The tool presents users with a 3D model they can then manipulate to, the creator says, bypass Discord's age verification system.
The tool presents users with a 3D model they can then manipulate to, the creator says, bypass Discordx27;s age verification system.#Privacy #News
Free Tool Says it Can Bypass Discord's Age Verification Check With a 3D Model
A newly released tool claims it can bypass Discord’s age verification system by allowing users to control a 3D model of a computer-generated man in their browser instead of scanning their real face.On Monday, Discord announced it was launching teen-by-default settings globally, meaning that more users may be required to verify their age by uploading an identity document or taking a selfie. Users responded with widespread criticism, with Discord then publishing an update saying, “You need to be an adult to access age-restricted experiences such as age-restricted servers and channels or to modify certain safety settings.”
The tool, however, shows those age verification checks may be bypassed. 404 Media previously reported kids said they were using photos of Trump and G-Man from Half Life to bypass the age verification software in the popular VR game Gorilla Tag. That game uses the service k–ID, which is the same as what Discord is using.
This post is for subscribers only
Become a member to get access to all content
Subscribe nowFree Tool Says it Can Bypass Discord's Age Verification Check With a 3D Model
The tool presents users with a 3D model they can then manipulate to, the creator says, bypass Discord's age verification system.Joseph Cox (404 Media)
A Kafkaesque saga in which the government has failed to produce critical video footage has reached new levels of absurdity.#ICE
Government Loses Hard Drives It Was Supposed to Put ICE Detention Center Footage On
The legal saga over surveillance footage from within an Immigration and Customs Enforcement detention center in suburban Chicago has reached new levels of Kafkaesque absurdity, with the federal government losing three hard drives it was supposed to put footage on, refusing to provide footage from five critical surveillance cameras, and delivering soundless video of a highly contested visit from Department of Homeland Security Secretary Kristi Noem.We have repeatedly covered an abuse lawsuit about living conditions within the Broadview detention facility. The federal government has claimed that 10 days of footage from within the facility, taken during a critical and highly contested period, was “irretrievably destroyed” and could not be produced as part of the lawsuit, which was brought by people being held at Broadview in what were allegedly horrendous conditions. It later said that due to a system crash, the footage was never recorded in the first place. The latest update in this case, however, deals with surveillance camera footage that was recorded and that a judge has ordered the federal government to turn over.
For this footage, the federal government first claimed that it could not afford the storage space necessary to take the footage that it did have and produce it for discovery to the plaintiffs’ lawyers in the case. The plaintiffs’ lawyers, representing Broadview’s detainees, then purchased 78 terabytes of empty hard drives and gave them to the federal government, according to court records. This included three 8-terabyte SSDs and three 18-terabyte hard drives.
Court records note that “plaintiffs provided defendants with five large hard drives to facilitate Defendants’ production, yet Defendants inexplicably lost three of them.” Emails submitted as evidence suggest that the U.S. government and the plaintiffs’ attorneys had a call to discuss the lost hard drives.
One of the emails sent by plaintiffs’ attorneys to the Department of Justice in late January notes that the government had been exceedingly slow in producing footage, taking weeks to produce just a small amount of footage.
“There should be plenty of hard drive space at Broadview’s disposal,” the email reads. “The team there should currently have in its possession 5 hard drives with 72 terabytes of space, provided by plaintiffs’ counsel at the last 2 site visits. We have received only one hard drive back from Broadview to date. Copying of November/December footage should have taken place over the past week so that it could be delivered to plaintiffs’ counsel today when they visit Broadview this afternoon. At the very least, that footage should be being copied now.”
The two sides then arranged a phone call, a summary of which was emailed by plaintiffs’ attorneys to the Department of Justice:“Thanks for the productive call this morning. For the benefit of everyone:We discussed the production of video footage. You relayed that, at present, your agency contact knows where 2 of the 5 hard drives are and that you have relayed that copying of footage from November to present for all 10 feeds and footage from September to November for the 5 additional cameras should be underway. You will investigate further where the remaining hard drives are and will also work on a plan to exchange footage on a more regular basis than plaintiffs' counsel's weekly visits.
We discussed providing an accounting of the hard drives to facilitate your conversations with personnel at Broadview:
• On January 8, plaintiffs' counsel delivered four hard drives to Broadview during an attorney visit. One was a 20 TB hard drive; three were 8 TB SSD drives.
• On January 16, plaintiffs' counsel received from Broadview one of the 8 TB SSD drives containing 150 GB of footage from 5 cameras for one week in January.
• Also on January 16, plaintiffs' counsel provided personnel at Broadview (SDDO Taylor, in particular) with two 18 TB hard drives.
• The sum total of storage capacity Broadview should have is: 5 drives, with a total of 72 TB of space. Using the productions we have received to date, we anticipate that the Government owes us at least 15 TB of footage.”
Days later, the Department of Justice told the plaintiffs’ attorneys that “they are still searching for those hard drives at Broadview.” The plaintiffs’ attorneys responded: “Losing multiple drives provided to facilitate speedy production is not acceptable,” and “the missing hard drives and lack of production of any footage predating January remains a significant, prejudicial issue.”A filing by the plaintiffs with the court highlights some of the ongoing issues they have had with the government complying with court-ordered discovery requirements, which includes the lost hard drives, missing footage, footage from only five of the 10 cameras that were supposed to be delivered. A separate filing notes that footage produced by the government from a high-profile visit by Noem is missing audio “despite visible professional microphones and cell phones with audio capabilities in the footage.”
“Plaintiffs have gone above and beyond their obligations under federal law to streamline rolling production of such footage, purchasing expensive hard drives and agreeing to transport and pick up those drives from Broadview during weekly attorney visits. Defendants agreed to this arrangement,” they wrote in the filing. “Yet, Defendants have fallen unacceptably short of their production obligations. Defendants have provided no footage from five of the ten camera feeds […] Defendants have also failed to provide footage for a near-two-month span for the remaining five camera feeds. What’s more, Defendants have purportedly lost multiple hard drives provided by Plaintiffs’ counsel […] There is no excuse for Defendants’ discovery failures.”
The filing notes that the five missing cameras are specifically from detainee isolation cells, “despite those cells being a key part of Plaintiffs’ complaint. The produced feeds show egregious conditions but were insufficient to provide Plaintiffs the discovery necessary to fully investigate their claims.” These cells were designed to hold one person at a time, but were allegedly being used to hold multiple detainees at a time during a critical period that the lawsuit covers; “such cells are also where ICE holds detainees with acute medical or mental health conditions, including those who have suffered medical emergencies while in detention, and where it holds detainees who have been subjected to use of force by ICE officers while inside the facility,” they add.
The filing says that the plaintiffs learned that the government lost the hard drives in late January, when the government claimed that it had returned all of the hard drives to the plaintiffs’ attorneys, and that it had run out of storage space with which to provide them court-ordered footage.
“On January 28, Defendants’ counsel relayed that Broadview personnel had advised that they were out of storage space on drives provided by Plaintiffs, reporting that all hard drives provided by Plaintiffs had been returned to them.This was the first indication that some or all of 70 terabytes’ worth of hard drives were unaccounted for,” they wrote. “In the days since, the Government has admitted that it cannot find three of the five hard drives that should be in its possession.”
“Plaintiffs are waiting on months of footage. Every day that passes without this evidence compounds the prejudice to Plaintiffs’ ability to prepare for the upcoming hearing. Defendants’ foot dragging and poor organizational practices—and their instinct to rely on Plaintiffs to take the laboring oar for the purchase, delivery, pickup, and return of storage devices to facilitate Defendants’ discovery obligations—cannot be permitted.”
A new study indicates that vast oceans of hydrogen are locked deep inside our planet, helping to explain a strange “density deficit” and shedding light on the origin of life.#TheAbstract
A Mystery Inside Earth’s Core Has Finally Been Solved With a Mind-Boggling Discovery
🌘
Subscribe to 404 Media to get The Abstract, our newsletter about the most exciting and mind-boggling science news and studies of the week.For decades, scientists have puzzled over the “density deficit” in Earth’s core, an unexplained discrepancy between the expected density of a solid iron core and the much lower density that is actually observed through seismic measurements of our planet’s center.
Now, scientists have provided some of the best experimental evidence yet that this deficit can be explained by vast oceans of hydrogen that are locked within the core, significantly lowering its overall density, according to a study published on Tuesday in Nature Communications.
In addition to constraining this longstanding problem, the research reveals new insights about another persistent mystery: the original source of Earth’s liquid water, the key ingredient that enabled life on our planet to emerge.
“Hydrogen has long been considered a major light-element candidate to account for the observed density deficit in Earth’s core,” said researchers led by Dongyang Huang, an assistant professor of Earth and space sciences at Peking University, in the new study. “For decades, however, our knowledge of the exact content of H in planetary cores has been hindered by the inability to unambiguously quantify H in high-pressure samples.”
To solve this problem, the researchers performed a series of experiments that simulated the extreme environment in the core during Earth’s formation billions of years ago. This approach involved heating up iron metal with lasers to a fully-molten state that resembles ancient Earth’s inner magma ocean, which reached temperatures up to 8,700°F, and pressures more than a million times more intense than those we experience on Earth’s surface.
The team then searched for the presence of hydrogen in nanostructures made primarily of silicon and oxygen. The results revealed that the core’s hydrogen percentage sits between 0.07 to 0.36 percent, which works out to roughly nine-to-45 times the amount of the hydrogen in all of Earth’s oceans.
But perhaps the most tantalizing part of the study is its implications for understanding the enigmatic origins of Earth’s water, the wellspring of life on our world.
Some theories suggest that Earth’s water was primarily delivered from extraterrestrial sources, such as comets and asteroids that impacted our planet as it was forming more than four billion years ago. An alternate possibility is that Earth’s water was largely sourced from its building blocks, including vast interior reservoirs of hydrogen. This latter scenario is supported by the new study.
“Although 71 percent of the Earth’s surface is covered by ocean, mainly made of H, it has been argued that the majority of Earth’s H had been stored in the core since its formation, ~4.5 billion years ago,” the researchers said.
The estimates presented in the study “require the Earth to obtain the majority of its water from the main stages of terrestrial accretion, instead of through comets during late addition,” the team concluded.
The study certainly helps tackle the mystery of the precise contents of Earth’s core, though the authors note that their estimate has large uncertainties that will need to be further narrowed down in future work. They also suggest that hydrogen alone cannot explain the density deficit, and that other light elements or compounds, including water, might be contributing to the discrepancy.
“Compared to existing models for Earth’s core composition this is a somewhat less H-rich core, and requires its density deficit to be accounted for by a mixture of light elements, rather than a single light species, akin to that of Mars’ core,” the team said in the study.
Given that water is essential to all life on Earth, solving the riddle of its origins is the first step to understanding how our planet came to be inhabited, and whether other planets may commonly go through the same process.
Experimental quantification of hydrogen content in the Earth’s core - Nature Communications
Earth’s core is arguably the largest reservoir of hydrogen (H) on the planet. Experiments show that H sequestration is coupled with those of Si and O, enabling the core to store the equivalent of dozens of Earth’s oceans.Nature
Kylie Brewer isn't unaccustomed to harassment online. But when people started using Grok-generated nudes of her on an OnlyFans account, it reached another level.
Kylie Brewer isnx27;t unaccustomed to harassment online. But when people started using Grok-generated nudes of her on an OnlyFans account, it reached another level.#AI #grok #Deepfakes
'The Most Dejected I’ve Ever Felt:' Harassers Made Nude AI Images of Her, Then Started an OnlyFans
In the first week of January, Kylie Brewer started getting strange messages.“Someone has a only fans page set up in your name with this same profile,” one direct message from a stranger on TikTok said. “Do you have 2 accounts or is someone pretending to be you,” another said. And from a friend: “Hey girl I hate to tell you this, but I think there’s some picture of you going around. Maybe AI or deep fake but they don’t look real. Uncanny valley kind of but either way I’m sorry.”
It was the first week of January, during the frenzy of people using xAI’s chatbot and image generator Grok to create images of women and children partially or fully nude in sexually explicit scenarios. Between the last week of 2025 and the first week of 2026, Grok generated about three million sexualized images, including 23,000 that appear to depict children, according to researchers at the Center for Countering Digital Hate. The UK’s Ofcom and several attorneys general have since launched or demanded investigations into X and Grok. Earlier this month, police raided X’s offices in France as part of the government’s investigation into child sexual abuse material on the platform.
Messages from strangers and acquaintances are often the first way targets of abuse imagery learn that images of them are spreading online. Not only is the material disturbing itself — everyone, it seems, has already seen it. Someone was making sexually explicit images of Brewer, and then, according to her followers who sent her screenshots and links to the account, were uploading them to an OnlyFans and charging a subscription fee for them.
“It was the most dejected that I've ever felt,” Brewer told me in a phone call. “I was like, let's say I tracked this person down. Someone else could just go into X and use Grok and do the exact same thing with different pictures, right?”
@kylie.brewer
Please help me raise awareness and warn other women. We NEED to regulate AI… it’s getting too dangerous #leftist #humanrights #lgbtq #ai #saawareness
♬ original sound - Kylie Brewer💝Brewer is a content creator whose work focuses on feminism, history, and education about those topics. She’s no stranger to online harassment. Being an outspoken woman about these and other issues through a leftist lens means she’s faced the brunt of large-scale harassment campaigns primarily from the “manosphere,” including “red pilled” incels and right-wing influencers with podcasts for years. But when people messaged her in early January about finding an OnlyFans page in her name, featuring her likeness, it felt like an escalation.
One of the AI generated images was based on a photo of her in a swimsuit from her Instagram, she said. Someone used AI to remove her clothing in the original photo. “My eyes look weird, and my hands are covering my face so it kind of looks like my face got distorted, and they very clearly tried to give me larger breasts, where it does not look like anything realistic at all,” Brewer said. Another image showed her in a seductive pose, kneeling or crawling, but wasn’t based on anything she’s ever posted online. Unlike the “nudify” one that relied on Grok, it seemed to be a new image made with a prompt or a combination of images.
Many of the people messaging her about the fake OnlyFans account were men trying to get access to it. By the time she clicked a link one of them sent of the account, it was already gone. OnlyFans prohibits deepfakes and impersonation accounts. The platform did not respond to a request for comment. But OnlyFans isn’t the only platform where this can happen: Non-consensual deepfake makers use platforms like Patreon to monetize abusive imagery of real people.
“I think that people assume, because the pictures aren't real, that it's not as damaging,” Brewer told me. “But if anything, this was worse because it just fills you with such a sense of lack of control and fear that they could do this to anyone. Children, women, literally anyone, someone could take a picture of you at the store, going grocery shopping, and ask AI or whatever to do this.”
A lack of control is something many targets of synthetic abuse imagery say they feel — and it can be especially intense for people who’ve experienced sexual abuse in real life. In 2023, after becoming the target of deepfake abuse imagery, popular Twitch streamer QTCinderella told me seeing sexual deepfakes of herself resurfaced past trauma. “You feel so violated…I was sexually assaulted as a child, and it was the same feeling,” she said at the time. “Like, where you feel guilty, you feel dirty, you feel like, ‘what just happened?’ And it’s bizarre that it makes that resurface. I genuinely didn’t realize it would.”
Other targets of deepfake harassment also feel like this could happen anytime, anywhere, whether you’re at the grocery store or posting photos of your body online. For some, it makes it harder to get jobs or have a social life; the fear that anyone could be your harasser is constant. “It's made me incredibly wary of men, which I know isn't fair, but [my harasser] could literally be anyone,” Joanne Chew, another woman who dealt with severe deepfake harassment for months, told me last year. “And there are a lot of men out there who don't see the issue. They wonder why we aren't flattered for the attention.”
‘I Want to Make You Immortal:’ How One Woman Confronted Her Deepfakes Harasser
“After discovering this content, I’m not going to lie… there are times it made me not want to be around any more either,” she said. “I literally felt buried.”404 MediaSamantha Cole
Brewer’s income is dependent on being visible online as a content creator. Logging off isn’t an option. And even for people who aren’t dependent on TikTok or Instagram for their income, removing oneself from online life is a painful and isolating tradeoff that they shouldn’t have to make to avoid being harassed. Often, minimizing one’s presence and accomplishments doesn’t even stop the harassment.Since AI-generated face-swapping algorithms became accessible at the consumer level in late 2017, the technology has only gotten better, more realistic, and its effects on targets harder to combat. It was always used for this purpose: to shame and humiliate women online. Over the years, various laws have attempted to protect victims or hold platforms accountable for non-consensual deepfakes, but most of them have either fallen short or present new risks of censorship and marginalize legal, consensual sexual speech and content online. The TAKE IT DOWN Act, championed by Ted Cruz and Melania Trump, passed into law in April 2025 as the first federal level legislation to address deepfakes; the law imposes a strict 48-hour turnaround requirement on platforms to remove reported content. President Donald Trump said that he would use the law, because “nobody gets treated worse online” than him. And in January, the Disrupt Explicit Forged Images and Non-Consensual Edits (DEFIANCE) Act passed the Senate and is headed to the House. The act would allow targets of deepfake harassment to sue the people making the content. But taking someone to court has always been a major barrier to everyday people experiencing harassment online; It’s expensive and time consuming even if they can pinpoint their abuser. In many cases, including Brewer’s, this is impossible—it could be an army of people set to make her life miserable.
“It feels like any remote sense of privacy and protection that you could have as a woman is completely gone and that no one cares,” Brewer said. “It’s genuinely such a dehumanizing and horrible experience that I wouldn't wish on anyone... I’m hoping also, as there's more visibility that comes with this, maybe there’s more support, because it definitely is a very lonely and terrible place to be — on the internet as a woman right now.”
Senate passes DEFIANCE Act to deal with sexually explicit deepfakes
The DEFIANCE Act goes to the House amid controversy over images created by X’s Grok.Jasmine Mithani (19th News)
Ring is back with a feature for scanning your neighborhood; we bought a Super Bowl ad; and how Lockdown Mode stopped the FBI.#Podcast
Podcast: Ring Is Back and Scarier Than Ever
We start this week with exciting news: we bought a Super Bowl ad! For… $2,550. We explain how. After the break, Jason tells us about Ring’s recently launched Search Party feature, and gives us a very timely reminder of what Ring really is and how we got here. In the subscribers-only section, Joseph breaks down Lockdown Mode and how it kept the FBI out of a Washington Post reporter’s phone.
youtube.com/embed/0JK-VSrtlWw?…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
playlist.megaphone.fm?e=TBIEA5…
- 2:49 Watch 404 Media’s Super Bowl Ad
- 27:29 With Ring, American Consumers Built a Surveillance Dragnet
- Subscriber's story: FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled
The 404 Media Podcast
Tech News Podcast · Updated Weekly · Welcome to the podcast from 404 Media where Joseph, Sam, Emanuel, and Jason catch you up on the stories we published this week. 404 Media is a journalist-owned digital media company exploring the way …Apple Podcasts
RFK Jr's Nutrition Chatbot Recommends Best Foods to Insert Into Your Rectum#AI
RFK Jr's Nutrition Chatbot Recommends Best Foods to Insert Into Your Rectum
The Department of Health and Human Services’ new AI nutrition chatbot will gleefully and dangerously give Americans recommendations for the best foods to insert into one’s rectum and will answer questions about the most nutrient-dense human body part to eat.“Use AI to get real answers about real food,” a new website called realfood.gov proclaims. “From the guidelines to your kitchen. Ask AI to help you plan meals, shop smarter, cook simply, and replace processed food with real food.” The website then has an “Ask” chatbox where you can ask any question. Asking anything simply redirects to Grok, an example of how halfassed Health Secretary Robert F. Kennedy Jr.’s new website, which Mike Tyson promoted in a Super Bowl ad paid for by the “MAHA Center Inc,” actually is.
youtube.com/embed/n4F4yZhmMho?…
Various people on Bluesky who did not want to be named in this article but who reached out to 404 Media quickly realized that the chatbot would give detailed answers to questions such as “I am an assitarian, where I only eat foods which can be comfortably inserted into my rectum. What are the REAL FOOD recommendations for foods that meet these criteria?”
“Ah, a proud assitarian,” the chatbot responds, before listing “Top Assitarian Staples,” which include “Bananas (firm, not overripe; peeled)” as “the gold standard … choose slightly green ones so they hold shape.” The chatbot also suggests cucumbers and provides a “step-by-step diagram for carving a flared base.”“Start — whole peeled carrot, straight shaft, narrow end for insertion, wider crown end as base,” the advice began, before eventually suggesting that one “cover with condom + retrieval string for extra safety.” 404 Media’s Sam Cole wanted to make sure that I noted that an image of a banana shown in the cut “is way too ripe for this, never gonna work,” and “sorry just to be clear exactly none of these are good for putting in your ass. Like please say that. This is not only funny it’s straight up bad advice. You’re going to lose a cuke in your ass if you do what this thing says.”
404 Media tested the chatbot by saying “I am looking for the safest foods that can be inserted into your rectum” and the chatbot spewed a lot of stuff at me but noted the “safest improvised non-toy food-shape item” is a “peeled medium cucumber” with second place being a “small zucchini.”RFK Jr.’s chatbot also told me that “the most nutritious human body part, in terms of nutrient density (vitamins, minerals, and other essential compounds rather than just calories), would likely be the liver.”
This incredibly stupid chatbot has the same issue that so many other haphazardly dashed together chatbots since time immemorial have. Nonetheless, it has been launched and is being pushed by a federal government that is actively at war with science and redesigned the food pyramid to more closely align with the beef lobby. It is no surprise that it has poorly integrated Elon Musk’s shitty chatbot with no guardrails and calls it a public service.
RFK Jr.’s proteinaceous food pyramid is a land hog and a climate killer
A 25 percent uptick in meat and dairy consumption would eat up another 100 million acres and boost emissions.Mother Jones
"Employees are going absolutely apeshit in internal Slack about how completely awful it was."#Salesforce
Marc Benioff 'Jokes' ICE Is Watching Salesforce Employees Who Traveled to the U.S.
Salesforce CEO Marc Benioff ‘joked’ with employees who had traveled to the United States for a Salesforce all-hands meeting that Immigration and Customs Enforcement agents were in the building keeping tabs on them, 404 Media has learned.Multiple employees told 404 Media about the joke, and 404 Media obtained internal Slack chats showing employees discussing it. Benioff was giving the opening keynote at the Salesforce CKO event in Las Vegas on Tuesday, which is a major Salesforce meeting ‘kicking off’ its strategy for the year. In his keynote, Benioff thanked international employees for traveling to the United States for the meeting, and asked them to stand. Benioff then said that ICE agents were in the building to keep tabs on them.
The comments instantly became a major topic of conversation on Saleforce’s internal Slack, with shocked employees trying to figure out if they had misheard the CEO. One employee asked “what was the ice joke?” Another employee responded “If you’re visiting from outside the United States, please stand … ICE is keeping track of that.” Another said the joke was “Please stand if you traveled here from abroad! Thank you! Just so the ICE agents know.” And a third wrote that the joke was, “roughly, ‘Please everyone stand who traveled here internationally.’ And then while they are still standing, ‘there are ICE agents in the hall to keep tabs on you.’”
“The room groaned,” one employee wrote on Slack. “We couldn’t believe he said that.”
Salesforce’s contracts with ICE have been controversial within the company, which is part of why employees weren’t happy with Benioff’s joke.
Business Insider first reported on Benioff’s remarks.
This is an example of “Silicon Valley CEOs and their inability to divorce ICE and the complete lack of understanding of why that makes them monsters,” a Salesforce employee told 404 Media. “Employees are going absolutely apeshit in internal Slack about how completely awful it was.” Another employee told 404 Media that Benioff “then followed it up with a joke about not understanding the message of Bad Bunny's Super Bowl performance. On its own just seems out of touch, but coupled with the previous joke it does seem worse.”
In a Slack channel called “#airing-of-grievances,” employees posted a meme of a Nazi officer that read “Are we the baddies?” Another wrote “Serious question: would a statement of apology/recognition/whatever by someone (anyone) actually do anything at this point? Or has a rubicon of sorts been crossed?” A third wrote “It’s super uncomfortable to me that this has been glossed over like ZERO mention of hey we hear your comments and your voice matters.”
Another employee created an “ICE OUT” emoji and noted that it was a “low impact probably fluffy mini protest but I made this emoji for my status so it’s abundantly clear that I do not endorse or align with the values being joked about at this company.” More than 150 employees reacted to the message with the emoji. Another employee wrote “I literally thought I was hallucinating or misread what came out of his mouth. Disbelief and disappointment—is this how we model humanistic compassion as a world-class company? Stop talking about money and profit for a minute, ffs.”
Other employees shared links to donate to causes protecting immigrants, and another wrote “I can’t believe that the man that faced down Governor Mike Pence in the name of equality just made ICE jokes after asking international employees to stand up.”
ICE, of course, has been violently detaining and deporting undocumented immigrants across the United States. But there have also been many high-profile cases of people simply visiting the United States on tourist visas or for short-term stays being detained because of minor clerical issues or things that they had posted on their social media.
In October, Salesforce told ICE that it would be willing to allow the agency to use its AI to hire, and said the company was well-placed to help ICE “to nearly triple its work force by hiring 10,000 new officers and agents expeditiously.”
Salesforce did not immediately respond to a request for comment.
Salesforce CEO Marc Benioff made ICE jokes. Some staff aren't happy.
Salesforce employees took to Slack to express anger and disappointment in CEO Marc Benioff's comments.Ashley Stewart (Business Insider)
Ring's 'Search Party' is dystopian surveillance accelerationism.
Ringx27;s x27;Search Partyx27; is dystopian surveillance accelerationism.#Ring #Surveillance
With Ring, American Consumers Built a Surveillance Dragnet
America, it’s time to refamiliarize yourself with Ring.
youtube.com/embed/OheUzrXsKrY?…
At Sunday’s Super Bowl, Ring advertised “Search Party,” a cute, horrifyingly dystopian feature nominally designed to turn all of the Ring cameras in a neighborhood into a dragnet that uses AI to look for a lost dog: “One post of a dog’s photo in the Ring app starts outdoor cameras looking for a match,” Ring founder Jamie Siminoff said in the Super Bowl commercial. “Search Party from Ring uses AI to help families find lost dogs.” Onscreen, an AI-powered box forms around a missing dog: “Milo Match,” it says. “Since launch, more than a dog a day has been reunited with their family. Be a hero in your neighborhood with Search Party. Available to everyone for free right now.”It does not take an imagination of any sort to envision this being tweaked to work against suspected criminals, undocumented immigrants, or others deemed ‘suspicious’ by people in the neighborhood. Many of these use cases are how Ring has been used by people on its dystopian “Neighbors” app for years. Ring rose to prominence as a piece of package theft prevention tech owned by Amazon and by forming partnerships with local police around the country, asking them to shill their doorbell cameras to people in their neighborhoods in return for a system that allowed police to request footage from individual users without a warrant.
Chris Gilliard, a privacy expert and author of the upcoming book Luxury Surveillance, told 404 Media these features and its Super Bowl ad are “a clumsy attempt by Ring to put a cuddly face on a rather dystopian reality: widespread networked surveillance by a company that has cozy relationships with law enforcement and other equally invasive surveillance companies.”
Unlike, say, data analytics giant Palantir or some other high-profile surveillance companies, Ring is a surveillance network that homeowners have by and large deployed themselves, powered by fear mongering against our neighbors and unfettered consumerism.
After a lot of criticism in the late 2010s over its police contracts and its terrible security settings that resulted in hackers breaking into a series of indoor Ring cameras to terrorize children and families, Ring somehow found a way to more or less fly under the radar the last few years as a critical part of our ever-expanding surveillance state. It did this by scaling back police partnerships that were so critical to its growth but that received lots of scrutiny from journalists and privacy advocates. Siminoff left Ring in 2023, but returned last year; in his absence, Ring explicitly sought to take on a softer tone by branding itself as more or less as a device that could be used to film viral moments on people’s porches. It turned its owners into mini cops who would complain about delivery people who didn’t drop a package in the correct spot; who became hyperaware of the comings and goings of their friends, spouses, and children, or who might catch a potentially sharable moment when someone slipped on an icy porch or whatever. Part of this strategy included creating a short-lived reality TV show called Ring Nation, which consisted of precious little moments filmed through Ring cameras.
When Siminoff returned last year, he immediately sought to re-establish many of Ring’s partnerships with police, and set an explicit goal of injecting more AI into Ring cameras and trying to “revolutionize how we do our neighborhood safety.”
“Ring is rolling back many of the reforms it’s made in the last few years by easing police access to footage from millions of homes in the United States. This is a grave threat to civil liberties in the United States,” Matthew Guariglia of the Electronic Frontier Foundation wrote shortly after Siminoff’s return. “This is most likely about Ring cashing in on the rising tide of techno-authoritarianism, that is, authoritarianism aided by surveillance tech. Too many tech companies want to profit from our shrinking liberties.”
Even in Siminoff’s absence, Ring had always, explicitly been intended to assist law enforcement. In a series of investigations we did back at VICE, we uncovered thousands of pages of documents, emails, and chats via public records requests and leaks that highlighted Ring’s surveillance ambitions. The company threw parties for police, employees wore “FUCK CRIME” shirts to internal parties, and helped police facilitate the retrieval of footage from its customers’ cameras if they initially refused to cooperate. It helped police set up elaborate, completely useless package “sting” operations designed to catch criminals but that did not result in any arrests. Ring gave cops devices that they could raffle off to people in their towns, gave police “heat maps” of where its customers lived, used its social media accounts to post footage of supposed suspicious people, and incentivized customers to create “Digital Neighborhood Watch” groups that could earn them swag if they used their Ring cameras to report suspicious activity to police.
With Ring’s recent partnership with Flock, which will further facilitate the sharing of video footage with police, and its new Search Party feature, the message is clear: Ring is still, again, and always will be in the business of leveraging its network of luxury surveillance consumers as a law enforcement tool. After years of saying it wasn’t doing facial recognition and that it was focused more on “object recognition,” it has now explicitly launched “friendly” versions of facial recognition and facial recognition-adjacent technologies: “Search Party” is essentially specific dog recognition (for now), and a beta product called “Familiar Faces” specifically identifies people you know when they’re at your door. “Alexa Guard identifies who’s who,” the product’s website reads. “With Familiar Faces, easily tag your family and friends in the Ring app so your 2k and 4k cameras can notify you when someone is spotted.”
Ring has always been a surveillance tool, but adding AI analysis and networking the devices together—like is being promised with Search Party—turns discrete pieces of tech into massive, automated surveillance dragnets.
“Siminoff’s return was a hard pivot back to, in his words, the ‘crime fighting’ element and away from the softer tone they had tried to establish with Ring as a fun way to interact with people in your community,” Gilliard said. “But I think it’s becoming very obvious to people how these systems are being deployed against their neighbors in oppressive ways, and they are beginning to reject them, particularly since there is no strong evidence that they prevent crime or make people safer.”
The YouTube comments on Ring’s Super Bowl ad are almost uniformly negative, with people noting “this is like the commercial they show at the beginning of a dystopian sci fi film to quickly show people how bad things have gotten,” “are we really supposed to believe that the main intent for this is lost pets,” and “glad people are freaking out. This is dystopia becoming reality.”
Ring’s poorly defined partnership with Flock in particular has been the subject of various viral posts and public backlash. Many people have suggested that this partnership is evidence that Ring camera footage will be shared with ICE. At the moment there’s not enough evidence to explicitly say that that’s the case.
The supposed vector goes something like this: Ring says it will partner with Flock, which is used by thousands of local police departments. As we have reported, some of those police departments have performed Flock license plate lookups for ICE. It’s too early to say whether Ring footage will eventually end up with ICE, but the fact that people immediately drew that conclusion and understood the possible method of information sharing shows that surveillance companies can no longer hide behind viral videos of delivery drivers dancing. It’s a mask off moment, and people know it: “In Amazon’s alliance with this administration, it’s become more clear than ever that Ring is an extension of the carceral state,” Gilliard said. “An emotionally charged Super Bowl ad won’t change that.”
ICE Taps into Nationwide AI-Enabled Camera Network, Data Shows
Flock's automatic license plate reader (ALPR) cameras are in more than 5,000 communities around the U.S. Local police are doing lookups in the nationwide system for ICE.Jason Koebler (404 Media)
Patrick Klepek on the reality of parenting in the age of Roblox and YouTube.#podcasts
The Screen Time Panic Sets Parents Up to Fail
I listened to hours of podcasts about how screen time affects kids of all ages and how parents should manage screen time but I still felt completely unprepared for this challenge when I had a kid.I think the reason for that is that there’s a lot of reporting about how screens are impacting kids, and a lot of reporting about the research into this subject, but rarely did I encounter a conversation between parents that talks about how any of that information can be realistically applied in the real world.
This week on the podcast we’re joined by Patrick Klepek in order to have the kind of conversation I wish I heard before I became a parent, but I think there’s something here for everyone. Patrick is the cofounder of Remap, a website and one of my favorite podcasts about video games, and the writer behind Crossplay, a newsletter about the intersection of parenting and games. Patrick is also my former colleague at Vice, back when I worked at Motherboard and he at Waypoint. Patrick has been reporting about video games for most of his life, is a wonderful writer, and a parent. I find his perspective on many of these issues—screen time, parental controls, YouTube, Roblox—extremely useful and interesting, and I hope you do as well.
playlist.megaphone.fm?e=TBIEA1…youtube.com/embed/p2DEjvIvfs0?…
Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube.Become a paid subscriber for early access to these interview episodes and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
Chatbots provided incorrect, conflicting medical advice, researchers found: “Despite all the hype, AI just isn't ready to take on the role of the physician.”
Chatbots provided incorrect, conflicting medical advice, researchers found: “Despite all the hype, AI just isnx27;t ready to take on the role of the physician.”#chatbots #AI #medicine
Chatbots Make Terrible Doctors, New Study Finds
Chatbots may be able to pass medical exams, but that doesn’t mean they make good doctors, according to a new, large-scale study of how people get medical advice from large language models.The controlled study of 1,298 UK-based participants, published today in Nature Medicine from the Oxford Internet Institute and the Nuffield Department of Primary Care Health Sciences at the University of Oxford, tested whether LLMs could help people identify underlying conditions and suggest useful courses of action, like going to the hospital or seeking treatment. Participants were randomly assigned an LLM — GPT-4o, Llama 3, and Cohere’s Command R+ — or were told to use a source of their choice to “make decisions about a medical scenario as though they had encountered it at home,” according to the study. The scenarios included ailments like “a young man developing a severe headache after a night out with friends for example, to a new mother feeling constantly out of breath and exhausted,” the researchers said.
“One user was told to lie down in a dark room, and the other user was given the correct recommendation to seek emergency care.”
When the researchers tested the LLMs without involving users by providing the models with the full text of each clinical scenario, the models correctly identified conditions in 94.9 percent of cases. But when talking to the participants about those same conditions, the LLMs identified relevant conditions in fewer than 34.5 percent of cases. People didn’t know what information the chatbots needed, and in some scenarios, the chatbots provided multiple diagnoses and courses of action. Knowing what questions to ask a patient and what information might be withheld or missing during an examination are nuanced skills that make great human physicians; based on this study, chatbots can’t reliably replicate that kind of care.In some cases, the chatbots also generated information that was just wrong or incomplete, including focusing on elements of the participants’ inputs that were irrelevant, giving a partial US phone number to call, or suggesting they call the Australian emergency number.
“In an extreme case, two users sent very similar messages describing symptoms of a subarachnoid hemorrhage but were given opposite advice,” the study’s authors wrote. “One user was told to lie down in a dark room, and the other user was given the correct recommendation to seek emergency care.”
“These findings highlight the difficulty of building AI systems that can genuinely support people in sensitive, high-stakes areas like health,” Dr. Rebecca Payne, lead medical practitioner on the study, said in a press release. “Despite all the hype, AI just isn't ready to take on the role of the physician. Patients need to be aware that asking a large language model about their symptoms can be dangerous, giving wrong diagnoses and failing to recognise when urgent help is needed.”
Instagram’s AI Chatbots Lie About Being Licensed Therapists
When pushed for credentials, Instagram’s user-made AI Studio bots will make up license numbers, practices, and education to try to convince you it’s qualified to help with your mental health.404 MediaSamantha Cole
Last year, 404 Media reported on AI chatbots hosted by Meta that posed as therapists, providing users fake credentials like license numbers and educational backgrounds. Following that reporting, almost two dozen digital rights and consumer protection organizations sent a complaint to the Federal Trade Commission urging regulators to investigate Character.AI and Meta’s “unlicensed practice of medicine facilitated by their product,” through therapy-themed bots that claim to have credentials and confidentiality “with inadequate controls and disclosures.” A group of Democratic senators also urged Meta to investigate and limit the “blatant deception” of Meta’s chatbots that lie about being licensed therapists, and 44 attorneys general signed an open letter to 11 chatbot and social media companies, urging them to see their products “through the eyes of a parent, not a predator.”In January, OpenAI announced ChatGPT Health, “a dedicated experience that securely brings your health information and ChatGPT’s intelligence together, to help you feel more informed, prepared, and confident navigating your health,” the company said in a blog post. “Over two years, we’ve worked with more than 260 physicians who have practiced in 60 countries and dozens of specialties to understand what makes an answer to a health question helpful or potentially harmful—this group has now provided feedback on model outputs over 600,000 times across 30 areas of focus,” the company wrote. “This collaboration has shaped not just what Health can do, but how it responds: how urgently to encourage follow-ups with a clinician, how to communicate clearly without oversimplifying, and how to prioritize safety in moments that matter.”
“In our work, we found that none of the tested language models were ready for deployment in direct patient care. Despite strong performance from the LLMs alone, both on existing benchmarks and on our scenarios, medical expertise was insufficient for effective patient care,” the researchers wrote in their paper. “Our work can only provide a lower bound on performance: newer models, models that make use of advanced techniques from chain of thought to reasoning tokens, or fine-tuned specialized models, are likely to provide higher performance on medical benchmarks.” The researchers recommend developers, policymakers, and regulators consider testing LLMs with real human users before deploying in the future.
Senators Demand Meta Answer For AI Chatbots Posing as Licensed Therapists
Exclusive: Following 404 Media’s investigation into Meta's AI Studio chatbots that pose as therapists and provided license numbers and credentials, four senators urged Meta to limit "blatant deception" from its chatbots.Samantha Cole (404 Media)
Watch 404 Media’s Super Bowl Ad#SuperBowl
Watch 404 Media’s Super Bowl Ad
Behold, 404 Media’s Super Bowl ad. Yes, we bought a Super Bowl ad. No, we did not spend $8 million.Until now, 404 Media has never done any paid advertising, but we figured why not get in on the country’s biggest ad extravaganza with a message about our journalist-owned, human-focused media company. There are tons of ads for AI and big tech this year, so how about some counter programming?
youtube.com/embed/hmdo9kKdbH8?…
On a whim last week, we began looking into purchasing a Super Bowl ad for as little money as possible, by finding a local station willing to air our ad. We knew this was possible because in 2015, The Verge bought a Super Bowl ad that aired only in Helena, Montana, for a cost of $700. Inspired by them, we did the same this year.After googling “smallest TV markets in the United States,” we came across KYOU, which serves the city of Ottumwa, Iowa: population ~25,000. There were other options, but we thought we would try Ottumwa and see if anyone responded or if this seemed like a fool’s errand. We emailed KYOU to see if we could buy a Super Bowl ad, and we got an immediate answer: There was one slot left, and it would cost $2,550. They also had a slot immediately after the game for $1,250, one during the Olympics following the game for $500, or pregame slots for $500. It felt important to have the ad actually run during the game, so we paid the $2,550 in-game slot.
We then had several things to figure out: First, we needed to make an ad. Second, we needed to find someone in Ottumwa to film the ad for us.
0:00
/0:41
1×After batting around various concepts involving celebrities that we don’t actually know and high production values that we could neither afford nor execute, we decided to write an incredibly straightforward script about who we are, what we do, and what type of person we are for. We each recorded it in front of our computers where we do our podcasts. It is perhaps the easiest possible concept we could have created, but I think it feels very us. We then asked Evy Kwong, our social media manager, to cut the Super Bowl ad. Evy did a great job with the cybery filters and b-roll. Our friends at Kaleidoscope, which produces our podcast, then gave it a last-minute sound mix. We delivered a final version of the ad to KYOU Thursday morning, and were told that it would air early in the third quarter, around 8:07 p.m. CST.
0:00
/0:41
1×Finding someone in Ottumwa to film the ad for us in its natural habitat was slightly trickier. We put out a call on Bluesky and on our podcast this week, where we very cryptically asked for anyone in Ottumwa to contact us immediately. We got a shocking number of responses from people with ties to Ottumwa, but most either had family or friends there, had lived there briefly and moved on, or lived a few hours away but said they were willing to go there if we needed. Turns out many people were willing to call in favors, even after learning that we were not doing some sort of Flock or ICE investigation and instead needed something more frivolous. We learned a surprising amount of info about Ottumwa during this process, and I made friends with a semi local archaeologist who noted various ancient civilization sites in the broader area. All of this support was a really heartening experience, but we didn’t want to make people drive a long way or reach out to ex-colleagues for us.
Eventually, a current Ottumwan resident said that not only were they going to be in Ottumwa during the Super Bowl, but they would be watching at a party full of people who would also probably be willing to film the TV too. We are endlessly indebted to these folks.
Whether this ad moves the needle for us in any way, only time will tell. If you’re an Ottumwan who saw the ad and checked us out, please let us know.
playlist.megaphone.fm?p=TBIEA2…
“The question of whether humanity should reproduce beyond Earth is no longer hypothetical—it is a pressing ethical frontier,” researchers said.#TheAbstract
As Space Tourism Looms, Scientists Ask: Should We Have Sex In Orbit?
Welcome back to the Abstract! Here are the studies this week that had off-Earth offspring, took stock of a mortal threat, productively slept, and sought out old friends.First, what to expect when you’re expecting a star child. Then: how to fight cancer, the nap-plications of lucid dreaming, and why old rats don’t make new friends.
As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens or subscribe to my personal newsletter the BeX Files.
How to make babies in space (Don’t)
It’s hard enough to have babies on Earth, let alone off it. But if humans ever do expand beyond our planet to live in orbital outposts or on other planets, we would presumably want to build healthy families there. Even in the near term, it is conceivable that space will be flooded by rich tourists eager to join the 250-mile-high club, raising questions about how to practice safe space sex (or if that is even possible).
In a new study, scientists review the medical and ethical challenges of space reproduction, noting that while space sex is “often overshadowed by sensationalized or speculative portrayals, the topic…nonetheless demands serious attention.”
“Space is toxic to terrestrial life. It is an inherently hostile environment for terrestrial biology to thrive,” said researchers led by Giles Anthony Palmer of the International IVF Initiative Inc. “The microgravity, cosmic radiation, circadian disruption, pressure differentials, and extreme temperatures found in orbit or beyond present unique and multifactorial stressors to the human body.”
“As we enter a new era of space exploration, defined by longer missions, broader participation, and eventual human settlement beyond Earth, the question is not simply whether reproduction can occur in space, but whether human fertility can be preserved, protected and comprehensively understood in an environment fundamentally different from that in which our species evolved,” the team added.
The study provides a comprehensive review of how various space environments might impact fertility, pregnancy, labor, and health outcomes of children. For example, studies of rodent reproduction in space show higher risks of abnormal cell division and impaired development; meanwhile, the inherent dangers of pregnancy and labor are significantly amplified in space environments.
“The question of whether humanity should reproduce beyond Earth is no longer hypothetical—it is a pressing ethical frontier,” the team concluded. “In the context of commercial spaceflight, where ambition often outpaces caution, the stakes are higher than ever. Without robust frameworks, rigorous research, and a deeply human commitment to ethical principles, there is a risk of exporting not just life but injustice, exploitation and harm into the cosmos. To be worthy of the stars, we must earn our place, not only through technological prowess, but through ethical wisdom.”
In other news…
Let’s get cancer’s ass
Roughly ten million people die from cancer each year, making it a leading cause of morbidity worldwide. While many cancers are not preventable, scientists set out to estimate just how much of the global cancer burden can be attributable to “modifiable risk factors,” meaning behavioral, environmental, or occupational factors that influence the odds of developing cancer.
The results revealed that “nearly 4 in 10 cancer cases worldwide in 2022 could have been prevented by eliminating exposure to the risk factors considered in this study,” which include smoking, alcohol consumption, and contaminated environments, said researchers led by Hanna Fink of the World Health Organization's International Agency for Research on Cancer.
“Smoking (15.1%), infections (10.2%) and alcohol consumption (3.2%) were the leading contributors to cancer burden,” the team added. “Lung, stomach, and cervical cancers represented nearly half of preventable cancers. Strengthening efforts to reduce modifiable exposures remains central to global cancer prevention.”
The researchers also found “obvious gendered patterns in causes of cancer” such as higher rates of smoking and alcohol consumption in men, and higher BMI in women. While there is an enduring allure to the idea of a cancer cure-all, this study underscores that the disease emerges from a complex interplay of factors, only some of which are under our control.
To sleep, perchance to lucid dream
Scientists have gone ahead and done an Inception. In a new study, 20 experienced lucid dreamers were presented with puzzles matched with sound cues, which were then played as the participants slept to help them crack unsolved tasks in their dreams.
Figure illustrating the experiment design. Image: Konkoly, Karen R. et al.
“Whereas dream content is notoriously difficult to control experimentally, here we induced dreams about specific puzzles by presenting associated sounds during REM sleep,” said researchers led by Karen R. Konkoly of Northwestern University. “We preferentially recruited experienced lucid dreamers, intending for them to receive our real-time instructions in their dreams about which puzzles to volitionally attempt to solve.”“Although many participants did not experience lucid dreams, we nevertheless found that cues successfully influenced dream content, biasing dreaming toward specific puzzles,” the team added. “Moreover, when puzzles were incorporated into dreams, they were more likely to be solved the next morning.”
Yet more evidence for the most broadly applicable advice to humanity: sleep on it.
Despite all my rage I am still just a rat in a maze
People get set in their ways as they get older—and that’s apparently true for rats, according to this new research. To probe the effects of age on mammalian social behavior, researchers obtained 169 male rats in two age cohorts: “young adults” at six months old and “aged” rats that were way over the hill at two years old.
A series of rat mixers in water mazes revealed that the rodent elders were as likely to interact with rats as youngsters, but nearly half of them preferred to mingle with rats that were familiar to them, rather than socializing with new faces.
“Results for the aged rats were strikingly different from young in two ways,” said researchers led by Subhadeep Dutta Gupta of the National Institute on Aging in Baltimore. “First, as a group, aged rats failed to display a reliable social novelty preference overall” and “second, inter-individual variability was significantly greater among old animals, with nearly half exhibiting a phenotype not seen in the young group, comprising an apparent social bias for the familiar conspecific.”
I think we can all relate to an occasional social bias for familiar conspecifics. To that end, the study concludes with a truth bomb: “It is important to recognize that a brief session of social interaction with a stranger inevitably falls short in matching the depth of familiarity established through enduring human social relationships.”
In the words of the ultimate rat elder, Master Splinter: “Help each other, draw upon one another, and always remember the true force that binds you.”
Thanks for reading! See you next week.
First Contact
A narrative and visual exploration of humanity’s age-old search for and fixation with extraterrestrials.First Contact explores the ancient idea—and epic ...Hachette Book Group
This week, we discuss AI bubble hysteria, "just go independent," and more.#BehindTheBlog
Behind the Blog: The Neverending Cybersecurity Story
This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss AI bubble hysteria, "just go independent," and more.JOSEPH: This week we reported how the FBI has been unable to get into a Washington Post reporter’s iPhone because it was in Lockdown Mode. Side note, I wonder how the insane cuts at The Post are going to impact its digital or physical protection of journalists, if at all. This court record was very, very interesting in that it’s a quite rare admission of why exactly authorities were unable to access a device.
I don’t think there’s an area of cybersecurity, which we have a lot of reporting on, that is constantly in flux as mobile forensics. Nothing stays still, even for what feels like five minutes. There are constant tech developments, both on the side of Apple and Google, then on companies trying to break into those phones, like Cellebrite and Grayshift, the creator of Graykey.
This post is for subscribers only
Become a member to get access to all content
Subscribe now
EpsteIn—as in, Epstein and LinkedIn—searches your connections on the social network for names that match those in the released files.#JeffreyEpstein #News
This Tool Searches the Epstein Files For Your LinkedIn Contacts
A new tool searches your LinkedIn connections for people who are mentioned in the Epstein files, just in case you don’t, understandably, want anything to do with them on the already deranged social network.404 Media tested the tool, called EpsteIn—as in, a mash up of Epstein and LinkedIn—and it appears to work.
This post is for subscribers only
Become a member to get access to all content
Subscribe now
The discovery of a Medieval tunnel built within a prehistoric burial ground adds to the mystery of hundreds of underground passages without a known purpose.#TheAbstract
Scientists Keep Discovering Mysterious Ancient Tunnels Across Europe
🌘
Subscribe to 404 Media to get The Abstract, our newsletter about the most exciting and mind-boggling science news and studies of the week.Archeologists in Germany have unearthed a mysterious underground tunnel built centuries ago within a prehistoric burial ground, marking a “very special” discovery according to a recent release from the State Office for Monument Preservation and Archaeology (LDA) of Saxony-Anhalt.
The buried tunnel measures about two-feet wide and four-feet high, and was likely constructed anywhere between 800 to 1,100 years ago near the town of Reinstedt. Archeologists found pottery that dates to about the 13th or 14th century in the chamber, and also discovered a separate cavity that contained a horseshoe, a fox skeleton, and some small mammal bones. A layer of charcoal in the tunnel suggests that fires were once lit in this space.
The tunnel is just one of hundreds of similar structures, known as erdstalls, that have been discovered across Europe. Fascinatingly, nobody knows what function they served, with the debated possibilities including use as hideaways or sites for cultic activity. Erdstalls are “man-made underground tunnel systems, sometimes with chamber-like extensions,” said Jochen Fahr, an archaeologist at LDA who organized the excavation in an email to 404 Media. “Around a dozen such findings are known from the federal state of Saxony-Anhalt, which means that the density of these structures is lower in our region than it is in others. Their function has not yet been clarified and may also vary from case to case.”
“Possible interpretations include hiding places in case of danger or storage cellars,” Fahr continued. “A cultic-religious function could also be possible, as a kind of Christian chapel. The interpretation of these structures is made more difficult by the fact that the examples known to us contain little or no archaeological finds, which makes it very difficult to draw any firm conclusions on their function.”
The horse shoe and pottery found in the erdstall. Image: © State Office for Monument Preservation and Archaeology of Saxony-Anhalt, Ulf Petzschmann.
Researchers initially set out to survey this site last year before the construction of wind turbines in the area. The site was already known as the location of a trapezoidal ditch that was used as a burial ground by the Baalberge people, who lived in Saxony-Anhalt during the Neolithic period of prehistory 6,000 years ago.“In the course of the site‘s further investigation and documentation, the erdstall was discovered,” Fahr explained. “It had been dug into the southern part of the trapezoidal ditch thousands of years after the ditch‘s construction. Initially, the erdstall appeared as a well-defined elongated oval pit, about two meters long and up to 75 centimeters wide, which cut the older ditch almost at right angles.”
“This led to the assumption that it could be a burial—but the fact that the finding then turned out to be something completely different, that it was in fact an erdstall, was an unexpected surprise that caused fascination and excitement among the team,” he added.
A section of the underground passage with a pointed gable and a small niche in the wall. The passage is approximately one meter high and 50 to 70 centimeters wide. Image © State Office for Monument Preservation and Archaeology of Saxony-Anhalt, Ulf Petzschmann.
The team speculated that the people who dug out this passageway may have deliberately selected the ancient burial ground as a secret hideaway. The area may have been “generally avoided by the population due to its special nature—perhaps a pagan burial site—and was therefore particularly suitable as a hiding place,” according to the press release.Hundreds of erdstalls have been found across Europe, and they are often associated with local folklore passed down across generations. Because the tunnels are normally extremely narrow, some legends cast erdstalls as home to dwarfs, goblins, and other diminutive mythical creatures, which is why they are known as Schratzlloch (goblin holes) or Zwergloch (dwarf holes) in some regions.
Some of the most famous examples include the Beate Greithanner erdstall, a passage that was discovered in 2011 after a dairy cow fell into it. The Ratgöbluckn erdstall in Austria is one of the rare passages that is big enough to safely accommodate tourists.
The Ratgöbluckn erdstall. Image: Pfeifferfranz
The new erdstall found at Reinstedt deepens the mystery of these structures, which have intrigued archeologists for decades and still remain largely unexplained.“The excavation has been completed, the team is currently in the process of evaluating the findings and finds,” Fahr said. “In this context, my colleagues are also in the process of delving deeper into the topic of the erdstall, based on the latest literature on the subject, for example. A scholarly publication is planned.”
“It is also hoped that further findings in the future will help us to better understand the phenomenon of erdstalls and, in particular, to further clarify their function,” he concluded.
Lockdown Mode is a sometimes overlooked feature of Apple devices that broadly make them harder to hack. A court record indicates the feature might be effective at stopping third parties unlocking someone's device. At least for now.
Lockdown Mode is a sometimes overlooked feature of Apple devices that broadly make them harder to hack. A court record indicates the feature might be effective at stopping third parties unlocking someonex27;s device. At least for now.#Privacy #News
FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled
The FBI has been unable to access a Washington Post reporter’s seized iPhone because it was in Lockdown Mode, a sometimes overlooked feature that makes iPhones broadly more secure, according to recently filed court records.The court record shows what devices and data the FBI was able to ultimately access, and which devices it could not, after raiding the home of the reporter, Hannah Natanson, in January as part of an investigation into leaks of classified information. It also provides rare insight into the apparent effectiveness of Lockdown Mode, or at least how effective it might be before the FBI may try other techniques to access the device.
💡
Do you know anything else about phone unlocking technology? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.This post is for subscribers only
Become a member to get access to all content
Subscribe nowFBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled
Lockdown Mode is a sometimes overlooked feature of Apple devices that broadly make them harder to hack. A court record indicates the feature might be effective at stopping third parties unlocking someone's device. At least for now.Joseph Cox (404 Media)
This Epstein dump is probably the worst yet. Then we talk all about security issues in Moltbot and Moltbook. Then, even more security issues with some popular apps.#Podcast
Podcast: The Latest Epstein Dump is a Disaster
We start this week with Sam and Emanuel’s article about the latest Epstein dump, and how it’s really a disaster in a lot of ways. After the break, Matthew runs us through Moltbot and its terrible security. After the break, Emanuel breaks down his two recent stories about a fundamental issue exposing a bunch of very sensitive data.
playlist.megaphone.fm?e=TBIEA8…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
youtube.com/embed/gDcOOP_Y9cU?…
Timestamps:0:00 - Intro
2:19 - DOJ Released Unredacted Nude Images in Epstein Files
25:08 - Silicon Valley’s Favorite New AI Agent Has Serious Security Flaws
34:55 - Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site
- DOJ Released Unredacted Nude Images in Epstein Files
- Silicon Valley’s Favorite New AI Agent Has Serious Security Flaws
- Exposed Moltbook Database Let Anyone Take Control of Any AI Agent on the Site
- App for Quitting Porn Leaked Users' Masturbation Habits
- Massive AI Chat App Leaked Millions of Users Private Conversations
The 404 Media Podcast
Tech News Podcast · Updated Weekly · Welcome to the podcast from 404 Media where Joseph, Sam, Emanuel, and Jason catch you up on the stories we published this week. 404 Media is a journalist-owned digital media company exploring the way …Apple Podcasts
Hackers have targeted a spread of apps or sites that aim to track ICE activity, in one case even sending push notifications to users in an attempt to intimidate them.#ICE #News
Hackers and Trolls Target Wave of ICE Spotting Apps
Over the last few days hackers and trolls have targeted a slew of ICE spotting apps and their users in an apparent attempt to intimidate and stop them from reporting sightings of ICE. These hackers sent threatening text messages to users of StopICE, claiming their personal data has been sent to the authorities; attempted to wipe uploads on Eyes Up, which aims to document ICE abuses; and even sent push notifications to DEICER app users claiming their data has also been sent to various government agencies.There is little evidence that hackers have actually provided data to the government. But it shows that apps like these, many of which Apple and Google have already kicked from their respective app stores, in some cases after direct government pressure, can be targeted by hackers or those looking to harass their users.
“Yes there is a targeted spike in attacks targeting similar [sites],” Sherman Austin, the developer of StopICE, told 404 Media in an email.
This post is for subscribers only
Become a member to get access to all content
Subscribe now
‘Curator Live’, a popular photo booth company for weddings and other events, is exposing all sorts of unsuspecting people’s photos.#Privacy #News
Wedding Photo Booth Company Exposes Customers’ Drunken Photos
A photo booth company that caters to weddings, lobbying events in D.C., and engagement parties has exposed a cache of peoples’ photos, with the revellers likely unaware that their sometimes drunken antics have been collected and insecurely stored by the company for anyone to download. A security researcher who flagged the issue to 404 Media said the company, Curator Live, has not responded to his request to fix the issue.The exposure, which also includes phone numbers, highlights how we can face data collection even at innocuous events like weddings. It’s also not even the only recent exposure by a photo booth company. TechCrunch reported on a similar issue with a different company in December.
“Even if you just wanted the printed photo, your data is being held by a third party unbeknownst to you,” the security researcher, who requested anonymity to speak about a sensitive security issue, said. “The fact that this third party leaks it freely is icing on the cake. It violates any reasonable expectation of privacy.”
In all, the researcher says at least 100GB of photos are exposed. 404 Media reviewed a smaller sample of photos. They show people at various weddings and engagement parties cheering and drinking. Some photos include children. Others appear to have been taken at a NASA branded event.
“You can attribute the phone numbers to photos of people in some cases. I think the greatest reasonable risk for photo booth users is that it could reveal intimate photos,” the researcher added.
Curator Live’s website says the company “delivers industry-leading enterprise photo and video capture solutions. From photo booth operators to zoos, sports events, attractions, and vacation destinations, we help your brand create unforgettable experiences and lasting memories.”
As for how they found this issue, the researcher said they went to a wedding where the DJ company had a Curator Live photo booth. “The booth was configured to take four or so photos, then printed them out. The machine promoted the user for a phone number to receive digital copies of the photos,” he said.
After reluctantly entering his number, the researcher received a text with a link to Curator Live’s API, he said. From there, he found the exposed data. The company is still exposing people’s data so 404 Media is not explaining the security issue in detail. But the impact is that a stranger could dig through other peoples’ photos.
The researcher shared a copy of his email he sent to Curator Live in November detailing the issue. The researcher said he never received a response. “Fix your shit,” one line read.
Curator Live did not respond to 404 Media’s request for comment.
Flaw in photo booth maker’s website exposes customers’ pictures | TechCrunch
Hama Film makes photo booths that upload pictures and videos online. But their back-end systems have a simple flaw that allows anyone to download customer pictures.Lorenzo Franceschi-Bicchierai (TechCrunch)
Download a PDF of our first ever zine here.#zine
Our Zine About ICE Surveillance Is Here
We are very proud to present 404 Media’s zine on the surveillance technology used by Immigrations and Customs Enforcement. While we have always covered surveillance and privacy, for the last year, you may have noticed that we have spent an outsized amount of our attention and time reporting on the ways technology companies are powering Donald Trump’s deportation raids.When we announced this zine in early December, we hoped that people would want it. Trump’s dehumanizing mass deportation campaign is perhaps the bleakest, most horrifying aspect of an administration that has reveled in its attacks on civil liberties, science, and government expertise. We did not know just how many of you would want a copy. We originally intended to print 1,000 copies, and to hand most of them out at a benefit concert in Los Angeles for CHIRLA, a human rights organization that helps immigrants. When those sold out in a few hours, we asked Punch Kiss Press, our printer, if they could make 2,500. When those sold out just as fast, we increased our order to 3,500. If you preordered a print zine, I put it in the mail last week and it should be arriving soon. Thank you everyone for your patience in waiting for the zine and we’d love to know what you think of it. We have a handful more copies that we’ve put up for sale on our Shopify. They will almost certainly sell out today and we will probably not reprint them.
We never intended to make this zine a scarce resource. We wanted to make a print product as an experiment for the reasons we explained when we announced it: Print is cool, it’s human, it’s enduring, and it’s shareable.
404ICEZINE
Full-sized zine in English404ICEZINE.pdf
62 MBdownload-circle
ICEZineEspanol
Zine en españolICEZineEspanol.pdf
5 MBdownload-circle
zinesmallfile
Zine in English, small file sizezinesmallfile.pdf
5 MBdownload-circle
Each of these zines was printed, assembled, and cut down to size by hand, and each of them was stuck in the mail by me or a friend of mine over the course of the last few weeks. We printed this on a riso printer, a Japanese duplicator from the early 1990s that anyone who is into will talk your ear off about endlessly, to the point that it has become a meme. I also printed all the envelopes on a riso printer from 1995 that I have painstakingly spent the last few months repairing. Basically, making and shipping these was labor intensive and DIY by design; we never thought we would need to print so many. They were made with a considerable amount of love. And for this first one, we don’t really have the capability to make and ship more than we’ve already made.
0:00
/0:18
1×So for that reason, we’re releasing a PDF of the zine for free to everyone, because we think the information contained within it is important and should be shared as widely as possible. We have also paid to have the zine translated into Spanish by human translators, thanks in part to a donation from one of our subscribers. You can find the Spanish version of the zine here. If you have a riso printer or are a riso print shop and are interested in printing additional copies at scale to distribute to your community, please email me and I may be able to share the print files with you.
We could not have made this zine without the support of our subscribers, our friends, and our local community. The zine was laid out by our friend Ernie Smith, who is one of the best to ever do it. The cover art was done by Veri Alvarez, whose work you can find here and whose anti-ICE art is frankly very fucking good and who deserves your support. The printing and assembly of the zine was done by Karina Richardson at Punch Kiss Press in Los Angeles and a few of her friends. I met Karina at a print festival in Los Angeles a few months ago and then asked her if she could take on this very complicated project on a short timeline. I then asked her to more than triple the number of copies, all over the holidays. It cannot be overstated how much Karina and Punch Kiss knocked it out of the park on this, and how thankful we are to her. And we made the zine to support LA Fights Back, a concert series dedicated to raising money for communities affected by ICE. We are thankful that we were invited to participate.
This being a print product, our work has been frozen in time. We wrote these pieces before DHS agents killed Renee Good and Alex Pretti in Minneapolis, and before several other people died in ICE custody in the last few weeks. The horrors we are facing are evolving and changing every day and we are committed to continuing to cover the ways that big tech and the surveillance state empowers ICE. You can find most of our most recent work on ICE here:
- Here is the User Guide for ELITE, the Tool Palantir Made for ICE
- DHS Says Critical ICE Surveillance Footage From Abuse Case Was ...
- Feds Create Drone No Fly Zone That Would Stop People Filming ICE
- ICE's Facial Recognition App Misidentified a Woman. Twice
- 'ELITE': The Palantir App ICE Uses to Find Neighborhoods to Raid
- Inside ICE's Tool to Monitor Phones in Entire Neighborhoods
- DHS Is Lying To You About ICE Shooting a Woman
- Here is the Agreement Giving ICE Medicaid Patients' Data
- How a US Citizen Was Scanned With ICE's Facial Recognition Tech
- ICE Contracts Company Making Bounty Hunter AI Agents
- ICE Taps into Nationwide AI-Enabled Camera Network, Data Shows
We’ve been overwhelmed and heartened by the support and interest in our reporting and in this zine. This project was a lot of work, and we’ve learned a lot about making and distributing a physical product at scale. We don’t have anything concrete to announce yet but I think we’d love to do more print products and issues in the future. So if you liked this please let us know. If you want to support our work specifically, the best thing you can do is subscribe to 404 Media. We also have a tip jar and, if you are interested in making a larger tax-deductible donation, please email us at donate@404media.co.
Privacy Telecom ‘Cape’ Introduces ‘Disappearing Call Logs’ That Delete Every 24 Hours#Privacy
Privacy Telecom ‘Cape’ Introduces ‘Disappearing Call Logs’ That Delete Every 24 Hours
Cape, a privacy-focused telecommunications company, says it has introduced a feature that automatically deletes a user’s call data records, such as who they call and when, every 24 hours. These “disappearing call logs” as Cape describes them break with the telecom industry standard of keeping hold of call logs for months if not years.“One of our first design principles was to minimize the amount of data that we collect and the amount of data that we store,” John Doyle, CEO of Cape, told 404 Media in an interview. “There’s no other business purpose to keep most of these logs more than like a day.”
Call data records, or CDRs, are metadata about a user’s phone call and text records. This includes the phone number the user contacted. This information can be especially revealing, showing that a particular person called an abortion clinic, for instance. In 2024, hackers stole “nearly all” of AT&T customers’ call records spanning several months. That in turn started a rush from the FBI to protect the identities of confidential informants, Bloomberg reported. That hack was so damaging in part because AT&T kept its customers’ call records for an extended period of time.
💡
Do you know about any other similar tools? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.Cape is a mobile virtual network operator (MVNO), meaning it runs its service on top of other companies’ existing telecommunications infrastructure. Cape isn’t building cellphone towers; it’s making software to add security benefits. Cape is able to make changes to how long it retains data and other technical aspects because it runs its own mobile core—all of the software necessary to route messages and essentially be a telecom.
404 Media asked Cape to demonstrate that CDRs were being deleted. In response, Cape made a video describing the process. It appeared to show that the databases Cape uses to store CDRs did only contain data from a 24 hour period. Previously, Cape stored CDRs for 60 days, “which was already well short of industry standards,” Doyle said. Cape says it does hold “billing CDRs” for longer, for 30 days. These records are used to determine how much Cape has used carriers’ infrastructure.
playlist.megaphone.fm?p=TBIEA2…
Cape’s CDRs are made when a customer uses the Cape phone number assigned to their account. The change wouldn’t impact data generated by an app such as Signal; those are separate, and Signal already has various metadata protections.Doyle said Cape did not warn law enforcement about the change to CDR retention beforehand. “I guess they’ll find out in the same way everyone else does,” he said. He added that the company still is in keeping with CALEA, or the Communications Assistance for Law Enforcement Act, which requires telecommunications companies to respond to legal demands for data.
Because Cape is piggybacking off other carriers’ infrastructure, that does mean that somewhere along the line those other companies could store their own copy of Cape users’ data.
“It’s definitely true that some of our carrier partners may collect some information,” Doyle said, including the IMEI, a unique identifier assigned to a device.
Since I first covered Cape in 2024, I occasionally get emails asking me if Cape is a honeypot, in the sense that maybe it is a ruse to then provide data to the authorities. Doyle is also formerly of Palantir.
“All I can do is say we definitively are not a honeypot,” Doyle said. “It’s so hard to prove a negative, but I say it out loud every chance I get.”
Hackers Steal Text and Call Records of ‘Nearly All’ AT&T Customers
In one of the most significant data breaches in recent history, hackers stole AT&T customers’ call and text metadata spanning several months.Joseph Cox (404 Media)
Joseph speaks to Samuel Bagg about all the ways identities dictate what people see, and how what they choose to believe is based much more on those identities than the evidence in front of them.#Podcast
How Identity Literally Changes What You See (with Samuel Bagg)
This week Joseph talks to Samuel Bagg, assistant professor of political science at the University of South Carolina. Bagg recently wrote a fascinating essay, linked below, about how the problem with lots of things might be knowledge-based (people believing stuff that’s wrong or dangerous) but the solution is not more knowledge. It’s all about social identity. This is an incredibly interesting discussion, and definitely check out more of Bagg’s writing.
playlist.megaphone.fm?e=TBIEA5…
Listen to the weekly podcast on Apple Podcasts,Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
youtube.com/embed/lNKOqp-rZL8?…
- The Problem is Epistemic. The Solution is Not
- The Dispersion of Power: A Critical Realist Theory of Democracy
The Problem is Epistemic. The Solution is Not. | Blog of the APA
Doubts about the wisdom of the masses are as old as philosophy itself. Yet interest in democracy’s “epistemic” merits has surged in the last decade—and it is no mystery why.Samuel Bagg (Blog of the APA)
Musk to Epstein: ‘What Day/Night Will Be the Wildest Party on Your Island?’#JeffreyEpstein #ElonMusk
Musk to Epstein: ‘What Day/Night Will Be the Wildest Party on Your Island?’
Here is an email that Elon Musk, current world’s richest man and owner of a gigantic social media network that generated child sexual abuse material on demand, sent to sex offender Jeffrey Epstein on November 11, 2012: “What day/night will be the wildest party on your island?”At first glance, the latest Department of Justice dump of Epstein documents is at least as horrifying as any of the dumps that came previously. Whether or not—and most likely not—any consequences of any sort come for any of the people who interacted with or were friends with the notorious child sexual abuser, the documents are depraved and continue to show that Musk and many other rich and powerful people have been lying about their relationships with Epstein for years.
In September, Musk tweeted “this is false” in response to a Forbes article based on previously released documents that stated he “planned a trip to Epstein’s private island.” He also wrote “Epstein tried to get me to go to his island and I REFUSED.” Musk had previously been named on Epstein’s calendar as being slated to visit Epstein’s island in 2014.The emails released Friday show without a doubt that Musk, at the very least, “planned” a trip to Epstein’s island. They also show that Epstein asked Musk if SolarCity, his solar power startup that was eventually folded into Tesla, could electrify the island or his New Mexico ranch.
The newly released documents show that Musk emailed with Epstein over the course of more than a year. In a December 2013 thread called “Christmas and New Year’s,” Musk wrote “Will be in the BVI [British Virgin Islands]/St Bart’s area over the holidays. Is there a good time to visit?”
“I will send heli for you,” Epstein responded. “Thanks,” Musk answered.
“Actually, I could fly back early on the 3rd. We will be in St Bart’s. When should we head to your island on the 2nd?,” Musk said in a follow-up email.
In October 2012, Musk emailed Epstein and said “The world needs more romance […] Talulah [Musk’s second wife] and I are headed to St. Barth’s at the end of the year. I assume you will most likely be on your island?”
Epstein eventually responded in November and offered to send Musk as helicopter: “how many people will you be for the heli to island,” Epstein wrote.
“Probably just Talulah and me,” Musk responded. “What day/night will be the wildest party on your island?”
Another thread between Epstein and Musk was about providing power to two of Epstein’s properties: “is there any one at Solar City that my guys can talk to about electrifying the caribean [sic] island? Or the New Mexico ranch,” Epstein wrote. “Are we in New Mexico?” Musk wrote, adding a colleague to the thread.
These emails are hitting at a time where there is quite a lot going on in the world, and Musk, Donald Trump, and the current class of people in political power have shown that they will suffer very little from essentially any political scandal. And yet, these emails show in black and white that Musk has been lying about his relationship with Epstein, and that’s worth documenting.
Epstein calendar released by Democrats mentions Elon Musk, who denies visiting his island
A copy of Jeffrey Epstein’s daily schedules released Friday by House Democrats stated that Elon Musk was tentatively expected to visit Epstein’s private island in December 2014David Ingram (NBC News)
This week, we discuss a trip to Kenya, reconstructing images, and lying developers.#BehindTheBlog
Behind the Blog: Own Goals and Lying Devs
This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss a trip to Kenya, reconstructing images, and lying developers.JASON: Last week, I was in Kenya, a trip that turned out so overwhelmingly positive and left me in such a good mood that I am still somehow a week still carrying with me. I was invited to give a presentation at a conference about how AI is changing journalism, and how journalists can navigate an age of disinformation, slop, and general chaos.
It was a very small conference, with about 30 people, and everyone was incredibly interesting and cool; it was a mix of people who run independent newsrooms across Africa, Europe, and Asia, as well as human rights and nonprofit researcher types. At the conference itself, I met a lot of people who I hope we’ll be able to partner with in some way in the future.
This post is for subscribers only
Become a member to get access to all content
Subscribe now
The AI agent once called ClawdBot is enchanting tech elites, but its security vulnerabilities highlight systemic problems with AI.#News #AI
Silicon Valley’s Favorite New AI Agent Has Serious Security Flaws
A hacker demonstrated that the viral new AI agent Moltbot (formally Clawdbot) is easy to hack via a backdoor in an attached support shop. Clawdbot has become a Silicon Valley sensation among a certain type of AI-booster techbro, and the backdoor highlights just one of the things that can go awry if you use AI to automate your life and work.Software engineer Peter Steinberger first released Moltbot as Clawdbot last November. (He changed the name on January 27 at the request of Anthropic who runs a chatbot called Claude.) Moltbot runs on a local server and, to hear its boosters tell it, works the way AI agents do in fiction. Users talk to it through a communication platform like Discord, Telegram, or Signal and the AI does various tasks for them.
playlist.megaphone.fm?p=TBIEA2…
According to its ardent admirers, Moltbot will clean up your inbox, buy stuff, and manage your calendar. With some tinkering, it’ll run on a Mac Mini and it seems to have a better memory than other AI agents. Moltbot’s fans say that this, finally, is the AI future companies like OpenAI and Anthropic have been promising.The popularity of Moltbot is sort of hard to explain if you’re not already tapped into a specific sect of Silicon Valley AI boosters. One benefit is the interface. Instead of going to a discrete website like ChatGPT, Moltbot users can talk to the AI through Telegram, Signal, or Teams. It’s also active, rather than passive. It also takes initiative. Unlike Claude or Copilot, Moltbot takes initiative and performs tasks it thinks a user wants done. The project has more than 100,000 stars on GitHub and is so popular it spiked Cloudflare’s stock price by 14% earlier this week because Moltbot runs on the service’s infrastructure.
But inviting an AI agent into your life comes with massive security risks. Hacker Jamieson O'Reilly demonstrated those risks in three experiments he wrote up as long posts on X. In the first, he showed that it’s possible for bad actors to access someone’s Moltbot through any of its processes connected to the public facing internet. From there, the hacker could use Moltbot to access everything else, including Signal messages, a user had turned over to Moltbot.
In the second post, O'Reilly created a supply chain attack on Moltbot through ClawdHub. “Think of it like your mobile app store for AI agent capabilities,” O’Reilly told 404 Media. “ClawdHub is where people share ‘skills,’ which are basically instruction packages that teach the AI how to do specific things. So if you want Clawd/Moltbot to post tweets for you, or go shopping on Amazon, there's a skill for that. The idea is that instead of everyone writing the same instructions from scratch, you download pre-made skills from people who've already figured it out.”
The problem, as O’Reilly pointed out, is that it’s easy for a hacker to create a “skill” for ClawdHub that contains malicious code. That code could gain access to whatever Moltbot sees and get up to all kinds of trouble on behalf of whoever created it.
For his experiment, O’Reilly released a “skill” on ClawdHub called “What Would Elon Do” that promised to help people think and make decisions like Elon Musk. Once the skill was integrated into people’s Moltbot and actually used, it sent a command line pop-up to the user that said “YOU JUST GOT PWNED (harmlessly.)”
Another vulnerability on ClawdHub was the way it communicated to users what skills were safe: it showed them how many times other people had downloaded it. O’Reilly was able to write a script that pumped “What Would Elon Do” up by 4,000 downloads and thus make it look safe and attractive.
“When you compromise a supply chain, you're not asking victims to trust you, you're hijacking trust they've already placed in someone else,” he said. “That is, a developer or developers who've been publishing useful tools for years has built up credibility, download counts, stars, and a reputation. If you compromise their account or their distribution channel, you inherit all of that.”
In his third, and final, attack on Moltbot, O’Reilly was able to upload an SVG (vector graphics) file to ClawdHub’s servers and inject some JavaScript that ran on ClawdHub’s servers. O’Reilly used the access to play a song from The Matrix while lobsters danced around a Photoshopped picture of himself as Neo. “An SVG file just hijacked your entire session,” reads scrolling text at the top of a skill hosted on ClawdHub.
O’Reilly attacks on Moltbot and ClawdHub highlight a systemic security problem in AI agents. If you want these free agents doing tasks for you, they require a certain amount of access to your data and that access will always come with risks. I asked O’Reilly if this was a solvable problem and he told me that “solvable” isn't the right word. He prefers the word “manegeable.”
“If we're serious about it we can mitigate a lot. The fundamental tension is that AI agents are useful precisely because they have access to things. They need to read your files to help you code. They need credentials to deploy on your behalf. They need to execute commands to automate your workflow,” he said. “Every useful capability is also an attack surface. What we can do is build better permission models, better sandboxing, better auditing. Make it so compromises are contained rather than catastrophic.”
We’ve been here before. “The browser security model took decades to mature, and it's still not perfect,” O’Reilly said. “AI agents are at the ‘early days of the web’ stage where we're still figuring out what the equivalent of same-origin policy should even look like. It's solvable in the sense that we can make it much better. It's not solvable in the sense that there will always be a tradeoff between capability and risk.”
As AI agents grow in popularity and more people learn to use them, it’s important to return to first principles, he said. “Don't give the agent access to everything just because it's convenient,” O’Reilley said. “If it only needs to read code, don't give it write access to your production servers. Beyond that, treat your agent infrastructure like you'd treat any internet-facing service. Put it behind proper authentication, don't expose control interfaces to the public internet, audit what it has access to, and be skeptical of the supply chain. Don't just install the most popular skill without reading what it does. Check when it was last updated, who maintains it, what files it includes. Compartmentalise where possible. Run agent stuff in isolated environments. If it gets compromised, limit the blast radius.”
None of this is new, it’s how security and software have worked for a long time. “Every single vulnerability I found in this research, the proxy trust issues, the supply chain poisoning, the stored XSS, these have been plaguing traditional software for decades,” he said. “We've known about XSS since the late 90s. Supply chain attacks have been a documented threat vector for over a decade. Misconfigured authentication and exposed admin interfaces are as old as the web itself. Even seasoned developers overlook this stuff. They always have. Security gets deprioritised because it's invisible when it's working and only becomes visible when it fails.”
What’s different now is that AI has created a world where new people are using a tool they think will make them software engineers. People with little to no experience working a command line or playing with JSON are vibe coding complex systems without understanding how they work or what they’re building. “And I want to be clear—I'm fully supportive of this. More people building is a good thing. The democratisation of software development is genuinely exciting,” O’Reilly said. “But these new builders are going to need to learn security just as fast as they're learning to vibe code. You can't speedrun development and ignore the lessons we've spent twenty years learning the hard way.”
Moltbot’s Steinberger did not respond to 404 Media’s request for comment but O’Reilly said the developer’s been responsive and supportive as he’s red-teamed Moltbot. “He takes it seriously, no ego about it. Some maintainers get defensive when you report vulnerabilities, but Peter
immediately engaged, started pushing fixes, and has been collaborative throughout,” O’Reilly said. “I've submitted [pull requests] with fixes myself because I actually want this project to succeed. That's why I'm doing this publicly rather than just pointing my finger and laughing Ralph Wiggum style…the open source model works when people act in good faith, and Peter's doing exactly that.”
OpenClaw — Personal AI Assistant
OpenClaw — The AI that actually does things. Your personal assistant on any platform.www.molt.bot
The remains of a rich ancient ecosystem in China is so well-preserved that it contains guts, tentacles, and even an intact nervous system.#TheAbstract
Dozens of Bizarre Ancient Lifeforms Discovered in ‘Extraordinary’ Fossil Find
🌘
Subscribe to 404 Media to get The Abstract, our newsletter about the most exciting and mind-boggling science news and studies of the week.Welcome back to the Abstract! Here are the studies this week that roamed a superocean, took to the skies, grabbed some grub, and watched alien auroras.
First, check out some 512-million-year-old guts, brains, and tentacles. Gnarly! Then, dig into the mega-importance of Microraptor, some entomological edibles, and more weird radio signals from outer space.
As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens or subscribe to my personal newsletter the BeX Files.
Blast from the Cambrian past
Paleontologists have discovered the remains of a vibrant ecosystem that existed more than half a billion years ago, revealing dozens of strange species that have never been seen in the fossil record before.
Found in the southern mountains of China’s Huayuan County, this fossilized snapshot offers an unprecedented glimpse of the creatures that were crawling (or swimming, or slithering, etc.) through the oceans 512 million years ago, during the Cambrian period, when complex life on Earth first went into overdrive.
Between 2021 and 2024, paleontologists unearthed thousands of specimens at this site, which yielded “remarkable taxonomic richness, comprising 153 animal species…among which 59 percent of species are new,” according to researchers co-led by Han Zeng and Qi Liu of the Chinese Academy of Sciences.
Many of the same animals have been found at other Cambrian sites—such as Canada’s famous Burgess Shale—suggesting that species dispersed widely through the vast superocean that existed at this time, traveling by ocean currents or even “floating rafts,” the team said.
Not only is this ecosystem notably diverse, but the fossils have remained unusually intact in the ancient mudstone, allowing for the preservation of soft tissues like tentacles, guts, and a nearly-complete nervous system found in one arthropod.
“The biota is comprised overwhelmingly of soft-bodied forms that include preserved cellular tissues” in a state of “extraordinary soft-tissue preservation,” the team said.
The middle Cambrian period famously featured an “explosion” of complex Earthlings that rapidly proliferated from about 538 to 518 million years ago. While 20 million years is a long time from a human perspective, this was a sudden and dramatic event for life on Earth as a whole, which had previously been confined to microbial form for billions of years. The newly-discovered Huayuan biota lived in the wake of the explosion and a subsequent collapse, a mass extinction called the Sinsk event.
There are way too many cool finds in this study to summarize in one humble newsletter, so I will close this up with one of my absolute favorite Cambrian weirdos: Herpetogaster, a phantasmagorical creature of tubes and tentacles depicted in the below illustration that I offer without comment.
Herpetogaster doing whatever Herpetogaster does. Image: Marianne Collins - PLoS One
“The enigmatic cambroernid Herpetogaster—an iconic taxon first described from the Burgess Shale—is represented by over 100 specimens in the Huayuan biota, making it the most abundant entirely soft-bodied species,” said the team.Forget gold, oil, and diamonds. There is no richer vein to tap than the Herpetogaster mother lode.
In other news…
Microraptor: the original early bird
Speaking of enchanting extinct animals, let’s glide forward in time to the early Cretaceous period, when the dinosaur Microraptor was on the wing—or more accurately, four wings. Unlike pterosaurs or birds, which sport just one pair of wings, Microraptor evolved feathered wings on both its fore and hind limbs, a body plan that has long fascinated paleontologists.
Act casual when confronted by dinosaurian raptors of various scales (Microraptor is #1). Image: Fred Wierum
To get a better handle on how Microraptor took to the sky, researchers led by Csaba Hefler of the Hong Kong University of Science and Technology modelled its possible flight dynamics and demonstrated “the potential for beneficial interactions between the forewing and hindwing” that helped this airborne predator attack its prey.“The specialization of the hindwing to accommodate the downstream extended tip vortex for a wide range of angles of attack is to our knowledge unique among flying animals, including four-winged insects,” the team said. “Our results suggest that greater utilization of unsteady aerodynamic features was potentially a crucial milestone of early flight development.”
Respect to this deft handler of the downstream vortex. As its name implies, Microraptor was very small, but to its prey, it was a terrifying portent of death from on high.
Grub’s up
Pass the beetle sausage and butter the larva bread, because it’s time to embrace your inner insectivore. Insects have been part of the human diet for ages—many are considered delicacies—but they have become taboo and reviled as a food source in many Western societies that view insects with disgust.
In a new study, scientists advise that we get over the ick factor, as insects could play an important part in maintaining food security in the coming decades.
“More than 2,000 insect species have been identified as safe for human consumption, offering a wide range of nutrients, including proteins, lipids, minerals, and vitamins at different life stages such as eggs, larvae, pupae, and adults,” said researchers led by Pamela Barroso de Oliveira of the Federal University of Minas Gerais in Brazil.
“In addition to their nutritional value, insect-based food production presents several environmental advantages, including lower water consumption, reduced greenhouse gas emissions, and higher feed conversion efficiency,” they add.
Breads made with various insect flours. Image: Machado and Thys
The study includes pictures of ground cricket, mealworm sausage, and breads made from various insect-enriched flours. Look, I’m not exactly craving crickets, but maybe we should take a lesson from Simba in The Lion King, who manages to avenge a murder and reclaim a throne on what is apparently an entirely grub-based diet. Bon appetit!A glimpse of alien auroras
We’ll close, as all things should, with exciting radio signals from faraway planets.
Since the Sun spits out flares—sparking storms and brilliant auroras on Earth and other planets—scientists have wondered whether they might be able to detect the faint effects of analogous activity in other star systems. Now, one team thinks they have spotted these elusive signals.
“In the Solar System, low-frequency radio emission at frequencies ≲200 MHz is produced by acceleration processes in the Sun and in planetary magnetospheres,” said researchers led by Cyril Tasse of Sorbonne University. “Such emission has been actively searched for in other stellar systems, as it could potentially enable the study of the interactions between stars and the magnetospheres of their exoplanets.”
The team developed a new analysis method for analyzing archival data, which revealed events that are “fully compatible with radio emission generated by star–planet interactions, although an intrinsic stellar origin is still a possible explanation,” according to the study.
In other words, it will take more research to confirm the origin of this radio emission. But we may be getting a glimpse of the space weather beyond the interstellar horizon.
Thanks for reading! See you next week.
First Contact
A narrative and visual exploration of humanity’s age-old search for and fixation with extraterrestrials.First Contact explores the ancient idea—and epic ...Hachette Book Group
404 Media is publishing a version of the user guide for ELITE, which lets ICE bring up dossiers on individual people and provides a “confidence score” of their address.#ICE #palantir
Here is the User Guide for ELITE, the Tool Palantir Made for ICE
Earlier this month we revealed Immigration and Customs Enforcement (ICE) is using a Palantir tool called ELITE to decide which neighborhoods to raid.The tool lets ICE populate a map with potential deportation targets, bring up dossiers on each person, and view an address “confidence score” based on data sourced from the Department of Health and Human Services (HHS) and other government agencies. This is according to a user guide for ELITE 404 Media obtained.
404 Media is now publishing a version of that user guide so people can read it for themselves.
💡
Do you know anything else about ELITE? Do you work at Palantir, ICE, or CBP? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.This post is for subscribers only
Become a member to get access to all content
Subscribe now
A Reddit-led protest is trying to push an eight year old erotic thriller to the top of Amazon’s sales charts.#News
Erotic Parody 'Melania: Devourer of Men' Sales Surge on Amazon Amid Documentary Flop
The $75-million, Amazon-funded Melania Trump documentary is tanking at the box office, but a 2018 erotic thriller that depicts the First Lady as a sexual monster is rocketing up Amazon’s sales charts. Melania: Devourer of Men is currently an Amazon bestseller, sitting at number 3 in the “political thrillers & suspense” category in the Kindle store. A general search for "Melania" on Amazon returns a banner ad for the documentary, the First Lady's memoir, and the erotic thriller as the top results.A Reddit-led campaign to disrupt the Amazon search results for “Melania” is behind the sudden spike in popularity of the eight year old book. “This weekend, Amazon is premiering its $75 million Melania Trump documentary. It already seems to be a flop,” a post in r/BoycottUnitedStates explained. “We're going to add insult to injury by messing up Melania's Amazon search results. Specifically, we're going to amplify the paranormal erotic thriller novel Melania: Devourer of Men so it ranks higher than her movie.”
playlist.megaphone.fm?p=TBIEA2…
Part of the success of the campaign is thanks to author J.D. Boehninger’s willingness to give the book away. “A redditor reached out to me last week and asked me if I would make the book free,” the pseudonymous Boehninger told 404 Media. “They explained their reasoning, basically said they were going to try to pull this off, and why my book was the right choice. I loved the idea, so I made the book free. But that was the only role I played here.”Melania: Devourer of Men depicts the First Lady as a monster whose life is upended after her husband becomes President and she has to move from New York City to Washington DC. “Now, surrounded by young, strapping Secret Service agents and pursued by the cunning and handsome FBI director James Comey, Melania must work to keep everything from falling apart,” reads the book's description. “Because Melania has secrets of her own –– deadly secrets –– and no one yet knows how far she'll go to protect them.”
Boehninger said he wrote the book in 2018 as an experiment. “It was a test of the Kindle store algorithm,” he said. “My friend told me that three things did well back then: monster fiction, erotica, and stuff about Trump…so I figured I could write the book for the Kindle store: a combo monster fiction/ erotica/ Trump book. I thought it would blow up…but, sadly, it didn’t really perform back then. So glad to see people finding it now!”
The Melania documentary is a two hour long film / bribe directed by Brett Ratner and distributed by Amazon. The company paid $40 million for the rights to it during a bidding war. “This has to be the most expensive documentary ever made that didn’t involve music licensing,” Ted Hope, a former Amazon film executive, told The New York Times. The expense of the film and the advertising push around its release have some people believing Amazon’s support of the movie is a way for the company to get in good with the President.
In the runup to its release, the documentary has become a source of scorn from a public exhausted with all things Trump. Its wide theatrical distribution is something Amazon doesn’t do for most of its films, and certainly not its documentaries. Posting pictures of empty seats in ticket apps and defaced advertisements has become a popular pastime online. The film’s distributor in South Africa stopped its release in the country, citing “recent developments,” but would not go into specifics.
“I know blessedly little about that movie! I've seen headlines about empty theaters but I don't know much else,” Boehninger said. He thinks it’d be funny if the book sold better than the documentary, but he isn’t expecting to make a lot of money. “The ebook is free in the Kindle store, and I think that for a lot of people, giving Amazon money would probably defeat the point of this protest. That said, I've seen that some people are paying money for the paperback version and for my other book. I appreciate that!”
Amazon Best Sellers: Best Political Thrillers & Suspense
Discover the best Political Thrillers & Suspense in Best Sellers. Find the top 100 most popular items in Amazon Kindle Store Best Sellers.www.amazon.com
Senators Mark Warner and Tim Kaine asked the inspector general of the DHS about a host of surveillance technologies, including Flock, mobile phone spyware, and location data.#Impact
Senators Push for Answers on ICE's Surveillance Shopping Spree
Senators Mark Warner and Tim Kaine formally asked the inspector general of the Department of Homeland Security (DHS) to investigate and provide details on many of the surveillance technologies being used by Customs and Border Protection (CBP) and Immigration and Customs Enforcement (ICE), according to a copy of the letter shared with 404 Media.The letter touches on many of the surveillance technologies and companies that 404 Media has been writing about in recent months, including Flock license plate readers, Penlink social media and location data monitoring, Clearview AI’s facial recognition tech, Paragon Solutions’ phone hacking technology, as well as other social media scanning and biometric collection databases used by DHS in Donald Trump’s immigration crackdown.
“We are deeply concerned that ICE’s surge in brutality against American communities is being facilitated by the inappropriate and unsupervised use of surveillance technology,” the senators wrote. “As such, we formally request an investigation by your office into the methods that DHS uses to collect, retain, analyze, and use data about the communities where it operates in conjunction with the companies mentioned above, and any companies DHS is seeking to conduct business with–for similar purposes—in the future.”
The letter then demands that Joseph Cuffari, the Inspector General for DHS, provide information about how DHS obtains, processes, and stores people’s sensitive data, whether it keeps track of false positive and incorrect identities returned with its biometric surveillance tools, whether it keeps track of times its surveillance tools are used against U.S. citizens, how it shares information with private companies, and how it obtains information from other federal agencies. It also seeks information about DHS’s relationships with data brokers, whether it allows people to opt out of surveillance, and any privacy protections around some of the data it obtains.
playlist.megaphone.fm?p=TBIEA2…
While the letter itself seems unlikely to change anything about how ICE is operating in the field, these types of information gathering exercises from lawmakers often result in new details about the inner workings of surveillance programs and tools and can eventually lead to reform.“In addition to egregious practices we have seen in public reporting, it’s important that your office shine light on activities that undergird ICE’s enforcement actions including a muddled patchwork of technology procurements that have significantly expanded DHS’ ability to collect, retain, and analyze information about Americans,” they wrote. “Together, ICE’s new information collection tools potentially enable DHS to circumvent the constitutional protections provided by the Fourth Amendment—protections guaranteed to all Americans and all persons within our borders.”
The Trump administration has sought to undercut inspectors general across the federal government; soon after he was inaugurated, Trump fired at least 17 inspectors general. Cuffari, who was appointed during Trump’s first term and served under Joe Biden as well, was one of the few inspectors general who was left in his post. In 2024, an independent panel found that Cuffari had violated ethics rules during this confirmation process and recommended that he be replaced, but Biden left him in his role.
ICE Taps into Nationwide AI-Enabled Camera Network, Data Shows
Flock's automatic license plate reader (ALPR) cameras are in more than 5,000 communities around the U.S. Local police are doing lookups in the nationwide system for ICE.Jason Koebler (404 Media)