If you’re worried about the bad optics of working with ICE, the federal government is here to help subsidize your recovery from mass deportation conjunctivitis. If you’re worried about the personal negative side effects of buddying up to ICE’s masked kidnapping squads, the administration is here to assure cops that it might cover some of the legal costs of doing business with ICE.
US Immigration and Customs Enforcement is pitching a plan to help shield local police officers who make immigration arrests from possible financial consequences if they are accused of on-duty misconduct.
The agency is proposing to subsidize liability insurance for state and local officers who are trained and deputized to enforce federal immigration laws, according to a planning document published Friday.
This offer is not valid in sanctuary cities or anywhere cops shops haven’t signed agreements to do ICE’s detention/arrest work for it. To get this extra coverage, law enforcement agencies will have to sign 287(g) agreements. These agreements make local law enforcement agencies part of mass deportation machinery. It requires agencies to hold arrested migrants and tell ICE to come pick them up. It also allows local cops to act as immigration officers by permitting them to perform arrests using ICE administrative “warrants.”
That word is in scare quotes because administrative warrants are just pieces of paper that say ICE knows of someone subject to a removal order. They are not reviewed by magistrate judges. And, unlike what ICE would have you believe, they do not authorize searches of private property.
This is where some of ICE’s (new) billions of dollars might be going. ICE officers don’t need this sort of insurance because they’re defended and indemnified by the federal government. (And they don’t need it anyway because the Supreme Court has made it pretty much impossible to successfully sue a federal officer for rights violations.)
Local cops aren’t nearly as immune as federal officers, so they might appreciate some insurance coverage in the extremely unlikely chance they are sued successfully for violating rights while doing ICE’s work for it. But the payout seems pretty fucking low considering ICE now commands the largest budget of any federal law enforcement agency.
Under the plan, officers would purchase insurance covering up to $500,000 in personal liability, which typically funds legal fees, settlements and judgments. Officers would be reimbursed up to $250 annually — roughly what the insurance is expected to cost.
The administration that claims to love cops (that love ICE) the most, this minimal payout should be viewed as insulting. First, the administration “allows” officers to spend their own money to purchase insurance coverage they wouldn’t otherwise need if their employing agencies had decided signing a 287(g) agreement wasn’t worth the trouble.
Second, tossing cops $250 a year does a whole lot of nothing when it comes to premiums for this specific sort of insurance. And, in other cases, partnering with ICE will automatically void these policies.
Pennsylvania’s risk pool, for instance, recently made clear that it would exclude “proactive immigration enforcement activities” from coverage, forcing several participating counties to search for other insurance options.
Butler County Sheriff Michael Slupe said he found insurance to cover his 13 deputies participating in the program at a cost of $20,000 in annual premiums.
In the first instance, there is no coverage to be had even if the DHS is willing to cough up a measly $250 a year for ICE buddy cops. In the second instance, a local agency is paying $1,538/year per officer to cover officers it has willingly lent to ICE’s anti-migrant activities. That means it’s still on the hook for the other $1,250/year. $3,250 (for 13 officers) looks like a down payment, rather than a meaningful contribution.
But the facts on the ground don’t bother Sheriff Slupe, apparently. He’s sure Trump will come riding the rescue with a fat stack of greenbacks.
“I want to make sure the guys are additionally covered, so we had to spend the money,” he said, adding that federal funding would cover the cost.
Technically almost true, if you read this to mean the federal government will cover an almost-insignificant portion of the cost. But it’s weird to see Sheriff Slupe offer to pitch in on immigration enforcement when his agency was thrown under the bus a bit following an alleged assassination attempt targeting Trump during his 2024 election campaign.
It’s all very stupid and unnecessary. It’s already pretty difficult to successfully sue law enforcement officers, thanks to the ever-expanding coverage of the qualified immunity doctrine (not actually a law!). Furthermore, the federal government’s pitch for additional liability insurance makes you wonder which Trump donors might profit from this push for new premiums. ICE already claims any officers participating in the 287(g) program are “acting under the color of federal authority,” which vastly increases the level of lawsuit immunity. Going even further, the federal government has already pretty much promised local law enforcement officers they’ll be well-defended should they be sued for boarding the ICE bang bus.
The agreements also state that local officers who face civil lawsuits can ask the US Department of Justice to represent them, and that ICE will generally support their requests.
Adding all of this up, we can only assume none of this adds up. The stipend is too small. The government says local officers should present themselves as federal officers in court proceedings. And these officers seem unlikely to ever need to hire their own representation should they be sued for their ICE-adjacent activities. And now ICE is encouraging participants in the 287(g) program to buy insurance they’ll likely never need or, in some cases, not be able to use due to limits enacted by insurance providers.
It comes across as a blend of stupid and performative. As such, it fits in perfectly with this administration’s MO. But if I were a cop doing ICE’s dirty work, I’d be demanding full coverage paid with federal tax dollars, rather than assume this cock-up of a hybrid will actually do anything when I’ve been sued by competent plaintiffs.
From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.
This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database.
There is no safe age verification. There is no age verification that doesn’t put people at risk.
Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches.
The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web:
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of theFederal Bureau of Investigation(FBI) today launched an official inquiry into the source of the images.
Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary.
That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.
So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned.
Yiiiiiikes.
And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed:
That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page.
But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records.
And it appears no one internally at the company noticed.
As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system:
The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.
The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.
“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”
Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this serviceon a semi-regular basis.
And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale:
A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license.
Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing.
Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage:
Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).
This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.
“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.
At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.
You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems.
Become a language expert with a Babbel Language Learning subscription. With the app, you can use Babbel on desktop and mobile, and your progress is synchronized across devices. Want to practice where you won’t have Wi-Fi? Download lessons before you head out, and you’ll be good to go. However you choose to access your 10K+ hours of online language education, you’ll be able to choose from 14 languages. And you can tackle one or all in 10-to-15-minute bite-sized lessons, so there’s no need to clear hours of your weekend to gain real-life conversation skills. Babbel was developed by over 100 expert linguists to help users speak and understand languages quickly. With Babbel, it’s easy to find the right level for you — beginner, intermediate, or advanced — so that you can make progress while avoiding tedious drills. Within as little as a month, you could be holding down conversations with native speakers about transportation, dining, shopping, directions, and more, making any trip you take so much easier. It’s on sale for $159 when you use the code LEARN at checkout.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
A little more than a year ago, the Trump administration pushed a novel legal theory in order to juice its migrant arrest stats. It was a two-part process. First, the administration unilaterally declared expansive areas near US military bases to be “national defense areas.”
This meant that areas surrounding bases — like (especially) Fort Bliss in El Paso, Texas (which is also home to one of ICE’s largest detention centers) — were subject to a separate set of rules governing “military zones.” In these areas, military officers could effect arrests on anyone “intruding” into these areas. The outlines of these areas were deliberately large — so much so that they butted up against US-Mexico border.
The point of this effort was obvious: Trump hoped to see more arrests at the border by allowing the military to pitch in with his mass deportation efforts. This was the administration’s “Posse Comitatus Act” workaround. That law, passed in 1878, forbade the federal government from co-opting military members to perform regular law enforcement work. It’s the same thing that was a sticking point in many of Trump’s National Guard deployments to major US cities.
By pretending massive areas surrounding US bases were now so essential to US national security that the government absolutely needed to draft soldiers into its immigration law enforcement effort, the Trump administration hoped to avoid adverse court rulings.
That hasn’t really worked. National Guard deployments have been blocked by federal courts. And while there hasn’t been a precedential ruling on this novel interpretation of “national defense areas,” the DOJ has decided to issue a legal memo — more than a year after this had already happened — that says this is all cool and legal.
On Aug. 14, the Department of Justice’s Office of Legal Counsel (OLC) released a 15-page memorandum contending that the Posse Comitatus Act does not prohibit military personnel from effecting arrests in the “immediate vicinity” of a designated “national defense area” for alleged crimes there. The opinion followed President Trump’s April 2025 order designating swaths of the Mexico-U.S. border as national defense areas.
There’s a lot of bullshit in the OLC’s memo [PDF], but let’s start with this:
Even though substantial portions of the NDAs may be presently unoccupied or have no standing structures on them, there is a military necessity to ensure that unauthorized persons are not establishing a position to monitor the activities of U.S. forces for intelligence gathering purposes or conducting reconnaissance in preparation for a terrorist attack. Individuals may also be drawn to remote and unoccupied locations to engage in criminal activity, which poses a threat to military personnel who may come upon them in the course of their duties or where the activity itself poses a danger, such as the operation of methamphetamine laboratories. As there is no way for military personnel to know a priori the identity or intent of an unauthorized person, there is a military purpose in apprehending, at least temporarily, anyone whose presence is unauthorized, in order to ensure appropriate measures can be taken to protect national security and the safety of military personnel. That military purpose continues even if the trespassers have exited the installation before they were apprehended.
It’s insanely hilarious to actually claim in an official legal memo that if soldiers aren’t allowed to detain migrants, some of them are just going to fire up a meth lab within the vicinity of a US military base.
But once we’re done laughing, we have to recognize the obvious side effects of this declaration by the DOJ: that anyone is subject to this interpretation of the law, which turns troops into cops just because the administration says it does.
One of the many troubling aspects of this assertion (and of the executive order underlying it) is that it places no burden on the government to clearly, physically denote the outlines of these supposed “national defense areas.” This means migrants crossing borders will just assume they’re walking on land and only find out after the fact that the government has unilaterally declared that area to largely be exempt from commonly accepted restrictions on US military officers.
And even if you don’t care what happens to migrants, especially those who have very recently illegally crossed in the US, you might want to take a moment to consider your fellow citizens who also won’t know they’re in a “national defense area” until they’re greeted at gunpoint by members of the US military. It’s already scary enough to get jumped by cops when you’re just minding your own business. Now, imagine this same experience, except with an armored vehicle featuring a top-mounted .50 cal machine gun.
The DOJ doesn’t seem to find much support for its assertions in the memo. And yet the OLC has delivered one all the same. The memo pretends there’s no difference between the military enforcing the law within the confines of US military base and enforcing it in large, unmarked areas whose confines can only be defined by those with access to information the Trump administration certainly isn’t going to be sharing with everyone.
But the DOJ OLC is also (sadly) correct to point out that this interpretation of the law is not subject to any adverse precedent. Do you know why that is? BECAUSE NO ONE BUT THIS ADMINISTRATION HAS TRIED TO DO THIS EXTREMELY FUCKED UP THING BEFORE. Opening an Overton Window in a legal vacuum doesn’t make you the smartest people in the room. It just makes you the pioneers of martial law fuckery.
Finally, the OLC says not even the vague boundaries of any supposed “national defense areas” should prevent military officers from arresting migrants (or anyone else in the area).
In sum, we conclude that the use of military personnel to arrest trespassers just outside of an NDA would not violate the PCA, given the express statutory authorization and the military-purpose of a commander’s traditional protective power.
Even the confines are not the confines. The OLC doesn’t bother to describe what it considers to be “just outside of an NDA.” Nor is it going to. That’s a problem for arrestees to try to suss out in courts that already give the federal government plenty of leeway any time it starts talking about national security or national defense. How far away can someone (as the DOJ’s hypothetical puts it) “engage in criminal activity” or “reconnaissance?” What’s the acceptable distance between an NDA and a meth lab? Any distance could be considered “just outside” as long as someone’s will to swear they saw some reconnaissance or criminal activity happening.
We’re fortunate that we haven’t seen this novel interpretation of the PCA abused excessively. So far! But the late arrival of this legal justification seems to indicate we’ll be seeing a lot more of that in the near future.
Apple and Google’s quick decision to rename the Gulf Of Mexico at the behest of a mad and racist king was a lovely example; and now we’re back again with both companies quickly moving to rename Lake Ontario “Lake America” just because the increasingly unpopular U.S. President had a brain fart during his pointless and harmful trade war with Canada.
“Everyone considers it fucking nuts.” Inside Apple, I'm told "not a soul" supports Donald Trump's Lake Ontario rebrand to "Lake America," but the company is also resigned to making such concessions to avoid the White House's rage. Details in @status.news: www.status.news/p/apple-maps…
These are, so we are clear, active choices — their mapping systems aren’t just innately and automatically following the lead of the authoritarian U.S. government’s GNIS data. Google (and the company’s defenders) had initially tried to insist they were following automated GNIS protocols, but that wasn’t actually the case:
“Google began rolling out this change for US users on Saturday. The company posted a brief update on its Google Maps blog, noting that it follows the US Geographic Names Information System (GNIS) for its maps, so the company implies it had no choice but to rename Lake Ontario in Google Maps, which is the most popular mapping platform in the US by a wide margin.
However, Google was even quicker to switch over to Lake America than the US government. While the GNIS database acknowledges the name change in a summary report, the base map layer still reflects the internationally recognized name of Lake Ontario. A message across the top of the USGS-operated website notes that the change to official maps is still pending.”
Even then, there’s nothing saying Google couldn’t have ignored the GNIS changes for the sake of product quality. As it is, both Apple and Google are still ensuring that U.S. users of both mapping products see King Trump’s pointless change, while everybody else in the world sees material reality.
This lightning-fast choice to quickly buckle to the incoherent whims of a tyrant over something this stupid certainly raises questions about what kinds of subservience we don’t know about yet by these titans of U.S. innovation. There was some hope that Apple, with new CEO leadership and no shortage of “fuck you money,” would demonstrate some sort of ethical leadership here, but alas.
Amusingly Mapquest (and I guess TomTom) used Apple and Google’s abject fecklessness to market “having the slightest hint of a backbone” as a market branding differentiator:
“The company said its mobile app received hundreds of thousands of downloads after it announced Thursday that the name Lake Ontario would remain on its apps, despite Trump directing the Interior Department to update the lake’s name in the Geographic Names Information System (GNIS).”
This is still somehow occurring despite the fact that Trump’s support is cratering due to pointless wars, high oil prices, sagging polling, and clearly waning health. Even on these peripheral issues where taking a stand could be easily defended by an ocean of highly paid lawyers, executives can’t even muster the vaguest outline of some sort of meaningful backbone.
I’m sure they’d argue that it’s their fiduciary responsibility to shareholders to not “antagonize” the U.S. government. But where’s the fiduciary responsibility to the continued existence to functional markets, industry autonomy, and democracy in a country under assault by some of the dimmest, most incompetent and corrupt autocrats the American experiment has ever seen?
Sony’s ability to generate anger lately is pretty impressive. After the company announced that there would be no more physical media versions of games made starting in 2027, to the resounding anger of many people, Sony also demonstrated yet again that it’s capable of ripping away the digital “purchases” people had made once its own licensing arrangements expire. While some folks out there understand that in the cases of some digital goods you’re not actually buying a thing, but a temporary license, many others either don’t know that or simply don’t like it, spurring on further anger against Sony across the internet. And that’s leaving aside entirely the subject of game and cultural preservation in all of this.
Sony is bad enough at this that they can manage to piss me off even when I probably agree with them when it comes to a particular lawsuit. Let’s get through the part where I’m on their side first.
There is a lawsuit going on in California, brought against Sony by a group of PlayStation gamers, that is arguing that the platform doesn’t comply with a relatively new California law for digital purchases that has strict rules around disclosing that the nature of the purchase is a license. The suit argues for non-compliance because the PlayStation Store uses the phrases “buy” and “purchase”, which is forbidden by the law.
(b) (1) It shall be unlawful for a seller of a digital good to advertise or offer for sale a digital good to a purchaser with the terms “buy,” “purchase,” or any other term which a reasonable person would understand to confer an unrestricted ownership interest in the digital good, or alongside an option for a time-limited rental, unless either of the following occur:
(A) The seller receives at the time of each transaction an affirmative acknowledgment from the purchaser indicating all of the following:
(i) That the purchaser is receiving a license to access the digital good.
(ii) A complete list of restrictions and conditions of the license.
(iii) That access to the digital good may be unilaterally revoked by the seller if they no longer hold a right to the digital good, if applicable.
(B) The seller provides to the consumer before executing each transaction a clear and conspicuous statement that does both of the following:
(i) States in plain language that “buying” or “purchasing” the digital good is a license.
(ii) Includes a hyperlink, QR code, or similar method to access the terms and conditions that provide full details on the license.
And here’s what it looks like if you were to make a purchase for a license for a digital game on the PlayStation Store:
So let’s go back to the law. Yes, the page uses the term “purchase”. It also asks for acknowledgement via the “Confirm Purchase” button that the customer understands they’re buying a license (and it’s in plain language), links to the SPLA and TOS which outline the restrictions and conditions of the license, and details the revokable nature of that license. Sony is arguing it’s compliant and I’m compelled to agree.
And if Sony left it at that, I wouldn’t be writing this post right now. But then the company just had to further and say something really stupid.
Now, as reported by Game File, Sony recently filed its response to the lawsuit, claiming that customers are not only told “your purchase of this digital product amounts to a licence”, but that “reasonable consumers” already understand this anyway without having to be told.
Sony’s argument is that because digital copies of games are not a finite resource, and that because multiple people can buy a digital copy of the same game, that means nobody actually ‘owns’ it – if they did, nobody else would be able to have it.
“As plaintiffs admit, Section 1 of the SPLA likewise explains that ‘the Software is licensed to you, not sold’, Sony’s filing reads. “This makes sense. In the digital age, it is not plausible to allege that reasonable consumers believed they were obtaining ‘ownership’ of a digital game.
“Were that the case, then Plaintiff Edward Heycock would not have been able to obtain the game Resident Evil Requiem on February 25, 2026 for $69.99 from the PlayStation Store after Plaintiff Jason Mendoza had obtained Resident Evil Requiem on February 14, 2026, because Mr Mendoza, not Sony, would have owned it then.”
And on this, Sony can fuck all the way off. This is completely wrong on a variety of levels.
Let’s start with the fact that the internet is chockablock with discussions trying to unconfuse many people when it comes to what they bought in a digital purchase. There are Reddit posts asking this question. There are tech blogs that have put out specific articles answering the question of ownership of certain digital goods. Or, if the wider internet doesn’t suffice for you, the FTC has articles on its own website that try to help address ownership rights for the public for digital goods. Here’s a snippet that will help drive home the second reason Sony’s statement is so dumb.
When you buy a physical item, you’ve got it. It’s yours. But when you click the “buy” button on a digital product, it really depends. You may have access to it only while you have an active account with the platform or website that sold it, or only for as long as that platform or website stays in business. Another factor is Digital Rights Management (DRM) software, which is attached to many digital items and is the thing that makes it impossible, for example, for you to play a video game on a different console brand.
Another reason why you might not have full control of your digital product is that what you really got when you clicked “buy” is often merely a license to access the content. This fact is often explained only in fine print in the terms of service — terms that the seller can usually change at will. And if the seller itself has licensing issues with the content you bought, then your own license to use the digital item can become worthless. All things beyond your control.
So all of these entities putting out all of this information to try to educate the public about what the hell they bought with a digital purchase are only speaking to the unreasonable? That’s, dare I say, an unreasonable thing to say.
And in that FTC post, did you happen to notice just how many qualifiers are stuffed into those two paragraphs? It depends. May. Many. Might. Often. So why all of those qualifiers?
Because some digital purchases can and do confer ownership to the buyer. Not everyone is out here selling a license. Some digital goods are sold as permanent ownership.
So, no matter how this particular lawsuit shakes out, Sony needs to either understand their own customers’ sentiments and knowledge far better than they do, or they need to stop saying things that they know are false. I can attest that the general public does not have a firm understanding of their ownership rights and what they’re actually buying with digital purchases. Pretending otherwise is nonsense.
Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced.
In this post, we go through the Settlement’s provisions in detail and explain why that is so, including how:
The Settlement embeds age assurance technology and age-gates into Meta’s social media products and requires all users—minors and adults—to undergo a rights-threatening age estimation process
The Settlement places severe restrictions on Teens that can only be modified by the Teens’ parents and only then in exchange for giving their parents a ton of information about their online community and usage;
The Settlement seems to empower the attorneys general to enforce Meta’s content restriction on “age inappropriate content,” categories that Meta itself has had trouble administering without excluding information about sexuality, sexual and reproductive healthcare, and abortion medication;
The Settlement actually requires Meta to collect, analyze, and retain more information about its Teen users—when the pressure should have been on Meta to diminish its surveillance capitalism.
Note: A chunk of the settlement addresses unauthorized users under age 13, and Meta’s obligations to comply with the Children’s Online Privacy Protection Act. Meta policy has banned users under 13 since the company opened to the public in 2006. Aside from the age assurance frameworks that support both those and the other parts of the Settlement, the under-13 provisions are not addressed in this post. Those provisions essentially require Meta to detect and delete all under-13 accounts.
Further note: All U.S. states are parties to the Settlement except Florida, New Mexico, and Texas. The Settlement includes D.C., American Samoa, Guam, Northern Mariana Islands, and Puerto Rico.
Age Gates Reinforced By Age Estimation Technology
In the Settlement, Meta agrees to age-gate Instagram and Facebook, thus making age gates a legal mandate. And Further, Meta will now enforce these age gates with “age assurance” technology, ditching its previous practice where the person signing up for the services self-attests to their birthdate. This concession firmly embeds deeply flawed age estimation technology into the online experience of millions of people around the world. First and foremost, the age verification setup seriously threatens online anonymity and privacy for everyone, as we’ve said before. The Technology also just adds a layer of creepiness into the user of any service. In the Settlement, Meta pledges to, within one year, apply one or more age assurance methods to each Instagram or Facebook user in the states and territories that joined the Settlement. [P. 10, §II.A.1]
1. Age Assurance Framework. Within one (1) year of the Effective Date, Meta will adopt an age assurance framework (“Age Assurance Framework”), wherein it will apply one or more age assurance methods developed by a third party and licensed to customers (“Commercially Available Age Assurance Methods”) orage assurance methods developed by Meta (“Proprietary Age Assurance Methods”) (collectively, “Age Assurance Methods”) to each Meta SMP user in the Settling States. For the purposes of this Section II.A, an age assurance method developed or acquired by Meta that uses the same or functionally identical technology and methodology to a Commercially Available Age Assurance Method shall be treated as a Commercially Available Age Assurance Method. The Age Assurance Framework must include Age Assurance Methods to evaluate whether a Meta SMP user is a Teen User or U13, as described in Section II.A.6. New users of Meta SMPs who have not yet had their age assessed by an Age Assurance Method pursuant to Meta’s Age Assurance Framework shall receive the Default Protections pursuant to Section II.A.10 of this Agreement.
Those methods might include both commercially available products, as well as proprietary age estimation process Meta might have or develop. Meta also pledges to consider age signals from Google and Apple operating systems and app stores. [§II.A.5] Meta has previously advocated for age assurance requirements to fall on Google and Apple rather than on individual services.
This age assessment essentially dumps users into one of three age-range buckets: 18+, 13-17, and under-13. Users under 13 have long been barred from Meta products, but this Settlement creates new obligations to search for and detect users who may have said they were older.
For those estimated to be over-18, the Settlement guarantees no direct benefit to you: no privacy protections, no greater user controls for your own accounts, no dent in Meta’s surveillance capitalism.
Those estimated to be 13-17 years old will be limited to Teen User accounts.
Those estimated to be under-13 will lose their accounts altogether.
Those who open new accounts will have two weeks to submit to age estimation, and if they decline to do so, Meta is now required to treat them as a Teen User by default, even if they self-identify as being 18 and older. [P. 18, §II.A.10.b]
(b) Fourteen (14) days or more after creating a Meta SMP account, Meta SMP users who have not yet had their age assessed by an Age Assurance Method pursuant to the Age Assurance Framework shall be treated as Teen Users for the purposes of this Agreement regardless of their stated age, except that Meta SMP users with a stated age of 18 years old or older shall receive the protections described in Section II.A.10.a.ii.
What about people with existing accounts, who are well past that two-week period to submit to age estimation? Will they also be defaulted to Teen User status if they decline age estimation? It seems so—the AGs would likely not have accepted a settlement that did not require Meta to take action against existing teen users who choose to forgo the age assurance process. Perhaps Meta will use its existing store of information about its current users as a type of permitted proprietary age assurance process? Thus, perhaps, an adult user whose Facebook account is itself older than 18 will be assessed as being over-18? Or a user who is identified as the spouse of a user who has been age-assured? But Meta can only rely on a proprietary process if it meets the accuracy standards set out in the Settlement Agreement.
How accurate does the age assurance process need to be?
The Settlement sets maximum false positive for both commercially available and proprietary age assurance methods [Pages 12-13, §II.A.6]. Within two years, each shall be no more 10% for ages 16-17 and 3% for ages 13-15.
6. Age Assurance Standards. (a) U18 False Positive Rate Thresholds. (i) Any Commercially Available Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within one year of the Effective Date: 10% for minors aged 16-17 and 3% for minors aged 13-15. (ii) Any Proprietary Age Assurance Methods deployed by Meta for any new and existing users in the Settling States shall meet or fall below the following U18 False Positive Rates excluding method circumvention within 1 and 2 years of the Effective Date: (A) Year 1: Within one year of the Effective Date: 14% for minors aged 16-17 and 7% for minors aged 13-15. (B) Year 2: Within two years of the Effective Date, 10% for minors aged 16-17 and 5% for minors aged 13-15.
Notably, there is no limit indicated in the error rate for false negatives, when the process wrongly identifies an adult as being under 18. The Settlement only requires Meta to maintain an appeal process for users whose age range is wrongly assessed. [P. 17, §II.A.9]
9. Appeals Process. Users claiming to have been mis-identified as minors must be offered a Clear and Conspicuous means to appeal the decision. Decisions on all user appeals must be made in a timely manner and communicated to the user along with a basis for the decision.
The Settlement generally shows little concern for those falsely placed in its Teen User category.
Meta must also employ measures to discourage age estimation circumvention, including placing limits on the number of attempts any user might make. [P. 16, §II.A.7] As part of this, Meta agrees to proactively monitor adult accounts to determine whether a user needs to undergo additional age estimation. [P. 16, §II.A.7.c] This is just one of the ways the Settlement embeds Meta’s active surveillance of its users for the next ten years (see below for more).
(c) Incorporating a proactive monitoring system that requires users to undergo an additional Age Assurance Method where a user is determined, including based on their conduct on Meta SMPs, to have likely circumvented the Age Assurance Method and is: (A) likely a Teen User after having been previously assessed as 18 or older; or (B) likely U13 after having been previously assessed as 13 or older. Users Meta determines are likely Teen Users after having been previously assessed as at least eighteen may choose not to undergo additional age assurance but then will be treated as Teen Users; and
Any age assurance process Meta uses must be tested annually.
Data minimization
The Settlement does have data minimization requirements for the data collected during the age assurance process. [§II.A.8] But there are numerous holes. The Settlement requires that all information obtained and retained as part of the age assurance processes thereafter be “immediately enqueued for deletion, after which it shall be deleted after a reasonable period of time.” But the Settlement defines a category of “Retainable Data” that may be retained for 90 days. This includes “metadata about the age assurance method used by the user information … where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes.” The Settlement requires at that all data collected by Meta or its vendor be stored according to industry-standard data security measures,” a standard that unfortunately does not eliminate the risk of a data breach.
8. Data minimization and security. (a) Except as set forth herein, all data collected by Meta from users of Meta SMPs in the Settling States for the sole purpose of conducting age assurance, all data maintained from known U13s, and all data collected by a vendor for use in a Commercially Available Age Assurance Method shall be held for the minimum period required to determine a user’s age status and thereafter immediately enqueued for deletion, after which it shall be deleted in a reasonable period of time. Meta may retain (1) U13 data only to the extent required for purposes of developing, training, testing, and measuring the performance of the U13 Age Model (“U13 Data”), provided that any U13 data that constitutes Personally Identifiable Information as defined by 16 C.F.R. Part 312.2 will be protected using Meta’s highest data privacy and security standards, and (2) metadata about the age assurance method used by the user information (“Retainable Data”) only where required to ensure the ongoing integrity of age assurance systems, including but not limited to the ability to identify circumvention and related patterns over time, and only for as long as it is required for those purposes. For the avoidance of doubt, U13 Data cannot be used for purposes such as ads targeting and delivery, marketing, or algorithmic optimization efforts. Any U13 Data and Retainable Data shall be maintained at the coarsest viable granularity and cannot be used for any other purpose unless legally required. Any Retainable Data that is no longer required for the purposes set forth herein shall be deleted within 90 days. The terms above shall not pertain to the user’s stated date of birth, stated age, nor the outcome of the Age Assurance Method (e.g., “teen or adult” classification). (b) Data collected by Meta or a vendor, or transmitted by a vendor, must be collected and stored using industry-standard data security measures and as required by law, including encryption in transit and at rest. (c) The Parties agree to discuss in good faith potential modifications to this provision as necessary to permit Meta to improve the efficacy of its Age Assurance Framework while preserving the principles of data minimization and security set forth in this Section.
Restrictions For Teens (And Anyone Who Opts Out of Age-Gating)
Teen User Accounts are subject to time, feature, and content restrictions. These will be applied to these estimated to be 13-17 as well as any new user who declines to submit to the age assurance process and to existing users who decline to submit to age estimation and for whom Meta cannot ascertain that they are older than 17.
Time restrictions
Teen Users will be subject to the following time restrictions (§II.B). These measures seem to assume that most of teen’s social media use is frivolous and unserious (not that those are in and of themselves bad; the right to play is among young people’s human rights), ignoring the fact that teens use social media for school and personal research, conducting activism campaigns, and other endeavors that might naturally not fit within these time limits:
Night Access Mode – no access (except messaging) to Instagram and Facebook from Midnight to 6 AM, and no push notifications from 10 PM – 7 AM.
School mode – no push notifications from 8 AM – 3 PM Monday-Friday from Aug 15-June 15.
Daily cumulative time limit of 2 hours per day across Instagram and Facebook, resetting at midnight, excluding video and audio content at least 22 minutes long, absent artificial prolongation, defined by the Settlement as “longform content.”
“Productive pauses and notices” designed to “reduce or prevent excessive, mindless, or unintended teen usage.” This means that a teen’s usage will be monetarily paused after 60 and 90 minutes of daily cumulative use with notices sent every 15 minutes of continuous use. According to the Settlement, these productive pauses and notices will look like this:
To be clear, the ability to set time limits, blackout times, and scheduled pauses are all useful features that should be available and easy to implement for users of all ages. Such tools would have allowed teens, and all users, the ability to design their own safe experience, customized to their own needs, online. Such users controls would have recognized that teens have human rights, agency, and autonomy.
But that’s not what these restrictions are. They are not tools that give the teen users control. Rather, they are imposed, top-down, on teens and anyone else who declines to submit to Meta’s age assurance process.
Feature restrictions (§II.C-D)
Within four months of the effective date of the Settlement, Meta must offer teens an option for a non-personalized feed, which is defined as a feed of chronologically ordered posts from friends and follows. Teens will also be able to disable autoplay as part of an “optional protective settings” package. Each of these settings must be “viewable within three user gestures and clearly labeled, easy to notice, viewable without scrolling, and discoverable in an intuitive location within” the service.
Again, these would be useful user controls that should be offered to users of all ages.
By default, teens will not see the number of likes or other reactions to their posts.
Teens will also not have access to what the Settlement calls “Cosmetic Procedure Filters,” that is, “any digital filter or augmented reality effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme make-up techniques.
X. “Cosmetic Procedure Filter” shall mean any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques. For the avoidance of doubt, “Cosmetic Procedure Filter” does not include: (1) Fantasy/Character Effects: Filters that change a user’s facial structure for the purpose of turning the user into a non-human or fictional character (e.g., an elf or cartoon) or an animal (e.g., a dragon or puppy); (2) Makeup/Smoothing Effects: Filters that smooth skin or alter appearance in ways that can be achieved by ordinary makeup techniques without altering the appearance of underlying physical facial structure or meaningfully changing skin tone; or (3) Parody and Exaggeration Effects: Effects that entertain users by distorting their appearance through parody, satire, or exaggerated forms (e.g., extreme visual distortions outside the scope of normal cosmetic procedures). To help operationalize this definition, the Settling States will provide Meta illustrative examples and guidance of AR effects that are Cosmetic Procedure Filters and AR effects that are not Cosmetic Procedure Filters in a letter to be sent within two (2) months of the Effective Date.
Meta has already had rules about cosmetic effects directed at teens since 2019. But the Settlement will give the states a major role in helping Meta identify what features are and are not Cosmetic Procedure Filters.
Content restrictions (P.1, §II.E, as defined by §I.C, E, F)
For content, Meta is basically pledging to continue its existing practices limiting Teen Users to age-appropriate content and accounts, to default Teen Users to age-appropriate experiences. This includes limiting access to accounts that “regularly share content that is inappropriate for teens” such as content from the following Meta community standards categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders.
C. “Age Appropriate Experiences” refers to content that is appropriate for Teen Users based on input from experts, parents, and teens. For the purposes of this Agreement, Age Appropriate Experiences shall mean content captured in Meta’s applicable Ages 13+ content setting, which is tied to policies inspired by movie ratings for ages 13+ and parent feedback. D. “Age Assurance Methods” shall have the meaning set forth in Section II. E. “Age Inappropriate Accounts” refers to accounts that regularly share content that is inappropriate for teens or that have account information that otherwise suggests the account is inappropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Accounts shall mean accounts that: (1) regularly share Age Inappropriate Content in the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders, or (2) have account names or profile photos or bios that suggest the account is otherwise inappropriate for minors, based on Meta’s policies for the following categories: Adult Nudity & Sexual Activity, Restricted Goods & Services, Suicide, Self-Harm or Eating Disorders. F. “Age Inappropriate Content” refers to content that is generally perceived by U.S. parents, youth experts, and teens as not being appropriate for Teen Users. For the purposes of this Agreement, Age Inappropriate Content shall mean content prohibited by Meta’s Community Standards concerning bullying and harassment; nudity and sexual activity; child sexual exploitation, abuse, and nudity; sexually explicit language; suicide, self-harm and eating disorders; graphic violence and incitements to violence; gambling; and restricted substances or goods (including illegal drug use), as well as policies specifically focused on protections for Teen Users, including those regarding high-risk viral challenges and risky stunts.
And even more worrisome, even though this is just Meta continuing its existing practices, the Settlement empowers the states to enforce its provisions. [P. 40, §IV.C.1.i; §VII.C] That means that over the next ten years, the duration of the Settlement, Meta will face the threat that a state attorney general will pursue legal action against it because it disagrees with how Meta interprets these categories of community standards, and pressure Meta to eliminate Teen User access to posts about sexuality and reproductive and sexual health. And Meta will now lack the hard-earnedFirst Amendment defenses to make its own curatorial decisions.
C. Notwithstanding anything in Sections VIII.A-B above, a Settling State may take any action, including but not limited to legal action to enforce compliance with the Agreement, without delay if the Settling State believes that a threat to the health or safety of the public requires immediate action.
The Parental Supervision Tradeoff
All of these Teen User restrictions can be modified – but only if the Teen User enrolls in the Parental Supervision that links their account to a parent’s or guardian’s account. Once their accounts are linked, Parents can modify the Teen User settings to make them less restrictive (they need the teen’s permission if they want to make them more restrictive).
And Parental Supervision comes with a huge privacy tradeoff. In exchange for designating someone as their Parent, the Parent gets a lot of information about the Teen’s use: the usernames of all of the teen’s connections, reports on how much time the Teen User spends on a Meta service, the time spent watching longform content, usernames of all those messaging with Teen User, and any evidence Meta has about suspected secondary accounts. The Supervising Parent also gets notices of the teen’s repeated searches related to suicide, self-harm and eating disorders. [P. 28, §II.G]
Parental Supervision 1. Meta agrees to provide Supervising Parents with information concerning the amount of time their Teen User is spending on Meta SMPs, including separately for time on the Meta SMP, time using the Meta SMP’s messaging features, time viewing Longform Content (to the extent excluded from the calculation of daily limits pursuant to Section II.B.3.a.i), and the usernames of the Teen User’s social connections and individuals messaging the Teen User, and usernames of any user reported by a Teen User. In addition, Instagram will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders, and Facebook will notify Supervising Parents should their Teen User engage in repeated searches for terms related to suicide, self-harm, or eating disorders. 2. For Teen Users, Supervising Parents will be notified on a daily basis when the Teen User communicates directly with each adult user for the first time with the Teen User and shall provide a link to the adult user’s profile to provide information such as their stated hometown or city or mutual connections, to the extent the information is publicly available. 3. Upon a Teen User enrolling Parental Supervision, Meta SMPs shall prompt the Supervising Parent to review their Teen User’s settings to consider making updates to support how their Teen User spends their time on Meta SMPs. Meta shall not preselect, recommend, or encourage settings to Supervising Parents that are less restrictive than the default settings in this Agreement. 4. Meta SMPs will periodically suggest checkups for Supervising Parents to do with their Teen Users to evaluate their settings and usage. 5. Meta SMPs agree to continue to take steps designed to encourage enrollment in their Parental Supervision tools. 6. If a Teen User is enrolled in Parental Supervision, Meta shall notify the Supervising Parent if the Teen User creates or explicitly links a new secondary Meta SMP account within their Accounts Center or has been linked to a Soft Matched Account through Meta SMPs, including a link to the secondary account’s profile. Meta SMPs shall automatically apply the Supervising Parent’s approved time management settings in Section II.B and content restrictions to all explicitly linked Meta SMP accounts and all Supervised Accounts for a Teen User belonging to the same Meta SMP.
Unfortunately, Meta doesn’t have a great way to learn whether there exists a genuine parent-Teen User relationship. But it will try to get it right. [§II.G.8]
This may be workable for young people with healthy and safe relationships with their parent or guardian. But obviously not good at all for a Teen User lacking such a safe relationship.
More Surveillance, Not Less
Moreover, rather than pushing Meta away from the collection, analysis, and retention of user data, the Settlement requires Meta to do more of it for the next ten years. Several provisions of the Settlement require Meta to carefully track its users use of Instagram and Facebook for the purposes of determining whether its age assurance framework and Teen User restrictions are working as intended.
For example:
Meta promises to review detected U13 users’ friend networks to identify other possible U13 users. [§II.A.6.(b).(i).(D)]
Meta will incorporate a “proactive monitoring system” to identify possible Teen Users among those who were initially determined to be older than 17 by its age assurance process. [§II.7.(c)]
Meta pledges to utilize and improve its existing “soft matching models” that track signals such as device IDs, phone numbers, and email addresses” to identify duplicate accounts. [§II.B.6.(a)]
Meta will continue to monitor Teen Users’ activity to “regularly evaluate the prevalence of Teen User exposure to Age Inappropriate Content, and Teen User exposure to experiences that are not Age Appropriate Experiences,” [§II.E.3] and also to “regularly evaluate the prevalence of Teen User exposure to Harmful Experiences on Meta SMPs.” [§II.F.3]
Monitor Teen Users’ messaging to identify message threads with potentially suspicious accounts. [§II.F.4]
The Settlement also requires Meta to actively monitor use of its services so that it can supply data to the Independent Auditor that will now monitor its compliance with the Settlement. “The Independent Auditor is entitled to access the non-privileged information, personnel, systems, and records that are reasonably relevant and sufficient to evaluate Meta’s implementation of the Injunctive Relief Terms, including, but not limited to, access to raw data; aggregated data; information; internal documents and communications” plus information from its age assurance processes, data regarding Teen User responses to the Productive Pauses, data regarding its models for soft matching of secondary accounts, data regarding the prevalence of Teen User exposure to Age Inappropriate Content and Harmful Experiences, and to experiences that are not Age Appropriate Experiences. [§III.E]
Moreover, one of the chief threats of Meta’ surveillance is the honeypot of data it creates that may be accessible to governments for law enforcement and other investigations. Nowhere in the Settlement do the 52 attorneys general pledge to not try to access all of the data the Settlement requires Meta to collect and retain.
Meta Has To Pay The States — Establishing Norms Beyond Meta
The Settlement also includes annual payments from Meta to the states, apparently proportionate to the size of each state’s teen user base. Over the ten year-life of the Settlement, these annual payments will total over $11 billion plus the prospect of an additional $5 billion—if Meta competitors adopt the same measures.
This quirk of the Settlement incentivizes the States to pursue similar age assurance processes and at-least-as-restrictive teen user measures for Meta’s chief existing competitors for teen use, YouTube, TikTok, and Snap, and for any new service that may gain widespread teen use over the life of the Settlement Agreement. If the states are able to get Meta’s competitors to adopt the same measures, then the states will get an additional $5 billion in annual payments. That’s quite the incentive for the states to pursue litigation and regulatory measures against those companies. All of this will further entrench age assurance and age-gating as the norm across online services.
1. In the event the Contingent Monetary Payment Trigger has occurred in a Settling State, Meta shall be obligated to pay to such Settling State ten equal installments in the amount as set out in Exhibit B (each, a “Contingency Installment Payment”).
2. Following the date the Contingent Monetary Payment Trigger has occurred, the Contingency Installment Payments shall be made to the Settling State on January 15 in each subsequent calendar year of the Agreement Term as follows:
(a) At the next scheduled payment date, the Settling State shall be paid the Contingency Installment Payment for that payment date and all prior payment dates. (b) For each of the remaining payment dates, the Settling State will be paid the Contingency Installment Payment for that payment date.
3. If a Settling State fails to achieve the Contingent Monetary Payment Trigger during the Agreement Term, the Contingency Installment Payments shall be permanently forfeited by such Settling State and retained by Meta. For the avoidance of doubt, no Settling State will have an obligation to repay the Contingency Payment
The Settlement is thus a bad deal for all users of Facebook and Instagram. It normalizes age gating and age assurance for millions of internet users. It denies teens the tools to create their own safe experiences online and places their social media experience firmly under the control of either Meta or their parents. And rather than addressing Meta’s collection, analysis, and retention of data about teens’ use of Instagram and Facebook, it binds Meta to continued surveillance.
This was inevitable. ICE has billions of new money to spend, zero shame, and not a single adult in a leadership position capable (or willing!) to talk the agency off the ledge.
ICE decided the neat new tool of cruelty it absolutely had to have were gloves that behave like stun guns or low-powered Tasers. Only one company makes these: Compliant Technologies. There’s a reason for that. Prior to ICE’s devolution during Trump’s second term, no agency of any size really had any reason to buy these stun gloves.
Early adopters were prisons and (wtaf) schools. These gloves made limited sense in prisons where guards are working in confined areas and possibly don’t want to utilize any weapon that might be taken away and used against them. Why they’re being used in schools is literally unimaginable. But here we are in the 21st century, witnessing schools pleading with law enforcement agencies to stop shocking their students with Compliant Technologies G.L.O.V.E., or (brace yourself) Generated Low Output Voltage Emitter, which sounds more like an electrician’s tool than something capable of rendering minors immobile.
With only one provider available, the decision was easy. ICE finalized its threatened purchase of 6,000 G.L.O.V.E.s from Compliant Technologies late last week, ensuring officers will have even more ways to inflict pain on thousands of non-criminals, ranging from ambushed migrants to peaceful protesters who have managed to momentarily inconvenience ICE’s kidnapping squads.
“ICE does not currently have an empty hand use of force device to provide to the field amidst unprecedented levels of threats and violence against ICE officers and agents to help ensure they can de-escalate tense situations before they turn violent,” the agency wrote in procurement documents.
WTF? Do you know who else doesn’t have “empty hand use of force devices?” 99.999% of US law enforcement agencies, including federal agencies that generally face more legitimate danger from arrestees, like the FBI, ATF, and Secret Service. And do you know why? Because it’s an absolutely psychopathic use of force “option.”
Somehow, it’s ICE that desperately needs this hideous option, even though all it’s really doing at this point is doing migrant mop-up work — arresting migrants by the thousands despite almost none of these remaining migrants having ever been arrested, much less convicted, for violent crimes.
The procurement document [PDF] contains more supporting statements from ICE that make it clear these gloves aren’t really meant to help subdue violent arrestees. The gloves are being purchased to give ICE officers the means and the opportunity to basically stun anyone they run into, including people they aren’t even seeking to arrest. This paragraph suggests stun gloves are nothing more than a violent way for ICE officers to “de-stress” while at work:
ICE requires a non-lethal, de-escalation device intended to diffuse situations of high-stress environments where physical altercations are likely, such as field domestic disputes or inmate transport in jails. It will be used when a subject is actively or passively resisting and an officer needs to gain control quickly to prevent injuries to both parties.
The document doesn’t explain what the phrase “field domestic dispute” means, nor does it provide context. Reading “domestic dispute” in its usual context, the sentence seems to suggest officers should be able to stun their domestic partners into compliance when things at home get a bit heated. Obviously that’s not what that phrase means, but it’s an extremely weird grouping of words that seems to be specific to ICE and its desire for gloves that can shock people.
Further down, ICE makes it clear it’s going to allow officers to deploy the gloves against peaceful protesters or anyone else who might be considered an obstacle to officers’ kidnapping plans.
“Soft” Empty-Hand Control- Enabling officers to briefly distract a subject who is resisting or hiding their hands to secure handcuffs without transitioning to higher, more forceful levels of control.
Civil Disturbance- Assisting crowd control units in moving groups or denying access to areas without requiring lethal or high-impact munitions.
ICE makes it sound like its officers will stop shooting or beating people because of these gloves. But I can guarantee you the gloves will be used whenever possible, especially when they might facilitate a beating. Since pretty much every ICE officer wears gloves, it will be impossible to tell who’s wearing the stun version and who’s just trying to look like a Call of Duty lobby idle animation. Officers are absolutely going to love these gloves because the element of surprise will always be on their side.
There’s no way ICE seriously believes 6,000 pairs of hand-worn cruelty application devices will actually limit the use of deadly force. But it can probably assume it might reduces shootings because its thousands of under-trained officers will probably be less willing to grab a metal gun from near their waist when they’re not sure whether or not their G.L.O.V.E.s are still activated.
This is just a way for ICE officers to hurt more people while pretending stunning anyone an officer touches is synonymous with de-escalation. This is just an agency loaded from top to bottom with sadists seeking out novel ways to inflict more pain.
Even as Donald Trump regularly uses mail-in ballots himself, he has decided that mail-in ballots are a system by which voting fraud occurs. To be quite clear, this is bullshit. There is astoundingly little evidence of significant voter fraud, and that’s equally true between in-person and voting-by-mail. And there’s zero evidence that mail-in voter fraud has ever even come close to swinging a federal election. Indeed, what little voter fraud there is often involves mixups of people who thought they were eligible to vote accidentally trying to vote when they were ineligible.
Either way, a few years back, Trump started blaming mail-in ballots for the completely mythological “rigged elections” he keeps insisting are happening, and of course the MAGA establishment quickly fell into line. We just recently wrote about how the Fifth Circuit appeals court has been working overtime to pretend that it’s well-established that mail-in ballots are insecure. But the bigger issue is that earlier this year, Trump issued an executive order to try to limit the use of mail-in ballots.
Specifically, the executive order tells the US Postal Service to engage in a “rulemaking” that is designed to make it much more difficult for states to offer mail-in ballots. And, on top of that, it demands that states that offer mail-in ballots must hand over their voter rolls to the federal government. The White House has been demanding voter rolls from a bunch of states, and so far every state that has engaged in litigation over this issue has won (it’s now over 20 cases, all of which have gone against the administration).
On its face, the executive order should be seen as pure nonsense, given that the states get to run elections, not the federal government. And even if it were the federal government, that’s not what executive orders are for. But given that the same Supreme Court that insisted no Democratic president could do literally anything without explicit congressional approval now treats Donald Trump as the very special birthday boy who gets whatever he asks for, we have to take even his most ridiculous demands seriously.
A district court judge, Indira Talwani, who is overseeing two of the cases challenging that executive order has issued injunctions in both cases, blocking the US government from putting it into effect. As Talwani notes, the states get to determine how their elections are run, per the Constitution.
Article I of the Constitution alsoempowers the States to prescribe the “Times, Places, and Manner of holding” congressional elections.U.S. CONST. art. I, § 4, cl. 1. “[T]hese comprehensive words embrace authority to provide a complete code for congressional elections, not only as to times and places, but in relation to notices, registration, supervision of voting, protection of voters, prevention of fraud and corrupt practices, counting of votes” among other issues. Smiley v. Holm, 285 U.S. 355, 366 (1932).
The President is elected by vote of the Electoral College. See U.S. CONST. amend. XII. The Electors Clause empowers each State to appoint electors to the Electoral College “in such Manner as the Legislature thereof may direct.” U.S. CONST. art. II, § 1, cl. 2. The States require their electors be appointed by popular vote of qualified voters. See Chiafalo v. Washington, 591 U.S. 578, 584 (2020).Accordingly, the States alone determine voter-eligibility requirements, subject only to the outer limits of the Constitution. See, e.g., U.S. CONST. amend. XIX (“The right of citizens of the United States to vote shall not be denied or abridged . . . on account of sex.”); U.S. CONST. amend. XXVI (“The right of citizens of the United States, who are eighteen years of age or older, to vote, shall not be denied or abridged . . . on account of age.”). For presidential elections, the Electors Clause gives States the primary authority to decide how electors are chosen.
As a result, the court ordered (among other things) the USPS to not take any steps to implement the executive order.
Furthermore, in the latter injunction, Talwani pointed out that the federal government failed to present literally any evidence of mail-in voting fraud:
The record is devoid of any declarations or other proffered evidence to suggest that mailin voting has resulted in voting by non-citizens.
In other words — the DOJ, despite the president insisting that non-citizen voting was happening all the time with mail-in ballots — didn’t even try to present evidence of that to the judge.
But this week, a USPS whistleblower revealed that the Postal Service has been building the machinery to implement the order anyway — issuing a final rule on August 26 and, per the disclosure, restarting development around July 29 even though the very clear injunction against doing anything was still in force. The whistleblower went to Senator Richard Blumenthal who released the whistleblower’s report, along with a letter to the Postmaster General demanding an explanation.
My office is in receipt of an alarming whistleblower disclosure (the “Disclosure”) outlining the United States Postal Service’s (“USPS”) perilously rushed and potentially unlawful implementation of President Trump’s Executive Order seeking to restrict mail-in voting. The whistleblower’s allegations make clear that USPS lacks the technical or operational capability needed to effectively implement the EO’s provisions in a way that safeguards every citizen’s right to vote in the upcoming midterm elections. Despite this, the Trump Administration appears intent on USPS moving forward with its flawed plans, no matter the chaos they may create. The whistleblower’s allegations also provide disturbing information suggesting that USPS may have violated a court order by continuing to implement the EO despite being ordered to cease all such work. We urge you to abandon this ill-conceived, unconscionable plan and ensure that all Americans can exercise their constitutional right to vote, including by mail, without interference by USPS.
The USPS’s defiance of the court order here is pretty direct. The judge issued an injunction on Section 3 of the executive order on June 25th. USPS did, in fact, stop work on the portal, while the DOJ appealed. On July 25th, the appeals court upheld the injunction, noting that the executive order “directs unprecedented levels of involvement by federal officials in how states administer elections.”
But just four days later, on July 29th, the whistleblower says that USPS leadership told the IT team to start building a tool to enforce the executive order, in direct and obvious defiance of the injunction against it. Then on August 11th, the district court expanded the injunction, which should have made it even clearer to USPS to stop. But USPS appears to have completely ignored that. While the Supreme Court put a stay on the injunction on August 24th, two days later the district court issued a temporary restraining order. But it appears that basically none of that mattered, as USPS leadership had the IT team continue to work on the thing they were explicitly barred by multiple courts to do.
As Blumenthal’s letter summarizes, the USPS rushed to build a portal whose main job appeared to be to block the mailing of mail-in ballots to voters (i.e., this is not them swiping already completed ballots, just refusing to send them to voters in the first place). And because USPS is now run by people whose main qualification is loyalty to Donald Trump, the execution is exactly as incompetent and slapdash as you’d expect:
The whistleblower’s Disclosure describes an unprecedented process that allows USPS to decide whether ballots issued by state election officials should be mailed. To do so, USPS is building an entirely new online system, the USPS Federal Ballot Mail Portal and related IT systems (the “Portal”), which will be used to screen ballots submitted by state election officials prior to USPS agreeing to mail them to voters. The Disclosure identifies problems at every stage of USPS’s development of the Portal, demonstrating deeply flawed plans for implementation. According to the whistleblower, USPS’s effort to develop and deploy the Portal has been “rushed,” “risky and haphazard” because leadership has demanded an impossible timeframe. In an effort to meet impossible deadlines, USPS has eliminated standard and needed testing, thereby creating substantial risk of a “catastrophic failure” of the system that could “derail the midterm elections.”
What could possibly go wrong:
USPS began work building the Portal on or around June 15, 2026 just three months before the date USPS planned to launch the system and just five months before the November 2026 midterm elections. On or about June 25, 2026, USPS ordered work on the Portal to cease due to a court order enjoining implementation of the EO. That work stoppage persisted for approximately a month, further reducing the time that USPS had to build the new system. According to the whistleblower, building the information technology infrastructure necessary to complete the Portal could take a year or more. Yet, USPS leadership demanded that the Portal be completed for a launch date of September 1, 2026, less than six months after the EO was issued. As a result of this rushed process, USPS has been unable to conduct tests of the Portal to ensure its proper functioning, troubleshoot problems, or distribute instructions on use to state election officials. According to the whistleblower, the Portal “violates standard principles of testing and debugging new software before launch.” Normal procedures at USPS for such systems include internal testing, customer acceptance testing, and a final development stage before release to public facing users. The Portal has gone through none of these basic checks.
Going beyond just Blumenthal’s summary, the actual whistleblower report has some astounding details about how the bosses at USPS working on this seem to have no clue how to build reliable software (one wonders if they’re ex-DOGE folks):
Throughout the development of the project, those giving guidance to tech developers lacked understanding of project parameters. Different team members continued to have different understandings of how the system is supposed to function which caused ongoing and greater confusion among the group.
While there continued to be no clear written requirements for the software and IT system, those developing the new election ballot mail IT system were placed in the position of trying to glean requirements from opaque comments at meetings. It continued to be clear that those giving directions did not understand exactly what was to be built. There was a growing concern that many were grasping at straws, trying to do their best to decipher cryptic instructions, and likely missing important details. Elements as basic to the project as whether a validation issue was a “warning” or an “error” continued to be unclear as leadership provided inaccurate information about these issues. To clarify, a warning allows a ballot to continue through the process while an error stops it. These occurrences reinforced the need for written requirements and the ongoing failures in communication.
Even so, the team was told that the system had to be ready to launch… by yesterday. They were given less than a month to figure it out. If you know anything about software development, project management, or… just about how anything works, these paragraphs are concerning:
Around this time at least one senior USPS official seemed to up the stakes by becoming a more active voice pushing for project completion on the new deadline. For example, when IT workers expressed concerns about the quality of the product under USPS leadership’s compressed timeline, the senior official stated that they (the official) “were not trying to stop anyone from getting their ballots and what is the problem?” Employees went on to reiterate concerns that many teams were still missing details of how systems were supposed to work and that written requirements could ensure that everyone was on the same page. The senior official was dismissive of these concerns. The conversation continued with others repeating the need for clear requirements; while leadership insisted that it was easy to understand what was needed and also that there was no time to write down the requirements. The contradiction was obvious that it should not take a great deal of time to write down something that is easily understood.
Concern continued to grow and the Whistleblower became aware that IT teams referred to the largely oral requirements as a “moving target.”
By the third week in August “user stories” – short, plain-language descriptions of a software feature written from the perspective of an end-user (focused on what a user wants to achieve and why) – were described as unusable “garbage”. User stories that had been generated had incorrect information and needed to be updated.
Throughout this project, the Whistleblower understood that IT teams were siloed and not communicating with one another. Teams had so little understanding what other teams were working on such that when elements were brought together, the teams were unaware of various developments, creating more work to utilize even the completed portions of the work.
By August 20, there was a massive rush as teams tried to get “everything committed” – in order to meet the goal of getting the ballot mail systems ready for customer testing on August 24. The resulting chaos caused work to be overwritten. By this point IT workers were resigned that even if they could get the portal put together and working in the internal development environment, there would not be enough time to test and fix any issue that would inevitably arise in customer testing.
The system was designated a grand total of four (FOUR!) days of user testing (and it’s not even clear if the testing actually happened):
By August 24 the expectation was that if somehow everything was accomplished on Monday the 24th, the code would end up in internal testing on Tuesday, August 25, then move to customer testing on Wednesday, August 26 allowing only four work days to test. For a system that manages something as important as handling voting and ballots, 4 days of user testing is entirely unreasonable. Only leadership seemed to express hope that the September 1 deadline was viable. If a problem was found during testing, which was almost certain, the IT workers would need to fix it and that fix would need to move back to internal testing and then into customer testing again. If a problem wasn’t found in the first 2 days, the fix could not make it back to the customer testing environment in time to meet the deadline.
In just the week prior to September 1, 2026, the Whistleblower learned that ITworkers have described the election ballot mail development process as “a shit show.”
Very confidence building!
The whistleblower notes that a similar internal tech project that the USPS IT team built in the past “set aside 47 working days for testing.” And this one gets four.
Perhaps an even bigger problem than the slapdash hand-wavey “build a complex system in weeks with no written requirements, and no time for testing,” was the demand for a “zero percent failure rate.” That means that if a single barcode won’t scan — whether because of bad connectivity or a voter got married and changed their name — USPS bounces the entire batch back to the state. And these batches can run to tens of thousands of ballots. Back to Blumenthal’s summary:
Not only is this system astonishingly untested, USPS has simultaneously implemented an impracticable zero percent failure rate. When ballots are submitted to USPS in large-volume batches, if any one ballot in the batch cannot be verified against the Portal, all ballots in that batch will be rejected. For example, if a state election official brings a batch of 10,000 ballots to USPS and USPS is unable to match just one of those ballots against the Portal – because, for example, someone has recently changed their name after marriage or they’ve moved – then USPS would refuse to mail the remaining 9,999 ballots as well. As the whistleblower notes, “USPS expects the state to take back the entire batch to cure the issue with the single ballot…” Should the slapdash Portal mistakenly mark a ballot as unverified, there is no clear process by which state election officials or voters themselves can challenge the rejection. The Rule simply vaguely states that they “will be informed of the escalation procedures should they decide to challenge a rejection.” Voters intending to cast ballots by mail may not even be aware that their ballots have been rejected, or were part of a rejected batch, until it is too late to secure an alternative ballot or vote in person. Expecting a well-built, thoughtful Portal to return an accurate result 100 percent of the time is already a stretch—expecting a “rushed,” “risky and haphazard” Portal to do the same is a recipe for disaster.
A zero percent failure rate means that a single bad scan (which could happen for any reason) could block thousands of ballots (literally all of which could be legit and fine) from being sent out. Given that eight states already run elections entirely by mail, this could mean significant percentages of voters just not receiving their ballots at all.
And, we’re relying on a hastily built system with barely any testing not to have any bad scans that lead to thousands of ballots being blocked.
Of course, what Blumenthal and the whistleblower call “risky and haphazard” most others might call “deliberately designed to suppress votes and create chaos that will allow MAGA to call into question the validity of an election.”
Look, this is just terrifying: the president and his administration are building a system designed to guarantee that fewer people receive their ballots, in a manner designed to create obvious chaos around an election they don’t expect to win. Whatever you want to call the intent, that’s an executive branch actively degrading the machinery of free and fair elections.
That should be the biggest story in the country.
Donald Trump has made it abundantly clear that he thinks the federal government works for him, and him alone. It does not. It works for the American people, and a court has already told USPS exactly that, twice. One postal employee understood the assignment well enough to risk their job and blow the whistle over it. It’s about time that more started to do so as well.
The Adobe Graphic Design Bundle has 3 courses designed to help you learn the essentials of graphic design and how to apply those skills to your projects. Courses cover Photoshop, Illustrator, and InDesign. You’ll learn all aspects of the design process. It’s on sale for $50.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.