It’s no secret that Donald Trump has been waging an Orwellian war on knowledge and information for most of his second term thus far. While purging history of American racism, slavery, and anything else that makes us look less than perfect has been the primary focus in this war, so too has Trump attempted to simply disappear data and information around climate change from the public view. This attempt to make us all more ignorant about the harms and potential negative outcomes from climate change is, of course, completely insane and self-destructive. But if you’re an octogenarian suffering from a textbook case of narcissistic personality disorder, what happens years after you’re going to be worm-food probably doesn’t concern you all that much.
Most recently, the Trump administration shut down climate.gov, a website that contained a wealth of information and research generated by government researchers and third-party scientists that worked at the request of government. Decades and decades of content and data, wiped away with the wave of a bruised hand by Trump.
Over decades, researchers in the US government and programs it sponsored built up a tremendous number of climate resources, from comprehensive analyses to massive datasets to basic explainers meant to inform the public. And people within the government built the climate.gov website to make it all accessible. But if you try to navigate there today, you get redirected to the climate page of the National Oceanic and Atmospheric Administration, and are greeted with the following message:
In compliance with Executive Order 14303 (“Restoring Gold Standard Science”), the White House Office of Science and Technology Policy’s June 23, 2025 Memorandum (“Agency Guidance for Implementing Gold Standard Science in the Conduct & Management of Scientific Activities”), 15 USC § 2904 (“National Climate Program”), 15 USC § 2934 (“National Global Change Research Plan”), and 33 USC § 893a (“NOAA Ocean and Atmospheric Science Education Programs”), you have been redirected to NOAA.gov. Future research products previously housed under Climate.gov will be available at NOAA.gov/climate and its affiliate websites.
This is, of course, nonsense. Or, to borrow a phrase, a litany of inconvenient truths that gave Trump indigestion and therefore had to be done away with. This was a repository of knowledge. It was a public good, making information on climate science available to anyone who sought it out. It didn’t cost a bunch of money. It contained work done by real scientists doing real science.
And, poof, it was gone.
Except many of the people who worked to build and maintain the site seem to have anticipated that this might happen. I don’t know how else to explain how they managed to not only maintain the full library of the site, but also spun up their own non-profit organization to host and maintain a nearly identical site on their own. And because this is material the government can’t copyright, it appears there is fuck-all the Trump administration can do about it.
While the government didn’t hesitate to delete inconvenient climate information, dedicated volunteers outside the government managed to preserve copies of much of the material, which the federal government is prohibited from copyrighting. The volunteers and former climate.gov admins got together and launched climate.us. On Tuesday, the team announced that it had completed the project to restore everything lost when climate.gov shut down.
The website features Climate.gov’s 15-year collection of climate news and stories, expert blogs, visual status reports on key climate indicators, maps and data pathways, climate literacy resources, classroom materials, and restored access to the Fifth National Climate Assessment.
If our own government is going to attempt to make us more stupid by trying to hide information, this is all of our jobs now. It may be a shame that it is the work of citizens to restore what our government is attempting to steal from us, but it is also a necessity. This is how you fight back against an authoritarian. It takes work. It takes effort. And it takes some money.
But this knowledge isn’t Trump’s property to erase. It belongs to all of us.
Remember last summer when everyone was freaking out about the explosion of AI-generated child sexual abuse material? The New York Times ran a piece in July with the headline “A.I.-Generated Images of Child Sexual Abuse Are Flooding the Internet.” NCMEC put out a blog post calling the numbers an “alarming increase” and a “wake-up call.” The numbers were genuinely shocking: NCMEC reported receiving 485,000 AI-related CSAM reports in the first half of 2025, compared to just 67,000 for all of 2024.
That’s a big increase! And it would obviously be super concerning if any AI company were finding and detecting so much AI-generated CSAM, especially as we keep hearing that the big AI models (perhaps with the exception of Grok…) have been putting in place safeguards against CSAM generation.
The source of most of those reports? Amazon, which had submitted a staggering 380,000 of them, even though most people don’t tend to think of Amazon as much of an AI company. But, still, it became a six alarm fire about how much AI-generated CSAM Amazon had discovered. There were news stories about it, politicians demanding action, and the general sentiment was that this proved how big the problem was.
Except… it turns out that wasn’t actually what was happening. At all.
Bloomberg just published a deep dive into what was actually going on with Amazon’s reports, and the truth is very, very different from what everyone assumed. According to Bloomberg:
Amazon.com Inc. reported hundreds of thousands of pieces of content last year that it believed included child sexual abuse, whichit found in data gathered to improve its artificial intelligence models. Though Amazon removed the content before training its models, child safety officials said the company has not provided information about its source, potentially hindering law enforcement from finding perpetrators and protecting victims.
Here’s the kicker—and I cannot stress this enough—none of Amazon’s reports involved AI-generated CSAM.
None of its reports submitted to NCMEC were of AI-generated material, the spokesperson added. Instead, the content was flagged by an automatic detection tool that compared it against a database of known child abuse material involving real victims, a process called “hashing.” Approximately 99.97% of the reports resulted from scanning “non-proprietary training data,” the spokesperson said.
What Amazon was actually reporting was known CSAM—images of real victims that already existed in databases—that their scanning tools detected in datasets being considered for AI training. They found it using traditional hash-matching detection tools, flagged it, and removed it before using the data. Which is… actually what you’d want a company to do?
But because it was found in the context of AI development, and because NCMEC’s reporting form has exactly one checkbox that says “Generative AI” with no way to distinguish between “we found known CSAM in our training data pipeline” and “our AI model generated new CSAM,” Amazon checked the box.
And thus, a massive misunderstanding was born.
Again, let’s be clear and separate out a few things here: the fact that Amazon found CSAM (known or not) in its training data is bad. It is a troubling sign of how much CSAM is found in the various troves of data AI companies use for training. And maybe the focus should be on that. Also, the fact that they then reported it to NCMEC and removed it from their training data after discovering it with hash matching is… good. That’s how things are supposed to work.
But the fact that the media (with NCMEC’s help) turned this into “OMG AI generated CSAM is growing at a massive rate” is likely extremely misleading.
For half a year, “Massive Spike In AI-Generated CSAM” is the framing I’ve seen whenever news reports mention those H1 2025 numbers. Even thepress releasefor a Senate bill about safeguarding AI models from being tainted with CSAM stated, “According to the National Center for Missing & Exploited Children, AI-generated material has proliferated at an alarming rate in the past year,” citing the NYT article.
Now we find out from Bloomberg that zero of Amazon’s reports involved AI-generated material; all 380,000 were hash hits to known CSAM. And we have Fallon [McNulty, executive director of the CyberTipline] confirming to Bloomberg that “with the exception of Amazon, the AI-related reports [NCMEC] received last yearcame in ‘really, really small volumes.'”
That is an absolutely mindboggling misunderstanding for everyone — the general public, lawmakers, researchers like me, etc. — to labor under for so long. If Bloomberg hadn’t dug into Amazon’s numbers, it’s not clear to me when, if ever, that misimpression would have been corrected.
She’s not wrong. Nearly 80% of all “Generative AI” CyberTipline reports to NCMEC in the first half of 2025 involved no AI-generated CSAM at all. The actual volume of AI-generated CSAM being reported? Apparently “really, really small.”
Now, to be (slightly?) fair to the NYT, they did run a minor correction a day after their original story noting that the 485,000 reports “comprised both A.I.-generated material and A.I. attempts to create material, not A.I.-generated material alone.” But that correction still doesn’t capture what actually happened. It wasn’t “AI-generated material and attempts”—it was overwhelmingly “known CSAM detected during AI training data vetting.” Those are very different things.
And it gets worse. Bloomberg reports that Amazon’s scanning threshold was set so low that many of those reports may not have even been actual CSAM:
Amazon believes it over-reported these cases to NCMEC to avoid accidentally missing something. “We intentionally use an over-inclusive threshold for scanning, which yields a high percentage of false positives,” the spokesperson added.
So we’ve got reports that aren’t AI-generated CSAM, many of which may not even be CSAM at all. Very helpful.
The frustrating thing is that this kind of confusion wasn’t just entirely predictable—it was predicted! When Pfefferkorn and her colleagues at Stanford published their report about NCMEC’s CSAM reporting system they literally called out the potential confusion in the options of what to check and how platforms would likely over-report stuff in an abundance of caution, because the penalty (both criminally and in reputation) for missing anything is so dire.
Indeed, the form for submitting to the CyberTipline has one checkbox for “Generative AI” that, as Pfefferkorn notes in her letter, can mean wildly different things depending on who’s checking it:
When the meaning of checking a single checkbox is so ambiguous that absent additional information, reports of known CSAM found in AI training data are facially indistinguishable from reports of new AI-generated material (or of text-only prompts seeking CSAM, or of attempts to upload known CSAM as part of a prompt, etc.), and that ambiguity leads to a months-long massive public misunderstanding about the scale of the AI-CSAM problem, then it is clear thatthe CyberTipline reporting form itself needs to change— not just how one particular ESP fills it out.
To its credit NCMEC did respond quickly to Pfefferkorn, and their response is… illuminating. They confirmed they’re working on updating the reporting system, but also noted that Amazon’s reports contained almost no useful information:
all those Amazon reports included minimal data, not even the file in question or the hash value, much less other contextual information about where or how Amazon detected the matching file
As Pfefferkorn put it, Amazon was basically giving NCMEC reports that said “we found something” with nothing else attached. NCMEC says they only learned about the false positives issue last week and are “very frustrated” by it.
Indeed, NCMEC’s boss told Bloomberg:
“There’s nothing then that can be done with those reports,” she said. “Our team has been really clear with [Amazon] that those reports are inactionable.”
There’s plenty of blame to go around here. Amazon clearly should have been more transparent about what they were reporting and why. NCMEC’s reporting form is outdated and creates ambiguity that led to a massive public misunderstanding. And the media (NYT included) ran with alarming numbers without asking obvious questions like “why is Amazon suddenly reporting 25x more than last year and no other AI company is even close?”
But, even worse, policymakers spent six months operating under the assumption that AI-generated CSAM was exploding at an unprecedented rate. Legislation was proposed. Resources were allocated. Public statements were made. All based on numbers that fundamentally misrepresented what was actually happening.
As Pfefferkorn notes:
Nobody benefits from being so egregiously misinformed. It isn’t a basis for sound policymaking (or an accurate assessment of NCMEC’s resource needs) if the true volume of AI-generated CSAM being reported is a mere fraction of what Congress and other regulators believe it is. It isn’t good for Amazon if people mistakenly think the company’s AI products are uniquely prone to generating CSAM compared with other options on the market (such as OpenAI, with its distant-second 75,000 reports during the same time period,per NYT). That impression also disserves users trying to pick safe, responsible AI tools to use; in actuality, per today’s revelations about training data vetting, Amazon is indeed trying to safeguard its models against CSAM. I can certainly think of at least one other AI company that’s been in the news a lot lately that seems to be acting far more carelessly.
None of this means that AI-generated CSAM isn’t a real and serious problem. It absolutely is, and it needs to be addressed. But you can’t effectively address a problem if your data about the scope of that problem is fundamentally wrong. And you especially can’t do it when the “alarming spike” that everyone has been pointing to turns out to be something else entirely.
The silver lining here, as Pfefferkorn points out, is that the actual news is… kind of good? Amazon’s AI models aren’t CSAM-generating machines. The company was actually doing the responsible thing by vetting its training data. And the real volume of AI-generated CSAM reports is apparently much lower than we’ve been led to believe.
But that good news was buried for six months under a misleading narrative that nobody bothered to dig into until Bloomberg did. And that’s a failure of transparency, of reporting systems, and of the kind of basic journalistic skepticism that should have kicked in when one company was suddenly responsible for 78% of all reports in a category.
We’ll see if NCMEC’s promised updates to the reporting form actually address these issues. In the meantime, maybe we can all agree that the next time there’s a 700% increase in reports of anything, it’s worth asking a few questions before writing the “everything is on fire” headline.
When the U.S. government signs contracts with private technology companies, the fine print rarely reaches the public. Palantir Technologies, however, has attracted more and more attention over the past decade because of the size and scope of its contracts with the government.
Palantir’s two main platforms are Foundry and Gotham. Each does different things. Foundry is used by corporations in the private sector to help with global operations. Gotham is marketed as an “operating system for global decision making” and is primarily used by governments.
I am a researcher who studies the intersection of data governance, digital technologies and the U.S. federal government. I’m observing how the government is increasingly pulling together data from various sources, and the political and social consequences of combining those data sources. Palantir’s work with the federal government using the Gotham platform is amplifying this process.
Gotham is an investigative platform built for police, national security agencies, public health departments and other state clients. Its purpose is deceptively simple: take whatever data an agency already has, break it down into its smallest components and then connect the dots. Gotham is not simply a database. It takes fragmented data, scattered across various agencies and stored in different formats, and transforms it into a unified, searchable web.
The stakes are high with Palantir’s Gotham platform. The software enables law enforcement and government analysts to connect vast, disparate datasets, build intelligence profiles and search for individuals based on characteristics as granular as a tattoo or an immigration status. It transforms historically static records – think department of motor vehicles files, police reports and subpoenaed social media data like location history and private messages – into a fluid web of intelligence and surveillance.
These departments and agencies use Palantir’s platform to assemble detailed profiles of individuals, mapping their social networks, tracking their movements, identifying their physical characteristics and reviewing their criminal history. This can involve mapping a suspected gang member’s network using arrest logs and license plate reader data, or flagging individuals in a specific region with a particular immigration status.
The efficiency the platform enables is undeniable. For investigators, what once required weeks of cross-checking siloed systems can now be done in hours or less. But by scaling up the government’s investigative capacity, Gotham also alters the relationship between the state and the people it governs.
Shifting the balance of power
The political ramifications of Palantir’s rise come into focus when you consider its influence and reach across the government. U.S. Immigration and Customs Enforcement alone has spent more than US$200 million on Palantir contracts, relying on the software to run its Investigative Case Management system and to integrate travel histories, visa records, biometric data and social media data.
These integrations mean that Palantir is not just a vendor of software; it is becoming a partner in how the federal government organizes and acts on information. That creates a kind of dependency. The same private company helps define how investigations are conducted, how targets are prioritized, how algorithms work and how decisions are justified.
Because Gotham is proprietary, the public, and even elected officials, cannot see how its algorithms weigh certain data points or why they highlight certain connections. Yet, the conclusions it generates can have life-altering consequences: inclusion on a deportation list or identification as a security risk. The opacity makes democratic oversight difficult, and the system’s broad scope and wide deployment means that mistakes or biases can scale up rapidly to affect many people.
Beyond law enforcement
Supporters of Palantir’s work argue that it modernizes outdated government IT systems, bringing them closer to the kind of integrated analytics that are routine in the private sector. However, the political and social stakes are different in public governance. Centralized, attribute-based searching, whether by location, immigration status, tattoos or affiliations, creates the capacity for mass profiling.
In the wrong hands, or even in well-intentioned hands under shifting political conditions, this kind of system could normalize surveillance of entire communities. And the criteria that trigger scrutiny today could be expanded tomorrow.
Gotham’s capabilities may enable government agencies to carry out similar operations on a much larger scale and at a faster pace. And once some form of data integration infrastructure exists, its uses tend to expand, often into areas far from its original mandate.
A broader shift in governance
The deeper story here isn’t just that the government is collecting more data. It’s that the structure of governance is changing into a model where decision-making is increasingly influenced by what integrated data platforms reveal. In a pre-Gotham era, putting someone under suspicion of wrongdoing might have required specific evidence linked to an event or witness account. In a Gotham-enabled system, suspicion can stem from patterns in the data – patterns whose importance is defined by proprietary algorithms.
This level of data integration means that government officials can use potential future risks to justify present action. The predictive turn in governance aligns with a broader shift toward what some scholars call “preemptive security.” It is a logic that can erode traditional legal safeguards that require proof before punishment.
The stakes for democracy
The partnership between Palantir and the federal government raises fundamental questions about accountability in a data-driven state. Who decides how these tools are used? Who can challenge a decision that was made by software, especially if that software is proprietary?
Without clear rules and independent oversight, there is a risk that Palantir’s technology becomes normalized as a default mode of governance. They could be used not only to track suspected criminals or terrorists but also to manage migration flows, monitor and suppress protests, and enforce public health measures. The concern is not that these data integration capabilities exist, but that government agencies could use them in ways that undermine civil liberties without public consent.
Once put in use, such systems are hard to dismantle. They create new expectations for speed and efficiency in law enforcement, making it politically costly to revert to slower, more manual processes. That inertia can lock in not only the technology but also the expanded scope of surveillance it enables.
Choosing the future
As Palantir deepens its government partnerships, the issues its technology raises go beyond questions of cost or efficiency. There are civil liberties implications and the potential for abuse. Will strong legal safeguards and transparent oversight constrain these tools for integrated data analysis? The answer is likely to depend on political will as much as technical design.
Ultimately, Palantir’s Gotham is more than just software. It represents how modern governance might function: through data, connections, continuous monitoring and control. The decisions made about its use today are likely to shape the balance between security and freedom for decades to come.
The verdict is in on Jonathan Haidt’s “The Anxious Generation,” and it’s devastating. A new piece in TES Magazine systematically demolishes Haidt’s claims by doing something revolutionary: actually asking experts who study this stuff what they think.
The result reads like an academic execution:
“When I read the book,I found it really hard to believe it was written by a fellow academic,” admits Tamsin Ford, professor of child and adolescent psychiatry at the University of Cambridge.
“What Jon is selling is fear,” argues Andrew Przybylski, professor of human behaviour and technology at the University of Oxford. “It’s not scientific.”
And this isn’t some fringe criticism. TES is the Times Educational Supplement, which has been around since 1910 and is basically the trade magazine for educators in the UK. At a time when many educators have been swallowing Haidt’s misleading claims, seeing a respected educational trade magazine systematically shred his arguments is remarkable.
But here’s the truly damning part: this expert demolition came out the exact same day that Politico published a breathless piece claiming Haidt’s crusade represents “the only true bipartisan issue left,” gushing about how governors from both parties are embracing policy reform based on his work.
The contrast couldn’t be starker: while actual experts are calling Haidt’s work unscientific garbage, politicians are treating it like gospel.
The TES piece doesn’t just criticize—it comprehensibly destroys Haidt’s core arguments with the precision of actual scientists who know what they’re talking about.
First, his claim that there’s a mental health “epidemic” among teenagers caused by social media. Ford points out the fundamental problems with Haidt’s use of data:
Ford argues that using self-report data for prevalence estimates is tricky owing to a “lack of methodological soundness and ‘noisy’ data”.
“A teenager with high scores on a mental health questionnaire at a single time point will include a mixture of those who have not fully understood the question or are mucking around, those who are having a one-off bad day or adjusting to a life stress and those with persistent difficulties that impair their function. The last are those with mental health conditions,” she explains.
When you look at the actual robust data from the UK’s NHS Mental Health survey, the picture is quite different from Haidt’s “tidal wave” narrative:
In terms of the best UK prevalence data, she says theNHS Mental Health of Children and Young People (MHCYP) survey(which includes input from parents, teachers and clinical assessors) found prevalence of mental disorders in those between 5 and 15 years old increased between 1999 and 2004 by 0.4 percentage points and again between 2004 and 2017 by 1.1 percentage points (data for older teens has only been collected once, in 2017, so there is no data over time).
It’s an increase, but Ford says the data does not support Haidt’s description of a “tidal wave” of mental health challenges, nor a “surge of suffering”.
“He is going beyond the data,” she argues.
The experts also systematically debunk Haidt’s claims about causation. Candice Odgers, professor of psychology and informatics at University of California Irvine and a former Techdirt podcast guest, concludes:
“It is perfectly reasonable to take a safety-first approach to kids and social media,” she argues. “But when these decisions are made, it should not be because someone tells you science has discovered social media is the cause of serious mental disorders or will harm our children’s brains. That is the story that is being told, but not what the science says.”
Meanwhile, Przybylski (another former podcast guest) points out a basic logical flaw in Haidt’s argument:
“By the logic of his argument, the correlation between the use of technology and the outcome should be stronger,” he says. “As the algorithms have got more pernicious, more sophisticated, things should be getting progressively worse. [That hasn’t happened.] There is no sense of mechanism here.”
The article also details how experts are particularly concerned about missing the real causes of mental health issues. Ford notes:
Ford says he has missed some other obvious contributing factors in the UK data, including closures of youth clubs and other safe spaces for young people, the world becoming more expensive and difficult to navigate, social changes with looser community bonds and more.
“One of the strongest and most consistent associations for poor mental health is poverty, and we’ve got more children living in poverty, and then we have this huge drop in accessibility to services…[so] there is no early intervention,” she says. “To pin this on phones doesn’t just go way beyond the evidence – it is actually dangerous, as it does not address these other critical factors.”
The experts are also scathing about Haidt’s proposed solutions, which include banning phones in schools and raising age limits for social media. David Ellis has been a leading critic of the addiction narrative:
“We did a satirical paper a couple of years ago and we followed the mathematical formulas that people had used [in this research],” he says. “We managed to create a friendship addiction scale that demonstrated that 80 per cent of our sample were addicted to their friends, which of course is nonsense.”
Even Nora Volkow, director of the National Institute on Drug Abuse in the US and one of the world’s leading experts on dopamine and addiction, disputes Haidt’s claims:
“there’s not a clear-cut definition of what addiction to a phone would be, [so] it is difficult to estimate the prevalence,” she says, addingshe knows of no studies that would support Haidt’s 10 per cent addiction figure.
The piece also highlights how Haidt’s claims about educational decline don’t hold up to scrutiny. While he claims there’s been a global decline in learning since smartphones arrived, Christian Bokhove from the University of Southampton points out:
And although “average trajectories” in reading and science were downward, Christian Bokhove, professor in mathematics education at the University of Southampton, argues that beyond the general picture, “many countries were not declining” in that period in any of the three subjects.
Echoing many of the other academics when it comes to their criticisms of Haidt, he argues that even if the data did show a universal decline, “there can be numerous causes for this”.
This aligns perfectly with what I wrote in the Daily Beast piece last year, which was based on many experts as well:
Over the last decade, numerous studies on the impact of phones and social media on children, including a study of studies, conclude that social media is good for some kids, helping them find like-minded individuals. It’s mostly neutral for many kids, and problematic for only a very small group (studies suggest less than 10 percent).
I also highlighted how the country-by-country evidence doesn’t support Haidt’s claims either… unless you cherry-pick your countries, which anyone can do.
Looking at suicide rates (which are more indicative of actual depression rates, rather than self-reported data, given the decreasing stigma associated with admitting to dealing with mental health issues), the numbers show that in many countries it hasremained flat or decreasedover the past 20 years. Indeed, in countries like France, Ireland, Denmark, Spain, and New Zealand, you see a noticeable decline in youth suicide rates.
If social media were inherently causing an increase in depression, that would be an unlikely result.
But here’s where this gets truly maddening. While experts are thoroughly demolishing Haidt’s claims, politicians are doubling down. That same-day Politico piece reveals the scope of the damage:
39 states now have some sort of phone restrictions in schools, and 18 states and Washington, D.C. have bell-to-bell bans — which ban phones for the entire school day — according to Haidt. After the next legislative sessions, which in many state capitols begin after the new year, more states are sure to enact full bans. The issue has rallied conservatives and liberals, and its potency with parents has largely steamrolled libertarian objections and big tech lobbying.
I first realized a remarkable story was sitting in plain view when I witnessed two governors who are almost comically far apart on the political spectrum both embrace Haidt. Last year, Arkansas Gov. Sarah Huckabee Sanders sent a copy of Haidt’s book to every other governor. She then hosted Haidt in her home state before joining him earlier this year on stage at Davos, not typically a lovefest forum for Arkansas governors and New York academics.
Shortly after that, at the winter meeting at the National Governors Association, I got to talking to New Jersey Gov. Phil Murphy and one of his top aides, and they also were trumpeting Haidt’s work. A liberal, former Goldman Sachs executive turned northeastern governor, Murphy, 68, sounded a lot like his 43-year-old conservative counterpart from Little Rock.
Different regions, different politics and different generations.
But here’s the thing: bipartisan support doesn’t make something right. It just makes it bipartisanly wrong. As I noted in my original piece, every generation has its moral panic, and this appears to be ours.
The TES piece concludes with the most important point of all, from Pete Etchells, professor of psychology and science communication at Bath Spa University:
“It is becoming increasingly difficult to say, ‘hang on, that’s not what the evidence says’, or ‘we don’t have evidence for that yet’, and I really, really worry about this,” he concludes. “There’s a road here where [people say], ‘well, we don’t need science and evidence because we can see it with our own eyes’.”
And that’s exactly what’s happening. Politicians across the spectrum are implementing policies based on Haidt’s work despite an overwhelming expert consensus that his claims are scientifically unfounded. We’re watching evidence-based policy get steamrolled by moral panic in real time.
Incredibly, even with all these quotes, there’s way more in the TES piece, which should leave no doubt in anyone’s mind that the actual experts in the field find Haidt’s book a horrific attack on science and evidence-based policy making.
When professors of child and adolescent psychiatry are saying they can’t believe a fellow academic wrote this book, when experts in human behavior and technology are calling it “fear” rather than science, when leading researchers are pointing out basic logical flaws in the arguments—maybe, just maybe, we should listen to them instead of the guy selling books and giving TED talks.
The verdict from people who actually study this stuff is clear: Haidt’s claims don’t hold up to scrutiny. The fact that politicians find his message appealing doesn’t make it true. It just makes it politically convenient.
And that’s a much scarier prospect than kids having phones.
Just days after a jury found Tesla partially liable in a fatal Autopilot crash and ordered the company to pay over $200 million, Elon Musk took to Twitter with a bold proclamation: “Teslas can drive themselves!”
The timing couldn’t be worse. Because thanks to a devastating article by Electrek’s Fred Lambert that digs deep into the trial transcripts, we now know just how far Tesla went to hide the truth about what happened in that crash. The company systematically withheld evidence, misled police investigators, and actively obstructed efforts to understand how its technology failed—behavior that looks suspiciously like criminal obstruction of justice, yet somehow apparently carries no criminal consequences.
This isn’t just about one lawsuit. It’s about how Tesla’s behavior threatens to undermine public trust in autonomous vehicle technology at precisely the moment when that trust is most crucial.
Let’s be clear: self-driving technology has enormous potential to save lives. Human drivers cause roughly 94% of serious traffic crashes, according to a decade-old study by the National Highway Traffic Safety Administration. Even imperfect autonomous systems could dramatically reduce that toll, and we shouldn’t hold them to an impossible standard of perfection.
But here’s the problem: overselling what these systems can actually do—and then covering up when they fail—threatens to poison public acceptance of the technology entirely. If people lose trust because companies like Tesla made promises they couldn’t keep, we could end up rejecting technology that might otherwise save thousands of lives.
The aviation industry figured this out decades ago. When planes crash, investigators swarm the scene, companies cooperate fully with authorities, and the entire industry learns from failures. That transparency has made flying extraordinarily safe. But Tesla’s approach in this Autopilot case shows the exact opposite mentality.
The Electrek story, based on trial transcripts from the recent case, reveals a pattern of deception that’s genuinely shocking. Here’s what Tesla did:
Within three minutes of the fatal crash, the Model S automatically uploaded a complete “collision snapshot”—video, sensor data, everything—to Tesla’s servers, then deleted the local copy. Tesla was the only entity with access to the critical evidence.
Within about three minutes of the crash, the Model S uploaded a “collision snapshot”—video, CAN‑bus streams, EDR data, etc.—to Tesla’s servers, the “Mothership”, and received an acknowledgement. The vehicle then deleted its local copy, resulting in Tesla being the only entity having access.
When police investigators tried to get the data, Tesla’s lawyer literally scripted their evidence request. As the homicide investigator testified:
“He said it’s not necessary. ‘Write me a letter and I’ll tell you what to put in the letter.'”
But the lawyer deliberately crafted the letter to avoid sending the actual crash data, instead providing infotainment logs and owner’s manuals.
McCarthy specifically crafted the letter to ommit sharing the colllision snapshot, which includes bundled video, EDR, CAN bus, and Autopilot data.
Instead, Tesla provided the police with infotainment data with call logs, a copy of the Owner’s Manual, but not the actual crash telemetry from the Autopilot ECU.
Tesla never said that it already had this data for more than a month by now.
When police brought the car’s computer to a Tesla service center for help extracting data, Tesla technicians falsely claimed the data was “corrupted”—even though they had the complete dataset sitting on their servers the entire time.
For years, Tesla told courts and plaintiffs that the crucial collision data “didn’t exist.” Only when forensic experts finally gained access to the car’s computer and found metadata proving Tesla had the data all along did the company finally admit what it had done.
As Electrek reports:
The automaker had to admit to have the data all along.
During the trial, Mr. Schreiber, attorney for the plaintiffs, claimed that Tesla used the data for its own internal analysis of the crash:
“They not only had the snapshot — they used it in their own analysis. It shows Autopilot was engaged. It shows the acceleration and speed. It shows McGhee’s hands off the wheel.”
Yet, it didn’t give access to the police nor the family of the victim who have been trying to understand what happened to their daughter.
Just reading through the summary Electrek wrote about the timeline is horrifying and raises obvious questions about why there’s no criminal liability here:
Tesla had the data on its servers within minutes of the crash
When the police sought the data, Tesla redirected them toward other data
When the police sought Tesla’s help in extracting it from the computer, Tesla falsely claimed it was “corrupted”
Tesla invented an “auto-delete” feature that didn’t exist to try explain why it couldn’t originally find the data in the computer
When the plaintiffs asked for the data, Tesla said that it didn’t exist
Tesla only admitted to the existence of the data once presented with forensic evidence that it was created and transfered to its servers.
When the collision data finally came to light, it painted a damning picture. Electrek’s summary of the forensic analysis is quite something:
Autopilot was active
Autosteer was controlling the vehicle
No manual braking or steering override was detected from the driver
There wasno record of a “Take Over Immediately” alert, despite approaching a T-intersection with a stationary vehicle in its path.
Moore found logs showingTesla systems were capable of issuing such warnings, butdid notin this case.
Map and vision data from the ECU revealed:
Map data from the Autopilot ECU included a flag that the area was a“restricted Autosteer zone.”
Despite this, the systemallowed Autopilot to remain engagedat full speed.
That last point is crucial. Tesla knew this wasn’t an appropriate place for Autopilot to operate, but the system didn’t disengage or warn the driver. The NTSB had specifically warned Tesla to “incorporate system safeguards that limit the use of automated vehicle control systems to those conditions for which they were designed.”
Tesla appeared to ignore that recommendation.
The jury found that the driver in this case bears primary responsibility—he admitted to being distracted and not using Autopilot properly. The jury assigned him 67% of the blame. But they also found Tesla 33% responsible, and that matters.
As Electrek notes:
However, there’s also no doubt that Autopilot was active, didn’t prevent the crash despite Tesla claiming it is safer than humans, and Tesla was warned to use better geo-fencing and driver monitoring to prevent abuse of the system like that.
This case (unlike some other stories about autonomous vehicles) isn’t about punishing innovation or holding technology to impossible standards. It’s about holding companies accountable when they oversell their capabilities and then actively obstruct efforts to learn from failures.
Tesla’s behavior in this case—the years of lies, the misdirection of police, the withholding of critical evidence—represents everything wrong with how some tech companies approach safety and accountability. It’s the opposite of what we need to build public trust in autonomous vehicles.
Self-driving technology can eventually make our roads safer. But getting there requires companies that are transparent about their systems’ limitations, cooperative with safety investigations, and committed to continuous improvement based on real-world data.
Tesla’s cover-up in this case shows a company more interested in protecting its stock price (the biggest source of Elon’s wealth) than protecting lives. And Musk’s tweet claiming “Teslas can drive themselves” just days after this devastating evidence came to light shows he’s learned nothing.
If we want autonomous vehicles to fulfill their life-saving potential, we need companies that act more like airlines after a crash investigation (full transparency, immediate cooperation, system-wide improvements) and less like Tesla in this case (cover-ups, obstruction, and doubling down on dangerous claims).
The technology itself isn’t the problem. The corporate culture that prioritizes PR over safety is.
The Internal Revenue Service is building a computer program that would give deportation officers unprecedented access to confidential tax data.
ProPublica has obtained a blueprint of the system, which would create an “on demand” process allowing Immigration and Customs Enforcement to obtain the home addresses of people it’s seeking to deport.
Last month, in a previously undisclosed dispute, the acting general counsel at the IRS, Andrew De Mello, refused to turn over the addresses of 7.3 million taxpayers sought by ICE. In an email obtained by ProPublica, De Mello said he had identified multiple legal “deficiencies” in the agency’s request.
Two days later, on June 27, De Mello was forced out of his job, people familiar with the dispute said. The addresses have not yet been released to ICE. De Mello did not respond to requests for comment, and the administration did not address questions sent by ProPublica about his departure.
The Department of Government Efficiency began pushing the IRS to provide taxpayer data to immigration agents soon after President Donald Trump took office. The tax agency’s acting general counsel refused and was replaced by De Mello, who Trump administration officials viewed as more willing to carry out the president’s agenda. Soon after, the Department of Homeland Security, ICE’s parent agency, and the IRS negotiated a “memorandum of understanding” that included specific legal guardrails to safeguard taxpayers’ private information.
In his email, De Mello said ICE’s request for millions of records did not meet those requirements, which include having a written assurance that each taxpayer whose address is being sought was under active criminal investigation.
“There’s just no way ICE has 7 million real criminal investigations, that’s a fantasy,” said a former senior IRS official who had been advising the agency on this issue. The demands from the DHS were “unprecedented,” the official added, saying the agency was pressing the IRS to do what amounted to “a big data dump.”
In the past, when law enforcement sought IRS data to support its investigations, agencies would give the IRS the full legal name of the target, an address on file and an explanation of why the information was relevant to a criminal inquiry. Such requests rarely involved more than a dozen people at a time, former IRS officials said.
Danny Werfel, IRS commissioner during the Biden administration, said the privacy laws allowing federal investigators to obtain taxpayer data have never “been read to open the door to the sharing of thousands, tens of thousands, or hundreds of thousands of tax records for a broad-based enforcement initiative.”
A spokesperson for the White House said the planned use of IRS data was legal and a means of fulfilling Trump’s campaign pledge to carry out mass deportations of “illegal criminal aliens.”
Taxpayer data is among the most confidential in the federal government and is protected by strict privacy laws, which have historically limited its transfer to law enforcement and other government agencies. Unauthorized disclosure of taxpayer return information is a felony that can carry a penalty of up to five years in prison.
The system that the IRS is now creating would give ICE automated access to home addresses en masse, limiting the ability of IRS officials to consider the legality of transfers. IRS insiders who reviewed a copy of the blueprint said it could result in immigration agents raiding wrong or outdated addresses.
“If this program is implemented in its current form, it’s extremely likely that incorrect addresses will be given to DHS and individuals will be wrongly targeted,” said an IRS engineer who examined the blueprints and who, like other officials, spoke on condition of anonymity for fear of retribution.
The dispute that ended in De Mello’s ouster was the culmination of months of pressure on the IRS to turn over massive amounts of data in ways that would redefine the relationship between the agency and law enforcement and reduce taxpayers’ privacy, records and interviews show.
In one meeting in late March between senior IRS and DHS officials, a top ICE official made a suggestion: Why doesn’t Homeland Security simply provide the name and state of its targets and have the IRS return the addresses of everyone who matches that criteria?
The IRS lawyers were stunned. They feared they could face criminal liability if they handed over the addresses of individuals who were not under a criminal investigation. The conversation and news of deeper collaboration with ICE so disturbed career staff that it led to a series of departures in late March and early April across the IRS’ legal, IT and privacy offices.
They were “pushing the boundaries of the law,” one official said. “Everyone at IRS felt the same way.”
The Blueprint
The technical blueprint obtained by ProPublica shows that engineers at the agency are preparing to give DHS what it wants: a system that enables massive automated data sharing. The goal is to launch the new system before the end of July, two people familiar with the matter said.
The DHS effort to obtain IRS data comes as top immigration enforcement leaders face escalating White House pressure to deport some 3,000 people per day, according to reports.
One federal agent tasked with assisting ICE on deportations said recent operations have been hamstrung by outdated addresses. Better information could dramatically speed up arrests. “Some of the leads that they were giving us were old,” said the agent, who spoke on condition of anonymity because he was not authorized to speak with the press. “They’re like from two administrations ago.”
In early March, immigrants rights groups sued the IRS hoping to block the plan, arguing that the memorandum of understanding between DHS and the IRS is illegal. But a judge in early May ruled against them, saying the broader agreement complied with Section 6103, the existing law regulating IRS data sharing. That opened the door for engineers to begin building the system.
The judge did not address the technical blueprint, which didn’t exist at the time of the ruling. But the case is pending, which means the new system could still come under legal review.
Until now, little was known about the push and pull between the two agencies or the exact technical mechanics behind the arrangement.
The plan has been shrouded in secrecy even within the IRS, with details of its development withheld from regular communications. Several IRS engineers and lawyers have avoided working on the project out of concerns about personal legal risk.
Asked about the new system, a spokesperson for IRS parent agency the Treasury Department said the memorandum of understanding, often called an MOU, “has been litigated and determined to be a lawful application of Section 6103, which provides for information sharing by the IRS in precise circumstances associated with law enforcement requests.”
At a time when Trump is making threats to deport not only undocumented immigrants but also U.S. citizens, the scope of information-sharing with the IRS could continue to grow, according to documents reviewed by ProPublica and sources familiar with the matter: DHS has been looking for ways to expand the agreement that could allow Homeland Security officials to seek IRS data on Americans being investigated for various crimes.
Last month, an ICE attorney proposed updating the MOU to authorize new data requests on people “associated with criminal activities which may include United States citizens or lawful permanent residents,” according to a document seen by ProPublica. The status of this proposal is unclear. De Mello, at the time, rejected it and called for senior Treasury Department leadership to personally sign off on such a significant change.
The White House described DHS’ work with the IRS as a good-faith effort to identify and deport those who are living in the country illegally.
“ProPublica continues to degrade their already terrible reputation by suggesting we should turn a blind eye to criminal illegal aliens present in the United States for the sake of trying to collect tax payments from them,” White House spokesperson Abigail Jackson said in a statement after receiving questions about the blueprint from ProPublica.
She pointed to the April MOU as giving the government the authority to create the new system and added, “This isn’t a surveillance system. … It’s part of President Trump’s promise to carry out the mass deportation of criminal illegal aliens — the promise that the American people elected him on and he is committed to fulfilling.”
In a separate statement, a senior DHS official also cited the court’s approval of the MOU, saying that it “outlines a process to ensure that sensitive taxpayer information is protected while allowing law enforcement to effectively pursue criminal violations.”
How the System Works
The new system would represent a sea change, allowing law enforcement to request enormous swaths of confidential data in bulk through an automated, computerized process.
The system, according to the blueprint and interviews with IRS engineers, would work like this:
First, DHS would send the IRS a spreadsheet containing the names and previous addresses of the people it’s targeting. The request would include the date of a final removal order, a relevant criminal statute ICE is using to investigate the individual, and the tax period for which information is sought. If DHS fails to include any of this information, the system would reject the request.
The system then attempts to match the information provided by the DHS to a specific taxpayer identification number, which is the primary method by which the IRS identifies an individual in its databases.
If the system makes a match, it accesses the individual’s associated tax file and pulls the address listed during the most recent tax period. Then the system would produce a new spreadsheet enriched with taxpayer data that contains DHS’ targets’ last known addresses. The spreadsheet would include a record of names rejected for lack of required information and names for which it could not make a match.
Tax and privacy experts say they worry about how such a powerful yet crude platform could make dangerous mistakes. Because the search starts with a name instead of a taxpayer identification number, it risks returning the address of an innocent person with the same name as or a similar address to that of one of ICE’s targets. The proposed system assumes the data provided by DHS is accurate and that each targeted individual is the subject of a valid criminal investigation. In effect, the IRS has no way to independently check the bases of these requests, experts told ProPublica.
In addition, the blueprint does not limit the amount of data that can be transferred or how often DHS can request it. The system could easily be expanded to acquire all the information the IRS holds on taxpayers, said technical experts and IRS engineers who reviewed the documents. By shifting a single parameter, the program could return more information than just a target’s address, said an engineer familiar with the plan, including employer and familial relationships.
Engineers based at IRS offices in Lanham, Maryland, and Dallas are developing the blueprint.
“Gone Back on Its Word”
For decades, the American government has encouraged everyone who makes an income in the U.S. to pay taxes — regardless of immigration status — with an implicit promise that their information would be protected. Now that same data may be used to locate and deport noncitizens.
“For years, the IRS has told immigrants that it only cares that they pay their taxes,” said Nandan Joshi, an attorney with the Public Citizen Litigation Group, which is seeking to block the data-sharing agreement in federal court. “By agreeing to share taxpayer data with ICE on a mass basis, the IRS has gone back on its word.”
The push to share IRS data with DHS emerged while Elon Musk’s DOGE reshaped the engineering staff of the IRS. Sam Corcos, a Silicon Valley startup founder with no government experience, pushed out more than 50 IRS engineers and restructured the agency’s engineering priorities while he was the senior DOGE official at the agency. He later became chief information officer at Treasury. He has also led a separate IRS effort to create a master database using products from Silicon Valley giant Palantir Technologies, enabling the government to link and search large swaths of data.
Corcos didn’t respond to a request for comment. The White House said DOGE is not part of the DHS-IRS pact.
Sen. Ron Wyden, the ranking Democrat on the Senate Committee on Finance, which oversees the IRS, told ProPublica the system being built was ripe for abuse. It “would allow an outside agency unprecedented access to IRS records for reasons that have nothing to do with tax administration, opening the door to endless fishing expeditions,” he said.
The Treasury Inspector General for Tax Administration, the department’s internal watchdog, is already probing efforts by Trump and DOGEto obtain private taxpayer data and other sensitive information, ProPublica reported in April.
The Trump administration continues to add government agencies to its deportation drive.
DOGE and DHS are also working to build a national citizenship database, NPR reported last month. The database links information from the Social Security Administration and the DHS, ostensibly for the purpose of allowing state and local election officials to verify U.S. citizenship.
And in May, a senior Treasury Department official directed 250 IRS criminal investigative agents to help deportation operations, a significant shift for two agencies that historically have had separate missions.
Earlier this year, I was a part of a CNN documentary, Twitter: Breaking the Bird, which gave me much pause for reflection about the state of social media and how we got here. This year alone we’ve witnessed an unprecedented wave of disruption across these platforms.
Government workers, locked out of their jobs, struggled to organize securely. Protestors, seeking to plan No Kings marches, wondered which app could be the most trusted. Inbound international travelers have been deleting their social apps for fear that immigration officers will search their phones. And during major disasters, like the tragic Texas floods and the LA fires, emergency responders and volunteers find their critical updates buried by algorithms that prioritize engagement over urgency. On a daily basis, countless online communities face arbitrary deplatforming, surveillance, and loss of their digital spaces without recourse or explanation.
These aren’t isolated incidents: they’re symptoms of a fundamental crisis in how we’ve allowed our digital communities to be governed. We’ve unwittingly accepted a system where massive corporations control the public sphere; algorithms optimize for advertising revenue rather than human connection, and we the people have no real agency over our digital existence.
We’ve Lost Our Way
I’ve spent decades building social technologies, including working at Odeo, the company that ultimately pivoted to become Twitter. There I was the social app’s first employee and de facto CTO until late 2006; and have since built numerous other community organizing platforms. I’ve watched with growing concern as our digital spaces have become increasingly toxic and hostile to genuine community needs. The promise of social media as we defined it in the early days—to connect and empower communities of people—has been subverted by a business model that treats human connection as a commodity to be monetized.
Today, if you run a Facebook Group with thousands of members, you have no real authority – your community exists at the whim of corporate policies you cannot influence. This is fundamentally at odds with how real-world communities have always operated. Your local gardening club, bowling league, or neighborhood association has democratic processes for leadership and decision-making. Why should our digital communities be any different?
It’s Time For a New Social Media Bill Of Digital Rights
I believe that the time has come for a new Social Media Bill of Digital Rights. Just as the original Bill of Rights protected individual freedoms from government overreach, we need fundamental protections for our digital communities from corporate control and surveillance capitalism.
So what could such a Social Media Bill of Rights include?
The right to privacy & security: The ability to communicate and organize without fear of surveillance or exploitation.
The right to own and control your identity: People and their communities must own their digital identities, connections and data. And, as the owner of an account, you can exercise the right to be forgotten.
The right to choose and understand algorithms (transparency): Choosing the algorithms that shape your interactions: no more black box systems optimizing for engagement at the expense of community well-being.
The right to community self-governance: Crucially, communities of users need the right to self govern, setting their own rules for behavior which are contextually relevant to their community. (Note: this does not preclude developer governance.)
The right to full portability – the right to exit: The freedom to port your community in its entirety, to another app without losing your connections and content.
To determine whether these are the appropriate “Rights,” I’ve just launched a new podcast, Revolution.Social where I invite my guests, including the likes of Jack Dorsey, Cory Doctorow, Yoel Roth, Kara Swisher and Renee DiResta, to share their feedback and debate where we need to head next.
Architecting For A Better Future
The good news is that the technical foundations for a better future already exist through open protocols that work like the web itself – interconnected and controlled by no single entity.
The Fediverse, powered by ActivityPub, enables platforms like Mastodon to create interconnected communities free from corporate control.
Nostr provides a foundation for decentralized, encrypted communication that no one can shut down.
BlueSky is pioneering user choice in algorithms.
Signal demonstrates that private, secure communication is possible at scale.
Unlike the walled gardens of Meta, TikTok, and Twitter (now X), these open protocols allow communities to connect across platforms while maintaining control of their spaces. When you use email or browse the web, you don’t worry about which email provider or browser your friends use – it just works. Our social spaces should function the same way.
What’s missing is the bridge between these technical capabilities and the tools communities actually need to thrive. We need to move from closed, corporate platforms to open protocols that communities can shape and control. This isn’t just a technical challenge – it needs to become a social movement. We need to build systems that are co-designed with communities, that respect their autonomy, and that enable their authentic purposes.
Evan Henshaw-Plath, known as “rabble,” is an activist and technologist passionate about building commons-based social media apps that prioritize equity and sustainability.
There’s a fundamental architectural flaw in how the internet works that most people have never heard of, but it explains nearly every frustration you have with modern technology. Why your photos are trapped in Apple’s ecosystem. Why you can’t easily move data between apps. Why every promising new service starts from scratch, knowing nothing about you. And most importantly, why AI—for all its revolutionary potential—risks making Big Tech even bigger instead of putting powerful tools in your hands.
Former Google and Stripe executive Alex Komoroske (who recently wrote for us about why the future of AI need not be centralized) has written an equally brilliant analysis that traces all of these problems back to something called the “same origin paradigm”—a quick security fix that Netscape’s browser team implemented one night in the 1990s that somehow became the invisible physics governing all modern software.
The same origin paradigm is simple but devastating: Every website and app exists in its own completely isolated universe. Amazon and Google might as well be on different planets as far as your browser is concerned. The Instagram app and the Uber app on your phone can never directly share information. This isolation was meant to keep you safe, but it created something Komoroske calls “the aggregation ratchet”—a system where data naturally flows toward whoever can accumulate the most of it.
This is a much clearer explanation of a problem I identified almost two decades ago—the fundamental absurdity of having to keep uploading the same data to new services, rather than being able to tell a service to access our data at a specific location on the internet. Back then, I argued that the entire point of the open internet shouldn’t be locking up data in private silos, but enabling users to control their data and grant services access to it on their own terms, for their own benefit.
What Komoroske’s analysis reveals is the architectural root cause of why that vision failed. The “promise” of what we optimistically called “the cloud” was that you could more easily connect data and services. The reality became a land grab by internet giants to collect and hold all the data they could. Now we understand why: the same origin paradigm made the centralized approach the path of least resistance.
As Komoroske explains, this architectural choice creates an impossible constraint for system designers.
This creates what I call the iron triangle of modern software. It’s a constraint that binds the hands of system designers—the architects of operating systems and browsers we all depend on. These designers face an impossible choice. They can build systems that support:
Sensitive data (your emails, photos, documents)
Network access (ability to communicate with servers)
Untrusted code (software from developers you don’t know)
But they can only enable two at once—never all three. If untrusted code can both access your sensitive data and communicate over the network, it could steal everything and send it anywhere.
So system designers picked safety through isolation. Each app becomes a fortress—secure but solitary. Want to use a cool new photo organization tool? The browser or operating system forces a stark choice: Either trust it completely with your data (sacrificing the “untrusted” part), or keep your data out of it entirely (sacrificing functionality).
Even when you grant an app or website permission only to look at your photos, you’re not really saying, “You can use my photos for this specific purpose.” You’re saying, “I trust whoever controls this origin, now and forever, to do anything they want with my photos, including sending them anywhere.” It’s an all-or-nothing proposition.
This creates massive friction every time data needs to move between services. But that friction doesn’t just slow things down—it fundamentally reshapes where data accumulates. The service with the most data can provide the most value, which attracts more users, which generates more data. Each click of the ratchet makes it harder for new entrants to compete.
Consider how you might plan a trip: You’ve got flights in your email, hotel confirmations in another app, restaurant recommendations in a Google document, your calendar in yet another tool. Every time you need to connect these pieces you have to manually copy, paste, reformat, repeat. So you grant one service (like Google) access to all of this. Suddenly there’s no friction. Everything just works. Later, when it comes time to share your trip details with your fellow travelers, you follow the path of least resistance. It’s simply easier to use the service that already knows your preferences, history, and context.
The service with the most data can provide the most value, which attracts more users, which generates more data. Each click of the ratchet makes it harder for new entrants to compete. The big get bigger not because they’re necessarily better, but because the physics of the system tilts the playing field in their favor.
This isn’t conspiracy or malice. It’s emergent behavior from architectural choices. Water flows downhill. Software with the same origin paradigm aggregates around a few dominant platforms.
Enter artificial intelligence. As Komoroske notes, AI represents something genuinely new: it makes software creation effectively free. We’re entering an era of “infinite software”—endless custom tools tailored to every conceivable need.
AI needs context to be useful. An AI that can see your calendar, email, and documents together might actually help you plan your day. One that only sees fragments is just another chatbot spouting generic advice. But our current security model—with policies attached at the app level—makes sharing context an all-or-nothing gamble.
So what happens? What always happens: The path of least resistance is to put all the data in one place.
Think about what we’re trading away: Instead of the malleable, personal tools that Litt envisions, we get one-size-fits-all assistants that require us to trust megacorporations with our most intimate data. The same physics that turned social media into a few giant platforms is about to do the same thing to AI.
We only accept this bad trade because it’s all we know. It’s an architectural choice made before many of us were born. But it doesn’t have to be this way—not anymore.
But here’s the hopeful part: the technical pieces for a fundamentally different approach are finally emerging. The hopes I had two decades ago about the cloud being able to separate us from having to let services collect and control all our data may finally be possible.
Perhaps most interestingly, Komoroske argues that the technological element that makes this possible is the secure enclaves now found in chips. This is actually a tech that many of us were concerned would lead to the death of general purpose computers, and give more power to the large companies. Cory Doctorow has warned about how these systems can be abused—he calls them Demon-haunted computers—but could we also use that same tech to regain control?
That’s part of Komoroske’s argument:
These secure enclaves can also do something called remote attestation. They can provide cryptographic proof—not just a promise, but mathematical proof—of exactly what software is running inside them. It’s like having a tamper-proof seal that proves the code handling your data is exactly what it claims to be, unmodified and uncompromised.
If you combine these ingredients in just the right way, what this enables, for the first time, are policies attached not to apps but to data itself. Every piece of data could carry its own rules about how it can be used. Your photos might say, “Analyze me locally but never transmit me.” Your calendar might allow, “Extract patterns but only share aggregated insights in a way that is provably anonymous.” Your emails could permit reading but forbid forwarding. This breaks the iron triangle: Untrusted code can now work with sensitive data and have network access, because the policies themselves—not the app’s origin—control what can be done with the data.
Years of recognizing that Cory’s warnings are usually dead-on accurate has me approaching this embrace of secure enclaves with some amount of caution. The same underlying technologies that could liberate users from platform silos could also be used to create more sophisticated forms of control. But Komoroske’s vision represents a genuinely different deployment—using these tools to give users direct control over their own data and to cryptographically limit what systems can do with that data, rather than giving platforms more power to lock things down. The key difference is who controls the policies. (And I’m genuinely curious to hear what Cory thinks of this approach!)
The vision Komoroske paints is compelling: imagine tools that feel like extensions of your will, private by default, adapting to your every need—software that works for you, not on you. A personal research assistant that understands your note-taking system. A financial tracker designed around your specific approach to budgeting. A task manager that reshapes itself around your changing work style.
To the extent that any of this was possible before, it required you simply handing over all your data to a big tech firm. The possibility of being able to separate those things… is exciting.
This isn’t just about better apps. It’s about a fundamental shift in the power dynamics of the internet. Instead of being forced to choose between security and functionality, between privacy and convenience, we could have systems where those aren’t trade-offs at all.
The same origin paradigm got us here, creating the conditions for data monopolies and restricting user agency. But as Komoroske argues in both the piece he wrote for us and this new piece, we built these systems—we can build better ones. We might finally deliver on its promises of user empowerment rather than further concentration.
As we’ve argued at Techdirt for years, the internet works best when it empowers users rather than platforms. The same-origin paradigm was an understandable choice given the constraints of the 1990s. But we’re no longer bound by those constraints. The tools now exist to put users back in control of their data and their digital experiences.
We can move past the learned helplessness that has characterized the last decade of internet discourse. We can reject the false choice that says the only way to access powerful new technologies is to surrender our freedoms to tech giants. We can actually build toward a world where end users themselves have both the power and control.
We just need to embrace that opportunity, rather than assuming that the way the internet has worked for the past 30 years is the way it has to run going forward.
The second most frustrating aspect of RFK Jr.’s performance as the head of Health and Human Services has been just how predictable the actions he’s taken are. When you start with a simple premise, that Kennedy is a vehement anti-vaxxer, the view that measles is less harmful than the MMR vaccine makes sense. The appointment of other wellness charlatans tracks perfectly. The pulling back on COVID vaccination guidance fits like a puzzle piece. And it should be no surprise that Kennedy decided to fire every single vaccine expert on the ACIP panel to clear the way for his anti-vaxxer views.
But really, truly, the most frustrating part of his reign thus far has been Congress’ complete unwillingness to end this era of malfunction, or in any way attempt to control it. From Kennedy’s nomination hearings all the way to the present, our representatives in Washington have sat back, arms folded, completely disinterested in the very real harm and, yes, deaths that are and will occur due to Kennedy’s incompetence.
But, god damn it, I have to believe that Congress at least might have a problem being lied to directly by Kennedy. And that appears to be what he did when he sent a report to back up his changing of the COVID vaccine guidance. The report is reportedly filled with studies that are either unpublished, under current dispute, or which don’t actually say what he says they say. Misinformation, in other words, fed directly by the HHS Secretary to a Congress that is supposed to oversee his work.
Titled “Covid Recommendation FAQ”, the document has not been posted on the HHS website, though it is the first detailed explanation of Kennedy’s announcement from the agency. Medical experts who reviewed all the citations in the FAQ said it distorts some legitimate studies and cites others that are disputed and unpublished.
One of the studies the HHS document cites is under investigation by its publisher, Sage Journals, regarding “potential issues with the research methodology and conclusions and author conflicts of interest,” according to a link on the study’s webpage.
“This is RFK Jr.’s playbook,” said Dr. Sean O’Leary, chair of the Committee on Infectious Diseases for the American Academy of Pediatrics and an assistant professor of pediatrics at the University of Colorado School of Medicine. “Either cherry-pick from good science or take junk science to support his premise — this has been his playbook for 20 years.”
To that end, there are more issues with the research and studies powering this document of bullshit. Rather than just published studies that are under current dispute, some of the studies cited haven’t even been published yet. That means no peer review. Kennedy has been quite fond recently of the phrase “gold standard science”, as though he just learned it. He doesn’t seem to know what it means, however. Peer reviewed studies are the gold standard in science and medical research, for what should be painfully obviously reasons. Even the NIH’s own site acknowledges this. If your research or paper cannot survive the scrutiny of your peers, how good can it really be?
Other studies, including unpublished studies, are cited in support of the CDC’s new guidance despite those studies explicitly stating that they should not be.
Another study cited in the document is a preprint that was made available online a year ago, and has still not been published in a peer-reviewed journal. Under the study’s title is an alert that “it reports new medical research that has yet to be evaluated and so should not be used to guide clinical practice.”
The FAQ draws on the preprint to claim that “post-marketing studies” of COVID vaccines have identified “serious adverse effects, such as an increased risk of myocarditis and pericarditis” — conditions in which the heart’s muscle or its covering, the pericardium, suffer inflammation.
While research early in the pandemic did find that, new research not included in the memo indicates that the risk has fallen with new vaccine protocols.
More cherry picking, it seems, along with a complete disregard for the very researchers that performed the research as to how it is used. Kennedy recently claimed his HHS would follow the science and scientists wherever the data leads. He is not, because it doesn’t conform to his agenda.
And then there are the bald-faced lies.
In two instances, the HHS memo makes claims about dangers to pregnant women that are actively refuted by the papers it cites to back them up. Both papers support the safety and effectiveness of COVID vaccines for pregnant women.
The HHS document says that another paper it cites found “an increase in placental blood clotting in pregnant mothers who took the vaccine.” But the paper doesn’t contain any reference to placental blood clots or to pregnant women.
“I’ve now read it three times. And I cannot find that anywhere,” said Turrentine, the OB-GYN professor.
If he were grading the HHS document, “I would give this an ‘F,'” Turrentine said. “This is not supported by anything and it’s not using medical evidence.”
Folks, there ought to be zero instances of our government operating on lies when it comes to creating policy. But that’s all this is. An agenda-driven madman heading up HHS changing policy and programs with a wave of a hand to comport with his misguided agenda, all while it’s being supported by either AI-generated slop or whatever the hell this FAQ-of-lies is.
So, to members of Congress on one side of the political aisle, I merely ask this: have you no pride? You’re okay with being spoon-fed lies from a former democrat simply because Dear Leader says so? You’re okay with having blood on your hands as a result of your inability to do your job performing oversight? You’re okay with being the useful idiot in Kennedy’s agenda?
Each day adds another layer of fucked-upness to this country’s anti-immigration efforts. We, as a nation, are now involved daily in extrajudicial renditioning of migrants to countries they’ve never lived in. We’re all implicated in nearly daily rejections of court orders and any remaining shred of human decency. We’re treating human beings like trash to be discarded, whether it’s mothers seeking abortions or migrants just hoping to find somewhere more stable to live.
And now we’re doing this: intermingling children in a massive criminal database for no other reason than they (or their parents) weren’t born in the United States. Here’s Dhruv Mehrotra with more details at Wired:
The United States government has collected DNA samples from upwards of 133,000 migrant children and teenagers—including at least one 4-year-old—and uploaded their genetic data into a national criminal database used by local, state, and federal law enforcement, according to documents reviewed by WIRED.
The records, quietly released by the US Customs and Border Protection earlier this year, offer the most detailed look to date at the scale of CBP’s controversial DNA collection program. They reveal for the first time just how deeply the government’s biometric surveillance reaches into the lives of migrant children, some of whom may still be learning to read or tie their shoes—yet whose DNA is now stored in a system originally built for convicted sex offenders and violent criminals.
The DOJ claims this is essential, even though it didn’t decide to start adding this particular data to the database until 22 years after its creation. According to DOJ statements, the addition of minors and migrants to a criminal database (CODIS [Combined DNA Index System], which is run by the FBI) is essential to the safety of the nation, allowing law enforcement to “assess” the threat posed by 4-year-old children to the general public due to their… um… lack of US citizenship.
The addition of migrant data dates back to the last few months of Trump’s first presidency. This went unaltered during Biden’s term.
Spanning from October 2020 through the end of 2024, the records show that CBP swabbed the cheeks of between 829,000 and 2.8 million people, with experts estimating that the true figure, excluding duplicates, is likely well over 1.5 million. That number includes as many as 133,539 children and teenagers.
The CODIS database is there to track criminals and was originally used to compile DNA samples and fingerprints only from those being criminally charged. Since then, it has been expanded to cover people who have, in many cases, done nothing more than reside in the United States without proper documentation.
People who use the term “illegal immigrants” or “illegal aliens” seem to think that being in this country without documentation is a criminal act in and of itself. And it is, but only to a certain extent. It’s a civil offense though, like not paying property taxes or getting a parking ticket. Do some of these things often enough and you might see criminal charges. But, generally speaking, no one’s getting fingerprinted and their DNA added to CODIS just because they didn’t feed the meter or fall behind on property tax payments.
For some reason, this nation has recently begun to believe it’s acceptable to treat certain civil violators like criminals if that makes it easier to deny them rights or, in this case, add them to a forever database just because there’s no court order or law preventing them from doing this.
It’s the sort of thing that dehumanizes migrants by turning them into database records. It further strips them of their humanity by adding them to a long list of actual criminals with the insinuation being that (1) they’re no less guilty than the criminals in the database, and (2) if they haven’t committed a crime yet, they’re probably going to, so why not be proactive.
For all the ugliness we’re witnessing during Trump’s second administration in terms of antipathy towards migrants, it’s important to point out that what’s been observed so far is directly attributable to Trump’s predecessor, who did nearly nothing to roll back Trump’s anti-immigrant policies.
The data, which CBP published to its website in February, shows that DNA collection accelerated under the Biden administration, with daily submissions to CODIS increasing sharply in 2024 alongside a reported rise in border apprehensions. On a single day in January 2024, for example, the Laredo, Texas, field office submitted as many as 3,930 DNA samples to the FBI—252 were listed as 17 or younger, CBP records show.
The bottom line is this: there’s no way any federal or local law enforcement officer should be adding a four-year-old to a criminal database. It’s impossible to think of any scenario where this addition is justified. For that matter, no minor who is not suspected of committing a crime should be in there either, especially if the only reason for adding them is just because the opportunity (detention by immigration officers) presented itself. A civil infraction is not a criminal offense, no matter how much three consecutive presidential administrations would prefer to believe. This is a travesty, aided and abetted by two presidents who decided the loudest, most hateful people in the nation should have a say in how immigration enforcement is carried out.