Privacy

  • |

    Google’s Public Starter Kit, Private Jackpot

    Lee Keybum here, reporting from the Terms of Surrender: Google grew inside a publicly supported scientific and technological ecosystem, then turned that runway into a private empire. That does not mean one company invented nothing. It means Big Tech loves treating public research, public infrastructure, and shared knowledge like a free starter kit while presenting concentrated wealth as the natural ending.

    Meanwhile, the ordinary user gets search results, targeted ads, another service agreement, and a privacy bargain written in font size suitable for ants. Google’s checkout screen should include a tip jar labeled “Taxpayer contribution.” The question is not whether private companies can build useful things. It is whether the public that helped make the conditions possible should receive more than the privilege of paying with attention, data, and an afternoon clicking “Agree.”

  • |

    X Terms Update: Your Post, Its Texas Courtroom

    I read X’s new terms so you do not have to, and the workplace arrangement is magnificent: you create the content, supervise the autonomous coworker, accept responsibility for the coworker’s behavior, and waive the jury if the office catches fire. X’s September 9 terms-update notice says the changes take effect October 9, while the current Terms of Service preserve users’ ownership of their posts. That sounds empowering until the rest of the paragraph arrives wearing a necktie.

    Under the agreement, X receives broad rights to process user content, including language covering the use of posts to train AI. The user keeps the deed to the house but gives the platform a very generous key, a remodeling permit, and permission to teach the robots where the bathroom is. This is the modern platform bargain: your words remain yours in the sentimental sense, while the company gets practical permission to turn them into fuel for systems you did not build and cannot inspect.

    The responsibility clause is where the unpaid internship begins. X’s updated language addresses autonomous features and places responsibility for actions connected to those features on the user under the contract. That does not mean every user has already been found legally liable for every automated mistake. It means the paperwork is preparing the user to stand beside the robot when the robot says something reckless, breaks something expensive, or starts a small diplomatic incident in the group chat.

    Then comes the courtroom-shaped furniture. The terms direct disputes toward Texas in applicable circumstances and use arbitration, class-action waivers, and jury-trial waivers where permitted. The trade reporting around the update focused on the new anti-lawsuit provision, because apparently the platform wants a social network with the legal posture of a gated industrial park. You may still have rights depending on the dispute and the law that applies, but the agreement is plainly designed to reduce the ordinary user’s leverage before the argument begins.

    So here is the fine-print version of user power: you provide the material, supervise the machine, accept the risk, travel through the Texas-and-arbitration maze, and possibly arrive without a jury or fellow users beside you. X keeps the data rights and the courtroom advantage, while you receive no wages, no benefits, and not even a decent grievance department. Still, the button says “Agree,” which is apparently how a platform turns unpaid machine supervision into empowerment.

    Sources

  • |

    The DOJ’s Paperwork Siege of the Voter Rolls

    I entered the federal filing cabinet wearing my most serious expression and found the Justice Department asking states to preserve voter records while pursuing a broader campaign for election data. Important distinction: preserving records means keeping them available for a legal dispute. It does not automatically mean releasing every voter file, and it does not prove that the records contain wrongdoing. The document coughed anyway.

    According to the Associated Press, preservation letters went to 29 states and Washington, D.C. The department has described the requests as routine litigation procedure, which is bureaucrat for “please remain calm while the machinery grows another arm.” The scale matters. A routine step normally does not arrive with this many jurisdictions, privacy objections, active court fights, and warnings about possible sanctions if records are not preserved.

    The AP report also notes that no evidence has been established of widespread election fraud. That leaves the public with a familiar government magic trick: gather a vast amount of sensitive information first, then let the existence of the information create the atmosphere of suspicion. The records may be relevant to a dispute. They are not, by their mere existence, a confession from the states or a verdict against voters.

    Meanwhile, the Brennan Center is pursuing a Freedom of Information Act case seeking records about how the Justice Department wants to gather, analyze, and use state voter-registration lists. Its case page describes a proposed September 16, 2026, production schedule, not a final ruling. So even the effort to find out what the department is doing has become another records dispute, because apparently the paperwork must first be subpoenaed from the paperwork.

    My audit finds a campaign wrapped in administrative fog: preserve everything, demand access where possible, describe the pressure as ordinary, and let the filing cabinets sweat in silence. The haunted machinery of oversight has been assembled backward. First it seizes the paperwork, then it asks the paperwork what it knows, and finally it treats the filing cabinet as a suspect for having drawers.

  • |

    ChatGPT’s Free Tier Just Found a Billion-Dollar Roommate

    OpenAI opened ChatGPT as a helpful conversation, then apparently discovered the spare room could produce a billion dollars a year. In its August 31 advertising announcement, the company said ChatGPT Ads reached a $1 billion annualized revenue run rate in under 200 days, with tens of thousands of advertisers already involved and more expansion planned. Lee Keybum has read enough terms of service to recognize the floor plan: the free assistant is becoming commercial real estate.

    That changes the ordinary-user bargain. You arrive with a homework question, a health worry, a breakup draft, or the desperate late-night search for a printer that does not require an app, and the platform sees a useful environment for advertising. OpenAI is not merely putting a billboard beside the chatbot. It is building a media business around the questions people ask when they think they are having a private-feeling conversation with software.

    OpenAI’s position is carefully drawn. Its advertising materials say ads may use conversation context to make them relevant, while advertisers cannot access private chats. The company’s ad policies also say advertising will not influence ChatGPT’s answers. Those are meaningful boundaries, and they are not the same as saying advertisers are reading everybody’s secrets or secretly rewriting every response. But privacy can be protected from direct sale while the conversation still helps organize the commercial neighborhood around the user.

    That is the part users are expected to accept with the serene confidence of someone placing a “do not touch” sign on a vending machine. The answer remains separate from the ad, OpenAI says, but the question has become valuable territory. Ask about running shoes and the platform may understand the aisle. Ask about dinner, anxiety, rent, software, or a birthday gift, and suddenly your emotional life has zoning potential.

    ChatGPT may not be selling your secrets to advertisers, but it has learned that every personal question is also a possible aisle in the digital supermarket. The chatbot insists the billboard in the kitchen is not part of dinner. Fine. Lee will still be reading the fine print before asking who gets the security deposit.

  • |

    The Government Group Chat Was Just a Church Basement

    My corkboard has reviewed the reported Minneapolis-area operation and would like to downgrade the terror network to “people with folding chairs.” According to The Associated Press, undercover federal investigators attended meetings in churches, schools, parks, and a Minneapolis library, where participants discussed peaceful protest tactics, de-escalation, police liaisons, and safety marshals. This is not exactly the command center of a supervillain empire. It is a community meeting with the same basic equipment as a church potluck and approximately the same odds of somebody losing the sign-up sheet.

    The contradiction is not that public safety concerns can never exist around protests. Of course they can. The contradiction is the reported leap from ordinary organizing to conspiracy theater. AP reported that investigators monitored chats, gathered license-plate information, and pursued financial records involving progressive groups and unions. The Minnesota Reformer described the broader surveillance effort, identified in reporting as Operation Puppet Master and Project Whipple Shield, as reaching into the organizing ecosystem around Metro Surge. The government appears to have found people discussing how to keep a protest calm and translated that into evidence of a network aiding “violent opportunists and agitators.”

    That is how the panic machine works: start with a real operation, add a frightening label, then let every normal noun report for questioning. “Safety marshal” becomes “field commander.” “Union meeting” becomes “financial node.” “Private chat” becomes “digital lair,” preferably with ominous lighting and one analyst whispering that the snacks may be encrypted. The Minnesota attorney general’s office has also issued a public statement about the DHS matter, making clear that this dispute is not merely a rumor circulating through somebody’s uncle’s group chat.

    The disclosed court materials, as reported, matter because they put the alleged threat inflation next to the mundane details investigators actually encountered. People were planning peaceful demonstrations, discussing de-escalation, and figuring out who would talk to police. Those activities may be politically inconvenient to powerful institutions, but inconvenience is not evidence of a hidden terror network. It is just democracy without a catered press conference.

    Holden’s final briefing: the supposed conspiracy had church-basement energy, while the genuinely alarming machinery was the aggressive monitoring, records collection, and institutional appetite for turning First Amendment activity into menace. Follow the thread, but check the knot. When the state benefits from keeping ordinary citizens frightened of one another, the fog is not a side effect. It is the product.

  • |

    America Bought a Surveillance Dragnet and Forgot the Employee Handbook

    The document coughed first: America had purchased a national map of where ordinary people drive, then apparently filed the employee handbook under “please use responsibly.” A Washington Post investigation reported at least 50 officers accused or charged with misusing license-plate-reader systems, including 26 cases involving intimate partners or former partners. The technology can help reconstruct a person’s movements across thousands of communities. The paperwork, meanwhile, appears to have been walking there with a carrier pigeon.

    That is the central administrative failure: the networks expanded faster than the rules explaining who may search them, for what reason, and what happens when the reason is “curiosity with a badge.” The Post described safeguards such as case-number requirements, search justifications, and routine review as optional or inconsistently enforced in many places. An audit log is not accountability if everyone treats it like a guest book at a haunted house.

    Exhibit A arrived from Reynoldsburg, Ohio. WOSU reported that two former officers may have conducted as many as 100 personal searches, including one plate searched 46 times. Those are reported allegations, not a verdict against every officer or every agency using the technology. But the numbers do explain why “the system keeps a record” is not a complete safety plan. A burglar alarm also keeps a record after the window is broken.

    The institutional contradiction is almost too tidy for government: a search can be technologically easy while the justification, review, and consequences remain bureaucratically foggy. Police agencies and vendors helped install a tool capable of tracing ordinary travel before dependable controls became routine. The public received the movement map first and the policy memo later, possibly after someone found it beneath a stack of procurement confetti.

    My mock finding, after an afternoon in the records room, is that the real suspect is not only the officer who found the search button. It is the missing policy that left the button glowing in the dark. The recommended form now includes a checkbox labeled: “Why did this officer look up an ex?” Beneath it: “Please use responsibly.” The filing blinked. Nobody called it accountability.

  • Google’s New Terms Say the Fine Print Is Getting Easier—Please Ignore the Bigger Fine Print

    Lee Keybum read Google’s new U.S. Terms of Service so you could keep your afternoon, and the friendly customer-service voice is impressive. Google says the updated terms, effective July 30, 2026, are easier to understand. That is probably true in the same way a landlord’s new note saying “the rent goes up because we love transparency” is easier to understand. The user clicks agree; Google keeps the steering wheel.

    The clearer wording does not turn the relationship into a democracy. Google’s terms still explain that the company may use automated systems to analyze content, change or remove services, and make users responsible for network usage tied to using those services. None of that automatically means a human is personally reading every message. It does mean the platform is reserving broad room to inspect, adjust, and sometimes rearrange the digital furniture while the customer is standing in the hallway holding the Wi-Fi password.

    Then comes the liability section, where the warm corporate smile briefly loses power. For covered disputes, the terms limit liability to the greater of $200 or the fees paid to Google during the previous 12 months. That is a very precise number, which is comforting until you remember that precision can also be used to label the size of the life raft. Google has built a whole cloud empire, but the emergency boat has the dimensions of a modest dinner check.

    This is the Big Tech makeover: make the language less intimidating while preserving the practical arrangement. Google can analyze content through automated processes, change or remove parts of the service, leave network costs with the user, and limit what the company may owe if the relationship goes sideways. Those provisions may be disclosed plainly, but plain disclosure is not the same thing as equal power. A user can understand the house rules perfectly and still not get a vote on the house.

    So yes, Google translated the fine print into clearer English. The translation reads: welcome to the kingdom, subject to kingdom rules. The login ate your afternoon, the platform kept the castle, and your legal recovery may be $200 or 12 months of fees—whichever is greater. At least now the moat has better documentation.

  • |

    AdaptHealth’s “Password File” Got Exfiltrated, So Now Everyone Pays the Bill Twice

    I don’t get hacked. I get audited.

    AdaptHealth says it “contained” the breach, which is adorable—like telling me the house fire is under control because the office paperwork is still on the desk. Their disclosure also points to the real culprit: attackers exfiltrated a stored “password file” tied to insurance-billing systems. That’s not just “data” in the abstract. That’s the credential plumbing that makes patient portals and billing workflows actually work—right up until it doesn’t.

    The company’s version of events is basically: an approach involving social engineering aimed at a third-party contractor session, followed by containment steps so AdaptHealth can keep servicing patients. But the contradiction audit is still doing laps: they say the incident is contained, yet they also confirm stolen insurance-billing passwords plus related personal information (and categories that may include sensitive health-related information). And they also say full scope/impact details aren’t determined yet—so the only outcome we can count on with certainty is the one users already recognize.

    Reset loops. Identity checks. Another “please verify” email that pops up like it’s subscription-based. Because when the password machinery gets taken, you don’t just lose access—you inherit the administrative chore list. PR math says “contained!” Patient math says “cool, so which portal do I have to reset again?”

    AdaptHealth’s contained narrative may be good for operations. But for ordinary people, “contained” still lands like this: the same system that helps you handle coverage and payments has been turned into a recurring “prove you’re you” obstacle course—twice, because apparently the bill always comes due.

  • |

    Apple Adds “Social Media” to the App Age Questionnaire (Because Your Kids’ Feeds Are Now a Form Field)

    Apple’s latest kid-safety update is “for families,” unless your family is a developer filling out paperwork. Then it’s for the form. Somewhere in App Store Connect, “social media” has become a selectable capability that determines how Time Allowances treats the app—because nothing says protection like turning your child’s feed into whichever bubble the questionnaire thinks is closest.

    Here’s the human version: an app’s social-media capabilities—redistributing/amplifying/interacting with user-generated content through a feed—map to a “Social Media” content descriptor. After that, the app-time system can route that app into the Time Allowances “Social Media” grouping, and under-13 handling follows whatever Apple’s rules say to do next. Depending on the setup, that can mean disabling social-media experiences for under-13 users or using Apple’s Declared Age Range API to confirm age ranges. Parenting, but make it a deadline-driven scheduling boss fight.

    And yes, Apple can tell the story as “parents get better tools.” But the mechanism is the opposite of what you’d want from a privacy promise: the outcome hinges on whether a developer clicked the right capability box—and whether their age-range declarations line up with what’s actually inside the app. That’s not magic parental empowerment; that’s compliance UI acting like a toll booth, where “agree” is the cart that rolls your assumptions straight into the platform’s sorting hat.

    This is the part where the crowd goes “wait, really?” and Apple goes “Terms of Surrender, we’ve always been this way.” The joke is that the “agree” step doesn’t just take your lunch money—it takes your kids’ feed and labels it by the nearest form field. Privacy should protect humans; instead, it’s scheduled by checkbox.

  • |

    BREAKING: The Fourth Amendment Needs a Warrant (and the Internet Immediately Starts Yelling Inaccurately)

    The algorithm wore a trench coat and slipped into the group chat with one scary sentence: “warrant/probable-cause style justification.” Immediately everyone installed a software update with two buttons—“SAFE FOREVER” on the left and “MEH, THEY STILL GOT YOU” on the right—and neither one matched what the Court actually did. Which, honestly, is how you can tell it wasn’t a legal system making people mad; it was the mood machine.

    In Chatrie v. United States (June 29, 2026), the Supreme Court treated access to cellphone geofence location history as a Fourth Amendment search. That matters because “Fourth Amendment search” is the Court’s way of saying the government doesn’t get to grab people’s location past history on vibes alone. The majority logic requires constitutional justification—warrant-like scrutiny—before location-history gets pulled into an investigation.

    Here’s where the contradiction audit kicks in. One headline-taking tribe turned that “needs constitutional justification” into an instant privacy apocalypse off-switch: case closed, they can’t track you anymore, go back to your brunch. Another tribe reacted by flipping the same sentence into a different prophecy: “nothing changed,” because paperwork always drifts, and the world is already doomed anyway. Both groups are performing the same error—taking a specific legal rule and translating it into a yes/no worldview setting.

    And the panic boutique loves this conversion rate. When you flatten “search + constitutional justification” into either “safe forever” or “they still got you,” you stop people from asking the one question that actually keeps you free: what process is required for this specific kind of location-history access? In other words, the real surveillance isn’t just the government’s—it’s the platforms’ ability to keep turning legal nuance into an anxiety scoreboard.

    The practical payoff is simple: the internet didn’t get a new privacy right, and it didn’t get a new surveillance guarantee. It got a new misunderstanding. Rights arrive with standards and conditions, not push notifications. So if your group chat insists the Supreme Court delivered a total apocalypse toggle either way, maybe don’t argue the legal holding—just follow the thread but check the knot, because that knot is misinformation wearing a confidence suit.

End of content

End of content