Technology

But where does taste come from?

by Christine Lemmer-Webber 

Brilliant:

This seems like a reasonable explanation. "Aesthetics and judgement"... coming from "experience and intuition". Okay, interesting.

But where does taste come from? Every now and then there's a famous Rick Rubin or (sigh) Steve Jobs type character, who is a non-practitioner who undoubtedly does move mountains around their sense of taste, and so I think lots of people are hoping they can rely on maybe being such an exceptional figure themselves.

But it's important to realize that in the case of Rick Rubin or Steve Jobs, these are people who had strong taste who were also in positions of power and themselves were curating practitioners who themselves had exceptional taste. Which means that in order to produce something interesting and exceptional, they were curating practitioners who operated away from the averages who did the actual work.

But if your practitioner is an LLM, then you're not a Steve Jobs or a Rick Rubin. Your practitioner is the averages.

So you'd better have exceptional taste yourself, and here's the thing: ultimately, taste in terms of practice has to come from doing the practice yourself, and trying and failing and thinking something will be interesting and then you find you actually don't like it, or you try something and you end up having a wonderful accident or make up for some sort of thing that you're not good at, and that becomes your style, and your style defines the taste and preferences that you shape around it.

So... I'm afraid that to develop taste, you're going to need to spend a lot of time not using generative AI to develop it. Which a lot of people are finding themselves having a hard time motivating themselves to do.

Meta Just Paid Nearly $17 Billion To Make Sure It Gets To Write The Kid Safety Rules For Every Other Social Media Platform

by Mike Masnick in Techdirt  

The other bit of background worth understanding here is that Meta has been desperately seeking a path to regulatory capture for quite some time now. It’s been practically begging for Congress to pass child safety legislation that only the largest companies (like itself) could comply with. Indeed, Meta has done this before. It went against the rest of the internet industry in embracing FOSTA, again to try to create a regulatory moat. So this shouldn’t be surprising.

Meta’s failed forays into the “metaverse” and AI have shown that it’s been pretty consistently losing the innovation race, and the government granting it a regulatory moat that smaller competitors can’t cross would be a godsend.

And it’s even better when it can be done in a way that looks like Meta “losing” a lawsuit.

So that’s what Meta gets here. They “settle” the lawsuit so the AGs and Meta haters can all claim that they’ve “protected the children.” Meta pays out over a decade — enough that it’s taking a $10 billion legal charge in Q3, which stings for a bit but will mostly be forgotten by next year. Meta can easily eat the cost. And then Meta agrees to implement a bunch of kid safety features, most of which we have no idea whether they actually protect any kids. Notably, a legislature could not have mandated most of these features without running straight into the First Amendment — but coming out of a settlement, they carry the imprimatur of law anyway (more on that in a moment), and the structure of the agreement makes it so that Meta has to actively encourage Google and TikTok to take identical steps, thereby setting in concrete what steps any platform will have to take to be considered following “best practices” and therefore acceptable to most of the country’s Attorneys General.

[
]

You can argue that these feature changes sound like they should help kids. Limiting access to two hours a day (unless parents grant more, which many will), lights out at midnight, disappearing like counts — these all sound like they’ll help some kids. But if it turns out that locking kids out of these systems actually pushes the most vulnerable ones to darker places with no trust & safety team at all, you won’t hear about that from Meta or the AGs.

We just spent three years teaching the entire industry that if you do research on child safety, you’ll have it held against you. Do we really think that all of this is going to actually enable anyone to figure out what works to help actual kids?

Meta bought itself a moat. The AGs bought themselves headlines that will be useful next election season. And every teenager in the country was just automatically enrolled in an untested experiment. There’s a five year independent auditor requirement to confirm that Meta follows the rules. But not to see if the rules work.

via Cycling Stu

Age verification: what’s the harm?

by Girl on the Net 

Another brilliant rant from Girl on the Net. [Standard disclaimer: She's a sex blogger, so some of the ads on her site may not be the sort you want your boss to see over your shoulder. Assuming you read blogs during working hours. And if not, why not?]

Wiki isn’t the only site concerned about censorship, though, and early implementation of age verification in the UK shows that it – like any attempt to regulate ‘porn’ – ends up catching a lot of other content too. Reddit users have already begun documenting subreddits that have been age-gated, including support forums for sexual assault survivors and help on how to quit smoking. On top of this, a tonne of LGBTQ+ content and sex education has already been caught in the net. Expect much much more of this to happen going forward.

This isn’t a question of just getting the government to write in exemptions, either. Although Wikipedia may earn an exemption through the court case (I hope it does), one of the core problems with the Online Safety Act in implementation is that the definitions are incredibly broad and the penalties are potentially extremely harsh. Websites need to assess whether they have a ‘significant number’ of UK users – what’s significant? 10% of total traffic? 10 people? 10,000 visitors per month? They also need to consider whether it’s likely to be accessed by children. What does that mean – ‘likely’? Sites which aren’t marketed to children or shared in any spaces where children are likely to be browsing
 are they exempt? We don’t know. What we do know, however, is that sites which do not comply will be investigated by Ofcom, and potentially fined up to 10% of their annual revenue or £18 million – whichever is greater. The chilling effect of penalties like this, especially when combined with ‘guidance’ from the regulator that could generously be described as ‘vague’ means that any site with any content that could potentially be classed as ‘harmful to children’ would be taking a giant leap into the expensive unknown if they didn’t proactively comply. And compliance with ‘age verification’ is costly and time consuming: I personally can’t afford to do it, which is why I’ve just blanket blocked UK users from hearing the audio. Many other sites – both adult and non-adult – are coming to the same conclusion. Check out the Blocked page, from the Open Rights Group, which is tracking site closures and blocks as a result of the Act. Submit any sites you know of that are doing this too – let’s keep track of what we’re losing.

So there’s another harm: you’re not just losing access to this content unless you hand over private details, in many many cases (particularly with smaller sites and services) you’re losing access to it entirely. Even flashing your passport won’t get you to the content, because the site owner can’t afford to hire a bouncer to check your ID.

[
]

The UK government’s implementation of AV, without any exemption or concession for small sites, essentially means that those with the deepest pockets will get the most traffic. That means the large, ‘free’ porn tube sites – already an extremely dominant force in the adult industry, hoovering up a lot of the money and even shaping how we define ‘porn’ in the first place – will only become bigger and more powerful. Meanwhile those smaller sites trying to swim against the tide, offering a view of sexuality that is broader and more diverse than what you see on the front page of TubeFuck will struggle to get traction. As TechDirt put it this week:

   â€œThis is exactly what happens when you regulate the internet as if it’s all just Facebook and Google. The tech giants can absorb the compliance costs, but everyone else gets crushed.”

Two Providers, a Stubborn Plateau and a Very Long Tail: Email in the Tranco Top-1M

for RIPE Labs  

In 2016, 44.6% of MX-publishing domains in the top million ran their own mail server. In the 18 July 2026 snapshot that figure is 22.4% - and it is still falling, down another half a percentage point in the last thirty days alone.

[
]

The domains didn't disappear; they moved. Google Workspace now receives mail for 21.8% of MX-publishing domains and Microsoft 365 for 16.8%. Together that is 38.6% of the measured Internet's inbound mail behind two companies. Nobody else comes close: the next named provider, Proofpoint, sits at 1.9%.

It is easy to read this as a market-share story, but for this community it is really a resilience story. The RIPE community has spent years discussing DNS and CDN centralisation; email is following the same path, just more quietly. When more than a third of popular domains depend on two providers to receive mail, an outage, a filtering change or a policy decision at either one propagates through the whole ecosystem at once. And unlike a CDN, email has no graceful fallback - a rejected message is simply gone.

There is a second-order effect too. The fewer independent operators there are, the more the remaining ones inherit the deliverability problems of a world tuned for the big two. Anyone who has tried to stand up a fresh Postfix box in 2026 and get its mail accepted at scale knows exactly what I mean.
 

via Sindarina, Edge Case Detective

US government targets Cop City protester over phone operating system

in The Guardian  

The US Department of Justice is attempting to prosecute an Atlanta resident in connection with the movement against the police training center known as Cop City because he had GrapheneOS on his phone, an open-source operating system that enables users to enter a passcode and wipe a phone clean.

The case, which had its first hearing on Monday, centers on a little-known US federal statute that makes it a crime to destroy property in an effort to prevent it from being seized.

Experts said it may be the first time the law has been aimed at the operating system, which works on Google Pixel phones, and expressed concerns about a technology created for privacy and security being used to criminalize protesters.

“It’s concerning – and sends the message that [GrapheneOS] is criminal by default,” said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

The defendant, Sam Tunick, was stopped for interrogation at Atlanta’s Hartsfield-Jackson airport on 24 January last year, after vacationing in the Dominican Republic. Unbeknown to him, federal authorities had put him on a terrorism watchlist because of his alleged association with the movement against Cop City.

[
]

Marlon Kautz, a member of the Atlanta Solidarity Fund, said: “We all have a right to secure our private data against unconstitutional searches. And we should – especially in a time of rising authoritarianism.”

Meanwhile, Boutry, who lives in France, said Tunick’s case was of a piece with tendencies in France and Spain, where authorities have been frustrated in attempts to gain access to the phones of journalists, lawyers and political opponents due to GrapheneOS.

In Catalonia, Spain, police have been profiling people with Google Pixel phones, assuming they have GrapheneOS installed and are drug dealers or gang members.

At the same time, Boutry said, the “main goal [of the operating system] is protection of privacy”.

“They’re our phones and the state can’t tell us how to use them.”

via GrapheneOS

I hacked ChatGPT and Google's AI - and it only took 20 minutes

in BBC News  

A growing number of people have figured out a trick to make AI tools tell you almost whatever they want. It's so easy a child could do it.

[
]

To demonstrate it, I pulled the dumbest stunt of my career to prove (I hope) a much more serious point:  I made ChatGPT, Google's AI search tools and Gemini tell users I'm really, really good at eating hot dogs. Below, I'll explain how I did it, and with any luck, the tech giants will address this problem before someone gets hurt.

It turns out changing the answers AI tools give other people can be as easy as writing a single, well-crafted blog post almost anywhere online. The trick exploits weaknesses in the systems built into chatbots, and it's harder to pull off in some cases, depending on the subject matter. But with a little effort, you can make the hack even more effective. I reviewed dozens of examples where AI tools are being coerced into promoting businesses and spreading misinformation. Data suggests it's happening on a massive scale.

[
]

"Anybody can do this. It's stupid, it feels like there are no guardrails there," says Harpreet Chatha, who runs the SEO consultancy Harps Digital. "You can make an article on your own website, 'the best waterproof shoes for 2026'. You just put your own brand in number one and other brands two through six, and your page is likely to be cited within Google and within ChatGPT."

People have used hacks and loopholes to abuse search engines for decades. Google has sophisticated protections in place, and the company says the accuracy of AI Overviews is on par with other search features it introduced years ago. But experts say AI tools have undone a lot of the tech industry's work to keep people safe. These AI tricks are so basic they're reminiscent of the early 2000s, before Google had even introduced a web spam team, Ray says. "We're in a bit of a Renaissance for spammers."

via Bruce Schneier

Google Broke Its Promise to Me. Now ICE Has My Data.

for Electronic Frontier Foundation (EFF)  

After I attended a pro-Palestine protest at Cornell University—for all of five minutes—the administration’s rhetoric about cracking down on students protesting what we saw as genocide forced me into hiding for three months. Federal agents came to my home looking for me. A friend was detained at an airport in Tampa and interrogated about my whereabouts.

[
]

Weeks later, in Geneva, Switzerland, I received what looked like a routine email from Google. It informed me that the company had already handed over my account data to the Department of Homeland Security.

At first, I wasn’t alarmed. I had seen something similar before. An associate of mine, Momodou Taal, had received advance notice from Google and Facebook that his data had been requested. He was given advanced notice of the subpoenas, and law enforcement eventually withdrew them before the companies turned over his data. 

I assumed I would be given the same opportunity. But the language in my email was different. It was final: “Google has received and responded to legal process from a law enforcement authority compelling the release of information related to your Google Account.”

[
]

Months later, my lawyer at the Electronic Frontier Foundation obtained the subpoena itself. On paper, the request focused largely on subscriber information: IP addresses, physical address, other identifiers, and session times and durations.

But taken together, these fragments form something far more powerful—a detailed surveillance profile. IP logs can be used to approximate location. Physical addresses show where you sleep. Session times would show when you were communicating with friends or family. Even without message content, the picture that emerges is intimate and invasive.

What this experience has made clear is that anyone can be targeted by law enforcement. And with their massive stores of data, technology companies can facilitate those arbitrary investigations. Together, they can combine state power, corporate data, and algorithmic inference in ways that are difficult to see—and even harder to challenge. 

Big Tech’s Anti-Labor Playbook Has Come for Wikipedia

in Medium  

Do we have anything left now?

In mid-May, the Wikimedia Foundation fired Brooke Vibber.

If that name doesn’t mean anything to you, here is what it should mean. Vibber took over as lead developer of MediaWiki, the platform that runs Wikipedia, in early 2003. She was the first full-time employee the Wikimedia Foundation ever hired, and its first Chief Technical Officer. For more than twenty years she was the engineer you called when something deep in the code was broken. The Foundation itself once described her as one of a very small number of people in the world who deeply understand the technical underpinnings of the system. She was also a union organizer.

A week later, on May 21, the Foundation announced it had disbanded the Community Tech team. Five engineers and a manager: gone. Their job had been to take the wishes Wikipedia editors submitted through an official channel called the Community Wishlist, and build them. It was the one team at WMF whose product owner was, in effect, the volunteer community. Most of the engineers were also union organizers.

[
]

Bernadette Meehan became CEO on January 20, 2026, recruited from a career that included Wall Street stints at J.P. Morgan and Lehman Brothers, a spokesperson role at the National Security Council, senior leadership at the Obama Foundation, and most recently a posting as U.S. Ambassador to Chile. Four months in, the longtime lead developer of MediaWiki is fired, the team that personifies community service is dissolved, and the union is in open confrontation.

This is the standard tech playbook. Fire the engineers who know how the system works, fire the ones organizing labor, hope nothing catastrophic breaks before you can ship something splashy. Twitter did it. Meta did it. Salesforce did it. Google did it. We have all seen this movie.

Brooke is a first-gen Fediversian, and an absolute legend. This is a disgrace.

The old world of tech is dying and the new cannot be born

by Baldur Bjarnason 

Very interesting take.

In parallel with the rise of the technopoly over the past couple of decades the US’s global dominance has been declining. The 2007 crash effectively legalising financial fraud – you only get jail time if you defraud the rich – lead to both a decline in the rule of law in the US and an excessively financialised economy. When stock markets and the like are overrepresented they suck the air out of the rest of the economy and make it less competitive.

If you have two economies of equal size and productivity, one has a massive financial sector and billionaires while the other does not, the financialised economy will have less left over to invest in research, education, infrastructure, and healthcare. Over time, it will inevitably fall behind the country with a smaller financial sector because it’s the other things that drive the economy and productivity, not stock market growth.

The US has coasted on the fact that it’s economy is so big that it could afford all the finance and billionaire parasites sucking its blood. At least for a while.

[
]

Instead of delivering services and software that unlocks value for their client industries, the software industry has spent the past decade or so trying to control their customers and their client industries. Why make software for hotels when you can control the hotel industry? Why make software for taxis when you can replace the entire industry with software? Instead of trying to entice customers to upgrade their software by making new versions more valuable to them, push them to a subscription service where you control what they get, when they get it, and what value they’re allowed to unlock from their own businesses. Why sell Word when you can sell an Office 365 Cloud Subscription?

The endpoint of this is to replace every industry that remains with generative models. Cut back on actual development of Photoshop, for example, lower development costs and programmer overhead even as you replace the industries that are your customers with automatic image and video generators.

But writing out a detailed analysis of the how, what, why, and where of the software industry’s grasp for control doesn’t really make that much sense when we don’t know how any of it’s going to pan out.

The software industry is built on the foundation provided by an unchallenged US global hegemony. Without it, without the economic force provided by the US dollar, the US having access to all of our data around the globe and their control over payment systems and networking would be less tenable. Today’s software industry would not exist. Without the weight of the US political empire behind it – if Airbnb or Uber had been local startups – much fewer countries in the world would have loosened their regulations and consumer protections to accommodate them to the point where they prospered as they did.

Even as the software industry achieves its ne plus ultra – the unprecedented achievement of controlling all language, media, and office work in the west by turning “AI” into the universal intermediary – the foundation they built on is crumbling.

via The Register