Last year, as decades of work by RFK Jr. to undermine vaccines with false links to deaths and autism culminated in his appointment to lead HHS, America saw the largest resurgence of measles cases in something like three decades. Three people died, including two children, all unvaccinated. Kennedy mostly ignored the outbreak from the beginning and has since only mustered the ability to say that people should get the MMR vaccine out of one side of his mouth while reminding everyone that he thinks vaccines are bad out of the other. Measles continued to roar into 2026, with Kennedy and HHS officials attempting to downplay case counts and deaths the entire time. We’ve already eclipsed 2025’s record-breaking case count here in 2026 and we still have months to add to that total.
And now we have our first two deaths from measles in 2026, as well. Both occurred in Pennsylvania and, while health officials aren’t releasing many details due to privacy concerns, it was noted that both of the deceased were unvaccinated for measles.
Citing privacy, health officials in Pennsylvania are not providing information on the people who died beyond that they were unvaccinated and were residents of Lancaster County. Officials noted that the deaths are among 393 confirmed cases reported this year across 28 counties in the state.
As we talked about recently, due directly to the decades of work Kennedy has taken to undermine vaccines, vaccination rates for school children have and are continuing to fall. These deaths, and the vast majority of the case counts, are completely needless. We have the solution to preventing them. The MMR vaccine is safe and effective for those that are not immunocompromised. There is no scientific reason to believe it causes autism. And, importantly, if 95% of us get vaccinated against measles, we achieve herd immunity which protects those that can’t get vaccinated, as well as very young children who haven’t been vaccinated yet.
And that last category is one that is likely to grow, thanks to the Trump administration’s blatantly stupid executive order attempting to curtail how childhood vaccines are delivered and when. Not to mention the constant muddy waters Kennedy himself creates as to whether vaccines are good or bad, when they are so, what risks they carry, and so on. It is not an overreach to say that this administration, and Kennedy’s decades of bullshit in particular, got these people killed.
Still, anti-vaccine rhetoric, misinformation, and disinformation have shaken confidence in the vaccine, driving down vaccination rates. Some of that damaging discourse has come from Trump administration officials, most notably ardent anti-vaccine activist Robert F. Kennedy Jr., who is currently the US health secretary. But President Trump has also contributed, falsely claiming in a White House press event two weeks ago that the MMR vaccine can be “quite lethal.” The MMR vaccine has never been linked to a death in a person with a competent immune system (it’s not recommended in those who are immunocompromised).
One hundred percent correct. People look to their leaders for guidance on things like public health. Or they used to, at least. For some non-insignificant percentage of the country, they really do think Trump and Kennedy know what they’re talking about when it comes to matters of medicine. They don’t, of course. Not even close. But enough people are listening to them that it puts all of us in danger.
This has to end. Outbreaks of infectious diseases at the level of the measles tend to grow exponentially if not addressed. That’s why we’re already past last year’s case count. The project for getting back to herd immunity and proper vaccination rates will not be a short one. It will take years.
And I very much doubt that we won’t pass the death count here before the end of the year as well.
By now you’ve almost certainly heard the news that Meta has settled with 52 state and local Attorneys General who had sued the company in some form or another over child safety on Meta’s platforms. The headlines are all covering the basics: the years-long case these states filed against Meta ends, and Meta pays somewhere between $12.7 billion and $18 billion, depending on which document you read (the consent judgment itself caps the total at $16,680,647,753.21; Meta’s press release rounds it up to “approximately $18 billion”). Also Meta will implement a bunch of changes to its platforms with the aim of improving child safety on those platforms. It will also “encourage” YouTube and TikTok to enable the same safety features even though (bizarrely), if YouTube and TikTok follow suit, then Meta will have to pay more.
Notably, the whole point of doing this as a “settlement” is that everyone involved knows full well that no government could mandate these feature changes without violating the First Amendment. But now that it’s in a “settlement” the courts may need to explore if these choices — which Meta could make freely on its own — suddenly have become a “state action,” implicating the First Amendment.
As with the various rulings against Meta over the last few months, people are cheering this on, without realizing the damage it will do. We’ll explore why this is problematic in a moment, but just to highlight that I’m not alone in thinking so, both EFF and Fight for the Future are warning how bad this settlement is. Here’s EFF:
Underthis settlement, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collection of even more personal information from users of all ages; this enshrines Meta’s harmful surveillance into law, and it will compromise users’ privacy and anonymity while increasing their exposure to data breaches and government data requests. And the data minimization and security measures don’t keep states from using data collected under the agreement for other law enforcement purposes – which could include things like criminal investigations of abortions or gender-affirming care.
And here’s Fight’s emailed statement:
Big Tech does pose harm to our kids through its business practices and exploitation, but pushing for more censorship, age-gating, and surveillance of young people at the hands of the same Big Tech companies that have already harmed young people is not the answer. Online ID checks when implemented put vital information behind age-gates, stamp down teenagers’ right to speak, and expose all of us to even more of our data being collected, hacked, and leaked. Meta knows that managing this amount of personal information and enforcing these agegates will be messy and that’s why they are seeking to offload the burden to anyone but themselves, while being seen to comply by the public and lawmakers. Instead of actually damaging their exploitative business model, this result allows Meta to bring everyone else down with them, from app stores to other social media companies. We feared that these lawsuits would manufacture consent for invasive age verification and content controls and our fears have been proven correct. We will continue to oppose online ID checks everywhere and be on the watch for more censorship creeping into Meta’s platform.
We’ll get into the specifics of why this settlement is so bad, but first some important background. For a few decades now, when basically all Attorneys General would get together to threaten and/or sue tech companies, it was almost always over bullshit headline grabbing claims where the AGs either had no jurisdiction or ability to legally do anything. Sixteen years ago, we wrote one story about an account written by a CEO of a company who faced down dozens of state AGs who were way more concerned about the headlines they generated than actually making platforms safe.
It was similar to other stories that we’d heard, where no matter what companies did to explain to the AGs what steps they were taking to keep a platform safe the AGs would simply turn around and misrepresent what they were told, out of context, to make the platforms look worse and worse until they agreed to some sort of settlement. It happened with Craigslist. It happened with ISPs being forced to kick their users off at the behest of the recording industry. Even John Oliver has covered how grandstanding state Attorneys General will target just about anyone they want to shake down in some form or another.
That’s not to say that there aren’t righteous cases brought by Attorneys General, but there are so many examples of them being much more about getting headlines than actually making people safer. And the simple fact is that these efforts are so resource intensive, so expensive, and so draining that it’s no surprise that most companies end up “settling” by agreeing to do things that the government simply cannot force a company to do. But because it’s a “settlement” people act like it’s not the government doing it.
In this case, given some of the recent court decisions, it’s no surprise that Meta would strike some sort of settlement. As these cases continued, the headlines would only get worse for the company. And Meta deserves some bad headlines, but as I’ve discussed, many of the bad headlines in these cases involved lawyers and the media taking things way out of context. The classic case with Meta is that many of its efforts to study how to make its platforms safer were used against the company as proof that “they knew!” their platforms were unsafe!
The lesson for the rest of the tech industry is grim and unambiguous: never study whether your own platform is causing harm. The mere existence of the research will be turned into Exhibit A that “they knew,” both in the court of public opinion and in actual courts.
The other bit of background worth understanding here is that Meta has been desperately seeking a path to regulatory capture for quite some time now. It’s been practically begging for Congress to pass child safety legislation that only the largest companies (like itself) could comply with. Indeed, Meta has done this before. It went against the rest of the internet industry in embracing FOSTA, again to try to create a regulatory moat. So this shouldn’t be surprising.
Meta’s failed forays into the “metaverse” and AI have shown that it’s been pretty consistently losing the innovation race, and the government granting it a regulatory moat that smaller competitors can’t cross would be a godsend.
And it’s even better when it can be done in a way that looks like Meta “losing” a lawsuit.
So that’s what Meta gets here. They “settle” the lawsuit so the AGs and Meta haters can all claim that they’ve “protected the children.” Meta pays out over a decade — enough that it’s taking a $10 billion legal charge in Q3, which stings for a bit but will mostly be forgotten by next year. Meta can easily eat the cost. And then Meta agrees to implement a bunch of kid safety features, most of which we have no idea whether they actually protect any kids. Notably, a legislature could not have mandated most of these features without running straight into the First Amendment — but coming out of a settlement, they carry the imprimatur of law anyway (more on that in a moment), and the structure of the agreement makes it so that Meta has to actively encourage Google and TikTok to take identical steps, thereby setting in concrete what steps any platform will have to take to be considered following “best practices” and therefore acceptable to most of the country’s Attorneys General.
The specific features don’t even matter that much, but for the record:
Time Limit:A default two-hour daily time limit that teens can only turn off with a parent’s permission. This limit is cumulative across Facebook and Instagram, and time spent scrolling on both apps counts toward the total, including if we detect that someone has multiple accounts.
Night Mode:A default block from our apps between midnight and 6am. This means teens will not be able to post or view their Feed, Stories, Explore, or Reels, for example.
School Mode:Notifications will be muted by default between 8 AM and 3 PM. During those hours, teens will no longer receive push notifications, except for direct messages and alerts about their account security or safety.
Regular Prompts:Teens will receive prompts after every 15 minutes of continuous screen time on Facebook or Instagram. They’ll also receive prompts when their total daily usage hits 60 minutes and 90 minutes. These prompts are designed to encourage intentional use.
Algorithmic Feed Control:Teens will be able to choose a non-algorithmic feed — one that isn’t personalized by our recommendation systems — as their default. We will periodically remind them of this option, and parents can choose to adjust their teen’s default experience to require this setting.
Autoplay Control:Teens will be able to turn off autoplay, so that content no longer automatically plays. Instead, they’ll need to take a deliberate action, like a tap or swipe, to see more. Parents can choose to adjust their teen’s default experience to require this setting.
Hidden Likes:Teens won’t see the number of likes and reactions on posts — both their own and those from others — by default.
Disabling cosmetic surgery and extreme makeup filters:In addition to our existing policy to block teens from using cosmetic surgery filters, we’ll now block teens from using extreme makeup filters.
Age Assurance:We work hard to find and remove underage accounts from our apps and, as part of our agreement, we’re investing in even stronger technology to proactively catch accounts that may belong to under-13s. We’re also strengthening the technology we use to identify accounts that may be between the ages of 13 and 17, so we can ensure those accounts are placed in experiences designed for teens, even if they give us an adult birthday. However, to ensure teens are consistently protected across the many apps they use, app stores must provide developers with verified age information. This will allow platforms to put age-appropriate protections in place for as many teens as possible. That’s why we’ll continue toadvocate for legislationthat empowers parents by requiring app stores to verify age and obtain parental approval before a teen downloads an app.
Age-appropriate content restrictions:We will maintain our current content standards so that, by default, teens are placed into 13+ content settings, inspired by movie ratings criteria and parent feedback. We will also continue to prevent teens from following or interacting with accounts we consider age-inappropriate. We will work to continually improve these systems to ensure age-appropriate content experiences for teens.
Unwanted contact from strangers:We will maintain our current practices of defaulting teens into private accounts on Instagram and private default settings on Facebook, and we’ll continue to restrict potentially suspicious adults from contacting them. We will also strengthen our efforts to make it harder for those adults to find, follow, or interact with teens.
Reporting and ongoing protection from harmful content:We will continue to give teens easy ways to report content that concerns them, and we’ll work to improve our response times. We will also continue our work to protect teens from potentially harmful experiences by regularly evaluating how often teens are exposed to them. We’ll draw on research and expert input to improve our work.
Strengthening our parental controls:We will encourage parents to set up our supervision tools and give them new controls and insights. This includes notifying parents when a teen links a secondary account, alerting them to interactions with potentially suspicious accounts, and providing periodic updates on their teen’s usage and any changes their teen attempts to make to their protective settings.
Some of those might be good features. Some of them might not be. Some of them might be good for some kids, but very bad for other kids.
Part of the problem is we really don’t know.
There is something of an accountability structure here too. Meta and the states will appoint an “independent” auditor for five years, and the age assurance system gets tested annually to meet certain thresholds. But it’s important to look at what’s actually being audited here. It’s whether or not Meta is implementing the things it’s promised to do, not whether any of those things actually work.
But now these are, effectively, mandated by law. Even though if Congress or the states had passed a law requiring these, it would almost certainly be thrown out as unconstitutional under the First Amendment.
The weirdest part of the agreement is that Meta has to try to convince Google (YouTube) and TikTok to implement some (but not all?) of these same features. Indeed, Meta has already put up a settlement-mandated open letter to those two companies asking them to implement those features.
What’s so weird is that if YouTube and TikTok agree to do this and to voluntarily throw billions of dollars at the states, then Meta also needs to pay more. The breakdown of the money Meta owes is partially dependent on them arm-twisting those two companies to do the same things:
The agreement includes a payment of approximately $18 billion, which can be used to fund youth online safety initiatives, among other state priorities. The payment will be distributed in annual installments over a 10-year period. Participating states will receive approximately 70% (approximately $12.7 billion) of the allocated payment over the decade. The remaining 30% (approximately $5.3 billion) will be released only after two specific conditions are met.
YouTube and TikTok implement a one-hour Daily Limit, Night Mode, and age assurance measures.
YouTube and TikTok each pay an amount matching the 30% figure, with half of the remaining funds tied to YouTube’s payment and half tied to TikTok’s.
You can argue that Meta might not actually want YouTube and TikTok to do this, so they won’t have to pay that extra $5.3 billion, but from a competitive standpoint, you have to think that Meta absolutely needs to have YouTube and TikTok implement these features or its already somewhat dwindling market share will dwindle faster.
It’s quite possible that YouTube and TikTok will go along with this, rather than get bogged down in a similarly costly legal fight. But, again, that would create many problems. First, we still don’t know if those feature changes are actually helpful or effective. But now they’re effectively government mandated.
In theory, this could open up room for other platforms to come in and sweep up the youth market by not implementing these same features. But the nature of this agreement is that if the state AGs suddenly feel like any platform is becoming too popular with the kids, it can point to this agreement and call it “industry standard” or “industry best practices” to insinuate that other companies not doing the same are deliberately choosing to keep kids unsafe.
Indeed, within the agreement there’s a bit of weirdness, in which Meta has to push for “industry wide adoption” which is currently defined as YouTube and TikTok, but which the agreement makes clear could include any new social media platform if such a new platform meets the thresholds. In other words, Meta is basically being forced into guaranteeing this settlement creates an industry-wide standard.
And that’s a real problem when we still don’t know how to actually help keep kids safer online. So if a web service comes up with a unique or innovative or different idea that works differently than what Meta has agreed to do, then that may be too risky to even try. Better to just follow what the AGs have “blessed” in this settlement.
As noted, we already know that some of these things are directly harmful. Age assurance is a privacy nightmare. Enshrining it as the industry standard means the end of meaningful online anonymity, and it “forces” Meta to collect more data about all of us — including adults — while handing the states a pipeline to that data for whatever else they decide it’s useful for.
That’s bad.
Also, there are some oddly specific requirements:
Meta SMPs will disable Teen Users from applying Cosmetic Procedure Filters to their content.
The agreement clarifies that this means:
… any digital filter or augmented reality (AR) effect that distorts, sculpts, redefines, or idealizes a user’s face in a way that cannot be achieved without cosmetic surgery or extreme makeup techniques.
And, sure, I can understand why such content might be unhealthy for teens. But it is, in fact, Constitutionally-protected speech. Meta could decide internally to block that speech specifically on its own platform (that’s its own editorial right). But now that it’s being done at the behest of government pressure, it almost certainly violates the First Amendment.
Also, somewhat oddly, some of the rules appear to only apply to content in English or Spanish:
With respect to Potentially Harmful Reported Content submitted in English or Spanish, Meta SMPs shall maintain processes designed to permit Teen Users to receive a response indicating Meta’s decision on the report within 6 hours in at least 90% of cases.
The implication is obvious: those are the languages most reports come in, and Meta is expected to staff up enough to clear them fast. But it also means the government has just negotiated a moderation service level that varies by the language you happen to speak — English and Spanish speakers get a six-hour guarantee, Tagalog and Mandarin speakers get whatever Meta feels like. That’s a strange thing for a state to be dictating at all.
This is also a perfect example of the kind of standard that only a giant can meet. A six-hour turnaround on 90% of reports is achievable when you have thousands of trust & safety staff and a decade of tooling. For a startup with four employees and a Discord server, it’s a fantasy — and now it’s the benchmark against which every AG will measure them.
So what happens now? The judge will need to review the settlement, but I’m actually wondering if some teenage users would have standing to challenge this. Meta is clearly restricting First Amendment protected speech under this agreement. It is free to do so on its own if it chooses to do so, but this is different. Here it’s doing so because it’s being forced to by various state AGs, making it a state action.
Under the Supreme Court’s recent (unanimous) Vullo decision, that seems pretty clearly unconstitutional. In that case,the justices said, quite clearly:
[A] government official cannot do indirectly what she is barred from doing directly: A government official cannot coerce a private party to punish or suppress disfavored speech on her behalf.
That seems like it should be the whole ballgame, because that’s what’s happening here.
One other point on all of this. Here’s the list of 52 Attorneys General that have agreed to this settlement:
Alabama, Alaska, American Samoa, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, District of Columbia, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, N. Mariana Islands, Nebraska, Nevada, New Hampshire, New Jersey, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Puerto Rico, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.
Notice anyone missing? Yup. There’s no New Mexico. Remember, New Mexico won its initial case against Meta recently, enabling the judge to force a different set of feature changes on the company. So… now Meta may have certain features for New Mexico, and different features for everywhere else?
None of this is to say that Meta shouldn’t do a better job trying to protect kids on its platform. Obviously, it can certainly do more. But this settlement seems much more like Meta using this case as a way to force the industry into a set of required steps (which might not help much, and may do real harm in some cases), making it difficult for smaller competitors to enter the market, and giving them a bit of regulatory capture through mass lawsuit settlement.
As law professor Jess Miers wrote, this settlement is about Meta selling out the entire social media industry, forcing them to embrace impractical and unhelpful features that serve only to lock in giants and lock out upstarts:
Meta sold out the entire social media industry today by signing all UGC services up for standards that are neither practical nor something the government actually has the right to mandate. This is precisely why I am not confident in them defending 230 at SCOTUS either in the Nevada case.
But for all the people “celebrating” this as a win “against” Meta, you’ve been fooled. Meta just cut a deal to put itself in charge of how social media works going forward. As Justin Maurer wrote on Bluesky, this is Meta taking a “please regulate me Daddy” approach to the government, and getting exactly what it really has been asking for.
We still don’t have any actual evidence that this will help anyone, let alone every kid. The state AGs didn’t have to prove how this would help kids. Meta didn’t have to prove it. The judge won’t be asked to. It’s just taken on faith. Meta offered this up, the AGs okayed it… and it all becomes a grand experiment on kids.
You can argue that these feature changes sound like they should help kids. Limiting access to two hours a day (unless parents grant more, which many will), lights out at midnight, disappearing like counts — these all sound like they’ll help some kids. But if it turns out that locking kids out of these systems actually pushes the most vulnerable ones to darker places with no trust & safety team at all, you won’t hear about that from Meta or the AGs.
We just spent three years teaching the entire industry that if you do research on child safety, you’ll have it held against you. Do we really think that all of this is going to actually enable anyone to figure out what works to help actual kids?
Meta bought itself a moat. The AGs bought themselves headlines that will be useful next election season. And every teenager in the country was just automatically enrolled in an untested experiment. There’s a five year independent auditor requirement to confirm that Meta follows the rules. But not to see if the rules work.
The thing about raiding law offices is that they tend to be filled with people who actually know the law. A bunch of opportunistic ICE officers thought they might be able to talk their way into an illegal search, but that initiative (is that the word for this?) died out almost immediately when the interloping officers were greeted by a small group of immigration lawyers.
As is to be expected, this attempted illegal raid occurred in a “blue” state — the states that are still seeing large amounts of immigration officer activity just because their populations refused to throw a majority of their support behind Donald Trump during the last three elections.
Multiple U.S. Immigration Customs and Enforcement agents armed with guns attempted to inspect a Sacramento immigration law firm — and threatened to return later and break windows — on Friday morning, according to several employees of the building.
Employees of the North Natomas law firm and next door dentistry office said the agents, who arrived in at least four vehicles, claimed to have received a list from Washington, D.C., which listed the building’s address as the primary mailing address for many people. The ICE agents requested to tour the office for beds, but were ultimately turned away after failing to provide a warrant.
You can see the pretense. And you can see how everyone else would have recognized it was a pretense, even if the ICE officers hadn’t backed down immediately in the face of “get a warrant” demands from the occupants of the law office.
ICE pretended that a lot of migrants using the law office as a mailing address (something likely limited to court documents, etc.) was evidence that the law office was illegally housing dozens of migrants. But, as a migrant trying to work your way through the immigration system, it just makes sense to list a law office as the address of contact when engaging court proceedings, especially if your housing situation may be in a constant state of flux. Telling courts to send summons, notices, etc. to your legal reps is the smart way to handle things like naturalization proceedings, given that the rules seem to keep changing, and our current government is doing whatever it can to disrupt immigration proceedings to maximize arrests and detentions.
It would be immediately clear to anyone but an opportunistic ICE thug that the Morris Law Office was incapable of housing a large number of migrants. It’s a strip mall law office that shares a building with a dental implant clinic.
Having rushed directly into a stone wall composed of well-composed immigration lawyers (as well as the absolute stupidity of having to pretend a strip mall law office could be a second home for a large number of migrants), ICE officers retreated empty-handed, but not before issuing a threat that only later proved to be as empty as their fingerless gloved hands:
Raissa Morris, owner of the Morris Law Group, received a text at 9:16 a.m. which read “immigration is here.” The message came from one of her employees who told her an agent, who was armed and wearing an ICE badge, had entered the front lobby and asked to speak to an office manager.
She quickly told one of her employees to tell an agent that they could not inspect the building without a warrant. The agent responded by saying that they had received a list from Washington, D.C., which featured multiple clients using the law firm’s address. He asked to inspect the office for beds and said if they received follow-up orders that they could return at 3 a.m. to break windows and enter.
Thugs to the very end. “If you won’t let us abuse our power and ignore your rights, we’ll just ask someone back at the office to swear out some paperwork that will let us get what we want without your cooperation.” Obviously, this paraphrasing is far more coherent and polite than anything uttered by your average ICE officer (and, at this point, almost any ICE officer would be lucky to be considered “average”). But the ultimate point remains: if ICE doesn’t get what it wants immediately, it will find a way to get it eventually.
Additional coverage by local news station KCRA includes some on-site reporting, along with screenshots of several photos of ICE vehicles shared by law firm employees. It also includes a comment from the DHS, which apparently couldn’t be bothered to respond to questions from reporters at the publication that first broke the news.
In a statement to KCRA 3, DHS said, “On August 14, ICE officers approached an unmarked door during a targeted enforcement operation, thinking it was the target address as it was listed as the address of the illegal aliens they were planning to arrest. Upon finding out it was a law firm; they departed the address.”
This statement is only true if you ignore the officers’ attempt to engage in a warrantless search, as well as the parting threat they issued when they were ejected by Morris Law employees. ICE had to know it was a law firm because that would be the first result in any normal search of that address. And officers couldn’t pretend it was just some hostel for migrants when they rolled up in at least four separate unmarked vehicles. They were clearly in a quasi-strip mall parking lot facing a business with the business name clearly displayed above the address the DHS now claims was so inscrutable it took an accosting and a confrontation with people who actually know and respect the law to inform the officers of their “mistake.”
The DHS statement is idiotic, which just means it’s on-brand for this administration. So far, the threat to come back and break windows while no one’s in the office has yet to materialize. But this government is filled with sore losers and sore winners (that would be the big baby boy sitting behind the Resolute Desk), so I wouldn’t put any money on ICE just taking this L and moving on to other things.
Imagine a scenario where a documentary filmmaker, in the course of making the documentary, captures some damning footage of corporate malfeasance, which she wishes to share with an investigative reporting organization anonymously. Should we be concerned that mandates on AI watermarking might reveal who she is, even if she’s not using AI at all?
Last week I pointed out some of the concerns I had with Anthropic’s AI-generated text watermarking implementation. As I explained, plenty of people use these tools for perfectly legitimate reasons. I talked specifically about non-native English speakers and some disabled communities, and how a label as binary as “some AI was used on this” inevitably lumps those uses in with all the genuinely bad ones.
A friend pointed me to a separate concern that I had not considered, from the human rights group WITNESS. I should say that WITNESS is generally supportive of AI transparency rules, and was apparently involved in the process to create the EU’s Code of Practice related to the rules that forced Anthropic to add these watermarks. But, for obvious reasons, it’s concerned about the privacy implications of these tools. Indeed, it released a fascinating report about how watermarking done badly represents a surveillance risk.
The scenario I described to open this piece comes straight from that report:
Her production software is C2PA-enabled.
She uses it because her international distribution partners require it. When she installed it, the setup asked for her name, email, and country. Standard fields. She completed them and started working.
What the setup process did not explain is that the software’s default configuration attaches her account details to the Content Credentials of every file she exports, via the CAWG identity extension. The option to disable this exists, in an advanced settings panel she has never opened, described in language that assumes familiarity with the C2PA specifications.
For most of the year this does not matter. Then, in the final weeks of production, she films something unplanned: a confrontation between managers and workers organizing without official recognition. She decides to submit the clip anonymously to a press freedom organization abroad. She exports it without checking the Content Credentials panel, because she does not know there is anything there that needs checking.
Her name travels with the file.
The report focuses on C2PA, which is the emerging standard most companies are using for non-text watermarking (for images, videos, etc.). It was put together by a bunch of the tech companies to solve their own problems regarding identifying AI-generated content. But with the EU’s AI Act and similar laws showing up, it’s getting pulled from “here’s a nifty tech solution” into “this is part of the law.” And, as the report notes, the current implementation can be abused for surveillance:
The populations most exposed are journalists, human rights defenders, and documentary filmmakers. For these groups, content provenance infrastructure creates a distinct and underappreciated surveillance surface: one that links identity to specific digital content with cryptographic precision, accumulates into detailed behavioral profiles over time, and is made harder to contest by the regulatory legitimacy surrounding it. Viewers of credentialed content face their own exposure: the act of verifying content can generate a behavioral record without their knowledge or consent.
This doesn’t mean that watermarking shouldn’t be used, but rather, as WITNESS notes, we should be aware of the risks, and seek to counter them.
The report lists multiple ways that “provenance” tools like watermarking can expose personal information. The most obvious: once watermarking is mandatory, piggybacking identity requirements on top of it becomes trivial — which, in practice, means close to inevitable:
The first is legislative and regulatory misuse. A government that understands the C2PA’s privacy surface can exploit it deliberately — through mandated identity assertions, required credentials as a condition of distribution, or convergence with national identity systems. The more likely near-term risk, however, may be a well-intentioned regulator who mandates C2PA-compliant credentials without understanding what that mandate activates. The outcome can be functionally identical to deliberate misuse.
While the report doesn’t say this quite so directly, you can see how mandates for this technology, combined with growing mandates for age or identity verification, could do real damage:
Identity can be required as a condition of creating or distributing content. A law or platform policy may require attaching personal information to Content Credentials before content can be published or distributed. The C2PA specification does not prohibit this as mandatory identity assertions may, in specific use cases, be a legitimate use of the standard. A government mandate requiring journalists to register their identity with a national authority before their content can carry verified credentials would require no modification to the specifications whatsoever, and would not be distinguishable, at the infrastructure layer, from those legitimate uses
We already have governments increasingly requiring everyone to prove their identity in some form before they can look at content. The provenance mandates are something of a mirror image: a mandate to prove who is creating the content before you can publish it. And that mandate is being dressed up as an anti-disinformation tool wrapped in a human rights cloak, making it way more difficult to push back on than a state porn-ID law. And that’s before we mention how the “AI” component leads many people who would otherwise be careful about tech mandates to scream “fuck AI, do this!”
The report also points out that content creators may not realize what information gets included in a watermark.
Personally identifiable information can be added by the user — inadvertently, or without being informed of the privacy implications of doing so. Content Credentials can carry personal information added by the creator—a name, a caption, a device identifier—without the tool surfacing what that disclosure means or who can access it. The harm is not always intentional on the part of the platform: tool design that prioritizes functionality over privacy literacy can produce the same outcome as deliberate data collection. A photographer including personal attribution to an image may not realize that information will travel permanently with the file, accessible to anyone who inspects the manifest.
Even in cases where people think they’re being careful, a pattern may still emerge that reveals sensitive information:
Identity can emerge from patterns across a body of published work.
Identity may become recoverable not from an individual manifest but from correlating assertions across a body of work over time— locations, timestamps, device identifiers, behavioral signatures—none of which individually crosses a sensitivity threshold, but which together build a detailed profile. For example, a state actor scraping a manifest store to map the movement patterns of an activist photographer across months of published work would not need access to any single sensitive file.
And perhaps worst of all, the final risk they highlight is that simply the act of verifying the provenance of some form of media requires interacting with third parties that may reveal some amount of information:
Engaging with Content Credentials exposes creator and audience behavior to third parties. Engaging with Content Credentials — whether as a creator signing content or as an audience member verifying it — can expose behavior to third parties. On the creation side, signing operations that require external connections for timestamping, certificate status checks, or manifest store submission generate server-side records linking the creator’s device, location, and timestamp to a specific piece of content, without any disclosure that this is occurring. On the verification side, depending on implementation, remote validation may require the viewer’s device to contact an external server directly, generating a logged request that records who verified what, from where, and when. In neither case does the affected party have awareness that this is happening or any means of refusing it: unlike cookies or tracking pixels, the C2PA specifications include no consent mechanism, no opt-out, and no disclosure requirements. A journalist signing footage before publication may unknowingly leave a server-side trace of that act. A reader who encounters a suspicious image on social media and verifies its provenance may unknowingly send a request associating their IP address, approximate location, and timestamp with that specific piece of content. At scale, across a platform or a jurisdiction, these logs become a map of who is creating what and who is reading what, where and when.
While the descriptions of the surveillance threats from the tech are good, what drives it home are some of the fictional scenarios that are absolutely worth reading. There’s a story of a government passing an “anti-disinformation” law, which then enables that government to track down a reporter exposing government malfeasance, because her identity is tied to her digital tools via its digital provenance requirements. In another scenario, a local reporting outfit working on an investigative piece partners with a foreign media org to hide its own involvement — only to have it revealed by the watermarking tech.
Or the story of an anonymous online video producer, who doesn’t realize that despite efforts to protect his identity, these provenance mandates actually reveal to everyone who he is. Perhaps the most terrifying is the human rights worker documenting war crimes, taking massive privacy and security precautions, but is ratted out by the tech in ways that are difficult to predict:
The state actor does not need a surveillance program to make the connection. They need two things that are already publicly available. The first is the organization’s own archive. In regions where field staff safety is less of a concern, the organization signs its content with its organizational identity. It is standard practice, and a source of institutional credibility with the tribunals and monitoring bodies it works with. That archive is public, verifiable, and searchable. It establishes, unambiguously, that this organization uses this specific tool. The association between the tool signature and the organization’s name is not inferred. It is proven, repeatedly, by the organization’s own publishing practice in contexts where they had no reason to hide it.
The second is the content credential metadata ecosystem. Services that index C2PA manifests, aggregating records from published content across platforms, make the tool signature searchable across a body of work. The conflict zone footage, submitted to the monitoring body and entering a semi-public record, carries the same tool signature as dozens of other pieces of content the organization has published under its name elsewhere.
The tool signature in the conflict zone footage matches the tool signature in the organization’s public archive. The organization’s known field presence does the rest. The credential record the organization designed to protect its staff contains, in the tool signature alone, a thread that leads directly back to them, and they placed that thread in the public record themselves, in good faith, in a different context entirely. The anonymity set was the user base of that tool, in that region, in that period, and that number was small enough to matter.
One of the problems of anonymity software today is that if not enough people are using it for everything else, your mere use of it alone may reveal things about you. That’s what the last paragraph of this scenario highlights.
That scenario also calls out another vector of concern: as more and more media comes with C2PA credentials (or other watermarks) attached, we’re going to get more and more aggregation by third parties, which opens up yet another vector of surveillance. After so many years of concerns about the aggregation of private information — especially in the EU with the GDPR — you’d hope that regulators would be more careful not to create another way to amass huge collections of data on each of us.
Instead, the EU spent all these years building an entire (somewhat annoying!) “consent” regime centered on the idea that a third party shouldn’t be logging what you looked at on the internet without first getting your permission. So it’s a bit odd for this very same regulatory apparatus to then push an infrastructure that might hand a lot of private information over to aggregators… just in a more secretive manner.
Again, none of this is to say that watermarks are inherently bad. There are many cases where they are incredibly useful. WITNESS’s own report leads off by saying that it is “increasingly necessary” and a “part of restoring trust in the information environment.” It also has many suggestions for how to build better, privacy preserving tools to do this better.
But a transparency tool that doubles as a tracking layer for journalists, human rights defenders, and the people reading their work is not much of a win for the information environment it’s supposed to be restoring.
This is a point we keep hammering on about tech policy, and especially about the sorts of technology mandates that have become so popular these days. It is really, really hard to look at an entire ecosystem and see how the pieces interact — but that’s the job when you’re writing rules that everyone has to build to. Mandates that might increase competition can decrease privacy and security. Mandates that might increase transparency can decrease competition or security. Almost every decision has tradeoffs.
We still need to make those decisions, but we should do so with our eyes open regarding the tradeoffs, and figure out the best ways to minimize the harms while increasing the benefits. Unfortunately, as it stands, it’s not clear that regulators have really understood all the potential downsides regarding mandated watermarking transparency yet.
When I wrote about the concern of watermark mandates last week, a lot of people were quick to dismiss them. “AI sucks and no one should use it” was the attitude of many commenters. But it’s not just about AI, as hopefully the examples in this article highlight. The filmmaker using her regular tools or the human rights worker documenting war crimes shouldn’t lose their anonymity because these mandates were designed to stop people from making a fake video of a politician.
There’s a hell of a lot of work left to do to get this right. Currently, the EU’s AI Act mandates a label designed to help you check whether the content you’re consuming was generated with the help of AI tools. But depending on how it’s implemented, that setup can create real problems. The very act of checking the provenance of an image or video can put your own IP address, your location, and a timestamp in some third party’s server log, tied to that media. Worried regulators mandated that the provenance tracking exist. Now we’re all going to have to deal with the fallout.
The Essential MATLAB and LabVIEW Mega Bundle has 9 courses to help you improve your skills in programming and visualization. You’ll learn the basics of each and then go through hands-on courses building apps, learning about data analysis and visualization, and more. It’s on sale for $30.
Note: The Techdirt Deals Store is powered and curated by StackSocial. A portion of all sales from Techdirt Deals helps support Techdirt. The products featured do not reflect endorsements by our editorial team.
Flock Safety has been on the wrong side of the press cycle — if not the wrong side of history — for most of the last couple of years. Flock’s automated license plate readers (ALPRs) are more comprehensive than many of those previously deployed by law enforcement agencies. Not only do they capture plate/location data, they take photos of the entire vehicle, providing searchable info about distinguishing vehicle features as well as setting the stage for the almost-inevitable introduction of facial recognition tech.
Flock’s network of cameras is capable of capturing 20 billion plate/vehicle images a month. What the public is receiving in return for this remarkable gain in law enforcement “efficiency” is a lot of false positives, illegal second-hand access by federal officers, and the sickening — but wholly expected — news that cops are using this tech to stalk ex-wives, ex-girlfriends, and women seeking abortions.
Reacting poorly and belatedly, Flock has finally decided to institute a few more on-by-default options meant to deter abuse of its systems and databases, as well as lowering the default record retention period from 30 days to one week. While it is good to see Flock recognizing its contribution to the ACAB ecosphere, the new guidelines don’t appear to prevent cop shops from bypassing the presets and going right back to lengthy retention periods and stripping measures meant to give supervisors a head’s up on potential misuse of Flock plate records.
Over the last few months, people have cut down surveillance cameras owned by the company Flock Safety with an electric saw in upstate New York, thrown paint on them in Oakland, California, and rammed a truck into them in Idaho. One man in Florida sits in a lawn chair holding up a piece of cardboard on a pole to block the camera’s view. City governments have joined in by deactivating the cameras or canceling contracts with Flock in Fort Collins, Colorado; Eugene, Oregon; Madison, Wisconsin; Knoxville, Tennessee; Syracuse, New York; and Walla Walla, Washington.
Civil disobedience still works, folks. If cops want to keep their Flock cameras, they’re going to have to spend more time surveilling the surveillance devices. We’ll keep paying their overtime and they’ll keep failing to recognize the sublime irony of their actions.
It’s not just about persistent surveillance. It’s that this persistent surveillance directly contributes to law enforcement misconduct by generating a massive set of records that can be accessed by pretty much any officer for no reason at all. Hence, all the stalking. Also hence: feeding federal officers info on migrants even though the feds aren’t legally allowed to access Flock’s systems directly.
But the best indicator that the public tide has turned against Flock isn’t the protests, the abandonment of contracts by several US cities, or even the increasing acts of hostility towards the cameras themselves by pissed off citizens. Instead, it’s this: prosecutors waging a one-sided battle to secure an indictment can’t even get that done. Welcome to the resistance, Cody Morelock — and more importantly, the members of this grand jury.
A Clermont County man, who was facing felony vandalism charges for allegedly destroying a Flock camera in Union Township, had his case dismissed.
Cody Morelock was accused of damaging the camera on Mount Carmel-Tobasco Road near Glenrose Lane on June 13, according to Union Township police.
The government’s prosecutors even had visual evidence of Morelock’s actions:
Police said surveillance footage from other nearby cameras helped identify Morelock as the suspect.
But, at the end of the prosecutorial day, the people (of the grand jury) decided the government didn’t get to ring Morelock up for doing something they apparently didn’t feel was criminal enough to result in an indictment.
A Clermont County grand jury declined to indict Morelock on felony charges.
There’s your jury nullification, I guess. Prosecutors wanted a felony and assumed they had this on lock given the average value of a Flock camera. But they didn’t. Either the grand jury decided the prospective value of the property didn’t support a felony charge, or it simply decided the government wasn’t going to get to punish someone for damaging a Flock camera because… well… pick any of the reasons listed above.
We don’t know for sure what happened here. And there’s a good chance we’ll never find out, given that grand jury records are rarely, if ever, made public. But it does look like the government went hot and heavy with the vandalism charges only to be met with the indifference of regular people who don’t care whether or not Flock cameras are vandalized. And when the government can’t sell its stuff to a captive audience that only gets to hear one side of the story, the government should recognize its actions — ranging from the installation of the cameras to this failed prosecutions — no longer reflect the will of the people and adjust accordingly.
Even before Trumpism, major papers just didn’t really like it when their writers (journalists or opinion columnists) expressed human opinions on social media. They feel it reflects poorly on the reputation and impartiality of the paper; that columnists and journalists somehow can’t separate their own beliefs from factual reality and should, in effect, display no meaningful personality while using social media.
It’s a very dated and silly idea; long-since made irrelevant by autocracy’s industrialized racism (why would a human journalist not be allowed to express an honest opinion on systemic, racist evil?), and the WaPo’s ownership’s clear goal of destroying the paper’s reputation all by themselves.
In this case it was clear Attiah, who hired Saudi-murdered columnist Jamal Khashoggi in 2017 and was central in shaping the former WaPo’s opinion pages, was fired for the cardinal sin of upsetting thin-skinned Republicans and rich people.
Unfortunately for the latter, Attiah took her complaint to binding arbitration and recently won, forcing WaPo to immediately reinstate her.
BREAKING: After the Washington Post fired me last year for speaking the truth in the wake of the Charlie Kirk killing, I fought back. And I'm happy to announce: I won my case against the Washington Post. They have been ordered to reinstate me immediately. www.nytimes.com/2026/08/24/b…
The arbitrator ruled that WaPo management’s decision wasn’t based on any actual, meaningful offense:
Sarah Miller Espinosa, the arbitrator, said in a written decision Thursday that The Post “did not have good and sufficient cause” to terminate Ms. Attiah and “violated” its labor agreement, according to a copy of the decision shared with The New York Times by Ms. Attiah’s lawyers.
“The Washington Post failed to establish the grievant engaged in gross misconduct,” Ms. Espinosa wrote.
That’s a real bummer for Bezos, who has tried to reshape the Post’s opinion columns so they focus exclusively on “personal liberties and free markets” (again that’s code for coddling Republicans, rich people, and corporations). Amusingly Attiah outlasted Adam O’Neill and Will Lewis, the two WaPo “leaders” who fired her for expressing human opinions about insufferable bigots.
To say that Donald Trump has been waging an ideological war against the American free press would be an understatement in the extreme. Even attempting to list out the many, many ways in which he has attempted to threaten, sue, undermine, stifle, chill, attack, and hamstring media outlets would be a waste of time. No thinking person fails to understand that he hates any media outlets that don’t behave like full sycophants and no reasonable person thinks that his actions are a positive for the country.
But sometimes his administration really does endeavor to show just how corrupt and against the First Amendment it is, in the starkest possible terms. Stars & Stripes is a news outlet partially funded by the Pentagon. It is under congressional mandate to operate on 1st Amendment principles and describes its work like this:
Stars and Stripes provides independent news and information to the U.S. military community, including active-duty servicemembers, DoD civilians, veterans, contractors, and their families. Stars and Stripes retains its editorial independence and is congressionally mandated to be governed by First Amendment principles, but it is part of the Pentagon’s Defense Media Activity. The Pentagon funding that makes up roughly half of Stars and Stripes’ annual budget is primarily used to print and distribute the newspaper to troops scattered across the globe, including in warzones such as Afghanistan, Iraq and Syria. The remainder of the news organization’s funding comes from advertising and subscriptions.
Earlier this year, however, a Pentagon spokesman said the administration planned to overhaul Stars & Stripes, with a specific aim to remove content it considered to be “woke distractions that siphon morale” and instead, presumably, force in content that does the opposite. If any of that sounds like an encroachment on editorial independence, congratulations, you have a working prefrontal cortex.
Erik Slavin has worked at Stars & Stripes for over two decades and was named Editor in Chief in 2025. He recently sat for an interview with CBS and was asked about the Pentagon’s stated aim to interfere in the editorial content of the paper. While noting that he had no idea what “woke content” the Pentagon was objecting to and what the standard for that would be, because nobody at the Pentagon bothered to tell him, he indicated that any attempt to censor the paper by the Pentagon would be his red line and counter to both the law and Pentagon policy that the paper be independent.
The Pentagon on Friday fired the editor-in-chief of Stars and Stripes and a top reporter for insubordination after they spoke publicly against any interference by the Defense Department in the military news outlet that has a long history of editorial independence. It was the latest move by an administration that has grown increasingly aggressive toward the news media.
Slavin said he was being fired “for stating in a CBS interview that hypothetical censorship of news for service members would constitute a red line.” Korte participated in the same interview.
“I stand by the principle that Stars and Stripes must remain editorially independent, as required by law and by the department’s own policies,” Slavin said.
This is a newspaper with a long, long history. It has been publishing since the American Civil War. It has endured despite the ire of military men far greater than its current whiskey-soaked Secretary of Defense/War/Whatever. General George Patton once tried to ban the paper over cartoons depicting American soldiers in a way he didn’t like, only to have General Eisenhower tell him to calm the hell down and not interfere.
The skin of people like Trump and Hegseth is apparently as thin as the paper upon which Stars & Stripes is printed. To so perfectly encapsulate their own anti-speech desires by firing someone simply for saying he wouldn’t bow to government censorship is significant, though unsurprising.
Meanwhile, American military members appear to be losing a news outlet that focuses on them.
With everything else going on in the world, it’s been a while since we’ve dug into a good old-fashioned patent troll story or a bogus defamation SLAPP. Today we’ve got a two-for-one. Leigh Rothschild is a patent troll of some renown — his entities have been connected to over 1,300 patent lawsuits — who regularly sues companies over questionable patents and plays the standard patent troll shakedown game of offering to “settle” for less than it will cost to defend the lawsuit.
We’ve mentioned Rothschild in the past on Techdirt for his patent trolling ways. Like many patent trolls, Rothschild is known for setting up a number of separate companies that control the various patents he holds or controls. Rothschild’s trolling is covered widely all over the internet, and it’s not difficult to find one of dozens of people calling out his trolling techniques:
The Rothschild Modus Operandi is to obtain a fairly bogus patent (in this case, patent 9,936,086), form a limited liability corporation (LLC) that only holds the one patent and then sue a load of companies with vaguely related businesses for infringement. A key element of the attack is to offer a settlement licensing the patent for a sum less than it would cost even to mount an initial defence (usually around US$50k), which is how the Troll makes money: since the cost to file is fairly low, as long as there’s no court appearance, the amount gained is close to US$50k if the target accepts the settlement offer and, since most targets know how much any defence of the patent would cost, they do.
Anyway, back in 2022 Rothschild apparently acquired a very sketchy patent, US Patent 8,799,083, on a “system and method for managing restaurant customer data elements.” The patent describes a series of blatantly obvious methods of letting a restaurant customer share some information about their preferences and track their orders. Plenty of prior art exists showing that this patent never should have been granted.
Rothschild took the patent he claimed he acquired and (as described above) put it into a dedicated shell company, Analytical Technologies, then sued at least twenty food-ordering businesses in Marshall, Texas (because, of course). The playbook worked about as well as it usually does: Subway, Darden, Denny’s, Cracker Barrel, Five Guys, and Dairy Queen all settled or stipulated to dismissal within a few months.
Starbucks did not.
Suing Starbucks was perhaps a strategic error, because rather than fold and settle, Starbucks hit back hard, accusing Rothschild, personally, of fraud, claiming that Analytical Technologies was “a sham shell entity to shield himself from personal liability” and claiming that there’s a “pattern and practice of [Rothschild] underfunding (or not funding) his shell entities” with the implication being that doing so was to avoid having to pay out legal fees if he lost the lawsuit.
It also pointed out that records show that the original named inventor on the patent, Andrew Silver, who had supposedly sold the patent to Rothschild… had already sold the patent earlier and engaged in other sketchy behavior, such that he probably no longer retained the rights to the patent when he “sold” it to Rothschild:
On April 14, 2008, Table Top Media (“TTM”) purchased the application that would mature into the parent ’007 Patent and said patent’s progeny, including the application that would mature into the Asserted ’083 Patent.
During the prosecution of the parent ’007 Patent, the application was abandoned because Silver failed to respond to an office action (a Notice of Abandonment dated 04/13/2010 stated that there was no reply to the Final Rejection mailed on 02/04/2009).
Silver and Gostanian revived the abandoned ’007 Patent by telling the USPTO that Silver’s former patent agent, Steven McDonald, had “unexpectedly passed away”. ’007 PxHx, 11/9/2010. But Steven McDonald was still alive and assisting Silver with the ’007 prosecution when the patent went abandoned as the privilege logs on the TTM litigation demonstrate…
There’s a lot more in the filing regarding the supposed “death” of McDonald who somehow kept helping Silver with his patents. But more importantly, there’s the issue of who actually owned this particular patent:
On February 19, 2014, Gostanian told the USPTO that Silver was the “100% owner” of the Asserted Patent in order to file a terminal disclaimer and obtain issuance, even though Gostanian and Silver understood that TTM had an “existing contract” and was the owner of the ’083 Patent application.
At the same time that Gostanian submitted the terminal disclaimer to the USPTO stating that Silver owns 100% of the ’083 Patent, Silver and Gostanian were preparing a lawsuit to sue TTM for specific performance because Silver sold the Asserted ’083 Patent family to TTM in 2008.
Mr. Silver submitted a sworn declaration in his lawsuit against TTM stating unequivocally that TTM bought the ’083 Patent family in 2008:
It then shows a bunch of documents, including ones signed by Silver showing that he knows that TTM owns the patent that he later claimed to sell to Rothschild. Oops!
If that wasn’t enough, there was the fact that the patent had expired before Rothschild ever filed. And because the asserted claims were method claims describing things a customer does — ordering, paying at the table — Starbucks couldn’t be a direct infringer at all. The only theory left was indirect infringement, which requires that Starbucks knew about the patent while it was still alive. Which is why Rothschild needed a pre-suit notice date, and why his lawyers’ explanation for the one they used is such a problem. Because it turns out they didn’t actually notify Starbucks while the patent was still valid:
Neither AT nor its counsel has provided to Starbucks or its counsel any support for AT’s Actual Notice Allegation.
On August 2, 2024, counsel for AT emailed counsel for Starbucks and stated, “We can agree to remove that statement [the Actual Notice Allegation] if we cannot provide you proof on Monday [August 5, 2024].”
But counsel for AT did not provide proof of AT’s Actual Notice Allegation on August 5, 2024. And counsel for AT did not remove the Actual Notice Allegation.
On September 5, 2024, counsel for AT admitted in an email that the Actual Notice Allegation was a “misrepresentation” and the result of a “typo/cut and paste problem”
That seems like quite an admission! So the patent expired in November of 2023. The troll claimed that it had notified Starbucks of its alleged infringement in March of 2023. Starbucks claimed they heard nothing until June of 2024. And when Starbucks asked for proof of the supposed notice, Rothschild’s lawyers promised it, didn’t produce it, didn’t withdraw the load-bearing allegation, and eventually admitted it was a “misrepresentation” due to a cut and paste “problem.”
Yikes. And yet, all those other fast food joints settled.
The filing from Starbucks resulted in an article on Bloomberg Law, entitled, “Starbucks Levels Fraud Claim in New Tactic to Fight Patent Suit.” In it, lawyer Rachael Lamkin, who is one of Starbucks’ lawyers and a long-term fighter against patent trolls, is quoted calling out Rothschild’s shell games:
Lamkin said she’s tussled with the prolific inventor for years and has been particularly frustrated by the early settlement offers from Rothschild, which she called “obnoxiously low.”
“The settlement amounts are so low that companies aren’t going to pay attorneys the thousands of hours it takes to catch him at his game,” she said in an interview. “And with Leigh Rothschild, we never get the money because the shells go bankrupt.”
This claim appeared to particularly annoy Rothschild, who turned around and sued Lamkin and Starbucks… for defamation. In Florida. The complaint goes on for a while about what an amazing “inventor” Rothschild is and how important his various patents are… and also about how he’s involved in various charities, claiming that the statement about shell companies and bankruptcies was defamatory. Also, Rothschild claimed that this one quote in a random Bloomberg article caused him — a guy who has been involved in over 1,000 lawsuits — to require special new medication for high blood pressure. Really?
Neither LMR nor any of the companies he is involved with, however, has ever owed any of the Defendants any money for them to “get.”
Moreover, none of the companies LMR is involved with is a “shell” (i.e., a company with no significant assets or operations); instead, each of the companies is a lawful corporate entity with assets, bank accounts, and operations appropriate for its purpose, which in most cases is to own and license valuable U.S. patents.
Further, none of the patent companies LMR is involved with has ever “go[ne] bankrupt.” Acknowledging this fact, Defendant Lamkin stated recently to LMR directly that “before I’m done with you I’m going to bankrupt you,” which evidences her own knowledge contrary to any “bankrupt” entities, and evidences her own bad faith and malevolent intent.
Be careful who you tussle with, however. Lamkin’s answer to the complaint (which includes counterclaims against Rothschild) has some fun statements:
Attorney Lamkin denies that Rothschild “has been an inventor his entire life.”
The answer also argues that the final paragraph above in which Rothschild claimed Lamkin had told him she would bankrupt him was “a fabrication.”
Attorney Lamkin denies that she has told Rothschild, “before I’m done with you I’m gong to bankrupt you.” That allegation is a fabrication. Attorney Lamkin denies the assertion that no patent company owned or managed by Rothschild has ever “go[ne] bankrupt.” Attorney Lamkin denies that she has knowingly made a false statement in connection with the facts at issue in this lawsuit or that she has exhibited “bad faith and malevolent intent.”
Later, in the counterclaims, Lamkin points out the factual basis for her original claims to Bloomberg, detailing multiple cases in which Lamkin represented a company sued by a company controlled by Leigh Rothschild, where, during discovery, it came out that the company had basically no working capital or funding, including examples where Rothschild was ordered to pay fees to the companies Lamkin represented and did not do so.
The most telling is the last one, of a shell company that only had $5 in its bank account:
Similarly, in RCDI, RCDI responded to post-judgment discovery admitting it only had “five dollars ($5.00)” in its bank account….
In short, by Rothschild’s own averred admissions based on his personal knowledge, multiple entities owned and/or controlled by him had little to no assets to satisfy judgments against them. This matches the definition of a “shell” entity that this Court has routinely applied….
The filing also highlights how this defamation lawsuit was clearly ridiculous, given that it included Starbucks as a defendant, even though the only statements mentioned were from Lamkin:
As further evidence of Plaintiffs’ improper motive in using this matter as leverage to settle the E.D. Tex. Litigation, Plaintiffs have sued Starbucks even though the statements at issue cannot be attributed to Starbucks.
The case was handed over to a magistrate judge, who recommended ruling against Rothschild on the defamation claim, finding that the statements by Lamkin were clearly not defamatory.
As framed within the context of the Bloomberg article, the statement is consistent with Rothschild’s reputation within the relevant PAE community. The undisputed facts show that, according to other online publications, Rothschild was described as a “patent troll” who asserted patent litigation lawsuits through his numerous shell companies, and that he utilized shell companies for the purpose of evading fees and penalties…. It is also undisputed that numerous articles, other internet posts, and judicial documents referred to Rothschild’s companies as “shells.”… Based on the undisputed facts, Rothschild’s reputation before Lamkin made her statement was that he created “shell” companies and that he was a “patent troll.” The Court agrees with Lamkin that her statement was consistent with Rothschild’s reputation, so Lamkin’s statement concerning Rothschild’s conduct with respect to PAE litigation does not support a defamation claim.
Imagine being such a patent troll that a court has to say, in effect, “dude, come on, everyone knows you’re a patent troll with shell companies for your trolling” and also “your reputation is such shit already that calling you a troll couldn’t make it worse.”
The court also rejected the argument that saying his companies go bankrupt was defamatory, in part because there’s nothing inherently disgraceful about bankruptcy:
The Court must determine whether Lamkin’s statement concerning Rothschild’s company “tends to” subject Rothschild to “hatred, distrust, ridicule, contempt, or disgrace.”… This Court finds that it does not. Bankruptcy is viewed as a helpful, oft-used tool for individuals or entities experiencing financial difficulty.
And even if both of those rulings were wrong, the court found, Lamkin’s statements were still protected under the First Amendment as rhetorical hyperbole, because you have to read the quote in the context of the whole article it appeared in. Rothschild wants to separate out specific minor inaccuracies (such as whether any of his companies was technically a shell or technically declared bankruptcy). But as the magistrate judge points out, that’s not how any of this works:
… the Court cannot disregard the context in which Lamkin’s statement was made in determining whether Lamkin’s statement was one of fact or one of opinion or hyperbole…. The broader context of Lamkin’s statement within Lamkin’s interview—which was subsequently republished in the Bloomberg article—is that Lamkin and Rothschild (and the entities connected with Rothschild) have long been engaged in PAE legal struggles and that Rothschild’s entities have failed to pay attorneys’ fees in PAE lawsuits. Lamkin and Rothschild have a history of litigation, and Lamkin’s statement that “we never get the money because the shells go bankrupt” stems from Lamkin’s experience in litigating cases against Rothschild, resulting in frustration from the low settlement offers and the inability to collect fees. …These facts are included in Lamkin’s quotes to the Bloomberg reporter. It is clear from the context of the Bloomberg article as a whole, as well as from the context of Lamkin and Rothschild’s litigation history and related experience with each other, that the statement is an opinion and hyperbole…
Indeed, the magistrate’s recommendations were for finding that Rothschild ran afoul of Florida’s anti-SLAPP law and that he should have to pay Lamkin’s legal fees:
In sum, Rothschild’s defamation claim was without merit and arose out of Lamkin’s free speech in connection with public issues. Moreover, Rothschild did not shoulder his burden to show that the defamation claim was not primarily based on First Amendment rights and was not without merit. Thus, Lamkin is entitled to an award of attorneys’ fees and costs against Rothschild under Florida’s Anti-SLAPP statute
Lamkin’s own counterclaim, for abuse of process, didn’t survive either — the court found it barred by Florida’s litigation privilege, and noted that simply filing a harassing lawsuit isn’t “abuse of process” without something more. So the scorecard is technically split, but the part that mattered went Lamkin’s way, along with the fees.
Under patent law, a judge can award reasonable fees in “exceptional cases.” Indeed, Rothschild was hit with such fees in the past for his trolling. But if you follow that link, you’ll see that the entity in question was RCDI, the company mentioned above that claimed it only had $5 in its bank account. A fee award against an entity that claims to only have $5 is worthless.
That’s what Starbucks was trying to route around by going after Rothschild personally for fraudulent transfer. We’ll never find out if it would have worked: the Texas case ended almost exactly a year ago, with both sides stipulating to dismissal and each eating its own costs. Rothschild then kept the Florida defamation case going for another full year after the fight that produced it was over.
Which means the one thing in this entire mess that looks likely to actually cost Rothschild money is the lawsuit he chose, entirely voluntarily, to file himself.
The first attempted revenge prosecution of former FBI director James Comey has gone nowhere. Whatever the DOJ didn’t botch directly was undone by Trump’s persistent refusal to adhere to the rules of political appointments.
The second attempted prosecution of James Comey isn’t going any better. The Trump DOJ willfully pretended an Instagram photo taken by Comey of seashells arranged to read “8647” was a “true threat.” As everyone but the deliberately ignorant knows, “86” generally means getting rid of something. In bar parlance, this means cutting someone off or kicking them out of the bar. In restaurant parlance, it means a menu option is no longer available.
This prosecution is even more shaky than the last one — the one where the administration pretended being misleading during congressional testimony was a criminal act worthy of indictment, even though everybody (and especially Trump appointees) do it all the time. Since the government couldn’t find a universal definition of “86” that meant “kill,” it had to rely on anything from AI prompts to motherfucking Mafia hitman/rat Sammy “The Bull” Gravano to press its case.
Now that it’s floundering again, the DOJ has decided it should double-down on the floundering. Comey is still fighting to have the case dismissed, while also seeking to hold the government accountable for its vindictive prosecution. The DOJ is hoping to hold this together long enough that everyone involved won’t be immediately dismissed for failing to accomplish the impossible.
The end result is that the DOJ’s arguments are more desperate and less minimally coherent. In its latest filing, the DOJ has decided to throw the First Amendment — along with any remaining logic — under the bus.
You read that headline correctly. The DOJ is now seriously (and while under oath) quoting Comey’s 2025 “legal thriller” in a last-ditch attempt to connect seashells with inciting violence against Trump. It has to be read to be believed. I won’t make you suffer through Comey’s sub-Grisham writing. But the DOJ will! Here’s the DOJ Vengeance Squad [PDF] attempting to turn protected expression into evidence of criminal activity:
On May 15, 2025, Comey was staying at a beachfront residence in Emerald Isle, North Carolina. Comey’s novel “FDR Drive” was only five days from public release. As Publisher’s Weekly described the novel, and as posted on Comey’s Instagram, the protagonist is a federal prosecutor “trying to take down Samuel Buchanan, a far-right media personality with a popular podcast.” FDR Drive, Publisher’s Weekly, https://perma.cc/6V82-HQ9A4. [Exhibit 1] The prosecutor “believes Buchanan went far beyond the protection of the First Amendment when he singled out his enemies by name and suggested ‘something should be done’ about them. His fans have obliged, killing or grievously injuring some of his foes.” Id. The novel itself describes the “stochastic terrorism” theory of Buchanan’s offense at length:
Sean nodded. “It’s where a charismatic leader jacks people up but, through the wonder of the internet, avoids a direct connection to what comes next. Stochastic is a term from statistics that means you can estimate the likelihood of something happening, even if you can’t predict who will do it and when and where.”
The words in bold are quoted directly from Comey’s novel. This is only part of it. The DOJ filing quotes Comey’s novel at length. If you want to read more, you can. But considering the argument being made by the DOJ, combined with what I assume is general disinterest in reading Comey’s fictional works, this is the part that matters… at least to the DOJ.
Several paragraphs of subpar political thriller later, the DOJ attempts to connect the dots… or at least the seashells and its pull quote from a book that was published “only days later.” 2+2=CRIME! says the DOJ:
On May 15, 2025, a charismatic leader named James Comey, through the wonder of the internet, posted a coded message to his followers meaning “kill” or “get rid of” (a euphemism for “kill”) President Trump.
Stupid and dangerous: that’s the DOJ we have now. But this is deliberate stupidity — prosecutors closing themselves in hopes of scoring a pair of poorly fitting Florsheims or landing a spot on Trump’s personal legal team post-2028, where anyone sufficiently devoid of personal morality or professional ethics will be rewarded with hundreds of billable hours.
From there, the DOJ continues with its conspiracy theory concoction, claiming there’s no way anyone but Comey could have arranged the “8647” seashells, even though it happened “four miles” away from Comey’s beachfront residence. The filing then cites “evidence” it has had for awhile, hoping that the court will draw inferences that can’t plausibly be implied by the DOJ:
In any event, at 3:12 pm, Comey’s wife sent him a screenshot including what appeared to have been a cropped definition of “U.S. English slang” indicating that “86” means “to get rid of or refuse service.” [Exhibit 5]. Two minutes later, at 3:14 pm, Comey posted a picture of the seashells on his Instagram account with the caption “Cool shell formation on my beach walk.”
If that hurt your head, prepare to bleed out:
There is no serious dispute that an objective viewer of Comey’s post could read it to mean “Kill President Trump.”
If that were true, the DOJ wouldn’t be in court hoping to salvage its case by suffering through Comey novels and trying to turn a hasty seashell-based joke into a federal crime.
But probably the stupidest thing about this is that the citation of Comey’s novel ignores the context. That section is about the government dreaming up a way to punish someone for something that — on its own — isn’t actually a criminal act. The main characters (government prosecutors) discuss the assassination of Thomas Becket in 1170 AD at the (inferred) urging of King Henry II. Then they arrive at this conclusion/miscarriage of justice:
The room was quiet for a moment before Nora said, “But that’s okay. I don’t think we need to base his intent on the perfect-attack-record thing. I think we just argue that he had to know his words would result in the attacks. He may not have known the identity of his knights, but he knew they were out there and would act on his words. So he just shouted that they were—what were the king’s words? ‘Miserable drones and traitors’?—if they didn’t get rid of the people he named. He knew what his knights would do. That should be enough to prove he intended it to happen.
Comey’s novel is a similarly unconcerned with First Amendment rights as Trump’s DOJ. If this hadn’t been written by a former prosecutor and FBI director, someone might have stepped in to shut this shit down. The incredible irony is that the DOJ is doing exactly what the characters in Comey’s book did while simultaneously insisting the man who wrote this book was trying to pull a King Henry II against Donald Trump even though stuff Comey wrote himself made it clear doing so might give the government a path to convict him of threatening the president.
What’s most amazing about all of this is that DOJ prosecutors apparently have the time and discretion to actually read James Comey’s fictional works and parse them for possible “evidence.” I can’t imagine doing this for free. And I think I might even have a problem doing this for pay. But here we are, watching the DOJ claim that Comey knew what he was doing because this one time a bunch of people who never existed said words that Comey put in their mouths. Ridiculous.