10 interesting stories served every morning and every evening.

Introducing Muse Glimmer: An Open Agentic Model That Runs on Your Device

research.meta.ai

Today, we’re in­tro­duc­ing Muse Glimmer, the next model from Meta Superintelligence Labs, and open sourc­ing the model weights un­der a per­mis­sive Apache 2.0 li­cense.

Muse Glimmer is a 30-billion-parameter model op­ti­mized for al­ways-on lo­cal agent work­flows. It’s small enough to run on a Mac or PC with a sin­gle con­sumer GPU, en­abling use cases that range from lo­cal agents and func­tion call­ing, to lo­cal cod­ing, and LLM-as-a-judge eval­u­a­tion. Muse Glimmer de­liv­ers strong per­for­mance on key agen­tic use cases and bench­marks com­pared with lead­ing mod­els in its size cat­e­gory.

Foundation mod­els have achieved re­mark­able ca­pa­bil­i­ties across rea­son­ing, code gen­er­a­tion, and tool use — yet most de­ploy­ments still de­pend on cloud in­fra­struc­ture and net­work ac­cess. Running mod­els lo­cally en­ables you to use AI any­where, any­time, with or with­out an in­ter­net con­nec­tion. This is in­creas­ingly vi­able: the open source com­mu­nity has shown that smaller mod­els, when trained ef­fec­tively, can ap­proach fron­tier-level per­for­mance on tar­geted tasks. Muse Glimmer is op­ti­mized for these lo­cal use cases.

Keeping with our long tra­di­tion of shar­ing fun­da­men­tal AI re­search, we’re re­leas­ing Muse Glimmer open weights to­day on Hugging Face, along with de­vel­oper doc­u­men­ta­tion to help you start build­ing and run­ning your own agents. Muse Glimmer is built to work with the tools de­vel­op­ers al­ready use. Optimized in­te­gra­tions on llama.cpp, MLX, and ExecuTorch will land in the com­ing days, so you can go from down­load to work­ing agent in min­utes.

How We Trained Muse Glimmer

An agent that man­ages your sched­ule, drafts your mes­sages, or­ga­nizes your files, and learns how you work needs deep ac­cess to per­sonal con­text. It also needs sev­eral ca­pa­bil­i­ties work­ing in con­cert: long-hori­zon ex­e­cu­tion, pre­cise tool call­ing, mul­ti­modal un­der­stand­ing, long-con­text mem­ory, and in­struc­tion fol­low­ing.

We de­signed Muse Glimmer to bal­ance ca­pa­bil­ity against the mem­ory and com­pute con­straints of lo­cal hard­ware. This re­quired a com­pact ar­chi­tec­ture, a novel dis­til­la­tion recipe that trans­fers agen­tic rea­son­ing from a much larger teacher model, and in­fer­ence op­ti­miza­tions — in­clud­ing quan­ti­za­tion — to meet la­tency ex­pec­ta­tions. We achieved this in the fol­low­ing phases:

Pre-Training. We trained Muse Glimmer on Muse Spark’s out­puts us­ing logit dis­til­la­tion, lever­ag­ing a sim­i­lar data mix as the teacher.

Mid-Training. We trained the model on longer-con­text, more agent-heavy data with richer rea­son­ing traces, along­side or­ganic data.

Post-Training. We com­bined su­per­vised fine-tun­ing with a mix of on-pol­icy dis­til­la­tion and re­in­force­ment learn­ing across gen­eral, rea­son­ing, cod­ing, and agen­tic do­mains.

Muse Glimmer was eval­u­ated un­der the stan­dards set out in Meta’s Advanced AI Scaling Framework and as­sessed for open-weight re­lease across all rel­e­vant cat­e­gories.

Built for Agents: What Muse Glimmer Can Do

Building ef­fec­tive agents re­quires key ca­pa­bil­i­ties work­ing to­gether to achieve the user’s goals. Muse Glimmer is trained and eval­u­ated across each of the fol­low­ing:

End-to-end Agentic Task Completion. Muse Glimmer achieves strong suc­cess rates on full-task bench­marks in­clud­ing DeepSearch QA, MCP-Atlas, 𝛕-Bench and SWE-Bench, which mea­sure its abil­ity to work within scaf­folds, write and de­bug code, and re­solve multi-turn re­quests from start to fin­ish.

Reliable Tool Use. The model han­dles a wide range of func­tion calls, in­vok­ing tools with pre­cise schemas through­out ex­tended work­flows.

Multi-Step Reasoning. Muse Glimmer chains rea­son­ing over long hori­zons, sus­tain­ing co­her­ent plans across com­plex, ex­tended work­flows.

Failure Recovery. When a tool call fails or re­turns an un­ex­pected re­sult, the model is trained to di­ag­nose the er­ror and retry rather than halt.

Multimodal Input and Reasoning. Through a ded­i­cated per­cep­tion en­coder, the model ac­cepts in­ter­leaved text and im­ages. This en­ables agents to in­ter­pret screen­shots, charts, and doc­u­ments along­side con­ver­sa­tion.

Scaffold Compatibility. Muse Glimmer works across OpenClaw and other agen­tic or­ches­tra­tion pat­terns.

Controllable Effort. Muse Glimmer sup­ports dif­fer­ent rea­son­ing strengths to se­lect the right bal­ance be­tween qual­ity and speed.

Multilingual. Muse Glimmer is trained on data from more than 100 lan­guages.

Performance

We eval­u­ated Muse Glimmer across a broad range of bench­marks to as­sess the di­verse ca­pa­bil­i­ties re­quired for ef­fec­tive au­tonomous agent be­hav­ior. Compared with Gemma4 – 31B and Qwen3.6 – 27B, Muse Glimmer per­forms strongly for its size class on sev­eral widely used LLM bench­marks.

For more de­tail about our eval­u­a­tions, see our re­port.

Optimized for Local Deployments

A lo­cal agent is truly use­ful if it’s fast enough to feel re­spon­sive. An agent that takes min­utes to re­ply or plan its next step breaks the flow of real work. We ap­plied two op­ti­miza­tions to make Muse Glimmer run at prac­ti­cal speeds on con­sumer hard­ware with­out sac­ri­fic­ing qual­ity.

Fitting the Model on Your Device.

At full pre­ci­sion, a 30-billion pa­ra­me­ter model would re­quire over 55 GB of mem­ory — far more than any con­sumer GPU of­fers. We use quan­ti­za­tion tech­niques to com­press the mod­el’s weights to ap­prox­i­mately 4-bit pre­ci­sion, shrink­ing the lan­guage model to un­der 20 GB. This leaves enough head­room for the mod­el’s work­ing mem­ory (its KV cache”), the per­cep­tion en­coder for im­age un­der­stand­ing, and the spec­u­la­tive de­cod­ing drafter to run si­mul­ta­ne­ously within a 24 GB or 32 GB en­ve­lope. We val­i­dated that this com­pres­sion in­tro­duces min­i­mal to no degra­da­tion on agen­tic tasks.

Faster Generation Through Speculative Decoding.

Language mod­els nor­mally gen­er­ate text one to­ken at a time, which can feel slow dur­ing long rea­son­ing chains or multi-step tool calls. Muse Glimmer ships with a light­weight drafter” model based on DFlash — a small com­pan­ion net­work that pro­poses en­tire blocks of to­kens at once. The main model then ver­i­fies these pro­pos­als in par­al­lel, ac­cept­ing cor­rect to­kens and cor­rect­ing wrong ones. This tech­nique lets Muse Glimmer gen­er­ate text sig­nif­i­cantly faster than stan­dard to­ken-by-to­ken gen­er­a­tion while pro­duc­ing iden­ti­cal out­put qual­ity. We pro­vide quan­tized drafter ver­sions to in­cur a smaller mem­ory over­head in the re­lease.

The Result:

We mea­sure the speed of our K-Quant-17GB model along­side the quan­tized DFlash drafter on MacBook M4-Max, M5-Max and on a RTX-5090. The model is fast enough for fluid con­ver­sa­tion and real-time agent in­ter­ac­tion, all run­ning en­tirely on your de­vice.

Get Started With Muse Glimmer Today

Muse Glimmer is avail­able now, and you can down­load the weights on Hugging Face. In the com­ing days, run it lo­cally through part­ners like Ollama, LM Studio, and Unsloth, de­ploy it with edge frame­works in­clud­ing llama.cpp, ExecuTorch, and MLX, serve it at scale with vLLM and SGLang, or get started quickly through part­ners like Together AI, Fireworks AI, and OpenRouter. You can even cus­tomize it for your use case by lever­ag­ing PyTorch’s TorchTitan train­ing fea­ture to tune the model fur­ther.

We’re also work­ing with our part­ners in­clud­ing AMD, Arm, Dell, Intel, and NVIDIA to op­ti­mize per­for­mance across de­vices. In ad­di­tion, we’re re­leas­ing doc­u­men­ta­tion so de­vel­op­ers have the re­sources they need to get started and build re­spon­si­bly with Muse Glimmer. This in­cludes guid­ance on set­ting up cus­tom scaf­folds, so it’s even eas­ier to start build­ing and de­ploy­ing per­sonal agents on day one. You can learn more and find re­sources to build on Meta’s AI Developer Center.

This work builds on Meta’s long track record of open AI re­search, ex­tend­ing it into agen­tic AI and giv­ing de­vel­op­ers ac­cess to lo­cal agen­tic ca­pa­bil­i­ties. As al­ways, we wel­come feed­back from the com­mu­nity and can’t wait to see what de­vel­op­ers build with this open weights model.

Download the Model on Hugging Face Developer Documentation

tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

bobdahacker.com

I re­ported this on January 28th, 2026. It is now July 2026. Six months later. The Firestore data­base is still wide open. The CTO never re­sponded. I guess my emails were too long and they did­n’t view them.

What is tl;dv?

tl;dv (Too Long; Didn’t View) is an AI meet­ing record­ing plat­form. It drops a bot into your Google Meet, Zoom, or Teams call, records every­thing, tran­scribes it, and gen­er­ates sum­maries with AI. Over 2 mil­lion users. Backed by in­vestors. Endorsed by half of LinkedIn’s sales in­flu­encer com­mu­nity.

They store your sales calls, job in­ter­views, per­for­mance re­views, in­ter­nal strat­egy ses­sions. The kind of con­tent where some­one says this call is be­ing recorded” and every­one ner­vously laughs and then shares trade se­crets for 45 min­utes.

The Vulnerability

When you sign up for tl;dv, the plat­form au­then­ti­cates you with a JWT and ex­changes it for a Firebase to­ken via gw.tldv.io/​v1/​users/​fire­base/​to­ken. That to­ken lets you query their Firestore data­base at pro­jects/​lmi-store/​data­bases/(​de­fault).

The meet­ings col­lec­tion has no ten­ant iso­la­tion. Any au­then­ti­cated tl;dv user can query every meet­ing across every ac­count on the plat­form. Each meet­ing record hands you the cre­ator’s email ad­dress, the con­fer­ence ID (which is a join­able Google Meet or Teams room), the provider, the record­ing sta­tus, and time­stamps.

For meet­ings in record­ing sta­tus, that con­fer­ence ID is a live, ac­tive call. You can watch the col­lec­tion in real time, see a meet­ing start record­ing, grab the ID, and walk into some­one’s call un­in­vited. At any given time there are roughly 1,000 meet­ings with sta­tus: record­ing sit­ting in the col­lec­tion. A thou­sand live calls with ex­posed con­fer­ence IDs. An at­tacker with a bot could join all of them si­mul­ta­ne­ously.

I Joined 2 Meetings

I did it.

Grabbed a con­fer­ence ID from Firestore and joined a live Google Meet be­long­ing to the Malaysian Ministry of Education. A lady was pre­sent­ing to over 157 par­tic­i­pants. The tl;dv bot was al­ready in the par­tic­i­pant list. I was in the same call. Nobody in­vited me. The Firestore data­base did.

I also joined a call where stu­dents from a ma­jor US uni­ver­sity were build­ing a startup app. 21 peo­ple in the call. They were screen-shar­ing their en­tire pro­ject, dis­cussing pro­to­types, and, I kid you not, talk­ing about how they needed to add client-side val­i­da­tion for .edu email ad­dresses. They were also set­ting up Supabase live on screen, and all I could think was please set up RLS poli­cies” be­cause most peo­ple don’t, and then you end up like tl;dv.

I wanted to say some­thing so badly. Hey, you might want server-side val­i­da­tion too.” But this was a proof of con­cept, not a con­sul­ta­tion.

The Scale

I queried the Firestore meet­ings col­lec­tion and saw there were 181,874 meet­ing records be­long­ing to 84,312 unique users across 35,003 email do­mains.

Government meet­ings from 23 coun­tries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. All .gov do­mains. Government em­ploy­ees record­ing calls on a plat­form that lets any free-tier user enu­mer­ate the whole thing.

University meet­ings from Berkeley, the University of Tokyo, De La Salle, Universidad Nacional de Colombia. Dozens of .edu and .ac do­mains.

Corporate meet­ings from all 35,000 re­main­ing do­mains. Mitsui-Soko (484 meet­ings across four re­gional of­fices), Mitsui Fudosan, HubSpot, Confluent, Mekari, AnyMind Group. Every com­pany that ever used tl;dv had their meet­ing meta­data in the same un­pro­tected col­lec­tion.

Peak month was July 2025 with 43,209 meet­ings. Busiest time slot: Wednesday at 2pm UTC, 7,804 meet­ings. Hump-day standup hour.

But Wait, There’s More

I wanted to know how much ac­tual con­tent was ac­ces­si­ble too, by de­fault meet­ings are pri­vate (Meaning you cant watch the video or see the tran­script), so I scraped 27,334 meet­ing IDs and checked which ones were pub­lic. Over 1,000 were. 715 in­vi­tee emails ex­posed across 228 do­mains.

Highlights: a Brazilian gov­ern­ment con­ser­va­tion meet­ing (PACTO Mata Atlântica) with par­tic­i­pants from WWF, The Nature Conservancy, Conservation International, WRI, and the São Paulo state gov­ern­ment. Meetings from Ukraine’s Ministry of Digital Transformation. A HubSpot sales call. Sessions in­volv­ing Universidad Nacional de Colombia and Chile’s Cámara Verde.

The Pasta Infrastructure

tl;dv names their mi­croser­vices af­ter pasta. A sub­do­main scan re­veals cap­pellini, car­bonara, fusilli, pasta, penne, put­tanesca-v0, and ravi­oli, all un­der tldv.io. An en­tire Italian restau­rant worth of Express servers.

Too Long; Didn’t Score

While ex­plor­ing their sub­do­mains I found https://​world­cup.tldv.io. A FIFA World Cup 2026 vibecoded pre­dic­tion game built on Base44 for tl;dv em­ploy­ees. It’s called World Cup Pick’em” and their in­ter­nal squad is named Too Long; Didn’t Score.” Cute.

The Player en­tity API has zero au­then­ti­ca­tion. GET /api/entities/Player re­turns every player record with­out a ses­sion cookie. 43 play­ers. 19 @tldv.io em­ploy­ees with full names and cor­po­rate emails.

Raphael Allstadt, my dis­clo­sure con­tact who gave vague re­as­sur­ances and then went quiet, came in 2nd place with 298 points. His per­sonal Gmail was also in the API re­sponse. Player #5 on the global leader­board is Super Duper CEO.” I’ll let you guess who that is.

The Prediction and Fixture en­ti­ties are also wide open. A com­pany that records mil­lions of peo­ple’s meet­ings vibecoded an in­ter­nal fun app that leaks their own em­ployee di­rec­tory. The irony is al dente.

Disclosure

On January 28th I mes­saged Raphael Allstadt on LinkedIn and told him I’d found a huge vul­ner­a­bil­ity that leaks user data. He re­sponded within min­utes: thank you! can you re­port it to our CTO and we will look at it im­me­di­ately?” I sent the email. He said thank you!” I asked about a re­ward. My CTO will come back to you,” he said.

The CTO never came back to me.

January 29th: your cto hasnt reached out yet btw and its not fixed.” January 30th, Raphael: I am sure the team is re­view­ing it very very soon ❤️ February 14th: havent got an email and the vul­ner­a­bil­ity stilll works.” Raphael: He’ll come back ☺️ I told him to maybe fix the vul­ner­a­bil­ity and not leave cus­tomers ex­posed. February 19th: We’re on it. It needs some time, but rest as­sured we’re fol­low­ing through. For fur­ther com­mu­ni­ca­tion, i’ll rec­om­mend reach­ing out to our CTO.”

The CTO who never re­sponded. That CTO.

March 6th: still not fixed.” Seen by Raphael at 5:42 PM. No re­ply.

July 22nd: still not fixed…” No re­ply.

Their se­cu­rity page is a tro­phy case. SOC2 com­pli­ant. GDPR com­pli­ant. EU AI Act com­pli­ant. Hosted in the EU. AES-256 en­cryp­tion. A founder com­mit­ment video. Six com­pli­ance badges lined up in a row. Buried at the bot­tom, a sin­gle line: If you have dis­cov­ered a pri­vacy or se­cu­rity is­sue that we should ad­dress, please al­ways let us know at [email protected]. Our se­cu­rity team will re­spond within 24 hours.” I emailed the CTO di­rectly. Six months. No re­sponse. Their Firestore data­base has bet­ter up­time than their in­box.

To tl;dv

Your plat­form records peo­ple’s most sen­si­tive con­ver­sa­tions. Job in­ter­views. Sales ne­go­ti­a­tions. Government brief­ings. Your users trusted you with con­tent they ex­plic­itly con­sented to record.

Fix the Firestore ten­ant iso­la­tion. Firestore se­cu­rity rules ex­ist for this. You al­ready do it cor­rectly for every other col­lec­tion (users, chats, tran­scripts, clips, record­ings, videos, notes, teams, or­ga­ni­za­tions all re­turn 403). You just for­got meet­ings.

Put auth on the World Cup app or take it down. Your em­ployee di­rec­tory is one GET re­quest away.

Respond to se­cu­rity re­searchers. Especially when they’re telling you that every meet­ing on your plat­form is queryable by any­one with a free ac­count.

So long and thanks for all the pasta :3

Security Verification

www.ft.com

For help please visit help.ft.com. We apol­o­gise for any in­con­ve­nience.

The fol­low­ing in­for­ma­tion can help our sup­port team to re­solve this is­sue.

The UK’s War on Anonymity Has Come to America

www.effort.news

An Effort in­ves­ti­ga­tion has iden­ti­fied a co­or­di­nated op­er­a­tion to in­flu­ence American law­mak­ers by five for­eign non-gov­ern­ment or­ga­ni­za­tions and their US af­fil­i­ates. These NGOs have con­verged upon a uni­fied strat­egy: use the rhetoric of child safe­ty’ to ad­vo­cate for dig­i­tal ID laws that would pre­vent adults from us­ing the in­ter­net anony­mously.

In Britain, they suc­ceeded in pass­ing those laws. They now form part of a sys­tem which sur­veils, ar­rests, and jails po­lit­i­cal dis­si­dents. Digital ID laws are a key com­po­nent used to strip Brits of in­ter­net anonymity, an oth­er­wise ef­fec­tive tech­no­log­i­cal coun­ter­mea­sure against au­thor­i­tar­i­an­ism.

British NGOs are now repli­cat­ing their play­book in the United States of America, at­tempt­ing to pass a patch­work of dig­i­tal ID laws in 21 states and the US Congress.

One British NGO, 5Rights, reg­is­tered un­der the Foreign Agents Registration Act, but has failed to file crit­i­cal in­for­ma­tion re­lated to its for­eign lead­er­ship. All five for­eign NGOs have in­flu­enced American pol­icy, ei­ther di­rectly or us­ing American prox­ies with sig­nif­i­cant for­eign man­age­ment.

The Center for Countering Digital Hate (CCDH) was founded by British Labour con­sul­tants Imran Ahmed and Morgan McSweeney2.

CCDH has al­ready been in­volved in cen­sor­ship scan­dals in the US and UK. They led a boy­cott cam­paign against X im­me­di­ately af­ter Elon Musk’s ac­qui­si­tion, spon­sored ma­jor cen­sor­ship leg­is­la­tion in the UK, and fre­quently hosted events in which US and UK gov­ern­ment of­fi­cials ad­vo­cated for cen­sor­ship.3

America First Legal, a law firm con­nected with the Trump ad­min­is­tra­tion, ac­cused CCDH of vi­o­lat­ing the Foreign Agents Registration Act (FARA) in 2024. The US Department of Justice has not pub­licly an­nounced any in­ves­ti­ga­tion into CCDH, and did not re­spond to our re­quest for com­ment.

Effort in­de­pen­dently cor­rob­o­rated the core claims made in this let­ter about the na­tion­al­i­ties and res­i­dences of CCDH lead­er­ship — that Imran Ahmed is CEO of both or­ga­ni­za­tions and is a British na­tional, that Clark and Brookes are shared di­rec­tors of both US and UK en­ti­ties, and that McNeill was a board mem­ber un­til July 11, 2024.

CCDH sup­ported bills with the ex­plicit in­tent of im­port­ing British laws. A joint state­ment by Buffy Wicks, the lead au­thor of AB 2273, Jordan Cunningham, an­other AB 2273 au­thor, and 5Rights Foundation states, The Bill is prac­ti­ca­ble and re­al­is­tic, draw­ing as it does on the UKs Age Appropriate Design Code (AADC).”

AB 2273 was co-de­signed by 5Rights Foundation, a for­eign prin­ci­pal that paid to lobby for AB 2273, ac­cord­ing to their own Foreign Agents Registration Act fil­ing.

5Rights is the lead­ing NGO pro­mot­ing the British Age Appropriate Design Code / AB 2273 model across American states. 5Rights en­gaged on 42 bills across 18 states, 11 of which have be­come law.

5Rights paid Capitol Connection $50,000 to lobby in the California Legislature from May to September 2022. They did not dis­close this lob­by­ing on be­half of a for­eign agent un­til 2024, over a year af­ter the bill they lob­bied for passed.

In their dis­clo­sure, Capitol Connection de­nied that 5Rights was su­per­vised, owned, di­rected, con­trolled, fi­nanced, or sub­si­dized by a for­eign gov­ern­ment, for­eign po­lit­i­cal party, or other for­eign prin­ci­pal. They did not sub­mit any in­for­ma­tion for ques­tion 12, which could have clar­i­fied what level of con­trol Kidron, their founder and then-di­rec­tor, had over 5Rights.

5Rights is a British non­profit founded by Baroness Beeban Tania Kidron, who sits in the British House of Lords, the up­per cham­ber of the British Parliament.

Despite the British gov­ern­ment us­ing these laws to tar­get po­lit­i­cal dis­si­dents, Baroness Kidron and 5Rights now ad­vo­cate for VPN bans, a change that would add the UK to a small num­ber of au­thor­i­tar­ian regimes — Russia, China, and North Korea — that ban VPNs.4

A cen­tral node in that British cen­sor­ship ecosys­tem is the Institute for Strategic Dialogue. They have con­tracted with the US State Department, European Union, and sev­eral UK min­istries for a to­tal of over $17M US dol­lars.5

Government fund­ing records by ju­ris­dic­tion

United States

$11.21m

European Union

$5.54m

United Kingdom

$0.72m

ISDs con­tracts ex­plic­itly de­scribe a mis­sion to con­trol in­ter­net speech. In the re­ports and pol­icy rec­om­men­da­tions pro­duced for these con­tracts,6 ISD con­flates po­lit­i­cal dis­sent with misinformation”, extremism”, hate speech”, or even violent ex­trem­ism”, both jus­ti­fy­ing and en­abling cen­sor­ship by gov­ern­ments for­eign and do­mes­tic.

ISD has lob­bied fed­er­ally in the United States.7 Their re­port states that a ma­jor­ity of Board mem­bers sit on both boards so that de­ci­sions can be taken col­lec­tively.”

Reset Tech is yet an­other global con­sor­tium with over­lap­ping lead­er­ship. Reset de­scribes its own gov­er­nance as fol­lows: We are gov­erned by a Board of Directors that over­sees our global op­er­a­tions.”8

Reset Tech Action, Reset Tech’s US 501(c)4 af­fil­i­ate, spent $1,352,800 lob­by­ing Congress and state leg­is­la­tures from 2024 through Q2 2026. Effort found sig­nif­i­cant over­lap be­tween Reset Tech and 5Rights: 4 of 6 bills it lob­bied for are bills 5Rights en­gaged with, in­clud­ing AB 2273, the bill 5Rights also lob­bied for.9

Reset Tech is also tied to ISD through their EU af­fil­i­ate, Reset Tech GmbH, which re­ceived €4.9M from the EU gov­ern­ment as part of the con­sor­tium led by ISD.

In the­ory, there may be age ver­i­fi­ca­tion laws which do not con­tribute to au­thor­i­tar­ian con­trol of speech. However, when for­eign prin­ci­pals are lob­by­ing for age ver­i­fi­ca­tion law, dur­ing a time when those laws are be­ing used to sup­press po­lit­i­cal speech in their home coun­tries, it can­not be a sur­prise if those laws are used for the same pur­poses in America.

Footnotes

Effort mapped en­gage­ments based on pub­lic state­ments, records, and news cov­er­age. The map is a lower bound of en­gage­ments the Effort team was able to ver­ify, but the list of en­gage­ments might be in­com­plete.

Effort mapped en­gage­ments based on pub­lic state­ments, records, and news cov­er­age. The map is a lower bound of en­gage­ments the Effort team was able to ver­ify, but the list of en­gage­ments might be in­com­plete.

Morgan McSweeney is iden­ti­fied as a founder by The Times and the New Statesman in cov­er­age of the launch. CCDHs web­site con­tin­ues to iden­tify Imran Ahmed as its founder and CEO.

Morgan McSweeney is iden­ti­fied as a founder by The Times and the New Statesman in cov­er­age of the launch. CCDHs web­site con­tin­ues to iden­tify Imran Ahmed as its founder and CEO.

CCDH-supported UK cen­sor­ship leg­is­la­tion:

Draft Online Safety Bill Online Safety Bill Online Safety Act 2023

X boy­cott cam­paign and cen­sor­ship speeches

CCDH-supported UK cen­sor­ship leg­is­la­tion:

Draft Online Safety Bill

Online Safety Bill

Online Safety Act 2023

X boy­cott cam­paign and cen­sor­ship speeches

In an ar­ti­cle ti­tled The VPN loop­hole in the fight to pro­tect chil­dren,” Kidron called so­cial me­dia bans with­out VPN bans for show and head­lines, not for chil­dren.” This rhetoric is de­ployed for a VPN-ban pol­icy which would pre­dom­i­nantly af­fect adults.

In an ar­ti­cle ti­tled The VPN loop­hole in the fight to pro­tect chil­dren,” Kidron called so­cial me­dia bans with­out VPN bans for show and head­lines, not for chil­dren.” This rhetoric is de­ployed for a VPN-ban pol­icy which would pre­dom­i­nantly af­fect adults.

We use con­ver­sion rates for July 27, 2026: €1 = $1.1389 and €1 = £0.85524. It ex­cludes the £635,204 ag­gre­gate for three un­named gov­ern­ment con­tracts and the £2,322,079 un­al­lo­cated gov­ern­ment-and-mul­ti­lat­eral re­main­der.

PeriodGovernment coun­ter­par­tyRe­cip­i­ent ISD en­ti­ty­Con­tract / award / spend recor­dReported amoun­tRecord

2024Government coun­ter­par­ties not namedIn­sti­tute for Strategic Dialogue (UK)Three gov­ern­ment con­tracts re­ported in the an­nual-re­turn sum­mary£635,204Char­ity Commission record 2024Multiple gov­ern­ments and mul­ti­lat­er­alsIn­sti­tute for Strategic Dialogue (UK)Accounts-listed fun­ders: US State Department; European Union; UK FCDO, DCMS and Home Office; Australian DFAT; Danish MFA; New Zealand Department of Internal Affairs; Public Safety Canada; Canadian Privy Council; UNESCO; German Government; and Ministerium der Finanzen des LandesNot sep­a­rately dis­closedISD 2024 ac­counts 2024Government and mul­ti­lat­eral in­sti­tu­tion­sIn­sti­tute for Strategic Dialogue (UK)Undisclosed re­main­der af­ter the three-con­tract ag­gre­gate£2,322,079­Cal­cu­lated from £2,957,283 less £635,204; see 2024 ac­counts. 2019 – 2021London MOPACInstitute for Strategic Dialogue (UK)Comprehensive scop­ing, en­gage­ment and con­sul­ta­tion process£50,000­MOPAC con­tract reg­is­ter 2022OfcomInstitute for Strategic Dialogue (UK)Analysis of on­line hate in the UK£79,250Contracts Finder 2022 – 2024London MOPACInstitute for Strategic Dialogue (UK)Shared Endeavour Fund in­de­pen­dent fund eval­u­a­tion£49,961.75­MOPAC reg­is­ter 2023 – 2024London MOPACInstitute for Strategic Dialogue (UK)Shared Endeavour Fund in­de­pen­dent fund eval­u­a­tion ex­ten­sion£61,746­MOPAC reg­is­ter 2023UK Department for Digital, Culture, Media & SportInstitute for Strategic Dialogue (UK)Research into cli­mate-re­lated mis/​dis­in­for­ma­tion af­fect­ing the UK£37,677Open-contract record 2024UK Foreign, Commonwealth & Development OfficeInstitute for Strategic Dialogue (UK)PPM con­sul­tancy spend recorded in January£102,437.90FCDO spend file 2024UK Foreign, Commonwealth & Development OfficeInstitute for Strategic Dialogue (UK)PPM con­sul­tancy spend recorded in March£158,752.07FCDO spend file 2024UK Ministry of Housing, Communities & Local GovernmentInstitute for Strategic Dialogue (UK)Evidence re­view of the 2022 Leicester un­restUndis­closedISD 2024 ac­counts 2024 – 2027European Commission, DG CNECTInstitute for Strategic Dialogue gGmbH (Germany), con­sor­tium lead; Institute for Strategic Dialogue (UK), con­sor­tium mem­berDig­i­tal Services Act com­pli­ance mon­i­tor­ing, five-mem­ber con­sor­tium€4,861,089 con­sor­tium to­tal; ISD share undis­closedTED award no­tice 2019 – 2022US Department of StateInstitute for Strategic Dialogue (UK)Community-based in­ter­ven­tions pro­gram in Kenya · SLMAQM19GR2273$2,250,000USAspending 2024 – 2027US Department of JusticeInstitute for Strategic Dialogue–USStrong Cities Network com­mu­nity-based hate-pre­ven­tion pro­ject · 15PBJA24GG02835ADVA$2,000,000USAspending 2022 – 2023US Department of StateInstitute for Strategic Dialogue (UK)Strong Cities Network re­gional hubs and gov­er­nance · SLMAQM22CA0079$1,333,333USAspending 2024 – 2026US Department of Homeland SecurityInstitute for Strategic Dialogue–USDomestic vi­o­lent-ex­trem­ism trends analy­sis · 23STFRG00021$1,249,621DHS no­tice of award Period not re­port­e­dUS Department of Homeland SecurityInstitute for Strategic Dialogue–USCountering vi­o­lent ex­trem­ism fi­nan­cial as­sis­tance · EMW-2023-GR-00123$817,129USAspending 2017 – 2019US Department of StateInstitute for Strategic Dialogue (UK)Novation from Trialogue Educational Trust · SLMAQM17CA2016$567,953.63USAspending 2024 – 2025US Department of StateInstitute for Strategic Dialogue (UK)Strong Cities Network ca­pac­ity-build­ing · SAQMIP24CA5173$444,005USAspending 2021 – 2023US Department of StateInstitute for Strategic Dialogue–USYoung peo­ple’s on­line and of­fline ini­tia­tives · SJO10021CA3010$422,408.08USAspending 2024 – 2025US Department of Homeland SecurityInstitute for Strategic Dialogue–USTargeted Violence and Terrorism Prevention grant · EMW-2024-GR-05344$315,009.94USAspending 2021 – 2023US Department of StateInstitute for Strategic Dialogue (UK)Young Cities pro­gram in Belgium · SBE20021GR3012$269,541.97USAspending 2023 – 2024US Department of StateInstitute for Strategic Dialogue (UK)Community re­silience against hate and po­lar­iza­tion · SGE21023GR0096$249,783.96USAspending 2023 – 2024US Department of StateInstitute for Strategic Dialogue (UK)Social co­he­sion and anti-Ukraine nar­ra­tives · SAQMIP24GR0009$246,669USAspending 2017US Department of StateInstitute for Strategic Dialogue–USStrong Cities Network CVE ex­per­tise · SLMAQM17CA1034$238,235USAspending 2018US Department of StateInstitute for Strategic Dialogue (UK)Digital plat­forms for im­mi­gra­tion in­te­gra­tion and CVE · SBE20017GR029$199,727USAspending 2021 – 2023US Department of StateInstitute for Strategic Dialogue (UK)City Pair Program work­shop · SFI30021GR3015$140,000USAspending 2017 – 2018US Department of StateInstitute for Strategic Dialogue (UK)Strong Cities Network ex­changes and work­shops · SIN65017CA0020$80,000USAspending 2020 – 2021US Department of StateInstitute for Strategic Dialogue (UK)Monitoring on­line in­for­ma­tion op­er­a­tions dur­ing COVID-19 · SFR63020CA0049$66,293.46USAspending 2024 – 2025US Department of StateInstitute for Strategic Dialogue (UK)Strong Cities Network peer learn­ing and ca­pac­ity build­ing · SUK56024GR0031$63,760USAspending 2017 – 2018US Department of StateInstitute for Strategic Dialogue (UK)Travel for Strong Cities Network work­shop · SUK56017CA034$50,000USAspending 2008 – 2009US Department of StateInstitute for Strategic Dialogue (UK)Counter-radicalization re­search and net­work de­vel­op­ment · SUK56008GR724$50,000USAspending 2017US Department of StateInstitute for Strategic Dialogue–USIndonesia CVE mes­sag­ing · SLMAQM17CA1041$33,848.99USAspending 2024US Department of StateInstitute for Strategic Dialogue–USLocal-leader con­fer­ence on hate pre­ven­tion and so­cial co­he­sion · SCA52524GR0019$32,963.16USAspending 2024 – 2025US Department of StateInstitute for Strategic Dialogue (UK)Strong Cities Network global sum­mit lo­gis­tics · SSF75024GR0015$24,992USAspending 2024US Department of StateInstitute for Strategic Dialogue–USCity-led strate­gies against hate ini­tia­tive · SSW80024GR0003$24,578.09USAspending 2018US Department of StateInstitute for Strategic Dialogue (UK)Australian–American city ties · SAS20018GR034$17,383USAspending 2024US Department of StateInstitute for Strategic Dialogue–USFrench cities coun­ter­ing hate-mo­ti­vated vi­o­lence · SFR63024CA0018$14,000USAspending 2023US Department of StateInstitute for Strategic Dialogue (UK)Strong Cities transat­lantic event travel · SNO60023GR0011$10,000USAspending 2024 – 2025US Department of StateInstitute for Strategic Dialogue (UK)Smart Cities Network peer learn­ing and ca­pac­ity build­ing · SMO55024GR0075$1,560.21USAspending

US rows are the com­plete set of re­cip­i­ent-name matches for INSTITUTE FOR STRATEGIC DIALOGUE in USAspending’s pro­ject-grant and co­op­er­a­tive-agree­ment search through August 3, 2026; award val­ues are shown in US dol­lars.

We use con­ver­sion rates for July 27, 2026: €1 = $1.1389 and €1 = £0.85524. It ex­cludes the £635,204 ag­gre­gate for three un­named gov­ern­ment con­tracts and the £2,322,079 un­al­lo­cated gov­ern­ment-and-mul­ti­lat­eral re­main­der.

US rows are the com­plete set of re­cip­i­ent-name matches for INSTITUTE FOR STRATEGIC DIALOGUE in USAspending’s pro­ject-grant and co­op­er­a­tive-agree­ment search through August 3, 2026; award val­ues are shown in US dol­lars.

Archived ISD re­port ex­am­ple.

Archived ISD re­port ex­am­ple.

US Senate LDA data­base.

Federal fil­ing pe­ri­o­dReg­is­trantRe­ported amountSource

2026 Q1ISD-USLess than $5,000LDA re­port 2026 Q2ISD-USLess than $5,000LDA re­port

US Senate LDA data­base.

Reset Tech home­page global col­lec­tive ref­er­ences: Reset Tech”: 1, we”: 6, and our”: 5 (only in the con­text of Reset Tech).

Reset Tech home­page global col­lec­tive ref­er­ences: Reset Tech”: 1, we”: 6, and our”: 5 (only in the con­text of Reset Tech).

The table to­tals $1,352,800 in re­ported lob­by­ing pay­ments and ex­pen­di­tures from 2024 through Q2 2026: $1,222,500 in fed­eral lob­by­ing pay­ments, $100,000 in Maryland em­ployer ex­pen­di­tures, and $30,300 in Nebraska lob­by­ist com­pen­sa­tion and re­im­burse­ment.

Filing pe­ri­o­dReg­is­trantRe­ported amount

2024 Q1–Q4Corbin Strategies$320,000 2024 Q1–Q4Center Road Solutions$170,000 2025 Q1–Q4; 2026 Q1–Q2EFB Advocacy LLC$502,500 2024 Q1–Q4; 2025 Q1–Q4Epplin Strategic Planning$230,000 2024Reset Tech Action$100,000 2024 – 2025Reset Tech Action$30,300

The table to­tals $1,352,800 in re­ported lob­by­ing pay­ments and ex­pen­di­tures from 2024 through Q2 2026: $1,222,500 in fed­eral lob­by­ing pay­ments, $100,000 in Maryland em­ployer ex­pen­di­tures, and $30,300 in Nebraska lob­by­ist com­pen­sa­tion and re­im­burse­ment.

We iden­ti­fied AVPA as a sig­nif­i­cant for­eign in­flu­ence over age ver­i­fi­ca­tion laws in the UK and US and added them to the map ac­cord­ingly, but they are out­side of the di­rect scope of this in­ves­ti­ga­tion, as we did not iden­tify legally clas­si­fied lob­by­ing from AVPA.

AVPA is a British trade or­ga­ni­za­tion of age ver­i­fi­ca­tion sup­pli­ers — mem­bers with a fi­nan­cial stake in age ver­i­fi­ca­tion man­dates.

AVPAs page lists Alastair Graham as chair and Ian Moody, Tony Allen, Andy Lulham, Julie Dawson, and Ryan Bessemer as the ex­ec­u­tive com­mit­tee. Their na­tion­al­i­ties are as fol­lows.

NameRoleSource con­firm­ing cit­i­zen­ship

Alastair GrahamChairBritish — Companies House of­fi­cer record Ian MoodyExecutive CommitteeBritish — Companies House of­fi­cer record Tony AllenExecutive CommitteeBritish — Companies House of­fi­cer record Andy LulhamExecutive CommitteeBritish — LinkedIn pro­file Julie DawsonExecutive CommitteeBritish — Companies House Yoti di­rec­tor record Ryan BessemerExecutive CommitteeAustralian — LinkedIn pro­file

We iden­ti­fied AVPA as a sig­nif­i­cant for­eign in­flu­ence over age ver­i­fi­ca­tion laws in the UK and US and added them to the map ac­cord­ingly, but they are out­side of the di­rect scope of this in­ves­ti­ga­tion, as we did not iden­tify legally clas­si­fied lob­by­ing from AVPA.

AVPA is a British trade or­ga­ni­za­tion of age ver­i­fi­ca­tion sup­pli­ers — mem­bers with a fi­nan­cial stake in age ver­i­fi­ca­tion man­dates.

AVPAs page lists Alastair Graham as chair and Ian Moody, Tony Allen, Andy Lulham, Julie Dawson, and Ryan Bessemer as the ex­ec­u­tive com­mit­tee. Their na­tion­al­i­ties are as fol­lows.

Just a moment...

www.patreon.com

Mars Bar from the 1990s found during house clearance

www.bbc.com

Mars Bar from 1991 found - and it’s 20g big­ger than to­day’s

20 hours ago

Eleanor MaslinEast Yorkshire and Lincolnshire

Victoria Gordon

A 35-year-old Mars Bar has been found dur­ing a house clear­ance — and the dis­cov­ery has gone vi­ral amid claims it high­lights the ef­fect of shrinkflation”.

The choco­late bar with a best-be­fore date of 1991 was found dur­ing a clear-out of a house in Scunthorpe.

Victoria Gordon, who runs the clean­ing ser­vice, posted a photo on so­cial me­dia of the 62.5g bar along­side one of to­day’s Mars Bars, which is 40g.

It was nearly as big as my hand, which was kind of why I no­ticed it,” she said.

Victoria Gordon

Speaking on BBC Radio Lincolnshire, Gordon said: We were clear­ing out a hoard­er’s house and every­thing we were root­ing through was decades old.

This Mars Bar stood out to me be­cause as I picked it up it was nearly the whole length of my hand.

I was like, Wow, look at the size of that!’”

A Mars spokesper­son said: Over the last 35 years, we have made a num­ber of up­dates to our bar sizes and pack for­mats to re­flect con­sumer de­mand, along­side con­sid­er­ing wider ex­ter­nal fac­tors such as man­u­fac­tur­ing costs and the price of co­coa.”

Supplied

Gordon, who runs Pocket Rockets, is not sure what she will do with the bar, but she said she might be sit­ting on a gold mine”.

I do post some hoard­ing videos but I’ve never had any­thing go this vi­ral,” she said.

It’s so fas­ci­nat­ing what peo­ple find so in­ter­est­ing. I al­most put it in the skip [but] I might do a UK tour with it.”

Related sto­ries

Illinois HB5511: What It Means for Linux and Open Source

linuxstans.com

HB5511 is of­fi­cially about TikTok and Instagram. Read past the press re­lease and it’s also about your op­er­at­ing sys­tem.

Governor JB Pritzker’s press re­lease on HB5511 is thick with quotes from leg­is­la­tors and ad­vo­cacy groups, and it names Instagram, TikTok, Snapchat, X, Facebook, and Roblox specif­i­cally. Device setup gets one men­tion, framed as some­thing a par­ent con­fig­ures dur­ing setup. Nowhere does it ex­plain that the law also cre­ates a sep­a­rate le­gal cat­e­gory called an op­er­at­ing sys­tem provider, with its own 2028 dead­line and its own civil penal­ties, that has noth­ing to do with what any par­ent chooses to click.

TL;DR

HB5511, the Children’s Social Media Safety Act, is now Illinois Public Act 104 – 0664. Pritzker signed it July 31.

The head­line pro­vi­sions tar­get so­cial plat­forms: no al­go­rith­mic feeds for mi­nors by de­fault, no no­ti­fi­ca­tions be­tween 10pm and 7am, no con­tact from adult strangers.

A sep­a­rate part of the bill de­fines op­er­at­ing sys­tem provider and cov­ered man­u­fac­turer broadly enough to in­clude any­one who builds an in­ter­net-con­nected OS, com­mer­cial or non­profit.

By January 1, 2028, those providers have to build an age-de­c­la­ra­tion step and hand an age-bracket sig­nal to any app that re­quests one.

Unlike Colorado, and un­like where California is head­ing, Illinois added no ex­emp­tion for open source soft­ware.

Enforcement runs through the Illinois Attorney General only. The bil­l’s own text caps penal­ties at $7,500 per af­fected child. The gov­er­nor’s press re­lease ad­ver­tises penal­ties of up to $50,000 per vi­o­la­tion. Those num­bers don’t ob­vi­ously square with each other.

The Version Illinois Wants You to Read

Set the op­er­at­ing sys­tem ques­tion aside for a sec­ond, be­cause the so­cial me­dia half of this bill is fairly stan­dard for 2026. Platforms built around al­go­rith­mic feeds, plus plat­forms where kids can be con­tacted by strangers (Roblox is the named ex­am­ple), now have to de­fault mi­nors into chrono­log­i­cal, fol­low-only feeds in­stead of an en­gage­ment-op­ti­mized one. Notifications get cut off overnight. Adult strangers can’t see a mi­nor’s pro­file, mes­sage them, or see their lo­ca­tion. News sites, email providers, broad­band com­pa­nies, and school soft­ware are all carved out by name.

It passed the General Assembly on June 1 with­out a sin­gle no vote, 57 – 0 in the Senate and 113 – 0 in the House con­cur­rence. Pritzker signed it July 31, flanked by quotes from Attorney General Kwame Raoul and groups like Common Sense Media and Mothers Against Media Addiction. Nothing about that roll­out men­tions your desk­top.

The Part the Press Release Skipped

Here’s what ac­tu­ally set off the Reddit thread: a post claim­ing Illinois now re­quires op­er­at­ing sys­tem providers, open source pro­jects in­cluded, to build age ver­i­fi­ca­tion by 2028. It was­n’t uni­ver­sally be­lieved. On at least one mir­ror of the dis­cus­sion, a com­menter ar­gued the fram­ing was mis­lead­ing and that the post should be cor­rected. So in­stead of trust­ing a screen­shot ei­ther way, we went and read the bill on the Illinois General Assembly’s own tracker.

It holds up. Separate from the so­cial me­dia rules, HB5511 cre­ates du­ties for an op­er­at­ing sys­tem provider and folds de­vice mak­ers, OS ven­dors, and app stores to­gether un­der the term cov­ered man­u­fac­turer. Legislative track­ers that fol­low this ex­act cat­e­gory of bill across states file this piece un­der its own name: Digital Age Assurance, the same bucket Colorado’s and California’s ver­sions land in.

What Every Covered Manufacturer Has to Build by 2028

An ac­ces­si­ble setup screen that asks an ac­count holder to in­di­cate a birth date, an age, or both.

A way for any app or plat­form that asks (the bill calls them operators” and covered de­vel­op­ers”) to re­ceive a sig­nal for that age, de­liv­ered through a con­sis­tent, en­crypted API.

A hard limit on what gets shared: only the min­i­mum in­for­ma­tion needed to an­swer the ques­tion, and no hand­ing it to a third party be­yond what the law re­quires.

The sig­nal it­self is­n’t a birth­day, it’s a bracket: un­der 13, 13 to 15, 16 to 17, or 18 and up. Operating sys­tems have un­til January 1, 2028 to have this built. Platforms then have un­til July 1, 2028 to start ac­tu­ally re­quest­ing that sig­nal for their users. Once an app gets a minor” bracket back, the law treats it as hav­ing ac­tual knowl­edge the user is un­der­age, which is what flips on every de­fault pro­tec­tion in the so­cial me­dia half of the bill.

Nothing in the bill re­quires a pass­port scan or a face scan at setup. It’s self-de­clared, the same way most apps ask your birth­day to­day, just cen­tral­ized once at the OS level in­stead of re­peated app by app. That’s ex­actly why a good chunk of the r/​linux replies were jokes about set­ting their in­stal­l’s date of birth to some­time in the Nixon ad­min­is­tra­tion.

Nobody Carved Out an Exception This Time

This struc­ture, OS hands out an age bracket, apps pull it through an API, al­ready showed up in Colorado and California, and both ran into the same ob­jec­tion: the de­f­i­n­i­tions were broad enough to catch com­mu­nity-run, non­com­mer­cial, open source pro­jects with no re­al­is­tic way to run an age-gated setup wiz­ard, let alone a com­pli­ance de­part­ment.

Colorado fixed it. Governor Jared Polis signed SB26 – 051 on June 3, and largely be­cause System76 founder Carl Richell worked di­rectly with the bil­l’s co-au­thor, State Senator Matt Ball, the fi­nal ver­sion ex­empts op­er­at­ing sys­tems, apps, code repos­i­to­ries like GitHub and GitLab, and con­tainer plat­forms like Docker and Podman, as long as they’re dis­trib­uted un­der an open li­cense. It also blocks a ven­dor from lock­ing down a mod­i­fied ver­sion of the soft­ware just to dodge the ex­emp­tion.

California is try­ing to get to the same place. Its orig­i­nal law, AB-1043, had the iden­ti­cal gap. Assemblymember Buffy Wicks, who wrote that bill, in­tro­duced a fol­low-up, AB-1856, specif­i­cally to re­de­fine op­er­at­ing sys­tem provider so it ex­cludes any­one ship­ping soft­ware un­der those same open terms. As of this writ­ing, that fix is still mov­ing through Sacramento, not fin­ished.

Illinois skipped that step en­tirely. HB5511s de­f­i­n­i­tions for cov­ered man­u­fac­turer and ap­pli­ca­tion store are ex­actly as broad as Colorado’s and California’s were be­fore any­one patched them. The struc­ture is­n’t unique to Illinois, ei­ther: California did it first, Colorado fol­lowed the same blue­print, and HB5511 reads like a close cousin of both, same age brack­ets, same API-based sig­nal, same per-child penalty fig­ures.

Even Big Tech’s Own Lobby Hated This One

Before Pritzker signed any­thing, the Electronic Frontier Foundation sent him a let­ter ask­ing for a veto, call­ing the bill a mas­sive pri­vacy and free speech night­mare” and nam­ing the open source ecosys­tem specif­i­cally as one of the things it put at risk. EFF grouped Illinois with a wider run of state bills lean­ing on child safety lan­guage to jus­tify sweep­ing age-ver­i­fi­ca­tion man­dates.

Separately, and for very dif­fer­ent rea­sons, NetChoice, the trade group that counts com­pa­nies like Google and Meta among its mem­bers, filed tes­ti­mony op­pos­ing the same bill. Its ob­jec­tion was First Amendment law and the risk of ex­pos­ing sen­si­tive user data, not open source specif­i­cally. It’s an odd pair­ing: a dig­i­tal rights non­profit and the lob­by­ing arm for the plat­forms the bill is sup­posed to be reg­u­lat­ing, ar­gu­ing against the same bill for op­po­site rea­sons. Illinois law­mak­ers passed it unan­i­mously any­way.

Could Anyone Actually Enforce This?

Only the Illinois Attorney General can bring a case. There’s no pri­vate right of ac­tion, so an in­di­vid­ual can’t sue over this per­son­ally. The civil penalty writ­ten into the bill it­self is up to $2,500 per af­fected child for a neg­li­gent vi­o­la­tion and up to $7,500 per af­fected child for an in­ten­tional one. That’s not a co­in­ci­dence: it’s the ex­act same fig­ure Colorado’s law uses, be­cause these bills are largely work­ing from the same tem­plate as they spread state to state.

Set that against the gov­er­nor’s own press re­lease, which ad­ver­tises penal­ties of up to $50,000 per vi­o­la­tion. It’s pos­si­ble both num­bers are tech­ni­cally ac­cu­rate and just re­fer to dif­fer­ent sec­tions of a fairly long piece of leg­is­la­tion, but noth­ing in the state’s own ma­te­ri­als rec­on­ciles them for the reader, and the big­ger num­ber is the one that made it into the an­nounce­ment.

As for ac­tu­ally reach­ing a hob­by­ist dis­tro main­tainer: noth­ing in the bill has teeth against some­one with no busi­ness pres­ence in Illinois, which is ex­actly the loop­hole half of r/​linux jumped to im­me­di­ately. Expect a wave of joke warn­ing la­bels on dis­tro down­load pages long be­fore any­one pays a fine. The providers who can’t shrug this off are the ones al­ready do­ing real busi­ness in the state, mean­ing Google, Microsoft, Apple, and any Linux ven­dor with ac­tual Illinois rev­enue on the books.

What Happens Between Now and 2028

The com­pli­ance dead­line is still more than a year out, which leaves room for a few things to hap­pen be­fore it mat­ters. NetChoice has al­ready chal­lenged com­pa­ra­ble so­cial me­dia and age-ver­i­fi­ca­tion laws in Mississippi, Colorado, California, Louisiana, Georgia, and Ohio, with mixed re­sults, some pro­vi­sions blocked, oth­ers up­held. Given that track record, a chal­lenge to HB5511 specif­i­cally would­n’t be a shock, though noth­ing had been filed as of this writ­ing. There’s also room for an amend­ment adding the same open source carve-out Colorado and California landed on. Or there’s room for noth­ing to change, in which case Illinois be­comes the ver­sion other states copy in­stead of the ex­cep­tion.

Which of those hap­pens prob­a­bly de­pends on whether the open source com­mu­nity shows up in Springfield the way Carl Richell showed up in Denver. Nobody did this time. There’s still time to change that be­fore January 1, 2028 turns into a dead­line that ac­tu­ally bites.

Needle 2 - The 14 MB Agentic LLM for Tiny Devices | Cactus

cactuscompute.com

Today we re­lease Needle 2: an open 45M-parameter model for tool call­ing, de­vice use and struc­tured ex­trac­tion. The whole model is a sin­gle 14MB bi­nary that runs a full ses­sion in 28MB of RAM. It is built on our Simple Attention Network find­ings, com­pressed to CQ2-bit with Cactus Quants, and baked into its own en­gine.

On the tool call and mo­bile de­vice use bench­marks, Needle 2 trades wins with other small mod­els like FunctionGemma 270M, LFM2.5 230M and Apple FM, at to 70× smaller, and 2 bits against their f16. Needle hits 500 to­kens/​sec de­code speed on a Raspberry Pi 5, be­tween 400 – 1,500 to­kens/​sec on VR de­vices like Meta Quest 3S and Apple Vision Pro, and ranges 300 – 700 on sub-$200 phones such as the Samsung A-Series. With a peak ses­sion RAM around 28MB, Needle runs on newer mi­cro­con­trollers like ESP32-S3.

The Playground lets you test Needle for wear­ables, ro­bots, smart homes, phones, and au­to­mo­tive. Needle is li­censed un­der Apache 2.0, with weights on Hugging Face; the repo gets you run­ning.

Our Bet

Bringing On-Device AI to <$200 Devices: Edge AI has lately meant Macs and PCs, but the edge is mostly cheap hard­ware: over 21 bil­lion con­nected IoT de­vices against roughly 1.5 bil­lion PCs, and in emerg­ing mar­kets most phones ship un­der $200. Count bud­get phones, Raspberry Pis, mi­cro­con­trollers, wear­ables, small ro­bots like Reachy Mini, and con­nected home de­vices, and roughly four in five edge de­vices cost un­der $200. That is the hard­ware Needle tar­gets: no GPU, no NPU, a few hun­dred MB of RAM.

Function Call & Device Use: Turning on a light does not need a fron­tier model. A watch, a home, a ro­bot: each al­ready ex­poses its abil­i­ties as func­tions with typed pa­ra­me­ters, so the only hard part is map­ping a messy sen­tence onto them: which func­tion, with which val­ues. Framed that way, the prob­lem needs no world knowl­edge and no open-ended prose, which is why 45M pa­ra­me­ters suf­fice where chat needs bil­lions. That smaller for­mu­la­tion is the bet every­thing else fol­lows from.

Extraction & Structured Outputs: The schema is the in­ter­face, and the same for­mu­la­tion cov­ers doc­u­ments: a schema plus a para­graph re­turns typed fields, an enum field is a clas­si­fier, an ar­ray field col­lects a list in one call. We en­force this with a con­tract, not a con­ven­tion: every turn is an­swered with a call en­ve­lope, the empty call is the re­fusal, and a byte-level gram­mar com­piled from the de­clared schemas con­strains every to­ken. The gram­mar car­ries the syn­tax, so all 45M pa­ra­me­ters go to choos­ing func­tions and ground­ing ar­gu­ments in the user’s words.

Edge-Cloud Collaboration: No small model cov­ers every­thing, so Needle says so in­stead of guess­ing: every re­sponse car­ries a learned con­fi­dence score, and off-topic re­quests re­turn the empty call. Above your thresh­old, act; be­low it, re-ask or es­ca­late to the cloud. Most de­vice re­quests are rou­tine con­trol, so es­ca­la­tion stays rare and the de­fault path stays pri­vate, in­stant, and free.

Lossless 2bit Quantization: Small mod­els break un­der post-hoc quan­ti­za­tion, so we never quan­tize post-hoc: Needle 2 trains against Cactus Quants from pre­train through post-train, weights, ac­ti­va­tions, and KV cache alike. The 2bit model you de­ploy is the model that was trained. That is what fits 45M pa­ra­me­ters into 14MB with noth­ing lost on our bat­tery.

Co-designed Model & Inference: Every ar­chi­tec­tural choice was bench­marked on the tar­get hard­ware be­fore it earned its pa­ra­me­ters, and the de­liv­er­able is the pair, not the weights: a sin­gle de­pen­dency-free C++ bi­nary that probes the CPU at startup and picks its ker­nels, with the model, to­k­enizer, and gram­mar com­piler sealed in­side. One ar­ti­fact runs from Cortex-M to x86 to WebAssembly. There is noth­ing to in­stall and noth­ing to down­load.

Fine-tune on your Mac/PC: Every prod­uct has its own tool vo­cab­u­lary, and a 45M model is small enough to re­train where it runs: the repo and python pack­age tune and test on your own com­puter in min­utes to a few hours. Ship a Needle that speaks your de­vice’s tools, not a generic as­sis­tant.

Production

Needle is pro­duc­tion-ready for prod­ucts that re­quire a min­i­mal RAM foot­print, low la­tency, pri­vacy, and of­fline re­li­a­bil­ity. Pebble - the pi­o­neer of the mod­ern wear­able in­dus­try - runs it lo­cally in the Index 01 app to turn spo­ken re­quests into ac­tions with­out de­pend­ing on a net­work con­nec­tion.

The Pebble Index Ring has no screen. So when you speak to it, the ac­tion just has to hap­pen, every time, with or with­out in­ter­net con­nec­tion. We run Cactus Needle lo­cally in the app, in­stead of re­ly­ing on the cloud. The mod­el’s foot­print is tiny and the per­for­mance never lets us down.

The Pebble Index Ring has no screen. So when you speak to it, the ac­tion just has to hap­pen, every time, with or with­out in­ter­net con­nec­tion. We run Cactus Needle lo­cally in the app, in­stead of re­ly­ing on the cloud. The mod­el’s foot­print is tiny and the per­for­mance never lets us down.

Architecture

Needle 2 is pre­trained on a pro­pri­etary 115B-token cor­pus and post-trained on 38B to­kens with com­pact rea­son­ing traces and care­ful dataset dis­tri­b­u­tion de­sign. For scale: LFM2.5 – 230M was pre­trained on 19 tril­lion to­kens, roughly 120× Needle’s to­tal, and the eval­u­a­tion be­low shows the two trad­ing wins. Each com­po­nent ex­ists to buy ca­pa­bil­ity with­out buy­ing band­width. The Hadamard MLP re­places the usual dense up-and-down pro­jec­tions with a fixed Walsh trans­form and learned di­ag­o­nals, so the chan­nel mix­ing that dom­i­nates a small mod­el’s weight reads costs al­most no pa­ra­me­ters at all. The en­gram moves world knowl­edge out of the stack into hashed n-gram ta­bles that are read a few rows per to­ken: ca­pac­ity that is nearly free at de­code time, which mat­ters on de­vices where every megabyte read from flash is la­tency and bat­tery. The multi-lane resid­ual streams give a 27-layer, 512-wide net­work the rout­ing flex­i­bil­ity of a much wider one, at the cost of a few dot prod­ucts per layer rather than more at­ten­tion or MLP vol­ume.

The mem­ory sys­tem is de­signed back­wards from fixed-RAM de­vices. Attention uses a 256-token slid­ing win­dow so the KV cache is bounded no mat­ter how long a ses­sion runs, and the sys­tem prompt and tool de­c­la­ra­tions are pinned as per­ma­nent sinks so the one thing a tool-call­ing model must never for­get—its tools—is struc­turally un­able to be evicted. The cache it­self is trained with QAT, and weights are stored in Cactus Quants at a mixed bits per weight av­er­ag­ing 2bit. The re­sult is that qual­ity de­ci­sions and de­ploy­ment de­ci­sions stay de­cou­pled: one trained model, spe­cial­ized to what­ever pre­ci­sion and win­dow a tar­get de­vice can af­ford.

The en­gine earns its speed from what it re­fuses to com­pute. Weights never de­com­press into RAM: the 2-bit codes are ex­panded in­side vec­tor reg­is­ters, fused into in­te­ger dot prod­ucts, so res­i­dent mem­ory stays at blob size and the arith­metic path is int8 end to end—ac­ti­va­tions, KV cache, and the lane rout­ing ta­bles alike. The gram­mar is an op­ti­miza­tion, not just a guar­an­tee: be­cause the matcher knows which to­kens are le­gal be­fore the log­its ex­ist, the en­gine com­putes out­put scores only for can­di­date rows, skip­ping up to 98% of the vo­cab­u­lary pro­jec­tion on struc­tural to­kens, and skips it en­tirely on steps whose out­put is al­ready forced. One uni­ver­sal bi­nary probes the CPU at startup and self-se­lects its ker­nel tier—SDOT, NEON, AVX2, RISC-V vec­tors, wasm SIMD, or scalar—and the thread pool spins through the short se­r­ial sec­tions of a to­ken in­stead of sleep­ing, which alone nearly dou­bled de­code. None of this changes a sin­gle out­put: every trick is ei­ther ex­act or val­i­dated to­ken-for-to­ken against the ref­er­ence path.

All of it is ul­ti­mately an en­ergy ar­gu­ment. On de­vice sil­i­con, mov­ing a byte out of flash or DRAM costs or­ders of mag­ni­tude more than a mul­ti­ply-ac­cu­mu­late, so the bud­get that mat­ters is FLOPs per to­ken and bytes per to­ken to­gether. The ar­chi­tec­ture cuts the first: a con­ven­tional trans­former of Needle’s width and depth spends 164 MFLOPs per to­ken, and even one squeezed down to Needle’s pa­ra­me­ter count spends 87, be­cause every pa­ra­me­ter it owns must be ex­er­cised through a mat­mul. Needle spends 70, and keeps a fifth of its pa­ra­me­ters as gath­ered mem­ory that costs no arith­metic at all. The bi­nary cuts the sec­ond, as the en­gine sec­tion showed: noth­ing re­ma­te­ri­al­izes, the arith­metic stays int8 end to end, and the gram­mar prunes com­pute out­right, so de­cod­ing a to­ken reads at most the 14MB blob once, and on struc­tural to­kens mean­ing­fully less. This is what bat­tery life is made of. Even on a high-end phone, an al­ways-on as­sis­tant lives in­side a power bud­get; every MFLOP is mil­li­watt-hours, and Needle spends to 85× fewer of them per to­ken than the mod­els it is bench­marked against.

Compute per to­ken

Bounded ses­sion mem­ory is what puts mi­cro­con­trollers in reach. Because the slid­ing win­dow caps state, Needle 2′s RAM is a de­ter­min­is­tic 28MB ceil­ing, not a curve that grows with con­ver­sa­tion length. That fits MCU-class parts with ex­ter­nal RAM, such as ESP32-P4 with 32MB of PSRAM, or STM32H7 and NXP i.MX RT boards with SDRAM. The en­gine com­piles sin­gle-threaded for bare metal and ships as a sta­tic li­brary for Cortex-M4, M7, and M55.

Evaluation

We eval­u­ate on five pub­lic func­tion-call­ing bench­marks: Google’s Mobile Actions, DroidCall, the Seal-Tools in-do­main and out-of-do­main tests, and BFCL v4 sin­gle-turn. Scoring is or­dered strict ex­act match: a row passes only if the func­tion names, the call or­der, and every ar­gu­ment value match. All Needle 2 num­bers are mea­sured end-to-end through the shipped C++ en­gine in its pro­duc­tion con­fig­u­ra­tion: CQ2-bit weights, tool re­trieval on, and the 256-token slid­ing KV win­dow. Nothing is re­laxed for bench­mark­ing; the num­bers re­flect the ex­act en­gine a de­vice runs, win­dow evic­tion in­cluded. Baselines run the re­leased check­points un­der vLLM at full con­text, and Apple FM runs on-de­vice.

Two asym­me­tries make this com­par­i­son hard, and we state both up­front. Precision: the base­lines stay at f16 de­lib­er­ately, be­cause con­ven­tional post-train­ing quan­ti­za­tion to 2 bits col­lapses mod­els that were never trained for ag­gres­sive com­pres­sion, while Cactus Quants is baked into Needle’s train­ing from the ground up. That skew fa­vors the base­lines. Scope: Needle is trained specif­i­cally for agen­tic tool call­ing and noth­ing else, while every base­line is a gen­eral lan­guage model car­ry­ing chat, prose, and world knowl­edge along­side its tool call­ing. That skew fa­vors Needle. There is no clean way to level both at once, so we do not try. The ta­bles an­swer one nar­row ques­tion: which model ex­e­cutes tool calls cor­rectly within an on-de­vice bud­get. We ac­cept the skew; it still paints the pic­ture we in­tend.

Mobile Actions (961 rows)

DroidCall test split (200 rows)

Seal-Tools in-do­main (700 rows)

Seal-Tools out-of-do­main (654 rows)

Needle was not trained for gen­eral func­tion call­ing: its cor­pus is con­sumer de­vice ac­tions—smart home, mo­bile, wear­ables, TV, car—plus struc­tured ex­trac­tion, and BFCLs gen­eral-pur­pose and en­ter­prise API sur­faces, in­clud­ing the Java and JavaScript SDK cat­e­gories, sit en­tirely out­side that dis­tri­b­u­tion. It ex­trap­o­lates nonethe­less: on Python sim­ple calls it lands within a point of FunctionGemma, a model six times larger trained for ex­actly this task, and it keeps a 93.4 well-formed rate across all 3,641 rows. The gap con­cen­trates where its train­ing data has never been: Java, JavaScript, and the par­al­lel multi-call cat­e­gories.

BFCL v4 sin­gle-turn (3,641 rows)

Squeak 6.1 Release Notes

squeak.org

These re­lease notes are op­ti­mized for view­ing in­side Squeak, as they con­tain a lot of in­ter­ac­tive ex­am­ples. On this page, in­ter­ac­tive links open in SqueakJS, which is a browser-based Smalltalk VM with some lim­i­ta­tions. For the best ex­pe­ri­ence, down­load Squeak and read the re­lease notes there.

*** Squeak 6.1 Vanessa” Release Notes ***

As Squeak ap­proaches its 30th an­niver­sary, we are proud to an­nounce the next ver­sion of the sys­tem, Squeak 6.1. Some high­lights of this re­lease are:

A new tree browser, which en­ables nav­i­ga­tion through classes and cat­e­gories us­ing re­fur­bished hi­er­ar­chi­cal morphs,

The re­turn of Objectland (also known as the Worlds of Squeak”),

Several changes and fixes for the ker­nel in­fra­struc­ture for sim­u­lat­ing, un­wind­ing, and sched­ul­ing processes and re­shap­ing classes,

Miscellaneous im­prove­ments and ad­di­tions to the toolset and user in­ter­face for in­spect­ing, de­bug­ging, pro­fil­ing, and ver­sion­ing code.

Please find be­low a de­tailed list­ing of all the changes, which in­cludes notes on Major Deprecations, Known Issues, and Compatibility Notes at the bot­tom.

About these re­lease notes. Phew, what a re­lease! Since the last re­lease 4 years ago, we have merged 1700+ patches with 9000+ method changes. Beyond doc­u­ment­ing tech­ni­cal changes in de­tail, these notes high­light the big­ger pic­ture and the over­all im­pact of ma­jor de­vel­op­ments. Along the way, you will find plenty of links to code point­ers and in­ter­ac­tive ex­am­ples. Thus, these re­lease notes serve not only as a changelog but also as a hands-on guide to ex­plor­ing new fea­tures and mech­a­nisms in Squeak. Click here to view an out­line of this doc­u­ment.

In mem­ory of Vanessa Freudenberg (1972 – 2025).

Detailed Improvements in Language, Tools, and the Environment

~~~ GUI Frameworks ~~~

Morphic (up to Morphic-ct.2218/MorphicTests-ct.97)

Major over­haul of tree morphs: Improves col­ors and mouse and key­board short­cuts for nav­i­gat­ing trees. Revises type-to-fil­ter sim­i­lar to lists, high­lights search terms, and en­ables search­ing sin­gle columns via [TAB]. Adds a con­fig­urable fil­ter mode to search within the cur­rent se­lec­tion, all vis­i­ble nodes, or the en­tire tree. Introduces a re­cur­sive find”/“find again” fea­ture avail­able via [CMD] + [F]/[CMD] + [G]. Adds a flag for au­to­matic ex­pan­sion of trees. Improves sup­port for drag’n’­drop by au­to­mat­i­cally ex­pand­ing nodes dur­ing drag­ging af­ter one sec­ond of hov­er­ing. Miscellaneous sta­bil­ity and per­for­mance im­prove­ments for lay­out­ing, ren­der­ing, and event han­dling in trees.

Improves col­ors and mouse and key­board short­cuts for nav­i­gat­ing trees.

Revises type-to-fil­ter sim­i­lar to lists, high­lights search terms, and en­ables search­ing sin­gle columns via [TAB]. Adds a con­fig­urable fil­ter mode to search within the cur­rent se­lec­tion, all vis­i­ble nodes, or the en­tire tree.

Introduces a re­cur­sive find”/“find again” fea­ture avail­able via [CMD] + [F]/[CMD] + [G].

Adds a flag for au­to­matic ex­pan­sion of trees.

Improves sup­port for drag’n’­drop by au­to­mat­i­cally ex­pand­ing nodes dur­ing drag­ging af­ter one sec­ond of hov­er­ing.

Miscellaneous sta­bil­ity and per­for­mance im­prove­ments for lay­out­ing, ren­der­ing, and event han­dling in trees.

In the world, sup­ports drop­ping of class ref­er­ences, sys­tem and method cat­e­gories, and in­spec­tor and ex­plorer fields to dis­play them in a new win­dow/​wid­get.

For mouse in­ter­ac­tions, adds new pref­er­ences to cus­tomize the dou­ble-click time and drag thresh­olds.

In the dock­ing bar win­dow menu, adds an item to col­lapse win­dows. Makes find work­space” eas­ier to use by ex­pand­ing the se­lected win­dow if col­lapsed. Reorders and dec­o­rates items in the help menu.

Text ed­i­tors: Underlines links (like this one!) dur­ing hov­er­ing and makes click­ing and text se­lec­tion through them more con­ve­nient. When en­clos­ing/​un­en­clos­ing a se­lec­tion in sin­gle/​dou­ble quotes, nested quotes are now au­to­mat­i­cally es­caped/​un­escaped.

Underlines links (like this one!) dur­ing hov­er­ing and makes click­ing and text se­lec­tion through them more con­ve­nient.

When en­clos­ing/​un­en­clos­ing a se­lec­tion in sin­gle/​dou­ble quotes, nested quotes are now au­to­mat­i­cally es­caped/​un­escaped.

Morphic API: Allows morphs to opt out of in­di­vid­ual halo events and to spec­ify a bal­loon text via a block in­stead of a se­lec­tor.

Menu con­struc­tion: Adds new util­i­ties for adding item groups and tem­porar­ily switch­ing ac­tion tar­gets dur­ing con­struc­tion. #addList: now in­ter­prets back­slashes in help tu­ples as line breaks. Automatically trims trail­ing lines be­tween menu items.

Adds new util­i­ties for adding item groups and tem­porar­ily switch­ing ac­tion tar­gets dur­ing con­struc­tion.

#addList: now in­ter­prets back­slashes in help tu­ples as line breaks.

Automatically trims trail­ing lines be­tween menu items.

Revises the de­bug menus of sev­eral morphs by adding a time-pro­filer short­cut for but­tons, pro­vid­ing ac­cess to the list and tree con­tents, and mak­ing ex­ist­ing browse ac­tion” and debug ac­tion” com­mands faster and more re­li­able.

Honors the pref­er­ence Open Tools Attached to Mouse Cursor” in Morph>>openAsTool.

Lots of UI tweaks and sta­bil­ity im­prove­ments: Improves theme sup­port for progress bars, text morph menus, and di­a­log win­dows. Improves high-DPI sup­port for but­tons, scroll panes, slid­ers, menus, multi-se­lec­tion lists, trees, drop-shad­ows, the scratch pad, the key­board ex­er­ciser, and oth­ers. Improves mul­ti­lin­gual sup­port in dif­fer­ent places. Fixes slips re­gard­ing the world dis­play depth menu, clock con­fig­u­ra­tion changes, search-bar print-its, pro­ject view morph styling, and tran­script count­ing. Fixes an is­sue when pro­fil­ing code where user events were swal­lowed. Several lay­out­ing fixes re­gard­ing pro­por­tional lay­outs, text morphs, scroll panes, and trans­for­ma­tion morphs. Fixes ren­der­ing is­sues with trans­form morphs, poly­gons, multi-se­lec­tion lists, and trees. Fixes scrolling in nested scroll panes. In text morphs, im­proves sta­bil­ity of text se­lec­tion and tweaks in­den­ta­tion re­gard­ing empty and blank lines. Fixes browse senders” of true, false, and nil, adds miss­ing ac­cess to work­space bind­ings dur­ing ac­cept-its, and im­proves ro­bust­ness of ed­i­tor his­tory. Fixes bugs in con­struc­tion of text con­tain­ers and con­ver­sion of para­graphs to texts. In lists, fixes au­to­matic se­lec­tion be­fore drag­ging an item. Fixes in­cor­rect yel­low-but­ton menu in­vo­ca­tion on but­tons and lists. Fixes a bug dur­ing menu con­struc­tion, which de­pended on unini­tial­ized state. Fixes scal­ing of color forms. Fixes in­tro­spec­tion of event han­dlers in morph meta-menus. Improves com­pat­i­bil­ity be­tween old and new bal­loon morphs. Fixes a re­mark­able slip that (1) pre­vented col­lapsed win­dows from ap­ply­ing a new UI theme and (2) in­tro­duced a pos­si­bly sig­nif­i­cant mem­ory leak of win­dows. Fixes an is­sue on ma­cOS where call­ing the VM with ad­di­tional com­mand line ar­gu­ments or plug­ging in ex­ter­nal de­vices led to an in­cor­rect The VM is con­fig­ured as a sin­gle­ton ap­pli­ca­tion” warn­ing. Improves sta­bil­ity and back­ward com­pat­i­bil­ity when load­ing morphs from files. Fixes cross-com­pat­i­bil­ity and con­cur­rency is­sues with MVC. Improves re­li­a­bil­ity of ha­los.

Improves theme sup­port for progress bars, text morph menus, and di­a­log win­dows.

Improves high-DPI sup­port for but­tons, scroll panes, slid­ers, menus, multi-se­lec­tion lists, trees, drop-shad­ows, the scratch pad, the key­board ex­er­ciser, and oth­ers.

Improves mul­ti­lin­gual sup­port in dif­fer­ent places.

Fixes slips re­gard­ing the world dis­play depth menu, clock con­fig­u­ra­tion changes, search-bar print-its, pro­ject view morph styling, and tran­script count­ing.

Fixes an is­sue when pro­fil­ing code where user events were swal­lowed.

Several lay­out­ing fixes re­gard­ing pro­por­tional lay­outs, text morphs, scroll panes, and trans­for­ma­tion morphs.

Fixes ren­der­ing is­sues with trans­form morphs, poly­gons, multi-se­lec­tion lists, and trees.

Fixes scrolling in nested scroll panes.

In text morphs, im­proves sta­bil­ity of text se­lec­tion and tweaks in­den­ta­tion re­gard­ing empty and blank lines.

Fixes browse senders” of true, false, and nil, adds miss­ing ac­cess to work­space bind­ings dur­ing ac­cept-its, and im­proves ro­bust­ness of ed­i­tor his­tory.

Fixes bugs in con­struc­tion of text con­tain­ers and con­ver­sion of para­graphs to texts.

In lists, fixes au­to­matic se­lec­tion be­fore drag­ging an item.

Fixes in­cor­rect yel­low-but­ton menu in­vo­ca­tion on but­tons and lists.

Fixes a bug dur­ing menu con­struc­tion, which de­pended on unini­tial­ized state.

Fixes scal­ing of color forms.

Fixes in­tro­spec­tion of event han­dlers in morph meta-menus.

Improves com­pat­i­bil­ity be­tween old and new bal­loon morphs.

Fixes a re­mark­able slip that (1) pre­vented col­lapsed win­dows from ap­ply­ing a new UI theme and (2) in­tro­duced a pos­si­bly sig­nif­i­cant mem­ory leak of win­dows.

Fixes an is­sue on ma­cOS where call­ing the VM with ad­di­tional com­mand line ar­gu­ments or plug­ging in ex­ter­nal de­vices led to an in­cor­rect The VM is con­fig­ured as a sin­gle­ton ap­pli­ca­tion” warn­ing.

Improves sta­bil­ity and back­ward com­pat­i­bil­ity when load­ing morphs from files.

Fixes cross-com­pat­i­bil­ity and con­cur­rency is­sues with MVC.

Improves re­li­a­bil­ity of ha­los.

Improves per­for­mance of large tree wid­gets, trans­for­ma­tion morphs, and an­i­mated GIFs.

Miscellaneous clean-ups and doc­u­men­ta­tion im­prove­ments for in­put events, ed­i­tor at­trib­utes, and oth­ers.

MorphicExtras (up to MorphicExtras-ct.360)

Introduces Objectland, which is a re­con­struc­tion of the fa­mous Worlds of Squeak” from 2003 and of­fers a col­or­ful col­lec­tion of ex­am­ples that demon­strate the mul­ti­far­i­ous ca­pa­bil­i­ties of Squeak. Re-adds the clas­sic Etoys race car ex­am­ple and adds sev­eral new ex­am­ples.

After 18 years of spot­less, clean Squeak, rein­tro­duces and up­dates the fa­mous BlobMorph.

For we­b­cams, adds a mir­ror op­tion and ex­tends in­ter­face for dou­ble-buffer­ing. Improves UI and sta­bil­ity of we­b­cam morph.

Improves in­stru­ment menu of score play­ers.

Fixes the preserve trash” pref­er­ence and im­proves the ro­bust­ness of the pi­ano key­board.

Improves high-DPI sup­port for the ob­jects tool, sev­eral of its tools such as event recorders, score play­ers, record­ing con­trols, and pi­ano key­boards, and sev­eral EToys-related morphs.

Etoys (up to EToys-ct.532)

Restores and re­vises a tu­to­r­ial on paint­ing and cre­at­ing scripts in Etoys.

Adds an undo but­ton to FreeCell.

Improves state in­di­ca­tion in Tetris.

Improves in­stru­ment menu of the midi in­put morph.

Improves ro­bust­ness of the play­ers gallery, the spec­trum an­a­lyzer, and the midi in­put morph. Fixes chang­ing the head­ing of a player.

Clean-ups and fixes for cards and stacks.

Improves high-DPI sup­port for Etoys icons, tile morphs and script ed­i­tors, all games, the ob­jects tool, the spec­trum an­a­lyzer, file lists, watches, and cal­en­dars.

Minor speedups for Kedama and play­ers.

Several clean-ups and refac­tor­ings that im­prove over­all mod­u­lar­ity and avoid un­in­tended de­pen­den­cies of other pack­ages on Etoys.

ST80 (up to ST80-mt.311)

Adds a close item to the world menu.

Improves high-DPI sup­port for sys­tem views.

Adds View>>imageForm for tak­ing a screen­shot of a view and dis­plays it in in­spec­tors.

Adds ed­i­tor short­cut [CMD] + [SHIFT] + [D] for debug it” (already ex­ists in Morphic).

Miscellaneous fixes and sta­bil­ity im­prove­ments: Ensures con­fir­ma­tion di­a­log be­fore clos­ing the cur­rent MVC pro­ject. Prevents un­ex­pected au­thor-ini­tials di­a­log when open­ing the ST80 world menu for the first time. Avoids an is­sue with stale de­ferred ac­tions in an empty MVC world, which caused emer­gency de­bug­gers to ap­pear only af­ter press­ing a mouse but­ton. In text ed­i­tors, fixes pretty-print­ing and spawn­ing if no com­pat­i­ble model is avail­able. Gently han­dles nil se­lec­tion pro­vided by the model. Fixes an is­sue with re­cently in­tro­duced key­board short­cuts. Repairs folder choosers.

Ensures con­fir­ma­tion di­a­log be­fore clos­ing the cur­rent MVC pro­ject.

Prevents un­ex­pected au­thor-ini­tials di­a­log when open­ing the ST80 world menu for the first time.

Avoids an is­sue with stale de­ferred ac­tions in an empty MVC world, which caused emer­gency de­bug­gers to ap­pear only af­ter press­ing a mouse but­ton.

In text ed­i­tors, fixes pretty-print­ing and spawn­ing if no com­pat­i­ble model is avail­able. Gently han­dles nil se­lec­tion pro­vided by the model. Fixes an is­sue with re­cently in­tro­duced key­board short­cuts.

Repairs folder choosers.

CommandLine (up to CommandLine-eem.27)

Repairs the pref­er­ence Save snap­shot of im­age on fail­ure”.

Improves UIManager sup­port for var­i­ous file di­alogs, font di­alogs, con­fir­ma­tions, and re­quests.

For in­ter­ac­tive di­a­log re­quests, im­proves the er­ror mes­sage be­fore quit­ting.

~~~ Programming & Tools ~~~

Tools (up to Tools-mt.1366/ToolsTests-ct.137)

Introduces a new tree browser, which dis­plays sys­tem cat­e­gories, classes, and mes­sage cat­e­gories in hi­er­ar­chi­cal panes and in­te­grates Monticello pack­ages. There are also five new pref­er­ences for con­fig­ur­ing its ap­pear­ance. Reworks drag’n’­drop for tree browsers and tra­di­tional browsers to sup­port all mean­ing­ful com­bi­na­tions of panes for copy­ing or mov­ing classes, meth­ods, and cat­e­gories. Adds dou­ble-click sup­port for hi­er­ar­chy tree browsers to switch the cen­tral class. This is es­pe­cially fun for multi-in­her­i­tance hi­er­ar­chies with traits. In the class pane menu, adds new items for gen­er­at­ing a new class or trait. In the mes­sage cat­e­gory menu, adds items to browse all [related] mes­sage cat­e­gories in the sys­tem. In the an­no­ta­tion pane of class de­f­i­n­i­tions, adds a short­cut for read­ing the full class com­ment. Simplifies ex­ten­sion point for cus­tom browsers to reg­is­ter as hi­er­ar­chy browsers. Improves multi-en­vi­ron­ment sup­port for all kinds of browsers and mes­sage sets.

Reworks drag’n’­drop for tree browsers and tra­di­tional browsers to sup­port all mean­ing­ful com­bi­na­tions of panes for copy­ing or mov­ing classes, meth­ods, and cat­e­gories.

Adds dou­ble-click sup­port for hi­er­ar­chy tree browsers to switch the cen­tral class. This is es­pe­cially fun for multi-in­her­i­tance hi­er­ar­chies with traits.

In the class pane menu, adds new items for gen­er­at­ing a new class or trait.

In the mes­sage cat­e­gory menu, adds items to browse all [related] mes­sage cat­e­gories in the sys­tem.

In the an­no­ta­tion pane of class de­f­i­n­i­tions, adds a short­cut for read­ing the full class com­ment.

Simplifies ex­ten­sion point for cus­tom browsers to reg­is­ter as hi­er­ar­chy browsers.

Improves multi-en­vi­ron­ment sup­port for all kinds of browsers and mes­sage sets.

Stowaway — Ride along with anything in the sky

stowaway.live

Pick any air­craft or satel­lite pass­ing over your house right now, and go sit in its win­dow seat.

The sky here is the real one out­side — your lo­ca­tion, your weather, this min­ute’s light — with the air­craft and satel­lites that are gen­uinely over­head. Click one and the cam­era fol­lows it; stow away and it takes a seat on board, over real ter­rain.

All of that is drawn in real time, which needs JavaScript and WebGL 2. Switching JavaScript on for this site should do it.

To add this web app to your iOS home screen tap the share button and select "Add to the Home Screen".

10HN is also available as an iOS App

If you visit 10HN only rarely, check out the the best articles from the past week.

Visit pancik.com for more.