CHATBOT Act Creates New Privacy Risks For FamiliesParents and families have different ideas about how much independence teenagers should have. Understandably, they also have very different expectations for 8-year olds, 13-year-olds, and 17-year-olds. The CHATBOT Act effectively requires AI providers to build the same monitoring architecture for users of very different ages.
And this mandated data collection will create new privacy and security risks. Once Congress requires AI companies to create a permanent, centralized record of teen AI conversations for parental review, that will be a valuable vault of extremely personal information. That raises serious questions about what would happen in cases where someone else gains access to it through account compromise, family disputes, or other security failures.
The vast archives of conversations created by the government-mandated family accounts won't be interesting only to parents. They will become valuable targets for hackers, identity thieves, civil litigants, and anyone else seeking access to the deeply personal information of others. The CHATBOT Act requires the records to exist, but addresses none of those risks.
Families are still figuring out what role AI should play in schoolwork and everyday life. Congress shouldn’t freeze one answer into federal law by requiring every AI company to build the same prescribed monitoring system.
The CHATBOT Act Applies A Children’s Law To TeenagersThe CHATBOT Act takes the basic structure of COPPA, a nearly 30-year-old law that applies to children aged 12 and under, and applies the same “verifiable parental consent” to older teenagers.
That’s a dramatic expansion of the law. Congress enacted COPPA to prevent kids from handing over detailed personal information to online services without making sure parents approved. For nearly three decades, Congress has required parental consent before websites collect personal information from any user under 13. COPPA is not simple to comply with, which is why so many internet companies, large and small, simply bar kids under 13 from having accounts. That includes major social media sites and AI. Facebook, Instagram, TikTok, X, YouTube, Snapchat, Discord, Spotify, and blogging platforms like WordPress all keep out users under 13. Children under 13 are also not allowed to use Microsoft Co-Pilot, Google Gemini, or ChatGPT. Anthropic does not allow users under 18 to use its AI model, Claude. In cases where younger kids maintain social media accounts despite the rules, studies show the vast majority of them are creating those accounts with parental consent.
In short, COPPA’s protections against collecting personal information from minors without parental consent already apply to the AI services CHATBOT Act seeks to regulate. Worse, the CHATBOT Act takes COPPA’s privacy protections and inverts them—it will result in AI services likely collecting more information about young users.
But the CHATBOT Act extends that model to high school students using AI assistants that are rapidly becoming tools for learning, research, writing, coding, and creative work. It then mandates specific, invasive surveillance tools that go well beyond anything COPPA requires.
The bill requires providers to offer these “family accounts,” with these specific features, as a default for teenagers. By doing so, CHATBOT effectively treats a high school senior the same way it treats an elementary school student.
Supporters may argue that parents of teens don’t have to create a family account. But every family with a teenager will still have to go through the bill’s parental-consent process before a teenager can use a covered AI system. Providers will need practical ways to verify that an adult is, in fact, the teenager’s parent. And parents of kids under 13 have no option to consent to their kids’ use of an AI system—the bill’s only option is to create a family account.
Congress should not extend the COPPA parental-permission model to millions of older teenagers, and it would be harmful to do so. The government does not require COPPA-style parental permission before a 17-year-old checks out a library book, uses Wikipedia, types search terms into Google, or reads a newspaper online. It shouldn’t require parental permission simply because the same question gets asked of an AI assistant.
The CHATBOT Act Will Pressure AI Companies To Check Users’ AgesThe bill says it doesn’t require age verification. But like many recent “kids online safety” bills, it imposes obligations that depend on a company knowing whether a user is under 18.
Specifically, the bill requires AI systems to either disable access to young kids, get parental consent, or the creation of a family account if a service has reason to believe a user is a minor. The standard means that services don’t need to have actual knowledge of a user’s age to be later held liable for improperly letting them use their AI tools. That creates a practical problem. Given the potential liability of getting something wrong, AI companies will likely require stricter forms of age verification to figure out who is under 13, a teenager, and who is a parent. Some providers might ask for government-issued identification. Other companies may rely on age estimation systems that use facial scans or other signals to guess a user’s age. Neither of these approaches is good for users’ privacy or security. One collects more information than is necessary, and the other inevitably makes mistakes.
Congress shouldn’t force companies into that choice, or families into this position. In the name of protecting children, the CHATBOT Act will result in online services collecting even more information from kids and families, creating privacy and security risks. Parents who want family accounts like those described in the bill should be free to choose AI services that offer them. But Congress shouldn’t pressure every provider to collect more information about everyone’s age simply to comply with the law.
A Better Way ForwardCongress doesn't have to choose between doing nothing and creating a sweeping new federal parental-monitoring mandate. Existing law allows regulators to police deceptive AI products, protect children's privacy under COPPA, and hold companies accountable when they market unsafe or misleading products to families.
Lawmakers have urged the FTC to crack down on AI-enabled toys that make unsubstantiated educational claims or illegally collect children's data. Those are regulatory actions that can be taken right now.
Finally, the FTC is currently investigating how AI companies test their products, protect children and teens, comply with COPPA, and enforce age restrictions. The results of that inquiry could be useful guidance to Congress, and to the public debate around these issues.
Cracking down on bad actors, while learning more about how families are already making decisions about AI use, is a much better path forward than building one, federally-prescribed model of parenting or product design.
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
The chart is interesting.
On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts...
EFF Guide to Recording Law Enforcement
This post is available as a printable one page handout in English and Spanish.
Recordings of law enforcement, whether by bystanders or by those directly encountering officers, can be powerful tools of government accountability and can support movements for social change. But recording officers can come with risks. Below are important legal and practical considerations related to recording the police and other law enforcement officers.
Can I legally record the police or immigration officers?Yes. All Americans have a First Amendment right to record law enforcement. This includes local police and federal officers such as those from Immigration and Customs Enforcement (ICE) and Customs and Border Protection (CBP). Although the Supreme Court has not squarely ruled on the issue, nine different federal appellate courts have recognized and affirmed this right, relying on decades of Supreme Court precedent.
Courts typically frame the right to record law enforcement as the right to record officers exercising their official duties in public. This right extends to bystanders as well as people recording their own interactions with law enforcement, such as livestreaming their own traffic stops. The right also applies to private places where the recorder has a legal right to be, such as in their own home.
You may take photos, or record video and audio. Courts have held that wiretap laws, which generally protect private conversations, do not prohibit civilians from audio recording law enforcement. That’s because officers exercising their official duties, particularly in public, do not have a reasonable expectation of privacy. Neither do civilians in public places who speak to law enforcement in a manner audible to passersby.
What are some limitations on the right to record law enforcement?Courts have been clear that behavior that obstructs or interferes with effective law enforcement or the protection of public safety is not protected. Officers can't order you to move because you are recording, but they may order you to move for public safety reasons even if you are recording.
If the law enforcement officer is off-duty or is in a private space that you don’t also have a right to be in, your right to record the officer may be limited. For example, a Los Angeles jury in 2026 found two women guilty of felony stalking after they followed an ICE agent to his home and livestreamed the pursuit.
What are some other considerations when recording officers?Even if you believe you are appropriately exercising your First Amendment right to record law enforcement, officers may nevertheless escalate the situation and/or retaliate against you. Below are some things to keep in mind.
- Stay calm and courteous.
- If you are a bystander, stand at a safe distance from the scene that you are recording. But note that officers may approach and confront you, closing that distance in an effort to accuse you of interfering with and possibly also assaulting a federal officer.
- Be alert and mindful of the possibility that officers may illegally retaliate against you in a number of ways, including arrest, destruction of your device, and bodily harm. They may also try to retaliate by harming the person being arrested.
- Consider the sensitive nature of recording in the context of an arrest. For example, the person being arrested or their loved ones may be concerned about exposing their immigration status, so think about obtaining consent or blurring out faces in any version you publish to focus on ICE/CBP conduct (while still retaining the original video).
- Law enforcement may not search your cell phone or other device without a warrant based on probable cause from a judge, even if you are under arrest. Thus, you may refuse a request from an officer to review or delete what you recorded. You also may refuse to unlock your phone or provide your passcode.
How well protected your photos or video footage are depends on both the device and the way you’re recording. If you’re uploading video to a livestreaming service, it can save that video to the cloud if you enable that setting. But what if you want to protect your recordings stored locally?
Modern smartphones generally protect data, including videos, using encryption. This means if your phone is locked and protected by a strong passphrase, it is more difficult for an officer to delete what you’ve stored on the device. Removing biometrics such as face and fingerprint unlock can protect your device contents further. You can check your settings by following the steps in our Surveillance Self-Defense guides (see below) to ensure device encryption is turned on.
Want more information?- Read more about your right to record law enforcement: https://www.eff.org/issues/right-record
- Read EFF’s Surveillance Self-Defense technical guide: https://ssd.eff.org
Facial Recognition at Madison Square Garden
Last month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition.
Turns out that the system was shut off for Taylor Swift’s wedding.
Evan Greer—one of the people that MSG alerts on—comments:
Ironically, Swift herself has reportedly used facial recognition at her own concerts to identify stalkers. This “privacy for me, surveillance for thee” attitude feels like a perfect encapsulation of the future we’re already living in: one where wealthy elites can afford privacy, while the rest of us are forced to live in a corporate surveillance panopticon...
