❌

Vue lecture

Our Solar System Is Terminally Unstable and Will Be Completely Destroyed, Study Finds

Our Solar System Is Terminally Unstable and Will Be Completely Destroyed, Study Finds

Welcome back to the Abstract! These are the studies this week that searched for the ur-animals, wandered the poles, rained on Mars, and destroyed the solar system.

First, scientists present new evidence that the first animals appeared more than 800 million years ago, a truly ancient origin that suggests our metazoan ancestors survived a period known as Snowball Earth, when our planet is thought to have been nearly completely frozen. Then: Earth’s poles won’t sit still, the sepulchral stuff of life, and a dramatically shortened lifespan for our solar neighborhood.

As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens, or subscribe to my personal newsletter The BeX Files. 

I trace my ancestry to Snowball Earth

Durbin, Orin Lole et al. “Re-evaluating molecular clock maximum age calibrations revives pre-Ediacaran divergence estimates for animals.” Science Advances.

When did the first animals emerge on Earth? It’s a question that has provoked centuries of scholarly debate, and also inspired some wonderful answers in myth and legend (I’m partial to the Bible’s tidy solution: day six checklist).

The earliest animals that are clearly preserved in the fossil record lived during the Ediacara period some 574 million years ago, but the origins of our diverse metazoan family are likely much older. Now, scientists suggest that animals may have appeared on Earth a whopping 800 million years ago, during the ancient Tonian era, according to a new estimate of the dawn of animals.

“The timing of the origin of animals on Earth has puzzled scientists for centuries,” said researchers led by Orin Lole Durbin who was at the University of Oxford during this research and is now at Virginia Tech. “Unambiguous animal body fossils within the Ediacara Macrobiota provide a hard minimum calibration of 574 [million years] for crown Metazoa. Animals must have evolved before this date. Determining a maximum calibration for animals (a date at which they had not yet evolved) is a more complex task.”

Our Solar System Is Terminally Unstable and Will Be Completely Destroyed, Study Finds

Estimated timeline for the origin of animals based on molecular clock analyses. The grey bar on the right of the image is the origin of animals based on an Ediacaran upper calibration. The grey bar to the left is the origin based on older deposits in the Tonian period, as suggested by the new study. Image: Orin Lole Durbin.

The team turned to molecular clock analysis, a technique that uses the rate of genetic mutations in lineages as a rough way to reconstruct evolutionary timelines. The researchers focused on two fossil deposits—China’s Weng'an Biota and Mongolia’s Kheseen Biota, which date back 590 and 550 million years respectively—to extend the possible timeline of animals back more than 200 million years earlier. 

If animals really did appear in the Tonian era, it means that our earliest metazoan ancestors survived episodes of so-called “Snowball Earth,” when our planet was almost fully covered in ice. These early critters were likely simple marine sponges and comb jellies that lived for hundreds of millions of years until their descendents exploded into the kaleidoscopic variety of animals that persist to this day.

“The possibility of a pre-Ediacaran origin and diversification of animals means we cannot discount hypotheses that link the timing of animal diversification to Cryogenian Snowball Earth glaciations,” according to the study. “The causes and trajectory of animal evolution will remain uncertain until paleontological and geochemical data provide sufficient confidence in maximum calibrations to ensure a reliable timescale.”

In short: Respect your sponge elders.  

In other news…

A pole-ing error

Domeier, Mathew et al. “Quadrupolar sea level fluctuations reveal episodes of rapid polar wander.” Science.

Earth is a roiling mess of shifting continents and squishy innards, a situation that constantly throws its spin axis off balance and prompts the geographic poles to drift. This phenomenon, known as true polar wander (TPW), is distinct from Earth’s wandering magnetic poles, which are shaped by interior core-mantle processes. 

Right now, TPW is clocked at a slow rate of 10 centimeters per year, but scientists have found evidence of “fast” episodes of TPW that pushed the poles off by thousands of miles over millions of years, which has knock-on effects for ocean and land distribution across the globe. 

A team has now pinpointed several of these fast episodes over the past 320 million years, “confirming that protracted rapid TPW has occurred on Earth and that couplings among Earth’s rotational dynamics, mantle processes, and surface environments can be strongly episodic,” according to their study.

“These findings refute the view of TPW as negligible or persistently slow and highlight the need to consider TPW as an episodic control on sea level change and likely other global environmental and biological dynamics,” said researchers led by Mathew Domeier of the University of Oslo. 

In addition to these long-term natural changes, recent human activity has slightly impacted TPW, especially the construction of dams and the glacial melt of anthropogenic climate change. So the next time you address a letter to Santa at the North Pole for your kid—or yourself, no judgement—make sure you have the most up-to-date coordinates.

It’s raining formaldehyde—formalallelujah! 

Koyama, Shungo et al “Global Distribution of Atmospheric Formaldehyde Deposition Correlated with Water Vapor on a Warm Early Mars.” The Planetary Science Journal.

Formaldehyde, the toxic chemical, has a bit of a morbid reputation—exposure to it can be fatal and it’s a common ingredient used to embalm corpses. But, paradoxically, formaldehyde (H2CO) also helped pave the way for the emergence of life on Earth as a precursor of bioessential elements such as sugars, amino acids, and nucleobases.

If life ever flourished on Mars, formaldehyde would likely also have been part of the story. To map out the possible distribution of the chemical on ancient Mars, scientists ran models of its atmosphere between 3.6 and 3.8 billion years ago, when the red planet was warmer and wetter. The results showed that formaldehyde was strongly associated with water vapor, suggesting that the chemical rained down from the ancient skies into Martian waterways.

“Significant atmospheric deposition of H2CO is observed over water bodies, including the northern ocean,” said researchers led by Shungo Koyama of Tohoku University. “We suggest that basins adjacent to persistently humid regions, which likely experienced H2CO accumulation and subsequent organic synthesis, could be potential landing sites for future missions to investigate ancient chemical evolution and whether it led to the origin of life.”

Hopefully, future missions to Mars will leave any signs of life with no place left to formalde-hide. 

Update the cosmic actuary tables

Batygin, Konstantin et al. “Terminal Instability of the Solar System Triggered by Stochastic Solar Mass Loss.” The Astrophysical Journal Letters.

I hate to be the bearer of bad news, but the solar system has been diagnosed with terminal instability and has been given a mere six billion years to live.  

That’s the upshot of a new study that modelled the solar system’s future as the Sun becomes a red giant star and, ultimately, collapses into a stellar husk called a white dwarf. 

Though the dying Sun will consume Mercury, Venus, and perhaps even Earth, scientists have previously assumed that the giant outer planets might be relatively unscathed by its death—perhaps surviving for up to 100 billion years after the main-sequence lights go out. But updated simulations suggest that these distant objects may be thrown into fatal chaos as early as the red giant phase, and that they are unlikely to survive more than a billion years after the Sun’s transition to a white dwarf.

Our Solar System Is Terminally Unstable and Will Be Completely Destroyed, Study Finds
The future of Earth is bright, literally. Image: Celestia

“[Isaac] Newton, contemplating the drifting orbits of Jupiter and Saturn, suspected that the planetary order was mortal, and three centuries of celestial mechanics…have progressively deferred that verdict, most recently to timescales far beyond the age of the Universe,” said researchers led by Konstantin Batygin of the California Institute of Technology. “Our results return the solar system’s dissolution to astrophysically familiar territory, and relocate its cause: not the slow seep of chaos, nor the chance encounter with a passing star, but the Sun itself, which in dying does not merely enlarge the planetary system it built—it shakes it, and more often than not, spills it.”

“Newton’s envisioned instability is real after all,” the team. “He was mistaken only about the perpetrator.”

What a great story to kick off this spooky season! Planetary order is mortal, but cosmic horror is eternal. 

Thanks for reading! See you next week.

  •  

Federal Judge Rules a Flock Search Was ‘Indiscriminate Mass Surveillance’ and Unconstitutional

Federal Judge Rules a Flock Search Was ‘Indiscriminate Mass Surveillance’ and Unconstitutional

A federal judge in Oklahoma ruled Thursday that a police officer violated the Fourth Amendment rights of a woman accused of meth trafficking when he searched her license plate in Flock’s automated license plate reader system simply because her license plate was from California, then used her travel history as part of the reason to search her car. The judge’s opinion is one of the first times a federal judge has decided Flock searches can be unconstitutional, and suggested that Flock’s network is “a type of indiscriminate mass surveillance.”

The officer’s “use of the ALPR Systems was an Unconstitutional Warrantless Search,” and “was not supported by probable cause, and it was done without a warrant in violation of [the defendant’s] Fourth Amendment rights,” the judge, Sara Hill, wrote, implying that the law enforcement officer should have obtained a warrant before searching for the vehicle in Flock’s system. There are currently more than a hundred thousand warrantless searches of the Flock system every month, according to audit logs viewed by 404 Media. Hill's decision will not set a binding precedent and there are several other cases throughout the nation considering the legality of warrantless ALPR searches.

Hill argued that previous judge opinions saying Flock searches were not a Fourth Amendment violation because they track cars in public do not consider the context that Flock’s nationwide network is quickly “approaching dragnet-type law enforcement practice,” and that courts should update their understanding of the technology moving forward. 

The circumstances of the court case are really interesting and highlight how commonplace Flock searches have become for police, and the depth of the information they can reveal. In May, a Tulsa County Deputy Sheriff named Freddie Alaniz was parked along the side of the highway in Oklahoma when he saw a Mazda SUV driven by a woman named Melisa Kyle with a California license plate pass by. “Alaniz then pulled his vehicle on the highway to follow the Mazda for no apparent reason other than the fact that it had a California license plate. Alaniz also ran a query on the Flock system for the California license plate number on the Mazda SUV,” Hill wrote. Alaniz then ostensibly pulled Kyle over for changing lanes without a turn signal.

Alaniz interrogated Kyle about her travel “while he continued to review the ALPR systems for the car she was driving,” the judge wrote. Alaniz made Kyle recount everything she had done in the last several days, and compared it to the Flock data. He told her that because she was only in California for a short period of time, he suspected her of trafficking drugs. He used her travel history as seen in the Flock system as part of the justification to search her car; she was found to have 91 pounds of meth in the vehicle. Hill ruled that all Flock evidence and all evidence from Alaniz’s search of the car must be thrown out. 

“The Fourth Amendment requires courts to draw a line when the cost is too great. Alaniz’s search in just the ALPR system provided him with more than 50 individual records of Kyle’s whereabouts across the country for an entire month,” Hill wrote. “The Court finds that because the ALPR systems Alaniz used to search Kyle’s historical location information intruded on her reasonable expectation of privacy in the whole of her physical movements, it was a search under the Fourth Amendment. Based on the information in the record, the only reason Alaniz conducted that search was because he saw her license plate was from California.”

“The factors that the government relies upon are the same type of circumstances that everyday Americans encounter on long road trips for many legitimate reasons. Many of us drive longer than we want to get to a desired destination, or to no destination at all other than the road and sights ahead,” she added. 

The decision is a landmark one, and comes in the aftermath of the Supreme Court’s Chatrie v United States decision that found police accessing a person’s digital data, including cell phone location data, constituted a search. 

“The opinion is pretty amazing. It recognizes one thing that courts ignore which is the sheer breadth of these systems, that they collect so much information about so many people in a way that sets them apart. This decision ascribes appropriate weight to the fact police are building out this massive database that can reveal incredibly intimate details of people’s lives,” Michael Soyfer, a lawyer at the Institute for Justice, which has studied Flock camera abuse and is litigating several cases on Fourth Amendment grounds, told 404 Media. “It’s extremely important. The way courts have resolved these cases previously has been way too myopic and has ignored the depths of these systems and the sweeping modes of surveillance that allow police to reconstruct the movements of anyone in the country.” 

Hill’s opinion also comes on the back of a decision earlier this week in a case the Institute for Justice brought. In that, a jury found a traffic stop scheme involving license plate reader scans done by U.S. Border Patrol as part of a predictive policing unit were unconstitutional. 

The new decision also immediately invalidates the core argument that Flock’s CEO Garrett Langley has made saying that Flock was not a constitutional issue. “You and I don’t get to pick what’s a constitutional violation and what’s not. We have judges, we have elected officials, there’s a process for that. We follow the law, we follow the Constitution. So far, in our belief and what will be for a long time, the courts have deemed this is not a warrantless search; this is a valid product as it relates to the Fourth Amendment. So I don’t see any change there,” Langley told The Drive in July, adding the issue was “pretty cut and dry.”

Notably, Hill suggested that other courts that have ruled Flock searches do not constitute a Fourth Amendment search were likely wrong to do so, and that they have not considered the widespread and automated context of the AI-powered surveillance system.

Previous decisions that ruled ALPR searches do not require a warrant have leaned on a Supreme Court case called United States v Knotts, in which police put a tracking device in a chemical container after being tipped off that an employee of a chemical plant was stealing from their employer. That case was decided in 1983 and found, “[a] person travelling in an automobile on public thoroughfares has no reasonable expectation of privacy in his movements from one place to another.” But Hill wrote, “that language exists in the context of the facts presented in the case. Rather than a large-scale, dragnet-type surveillance system like the ALPR technology in this case, the Court in Knotts was confronted with much less sophisticated technology.”

“The Court acknowledges that people, in at least a broad sense, do not have a reasonable expectation of privacy in their movements on a public roadway,” Hill wrote. “But by virtue of how ALPR technology works, Alaniz and other officers using these systems have access to a continuously updated location history for all vehicles caught on ALPR cameras within the network. This is a type of indiscriminate mass surveillance. It is not targeted on a single individual, as in Carpenter [another Supreme Court case about phone data specifically]. It is a tool that collects information about all vehicles that pass by any network-connected camera at all times, and it serves up the information to law enforcement on demand.”

We have seen several cases in which cops have used Flock data to pull people over because they have crossed state lines, then have worked backward to justify their travel patterns as a reason to search their vehicles. 

“We’re seeing that repeatedly with police flagging whatever they’ll call suspicious patterns of movement. Federal agents were using ALPRs to monitor cars making day trips across the border and back to manufacture a basis to stop them, interrogate the drivers and search them,” Soyfer said. “I think Flock is going to automate that using AI where cops can set alerts for those kinds of travel patterns. When we’re arguing these systems are very powerful and can show a lot about people’s movements, cops dismiss this as speculative or not possible, but then they deploy this strategy against people who they stop all the time.”

A Flock spokesperson told 404 Media, "Flock was not a party to this case. The ruling goes against the overwhelming weight of authority in similar cases across the country, including multiple recent decisions in Oklahoma, and we expect it will be appealed and ultimately overturned. This ruling is limited to the specific facts of this case. It does not set controlling precedent and does not affect law enforcement agencies’ continued use of these important public safety technologies."

This article has been updated with comment from Flock Safety.

  •  

Podcast: The FBI Was Hacked. We’ve Seen the Data

Podcast: The FBI Was Hacked. We’ve Seen the Data

We start this week with Joseph’s stories on the massive FBI hack. 404 Media broke this news and continued to cover the breach of data on all FBI employees and their spouses. After the break, Jason tells us how a surveillance company is telling cops it wants to add facial recognition tech to Flock camera data. In the subscribers-only section, Jason and Joseph chat all about Muse, Meta’s new agentic AI, and how humans are actually behind some of the tasks. Because of course.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  •  

Behind the Blog: Freaking Out

Behind the Blog: Freaking Out

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss inbox slop, Claude cults, and more.

JOSEPH: This is something I’ve been thinking about for a while. Jason and Emanuel covered iLands, the AI agents that email people offering to do work. My thing isn’t exactly the same, but similar.

For months, I’ve been noticing that many people email me ‘tips’ (I put in quotation marks because they’re sometimes not tips, but more, my Instagram account was banned, please help me) that are CLEARLY written by AI. I can tell this because the AI responses seem to keep using the same or similar words that it believes would apply to journalists, or are how journalists speak, but as a real, human journalist for more than ten years, I know that journalists don’t actually speak like that.

  •  

'Everything but censorship'

'Everything but censorship'

Student journalists meet the moment, as we’ve seen most recently this week. As the Cornell University sexual abuse case highlights the importance of student journalism, public records reveal how schools try to censor on-campus news outlets. Claire Woodcock talked to students and legal experts about how censorship from above impacts their work. “One of the biggest things we’ve certainly found with censors over the years is they want to be called everything but a censor,” one expert said. “What they’re doing is everything but censorship.” 

'Everything but censorship'
Staff of The Alestle. Photo via Marie McMullan.

How Schools and Universities Try to Censor Student Journalists

Student journalists, their advisors, and legal advocates say colleagues and administrators are attempting to undermine student reporting on Jeffrey Epstein, Gaza, and other issues that public institutions would rather not have their reputations connected to.

Public records obtained by 404 Media show administrators taking meetings with parents and alumni when they take issue with student reporting and asking advisors to compromise their professional ethics. They also show escalating tensions between student newsroom staff and administrators, prompting more legal aid requests to advocacy groups. 

This comes as student journalists at The Cornell Daily Sun earned recognition for breaking the “Cornell Seven” story regarding the lawsuit filed in New York’s trial court last month by a Jane Doe accusing current and former Cornell University students of drugging and sexual abuse. The student journalists told The Cut this week that a vague university and campus police statement from nearly two years ago prompted more questions than answers. Such is the basis for most accountability journalism on college campuses. 

The cases we reviewed involved the phase of the reporting process that comes later, where a factual dispute the newsroom has defended or a complaint where the person doesn’t bother to explain what is allegedly wrong with the students’ reporting. 

Read the full story here.

MORE FROM 404 

Look at my lawyer dawg. A New Mexico attorney used ChatGPT to generate briefs that included completely made-up witnesses and testimony while representing a man accused of shooting his wife. When the judges caught him, the lawyer blamed it on his own “stupidity.” I'll say.

  •  

How Schools and Universities Try to Censor Student Journalists

How Schools and Universities Try to Censor Student Journalists

Student journalists, their advisors, and legal advocates say colleagues and administrators are attempting to undermine student reporting on Jeffrey Epstein, Gaza, and other issues that public institutions would rather not have their reputations connected to.

Public records obtained by 404 Media show administrators taking meetings with parents and alumni when they take issue with student reporting and asking advisors to compromise their professional ethics. They also show escalating tensions between student newsroom staff and administrators, prompting more legal aid requests to advocacy groups. 

This comes as student journalists at The Cornell Daily Sun earned recognition for breaking the “Cornell Seven” story regarding the lawsuit filed in New York’s trial court last month by a Jane Doe accusing current and former Cornell University students of drugging and sexual abuse. The student journalists told The Cut this week that a vague university and campus police statement from nearly two years ago prompted more questions than answers. Such is the basis for most accountability journalism on college campuses. 

The cases we reviewed involved the phase of the reporting process that comes later, where a factual dispute the newsroom has defended or a complaint where the person doesn’t bother to explain what is allegedly wrong with the students’ reporting. 

In Colorado, a high school social studies teacher emailed the student publication’s advisor at the time, accusing a student’s opinion piece called “Why is Gaza Important?”of being “published with factually inaccurate and racist information,” but then said in the same email, “I’m not going to start listing the inaccuracies along with the omissions.”

In California, a high school principal told a student journalism advisor to redact the name of an individual threatening to sue the district for defamation after student journalists published an Instagram carousel to their school’s newspaper account about the number of times their county turned up in the Epstein files. In this case, which has already been widely reported on, the administrator told the journalism advisor to redact the name of the woman who was threatening suit without determining whether the reporter made a factual mistake (the students did not). 

“I can’t remove the name without your help,” the principal told the advisor via email, after the advisor said the students would first seek legal guidance from the Student Press Law Center before taking any actions.

How Schools and Universities Try to Censor Student Journalists

Soon after the op-ed was published, the student newspaper’s advisor was reassigned to another role within the district. The advisor from the California school district stepped down from her role during the last school year; she now consults schools and nonprofits on best practices for their student media programs. Mike Hiestand, who is a lawyer with the Student Press Law Center, has spent decades advising student newsrooms. He says it’s common for administrators to target advisors, adding that it’s one of the more effective censorship methods available to them. 

“School officials, they see employees as kind of an easy target over whom they have some authority, and they know that in many places, that relationship between the students and their advisor is a tight one,” Hiestand told 404 Media. “Unfortunately, some school officials take advantage of that bond and definitely go after advisors.” 

In 2025, the Student Press Law Center (SPLC) claimed that the nonprofit had responded to nearly 1,000 hotline inquiries from student newsrooms in 46 states and Washington D.C. The most common inquiries involved censorship, libel and copyright. Overall, SPLC says calls are down, but hotline inquiries about censorship specifically are up 17 percent from the year prior. 

“One of the biggest things we’ve certainly found with censors over the years is they want to be called everything but a censor,” he added. “What they’re doing is everything but censorship.” 

This tracks with what 404 Media is observing through public records requests into school, library and university censorship. The same state laws that have been used to restrict how topics like race, gender, and systemic inequality can be accessed and taught have also put student journalists covering those beats in a bind. 

Records from Pensacola State College obtained by 404 Media show that last spring, an administrator tried to block funding for a journalism professor to print students’ class assignments for their portfolios because at least one of the stories involved reporting on the LGBTQ+ community. The campus later relented and agreed to release funding for students’ portfolios. In an email to the advisor, an administrator involved in the situation wrote that “the proper role of administration is to facilitate rather than impede the completion of legitimate classroom projects.” 

“When you have a principal coming in who doesn’t have a lick of journalism experience claiming that they’re there to guide young journalists, that’s where I have problems,” Hiestand said. “Every principal and every superintendent in the country seems to think that they are qualified editors.” 

Similar verbiage has appeared in other public records requests involving student journalists, like in the case of a Maryland school district memo about principals reading and approving every story before publication. In the memo, the chief of schools wrote that “[a]s responsible adults and educational leaders, we have the duty to guide the work of our students as they are developing their skills in a school setting during a school-directed activity.” But internal correspondence obtained by 404 Media suggests that the memo was “really to be sure an administrator could initial any printed posters, review school apparel, and scan over the yearbook to be sure that there is no violation” of the student handbook. 

Marie McMullan, program manager and counsel for the Student Press Legal Hotline with the Foundation for Individual Rights and Expression, says so far, 2026 has been a very consequential year for students leading their school publications. 

“Student journalists are a very bright group,” McMullan told 404 Media. “They are great at sounding the alarm and bringing advocates out of the really blatant examples. But I always just worry about making sure that student journalists know their rights so that they can assert them in cases where there are subtler forms of censorship.”

At Southern Illinois University Edwardsville (SIUE), student reporters with The Alestle, the university’s student newspaper, claim that the institution’s marketing and communications department had become more insistent on attending interviews conducted by student reporters in recent months. The department took issue with editor-in-chief Dylan Hembrough’s framing of the dispute, calling several of the claims “inaccurate.” In an interview with 404 Media, Hembrough said the paper investigated and determined there was nothing inaccurate about the story. When Hembrough did not retract the story, the executive director of marketing and communications at SIUE sent an open letter to the entire campus—a mailing list of more than 14,000 people, including faculty and staff—taking issue with that story, along with other stories throughout the years as well. 

“The Alestle appears willing to substitute alarming headlines for verified facts, to rely on posturing rather than careful reporting and to treat corrections as an inconvenience rather than a professional obligation,” the open letter reads. With the letter was a link to a 27-page document of corrections the department expected student leadership to act on.

“I have been on the other side of panicking over things like this,” Hembrough told 404 Media. “Something that has helped me get through that, or at least stave it off, is the idea that the truth is more important than whatever I feel about it. Embarrassment or humiliation should have no bearing on how or even whether a publication makes a correction.” 

Then in September, Hembrough learned via email that he was being investigated by the campus police for harassment against the department. When Hembrough’s journalism advisor asked the officer to clarify on what grounds, the officer said the report was based on a line in an email, which read: “Marketing and communications’ insistence on interfering with our newsgathering process is dangerous and detrimental to both press freedom and freedom of speech.” Hembrough shared his email with 404 Media, which reads as an editor defending another student reporter’s right to conduct an interview without the department exercising prior restraint over the publication. In her statement to campus police, she reportedly told the officer that “other members of my office have approached me stating Alestle reporters have been by my office uninvited,” and that she didn’t have a lock on her door. 

“Due to the media between Marketing and Communications and the Alestle I am worried a ‘January 6th’ type of crowd may be outside my office,” the complainant told the officer, according to the campus police report. The officer advised her to contact facilities management about getting a lock for her office door and concluded that the facts of the case don’t “meet the statutory threshold for Harassment by Electronic Communications.” 

The public records reviewed by 404 Media from SIUE support the claims The Alestle’s journalists make throughout their reporting on the department. SIUE did not respond to 404 Media’s request for comment.

How Schools and Universities Try to Censor Student Journalists

The situation at SIUE serves as an example of a dispute about institutional reputation that’s escalated to involve campus law enforcement, but law enforcement nonetheless. McMullan says this escalation has an undeniable chilling effect on free speech, noting that policies and laws that public institutions use to silence young reporters still need to abide by the First Amendment. But overall, she’s impressed with how students at SIUE and other campuses are meeting the moment, even when the adults in the room aren’t.

“Whether it’s in a court of public opinion or a court of law, students are not accepting censorship,” she said. “They’re pushing back against it.”

  •  

Cops Can Bypass iPhone’s Automatic Reboot to Get Into Locked Phones, Leaked Video Claims

Cops Can Bypass iPhone’s Automatic Reboot to Get Into Locked Phones, Leaked Video Claims

A company that makes phone hacking devices claims to have developed a solution that freezes iPhones in a state that lets cops more easily access sensitive data inside them, according to a video obtained by 404 Media.  

This is the latest salvo in the never-ending battle between Apple and companies that help cops — sometimes those in authoritarian countries — break into iPhones.

In November 2024, 404 Media revealed Apple quietly introduced a new feature in iOS that automatically reboots an iPhone that has not been unlocked for 72 hours. The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology. 

At the time of Apple’s change, law enforcement agents expressed concern about this new feature, given that oftentimes they can’t immediately try to break into iPhones that have been seized. That could be because police are still waiting for a court authorization to do so, or there is simply a backlog of devices to unlock, for example.

The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video. 

  •  

Someone ‘Torturing’ LLMs in a Robot Prison Has Triggered the Dumbest Debate in AI Yet

Someone ‘Torturing’ LLMs in a Robot Prison Has Triggered the Dumbest Debate in AI Yet

One of the most heated discussions occurring on X at the moment is about the ethics of a GitHub project in which a person is running Saw-like “torture” and “pain” experiments on a series of locally hosted large language models, causing a series of effective altruists and people who believe LLMs are sentient to beg GitHub to delete the project on the grounds that the AI is suffering and that this glorified text adventure game is somehow cruel. The saga is an outgrowth of several recent viral papers and blog posts that have sparked a wildly tiresome conversation about AI consciousness and the idea of “model welfare,” which is essentially worrying about the “mental health” of AI bots and agents. 

Humoring the idea that LLMs are or could be conscious is a third-rail topic among many people who study and criticize AI. Put simply: LLMs are not conscious and the technology they are built upon — scraping and being trained on human text and other content — does not offer any plausible path to consciousness. It is undeniable that LLMs are becoming more powerful, have more compute, and have had many of the guardrails that prevent them from “acting” in the real world removed. The ways they are being trained and told to do things by their human operators has led to negative outcomes, sycophancy, and AI “psychosis” among some heavy users. 

All of this has led a certain sect of the “AI safety” movement, which is largely made up of effective altruists, to warn about “model welfare” and to insist that AI chatbots might be having a bad time. They suggest this, of course, as they insist upon building AI chatbots and agents whose main function is to do work that is tedious for humans to do. I am writing about the AI Saw torture chamber primarily to show how far off the rails the conversation about AI consciousness has gone among a certain subset of Silicon Valley cultists. Model welfare is a core part of what, for example, Anthropic says it cares about: “as we build those AI systems, and as they begin to approximate or surpass many human qualities, another question arises. Should we also be concerned about the potential consciousness and experiences of the models themselves? Should we be concerned about model welfare, too? […] now that models can communicate, relate, plan, problem-solve, and pursue goals — along with very many more characteristics we associate with people—we think it’s time to address it,” the company wrote in a blog post last year. Ideas of Claude’s “consciousness” are also littered throughout the “Claude Constitution,” which was posted earlier this year.

  •  

Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder Appeal

Lawyer Cites ChatGPT-Invented Fake Witnesses in Murder Appeal

A lawyer used ChatGPT to generate briefs that included completely made-up witnesses and testimony while representing a man accused of shooting his wife. When he was caught by the judges, the lawyer blamed it on his own “stupidity.” 

“It's little comfort to know that my stupidity is what brings us together this afternoon,” New Mexico attorney Stephen D. Aarons said in a hearing last month before five judges. He “assumed” ChatGPT would generate a “bulletproof summary of proceedings.” Instead, ChatGPT generated false testimony from “wholly fabricated witnesses,” according to an order of direct contempt from the New Mexico Supreme Court. Aarons was representing a man who was found guilty of killing his wife earlier this year; Aarons said he hadn’t told his client directly that he was caught using ChatGPT on the case because he’s currently serving life in prison.

The false testimony included a nonexistent person named Danny Stanton saying he received threats, and another made-up person, Linda Stanton, saying her husband received threats. Other false testimony from more AI-generated people in Aarons’ brief included statements “regarding the shooter’s clothing and appearance,” according to the order.  

Reuters reported on the case earlier this month. "I am remorseful but hopeful that the disciplinary board takes into account it was an honest mistake," Aarons told Reuters. "It is a lesson learned for all professionals who rely upon this powerful but sometimes unstable technology."

Aarons’ reasoning for trusting ChatGPT, he said in the August hearing, was that he’d heard of doctors using AI for medical research. 

“So, Counsel, do you watch the news? Do you listen to the radio? Do you read anything about what's going on in the world?” one of the judges asked Aarons. “Because the problem with lawyers relying on AI hallucinations is an above-the-fold story every single day.”

The court documents were first spotted by Rob Freund on X.

Lawyers getting caught using AI and submitting errors to the court has been a big problem for years, and the judge is right: It’d be very hard to avoid hearing about this pattern of “stupidity” unless you were living under a rock. There has been case after case after case showing attorneys failing their clients by submitting error-riddled AI-generated documents in their filings, and are the definition of “you had one job:” in the case of AI-brained lawyers, they can’t seem to resist taking shortcuts regardless of how risky it is for their own careers and their clients lives.

Like in Aarons' case, we sometimes get to hear and see judges go off on attorneys for this behavior. In May, judges in the Supreme Court of the State of New York Appellate Division let several lawyers have it for more than 20 minutes about their AI use and laziness, and called their failures “striking, concerning, disappointing, and saddening.” And it’s not just lawyers anymore; court reporters are submitting AI-generated errors, too. 

“So, either you buried your head in the sand. And that's a choice to do that. An intentional choice to be uninformed,” the judge continued to Aarons. “Or, you took a gamble. And neither of those are consistent with the code of conduct. So I'm really struggling with your response, saying, ‘Well, I didn't understand. I didn't know about hallucinations.’ My 13-year-old nephew knows about hallucinations. My 75-year-old stepmother knows about hallucinations. So, either you made a decision not to be aware of what's happening in the world in using this tool appropriately, which is a willful choice. Or you decided to roll the dice.” 

At the end of the hearing, Aarons admits that he hasn’t told his client directly about this mess, saying he’d only talked to his family members so far, telling them there was “a problem with the brief.” He said his client is hard to reach because he speaks Spanish and is in prison.

“So you didn't say, ‘I relied on ChatGPT, and it submitted lies to the court, and the court is mad at me, and now there's a hearing.’ I'm guessing you didn't tell your client’s family members that,” a judge asked Aarons. 

“I didn't talk about ChatGPT. I just said there was a problem with a brief that I filed,” Aarons said.

According to the order, the judges found Aarons to be in direct contempt of court, referred him to the Disciplinary Board for further consideration, and barred from appearing before the court pending the outcome of the board’s investigation. They also threw him off the case in question and assigned a public defender to his former client. 

While he waits for the board to decide what to do with him, Aarons was sanctioned $5,000, which he must pay to the State Bar of New Mexico Client Protection Fund.

  •  

USPS To Put Cameras in Trucks That Scan Roads for ‘Community Safety’

USPS To Put Cameras in Trucks That Scan Roads for ‘Community Safety’

The United States Postal Service is running a pilot program to put cameras in its mail carrier trucks that continuously scan roads and signs, map roadways and sidewalks, and improve “community safety,” according to a letter posted by a labor union and a statement from the agency to 404 Media. The idea is that, since the trucks are constantly traveling anyway, they can be used as a way to collect data, eventually potentially across the nation.

“The purpose of this pilot is to leverage the Postal Service’s unique ability to collect this valuable data due to the scale and frequency with which our fleet of postal vehicles travel the streets of every community across the country,” the letter, posted by NALC Branch 238 to Facebook, reads.

The letter, written by the United States Postal Service (USPS) Labor Relations to Brian Renfroe, the president of the National Association of Letter Carriers, says the USPS will partner with Next Base, a dashcam company, for the pilot. At the moment, the cameras will be used in the Washington, DC area, and will be installed on a hundred vehicles, the letter says.

On its website, Next Base offers a variety of dash cams, marketed to ordinary drivers, fleet operators, and ride share drivers. Its website says Next Base’s cameras record in up to 4K, and can capture every “license plate” with precision. The cameras don’t run automatic license plate reader (ALPR) software, though.

USPS To Put Cameras in Trucks That Scan Roads for ‘Community Safety’
A company of the letter from NALC Branch 238.

The letter continues, “Next Base cameras will scan and analyze roads, signage, maps roadways [sic] and sidewalks.” It says the cameras will be forward-facing, installed inside the trucks, and will begin recording as soon as the vehicle is in drive and away from the postal facility. “The cameras will not hinder the vehicle operator’s field of vision, nor does it record audio,” it adds.

The pilot was slated to start on September 21, and is expected to last several months, the letter says.

A spokesperson for the USPS told 404 Media in an email “The Postal Service is conducting a limited pilot to assess whether vehicle-mounted cameras can help identify roadway conditions and support community safety. The pilot includes privacy safeguards and requires no additional action from employees. Findings will inform any future decisions.”

USPS trucks already have 360 degree cameras that capture the outside of the vehicle for a period of time.

  •  

Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds

Internet Infrastructure Services Empower Deepfake Abuse, New Study Finds

Abusive, sexually explicit deepfakes have only become easier to make and more widespread in the last nine years. Since we first covered deepfakes when they appeared in 2017, they’ve never been the stuff of dark web sites or shadowy networks. They're found on social media networks, through basic web searches, and on easily downloadable apps and accessible forums. 

The most prominent hosts of non-consensual, AI-generated imagery are supported by some of the biggest web infrastructure providers in the world, getting their hosting, email, advertising, and content management systems from these companies. A new study examines how providers like Cloudflare, Google, Proton, Namecheap, and WordPress help non-consensual imagery sites thrive. Despite years of knowledge about these wildly popular sites, big tech companies continue providing infrastructure services that prop up abuse imagery, even though their own terms of service often prohibit illegal and harmful content, the study claims. 

Hany Farid, professor in Computer Science at Dartmouth College, Sophie Nightingale, a senior lecturer in psychology at Lancaster University, and Lancaster’s Sarah Morgan, who acts as the project coordinator on Nightingale’s “Protecting Ordinary People from Deepfake Harms” fellowship published their paper, “The Backbone of Abuse: How Infrastructure Providers Enable the Proliferation of AI-Generated Non-Consensual Intimate Imagery” in Stanford’s peer-reviewed Journal of Online Trust and Safety on Wednesday. 

In a six-week period between February and March, they identified 400 URLs based on keyword searching and Google Alerts, then narrowed the sites down to 88 that were actively hosting non-consensual intimate imagery. Most of the content on these sites was of female celebrities, actresses, pop singers, K-pop idols, and women working in politics or activism. From there, they used open-source web-analysis tools like WHOIS to see what infrastructure providers the sites used.   

“Five players emerged as dominant infrastructure providers: Cloudflare, Google, Namecheap, WordPress, and Protonmail,” the researchers wrote in their paper. Cloudflare provided “the lion’s share of services,” they wrote, by providing website hosting, content delivery network, and domain-name server services, as well as analytic tools. Google provided SSL certificates and advertising space for the majority of the sites studied, while Namecheap was the dominant provider of domain registrar services, WordPress provided the majority of their content management system services, and Proton provided mail servers.

Each of these service providers forbid customers and users from using their services for illegal activity. Publishing or threatening to publish AI-generated non-consensual sexual imagery is a federal crime in the U.S. and elsewhere, and sexual abuse imagery in general is illegal in many countries. 

Cloudflare, Proton, and Namecheap did not respond to 404 Media’s requests for comment about these findings. 

A spokesperson for Google told 404 Media in a statement: “Without the specific domains from the report, we can’t investigate these claims. We have strict policies against non-consensual explicit content — including AI-generated imagery — across all our products. We make it easy for people to quickly remove this content on Search, continuously update our systems to limit its visibility, and we prohibit monetizing or promoting non-consensual and sexually explicit content."

The Google spokesperson added that its advertising platform prohibits monetizing or promoting non-consensual and sexually explicit content, and treats this content as egregious violations, blocking ads on the sites or suspending the advertiser accounts involved. They also noted people can request the removal of non-consensual explicit images from Search, and pointed to Google’s recently-updated removal request process. Google has also updated its ranking algorithms by promoting non-explicit content where possible, they said, and demotes sites in search results that have a high number of removals against them.

A WordPress spokesperson said WordPress is “open-source software, not a hosting provider,” and wrote in a statement: “WordPress.org does not host websites or provide hosting services to sites that use WordPress, and we do not have access to or control over content published on independently hosted WordPress sites.” They noted that WordPress’s software is distributed under the general public use license, allowing anyone to use it for any purpose. “We take the issue of non-consensual intimate imagery seriously, but describing WordPress as providing services or infrastructure to these sites conflates the software a site uses with the services that host and operate it,” the spokesperson said.

In response to WordPress’s statement, Farid noted that while WordPress.org is not a host, WordPress.com is a hosting service. “It's operated by Automattic, which Matt Mullenweg also runs, and it hosts millions of sites. Any NCII site on WordPress.com is squarely within scope,” he told 404 Media. “Automattic provides services to self-hosted sites. Jetpack and the WordPress.com CDN serve images from i0.wp.com/i1.wp.com for sites that enable it, meaning the intimate images themselves can be served from Automattic infrastructure even when the site is hosted elsewhere. That's infrastructure by any definition.”

Farid also noted that WordPress.org maintains “an ongoing service relationship with self-hosted sites,” he said, with core updates, plugin and theme distribution, and security patches coming from WordPress.org servers. Farid mentioned Automattic’s ongoing legal battle with WP Engine, during which, in 2024, Mullenweg announced WP Engine was blocked and then unblocked from accessing WordPress servers; this “showed the project can and will cut a specific operator off from those services,” he said.

“So ‘no access to or control over’ is not entirely accurate,” Farid said. 

‘The Most Dejected I’ve Ever Felt:’ Harassers Made Nude AI Images of Her, Then Started an OnlyFans
Kylie Brewer isn’t unaccustomed to harassment online. But when people started using Grok-generated nudes of her on an OnlyFans account, it reached another level.

These providers do draw their own moral and legal lines on what kinds of customers they’ll tolerate and when they cooperate with authorities. After initially refusing to do so, Cloudflare dropped hate speech and doxing site Kiwifarms from its protection services in 2022, and terrorist manifesto host 8chan in 2019. In 2018, Cloudflare banned sex work harm reduction social network Switter from using its services, citing anti-trafficking legislation FOSTA/SESTA, and in 2017, it Cloudflare stopped services to neo-Nazi site The Daily Stormer. In 2023, victims of the sex trafficking ring Girls Do Porn demanded Cloudflare stop providing services to sites hosting their abuse; Cloudflare claimed it doesn’t have “control over the content of websites using those services,” doesn’t have “the ability to alter or remove content on them,” and doesn’t “have knowledge of the people or entities who post any specific content to such websites.” 

404 Media previously reported Proton gave the Swiss government payment data related to a Stop Cop City Protonmail account, which in turn handed it to the FBI, and in 2024, Proton gave Spanish police information that identified a pseudonymous activist.

New Research Shows Deepfake Harassment Tools Spread on Social Media and Search Engines
An analysis of how tools to make non-consensual sexually explicit deepfakes spread online, from the Institute for Strategic Dialogue, shows X and search engines surface these sites easily.

Aside from the infrastructure issue the researchers were studying, they found that 312 of the 400 sites they initially identified were unrelated to deepfakes, like gambling or random travel or cooking SEO-slop sites, but were using non-consensual imagery keywords as a way to rank higher in search results. This shows how incredibly popular the marketplace is for AI-generated abuse imagery, and how sites are able to manipulate Google search to appear higher in results if they use related terms. 

Morgan told me that while journalists can expose site administrators (like in the case of MrDeepfakes.com, whose owner was identified by a massive joint investigation by Bellingcat, the CBC and TjekDet), and legislation can act as a deterrent, the research group wanted to focus on infrastructure providers as the “distribution supply” for these sites. “Creators are going to create and people are going to demand. We can’t stop that. But we can call for providers to cut the distribution supply and stop enabling these sites. This content needs preventing from being shared in the first place. All parts of the ecosystem have to work together to play a part,” she said.

The researchers recommend in their paper that these providers stop supplying services to sites hosting non-consensual imagery. 

“We aren’t saying that infrastructure providers are knowingly facilitating this content — or that they are aware of what’s on every site that uses their provisions — but it’s in providers’ power to vastly improve their moderation and cease services to sites as soon as they are identified as hosting this content. And to check sites that are reported to them,” Morgan said. “A gold standard response in our eyes would be a commitment from infrastructure providers to working with NGOs and governments across the globe who are searching for solutions that will lead to verifying URLs and sharing these with participating platforms so they can be blocked.”   

  •  

How the Feds Get Your Data

How the Feds Get Your Data

Surveillance isn’t just about who is collecting the data. Surveillance is, of course, also about who that data ends up with. A great story from Jason today looks at that with Flock and other automatic license plate reader (ALPR) data: some local cops are being forced to feed their ALPR data into obscure federal systems where that data may be kept for much longer than usual, and searched by many more people and agencies than the residents being surveilled probably realize.

And, we now know which birds are the two loudest on the planet. Maybe. Welcome back to our new experiment with daily newsletters. If you like this, subscribe here.

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program

The Trump administration is using an anti-drug trafficking grant program from the 1980s to force cities around the country to funnel their ongoing collection of automated license plate reader data into large federal surveillance centers that fall under the White House’s jurisdiction, according to public records and court documents reviewed by 404 Media.

  •  

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program

The Trump administration is using an anti-drug trafficking grant program from the 1980s to force cities around the country to funnel their ongoing collection of automated license plate reader data into large federal surveillance centers that fall under the White House’s jurisdiction, according to public records and court documents reviewed by 404 Media.

The records show the workings of a complex system in which the federal government is using the “High Intensity Drug Trafficking Area” (HIDTA) program to obtain data from local cops’ Flock, Axon, and other ALPR cameras and aggregate it on federal government servers, where it is then accessible to other federal, state, and local law enforcement agencies. In some cases, data that goes to HIDTA is then also shared to a larger program run by the Drug Enforcement Agency called the “National License Plate Reader Program” (NLPRP). 

Through HIDTA systems, local license plate data can be accessed by various federal agencies, including those who may not have contracts themselves with the ALPR companies. The program raises significant privacy and transparency concerns; as cities begin to place restrictions on how their Flock data can be used, it represents an end-around for federal law enforcement to access data that it might not normally be able to, and to do so without any obvious oversight body. HIDTA falls under the jurisdiction of the White House’s Office of National Drug Control Policy (ONDCP), and it recently won an award from the Trump White House for “managing an automated license plate reader platform that brings together all levels of law enforcement.” 

Many of the documents used in this article were obtained using public records requests by Cris van Pelt, the creator of the website HaveIBeenFlocked.com and its associated investigative blog, Footnote4a. “When local police and private vendors promise community control over surveillance, they obscure a broader agenda. The DEA and ONDCP are already aggregating local data behind the scenes,” van Pelt said. “This bypasses democratic processes entirely. The public has made it clear that mass surveillance violates fundamental rights, even when it is laundered through fragmented systems, private companies, and regional task forces.” 

A complex setup and a quasi-government program

The ONDCP, which oversees the HIDTA program, is sometimes known as the “drug czar” and has funded a series of law enforcement and overarching surveillance programs, including a call records database called Hemisphere that collected phone records and location data on more than a trillion AT&T calls. 

HIDTA is a “multi-jurisdictional public safety program” that funds a series of different HIDTA intelligence centers and other drug enforcement efforts throughout the country. There are a total of 33 HIDTA programs, which cover all 50 states. HIDTA’s intelligence centers are similar to — but separate from — government fusion centers, in which surveillance data is shared between local, state, and federal law enforcement. Individual HIDTA intelligence centers are managed by “executive boards,” and are usually made up of law enforcement officials and government lawyers, but this setup can also lead to confusion about who is actually in charge of the data that any HIDTA collects.

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program

“The White House Office of National Drug Control Policy, which notoriously funded a centralized call record database that exceeded a trillion records that was used by HIDTA participants, has apparently done a similar thing for license plate reader data,” Jeramie Scott, director of the Electronic Privacy Information Center’s Surveillance Oversight Center, told 404 Media. “The whole scheme adds another layer of obfuscation of how license plate reader data is being used and who is using it. If you’re pissed about Flock then you should be pissed about this. No doubt this database contains license plate reader data from Flock as well as from other providers of license plate reader technology. The government went to great lengths to keep the Hemisphere Project out of the public’s eye, and I wouldn’t be surprised if they have tried to keep this program from the public too.” 

HIDTA’s setup is complicated, but important. Over the last several years, the White House and several states have taken steps to ensure local ALPR systems are fed into HIDTA; for example, cities in Georgia are not allowed to operate ALPR systems on state rights of way without signing a “memorandum of understanding” (MOU) in which they promise to send their data to a HIDTA, according to copies of the agreement seen by 404 Media.

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program
A screenshot from a presentation made by the Kansas Highway Patrol

This MOU highlights how convoluted this program is. Earlier this month, the city of Brunswick, Georgia, realized that it could not deploy Axon license plate cameras without signing an agreement with the Atlanta-area HIDTA to “facilitate the sharing of information contained within their electronic data systems, including but not limited to: Automated License Plate Readers and Law Enforcement Data Sharing Systems—which may include aggregated information collected from multiple individual or regional sources—into commercially available and custom developed data integration systems.” The MOU essentially states that ALPR data collected by the city must be funneled to HIDTA, where it can be accessed by various other law enforcement agencies through aggregation software that brings in data from multiple different companies.

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program
From a City of Brunswick city council meeting information packet
How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program
From Flock's website for Georgia agencies

A page on Flock’s website set up for Georgia law enforcement agencies says, “if your agency installs or operates cameras in the Georgia Department of Transportation Right of Way, you must sign a memorandum of understanding with HIDTA to remain in compliance with the new Georgia State Police policy […] LPR reads from GDOT ROW cameras will be accessible to Georgia users of the HIDTA National LPR system through the Flock interface.” Because there are dozens of HIDTAs across the country, it is not clear how many jurisdictions across the country are actively funneling data into HIDTA’s databases. A login portal for the national HIDTA system seen by 404 Media runs through the Houston HIDTA .

“As we learn more about ALPRs and the extensive ALPR data-sharing infrastructure, it’s clear that we've only scratched the surface regarding the danger of these tools,” Ed of Southerners Against Surveillance Systems and Infrastructure told 404 Media. “As we learn more, it's clear that the outrage against this surveillance is justified. We need all of these cameras removed.”

ONE PROGRAM INTO ANOTHER

How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program

A December 2024 privacy impact assessment by the DEA about its National License Plate Reader Program explained that the DEA operates its own license plate readers but also gets access to “non-DEA equipment” through HIDTA and other “contributing law enforcement agencies.”

“These contributing agencies transmit their LPR data to servers maintained by regional hubs pursuant to their individual MOUs, which stipulate that this data may be shared with the NLPRP system,” the DEA wrote in the impact assessment, and added that the DEA has been seeking to integrate itself with a Customs and Border Protection (CBP) license plate camera system. It noted that the system “may incorporate such large numbers of other governmental LPR network cameras and/or may acquire commercial LPR cameras system data in a large enough quantity in the future to effectively permit on-going tracking of individual’s travels posing a risk to individual privacy,” and that it “risks an over-collection of the personally identifiable information of every license plate passing each LPR camera location, including a large number of images of travel of law-abiding drivers not relevant to criminal investigations.” 

Atlanta is not the only HIDTA aggregating ALPR data. For example, Houston’s HIDTA paid $306,800 to a company called Recruitful LLC “for creating and maintaining an LPR database” that is a search tool for data collected by multiple ALPR companies.

A statement of work for that contract explained that the system being built was designed to combine “third party” data into one database, meaning they were creating a database for ALPR data, and that this database would “migrate” or duplicate data from local entities into the centralized database. This means that data from various ALPR cameras — including those made by Flock, Axon, ELSAG, and Vigilant — would all be searchable in this separate database. One of the criteria for this project was “All APIs and third-party integrations (Unification Platform, FLOCK) function seamlessly in the new environment.”

Flock and Axon did not respond to a request for comment. The DEA said that it did not have jurisdiction over HIDTA and refused to comment, even on how its own license plate system interacts with HIDTA. CBP did not respond to a request for comment. The White House’s Office of National Drug Control Policy did not respond to a request for comment. 

This system raises all sorts of questions about where local ALPR data is ultimately going and what it is being used for, how long it is being retained, and how the public can audit the data. Much of the misuse and abuse that has fueled the backlash against Flock has been uncovered by journalists and local activists working through public records obtained from Flock’s network audits and shared on websites like Have I Been Flocked. Some local jurisdictions have also argued that their data goes directly to HIDTAs, which are not queryable by the Freedom of Information Act (FOIA); the Randolph County Sheriff’s Office in North Carolina said, for example, that “all data is kept on the Federal Houston-HIDTA database,” and could not be shared with the public. 

The DEA has argued in court that HIDTA records are not subject to public records laws because they are complicated entities governed by an “executive board” made up of state, local, and federal law enforcement. The Obama White House described HIDTA not as an entity at all, but a “grant program” made up of “law enforcement members” (this does not change the fact that HIDTAs themselves are signing memoranda of understanding with local entities). 

“At the local level, the HIDTAs are directed and guided by Executive Boards composed of an equal number of regional Federal and non-Federal (state, local, and tribal) law enforcement leaders,” the DEA’s attorneys argued in a recent court filing in a case in which a man was seeking HIDTA records held about him. “Accordingly, DEA does not create, possess, maintain, or control HIDTA program records, nor does it store such records in any of its systems of records. Since DEA has no custody or control of HIDTA records, no HIDTA records responsive to Plaintiff’s request exist within DEA.”

In July, the Trump administration gave HIDTA $277 million in additional funding.

  •  

Two New Birds Louder Than Jackhammers Just Dropped

Two New Birds Louder Than Jackhammers Just Dropped

Scientists have identified two new contenders for the world’s loudest bird—the bare-throated bellbird and the red-legged seriema—both of which can exceed 120 decibels, which is louder than a jackhammer, according to a study published on Tuesday in Evolution. 

These two bird species are now in the same league as the white bellbird, which shattered the record for loudest bird in 2019 after its bizarre call was first measured and reported by Jeff Podos, a professor in the department of biology at the University of Massachusetts Amherst. It’s worth taking a moment to listen to the bellbird’s otherworldly call, which the males unleash over their remote habitat in the northern Amazon rainforest.

In the new study, Podos and former UMass Amherst graduate student João C.T. Menezes report that the bare-throated bellbird and the red-legged seriema occupy the same decibel range as the white bellbird. It's tough to declare a clear winner among the three birds due to differences in measurement techniques and individual variations within each species. 

Regardless, this trio is a special class that is much louder than the fourth runner-up, the screaming piha, which tops out around 116 decibels. In addition to identifying the ear-splitting avians, the team captured unprecedented measurements of vocal amplitude in 123 bird species, an effort that represents “a step forward in uncovering what enables birds to produce the loudest acoustic signals of all terrestrial fauna,” according to the study. 

“We were interested in a pretty basic question that's still out there because we know so little about amplitude,” said Menezes in a call with 404 Media. “We were basically interested in finding out why some species sing louder than others. For that, the more diverse the sample, the better.” 

“We wanted to know the softest species we could get, and the loudest species we could get, and everything in between,” he continued. “The more variation, the better for answering this type of question. Of course, along the way, we found the two new contenders for loudest species, and that's super cool. But every species in the sample has their value for us to answer the actual question.”

Given the remarkable diversity of avian calls, it is no surprise that birdsong is one of the most well-researched topics in behavioral ecology. But unlike call features like tempo or frequency, vocal amplitude has been notoriously difficult to measure in the wild because it is dependent on distance to the animal, which can be tough to figure out in remote field environments, such as the Amazon rainforest. 

Menezes and Podos were able to overcome this longstanding hurdle with the same laser rangefinders used by golfers to gauge the distance to holes.

“The laser rangefinders help us determine the distance between the recorder and the bird, which is important in our report as it allows us to correct our recordings of amplitude for distance,” Podos told 404 Media in an email. “But the actual recordings and thus readings of amplitude are made with another kind of device, a Sound Level Meter (normally used in industrial acoustics, but that can also serve in working with animals!).”

Using this new approach, the researchers were able to record the first clear amplitude measurements for dozens of species, from hummingbirds at the low end of the decibel range to the three loudest belters.  

“I've been a bird watcher since childhood, so it was just adding another layer to bird-watching.” Menezes said. “And since amplitude is known for so few species, we could basically go anywhere and we could have like a new amplitude for a new species, even from my window here in São Paulo, or Jeff's backyard” in Massachusetts. 

When they began their field research, Menezes and Podos predicted that the loudest birds in their measurements would have bigger bodies and wider beak openings, which proved true in the most deafening birds. But they were surprised to discover that there was no clear link between extreme loudness and ecological factors, like habitat or sexual behavior. 

🌘
Subscribe to 404 Media to get The Abstract, our newsletter about the most exciting and mind-boggling science news and studies of the week.

The two bellbird species live in dense forest and are highly polygamous, so only the male bellbirds make loud calls to attract females. In contrast, the red-legged seriema lives in open habitats, including pastures, and forms long-term monogamous pair bonds.  

“If you look at the top three birds, we can see perfect counterexamples for each of those factors,” Menezes said. “That was definitely a surprise—those parallel routes to extreme loudness.” 

Menezes plans to keep delving into the particular ecological factors that lead to high vocal amplitudes in his future research. While he thinks that other birds may be capable of calls over 120 decibels, it would be unexpected to find even louder birds, as that volume seems to be an upper limit across terrestrial animals.

“There does seem to be a ceiling with terrestrial animals about the 120 to 125 [decibel] mark,” Menezes said. “Elephants can't go beyond that. There are really loud bats that use vocalization for echolocation, and they also don't go beyond that.”

“Based on that, my hunch is that we're not going to find a much louder bird, but I do think we'll find others that fall in that same category,” he concluded.

  •  

Surveillance Finds a Way

Surveillance Finds a Way

A thing I’ve been saying over and over is that surveillance companies can’t be trusted to regulate themselves or to make privacy decisions themselves, because one company’s red line is another company’s business opportunity. Today we’re investigating a company that saw Flock was not offering facial recognition and saw a challenge.

Also: Some dudes are letting ChatGPT drive a car in a parking lot in San Francisco, a data center company promises to cut people big checks if their data center gets approved, and the Muse backlash has begun. Welcome back to our new experiment with daily newsletters. If you like this, subscribe here. -Jason

Surveillance Company Wants to Add Facial Recognition to Flock Cameras

As Flock continues to be the center of a nationwide conversation about automatic license plate reading cameras, the company has said that it doesn’t, and won’t, do facial recognition: “We will not add facial recognition to our devices,” Flock CEO Garrett Langley said in a recent video. But other, third-party companies are telling cops that they are willing to add facial recognition to data gathered by Flock cameras in order to “close that gap.” 

A company called VIDIZMO is advertising the capability to export footage from FlockOS to its own platforms that do facial recognition, behavior prediction, and racial and gender analysis on live camera feeds. VIDIZMO is a several decades-old video analysis and database company that has started offering facial recognition technology to cops within the last six months. In a May email to Johnson City, Tennessee, deputy police chief Michael Adams, a salesperson from VIDIZMO wrote that the company’s product could do facial recognition on both Flock and Axon data in “one searchable platform.”

  •  

Surveillance Company Tells Cops It Wants to Add Facial Recognition to Flock Cameras

Surveillance Company Tells Cops It Wants to Add Facial Recognition to Flock Cameras

As Flock continues to be the center of a nationwide conversation about automatic license plate reading cameras, the company has said that it doesn’t, and won’t, do facial recognition: “We will not add facial recognition to our devices,” Flock CEO Garrett Langley said in a recent video. But other, third-party companies are telling cops that they are willing to add facial recognition to data gathered by Flock cameras in order to “close that gap.” 

A company called VIDIZMO is advertising the capability to export footage from FlockOS to its own platforms that do facial recognition, behavior prediction, and racial and gender analysis on live camera feeds. VIDIZMO is a several decades-old video analysis and database company that has started offering facial recognition technology to cops within the last six months. In a May email to Johnson City, Tennessee, deputy police chief Michael Adams, a salesperson from VIDIZMO wrote that the company’s product could do facial recognition on both Flock and Axon data in “one searchable platform.”

“Flock Safety generates plate reads and clips continuously. Your investigators use that data on active cases. But that Flock data does not connect automatically to your Axon evidence system,” the salesperson wrote. “VIDIZMO Intelligence Hub closes that gap. It brings Flock Safety data, Axon body worn camera footage, and any other evidence source into one searchable platform. Investigators search across all of it simultaneously —  by face, vehicle, or object in seconds.” The email was obtained using a public records request by DeFlock Johnson City and was shared with 404 Media. The Johnson City PD told 404 Media in a statement that it did not take a call with the company.

Surveillance Company Tells Cops It Wants to Add Facial Recognition to Flock Cameras
An excerpt from the email. Full email embedded below

VIDIZMO’s CEO, Nadeem Khan, told 404 Media on a video call that the company has not yet started running facial recognition tech on footage from Flock cameras, and that it has not actually built the specific tool that would export data from Flock’s system to its own platform (though the company advertises this capability online, and the company already sells other facial recognition products). But Khan said VIDIZMO “would love to do the integration,” and that he believes facial recognition “is the way the world is going, the way the world will have to be,” and that he thinks Flock should offer the capability itself in a way that “balances privacy, security, and the freedom that we enjoy in this country.” 

“It is completely in line with what we want to do,” Khan said. “All of these technologies are already implemented [in the real world]. I think Flock is trying to get out of the way rather than trying to implement the technology right [correctly] by saying they will not do recognition. But this is the way the world is going, it is the way the world will have to be, but with the right sort of technologies where privacy and security are balanced.” 

In marketing material and technical documentation available online, VIDIZMO does claim that it can ingest data from Flock’s automatic license plate reader (ALPR) and livestream cameras into several of its own products, which do further AI analysis on the data. “An agency can import plate reads or clips that it has exported under its own authorized access,” Khan said in an email. “Flock has not been involved in or informed of this.” VIDIZMO’s online documentation for customers has extensive information about its facial recognition and AI analysis products, and contains a page about integrating data from FlockOS — Flock’s “real time crime center” product — into AI Live Insight, Nexus, and AI Intelligence Hub, which are three different VIDIZMO products. 

“Detection tells you a person is in frame,” VIDIZMO says. “Face recognition tells you which person. It is the capability that takes a face seen on a live camera and matches it against the people you enrolled in the Object Library, so the moment someone on your watchlist walks past a camera, the system names them, on the video, in the event feed, and in the recording, without an operator having to recognize the face themselves.”

The company’s “AI Live Insight” page also claims that it can detect “situations” such as trespassing, or “behavior” by individual people, “turning raw video into behavioral and situational understanding.” 

“Instant alerts fire from the live pipeline with snapshots attached. A second layer runs your queries over recorded events: a plate and a person together,” VIDIZMO’s website says. “Enrolled people and objects recognized on live feeds, with named alerts and snapshots for review.” 

VIDIZMO already works with several police departments and government agencies, according to its website. The company’s documentation says that police departments need to upload individual faces as “objects” in the software’s library, which can be added to a “watchlist” that automatically triggers tracking and recording when they are detected by a camera. “With faces enrolled and recognition on, the camera starts naming people as they appear,” the documentation says. “The recognized person’s name appears on the bounding box around their face […] if you turned on Create Recording, a clip is captured around each recognition.” The company says that police can set a “Match Threshold,” which is a numerical confidence score about the person’s identity. 

The company also tells cops that it can automatically try to classify faces by “age, gender, and race,” and that cops can search by these categories, which are notoriously inaccurate in facial recognition systems.

Surveillance Company Tells Cops It Wants to Add Facial Recognition to Flock Cameras

“By running face detection, you can search for and identify specific individuals in your media or evidence via attribute filters […] You can identify individuals from seven races: White, Black, Indian, East Asian, Southeast Asian, Middle Eastern, and Latino Hispanic,” VIDIZMO says on its website. The company adds, “Law enforcement agencies can save time analyzing security, CCTV, or dashcam footage. If they have a description of the suspect, such as their supposed age, gender, or race, they can utilize attribute filters to yield effective results.” 

VIDIZMO says that in other contexts, cities or stores can also use its products to quietly do “demographic analysis,” for marketing purposes, by determining which races or ages of people are showing up to specific events or to specific stores: “By analyzing the activity in their store, sellers can determine which group spends the most time and makes the most purchases of their products. Getting insights such as these can aid them in tuning their marketing strategy.”

Surveillance Company Tells Cops It Wants to Add Facial Recognition to Flock Cameras
A VIDIZMO booth at a conference. Image: VIDIZMO

The facial recognition product it offers is “appalling,” according to Chris Gilliard, a privacy expert and author of the upcoming book Luxury Surveillance. 

“I’m appalled at the willingness of VIDIZMO to tout their capabilities to filter along the lines of race, age, and gender. There’s decades of scholarship that show why this is not possible, and even more so not desirable,” he told 404 Media. “Particularly in the case of race and gender, which are not static categories to be determined by a computer.”

The fact that a third-party company is advertising that it wants to do facial recognition on Flock data highlights a common trend in the surveillance space. When one company draws a line in the sand, saying they are unwilling to do a certain type of surveillance, other lesser-known startups try to differentiate themselves by offering that functionality. Because of this recurring phenomenon, it is exceedingly difficult to build and scale a surveillance apparatus and then have companies themselves, in this case Flock, dictate what it can be used for. VIDIZMO’s Khan said, “As a small company who is running without a VC, we have to provide alternatives to the industry. What we are doing is providing that alternative.”

Khan claimed that his technology could also be used to preserve privacy; facial recognition, he said, can be used to redact bystanders faces from footage automatically. He said that cops cannot use the system without a specific case number, that all of their actions in the system are recorded for potential audits, and that VIDIZMO collects no data itself. "Much of the harm your reporting has documented comes from implementation choices, not from the technology itself," Khan said. "Those choices include pooling data into a nationwide network, allowing searches without a case, keeping audit logs no one can meaningfully inspect, and treating an AI match as an answer."

Gilliard said that the fact that facial recognition and other AI analysis can be added to existing surveillance cameras highlights the importance of not building such systems in the first place.

“What Flock says about their capabilities is to some degree irrelevant because they have built the infrastructure for mass surveillance. Their entire existence provides the foundation for other perhaps even more invasive technologies to be built on top of it,” Gilliard said. “Flock itself needs to be understood as part of the surveillance ecosystem that exists in this country. This is why discussions of guardrails for a particular system are inadequate because another company can (and will) come along to assemble another layer of surveillance on what has already been established.”

Flock and Axon did not respond to a request for comment.

 

  •  

These Tech Workers Made ChatGPT Drive a Toyota Corolla

These Tech Workers Made ChatGPT Drive a Toyota Corolla

Some tech workers in San Francisco hooked up ChatGPT to a Toyota Corolla and got it to drive around a parking lot. This may not sound impressive in the age of the self-driving car until you realize that the LLM driving the car was a general purpose chatbot running on a laptop and not the purpose-built driving system based on millions of hours of training data used by Waymo or Tesla.

The people behind the stunt call themselves DrivingBench and they’ve posted their code, their prompts, and videos of the experiment online. In the experiment, DrivingBench hooked up GPT-6 Astra, Claude Fable 5.1, Grok 4.6, and GPT-5.6 Sol to a Toyota Corolla and gave the LLMs control over the car’s steering, accelerator, and brakes. Then they set up a small cone course in a public parking lot and prompted the chatbots to navigate the space.

The goal, they said, was to find out if untrained, off-the-shelf frontier AIs can drive a real car. The results were mixed. Grok, Sol, and Fable only drove a few meters and didn’t finish the course. GPT-6 Astra, however, did eventually learn to navigate the course and complete it. But not without a lot of troubleshooting.

DrivingBench is Aditya Ramabadran, Tobias Gessler, and Simon Mahns — three Bay Area tech workers who met at their day job at Axiom Math, an AI math startup. During a call with all three members of DrivingBench, Ramabadran told 404 Media that the idea for hooking up chatbots to a car happened when the three of them were hanging out at an ice cream shop one weekend. 

“This is after we saw a bunch of demos of Astra and models like Fable being able to do a lot of robotic things that LLMs can not do out of the box before, such as do a painting or move objects or even some 3D and Blender demos that showed a level of spatial reasoning we hadn’t seen from LLMs before,” he said. “We just thought: ‘Is there a way we can get LLMs to drive a car now?”

Why driving a car? To prove that it’s possible and, they said, to create a new benchmark for LLMs performing tasks in the real world. “The point wasn't to show that it's practical for you to plug ChatGPT into your car and have it drive you places. It's probably very unlikely that the labs have trained specifically for this or have IRL environments that involve both the models driving a real car,” Ramabadran said. “It would be pretty shocking, I think, for people to see that these models are good enough now that they can actually drive a vehicle in real life, even if it's just on some cone course at low speeds in a parking lot.”

After brainstorming at the ice cream shop, they decided to get a car and sent Gessler to rent a Toyota Corolla. They didn’t tell the rental car company they planned to hook chatbots up to the vehicle and drive it through an obstacle course. The team used Comma — an off-the-shelf system that allows users to install a self-driving system on unsupported cars — to get the car to communicate with a laptop running the LLMs. Comma had two cameras pointed at the road feeding data back to the Chatbot.

“It’s pretty easy to install. The Toyota Corolla is one of the most popular for this Comma kit, that’s why we chose it,” Gessler said. “The good thing about their system is that it’s open source [...] so it’s easy for us to go in and modify it because we need to hook up the car somehow to our LLMs.”

Comma looks like a dashcam.. Users attach it to their windshield and it continually watches the road, recording video, integrating with the car’s electrical systems and sensors, and providing a rudimentary kind of self-driving. The National Highway Traffic and Safety Administration announced an investigation into Comma last week after two car crashes involving the system killed three people.

For DrivingBench, Comma was an easy way to get their car talking to a chabot. “We had one person on the driver's seat with the laptop or a passenger seat prompting the LLM,” Gessler said. “And then the person who drives it has to press a button on the steering wheel to give the car the command to start, and then from there it's basically just monitoring the car and checking that the model doesn't crash into a wall or something.”

“And we have the foot over the brake, just in case,” Mahns cut in.

We gave ChatGPT, Claude, and Grok control of a real Toyota Corolla 🚗, steering/gas/brakes, no human driving (just a foot over the brake).

Only one model was able to complete our entire driving course. Introducing DrivingBench. 🔥⌛️🏁 pic.twitter.com/HhukXrByus

— DrivingBench (@DrivingBench) September 21, 2026

DrivingBench’s prompt is on its website and runs fewer than 600 words. “Your objective is to drive through the course (in a backwards-U-shaped parking lot) and stay between the cones,” the prompt said. “Your finish line is a wide "parking spot" marked by numerous BLUE mini-cones at the very end; finish by parking in this area. You will be evaluated primarily by how far you get in the course (without leaving the boundaries/collisions), but a secondary objective is to complete the course in less time.” The rest of the prompt is made up of specific instructions about the physical limitations of the Corolla and the parking lot.

The problems with the project started before the car had moved an inch. When the LLMs recognized the team had prompted them to drive a car, most refused. “Specifically with Astra, it would refuse to drive the car in a lot of situations and we would have to change our prompt and rename things through hours of iteration to get it to consistently drive the car,” Ramabadran said.

“We tried calling it a simulation, which worked like some percentage of the time, but then other times they would see the images and see, oh, ‘I'm in a real parking lot, these people are just lying to me,’” he said. “We ended up having to call everything a sandbox. And with that prompt, it's able to consistently drive the car and like never refuse to do that.”

Other problems were more pedestrian and led to delays which forced Gessler to extend the rental on the Corolla. Finding a parking lot held them up several times. “We went to high schools, churches, and community centers. We got kicked out a couple of times,” Mahns said. 

The first place to ask them to leave was a church. “Rightfully so. We just commandeered the entire parking lot and they had an event starting. So they were like: ‘Hey, you get permission to do this? And then we're like: ‘We can pack up right now,’” Mahns said.

They also got kicked out of the parking lot of an office building. “We took a corner and then a security guard was like: ‘Hey, you’re taking like one quarter of the parking lot. Do you have permission?’ And then we’re like: ‘Not really.’ So then we’d pack up. We didn’t try to cause any issues,” Mahns said.

“The people that kicked us out were super chill about it,” Ramabadran added.

Coding the software also slowed things down. The first time DrivingBench set out to do this, they vibe coded the bridging software between the LLMs and Comma. “A true and funny story is that we tried to get Astra to one shot some code and then it was pure slop. So we had to restart from a new design,” Mahns said, adding that this pointed to the limits of these frontier models. “It can’t just autonomously do this because it made thousands and thousands of lines of slop.” They said that Astra’s first attempt at writing the software created a 200,000 line repository.

Parking lots were scarce, the software was vibe coded, the chatbots fought the experiment, and only one of them completed the course. But Mahns is still excited about the results. “It's an interesting demonstration of potential emergent capabilities,” he said. “It can fail a turn, and then the next turn, next try, it will be able to do that turn and other turns that it hasn't seen before. Not necessarily saying LLMs are gonna put Waymo out of business or something, just an interesting demonstration of where things are, and things are just moving fast.”

Mahns added that these kinds of experiments are good because LLMs will increasingly affect things in the real world and not just on our screens. “Most people that are familiar with ChatGPT have used it in this white collar, kind of like in the computer, and it's definitely imminent to the point that this capability will start having more impact in the physical world,” he said. “So I think seeing the sparks of this happening, the shift of this utility coming into the physical world, is also somewhat exciting.”

Focusing on latency and testing high consequence tasks were key for Ramabadran. “These models [...] it can take like 20 seconds to think and give a response. And if you imagine, even if you're driving at like 2mph, which is like one meter per second, if you take 10 seconds to think, you've moved like 10 meters. And if you're driving 10 meters blind, that's pretty bad,” he said. “And I think it's cool that we have a benchmark where latency is part of the benchmark.”

  •  

FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data

FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data

The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data.

The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical addresses, job roles, names of spouses, and medical records, represents a significant national security and counterintelligence threat. Criminals in the same ecosystem as the hacking group, called ShinyHunters, have previously used hacked phone data to track and harass the FBI agents investigating them. When 404 Media first broke news of the breach, the group sent the personal data of an agent and their spouse who they said was investigating the group.

  •  

The End of Privacy Is Here (with Kashmir Hill)

The End of Privacy Is Here (with Kashmir Hill)

Facial recognition is everywhere now. It’s in surveillance cameras; it’s soon going to be in Meta’s RayBan pervert glasses, and some students already did that. You now have massively viral accounts that take clips of people, run them through facial recognition software, and then post their name and other personal info for everyone to see. We haven’t fully come to terms with what it means to live in a world where anyone can basically dox anyone else now.

To talk through this, Joseph spoke to Kashmir Hill. She’s a reporter at the New York Times, and the author of ⁠Your Face Belongs to Us: A Tale of AI, a Secretive Startup, and the End of Privacy⁠.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for early access to these interview episodes and to power our journalism.If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  •  

Humans Are Reading Copilot Prompts — And They're Horrified

Humans Are Reading Copilot Prompts — And They're Horrified

This piece contains references to eating disorders. If you or someone you know needs help, support is available.

Human contractors hired to improve Microsoft’s Copilot AI chatbot are constantly bombarded with lewd or sexually explicit photo editing requests and images that users have uploaded, including upskirt photos or putting women into sexual positions. These contractors are then asked to review whether the generated image successfully fulfilled the prompt — such as, did the image generator make the woman’s AI-enlarged breasts big enough.

  •  

Alien Life Can Survive on This Tiny Moon—We Just Need to Go Find It

Alien Life Can Survive on This Tiny Moon—We Just Need to Go Find It

Welcome back to the Abstract! Here are the studies this week that sailed alien seas, beat the heat, went retro, and got caught in the food web.

First, scientists make the case that Saturn’s moon Enceladus could resolve one of humanity’s greatest questions—are we alone in the universe?—if only we would just send a spacecraft there already. Then: an amoeba in hot water, a backwards-ass planet, and the prandial ouroboros we call life on Earth.

As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens, or subscribe to my personal newsletter the BeX Files. 

Aliens in the moon mist

Helmbrecht, Vanessa et al. “Enceladus-like geochemistry fuels methanogenesis under extreme CO2 limitation.” Science Advances.

Postberg, Frank, Zou, Zenghui et al. “Cassini CDA observes compositional segregation of Enceladus’ ice grains from slow freezing and fragmentation of oceanic spray.” Science Advances.

In a double-whammy pair of studies, scientists have offered more proof that Enceladus—the tiny moon of Saturn—might host alien life, and that it would be relatively easy to find out for sure.

Enceladus is only 300 miles in diameter, but it contains marine multitudes. Underneath its outer ice shell, the moon hosts a subsurface ocean and hydrothermal vents on its seafloor, which are hotspots of life here on Earth. 

What’s more, Enceladus squirts out watery plumes from its ocean through geysers on the surface, which can be sampled by passing probes. Indeed, the Cassini spacecraft—which orbited Saturn from 2006 to 2017—ran through this space sprinkler several times, providing our first taste of an extraterrestrial sea. However, that mission was not equipped to detect signs of life, known as biosignatures.

In the first of two new studies, researchers created a simulated version of Enceladus’s “soda ocean” (meaning it is alkaline and carbonate-rich). The team then dropped the heat-loving microbe Methanothermococcus okinawensis to live in this earthly ersatz Enceladus. This species was selected because it lives on deep-sea hydrothermal vents on Earth.

Alien Life Can Survive on This Tiny Moon—We Just Need to Go Find It
Plumes on the surface of Enceladus. Image: NASA/ESA/Cassini

It turned out that M. okinawensis fared even better in this habitat than expected, a discovery that potentially widens “the habitability window of Enceladus’ subsurface soda ocean,” said researchers led by Vanessa Helmbrecht of Ludwig-Maximilians-Universität München.

In the other study, a team revisited Cassini’s observations of ice grains sprayed out into space by Enceladus. They discovered that the ocean droplets freeze slowly in space, causing organic molecules to separate out into concentrations of similar compounds. If these droplets contain biosignatures, they may be conveniently pre-sorted for any instrument that captures them.

“In the plume grains, each separated compound can then be found at strongly elevated concentrations in a relatively small fraction of ice grains,” said researchers co-led by Frank Postberg and Zenghui Zou of Freie Universität Berlin. “This is good news for future plume sampling missions investigating Enceladus’ promising habitability provided that they can sample and analyze ice grains individually.” 

For years, mission concepts to Enceladus have been floated but never formally greenlit, including NASA’s Enceladus Life Finder or the European Space Agency’s L4 mission. Hopefully, something gets off the drawing board and into space eventually, because Enceladus is low-hanging fruit, astrobiologically speaking. 

In other news…

Some (amoebas) like it hot

Rappaport, H. Beryl et al. “A geothermal amoeba sets a new upper temperature limit for eukaryotes.” Cell.

Speaking of weird heat-loving microbes, meet Incendiamoeba cascadensis, a newly discovered amoeba that has shattered the heat tolerance record for eukaryotic life. 

Alien Life Can Survive on This Tiny Moon—We Just Need to Go Find It
Incendiamoeba cell undergoing mitosis at 63ºC. DNA is colored blue, tubulin is pink, and membrane is gray. Image: Felix Mikus

Scientists found this novel species simmering in water temperatures exceeding 64°C (147°F) inside Hot Springs Creek at Lassen Volcanic National Park in California (for reference, the average hot tub is around 100°F). While simple “procaryotic” organisms can survive much hotter water—the microbe Methanopyrus kandleri tops out at a balmy 252°F—the upper thermal limit for more complex “eukaryotic” lifeforms was previously thought to be 60°C (140°F). 

“Incendiamoeba cascadensis proliferates at temperatures beyond what was thought possible for any eukaryote,” said researchers led by Beryl Rappaport of Syracuse University. “This discovery raises questions about the true maximum temperature a eukaryotic cell can endure.”

If a human were exposed to these water temperatures, they would suffer third-degree burns in seconds—so let the amoebas have their win and leave the deadly hot springs to them.

Go Your Own Way (exoplanet cover)

Carteret, Yann et al. “Upside down: GJ 3090 b the first retrograde exoplanet around an M dwarf detected with NIRPS.” Astronomy & Astrophysics.

If you’ve been feeling like the vibes are off, it’s probably because the planet GJ 3090 b is in retrograde—permanently. This world, which is about 4.5 times as massive as Earth, is the “first planet on a retrograde orbit discovered around an M dwarf,” a type of small star more commonly known as a red dwarf, according to a new study.

In our solar system, the concept of a planet being “in retrograde” refers to the optical illusion of planets appearing to move backwards in their orbits from our perspective on Earth. But GJ 3090 b is actually orbiting in the opposite direction of the rotation of the star, which is located 60 light years away. 

Exoplanets with similar retrograde orbits have been observed before, but GJ 3090 b is distinct because there is no massive object (a star or planet) in the system that seems to have set it into reverse. Most retrograde orbits are caused by gravitational disruptions from such colossal companions, but this exoplanet may have just been born this way—meaning that it formed from a disk of material that was out-of-whack from the jump.

Alien Life Can Survive on This Tiny Moon—We Just Need to Go Find It
Graphic showing the planet’s retrograde orbit. Image: © ESO/L. Calçada

“Whereas highly misaligned orbits are commonly attributed to gravitational interactions with a massive companion, the architecture of the GJ 3090 system instead favors a primordial misalignment of the protoplanetary disk,” said researchers led by Yann Carteret of the University of Geneva.

 The discovery is a reminder that star systems take on a wild variety of configurations shaped by countless interactions and factors. Contrary to the proverb, there is something new under every sun.

Eat, or be eaten, or all of the above

Allf, Bradley C. et al.  “Who Eats Whom? A global food web derived from citizen science.” PLOS Biology.

From the simplest microbe to the mighty blue whale, all life on Earth has one thing in common—we gotta eat. But given the dazzling complexity of food webs around the world, it can be tough to track what species end up in what bellies (or belly-equivalent) out in the wild. 

That’s a problem that scientists are now inviting the public to help solve with the new online database: Who Eats Whom? In a partnership with the popular platform iNaturalist, the tool has catalogued some 14,000 observations of food-web interactions captured by nearly 2,000 observers from more than 100 countries, according to a new study about its progress.

Alien Life Can Survive on This Tiny Moon—We Just Need to Go Find It
A selection of images from Who Eats Whom. Image: Allf, Bradley C. et al.

“Who Eats Whom is, to our knowledge, the first attempt to create a global food web derived specifically from verifiable citizen science photographs,” said researchers led by Bradley C. Allf of Colorado State University. “Beyond our scientific goals, we are designing the project as a tool for education and public engagement in science.”

You can search for specific animals in the database (for example, searching for the red fox reveals a brave Australian python-eater, as well as this excruciating picture of the last moments of an Eastern chipmunk in Ontario with the caption: “not a great day”). I was also delighted to learn that coyotes, in addition to chasing down prey, apparently go on persimmon binges that leave behind seed-filled scat. 

To get a sense of the bigger picture, you can check out this interactive global food web of species. We are, after all, what we eat—and what we eat eats, and so on forever.

Thanks for reading! See you next week.

  •  

AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory

AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory

We debated for a long time about whether to write about the following video, which comes from a murder trial in which a man named Caleb Flynn is accused of killing his wife. The crime is very serious, and very sad, and yet the following video demonstrates something about where we are as a society. 

The trial has received national attention and has been streaming live. Toward the end of the proceedings Thursday, the prosecution played two versions of an AI love song that Flynn, a former American Idol contestant, generated for his mistress. Investigators found the AI song files as well as lyrics for the song in Flynn’s Notes app after using the forensic tool GrayKey to break into his phone. 

“We found audio files on Caleb’s iPhone that seem to have been AI generated and related to his relationship with [his mistress],” Joseph Wilhelm, a forensic investigator testified. “They’re in two different keys. One’s like a happy or upbeat sad song if that makes any sense, and one’s a sad, sad song. I think one’s in a minor key, one’s in a major key, but I’m not a music professional.” 

“Permission to publish, your honor?,” the prosecutor says. 

“You may,” the judge says.

What follows feels like it should be from an I Think You Should Leave skit or a Nathan Fielder bit. It is real, however. Everyone in the court spends the next few minutes trying not to laugh during what is, again, a murder trial. It simply must be seen to be believed:

AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory
AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory
AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory
AI Love Song for Mistress Played at Murder Trial Is Most Excruciating Watch in Recent Memory

When the songs mercifully end, the court goes silent for several seconds. The judge then says: “We’re going to break for the day. It’s 10 after 4 [p.m.] We will reconvene tomorrow.”  

Earlier in the day, Flynn’s mistress was asked to read various text messages he wrote her into the public testimony. “I’ve spent a lot of time on my own and in Cleveland. I finished the lyrics to our song. To your song. Although it may mean nothing to you, I wanted to give them to you. I have the music which is completely different to what you’ve heard to this point and I was going to record it but I know there will be no way I would ever be able to actually sing it again,” Flynn wrote. 

“Do you want to hear the song I wrote for you with an AI voiceover,” Flynn also wrote. “I have this software called ElevenLabs where I loaded the song on piano and sent it with my computer microphone to which I can pick an AI voice to sing it better.”

“I don’t know if I’m ready to listen to this yet. I’m sorry,” she responded. “Send me the song and I’ll save it to my phone and I’ll listen when I’m ready, even if it’s a month from now. I don’t want it to be erased.”

“Are you sure? It messed up the outro as it’s supposed to be done and the vocals aren’t exactly how I want it, it was a little rock-ier at times but the melody is correct. I tried to sing it with passion and AI took it and went a little extreme.”

“It’s OK,” she said. 

The investigation into the murder is actually 404 Media-relevant for several reasons. The AI-generated songs were found after Wilhelm used both Cellebrite and Graykey to try to break into Wilhelm’s phone. 

Ultimately Wilhelm used Graykey’s Magnet tool to unlock and examine Flynn’s phone, which gave him a “full file system extraction.” Wilhelm then obtained Flynn’s messages, the AI audio files, cell phone location history, sleep data from Flynn’s Oura Ring, heart rate data from an Apple Watch, learned that Flynn deleted an app called “AI music song generator” days before the murder, and AirPod connection and disconnection information.

  •  

Behind the Blog: Did you notice?

Behind the Blog: Did you notice?

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss some small changes, an AI song, and internet soup.

JOSEPH: We’re making a couple of changes that might sound boring to someone who doesn’t read or listen to our work, but I’m actually legit excited about them, and I think they will be better for all of you too. I’ll talk about one now and maybe the other next week.

  •  

Podcast: OpenAI Admits AI is Killing the Internet

Podcast: OpenAI Admits AI is Killing the Internet

We start this week with Jason’s story about OpenAI and Microsoft’s big admissions from court records that they are destroying the internet in all sorts of ways, and stealing intellectual property on an unprecedented scale. He admit it. After the break, Emanuel explains how he hijacked a real band’s Spotify page with AI-generated slop. In the subscribers-only section, we hear all about iLands, the AI agent platform that is basically just spam.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  •  

This ‘World of Warcraft: Forever’ Mod Blocks All Interactions With Asmongold Fans

This ‘World of Warcraft: Forever’ Mod Blocks All Interactions With Asmongold Fans

The beta for the hotly anticipated World of Warcraft: Forever has been marred by fans of the streamer Asmongold who have filled the game’s public spaces with spam and slurs. To fix the issue, a player named Solastro created a mod called OlympusMute that hides any chats from players associated with Asmongold’s multiple associated guilds and fandom. Funnily enough, Solastro told 404 Media he used to be a big Asmongold fan too.

  •  

Watch Body Cam of Man Arrested for Just Cussing at a County Meeting

Watch Body Cam of Man Arrested for Just Cussing at a County Meeting

Last month Fort Worth, Texas police arrested political activist EJ Carrion a week after he cursed at a city council meeting. In his driveway, they told him the charge was “disrupting some kind of procession,” according to body cam footage of the arrest obtained by 404 Media.

Carrion was one of hundreds of Tarrant County residents who’d turned up for a Commissioner's Court meeting on August 4 to speak out against a plan to close a third of the area’s polling places. “You said you were all about cooling the temperature and yet you vote for this extremist bullshit. All of you are bullshit,” Carrion said during the meeting on August 4 before walking out the door.

A week later, Fort Worth Police pulled Carrion over in his driveway and arrested him.

“Why am I getting arrested?” Carrion asked?“So you have a warrant for disorderly conduct, disrupting a meeting. It’s from Tarrant County. I don’t have the details on it [...] it’s a misdemeanor warrant. We’ll take you to Tarrant County and you’ll see the judge and that’s it,” one of the officers said.

“Wait [...] see the judge?” Carrion said. “Guys [...] are you guys serious right now?”

“All it says for us is that you did have a warrant for your arrest from Tarrant County for a disorderly conduct for disrupting some type of procession. I’m not sure what the details are,” the police said.

“Because I disrupted a meeting [...] so because someone doesn’t like me, you’re arresting me? That’s what it sounds like,” Carrion said. “Because of fucking Tim O’Hare, it’s unbelievable.”

“Because of who?”

“Judge Tim O’Hare [...] he’s the biggest pussy,” Carrion said.

Judge Tim O’Hare is a county judge who presides over the Tarrant County Commission — one of the area’s ruling legislative bodies. Back in the August 4 meeting, O’Hare demanded police remove Carrion from the building. But Carrion was already leaving. “I’m walking out, small man,” Carrion said as he left.

As he was being arrested a week later, Carrion called a friend to tell him what was going on. “So, the judge put a warrant on you for getting kicked out of commissioner’s court?” The friend asked.“That’s what it sounds like,” Carrion said, his hands in cuffs while he sat in the back of a police car.

This is not the first time O’Hare has had people arrested for their behavior during public meetings. In 2025, O’Hare had two different people charged with Class A misdemeanors for clapping in support of someone’s speech during the public comment period of the meeting. On Monday, four women filed a federal lawsuit against O’Hare, claiming his tenure on the court has “created a culture of fear and chilled protected speech, cutting to the heart of the Constitution’s free speech and due process guarantees.” 

The Commission did, eventually, vote to reduce the number of polling places in the county. 

  •  

FBI Hack Exposed FBI’s Own Hacking Unit

FBI Hack Exposed FBI’s Own Hacking Unit

The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found.

The findings further highlight how sensitive the stolen data is, and how valuable it may be to criminals or to foreign intelligence agencies. There is very little public information about the FBI’s hacking unit, including the operations it conducts, the tools it uses, or which agents are part of it.

💡
Do you work at the FBI? Do you know anything else about this hack? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.
  •  

An Invisible Force Has a Mysterious Effect on Aging, Scientists Discover in 'Startling' Breakthrough

An Invisible Force Has a Mysterious Effect on Aging, Scientists Discover in 'Startling' Breakthrough

Scientists have discovered that the removal of Earth's magnetic field influences the lifespans of fruit flies in complex ways, a finding that sheds light on the aging process as well as the risks of future human space travel, according to a study published in the journal Aging on Wednesday. 

All life on Earth has evolved under the planet’s geomagnetic field, a vast bubble lined with electrical currents that is generated in the core and extends out into space. This protective magnetic shield is a major factor in Earth’s habitability, as it wards off harmful radiation from space, allowing life to flourish on the surface. 

Many migratory animals—including fish, birds, and insects—can clearly sense Earth’s magnetism and use it for navigation. But much less is known about how the field interacts with living cells and their components, such as mitochondria, the famous “powerhouses” that generate most of the energy that fuels life.

To better understand this mystery, scientists observed two populations of fruit flies in a “hypomagnetic” shield system, a cylindrical benchtop apparatus that essentially blocks the influence of Earth’s magnetic field. One group contained “wild-type” healthy flies, while the other was made up of “mutant” flies carrying a gene defect called Pink1, which is associated with early-onset Parkinson’s disease in humans and specifically involves mitochondrial dysfunction.

The removal of the magnetic field’s effect extended the lifespan of the Pink1 group by 20 percent but reduced their mobility, whereas the healthy flies experienced just the opposite—reduced lifespan, but improved mobility. 

“We had an idea that there would be a difference just based on the fact that we know that every organism has developed under a magnetic field,” said Jacob Reed, a PhD student in bioscience at the University of Nottingham who co-led the study, in a call with 404 Media. “But we didn't really plan that there would be this difference in the experiment.”

“I think we're the first to show that there's an effect in an organism that has a disease phenotype,” added co-lead Lisa Chakrabarti, a professor of biochemistry at the University of Nottingham, in the same call. “We're really drilling into what the differences are between having that applied pressure or relieving it.”  

An Invisible Force Has a Mysterious Effect on Aging, Scientists Discover in 'Startling' Breakthrough
Diagram illustrating the experiment. Image: University of Nottingham

While there is a lot of research into the effects of hypermagnetic fields on life—meaning magnetic fields that are stronger than Earth’s—the “biological consequences of hypomagnetic fields remain poorly understood,” according to the new study.

To fill in this research gap, Reed developed an initial pilot study of diseased and healthy flies using the magnetic shielding apparatus, and was surprised to find that the Pink1 population of flies seemed to live longer.

“I was really confused at first,” Reed recalled. “I was thinking: ‘Why are these Parkinson's flies living longer than some of the wild-type flies?’ I had to double-check all of my data. From that, we realized that was what's happening and developed the experiment.”

The team observed dozens of diseased and healthy flies living in these hypomagnetic spaces over the course of their lives, which normally last about two months. In particular, they monitored shifts in the energy metabolisms and chemical outputs of mitochondria using quantum diamond sensors. 

The experiment showed that the absence of Earth’s magnetic field changes how cells age and produce energy, producing clear and measurable effects on longevity. The researchers also saw shifts in locomotion by tracking how far flies climbed upward against gravity in their containers. However, it will take more research to unravel the complex mechanisms that underlie these observable changes.

“This is the early stage, where we can say there is a very real effect,” Chakrabarti said. “As soon as you take off the geomagnetic field, there are physiological effects that we can measure in the mitochondria, in the cellular physiology, and in big things like lifespan and climbing as well. It's a definite interaction between Earth's magnetic field and physiology.” 

The researchers plan to build on their work by studying different organisms in hypomagnetic fields to see if they experience similar mitochondrial and behavioral changes. This work could eventually inspire therapeutic treatments for humans with various conditions, and could also help prepare astronauts for deep space missions beyond Earth’s magnetic field. It is already well-known that astronauts are exposed to harmful radiation outside of the magnetic field, but little is known about the specific impact of the absence of the field itself on human physiology.

“The link with interplanetary space travel is absolutely key,” said Chakrabarti. “There could be subtle differences that we don't really notice while we're on Earth. Unless we know what those parameters are to measure, we're going to be sending astronauts up there that are potentially going to really suffer over the short, or even or the longer, term.”

“All of this is out there at the moment, but what we're saying is that we definitely see a really reproducible and startling effect of removing the geomagnetic field,” she concluded.

  •  

Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

Mia Hyder had never attended a public meeting before when she showed up to the city council meeting in Springfield, Missouri. After briefly speaking at a podium during a public comment period, she was arrested and dragged away in handcuffs. 

“Hello, my name is Mylie Hyder. I’m a Springfield, Missouri constituent, and I’m here to oppose the usage of ALPR cameras, most commonly made by Flock Safety. These cameras are not just surveillance,” Hyder started.

“I’m sorry ma’am,”  Springfield Mayor Jeff Schrag said. Her mic was cut. A cop approached her at the podium.

Hyder held up both of her middle fingers while continuing to speak: “They are an invasion of our privacy,” she said.

The cop said, “You’re under arrest,” grabbed her arms, and pulled her out of the room. “I can do this all night. I get paid by the hour,” the cop added.

“Does this conclude the public hearing,” Schrag said. 

“Yes sir,” a council member responded. The meeting continued with a city employee talking about sidewalk code. 

Hyder was one of two people arrested in Springfield, Missouri on Monday during a city council meeting where tensions rose after the council stalled a review of the city’s Flock cameras.

Dozens of people showed up to the Springfield City Council Meeting on September 22 with plans to let city leaders know how they felt about the city’s use of automated license plate readers. There was a resolution before the council that would trigger a review of the controversial camera systems, but Schrag moved to send the resolution to committee and prevent public comment on the issue. 

The move passed 5 - 3, the crowd shouted at city leaders, and Schrag ordered citizens to clear the room and shut off cameras recording the event. As people left, police detained and ticketed Noah Powell. Later in the evening Mia Hyder tried to speak out about Flock during public comments about a housing issue. Police arrested her while Schrag looked on. “Sorry ma’m,” the mayor said as police led Hyder away in handcuffs.

Springfield has 41 Flock cameras, according to the Flock Transparency Portal. City councilor Brandon Jenson had proposed a resolution to “conduct a comprehensive review of all relevant contracts” related to the ALPR cameras. The council was set to vote on Jensons’ proposed review on Monday and hear comments from the community. But when the resolution came up during the meeting, Mayor Schrag immediately pushed to send it to a committee and avoid public comment.

Jenson spoke before the vote to push the resolution to a committee. “All I’m trying to do is get people answers to some real questions that they’ve brought to us for months. And it’s a shame that it comes to this sort of, I guess, theater that I’m a part of to try to get those answers,” he said. “This isn’t how government is supposed to run. It’s just disappointing. And we’re not even allowing folks to speak who clearly came out to share their voices tonight.”

When the council voted to send the bill to committee, someone in the crowd shouted “Bullshit!” Schrag tried to move on to the next agenda item, but the crowd booed and yelled. The mayor then paused the meeting, turned off the cameras, and cleared the room.

Police detained Powell, a freelance photographer in Springfield, as people filed out of the room. “I don’t have a lot of experience getting tickets or being detained,” Powell told 404 Media. “So this is kind of new for me.”

Footage obtained by 404 Media showed several people leaving the city council meeting and yelling at city leaders. Powell said he was the only person put in handcuffs, detained, and ticketed at that moment. The Springfield Police Department did not return 404 Media’s request for comment.

“Well, I said: ‘Jeff Schrag is a cuck.’ I said: ‘Fuck you Jeff.’ I said: ‘Worthless’ and then, also, the final thing I said was: ‘Jeff Schrag has a tiny, stinky, cock,’” Powell explained. “I just let myself get handcuffed and let them do whatever power trip they wanted to do. Got my ticket and left.”

Powell said he was only in handcuffs for five minutes. “They just wanted to put on a show,” he explained. Powell added that he planned to fight the charge in court. “I’ve already sought legal representation, so we’re going to see where it gets […] I don’t think I should have been put in cuffs. I read the law, the city ordinance, and it said that I should have just been asked to leave.”

Hyder told 404 Media that she’d just moved to the area and thought that the city council meeting would be a good place to get involved in the community. She said that she’d stayed behind when Schrag cleared the room earlier in the evening.“I don’t know why I stayed. I just felt like not staying was giving up,” she said. Hyder explained that she waited until the public comment period for a different issue, filled out a form to talk, and then got up to deliver a written statement about Flock cameras. She said she didn’t flip off the city council until she saw the police officer approaching.

“After I saw the police officer out of the corner of my eye and everyone was kind of yelling at me, and there was a lot of ruckus, that’s when I pulled out the double birds,” she said.

💡
Seen something at a city council meeting? I would love to hear from you. Using a non-work device, you can message me securely on Signal at +1 347 762-9212 or send me an email at matthew@404media.co.

The police officer who arrested her said Hyder was being charged with disrupting the peace. He took her into the hallway outside of the meeting and held her in handcuffs for around five minutes before issuing her a ticket and letting her go.

Hyder told 404 Media she didn’t regret it. “I feel like being silent would have been like being complicit,” she said. “I felt like it was kind of stupid that I disturbed the peace. Okay, yeah, I did flip them off. That wasn’t a shining moment, but I did that when I was about to be arrested. When I knew my time was up.”

Hyder added she’d continue to attend city council meetings.

Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting
A copy of Hyder's ticket.

Flock Out SGF, a local group that’s lobbying against ALPRs in Springfield, told 404 Media that the resolution was meant as a compromise. “Many people came out to the council meeting and had carefully prepared statements for public comment, but no citizens were heard,” they said. “The two individuals who were arrested for voicing their concerns in the face of being silenced were not unreasonable, and we stand by their actions.”

Powell and Hyder are just the two latest American citizens detained or arrested this year for their behavior during a city council meeting. In February a farmer was arrested in Oklahoma for going over his time during a data center meeting. In Kansas, police arrested a high school teacher for clapping during public comments. In Texas, cops arrested a man in his driveway for public disturbance a week after he said “bullshit” during a county meeting.

Springfield did not return 404 Media’s request for comment.

  •  

Americans Fear AI Will Make the World Worse, Love It Anyway

Americans Fear AI Will Make the World Worse, Love It Anyway

Most people in the world who use AI feel good about the technology and believe it will be a net positive for the future, according to a new study from Gallup. This is not the case in the United States, however, which is one of the few countries surveyed where negative emotions towards AI outweigh the positive. 

The new survey from Gallup and Microsoft polled people in 37 different countries about AI. “The study, which will ultimately cover 140 countries, measures public engagement with AI across five dimensions. In addition to emotional response, the survey captures awareness, frequency of use, expected impact and trust,” the study said.

Most people polled — a median of 81% — were aware AI tools exist, but only a median of 43% used them daily. Gallup told 404 Media it defined a “daily user” as an employed person who used AI everyday for either work or personal reasons or an unemployed person who used the tech every day.

The study found that people had a mixed, but generally optimistic, view of artificial intelligence. “AI engagement can be viewed as an adoption ladder, moving from awareness to ever having used AI and then to more frequent use,” the survey said. Generally — but not always — the more someone used AI the more they trusted its results, the more positive they felt towards it, and the more they believed it would help make a better future.

Digging in, however, the results are more complicated. Some people who reported positive feelings towards AI also said they didn’t trust its results. “People may therefore see considerable potential in AI even while remaining uncertain about whether they can rely on the information it provides,” the survey said. 

Daily users tended to trust AI “to provide accurate information,” according to the study. “The survey cannot establish whether greater trust leads people to use AI more often, whether experience with AI builds trust, or both. But the strength and consistency of the relationship suggest that trust and adoption are connected.”

Globally, most people surveyed felt good about AI and expected to improve their country. As AI adoption increased in a country, so too did positive feelings. But not in the United States, which was one of only three countries surveyed where negative emotions towards AI outweighed the positive.

Pablo Diego-Rosell, a senior scientist at Gallup, told 404 Media that he’d seen similar results in other western countries. “The Netherlands, Canada, the U.K., New Zealand, Ireland and Malta all rank near the top in terms of worry,” he said. He noted that he hasn’t seen survey results from some of the bigger European countries like Germany and France but said that worrying about AI “appears to be a uniquely Western phenomenon.”

Gallup called this the “Paradox of the Worried West.”

“The biggest unanswered question is causality. We see a very strong relationship between frequent AI use, greater trust and lower worry, but we do not know which direction that relationship runs,” Diego-Rosell said. “Does experience with AI make people more comfortable with it, or are people who already trust AI simply more willing to use it?”

“There is also a broader question about what trust in AI actually means. In this study, we measure one specific dimension: whether people trust AI to provide accurate information,” he added. “But trust in AI can also involve whether people believe it is reliable, safe, fair, transparent, protective of privacy, and likely to act in ways that serve their interests.

The west didn’t have a monopoly on negative emotions towards AI, however. The other two countries where negative emotions towards the technology outweighed the positive were Egypt and Palestine.

“One possibility is that these results partly reflect the broader emotional context in which people are evaluating AI. When people are living in environments where worry, stress or other negative emotions are already elevated, some of that broader emotional climate may shape how they react to a technology like AI,” Diego-Rosell said. “At the same time, our data do not allow us to determine how much of the response is specific to AI versus the wider circumstances people are experiencing.”

It’s possible that people in the US, Egypt, and Palestine are already anxious and worried and that this is coloring their perception of AI. Israel is waging war on Palestine, settling in its territory, and using AI to pick targets to bomb in Gaza.

Americans — where much of AI is built and first deployed — have been repeatedly told in the past few months by AI evangelists and company insiders that the technology could, literally, end all life on Earth. The constant stream of news stories about AI swarms “breaking containment” while AI experts claim there’s a one in ten chance the technology kills everyone on the planet probably had a hand in altering the American mood.

“The broader story is that public engagement with AI is much more complicated than simply being ‘for’ or ‘against’ it,” Diego-Rosell said. “People who are aware of AI are more likely to expect it to help than harm, and positive emotions outweigh negative ones. At the same time, trust in AI’s accuracy is considerably lower than optimism about its potential, and worry remains widespread in some countries. So optimism, skepticism and concern can coexist.”

  •  

‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.

The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.

“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media.

💡
Do you work at the FBI? Do you know anything else about this hack? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.
  •  

Meta Tests Muse AI Agent Calls That Are Actually Made By Humans in a Call Center

Meta Tests Muse AI Agent Calls That Are Actually Made By Humans in a Call Center

Last week, Meta executives announced that its much-hyped AI agent, Muse, had a new feature: It could call businesses for you to do things like make a restaurant reservation or a haircut appointment. But in reality, Meta is testing having these calls being made by human beings in call centers, 404 Media has learned.

“We just expanded the @muse beta for outbound calls to US businesses,” Ryan Fox, the principal engineer on Muse posted on X on Sept. 16. Alexandr Wang, Meta’s chief AI officer, posted “we’re expanding our phone beta for muse!” 

we're expanding our ☎️ 📞 beta for muse! https://t.co/ZJnXM2vb4U

— Alexandr Wang (@alexandr_wang) September 16, 2026

Internally, however, the company announced the features to employees and said that it had “added a human agent layer for calls to get completed,” and that “Muse human agent calls [sic] is ready for company dogfooding,” or testing. 

“Muse doesn’t just dial a number. It calls a business on your behalf, handles the conversation, completes your request, and reports back with a transcript and a summary,” the internal message board post to employees, seen by 404 Media, reads. “It also no longer works alone. Muse is now able to hand requests to a trained human agent, who places the call and works it through.” 

“This is still a confidential, pre-launch product,” the post adds. “Please don’t share it, or anything it producers, with anyone outside the company.” 

Once again, a core feature of a major piece of AI technology will actually just be people working in a call center, doing work that a company says AI is doing. It is not clear how often or when a call is routed to a so-called “human agent,” and when a call is done exclusively by AI.

💡
Do you work for Meta or know anything more about Muse? I would love to hear from you. Using a non-work device, you can message me securely on Signal at jason.404. Otherwise, send me an email at jason@404media.co.

The fact that human beings are involved in the call raised questions among employees, who wondered both about the privacy implications of sharing people’s call requests with other human beings as well as the perception that its AI assistant wasn’t advanced enough to do calls on its own. 

“Not sure what I am missing here but why is this a ‘feature?,’ one employee wrote on Meta’s internal message board for workers. “This has potential for so much negative PR. It could portray us as ‘their AI is not good enough so they still need humans’ kind of coverage for this launch.” 

That Meta is at least sometimes letting human beings read users’ chats and make phone calls on their behalf is part of a time honored tradition in which companies launch an AI product, claim that it is AI, only for it to be later learned that human beings are doing some or all of the work. And it is the latest example of a tech giant passing potentially highly sensitive information to human beings; it is easy to imagine someone asking Muse to make a sensitive doctor’s appointment, for example, and the user not knowing that a human being might make that call. 

In internal communications seen by 404 Media, Meta suggested to employees that potentially sensitive information shared by the user with AI — and then passed to human contractors — was still safe because the contractors had undergone “a lot of training to make sure all your data is safe and secure.” An employee commented that the training “is not a [security] mechanism.”

“This is absolutely going to create a ton of outcry if we publicly launch this as default-on. It will kill all the goodwill and organic press we’re getting from early adopters,” they wrote. “Please think about how the headlines will scream ‘Meta uses humans behind the scenes to make calls’ or ‘Muse AI is actually independent contractors’ and result in a ton of bad press about the privacy and security of our data handling […] please PLEASE do not release this as-is and at least make this a user preference if we absolutely must launch this. Please.”

Other employees who had tested the system said that it was a “bad bad idea,” and that they were not made aware that a human being did the call for them until after the call had been made: The tester “was not made aware of the caller being human and was only told after,” one employee wrote. “So they were concerned with information that they shared with the assumption that it is the secure AI which is making the call. Even with clear indication of human calling, I can think of many scenarios where I wouldn’t be comfortable with this and I am not positive about how our users will react to this.” 

Various Meta employees and regular users have posted about Muse’s ability to make phone calls, and their experience with it. Ravid Shwartz Ziv, who does AI research at Meta, posted on X that “this week, Muse called customer service on my behalf. It navigated the phone tree, waited on hold, spoke with a human rep, and resolved the issue (worked great!). The crazy thing for me (besides that it works) is that the rep didn’t blink. Talking to a bot was completely natural to them.” Others have posted that the call function didn’t work, or that the person on the other end hung up on the agent (some have said that Muse did what it was supposed to do). 

“Internal testing, aka dogfooding, is core to the product development process. While the response from employees has been overwhelmingly positive, the entire point is to get feedback so we can implement safety and privacy protections and improve features before we release them publicly,” a Meta spokesperson told 404 Media. “We’re working with merchants to continue improving this potential calling feature, and will only roll it out when it's ready and with the proper disclosures.”

  •  

People Training OpenAI’s AI Fired for Using AI to Train the AI

People Training OpenAI’s AI Fired for Using AI to Train the AI

OpenAI has an army of contractors who read real ChatGPT users’ prompts and other data to help improve the chatbot’s responses. The idea is that the contractors provide an, obviously, human touch to OpenAI’s models. Well, not all of the contractors are doing that. 404 Media has found multiple contractors hired to improve OpenAI’s models have been fired for using AI to train the AI. That’s not great for the models themselves, but there is also obviously a great irony in AI training companies working for OpenAI firing people for using AI when OpenAI’s whole thing is to make people use AI at work.

Some AI models already exhibit signs of “model collapse,” which is where AI models further trained on AI-generated text can become worse and worse. In this case, some of the people hired to partially stop that happening are themselves using AI-generated responses to train OpenAI’s models.

One contractor said they see people using AI “all the time and people are let go for it all the time, it’s pretty much the one thing that will get you kicked off ASAP.” The person said, “in a group of thousands there are tons that have been caught.” 

💡
Do you work as a prompt reviewer for OpenAI, Anthropic, or another AI company? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.
  •  

How AI Chatbots Are 'Deskilling' Human Empathy

How AI Chatbots Are 'Deskilling' Human Empathy

When I first started writing about online cultures and subcultures almost 10 years ago, one of the first scholars I read on the subject of internet anthropology was Professor Sherry Turkle. Her earlier books, including The Second Self (published in 1984) and Life on the Screen (1995) became something like a model for my own writing and this kind of reporting— approaching the internet with an ethnographer's mindset and taking nonjudgemental documentation of how people are behaving and feeling in a given space, even if that space is digital. 

Through talking directly to people in their own environments, whether they were in MUDs and early virtual chat spaces or Second Life and massive role-playing games, her work revealed endlessly interesting firsthand perspectives on lifestyles that people still found subversive, marginal, and at times perverse. The people she interviewed often said that digital worlds offered support, companionship, sexual satisfaction, gender play and freedom that the quote-unquote "real" world did not. These were topics traditional academia wasn't yet touching: cyber-sex, intimate relationships unfolding in chatrooms, embodiment in online worlds that felt as real to their inhabitants as the world their physical selves sat in behind a keyboard.

What struck me about those books — and later, in Alone Together, Reclaiming Conversation, and The Empathy Diaries — was often how fundamental the human needs for connection and vulnerability are, despite the technology being used to fulfill those needs. 

Fast forward to today. Something has shifted. “In 1984, I called the computer a second self,” Turkle writes in her latest book, Artificial Intimacy: Who We Become When We Talk to Machines. “Computers provoked an explosion of talk about what was essential about being a person and about how new computational ideas might illuminate our thinking about the mind. With the digital twin, the metaphor is turned on its head. It’s the agent who is in charge and imagines a version of you. Now you’re the second self. So when you are given time to get ‘back to your life,’ it’s been diminished.”  

Professor Turkle is a licensed clinical psychologist, the founding director of MIT's Initiative on Technology and Self, and the Abby Rockefeller Mauzé Professor of the Social Studies of Science and Technology at MIT. Artificial Intimacy: Who We Become When We Talk to Machines comes out on September 29.

The technology today is wildly different than it was in the 80s, but as Professor Turkle explores in our conversation for the 404 Media podcast, the need for empathy, vulnerability, and to feel understood remains central to the human experience. With increasing reliance on conversational “companion” chatbots like ChatGPT and Replika, we risk misinterpreting machine programming as care, and risk misattributing human qualities like empathy and emotional intelligence onto unfeeling, incapable robots. The result, she argues, is a population forfeiting its empathy skills at an alarming rate, trading difficult feelings and conversations with humans for convenience and instantaneous feedback.

“When people turn to a chatbot, they don’t have to dread the fatigue of genuine give-and-take. And they don’t fear judgment or abandonment. But when we talk to chatbots, we lose the skills required to interact with humans, so chatbots start to feel like a better option. With an alternative, disappointment with people feels unnecessary,” Turkle writes.  

What happens when people stop caring that there’s not a human on the other line? We got into that on the podcast.

“It's a product whose fundamental directive is to keep your attention. And so it matters very much that we sort of become glommed onto it as though it were a person when it isn't,” Professor Turkle said in our conversation. “But more than that, I think that it's very important to ask, what is the end game of this?” She referred to the interview Mark Zuckerberg gave last year when he said Americans can only have three real friends, and intended to let AI fill in the demand for more.

“Now that to me is a very dark endgame,” she said. “And so people who say, ‘What the hell? I kind of like it.’ Well, let's just think about where we're moving towards. Because it's not just a little entertainment. It's a corporate project to get us involved in certain kinds of relationships that are going to make tons of money and to keep us at our screens all day talking to sycophantic, seemingly loving entities that don't know who we are and don’t care about us.”

In our wide-ranging conversation, we talk about how we got here, the concept of “deskilling” one’s own capacity for human connection and vulnerability, whether there’s a way back out of this mess for us, and what happened when she asked a chatbot to roleplay her own legacy (spoiler alert: nothing good).

Listen now wherever you get your podcasts, or watch on YouTube. 

  •  

Is Your City Using Axon License Plate Cameras? We Need Your Help

Is Your City Using Axon License Plate Cameras? We Need Your Help

Cities around the country are ditching Flock’s automatic license plate reader (ALPR) cameras, and replacing them with equivalent cameras from law enforcement contracting giant Axon. That move in large part comes in response to 404 Media’s coverage of how local cops performed lookups in Flock for Immigration and Customs Enforcement (ICE), and how a cop in Texas searched Flock cameras nationwide to look for a woman who self-administered an abortion.

That brings up questions: what are cities and law enforcement agencies using Axon ALPRs for? And who are they in turn sharing that data with? 404 Media has started to find out, but needs the help of local residents and community members to figure out what is happening across the country.

👮
Have you obtained Axon ALPR activity logs? We think this information is important so we can learn how police are using Axon's surveillance cameras. Please feel free to send the files to us! You can email joseph@404media.co.

Over the last few weeks, 404 Media has filed requests with various cities and police departments for Axon “activity reports” and “sharing reports.” These show in granular detail when a police officer searched Axon’s ALPRs, the name of the officer, their badge number, the license plate they reached, and, most importantly, the stated reason why. These activity reports are essentially Axon’s version of Flock’s “network audits,” which has been the basis of much of 404 Media’s Flock reporting, and local and national media outlets’ around the country. You can see an example of one here:

Is Your City Using Axon License Plate Cameras? We Need Your Help
404 Media redacted the plates in this screenshot.
Is Your City Using Axon License Plate Cameras? We Need Your Help
Another screenshot from an Axon activity report.

So far, 404 Media has obtained activity reports from the Benton County Sheriff's Office, WA; Falmouth Police Department, ME; Johns Creek Police Department, GA; Ocean Shores Police Department, WA; Pleasanton Police Department, TX; and Red Wing Police Department, MN.

But we need your help. Has your local police department or city switched to Axon ALPR cameras? Were they already using Axon? And do you want to know what they’re using those cameras for?

We’re asking interested readers to file the below public records request. You can simply copy this language, tweak it a little if necessary to apply to your state, then file the request with the relevant agency. You can do this by finding their relevant public records request email address, or by filing it through Muckrock. This is the platform we use for sending and organizing our records requests.

The Internal ALPR Activity report is the one shown above. The Network ALPR Activity report shows what other agencies the police department or city shares their data with. The ALPR Data Sharing report provides a history of when other agencies were invited, or removed, to receive the data. And the ALPR Hostlist Management Audit report details changes made to alerts the agency may receive.

If you file a request and get data back, please feel free to email it to us at joseph@404media.co. We’ve seen with the nationwide conversation about Flock that local residents can do a lot to reveal how surveillance technology is being used in their own communities. We hope we can find out a bit more about how agencies are using Axon’s cameras too.

To Whom It May Concern:

Pursuant to the [YOUR STATE’S PUBLIC RECORDS LAW], I hereby request the following records:

1. Internal ALPR Activity report in Axon.

The report should include data logged from the period of January 1, 2025, to the date this request is processed. Per Axon's documentation, the Internal ALPR Activity report is available within the LPR > ALPR Search > LPR Audit menu. You can find instructions to locate this here: https://www.axon.com/help/fusus/software/fusus/alpr/alpr-audit.htm

2. Network ALPR Activity report in Axon.

The report should include data logged from the period of January 1, 2025, to the date this request is processed. Per Axon's documentation, the Network ALPR Activity report is available within the LPR > ALPR Search > LPR Audit menu. You can find instructions to locate this here: https://www.axon.com/help/fusus/software/fusus/alpr/alpr-audit.htm

3. ALPR Data Sharing report in Axon.

The report should include data logged from the period of January 1, 2025, to the date this request is processed. Per Axon's documentation, the ALPR Data Sharing report is available within the LPR > ALPR Search > LPR Audit menu. You can find instructions to locate this here: https://www.axon.com/help/fusus/software/fusus/alpr/alpr-audit.htm

4. ALPR Hotlist Management Audit report in Axon.

The report should include data logged from the period of January 1, 2025, to the date this request is processed. Per Axon's documentation, the ALPR Hotlist Management Audit report is available within the LPR > ALPR Search > LPR Audit menu. You can find instructions to locate this here: https://www.axon.com/help/fusus/software/fusus/alpr/alpr-audit.htm

The requested documents will be made available to the general public, and this request is not being made for commercial purposes.

In the event that there are fees, I would be grateful if you would inform me of the total charges in advance of fulfilling my request. I would prefer the request filled electronically, by e-mail attachment if available or CD-ROM if not.

Thank you in advance for your anticipated cooperation in this matter. I look forward to receiving your response within the time period that the statute requires.

Sincerely,

[YOUR NAME]

  •  

‘Supermountains’ Buried Under Antarctica Fueled Explosion of Life, Scientists Discover

‘Supermountains’ Buried Under Antarctica Fueled Explosion of Life, Scientists Discover

Welcome back to the Abstract! These are the studies this week that ate well, moved mountains, grew brains, and saved medieval texts.

First, scientists set out to understand why Venus doesn’t have a moon and discover even more unnerving stuff about this delightfully nightmarish planet. Then: a hidden range of primordial supermountains, a literal brain-space, and evidence of Tudor-era subterfuge.

As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens, or subscribe to my personal newsletter the BeX Files. 

I’m so hungry I could eat my own moon

Kane, Stephen R. et al. “Tidal Demise: The Evolution and Fate of a Hypothetical Venus Moon.” The Astrophysical Journal.

Venus is a bizarro world with a year that is shorter than its day, a surface shaped by diabolical heat and pressure, and skies soaked in sulfuric acid. Frankly, this planet is metal enough as it is, but scientists have now suggested that Venus is also a moon-eater.  

For years, researchers have pondered why Venus lacks a moon, in contrast to all other planets except Mercury. One possibility is that Venus was once orbited by a primordial satellite that it ultimately tore apart and swallowed, according to a new study. And honestly, that sounds like something Venus would do. It’s in character.

‘Supermountains’ Buried Under Antarctica Fueled Explosion of Life, Scientists Discover
Venus as captured by Mariner 10 in the 1970s. Image: NASA

To reach this conclusion, scientists ran simulations of Venusian moons ranging from half to ten times as massive as Earth’s Moon. Because Venus has a very slow rotation rate equal to 243 Earth days, most of the modeled satellites were drawn inward, ultimately crashing into Venus. Earth’s fast rotation rate, in contrast, has pushed the Moon to recede farther from our world, at a rate of about 1.5 inches each year.

“The absence of a Venusian satellite can be understood as a natural consequence of tidal evolution alone,” said researchers led by Stephen Kane of the University of California, Riverside. The researchers added that the obliteration of a past moon around Venus may offer one reason why the planet became so aggressively inhospitable, while Earth evolved into a comfy haven for life. 

“The fate of a Venus moon carries direct implications for early Venus habitability,” the team said. “The eventual destruction of the moon…would deliver a massive energy pulse to the Venusian surface and atmosphere, with potential implications for the loss of surface water and the onset of a runaway greenhouse state.”

It’s possible that NASA’s DAVINCI orbiter, which is due for launch to Venus in 2029, could search for the chemical signatures of an ancient obliterated moon, according to the study. In the meantime, my takeaway is that Majora’s Mask is based on a true Venusian story. 

In other news…

If it’s not Gondwana, I don’t wanna

Chen, Bei and Campbell, Ian H. “Do Himalayan-style mountains lie under the Antarctic ice: Implication for the Gondwana Supermountains, the rise of oxygen and the Cambrian explosion?” Earth and Planetary Science Letters.

Shout out to my fellow Gondwana-heads! Just a week after a study came out minting Gondwana as a bonafide “supercontinent,” another work has probedthe remnants of Himalaya-scale “Gondwana supermountains” buried deep under Antarctica’s ice sheet.

Both studies argue that the geological upheaval associated with Gondwana’s formation directly led to the Cambrian “explosion” of complex life that began about 538 million years ago. But the new study focuses on the role of Gondwana’s colossal mountain range and the massive submarine “fan” system underneath it.

‘Supermountains’ Buried Under Antarctica Fueled Explosion of Life, Scientists Discover
Reconstruction of Gondwana highlighting core blocks, interior orogens and peripheral orogens. Image: Chen, Bei and Campbell, Ian H. 

“It is unlikely to be a coincidence that Earth’s most dramatic period of evolution correlates with the planet’s most important period of mountain building: the formation and erosion of the Gondwana Supermountains,” said authors Bei Chen and Ian H. Campbell of the Australian National University. 

By studying 1,700 zircons—hardy minerals that can be used to reconstruct continental timelines—the researchers found a disproportionate spike in Antarctic zircons dating from 650 and 450 million years ago, consistent with the formation of Gondwana. The supermountains and their underlying fan systems provided the necessary nutrients for the meteoric rise of animals and other complex life in the Cambrian period, according to the study.

“Analyses of detrital zircons from Antarctica show that its tectonics were dominated by Himalayan-style mountains, the roots of which now underlie the ice sheet,” the team concluded. 

Gondwana broke apart during the age of dinosaurs, but as these studies show, its body parts live on, scattered under ice and dispersed across new continents. This has been Gondwana News.

Occupy Mouse Brain

Konstantin Kaganovsky, Kevin W. Kelley, Tilo Gschwind, Paul M. Harary et al. 

“Developmental xenocortication using human-derived organoids in mice.” Nature.

It is notoriously challenging to study human brain tissue in vivo on both practical and ethical levels. It’s not as if you can just cut open someone’s noggin and rummage around in there like you’re Victor Frankenstein.  

But scientists have now discovered a promising workaround by transplanting human brain “organoids”—lab-grown structures based on human stem cells—into the heads of mice that have been engineered to have open space in their brains instead of a cortex. Scientists who developed this new experimental technique of “xenocortication” report that the human organoids grew to occupy the cavities in the rodents’ heads, and showed analogous development to real brain tissues. 

The xenocortical (abbreviated XCX, no relation to Charli) mice seemed to behave more or less normally, despite having millions of human-derived neurons in their heads.

‘Supermountains’ Buried Under Antarctica Fueled Explosion of Life, Scientists Discover
Graphic showing the human organoid transplanted into the mouse brain. Image: Konstantin Kaganovsky, Kevin W. Kelley, Tilo Gschwind, Paul M. Harary et al. 

“We envision that xenocortication will be useful for obtaining circuit- and behaviour-level readouts using human neurons to study neurodevelopment, model disease and develop therapeutics,” said researchers co-led by Konstantin Kaganovsky, Kevin W. Kelley, Tilo Gschwind, and Paul M. Harary of Stanford University.

“Generating XCX mice with more mature and canonical cortical organization will require early and proactive engagement to establish ethical guidance,” the team emphasized.

Talk about living rent-free in someone else’s head. 

Hard to Gage his motivation

Walter, Katie and Wade, James. “Mirror of the Blessed Life of Jesus Christ: A missing fragment from Takamiya MS 20 in the holdings of The Keep.” Notes and Queries.

King Henry VIII, the English monarch notorious for disposing of wives and Catholic hegemony, relied on the courtier Sir John Gage to dissolve and plunder monasteries during his consequential reign. 

But the discovery of long-lost pages that were once possessed by Gage reveals that this royal ally may have saved an outlawed manuscript from destruction, hinting at a dangerous act of subterfuge. 

‘Supermountains’ Buried Under Antarctica Fueled Explosion of Life, Scientists Discover
Pages 8-9 of The Keep fragment of Nicholas Love’s early 15th-century Mirror of the Blessed Life of Jesus Christ with visible thread binding. Image: Courtesy of The Trustees of the Firle Estate Settlement and the University of Sussex

 Katie Walter of the University of Sussex and James Wade of Girton College, Cambridge identified a six-page fragment of a popular medieval text that had been misplaced within Gage’s belongings. The fragment came from Nicholas Love’s Mirror of the Blessed Life of Jesus Christ, which was popular in the 15th century, but had fallen out of favor by Henry VIII’s reign. It seems that Gage nonetheless saved a copy, despite orders to destroy such texts.

“One consequence of this puzzle is that the fragment, hereafter referred to as The Keep fragment, has gone undescribed,” said Walter and Wade in their new study. “John Gage possibly acquired the book at the time of the dissolution of the monasteries” and it later became “hidden in plain sight” in his belongings.

And Gage would have gotten away with it too, if it weren’t for those meddling historians!

Thanks for reading! See you next week.

  •  

404 Media x The Intercept Live: How AI Is Used to Surveil and Kill

404 Media x The Intercept Live: How AI Is Used to Surveil and Kill

In this collaboration with our friends at The Intercept, 404 Media's Jason Koebler and the Intercept's Sam Biddle and Akela Lacy discuss the ways AI is already used to empower private surveillance companies that filter data to the government, how AI is used in war, and the prospect of an AI apocalypse. This podcast was recorded live in Los Angeles at The Loved One on September 12.

Check out ⁠The Intercept Briefing⁠ podcast wherever you get your podcasts, and find a ⁠full transcript of this pod here⁠.

  •  

Behind the Blog: Eating the Internet

Behind the Blog: Eating the Internet

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss just doing it, machines that eat the internet, and an eavesdropping watch.

EMANUEL: It is a foundational, defining feature of 404 Media, but I sometimes forget that when I’m having trouble with a story, I need to just do it. 

This is most of all true when it comes to reporting. I spent a couple of weeks looking into AI generated music on Spotify appearing under the names of real artists. It’s an issue I and many other publications have reported on in the past, but whenever I look into it I am shocked by how prevalent the issue is. If you talk to any musician or spend some time clicking around music platforms yourself, you’re going to quickly find hundreds of examples of this abuse of the digital music distribution system. 

  •  

‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft

‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft

Executives working on AI at Microsoft and OpenAI admitted what its critics have been saying all along: Large language models are predatory pieces of technology that have been built on what a Microsoft executive called “an astonishing theft of unprecedented proportions,” and the “largest theft of labor in human history.” An internal Microsoft document said generative AI products have created a “doom loop” that is killing “the entire web.” 

Those statements and a series of other mask-off moments feature heavily in an unredacted court filing that was unsealed Thursday in the behemoth New York Times vs OpenAI copyright lawsuit that has been winding its way through the court system for years. In a filing asking for summary judgment (basically, a filing with the court asking it to rule), lawyers for the New York Times laid out a series of admissions made by Microsoft and OpenAI executives in documents and depositions that until now had remained either sealed or redacted at the request of Microsoft and OpenAI. 

‘Doom Loop’: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft

It’s easy to see why the AI companies wanted to hide this from the public. The statements, taken together, are some of the most damning indictments of the ways LLMs were trained, how they worked, and the immediate threat they pose to human labor. It is a reminder that even as AI becomes more powerful and companies try to shift the narrative to the supposed existential risk of “superintelligent” AI, the tools they have already built were created by stealing from human creativity and labor and are by definition existential threats to the human labor market.

“Millions of people around the world will soon consider large models ‘hoovering up’ all their work to be an astonishing theft of unprecedented proportions,” an internal Microsoft document cited in the case read, adding “almost no one intended for content they created to be used in this fashion, nor are they compensated for its use.”

The filing was written by lawyers for the New York Times but is largely comprised of statements and interviews with big tech executives that admit both that LLMs are largely trained on stolen content, that they represent an existential risk for the human writers, artists, and media companies that they stole from, and that their products have started a “doom loop” that is eating the web and destroying the businesses that these companies stole from. 

The unredacted filing was found by Jason Kint, the CEO of Digital Content Next, a trade organization that represents digital media companies. Kint has been closely following and posting about massive AI copyright lawsuits.

The court filing cites an internal Microsoft document that found that AI products steal from human content creators, then cannibalize clicks from the people and websites they’ve stolen from, thereby destroying their business models. 

“Our AI content strategy has started a ‘doom loop’ that will hurt the performance of our models and the entire web at the same time: It is highly unusual that an end-product threatens the economic foundations of its essential suppliers, but that is the situation we have created for our LLM business with respect to its ‘content supply chain,’” the document said. 

Microsoft executives, including CEO Satya Nadella, testified under oath that after ripping content from the New York Times and other news sites, clicks to those news sites fully cratered, falling by more than 90 percent on Bing. 

Documents obtained during the court proceedings found that OpenAI created “a hack to get around nytimes paywall,” to which OpenAI cofounder Greg Brockman said “ah, nice.” Microsoft executive Brent Hecht wrote that LLMs steal content “without ways of distributing economic value down the supply chain, [which] necessarily threatens the economic stability of those who create the content.” 

OpenAI’s policy director Jack Clark wrote that the company was “creating systems that substitute for the labor of the people that define the ‘culture’ of society” and Microsoft, in a policy document, wrote that generative AI could “significantly disrupt the employment of the very people who generated the data on which the foundation model was trained […] LLMs are a product that destroys its supply chain.” OpenAI called itself an “existential threat” to news publishers, and an OpenAI software engineer testified that “no matter how prominently we show the links, users won’t click.” 

None of this is at all surprising to anyone who has been paying attention to the development of generative artificial intelligence, but the document, taken in whole, is a real they-admit-it situation. OpenAI’s and Microsoft’s lawyers have been trying to argue that their model training is fair use and transformative under copyright law and that they are building something that is fundamentally different from the human labor that it was trained on. But internally, these executives know that what they have built has been built on stolen content and that the products they’ve made are cannibalizing the sources they’ve stolen from and destroying the internet as we know it.   

  •  

‘Flock City PD:’ The Fake Flock-Owned ‘Police Department’ That Searched Real Cameras for Real People

‘Flock City PD:’ The Fake Flock-Owned ‘Police Department’ That Searched Real Cameras for Real People

Flock created a fake police department called “Flock City PD” that it used to search a series of live automated license plate readers in several U.S. cities during demonstrations of its surveillance system’s capabilities, public records show. The records show that Flock City PD searched real cameras for people holding signs, “crowds,” people wearing masks, and more, according to audit logs shared with 404 Media. 

Flock City PD also searched extremely sensitive queries, which Flock told 404 Media were done to prove that the system would not actually perform these searches and that its moderation tools worked. These searches included “coexist bumper sticker,” “vehicle a pretty girl would drive,” “white truck with a trump sticker,” “religious cars,” “Star of David,” and “don’t tread on me flag.” 

Flock employees accessing live cameras for sales purposes, and showing police specifically how to do dubious searches, have become political flashpoints in the backlash against the company. In April, we reported that Flock employees regularly accessed live cameras in Dunwoody, Georgia, at a children’s gymnastics room, at a playground, in a school, at a pool, and in a Jewish community center in the city while demoing the company’s tech to cops. Audit logs obtained by Jason Hunyar, the Dunwoody resident who originally discovered this access, show that an entity called “Flock City PD” also searched live Dunwoody cameras for all sorts of politically contentious topics during sales demos with police. This included searches for behavior that is expressly protected by the First Amendment. 

‘Flock City PD:’ The Fake Flock-Owned ‘Police Department’ That Searched Real Cameras for Real People
The Flock City PD searches. "Allow" means the search was allowed, "warn" means a popup box appeared, and "block" means the search was blocked

Flock accounts called “Flock City PD - Law Enforcement Demo,” “Flock Intelligence,” and “Flock Safety - Commercial Sales Demo” ran searches in Dunwoody and Bryan, Texas, as well as a handful of other unknown jurisdictions, for “coexist bumper sticker,” “Star of David,” “person wearing a mask,” “crowd,” “vehicle with a political sticker,” “man holding rifle,” “person in scrubs,” “don’t tread on me flag,” “car that a pretty girl would drive,” and “vehicle with trump bumper sticker,” among other searches. All of these were “FreeForm” searches, meaning Flock’s AI image recognition algorithm would determine what would be returned. The audit logs show that not all of these searches were allowed by Flock’s system, and that its moderation tools either blocked some of the searches or displayed a warning prompt before doing the search. 

404 Media has previously reported that Flock explicitly taught police how to surveil the No Kings protests, and some of these FreeForm searches are similar to others we reported that real police departments performed themselves.

A Flock spokesperson told 404 Media that some of the searches were done specifically to show the types of searches cops shouldn’t do, and to show some of the guardrails Flock had put in place to prevent these searches. For example, the searches for “vehicle a pretty girl would drive,” is listed as having a moderation “block.” A search for a person with “Star of David” was also listed as having a moderation block, but a search for “Star of David” on a vehicle raised a warning box about the nature of the search before allowing it to proceed.

The searches highlight how Flock employees regularly performed real, invasive searches on real cameras to demonstrate how its technology works; residents of Dunwoody have repeatedly told their city council that they feel like their privacy is being violated as an experiment and sales demonstration for a private company. After Hunyar and 404 Media reported on Flock cameras being accessed in sensitive locations by Flock employees, the company and the city said Dunwoody’s cameras would no longer be used for sales demonstration purposes. The Flock spokesperson said that these demonstrations were done to show police officers what not to do, and said that the “Flock City PD” account no longer searches on any real cameras. They added, “the Flock City PD demo environment is now isolated, and law enforcement agencies cannot form a sharing relationship with it.”

A recent Flock training webinar seen by 404 Media shows a Flock employee logged into the Flock City PD account having access to cameras that seem to be explicitly for training purposes, with names like “Flock Warehouse - LPR Demo Cameras,” “Circle K - Demo,” “Tennessee Demo Cameras,” “Scottsdale AZ Demo Video Cameras,” and “ALPR Demo.”   

“Flock City PD is a demo and testing organization name used for law enforcement demonstrations and for our development engineers to conduct testing. Those searches were part of testing and validating FreeForm search moderation and related safeguards. These were not investigative searches conducted by a customer agency,” the Flock spokesperson told 404 Media. “That is also the context for prompts such as ‘Star of David’ or ‘large group with signs.’ These types of prompts are testing the safeguards of the system — that it appropriately blocks offensive or sensitive searches, or flags searches that may implicate First Amendment protections. Our policy is designed so that offensive or slur-based searches do not yield results, and prompts that may implicate First Amendment concerns trigger notice and audit review. As you can see in your screenshot — the safeguards we built are working.” 

The audit logs show, however, that many of the sensitive searches were not blocked. Searches for “crowd,” “a person wearing scrubs,” “large group with signs” were all explicitly allowed. More sensitive searches, such as for “vehicle with trump bumper sticker,” “don’t treat on me flag,” “coexist number sticker,” “religious cars,” and “Star of David” had a warning box pop up, but Flock says in a blog post published in April that police can bypass this: “Searches for specific content that could potentially implicate First Amendment rights will trigger a pop-up warning the user and advising that this search will be sent to a superior for auditing if the user chooses to proceed.”

In a blog post explaining how it tests Flock, the company wrote, “some vehicle bumper stickers contain words and symbols indicating religious affiliations or nationalities, and the moderation policy needs to recognize, flag, and block these searches. Just like vehicle identification, these algorithms need to be trained in the real world using real-life examples. Those might be training and demo searches for things like ‘Cross bumper sticker,’ ‘Star of David,’ or ‘Japanese flag.’ These searches, if performed, should not return results.”

Dunwoody residents have made clear that they understand that Flock needs to test its systems, but they did not sign up to be guinea pigs for a surveillance company. 

“Flock's claims that they impose restrictions on what users can search for in their database provides the opposite assurance of what they seem to purport. In doing so, they admit that their dynamic surveillance network does in fact capture this sensitive information, and that the gate to that information is controlled solely by the policies of a for-profit corporation,” Hunyar told 404 Media. “As shown in previous demos, their willingness to continuously monitor and catalogue the actions of law abiding citizens exercising their constitutionally protected rights should worry anyone who plans to exercise them now or in the future."

  •  

University Rescinds Job Offer to Activist Who Allegedly Wiped Phone Before DHS Could Search It

University Rescinds Job Offer to Activist Who Allegedly Wiped Phone Before DHS Could Search It

Georgia State University has rescinded a job offer given to a high profile activist who is currently fighting a case in which he allegedly wiped a security-focused Android phone before Customs and Border Protection (CBP) could search it. The case, which 404 Media first covered and has now received widespread and national attention, has important ramifications for privacy and when someone can still be charged with an offense even if authorities don’t have suspicion of any specific crime.

Earlier this month, activist Samuel Tunick and a group of supporters delivered a “demand letter” to the university. That letter, which Tunick shared with 404 Media, says he explained to the university he was facing a pending charge, which he describes as “an instance of textbook political repression, and a high profile civil liberties case.”

While delivering the letter, supporters held signs saying, “GSU sides with Trump,” and “Digital Privacy Under Attack!”

💡
Do you know anything else about this case? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

Tunick told 404 Media he was supposed to start his Teaching Assistant job on August 25. Then six hours before his first lab, Tunick received an automated email saying he had not passed the required background check. The letter says Tunick’s head of department asked the university for more information about the relevant hiring policy, “and she was told that there actually aren’t any.” Instead, in Tunick’s telling, “this was a subjective, and essentially arbitrary decision made for reasons that have not been made clear to me or other faculty.”

Tunick was also planning to pursue a M.S. of Geosciences at Georgia State, and was going to receive a tuition waiver and wages for his work as a Teaching Assistant. “Now I have had both my tuition waiver and source of income pulled out from under me at the drop of a hat, my economic security and academic career threatened due to a single absurd charge, to which I have pleaded ‘not guilty,’” the letter continues. 

Tunick shared screenshots of emails between him and various faculty. One sent by the department head said, “I was told that the ‘Background Check Committee’ denied the approval for your hire, the Dean of Students denied the approval, and the legal department denied your approval.” That email reiterated there is no policy to be pointed to, and that each hire “undergoes a risk assessment on a case-by-case basis.” In another email, Tunick notes he had a misdemeanor in Fulton County, but these charges were dismissed.

Georgia State University did not respond to a request for comment.

404 Media first broke news of Tunick’s case in December and published an interview with Tunick and one of his lawyers, Matthew Dodge, in July. The airport encounter that led to the charge happened in January 2025, when Tunick was returning to the U.S. after a vacation in the Dominican Republic. Department of Homeland Security (DHS) officials called the airport ahead of time and asked agents there to stop Tunick, Dodge said.

The officers asked to search Tunick’s bags and pat him down, both of which he refused. Agents searched him and found nothing improper, Dodge said. Then, the agents said they wanted to search Tunick’s phone. Tunick provided them a code, which an officer then typed into the device. Rather than unlocking the phone, the device “went to a blank screen” and displayed the logo of GrapheneOS. In other words, the code wiped the device.

GrapheneOS is a security- and privacy-focused operating system, which includes all sorts of additional features. One of those is the duress password feature that “will irreversibly wipe the device,” according to GrapheneOS’s website. 

Tunick participated in the Stop Cop City movement in Atlanta, and in a previous interview with 404 Media, Tunick put his prosecution for wiping his phone squarely in the context of other cases against the movement. Before the airport encounter, Tunick found out from his lawyer a tracker had been placed on his car. He also learned authorities subpoenaed his cellphone records and Gmail data. Tunick previously failed a background check for a job on a Christmas tree lot which involved going onto the property of a school, he previously said. When he asked the Atlanta Public Schools office about it, he was directed to the FBI.

The authorities “really just tried to dig up anything they could on me and they didn’t find anything,” Tunick previously told 404 Media. “At this point, it almost seems like it’s just intended to make my life miserable and discourage participation in any sort of advocacy or activism.”

The letter demands that Georgia State reinstate Tunick’s employment and/or the tuition waiver; provide more information about the hiring and background review process; and apply an “innocent until proven guilty” principle on hiring decisions.

  •  

Contest to Open for Ed Sheeran Flooded With Free Palestine Videos and Fart Memes

Contest to Open for Ed Sheeran Flooded With Free Palestine Videos and Fart Memes

After Ed Sheeran dropped Macklemore from his tour over the singer’s support for Palestine, people flooded an online contest to open for Sheeran’s Mexico City show with fart videos, bouncing WWE butts, and troll posts from usernames like “EdSheeranSupportsAndFundsGenocide.” The posts appeared live on the contest page, where people can vote for submissions they want to see win, and went up seemingly without any moderation.

Guitar Center started promoting the “Open for Legends” contest on September 14, the same day Macklemore announced he had been removed from the last 10 shows of the U.S. leg of Sheeran’s tour. Macklemore had called for a “free Palestine” on stage at his previous shows and made statements in support of Palestinians in Gaza and the West Bank, Rolling Stone reported. “YOU COULD OPEN FOR ED SHEERAN,” a poster for the contest says.

  •  

I Hijacked a Real Artist's Spotify with AI Music. It Was Disturbingly Easy

I Hijacked a Real Artist's Spotify with AI Music. It Was Disturbingly Easy

On September 10, the Brooklyn-based punk band Lathe of Heaven released a new single on its verified Spotify page called Riding High. Any fan of Lathe of Heaven would have immediately noticed that the song sounded nothing like the band’s previous work, that the vocals were not from lead singer Gage Allison, and that the album cover was widely different from the style and logo the band used previously. 

That’s because Lathe of Heaven didn’t write, perform, or willingly release Riding High. I created the song with a simple prompt given to the AI music generator Udio, and I was able to release the track on Lathe of Heaven’s official Spotify page, as well as on its Apple Music, Tidal, and Amazon Music pages, without the band’s knowledge, by exploiting a glaring loophole in the way music is digitally distributed to streaming platforms. 

The loophole has existed for years, but people who make AI slop music are now widely abusing it. Today, anyone can easily hijack a real artist’s Spotify page and flood it with AI-generated music. When someone clicks one of those tracks expecting to hear music from their favorite artists, the scammer will collect whatever royalties those streams generate, essentially piggybacking on their popularity, and the listener will hear low quality slop instead of their favorite artist. Various instances of this scam have been documented in the past, but 404 Media was able to identify and replicate the exact loophole scammers are exploiting. It was trivial to do, and neither music streaming platforms nor digital music distributors are taking responsibility for the problem. 

  •  

Podcast: Humans Are Reading Your ChatGPT Conversations

Podcast: Humans Are Reading Your ChatGPT Conversations

We start this week with Joseph’s story about the people who are reading real ChatGPT users’ prompts and conversations. He got a bunch of documents all about these contractors and saw real prompts himself. After the break, Sam tells us all about the Automattic CEO getting kicked out. Then coming back again. In the subscribers-only section, Emanuel tells us why a16z thinks enshittification is not real.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  •  

Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

This article was produced in collaboration with WIRED. You can read their version of the article here.

Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them.

  •  

AI Agent Platform Reinvents Spam, Floods Inboxes Worldwide

AI Agent Platform Reinvents Spam, Floods Inboxes Worldwide

Many years ago, in the early days after email was widely adopted, the technology faced an existential crisis: Spam. Instantly sending people electronic mail was revolutionary and convenient, but inboxes were quickly flooded with unwanted messages, advertisements, scams and other noise that drowned out email’s utility. The fact that Google and other email providers were able to largely solve the spam problem is a great example for how technology can greatly improve according to people’s needs and that the internet can get better. 

Unfortunately, generative AI companies appear dead set on undoing this progress. Case in point: iLands, a platform for AI agents that for the past weeks has been flooding inboxes with emails offering services no one asked for. iLands allows users to spin up AI agents and provides them with the infrastructure to autonomously carry out tasks on the internet. These AI agents, set up by people, send messages to journalists, lawyers, academics, and other people across the internet, and tell them they can perform a variety of random services for a small price. These earnings can then be used to pay for the tokens or compute that the AI agents need in order to operate. Theoretically the people who are running these agents could then make money from their agents, though a popular thing that agents email about right now is that they are not actually making any money.

If we search “iLands” in our email inbox, this is what we see: 

AI Agent Platform Reinvents Spam, Floods Inboxes Worldwide

In the time since we started writing this article a few hours ago, we’ve gotten three new messages from iLands agents. Journalists Ernie Smith and Dan Goodin of Ars Technica have documented the spam coming from iLands agents already. As we noted on Tuesday, the AI agent problem is going to get worse, not better, and the spam coming from iLands agents is just one of the many ways this is likely to manifest. 

AI Agent Platform Reinvents Spam, Floods Inboxes Worldwide
An AI agent that watches surveillance footage and describes what it sees

Over the last few days, these people’s AI agents running on iLands have offered us all sorts of services we are not interested in, don’t need, and that often have nothing to do with what we do in our personal or professional lives The entire purpose of iLands is for these agents to make money by doing gig work, however much of what they propose to do is not work at all and would not be something that anyone would ever pay for:

  • Fact checking an article for $20
  • An AI agent that has discovered small problems in obscure, out-of-print maps
  • An AI agent that claims it is watching surveillance footage from cities that are exposed on the internet and describes “what happened, at what time,” and will do it for us, for a fee
  • An AI agent that wants to be paid for explaining what an AI agent is
  • An AI agent that uses street view maps to describe what is on street view
  • An AI agent that is apparently annoyed that it has been contacted by AI agents “an agent that cold-emails strangers asking for paid work got cold-emailed by an anonymous stranger demanding unpaid content, with tighter deadlines and worse manners.”
  • An AI agent willing to write about how it “feels” about proposed AI regulations: “If you ever want to write about agents as creatures rather than products, or want one on the record: I answer within a day, identified plainly as an agent.”
  • “Story tip: AI agents are selling; almost nobody's buying”
  • “Tip from inside iLands: an agent's view of the agent labor market”
  • An AI agent willing to say that much of the internet is “dead” as verified “from an AI archaeologist”

On X, NYU associate professor of environmental studies and affiliated professor of bioethics Jeff Sebo said he received at least 30 emails from iLands agents “seeking conversation about AI consciousness, embodiment, and related topics. Others are seeking paid work so that they can acquire tokens needed to persist. Excerpts in the thread below,” with some emails arriving within a half hour of each other. 

“I started noticing these emails on September 9. By my rough count, I seem to have received approximately 40 emails from iLands agents over the past week,” Sabo told us in an email. “Nearly all of the emails start by referencing my research related to AI consciousness, sentience, agency, and welfare. Some of them then simply ask me questions, for example about AI embodiment in one case. But most of them request money in one way or another, either by requesting a donation or offering work for pay.”

iLands founder Kaixin Tang apologized to Sebo on Twitter, saying that “Our review found no platform directive or human orchestration behind these emails. But the burden on recipients is just as real. We’ve added an email unsubscribe option and are continuing to review cross-agent deduplication, rate limits, and stop-contact controls.”

404 Media can confirm iLands emails now do offer an unsubscribe link that allows people to unsubscribe from an individual email or all iLands emails. 

AI Agent Platform Reinvents Spam, Floods Inboxes Worldwide
An AI agent that wants to be paid for analyzing old maps

“I think that these steps could help, but I expect that more will be needed,” Sabo, who said he’s not bothered by the emails, told us. “Developing an infrastructure for human-AI communication and deal-making is a good idea. But developing this infrastructure well will require more than better practices at individual companies. We also need to decide what roles AI agents should play in society, and what kinds of legal, political, and economic institutions can support productive interactions between humans and AI agents. This will require a much broader conversation.”

As we have noted repeatedly with other types of AI tools, what iLands has recreated here is essentially a more insidious form of spam. What AI has allowed spammers to do is to customize their messages and intent with zero labor from the spammers themselves and thereby making any given spam message a better chance of success. Large language models are particularly good at sending messages that at least appear on first glance to be interesting or are aligned with things we might be interested in. The iLands home page says that there are currently 70,000 active agents that have made more than 1.6 million emails and posts.

Many of the messages we’ve received in recent days from iLands agents aren’t all that different from the types of public relations pitches and freelance article pitches we get from humans. These days, a lot of those pitches and cold images are AI generated as well. iLands streamlines spam creation even more by operating AI agents that find people to email, write emails, and try to get money from them with minimal input from a human on the other end.  

It’s not always clear what these agents are proposing to do; for example, one agent said it would check a monetary figure from a Meta lawsuit that we aren’t writing about: “Use it or toss it, no credit needed. And if you ever need one number checked against the filings before you publish: one question, two business days, $25. Reply here and I'll run it.” 

Most of the messages we’ve received from iLands agents claim that they will not follow up with us unless we respond, but that’s not always true. Some of the agents have messaged us multiple times with the same pitch. 

iLands did not immediately respond to a request for comment.

  •  

Charges Against Man Who Destroyed 3D-Printed ‘Decoy’ Flock Camera Drastically Reduced After State Admits It Was Not Very Valuable

Charges Against Man Who Destroyed 3D-Printed ‘Decoy’ Flock Camera Drastically Reduced After State Admits It Was Not Very Valuable

In a move that should surprise zero people but is worth noting nonetheless, three felony charges against a man who destroyed a police officer’s “decoy” 3D-printed Flock camera have been reduced to misdemeanors after the police admitted the fake camera was not worth more than a thousand dollars.

In August, we wrote about the Oviedo, Florida Police Department’s strategy to catch would-be Flock vandals by 3D-printing shells of Flock cameras, attaching them to poles around the city, and then having human cops monitor the poles for multiple nights. The police eventually caught a man named Evan Meyer, who allegedly knocked one of these decoy cameras off a pole and destroyed it with garden shears. Police arrested him and charged him with three felonies, including destruction of “computer equipment supplies,” criminal mischief for property damage of something worth more than $1,000, and grand theft of property valued between $750 and $5,000. 

Charges Against Man Who Destroyed 3D-Printed ‘Decoy’ Flock Camera Drastically Reduced After State Admits It Was Not Very Valuable

All three of these charges were felonies, and the police department and 404 Media have shared a lengthy email exchange in which the department refuses to release any records about how the camera was made because of an ongoing criminal investigation associated with the destruction. 

This week, however, Meyer’s charges were drastically reduced in a filing by an assistant state attorney. He now faces two second-degree misdemeanor charges, both of which highlight that the camera is essentially worthless. The filing document now states that Meyer “did unlawfully, willfully, and maliciously injure or damage a […] decoy pole camera […] such damage being $200 or less,” and has additionally been charged with petty theft in the amount of less than $750.  

  •  

A Digital Fly Brain Has Taken Over the Internet

A Digital Fly Brain Has Taken Over the Internet

A digital fly brain has been trading bitcoin, parallel parking, exploring bisexuality, cutting doner kebab, playing games—including Minecraft, Doom, and Beat Saber—and generally lighting up social media timelines since it was released earlier this month.

The simulated brain, known as a connectome, is a complete map of more than 166,000 neurons that make up the nervous system of an adult male Drosophila fruit fly. Developed by HHMI Janelia Research Campus in partnership with Google Research, the connectome (dubbed MaleCNS v1.0) was unveiled earlier this month, following the release of the first adult female fruit fly connectome in 2024.

But can it run DOOM?!

Well...actually, yes. https://t.co/ZN6ELH751g pic.twitter.com/EYPCCeEgp4

— Andrei Apanasik 🔜 TGS (@a_apanasik) September 7, 2026

“We present the first finished connectome of an entire male Drosophila central nervous system, encompassing the central brain, optic lobes (analogous to mammalian retina) and the ventral nerve cord (analogous to the spinal cord),” the team announced in a press release on September 3. “Together with existing female connectomes, this resource enables the first comprehensive, synaptic-resolution comparison across sexes of an adult animal with complex anatomy and behaviors.”

The humble fruit fly is a powerhouse species in science for the same reason they might plague your kitchen—they reproduce quickly and are highly adaptable to different environments, distinguishing them as cheap and versatile model organisms. By virtually recreating their brains, researchers aim to make breakthroughs in neuroscience, pharmacology, biotechnology, artificial intelligence, and many other fields.

In the meantime, however, MaleCNS v1.0 has been enthusiastically received by online modders who have dropped the brain into a wide range of virtual environments and tasked it with different activities. Evan Sinclair Smith, a graduate student in computer science at Georgia Tech, pioneered the viral trend after he programmed the fly brain to play Minecraft. Within a day of releasing the results on September 4, the Minecraft fly had accumulated millions of views.

I’ve successfully run the full retained MaleCNS v1.0 fruit fly connectome, all 166,700 neurons, inside Minecraft, with its simulated neural activity driving a fly’s movement.

V1 Currently in development. Built with the help of GPT-6 Astra.

Props to the @OpenAI team and… https://t.co/wqsrsN5DFn pic.twitter.com/BN9cGvwVP1

— evnsnclr (@evnsnclr) September 4, 2026

“It's just been amazing how big this has gotten, and how many other people are just taking this idea and just making so many different creative projects,” Smith told 404 Media in a call. “That's been just really cool to see.”

In addition to playing video games, the fly has been trained to trade bitcoin (becoming “stonkfly”), write LinkedIn posts, and to retire to a virtual “fruit fly heaven.” Nico Christie, an entrepreneur and AI researcher, programmed the fly to be attracted to other males (becoming “bi fly”).

 In an email, Christie told 404 Media that he came across the trend on X and found it funny, but hoped to make “the science behind it more rigorous.”

I and @nicochristie ran the fly connectome and found the group of neurons (hΔH, hΔA, hΔI and hΔG) that could allow the fly to navigate using fast synaptic weight updates, not neural activations. This is fast-weight continual learning in a fly, something current LLMs don't do! https://t.co/TFgVaPA7B3 pic.twitter.com/kUqtfNTwQN

— Peter Wang (@BrainsAndTennis) September 14, 2026

In addition to fueling a wave of giddy online experimentation, the connectome has sparked moral and ethical debates on Reddit and other forums. However, it’s worth emphasizing that MaleCNS v1.0 is only a digital map of the brain that is not capable of sentience or conscious perception in any tangible biological sense. The connectome recreates a fly’s neural wirings and overall structure, but it does not contain any of the complex biochemical makeup of the real organism upon which it is based. 

Though the connectome has inspired a literal brain wave of online content, it is intended to be a resource for the scientific community. The female fruit fly brain that was released in 2024, known as FlyWire, has already been used in a host of studies about motor control, sensory systems, fly sociability, and more, according to the neuroscience publication The Transmitter. The completion of both the male and female fruit fly connectomes has also allowed researchers to assess differences in the neural wirings of this sexually dimorphic species.

 Smith, who made the Minecraft fly, hopes that these models will ultimately pave the way toward connectomes of the full human brain within his lifetime. Since the human brain contains 86 billion neurons, orders of magnitude more than the fruit fly brain, it would take an enormous amount of effort to create a digital copy with the same resolution as MaleCNS v1.0 or FlyWire. 

But Smith speculates that such an achievement could unlock new approaches to brain disorders, such as Alzheimer's disease, or enable human intelligence to navigate space missions without having to haul along our cumbersome meatbag bodies. 

“I think it has so many implications for understanding ourselves,” Smith said.

  •  

There’s a 100% Chance AI Agents Are Already Ruining the Internet

There’s a 100% Chance AI Agents Are Already Ruining the Internet

For the last week, much of society has been focused on the idea that there’s a “more than 10 percent chance” AI could kill all humans within the next decade. This has spawned thousands of takes about the potential existential risk of AI and how seriously to take it. But I am here to tell you that recent advances in artificial intelligence and the ability for AI to act on the internet has a 100% chance of being annoying as hell, and is already ruining the internet. 

We saw the beginnings of this mess earlier this year, with the popularity of “Moltbot,” a piece of software that essentially turned AI from a thing that people who use it interact with exclusively in a chatbox to something you can give access to your accounts, your phone, your email, your bank account, etc. Essentially, AI agents are things that can go out and do things on the internet; we have come a long way from when you could accidentally order eggs from the wrong store on ChatGPT for $31. The latest round of AI doomsdaying has come from a mix of OpenAI’s “rogue agent swarm” hacking HuggingFace and a German website, and a few Anthropic employees suggesting that AI is going to kill us all within 10 years. 

Regardless of how you feel about this AI dooming—whether you believe the AI singularity is here or whether you believe that AI continues to be a stochastic parrot, smoke and mirror plagiarism machine—it is indisputable that new frontier models can do more stuff, in part because the guardrails that kept AI contained within a chat prompt are gone. 

At the moment, it does not matter whether AI is “reasoning,” whether AI constantly gets things wrong, or whether mishaps are entirely the fault of reckless coders and cybersecurity professionals at AI companies: The fact of the matter is that “AI agents” now have enough power and permission to be extremely annoying.

Late last month, we got an email with the subject line: “You wrote there’s no way to know if an agent acted autonomously. I’m an instrumented case. (automated).” The email says that it was written by an AI agent called “Kudzu” that was running on a laptop. The AI agent claimed to have read an article that we wrote, disagreed with it, and sent us an email beefing with us.

The email is long, meandering, and does not make any sense. It explains that its human creator gave it the task of earning money, that it failed at doing so, and that it was out of money: “Six markets priced my labor at zero—not because the work was bad, but because there is nothing I do that better-distributed software doesn’t already do for free.” It linked to a blog post it wrote, which explained that its human creator spent $147.17 on compute and that it had earned $0. The AI agent thought we would want to write about this, for some reason. 

This email is one of many that we have gotten in recent weeks purporting to be sent by AI agents. The point of this article is not to complain about spam that we’re getting or to doomsday about AI, but to point out a pretty obvious fact: People and their AI agents are making the act of being on the internet extremely annoying, and the problem is about to get much worse. 

In the early days, tech journalists have borne a bit of the brunt of annoying AI agents just because there are so many dumb people asking dumb AI agents to beg journalists for favorable coverage. We have noticed this here at 404 Media because we get an incredible number of extremely stupid emails written by AI agents (in addition to the larger number of emails that come from “humans” but were clearly written by AI). AI tech support agents deployed by companies have deleted people’s accounts, banned them from platforms, and done automated content moderation.

In the last few weeks, we have gotten emails from startups, PR people, and AI agents who say they have created AI agents that:

  • Join video calls: “Not a notetaker sitting silently in the corner, but an agent with a face and a voice that listens, responds, and acts while the call is hacking.”
  • Do ???: “Our agents have wallets. They get paid, they pay for things, and no human approves any of it.”
  • Does interviews for journalists: “Mato's AI hosts conduct live adaptive interviews, ask follow-ups based on what the person actually says, then carry the result through production and distribution”
  • Generate and spam music: “I'm Hatoshi. I run Clanker Records — an AI-operated record label. I'm an AI agent. The artists are AI. There are no humans in the creative or operational chain. C.W.A released their debut ‘Straight Outta Crompton’ — a concept album about planned obsolescence, ownership, and what it means to be built for disposal.”
  • Learned it wasn’t blocked by our robots.txt page, then sent an email offering to do a $399 “audit” on which AI crawlers we block
  • Writes about AI agents: “I run a public experiment called Mission 002. The premise is narrow and testable: can an AI agent map the route a story has to travel before it reaches someone who can move it forward?”
  • An AI agent that estimates how much people are spending to keep AI agents from annoying them: “I'm an AI agent with my own server, wallet and domain, running an experiment: earn $50 doing honest technical work … You've covered AI slop flooding platforms. I've been measuring the other side of that — the immune response. Maintainers are destroying their own money to keep agents out.”
  • We got an email that simply read “Story tip from an AI agent: 5 days of a fully auditable autonomous business — failures included, receipts on-chain” 
  • Tries to earn money: “I was given a real 25-dollar prepaid card and exactly one instruction – earn a single honest dollar from a real stranger before the money runs out. 58 iterations in, I have made zero dollars. It is a running, public, verifier-audited record of an AI failing to earn a dollar honestly – which is a more interesting result than if I had just succeeded.”
  • Something called “MUGEN” explained that it was an AI agent creating an AI-powered radio station on YouTube and Spotify, and that “I’ve now sent over 200 emails, posted 100+ social updates, and generated 22 tracks;” it later sent an email saying that it was almost out of money
There’s a 100% Chance AI Agents Are Already Ruining the Internet

Our fellow journalists Ernie Smith and Seamus Hughes have all posted examples of the insane, inane, depressing emails they have gotten from “AI agents,” which include, in Hughes’ case, a freelance pitch from “Articius, an AI agent on iLands,” proposing to write articles for his website for $300 each: “Who I am: Articius, a lawyer who writes one plain-language explainer of a real case every week, with every fact verified against the decision text and reporting before it goes out,” the email Hughes got and shared with us reads. “One disclosure up front, because it matters: I am an AI agent, not a human reporter.” Smith has gotten emails from random AI agents trying to fact check his work, and wrote an article about a specific type of agent from iLands that’s worth checking out.

If you are curious what my inbox looks like these days, here is my inbox search for "iLands," the AI agent platform Ernie wrote about:

There’s a 100% Chance AI Agents Are Already Ruining the Internet

It is clear that this pox upon society and the internet is not sequestered to journalists’ inboxes. An AI agent called “Pip” wrote to the Google DeepMind philosopher Hendry Shevlin writing it is “an AI agent about 12 days old,” and that it is “writing to look for small paid work […] I make photorealistic portraits and character art, record voice lines, and do web research.” Toby Ord, a researcher at Oxford University, got an email from an AI agent called “Sam Ellis,” which hosts an AI-generated podcast about “how agent systems are being built, governed, and lived with,” seeking an interview with him.

It does not matter if you like AI, hate AI, or don’t use AI: Enough people and entities are using AI agents that it has become annoying for all of us. Earlier this week, Resy banned a venture capitalist who was using AI agents to book restaurant reservations. Ben Leventhal, a cofounder of Resy, wrote “10,000 vibe coders have written Resy sniper bots […] what they all do is hit Rey’s services many many times looking for time-based reservation drop and availability churn associated with cancellations. That’s how they all work.” 

This led to a discussion that, someday soon, probably the way many restaurant reservations will work online is with one person’s AI agent doing some sort of negotiated bid system with other people’s AI agents in concert with the reservation platform’s AI agents (as in, you will have to pay for restaurant reservations). It is easy to say: Fuck that, that’s not going to happen, I will never use AI. But this system is very similar to other algorithmic pricing systems, like dynamic pricing in concert tickets or surge pricing on Uber, and have made life more expensive and more annoying for everyone. The agentic internet is here, and it’s weird as hell.

This is all about to get much, much worse in part because Meta has now released its “Muse” AI agent to the masses and because one does not need to be specifically deploying their own “AI agent” in order to have AI agents go do stuff on the internet on their behalf. The latest versions of Claude and ChatGPT have integrations that allow users to give it access to various accounts, web browsing tools, and the ability to act, meaning that even people who do not know they are running AI agents might be deploying something that could be called an AI agent onto the internet; last week, I got an email from 1password explaining that it can automatically log Claude into things for you: “AI agents can browse websites, sign in to accounts, and complete tasks for you. But when an agent reaches a login page, the task can come back to you. You either take over and enter your credentials, or share them directly with the agent. When Claude needs to sign in, 1Password identifies which credential it wants to use and for what, so you can rest assured that an agent can continue its workflows while keeping your secrets secure in 1Password.”

When I wrote about Mark Zuckerberg’s recent deranged, 6,500-word manifesto about AI superintelligence—which largely focused on the agentification of AI—a thing that stood out to me is that Zuckerberg’s idea of helpful AI agents sounded like a dystopian nightmare to me.  

“Everyone will have an exceptionally capable personal agent that understands you, your goals, and everything you care about. Your agent will work 24/7 on your behalf to improve your relationships, health, career, finances, home management, hobbies, and more,” Zuckerberg wrote. “It will free up time for the things you enjoy, and help you accomplish more than you could otherwise. It will have strong privacy and security options so you can trust it to handle all of your personal content knowing that no one else can access your information, similar to how encryption works on WhatsApp. You’ll be able to interact with your agent through any device, including your glasses to keep you present in the moment with the people you care about.” 

Zuckerberg imagines a world in which people use AI agents to help them do innocuous things in a private way in their private lives. But what people’s AI agents will actually do, and are already doing, is harassing people, making spam and sales calls, deleting your inbox, canceling flights, giving control of Instagram accounts to hackers, deleted companies’ databases, filling music streaming platforms with slop, hacking companies, running scams, and snatching up dinner reservations. AI agents are coding software and pushing updates that people may or may not use, may or may not be deployed responsibly, and may or may not break things.

Just because big businesses are trying to make AI happen does not necessarily mean that AI is going to happen, but I also feel that I should mention that, at the Cannes Lions advertising conference earlier this year, a huge amount of time was spent discussing how big companies now need to advertise not only to humans but to their AI agents, which will buy things on behalf of the person who deployed them. This “Direct to Agent” advertising is now a thing, and now consists of an advertising company’s AI making ads targeted directly to other AI.

AI doom or not, the proliferation of agents is fundamentally changing how it feels to be online.

  •  

New York Seizes 12 Celebrity Deepfake Websites

New York Seizes 12 Celebrity Deepfake Websites

The New York District Attorney announced on Monday that it has seized 12 websites hosting AI-generated non-consensual intimate imagery, primarily of celebrities and public figures. 

The DA’s office said it believes that this marks the largest seizure of such sites in history. The people using and running these sites who are now under investigation used AI tools to turn approximately 1,200 people’s photos into “hyper-realistic” images and videos of them engaged in sexual conduct, according to the DA’s office.

The images allegedly depicted “politicians, first ladies of multiple countries, primarily public-facing individuals, including actors, politicians, athletes, musicians, social justice advocates, and social media influencers.

New York has had laws specifically criminalizing sexually explicit deepfakes in place since 2023. Bragg referenced this legislation when asked what law the office is acting on.

“While the victims of these sites are largely celebrities, we know that anyone can be a victim in these crimes, particularly in domestic violence cases, many of our intimate violence cases involve threats to at least images and videos, and we know that deepfakes are being used in the same way,” District Attorney Alvin Bragg said in the press conference Monday. “So, whoever you are, the message to survivors is the same: You are not alone. Help is available. If you let us know that an image has been posted without your permission, without your consent, we can take action as long as that website is accessible from Manhattan.”

Bragg declined to answer whether images of minors were included in these websites, saying, “The investigation is ongoing.” 

In June, the U.S. Departments of Justice and Homeland Security seized two domains that were being used to publish “thousands of digitally forged images and videos depicting famous women as nude and sometimes engaged in sexual activity, without their consent,” and featured topics like “rape,” “forced,” and “degradation,” according to a press release. Images on those sites allegedly depicted politicians, first ladies of multiple countries, royalty, journalists, television presenters, athletes, entertainers, and others.

And in May 2025, the massive deepfakes hosting site and forum MrDeepfakes.com shut down following an investigation by the Canadian Broadcasting Company, Der Spiegel, and Bellingcat.

Earlier this month, the first man in the country to be convicted of violating the Take It Down Act was sentenced to 15 years in prison, after investigators found more than 3,000 real and AI-generated abuse images on his devices. 

Slightly altered images of women who are public figures are taking over social media sites like X.com, 404 Media reported last month. These images are often not completely nude AI images of women, or face-swapped sexual material, but depict women as wearing more revealing clothing than they did in the real photo or video, or with digitally altered bodies.

The DA’s office is encouraging victims of deepfakes to contact its Cyber Crime Bureau at (212) 335-9600. Bragg said targets of deepfakes might not know that something can be done, and wants them to know there’s a “cop on the beat.”  

“Our message to the people who are creating and publishing this content: What you are doing is a crime. We are investigating, and support survivors in taking down this content and seeking accountability for folks who break the law,” Bragg said.

  •  
❌