10 interesting stories served every morning and every evening.

California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt

www.tomshardware.com

California’s leg­is­la­ture has passed Assembly Bill 1856, ex­empt­ing open-source op­er­at­ing sys­tems from the State’s Digital Age Assurance Act months be­fore the law is due to take ef­fect on January 1, 2027. The Senate amended the Bill on August 21 be­fore pass­ing it on the 26th in a 39 – 0 vote, with the Assembly then ac­cept­ing these changes in a con­cur­rence vote the fol­low­ing day. The amend­ment ends al­most a year of un­cer­tainty sur­round­ing whether Linux dis­tri­b­u­tions and SteamOS would be forced to col­lect user age data dur­ing ac­count setup along­side Windows, ma­cOS, iOS, and Android. AB 1856 has now been sent to Governor Gavin Newsom, who signed the orig­i­nal act into law last October.

These amend­ments re­de­fine the term operating sys­tem provider” to ex­clude any per­son or en­tity that dis­trib­utes an OS or ap­pli­ca­tion under li­cense terms that per­mit a re­cip­i­ent to copy, re­dis­trib­ute, and mod­ify the soft­ware.” Any soft­ware dis­trib­uted un­der the GPL, MIT, BSD, and Apache li­censes sat­is­fies that test, which re­moves the likes of Debian, Fedora, Ubuntu, Arch, and the BSD fam­ily from AB 1856’s scope.

A sec­ond ex­clu­sion re­moves soft­ware com­po­nents that aren’t offered to con­sumers as a stand-alone ex­e­cutable ap­pli­ca­tion through a cov­ered ap­pli­ca­tion store” from the law’s de­f­i­n­i­tion of an ap­pli­ca­tion, cov­er­ing li­braries and de­pen­den­cies dis­trib­uted through pack­age man­agers like apt and pac­man. AB 1856 does­n’t ex­plic­itly say that re­pos aren’t app stores, but a store’s main oblig­a­tion un­der the law is to re­quest an age sig­nal from the user’s OS provider and pass it to de­vel­op­ers; an ex­empt open-source OS pro­duces no sig­nal. A third carve-out ex­cludes store­fronts dis­trib­ut­ing ex­ten­sions or add-ons that run ex­clu­sively in­side a host ap­pli­ca­tion, which takes browser ex­ten­sion stores out of scope.

The amend­ments to AB 1856 also re­move the orig­i­nal de­f­i­n­i­tion of user,” which read, a child that is the pri­mary user of a de­vice,” and tech­ni­cally clas­si­fied every de­vice owner in California as a child. The law’s sig­nal­ing frame­work de­pends on adults de­clar­ing their age on ac­count setup, so their de­vices get flagged as 18 and over, but un­der that de­f­i­n­i­tion no­body could ever be flagged as an adult.

In ad­di­tion, law­mak­ers in­serted a new pro­vi­sion pro­hibit­ing any­one from re­quest­ing an age sig­nal from an OS provider or app store un­less re­quired by law. That closes off po­ten­tial abuse of the age API that could have led to it be­ing used as a gen­eral-pur­pose data col­lec­tion chan­nel even when age ver­i­fi­ca­tion was­n’t re­quired. Platforms and de­vel­op­ers also gain a good-faith safe har­bor against er­ro­neous sig­nals, pro­tect­ing them from li­a­bil­ity when age-gat­ing sig­nals are in­ac­cu­rate.

Windows, ma­cOS, iOS, and Android re­main fully in scope, with age col­lec­tion re­quired at ac­count setup from January 1, 2027. A later July 1, 2027, dead­line ap­plies to de­vices set up be­fore January 1. Whether SteamOS is in scope is­n’t yet clear: its Arch-based sys­tem com­po­nents are open source, but Valve dis­trib­utes the im­age along­side the pro­pri­etary Steam client. GrapheneOS, which in March said it would refuse to com­ply with age-ver­i­fi­ca­tion man­dates, is dis­trib­uted un­der open-source MIT and Apache li­censes and now falls out­side the law’s scope en­tirely, though Brazil’s Digital ECA still ap­plies to it.

Assemblymember Buffy Wicks, who wrote both the Digital Age Assurance Act and the AB 1856 amend­ment, in­tro­duced the ex­emp­tion back in February fol­low­ing crit­i­cism from Linux de­vel­op­ers and the Electronic Frontier Foundation.

Get Tom’s Hardware’s best news and in-depth re­views, straight to your in­box.

Follow Tom’s Hardware on Google News, or add us as a pre­ferred source, to get our lat­est news, analy­sis, & re­views in your feeds.

Luke James is a free­lance writer and jour­nal­ist.  Although his back­ground is in le­gal, he has a per­sonal in­ter­est in all things tech, es­pe­cially hard­ware and mi­cro­elec­tron­ics, and any­thing reg­u­la­tory.

The Internet Is Kind of a Predatory Cesspit Now

www.stephendiehl.com

I’m a kid of the 90s, and I still re­mem­ber the early in­ter­net. It was slow, ugly, un­re­li­able, and full of cranks, a strange world of wheez­ing dial-up modems, Usenet flame­wars, <marquee> tags, and danc­ing ba­bies. It was also stub­bornly alive and hu­man. People built web­sites about Babylon 5, model rock­ets, train timeta­bles, share­ware, and what­ever else had colonised their minds. Most of it had no busi­ness model. That was the lit­eral point. The web felt like a pub­lic square as­sem­bled by ob­ses­sive am­a­teurs.

None of this was en­tirely in­no­cent. There were scams, viruses, Nazis, pornog­ra­phy, and chain emails from de­posed Nigerian princes. But then pre­da­tion moved from the pe­riph­ery to the cen­tre. It used to be an abuse of the net­work. Now it is the net­work’s or­gan­is­ing prin­ci­ple. The scam­mer once had to find a vic­tim. The plat­form now finds one, pro­files the weak­ness, op­ti­mises the pitch, processes the pay­ment, and rec­om­mends the next scam. What was once an aber­ra­tion has be­come the norm.

The mod­ern in­ter­net is now a highly op­ti­mised ma­chine for de­tect­ing hu­man vul­ner­a­bil­ity, am­pli­fy­ing it, and plac­ing a pay­ment link be­side it. Any in­se­cu­rity can be­come a com­mer­cial niche, in­clud­ing the de­sire to es­cape com­mer­cial life it­self. There is al­ways a course, a newslet­ter, a pri­vate com­mu­nity, or a re­fer­ral code wait­ing at the end of the fun­nel.

The bleak part is not that grifters ex­ist. Every so­ci­ety has huck­sters. It is that much of the pop­u­la­tion has been con­scripted into the down­line. Ordinary peo­ple now spend their lives pro­mot­ing in­vest­ments they barely un­der­stand, prod­ucts that do not work, and po­lit­i­cal claims they have never ex­am­ined. Many earn noth­ing. They are un­paid dis­trib­u­tors for some­one far­ther up the pyra­mid. The con­sumer, sales­man, and prod­uct have col­lapsed into the same ex­hausted per­son.

People in­creas­ingly be­have like ad­dicts be­cause ad­dic­tion is the busi­ness model. The feed sup­plies al­ter­nat­ing doses of out­rage, fear, envy, lust, and hope. Each feel­ing ar­rives with some­thing to buy. People doom­scroll un­til they ac­quire the anx­i­ety that the next in­flu­encer will mon­e­tise. Then they pur­chase a bet, a coin, a sup­ple­ment, a course, or an en­emy. Finally, they re­post the pitch. Consumption be­comes dis­tri­b­u­tion. The mark be­comes the sales­man.

This is an in­dus­trial sys­tem for man­u­fac­tur­ing weak­ness at scale. A le­git­i­mate busi­ness can sur­vive a sat­is­fied cus­tomer. A grift can­not. It needs the cus­tomer fright­ened, ag­grieved, lonely, sick, or greedy for­ever.

When I started writ­ing about cryp­tocur­rency in 2020, I still car­ried a naive as­sump­tion about the size of this econ­omy. I thought peo­ple were gen­er­ally de­cent and the grifter class was a small pool of de­gen­er­ates with rot­ten moral char­ac­ter, prey­ing on those made vul­ner­a­ble by the ma­te­r­ial con­di­tions of our time.

I was very wrong. The grift econ­omy is mas­sive. More dis­turb­ing still, it is par­tic­i­pa­tory. A large and grow­ing share of the pop­u­la­tion now ap­pears will­ing to de­vote every wak­ing hour to fleec­ing their fel­low man as a ca­reer choice. They stream, post, re­cruit, pro­mote, re­fer, as­tro­turf, and close. They turn every friend­ship into a lead and every con­ver­sa­tion into a qual­i­fy­ing call. They do not clock out be­cause the mar­ket fol­lows them into bed. The smart­phone is a shop counter that sleeps be­side their head.

Obviously most of these peo­ple are not suc­ceed­ing. The maths sim­ply can never work out. That is part of the trick. The as­pir­ing in­flu­encer with forty-seven fol­low­ers is not an en­tre­pre­neur in any mean­ing­ful sense. He is free labour for the plat­form and cheap dis­tri­b­u­tion for the per­son sell­ing him the dream. The af­fil­i­ate mar­keter buys a course about af­fil­i­ate mar­ket­ing, then re­cov­ers the cost by sell­ing the same course to the next af­fil­i­ate mar­keter. The life coach coaches new life coaches. The drop­ship­per sells tu­to­ri­als to failed drop­ship­pers. The pyra­mid is so­cial be­fore it is fi­nan­cial. Everyone stands on some­one else while in­sist­ing they are about to es­cape.

This arrange­ment blurs the use­ful moral dis­tinc­tion be­tween preda­tor and prey. Many on­line grifters are them­selves marks. They be­lieve the rub­bish they sell be­cause be­lief makes the sell­ing bear­able. They have sunk money, time, iden­tity, and pub­lic dig­nity into the scheme. Admitting the prod­uct is worth­less would mean ad­mit­ting that years of their life were worth­less too. It is psy­cho­log­i­cally cheaper to re­cruit an­other vic­tim. The fraud sus­tains the faith, and the faith sus­tains the fraud.

A nor­mal trade ends when a need is sa­ti­ated. You need a chair. Someone sells you a chair. You sit down and stop think­ing about chairs. However, an on­line grift can never sa­ti­ate. It must pre­serve the need that feeds it. The griev­ance mer­chant can­not re­solve your griev­ance. The well­ness in­flu­encer can­not let you feel well. The trad­ing guru can­not let you be­come fi­nan­cially se­cure. The manos­phere pod­caster can­not let young men be­come calm, loved, and so­cially com­pe­tent. Satisfaction is churn. Misery is re­cur­ring rev­enue.

The plat­forms did not in­vent fear, greed, lone­li­ness, or sta­tus anx­i­ety. They in­dus­tri­alised their ex­trac­tion. Their rec­om­men­da­tion sys­tems are vast re­in­force­ment-learn­ing loops that con­tin­u­ously ex­per­i­ment on hu­man weak­ness. Each ob­jec­tive is a mov­ing com­pos­ite of high-di­men­sional sig­nals for at­ten­tion, re­ten­tion, and con­ver­sion, dis­persed across mod­els, met­rics, tests, and feed­back sys­tems. The sub­ject can­not see the ex­per­i­ment. The op­er­a­tor can­not fully ex­plain it. The reg­u­la­tor can barely com­pre­hend it. The loop knows only that one stim­u­lus keeps a per­son scrolling while an­other lets them leave. Calm ac­cu­racy loses. Threat, trans­gres­sion, hu­mil­i­a­tion, and im­pos­si­ble promises win. The re­sult­ing so­cial dam­age ap­pears nowhere in the ob­jec­tive func­tion. It ar­rives as an ex­ter­nal­ity.

This cre­ates a bru­tal se­lec­tion en­vi­ron­ment. The hon­est fi­nan­cial ad­viser ex­plains di­ver­si­fi­ca­tion and gets twelve views. The crypto lu­natic pre­dicts a thou­sand­fold re­turn and gets twelve mil­lion. The physi­cian says a chronic con­di­tion re­quires care­ful man­age­ment. The well­ness crank says seed oils are poi­son­ing your soul. The his­to­rian de­scribes an am­bigu­ous event with con­tin­gent causes. The po­lit­i­cal in­flu­encer iden­ti­fies a se­cret ca­bal and gives you the ad­dress of a pizza par­lour. One of these peo­ple has the bet­ter busi­ness model. It is not the one bur­dened by re­al­ity.

The sys­tem is dopamin­er­gic in the most ba­nal and me­chan­i­cal sense. It runs on an­tic­i­pa­tion, un­cer­tainty, and vari­able re­ward. The next re­fresh might bring ap­proval, out­rage, profit, or vin­di­ca­tion. Usually it brings noth­ing, which makes the next re­fresh more ur­gent. Social me­dia fused the Skinner box with the com­mis­sion struc­ture. The ad­dict is handed a re­fer­ral code and told he is now a small busi­ness owner.

Crypto has be­come the sub­ject of my ver­bal ire so of­ten be­cause it is the apoth­e­o­sis of the grift econ­omy. It takes alien­ation, pre­car­ity, gam­bling ad­dic­tion, tech­no­log­i­cal mys­ti­fi­ca­tion, and a thick slurry of lib­er­tar­ian derp, then syn­the­sises them into the ul­ti­mate preda­tory in­vest­ment prod­uct.

Crypto also per­fected the re­cur­sive struc­ture of the mod­ern on­line grift. Promotion cre­ates price move­ment. Price move­ment is pre­sented as proof of adop­tion. That proof re­cruits new buy­ers. Their money cre­ates more price move­ment. Every par­tic­i­pant has a di­rect fi­nan­cial in­cen­tive to be­come a pub­li­cist for his own po­si­tion. The as­set comes with its own vol­un­teer pro­pa­ganda net­work. It is a pyra­mid scheme with a pod­cast de­part­ment.

Much to my dis­may, the rest of the in­ter­net has learned the same les­son. The cheap­est prod­uct is empty promises un­teth­ered to re­al­ity. The most scal­able labour force is the ad­dict. The best mar­ket­ing con­ceals it­self in­side iden­tity. Sell peo­ple a world­view, and they will ad­ver­tise it for free be­cause crit­i­cism of the prod­uct now feels like crit­i­cism of the self.

Language mod­els will make this cheaper and worse. The cost of pro­duc­ing plau­si­ble lies has been dri­ven to pre­cisely zero. One per­son can gen­er­ate a land­fill of ar­ti­cles, videos, tes­ti­mo­ni­als, in­vest­ment analy­sis, and syn­thetic ex­perts be­fore break­fast. The grift no longer needs con­vic­tion, charisma, or even a pulse. It needs a lan­guage model, an af­fil­i­ate ac­count, and ac­cess to a pop­u­la­tion whose crit­i­cal fac­ul­ties have been sand­blasted by twenty years of al­go­rith­mic me­dia.

There is a temp­ta­tion to re­gard the peo­ple caught in this ma­chine with sim­ple con­tempt. Some de­serve it. A per­son who know­ingly ru­ins strangers for com­mis­sion has made a moral choice. But con­tempt is not an analy­sis. Precarity sup­plies the re­cruits. Alienation sup­plies the au­di­ence. The col­lapse of sta­ble work, af­ford­able hous­ing, lo­cal in­sti­tu­tions, and plau­si­ble routes to ma­te­r­ial se­cu­rity is what makes the pitch of the grift econ­omy so se­duc­tive. The grift of­fers agency where or­di­nary life of­fers de­lay. It of­fers com­mu­nity where so­ci­ety of­fers iso­la­tion. It of­fers a jack­pot where work of­fers a per­for­mance re­view and an­other year of rent in­creases.

Then it metabolises those in­juries into new in­juries. The lonely man buys a doc­trine that makes him in­tol­er­a­ble to women. The in­debted worker gam­bles his re­main­ing sav­ings on a crypto to­ken. The fright­ened pa­tient aban­dons med­i­cine for sup­ple­ments. The po­lit­i­cally pow­er­less per­son spends four­teen hours a day scream­ing at strangers while the peo­ple with power qui­etly cut his wages and pub­lic ser­vices. The promised es­cape re­pro­duces the con­di­tion that made es­cape de­sir­able.

It is a des­per­ately sad way to live. There is no craft in it, no sol­i­dar­ity, and no com­ple­tion. No com­pas­sion or joy. Every re­la­tion­ship be­comes an au­di­ence. Every in­ter­est just be­comes grist for the con­tent mill. Every con­vic­tion be­comes a con­tent strat­egy. The grifter can never rest be­cause ab­sence kills en­gage­ment. The mark can never rest be­cause the next post might con­tain the se­cret. Both wake to the same no­ti­fi­ca­tions, trapped on a dopamine tread­mill dri­ven by opaque al­go­rithms that can never slow down.

The worst ad­vice from the 90s, just say no,” starts to look less stu­pid when our great­est tech­ni­cal in­no­va­tion learns to turn dis­tress into in­ven­tory. Disconnection is not Luddism in that en­vi­ron­ment. It is the re­fusal to mis­take a preda­tory sys­tem for a so­cial world.

Complete dis­con­nec­tion is nearly im­pos­si­ble. Modern life no longer per­mits it. But an ap­pli­ance is used for a bounded pur­pose and then put away. Emails, train times, ar­ti­cles, and files all have end­points. Infinite feeds of dri­vel do not. They carry the casino into bed and let an opaque RL loop se­lect the emo­tions that ar­rive be­fore break­fast.

The in­ter­net is in­dis­putably an in­hu­man place. Not be­cause it con­tains no hu­mans. Billions of us are in here, scream­ing fran­ti­cally at each other while feel­ing ut­terly alone. It is in­hu­man be­cause the sys­tems gov­ern­ing it are ut­terly alien al­go­rithms that can­not recog­nise hu­man ends. They recog­nise en­gage­ment, con­ver­sion, re­ten­tion, and growth. Grief is a mar­ket seg­ment. Loneliness is a tar­get­ing sig­nal. Friendship is a re­ten­tion mech­a­nism. Political con­vic­tion is ad in­ven­tory. Nothing can sim­ply mat­ter. It must per­form.

Life in­side this en­vi­ron­ment means adopt­ing its cat­e­gories. Thoughts are as­sessed by their reach, ex­pe­ri­ences by their share­abil­ity, and peo­ple by their use­ful­ness to an iden­tity. A per­son be­comes leg­i­ble to the ma­chine by be­com­ing less leg­i­ble to him­self. Eventually the sys­tem no longer needs to im­pose its val­ues. Its sub­jects carry them in their pock­ets and en­force them on their own minds.

The phys­i­cal world is not pure. It con­tains sales­men, casi­nos, dem­a­gogues, fa­nat­ics, and bores. It also con­tains stub­born lim­its. A con­ver­sa­tion ends. A pub closes. A book runs out of pages. Your friend gets tired of hear­ing you talk and tells you to shut up. Reality sup­plies fric­tion, and fric­tion is one of the few re­main­ing de­fences against ap­petite with­out limit.

We are not go­ing back to the early in­ter­net. Nor should we ro­man­ti­cise it. The old web had plenty of sewage. What it also had was space be­yond the mar­ket. A per­son could make some­thing with­out be­com­ing a brand. A con­ver­sa­tion could end with­out a con­ver­sion. A com­mu­nity could ex­ist with­out turn­ing its mem­bers into marks for an in­vest­ment scheme.

The ques­tion is not whether the in­ter­net con­tains use­ful things. It does. The ques­tion is whether hu­man ex­is­tence should be or­gan­ised around alien and in­hu­man ob­jec­tive func­tions no hu­man chose and no­body can in­spect or un­der­stand. An RL loop can op­ti­mise en­gage­ment, re­ten­tion, and con­ver­sion. It can­not tell us what a hu­man life is for. The fi­nal grift is let­ting the loop de­cide what your life should be.

Trump’s DHS is using an obscure law to secretly snoop on journalists, non-profits and unions: ‘It’s outrageous’

www.theguardian.com

The Trump ad­min­is­tra­tion has been de­ploy­ing an ob­scure le­gal ma­neu­ver to try to ob­tain pri­vate in­for­ma­tion on jour­nal­ists, non-prof­its and unions, rais­ing alarm over a power the gov­ern­ment has as­serted with­out ju­di­cial over­sight.

In one in­stance, the gov­ern­ment ob­tained six months of tele­phone records for Georgia Fort, a Minneapolis jour­nal­ist. Fort was not no­ti­fied of the re­quest for her in­for­ma­tion, nor was she given a chance to con­test the gov­ern­men­t’s ef­fort to ob­tain them, her lawyers said in court pa­pers.

In February of this year, fed­eral pros­e­cu­tors twice sought search war­rants for ac­count in­for­ma­tion for the YouTube chan­nel of Fort and the jour­nal­ist Don Lemon, both of whom have pleaded not guilty to crim­i­nal charges in con­nec­tion to a protest at a Minneapolis church in January that they were cov­er­ing. A judge twice re­jected the re­quest, writ­ing that the gov­ern­ment had failed to es­tab­lish prob­a­ble cause of a crime and that he wanted Lemon and Fort to be in­formed of the re­quest so they could have a chance to chal­lenge it. About a month af­ter the judge’s rul­ing in late February, the gov­ern­ment said it was with­draw­ing the re­quest.

But of­fi­cials had­n’t given up on get­ting the data.

Less than a month later, the DHS served Google with a dif­fer­ent re­quest for the YouTube in­for­ma­tion. This time, DHS uti­lized a dif­fer­ent method that did­n’t re­quire ap­proval from a judge, only a sign-off from a DHS of­fi­cial. It served Google an ad­min­is­tra­tive sum­mons cit­ing an ar­cane pro­vi­sion of fed­eral law — 19 USC 1509 — deal­ing with cus­toms im­ports. The pro­vi­sion gives the DHS broad power to in­spect records in or­der to de­ter­mine whether du­ties and taxes are be­ing cor­rectly levied on im­ported items. It also in­structed the re­cip­i­ents of the sum­mons to keep it se­cret.

The DHS sum­mons was is­sued un­der a statute that does give the agency broad power to de­mand records, but only in the lim­ited cir­cum­stance of there be­ing a need to in­ves­ti­gate a cus­toms is­sue, said Chris Duncan, a for­mer lawyer at the Department of Homeland Security. These laws have ab­solutely noth­ing to do with a do­mes­tic sit­u­a­tion at a church, a so­cial me­dia post, even an im­mi­gra­tion mat­ter,” he said.

It’s out­ra­geous con­duct on so many lev­els. It’s hard to know where to be­gin,” said John Roth, who served as the in­spec­tor gen­eral for the Department of Homeland Security from 2014 to 2017. This is an im­proper use of the sub­poena un­der any cir­cum­stances. This is not a cus­toms case; it is not a cus­toms vi­o­la­tion. They are not in­ves­ti­gat­ing a cus­toms vi­o­la­tion.”

The episode in Minnesota was par­tic­u­larly alarm­ing be­cause it ap­peared to be an end run around a judge who was skep­ti­cal of the gov­ern­men­t’s need for the in­for­ma­tion.

There is no judge in the loop. You don’t have that in­de­pen­dent au­thor­ity to scru­ti­nize the de­mand and to say whether or not it’s le­git­i­mate,” said Caitlin Vogus, a se­nior ad­viser at the Freedom of the Press Foundation.

The DHS also sought and ob­tained six months of phone records for Fort from T-Mobile, which in­cluded records for more than 10,000 calls and text mes­sages. Fort was not no­ti­fied the gov­ern­ment was seek­ing the records un­til mid-July, when gov­ern­ment lawyers pro­duced them to her lawyers. Fort’s lawyers wrote in a fil­ing this week they were stunned” to see the gov­ern­ment had uni­lat­er­ally been able to ob­tain a log of her com­mu­ni­ca­tions af­ter a judge had warned them about ob­tain­ing records about a jour­nal­ist.

That’s very con­cern­ing be­cause the in­for­ma­tion de­manded can help the gov­ern­ment un­cover a jour­nal­ist’s con­fi­den­tial sources,” Vogus said.

In a state­ment, T-Mobile did not ad­dress why it turned over the in­for­ma­tion.

We take our re­spon­si­bil­ity to pro­tect cus­tomers’ pri­vacy and per­sonal in­for­ma­tion very se­ri­ously. Our team care­fully re­views gov­ern­ment de­mands for cus­tomer in­for­ma­tion and re­sponds in ac­cor­dance with the law. We don’t com­ment on spe­cific law en­force­ment de­mands,” the com­pany said.

The Department of Justice and the Department of Homeland Security both de­clined to com­ment on the use of the sum­mons.

In ad­di­tion to Fort and Lemon, the DHS also sought in­for­ma­tion on the YouTube ac­counts for the left-lean­ing out­let Democracy Now, con­ser­v­a­tive pod­caster Megyn Kelly, the Milwaukee Journal-Sentinel and an in­de­pen­dent jour­nal­ist named Brendan Gutenschwager. Some of the videos they cited in the sum­mons were livestreams of the protest, but not all of them. The video cited as part of the re­quest for in­for­ma­tion on Democracy Now in­volved a news re­port on the protest and an in­ter­view with Nekima Levy Armstrong, who led the protest. The video cited on the re­quest for Kelly’s show in­cluded an in­ter­view with Jonathan Parnell, the pas­tor at the church.

It’s un­clear why ex­actly the DHS wanted the YouTube ac­count in­for­ma­tion, which in­cludes things like a user’s IP ad­dress, and in­for­ma­tion about when a user was log­ging in.

It’s still con­cern­ing that the gov­ern­ment sought sub­scriber in­for­ma­tion for Lemon and Fort be­cause there’s no rea­son it would need this in­for­ma­tion for the crim­i­nal charges that it’s brought against them,” Vogus said. It’s not a crime to post a YouTube video, and it’s not at all clear why the gov­ern­ment is de­mand­ing this in­for­ma­tion about Lemon and Fort’s YouTube ac­counts.”

The episode was the most re­cent ex­am­ple of an alarm­ing pat­tern in re­cent months in which the DHS avoided ju­di­cial scrutiny and de­ployed a sum­mons re­lated to cus­toms en­force­ment to pres­sure com­pa­nies into turn­ing over in­for­ma­tion on Americans. The US con­sti­tu­tion’s fourth amend­ment pro­tects against un­rea­son­able searches and seizures and law en­force­ment gen­er­ally must show a judge or a grand jury they have prob­a­ble cause to be­lieve the ma­te­ri­als they want to search will pro­duce ev­i­dence of a crime.

But over the last few months, the Department of Homeland Security has un­der­taken a brazen ef­fort to get around that fun­da­men­tal safe­guard. In ad­di­tion to ef­forts to ob­tain records on Minnesota jour­nal­ists, the DHS has used 1509 sum­monses to pres­sure so­cial me­dia com­pa­nies to un­mask the iden­ti­ties of peo­ple who have crit­i­cized ICE of­fi­cers and to ob­tain fi­nan­cial in­for­ma­tion on a host of unions and left-lean­ing non-profit or­ga­ni­za­tions in Minneapolis.

In a sep­a­rate case in which 15 ac­tivists face crim­i­nal con­spir­acy charges, DHS suc­cess­fully ob­tained the fi­nan­cial records of the Sunrise Movement, the Service Employees International Union (SEIU) and the Communications Workers of America, as well as Venmo records for a non-profit or­ga­ni­za­tion called Voices for Racial Justice. None of the or­ga­ni­za­tions is charged with crimes and the DHS did not of­fer an ex­pla­na­tion for why it needed the records. PayPal, Venmo’s par­ent com­pany, de­clined to com­ment.

There’s a long his­tory of DHS abus­ing this sum­mons au­thor­ity in par­tic­u­lar, and us­ing it to seek both records that are clearly out­side of its scope in gen­eral, and more par­tic­u­larly to try to go af­ter peo­ple whose speech DHS is some­how irked by — but whose speech is pro­tected by the first amend­ment,” said Nathan Freed Wessler, a lawyer at the American Civil Liberties Union who spe­cial­izes in pri­vacy is­sues.

It is dif­fi­cult to de­ter­mine the fre­quency with which the DHS is serv­ing the 1509 sum­monses and how of­ten they are suc­cess­ful in ob­tain­ing in­for­ma­tion. The sum­monses of­ten re­main hid­den from pub­lic view un­less the com­pany be­ing served, or the user, chal­lenges them. Companies are not re­quired to no­tify users that they have been served with a 1509 sum­mons for in­for­ma­tion, though some do. The New York Times re­ported in February that the DHS had served hun­dreds of ad­min­is­tra­tive sub­poe­nas on so­cial me­dia com­pa­nies for in­for­ma­tion on users.

Without know­ing how many of these sub­poe­nas there are and what they’re be­ing used for, there’s no way for courts or law­mak­ers or the pub­lic to put checks on ex­ec­u­tive branch abuses,” said Wessler, the ACLU at­tor­ney.

In the Minneapolis church case in­volv­ing Lemon and Fort, the Trump ad­min­is­tra­tion has ar­gued it had the power to use the cus­toms-re­lated sum­mons to ob­tain in­for­ma­tion even though the crimes the de­fen­dants were charged with have noth­ing to do with cus­toms. The pro­test­ers en­tered the church be­cause a lo­cal ICE of­fi­cial was a pas­tor there, and could have po­ten­tially as­saulted him or in­ter­fered with his du­ties, jus­tice de­part­ment lawyers wrote in a fil­ing ear­lier this year. Even though the man does not ap­pear to have been there, and there were no DHS of­fi­cials at the church or in­volved in the protest, lawyers said the DHS was en­ti­tled to is­sue the sum­mons be­cause it was in­ves­ti­gat­ing a po­ten­tial as­sault on a law en­force­ment of­fi­cer.

In court fil­ings, the Trump ad­min­is­tra­tion has ar­gued the Department of Homeland Security has the power to de­mand such records with­out ju­di­cial over­sight.

Although § 1509 ref­er­ences duties, fees, and taxes,’ the plain lan­guage of the statute does not limit DHSs in­ves­tiga­tive au­thor­ity to those sub­jects; in­stead, DHS is au­tho­rized to in­ves­ti­gate po­ten­tial crimes to en­sure compliance with the laws of the United States ad­min­is­tered by the United States Customs Service,’” which has been folded into the Department of Homeland Security, a lawyer wrote in a December court fil­ing last year.

That is an over­broad mis­read­ing of the statute, one ex­pert said.

I don’t buy that,” said Duncan, the for­mer DHS lawyer. It’s not a free-for-all that was thrown in there. Congress does not op­er­ate that way. Given these pro­vi­sions were specif­i­cally in­cor­po­rated into ti­tle 19, the cus­toms statute, Congress ob­vi­ously in­tended to au­tho­rize only records, de­mands and in­ter­views in fur­ther­ance of in­ves­ti­ga­tions into cus­toms vi­o­la­tions, not wild goose chases into pos­si­ble vi­o­la­tions of any fed­eral law with­out any ju­di­cial over­sight.”

In Fort’s case, Google did not com­ply with the sum­mons for any of the ac­counts. The com­pany re­sponded to the DHS by say­ing it had not of­fered ev­i­dence of how it was re­lated to a cus­toms in­ves­ti­ga­tion.

A Google spokesper­son said the com­pany re­views each re­quest for data it gets to en­sure it is le­gal and pushes back when it is too broad or does­n’t fol­low the cor­rect process.

Many so­cial me­dia com­pa­nies say they no­tify users when law en­force­ment makes a re­quest for their in­for­ma­tion and give them a chance to con­test the sum­mons. It’s not al­ways clear what the com­pa­nies will do if the user does­n’t re­spond or won’t con­test the re­quest them­selves. But pri­vacy ex­perts ques­tion whether that no­tice is ad­e­quate, say­ing many users are con­fused when they are con­tacted and do not have the re­sources to get a lawyer to con­test the de­mand in court.

They want peo­ple to think that they are go­ing to stand up for peo­ple’s pri­vacy, but they re­ally shifted the bur­den com­pletely onto the user,” said Lauren Regan, ex­ec­u­tive di­rec­tor of the Civil Liberties Defense Center, which rep­re­sented a Reddit user who chal­lenged the gov­ern­men­t’s ef­forts to get Reddit to re­veal their iden­tity through a 1509 sum­mons.

Companies are not re­quired to re­spond to a 1509 sum­mons and can ig­nore the re­quest if they think it is un­law­ful, forc­ing the gov­ern­ment to go to court to try to en­force the sum­mons. The Guardian was un­able to iden­tify any cases where the gov­ern­ment at­tempted to get a court or­der to en­force a 1509 sum­mons out­side of the tra­di­tional cus­toms con­text. Companies can also file their own mo­tions to try to quash the sum­monses.

If a user ac­tu­ally hired a lawyer, it would cost tens of thou­sands of dol­lars to fight one of these,” said F Mario Trujillo, a lawyer at the Electronic Frontier Foundation, a pri­vacy watch­dog. They are not shoul­der­ing that bur­den; they’re push­ing that cost onto users and onto non-profit groups when they could eas­ily get their high-pow­ered lawyers who are be­ing paid $500 to $1,000 an hour to fight these.”

In 2017, Twitter filed a law­suit chal­leng­ing a Department of Homeland Security 1509 sum­mons seek­ing to un­mask an ac­count, @alt_uscis, that was crit­i­cal of the DHS. The de­part­ment ul­ti­mately with­drew the sum­mons.

In sev­eral cases, the DHS has with­drawn a 1509 sum­mons af­ter it was chal­lenged in court and be­fore a judge could rule on its le­gal­ity. That may be a de­lib­er­ate strat­egy to avoid hav­ing a judge rule on the le­gal­ity of the sum­mons.

In one in­stance last year, the DHS served a 1509 sum­mons on Meta to un­mask the user be­hind an Instagram and Facebook ac­count that mon­i­tored ICE agent ac­tiv­i­ties in the Philadelphia sub­urbs. The user chal­lenged the sum­mons in court, say­ing it was clearly not au­tho­rized un­der the law. Lawyers for the DHS de­fended the sum­mons, say­ing it fell within the scope of laws the DHS en­forced. Both sides pre­sented ar­gu­ments be­fore a judge on 15 January and DHS with­drew the sum­mons the next day.

They don’t want a judge to take away this scary tool be­cause they are get­ting stuff out of it,” Regan said. Once a court rul­ing says thou shalt not use this statute’, it does not ap­ply.”

In 2017, the DHS in­spec­tor gen­eral is­sued a re­port find­ing inconsistent — and, in some cases, im­proper” — use of the 1509 sum­monses af­ter the @alt_uscis case.

The of­fice of the in­spec­tor gen­eral re­view found that of­fi­cials in Customs and Border Protection’s of­fice of pro­fes­sional re­spon­si­bil­ity were reg­u­larly mis­us­ing the sub­poena and rec­om­mended a se­ries of re­forms to en­sure more over­sight over those that were used. The of­fice agreed to the re­forms.

Lawmakers added $1 to Texans' car insurance policies. That money paid for thousands of Flock cameras.

www.texastribune.org

Audio record­ing is au­to­mated for ac­ces­si­bil­ity. Humans wrote and edited the story. See our AI pol­icy, and give us feed­back.

In 2023, the Texas Legislature unan­i­mously passed a law rais­ing auto in­sur­ance costs for Texans by $1 to com­bat ram­pant cat­alytic con­verter theft.

Three years later, a lit­tle-known state agency has de­voted at least $30 mil­lion of that fee to­ward su­per­charg­ing the state’s Flock sur­veil­lance net­work, plac­ing cam­eras along high­ways and streets from El Paso to the Louisiana bor­der, an analy­sis by The Texas Tribune found.

The Motor Vehicle Crime Prevention Authority, led by a board mostly ap­pointed by Gov. Greg Abbott, has turned the $1 fee hike into at least 3,200 Flock cam­eras.

The agency has awarded no fewer than 95 grants to help law en­force­ment agen­cies pur­chase and main­tain about 2,000 Flock cam­eras. Another $15.9 mil­lion is help­ing the Texas Department of Public Safety add al­most 1,200 more.

The ef­fort is far from over. In early August, the agency ap­proved an­other $3 mil­lion to help DPS in­stall 583 more cam­eras along Texas toll­ways over the next year.

Miguel Rodriguez, chair of the Motor Vehicle Crime Prevention Authority, said dur­ing an August 2023 meet­ing that he hoped to use pro­ceeds from the fee in­crease to cover the en­tire state” with cam­eras.

Rodriguez, who is also the Laredo Police Chief, sees the cam­eras as a pow­er­ful law en­force­ment tool, par­tic­u­larly to com­bat crim­i­nal or­ga­ni­za­tions.

That kind of ca­pa­bil­ity di­rectly dis­rupts the op­er­a­tional ad­van­tage these transna­tional crim­i­nal or­ga­ni­za­tions rely on, and it strength­ens our abil­ity to pro­tect both Texas com­mu­ni­tiesand the broader re­gion,” he said in an email.

But on Friday evening, af­ter mul­ti­ple re­quests for com­ment from the Tribune about its find­ings, Abbott’s of­fice said the gov­er­nor was paus­ing all state fund­ing for lo­cal grants to be used for Flock cam­eras.

To the ex­tent that cities get any fund­ing for those cam­eras, most of it comes from the fed­eral gov­ern­ment. To the ex­tent any fund­ing comes from Texas agen­cies, those agen­cies are clar­i­fy­ing that those funds can­not be used for Flock cam­eras,” Abbott spokesper­son Andrew Mahaleris said in a state­ment shared first with the Tribune.

The $1 per year fee in­crease has raised an es­ti­mated $81 mil­lion, al­low­ing the au­thor­ity to fun­nel $50.8 mil­lion into 234 grants that have helped re­im­burse po­lice de­part­ments for of­fi­cers, crime an­a­lysts and at­tor­neys to pros­e­cute ve­hic­u­lar crimes, as well as drones and other sur­veil­lance de­vices.

The Tribune found agency grants to po­lice de­part­ments ranged from $7,000 for two Flock cam­eras in Bellmead, near Waco, to al­most $1.7 mil­lion for 201 cam­eras in Dallas. Some city net­works — like the 165 cam­eras in Laredo and 150 in El Paso — were en­tirely sub­si­dized by the grants.

The state agency does not de­tail how much of its grant money went to Flock cam­eras. Instead, the Tribune tracked the grants by re­view­ing the ve­hi­cle au­thor­i­ty’s meet­ing records, as well as doc­u­ments, agen­das and dis­cus­sions from 101 city coun­cils and county com­mis­sions that ap­proved or dis­cussed Flock-related grants.

It is likely the au­thor­ity has paid for more Flock cam­eras than the Tribune analy­sis found be­cause 124 grants lack clear pub­lic doc­u­men­ta­tion about what was pur­chased.

The statewide ef­fort to pro­lif­er­ate Flock cam­eras comes as back­lash is mount­ing over the sur­veil­lance, in­clud­ing from some mem­bers of the Legislature, where the $1 fee was ap­proved with­out op­po­si­tion.

The sheer vol­ume of in­for­ma­tion cap­tured is not some­thing that is en­ter­tained, in my view, by the Fourth Amendment,” said Rep. Mitch Little, R-Lewisville.

State Sen. Carol Alvarado and Rep. Jeff Leach, the bil­l’s au­thor and House spon­sor, said sur­veil­lance cam­eras were never dis­cussed when the bill was con­sid­ered. Alvarado said she was sur­prised to learn from the Tribune that the in­sur­ance fee was fund­ing AI-supported li­cense plate read­ers.

I did not have that in mind when we passed the bill,” said Alvarado, D-Houston. When I think of com­bat­ing crime, I’m think­ing … more boots on the ground, hir­ing more of­fi­cers to tackle the crime or some type of un­der­cover work.”

Alvarado said there is a fine line” be­tween pro­tect­ing the pub­lic from crime and pro­tect­ing peo­ple’s pri­vacy, but said she did not plan to file leg­is­la­tion to shift the grant re­quire­ments.

Flock cam­eras, the na­tion’s most com­monly used li­cense plate reader, cre­ate a vehicle fin­ger­print” with the use of ar­ti­fi­cial in­tel­li­gence — stor­ing each ve­hi­cle’s li­cense plate, make, model, color and de­tails such as dents and bumper stick­ers in a data­base ac­ces­si­ble by law en­force­ment across the coun­try with­out hav­ing to ob­tain a search war­rant.

The ex­act num­ber of Flock cam­eras in Texas is un­clear. DeFlock, an anti-sur­veil­lance watch­dog that has mapped the lo­ca­tions of Flock cam­eras us­ing ver­i­fied crowd­sourc­ing, has iden­ti­fied about 13,000 in the state. By that count, the in­sur­ance fee in­crease has paid for one in four Texas cam­eras.

That also rep­re­sents a sharp in­crease in Flock cam­eras in the state since December 2023, when a com­pany spokesper­son told the ve­hi­cle au­thor­i­ty’s board that there were about 7,500 cam­eras in the state.

Flock does not dis­close how many cam­eras it has in the field, but Texas is es­ti­mated to have the sec­ond most in the na­tion, af­ter California. Nationally, Flock of­fi­cials say, about 7,000 law en­force­ment agen­cies use a to­tal of 120,000 cam­eras and other sur­veil­lance prod­ucts.

In Texas, state agen­cies don’t rely solely on ve­hi­cle au­thor­ity grants to add sur­veil­lance de­vices, and Abbott’s of­fice pointed to fed­eral grants for fund­ing the cam­eras. DPS, for ex­am­ple, has a $28.5 mil­lion con­tract for Flock cam­eras. But the grants have helped get the cam­eras into the hands of the state’s smaller po­lice de­part­ments that may have strug­gled with the cost of the equip­ment.

Departments that opt in to Flock’s na­tional lookup pro­gram can search each oth­er’s data from any­where in the coun­try, al­low­ing ve­hi­cles to be tracked with un­prece­dented ef­fi­ciency.

The abil­ity to share data has been one of the most ef­fec­tive ways Flock has been able to help find, just last year, over 10,000 miss­ing per­sons,” Flock spokesper­son Trevor Chandler said in an in­ter­view.

But for a rapidly grow­ing coali­tion of Texans op­posed to the cam­eras, the Flock net­work is a dan­ger­ous com­bi­na­tion of in­va­sive sur­veil­lance and lim­ited over­sight that un­der­mines pri­vacy rights.

Kenneth Feagins, an or­ga­nizer with DFW DeFlock, one of sev­eral new grass­roots anti-sur­veil­lance groups in the state, said he sees an alarming trend” of po­lice im­prop­erly ac­cess­ing a net­work that can amass data on where peo­ple live, shop, wor­ship and work.

For me, it’s al­ways been the ques­tion of, well, how much lib­erty are we will­ing to trade for safety?” Feagins said.

Recently re­vealed ex­am­ples of mis­use — in­clud­ing po­lice of­fi­cers us­ing Flock data to stalk ex-part­ners and co-work­ers — have sharp­ened those con­cerns.

A Lufkin of­fi­cer was in­dicted Aug. 24 on 100 counts of mis­us­ing of­fi­cial in­for­ma­tion, which Abbott cited as a con­cern­ing de­vel­op­ment dur­ing a Friday ra­dio in­ter­view. Officers in Baytown, Harris County, Fort Bend County, Temple and Pasadena also have been ar­rested, dis­ci­plined or in­ves­ti­gated.

There’s a lot of ma­li­cious things that can be done with this data, and those things are no longer hy­po­thet­i­cal,” Feagins said.

Cameras changed the game” for po­lice

The Motor Vehicle Crime Prevention Authority was es­tab­lished by the Legislature in 1991 to com­bat au­to­mo­bile theft.

The au­thor­ity is led by a DPS of­fi­cial and six gov­er­nor-ap­pointed board mem­bers — two from law en­force­ment, two from the in­sur­ance in­dus­try and two con­sumer rep­re­sen­ta­tives.

The ve­hi­cle au­thor­ity pri­mar­ily flexes its mus­cle via grants funded by fees added to an­nual auto in­sur­ance pre­mi­ums — $1 ini­tially, ris­ing to $2 in 2011 and $4 in 2019 — that largely went to fund task force ef­forts for po­lice de­part­ments.

In 2023, with cat­alytic con­verter theft spik­ing across Texas, law­mak­ers ap­proved adding an­other $1 to the in­sur­ance fee in a bill named for Harris County Deputy Darren Almendarez, who was shot to death af­ter in­ter­rupt­ing cat­alytic con­verter thieves in a gro­cery store park­ing lot.

The leg­is­la­tion made no ref­er­ence to li­cense plate read­ers, and Rep. Brian Harrison, who voted for the bill, said he was­n’t aware of any con­ver­sa­tions about us­ing the fee in­crease that way. The Midlothian Republican filed bills that year and in 2025 to re­quire a war­rant be­fore po­lice could ac­cess li­cense plate reader data.

In a mil­lion years, I never could have even con­tem­plated that this would be used to fund what is ef­fec­tively war­rant­less sur­veil­lance,” Harrison said. Otherwise, I can’t imag­ine it would have got­ten unan­i­mous sup­port. I sure as hell would­n’t have voted for it if I knew some bu­reau­crat was go­ing to redi­rect the money to Flock cam­eras.”

Anticipating mil­lions from the $1 in­sur­ance fee hike, the ve­hi­cle au­thor­ity in 2023 asked law en­force­ment for ad­vice on how best to spend the money. Automatic li­cense plate read­ers like Flock cam­eras were by far the top choice for com­bat­ting cat­alytic con­verter theft, beat­ing out over­time for in­ves­ti­ga­tors and ad­di­tional train­ing.

The cam­eras, Rodriguez said, are par­tic­u­larly help­ful for ad­dress­ing cat­alytic con­verter theft, a mobile, high-vol­ume, low-wit­ness crime” where the ve­hi­cle used is of­ten the only lead.

Without tech­no­log­i­cal help, de­part­ments were left work­ing with par­tial de­scrip­tions taken from grainy sur­veil­lance footage of sus­pect ve­hi­cles, Rodriguez said.

Data from the li­cense plate read­ers, known in law en­force­ment as LPRs, was searched 62,000 times in 2025, lead­ing to about 1,660 cleared cat­alytic con­verter theft cases, a re­port from the au­thor­ity said.

Pasadena Police Sgt. Douglas Buckert said the cam­eras changed the game” for cat­alytic con­verter theft in­ves­ti­ga­tions.

The num­ber of leads we’ve got­ten since our de­part­ment has de­ployed Flock cam­eras is out­ra­geous,” Buckert told the au­thor­ity in early 2024. I could have six more in­ves­ti­ga­tors and not get it all done.”

Grant-funded cam­eras, much more than other tech­nol­ogy, have also ex­panded the reach of po­lice in in­ves­ti­ga­tions far be­yond cat­alytic con­verter cases, de­part­ment of­fi­cials say.

Dallas Police Sgt. Bryan Roden told board mem­bers dur­ing a January meet­ing that an au­thor­ity grant let his de­part­ment in­crease its net­work from 100 to 300 cam­eras, help­ing to bust a mil­lion-dol­lar tire theft ring and solve a hit and run. Working with the Department of Homeland Security, Dallas po­lice lo­cated a fugi­tive wanted for co­caine man­u­fac­tur­ing by us­ing Flock cam­eras he reg­u­larly passed to build a pattern of life as­sess­ment,” Roden said.

Temple Police crime an­a­lyst Mike Treehern told the Tribune that the cam­eras helped de­crease the num­ber of stolen ve­hi­cles in his city, where 84% of their Flock cam­eras are funded by the state grant.

It’s ab­solutely helped us, and we would not have any­where near the amount of cam­eras that we do with­out [vehicle au­thor­ity] funds,” Treehern said.

The grant has also been a force mul­ti­plier for smaller de­part­ments. In Cibolo, a city north of San Antonio with a pop­u­la­tion of 36,000, an au­thor­ity grant mul­ti­plied the num­ber of Flock cam­eras from 11 to 52.

Honestly, a lot of our sur­round­ing com­mu­ni­ties started look­ing at them, specif­i­cally through the [Motor Vehicle Crime Prevention Authority],” Cibolo Police Lt. John Wells told board mem­bers in a January meet­ing. Seguin was look­ing at them, Guadalupe County, the New Braunfels Police Department, all of our neigh­bors, so we started look­ing as well.”

Hannah Foust, founder of DeFlock Carrollton, said the cam­eras give po­lice sur­veil­lance power well in ex­cess of what’s needed to stop car thieves.

I do think that mo­tor ve­hi­cle theft is a con­cern, it’s an is­sue,” Foust said. [But] I do think that this grant pro­gram, and the way it’s been used … it re­ally shifts the fo­cus to a broader sur­veil­lance pro­gram, as op­posed to fo­cus­ing on cat­alytic con­verter pre­ven­tion.”

$1 fee hike helped DPS ex­pand its Flock net­work

The au­thor­i­ty’s most sig­nif­i­cant in­vest­ment in Flock came in 2025 when it signed a three-year, $15.9 mil­lion con­tract with DPS to in­stall 1,183 cam­eras in a pro­ject largely over­seen by DPS Major Sharon Jones, the board’s self-de­scribed pro Flock” mem­ber who left the po­si­tion Aug. 1.

The con­tract aims to bol­ster DPS net­work of cam­eras and make it ac­ces­si­ble to lo­cal law en­force­ment agen­cies in places that oth­er­wise could not be eas­ily reached — in­clud­ing lo­cal mu­nic­i­pal­i­ties that are re­sis­tant to the sur­veil­lance.

Patrick McBroom, po­lice com­man­der for the Panhandle Auto Burglary and Theft Unit, said DPS cam­eras help his task force mon­i­tor in­ter­state traf­fic at the Oklahoma and New Mexico bor­ders — ar­eas of Texas be­yond the view of 138 grant-funded cam­eras his team mon­i­tors.

All those roads lead­ing out and into Texas have DPS cam­eras on them, so if we have stolen items that may be go­ing out of state, we’re able to look at those cam­eras to see if those ve­hi­cles have left the state,” McBroom said.

During an April con­ver­sa­tion about the DPS con­tract, Rodriguez noted the state po­lice force’s cam­eras could im­prove sur­veil­lance in ar­eas where lo­cals are un­will­ing to in­stall their own cam­eras. A grow­ing num­ber of cities and coun­ties, in­clud­ing Austin, have can­celed their Flock con­tracts in the face of res­i­dents’ pri­vacy con­cerns.

I think that if for what­ever rea­son you are within those ju­ris­dic­tions that do not want Flock, let’s get to­gether with DPS, [so] that, you know, we can put those in state right-of-way. And there’s noth­ing that they can tell us,” Rodriguez said to Jones.

Rodriguez told the Tribune that the DPS net­work pro­vides a needed crime-fight­ing tool in ar­eas hos­tile to Flock cam­eras and sim­i­lar de­vices.

Almost 100 mu­nic­i­pal­i­ties in the U.S. have ended their Flock con­tracts in re­sponse to pub­lic out­cry, in­clud­ing sev­eral in Texas, such as Bandera and Hood County. Both had re­ceived grants for their cam­eras but ended their con­tracts af­ter is­sues with Flock in­stal­la­tion and in re­sponse to pub­lic up­roar over their use.

As crit­i­cism over the cam­eras has ex­ploded — in­clud­ing de­vices that were cut down or van­dal­ized as acts of protest — agency board mem­bers have ex­pressed frus­tra­tion at what they see as mis­in­for­ma­tion that clouds the pos­i­tive im­pact from the cam­eras.

We’ll have a larger con­ver­sa­tion re­gard­ing the need to ed­u­cate the pub­lic, and we must put a stamp on those who are spread­ing false in­for­ma­tion on li­cense plate read­ers,” Jones said in a July grant meet­ing.

A con­cern for our pri­vacy”

Foust started Carrollton’s DeFlock group af­ter her neigh­bors ex­pressed frus­tra­tion at the cam­eras’ rapid spread. Spotting a cam­era along the route her chil­dren walk to school gave her pause; see­ing one go up in front of her com­mu­nity recre­ation cen­ter made her act.

You can’t en­ter or exit that com­plex with­out pass­ing a Flock cam­era, and that’s also my polling place, so that re­ally gave me a strong re­ac­tion,” Foust said. They were in places that we nor­mally feel very safe at, and there’s no con­cerns for our safety, for our chil­dren’s well-be­ing, but there sud­denly was a con­cern for our pri­vacy.”

Foust is open to dis­cuss a va­ri­ety of so­lu­tions to her con­cerns, in­clud­ing ac­tion by the Texas Legislature, but said the first step is get­ting city of­fi­cials to be trans­par­ent about their use.

I think be­fore we can have a true and hon­est con­ver­sa­tion about what leg­is­la­tion might look like or what guardrails or safe­guards could be put in place, I think we need to start on a level play­ing field of un­der­stand­ing,” Foust said. What is the sys­tem, what is it ca­pa­ble of, and how could it be set up in a way that’s sup­pos­edly safe?”

Harrison and Little said they in­tend to file bills next leg­isla­tive ses­sion ban­ning the de­vices be­cause they be­lieve the cam­eras vi­o­late the Fourth Amendment’s pro­tec­tion against un­rea­son­able searches. Little said he’s par­tic­u­larly con­cerned about whether vast amounts of per­sonal data is se­curely stored and whether Flock, a pri­vate com­pany, should be able to ac­cess it.

The peo­ple in Lewisville, Texas have a rea­son­able ex­pec­ta­tion of pri­vacy from po­lice of­fi­cers in Pampa, Texas, and yet they can ob­serve all that data,” Little said. So the shar­ing of it across state lines, across ju­ris­dic­tional lines, to me is highly prob­lem­atic.”

Harrison said he was shocked and dis­mayed” that so few Republicans had spo­ken out against Flock cam­eras and what he calls bla­tant con­sti­tu­tional vi­o­la­tions. He also said state of­fi­cials should take more im­me­di­ate ac­tion to shut off” Flock grants be­cause leg­is­la­tors never in­tended to use the in­sur­ance fee in­crease for cam­eras.

I think the Legislature should­n’t take this sit­ting down. I think the gov­er­nor should act on this,” Harrison said. If that’s hap­pen­ing, what that means is there’s clearly no ex­plicit leg­isla­tive in­tent or di­rec­tion for that to be hap­pen­ing.”

Tencent Releases and Open-Sources Tencent Hy4 preview

www.tencent.com

Ranked among the top tier of open-source mod­els, Hy4 pre­view is built for real-world pro­duc­tiv­ity tasks, de­liv­er­ing out­stand­ing per­for­mance across cod­ing, of­fice work, and sci­en­tific re­search

Tencent has re­leased and open-sourced Tencent Hy4 pre­view, a next-gen­er­a­tion large lan­guage model with 770B to­tal pa­ra­me­ters and 49B ac­tive pa­ra­me­ters, and a con­text win­dow ex­ceed­ing 1M to­kens. It demon­strates out­stand­ing ca­pa­bil­i­ties on real-world pro­duc­tiv­ity tasks span­ning cod­ing, of­fice work, and sci­en­tific re­search.

Hy4 pre­view is now avail­able as an open-source model and can also be ac­cessed glob­ally through WorkBuddy and CodeBuddy, as well as Yuanbao, ima and other Tencent prod­ucts. Users can try the model di­rectly through these ap­pli­ca­tions, or con­nect to it via API through Tencent Cloud TokenHub and OpenRouter.

Upon launch, Hy4 pre­view will be avail­able for free on WorkBuddy and CodeBuddy for two weeks. Free ac­cess to Hy3 on both plat­forms has also been ex­tended un­til September 30.

Hy4 pre­view was ex­panded sig­nif­i­cantly in model size, con­text length, and data vol­ume, and  the ad­vances in both pre-train­ing and post-train­ing have led to a ma­jor leap in over­all in­tel­li­gence, plac­ing the model among the top tier of open-source mod­els.

Hunyuan con­tin­u­ously works in deep co-de­sign with prod­ucts such as CodeBuddy and WorkBuddy, op­ti­miz­ing the real-world user ex­pe­ri­ence across pro­duc­tiv­ity sce­nar­ios. In a blind eval­u­a­tion con­ducted in­ter­nally by Tencent in­volv­ing 163 ex­perts and 203 en­gi­neer­ing tasks, Hy4 pre­view scored an av­er­age of 2.99 out of 4.00, slightly ahead of GLM-5.3 (2.92/4.00) and Kimi K3 (2.94/4.00).

Designed for pro­duc­tiv­ity, Hy4 pre­view was de­vel­oped us­ing high-qual­ity train­ing data co-cre­ated with Tencent ex­perts across soft­ware en­gi­neer­ing, gam­ing, fi­nance, se­cu­rity, and other do­mains, as well as through deep co-de­sign with prod­ucts such as WorkBuddy. This has helped drive sig­nif­i­cant im­prove­ments across a wide range of real-world pro­duc­tiv­ity tasks.

In soft­ware en­gi­neer­ing, Hy4 pre­view de­liv­ers stronger un­der­stand­ing, plan­ning, de­bug­ging, and val­i­da­tion ca­pa­bil­i­ties for long-con­text de­vel­op­ment tasks, while also en­hanc­ing the vi­sual qual­ity and in­ter­ac­tion ex­pe­ri­ence of front-end de­vel­op­ment.

In of­fice pro­duc­tiv­ity and an­a­lyt­i­cal sce­nar­ios, the model demon­strates a sig­nif­i­cantly stronger un­der­stand­ing of com­plex work­ing en­vi­ron­ments and en­hanced fi­nan­cial analy­sis ca­pa­bil­i­ties. It has also been op­ti­mized for data analy­sis and cross-doc­u­ment col­lab­o­ra­tion, sup­port­ing the full work­flow from in­for­ma­tion pro­cess­ing through to the cre­ation of doc­u­ments, spread­sheets, and pre­sen­ta­tions.

In game de­vel­op­ment, Hy4 pre­view can gen­er­ate a playable pro­to­type from a sin­gle nat­ural-lan­guage re­quest, and work ef­fec­tively with game en­gines. Developers can then con­tinue re­fin­ing com­plex game pro­jects through multi-turn in­ter­ac­tions.

In sci­en­tific re­search, Hy4 pre­view demon­strates stronger ca­pa­bil­i­ties in un­der­stand­ing, rea­son­ing through and solv­ing com­plex re­search prob­lems, with no­table im­prove­ments across ar­eas in­clud­ing AI re­search and de­vel­op­ment, mol­e­c­u­lar dy­nam­ics sim­u­la­tion, con­densed-mat­ter physics and fun­da­men­tal math­e­mat­ics.

Notably, Hy4 pre­view also con­tributed to its own de­vel­op­ment process, par­tic­i­pat­ing for the first time in the au­to­mated op­ti­miza­tion of train­ing meth­ods, data strate­gies, eval­u­a­tion frame­works, and low-level op­er­a­tors. The model pro­posed ap­proaches, ran ex­per­i­ments, and it­er­ated based on the re­sults, with the re­sult­ing code, logs, and feed­back feed­ing into sub­se­quent rounds of ex­plo­ration. This es­tab­lished an early-stage re­cur­sive self-im­prove­ment loop.

Hy4 pre­view has also au­tonomously an­a­lyzed bot­tle­necks in its in­fer­ence sys­tem  and car­ried out mul­ti­ple rounds of op­ti­miza­tion on ar­eas such as op­er­a­tor fu­sion and com­mu­ni­ca­tion op­ti­miza­tion. These im­prove­ments in­creased end-to-end through­put by 31.8% com­pared with the base­line, with con­sis­tent gains across dif­fer­ent con­text lengths and con­cur­rency lev­els. This demon­strates the mod­el’s abil­ity to au­tonomously op­ti­mize its own in­fer­ence in­fra­struc­ture.

Hy4 pre­view con­tin­ues to of­fer cost ef­fi­ciency, help­ing make ad­vanced AI more widely ac­ces­si­ble. API pric­ing is set at USD 0.834 per mil­lion in­put to­kens, USD 2.501 per mil­lion out­put to­kens and USD 0.042 per mil­lion to­kens for cache hits.

Through a pre­view-first ap­proach, fol­lowed by of­fi­cial re­leases, Hunyuan con­tin­u­ously in­cor­po­rates real-world feed­back into its re­search and de­vel­op­ment process, en­abling its mod­els to im­prove by solv­ing real-world prob­lems. The next batch of mod­els in the Hy4 se­ries is ex­pected to roll out soon.

Bug blindness

danluu.com

I used to won­der why I see so many more bugs than most peo­ple. I eas­ily ob­serve hun­dreds to thou­sands of bugs per week and noth­ing seems to work, but most peo­ple I talk to don’t see any­thing like this. For a long time, I thought this had some­thing to do with how I use com­put­ers but, over time, I’ve re­al­ized that it’s mostly that peo­ple are hit­ting the same bugs and don’t no­tice.

If you’re not a pro­gram­mer, that’s prob­a­bly a bet­ter way to see the world, but I think cur­ing qual­ity/​bug blind­ness is help­ful for pro­gram­mers. I’ve done this with a lot of friends and ac­quain­tances (just by point­ing out bugs). After a few weeks, peo­ple who are so in­clined tend to start notic­ing bugs as well.

Because I no­tice these kinds of things, I’ve had mul­ti­ple jobs where di­rec­tors/​VPs/​ex­ecs/​etc. some­times ask me to eval­u­ate some­thing when they want an ac­tual opin­ion from some­one who is rel­a­tively likely to no­tice is­sues (and fix them or drive fixes for them if nec­es­sary). Sometimes I won’t find any is­sues (there are likely is­sues that just aren’t the kind I no­tice). More of­ten, I find is­sues that fall some­where from mild” to moderate”. And, some­times, the is­sues are se­vere, to the point where one might even say the thing ac­tu­ally does­n’t work.

I find this last cat­e­gory a bit mys­te­ri­ous, as when I look up dis­cus­sions on how the thing got into this state, there’s usu­ally a stream of in­ter­nal com­ments in­di­cat­ing that the thing is great, it works well, etc., but when I open up the thing and try it, it’s in a state where the thing only works if you do quite a few non-in­tu­itive workarounds. More likely than not, not only would a nor­mal user not be able to use the thing, they’d have such a hi­lar­i­ously/​in­fu­ri­at­ingly bad ex­pe­ri­ence that they’d tell their friends.

I’ve had this post in mind for maybe a decade or so, but I was hes­i­tant to write it up be­cause, in the back of my mind, I al­ways won­dered if I’m some­how trig­ger­ing weird cor­ner case be­hav­ior most users don’t hit with­out re­al­iz­ing it. But af­ter see­ing more and more cases where the prod­uct launches and falls flat on its face be­cause users run into the ex­act same is­sues I saw, I don’t think that, in gen­eral, I’m hit­ting bugs be­cause I’m do­ing un­usual things a nor­mal user would­n’t do. If a prod­uct seems se­verely flawed when I use it, it prob­a­bly is. And with the magic of LLMs, nowa­days, I can even have LLMs act like nor­mal users in a lot of ways and show that the is­sues re­pro­duce across many dif­fer­ent sce­nar­ios.

A few ex­am­ples

I don’t want to give any spe­cific ex­am­ples where it was my job to see how well the thing worked be­cause, even if the in­ter­nal ex­am­ples are meant in a con­struc­tive, blame­less, way, they may not al­ways read that way when re-posted ex­ter­nally, so I’ll give a few less in­ter­est­ing and less well sup­ported random” ex­am­ples.

A while ago, I wrote up the re­sults of some web search queries and found poor re­sults from Google, Bing and Kagi. In gen­eral, the ma­jor search en­gines failed to re­turn good re­sults for the queries and re­turned pages full of low-qual­ity SEO spam as well as some sites that were ac­tu­ally scams. BTW, on the scale men­tioned above, I would con­sider this moderate” and not severe” (severe would be some­thing like, the search en­gine re­turns 500 er­rors half the time, the ma­jor­ity of re­sults are scams, etc; my bar for se­vere is that a nor­mal user likely won’t be able to use the thing at all, not that they have a bad ex­pe­ri­ence). Almost no­body1 ob­jected to my char­ac­ter­i­za­tion of Google and Bing search re­sults, but peo­ple told me that I was wrong about Kagi. In some cases, peo­ple sent me their ac­tual search re­sults. In every such case, the search re­sults did not con­tain a good re­sult that I could see (e.g., for the sea­sonal fore­cast query, the search failed to re­turn an up-to-date sea­sonal fore­cast) and was full of SEO spam. In one case, a per­son passed me both their list of Kagi fil­ters as well as the search re­sults they got with­out mak­ing claims that the re­sults were good or bad, but peo­ple gen­er­ally in­sisted the re­sults were good even though the re­sults both failed to link to a use­ful re­sult and were full of spam ex­cept in cases where the user did some­thing like pin GitHub to the top of their re­sults, which worked for the queries where the goal was to down­load soft­ware that’s hosted on GitHub, but of course com­pletely fails for the other queries from the post.

In the ab­stract, I get that peo­ple who are fans of things tend to be blind to the thing’s faults. For ex­am­ple, since I bought a Volvo af­ter see­ing how they do in out-of-sam­ple crash tests, I some­times search for an­swers to my ques­tions on Volvo car fo­rums. For well over a decade, the re­li­a­bil­ity data that ex­ists (and I think this is backed up by the anec­do­tal ex­pe­ri­ence that me­chan­ics who work on Volvos have) is that Volvo re­li­a­bil­ity is mediocre to poor, but of course Volvo fo­rums are full of peo­ple who in­sist that Volvos are among the most re­li­able cars and that the data are all wrong.

An ex­am­ple that might be more cen­tral to the topic is Blackboard (the course man­age­ment soft­ware). Back when it was the most widely used soft­ware by uni­ver­si­ties for course­work, the soft­ware was widely dis­liked by both stu­dents and pro­fes­sors. I think it would be fair to say that it was the most widely dis­liked soft­ware in my so­cial cir­cles (there was more strongly dis­liked soft­ware, like Visual Source Safe, but any more strongly dis­liked soft­ware was­n’t widely used enough to be the most widely dis­liked over­all). The Wikipedia page notes

Blackboard had be­come one of the most dis­liked — even de­tested — com­pa­nies in ed­u­ca­tion.”

Blackboard had be­come one of the most dis­liked — even de­tested — com­pa­nies in ed­u­ca­tion.”

as well as

In December 2011, Fast Company re­ported that 93% of re­spon­dents to the Amplicate cus­tomer opin­ion sur­vey hate” the com­pany.

In December 2011, Fast Company re­ported that 93% of re­spon­dents to the Amplicate cus­tomer opin­ion sur­vey hate” the com­pany.

Back when I was much younger and had less of a fil­ter, I ran into some­one who worked at Blackboard and, with­out think­ing, I stu­pidly blurted out some­thing like what’s it like to work on this soft­ware that so many peo­ple dis­like?”. Luckily, the per­son I was talk­ing to was­n’t of­fended at all and, in­stead, they were ac­tu­ally con­fused be­cause they thought it was widely loved soft­ware that users re­ally liked. They did­n’t re­ally be­lieve what I said could be true and I made some com­ment in­di­cat­ing that it was just con­fu­sion on my part and then the con­ver­sa­tion con­tin­ued in a dif­fer­ent di­rec­tion. At the time, as some­one much younger and more naive, I was re­ally sur­prised to hear that the soft­ware that was prob­a­bly the most widely dis­liked soft­ware in my so­cial cir­cles was thought to be re­ally well-liked soft­ware by the one em­ployee from the com­pany I met (and, pre­sum­ably other em­ploy­ees as well).

I can un­der­stand how the Volvo fo­rums get to be how they are, in that cars are re­li­able enough in gen­eral now that peo­ple gen­er­ally don’t ex­pe­ri­ence car break­downs, so it’s easy for some­one to think some­thing like the data can’t be right; af­ter all, my car has never bro­ken down”. It’s more of a mys­tery to me how some­body can look at a set of search re­sults that are full of spam and then dash off a mes­sage ex­plain­ing how great the re­sults are, even if they’re a fan of a par­tic­u­lar search en­gine or how some­one can think that users gen­er­ally love soft­ware that’s fa­mous for be­ing dis­liked, to the point that every sin­gle per­son I talk to about it tells me how bad it is (often in un­prompted com­plaints), there are news ar­ti­cles that dis­cuss how much peo­ple dis­like the soft­ware, and the near-uni­ver­sal dis­like for the soft­ware is men­tioned on its Wikipedia page. Another Blackboard-like ex­am­ple might be Discourse (forum soft­ware) web per­for­mance, where one of the in­spi­ra­tions for this post was dis­cus­sions with Discourse em­ploy­ees who thought that Discourse had great per­for­mance. I found that one in­ter­est­ing be­cause Discourse ac­tu­ally had code in it that slowed down ac­tual page loads in or­der to cheat on web per­for­mance met­rics like LCP. That went well be­yond just op­ti­miz­ing for a bench­mark and rose to the level of ac­tual cheat­ing that not only had no ben­e­fit to the user, it ac­tu­ally harmed the user. At some level, the pro­gram­mers im­ple­ment­ing that sort of cheat­ing and ad­vis­ing users on how to not ac­ci­den­tally sub­vert the cheat­ing must know that the ac­tual per­for­mance of their app is poor, but it’s very easy for peo­ple to put up men­tal bar­ri­ers around this kind of thing.

By now, I would­n’t say that I’m sur­prised be­cause I’ve seen this kind of thing enough that I would ac­tu­ally con­sider it sur­pris­ing if it did­n’t hap­pen, but I still won­der what’s go­ing on in­side some­one’s head when some­thing like this hap­pens.

For a non-pro­gram­ming ex­am­ple, we pre­vi­ously noted in this post on how peo­ple have dif­fer­ent per­spec­tives on obvious” facts, there’s a bas­ket­ball player who, sub­jec­tively, is gen­er­ally con­sid­ered to be the dirt­i­est player of his era. The NBA does­n’t track ob­jec­tive mea­sures of player dirt­i­ness, but he seems dom­i­nant on a wide va­ri­ety of mea­sures. For ex­ampe, al­though, like re­bounds be­fore 1950, gen­i­tal strikes aren’t an of­fi­cially tracked stat, he surely holds the record for punch­ing, kick­ing, knee­ing, or oth­er­wise strik­ing play­ers in the gen­i­tals this cen­tury (he should also hold the record for era-ad­justed num­bers, but it’s pos­si­ble that he does­n’t have the all-time record due to play be­ing much dirt­ier over­all in the 80s and 90s). In dis­cus­sions, most fans of his team don’t seem to no­tice this and the phrases natural re­bound­ing mo­tion” and natural shoot­ing mo­tion” have be­come run­ning jokes from how obliv­i­ous the team’s fans are when they jus­tify this play­er’s con­tor­tions when he strikes other play­ers in the gen­i­tals.

On av­er­age, hu­mans have a high abil­ity to ig­nore neg­a­tives in things they’re a fan of, in­clud­ing (and of­ten es­pe­cially) their own work or work their com­pany does. For bet­ter or for worse, I seem to have the op­po­site of this and my thoughts im­me­di­ately go to the flaws in my­self and my work. A num­ber of times, as a re­sult of a blog post, some­one has mes­saged me with some­thing like how would you like it if some­one crit­i­cized your work?” or how would you like it if some­one said your work is­n’t good?” To the for­mer, my thought is that I go to great lengths to get crit­i­cism from peo­ple who can poke holes in my rea­son­ing, so it’s pretty awe­some if some­one has re­motely rea­son­able crit­i­cism of my work. And to the lat­ter, I gen­er­ally think my work is full of ma­jor flaws, so, uhh, yeah, it seems pretty rea­son­able to say it is­n’t good. There are par­tic­u­lar as­pects of my work that I think are in­ter­est­ing or good but, over­all, I don’t know that I’d rate any­thing I’ve done as good. I’m not say­ing I don’t have blind spots, but I think I’m a bit less prone to this par­tic­u­lar one than most peo­ple2.

Habitual mit­i­ga­tions

If I think about anal­o­gous blind spots I’ve had, one that jumps out at me is from when I was a lit­tle kid and a friend of mine used my com­puter. For this story to make sense, you have to know that this was in the me­chan­i­cal mouse era. Over time, de­tri­tus would get stuck to your mouse ball and cause it to track er­rat­i­cally un­less you cleaned it out.

When my friend tried to use my com­puter he found it im­pos­si­ble to use the mouse be­cause mouse pointer move­ment seemed al­most ran­dom. When I sat down at the com­puter again and used the mouse I did­n’t have any prob­lem us­ing it at all, but on look­ing at what I was do­ing with my hand to smoothly move the pointer in a straight line, I was vi­o­lently throw­ing my hand all over the place. I re­al­ized I must’ve ad­justed to the de­tri­tus on the mouse ball over time as it ac­cu­mu­lated and I was some­how com­pen­sat­ing for the mouse’s ex­tremely er­ratic track­ing by mak­ing coun­ter­vail­ing er­ratic move­ments3. I thought it was pretty amaz­ing that I could not no­tice that I was do­ing this and I al­ways won­der if I’m do­ing some equiv­a­lent thing to­day.

I some­times think about all of the mit­i­ga­tions I’ve de­vel­oped to work around bugs. For ex­am­ple, when open­ing a new Google Doc, I used to im­me­di­ately put the ti­tle I wanted into the doc. At some point, maybe ten years ago or so, Google Docs added some kind of de­lay such that the typ­ing you do into the ti­tle box right af­ter you open the doc gets over­writ­ten, so I now have this habit where, af­ter open­ing a Google Doc, I do some­thing else and then I change the ti­tle. Over time, as Google Docs has had more and more fea­tures added, I’ve de­vel­oped a se­ries of habits that avoid all sorts of pit­falls (such as try­ing to search at the wrong” time and get­ting the use­less na­tive browser search in­stead of the Google Docs search).

My feel­ing is that a large frac­tion of com­puter lit­er­acy and soft­ware lit­er­acy is de­vel­op­ing a large li­brary of these habits that you just do at a non-con­scious level. These are of­ten quite spe­cific to the sit­u­a­tion, such as a habit I de­vel­oped when I worked at Microsoft of flip­ping my lap­top’s WiFi switch to off be­fore log­ging in (which I no­ticed other peo­ple do­ing as well). This was be­cause there was some ser­vice, which would of­ten fail your lo­gin with There are cur­rently no lo­gon servers avail­able to ser­vice the lo­gon re­quest”. But if that ser­vice could­n’t con­nect at all, the check would be by­passed and you could just log in.

Quality blind­ness

We could fill a post up with ex­am­ples like that, but back to the main topic of the post, one com­monly sug­gested way to try to over­come qual­ity blind­ness is to have peo­ple dog­food their own soft­ware. On av­er­age, this is a lot bet­ter than not dog­food­ing, but it only works to the ex­tent that peo­ple don’t fig­ure out (and then for­get about) habits that work around what­ever is­sues the soft­ware has. On av­er­age, pro­gram­mers are pretty good at work­ing around soft­ware foibles (you had to be in or­der to be an ef­fec­tive pro­gram­mer pre-LLM), so it’s very easy for pro­gram­mers to not no­tice these kinds of is­sues if they’re not pay­ing at­ten­tion.

On the flip side, a large part of mak­ing an app easy for peo­ple to use seems to mean mak­ing weird habits like these un­nec­es­sary. Although this sounds like it should be easy to do, from hav­ing seen peo­ple try to give feed­back about this kind of thing, the re­flex­ive re­ac­tion of most de­vel­op­ers seems to be huh? It’s easy to do X, just do [complex se­quence of things that no nor­mal per­son would think of if they had­n’t used the app many times be­fore un­less it was specif­i­cally ex­plained to them or they saw some­one else do it]” or huh? Didn’t you see that the in­struc­tions for this are clearly laid out in page 43 of the man­ual af­ter you ex­e­cute the steps in Appendix B on page 261?”.

That be­ing said, I think cur­ing peo­ple of qual­ity blind­ness is do-able be­cause I’ve done it quite a few times. I think this only re­ally works when the per­son is re­cep­tive, as peo­ple have in­fi­nite ca­pac­ity for will­ful blind­ness but, in cases where peo­ple are re­cep­tive, just point­ing out is­sues they did­n’t no­tice seems to work. Years or even a decade later, peo­ple will some­times tell me they see bugs every­where now.

The rea­son I think this is worth do­ing is that I’ve seen peo­ple and teams with a high de­gree of qual­ity blind­ness ship things that have re­duced or even no chance of suc­cess be­cause of prod­uct qual­ity is­sues4. It’s one thing to know­ingly and de­lib­er­ately trade off qual­ity for speed5, but when I’ve seen this hap­pen there’s al­ways been a kind of qual­ity blind­ness where every­one in­volved with the pro­ject thinks they’re ship­ping some­thing very high qual­ity when that’s not the case.

This has never been unim­por­tant, but it’s got­ten more im­por­tant with cod­ing agents be­cause, while it’s eas­ier than ever to churn out low qual­ity soft­ware, it’s also eas­ier than ever to im­prove qual­ity, whether that’s bet­ter per­for­mance, fewer bugs, etc.

But, to do this, you have to ac­tu­ally no­tice that this is pos­si­ble, that qual­ity can be im­proved.

Thanks to Yossi Kreinin, Dennis Snell, Michael Malis, Emu Chu, Gary Bernhardt, Jon Surrell, and Matt Mullenweg for com­ments/​cor­rec­tions/​dis­cus­sion.

Naturally, Gary Bernhardt ran into a Google Docs bug while read­ing a draft of this post.

P.S. Like I’ve men­tioned in the last four posts, I’ve been try­ing to write posts more quickly be­cause, with LLMs, it’s so much eas­ier to look at data and fig­ure things out but, since I’m not writ­ingn with LLMs, the time it takes to write some­thing up has­n’t fun­da­men­tally changed, un­less I want to move to a dif­fer­ent point in the qual­ity-ve­loc­ity trade-off space. The prior re­sult was that I would run some ex­per­i­ments and tell a few friends and then never write any­thing up be­cause, due to Amdahl’s law, writ­ing any­thing up would ef­fec­tively con­sume all of my band­width for run­ning ex­per­i­ments. In fact, de­spite try­ing to do this (my goal is to spend 30 min­utes per post on the write-up), since writ­ing my last post, I have three re­sults that I think could make a to­tally fine blog post that I haven’t had time to write up (not in­clud­ing things done for work, which would add a few more things). Without hav­ing LLMs write for me, I don’t see a rea­son­able way to get the time per post sig­nif­i­cantly be­low 30 min­utes (and I think I of­ten miss my goal and take more than 30 min­utes), so the non-LLM op­tions here are some posts that are much slop­pier than my nor­mal posts (in a hu­man slop kind of way), or al­most no posts.

Anyway, if you have opin­ions on these quick (and surely more wrong) write­ups, let me know what you think (X Bsky Mastodon)!

Appendix: ad­ver­tis­ing blind­ness

Michael Malis (founder and for­mer CEO of Freshpaint) noted (in mes­sages, hence the mes­sage-like for­mat)

For a sim­i­lar but dif­fer­ent data point - I’ve seen sim­i­lar blind­ness when it comes to ad­ver­tis­ing. When I would ex­plain Freshpaint to peo­ple, I would tell them that we help hos­pi­tals with mar­ket­ing A com­mon ques­tion I get is why do hos­pi­tals do mar­ket­ing. The weird thing is if you pay at­ten­tion, hos­pi­tals do a ton of mar­ket­ing In SF there’s tons of bus ads and bill­boards for ucsf/​sut­ter health/​stan­ford and var­i­ous treat­ments

For a sim­i­lar but dif­fer­ent data point - I’ve seen sim­i­lar blind­ness when it comes to ad­ver­tis­ing. When I would ex­plain Freshpaint to peo­ple, I would tell them that we help hos­pi­tals with mar­ket­ing

A com­mon ques­tion I get is why do hos­pi­tals do mar­ket­ing. The weird thing is if you pay at­ten­tion, hos­pi­tals do a ton of mar­ket­ing

In SF there’s tons of bus ads and bill­boards for ucsf/​sut­ter health/​stan­ford and var­i­ous treat­ments

This is a dif­fer­ent topic from both Michael’s com­ments and the post, but I’ll say that I’ve talked to quite a few peo­ple who don’t be­lieve ads work at all, but I talked to some­one whose data method­ol­ogy and judge­ment I trust about ads A/B test­ing at one big com­pany I worked for and looked at the data my­self at an­other com­pany and I thought the causal ev­i­dence for ads pro­vid­ing real lift (well be­yond the cost of the ad) was strong in those cases. In the case where I looked at it, they did a geo-seg­mented A/B test where they bought ads in some geos but not oth­ers (this was done world­wide, with the re­gions be­ing things like U.S. states, Canadian provinces, etc.). This kind of geo-seg­men­ta­tion was done be­cause, even with cross-de­vice track­ing, it’s not 100% clear if some­one has been ex­posed to an ad or not (of course this is still the case with this kind of seg­men­ta­tion and I would pre­fer seg­men­ta­tion that was more clus­tered to pop­u­la­tion ar­eas and did­n’t have splits where peo­ple are rel­a­tively likely to, for ex­am­ple, com­mute from one side of a bound­ary to the other, but this kind of con­t­a­m­i­na­tion gen­er­ally makes the likely true lift higher than the es­ti­mated lift), so peo­ple some­times do these geo-seg­mented A/B tests.

Anyway, in these A/B tests, re­turn on ad spend was quite good just on di­rect rev­enue gain, and there was also a gain in users which seems likely to re­sult in more rev­enue down the road (the later rev­enue was­n’t an­a­lyzed). I don’t know about ad ef­fec­tive­ness in gen­eral or if your par­tic­u­lar ads are ef­fec­tive, but the com­monly re­peated idea that ads don’t work in gen­eral seems wrong to me.

On the topic of Michael’s com­ment, I think it’s easy for pro­gram­mers to not no­tice ads. Almost all pro­gram­mers I know use an ad blocker and, in real life, their eyes seem to just skim over ads and not no­tice them. I can see how this would feed into the idea that ads don’t work. Who the heck would look at these things? But from my in­ter­ac­tions with normal” peo­ple as well as the data I’m fa­mil­iar with from my time at Google, many or per­haps most peo­ple don’t even re­al­ize that a lot of ads are ads. When they do a Google search and they click on the top re­sut, they of­ten have no idea they’re not look­ing at what Google thinks” is the best link, they’re look­ing at at a link from who­ever paid Google the most to buy that ad slot.

Em Chu, on a ha­bit­ual bug mit­i­ga­tion:

I’m sure you can col­lect in­fi­nite ex­am­ples for this sec­tion, but I just want to Complain: when wak­ing up and un­lock­ing my lap­top (mac), it’s very easy to get it in a state where it’s awake” but un­us­able (black screen with cur­sor or sim­i­lar) which can only be fixed by phys­i­cally clos­ing the lid and re-open­ing it. To work around this, I think I usu­ally wait a sec­ond af­ter the screen turns on, in­ter­act with the track­pad, and then un­lock it, though hon­estly that hap­pens mostly sub­con­sciously, and I clearly need prac­tice given that I still hit the bug a few times a month.

I’m sure you can col­lect in­fi­nite ex­am­ples for this sec­tion, but I just want to Complain: when wak­ing up and un­lock­ing my lap­top (mac), it’s very easy to get it in a state where it’s awake” but un­us­able (black screen with cur­sor or sim­i­lar) which can only be fixed by phys­i­cally clos­ing the lid and re-open­ing it. To work around this, I think I usu­ally wait a sec­ond af­ter the screen turns on, in­ter­act with the track­pad, and then un­lock it, though hon­estly that hap­pens mostly sub­con­sciously, and I clearly need prac­tice given that I still hit the bug a few times a month.

On read­ing this, I ex­am­ined how I open my lap­top and re­al­ized that I have some funny habits as a re­sult of work­ing around other lap­top bugs. The spe­cific bug men­tioned here does­n’t re­pro­duce on my lap­top and it seems that I can stop the ha­bit­ual mit­i­ga­tion I put into place for some prior lap­top.

Gary Bernhardt, on his ex­pe­ri­ence read­ing a draft of this post

While read­ing it, Google Docs’ UI seems to have bro­ken, mak­ing it im­pos­si­ble to scroll up to read some com­ments (see screen­shot [not shown in post]).

While read­ing it, Google Docs’ UI seems to have bro­ken, mak­ing it im­pos­si­ble to scroll up to read some com­ments (see screen­shot [not shown in post]).

From look­ing at the screen­shot, I’ve seen the ex­act same bug and have some mit­i­ga­tions for it (different ones de­pend­ing on the con­text). I would per­son­ally rate Google Docs as far above av­er­age in terms of soft­ware qual­ity: I find it much less buggy and janky than the ma­jor al­ter­na­tives (Microsoft Word, Open Office, var­i­ous old ed­i­tors that are long gone like StarOffice, Lotus, etc.). And yet, I could eas­ily sit down and write a 10k word post on Google Docs bugs and the workarounds I have for them.

At times, I’ve tried to see if I can get a job some­where where I just fix qual­ity is­sues all day. This has never panned out, due to some com­bi­na­tion of this not be­ing a very high pri­or­ity and it also not be­ing a nor­mal role that com­pa­nies have a role for. I some­times day­dream about join­ing com­pa­nies as an in­tern and just fix­ing qual­ity is­sues for a few months and then leav­ing. In prac­tice, I think if I got such a job, a lot of the fixes would get blocked and it would be very dif­fi­cult to ac­tu­ally drive change as an in­tern for three months, so it would have to be some mostly aban­doned pro­ject where no­body cares what I do (and cor­po­rate pri­or­ties aren’t so fo­cused on ship­ping fea­tures that fixes get im­me­di­ately re-bro­ken).

@IncidentNoodle

Unintentionally on topic: the <abbr> tags worked on mo­bile ~last week, but are no longer work­ing across any iOS browser (safari/chrome/firefox), and I had a hard time fig­ur­ing out that hover showed them on ma­cOS browsers (all three) due to the long de­lay

Unintentionally on topic: the <abbr> tags worked on mo­bile ~last week, but are no longer work­ing across any iOS browser (safari/chrome/firefox), and I had a hard time fig­ur­ing out that hover showed them on ma­cOS browsers (all three) due to the long de­lay

@gunch­leoc@mastodon.scot:

Germans have a word for that - Betriebsblindheit

Germans have a word for that - Betriebsblindheit

@oulipien.bsky.social:

Crazy anec­dote from @danluu.com here and I wish he’d been even blunter at the time and asked this per­son where they’d got­ten this be­lief about Blackboard be­ing liked by any­one at all. User sur­veys? Principal (as in, not agent) sur­veys? Inner con­vic­tion??? [screenshot of Blackboard anecodote] [Some vari­ant of, peo­ple are forced to say that they don’t see bugs by their bosses]

Crazy anec­dote from @danluu.com here and I wish he’d been even blunter at the time and asked this per­son where they’d got­ten this be­lief about Blackboard be­ing liked by any­one at all. User sur­veys? Principal (as in, not agent) sur­veys? Inner con­vic­tion??? [screenshot of Blackboard anecodote]

[Some vari­ant of, peo­ple are forced to say that they don’t see bugs by their bosses]

I don’t thnk this is con­sis­tent with any of the ma­jor ex­am­ples in the post, let alone all of them. Consider the Blackboard ex­am­ple men­tioned above. It’s un­likely that I and other peo­ple this Blackboard em­ployee are secret shop­pers” who are check­ing in on em­ploy­ees, and the em­ploy­ee’s re­ac­tion is clearly ab­surd to any­one who is­n’t such a hy­po­thet­i­cal (and in re­al­ity, non-ex­is­tent) se­cret shop­per, so re­act­ing like this just makes them look a bit silly in the eyes of a large frac­tion of the peo­ple they meet for no ben­e­fit (for ex­am­ple, see the pre­vi­ous quote, which seems like a typ­i­cal in­ter­nal re­ac­tion). Perhaps a few very para­noid em­ploy­ees would main­tain this front on the off chance they run into some friend or rel­a­tive of the boss who knows that they work for the com­pany who re­lays the story back and they have a boss who would care about this, but it’s just not plau­si­ble that this is (for ex­am­ple) the case for every Discourse em­ployee who reached out to me to ex­plain to me that Discource per­for­mance is re­ally good.

If we look at the bas­ket­ball ex­am­ple, this is even more ab­surd. You could pos­si­bly come up with some kind of rea­son­ing like, other fans would shun you if you did­n’t be­lieve or pre­tend to be­lieve the most ab­surd ra­tio­nal­iza­tion, but as some­one who has spent a lot of time around sports fans, I’ve gen­er­ally not found this to be the case. And, to the min­i­mal ex­tent to which this is kinda sorta the case, it’s more an is­sue of self se­lec­tion, where fans who are into the most ex­treme ra­tio­nal­iza­tions will spend more time around fans who are into the most ex­terme ra­tio­nal­iza­tions and fans who are less into these ex­treme ra­tio­nal­izaitons will tend to spend more time with fans who are less into them.

Also, just look­ing at the ca­reer path of peo­ple who don’t buy into these things and fix them, notic­ing these is­sues and fix­ing them has gone very well for those peo­ple. Pretending these is­sues don’t ex­ist (whether that’s at a con­cious level or not) also seems to work well, so I don’t know that fix­ing these is­sues is ac­tu­ally a bet­ter ca­reer path, but it’s cer­tainly not so bad that, in gen­eral, there’s mean­ing­ful ca­reer pres­sure to pre­tend these things don’t ex­ist over­all even if there are some in­di­vid­ual po­si­tions where there’s some di­rect pres­sure to pre­tend these is­sues aren’t real.

Daniel Gibson:

Who else uses the Shift key to end the screen­saver, be­cause in case the event goes through to an ac­tual pro­gram it’s least likely to do have un­in­tended ef­fects?

Who else uses the Shift key to end the screen­saver, be­cause in case the event goes through to an ac­tual pro­gram it’s least likely to do have un­in­tended ef­fects?

This re­minds me of how, when I want to send a queued mes­sage to codex im­me­di­ately and in­ter­rupt the cur­rent tool call, I put my fin­ger on the key and the press as quickly as pos­si­ble to re­duce the win­dow of time where the tool call will fin­ish and the es­cape key will stop codex en­tirely in­stead of caus­ing the mes­sage to send. I should prob­a­bly just run a patched ver­sion of codex that has fixes for this and a few other is­sues I’ve run into, but I’m al­ready do­ing things like try­ing out some weird work­load-spe­cific op­ti­mized ver­sion of rip­grep that also has an added na­tive code com­piler which com­piles match­ing ex­pres­sions in an­other thread while the search starts and then cuts over af­ter com­pi­la­tion com­pletes, so it’s not like I’m against cre­at­ing weird patches to im­prove my work­flow and it’s more of an is­sue of over­all band­width (no doubt, on writ­ing this, some­one will tell me that I could just hit an­other key in­stead and could’ve found this out by ask­ing codex about the key in the time it took me to write this com­ment). Just like with Google Docs, I con­sider codex above av­er­age in terms of soft­ware qual­ity in the space, but even though I haven’t been us­ing it for a year, I could eas­ily write 10k words on all the workarounds I’ve im­ple­mented (either by habit or, in some cases, with ac­tual scripts that mon­i­tor for bro­ken be­hav­ior and then cor­rect it).

some­one told me the re­sults did­n’t re­pro­duce on Google when they tried it some num­ber of weeks later. Of course it did­n’t, which I dis­cussed here in more de­tail, but for the short of it, here’s this post about scams and other bad re­sults on Google that was #1 on HN for a while. Of course some­body fixed that! And, also, ad re­sults are non-de­ter­min­is­tic and, while there are a lot of bad ads, it’s not like the ma­jor­ity are scams, so you would­n’t ex­pect to get scam ads at the top re­sults even if some­one else did for the same query. [return]

For ex­am­ple, any­one fa­mil­iar with my code at Twitter will re­call the huge com­ments I had at the top of the main files for the things I owned, which de­scribed the var­i­ous ways in which the thing is re­ally flawed. They were all things that, for one rea­son or an­other, I thought weren’t worth the time to fix, but they were still se­ri­ous prob­lems that any­one in­ter­act­ing with the code ought to know about. For this met­rics pro­ject, I even had a long doc that de­scribed the is­sues in great de­tail (IIRC, in a lot of cases, the rough shape of the fix was de­scribed; maybe to­day an LLM could take that and fix it). I have the same feel­ing about my writ­ing. While a huge num­ber of bugs sneak through my writ­ing (like spelling and gram­mat­i­cal er­rors), most of those are things I sort of don’t care about and will skim past in other peo­ple’s writ­ing as well. When I say don’t care, it’s not that I don’t want things to be bet­ter (when peo­ple send me cor­rec­tions I gen­er­ally fix things), it’s just that my brain does­n’t nat­u­rally pay at­ten­tion to those things no mat­ter whose writ­ing it is, so I don’t seem to have a par­tic­u­lar blind spot in my writ­ing with re­spect to these kinds of bugs. For the things I do care about, I could edit posts end­lessly be­cause, no mat­ter how much I edit, the post still seems pretty bad to me. I used to of­ten (and still some­times) send a post to some­one and ask them if it makes any sense to pub­lish it at all be­cause I gen­er­ally don’t like my out­put and, if I’m just look­ing at my own writ­ing, I don’t think it’s worth pub­lish­ing. At this point, I’ve done this enough that I’ll of­ten just pub­lish even though I don’t like what I wrote, but if some­one says how would you like it if some­one told you your work was­n’t good?” as a kind of gotcha”, boy, they re­ally have no idea how I think about my work. There are var­i­ous tricks I’ve used to get around this (not ex­plic­itly to get around this, but they do so as a side ef­fect). As dis­cussed in this old post on writ­ing, for a while, I hired a pro­fes­sional ed­i­tor and had a process goal of do­ing one pass on each post and then try­ing to im­prove the next post. And as noted in the post­script to re­cent posts, now I’m try­ing to write with ex­tremely min­i­mal cleanup and edit­ing and push posts out in half an hour re­gard­less of the state of the data I’m look­ing at or the post (which I’m gen­er­ally fail­ing to do; I thought I might suc­ceed on this one be­cause it does­n’t have any data analy­sis, but some­one made a com­ment on the draft post that got me to re-write the whole thing, and just on num­ber of words in the post, half an hour would re­ally be push­ing it on the orig­i­nal and then it in­creased in length). Of course a post that’s writ­ten as quickly as pos­si­ble with lit­tle to no re­gard for clean­ing things up is go­ing to be ter­ri­ble in all kinds of ways, so all flaws I see in the post don’t stop me from pub­lish­ing it. Have my re­cent posts been good? Of course not; for any of the ex­per­i­men­tal/​data posts, I could prob­a­bly name ten things that should be fixed about each of them off the top of my head. For this post, I’d have to re-read it to come up with ten things, but I’m sure if I did re-read it I’d want to re-write the whole thing be­cause of the is­sues it has. [return]

For ex­am­ple, any­one fa­mil­iar with my code at Twitter will re­call the huge com­ments I had at the top of the main files for the things I owned, which de­scribed the var­i­ous ways in which the thing is re­ally flawed. They were all things that, for one rea­son or an­other, I thought weren’t worth the time to fix, but they were still se­ri­ous prob­lems that any­one in­ter­act­ing with the code ought to know about. For this met­rics pro­ject, I even had a long doc that de­scribed the is­sues in great de­tail (IIRC, in a lot of cases, the rough shape of the fix was de­scribed; maybe to­day an LLM could take that and fix it).

I have the same feel­ing about my writ­ing. While a huge num­ber of bugs sneak through my writ­ing (like spelling and gram­mat­i­cal er­rors), most of those are things I sort of don’t care about and will skim past in other peo­ple’s writ­ing as well. When I say don’t care, it’s not that I don’t want things to be bet­ter (when peo­ple send me cor­rec­tions I gen­er­ally fix things), it’s just that my brain does­n’t nat­u­rally pay at­ten­tion to those things no mat­ter whose writ­ing it is, so I don’t seem to have a par­tic­u­lar blind spot in my writ­ing with re­spect to these kinds of bugs. For the things I do care about, I could edit posts end­lessly be­cause, no mat­ter how much I edit, the post still seems pretty bad to me.

I used to of­ten (and still some­times) send a post to some­one and ask them if it makes any sense to pub­lish it at all be­cause I gen­er­ally don’t like my out­put and, if I’m just look­ing at my own writ­ing, I don’t think it’s worth pub­lish­ing. At this point, I’ve done this enough that I’ll of­ten just pub­lish even though I don’t like what I wrote, but if some­one says how would you like it if some­one told you your work was­n’t good?” as a kind of gotcha”, boy, they re­ally have no idea how I think about my work.

There are var­i­ous tricks I’ve used to get around this (not ex­plic­itly to get around this, but they do so as a side ef­fect). As dis­cussed in this old post on writ­ing, for a while, I hired a pro­fes­sional ed­i­tor and had a process goal of do­ing one pass on each post and then try­ing to im­prove the next post. And as noted in the post­script to re­cent posts, now I’m try­ing to write with ex­tremely min­i­mal cleanup and edit­ing and push posts out in half an hour re­gard­less of the state of the data I’m look­ing at or the post (which I’m gen­er­ally fail­ing to do; I thought I might suc­ceed on this one be­cause it does­n’t have any data analy­sis, but some­one made a com­ment on the draft post that got me to re-write the whole thing, and just on num­ber of words in the post, half an hour would re­ally be push­ing it on the orig­i­nal and then it in­creased in length). Of course a post that’s writ­ten as quickly as pos­si­ble with lit­tle to no re­gard for clean­ing things up is go­ing to be ter­ri­ble in all kinds of ways, so all flaws I see in the post don’t stop me from pub­lish­ing it. Have my re­cent posts been good? Of course not; for any of the ex­per­i­men­tal/​data posts, I could prob­a­bly name ten things that should be fixed about each of them off the top of my head. For this post, I’d have to re-read it to come up with ten things, but I’m sure if I did re-read it I’d want to re-write the whole thing be­cause of the is­sues it has.

This was, in­ad­ver­tently, a kind of re­venge on my friend for when I tried to open his door for the first time to leave his place. Since the door clearly opened to the out­side, I tried push­ing on the door, which did­n’t work, so I checked if there was a latch that was stuck, if the door was still locked, if I needed to push harder, etc., none of which worked. When he saw that I could­n’t open the door I asked him what the trick was he said, in a tone of voice that made it sound like this was ob­vi­ously some­thing every­one should know, you need to pull the door be­fore push­ing it. The door was wedged such that the eas­i­est way to open the door was to pull the door as tightly shut as pos­si­ble and then im­me­di­ately shove the door open. This friend, since he grew up in that house, thought this was ob­vi­ous, ap­par­ently not re­al­iz­ing that it’s not nor­mal to have to try to close a door ex­tra hard to open it. [return]

a re­sponse I’ve heard to this kind of thing re­cently is that Anthropic had the best growth num­bers in his­tory while Claude was very buggy. If you have the best cod­ing model and agent in the world, you can get away with a lot, but even they seem to have spent a fair amount of ef­fort im­prov­ing qual­ity. Maybe you can also get away with it if you have a prod­uct that suc­ceeds due to bundling, the strength of your en­ter­prise sales team, net­work ef­fects, mo­nop­oly power, etc.; all but one of the cases I’m think­ing of are places where the team did­n’t have these things on their side. I ac­tu­ally thought the one other case I was think­ing of would be some­thing like Blackboard, but (if the Google re­sults are ac­cu­rate) I see that the soft­ware has de­clined from be­ing #1 in the mar­ket to be­ing a mi­nor­ity player, so maybe they could­n’t get away with it ei­ther (I did­n’t look into the rea­sons for the de­cline; per­haps it’s a co­in­ci­dence). As noted above, Blackboard is an ex­am­ple where you could ar­gue that the soft­ware qual­ity did­n’t mat­ter and peo­ple might as well just be­lieve what­ever makes them happy; if think­ing that users love the soft­ware, then why not think that? But most of the rest of the ex­am­ples that come to mind for me aren’t cases like that. I don’t think this is the best ex­am­ple, but it comes to mind be­cause the com­ment be­low is the last time I was re­minded of the Blackboard ex­am­ple. There was a com­ment from a Tumblr em­ployee who said that they’d solved the mod­er­a­tion (abuse / spam / tox­i­c­ity / etc.) prob­lem me­chan­i­cally at Tumblr via the way re­blogs worked and that the me­chan­ics Tumblr pro­vided to users were good enough that the com­mu­nity could self-po­lice bad be­hav­ior and that other so­cial me­dia sites would do well to learn from Tumblr. This was re­fer­ring to Tumblr back in its hey­day (maybe 2009 – 2014). I never re­ally read much on Tumblr so I don’t per­son­ally have an opin­ion, but back when it was a ma­jor so­cial me­dia plat­form, the rep­u­ta­tion among folks I know was that it was heavy on bad be­hav­ior, par­tic­u­larly pile-ons caused by peo­ple tak­ing out of con­text quotes and turn­ing them into rage­bait (not to say this does­n’t hap­pen on other plat­forms, but the be­lief was that the way Tumblr was struc­tured and/​or the com­mu­ni­ties in­volved made this worse on Tumblr). I’m not sure I know any­one who used Tumblr at the time who would say that the com­mu­nity was good at self-polic­ing. In fact, when Scott Alexander wrote one of his most fa­mous pieces, Toxoplasma Of Rage, he ded­i­cated an en­tire sec­tion to how Tumblr’s re­blog sys­tem is par­tic­u­larly bad and is guar­an­teed to re­sult in bad be­hav­ior. He ac­tu­ally says that who­ever de­signed the sys­tem ei­ther did­n’t un­der­stand what they were do­ing or they un­der­stood all too well and de­lib­er­ately made the most rage­bait-in­duc­ing sys­tem pos­si­ble. This was writ­ten dur­ing the time when this em­ployee said that Tumblr had solved the mod­er­a­tion prob­lem and uses ex­am­ples from that time. Moderation at scale is an im­pos­si­bly hard prob­lem, so as a non-Tum­blr user, I’m not even sure that Tumblr did worse than other plat­forms given its size and growth rate, but I think you’d need some qual­ity blind­ness to think that Tumblr had solved the mod­er­a­tion prob­lem. I think the strongest pos­i­tive case you could plau­si­bly make would be some­thing like Tumblr was bet­ter than av­er­age, but many peo­ple had a worse than av­er­age ex­pe­ri­ence due to the com­mu­ni­ties they were in and some of these com­mu­ni­ties were un­usu­ally widely read and Tumblr there­fore un­fairly gained a rep­u­ta­tion as be­ing a par­tic­u­larly bad plat­form”. I don’t know if that’s true or not, but it does­n’t seem im­pos­si­ble that it could be true; it does seem im­pos­si­ble that Tumblr solved the mod­er­a­tion prob­lem. [return]

a re­sponse I’ve heard to this kind of thing re­cently is that Anthropic had the best growth num­bers in his­tory while Claude was very buggy. If you have the best cod­ing model and agent in the world, you can get away with a lot, but even they seem to have spent a fair amount of ef­fort im­prov­ing qual­ity.

Maybe you can also get away with it if you have a prod­uct that suc­ceeds due to bundling, the strength of your en­ter­prise sales team, net­work ef­fects, mo­nop­oly power, etc.; all but one of the cases I’m think­ing of are places where the team did­n’t have these things on their side. I ac­tu­ally thought the one other case I was think­ing of would be some­thing like Blackboard, but (if the Google re­sults are ac­cu­rate) I see that the soft­ware has de­clined from be­ing #1 in the mar­ket to be­ing a mi­nor­ity player, so maybe they could­n’t get away with it ei­ther (I did­n’t look into the rea­sons for the de­cline; per­haps it’s a co­in­ci­dence).

As noted above, Blackboard is an ex­am­ple where you could ar­gue that the soft­ware qual­ity did­n’t mat­ter and peo­ple might as well just be­lieve what­ever makes them happy; if think­ing that users love the soft­ware, then why not think that? But most of the rest of the ex­am­ples that come to mind for me aren’t cases like that. I don’t think this is the best ex­am­ple, but it comes to mind be­cause the com­ment be­low is the last time I was re­minded of the Blackboard ex­am­ple. There was a com­ment from a Tumblr em­ployee who said that they’d solved the mod­er­a­tion (abuse / spam / tox­i­c­ity / etc.) prob­lem me­chan­i­cally at Tumblr via the way re­blogs worked and that the me­chan­ics Tumblr pro­vided to users were good enough that the com­mu­nity could self-po­lice bad be­hav­ior and that other so­cial me­dia sites would do well to learn from Tumblr. This was re­fer­ring to Tumblr back in its hey­day (maybe 2009 – 2014). I never re­ally read much on Tumblr so I don’t per­son­ally have an opin­ion, but back when it was a ma­jor so­cial me­dia plat­form, the rep­u­ta­tion among folks I know was that it was heavy on bad be­hav­ior, par­tic­u­larly pile-ons caused by peo­ple tak­ing out of con­text quotes and turn­ing them into rage­bait (not to say this does­n’t hap­pen on other plat­forms, but the be­lief was that the way Tumblr was struc­tured and/​or the com­mu­ni­ties in­volved made this worse on Tumblr). I’m not sure I know any­one who used Tumblr at the time who would say that the com­mu­nity was good at self-polic­ing. In fact, when Scott Alexander wrote one of his most fa­mous pieces, Toxoplasma Of Rage, he ded­i­cated an en­tire sec­tion to how Tumblr’s re­blog sys­tem is par­tic­u­larly bad and is guar­an­teed to re­sult in bad be­hav­ior. He ac­tu­ally says that who­ever de­signed the sys­tem ei­ther did­n’t un­der­stand what they were do­ing or they un­der­stood all too well and de­lib­er­ately made the most rage­bait-in­duc­ing sys­tem pos­si­ble. This was writ­ten dur­ing the time when this em­ployee said that Tumblr had solved the mod­er­a­tion prob­lem and uses ex­am­ples from that time.

Moderation at scale is an im­pos­si­bly hard prob­lem, so as a non-Tum­blr user, I’m not even sure that Tumblr did worse than other plat­forms given its size and growth rate, but I think you’d need some qual­ity blind­ness to think that Tumblr had solved the mod­er­a­tion prob­lem. I think the strongest pos­i­tive case you could plau­si­bly make would be some­thing like Tumblr was bet­ter than av­er­age, but many peo­ple had a worse than av­er­age ex­pe­ri­ence due to the com­mu­ni­ties they were in and some of these com­mu­ni­ties were un­usu­ally widely read and Tumblr there­fore un­fairly gained a rep­u­ta­tion as be­ing a par­tic­u­larly bad plat­form”. I don’t know if that’s true or not, but it does­n’t seem im­pos­si­ble that it could be true; it does seem im­pos­si­ble that Tumblr solved the mod­er­a­tion prob­lem.

most of my pro­jects are de­lib­er­ately low qual­ity; what I try to do is do the high­est ROI test­ing, not test to the point the qual­ity is what I would ac­tu­ally con­sider good, and this also goes for things like mak­ing in­ter­faces very nice, etc. [return]

Creepy crawlies

people.kernel.org

You’ve prob­a­bly heard me com­plain about the AI crawlers” be­fore, but now I ac­tu­ally have some hard num­bers I can put up to show their im­pact. In a few words, it’s bad enough to cre­ate a con­stant background ra­di­a­tion” of sys­tem load, per­ma­nently ty­ing up a chunk of ca­pac­ity spent on pro­duc­ing out­put that is only use­ful for a sin­gle pur­pose — feed­ing a learn­ing model.

TL;DR: we spend more CPU cy­cles ren­der­ing com­mits for scrap­ers than we spend on all other kinds of le­git­i­mate ac­cess, in­clud­ing git clones. At any one time, across 5 geo-dis­trib­uted nodes, there are 14 CPU cores do­ing noth­ing but ren­der­ing git com­mits as html.

Why is git.ker­nel.org interesting” to crawlers

Linux de­vel­op­ment hap­pens in the open — from git repos­i­to­ries you can clone, to dis­cus­sion archives you can fol­low in real time. To a large lan­guage model, this is a gold­mine of learn­ing data, be­cause all of this is not only im­me­di­ately avail­able, but is easy to fil­ter in or­der to guar­an­tee pure unadul­ter­ated pre-AI con­tent. Training an LLM on con­tent pro­duced by the LLM gives it the equiv­a­lent of a dig­i­tal prion dis­ease, so when a source is guar­an­teed to be LLM-free, like the en­tire his­tory of ker­nel com­mits, it’s worth its weight in gold as a source of train­ing data.

The stu­pid­est way of do­ing it

We make al­most every­thing clon­able, be­cause hey — we may not be around for­ever, so here — clone the re­pos. Also, clone the archives. Grab a copy just so we’re not the only ones who have it all. Seriously, it’s just a git clone” away — and then you’ll have the whole his­tory.

For ex­am­ple, did you know you can clone the en­tirety of LKML and then do what­ever you want with it? It’s just git re­pos all the way down.

So, you’d think that some­thing that pre­tends to be Artificial Intelligence” would use the most ef­fi­cient way of us­ing our data for train­ing pur­poses, right? Clone the re­pos, walk every com­mit. Done.

But no, let’s in fact choose the stu­pid­est pos­si­ble way of do­ing it — by ren­der­ing every­thing as HTML com­mit by com­mit and then pars­ing it.

At the time of writ­ing, linux.git is about 1.48 mil­lion com­mits. Oh, and we have about 922 forks of it on git.ker­nel.org — but don’t worry, it’s ac­tu­ally ex­tremely ef­fi­cient on the back­end, since it’s mostly the same ob­jects in every fork.

Unless, of course, you’re a scraper, in which case you have, oh, sev­eral BILLION valid URLs you can scrape, only to get 922 du­pli­cates of the same 1.48 mil­lion com­mits — which is ex­actly what the scrap­ers are do­ing.

But wait, it’s not just com­mits it­self. You can also ask for patches, plain ren­ders, diffs be­tween ar­bi­trary com­mits — cgit is happy to let you, which was per­fect for the times when the Internet was for hu­mans or crawlers who obeyed ro­bots.txt, and is AWFUL right about now, be­cause we can gen­er­ate 1.2 METRIC BAJILLION valid URLs just for a sin­gle fork of linux.git.

Block them

Initially, this was the so­lu­tion — look through the logs, find out which IPs are ob­vi­ous scraper bots, and fail2ban them. At first, this was easy, be­cause the bots help­fully told you who they were via their user-agent. Then, they wised up and started pre­tend­ing that they were ran­dom vanilla browsers.

So, we started ban­ning them by IP — af­ter all, it’s easy to fig­ure out that an IP that is try­ing to grab every pos­si­ble com­mit in a 8-year-old aban­doned fork of linux is not re­ally some lone Chrome on Windows user who is just fu­ri­ously click­ing every link that comes across their screen.

The bots then started fan­ning out to en­tire sub­nets, but this was still meh, be­cause ob­vi­ously an IP com­ing from Google Compute is just pre­tend­ing to be a Firefox user. Banning the whole ASN was jus­ti­fied, even if this oc­ca­sion­ally caught a ran­dom le­git­i­mate in­stance try­ing to au­to­mate link check­ing in com­mits.

Enter… your TV?

And… that’s when things turned re­ally, re­ally ugly. Suddenly, the crawlers were com­ing from mil­lions of ran­dom res­i­den­tial or mo­bile IPs, all pre­tend­ing to be ran­dom mod­ern browsers. An IP like that would make 4 – 5 re­quests and then never show up in the logs again. There was no point in ban­ning them, be­cause by the time you fig­ured out that they were bots, they were al­ready done with you. You just need­lessly bal­looned your fire­wall rule­set by adding IPs that would never be back.

They de­scended like swarms of lo­cust, hit hard and fast un­til the sys­tem fell over and then moved on to the next tar­get un­til you re­cov­ered. Then, they re­turned. Rinse. Repeat.

They still do that — wel­come to the won­der­ful world of proxy SDK mon­e­ti­za­tion.” It’s big busi­ness, and your TV is prob­a­bly do­ing it.

Make them pay

When this first be­came a prob­lem, oh, about a year ago, we naively thought that there was a way to make it stop. Just make the bots per­form a task that would flip the econ­omy of the whole thing up­side-down by mak­ing them burn some cy­cles do­ing throw­away math. Like, cal­cu­late what string, when com­bined with their own IP and a se­cret we pro­vide, would gen­er­ate a sha256 sum with 4 lead­ing ze­roes.

In other words, we put Anubis in front of every­thing.

It was im­me­di­ately ex­tremely ef­fec­tive — the bots just gave up. For a few months, it was bliss: bots were blocked at the perime­ter and gave up, mov­ing on to eas­ier tar­gets; the users were mildly an­noyed but tol­er­ated it, and the Anubis stack was easy enough to de­ploy every­where.

A few months later, the bots were back, solv­ing dif­fi­culty 4. No prob­lem, we said, let’s raise dif­fi­culty to 5.

The le­git­i­mate users were more an­noyed now. Difficulty 5 takes a few sec­onds to solve on a mo­bile de­vice, and the phone gets un­com­fort­ably warm as it’s do­ing the num­ber crunch­ing. However, it was ef­fec­tive and bought us a few more months of peace.

Then… the bots started solv­ing dif­fi­culty 5.

Where we are now

Today, git.ker­nel.org re­ceives about 6M daily re­quests de­mand­ing to see ran­dom com­mits. Of these, 66% are still im­me­di­ately bat­ted away with the Anubis chal­lenge, but 33% are now solv­ing the math and get­ting through to the main site — be­cause ap­par­ently what we have to of­fer is worth spend­ing a ton of cy­cles to cal­cu­late the Anubis chal­lenge.

It’s im­pos­si­ble to tell with cer­tainty which of these are bots and which are real hu­mans — but chances are, if it’s ask­ing for an old com­mit in a ran­dom old fork, it’s prob­a­bly not a real de­vel­oper try­ing to do their work.

With a bunch of gen­er­ous as­sump­tions, le­git­i­mate re­quests are only about 2% of git.ker­nel.org traf­fic — every­thing else are scrap­ers.

How bad is it?

At this point, we’re not quite over­whelmed — if you visit git.ker­nel.org, it will likely be snappy and re­spon­sive. The thing that usu­ally takes us down are not scraper bots, but poorly de­signed CI sys­tems that try to do some­thing stu­pid like shal­low-clone sta­ble.git from 20 dif­fer­ent nodes, all at the same time. (Shallow clones are aw­ful. Run your own damn mir­ror if you’re go­ing to do some­thing nasty like that.)

However, you should know that out of the to­tal of the 90 cores across 5 geo-dis­trib­uted nodes, there are 14 – 16 cores that are con­stantly do­ing noth­ing but ren­der­ing com­mits for scrap­ers. On av­er­age, that’s 20% of our en­tire ca­pac­ity — ex­cept the swarms de­scend in waves and the ac­tual graph is a lot more spiky than a 20% flat­line.

Where does that leave us?

Unclear. Maybe the AI bub­ble bursts and we sud­denly have a lot fewer en­ti­ties out there try­ing to train their mod­els. Alternatively, maybe they smarten up and stop con­sum­ing our data in the dumb­est way pos­si­ble.

In terms of what we’re do­ing, we’re turn­ing off fea­tures to re­duce the num­ber of crawlable URLs and to gate off ac­tions that are ex­pen­sive for us to run. Expect to lose some func­tion­al­ity, at least when ac­cess­ing our re­sources anony­mously. Trust me, we hate it just as much as you, but at this point it’s a ne­ces­sity.

Worst of all, there are no sim­ple so­lu­tions to the prob­lem. Companies of­fer­ing cus­tom AI mod­els still pop up daily, all of them hun­gry for train­ing data. App mak­ers are still look­ing for ways to turn a profit, so they will con­tinue to turn your house­hold ap­pli­ances into at­tack vec­tors.

That said, we promise to still of­fer all of our data for down­load to any­one who asks. You just may have to jump through more hoops to get it.

Sorry. (Oblig. Canadian thing to say.)

Turns out Brits would quite like their private messages to stay private

www.theregister.com

se­cu­rity

Polling finds two-thirds don’t trust this gov­ern­ment, or any fu­ture one, with ac­cess to their en­crypted chats

Brits have de­liv­ered a fairly un­am­bigu­ous ver­dict on giv­ing the gov­ern­ment ac­cess to their en­crypted mes­sages: no, thanks.

New polling com­mis­sioned by the Center for Democracy & Technology (CDT) found that 93 per­cent of British adults be­lieve they have a right to pri­vate con­ver­sa­tions on­line, while 89 percent think no­body should be able to ac­cess their per­sonal mes­sages with­out a court or­der.

Perhaps more awk­wardly for Westminster, two-thirds said they would not trust ei­ther the cur­rent gov­ern­ment or any fu­ture one with the power to ac­cess en­crypted mes­sages.

REG AD

That dis­trust crosses po­lit­i­cal lines. Among peo­ple who voted in the 2024 gen­eral elec­tion, 58 percent of Labour vot­ers said they would­n’t trust any gov­ern­ment with the power, along­side 59 percent of Conservatives, 56 percent of Liberal Democrats, 69 percent of Greens and 75 percent of Reform vot­ers.

REG AD

Public First did the ask­ing, polling 2,000 British adults for CDT in April and weight­ing the re­sults to re­flect the wider pop­u­la­tion. The mar­gin of er­ror is 2.2 per­cent­age points.

The find­ings land as the UK gov­ern­men­t’s ap­petite for slurp­ing en­crypted data con­tin­ues to col­lide with the tech in­dus­try’s in­sis­tence that en­cryp­tion works best when no­body has a spare key ly­ing around.

That fight be­came par­tic­u­larly pub­lic when Apple with­drew Advanced Data Protection from UK users af­ter re­ceiv­ing a se­cret Technical Capability Notice (TCN) un­der the Investigatory Powers Act. Apple chal­lenged the or­der, and while the US gov­ern­ment later said Britain had with­drawn its de­mand for ac­cess to Americans’ en­crypted data, re­ports have since sug­gested an­other TCN was is­sued fo­cus­ing on British users.

Despite the in­ter­na­tional row, 55 percent of those polled had­n’t heard about the Apple no­tice at all. Once pre­sented with the idea, en­thu­si­asm re­mained thin.

Just 12 percent backed the gov­ern­ment be­ing able to se­cretly or­der com­pa­nies to pro­vide ac­cess to users’ in­for­ma­tion while pre­vent­ing those com­pa­nies from re­veal­ing the or­der. A third said the gov­ern­ment should­n’t have that power at all, while an­other 41 percent wanted greater trans­parency or par­lia­men­tary over­sight.

Nor were re­spon­dents par­tic­u­larly sold on sac­ri­fic­ing se­cu­rity for law en­force­ment. 53 percent said the se­cu­rity risks of ac­cess­ing en­crypted mes­sages out­weighed the ben­e­fits, com­pared with 28 percent who thought the ben­e­fits came out on top.

The rea­sons will sound fa­mil­iar to any­one who has fol­lowed the en­cryp­tion de­bate for more than five min­utes. 84 percent wor­ried that mech­a­nisms al­low­ing ac­cess to en­crypted mes­sages could in­tro­duce vul­ner­a­bil­i­ties for hack­ers and crim­i­nals, while 82 percent were con­cerned the pow­ers could be abused.

Knowing some­one might be watch­ing could also change how peo­ple be­have. 65 percent said they’d be­come more cau­tious about what they liked, shared or com­mented on, while 41 percent said they’d self-cen­sor crit­i­cism of pub­lic in­sti­tu­tions or gov­ern­ment of­fi­cials.

REG AD

CDT is not a dis­in­ter­ested ob­server: the dig­i­tal rights group cam­paigns for strong en­cryp­tion and com­mis­sioned the re­search as part of that work. The polling it­self, how­ever, was car­ried out in­de­pen­dently.

Commenting on the re­search, Jim Killock, ex­ec­u­tive di­rec­tor of Open Rights Group, said: The British pub­lic in­stinc­tively know that be­ing able to com­mu­ni­cate pri­vately is cru­cial to our in­di­vid­u­al­ity and to the sur­vival of a free and open so­ci­ety.

The gov­ern­ment per­sists with the myth that it can weaken en­cryp­tion to tar­get the bad guys only. Attacks on the se­cu­rity of our phones, se­cu­rity tools and mes­sag­ing apps harm us all and make our democ­racy weaker.”

None of this is likely to end Westminster’s long-run­ning pur­suit of en­crypted com­mu­ni­ca­tions. But if min­is­ters were hop­ing the pub­lic was en­thu­si­as­ti­cally be­hind them, the num­bers sug­gest oth­er­wise. ®

RISC-V is now officially supported by CPython! | Python Insider

blog.python.org

Over the last few months, I’ve been work­ing on im­prov­ing CPython’s sup­port for the RISC-V ar­chi­tec­ture, and I’m thrilled to an­nounce that RISC-V is now of­fi­cially sup­ported by CPython as a tier 3 plat­form! 🎉 🚀

What is RISC-V?

RISC-V is an open in­struc­tion set ar­chi­tec­ture (ISA). Importantly, un­like pro­pri­etary in­struc­tion sets (such as x86 and ARM), it is de­vel­oped as an open stan­dard and can be im­ple­mented by any­one.

Its ecosys­tem has grown con­sid­er­ably in re­cent years and is pro­jected to quadru­ple by 2032. With that growth, it’s in­creas­ingly im­por­tant that Python works re­li­ably on these plat­forms.

Getting here

This would not have been pos­si­ble with­out com­mu­nity con­tri­bu­tions. RISC-V sup­port in CPython has de­vel­oped over time with peo­ple test­ing on real hard­ware, fix­ing ar­chi­tec­ture-spe­cific is­sues, im­prov­ing build sup­port, re­port­ing bugs, and re­view­ing patches. That work is what has brought the plat­form to the point where it could be added to PEP 11.

A par­tic­u­larly im­por­tant part of this has been hav­ing re­li­able, on­go­ing test­ing on real RISC-V hard­ware. I’d like to thank the RISE Project for their sup­port. RISE has kindly pro­vided sev­eral RISC-V ma­chines for CPython, giv­ing us build­bots for test­ing as well as de­bug­ging ar­chi­tec­ture-spe­cific is­sues.

I’d es­pe­cially like to thank Ludovic Henry from the RISE Project, Furkan Onder, and Emma Smith, along with the many oth­ers who have con­tributed. Additionally, I’m per­son­ally grate­ful for the Sovereign Tech Agency, which through their amaz­ing fel­low­ship sup­ported my work on this.

What’s next?

While tier 3 sup­port is an im­por­tant mile­stone, there’s plenty more to do. We are cur­rently in­ves­ti­gat­ing how to im­prove our test­ing fur­ther by bring­ing RISC-V di­rectly into CPython’s CI, again kindly sup­ported by RISE with their RISE RISC-V Runners ini­tia­tive. This should give con­trib­u­tors faster feed­back than the build­bots (which usu­ally run af­ter a patch is merged) and would al­low us to catch RISC-V-specific prob­lems ear­lier.

In the long term, I’d also love to work to­wards pro­mot­ing RISC-V to tier 2 sup­port.

There are also op­por­tu­ni­ties to move be­yond sim­ply mak­ing CPython work on RISC-V. I’d like to ex­plore ar­chi­tec­ture-spe­cific op­ti­miza­tions to take bet­ter ad­van­tage of RISC-V ca­pa­bil­i­ties where do­ing so can im­prove CPython’s per­for­mance.

Importantly, we need peo­ple to use it and give us feed­back. If you have ac­cess to RISC-V hard­ware, please try build­ing and run­ning CPython, run your work­loads and test suites, and please let us know what breaks. Testing across dif­fer­ent RISC-V en­vi­ron­ments will help us make sup­port bet­ter for every­one!

CPython is also only one part of the Python ecosys­tem. Continued com­mu­nity work across pack­ages, com­pil­ers, tool­ing, and in­fra­struc­ture will be im­por­tant in mak­ing RISC-V an in­creas­ingly well-sup­ported plat­form for Python as a whole.

There’s a lot still to do, and I’m look­ing for­ward to con­tin­u­ing that work!

No AI Fridays

noaifridays.com

Why?

Study af­ter study shows that us­ing LLMs can cause you to ac­cu­mu­late cog­ni­tive debt, make you less en­gaged with your work, neg­a­tively im­pact your crit­i­cal think­ing abil­i­ties, and ham­per your skill for­ma­tion.

Constant use of AI cre­ates blind spots. When we of­fload de­ci­sion-mak­ing, we be­come un­aware of the trade-offs. You can use No AI Fridays to as­sess what’s ac­tu­ally hap­pen­ing and ret­ro­spect on the choices the AI made for you. Make sure the di­rec­tion it’s steer­ing you to­wards is still aligned with your per­sonal pref­er­ences and style.

If the pro­duc­tiv­ity gains from AI are so big, spend­ing one day a week to min­i­mize its down­sides should­n’t be a dif­fi­cult trade-off.

By de­fault­ing to AI we miss op­por­tu­ni­ties for good old au­toma­tion. One day a week with­out to­kens can lead to sig­nif­i­cant to­ken us­age re­duc­tion over the long term.

If that’s still not enough for you, try to re­mem­ber when cod­ing was fun—how it felt to en­ter a flow state and de­liver cool stuff you were gen­uinely con­nected to and proud of.

How?

Just send this link to who­ever is the boss at your shop and ask them if you can do it. The ba­sic setup is sim­ple: turn off your AI as­sis­tants for the day, write code with your own hands, read the doc­u­men­ta­tion, and think things through your­self.

Who?

For now, as the CEO of HTMX, I’ve man­dated No AI Fridays.

htmx

If you want your com­pany to be added to the list, just ping me at @lazilyevaluated and I will add you.

FAQ

How do I con­vince my boss to do No AI Fridays at my shop?

Just send them a link to this web­site.

Can I still use grep­tile, pre­lint, etc.?

These are ac­tu­ally awe­some when used with hand­crafted code—they give you feed­back that you can learn from. Your LLM is not learn­ing shit from their feed­back, but you can.

Can I do more than one day per week?

Sure, de­pend­ing on how and what you do, you may find your bal­ance with up to 7 days with­out AI.

Can I do less than one day per week?

You are push­ing it, mate.

Can I just take a peek or two?

A cou­ple of shots of Claude or a pint of Codex is al­ways best when you try to quit, right?

Can I quit af­ter a cou­ple of weeks?

If quit­ting is what you like.

I have a ques­tion

Just send it to @lazilyevaluated.

To add this web app to your iOS home screen tap the share button and select "Add to the Home Screen".

10HN is also available as an iOS App

If you visit 10HN only rarely, check out the the best articles from the past week.

Visit pancik.com for more.