This blog centers entirely around fostering hope. On here I'll reblog hopecore, hopepunk, and the like. Most of my original posts with images were snagged from Pinterest.
Hey, UK folks! Waterstones is having a 3-day pre-order sale that includes the UK paperback of Enshittification (which drops on Sept 1). Use SUMMER26 to get 25% off.
Data brokers are a cancer. There's a direct line from the unrestricted collection, retention and processing of our data to a host of evils, from deepfake porn to phishing scams; from racial discrimination in hiring to ICE roundups of migrants; from targeted election interference to identity theft:
Why do data brokers exist? Because we let them. Congress hasn't passed a new federal consumer privacy law since 1988, when they made it illegal for video stores to disclose your VHS rentals. All other acts of consumer surveillance are legal. Data brokers spy on us for the same reason your dog licks its balls: because they can, and we don't stop them:
Getting rid of data brokers wouldn't solve all our problems, but it sure would go a long way to solving many of them. Rather than legally requiring platforms to spy on kids (to exclude them from being targeted by platforms' algorithms), we could prohibit platforms from spying on anyone, including kids, meaning kids couldn't be identified (much less targeted) by algorithms or ads:
Data brokers produce mountains of raw material used for every form of scam and torture. It's data brokers who power the gig economy's "algorithmic wage discrimination" system, where nurses and other workers are offered less pay based on how much credit card debt they're carrying:
So the feds (both Congress and the executive branch) have surrendered, and that leaves states alone on the battlefield fighting the privacy wars alone. State legislatures have taken some big steps, but – crucially – they've stopped short of banning data brokers from operating within their borders. Having taken a ban on data brokers off the table, states are left with complex, often unworkable "compromises" that go nowhere.
This is where DROP comes in. DROP stands for "Delete Request and Opt-out Platform," and it's a new phase of California's privacy regime that kicks off next month. Under DROP, you fill in some paperwork and then the state requires every data brokerage operating in California to delete your data, as well as any inferences they've made about you based on that data:
Implementing DROP is nowhere near as good as banning data brokers. The idea that data brokers should be able to collect, retain and process your data unless you tell them not to implies that everyone starts off wanting to be spied on, and therefore data brokers should assume that unless they hear otherwise, we're delighted to be the subject of commercial surveillance. This is an incredibly stupid supposition, contradicted by all available evidence. For example, when Apple offered iPhone owners a one-click option to block Facebook from spying on them, 96% of iPhone owners clicked the button:
Indeed, given this fact, one wonders why Apple bothers with the "don't spy on me" button at all. Why not have a "do spy on me" button that is unchecked by default, and leave users to dig through their settings to find the option to opt in to being surveilled? Of course, then it would make the fact that Apple spies on its customers and uses the data to target ads (with no way to opt out) a little awkward:
In the absence of a ban on surveillance without explicit, opt-in consent, we are left with the bizarre fiction that most of us want to be spied on, a fiction that pervades the DROP process, making the entire procedure nearly impossible to complete.
To start the DROP process, you must first create a Login.gov ID. This is an incredibly invasive process that involves photographing multiple pieces of ID and taking several selfies using special apps and webpages that hijack your device's camera and processor in a bid to prevent bad actors from spoofing the process. There's a plausible reason for this rigmarole: Login.gov is the authentication system for multiple federal, state and local IT systems in the US, so a fake or stolen Login.gov ID could be used to access your IRS, Social Security, and other very sensitive accounts.
The corollary of this is the promise of Login.gov: once you create your ID (a lengthy, multi-stage process) you won't have to jump through lots of painful bureaucratic hoops to access a wide variety of government services.
DROP didn't get the memo.
After you log in to DROP via Login.gov, you are sent a text message – to the phone number in your Login.gov profile – with a link to access a "secure" website that takes over your camera to let you take a "secure" photo of the front and back of your California driver's license or your US passport. What if you don't have either of those? I guess that means you want to be spied on by data brokers.
Note that these are the same credentials you have to supply to get the Login.gov ID that you've just used to get to this step in the process. In other words, in order to get to the stage where they ask you to photograph your driver's license, you have to have already photographed and validated your driver's license.
Once you complete this (pointless, redundant) step, you're directed back to your computer, where the process continues. Here, you must fill in all kinds of biographical detail, as well as specialized pieces of information, including your car's VIN. This is a piece of information that most people don't have – but which the California DMV does have and could auto-feed into the system, given that you've repeatedly affirmatively identified yourself to the service.
You also have to provide your mobile advertising identifier, a long, unique number that you may or may not be able to extract from your phone, depending on the model and the OS version. If you can't get it that way, you can install an app like AAID, which comes with a long list of – you guessed it – permissions to extract, store and process your private information.
Here's the thing: the whole point of a mobile ad identifier is that apps can access it (this is how they identify and track you). That step, where the system made you switch to your phone and use your camera to photograph your driver's license? That step could have automatically pulled this data off your device. That's the whole fucking point of this exercise: that web-pages and apps can request your mobile ad identifier.
Instead, DROP wants users to dig through their phone's deepest settings and/or install an app to retrieve a 32-digit number, which they then must key into a webform on their computer or in a different app on their phone.
Once you've done this, you must fill in another page of biographical information, including information that you've already provided to Login.gov and information you've already filled in on previous screens.
On this screen, you must also verify your phone number by sending yourself a text and then pasting in a unique number the system sends to you. But remember how this whole thing started? The first step is that you authenticate with Login.gov, which sends a text to your phone so you can take a (redundant) picture of your driver's license. There is no way you could get this far in the process unless you controlled the phone number you've just "verified" with the system.
Next, you must verify your email address, by receiving an email with a unique code in it and keying or pasting that into the webform, too. Again, remember how this process started: with you logging in with Login.gov, using your email address, which the system has already treated as verified since the very start of this (very) long and (very) complicated process.
This whole thing is terrible, and it is predicated on the absurd premise that Californians have to be defended from the threat of strangers who pretend to be them in order to sneakily opt them out of surveillance. DROP requires stronger authentication than any other US government system I've ever interacted with. I file my tax returns with fewer authentication steps. I renew my car's DMV registration with fewer authentication steps. I became a US citizen with fewer authentication steps.
This is either a system with no coherent threat model, or (far more probably), its threat model is that people will use it. This is California's answer to "a locked filing cabinet stuck in a disused lavatory with a sign on the door saying 'Beware of the Leopard'":
It's especially instructive to compare this process to the steps you have to take in order to "opt in" to having a data broker open a file on you and stuff it full of your sensitive, personal information, which is then sold to all comers:
Step one: Exist.
Step two: There is no step two.
It's also instructive to compare this process to the steps a data broker has to take to spy on you and sell your data:
Step one: Exist.
Step two: There is no step two.
Though there are many obvious ways this could be made better, I want to stress here that you shouldn't have to do this at all. It's entirely backwards. The process for not being spied on should look like this:
Step one: Exist.
Step two: There is no step two.
If anyone is going to be forced to jump through hoops to participate in the mass collection and catastrophic mishandling of private data, it should be the data brokers, not the people they spy on.
This kind of malicious compliance is the inevitable outcome of a process that starts by taking the obvious best measure off the table. The answer to the problem of data brokers is banning data brokers, not creating a demented hairball of form-filling that maintains the fiction that data broker surveillance is consensual.
In its own way, this process reminds me of the whole "carbon credit" fiasco. The answer to too many carbon emissions is to democratically decide to ban certain kinds of carbon emissions. But that would require states to do things, rather than simply "nudging" a process that is guided by "the market." So we end up with these junk "credits" that companies manufacture by promising not to log forests, many of which are already wildlife preserves and/or subsequently burn down:
The best critique of this whole thing came in 2021 from the Climate Ad Project, who produced a short video in which people were allowed to kill one another provided they purchased "murder offsets":
In a state of nature, murder exists. We, as a society, have decided this is bad. Rather than creating "incentives" not to murder, we just banned murder. Admittedly, we still get some murders, but when these happen, we don't treat it as "a mispricing of the anti-murder incentive" – we treat it as a crime.
The commercial surveillance industry may not be a criminal enterprise (yet), but it is the source of a torrent of crime, a flood of crime, a tsunami of crime. Every piece of your information that a data broker possesses exposes you to the risk of being victimized by a criminal. For this reason, I strongly believe that you should go through the tedious, performatively difficult DROP process:
https://consumer.drop.privacy.ca.gov/
But let's not pretend that this is good – or even adequate. There is no demand for being spied on. There is no basis for taking such enormous care in making sure people aren't maliciously removed from surveillance databases. If these databases exist at all (they should not), then we should make spies go through all this paperwork, to prove that you do want to be spied on, and unless they manage it, then spying on us should be treated as the crime it is.
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
Move over, solar and wind. Thanks to new technologies, a “geothermal renaissance” is propelling green energy further than ever before.
As with other areas of renewable energy, advances in technology mean that the potential energy output and affordability of geothermal energy are rapidly increasing.
The new geothermal process used at the Newberry Volcano in Oregon produces ten times more energy than a traditional geothermal plant while requiring less than half the water and well drilling.
it literally doesn’t matter if you’re in your 20s or 30s or 40s or 50s or 60s or 70s or 80s or fucking 90s. if you’re still alive, you literally still have that chance in your hands. don’t let your mind or anyone or anything trick you into thinking otherwise!!!!
"I can't believe humans would hunt the thylacine to extinction, humans are fundamentally evil" Hey, did you know that extinction was long thought to be impossible, and within 50 years of humans realizing that extinction via overhunting was a possibility it practically stopped happening? Did you know that humans are so desperate to prevent more losses that they're funneling millions of collective hours and billions of euros into helping other species? Hours and euros that could be spent on humans, and species on whom humanity's own survival does not depend? Did you know that due to an accidental introduction of rats, the Lord Howe Island stick insect population was brought down to 24 individuals and now there are tens of thousands of them?
This bug. This bug that, to most humans, is utterly useless, relatively gross, and completely foreign. Humans saved it because humans do not want to cause another extinction ever again if they can avoid it.
as someone in the field of ecological conservation, I can promise without a shadow of a doubt that people DO care. SO MANY people care.
I have to race to sign up to volunteer trips because even with dozens of spots available, people rush to devote their unpaid free time to helping the environment. these trips often fill up within hours. people care.
you will see a lot of bad news because that is the kind of news that people pay the most attention to. I know this more than you'd think from my optimism- not only do I live somewhere facing some of the most extreme ecological issues on the planet, I also spend my time studying the Bad Stuff every single day.
to see all of this firsthand and stay hopeful is proof enough that there IS hope. I promise there is good news, brilliant news, all the time. it's just less visible. but it's no less important or impactful.
death to nonchalance. romanticise your existence to an unreasonable degree. be gloriously delusional about how good it can get. inconvenience yourself for the sake of love. gush about your passions. get obsessed. get invested. be a fool for the right things. adore your people with your whole chest. devote yourself to something far greater than yourself. get dolled up for the most mundane activities imaginable. smile with your teeth. giggle shamelessly. kiss longer & slower. have a signature everything. accumulate hilarious stories. love so hard it rewires others’ beliefs about love. be someone God clearly had fun making. let people know they made your day. make someone’s day. take spontaneity seriously. send five voice notes in a row, because why wouldn’t you? leave people better than you found them. be so infatuated with your babies faces you take approximately 400 photos of them a day. gush. just gush!!