DOJ: TikTok to pay $400M in settlement over suit alleging violation of children’s privacy law

The Department of Justice (DOJ) announced a $400 million settlement with TikTok over a lawsuit alleging the company violated the Children’s Online Privacy Protection Act (COPPA).

As part of the agreement with TikTok, its developer ByteDance and related entities, the DOJ said in a Friday press release that the social media giant will pay $300 million immediately and the additional $100 million when certain conditions are met regarding a previous legal dispute with Musical.ly, TikTok’s predecessor.

“This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley Woodward Jr.

“The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations,” Woodward continued.

COPPA dictates that online services aimed at children must obtain parental consent before collecting personal information from users under 13 years old.

The suit alleging that TikTok violated this law was filed by the DOJ in 2024, though the Justice Department asserted that the social media company had experienced immense internal changes since that time.

“Since the Justice Department filed its complaint in 2024, TikTok has undergone significant changes to its ownership, management, compliance functions, and privacy practices,” the release stated.

“The company has implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight,” it continued.

In January of this year, TikTok announced that a majority American-owned joint venture was established to comply with President Donald Trump’s 2025 executive order requiring the company’s divestiture in order to keep operating in the U.S.

Keep reading

US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search

 A federal case in Atlanta is raising questions about a privacy-focused mobile operating system, with prosecutors arguing that its features were used to erase evidence. The US Department of Justice is attempting to prosecute Atlanta resident Sam Tunick under a federal statute that makes it a crime to destroy property in an effort to prevent it from being seized.

The case centers on Tunick’s use of GrapheneOS, an open-source operating system that works on Google Pixel phones and lets users enter a passcode to wipe a device clean.

Experts said the legal approach is unusual and may be the first time the law has been aimed at an operating system. “It’s concerning – and sends the message that [GrapheneOS] is criminal by default,” said Christophe Boutry, a cybersecurity and surveillance expert. Boutry and Bill Buddington, senior staff technologist at the Electronic Frontier Foundation, both said they had not seen a similar case.

The incident began at Hartsfield-Jackson Atlanta International Airport on January 24 of last year. Tunick had just returned from a trip to the Dominican Republic when he was stopped for questioning. According to court testimony, federal agents had already circulated his name and photo internally, saying he was under investigation for “suspected terrorism activities” because of his alleged association with the movement against Cop City.

Keep reading

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required

The Fourth Circuit issued a disappointing opinion in U.S. v. Belmonte Cardozo, a case in which EFF filed an amicus brief, alongside the national ACLU, its Maryland, North Carolina, South Carolina, and Virginia affiliates, and the National Association of Criminal Defense Lawyers (NACDL).

We argued that electronic device searches at the border should require a warrant based on probable cause, but at minimum, regardless of whether an officer searches by hand or with forensic software that plugs into a device and downloads its entire contents for search, the same Fourth Amendment standard should apply to all device searches at the border.

Unfortunately, the court rejected that argument and ruled that a lower standard applies to manual searches, allowing the government to conduct extraordinarily invasive electronic device searches without any suspicion of wrongdoing, simply because the border officer chooses to search by hand rather than with a forensic tool.

The Border Search Exception Meets Your Phone

The Fourth Amendment requires that government searches of persons or property be reasonable, which usually means obtaining a warrant based on probable cause from a judge.

But a warrantless search can still be reasonable if it falls within an exception to the warrant requirement, including the exception that allows officers to search your belongings at the border. The border search exception allows warrantless searches of persons or property crossing the U.S. border, including the functional equivalent of the border such as international airports, given the government’s interests in controlling who and what may enter the country.

Historically, courts have categorized border searches of luggage, vehicles, and personal effects as “routine” and thus reasonable even if conducted without any suspicion that the traveler has engaged in wrongdoing; courts have also held that more invasive “nonroutine” searches, such as certain body searches and searches that damage property, require reasonable suspicion.

But a person’s privacy interests in the personal data on a phone or laptop are extraordinarily different than their limited privacy interests in the contents of their suitcase.

The Supreme Court addressed cell phone privacy in Riley v. California (2014), holding that the search-incident-to-arrest exception to the warrant requirement did not apply to cell phones, thereby generally requiring a warrant for phone searches, at least at the interior of the country. The court recognized the unprecedented privacy interests people have in their cell phones and how even brief manual searches can reveal the “sum of an individual’s private life,” including our political affiliations, religious beliefs, sexuality, and more. Accordingly, the Supreme Court held that because electronic device searches bear “little resemblance” to searches of bags or physical containers, they should be evaluated differently.

Following Riley, the Fourth Circuit considered two border device search cases involving forensic searches, in which border officers used external software to extract and analyze a device’s data.

In U.S. v. Kolsuz (2018), the Fourth Circuit held that a forensic search of a cell phone at the border “must be considered a nonroutine border search, requiring some measure of individualized suspicion” of a transnational offense, but the court declined to decide whether the standard is only reasonable suspicion or instead a probable cause warrant.

Then in U.S. v. Aigbekaen (2019), the Fourth Circuit held that a forensic device search at the border in support of a purely domestic law enforcement investigation requires a warrant. The court also reiterated the general Kolsuz rule for a forensic border-related device search: the “Government must have individualized suspicion of an offense that bears some nexus to the border search exception’s purposes of protecting national security, collecting duties, blocking the entry of unwanted persons, or disrupting efforts to export or import contraband.”

In Belmonte Cardozo, manual searches were finally before the court.

Keep reading

Comcast Turns Millions Of Routers Into Motion Sensors – The Same WiFi Signals Can ID You With 99.5% Accuracy

Dear Comcast customers: The internet gateway in your living room is now a motion sensor. It’s free of charge, and the data can go to law enforcement without further notice. What’s more, researchers have already shown that these same signals can identify exactly who is in the room.

On Tuesday, Comcast unveiled Xfinity Shield, a home security platform built entirely around the WiFi network. Its centerpiece, WiFi Motion, turns the leased gateway into a motion detector at no extra charge. According to Comcast, a typical customer has roughly 36 devices connected to their WiFi.

WiFi Motion works because a human body moving through a room disturbs the signal field between the gateway and stationary connected devices, like a printer or a game console. While the feature is opt-in and – according to Comcast’s rollout materials – does not track phones or reach through WiFi extenders, those limitations are choices Comcast made in software, not limitations of the technology itself.

Comcast says WiFi Motion works “without recording video, capturing images or identifying individuals.”

The company is not shy about identification as a product. The $15-a-month tier, Xfinity Shield Select, adds AI-powered cameras that identify people, pets, packages and vehicles. The free tier’s restraint is a line drawn one product SKU away.

Keep reading

X Wins Australian Case Over Private Message Scanning Rule

Australia’s eSafety Commissioner wrote a rule requiring online services to scan what their users send each other. Not to act on reports, but to run detection systems across private messages before anyone has complained, hunting child sexual abuse and pro-terror material. Top censor, Julie Inman Grant, wrote it herself, under powers the Online Safety Act hands her, and breaching it carries penalties of up to $49.5 million.

Then she took the view that it covered social media platforms as well, because they let users send each other messages.

On August 12, the Federal Court told her it does not. The Relevant Electronic Services Standard “does not apply” to X, Justice Elizabeth Raper held, ruling for the platform in a case it brought in May 2025. It “would be rather perverse for a social media service…not to enable messaging or chat between end users,” X’s barrister had argued — on eSafety’s reading, having a DM function was enough to pull a platform into a rulebook written for something else.

The distinction is important because of who writes what. Social media services in Australia are covered by a code developed with the industry, X included. The RES Standard is not a negotiated code. It is an instrument the Commissioner drafts and enforces herself. The standard says it applies “to the exclusion of any industry code” — so reading it to cover social media would have let the instrument she controls displace the one she negotiated.

Raper said so directly. “I accept X Corp’s characterisation of the facts that the RES Standard has been made by the commissioner…as a standard applicable to participants in a different section of the online industry, that are specified…as ‘providers of relevant electronic services’,” she wrote.

Keep reading

The Right To Be Left Alone

“The makers of our Constitution undertook to secure conditions favorable to the pursuit of happiness… They conferred against the Government the right to be let alone — most comprehensive of rights and the right most valued by civilized men.” ~ Justice Louis D. Brandeis (1856-1941)

The rapid spread of public surveillance cameras represents something far more consequential than a new piece of police technology. It represents a fundamental change in the relationship between the individual and the state.

These cameras allow government agents to record, identify, catalog and retroactively track the movements of people who have committed no crime, are suspected of no wrongdoing and have done nothing to invite government scrutiny. That’s not public safety. It’s an assault upon individual privacy.

Privacy is not a privilege granted by government. It is an aspect of personal liberty that government exists to protect. It is a natural human right protected from the government in the Bill of Rights. The fact that a person leaves his home and travels upon a public road does not mean that he has surrendered that right.

There is an enormous moral and constitutional difference between a police officer who happens to observe a person in public and government surveillance that automatically and systematically records that person’s vehicle, location and movements; and stores that information for future use.

A free society doesn’t just protect people from crime; it protects them from arbitrary government. The presumption is liberty. Government is the negation of liberty. A person should not have to establish his innocence before the government leaves him alone. The burden always belongs to the government to justify all intrusions into personal liberty. Police cameras reverse that principle. They collect information about everyone the camera views and leave it to individuals to challenge the collections afterward.

The Constitution requires articulable suspicion connecting the person being surveilled to a legitimate law-enforcement objective to justify public surveillance. A vague assertion that the technology might someday help solve a crime or enhance public safety does not meet that standard.

The view that personal privacy and public safety are in equipoise — that they are merely two competing interests of equal moral and legal weight from which government officials are entitled to choose subjectively their preferred balance — is the core of authoritarianism.

Safety is one of the legitimate purposes for which government exists. Privacy is among the personal liberties that government exists to protect. It cannot be taken away without judicial approval. Government cannot justify violating a natural right merely by asserting that doing so might make people safer. If that were so, there would be no meaningful boundary on any governmental power.

There is a profound difference between investigating a specific crime through constitutionally authorized surveillance and constructing a permanent infrastructure of suspicionless surveillance. The former begins with evidence and seeks information relevant to a particular governmental purpose. The latter begins with everyone and waits for the evidence.

When 7,000 American police departments have these systems with no legislative approvals, we have the police making policy judgments. They are deciding that the government should possess a new capacity to observe innocent people, what information should be collected, how long it should be retained, who should have access to it and what purposes may justify searches; all this irrespective of the Constitution.

Those are not merely administrative questions. They are questions about personal liberty.

If elected legislators believe that such surveillance is necessary, they should publicly debate it, enact specific legislation mandating warrants, establish meaningful limitations and accept responsibility before the voters. The decision should not be buried in a police procurement process or treated as an ordinary equipment purchase.

Liberty cannot depend upon the benevolence, restraint or good intentions of government employees. The premise of the Constitution is that government power must be limited, checked and divided because government officials are human beings who possess power and will inevitably have incentives to abuse it.

The answer is not better government surveillance. The answer is what the Fourth Amendment requires: No government surveillance without search warrants.

The constitutional question cannot be reduced to whether someone was physically standing in a public place. A police officer seeing a car pass by is one thing. A government database capable of reconstructing months of a person’s movements is something fundamentally different.

The difference is the difference between observation and surveillance.

Keep reading

Meta Faces Criminal Complaint in Germany for Its AI-Glasses, Accused of Violating Privacy Laws

Who wants to be filmed all the time?

The struggle between new, useful tech gadgets and the objections that these new capabilities raise is a field expected to grow in the next few years, and make many lawyers very wealthy.

One such example is the Meta AI-Glasses.

In principle, it seems a great idea to pack so much computing power in a pair of glasses for our benefit.

But once you start to compute the legal and ethical objections that this gadget raises, it becomes a much less clear question.

Today (12), a German advocacy group took matters into their own hands, and filed a criminal complaint against Meta and other companies, ‘arguing the devices violate privacy laws’.

Reuters reported:

“Digital rights group HateAid said in a statement on Wednesday that the launch of the devices, the Ray-Ban Meta Wayfarer in particular, broke German digital privacy laws, in the latest sign of legal scrutiny in a nation where the right to privacy is highly valued.

‘There’s no place to escape from smart glasses. You have to expect at any moment to be filmed and then exposed on the internet’, said HateAid managing director Josephine Ballon.

The organization reported the management of Meta, units of spectacles maker EssilorLuxottica including Ray-Ban, as well as retailers Fielmann, Apollo-Optik, Mister Spex and MediaMarkt to the Frankfurt-based digital crime prosecution unit ZIT.”

The complaint is based on Germany’s federal digital data protection law, which prohibits the sale of communication devices designed to film people without them noticing.

Keep reading

He Spoke at a Town Meeting. Then Flock Cameras Started Tracking His Car.

A resident steps up to the mic at a town council meeting, says something inconvenient, then drives home — unaware that somewhere in a police database, that license plate just became a person of interest. No warrant. No probable cause. Just an officer with a grievance and a subscription service the town approved at a meeting most residents never knew about.

That scenario isn’t hypothetical anymore. In 2026, it’s documented — from Georgia to Rhode Island.

How Flock Works – and How It Can Be Weaponized

The system was built to catch criminals; the problem is there’s nothing reliable stopping it from being aimed at everyone else.

Flock Safety sells automated license-plate reader (ALPR) networks to police departments nationwide. The pitch is straightforward: catch criminals faster by searching vehicle movement data after incidents occur. What the system doesn’t include is a reliable filter between a legitimate investigation and a personal score to settle. Unlike federal wiretap law, no federal statute currently governs ALPR data retention periods or inter-agency sharing agreements, leaving oversight entirely to municipal contracts.

The documented abuse cases are piling up:

  • The Electronic Frontier Foundation identified more than 50 agencies running hundreds of Flock searches tied to protest activity
  • CNN report from July 2026, citing an Institute for Justice tally, found at least two dozen cases where officers resigned or were arrested for allegedly using Flock to stalk romantic partners
  • A police chief in Braselton, Georgia, was arrested for allegedly using ALPR cameras to stalk and harass private citizens
  • Court documents show searches conducted far outside officers’ jurisdictions, according to a 2026 investigation republished by Yahoo
  • Flock told 404 Media it was “aware of 15 incidents of abuse” — a figure critics argue the platform’s design makes structurally impossible to trust

Keep reading

Princeton Study Shows How Bad Actors Can Exploit Georgia Elections To Expose How You Voted

A new analysis from Princeton University’s Center for Information Technology Policy shows that a capable analyst — or even an ordinary AI model — can reconstruct the order in which most Georgia ballots were scanned and, by combining that order with other ordinary election records, determine how individual voters cast their ballots.

Using publicly available data from the state’s May 2026 primary, researcher Max Springer demonstrated the technique at scale, recovering the scanning order of roughly 1.5 million ballots (98.9 percent of in-person ballots) across 139 counties. In smaller example jurisdictions, the linkage was nearly complete: in Heard County every one of the 650 early in-person voters could be tied to a specific ballot, and in Ball Ground (Cherokee County) all 1,860 early voters were matched. In other words, the supposedly secret ballot is not nearly as secret as the public has been told.

Early voting compounds the vulnerability. Voters at vote centers come from multiple precincts and often use different ballot styles with different candidate choices. Those differences create additional data points that can improve the ability to isolate individuals inside the Cast Vote Records (the electronic files that list every candidate choice marked on each ballot). Match confidence will vary — some linkages can be made with near certainty, others with lower confidence — but a talented programmer or AI user can still perform substantial voter profiling.

In small towns and close-knit communities, the risks of exposure are obvious. Parents could identify teachers’ ballots. Employees could face pressure from employers, or bias from potential employers. Even people who never face overt pressure could still experience quiet discrimination.

Some voters already avoid primaries because they do not want their party preference known. The ability to reverse-engineer candidate choices in a general election would only increase the potential for intimidation and could open the door to a whole new form of doxing.

Many people assume election officials are supposed to be able to know how individuals voted. They are not. Georgia law requires “absolute secrecy” of the ballot. While election officials must handle anonymous ballots, the system also must not allow anyone — including poll officials, election boards, or the state’s vendors — to determine how any particular voter cast his ballot.

The ability to reconstruct individual voting choices — and potentially disclose them — raises serious legal concerns under Georgia law, but also carries substantial commercial and political value. In an era when major campaigns routinely spend hundreds of millions of dollars, the ability to know how specific voters actually cast their ballots could be worth millions.

When that information can be assembled across multiple election cycles, the ability to build detailed, long-term voter profiles only grows stronger. That kind of data is useful to campaigns, advocacy groups, and anyone building sophisticated micro-targeting models. An insider at the state or county level with access to the original internal data files could face a clear temptation. The creation of traceable ballots must stop — while preserving the ability to audit the election.

Those concerns are heightened by the fact that Georgia’s Secretary of State’s office has already experienced multiple serious data exposures and breaches. In 2015, the office distributed voter files containing Social Security numbers, driver’s license numbers, and birth dates for more than 6 million voters (the “PeachBreach”). In 2016-2017, a server at Kennesaw State University that handled statewide election preparation was found exposed to the internet, containing millions of voter records with personal identifying information, election databases, and supervisor passwords.

Additional web portal vulnerabilities in later years have repeatedly risked or briefly exposed personal voter data. Combined with ordinary internet security risks, the traceable ballot-level data that remains inside official systems cannot be treated as securely walled off from potential misuse.

Keep reading

What in the Actual? Mamdani Doxxes NYC’s Wealthy by Publishing Their Names and Addresses

New York City Mayor Zohran Mamdani (D) just made it a whole lot easier for anyone to look up the names and home addresses of wealthy New Yorkers who own second properties in the city.

How? By publishing a searchable database of properties that could fall under the new pied-à-terre tax, complete with the owners’ full names and addresses.

The list covers unoccupied, non-primary residences worth more than $1 million across the five boroughs.

The New York Post reports that the move by the administration is “effectively doxxing thousands of wealthy New Yorkers.”

I’m almost certain that those individuals are thrilled to have their potentially empty homes’ addresses advertised to unhinged “tax the rich” leftists.

For property owners who already felt targeted by the city’s new tax push, having their personal information posted online is only pouring fuel on the fire, which is the intent, really. Mamdani is literally trying to drive wealthy individuals out of the city that serves as the economic engine of the nation.

It fits a clear pattern of taunting. RedState’s Nick Arama detailed how Mamdani recently mocked second-home owners online by gloating that notification letters for the new pied-à-terre tax were already in the mail and that “you’ve got mail.”

Arama accurately described the derisive message as “gross,” which might as well be an evergreen description going forward for Mamdani’s economically illiterate reign.

Keep reading