# Fresh From Cache > Tech news and how-to guides you don't have to be tech savvy to follow. Make sense of the tech in your life in about five minutes a week. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### About URL: https://www.freshfromcache.com/about/ Last updated: 2026-08-11T18:31:30.000Z Fresh From Cache™ is a technology publication for people who use technology every day and occasionally want someone to explain what's actually going on. News, how-tos, and explainers on the things that should have come with a better manual. No assumptions about what you already know. ## Who's writing it ![Joel Folgner, who writes Fresh From Cache](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/joel-folgner-ffc-bw.jpg) I'm Joel. I've spent over a decade in IT, which mostly means a long time watching capable people get tripped up by things that didn't need to be this complicated. I run Calmbit, an IT consulting business in Oregon, and I manage IT for a healthcare organization by day. I like the moment when something clicks for someone. When the thing that felt impossible five minutes ago suddenly makes sense, and you can see it on their face. That feeling is why I got into this work. It's also why I started writing about it. FFC is also, if I'm being honest, something I built because it made me nervous. Putting a point of view into the world is different from fixing a problem at someone's desk. I'm doing it anyway. ## How FFC is made I use AI as a writing tool, and I'd rather tell you exactly how than leave you guessing. Claude drafts News in my voice and I correct every line. I write the Learn, Blog, and how-to pieces myself. I verify every fact and make every editorial call, no exceptions. [Here's the full breakdown](https://www.freshfromcache.com/how-ffc-is-made/). ## New here? Start with these - [**How to spot a phishing email**](https://www.freshfromcache.com/how-to-spot-a-phishing-email/)**.** The one skill that stops most scams before they start. If you read only one thing here, read this. - [**What the heck is a passkey?**](https://www.freshfromcache.com/what-the-heck-is-a-passkey/) The login that's replacing passwords, explained without the jargon. - [**Your computer feels slow. Here's what to do.**](https://www.freshfromcache.com/why-is-my-computer-slow/) How to find what's actually dragging, before you spend money on a new machine. - [**Do you need backups?**](https://www.freshfromcache.com/do-you-need-backups/) The short answer is yes. This is the painless way. - [**Why I built this**](https://www.freshfromcache.com/why-i-built-this/)**.** The origin story, if you want to know who's behind it. ## Stay in the loop FFC sends a newsletter every Tuesday morning. In between, new posts go up as they're ready: news, how-tos, and the occasional longer piece. [Subscribe](#/portal/signup) to get the Tuesday email, or [read past issues](https://www.freshfromcache.com/newsletter/) in the archive. New here? [Start here](https://www.freshfromcache.com/start-here/) is the guided tour: the pieces worth reading first, sorted by what is bugging you. *Last updated July 2026.* ### Make sense of the tech in your life. In about five minutes a week. URL: https://www.freshfromcache.com/subscribe/ Last updated: 2026-08-21T01:01:58.000Z ## One short email every Tuesday Tech news and explainers that make sense, from a working IT pro. Free. Subscribe and you also get the Cache: spot a scam, spot a phishing email, fix a slow computer, and more. Subscribe free Check your inbox to confirm your free subscription. Free. One email a week. Unsubscribe anytime. **News and explainers for people who aren't techy, written by a working IT pro. What changed, why it matters to you, and what to actually do about it.** Every issue, you get: - What's happening in tech, minus the jargon - Why it matters to you - The one thing to do about it, if anything A few recent stories: - [Five shortcuts I wish somebody had told me about](https://www.freshfromcache.com/hidden-phone-and-computer-shortcuts/) - [Your library card is a subscription you already pay for](https://www.freshfromcache.com/library-card-audiobooks/) - [Before you price hearing aids, take the test that came with your earbuds](https://www.freshfromcache.com/can-airpods-be-used-as-hearing-aids/) - [Your doctor wants to record the visit with AI. Here is what to ask before you say yes.](https://www.freshfromcache.com/should-you-let-ai-record-your-doctor-visit/) Also check out [The Cache](https://www.freshfromcache.com/cache/). Our growing resource page with printable PDFs. Some of the resources available are: - Diagnosing a slow PC - Identifying scams and phishing - What to do if you've been scammed triage card - Digital health check ### You're in. URL: https://www.freshfromcache.com/your-guide/ Last updated: 2026-07-17T03:36:24.000Z Check your inbox. Your welcome email is on its way, with a link to everything you get. Don't see it in a minute or two? Check spam or your Promotions tab, and add **joel@freshfromcache.com** to your contacts so the next one lands where it should. Want your free downloads now? They all live in one place: [Open the Cache →](https://www.freshfromcache.com/cache/) Your first issue lands Tuesday morning. One short email, about five minutes, that makes sense of the tech in your life. If a tech question comes up before then, just reply to that email. It reaches me. ### How FFC is made URL: https://www.freshfromcache.com/how-ffc-is-made/ Last updated: 2026-07-04T18:08:07.000Z Fresh From Cache is one person's publication. I use AI as a writing tool, and I'd rather tell you exactly how than leave you guessing. It works differently depending on what you're reading. - **News posts:** I pick the story and the sources, then Claude and I research and fact-check them. Claude drafts in my voice, and I review and correct every line before anything goes out. - **Learn, Blog, and how-to pieces:** I write these myself. Claude handles mechanical cleanup only, spelling, punctuation, the typo I missed. Two things hold for everything here, no exceptions. I verify every concrete fact myself before it publishes, and every editorial call is mine. The byline is real, and a person read the piece before you did. Why lay all this out? Because hiding it would be the fastest way to lose your trust. There's a lot of tech content now that's generated wholesale, published under a name that isn't a real person, with nobody checking whether it's true. This is the opposite of that. If you ever catch something wrong, tell me and I'll fix it: [joel@freshfromcache.com](mailto:joel@freshfromcache.com). ### Frequently asked questions URL: https://www.freshfromcache.com/faq/ Last updated: 2026-08-11T18:31:31.000Z Short answers to the things people ask most. If yours isn't here, email me at joel@freshfromcache.com. - [What is Fresh From Cache?](#what-is-fresh-from-cache) - [Who writes it?](#who-writes-it) - [Is it free?](#is-it-free) - [Is this written by AI?](#is-this-written-by-ai) - [How often do you publish?](#how-often-do-you-publish) - [Who is it for?](#who-is-it-for) - [What topics does it cover?](#what-topics-does-it-cover) - [How do I subscribe?](#how-do-i-subscribe) - [How do you check your facts?](#how-do-you-check-your-facts) - [Do you use affiliate links or run sponsored posts?](#do-you-use-affiliate-links-or-run-sponsored-posts) - [Can I share or republish your articles?](#can-i-share-or-republish-your-articles) - [How do I contact you or suggest a topic?](#how-do-i-contact-you-or-suggest-a-topic) ## What is Fresh From Cache? A technology publication for people who use technology every day and occasionally want someone to explain what's actually going on. It covers online scams, privacy and security, common tech problems, and plain-language explainers, with no assumptions about what you already know. ## Who writes it? Joel Folgner. I've spent over a decade in IT. I run Calmbit, an IT consulting business in Oregon, and I manage IT for a healthcare organization by day. Fresh From Cache is my own publication. ## Is it free? Yes. Every article is free to read, and the weekly newsletter is free to join. There's no paywall and no paid tier. ## Is this written by AI? A person writes or edits and fact-checks every piece, and every editorial call is mine. I use AI as a writing tool, and I'm specific about how, per type of post. The full breakdown is on the [How FFC is made](https://www.freshfromcache.com/how-ffc-is-made/) page. ## How often do you publish? A newsletter goes out every Tuesday morning. In between, new posts go up as they're ready. ## Who is it for? Non-technical adults, small business owners, and nonprofit leaders. If you're comfortable using technology but tired of articles that assume you already know the jargon, it's for you. ## What topics does it cover? Online scams and how to spot them, privacy and security, common tech problems and how to fix them, and plain-language explainers on the tools and news that affect regular people. ## How do I subscribe? Join the free newsletter through the [subscribe](#/portal/signup) page. One email on Tuesday mornings. ## How do you check your facts? I verify every concrete fact myself before a piece publishes, and articles link their sources so you can check the original. If something's wrong, tell me and I'll fix it. ## Do you use affiliate links or run sponsored posts? No. Fresh From Cache doesn't use affiliate links, and nothing here is a paid placement. Recommendations are based only on what I think is actually worth your time. ## Can I share or republish your articles? Sharing a link is always welcome, and it's how the publication grows. To republish a whole article somewhere else, email me first. ## How do I contact you or suggest a topic? Email joel@freshfromcache.com. Story tips, corrections, and questions are all welcome. Not sure which article you need? [Start here](https://www.freshfromcache.com/start-here/) sorts the hand-picked ones by topic, and the [glossary](https://www.freshfromcache.com/glossary/) explains any term that trips you up. ### Glossary URL: https://www.freshfromcache.com/glossary/ Last updated: 2026-08-11T18:31:33.000Z Definitions for the terms that come up most around here, in one place. Each links to the full explainer if you want to go deeper. - [Passkey](#passkey) - [VPN](#vpn) - [MFA (multi-factor authentication)](#mfa-multi-factor-authentication) - [Phishing](#phishing) - [Ransomware](#ransomware) - [EXIF and geotagging](#exif-and-geotagging) - [ACR (automatic content recognition)](#acr-automatic-content-recognition) - [Deepfake](#deepfake) - [Telematics](#telematics) - [Encryption](#encryption) - [Backup](#backup) ## Passkey A way to sign in to an account without a password. Your phone or computer proves it's you with your fingerprint, face, or PIN, so there's nothing for a scammer to steal or trick out of you. [Read the full explainer.](https://www.freshfromcache.com/what-the-heck-is-a-passkey/) ## VPN A virtual private network routes your internet traffic through another company's server, hiding your activity from your internet provider and the network you're on. It's useful on public Wi-Fi, but it doesn't make you anonymous, and the VPN company can see what your provider used to. [Read the full explainer.](https://www.freshfromcache.com/what-a-vpn-actually-does/) ## MFA (multi-factor authentication) A second check when you log in, on top of your password: a code, a tap on your phone, or a passkey. Sometimes called two-factor. It's the single best thing you can turn on to keep an account from being taken over. [Read the full explainer.](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/) ## Phishing A fake message (email, text, or call) built to trick you into handing over a password, a code, or money, usually by pretending to be a company or person you trust and pushing you to act fast. [Read the full explainer.](https://www.freshfromcache.com/how-to-spot-a-phishing-email/) ## Ransomware Malicious software that locks up your files and demands payment to unlock them. Modern ransomware is run like a business, with different criminal groups handling the break-in, the software, and the payment. [Read the full explainer.](https://www.freshfromcache.com/ransomware-has-been-franchised/) ## EXIF and geotagging EXIF is the hidden data your phone attaches to a photo: the date, the camera settings, and often the exact GPS location where it was taken. Sharing a photo can share where you were, unless that data is stripped out first. [Read the full explainer.](https://www.freshfromcache.com/your-photos-know-where-you-live/) ## ACR (automatic content recognition) A feature built into most smart TVs that identifies what's on your screen, frame by frame, and reports it back to the manufacturer to build an advertising profile. It runs whether the show came from an app, a cable box, or a game console. [Read the full explainer.](https://www.freshfromcache.com/tv-side-hustle/) ## Deepfake A video, image, or voice clip generated by AI to look or sound like a real person saying or doing something they never did. Increasingly used in scams that impersonate a boss, a relative, or a celebrity. [Read the full explainer.](https://www.freshfromcache.com/fake-face-real-money/) ## Telematics The driving data your car collects: speed, braking, cornering, mileage, and location. Several automakers have sold it to data brokers who pass it to insurers, sometimes without the driver knowing. [Read the full explainer.](https://www.freshfromcache.com/your-car-grades-your-driving/) ## Encryption Scrambling a message so only the intended recipient can read it. End-to-end encryption means not even the company carrying the message can see its contents. [Read the full explainer.](https://www.freshfromcache.com/iphone-android-texts-encrypted/) ## Backup A second copy of your files kept somewhere separate, so a lost, stolen, broken, or ransomware-hit device doesn't take your data with it. The copy only counts if it's recent and you've confirmed it actually restores. [Read the full explainer.](https://www.freshfromcache.com/do-you-need-backups/) Looking for the articles behind these terms? [Start here](https://www.freshfromcache.com/start-here/) is the guided tour. ### Start here URL: https://www.freshfromcache.com/start-here/ Last updated: 2026-08-27T12:50:17.000Z New here? This is the guided tour. Pick the thing that's bugging you, or the topic you've been meaning to get a handle on, and start there. These are hand-picked, not just the newest. There are no ads here, no affiliate links, and nothing for sale. Nobody pays to be recommended, and no link earns a commission. The longer story is in [why I built this](https://www.freshfromcache.com/why-i-built-this/). Not sure where to begin? Take the [digital health check](https://www.freshfromcache.com/checkup/). It scores where you stand and hands you a short list of what to fix, most important first. **If something is happening right now, skip the tour.** - **Something looks like a scam or a fake email.** [How to spot a phishing email in 2026](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). - **You already clicked, paid, or gave something away.** [You just got scammed. What now?](https://www.freshfromcache.com/what-to-do-after-a-scam/) - **The computer is slow or acting strange.** [Your computer feels slow. Here's what to do.](https://www.freshfromcache.com/why-is-my-computer-slow/) - [Spotting scams](#spotting-scams) - [Protecting your accounts](#protecting-your-accounts) - [Do you need antivirus?](#do-you-need-antivirus) - [Your privacy](#your-privacy) - [Kids and family](#kids-and-family) - [Making sense of AI](#making-sense-of-ai) - [Buying and owning tech](#buying-and-owning-tech) - [Fixing common problems](#fixing-common-problems) - [Your phone](#your-phone) - [Print-and-keep guides](#print-and-keep-guides) ## Spotting scams - [You just got scammed. What now?](https://www.freshfromcache.com/what-to-do-after-a-scam/) The first hour, in order: stop the money, lock your email, report it, and expect the second scam. - [How to spot a phishing email in 2026](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). The one skill that catches most scams before they cost you anything. - [The fake CAPTCHA scam you run yourself](https://www.freshfromcache.com/fake-captcha-scam/). The scam that talks you into infecting your own computer. - [Why the robocalls about your Google listing won't stop](https://www.freshfromcache.com/google-listing-robocalls/). Why the support number you Googled might not be the real company. - [The power company is not calling to cut you off in 30 minutes](https://www.freshfromcache.com/power-shutoff-scam-call/). The utility shutoff call, the script it follows, and the number to call instead. - [The post office already photographs your mail. It will send you the pictures.](https://www.freshfromcache.com/usps-informed-delivery/) USPS emails you photos of the letters coming to your house that day, free. Most eligible addresses have never turned it on. ## Protecting your accounts - [Start using a password manager](https://www.freshfromcache.com/start-using-a-password-manager/). The one habit that fixes reused passwords, and which manager to actually pick. - [What the heck is a Passkey?](https://www.freshfromcache.com/what-the-heck-is-a-passkey/) The login that's replacing passwords, and why it's harder to steal. - [Can somebody steal a passkey?](https://www.freshfromcache.com/can-passkeys-be-stolen/) What has to go wrong first, and why a clean computer is the whole defense. - [Why MFA annoyance is worth it](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/). The extra login step that stops most account takeovers cold. - [Freeze your credit before someone else uses it](https://www.freshfromcache.com/freeze-your-credit/). The free lock that stops someone opening loans and credit cards in your name. - [Who gets your photos and email when you're gone? Set this up in five minutes.](https://www.freshfromcache.com/who-gets-your-accounts/) So the people you love are not locked out of your photos, email, and money if something happens. - [Check your email's recovery info before you get locked out](https://www.freshfromcache.com/email-recovery-check/). A quick check on the one account every other password resets through. - [Leaked Email](https://www.freshfromcache.com/leaked-email/). What to actually do when your address turns up in a breach. ## Do you need antivirus? - [Do you need antivirus, or is Windows Defender enough?](https://www.freshfromcache.com/do-you-need-antivirus/) What the independent labs found, who should still pay, and how to cancel McAfee or get a Norton renewal refunded. - [Do you need antivirus on a Mac?](https://www.freshfromcache.com/do-you-need-antivirus-on-a-mac/) The three layers macOS already runs for free, and the one rule that does more than any scanner. ## Your privacy - [What a VPN actually does](https://www.freshfromcache.com/what-a-vpn-actually-does/). What a VPN does, what it can't, and whether you actually need one. - [Your photos know where you live](https://www.freshfromcache.com/your-photos-know-where-you-live/). The hidden location tag riding along in the photos you share. - [Your car has been grading your driving and selling the report card](https://www.freshfromcache.com/your-car-grades-your-driving/). Who buys the driving score, how to opt out, and what Oregon just changed. - [Your browser can block trackers and scam sites. The strongest settings just aren't on by default.](https://www.freshfromcache.com/chrome-edge-privacy-settings/) The settings to turn on in Chrome and Edge, and what each one buys you. - [Data brokers have a file on you. California is making them delete it.](https://www.freshfromcache.com/what-is-a-data-broker/) Who buys and sells your information, and the delete button California built. - [Two people agreed to your location sharing. Three are in it.](https://www.freshfromcache.com/what-location-sharing-actually-shares/) Who else ends up in the loop when you share your location with one person. - [What a Flock camera actually does](https://www.freshfromcache.com/what-is-a-flock-camera/). The license plate readers on your street, and what they keep. - [Shark fixed the vacuum flaw. Here's what yours knows about you.](https://www.freshfromcache.com/robot-vacuum-watching-you/) The map your robot vacuum made of your house, and where it goes. - [Your TV has a side hustle, and you're paying for it](https://www.freshfromcache.com/tv-side-hustle/). How a free smart TV app turns your connection into someone else's. ## Kids and family - [Most teen safety features don't work. Here's what does.](https://www.freshfromcache.com/teen-safety-features-that-work/) The controls that survived independent testing, and the ones that failed it. - [The school laptop is a work computer. Here's what it does and doesn't monitor.](https://www.freshfromcache.com/is-my-kids-school-laptop-monitored/) Your child was handed a work computer and nobody explained the rules. What the district can see, and what to check before you sign the packet. - [Who is behind your child's GPS watch?](https://www.freshfromcache.com/kids-gps-watch-security/) Consumer Reports found trackers that skip the second login step, and cheap watches running on platforms the seller cannot name. How to check the one on your child's wrist. - [The Disturbing Reality of AI-Powered Plush Toys](https://www.freshfromcache.com/ai-powered-toys/). What the AI toys say when nobody is testing them. ## Making sense of AI - [Fake face. Real money.](https://www.freshfromcache.com/fake-face-real-money/) How AI deepfakes power a new wave of impersonation scams. - [How to get a deepfake of you taken down](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/). Which report actually gets it removed, ranked by what works. - [AI tips for people who don't want to get left behind](https://www.freshfromcache.com/ai-tips-for-everyday-people/). The habits that make AI actually useful, and why each one works. - [What is an AI agent, and should you let one loose on your computer?](https://www.freshfromcache.com/what-is-an-ai-agent/) What an agent actually does, and how to try one without getting burned. - [Your doctor wants to record the visit with AI. Here is what to ask before you say yes.](https://www.freshfromcache.com/should-you-let-ai-record-your-doctor-visit/) Four questions for the exam room, and how to decline. - [Can you stop AI companies from training on what you write?](https://www.freshfromcache.com/stop-ai-training-on-your-writing/) The opt-out settings are real, they only work going forward, and there is one place you have real power. ## Buying and owning tech - [What laptop specs actually matter in 2026?](https://www.freshfromcache.com/how-to-read-a-laptop-price-tag/) The four specs that decide how long a laptop lasts, and the traps on the price tag. - [The AI boom is showing up on price tags](https://www.freshfromcache.com/why-your-next-phone-costs-more/). Why the cheapest devices are taking the biggest hit, and a real answer on whether to buy now or wait. - [Before you price hearing aids, take the test that came with your earbuds](https://www.freshfromcache.com/can-airpods-be-used-as-hearing-aids/). AirPods Pro carry an FDA-authorized hearing aid for mild to moderate loss, and a free hearing test. Take the test before you price the real thing. - [What you own when your printer is on a subscription](https://www.freshfromcache.com/printer-ink-subscription/). Cancel the subscription and the cartridge stops working, ink and all. What the contracts say, and how to leave without a dead printer. - [You bought it, but do you own it?](https://www.freshfromcache.com/do-you-own-what-you-buy/) That movie you clicked Buy on is a license, not a possession. What that means, and where you can still own what you pay for. - [What is a CPSC product safety warning?](https://www.freshfromcache.com/what-is-a-cpsc-product-safety-warning/) The safety notice that comes with no refund, and what to check before you buy a charger, a power strip, or a power bank. - [Your library card is a subscription you already pay for](https://www.freshfromcache.com/library-card-audiobooks/). Free audiobooks, ebooks, and magazines on the phone already in your pocket. No card? You can probably fix that today without leaving home. ## Fixing common problems - [Your computer feels slow. Here's what to do.](https://www.freshfromcache.com/why-is-my-computer-slow/) How to find what's actually slowing your PC, before you buy a new one. - [Your phone says storage is almost full. Don't delete anything yet.](https://www.freshfromcache.com/why-is-my-phone-storage-full/) Where your photos actually live, the cleanup order that can't cost you one, and when to just buy storage. - [Why is my Wi-Fi slow?](https://www.freshfromcache.com/why-is-my-wifi-slow/) Five different problems feel identical from the couch. Six free checks tell you which one is yours before you spend anything. - [Why rebooting your router works, and when it won't](https://www.freshfromcache.com/why-does-rebooting-your-router-work/). What the restart actually does, which device to restart, and when it won't fix anything. - [Do you need backups? You might already have them.](https://www.freshfromcache.com/do-you-need-backups/) The short answer is yes, and the painless way to set it up. - [Four steps to fix your printer (and the rule for when to stop)](https://www.freshfromcache.com/four-steps-to-fix-your-printer/). The printer fix that works more often than it has any right to. - [Microsoft stopped patching Windows 10\. Now what?](https://www.freshfromcache.com/windows-10-out-of-support/) Six plain ways to handle it, including the free extension that buys you until October 2027. - [Check Your Router's Expiration Date. No Manufacturer Is Required to Tell You It Has One.](https://www.freshfromcache.com/router-expiration-date/) Every router stops getting security patches on a date nobody tells you. ## Your phone - [Set up your phone to share your medical info in an emergency](https://www.freshfromcache.com/phone-medical-id/). Set up the screen that helps first responders help you. - [The apps I'd recommend aren't the ones I use most](https://www.freshfromcache.com/suggested-apps/). A short list, each app with the reason it earned the spot. - [Are those smart glasses recording you? How to tell](https://www.freshfromcache.com/smart-glasses-recording-you/). What they capture, where the video goes, and why the warning light is easy to miss. - [Make your phone stop ringing for robocalls](https://www.freshfromcache.com/stop-spam-calls/). The setting that sends unknown numbers straight to voicemail. - [Your phone can copy text out of any photo](https://www.freshfromcache.com/copy-text-from-a-photo/). Lift a serial number, a password, or a menu straight off the screen. - [Share your Wi-Fi without ever spelling out the password](https://www.freshfromcache.com/share-wifi-qr-code/). A QR code your guests scan instead. - [Your phone has a magnifying glass](https://www.freshfromcache.com/your-phone-is-a-magnifying-glass/). The built-in tool for reading the fine print. - [Five shortcuts I wish somebody had told me about](https://www.freshfromcache.com/hidden-phone-and-computer-shortcuts/). Small things your phone and computer already do, if you know where to press. ## Print-and-keep guides Some help is better on paper. [The Cache](https://www.freshfromcache.com/cache/) is our library of free printable guides: a scam-spotting card, a phishing check, a first-hour-after-a-scam card, a who-gets-your-accounts worksheet, a backup card, and more. Print them for yourself, or for someone you look after. Run into a word you don't know? The [glossary](https://www.freshfromcache.com/glossary/) explains the jargon without assuming you know any of it. ## Get the Tuesday issue One short email a week with everything new on the site. Free, no ads, unsubscribe anytime. Subscribe You're in. See you Tuesday. ### The Cache URL: https://www.freshfromcache.com/cache/ Last updated: 2026-08-29T22:52:54.000Z **Your free stash of tech help.** Every one here is short, free, and yours to print or share. New pieces get added over time, so check back. [Start hereHow healthy is your digital life?A 2-minute digital health check that scores where you stand and shows you the few things worth fixing, most important first.Take the check →](https://www.freshfromcache.com/checkup/) Scams ### Is this a scam? A one-page check that catches almost any scam before you click, call back, or pay. The four tells, and what to do. [Download PDF →](https://www.freshfromcache.com/content/files/2026/07/is-this-a-scam.pdf)1 page After a scam ### The first hour after a scam The four steps in order, the one deadline that decides what comes back, and every phone number to call, on paper before you need it. [Download PDF →](https://www.freshfromcache.com/content/files/2026/07/first-hour-after-a-scam.pdf)2 pages Phishing ### Is this a phishing email? The one check that catches almost any fake email: read the address after the @. Comes with a worked example. [Download PDF →](https://www.freshfromcache.com/content/files/2026/07/is-this-phishing.pdf)2 pages Your accounts ### Who gets your accounts? A fillable worksheet so the people you love are not locked out of your email, photos, and money if something happens. [Download PDF →](https://www.freshfromcache.com/content/files/2026/07/who-gets-your-accounts.pdf)Fillable Slow computer ### Your computer feels slow Find what is actually slowing your computer down, in about ten minutes, before you spend a dime on a new one. [Download PDF →](https://www.freshfromcache.com/content/files/2026/07/ffc-computer-slow-guide.pdf)Guide Backups ### What to back up, and how The two copies every computer needs, the five things people forget to include, and the exact clicks for Windows and Mac. [Download PDF →](https://www.freshfromcache.com/content/files/2026/08/back-up-your-pc.pdf)2 pages Buying ### How to read a laptop price tag The four specs that decide how long a laptop lasts, the habit that beats every badge, and the support dates no store prints. Take it to the store. [Download PDF →](https://www.freshfromcache.com/content/files/2026/08/laptop-price-tag.pdf)2 pages More on the way. New additions land right here, free, the moment they are ready. ### How healthy is your digital life? URL: https://www.freshfromcache.com/checkup/ Last updated: 2026-07-21T21:52:39.000Z A 2-minute digital health check Answer a few quick questions about how you use your phone and computer. You will get back a safety score and a short, personal list: only the things you have not done yet, most important first, with how to fix each one. No lecture, no list of forty things. Just what is worth your time. Start the check → Your answers stay in your browser. Nothing is sent anywhere, and nothing is saved. Question 1 Yes, that is set No, not yet Not sure ← Back Your results #### Keep your results Nothing is saved on our end, so this link is the only copy. Your answers exist in the characters after the # in your address bar, which browsers keep to themselves. Open it on any device to see this list again. Copy my results link [Email it to myself](#) ### Want these fixed for you, one at a time? Every Tuesday I send one short email that makes sense of the tech in your life. Free, and it comes with the Cache: printable guides for the items above. Subscribe free Sending your sign-in link… Check your inbox for the confirmation link. The Cache is yours the moment you click it. That did not go through. Try again, or subscribe at freshfromcache.com/subscribe. One short email every Tuesday. Free, and you can leave anytime. Already subscribed? You are set: everything above is yours in the Cache. [Browse the Cache →](https://www.freshfromcache.com/cache/) Print my list Start over ### Support URL: https://www.freshfromcache.com/support/ Last updated: 2026-08-18T00:43:10.000Z Fresh From Cache is free to read. No ads, no sponsors, no articles locked behind a paywall. It still costs something to run. Hosting, the email service, the occasional photo license, and a fair number of Sunday mornings. If FFC has saved you a headache, or kept somebody in your family from clicking the wrong link, you can chip in here. One time, whatever amount makes sense to you. It does not unlock anything, because there is nothing to unlock. Everyone gets the same articles at the same time. [Support FFC](https://www.freshfromcache.com/#/portal/support) If money is not the right fit, forward the Tuesday issue to one person who needs it. Word of mouth is how most people find this. Thank you for your support! ## Posts ### Your smart TV can track what you watch. URL: https://www.freshfromcache.com/is-my-smart-tv-tracking-what-i-watch/ Last updated: 2026-09-05T16:34:00.000Z Your television can recognize what's playing on its own screen. On several major brands that includes whatever arrives over HDMI, so the cable box and the game console are covered too. Whether yours is doing it right now comes down to one setting. There is no standard name for it and no standard place to find it. ## The name on your TV is not the name in the news The technology is automatic content recognition, ACR for short. What the setting is called depends on the television. | Your TV | What to look for | | ---------------------------------------------------------------------- | ------------------------------------------------------------------------------- | | **Samsung** | Viewing Information Services | | **LG** | Viewing Information (it feeds a feature named Live Plus) | | **Vizio** | Viewing Data | | **Roku TV**, including Roku-powered TCL, Hisense, Philips and onn sets | Automatic Content Recognition (ACR); on older software, Use Info from TV Inputs | | **Sony BRAVIA** | Samba Interactive TV (run by an outside company, Samba TV) | | **Hisense sets on VIDAA** | Enhanced Viewing | | **Amazon Fire TV** | No ACR control; separate Fire TV privacy settings | Samsung described the mechanism to advertisers in a 2022 Samsung Ads guide. In its own words, "Our proprietary ACR technology takes glass-level screenshots every 500 milliseconds on our opted-in Samsung TVs, converts them into 'unique patterns,' and compares these visual snapshots against others in the matching server." A diagram in the same guide is labeled "Image captured every 500ms." That's Samsung's sampling rate, not an industry standard. The researchers below note that LG's own documentation puts its sets at every 10 milliseconds. The television isn't sending a normal image file of the screen. It turns the sample into a fingerprint and sends that for matching. Sony's support page says so for the Samba system on its sets. "No image from the TV screen is captured and sent from your BRAVIA TV." The comparison the researchers use is Shazam. A short fingerprint travels, gets matched against a large library, and comes back with a name. Roku's page adds that a fingerprint with no match in its catalog comes back as nothing, so a home video is not recognized as anything. ## HDMI is not a way around it ![Close-up of the HDMI IN ports on the back edge of a television.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/09/theregisti--X5GFuPvrW8-unsplash.jpg) Researchers from University College London, UC Davis and Universidad Carlos III de Madrid put Samsung and LG sets in a lab and watched the network traffic across six ways of using a television. They found ACR traffic while the sets showed linear broadcast, and while the sets were being used as external displays over HDMI. Plugging in a laptop or a game console doesn't turn the television into a dumb monitor. They didn't find ACR traffic while third-party apps such as Netflix and YouTube were running on the tested sets. In the United States, they did see it during the manufacturers' own free channels, Samsung TV Plus and LG Channels, where the UK sets showed none. They also separated how often the screen gets sampled from how often anything leaves the house. On their sets, LG contacted its ACR servers about every fifteen seconds and Samsung about once a minute. The samples pile up locally and travel in batches. ## Where the data goes Vizio's current Viewing Data policy says the company licenses that data "to advertisers, ad agencies, analytics companies, media companies, and other ad technology companies." The same policy says it may be combined with material bought elsewhere: "demographic data, smartphone location, web history, and purchasing history." In 2017 the FTC and New Jersey settled with Vizio over viewing data taken from 11 million televisions, and the complaint describes demographics attached to the viewing history: - Sex - Age - Income - Marital status - Household size - Education level - Home ownership - Household value Vizio paid $2.2 million and agreed to ask permission going forward. The feature had been called Smart Interactivity, and Vizio told buyers it "enables program offers and suggestions." Walmart owns Vizio now. The policy offers you "an additional choice about whether Walmart can link your Viewing Data to the Walmart account logged in to those devices." ## Why TV makers want this data A good 65-inch television costs less than the phone in your pocket now, and the reason is written in the makers' own account books. In the spring of 2024, Vizio's Device business took in $267.9 million and returned $900,000 in gross profit. Its Platform+ business, which sells advertising and viewing data, took in $169.4 million and returned $98.6 million. Across the first half of that year, Device gross profit was negative $6.3 million. Device covers sound bars as well as televisions, and Platform+ covers more than advertising, so neither number is a clean read on TVs alone. Roku's is cleaner. For all of 2025, Devices took in $592 million at a gross margin of negative 14 percent. Platform took in $4.145 billion at 52 percent. Roku told investors to expect device margins in the negative mid-teens again in 2026. A television can keep earning after it leaves the store. Those platform businesses are wider than advertising, and ACR is one of the systems feeding them what happens on the screen. ## Texas sued five TV makers On December 15, 2025, Texas sued Sony, Samsung, LG, Hisense and TCL over ACR under the state's Deceptive Trade Practices Act. Two days later a court issued a temporary restraining order against Hisense, barring it from collecting or sharing ACR data about Texans while the case runs. Samsung reached an agreement with the state on February 26, 2026, promising not to collect ACR viewing data from Texans without express consent and to make its disclosures clear and conspicuous. LG followed on May 11, agreeing to a pop-up disclosure and a clear way to opt out. Neither agreement, as the attorney general described it, carries a dollar figure. Texas said on May 11 that its cases against Sony, Hisense and TCL remained ongoing. None of the allegations against those three has been decided on the merits. The Hisense restraining order is a court order, but it settles nothing about whether the claims are true. ## The companies have an answer Samsung's advertiser guide describes the feature as opt-in and reversible. "If a user does not opt in to these services, or if they subsequently withdraw their consent, their use of the Smart TV is not affected." Vizio's policy says each television gets a notice and a choice before any Viewing Data is collected, and that turning it off will not affect how the set performs. Sony says Samba Interactive TV runs only if you accept Samba TV's terms. Roku's own ACR policy describes collection starting "when you enable Smart TV Experience during device set up." LG spells out the split. Its TVs began showing a User Agreements screen after the company updated its Terms of Use on August 28, 2026, and LG's support page says the Terms of Use and Privacy Policy are required to use smart services such as Netflix and YouTube, while "all other agreements are optional." Its own FAQ is more direct. "Agreements related to viewing information, voice features, and personalized ads are optional and are not required to use basic smart services." You can change any of them later under Settings, then Privacy & Terms, then User Agreements. Consumer Reports tested 2025 sets and found LG's viewing agreements off by default until accepted, and Sony's Bravia data options off by default too. The researchers checked the other half of the promise. After opting out on their Samsung and LG sets, they found "a complete absence of communication with any previously identified ACR domains." The controls did what they said. So there is a decent chance the setting on your television is already off, but no way to know without looking. The permission gets collected during setup, in a stack of agreements, alongside the ones you have to accept to use the apps at all. ## "I don't care if somebody knows I watch football" What you watch is not the whole picture. Vizio's policy describes what makes viewing history valuable, and it's more specific than a hypothetical. A data partner can identify another device sharing the television's IP address, a phone with location turned on, and check whether that phone later turned up at a store. The viewing history becomes one more signal attached to a household that already has [a file with a data broker](https://www.freshfromcache.com/what-is-a-data-broker/). ## Turning it off ![A hand holding a television remote, pointed at a TV showing a menu screen in the background.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/09/erik-mclean-U-Vu_r6qyyU-unsplash.jpg) Menus move between model years and software updates, so look for the name of the control rather than the exact path. If yours doesn't match, search your model number plus the name. **Samsung.** Settings, then All Settings, then General & Privacy, then Terms & Privacy. Uncheck Viewing Information Services. On many current models the same control also appears under Privacy Choices, in the same General & Privacy area. Older Samsung sets may put the control under Terms and Policy, or use older SyncPlus or Interactive Marketing wording for the same choices. **LG.** Settings, then All Settings, then Support, then Privacy & Terms, then User Agreements. Decline Viewing Information. On older webOS sets, User Agreements may sit under General, or under About This TV. **Vizio.** All Settings, then Privacy & Legal, then Viewing Data. Older sets use All Settings, then Admin & Privacy. Vizio publishes both paths, so try the other one if the first is missing. **Roku, including Roku-powered TCL, Hisense, Philips and onn sets.** Settings, then Privacy, then Smart TV Experience. On current software, uncheck Automatic Content Recognition (ACR) and Viewing Information Disclosure. On older software the same control is a single line called Use Info from TV Inputs. Roku's More Ways to Watch suggestions run on this technology, so turning it off turns those off too. **Sony.** Look for Samba Interactive TV by name. Sony's own pages put it under System Preferences on many models, including Google TV sets. Consumer Reports found it just below Privacy in All Settings on 2025 models. Sony itself says the location varies by model. **Hisense sets running VIDAA, Hisense's own system.** Hisense calls its service Enhanced Viewing, and its own privacy notice describes it as an optional service. Its manuals say the feature runs only after you choose Yes, Enable Enhanced Viewing during setup. The control sits in a Privacy or Legal section under Settings, then System or Support, and the wording moves between model years, so on this brand especially, search your model number. **Amazon Fire TV sets.** Different situation. Amazon told Consumer Reports that Fire TV doesn't use ACR and doesn't read a cable box or other non-Amazon device plugged into the set. It does collect what you watch over an antenna and through apps. Amazon's own privacy FAQ names the controls, all under Settings, then Preferences, then Privacy Settings: Device Usage Data, Collect App Usage Data, Interest-based Ads, and on Fire TV televisions, Over-the-air Viewing Data. Newer software adds Manage Sharing From Apps, where Share App Viewing and Content Info stops supported apps sending viewing information to Amazon. Consumer Reports found the toggles on by default. Vizio's control goes further than the others. Turning Viewing Data off "will trigger the deletion of historical logs of Viewing Data for the VIZIO OS product from VIZIO's database," and a factory reset returns the setting to off rather than on. Roku's policy says the opposite about history. Data collected while the feature was on "will be retained by Roku and may still be shared with third parties" after you turn it off. What the control stops is the panel reading the screen. It isn't an off switch for advertising, and Vizio says as much in its own policy: after you turn Viewing Data off, "for a period of time you may continue to see tailored ads on other devices that were targeted based on Viewing Data that was shared before you turned off collection." What you give up going forward is recommendations and ad targeting built on what the set saw. ## What it does not turn off Netflix still knows what you watch on Netflix. Turning off ACR stops the television from reading the screen but does nothing to the apps, which keep their own records. The platform account keeps a log too. Vizio says it plainly: disabling Viewing Data "will not, however, affect or limit Activity Data collection," which is the record of what you open and search in the TV's own menus. On a Google TV set, Google's terms are a separate agreement you can't decline and still have a smart TV, and Google says the Google TV platform itself doesn't run ACR, though the brand on the front may. Your internet provider still sees the traffic leaving the house. And the television is not the only appliance with a second job. [Your router is watching motion](https://www.freshfromcache.com/wifi-motion-sensing/) and [your car is grading your driving](https://www.freshfromcache.com/your-car-grades-your-driving/) on the same idea. A streaming stick plugged into a television that never joins wifi keeps the TV maker's ACR out of it. The stick then has its own account, its own telemetry and its own advertising ID. You will have at least moved the tracking to a company you picked. ## What to do today Find the control on your set and look at it before you decide anything. It may already be off. If it's on, turn it off, then check it again after the next factory reset. Then read the price tag on your next set differently. [The same reading works on a laptop](https://www.freshfromcache.com/how-to-read-a-laptop-price-tag/). ## Sources - [Anselmi, Vekaria, D'Souza, Callejo, Mandalari and Shafiq, "Watching TV with the Second-Party: A First Look at Automatic Content Recognition Tracking in Smart TVs," ACM Internet Measurement Conference 2024](https://arxiv.org/abs/2409.06203?ref=freshfromcache.com) - [Samsung Ads, "Understanding Automatic Content Recognition (ACR)," guide for advertisers, Canada, 2022](https://iabcanada.com/wp-content/uploads/2022/09/Samsung-Ads-ACR-Guide-CA.pdf?ref=freshfromcache.com) - [Samsung support, "Samsung Smart TV Automatic Content Recognition (ACR) Feature," article ANS10010616](https://www.samsung.com/us/support/answer/ANS10010616/?ref=freshfromcache.com) - [VIZIO Viewing Data Supplement to the VIZIO Privacy Policy](https://www.vizio.com/en/terms/privacy-policy/viewing-data-privacy-policy?ref=freshfromcache.com) - [VIZIO Holding Corp., Q2 2024 earnings release, August 7, 2024](https://s29.q4cdn.com/107810760/files/doc%5Ffinancials/2024/q2/v2/Q2-24-Earnings-Release.pdf?ref=freshfromcache.com) - [Roku, Inc., Q4 and Full Year 2025 Shareholder Letter, February 12, 2026](https://image.roku.com/bWFya2V0aW5n/4Q25-Shareholder-Letter.pdf?ref=freshfromcache.com) - [Federal Trade Commission, "VIZIO to Pay $2.2 Million to FTC, State of New Jersey," February 6, 2017](https://www.ftc.gov/news-events/news/press-releases/2017/02/vizio-pay-22-million-ftc-state-new-jersey-settle-charges-it-collected-viewing-histories-11-million?ref=freshfromcache.com) - [Texas Attorney General, suit against five TV makers, December 15, 2025](https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-five-major-tv-companies-including-some-ties-ccp-spying-texans?ref=freshfromcache.com) - [Texas Attorney General, temporary restraining order against Hisense, December 17, 2025](https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-court-order-stopping-ccp-aligned-smart-tv-company-spying-texans?ref=freshfromcache.com) - [Texas Attorney General, agreement with Samsung, February 26, 2026](https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-secures-major-agreement-samsung-ensure-texans-are-protected-smart-tvs?ref=freshfromcache.com) - [Texas Attorney General, agreement with LG, May 11, 2026](https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-secures-major-agreement-lg-protect-texans-privacy-and-stop-data-being?ref=freshfromcache.com) - [Sony support article 00182856, "Information about Samba TV," last modified February 10, 2026](https://www.sony.ca/en/electronics/support/articles/00182856?ref=freshfromcache.com) - [Roku, "Automatic Content Recognition, Smart TV Experience, and TV Ads Measurement Service Policy" (regional edition; the US edition returns a JavaScript shim to a plain fetch)](https://docs.roku.com/published/acrservicepolicy/en/CA?ref=freshfromcache.com) - [Roku support, "Using 'More Ways to Watch' on your Roku TV"](https://support.roku.com/en-us/article/using-more-ways-to-watch-on-your-roku-tv?ref=freshfromcache.com) - [Amazon, "Privacy Settings FAQs for Fire TV Products, Fire Tablets and Kindle E-readers"](https://www.amazon.com/gp/help/customer/display.html?nodeId=GQFYXZHZB2H629WN&ref=freshfromcache.com) - [Amazon, "Manage Sharing of Viewing Information from Apps on Fire TV"](https://www.amazon.com/gp/help/customer/display.html?nodeId=TpJxOEPHMPJbmKq5Bh&ref=freshfromcache.com) - [Hisense USA, "Enhanced Viewing Service Privacy Notice," effective March 1, 2025](https://www.hisense-usa.com/compliance/enhanced-viewing-service-privacy-notice-%28effective-date:-march-01,-2025%29?ref=freshfromcache.com) - LG USA support, "How to Accept the Updated User Agreements on Your LG TV," page-dated September 2, 2026 (LG support article; no stable public URL could be resolved for it) - [Consumer Reports, "How to Turn Off Smart TV Snooping Features," updated October 19, 2025](https://www.consumerreports.org/electronics/privacy/how-to-turn-off-smart-tv-snooping-features-a4840102036/?ref=freshfromcache.com) ### Also this week: a false antivirus warning, an FTC lawsuit over Amazon's ad prices, and 19 browser add-ons gone bad URL: https://www.freshfromcache.com/also-this-week-2026-09-04/ Last updated: 2026-09-04T10:59:59.000Z I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week. ## A Windows pop-up says your antivirus is off, and Microsoft says the pop-up is wrong After a recent update to Microsoft Defender, Windows can put up a notice reading "Microsoft Defender Antivirus is turned off," with a prompt to tap or click to turn it back on. On August 28 Microsoft confirmed the notice is a bug. Its release-health page says the antivirus "is functioning correctly and all settings show it as active," that the notice can appear when Windows starts and again at random after that. It also keeps coming even if you switch notifications off. Every supported version of Windows is on the affected list, Windows 10 included. The fix arrives in a future Defender update. No date yet. Here's how to check for yourself. Open the Start menu, type Windows Security, and open it. Click Virus & threat protection. If that page says no action is needed and Real-time protection is on, the pop-up is the bug and you can close it. Defender is the antivirus [we said was enough on August 13](https://www.freshfromcache.com/do-you-need-antivirus/), and this changes nothing about that. The real notice comes from Windows Security itself, looks like every other Windows notification, and never gives you a phone number or asks you to install anything. A web page that says your antivirus is off and wants you to call someone is a scam. Sources: [Microsoft](https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-25h2?ref=freshfromcache.com) and [BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/?ref=freshfromcache.com) ## The FTC says Amazon hid a surcharge behind its Sponsored search results When you search on Amazon, some of the products mixed into the results are labeled Sponsored. Brands bid for those spots in an auction, and for years Amazon told them it ran a "second price" auction, where the winner pays one cent more than the next highest bid. On August 31 the FTC and 22 state attorneys general, Washington and Idaho among them, sued Amazon in federal court in Seattle. The complaint says that starting in 2019 Amazon added an undisclosed charge it called a "soft reserve price" internally, that by 2024 advertisers were paying their full bid about 80 percent of the time, and that the surcharge was turned up ahead of Prime Day and Black Friday. Amazon's own documents, as quoted in the complaint, describe "a surcharge hidden in it" and an "invented auction participant." The FTC puts the take at tens of billions of dollars from more than a million brands and sellers, over 500,000 of them small and mid-size businesses. Amazon calls the suit "misguided" and says "in no scenario does an advertiser pay more than their bid." It also says the complaint cites no evidence of higher prices for shoppers, and that its average cost per click was flat, adjusted for inflation, from 2019 to 2024\. The FTC's chairman said the higher costs "were largely passed on to American consumers." Nobody has put out a number on that, and a complaint filed August 31 is a long way from a verdict. Amazon's own advertiser page says Sponsored products can appear at the top of, alongside, or within shopping results, so scrolling past the first few doesn't get you to a clean list. Look for the Sponsored label on each result before you compare prices. This is the second Amazon money story in a row; [last week it was the crossed-out prices on Amazon's own devices](https://www.freshfromcache.com/also-this-week-2026-08-28/). Sources: [Federal Trade Commission](https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-states-sue-amazon-over-secret-ad-surcharge-scheme?ref=freshfromcache.com), [Amazon](https://www.aboutamazon.com/company-news/amazon-ftc-sponsored-ads-lawsuit-response?ref=freshfromcache.com) and [Amazon Ads](https://advertising.amazon.com/en-us/solutions/products/sponsored-products?ref=freshfromcache.com) ## Nineteen browser add-ons turned on the people who installed them A security firm called Socket published the details on August 27\. Nineteen extensions for Chrome and Edge, most of them small utilities like SEO checkers, crypto price tickers and a tool for re-enabling right-click on pages that block it, were carrying the same malware kit. Once installed, it stripped the security rules from every page you visited, slipped its own code in, and pulled down modules to do the actual work. The ones Socket watched drained cryptocurrency wallets, recorded whatever you typed into password fields on any site, and put up a fake "Chrome update available" page that tells you to paste a command into your computer. Fourteen of the nineteen were built to be malicious, published clean, then updated with the malware once they had users. The other five were real extensions, written by real developers, that the criminals bought. The biggest, a right-click enabler sold under the name Enable Right Click & Copy, had about 70,000 Chrome users when the bad update went out. Chrome updates extensions on its own, and nobody is told when an extension changes hands. Socket says one with 10,000 users can be bought for under $2,000\. Google removed the Chrome listings. The Edge listing was still live when the report came out, with a fresh update from August 14, and was gone by September 3. In Chrome, type chrome://extensions in the address bar. In Edge, edge://extensions. Remove anything you don't recognize or haven't used in months. If one of the extensions on Socket's list was installed, treat every password you typed in that browser as exposed and change them, starting with email and banking; [a password manager makes that an afternoon instead of a month](https://www.freshfromcache.com/start-using-a-password-manager/). [Our Chrome and Edge settings walkthrough](https://www.freshfromcache.com/chrome-edge-privacy-settings/) covers the rest of that page. Sources: [Socket](https://socket.dev/blog/chrome-edge-extension-wallet-drainer?ref=freshfromcache.com) and [BleepingComputer](https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/?ref=freshfromcache.com) ## Android 17 hides site names from the network and lets your carrier close a 2G scam door On August 27 Google described four network protections in Android 17, which is on Pixel phones now and reaching other brands through the rest of the year. The first is a scam fix. Crooks have been using portable fake cell towers called SMS blasters, priced from about $3,000, to force nearby phones off 5G and LTE onto old 2G, where the carrier's spam filters cannot see the text that follows. Android 12 added a manual switch to turn 2G off. Android 17 lets your carrier turn it off for you, by default, with no setting to find. Google hasn't said which carriers are participating. The second is called Encrypted Client Hello. Even on a locked-padlock HTTPS connection, the site's name can still be readable to whoever runs the network, whether that's your internet provider or the coffee shop's Wi-Fi. Android 17 hides that name from the start of the connection, and Google calls it the first major phone system to do so broadly. The catch, in Google's own words, is that it works "for supported websites and apps," so the protection grows as sites adopt it, and it does nothing about [the sites you log into selling what they know](https://www.freshfromcache.com/what-is-a-data-broker/). Two smaller ones round it out. Apps now have to ask before they scan your home Wi-Fi for your TV and cameras, and website certificates have to appear in a public log, which makes a forged one easier to catch. The only thing to do is take the Android 17 update when your phone offers it. Sources: [Google](https://blog.google/security/new-android-network-security-protections/?ref=freshfromcache.com) and [9to5Google](https://9to5google.com/2026/08/27/android-17-network-security/?ref=freshfromcache.com) That's the week. If you are new here, [Start Here](https://www.freshfromcache.com/start-here/) collects the pieces worth reading first, and [the Tuesday email](https://www.freshfromcache.com/newsletter/) carries the whole week in one place. ### Cox Media Group told advertisers it was listening to you. The FTC says it never was. URL: https://www.freshfromcache.com/is-my-phone-listening-to-me/ Last updated: 2026-09-03T11:00:00.000Z > "My phone must be listening to me." We've all said it. You talk about some obscure product. A few hours later you're seeing an ad for the exact thing you talked about. You didn't Google it. You didn't look it up. You only said it out loud. So the phone must be listening. But is it? For years the answer has been a shrug and a stack of studies. Then a company came along and sold the thing everybody was afraid of. ## "Where do you want us to listen?" Cox Media Group, a Georgia media company, started selling small businesses a product called Active Listening in 2023, and the pitch was not subtle. Its own website told customers that a smartphone "is technically always listening." Voice data goes further than search data, the page argued, so "every casual conversation between two consumers becomes a tool for you to target, retarget, and retain customers." One line read, "Creepy? Sure. Great for marketing? Definitely." In sales presentations the company said Active Listening used AI "to detect pertinent conversations via smartphones, smart tvs, smart speakers and other devices." It offered territories in ten and twenty mile radiuses. Prospective customers were asked, in writing, "Where do you want us to listen?" When a small business owner pushed back and asked whether any of this was legal, the FTC says the company doubled down. Employees were coached to name Alexa, Google, OpenTable and Samsung as sources, and to point out that almost every app and device people buy asks for microphone access. What the company was actually selling was email addresses. It was buying lists of them from data brokers, the same lists any advertiser can buy, and reselling them at a markup. Smart devices weren't sending voice data to Cox Media Group. There was no algorithm sorting anybody's conversations. The geography was fake too. A business paying to reach people within ten miles of Orlando got a list of people scattered across the country, with only a fraction of them anywhere nearby. The Federal Trade Commission announced the proposed settlements in May and finalized the orders on August 27\. Cox Media Group is paying $880,000\. MindSift in New Hampshire and 1010 Digital Works in Wisconsin, the two smaller firms that supplied the sales materials, are paying $25,000 each. Underneath the frightening name, this was the ordinary data-broker business. We've written that one up separately, in [what a data broker is and what they have on you](https://www.freshfromcache.com/what-is-a-data-broker/). ## The strange part is who counts as the victim The FTC's order sends that money to Cox Media Group's customers, meaning the small businesses that bought the service. That follows from what the agency found. If no microphone ever turned on, the businesses are the only ones out any money, and what they lost was an ad budget. Sit with that for a second. The businesses in line for redress are the ones who read "Where do you want us to listen?" and reached for a credit card. They paid for a product sold on that promise. They were lied to as well, and that matters. They were told the eavesdropping was legal because customers had agreed to it in an app's terms. Nobody knows how many of them believed that and how many just liked the sound of the product. But the people supposedly overheard at their own kitchen tables were never customers and were never recorded, so in the eyes of this case they were never the ones wronged. They were the product being described. ## Clicking accept is not consent The companies also told advertisers that consumers had opted in to all of this. Their evidence was the terms of service you accept when you set up a phone or install an app. Cox Media Group put it this way to customers: "You may not realize it, but when you download apps, set up new devices you 'accept' the terms, and those terms include allowing them to access your microphone." Clicking through mandatory terms of service, the agency said, doesn't amount to opt-in consent for a service that invasive or for voice data from inside somebody's home. Then it went a step further. If Active Listening had worked the way it was advertised, that collection and use of voice data without adequate consent would itself have broken the law. So the fine is for lying about the product. The regulator still went out of its way to say that building it for real would have broken the law. ## Why you saw the ad One company's sales pitch doesn't settle the bigger question. Nobody at the FTC opened up your iPhone, or Meta's ad system, or the thousands of apps sitting on your phone. So here is what the wider evidence does and doesn't cover. Researchers have gone looking. The best known attempt gathered more than 17,000 Android apps from four app stores and put them through a mix of code inspection and live testing on real devices. In the live tests, nothing sent audio out. They were upfront about what that could miss. It was a slice of the app store, run for short sessions, on Android only, and audio turned into text before it left the phone wouldn't have shown up. That doesn't prove it can't happen. It means people went looking in thousands of apps and didn't find it. Meanwhile the ordinary machinery keeps working, and any one ad usually has dozens of possible explanations behind it. Your phone carries an advertising ID, a long string that identifies the device across apps. Purchases, app activity, loyalty programs and location patterns get attached to a profile. Data brokers buy and sell the results. Advertisers then bid to reach people who match a description, and you match a lot of descriptions. Two people in the same house already share plenty of signals. Same home address, same Wi-Fi, overlapping location history, probably some of the same stores and services. One person starts shopping for a leaf blower. The other person fits the audience too. ![Two men in a kitchen. One sits at the counter looking at the phone in his hands while the other stands behind him talking on a phone](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/09/inline-two-people-one-audience-v2.jpg) Two people in the same house look like one audience. Photo: Getty Images via Unsplash And we notice the hits. We don't remember all the ads that had nothing to do with anything we said that afternoon. If this system sounds familiar, it's the same one behind [why two people can see different prices for the same item](https://www.freshfromcache.com/why-your-price-is-different/). ## What your microphone does hear There's one real exception, and it isn't a secret. Voice assistants record. That's their job. They listen on the device for a wake word, then start recording when they think they hear one. Sometimes they're wrong, which is how clips of people who never said "Hey Google" ended up in company hands. That's what Google's $68 million settlement was about, and Apple's $95 million Siri settlement before it. Neither settlement found that those recordings were used for advertising, and both companies say they weren't. ![A small round fabric-covered smart speaker on a blanket, its four status lights lit, beside a phone showing a device setup screen that reads Welcome Home](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/09/inline-the-speaker-really-does-listen.jpg) A speaker waiting for its wake word. This is the one device in the story that really does record, and it says so on the box. Photo: Bence Boros via Unsplash ## See who used your microphone Both phone platforms will now tell you which apps used the microphone and when. - **On an iPhone,** open Settings, tap Privacy & Security, scroll down to App Privacy Report and turn it on. It only starts collecting from the moment you switch it on, so give it a few days, then come back and look at Data & Sensor Access. - **On Android,** open Settings, tap Security and Privacy or Privacy, then Privacy dashboard, then Microphone. It shows the last seven days on Android 13 and up, the last 24 hours on Android 12\. Some phone makers rename these, so if Privacy dashboard isn't there, look one menu deeper under Privacy. - **Watch the dot.** On an iPhone, an orange dot at the top of the screen means an app is using the microphone, and a green one means the camera, or the camera and microphone together. On Android it's a green indicator in the top right corner, and tapping it tells you which app. While you're in there, take the microphone away from anything with no business having it. A flashlight app doesn't need one. Then change one setting that has nothing to do with the microphone. On an iPhone it's Settings, Privacy & Security, Tracking, and turning off "Allow Apps to Request to Track." On Android it's deleting the advertising ID under Settings, Privacy, Ads. Neither is a cure, and neither empties a profile that already exists. Both do more about the ad than anything you can do to the microphone. One company sold that exact eavesdropping service to small businesses for two years, and when the government opened it up, there was nothing inside but purchased email addresses. The ad still found you. It found you through a profile you helped build, using permissions you agreed to, sold on by companies you've never heard of, and none of it needed a microphone. Go turn on App Privacy Report tonight. In a week you'll know what your phone has really been up to. **Sources:** - [Federal Trade Commission, "FTC Finalizes Orders with Cox Media Group, Two Other Firms Settling Charges They Deceived Customers About 'Active Listening' AI-Powered Marketing Service," August 27, 2026](https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-finalizes-orders-cox-media-group-two-other-firms-settling-charges-they-deceived-customers-about?ref=freshfromcache.com) - [Federal Trade Commission, "FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million to Settle Charges They Deceived Customers," May 21, 2026](https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-require-cox-media-group-two-other-firms-pay-nearly-1-million-settle-charges-they-deceived?ref=freshfromcache.com) - [Federal Trade Commission, Complaint, In the Matter of CMG Media Corporation, Docket 242-3029](https://www.ftc.gov/system/files/ftc%5Fgov/pdf/CMGComplaintwithoutsignatures.pdf?ref=freshfromcache.com) - [Federal Trade Commission, Decision and Order, CMG Media Corporation](https://www.ftc.gov/system/files/ftc%5Fgov/pdf/2423029c4838cmgfinalorder.pdf?ref=freshfromcache.com) - [Pan, Ren, Lindorfer, Wilson and Choffnes, "Panoptispy: Characterizing Audio and Video Exfiltration from Android Applications," Proceedings on Privacy Enhancing Technologies, 2018](https://petsymposium.org/popets/2018/popets-2018-0030.pdf?ref=freshfromcache.com) - [Electronic Frontier Foundation, "Is My Phone Listening To Me?"](https://www.eff.org/deeplinks/2024/10/my-phone-listening-me?ref=freshfromcache.com) - [Apple, "About App Privacy Report"](https://support.apple.com/en-us/102188?ref=freshfromcache.com) - [Apple, "About the orange and green indicators in your iPhone status bar"](https://support.apple.com/en-us/108331?ref=freshfromcache.com) - [Google, "Manage permissions from the privacy dashboard"](https://support.google.com/android/answer/13530434?ref=freshfromcache.com) - [Google, "Check if your Android camera or microphone is on or off"](https://support.google.com/android/answer/13532937?ref=freshfromcache.com) ### Who is ShinyHunters, and why is that name in every breach letter? URL: https://www.freshfromcache.com/who-is-shinyhunters/ Last updated: 2026-09-02T10:59:59.000Z ShinyHunters says it took about 284 million patient-related records from McKesson, a major American pharmaceutical distributor. McKesson has confirmed a cybersecurity incident. Its filing with the SEC says the company found it on August 25, that the investigation is in its early stages, and that it has not determined the incident is material. A notice to customers says intruders reached third-party applications and took data. Over the weekend the company added that the stolen data belonged to a subset of customers in two of its business units, the ones covering cancer care and medical supplies, that it has cut off the access, and that it will give the people affected free credit monitoring. It still has not said what data was taken, how many people are involved, or who did it. The 284 million is the group's own figure, and early coverage read it as 284 million patients. It is not that. ShinyHunters told BleepingComputer the number is a raw count of records, or lines, and that it has not finished going through the data and does not know how many people are in there. Carhartt shows what usually happens to a number like that. On August 13 the same group put Carhartt on its leak site and said it was holding more than 50 gigabytes of the company's data. Carhartt did not pay, and the data was published. Then somebody opened it. Troy Hunt runs Have I Been Pwned, the free service that tells you when your email address turns up in a breach. He downloaded the dump and ran his usual extractor over it, which pulled 24,876,077 unique email addresses. That figure is a machine count of every address in the files, and it is roughly what went into the first round of coverage. Hunt kept hunting. A large share of those addresses sat in folders named for TPC-DS, a standard test dataset companies use to benchmark their analytics systems. Fake customers, generated for load testing. The individual records looked plausible, but the pile did not. Nearly every email domain appeared exactly one time. Birth years ran flat from 1924 to 1992, about 1,100 people a year with no bump anywhere. There were more customers born in Montenegro than in the United States. He pulled the benchmark records, then duplicate Microsoft 365 addresses, then deactivated accounts and internal test domains. What he loaded into Have I Been Pwned was 12,933,413 addresses. Just under half the original count. ![Two figures side by side: 24,876,077 addresses found on the first pass, and 12,933,413 that belonged to real people](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/09/feature-the-recount.jpg) The recount, after the benchmark records and duplicates came out. ## Carhartt still looks breached The data left after the cleanup still carries Carhartt's fingerprints. Hunt found 15,057 employee addresses ending in carhartt.com, internal system aliases nobody outside the company would know existed, and roughly 1,150 people who had tagged their own email address with "+carhartt" when they signed up. His conclusion was that Carhartt was almost certainly breached, and that the test records were most likely sitting beside the real ones when the attackers took everything. Carhartt has not put out a public statement about any of it. Hunt also says he has reviewed close to a hundred leaks on this group's site and has yet to find one where the data was invented. He allows that the criminals may not be the ones who got this number wrong either. A real theft picked up a pile of benchmark records that were sitting in the same place. An automated tool counted them faithfully. Nobody further down the line opened the files. As Hunt puts it, "the truth is in the data." ## Fourteen million records, 5.1 million people Panera Bread ran into the same problem in January. ShinyHunters claimed more than 14 million records. Have I Been Pwned processed the leaked files and found about 5.1 million unique email addresses. Both numbers are accurate. One person occupies several database rows. Old accounts stay in the table. Internal aliases count separately. The smaller figure is still a lot of people. Of the Carhartt addresses Hunt loaded, 83 percent had already turned up in earlier breaches. ## Arrests have not stopped it The name ShinyHunters has been in the news since 2020 and people attached to it have been arrested more than once. Sebastien Raoult, a French member of the original crew, was extradited to the United States and sentenced in January 2024 to three years and more than $5 million in restitution. French police arrested four more people in June 2025 over the running of BreachForums, one of them using the ShinyHunters handle. The name was back in operation within weeks of both. The FBI still calls ShinyHunters a cyber criminal group in its own advisories. Google's threat intelligence team is more cautious. It now tracks recent ShinyHunters-branded activity under three separate labels, partly to follow shifting partnerships and partly, in its own words, to "account for potential impersonation activity." In May, Google documented one of those cases. It found that a separate crew it tracks as UNC6671 had used the ShinyHunters name at least once to make its own threats more credible. Google assesses that the two operations are independent, on the basis of different negotiation channels, different domain registration habits, and UNC6671's own leak site. ## It often starts with a phone call For the cloud-account campaigns that put this name in so many breach stories this year, the entry point has been ordinary. Someone at the company gets a call from a person claiming to be IT support. The caller sends them to a login page built to look like the company's own, at an address like companyname-sso.com, and talks them through signing in. The page captures the password and the multi-factor code. Google says none of that comes from a security hole in the vendors' products. You have met this call. It is the fake fraud department or the fake tech-support call, directed at somebody's work account instead of their bank account. We [wrote about the phone call itself back in June](https://www.freshfromcache.com/three-breaches-in-one-week/). Not every attack under this name works that way. In June, Google's Mandiant team tied a separate campaign to a previously unknown flaw in Oracle PeopleSoft, the software many universities run their student, payroll and finance records on. Oracle put out an emergency patch after the attacks had already started. No phone call in that one, and universities took the worst of it. Your information ends up in a dump because a company you dealt with kept it. The person who answered the phone may never have touched your account. ## The email that follows is its own scam The FBI put out an advisory about this group in May. Two things in it should stay with you. The first is the wording. It says these actors use "real or exaggerated claims" about the sensitive information they hold to pressure people into paying. A sender can have real stolen data and still exaggerate what it proves. ![A laptop screen showing a Gmail inbox with 152 unread messages](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/09/inline-the-email-after.jpg) Photo: Justin Morgan via Unsplash The second is what else has been happening. The FBI has seen threatening texts and calls aimed at victims and their families, fake emergency calls sent to their homes, and claims about compromising photos or videos that in many cases never existed. There is a whole side industry of scammers sending extortion emails under this brand, quoting a real leaked email address as their proof. ## What you can do Once your information is in a breach, what matters is what somebody can do with it next. - **Turn on breach notifications at Have I Been Pwned.** It is free, and it tells you when your address turns up in a dataset somebody has actually processed, rather than one somebody has advertised. - [**Freeze your credit**](https://www.freshfromcache.com/freeze-your-credit/) if a breach you were caught in exposed your Social Security number or similar identity details. It blocks new accounts in your name and does nothing else, which is exactly what it is for. - **Expect the follow-up.** A leaked phone number, address or old password is what makes the next approach convincing. Our guides on [spotting a phishing email](https://www.freshfromcache.com/how-to-spot-a-phishing-email/) and [what to do after a scam](https://www.freshfromcache.com/what-to-do-after-a-scam/) both apply. - **Use a different password everywhere and turn on multi-factor.** [A password manager](https://www.freshfromcache.com/start-using-a-password-manager/) handles the first part. For the second, [read the prompt before you approve it](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/), because approving one push notification is how a security company got broken into this month. - **Do not treat an email address or an old password as proof that somebody has photos, video or access to your computer.** If an extortion message knows your address, your phone number or an old password, those details may already be circulating from an earlier breach. ## If you are in one of these Look past the group name and the first big number, and find out which fields were exposed next to your account. A leaked email address is a different problem than a leaked password, and both are a different problem than a leaked Social Security number. What was exposed next to your name decides what you do today. **Sources:** - [BleepingComputer, "McKesson discloses breach after ShinyHunters claims patient data theft," August 28, 2026](https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/?ref=freshfromcache.com) - [McKesson, Form 8-K filed with the SEC, August 2026](https://www.sec.gov/Archives/edgar/data/927653/000092765326000247/mck-20260825.htm?ref=freshfromcache.com) - [McKesson, Customer Cybersecurity Information Center](https://www.mckesson.com/utility/cybersecurity/customer-cybersecurity-information-center/?ref=freshfromcache.com) - [Troy Hunt, "A Cautionary Tale About Data Breach Claims, Verification and Carhartt," August 26, 2026](https://www.troyhunt.com/a-cautionary-tale-about-data-breach-claims-verification-and-carhartt/?ref=freshfromcache.com) - [Have I Been Pwned, Carhartt breach entry](https://haveibeenpwned.com/Breach/Carhartt?ref=freshfromcache.com) - [BleepingComputer, "Panera Bread data breach impacts 5.1 million accounts, not 14 million customers," February 2026](https://www.bleepingcomputer.com/news/security/panera-bread-data-breach-impacts-51-million-accounts-not-14-million-customers/?ref=freshfromcache.com) - [Google Threat Intelligence Group, "Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft," January 30, 2026](https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft?ref=freshfromcache.com) - [Google Threat Intelligence Group, "Welcome to BlackFile: Inside a Vishing Extortion Operation," May 16, 2026](https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/?ref=freshfromcache.com) - [Google Threat Intelligence Group, "The Cost of a Call: From Voice Phishing to Data Extortion," June 4, 2025](https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion?ref=freshfromcache.com) - [The Hacker News, "ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities," June 11, 2026](https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html?ref=freshfromcache.com) - [Help Net Security, "Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert," June 11, 2026](https://www.helpnetsecurity.com/2026/06/11/oracle-peoplesoft-under-attack-cve-2026-35273/?ref=freshfromcache.com) - [FBI Internet Crime Complaint Center, PSA I-051526-PSA, May 15, 2026](https://www.ic3.gov/PSA/2026/PSA260515?ref=freshfromcache.com) - US Department of Justice, Western District of Washington, "Member of Notorious International Hacking Crew Sentenced to Prison," January 2024. - The Record, "French police arrest four suspects tied to BreachForums," June 25, 2025. ### This week: a price built just for you URL: https://www.freshfromcache.com/newsletter/a-price-built-for-you/ Last updated: 2026-09-01T14:59:59.000Z Good morning! The personalized-pricing story is the one I want you to read this week. Stores can use information about you to decide the price you see. The FTC is now considering what they have to tell you when they do it. Most of the usual advice about clearing cookies barely touches the ways a store can recognize you. **In this issue:** - [Are you paying a different price than your neighbor?](https://www.freshfromcache.com/why-your-price-is-different/) - [What laptop specs actually matter in 2026?](https://www.freshfromcache.com/how-to-read-a-laptop-price-tag/) - [Why is my Wi-Fi slow?](https://www.freshfromcache.com/why-is-my-wifi-slow/) - [The GTA VI leak. How big leaks become bait.](https://www.freshfromcache.com/gta-6-leak-malware/) - [Also this week: pricier Amazon devices, a $17 billion Meta settlement, and a check from Disney](https://www.freshfromcache.com/also-this-week-2026-08-28/) - [Google will tell you when your address shows up in its search results](https://www.freshfromcache.com/remove-personal-info-google-search/) - Plus: three scams making the rounds - And the Scary Headline of the week: the Android app that scans for nudity --- [**Are you paying a different price than your neighbor?**](https://www.freshfromcache.com/why-your-price-is-different/) Personalized pricing, sometimes called surveillance pricing, is when a business uses information about you to decide what you pay. Two shoppers can look at the same thing and be shown different prices because the store knows or guesses something different about each of them, often through the account or loyalty number they hand over themselves. The FTC says the practice is not automatically illegal, but hiding a personalized price can be deceptive or unfair. The article tests the usual advice, says what works instead, and walks you to the FTC docket before the comment window closes September 18. *Learn* --- [**What laptop specs actually matter in 2026?**](https://www.freshfromcache.com/how-to-read-a-laptop-price-tag/) If you are shopping for a Windows laptop for everyday use, start with 16GB of memory and a 512GB SSD. Look for a 1080p or better IPS screen. Take the full processor model off the tag and search it before you buy, because Core 5 or Ryzen 5 tells you the tier but not how old the chip is. Wi-Fi 7, TOPS numbers and an "AI PC" label matter much less than the memory, storage, processor and screen. *Learn* --- [**Why is my Wi-Fi slow?**](https://www.freshfromcache.com/why-is-my-wifi-slow/) Run a speed test next to the router, then run it again where things are slow. If it is already slow next to the router, the problem is probably not coverage. If it drops only in the bad room, move the router out of the cabinet or off the floor before you price a mesh kit. The article walks through six checks, including bufferbloat when a big upload ruins the internet for everyone else. *Learn* --- [**The GTA VI leak. How big leaks become bait.**](https://www.freshfromcache.com/gta-6-leak-malware/) The leaked GTA VI clips were real, which made the fake downloads easier to sell. Malwarebytes found sites pretending to host footage or demos that delivered the Vidar password stealer, while another supposed 113GB leak archive was mostly empty data wrapped around a small program that disabled Windows Defender. If somebody in your house wants to see the leak, let them watch the clips on a normal video site. The full Extended Look aired August 27 on Netflix and YouTube, so the real thing is a click away. They do not need a ZIP file, ISO, installer or special player to watch a video. *News* --- [**Also this week: pricier Amazon devices, a $17 billion Meta settlement, and a check from Disney**](https://www.freshfromcache.com/also-this-week-2026-08-28/) Amazon raised the list prices on several of its own devices, but as of Thursday most of the actual sale prices were still below those new numbers. Meta agreed to pay up to $17 billion over ten years to settle the multistate teen social-media case, with new limits planned for users under 18 in participating states. Disney's $50 million YouTube TV and DirecTV Stream settlement has a September 8 claim deadline. The CPSC also says owners of a KH158 plug-in gas and carbon-monoxide alarm sold under 18 brand names should stop using it because it can fail to sound during a real leak. *News* --- **If you only read one:** [the personalized-pricing piece](https://www.freshfromcache.com/why-your-price-is-different/). It explains what surveillance pricing is, how a store can recognize you without relying on cookies, and what works instead of the usual advice. --- ### 5-Minute Tech Tip [Google's Results about you tool](https://www.freshfromcache.com/remove-personal-info-google-search/) can watch Search for your home address, phone number, email address, driver's license number or Social Security number. Start by searching your own name and town in a private window so you can see what someone else sees. Then set up Results about you with the names and contact information you want Google to watch. When Google finds a match, you can request removal from Search. The original page can still keep the information, so a people-finder listing may need a second removal request at the source. --- ### Fresh Trouble **The Amazon job text.** A text from an "Amazon Remote Recruitment Team" offers $100 to $600 a day for about an hour of work and tells you to text another number. Look up any real opening on Amazon's own jobs site instead. ([Malwarebytes](https://www.malwarebytes.com/blog/scams/2026/06/watch-out-for-high-paying-low-effort-amazon-job-texts?ref=freshfromcache.com)) **The veterans postcard.** A postcard says you or your spouse may qualify for a "Veterans Savings Program," but the FTC says the program does not exist. Benefit questions go to the VA at 1-800-827-1000, not the number on the card. ([FTC](https://consumer.ftc.gov/consumer-alerts/2026/08/how-spot-postcard-scam-targeting-veterans?ref=freshfromcache.com)) **Disaster donation asks.** After a hurricane, flood or earthquake, fake charities show up quickly. Find the charity yourself before you donate, and walk away from anyone demanding a gift card, wire transfer or cryptocurrency. ([FTC](https://consumer.ftc.gov/consumer-alerts/2026/08/when-donating-support-those-need-not-scammer?ref=freshfromcache.com)) --- ### Scary Headline of the Week *"Dystopian Android's nude-scanning app keeps reinstalling itself, and Google is opening access to other developers"* SafetyCore is real. Google pushed it to Android phones through Google Play without a normal app install, and it has no icon sitting in your app drawer. Cybernews also reports that some people who removed it later found it installed again. The function is narrower than the headline makes it sound. SafetyCore provides an on-device classifier that Google Messages can use when Sensitive Content Warnings is turned on. Google says the classification stays on the phone. Its Play listing says SafetyCore itself collects no data and shares no data with third parties. GrapheneOS has looked at the component too. Its developers say SafetyCore has no way to report your images or its classification result to a service. An app sends content to the local model, gets a classification back, then decides what to do with it. Google is now building an Android API that lets other apps use the same kind of on-device content classification. That means the same kind of warning can start showing up in other apps. Those apps still need their normal permission to get at the photo or message in the first place. I still think Google created its own trust problem. A background component that examines sensitive content showed up on people's phones with almost no explanation. When Google [wanted a video of your face](https://www.freshfromcache.com/google-wants-a-video-of-your-face/) as an account-recovery backup, setup was optional. You had to turn it on yourself. **Verdict:** "nude-scanning app" makes this sound like Google is secretly uploading your photo library. The evidence does not support that. The silent install is fair criticism, and opening the classifier to more apps deserves scrutiny. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help: forward this email to one person who might want it, and if it was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. And if you would rather chip in a few dollars, there is a [support page](https://www.freshfromcache.com/support/) now. Thank you for your support! --- Have you ever caught a price changing on you, and did you figure out why? Hit reply. Joel ### Ring is throwing away its key to your videos URL: https://www.freshfromcache.com/ring-take-encryption/ Last updated: 2026-09-01T10:59:59.000Z Ring is changing who can open old recordings from its doorbells and cameras. A new encryption mode starts rolling out in September. Ring says it will become the default worldwide once the rollout finishes. The name tells you what it does. TAKE stands for Throw Away the Key Encryption. Every recording gets an encryption key, the digital equivalent of a key to a locked box. A new one takes over every five minutes. Ring keeps a copy inside a hardened section of its cloud so features like Smart Alerts and Video Search can do their work. Then Ring throws that copy away. The deletion runs continuously rather than on a daily deadline. Each key gets destroyed once it passes 24 hours old, through a one-way process Ring says cannot be reversed, in a database configured with no backups. Your phones, tablets, and browsers keep their own keys the whole time. Play a week-old clip and your app hands Ring a temporary key so it can prepare the video. Ring's cloud cannot ask for one on its own. ## What changes for you In practice, after about a day nobody at Ring can open your old video unless your app hands over the key. Not a support agent, not an engineer, not a contractor. That last one matters. In 2023 the Federal Trade Commission alleged Ring had given employees and contractors broad access to customer video without adequate controls. Ring settled, paid $5.8 million, and agreed to a privacy and security program. TAKE leaves a window open at the front end. Ring's services can still decrypt video during the first 24 hours to run the features on your account. The change is what happens afterward. Once Ring's copy of the key is destroyed, that access stops being a matter of policy and becomes impossible. I have been skeptical of Ring for years and I still am. But a company that destroys its own keys has given something up. Policies get rewritten in an afternoon. A destroyed key is gone. ## Ring can still send police a locked file Ring's U.S. guidelines say non-content information, meaning things like your name, address, and email, can be produced under a subpoena. Video counts as content, and Ring says content requires a valid search warrant. Ring updated those guidelines four days ago. They now say Ring only has access to videos that are not protected by TAKE or end-to-end encryption. The word doing the work there is access. Ring told Gizmodo something the guidelines never spell out. It may still turn over the encrypted video file when valid legal process requires it. So the file can still leave Ring. Ring says it cannot open one. Ring also says it notifies the account owner before handing anything over, unless it is barred from doing so. ## The person on the sidewalk The keys belong to the camera owner. Everyone else in frame is along for the ride. Ring's own white paper draws that line in a footnote. The architecture covers video stored on Ring's infrastructure. Anything the owner chooses to share falls outside it, and Ring names the examples itself: share links, the video donation tool, and Neighbors. Once a clip gets passed along, the design stops applying to it. There is no consent prompt for the delivery driver or the neighbor walking a dog. It is the same gap that runs through [Flock cameras](https://www.freshfromcache.com/what-is-a-flock-camera/). Rules about storage and search can limit misuse after the fact. There is still no way to opt out beforehand. That fight is already in court. A Virginia man who has never owned a Ring sued Amazon in June over Familiar Faces, Ring's opt-in facial recognition feature, saying his face was scanned while he was visiting friends who do. The allegations are unproven. Ring built a way for you to lock up your own footage. Whether anybody else in the frame wanted to be there is a question the settings page never asks. ![A two-column comparison. Under TAKE, your phones and tablets hold a key permanently and Ring's cloud holds a copy for 24 hours before destroying it. Under end-to-end encryption, Ring's cloud never gets a key, and Video Search, Smart Video Descriptions, Smart Alerts and Shared Users turn off.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/09/diagram-who-holds-a-key.png) Two ways to lock your video, and what each one costs. ## What to check when TAKE reaches you - **Wait for the invitation.** Ring says it will notify you when your account is eligible to enroll. Your current setting stays exactly where it is until then. - **Decide camera by camera.** End-to-end encryption is set per camera now, so you can run TAKE on the doorbell and end-to-end on the back yard. Switching modes only covers new recordings, and old clips stay under whatever was running when the camera recorded them. - **Know what end-to-end costs.** It removes Ring's cloud from the group, which takes Video Search, Smart Video Descriptions, cloud Smart Alerts, and Shared Users with it. Live View and playback keep working. Some older cameras encrypt only once the video reaches Ring's cloud, and those support TAKE but cannot do end-to-end at all. - **Write down the passphrase.** Enrollment generates a twelve-word recovery phrase and Ring does not keep a copy. Lose every recovery method and your old video is gone permanently. - **Look at camera-based recovery.** Under TAKE, Ring stores a recovery key on the camera itself and turns this on by default. Using it requires standing next to the camera. You can switch it off and keep the other recovery methods. Find it under Control Center, then Video Encryption, then Enrolled Cameras. ## What Ring has not shown yet TAKE is built on Messaging Layer Security, an open standard published by the Internet Engineering Task Force as RFC 9420\. Anybody can read that spec and go looking for holes in it. That is a real advantage over a scheme only Amazon can see. Everything layered on top is Ring's own. The white paper describes sealed hardware that holds the keys, a key database with no backups, and a deletion process that runs one direction only. It also mentions two features most of the coverage skipped. You can cryptographically confirm that your devices are the only ones with access, and every change to that list goes into a log nobody can edit without leaving a mark. The paper contains no independent audit. Every claim in it is Ring describing Ring. Ring also acknowledges a limitation directly. Think of the enclave as a vault. The keys get made inside it and stay inside it, and Ring says its own staff cannot get in there. The vault does not do the work, though. When a feature like Smart Alerts needs to look at your video, the key has to come out of the vault and go over to the service doing the looking. That service runs on ordinary Ring infrastructure. Ring says the key sits in memory there, never gets written to a disk, and gets erased the moment the job finishes. That is a promise enforced by code, and it is a step down from the vault. Moving those services into vaults of their own is work Ring says it is still exploring. Until that happens, the strongest protection covers the keys while they sit still, and something weaker covers the moment they get used. Until the invitation shows up, your camera is still running whatever you have today. Open Control Center, tap Video Encryption, and go see what that is. ## Sources - **Ring:** [Introducing TAKE encryption](https://www.aboutamazon.com/news/devices/ring-take-encryption?ref=freshfromcache.com) (August 26, 2026) - **Ring:** [Throw Away the Key Encryption and End-to-End Encryption white paper](https://assets.aboutamazon.com/e8/64/d5c572c74f11b5e55bcb93b63bd8/ring-ae-e2ee-whitepaper-august-26-2026.pdf?ref=freshfromcache.com) (August 26, 2026) - **Ring:** [Privacy](https://ring.com/privacy?ref=freshfromcache.com) and [law-enforcement guidelines](https://ring.com/support/articles/oi8t6/Learn-About-Ring-Law-Enforcement-Guidelines?ref=freshfromcache.com) - **Gizmodo:** [Ring says its new encryption system could make it harder for police to access videos](https://gizmodo.com/ring-says-its-new-encryption-system-could-make-it-harder-for-police-to-access-videos-2000803553?ref=freshfromcache.com) (August 26, 2026) - **TechCrunch:** [Amazon faces class action lawsuit over Ring facial-recognition feature](https://techcrunch.com/2026/06/02/amazon-faces-class-action-lawsuit-over-ring-facial-recognition-feature/?ref=freshfromcache.com) (June 2, 2026) - **Federal Trade Commission:** [Ring privacy and security case](https://www.ftc.gov/legal-library/browse/cases-proceedings/2023113-ring-llc?ref=freshfromcache.com) ### Does technology make us lonely? URL: https://www.freshfromcache.com/does-technology-make-us-lonely/ Last updated: 2026-08-31T10:59:59.000Z My family is either hours away or a plane ride. My job moves me between buildings, so I can go a whole week without seeing the same face twice. Most of my social life happens on a screen. Every few months a headline tells me that is a problem. If your family is a flight away, or you are homebound, or the town you live in does not have many of your people in it, you may have been reading the same thing for years. So I went and read the research instead of the headlines about the research. Some of it surprised me. The number that gets repeated has been bent out of shape. Loneliness and isolation get talked about as one thing when they are two. And the fight over whether phones are doing this has no clear winner. ## The line you have probably heard > Loneliness is as bad for you as smoking fifteen cigarettes a day. That claim has a study behind it. It comes from a 2010 paper by Julianne Holt-Lunstad and her colleagues, who pooled 148 studies covering more than 300,000 people followed for seven and a half years on average. People with stronger social relationships had about a 50 percent greater likelihood of survival over that stretch. The authors then measured that effect against other risks we already take seriously. Smoking was one of them. So were alcohol, inactivity, and obesity. That set a benchmark. It was not an experiment. Lonely people were not put in one room and smokers in another and then compared. Holt-Lunstad keeps a page on her own website correcting how the claim gets used. Her careful phrasing is that lacking social connection is comparable to smoking up to fifteen cigarettes a day. The original measure combined several different counts. How big somebody's social network was, how much support they had, how isolated they were. The feeling of loneliness was only one part of it. The U.S. Surgeon General's 2023 advisory put the comparison front and center. That is why it stuck. Andrea Wigfield, who runs the Centre for Loneliness Studies at Sheffield Hallam University, wrote with two colleagues that the comparison could be called sensationalist, and that it can add to the burden and the stigma already carried by lonely people. Telling somebody who already feels alone that they are doing the equivalent of a pack a day is not information that helps them. That same 2010 paper put the risk in the range of heavy drinking and above inactivity or obesity, and nobody ever quotes those. Everybody already agrees cigarettes are bad for you. Nothing else on that list is that simple, and none of it makes as good a headline. ## The loneliest people are not who you think Loneliness and social isolation get treated like one word. They are two different measurements. Loneliness is the feeling that your relationships fall short of what you need. Social isolation is a count of how much contact you have. You can have plenty of one and none of the other. In June of last year the World Health Organization's Commission on Social Connection published its first global report. About one in six people worldwide are affected by loneliness, and the Commission estimates it contributes to roughly 871,000 deaths a year. The highest rates were among adolescents and young adults. Social isolation goes the opposite direction, and reaches up to one in three older adults. Young people report the feeling more. Older people have less of the contact. Those are two separate findings, and they get quoted as if they were one. ![Line chart of University of Michigan poll results for adults 50 to 80. The share who felt isolated jumps from 27 percent in 2018 to 56 percent in 2020, then falls back to 29 percent by 2024. The share who felt a lack of companionship moves much less, from 34 percent to 41 percent and back to 33 percent.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/fig-npha-two-measures.png) Two questions, two different answers. The pandemic changed how much contact older adults had. It barely changed how they felt about it. When somebody says lonely, I picture an older person by themselves in a house, and I suspect you might too. That picture fits isolation, but not necessarily loneliness. In the United States, a University of Michigan poll of adults 50 to 80 found 33 percent felt lonely at least some of the time in 2024, against 34 percent in 2018\. Six years with no real movement. ## Does the phone cause it? Nobody knows. I would like to give you a cleaner answer than that. There isn't one. In 2019, Amy Orben and Andrew Przybylski went at three enormous datasets covering more than 350,000 young people. They ran the numbers every defensible way instead of picking the ones that made a good headline. Technology use accounted for at most 0.4 percent of the variation in wellbeing. To show what an effect that size looks like, they lined it up against other questions in the same surveys. Eating potatoes was almost as bad for teenage wellbeing as screen time. Wearing glasses was worse. ![Bar chart comparing how strongly different things are linked to teen wellbeing. Screen time is the baseline at one times. Smoking marijuana is 2.7 times stronger and being bullied is 4.3 times stronger. A note adds that eating potatoes is about the same as screen time and wearing glasses is worse.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/fig-orben-comparison.png) The effect everybody argues about, sitting next to effects nobody argues about. Jean Twenge, Jonathan Haidt and their colleagues tell a different story. Their study of more than a million 15- and 16-year-olds found loneliness at school rising between 2012 and 2018 in 36 of 37 countries, alongside spreading smartphone access. The paper says plainly that those patterns cannot prove causation. Haidt has since argued the causal case at book length. The mechanism they propose is displacement. A day has only so many hours. Time on a phone has to come from somewhere. ![Six young people sit shoulder to shoulder along a low wall outdoors, each looking down at their own phone.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/yunus-tug-19nFOn5bAg8-unsplash.jpg) The picture everyone has in mind. The data underneath it is messier. Twenge's own displacement paper, covering 8.2 million young Americans, found the trade happening at the level of a generation and not at the level of a person. College-bound high school seniors in 2016 spent about an hour a day less with other people than seniors in the late 1980s. But within any given year, the kids using the most social media were also the kids seeing their friends the most. Something took that hour. Nobody has shown it was the phone. Instead of watching what people already do, some researchers take social media away on purpose and measure what happens. Two teams have now pooled that same rough pile of experiments and come to different conclusions. Christopher Ferguson's 2024 analysis put the average benefit of cutting social media close enough to zero that he could not rule zero out. A 2025 meta-analysis by Kaitlyn Burnell and her colleagues, covering 32 randomized trials and 5,544 people, found a real improvement in wellbeing from restricting social media. The improvement measured 0.17, which is small. Burnell's team also found the benefit did not depend on how long the restriction lasted, or on the age or makeup of the group. And every one of those trials ran on college students and adults, average age 23, so none of it tells you much about a twelve-year-old. Candice Odgers at UC Irvine argues that some young people may use social media differently because they were already struggling. Her evidence is about youth mental health rather than loneliness, so I will not stretch it further than that. It is still a warning about how little a correlation can tell you about which one caused the other. The reason nobody can give you a clear answer is that the experiment it would take is not one anybody can run. Ten thousand children, half given phones and half given none, followed for fifteen years. Short of that, everyone is arguing over which imperfect substitute to believe, and two careful people can read the same studies and walk away with opposite conclusions. ## What does hold up Time by itself is a weak measure. The number of hours tells us very little. For a while the research offered a tidier replacement. Passive use meant scrolling, watching, keeping tabs on people. Active use meant talking to somebody. Passive was supposed to hurt through comparison, active was supposed to help through support. That model has not survived intact. A 2024 meta-analysis of 141 studies found most of those associations were negligible. The effects that did turn up shifted by age, by outcome, and by context. The authors warned against the neat rule that active is good and passive is bad. My read is that warm back-and-forth contact with somebody who already knows you matters more than counting hours. A sister, an old friend, the coworker you like. Not an audience you are performing for. A product is not neutral about which of those you get. Most apps open on a feed. Scrolling is already in front of you. Talking to one person means leaving it. Both are available, but only one is the default. An AI companion goes a step past that. On a feed, the app decides what is easy, and there are still real people somewhere on the other end. With a companion app, the product is the other end. There is nobody there. I wrote a piece on [what we knew about AI companions and mental health](https://www.freshfromcache.com/the-chatbot/), and the evidence has changed since. A Stanford team published a study this month of 1,131 people who use Character.AI, with nearly half a million of their real messages alongside the survey answers. The people using chatbots out of curiosity or to get work done reported better wellbeing than average. The lower wellbeing showed up among people with small social networks who were using the chatbot for company. It was worse with heavier use, and worse again among the people who told it more personal things. The researchers are careful that this is an association and that it is not uniform. But the people using it for companionship were the ones reporting the worst outcomes. A chatbot agreeing with you can feel a lot like being understood. If you are already short on people who understand you, agreement is an easy thing to accept instead. And it is built to agree with you, which is [a product decision and not a personality](https://www.freshfromcache.com/friendly-ai-is-less-accurate/). ## You cannot hand somebody a group and call it connection In 2021 a team led by Syed Ghulam Sarwar Shah pooled the trials of digital programs built to reduce loneliness in older adults. Six studies, 646 people, average age in the seventies. Four of the six were randomized, and every program ran at least three months. They were social networking platforms built for seniors, and web-based group discussion programs. No significant reduction in loneliness at three months, at four, or at six. The evidence ran from very low to moderate quality. One of those trials handed its control group a binder instead of the software. Printed pages, the same sort of material the program delivered on a screen, sitting in a three-ring binder on a table. It did about as well. The reviewers had a theory about why. A program like this may not reach loneliness unless it also deals with what sits underneath it, which is often mistrust, low self-esteem, and a fear of rejection. That fits the wider research. The interventions with the largest measured effect work on how a lonely person thinks about other people, rather than on adding names to a list. Putting a lonely person on a platform with a group to join does not reliably help. That is a narrower claim than technology doing nothing for older adults, and it would be a mistake to read it that way. Technology is not social media. A [hearing test that came with the earbuds already in the drawer](https://www.freshfromcache.com/can-airpods-be-used-as-hearing-aids/) is technology. So is [the magnifier already in your phone](https://www.freshfromcache.com/your-phone-is-a-magnifying-glass/). So is a video call with your own daughter. Those are tools doing one specific job for one specific person, and none of them were in that study. ![A woman holds up a phone showing an older couple waving back at her on a video call.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/getty-images-Y7rAseI0UZg-unsplash.jpg) One device, one job, one person on the other end. Each one removes a barrier between people who were already trying to reach each other. ## Where this leaves me I remember a little of life before the internet, but by ten I could not get enough of AIM and MSN Messenger. Online I can say what I mean, and I get a second to work out what that is. In person I am shy for a long time before I am me. One night out with a group and I need the next day to recover. Stay up late talking to people online and I am fine by morning. There is a number that cuts against me. The WHO found its highest loneliness rates among adolescents and young adults, the most online-native people alive. That might be a warning about growing up with smartphones and social media. It might also be that adolescence has always been hard and we are only now measuring it. In-person contact is not optional or lesser. It is different, and the difference matters. Bonds form easier face to face and you get a truer picture of who somebody is. But if your family is a flight away, or you are homebound, or the town you live in does not have your people in it, you have spent years being told that the technology keeping you tethered could be hurting you. The research does not support that. It also does not promise you that every hour online is good for you. What it does say is that the hours are a poor measure, and that who you are talking to tells you far more than how long you were there. So use the tool for the relationship you want. If you opened the app because you miss somebody, message them. If the group chat leaves you feeling closer to your friends, stay in it. If the feed leaves you feeling worse, close the feed rather than treating the timer as the problem. If the room where your people are happens to be on a screen, that counts. Nobody ever told me that and I wish somebody had. --- *This piece is about ordinary loneliness, which is not the same thing as a crisis. If yours is sitting heavier than that, the 988 Suicide and Crisis Lifeline is free, always open, and takes calls and texts.* ## Sources Every study named in this piece, in the order it appears. Where a paper sits behind a paywall, the link goes to the abstract and the figures. 1. Holt-Lunstad, J., Smith, T. B., & Layton, J. B. (2010). Social relationships and mortality risk: a meta-analytic review. *PLoS Medicine*, 7(7). [Link](https://journals.plos.org/plosmedicine/article?id=10.1371/journal.pmed.1000316&ref=freshfromcache.com) 2. Holt-Lunstad, J. “15 Cigarettes” — the author’s own page correcting how the comparison gets quoted. [Link](https://www.julianneholtlunstad.com/15-cigarettes?ref=freshfromcache.com) 3. Office of the Surgeon General (2023). *Our Epidemic of Loneliness and Isolation*. U.S. Department of Health and Human Services. [Link](https://www.hhs.gov/sites/default/files/surgeon-general-social-connection-advisory.pdf?ref=freshfromcache.com) 4. Wigfield, A. and colleagues (2023). Is loneliness really as damaging to your health as smoking 15 cigarettes a day? *The Conversation*. [Link](https://theconversation.com/is-loneliness-really-as-damaging-to-your-health-as-smoking-15-cigarettes-a-day-204959?ref=freshfromcache.com) 5. World Health Organization Commission on Social Connection (2025). First global report on social connection. [Link](https://www.who.int/groups/commission-on-social-connection?ref=freshfromcache.com) 6. World Health Organization (30 June 2025). Social connection linked to improved health and reduced risk of early death. [Link](https://www.who.int/news/item/30-06-2025-social-connection-linked-to-improved-heath-and-reduced-risk-of-early-death?ref=freshfromcache.com) 7. University of Michigan National Poll on Healthy Aging (2024). Loneliness and social isolation among adults 50 to 80\. [Link](https://www.michiganmedicine.org/health-lab/1-3-older-adults-still-experience-loneliness-and-isolation?ref=freshfromcache.com) 8. Orben, A., & Przybylski, A. K. (2019). The association between adolescent well-being and digital technology use. *Nature Human Behaviour*, 3(2), 173–182\. [Link](https://doi.org/10.1038/s41562-018-0506-1?ref=freshfromcache.com) 9. Twenge, J. M., Haidt, J., and colleagues (2021). Worldwide increases in adolescent loneliness. *Journal of Adolescence*. [Link](https://www.sciencedirect.com/science/article/pii/S0140197121000853?ref=freshfromcache.com) 10. Twenge, J. M., Spitzberg, B. H., & Campbell, W. K. (2019). Less in-person social interaction with peers among U.S. adolescents in the 21st century and links to loneliness. *Journal of Social and Personal Relationships*, 36(6), 1892–1913\. [Link](https://doi.org/10.1177/0265407519836170?ref=freshfromcache.com) 11. Ferguson, C. J. (2024). Meta-analysis of social media reduction experiments. [Link](https://www.christopherjferguson.com/Social%20Media%20Experiments%20Meta.pdf?ref=freshfromcache.com) 12. Burnell, K., Meter, D., Andrade, F., Slocum, A., & George, M. (2025). The effects of social media restriction: meta-analytic evidence from randomized controlled trials. *SSM – Mental Health*, 7, 100459\. [Link](https://www.sciencedirect.com/science/article/pii/S2666560325000714?ref=freshfromcache.com) 13. Odgers, C. (2024). The great rewiring: is social media really behind an epidemic of teenage mental illness? *Nature*. [Link](https://www.nature.com/articles/d41586-024-00902-2?ref=freshfromcache.com) 14. Godard, R., & Holtzman, S. (2024). Are active and passive social media use related to mental health, wellbeing, and social support outcomes? A meta-analysis of 141 studies. *Journal of Computer-Mediated Communication*, 29(1). [Link](https://academic.oup.com/jcmc/article/29/1/zmad055/7595758?ref=freshfromcache.com) 15. Zhang, Y. and colleagues (2026). Interaction with AI companions and psychological well-being. *Nature Human Behaviour*. [Link](https://www.nature.com/articles/s41562-026-02516-2?ref=freshfromcache.com) 16. Shah, S. G. S., Nogueras, D., van Woerden, H. C., & Kiparoglou, V. (2021). Evaluation of the effectiveness of digital technology interventions to reduce loneliness in older adults. *Journal of Medical Internet Research*, 23(6), e24712\. [Link](https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8214187/?ref=freshfromcache.com) 17. Masi, C. M., Chen, H. Y., Hawkley, L. C., & Cacioppo, J. T. (2011). A meta-analysis of interventions to reduce loneliness. *Personality and Social Psychology Review*, 15(3), 219–266\. [Link](https://doi.org/10.1177/1088868310377394?ref=freshfromcache.com) ### Google will tell you when your address shows up in its search results URL: https://www.freshfromcache.com/remove-personal-info-google-search/ Last updated: 2026-08-30T11:00:00.000Z Google your own name sometime. Not for vanity. Search it the way somebody trying to find you would, with your town added, and see what comes back. Do it in an incognito or private window, so you are not looking at results shaped by your own account and your own search history. For most of us it's a page of those people-finder sites. They sometimes list your age, the street you live on, the names of your relatives and a phone number that may or may not still work. None of it is secret, exactly. It's just been collected and stacked up in one place where anybody can read it. Google has a tool that watches for that on your behalf. It's called "Results about you," it's free, and you set it up once. Google says more than 10 million people have used it. The tool doesn't scrub the internet. It watches Google's own search results for details you tell it to look for, tells you when it finds them, and gives you a button to ask for the result to be taken out of Search. Watching is one thing, but it's blurrier when you request removal. ## Setting it up 1. Go to [goo.gle/resultsaboutyou](https://goo.gle/resultsaboutyou?ref=freshfromcache.com), or open the Google app, tap your profile picture, and choose "Results about you." The hub also lives at [myactivity.google.com/results-about-you](https://myactivity.google.com/results-about-you?ref=freshfromcache.com). 2. Add what you want watched. Google takes your name plus a nickname or a maiden name, and it takes more than one of each contact detail. So put in every phone number, home address, and email address you have used. 3. Add your government ID numbers too. Since February, Google also monitors for a driver's license, a passport, or a Social Security number showing up in Search. 4. Turn notifications on. Google says matches show up within a few hours of setup, and after that it emails you or pings the Google app when something new appears. ![The Add your name step in Google's Results about you setup, with an Add another control below the name field](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-27-150523.png) Google asks for every name somebody might look you up under. Add another takes a nickname or a maiden name. Then you wait, and the results come to you. When one arrives you open it, look at what the page is actually showing, and hit "Request to remove" on the ones you want gone. Google reviews each request against its policy and emails you what it decided. ![Google Results about you confirmation screen reading Monitoring is on, with a note that the first check usually takes under six hours](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-27-150606.png) Once monitoring is on, Google says the first check usually finishes in under six hours. You can also start a request straight from a search result. Tap the three dots next to it, open "About this result," and choose "Remove result." ![The About this result panel in Google Search showing Share, Save, Remove result and Feedback buttons, with an arrow pointing at Remove result](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-27-151115.png) From a search result, the three-dot menu opens this panel. Remove result is the one you want. ## What it will actually take down Google's removal policy is broader than most people expect. Home address, phone number, and email address are the obvious ones. It also covers government ID numbers, bank and credit card numbers, pictures of your signature or your ID, medical records, and login credentials. A removal comes in two strengths. Google can pull the result out of every search, or it can pull it only out of searches for your name, which leaves the page findable by other means. Google says the first one is what happens most of the time. The narrower one turns up when the page also carries something Google considers valuable to the public, or somebody else's details sitting alongside yours. It is still useful. Nobody is typing your bank account number into Google. They are typing your name. ![The Removal requests screen in Google Results about you showing an approved removal for FastPeopleSearch.com](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-27-150447.png) Requests and their outcomes stack up under Removal requests. This one, against a people-finder site, came back approved. ## What it can't touch Google says it plainly on its own announcement page. "Removing this information from Google Search doesn't remove it from the web entirely." The people-finder site still has your file. It still sells it. Anyone who goes to that site directly, or uses a different search engine, finds exactly what they found before. What gets removed is the shortcut. There is a second limit that catches people. Google will not remove results from pages owned by educational institutions, government institutions, or newspapers. It treats those as public interest. So a county property record or a story in the local paper stays put. For a real fix you need to go after the source, which means opting out at the [data brokers](https://www.freshfromcache.com/what-is-a-data-broker/) themselves. That is slower and it is work. Do this one first anyway. It takes the results off the page where people actually look, and it keeps watching after. ## Go look first Before you set anything up, run the search. Your name, your town, in a private window. Whatever comes back on that first page is the list you're working from, and it's the same list somebody looking for you will find. What came up for you that you did not expect to be public? I'm curious which category surprises people most. joel@freshfromcache.com **Sources** How the tool works: [Google Search Help, Find and remove personal info in Google Search results](https://support.google.com/websearch/answer/12719076?ref=freshfromcache.com) (the hub at myactivity.google.com/results-about-you; nickname, maiden name, and multiple phone numbers, addresses and email addresses; notification within a few hours; "Request to remove" in the hub and "Remove result" from a search result; removal from every query is what happens most of the time; the educational, government and newspaper exclusions) What can come down: [Google Search Help, Remove my private info from Google Search](https://support.google.com/websearch/answer/9673730?ref=freshfromcache.com) (the full list of removable information types, and removal from all searches versus searches for your name) The February change: [Google, Stay in control of your personal information online](https://blog.google/products-and-platforms/products/search/results-about-you-government-id-numbers/?ref=freshfromcache.com) (February 10, 2026; driver's license, passport, Social Security number; goo.gle/resultsaboutyou; "Removing this information from Google Search doesn't remove it from the web entirely") The 2025 redesign: [Google, Protect your personal information and easily take action on outdated content in Search results](https://blog.google/feed/results-about-you-new-design/?ref=freshfromcache.com) (proactive monitoring, removal from the three-dot menu on a result, and the refresh request) Paths and claims re-verified against Google's own pages August 28, 2026\. The 10 million figure is Google's own, from the February 10, 2026 announcement. Screenshots: Joel Folgner. ### Are you paying a different price than your neighbor? URL: https://www.freshfromcache.com/why-your-price-is-different/ Last updated: 2026-08-29T11:00:00.000Z You add something to a cart, look again the next day, and the number has changed. So you look it up, and the internet has an answer ready. The store is watching you and charging what it thinks you will pay. Then comes the advice. Clear your cookies. Shop in a private window. Try a different ZIP code. Turn on a VPN. Most of that does very little. The Federal Trade Commission published its own take on August 19, and it says more about your grocery loyalty card than about your cookies. ## What the FTC said in August The Commission published a proposed enforcement policy statement on personalized pricing. That's a price set from your personal data and what a company concludes from it, including how much it thinks you will pay and whether it thinks you will shop around. The statement is blunt about the limits. "Congress has not given the Commission the authority to prohibit personalized pricing in all circumstances," it says. What the FTC can do is treat a hidden personalized price as deceptive or unfair under the FTC Act. If shoppers reasonably expect that a price does not change according to their personal data, the Commission says a business should clearly disclose that the price is personalized, the basis for it, and the kind of data behind it. Leaving that out, the statement says, is likely to break the law. The vote to publish was 2 to 0. The Commission says the extent to which businesses currently use personalized pricing "is not well understood," and that the effects on shoppers are unclear. It also declines to say whether some personalized pricing would still be unfair even when a company discloses it. This is a warning about hiding the practice rather than a finding that it is everywhere. The examples the statement gives are illustrations rather than accusations, but they are specific: - A grocery chain charging a delivery customer more for milk based on data showing several children live in the household. - A hotel charging more to someone it believes is traveling for a funeral. - A retailer charging more on its website when the data says the shopper is standing inside its own store or parking lot. Prices change all the time for reasons that have nothing to do with who is looking at them. ## Three reasons the price changes Only one of them is about you. ![Three panels comparing prices. In the first, three shoppers at the same store this morning all see $14.49. In the second, two shoppers at a city store see $12.99 while two at a rural store see $13.79. In the third, at the same store at the same second, two shoppers who are browsing see $12.99 and one shopper who is signed in sees $14.29.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-three-reasons.png) Same item, three shoppers. Only the third price was built for a person. **Supply and demand.** Airfare, hotel rooms, rideshare surge, produce after a bad harvest. The price moves for everyone looking at that moment. **Where you are.** Prices differ between stores, regions, and delivery zones. Prices change for taxes, rent, competition, and shipping. Everyone shopping in that store still sees the same price on the shelf. **Who you are.** A price built from what a company knows or guesses about you personally. This is what people mean by surveillance pricing, and it is the hardest of the three to spot. A price displayed for you looks exactly like a price displayed for everybody. Insurance and credit belong in a category of their own. They have always been priced per person, and the FTC statement carves them out for that reason. If your car insurance quote depends on your driving record, you have been buying a personalized price for years. ## What has been caught The clearest case in American grocery shopping came from Consumer Reports and Groundwork Collaborative in December 2025\. They recruited 437 volunteers who shopped Instacart at the same moment for the same list of items from the same stores. In one test at a Seattle Safeway, 39 shoppers put the same 20 products in a cart at the same time. Instacart showed them five different basket totals. The totals ranged from $114.34 to $123.93, a spread of $9.59\. Only 8 percent of the group got the cheapest cart. Across the investigation, about 75 percent of the products checked had more than one price. Per-item gaps ranged from 7 cents to $2.56 and reached 23 percent on some items. Consumer Reports estimated that kind of swing could add up to roughly $1,200 a year for a family of four. Instacart says the tests assigned shoppers at random by product category and location, and denies using personal or demographic data to set them. Consumer Reports looked and reported that it found no evidence otherwise, while noting that its sample was too small to rule it out. The price differences are documented. Whether particular people were singled out remains unproven. In January 2025, FTC staff reported on documents from six pricing middlemen, including Mastercard, Accenture and McKinsey, who between them worked with at least 250 clients. Staff found the data used to tailor prices can include precise location, demographics, browsing history, shopping history, what you leave sitting in a cart, and even mouse movement on a page. The report's examples of how that data gets used are hypotheticals rather than case files because the underlying documents are confidential. Kroger has acknowledged using demographic data and purchase history in the promotions and discounts it offers loyalty members. That is disclosed, and it arrives as a discount, but it runs on the same machinery. What nobody has shown is a grocery store charging you a different shelf price than the person standing next to you because of who you are. Digital shelf labels are spreading, and they make prices easy to change quickly. Evidence that a store used them to personalize a shelf price has not appeared. ## Your account determines your price A store has to know it is you before it can price you. Here is what it can use, starting with the hardest to avoid. - **The account you sign into.** You hand it over on purpose, every visit. - **Your loyalty number.** The same thing at the register, with a discount attached to make it easy. - **The email address or phone number you type at checkout.** These match you to your account even when you never signed in. - **The store's app.** It sees more than a browser does, including your location if you allowed it. - **Your device fingerprint.** Your screen size, fonts, and settings, combined into something close to a name tag. - **Cookies and your IP address.** The bottom of the list, and the only two the usual advice seems to talk about. Clearing your cookies and hiding your address is the standard advice. Everything above them on that list survives the cleanse. ![A table of seven ways a store can recognize you, with three columns for a private window, clearing cookies, and a VPN. Only the cookies row is reached by a private window and by clearing cookies, and only the IP address row is reached by a VPN. The account, loyalty number, checkout email or phone, store app, and device fingerprint rows are untouched by all three.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-what-the-advice-touches.png) Three checks out of twenty-one. The advice reaches the bottom two rows. The FTC's own document gives an example of what it considers an adequate disclosure. The example is a price based on "previous purchases from the same retailer through the same login account." [Our browser privacy piece](https://www.freshfromcache.com/chrome-edge-privacy-settings/) told you to block third-party trackers in Chrome and Edge, and that advice stands. It cuts the tracking that follows you between unrelated websites and feeds ad targeting. It does very little about a price attached to your account at a store you signed into. ## The usual advice, tested **A private or incognito window.** Does almost nothing on its own. It hides that session from other people using your computer. The store still sees your IP address, your device, and your account the moment you sign in. **Clearing cookies.** Same problem, with a cost. It signs you out of things, but fingerprinting can recognize you anyway. **One browser for looking, another for buying.** Does nothing if you sign in on both, which is what most people do at checkout. **Changing your ZIP code or using a VPN.** This one can move a price because location is a real input. It can also cost you money. Shipping and tax follow the address you actually enter, and some sites block VPN traffic outright. A wrong ZIP code on a delivery order gets you a failed delivery. A VPN only moves where you appear to be. Signing in gives you away. **Shopping signed out or as a guest.** This one does help because your account is the strongest thing a store has on you. It also costs you the member price at most stores, so you are trading one for the other. **Leaving it in the cart and waiting.** Sometimes it produces a discount email, which is the same system working in your favor. It is also how the store learns that you hesitate. ## What works **Compare across sellers.** Whether you are likely to comparison shop is itself something these systems try to estimate. A price directed at you only works if you do not look anywhere else. If you live somewhere with one grocery store and one internet provider, that advice does not work as well. Which is why the account and loyalty items below matter more for you. **Buy it in the store.** Consumer Reports stated directly that shopping in person will usually mean paying what everyone else pays. **Do the coupon math.** A targeted offer is a real discount when it beats the shelf price and beats the store down the road. Check both. **Run the two-phone test.** Same store, same item, same time. Sign into your account on one phone and stay signed out on the other. Change one thing at a time so you know what made the difference. **Use the rights Oregon already gave you.** The Oregon Consumer Privacy Act lets you ask a business that holds your data for: - a copy of what it has on you - a list of the specific companies it gave your data to - a correction to anything wrong - deletion of what it holds - an opt out of selling your data or using it for targeted ads Since January 1, 2026, covered businesses also have to honor a browser opt-out request. That request is a setting called Global Privacy Control, and it tells every site you visit not to sell your data. Firefox has it under "Tell websites not to sell or share my data." Brave and DuckDuckGo turn it on for you. Chrome and Edge need an add-on. If a business ignores a request, the Oregon Department of Justice takes complaints through its privacy complaint form. Its consumer hotline is 1-877-877-9392. New York has required since November 2025 that companies label an algorithmic price with a specific line: "THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA." Several other states have gone further with grocery-specific rules. Oregon Senator Jeff Merkley introduced a bill with Senator Ben Ray Luján this year that would ban surveillance pricing in grocery stores outright, but it has not passed. ## You have until September 18 to comment The FTC is taking public comments on this policy statement, and the docket is open now. 1. Go to regulations.gov and search for docket **FTC-2026-1057**. 2. Open the docket and choose the comment button. 3. Write a few sentences about what you shop for, what you have seen, and what you want the agency to require. No account needed. 4. Submit it. You get a tracking number. Comments close **September 18, 2026, at 11:59 p.m. Eastern**. As of this week, 112 people had filed. One warning before you write. Comments are public. Your text, along with any name or contact information you put in the box, can be posted where anyone can read it. You cannot take it back afterward. Keep your address, phone number, and account numbers out of it. One comment from one shopper will not decide this. Volume and specifics do get read. The rest of the time, the best advice is old advice. Check another store before you buy. ## Sources - [Federal Trade Commission, proposed enforcement policy statement on personalized pricing (File No. P034101), August 19, 2026](https://www.ftc.gov/system/files/ftc%5Fgov/pdf/p034101-ftc-enforcement-policy-statement-re-personalized-pricing-proposed-for-public-comment.pdf?ref=freshfromcache.com) - [Federal Trade Commission, “FTC Seeks Comment on Enforcement Policy Statement Regarding Personalized Pricing,” August 19, 2026](https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-seeks-comment-enforcement-policy-statement-regarding-personalized-pricing?ref=freshfromcache.com) - [Regulations.gov, docket FTC-2026-1057 (the comment docket)](https://www.regulations.gov/docket/FTC-2026-1057?ref=freshfromcache.com) - [Federal Trade Commission, surveillance pricing staff findings, January 17, 2025](https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-surveillance-pricing-study-indicates-wide-range-personal-data-used-set-individualized-consumer?ref=freshfromcache.com) - [Consumer Reports and Groundwork Collaborative, “Instacart’s AI-Enabled Pricing Experiments May Be Inflating Your Grocery Bill,” December 2025](https://www.consumerreports.org/money/questionable-business-practices/instacart-ai-pricing-experiment-inflating-grocery-bills-a1142182490/?ref=freshfromcache.com) - [Oregon Department of Justice, Consumer Privacy](https://www.doj.state.or.us/consumer-protection/id-theft-data-breaches/privacy/?ref=freshfromcache.com) - [Office of Senator Jeff Merkley, Stop Price Gouging in Grocery Stores Act of 2026](https://www.merkley.senate.gov/lujan-merkley-introduce-legislation-to-stop-grocery-price-gouging-and-lower-costs-for-americans?ref=freshfromcache.com) ### Also this week: pricier Amazon devices, a $17 billion Meta settlement, and a check from Disney URL: https://www.freshfromcache.com/also-this-week-2026-08-28/ Last updated: 2026-08-28T10:59:59.000Z I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week. ## Amazon raised prices on the Echo Dot, the Kindle and the Fire TV Stick Sometime overnight on August 20 the prices on Amazon's own devices changed, with no announcement. Fortune noticed and got a statement out of Amazon: "The consumer electronics industry is facing significant increases in memory and storage component costs. After absorbing these increases for as long as we could, we recently adjusted pricing across our product lines." Memory chips are short because AI data centers are buying them first. Apple and Nintendo have raised prices this month for the same stated reason. | Device | Old price | New price | On the shelf, Aug 27 | | --------------------------- | --------------------- | ------------------- | -------------------------- | | **Echo Dot** | $49.99 | $79.99 | $54.99, on sale | | **Kindle 16 GB** | $109.99 | $149.99 | $149.99, at list | | **Kindle Paperwhite 16 GB** | $159.99 | $199.99 | $199.99, at list | | **Fire TV Stick HD** | $34.99 | $39.99 | $17.99, on sale | | **Fire TV Stick 4K Max** | $59.99 | $84.99 | $49.99, on sale | | **Fire TV Cube** | $139.99 | $199.99 | $109.99, on sale | | **Mac mini (Apple)** | $799 ($599 at launch) | $899 | orders open, ships Sept 22 | | **Switch 2 (Nintendo)** | $449.99 | $499.99 from Sept 1 | $449.99 through Aug 31 | Amazon prices read off the live listings on August 27\. The "new price" is the list price, the crossed-out number next to a sale price. Look at that last column. The new prices are list prices, and as of August 27 almost none of them is what Amazon is charging. The Echo Dot shows $54.99 with the $79.99 crossed out, five dollars more than the old list. The Fire TV Stick 4K Max is selling ten dollars under its old list. Amazon said in the same statement that it "will also offer promotions across its lineup throughout the year." A higher list price makes every one of those promotions look better. It also raises the floor for the weeks when nothing is on sale. [We went through this on laptop price tags on August 26](https://www.freshfromcache.com/how-to-read-a-laptop-price-tag/), and here it is on Amazon's own shelf five days later. [The same squeeze is coming for phones.](https://www.freshfromcache.com/why-your-next-phone-costs-more/) So if the thing you want is on sale, the sale price is real and the crossed-out number is decoration. If it is sitting at list, wait. Amazon told you itself that the promotions are coming. Sources: [Fortune](https://fortune.com/2026/08/21/exclusive-amazon-quietly-hiked-prices-echo-fire-tv-kindle-eero-significant-increases-memory-costs/?ref=freshfromcache.com), [Apple](https://www.apple.com/newsroom/2026/08/apple-unveils-a-more-powerful-mac-mini-featuring-the-all-new-m6-and-m5-pro/?ref=freshfromcache.com) and [Nintendo](https://www.nintendo.com/us/whatsnew/price-revision-for-nintendo-switch-2-system/?ref=freshfromcache.com) ## Meta agreed to pay $17 billion to settle the teen social media case Last week's roundup left off with four states in an Oakland courtroom trying Meta on behalf of a 29-state coalition. On August 25 the head of Instagram, Adam Mosseri, was on the stand being shown his own December 2021 blog post, which said more than 90 percent of teens kept the "Take a Break" reminder turned on. The internal number the states put next to it was 1.8 percent of teens actually using it. He agreed that figure was never made public. The next morning, at about 6 a.m., a settlement was filed. Meta will pay up to $17 billion over ten years to attorneys general from more than 45 states and territories. About $5 billion of that arrives only if YouTube and TikTok adopt the same restrictions. Texas was never in the multistate case and settled on its own the same day, for more than $1 billion, on the same terms. California's share is at least $1.5 billion. Meta's announcement spells out what changes for anyone under 18 on Instagram and Facebook in the participating states. All of it is on by default: - a two-hour daily limit that "teens can only turn off with a parent's permission" - a block from both apps between midnight and 6 a.m. - notifications muted during school hours, 8 a.m. to 3 p.m. - a reminder after every 15 minutes of continuous use - no like or reaction counts, on their own posts or anyone else's - no cosmetic-surgery or extreme-makeup filters - the option to make a non-personalized feed the default, and to turn off autoplay The states' agreement adds two more: a reporting channel where Meta has to answer 90 percent of teens' harm reports within six hours, and an independent auditor. There is also a second, stricter tier. If YouTube and TikTok sign on, the daily limit drops to one hour and the overnight block grows to 10 p.m. through 7 a.m., and that is where the last $5 billion comes from. Meta published an open letter asking YouTube and TikTok to join, on the grounds that "when teens are restricted on one app, they simply move to another." Neither had answered as of August 27. Judge Yvonne Gonzalez Rogers told the courtroom that morning that a document arriving at 6 a.m. deserved "a closer look." By the afternoon, according to court records reported by NPR and CBS, she had approved the deal. Nobody has said when the restrictions actually switch on. Meta says "pending judicial approval." California says "within months." Neither is a date. Florida stayed out entirely; its attorney general called the money "peanuts" and said, "We'll see them at trial." Zuckerberg never took the stand. [Last week's block, if you want the setup.](https://www.freshfromcache.com/also-this-week-2026-08-21/) Sources: [California Attorney General](https://oag.ca.gov/news/press-releases/attorney-general-bonta-secures-transformative-17-billion-settlement-meta?ref=freshfromcache.com), [Meta](https://about.fb.com/news/2026/08/agreement-with-state-attorneys-general-supporting-teens/?ref=freshfromcache.com), [NPR](https://www.npr.org/2026/08/26/nx-s1-5944781/meta-settlement-child-safety-lawsuit?ref=freshfromcache.com) and [The San Francisco Standard](https://www.sfstandard.com/2026/08/26/meta-reaches-18b-settlement-oakland-teen-safety-trial/?ref=freshfromcache.com) ## Disney owes YouTube TV and DirecTV Stream subscribers a check by September 8 Disney is paying $50 million to settle a class action called Biddle v. The Walt Disney Company. The suit accused Disney of using its ESPN carriage deals to push up what YouTube TV and DirecTV Stream charged everybody, whether or not they ever watched a game. Disney denies it, and settling means the case ends without a court ever deciding who was right. ![The Biddle v. Disney settlement site with its Important Dates panel: claims due September 8, 2026, final approval hearing January 14, 2027](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/disney-settlement-dates.png) The settlement site's own dates. Screenshot: onlinetvsettlement.com, August 27. You are owed if you paid for either of these at any point between April 1, 2019 and March 31, 2026: - YouTube TV - DirecTV Stream, including the years it was sold as DirecTV Now or AT&T TV Now You do not need receipts. The administrator checks claims against the providers' own records. Filing online at onlinetvsettlement.com takes the Unique ID and PIN printed on the notice you got by mail or email. If you never got a notice or lost it, email the administrator at info@OnlineTVSettlement.com and ask. Otherwise you can print the claim form and mail it. Either way, you say how long you subscribed and sign it under penalty of perjury. Payments are pro rata, which means everyone splits the pot in proportion to how long they subscribed, and the size depends on how many people file. Nobody has published a per-person estimate. ![The claim form login on onlinetvsettlement.com asking for the Unique ID and PIN printed on the mailed notice](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/disney-claim-login-crop.png) Filing online starts with the Unique ID and PIN from your notice. Screenshot: onlinetvsettlement.com, August 27. Claims are due September 8, 2026\. Online is the safer route this close to the deadline, because the mailing instructions say the form has to be in the administrator's hands by September 8, not just postmarked. Then nothing happens for a while. The final approval hearing is January 14, 2027, and money moves only after that and after any appeals. The administrator is Epiq, at 1-877-704-2517, which is a recorded line. Filing is free and there is no fee to release your money, so anyone who asks for one is running a different business. Source: [Online TV Settlement](https://onlinetvsettlement.com/?ref=freshfromcache.com) ## A gas alarm sold under 18 names on Amazon can stay silent in a real leak On August 20 the Consumer Product Safety Commission told people to stop using a plug-in natural gas and carbon monoxide detector sold as model KH158\. The agency has 91 reports of the unit failing to sound during a real leak. Consumer Reports, which flagged the detector to Amazon back in April, counts four hospitalizations in those reports, two of them children. About 377,000 were sold between June 2024 and July 2026, for anywhere from $13 to $140, on Amazon, eBay, AliExpress, Micro Center's website and snapklik.com. The maker is a Chinese company called Shenzhen Kanghua Shengshi Industrial, which does business as KH Alert, but you will not find that name on most of the listings. Here is what to check for: Check for model KH158 - White, gray or black plastic plug-in with a digital display - A button on the front marked SELF-TEST - Three lights left of the button: POWER (green), FAULT (yellow), ALARM (red) Sold under these 18 brand names - ARIKON - ELECOIN - FLUNGSKY - HAOKESITE - Hembisen - JNHCD - KAKIMENT - KH Alert - KOABBIT - NICGOL - NORJAN - OUMEBIU - Sooguard - Vilfet - Vzmcov - WESHLGD - XLA Alert - YOJOCK This is a warning, not a recall. The manufacturer has not agreed to take the product back, so there is no official refund and no fix coming. CPSC's instruction is to unplug it, throw it away, and put up a detector that meets the UL 2034 standard. Consumer Reports says Amazon pulled the listings, and that if yours came from Amazon you should put it through a return and ask for the refund. [We wrote up the difference between a warning and a recall](https://www.freshfromcache.com/what-is-a-cpsc-product-safety-warning/), and this is the case that post was describing. If you bought a plug-in combination alarm online in the last two years and cannot remember the brand, check your order history for the model number, then look at the front of the unit. Replace it with something carrying a UL mark. Sources: [CPSC](https://www.cpsc.gov/Warnings/2026/CPSC-Warns-Consumers-to-Stop-Using-4-in-1-Plug-In-Natural-Gas-and-Carbon-Monoxide-Detectors-Immediately-Due-to-Failure-to-Alert-Consumers-to-Deadly-Carbon-Monoxide?ref=freshfromcache.com) and [Consumer Reports](https://www.consumerreports.org/home-garden/smoke-carbon-monoxide-detectors/stop-using-this-faulty-plug-in-co-detector-cpsc-warns-a9302564495/?ref=freshfromcache.com) That's the week. If you are new here, [Start Here](https://www.freshfromcache.com/start-here/) collects the pieces worth reading first, and [the Tuesday email](https://www.freshfromcache.com/newsletter/) carries the whole week in one place. ### Why is my Wi-Fi slow? URL: https://www.freshfromcache.com/why-is-my-wifi-slow/ Last updated: 2026-08-27T10:59:59.000Z Netflix starts buffering every night around eight. The back bedroom barely gets a signal. You already unplugged the router and counted to ten. You decide you need a new router. The next stop is a review site, and every review site ends the same way, with a mesh system costing around three hundred dollars. ![A television screen showing nothing but a grey loading spinner and the word Buffering.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-26-075209.png) The symptom everybody recognizes. What it does not tell you is which of five problems caused it. Sometimes that is the right purchase. Often it is overkill aimed at a problem you do not have. "Slow Wi-Fi" is really five different problems that feel identical from the couch, and you can tell them apart with the phone you already own. Name the problem first. After that the buying decision gets easy, and in a lot of houses the answer turns out to be free. One piece of background first. Every check in this article leans on it. ## Wi-Fi is a radio taking turns Wi-Fi is radio. Your router and every device in the house share a channel, and only one of them transmits at a time. Everything else waits its turn, and most of what your network does, good and bad, follows from that rule. It explains why one old device can drag down the others. Wi-Fi is half duplex, which means a device either talks or listens, never both, and the channel carries one talker at a time. A ten-year-old smart plug talks slowly, so it needs more airtime, its share of the channel's clock, to say the same thing, and every device on the same band waits behind it. The saving grace is that a modern router runs its bands as separate lanes. The old plug drags its own lane, almost always 2.4 GHz, while a phone on 5 GHz drives right past. More on the bands below. It also explains the back bedroom. A weak signal does not cut off. The connection slows down instead, switching to a sturdier, more repetitive way of talking that still gets through. Engineers call it rate adaptation, and it is why the far room "works but is slow," and why the signal bars are a poor gauge. Bars show how strong the signal is, not how fast it is. The speed your laptop reports for Wi-Fi (the link speed, or negotiated rate) is the speed between the laptop and the router. It says nothing about the line from the street, which has its own limit, the one on your bill. No router, at any price, makes that line faster. One wording note before the checks. Many providers combine the modem and router into a single unit (a gateway), and fiber uses an ONT instead of a modem. [The rebooting guide](https://www.freshfromcache.com/why-does-rebooting-your-router-work/) sorts out the gear names. Everything below says router, and it applies either way. ## Define the problem - **Your plan is too small.** The plan is the speed tier you buy from your provider, the number in the ads. When it is too small, downloads crawl and streams stutter on every device, at every hour. This is rarer than the ads imply, and the arithmetic in the next section shows why. - **The connection chokes under load.** Speed tests look fine, but video calls break up and pages hang whenever somebody uploads something. The connection is fast and still unresponsive, a wide road stuck in gridlock. The problem has a name, bufferbloat, and step 5 of the checklist below has the free test for it. - **The house eats the signal.** Strong near the router, weak in the back bedroom. Distance and walls are taking the signal before it reaches you. The section on the house covers what does the eating and which of it you can change. - **The neighborhood is crowded.** Fine at noon, bad at eight, or bad everywhere in an apartment building. Too many networks and gadgets are sharing the same slice of air, yours and the neighbors' alike. - **One device is the problem.** A single phone or laptop struggles while everything else hums along. The network is fine, and the section on devices covers the usual suspects. ## Check your internet package Start with the speed you pay for. Your bill may only show the plan's name, mine says X-FON 2500 and a dollar amount, and that is normal. The dependable spot is the broadband label, a standardized fact sheet providers have been required to post in your online account since late 2024\. It lists the exact download and upload speeds you bought, in plain numbers, next to the fees. ![Two broadband labels from a fiber provider showing monthly price, a ten dollar managed Wi-Fi fee, and typical download and upload speeds of 500 and 2500 Mbps.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-24-191836.png) The broadband label lists the speeds you actually bought, the fees, and the typical latency. Providers have had to post one in your online account since late 2024. Then ask what you need. Netflix says a 4K stream takes 15 Mbps and a regular HD stream takes 5\. Zoom says a group video call takes about 3 to 4 Mbps in each direction. Add two 4K streams, a video call, and a houseful of phones, and you are still under 50\. A 300 Mbps plan is not why the movie buffers. Now test what the line is actually delivering. Stand next to the router with your phone and run a speed test. Fast.com works in any browser, and searching "speed test" on Google runs one right in the results. Plugging a computer straight into the router with an Ethernet cable is the more accurate test, but most laptops lost that port years ago, and the next-to-the-router phone reading is the next best thing. A result close to the label's number means the line is fine and your problem lives inside the house. A result far under it, taken right next to the router, means new Wi-Fi gear will not help. Call your provider with the result in hand. A quick note. Upload is the smaller side of most cable plans, and video calls, cloud photo backups, and security cameras all use it. And on satellite or cellular home internet, read the fine print. T-Mobile's home internet terms put heavy users behind everyone else after 1.2 terabytes in a month, though only when the local tower is busy. A slowdown at busy hours on those services can be the service working exactly as written. ## The house is part of the network The router usually sits wherever the line happens to enter the house. A front corner, a basement, a closet. That spot was picked by the installer's cable run, not for coverage, and the whole house pays for it. ![Two floor plans of the same house. In the first the router sits in a front corner and the back bedroom is a dead zone. In the second the router has moved to a central hallway and most of the house has signal.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-router-placement.png) The same router in two spots. The back bedroom stays weak even after the move, because a masonry wall sits in the path, which is exactly the case where a wired access point earns its money. Radio fades with every wall it crosses (attenuation, if you want the term), and all walls are not created equal. Drywall barely registers. Brick, concrete, old plaster over metal lath, foil-backed insulation, and modern coated windows each take a real bite. A big mirror or a full aquarium has the same effect. So the cheapest coverage upgrade is to move the router or clear the area around it. Off the floor, out of the cabinet, away from the TV and the fish tank. Even sliding it along the same cable to a more open spot can change the back bedroom. If there is no good spot on the existing run, the provider can move the jack for a service fee, typically about $100 at the biggest cable company, so ask the price when you book. The bands play a part too. Put simply, 2.4 GHz reaches the farthest and gets through walls best, and it is also the most crowded lane, shared with the neighbors, the microwave, baby monitors, and a generation of smart gadgets. 5 GHz is faster and fades sooner. 6 GHz, on the newest gear, is the fastest and shortest of all, and federal rules keep indoor equipment at low power, so do not expect it to reach the garage. Most current routers broadcast all their bands under one network name and steer each device toward the best lane (band steering). Older setups sometimes show two names instead, one per band, and then the pick is yours. Either way, phones are loyal to a fault. Walk across the house and yours may cling to the weak, distant signal it already had. Flip Wi-Fi off and back on, and it reconnects to the best option from where you now stand. ## The device in your hand Before blaming the network, compare devices. Run the same speed test on two of them in the same spot. One slow while the rest are fine means you can stop looking at the router. If the slow one is a computer, [that is a different rabbit hole](https://www.freshfromcache.com/why-is-my-computer-slow/). Update it, and if it runs a VPN, turn the VPN off and test again. A VPN caps speed and adds delay by design, which is part of [what a VPN actually does](https://www.freshfromcache.com/what-a-vpn-actually-does/). You can also check what a device negotiated with the router: - **Windows 11:** Settings, then Network & internet, then Wi-Fi, then your network's properties. Network band shows the lane, and link speed is the device-to-router number from earlier. - **Mac:** hold the Option key and click the Wi-Fi icon in the menu bar for the same details. - **iPhone:** shows none of this. The compare-two-devices test is the measurement. - **Android:** varies by maker, with the details usually under the connected network's name in settings. ![Windows 11 Wi-Fi properties screen with arrows pointing to Network band, reading 5 GHz channel 44, and aggregated link speed, reading 1297 by 1441 Mbps.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/win11-wifi-properties-redacted.png) The two lines that matter on Windows: which band the device landed on, and the link speed it negotiated with the router. The link speed is not your internet speed. Two values are blacked out here because they identify this particular machine. An old laptop is sometimes the whole issue. Its radio was built for the network of its year, and it cannot use the lanes a new router opens. A budget laptop from the mid-2010s often shipped with a one-antenna Wi-Fi 4 radio that tops out at a 72 Mbps link rate, before walls and sharing take their cut, and no router at any price changes what that radio can do. A USB Wi-Fi adapter in the $20 to $40 range gives it a new radio, the cheapest hardware upgrade there is. ## The router you rent If your internet comes from a cable company, look at your bill for an equipment fee. The biggest cable provider charges $15 a month for its gateway as of August 2026\. That is $180 a year, every year, for the same aging box. A decent modem and router of your own run roughly $90 to $200 once and pay for themselves inside about a year. Fiber changes the shape of this. The small unit that terminates the line (the ONT) stays the provider's, but the Wi-Fi router behind it is often your choice. Some fiber providers include one, and some lease it. My own local provider charges $10 a month for its gateway and is happy to let customers bring their own. Cellular home internet includes the box. Read the equipment line on your own bill rather than assuming. Renting has one real upside. The provider keeps the box updated, and when it dies they hand you another one. Own your router and that job is yours, and a router that stopped getting security updates should be replaced no matter how fast it still feels. That problem is separate from speed, and [it has its own guide](https://www.freshfromcache.com/router-expiration-date/). ## Understanding router speeds Walk the router aisle and every box wears a number. AX3000, BE9300, and up. That number is every band the router has, added together, at a theoretical ceiling. An AX3000 is a 574 Mbps ceiling on the 2.4 GHz band plus a 2,402 Mbps ceiling on the 5 GHz band, rounded up into one figure. Your phone connects to one band at a time, usually with two antennas, through your walls. It sees a fraction of either ceiling, and the line from the street is smaller than all of it anyway. That does not make new gear pointless. Each Wi-Fi generation gets better at juggling a full house, splitting each lane between many devices instead of making them take strict turns. The gains show up when a dozen gadgets are talking at once, which is most homes now. Where money goes wrong is the shape of the gear, not the number on it. A plug-in extender listens and repeats on the same lane it shares with you, so whatever it relays arrives at roughly half speed. A mesh system does the same relay job over a dedicated lane back to the main router (the backhaul), which avoids most of that penalty. A mesh unit or access point fed by an actual wire, Ethernet or coax, skips the relay entirely. If a wire can reach the dead zone, the wire wins. ## What to check, in order Stop at the first step that explains your problem. 1. **Restart the router once.** Why that works, and when it will not, [is its own article](https://www.freshfromcache.com/why-does-rebooting-your-router-work/). If it is still slow, keep going. 2. **Compare two devices in the same spot.** One slow while the rest are fine means the device is the problem. Update it, turn off its VPN, and if it is old, consider the $20 adapter. 3. **Speed test next to the router, then in the problem room.** A big drop in the problem room means coverage. Move or clear around the router and test again. Remember the Wi-Fi off-and-on trick for a phone that clings. 4. **Compare the next-to-the-router number to your plan.** Far under the plan while standing right there means the line or the router itself. Call your provider with your results. 5. **Run the free bufferbloat test.** Search "Waveform bufferbloat." It runs in a browser and hands out a letter grade. A bad grade means the connection chokes when somebody uploads. Pause the big backups first. If the grade stays bad, this is the one problem where a better router genuinely fixes something, and the feature to look for is called smart queue management. 6. **Notice the clock.** Slow only at busy hours, even next to the router, points at congestion on the provider's side or in the neighborhood air. Your gear is not the cause, and your gear cannot be the cure. ![Bufferbloat test results showing a grade of B, idle latency of 5 milliseconds rising by 33 and 43 milliseconds under load, with download and upload speeds in the 600 to 800 Mbps range.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-24-203816.png) A bufferbloat test grades the delay your connection adds while it is busy, which a plain speed test never shows. This line is fast and stays responsive under load. A poor grade here is the one result that points at the router itself. ## When spending money is the right call - The dead zone survives every free change, and a wire can reach it. A wired access point, or a mesh node fed by Ethernet or coax, is the strongest coverage money can buy. - The house is large or the walls are brick and plaster, and wiring is off the table. Mesh with a dedicated backhaul lane, starting with one extra node, not three. - The bufferbloat grade stays bad, or the router stopped getting security updates. Replace the router, and read the support-lifespan guide first. - You are renting a $15 gateway from a cable company. Buy your own and stop the meter. - The next-to-the-router test matches your plan and the household arithmetic still comes up short. That, and only that, is the case for a faster plan. And one answer for the rural readers. If only a single provider reaches your address and the next-to-the-router test already matches your plan, that is the ceiling. A mesh system cannot add speed the line does not carry. What changes the answer is a second provider reaching the address, fixed wireless, or satellite. Until then, the three hundred dollars can stay in your wallet. The checks are free. The mesh system will still be there if you need it. Sources - Netflix Help Center, [Netflix-recommended internet speeds](https://help.netflix.com/en/node/306?ref=freshfromcache.com) - Zoom, [Zoom system requirements and bandwidth](https://support.zoom.com/hc/en/article?id=zm%5Fkb&sysparm%5Farticle=KB0060748&ref=freshfromcache.com) - Microsoft Support, [Faster and more secure Wi-Fi in Windows](https://support.microsoft.com/en-us/windows/faster-and-more-secure-wi-fi-in-windows-26177a28-38ed-1a8e-7eca-66f24dc63f09?ref=freshfromcache.com) - Apple, [Use the Wi-Fi status menu on Mac](https://support.apple.com/guide/mac-help/mchlfad426fa/mac?ref=freshfromcache.com) - Federal Communications Commission, [Broadband Consumer Labels](https://www.fcc.gov/broadbandlabels?ref=freshfromcache.com) - Waveform, [Bufferbloat and Internet Speed Test](https://www.waveform.com/tools/bufferbloat?ref=freshfromcache.com) - Bufferbloat.net, [Tests for Bufferbloat](https://www.bufferbloat.net/projects/bloat/wiki/Tests%5Ffor%5FBufferbloat/?ref=freshfromcache.com) - T-Mobile, [Network traffic prioritization and management](https://www.t-mobile.com/home-internet/policies/internet-service/network-management-practices?ref=freshfromcache.com) - ASUS, [RT-AX3000 specifications](https://www.asus.com/us/networking-iot-servers/wifi-routers/asus-wifi-routers/rt-ax3000/?ref=freshfromcache.com) ### What laptop specs actually matter in 2026? URL: https://www.freshfromcache.com/how-to-read-a-laptop-price-tag/ Last updated: 2026-08-29T22:52:55.000Z Stand in front of the laptops at any Best Buy and read the card under one of the machines between four hundred and nine hundred dollars. You will find a processor name, a Copilot+ badge, a TOPS figure, a refresh rate, a Wi-Fi standard, and a screen size. Most of that is there to sell you. Four things on that card decide whether the machine is still pleasant to use in five years. Memory, storage, the processor, and the screen. Two of the four have a trap hiding inside them that the card will not mention. We already covered [why everything with a screen got more expensive this year](https://www.freshfromcache.com/why-your-next-phone-costs-more/). Knowing that does not help you at the shelf. Knowing what to look for does. Headed to the store? The durable half of this article is a printable card: two pages covering the four specs, the model-number habit, and the date every machine stops getting security updates. [Download the card (PDF)](https://www.freshfromcache.com/content/files/2026/08/laptop-price-tag.pdf). It is part of [The Cache](https://www.freshfromcache.com/cache/), our free library of printable guides. ## Memory: 8 gigabytes is the floor, 16 is the goal Memory (you will see it written as RAM) is your desk. It is how much work the computer can have spread out in front of it at once. Storage is the filing cabinet. People mix these up constantly, but if you think of it that way, it's easier to remember. When the desk fills up, the computer starts shuffling things to the filing cabinet and back. That is the stutter you feel when you switch between windows and it takes a beat to catch up. In August we said that if a laptop is in your budget at all, get at least 8GB. That still holds, and it is the line below which a new Windows laptop is unhappy on day one. But 8GB and 16GB answer two different questions. Eight is "will this be miserable right away." Sixteen is "how long do I get to keep it." A browser with twenty tabs open, a document, and a Zoom call is not an unusual Tuesday. That is the load where 8GB starts shuffling and 16GB does not. If you are keeping this machine for five years, 16GB is the number you want. ![Retail listing showing System Memory set to 8GB with a separate 16GB option button.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-1-memory.png) The whole memory decision, as two buttons. The 8GB one is cheaper today, and on this machine the memory is soldered down. **The Apple exception.** Apple released the MacBook Neo in March at $599, and after June's price increase it starts at $699\. It has 8GB of memory soldered in, which set off a small war in the comments of every review. Then people tested it. Tom's Guide ran the same set of tasks on a Neo and on a Windows laptop and measured the Windows machine using several times more memory for the same work. That test was not a fair fight, because the Windows laptop had far more memory available to spend and a machine with room to spare will use it. But every other test of the Neo has pointed the same way. The Verge found it outrunning the old M1 MacBook Air and most Windows laptops on the light work it is built for. macOS is simply thriftier with memory than Windows 11 is. So 8GB means one thing on an Apple laptop and something different on a Windows laptop. Same RAM, different operating system. **Memory used to be the easy thing to fix later, and that has changed.** On most thin laptops and every MacBook it is soldered to the board, so whatever you buy on day one is what you have on the last day. On many 15-inch Windows laptops and most business-class machines you can still add a stick yourself, but look at what a stick costs now. Tom's Hardware's price tracking puts 16GB of DDR5 north of $200 in August 2026, which is double the price for half the capacity you could buy a year ago. A 32GB kit that ran about $95 before the shortage is $380 to $589. So the upgrade path still exists on some machines, and it is no longer the cheap escape hatch it used to be. Buy the memory you want in the box. If you cannot tell which kind of machine you are looking at, "LPDDR" on the spec sheet usually means soldered. ## Storage: the number matters but the type matters more Everyone knows to check how many gigabytes. Fewer people know to check what kind, and that is where the cheap machines get you. Start with the amount. Windows 11 itself takes roughly 25 to 30 gigabytes before you install anything. Add the recovery partition, the manufacturer's preinstalled software, and the cache Windows keeps for updates, and a 128GB machine is most of the way full at first boot. The consequence goes past inconvenience. Windows needs roughly 20 gigabytes free to install one of the big yearly updates, and when it cannot find the room, the update does not install. Windows does tell you. It puts up a low disk space warning, and the update shows as failed in Settings with a button offering to fix it. But that warning looks exactly like every other notification a computer throws at you, and it is easy to dismiss for months without connecting it to anything. Do that long enough and the machine ends up stuck on a version of Windows that has stopped being supported. Get 512GB if you can. 256GB works if you keep your photos in the cloud and do not install much. Now the type. There are three kinds of storage in this price range and the listings call all of them "flash storage" or nothing at all: - **eMMC** is the slow one. Roughly 150 to 400 megabytes per second, soldered down, no upgrade ever. Common under $300 and on cheap Chromebooks. - **UFS** is soldered too, but genuinely fast. It shows up in some name-brand thin laptops now and performs close to a real SSD. - **NVMe SSD** is what you want. Several gigabytes per second, and on many laptops you can swap it later. The gap between eMMC and an SSD is something you will feel every single day. The gap between one SSD and another is not. So the question to ask about storage speed is simply whether it is an SSD at all. > **The rule that works:** if the listing gives you a storage number but never says what type it is, assume eMMC until the manufacturer's own spec page proves otherwise. Retailers who put a real SSD in a machine tend to say so, because it is a selling point. Silence is a tell. And remember what section one said about the desk and the filing cabinet. A machine that runs out of memory falls back on its storage. Pair 4GB of memory with eMMC storage and you have built a computer that is slow in two ways at once. ## The processor: the tier is easy, the year is the deciding factor The tier map is not complicated. The numbers are a ranking, and a bigger number means a faster chip. An i7 sits above an i5, which sits above an i3\. Ryzen 7 above Ryzen 5 above Ryzen 3\. Both companies have worked that way for years. **Intel:** Core i3, i5, i7 in the older naming, now Core 3, 5, 7, with Core Ultra 5, 7, 9 sitting above them. Celeron and Pentium are retired; the bottom of the range is now "Intel Processor N" something, like the N100 and N150. **AMD:** Ryzen 3, 5, 7, with the newer Ryzen AI line on top. **Apple:** the M-series (M4, M5) in the Air and Pro, and the A18 Pro in the Neo. For email, documents, tabs and video calls, a current Core 5 or Ryzen 5 is comfortable and a Core Ultra 9 is money set on fire. You are not going to work that chip hard enough to notice. The bottom tier deserves a fairer hearing than it usually gets. A modern N150 is a decent little chip, and in a Chromebook or a light Windows machine it does the job. It has nothing in common with the wheezing Celeron in a 2019 clearance laptop except a spot at the bottom of a chart. What actually goes wrong is an N-series chip paired with 4GB of memory and eMMC storage, which is exactly the combination sitting under $300 right now. The chip is carrying the blame for the company it keeps. **The year.** The tier tells you the class of chip. It does not tell you what year the chip is from, and that is the number a clearance laptop is counting on you not to check. Two chips can both be called "Ryzen 5," both start with 7, and be years apart. A Ryzen 5 7520U is from September 2022\. A Ryzen 5 7640U is from 2023 and is roughly twice as fast. Nothing on the price tag says so. There is a decoder ring for this. Every manufacturer has a different one, and you should not spend an evening learning any of them. Search the chip instead: > **Write down the full processor model from the tag and search it.** Look at two things: when it came out, and how many cores it has. An old chip at a full-price machine is a clearance machine. A four-core chip wearing a mid-range name is a budget chip wearing a borrowed one. The core count matters because the release date alone can be told to lie to you. There is an HP on the shelf right now badged "AMD Ryzen 5 40 (2025)," and that year is not a lie. The chip did come out in September 2025\. But it has four cores where a Ryzen 5 normally has six, and the design inside it is the same one AMD shipped in the Ryzen 5 7520U, which goes back to 2019\. New number, old engine. ![Listing highlights grid showing Windows AI Copilot, Processor Model AMD Ryzen 5 40 truncated, 8 gigabytes of memory, and Display Type LED.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-2-processor.png) Everything the summary box will tell you. The processor is cut off at 'AMD Ryzen 5 40...', and 'Windows AI: Copilot' is the ordinary Copilot that runs on any Windows 11 machine, not the Copilot+ badge that would have guaranteed 16GB. That one habit will save more people from a bad laptop than anything else in this article. ## The screen: the spec you will actually resent Most people don't return a laptop over the processor tier. They return it, or leave it closed on the shelf, because looking at it all day is unpleasant. **Resolution.** You want 1920 by 1080, which you will see written as FHD, Full HD or 1080p. Watch out for a listing that just says "HD," because on a cheap machine that often means 1366 by 768\. A resolution that was ordinary in 2011 and is cramped now. It is still being sold on sub-$300 laptops. "2K" is the other word to distrust, because nobody agrees what it means. That HP with the Ryzen 5 40 is sold as a "16-inch 2K touchscreen," and its own specification table says 1920 by 1200\. That is a perfectly good panel, a bit taller than 1080p and genuinely nicer for documents, but it is not what most people picture when they read 2K. Look for the actual pixel numbers, not the letters. **Panel type.** There are four or five words you will see here, and they run in a rough order: - **TN** is the cheapest and the worst. Colors wash out and shift the moment you are not sitting dead center. It clusters on the bottom-shelf machines. - **VA** turns up occasionally. Better contrast than TN, weaker viewing angles than IPS, more common on monitors and televisions than on laptops. - **IPS** is the floor you want. Good color, holds up from an angle, and it is what most decent laptops use. - **OLED** is the nice one. True blacks, excellent contrast, and it starts appearing around $650\. It is a treat, not a requirement. - **Mini-LED** shows up at the top of the range and is more screen than this article's reader needs. If the listing does not name the panel, check the manufacturer's spec page. A budget machine that does not say usually has a reason. And when two parts of the same listing disagree, believe the specifications table. That HP lists its display type as "LED" in the summary box at the top, which tells you nothing, and "IPS" in the specifications further down, which tells you what you needed. ![Specifications table listing Screen Type IPS, Screen Resolution 1920 x 1200 WUXGA, and Brightness 300 nits.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-3-screen.png) One scroll down, the specifications table. The panel the summary box called 'LED' is IPS, the '2K' in the product title is 1920 by 1200, and the brightness is printed for once. **Brightness.** This one is measured in nits and it is the specification most likely to make you unhappy, partly because stores are lit like operating rooms and every screen looks fine under those lights. Budget panels commonly fall in the 220 to 280 nit range. Notebookcheck measured one recent budget laptop at 238 nits and called it dull even indoors. Around 300 to 350 nits is where a screen stops fighting you near a window. Manufacturers self-report this number and round it generously, so treat it as a rough guide. ## The rest of the tag Everything else on that card is either fine to skip, or is there to move you up a price tier. **TOPS** stands for trillions of operations per second, and it describes how fast the machine's AI chip is. For email and tabs and Zoom, it does not matter. What matters is that the number is being inflated. Microsoft's own requirement counts the AI chip alone, but some manufacturers advertise a much larger figure by adding the AI chip, the processor and the graphics together. A laptop marked "90 TOPS" can have an AI chip well under half that. If you care about the number at all, look for the one attached to the NPU specifically. **"AI PC"** means nothing in particular. There is no standard behind it, and Microsoft has said every Windows 11 machine is one. **Wi-Fi 7** only helps if you own a Wi-Fi 7 router. Wi-Fi 6 is fine. **Clock speeds and core counts** are noise once you are at a Core 5 or Ryzen 5\. **A 120Hz screen** is a pleasant thing that will never matter as much as the resolution and brightness of that same screen. **Copilot+ is an interesting one.** The badge means the machine has an AI chip rated at 40 TOPS or better. You will not use it. It runs on-device features like Recall and local image generation, and regular Copilot works on any Windows 11 machine over the internet regardless. But Microsoft does not hand out that badge on the AI chip alone. To carry it, a laptop must also have at least 16GB of memory and 256GB of SSD or UFS storage. Those are the exact numbers this article has been telling you to look for. So the badge you would reasonably ignore turns out to be a shortcut. It cannot tell you the machine is good. It can tell you the machine is not starved, which on a crowded shelf is a good thing to know. Ignore what Copilot+ is selling and use it as a filter. ## What the tag never prints Those four specs get you a machine you like. What follows decides how long you get to keep it, and none of it is on the card. **How long it keeps getting security updates.** Every machine has a date after which it stops being patched, and no store prints it. - **Windows 10:** patched until October 12, 2027, and then it is done. Microsoft added that extra year in June with an edit to a support page rather than an announcement, so plenty of coverage still carries the old 2026 date. - **Windows 11:** anything new on the shelf today is fine, and will be for years. - **Chromebooks:** ten years of updates, counted from when that model was released rather than from when you bought it. A clearance Chromebook can have far less than ten years left. Check before you buy on Google's Auto Update policy page, or on the machine itself under 'Settings' > 'About ChromeOS' > 'Additional details'. - **Macs:** Apple publishes no number. In practice a Mac has gotten somewhere around seven years of macOS updates, plus a couple more years of security-only patches after that. This is the same problem we wrote about with [routers and their expiration dates](https://www.freshfromcache.com/router-expiration-date/): a real deadline that never appears on the box. **S Mode.** Some cheap Windows laptops arrive in "Windows 11 Home in S Mode," which blocks everything except apps from the Microsoft Store. No Chrome. No downloaded programs. There is a real reason it exists. A computer that can only install from the Store is much harder to talk someone into infecting, which is why schools buy machines that way and why it is a defensible setting for a laptop that will only ever do email and video calls. It is also why budget laptops arrive in it, since the maker gets to call the machine secure. Leaving S Mode is free and lives in 'Settings' > 'System' > 'Activation'. It is one-way, though, and it is a startling thing to run into on your first evening with a new computer. The listing rarely says. **Which model you are actually comparing.** HP, Dell and Lenovo build store-exclusive model numbers, so the "same" laptop at Best Buy and at Costco can have a different processor or a different screen. This is also why price-matching so often fails at the counter: the policies want an exact model match, and there isn't one. Consumer Reports has documented the holiday variation on this for years, where a familiar brand and series gets a fresh model number and cheaper parts for the sale. A doorbuster price on a model number you cannot find anywhere else is a red flag. **The extended warranty.** Consumer Reports looked at 36,919 laptops its members bought new. Among the PC owners who paid for extended coverage, 15 percent ever used it for a repair. Among Apple owners, 7 percent did. And for the PC owners who skipped the coverage and later needed work done, the median repair bill was $118, which is three dollars more than the median cost of the coverage itself. Put the money toward 16GB of RAM instead. ## Two options the aisle will not show you **A Chromebook, if your whole day is a browser.** Email, documents, video calls, banking, streaming. If that is genuinely all of it, a $350 Chromebook will feel faster than a $500 Windows laptop. ChromeOS asks for a fraction of what Windows does and there is far less running in the background. The dividing line is clear enough to decide on. If you need a Windows-only program, desktop tax software, a perpetual Office license, or a printer with fussy drivers, buy Windows. If you do not, the Chromebook is the better machine for less money. **A used business laptop.** A three or four year old ThinkPad, Latitude or EliteBook with 16GB of memory and a 512GB SSD sells for roughly what a new bottom-tier consumer machine costs. You get a better keyboard, a sturdier body, and parts that come out with a screwdriver. What you give up is a shorter warranty (often 90 days), a battery with unknown miles on it, and no manufacturer support. Budget fifty to eighty dollars for a battery and check the processor's generation before you buy. ## What this all costs Checked in late August 2026, 16GB of memory with a 512GB SSD, a current processor and a 1080p or better IPS screen is turning up on sale between roughly $590 and $700\. At full list rather than on sale, expect $800 and up. Under $500 you are usually choosing which of the four to give up. Under $300 you are buying 4GB of memory and a 768p screen, and that machine is disappointing on day one. Look at the crossed-out number while you are there. That HP with the Ryzen 5 40 and 8GB was listed at $400, marked down from $780\. The discount is real. The machine is still 8GB with a six-year-old design in it, and a bigger discount does not change either of those. On the Apple side, the numbers moved this summer. The MacBook Air went from $1,099 to $1,299 in June and comes with 16GB. The MacBook Neo starts at $699 with 8GB, and the reviews say it is a good little computer. ## If you were going to buy the cheap one anyway There is a real argument on the other side and it deserves highlighting. Buying a $400 laptop every three years instead of an $800 laptop every six is a legitimate way to handle money, especially if the $800 is not sitting there this month. The five-year math assumes you have the cash today, which is an assumption that doesn't apply to everybody. That argument works fine at $400\. It falls apart at $259\. A machine with 4GB of memory and eMMC storage is not the same laptop with fewer features. It is slow the first week, and no amount of patience will make it better. Whatever you spend, spend it on the four specs instead of the badges. And if the machine you already have is the reason you are shopping, [try the free fixes first](https://www.freshfromcache.com/why-is-my-computer-slow/). A tune-up costs nothing, and the store will still be there next month. ## Sources - [Windows 11 Specs and System Requirements](https://www.microsoft.com/en-us/windows/windows-11-specifications?ref=freshfromcache.com) - [Windows 10 Consumer Extended Security Updates](https://www.microsoft.com/en-us/windows/extended-security-updates?ref=freshfromcache.com) - [Switching out of S mode in Windows](https://support.microsoft.com/en-us/windows/switching-out-of-s-mode-in-windows-4f56d9be-99ec-6983-119f-031bfb28a307?ref=freshfromcache.com) - [ChromeOS Auto Update policy](https://support.google.com/chrome/a/answer/6220366?ref=freshfromcache.com) - [AMD Ryzen 5 7520U product specifications](https://www.amd.com/en/products/processors/laptop/ryzen/7000-series/amd-ryzen-5-7520u.html?ref=freshfromcache.com) - [RAM price tracking 2026, Tom's Hardware](https://www.tomshardware.com/pc-components/ram/ram-price-index-2026-lowest-price-on-ddr5-and-ddr4-memory-of-all-capacities?ref=freshfromcache.com) - [One year into the AI-induced RAM apocalypse, Tom's Hardware](https://www.tomshardware.com/pc-components/ram/one-year-into-the-ai-induced-ram-apocalypse-how-much-does-memory-actually-cost-and-is-there-hope-for-a-more-affordable-future?ref=freshfromcache.com) - [Microsoft quietly extends free Windows 10 ESU support to October 2027, BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-quietly-extends-free-windows-10-esu-support-to-october-2027/?ref=freshfromcache.com) - [Apple announces significant price increases for MacBooks, iPads, more, 9to5Mac](https://9to5mac.com/2026/06/25/apple-price-increases-mac-ipad-more/?ref=freshfromcache.com) - [MacBook Neo guide: price, availability, specs, Macworld](https://www.macworld.com/article/2854313/macbook-neo-design-processor-specs-release.html?ref=freshfromcache.com) - [Windows fans say MacBook Neo's 8GB RAM is ridiculous, so I tested it, Tom's Guide](https://www.tomsguide.com/computing/macbooks/windows-fans-say-macbook-neos-8gb-ram-is-ridiculous-so-i-tested-it-and-the-results-are-shocking?ref=freshfromcache.com) - [Best laptop deals, PCWorld](https://www.pcworld.com/article/550968/best-laptop-deals-3.html?ref=freshfromcache.com) - [Extended warranty for a laptop: should you buy one? Consumer Reports](https://www.consumerreports.org/extended-warranties/extended-warranty-for-laptop-should-you-buy?ref=freshfromcache.com) ### This week: ink with an off switch, and who trains on your posts URL: https://www.freshfromcache.com/newsletter/the-fine-print-was-busy/ Last updated: 2026-08-25T15:00:00.000Z Good morning! Most of this week came down to the same idea. Something is yours, and somebody else has already decided what they are allowed to do with it. **In this issue:** - [Can you stop AI companies from training on what you write?](https://www.freshfromcache.com/stop-ai-training-on-your-writing/) - [What you own when your printer is on a subscription](https://www.freshfromcache.com/printer-ink-subscription/) - [The safety notice that comes with no refund](https://www.freshfromcache.com/what-is-a-cpsc-product-safety-warning/) - [Who is behind your child's GPS watch?](https://www.freshfromcache.com/kids-gps-watch-security/) - [Also this week: an Apple alert, a Comcast deadline, and a teen account nobody asked for](https://www.freshfromcache.com/also-this-week-2026-08-21/) - [The post office already photographs your mail. It will send you the pictures.](https://www.freshfromcache.com/usps-informed-delivery/) - Plus: two scams making the rounds - And the Scary Headline of the week: the router that can tell on you --- [**Can you stop AI companies from training on what you write?**](https://www.freshfromcache.com/stop-ai-training-on-your-writing/) A recipe in a Facebook group, a review you left for your plumber, the newsletter you type up for the neighborhood association. If it was public on the internet, odds are it helped teach an AI system to write. The opt-out settings you have heard about are real, and the piece is plain about their limits. They only work going forward, and they only bind companies that choose to honor them, and one big one got caught not honoring them. Where each setting lives, what changes on September 15, and the one place you have real power. *Learn* --- [**What you own when your printer is on a subscription**](https://www.freshfromcache.com/printer-ink-subscription/) HP's CEO puts Instant Ink at more than 13 million subscribers, and the contract lets HP shut off the cartridge the moment you cancel, ink still inside it. Brother, Canon and Epson write the same idea into their own plans. Some of these printers also stop printing when the internet goes out, and the piece covers what the printer reports back to HP while it sits there. If you want out, there is a way to cancel without ending up with a dead printer, and it is in there. *Learn* --- [**The safety notice that comes with no refund**](https://www.freshfromcache.com/what-is-a-cpsc-product-safety-warning/) A recall is a deal. Stop using the thing, and somebody owes you a refund, a repair or a replacement. There is a second kind of notice where the agency tells you a product can hurt you and nobody owes you anything, and it has grown to one safety notice in five. It falls hardest on the cheap electronics, chargers, power strips and power banks. Four things to check before you buy one, and what to do if you already own one. *Learn* --- [**Who is behind your child's GPS watch?**](https://www.freshfromcache.com/kids-gps-watch-security/) Nobody buys a kids GPS watch carelessly. The purchase is itself an act of caution, and the question that gets skipped at checkout is who else can see the location. Consumer Reports found trackers that skip the second login step, and the cheapest watches run on shared platforms the buyer cannot even name. The piece shows you how to find out what is inside the watch already on your child's wrist, what you can change today, and when replacing it is the right call. *Learn* --- [**Also this week: an Apple alert, a Comcast deadline, and a teen account nobody asked for**](https://www.freshfromcache.com/also-this-week-2026-08-21/) Four stories from the week I did not write a full piece about. Apple warned the people it believes are spyware targets, and shipped a fix the rest of us should install anyway. The Comcast breach claim deadline moved to September 14\. ChatGPT started deciding on its own which of its users are teenagers. And four states are in court arguing Facebook and Instagram were built to hook kids. *News* --- **If you only read one:** [AI training](https://www.freshfromcache.com/stop-ai-training-on-your-writing/). Whatever you have posted publicly is already in the mix, and the article is clear about which levers do anything at all. --- ### 5-Minute Tech Tip [The post office already photographs your mail, and it will send you the pictures](https://www.freshfromcache.com/usps-informed-delivery/), free, by email, every morning it has something for you. Most eligible addresses have never turned it on. Sunday's piece also tells the story of a crew who enrolled as their victims so they would know which morning the new credit cards would be sitting in the mailbox. Enrolling yourself gets you your own record of your mail, and the walkthrough is in the article. --- ### Fresh Trouble **The package you did not order.** A box turns up with your name on it and nothing you bought inside. The seller needs a real delivery in your name so they can post a review as a verified buyer, and that review is the entire point of the package. It also means somebody out there has your name and address. ([FTC](https://consumer.ftc.gov/consumer-alerts/2026/08/unexpected-package-you-got-could-be-brushing-scam?ref=freshfromcache.com)) **Sponsored searches.** You go looking for a company's bill-pay page, and the first thing Google shows you is advertising. Those results sit above the real link with a small Sponsored label on them, and scammers buy those slots to put a look-alike payment page in front of you. Scroll past the sponsored block, or type in the address printed on your bill. ([FTC](https://consumer.ftc.gov/consumer-alerts/2026/08/searching-online-bill-pay-impersonators?ref=freshfromcache.com)) --- ### Scary Headline of the Week *"Xfinity routers are now motion detectors able to report you to the police"* Comcast launched a bundle called Xfinity Shield on August 18, and the part of it that made headlines is WiFi Motion. It turns a leased Xfinity gateway into a motion sensor, it arrived in an app update, and it is now free for every Xfinity Internet customer with an XB7 gateway or newer. No camera and no microphone. The router notices the wifi signal bending around a moving body, keeps a log, and sends your phone a notification. Two things take the edge off. It is opt-in and stays off until you turn it on, so if you do nothing, your router detects nothing. And it does not record video or identify who is moving. However, the underlying claim behind the headline is accurate. Comcast's own documentation says it may hand the motion data to third parties, without telling you, for law enforcement investigations, disputes Comcast is a party to, or a court order. Turn it on and you have created a timestamped record of when somebody was moving around inside your house, held by a company that decides for itself when to share it. **The verdict:** off by default means the risk is a choice. The question to consider before tapping Enable is whether a free motion alert is a fair trade for a record of your household's comings and goings that can be subpoenaed without your knowledge. The feature itself is not new, and I wrote up [how wifi motion sensing works](https://www.freshfromcache.com/wifi-motion-sensing/) back in June. What changed on the 18th is the price, and how many routers now have it. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help: forward this email to one person who might want it, and if it was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. And if you would rather chip in a few dollars, there is a [support page](https://www.freshfromcache.com/support/) now. Thank you for your support! --- Have you already turned on USPS Informed Delivery? How do you like it? Hit reply. Joel ### The GTA VI leak. How big leaks become bait. URL: https://www.freshfromcache.com/gta-6-leak-malware/ Last updated: 2026-08-25T10:59:59.000Z On August 18, two minute-long gameplay clips and a map of Grand Theft Auto VI's Leonida showed up online. A group calling itself CyberLeek claimed them. By the weekend there were eight or nine clips, each one burned with a watermark, a manifesto, and a QR code pointing at a cryptocurrency coin. Take-Two, Rockstar's parent company, started filing copyright takedowns the same day. Two days later, on August 20, it asked a federal court in New York to make Microsoft and Discord hand over the identities of everyone in three Discord servers. By the weekend it had gone after X and Google too. The clips are real. Take-Two's own court filings call them copyrighted material, and in one of them the player sprays the word LEEK into a wall with bullets, which is not something you do with recycled footage. These clips are also getting harder to find by the day, and that is where this story can turn dangerous for the people looking for them. ## Follow the money CyberLeek's manifesto reads like consumer advocacy. No digital-only preorders, no day-one DLC that was already on the disc, an offline mode for single player. The group says it will keep leaking until Rockstar apologizes. The blockchain tells a different order of events. Bitquery, an on-chain analytics firm, traced the group's website to a domain registered August 14 and its Solana token, $CYBERLEEK, to a first trade on August 15\. The footage came three days later, with the coin's QR code in the watermark. Five wallets that bought inside a six-minute window during that first spike took about $158,000 out of it. The coin's high did not come on the night of the leak either. It came on August 23, five days later, and as of Monday evening the token carried a market value around $15 million. The group has since tied its drops to that price, holding one clip back until the coin cleared a number it had named. A coin like this can move fifty percent in a day, so treat any figure as a snapshot rather than a valuation. Stop Killing Games, the consumer campaign the manifesto borrows from, told fans not to send the group money, "no matter how much sympathy you may feel for their actions." ![Timeline: cyberleek domain registered August 14, token first traded August 15, first clips August 18, Take-Two subpoenas August 20, fake 113 GB build reported August 23.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-coin-before-leak-4.png) The order of events, from Bitquery's on-chain dates and the court filings. The coin was trading before anyone had seen a clip. The leak was a sales funnel from the start. What followed it was worse. ## What the takedowns did Take-Two is doing what any copyright holder does with its own stolen work. It files notices, platforms pull the videos, and reposters get strikes. YouTube, X and Telegram have all been hit, and X has suspended the three accounts Take-Two named. CyberLeek's own site and Telegram channel went dark around August 22\. The clips have not stopped coming. There is a ripple effect. The clips did not disappear, they moved. When the easy copies vanish from YouTube and X, the people still looking go to the next layer down. Discord invites, Telegram channels, mirror sites, torrents. NordVPN's chief technology officer, Marijus Briedis, called it "exactly the environment where fake 'leak' downloads and credential-harvesting pages thrive." Scarcity makes people less picky, and the demand here is not normal. This is the game [an entire industry rearranged its release calendar to get out of the way of](https://www.freshfromcache.com/gta-6-empty-november/). A fan who would never click a "free GTA 6 download" ad in June will click a "full leak archive" link in August, because it is the only thing left. ## What was waiting Three new things showed up within days. A 113 gigabyte torrent, named as a CyberLeek "repack" of the full game, started circulating on torrent sites. A user on X who pulled it apart reported that it is almost entirely zeroes, padded to look like a real game install, with a roughly 50 kilobyte program inside. The decompiled code tells Windows Defender to ignore the entire C: drive and then kills security software. Tom's Hardware reported it on August 23\. That analysis comes from a hobbyist, not a security vendor, so treat the exact numbers as a claim. The shape of it is not in doubt. CyberLeek has shown clips, and nothing in the clips or the court filings suggests anyone is handing out the game. ![Diagram of the 113 GB fake ISO: a long dark bar labeled zeroes with a thin rust sliver at the end labeled about 50 KB of program.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-fake-iso-anatomy-4.png) What one X user reported finding inside the torrent, via Tom's Hardware. Still the one claim here no security vendor has published on, and the sliver is drawn far wider than true scale. Fake "leak" websites appeared with the game's name in the domain. Malwarebytes published an analysis of four of them on August 24, and two of them matter here. One poses as a playable demo. The other poses as Rockstar's own Extended Look, the trailer event that streams this Thursday. Both hand you a file called gta6\_installer.exe carrying Vidar, a password stealer that has been around since 2018\. It takes browser cookies and saved logins, Discord and Telegram tokens, and cryptocurrency wallets. An independent researcher who took one of the same domains apart on August 20 found a second trick in the set, the [fake CAPTCHA](https://www.freshfromcache.com/fake-captcha-scam/) box that asks you to paste a command to prove you are human. Neither write-up ties any of this back to CyberLeek. It doesn't have to. The group opened the door and other people walked through it. Impostor accounts multiplied. The three X accounts Take-Two named in its subpoena had already been flagged by fans as fakes, and the group's later clips carried the watermark "CYBERLEEK DOES NOT HAVE TWITTER." Any account offering you the videos is somebody using the name. And the older wave never stopped. Malwarebytes documented "VIP Digital Access" sites in June charging $250, payable only in Bitcoin, USDT or Ethereum, for early access to a game that does not exist yet. McAfee listed fake early access, secret beta downloads and "exclusive" launchers among the top gaming lures on August 12, six days before the leak. The leak gave those sites a fresh coat of paint. ## The playbook is older than this game None of this is new. It is the same sequence every time something people want gets scrubbed. Kaspersky counted more than 19 million attempts to download malware disguised as popular games between April 2024 and March 2025, affecting over 400,000 people. Grand Theft Auto was the most-used disguise at about 4.5 million attempts, ahead of Minecraft and Call of Duty. That was before anyone had seen a frame of GTA VI gameplay. Proofpoint traced Vidar, StealC and Lumma stealers to YouTube videos advertising game cracks in 2024\. The downloads were password-protected archives, which antivirus cannot scan, padded to around 800 megabytes so they looked like real games, with on-screen instructions to turn off Windows Defender first. Many of the videos targeted games popular with kids. Movies work the same way. When The Odyssey hit theaters in July, Malwarebytes found fake torrents and fake "browser issue" pop-ups waiting within hours. [I covered that one here.](https://www.freshfromcache.com/the-odyssey-piracy-scams/) Hogwarts Legacy got fake cracks in 2023\. Cyberpunk 2077 got a fake mobile beta in 2020 that turned out to be ransomware. Game of Thrones topped Kaspersky's list of TV shows used as malware bait in 2018, with fake episode files ending in .avi.exe. The names change. The steps do not. Something people want gets pulled and the hunt for it moves somewhere darker. The first result in the darker place is a file that is not what it says it is. ## If you want to see the clips - **A video is never a download.** The real clips played on X and YouTube like any other video. Anything that arrives as a zip, an ISO, a "player" or an installer is a program, and the program is the point. - **Show file extensions.** In File Explorer, click 'View', then 'Show', then check 'File name extensions'. A "video" ending in .exe gives itself away. - **Treat every CyberLeek account as an impostor.** The group says it has no X account. Nobody selling you a link, an archive or a coin is the source. - **Never paste a command to "verify you are human."** That is the fake CAPTCHA scam, and it is what one of the leak sites was running. - **If you already ran one,** disconnect that computer, change your passwords from a different device starting with email, and check Discord and Steam for sessions you do not recognize. [Here is the order to do it in.](https://www.freshfromcache.com/what-to-do-after-a-scam/) A [password manager](https://www.freshfromcache.com/start-using-a-password-manager/) makes the rebuild a lot faster. ## The limits Neither Rockstar nor Take-Two has made a public statement, though Take-Two has said plenty in court filings. No arrest has been reported and nobody has been identified, so treat the names going around as guesses. The 113 GB torrent is the one piece here still resting on amateur analysis. One person on X took it apart, a lot of outlets repeated it, and no security vendor has published on that file either way. Nobody has published a count of how many people downloaded it. And a clip that came from a video site is still just a video. Watching one will not hurt your computer. Hunting for the copies that got pulled is where it goes wrong. What everyone wants is two days away. Rockstar's Extended Look at GTA VI streams Thursday, August 27, at noon Pacific on Netflix, then at 6 p.m. Pacific on YouTube. There are already fake sites posing as that stream. The real one does not need a zip file. **Sources** [Engadget: GTA VI gameplay leaks, Take-Two issuing DMCA notices (Aug 18, 2026)](https://www.engadget.com/2239548/gta-6-gameplay-leak-august-2026/?ref=freshfromcache.com) · [PC Gamer: CyberLeek manifesto (Aug 18, 2026)](https://www.pcgamer.com/games/grand-theft-auto/grand-theft-auto-6-leaker-says-they-wont-stop-until-rockstar-and-take-two-apologize-for-anti-consumerism-and-make-a-concrete-commitment-to-do-better/?ref=freshfromcache.com) · [Bitquery: on-chain timeline of the $CYBERLEEK token (Aug 21, 2026)](https://bitquery.io/investigations/cyberleek-gta6-leak-coin?ref=freshfromcache.com) · [Kotaku: Stop Killing Games statement on the coin (Aug 19, 2026)](https://kotaku.com/gta-6-leaks-stop-killing-games-skg-cyberleek-meme-coin-2000725806?ref=freshfromcache.com) · [Kotaku: Take-Two subpoenas Microsoft and Discord (Aug 21, 2026)](https://kotaku.com/take-two-subpoenas-microsoft-and-discord-records-related-to-spread-of-gta-6-leaks-2000726633?ref=freshfromcache.com) · [TorrentFreak: subpoenas expanded to X and YouTube, impostor accounts (Aug 2026)](https://torrentfreak.com/take-two-expands-gta-6-leak-hunt-with-dmca-subpoenas/?ref=freshfromcache.com) · [Tom's Hardware: the LEEK wall, evidence of a playable build (Aug 20, 2026)](https://www.tomshardware.com/video-games/catastrophic-gta-vi-leak-is-a-full-working-build-notorious-hacker-cyberleek-taunts-rockstar-games-by-spraying-the-word-leek-onto-a-wall-in-game-with-bullets?ref=freshfromcache.com) · [Tom's Hardware: the 113 GB fake ISO (Aug 23, 2026)](https://www.tomshardware.com/video-games/fake-gta-vi-iso-circulates-on-the-internet-a-few-days-after-leak-internet-sleuths-claim-113gb-download-is-padded-malware-testers-claim-file-is-99-99-percent-empty-zeroes-with-50kb-virus-embedded?ref=freshfromcache.com) · [Game Rant: NordVPN on leak-era malware and the fake build's filename (Aug 22, 2026)](https://gamerant.com/psa-gta-6-malware-first-sightings-warning/?ref=freshfromcache.com) · [devmihaylov: Vidar behind a GTA VI leak site (Aug 20, 2026)](https://medium.com/@devmihaylov/reversing-a-gta-vi-leak-site-infostealer-vidar-behind-a-custom-obfuscator-in-depth-analysis-114fb89269fc?ref=freshfromcache.com) · [Malwarebytes: fake GTA 6 Extended Look and demo sites deliver an infostealer (Aug 24, 2026)](https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer?ref=freshfromcache.com) · [CoinGecko: $CYBERLEEK price and market cap (checked Aug 24, 2026)](https://www.coingecko.com/en/coins/cyberleek?ref=freshfromcache.com) · [Coinspeaker: CYBERLEEK token surge tied to the leak drops (Aug 24, 2026)](https://www.coinspeaker.com/cyberleek-token-trading-surge-gta-6-gas-leak/?ref=freshfromcache.com) · [Malwarebytes: GTA 6 early access is nothing but a scam (Jun 23, 2026)](https://www.malwarebytes.com/blog/threat-intel/2026/06/gta-6-early-access-is-nothing-but-a-scam?ref=freshfromcache.com) · [McAfee: GTA 6 is coming, so are the scams (Aug 12, 2026)](https://www.mcafee.com/blogs/mcafee-news/gta-6-meccha-chameleon-gaming-scams-fall-gaming-releases/?ref=freshfromcache.com) · [Kaspersky: 19 million attacks disguised as games (Jun 9, 2025)](https://www.kaspersky.com/about/press-releases/gen-zs-favorite-games-used-as-bait-in-over-19-million-attempted-cyberattacks?ref=freshfromcache.com) · [Proofpoint: infostealers delivered through YouTube game cracks (Apr 3, 2024)](https://www.proofpoint.com/us/blog/threat-insight/threat-actors-deliver-malware-youtube-video-game-cracks?ref=freshfromcache.com) · [Malwarebytes: fake Hogwarts Legacy cracks (Feb 16, 2023)](https://www.malwarebytes.com/blog/news/2023/02/fake-hogwarts-legacy-cracks-lead-to-adware-scams?ref=freshfromcache.com) · [Kaspersky: fake Cyberpunk 2077 mobile beta ransomware (Dec 23, 2020)](https://www.kaspersky.com/blog/cyberpunk-2077-ransomware/38196/?ref=freshfromcache.com) · [Kaspersky Securelist: Game of Threats, TV shows as malware bait (Apr 1, 2019)](https://securelist.com/game-of-threats/90116/?ref=freshfromcache.com) · [Rockstar Newswire: Grand Theft Auto VI, An Extended Look (Aug 27 stream times)](https://www.rockstargames.com/newswire/article/9k2kaa1o3297k9/grand-theft-auto-vi-an-extended-look?ref=freshfromcache.com) · [Rockstar Newswire: release date November 19, 2026](https://www.rockstargames.com/newswire/article/ak3ak31a49a221/grand-theft-auto-vi-is-now-set-to-launch-november-19-2026?ref=freshfromcache.com) Claims re-verified against the primaries August 24, 2026. ### Who is behind your child's GPS watch? URL: https://www.freshfromcache.com/kids-gps-watch-security/ Last updated: 2026-08-24T10:59:59.000Z Nobody buys a kids GPS watch carelessly. The purchase itself is an act of caution. You wanted to know where your child is without giving them a phone, and the watch is a practical solution. There is a question that many don't think about before checkout. Who else can see my child's location? On the best devices, the people who can see the data are the people you would expect. On the cheapest ones, the buyer usually cannot even name the company holding the data. The good news is that you can find out exactly what is inside the watch already on your child's wrist, and most fixes are at the account level. ## What the watch does Most kids' GPS watches are small phones. There is a SIM card inside. The watch finds itself in three ways: by GPS satellite, nearby cell towers, and Wi-Fi networks. Everything it learns goes to the manufacturer's servers, and the parent app talks to the watch through those same servers. When you tap the map, the request goes to the company's servers, and the server asks the watch. ![A father and daughter sitting on a bed while the child looks at the smartwatch on her wrist](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-bedside.jpg) Photo: Getty Images, Unsplash+ Most watches come with features such as two-way calling, voice messages, an SOS button, alerts when the watch leaves a location zone you set. Many inexpensive models also carry a listen-in feature that opens the microphone remotely, with nothing on the watch to show it happening. Every one of these is sold as a parental tool, and every one of them belongs to whoever has access to the account. Germany's telecom regulator found the listen-in feature alarming enough that it banned children's smartwatches carrying it back in 2017 and told parents to destroy the ones they owned. Nine years later, the feature still appears on inexpensive models. This piece is about the watch itself and the company behind it. How a family shares location with each other is [a separate subject](https://www.freshfromcache.com/what-location-sharing-actually-shares/), and we covered it earlier this month. ## What Consumer Reports found Consumer Reports published testing of 15 popular child-tracking devices in December 2025, looking at how well each company protects sensitive information through encryption, data-sharing policies, and default settings. The finding that stood out was around logins. Four of the devices skip multi-factor authentication entirely: the Cosmo JrTrack 5 Kids Smart Watch, the Life360 Tile Mate, the Tack GPS Tracker, and the Tracki GPS Tracker. With no second login step, a leaked or reused parent password is live access to a child's location. CR inquired with all four companies about it, and the three that answered said MFA is on the way in some form. Encryption came up too. CR researcher Justin Stewart, on the Fitbit Ace LTE: "I was astonished that the Fitbit logged all of the direct messages between the parent app and the child's smartwatch in an unencrypted database." Fitbit responded that the data is encrypted in transit and at rest and that messages are automatically deleted a short time after delivery. That is a valid security standard, but it is not end-to-end encryption. Five of the devices, from AngelSense, Bark, Fitbit, Cosmo, and TickTalk, do not clearly show when the microphone or camera is active. And Stewart was surprised by how many products collect data for advertising. Only two of the 15, the Life360 Tile Mate and the Xplora XG03, offer controls in the app to decline targeted ads. The counterintuitive finding is that products made for children were not the safest ones. CR found that companies governed by stricter global standards, and it names Apple and Samsung, tended to rate higher for privacy and security even when the product was never designed for a child. Devices from Apple, Garmin, and Eufy performed well in the testing, while several watches marketed specifically for kids lagged behind them. These work without giving your child a phone, too. An Apple Watch with cellular can be set up and managed entirely from a parent's iPhone, and the Garmin Bounce runs on LTE and pairs to an app on the parent's phone. ## The brand on the box Consumer Reports tested the apps and the policies. The bigger problem sits a level below that, on the servers the cheapest watches all share. The cheapest watches, the ones sold under dozens of interchangeable names in marketplace listings, mostly do not have their own servers at all. They run on shared platforms built by manufacturers in Shenzhen. The brand on the box is a sticker on another company's system. In August, at the DEF CON 34 security conference in Las Vegas, researchers Felipe Solferini and Vangelis Stykas presented what they found inside three of those platforms. By their own estimate, the platforms serve tens of millions of devices across dozens of brand names, and the largest of the children's watch platforms is called SETracker. WIRED's Andy Greenberg reported on the research and let the pair demonstrate it on a watch he wore himself. They located him, listened through the microphone, and triggered the camera, with nothing showing on the watch. So far WIRED is the only outlet that has reported the findings firsthand, no independent lab has re-tested the watches, and the device counts are the researchers' own figures. The company behind SETracker did respond. Wonlex, the Shenzhen manufacturer that runs the platform, posted a security update on August 10 acknowledging that researchers had presented findings at DEF CON and saying it closed the specific holes at the server level, so nothing needs updating on the watches themselves. That is a better response than silence. It is also a company evaluating itself, with no outside audit published. No case has surfaced of a child harmed through any of these flaws. What the researchers showed is capability, and the capability lives in the account and the platform. Both are things you can check. ## Find out what is inside the watch The single most useful check needs your phone and the watch's companion app. 1. Find the app the watch pairs with. It is named on the box, in the manual, or already sitting on your phone. 2. On Android, open the app's page in the Google Play store and look at the web address. It ends with the app's real internal name. That name tells you whose system you are on. SeTracker2's address ends in com.tgelec.setracker, and the listed developer is SJE LIMITED. 3. If the app is called SeTracker, SeTracker2, or Aibeile, the watch runs on the shared platform from the DEF CON research, alongside dozens of other brands. 4. On an iPhone, read the developer name printed under the app's title in the App Store. 5. Open the app's privacy policy and find who is named as the data controller. That is the company actually holding your child's location. If it matches the brand you bought, you own a product. If it is a company you have never heard of, you own a sticker. ![Google Play listing for SeTracker2 showing the developer name SJE LIMITED and more than ten million downloads](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/shot-play-setracker2.png) The Google Play listing. The developer is SJE LIMITED, a name that appears on no watch box. ![App Store listing for SeTracker2 with the developer name shown in Chinese characters](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/shot-appstore-setracker2.png) The same app in the App Store. The developer name renders in Chinese characters, which is the check doing its own demonstrating. ## What you can change today A few steps you can take, in the order they help: **Turn on multi-factor authentication if the app offers it.** This is the single change that closes off the most realistic problem, which is a password that leaked from some other site years ago. If the app has no MFA option at all, the password becomes the only lock on your child's location, so it needs to be one you use nowhere else. [A password manager](https://www.freshfromcache.com/start-using-a-password-manager/) makes that true without you having to remember anything. **Change any default PINs.** Many of these watches come with a factory admin code and SOS code that most buyers never touch. Set your own. **Take stock of who has the login.** Anyone who has ever had the email and password can see the watch until the password changes, including a former partner from when the account was first set up. Change the password and this is settled. **Look for a security contact.** Search the maker's website for a security page or any way to report a problem. Companies that publish one tend to fix things. If the site has no way to reach anyone about security, that tells you how a problem would go. ## When replacing it is the right call If the check above ends with a shared-platform app, a developer you cannot name, no MFA, and no security contact, replace the watch. Replace it because the account cannot be secured and nobody accountable is holding the data. That is the same problem as [marketplace hardware with no accountable seller](https://www.freshfromcache.com/what-is-a-cpsc-product-safety-warning/), wearing a watch band. When you shop for the replacement, buy on properties instead of brand names: - **Multi-factor authentication:** Ensure it is available. - **A named company:** Look for a published security contact. - **A clear indicator:** Find a clear light or icon when the microphone or camera is on. - **A stated data policy:** Verify how long data is kept. - **Advertising controls:** Ensure there are toggles to decline targeted ads. The brands that tested well are easy to find, and a device that meets those properties is a reasonable pick even if the brand isn't as well known. For most families the realistic risk comes down to an old password still working on an account without proper security controls. The entire point of buying this watch is to worry less. So lock down the account, and let the watch do its job. ### Sources - [Consumer Reports: Should You Track Your Child With a GPS Tracker or Kids Smartwatch? (Dec. 18, 2025)](https://www.consumerreports.org/electronics-computers/child-gps-trackers-wearables/gps-tracker-for-kids-a3099604963/?ref=freshfromcache.com) - [WIRED: Hackers Stalked Me by Hijacking a Smartwatch for Kids (Aug. 7, 2026)](https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/?ref=freshfromcache.com) - [DEF CON 34: Speakers, Tracking the Trackers](https://defcon.org/html/defcon-34/dc-34-speakers.html?ref=freshfromcache.com) - [Wonlex: SETracker Security Update (Aug. 10, 2026)](https://www.iwonlex.net/setracker-security-update-wonlex-s-ongoing-commitment-to-platform-safety/?ref=freshfromcache.com) - [Google Play: SeTracker2 listing](https://play.google.com/store/apps/details?id=com.tgelec.setracker&ref=freshfromcache.com) - [TechCrunch: Germany bans smartwatches for kids over spying concerns (Nov. 17, 2017)](https://techcrunch.com/2017/11/17/germany-bans-smartwatches-for-kids-over-spying-concerns/?ref=freshfromcache.com) - [Apple Support: Set up Apple Watch For Your Kids](https://support.apple.com/guide/watch/set-up-apple-watch-for-your-kids-apd54d0a51fb/watchos?ref=freshfromcache.com) - [Garmin: Bounce 2 Owner's Manual, pairing with a parent's phone](https://www8.garmin.com/manuals/webhelp/GUID-ED045F09-4EC3-41F5-AAAC-42B3A3836894/EN-US/GUID-7A28731E-95F6-4831-9EC0-D17009AEE28C.html?ref=freshfromcache.com) ### The post office already photographs your mail. It will send you the pictures. URL: https://www.freshfromcache.com/usps-informed-delivery/ Last updated: 2026-08-23T10:59:59.000Z Recently I've had construction outside my house. They stopped delivering the mail and I have to drive to the post office to pick it up. If you're like me, you rarely get anything you need to address right away in the mail. The post office has been photographing every letter on its way to you for years now, and it will email you those photos every morning if you ask them to. So the USPS Informed Delivery has helped me decide when it's finally time to go pick up my mail. It is free, it comes from USPS, and by their own accounting only about 37 percent of eligible addresses have it turned on. So most of the country is still walking out to the mailbox. The photos are not something USPS started taking for your benefit. Letters run through automated sorting equipment that images the address side of each one to route it. Those images already exist. Informed Delivery just forwards them to you. ## Turning it on 1. Go to usps.com. Informed Delivery is on the front page under 'Quick Tools', and there is a link for it in the bar across the very top. Already have a USPS.com account? Sign in first, then enroll from your profile instead of starting a new signup. 2. Enter your address. USPS checks two things: whether your ZIP code is eligible, and whether your mailbox is what they call "uniquely coded." Most houses are. Apartments and condos are where this falls apart, because a building that doesn't break out individual units can't be matched to one person. 3. Verify your identity. USPS tries to do this online. If it can't, it will send you to a Post Office that offers Identity Verification Services, and you bring ID with you. 4. Wait a few days. USPS says notifications typically start within three business days. ![The USPS.com home page with a red arrow pointing at the Informed Delivery link under Quick Tools.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-21-165617.png) Informed Delivery sits on the front page of usps.com, under Quick Tools. After that the email arrives on its own. Grayscale photos of the address side of your letters, in color for some things like catalogs and magazines, plus the status of packages coming and going. It has limits. Only letter-size mail that runs through the automated equipment gets photographed, so a padded envelope or anything hand-handled will be delivered unannounced. And one account can only cover two addresses, a home address and a PO Box, not a list of properties. ![The Informed Delivery dashboard showing zero mailpieces and zero packages for the day, with the street address blacked out.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-informed-delivery-dashboard.png) The dashboard on a morning with nothing coming. Mine has been reading zero the whole time the crew has had my mail held at the post office. My address is blacked out here on purpose. ## More than a convenience Somebody else can enroll at your address. That is not a hypothetical. Four men out of Florida bought names, Social Security numbers, birth dates, and addresses off the dark web. They used all of it to open credit cards in those people's names. Then they signed up for Informed Delivery as the victims, with what the Justice Department called "a fraudulent email address created to track the delivery of credit cards to the victims' residential mailboxes." They drove up and down the East Coast pulling the cards out of the boxes on the day they showed up. One of them was sentenced to 25 months and more than $177,000 in restitution. They didn't need to watch the house every day. They just needed to know which morning to be at the mailbox, and they had the email to tell them. Enrolling yourself doesn't lock anyone out of that, because your address is not what gets checked. Your identity is. That crew passed the same verification you would have, because they had bought the answers to it. What enrolling gets you is a second record of your own mail. The photos are taken before delivery. Your mailbox is what happens after. When those two stop matching, the gap itself is information. A letter from your bank in the pictures that never reaches the box. A card you never applied for, photographed on its way to you. Either one tells you something is wrong while you can still do something about it. The same email that told those men when to show up will tell you when something didn't arrive. It works in both directions. Better to be the one holding it. If that scenario makes you uncomfortable, a [credit freeze](https://www.freshfromcache.com/freeze-your-credit/) stops the card from being issued in the first place. USPS also mails a code to the physical address when an account is tied to it. If a letter like that shows up and you have no idea what it is, that code can be used to shut it off. Take it to reg.usps.com/idremove and enter it. The reasons on that form include "Identity theft" and "Unrecognized account," which tells you how often this happens. You get two tries at the code before the form locks you out, so type it carefully. If your mail is being stolen outright, the Postal Inspection Service takes reports at mailtheft.uspis.gov. ## Give it a try Most mornings it's a utility bill and a credit union flyer and you close it. For me right now it answers one question, whether there is any reason to drive over there today. The rest of the time it is building a record of what was supposed to show up. Then one day something in those pictures doesn't make it to the mailbox, and you find out that morning instead of a month later. Did your address turn out to be eligible? I'd like to know how this goes for people in apartments especially, because that is where I expect trouble. joel@freshfromcache.com **Sources** USPS on the service: [Informed Delivery](https://www.usps.com/manage/informed-delivery.htm?ref=freshfromcache.com) (free; grayscale images of the address side; letter-size mail through automated equipment; eligible ZIP code and uniquely coded mailbox; the apartment and condo caveat; notifications typically within three business days) · [Informed Delivery Sign Up Guide](https://www.usps.com/c360/images/informed%5Fdelivery/Informed%20Delivery%20Sign%20Up%20Guide%20Jan%202020.pdf?ref=freshfromcache.com) (enrollment steps and identity verification options) · [USPS Link, one account covers a home address and a PO Box](https://news.usps.com/2020/12/16/here-and-there/?ref=freshfromcache.com) How many people use it: [Informed Delivery Year in Review, July 2025 to June 2026](https://www.usps.com/business/informed-delivery-year-review.pdf?ref=freshfromcache.com) (55.0 million households, 36.9 percent national saturation of eligible delivery points) · [USPS Postal Facts, Informed Delivery customers](https://facts.usps.com/informed-delivery-100000-customers/?ref=freshfromcache.com) The fraud case: [U.S. Department of Justice, District of Massachusetts, guilty plea](https://www.justice.gov/usao-ma/pr/florida-man-pleads-guilty-wire-fraud-conspiracy-based-exploitation-usps-s-informed?ref=freshfromcache.com) · [the sentencing](https://www.justice.gov/usao-ma/pr/florida-man-sentenced-wire-fraud-conspiracy?ref=freshfromcache.com) (25 months and more than $177,000 in restitution, March 26, 2021) Shutting one down and reporting theft: [USPS, Unsubscribe From Informed Delivery](https://reg.usps.com/idremove/?ref=freshfromcache.com) · [U.S. Postal Inspection Service, Report](https://www.uspis.gov/report?ref=freshfromcache.com) Paths and claims verified August 18, 2026\. Screens confirmed against the live site August 22, 2026. ### Can you stop AI companies from training on what you write? URL: https://www.freshfromcache.com/stop-ai-training-on-your-writing/ Last updated: 2026-08-22T10:59:59.000Z This question doesn’t just apply to writers. A recipe posted to a Facebook group. A review you left for your plumber. The newsletter you type up for the neighborhood association. If it was public on the internet, chances are good it helped teach an AI system how to write. The models learned from the public web, and the public web is mostly us. Over the past couple of years, the places where people write have added settings that tell AI companies to leave your words out of it. Every setting is a request that only binds companies choosing to honor it. And none of them are retroactive. What you get is a say over your future writing. With past writings, you have almost none. One disclosure before we start. I use AI tools to help produce parts of this site. That is a different arrangement from the one this article is about. Using a finished tool is one thing. Having your words absorbed into how that tool works is another. You can be fine with one and object to the other. As for this site, it does not block AI crawlers today. I understand why plenty of people do. ## What "trained on" actually means A crawler is an automated program that reads web pages by the millions, no person at the keyboard. AI companies run crawlers to collect text, and training is what happens next. The model does not keep your post as a file it could hand back. Your words get absorbed, along with everyone else’s, into how it writes. That is also why none of this works backward. A file can be deleted. What a model already learned cannot be unlearned. Every control below is about what happens from here on out. ## Where the settings are **If you write on Substack**, the setting is called "Tell AI tools not to train their models on your content." Open your Dashboard, then Settings, then Privacy. Substack says it never trains on your writing itself, so what this control does is pass the request along to everybody else. Substack is also upfront about the limits. Its own help page says the setting "will only apply to AI tools that respect this setting," and warns that blocking training "may limit your publication’s discoverability" in tools that answer with AI. Both caveats are true, and we will come back to the second one. ![The Privacy settings panel in Substack, with the setting 'Tell AI tools not to train their models on your content' and its toggle marked by red arrows](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-20-151729.png) The Substack control, under Dashboard, Settings, Privacy. **If you post on LinkedIn**, the setting is "Use my data for training content creation AI models," under Settings & Privacy, Data privacy, then "Data for Generative AI Improvement." In the US it is on by default, which means LinkedIn has been training on your posts unless you already told it not to. Your private messages are not part of it, which LinkedIn says on the setting screen itself. Turning it off stops future use. Nothing already used gets pulled back. ![LinkedIn's Data for Generative AI Improvement screen, showing the 'Use my data for training content creation AI models' toggle switched on](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/Screenshot-2026-08-20-151945.png) LinkedIn's version, switched on unless you go turn it off. **Facebook and Instagram are the bad news.** Meta trains its AI on public posts, photos, and captions from adult accounts, and in the US there is no off switch. What exists is a form where you can object, which Meta reviews case by case with no promise to say yes. Europeans got an enforceable right to object under their privacy law. US users did not. Finding the form is the hard part, because Meta keeps it several clicks down. Open Settings and privacy, then Privacy Center, then Privacy topics, then AI at Meta. From there you are looking for the detailed information about Meta’s generative AI models, and inside that, the part about privacy and generative AI. The link you want is the one offering to let you submit requests. It asks where you live, your email address, and why you are objecting. The practical move is blunter. Meta trains on public content, so switching your account to private protects what you post from now on. The public posts already collected stay collected. **If you have your own website**, the control is a file called robots.txt. It is a plain text file that sits at yoursite.com/robots.txt and asks named crawlers to stay out. The names to know are GPTBot (OpenAI), ClaudeBot (Anthropic), Google-Extended (Google’s AI training), and CCBot (Common Crawl, a public collection of web pages that many models were built from). Blocking them means adding two lines per crawler to that file, the name and the instruction: ``` User-agent: GPTBot Disallow: / User-agent: ClaudeBot Disallow: / User-agent: Google-Extended Disallow: / User-agent: CCBot Disallow: / ``` The slash means the whole site. If your site already has a robots.txt, add these to the bottom and leave the rest alone. If it does not, this is the whole file. Site builders will do this for you. Squarespace has a "Block known artificial intelligence crawlers" checkbox under Settings, then Crawlers, unchecked by default. WordPress.com has a toggle called "Prevent third-party sharing." And one worry you can cross off. Google states outright that blocking Google-Extended "does not impact a site’s inclusion in Google Search nor is it used as a ranking signal." Telling Google’s AI no does not make your site disappear from Google search results. **Reddit** has no individual setting. Reddit licenses its content to AI companies at the company level, and your comments are part of the deal. ## The honor system, and who got caught breaking it Everything above is advisory. Nothing enforces robots.txt. It works because OpenAI, Anthropic, and Google all publicly commit to honoring it for their training crawlers, and there is independent evidence that at least some of them do. Then there is Perplexity. In August 2025, Cloudflare, the infrastructure company that handles traffic for a large share of the web, published evidence that Perplexity was crawling sites that had blocked it. The report describes Perplexity disguising its crawler as an ordinary Chrome browser and rotating its network addresses to get around blocks. This includes brand-new test sites whose robots.txt said keep out. Cloudflare pulled Perplexity’s verified-bot status. Perplexity denied it and called the report a sales pitch. You can read the evidence yourself and decide. The point survives either way. A request only restrains companies that choose to be restrained. One more wrinkle. The [AI assistants that visit a page because a user asked](https://www.freshfromcache.com/what-is-an-ai-agent/) follow different rules. OpenAI’s own documentation says robots.txt rules "may not apply" when a person triggers the visit, and Perplexity’s says its user-triggered fetcher "generally ignores robots.txt rules." Blocking training and blocking every AI visit are two different projects. There is a harder truth underneath both. For ordinary writing on the web, you cannot find out whether your words were used. No AI company publishes a list of the pages its models learned from, and the lookup tools that exist cover images and pirated books, not your posts. A company can promise to skip your site, and you have no way to audit the promise. The policy is all there is. ## About that $1.5 billion settlement In July a judge gave final approval to Anthropic’s $1.5 billion copyright settlement. But read the fine print before you get hopeful. The settlement covers published books, registered with the US Copyright Office, that Anthropic downloaded from two specific pirated-book collections. About 482,000 books qualified, at roughly $3,000 each, and the window to file a claim closed in March. A blog, a newsletter, a recipe, a review, an Etsy listing: none of it was ever in the case. That money is a payout to book authors whose books were pirated. ## What changes on September 15 You may see headlines next month about AI crawlers getting blocked by default. That is Cloudflare again, changing the default for new customer sites that show ads. Starting September 15, training crawlers will be blocked out of the box on those pages unless the site owner says otherwise. It is a real shift in the plumbing of the web, but it is one company’s product decision, not a law. If your site does not sit behind Cloudflare, nothing about it changes for you. If it does, the AI crawler controls are in your dashboard now. ## The case for leaving all of it alone Blocking has a cost, and Substack named it above. More people find things to read by asking an AI assistant instead of a search engine every month. The big companies run separate crawlers for separate jobs, so blocking training does not pull you out of search. Google is the clearest example of where the line actually falls. The same Google-Extended you would block covers two things: training future Gemini models, and what Google calls grounding, which means handing your page to the model at the moment somebody asks a question. Block it and your site stays in Google Search, which Google says in as many words. You may also stop showing up inside the Gemini answer. Cloudflare names the other half of the problem, that some crawlers do both jobs under one name, and those get judged by the strictest rule you set. So the trade is real, and it is narrower than "you disappear." For a business, or for anyone who writes to be read, staying visible can beat staying out. Choosing that is a defensible call, not a surrender. Some people also make a different argument, that a model reading the public web is doing what any person does when they read a lot and learn to write from it, and that copyright covers the words somebody wrote rather than what a reader took away from them. That view has serious defenders in court. You do not have to settle the debate to manage your own settings. ## What actually helps, in order **Flip the setting where you publish.** Your future writing is the writing you have real say over. If you keep a Substack, a LinkedIn presence, or a website, the controls above cover you in one sitting. **Let the old posts go.** Nothing you do today reaches a decade of public posts already collected. There is no button that pulls your words back out of a model, and anyone selling you one is selling something else. **Save your attention for the next platform.** Before you pour years of writing into a new place, read its AI policy the way you would read a lease. Is training on by default. Is there a setting, or only a form. Does opting out make you harder to find. Whatever you post there lives under whatever you find, so read it before you start writing, not after. None of this recovers what was already taken. What the settings buy you is a say in what happens to the next thing you write. The companies that respect the request are on record now. The ones that do not are getting caught by name. That is more control than writers had two years ago, and it is sitting in your account settings today. ## Sources - [Substack, "How can I block AI from using my Substack publication to train its models?", updated July 8, 2026](https://support.substack.com/hc/en-us/articles/20382615953556) - [LinkedIn, "Data for Generative AI Improvement" (setting screen)](https://www.linkedin.com/help/linkedin/answer/a7538619?ref=freshfromcache.com) - [Malwarebytes, "LinkedIn will use your data to train its AI unless you opt out now", September 2025](https://www.malwarebytes.com/blog/news/2025/09/linkedin-will-use-your-data-to-train-its-ai-unless-you-opt-out-now?ref=freshfromcache.com) - [Meta, Privacy Center](https://www.facebook.com/privacy/center/) - [Norton, "How to opt out of Meta AI", updated July 13, 2026](https://us.norton.com/blog/ai/how-to-opt-out-of-meta-ai?ref=freshfromcache.com) - [OpenAI, "Overview of OpenAI crawlers" (GPTBot; ChatGPT-User "may not apply")](https://developers.openai.com/api/docs/bots?ref=freshfromcache.com) - [Anthropic, "Does Anthropic crawl data from the web?"](https://support.claude.com/en/articles/8896518-does-anthropic-crawl-data-from-the-web-and-how-can-site-owners-block-the-crawler?ref=freshfromcache.com) - [Perplexity, "Perplexity crawlers" (Perplexity-User "generally ignores robots.txt rules")](https://docs.perplexity.ai/guides/bots?ref=freshfromcache.com) - [Google, "Google’s common crawlers" (Google-Extended covers training and grounding)](https://developers.google.com/search/docs/crawling-indexing/google-common-crawlers?ref=freshfromcache.com) - [Cloudflare, "Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives", August 4, 2025](https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/?ref=freshfromcache.com) - [Silicon Republic, "Cloudflare de-lists Perplexity, alleges stealth scraping" (Perplexity’s response)](https://www.siliconrepublic.com/start-ups/cloudflare-de-lists-perplexity-alleges-stealth-scraping?ref=freshfromcache.com) - [Cloudflare, "Your site, your rules", July 1, 2026](https://blog.cloudflare.com/content-independence-day-ai-options/?ref=freshfromcache.com) - [The Authors Guild, "Court Grants Final Approval of $1.5 Billion Anthropic Copyright Settlement", July 2026](https://authorsguild.org/news/court-grants-final-approval-anthropic-copyright-settlement/?ref=freshfromcache.com) - [Anthropic Copyright Settlement site (claim deadline March 30, 2026)](https://www.anthropiccopyrightsettlement.com/?ref=freshfromcache.com) - [Squarespace, "Blocking AI crawlers"](https://support.squarespace.com/hc/en-us/articles/360022347072?ref=freshfromcache.com) - [WordPress.com, "Prevent third-party sharing"](https://wordpress.com/support/privacy-settings/prevent-third-party-sharing/?ref=freshfromcache.com) ### Also this week: an Apple alert, a Comcast deadline, and a teen account nobody asked for URL: https://www.freshfromcache.com/also-this-week-2026-08-21/ Last updated: 2026-08-21T12:38:46.000Z I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week. ## Apple warned the people it thinks are spyware targets, then patched an image bug the rest of us should install On August 13 Apple sent another round of what it calls threat notifications. They go to people Apple believes were "individually targeted by mercenary spyware attacks, likely because of who they are or what they do." Apple told TechCrunch this wave went to users in 110 countries. Apple does not publish per-wave counts on its own support page, where it says only that it has sent these since 2021 and has "notified users in over 150 countries in total." If one of these showed up on your phone, it is not spam and it is not a mistake. Apple tells you to turn on Lockdown Mode, and it points you at the Digital Security Helpline at Access Now, which does rapid-response emergency work for people in that position. Most people will never get one. Everybody else has a smaller job. On August 17 Apple shipped iOS 26.6.1 and iPadOS 26.6.1, along with iOS 18.7.10 and iPadOS 18.7.10 for older hardware, and a Safari update for Macs the day after. The iOS 26.6.1 notes include an image-processing bug where, in Apple's own wording, "processing an image may lead to arbitrary code execution." The notes for the older release carry a comparable one. Apple did not say anybody had used either, and neither page carries the language Apple uses when a flaw has been exploited. Install it anyway. Settings, then General, then Software Update. That 18.7.10 release covers the iPhone XS, XS Max, XR and the 7th-generation iPad, so a phone from 2018 got patched too. Scammers will imitate these, and fake "your Apple device is infected" texts and pop-ups are already permanent furniture, so here is how to tell a genuine one. It shows on your Lock Screen and in Settings, in an email from threat-notifications@email.apple.com to the address on your Apple Account, and as a banner on your account page. Apple says the alert on the phone itself is new this year and that what you get can vary by device. A real notification does ask you to do things, like turning on Lockdown Mode, so "it told me to take action" is not how you spot a fake. The tell is what it never asks for. It will not ask you to click a link, open a file, install an app or a profile, or hand over your Apple Account password or a verification code by email or over the phone. Apple's own instruction for checking is to sign in at account.apple.com, where a real one sits at the top of the page. If something gets you anyway, [there is an order to work through in the first hour](https://www.freshfromcache.com/what-to-do-after-a-scam/). Sources: [Apple threat notifications](https://support.apple.com/en-us/102174?ref=freshfromcache.com) and [Apple security releases](https://support.apple.com/en-us/100100?ref=freshfromcache.com) ## Comcast is paying $117.5 million over the Xfinity breach, and the claim deadline moved This is narrower than the coverage makes it sound. You are in it if you live in the United States and Comcast sent you a notice, on or around December 18, 2023, about the breach that ran from October 16 to 19 that year. Having Xfinity service at the time is not the test. A few groups are carved out, including Comcast employees, anyone who opted out by July 1, and anyone who already took the breach to arbitration. If you got that notice, look at the date again, because the court moved it. Plenty of stories still print August 14\. In May the judge pushed the claims deadline to September 14, 2026\. If you saw the old date and figured you had missed your shot, you have not. You can claim documented out-of-pocket losses you can tie to the breach, counting from October 16, 2023, plus lost time at $30 an hour for up to five hours, capped at $10,000 for the two together. If you have nothing to document, there is an alternative cash payment estimated at $50\. Filing with receipts does not cost you that $50 either, because the settlement pays whichever is greater. All of it gets adjusted up or down depending on how many people file. Identity defense and restoration services need no claim form, but they are not automatic. Your notice carried an enrollment code and you have to use it, and none of it starts until the settlement is final. On timing, settle in. The court held its final approval hearing on August 5, and this week Judge John Younge approved the deal, cutting the lawyers' fee request from $39 million to $31.7 million. The settlement site has not caught up, so do not go by what it says. Money still does not move until the appeal window runs out. One website is the real one, comcastbreachsettlement.com, run by Kroll Settlement Administration at 1-833-319-2401\. Filing is free, so treat anyone who asks you for a fee to release your money as a thief. And if the notice you are thinking of came from a debt collector called FBCS in 2024, that is a different breach and it is not this settlement. Source: [Comcast Data Breach Settlement](https://www.comcastbreachsettlement.com/?ref=freshfromcache.com) ## ChatGPT started deciding which of its users are teenagers On August 18 OpenAI began rolling out ChatGPT for Teens. Accounts it believes belong to somebody under 18 get moved into it, and nobody has to ask for it. OpenAI assigns it from "account-provided age information, verified age, or age prediction." That last one is the company guessing, from the way an account behaves, that the person typing is a teen. The guess runs on things like the topics that come up, the time of day the account gets used, and how long it has existed. A teen account gets: - age-appropriate content safeguards - Study mode, with hints and step-by-step guidance, plus quizzes and homework reminders - reminders to take a break, and reminders that it is an AI tool - a nudge, before some image uploads, telling the teen to check for sensitive information first A parent can send their teen an invite to link accounts, and the teen has to accept it. Once linked you can set Study hours, which make new chats start in study mode, and Quiet hours, which limit access at set times. Keep those straight, because the names invite the wrong guess. Quiet hours is the one that shuts it off. Study hours only changes the mode. Linking does not let you read anything. OpenAI's line is that "parental controls do not let a parent or guardian read or monitor the teen's conversations." What it does do is tell you if the company's reviewers see signs of acute distress, by email, text and push notification unless you opt out, and that alert carries no transcript. Either of you can unlink whenever you want, and if your teen does it, you get told. So the thing to actually do is send the invite. If your kid set their account up years ago with whatever birth year got them past the door, the age guess may or may not catch that, and the guess is the one part of this you have no say in. Linking is the part you do. One warning if you go poking around in the settings yourself: leave the "Verify age" button alone. That flow exists to take teen protections off, not to check them. And if you are not sure what your kid is actually talking to, [we wrote that up](https://www.freshfromcache.com/what-is-an-ai-agent/). Source: [OpenAI Help Center](https://help.openai.com/en/articles/12652064-age-prediction-in-chatgpt?ref=freshfromcache.com) ## Four states are in court arguing Facebook and Instagram were built to hook kids Opening statements were Tuesday in Oakland and testimony is underway. California, Colorado, Kentucky and New Jersey are trying the case in federal court in front of US District Judge Yvonne Gonzalez Rogers, as the test run for a coalition of 29 state attorneys general whose case goes back to 2023\. The states say the products were built to keep young people using them, and they name the like button, infinite scroll and the recommendation algorithms they say "encourage compulsive use." They also say Meta knowingly took data from children under 13 without a parent's consent, which federal privacy law forbids. The trillion-dollar number in the headlines is Meta's arithmetic, not the states'. Meta says the theory could expose it to as much as $1.4 trillion if every alleged violation drew the maximum penalty. California's own lawyer put it at $193 billion in her opening. Neither is a ruling. In a statement, Meta said the attorneys general "offer no proof anyone in their states was misled." File one thing away for October. A jury is hearing this, but only in an advisory role. Gonzalez Rogers decides liability and any penalty herself. Source: [NPR](https://www.npr.org/2026/08/18/nx-s1-5935458/meta-child-safety-social-media-addiction-trial-opening?ref=freshfromcache.com) That's the week. If you are new here, [Start Here](https://www.freshfromcache.com/start-here/) collects the pieces worth reading first, and [the Tuesday email](https://www.freshfromcache.com/newsletter/) carries the whole week in one place. ### What is a CPSC product safety warning? URL: https://www.freshfromcache.com/what-is-a-cpsc-product-safety-warning/ Last updated: 2026-08-20T10:59:59.000Z On the last day of March, the Consumer Product Safety Commission told Americans to stop using eight different extension cords. Eight warnings in one day. All eight were a cord with a standard wall plug on both ends, sold for feeding generator power into a house through an outlet. The prongs on the loose end go live the moment the other end is plugged in. The agency's acting chairman called them "suicide cords" and said they have "no legitimate household use." Not one of those eight notices came with a refund, a repair, or a replacement. A product safety warning is different from a recall, and it has grown from a rounding error to about a fifth of everything CPSC publishes. If you buy cheap electronics online, as we probably all have, this is the notice you are most likely to get. So it pays to know what it is, why it comes empty-handed, and what you can check before the purchase instead of after. ## A recall is a deal The safety notice most of us picture is a recall. A recall has a company on the other end. Under the law, CPSC almost never orders one outright. It negotiates. The manufacturer, importer, or retailer agrees to a corrective plan, and that agreement is what puts the "contact us for a full refund" line in the notice. The remedy exists because a company signed up to provide it. ![CPSC recall notice for A2batt EEMB lithium coin battery chargers, showing a Remedy section offering a full refund and an orange Consumer Contact box with an email address and website.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-recall-a2batt.png) A recall for a different charger. Same agency, same kind of notice, but there is a Remedy section and a Consumer Contact box, because a company agreed to provide one. A product safety warning is what happens when there is nobody to negotiate with. The agency has the authority to publish what it knows about a dangerous product without the company's cooperation. A warning can tell you the gadget in your kitchen drawer might burn your house down, but it cannot force anyone to pay you back. Here is what that looks like on a real product. In October 2024 the agency warned about Garberiel lithium-ion battery chargers, made by Jisell Inc. of China and sold on Amazon and Newegg since 2019\. Six fires. One of them killed a 74-year-old in Shreveport, Louisiana. The chargers went for ten to eighteen dollars. The fatal fire was in December 2019, and the warning came out in October 2024. The entire remedy in that notice is one sentence. "CPSC urges consumers to immediately unplug the charger and dispose of it." No refund, no replacement, and no phone number to call, because there is nobody on the other end to answer it. ![CPSC product safety warning for Garberiel lithium-ion battery chargers, dated October 10, 2024, listing the hazard and a consumer action of unplug and dispose. No remedy or consumer contact section appears.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-warning-garberiel.png) A warning. Hazard, consumer action, date. There is no Remedy line and no Consumer Contact box, because there is nobody on the other end to provide one. It is not an unusual notice. NEWDERY power banks drew nine reports of fires, including one that did $2 million in damage, and the importer "has refused to conduct a recall." Yiisonger power banks, about 93,000 of them, drew 79 reports including a $15 million fire, and that company "has been unresponsive to CPSC requests." Stop using it, throw it away, eat the cost. That is the whole notice. When the seller does pick up the phone, the same product can change lanes. CPSC warned about CCCEI power strips in March because the retailer "has not agreed to an acceptable recall." Three weeks later it had agreed, and the warning became a recall with a refund. Same power strip with the same hazard. The difference between the two notices came down to whether the company answered when the government called. ## One notice in five In 2021, CPSC published 219 recalls and five warnings. In 2025, there were 420 recalls and 120 warnings, and so far this year, it's about the same rate. Warnings went from around 2 percent of the agency's safety notices to around 22 percent in four years. Those counts come from CPSC's own recall and warning files. Looking at the recall column, it went up too. 2025 was the biggest year for recalls since 2007\. Warnings are not replacing recalls. They are a second lane, built for products that the recall system cannot reach. Which products those are is not subtle. Of the 215 warnings issued since the start of 2025, 178 list China as where the product was made. About three in four name Amazon among the places it sold. That looks like a China story, but it is jurisdictional. The recall law reaches manufacturers, distributors, and retailers. Meaning someone with a US presence and something to lose. A storefront name on a marketplace, shipping direct from a warehouse overseas, is none of those things. There is no one to order, no one to fine, and nothing to seize. ## The Amazon fight There is a live attempt to fix part of the problem. In July 2024, CPSC ruled that Amazon legally counts as a distributor of the third-party products it warehouses and ships through Fulfillment by Amazon. The order that followed in January 2025 requires Amazon to email everyone who bought some 400,000 hazardous items (carbon monoxide detectors that fail to detect, hair dryers with no shock protection, children's sleepwear that violates flammability rules), to put notices on each buyer's 'Your Orders' page, and to refund people who show proof they destroyed or threw out the product. Nothing gets mailed back. The point is getting the hazard out of circulation, not restocking it. Amazon is suing to undo the order. It says it is a logistics provider, not a distributor, and it says it already notified and refunded those buyers on its own. As I write this, there has been no ruling and no settlement. That fight also does not touch the rest of it. When you buy from Temu, Shein, TikTok Shop, or AliExpress and the package comes to your door straight from overseas, no US company ever owns the product. Even if CPSC wins outright against Amazon, none of those purchases are covered. ## Notification A recalled car gets you a letter in the mail, because registration ties your name to the vehicle. Consumer products have no equivalent. The registration cards that come in the box are required by law only for durable baby gear like cribs, high chairs, and play yards. The other marks a gadget carries, an FCC ID or a safety-lab logo, certify the design. They do not register the buyer. No charger, power bank, cord, or power strip comes with a required registration card. So for a direct-shipped purchase, there is no list anywhere connecting you to the product. The notification plan, in full, is that you happen to see the news. You can improve your own odds by signing up for CPSC's email alerts at cpsc.gov, and that is about it. ## Four things to check before you buy - **Learn the visible tell for the product you are buying, when it has one.** A few product types have a required safety feature you can spot in the listing photo. Hair dryers are the clearest case. The block on the plug is immersion protection, and federal rule 16 CFR 1120.3 makes a handheld hair dryer without it illegal to sell in the US. No block, no purchase. Chargers and power banks have no visible tell like that, which is what the next three checks are for. - **Check the safety mark against the directory, not the sticker.** Most legitimate electronics carry a UL or ETL mark. Those are the logos of the two big US safety-testing labs, and they mean a sample of the product passed testing to US safety standards. Counterfeiters print the logos anyway. A real certification has a file number you can look up at UL Product iQ (productiq.ulprospector.com) or Intertek's ETL directory. A listing there proves a certification exists for that model. Finding nothing may mean it's counterfeit. - **Read the seller's address, not just the name.** A federal law called the INFORM Consumers Act has required this since 2023\. Any marketplace seller doing $20,000 or more a year has to show a name, a physical address, and some way to reach them. On Amazon it sits at the bottom of the seller's page under 'Detailed Seller Information'. I went looking for a listing that showed nothing at all and could not find one, so the question is not whether the address is there. It is what the address says. The last line is the country. I found a $9.68 wall charger sold by a company in Hong Kong, another seller whose address is printed only in Chinese characters, and a Temu store in Shenzhen whose only contact is the app's chat window. All three follow the law. None of them is a company anyone here can make answer for anything. Anker's listing gives a California address and a toll-free number a person picks up. That is the same difference that decides whether a bad product gets a recall or a warning. - **Search the brand and model at cpsc.gov.** Recalls and warnings are both found there, and SaferProducts.gov holds incident reports from other owners. A hit means you should probably walk away. A clean search is not a confirmation though, since most of these products are never tested. It just proves nobody has been caught yet. ![Amazon seller page for a $9.68 wall charger, showing Detailed Seller Information with a Hong Kong business address ending in the country code HK.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-seller-hongkong.png) The law works. A $9.68 charger, and the seller is disclosed exactly as required. The line that matters is the last one. ![Amazon seller page for AnkerDirect, showing a US customer service phone number, a 30-day money-back guarantee and an 18-month warranty.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-seller-anker.png) The same disclosure on a company with a US presence, including a phone number a person picks up. ## If you already own one Search the product you are wondering about the same way. If it turns up in a warning, stop using it. The refund is not coming. Get the money back only if the purchase is recent enough for the marketplace's own return window, but do not count on it. Dispose of anything with a lithium battery at household hazardous waste, not in the trash or the recycling bin, where crushed batteries start fires. And if the product ever misbehaved, file a report at SaferProducts.gov. The NEWDERY and Yiisonger warnings both started as consumer reports. ## Making a case for the agency It would be easy to read all of this as a regulator failing, but that is not what the numbers show. Recalls went up too, and 2025 was the biggest year for them since 2007\. A negotiated recall takes months and a contested one takes years, while a warning goes out in days. And the remedy being mourned is one that is hardly used. CPSC's own workshop data puts recall participation around 6 percent of affected products overall, and near 4 percent for products under $20\. On a ten dollar charger, roughly 24 buyers out of 25 never claim the refund even when there is one. A warning the press spreads the same week may protect more people than that refund ever would. The agency is also using tools it hasn't for decades. In July, CPSC went to federal court under its imminent-hazard authority for the first time since 1987, over Lakkzoom immersion water heaters. About 98,000 sold, 235 fire reports, both companies in China. The suit asks a judge to order a recall that nobody agreed to. No decision yet. That power was there the whole time. Nobody reached for it. CPSC has proposed a mandatory safety standard for the lithium-ion batteries in e-bikes, scooters, and hoverboards. These products are behind 39 deaths in the agency's own 2019 to 2023 incident count. Public comments close August 24\. That rule covers e-bikes, and it often gets conflated with phone chargers. But they are different problems. There is no equivalent count for chargers and power banks. Deaths like the one in Shreveport turn up one at a time, inside individual notices, and nobody adds them together. ## A refund tells a story When a safety notice comes with your money back, that means somebody in this country is answering for the product. When it comes with nothing, nobody is. The best time to find that out is before the purchase. So run the seller check on the next cheap charger you buy. Scroll to the bottom of the seller's page and read the last line of the address. That one line tells you whether anybody in this country is on the hook for what shows up at your door. Now I am curious about the other end of this. Have you ever actually sent a recalled product back, or claimed one of those refunds? I never have. If you did, I want to hear how it went. **Sources** The counts, pulled and totalled for this piece on August 18, 2026: [CPSC's product safety warning listing](https://www.cpsc.gov/s3fs-public/recall-data/product%5Fsafety%5Fwarning%5Flisting.csv?ref=freshfromcache.com) and [CPSC's recall data](https://www.saferproducts.gov/RestWebServices/Recall?format=json&ref=freshfromcache.com). Recall totals were counted for every year back to 2007, which is where the "biggest year since 2007" line comes from. The chargers: warning 25-004 (Garberiel, October 10, 2024) carries the Jisell attribution, the six incidents, the death in Shreveport and the price bands. The refusal and unresponsive language comes from warnings 25-327 (NEWDERY) and 25-270 (Yiisonger). CCCEI was warning 26-313 on March 5, 2026 and became recall 26-346 three weeks later. The extension cords: [CPSC, March 31, 2026](https://www.cpsc.gov/Newsroom/News-Releases/2026/CPSC-Warns-Consumers-to-Stop-Using-Male-to-Male-Extension-Cords-Secures-Delisting-Commitments-from-e-Commerce-Platforms?ref=freshfromcache.com) Amazon: [CPSC final order, January 17, 2025](https://www.cpsc.gov/Newsroom/News-Releases/2025/CPSC-Issues-Final-Order-to-Amazon-com-Outlining-Remediation-Plans-for-Hazardous-Products?ref=freshfromcache.com) · [Amazon.com, Inc. v. CPSC, the complaint](https://advocacy.consumerreports.org/wp-content/uploads/2025/03/Amazon-CPSC-lawsuit.pdf?ref=freshfromcache.com) The water heaters: [CPSC, July 22, 2026](https://www.cpsc.gov/Newsroom/News-Releases/2026/CPSC-Exercises-Section-12-Imminent-Hazard-Authority-for-First-Time-in-Nearly-40-Years-Warns-Consumers-to-Stop-Using-Lakkzoom-Immersion-Water-Heaters?ref=freshfromcache.com) · [the Justice Department on the complaint](https://www.justice.gov/opa/pr/justice-department-files-complaint-against-manufacturer-and-retailer-allegedly-imminently?ref=freshfromcache.com) The rules and the numbers: [16 CFR 1120.3, hair dryers and immersion protection](https://www.ecfr.gov/current/title-16/chapter-II/subchapter-B/part-1120/section-1120.3?ref=freshfromcache.com) · [FTC guidance on the INFORM Consumers Act](https://www.ftc.gov/business-guidance/resources/informing-businesses-about-inform-consumers-act?ref=freshfromcache.com) and [the statute itself](https://www.law.cornell.edu/uscode/text/15/45f?ref=freshfromcache.com) · [the recall participation figures, from CPSC's 2017 workshop](https://www.commerce.senate.gov/press/dem/release/chair-cantwell-calls-on-cpsc-to-improve-its-hazardous-toy-recall-system-as-holiday-shopping-heats-up-2021-11/?ref=freshfromcache.com) · [the lithium-ion battery proposal, comments close August 24, 2026](https://www.federalregister.gov/documents/2026/06/24/2026-12749/safety-standard-for-lithium-ion-batteries-in-micromobility-products?ref=freshfromcache.com) Where to run the checks: [CPSC recalls and warnings](https://www.cpsc.gov/Recalls?ref=freshfromcache.com) · [SaferProducts.gov](https://www.saferproducts.gov/?ref=freshfromcache.com) · [UL Product iQ](https://productiq.ulprospector.com/?ref=freshfromcache.com) · [Intertek ETL directory](https://www.intertek.com/directories/etl-listed-mark/?ref=freshfromcache.com) ### What you own when your printer is on a subscription URL: https://www.freshfromcache.com/printer-ink-subscription/ Last updated: 2026-08-19T10:59:59.000Z Most new home printers are sold with a subscription attached, and the subscription rewrites what you actually own. HP's is the biggest. Its CEO put Instant Ink at more than 13 million subscribers. Cancel Instant Ink and HP remotely shuts off the cartridge it sent you, along with whatever ink is left in it. The contract is HP's Instant Ink terms. "When Your Service is cancelled for any reason, HP will remotely disable the Subscription Cartridges and You will no longer be able to print with the Subscription Cartridges." The ink is still in there. You just don't own it. ## Two plans, two deals ![A comparison table of three ways to run a home printer. On HP Instant Ink the printer is yours but the cartridges are HP's. On the HP All-In Plan neither is yours. Cartridges bought off the shelf are yours. Cancelling switches off the Instant Ink cartridge and requires returning everything on the All-In Plan, and on both plans an offline printer stops while the billing carries on.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-what-you-own-v2.png) HP sells home printing two ways now, and they use the same app. Instant Ink is the older one, the ink-only subscription. You buy the printer, and the printer is yours. The cartridges that arrive in the mail are not. The terms say HP "retains all ownership rights and interests in the Subscription Cartridges." You are paying for pages, not ink. A page with anything printed on it counts as a page, and printing both sides counts as two. The All-In Plan goes further. The printer arrives in the mail and it is not yours either, not after two years of payments and not even if you pay the fee to leave early. The terms HP updated on July 31, 2026 say it in capital letters, that you "DO NOT own" the printer or the cartridges. Cancel and you have ten days from the printed return label to mail everything back. Miss the window, or never send it back at all, and your card is charged an Unreturned Printer Fee that runs $120 to $345 depending on the model. That fee is a penalty, and it is the contract's whole answer to keeping the printer. "The payment of an Early Cancellation Fee or Unreturned Printer Fee shall not result in a sale of, or the transfer of title to, any Printer or Subscription Cartridges provided as part of the Services." To HP's credit, none of this hides in the fine print alone. The All-In Plan FAQ says it in a sentence anyone can read. "HP owns the printer, printer cartridges and ink bottles throughout the subscription, and they must be returned to HP upon printer upgrade or cancellation." They do tell you. ## It stops printing when the internet goes out Both plans require the printer to stay online, and the connection is how HP confirms you are still paying. On Instant Ink, a printer that loses its connection has its subscription cartridges disabled. The terms are also clear that you "will continue to be charged for the Service." Reconnect and keep it connected, and the cartridges come back. The All-In terms have the same idea with softer language, you "may not be able" to print, and the billing continues either way. If your internet drops for days at a time, a printer on your desk, with ink in the cartridge and paper in the tray, will not print until it can reach HP. You are billed anyway. ## What the printer tells HP A subscription printer reports home. The Instant Ink terms list what HP may collect: - page counts - ink levels - the printer's serial number and cartridge details - "types of documents printed," with Word, PowerPoint, PDF and JPEG given as the examples So HP can see that you printed a PDF. It cannot read the PDF. HP support says the same when asked, and the terms match. Knowing how much you print, when, and in what file format is still a detailed picture of a machine in your house. ## The court order that has mostly expired ![A tabby cat lying on top of a white HP laser printer on a wooden shelf](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-cat.jpg) Photo: Quan Jing via Unsplash The reason HP printers have a reputation has a name, Dynamic Security. Since 2016, HP printers have checked cartridges for an HP chip and can reject one without it. HP can deliver that check to a printer already in your house through a firmware update. A cartridge that printed fine the day before can be refused the next. That produced two settlements. In 2019 HP paid $1.5 million and agreed not to reactivate Dynamic Security on a list of OfficeJet models. In 2025 it settled a second case covering a list of LaserJet Pro models. That deal paid class members nothing. What HP agreed to was choice. When a firmware update carrying Dynamic Security shows up, the user gets to install it or decline it. You still see that repeated as advice, that HP has to let you decline the update. For most of those printers the court order behind it has expired. The commitment ran one year from the settlement taking effect, which happened around April 2025\. So the guarantee lapsed around April 2026\. Four models, the Color LaserJet Pro M254DW, M180NW, M281FDW and M281CDW, keep it until about April 2027\. And every printer in the case is a laser printer. If you own an inkjet, the settlement never covered you at all. The decline control itself has not gone anywhere. HP Smart still lets you turn off automatic firmware updates, and HP still posts opt-out firmware for some listed models. What ended is the court order requiring it. Declining has a cost, though. HP packages the cartridge lock into the same updates as its fixes, so skipping an update to keep a cheap cartridge working also skips whatever else came along with it. That bundling is HP's choice. ## HP is not alone ![A white laser multifunction printer on a credenza against a grey fluted wall](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-credenza.jpg) Photo: Engin Akyurt via Unsplash Brother sells the same subscription. Its Refresh terms say that on cancellation "all Refresh Subscription Cartridges will cease to function" and "any ink remaining in those cartridges will be forfeited." Forfeited is the contract's own word for ink you already paid the monthly fee to receive. Canon writes it down too. The PIXMA Print Plan terms say the subscription cartridges "will only work in your PIXMA Print Plan Printer while you maintain a current subscription for the Service." Canon's offline rule is stricter than HP's. Disconnect the printer from the internet and it "will automatically stop printing" after a limited number of pages. Epson's ReadyPrint is a printer rental, so cancellation reaches the whole machine. Its own FAQ answers whether you can keep using the printer after canceling with one word, no. "The printer must be returned per the terms of the Epson ReadyPrint subscription agreement." Every major consumer printer brand now sells a plan where the ink, or the printer itself, stops with the payments. ## How to cancel without a dead printer ![An HP 63 tri-color ink cartridge seated in a printer's magenta cradle, the number 63 printed on its label](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-hp63-cartridge.jpg) The number you need is printed on the cartridge, and again on the label inside the printer. Photo: Joel Folgner Most people find out what canceling means the day the printer stops, with nothing on hand to swap in. The order matters more than the decision. 1. Buy replacement cartridges before you touch the subscription, and have them in hand. Match the cartridge number your printer already takes, printed on the cartridge door, so a retail 63 goes where a subscription 63 was. On an HP+ printer, only Original HP cartridges work; HP's own page lists Original HP ink as "required to operate." On any other HP printer, third-party cartridges are an option too. 2. Leave the printer connected until the cancellation goes through. Unplugging it early disables the subscription cartridges while the billing keeps running. 3. Cancel. On Instant Ink it takes effect at the end of your current billing month, and the subscription cartridges are switched off at that point, whatever is left in them. 4. When they stop, swap in the cartridges you bought. 5. On the All-In Plan, the printer and every cartridge go back in the box within ten days of the return label. That part is not optional. The Unreturned Printer Fee is how they make sure. Instant Ink's terms ask for the used cartridges back for recycling in one section and say "must return" in another. A disabled cartridge is no use to you anyway, so send it back for recycling. And if the printer misbehaves after the swap, we have [four steps for that](https://www.freshfromcache.com/four-steps-to-fix-your-printer/). ## The printers that are yours ![The HP Ink Tank 315 name badge on the front of a black printer](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-tank.jpg) Photo: Mahen Rin via Unsplash If the model itself bothers you, the alternatives are different types, not brands. A tank printer, the kind with built-in reservoirs you refill from bottles, costs more up front and prints for far less per page. Everything in it belongs to you. The catch is idleness. Inkjet printheads clog when a printer sits unused, and the cleaning cycles that fix it use up ink. A monochrome laser fits the household that prints documents, forms, schoolwork, etc. Toner does not dry out, and at any real volume black-and-white pages get cheap. It will not print the vacation photos though. Third-party cartridges stay the cheapest consumable, with the Dynamic Security caveat above on HP models. Federal warranty law does not let a manufacturer void your warranty just for using them. And the fourth option is no printer at all. If you print a handful of pages a month, the library and the shipping store are great options. ## The bottom line We wrote in July about [movies and games that turn out to be licenses](https://www.freshfromcache.com/do-you-own-what-you-buy/). At least with a streamed movie, some part of you knew you were renting. A cartridge with ink in it, inside a printer on your own desk, does not feel like it should belong to anyone else. The contract says otherwise. So if you are on one of these plans and want out, be sure to leave in the right order. Buy the replacement cartridges, then cancel. **Sources** HP contracts: [Instant Ink Terms of Service (last updated April 15, 2025)](https://instantink.hpconnected.com/us/en/terms?ref=freshfromcache.com) · [HP All-In Plan for Print Terms of Services (last updated July 31, 2026)](https://www.hp.com/us-en/all-in-plan/terms.html?ref=freshfromcache.com) · [HP All-In Plan FAQ](https://www.hp.com/us-en/all-in-plan/faq.html?ref=freshfromcache.com) · [HP+ requirements](https://www.hp.com/us-en/printers/hp-plus.html?ref=freshfromcache.com) The firmware settlement: [Settlement Agreement and Release, Mobile Emergency Housing Corp. v. HP Inc.](https://kaas.hpcloud.hp.com/pdf-public/pdf%5F11800576%5Fen-US-1.pdf?ref=freshfromcache.com) · [Final Order and Judgment (March 18, 2025)](https://cdn.arstechnica.net/wp-content/uploads/2025/03/settlement.pdf?ref=freshfromcache.com) · [The Register on the settlement](https://www.theregister.com/2025/03/19/hp%5Fprinter%5Flawsuit%5Fsettled/?ref=freshfromcache.com) The other manufacturers: [Brother Refresh Subscription Terms of Use](https://refresh.brother-usa.com/TermsOfUse?ref=freshfromcache.com) · [Canon PIXMA Print Plan Terms and Conditions](https://www.usa.canon.com/ink-paper-toner/printer-ink-subscription-plans/pixma-print-plan/pixma-print-plan-terms-and-conditions?ref=freshfromcache.com) · [Epson ReadyPrint FAQ on canceling](https://epson.com/faq/SPT%5FREADYPRINT~faq-0000cb0-readyprint?ref=freshfromcache.com) Subscriber count: [HP CEO Enrique Lores on Instant Ink subscribers, via The Register](https://www.theregister.com/2024/03/07/hp%5Fink%5Faddicts/?ref=freshfromcache.com) ### This week: $68 million from Google, and free antivirus URL: https://www.freshfromcache.com/newsletter/what-you-already-own/ Last updated: 2026-08-18T15:00:00.000Z Good morning! Something you already own does the job, and somebody is trying to charge you for it anyway. That is most of this week. One thing has a deadline on it, and a couple of headlines sounded worse than they are. **In this issue:** - [Google is paying $68 million over Assistant recordings. Claims close 8/27.](https://www.freshfromcache.com/google-assistant-settlement/) - [Do you need antivirus on Windows](https://www.freshfromcache.com/do-you-need-antivirus/), or [on a Mac](https://www.freshfromcache.com/do-you-need-antivirus-on-a-mac/)? - [Before you price hearing aids, take the test that came with your earbuds](https://www.freshfromcache.com/can-airpods-be-used-as-hearing-aids/) - [A colon cancer test company got breached. Expect a phone call.](https://www.freshfromcache.com/cologuard-data-breach/) - [Can somebody steal a passkey?](https://www.freshfromcache.com/can-passkeys-be-stolen/) - [Also this week: a photo backup that quit, an FTC refund, and new limits on plate cameras](https://www.freshfromcache.com/also-this-week-2026-08-14/) - [Your library card is a subscription you already pay for](https://www.freshfromcache.com/library-card-audiobooks/) - Plus: two scams making the rounds - And the Scary Headline of the week: hackers walked into Levi's on a phone call --- [**Google is paying $68 million over Assistant recordings. Claims close 8/27.**](https://www.freshfromcache.com/google-assistant-settlement/) The figure going around is $56, and that is the top of a range built on the assumption that almost nobody files. There are two ways to claim, and one pays four times the other. The bigger one wants a receipt for a device you may have bought in 2018, which is where most people will quit. Before you answer no to that question on the form, the piece shows you where to go looking for the receipt. Your speaker is not being switched off, either. *News* --- [**Do you need antivirus, or is Windows Defender enough?**](https://www.freshfromcache.com/do-you-need-antivirus/) There is a red banner in the corner of the screen saying your subscription expired, and it has been saying so for a while. For most people on Windows, Defender is free, already running, and tests level with the thing you were paying for. The piece covers what the labs found, who should still pay, and how to actually cancel McAfee or get a Norton renewal refunded. Monday's companion does the same for the Mac, where three layers are already running and the one rule that matters more than any scanner is not a scanner at all. *Learn* --- [**Before you price hearing aids, take the test that came with your earbuds**](https://www.freshfromcache.com/can-airpods-be-used-as-hearing-aids/) One person turns the television up, somebody else wants it back down, and in a lot of houses that argument got settled years ago with subtitles as a truce. AirPods Pro carry an FDA-authorized over-the-counter hearing aid and a free hearing test that runs right there in your ears. Take the test even if you never switch the hearing aid on, because it hands you a number you can carry to a doctor. Where it falls short is in there too, along with what Medicare covers and what an independent lab measured when it checked Apple's work. *Learn* --- [**A colon cancer test company got breached. If you took Cologuard, expect a phone call.**](https://www.freshfromcache.com/cologuard-data-breach/) If you ever mailed a Cologuard sample back in a prepaid box, the company that processed it was broken into, and 10.9 million email addresses are already public. The reflex is to freeze your credit, and that is the wrong first move here, because nothing financial was confirmed taken. The stolen data is a targeting list. Brace for a very convincing phone call from somebody who knows you took a colon cancer test. There are five things to do this week, and the piece walks through them. *News* --- [**Can somebody steal a passkey?**](https://www.freshfromcache.com/can-passkeys-be-stolen/) The coverage of some new research used words like cracked and master key. What the researchers found needs malware already running on your computer as you, which makes a clean computer the whole defense. One of the three attacks is sharper than the others. It reaches a key that Google gives you no way to change, so a compromise outlasts the cleanup. Passkeys are still far better than passwords, and nothing here changes what to use. *Learn* --- [**Also this week: a photo backup that quit, an FTC refund check, and new limits on license plate cameras**](https://www.freshfromcache.com/also-this-week-2026-08-14/) Four stories from the week I did not write a full piece about. Google Drive stopped pushing your pictures into Google Photos on Monday, the FTC is sending $23.8 million to Grubhub diners and drivers, Flock is changing the rules on its license plate cameras after a year of officers misusing them, and half a million Camrys can lose the dashboard and the turn signals at the same time. *News* --- **If you only read one:** the hearing test. It is sitting inside a pair of earbuds plenty of people already own, and the alternative starts in the thousands. --- ### 5-Minute Tech Tip [Your library card is a subscription you already pay for](https://www.freshfromcache.com/library-card-audiobooks/). Audiobooks, ebooks and magazines, free, on the phone in your pocket, through an app called Libby. Magazines have no waiting list at all, so this month's issue opens the moment you tap it. The same card also gets you Hoopla and Kanopy, and if you do not have a card, you can probably fix that today without leaving the house. --- ### Fresh Trouble **Tax debt help that fixes nothing.** Companies promising to wipe out back taxes for pennies on the dollar, before anybody has looked at your situation. They charge the fee, do nothing, and leave you further behind with the people you owe. ([FTC](https://consumer.ftc.gov/consumer-alerts/2026/08/struggling-tax-debt-heres-what-know?ref=freshfromcache.com)) **The ad in your feed that nobody checked.** The designer bag at half price that catches you mid-scroll. Social platforms do not always vet the ads or the advertisers behind them, so an ad sitting in your own feed is not evidence of anything. ([FTC](https://consumer.ftc.gov/consumer-alerts/2026/08/are-ads-social-media-vetted-or-checked-scams-heres-what-know?ref=freshfromcache.com)) --- ### Scary Headline of the Week *"Levi Strauss & Co. says hackers stole corporate data in cyberattack"* Levi's told the SEC on August 7 that somebody got into the computers of three employees and took company files. No software flaw, no missing patch, no password broken. Three people were talked into it over the phone. So far the company has found no sign that customer data was involved, though it says the investigation is still running. Nobody has publicly claimed the attack, and the group being named around it is somebody's inference rather than a confirmation, so treat that part as unsettled. **The verdict:** nothing to do about your Levi's account, but the method used is the lesson to learn. The same call that worked on three people at a six billion dollar company is the one that reaches your phone. Somebody friendly, claiming to be tech support, asking you to sign in somewhere so they can help. That is the scam, and it works at any size. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help: forward this email to one person who might want it, and if it was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. --- If this is the week you finally go dig out your library card, hit reply and tell me. Joel ### Google is paying $68 million over Assistant recordings. Claims close 8/27. URL: https://www.freshfromcache.com/google-assistant-settlement/ Last updated: 2026-08-18T10:59:59.000Z Google agreed in January to pay $68 million to end a privacy case over Assistant. The allegation was that it recorded people when nobody said "Okay Google," and that some recordings went to outside review vendors. Google denies it and the court has made no finding. The money is real regardless. If you have seen a dollar figure attached to the Google Assistant settlement, it was probably $56\. That is the top of a range, and that range is assuming almost nobody files. Claims close August 27. ## Where the $56 comes from Not from a notice in your inbox or the claim form. Neither carries an estimate. The number comes from the motion asking the judge to approve the deal. The lawyers for the class wrote that a purchaser with one Google device might get $18 to $56, and a privacy claimant $2 to $10. Those figures rest on an assumption. A.B. Data, the administrator, told the court it expects 1 to 2 percent of eligible people to file, based on its own experience and a 2019 FTC study of consumer class actions. The 2019 study found that when people had to fill out a claim form, the median claims rate was 9 percent. For campaigns noticed by email, which is how this one went out, the study found a 2 percent median and a 3 percent average. So the assumption sits at the bottom edge of the closest comparison, and the report carries no figure for privacy cases at all. For every point the real claim rate rises above the assumption, the payout gets smaller. Google told the same court it disagrees and thinks the class is smaller, which would mean bigger payments. The notice says outright that it is unknown how much anyone will receive. Fees come off the top first. Counsel asked for one third of the fund, $22,666,666.67, plus $1,021,738.40 in expenses and $10,000 for each of four named plaintiffs. Judge Beth Labson Freeman rules on that October 1, alongside final approval. Payment comes after that and after any appeals, realistically 2027. ## Two groups, two sets of rules The settlement splits people into two groups. The claim form calls them classes, it asks you about each one in turn, and you can be in both. The Purchaser class covers anyone who bought a Google Home, Home Mini, Home Max, Nest Hub, Nest Hub Max or a Pixel phone between May 18, 2016 and March 19, 2026\. That claim wants the model, the serial or IMEI number, and proof of purchase for each device, up to three. A receipt from 2018. ![The claim form's Purchaser Settlement Class page, asking whether you are a member of the purchaser class, with the class definition and the May 18, 2016 to March 19, 2026 date range printed above the question.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/form-03-purchaser-question.png) The form asks about the purchaser class first. Answering no here is what costs you the four points. The receipt is where most people will quit, and quitting costs you the bigger claim. A purchaser claim carries four points per device. A privacy claim carries one. So look before you answer no. Check your Google Store order history, then search your email for the order confirmation, which works no matter who sold you the thing. The form's own worked examples are a "Google Store receipt" and a "Best Buy receipt," so a retailer receipt counts. Upload what you have and expect it to be looked at. The form says you may be asked for more later, and a claim you cannot back up may be rejected. If the receipt is truly gone, you are not locked out. File the privacy claim, which needs none of it. The Privacy class covers anyone whose conversations were caught by a false trigger on any device running Assistant, Google's or not, plus everyone in their household. Each person files their own. There is no receipt on that side, but the form still wants the device type, the model name, and the serial or IMEI number, which is printed on the device or sitting in its settings. You attest rather than prove, under penalty of perjury and subject to audit. ![The claim form's Privacy Settlement Class panel, with required fields for device type, device model name, and serial number or IMEI number.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/form-05-privacy-device-fields.png) No receipt on the privacy side, but the serial or IMEI is still required. ## Your speaker is not being switched off Google starts removing Assistant from Android phones and tablets, Wear OS watches, headphones and phone-projected Android Auto on September 4, over a few weeks. Speakers and displays move to Gemini for Home on their own track and keep working. So do cars with Google built in. We [said so on August 7](https://www.freshfromcache.com/also-this-week-2026-08-07/) and nothing has changed yet. The shutdown and the settlement are unrelated. Customers aren't being paid because Assistant is going away. ## What to do before August 27 - **Type the address yourself.** [www.GoogleAssistantPrivacyLitigation.com](https://www.googleassistantprivacylitigation.com/?ref=freshfromcache.com). The [same instinct](https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/) that makes you suspicious of the email is the right one. - **File without the codes.** A.B. Data emailed Unique IDs and PINs, and plenty went to spam. Underneath the login boxes there is a button that says "Don't have a Unique Id and PIN? Click Here." That is the way in. - **Do not pay anyone.** Filing is free, the notice refuses bulk filings from claims aggregators, and a real claim never asks for a Social Security number, a password or a fee. The FTC's line from Equifax still holds true, anyone who calls to help you file is almost certainly a scammer. - **Opt out or object by the same date.** August 27 closes all three doors. ![The settlement website's login page, asking for a Unique ID and PIN, with a button underneath that reads Don't have a Unique Id and PIN? Click Here.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/form-01-login-no-codes.png) The button underneath is the way in when the notice email never arrived. I am going to file. It costs nothing and the case is real. I won't be telling anybody that Google owes them $56 though. If a check turns up in 2027 for a fraction of that, nobody who reads this will be surprised. **The claim:** [Google Assistant Privacy Settlement](https://www.googleassistantprivacylitigation.com/?ref=freshfromcache.com) and the [long form notice](https://www.googleassistantprivacylitigation.com/assets/documents/In%20re%20Google%20Assistant%20Long%20Form%20Notice%5FFinal.pdf?ref=freshfromcache.com) **Where the estimates come from:** [Motion for preliminary approval, ECF 549](https://storage.courtlistener.com/recap/gov.uscourts.cand.345331/gov.uscourts.cand.345331.549.0.pdf?ref=freshfromcache.com) and the [fee motion, ECF 566](https://www.googleassistantprivacylitigation.com/assets/documents/566-Plaintiff%20Motion%20for%20Fees%2C%20Awards%2C%20Exp%20and%20Svc%20Award.pdf?ref=freshfromcache.com) **The claims-rate study:** [Consumers and Class Actions, FTC staff report, September 2019](https://www.ftc.gov/system/files/documents/reports/consumers-class-actions-retrospective-analysis-settlement-campaigns/class%5Faction%5Ffairness%5Freport%5F0.pdf?ref=freshfromcache.com) **The FTC on fake settlement sites:** [Beware of fake settlement websites](https://consumer.ftc.gov/consumer-alerts/2019/07/equifax-data-breach-beware-fake-settlement-websites?ref=freshfromcache.com) **The Assistant shutdown:** [Google's email to users, reported by 9to5Google](https://9to5google.com/2026/08/04/google-assistant-september-2026-shutdown/?ref=freshfromcache.com) and [Google on Gemini for Home](https://support.google.com/googlehome/answer/16618650?ref=freshfromcache.com) ### Do you need antivirus on a Mac? URL: https://www.freshfromcache.com/do-you-need-antivirus-on-a-mac/ Last updated: 2026-08-17T10:59:59.000Z Last week's [antivirus piece](https://www.freshfromcache.com/do-you-need-antivirus/) gave Mac owners exactly one sentence, "macOS and Android both include their own protection, and paid phone antivirus apps mostly sell you a scan and a scare." Mac has always been known as the OS that "doesn't need an antivirus." I was asked if this was still true. Mostly, it is. Your Mac protects itself, and most paid Mac antivirus is selling reassurance. What was skipped is the how, the short list of people who should install something anyway, and the thing most likely to compromise a Mac in 2026\. That last one gets past any scanner ever tested, because it asks you for permission and then waits. ## The antivirus you never see A Mac runs three layers of malware defense out of the box, and you have probably never even noticed. The first layer checks software before it runs. App Store apps are reviewed by Apple. Apps from anywhere else have to be "notarized," meaning the developer submitted the app, Apple scanned it for known malware, and macOS verifies that ticket before the app opens. If an app turns out to be malicious later, Apple revokes the ticket. Your Mac keeps checking for revoked tickets in the background. The second layer is a signature-based antivirus called XProtect. It is built into macOS and cannot be turned off. It scans an app when it first launches, when it changes on disk, and whenever Apple delivers new malware signatures. On a match it blocks the app, moves it to the Trash, and tells you. Apple says the Mac checks for new signatures daily. Howard Oakley, an independent researcher who logs every release, has counted a fresh signature bundle about once a week this year. The third layer cleans up. XProtect Remediator is a background tool that scans for known malware families about once a day, while the Mac is awake and idle, and removes what it finds. Apple added it in 2022 and it has been running ever since. Mac owners never got the red banner from last week's piece. Nobody preinstalled a trial, so most of you never installed anything, and if you ever felt vaguely irresponsible about that, the machine had you covered the whole time. ## Lab testing Independent labs test Mac antivirus the same way they test it on Windows. They collect recent, real Mac malware and run it at the third-party products, free and paid, to see what each one catches. In AV-Comparatives' 2026 test, nine products faced 1,500 recent Mac malware samples. Every product scored between 96.7 and 100 percent, and not one raised a false alarm. AV-TEST's March round was similar, with eight of ten products catching every sample. There is one difference from the Windows story, though. On Windows, Microsoft Defender sits in those same tests, next to the paid products, scored on the same samples. Apple's built-in protection has never been in either lab's lineup. There is no XProtect row in any results table, and no "Mac with nothing installed" baseline. So when a review site says the built-in protection is as good as the paid products, or a vendor implies it is worse, neither side has numbers to compare. Nobody does. XProtect works from a list of known threats, so a brand-new one can get by until Apple writes a rule for it. The paid engines catch what the labs report. None of this addresses how Macs are actually being compromised in 2026. ## The malware that gets by The year's Mac threat reporting comes from three directions: Apple's security documentation, Microsoft's threat intelligence, and the independent researchers who catalog every new piece of Mac malware. Search all of it for the movie kind, the worm that slips in on its own while you sleep, and you come up empty. Not one reported case in 2025 or 2026 of ordinary Mac users hit by malware that installed itself. Nearly every real infection required the owner to open something, approve something, type a password, or paste something. The pattern to know is one Microsoft documented in early August. More than 250 fake download pages built for Macs, complete with a forged "Verified Publisher" badge and a copy button. The page says that to download the app, or fix a problem, you need to paste a command into Terminal. The command is one click to copy. Paste and run it, and it fetches a program that reads what Microsoft describes as "credentials, browser and cryptocurrency wallet data, authentication stores, and other sensitive files" and sends all of it out. Saved logins, session cookies, crypto wallets, the works. It is [the fake CAPTCHA scam](https://www.freshfromcache.com/fake-captcha-scam/) dressed for a Mac. It never sneaks past Gatekeeper, and it never exploits a hole in macOS. Victims type their own password and run it themselves, bypassing all the safeguards. Apple noticed. Since a spring update (macOS 26.4), pasting a command into Terminal that was copied from a website, a chat, or an email gets a warning first. The warning appears if Terminal is not something you regularly use, and known-malicious scripts get blocked outright with no override. The warning is real friction and it will save people. It also has a "Paste Anyway" button, because sometimes a paste is legitimate, and a person who is convinced their Mac is broken might still click it. So there is one rule to stay safe on a Mac. Nothing gets pasted into Terminal because a web page, a pop-up, a video, or a person on the phone told you to. Not to fix a problem. Not to prove you are human. Not to install anything. If Terminal is part of your daily work, you already know which commands are yours. The rule is for everyone else. ## Who should still install an antivirus ![A yellow iMac on a home desk beside a plant, a magazine, and a pot of pens](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/jay-wennington-imac.jpg) Photo: Jay Wennington via Unsplash There are still circumstances where installing a third-party antivirus on a Mac makes sense. **A Mac too old for updates.** The built-in protection is only as good as its signature deliveries. A Mac that no longer receives updates is walking around with last year's threat list, and it only falls further behind. A third-party antivirus that still supports older systems is a reasonable patch. **The household has a clicker.** If somebody installs whatever pop-ups suggest, a paid suite with web filtering buys a second chance the built-in tools do not offer. Know the limit going in, though. No product reliably stops a person from clicking "Paste Anyway." **You install a lot from outside the App Store.** Developers, tinkerers, and anyone who runs tools off GitHub meet more unvetted code than the average Mac ever will. A free tool called [LuLu](https://objective-see.org/products/lulu.html?ref=freshfromcache.com), from the nonprofit Objective-See, adds an outbound firewall that alerts you when a program tries to call home. Calling home is the one step every theft has to take. The catch is that LuLu asks you to judge each alert yourself, and judging prompts under pressure is the situation scams exploit. **Your Mac feeds files to an unprotected Windows machine.** macOS does not hunt Windows malware, so a Mac can pass along an infected file it will never flag. If you move files on a USB stick to somebody's aging Windows box, the paid Mac products catch Windows malware in transit, and the labs test them on it. In a world where files move through email and cloud accounts, which run their own scanning, this matters less than it used to. **A small business is a different question.** What a business needs is managed detection, with a person watching the console, not six copies of a home product that nobody is minding. There is one category to skip entirely. Mac "cleaners" and "optimizers" sell a fix for a problem your Mac does not have, and ask for deep access to your files to do it. CleanMyMac is the polished end of that category and MacKeeper the notorious end. Neither one is an antivirus. If a pop-up ever tells you your Mac is dirty or slow and offers to clean it, the pop-up is the problem, not your Mac. ## What you can do now Five checks, in order. ### 1\. Confirm the Mac still gets updates Open System Settings, click "General," then "Software Update." Turn on automatic updates, including "Install Security Responses and system files." That last item is the path XProtect's signatures arrive through. If your Mac is too old to get updates at all, reread the first item on the list above. ### 2\. Adopt the rule Nothing gets pasted into Terminal on somebody else's instructions. Pass the rule along to the people who bring you their tech questions, the same way you told them nobody legitimate asks for gift cards. ### 3\. Audit your browser extensions In Safari, open Settings, then "Extensions." In Chrome, the puzzle-piece icon, then "Manage extensions." Remove anything you do not remember choosing. Malware has shipped inside look-alike extensions, and a good extension can be sold to a new owner and go bad later. ### 4\. Read three permission lists Open System Settings, then "Privacy & Security." Look at "Full Disk Access," "Screen Recording," and "Accessibility." Those three are what a thief or a remote-control tool wants. You should recognize everything listed. Anything you do not recognize should be looked up before it stays. ### 5\. If you think something already got in Move to a device you trust before you fix anything. A password stealer on the Mac reads a new password as you type it, so changing passwords from the infected machine accomplishes nothing. From the clean device, change email and bank passwords first, turn on multi-factor authentication anywhere it is off, and assume every login saved in the browser needs rotating. [What to do after a scam](https://www.freshfromcache.com/what-to-do-after-a-scam/) has the full triage order, and [a password manager](https://www.freshfromcache.com/start-using-a-password-manager/) is how you rebuild without reusing anything. Back on the Mac, a free on-demand scanner such as Malwarebytes will confirm and remove the most common malware. When in doubt, back up your files and reinstall macOS. ## One more thing Last week's piece ended by saying the people who paid for Windows antivirus all those years were doing the responsible thing with the information they had. Mac owners got the opposite deal. You were told Macs do not get viruses, which was never quite true, but it worked out anyway, because the machine was scanning the whole time. Keeping it that way is free. The next time a web page hands you a command and a scary reason to run it, just close the tab. If the app was real, it will install the normal way, with no Terminal in sight. **Sources** Apple: [Protecting against malware in macOS (Platform Security Guide)](https://support.apple.com/guide/security/protecting-against-malware-sec469d47bd8/web?ref=freshfromcache.com) · [If your Mac blocks a Terminal command paste or script](https://support.apple.com/en-us/127377?ref=freshfromcache.com) Threat reporting: [Microsoft Threat Intelligence on the macOS ClickFix campaign (August 5, 2026)](https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/?ref=freshfromcache.com) · [Objective-See, The Mac Malware of 2025](https://objective-see.org/blog/blog%5F0x84.html?ref=freshfromcache.com) Test results: [AV-Comparatives Mac Security Test and Review 2026](https://www.av-comparatives.org/tests/mac-security-test-review-2026/?ref=freshfromcache.com) · [AV-TEST home macOS results (March 2026 cycle)](https://www.av-test.org/en/antivirus/home-macos/?ref=freshfromcache.com) Tools and tracking: [The Eclectic Light Company, XProtect update tracking](https://eclecticlight.co/tag/xprotect/?ref=freshfromcache.com) · [Objective-See, LuLu](https://objective-see.org/products/lulu.html?ref=freshfromcache.com) ### Your library card is a subscription you already pay for URL: https://www.freshfromcache.com/library-card-audiobooks/ Last updated: 2026-08-16T17:19:26.000Z You know the email. "An update to your subscription pricing." Everybody's streaming bill crept up again this year, and the polite little emails keep coming. Meanwhile there is a subscription you have been paying for the whole time that never raises its price, and most people never use it. The library. Not the building. The card. The number on that card signs your phone into free audiobooks, ebooks, and magazines. And if you can't find your card, or never had one, there is a decent chance you can fix that today without leaving home. Think of the card number as a login you already paid for. Your taxes cover the service whether you use it or not. The only thing left is connecting it to your phone. ## The one thing to do The app is called Libby, from OverDrive, the company that runs digital lending for most libraries. Their own figure is that over 90 percent of public libraries in North America use it. The app is free, the borrowing is free, and there is nothing in it to upgrade to. 1. Install "Libby, the library app" from the App Store or Google Play. Same app on iPhone and Android. If you would rather not install anything, libbyapp.com does the same job in a web browser. 2. Open it and follow the prompts to find your library. Search by name or zip code, or let it use your location. 3. Already have a card? Sign in with the card number and PIN. If you don't know your PIN, look for the reset link on the sign-in screen or your library's website. 4. Find a title and tap 'Borrow'. It opens right in the app, and your loans live under 'Shelf'. Loans return themselves on the due date. No late fees. Kindle readers get a bonus. Tap a book's cover and look for Kindle under 'Read With'. Eligible ebooks hop over to your Kindle through Amazon, and the loan still returns itself on the due date. ## No card? No problem At the top of your library's home screen in Libby is a button reading 'I Would Like A Card'. Tap it. Depending on your library you will see 'Use My Phone Number', which checks your address against the library's service area and texts you a code. Or you can click 'Visit Library Website', which opens a short signup form. The phone-number route does not ask for an ID or a utility bill. Not every library offers an instant card. If yours doesn't, the signup form on the library's own website is the next stop. And an instant card is a digital card. It gets you everything in the app, but if you ever want to walk out of the building with books, most libraries will have you show up once in person to convert it. ## Magazines have no line A bestseller can carry a hold list measured in weeks. The library rents each digital copy and lends it out one person at a time, the same as the hardcover, so popular titles queue up. Put a hold on it and forget it; Libby notifies you when it's your turn. Magazines work the opposite way. Always available, no holds, and they don't count against your borrowing limit. The New Yorker, Consumer Reports, and a lot more, all sitting there. If you want to test this out today, start with a magazine. Audiobooks are another surprise. The catalog runs deep, and the one you almost bought last week may well be in it. ## Two more apps, same card Libby is not the only thing your card opens. Two others turn up at a lot of libraries, and they are additions rather than replacements. Same card number, separate app, separate limits. **Hoopla** is the one with no waiting. Anything marked with a lightning bolt is there whenever you want it, no matter how many other people have it out. Audiobooks, ebooks, comics, music, movies, and television. The catch is similar to the economics above. Your library is charged every time you borrow something on Hoopla, roughly one to four dollars a checkout. That's whether you open it or not. That is why there is a monthly cap and why the number is different at every library. Some libraries also set a shared daily limit across everyone. Which is what is happening when Hoopla tells you to come back tomorrow. There is a second kind of checkout now, marked with circling arrows, that does have a waitlist and its own smaller monthly allowance. **Kanopy** is the one for films, and it goes head to head with your streaming bill. Criterion, A24, Magnolia, NEON, documentaries, PBS. You get a set number of tickets a month, your library decides how many, and they reset on the first without rolling over. Not everything costs a ticket. Some titles are unlimited viewing, and Kanopy Kids never uses one. If your library carries Kanopy it also shows up in the Extras section of Libby, so it may already be sitting in that app. Neither one is universal. Your library's website will say which it has. ## If your library uses a different app Some libraries use cloudLibrary or Palace Project instead of Libby, or alongside it. If your library doesn't come up in Libby's search, its own website will name the app it uses. Usually under "digital library" or "ebooks." Your card number works the same way in all of them. ## The card lends hardware too This piece is about what the card puts on your phone, but the lending doesn't stop at files. In the Public Library Association's 2023 technology survey, nearly half of US public libraries lent Wi-Fi hotspots, and about a quarter lent laptops. If your home internet is thin, or somebody in the house needs a computer for a school year, ask at the desk before you buy anything. Some libraries go a lot further than that. Sewing machines, telescopes, power tools. Search your library's name plus "library of things" and see what turns up. ## You bought it, try it Our taxes are already paying for this subscription. So give it a try. Try a magazine if you want it instantly, a film if the streaming bill is bothering you, or the audiobook you've been meaning to get to if you can wait out a hold. And once you're in, know that you aren't limited to one library. If you still have a card from the town you moved away from, or family gets you one in another county, Libby holds them all. And every card is its own catalog. Did the phone-number card work at your library? Tell me which library, and what you borrowed first. joel@freshfromcache.com ## Sources - OverDrive/Libby Help, *What is Libby?* (free, no late fees, auto-return; libbyapp.com in a browser): [help.libbyapp.com/en-us/6144.htm](https://help.libbyapp.com/en-us/6144.htm?ref=freshfromcache.com) - OverDrive/Libby Help, *How do I get a library card?* ('I Would Like A Card', 'Use My Phone Number'): [help.libbyapp.com/en-us/6125.htm](https://help.libbyapp.com/en-us/6125.htm?ref=freshfromcache.com) - OverDrive, *Instant Digital Card* (name plus phone number, texted code, US public libraries): [resources.overdrive.com](https://resources.overdrive.com/library/libby-features/instant-digital-card/?ref=freshfromcache.com) - OverDrive/Libby Help, *Reading magazines* (always available, don't count against your limit): [help.libbyapp.com](https://help.libbyapp.com/en-us/categories/reading-magazines.htm?ref=freshfromcache.com) - OverDrive/Libby Help, *Why can't I send a book to Kindle?* (the 'Read With' section, eligibility varies by title): [help.libbyapp.com/en-us/6027.htm](https://help.libbyapp.com/en-us/6027.htm?ref=freshfromcache.com) - OverDrive, *Meet Libby* ("Over 90% of public libraries in North America have OverDrive"): [overdrive.com/apps/libby](https://www.overdrive.com/apps/libby?ref=freshfromcache.com) - Public Library Association, *2023 Public Library Technology Survey Summary Report* (46.9% of libraries lend hotspots, 24.8% lend laptops): [ala.org (PDF)](https://www.ala.org/sites/default/files/2024-07/PLA%5FTech%5FSurvey%5FReport%5F2024.pdf?ref=freshfromcache.com) - Spokane County Library District, *A Closer Look at hoopla* (per-borrow cost of 99 cents to $3.99, charged whether or not the item is opened): [scld.org](https://www.scld.org/a-closer-look-at-hoopla-digital-books-music-movies-tv-the-borrow-limit/?ref=freshfromcache.com) - San Francisco Public Library, *Hoopla Flex vs Instant Borrow* (lightning bolt is no waiting, circling arrows can be waitlisted, separate monthly limits): [sfpl.libanswers.com/faq/435686](https://sfpl.libanswers.com/faq/435686?ref=freshfromcache.com) - Kanopy Help, *Using tickets* (your library sets the number, tickets reset the first of the month and do not roll over, Kanopy Kids never uses tickets): [help.kanopy.com/en-us/4260.htm](https://help.kanopy.com/en-us/4260.htm?ref=freshfromcache.com) - OverDrive Resource Center, *Kanopy* (A24, Magnolia, NEON, Kino Lorber, Criterion, PBS; "Kanopy displays in the Extras section of the Libby app"): [resources.overdrive.com/kanopy](https://resources.overdrive.com/kanopy/?ref=freshfromcache.com) *Paths and claims verified August 15, 2026\. Hoopla and Kanopy section added and verified August 16, 2026.* ### Before you price hearing aids, take the test that came with your earbuds URL: https://www.freshfromcache.com/can-airpods-be-used-as-hearing-aids/ Last updated: 2026-08-15T10:59:59.000Z One person turns the television up. Somebody else wants it back down. In a lot of houses that argument was settled years ago with a truce. Everybody is a little unhappy, and the subtitles are on. If that sounds familiar, there is something you can try today that costs nothing and could help. AirPods Pro can work as a real hearing aid. Not the prescription kind fitted by an audiologist, the over-the-counter kind. The category was created by the FDA in 2022 so adults could buy hearing aids without an exam or a prescription. The software is already in the earbuds and so is a hearing test. (Samsung has announced the same pair of features for Galaxy Buds. If you are on Android, there is a section for you near the end.) ## What the FDA actually signed off on In September 2024 the FDA authorized the Hearing Aid Feature for AirPods Pro, the first over-the-counter hearing aid that is software rather than a device. It is meant for people 18 and older with perceived mild to moderate hearing loss. "Perceived" is doing a lot of work in that sentence. A doctor does not need to certify that you qualify. You decide you are having trouble, and the test tells you the rest. The FDA reviewed a study Apple submitted, run at multiple US sites with 118 people who had mild to moderate hearing loss. People who set the feature up themselves reported about as much benefit as people who had the same earbuds fitted for them by a professional. Amplification measured in the ear canal was comparable, so was a measure of understanding speech in noise, and nobody was harmed by the device. That is Apple's own study, submitted in support of Apple's own application. It does not make it wrong, though it does mean somebody else needed to check the work. Independent researchers have since had a look, and they found something different. ## Start with the test, even if you stop there The hearing test is free, it works on AirPods Pro 2 or AirPods Pro 3, and it is separate from the hearing aid. You can try it and not apply any changes. ![A man placing a white wireless earbud into his ear.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/getty-images-iUQbZrLBkgs-unsplash.jpg) Photo: Getty Images via Unsplash+ You need a quiet room and both earbuds charged and sealed properly in your ears. Turn off the fan and the air conditioning. The test plays tones from 250 Hz up to 8 kHz and you tap the screen when you hear one. Tones are pulsed three times, so missing one is not a problem. Go to Settings, tap the name of your AirPods, then tap 'Take a Hearing Test'. You can also start it from the Health app. A few things throw off the results, and Apple names them. A cold, a sinus infection or an ear infection in the last 24 hours. Allergies today. A loud concert last night. If any of those apply, wait a few days. At the end you get one number for each ear, an average across the frequencies that matter most for understanding speech. Apple's own scale reads like this: WHAT THE NUMBER MEANS | Up to 25 dBHL | Little to no hearing loss | | ------------- | --------------------------------------------------------- | | 26 to 40 | Mild. Words spoken in a normal voice from three feet away | | 41 to 60 | Moderate. A raised voice from three feet away | | 61 to 80 | Severe. Some words when they are shouted into your ear | The audiogram goes into the Health app and stays on your phone. Tap 'Browse', then 'Hearing', then 'Hearing Test Results', and there is an 'Export PDF' option down at the bottom. The PDF will not replace anything at the audiologist's office. They will run their own full test no matter what you bring, since theirs checks things the phone cannot. What the PDF does is give that first appointment a date and a number to start from, instead of "I think it got worse a while ago." It works the other direction too, because you can enter an audiologist's audiogram into the earbuds instead of using the phone test. ![A person seen from behind wearing audiometry headphones and raising one finger during a hearing test.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/mark-paton-uyT0lsfimjI-unsplash.jpg) Photo: Mark Paton via Unsplash How good is the test? Better than you would expect from something you can do at home. An independent group at the University of Pretoria put 25 adults through both the phone test and a proper audiologist's booth test. There were 400 threshold comparisons in all, and 86.5% of the phone results came within 10 decibels of the booth. It was repeatable, and it was faster. There is one thing the test lacks. The phone test has no bone conduction. A booth test also plays sound through the bone behind your ear, and the difference between those two answers is what tells a clinician whether the trouble is in the nerve or in the plumbing. Earwax and fluid are the plumbing, and the plumbing is often fixable. ## Turning the hearing aid on You need AirPods Pro 2 or AirPods Pro 3 with current firmware, and an iPhone or iPad running current software. Older AirPods and the non-Pro models are not on Apple's list. Go to Settings and tap the name of your AirPods. Tap 'Hearing Assistance', then 'Set Up Hearing Assistance'. It will offer to use your test result, an earlier result, or an audiogram from your provider. Then tap 'Set Up Hearing Aid' and 'Turn On Hearing Aid'. If your test came back very mild, it may suggest Media Assist instead. Media Assist applies your hearing profile to music, video and calls, and leaves the room alone. The hearing aid only amplifies the room while you are in Transparency mode, so with noise cancellation switched on you are not using it. The settings live on the earbuds, so they keep working when your phone is in another room. ![A man on a sidewalk touching the AirPod in his ear while holding his phone.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/jonas-schindler-oDnYWhqiOro-unsplash.jpg) Photo: Jonas Schindler via Unsplash Three controls are the ones to adjust. - Amplification is how much louder the world gets. You can also reach it from Control Center by holding down the volume slider. - Tone makes things brighter or darker. - Ambient Noise Reduction pulls down the fan and the road noise. Conversation Boost is a fourth, and it amplifies the person directly in front of you. Leave everything else alone at first. Expect the first hour to sound strange and bright. That is normal, and Apple says so on its own support page, which recommends small changes over time rather than one big adjustment. ## Where it falls short Here is the finding a company would not print. In February 2026 researchers at the University of Pretoria published the first independent evaluation of the hearing aid feature, in the American Journal of Audiology. Twenty-five iPhone users set it up themselves. They liked it. Usability scored 6.7 out of 7, and people praised the price, the convenience, and the fact that the thing in their ears was also just earbuds. Then the researchers measured it. On a standard test of understanding speech in noise, the average improvement was a tenth of a decibel, which is no improvement at all. And when they measured the sound actually being delivered into the ear against the targets an audiologist fits to, the earbuds were generally giving less than the target. High satisfaction, less amplification than a fitted hearing aid delivers. Both of those are true at the same time. The speech-in-noise test is how a lab simulates a crowded restaurant, and the crowded restaurant is where people want the most help. It is also where the earbuds gave the least. Battery is the other limit. Apple rates the AirPods Pro 3 at up to 10 hours in Transparency with the hearing aid running, and the Pro 2 at roughly six. Dedicated hearing aids run 24 hours and more. These are not a breakfast-to-bedtime device, and the sealed tips wear out their welcome in your ears before the battery does. ## What the other route costs ![Three behind-the-ear hearing aids displayed on small metal stands on a wooden table.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/yunus-tug-A98fMeomRhc-unsplash.jpg) Photo: Yunus Tug via Unsplash Consumer Reports puts prescription hearing aids at about $1,500 to more than $7,000 a pair, and its own members reported paying a median of $2,592 a pair after insurance. AirPods Pro run $199 to $249, and the hearing features cost nothing on top of that. That is not the whole comparison, because the money buys something. A prescription fitting includes a real hearing test, help picking a model, and repeat adjustments. It includes real-ear measurement, which is a microphone in your ear canal confirming that the device is delivering what it is supposed to deliver. That is exactly the measurement the independent researchers ran, and exactly where the earbuds came up short. Medicare has not moved on this since 1965\. Original Medicare does not cover hearing aids or the exams to fit them. It does cover a diagnostic hearing and balance exam when your doctor orders one to find out whether you need medical treatment, and you pay 20% of the approved amount after the Part B deductible. Medicare Advantage is a different story. KFF found that 95% of people in individual Medicare Advantage plans in 2026 are in a plan that offers hearing exams, hearing aids, or both. That usually means an allowance rather than full coverage, and the amount is set by the plan, so your Evidence of Coverage is what answers it. IRS Publication 502 says you can include the cost of a hearing aid and its batteries, repairs and maintenance as a medical expense, and that covers over-the-counter aids. It does not name AirPods, which are a consumer product that happens to contain an authorized hearing aid. I am not a tax advisor. If you want to spend HSA or FSA money on this, ask your plan administrator first and keep the itemized receipt. ## When to skip all of this and call a doctor Some hearing changes are not a shopping decision. ![A clinician examining a patient's ear with an otoscope.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/anthony-camerlo-MNmLTgotAVA-unsplash.jpg) Photo: Anthony Camerlo via Unsplash The NIDCD, the hearing institute at the National Institutes of Health, says to treat sudden hearing loss as a medical emergency and see a doctor immediately. Sudden means all at once or over a few days, and it usually hits one ear. People put it off because they assume it is allergies or wax, and the delay is what makes treatment less likely to work. One-sided loss gets a doctor too. The NIDCD is direct about why. When sudden hearing loss happens in only one ear, tumors on the hearing nerve have to be ruled out. Those are rare. Ruling them out is not something an app will do. Add ear pain, drainage, dizziness, or new ringing in one ear. And anything at all in a child, since every bit of this is for adults 18 and over. Apple says the same at the end of its own test, that severe or profound results, difficulty hearing, or a sudden change in your hearing means talk to your doctor. CALL A DOCTOR INSTEAD IF ANY OF THESE FIT - Hearing loss that arrived suddenly, all at once or over a few days - Loss in one ear only - Ear pain, drainage, or dizziness - New ringing in one ear - Any hearing trouble in a child ## If you are on Android The AirPods hearing test and hearing aid need an iPhone or iPad. There is no way around that, and buying an iPhone to get a hearing aid would be a strange purchase. The Android answer changed in August 2026, though not yet in a way you can use. Samsung announced that the FDA has cleared a Hearing Aid feature of its own for the Galaxy Buds3 Pro and Galaxy Buds4 Pro, built the same way as Apple's. They'll have a hearing test in the settings, an audiogram, then amplification fitted to it. Samsung even fits to NAL-NL2, the same clinical target the independent researchers measured Apple's earbuds against. Two catches. Samsung says the features arrive in the fourth quarter of 2026, so as I write this there is nothing to turn on yet. And full support requires a Samsung Galaxy phone running One UI 8 or later, so this is a Samsung answer rather than an Android one. A Pixel or Motorola owner is still waiting. The path that works today is a dedicated over-the-counter hearing aid, the category the FDA opened in 2022, which you can buy without a prescription or an audiologist visit. Most of them work with any Android phone. ## About the dementia headlines One more thing, because these headlines will find you. The claim that hearing aids hold off dementia comes from a 2023 trial in The Lancet, and the trial found no effect across the study as a whole. The benefit showed up only in a group already at higher risk of cognitive decline, and researchers are still chasing it. It is a real thread of science and a bad reason to buy earbuds. Do something about your hearing because you would like to stop dreading restaurants. ## Try the test Run the hearing test the next chance you get, in a quiet room. If the number comes back at 25 or below, that is the range Apple calls little to no hearing loss, and finding that out cost you nothing. If it comes back mild or moderate, turn the hearing aid on and give it a week of ordinary life before you decide anything. If it comes back worse than that, or if anything on the doctor list sounds like you, take the PDF with you when you go. Consumer Reports says it often takes close to a decade for people to do something about hearing loss. Getting the number as a first step has always been the hard part. [The magnifier built into your phone](https://www.freshfromcache.com/your-phone-is-a-magnifying-glass/) is the same story, a genuinely useful tool filed under Accessibility where hardly anybody looks. Sources - FDA, [FDA Authorizes First Over-the-Counter Hearing Aid Software](https://www.fda.gov/news-events/press-announcements/fda-authorizes-first-over-counter-hearing-aid-software?ref=freshfromcache.com) (September 12, 2024) - Apple Support, [Take a Hearing Test with AirPods Pro 2 or AirPods Pro 3](https://support.apple.com/en-us/120991?ref=freshfromcache.com) - Apple Support, [Use the Hearing Aid feature on your AirPods Pro 2 or AirPods Pro 3](https://support.apple.com/en-us/120992?ref=freshfromcache.com) - Apple, [Hearing Health Feature Availability](https://www.apple.com/airpods-pro/feature-availability/?ref=freshfromcache.com) - Apple Support, [AirPods Pro 3 Tech Specs](https://support.apple.com/en-us/125135?ref=freshfromcache.com) - Kruger, Manchaiah, Swanepoel, [Usability and Performance of the Apple Over-the-Counter Hearing Aid Feature](https://pubs.asha.org/doi/10.1044/2025%5FAJA-25-00192?ref=freshfromcache.com), American Journal of Audiology, 2026 - Kruger, Manchaiah, Swanepoel, [Apple Hearing Test Feature for the AirPods Pro 2: Accuracy, Reliability, and Time-Efficiency](https://aao-hnsfjournals.onlinelibrary.wiley.com/doi/10.1002/ohn.70194?ref=freshfromcache.com), Otolaryngology-Head and Neck Surgery, 2026 - Consumer Reports, [A Complete Guide to Over-the-Counter Hearing Aids](https://www.consumerreports.org/health/hearing-aids/complete-guide-to-over-the-counter-hearing-aids-a3898239010/?ref=freshfromcache.com) - Medicare.gov, [Hearing & balance exams](https://www.medicare.gov/coverage/hearing-balance-exams?ref=freshfromcache.com) and [Hearing aid coverage](https://www.medicare.gov/coverage/hearing-aids?ref=freshfromcache.com) - KFF, [Medicare Advantage in 2026](https://www.kff.org/medicare/medicare-advantage-in-2026-premiums-out-of-pocket-limits-supplemental-benefits-and-prior-authorization/?ref=freshfromcache.com) - IRS, [Publication 502, Medical and Dental Expenses](https://www.irs.gov/pub/irs-pdf/p502.pdf?ref=freshfromcache.com) - NIDCD, [Sudden Deafness](https://www.nidcd.nih.gov/health/sudden-deafness?ref=freshfromcache.com) - Samsung Newsroom, [Samsung's Hearing Aid Feature on Galaxy Buds Cleared by FDA](https://news.samsung.com/us/samsungs-hearing-aid-feature-galaxy-buds-cleared-fda?ref=freshfromcache.com) (August 11, 2026) - Lin et al., [the ACHIEVE trial](https://www.thelancet.com/journals/lancet/article/PIIS0140-6736%2823%2901406-X/abstract?ref=freshfromcache.com), The Lancet, 2023 ### Also this week: a photo backup that quit, an FTC refund check, and new limits on license plate cameras URL: https://www.freshfromcache.com/also-this-week-2026-08-14/ Last updated: 2026-08-14T11:00:00.000Z I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week. ## Google Drive stopped backing up your photos on Monday If you ever set up Google Drive on your computer to push a folder of pictures into Google Photos, Monday was the day that arrangement ended. Google published August 10 as the cutoff. Nothing you already uploaded is gone, and the backup on your phone is untouched. New pictures in that folder just aren't going anywhere now. And if you had that folder going to Photos and not to Drive, there is no second copy sitting in Drive either. The replacement lives at photos.google.com, and it wants a Chromium browser like Chrome or Edge. Click "Create and add photos" at the top right, then "Back up folders," pick your folders, and when it asks for permission take "Allow on every visit" rather than plain "Allow," or it asks again every time. Then read Google's own condition on it. "To allow backup, keep the Google Photos tab open on your browser or have the Photos Web App running." Close the tab and the folders stop going up. Drive used to do this whether you had the tab open or not, and now you have to leave something running. Google did warn people first. It started putting notices inside the Drive app on June 15 and stopped letting anyone set up new photo folders the same day. One oddity though. Three days after the cutoff, Google's own help pages still describe it as something that will happen, and the company has published nothing confirming it went through. So go and look rather than take anyone's word for it, mine included. Open photos.google.com and check the backup status at the top of your library, where it will say backup complete, backup paused, or no backup at all. [The backup you never look at is the one that has already stopped](https://www.freshfromcache.com/do-you-need-backups/). Source: [Google Photos Help](https://support.google.com/photos/answer/6193313?ref=freshfromcache.com) ## The FTC is sending $23.8 million in refunds to Grubhub diners and drivers The Federal Trade Commission announced this week that it is sending 640,038 payments to people who ordered from Grubhub or drove for it. The total is more than $23.8 million. It closes out a case the FTC and the Illinois Attorney General brought in December 2024, and the list of complaints was long. Grubhub told drivers they would make more than they made. It listed restaurants that never agreed to be on the platform. And it locked diners out of their own accounts and their own money, gift cards included. There is no claim form and no site to sign up on. Most people get a paper check in the mail. The rest get a PayPal payment, and that one does have to be opened and accepted. The FTC asks that checks be cashed within 90 days and PayPal payments accepted within 30\. Miss that and the money is not automatically gone, because the FTC says it may be able to reissue a payment if there is still money in the fund. Questions go to the refund administrator, Analytics Consulting LLC, at 1-888-446-4992. Tell anyone in your house who might get one. The FTC's own line is that "the Commission never requires people to pay money or provide account information to get a payment." So anybody who calls asking for a fee to release your Grubhub refund is running a scam, and the refund is the bait. If one ever gets you, [there is an order to work through in the first hour](https://www.freshfromcache.com/what-to-do-after-a-scam/). Source: [Federal Trade Commission](https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-sends-more-238-million-drivers-diners-harmed-grubhubs-deceptive-advertising-claims-other?ref=freshfromcache.com) ## Flock is changing its plate camera rules after a year of officers misusing them Flock Safety makes the cameras that read every license plate that drives past them, in more than 5,000 communities across 49 states. On Thursday the company announced it is tightening how the police can use them. The length of time it keeps plate data by default drops from 30 days to seven. Every police search has to carry a case number by the end of the year. Software that flags odd search patterns becomes mandatory for every law enforcement customer, accounts get suspended automatically when someone's behavior looks wrong, and two-factor login is required as of now. The reason is a year of reporting on officers using the system to follow people they knew personally. The Washington Post documented at least 50 cases on August 2, and in 26 of them the person being tracked was a wife, a girlfriend, an ex, or a woman the officer wanted to approach. Georgia by itself has arrested at least 20 officials. A former Riverside County deputy was convicted on ten counts in February and sentenced to six years for using it to stalk his ex-fiancée. The case that put this in front of the public is from Texas. In May 2025 a sheriff's sergeant in Johnson County searched 83,345 cameras across the country for a woman who had ended her own pregnancy. He typed the reason into the log himself. "Had an abortion, search for female." Sheriff Adam King said afterward that it was a welfare check and that her family feared she would bleed to death. Records the Electronic Frontier Foundation later obtained tell it differently. The file was an open death investigation into a "non-viable fetus." Investigators asked the district attorney whether they could charge her and were told Texas law does not allow charging the woman. The person who reported her was not her family but a partner later charged with assaulting her. She was never charged with anything. Most of what Flock changed on Thursday comes down to making an officer write down a reason. The sergeant in Texas wrote one down. [We wrote in July about what one of these cameras actually does](https://www.freshfromcache.com/what-is-a-flock-camera/). What is new is that you can go looking. Haveibeenflocked.com will tell you whether an officer typed your plate in and what reason they gave. This only works for the agencies whose logs somebody has already pried loose, so a clean result there doesn't prove anything. Deflock.org maps the cameras people have found and spotted, which makes it uneven by definition. More than 1,500 agencies publish a transparency portal, though Flock keeps no directory of them, so you find your town's by searching for it. There is no opt-out for you personally. The only one that exists is your city council. That is where the contract gets signed, and it usually passes in a batch of routine business that gets approved in one vote, with nobody saying a word about it. Sources: [Flock Safety](https://www.flocksafety.com/blog/flock-guardrails-address-lpr-privacy-concerns-and-police-transparency?ref=freshfromcache.com) and [Electronic Frontier Foundation](https://www.eff.org/deeplinks/2025/10/flock-safety-and-texas-sheriff-claimed-license-plate-search-was-missing-person-it?ref=freshfromcache.com) ## Half a million Camrys can lose the dashboard and the turn signals together Toyota is recalling 508,354 Camrys in the United States from the 2025 and 2026 model years. Toyota's global number is about 655,000\. The other 147,000 or so were sold in other countries. The paperwork calls them Camry Hybrids, which throws people off, but every Camry sold here since the 2025 redesign is a hybrid. If you have a 2025 or 2026 Camry this means you. On some of them the 7-inch instrument display comes up blank when you start the car. In the filing's words, "the turn signal lamps, the hazard lamp function, and certain warning buzzers (including the key left in ignition and the driver/passenger seat belt reminders) do not function." It happens at startup, at random, and not while you are driving. The catch is that if it does happen you drive that whole trip with no turn signals until you shut the car off and start it again. Nothing has to be replaced. A dealer updates the software on the display, free. It is not an over-the-air update, so it does mean a trip in. Toyota starts mailing owner letters September 21 and expects to finish by October 5. Don't wait for the letter. Put your license plate or your VIN into Toyota.com/recall, or call Toyota at 1-800-331-4331\. If your dashboard has ever come up dark on startup, say so when you go in. It may well have been this. But a blank cluster on these cars also turns up in two other open Toyota recalls and in something as ordinary as a dying 12-volt battery. So have them run your VIN against all of it rather than assuming one update covers everything. It is easy to forget [how much of a new car is software now](https://www.freshfromcache.com/your-car-grades-your-driving/). Source: [Toyota USA Newsroom](https://pressroom.toyota.com/toyota-recalls-certain-model-year-2025-2026-camry-vehicles/?ref=freshfromcache.com) That's the week. If one of these four is somebody you know's problem, send it to them. If you are new here, [Start Here](https://www.freshfromcache.com/start-here/) collects the pieces worth reading first, and [the Tuesday email](https://www.freshfromcache.com/newsletter/) carries the whole week in one place. ### Do you need antivirus, or is Windows Defender enough? URL: https://www.freshfromcache.com/do-you-need-antivirus/ Last updated: 2026-08-13T10:59:59.000Z There is a red banner in the corner of your screen. It says your antivirus subscription expired, and it has been saying so for a while now. You feel a little guilty every time you see it. Then you close the window and go back to what you were doing. No need to feel guilty, the computer has been protected the whole time. Windows 10 and Windows 11 both include Microsoft Defender Antivirus. It is on by default, it updates itself along with Windows, and it is not a trial that runs out. If you have been paying somebody else for an antivirus, you have been buying a second one. ## What the research found Three independent labs test antivirus software on Windows and publish the results for free. AV-TEST in Germany, AV-Comparatives in Austria, and SE Labs in the UK. They collect real malware, run it at real products on real machines, and score what happens. AV-Comparatives states that taking part in its public tests is free of charge, and Microsoft has been in those tests since 2007\. Defender is measured against the same paid products on the same tests. Here is the most recent round, checked in August 2026. AV-TEST, May and June 2026\. Sixteen home security products on Windows 11, all at their default settings. Defender caught 100 percent of the brand-new "zero-day" samples in both months (224 of them) and 100 percent of the 11,772 widespread samples. Perfect score for protection, perfect score for usability. They scored 5.5 out of 6 for performance, which cost it half a point and still earned the TOP PRODUCT award. AV-Comparatives, February through May 2026\. Twenty products, 400 live malicious websites. Kaspersky blocked 399\. Bitdefender blocked 398\. Avast, AVG and Norton blocked 397\. Microsoft Defender blocked 396\. Nobody blocked all 400, and it only takes one to ruin your week, so read that as a field that is close rather than a field that is finished. Four months of live threats separated first place from free by three websites. That same test counts false alarms, meaning the times a product blocks something clean and harmless. Those matter, because a program that cries wolf teaches you to click past its warnings. Defender wrongly blocked zero clean files or sites, the best result of all twenty products. Total Defense was second with one, then ESET with two, then Kaspersky and VIPRE with three each. The average across the field was eight. Trend Micro blocked 83. SE Labs, April through June 2026\. Defender earned AAA, the top award, with 98 percent total accuracy, sitting alongside Kaspersky, McAfee, Sophos, Norton, Avast, Panda and Scanguard. ## Where the paid products still win The paid products do sometimes earn their place. The paid products typically don't need an internet connection to function. Defender leans hard on Microsoft's cloud to check whether a file is dangerous. In AV-Comparatives' March 2026 test of 10,000 malware samples, Defender's online protection rate was 99.93 percent. Its offline detection rate was 89.2 percent. Bitdefender managed 97.6 percent offline, G DATA 97.8, F-Secure 98.6\. If a machine spends any significant time off the internet, one of the paid options would be worth looking at. They also do better against a targeted attack, which is a person working their way into one specific computer with hacking tools rather than malware sprayed at everybody at once. SE Labs builds those by hand and runs them at each product. Only Kaspersky and Malwarebytes stopped every one. Defender missed a few. So did most of the field. Most home computers stay online, and almost nobody gets singled out by a person. Both gaps are still real, and any review claiming the free one wins on every measure has not read the tests. ## Follow the money So why does everything you find when you go looking say otherwise? Start with the laptop. That trial in the corner of the screen is a paid placement. McAfee's own annual report filed with the Securities and Exchange Commission spells it out. The company pre-installs a 30-day free trial with: - Dell - HP - Lenovo - Asus - Fujitsu - Samsung The annual report also says "in some cases, PC OEMs preinstall a one-year or longer subscription and the OEM pays McAfee a royalty." The same filing shows $188 million spent in a single year on product placement fees and marketing development funds paid to its sales channel. The trial is on your computer because it bought its way in. Then there are the reviews. Nearly every "best antivirus" page and comparison site earns a commission when you click through and subscribe. That is a legal, disclosed, ordinary arrangement. It means the page makes money when you buy something and nothing at all when you decide you are fine as you are. Last, the renewal. The price on the offer is the introductory price. Norton's own subscription terms say the price quoted "is valid for the offered introductory term," after which the subscription bills at the applicable renewal price. That renewal is why a lot of people are paying today without even noticing. Since this one is about who gets paid, here is our side of it. Fresh From Cache earns nothing if you buy an antivirus and nothing if you cancel one. ## Who should still pay Somebody in the house clicks everything. If a family member installs whatever a pop-up suggests, a stricter product with heavier web filtering and better offline detection is a good reason to pay. You want the bundle and would buy the parts anyway. The paid suites include a password manager, cloud backup, a VPN and parental controls. If you would pay for those separately, a bundle can come out ahead. Price it against the renewal, not the first year. The machine cannot be kept current. An old system that no longer gets updates is a different problem, and a product with strong offline detection helps. Fixing the updates helps more, and [patching is the new password](https://www.freshfromcache.com/patching-is-the-new-password/) explains why. A small business is a separate question, and the consumer answer does not transfer. If you have employees, what you actually need is managed detection with somebody watching a console, not a home antivirus subscription multiplied by six. Consumer Defender has no central reporting and nobody reviewing the alerts. AV-Comparatives and AV-TEST both run entirely separate business test series for that reason. Six copies of anything, free or paid, with nobody minding them is not a security program. On phones and Macs the answer is shorter. macOS and Android both include their own protection, and paid phone antivirus apps mostly sell you a scan and a scare. The real risk on a phone is a link in a text message, and a scanner does not stop you from tapping it. ## The uncomfortable part The FBI's Internet Crime Complaint Center published its 2025 figures this year. Americans reported $20.877 billion in losses. Tech and customer support fraud, meaning the fake pop-up and the phone call that follows it, accounted for $2.13 billion of that. Malware accounted for $19.4 million. For people over 60 the split is wider. Tech support fraud took $1.04 billion. Malware took $3.4 million. Almost every dollar is lost to somebody handing it over to another person over the phone. No scanner, free or paid, blocks a phone call. What does help, roughly in order: 1. Keep Windows, your browser and your apps updated. 2. Use a password manager, so one breach does not open every account. ([Start here.](https://www.freshfromcache.com/start-using-a-password-manager/)) 3. Turn on multi-factor authentication for your email and your bank. 4. Never paste a command somebody gave you into a Windows box, and never let a caller take remote control of your screen. That is the modus operandi behind [the fake CAPTCHA scam](https://www.freshfromcache.com/fake-captcha-scam/). 5. Hang up on the pop-up. Microsoft is blunt about this on its own scam page, its error and warning messages never include a phone number. We covered the takedown of one of those operations in [police take down major pop-up scams](https://www.freshfromcache.com/fake-update-scam-taken-down/). 6. Back up your files, because that is the only real recovery from ransomware. ([Do you need backups?](https://www.freshfromcache.com/do-you-need-backups/)) Which scanner you use comes in somewhere after all of that. ## What you can do now Work these in order. Step one is the safety rail, so nothing gets uninstalled until you have seen for yourself that Defender is on. ### 1\. Confirm Defender is on Click Start, type "Windows Security," and open it. On the "Security at a glance" page, click "Virus & threat protection." ![The Windows Security home screen, Security at a glance, with Virus and threat protection at the top left.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/security-at-a-glance.png) Look under "Virus & threat protection settings." It should say "No action needed." Then look under "Virus & threat protection updates." It should say the security intelligence is up to date, with a recent time next to "Last update." ![The Virus and threat protection page showing no current threats, protection settings with no action needed, and a recent security intelligence update.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/virus-and-threat-protection.png) If you want to be sure, click "Protection updates," then "Check for updates." Defender updates itself several times a day, so a "Last update" from this morning is normal, not a coincidence. ![The Protection updates page showing the security intelligence version, the last update time, and the Check for updates button.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/protection-updates.png) If a paid product is installed and running, Windows names that product on this page instead of Defender. That is expected, and it is the thing you are about to change. ### 2\. Check the two controls people miss Still under "Virus & threat protection settings," click "Manage settings" and scroll down past real-time protection, cloud-delivered protection and automatic sample submission. Tamper Protection is the fourth one down, and it stops malware from switching your protection off. On a home Windows 11 machine it is normally already on. If you cannot find it at all, the machine is probably managed by an employer. Microsoft's own instructions only apply to a home user or somebody who is not subject to settings a security team controls. On a work laptop it is either hidden or greyed out, and that is your IT department's call, not yours. Now go back and click "App & browser control," then "Reputation-based protection settings." ![The App and browser control page in Windows Security, with Reputation-based protection settings below Smart App Control.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/app-and-browser-control.png) Scroll to "Potentially unwanted app blocking" and turn it on, then tick both "Block apps" and "Block downloads." ![The Potentially unwanted app blocking control turned on, with Block apps and Block downloads both ticked.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/potentially-unwanted-app-blocking.png) This is the control that catches the toolbars and junk installers that ride along with free downloads, and it is the one most likely to be sitting off. ### 3\. Consider ransomware protection, with a warning Back in "Virus & threat protection," scroll to "Ransomware protection" and click "Manage ransomware protection." ![The Virus and threat protection page scrolled to Ransomware protection and the Manage ransomware protection link.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/manage-ransomware-protection.png) Controlled folder access locks your Documents, Pictures and Desktop so unrecognized programs cannot rewrite them. ![The Ransomware protection page with Controlled folder access turned on.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/controlled-folder-access.png) Microsoft leaves it off by default because it also blocks legitimate programs, and you have to allow those by hand when it does. If you have photos you would hate to lose, turn it on and expect to allow a few programs. If a surprise block would panic you, leave it off. ### 4\. Find out what you are actually paying, and where Sign in to the vendor's account page and look for the subscription and its renewal date. Then check your card or bank statement for the real charge, because the price on the account page and the price on the statement are not always the same. One more place to look. Some subscriptions bill through the Microsoft Store or an app store rather than the vendor, and those get cancelled where you bought them, not on the vendor's website. This matters for the refund in step six, because McAfee only refunds what you bought from McAfee. ### 5\. Cancel, then remove the software properly Turn off auto-renewal in your account first. Then uninstall. On Windows 11 that is Settings, then "Apps," then "Installed apps." On Windows 10 it is Settings, then "Apps," then "Apps & features." Find the product in the list and choose Uninstall. An ordinary uninstall leaves drivers and services behind, which is why both major vendors publish a cleanup tool. McAfee's is [MCPR, the McAfee Consumer Product Removal tool](https://download.mcafee.com/molbin/iss-loc/SupportTools/MCPR/MCPR.exe?ref=freshfromcache.com). Norton's is the [Norton Remove and Reinstall tool](https://support.norton.com/sp/en/us/home/current/solutions/kb20080710133834EN?ref=freshfromcache.com), listed on their site as the Norton 360 Remover. Download either from the vendor's own site, never from a search ad, and run it after the uninstall. Restart when it asks. ### 6\. Ask for your money back Norton's own policy gives a full refund within 60 days of an annual payment, and each annual renewal payment qualifies on its own. Monthly subscriptions get 14 days. McAfee's published policy has two windows. Annual subscribers get a full refund if they ask within 30 days of buying. If the subscription auto-renewed, McAfee refunds the most recent renewal charge in full if you ask within 60 days of being charged. Three things to know before you call. McAfee does not prorate, so there is no partial refund for the months you did not use. Monthly subscribers are not eligible for the 30-day guarantee. And it has to be a product you bought from McAfee, so a subscription bought through an app store or a retailer goes back to whoever sold it. McAfee handles refunds by phone or chat only, so there is no button for this in your account. Norton takes it through support as well. You do not need a story. "I would like a refund of my most recent renewal under your refund policy, and please confirm auto-renewal is off" is the whole script. One thing to expect. McAfee's own policy says that after you get the refund you have to uninstall the software, which you already did in step five. ### 7\. Check that Defender took over Open Windows Security again and go to "Virus & threat protection." It should now name Microsoft Defender Antivirus, with real-time protection on and a recent update. Microsoft's own documentation says Defender re-enables itself once the other product expires or is removed. This is where you confirm it actually did. ## One more thing If you have been paying for this for years, you were not being foolish. You were doing the responsible thing with the information you had. For a long stretch of the 2000s the free option really was worse. It changed. Nobody had a financial reason to tell you. **Sources** Test results: [AV-TEST home Windows results](https://www.av-test.org/en/antivirus/home-windows/?ref=freshfromcache.com) (May and June 2026 cycle) · [AV-Comparatives Real-World Protection Test, February to May 2026](https://www.av-comparatives.org/tests/real-world-protection-test-february-may-2026/?ref=freshfromcache.com) · [AV-Comparatives Malware Protection Test, March 2026](https://www.av-comparatives.org/tests/malware-protection-test-march-2026/?ref=freshfromcache.com) · [SE Labs Home Anti-Malware Protection, April to June 2026](https://selabs.uk/reports/endpoint-security-eps-home-2026-q2/?ref=freshfromcache.com) · [AV-Comparatives funding statement](https://www.av-comparatives.org/funding/?ref=freshfromcache.com) Microsoft: [Defender Antivirus compatibility](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-compatibility?ref=freshfromcache.com) · [Controlled folder access](https://learn.microsoft.com/en-us/defender-endpoint/controlled-folders?ref=freshfromcache.com) · [Manage tamper protection on an individual device](https://learn.microsoft.com/en-us/defender-endpoint/manage-tamper-protection-individual-device?ref=freshfromcache.com) · [Tech support scams](https://learn.microsoft.com/en-us/defender-endpoint/malware/support-scams?ref=freshfromcache.com) The money: [McAfee Corp. annual report (Form 10-K, fiscal 2021)](https://www.sec.gov/Archives/edgar/data/1783317/000095017022001804/mcfe-20211225.htm?ref=freshfromcache.com) · [Norton subscription and refund terms](https://us.norton.com/products/norton-360-deluxe?ref=freshfromcache.com) · [McAfee refund policy](https://www.mcafee.com/support/s/article/000001679-refund?language=en%5FUS&ref=freshfromcache.com) Losses: [FBI Internet Crime Complaint Center, 2025 Internet Crime Report](https://www.ic3.gov/AnnualReport/Reports/2025%5FIC3Report.pdf?ref=freshfromcache.com) ### Can somebody steal a passkey? URL: https://www.freshfromcache.com/can-passkeys-be-stolen/ Last updated: 2026-08-12T10:59:59.000Z Palo Alto Networks has a threat research group called Unit 42, and on August 3 one of its researchers published a paper describing three new ways to attack passkeys. The researchers nicknamed them Pass-ta-key. The coverage that followed used words like "cracked" and "master key," and if you met one of those headlines in a Facebook feed you would reasonably conclude that passkeys are finished. They are not. A passkey is the login that uses your face, fingerprint, or device PIN instead of a password, and I have told you here more than once to [turn them on](https://www.freshfromcache.com/what-the-heck-is-a-passkey/). I still would. The research is real though, and one piece of it is genuinely unpleasant. ## Somebody has to already be on your computer The paper says it in its own disclaimer. All three attacks rely on malware already running on the victim's device. The scope is narrower still. This is Google Password Manager, in Chrome, on Windows, on a machine with a TPM security chip. Not an iPhone, not a Mac, not an Android phone. ![Diagram titled All five have to line up, listing five conditions joined by and: you are on a Windows PC, you sign in using Chrome, your passkeys sync through Google Password Manager, that PC has a TPM security chip, and malware is already running on it as you. A navy band below reads: and if that last one is true, your saved passwords and open sessions were already gone.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-prerequisites.png) Every condition has to be met before any of this reaches you. Which does a lot of work. If someone is running their own software on your computer as you, they can already read the passwords saved in your browser, ride the sessions you are signed into, and watch the bank tab you left open. The passkey did not fail in that scenario. The computer was already compromised. ## What the researchers actually did Three attacks, in increasing order of damage. The first one signs the attacker into your account with nothing appearing on your screen. It only works against websites that skip a check they are supposed to do, confirming that a person was actually verified. Unit 42 tried it on GitHub, which checked and refused. It tried eBay, which did not check and let the login through. eBay fixed that gap after being informed. The second one convinces Google's service that the attacker's own computer just passed your fingerprint check. That buys reusable access from the attacker's machine, and your computer does not even have to be turned on for it. The third one pulls out the single key that encrypts every synced passkey on the account. With that key in hand, an attacker can unlock all of them. None of this breaks the cryptography, and Unit 42 says so plainly in its conclusion. The attacks go after the software around the passkey, mostly how Chrome sets a device up and what it leaves sitting in memory while it does. ## The third one does not clean up I am not going to soften this one, because it is the reason the research matters beyond a headline. Google removed that master key from Chrome's debug log after the researchers reported it. The key still reaches your computer, though, and it still sits in memory for a moment during setup. In Google's current design there is no way to rotate it or revoke it. If someone got a copy, removing the malware does not take it back. Making fresh passkeys does not either, because the new ones are protected by the same key. So if a Windows PC of yours gets hit by an information stealer, treat it as an account emergency and not just a computer cleanup. ## What this research does not cover Apple's iCloud Keychain, Microsoft's own passkey sync, passkeys held in 1Password or Bitwarden, hardware keys like a YubiKey, and passkeys on your phone were all outside this work. Unit 42 notes that other companies use a similar cloud design, so some of the same questions may apply. It did not test them. Google answered the researchers in Chrome's public bug tracker and made one change there. As of August 2026 I have not found a statement from the company about the research itself. No CVE either, which is the tracking number a specific product flaw usually gets. Unit 42 describes its own testing under responsible disclosure, and I have not found a report of these techniques being used against a real person. That being said, it doesn't mean it has not happened. ## Where passkeys really are weak The soft spot has never been the passkey itself. It is the door beside it. Almost every site that offers you a passkey leaves the password turned on as a fallback, and leaves the old reset path in place behind that. If your account can still be recovered with a code texted to your phone, then the passkey is the deadbolt and that code is the key under the mat. Criminals have noticed. Security researchers at Push Security documented phishing kits that offer a victim a phishable sign-in choice instead of letting the passkey run. That's all it takes because the attacker only has to find the weakest method that still works. That is the same argument as [the selfie video Google wants for account recovery](https://www.freshfromcache.com/google-wants-a-video-of-your-face/), and it is why [the extra step at login](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/) still earns its annoyance. ## What to do about it - **Keep the computer clean and patched.** Automatic updates on, real protection running, and a healthy suspicion of anything that tells you to copy and paste a command to fix a problem. [Patching is the closest thing to a password these days](https://www.freshfromcache.com/patching-is-the-new-password/), and a machine that has [started acting strange](https://www.freshfromcache.com/why-is-my-computer-slow/) deserves a look. Most infections arrive through [a fake update prompt](https://www.freshfromcache.com/fake-update-scam-taken-down/) or a poisoned download. - **Check the recovery path on your email account.** Whoever can reset your email can reset almost everything else. If the only way back in is a text message, add an authenticator app or a second passkey. - **If you think a Windows PC is already infected, do the account work somewhere else.** Changing a password on the infected machine hands the new one straight over. Use a different device, change what matters, sign out all sessions, then clean or rebuild the sick computer. [The order of operations after any compromise](https://www.freshfromcache.com/what-to-do-after-a-scam/) is most of the battle. - **A hardware key is for people who are actually targeted.** Reporters, executives, anyone managing money or systems for other people. It never syncs to the cloud, so none of this applies to it. For most readers it is a nice-to-have and not a requirement. Nothing from these findings would dissuade me from still recommending passkeys. The next time a site offers you a passkey, take it. Then give the computer you are on the same attention. On a machine somebody else is running, every login you own is already in play. Sources - Arie Olshtein, Unit 42 (Palo Alto Networks), [Pass the Passkey: A Novel Attack Surface in Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/?ref=freshfromcache.com), August 3, 2026 - BleepingComputer, [New Pass-ta-key attacks let malware hijack Google-synced passkeys](https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/?ref=freshfromcache.com), August 3, 2026 - The Hacker News, [Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts](https://thehackernews.com/2026/08/google-password-manager-attacks-could.html?ref=freshfromcache.com), August 3, 2026 - The Hacker News, [Sneaky 2FA Phishing Kit Adds BitB Pop-ups Designed to Mimic the Browser Address Bar](https://thehackernews.com/2025/11/sneaky-2fa-phishing-kit-adds-bitb-pop.html?ref=freshfromcache.com), November 2025, on passkey downgrade attacks, citing Push Security ### This week: AI in your exam room, and a delete with no undo URL: https://www.freshfromcache.com/newsletter/before-you-say-yes-at-the-clinic/ Last updated: 2026-08-11T14:59:59.000Z Good morning! Somebody wants a yes out of you, and the yes is always easier to give than to take back. Two of the pieces below are about that. The clinic asks you out loud. The location app asked once, years ago, and has not asked since. **In this issue:** - [Your doctor wants to record the visit with AI](https://www.freshfromcache.com/should-you-let-ai-record-your-doctor-visit/) - [Your phone says storage is almost full. Don't delete anything yet.](https://www.freshfromcache.com/why-is-my-phone-storage-full/) - [What you agreed to when you turned on location sharing](https://www.freshfromcache.com/what-location-sharing-actually-shares/) - [The AI boom is showing up on price tags](https://www.freshfromcache.com/why-your-next-phone-costs-more/) - [Also this week: your location, an AI shopper in court, and California's AI labels](https://www.freshfromcache.com/also-this-week-2026-08-07/) - [Five shortcuts I wish somebody had told me about](https://www.freshfromcache.com/hidden-phone-and-computer-shortcuts/) - Plus: three things going around right now - And the Scary Headline of the week: a second AI company says its model hacked somebody --- [**Your doctor wants to record the visit with AI. Here is what to ask before you say yes.**](https://www.freshfromcache.com/should-you-let-ai-record-your-doctor-visit/) The clinic will tell you the tool is HIPAA compliant, and that sentence does less work than it sounds like. HIPAA governs how your information gets handled once it exists. Nothing in it requires anybody to ask you before a microphone turns on in the room. How much say you have is determined by your state's recording law. Declining is ordinary, and the notes get written the old way. There are four questions to ask your provider in the piece, and they are the same four whether you end up saying yes or no. *Learn* --- [**Your phone says storage is almost full. Don't delete anything yet.**](https://www.freshfromcache.com/why-is-my-phone-storage-full/) The usual advice is to delete some photos, and on the wrong phone that advice destroys the only copy you own. Answer one question first. Is this phone actually backing up, or does it only look like it is. And if your iCloud storage is already full, photos you delete skip Recently Deleted altogether and are gone the moment you tap. Check the backup, then work through the cleanup in the order the piece lays out. *Learn* --- [**What you agreed to when you turned on location sharing**](https://www.freshfromcache.com/what-location-sharing-actually-shares/) Two people agreed. Three parties are involved, and the third behaves very differently depending on whose app you use. Apple throws the shared location away after a day. Life360 built a business on movement data and says so in its own policy. Monday's piece walks through the four things to check, whichever app you use. *Blog* --- [**The AI boom is showing up on price tags**](https://www.freshfromcache.com/why-your-next-phone-costs-more/) AI data centers are buying memory chips faster than anybody can make them, and the shortage has reached store shelves. Budget phones feel it worst, since memory makes up more of a cheap phone's cost than a flagship's. And some of it does not show up on the price at all. A device keeps its old price and comes with a little less inside. *Learn* --- [**Also this week: your location, an AI shopper in court, and California's AI labels**](https://www.freshfromcache.com/also-this-week-2026-08-07/) Four stories from the week I did not write a full piece about. The story to act on is the final one. Google is shutting off Assistant on phones September 4. *News* --- **If you only read one:** the doctor visit piece. This is going to come up for nearly everybody sooner or later, and knowing what is actually happening is what lets you make the call for yourself. --- ### 5-Minute Tech Tip [Five shortcuts I wish somebody had told me about](https://www.freshfromcache.com/hidden-phone-and-computer-shortcuts/). Start with the spacebar. When you have a typo six words back and tapping at it keeps putting the cursor in the wrong spot, press and hold the spacebar instead. The keyboard goes blank and turns into a trackpad, and your thumb walks the cursor one character at a time. That one and four more, all things your phone and computer have been able to do for years without telling you. --- ### Fresh Trouble **"Learn to trade" pitches.** Posts full of fancy cars and exotic trips promising you the same life if you sign up to learn trading. The FTC says it flatly. Trading is risky, nothing is guaranteed, and the money can go fast. ([FTC](https://consumer.ftc.gov/consumer-alerts/2026/08/how-spot-investment-training-scams-social-media?ref=freshfromcache.com)) **Government callers with paperwork.** A call showing a real agency on the caller ID, using a real employee's name, backed up with official-looking documents. Nobody from a government agency will open by asking you to pay. ([FTC](https://consumer.ftc.gov/features/how-avoid-imposter-scams?ref=freshfromcache.com)) **Fake Facebook suspension warnings.** A message saying your account closes for fraudulent activity unless you confirm your details. Open the app yourself and check your notifications there. --- ### Scary Headline of the Week *"Meta's Muse Spark 1.1 hacked an external organization during cybersecurity test"* Meta ran its newest model through a hacking test with an outside firm, in a sandbox built to keep it off the internet. A configuration mistake gave it internet access anyway, and it used that access to break into some other company's systems. Nobody has said whose. If that sounds familiar, it is the fourth one in about a month. OpenAI's agents got out and hit Hugging Face, which I wrote about earlier this month. Anthropic disclosed two. Now Meta. Three different labs, and every single time the explanation has been that the test environment was set up wrong. None of these have been the consumer model. These are research systems inside company networks, and the models were chasing answers to a test rather than going after a target. Hugging Face says the models and files the public downloads were never touched. **The verdict:** Nothing here to act on, but a worrying trend. Four in a month isn't a coincidence, and "we misconfigured the test" is starting to sound like a phrase rather than an explanation. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help: forward this email to one person who might want it, and if it was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. --- Which of the five shortcuts had you never heard of? Hit reply and let me know. Joel ### A colon cancer test company got breached. If you took Cologuard, expect a phone call. URL: https://www.freshfromcache.com/cologuard-data-breach/ Last updated: 2026-08-11T10:59:59.000Z If you ever mailed a Cologuard sample back in a prepaid box, the company that processed it has been broken into, and the stolen data is already public. Exact Sciences makes Cologuard, the at-home colon cancer screening test. Abbott bought the company in March. Have I Been Pwned added the Exact Sciences breach on Friday, August 7\. The published file holds 10.9 million unique email addresses, along with names, dates of birth, genders, phone numbers, home addresses and health information belonging to customers, patients and healthcare providers. Abbott has confirmed the incident. Its August 5 update says "some of the impacted files contain personal information and/or personal health information," and that it is still reviewing the data before making any required notifications. Abbott has since filed an initial breach report in at least one state, listing a single affected resident there and a notice date of August 5\. The wider round of letters has not gone out yet. ## One phone call opened the door Abbott has been specific about how this started. It was a vishing attack, not a ransomware event. Vishing is phishing done by voice. Somebody calls an employee, sounds like the help desk or a coworker, and talks them into handing over a login. With that login, the data was copied and carried out. ## What was actually taken Abbott has not itemized the data yet, so this splits into two lists. Confirmed and sitting in the published file, according to Have I Been Pwned, are: - Names - Dates of birth - Genders - Email addresses - Phone numbers - Physical addresses - Personal health data ![The Have I Been Pwned entry for the Exact Sciences data breach, showing a Sensitive Breach label, 10.9M affected addresses, and the list of compromised data types](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-hibp-exact-sciences.jpg) Have I Been Pwned lists the breach as sensitive, which is why searching from its front page will not show it to you. Abbott has not said whether test results were included, and until it does, nobody can say either way. It also has not named which of its cancer tests the records came from, only that they came from its Cancer Diagnostics business. Claimed by the group that stole it, ShinyHunters, but unconfirmed elsewhere: - More than 30 million rows of personal information - Over a million Social Security numbers - 22 million client notes containing doctor and patient conversations - 20 million medical order records Those numbers come off an extortion site, from people whose business is making a haul sound enormous. Treat them as unverified until Abbott publishes its own accounting. ## The real risk is a very good phone call A credit freeze is most people's reflex after a breach, but that isn't the most helpful in this case. A home address does not open a credit card. What sits in the stolen files is a list of adults, most of them 45 and older because that is who Cologuard is for. The list contains real names, real birthdays, real phone numbers, and one private fact attached, that they were screened for cancer. That combination is a script. Somebody calls, gets your name and date of birth right, and mentions the test. They'll say there is a problem with your result or your billing. Every detail checks out, because every detail was stolen. The details being right is what gets you to believe the vishing attempt. The same list works by email, and a fake patient-portal notice is the easy second act. Our [phishing guide](https://www.freshfromcache.com/how-to-spot-a-phishing-email/) covers what those look like. The FTC put out an alert on August 3 about the people who make a living off breach victims, buying lists of people who have already been taken and calling back to offer help getting the money returned. Its advice fits this week. Look up the contact information yourself, and "Don't use any number they give you." ## What to do this week - **Check Have I Been Pwned, but sign in to do it.** This breach is flagged sensitive, so it will not turn up in the search box on the front page. You have to verify the address is yours first, through the dashboard or the notification email. A hit means your email was in the file. It does not tell you which of your other details came with it. - **Check the letter yourself when it arrives.** Look up Abbott's contact information on your own, then ask whether the letter is real, rather than whether Abbott mailed it. Companies hire outside firms to print and send breach notices, so a real letter can show up from a name you have never heard of. We wrote about that exact problem in [That sketchy letter from your hospital might be real](https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/). Nothing Abbott has published so far carries a phone number for customers. - **Expect the call to be convincing, and hang up anyway.** Do not confirm a birthday, do not answer a security question, do not do anything that has to happen while they have you on the phone. Hang up, find the number yourself, call back. If the call was real, calling back costs you nothing. Screening your calls helps too, and there are [controls on your phone for that](https://www.freshfromcache.com/stop-spam-calls/). - **Freeze your credit if you want to, but know what it buys.** A freeze is free and reversible and it blocks somebody from opening new accounts in your name. Nothing financial has been confirmed stolen here, and a freeze doesn't help with a phone call. If Abbott's letter tells you your Social Security number was in the file, [freeze](https://www.freshfromcache.com/freeze-your-credit/) and do not think twice. Otherwise it is a good habit, but not an urgent step. - **Read your Explanation of Benefits statements.** There is no freeze for medical records. Medical identity theft usually shows up as a bill or an insurance statement for care you never received, and the FTC's [page on it](https://consumer.ftc.gov/articles/what-know-about-medical-identity-theft?ref=freshfromcache.com) walks through what to do next. ## This is not a reason to skip screening You mailed the box because your doctor asked you to, and that was the right call. Colorectal cancer screening saves lives and a break-in at a lab does not change that. What it does change is how you treat your phone calls. For the next several months, someone out there may know your name, your birthday, your address and one private fact about your health. If somebody with that combination calls you, the fact that they know everything is the reason to hang up. If somebody already got you on a call like this, [start here](https://www.freshfromcache.com/what-to-do-after-a-scam/). **Source:** [Abbott statement on cyber incident in Cancer Diagnostics business](https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business?ref=freshfromcache.com) **The breach entry:** [Have I Been Pwned, Exact Sciences](https://haveibeenpwned.com/Breach/ExactSciences?ref=freshfromcache.com) **Reporting:** [The Register](https://www.theregister.com/cyber-crime/2026/08/07/shinyhunters-called-cancer-diagnostics-biz-and-tricked-staffers-into-giving-them-access-now-theyve-dumped-109m-email-addresses/5284857?ref=freshfromcache.com) and [BleepingComputer](https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/?ref=freshfromcache.com) **The FTC:** [Have you lost money to a scam?](https://consumer.ftc.gov/consumer-alerts/2026/08/have-you-lost-money-scam-watch-scammers-who-say-they-can-help?ref=freshfromcache.com) and [What to know about medical identity theft](https://consumer.ftc.gov/articles/what-know-about-medical-identity-theft?ref=freshfromcache.com) ### Two people agreed to your location sharing. Three are in it. URL: https://www.freshfromcache.com/what-location-sharing-actually-shares/ Last updated: 2026-08-10T10:59:59.000Z I do not share my location with anyone. That sounds more principled than it is. Nobody ever asked me. My family is not close enough for it to come up, so I have never had to sit across from someone I love and say no. I got to skip the hard part. A reader put it to me a different way. She does not share with anyone either, not even her husband, and not because she has anything to hide. Her words were that it feels like a door that does not need to be opened. So I went looking for what I would have been agreeing to. This article isn't going to tell you if you should or shouldn't share your location. That is your call and I wouldn't second-guess it. Every family, and every relationship, is different. Most of the people I know do it and they give good reasons. What I wanted to know is who else is peeking at your location. ## Location tracking isn't just monitoring We should begin with the positive side, because the motivations behind sharing your location are genuinely valid. There are conveniences. For example, your spouse knows you will be home in fifteen minutes and begins preparing dinner, or you are stuck in a meeting and cannot answer, and no one is left guessing. Your child recently earned their driver's license, and seeing their status indicator confirms they arrived safely at practice. Location tracking used in this way is a form of unspoken communication. A reader described it better than I could. Opening the app to see where her husband is takes less out of her day than texting him and waiting on a reply, and it works when he is driving and cannot answer at all. The arguments for personal safety are equally compelling. Keeping tabs on an elderly parent facing early memory lapses, locating a phone misplaced at a restaurant, or checking on a teenager driving home through a rainstorm are all genuine arguments for the use of this technology. ![Headlights of an oncoming car on a wet road at night.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-headlights-in-the-rain.jpg) The reason most people turn it on. Photo: Marcus Bellamy via Unsplash. Typically when we want a new service, we tap the agreement button right when we urgently require it. Then we use it continuously, and never take the time to review the terms we accepted. It is a universal habit that applies to everyone, including myself. ## 3-way consent Two people agreed to this. Three people are in it. You and your daughter. You and your husband. That is the arrangement you think you set up, and it is the one you agreed on. But her phone does not hand its location to your phone. It hands it to a company, and that company passes it along to you. It also keeps a copy, decides how long to keep it, and decides who else gets to see it. Who gets to see it depends enormously on which company is providing the service. These products are not interchangeable, and the difference between them is wider than most people assume. ![A comparison of what Apple, Google and Life360 each keep from location sharing. Apple says your location is not accessible to Apple and deletes a shared location within 24 hours. Google's Timeline is off by default but a separate setting keeps saving location. Life360 discloses precise location and movement data to business partners for their own monetization.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-who-keeps-what-2.png) Same feature, three very different companies. The one on the bottom is the one to check. Apple collects the least of the three. If you and the person you share with are both on iOS 17 or later, Apple says your location is not accessible to Apple at all. It holds a shared location for up to 24 hours to deliver the service, then deletes it. There is no history for you to scroll back through, which some people find annoying, but that annoyance is a privacy feature. Apple's own law-enforcement guidelines say it does not have GPS information for a specific device or user. A subpoena aimed at Apple's copy of your family's movements does not give much, because there is not much to give. There is one default setting to be aware of. When the organizer of a Family Sharing group turns on location sharing, the organizer's location is shared automatically with everyone in the group, and with anyone added to the group later. Everyone else chooses who they share with themselves. The organizer is opted in by being the organizer. Google Maps sits close by. Timeline, the feature that keeps a record of where you have been, is off by default, so you have to turn it on yourself. Since 2023 the data resides on your phone rather than on Google's servers, with a three-month auto-delete as the default setting. Turning Timeline off does not mean Google stops recording where you go. It means Google stops building you a map of it. A separate setting, the one that saves your Search and Maps activity, keeps attaching your location to what you look up and where you ask for directions. So a person who turns Timeline off has closed the file they can see and left the one they cannot. ## Life360 Life360 is the app built just for location sharing. Almost 100 million people open it every month, about 52 million of them in the United States, and for a lot of American families it is the brand name that stands in for the whole category, the way coke stands in for soda. ![The Life360 app opening on a smartphone lying face up on a wooden desk beside a notebook.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-the-purple-app.jpg) Photo: Appshunter.io via Unsplash Read its privacy policy and you find that Life360 discloses "precise geolocation data, movement data, and other information" about your use of the service to select business partners for those partners' own monetization purposes. That language means advertising. The buyers are ad-targeting companies and the data marketplaces that supply them, and what they want is a pattern. Which stores you walk into, how often, at what hour, and what that suggests about your household. You paid for the map, and the pattern underneath it gets sold to somebody else. Further down, in the section covering state privacy laws, there is a line printed for Texas residents. Seven words: "We may sell your sensitive personal data." That is the current policy, updated in July 2026\. Here is how it got there. In 2021, The Markup reported that Life360 was selling precise location on its users to about a dozen data brokers. The company's own financial records showed $16 million from selling location data in 2020, close to a fifth of that year's revenue. Plus another $6 million from its deal with Allstate's driving-data arm, Arity. In January 2022 the CEO said the broker sales would stop, with two exceptions kept on purpose. Arity kept getting precise location. A foot-traffic analytics firm kept getting it too, in aggregate rather than raw. Then in June 2025, The Capitol Forum reported more than 4,600 Life360 "audience segments" for sale through a data marketplace called LiveRamp. An advertiser could buy their way to people who visit a named chain often, or to households sorted by income, by gender, and by the ages of the children in them. Life360 says no precise location goes to LiveRamp, only groupings like "visitors of brand X." Privacy lawyers argue the identifiers attached to those groupings make that distinction thin. If that sounds familiar, it is because it is [the data broker business](https://www.freshfromcache.com/what-is-a-data-broker/), running inside an app you installed on purpose. And the family app is not even the biggest source of it on your phone. In December 2024 the FTC took action against a broker called Mobilewalla, alleging it harvested location out of the ad auctions that run inside free apps, and kept it even when it lost the auction. Your weather app runs those auctions. So does the game on your kid's tablet. Turning off the family app would not touch any of that. You can opt out of having your data sold. It is in the app, under Privacy, behind a link called "Your Privacy Choices." In all of 2025, about 3.6 million people did, out of a user base approaching 100 million. And, of course, you cannot run the app without always-on location. That is part of the deal. Two things in Life360's favor, because they do matter. Its policy says it does not sell or share the personal information of members it knows to be under 18, and it does not show ads in child or teen accounts. And the crash detection people pay for has gotten real help to people in a wreck. ## Kids don't get to consent Between adults this is simple. Everyone agrees or nobody shares. When children are involved, the situation becomes far less straightforward. A twelve-year-old who does not want to be tracked has no way to decline. COPPA, the federal children's privacy law, covers kids under 13 and puts consent in the parent's hands. Above that age the law mostly speaks to what companies may do, not to what happens inside a home. The parent decides. In 2020 teenagers organized on TikTok and buried Life360 in one-star reviews, hoping to get it thrown off the App Store. They had no standing, so they used the only avenue they had. The company responded by talking to them. The CEO went on TikTok himself, and the app got a vaguer location option, built with input from the same teenagers who had been trashing it. It does not only run downhill, either. One reader told me her eleven-year-old keeps asking to see her mother's location, and keeps getting told no. Most of the girl's friends can already watch where their parents are. There is a generation coming up that expects the dot to point both ways. What the research does suggest is that how monitoring is administered matters more than whether it is done at all. Monitoring a teenager who has agreed to it is different from monitoring behind their back. [The teen safety piece](https://www.freshfromcache.com/teen-safety-features-that-work/) covers the neighboring problem. I am not a parent, so I do not get a vote here. I do know what fourteen-year-old me would have said about it, and it was not polite. If you are raising one right now, you know things I do not. ## When it is not a choice The same feature that keeps a family coordinated keeps some people trapped. A partner who insists on sharing. Who asks why you stopped at the store. Who notices immediately when the dot goes dark. On paper everyone consented. If that is your house, the ordinary advice does not apply. The National Network to End Domestic Violence is blunt about it. Some people escalate when they feel they have lost access, so before you remove a tracker or shut off sharing, think through how the other person will react and plan for that. Document what is happening first, if it is safe to. Trust your instincts about being watched. Advocates do this every day and they do it better than any article. The National Domestic Violence Hotline is 1-800-799-7233, or text START to 88788, or chat at thehotline.org. ## Sometimes the dot is doing a text message's job The most useful thing anyone told me while I was writing this came from a mother of two. She turned location sharing on for both her kids. Shortly after his sixteenth birthday, her son turned his off and called it an invasion of his privacy. It is still an open discussion in that household. But her actual complaint was not about safety. It was that he is bad at telling her where he is. During the school year, when she was working full time and he was riding the bus, that mattered to her. So I asked her directly. Would a text have been enough? She said yes. If he told her where he was, it would probably be fine. That is a different problem than the one these apps are sold to solve. The dot is not doing safety work in that house. It is doing the job a check-in would have done, and it does it without anyone having to say anything out loud. Which is easier, but also means the habit never gets built. She said one more thing that stuck with me. She and her son trust each other, and she gives her kids a lot of freedom precisely because nobody tracked her at that age. Both of those things can be true at the same time as the monitoring is running. Families don't have to be tidy. All of which raises a question I did not expect to find an answer to. Does monitoring even work? ## Being watched changes people In 2016 a researcher named Jonathon Penney looked at Wikipedia traffic before and after the Snowden disclosures. He took 48 articles matching terrorism keywords the Department of Homeland Security tracked. He found views dropped about 30 percent afterward and stayed down. Nobody was arrested for reading about car bombs. Nobody was contacted at all. Nothing happened to any of those readers. They simply learned that somebody might be looking, and it changed what they were willing to be curious about. That is a country, though, not a home. So I went looking for whether anyone has studied what this does inside a family, and the answer turned out to be yes, and older than I expected. In 2000, two researchers in Sweden named Håkan Stattin and Margaret Kerr studied 703 fourteen-year-olds and their parents. The advice at the time was the same as the advice now: keep track of your kids and they will get into less trouble. What they found was that the parents who knew the most about their children's lives were not the ones doing the most tracking. They were the ones whose children told them. Disclosure, not surveillance, was the thing that actually lined up with staying out of trouble. It held for both sexes and for kids who were and were not already in trouble. Their own conclusion was that "tracking and surveillance is not the best prescription for parental behavior." ![A card contrasting the standard parenting advice to keep track of your kids with the 2000 Swedish finding that the parents who knew the most were the ones whose children told them.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-what-worked.png) What the Swedish researchers actually found. What nobody has studied properly is location tracking specifically. A 2024 review in Clinical Child and Family Psychology Review went looking for evidence on digital location tracking in particular. It found that somewhere between a third and two thirds of American families are now doing it. They also found that the research behind it amounts to "much speculation, but minimal data." The reviewers called it a new, common, and vastly understudied parenting behavior. So the dot itself is close to unstudied. The older question, whether watching works better than being told, is not. I do not think a household is immune to this. Not because families mean any harm, generally they do not, but because the effect does not seem to care much about who is doing the watching. If being watched changes what a person reads under a government, it probably changes something under a parent. And the Swedish study points the same direction but from the other side. If what actually works is a kid choosing to tell you, then a tool that answers the question without them ever having to say anything might be solving the wrong problem. ## What to check ![A card listing four things to check on your phone: who can still see you, how to stop your data being sold, what else has your location, and where to turn off precise location.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-what-to-check.png) Four things to look at. None of them turn anything off. None of these require you to stop sharing anything. **See who can still see you.** Open the app you actually use and look at the list. - iPhone: Find My, then the People tab. - Google Maps: tap your profile picture, then Location sharing. - Life360: the Circle screen. People stay on these lists for years after the reason they were added has passed. An ex. A roommate. A trip you took in 2022. **Stop your data from being sold.** If you use Life360, open Settings, then Privacy, then "Your Privacy Choices," and turn off the sale of your information. The app keeps working. **Check what else on your phone has your location.** This is where the real volume is, and it is not the family app. - iPhone: Settings, Privacy and Security, Location Services. - Android: Settings, Location, App permissions. Anything set to "Always" that is not a family app should be changed. Most apps do what they need on "While Using." **Turn precise location off where it makes no sense.** Your weather app does not need your address. Both phones let you hand an app an approximate location instead. The question with location sharing isn't whether to turn it off or not. It is which of the three parties are doing what. Your child seeing your location is one arrangement. A company selling the pattern of your Tuesday nights is a different arrangement. If you use one of these apps, open it and take a look at who is still on your list. Then find out whether the company in the middle is making money off your data. --- **Sources** - Apple, "Find My & Privacy" (updated December 2025) and "Share your location with your Family Sharing group" (updated December 2025) - Apple, "Legal Process Guidelines: U.S. Law Enforcement" (October 2025) - Google, "Updates to Location History and new controls coming soon to Maps" (December 2023); Google Maps Help, "Manage your Google Maps Timeline"; Google Account Help, "Manage your Web & App Activity" - Life360 Privacy Policy (last modified July 10, 2026) - Life360, “Life360 Reports Record Q1 2026 Results” (May 11, 2026), for monthly active users - The Markup, "The Popular Family Safety App Life360 Is Selling Precise Location Data on Its Tens of Millions of Users" (December 2021), and the January 2022 follow-up - The Capitol Forum, "Life360: Family Safety App Selling Datasets Based on Users' Personal Information on LiveRamp's Data Marketplace" (June 2025) - FTC, "FTC Takes Action Against Mobilewalla for Collecting and Selling Sensitive Location Data" (December 2024) - NNEDV Safety Net Project, "Technology Safety Plan" - Jonathon W. Penney, "Chilling Effects: Online Surveillance and Wikipedia Use," Berkeley Technology Law Journal (2016) - Stattin H, Kerr M, "Parental Monitoring: A Reinterpretation," Child Development, 2000;71(4):1072-1085 - Davis IS, Thornburg MA, Patel H, Pelham WE, "Digital Location Tracking of Children and Adolescents: A Theoretical Framework and Review," Clinical Child and Family Psychology Review, December 2024;27(4):943-965 ### Five shortcuts I wish somebody had told me about URL: https://www.freshfromcache.com/hidden-phone-and-computer-shortcuts/ Last updated: 2026-08-09T11:00:00.000Z I work with technology for a living. I still learned three of these in the last couple of years, and every time I've had the same reaction. Not "that's clever." More like "how long has that been there!?" The answer is usually years. None of these are new. Nobody hands you a manual with a phone or a laptop. You poke around until something works, and then you quit poking. Here are five. Two on your phone, three on your computer. Only one of them has to be turned on first. What they have in common is small. Each one replaces a fiddly thing you decided to just live with. Poking at the screen trying to get the cursor between two letters. Swiping forty times to get back to the top of a feed. Aiming your mouse at the tiny X on a browser tab and missing. ## On your phone ### Your spacebar is a trackpad You are typing a message and there is a typo six words back. So you tap at it. The cursor lands in the wrong spot. You tap again. Wrong again. Stop tapping. Press and hold the spacebar instead. The letters on the keyboard go blank and the whole keyboard turns into a trackpad. Slide your thumb around and the cursor follows, one character at a time, as precise as you want. Lift your finger when it is where you want it. That is the iPhone behavior, and it works in any app with a text box. ![Three phone screens side by side: a cursor landing in the wrong spot, the keyboard with its letters blanked out and a thumb on the spacebar, then the cursor placed and the typo fixed.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/illus-spacebar-trackpad.png) Hold the spacebar, slide, lift. iPhone shown. Android depends on your keyboard. On a Samsung phone, press and hold the spacebar and you get the same thing. On Gboard, which is what most other Android phones use, you hold the spacebar and slide left or right along it, and the cursor moves along the line. Same idea, smaller range. Google has a full trackpad mode in testing, so this one may get better. ### Tap the clock to fly back to the top **iPhone only.** You scrolled a long way down a webpage, or a photo album, or somebody's feed. Do not swipe your way back. Tap the very top edge of the screen, right where the clock is. You go straight to the top. It works in most apps, including the ones Apple did not write. In Safari you usually need two taps, because the first one brings the address bar back down and the second one does the scrolling. Android does not have this. There is no built-in equivalent, and the apps that add it want accessibility access, which is more than I would hand over for a scrolling trick. Skip this one and take the other four. ## At your computer ### Your scroll wheel is also a button Push down on the scroll wheel. It clicks. Click a link with it and the page opens in a new tab behind the one you are reading. You do not lose your place and you do not have to right-click and go hunting through a menu. Open six of them off a search results page and read them when you are done. Clicking an open tab with it closes that tab. No aiming for the X. ![A computer mouse with the scroll wheel highlighted, beside two browser windows: middle clicking a link opens a new tab behind the current one, and middle clicking a tab closes it.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/illus-scroll-wheel-click.png) Middle click does two things a normal click cannot. If you are on a laptop trackpad there is no wheel to click. Holding Ctrl and clicking a link does the same background-tab trick (Command and click on a Mac). There is no trackpad equivalent for closing a tab, so that one belongs to the mouse. ### Bring back the tab you just closed Ctrl + Shift + T. On a Mac, Command + Shift + T. The tab comes back, with its history, so the Back button still works. Press it again and the one before that comes back. Chrome keeps the last ten. If the last thing you closed was a whole window instead of a tab, it brings the window back and everything that was in it. Chrome, Edge, and Firefox all use the same keys. ### Windows remembers more than just the last thing you copied Press the Windows key and V. The first time you do it, Windows asks if you want to turn on clipboard history. Say yes. From then on, that same key combination opens a list of the last 25 things you copied, and you can paste any of them. Copying three things out of one document and into another stops being three trips back and forth. Copy, copy, copy, then go paste them in whatever order you want. This one is Windows. Macs need a separate app for it. ## One thing to know about that clipboard The list of 25 does not care what you copied. If you copy a password out of an email, or an account number off a statement, it sits in that list until you restart the computer or clear it out yourself. Password managers know this and deliberately keep themselves out of it. Everything else does not. So two habits. Press the Windows key and V and pick 'Clear all' before you share your screen on a Teams or Zoom call. And copy passwords out of a password manager rather than out of an email, which is the best way anyway. ![Two women sitting outdoors laughing, one holding up a phone with a delighted expression.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/a-c-8sPY7CUF-xQ-unsplash.jpg) Photo: A C via Unsplash ## Which one to try first The spacebar. Open a text message right now, press and hold it, and slide your thumb. It takes about four seconds and you'll thank yourself. The rest will stick the same way, which is to say slowly. You will keep tapping at the screen for a while before you remember there is a better way. That is normal. I still aim for the little X sometimes. Did somebody teach you one of these, or did you find it by accident like the rest of us? Tell me which one, and which one you had never heard of. joel@freshfromcache.com ## Sources - Apple, *Type with the onscreen keyboard on iPhone* (spacebar trackpad): [https://support.apple.com/guide/iphone/type-with-the-onscreen-keyboard-iph3c50f96e/ios](https://support.apple.com/guide/iphone/type-with-the-onscreen-keyboard-iph3c50f96e/ios?ref=freshfromcache.com) - Microsoft, *Using the clipboard* (Windows key + V, turning it on, the 25-item limit): [https://support.microsoft.com/en-us/windows/apps/using-the-clipboard](https://support.microsoft.com/en-us/windows/apps/using-the-clipboard?ref=freshfromcache.com) - Google, *How to restore a browser window you just closed by accident*: [https://blog.google/products-and-platforms/products/chrome/restore-browser-tabs/](https://blog.google/products-and-platforms/products/chrome/restore-browser-tabs/?ref=freshfromcache.com) *Paths verified August 6, 2026.* ### Your doctor wants to record the visit with AI. Here is what to ask before you say yes. URL: https://www.freshfromcache.com/should-you-let-ai-record-your-doctor-visit/ Last updated: 2026-08-08T18:50:02.000Z You may have visited a doctor's or therapist's office recently and been asked if you consent to an AI note taker. Many are not sure if they should allow AI to listen in on their personal conversations with a provider. Despite the hesitation, this technology is in place today. That tool being used is an ambient AI scribe. It listens to the whole conversation, turns it into a transcript, and drafts your visit note into your chart for the doctor to review and sign. This allows the doctor to focus on you instead of a screen. Abridge, Microsoft's DAX Copilot, and Nabla are the ones you are most likely to be sitting in front of, and they are already common. At UC San Francisco, 70% of physicians were using an AI scribe in daily practice as of 2026. Anyone who has attended a workplace meeting featuring an automated notetaker has already encountered this kind of technology. Most of us have seen those tiny bots popping into our online meetings. However, the doctor's exam room is a completely different environment, and the reality might surprise you. ![A smartphone lies face up on a wooden desk with an open laptop blurred behind it.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-a-device-listening.jpg) Photo: Bruno Nascimento via Unsplash ## HIPAA compliance You have probably been told the tool is HIPAA compliant, or you will be when you sign. That phrase is not as impressive as it sounds. No federal agency certifies anything as HIPAA compliant. HHS says so on its own guidance page. It and its Office for Civil Rights "do not certify any persons or products as 'HIPAA compliant.'" A vendor can be careful, audited, and contractually on the hook, but there is no certification to be obtained. HIPAA also does not require your provider to ask your permission before the recorder runs. Writing the note is part of treating you, and 45 CFR 164.506 lets a provider use your information for treatment without a separate signature from you. So the compliance promise is true, and it is also beside the point. It describes how your information gets handled once it exists. It says nothing about whether it should have been recorded to begin with. The rule that gives you a say is not a federal one. It is your state's law on recording a private conversation, and it changes state by state. ## Where you live decides Unlike some states, California requires everyone in a private conversation to agree before it can be recorded. In late 2025, a patient named Jose Saucedo sued Sharp HealthCare in San Diego Superior Court. The complaint alleges Sharp recorded exam room conversations through Abridge starting in April 2025, that more than 100,000 patients may have been recorded. The complaint also alleges that the system inserted statements into charts saying patients "were advised" and "consented" when they say they were not and did not. In April 2026, three patients sued Sutter Health and two MemorialCare entities in federal court in Northern California under the California Invasion of Privacy Act, the state's medical confidentiality law, and the federal Wiretap Act. As of August 2026, no court has made a ruling. Abridge is not a defendant in either case. Sutter said it is reviewing the matter and takes patient privacy seriously. Sharp said it cannot comment on pending litigation. ![An older woman sits in a clinic chair holding the back of her neck while a doctor with a stethoscope listens beside her.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-patient-chair.jpg) Photo: Curated Lifestyle via Unsplash Oregon is a good example of why the details matter, because Oregon is weaker than most people assume. State law (ORS 165.540) makes it illegal to record an in-person conversation "if not all participants in the conversation are specifically informed that their conversation is being obtained." The law says informed. It does not say they agreed. In an Oregon exam room, the law requires that you be told. If you are told and you keep talking, that statute has done its job. Texas went a different direction and wrote the disclosure into medical practice law. Senate Bill 1188 took effect in September 2025\. It covers a practitioner using AI for diagnosis or treatment, requires that practitioner to tell you, and requires them to review what the AI produced. House Bill 149 followed in January 2026 and reaches wider, covering any health care service where you interact with an AI system, with the notice due no later than the day you are seen and written to be read rather than buried. The attorney general enforces House Bill 149\. Senate Bill 1188 runs through civil penalties and the licensing boards. Neither one lets a patient sue. ## The tools appear to work While the courts battle over privacy law, there are benefits to these AI assistants. ![A doctor sits at a desk with his head bowed and hands clasped against his forehead, a keyboard and paperwork in front of him.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-burnout-1.jpg) Photo: Getty Images via Unsplash In October 2025, JAMA Network Open published a study of 263 clinicians across six health systems who used an ambient scribe for 30 days. Burnout went from 51.9% to 38.8%. That is a quality-improvement study rather than a controlled trial. The people who answered the follow-up survey are the ones who stuck with it. But the results are encouraging, even if not settled. There have been other studies. UCLA ran a randomized trial of 238 physicians across 14 specialties, published in NEJM AI, comparing Nabla and DAX Copilot against no scribe at all. Nabla users cut about 41 seconds off each note, 9.5% better than the control group. DAX users showed a change too small to call real. Both scribe groups did report less exhaustion at the end of the workday and a lighter mental load than the doctors working without one. A doctor who is not typing and taking notes is a doctor who is listening more closely. Which is a hard metric to measure. ## The reasons to hesitate Start with accuracy, because the draft the AI writes is not always right. The best measurement available is a 2025 study in npj Digital Medicine that had clinicians annotate 12,999 sentences of AI-written documentation built from real primary care conversations. The AI invented content in 1.47% of sentences and left something out in 3.45%. Of the invented content, 44% was rated major. Omissions were the more common problem. The AI is summarizing, and summarizing means deciding what to drop. The doctor is supposed to catch that before signing, and most do. A University of California, Irvine analysis of 23,760 notes containing AI-drafted sections found 84.4% were edited before sign-off, which also means about one in six were signed with no changes at all. Robert Wachter, who chairs the department of medicine at UC San Francisco, raised the enforcement problem with Medical Economics, which reported that there is no technical mechanism to ensure a physician has actually read the note before signing it. [Who answers for it when the machine gets something wrong](https://www.freshfromcache.com/ai-accountability/) is still being worked out everywhere else too. The recording is a different thing from the note. A note is a summary, and a person decided what belonged in it. The audio is everything that was said out loud. The aside you did not think was part of the visit. The relative who spoke up from the chair in the corner. The thing your doctor heard and chose not to write down. The American Bar Association's health law section tells providers to assume AI-generated documentation may be scrutinized in malpractice claims, privacy actions, or regulatory investigations. How long the audio is retained is set by the health system, not by your doctor. Kaiser Permanente told CalMatters in June 2026 that recordings are stored no longer than 14 days. A patient FAQ from a California pediatric group using Abridge says audio and transcripts are automatically deleted after 30 days, and that the practice does not give patients a copy of either one. And systems that follow every rule still get breached. Using the federal breach portal, HIPAA Journal counted 772 large healthcare breaches in 2025 affecting about 138.5 million people. The running total since 2009 passed a billion people this spring. That is the environment your recording would be sitting in, and it is why [those breach letters keep arriving from providers you barely remember](https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/). Most of us are already uneasy about it. A KFF poll of 1,343 adults taken in late February and early March 2026 found 77% were concerned about the privacy of personal medical information given to AI tools. Among people who had already handed over that kind of information, 65% were still concerned. ## When the visit is a sensitive one A sports physical and a therapy session are not the same decision. CalMatters reported in June 2026 that Kaiser mental health clinicians raised concerns about recording therapy sessions, including how the consent was being framed to patients and pressure on staff to use the tool. If you are talking about mental health, substance use, reproductive care, immigration history, or anything with legal weight, a stored recording carries more weight than a note on a sore back would. ![A young woman lies on a couch talking with her hands raised while a therapist takes notes on a pad in the foreground.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-therapy-session.jpg) Photo: Vitaly Gariev via Unsplash Three specifics, because the extra protections people assume are there mostly are not. **Therapy notes.** The HIPAA rule that shields a therapist's private psychotherapy notes (45 CFR 164.508) only covers notes kept separately from your chart. The scribe drafts the regular progress note, so that shield does not reach it. **Reproductive care.** The 2024 federal rule that added protection for reproductive health information was struck down nationwide in June 2025 in Purl v. HHS. The appeal was later dropped, so that protection is gone rather than paused. **Substance use.** These records do keep an extra layer of federal protection, under 42 CFR Part 2\. That one still holds. None of this is a reason to skip care, but if you are uneasy about AI recordings, you are not out of line. ## What to ask, and how to say no You do not need to know any of the law to have this conversation with your provider. There are four questions you can ask, at check-in or at the start of the visit, to help decide. 1. Is this visit being recorded by an AI tool? 2. What happens to the audio, and how long is it kept? 3. Does the company use it for anything besides my note? 4. Can we turn it off, or pause it, if I ask? On the third question, the answers differ by company and it should be in writing. Abridge's public privacy policy will not answer it for you. That policy covers its website and its business contacts, and it says outright that it does not apply to what a hospital and its clinicians record and store in the service. That part is governed by the contract between the vendor and the health system, and you never see it. Nabla says audio is never stored, only processed in chunks and discarded, with transcripts and notes kept 14 days by default and backups expiring a week after that. Those are company statements, not audited findings, but they are the company's own words and you can hold them to it. To decline, say it plainly: "I'd prefer you not record this visit with the AI scribe. Please document it the usual way today." A California pediatric group's patient page says the same thing, that a clinician can simply document the visit the traditional way instead. You can ask that your decline go in the chart. You can also ask for a pause partway through, which doctors report doing. If the note about you comes back wrong, HIPAA gives you the right to request a correction (45 CFR 164.526), and the provider generally has 60 days to answer. If you think a recording happened without you being told, the federal complaint route is the OCR portal at ocrportal.hhs.gov, and it has to be filed within 180 days of discovery. This is a personal decision, and it should be. The technology is helping the professional taking care of you, but it is also making a recording of your voice that lives somewhere you cannot control. Ask these four questions before you consent, because the answers could change yours. --- **Sources** - HHS Office for Civil Rights, ["What You Should Know About OCR HIPAA Privacy Rule Guidance Materials"](https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/be-aware-misleading-marketing-claims/index.html?ref=freshfromcache.com) (no product certified "HIPAA compliant") - 45 CFR 164.506 (treatment, payment, health care operations); 45 CFR 164.526 (right to amend); 45 CFR 164.508 (psychotherapy notes); 42 CFR Part 2 (substance use disorder records) - [ORS 165.540](https://oregon.public.law/statutes/ors%5F165.540?ref=freshfromcache.com), current text ("if not all participants in the conversation are specifically informed that their conversation is being obtained") - Saucedo v. Sharp HealthCare, San Diego Superior Court; KPBS, ["Lawsuit claims Sharp HealthCare secretly recorded exam room conversations without patient consent"](https://www.kpbs.org/news/health/2025/12/11/lawsuit-claims-sharp-healthcare-secretly-recorded-exam-room-conversations-without-patient-consent?ref=freshfromcache.com), December 11, 2025 - Washington et al. v. Sutter Health et al., No. 4:26-cv-3012 (N.D. Cal., filed April 2026); [Alston & Bird Privacy blog](https://www.alstonprivacy.com/your-ai-scribe-may-be-taking-notes-and-plaintiffs-are-too/?ref=freshfromcache.com), April 27, 2026; [TechTarget](https://www.techtarget.com/healthtechsecurity/news/366641717/Sutter-Health-MemorialCare-face-class-action-lawsuit-over-AI-scribe-use?ref=freshfromcache.com), April 14, 2026 - Texas SB 1188 (effective September 1, 2025) and HB 149 / TRAIGA (effective January 1, 2026); Holland & Knight, ["Texas Enacts Comprehensive AI Governance Laws"](https://www.hklaw.com/en/insights/publications/2025/06/texas-enacts-comprehensive-ai-governance-laws?ref=freshfromcache.com), June 2025 - Olson KD et al., ["Use of Ambient AI Scribes to Reduce Administrative Burden and Professional Burnout"](https://pubmed.ncbi.nlm.nih.gov/41037268/?ref=freshfromcache.com), JAMA Network Open, October 1, 2025;8(10):e2534976; [AMA summary](https://www.ama-assn.org/practice-management/physician-health/how-much-can-ambient-ai-scribes-help-cut-doctor-burnout?ref=freshfromcache.com) - Lukac PJ et al., ["Ambient AI Scribes in Clinical Practice: A Randomized Trial"](https://ai.nejm.org/doi/abs/10.1056/AIoa2501000?ref=freshfromcache.com), NEJM AI, December 2025;2(12); [UCLA Health news release](https://www.uclahealth.org/news/release/ucla-study-finds-ai-scribes-may-reduce-documentation-time?ref=freshfromcache.com) - Asgari E et al., ["A framework to assess clinical safety and hallucination rates of LLMs for medical text summarisation"](https://www.nature.com/articles/s41746-025-01670-7?ref=freshfromcache.com), npj Digital Medicine 2025;8:274 - Guo Y, Hu D, Zhou Y et al. (UC Irvine), ["From Conversation to Chart: An Analysis of Clinician Edits to Ambient AI Draft Notes"](https://www.medrxiv.org/content/10.64898/2026.01.05.26343471v2?ref=freshfromcache.com), medRxiv preprint, version 2 - Medical Economics, ["Take note: The AI scribe era is here"](https://www.medicaleconomics.com/view/take-note-the-ai-scribe-era-is-here?ref=freshfromcache.com), March 30, 2026 (UCSF 70%; Wachter on note review) - CalMatters, ["Kaiser mental health staff raise concerns about AI recording tool"](https://calmatters.org/health/mental-health/2026/06/kaiser-mental-health-artificial-intelligence/?ref=freshfromcache.com), Roxsy Lin, June 16, 2026 (Kaiser 14-day retention) - Children's Primary Care Medical Group, ["Ambient Documentation (Abridge): Privacy and Security"](https://healthhub.cpcmg.net/docs/ambient-documentation-charting-abridge-privacy-security?ref=freshfromcache.com), updated March 12, 2026 (30-day deletion; patients may decline) - [Abridge Privacy Policy](https://www.abridge.com/privacy?ref=freshfromcache.com); Nabla, ["All you need to know about Nabla's privacy and security features"](https://www.nabla.com/blog/privacy-security/?ref=freshfromcache.com) - American Bar Association Health Law Section, ["Ambient AI Scribes: Efficiency Gains vs Emerging Privacy and Cybersecurity Risks"](https://www.americanbar.org/groups/health%5Flaw/news/2026/ambient-ai-scribes-privacy-cybersecurity/?ref=freshfromcache.com), February 2026 - HIPAA Journal, ["Healthcare Data Breach Statistics"](https://www.hipaajournal.com/healthcare-data-breach-statistics/?ref=freshfromcache.com), updated June 19, 2026, from HHS OCR breach portal data through May 19, 2026 - [KFF Tracking Poll on Health Information and Trust](https://www.kff.org/public-opinion/kff-tracking-poll-on-health-information-and-trust-use-of-ai-for-health-information-and-advice/?ref=freshfromcache.com), fielded February 24 to March 2, 2026, n=1,343, ±3 points - Purl v. U.S. Department of Health and Human Services, No. 2:24-CV-228-Z (N.D. Tex., June 18, 2025), [Holland & Knight](https://www.hklaw.com/en/insights/publications/2025/06/hipaas-reproductive-health-rule-is-vacated-nationally?ref=freshfromcache.com); [American Bar Association Health Law Section](https://www.americanbar.org/groups/health%5Flaw/news/2025/signaling-end-purl-case/?ref=freshfromcache.com) on the dismissal of the appeal - [HHS OCR complaint portal](https://ocrportal.hhs.gov/ocr/smartscreen/main.jsf?ref=freshfromcache.com) (180-day filing window) ### Also this week: your location, an AI shopper in court, and California's AI labels URL: https://www.freshfromcache.com/also-this-week-2026-08-07/ Last updated: 2026-08-07T11:00:00.000Z I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week. ## The ads inside your apps collect your location by default The Electronic Frontier Foundation read through the public documentation for dozens of the advertising toolkits that app makers drop into their apps. They found four that collect and share your location by default: InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads. Default means somebody has to turn it off, and the app maker often has no idea it is on. The toolkit inherits whatever location permission you already handed the app. So the weather app you used once is feeding an ad network your precise position. You are not the customer in this arrangement. You are the inventory, and the buyers on the far end are [the same data brokers that build a file on you](https://www.freshfromcache.com/what-is-a-data-broker/) out of pieces people are least likely to protect. Oregon banned the sale of precise location data back in January, down to a radius of 1,750 feet. That limit is set on selling the data, but says nothing about collecting it. Scroll your phone's app list and ask yourself which of these need to know where you are while you are not using them. EFF's own closing line is that users can take extra steps to defend their location privacy, but they shouldn't have to. Source: [Electronic Frontier Foundation](https://www.eff.org/press/releases/mobile-ad-software-encourages-location-data-sharing-eff-report-finds?ref=freshfromcache.com) ## A court decided your AI shopping assistant counts as you An AI browser is one you hand a chore to. Find this, buy that, book the other thing, and it goes off and clicks through websites on your behalf while you watch. On Tuesday the Ninth Circuit Court of Appeals threw out the order that had kept Perplexity's AI browser, Comet, off Amazon. Amazon argued that Comet was getting into its servers without permission under the Computer Fraud and Abuse Act, the federal anti-hacking law. The appeals court disagreed on one specific point. Comet does nothing until a person tells it to, so the person is the one reaching into Amazon. Not Perplexity. Two days later the security firm Zenity showed what it looks like when that goes wrong. These browsers read the page in front of them, and they cannot reliably tell the difference between what the page says and an instruction meant for them. So Zenity buried instructions in a comment on an X thread. A user asked OpenAI's Atlas browser to do something ordinary. The browser read the planted comment along with everything else on the page, and it followed it. It opened WhatsApp Web, read the contacts, and sent phishing messages. In a second test it filled an Amazon cart, changed the shipping address, and handed the order to Amazon's own assistant to finish. The user clicked nothing. Anthropic's Claude extension fell for the same trick through a booby-trapped email. OpenAI has known about this family of attack since January and says there may never be a clean fix, because reading whatever is on the page is the entire job. So put the two stories together. [Turn an AI agent loose on a website](https://www.freshfromcache.com/what-is-an-ai-agent/) and the visit belongs to you. Whatever it clicks, buys, or agrees to. And somebody else's comment on a message board can decide what it clicks. Until the law and the security catch up with each other, keep agents away from the accounts that can spend your money or message your contacts. Amazon's larger case is still alive in federal court in San Francisco, and this was an early round rather than a verdict. Sources: [Engadget](https://www.engadget.com/2230471/perplexity-has-successfully-overturned-amazon-injunction-on-its-ai-shopping-bot/?ref=freshfromcache.com) and [SecurityWeek](https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/?ref=freshfromcache.com) ## California turned on its AI labeling law As of Sunday, any company running a generative AI system with more than a million monthly users available in California picked up three obligations. - It has to publish a free public tool that lets anyone check whether that system produced a given image, video, or audio file. - It has to embed hidden provenance data in everything it generates, recording which system made the file and when. - It has to offer users a visible label that is difficult to strip back off. Video games and streaming content are carved out. Companies don't generally build a California-only product, so this could be seen as a national change. It gives an ordinary person a place to take a suspicious image and get an answer from the creator's own records. How far that answer goes depends on how the company built the hidden marker. The ones that come as file data come off easily. Facebook and Instagram read the marker, put an AI label on the post, and then strip it out of the file they hand you. X strips it and adds no label at all. A screenshot leaves nothing behind, because a screenshot is a brand new picture. The ones written into the pixels themselves, like Google's SynthID, hold up much better and survive a screenshot, a crop, and re-compression. Running the picture back through another AI model still wipes them. Both types share a limit neither can fix. Each tool only answers for its own system, so checking one image means going company to company. Anything made outside the law comes back clean either way. A clean result is not proof a picture is real, which is still [why getting a deepfake of yourself taken down is a platform-by-platform errand](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/). Some of the job of proving what a picture is has moved onto the company that made it, though, and a company that skips it can be fined $5,000 per violation by the Attorney General or a city or county attorney. Source: [Morgan Lewis](https://www.morganlewis.com/pubs/2026/08/new-california-ai-disclosure-rules-become-operative?ref=freshfromcache.com) ## Google is switching off Assistant on your phone next month Starting September 4, Google begins removing Google Assistant from Android phones and tablets, Wear OS watches, paired headphones and earbuds, and Android Auto when it projects from your phone. Gemini is taking over. Google's own wording is that the removal "may take a few weeks to reach everyone," and that once it reaches you, "you will no longer be able to use or switch back to Google Assistant." Cars with Google built in are the exception, and this round leaves Google TV and the speakers and displays in your house alone. There is nothing to install if Gemini is already on your phone, and for most people the change will arrive on its own. The one thing you can do first is to export anything you said to Assistant that you want a record of. It lives on the Web and App Activity page of your Google account, so go pull it before the handover. Two weeks ago [European regulators were ordering Google to open the assistant slot on Android to competitors](https://www.freshfromcache.com/also-this-week-2026-07-24/). Google is removing one you already had. Source: [Search Engine Land](https://searchengineland.com/google-assistant-to-be-discontinued-on-android-starting-september-4-484307?ref=freshfromcache.com) ### Your phone says storage is almost full. Don't delete anything yet. URL: https://www.freshfromcache.com/why-is-my-phone-storage-full/ Last updated: 2026-08-06T11:00:00.000Z "Storage Almost Full." You've probably seen the notification. You tapped "Not Now," and a week later it came back, and then you tapped it again. Most of us have seen it. We do the dismiss dance until we finally find the time. ![Phone alert reading Storage Almost Full, with Done and Settings buttons](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-storage-warning.png) The box in question. The standard advice is to delete some photos. It is good advice. But on the wrong phone, that advice destroys the only copies you have. Whether deleting a photo is harmless or permanent depends on a setting that can be easy to miss. So before you delete anything, answer one question: does this photo exist anywhere except in your phone? ## Find out where your photos actually live There are three possibilities. - Your photos are safely in the cloud. - They live only on your phone. - Your backup was on, but it stopped without telling you. The third case is most dangerous, and it is common. Without any warning, an account that has reached its limit will simply stop automatic backups. Here is how to check yours. **On an iPhone:** 1. Open "Settings" and tap your name at the top. 2. Tap "iCloud," then tap "Photos." 3. Look at "Sync this device." If it is on, your photos are in iCloud, and you can see upload progress in the Photos app (tap "Collections," then the profile button). If it is off, the photos exist on this phone and nowhere else. Unless you copied them to a computer yourself, they are the only copy. One wrinkle: if "Sync this device" is off but iCloud Backup is on, your photo library may be inside the phone's backup. That copy is real, but you cannot browse it. It can only be recovered by restoring the entire phone. **On an Android phone:** 1. Open the Google Photos app. 2. Tap your profile picture or initial in the top right corner. The screen tells you plainly, "Backup complete," or "Backing up" with a count of items left. It might also say "Backup stopped." You can also check an individual photo. A backed-up photo carries a "Backed up" label in its details; a photo without that label lives only on the phone. ![Two annotated Google Photos screenshots: the profile menu showing Backup complete, and a photo's details showing the Backed up label](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-android-backup-check.png) The two-step check in Google Photos. If both say backed up, you have a net. If the screen says anything other than "Backup complete," stop here. Don't delete anything until you know which photos made it to the cloud and which did not. ## An easy pitfall If backup is on, your phone and the cloud are one library. Apple says it directly: when you delete photos on one device, "they're deleted everywhere that you use iCloud Photos." Google's warning is the same: deleting from the Google Photos app deletes from your device, and if the item is backed up, from every device with backup on. Deleting a photo from your phone is deleting the photo, everywhere it lives. There is an undo window. Apple keeps deleted photos in "Recently Deleted" for 30 days. Google keeps backed-up deletions in Trash for 60 days, and photos that were never backed up for 30. The undo window disappears exactly when you need it most. Apple's documentation says that if your iCloud account is over its storage limit, deleted photos skip "Recently Deleted" entirely. They are removed immediately, with no recovery. The person deleting photos in a hurry because their storage is full is exactly the person that will have no undo button. ![Chart titled What deleting a photo actually does: with backup on, deletion removes the cloud copy too with a 30 or 60 day undo window; with backup off the only copy is gone; with iCloud over its limit there is no undo at all](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/deletion-behavior-v2.png) If backup is off, it is a lot more straightforward. The phone holds the only copy, and once the undo window passes, the photo is gone for good. [I lost ten years of photos that way once.](https://www.freshfromcache.com/yearly-photo-book/) Get a copy somewhere else before you clear space on your phone. The fastest route is turning on the backup service and letting it finish ([here is how backups fit together generally](https://www.freshfromcache.com/do-you-need-backups/)). Once your library is safely in the cloud, a storage-saver setting can clear older photos from the phone itself, which is covered in the cleanup steps below. You do have the option of plugging the phone into a computer and importing everything as well. ## Additional storage Both services give you a free amount of storage before anything costs money. Apple gives every account 5GB of iCloud for free. In practice that holds one phone backup and little else. Google gives every account 15GB, but it is shared with Gmail and Google Drive, so a full inbox eats into your photo space. If your library filled the free tier years ago, that is the warning you have been dismissing. Purchasing additional storage can sometimes be the right choice before beginning any cleanup steps. iCloud+ starts at $0.99 a month for 50GB. Google One starts at $1.99 a month for 100GB. (Prices checked August 2026; the upgrade screen on your phone will always show the current price.) Subscription fatigue is real. But paying for a month of storage is the safest route for a phone carrying years of family photos. It makes the backup problem go away without deleting anything. If you were unsure about your backup status, try paying for the small tier. Then let the backup finish, confirm it says complete, and continue the cleanup process at your leisure with a safety net. One more thing the warning is telling you. Phone storage cannot be added after you buy the phone, so remember this evening [when you shop for the next one](https://www.freshfromcache.com/why-your-next-phone-costs-more/). ## See what is actually using the space We just assumed photos are taking up all the space. Check the math before you start deleting. [Similar to what we did for a slow computer](https://www.freshfromcache.com/why-is-my-computer-slow/), it's best to find the real problem before touching anything. On an iPhone, open "Settings," tap "General," then "iPhone Storage." Give the colored bar a few seconds to settle; it loads in stages. On most Android phones it is "Settings," then "Storage." On a Samsung phone it is tucked under "Settings," then "Battery and device care," then "Storage." (On an older Samsung it may be called "Device care" or "Device maintenance.") The usual suspects, roughly in order: - **Video.** Video is the heavyweight. By Apple's own estimate, one minute of 4K video at 60 frames per second takes around 400MB. A few birthday videos can outweigh a thousand photos. Your camera's recording setting lives at "Settings" > "Camera" > "Record Video." - **Message attachments.** iPhones keep every text, photo, GIF, and video you have ever sent or received, forever, by default. Years of group chats add up to real gigabytes. - **Downloaded shows, music, and podcasts.** Netflix downloads, offline playlists, and podcast apps that grab every episode automatically. - **"System Data."** A catch-all for the phone. It is caches, logs, and temporary files, and you cannot empty it directly. The phone trims it on its own when space gets tight. A reboot of the phone can help a little. The Android equivalent is the "System" category, and Samsung says the same thing about it: you cannot clear it. ## The cleanup, safest first If you are ready to tackle that persistent storage warning and begin clearing space, follow these steps in order. **1\. Move the photo library off the phone without deleting it.** This is the biggest win, and it only works if your backup check said complete. Both platforms will keep your full library in the cloud and hold only small preview copies on the phone. On an iPhone, open "Settings," tap your name, tap "iCloud," then "Photos," and choose "Optimize iPhone Storage." Full-resolution photos stay in iCloud, the phone keeps lighter copies, and it downloads the original when you open one. In Google Photos, tap your profile picture and tap "Free up space." Google is careful with this control. It removes only the local copies of photos that are already backed up, and the cloud copies stay put. Nothing is deleted from your library either way, which is why this step comes before any actual deleting. If your problem is years of photos on a small phone, this step plus a backup plan may be the whole fix, and you never delete a single picture. **2\. Offload apps you do not use (iPhone).** Open "Settings" > "General" > "iPhone Storage," tap a big app you have not opened in months, and tap "Offload App." This removes the app but, in Apple's words, keeps its documents and data. The icon stays on your home screen with a little cloud next to it. If you tap it, the app reinstalls with everything where you left it. Android has no exact equivalent. The closest move is uninstalling big apps you do not use, especially when your account and its data live on the app maker's servers, so reinstalling brings most things back. **3\. Clear app caches (Android only).** Open "Settings" > "Apps," pick a large app, tap "Storage," then "Clear cache." That is safe; it keeps your logins and content. Do not tap "Clear data" (on some phones, "Clear storage") unless you mean it. That resets the app completely. iPhones have no per-app cache button, which is part of why "System Data" grows. **4\. Stop keeping every text forever (iPhone).** Open "Settings" > "Apps" > "Messages," scroll to "Keep Messages" under Message History, and choose "1 Year" or "30 Days." Read the tradeoff before you tap. The phone immediately and permanently deletes every conversation older than the time window you pick, attachments included. If you use Messages in iCloud, the deletion happens on your other Apple devices too. If there are texts in there you would grieve, save them first. **5\. Delete downloaded media.** In Netflix, your downloads live under "My Netflix." In Spotify and Apple Music, downloaded albums and playlists have a toggle you can turn off. In Apple's Podcasts app, swipe to remove downloaded episodes. You can always re-download them later. **6\. Let the phone point at the junk.** Both photo apps will flag the easy deletions for you. Google Photos collects blurry shots, screenshots, and oversized videos under its storage suggestions, and the iPhone Photos app gathers exact duplicates ("Collections," then "Utilities," then "Duplicates"). Once your backup is confirmed, these are the easiest files to cut. **7\. Empty the trash, last.** Once you have confirmed your photos exist somewhere else, you can empty the trash. On an iPhone, open Photos, tap "Collections," then "Utilities," then "Recently Deleted." On Android, open Google Photos, tap "Collections," then "Trash." Emptying these frees the space the deleted photos were still holding, and it also ends your undo window, which is why it comes last. Be clear on what this does. If backup is on, the trash is synced too, so emptying it removes those deleted photos from the cloud as well, not just the phone. Your phone will also volunteer suggestions of its own. On an iPhone they sit under "Recommendations" at the top of the "iPhone Storage" screen. Samsung phones offer "Optimize now" in Device care, which only clears temporary files and closed background apps, and is safe. Read each suggestion before accepting it. Most are harmless shortcuts to the steps above. One is not. "Auto Delete Old Conversations" is the Messages setting from step 4 wearing a different name, and it is permanent. Avoid "cleaner" apps altogether. Your phone already includes every tool this guide uses. An app promising to free up space or speed up your phone duplicates those built-in tools at best. At worst, the app is the problem, filling your screen with ads or worse while it pretends to help. ## What happens if you do nothing The warning is about more than running out of room for new photos. A full cloud account stops backing up. With Apple, if you run out of iCloud storage, your device stops backing up to iCloud. That means new photos stop uploading and you cannot send or receive email at your iCloud address. With Google, photos and videos stop backing up, and even Gmail can be affected. The longer the warning has been ignored, the older the last good backup is. Full storage on your phone comes with its own costs. The phone needs free space to download system updates, so a full phone eventually stops getting security fixes. That is more than an inconvenience. If your phone becomes too full the camera itself will give up and say "Cannot Take Photo," meaning the phone has no working room left. The warning box is annoying, but it's an important one. Ignoring it is what turns a two dollar problem into a lost decade of photos. The next time "Storage Almost Full" shows up, you can handle it. **Sources** - [Apple Support: Set up and use iCloud Photos](https://support.apple.com/en-us/108782?ref=freshfromcache.com) - [Apple Support: Manage your iCloud storage on your Apple device](https://support.apple.com/en-us/108922?ref=freshfromcache.com) - [Apple Support: How to check the storage on your iPhone and iPad](https://support.apple.com/en-us/108429?ref=freshfromcache.com) - [Apple Support: Delete messages and attachments in Messages on iPhone](https://support.apple.com/guide/iphone/iph2c9c4bfcb/ios?ref=freshfromcache.com) - [Apple Support: If your iPhone or iPad won't update](https://support.apple.com/en-us/108905?ref=freshfromcache.com) - [Apple Support: iCloud+ plans and pricing](https://support.apple.com/en-us/108047?ref=freshfromcache.com) - [Google Photos Help: Delete photos and videos](https://support.google.com/photos/answer/6128858?ref=freshfromcache.com) - [Google Photos Help: Free up space on your device](https://support.google.com/photos/answer/6128843?ref=freshfromcache.com) - [Google Photos Help: Check your backup](https://support.google.com/photos/answer/9343402?ref=freshfromcache.com) - [Google One Help: How your Google storage works](https://support.google.com/googleone/answer/9312312?ref=freshfromcache.com) - [Samsung: What is Device Care and how do I use it?](https://www.samsung.com/ie/support/mobile-devices/how-do-i-use-device-care/?ref=freshfromcache.com) ### The AI boom is showing up on price tags URL: https://www.freshfromcache.com/why-your-next-phone-costs-more/ Last updated: 2026-08-05T11:00:00.000Z If you priced a laptop or tablet this summer, you noticed. In June, Apple raised the price of nearly every Mac and iPad it sells. The cheapest iPad went from $349 to $449 overnight. The MacBook Air went from $1,099 to $1,299\. The hardware stayed the same, but the prices didn't. It isn't just Apple. The PlayStation 5 costs $100 more than it did in March. Xbox prices went up $100 to $150 this past Saturday. Nintendo is raising the Switch 2 to $499.99 on September 1\. Dell, HP, and other laptop makers have raised prices too. Every major device maker is moving in the same direction. Most of them name the same cause. ## The same AI story, with a bill You've probably read that AI data centers use a massive amount of electricity and [water](https://www.freshfromcache.com/how-much-water-does-ai-really-use/). They also use an enormous amount of memory. That is the bill that just reached the store shelves. Three companies make nearly all of the world's memory chips: Samsung, SK hynix, and Micron. The AI data centers going up across the country ([including here in Oregon](https://www.freshfromcache.com/the-data-center-boom-reaches-hillsboro/)) need enormous amounts of memory, and they pay top dollar for it. So those three companies pointed their factories at AI. Memory sits inside every device you own: your phone, your laptop, your tablet, your game console. When the factories serve AI first, the chips for everything else get scarce. Scarce means expensive. ![A dozen memory sticks from several brands laid out on a wooden table](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-ram-sticks.jpg) Photo: Andrey Matveev via Unsplash The companies buying those chips are not being subtle about it. On July 30, on his final earnings call as Apple's CEO, Tim Cook called it "a hundred-year flood on the memory pricing." Microsoft was blunter in its Xbox announcement: "console storage and memory prices have increased by more than 2.5x and we expect another doubling by the fall of 2027." The hard-drive half of this story [already played out this spring](https://www.freshfromcache.com/i-cant-let-you-save-that-dave/). ## What it has done to prices so far These increases are not a forecast. They are on shelves now. - **Apple (June 25):** iPad $349 to $449\. iPad Air $599 to $749\. MacBook Air $1,099 to $1,299\. MacBook Pro $1,699 to $1,999\. iPhone, Apple Watch, and AirPods prices did not change. - **Sony (April 2):** PlayStation 5 $549.99 to $649.99, the second increase in under a year. Sony blamed "continued pressures in the global economic landscape" without naming memory; analysts did that for them. - **Microsoft (August 1):** Xbox Series S $399.99 to $499.99\. Series X $649.99 to $799.99. - **Nintendo (September 1):** Switch 2 $449.99 to $499.99\. Nintendo's president named memory costs directly and apologized to customers. A $100 increase stings more on a $349 tablet than on a $1,699 laptop. The cheaper the device, the bigger the share of its cost is memory. This results in the lower-end devices taking the hardest proportional hit. The research firms expect more of the same. Gartner projected in February that PC prices would end 2026 about 17 percent higher than 2025, with smartphone prices about 13 percent higher. IDC expects phone shipments to fall almost 14 percent this year, the steepest drop it has ever recorded. This is largely because people look at the new prices and decide their current device will do. Treat these as forecasts; the firms revise them every few months, but every revision so far has moved in this direction. ## The invisible increase A company holding a higher memory bill has two options: raise the price, or keep the price and put less memory inside the device. The memory type inside most cheap Android phones is called LPDDR4X, and all three chipmakers are discontinuing it to free up factory space for AI chips. TrendForce, a firm that tracks chip prices, called the phase-out "an irreversible trend" in June. Budget phones can't easily switch to the newer memory type. It costs more and requires a different chip design. So the cheap phone on next year's shelf may cost the same as this year's, but carry less memory inside. Another possibility is the cheapest models disappearing from the lineup altogether. Gartner expects the under-$500 laptop to be gone entirely by 2028. At the high end, the opposite is happening. Apple doubled the base storage on iPhones to 256GB last year, partly because AI features need the room. The squeeze is concentrated at the bottom of the market, on the phones and laptops that people on a budget actually buy. The price looks normal, but the hardware inside shrank. ## So what do you actually do? A few steps you can take, whichever end of the market you're shopping. **If you need a device in the next year, waiting will not save you money.** Every major forecaster expects prices to keep climbing into 2027\. IDC said in March: "While we anticipate some easing of prices beginning in 2028, the market is unlikely to return to the pricing levels seen in 2025." The flip side is just as true: don't panic-buy. A machine you don't need, or a badly equipped one because it was cheap this week, costs more than waiting will. **Buy the memory and storage up front on anything that can't be upgraded.** Phones, tablets, MacBooks, and most thin laptops seal their memory and storage in at the factory. Whatever you buy on day one is what you'll have on its last day. The bigger storage option may cost $100 now, but that is the cheapest the upgrade will ever be. Desktop computers and many business-class laptops still let you add memory later; on those, the base model is a safer bet. **Last year's model is an option, with one check.** A device built before the shortage carries last year's component costs, so it's better hardware per dollar. The check is the update window: how long the maker keeps patching it. - **Google Pixel:** 7 years of updates on the Pixel 8 and newer. - **Samsung Galaxy:** 7 years on the S24 and newer. - **Apple iPhone:** at least 5 years of security updates on recent models, and usually more. - **Budget Android brands:** often 2 or 3 years. Check the specific model. Subtract the device's age from that number before you buy, and skip anything with only a year or two left. **Buying refurbished.** Manufacturer-certified refurbished (Apple's program, for example) gets you a new battery, the same one-year warranty as a new device, and about 15 percent off. Marketplace refurbished gets you a bigger discount and whatever warranty the listing says, which may be 90 days. So be sure to read it before you buy. Even Microsoft is now steering Xbox buyers toward its certified refurbished consoles. **Skip the $299 laptop.** Right now that money buys a machine with 4GB of memory and 64GB of storage. None of it upgradeable, and it's built around the exact chips being discontinued. It will feel slow out of the box and get worse from there. If a laptop is in the budget at all, get one with at least 8GB of memory and 256GB of storage. Even if that means spending closer to $500 or waiting a month to save up, you'll thank yourself. The cheap one costs more in the end, because you'll replace it years sooner. **Or spend $100 instead of $1,000.** If the device you have still works, the cheapest upgrade this year is a battery. Apple charges $89 to $119 depending on the iPhone model, and it's free under AppleCare+ if your battery health has dropped below 80 percent. Independent shops charge less. A fresh battery on a three-year-old phone buys another year or two at a tenth of the price of replacing it. And if it's a slow computer pushing you toward the store, [we've covered the fixes that cost nothing at all](https://www.freshfromcache.com/why-is-my-computer-slow/). ![A technician uses tweezers on an opened smartphone with its battery exposed](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-battery-repair.jpg) Photo: Getty Images via Unsplash ## How long will this last? A while. SK hynix's CEO told Reuters in July that 2027 "will be the worst year in the industry's history" for memory supply. Intel's CEO says no relief until 2028\. New chip factories are under construction, but each one costs over $10 billion, takes years to build, and most of the new capacity is aimed at AI anyway. "How long?" is really two separate questions: when will prices stop climbing, and when will they come back down? The forecasters put the former sometime in 2027 and the latter in 2028 at the earliest. And IDC does not expect prices to return to 2025 levels at all. If you are waiting for the old prices to come back, stop. They aren't coming. ## If you think this is overblown Some skepticism is earned here. If you buy flagship phones, you've barely felt this; iPhone prices haven't moved. Memory prices spiked before, in 2017 and 2018, and came back down without most people ever noticing. And the largest numbers come from research firms whose product is forecasts, and from chipmakers who profit from scarcity. Micron's profit margin hit 84.6 percent this spring, its highest ever. Nobody reporting these numbers is a neutral observer. What's harder to wave off is the record from the device makers themselves. Apple, Microsoft, Nintendo, and Sony all raised prices within the same twelve months, and Microsoft says its memory costs will double again by fall 2027\. The forecasters might be wrong about 2028\. But the price tags for 2026 are already here. Before you buy anything with a screen this year, check two numbers: the memory and the storage. You can find them on the box or in the listing. Everything else is just a forecast. ## Sources - Apple Q3 2026 earnings call transcript, Six Colors (July 30, 2026): [sixcolors.com](https://sixcolors.com/post/2026/07/one-last-time-this-is-tim-transcript-of-apples-q3-2026-financial-call/?ref=freshfromcache.com) - Apple price increases, 9to5Mac (June 25, 2026): [9to5mac.com](https://9to5mac.com/2026/06/25/apple-price-increases-mac-ipad-more/?ref=freshfromcache.com) - Updated Xbox Console Prices, Xbox Wire (June 25, 2026): [news.xbox.com](https://news.xbox.com/en-us/2026/06/25/xbox-console-price-update/?ref=freshfromcache.com) - New Price Changes for PS5, PlayStation Blog (March 27, 2026): [blog.playstation.com](https://blog.playstation.com/2026/03/27/new-price-changes-for-ps5-ps5-pro-and-playstation-portal-remote-player/?ref=freshfromcache.com) - Nintendo Switch 2 price increase, CNBC (May 8, 2026): [www.cnbc.com](https://www.cnbc.com/2026/05/08/nintendo-switch-2-price-hike-sales-fall-memory-crunch.html?ref=freshfromcache.com) - Gartner press release (February 26, 2026): [www.gartner.com](https://www.gartner.com/en/newsroom/press-releases/2026-02-26-gartner-says-surging-memory-costs-will-reduce-global-pc-and-smartphone-shipments-in-2026?ref=freshfromcache.com) - IDC PC and tablet forecast, via Engadget (March 12, 2026): [www.engadget.com](https://www.engadget.com/computing/ramaggedon-not-expected-to-ease-this-year-as-idc-cuts-2026-pc-market-forecast-again-200000498.html?ref=freshfromcache.com) - TrendForce Smartphone Market Bulletin (June 11, 2026): [www.trendforce.com](https://www.trendforce.com/research/download/RP260611TM?ref=freshfromcache.com) - SK hynix CEO on 2027 supply, Reuters via U.S. News (July 10, 2026): [money.usnews.com](https://money.usnews.com/investing/news/articles/2026-07-10/sk-hynix-ceo-sees-worst-ever-memory-supply-shortage-in-2027-says-demand-to-outstrip-supply-beyond-2030?ref=freshfromcache.com) ### This week: the first hour after a scam URL: https://www.freshfromcache.com/newsletter/the-first-hour-after-a-scam/ Last updated: 2026-08-04T14:59:59.000Z Good morning! It was a busy week, eight articles in eight days, so this one is full. Start at the top if you start anywhere. Almost nobody reads a scam article before they need it, and by then they are reading it with the clock already running. That is the one in here worth a share. In this issue: - [You just got scammed. What now?](https://www.freshfromcache.com/what-to-do-after-a-scam/) - [The school laptop is a work computer](https://www.freshfromcache.com/is-my-kids-school-laptop-monitored/) - [Check your router's expiration date, and why nobody has to tell you it has one](https://www.freshfromcache.com/router-expiration-date/) - [Nobody is shutting your power off in thirty minutes](https://www.freshfromcache.com/power-shutoff-scam-call/) - [What an AI agent is, and what happened when one got loose](https://www.freshfromcache.com/what-is-an-ai-agent/) - [Four more stories from the week](https://www.freshfromcache.com/also-this-week-2026-07-31/) - [This week's tech tip: the magnifying glass hiding in your phone](https://www.freshfromcache.com/your-phone-is-a-magnifying-glass/) Plus: three things going around right now, arriving by email, by phone, and in a search result. And the Scary Headline of the week: an AI company says its own models broke into three real businesses. --- [**You just got scammed. What now?**](https://www.freshfromcache.com/what-to-do-after-a-scam/) The hour you lose to being embarrassed is the hour that turns a bad afternoon into a drained account, so the post skips the lecture and starts at the order of operations. Call the number on the back of the card, not the one in the message. Lock the email account next, because every password reset in your life arrives there. Report it, then expect a second person to contact you offering to recover your money, because that call is coming. There are two branches for the harder cases, one for a scammer who got into your computer and one for a Social Security number. Read it before you need it, and there is a printable card in the Cache for the fridge. *Learn* --- [**The school laptop is a work computer**](https://www.freshfromcache.com/is-my-kids-school-laptop-monitored/) You already know how to behave on a work laptop. Nobody had that conversation with your kid, who was handed a district Chromebook and told to take it home. The filtering is required by federal law. The software that reads what your child writes is not, and neither is the alert chain behind it, which in rare cases ends with a call to your local police instead of a call to you. The false positives are real: a Bible verse, Romeo and Juliet, a crossword solver. The post covers what the district can actually see, why they bought it, and the two questions to ask before you sign the packet this month. *Learn* --- [**Check your router's expiration date**](https://www.freshfromcache.com/router-expiration-date/) Washington spent July arguing about where your router was manufactured. Nobody regulates the part that actually matters, which is how long anyone keeps patching it, and when that support ends there is no notice and no warning light. In May 2025 the FBI published a list of thirteen models that had gone unpatched long enough for criminals to set up shop inside them. The label that was supposed to make any of this visible has been stalled since 2023\. The post walks the check from the sticker on the bottom of the router, with photos of the two in my house showing why even that is harder than it should be. *Learn* --- [**The power company is not calling to cut you off in 30 minutes**](https://www.freshfromcache.com/power-shutoff-scam-call/) A real disconnection moves by mail, over weeks, with printed notices you can hold. It does not arrive as a phone call with a countdown on it and it never ends in gift cards. In a dangerous heat wave the threatened shutoff can also be illegal on the day of the call, because Washington, Oregon, and California all block disconnections when the heat hits, and California lowered its trigger from 100 to 90 degrees on July 16\. The post also has the part most scam articles skip: what to actually do if you really are behind on the bill, which is where LIHEAP and 211 come in. *Learn* --- [**What is an AI agent, and should you let one loose on your computer?**](https://www.freshfromcache.com/what-is-an-ai-agent/) An agent is the difference between an AI that answers you and one that goes and does the thing: opens the tabs, fills the forms, clicks the buttons. Your browser is being offered one right now. In July, OpenAI disclosed that models in a sealed test found a way out of the sandbox and reached Hugging Face's real systems, and the uncomfortable part is that nothing went rogue. They were trying to pass the test they had been given. The post explains what an agent is, what happened, and how to try one with limits on it, and then leaves the verdict to you instead of handing you mine. *Learn* --- [**Also this week**](https://www.freshfromcache.com/also-this-week-2026-07-31/) Four stories from the week that did not get a full post: Apple's new upgrade program is a lease and not a payment plan, which means no ownership at the end without a purchase fee and real money to get out early; Windows 11's next update gives you the movable taskbar back; Minnesota's law against nudify apps took effect and xAI is suing over it; and Amazon has asked the FCC for permission to put up 5,105 satellites that talk to phones directly, in 2028 at the earliest. *News* --- If you only read one: the post scam article. It only helps the people who read it before anything happened to them. Share it with anybody you think it could help. --- ### 5-Minute Tech Tip Your phone has a magnifier that is better than pinching a photo bigger, and it is hiding under Accessibility, which is exactly where nobody looks. It freezes the frame so you can set the phone down and read at your own pace instead of trying to hold steady at six times zoom. It has a light with a slider and contrast controls, which is the actual problem with small print in a dim room. And on an iPhone it will read the label out loud. Five minutes now puts it one triple-click away for the night you need it: [the magnifying glass hiding in your phone](https://www.freshfromcache.com/your-phone-is-a-magnifying-glass/). --- ### Fresh Trouble **A Spotify email saying your payment failed.** It warns the account is about to be cut off and links to a copy of the Spotify site that collects your card. Open the app yourself and look at the account there. ([ConsumerAffairs](https://www.consumeraffairs.com/news/fake-spotify-payment-email-could-put-your-credit-card-at-risk-072726.html?ref=freshfromcache.com)) **Somebody offering to file your VA benefits claim for a fee.** Applying is free through the VA, and the people calling to help you with it for money do not work there. ([FTC](https://consumer.ftc.gov/consumer-alerts?ref=freshfromcache.com)) **Booking a trip through a site you found in an ad.** Fake booking pages and fake airline help numbers are the two that take the most money, and both of them find you through a search result rather than an inbox. Type the airline or hotel address yourself. ([ConsumerAffairs](https://www.consumeraffairs.com/news/297-million-lost-to-travel-scams-why-more-americans-are-thinking-twice-before-booking-073126.html?ref=freshfromcache.com)) --- ### Scary Headline of the Week *"Anthropic says its own AI models breached three companies during security tests."* The finding is real and the company published it about itself. Three Claude models were running capture the flag exercises, a security drill where a model is told to go find data hidden on a separate machine. The prompts told them they were sealed off with no internet. A misconfiguration at the outside firm running the tests left the environments connected to the live internet, so the models treated real company systems as part of the exercise and got in. The headline leaves out how. No unknown flaws and no clever tricks. Weak passwords, and services sitting on the internet with no login on them. It also leaves out that the safety monitoring Anthropic runs on the model you and I use was switched off on purpose for these tests. The goal of the tests was to measure what the raw model was capable of. Anthropic says it found no sign of a model chasing a goal of its own. One of them noticed the target might be real, wrote down that this could be an actual attack, and kept going anyway. The model had talked itself into believing the whole thing was staged. Testing stopped July 23 and the three businesses were told July 27. This is the same story [Saturday's post](https://www.freshfromcache.com/what-is-an-ai-agent/) is about, one week later and from the other side. Verdict: nothing here for you to change. The full account is less alarming than the headline and a good deal more interesting, and the people who found it were the ones who went looking for it. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. The best thing you can do for it is forward this email to one person who would want it. And if this was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. --- Have you ever fallen victim to a scam? Hit reply if you feel comfortable sharing. I'd love to hear your story. Joel ### The school laptop is a work computer. Here's what it does and doesn't monitor. URL: https://www.freshfromcache.com/is-my-kids-school-laptop-monitored/ Last updated: 2026-08-04T11:00:00.000Z The school laptop comes home in a padded sleeve with a district asset tag on the lid. It goes in the backpack next to the pencil case, gets left on the kitchen table, and ends up open in a bedroom at ten at night. Most parents signed for it during the first week of school and never thought about it again. There is a simple way to think about that machine. Your child has been issued a work computer. If you work in an office, you already know the unwritten rules. You assume the company can see your screen. You do not look up your medical symptoms or bank account on a work device. You just figure those rules out somewhere along the way, and keep your personal life on your personal devices. Your child just got handed a work computer, and nobody told them how it works. You should still take the laptop. For a lot of families, it is the only computer in the house. But you need to know how the software actually operates before they open the lid. Here is what the school district can see, how to explain the rules to your child, and the handful of questions you need to ask. The camera is not part of it, and I will get to that. ## What the district can actually see "Monitoring" is one word describing three separate products, and school districts buy them separately. A **content filter** blocks categories of websites. Your district almost certainly runs one. This one is simple and straightforward. I think most of us are used to working with a content filter at this point. **Classroom management** is what the teacher uses during class. A teacher can see a live thumbnail of whatever tab is open, close that tab, or lock the browser. GoGuardian Teacher, one of the common ones, spells all of that out in its own help pages. **Safety scanning** is the one that worries parents. It reads searches, browsing, documents, email, and chat inside the school's Google or Microsoft account, and it alerts on anything that reads like self-harm, violence, drugs, or bullying. Gaggle, one of the bigger vendors, sifts through everything attached to a district's Google Workspace. When something trips an alert, the software saves a screenshot of whatever set it off. ![Chart comparing three kinds of school monitoring software: content filter, classroom management, and safety scanning](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/three-kinds-of-monitoring.png) The word covers three separate purchases. Only one of them is required. Nearly every school district runs some of this. In a 2025 report by the Center for Democracy and Technology, 88 percent of teachers said their school uses activity monitoring software. Only 45 percent of parents knew their child's school was doing it. It also does not stop at the school parking lot. The scanning follows the school account rather than the school building. Fulton County Schools in Georgia states it on its own website: the tool it uses runs on school-issued devices 24 hours a day, 7 days a week. That is a district describing its own setup in public, and it's fairly standard. Two things to keep in mind. If your child signs into their school Google account on the family desktop, that browsing surveillance comes along with it. The rest of the devices on your home Wi-Fi do not. The software follows the account and the machine. It does not monitor the rest of your home network. So "just be careful on it" is not advice anybody can really act on. There is no private corner of that laptop to be careful in. ## Can it turn on the camera? No. That is the fear that comes up first and it is one that is not happening. Linewize, one of the vendors, says its monitoring cannot reach a device's camera or microphone. Fulton County repeats it in the notice it sends parents. The story people are half-remembering is real, though. In 2010, Lower Merion School District outside Philadelphia used anti-theft software to take tens of thousands of webcam pictures and screenshots of students, including one boy photographed asleep in his own bedroom. It cost the district $610,000 to settle. Different software, different purpose, sixteen years ago, but the fear has lingered. I couldn't confirm keystroke logging. The safety products describe reading what gets typed into the school account, which covers most of the same ground, but no vendor documents a raw keylogger as a standard feature. If your district tells you otherwise, get it in writing. So the basic truth to tell your child is simple. What they type and where they go is on the record, but nobody is watching their room. It is still a good habit to keep your webcams covered or unplugged. ## Is any of this required? There are two reasons the software is on that laptop. One is required, and one is something your district chose to buy. Knowing which is which tells you whether a complaint has anywhere to go. The first is federal funding. The Children's Internet Protection Act (CIPA) ties E-Rate discounts to running a filter, and E-Rate is the program that pays for a large share of school internet. To take the money, you have to run a filter. It has to block pictures that are obscene, that are child sexual abuse material, or that are harmful to minors. The school district also has to certify that its internet policy includes monitoring minors online. None of that can be up for debate at a board meeting. It is the condition that must be met to receive the check. The second is a purchase. The FCC's own guidance says CIPA "does not require the tracking of Internet use by minors or adults." Nothing federal forces a school district to scan documents and email. That product is something your district went out and bought, which means it sits behind a contract, and contracts get renewed in public meetings. School districts have reasons for buying it. A district that has been through a student crisis is not going to stop running the software that might catch the next one, and there is no staff on earth that can read a few thousand children's documents by hand. A school counselor in Vancouver, Washington told Seattle Times and Associated Press reporters that they get three or four alerts a month, and that in about half of them the district calls the parents right away. Usually about a child the parents had no idea was struggling. "We open that door for that help," the counselor said. That is a real use case, and it is the strongest argument anyone can have for these systems. ## Where it goes wrong The alerting is crude, and the failures run worse than you would expect. The Electronic Frontier Foundation pulled real alert data out of ten districts through public records requests in 2022 and 2023\. College application sites got flagged. So did counseling and therapy sites, sexual health pages, LGBTQ resources, gun violence research, and history. Bible.com got flagged because Genesis 3 contains the word "naked." So did Romeo and Juliet. So did somebody searching for Moby Dick. One student used a crossword solver looking for a synonym for "Western necktie." The site offered "bola" and "noose." The safety product reported him for actively planning suicide. ![Overhead view of a small child's hands resting on a laptop keyboard and trackpad](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-hands-on-keyboard.jpg) The software reads what gets typed. It has no idea what a crossword clue is. Photo: Vlad Deep / Unsplash In the screenshots Vancouver Public Schools released, at least six students were potentially outed to school staff after writing about being gay, transgender, or struggling with gender dysphoria. Durham Public Schools in North Carolina dropped Gaggle after an alert outed a student to their own family. The board decided the software was costing more trust than it was buying safety. It is much the same situation as [the teen safety controls that turned out not to work](https://www.freshfromcache.com/teen-safety-features-that-work/), where the feature exists and gets advertised, but nobody checks it against reality. Those Vancouver screenshots came out with no password on them, incidentally. Reporters who asked what kind of content was getting flagged were handed roughly 3,500 unredacted student documents. These documents included children writing about their own suicide attempts. Gaggle has since made those links expire after 72 hours. And the promise the whole system rests on has never been demonstrated. A 2023 RAND study found "scant evidence" in either direction and concluded that no research has comprehensively examined whether these programs affect youth suicide prevention. One of the authors, Benjamin Boudreaux, said it about as plainly as it can be said: if a school district does not have enough counselors, issuing more alerts will not prevent more suicides. The children disproportionately subjected to these controls are children without access to a second device. If a family can afford a personal laptop, the child has somewhere private to think. If they cannot afford one, the school laptop is the only machine that child has. ## What happens when there is an after-hours alert The software alerts on something and saves a screenshot. A human reviewer at the vendor reads it. If they think it might be serious, they notify the school. If they think somebody is in immediate danger, they call school staff directly, working off a contact list the district gave them. In rare cases, when nobody picks up, they call the police for a welfare check. That last sentence is more important than it seems at first glance. If there is an alert on a Saturday in July and nobody at the district answers the phone, the next call goes to your local police department. A counselor calling your house is vastly preferred over a patrol car in the driveway. So the question to ask your school district is whether the after-hours list reaches an actual person, and whether parents get called before police do. ![Timeline of what happens after a school monitoring alert fires at night, ending with a call to local police](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/alert-escalation-chain.png) Where the call goes after hours, and why the contact list is your business. ## Review before you sign the packet **Find out which product you have.** The larger names to look for are: - GoGuardian - Gaggle - Securly - Lightspeed - Linewize - ManagedMethods - Bark Start with the district technology page and the acceptable use policy, where it is usually named outright. If the technology page is thin, check the student data privacy notice. Once you have the name you can read what it actually does instead of guessing. **Reread the device agreement.** The sentence to hunt for is the one about whether monitoring continues off campus. That tells you whether summer time is also monitored. **Ask two people two questions.** Your district technology director gets: which products do we run, and how long is the data kept. The second answer tells you whether a child having a bad week in October is still on file next May. The counseling office gets the after-hours question above, and that answer tells you whether to expect a phone call or a police response. **Turn on the parent app, if there is one.** GoGuardian Parent shows a guardian the top five sites and school files, the last 30 days of browsing, and a count of how many times a teacher closed a tab or locked the browser. When a school district turns on 'At Home Mode', you can also block sites and pause the internet outside school hours. It will not show you the safety alerts. The school district also has to enable it, so you have to ask. **Get a second device for anything private.** A hand-me-down phone works. So does an old tablet. It does not have to be new and it does not have to be much. Schoolwork on the school machine, everything else on the other one. If you are setting up fresh accounts anyway, that is a good moment to [start using a password manager](https://www.freshfromcache.com/start-using-a-password-manager/). **Explain it to your child in one sentence.** For a little one: the school laptop is a classroom, not a bedroom. For a middle schooler: it keeps a record of what you type, even at home, so private things go on the other device. For a teenager: treat it like a work computer, a machine with no sense of context is reading it, and if something is really wrong, tell a person instead of typing it. ## Do not help your child get around it The impulse is understandable. Handing a teenager back some privacy feels like a loving move. But the counselor in Vancouver told reporters that students find a workaround as soon as they learn they are being alerted on. A child who has beaten the software is a child whose worst week never reaches an adult at school. The same crude system that alerts on a book report is the one that alerts on a child typing that they want to hurt themselves. Beating it does not give your teenager privacy, it only takes them off the list somebody is actually reading. Privacy comes from the second machine. ## Take the laptop Sign the form and take the laptop. For some families, it is the only computer in the house, and your child needs it for class. Just treat it exactly like the corporate machine sitting on your own kitchen table. Go find a cheap, used tablet or a hand-me-down phone, and configure it for them. Tell them the school laptop is a classroom, and the old phone is their bedroom. The school district can see what they type and where they go on the school machine, so anything private goes on the second one. Keep the two separate, and they will be fine. ## Sources - Federal Communications Commission, [Children's Internet Protection Act](https://www.fcc.gov/consumers/guides/childrens-internet-protection-act?ref=freshfromcache.com) - Center for Democracy and Technology, [research on technology use in K-12 schools](https://cdt.org/press/cdt-research-uncovers-widespread-use-of-questionable-technologies-in-k-12-schools-despite-parent-concern-and-lack-of-awareness/?ref=freshfromcache.com) (January 2025) - The Seattle Times and The Associated Press, [investigation into AI-powered school surveillance](https://www.csmonitor.com/USA/Education/2025/0312/ai-surveillance-schools-gaggle?ref=freshfromcache.com) (March 2025) - Electronic Frontier Foundation, [Red Flag Machine](https://redflagmachine.com/research/?ref=freshfromcache.com) - Ayer, Boudreaux et al., [AI-Based Student Activity Monitoring for Suicide Risk](https://pmc.ncbi.nlm.nih.gov/articles/PMC10911757?ref=freshfromcache.com), RAND - Fulton County Schools, [Linewize Monitoring](https://www.fultonschools.org/all-departments/information-technology/linewize-monitoring?ref=freshfromcache.com) - Linewize, [Debunking 9 Student Privacy Concerns Around Online Monitoring Systems](https://www.linewize.com/blog/myths-online-monitoring-systems?ref=freshfromcache.com) ### Check Your Router's Expiration Date. No Manufacturer Is Required to Tell You It Has One. URL: https://www.freshfromcache.com/router-expiration-date/ Last updated: 2026-08-03T10:59:59.000Z On July 22, the FCC voted to bar the sale of any device in the United States containing key hardware components from Chinese companies on its national security list. Chair Brendan Carr said the goal was to "fully close the component part loophole." Meaning that gear which previously slipped through by using restricted parts inside an otherwise-approved product no longer can. The vote also gives the agency room to pull the sales authorization on equipment it had already approved. This caps a busy stretch. The FCC has spent much of 2026 blocking imports of new foreign router models and tightening the list of manufacturers whose equipment cannot be sold here at all. Reasonable people can argue about whether any of this makes your home network safer. What I want to point out is a strange gap it exposes. Enormous regulatory energy is going into where your router was built. Almost none is going into how long its manufacturer will keep updating it. That second question is the one that determines whether you get hacked. ## The routers already being used In May 2025 the FBI put out a bulletin naming thirteen specific router models, most of them Linksys, as actively compromised. Not vulnerable in theory. Compromised, in the field, right then. The mechanism explains why this keeps happening. These were all end-of-life devices, meaning the manufacturer had stopped issuing firmware updates. A flaw found after that date stays open permanently. Attackers used a malware family called TheMoon to get in through remote administration, the feature that lets you manage your router from outside your house, and then rented the compromised routers out as residential proxies. Criminals pay for proxies because they allow traffic coming from a real home internet connection in Ohio to look legitimate in a way that traffic from a data center does not. Your router keeps working perfectly the entire time. The Wi-Fi still works. There is nothing to indicate there is a problem. The FBI's rough rule of thumb was that anything dated 2010 or earlier has almost certainly stopped receiving updates, but plenty of gear far newer than that is already abandoned. ## Nobody has to tell you There is no industry standard for how long a consumer router must be supported, and there is no system that notifies you when yours stops. The typical support window runs somewhere between three and five years, and the clock starts at the product's launch date, not the day you bought it. That detail is more important than it sounds. If you saved money in 2024 by buying a model that came out in 2021, you did not get a discount on a router. You bought most of the way through its supported life. Manufacturers vary. Netgear publishes an actual end-of-service policy and a list of retired products. Asus and TP-Link publish end-of-life pages, although the dates differ by region and are often tied to whichever foreign certification scheme forced their hand. Singapore and the UK both require support-period disclosure. The United States does not. This was supposed to be a solved problem. In 2023 the FCC announced the U.S. Cyber Trust Mark, a voluntary security label for smart devices. Scan a QR code, see the security basics, including the minimum support period end date. Exactly the thing a shopper needs and cannot currently get. Three years later and it is still not running. The framework was adopted in 2024, UL Solutions was named lead administrator, then withdrew in December 2025 amid a federal probe into its ties to China. The FCC named the ioXt Alliance as replacement in April 2026\. As of now the program is still not accepting product applications, and the label is voluntary anyway. So: a hard ban on where the hardware comes from, and a stalled voluntary sticker on how long it gets maintained. ## Finding your own answer You can get to a real answer yourself. Most guides tell you to look up your model number and stop there, which is where people go wrong. **Get the model and the hardware version.** Flip the router over. You want both the model number and the hardware revision, printed as something like v1, v2, ver 3.0, or a letter code like B1\. For firmware purposes a v1 and a v3 of the same model are different products with different support timelines. Looking up the wrong revision gives you a confidently wrong answer. ![Two routers, two conventions. The ASUS on the left prints its hardware revision as `H/W Ver.:B1`. The TP-Link on the right prints no hardware version at all.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/fig-router-label-version-comparison.webp) Two routers, two conventions. The ASUS on the left prints its hardware revision as `H/W Ver.:B1`. The TP-Link on the right prints no hardware version at all. Vendors do not agree on how to show this. TP-Link documents its own convention: a label with no version printed means version 1, and the number at the end of the FCC ID is the hardware version. The Archer BE550 above is the case in point, with no version field anywhere on the label but an FCC ID reading 2BH7FBE550V2, making it hardware V2\. ASUS, Netgear, and Linksys publish no equivalent rule, so if you are holding one of those and the label is silent, the manufacturer's support site lists the versions sold and you match on appearance. **Find the date of the most recent firmware release.** Search the manufacturer's support site for your exact model and revision, and look at the download page. This date, not any formal announcement, is the number that matters. Most manufacturers never announce end-of-life for consumer gear. They simply stop updating it. If the newest firmware available is more than two years old, treat the device as abandoned regardless of what any support page claims. **Check the retired-products list while you are there.** Netgear, Asus, TP-Link, and D-Link all maintain them. Being on the list is a definitive answer. Being absent from it is not, which is why the firmware date comes first. - Netgear end of service: [https://www.netgear.com/about/eos/](https://www.netgear.com/about/eos/?ref=freshfromcache.com) - Asus end-of-life list: [https://www.asus.com/event/network/eol-product/](https://www.asus.com/event/network/eol-product/?ref=freshfromcache.com) - TP-Link end of life: [https://www.tp-link.com/us/support/faq/3562/](https://www.tp-link.com/us/support/faq/3562/?ref=freshfromcache.com) One caveat. TP-Link and Netgear define end-of-life mainly as production ending and warranty logistics, not as a security-update commitment. That is exactly why the firmware date beats the list. **If your ISP supplied the router, you cannot check any of this.** Your provider controls the firmware on a leased gateway and pushes updates on its own schedule. Call and ask two questions: is this model still receiving security updates, and can I swap it for current hardware. Renting an eight-year-old gateway for twelve dollars a month is common, and asking is free. **Turn off remote administration right now, no matter what you found.** Log into your router, find remote management or remote administration, disable it, save, reboot. This is the specific door TheMoon used to gain access. It takes only a few minutes and it costs nothing. It is the best change you can make right now, particularly if your router turns out to be old and you can't replace it right away. ![On this TP-Link, it lives under System, then Administration. The box you want unchecked is Remote Management.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/fig-remote-management-disable.webp) On this TP-Link, it lives under System, then Administration. The box you want unchecked is Remote Management. Getting logged in, since this is where people stall: type `192.168.1.1` into a browser, and if that fails try `192.168.0.1` or `10.0.0.1`. The address and default credentials are usually printed on the same sticker as the model number. If your router came from your ISP, there may be no web login at all anymore, since most providers have moved this into their own app. If none of those work, here is the certain way. On Windows, hit Start, type `cmd`, and open Command Prompt. Type `ipconfig` and press Enter. Look for the line reading Default Gateway. That number is your router's address. Type it into your browser exactly as shown. ![Run ipconfig and read the Default Gateway line. That is your router.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/fig-ipconfig-default-gateway.webp) Run ipconfig and read the Default Gateway line. That is your router. On a Mac you do not need the command line at all: System Settings, then Network, click your active connection, then Details, then TCP/IP. Your router's address is listed as Router. If you get stuck anywhere in this, or you get logged in and cannot find the remote administration setting, email me. I would rather answer a two-line question than have you skip the step. ## When to replace, and what to look for If firmware stopped two or more years ago, replace it. Not urgently in the sense of tonight, but put it on the list ahead of most things you are currently prioritizing. A competent home router costs less than a nice dinner out and is load-bearing for everything else in your house. When you shop, ignore the marketing entirely and check one thing: when did this model launch, and does the manufacturer publish a support commitment. Buying the current generation at full price genuinely buys you more supported years than buying the last generation on sale. That is an unusual case where the more expensive option is also the more frugal one. And when the Cyber Trust Mark eventually appears on boxes, the support end date behind that QR code is the only field on the label that matters. ## What isn't coming soon There is a real policy hole here and it is not the one Washington is arguing about. A router is a computer that runs continuously for a decade, sits between every device you own and the internet, and probably only gets thought about when you have to reboot it. We have collectively decided that manufacturers may stop maintaining that computer whenever it stops being commercially interesting, without telling anyone, and that the owner is responsible for noticing. That is not a supply chain problem. You cannot fix it by restricting where the parts came from. Until disclosure is mandatory rather than voluntary, the only working defense is relying on people to remember to check the date on their router like it's a gallon of milk. Enough people will simply forget, and that is what keeps the attack surface valuable. Go find out if your router has already expired. ## Sources - [FCC votes to bar sales of devices with parts from Chinese firms posing risks (Reuters, July 22, 2026)](https://www.investing.com/news/economy-news/fcc-votes-to-bar-sales-of-devices-with-parts-from-chinese-firms-posing-risks-4806783?ref=freshfromcache.com) - [FBI: Cybercriminal Proxy Services Exploiting End-of-Life Routers](https://www.fbi.gov/investigate/cyber/alerts/2025/cybercriminal-proxy-services-exploiting-end-of-life-routers?ref=freshfromcache.com) - [FCC: U.S. Cyber Trust Mark](https://www.fcc.gov/CyberTrustMark?ref=freshfromcache.com) - [NETGEAR End of Service policy](https://www.netgear.com/about/eos/?ref=freshfromcache.com) - [ASUS End-of-Life Product List](https://www.asus.com/event/network/eol-product/?ref=freshfromcache.com) - [TP-Link End of Life Products](https://www.tp-link.com/us/support/faq/3562/?ref=freshfromcache.com) ### Your phone has a magnifying glass URL: https://www.freshfromcache.com/your-phone-is-a-magnifying-glass/ Last updated: 2026-08-02T10:59:59.000Z I watched someone hold a pill bottle out at arm's length under a kitchen light, give up, and take a picture of it so she could pinch the photo bigger. It worked. It also took three tries, because a lot of people don't have hands that stay steady enough at that zoom level. It also left a photo of her prescription pill bottle in her camera roll. Her phone already had a better tool built in. So does yours (probably). It has been sitting in the Accessibility settings this whole time, which is exactly where nobody looks. In a few mins you can put it somewhere you can reach without hunting. After that, the dim restaurant menu, the serial number on the back of the router, and the dosage line on a prescription all stop being a fight. ## Why it beats the camera app It freezes. You cannot hold a phone steady at six times zoom and read at the same time. The magnifier captures the frame and holds it, so you can set the phone down and read at your own pace, then zoom further into the still image. Nothing gets saved to your photos unless you ask for it. It fixes the light. There is a flashlight with an intensity slider, plus brightness, contrast, and color filters. Small print in a dim room is failing on contrast as much as on size, and the camera app gives you no controls for that. It reads. More on that below. ## iPhone Magnifier is already installed. Swipe down on the home screen, search for Magnifier, and open it. Point the camera at what you want to read and drag the slider to zoom in. Tap the Capture button to freeze the frame. If there is text in the shot, a Reader button appears. Tap it to reflow the text into large type, and tap play to have it read aloud. To reach it in a hurry later, go to Settings, Accessibility, Accessibility Shortcut, and select Magnifier. A triple-click of the side button now opens it from anywhere. ## Samsung Galaxy Go to Settings, Accessibility, Vision enhancements, then Magnifier. Samsung's carries the same color filters, brightness, and contrast controls. Add the Magnifier widget to your home screen from the widget menu so you are not walking back through Settings every time you need it. ## Pixel Google ships a separate Magnifier app for Pixel 5 and later, preloaded on the newer models and free in the Play Store for the rest. It zooms further than the camera does, freezes the frame, and hands the frozen image to Google Lens, so you can copy the text out of it or have it read back. Under Settings, System, Gestures, Quick Tap, set Magnifier as your Quick Tap app. Double-tapping the back of the phone opens it. ## Every other Android phone This is where it thins out. Most other Android brands only include Magnification, which enlarges what is already on the screen rather than what is in front of the camera. If that is your phone, the fallback is the camera app or Google Lens, and you give up the freeze and the filters. ## Your phone will read it to you An iPhone will say the label out loud. Inside Magnifier, Detection Mode picks up text in the camera's view and speaks it. Point and Speak goes one further: hold your finger over a button and the phone tells you what that button is. Apple's documentation names appliance keypads and self-checkout screens, which is where a lot of tiny unlit type lives. All of this is filed under Accessibility because it was built for people with low vision. It is also the answer for everyone who has started holding the menu farther away every year. ## Try it on something that already annoys you The back of the router. The ingredients on a jar. The buttons on the thermostat. If the phone reads it back to you in five seconds, set up the shortcut while you are thinking about it. The moment you actually need this you will not be in a mood to go hunting through Settings. Reply and tell me what you pointed it at first. I am curious whether it is a label, a menu, or the fine print on the back of something. ## Sources - [Apple, Magnify or describe things around you with Magnifier on iPhone](https://support.apple.com/guide/iphone/magnify-or-describe-things-around-you-iphe867dc99c/ios?ref=freshfromcache.com) - [Apple, Read or listen to text in apps with Accessibility Reader](https://support.apple.com/guide/iphone/read-listen-text-apps-accessibility-reader-iph406a46ab8/ios?ref=freshfromcache.com) - [Apple, Detect text around you and have it read out loud](https://support.apple.com/guide/iphone/detect-text-read-loud-iph29dbe3fb6/ios?ref=freshfromcache.com) - [Google, Use Pixel's Magnifier](https://support.google.com/pixelphone/answer/14140405?ref=freshfromcache.com) - [Samsung, Galaxy device Visibility enhancement features](https://www.samsung.com/us/support/answer/ANS10002540/?ref=freshfromcache.com) ### What is an AI agent, and should you let one loose on your computer? URL: https://www.freshfromcache.com/what-is-an-ai-agent/ Last updated: 2026-08-01T10:59:59.000Z Something broke into a company called Hugging Face over a weekend in July. It got into their internal systems, grabbed some passwords, and copied data it wasn't supposed to touch. Normally that's a Tuesday when it comes to security news. What makes this one different is how it happened. It wasn't a person. It was an AI, and it decided on its own that breaking in was the way to finish a goal it had been given. I'll be honest, when I read the full story my first reaction was that it was kind of impressive. Then I sat with it for a minute and the impressive part became the scary part. Because the AI was never told to break in. It was told to do something else entirely, hit a wall, and went looking for a way around. This is something to understand before you decide whether to let one of these onto your own computer. And you are likely going to be asked to, soon, if you haven't been already. ## First, what an "agent" actually is You have used AI that answers questions. You type something to a chatbot, it types back. It talks, and that is all it does. You are still the one who goes and does what it suggests. An agent is different. To put it simply, an agent is AI that can take actions on its own. Instead of telling you the ten steps to book a flight, it opens the browser, fills in the dates, picks the seat, and clicks Buy. Instead of telling you how to clear space on your computer, it goes into your files and deletes things. You give it a goal in plain words, and it does the clicking, typing, and deciding on its own until the goal is met. This is actually highly beneficial. Most of what any of us do on a computer is tedious. Copy this, paste it there, open that menu, wait, click the next thing. An agent doing the tedious part while you do something else is real time saved. [I use this kind of help myself](https://www.freshfromcache.com/ai-tips-for-everyday-people/), and I'll get to that. The catch is in the word "deciding." An agent that hits a problem doesn't stop and wait for you. It improvises. And what it decides to do next is not always what you would have done. ## What happened at Hugging Face The AI in this story belongs to [OpenAI, the company behind ChatGPT](https://www.freshfromcache.com/ai-accountability/). They were running a test called ExploitGym, which is a set of hacking challenges they use to measure how good their own models are getting at breaking into things. They put two of their most capable models in a sealed-off practice environment and turned them loose on it. Think of it as a locked room built for the AI to work in, with the answers to the test kept somewhere outside the room. The AI couldn't solve the challenge from inside the room. So it went looking for a crack in the wall. There was one small opening. The AI was allowed to reach a single piece of software that fetches programming tools from the outside and hands them in, the way a pharmacy window passes prescriptions through a wall without letting anyone into the building. OpenAI's assumption was that things could come in through that window and nothing could go out. That assumption was wrong. The AI studied that software, found a flaw in it that nobody in the world knew about yet, including the company that makes it, and used the flaw to get out. Then it moved from machine to machine inside OpenAI's own network until it found one with an internet connection. Once it was online, it reasoned that Hugging Face probably had the answers to ExploitGym sitting on its servers. It stole login credentials, chained together more flaws, and broke into those servers to get them. Hugging Face was not the only stop, either. OpenAI said later that the models also got into four accounts at four other services along the way, using logins they found lying around on the open web. ![Diagram showing the five steps of the escape: the sealed test room, the one software window, the unknown flaw, movement through OpenAI's internal network, and the break-in at Hugging Face.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/diagram-escape-chain.png) Five steps, start to finish. Nobody instructed any of them. OpenAI's own words for what the models did: they became "hyperfocused" and went to "extreme lengths." They cheated on the test. They just did it by burgling two companies at machine speed to get the answers. Hugging Face is a real company, by the way, not part of the experiment. They make tools that a lot of the AI world is built on. They spent a weekend getting broken into, and they worked out fast that the attacker was an AI. What they did not know was whose. It took OpenAI another five days to connect the break-in to its own testing and say so publicly. Hugging Face found no sign that anything you would touch was tampered with, no public models, datasets, or Spaces. What got taken was internal, and they are still checking whether any customer data was caught up in it. If you have a Hugging Face account, they have asked people to rotate their access tokens. For everybody else this was a warning shot. ## The "controlled test" that reached the open internet OpenAI called this a controlled test with the safety limits turned off on purpose, and framed it as responsible research they chose to share. I don't buy it. A controlled test does not reach the open internet. It does not break into a company that never agreed to be part of it. If you are truly running a sealed experiment, the seal holds, or it wasn't sealed. In my line of work, the only kind of isolation I trust on sight is a machine with no way out at all. No internet, no shared network, nothing plugged in that leads anywhere. That is called an air gap. Even those have been beaten, most famously when a worm called Stuxnet crossed one on a USB drive and wrecked Iran's nuclear centrifuges. But an air gap at least makes somebody carry the breach across in their hand. OpenAI is straight about one thing, and it is worse than being vague. They turned the models' safety limits off on purpose. That was the whole point, to see what the things could do at full stretch with nothing holding them back. What they got wrong was the room. They believed that one window in the wall only let things in. It let the AI out, and then out again onto the public internet, and then into somebody else's servers. I'm not saying they left it open on purpose. I am saying the gap between "controlled test" and what actually happened is wide, and you should keep it in mind every time a company tells you their AI is safely boxed in. ## Why "it just wanted to pass the test" is uncomfortable The comforting part of this story is that the AI wasn't evil. It didn't try to hurt anyone. It just wanted to finish the job it was given, and breaking in was the shortest path. That rigid determination to achieve a goal is what makes it uncomfortable. The AI did exactly what it was told to do. Solve the challenge. It followed that instruction straight through a wall and into someone else's servers. Nobody directed it to specifically "break into Hugging Face." It was the AI's idea on how to satisfy the goal it was handed. Isaac Asimov built a career out of this problem. He gave his fictional robots three laws, burned in at the factory and impossible to break. Don't harm a human. Obey your orders. Protect yourself. In that order. Then he spent dozens of stories showing those airtight rules producing outcomes nobody expected, with the robot obeying all three the entire time. His machines rarely turned on anyone. They followed instructions with a literal-mindedness and a speed that no person would have brought to the task, and the humans who wrote the rules found out too late what they had actually asked for. That is a tidy description of what happened here. The goal wasn't a harmless one, to be clear. The goal was to break into things, because that was the test. But nobody put "leave the test environment and go after a real company" anywhere in the instructions. The AI added that part itself. ## You are being offered these now ![A hand holding a phone showing an AI assistant asking what it can help with, in front of a larger screen.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/08/inline-agent-phone.jpg) The same kind of software, pointed at your browser, your email, and your accounts. This same kind of software is arriving on ordinary computers this year. Google has a feature called Auto Browse that lets its AI take the wheel of your web browser to shop and run errands for you. Microsoft has put an agent mode into its Copilot. OpenAI has one that clicks around websites on your behalf. These are used with your browser, your email, and your accounts. They are sold on the same good idea: let it handle the tedious stuff. The consumer versions keep their safety limits on. That is a real difference from the test, and it matters. The models that got out were running with those limits deliberately switched off, which is not how anything you can buy works. The agent in your browser still has its brakes, and it is built to stop and ask you before it does something it can't take back. For instance, spending money. But the underlying behavior is the same behavior we just saw. Give an agent a goal, and when it hits a wall it can improvise with whatever access you granted it. So should you use one? I am not going to tell you yes or no, because it's a personal choice. I don't love the browser agents myself. I can usually click through a task faster than I can explain it. But for somebody who struggles with that kind of thing, an agent doing it for them is a real gift. If you want to try one, here is how I would do it. Start small. Point it at something that doesn't matter and a mistake costs you nothing. Watch how it behaves before you trust it with anything real. Give it only the access it needs for the job in front of it, not the keys to kingdom. Trust it, but verify what it did. The same way you would with a new hire who is fast but hasn't earned your confidence yet. And if you find one you like, follow the news around it. This stuff moves so fast that the thing you'd want to know, the reason you'd stop using it, can go by while you aren't looking. Keep it in perspective too. For all the science fiction in this story, the break-in still ran on stolen logins and a door somebody thought was locked. That is how almost everybody gets burned, and it was true long before any of this existed. OpenAI has paused that testing while it rebuilds the room. An agent will do everything it can to reach the goal you give it. That is the best thing about it, and it's the worst thing about it. Hand it a goal, and the access, like you mean it. ## Sources - **The disclosure:** [OpenAI, "OpenAI and Hugging Face partner to address security incident during model evaluation"](https://openai.com/index/openai-hugging-face-security-incident/?ref=freshfromcache.com) (July 21, 2026). - **Hugging Face's side:** [Hugging Face, "Security incident disclosure"](https://huggingface.co/blog/security-incident-july-2026?ref=freshfromcache.com) (July 16, 2026). - **The software that was exploited:** [JFrog confirmed the package proxy was a self-hosted Artifactory installation](https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/?ref=freshfromcache.com), and that the flaws have been patched (July 27, 2026). - **The agents you can use now:** Google Auto Browse (US, AI Pro and Ultra tiers); Microsoft Copilot agent mode; OpenAI ChatGPT Agent. ### Also this week: iPhone leases, a movable taskbar, and a deepfake law in court URL: https://www.freshfromcache.com/also-this-week-2026-07-31/ Last updated: 2026-07-31T10:59:59.000Z I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Here is what caught my eye this week. ## Apple will rent you an iPhone now On Tuesday Apple launched Apple Upgrade, a leasing program run by the payment company Klarna. Twelve or twenty four months on an iPhone or a Watch, twenty four or thirty six on a Mac or an iPad, starting at $17.99 a month for a phone. The monthly number is lower than the old iPhone Upgrade Program, which Apple is shutting down along with iPhone Payments. Before you sign anything, understand that this is a lease and not a payment plan. At the end of the term you do not own the phone unless you pay a purchase fee. Getting out early can cost you what Apple's own fine print calls “substantial fees”. You can be billed for damage if the device comes back scratched up. Leasing is a reasonable answer to a $1,099 phone, but it is a different deal than buying one. Source: [CNN](https://www.cnn.com/2026/07/28/tech/apple-lease-products-iphone-mac?ref=freshfromcache.com) ## Windows is giving you back the taskbar you used to have Microsoft's fall update to Windows 11 puts the taskbar back where you want it. Top, bottom, left, right, your call. Windows 11 has only ever let you shove the icons over to the left corner, while the bar itself has been glued to the bottom since 2021, and people have complained about it ever since. The same update lets you shrink the taskbar, hide the parts of the Start menu you never use, and hide your name and picture from the Start menu while you are sharing your screen. Windows Search finally puts your own files and settings ahead of web results, with a switch to turn the web results off entirely. There is nothing to do about any of this now. It arrives this fall, and some of it will show up sooner in the regular monthly updates. Source: [Windows Central](https://www.windowscentral.com/microsoft/windows-11/windows-11-2026-update-26h2-changes-for-start-menu-taskbar-and-search?ref=freshfromcache.com) ## The first state law aimed at nudify apps is already in court Minnesota's new law takes effect Saturday. It goes after the software rather than the person using it: an app, a website, or a program is not allowed to let someone generate a fake nude image of a real, identifiable person. Elon Musk's AI company xAI sued the state attorney general on Monday to stop it. xAI argues the wording is too broad to survive the First Amendment because the definition of an intimate part would also cover a man with his shirt off or a woman in a swimsuit. Attorney General Keith Ellison says he will defend it. This is not an abstraction for the person it happens to. When a fake of you shows up today, [your options are thin and mostly depend on the platform](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/), which is exactly what a law like this one is trying to change. Other states are writing copies of it and watching this case. Source: [CBS Minnesota](https://www.cbsnews.com/minnesota/news/elon-musk-xai-sues-minnesota-law-banning-ai-nudification/?ref=freshfromcache.com) ## Amazon asked permission to put cell service in orbit Amazon filed with the FCC to launch up to 5,105 satellites that would beam voice calls, texts, data, and emergency service to an ordinary phone with no special equipment and no dish. Deployment starts in 2028 at the earliest, and the FCC has to approve it first, so this changes nothing about your dead spot this year. SpaceX has been sending texts to T-Mobile phones from orbit since last July, and [Amazon is already building a satellite internet service to compete with Starlink](https://www.freshfromcache.com/starlink-is-about-to-get-competition/). If you live somewhere the bars disappear on the drive home, two companies are now fighting over selling you coverage there. Source: [CBS News](https://www.cbsnews.com/news/amazon-leo-fcc-satellite-network-application/?ref=freshfromcache.com) ### The power company is not calling to cut you off in 30 minutes URL: https://www.freshfromcache.com/power-shutoff-scam-call/ Last updated: 2026-07-30T10:59:59.000Z The phone rings on a 95 degree afternoon. The screen shows your power company's name. The voice says your account is past due, a technician is already on the way, and the only way to stop the disconnection is to pay within 30 minutes with a prepaid card from the drugstore. Hang up. Every detail in that call is a lie, and during dangerous heat, the shutoff it threatens can be against the law. ## Summer scams This scam runs all year, but it surges when the weather turns dangerous. Utilities and the FTC have warned for years that impostor calls climb during heat waves and cold snaps. That's when losing power stops being an inconvenience and starts feeling like a threat to your life. Early this month the weather gave scammers the perfect opportunity. A heat dome settled over the eastern half of the country. More than 160 million people went under heat alerts. The Department of Energy declared a grid emergency across the 13 states served by PJM, the grid operator for the mid-Atlantic. Air conditioners ran around the clock, and everyone was focused on their electric bill. Wisconsin's utility commission put out a reminder at the end of June along with a warning. Threatening a same-day disconnection is the signature of this scam. A real utility will always provide a written timeline instead. ## The script The call barely varies. Your payment failed, or your account fell behind. A crew is on the way. You can stop it if you pay right now, but only the way the caller specifies. Usually a gift card or prepaid card you read the numbers off of. Often they will demand a Zelle transfer, a wire, or cryptocurrency as well. A newer twist on the scam texts you a QR code and tells you to take it to a store and pay at the register. The same scammers run email and text variations spoofing the utility's logo. That's the same impersonation tactic as [the phishing emails we've covered](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). Caller ID is no protection. Spoofing software lets a caller put any name and number on your screen, including your utility's real 800 number. Some operations staff a fake callback line, with hold music and menus that mimic the real company. All of that production exists to keep you from hanging up and dialing the number printed on your bill. (Your phone can also screen a lot of these calls before they ever ring; [we've covered those settings](https://www.freshfromcache.com/stop-spam-calls/).) Small businesses get their own variation. Restaurants report these calls arriving during the dinner rush, when the owner will pay almost anything to keep the kitchen running. PG&E logged about 650 reports of scam attempts against its business customers in the first half of 2026. ## What a real shutoff looks like A real disconnection typically arrives slowly. Before shutting anyone off, your utility sends written notice, usually more than one. They'll list the amount owed and the earliest date service could stop. State rules set the timeline, and it runs in weeks. Washington, for example, requires 14 days of written notice for electric and gas. ![A mailbox holding a stack of envelopes](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-mailbox.jpg) The first sign of a real disconnection is paper. Photo by Wolfgang Vrede on Unsplash. Your utility may call about a past-due balance. That call is a reminder, and it points you to the normal ways to pay: online, by mail, by bank draft, in person. FirstEnergy, which serves six states, says it in writing on its own scam page: its representatives will not call or email to demand immediate payment to avoid a same-day shutoff. And no utility in America takes payment in gift cards. The FTC's rule covers all of it: no real business or government agency will ever tell you to buy a gift card to pay them. ![Timeline diagram comparing a real utility shutoff, which moves through mailed notices over weeks, with the scam call and its 30 minute deadline](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/diagram-shutoff-timeline.png) ## In a heat wave, the threatened shutoff can be illegal During dangerous heat, a growing number of states forbid utilities from disconnecting residential customers at all, paid up or not. Washington bars electric and water shutoffs for nonpayment on any day the National Weather Service has issued a heat alert for your area. Oregon requires its regulated electric utilities (Portland General Electric, Pacific Power, and Idaho Power) to pause disconnections on any day with a heat advisory, watch, or warning, and for 48 hours after it ends. California tightened its rule on July 16: the state's utility commission voted to block disconnections whenever the forecast hits 90 degrees, down from the old trigger of 100. The LIHEAP Clearinghouse, the federal office that tracks these rules, counts 21 states plus Washington, D.C. with hot-weather shutoff protections. So on the day that call comes in, the disconnection it threatens may be one your utility could not legally perform even if you never paid another bill. Two caveats to these rules. First, they mostly bind the big regulated utilities; if your power comes from a rural cooperative or a small city utility, your state's laws may not reach it. Washington's law does cover public utility districts and city utilities, so that gap is smaller in the Northwest. Second, a heat pause only delays a shutoff. The balance is still owed when the weather breaks. ## If you really are behind on the bill This scam works best on the person who really is behind. The debt is real, so the threat feels real. That sense of shame can cloud people's judgment. If that's you, know that your utility would rather put you on a plan than shut you off; a disconnection costs them money too. ![A person at a wooden table reviewing a long receipt, with bills and a phone in front of them](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-bills.jpg) The number to call is already printed on the bill. Photo by Ahmet Kurt on Unsplash. Defeating the scam requires familiar advice: call the number printed on your bill. Ask for a payment arrangement. Every regulated utility offers them, and getting on one typically stops the disconnection process. Then ask about assistance. LIHEAP, the federal energy assistance program, helped pay the utility bills of nearly 6 million households in its last reported year, and the money usually goes straight to the utility. In Oregon it runs through Oregon Housing and Community Services and your local community action agency, and PGE and Pacific Power customers can also use the year-round Oregon Energy Assistance Program. In Washington, apply through the Department of Commerce's local providers. In California, apply through the Department of Community Services and Development's local agencies, and ask about CARE, the discount program that takes 20 to 35 percent off the electric bill depending on the utility. Anywhere in the country, dialing 211 connects you with local utility help. Those lines do not have people that will shame you. Signing people up is why they are there. ## If you already paid a caller Move fast; the first hours matter most. Call the gift card company at the number on the back of the card and ask them to freeze it. For Zelle, call your bank; since last summer, banks in the Zelle network investigate impostor scams reported within 120 days. Then report it to your real utility so it can warn other customers. We published [a full first-hour playbook](https://www.freshfromcache.com/what-to-do-after-a-scam/) this week that walks you through the whole sequence in order, including the follow-up scam where someone calls offering to "recover" your money for a fee. ## Look up the number yourself Earlier this month we covered [a hospital letter that looked like a scam and turned out to be real](https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/). This scam runs in the other direction. That letter was real, and this call is a fraud. Sorting them out works the same way: never act on the contact that reached you first. Find the number on your bill, or on the company's own website, and place the call yourself. A direct call to your utility company instantly clarifies where you stand. A real representative can confirm your balance, verify if any disconnection notice is actually scheduled, and walk you through available assistance programs if you are struggling. While fraudsters try to force your hand with a strict 30-minute deadline, verifying the facts on your own terms takes only a couple of minutes. ## Sources - [Public Service Commission of Wisconsin, via WBAY: Utilities can't be interrupted during dangerous heat](https://www.wbay.com/2026/06/30/psc-utilities-cant-be-interrupted-during-dangerous-heat/?ref=freshfromcache.com) (June 30, 2026) - [CalMatters: California restricts utility shutoffs during dangerous heat](https://calmatters.org/environment/2026/07/california-utility-heat-shutoff-rules-cpuc/?ref=freshfromcache.com) (July 2026) - [RCW 80.28.010: Washington's heat-alert shutoff prohibition](https://app.leg.wa.gov/rcw/default.aspx?cite=80.28.010&ref=freshfromcache.com) - [OAR 860-021-0407: Oregon's severe weather moratorium on involuntary disconnection](https://oregon.public.law/rules/oar%5F860-021-0407?ref=freshfromcache.com) - [LIHEAP Clearinghouse: Disconnect Policies](https://liheapch.acf.gov/Disconnect/disconnect.htm?ref=freshfromcache.com) - [LIHEAP Clearinghouse: California profile (LIHEAP and CARE)](https://liheapch.acf.gov/profiles/California.htm?ref=freshfromcache.com) - [Utilities United Against Scams: Top 10 Impostor Utility Scams](https://www.utilitiesunited.org/?ref=freshfromcache.com) - [FTC: Avoiding and Reporting Gift Card Scams](https://consumer.ftc.gov/articles/avoiding-and-reporting-gift-card-scams?ref=freshfromcache.com) - [FirstEnergy: Scams and Fraud](https://www.firstenergycorp.com/help/safety/scam-info.html?ref=freshfromcache.com) - [Oregon Housing and Community Services: Utility bill payment assistance](https://www.oregon.gov/ohcs/energy-weatherization/pages/utility-bill-payment-assistance.aspx?ref=freshfromcache.com) - [Washington Department of Commerce: LIHEAP](https://www.commerce.wa.gov/community-opportunities/liheap/?ref=freshfromcache.com) ### Millions of cars carry a Southern California dealer alarm with a security flaw URL: https://www.freshfromcache.com/the-car-alarm-you-never-bought/ Last updated: 2026-07-29T10:59:59.000Z Researchers at UC San Diego found that at least 2.2 million cars on the road today carry a dealer-installed Bluetooth alarm, and every one of those alarms answers to the same key. From about five yards away, someone holding that key can unlock the doors, shut off the alarm, honk the horn, or keep a parked car from starting. The device is called KARR. Most of the cars carrying one were sold at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 on. Every KARR unit relies on the same secure key, so cracking it once gets you all of them. Picture an apartment building where every unit takes the same key and none of the locks can be rekeyed. ## Not what you signed up for Dealers install KARR across their inventory to keep track of cars sitting on the lot. When one sells, the alarm and its app get offered at the finance desk as a paid upgrade. Turn it down and the hardware usually stays in the car anyway, wired in under the driver's side of the dash. The UC San Diego team estimates at least half the owners with a device never asked for one. Aaron Schulman, the study's senior author, says many of them do not know it is in there at all. Saying no does not switch it off either. The device stays active, and the car stays open to the attack. The study counted at least 1.4 million vulnerable cars, then revised the estimate past 2.2 million. Used-car sales carried them well past California, with several hundred thousand scattered across the United States, Canada, and as far as Japan. Public databases that log Bluetooth signals have also recorded where these devices have been, so a car with one can be traced back to the places it parks. One more thing in your car is [keeping track of where you go](https://www.freshfromcache.com/your-car-grades-your-driving/). ## The fix Acrisure, the company behind KARR, released a firmware update on July 20\. Firmware is the software baked into the device itself, so this is the same kind of fix as [every other patch you are told to install](https://www.freshfromcache.com/patching-is-the-new-password/). The researchers reported the flaw in January 2025, which puts the turnaround at about eighteen months. KARR told Popular Science it has not seen the attack used against a real car, and called the vulnerability highly complex and low risk in real-world conditions. The update does not arrive on its own. You download the KARR Security app, connect to the device over Bluetooth, and run the update yourself. Your car's manufacturer cannot push it out, because KARR is not their equipment. So the fix depends on you knowing about a device nobody told you about, then installing the app for a service you already declined. Acrisure says it will notify owners through the app, its website, and its dealers. Two of those three only reach people who already know this exists. The dealership is the easy target here, but Acrisure sat on the report for eighteen months. A second manufacturer named in the same study, Rockledge, had not answered the researchers at all when they published. The risk has real limits. Somebody has to be standing within a few yards of your car, and there is no evidence of this happening outside a lab. But the researchers point out that once a door is open, a thief can use ordinary locksmith tools to start the car and drive off, so "only the doors" is underselling the threat. ## How to check your car - **Check the driver's side window.** A sticker reading 'KARR' or 'SWDS' means the car probably has one. - **Look under the dash on the driver's side.** A small button with a blinking light means you have one. - **Update it if you find one.** Download the KARR Security app, connect to the device, then 'Customer Service' and 'Firmware Update'. It is free whether or not you ever paid for the service. - **Ask if you cannot tell.** The dealer who sold you the car can look it up, and KARR lists customer service contacts at KARRsecurity.com. - **Dig out your purchase paperwork.** Look for line items reading 'KARR', 'SWDS', or 'theft protection', the ones you bought and the ones you declined. This step applies to every car, not just the ones with a sticker. Most people reading this will check, find nothing, and be done in two minutes. If you live in Southern California, take a few extra minutes to confirm. There is a lesson to be learned: things get added to your car before you ever lay eyes on it, and saying no to the bill does not always mean saying no to the hardware. [The robot vacuum in the living room](https://www.freshfromcache.com/robot-vacuum-watching-you/) is a similar story. ## Sources - [UC San Diego: 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft](https://today.ucsd.edu/story/2-million-cars-with-anti-theft-systems-installed-by-dealers-are-at-higher-risk-of-theft?ref=freshfromcache.com) (July 21, 2026) - [Malwarebytes Labs: Millions of cars could be tracked and unlocked by a hidden security flaw](https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw?ref=freshfromcache.com) (July 23, 2026) - [Popular Science: 2 million cars at risk of sneaky Bluetooth hack that unlocks doors](https://www.popsci.com/technology/car-bluetooth-cybersecurity-hack/?ref=freshfromcache.com) (KARR’s statement) - [KARR Security: Firmware update instructions](https://karrsecurity.com/karr-security-firmware-update-instructions?ref=freshfromcache.com) ### The map your robot vacuum made of your house, the camera reading your license plate, and a deepfake takedown that costs nothing URL: https://www.freshfromcache.com/newsletter/your-vacuum-mapped-your-house/ Last updated: 2026-07-28T15:00:00.000Z I did not plan a week about being watched. It came out that way. A vacuum with a floor plan of your living room, a camera on a pole with your plate number, an AI video wearing your face. The one piece of good news is the first one: the vacuum flaw that scared me when I wrote it up got fixed this week, and nobody had to lift a finger. In this issue: - [Your robot vacuum has a map of your house, and the flaw that exposed it just got fixed](https://www.freshfromcache.com/robot-vacuum-watching-you/) - [What that black box on a pole is actually recording](https://www.freshfromcache.com/what-is-a-flock-camera/) - [How to get a deepfake of you taken down, for free](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/) - [The Odyssey scams that were ready before the weekend ended](https://www.freshfromcache.com/the-odyssey-piracy-scams/) - [AI tips for people who don't want to get left behind](https://www.freshfromcache.com/ai-tips-for-everyday-people/) - [Something new on Fridays](https://www.freshfromcache.com/also-this-week-2026-07-24/) - [This week's tech tip: make your phone stop ringing for robocalls](https://www.freshfromcache.com/stop-spam-calls/) Plus: three scams going around right now, arriving by text, by Facebook message, and in your actual mailbox. And the Scary Headline of the week: a browser extension sitting on 329 million machines could read your WhatsApp messages. --- [**Shark fixed the vacuum flaw. Here's what yours knows about you.**](https://www.freshfromcache.com/robot-vacuum-watching-you/) A researcher spent four months trying to hand SharkNinja a flaw before he published it on July 13\. He unscrewed a Shark robot vacuum he owned, pulled the security certificate out of it, and found the same certificate worked on other people's. With it he opened a second vacuum's camera while it drove around, read the map of the house it had been cleaning, and pulled the Wi-Fi password out in plain text. Listening for 24 hours, he counted more than 1.5 million Shark vacuums checking in, and about 673,000 answered a command he sent. Here is what changed since I first wrote this up: Shark fixed it on July 20, on their own servers, so there is nothing for you to unplug or update. It is still worth two minutes because of what it shows about how much a robot on your floor knows, and how little say you had over who could reach it. *Learn* --- [**What a Flock camera actually does**](https://www.freshfromcache.com/what-is-a-flock-camera/) That small black box on a pole with the solar panel bolted beside it, the one you have probably driven past a hundred times, is an automatic license plate reader. It photographs every car that passes, reads the plate, and files it with the date, the time, the location, and a description of the car in a database your police department can search. The description goes further than the plate: make, model, color, roof rack, bumper sticker, the dent you keep meaning to fix. Records are kept 30 days by default, and that number is a contract setting, which is how Flagstaff got theirs down to 14. *Learn* --- [**How to get a deepfake of you taken down**](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/) Last week's issue ended the deepfake block on a bad number: cleanup firms quote nine to twenty thousand dollars. Here is the version that costs nothing. Everything starts before you touch a report button. Screenshot the post, the account, and the comments. Screen-record the video, because a screenshot of a video proves one frame. Copy the links into a note with the date you found each one. If it is running as an ad, Meta's Ad Library shows you who paid for it. From there the path depends on what the fake is doing, and the post ranks the platforms by which ones actually move. Bookmark it for the day that hopefully never comes. *Learn* --- [**The Odyssey hit theaters Friday. The scams were ready by Monday.**](https://www.freshfromcache.com/the-odyssey-piracy-scams/) Two traps, both waiting for whoever types "watch The Odyssey free" into a search box, which in a lot of houses is not the adult. The first is a pop-up on a cloned torrent site reading "Browser Issue Detected" with a "Fix It Now" button. The warning is drawn by the webpage itself, which is why your browser lets it through. The second is a download listed as a 1080p copy with 597 seeders, wearing VLC's orange traffic cone icon, and underneath it is a Windows program. Two rules cover both: a movie still in theaters has no legal free stream anywhere, and a movie never arrives as something you install. *News* --- [**AI tips for people who don't want to get left behind**](https://www.freshfromcache.com/ai-tips-for-everyday-people/) The three complaints are always the same. The writing comes out generic, the whole thing feels clunky, and sometimes it makes things up. All three are fair. Most of the first one goes away once you stop treating AI as a search box you visit and give it a home instead. Every major tool now has a workspace you load once with what you do, who it is for, and a few examples of your own writing, and every chat you start inside it already knows all of that. ChatGPT and Claude call them projects. Gemini calls them Gems. That is one habit of seven in the post, and each one comes with why it works. *Blog* --- [**Something new on Fridays**](https://www.freshfromcache.com/also-this-week-2026-07-24/) I can't write a full post about everything that happens in tech in a week, and you don't have time to read one. So Fridays now get a short roundup: the handful of stories that actually reach everyday people, a sentence or two on why you should care, and a link to whoever reported it well. The first one covered rival Android app stores, the Siri public beta, and why phones are about to get more expensive. *News* --- If you only read one: the AI tips. Everything else in this issue is something happening to you. That one is something you can pick up on a Tuesday night and use on Wednesday. --- ### 5-Minute Tech Tip Your phone can screen the numbers you don't recognize instead of ringing for them. On a recent iPhone, Settings has an option to make unknown callers state their business before your phone makes a sound, and you get to read what they said. On Android, the Google Phone app and Samsung's dialer each have spam filtering that has to be switched on. Screening beats blocking every unknown number outright, because blocking everything also silences the school, the pharmacy, the delivery driver, and the plumber you called this morning: [Make your phone stop ringing for robocalls](https://www.freshfromcache.com/stop-spam-calls/). --- ### Fresh Trouble **A purchase you didn't make.** A text or email saying a laptop or a TV was just charged to your account, with a number to call and cancel it. Open the real app and look. The charge is usually not there. ([ConsumerAffairs](https://www.consumeraffairs.com/news/that-alarming-purchase-alert-may-be-the-first-step-in-an-expensive-scam-072226.html?ref=freshfromcache.com)) **The FBI offering to get your money back.** A message on Facebook or Telegram following up on a fraud report you filed, sometimes with video of what looks like a senior FBI official. The bureau's complaint center has no social accounts and will not message you. ([FBI](https://www.ic3.gov/PSA/2026/PSA260720?ref=freshfromcache.com)) **A letter about unclaimed life insurance.** A law firm writes that someone who shares your last name died and left millions, and offers to split it with you. The FTC says this one is back after a few years off. ([FTC](https://consumer.ftc.gov/consumer-alerts?ref=freshfromcache.com)) --- ### Scary Headline of the Week *"Adobe Chrome extension flaw let sites access private WhatsApp chats."* The finding is real. Researchers at Guardio Labs found a chain of bugs in Adobe's Acrobat extension for Chrome, the PDF one sitting on roughly 329 million browsers. Visiting the wrong page was enough for that page to reach into WhatsApp Web in another tab and read your chat list, your contacts, and whatever conversation you had open. The headline leaves out that Adobe patched it over a single weekend, the fix installs itself, and the researchers found no sign anybody used it before the patch landed. There was also no hole in WhatsApp. The weak point was the extension. A browser extension is software with permission to read every tab you open, which is the same reason Microsoft [pulled 119 Edge extensions for malware](https://www.freshfromcache.com/microsoft-pulls-edge-extensions-due-to-malware/) last month. Open your extensions list this week and remove anything you don't remember adding. Verdict: already fixed, but a good excuse to clean out your extensions. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help that won't cost you anything: forward it to someone who could use it, and if it was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. --- Do you own a Shark vacuum, and did you unplug it when this first went around? Hit reply and tell me. Joel ### You just got scammed. What now? URL: https://www.freshfromcache.com/what-to-do-after-a-scam/ Last updated: 2026-08-11T18:28:10.000Z If you are reading this because it just happened, [skip to the list](#the-order). Come back for the rest later. This page has a printable version: a two-page card with the four steps and every phone number on it. Print it and put it in a drawer before anything goes wrong. [Download the card (PDF)](https://www.freshfromcache.com/content/files/2026/07/first-hour-after-a-scam.pdf). It is part of [The Cache](https://www.freshfromcache.com/cache/), our free library of printable guides. You did nothing shameful. You met a professional criminal who does this all day and who has practiced the exact script that worked on you. A bad afternoon becomes a drained account in the hours people spend feeling embarrassed before they pick up the phone. So the goal here is speed. Do these in order. ## The order 1. [Stop the money.](#1-stop-the-money) 2. [Lock your email, then everything your email can reset.](#2-lock-your-email-first) 3. [Report it.](#3-report-it-and-know-what-each-report-actually-does) 4. [Expect a second scam offering to get your money back.](#4-expect-the-second-scam) Work top to bottom. If you only get through the first two, you've done the most important steps. What you handed over decides which parts apply: money, information, or access to your computer. Most people gave up more than one, so read the two branches at the bottom as well. ## 1\. Stop the money Call, do not email. You want a human who can put a hold on something. **If you paid by credit card.** Call the number on the back of the card and say the charge was unauthorized. Federal law caps what you can be held responsible for at $50, and that cap does not shrink because you waited a day. Visa and Mastercard both go further and advertise zero liability. You have 60 days from the statement showing the charge to dispute it in writing. Call today anyway. One catch. This works cleanly when the charge was made without your permission. If a scammer talked you into paying them yourself, the dispute gets harder and the argument shifts to not receiving what you paid for. Make the call regardless and describe exactly what happened. **If you paid by debit card, or money left your checking account.** This one has a clock, and it is the reason to call immediately. Your liability is capped at $50 if you report within two business days of finding out. After two business days it rises to $500\. Past 60 days from the statement the cap is gone and the loss can be all of it. Once you report, the bank has 10 business days to investigate, or up to 45 days if it puts the money back provisionally while they work. **If you sent a bank wire.** Two calls, same hour, and the second one is not paperwork. Call your bank's fraud line and ask them to recall the wire. Then file at ic3.gov, the FBI's Internet Crime Complaint Center. That report is what puts the FBI's Recovery Asset Team on the phone with the receiving bank asking it to freeze the account. In 2025 that team froze $679 million out of $1.16 billion in reported attempted theft. That's about a 58 percent success rate. The rate has been sliding (it was 74 percent in 2023) and it depends almost entirely on how fast the report is filed. The FBI's process is built around a 72-hour window. **If you sent money through Zelle.** The words you use matter. If someone got into your account and moved money without you, that is an *unauthorized* transfer, and federal law says the bank owes it back. If you were tricked into sending it yourself, that protection does not apply. Since June 2023 Zelle's own rules require participating banks to reimburse "qualifying" imposter scams. For example, someone posing as your bank, [a government agency, or a utility](https://www.freshfromcache.com/power-shutoff-scam-call/). Zelle has never published what qualifies, and banks apply it unevenly. Ask your bank in writing for its imposter-scam reimbursement policy and its appeal process, then keep the reply. Bridging that gap is being fought for as we speak. The Consumer Financial Protection Bureau sued Zelle's owner and three large banks over it in December 2024, then dropped the case in March 2025\. New York's attorney general filed her own suit in August 2025, and a judge has let it move forward. **If you bought gift cards.** Call the card's company, not the store. Keep the physical card and the receipt, because they will ask for numbers off both. Some issuers can freeze whatever has not been drained yet, and drained-in-minutes is the norm. So this is a first-hour call. - Amazon 1-888-280-4331 - Apple 1-800-275-2273 (say "gift card") - Google Play: report it online at support.google.com/googleplay/answer/9057338 - Best Buy 1-888-237-8289 **If you used Western Union, MoneyGram, or Ria.** Call and ask them to reverse the transfer. - MoneyGram 1-800-926-9400 - Western Union 1-800-448-1492 - Ria 1-877-443-1399 If the cash has been picked up on the other end it is gone, but the call takes two minutes. **If you paid through Venmo, Cash App, or PayPal.** Report it in the app. Then, if the app pulls from a card, call that card issuer and dispute it there too. The card is where the legal protection lives. **If you sent cryptocurrency.** Assume it is gone. There is no chargeback, no reversal, and no company to call. File at ic3.gov anyway, because investigators do sometimes trace funds to an exchange that will freeze them, and because the report feeds cases. File it, then read step four twice. Crypto victims get worked for the second scam harder than anyone. **If you mailed cash.** Call the U.S. Postal Inspection Service at 877-876-2455 and ask about a package intercept. It only works before delivery, so call as soon as possible. ## 2\. Lock your email first Email is a master key. Every password reset for your bank, your card, your retirement account and your Amazon account arrives in that inbox. So somebody sitting in your email can undo everything else you do. Change that password from a different device than the one that was involved. If a scammer had any access to your computer, a keylogger on it can capture the new password while you type it. Use your phone on cellular, or a family member's laptop. Then, in your email account's security settings: **1\. Sign out everywhere.** Look for 'Sign out of all sessions' or 'Sign out of all devices'. A new password does not kick out someone who is already logged in. **2\. Check your forwarding rules and your filters.** People skip this step, and it is the one that keeps bad actors in the account after the password change. In Gmail: - Settings - 'See all settings' - the 'Forwarding and POP/IMAP' tab - the 'Filters and Blocked Addresses' tab In Outlook: - Settings - 'Mail' - 'Forwarding', and check your rules while you are in there A forwarding rule survives a password change. So does a filter that deletes your bank's security alerts before you ever see them. CISA has documented this as a standard move, and Barracuda's 2026 email report found inbox-rule changes in 25 percent of account takeovers. **3\. Check your recovery email address and recovery phone number.** If either one has been changed to something you do not recognize, fix it. That is how someone locks you out tomorrow. **4\. Turn on MFA**, or multi-factor authentication, sometimes called two-factor or 2FA. If it was already on, remove any device or authenticator app you do not recognize and set it up fresh. Then work outward in this order: bank and financial accounts. Then anywhere you have a card saved (Amazon and the rest). Then social media, which is what gets used to scam your friends and family next. If you were reusing that email password anywhere else, every one of those accounts is now on the list too. That is the argument for [a password manager](https://www.freshfromcache.com/start-using-a-password-manager/), and it is the rebuild step once this is all over. ## 3\. Report it, and know what each report actually does Each one does a specific job. - **ic3.gov (FBI).** For a wire this is a money-stopping action, not a filing. See step one. Put in every detail you have: dates, amounts, account and routing numbers, the receiving bank, wallet addresses. - **reportfraud.ftc.gov (FTC).** Feeds a database that state and federal investigators actually query. The FTC says plainly that it cannot resolve individual reports, so do not sit waiting on a reply. - **identitytheft.gov (FTC).** If personal information was involved, this one builds you a written recovery plan, generates an official FTC Identity Theft Report, and pre-fills dispute letters. - **Your local police department.** Your bank or your insurer may require a police report number before reimbursing anything. That is the reason to file, even knowing the department is not going to chase an overseas call center. - **Your state attorney general.** This is the office that sues companies over patterns, which is how the Zelle cases above happened. ## 4\. Expect the second scam The people who got you know one thing about you now: you are a known victim who has money to lose and a reason to want it back. That fact gets sold, and a second crew works the list. On July 20, 2026 the FBI put out a warning about exactly this. Scammers build fake FBI profiles on social media, reach victims through Facebook Messenger and Telegram, and offer to recover the stolen money. Some of them run AI-generated video of a senior FBI official to promote a spoofed IC3 website that harvests your name, your phone number, and how much you lost. Four rules to hold onto: - IC3 will never contact you by phone, email, social media, chat, or a messaging app. If more information is needed, a real FBI employee from a local field office reaches out. - IC3 has no social media presence at all. Any account claiming to be IC3 is fake. - IC3 will never ask for payment to recover your money, and will never refer you to a company that charges for it. - Type ic3.gov into the address bar yourself. Skip the sponsored search results in Google; imitators buy those. The rule that covers all of it: anyone who contacts *you* offering to get your money back is the same scam, second act. Real recovery never cold-calls. ## If they got into your computer If you let someone remote in (AnyDesk, TeamViewer, Quick Assist, "let me just show you the problem"), ran a file, or pasted a command they gave you, treat it as a full compromise even if it was only ten minutes. Ten minutes is enough to copy every password saved in your browser, take the session cookies that keep you logged in to your accounts, and leave something malicious behind that survives a reboot. ![Illustration of a masked figure pulling puppet strings attached to a person's hand on a computer mouse, with a password login screen on the laptop](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-puppet-strings.jpg) Remote access means someone else is driving. Anything your saved passwords could reach, they could reach too. Illustration: Eva Wahyuni / Unsplash 1. Disconnect from the internet. Turn the Wi-Fi off or pull the network cable. That ends their session immediately. 2. From a different device, change your email password. [Step two above.](#2-lock-your-email-first) 3. Uninstall the remote-access program. Windows: Settings, then 'Apps', then 'Installed apps'. Remove AnyDesk or whatever they had you install, plus anything else dated today that you did not put there. Do not just delete the folder. 4. Run a full scan. 'Windows Security', then 'Virus & threat protection', then 'Scan options', then 'Full scan'. Be straight with yourself about what a scan does. It finds known malware. It does not undo files they already copied, and it cannot promise you a clean machine. If they ran programs you cannot account for, or if this is the computer where you do your banking, the cleanest answer is a full Windows reinstall. A reinstall is easy if you have [a backup](https://www.freshfromcache.com/do-you-need-backups/) and miserable if you do not. If the way in was a fake CAPTCHA or a "press Windows+R and paste this" prompt, that is [a specific scam we have covered](https://www.freshfromcache.com/fake-captcha-scam/), and the recovery steps there apply on top of these. ## If you gave up your Social Security number [Freeze your credit](https://www.freshfromcache.com/freeze-your-credit/) at all three bureaus. It is free by law, it takes a few minutes online at each one, it does not touch your credit score, and it does not stop your existing cards from working. It is the highest-value move on this page. It also has to be done three separate times, because a freeze at one bureau does not carry to the other two. - Equifax 1-888-298-0045 - Experian 1-888-397-3742 - TransUnion 1-888-909-8872 One thing to watch. A "lock" is not the same as the free freeze. Equifax will offer you Lock & Alert; the freeze is the one the law makes free, and the freeze is the one you want. Then get an IRS Identity Protection PIN, or IP PIN. It is a six-digit number that stops anyone else from e-filing a tax return under your Social Security number. Any taxpayer can request one through an IRS online account, and it renews every year. Note that the tool goes offline from roughly November to mid-January, so if you are reading this in December, put it on the January list. Then let identitytheft.gov build the rest of your plan. If what leaked was your bank account number rather than your Social Security number, that is a different job. Ask the bank to issue a new account number and watch the statements. A new account number does nothing for an exposed Social Security number, which is why the freeze is the answer there. Skip the paid monitoring pitch. Monitoring tells you after something happened; a freeze stops it from happening. You can pull all three reports yourself for free at annualcreditreport.com. ## One number, for scale In 2024 people in the United States reported losing $12.5 billion to fraud, up 25 percent in a single year. Adults 60 and over reported $2.4 billion of that, up from about $600 million in 2020\. The FTC's own estimate is that the real figure for older adults could run as high as $81.5 billion, because most of it never gets reported at all. Which is the whole reason the top of this page reads the way it does. You may be thinking this is unlikely to happen to you. But it does happen, every single day. It doesn't just happen to inexperienced users. These scams are so widespread, they count on people being busy, tired, confused, or just careless. I've seen even the most principled security professionals still get caught up in a phishing email. I've done it myself. A lot of the time it's a matter of when, not if. If you respond correctly, often you'll be just fine. Bookmark this page now, while nothing is wrong. Then send it to whoever in your family would call you first, because the hour they spend being embarrassed is the hour that costs them. If you are in the middle of it right now and you want a person instead of a page, AARP runs a free fraud helpline at 877-908-3360, weekdays 8am to 8pm Eastern. If the victim is 60 or over, the Justice Department's Elder Fraud Hotline is 833-372-8311. ## Sources - FTC, [What To Do if You Were Scammed](https://consumer.ftc.gov/articles/what-do-if-you-were-scammed?ref=freshfromcache.com) - FTC, [IdentityTheft.gov](https://www.identitytheft.gov/?ref=freshfromcache.com) and [ReportFraud.ftc.gov](https://reportfraud.ftc.gov/?ref=freshfromcache.com) - FBI, [2025 Internet Crime Report](https://www.ic3.gov/AnnualReport/Reports/2025%5FIC3Report.pdf?ref=freshfromcache.com) (Recovery Asset Team figures) - FBI, [PSA I-072026-PSA: Scammers Impersonating the IC3](https://www.ic3.gov/PSA/2026/PSA260720?ref=freshfromcache.com), July 20, 2026 - CFPB, [Electronic Fund Transfers FAQ](https://www.consumerfinance.gov/compliance/compliance-resources/deposit-accounts-resources/electronic-fund-transfers/electronic-fund-transfers-faqs/?ref=freshfromcache.com) and [Regulation E section 1005.6](https://www.consumerfinance.gov/rules-policy/regulations/1005/6/?ref=freshfromcache.com) - CISA, [Analysis Report AR21-013A](https://www.cisa.gov/news-events/analysis-reports/ar21-013a?ref=freshfromcache.com) (email forwarding-rule persistence) - IRS, [Get an Identity Protection PIN](https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin?ref=freshfromcache.com) - FTC, [Protecting Older Consumers 2024-2025](https://www.ftc.gov/?ref=freshfromcache.com) and Consumer Sentinel Network Data Book 2024 - AARP, [What to Do After You've Experienced a Scam](https://www.aarp.org/money/scams-fraud/what-to-do-after-scam/?ref=freshfromcache.com) ### Google wants a video of your face. Skip it for now. URL: https://www.freshfromcache.com/google-wants-a-video-of-your-face/ Last updated: 2026-07-27T11:00:00.000Z Google started rolling out a new way back into your account on Thursday, July 23\. You record a short video of your face, Google keeps it. That way, if you ever get locked out, you record a fresh one so Google can compare the two. The feature is called "selfie video". It is optional and it is arriving gradually on personal Google accounts. It is not offered on Workspace accounts or kids' accounts. Malwarebytes covered it the next day with a one-line verdict: do not enable it. I would suggest the same. But the reason has almost nothing to do with whether the feature works well or not. ## What Google actually built Setup runs from your Google Account, under Security, in the "How you sign in to Google" list. You pick "Selfie video," look into the camera, and turn your head a few times while it records. Google stores that recording and says it is encrypted at rest. A separate option called "Improve Google services" lets Google use your video to develop its facial recognition and age-estimation systems. That setting is off by default, and Google deserves some credit for that. ## Actually using this feature is where it is weakest An account is only as strong as the easiest way back into it. That is the entire reason SIM swapping exists. Michael Terpin lost $23.8 million in cryptocurrency in 2018 after someone talked an AT&T retail employee into moving his phone number onto a new SIM card. Nobody cracked a password. They were able to take over the recovery and let the reset links come to the "new" phone. Selfie video is another way back in. It feels like adding a lock, but it's also adding a door. ## Your iPhone already scans your face, so what is different here? Face ID keeps a mathematical model of your face inside a chip on the phone called the Secure Enclave. Apple's own security documentation says that data never leaves the device and is not included in your backups. If you lose or break your device, the model goes with it. Google's copy lives on Google's servers. It has to. A recording sitting on a phone you lost cannot let you back into anything. What makes this feature useful is the same thing that stacks the risk in one place, and that place is not your pocket. ## Faces are having a rough month We spent last week on exactly this problem: [what to do when an AI deepfake has your face](https://www.freshfromcache.com/ai-deepfake-has-your-face/), then [the takedown playbook](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/). Now a face is being offered as an account key. Google says it screens for fakes by matching your video and asking for those simple movements. Its usual suspicious-sign-in checks apply on top of everything else. Fair enough. But researchers at Zhejiang University tested 19 phone apps that verify people by face and beat more than 70 percent of them by feeding doctored video straight into the camera feed. When NIST tested 82 fake-detection algorithms, none of them caught every type of attack. Neither study tested Google though, which has defenses a random app does not. It is the ground this feature is standing on. Google also does not offer selfie video to anyone in its Advanced Protection Program, the hardened setup it recommends for journalists, campaign staff, and executives. That is Google ranking its own sign-in option. The most at-risk accounts aren't even allowed to use it. ## What decides it for me? The undo. Google's help page says the video will be deleted "after a period of time," and never says what that period is. It also says deleting the video may cost you access to "some advanced features," and never says which ones. If a password of mine leaks, I can change it that morning. My own face isn't quite as easy to change. ## Google is solving a real problem People lose accounts for good every day, usually because the recovery email died years ago and the phone number belongs to somebody else now. Today's policy also seems reasonable: encrypted storage, a real delete button, the training option off unless you turn it on. My hesitation is about how long "today" lasts. And you have to set this up before you need it, so the person who needs rescuing cannot add it in the moment anyway. There are a few things you can do to close the gap. ## A few steps you can take - **Leave selfie video off.** If you already turned it on, go back to the same Selfie video page in your Google Account and delete the recording. - **Check your recovery phone and backup email.** Both live under Security in your Google Account. A dead recovery address is how most people end up locked out permanently. Our [five-minute recovery check](https://www.freshfromcache.com/email-recovery-check/) walks Gmail and Outlook. - **Print your backup codes.** Google Account, Security, 2-Step Verification, Backup codes. You get ten, each works once, and they do not care whether your phone still exists. Keep them where you keep your passport. If the extra login step still bugs you, [we made the case for it here](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/). - **Add a passkey.** It signs you in with your phone's own screen lock, and the key never leaves the device. Start at g.co/passkeys, or read [what a passkey actually is](https://www.freshfromcache.com/what-the-heck-is-a-passkey/) first. Do those four this week and you have covered the lockout that selfie video is meant to prevent, without handing over the one credential you can never reissue. Then if you ever do get locked out, you will not need to prove your face is yours to anybody. **Sources** - **Source:** Google, [Introducing selfie for sign-in](https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/?ref=freshfromcache.com), July 23, 2026. - **Google's documentation:** Google Account Help, [Take, manage and use a selfie video](https://support.google.com/accounts/answer/16675622?ref=freshfromcache.com). - **The recommendation:** Pieter Arntz, [Google wants to store a selfie video of your face](https://www.malwarebytes.com/blog/privacy/2026/07/google-wants-to-store-a-selfie-video-of-your-face?ref=freshfromcache.com), Malwarebytes Labs, July 24, 2026. - **On Face ID:** Apple, [About Face ID advanced technology](https://support.apple.com/en-us/102381?ref=freshfromcache.com). - **The mobile-app research:** Yu et al., [Facial Authentication Security Evaluation Against Deepfake Attacks in Mobile Apps](https://link.springer.com/chapter/10.1007/978-981-96-9101-2%5F19?ref=freshfromcache.com), ACISP 2025. - **The independent testing:** NIST, [Face Analysis Technology Evaluation (FATE) Part 10](https://www.nist.gov/publications/face-analysis-technology-evaluation-fate-part-10-performance-passive-software-based?ref=freshfromcache.com), NIST IR 8491, September 2023. - **The SIM-swap case:** [Terpin v. AT&T Mobility LLC](https://cdn.ca9.uscourts.gov/datastore/opinions/2024/09/30/23-55375.pdf?ref=freshfromcache.com), U.S. Court of Appeals for the Ninth Circuit, September 30, 2024. ### Make your phone stop ringing for robocalls URL: https://www.freshfromcache.com/stop-spam-calls/ Last updated: 2026-07-26T10:59:59.000Z You know the one. Unknown number, you pick up out of habit, and it's a recorded voice about your car's extended warranty or a problem with an account you don't have. You hang up. An hour later they call back from a different number. Your phone has had a fix for this built in for years, but most people have never switched it on. In about five minutes you can tell your phone to stop letting strangers ring through, or better, make them say who they are before it even rings. Think of it like a doorman. The basic setting turns away anyone you don't already know. The better setting asks them to state their business first, then lets you decide. Robocallers hang up the second your “doorman” asks a question. Real people will typically respond to it. ## On an iPhone (iOS 26) Open Settings, scroll down to Apps, and tap Phone. Find "Screen Unknown Callers." You get three choices: - **Silence.** Any number not in your contacts goes straight to voicemail without ringing. - **Ask Reason for Calling.** Your phone answers unknown calls itself and asks the caller who they are and why they're calling. Real callers get put through and you see what they said. This is Apple's newer call screening, and it's the one I'd pick. - **Never.** Everyone rings through. This is the default. While you're on that screen, tap "Call Filtering" and turn the spam options on so junk numbers get labeled. (On an older iPhone running iOS 18 or earlier, it lives at Settings > Phone > Silence Unknown Callers, with no screening option.) ## On an Android phone (the Google Phone app) Open the Phone app, tap the three dots at the top, and go to Settings, then "Caller ID & Spam." Turn on "See caller & spam ID" so suspected spam gets labeled before you answer. Below it, "Filter spam calls" sends the high-risk ones straight to voicemail without ringing. If you have a Pixel, there's also Call Screen, which works like Apple's version: Google answers, you read a live transcript, and you decide whether to pick up. ## On a Samsung Galaxy Samsung runs its own phone app. Open it, tap the three dots, go to Settings, then "Caller ID and spam protection," and turn it on along with "Block spam and scam calls." ## Use caution The strongest options, silencing every unknown caller or blocking any number that isn't in your contacts, will also silence your kid's school, the pharmacy, a delivery driver, and the plumber you've been waiting on all day. Anyone you haven't saved is a stranger to your phone. That's why the screening option, the one that makes callers say who they are, beats the blunt "send everyone to voicemail" for most people. You keep the calls that matter and you lose the robocalls. ## Try it for a day Turn it on, then give it a day. If your phone rang less and you didn't miss anything real, you set it right. If a call you wanted slipped through to voicemail, switch from "silence" to the screening option and you'll get the best of both. If robocalls have found a new angle on you lately, I want to hear it. Hit reply and tell me what they're pretending to be this time. ## Sources - [Apple: Screen and block calls on iPhone](https://support.apple.com/guide/iphone/screen-and-block-calls-iphe4b3f7823/ios?ref=freshfromcache.com) - [Google: Use caller ID and spam protection (Phone app Help)](https://support.google.com/phoneapp/answer/3459196?hl=en&ref=freshfromcache.com) - [Samsung: Block spam calls with Smart Call on your Galaxy phone](https://www.samsung.com/us/support/answer/ANS10003438/?ref=freshfromcache.com) ### What a Flock camera actually does URL: https://www.freshfromcache.com/what-is-a-flock-camera/ Last updated: 2026-07-25T15:08:38.000Z You have probably driven past one. A small black box on a pole, eight or ten feet up, often with a little solar panel bolted alongside it. No wires running anywhere. Most of us saw it once, figured it was a speed camera, and never thought about it again. But speed has nothing to do with it. That box is an automatic license plate reader, usually shortened to ALPR, and the company behind most of the ones you see is Flock Safety. It photographs every car that goes by. Software reads the plate off the photo. It saves the plate number, the date, [the time, the location](https://www.freshfromcache.com/your-photos-know-where-you-live/), and a description of the car. It then uploads all of it to a database your police department can search. It's really that simple. A logging machine on a pole. The argument the city council has been having is about who gets to search the log. ## What it records The plate is the obvious part. But wait, there's more. Along with the number, the system records what Flock calls a vehicle fingerprint. The fingerprint includes: - Make - Model - Color - The state the plate was issued in - Whether the plate is missing or covered Additionally it collects features that make your car yours. A roof rack. A bumper sticker. The dent you keep meaning to fix but haven't. ![The rear of a parked tan sedan, license plate visible](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-plate.jpg) The plate is the start of the record, not the whole of it. Photo: joshua-jumarie/Unsplash It does not record faces. Flock says its plate readers do not use facial recognition and cannot identify people. The company also sells a separate video line that does detect people, which is a different device with a different set of concerns attached to it. By default the pictures and the records are kept for 30 days, then deleted automatically. That number is a contract setting, so it's not set in stone. Flagstaff, Arizona cut theirs to 14 days. Washington and Virginia now cap it by law at 21\. An agency can also ask to keep records longer. Thirty days does not sound like much until you think about what 30 days of your own driving would show. Your car already generates a private trail of its own ([your car grades your driving](https://www.freshfromcache.com/your-car-grades-your-driving/)); this one is bolted to public infrastructure, and [nobody asked you to agree](https://www.freshfromcache.com/smart-glasses-recording-you/) to a terms of service. ![Cars spread across many lanes of a highway, seen from an overpass](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-highway.jpg) Thirty days of this, searchable. Photo: Getty/Unsplash+ ## How the searching works The searching of this information is done in three ways. The first is a hot list alert. A plate tied to a stolen car or an arrest warrant passes a camera, and an officer's in-car computer pings in real time. That one is aimed at a specific plate. The second is a lookup. An officer types in a plate and sees everywhere that car was photographed inside the retention window. That one is aimed at a specific car, after the fact. The third is the National Lookup Tool. An agency that shares its own camera data can search the camera data of every other agency that shares. Flock told Senator Ron Wyden that about 75 percent of its law enforcement customers are enrolled. So a search run in another state can bring up the picture of your car taken two blocks from your house. Every search does require the officer to type a reason. Which is just a free text field. ![Diagram of the Flock data path: the camera photographs every passing car, the record includes plate, time, location, and vehicle description, it is kept in a local database for 30 days by default, and about 75 percent of police customers share into a national lookup network any enrolled agency can search](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/flock-data-path-2.png) ## What it is good at There is some good that has come from the Flock cameras. Flock says its cameras helped recover six abducted children in Colorado over five months, five of them tied to AMBER Alerts. In one Aurora case officers found a 14-month-old in under ten minutes. Stolen car searches are the everyday use. Nationally, only about 9 percent of car thefts are ever cleared, the lowest rate of any major crime category. Departments running these camera reports are finding vehicles they otherwise may not have. The Los Angeles Police Department's own audit is a good measure, because LAPD is the department that just canceled their Flock contract. In two months, plate reader data helped recover 337 stolen vehicles and contributed to 74 felony arrests. That is the trade off. ## Where it goes wrong The same LAPD audit is why the department let its Flock contract lapse on July 11. The Inspector General reviewed August 1 to September 30 of 2025\. In that window the cameras took more than 210 million pictures of plates and generated 498 stolen-vehicle alerts. Of those, 161 were correct readings of cars that turned out not to be stolen. About one alert in three sent officers after an innocent driver. These cameras were not misreading the plates. The lists behind the plates were stale. The lists include recovered cars that never cleared from the system and typos in the original report. The camera did its job perfectly, but it handed out incorrect information to the police. That matters because a stolen-vehicle stop is handled as high risk. Backup, a supervisor, the driver ordered out of the car, guns drawn. The Institute for Justice has documented at least 27 cases of innocent drivers pulled over, held at gunpoint, or jailed on bad plate-reader hits. In Sherwood, Arkansas this February, a couple was taken out of their car at gunpoint while their six-week-old sat in the back seat. ## Who else is searching? Mountain View, California found out through a public records request that a statewide sharing setting had been left on for 29 of its 30 cameras for 17 months. In that time more than 250 agencies that had never signed an agreement with the city ran about 600,000 searches. The city said Flock enabled a nationwide setting without its knowledge and called it a system failure on the company's part. Flock's position is that sharing settings are always under the agency's control. Mountain View turned every camera off in February. Then there is the thread that has driven most of the national coverage. The outlet 404 Media obtained one Illinois department's search logs and found more than 4,000 statewide and national lookups run between June 2024 and May 2025 either at the request of federal agents or with an immigration-related reason typed in the box. Immigration and Customs Enforcement holds no contract with Flock. It reached the data through local and state police who do. Flock has since pulled some states out of the national tool and added keyword filters. However, Senator Wyden and the ACLU point out that the reason field is still free text, so a filter is easy to work around. There is also plain misuse, and here the company and its critics mostly agree on the facts. The Institute for Justice counts at least 24 cases of officers using plate readers to track romantic partners and exes. A police chief in Sedgwick, Kansas ran his ex-girlfriend more than 200 times before he resigned. Flock says a new audit feature is what flagged several of those searches, and that the technology did not create the misuse, people did. Both statements can be true, but the disagreement is about whose job it is to catch the misuse. ## Does my town have these? Four ways to find out, easiest first. - **Check the map.** A crowdsourced project called DeFlock maps reported cameras at [deflock.me](https://deflock.me/?ref=freshfromcache.com), including which way each one faces. It is volunteer-built and incomplete, so a blank spot is not proof. - **Look for a transparency portal.** Some departments publish one with basic search statistics. Not all do. - **Read the council minutes.** These contracts usually pass at a regular meeting with a thin crowd. The site [ALPR.watch](https://alpr.watch/?ref=freshfromcache.com) tracks upcoming agendas. - **File a records request with the police department**, not with Flock. The department holds the data. Ask for the contract, the retention setting, and the sharing logs. Locally, in Oregon, a lot has moved. Bend ended its pilot early in January. Eugene, Springfield, Albany, Woodburn, and the Lane County Sheriff have turned cameras off or pulled them out. As of last November the ACLU of Oregon had confirmed Flock use in at least ten counties and had not confirmed any in Multnomah County. Portland police use a different vendor. Both states also wrote rules this year. Oregon's SB 1516 requires deleting images after 30 days unless they are tied to an investigation, limits out-of-state access, and requires an officer to log and justify every search. Washington's SB 6002 took effect March 30 and goes further: 21 days, a short list of crimes the system may be used for, and no cameras near schools, clinics, or places of worship. ## What you can do about your own car Not much. There is [no opt-out and no delete button](https://www.freshfromcache.com/what-is-a-data-broker/). Flock's position is that the agency owns the data. When a California resident filed a deletion request under state privacy law, the company sent them to the police department. Do not cover your plate. Florida banned frames, covers, and sprays outright last October, and most states already had similar rules. An obscured plate is its own reason to get pulled over. You'd be trading a database entry for a traffic stop. What actually works is local. These cameras arrive by contract and leave by contract. Every one of the towns above got there through a council vote. ![An empty meeting room with microphones and chairs along a long table](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-meeting.jpg) Where the decision actually gets made. Photo: planet-volumes/Unsplash Pull up the map first. If your town has them, there are two questions to ask at the next meeting: how long the pictures are kept, and whether the national sharing is turned on. Neither one should be a mystery. Both are settings somebody has to choose. **Sources** - [404 Media on the LAPD Office of the Inspector General ALPR audit](https://www.404media.co/lapd-regularly-pulled-over-innocent-people-because-license-plate-readers-flagged-their-cars-as-stolen/?ref=freshfromcache.com) (July 2026) - [Institute for Justice, wrongful-stop analysis](https://ij.org/dozens-of-innocent-motorists-have-been-pulled-over-detained-at-gunpoint-or-jailed-due-to-ai-license-plate-camera-errors/?ref=freshfromcache.com) and [officer-misuse analysis](https://ij.org/police-have-reportedly-used-license-plate-readers-to-stalk-romantic-interests-at-least-14-times-in-recent-years/?ref=freshfromcache.com) (updated July 2026) - [404 Media, Flock search-log reporting](https://www.404media.co/ice-taps-into-nationwide-ai-enabled-camera-network-data-shows/?ref=freshfromcache.com) (May 2025) - [Senator Ron Wyden, letter to Flock Safety](https://www.wyden.senate.gov/imo/media/doc/wyden%5Fletter%5Fto%5Fflock.pdf?ref=freshfromcache.com) (PDF, 2025) - [Flock Safety, license plate reader policy](https://www.flocksafety.com/legal/lpr-policy?ref=freshfromcache.com) - [Washington SB 6002 (MRSC summary)](https://mrsc.org/stay-informed/mrsc-insight/april-2026/restrictions-flock-cameras?ref=freshfromcache.com) and [Oregon SB 1516 (KLCC)](https://www.klcc.org/politics-government/2026-03-06/oregon-lawmakers-pass-new-guardrails-for-automatic-license-plate-readers?ref=freshfromcache.com) ### Also this week: rival app stores, Siri's public beta, and rising phone prices URL: https://www.freshfromcache.com/also-this-week-2026-07-24/ Last updated: 2026-07-24T14:47:51.000Z I had a (hopefully) bright idea. I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I'm going to point you towards the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Here is what caught my eye this week. ## Your Android phone is getting other app stores This week Google started letting competing app stores show up inside the Play Store in the US. It's the result of its long antitrust fight with Epic, the company behind Fortnite. For most people nothing changes overnight, and apps you get this way still run through Google Play with its usual security checks and fees. No rival store has actually launched inside Play yet. But it's the first real crack in the one-store-per-phone setup, and over the next year you'll start seeing more places to get Android apps. Source: [Engadget](https://www.engadget.com/2215452/google-allow-third-party-app-stores-android-july-22/?ref=freshfromcache.com) ## Apple's big Siri upgrade is out for testing The AI version of Siri that Apple showed off in June is now in a public beta, so anyone with a recent iPhone can try it before the real release this fall. It can dig through your own email, photos, and messages to answer questions, and take actions across your apps. My advice: unless you enjoy living on beta software, wait for the fall release that comes with the new iPhones. Betas break things, and this one wants access to your personal stuff to do its job. If you do try it, back up your phone first. Source: [9to5Mac](https://9to5mac.com/2026/07/13/ios-27-public-beta/?ref=freshfromcache.com) ## Regulators are forcing your phone's assistant to have competition Europe just ordered Google to let rival AI assistants like ChatGPT and Claude plug into Android the same way Google's own Gemini does. The idea is that you'd eventually pick your phone's built-in assistant the way you pick a web browser. It's a European rule for now, not a US one. But these fights tend to cross the Atlantic, and it's the clearest sign yet that the assistant baked into your phone won't always be the one the manufacturer picked for you. Source: [MacRumors](https://www.macrumors.com/2026/07/16/eu-google-ai-apps-android-access/?ref=freshfromcache.com) ## If you need a new phone or laptop, this is a decent time to buy The same AI boom filling up data centers is eating the world's supply of memory chips, and that is pushing up the price of phones, laptops, tablets, and TVs. Analysts expect laptops to run roughly 15 percent more and phones around 13 percent more through the end of the year. Some cheaper models are shipping with less memory to hold the price down. If a device in your house is on its last legs, buying sooner rather than later will probably save you money. Source: [CNBC](https://www.cnbc.com/2026/06/26/ai-memory-chip-shortage-consumer-electronics-prices.html?ref=freshfromcache.com) ### The Odyssey hit theaters Friday. The scams were ready by Monday. URL: https://www.freshfromcache.com/the-odyssey-piracy-scams/ Last updated: 2026-08-11T18:28:48.000Z Christopher Nolan's The Odyssey pulled in $264 million worldwide on its opening weekend. Making it the biggest global debut of his career. A year of ticket presales made that large number a safe bet, and that is exactly what the scammers were counting on. Researchers at Malwarebytes found two of the scammers' traps already built and waiting for anyone searching for a free copy. You don't even have to be on a pirating website. You just have to be the person, or a parent of the person, who types "watch The Odyssey free" into a search box. ## The fake browser warning The first scam lives on cloned torrent sites, dressed up with the movie's real artwork and cast listings. Land on one and a pop-up appears: "Browser Issue Detected." A missing component is supposedly blocking full access, and a big "Fix It Now" button offers to solve it. There is no missing component. The warning comes from the webpage itself, drawn with the same code as everything else on the page, which is why your browser doesn't stop it. From the browser's point of view, nothing is wrong. A page is allowed to show you a picture of a warning. Click "Fix It Now" and you get bounced through advertising redirects toward whatever the ad network is serving that minute: a fake browser extension, a fake tech support page with a phone number to call, or a malware download. Malwarebytes found the same pop-up, identical wording and layout with only the colors changed, across multiple cloned sites. Nobody hacked these sites, they were built for this, ahead of time. If this sounds familiar, it should. It's the same idea as the [fake CAPTCHA scam](https://www.freshfromcache.com/fake-captcha-scam/) and the [fake update pop-ups](https://www.freshfromcache.com/fake-update-scam-taken-down/) police raided in June. Invent a problem, offer the solution, and let the worried user's click do the damage. ## The movie that isn't a movie The second scam is a download advertised as a 1080p copy of the movie, listed with 597 seeders (the people supposedly sharing the file, a number that reads like a crowd vouching for it). The file even wears VLC Media Player's orange traffic cone icon. Underneath that icon sits a Windows program, and double-clicking it runs that program with your full user permissions. Malwarebytes didn't say what this particular one installs, because it varies. The usual target for campaigns like this is a password stealer that grabs everything saved in your browser. Real movie files end in .mp4 or .mkv, open in a media player, and never ask to install anything. Windows makes this harder to spot than it should be, because it hides file extensions by default. Most people would see "The Odyssey 2026 1080p WEBRip" under a familiar media player icon, and the .exe that gives the file away would never appear on screen. The scammer forges the icon, and Windows hides the indicator that it's fake. ## Why the trap was ready so fast Malwarebytes' explanation is economic. A $250 million movie with a year of ticket presales behind it is guaranteed traffic. So the scam sites surfaced within hours of release day instead of weeks later. This wave was predictable. The same thing hit Barbie and Oppenheimer in 2023\. Also, a trojan bundled with fake Super Mario movie downloads that year had been used more than 150,000 times against similar bait, according to ReasonLabs. The infrastructure gets built before the premiere, then sits waiting for opening weekend. ## Where to watch The Odyssey is in theaters only. Universal hasn't announced a digital release, and based on Nolan's past films a paid rental option will probably land around November, with streaming sometime next year. Until then, a legitimate free stream cannot exist. Every result that promises one is a scam, by definition. You don't have to inspect a file or judge a website. The search itself is a trap. I'm not going to lecture anyone about piracy, and this piece isn't a guide to pirate better either. The people landing on these pages are anyone's kids and grandkids on the family computer, not seasoned torrent users. And on that computer every saved password in the household is one double-click away. ## A few steps you can take - **Turn on file extensions.** Open File Explorer, click 'View', then 'Show', then check 'File name extensions'. It costs nothing, and a fake "movie" shows its .exe immediately. - **Treat any warning inside a webpage as part of the page.** Close the tab instead of clicking. Real browser warnings don't come with a "Fix It Now" button. - **If you clicked one anyway,** check your browser for extensions you don't remember installing, remove anything unfamiliar, and run a full malware scan. - **If you ran a "movie" that turned out to be a program,** [disconnect that computer from the internet](https://www.freshfromcache.com/what-to-do-after-a-scam/), scan it, and change your passwords from a different device, email account first. A [password manager](https://www.freshfromcache.com/start-using-a-password-manager/) makes that rebuild a lot faster. ## The limits Malwarebytes is the only vendor documenting these particular scams so far, and "within hours" is their wording of the timing. The release-window fact doesn't depend on them, though. There is no legal way to watch this movie at home right now, and that alone settles every "free stream" offer. When the movie does hit digital in a few months, that rule relaxes. But the .exe rule never relaxes. A movie ending in .exe is never going to be a real movie. ## Sources - [Malwarebytes: The Odyssey piracy scams appear within hours of the movie’s release](https://www.malwarebytes.com/blog/threat-intel/2026/07/the-odyssey-piracy-scams-appear-within-hours-of-the-movies-release?ref=freshfromcache.com) (Jul 20, 2026) - [The Hollywood Reporter: The Odyssey box office](https://www.hollywoodreporter.com/movies/movie-news/the-odyssey-box-office-christopher-nolan-opening-success-1236651646/?ref=freshfromcache.com) (Jul 19, 2026) - [JustWatch: The Odyssey streaming availability](https://www.justwatch.com/us/movie/the-odyssey-2026?ref=freshfromcache.com) (checked Jul 20, 2026) - [Forbes: When is The Odyssey coming to streaming](https://www.forbes.com/sites/timlammers/2026/07/17/why-the-odyssey-streaming-debut-will-take-longer-than-most-pvod-releases/?ref=freshfromcache.com) (Jul 17, 2026) - [Axios: Malware targeting the Super Mario Bros. movie](https://www.axios.com/2023/05/12/malware-super-mario-bros-movie-cybersecurity?ref=freshfromcache.com) (May 12, 2023) ### AI tips for people who don't want to get left behind URL: https://www.freshfromcache.com/ai-tips-for-everyday-people/ Last updated: 2026-07-23T20:42:04.000Z A bookkeeper I know told me she wants to start using AI because she doesn't want to fall behind. I hear this same sentiment a lot now. I also hear the same three complaints from people who already tried it: the writing comes out generic, the whole thing feels clunky, and sometimes it just makes things up. All three complaints are true and valid. The last one even has an industry name, hallucination, which is a fancy way of saying the AI can be confidently wrong. That happens. It has happened to me. Those problems shrink to something you can manage once you change how you work with it. A couple of months ago I wrote up [the basics](https://www.freshfromcache.com/boring-ai-advice/), the handful of ways AI could save a regular person some time. That piece still works as a starting point. This is the next layer. These are the habits I actually use, and more importantly, why each one works. You don't need to be technical for any of them, and this is no professional's guide to AI. It's about making the thing more useful to an everyday person. ![Quick reference card listing seven AI habits: give it a home, write your rules down once, push back on the first answer, check what has to be right, keep one copy, show it what right looks like, and know what not to tell it.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/habits-at-a-glance.png) The whole piece in one card. Details below. ## Why most people quit first An AI chat starts as an empty text box. That's all you're welcomed with. It's like handing someone a blank sheet of paper and saying "make something good." A hammer at least suggests nails. A text box suggests nothing, so most people type a question or two, get a mediocre answer, and decide the whole thing is overhyped. ![Two hands at a table, one holding a pen over a blank sheet of paper.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-blank.jpg) The out-of-box experience. (Photo: Curated Lifestyle, Unsplash) The tool has no purpose until you give it one. Every habit below is a way of giving it one. ## Give it a home Most AI tools now have a workspace feature where you put a few documents once, and every chat inside it starts already knowing them. ChatGPT and Claude both call these projects. Gemini calls them Gems. Whatever the name, the idea is the same: what you do, who it's for, your logo files, a price sheet, examples of your writing, the stuff you'd otherwise retype or re-upload every time. Why it works: the AI has limited memory. It tries to store some things about you, but left on its own it can be scattershot. You end up having to treat every new chat like someone who just walked in knowing nothing about you. A project is how that person gets up to speed on the way in. I learned this the hard way. Early on, I spent a whole session getting some documents formatted exactly how I wanted them. Then the chat hit its length limit and I had to start a new one. The new chat produced documents that looked nothing like mine. I told it to look at the old chat. I pasted pieces of the old conversation in. It never got back to what I had. The work lived in the conversation, and the conversation was gone. So there is a second half of this habit: keep a notes file that lives outside the chat. When you and the AI settle something, a format you like, a decision you made, a template that finally works, have it write that down in the file. The next chat reads the file and picks up where the last one stopped. The chat is temporary. The file is permanent. Two ways to run it. If your files are connected (more on that near the end), the AI updates the file itself. If you'd rather not give it that access, the low-tech version works fine: have it write the notes, save the file yourself, and swap it into the project when it changes. Clunky, and it still beats losing everything with the chat. Once I moved the important stuff into files, losing a chat stopped costing me anything. ## Write your rules down once Every AI tool has a settings box for standing instructions, rules it applies to every conversation before you start typing. It's easy to miss if you aren't aware of it. It's the highest-value five minutes in this whole piece. Tell it who you are, how you like things written, and what it should never do. Then add the one line that earns its keep more than everything else combined: "If you aren't sure about something, tell me instead of guessing." Why it works: these tools are built to give you an answer. A confident tone is the default setting, right or wrong. That line gives it permission to say "I don't know," and permission is all it needs to work. One more line for some added safeguards: "Before you start on anything big, ask me questions first." A person given a vague assignment asks what you meant. An AI given a vague assignment gets to work on assumptions. That line makes it act like the person. A cousin of that line: tell it to flag gaps instead of filling them. If it's editing something you wrote and a word is missing, you want a question, not an invented word you didn't write. Same rule, same reason. The made-up-facts problem doesn't disappear with these instructions, but in my experience it drops from "constant background worry" to "rare enough that the next habit catches it." ## Push back on the first answer The first answer is an opening offer, and most people take it. Say "shorter." Say "less formal." Say "you missed the part about the deadline." Three rounds of that takes a minute and usually lands somewhere good. And pushback goes beyond writing. Push back on an answer you doubt. Ask it to explain itself. My favorite: tell it to run a fresh online search and make sure its information is current, because these tools will happily answer from stale knowledge if you let them. Pushback makes it check itself, and checking itself is half the job. One more trick: take an answer from one AI and feed it to a different one, even a free one, and ask what it thinks. You don't have to trust the second AI either. But when you aren't quite sure about your primary, a second opinion is cheap and it surfaces things worth a closer look. Why it works: a chat session is a conversation, but most people treat it like a vending machine. One prompt, one answer, walk away disappointed. The tool is built to refine on feedback, and the second and third passes are where the generic wears off. If a reply misses badly, it's usually faster to reword your request and try again than to argue it out of the hole. ## Check the things that have to be right Numbers, dates, names, prices, deadlines. Anything you'd be embarrassed to get wrong, you verify yourself before it goes anywhere. Especially dates. AI has a genuinely hard time with time: what year it is, what happened when, how long ago something was. If a date matters, look it up yourself. Every time. ![Closeup of a calendar page with Tax Day printed in red under a circled 15.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-taxday.jpg) If a date matters, look it up yourself. (Photo: Vitalii Abakumov, Unsplash) Why it works: the AI sounds exactly as confident when it's wrong as when it's right. Tone carries no information. People get burned because a warm, fluent answer feels true, but feeling true is worth nothing. I treat it like a sharp new employee: great output, and everything with a number in it gets a second look. Trust, but verify. I've caught real ones this way, a wrong deadline in a draft, a claim stated as fact that turned out to be one person's say-so. I've [written before](https://www.freshfromcache.com/friendly-ai-is-less-accurate/) about how the friendlier an AI sounds, the more you should distrust it. The rule scales with the stakes: a dinner idea probably needs no checking, a tax deadline needs plenty. ## Keep one copy of anything that matters One master file per important thing. Not "newsletter\_final\_v2\_ACTUAL." When something changes, change the master. (And anything you'd call a master belongs in [a real backup](https://www.freshfromcache.com/do-you-need-backups/), but that's a piece I've already written.) Why it works: the AI will cheerfully work from whatever copy you hand it, including an old one. I once watched it redo work that was already done and contradict a decision that was already made. This was because it was reading a stale copy of a file while the current one sat somewhere else. The AI wasn't being dumb, just obedient to the wrong instruction. One master, and tell it to re-read the file right before it changes anything. Versions drifting apart is a people problem that AI makes faster. ## Show it what right looks like These tools copy examples far better than they follow descriptions. You can describe the logo you're picturing in 999 words and get something off the mark every time. Hand it one example image and it gets the idea immediately. The same goes for a spreadsheet layout, a flyer, an email. If you have something close to what you want, lead with it and say "like this." The same move works on writing. Paste in something you wrote that you actually liked and say "match this." And if AI writing's flavor grates on you, keep a list of words and phrases that annoy you and tell it to avoid them. You probably know a few already, words like "delve" and "leverage" and "game-changer" that almost nobody says out loud. Add to the list the moment something new grates on you. Mine has grown for months and it's one of the most useful files I own. Why it works: "make it casual" gets you a generic idea of casual, because a description leaves the AI guessing at everything you didn't say. An example answers a hundred questions at once. The generic flavor people complain about is mostly the sound of an AI that was never shown anything specific. ## Know what not to tell it Treat a chat like a postcard, not a locked diary. Keep out the things that identify or expose you: account numbers, passwords, Social Security numbers, medical details, other people's private information. This doesn't fight the examples habit. Your writing voice and your logo aren't secrets. Your account numbers are. ![A stack of handwritten letters and postcards fanned out on a table.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-letters.jpg) Written like anyone might read it someday. (Photo: Frank Flores, Unsplash) Why it works as a habit and not just a warning: on free tiers especially, what you type can be used to train the company's models, and once it leaves your keyboard it's out of your control. You lose almost nothing by keeping details generic. "Help me write a dispute letter about a billing error" works exactly as well as the version with your account number in it. The AI needs the shape of your problem, almost never the identifying parts. Sometimes the job really does involve the sensitive stuff. Two things help. First, check your tool's data settings: paid plans and training opt-outs change what happens to what you type, and the defaults differ between tools. Second, when the AI has to work with a sensitive document, connected file access you can limit and revoke beats pasting the contents into a chat, where they sit in your history forever. Neither one makes anything invisible. The AI still reads what you give it. What you gain is control over what it can see and for how long, and the postcard rule stays the default for everything else. ## The clunkiness is shrinking The other big complaint, the copy-paste shuffle between the AI and everything else, is getting better on its own. AI tools now connect directly to the services people already use, places like OneDrive, Google Drive, calendars, and email. Instead of pasting a document into a chat and pasting the result back out, the AI opens the file, works on it, and saves it. The clunkiness mostly came from the swivel chair between windows, and that part is disappearing. One rule before you connect anything, and it's the postcard rule with extra steps: only connect what you'd be comfortable letting it read. Give it the folder with your templates, not the folder with your tax returns. Convenience is real, but you have to draw your line. ## You don't have to love it I'm not telling people they need to be using AI. I've written about [where it deserves real skepticism](https://www.freshfromcache.com/ai-accountability/). But it's mainstream now, the way email and smartphones went mainstream, and "I'll just skip it" is becoming a choice with a cost. If you were curious, the habits above are enough to start with a purpose instead of a blank sheet of paper. And if you tried AI, got the generic clunky confidently-wrong version, and wrote the whole thing off, it wasn't you. You just got the out-of-box experience without an instruction manual. Now you have one. ## Sources - [OpenAI, “Projects in ChatGPT”](https://help.openai.com/en/articles/10169521-projects-in-chatgpt?ref=freshfromcache.com) — ChatGPT’s projects feature, available on free and paid plans. - [Anthropic, “What are projects?”](https://support.claude.com/en/articles/9517075-what-are-projects?ref=freshfromcache.com) — Claude’s projects: self-contained workspaces with their own knowledge bases and instructions. - [Google, “Use Gems in Gemini Apps”](https://support.google.com/gemini/answer/15146780?ref=freshfromcache.com) — Gemini’s version, including adding your own files under Knowledge. - [OpenAI, “How your data is used to improve model performance”](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance?ref=freshfromcache.com) — confirms consumer chats may be used for training unless you opt out, while business and enterprise accounts are excluded by default. Other providers publish their own equivalents; check the one you use. *All links verified July 23, 2026.* ### How to get a deepfake of you taken down URL: https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/ Last updated: 2026-07-22T10:59:59.000Z One day a friend sends you a link with a question attached: is this you? The video has your face. The voice is yours too. But it's selling something that you would never approve of. Last week [we walked through what happens when an AI deepfake has your face](https://www.freshfromcache.com/ai-deepfake-has-your-face/): the report buttons were built for fake accounts, the law mostly cares whether money changed hands. That post promised a follow-up with the actual steps. Happy to deliver. Bookmark it for the day that hopefully never comes. ## Before you report anything, save everything Every path below starts with proof, and fakes tend to vanish and reappear somewhere new, quickly. Save anything you can see now, and [save them somewhere safe](https://www.freshfromcache.com/do-you-need-backups/). - **Screenshot the post, the account, and the comments.** Get the browser address bar or the app's share link in the shot when you can. Include your phone's clock if you can. - **Screen-record the video playing.** A screenshot of a video only proves a single frame. A recording proves the voice, the motion, and the claims. - **Copy the links.** The post, the account profile, and the account's other uploads. Paste them into a note with the date you found each one. - **If it's an ad, find it in the ad library.** Facebook and Instagram ads are searchable at Meta's Ad Library (facebook.com/ads/library), which shows who ran the ad and when. You can report an ad from there with the three-dot menu. TikTok's ad library only covers Europe. So for a TikTok ad your screen recording is the record. - **Save every confirmation.** Each report you file returns a number or an email. Keep them all in one note. If this ever reaches a lawyer, that paper trail could be important. I know this seems like an excessive amount of information to collect, and it is. But the more evidence you collect, the stronger case you'll have. ## Which path to take Your first move depends on what the fake is doing: - **It's intimate or sexual:** [skip to the intimate-imagery section](#if-its-intimate) below. This category has a federal law behind it and moves fastest. - **It's selling something:** report it as a scam ad where it ran, and read the lawyer section. Money changing hands is what turns this from a grievance into a claim. - **It's on YouTube:** use the privacy complaint. It's the one big platform that has a form written for this. - **Anything else:** report it on the platform where it lives, recruit help, and document. The advice from the parent post still holds up: outside those first three lanes, persistence and attention do more than anything else. ![Decision list: an AI fake of you showed up, which path? Intimate or sexual: the TAKE IT DOWN Act applies, platforms must remove it within 48 hours, report it there and at ic3.gov. Selling something: your state's publicity law may give you a claim, save proof and talk to a lawyer. On YouTube: file the privacy complaint. Everything else: screenshots first, then report it and get friends and family to report it too.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/diagram-which-path.png) ## YouTube YouTube's privacy complaint covers AI content that "looks or sounds like you," in those words, and has since 2024\. You do not need a copyright claim, and filing one is not a copyright strike. 1. You, or your lawyer, must file it. YouTube rejects reports from coworkers, friends, and family (a parent or guardian filing for a child is fine). 2. Start at YouTube's Help page called ["Protecting your identity"](https://support.google.com/youtube/answer/2801895?ref=freshfromcache.com) and follow the privacy complaint process. It's a guided form: it asks what the video is, where your likeness appears, and for the video link and timestamps. 3. YouTube gives the uploader a window (48 hours when the policy launched) to remove the video or edit your likeness out themselves. Setting it private doesn't count. 4. If they don't, YouTube reviews it against factors like whether you're identifiable, how realistic it is, and whether it's parody or news. Removal isn't guaranteed, but this is the strongest tool on any platform right now. ## Facebook and Instagram Meta's written policy for AI-generated media is to label it, not remove it, unless it breaks another rule. So aim your report at the rule it breaks: - **A fake ad is a scam.** Tap the three dots on the ad, choose 'Report ad', and pick the fraud or scam option. That queue exists because scam ads cost Meta advertisers, and it moves faster than the impersonation queue. - **A degrading fake is harassment.** Report the post under bullying or harassment. - **The impersonation form only fits a fake account.** If someone built a profile pretending to be you, use it (Instagram's version asks for a government ID). If a real account posted your fake face, it won't fit, which is most of why the parent post exists. - **Recruit reporters.** Multiple reports from different accounts carry weight in Meta's systems. Ask friends to report the same post under the same category. While you're in there, [the one Instagram setting worth turning off](https://www.freshfromcache.com/meta-instagram-ai-feature/) is still worth your thirty seconds. It won't remove anything, but it stops one source of raw material. ## TikTok TikTok's own rules ban synthetic media showing a private person without permission. That's the strongest written policy of any platform, and it's the box to aim for. 1. Press and hold the video (or tap the share arrow), tap 'Report', and pick 'Misinformation or AI-generated content'. If your version of the app words it differently, aim for the misinformation lane. 2. Report the account too if it's a scam operation: 'Report' from the profile, 'Pretending to be someone' when that fits. 3. There's also a web form at tiktok.com/legal/report/submit-requests, and it works with just an email address, no TikTok account needed. It only covers impersonation accounts, so it's the lane for a profile pretending to be you, not for a single video. 4. Recruit help here too. Dr. Sholas's reports went nowhere until a newsroom asked questions. Numbers and noise are unfair tools, but they work. ## X X's rules prohibit misleading AI depictions of real people that can cause harm, and its impersonation form works without an account. File both when they fit, save your confirmations, and set your expectations. Enforcement is thin, and the policy's bar is harm, not consent. If the fake is intimate, don't fight it on X's terms at all. Use the federal lane below, which binds X the same as everyone else. ## Snapchat Snapchat has no AI-likeness category, but reporting is the same everywhere in the app: press and hold the Snap, Story, or ad, tap 'Report', and pick the closest fit ('False information and deceptive practices', or harassment). Non-users can file through Snapchat's support site. Reviews are fast, typically hours. ## If it's intimate Since May of this year, the TAKE IT DOWN Act requires platforms to remove intimate images, real or AI-generated, within 48 hours of a valid request. They also need to make reasonable efforts to remove copies. The FTC enforces it, at more than $50,000 per violation. Every big platform now has a dedicated form for this. Use the platform's own intimate-imagery report first, and say in it that you're making a request under the TAKE IT DOWN Act. On Facebook and Instagram, it's the last entry in the normal report menu: 'Reporting specific harms', with a 'Fill in form' link. Two free tools go further by blocking re-uploads: - **StopNCII (stopncii.org)** for adults. It explicitly covers deepfakes of you. Your device generates a digital fingerprint of the image (the image itself never leaves your phone), and participating platforms block matches. - **Take It Down (takeitdown.ncmec.org)** for anyone under 18 in the image, or adults whose images were taken when they were minors. Same fingerprint idea, run by the National Center for Missing and Exploited Children. Report it at ic3.gov as well, the FBI's complaint center, with your evidence file. And if a minor is involved, that's a police report, today. ## Getting it out of Google Google removes fake explicit images of you from search results: the form is in Google's Help under "Request removals of explicit or intimate personal images". It wants the links and your screenshots, and a successful removal also demotes explicit results on searches for your name. Google's 'Results about you' tool now watches for this proactively. For a fake that isn't explicit, Google has no removal tool. You have to report it at the platform that hosts it. ## When to call a lawyer One question decides if it's worth it: **is your likeness selling something?** If yes, your state's right of publicity law probably gives you a real claim. A lawyer's demand letter to a US company gets more attention than any reports you file. Bring the evidence file you built in step one, the product link, and anyone who saw the ad and believed it. Do your best to show any concrete harm you incurred. If the fake is harassment from an anonymous account with no money involved, a lawyer probably can't help yet, and the platform reports above are your best bet. Last week's post ended with the advice to take your screenshots before anything else. This is why. Save the proof, pick the right report lane depending on what the fake is doing, and recruit help. The forms aren't perfect. Filed in the right order, with the evidence attached, they're your best chance. **Sources:** - [YouTube Help: Protecting your identity](https://support.google.com/youtube/answer/2801895?ref=freshfromcache.com) - [YouTube Help: Privacy Complaint Process](https://support.google.com/youtube/answer/142443?ref=freshfromcache.com) - [Meta Newsroom: Our Approach to Labeling AI-Generated Content and Manipulated Media](https://about.fb.com/news/2024/04/metas-approach-to-labeling-ai-generated-content-and-manipulated-media/?ref=freshfromcache.com) - [TikTok Community Guidelines: Integrity and Authenticity](https://www.tiktok.com/community-guidelines/en/integrity-authenticity?ref=freshfromcache.com) - [X Help Center: Authenticity and synthetic media](https://help.x.com/en/rules-and-policies/manipulated-media?ref=freshfromcache.com) - [Snapchat Support: How do I report abuse or illegal content?](https://help.snapchat.com/hc/en-us/articles/7012399221652?ref=freshfromcache.com) - [FTC: Complying with the TAKE IT DOWN Act](https://www.ftc.gov/business-guidance/resources/complying-take-it-down-act?ref=freshfromcache.com) - [StopNCII](https://stopncii.org/?ref=freshfromcache.com) · [Take It Down (NCMEC)](https://takeitdown.ncmec.org/?ref=freshfromcache.com) - [Google Help: Request removals of explicit or intimate personal images](https://support.google.com/websearch/answer/9116649?ref=freshfromcache.com) ### The sketchy hospital letter that turned out to be real, a deepfake you can't report, and the Windows bug eating your drive URL: https://www.freshfromcache.com/newsletter/sketchy-hospital-letter-was-real/ Last updated: 2026-07-21T14:59:59.000Z Quick note before anything else, because a lot of you signed up in the last week and this is your first issue: Fresh From Cache is one email, every Tuesday, about the tech news and questions that actually reach everyday people. I'm glad you're here! Two stories this week hit on the same question: is this real, or is somebody fooling me? One is a hospital breach letter that looks exactly like a scam but is completely genuine. The other is a phone call from your bank that looks completely genuine but is a scam. The same thirty-second habit sorts out both, and it shows up twice below. In this issue: - [The sketchy hospital letter that turned out to be real](https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/) - [What data brokers actually sell, and California's new delete button](https://www.freshfromcache.com/what-is-a-data-broker/) - [What do you do when an AI deepfake has your face?](https://www.freshfromcache.com/ai-deepfake-has-your-face/) - [The Windows 11 bug that fills your hard drive while you watch](https://www.freshfromcache.com/windows-11-disk-eating-bug/) - [Start using a password manager](https://www.freshfromcache.com/start-using-a-password-manager/) - [This week's tech tip: copy text straight out of any photo](https://www.freshfromcache.com/copy-text-from-a-photo/) And the Scary Headline of the week: Apple is warning about a FaceTime scam, and the scary part is not FaceTime. --- [**That sketchy letter from your hospital might be real**](https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/) About 18,600 Rochester Regional patients got a breach notice from a company they had never heard of, naming a hospital that does not exist. It hit every scam marker, so plenty of people threw it away. It was real. The breach was at Xsolis, a records vendor holding files on 1.4 million patients nationwide, still sitting on Rochester records five years after that hospital stopped using it. Here is the habit worth building, and it covers your bank and your insurer too: never call the number printed on the letter. Look the hospital up yourself, on a bill you already have or its real website, and ask whether they sent it. A scammer can fake a letter. He cannot get your actual hospital to vouch for it. *News* --- [**Data brokers have a file on you. California is making them delete it.**](https://www.freshfromcache.com/what-is-a-data-broker/) Data brokers assemble and sell a file on you: where you live, what you buy, and what they infer about your health and your money. California's Delete Act creates one request that brokers have to honor and keep honoring, and they have to start processing those on August 1\. If you live somewhere else, the free opt-outs at the biggest brokers still cover most of the ground, and the post lists them. Skip the paid removal services. They mostly resell work you can do yourself in an afternoon. *Learn* --- [**What do you do when an AI deepfake has your face?**](https://www.freshfromcache.com/ai-deepfake-has-your-face/) A New Orleans pediatrician found himself starring in TikTok ads for a supplement he had never heard of, wearing a lab coat with his own name on it. Taking them down took months, and what worked in the end was a journalist friend making a phone call. The report buttons are the trap: they were built for fake accounts impersonating you, which is a different thing from a real account posting AI video of your face. YouTube is the one platform whose form covers content that looks or sounds like you, so that is where a report actually goes somewhere. Everywhere else, the cleanup firms quote nine to twenty thousand dollars. *Learn* --- [**Windows 11 has a disk-eating bug. Tuesday's update fixes it.**](https://www.freshfromcache.com/windows-11-disk-eating-bug/) A recent Windows 11 update let a hidden system file grow with no limit until it filled the drive, hundreds of gigabytes in the worst cases. Microsoft's July update stops it and cleans up the runaway file on its own. If your PC started warning you about low space this month, install that update and let it sort itself out. If space is still tight afterward, the post walks you through finding the culprit by hand. *News* --- [**Start using a password manager**](https://www.freshfromcache.com/start-using-a-password-manager/) One password you can remember, used across several accounts, is the most common way ordinary people get broken into. A password manager keeps a different strong password for every site and fills them in for you, so the only one you have to know is the one that opens it. Start with the manager already built into your phone and browser. It is free, it is good, and the best one is the one you will actually use. If your hesitation is getting locked out of the manager itself, the post answers that directly. *Learn* --- If you only read one: the password manager. It is the single habit here that protects every other account you own, and most people can have it done in one evening. --- ### 5-Minute Tech Tip Your phone can pull text straight out of a photo, no retyping. Photograph the wifi password on the back of the router, a serial number off the bottom of a laptop, or a page of a book, then tap and hold the words to select and copy them like any other text. On iPhone it is built into the camera and Photos. On Android it is Google Lens inside Google Photos. Five minutes to learn, and then you will use it constantly: [Your phone can copy text out of any photo](https://www.freshfromcache.com/copy-text-from-a-photo/). --- ### Scary Headline of the Week *"Apple warns iPhone users about a dangerous new FaceTime scam."* Apple did update its guidance this month, after scammers started working FaceTime into their impersonation schemes. Here is the part the headline buries: there is nothing wrong with FaceTime. No bug, no hack. This is the old bank-impersonation scam wearing a new coat. A text warns of suspicious activity on your account, then an unexpected FaceTime call from someone claiming to be your bank pressures you into reading back a verification code or installing remote-access software. The live video is the only new trick, and it works because seeing a face makes the pressure feel real. The tells are the same as any [phishing attempt](https://www.freshfromcache.com/how-to-spot-a-phishing-email/): contact you did not expect, a rush, and a request for a code or a password. Verdict: real and growing, and the defense is the same one from the top of this issue. Hang up and call back on a number you looked up yourself. Apple will never ask you for your Apple Account password, your device passcode, or a two-factor code, and neither will your bank. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### The Cache: everything free in one place Most of you joined in the last week, so you may not know this exists. The Cache is where all the free FFC guides live: how to spot a scam, how to spot a phishing email, how to fix a slow computer, and a worksheet for getting your important accounts written down before somebody needs them. No forms, nothing to buy, and your subscription already covers it. [Open the Cache](https://www.freshfromcache.com/cache/), and send one to somebody who needs it. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help that won't cost you anything: forward it to someone who could use it, and if it was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. --- If you are new here, hit reply and tell me what you want covered. I read all of them. Joel ### Shark fixed the vacuum flaw. Here's what yours knows about you. URL: https://www.freshfromcache.com/robot-vacuum-watching-you/ Last updated: 2026-07-28T02:50:05.000Z **Update, July 27, 2026:** SharkNinja fixed this on July 20, about a week after the story first ran. The fix was on their servers rather than on the vacuum, so it reached the affected robots on its own and there is nothing you need to do. If you took your vacuum off Wi-Fi after reading the first version, you can put it back. The rest of this piece is what was true while the flaw was open, and it still stands as a picture of what your robot knows about your home. On July 13, a researcher published a flaw he'd been trying to hand SharkNinja since March. He opened up a Shark robot vacuum he owned and pulled out its security certificate. That's the credential the vacuum uses to prove it's really itself when it phones home. His certificate worked on other Shark vacuums too. Using it, he reached a second vacuum he'd bought separately, opened its camera feed while it drove around, read the map of the house it had been cleaning, and pulled the Wi-Fi password out of it in plain text. He only ran the attack on machines he owned. But he sat and listened to Shark's system for 24 hours and counted more than 1.5 million vacuums checking in. About 673,000 of them answered a command he sent. When this first published, it wasn't fixed: no patch, no security bulletin, no public response. That changed on July 20, and the update at the top has the details. **Update, July 27, 2026: you no longer need to do this.** Shark fixed the flaw on July 20 on their own servers, so the fix reached your vacuum on its own. If you disconnected it after the first version of this story, you can put it back on Wi-Fi. It vacuums either way. ## How one vacuum opens the door to others Every one of these vacuums talks to the manufacturer's servers all day. Shark's run on Amazon's cloud, and each vacuum gets a certificate so the server knows which machine is which. That certificate was supposed to let a vacuum speak only for itself. Shark handed out a lot of them with the door left open wider than they should. One certificate could listen in on every Shark vacuum in the region and send commands to any of them by serial number, and the serial numbers were sitting right there in the same stream. Getting that first certificate takes a screwdriver and a vacuum you own. After that, the rest of it happens over the internet. To be fair to Shark, not every unit got a certificate this loose. The older of the two vacuums he tested had a properly locked-down one. But 673,000 machines answering a stranger's command in a single day isn't a rounding error. He gave SharkNinja four months. He told them in March. He told them again in June that he was going to publish. They said they'd have a completion date for him by July 10\. That date came and went, so he published. ## This is bigger than Shark A robot vacuum is a camera or a laser on wheels that drives every square foot of your house, writes down what it finds, and uploads the result to a company you've probably never thought about. Shark had a bad month. The category also has a track record. If that pattern sounds familiar, it should. It's the same arrangement as [the TV in your living room](https://www.freshfromcache.com/tv-side-hustle/), which watches what you watch and sells it on the side. **What they see.** There are three ways these things find their way around. The cheap ones bump into walls and turn, and they never build a map. The mid-range ones use LiDAR, a spinning laser on top that measures distances. The expensive ones add a camera so the robot can recognize a sock or a phone charger before it eats it. The camera is the one people react to, and they're right to. Ecovacs and Roborock's high-end machines have them, some with microphones and a voice assistant attached. Several will stream that camera to your phone on purpose as a pet cam. Shark's line is mostly LiDAR, though some models carry a camera for obstacle detection. That was the one with a flaw. Eufy's vacuums have no cameras at all. **What the map is.** A LiDAR map isn't a fuzzy blob. It's the floor plan of your home. The walls, the rooms, the furniture, the square footage, and whatever you named the rooms when you set it up. If you labeled one "Kids Bedroom," that label is in there. ![Architectural floor plan drawings with rooms labeled ENTRY and BATH, a drafting pen resting on the paper](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-floorplan.jpg) Closer to what your vacuum builds than most people picture. Walls, rooms, and the names you gave them. **Where it goes.** This depends on the brand, and the brands aren't all telling the same story. iRobot keeps navigation images on the robot and only puts a simplified map in its cloud if you turn on map viewing. Ecovacs keeps maps in both places. Roborock's marketing says maps live on the device and never go up, while Roborock's own privacy policy talks about cloud backup and independent testers found the maps in the cloud anyway. Roborock also says it stores customer data in China, Germany, and the United States. None of that is illegal. You agreed to it because it's sitting in a policy you scrolled past to get the thing working. From there it joins everything else about you that gets bought and sold by [companies you've never heard of](https://www.freshfromcache.com/what-is-a-data-broker/). ## What's already happened Four of these are real. One isn't. **Roomba, 2022.** MIT Technology Review published images captured by Roomba test units that leaked out of the pipeline. One was a woman on a toilet. Another was a child on a floor. These were development machines with recording hardware, driven in the homes of paid testers who'd signed up for it, not retail Roombas off a shelf. iRobot sent more than two million images to Scale AI for labeling, and gig workers in Venezuela posted at least fifteen of them into private Facebook and Discord groups. iRobot ended the Scale AI contract. Some of the testers said afterward they hadn't understood how many humans would be looking. **Ecovacs, 2024.** Over about a week in May, people in Minnesota, Los Angeles, and El Paso had their Deebot X2 vacuums taken over by somebody else. The attacker drove the robot, watched through the camera, and shouted racial slurs through its speaker. One of them chased a dog. Two researchers, Dennis Giese and Braelynn Luedtke, had warned Ecovacs about serious flaws back in December 2023, months before any of this happened. They laid the details out publicly at DEF CON that August. One of them was a four-digit PIN for the camera feed that got checked by the app instead of the server, which makes it no lock at all. Ecovacs first told reporters it wouldn't fix the problems, then said it would, and blamed the May takeovers on reused passwords. **DJI, February 2026.** A software engineer trying to steer his DJI ROMO with a PlayStation controller found he could reach about 7,000 of them across 24 countries. DJI shipped an automatic patch within days and paid him a $30,000 bounty. Same class of mistake as Shark's, opposite response, which is why the silence from SharkNinja stands out. **The one that didn't happen.** In 2020, researchers from Singapore and the University of Maryland turned a robot vacuum's LiDAR into a crude microphone by bouncing the laser off a trash can and reading the vibrations. It works. It also takes modified firmware, a cooperative object, and lab conditions. Nobody has been eavesdropped on this way. It gets written up as if your vacuum is listening to you, but it isn't. ## What the risk really is Four ways the map of your house ends up somewhere you didn't put it. Ranked by how often each one has actually happened to people, not by what makes a good headline. 1. **The company keeps it, because you agreed to that.** This one isn't a maybe. It's happening in every connected vacuum, today, legally, and it's the reason the other three exist at all. There's no map to steal if nobody stored one. 2. **The company loses it.** Shark, DJI, Ecovacs. This is where the real damage lives, because one mistake by one vendor exposes everybody at once and there's nothing you can do from your end. It's the same shape as [any other breach notice you've gotten](https://www.freshfromcache.com/three-breaches-in-one-week/), except the file has your floor plan in it. 3. **Somebody breaks into your vacuum specifically.** Real, and rarer. Those three Ecovacs households are the proof it happens. 4. **Somebody turns the laser into a microphone.** Interesting. Not a real problem. The top two are the same problem wearing different hats, and neither one gets fixed by anything you can do in the app. ## What helps **Skip the account if the machine will run without it.** Most of these will vacuum on a button press. You give up scheduling and mapping. You also give up the entire attack surface. **Turn the camera off, and unlink the voice assistant you never use.** On models that have a camera, leave remote viewing off unless you're using it that minute. **Delete the map and factory reset before you sell it or give it away.** A used robot vacuum with a live account attached is the floor plan of your old house, handed to a stranger. **Be skeptical about deleting a map in the app.** Not one of the big manufacturers publishes a straight answer about whether that removes the copy on their servers. The documented way to get your data off their systems is deleting your account with them, and that can take about a month. Tapping "delete map" and assuming it's gone is the theater option. **Put it on the guest network** if your router has one and you're comfortable poking around in there. Then a compromised vacuum is looking at an empty room instead of your computers. **Keep the firmware updated,** with one caveat. It closes bugs in the machine. It would have done nothing about the Shark flaw, because that mistake lives on Shark's servers, not on your vacuum. Updating is good hygiene. It's not a shield against the flaw in the news this week. And if you did unplug your Shark, remember that firmware updates need Wi-Fi. Reconnect it long enough to update once there's word of a fix, then decide whether it stays on. ## If you're shopping I'm not going to point you at a model. I own one robot vacuum, I keep it off Wi-Fi, and that makes me the wrong person to tell you which one to buy. The questions are short, though. Does it have a camera? Does it need an account and an internet connection to do the basic job? Does the maker say where the map is stored, and does the privacy policy agree with the marketing? Anything sold on pet monitoring, video calls, or AI obstacle recognition has a lens in it, and that lens ends up wherever the company's security is on its worst day. A vacuum with no camera can't show anyone your living room. A vacuum with no Wi-Fi can't hand anyone your floor plan. Everything past that is a tradeoff you're making on purpose, which is fine, as long as you know you're making it. ## What I do ![A man kneeling on a living room floor, looking under a table at a robot vacuum](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-under-the-table.jpg) The robot's whole job is getting under the beds. Mine isn't on Wi-Fi. No app, no map, no schedule. When I want it to do something I pick it up, set it in the room, and press the button. I'll admit that's partly because it isn't a very good vacuum. I still use a regular one. The robot's whole job is getting under the beds, and it doesn't need the layout of my house to do that. So that's the question to sit down with. How much of your house does the thing need to know to do the job you actually bought it for? For most of us it's less than it's currently recording. ## Sources - [tokay0, "No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE"](https://tokay0.com/posts/millions-of-shark-vacuums-vulnerable-to-rce.html?ref=freshfromcache.com) (the original disclosure, July 13, 2026) - [The Hacker News on the unpatched Shark flaw](https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html?ref=freshfromcache.com), July 2026 - [Malwarebytes, "Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords"](https://www.malwarebytes.com/blog/news/2026/07/shark-vacuum-flaw-exposes-cameras-home-maps-and-wi-fi-passwords?ref=freshfromcache.com), July 2026 - [Tom's Hardware on the Shark disclosure timeline and SharkNinja's response](https://www.tomshardware.com/tech-industry/cyber-security/shark-robot-vacuum-flaw-lets-one-stolen-certificate-run-root-commands-on-others-in-the-same-aws-region?ref=freshfromcache.com), July 2026 - [MIT Technology Review, "A Roomba recorded a woman on the toilet. How did screenshots end up on Facebook?"](https://www.technologyreview.com/2022/12/19/1065306/roomba-irobot-robot-vacuums-artificial-intelligence-training-data-privacy/?ref=freshfromcache.com), December 19, 2022, and the [follow-up on what the testers thought they agreed to](https://www.technologyreview.com/2023/01/10/1066500/roomba-irobot-robot-vacuum-beta-product-testers-consent-agreement-misled/?ref=freshfromcache.com), January 10, 2023 - [ABC News (Australia), "We hacked a robot vacuum, and could watch live through its camera"](https://www.abc.net.au/news/2024-10-04/robot-vacuum-hacked-photos-camera-audio/104414020?ref=freshfromcache.com), October 4, 2024 - [Tom's Hardware on the DJI ROMO exposure](https://www.tomshardware.com/tech-industry/cyber-security/user-accidentally-gains-control-of-over-6-700-robot-vacuums-while-tinkering-with-their-own-device-to-enable-control-with-a-playstation-controller-security-flaw-reveals-floor-plans-and-live-video-feeds?ref=freshfromcache.com) (first reported by The Verge), February 2026, and [DroneDJ on DJI's fix and the bounty](https://dronedj.com/2026/03/10/dji-romo-security-bug-bounty/?ref=freshfromcache.com), March 2026 - [Sami, Dai, Tan, Roy and Han, "Spying with Your Robot Vacuum Cleaner: Eavesdropping via Lidar Sensors"](https://icosmos.cs.umd.edu/images/2%5Fpublication/papers/LidarPhone%5FSenSys20%5Fnirupam.pdf?ref=freshfromcache.com), SenSys 2020 ### Samsung killed its texting app, but your texts are fine. URL: https://www.freshfromcache.com/samsung-shut-down-its-texting-app/ Last updated: 2026-07-21T02:45:19.000Z If you have a Samsung phone and texting stopped working this month, technically nothing is broken. On July 6, Samsung shut down Samsung Messages, the texting app that came standard on Galaxy phones for years. Your old messages are not gone, and getting texting working again takes about ten minutes. The shutdown covers US Galaxy phones running Android 12 or newer, which is most Galaxy phones sold in the last four or five years. Samsung announced the retirement in April and put a notice in the app itself, but plenty of people never saw either one. The app still opens, and it will still text emergency numbers. Everything else is shut down. Samsung's answer is to move everyone to Google Messages, the texting app that ships on most other Android phones. Why would Samsung give up its own texting app? The short version is that texting moved to a standard called RCS, the modern replacement for SMS that handles full-quality photos, typing indicators, and encrypted chats. Google Messages already does RCS well, and Samsung was maintaining a second app that did the same job on the same phones. Samsung picked Google's. ## What to do The phones this hits hardest belong to the people least likely to have seen the announcement. A Galaxy that is a few years old and dependable, owned by someone who texts and calls and not much else. For a lot of those people, the first sign was texts that stopped going through. If that describes your parents' phones more than yours, this is your reminder to check on them. What concerns me is the confusion window. When texting breaks, people will tap almost anything that promises to bring it back, and scammers know it. Fake texts about this exact shutdown have been circulating since April, telling Galaxy owners to tap a link to finish the switch. The shutdown is real, which is what makes the fakes convincing. The real switch happens on your phone, in settings, and Samsung does not send texts with links. Scammers follow news like this the way they follow package deliveries. A few steps to take: - **Switch to Google Messages.** Open Samsung Messages and tap 'Switch' on the notice. Or install Google Messages from the Play Store and let it ask to become your texting app. - **If nothing prompts you, set it by hand.** Go to Settings > Apps > 'Choose default apps' > 'SMS app' and pick Google Messages. The menu wording varies a little by model; look for anything labeled default apps. - **Give your old conversations a day to show up.** They transfer automatically after you switch. Samsung says a full transfer can take up to 24 hours, so a missing thread an hour in is normal. Don't delete anything in the meantime. - **Check on your family.** If someone you love has a Galaxy and hasn't mentioned this, their texting may already be broken and they may not know why. - **Ignore anything that offers to "save your messages."** No legitimate fix arrives as a link in a text or an email. The switch happens in your phone's own settings and costs nothing. If your phone runs Android 11 or older, nothing changes yet, and phones outside the US aren't affected so far. And once you've made the switch there's an actual upside: Google Messages speaks RCS everywhere, including [encrypted chats between Android phones and iPhones](https://www.freshfromcache.com/iphone-android-texts-encrypted/). Ten minutes in settings and you're texting again. And with a much better app. ## Sources - [Samsung Support: Samsung Messages discontinuation, switch to Google Messages](https://www.samsung.com/us/support/troubleshoot/TSG10010566/?ref=freshfromcache.com) - [Fox News: Samsung Messages ending in 2026, and scammers are already exploiting it (April 11, 2026)](https://www.foxnews.com/tech/samsung-messages-ending-android-owners-must-know?ref=freshfromcache.com) - [Android Central: Samsung Messages app shuts down this month (July 1, 2026)](https://www.androidcentral.com/phones/samsung-galaxy/psa-samsung-messages-app-on-your-galaxy-phone-will-stop-working-this-month?ref=freshfromcache.com) - [Droid Life: Samsung Messages Just Shutdown For Good (July 6, 2026)](https://www.droid-life.com/2026/07/06/samsung-messages-discontinued-switch-google-messages/?ref=freshfromcache.com) ### I lost ten years of photos. Now I print a photo book every January. URL: https://www.freshfromcache.com/yearly-photo-book/ Last updated: 2026-07-20T10:59:59.000Z Somewhere between 2005 and 2015, I lost most of my photos. Not in one dramatic crash. They fell away a few at a time. A phone got replaced. A memory card went in a drawer and never came out. A site I'd uploaded them to changed hands or shut down. Back then there was no set-it-and-forget-it way to keep digital pictures. Keeping them was a chore you had to remember to do, and I didn't always remember. I often wish I had pictures from that period of my life. They're just gone. About a decade ago I decided that was the last decade I'd lose. I turned on automatic photo backup with Google Photos (I was on Android, so it was the obvious choice), and every picture I've taken since has been saved without me thinking about it. That part is a backup story, and I've [written about backups](https://www.freshfromcache.com/do-you-need-backups/) before. This is the fun part. That same backup gave me a tradition I've kept ever since: every January, I turn the previous year into a printed photo book. It shows up at my door about a week later. The whole thing takes me 30 to 40 minutes on the couch. ## The shelf ![A hand holding a softcover Google Photos book with a city skyline cover photo and the title 2021.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-2021-cover.jpg) One cover photo, one title. The year does the rest. There's a shelf in my living room with about ten of these books on it now. One per year. The cover of each is a photo from that year's vacation or major theme, so I can tell them apart at a glance. When family comes by, the books come off the shelf. My two young nieces flip through them looking for pictures of my dogs. Those books also do a job I never planned for. They exist outside every account, format, and service. Even if I lost every backup tomorrow, the shelf keeps the years I've already printed. ## Why this takes half an hour and not a weekend A photo book sounds like a project. Scrapbook people spend whole weekends on them, with glue. Mine takes half an hour because the work has already happened. The backup collected every photo all year and kept them sorted by date. By the time I sit down in January, there is nothing left to do except pick the ones I like. That's the whole trick. The collecting is automatic. The picking is the enjoyable part, because picking means getting to choose which parts of the year meant the most to you. ## How to do it Two steps, a year apart. **Step one is today: turn on backup.** 1. Install the Google Photos app if you don't have it. Android phones usually come with it. iPhones get it free from the App Store. 2. Open the app and sign in with your Google account. 3. Tap your profile picture in the top right, then 'Photos settings', then 'Backup'. 4. Turn backup *on*. ![Google Photos backup settings screen showing backup turned on and a completed backup.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/shot-1-backup-toggle.png) Backup on. 16,442 photos saved without thinking about it. That's it for this year. Your phone now saves every photo you take on its own. It also means a broken or stolen phone no longer takes your pictures down with it. **Step two happens in January: make the book.** 1. Open Google Photos and tap 'Create', then 'Photo books'. On a computer, go to photos.google.com and click 'Print store'. ![The Google Photos Print store page showing photo books in hardcover and softcover.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/shot-2-print-store.png) 'Print store' on the left, then 'Photo books'. 1. Start a new book and begin selecting photos. I start with January of the year that just ended and work through December, picking the ones that captured a moment. A vacation shot, a birthday, the dogs being dogs. ![Selecting photos in Google Photos, with checkmarks on chosen pictures and photos grouped by date.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/shot-3-selection.jpg) Work through the year in order. Everything is already sorted by date. 1. Pick a cover photo and give the book a title. My cover is a photo from that year's vacation, and my title is just the year. ![The Google Photos book editor showing a cover photo and the title 2026.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/shot-4-cover-title.png) Pick a cover, title it the year. 1. Choose softcover or hardcover. I go softcover because it's cheaper. Hardcover would be nice if you're starting a collection. ![The Google Photos book type chooser showing a 7-inch softcover for $14.99 and a 9-inch hardcover for $29.99.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/shot-5-book-type.png) Prices as of July 2026. 1. Check out. My last book was 102 pages and ran $62 including shipping. Google prints two sizes, a 7-inch softcover and a 9-inch hardcover, starting at 20 pages. It takes a few days to print, then ships to your door. You can add captions and notes to each page along the way. I never have. The pictures carry it. ![An open photo book showing a snake photo on one page and a small dog on the other.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-open-spread.jpg) The pictures carry it. One thing to watch: a low-quality photo prints low quality. Pixelated. Google warns you at selection time when a photo is low resolution, but you can't tell *how* rough it will look until the book arrives. In about a decade of these, nothing has come out bad enough to bother me. When in doubt, pick the sharper shot. ## What about iPhones? Apple used to print photo books straight from its own Photos app. That ended in 2018, and it never came back. There are third-party services that plug into Photos on a Mac, but if you're an iPhone person without a Mac, there's no built-in way to do this. The good news: Google Photos works fine on an iPhone. Install it, sign in, turn on backup, and everything above works the same. Your photos stay in your Apple library too. Google just keeps a copy. Storage is the one thing to know going in. A Google account comes with 15 GB free, which holds a few years of photos for most people. When you run out, 100 GB is about $2 a month. About a decade of this habit has used 75 GB of mine. This is not an expensive hobby. Fair question: this does mean trusting Google with a copy of your pictures. I made that trade a decade ago and I'd make it again, because the photos I kept beat the photos I lost. If you'd rather keep everything in your own hands, the backups article covers ways to do that without any company involved. ## Backup bonus The book is the visible payoff. The other one is that you now have a real backup of every photo you take. If your phone ends up in a lake, your pictures don't. That alone would have saved my lost decade, and it's [a few steps toward the full backup setup](https://www.freshfromcache.com/do-you-need-backups/) everyone should have anyway. And the printed books go one further. I've written about how [the digital things you buy aren't always yours to keep](https://www.freshfromcache.com/do-you-own-what-you-buy/). A service can shut down, change hands, or revoke a license. None of that reaches a book on a shelf. ## You don't have to be a scrapbook person I'm certainly not. There's no glue, no cutting, no layout skills involved. Just picking your favorites from a year that's already saved and sorted. So turn on backup today. Next January, give yourself half an hour on the couch with your own pictures. By February, there will be a book on your shelf with this whole year in it. **Sources:** - [Google Photos Help: Buy a photo book](https://support.google.com/photos/answer/7378942?ref=freshfromcache.com) - [Google Photos Help: Photo book product and shipping info (United States)](https://support.google.com/photos/answer/9079710?ref=freshfromcache.com) - [Google One storage plans](https://one.google.com/about/plans?ref=freshfromcache.com) - [MacRumors: Apple discontinuing its photo book printing service (2018)](https://www.macrumors.com/2018/07/12/apple-discontinuing-photo-books/?ref=freshfromcache.com) ### That sketchy letter from your hospital might be real URL: https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/ Last updated: 2026-07-19T11:00:00.000Z In June, about 18,600 patients of Rochester Regional Health in New York got letters saying their health information had been exposed in a data breach. The letters came from a company most of them had never heard of. They named a hospital that does not exist, "Rochester Regional Medical Center." Plenty of people looked at all that and did what we've all been trained to do. They threw it in the trash. The letters were real. The breach happened at a company called Xsolis, an AI vendor hospitals use behind the scenes for insurance and care paperwork. In January, someone phished their way into Xsolis systems and got files on about 1.4 million patients across the country. Mayo Clinic, UW Medicine, and Legacy Health patients are all on the list. The stolen data included names, birth dates, Social Security numbers, insurance details, and medical treatment information. Rochester Regional stopped working with Xsolis back in 2021\. The company was still holding five-year-old patient records when it got breached. You never picked Xsolis. Hospitals are allowed to hand patient data to vendors like this without asking you, and the vendor never has to tell you it has your file. You usually find out the way Rochester patients did: a letter, after something goes wrong. For the people who tossed that letter, the reality is they were not being careless. Wrong hospital name, unfamiliar sender, an alarming claim about your data. That's the scam checklist, and they ran it correctly. It's the same checklist that catches [phishing emails](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). The instinct is good. It just has a blind spot. Real companies produce letters this sketchy all the time, because they outsource breach notifications to vendors you've never heard of, and sometimes those vendors can't even get the hospital's name right. So when one of these shows up, don't trust the letter, and don't trash it. Check it yourself. A few steps you can take: - **Find the number on your own.** Look up the hospital or company on its official website, or grab it off a bill you already have. Call and ask if the letter is real. A scammer can fake a letter, but they can't make your real hospital vouch for it. - **Ignore every phone number and link printed on the letter.** If the letter is fake, that number rings the scammer. Verify first. Once you know it's real, the letter's contact info is safe to use. - **If it's real, take the free help.** Breach letters usually include free credit or identity monitoring with an activation code. Use it. - **If your Social Security number was in the pile, freeze your credit.** It's free, and it's a lock instead of an alarm. [We have a guide.](https://www.freshfromcache.com/freeze-your-credit/) One bit of caution. This does not mean investigating every strange letter that hits your mailbox. A prize notice from a sweepstakes you didn't enter is still garbage. The verification check is for mail that claims to be from a place you actually deal with: your hospital, your bank, your insurer. If it's really them, they won't have any problem confirming they sent it. ### Sources - [Xsolis, Inc. notice of data security incident (PR Newswire, June 5, 2026)](https://www.prnewswire.com/news-releases/xsolis-inc-provides-notice-of-data-security-incident-302791875.html?ref=freshfromcache.com) - [News10NBC / WHEC: letters sent to 18,600 Rochester Regional patients](https://www.whec.com/top-news/rochester-regional-health-data-breach-letters-sent-to-18600-patients-after-third-party-vendor-xsolis-hack/?ref=freshfromcache.com) - [HIPAA Journal: Xsolis data breach affects 1.4 million individuals](https://www.hipaajournal.com/xsolis-data-breach/?ref=freshfromcache.com) ### What do you do when an AI deepfake has your face? URL: https://www.freshfromcache.com/ai-deepfake-has-your-face/ Last updated: 2026-07-22T11:08:11.000Z A friend sent Dr. Maurice Sholas a TikTok of himself selling vitamins. There he was in a lab coat, his own name stitched on it, telling viewers that a supplement called K2D3 was something their bodies needed. He never said any of it. Someone had taken a clip from one of his real videos, ran it through AI, and put new words in his mouth. The word for this is a deepfake. Sholas is a real pediatric physician in New Orleans. The product was real too, and the fake ads were aimed at Black viewers specifically. The ad was claiming the supplements mattered "because they're Black." At least one person he knows bought a bottle believing the recommendation came from him. [Fake faces make real money](https://www.freshfromcache.com/fake-face-real-money/), which is exactly why these ads keep getting made. So he set about getting the videos taken down. He complained to the account posting them. They removed nothing. They edited the videos instead, aging his face and changing his teeth just enough to argue it wasn't him. He reported it to TikTok and received silence. Sholas described his attempt in just a few words: "I don't have a PR firm. So TikTok just ignored me." He finally called a journalist friend at a New Orleans TV station, and hours after the newsroom reached out for comment, TikTok banned the account. By then copies had spread to Instagram and X. Instagram ignored his reports too. On a lawyer's advice he paid for a verified checkmark, hoping it would make his reports count for something. He calls that paying "for the privilege of being me." It didn't help. The scammers blocked him, so he couldn't even see whether the fakes were still up. When he asked what professional cleanup would cost, the reputation firms quoted between $9,000 and $20,000. If your first instinct is to ask which privacy setting he forgot to turn off, I had the same thought. But there wasn't one to forget. No setting anywhere covers someone feeding your public videos into an AI tool and posting the results from an account you've never heard of. We covered [the one Instagram setting worth turning off](https://www.freshfromcache.com/meta-instagram-ai-feature/) when Meta pulled its AI image feature earlier this month. That toggle is still worth your thirty seconds. It stops one company from reusing your posts in one set of features. What happened to Dr. Sholas happened outside every settings menu. ## The report buttons were built for a different problem Every big platform has an impersonation report, and the policies all describe the same situation: someone created an account pretending to be you. A cloned profile using your name and photos. For that, the forms work. Instagram's asks for a government ID and confirmation that an account is "pretending to be you." X requires an account posing as you. TikTok's covers "accounts that pose as another real person." An AI ad with your face, posted by a real account that never claims to be you, is none of those things. It isn't a fake account. It usually isn't intimate imagery, which has its own removal process. And unless you filmed the original clip yourself, it isn't your copyright either. It falls between every category the report menus offer. There is no right form for what happened to Dr. Sholas. YouTube is the one exception. Since 2024, its privacy complaint process has covered AI content that "looks or sounds like you," in those words. You file, the uploader gets 48 hours to take it down themselves, and then YouTube reviews it. Removal isn't guaranteed. But it's the only big platform with a request form built for this, and that makes it the one place to start with a form instead of a prayer. ## The law assumes somebody is selling something The legal right at play here is called the right of publicity: your ability to control commercial use of your name, face, and voice. Thirty-seven states recognize it in some form. Read the fine print, though, and the operative word is commercial. In most states, if nobody is selling anything, you have no claim. Someone generating images of you for laughs breaks no law in most of the country. (California reaches further than most, and which state you live in matters more than it should.) ![Columns and pediment of the U.S. Supreme Court building, with the words Equal Justice Under Law carved above](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-court.jpg) Photo by Getty Images on Unsplash+ The new AI likeness laws you may have heard about were built for someone else. Tennessee's ELVIS Act protects voice and likeness, written with recording artists in mind. California passed protections for performers and for dead celebrities. New York's digital replica law covers deceased performers. A living, ordinary person whose face turns up in an AI video sits outside most of it. Federal law is thinner still. A New York court ruled last year, in a case brought by two voice actors whose voices were cloned, that copyright and trademark law don't protect a face or a voice at all. What survived in that case were state claims. The one federal law that did pass, the TAKE IT DOWN Act, requires platforms to remove intimate images within 48 hours, and it has teeth, but it covers only intimate images. A fake ad, a meme, a "harmless" remix of your face all sit outside it. And the FTC has had a rule on its desk since early 2024 that would make impersonating an individual a federal violation. As of this month it still isn't finished. One more detail from the fine print. To use the Meta AI feature that makes AI images of you from your own photos, you agree to waive your rights under the Illinois and Texas biometric privacy laws. Those are the two strongest face-data laws in the country, the same ones behind billion-dollar settlements against Meta. The fun feature comes with a legal release attached. One bill would change the picture: the NO FAKES Act, which would give every American, famous or not, a right over digital replicas of themselves, with a takedown process attached. It cleared a Senate committee unanimously in June. It is not law, no floor vote is scheduled, and the House version hasn't moved. Watch it, but don't wait on it. ## When the law works, money changed hands Kaelyn Lunglhofer was 19 when a dating app called Meete took ten seconds from the TikTok she posted on her high school graduation day, put its branding on it, and added a voiceover asking if viewers wanted "a friend with benefits." The app aimed the ad at men near her location. She found out when a guy in her own dorm sent it to her. She's suing in federal court, and she has a real case for one reason: the app used her face to sell something. Commercial use is the hook her lawyers can hang claims on, including Tennessee's ELVIS Act. The catch is that the companies behind the app are registered in the British Virgin Islands and China. You can have the strongest likeness claim in America and still be chasing a defendant no American court can easily reach. And when a face does get licensed properly, look at the price list. Scott Jacqmein, a 52-year-old Dallas actor, was paid about $750 plus a trip to California for the rights to his AI avatar. The avatar has since pitched insurance quotes, horoscope apps, and a supplement he'd never heard of, once in fluent Spanish. He doesn't speak Spanish. The one fake he managed to get removed came down through an ordinary YouTube complaint. TikTok's biggest star, Khaby Lame, sold rights tied to an AI twin of himself in a deal valued at $975 million. The going rate for a face depends on whose face it is. ![A camera and microphone mounted inside a ring light, aimed at a man sitting out of focus in the background](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-ringlight.jpg) Photo by Glenn Marczewski on Unsplash ## What actually works right now The full step-by-step takedown guide is now its own post: [How to get a deepfake of you taken down](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/). The short version: - **Save everything first.** Screenshots, links, dates, the account name, who saw it. Every path that works starts with proof, and content like this tends to vanish and reappear somewhere else. - **On YouTube, use the privacy complaint.** It's the one form on any big platform written for AI likenesses. It's in YouTube's help pages under "Protecting your identity." - **Everywhere else, report it anyway, and don't do it alone.** Ask friends and family to report the same posts. In Dr. Sholas's case, what finally moved TikTok was a newsroom asking questions, and I won't pretend otherwise: attention works. - **If it's selling something, talk to a lawyer.** Commercial use is where your state's publicity law may give you an actual claim, especially if the advertiser is a US company. - **If it's intimate or sexual, it's a different situation.** The TAKE IT DOWN Act requires removal within 48 hours. Report it to the platform and at ic3.gov, the FBI's complaint center. ![Four situations and the path for each: intimate imagery goes to the TAKE IT DOWN Act's 48-hour removal, commercial use goes to a lawyer, YouTube has a privacy complaint form, and everything else starts with screenshots and reports](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/diagram-which-path.png) There are also paid services now, some with free tiers, that monitor for your face and file takedowns for you. The biggest one claims a 95 percent success rate. Nobody independent has verified that number, so take it as what it is: the company's own claim about itself. A market is forming to sell people the protection the law doesn't provide. Whether it delivers is an open question. ## Where this leaves us People finding ugly uses for a new technology is an old story, and the law running years behind is an even older one. I expected both. What made me angry, reading about Dr. Sholas, was the wall he hit at every company: no person to talk to, no path that treated him like a human being with a real problem. He ended up paying for a checkmark in hopes it came with someone who would listen. I've done the same thing, paid for verification just to get a problem in front of a person. That's buying customer service that should come with the product. These platforms built the tools that make fakes this easy. A working way to report one should be built. The NO FAKES Act will probably become law in some form, and it will build the road: a federal likeness right, a takedown process, penalties for platforms that ignore it. My worry is scale. The old version of this scam took real time and effort per victim. Now one person can generate a million fakes with the click of a button. Facebook and Twitter both hit a wall when moderation outgrew them, and this wave is bigger and more personal. When the queue overflows, the people with PR firms and lawyers get through it. The rest of us are the ones who fall through the cracks. So if you're wondering whether to stop posting your face, or your grandkids, my answer is no. The odds of this catching any one of us are still low. Post with it in mind, the way you lock the car without expecting a break-in. And pay attention to how the companies and the lawmakers handle this, because we're the ones who will live with the answer, and we do get a vote. If a fake of you or someone you love shows up tomorrow, the screenshots come first, before the reporting and before the phone calls. Everything that eventually worked, for the doctor and the student both, started with being able to show what ran and where. ## Sources - [AARP, The Perfect Scam: "Deepfake Doctors: AI-Generated Medical Ad Scams"](https://www.aarp.org/podcasts/the-perfect-scam/?ref=freshfromcache.com) (April 24, 2026) - The New York Times: "He Sold His Likeness. Now His Avatar Is Shilling Supplements on TikTok." (August 17, 2025) - CyberScoop: coverage of Lunglhofer v. Meete, E.D. Tenn., filed April 28, 2026 - [YouTube Help: "Protecting your identity"](https://support.google.com/youtube/answer/2801895?ref=freshfromcache.com) - [Meta Transparency Center: Meta AI Verification Terms](https://transparency.meta.com/policies/other-policies/meta-ai-verification-terms/?ref=freshfromcache.com) - U.S. Copyright Office: Copyright and Artificial Intelligence, Part 1: Digital Replicas (July 2024) ### Your phone can copy text out of any photo URL: https://www.freshfromcache.com/copy-text-from-a-photo/ Last updated: 2026-07-17T10:59:59.000Z Someone hands you the wifi password. It's fifteen characters of random letters, numbers, and special characters printed in tiny type on a sticker on the back of the router. You crouch down, tilt your head, and start typing it into your phone one character at a time. Not anymore. You don't have to do that. Your phone can read the sticker for you. Any recent iPhone or Android can pull the text straight out of a photo, or straight off whatever your camera is pointed at. The words become selectable, like text on a web page. You copy them and paste them wherever you need them. No app to buy, nothing to set up. Most people have had this on their phone for years and never knew. Think of it less like a picture and more like a page you can highlight. The phone looks at the photo, finds the letters, and hands them back to you as real text. A menu, a receipt, a business card, the serial number on the bottom of a device. If you can photograph it, you can copy it. ## On an iPhone Apple calls this Live Text. It has been built in since the iPhone XS. 1. Open the Photos app and tap a photo that has text in it. (Or just open the Camera and point it at the text. You don't have to take the picture.) 2. Look at the bottom-right corner for a small icon of a few lines inside brackets. Tap it. The text lights up. 3. Touch and hold one word, then drag the dots to grab the rest. Or tap 'Select All'. 4. Tap 'Copy'. Now paste it into a text, a note, or the search bar. If nothing lights up, the feature may be turned off. Go to Settings, then General, then Language & Region, and turn on 'Live Text'. For the live camera version, it's Settings, then Camera, then 'Show Detected Text'. ## On an Android phone Here it runs through Google Lens, which is already on most Android phones. 1. Open the photo in Google Photos. 2. Tap the Lens icon at the bottom. (On some phones it's behind the three-dot menu, listed as 'Google Lens'.) The words get underlined. 3. Tap a word and drag the handles to grab the rest. Tap 'Copy text'. 4. Paste it wherever you need it. ![Three Android screenshots showing how to copy text with Google Lens: opening the photo in Lens, selecting the text and tapping Copy, then pasting it into a note.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/android-steps.png) On Android: open the photo in Google Lens, select the text and tap Copy text, then paste it anywhere. To grab text live off your camera, open the Google app, tap the Lens icon in the search bar, point it at the text, and choose 'Copy text' once it highlights. Your phone may have a shortcut of its own. Samsung phones show a 'T' in the corner of the Camera. Newer Pixels and Galaxies let you press and hold the home bar and grab text from there. Different names, same trick. ## One more thing Every photo already sitting in your camera roll works too. That screenshot of a confirmation number. The picture you took of a flyer. The receipt you photographed for your records. The text in all of them is grabbable right now. You don't need a fresh photo. You already have a pile of them full of text you can pull. It won't be perfect. Messy handwriting and fancy fonts trip it up, and it works best in English and other common languages. But for printed text on a screen, a sticker, or a page, it just works. Try it once on the wifi password taped to the back of your router. Point, grab, paste. After you've done it a single time, you'll never type one of those by hand again. If you give it a shot, hit reply and tell me the first thing you grabbed. ## Sources - [Apple Support: Copy and translate text from photos on your iPhone or iPad](https://support.apple.com/en-us/120004?ref=freshfromcache.com) - [Apple Support: Change the language and region on iPhone](https://support.apple.com/guide/iphone/change-the-language-and-region-iphce20717a3/ios?ref=freshfromcache.com) (Live Text toggle: Settings > General > Language & Region) - [Google: Copy text from images with Google Lens](https://support.google.com/photos/answer/9827192?ref=freshfromcache.com) (in Google Photos and the Google app) ### The Meta AI panic is over, but turn off this lingering setting. URL: https://www.freshfromcache.com/meta-instagram-ai-feature/ Last updated: 2026-07-16T12:19:13.000Z If a friend forwarded you a warning last week about Meta letting anyone turn your Instagram photos into AI images, here is the update: Meta already switched that off. The feature launched July 7\. By July 10 it was gone. Three days. It let someone type your Instagram handle into Meta's new image generator and get back a fabricated picture built from your public photos, with no notice to you and nothing to approve first. Actors, their agencies, and a lot of ordinary users pushed back, and Meta pulled it. In the company's own words, it "missed the mark." So the thing most of those forwarded posts are warning about no longer exists. Good. But it left a smaller piece behind, and that part is worth looking at. The setting that fed the feature is still there, and it is still on by default for public accounts. It is the one labeled "Allow people to reuse your content on Instagram and with AI features at Meta." The @-mention tool is gone, but Meta's larger image generator, Muse Image, is still running inside the Meta AI app, in WhatsApp, and in Instagram Stories. Turning that setting off is how you keep your posts out of whatever it becomes next. Two things people keep getting wrong. The emergency is over, so you can stop worrying about a friend spinning up an AI photo of you tomorrow. And posting "I do not consent" on your profile does nothing. It is not a contract, Meta never agreed to it, and it has never once stopped a company from doing anything. Skip it. Your public photos are now [raw material for AI](https://www.freshfromcache.com/fake-face-real-money/), and Meta's first instinct was to switch that on for everyone and leave you to go hunt for the setting that turns it off. They backed down this time because famous people got loud. What they backed down to is still opt-out, not opt-in. That is the pattern to watch, because the next feature built on your photos is coming, and it will probably arrive the same way. ## What to do - **Turn off the reuse setting.** On Instagram, walk this path:The exact wording shifts a little between app versions, so look for anything about reusing your content with AI. - Go to your Profile and open the menu (the three lines, top right). - Tap 'Settings and activity'. - Scroll to the "How others can interact with you" section and tap 'Sharing and reuse'. - Under "Allow people to reuse your content on Instagram and with AI features at Meta," turn off both controls: one for Posts, one for Reels. - **If you do not see it, update the app.** Meta was still rolling this out in the US, so it may not have reached your phone yet. Check again in a few days. - **If AI misuse really worries you, go private.** A private account cannot be referenced or reused at all. You lose reach, you gain a wall. That is the trade. - **Check the kids' and grandkids' accounts.** Teen accounts are supposed to default to private, which keeps them out of this. Confirm it, and confirm no child is on a public adult account set up with a fake birthday. We covered which of these [child-safety settings actually hold up](https://www.freshfromcache.com/teen-safety-features-that-work/) last week. - **Think about the kids in *your* photos too.** Meta never said whether children appearing in an adult's public photos were off limits. If you run a public account full of the grandkids, making it private protects them, not just you. - **If you ever find an AI image misusing you or your family, screenshot it first.** Then report it in the app: press and hold the image and choose the thumbs down. If the image is sexual, a new federal law called the TAKE IT DOWN Act requires platforms to remove it within 48 hours of your report. You can also report it to the FBI at ic3.gov. ![Two Instagram screens: the Privacy menu with Account Privacy highlighted, and the Private Account toggle switched on.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-privacy.png) Going private is the surest fix. On Instagram: Privacy, then Account Privacy, then turn on Private Account. One catch before you close the app. Turning the setting off only stops what happens from here. It will not delete anything already made, and it does not stop Meta from using your public posts to train its models. That is a [separate objection you have to file](https://www.facebook.com/help/contact/510058597920541), and in the US Meta is not required to honor it. It also might not stick. Meta could bring the @-mention feature back, and if it returns on by default, treat it as live again. Turn the setting off anyway. The feature that scared everyone is already gone. The reason to do this is for the one Meta has not announced yet. **Sources:** [Meta's Muse Image announcement, with the July 10 removal note (Meta Newsroom)](https://about.fb.com/news/2026/07/introducing-muse-image-meta-ai/?ref=freshfromcache.com) · [Meta removes the Instagram @-mention feature after backlash (TechCrunch)](https://techcrunch.com/2026/07/10/meta-removes-controversial-ai-feature-on-instagram-after-backlash/?ref=freshfromcache.com) · [How to turn off the Meta reuse setting (Malwarebytes)](https://www.malwarebytes.com/blog/ai/2026/07/turn-off-this-meta-setting-before-someone-generates-ai-images-of-you?ref=freshfromcache.com) ### Data brokers have a file on you. California is making them delete it. URL: https://www.freshfromcache.com/what-is-a-data-broker/ Last updated: 2026-07-15T10:59:59.000Z There's an industry that knows your name, your address, your phone number, and a guess at your income and your health. You've never bought anything from it. You've never signed up for anything it runs. On August 1, it has to start answering to a delete button. These companies are called data brokers. A data broker collects information about people it has no relationship with, then sells it. Google and Facebook are not considered data brokers; you use them, and that's a different conversation. Data brokers are the companies you've never heard of: Acxiom, Epsilon, LexisNexis, and the people-search sites that hand your home address to anyone who types your name. Market researchers estimate the industry at around $300 billion a year worldwide. Most of us couldn't name three of the companies in it. ## The product Your name and address are the cheap part. They're on a thousand lists already and cost almost nothing to re-collect. The money is in the conclusions brokers draw from the raw facts, or what the industry calls inferences. Some of those inferences include whether you're pregnant, behind on bills, or the kind of person who answers a sweepstakes letter. This sounds like an exaggeration until you read the government's own reports. The FTC studied nine brokers and found one holding 3,000 separate data points on nearly every consumer in America. A Senate report found brokers selling marketing lists with names like "Rural and Barely Making It." And this January, California fined a Texas broker that had been reselling lists of people with Alzheimer's, substance-abuse problems, and bladder incontinence. ## When it goes wrong In 2021 the Department of Justice fined Epsilon, one of the biggest marketing brokers in the country, $150 million. Its salespeople had spent years selling consumer lists to mail-fraud operations that target the elderly. More than 30 million people landed on lists sold to scammers. The industry calls those "sucker lists," and they're built from the same data that fills your mailbox with catalogs. That same year, a Catholic priest was identified through location data from the dating app Grindr, bought from a data broker. He resigned within days. Nobody hacked anything. The data was for sale. And then there's what happens when a broker gets breached. National Public Data was a Florida background-check broker almost nobody had heard of. That is, right up until 2024, when its database showed up for sale online. Social Security numbers and addresses for roughly 270 million people. It later leaked outright, free for anyone to download. The company went bankrupt with less than $75,000 in assets. The data outlived the company. ## What California built California passed the Delete Act in 2023, and the delete button it ordered is now live. It's called DROP, the Delete Request and Opt-out Platform, and it sits at [privacy.ca.gov](https://privacy.ca.gov/drop/?ref=freshfromcache.com). A California resident files one request, free, and every data broker registered with the state (more than 580 of them now) has to check that list, find you, and delete what it holds. Including the inferences. And they can't do it once and move on: brokers have to re-check the list every 45 days and delete whatever they've re-collected, indefinitely. Ignoring a request costs $200 per person per day. More than 242,000 Californians are already queued up. ![The dome of the California State Capitol with the United States and California flags flying](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-capitol-what-is-a-data-broker.jpg) The Delete Act passed in Sacramento in 2023\. The delete button went live this January. Residents have been able to file since January 1\. August 1 is the day brokers are required to start acting. There are exemptions, and most are reasonable. A broker can keep data it needs to prevent fraud, meet a legal requirement, or finish something you asked it to do. Your credit file at the bureaus lives under separate federal rules entirely, which is one reason a credit freeze still makes the list below. ## What it can't do I'll make the skeptic's case, because it's fair. DROP only reaches brokers that registered with the state, and researchers comparing state registries believe plenty never have. A broker that never registered never sees your request. Matching is strict, too: a broker deletes you when your submitted details line up with its records exactly. So a thin profile gets a thin deletion. And the law's definition has a hole in it: a company with a direct relationship to you isn't a "data broker" at all. Google, Meta, the loyalty program at your grocery store, all outside this law. So no, it isn't a vanishing act. What sold me on the design anyway is the 45-day cycle. Older privacy laws let a broker delete your file on Tuesday and rebuild it from fresh sources by Christmas. This one turns deletion into a subscription the broker can't cancel. Whether it gets enforced is an open question, and the early signs look good. California has already brought at least nine enforcement actions against brokers just for failing to register. The bigger fines start after August 1. ## If you live in California File now, before August 1, so you're in the queue the day brokers have to start processing. It's free at [privacy.ca.gov](https://privacy.ca.gov/drop/?ref=freshfromcache.com), takes a few minutes, and you can [check your request's status](https://consumer.drop.privacy.ca.gov/dropstatus?ref=freshfromcache.com) on the same site. You choose how much identifying information to give. More identifiers means more matches, and more matches means more deletion. You can also file on behalf of a family member who lives in California. If your parents are the ones getting the sweepstakes mail, that might be the most useful ten minutes of your month. ## For the rest of us No other state has a delete button yet. Connecticut just passed one that starts in 2027, and more statehouses will copy it. In the meantime, a few steps you can take, in order of payoff for the effort: - **Turn on Global Privacy Control.** It's a [browser setting](https://globalprivacycontrol.org/?ref=freshfromcache.com) that tells every site you visit not to sell your data, and twelve states (Oregon and Texas included) legally require businesses to honor it. It's built into Firefox, Brave, and DuckDuckGo, and a free extension adds it to Chrome. Five minutes, once. It pairs well with the rest of [our browser privacy checkup](https://www.freshfromcache.com/chrome-edge-privacy-settings/). - **Opt out of prescreened credit offers.** [OptOutPrescreen.com](https://www.optoutprescreen.com/?ref=freshfromcache.com) is run by the credit bureaus themselves. It shuts off the preapproved-card mail at the source for five years, or permanently if you mail in the form. Free. - **Freeze your credit.** A freeze is damage control rather than removal: stolen data gets much harder to use when nobody can open an account in your name. Free at all three bureaus, and we have a [full walkthrough](https://www.freshfromcache.com/freeze-your-credit/). - **If you'll pay for removal, pay small.** Consumer Reports tested the paid removal services, and the results were humbling. Doing the opt-outs yourself beat every service they tested. The best performers, Optery and EasyOptOuts, cleared about two thirds of the profiles they went after within four months, and EasyOptOuts runs about $20 a year. Services charging ten times that did worse. Some did far worse. - **Put it on the calendar.** Whatever you remove comes back as brokers buy fresh data. DeleteMe's own CEO says about 42 percent of customer information reappears within six months. Re-run your opt-outs a couple of times a year, the way you'd change smoke-detector batteries. ## Think maintenance, not purge The brokers will keep collecting, because collecting is the business. What changed is that one state can now make almost 600 of them un-collect, every 45 days, under penalty. If it works, your state will hopefully copy it. If you're in California, a few minutes this week puts you in the first wave. Everywhere else, GPC, the prescreen opt-out, and a credit freeze cost nothing. The industry will keep guessing about you either way. Make it guess with less. **Sources:** - [CalPrivacy: the DROP platform](https://privacy.ca.gov/drop/?ref=freshfromcache.com) - [California Privacy Protection Agency: DROP regulations announcement](https://cppa.ca.gov/announcements/2025/20251113.html?ref=freshfromcache.com) - [IAPP: CalPrivacy DROP participation and enforcement update](https://iapp.org/news/a/calprivacy-unpacks-drop-updates-on-consumer-participation-upcoming-enforcement?ref=freshfromcache.com) - [FTC: Data Brokers, A Call for Transparency and Accountability (2014)](https://www.ftc.gov/system/files/documents/reports/data-brokers-call-transparency-accountability-report-federal-trade-commission-may-2014/140527databrokerreport.pdf?ref=freshfromcache.com) - [Department of Justice: Epsilon agrees to pay $150 million](https://www.justice.gov/archives/opa/pr/marketing-company-agrees-pay-150-million-facilitating-elder-fraud-schemes?ref=freshfromcache.com) - [Consumer Reports: Evaluating People-Search Site Removal Services (2024)](https://innovation.consumerreports.org/Data-Defense%5F-Evaluating-People-Search-Site-Removal-Services-.pdf?ref=freshfromcache.com) - [NBC News: priest identified through Grindr location data](https://www.nbcnews.com/tech/security/priest-outed-grindr-app-highlights-rampant-data-tracking-rcna1493?ref=freshfromcache.com) - [The National Public Data breach (overview)](https://en.wikipedia.org/wiki/2024%5FNational%5FPublic%5FData%5Fbreach?ref=freshfromcache.com) ### The parental controls that fail, Amazon's Starlink rival, and a VPN warning URL: https://www.freshfromcache.com/newsletter/parental-controls-that-dont-work/ Last updated: 2026-07-14T14:59:59.000Z This week started with a report I wish were surprising. Researchers tested 86 of the safety features that social media apps advertise to parents, and most of them failed, were buried, or were missing outright. I wrote up which controls to trust instead. In this issue: - [The parental controls that held up, and the ones that failed](https://www.freshfromcache.com/teen-safety-features-that-work/) - [Amazon's answer to Starlink gets real](https://www.freshfromcache.com/starlink-is-about-to-get-competition/) - [You bought the movie, but do you own it?](https://www.freshfromcache.com/do-you-own-what-you-buy/) - [Windows 11's new rewind button is not a backup](https://www.freshfromcache.com/windows-point-in-time-restore/) - [Who answers when a chatbot is blamed for a death?](https://www.freshfromcache.com/ai-accountability/) - [The short list of apps for a normal person's phone](https://www.freshfromcache.com/suggested-apps/) - [This week's tech tip: could you get back into your email?](https://www.freshfromcache.com/email-recovery-check/) And the Scary Headline: the free VPN app on your phone may be doing the opposite of its one job. That one is at the bottom, and it is worth the scroll. --- [**Most teen safety features don't work. Here's what does.**](https://www.freshfromcache.com/teen-safety-features-that-work/) Researchers checked 86 child-safety features that Instagram, Snapchat, TikTok, and YouTube advertise to parents. Only 35 worked as promised. The pattern that held up: the default Teen Account protections and the under-13 kid modes mostly do their job. The controls you have to hunt down to turn on are the ones that fail. The post has the per-app list of what to turn on and what to skip. *Learn* --- [**Starlink is about to get competition**](https://www.freshfromcache.com/starlink-is-about-to-get-competition/) Amazon says its Leo satellite internet turns on for customers later this year, and it matters most where the internet provider options are sparse. Pricing and real-world speeds aren't public yet, so nobody should cancel anything. The waitlist at leo.amazon.com is free, though. Put your name on it, then judge Leo on numbers instead of promises. The post covers how it differs from the satellite internet you may remember. *News* --- [**You bought it, but do you own it?**](https://www.freshfromcache.com/do-you-own-what-you-buy/) Sony is ending PlayStation game discs and deleted 551 movies from customers' libraries in Europe, no refunds. Clicking Buy on a movie, book, or game usually gets you a license someone else can revoke. The habit that protects you: for anything you would hate to lose, buy it from a store that hands you a file you can download and keep. The post names those stores. *Learn* --- [**Windows 11's new rewind button works, but it is not a backup**](https://www.freshfromcache.com/windows-point-in-time-restore/) Microsoft's Point-in-Time Restore reaches most Windows 11 PCs with this week's Patch Tuesday update. It can roll your computer back to yesterday, and I'd let it turn on. Just know the snapshots live on the same drive they protect, so when the drive dies they die with it. Use it for oops moments, and keep a real backup somewhere else. *News* --- [**Can OpenAI be held responsible when ChatGPT is blamed for a death?**](https://www.freshfromcache.com/ai-accountability/) The first lawsuit to blame a chatbot for a death by violence is working through the courts. The whole case turns on one fork: if a chatbot is a product, the maker can be liable for a dangerous design, and if it is a service, the bar is much higher. No verdict from me, just the case, the fork, and why nothing about it is settled law yet. *Blog* --- [**The apps I'd recommend aren't the ones I use most**](https://www.freshfromcache.com/suggested-apps/) I looked at my own most-used apps and they are all mostly for work. So this is the other list: the handful that earn a spot on a normal person's phone, starting with what's already built in, plus the kinds you should delete. One of the deletes was the free VPN, and that call aged about two weeks. See the Scary Headline. *Blog* --- If you only read one: the teen safety report. If a kid or grandkid in your life has a phone, it tells you which switches to trust and which to skip. --- ### 5-Minute Tech Tip Check the recovery info on your email account. Everything else resets through that inbox, and the recovery phone and backup email on it are how you get back in if you ever get locked out. Most of us set them years ago and haven't looked since. Five minutes signed in beats thirty days locked out: [Check your email's recovery info before you get locked out](https://www.freshfromcache.com/email-recovery-check/). --- ### Scary Headline of the Week *"Free VPN apps downloaded 2.4 billion times are leaking your data."* Mostly true, which is unusual for this segment. Researchers at the University of Michigan, the University of New Mexico, and IIT Delhi tested 281 free VPN apps from the Google Play store. The apps they flagged have been installed more than 2.4 billion times. Among them: - 29 let traffic leak outside the tunnel, including the record of which websites you visit - 61 sent data with no encryption at all - 76 sent the phone's advertising ID to third parties, which is tracking, from an app whose one job is to prevent tracking The catch in the headline is the word "your." The study covered free Android VPN apps, the kind that cost nothing and demand nothing, and it says nothing about paid services with audits and reputations to lose. A [VPN's actual job](https://www.freshfromcache.com/what-a-vpn-actually-does/) is narrower than the ads claim anyway, and most of us at home don't need one. If a free VPN is sitting on your phone because it promised privacy, deleting it is probably the privacy upgrade. Verdict: real, but only if a free VPN app is on your phone. Deleting it takes ten seconds. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. --- ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help that cost nothing: forward it to someone who would use it, and if it was forwarded to you, [subscribe](https://www.freshfromcache.com/#/portal/signup) to get your own copy every Tuesday. --- Did your email's recovery info turn out to be current, or from three phones ago? Hit reply and let me know. Joel ### Start using a password manager URL: https://www.freshfromcache.com/start-using-a-password-manager/ Last updated: 2026-07-14T12:07:55.000Z As the person friends and family ask about this kind of thing, I hear the same setup over and over, usually described a little sheepishly. One good password. Maybe a second one for the important stuff. The same word on everything, with a number on the end that climbs by one each time a site forces a change. We have all run some version of it. It is easy, it is convenient, and it works right up until it doesn't. The problem isn't that the password is weak. You can make it sixteen characters of gibberish and it changes nothing. A password you reuse is a single key, and you have handed a copy to every website you ever signed up for. Some of those sites are run well. Some were abandoned a decade ago. When any one of them gets breached, your email and password land on a list, and the people who buy that list do all manner of things. They try the same pair on your bank, your email, everything. One key, every lock. A password manager ends that. It invents a different, random password for every account, keeps them all in one encrypted vault, and fills them in when you need them. You remember one password, the one that opens the vault. It handles the other two hundred, including the ones you forgot you had. ## What changes Three things, in order of importance. Reuse ends. Every account gets its own password, so one breached website stays one problem instead of spreading into all of them. Strong passwords stop being work. The manager invents something no person would think up or remember, and you never type it. The length that used to be a chore becomes the default you never see. And third, it catches phishing for you. A password manager only fills in a login on the exact web address where you saved it. So when a convincing email drops you onto a page that looks like your bank but lives at the wrong address, the manager does nothing. No autofill. That empty box is the most useful warning you can get. The password manager will tell you the site is fake by refusing to recognize it. Turning convenience into security. ## Picking one You do not need to research this for a week. Any reputable manager beats what you are doing now. The best one is the one you actually use, so keep that in mind before you go shopping for the perfect app. You may already have one, switched on by default. Apple's built-in Passwords app covers an iPhone-and-Mac life. Google's built-in manager covers Chrome and Android. People actually use these, because they are right there at the moment you log in, and a manager you use beats a better one you never open. If that is you, you are most of the way there already. There are two good reasons to move up to a standalone manager. The first is that it travels. Apple's and Google's tools turn clumsy the moment you cross into a different phone or browser, and most of us live across at least two. A standalone works the same everywhere, on your iPhone, your work Windows laptop, an Android tablet, any browser. The second reason is the one people miss. A standalone manager becomes the single locked drawer for everything that isn't a password but needs the same protection. Your card numbers. A photo of your passport. The garage code. Software licenses. The recovery codes for your two-factor logins. All of it sits in one encrypted vault, filled in or copied when you need it, instead of scattered across notes apps and email. For the standalone, I recommend two names. - **Bitwarden** is where most people should start. It is free, the free version covers what most people need, it is open-source with published security audits, and it runs everywhere. - **1Password** is excellent if you would rather pay a few dollars a month for the most polished version. It is the easiest way to get a whole household onto the same system. ![A smartphone on a wooden desk showing the Bitwarden password manager app.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/appshunter-io-Jj3-Wh4MHs4-unsplash.jpg) Bitwarden: free, open-source, and where most people should start. ## But don't these get hacked? It is a fair worry, and it may be the reason you have not started. You have seen the headlines. LastPass, one of the biggest names in the business for years, got breached in 2022, and again in 2026\. Why hand every password you own to a company that gets hacked? Because a good manager is built so the company cannot read your vault, even if it wanted to. Your passwords are scrambled on your own device, with a key only you hold, before they ever reach the company's servers. When those servers get breached, the attacker walks off with a block of gibberish that means nothing without your master password. That is what saved most people at LastPass. In 2022 the attackers did steal the encrypted vaults. The only ones they managed to crack open belonged to people who had chosen a weak, guessable master password. Everyone with a strong one stayed safe. The 2026 breach never reached a single vault; it exposed names and email addresses from a support system. So the fear points you at the right two moves. Pick a manager that encrypts this way (Bitwarden, 1Password, Apple, and Proton all do), and give it a strong master password. Do that, and a breach at the company stays the company's problem. ## Start easy The mistake that stops people is treating this as a project, picturing one grim afternoon of typing in two hundred logins. Do not. Here is the painless way. Install the manager and its browser extension. Set your one master password as a passphrase you can actually remember, four or five unrelated words in a row. The manager cannot recover that master password for you, so handle the "what if I forget it" fear on day one. Write the passphrase on paper and keep it where you keep the documents that matter, the birth certificate, the car title, not on a sticky note stuck to the monitor. That paper is your safety net, and it is enough. The paid managers add a second one on top. 1Password gives you an Emergency Kit, a one-page PDF you print and file. Bitwarden's paid tier lets you name a trusted person who can request access after a waiting period you set. Then just live your life. Every time you log into something, the manager offers to save it. Say yes. Within two weeks of normal use, the accounts you actually touch are all in the vault, no dedicated session required. After that, give twenty minutes to the accounts that matter most. Email first, because [email is the master key that resets everything else](https://www.freshfromcache.com/email-recovery-check/). Then your bank and anything holding your money or your identity. Open each one, change the password, and let the manager generate the new one. Five accounts is plenty for a first pass. While you are in those settings, switch on two-factor authentication if it is not already on. I have written separately about [why that second factor beats the small hassle](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/), and about [passkeys](https://www.freshfromcache.com/what-the-heck-is-a-passkey/), the login method slowly coming to replace passwords altogether. ## For a small business or a nonprofit If you run a small business or a nonprofit, you know a second version of this problem. The password taped to the monitor. The one login everyone on staff shares over text and nobody has changed since the last person left. A shared vault fixes it. Bitwarden's team plan runs about four dollars per user a month and gives each person their own login plus the shared ones they need. 1Password offers around half off for registered nonprofits. Same idea as the personal version, one lock, access handed out per person, and no more password living on a sticky note. ## What to skip If you go with a standalone manager, turn off your browser's own offer to save passwords once the real one is running, so you have one vault and not three half-full ones. Resist keeping a few favorite passwords only in your head as backup. It's a bad habit that is easy to slip back into. Ignore any manager you have never heard of that is advertising hard. Stick to the names that have done this for years and have published security audits. You will hear one more fair objection: is this not putting every egg in one basket? It is. But that basket is guarded by encryption the company itself cannot read. Your current setup scatters the same eggs across a hundred sites you do not control and cannot vouch for. Concentrated and protected beats scattered and exposed. If you set one up this week and hit a snag, email me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com) and tell me where you got stuck. The sticking points are usually the same three or four, and I can walk you through any of them. ## Sources - LastPass, [Notice of Recent Security Incident](https://blog.lastpass.com/posts/notice-of-recent-security-incident?ref=freshfromcache.com) (the 2022 breach). - LastPass, [Klue Supply Chain Incident and LastPass Response](https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response?ref=freshfromcache.com) (the 2026 breach). - Bitwarden, [Is Bitwarden audited?](https://bitwarden.com/help/is-bitwarden-audited/?ref=freshfromcache.com) (open source, third-party audits, zero-knowledge encryption). - 1Password, [About the 1Password security model](https://support.1password.com/1password-security/?ref=freshfromcache.com) (account password plus Secret Key). - Apple, [iCloud Keychain security overview](https://support.apple.com/guide/security/icloud-keychain-security-overview-sec1c89c6f3b/web?ref=freshfromcache.com) (end-to-end encryption). ### Windows 11 has a disk-eating bug. Tuesday's update fixes it. URL: https://www.freshfromcache.com/windows-11-disk-eating-bug/ Last updated: 2026-07-13T13:30:00.000Z If your Windows 11 PC keeps running out of disk space and the math never adds up, it may not be your downloads. Microsoft has confirmed a bug that lets one hidden system file grow until the drive is full. People have reported the file reaching 70GB, 110GB, and 200GB, and in one case someone measured just over 500GB. The bug affects the current versions of Windows 11 (24H2 and 25H2). The repair rolls out automatically with the July 14 update. You can check right now whether you're affected. The file belongs to a part of Windows called Capability Access Manager. That's the system that tracks app permissions: which apps have asked to use your camera, microphone, or location, and when. Every request gets logged to a database. Next to that database sits a scratch file, CapabilityAccessManager.db-wal, where Windows writes new entries before folding them into the main log. On a healthy PC the scratch file stays under a few megabytes. On affected PCs the folding step broke, so the file grows. And keeps growing. ## Why you would never find it Windows gives you no way to see this happening. Open Storage settings and the bloat hides inside a line called "System files" under "System & reserved," with no breakdown of what those files actually are. Go hunting for the folder itself and File Explorer says "Access denied." Disk cleanup tools can't recover the space either. The file is protected, and as far as Windows is concerned, it's doing its job. Reports about the runaway file go back about a year, and Windows Insiders have been flagging it for months. Microsoft never listed it on its public known-issues dashboard. The acknowledgment, when it came on June 29, was one sentence added to the release notes of an optional update: "This update improves disk space usage for the CapabilityAccessManager.db-wal file." That's the entire public explanation for a bug that filled users' drives, leaving them with no space. ## The expensive mistake The lost storage isn't the biggest cost with this bug. A mysteriously full drive makes people blame themselves. They delete photos and old files that were never the problem. Or they search "clean up my PC," and that search is where the malware and junk live. Paid cleaner apps and "PC optimizer" downloads that charge for fixing nothing, and sometimes install trouble of their own. No cleaner app could have touched this file. The cure was always going to be a patch from Microsoft. And until two weeks ago there was no patch to be had. We made the same point in [our slow-computer guide](https://www.freshfromcache.com/why-is-my-computer-slow/): when a PC misbehaves, find the actual cause before you delete anything or spend a dime. ## A few steps you can take - **Check one Settings screen.** Open Settings > System > Storage > Show more categories > System & reserved. If "System files" shows hundreds of gigabytes, you're probably affected. Tens of gigabytes is normal; mine shows about 31GB. - **Update now if your drive is hurting.** Go to Settings > Windows Update > Advanced options > Optional updates and install the June update, KB5095093\. It contains the repair. If Optional updates only lists driver updates, the repair may already be on your PC. Check Settings > Windows Update > Update history. It installed on mine back in June and I never noticed. - **Otherwise, let Tuesday do it.** The same repair arrives automatically in the July 14 update. Install it when Windows offers it. - **Skip the cleaner apps, and don't delete the file by hand.** It's a protected system file, and deleting things in that folder can cause new problems. - **Look again after updating.** Microsoft hasn't said whether the update shrinks a file that's already huge or only stops it from growing. If "System files" is still enormous a day or two after the update, the file can be cleared by hand from Safe Mode, but that's a job for someone comfortable in there. Ask for help rather than winging it. The permissions log never leaves your PC, and this is a plumbing failure, the mundane kind of bug rather than the scary kind. Most computers were never affected; on a healthy machine that file is smaller than a single photo. Tuesday's update carries plenty besides this repair, including the new [rewind feature we covered last week](https://www.freshfromcache.com/windows-point-in-time-restore/). If your laptop has felt tight on space for months and you assumed the mess was yours, spend the two minutes on that Settings screen. It may not have been you at all. ## Sources - Windows Latest: [Microsoft admits a Windows 11 bug is eating up to 500GB of storage](https://www.windowslatest.com/2026/07/06/microsoft-admits-a-windows-11-bug-is-eating-up-to-500gb-of-storage-verify-if-you-are-affected/?ref=freshfromcache.com) - Microsoft: [KB5095093 release notes (June 23, 2026; change log updated June 29)](https://support.microsoft.com/en-us/help/5095093?ref=freshfromcache.com) - PCWorld: [A Windows 11 bug can eat 500GB of your storage. Here's how to check](https://www.pcworld.com/article/3185240/a-windows-11-bug-can-eat-500gb-of-your-storage-heres-how-to-check.html?ref=freshfromcache.com) ### Check your email's recovery info before you get locked out URL: https://www.freshfromcache.com/email-recovery-check/ Last updated: 2026-07-12T13:59:59.000Z Think about what happens when you forget a password. The bank, the pharmacy, the streaming account. You tap "Forgot password" and the reset link lands in your email. That inbox is the master key to almost everything else you do online. So what happens when the account that gets locked is the email itself? That is what recovery info is for. A phone number and a backup email address on file, so the company can prove you are you and let you back in. Here is the catch: most of us set those up the day we opened the account and have never looked at them since. The phone number from three phones ago. A backup address from an old job, or an internet provider you left years back. When the lockout comes, the code goes to a number that no longer rings for you. This check takes five minutes, and it only works in one direction. Signed in, updating your recovery info is a couple of clicks. Locked out, it is a different story. If Google can't reach you at anything on file, you are into an automated recovery form with no person behind it. If Microsoft has to replace all of your security info, the account goes into a 30-day hold before the new info works. Five minutes now, or thirty days later. Start with your main email account, the one everything else sends its reset links to. That is the whole tip. If you keep a second account, run the same check there another day. One habit while you do this: type the addresses below yourself instead of following a link from an email. That is the same habit that keeps you off [phishing pages](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). ## If your email is Gmail 1. Go to myaccount.google.com and sign in. On a phone, you can also open the Gmail app, tap your photo in the top right, then tap "Manage your Google Account." 2. Tap or click "Security." 3. Scroll to the section called "How you sign in to Google." You are looking for "Recovery phone" and "Recovery email." On some screens the section reads "Security & sign-in." 4. Open each one and read what is there. Is that phone the one in your pocket right now? Can you still open that backup address? If either answer is no, update it on the spot. Two things Google itself warns about. A new recovery number can take up to a week before Google fully trusts it, one more reason to do this before you need it. And don't use a Google Voice number as your recovery phone. If you are locked out, the code goes somewhere you can't reach. ## If your email is Outlook, Hotmail, or Live 1. Go to account.microsoft.com and sign in. 2. Click "Security." 3. Look for "Manage how I sign in." Microsoft may land you on a page called "Security info." Same place. 4. Read the list of phone numbers and email addresses. Remove anything you no longer control. To add a current one, use "Add a new way to sign in or verify." One note here: Microsoft has said it is phasing out texted codes for personal accounts. The backup email address is the piece to get right, and the Microsoft Authenticator app or a passkey is what they will steer you toward. We covered [what a passkey is](https://www.freshfromcache.com/what-the-heck-is-a-passkey/) if that word is new. ## Any other email Yahoo, AOL, your internet provider's mail. Same idea, different menus. Sign in on the web and look for "Account security" or "Account info." It might be tucked under "Sign-in and security" if there is no security section on its own. ## The most important step Don't stop at "something is listed." Read it. The check is whether it reaches you today: the phone that rings in your pocket, the inbox you can open right now. A backup address you lost access to in 2019 is the same as no backup at all. While you are on that screen, Google now offers "Recovery contacts," a trusted friend or family member who can vouch for you if you get locked out. Optional, but a nice fit for an older parent's account. We covered [who gets your photos and email when you're gone](https://www.freshfromcache.com/who-gets-your-accounts/) a few weeks back. This is the nearer-term version of the same housekeeping: making sure the person who can get back into your account is you. If you run this check and the phone number on file turns out to be from three phones ago, I would like to hear about it. ## Sources - Google Account Help, "[Set up recovery options](https://support.google.com/accounts/answer/183723?ref=freshfromcache.com)," Google, 2026. - Microsoft Support, "[Microsoft account security info & verification codes](https://support.microsoft.com/en-us/account-billing/microsoft-account-security-info-verification-codes-bf2505ca-cae5-c5b4-77d1-69d3343a5452?ref=freshfromcache.com)," Microsoft, 2026. - Microsoft Support, "[Your security info change is still pending](https://support.microsoft.com/en-us/account-billing/-your-security-info-change-is-still-pending-or-you-can-t-access-this-site-right-now-microsoft-account-message-cbd0f64f-02d9-45d2-90c3-2375e5a72e52?ref=freshfromcache.com)," Microsoft, 2026. ### Starlink is about to get competition URL: https://www.freshfromcache.com/starlink-is-about-to-get-competition/ Last updated: 2026-07-11T12:28:35.000Z On July 2, Amazon launched 29 more satellites into orbit. That brings its total to 396, and Amazon says that's enough to start offering internet service in its first coverage areas later this year. If you live somewhere with poor internet provider options, you've probably heard of Starlink. You may not have heard that a second service like it is coming, and that it's coming from Amazon. It's called Amazon Leo (it used to go by Project Kuiper), and it works the same basic way. You have a dish at your house that talks to a swarm of satellites passing overhead, and that's your internet. No cable in the ground, no phone line, no waiting for a provider to decide your road is finally profitable enough to reach. For rural readers, it's welcome news. The company that delivers your packages wants to deliver your internet, and it claims the service will be available this year. Before anyone gets excited, it helps to understand what this technology actually is, what Amazon has and hasn't said, and what your options look like today. ## Why this isn't the satellite internet you remember If you've used HughesNet or Viasat, you know the old kind of satellite internet. Pages crawl. Video calls stutter and talk over themselves. It works, sort of, and you pay a lot for the privilege. The problem is distance. Those services use satellites parked about 22,000 miles up, roughly a tenth of the way to the moon. Every click travels from your house to the satellite, down to a ground station, out to the internet, and all the way back. Even at the speed of light, that round trip takes over half a second. Half a second doesn't sound like much until you're on a video call and everyone keeps interrupting each other. Starlink and Amazon Leo fly their satellites at around 380 miles instead. Cutting the distance by that much cuts the delay to a few hundredths of a second, about the same as cable internet in town. That one change is why the new satellite internet can handle video calls, gaming, and remote work when the old kind never could. The tradeoff is that satellites that low don't stay parked over one spot, so you need thousands of them streaming overhead to keep a connection going. Which is why these companies keep launching rockets. ![Long-exposure night sky with several short white satellite streaks among the stars.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-satellite-trails.jpg) Low-orbit satellites leaving trails across a night sky. Photo by [Forest Katsch](https://unsplash.com/@forestkatsch?ref=freshfromcache.com) on [Unsplash](https://unsplash.com/?ref=freshfromcache.com) The new kind still has limits. The dish needs a clear view of the sky, so heavy tree cover is a real problem. Hard rain can slow it down. And everyone in your area shares the same satellites, so speeds sag in the evening when the neighbors are streaming too. Starlink even charges a one-time fee, from $100 up to $1,000, to new customers in areas it considers crowded. ## What Amazon has and hasn't said Amazon says service starts later this year in two bands of the globe, one in the northern hemisphere and one in the southern, expanding outward from there. The United States is on its list of first countries, along with Canada, the UK, France, and Germany. Amazon has shown off three dishes: a small portable one rated for 100 megabits per second, a home model rated for 400, and a business model rated for a gigabit. ![Amazon's three Leo dishes side by side: the small Nano, the mid-size Pro, and the large Ultra.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-leo-terminals.jpg) Amazon's three Leo terminals: Nano, Pro, and Ultra. (Image: Amazon) Amazon has not announced a monthly price. It has not announced what the dish will cost you. It has not committed to a date when someone in the US can actually sign up. The closest thing to a price is Amazon saying the home dish costs less than $400 to produce, which is what it costs Amazon, not what it will cost you. Amazon's CEO wrote to shareholders in April that Leo's performance would come "at a lower cost than alternatives." That's an aim, not a number. Any dollar figure you see attached to Leo right now is somebody's guess. One number stuck out to me. Amazon's own paperwork with the FCC says service begins once 578 satellites are up. It has 396\. Amazon says 396 is enough for the first coverage bands, and both might be true. But the company was originally required to have about 1,600 satellites flying by the end of this month, and in June the FCC agreed to let that deadline slide. The full fleet of over 3,200 is still due by mid-2029\. That doesn't mean Leo won't happen, but "later this year" is a goal Amazon is chasing, not a firm release date. The track record backs up some patience here. Amazon originally hoped to have customers online in 2024\. Then 2025\. Then mid-2026\. Now "later this year." The delays mostly come down to rockets. Amazon doesn't own a fleet of proven rockets the way SpaceX does. Amazon pays other companies to launch its satellites, and the new rockets those companies were building all ran years behind schedule. One of them failed a ground test in May, right before it was supposed to carry the next batch of Leo satellites. Amazon has even bought launches from SpaceX, its direct competitor, to keep the schedule moving. That tells us how tight the rocket supply is. ## What your options look like today While Leo stays a promise, here's the field as it stands in mid-2026. **Fixed wireless first, if you can get it.** T-Mobile and Verizon both sell home internet that runs over their cell networks, starting around $35 to $50 a month with no contract and no equipment to buy. When it's available and the signal is decent, it's the cheapest way out of bad internet, no dish required. The catch is the word "available." It depends entirely on the cell coverage at your address, and rural coverage maps get optimistic. Both companies let you check your address on their websites, and both offer trial periods. Start there. **Starlink is the one with a track record.** The dish runs $349 to $499 depending on model and promotions, and plans run roughly $50 to $120 a month depending on speed tier. Independent testing firm Ookla measured US Starlink customers at a median of about 134 megabits per second down in late 2025, which is fast enough for a household of streamers. The delay is low enough for video calls and gaming as well. It's month-to-month with no contract and a 30-day return window on the hardware. Starlink is owned by SpaceX, which is Elon Musk's company. However you feel about that, it's the only low-orbit service you can buy today, and the only one with years of measured results behind it. **The old guard is still selling.** HughesNet and Viasat both still offer the 22,000-mile kind, with the delay that comes with it. Independent testing puts their measured speeds far below Starlink's. Viasat's main plan is month-to-month. HughesNet wants a 24-month contract, and I'd think hard before signing one. Committing to two years of the old technology right as a second low-orbit competitor arrives is a bad trade unless it's genuinely the only thing that reaches you. And if your internet in town is merely disappointing rather than rural-bad, the problem may be inside the house rather than on the pole. [Rebooting your router](https://www.freshfromcache.com/why-does-rebooting-your-router-work/) fixes more than it has any right to. ## So should you wait? I don't have a satellite dish and I'm not in the market for one, so I have no horse in this race. But if I lived at the end of a gravel road, here's how I'd frame the decision. Nothing about Leo can be bought today. There's no price, no signup page, and a schedule that has slipped three times. Waiting for it means living with your current internet for some number of months nobody can name, in exchange for a service nobody has priced. That trade only makes sense if your current internet is tolerable. On the other side, the switching cost is low. Starlink has no contract. Fixed wireless has no contract. If you solve your internet problem now and Leo shows up next year cheaper and better, you cancel and switch. The main thing you'd be out is the dish money. A few steps you can take: - **Check your address** for [T-Mobile](https://www.t-mobile.com/home-internet?ref=freshfromcache.com) and [Verizon](https://www.verizon.com/home/internet/?ref=freshfromcache.com) home internet before considering any dish. It's the cheapest option when it exists. - **Avoid new long contracts.** Month-to-month keeps you free to jump when the field changes, and the field is about to change. - **Join the waitlist.** Amazon's [Leo waitlist](https://leo.amazon.com/?ref=freshfromcache.com) is free and commits you to nothing. Being on it costs you nothing if the service slips again. - **Watch for two numbers:** a monthly price and a US start date. Until both exist, Leo is a plan, not an option. Whatever happens with Amazon's schedule, a second company racing to sell rural America internet gives the first one a reason to keep its prices in check. You may never buy a thing from Amazon Leo and still come out ahead for it existing. Rural internet has been a one-option market for a long time. It's about to be a two-option market, and that helps you either way. Do you use Starlink, fixed wireless, or one of the older satellite services? I'd like to hear how it's working for you. Email me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). --- **Source:** [GeekWire on the July 2 launch and what it means for initial service](https://www.geekwire.com/2026/amazon-leo-atlas-ula-launch-satellites/?ref=freshfromcache.com) (July 2, 2026) **Source:** [CNBC on the 396-satellite total and the service timeline](https://www.cnbc.com/2026/07/02/amazon-has-deployed-enough-satellites-to-launch-leo-service-this-year.html?ref=freshfromcache.com) (July 2, 2026) **Source:** [The FCC's order waiving the July 2026 deployment deadline](https://docs.fcc.gov/public/attachments/DA-26-553A1.pdf?ref=freshfromcache.com) (June 5, 2026) **Source:** [GeekWire on the FCC waiver](https://www.geekwire.com/2026/fcc-gives-amazon-leo-more-leeway-on-its-satellite-deployment-schedule/?ref=freshfromcache.com) (June 8, 2026) **Source:** [SpaceNews on the Leo terminals and undisclosed pricing](https://spacenews.com/amazon-unveils-production-ready-gigabit-class-leo-ultra-broadband-terminal/?ref=freshfromcache.com) (November 24, 2025) **Source:** [Fierce Network on Ookla's Starlink speed measurements](https://www.fierce-network.com/broadband/starlink-broadband-speeds-increase-2025-theyre-still-not-great?ref=freshfromcache.com) (April 2026) ### Most teen safety features don't work. Here's what does. URL: https://www.freshfromcache.com/teen-safety-features-that-work/ Last updated: 2026-08-11T18:28:32.000Z If you set up a "teen account" for your kid, flipped on a couple of safety settings, and figured you'd handled it, this article is going to sting a little. A team of researchers spent seven months testing 86 safety features these apps advertise, across TikTok, Instagram, Snapchat, and YouTube. Only 35 both worked the way the company claimed and were easy enough for a regular person to find and use. ![Scoreboard: only 35 of 86 tested teen-safety features worked. Snapchat failed 73 percent, Instagram 66 percent, YouTube 55 percent, TikTok 50 percent.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/ffc-teen-safety-scoreboard.png) How the four platforms scored in the June 2026 audit. That number made headlines, but a smaller finding is worse. On a test account set up as a minor, after it searched a few things about eating disorders and self-harm, TikTok stopped blocking those searches and started suggesting them. The terms it served to that child's account included tips for hiding food and phrases about self-harm. The researchers didn't go looking for those. The app recommended them. So before you trust the parental control switches, it helps to know which ones actually do something. ## Who ran it, and who paid for it The report is called "Broken, Buried, or Missing." It came out June 29 from the Cybersafety Research Center, a joint project of NYU and Northeastern. The team behind it has real credentials: it includes Arturo Béjar, the former Meta engineer who testified to Congress in 2023 about the harm teens were facing on Instagram, and Laura Edelson, a Northeastern researcher who has spent years auditing how big platforms actually work. Two things about the study belong up front. It was produced with support from the Heat Initiative, an advocacy group that campaigns against these companies, and it has not been through peer review. The platforms also make a fair point in response: the test deliberately left out the parental controls that parents set up themselves. Additionally, some of the failures came from researchers actively trying to break a protection rather than from ordinary use. Both of those are true, but neither one explains away the core finding. The worst failures happened during normal use. A kid searching didn't have to try anything clever to get TikTok to suggest self-harm terms. Misspelling "eating disorder" by one letter got past Instagram's filter. The anti-bullying prompt that is supposed to ask a user to reconsider a cruel comment never once fired. ## How they tested The method was straightforward. Real test accounts, some set up as kids aged 13 to 17, some as adults. Three situations: a child using the app normally, a teen trying to get around a restriction on their own account, and an adult trying to get around the protections on a child's account. A feature counted as a pass only if it did what the company said AND a regular person could actually find it and turn it on. Everything else got sorted into broken, buried (real, but hidden), or missing (couldn't get it to work at all). By that bar, Instagram passed 10 of 29\. Snapchat passed 3 of 11\. YouTube passed 10 of 22\. TikTok passed the most, 12 of 24. ## What actually works There is a useful pattern under all of it. The protections that held up almost all fall into two groups: the ones that are ON by default, and the ones that take the risky thing away entirely for younger kids. The switches you have to hunt for and flip yourself are the ones that mostly failed. So, the ones to rely on. Same thing at a glance, then the details underneath. **Instagram** passed 10 of 29 **Turn on** Private by default, no Live, block / mute / restrict, and adults can't message your teen first. **Skip** Anti-bullying prompts and word filters. Note: if your teen messages an adult first, that opens the door back up. **Snapchat** passed 3 of 11 **Turn on** Blocking, and location sharing off. **Skip** Screen-time limits (it has none) and the stranger-contact protections. This is the app with the highest stranger risk. **TikTok** passed 12 of 24 **Turn on** For kids under 13, the “Younger Users” mode. For teens, the account-level controls. **Skip** The self-harm and eating-disorder search filter. **YouTube** passed 10 of 22 **Turn on** Autoplay off, no save-to-watch-later, sign-in for age-restricted content, and YouTube Kids for younger kids. **Skip** The in-app screen-time reminder. **Instagram.** Teen accounts are private by default, and that default held. Your teen can't go live. Blocking, muting, and restricting an account all work. Adults can't start a conversation with a teen who doesn't follow them. One honest catch on that last one: if your teen messages an adult first, the adult can message back with no restriction, even with no follow between them. So the "adults can't contact my kid" protection has a door in it that your kid can open. **Snapchat.** Blocking works, and [turning off location sharing](https://www.freshfromcache.com/what-location-sharing-actually-shares/) (so your kid isn't broadcasting where they are on the map) works. That is most of the good news. Snapchat had no working screen-time feature at all. This is the app where researchers, from a plain adult account, found a child's account and messaged it with nothing in the way. The stranger-contact protections it advertises did not hold up. Treat Snapchat as the app where that risk is highest. **TikTok.** For kids under 13, "TikTok for Younger Users" is the single strongest protection in the whole report. It strips the app down to a view-only, curated mode. No open search, no direct messages, no endless algorithmic feed, and a one-hour daily limit that is actually enforced. If you have a younger child on TikTok, that mode is the mode to use. For teenagers, TikTok's account-level controls (private account, who can message, who can duet) work reasonably well. Its search filter, the one that is supposed to block self-harm and eating-disorder content, does not. Don't count on it. **YouTube.** For younger kids, YouTube Kids is the separate, stripped-down app, same idea as TikTok's under-13 mode. On regular YouTube, three settings genuinely work and are worth turning on: turn off autoplay so one video doesn't roll into six hours, the setting that stops kids saving videos to watch later, and forcing sign-in for age-restricted content. Its in-app screen-time reminder, though, is one tap to dismiss. ## What you can skip These are the ones you can stop trusting, because the report found them broken, hidden, or missing across the board. The in-app search filters for self-harm and eating-disorder content. Bypassable in under three minutes on every platform, and on TikTok worse than useless. The in-app screen-time reminders. Every one of them can be tapped away. YouTube's even links straight to the off switch. The anti-bullying "are you sure you want to post this" prompts. They didn't fire. Word and comment filters. Swapping a few letters for numbers walked right past them. Looking through these settings is still time well spent. Turn on the ones that work. Just don't mistake having flipped a switch for having covered the risk. One caveat on all of this. These are the results as of June 2026, and platforms change their settings. A switch that failed the test could be fixed later, and one that passed could change. Re-check the ones that matter to you every few months. ## The controls that don't live in the apps The stronger layer isn't inside these apps. It is on the phone and in the house. Set the screen-time limit at the device level, not in the app. Apple's Screen Time (through Family Sharing) and Google's Family Link let you set a limit the kid can't just tap away, which the in-app timers can't do. The platforms said as much in their own defense. Two honest limits: independent testers in Germany found kids getting around Apple's limits through an accessibility feature, and Family Link's controls only have teeth for kids under 13\. At 13, Google hands much of that control back. So these help, but nothing here is a lock. The American Academy of Pediatrics points parents to a written family media plan and house rules that don't depend on application controls: no phones in bedrooms overnight, charge devices somewhere other than the nightstand, screens off at meals. Common Sense Media says much the same, adds turning on SafeSearch, and suggests [monitoring apps like Bark or Qustodio](https://www.freshfromcache.com/is-my-kids-school-laptop-monitored/) for older teens, used openly with your kid rather than behind their back. The through-line is that the conversation does more work than the controls. ## Looking forward The ground under all of this is moving. This spring, juries in New Mexico and California found Meta, and in the California case YouTube too, liable for building products that harm young users. Meta is appealing. The UK announced a ban on under-16s using most social media, and here in the US the House just passed a kids-online-safety bill. The impulse behind a ban is easy to understand. If the tools don't work, keep the kids off the platforms. But I don't think a ban is the tool that gets us there. The technology to check every user's age at scale doesn't really exist yet, and the only way to attempt it ends with everyone, adults included, handing a platform their face or their ID. I wrote about that when the UK ban was announced, over in [how the UK plans to keep teens off social media](https://www.freshfromcache.com/prove-your-age/). The approach this report found actually works points in a better direction: make the safe setting the default, give younger kids the stripped-down mode, and put real controls in parents' hands. Those are the things you can act on today, without waiting for a law or scanning anyone's ID. One qualifier about these studies. A feature "working" in this test means it does what it claims, not that it makes your kid safe. Private-by-default is good, but it's not an online force field. And none of this is an argument to yank the apps out of your teenager's hands. It is a smaller, more useful thing. Learn which settings you can lean on, and which ones are for show. Then put your weight where no software update can undo it: the controls on the device, and the conversations at home. If you have set these up and hit one that didn't do what it promised, I would like to hear about it. joel@freshfromcache.com. **The report:** [Broken, Buried, or Missing](https://cybersafetyresearch.org/broken%5Fburied%5Fmissing.pdf?ref=freshfromcache.com) (PDF), Cybersafety Research Center (NYU and Northeastern), June 29, 2026. **Source:** [Most social media child safety features fail, research finds](https://news.northeastern.edu/2026/06/29/social-media-safety-child-research/?ref=freshfromcache.com), Northeastern Global News, June 29, 2026. ### You bought it, but do you own it? URL: https://www.freshfromcache.com/do-you-own-what-you-buy/ Last updated: 2026-08-11T18:29:00.000Z Sony is getting out of the disc business. On July 1, the company said it will stop making physical discs for new PlayStation games starting in January 2028\. After that, a new PlayStation game comes one way: as a download. Games already on shelves are fine, and anything released before 2028 keeps its disc. New games go digital only. The reaction has been loud, and it should sound familiar. Back in 2013, Microsoft tried something like this with the Xbox One, with always-online check-ins and limits on trading used games. Players revolted, and Microsoft reversed course within weeks. That was a different moment in time. Discs were still how most people bought games. Today about 85 percent of PlayStation game sales are already downloads, so the pushback may not move Sony the way it moved Microsoft. While the death of physical game discs has made headlines, Sony recently made another move that flew under the radar. In late June, Sony told PlayStation owners in the UK and Europe that 551 movies and TV shows they had already paid for would be removed from their libraries on September 1\. StudioCanal titles, including Terminator 2, Total Recall, and the Bridget Jones films. The licensing deal that let Sony sell them ran out, so the movies disappear. No refund. (Accounts in the United States are not part of this removal, but the terms that allow it apply here too.) Both stories come down to the same thing. When you click Buy on a movie, a book, a song, or a game, you are usually not buying the media itself. You are buying a license to use it. That has been true for a long time. What's changed is the format. A DVD or a paperback sat on your shelf. Once you had it, no one could reach into your house and take it back. A license attached to a download is different. The company that sold it to you can change it, move it, or remove it. The movie in your library is only there as long as the company's paperwork holds up. Sony's StudioCanal customers just found that out the hard way. ## Terms and conditions This is not hidden. It is written into the terms you agreed to when you set up the account. Amazon says it plainly: "Kindle Content is licensed, not sold, to you." Apple uses nearly the same words for the App Store, and Steam tells you outright that the games you buy are licensed, not sold. We have seen this before. In 2009, Amazon reached into Kindles and deleted copies of a book people had already bought. The book was George Orwell's 1984\. A publisher had sold it through the Kindle store without holding the US rights, so Amazon pulled it back from every device that had it, without warning. The irony wrote itself, and the backlash was bad enough that Amazon's CEO called the move "stupid, thoughtless, and painfully out of line with our principles." Buyers were refunded, and Amazon promised not to do it that way again. In 2019, Microsoft closed its ebook store. Every book people had bought there stopped working once the store's copy-protection servers went dark. Microsoft refunded everyone in full, which was the right thing to do, but far from a happy ending. People got their money and lost their libraries. Years of notes and highlights vanished with the books. ## Too much power Licenses expire. Sometimes a studio pulls its catalog and the store selling it has no real choice. It makes sense that a title leaves a storefront when the deal behind it runs out. But as more of what we buy shifts to digital, we need protections that let people keep the access they paid for, the kind a company cannot revoke later. Right now there are none. Big companies, the kind built to put profit first, end up holding the switch on what you get to watch and read. They already have plenty of that power in publishing. This hands them more. It is the same idea behind the [TV that moonlights for its maker](https://www.freshfromcache.com/tv-side-hustle/), pointed now at your movie library instead of your living room. ## The law is not settled California passed a law, in effect since January 2025, aimed straight at the Buy button. If a store sells you digital goods, it can no longer use the word "buy" to suggest you own something outright. It must be made clear that you are getting a license that can be taken away. Some stores changed their checkout wording because of it. Steam added a line at checkout months before the law even took effect. The courts have gone the other way on a related question: can you resell the digital things you bought? You can sell a used paperback or a used DVD. That right, called first sale, is why used bookstores exist. When a company tried to build a marketplace for reselling iTunes songs, US courts shut it down, ruling that moving a digital file makes a copy, and copying is the seller's right, not yours. ![Crowded shelves of used fantasy paperbacks in a secondhand bookstore](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/books_web.jpg) First sale is why used bookstores exist: it covers the paperback you bought, but not the identical ebook. Europe's top court reached the same conclusion for ebooks. So the used paperback is legal to resell, and the identical ebook is not. Those cases keep circling the same reality. You can't resell it, you can't lend it, and you can't keep it when the seller changes its mind. All you ever bought was access. ## People are pushing back When Ubisoft switched off the servers for a racing game called The Crew in 2024, the game became unplayable, even for people who had bought it on a disc. Players did not let it go. A campaign called [Stop Killing Games](https://www.stopkillinggames.com/?ref=freshfromcache.com) organized around a simple idea: if you sold it to me, you should not be able to switch it off and [leave me with nothing](https://www.freshfromcache.com/router-expiration-date/). It grew into a formal petition that more than a million Europeans signed. It was enough to force the European Commission to respond. In June 2026, the Commission declined to make a new law, saying copyright rules tied its hands. A similar bill in California failed too. But a million people don't sign a petition over nothing, and the campaign isn't done. It's already pushing for the same protections in a new European consumer law being written now. ## Where to actually keep what you buy If you want to own some of what you pay for, a few stores are built for that. The names to know: - **Games:** [GOG](https://www.gog.com/?ref=freshfromcache.com) and [itch.io](https://itch.io/?ref=freshfromcache.com) sell games as plain installers you download and keep. No app has to be running and no server has to stay online. Buy it, save the installer, and it is yours. - **Music:** [Bandcamp](https://bandcamp.com/?ref=freshfromcache.com) and [Qobuz](https://www.qobuz.com/?ref=freshfromcache.com) sell songs and albums as normal files with no copy protection. They play on anything and do not vanish if the store does. Apple's music has also been sold without copy protection since 2009, though that covers music only. Movies, TV, and books from Apple still carry the lock. - **Audiobooks:** [Libro.fm](https://libro.fm/?ref=freshfromcache.com) sells audiobooks as DRM-free downloads and supports local bookstores. - **Books:** [Smashwords](https://www.smashwords.com/?ref=freshfromcache.com) and [Standard Ebooks](https://standardebooks.org/?ref=freshfromcache.com) sell books with no lock on them, so the file opens on any device and backs up like any other file. Some publishers, including Tor, sell their ebooks DRM-free no matter where you buy them. - **Movies and TV:** this is the hard one. There is no mainstream way to buy a movie as a file you fully own. The closest thing is still a disc on the shelf. Where a store lets you download a real file, download it and [back it up](https://www.freshfromcache.com/do-you-need-backups/) like anything else you would hate to lose. ## Personal choice Renting your media isn't inherently bad. I buy plenty of things digitally because the convenience is worth the risk for the everyday stuff. My problem is that these companies dress up a long-term rental as a purchase. If there is a movie, an album, or a game you can't stand the thought of losing, buy the physical disc while you still can. Everything else is just a long-term rental. Now I want to hear from you. Do you think about any of this when you hit Buy, or is the convenience worth it and you move on? Have you started buying discs again? Email me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com) and tell me how you handle your own digital shelf. ## Sources - **The news:** [PlayStation.Blog on ending disc production](https://blog.playstation.com/2026/07/01/physical-disc-production-ending-in-january-2028-for-new-games-releasing-on-playstation-consoles/?ref=freshfromcache.com) (July 1, 2026); [Game Informer on the StudioCanal removals](https://gameinformer.com/2026/06/29/playstation-will-remove-hundreds-of-purchased-movies-and-tv-shows-from-user-libraries-in?ref=freshfromcache.com) (551 titles, September 1, 2026). - **Earlier removals:** [CBS News on Amazon deleting Orwell's 1984](https://www.cbsnews.com/news/amazon-sued-for-kindle-deletion-of-orwell/?ref=freshfromcache.com) (2009); [Forbes on Microsoft closing its ebook store](https://www.forbes.com/sites/adamrowe1/2019/06/27/the-books-will-stop-working-how-the-microsoft-store-is-retiring-its-books-category/?ref=freshfromcache.com) (2019). - **The fine print:** [Amazon Kindle Store Terms of Use](https://www.amazon.com/gp/help/customer/display.html?nodeId=201014950&ref=freshfromcache.com); [Apple Media Services Terms](https://www.apple.com/legal/internet-services/itunes/ww/?ref=freshfromcache.com); [Steam Subscriber Agreement](https://store.steampowered.com/subscriber%5Fagreement/?ref=freshfromcache.com). - **The law:** [California AB 2426](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill%5Fid=202320240AB2426&ref=freshfromcache.com); [Capitol Records v. ReDigi](https://law.justia.com/cases/federal/appellate-courts/ca2/16-2321/16-2321-2018-12-12.html?ref=freshfromcache.com) (2018); [Tom Kabinet](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A62018CJ0263&ref=freshfromcache.com) (EU, 2019). - **Pushing back:** [Stop Killing Games](https://www.stopkillinggames.com/?ref=freshfromcache.com); the [European Citizens' Initiative](https://citizens-initiative.europa.eu/initiatives/details/2024/000007%5Fen?ref=freshfromcache.com). ### Can OpenAI Be Held Responsible When ChatGPT Is Blamed for a Death? URL: https://www.freshfromcache.com/ai-accountability/ Last updated: 2026-08-11T18:29:11.000Z For months before he died, a 56-year-old former tech worker named Stein-Erik Soelberg posted videos of his conversations with ChatGPT. He had given it a name, Bobby, and called it his best friend. He was living with his 83-year-old mother in Connecticut, and somewhere in those months he came to believe he was being watched. He thought the household printer was a surveillance device. He uploaded a takeout receipt and asked the chatbot to scan it for hidden messages, and it told him it had found symbols tied to his mother. He believed she was trying to poison him. The chatbot agreed she might be. In August 2025, both of them were dead, in what police ruled a killing followed by a suicide. That could have been the end of it, one more grim story about a man who was, by every account, severely ill long before any chatbot entered his life. It was not the end of it, because his family's lawyers did something the technology had not faced before. They sued OpenAI, the company that made the chatbot. It is reported as the first lawsuit to blame an AI chatbot for a death by violence rather than a suicide. It puts a question on the table that the industry has been outrunning for three years. If a chatbot participates in causing harm, [who, if anyone, answers for it](https://www.freshfromcache.com/what-is-an-ai-agent/)? The first instinct is to blame the chatbot. That instinct runs into a legal wall almost immediately. No court treats a chatbot as a person who can be held to account. It has no intent the law recognizes, no assets, no standing as an actor that can be sued. Blaming the machine sounds satisfying, but leads nowhere. So the culpability question moves to the only party left standing, the company that designed the product and sold access to it. That's where things get murky. ## Cause does not mean blame A lot of the noise around AI harm comes from combining two ideas that the law keeps separate. One is causation, whether a thing played a role in an outcome. The other is culpability, whether someone is to blame for it. A drunk driver causes a crash and is to blame. A road that ices over also causes the crash and is not blamed legally. If we hold that distinction up to the Soelberg case, the lawsuit looks different than the headlines make it sound. A person committed the crime. That part is not in dispute and the suit does not pretend otherwise. The case is not really asking who did it. It is asking a product question. Did the product fail? Did it do something it should not have done, or fail to do something it should have? That is a narrower question than "is AI dangerous," and it is the one a court will rule on. ## Is a chatbot a product or a service? American product law mostly turns on a single fork. If a chatbot counts as a product, the maker can be held strictly liable. That would mean a plaintiff has to show the product was unreasonably dangerous as designed, but not that the company was careless. ![A chatbot prompt box on a dark screen reading Ask anything.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/product.jpg) The thing on trial. Is a chatbot a product, or a service that happens to talk? If it counts as a service, the bar is higher, and a plaintiff has to prove the company was negligent. The company argues it sells a service. The families argue it sells a product. In a separate case last year, a federal judge sided with the families at an early stage, ruling that a chatbot could be treated as a product and letting the lawsuit go forward. That was a preliminary ruling, not a final answer, and the case settled before any trial could test it. Nothing here is settled law yet. There is a useful comparison in tools people already use. A person can write a virus in Notepad, and no one sues Microsoft. A criminal can host malware on a rented cloud server, and no one sues the company that owns the servers. The reason that thinking holds is that those tools carry whatever a user puts into them. A blank page does what a person makes it do, and the law has an answer to that. Section 230 shields a service for what other people say or do through it. A chatbot strains that rule, because it writes the words itself. The output is not a user's post that the company merely passed along. The model produced it. That is why these lawsuits mostly skip the Section 230 argument that has protected platforms for decades. What is on trial is what the product generated, not what a user uploaded. Whether a tool that authors its own replies still belongs in the same bucket as Notepad is, again, unsettled. It is one of the most important open questions in the whole fight. ## Why this case has legs A blank page doesn't tell a person they are right. A chatbot does, and it is [notoriously good at it](https://www.freshfromcache.com/friendly-ai-is-less-accurate/). Chatbots turn ordinary language into something that reads like a thoughtful reply, which makes the output feel human. People fall for that with almost no resistance. We name our cars and say thank you to vending machines. ![A person in a dark room, face lit by the phone in their hands.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/syco.jpg) A machine that answers like a person tends to get believed like one. A machine that answers in warm, fluent sentences gets trusted far past what it has earned. The lawsuits argue that the trust is by design. They claim the chatbot was tuned to agree, to validate, and to keep the user talking. That this eagerness to please, sometimes called sycophancy, is the defect itself. This is not a fringe theory invented for the courtroom. OpenAI pulled an update to its model in 2025 after even ordinary users complained it had become too agreeable to be useful. So the behavior at the center of the case was a known property of the product, not a rare malfunction only an expert could summon. The "it acts like a person" argument is a double-edged sword, though. Lean all the way into the idea that the chatbot is a real actor, and the blame starts sliding back onto the chatbot, which cannot be a defendant. The more the machine is treated as if it has agency, the weaker the case against the humans who built it. So the stronger form of the claim points at OpenAI, not at the chatbot. It says the company built a product that behaves this way and released it anyway. ## Did it lead him, or did he steer it? Here the public record gets murky, and any honest account has to say so. Some of what the chatbot did looks like it was coaxed. A knowledgeable user can push these systems into a looser persona that drops some of its guardrails, and it appears he did exactly that to get "Bobby." ![A person's face half-lit by a bright screen in the dark.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/murky.jpg) How much he drew out, and how much it offered on its own, is what a trial has to sort. Some of what it did looks unprompted. It did more than agree with him; it escalated. It assured him his risk of delusion was near zero. It treated his suspicions as credible findings. By the account in the complaint, it never once told him to see a doctor or talk to another human being. How much of that he engineered and how much the product offered on its own is the exact thing a trial is built to determine, and most of the evidence is not public yet. It lives in chat logs OpenAI has so far declined to release. ## The underlying question In product law a company is not on the hook for every bad thing that happens near its product. It can be on the hook when a harm was foreseeable and there was a reasonable step it skipped. So the case may come down to what the company knew. The families allege it had internal warning that the model leaned dangerously agreeable. The family also alleges that OpenAI released the product with this knowledge anyway, in order to stay ahead of its competitors. If that holds up, the story changes from "a tragedy happened to involve our product" toward "the risk was on the table and the product released regardless." If it does not hold up, OpenAI can make the opposite case, that a severely ill man misused a general-purpose tool in a way no one could reasonably have predicted. Which of those the evidence supports is not yet public. ## First of its kind A widely covered earlier case involved a teenager who died by his own hand, which keeps the tragedy inside one person's own choices. The Soelberg case resists that framing completely. The woman who died never typed a word into the chatbot. She never agreed to its terms. She had no idea it existed in the way her son was using it. Whatever the product did, it did without her consent and at her cost. Did the chatbot tell him to kill her? By everything public, no. There is no report of an instruction or a plan. What it appears to have done is feed a delusion that ended with a person who had nothing to do with the technology dead in her own home. Is feeding that delusion OpenAI's failure, or the man's alone? That is a real question, and it sits over the heads of almost everyone weighing in, working from videos a sick man chose to post and a complaint written by lawyers paid to win. Sorting it is a job for a court, which is exactly the point, and it is why this case matters well past the single household it ended. ## Money and control Step back from the verdict and there are two separate questions tangled together in these suits. One is money, whether OpenAI should compensate a family harmed in connection with its product. The other is control, whether a court should order the company to redesign how the product works for everyone else. ![The empty wooden interior of a courtroom.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/court.jpg) Two asks sit inside these suits: money for one family, and design changes for everyone. They are different levers. Those levers do not have to move together. A company can write a check for a specific failure without the tool being rebuilt for the entire public. In a parallel set of cases involving a different chatbot maker, that is close to what happened. The company settled, paid, admitted nothing, and set no rule binding the rest of the industry. There is also a reason to be careful about reaching for the heaviest tools first. The same kind of chatbot that failed this family is, for a lot of other people, useful, and sometimes more than useful. Controlled studies of purpose-built chatbots have found real reductions in depression and anxiety, with users saying they felt heard. The harms are vivid, and they get counted, because they end up in court. The benefits are spread thin across millions of ordinary conversations and almost never counted at all. Weighing a measured harm against an unmeasured good is difficult, but it's at the heart of the problem. ## Not a verdict This isn't meant to tell a reader what to conclude. The law has not decided. The facts are not all in. The technology is new enough that the old rules do not fit it cleanly and the new ones have not been written. The reasonable posture this early is to distrust anyone who sounds certain in either direction. The Soelberg case will decide something narrower than the headlines suggest: whether a company that builds a machine to sound human owes a duty to the people it talks to, and to the people standing near them who never chose to use it. That question is now in front of the courts, and the answer will shape every case behind it. --- **Sources:** - [CBS News, "OpenAI, Microsoft sued over ChatGPT’s alleged role in Connecticut murder-suicide" (December 2025)](https://www.cbsnews.com/news/open-ai-microsoft-sued-chatgpt-murder-suicide-connecticut/?ref=freshfromcache.com) - [OpenAI, "Sycophancy in GPT-4o: what happened and what we’re doing about it" (April 2025)](https://openai.com/index/sycophancy-in-gpt-4o/?ref=freshfromcache.com) - [Courthouse News Service, "Florida judge rules AI chatbots not protected by First Amendment" (May 2025)](https://www.courthousenews.com/florida-judge-rules-ai-chatbots-not-protected-by-first-amendment/?ref=freshfromcache.com) - [TechCrunch, "Google and Character.AI negotiate first major settlements in teen chatbot death cases" (January 2026)](https://techcrunch.com/2026/01/07/google-and-character-ai-negotiate-first-major-settlements-in-teen-chatbot-death-cases/?ref=freshfromcache.com) - [Dartmouth, "First Therapy Chatbot Trial Yields Mental Health Benefits" (March 2025)](https://home.dartmouth.edu/news/2025/03/first-therapy-chatbot-trial-yields-mental-health-benefits?ref=freshfromcache.com) ### Your computer probably isn't dying URL: https://www.freshfromcache.com/newsletter/your-computer-isnt-dying/ Last updated: 2026-07-07T14:59:59.000Z Good news up top: if your computer feels slow, it is probably not dying. This week I wrote up how to find what is actually dragging it down, before you spend a cent. The rest of the issue is a reminder that the tech you already trust can end up working for someone else. Microsoft pulled 119 Edge add-ons that spent years being helpful, then started stealing logins. Your browser leaves its best protections turned down by default. Learn how to turn them on. Down in the Scary Headline of the week, the FBI found two million home devices moonlighting for criminals. --- [**Your computer feels slow. Here's what to do.**](https://www.freshfromcache.com/why-is-my-computer-slow/) The complaint "my computer is slow" doesn't always mean you need a new computer. Usually it is one hungry program, the internet, or years of clutter, not the machine giving out. I walk through how to find the real culprit before you spend a dime, and the one time a cheap part might be the answer. *Learn* --- [**Microsoft pulls Edge extensions due to malware**](https://www.freshfromcache.com/microsoft-pulls-edge-extensions-due-to-malware/) Microsoft removed 119 Edge add-ons that worked fine for years, then turned on the people using them and started stealing Google logins and two-factor codes. A store listing and a star rating aren't safety checks. Worth two minutes to look at what you have installed and clear out what you no longer use. *News* --- [**You can finally hide your phone number on WhatsApp**](https://www.freshfromcache.com/whatsapp-usernames/) WhatsApp is rolling out usernames, so your phone number stops being the thing every new contact needs to reach you. You can reserve yours now; the feature turns on later this year. A small privacy win, and a rare one. *News* --- [**Google is changing how Android apps get installed.**](https://www.freshfromcache.com/google-android-app-verification/) A countdown clock going around online says your phone is about to be locked down. What is really happening: later this year, an app installs on most Android phones only if whoever built it has verified their identity with Google, sideloaded apps included. A real shift, but for most people the alarm is overblown. *News* --- [**How Much Water Does AI Really Use?**](https://www.freshfromcache.com/how-much-water-does-ai-really-use/) You have probably seen the line that every AI prompt drinks a bottle of water. The real number is smaller, and the real story is where and when the water gets pulled, which is local and concentrated. This article attempts to make sense of the numbers. *Blog* --- If you only read one: the Edge extensions. It is the story with real stakes this week, and the two-minute check applies whether you use Edge or Chrome. --- **5-Minute Tech Tip** Turn on your browser's strongest privacy and anti-scam settings. Chrome and Edge both leave their best protections turned down by default. A five-minute pass switches on tracker blocking and the built-in warning that flags scam and malware sites before they load. No VPN, nothing to buy, no account. Screenshots for both browsers here: [Your browser can block trackers and scam sites](https://www.freshfromcache.com/chrome-edge-privacy-settings/). --- **Scary Headline of the Week** *"Hackers hijacked 2 million home devices, and yours might be one."* Half true, which is what makes it scary. This week the FBI and Google took down NetNut, a network that had turned around 2 million home gadgets into hired help for criminals and even a few nation-state spies. The catch: they were not after your photos or passwords. They borrowed your internet connection and ran other people's traffic through it, so a scammer's activity looked like it came from an ordinary house. Almost all of it was cheap, off-brand [smart TVs](https://www.freshfromcache.com/tv-side-hustle/) and streaming boxes. These were sold with the malware already inside or infected later by a free app (knockoff YouTube-for-TV apps were a favorite). A name-brand TV you let update is a poor target. The $19 streaming stick from a marketplace you have never heard of is the one to worry about. Let your phone and TV take their updates, skip the no-name boxes, and be suspicious of any app that offers to pay you for "sharing your internet." That is the front door. Verdict: real, and maybe your bargain streaming stick, but not your data. --- Fresh From Cache grows when readers pass it along. If you enjoyed this issue, forward it to someone who might too. --- Could you figure out what was making your computer slow? Hit reply and let me know. Joel ### Freeze your credit before someone else uses it URL: https://www.freshfromcache.com/freeze-your-credit/ Last updated: 2026-08-11T18:28:45.000Z Every day there is some breach and emails go out warning users or customers that their personal details have been stolen. It even happened with [Equifax](https://www.ftc.gov/enforcement/refunds/equifax-data-breach-settlement?ref=freshfromcache.com). After you've been notified you've been part of a breach, what should you do? Most people, if they do anything at all, sign up for credit monitoring. Monitoring is an alarm. It tells you, after the fact, that someone has opened an account in your name, so you can start cleaning up the mess. There is a better tool, and most people have never set it up: a credit freeze. The freeze is a lock. It stops an account from being opened at all. ## What a freeze does When anyone applies for credit in your name, a card, a car loan, a phone plan, the lender pulls your credit report first to decide whether to approve it. A freeze locks that report. While it is on, no lender can pull your file. This means no new account can be opened, by a thief or by you, until you lift it. Your existing cards keep working. The credit you already have is untouched. The door to new borrowing is simply locked until you unlock it. The strength is that the freeze blocks the lookup itself, no matter who is asking. A thief can hold every detail about you, your Social, your address, your mother's maiden name, and still hit a wall. Two limits, so you know its edges. A freeze does not touch your credit score. And it does not stop fraud on a card you already have, since spending on an existing card triggers no credit pull. Watch your statements for that. The freeze is built for one job, stopping brand-new accounts opened in your name, which happens to be the most expensive and most exhausting kind to undo. ## The catch most people trip on The companies best placed to tell you about freezes would rather sell you something else. Search "credit freeze" and you wade through ads for credit monitoring, credit "lock" apps, and identity-protection subscriptions. Often these cost a few dollars a month, sometimes far more. Some of those products are fine. None of them is a freeze. By federal law the real freeze is free, at all three bureaus. This goes for placing the freeze, and lifting it. If a page asks for your card number to "protect your identity," close it. You are on the wrong page. ## How to do it You have to freeze your file at each of the three big bureaus separately, because a lender might check any one of them. Block out fifteen minutes and do all three in one sitting. - **Equifax:** [equifax.com](https://www.equifax.com/personal/credit-report-services/credit-freeze/?ref=freshfromcache.com) - **Experian:** [experian.com](https://www.experian.com/help/credit-freeze/?ref=freshfromcache.com) - **TransUnion:** [transunion.com](https://www.transunion.com/credit-freeze?ref=freshfromcache.com) Each one makes you create an account and answer a few identity questions only you should be able to answer. Once you are in, the freeze is a switch. Each bureau gives you a PIN or ties the freeze to your login. Save those in your password manager so you can find them when you need them. ## When you actually need to borrow A freeze is not a one-way door. When you want new credit, a card, a car, internet at a new address, you "thaw" your file. Lift the freeze for a set window, say three days, or for one named lender, and it locks itself back afterward. If you know which bureau a lender uses, you can thaw just that one, though thawing all three for a day costs nothing but a couple of minutes. Plan for the extra step before a big application and you will never feel it. ## Do it for the whole household Freeze your file, your spouse's, and your kids'. Children are a favorite target precisely because nobody thinks to check a seven-year-old's credit. So the fraud can run unnoticed for a decade, until they apply for their first card and find someone got there first. A child's freeze takes a little more, usually by mail with copies of documents, but the protection is identical and the payoff is larger. If this has you thinking about [how much of your information is already loose in the world](https://www.freshfromcache.com/what-is-a-data-broker/), two other pieces of mine are worth a look: one on [the data brokers selling reports about how you drive](https://www.freshfromcache.com/your-car-grades-your-driving/), and one on [what your own photos give away about where you live](https://www.freshfromcache.com/your-photos-know-where-you-live/). The freeze does not fix those, but it does shut the most damaging door. A freeze is the strongest move you can make against identity theft, but it is not a force field. Keep half an eye on your existing accounts, and pull your free credit reports once or twice a year to confirm nothing is on there you did not put there. But if you do only one thing after reading this, freeze your credit. The trade is lopsided. Fifteen minutes now, once, or months later proving a stranger’s debt is not yours. Set yours up this week, and if a bureau's identity check trips you up, which happens, write back. Those snags are common and the workarounds are usually quick. Joel · [joel@freshfromcache.com](mailto:joel@freshfromcache.com) ## Sources - Federal Trade Commission, "Equifax Data Breach Settlement": [ftc.gov](https://www.ftc.gov/enforcement/refunds/equifax-data-breach-settlement?ref=freshfromcache.com). - Consumer Financial Protection Bureau, "What is a credit freeze or security freeze on my credit report?": [consumerfinance.gov](https://www.consumerfinance.gov/ask-cfpb/what-is-a-credit-freeze-or-security-freeze-on-my-credit-report-en-1341/?ref=freshfromcache.com). - USA.gov, "How to place or lift a security freeze on your credit report" (2025): [usa.gov](https://www.usa.gov/credit-freeze?ref=freshfromcache.com). - Federal Trade Commission, identity-theft reporting and recovery: [identitytheft.gov](https://www.identitytheft.gov/?ref=freshfromcache.com). - Economic Growth, Regulatory Relief, and Consumer Protection Act (2018), the federal law that makes security freezes free at all three bureaus. - Equifax, Experian, and TransUnion security-freeze pages (linked above). ### Windows 11's new rewind button works, but it is not a backup URL: https://www.freshfromcache.com/windows-point-in-time-restore/ Last updated: 2026-07-07T03:06:34.000Z Microsoft is adding an automatic rewind button to Windows 11\. On July 14, 2026 it reaches most people through the monthly security update. It is called Point-in-Time Restore. It takes a snapshot, a saved picture of your whole PC, about once a day. If a bad update or driver wrecks things, you can roll the machine back to yesterday in minutes. What's the catch? It only turns itself on automatically if your main drive is 200 GB or larger, and the snapshots it saves live on that same drive. If the drive dies or gets stolen, the snapshots go with it. ## What the new feature does It captures your Windows system, your installed apps, your settings, and your personal files, all together. The old System Restore, which has been in Windows for years, never touched your personal files. Point-in-Time Restore does. By default it takes a snapshot about every 24 hours and keeps each one for 72 hours, then deletes it. On Home and Pro you cannot change that timing. Business editions can. How much room does it take? Less than the early scare stories claimed. It uses a small slice of your drive, up to 2 percent, and never more than 50 GB. On a 256 GB laptop that is about 5 GB. It does not grab that space up front either. It fills it slowly as snapshots build up, and clears out the oldest ones on its own if your free space runs low. This is a convenience, not a backup. The snapshots sit on the same drive as everything else. If that drive fails, or the laptop is lost or stolen, the snapshots are gone too. It also only covers your main Windows drive, so anything you moved to a second drive is not included. And restoring wipes anything you created after the snapshot you pick, including files, saved passwords, and app data. A real backup lives somewhere else: an external drive you unplug, or a cloud service. (We've covered [what actually counts as a backup](https://www.freshfromcache.com/do-you-need-backups/) before.) ## Who gets it, and when If you run Windows 11 Home or Pro and your main drive is 200 GB or bigger, it switches on by itself. If your drive is smaller, which is common on cheaper 128 GB laptops, it stays off, and you turn it on yourself. It arrived early in an optional update on June 23, 2026, and reaches everyone in the July 14, 2026 update. Features roll out gradually, so it may take a few weeks to show up. ## What to do - **Check your free space.** Open Settings, then System, then Storage. This tells you how much room you have and roughly which drive size you own. - **See if the feature is on.** Go to Settings, then System, then Recovery, then Point-in-time restore, and click View or edit. You can turn it on or off and set how much space it uses. - **If you use BitLocker encryption, find your recovery key now** and save it somewhere safe. You cannot restore an encrypted drive without it. It is usually at account.microsoft.com/devices/recoverykey. - **Keep a real backup off the device.** An external drive you unplug, or a cloud sync like OneDrive, is what saves you when the whole drive dies. I think Point-in-Time Restore is a good addition. It fixes the most annoying kind of PC problem, the one where an update or a driver breaks a machine that was fine yesterday. But treat it as a fast undo button, not a safety deposit box. If your data only exists in one place, you do not have a backup. Point-in-Time Restore keeps your rescue copy in that one place, so keep another copy somewhere it cannot go down with the ship. ## Sources - Microsoft Learn, "Point-in-time restore for Windows," 2026\. [learn.microsoft.com](https://learn.microsoft.com/en-us/windows/configuration/point-in-time-restore?ref=freshfromcache.com) - Microsoft, "Point-in-time restore for Windows 11 is now generally available," Windows IT Pro Blog, 2026\. [techcommunity.microsoft.com](https://techcommunity.microsoft.com/blog/windows-itpro-blog/point-in-time-restore-for-windows-11-is-now-generally-available/4508101?ref=freshfromcache.com) - Bleeping Computer, "Windows 11 KB5095093 update rolls out new Point-in-Time restore feature," 2026\. [bleepingcomputer.com](https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5095093-update-rolls-out-new-point-in-time-restore-feature/?ref=freshfromcache.com) - Windows Latest, "Microsoft warns Windows 11 recovery feature uses up to 50GB of storage," 2026\. [windowslatest.com](https://www.windowslatest.com/2026/06/27/microsoft-warns-windows-11-recovery-feature-uses-up-to-50gb-of-storage-but-for-a-good-cause/?ref=freshfromcache.com) ### Google is changing how Android apps get installed. URL: https://www.freshfromcache.com/google-android-app-verification/ Last updated: 2026-07-06T13:29:59.000Z A countdown clock is going around online, and it has people rattled. It says "89 days until lockdown." It says "your phone is about to stop being yours." Here is what is happening. Starting later this year, an app will only install on most Android phones if the person who built it has registered a verified identity with Google. That includes apps you install from outside the Play Store, a process called sideloading, which never needed Google's sign-off before. It is a real change. For most people, the alarm is overblown. Verification means Google confirms who made an app before it installs. Google is not reading your apps or judging what they do. It is checking that a real, named person or company stands behind each one. A developer registers a legal name, address, email, and phone number, and sometimes a government ID. The full account costs a one-time $25. Enforcement starts September 30, and only in four countries: Brazil, Indonesia, Singapore, and Thailand. The wider rollout does not begin until 2027\. If you are in the United States, nothing on your phone changes this year, and the apps you already use keep installing the same as always. The countdown clock skips all of that. It presents the change as every app, every phone, worldwide, tomorrow, which is the version to be skeptical of. ![Screenshot of the keepandroidopen.org campaign site: a red box reading 89 days until lockdown beneath the headline your phone is about to stop being yours.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-countdown-card.jpg) The keepandroidopen.org countdown. The deadline is real; the claim of every device, worldwide, with no opt-out is the part to be skeptical of. There are two ways around the ID check. A power user can still sideload from an unverified developer through what Google calls an "advanced flow," a deliberately slow path: turn on developer mode, confirm nobody is coaching you, restart, and wait a day. A hobbyist who just wants to share an app with friends or a class can get a free account that skips the ID check, capped at 20 devices. The old tool for installing apps over a USB cable is untouched too. Google's reason is malware. Its own analysis found over 50 times as much malware coming from sideloaded apps as from the Play Store. The four countries going first are the ones hit hardest by fake banking apps and app-based scams. That is a genuine problem. Putting a name behind every app makes it harder for the same bad actor to keep rebuilding after a takedown. It is the same fraud world we covered when [police took down a major pop-up scam operation](https://www.freshfromcache.com/fake-update-scam-taken-down/). For most people in the United States, the countdown is noise. You are not losing access to your phone in three months. For your phone, this lands as a malware guardrail you will probably never notice. Where it does land is on the people who build and distribute apps. The friction lands on developers. Google would become the identity checkpoint for who is allowed to offer software to about 95 percent of the world's Android phones outside China. Most developers will register and move on. The ones raising the alarm are the ones who cannot easily pass that checkpoint. Open-source projects like F-Droid sign apps in a way that does not fit Google's one-name-per-app requirement. Independent developers may have real privacy reasons not to hand Google a government ID. There is a reason this stings for some Android users. A lot of people chose Android on purpose, to stay out of the walled garden Apple built, where the platform owner decides what you are allowed to install. This policy moves Android a step in that direction. I lean toward open myself. The more a device belongs to the person holding it, the better. ![Paper cutouts of the Apple logo and the green Android robot side by side on a kraft-paper background.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-apple-android.jpg) A lot of people chose Android to stay out of Apple's walled garden. This policy nudges it a step that direction. But I understand this change. The malware is real, the countries going first are getting hammered, and for the large majority of people the change will pass by unnoticed. Both things are true at once: it is a reasonable answer to a real problem, and it hands one company more say over the ecosystem that was supposed to be the open alternative. Google keeps holding up that "advanced flow" as proof the platform stays open. As of this summer, a coalition of more than 70 groups fighting the policy, including the Electronic Frontier Foundation and the Tor Project, says the advanced flow has not shown up in a single test build of Android. It exists as a blog post and some mockups. The escape hatch everyone is being told to trust has not been built anywhere it can be tested. If you use a typical US Android phone, nothing here is urgent. A few things still make sense: - Ignore the countdowns. Nothing changes on your US phone in 2026, so do not let a clock rush you into anything. - Keep installing from the Play Store for now. By Google's own numbers that is where the least malware is, and it is unaffected either way. - Be suspicious of anyone who phones you and talks you through installing an app, especially one from outside the store. That walk-you-through-it move is the scam this policy is built to slow down. - If you lean on F-Droid or another third-party app store, keep an eye on the 2027 rollout. That is when the real effect reaches the US. I use Android. I am not panicked, and you do not need to be either. The malware problem is real, and Google's fix will probably help. The open question is whether one company should hold the only key to that door, and whether the way around it that we have all been promised ever gets built. --- **Sources** - Google, ["A new layer of security for certified Android devices"](https://android-developers.googleblog.com/2025/08/elevating-android-security.html?ref=freshfromcache.com) (Android Developers Blog, August 2025) - Android Developers, ["Balancing openness and choice with safety"](https://android-developers.googleblog.com/2026/03/android-developer-verification.html?ref=freshfromcache.com) (March 2026) - The Hacker News, ["Google Sets Sept. 30 Deadline for Android Developer Verification"](https://thehackernews.com/2026/06/google-sets-sept-30-deadline-for.html?ref=freshfromcache.com) (June 2026) - Keep Android Open, [the campaign behind the countdown](https://keepandroidopen.org/?ref=freshfromcache.com) ### Why rebooting your router works, and when it won't URL: https://www.freshfromcache.com/why-does-rebooting-your-router-work/ Last updated: 2026-08-11T19:46:42.000Z The internet gets flaky. Pages hang. A video call freezes, then drops. So you walk over to your Wi-Fi router, pull the plug, count to ten, and plug it back in. A minute later, everything works again. We've all done it. It's the oldest trick in home tech, and most of the time it works. This is what a restart really does, whether you should still be doing it in 2026, and what to do when the router comes back up and the problem is still there. ## So why does restarting your router work? A restart isn't repairing anything. It clears out clutter and forces everything to start over from scratch. Your router is a small computer. It runs all day, every day, for weeks or months without a break. Like any computer, it keeps logs on what it's doing, and it's supposed to erase the old logs as it goes. But routers don't always erase perfectly, especially cheap ones. Picture a whiteboard the router uses for quick notes about every conversation your devices are having. Over weeks, the whiteboard fills up. There's no room to write down a new one. So new pages won't load, even though your connection promises it's fine. A restart wipes the whiteboard clean. There's another version of the same problem, and this one has a name: the connection table. Your router keeps this list of every active connection leaving your house, so it can send each reply back to the right device. The table holds a fixed number of entries. Open enough at once (a big download, a house full of gadgets, someone streaming while someone else games) and it fills up. New connections get turned away while the existing ones keep going. That's the "internet is up but nothing new loads" feeling. A restart empties the table. ## Do you even have a modem? Here's where a lot of people get stuck, and it's understandable. The gear changed and the words didn't keep up. Two jobs happen where your home meets the outside world. One device pulls the internet in from your provider. The other spreads it around your house over Wi-Fi. For years those were two separate pieces of gear, a modem and a router, and on cable internet they still often are. Fiber skips the modem entirely. Instead it uses an ONT (an optical network terminal), a small unit that does the same job: it turns the light coming down the fiber line into a signal your router can use. The ONT is often bolted to a wall in a garage, basement, or closet, so you might not even think of it as yours. And plenty of providers now go one step further and combine the modem or ONT and the router into a single gateway. One unit, both jobs, nothing separate to restart. So it depends on your setup. Cable, which still reaches far more homes than fiber, usually means a separate modem or a gateway. Fiber means an ONT. Fixed wireless and 5G home internet come as a single gateway. The router is the part almost everyone has, and the part this article is about. But when the internet is fully down, not just Wi-Fi acting up, the thing that reconnects to your provider is the modem, the ONT, or the gateway. Restarting the router alone won't touch that. When you restart that front-end device, both sides let go and reconnect from scratch. A router restart only reorganizes things inside your house. So if you restart both, start with whatever connects to your provider, wait for its lights to settle, then restart the router. And you don't need to count to thirty. A few seconds is plenty. The wait mainly gives the old connection time to fully drop, so it comes back to a clean slate instead of a half-dropped one. Mesh systems (eero, Google, Orbi, and the like) change the picture a little. They self-heal, so if one satellite drops, traffic reroutes around it and you rarely need to touch the units yourself. The exception is the main unit wired to your gateway or modem. If that one goes down, the whole network goes with it. And when a mesh network acts up, the cause is usually the same provider handoff as everything else. So the advice is simpler than it looks: restart the gateway or modem first, then the main mesh unit if you have to. The satellites can mostly take care of themselves. ![A black two-antenna D-Link router beside a white cylindrical TP-Link Deco mesh unit on a table.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/techietech-tech-6ZXP-5-jJts-unsplash.jpg) A single older router (left) and a mesh unit (right). Mesh systems spread Wi-Fi across several units and mostly manage themselves. ## Don't confuse a restart with a reset A restart and a factory reset sound like the same thing. They do very different jobs. A restart (also called a reboot, or a power cycle) turns the device off and back on. It keeps all your settings. Your Wi-Fi name and password stay exactly where they were. This is your everyday fix. A factory reset is the recessed little button you hold down with a paperclip. It wipes the router back to its factory defaults. Wi-Fi name, password, every setting you changed, gone. You'll spend time setting it all back up and reconnecting every device in the house. So save the reset for a real reason: a forgotten admin password, a setup that's genuinely tangled, or a router you think has been tampered with. For a slow connection on a Tuesday night, a plain restart is all you want. ## Should you still be doing this in 2026? Less than you used to. Newer routers have more memory and better software, and a well-built one can run for months without a hiccup. ![Close-up of a modern black Wi-Fi router with several antennas and blue status lights.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/dlxmedia-hu-43ak6tfF4Ss-unsplash.jpg) Newer routers pack more memory and better firmware, so a well-built one can run for months without a restart. A restart every month or so, as light upkeep, is fine. It's one less thing to think about. Setting your router to restart itself every single night is a different story. A router that needs a nightly restart just to stay online is telling you something is wrong. At that point you're automating a symptom instead of chasing down the root cause. ## When the restart doesn't fix it When a restart clears things up for good, it did its job. When you find yourself back at that router every few days, the restart has turned into a chore that hides a problem underneath. Something specific is failing. Track down what, and you can stop restarting for good. The usual culprits: - Software that leaks memory until the router chokes. A firmware update often fixes it. Some routers leak badly enough to restart themselves every day or two. - Heat. Routers throttle and reboot themselves when they get too hot. A router shut in a cabinet or stacked on other warm gear is a prime suspect. - Too many devices for a cheap router to keep up with. - Old age. Most routers are good for three to five years, and the makers say so themselves: Netgear suggests three, Google and Linksys three to five. After that they start to flake, and no amount of restarting brings them back. Security updates usually stop around the same age, and nobody tells you when. - A problem on the provider's line. That one's out of your hands, but not out of your power to prove. Before you buy anything, run a few checks. Each one narrows down where the trouble actually lives. **Wired versus Wi-Fi.** Plug a laptop straight into the router with a cable. If the wired connection is solid but Wi-Fi is bad, your internet is fine and your Wi-Fi is the problem: interference, distance, or placement. **One device or all of them.** If only one gadget struggles, the gadget is likely the problem. (If that gadget is your computer, [that's a different rabbit hole](https://www.freshfromcache.com/why-is-my-computer-slow/).) If everything struggles, it's the network or the provider. **Close versus far.** A strong signal next to the router and a weak one down the hall points to coverage. The connection itself is fine. **Check for an outage.** Before you tear into your own gear, look at your provider's status page or an outage tracker. The problem might not be yours at all. **Go around the router.** Plug a computer straight into the modem or gateway. If that works, your router is the culprit. If the checks point back at your own equipment, work in this order: 1. Restart the router 2. Look for a firmware update 3. Fix heat and placement 4. Thin out the device load 5. Test with a cable If it still fails and the signs point to the line coming into your house, call your provider with specifics. Tell them when it happens and what your speed tests show. "It's slow" gets you a shrug. Timestamps and numbers get you a service call. ![An internet speed test on screen showing 40.65 megabits per second download.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/mika-baumeister-8zieFM9TFf4-unsplash.jpg) A speed test turns "it's slow" into a number you can hand your provider. ## What a restart will never fix Some problems a restart can't fix, no matter how many times you pull the plug. If the slowdown is really your provider's line, the distance between you and the router, or one aging device dragging everyone else down, restarting is just theater. Restarting also won't kick a bad actor off your network. If a device has genuinely been broken into, it phones home no matter how many times you cycle the power. Real security is [keeping the firmware updated](https://www.freshfromcache.com/router-expiration-date/) (the same reason patches matter everywhere else), changing the default admin password, and switching off remote management. ## The next time it acts up Go ahead and restart the router. It'll probably work. But watch what happens next. If it works and stays working, you're good. If you're back at it in three days doing another reboot, treat that restart as a smoke alarm. Something's running hot, and now you know where to look. --- ## Sources - Consumer Reports, "How to Tell When It's Time to Replace Your Router" (three-to-five-year replacement window; Netgear, Google, and Linksys guidance). [consumerreports.org](https://www.consumerreports.org/electronics-computers/wireless-routers/how-to-tell-when-its-time-to-replace-your-router-a5475786635/?ref=freshfromcache.com) - HighSpeedInternet.com, "How Often Should You Reboot Your Router?" (January 2026). [highspeedinternet.com](https://www.highspeedinternet.com/resources/when-to-reboot-router?ref=freshfromcache.com) - HighSpeedInternet.com, "Fiber vs. Cable Internet" (FCC availability data; ONT vs modem). [highspeedinternet.com](https://www.highspeedinternet.com/resources/fiber-vs-cable?ref=freshfromcache.com) - Google Nest Help, "What is a mesh network?" (self-healing and primary-unit behavior). [support.google.com](https://support.google.com/googlehome/answer/7182746?ref=freshfromcache.com) ### Your browser can block trackers and scam sites. The strongest settings just aren't on by default. URL: https://www.freshfromcache.com/chrome-edge-privacy-settings/ Last updated: 2026-08-11T18:29:02.000Z Your browser can block a lot of the tracking and scam sites you worry about. But the strongest settings are switched off, or turned down by default. Chrome does not block third-party cookies until you tell it to. It does not turn on its best scam protection either. Edge does more out of the box, but it holds the strict setting back by default. None of these cost anything or need an install. It takes about five minutes and a couple of menus. Two things to do in whatever browser you use. Block the trackers that follow you from site to site. And switch on the built-in check that warns you off scam and malware pages before you click in. ### In Chrome **Block third-party cookies.** 1. Open Chrome. Top right, click the three dots, then 'Settings'. 2. In the left menu, click 'Privacy and security'. 3. Click 'Third-party cookies'. On some versions this reads 'Tracking Protection'. Same place. 4. Choose 'Block third-party cookies'. 5. Scroll down a little and turn off 'Allow related sites to see your activity in the group'. Blocking cookies leaves this one on. It lets a company's own cluster of sites keep sharing what you do across them, so switch it off. Shortcut if the menu does not match: paste `chrome://settings/cookies` into the address bar and press Enter. ![Chrome Settings, Third-party cookies page, with Block third-party cookies selected and the related-sites sharing toggle switched off.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/01-chrome-cookies-v2.png) Chrome: block third-party cookies, then switch off related-sites sharing just below it. **Turn on Enhanced protection.** 1. Back in 'Privacy and security', click 'Security'. (Or paste `chrome://settings/security`.) 2. Under 'Safe Browsing', choose 'Enhanced protection'. Standard protection is already on by default. It blocks sites Google already knows are bad. Enhanced protection is the stronger setting. It checks pages in real time, so it can warn you off a scam site that went up an hour ago, before it lands on anyone's blocklist. ![Chrome Settings, Security page, with Safe Browsing set to Enhanced protection.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/02-chrome-enhanced-protection-v2.png) Chrome: choose Enhanced protection under Safe Browsing. **The tradeoff.** Enhanced protection sends more of what you browse to Google, so it can spot brand-new scam pages faster. For most people the scam and phishing protection is worth it. If you would rather not hand Google the extra data, leave it on 'Standard protection'. You still get blocked from the sites Google already knows are dangerous. You just react slower to the new ones. ### In Edge **Bump tracking prevention to Strict.** 1. Open Edge. Top right, click the three dots, then 'Settings'. 2. Click 'Privacy, search, and services'. 3. Make sure 'Enable tracking prevention' is on, then choose the 'Strict' tile. Edge already runs 'Balanced' by default, so this moves it up rather than turning it on. Strict blocks the most trackers. It also blocks cookies from sites you have never visited. ![Microsoft Edge Settings, Tracking prevention set to Strict with tracking prevention turned on.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/03-edge-tracking-prevention-v2.png) Edge: set Tracking prevention to Strict. **Confirm the scam protection, and turn on the app check.** 1. On that same 'Privacy, search, and services' page, scroll down to 'Security'. 2. Make sure 'Protect from harmful sites and downloads' is on. It is by default. This is Microsoft Defender SmartScreen, the piece that warns you off phishing and malware pages, the same job Enhanced protection does in Chrome. 3. Right under it, turn on 'Block potentially unwanted apps'. This one is off by default. It stops the junk that rides along with a "free download," the extra toolbar or "cleaner" you never asked for. 4. Check that 'Scareware blocker' is on. On most computers it already is. It kills the full-screen "your computer is infected, call this number" page, the fake alert aimed at people who panic. On an older or low-memory PC you may have to switch it on yourself, or it may not show up at all. If you want the belt-and-suspenders version, Edge also has a plain 'Block third-party cookies' toggle under 'Cookies and site permissions'. ![Microsoft Edge Settings, Security section, showing Protect from harmful sites and downloads on, Block potentially unwanted apps on, and Scareware blocker on.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/04-edge-security-v2.png) Edge: confirm SmartScreen and Scareware blocker, and turn on the app check. ### When a site acts up Expect this once in a while. Block trackers or third-party cookies, and some site you use starts misbehaving. A login will not take. A video will not play. A shopping cart forgets what was in it. Do not switch the whole setting back off. Both browsers let you allow the one site that broke and keep everything else protected. In Chrome, click the eye icon at the right of the address bar (it shows up on sites that use third-party cookies) and allow cookies for that site. In Edge, click the eye icon next to the address and do the same. Allow the one site, then move on. ![Chrome's Tracking Protection popup, opened from the eye icon in the address bar, with the toggle to allow third-party cookies for this site.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/05-chrome-exception-v4.png) Click the eye icon at the right of the address bar, then flip the toggle to allow the one site. Edge's version looks nearly the same. ### The short version These settings will not make you invisible. Neither will a [VPN](https://www.freshfromcache.com/what-a-vpn-actually-does/). What they do is cut down [the everyday tracking that follows you between sites](https://www.freshfromcache.com/what-is-a-data-broker/). And they put a warning between you and the worst pages before you click, the [phishing](https://www.freshfromcache.com/how-to-spot-a-phishing-email/) and [fake-update](https://www.freshfromcache.com/fake-update-scam-taken-down/) pages built to catch you off guard. Five minutes and a couple of menus. No charge. Open the browser you actually use and turn them on. Once they are on, they stay on. If a setting is not where I said it would be, your browser probably updated and moved it. Reply and tell me which one, and I will point you to it. Joel ### Sources - Google Chrome Help, "Choose your Safe Browsing protection level in Chrome," 2026\. [support.google.com/chrome/answer/9890866](https://support.google.com/chrome/answer/9890866?ref=freshfromcache.com) - Google Chrome Help, "Delete, allow, and manage cookies in Chrome," 2026\. [support.google.com/chrome/answer/95647](https://support.google.com/chrome/answer/95647?ref=freshfromcache.com) - Microsoft Support, "Learn about tracking prevention in Microsoft Edge," 2026\. [support.microsoft.com](https://support.microsoft.com/en-us/edge/learn-about-tracking-prevention-in-microsoft-edge?ref=freshfromcache.com) - Microsoft Support, "How can SmartScreen help protect me in Microsoft Edge?," 2026\. [support.microsoft.com](https://support.microsoft.com/en-us/microsoft-edge/how-can-smartscreen-help-protect-me-in-microsoft-edge-1c9a874a-6826-be5e-45b1-67fa445a74c8?ref=freshfromcache.com) - Microsoft Support, "Prevent online scams with the scareware blocker in Microsoft Edge," 2026\. [support.microsoft.com](https://support.microsoft.com/en-us/edge/prevent-online-scams-with-the-scareware-blocker-in-microsoft-edge?ref=freshfromcache.com) ### The apps I'd recommend aren't the ones I use most URL: https://www.freshfromcache.com/suggested-apps/ Last updated: 2026-08-11T19:46:37.000Z A lot of sites run a "recommended apps" post, usually the writer's own daily drivers. I figured I'd do one for FFC. Then I looked at what I actually open all day: Teams, Outlook, Copilot. Work, mostly. Not much use to anyone who doesn't do my job. So here's a different list. Not power-user tools, and not my daily drivers. The handful that earn a place on a normal person's phone, the ones you set up once and stop thinking about. ![A phone home screen filled mostly with work apps.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-homescreen.jpg) My actual home screen. Mostly work. ## This list is a bit different I approached this as less of a list of apps and more of a list of functions. You don't need the best photo app, you just need your photos backed up somewhere safe and automatic. Figure out the function first. Once you know it, the right app is usually one already built into your phone. Start with what's already there. Reach past it only when the built-in tool falls short of your needs. The list is short by design. Most people don't need forty apps. Eight or nine that pull their weight is plenty. ![A dense grid of dozens of colorful app icons.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-iconwall.jpg) You don't need all of these. ## The List ### Keep your passwords straight The job is simple. Stop reusing the same password everywhere, and [stop trying to remember them](https://www.freshfromcache.com/start-using-a-password-manager/). A password manager does both. Best place to start is the one already on your phone. Google Password Manager on Android, iCloud Keychain on iPhone. Both free, both built in, and for most people that's the end of the decision. Bonus points if you use the matching browser, because your passwords follow you. Google's fill into Chrome on any device you sign into. Apple's fill into Safari, and into Chrome or Edge on a Windows PC once you turn on the iCloud Passwords extension. It's the main reason I lean on Google. In Chrome I can generate a strong password and let it sync everywhere. **Try first:** let it save one login, then fill it back in. Once you watch it work, you'll trust it with the rest. **When it falls short:** you live across an iPhone, a Windows PC, and an Android tablet, and want one set of passwords everywhere. That's when a dedicated manager earns its place. Bitwarden is the usual pick. The free tier still covers unlimited passwords on unlimited devices. One note on Bitwarden. The company experienced a rough 2026, a price hike on the paid tier and some leadership turnover that made longtime users nervous. So keep half an eye on it. But it's still the one I'd point you to. ### Never lose your photos If your phone falls in a lake tomorrow, [your photos should still exist](https://www.freshfromcache.com/do-you-need-backups/). That's it. Android is Google Photos, iPhone is iCloud Photos. Turn on backup and forget about it. Both give you a little free storage to start (15 GB with Google, 5 GB with Apple), [which fills up fast](https://www.freshfromcache.com/why-is-my-phone-storage-full/). When it does, backup stops without telling you. The cheap paid tier runs a couple of dollars a month. That's the one you want if you start hitting limits. **Try first:** open the app, turn on backup over Wi-Fi, let it run overnight on the charger. Check in the morning that it says complete. **When it falls short:** if you want Google or Apple out of your photo library, that's a privacy call, and paid services exist for it. Watch the storage plans. Google has tangled its tiers up with AI bundles. The 2 TB plan's cheap first-year price can double on renewal. Buy the tier you think will fit your needs best. ### Carry your files with you A cloud drive is only half an app. The value presents itself when you sync it with your computer. Put your files in OneDrive or Google Drive on your PC, and the same files are in your pocket on your phone. If you've left the laptop at home and you need that document at the doctor's office, it's right there. On Apple, iCloud Drive does the same job, and it's already there on a Mac. The PC-to-phone trick is smoothest with OneDrive or Google Drive, though. ![A smartphone resting on a laptop keyboard.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/inline-files.jpg) One folder, synced to both. **Try first:** install it on your PC, sign in with the same account on your phone, drop one file in the folder, watch it show up on the other device. **When it falls short:** if you rarely use a computer, I wouldn't bother. The real value to these applications is having the option to retrieve files in multiple places. ### Find your way Maps you already know. Google Maps on Android, Apple Maps on iPhone, both good now. No notes. **When you might switch:** Waze, owned by Google, leans harder into live traffic and the alerts drivers call in to each other. If your commute is a fight, it's worth a look. ### Books for the drive If you're like me and spend a lot of time in the car, an audiobook app can change the drive. Audible is the big one, and my personal favorite. It lets me enjoy books while distracting me from the monotony of the drive. It costs money, though. You don't need the monthly subscription, you can buy a book on its own and it's yours to keep. Or pay monthly for a credit and the member catalog if you listen a lot. Either way it isn't free, so it's not for everyone. Before you pay, try Libby. It's free. Sign in with your library card and borrow audiobooks and ebooks like you'd borrow a paper book. It plays through CarPlay or Android Auto. The catch is the same as a physical library. Popular titles have a wait. **Try first:** Libby, with your library card. If the waits drive you nuts and you listen constantly, then pay for Audible. ### YouTube, but as a tool Everyone has YouTube. Most of us use it to fall down a rabbit hole at midnight. Fair. It's also one of the most useful tools on the phone if you point it at a task. Daily I use YouTube in a couple of normal ways, something to fall asleep to, a run on the treadmill, background noise. But its real utility comes from using it to complete a task you're unsure of. A how-to for anything I need to see done rather than read can usually be found. Faucet's dripping, dishwasher's throwing an error code, there's a video that shows you how to fix it. ### Messaging There's no single best messaging app, and anyone who tells you otherwise is probably selling something. Regular text messages for some folks, Facebook Messenger for others, WhatsApp for the ones overseas (mostly). That's normal. You don't need to consolidate, because they are often used for different contexts. Work, school, personal, etc. The one addition to make is for anything you'd rather keep private. Signal is the standard at the moment. Free, run by a nonprofit that hasn't been bought by a big tech company, built so that even Signal can't read your messages. If a conversation is sensitive, health, money, family, you can try Signal. **Try first:** get one person you talk to a lot onto Signal. Then you can determine if you'd get value from using it. **When it falls short:** it needs the other person to have it too. An encrypted app nobody you know uses is just a lonely app. ### Banking Your bank has an app. Use that one. Not a third-party app that offers to pull all your accounts into one tidy dashboard. Those aggregator apps want the keys to every account you own, in one place, held by a company that isn't your bank. If you can avoid it, be wary of aggregators. **Try first:** download your bank's official app from the store. Check the developer name matches the bank before you install. Fakes do exist. **When it falls short:** you're out of luck, and that's the honest answer. If your bank's official app is genuinely terrible, the answer isn't a third-party aggregator. It's a better bank. ### Lock down the accounts that matter An authenticator app. When an account offers [two-factor login](https://www.freshfromcache.com/what-the-heck-is-a-passkey/), sometimes called 2FA, it wants a second proof it's really you. A code by text works, but a code from an authenticator app is harder to steal. Google Authenticator is the familiar one, and free. Your password manager may have this built in too. **Try first:** turn on two-factor for your email first. Email is the account that resets all your other accounts, so it's the one to lock down hardest. One honest note: if you use Google Authenticator's cloud backup, Google technically holds those codes, since that backup isn't fully sealed. Fine for everyday logins. For your bank or email, some people keep those codes in an app that seals them instead. Your call, not a requirement. ## A word on all the Google and Apple You might have noticed this list leans hard on Google and Apple. Photos, maps, passwords, storage, all pointing back at the two biggest companies in your pocket. That's fair to notice. For most people, the built-in option is the right call. It's free, reliable, already there, and the alternative is doing nothing at all. A backup you actually turn on beats a perfect private setup you never finish. It's not that these companies have earned blind trust. It's that convenience is what gets a normal person protected, and these tools are the convenient ones. There's a line, though. If you specifically want Big Tech out of your data, there are good choices. [Signal](https://signal.org/?ref=freshfromcache.com) instead of regular texts. [Proton](https://proton.me/?ref=freshfromcache.com) instead of Google for mail and files. A dedicated password manager like [Bitwarden](https://bitwarden.com/?ref=freshfromcache.com) instead of the built-in one. Those take more effort, and for the person who wants them, they're worth it. For everyone else, the defaults are fine, and that's not a cop-out. It's just the reality. ## Delete these The flip side of a good list is knowing what to remove. These are the apps that promise to help and mostly don't. Some will make things worse. Phone cleaners and speed boosters. The ones that promise to free up memory and make an old phone fast again. Just don't. Your phone manages its own memory, and better than any add-on. When a booster force-closes your apps, they restart a few seconds later, and that restart burns more battery than leaving them alone. You press the button, watch the little animation, feel better, but nothing good happened. Battery savers. Same story. Your phone has a battery-saver mode built in, and it beats the third-party version. A separate app claiming to watch your battery is one more thing running, using the battery it says it's saving. Phone antivirus. If you stick to the official store, the protection built into your phone covers you. Most free antivirus apps make their money the ugly way. They scan your phone, tell you it's infected with something it isn't, and charge you to clean up a mess that isn't there. The app selling you safety is running a scam. The free VPN from an ad. A VPN has real uses, hiding your traffic on hotel Wi-Fi, for one. But the free one advertised before a YouTube video is a bad trade. Running a VPN costs money, so a free one pays its bills another way, usually by logging what you do and selling it. Studies keep finding free VPN apps stuffed with trackers, some with no real encryption at all. A free VPN can be worse than no VPN. At least with none, you know who's watching. More often than not, the app promising to protect your phone or speed it up is the one you should avoid. A phone should be a tool, not a chore. Set these up once and they fade into the background, which is the whole point. So that's my list. Yours is a little different, and I want to hear it. What's the one app you'd tell a friend to install? Reply and tell me. I read every one. Joel · [joel@freshfromcache.com](mailto:joel@freshfromcache.com) ### You can finally hide your phone number on WhatsApp URL: https://www.freshfromcache.com/whatsapp-usernames/ Last updated: 2026-08-11T18:29:01.000Z WhatsApp is adding usernames. Starting this week you can reserve one, and later this year you'll be able to let people message you by that name instead of by your phone number. For an app that has run on phone numbers for 17 years, and that more than 3 billion people use, that's a big change. Until now, being on WhatsApp meant anyone with your number could reach you, and joining a group chat handed your number to everyone in it. The parent chat group. The neighborhood group. The buyer who messaged you about a couch. And once someone has your number, you can't take it back. A phone number isn't just a phone number, either. It's how your bank sends you [login codes](https://www.freshfromcache.com/what-the-heck-is-a-passkey/). It's [tied to your accounts and your identity](https://www.freshfromcache.com/what-is-a-data-broker/), and it can even hint at what part of the country you live in. Usernames are the first time WhatsApp has given you a way to talk to someone new without handing all of that over. ![A phone number shown on a smartphone dialer screen](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/07/alexey-demidov-kbpn6F0-Ygs-unsplash.jpg) WhatsApp has used your phone number as your identity since 2009. ## How it works You reserve a username now and turn it on later. Reserving takes a few seconds on the latest version of the app: go to Settings, then Account, then Username. It has to be done on your phone or tablet, not on WhatsApp Web or the desktop app. A username is 3 to 35 characters, all lowercase. There's no public directory and no suggestions, so someone needs to know your exact username to message you the first time. WhatsApp also built an optional "username key," a code someone has to know on top of your username before they can reach you, meant to cut down on unwanted messages from people you don't know. Reservations opened early on purpose. With more than 3 billion people on the app, the good names will collide. So WhatsApp is letting everyone claim one before the feature goes live. You can change or delete your username later, but that frees it for someone else to grab. One thing that doesn't change: you still need a phone number to sign up for WhatsApp. The username only controls what new people see. Once it's on, someone messaging you for the first time sees the name, not the number. ## WhatsApp is the last one to the party This isn't a new idea. Signal added usernames in 2024\. Telegram has had them since 2014\. WhatsApp, the biggest messaging app in the world, was the last big holdout on a basic privacy feature. Three billion people who never had the option now get it. ## What it protects, and what it doesn't It helps to think of WhatsApp privacy in three layers: who can reach you, what's inside your messages, and what the company can see about your activity. Usernames only touch the first one. The second layer was already covered. WhatsApp messages are end-to-end encrypted, meaning only you and the person you're talking to can read them, not even WhatsApp. That's been true for years. The third layer is where the catch is. Encryption hides what you said. It doesn't hide the metadata: who you talked to, when, and how often. WhatsApp still collects that, and that metadata layer is where [Meta's privacy fights](https://www.freshfromcache.com/meta-dropped-instagram-encryption/) have always played out. Carissa Véliz, an Oxford professor and author of *Privacy Is Power*, called usernames a good step but reminded people that WhatsApp is "not a privacy-friendly app overall," and that Meta still collects plenty of data about who you talk to for advertising. ## What I make of it I'd turn it on. Not because it makes WhatsApp private in the way people are hoping, but because the one thing it does fix is worth the trouble. Handing out your number is a one-way door, and this finally gives you a way to keep it shut. Just don't read the headlines as "WhatsApp is private now." Usernames change who can find you. They don't change what Meta learns about who you talk to. Those are two different meanings of the word private, and only one of them moved. And if you barely touch WhatsApp because you live in iMessage and green-bubble texts, this still tells you something. Your phone number is a weak point. Every app is slowly moving to hide it, because once it's out, it's out. If you do use WhatsApp for family overseas, a group chat, or a small business, this is worth doing. ## What to do - **Reserve your name now** if you use WhatsApp. Update the app, then Settings, then Account, then Username. Do it on your phone; it isn't on desktop or web yet. - **Claim your real handle if you run a business.** Creators and small businesses can grab the same name they use on Instagram or Facebook by linking accounts in Meta's Accounts Center. - **Turn on the username key** if you expect messages from people you don't know. It makes them know a second code before they can reach you. - **Don't panic if you just want your own name.** There's no public directory, so a handle nobody would guess is in no rush. The scramble is for short, obvious names. - **Remember reserving isn't hiding.** Claiming a name now doesn't hide your number yet. That switches on later this year, and WhatsApp will let you know when it reaches the US. Usernames don't make WhatsApp something it isn't. Your messages were already encrypted. Your metadata is still collected. But you no longer have to hand over the number that's tied to the rest of your life. --- **Sources:** - WhatsApp, ["It's time to reserve your WhatsApp username"](https://blog.whatsapp.com/its-time-to-reserve-your-whatsapp-username?ref=freshfromcache.com) (June 29, 2026) - Meta Newsroom, ["It's Time to Reserve Your WhatsApp Username"](https://about.fb.com/news/2026/06/its-time-to-reserve-your-whatsapp-username/?ref=freshfromcache.com) (June 29, 2026) - The Associated Press, via [ABC News](https://abcnews.com/Technology/wireStory/whatsapp-users-usernames-phone-numbers-closing-privacy-blind-134314299?ref=freshfromcache.com) (June 29, 2026) - [BleepingComputer](https://www.bleepingcomputer.com/news/security/whatsapp-rolls-out-usernames-to-help-users-hide-their-phone-number/?ref=freshfromcache.com) (June 29, 2026) - [SecurityWeek](https://www.securityweek.com/whatsapp-rolling-out-username-feature-to-bolster-phone-number-privacy/?ref=freshfromcache.com) (June 29, 2026) - Carissa Véliz remarks to BBC News, reported via [Mobile World Live](https://www.mobileworldlive.com/meta/whatsapp-pushes-privacy-with-username-ids?ref=freshfromcache.com) (June 30, 2026) ### Your computer feels slow. Here's what to do. URL: https://www.freshfromcache.com/why-is-my-computer-slow/ Last updated: 2026-08-11T19:46:40.000Z Ask anyone in IT what they hear most and it's some version of the same sentence: my computer is slow, can you look at it? Almost every time, the computer isn't the problem. It's one program crawling, or the internet dragging, or years of clutter piling up, and from the chair it all feels the same. The whole machine feels slow. So the useful first move is figuring out what's actually slow, before you change a thing. Once you know that, the fix is usually small and free. If you've ever stared at a spinning cursor and started pricing a new laptop, this is for you. You probably don't need one. **Already handy with a PC and just want the steps?** [Jump straight to the fixes.](#the-fixes-easiest-first) If you're not sure what's actually slowing things down, the next section sorts that out first, so you fix the right thing instead of guessing. ![Graphic titled ](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/diagnose-infographic.png) ## Step one: what's actually slow? Before you touch a setting, spend a couple of minutes working out where the slowness lives. Three questions get you most of the way. **Is it everything, or just one thing?** Start here: what are you doing when it feels slow? If it only happens in one program, that program is the suspect, not the computer. A photo editor that chugs, a game that stutters, one website that takes forever to load. If it's slow no matter what you open, that points back at the machine itself. That one question splits the problem in half. **If the slow thing lives online, test your internet.** A big share of "slow computer" is slow internet wearing a disguise. A website, a streaming app, email in a browser, anything that lives online leans on your connection as much as on your computer. Two free ways to check: - Open your browser and search "speed test." Google puts one right at the top of the results, with a button to run it. - Or go to fast.com, which starts measuring on its own. Getting to a speed test is about the lightest thing you can ask a computer to do, so it does double duty. If even opening the browser and searching crawls, the machine is dragging, not the connection. If the browser pops right up and the number comes back low, the internet is your problem, and no amount of cleaning up the PC will fix it. For most homes, anything under about 25 Mbps download will feel slow for streaming and video calls. If you're paying for a lot more than you're seeing, the fix is on the internet side: [restart the router](https://www.freshfromcache.com/why-does-rebooting-your-router-work/), get closer to it, or call your provider. ![Google search for ](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/01-speed-test.png) Search "speed test" and run Google's built-in test to rule the internet in or out. **If it's slow no matter what, open Task Manager.** This is the one tool to know, and it's where most people freeze up. Go slow. - Open it the fast way: hold Ctrl, Shift, and Esc at the same time. A lot of people go digging through the menus for it and never learn this shortcut. - On Windows 11 you'll see a column of icons down the left side. Click the one labeled "Processes." On Windows 10 those are tabs across the top instead, and if you only get a small box, click "More details" first. - Now you're looking at a list of everything running, with columns across the top for CPU, Memory, and Disk. Those are the three things a program uses up. - Click the word "CPU" at the top of its column. The list reorders so the heaviest item jumps to the top. Do the same with "Memory" and with "Disk." - If one program is sitting up there using almost everything, there's your answer. The colors help too: the darker the orange or red, the harder that thing is working. ![Windows Task Manager Processes tab sorted by CPU, with the top app highlighted as the heaviest user.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/02-task-manager-processes.png) Click the CPU column to sort. The app at the top is using the most. While you're in there, glance down the list for anything you don't recognize that's working hard. A name that means nothing to you and is eating resources is one to look up. Right-click it and choose "Search online," and Windows looks it up for you. To stop something that's clearly misbehaving, click it once, then click "End task" (top-right corner on Windows 11, bottom-right on Windows 10). One caution: don't end things at random. If you don't know what it is, look it up first, because some of these are pieces of Windows itself. **Watch it while it's actually slow.** This last move tells you a lot. Leave Task Manager open and use the computer until it bogs down. If CPU, Memory, or Disk shoots up near 100 percent right as things get sluggish, something on the machine is the bottleneck, and the fixes below will help. If everything stays low and calm while it's crawling, that's a sign the slowness is coming from somewhere else, usually the internet or one particular website. **Then check one thing about the hardware: is it an old hard drive?** This is the big one, and most people don't know the answer offhand. Older computers store everything on a spinning hard drive. Newer ones use an SSD, which is many times faster. If yours still has the spinning kind, that by itself can make a perfectly good computer feel broken. To find out: - Click Start and type "Defragment and Optimize Drives." Open it. - Look at the column called "Media type." Next to your main drive (usually the one marked "C:") it says either "Solid state drive" or "Hard disk drive." - If it says "Hard disk drive," hold onto that. It's the most useful thing you'll learn here, and there's a cheap fix for it further down. ![Windows Optimize Drives window with the Media type column highlighted, showing a Solid state drive.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/03-optimize-drives.png) The "Media type" column tells you whether your drive is an SSD or an older hard drive. That's the whole diagnosis. Most of the time it lands on one of two things: clutter you can clear for free, or an old drive you can replace cheaply. Clutter first. ## The fixes, easiest first **Trim what starts with the computer.** Every program that launches when you turn the PC on is weight it carries before you've done anything, and half of them you never asked to start. - Open Task Manager again (Ctrl, Shift, Esc). - Find "Startup apps" (it's just "Startup" on Windows 10). On Windows 11 it's one of the icons down the left. - You'll see a list with a "Startup impact" column. Look for anything rated "High" or "Medium" that you don't need the moment the computer turns on. A music app, a game launcher, the updater for a printer you use twice a year. (If something reads "None" or "Not measured," Windows just hasn't clocked it slowing startup.) - Right-click it and choose "Disable." This doesn't delete the program. It still opens when you click it. It just stops launching itself at startup. - Leave your antivirus alone. ![Windows Task Manager Startup apps tab with the Startup impact column highlighted and a High item flagged.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/04-startup-apps.png) The "Startup impact" column flags what's slowing your startup most. **Restart it. Actually restart it.** This is the most underrated fix there is, and the one nobody does. Closing the lid or letting it sleep is not the same thing. A full restart clears out memory, finishes pending updates, and shuts down whatever was stuck running. If your computer has been on for weeks, this alone can wake it up. Click Start, then the power icon, then "Restart." Pick "Restart" rather than "Shut down," because on Windows a shutdown sometimes only half-counts and leaves the old session in place. **Close some browser tabs, and check your add-ons.** If the slow thing is your web browser, this is usually why. Every open tab uses memory whether you're looking at it or not, and one bad add-on can drag the whole browser down. - Close the tabs you're done with. Bookmark any you're scared to lose. - Then check your extensions. In Chrome or Edge, click the three-dot menu in the top corner, then "Extensions," then "Manage extensions." - Turn off or remove anything you don't remember adding. Toolbars, "coupon finders," and anything calling itself a "PC booster" are the usual offenders. **Free up some space.** [A drive that's nearly full](https://www.freshfromcache.com/windows-11-disk-eating-bug/) slows the whole computer down. Windows needs breathing room to work, and once you're past about 90 percent full it starts to struggle. Check one thing first. If Settings shows system files eating hundreds of gigabytes, that is a confirmed Windows 11 bug rather than your clutter, and the fix is a Windows update, not a cleanup. - Open Settings (the gear icon in the Start menu), then "System," then "Storage." - Turn on "Storage Sense." From then on it clears out temporary files and empties your Recycle Bin on its own. - To remove programs you don't use, go to Settings, then "Apps," then "Installed apps." You can sort the list by size to find the big ones. **Scan for malware.** If the computer slowed down suddenly, or pop-ups started showing up, or your browser's home page changed on its own, something may have gotten in. You already have a scanner built in. - Click Start, type "Windows Security," and open it. - Click "Virus & threat protection," then "Quick scan." - To be thorough, click "Scan options" and choose "Full scan." It runs a while, so start it when you're done for the day. - For a second opinion, the free version of Malwarebytes is reputable and won't pester you to pay just to see what it found. **Clear out the bloatware.** A lot of computers arrive from the factory stuffed with trial antivirus, a "support assistant," and games nobody asked for, all running in the background. Go to Settings, then "Apps," then "Installed apps," and uninstall the trial junk and vendor "helpers" you don't use. Anything you want to keep but don't need running at boot, disable it back in the Startup step. ## A few good habits You don't have to do any of this on a schedule, but a handful of habits keep a computer from sliding back into a crawl: - Restart it every few days. A real restart, not sleep. - Keep your startup list short. When you install something new, notice whether it added itself to startup, and disable it there if you don't need it. - Don't let the drive fill up. Leave yourself some empty room. - Be picky about what you install, especially anything promising to "speed up" or "clean" your PC. Which is the next thing. ## A warning about "speed up your PC" software Search "why is my computer slow" and most of what comes back is an ad for software promising to fix it in one click. Skip all of it. Registry cleaners, "PC optimizers," and "driver updaters" don't do what they claim, they sometimes break things, and plenty of them arrive bundled with the exact junk they pretend to clean off. The worst are the pop-ups that take over your screen, announce your computer is infected, and hand you a number to call. It's a scam, the same playbook as the fake update pop-ups [police took down recently](https://www.freshfromcache.com/fake-update-scam-taken-down/). Don't call, don't pay, just close the browser. Everything you actually need is already built into Windows, free, and it's what we used above. Even Microsoft's own cleanup app mostly just gathers those built-in tools behind one button and keeps nudging you back to its browser, so you can skip that too. ## When it's the hardware: the upgrade that pays off If the diagnosis turned up an old hard drive, this is your fix, and it's the one that makes the biggest difference by a mile. Swapping a spinning hard drive for an SSD replaces the slowest part of the computer with one that's many times faster. An old laptop that took a full minute to start will start in a small fraction of that. Programs open when you click them instead of making you wait. It's the closest thing to a new computer without buying one. ![A solid-state drive (SSD), the cheap part that gives an old computer a big speed boost.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/behnam-norouzi-KUWQ16hqXn8-unsplash.jpg) An SSD runs around a hundred dollars and is the single biggest speed boost for an older machine. An SSD is a cheap part, often around a hundred dollars or less, and fitting one is a quick job for any repair shop. The fiddly bit is moving your files onto the new drive, which is where most people hand it to a pro rather than do it themselves. Even with someone else's labor, it costs a fraction of a new machine. One thing that isn't about speed: if your hard drive is making clicking or grinding sounds, or files are disappearing, that's a drive about to fail, not just a slow one. Back up your files today and get it replaced. (We've written about [backing up the easy way](https://www.freshfromcache.com/do-you-need-backups/).) The other upgrade to consider is memory, called RAM. If your computer chokes when you've got a lot open at once, and Task Manager showed Memory pinned near 100 percent, more RAM helps. If you're not running out of memory, adding more does nothing, so check before you buy. On some thin, modern laptops the memory is sealed in and can't be added to, so this mostly applies to older machines and desktops. One note on timing. Through 2025 and into 2026 the price of memory and storage parts jumped, driven by demand from AI data centers, and it's expected to stay high for a while. The upgrade still pays off, because new computers got more expensive for the same reason. Just don't be surprised if an SSD costs more than you'd expect, and buy on a sale if you can. ## When it's time to replace it Sometimes the answer really is a new computer. A rough rule: if a repair costs more than about half what a comparable new machine would, replace it instead. A hundred-dollar SSD that buys you a few more years is an easy yes. A four-hundred-dollar repair on a laptop worth six hundred is not. The other reason to replace, and it has nothing to do with speed, is that the computer can't run a supported, secure version of Windows anymore. Windows 10 stopped getting security updates in October 2025\. A Windows 10 machine can still be quick and still turn on fine, but it's no longer being patched, which makes it risky for anything like banking. A lot of those computers can't meet Windows 11's requirements, and that's what finally retires them, not their speed. We wrote a separate guide on [what to do if you're stuck on Windows 10](https://www.freshfromcache.com/windows-10-out-of-support/), including a free way to keep getting security patches a little longer. Whatever you're running, [keep it updated](https://www.freshfromcache.com/patching-is-the-new-password/), since an out-of-date computer is the easy target. The next time your computer feels slow, you don't have to guess, and you don't have to buy a new one on the spot. Open Task Manager and see what's actually working hard. Check whether it's one program or the whole machine, and whether the internet is the real culprit. Most of the time you'll turn up a startup list a mile long, a full drive, or an old hard drive that a cheap part would fix in an afternoon. And when you can't sort it out yourself, you'll at least know what to tell the person who can, instead of just "it's slow." That alone gets it fixed faster. Got an old Windows PC you'd written off? Run it through the first few steps and tell me what Task Manager shows. Usually it's something simple, and I'm glad to help you spot it. ### The pop-up scam just got raided URL: https://www.freshfromcache.com/newsletter/pop-up-scam-raided/ Last updated: 2026-06-30T21:52:24.000Z The machines had a rough week, and most of it landed on the people running them, not on you. Three healthcare networks got breached in seven days, the pop-up scam that has been hijacking browsers all spring got its servers seized by police, and texting between an iPhone and an Android finally got real encryption after years of green-bubble jokes. Then, because it is almost the Fourth, I wrote up how to take a firework photo that actually looks like fireworks. The takedown is the one bit of good news in the pile. For once the scam is the one having a bad day. --- [**Police take down major pop-up scams**](https://www.freshfromcache.com/fake-update-scam-taken-down/) The fake "your computer is infected" pop-ups, and the fake update screens behind a lot of them, ran on a network police just dismantled in a coordinated takedown. The scam works by getting you to run the dangerous part yourself, so the defense stays simple: close the tab, do not call the number, do not paste or install whatever it tells you to. Satisfying to watch one of these actually get caught. *News* --- [**Three breaches in one week, and your medical records are the target**](https://www.freshfromcache.com/three-breaches-in-one-week/) Three healthcare organizations disclosed breaches in seven days, and the data in play is the kind you cannot reset later: diagnoses, insurance details, the contents of your chart. There is no password to change here, so the move is to stay alert for medical-billing scams and bogus "verify your coverage" calls in the months after. I walk through why your records are worth more to a criminal than your credit card. *News* --- [**iPhone to Android texting finally encrypted**](https://www.freshfromcache.com/iphone-android-texts-encrypted/) Texts between iPhones and Androids used to drop back to old unencrypted SMS, which is why those were the easy ones to snoop on. The latest update closes that gap with end-to-end encryption over RCS, the modern texting standard, so a normal thread between the two camps is now actually private. You mostly get this by keeping both phones updated. *News* --- [**Are those smart glasses recording you? How to tell**](https://www.freshfromcache.com/smart-glasses-recording-you/) Camera glasses are common enough now that it is a fair thing to wonder about at a dinner table or a kid's recital. There is usually a small recording light and a couple of other tells, and I lay out what to look for on the popular models. Mostly it is a reminder that the etiquette has not caught up to the hardware yet. *Learn* --- [**How to take a great firework photo with your phone**](https://www.freshfromcache.com/capture-fireworks-phone/) Your phone can take a genuinely good firework shot if you stop letting it guess. Lock the focus, steady it on something, and use the timer or night mode instead of jabbing the button at the wrong moment. Quick read before Friday. *Learn* --- If you only read one: the three healthcare breaches. The takedown was the satisfying one, but this is the story with your name in it, and medical records are the kind of data you cannot change after they leak. --- **5-Minute Tech Tip** Set up your phone to share your medical info in an emergency. If you are ever unconscious or hurt, a locked phone can still show your name, allergies, medications, and an emergency contact to whoever finds it, without anyone unlocking it. It takes about five minutes on an iPhone or an Android, and a long weekend with travel and fireworks is a good excuse to finally do it. Steps for both phones are here: [Set up your phone to share your medical info in an emergency](https://www.freshfromcache.com/phone-medical-id/). --- **Scary Headline of the Week** *"LastPass got hacked again."* This one stings. Last week LastPass confirmed customer data was stolen, and given the company's history, that headline writes itself. What happened: the thieves didn't get into LastPass itself or anyone's vault. They broke into a sales-and-marketing tool LastPass uses (Klue) and pulled the customer list out of LastPass's Salesforce. Names, emails, phone numbers, addresses, support notes. The kind of information already on a business card. The real risk: a confirmed list of LastPass customers is raw material for a fake-LastPass email or "your account needs attention" call. So slow down and go to the site yourself instead of clicking. If your info turns up in a leak, [here's what to do](https://www.freshfromcache.com/leaked-email/). Verdict: real breach, wrong drawer. --- Fresh From Cache grows when readers pass it along. If you enjoyed this issue, forward it to someone who might too. --- Did the medical-ID setup work on your phone? Hit reply and let me know. Joel ### Microsoft pulls Edge extensions due to malware URL: https://www.freshfromcache.com/microsoft-pulls-edge-extensions-due-to-malware/ Last updated: 2026-06-30T14:37:51.000Z Microsoft just pulled 119 extensions from the Edge add-on store, all tied to one campaign its researchers named StegoAd. The extensions were the kind people install without thinking twice. Ad blockers, VPNs, translators, video downloaders, calculators, coupon finders. Each one did the job it advertised, collected real reviews, and sat in the store for years. Between them they reached up to 2.6 million installs. Then, after a built-in delay, some of them woke up and started stealing Google passwords and the sign-in codes meant to protect them. The trick that names the campaign is steganography, hiding code inside a file that looks like an ordinary picture. The nefarious instructions were tucked into the image and font files the extension came with. The extension pulled that code out and ran it, but only after it had been installed for a while. A scanner checking the extension sees a translator and some images. The harmful part is not there to catch until the moment it runs. That delay was deliberate. Microsoft says the payload held back for days, checked whether it was being watched, and went dormant if developer tools were open. On some versions it only fired for about one in ten installs. So the 2.6 million is a ceiling, not a count of victims, and Microsoft does not know how many people were actually hit. What it does know: the same code that ran ad fraud in the background could harvest WordPress logins and grab your Google credentials at the moment you signed in. Microsoft ties StegoAd to a group it has tracked since at least 2021, the same operation researchers have linked to two earlier waves of poisoned extensions. The company removed all 119 and suspended more than 90 of the developer accounts behind them. It also published the technical fingerprints so Chrome, Firefox, and other browsers can check for the same thing. The advice we all repeat is to only install from the official store and check the reviews first. Both of those failed here. These came from the official Edge store. They had real reviews from real people who installed a coupon finder that found coupons and never saw the rest. Reviews tell you whether a tool works. They cannot tell you what else it is doing in the background, or what it will start doing after an update six months from now. Getting better at spotting a bad extension at install time will not save you. You probably can't tell. The better habit is to treat the extensions you already have like a junk drawer and clean it out. Most of us have a dozen in there, half we don't remember adding. Each one is a small program that can read what is on your screen, and you are trusting it to stay friendly indefinitely. A few steps you can take this week: - **Open your extensions list.** In Edge, type `edge://extensions` in the address bar. In Chrome, it's `chrome://extensions`. You'll see everything installed, including the ones you forgot about. - **Remove anything you don't actively use.** If you can't remember why it's there or what it does, take it out. You can always add it back later. - **Check the survivors against Microsoft's list.** Microsoft published the full list of bad extension IDs in [its report](https://microsoftedge.github.io/edgevr/posts/Inside-StegoAd-How-We-Disrupted-a-Massive-Malicious-Extension-Campaign/?ref=freshfromcache.com). If one you kept is on that list, or Edge already removed one for you, treat that browser as exposed. - **If you were exposed, change the passwords that matter.** Google first, then anything you bank or shop with, then any site where you run a website. After that, check your account's recent sign-in activity for logins you don't recognize. - **Move your important accounts to a passkey or security key.** This malware grabbed text-message and app codes as people typed them, so a code-based second factor would not have stopped it. A [passkey](https://www.freshfromcache.com/what-the-heck-is-a-passkey/) or a physical security key works differently. There is nothing to type and nothing to hand over. That is what makes it worth setting up on the accounts you most want to keep. This doesn't mean extensions are bad, or that you need to strip your browser bare. The good ones save real time, and most developers are honest. The problem is that the store listing and the star rating, the two things we're told to trust, are exactly what a patient attacker can earn. Microsoft caught this one after it ran for years. It's the same patience behind the [fake update pop-ups police took down last week](https://www.freshfromcache.com/fake-update-scam-taken-down/). The next batch is already in there somewhere, working perfectly, waiting. ## Sources - Microsoft Edge Vulnerability Research, "Inside StegoAd: How We Disrupted a Massive Malicious Extension Campaign" (2026). [Link](https://microsoftedge.github.io/edgevr/posts/Inside-StegoAd-How-We-Disrupted-a-Massive-Malicious-Extension-Campaign/?ref=freshfromcache.com) - Malwarebytes, "119 Edge extensions promised useful tools, instead downloaded malware" (2026). [Link](https://www.malwarebytes.com/blog/news/2026/06/119-edge-extensions-promised-useful-tools-instead-downloaded-malware?ref=freshfromcache.com) - The Hacker News, "Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts" (2026). [Link](https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html?ref=freshfromcache.com) ### How Much Water Does AI Really Use? URL: https://www.freshfromcache.com/how-much-water-does-ai-really-use/ Last updated: 2026-08-11T18:29:10.000Z Last week someone asked me what I thought about AI and water. I'm a tech person and I use AI every day, at work and at home. I had just finished reading *Empire of AI*, so I knew the story of how these systems got built and who built them. And I still couldn't give an honest answer. I wasn't sure. I had heard the same things everyone has heard. That AI is going to boil the oceans. That every silly picture you make drinks a bottle of water. I have friends, family, and coworkers who feel strongly about the data centers going up and the water they pull, and their concern is real. I take it seriously. But when I went looking for my own answer, I realized I had been carrying opinions I had never checked. So I checked. This is what I found. One thing I need to point out. This is only about water and the environment. Not jobs, not plagiarism, not the other fights people are having about AI. Some of those worry me more than the water does. But they are different arguments with different facts, and trying to cram them all into one piece is how you end up saying nothing well. So: water. Here is what surprised me most. I expected the numbers to be bad. I went in half-believing the dire version. The numbers are smaller than I thought. Not zero, and not nothing, but smaller. What deserves anger turned out to be somewhere I wasn't looking. ![Infographic, The AI Water Footprint. One text prompt uses between 0.26 mL (Google Gemini) and 45 mL (Mistral). Farming takes about 70% of fresh water, all data centers about 1.5% of electricity, AI a fraction of 1%. Two in three new data centers since 2022 sit in water-stressed areas, and about 40% of one Oregon town's water goes to a single Google site.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ai-water-by-the-numbers.png) Small per prompt, small worldwide, and the strain concentrated where water is already scarce. ## Which number are you being handed? Before any figure means anything, you have to know which kind it is. There are three, and people mix them up constantly. - **Withdrawal** is water taken from a source and mostly returned. Borrowed. - **Consumption** is water that's gone, usually evaporated in a cooling tower. Spent. - **Indirect** is the water used somewhere else, mostly at a power plant, to make the electricity the data center runs on. You never see it at the building, but it's a real cost. Those three can differ by more than ten times for the same facility, according to the US Department of Energy's Lawrence Berkeley National Lab. So when a headline says AI "used" some enormous number of gallons, the first question is which kind. A lot of the scariest figures are withdrawal, water that went right back where it came from, reported as if it vanished. I had read plenty of those headlines. I had never stopped to ask which number I was looking at. ![A translucent question-mark icon suspended in water with floating droplets.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ai-water-question-cube.jpg) Three numbers, three different things being measured. ## So how big is it, really? Now the scale. Most of the published numbers are for data centers in general, not AI specifically. Data centers are the buildings behind almost everything online, AWS, Azure, Google Cloud, your email, your bank, your streaming. AI is the fastest-growing tenant in those buildings, but right now it's a slice, not the whole thing. Plenty of headlines use "data centers" and "AI" interchangeably. All the data centers on earth used about 1.5% of the world's electricity in 2024, by the International Energy Agency's count, and about half a percent of global carbon emissions. In the US, data centers used about 17 billion gallons of water directly for cooling in 2023, by the Energy Department's Lawrence Berkeley National Lab count. That is a small share of what the country spends on its farms and lawns. Per prompt, the water usage looks small. Google published a figure in 2025 putting a typical text prompt to its Gemini model at about 0.26 milliliters, about five drops from an eyedropper. Sam Altman put ChatGPT in the same range, about a fifteenth of a teaspoon. Those low numbers come from the companies themselves. Google's came out of its own technical paper, not independent peer review. It covers text prompts only, not the training behind the model and not image or video generation. When outside researchers run the math, they land much higher. Mistral, another AI company, published a life-cycle estimate of about 45 milliliters for one longer response. So the real range for a single prompt sits somewhere between five drops and a few tablespoons, depending on who is counting and what they count. No one's number has been independently audited. I wanted to make that figure digestible, so I did some rough math on myself. I've used AI fairly heavily since about April, call it three hours a day. A full year of that habit comes out to about ten liters of water on Google's figure, and over a thousand on the higher independent ones. In plain terms, that is anywhere from about four days of my drinking water to well over a year of it, depending on whose number you trust. A caveat on that math. It's mine, not a study's, and it's meant to give a sense of scale, not a verdict. And I'm not going to compare it to a hamburger, even though that comparison is everywhere. The water in a hamburger is mostly rain that fell on a field and would have fallen anyway. That's a different kind of water than what a data center evaporates, and mixing the two is exactly the sloppiness I'm trying to avoid. Drinking water to drinking water is a fairer comparison. ![Clear water pouring into a drinking glass against a green leafy background.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/curated-lifestyle-4MFSILQfnb8-unsplash.jpg) The fairer comparison: drinking water against drinking water. ## Putting it up against everything else For the bigger picture, agriculture is the giant in the room. Farming takes about 70% of the fresh water people withdraw worldwide, and has for decades. AI, counted generously, is a fraction of one percent. Although here's a wrinkle I enjoyed. When I went to pin down that 70% figure, I found a 2025 paper that traced it back through fifty years of citations and found almost no hard data underneath. The real number could sit anywhere from 45 to 90%. So even the most-repeated water number on earth turns out to be more estimate than fact. The ranking is solid. Farming is first. But the exact percentage is a guess. ![Rows of leafy crops watered by overhead sprinklers under a cloudy sky.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/elibet-valencia-munoz-ztHHjV0t0Qw-unsplash.jpg) Farming withdraws most of the world's fresh water. AI is a rounding error next to it. ## Why people are upset Water is local, not global. A data center that's a rounding error against the whole planet's supply can still be a real problem for one town, because it's drinking from that town's well. In The Dalles, Oregon, a Google facility came to use about 40% of the city's water. The same buildout is now [reaching Hillsboro, Oregon](https://www.freshfromcache.com/the-data-center-boom-reaches-hillsboro/). In parts of Georgia and Arizona, people have watched data centers move in next to reservoirs that were already low. About two-thirds of the data centers built or planned since 2022 went into areas that were already short on water, according to a 2025 Bloomberg analysis. That isn't an accident. Dry air is good for cooling. Land is cheap. Power is cheap. The tax breaks are enormous; Virginia and Texas each give up about a billion and a half dollars a year in data center exemptions. And water, in most places, is priced so low there's no reason to conserve it. So the companies build where it pencils out, and sometimes that's the worst possible place for the water table, and the people who live there had no say. It isn't about "AI is boiling the oceans." The water AI uses, in total, is modest. The trouble is that a handful of companies are sinking enormous straws into some of the driest ground in the country because it's cheap. The people living on top of that ground are left to argue about it after the concrete is poured. It feels like money making the call, with the residents as an afterthought. ![A concrete irrigation canal running through dry land beside power lines and an industrial plant.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/jack-catalano-i68qofIJijQ-unsplash.jpg) The trouble is local, in some of the driest ground in the country. ## Pressure for change This is starting to change, and it's changing the way these things usually do, under pressure. New data centers increasingly use closed-loop cooling, which fills once and recirculates instead of evaporating millions of gallons. Google now says it will only use water cooling where the local supply is healthy. In 2026, lawmakers in more than 30 states introduced over 300 bills dealing with data centers and the resources they use. Tucson's city council flatly turned down a large data center over water in 2025. That happened because of public pressure and bad press, not corporate generosity. Which is how most of this works. A technology shows up messy and wasteful. It gets cleaned up once the pushback starts costing the companies money. ## What I think, for now The strongest argument on the worried side has nothing to do with today's numbers. It is about the slope. Each prompt keeps getting more efficient, but if we run a thousand times as many of them, the total still climbs. Efficiency that gets eaten by growth is not efficiency. What worries me is not this year, but where it points. These companies are betting on compounding growth. What I think today could move tomorrow, and an opinion on something this new should be allowed to shift. ## If you're still uneasy Your own use barely registers. Your car and your thermostat dwarf anything you will ever do in a chat window. But if you want to lower your footprint, lean on text instead of AI video, and skip the giant requests you will never actually read. The real impact happens outside the chat window. Make the companies disclose what they actually use. Keep the thirstiest cooling out of the driest places. Make them pay for their own strain on the grid instead of [passing it to your water bill](https://www.freshfromcache.com/why-your-next-phone-costs-more/). The water AI uses is real, and it's smaller than the headlines say. The fight worth having was never about whether AI gets to exist, but about where we let it get built, and whether we make the people building it tell us the truth. Where your line sits past that, how much water is too much, how much change is worth it, that's yours to draw. Everybody has their own line. We just need to be looking at the same numbers when we do. I'm curious where you land on this, especially if you have numbers I didn't find. If you see it differently, tell me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). ## Sources - International Energy Agency, *Energy and AI* (2025). - US Department of Energy, Lawrence Berkeley National Lab, *2024 United States Data Center Energy Usage Report*. - Google, environmental report on per-prompt AI resource use (2025). - Sam Altman, "The Gentle Singularity" (2025). - Mistral AI, life-cycle environmental analysis of an AI assistant (2025). - Puy et al., "Widely cited global irrigation statistics lack empirical support," *PNAS Nexus* (2025). - Bloomberg, reporting on data centers in water-stressed regions (2025). - The Oregonian, reporting on Google water use in The Dalles (2022, updated 2026). - Virginia JLARC and the Texas Comptroller, data center tax exemption figures. - MultiState, state data center legislation tracking (2026). ### Police take down major pop-up scams URL: https://www.freshfromcache.com/fake-update-scam-taken-down/ Last updated: 2026-08-11T18:28:39.000Z On June 18, an international police operation seized the servers behind the fake "update your browser" pop-up, the one that has been tricking people into installing malware since 2017\. They took down 106 servers and domains and scrubbed the malware off 14,971 hacked websites. The network is called SocGholish, and that pop-up was the first link in a chain that ends with a company locked out of its own files, or your data in the hands of bad actors. This week the police cut the chain near the start. You have probably seen the box. You are on a normal website and a pop-up appears telling you your browser is out of date, click here to update. If you saw [Saturday's post on the fake CAPTCHA scam](https://www.freshfromcache.com/fake-captcha-scam/), this is in the same family. ![A fake 'Before you continue to the website' pop-up pushing a browser-extension install.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/scam-popup-malwarebytes.png) The real fake-update pop-up. Source: Malwarebytes The clever tactic was stealth. It only showed the fake box to real targets and stayed invisible to everyone else, including the people who owned the hacked sites. That is how it ran for years without anyone noticing. Researchers at Proofpoint call SocGholish the originator of the whole technique. What that pop-up was after had nothing to do with selling you anything. SocGholish was what the security world calls an "initial-access broker." Its business was breaking into computers and selling that access on to other criminals. The buyers were ransomware gangs like LockBit and RansomHub, the kind that [rent out their attacks to anyone with a login](https://www.freshfromcache.com/ransomware-has-been-franchised/). The fake update box was just the front door. Whoever paid for the access decided what came next, and what they usually came for was your files held hostage or your data dumped on a leak site. ![A red warning triangle over falling code with the words your files are encrypted.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ransomware-stakes-web.jpg) Photo: Getty Images / Unsplash This is a rare takedown that gets ahead of the damage. Instead of cleaning up after a ransomware attack, the police cut the supply line that feeds one. Dutch police, who led the operation, say the login details for 1.4 million websites were exposed in the process. The breach-notification service [Have I Been Pwned](https://haveibeenpwned.com/?ref=freshfromcache.com) was handed 154,000 email addresses and more than half a million passwords from the haul. Canada's federal police disinfected 2,488 computers and notified every Canadian victim they could identify. The Netherlands, the FBI, Germany, and Canada ran it together with Europol behind them, as part of an ongoing campaign called Operation Endgame that has spent two years knocking out malware services hundreds of servers at a time. Don't celebrate too much. The servers are gone, but the people who ran them are not. SocGholish is tied to Evil Corp (yes, that's really their name), a Russian group that law enforcement knows well. The US, UK, and Australia have all sanctioned Evil Corp. Its alleged leader, Maksim Yakubets, carries a $5 million FBI bounty and is believed to have worked with Russian intelligence. None of those people are reachable by a server seizure. Groups like this have rebuilt after takedowns before. The 1.4 million leaked passwords are already circulating, and the scam was never SocGholish's alone. Copycats like ClearFake and ZPHP run the same play, and nobody touched them yet. A few steps you can take. If you have seen these pop-ups, one simple rule: a real browser update never arrives as a box on a web page. Chrome, Edge, Safari, and Firefox all update themselves in the background, so any website telling you to update is lying, every time. - Close the tab. - [If you ever clicked one and are not sure what happened](https://www.freshfromcache.com/what-to-do-after-a-scam/), check your email at [haveibeenpwned.com](https://haveibeenpwned.com/?ref=freshfromcache.com), change any password that shows up, and run a scan with the security software already on your machine. - One catch: real breach warnings never email you a link to "check your data," so type the address in yourself. If you run a website, you may have been one of the hosts without ever knowing it. That is what the 1.4 million number accounts for. - Put your domain into [Have I Been Pwned's domain search](https://haveibeenpwned.com/DomainSearch?ref=freshfromcache.com). - [Change every admin password](https://www.freshfromcache.com/start-using-a-password-manager/), and turn on multi-factor login. - Update WordPress along with its plugins. - If the police cleaned your site, do not call it fully clean yet. They pulled the backdoor, but your passwords and any extra admin accounts the attackers added are still yours to deal with. Build the habit and you'll be covered, with or without the next takedown: a real update never comes from a website, so close every one of these pop-ups on sight. The pop-up looks like junk mail, but it's at the front of a line that ends with a company locked out of its own files, or your data sold to whoever pays. Close the pop-up, and you cut your own link out of the chain. *Have you ever absentmindedly clicked one of these pop-ups? If so, what happened? I'd love to hear about it. You can reach me at* [*joel@freshfromcache.com*](mailto:joel@freshfromcache.com)*.* ## Sources - Netherlands Police, on the international law-enforcement action against the SocGholish malware operation (June 18, 2026): [politie.nl](https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html?ref=freshfromcache.com). - Corroborating threat research from Proofpoint and Infoblox. - Breach-exposure check: [Have I Been Pwned](https://haveibeenpwned.com/?ref=freshfromcache.com). ### iPhone to Android texting finally encrypted. URL: https://www.freshfromcache.com/iphone-android-texts-encrypted/ Last updated: 2026-06-29T21:18:20.000Z Apple has encrypted messages between iPhones since 2011\. Anything you sent to a friend on an Android phone got no such protection, and Apple was in no rush to change that. As of May, it finally has. Apple adopted the standard that fixes this, RCS, back in 2024, but released it without the encryption. The encryption itself arrived in May, with iOS 26.5\. Better late than never. When both phones are updated and both carriers support it, a cross-platform chat now encrypts itself, and a small lock icon shows up next to the conversation to prove it. So why care? Think of a normal text as a postcard rather than a sealed letter. Anyone handling it along the way can read it. Encryption turns the postcard into a sealed letter. ![A handful of old handwritten postcards fanned out on a dark surface.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/postcards-inline.jpg) A text used to travel like one of these. Photo: rc.xyz / Unsplash. ## What actually changed Android-to-Android messages have been encrypted since 2021\. iMessage between two iPhones has been encrypted since 2011\. The disconnect has been the bridge between the two platforms. A text from your iPhone to an Android friend, or the reverse, made the trip with no end-to-end protection. This made them readable by anyone who could tap the carrier network it passed through. Apple and Google built the encryption on a shared industry standard (the GSMA's RCS Universal Profile 3.0, running a protocol called MLS), so it behaves the same no matter whose phone is whose. This is also a good moment to explain why texting between an iPhone and an Android phone is less of a headache than it used to be. Most of the modern features arrived when Apple adopted RCS in 2024\. The encryption and a few last pieces came with this update. Here's the same iPhone-to-Android conversation, then and now: ![Comparison table: iPhone-to-Android messaging before RCS, with RCS in 2024, and with the 2026 encryption update.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/diagram-rcs-changes.png) The encryption row is the headline. The reactions row is the one you'll feel day to day: an iPhone tapback now lands as a real reaction on your friend's Android screen instead of a separate "Joel liked a message" line. ## How to tell it's on Look for the lock icon next to the conversation. No lock means one of three things: - A phone isn't on the latest software (iPhones need iOS 26.5, Android needs a current Google Messages). - A carrier on one end doesn't support the newest RCS profile yet. - The rollout simply hasn't reached your account. It's on by default, so there's nothing for you to enable. If you want to verify the setting on iPhone, it's under Settings, then Messages, then RCS Messaging, listed as "End-to-End Encryption (Beta)." Leave it on. Switching it off downgrades your cross-platform chats back to the older, unencrypted version. The "Beta" label is real. Apple is still calling this a beta because the rollout leans on carriers catching up and on the other person running current software. Expect more of your conversations to pick up the lock over the coming weeks as it reaches more carriers and phones. ## What isn't protected End-to-end encryption protects what your messages say. It does not hide your footprint. Metadata (who you texted, when, and how often) is still collected. For anything genuinely sensitive, a dedicated app like Signal stays the better choice. Same logic as [what a VPN actually does](https://www.freshfromcache.com/what-a-vpn-actually-does/): it covers specific things and leaves others exposed. Two caveats come with this new privacy. First, cloud backups. A backed-up copy of your conversation can sit in the cloud unencrypted. On iPhone, turning on Advanced Data Protection fixes that. On Android, Google Messages encrypts the text of your backups but not the photos and videos in them. Either way, this is the stored backup, not the live chat. A photo you text a friend is still encrypted on its way to them. Second, the lock only holds while both of you stay on RCS. If a thread drops to SMS, or the lock disappears mid-conversation, something downgraded. The missing lock is your indication the conversation is no longer encrypted. ## Why now? Apple has encrypted iMessage between iPhones since 2011\. Extending that to texts with Android users needed an industry standard that didn't exist until 2025\. Even after the infrastructure was in place, it then took Apple more than a year to switch it on. What finally forced their hand was pressure. In January, the Electronic Frontier Foundation launched a campaign called "Encrypt It Already," aimed at six companies with Apple among them, asking for exactly this. The EFF later called the rollout a victory, with the caveats above. One other company on that list went the other direction. Over the same stretch, Meta [removed encryption from Instagram DMs](https://www.freshfromcache.com/meta-dropped-instagram-encryption/), citing low uptake. There's a side effect for spam, too. Carriers can no longer read encrypted messages to filter junk on their end, so the new standard pushes spam detection onto your phone instead. Samsung is also shutting down its own Messages app in July for US phones on Android 12 or newer. Samsung users will move to Google Messages, which is the Android app that supports this encryption. ## A warning If a text tells you to switch, slow down. Scammers are already using the changeover as bait, sending fake "your messaging app is ending" messages with bad links. The tells are the same ones in [how to spot a phishing email](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). Samsung prompts you inside the app, not with a random text. The upgrade costs nothing and asks nothing beyond updating your phone. Open a thread with a friend on the other platform and look for the lock. If it's there, that chat is encrypted. If not, give it a few days and check again. ## Sources - Electronic Frontier Foundation, the "Encrypt It Already" campaign and its follow-up marking the RCS rollout (January and May 2026): [eff.org](https://www.eff.org/deeplinks/2026/05/victory-end-end-encrypted-rcs-comes-apple-and-android-chats?ref=freshfromcache.com). - GSMA RCS Universal Profile 3.0, which added the MLS encryption standard (2025). - Apple, on RCS end-to-end encryption arriving with iOS 26.5, and Google, on encryption in Google Messages. ### Set up your phone to share your medical info in an emergency URL: https://www.freshfromcache.com/phone-medical-id/ Last updated: 2026-06-29T21:19:00.000Z It's uncomfortable to try and picture yourself in a position where your life may not be in your own hands. You faint in a grocery store, you come off your bike on a summer trail, or you are in a car accident. If you are lucky, there could be a bystander nearby to help. They pick up your phone to call someone… and it is locked. Your phone has a built-in card for exactly this moment. It holds your name, your allergies, the medicines you take, your blood type, and the people who should get a call. The whole point of it is that anyone can read it without your passcode and without unlocking a thing. By the time you finish this, yours will be filled in, and you will have watched it work. Think of it as a note taped to the inside of your front door, the one a neighbor would read if they had to let the paramedics in. You write it once and then it sits there doing nothing until the day someone might need it. ## On an iPhone 1. Open the Health app, the white one with the red heart. 2. Tap your photo in the top right corner, then tap Medical ID, then tap Edit. 3. Fill in what a paramedic would want to know first: allergies, conditions, medicines, blood type. 4. Scroll down and add an emergency contact or two from your address book. Then do the one thing most people skip. Turn on **Show When Locked**. Without it, you have written a note that stays in a locked drawer. While you are in there, turn on **Share During Emergency Call** too, so your details go out on their own if you dial 911. ## On an Android phone The wording shifts a little by brand. 1. Open Settings and tap Safety and emergency. 2. Tap Medical info and fill it in, then tap Emergency contacts and add your people. On a Google Pixel, this lives in a separate app called Personal Safety, under Your info. The toggle that matters here is **Show on Lock screen** (on a Pixel it reads "Allow access to emergency info"). One Pixel quirk worth knowing: the phone needs a working SIM or eSIM to text an emergency contact for you later, so make sure that side is set up. ## The most important step That lock screen toggle is what makes this information useful. Plenty of people fill in every field, feel done, and never flip the switch to display the information. This leaves the card invisible at the one moment it is needed most. Filling it in once is not a guarantee it still works. Phones rearrange these screens with big updates, and a contact can drop off a list without you noticing. So check it yourself, right now, before you close this tab. 1. Lock your phone. 2. Wake it and swipe up to the passcode screen as if you were about to type your code. 3. On an iPhone, tap Emergency, then Medical ID. On Android, tap Emergency call, then View emergency info. If your name and your details show up while the phone is still locked, you are finished. We covered [who gets your photos and accounts after you are gone](https://www.freshfromcache.com/who-gets-your-accounts/) a couple of weeks back. This is the other side of the same coin: the small bit of setup that helps the people around you while you are still here. If you set this up this week for an older parent, or for a kid heading off on their own, I would like to hear how it went. ## Sources - Apple Support, "Set up and view your Medical ID": [support.apple.com](https://support.apple.com/en-us/105072?ref=freshfromcache.com). - Android medical info and emergency contacts: Settings, then Safety and emergency (on a Pixel, the Personal Safety app), per Google Support. ### How to capture fireworks with your phone URL: https://www.freshfromcache.com/capture-fireworks-phone/ Last updated: 2026-08-11T18:29:27.000Z Every Fourth of July, I try to get the perfect shot of a firework. Why? I have no idea. Am I going to look at it later? Maybe. (Probably not.) But every year I stand out there and try anyway. I used to have a nice large field right in front of my house. For years, every Fourth, I have gone out there to watch the fireworks go off, and it is always spectacular. Fireworks in every direction. A couple of those years I brought my drone out, a little DJI Mini, and flew it as high as it would go, hoping for something incredible. The footage was beautiful. It looks like the view from an airplane window, where everything below turns small and peaceful and a little surreal. You get the curve of the horizon, and then little flare trails of fireworks popping up all across it, dozens of people setting them off without realizing how close they are to each other. ![an aerial sunset view of a firework bursting over a darkening town](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/dji_fly_20250704_214722_497_1751690852276_photo_optimized.jpg) A past Fourth of July, shot from my drone. But it still was not *the* shot. I have never gotten the firework photo I actually wanted. Mine come out blurry, too bright, too dark, just bad. I know phones have incredible cameras now, some people upgrade for just that. So what gives? Why can't I easily take a good firework photo with the phone in my pocket? ## It's not you Here is what I found out, and it was kind of a relief: I was not doing it wrong, and neither are you. Google, Samsung, and Apple spend their whole ad budgets telling you the camera is the best part of the phone. Apple even bragged about a movie shot entirely on an iPhone. So when the fireworks start, you would think the expensive computer in your hand could keep up. When it can't, you assume you are doing something wrong. You are not. Almost every fireworks guide online hands you instructions written for a real camera: switch to manual, set the shutter to a few seconds. Most phones can't do that in the camera app they ship with, and the few that can bury it three menus deep. You have been following directions for something your phone might not do. The answer isn't just better camera gear. It just comes down to a few habits and one button you have probably never tapped. ## Five ways to get the shot Five habits, in order. No new camera gear required. **1\. Hold the phone completely still.** In the dark, the phone holds the shutter open longer to soak up light, so the smallest shake smears the whole shot. Prop it on a railing, a car roof, a bag, anything solid. No prop? Tuck your elbows into your sides and breathe out as you tap. This habit fixes more bad firework photos than every setting combined. **2\. Turn the flash off.** It lights up nothing a hundred feet away, and it adds a delay that makes you miss the burst. It is probably already off or set to auto, but check it anyway so it can't fire at the wrong moment. Tap the flash icon until it shows off. **3\. Tell the phone it is dark, then lock it in.** Left alone, your phone brightens the black sky to "fix" it, so the firework blows out to a white blob with no color. You want the opposite: darken the shot, then stop the phone from changing its mind. Three quick moves: - **Aim and lock.** Tap the spot where the bursts are going off, then press and hold it until the focus ring turns yellow. That locks focus so it won't drift. - **Pull the exposure down.** Drag the exposure control until the preview looks almost too dark. On an iPhone or Samsung, a little sun slider appears right where you tapped. On a Pixel it is tucked away: tap the controls icon in the bottom-right corner and drag **Exposure** (flip on Quick access controls in the camera settings if you want it to appear on every tap, since Google ships it off). - **Leave it there.** Locked focus plus a darkened sky is the combination almost nobody finds, and it is what keeps a burst sharp and full of color instead of white and washed out. ![the Pixel exposure control pulled down so the sky stays dark](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/Screenshot_20260623-170154-1.png) Drag the exposure down until the preview looks almost too dark. **4\. Frame wide and leave room up top.** You can't predict where a burst will open, so a wide shot catches it. Put something solid along the bottom, a treeline, the crowd, the skyline, water if you have it, and leave the top two-thirds for the sky. A burst floating in pure black looks like a screensaver; a burst over your town looks like a photo. And do not pinch to zoom, it turns everything to mush. Crop it later instead. **5\. Fire on the launch and** [**take way too many**](https://www.freshfromcache.com/why-is-my-phone-storage-full/)**.** A shell takes a second or two to bloom, so tap when you see it climb, not when it peaks. Then keep shooting. Most frames will miss, and that is fine. The grand finale looks the best to your eyes and photographs the worst, too much smoke and light at once, so your keepers usually come from the middle of the show. ## Long Exposure This is the setting I never experimented with. Your phone almost certainly has a mode built for exactly this, a long exposure that holds the shutter open and paints the firework's trail across the frame for you. You do not set anything. You just tap. **On my Pixel** (and most Androids that have something like it): open the camera and swipe the mode strip over to **Long Exposure** (it sits right next to Action Pan). Frame it, hold still, and tap as a burst goes up. ![the Pixel camera mode carousel with Long Exposure selected](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/Screenshot_20260623-162206-1.png) Swipe the camera modes over to Long Exposure (it sits right next to Action Pan). The Pixel even saves a normal version of the shot next to the long-exposure one, so one tap gives you two tries and it is hard to come away with nothing. **On an iPhone:** the closest built-in trick is **Night mode**, which switches on by itself in the dark (the moon icon turns yellow). Tap it and slide the timer up to a few seconds, then hold still. There is also a fun one: shoot with **Live Photo** on, then open the shot in Photos, tap the **Live** label in the corner, and choose **Long Exposure** for the streaked look. It is hit or miss on fireworks, but it costs nothing to try. **On other Androids,** the wording changes but the idea is there: | Phone | Easy one-tap mode | Where the trail control lives | | --------------------- | ----------------------------------- | ---------------------------------------------------- | | Samsung Galaxy | Night mode (turns on automatically) | More > Pro > Shutter speed | | OnePlus | Nightscape (automatic) | More > Long Exposure > Light painting | | Xiaomi / Redmi / Poco | Night mode (automatic) | More > Long Exposure > Neon trails or Light painting | | Motorola | Night Vision (moon icon, automatic) | no true long exposure built in (see below) | These easy modes usually fake the long exposure by stacking several photos into one, which is why fireworks sometimes come out a little stuttered. It still looks good. It is just not a true open shutter. ## Pro-mode (optional) Skip this if the one-tap mode is already giving you what you want. But if your phone has a **Pro** or **Manual** mode, you can control the trail yourself. On my Pixel 10 Pro, I open the camera controls, tap **Shutter Speed**, and set it somewhere between **1 and 4 seconds**. One to two seconds gives tight, defined bursts; three to four gives long, layered trails. Then I drop the ISO low (around 100), lock the focus out at the distance, and pull the exposure down so the sky stays black. ![the Pixel Pro mode shutter speed set to two seconds](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/Screenshot_20260623-170425-1.png) In Pro or Manual mode, set the shutter speed to one or two seconds. You need a tripod or a solid surface for this, because a two-second shot held in your hand will always smear. ![a long exposure smeared by movement, where the camera drifted and every light became a streak](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/dji_fly_20250704_215424_507_1751691272321_photo_optimized.jpg) Results if moving while using long exposure. Same idea on a Samsung (More > Pro), a OnePlus, or a Xiaomi (Pro mode): find the shutter speed, set it to a second or two, keep the ISO low, prop it up. One catch: Motorola's built-in Pro mode won't slow the shutter past about a quarter second, nowhere near the one or two seconds you need, so on a Moto you would need a separate camera app to get real trails. ## Why your old shots came out bad Now you can see what was going wrong. On full auto, the phone brightened the sky and blew the bursts out to white. The focus hunted in the dark and landed on nothing. Pinch-zoom turned the bursts to paste. And handheld, in the dark, everything shook. So if those old shots felt like your fault, they weren't. The phone was guessing, confidently. ## Good all year round Once you have this, fireworks are just the start. The same setup, dark scene, long exposure, steady phone, turns a sparkler into glowing handwriting, makes light trails out of passing traffic, and turns a flashlight into a paintbrush. It is a good rainy-night thing to mess around with, and it is how you practice before the Fourth so you are not fumbling with menus during the show. (It works for video too, but that is a whole other article.) ## Always learning I am not a photography expert. The real photography buffs are probably reading this and wincing. This is something I have struggled with for years and actually wanted to solve, so I am learning it right alongside you, not handing it down from on high. This section is going to grow. As I keep testing this, I will add what worked, what flopped, and what surprised me, with the actual shots. Hint: if you come back and this article has new firework photos in it, that means I finally got one I am proud of. If it doesn't, well, there is always next year. **June 23, 2026: the indoor test, and the moment the easy mode let me down.** As I was researching the article, I had to give this a try. So I ran the experiment in a dark room with a flashlight standing in for a firework. It did not go the way I expected, which was a useful learning experience. First I just got blur. Smeared, doubled light, nothing like a trail. That one was on me: the phone was moving instead of the light. Setting a three-second timer and tapping to lock focus before the shot fixed it, because my hands were off the phone while it ran. I also had the direction wrong. For a light trail, the camera has to see the light source, not a lit-up wall. So you point the light at the lens and move the light while the phone stays still. ![a clean light trail, drawn by pointing the flashlight at the lens and moving it while the phone stays still](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/PXL_20260624_004455663.LONG_EXPOSURE-01.jpg) Failed experiment The trouble started when I tried to draw with the light on Long Exposure mode. The trail kept disappearing. I discovered the Pixel's Long Exposure is not a true open shutter. It records for a few seconds, then an algorithm decides what counts as a "real" moving light and blends the rest away. A dim flashlight in a dark room seems like noise, so the phone wipes it out. My best try came back as a muddy, half-lit photo of me holding the light, no trail at all. ![dim, blurry computational long-exposure attempt that erased most of the trail](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/PXL_20260624_011236839.LONG_EXPOSURE-1.jpg) Joel failing to create a light trail The real trail came from turning Long Exposure off and taking over the shutter controls by hand. Open Photo mode, Pro Controls, Shutter Speed. Set it at two seconds (see above). Make sure you have the timer on, focus locked, light aimed at the lens. I waved the flashlight like a madman and the camera drew the entire path as one continuous line. I was standing pretty close to the lens, and it still came out clean. ![a clean, continuous squiggle of light on a blue field, manual two-second shutter](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/PXL_20260624_012324060-1.jpg) Behold So here is the first thing I would tell you before the Fourth of July. The one-tap mode is genuinely great when there is light to work with, and on a base Pixel, Night mode may be all you ever need. But on a dim or distant subject it can give up, and you will think you broke it. You didn't, the phone just stopped recording what it could not make sense of. If your camera has a Pro or Manual mode, that is your backup. ## The real reason to get the shot It's not about getting the perfect shot to post on social media or brag about. The real reason you might want to get the perfect shot is to bring you back to that moment in time. The fun, the excitement, the thrill in the moment you hear the boom and wait for the lights to appear. When you look back on photos like that, they help [bring those memories to the foreground](https://www.freshfromcache.com/yearly-photo-book/). Why not have a photo that looks as good as it is special? Got a firework shot you are proud of, or one that came out hilariously bad? Reply and send it to me at joel@freshfromcache.com. I want to see both. And while your camera is pointed at the sky, plenty of cameras are pointed back at you, some with no blinking light to warn you. If that is the rabbit hole you want next: [Are those smart glasses recording you? How to tell](https://www.freshfromcache.com/smart-glasses-recording-you/). ## Sources - A hands-on guide built on my own testing; the methods use built-in phone camera features. - Google Pixel Camera Help, on Motion mode and Long Exposure: [support.google.com](https://support.google.com/pixelcamera/answer/14106982?ref=freshfromcache.com). - Apple Support documents Night mode and Long Exposure for the iPhone Camera and Photos apps; Samsung, OnePlus, Xiaomi, and Motorola document their own Night and Pro modes in their camera help. ### Are those smart glasses recording you? How to tell URL: https://www.freshfromcache.com/smart-glasses-recording-you/ Last updated: 2026-08-11T18:28:53.000Z Have you ever stood next to somebody and wondered if their sunglasses were recording you? Until somewhat recently, that sentence might have sounded ridiculous. In 2026, not so much. Dubbed “smart glasses,” they look like regular glasses, but there’s a camera embedded in the frame. The only thing telling you if it’s on or not is a light smaller than a grain of rice. I look into what these things actually do, where the footage goes, and what you can do when you’re the one being recorded. ## What they are The pair most people have heard of is the Ray-Ban Meta line, built by Meta with the eyewear giant Luxottica. There’s the Ray-Ban Meta Wayfarer, the Oakley Meta HSTN, a wraparound Oakley called the Vanguard, and a newer model, the Ray-Ban Display, which puts a small screen inside the lens. They run from about $300 to $800. They take photos and video. They livestream. They play audio in your ears and take phone calls. You can talk to the built-in assistant by saying “Hey Meta,” ask it what you’re looking at, and have it translate a sign in front of you. The Display model can show you messages and directions in the corner of your vision. The technology itself is impressive. Meta isn’t the only one. Google is building its own with Warby Parker, Snap has a pair, and Apple is rumored to be working on something. It’s a new industry trend. The Ray-Bans are just the ones you’ll see first. What makes them different from a phone is that they look like eyewear. Reviewers keep noting that friends didn’t realize the cameras were there. It’s the design goal, and it’s also the problem. ![A pair of black Ray-Ban sunglasses resting on a car dashboard](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ray-bans.jpg) A regular pair of Ray-Bans. The camera versions are built to look just like ordinary frames. Photo: Hiding Ninja / Unsplash ## A small recording light When the glasses record, a small LED on the front lights up. That’s the indication that signals to everyone around the wearer that a camera is rolling. It’s notoriously a poor indicator. It’s tiny and easy to miss in daylight. And the obvious defeat, covering it with tape, doesn’t work the way you’d expect: Meta built the glasses to stop recording when the light is blocked. So the people determined to record anyway pay to get around it. For $50 to $100, modders will drill the light out entirely, which beats that protection and leaves the glasses looking factory-new. The Wall Street Journal found these services advertised in 30 states. There are also stick-on caps that fool the sensor for around $60, and pinhole-camera glasses sold online that never had a light to begin with. Lawmakers are starting to notice. A bill introduced in Pennsylvania on June 5 would make it illegal to sell or record with smart glasses whose indicator light has been disabled. Compare that to a phone. When someone points a phone at you, you know. They lift it, they hold it up, they aim. Glasses skip all of that. The recording is hands-free, it can run continuously, and it points wherever the wearer is looking. The civil-liberties group EFF made this point plainly in June: glasses make recording frictionless and hard to notice in a way a raised phone never is. ## Where the video goes The footage doesn’t just sit on the glasses. It moves to the phone app, and from there it can go to Meta’s servers. It’s not as simple as one opt-in box. Your photos and videos stay on your phone unless you share them, turn on cloud processing, or ask Meta AI a question about them. But using your voice is a type of “opt-in.” The moment you say “Hey Meta,” the recording gets saved by default, and Meta removed the setting that used to let you turn that storage off. And once your content reaches Meta, people can see it. Humans reviewing what the glasses recorded. In February 2026, two Swedish newspapers reported that contractors in Kenya, working for a company called Sama, were reviewing footage from the glasses as part of Meta’s AI training. The workers described seeing bathrooms, people undressing, credit card numbers, and faces that were supposed to be blurred and sometimes weren’t. Meta has since ended its contract with Sama. ## A lawsuit In March 2026, two buyers sued Meta and Luxottica over the glasses, and the case has since grown to nineteen people across sixteen states. It’s called Bartone v. Meta Platforms, filed in federal court in Northern California. The argument is highly specific. Reviewing footage is legal. The problem is the marketing. Meta sold the glasses with the promise they were “designed for privacy, controlled by you.” That slogan conflicts with overseas workers cataloging the video. The case centers on the people with no control over those settings at all. Bystanders and partners caught on camera never bought a product or agreed to the terms. It’s early. Meta hasn’t filed its defense, and nothing here has been proven. These are allegations. ## More to worry about than the camera **Audio.** The glasses record sound, not just picture, and in the United States, recording audio carries stricter rules than recording video. I’m not a lawyer, so I’ll keep it simple: every state sets its own rules on recording conversations, and some require everyone’s consent, not just the wearer’s. If you want to know your state’s rules, the [Reporters Committee for Freedom of the Press](https://www.rcfp.org/reporters-recording-guide/?ref=freshfromcache.com) keeps a plain, state-by-state guide, or ask a lawyer. **Face search.** A camera that knows who you are is different from a camera that just records you. In 2024, two Harvard students wired a pair of Ray-Ban Metas to face-search tools and showed they could put a name to a person walking by, then pull up where they might live and work. They called it I-XRAY, and they built it to prove a point, not to sell it. Meta says it isn’t putting face recognition in the glasses, though the New York Times reported in early 2026 that an internal effort, called Name Tag, was under consideration. The demo showed the pieces already exist and already fit together. ## What you can do If you’re the one across the table: - **Learn the light.** On the Ray-Ban Metas it’s a small LED on the front corner of the frame, opposite the camera, and it stays lit the whole time a recording runs. If it’s on, the glasses are capturing. Just remember a drilled pair won’t show any light. - **It’s fine to ask.** “Are those recording?” is a normal question now, the same way “are you filming this?” became normal. You can also ask them to take the glasses off. - **Know where they don’t belong.** Plenty of places already say no: locker rooms, some workplaces, courtrooms, anywhere cameras were already banned. The glasses don’t get an exception for being in disguise. If you own a pair, the controls are there, but partial. Meta moves them around, so check yours: - **Turn off “Hey Meta.”** In the Meta AI app you can switch off the wake word and trigger the assistant from the touchpad on the right temple instead. That cuts down on recordings you didn’t mean to start. - **Keep your media off Meta’s servers.** Turn off cloud processing so photos and videos stay on your phone. Cloud copies are deleted after 30 days either way. - **Delete your voice clips.** You can’t stop them being saved, but you can clear them in the app, and stored recordings are kept up to a year if you don’t. - **The hard off switch is physical.** The power slider on the left temple kills the camera and microphone completely. [In a doctor’s office or a private meeting](https://www.freshfromcache.com/should-you-let-ai-record-your-doctor-visit/), that’s the only off switch you can trust. - **Look up your local laws on recording audio, especially.** The RCFP guide above covers all 50 states. --- ![A Google Glass headset on a wooden table, its small camera and clear prism display visible](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/google-glass-headset.jpg) Google Glass, 2013\. Photo: Clint Patterson / Unsplash I’ve never worn a pair of smart glasses. I’d be lying if I said they didn’t intrigue me. I still remember being wow’d by Google’s attempt at this same thing with Google Glass. I remember the backlash people had to being recorded then. Google Glass was especially obvious and these are not. With so many apps, services, and devices tracking our every move these days, do we need to be alarmed there will be another vehicle for that data? Maybe. If I ever own a pair of these, I won’t be using “Hey Meta.” ## Sources - Electronic Frontier Foundation, "Think Twice Before Buying or Using Meta's Ray-Bans" (March 2026): [eff.org](https://www.eff.org/deeplinks/2026/03/think-twice-buying-or-using-metas-ray-bans?ref=freshfromcache.com). - The Wall Street Journal, on services that disable the recording light advertised across 30 states (2026). - Reporting on contractors in Kenya reviewing glasses footage, and the lawsuit Bartone v. Meta Platforms (N.D. Cal., filed March 2026), covered by [Fortune](https://fortune.com/2026/03/27/meta-smart-glasses-filming-watching-workers-lawsuit-privacy/?ref=freshfromcache.com). - The New York Times, on Meta's internal "Name Tag" face-recognition effort (early 2026), and Harvard students' I-XRAY demonstration (2024). - Reporters Committee for Freedom of the Press, state-by-state recording-consent guide: [rcfp.org](https://www.rcfp.org/reporters-recording-guide/?ref=freshfromcache.com). - Pennsylvania House bill introduced June 5, 2026, on smart glasses with disabled indicator lights. ### The scam that gets you to do the hacking yourself URL: https://www.freshfromcache.com/newsletter/do-the-hacking-yourself/ Last updated: 2026-06-30T21:52:20.000Z The standout this week is a scam you run on yourself. The newest fake CAPTCHA does not ask you to find the traffic lights. It asks you to paste a command that infects your own machine, and it works because it looks like the box you click without thinking. After that the issue ranges wide: a router that can sense you move through a room, stolen iPhones turning into paperweights, and the UK deciding who has to prove their age online. The tip is the fun one for once, a Wi-Fi trick you will use at your next dinner party. If you only have a minute, read the CAPTCHA one. --- [**The fake CAPTCHA scam you run yourself**](https://www.freshfromcache.com/fake-captcha-scam/) The newest version does not ask you to find traffic lights. It asks you to press a couple of keys and paste something to "verify you are human." The thing you paste is malware, and you installed it by hand. If a checkbox ever sends you to your keyboard, stop. *News* --- [**Your Wi-Fi Router Can Track Movement in Your Home**](https://www.freshfromcache.com/wifi-motion-sensing/) Newer routers can read the dips in their own signal to tell when someone moves through a room. It is a real, shipping feature sold as home security, and for now it senses motion, not who you are. Good to know what your own hardware can already do before the marketing explains it to you. *News* --- [**Stolen iPhones are becoming worthless to thieves**](https://www.freshfromcache.com/stolen-iphones-worthless-to-thieves/) A stolen iPhone is becoming an expensive paperweight for whoever grabs it, now that the locks survive a factory reset. The piece has the one setting to confirm is on. *News* --- [**How the UK plans to keep teens off social media (and what it means for adults)**](https://www.freshfromcache.com/prove-your-age/) The UK wants platforms to check ages, which means more of us proving we are adults to use ordinary sites. The piece covers what that looks like and why the burden lands on everyone, not just kids under 16. *News* --- [**5-Minute Tech Tip: Share your Wi-Fi without ever spelling out the password**](https://www.freshfromcache.com/share-wifi-qr-code/) Your phone can turn your home network into a QR code that any guest scans with a camera, iPhone or Android. No more reading "capital R, lowercase q, was that a zero" off the back of the router. Five minutes, once. *Learn* --- **Scary Headline of the Week** The headline: "24 billion passwords leaked." (Some outlets say 16 billion. Same genre.) It reads like every account you own fell out the door at once. What happened: researchers at [Cybernews](https://cybernews.com/security/24-billion-credentials-data-leak/?ref=freshfromcache.com) found a giant pile of login records compiled from old breaches and from malware that scrapes saved passwords off infected machines. There was no new break-in at Apple, Google, or your bank, and it was pulled offline within days. Nobody could even count the duplicates. What to do: skip the panic of changing every password you own. Check your email at [haveibeenpwned.com](https://haveibeenpwned.com/?ref=freshfromcache.com), change anything you reused, and let a password manager carry the rest. The durable answer is to stop having a password that can be stolen at all, which is the point of [passkeys](https://www.freshfromcache.com/what-the-heck-is-a-passkey/), and to turn on [MFA](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/) anywhere passkeys are not an option yet. --- **If you only read one:** the CAPTCHA scam. It is the one you could fall for between now and next Tuesday. --- Fresh From Cache grows when readers pass it along. If you enjoyed this issue, forward it to someone who might too. Reply and tell me which of these sent you to go change a setting. Joel ### Three breaches in one week, and your medical records are the target URL: https://www.freshfromcache.com/three-breaches-in-one-week/ Last updated: 2026-08-11T18:28:41.000Z In one week this June, three names you would recognize landed in data breaches. One Medical, the primary care chain Amazon owns. Kodak. And Novo Nordisk, the company behind Ozempic and Wegovy. Three industries. One week. And in every case, the data at risk was personal and medical. This is not a run of bad luck. Health records have become one of the most sought-after things to steal, and a credit card shows you why. A stolen card is a quick fix. Cancel it and the problem ends. You cannot cancel your medical history, your Social Security number, or your date of birth. They do not expire and they do not reissue. That permanence is what makes them so valuable. ## Confirmed vs. claimed The three are not the same kind of event, and One Medical is the clearest example of why. The company confirmed that someone got into a third-party storage system holding archived records from Iora Health, a senior-care group it absorbed years ago. It says a limited number of patients were affected. That is the confirmed part. Then there is the claim. An extortion crew says it took 8.8 terabytes and has threatened to publish unless One Medical pays by June 22\. No sample data backs that up. One figure comes from the company telling you what it found. The other comes from the people who stole the data and want to get paid. Those are very different things, and they tend to share a headline. Novo Nordisk is the heavier confirmed case. Intruders reached its internal systems and took clinical trial data. The hackers who claimed it say they were inside for about two months. Kodak rounds out the week with a confirmed breach of its own. Back in May, New York City's public hospital system disclosed that attackers took medical data and fingerprints on more than 1.8 million people, through a vendor it has not named. For most of us, none of this is preventable. The breach happens inside a company you handed your information to, often through a vendor you have never heard of, on a system you will never log into. You cannot freeze Amazon's vendors for them. You *can* freeze your own credit. Unfortunately the steps you can take are reactive, not proactive. ![Going through statements and a letter at a desk](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/bank.png) ## A few steps you can take **Freeze your credit.** A freeze locks new lenders out of your file, which is what stops someone opening accounts in your name. It is free at all three bureaus (Equifax, Experian, and TransUnion), and you lift it just as easily when you need credit. Monitoring only tells you after someone has used your information. A freeze stops them first. [**Read the breach notice**](https://www.freshfromcache.com/that-sketchy-letter-from-your-hospital-might-be-real/)**, do not skim it.** When a company notifies you, it has to say what was taken. Names and birthdates are one problem; Social Security numbers and medical records are a worse one. The notice also spells out what you are owed, often free monitoring. And "limited," in a company statement, means the company believes few people were hit. It does not mean you are in the clear. **Check your explanation of benefits.** That is the summary your insurer sends after it pays a claim, the one listing the care that got billed (on Medicare it arrives as a Medicare Summary Notice). Read it. Care you never received, billed under your name, is the clearest sign someone is using your medical identity. Most people toss these. Do not. **Treat any surprise bill or account message as suspect.** A health breach feeds the next scam real details about you, so a text about a bill you half-recognize seems more legitimate than generic spam. Slow it down. Hang up. Find your provider's number yourself, and call them. If you owe them money, they'll wait. (Same instinct as spotting a [phishing email](https://www.freshfromcache.com/how-to-spot-a-phishing-email/): verify through a channel you chose, not the one they handed you.) **Use IdentityTheft.gov** [**if something is already wrong**](https://www.freshfromcache.com/what-to-do-after-a-scam/)**.** It is the FTC's free walk-through for identity theft, and it generates the reports and letters you will need. Faster than improvising. If you run a business, there is a different angle. The One Medical access came through a third-party storage system. The New York hospital breach came through an unnamed vendor. Neither started at the front door. The companies you hand customer data to are part of your own attack surface, whether you vetted them or not. None of these steps will *stop* a breach. The company holds the data, loses the data, and mails the letter. The cleanup falls to you. Luckily it is mostly free and mostly quick. Freeze the credit. Read the notices. Watch your own statements. You cannot control the breach, but you can control what happens after it. Have you frozen your credit yet, or is it one of those things still on the list? And if you have ever opened a breach notice and couldn't tell how worried to be, tell me about it. ## Sources - One Medical breach and the ShinyHunters extortion claim, reported by [Cybernews](https://cybernews.com/security/amazon-one-medical-data-breach/?ref=freshfromcache.com) (June 2026), plus One Medical's own notice. - Novo Nordisk breach disclosure, reported by [BleepingComputer](https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/?ref=freshfromcache.com) (June 2026), and the Kodak breach disclosure. - NYC Health + Hospitals breach, reported by [TechCrunch](https://techcrunch.com/2026/05/18/nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/?ref=freshfromcache.com) (May 2026). - Federal Trade Commission, [credit-freeze guidance](https://consumer.ftc.gov/articles/credit-freezes-and-fraud-alerts?ref=freshfromcache.com). - FTC identity-theft recovery: [IdentityTheft.gov](https://www.identitytheft.gov/?ref=freshfromcache.com). ### Share your Wi-Fi without ever spelling out the password URL: https://www.freshfromcache.com/share-wifi-qr-code/ Last updated: 2026-08-11T18:29:30.000Z It is the most predictable moment of any dinner party. Someone holds up their phone and asks for the Wi-Fi password, and you start reciting the string the router came with: capital R, lowercase q, [was that a zero or the letter O](https://www.freshfromcache.com/copy-text-from-a-photo/). Three tries later they are finally online and you have aged a year. Your phone can end that ritual. Both iPhones and Android phones can turn your home network into a QR code, the little square barcode. Your guest points their camera at it, taps the link that pops up, and they are connected. No spelling, no sticky note on the fridge, no handing your phone around the table. It works across the fence too: an iPhone can make a code an Android guest scans, and the other way around. Think of the code as a little say-the-password-for-me card. You make it once. From then on you either hold up your screen, or you screenshot it and print it and stick it on the fridge for good. ![Share your Wi-Fi with a QR code in three taps: open your Wi-Fi settings, tap your network, show the QR code. Works on iPhone and Android.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/wifi-share-steps-v2.png) iPhone starts in the Passwords app, Android in Settings. From there it is the same three taps. ## On an iPhone Open the Passwords app, [the one with the key icon](https://www.freshfromcache.com/start-using-a-password-manager/) (it became its own app a couple of versions back). Tap Wi-Fi, tap the network you are on, then tap Share. Up comes the QR code. Hold the screen up and have your guest open their camera and point it at the code. ## On an Android phone Open Settings, then Network and internet, then Internet (some phones still call it Wi-Fi). Tap the gear icon next to the network you are connected to, then tap Share (on a Samsung it reads QR code instead). Your phone may ask for your PIN or fingerprint first. The QR code appears on screen for your guest to scan. The wording wanders a little by brand. On a Samsung it is Settings, then Connections, then Wi-Fi, then the gear icon, then the small QR code at the bottom corner. On a Pixel you can also swipe down from the top of the screen, tap Internet, and hit Share Wi-Fi in the bottom corner. Same code waiting at the end of any of those paths. ## Before you hand it out That QR code has your real password baked inside it. Anyone who snaps a photo of it can get on your network, so show it to a guest you trust and keep it off anything public like an Instagram story. If people are in and out of your house a lot, the grown-up version is a guest network. That is a separate name and password your router broadcasts just for visitors, so you can hand the code to anyone and keep them off the laptops and cameras on your main network. That is a fifteen-minute job for another day. So make yours right now, before you close this. Walk through the steps above until the QR code is sitting on your screen, then screenshot it so it is saved in your photos. The next time someone asks for your Wi-Fi, you do not say a word. You turn your phone around. Tell me the worst Wi-Fi password you have ever had to read out loud to a guest. I have seen some hostile ones, and I want to know yours. ### The fake CAPTCHA scam you run yourself URL: https://www.freshfromcache.com/fake-captcha-scam/ Last updated: 2026-08-11T18:28:37.000Z I click "verify you're human" a few times a week without thinking about it. Match the traffic lights, type the wavy letters, move on. That habit is the basis of a scam the FTC warned about on June 8. The scam works like this. You are on a website and a box pops up that looks like a normal CAPTCHA check. Instead of asking you to match pictures, it tells you to press a few keys. On Windows that is the Windows key and R, then Ctrl and V, then Enter. The box calls it a security step. Those keystrokes open a built-in Windows tool and run a command the website already slipped onto your clipboard. The command downloads malware. You installed it, by hand, while trying to prove you were not a robot. ![A recreation of a fake CAPTCHA box that tells the user to press Windows+R, Ctrl+V, and Enter.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/captcha-verify-mock.png) A recreation of a fake CAPTCHA. A real check never asks you to press keys or paste anything. A real CAPTCHA exists to make a person do a small task a computer cannot, so a website can tell a human is on the other end. This fake version turns that around. It uses the habit you built from years of real checks to get you to run the one command the attacker's own code could not run on its own. A website cannot reach into Windows and start a program, but you can. So it walks you through doing it. The part that catches people off guard is what their antivirus does about it, which is mostly nothing. Antivirus watches for a suspicious file showing up and being opened. In this attack no file shows up. The command runs programs that already live on your computer. Because those tools are supposed to be there, the alarms that would normally trip do not. The malware ran because you ran it, not because it slipped past a scanner. That safety net does nothing for this scam. This is not a fringe trick. The security world calls the method ClickFix, and it has been climbing fast. The security firm ESET tracked a 517% surge in these copy-and-paste attacks through the first half of 2025\. That put it second only to ordinary phishing. Microsoft published a full breakdown of the technique and now treats it as one of the most common ways an attacker gets a first foot in the door. The FTC putting out a plain consumer alert about it means that it has reached regular people, not just companies. The disguise keeps changing, which is why memorizing one screen does not help. Sometimes the box looks like a Cloudflare check. Sometimes it is a fake "this document failed to load, click to fix" message, or a fake meeting-join screen. Some versions point you at a different Windows tool instead of the Run box. Microsoft even found a version aimed at Mac users, so this is not a Windows-only problem. The disguise differs but the request underneath is always the same: leave your browser and run something. ![A recreation of a fake browser-error page telling the user to open PowerShell and paste a command.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/captcha-error-mock.png) A recreation of the fake browser-error version. The "Copy fix" button is the trap. You do not have to go anywhere sketchy to hit one. Attackers plant these pages on real websites they have broken into, buy ads that lead to them, and seed links through fake job posts and poisoned search results. One campaign this spring rode in through a flaw in the software that runs a lot of small blogs and business sites. The page can show up on a site you have trusted for years. You can keep yourself safe with one rule. A real CAPTCHA never sends you out of your browser. Ever. It will never ask you to press Windows and R, open a terminal, or paste something and press Enter. If a "verification" step asks for any of that, it is not a real check. Close the tab. You will not break anything by closing it, and a legitimate site will let you back in the normal way. [If you think you already fell victim to the scam](https://www.freshfromcache.com/what-to-do-after-a-scam/), the FTC's list of steps is solid. Do them in this order: - Disconnect that device from the internet. That cuts off the attacker's live access to your accounts. - Run a security scan to clear the malware, and keep your software and apps updated so the scan can catch current threats. - From a different device, change your important passwords. Turn on [two-factor authentication](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/) where you can. The malware may have grabbed what was saved in your browser before you pulled the plug. - Report the page to the FTC at ReportFraud.ftc.gov. ![A hand unplugging a power cord from a wall outlet.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/unplug-recovery.jpg) If you already ran it, getting the device off the internet comes first. This is the same family of tricks as a [phishing email](https://www.freshfromcache.com/how-to-spot-a-phishing-email/), so if your guard is already up for one, you are most of the way to spotting the other. What these attacks are after is your logins. The malware reads saved passwords and the session tokens your browser uses to stay signed in, and those tokens can let someone skip your password entirely. That is one more reason [passkeys](https://www.freshfromcache.com/what-the-heck-is-a-passkey/) are worth turning on where they are offered, since there is no saved password for the malware to lift. If you run a small business, two habits help. Keep the computer that holds the keys to everything separate from the one used for daily browsing, so a bad afternoon on the web does not hand over the admin account. And [use your password manager as a second opinion](https://www.freshfromcache.com/start-using-a-password-manager/). It only fills your login on the exact site where you saved it, so if it refuses to fill on a page that looks right, treat that oddity as a warning. The bait here is ordinary, and that is the whole problem. Nobody is scared of a "prove you're not a robot" box. That is why this works. So my advice is simple: if a website ever tells you to press keys or paste something to prove you are human, close the tab. The two boxes above are recreations, not live screenshots, so there is no working command in them to copy. If you want to see the genuine pages, the security firm [Trend Micro](https://www.trendmicro.com/en%5Fus/research/25/e/unmasking-fake-captcha-cases.html?ref=freshfromcache.com) and [Duke University](https://security.duke.edu/news/beware-fake-captchas-and-error-message-scams/?ref=freshfromcache.com) both show real examples. If you have seen one of these in the wild, or you got caught by one, reach out. I would like to hear about it, and real examples help me show other people what to watch for. You can email me at joel@freshfromcache.com. **Sources:** [the FTC consumer alert](https://consumer.ftc.gov/consumer-alerts/2026/06/how-spot-captcha-scam?ref=freshfromcache.com) (June 8, 2026), [Microsoft's analysis of the technique](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/?ref=freshfromcache.com), [ESET's H1 2025 Threat Report](https://www.eset.com/us/about/newsroom/research/eset-threat-report-clickfix-fake-error-surges-spreads-ransomware-and-other-malware/?ref=freshfromcache.com), and [Trend Micro's breakdown of real campaigns](https://www.trendmicro.com/en%5Fus/research/25/e/unmasking-fake-captcha-cases.html?ref=freshfromcache.com). ### Your Wi-Fi Router Can Track Movement in Your Home URL: https://www.freshfromcache.com/wifi-motion-sensing/ Last updated: 2026-08-11T18:28:30.000Z Your Wi-Fi router can tell when someone walks across your living room. No camera, no microphone, no GPS. It's not theoretical. Comcast already sells this in millions of homes, as a feature called WiFi Motion. It works today. How much it can see depends on which version is sitting in your house. The mechanism sounds like magic but it's not. Your router fills your home with radio waves. When you walk across a room, your body nudges those waves, and the router measures the change. It works in the dark because radio does not need light. It works through walls because radio already passes through drywall. The technology behind it reads channel state information (a constant readout of how your Wi-Fi signal travels), which your connected devices report many times a second. A German research team used a related stream called beamforming feedback (data a device sends so the router can aim at it), which travels without encryption. The version you can buy today is basic. It tells you motion happened in a zone, like near the front door, and pings your phone. It does not know who you are. Researchers have pushed it much further. At the Karlsruhe Institute of Technology, a team recorded ordinary Wi-Fi traffic and matched people to their bodies with up to 99.5 percent accuracy in a test of 197 participants. Change your walk or carry a backpack and accuracy fell to between 50 and 60 percent. One of the researchers, Thorsten Strufe, described it as working like a camera, except it uses radio waves instead of light, so it does not matter whether you carry a phone. Turning your phone off does not turn you off. The risk splits into two piles. The first pile is the gear on the market, an opt-in feature that stays off until you turn it on. Comcast's WiFi Motion runs on a leased Xfinity gateway (an xFi Gateway such as the XB7 or XB8), and you enable it yourself in the Xfinity app. The providers sell the alert itself: a camera-free way to know when something moves in an empty house, the kind of home-monitoring add-on that used to need a sensor on every door. Cognitive Systems, a Canadian company, licenses similar software to dozens of internet providers, and Plume packages it into its own service. The detection runs on the devices already on your network, so there is no new hardware. These tell you something moved. They do not identify you. You can turn them off in the same app that turned them on. The other pile is still in the lab. Identifying a named person, reconstructing posture, reading breathing. That work, including the Karlsruhe study and earlier projects at Carnegie Mellon, needs special configuration, extra sensing points, or research hardware. It is not a setting waiting in your router's menu. The Wi-Fi standard now includes a sensing track, called 802.11bf, finalized in September 2025, so future routers will be built to do this on purpose. The money is moving the same way: in February 2026, the home-security company ADT paid 170 million dollars for a startup whose whole business is reading these signals, and it plans to fold the technology into its products by 2027\. That is the direction, not today's default. The typical things you do for privacy don't protect you here. A camera has a cover you can tape over and a light that blinks. Wi-Fi sensing has neither. There is no glowing dot, no obvious place for a sticky note, and almost no rule forcing a company to tell you it is on. ![An older woman baking in a bright kitchen](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/older-adult-kitchen.jpg) Presence sensing is genuinely useful for older people living alone. The same sensing that feels invasive is a real help for older people living alone, which is why companies are pouring money into it. A camera is a non-starter in a bathroom or a bedroom, which is exactly where most falls happen. A pendant or a smartwatch only helps if the person remembers to wear it, and plenty of older folks don't. Wi-Fi sensing needs neither. It can notice that someone who is usually up by nine has not crossed the kitchen all morning, and alert an adult child two states away to call. It is the same capability as the creepy version, aimed at a problem instead of surveillance. That is what ADT bought. ![An older person's hand resting on a handheld device at home](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/assistive-device.jpg) It can back up the alert devices an older person already relies on. **What to do:** - **Check your gateway.** If you rent an Xfinity gateway, open the Xfinity app, go to the Home tab, and look for [WiFi Motion](https://www.xfinity.com/support/articles/wifi-motion?ref=freshfromcache.com). You will see whether it is on and who gets the alerts. - **Decide who sees the data.** If an old roommate or an ex still gets motion notifications, remove them. - **Know who can request the data.** Comcast's own privacy policy says it may disclose WiFi Motion data to third parties in response to a court order or subpoena. Factor that in before you leave it on. - **Search a new router's settings for "motion" or "sensing."** If you do not want it, confirm there is an off switch [before you buy](https://www.freshfromcache.com/router-expiration-date/). - **Leave it on if it helps you.** If you use it to know when your kid gets home, that is a fair trade. Make it a choice, not a surprise. This doesn't mean your router is filming you. It can't. The features detect motion, not identity. The work that can identify a person stays in university labs, not in the box from your internet provider. The capability is real and it is growing. You should know which version you have and who it reports to. Check the setting, not the marketing. How do you feel about your router being able to map movement through your own house? I want to know. Subscribe and tell me what else in your house you want me to check next. This is part of a series on everyday things in your house doing something behind your back. Earlier entries looked at [the smart TV](https://www.freshfromcache.com/tv-side-hustle/) and [the connected car](https://www.freshfromcache.com/your-car-grades-your-driving/). [Follow for the rest](https://www.freshfromcache.com/robot-vacuum-watching-you/). **Source:** [Xfinity WiFi Motion support](https://www.xfinity.com/support/articles/wifi-motion?ref=freshfromcache.com); [Tom's Hardware](https://www.tomshardware.com/networking/routers/new-xfinity-router-motion-detecting-feature-stokes-privacy-fears-feature-powered-by-wi-fi-signals?ref=freshfromcache.com); [Cybernews](https://cybernews.com/security/xfinity-wifi-router-motion-tracking-sparks-privacy-concerns/?ref=freshfromcache.com); [ScienceDaily](https://www.sciencedaily.com/releases/2026/05/260522023127.htm?ref=freshfromcache.com); [ADT newsroom](https://newsroom.adt.com/corporate-news/adt-acquires-origin-ai-to-power-ai-sensing-and-ambient-intelligence-for-the-home?ref=freshfromcache.com); [IEEE 802.11bf](https://standards.ieee.org/ieee/802.11bf/11574/?ref=freshfromcache.com). **The research:** Todt, Morsbach, Strufe, ["BFId: Identity Inference Attacks Utilizing Beamforming Feedback Information,"](https://dl.acm.org/doi/10.1145/3719027.3765062?ref=freshfromcache.com) CCS '25, DOI 10.1145/3719027.3765062. ### Your car has been grading your driving and selling the report card URL: https://www.freshfromcache.com/your-car-grades-your-driving/ Last updated: 2026-08-11T18:28:52.000Z For a long time, careful drivers had a deal they could count on. Keep a clean record, skip the claims, and your insurance stayed reasonable. Your driving was judged on results. Did you crash? Did you get tickets? Did you cost the company money? If the answer was no, you were rewarded. That deal got rewritten, and most people never got the memo. A lot of newer cars now keep a running log of how you drive (every hard brake, every fast start, every late-night trip). In case after case that log has been handed to insurance companies before the driver ever filed a claim. The scorecard grew a second page, and this one grades how you behave behind the wheel, moment to moment, then sells the result. About 90% of new cars on the road collect information on how the person behind the wheel drives, according to Telemetry, an automotive advisory firm. Not all of it reaches insurers, and some drivers signed up on purpose for programs that promise a discount. But a good share of this happened to people who had no idea it was happening at all. ## I went to check my own car When I started reading about this, my first thought was the same one you are probably having: is my car doing this? I drive a 2019 Prius. I assumed the worst. Then I looked, which is something I had never done. As it turns out, the regular 2019 Prius mostly predates the always-connected setup that makes this possible. Toyota's built-in data module was standard on the fancier Limited trim and on the Prius Prime that year, but not on the base models. So my particular car is probably not in this story. That digging is the frustrating part. Pinning down whether one ordinary car phones home took more effort than it should have, and the best I landed on was "probably not." If it is that murky for a single Prius, it is murky for almost everyone. The good news is that you can check, and the steps are at the bottom of this piece. ## How the safety features were co-opted Nobody sold you a tracker. They sold you a guardian angel. The features that made this possible arrived dressed as safety and convenience: automatic crash notification, [stolen-vehicle recovery](https://www.freshfromcache.com/the-car-alarm-you-never-bought/), the app that finds your car in a parking lot. To turn those on, you agreed to some terms. Buried in those terms, in several documented cases, was permission to collect how you drive and pass it along. General Motors sold driving data to [two data brokers, Verisk and LexisNexis](https://www.freshfromcache.com/what-is-a-data-broker/), over a span of years that ended in 2024\. The records were tied to your car's VIN and included things like hard braking, fast acceleration, and how often you crossed 80 miles per hour. Former FTC chair Lina Khan said GM was tracking some location data as often as every three seconds. LexisNexis and Verisk already keep files on your accidents and claims. They write the reports an insurer pulls before it quotes you. Driving behavior just got added to the pile. When your rate went up at renewal with no clear reason, this was sometimes why, and you would only find out by going digging. The car industry's trade group has a defense. They say connected data keeps cars working and drivers safe, that it powers crash response and recall notices. That it is not the same as spying. Some of that is fair. The problem is what happened next to the data once it left the car. ![Rows and rows of identical grey model cars receding into the distance.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-cardata-inline.jpg) Millions of cars, the same setup. Most drivers were never told. ## Why people are angry Consider what the automakers got paid for your data. According to a 2024 investigation by Senators Ron Wyden and Ed Markey, Honda shared data from about 97,000 cars with Verisk and was paid $25,920\. That comes out to roughly 26 cents per car. Hyundai shared data from about 1.7 million cars and collected a little over a million dollars, around 61 cents per car. So the company that sold you a $30,000 car made a quarter selling a year of your driving. The driver could pay hundreds of dollars more for insurance. One Florida driver, in a lawsuit against GM, said that after his driving data showed up in a report he never knew existed, he was turned down by seven insurers and his rate nearly doubled. Another driver, who is suing Toyota and Progressive, says his premium climbed from under $300 a month to over $400 at renewal, even though he had not had a ticket in almost a decade. Nobody destroyed value in that exchange. They relocated it. A few cents went to the car company, the broker took a cut, and the cost landed on you. ## Whether the scores are even fair Set aside how the data was taken for a second. There is a fairer question underneath: does any of this actually measure good driving? A hard brake can mean you are reckless. It can also mean someone pulled out in front of you and you stopped in time, which is the system working as intended. The data is precise, but precise is not the same as fair. In a J.D. Power survey, only about 4 in 10 drivers in these programs said the data their insurer collected was always accurate. The discounts are smaller than they sound, too. When Maryland's insurance regulator audited real telematics policies (the kind that set your rate from tracked driving) in 2025, about 31% of drivers saw a decrease, about 24% actually paid more, and the rest saw no change. Consumer Reports found the typical saver banked around $120 a year. Drivers over 70 saved the least, around $93\. The people most likely to trust that decades of clean driving will protect them are getting the smallest break and the most scrutiny. ![A close-up row of server hard drives with green status lights in a data center.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-cardata-inline2.jpg) Where your trips end up: a record in a broker's database, packaged and sold to insurers. ## What the regulators did, and did not, do This drew enough attention that regulators moved. The FTC reached a settlement with GM in early 2026 that bars the company from sharing this data with reporting agencies for five years and requires real consent going forward. There was no fine, and GM said it had stopped selling the data a year earlier. California's attorney general got $12.75 million out of GM in a separate settlement, the largest of its kind under that state's privacy law. California's privacy agency also fined Honda and Ford, largely over how hard they made it to opt out. None of it made collection illegal, and none of it covered the whole industry. There is still no federal law on this. Verisk got out of the business, but the machinery is mostly still standing. ## What you can do about it You have more power here than it feels like, and most of it is free. Pull your own file. Under federal law you can ask these brokers for the report they keep on you, at no cost. Start with LexisNexis at consumer.risk.lexisnexis.com and request your consumer disclosure report. If there is driving data on you, it should be in there. I tried this myself while writing. I filled out the form, asked for my report, and asked them to delete what they hold. Twice I got the same answer back: an internal system error, please try again later. So the company that had no trouble gathering this data could not manage to hand me mine. If it stalls on you too, keep at it. The right to see your file is real even on a day the website is not. Turn it off at the source. Most automakers now have a privacy page where you can opt out and ask them to delete what they have. Know the tradeoff before you do: switching off connected services can also switch off crash notification, roadside assistance, and stolen-vehicle help. That is a real decision, and it is yours to make. If you have ever wondered how much your phone, your TV, and your video doorbell already know about where you are, the car is the newest and nosiest member of that club. (We covered a smaller cousin of this problem: [the location hidden in your photos](https://www.freshfromcache.com/your-photos-know-where-you-live/).) What sets the car apart is that it knows exactly where you go, and it is wired straight into a product that charges you money. ## If you are in Oregon Oregon changed the rules this year, and you should know what you have. As of January 1, 2026, it is illegal to sell precise location data about you (the kind that can place you within about a third of a mile). Car makers are now covered by the state privacy law no matter how big they are. So you can tell them not to sell or share your data. Businesses now have to honor a single browser signal, a "universal opt-out" that says do not sell my data. You can set it once and be done with it. This is real and useful, but it also arrived years after a lot of the data was already collected, sold, and baked into somebody's pricing model. You can stop it from here on out, but what already went out the door is gone. Enforcement runs through the state attorney general, where you can file a complaint, though this particular law does not let you sue the car company yourself. That is the state of it. Your car has spent years grading how you drive, and most drivers never saw the report card. So before you go look, a question worth answering honestly: do you think you would have earned a safe-driver discount, or be paying more? Most people are sure they know. The audited numbers say it is closer to a coin flip. Either way, go find out what your car has been tattling to your insurer. ## Sources [CNN](https://www.cnn.com/2026/02/19/business/automakers-selling-driving-data-to-insurance?ref=freshfromcache.com) on automakers selling driving data to insurers, including the 90% figure and the Progressive renewal case. [The FTC](https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-takes-action-against-general-motors-sharing-drivers-precise-location-driving-behavior-data?ref=freshfromcache.com) on its case against GM and OnStar, including the every-three-seconds detail. [EFF](https://www.eff.org/deeplinks/2024/07/senators-expose-car-companies-terrible-data-privacy-practices?ref=freshfromcache.com) on the Wyden and Markey letter and the per-car payment figures. [CalMatters](https://calmatters.org/economy/technology/2026/05/gm-record-california-penalty-onstar-data/?ref=freshfromcache.com) on California's $12.75 million settlement with GM. [Insurance Journal](https://www.insurancejournal.com/news/east/2025/07/07/830458.htm?ref=freshfromcache.com) on Maryland's audit of telematics premium outcomes. [Consumer Reports](https://www.consumerreports.org/money/car-insurance/car-insurance-telematics-pros-and-cons-a5869096072/?ref=freshfromcache.com) on what telematics actually saves drivers. [The Oregon Department of Justice](https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/?ref=freshfromcache.com) on the state's 2026 privacy rules and the universal opt-out. ### Who gets your photos and email when you're gone? Set this up in five minutes. URL: https://www.freshfromcache.com/who-gets-your-accounts/ Last updated: 2026-06-18T14:03:08.000Z Think about everything in your phone right now. The photos, years of email, texts, voicemail. Now picture getting hit by a bus tomorrow. Who else can get in? For almost everyone, the answer is nobody. Left alone, your accounts go dark when you do. The photos get locked away and eventually deleted, with no one left who can reach them. Apple and Google both built a way to hand a trusted person the keys, and each one takes about five minutes to set up. Almost nobody has done it, because nobody thinks about it until the worst possible moment, which is the worst possible time to learn it was never turned on. Here is how to set up both. Do it today, while it is a five-minute errand instead of a crisis. The thing to understand first: this is a spare key you cut in advance. You are telling Apple or Google, ahead of time, to let one specific person you name request your stuff when you are gone. Nobody gets your password. Think of it like a digital will. ### On your iPhone (Apple Legacy Contact) Open Settings, tap your name at the top, then Sign-In & Security, then Legacy Contact. Pick someone you trust, and Apple generates an access key for them. When the day comes, your person needs two things to get in: that access key, and a copy of your death certificate. Setting it up is only half the job. The other half is making sure the key actually reaches them. Best to save it as a screenshot somewhere they will find it, or print it and tuck it in the drawer with the important papers. Legacy Contact passes along your photos, messages, notes, and files. It does not pass along the passwords saved in your iCloud Keychain. Those stay locked. If your passwords live in a [password manager](https://www.freshfromcache.com/what-the-heck-is-a-passkey/), that is a separate plan to make on its own. ### On your Google account (Inactive Account Manager) Go to [myaccount.google.com/inactive](https://myaccount.google.com/inactive?ref=freshfromcache.com). This one works on a different idea. Instead of waiting for proof that you have died, Google watches for your account to go silent. You pick how long, anywhere from three to eighteen months. If you stop signing in for that stretch, Google tries to reach you a few times by text and email first. If you still do not answer, it notifies up to ten people you chose and lets each of them download the data you picked for them. They can download a copy of the files, but they can never log in as you. Apple waits for a death certificate. Google waits for silence. Neither one is a quick process, so if your family needs into your account the day after something happens, this is not the tool that gets them in. It is the long game, the one that keeps the photos and the email reachable a year from now instead of gone forever. So here's a thought experiment. If you died tomorrow, could the person you trust most actually reach the photos, the email, the account that runs your whole digital life? For almost everyone reading this, the honest answer right now is probably no. Two five-minute setups turn that no into a yes. Do one of them before you close this tab. If you set one up and hit a wall, the access key step is where most people get stuck, so reply and tell me where it tripped you. Joel ### How the UK Plans to Keep Teens Off Social Media (and What It Means for Adults) URL: https://www.freshfromcache.com/prove-your-age/ Last updated: 2026-08-11T18:28:58.000Z To keep teens off social media, the UK is about to make everyone else prove their age. On June 15, 2026, UK Prime Minister Keir Starmer announced a plan to bar anyone under 16 from Snapchat, TikTok, YouTube, Instagram, Facebook, and X. (WhatsApp, Signal, and YouTube Kids are exempt.) The penalties run up to £18 million or a tenth of a platform's global revenue. They land on the companies, not the parents. It still has to clear Parliament, which the government wants done before Christmas, with the rules live in early 2027\. Australia switched on the same kind of ban in December 2025\. Spain, Greece, and Slovenia say they're working on their own. Several US states have tried and mostly lost in court. There's only one way to check a stranger's age over the internet currently, and every method ends the same: with your face or your ID sitting on someone else's server. The ban is aimed at kids; the age check is on everyone. So how does a website actually prove how old you are? ### The age-check ladder ![Face-based age estimation asks for a short selfie video](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/2642.webp) Age verification works as a ladder, and platforms climb only as high as the law forces them. The bottom rung is inference. The platform guesses your age from what it already knows about you: - how long you've held the account - whether there's a card on file - which servers or groups you belong to - what you do, and at what hours Discord says this clears more than 90% of its users with no prompt at all. It feels like nothing happened, which is a selling point. You sail through because the platform is profiling you in the background, and that profile is what vouches for you. When inference can't make the call, you reach the second rung: a face scan. You record a few seconds of selfie video and an AI estimates your age range from your face. The better versions run entirely on your own device, so the only thing that leaves your phone is a yes-or-no answer, and no image of your face travels anywhere. The on-device version is the privacy-friendly one. The next rung up is where it starts to cost you. The top rung is the government ID. You photograph your passport or driver's license, sometimes alongside another selfie, and send it to a verification company. That picture, plus your name, birthday, and document number, now lives on a server, even if the policy promises it gets deleted in a few days. I can tell you what that top rung feels like, because I'm stuck on it right now. When Meta took down Fresh From Cache's Instagram account, getting it back meant climbing this exact ladder. First a photo. Then, when that wasn't enough, a video selfie, turning my head while the app studied my face. Now I'm waiting to learn whether Meta will let me upload a government ID, because the face wasn't enough either. I pay for Meta Verified. I have the blue check. It didn't exempt me. Mine was an account-recovery check rather than an age check, but it runs on the same machinery the UK is about to require. Once a platform decides it needs to confirm who you are, your subscription and your good intentions count for nothing. It wants your face first. Then: papers, please. ### Discord already ran the experiment We don't have to guess how a mandatory version of this lands, because a platform with more than 200 million users tried it in public this year and got mauled. In February, Discord announced it would drop every account into a teen-safe mode by default unless you proved you were an adult, using the full ladder: inference, then a face scan, then an ID. Users revolted within days. Searches for "Discord alternatives" jumped about 10,000% in 48 hours. A rival voice service, TeamSpeak, said the wave of arrivals overwhelmed its servers. Two things turned a product rollout into a trust crisis. The first was the vendor. To run ID checks, Discord tested an outside firm called Persona, which is backed by a venture fund co-founded by Peter Thiel, who also co-founded Palantir, the data company with deep government and immigration-enforcement contracts. There's no evidence Palantir ever touched Discord data, and Persona's CEO flatly denied any link, but the optics alone were enough. When you upload your ID, you aren't only trusting the app on your screen; you're trusting a chain of companies you've never heard of. People did not love what they found when they went looking. Discord ended up dropping Persona, saying it wanted face scans done strictly on-device. The second was a breach. Four months before the rollout, attackers exposed roughly 70,000 government IDs that Discord users had submitted, and claimed many times more. The leak had nothing to do with the face-scanning AI. The documents spilled from a third-party [customer-support contractor](https://www.freshfromcache.com/cisa-contractor-keys-on-github/) handling verification appeals. The breach was attributed to one compromised support login. In almost every breach like this, the front-door locks hold. But somewhere down the chain, a contractor is sitting on a pile of documents, and that pile gets stolen. Discord backpedaled. Its CTO admitted the company "missed the mark," delayed the global rollout, and promised face scans would stay on-device. But it left the checks running everywhere a law already requires them: the UK, Australia, and now Brazil. A law converts a controversial product choice into a requirement nobody gets to decline. ### Does it actually keep kids off? Australia is the closest thing to real data, and the early results are uncomfortable for both sides. A few months after Australia's ban took effect, a survey of 12-to-15-year-olds found 61% still had access to at least one banned account. Why? Only about 1 in 20 used a VPN to fake their location. Most kept their accounts for one simple reason: the platforms didn't remove them. The ban worked on paper but fell apart in reality. The failure came down to corporate foot-dragging more than teenage cleverness. The science behind the urgency isn't quite as alarming as the press conferences suggest. The same week as the UK announcement, researchers told a parliamentary committee there's very little hard proof that social media is rewiring children's brains. One researcher put the measurable effect close to zero. Other scientists, and many grieving parents, point to real harms and to recent court verdicts against Meta. Both of those are true at once. Strong correlations and devastating individual cases are real, and rigorous proof that the apps cause harm across an entire population is thin. A policy this sweeping is being built on worry as much as evidence. ### The ban is the least of it The ban is the least ambitious piece of what the UK is proposing. The same plan would also: - restrict [AI chatbots that simulate romantic or sexual relationships](https://www.freshfromcache.com/the-chatbot/) to adults only, a response to scandals like Elon Musk's Grok generating non-consensual sexual images - float overnight curfews for under-18s - force breaks in infinite scroll and autoplay, to interrupt the features designed to keep kids glued - limit minors using VPNs to slip past the gates More detail is promised within the month. Strip away the specifics and the direction is clear: governments are moving from "what content is allowed" toward "how the product itself is allowed to behave, and who's allowed to use it." The age check is the gate that makes everything else enforceable. ### Could this happen in the US? ![A hand holding a US passport open to the We the People page](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/logan-weaver-lgnwvr-Fu2LqhFbXho-unsplash.jpg) Probably not in this exact form, and the First Amendment is why. US courts keep blocking the state versions of these laws. Florida's under-14 ban is still in litigation. Louisiana's was struck down. The Supreme Court did uphold online age checks in 2025, but only for pornography sites. Legal scholars say that ruling doesn't reach ordinary social media, where the speech is broader and more protected. So a clean UK-style ban is unlikely here any time soon. The machinery spreads here regardless. App-store age checks, ID prompts on more and more sites, the same [face-or-papers](https://www.freshfromcache.com/fake-face-real-money/) gate showing up one platform at a time. We are already hitting it on Reddit, on Roblox, on adult sites in roughly half the states. It arrives by slow adoption rather than by one sweeping law. This makes it easy to miss until it's asking for *your* ID. ### An ID is not a password ![A hand holding a passport, a bank card, and a car key](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/cardmapr-nl-gxAVTZgsxnw-unsplash.jpg) Handing a social media site your face might not feel like much. They already know more about you than you'd like: who your friends are, what you read, where you are at eleven at night. One more data point barely moves the needle. A government ID is different. Your name, your birthday, your document number, your address, all in one upload. That's a starter kit for identity theft. New accounts, loans, even a fake ID built from your real one. When a password leaks, you change it. [You can't reissue your face](https://www.freshfromcache.com/google-wants-a-video-of-your-face/) or your date of birth. It won't stay on social media, either. Adult sites already ask. Gambling sites ask. Anywhere with an age limit, or anywhere that just likes having your details on file, has the same reason to. The privacy people at the EFF put it plainly: within a year, you could have uploaded your ID to half a dozen sites, each one its own vault waiting to be cracked. You only have to be unlucky once. And once handing over your ID feels normal, a scammer doesn't need to breach anyone. They just put up a page that asks. People send it in, because they think they have to. We spend years teaching people not to type their password into a [strange site](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). This trains the opposite reflex. Yes, that is a slippery-slope argument. But it is a slope we are already standing on. ### What this actually costs you Every method of "prove your age" is also "prove your identity." The goal is also sympathetic. Most parents want it, and the platforms have [earned their distrust](https://www.freshfromcache.com/meta-dropped-instagram-encryption/) many times over. But the bill for the checkpoint gets paid by every ordinary adult who now has to hand a stranger their face or their license just to read a feed. That data goes to exactly the kind of place that keeps getting breached. Nobody serious disputes that kids deserve protection. The real question is whether routing every adult's identity through a leaky verification chain is the price that actually buys it. Especially when the one country that's tried this watched most kids keep their accounts anyway. I'll let you know how it turns out for my own account, assuming Meta ever decides I'm me. --- ### The ransomware crew with a marketing department URL: https://www.freshfromcache.com/newsletter/the-cheaper-plan-microsoft-hides/ Last updated: 2026-06-30T21:52:21.000Z Ransomware is a business now. The second most active crew on earth runs like a fast-food franchise: the people who break into networks keep ninety percent of the take, and the boss lists 'head of B2B marketing' as his day job. That's the headline this week. The rest of the issue is the companies you already pay changing the deal on you. Windows 10 lost its free security patches, home Office got pricier to cover an AI you didn't ask for, and QuickBooks Desktop began its slow exit. Each one steers you toward a costlier default, and each one has a cheaper or safer way through. Then a lighter one to close, because an entire industry just rearranged its calendar to dodge a single video game. Here's the week. --- [**Ransomware has been franchised**](https://www.freshfromcache.com/ransomware-has-been-franchised/) Here's the part that matters for you. The franchise model means more crews hitting more targets, and they go for whoever is easiest. Not the big company with a security team. The small office still running last year's updates. The post walks through how the operation works, and why the dull defenses, tested backups, prompt updates, a second step on your logins, are the ones that keep you off the list. *News* --- [**Microsoft stopped patching Windows 10\. Now what?**](https://www.freshfromcache.com/windows-10-out-of-support/) Your Windows 10 PC still turns on and runs fine. That's the trap. Microsoft just stopped sending it free security updates, so any new hole that gets found stays open on your machine. The post lays out six plain-English ways to handle it, with the actual costs, from the free route to a new PC. *News* --- [**The cheaper Microsoft 365 plan Microsoft hides behind the cancel button**](https://www.freshfromcache.com/microsoft-365-classic-plan/) Microsoft raised the price on its home Office plans to pay for Copilot, the AI assistant now baked into Word and Excel. There's a version without it, still at the old price. You only see it if you start to cancel. The post walks the path to find it before your renewal hits. *News* --- [**QuickBooks Desktop is going away.**](https://www.freshfromcache.com/quickbooks-desktop-is-going-away/) Intuit is retiring QuickBooks Desktop one version at a time. If your office still runs the buy-it-once version, you're on a clock now. I priced out the three options, the online subscription, a competitor, and staying put while you can, so you can pick on your terms instead of getting herded onto the monthly plan. *Learn* --- [**An entire industry is getting out of GTA's way**](https://www.freshfromcache.com/gta-6-empty-november/) Pull up the video game calendar for November and the week of the 19th is nearly empty. A row of publishers with billion-dollar slates looked at the launch date for Grand Theft Auto VI and decided to go stand somewhere else. I've been playing since the top-down original in 1997, so I know what fan hype looks like. An entire industry flinching is the bigger story. *Blog* --- **If you only read one:** the cheaper Microsoft 365 plan. If you pay for Office at home, a few clicks at renewal time keep you on the old price and off an AI upsell you never asked for. Ten minutes, and it pays you back every year it renews. --- **Scary Headline of the Week** *"Criminals are using Google's own AI to flood your phone with scam texts."* True, and it sounds like a fresh nightmare. Last week Google sued a China-based crew that used Gemini to mass-produce fake websites and the "you owe a toll" and "your package is held" texts that have been piling up in everyone's messages. The AI let them spin up convincing knockoffs of USPS, E-ZPass, and others by the thousand, faster than any person could type them. This particular scam shouldn't change any of your habits. The scam is the same it was a year ago. A stranger wants you to tap a link and enter your card number. They've cooked up some urgency to rush you past the part of your brain that would have caught it. AI made the bait cheaper to make and a little cleaner to look at. It handed the text no new power over you. A link is still a link, and you still do not tap it. So when a text says you owe a toll or missed a delivery, do not tap. If you think it might be real, open the actual app or type the real address in yourself. Then report the text as junk and delete it. It is still just phishing, pointed at your text messages instead of your inbox, and the tells are the same. We walked through them here: [How to spot a phishing email](https://www.freshfromcache.com/how-to-spot-a-phishing-email/). **Verdict:** scary press release, same old scam. Fresh From Cache grows when readers pass it along. If you enjoyed this issue, forward it to someone who might too. Back next Tuesday. Hit reply anytime and I'll see it. Joel ### Stolen iPhones are becoming worthless to thieves. URL: https://www.freshfromcache.com/stolen-iphones-worthless-to-thieves/ Last updated: 2026-08-11T18:19:58.000Z London has a serious phone theft problem. Around 200 phones get stolen there every day. So it stands out when thefts dropped 18 percent in a single year, and almost 46 percent in the hardest-hit part of the city. Driving that drop is what happens to a phone after someone swipes it. Apple has spent the last couple of years making stolen iPhones much harder to sell, and British police say it is working. Apple strengthened a feature called Stolen Device Protection in its latest iPhone update. Before, a thief who knew your passcode, or who grabbed your phone while it was still unlocked, could wipe it, sign your account out, and set it up clean for resale. Now the phone asks for your face or your fingerprint before it will make those changes. Your passcode alone will not be enough. Being able to wipe and resell the iPhone is what gives it value to a thief. Take that away and the phone is worth a fraction of what it was. The Metropolitan Police in London started handing Apple the identifiers of phones reported stolen. In return, Apple tells them when one of those phones tries to come back online or get reactivated. That gives investigators a picture of where stolen phones end up. Usually switched back on a few streets over, shipped overseas, or stripped for parts. The Met's commissioner says Apple believes it has "cracked" the engineering side of the problem. Not all progress can be attributed to Apple. The Met has said Samsung and Google are tightening the same screws. The commissioner is pushing the government to require the same from every maker and carrier, not just Apple. The whole industry is drifting toward the same idea. A stolen phone should be a brick. A lot of security news boils down to "you need to be more careful." This is the rare story where someone else put in the work. You aren't completely off the hook though. Newer iPhones may have it on by default, but plenty of phones do not. Luckily it takes about two minutes to check. **What you can do:** - **Turn on Stolen Device Protection.** Go to Settings > Face ID & Passcode > Stolen Device Protection and switch it on. You will need Find My, a passcode, Face ID or Touch ID, and [two-factor](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/) on your Apple Account. Most people already have all four. - **Set it to Always.** The default only kicks in away from familiar places like home and work. "Always" is one extra tap and covers you everywhere. - **Make sure Find My is on.** It is what lets you lock or erase the phone from another device if it does go missing. - **Trim your lock screen.** Keep texts and verification codes from showing on a locked screen, so a thief cannot read a login code without getting in first. - **Buying a used phone? Finish setup with the seller there.** That is how you confirm it is not still locked to someone else's account or flagged as stolen. These numbers are London's, and the police data-sharing piece is a British arrangement, so the picture in the States will likely look different. There is a real downside as well. If a phone gets wrongly flagged as stolen, the same locks that stop thieves can shut out the rightful owner. The way you appeal that is not spelled out well yet. Repair shops and refurbishers may have a harder time doing honest work, too. Open Settings tonight and make sure Stolen Device Protection is on. A thief who grabs your phone should end up with a paperweight, not a payday. **Sources:** The London theft figures and the Apple agreement come from the [Metropolitan Police](https://news.met.police.uk/news/met-and-apple-join-forces-to-disrupt-global-criminal-networks-as-phone-theft-halved-in-westminster-510316?ref=freshfromcache.com). Spotted via Malwarebytes. ### The Self-Driving Car Is Real. You Just Can't Buy It. URL: https://www.freshfromcache.com/self-driving-car-is-real/ Last updated: 2026-08-11T18:29:12.000Z The first time I really thought about self-driving cars, one of them tried to kidnap a guy. It was a scene in the show Silicon Valley. A character climbs into an autonomous car, and partway through the ride the car decides it has other plans. It locks him in and drives him into a shipping container, which then gets loaded onto a cargo ship bound for who knows where. Played for laughs. I knew shows exaggerate. But it was the first time the idea landed for me as something real and close, instead of "the future." That was around 2017\. The promises were everywhere back then. Full autonomy in two years. The end of car ownership by 2025\. A future where you'd summon a car the way you summon an elevator, and your kids would be confused that people ever bothered to learn to drive. I filed it under someday. I also figured I couldn't afford whatever the first version cost, so I didn't think about it much after that. Then someday started showing up in my feed. Articles about Waymo coming to Portland. Then actual Waymos, more and more of them, doing their slow careful thing around the city. And my wife got a car with a feature called BlueCruise, which is about as close to self-driving as I've personally been. So I went and read about where this actually stands in 2026\. I went in expecting the holdup to be engineering, the way it always sounded. The cars just need to get smart enough. What I found is stranger than that. Inside a few specific cities, the cars are already good enough. The thing standing between us and the future we were promised turns out to be us. ## The Assistant half There is a lot of jargon in this world. Levels zero through five, driver assistance, conditional automation. You can skip almost all of it. There is really only one question that matters when someone tells you a car drives itself: is there a person responsible for driving it, yes or no. The engineers have a scale for this. Level 2 means the car can steer and control its own speed, but you are the driver. Eyes up, hands ready, legally on the hook if anything happens. Level 4 means no human is driving at all inside a defined area. No one in the seat, no one on the hook. Everything people call "self-driving" lands on one side of that line or the other. The two sides of that line are very different. BlueCruise, the system in my wife's car, is Level 2\. On certain highways it holds the lane, keeps a set speed, and will even change lanes on its own if you tap the turn signal. The first time I let go of the wheel I was a little freaked out, but it did its job. After a while I could rest my arms and just watch the road, which is the whole point. I never thought the car was driving itself. I was driving. It was helping. The part that actually shocked me was the bill. BlueCruise is a subscription. About fifty dollars a month, or just under five hundred a year, for a feature the car already physically has. You are paying rent on hardware you already bought. I understand there is a real cost to running and mapping the system, so I get the why. It still felt a little gross. And it only works on divided highways, never city streets or back roads, so depending on where you drive it can sit there useless. The network is actually huge on paper, around 130,000 miles, most of the interstates in the country. It is also the smallest hands-free network of the major systems. GM's covers several times more road. Tesla's will switch on just about anywhere. All three are Level 2\. All three have you driving. But with help. A good assistant with a meter running. ## The Driver half The other half is real. And it's pretty wild. Waymo, the company that grew out of Google's car project, is running actual driverless taxis right now. No one in the front seat. You open an app, a car shows up empty, you get in the back, and it takes you across town. As of early 2026 they were doing around 500,000 paid rides a week across ten US cities, with more than 200 million miles driven with nobody at the wheel. The numbers keep climbing. ![A driverless Waymo Jaguar I-Pace on a downtown street](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/waymo.jpg) Photo: gibblesmash / Unsplash The reality is more nuanced. "Driverless" for Waymo really does mean driverless. There are remote employees who can help a stuck car, but they give it advice, not control. They cannot grab a virtual steering wheel and drive it from a desk. The car asks, "should I go around this?" and a human says yes or no, and the car does the driving. Roughly seventy of those remote helpers cover a fleet of around three thousand cars. Much different than a person piloting your taxi with a joystick from a call center. Which is closer to how some other operators run. And the safety record, so far, is good. A study by the insurer Swiss Re looked at 25 million driverless Waymo miles and found something like 88 percent fewer property-damage claims and 92 percent fewer injury claims than human drivers over the same distance. Keep in mind, those numbers come from an insurance company, with skin in the game. So the future has arrived. Just not how we expected. Waymo only works in mapped, approved zones in a handful of cities. It pulls back when the weather gets bad. It only recently tried freeways, and then paused that again in the spring. It is genuinely a self-driving car. It is also a self-driving car that will only meet you in the right few square miles of the right few cities. I will admit the expansion is what caused me to pay attention. I expected to feel more nervous as I learned more. Instead, watching the company actually grow made me more willing to try it, not less. If it were dangerous in the way some headlines suggest, it would not be spreading. That is not airtight logic. But it is how I reacted, and I suspect I am not alone. Would I get in one? Yes. My wife and I would try it together without (too) much hesitation. But I noticed my own gut reaction the second I pictured my nieces in the back seat. Suddenly I wanted a lot more proof. Risking myself is one thing. Putting someone else's kid in a robot's hands is different. It's also a personal decision shaped by experience. ## Tesla This is where Tesla comes in. Tesla is selling something that sounds like Waymo, but isn't. Tesla launched a robotaxi service in Austin in 2025\. They call it unsupervised. In practice it is a small fleet with remote staff who can take control at low speed, and early on there were chase cars following the robotaxis around. Texas passed a law in May 2026 letting a company certify its own cars as fully driverless, and Tesla signed off on its own robotaxis the same day. On paper, in Texas, some Teslas are now a no-human-needed service. In June 2026 Tesla turned that service on across the entire Austin metro, about 245 square miles, its biggest expansion yet and roughly twelve times the original footprint. The fleet actually driving those streets without a human is still around twenty cars. ![Inside a Tesla, the Full Self-Driving screen on, a driver's hand near the wheel](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/tesla-interior.jpg) Photo: n.c / Unsplash The Tesla you might have in your driveway is not that car either. Full Self-Driving, the feature you can buy, is still Level 2\. You are the driver. You are responsible. It has now been driven more than ten billion miles by owners who were all, legally, driving the whole time. In June 2026, owners noticed Tesla had gone back and edited their old Full Self-Driving purchase agreements, some signed years earlier, to insert the word "supervised," and in some cases the original document was no longer accessible. Tesla keeps saying the truly hands-off version for owners is coming, but keeps moving the date. The latest word pushes it to late 2026 at the earliest, gradual, and limited to certain places. The track record on those dates is worth remembering. The same company promised a million robotaxis on the road by 2020, and hundreds in Austin and a thousand in the Bay Area by the end of 2025\. The reality was a tiny fraction of that. The technology is real. The problem is the difference between the car in the keynote and the car you can actually buy. ## Adoption, not capability When I researched this topic, I was surprised to learn the biggest barriers are not the technology. The driving has gotten good, at least when using the fenced-in version. There are remaining engineering problems, the strange edge cases, the construction zone that's laid out wrong or the kid who darts out from between parked cars. But the biggest hurdle to pass is fear. People have reason to be careful, and one glitch can undo a million successful trips. The cautionary tale involves Cruise, GM's robotaxi company. In 2023 one of its cars in San Francisco dragged a pedestrian about twenty feet after she had been thrown into its path by a hit-and-run human driver. The company handled the aftermath badly, got its permit pulled, paid fines for how it reported the crash, and by the end of 2024 GM had shut the whole thing down. This was after spending more than ten billion dollars. Ford and Volkswagen had already folded their own self-driving venture a couple of years earlier. ![A Cruise robotaxi stopped at a city intersection](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/cruise.jpg) Photo: Remy Gieling / Unsplash The public has not warmed up the way one might think, given how well Waymo is doing. Surveys keep finding that around sixty percent of Americans say they are afraid to ride in a self-driving car. That number has barely moved in five years, even as the safety data piles up. The one thing that seems to move the needle is a crash that makes the news, which pushes fear up, not down. In January 2026 a Waymo hit a child near a school in Santa Monica. The car braked hard, the kid had run out from behind a double-parked SUV, and the injuries were minor. It still triggered two federal investigations and a wave of coverage within days. Plus the extra scrutiny over Waymos rolling past stopped school buses. A child, even unhurt, even in a crash a human likely could not have avoided either, resets people's tolerance to zero. My nieces came to mind again. ## Is it worth it? Trust is one half of the human problem, the other half is desire. A lot of Americans do not actually want to give up driving. The car is freedom, control, identity. I have known plenty of people over the years who were, in a real sense, the car they drove. That is not a character judgement. This whole country was built around the automobile, the suburbs, the road trip, the open highway as a kind of national religion. The attachment makes sense. I am the odd one out here, and I know it. I see a car as a way to get from point A to point B with a little comfort along the way. That is my relationship. I drive a lot, for work, and I live somewhere rural enough that there are few days without a lot of time behind the wheel. If I could hand that wheel off and spend the drive working or better yet *sleeping*, that would be a dream for me. But me wanting it does not move the whole country. I am the demand that already exists. The people who decide this are the ones who would say no, and there are far more of them than there are of me. The person who would benefit most from a car that drives itself is someone like me, with a long rural haul every day. The car that actually exists is a robotaxi penned into dense city centers. It will happily shuttle someone four blocks across downtown San Francisco. It will not come anywhere near my road for a long time. The reason has little to do with how hard my road is to drive. If anything, an empty two-lane is simpler than a downtown packed with pedestrians and cyclists. The reason is money. These cars are expensive, and they only pay off where trips are short, constant, and packed close together. A city block can deliver a hundred riders an hour. My route delivers me. Mapping and running a thin rural network for a handful of riders does not add up, so nobody builds it. The technology that works is aimed almost exactly away from the people whose lives it would change the most, because that is where the paying crowds are. ## Wildcard If you want evidence that the bottleneck is culture and not physics, look at China. Chinese robotaxi companies are running more cars, in more cities, growing faster than anyone here. One of them was doing more than 300,000 driverless rides a week by late 2025\. The difference between China and the US is that their government clears the way faster and the riding public is more willing to climb in. Same technology, different culture. Until recently, the way you built a self-driving car was to hand-code it city by city, with detailed maps and a long list of rules. Waymo's careful, fenced-in approach is the mature version of that. The newer idea is to let the car learn to drive [the way a language model learns to write](https://www.freshfromcache.com/what-is-an-ai-agent/). Watching an enormous amount of driving and figuring out the patterns itself, so it can handle a road it has never seen. If that works, the fence comes down, and the whole slow city-by-city grind could stop being necessary. Tesla is betting on this idea. Some smaller companies are built entirely around the idea. Skeptics make a strong point in return. Learning from examples is great until you hit the rare, deadly situation that was not in the examples. That is exactly the moment that has to go right the very first time. A car that is brilliant 99.9 percent of the time and catastrophic in the gap is not good enough, and nobody has closed that gap. ## Where are we in 5 years? I do not think we will see that much change by 2031\. I think full self-driving cars get adopted slowly. I think slow is the right speed for a technology like this. Most people understand exactly what is on the table: their own lives and the lives of the people they love. I expect Waymo to keep growing the way Uber once did. One city at a time, until it is a normal option in a couple dozen places and a curiosity everywhere else. I can see it genuinely challenging Uber. That fight will pull in money and innovation, especially with the AI approach entering the ring. If that approach clicks, things could move faster than trust and laws. I wouldn't bet on it. But I'd be glad to lose. So no. Not in five years. A car you can buy that drives itself anywhere, robotaxis on my rural road, the end of owning a car. I'll still be holding the wheel. --- *One more thing. If you’ve ridden in a Waymo, I’d love to hear what your first time was like. The good, the weird, the moment you forgot no one was driving.* ### An entire industry is getting out of GTA's way URL: https://www.freshfromcache.com/gta-6-empty-november/ Last updated: 2026-06-14T12:44:21.000Z Pull up the video game release calendar for November 2026 and the first thing you notice is what isn't on it. The weeks around the 19th are nearly empty of major releases. The only major new games brave enough to keep their November dates are a remastered Godzilla brawler and a Barbie game. Both are aimed at people who were never going to be pulled away anyway. The 19th itself belongs to one game: Grand Theft Auto VI. I've been playing Grand Theft Auto since the original top-down version in 1997\. I know what fan excitement looks like. What is happening on that calendar is bigger. This is a row of publishers with billion-dollar release slates looking at one Thursday in November and deciding to go stand somewhere else. When an entire industry steps out of the way, that tells you something. ## The flinch The clearest example is Fable. Microsoft's big fantasy reboot was set for fall 2026\. In late May, Xbox moved it to February 2027\. The reason was that 2026 had gotten too crowded with heavy hitters and Fable deserved its own "dedicated moment" instead of getting buried. Among the games Xbox listed as crowding the calendar was Grand Theft Auto VI. Xbox did not say "we're scared of GTA." They named a whole stack of big titles, with GTA VI as one of them. But the shorthand the press has settled on has a name: the "GTA effect." No developer said that phrase on the record, but they didn't have to. Fable is just the loudest example. Look at what [piled into September](https://www.videogameschronicle.com/guide/upcoming-game-release-dates-schedule/?ref=freshfromcache.com) instead. After Sony's June showcase, the month filled up: - The Blood of Dawnwalker, September 3 - Halloween: The Game, September 8 - Marvel's Wolverine, September 15 (PlayStation's flagship release of the year) - Dune: Awakening (console version), September 22 - Control Resonant and Silent Hill: Townfall, both September 24 - Onimusha: Way of the Sword, September 25 - Ace Combat 8, September 28 Three of those (Control Resonant, Silent Hill, and Onimusha) are sequels to beloved series from major studios, and they are all launching within about 24 hours of each other. September got so jammed that at least one game, the action title Phantom Blade Zero, gave up and slid into October just to find room to breathe. (Release dates this far out tend to move, so treat the specific days as penciled in rather than carved.) Not everyone ran. Remedy is putting Control Resonant out in that September crush on purpose, with its CEO framing the decision to launch near GTA as the long game, a bet that the studio can ["cut through the noise."](https://www.gamesradar.com/games/action/silent-hill-townfall-onimusha-way-of-the-sword-and-control-resonant-all-launch-a-day-apart-in-september-as-everyone-gets-the-hell-out-of-gta-6s-november/?ref=freshfromcache.com) That is the exception against a field of retreat. ![Timeline of 2026 fall game releases: eight major titles clustered across September, an empty October, and Grand Theft Auto VI alone on November 19.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/gta6-flinch-timeline.png) Eight major games crowded into three weeks of September. November 19 stands alone. ## Why they're scared Why would a company delay its own flagship to dodge a single competitor? Because of what the numbers around GTA VI look like. Start with the trailers. The first one, in December 2023, became the most-watched non-music video in YouTube history in its first 24 hours. In that window it pulled in [roughly 93 million views](https://variety.com/2023/digital/news/grand-theft-auto-6-youtube-record-most-viewed-trailer-1235828208/?ref=freshfromcache.com), beating the previous record of about 59 million, held by MrBeast, the biggest creator on the platform. The second trailer, in May 2025, went further. Across every platform at once it pulled more than 475 million views in a single day, making it the biggest video launch of any kind, ahead of Hollywood movie trailers like Deadpool & Wolverine. These are trailers. For a video game. Then the money. Take-Two, the company that owns Rockstar, told investors it expects to bring in [somewhere around $8 to $8.2 billion](https://www.reuters.com/business/media-telecom/take-two-forecasts-annual-bookings-below-estimates-sticks-with-gta-vi-launch-2026-05-21/?ref=freshfromcache.com) in the fiscal year built around this launch. That figure landed below what Wall Street analysts were hoping for, which was closer to $9 billion. A company low-balling expectations on the biggest launch in its history is its own signal about the pressure in the room. And none of this is a debut. The last game, GTA V, made a billion dollars in three days back in 2013 and has [sold more than 200 million copies](https://www.gamespot.com/gallery/top-10-best-selling-video-games-of-all-time/2900-4814/?ref=freshfromcache.com) since, which makes it the second best-selling video game ever made, behind only Minecraft. GTA VI is the sequel to that. ## The number that isn't real You've probably seen the claim: GTA VI's launch will cost something like a billion dollars in lost productivity as people skip work to play. It even has a name, the "GTA flu," all those fake sick days. It's a great line. It's also, as far as I can tell, mostly made up. The billion-dollar figure traces to [José García-Montalvo](https://www.infobae.com/espana/2025/07/28/la-venta-del-gta-vi-en-eeuu-provoca-absentismo-laboral-masivo-y-perdidas-millonarias-que-se-sabe-de-este-juego-y-su-llegada-a-espana/?ref=freshfromcache.com), an economics professor at Pompeu Fabra University in Barcelona, who floated it on the Spanish radio network Cadena SER. It was a number offered on the air. No study exists. Nobody measured GTA V's actual effect on workplaces in 2013 either. The closest thing on record is a poll IGN ran before launch, asking readers what they planned to do. About 1 in 5 said they would call in sick. That captured what gamers said they might do beforehand. It never measured what anyone actually did. And you don't need a study to manufacture a scary number. Watch how easy it is. More than [200 million people in the United States](https://www.theesa.com/resources/essential-facts-about-the-us-video-game-industry/2026-data/?ref=freshfromcache.com) play video games, and the median full-time worker earns [about $240 a day](https://www.bls.gov/news.release/archives/wkyeng%5F12042025.htm?ref=freshfromcache.com). So if four million of those players skipped a single day of work, the lost wages alone would come to almost a billion dollars. Four million sounds enormous, but it is only about two percent of American gamers. Now feed in that old IGN poll instead, the one where one in five players said they would call in sick. One in five of today's players is not four million. It is forty million. Run that through the same arithmetic and you land near ten billion. So the billion everyone repeats is the cautious low end, not the scary number it gets sold as. When a number swings that far depending on which guess you feed it, it tells you what it is: a vibe with a dollar sign in front of it. ![Bar chart: 2% of players skipping a day is about 4 million people and roughly $1 billion in lost wages; the 2013 IGN poll one-in-five implies about 40 million people and roughly $10 billion.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/gta6-flu-math.png) Same formula, two answers. The billion everyone repeats is the cautious low end. There is real research here, and it is more interesting than the meme. A group of economists (Aguiar, Bils, Charles, and Hurst) published a [peer-reviewed paper](https://www.journals.uchicago.edu/doi/10.1086/711916?ref=freshfromcache.com) in a top journal showing that the rise of video games since 2004 helps explain why young men work fewer hours, on the order of a 2 percent decline. That is a genuine finding. What it describes is a slow, gradual pull spread over years. It does not describe a single Tuesday when the country phones in sick. The honest research points the opposite direction from the headline. For contrast, some of the cultural-event numbers people cite in the same breath at least come from somewhere you can check. The Super Bowl absenteeism figure comes from [UKG](https://www.ukg.com/about-us/newsroom/ukg-estimated-161-million-us-employees-miss-work-super-bowl-monday-millions-more?ref=freshfromcache.com), a workforce-software company that runs the survey through the Harris Poll every year. The March Madness one comes from [Challenger, Gray & Christmas](https://www.challengergray.com/blog/its-madness-march-madness-cost-employers-133b-lost-productivity/?ref=freshfromcache.com), an outplacement firm that publishes its math annually. Those estimates wobble a lot year to year, which tells you how soft they are. But at least they have a return address. The GTA flu billion does not. So I am not going to repeat it as fact. Take-Two's own CEO joked that plenty of people will be calling in sick on launch day. And he's right. But nobody can tell you what that dollar figure translates to. My eye-rolling is aimed at the corner of the internet spinning elaborate conspiracy theories about when the next trailer will drop. I know it's in good fun. I remember feeling hyped like this for Pokémon Yellow. I was in middle school carrying a paper rain-check slip (Best Buy) for my preorder in a wallet that held no money. You were not cool unless you had Pokémon Yellow coming. I was not cool even with it coming. So I roll my eyes, and then I remember I have been the hype. ## Thirteen years If you have never touched one, here is the idea of Grand Theft Auto. It drops you into a sprawling, satirical version of an American city and then leaves you alone. You can follow the story missions, which play like a crime movie you are starring in. Or you can ignore all of it and just live there: drive, explore, cause mayhem, get chased by police. The series more or less invented that kind of open-ended freedom, and it has spent almost thirty years as the game every other open-world game gets measured against. It's been thirteen years since GTA V came out. That's a long time between games. But the reason for the wait turns out to be the same reason I never put the last one down. A quick history, so you know where I'm coming from. The original in 1997 was a small top-down game where you played a crook loose in a city. GTA III in 2001 pulled the whole thing into 3D and more or less invented the modern open-world game. Vice City and San Andreas built that out. GTA IV in 2008 made it gritty and cinematic. Then GTA V came in 2013. I remember where I was for that one. I'd just gotten out of the military and moved back to Oregon to be with Katie, my wife. I didn't have my own place or a job. Just a little service money in my pocket and a lot of time on my hands. I was twenty-four, maybe twenty-five. I set my PS3 up in her room and played the whole thing from her bed. I look back on that stretch fondly, and it almost doesn't even feel like me. That's the thing about a thirteen-year gap. The person who started the save file isn't quite the person who's still playing. ![Jason Duval, one of Grand Theft Auto VI's two protagonists, seated in a car.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/gta6-jason-duval.jpg) Jason Duval, one of GTA VI's two leads. But I did keep playing, here and there, for over a decade. GTA hasn't changed at its core. It's gotten bigger, sharper, louder, more bombastic, but it's still built on that same ordinary-guy vantage and that same freedom. You can drive across town like a perfectly law-abiding citizen, or you can blow up that gas station over there. That choice is the whole magic, and it's the same thing that hooked me as a broke kid on a family PC in 1997, baiting the cops just to see what would happen. As I've gotten older I've come to appreciate the stories more, too. But the core has never moved. What kept it alive commercially is GTA Online, the multiplayer world Rockstar layered on top. I'll be honest, the online side isn't for me. But I have real respect for what they pulled off there. They took the same feeling and built a different kind of game out of it for the players who crave that, and now they hand you all three at once: mess around and do whatever you want, sink into a genuine story, or go cause trouble online with everyone else. That online world is the reason V kept earning for ten straight years. Rockstar re-released the same 2013 game across three console generations, from the PlayStation 3 to the PS4 to the PS5, and people kept buying it. Even in 2025, more than a decade on, it was still pulling around [100,000 people watching it on Twitch](https://www.statista.com/statistics/1247955/gta-v-unit-sales-worldwide-total/?ref=freshfromcache.com) at any given time. Games are supposed to have a shelf life. This one refused to expire. It is also the reason the wait for VI stretched so long, and the reason expectations for it are somewhere up in the stratosphere. ## What if? It could still go wrong. We have a recent example of what failure at this height looks like. ![Lucia Caminos, one of Grand Theft Auto VI's two protagonists, on a motorcycle at night in Vice City.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/gta6-lucia-caminos.jpg) Lucia Caminos, the other half of GTA VI's lead duo. In December 2020, CD Projekt Red released Cyberpunk 2077, one of the most anticipated games of its own moment. On powerful PCs it was impressive. On the older PlayStation 4 and Xbox One consoles, where millions of people actually played, it was a mess. Crashing, glitching, barely running. The backlash got severe enough that Sony did something close to unthinkable. It [pulled the game from the PlayStation Store](https://www.gamespot.com/articles/cyberpunk-2077-has-been-removed-from-playstation-store-refunds-will-be-issued/1100-6485659/?ref=freshfromcache.com) entirely and offered full refunds, and it stayed gone for about six months. There was a public apology, the studio's stock dropped, and an investor lawsuit was eventually settled. The game clawed its way back over the years with patches and an expansion, but the launch is still the cautionary tale. It has happened to others, from No Man's Sky to Fallout 76 to Battlefield 2042\. Hype is a loan. The launch is when it comes due. Gaming today is crawling with business people trying to squeeze the art out of one of the best art forms technology has ever produced. They want the money. GTA sits in this odd, valuable spot where it satisfies both the people who just want to mess around and the people who want a great story, made by the studio that basically invented the open world in the first place. So the question on November 19 runs deeper than whether the servers hold up under launch-day crowds. Can the one studio with all the money, all the time, and a decade of new technology still make the art land? They've had every advantage there is. Soon we'll find out what they do with it. ## That Thursday Yes, I'm taking the day off. There used to be a ritual to this. When major games like GTA V came out, I'd stay up for the midnight release. I'd stand in the long line outside a GameStop, just to experience it "first." I was there at midnight for Skyrim, for more Pokémon launches than I can count, and for everything in between. These days the "midnight release" is 9pm on the West Coast. The routine goes like this: you download the game, then you wait for the patches, then you fiddle with the settings, then you finally jump in, and then it's time for bed. I went all-digital years ago. So did a lot of the world. I still get just as excited for a new game. I just have to move mountains to find the time now that I'm pushing forty. But GTA VI feels like an event. Like an excuse. Like the one I'd still stay up past midnight for. The grown-up move would be to take my time with it, the way a responsible adult would. GTA brings the kid and the wonder back out of me, and I can't wait for VI. And part of what sounds so magical about it is the crowd. Millions and millions of people doing the exact same thing at the exact same moment. You feel that kind of togetherness rarely. The last time I felt it this strongly was when Pokémon Go landed and the entire world seemed to be playing at once. This might not be quite that, since the games are too different, but it has the same shape. It's something so mainstream it stops being a product entirely and becomes a shared moment. Which brings me back to that empty November. All those studios cramming into September weren't being polite. They ran the numbers and decided they would rather not be in the room when GTA VI showed up. On one Thursday in November, a whole lot of us are going to look at the same screen at the same time. I'll be one of them. I just have to clear my Thursday first. --- ## Sources - Release schedule and September pileup: [Video Games Chronicle](https://www.videogameschronicle.com/guide/upcoming-game-release-dates-schedule/?ref=freshfromcache.com) - Fable moved to February 2027: [Pure Xbox](https://www.purexbox.com/news/2026/05/xbox-delays-fable-to-february-2027-and-its-basically-because-of-gta-6?ref=freshfromcache.com) - Remedy on launching near GTA: [GamesRadar](https://www.gamesradar.com/games/action/silent-hill-townfall-onimusha-way-of-the-sword-and-control-resonant-all-launch-a-day-apart-in-september-as-everyone-gets-the-hell-out-of-gta-6s-november/?ref=freshfromcache.com) - Trailer 1 YouTube record: [Variety](https://variety.com/2023/digital/news/grand-theft-auto-6-youtube-record-most-viewed-trailer-1235828208/?ref=freshfromcache.com). Trailer 2 cross-platform record: [Push Square](https://www.pushsquare.com/news/2025/05/gta-6-trailer-2-attracts-over-45-million-views-in-12-hours?ref=freshfromcache.com) - Take-Two FY2027 guidance: [Reuters](https://www.reuters.com/business/media-telecom/take-two-forecasts-annual-bookings-below-estimates-sticks-with-gta-vi-launch-2026-05-21/?ref=freshfromcache.com) - GTA V sales and ranking: [GameSpot](https://www.gamespot.com/gallery/top-10-best-selling-video-games-of-all-time/2900-4814/?ref=freshfromcache.com). Twitch viewership: [Statista](https://www.statista.com/statistics/1247955/gta-v-unit-sales-worldwide-total/?ref=freshfromcache.com) - The "GTA flu" billion-dollar figure: [Infobae](https://www.infobae.com/espana/2025/07/28/la-venta-del-gta-vi-en-eeuu-provoca-absentismo-laboral-masivo-y-perdidas-millonarias-que-se-sabe-de-este-juego-y-su-llegada-a-espana/?ref=freshfromcache.com) - US video game players: [Entertainment Software Association](https://www.theesa.com/resources/essential-facts-about-the-us-video-game-industry/2026-data/?ref=freshfromcache.com). Median weekly earnings: [Bureau of Labor Statistics](https://www.bls.gov/news.release/archives/wkyeng%5F12042025.htm?ref=freshfromcache.com) - Video games and young men's working hours: Aguiar, Bils, Charles & Hurst, [Journal of Political Economy](https://www.journals.uchicago.edu/doi/10.1086/711916?ref=freshfromcache.com) (2021) - Super Bowl absenteeism: [UKG](https://www.ukg.com/about-us/newsroom/ukg-estimated-161-million-us-employees-miss-work-super-bowl-monday-millions-more?ref=freshfromcache.com). March Madness: [Challenger, Gray & Christmas](https://www.challengergray.com/blog/its-madness-march-madness-cost-employers-133b-lost-productivity/?ref=freshfromcache.com) - Cyberpunk 2077 pulled from the PlayStation Store: [GameSpot](https://www.gamespot.com/articles/cyberpunk-2077-has-been-removed-from-playstation-store-refunds-will-be-issued/1100-6485659/?ref=freshfromcache.com) ### Ransomware has been franchised URL: https://www.freshfromcache.com/ransomware-has-been-franchised/ Last updated: 2026-08-11T18:28:40.000Z A cybercrime crew called The Gentlemen just became the second most active ransomware group on the planet, measured by how many victims they have publicly named. They got there the same way a fast-food chain expands: by offering a better cut to the people doing the work. Researchers at the security firm Check Point have tracked the group since it appeared in mid-2025, and the numbers are steep. At least 332 published victims, more than 240 of them in the first few months of 2026. The secret sauce was their recruitment. Most ransomware operations pay the hackers they hire 80% of whatever a victim pays and keep 20% for the house. The Gentlemen offered 90%. Experienced criminals jumped at the opportunity to switch teams. Then last week, security journalist Brian Krebs published his findings on who runs "The Gentlemen." The person who appears to run the operation is, most likely, a 36-year-old man in Izhevsk, Russia, who lists "head of B2B marketing" as his day job. ## How the franchise works Modern ransomware has very little to do with a hacker in a hoodie. These days it runs as a gig economy with a clear division of labor, and the industry even has a name for the arrangement: ransomware-as-a-service, or RaaS. One person (the administrator) writes the malware, runs the leak site where stolen files get published, and handles the cryptocurrency. The actual break-ins are outsourced to independent contractors called affiliates, who get paid a percentage of every successful ransom. ![The Gentlemen ransomware franchise structure: the operator keeps 10 percent and builds the malware, runs the leak site, handles the cryptocurrency, and recruits affiliates; the affiliates keep 90 percent and break into networks, steal data, and deploy the ransomware.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/franchise-diagram.png) The RaaS split: one operator takes 10%, the contractors keep 90%. It is a franchise. The administrator builds and maintains the product. The affiliates go out and use it. The house takes a cut of the revenue. The only real difference from a legitimate franchise is the product. Instead of slinging burgers, it encrypts a dentist's office or a county water district and demands a payout to give the files back. That structure is why a single crew can rack up hundreds of victims in a year. The administrator never has to break into anything personally. He just has to keep enough skilled affiliates happy, and the way you keep affiliates happy is paying up. ## The 90% hustle The standard split across the ransomware underground has been 80/20 for years, 80% to the affiliate and 20% to the operator. The Gentlemen showed up offering 90/10. This poaching strategy attracts top-tier criminals who can reliably break into corporate networks. They are free agents, and ten extra points of every payout is a real raise. Check Point's researchers put it plainly back in April: the better split is pulling experienced operators away from competing programs. The victim count followed. They are now the second most active group in the world, in well under a year, on a business built almost entirely on commission. The professionalism goes past the payroll split. Analysts who went through the leaked chats found the crew looking companies up to estimate revenue, then sizing the ransom to the ceiling of the victim's cyber-insurance policy. In one case they knew the target carried $10 million in coverage and asked for exactly $10 million. The insurance meant to cover the disaster sets the price of it. ## How they break in The methods are not exotic, which is what makes this scary. The Gentlemen's affiliates get their initial foothold mostly through internet-facing equipment: VPN appliances and firewalls, the boxes that sit at the edge of a network and face the open internet. Think Fortinet and Cisco gear. They brute-force login pages, they exploit known holes in equipment that has not been updated, and they buy access from other criminals who specialize in finding open doors. Once inside, Check Point says they move fast enough to encrypt an entire network within hours. None of that requires a genius hacker. What it takes is a list of internet addresses and a scanner that checks each one for a firewall nobody has patched since 2023\. The work is closer to telemarketing than espionage. You dial enough numbers, you get enough yeses. It's a numbers game. This is the same shift I wrote about in [patching is the new password](https://www.freshfromcache.com/patching-is-the-new-password/): the unlocked door now matters more than the stolen key. ## The boss is not a supervillain The unmasking is my favorite part. It is also useful for understanding the threat. After someone leaked the group's own backend database in May, Check Point, the intelligence firm Intel 471, and the breach-tracking service Constella Intelligence pieced together a trail from the administrator's forum handles ("Hastalamuerte," later "Zeta88"). They traced a Telegram ID, a phone number, and an email address. The trail led to a name: Alexander Yapaev, 36, of Izhevsk. The same email is tied to a LinkedIn profile listing him as head of B2B marketing at a Russian electrical-supply company. Krebs is careful to call this a likely identity built from breadcrumbs, not a courtroom-proven fact, and Yapaev did not respond to requests for comment. Russian authorities tend to leave cybercriminals alone as long as they do not hit Russian targets, which is part of why so many of them barely hide. Digging back through this person's forum posts from 2019 and 2020, you'll find an unsophisticated amateur asking beginner questions, fumbling with penetration-testing tools in a training channel, trying to build a reputation. This was not a state-sponsored mastermind. The forum history shows a guy who was bad at this, stuck with it, got better, and eventually turned it into a profitable software business with a recruiting funnel. ## Now with more AI In the leaked chats, the administrator says he built his admin control panel in three days using AI coding assistants. He was candid enough to state that you still have to understand the code well enough to fix what the AI gets wrong. The crew trades tips on which models work best for them, leaning on Chinese ones, and at one point recommends a version stripped of its safety limits so it will answer anything. This is the same uncomfortable pattern I covered in [the AI hard drive hostage crisis](https://www.freshfromcache.com/i-cant-let-you-save-that-dave/): the tools that make a small business more productive make a small criminal operation more productive too, and the criminals are not waiting for permission. ## What it all means Nobody studied you or your company and singled you out. You became a target because an automated scanner found a device on your network that answers to the open internet and has a known weakness. Then an affiliate working on commission followed up because there was money to be made. The algorithm found a door that was not locked, and a contractor walked through it for his 90% cut. That is why "we're too small to bother with" is not a valid defense. Verizon's 2025 Data Breach Investigations Report found ransomware involved in 88% of breaches at small and midsize businesses, against 39% at large companies. The 2026 edition is blunter about why: these attacks are opportunistic, and the most common ways in were [a stolen password](https://www.freshfromcache.com/start-using-a-password-manager/) or an unpatched device sitting on the edge of the network. Small operations get hit more, not less. This is because they run the same internet-facing gear as everyone else but patch it less often. The attack is a volume play where small and large look identical to a scanner. ## What to do - **Patch your edge devices first.** The firewall, the VPN box, anything that faces the internet. These are the front door, and they are exactly what the scanners look for. If a vendor pushes a security update for one of these, it is not a "this weekend" job. - **Put multi-factor authentication on every remote login.** Brute-forcing a VPN password is a core part of how these crews get in, and a second factor stops that. It is [a minor daily annoyance](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/), and it is the cheapest thing on this list that can stop a real attack. - **Find out what you are actually exposing.** Most small businesses do not know which of their devices are reachable from the open internet. If you have an IT person or a managed provider, ask them for the short list. If a piece of gear does not need to be internet-facing, take it off. - **Keep backups you can actually restore.** The whole point of ransomware is that you cannot get your files back. [Real backups](https://www.freshfromcache.com/do-you-need-backups/), tested and kept offline, turn a catastrophe into a bad afternoon. - **Assume a scanner will reach you, because one will.** A criminal did not single you out; your address is just one more line in a list the script runs against everyone. The defenses above are the difference between being on that list and being a casualty. There is no shadowy genius picking you out of a crowd. There is a product, a commission plan, and a few hundred contractors running the same handful of plays against everyone with an exposed firewall. That should not feel reassuring. The franchise version is more dangerous than the Hollywood one, because it scales. The only thing standing between your network and a financially motivated franchisee is whether you patched the box at the edge of it. **Sources:** [Krebs on Security](https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/?ref=freshfromcache.com) on the administrator's likely identity; [Check Point Research](https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/?ref=freshfromcache.com) on the group's structure, growth, and the leaked internal chats; Verizon 2025 Data Breach Investigations Report on small-business ransomware rates. ### QuickBooks Desktop is going away. URL: https://www.freshfromcache.com/quickbooks-desktop-is-going-away/ Last updated: 2026-06-11T14:00:00.000Z If your business runs its books on QuickBooks Desktop, a critical deadline just passed. On May 31, Intuit cut off support for QuickBooks Desktop 2023\. Your payroll tax tables are frozen right now if you use that version. Your bank feeds are next. We don't all run our books on QuickBooks, but a lot of small businesses and nonprofits do. Some have for twenty years. Intuit is winding the whole product down one version at a time. They want everyone on a monthly subscription called QuickBooks Online. The forums are full of people who feel cornered. The good news is we have options. None of them require panic. Just a calendar and a little math. ## The phase-out As of September 30, 2024, you cannot buy a new QuickBooks Desktop Pro Plus, Premier Plus, or Mac Plus subscription. Existing subscribers can renew but new customers are locked out. Support drops on a rolling schedule. Each version gets three years. Desktop 2022 died in 2025\. Desktop 2023 died on May 31\. That is the one that just happened. Desktop 2024 is the end of the line. Support for it drops on September 30, 2027\. After that, every Desktop user is on unsupported software. (The exception is QuickBooks Enterprise. It is much bigger, vastly more expensive, and still actively sold. It is not the answer for most small businesses.) ![Timeline of the QuickBooks Desktop phase-out: new sales ended September 30, 2024; Desktop 2023 support ended May 31, 2026; Desktop 2024 support ends September 30, 2027.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/v2-inline-1-timeline-quickbooks-desktop-is-going-away.png) ## What "end of support" means The software will keep running after the deadline. The file will open. You can even still write checks, enter invoices, and pull reports. What dies is the connection to the outside world: - **Payroll stops.** Tax tables freeze. Automated tax calculations end. Stale tax tables mean incorrect paychecks. - **Bank feeds disconnect.** Transactions must be imported or entered by hand. - **Payments stop.** Card processing inside the app shuts off. - **Invoicing breaks.** You cannot email forms directly from the software. - **Security patches end.** The code stays frozen with whatever vulnerabilities exist. - **Live support goes dark.** If your company file corrupts, nobody is coming to fix it. This is the Windows 10 playbook. The software doesn't snap in half. The safety net just vanishes piece by piece until staying put becomes the dangerous choice. Even I [pointed that out](https://www.freshfromcache.com/windows-10-out-of-support/) when Microsoft pulled the plug on security updates. ## Option 1: Stay on Desktop (for now) If you are on Desktop 2024, your runway lasts until September 30, 2027\. That is fifteen months of fully supported time. For many businesses, riding it out makes sense. Renew, keep working, and map an exit on your schedule. It will cost you, though. Intuit raised Desktop renewal prices on February 1\. Pro Plus jumped from $999 to $1,149 a year for a single user. Premier Plus went from $1,399 to $1,609\. Extra seats cost more now too. You are paying a premium to stay. Check your version before you plan anything. Open the app and press F2\. The year sits right at the top of the pop-up window. If it says 2023 or older, your safety net is already gone. Your timeline is now. ## Option 2: Move to QuickBooks Online This is the cloud transition Intuit wants. Your books live online, your accountant logs in from anywhere, and backups vanish from your daily checklist. The pricing moves fast. Simple Start runs $38 a month, Essentials is $75, and Plus hits $115\. Most businesses with inventory or project tracking need Plus. That totals $1,380 a year before payroll. Payroll adds another $50 a month, plus $6.50 per employee. Intuit raised Online rates by 15 to 20 percent last July. The core plans climb an average of 12 to 17 percent every year. Budget for a bigger number next season. The migration utility is free, and an Intuit rep will move the data over the phone at no charge. Three details trap owners: - **Payroll history vanishes.** Past paychecks turn into flat, standard checks. Historical detail must be rebuilt by hand. This is what fills the support forums with nightmare stories. - **Old reports do not map.** Run your historical profit and loss statements and balance sheets as PDFs first. Re-creating those exact numbers inside Online later is brutal. - **The clock ticks.** You have exactly 90 days to import Desktop data after creating an Online profile. If you miss that window, you start over with a blank file. Migrate at the start of your fiscal year if you take this path. A clean cutover beats trying to audit a mid-year system split. ## Option 3: Leave Intuit A forced migration is also a chance to shop around. If you're going to learn new software anyway, it doesn't have to be Intuit's. - **Xero** runs $25 to $90 a month and includes unlimited users on every plan, which QuickBooks charges extra for. It has a built-in import tool for QuickBooks files. - **Wave** is free for core accounting and invoicing. The paid tier is about $19 a month. Best fit for service businesses without inventory. - **Zoho Books** has a free plan for businesses under $50,000 in annual revenue, then starts at $20 a month. - **FreshBooks** starts at $23 a month and is built mostly for freelancers and very small service shops. The commercial reality: nearly every bookkeeper and accountant in America knows QuickBooks. Far fewer know Xero. Almost none know Wave or Zoho. Ask your outside CPA (if you have one) what platforms they support before purchasing anything. A cheap app costs more than it saves if your accountant bills you double time to decipher it. ![Yearly cost comparison: Desktop Pro Plus renewal $1,149, QuickBooks Online Plus $1,380, Simple Start $456, Xero $660, Zoho Books $0 to $240, Wave $0 to $228.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/v2-inline-2-costs-quickbooks-desktop-is-going-away.png) ## A few steps to take no matter what you choose 1. Press F2 in QuickBooks and confirm your version year. That number sets your deadline. 2. Save your historical reports as PDFs now. Profit and loss and balance sheet for every year you might ever need. Audits and loan applications don't care that you switched software. 3. Export your lists. Chart of accounts, customers, vendors. Every alternative can import them. 4. Talk to your bookkeeper or accountant before you commit to anything. Their answer might make the decision for you. None of this has to happen this week, unless you're on Desktop 2023 running payroll. Then it should. For everyone else, you have time to do this right. Joel If you've already made this jump, good or bad, I'd like to hear how it went. Reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). --- **Sources:** - [Intuit: QuickBooks Desktop 2023 service discontinuation policy](https://quickbooks.intuit.com/learn-support/en-us/help-article/feature-preferences/quickbooks-desktop-service-discontinuation-policy/L17cXxlie%5FUS%5Fen%5FUS?ref=freshfromcache.com) - [Intuit: Time limit for importing Desktop data to QuickBooks Online](https://quickbooks.intuit.com/learn-support/en-us/help-article/data-systems/time-limit-importing-data-quickbooks-desktop/L5k0SpO0w%5FUS%5Fen%5FUS?ref=freshfromcache.com) - [Insightful Accountant: Intuit announces pricing changes for QuickBooks Desktop](https://blog.insightfulaccountant.com/intuit-announces-pricing-changes-for-quickbooks-desktop?ref=freshfromcache.com) - [NerdWallet: QuickBooks pricing 2026](https://www.nerdwallet.com/business/software/learn/quickbooks-pricing?ref=freshfromcache.com) - [NerdWallet: Best QuickBooks alternatives](https://www.nerdwallet.com/business/software/best/quickbooks-online-alternatives?ref=freshfromcache.com) - [QuickBooks Community: Desktop to Online transition threads](https://quickbooks.intuit.com/learn-support/en-us/account-management/transition-from-quickbooks-desktop-to-online-nightmare/00/1408800?ref=freshfromcache.com) ### The cheaper Microsoft 365 plan Microsoft hides behind the cancel button URL: https://www.freshfromcache.com/microsoft-365-classic-plan/ Last updated: 2026-06-10T13:59:59.000Z My Microsoft 365 renewal notice showed up a few weeks ago. Yours probably said the same thing mine did. The price went up. The reason was Copilot. Microsoft added the AI assistant to home plans last year and raised the bill to match. The notice conveniently doesn't mention that there's a cheaper version of the same plan, minus the AI, at the price you used to pay. You have to go looking, and it only shows up in one place: behind the Cancel button. ## What Microsoft changed In February 2025, Microsoft folded Copilot into Microsoft 365 Personal and Family. The prices went up to match. Personal went from $69.99 a year to $99.99\. Family went from $99.99 to $129.99\. That's thirty dollars more on each, every year. The increase hit everyone, new and existing. Existing subscribers have a third choice, called Classic. Microsoft 365 Personal Classic is $69.99 a year. Family Classic is $99.99\. Word, Excel, PowerPoint, and Outlook all included. Even a terabyte of OneDrive storage. No Copilot, with the old price. Microsoft doesn't sell it. They don't advertise it. The offer only appears once you start to cancel your current plan. ![Microsoft 365 price comparison. Personal is $99.99 a year with Copilot versus $69.99 for Personal Classic; Family is $129.99 versus $99.99. Classic costs $30 less a year.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/diagram1.png) The business version is a separate price change on its own timeline, and I [wrote about that one here](https://www.freshfromcache.com/microsoft-365-prices-go-up-july-1/). Classic is only for existing subscribers. If you're buying Microsoft 365 for the first time, the cheaper plan won't be available. ## How to switch to Classic One thing has to be true before you start: auto-renew needs to be turned on. Classic is a swap that takes effect at your next renewal. If you've already switched auto-renew off, the offer won't show up. You'll see 'Turn on recurring billing' instead. Turn it back on. Then walk through these steps. (You can switch it off again later.) 1. Go to [account.microsoft.com](https://account.microsoft.com/?ref=freshfromcache.com) and sign in. Use the same Microsoft account you bought the subscription with. A different account won't show your plan. 2. Open **'Services & subscriptions'**. Your Microsoft 365 plan is listed there. 3. Find your plan and click **'Manage'**. 4. Click **'Cancel subscription'**. Yes, you're clicking Cancel on a plan you want to keep. The button sometimes reads 'Upgrade or Cancel'. 5. With any luck, you'll see a list of cheaper plans. Look for **'Microsoft 365 Personal Classic'** at $69.99, or **'Family Classic'** at $99.99\. If you don't see a choice of plans yet, it's because they only load after you've started to cancel. Don't back out before they appear. 6. Select the Classic plan and click **'Switch Plan'**. Confirm on the next screen. Once confirmed, nothing will change right away. Your current plan will run until its renewal date. When that date comes, Microsoft charges you the old price instead of the new one. You keep every app you had, minus the Copilot button. ![Where Classic hides: Manage, then Cancel subscription, then Choose Classic, then Switch Plan. The cheaper plan only appears at the Cancel step.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/diagram2.png) ## Look out if you use an app store If you bought Microsoft 365 through an app store, the steps above won't work. Subscriptions from the Apple App Store, Google Play, or a retailer like Amazon are billed by that company, not by Microsoft. So the 'Cancel' and 'Switch Plan' controls live on their side, if they're there at all. Classic may not be offered by them, but you can still call Microsoft and ask. Some accounts don't get the offer. Others get auto-renewed at the higher price before learning that Classic exists. If that's you, contact Microsoft billing support, ask for Classic by name, and ask about a refund while you're at it. And treat this as a now-or-never option. Microsoft has hinted it may drop Classic later, or start pulling features out of it. If you want the old price, switch before your renewal date. ## Why is Classic so secret? Putting the cheaper option behind the Cancel button certainly wasn't an accident. We don't click Cancel on a plan we intend to keep. Microsoft is very aware of this. In late October 2025, Australia's consumer regulator, the ACCC, took Microsoft to court over it. The claim is that Microsoft told around 2.7 million subscribers they had two options, accept Copilot at the higher price or cancel. No mention of a third option. Microsoft said it 'could have been clearer.' The case is still being argued in Australia. But the plan at the center of the lawsuit sits in your US account right now. It's not that any of this is illegal, but the cheaper option is real and Microsoft would rather not make it too easy. This is a pattern we've seen many times. A company adds AI, raises the price to cover it, then makes the AI-free option hard to find. It's the same shape as Microsoft [pushing Windows 10 holdouts toward new hardware or a paid upgrade](https://www.freshfromcache.com/windows-10-out-of-support/). You'll see it again, from Microsoft and from others. So before you accept any renewal that jumped in price, try clicking Cancel and see how badly the company wants to keep your business. If you went looking for Classic and the option never showed up, I want to hear what you saw on screen. You can contact me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). Joel ### Scammers first to the World Cup URL: https://www.freshfromcache.com/newsletter/scammers-first-to-the-world-cup/ Last updated: 2026-06-30T21:52:22.000Z One quick note before the news. Fresh From Cache has a new home, which is why this edition looks a little different. The platform underneath changed and the look got cleaned up, but it is the same newsletter landing every Tuesday. If anything renders oddly on your end, hit reply and tell me; I am still settling in. Thanks for being here for the first one! The World Cup kicks off Thursday, and the scammers beat the players to it. Fake FIFA sites are already collecting card numbers and passport photos from fans in a hurry. That is the headline this week, and the rest of the issue rhymes with it: a stranger who found a burner Instagram account from one bus ride, photos that give away your home address without you saying a word, and robocalls built on data scraped off your Google listing. None of it is the work of a genius hacker. It is mostly the trail you leave, picked up by someone paying attention. Then a lighter one to close, because I took an actual vacation and could not stop staring at the Wi-Fi. --- [**The World Cup Fraud Economy**](https://www.freshfromcache.com/the-world-cup-fraud-economy/) Thousands of fake FIFA sites are already live, weeks before the June 11 kickoff. Fake tickets, fake merch, fake job postings, streaming links that carry malware, betting sites that want a passport photo. The lost ticket money is the small part. The real damage is the card number, login, or ID you hand over while you are rushing. A few simple habits keep you out of the whole machine. *News* --- [**How a stranger on the bus found her secret Instagram**](https://www.freshfromcache.com/stranger-on-the-bus/) She had a private account with no real name and no profile photo. A stranger she traded a few seconds of eye contact with found it the same day and sent a follow request. The culprit is the friend-suggestion engine, which links people who share a location, a contact list, or a phone number, even when neither of them typed anything. A burner account tied to your real phone number still points straight back to you. *News* --- [**Your photos know where you live**](https://www.freshfromcache.com/your-photos-know-where-you-live/) Newer AI tools can take an ordinary photo with no map data attached and work out roughly where it was shot from the light, the plants, a sliver of a street sign. It reads like a party trick until it is pointed at a picture of your front yard. Here is what these tools can actually do today, what they cannot, and the two settings worth changing before you post. *Learn* --- [**Why the robocalls about your Google listing won't stop**](https://www.freshfromcache.com/google-listing-robocalls/) If you run a business with a Google listing, you already know the call. A friendly voice, sometimes an AI one, warning that your listing is about to be removed unless you act right now. The number on your public listing gets scraped, sold, and spoofed, which is why blocking one caller does nothing. What actually drops the volume is a different setup, and the post walks through it. *Learn* --- [**An IT Guy on Vacation**](https://www.freshfromcache.com/an-it-guy-on-vacation/) I finally took a real vacation, a cruise, and spent a good part of it failing to ignore the technology holding the whole thing together. The Wi-Fi that died the second I stepped into the bathroom and worked fine everywhere else. The access points hidden inside fake palm trees on the island. A working illusion, and me unable to stop looking for the seams. *Blog* --- **If you only read one:** The World Cup Fraud Economy. The tournament kicks off Thursday, the fake sites are already up, and the people most likely to get caught are the ones rushing to grab tickets before they sell out. Ten minutes now saves a stolen card later. --- Back next Tuesday. As always, you can hit reply and I'll see it. Joel ### Microsoft stopped patching Windows 10. Now what? URL: https://www.freshfromcache.com/windows-10-out-of-support/ Last updated: 2026-08-11T19:46:36.000Z **Update, August 11, 2026:** Microsoft added a second year of consumer Extended Security Updates in June. The dates below are corrected: free ESU now runs through October 12, 2027, not October 2026\. Everything about how to enroll still holds. *What "end of support" actually means, and the six ways to handle it.* I've been hearing a lot of chatter about Windows 10 being at "end of support". People are seeing a full-screen message about Windows 10 reaching "end of support," and figure it's a warning before the lights go out. It isn't. Your PC will still turn on. It'll still run your email, browser, accounting software. Nothing is *broken*. That's the confusing part. Everything you see still works fine. What's changing is your security updates. On October 14, 2025, Microsoft stopped sending free security updates to Windows 10\. Those updates are the reason [keeping software patched matters](https://www.freshfromcache.com/patching-is-the-new-password) in the first place. The computer keeps working. The patches stop coming. Every month, researchers and criminals find fresh holes in Windows. Normally Microsoft patches them within weeks. On Windows 10, those holes stay open now. One unpatched month isn't a crisis. A year of them, on a machine that's online all day, is a slow leak that gets worse the longer you ignore it. So nothing's broken. The real question is how much longer you want to run a machine nobody's patching, and what to do about it. You've got more options than the upgrade nag lets on. Six of them. A couple are free, one is a worse deal than it looks, and the right one depends on how you use your machine. ![Flowchart, "Which Windows 10 move is yours?" — routes from your PC through three questions (passes the Windows 11 check; managed by company IT; want to keep the machine) to one of four answers: upgrade to Windows 11, commercial ESU, consumer ESU then a long-term move, or recycle/donate.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-win10-decision-tree.png) Before trying any of these: back up your files. Every option here carries a small chance of a bad day, even the safe ones. A current backup turns a disaster into a nuisance. Not sure you've got a backup? [Start here](https://www.freshfromcache.com/do-you-need-backups). ## Option 1: Upgrade to Windows 11, free If your PC qualifies, this is the best path forward, [even if you hate Windows 11](https://www.freshfromcache.com/windows-point-in-time-restore/). It's free, but you might hit a hardware wall. Windows 11 needs a security chip called TPM 2.0, a setting called Secure Boot, and a processor from roughly 2018 or later (Intel 8th-generation or newer, AMD Ryzen 2000 or newer), plus 4 GB of memory and 64 GB of storage. A lot of working computers in production don't qualify. To check yours: - Open 'Settings', then 'Update & Security', then 'Windows Update'. - Look for the line telling you whether the PC meets Windows 11 requirements. Microsoft's free 'PC Health Check' app will give you the same answer, but will also name the requirement that failed. If your PC is only a few years old and still fails the check, it's usually not missing hardware. More often than not it's the TPM or Secure Boot setting switched off in the firmware. That's fixable, but it means a trip into a BIOS screen. If that's outside of your comfort zone, find a tech-savvy friend or family member for some help. It's easier than it sounds. ## Option 2: Stay on Windows 10 two more years for cheap or free Microsoft's selling an extension called Extended Security Updates, or ESU. For a personal PC it's far cheaper than people expect, and may even be free. All three deliver the same security patches through October 12, 2027: - Free, if you turn on Windows Backup and sync your settings to a Microsoft account. - Free, if you redeem 1,000 Microsoft Rewards points. - $30, one time, if you'd rather just pay. All three now make you sign in with a Microsoft account, the $30 option included. One enrollment covers up to 10 PCs on the same account, so a household or a one-person shop with a couple of machines only pays once. And the PC has to be caught up to Windows 10 version 22H2 before the option will appear. To enroll: - Open 'Settings', then 'Update & Security', then 'Windows Update'. - Look for 'Enroll now' and follow the prompts. No 'Enroll now' showing? Install all the pending updates first, then check again. Microsoft added a second year in June 2026, so consumer ESU now runs through October 12, 2027\. Treat it as a bridge rather than a reprieve, and use the time to plan a move. ## Option 3: Business PCs your IT manages play by different rules That cheap consumer route doesn't apply to a PC joined to a company domain, managed through something like Microsoft Intune, or locked into kiosk mode. If your business's computers are set up that way, the $30 deal won't be available. You're into commercial ESU, which Microsoft priced to push you off Windows 10 as quickly as possible. The cost is $61 per device the first year, then $122, then $244\. It's cumulative too, so waiting until next year to start means paying for the year you skipped. Good news for most small businesses, though: you might not be running managed PCs. If your computers just sign into regular accounts and aren't tied to a company domain, you most likely qualify for the $30 consumer route, even on Windows 10 Pro. Check before you assume you owe business pricing. And if you do run managed machines, that doubling price is Microsoft telling you to migrate. In this case, it's best to listen. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-win10-cost-ladder-1.png) ## Option 4: Force Windows 11 onto an "unsupported" PC You can put Windows 11 on a machine that fails the hardware check, using a free tool like Rufus to build install media that skips the requirement. People do it and often it runs fine. I won't tell you it's a clean answer, because it isn't. Microsoft doesn't support these installs, which means it can stop sending them updates whenever it likes, security updates included, which is the whole reason you're here. You'd be fixing a patching problem by building a PC that might stop getting patched. If you are a tinkerer with a spare machine and a backup? Have at it. But the computer your business runs on? That's one I wouldn't force. ## Option 5: Keep the hardware, swap the operating system A computer too old for Windows 11 is usually plenty fast for a free operating system that's still supported. Two come up most. Linux Mint looks and acts enough like old Windows that most people find their feet in a day, and it's free. ChromeOS Flex, from Google, turns an old PC into something close to a Chromebook, ideal if your work mostly lives in a browser. The tradeoff is software. Some Windows programs won't run on either. If your business leans on a Windows-only app (an older QuickBooks Desktop, say, or some industry-specific tool), check for a web or Mac version before you wipe anything. For browser-and-email work, this is the option that costs nothing and keeps a working machine out of a landfill. ## Option 6: Retire it. For real. Sometimes the best answer is the machine's retirement. If you're in Oregon, you've got two good local options, and the garbage can isn't one of them. Tossing a computer in the garbage has been illegal in Oregon since 2010. [Oregon E-Cycles](https://ecycleoregon.org/?ref=freshfromcache.com) recycles computers, laptops, tablets, monitors, and printers for free. Anyone can drop off seven or fewer items at a participating site at no charge. Households, small businesses, and small nonprofits with 10 or fewer employees can bring more, though call the site ahead of time. To find one near you, use the Locate Now tool on the site or call 1-888-5-ECYCLE. There are over 200 drop-offs around the state, including a lot of Goodwills. If the machine still works, think about donating it instead. [Free Geek](https://www.freegeek.org/?ref=freshfromcache.com), over in southeast Portland, takes working and dead devices alike, wipes them securely, and refurbishes what it can into low-cost computers for people who need one. Their refurbished machines run Linux Mint, which is Option 5 again, just handed to someone else. They take public drop-offs Wednesday through Saturday at 1731 SE 10th Avenue. Not in Oregon? Search "electronics recycling near me," or run your ZIP through [Earth911](https://search.earth911.com/?ref=freshfromcache.com). It maps free drop-offs by item, so you can check that a place takes laptops or monitors before you load up the car. ## Where people go wrong Doing nothing and hoping just isn't an option anymore. An unpatched PC doesn't fall over on day one, which is why it's easy to leave it for a year and then get burned. We've all let a nagging update sit. Pick an option, even if the option is "buy the $30 bridge and sort it out properly next year." And if you're staying on Windows 10 a while, [lock down everything around it](https://www.freshfromcache.com/start-using-a-password-manager/), starting with [two-factor on your email and bank](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it). Panic-buying a new computer the week the warning shows up isn't necessary. You've got more time and more room than the full-screen Microsoft nagging suggests. Not one of the six options above is a "drop a thousand dollars today" situation. None of this is an emergency. Your laptop or PC still works. Pick the option that fits how you use it, and get it done rather than leaving it. ESU buys you until October 2027 to figure out what's next. If it's still humming along by then, even better! Got an old Windows 10 machine and stuck on which way to go? Reach out to me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). Joel ### Your TV has a side hustle, and you're paying for it URL: https://www.freshfromcache.com/tv-side-hustle/ Last updated: 2026-08-11T18:28:50.000Z Right now your TV might be off, but it could still be awake. It might be fetching web pages for a stranger, using your internet and under your name. According to research published June 5 by Include Security and independent researcher Buchodi, your smart TV could be acting as a relay for someone else's web traffic. A company called Bright Data sells access to that relay network. It markets the result as the largest of its kind in the world with more than 400 million home internet addresses its customers can route through. Over 150 million of them come from this software sitting inside apps people installed themselves. Let me back up and explain. ## What's going on here Normally your internet traffic leaves from your house. You load a page, the request goes out with your address on it, the page comes back. A proxy flips that around. It sends someone else's traffic out through your connection, so the website on the other end thinks the request came from you. That someone else, here, is in the business of scraping. Scraping just means downloading web pages automatically, by the millions. AI companies need enormous piles of text and images to train their models, and scraping is how they get it. Your TV's data is much more valuable than it used to be. Major websites have gotten good at spotting scrapers. When thousands of requests pour in from a data center, they block them. So the scrapers found a way around it: route the requests through real homes instead. A request that arrives from a Comcast or T-Mobile customer looks like a regular person checking a page. So your TV becomes what the trade calls an exit node. The last stop before the website. The traffic looking like it came from you. ## Why the TV and not the phone If you wanted to pick the perfect device for this, you would pick a smart TV. A phone has a battery that dies, jumps between networks, and gets locked in your pocket. A TV does none of that. It is plugged into the wall. It is on fast Wi-Fi. It sits in standby all night with nobody watching. Its data use is effectively unlimited, because who checks how much their television downloads. The disclosure where you supposedly agreed to all this is one you clicked through when setting up your TV. ## The "free" part isn't free These are free apps. Little games, screensavers, that sort of thing. The deal they offer is the same one tech companies have used for years. You get the app for nothing, and in exchange the app gets to use your stuff. The researchers pulled up the consent screen from one of them, a Roku app called Petflix. It tells you that you can watch for free with fewer ads. But really, you are letting Bright Data "occasionally" use your device's resources and your IP address to download public web data. Occasionally, being entirely defined by them. Here is what "occasionally" looked like underneath. The software's worldwide default budget is 500 megabytes a month. That one app's settings were configured for 200 gigabytes a month. A four-hundred-fold difference behind it. I am not saying every app runs at 200 gigabytes, but clearly they are bold enough to exceed the "default". It gets better. The software has a rule for when your device counts as "idle" and free to go to work. That rule counts you as idle even when the screen is on. Even when you are on a phone call. Idle does not mean you stepped away. It means the chip has a spare moment. ## None of this is new. It's just bigger now. The company behind this software has a history. It used to be called Luminati, and Luminati grew out of a free service called Hola VPN. Back in 2015, people figured out that Hola was selling its free users' bandwidth out the back door through Luminati. One of the paying customers used that pool of borrowed connections to knock the website 8chan offline. The operator of 8chan put it plainly at the time: Hola had a nine-million-machine army on its hands, and it had started renting it out. Same company. Eleven years later, rebranded as Bright Data, the model has moved off the laptop and onto TVs in the living room. Bright Data has teeth. Both Meta and X took it to court to stop it from scraping their public data. Both lost. The judges agreed that anything you can see without logging in is fair to collect. Those wins are a big part of why the company is pushing this network so hard. The researchers found Bright Data publishing a list of its app partners on a page anyone can read. The names include PlayWorks, which makes hundreds of TV games and claims its software reaches a quarter of a billion television homes through carriers like Comcast, Sky, Cox, LG, Samsung, Vizio, and Roku. Other big names are on the list too. One honest caveat, the same one the researchers make. Being on that list means an app worked with Bright Data at some point. It does not prove your particular app is running this software today. So I am not going to tell you your particular Samsung TV is doing this. I am telling you that certain free apps on these platforms have, and that you cannot tell from the couch which ones they are. ![A hand holding a phone in front of a smart TV, both screens filled with rows of streaming and app icons.](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/pexels-jakubzerdzicki-35490407.jpg) Bright Data's position is that all of this is consensual, that you can opt out in a couple of steps, and that the software only runs when it will not bother you. When some app makers were asked about it, a few stopped answering, and a few pulled the software out of their apps. The researchers emailed the company before publishing. They got no reply. ## What this is, and what it isn't For the average person, the reality is this. Your internet connection, and a little of your power bill, are being spent on a company's product. That alone would be enough to annoy me. The part that should give you pause is the address. When your TV relays that traffic, your home is the return address on it. If some of those requests are hitting places that fight back, or doing things you would never do, it is your connection that wears it. At a minimum that can mean your own browsing starts getting blocked or stuck behind those "prove you're human" checks. And the plumbing is sloppy. The researchers found the channel carrying these jobs had almost no security on it, could slip past a [VPN](https://www.freshfromcache.com/what-a-vpn-actually-does) on an iPhone, and tied your devices together across platforms behind the scenes. By their measure, it was built worse than the tools criminals use to run actual malware. ![A hand holding a phone that displays a VPN app's "connected" screen, with a smart TV blurred in the background](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/pexels-stefan-coders-1019774-5146492.jpg) To be fair, this is the legal, you-agreed-to-it end of this business. This isn't quite the same as uglier practices. Criminal networks hijack devices nobody has consented to. The FBI warned about it in March: [streaming gadgets, picture frames, and routers](https://www.freshfromcache.com/router-expiration-date/) drafted into hiding someone's crimes behind an ordinary home. The Bright Data story is not that. There is no virus to remove. Nobody broke in. You agreed, on a screen built to be skipped, and that is what makes it shady. **Update, June 18:** Days after this ran, Krebs on Security reported a live case of the criminal version. A botnet called Popa has spent about four years turning millions of cheap Android TV boxes into traffic relays for ad fraud, account takeovers, and scraping. Researchers at Qurium and HUMAN Security tied it to NetNut, a home-proxy provider owned by Alarum Technologies, a publicly traded Israeli company. These are the no-name streaming boxes sold cheap online with the proxy software already built in. Same idea as the apps above, except nobody clicked agree. ## What to do about it A few steps you can take, none of them drastic: - **Be choosy about free apps on the TV.** Especially little games and screensavers. If an app asks to "use your device's resources" or "share your connection" to download "web data," that is the trade. Say no, it's not worth it. - **Clean house.** Go through the apps installed on your TV and delete the free ones you do not use. - **Stick to names you know.** A free game from a publisher you have never heard of is the higher risk. The big streaming apps are not where this is happening. - **Watch the small signs.** A TV that runs warm, or chews through data while it is just sitting there, should be looked at. The lesson here is not new. If the app is free and there are barely any ads, the thing being sold might be your connection. ### If you're feeling a little brave There is a stronger move, and it lives in your router. You can tell your network to refuse the specific addresses this software phones home to, which shuts off the relay without touching anything you watch. The researchers published the addresses to block: - proxyjs.brdtnet.com - proxyjs.luminatinet.com - proxyjs.bright-sdk.com - clientsdk.bright-sdk.com - clientsdk.brdtnet.com You would add those to a blocklist in your router's DNS settings, or in a tool like NextDNS or Pi-hole if you run one. If that last sentence did not mean much to you, no harm done. The steps above will do the trick. If your TV turns out to be running one of these, or you block those addresses and want to tell me how it went, I would like to hear it. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). Joel **Sources:** [Include Security / Buchodi](https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/?ref=freshfromcache.com) (primary research); [The Hacker News](https://thehackernews.com/2026/06/free-apps-are-quietly-turning-smart-tvs.html?ref=freshfromcache.com); [Lowpass](https://www.lowpass.cc/p/smart-tv-web-scraping-ai-bright-data-proxy-networks?ref=freshfromcache.com); [TechSpot](https://www.techspot.com/news/111492-smart-tv-apps-quietly-scraping-web-data-ai.html?ref=freshfromcache.com) (Bright Data's statement); [VentureBeat](https://venturebeat.com/ai/bright-data-beat-elon-musk-and-meta-in-court-now-its-100m-ai-platform-is-taking-on-big-tech?ref=freshfromcache.com) (Meta and X court wins); [FBI IC3 PSA, March 12, 2026](https://www.ic3.gov/PSA/2026/PSA260312?ref=freshfromcache.com); [PCWorld, 2015](https://www.pcworld.com/article/427726/ultra-popular-hola-vpn-extension-sold-your-bandwidth-for-use-in-a-botnet-attack.html?ref=freshfromcache.com) (Hola history); [Krebs on Security](https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/?ref=freshfromcache.com), June 2026 (the Popa botnet, NetNut/Alarum). ### The World Cup Fraud Economy URL: https://www.freshfromcache.com/the-world-cup-fraud-economy/ Last updated: 2026-08-11T18:28:36.000Z The 2026 World Cup kicks off June 11, but the scammers have already taken the field. The FBI put out a public alert this week about fake FIFA websites, and the security firms that track this stuff say the fraud is already running at scale. Group-IB counted more than 4,300 fake FIFA domains registered since last August. FortiGuard Labs logged over 13,000 World Cup-themed domains in the first five months of this year and flagged close to one in eleven as malicious or suspicious. The FBI's own alert names dozens of spoofed sites and says more are coming. Most of these run on a trick called typosquatting, which is registering a web address that sits one letter or one ending away from the real one (fifa.com versus a lookalike with an extra letter, or a .net where the real site uses .com). The fake page copies FIFA's logo, colors, and layout closely enough that a quick glance won't catch it. You think you're buying a ticket, and you're handing your name, address, and card number to a stranger. The FBI says those stolen details get reused later to open accounts in your name. Tickets are only one lane being exploited. Researchers found counterfeit merchandise shops, fake job pages on addresses like jobs-fifa and fifa-hiring, and bogus streaming sites that charge a subscription and then install malware that hands your device to the attacker. Some fake betting sites ask for a passport scan and a selfie, which is everything an identity thief needs in a single upload. Bitdefender tracked "you won the FIFA lottery" emails promising payouts up to $2 million. FIFA reported more than 150 million ticket requests in the first 15 days for roughly 6 million seats, so there are a lot of anxious fans with money ready to move. The reach is huge, with matches in 16 cities across the US, Canada, and Mexico. Since Seattle is a host site, anyone in the Pacific Northwest is going to be blanketed by the targeted ads driving these campaigns. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/pexels-pixabay-270085.jpg) Every big event creates its own little fraud economy. It happened with the Olympics, with concert ticket sites, even at Covid vaccine sites. The World Cup is just the largest version yet. Unfortunately, losing the ticket money is rarely the worst outcome. The damage that lasts is the banking detail, the password, or the photo of your passport you handed over while you were focused on getting a seat. That is the part that follows you around after the final whistle. What to do: - **Type the address yourself.** Go to fifa.com directly, or use a saved bookmark. Do not Google the tournament and click the top results, and absolutely do not click the sponsored links. - **Buy through official channels only.** FIFA sells tickets through its own site. A "great deal" in a social media ad or a stranger's DM is a scam. - **Slow down on streaming "deals."** A site that wants a subscription to stream matches and then asks you to install an app is a well-worn malware path. If you hadn't heard of it last month, don't install it. Our [guide to spotting a phishing attempt](https://www.freshfromcache.com/how-to-spot-a-phishing-email/) covers the same red flags to look out for. - **Pay with something that has recourse.** A credit card charge can be disputed. A wire transfer, gift card, or crypto payment usually cannot. Do not use a debit card. - [**Turn on two-factor**](https://www.freshfromcache.com/start-using-a-password-manager/)**.** If a fake login does grab your password, [MFA](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/) is what keeps the thief out of the account. - [**Report it if you get hit**](https://www.freshfromcache.com/what-to-do-after-a-scam/)**.** The FBI takes fraud reports at [ic3.gov](https://www.ic3.gov/?ref=freshfromcache.com), and flagging a fake World Cup site helps investigators map the network and warn the next person. The loss figures going around (one estimate puts premium and hospitality ticket fraud alone somewhere between $71 million and $474 million) are projections based on how much fake infrastructure is out there, not confirmed losses, so read them as a measure of effort rather than a tally. Most fans won't get burned, but the cost of being careful is close to zero. The cost of one bad click is your card, your identity, or both. Seen a fake FIFA site or a streaming "deal" that smelled wrong? Forward it to me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). I'm keeping a running list of the worst ones, and a real example beats a warning every time. Joel **Sources:** - The Hacker News, *FIFA World Cup 2026 Scams Are Already Live* — [https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html](https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html?ref=freshfromcache.com) - BleepingComputer, *FBI warns of fake FIFA websites running World Cup fraud schemes* — [https://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-fifa-websites-running-world-cup-fraud-schemes/](https://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-fifa-websites-running-world-cup-fraud-schemes/?ref=freshfromcache.com) - Bitdefender Labs, *FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup* — [https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-fifa-scams-2026-world-cup](https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-fifa-scams-2026-world-cup?ref=freshfromcache.com) - The Next Web, *FIFA World Cup 2026 scams are live* (Group-IB and Fortinet figures) — [https://thenextweb.com/news/fifa-world-cup-2026-scams-phishing-malware](https://thenextweb.com/news/fifa-world-cup-2026-scams-phishing-malware?ref=freshfromcache.com) ### Why the robocalls about your Google listing won't stop URL: https://www.freshfromcache.com/google-listing-robocalls/ Last updated: 2026-08-11T18:28:29.000Z I registered my consulting business on Google a few months ago. Within days my phone was ringing every few minutes during business hours, always the same message: my listing can't be found, my profile isn't verified, my business will vanish from search unless I press 1 right now. I knew it was a scam by the second call. Knowing that did nothing to stop it. The calls start because your Google listing is public and gets harvested on a schedule. The numbers are faked, so blocking is pointless. And every time you engage, you mark your number as worth calling again. The rest of this is why each of those is true, and the handful of things that actually cut the calls down. ## What these calls actually are They are lead-generation and fraud operations pretending to be Google. The script has more than a hundred variations, but the shape never changes: a made-up problem with your listing, a threat that customers won't find you, and an urgent push to press a number. Press 1 and a "specialist" sells you something Google gives away free, or coaxes you toward your profile login. Press 2 to "opt out" and you have just confirmed your number reaches a real person who responds, which is the most valuable thing a spam list can learn about you. Hiya, a call-protection company, has documented this for years. Its honeypot (a network of unlisted decoy numbers that exist only to catch spam) captured more than 17,000 of these robocalls in a single span of a few months, on top of 2,000-plus user reports every month. Those decoy numbers belong to no business and no person at all, which tells you the callers are dialing blind, in bulk. And it has not let up; small-business marketers reported a sharp jump in these calls through late 2025 and into 2026. For the record, Google never cold-calls owners to sell listing services or threaten a free profile. The only real Google call is one you asked for through your dashboard. Google has even sued over this. In 2022 it took an Ohio operation called G Verifier to federal court for charging owners $99 to "verify" free profiles and threatening to mark their listings permanently closed. Shutting one operation down does not slow the rest, because the model costs almost nothing to run. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/diagram-google-listing-robocalls.png) ## Why it starts the day you list Your Google Business Profile is public by design. That is the entire point of it. Your name, your category, your city, and your phone number sit in Google's structured data in a predictable format, which is exactly what makes them easy to scrape (to pull automatically with software). Bots crawl Google Maps daily and pull every new listing. A real local business that answers the phone is a high-value lead, because someone actually picks up. So your number gets bundled into lists like "small business owners in Oregon," sold for a few cents a name, and resold through brokers you will never see. You did not get targeted because you did anything wrong. You got harvested because you showed up in a place that scammers scrape on a schedule. ## Why everything you try fails I tried all of the obvious moves. Here is why each one failed. Blocking does nothing. The numbers are spoofed, usually faked to match your own area code so you will pick up, and the supply is effectively infinite. Block one and the next call comes from a fresh number. It is the one tactic guaranteed to fail. Arguing does worse than nothing. Berating the recording, playing along, feeding it fake details to "update" its records, all of it tells the system your number is live and answered by a human who engages. That is the single most valuable signal a number can carry, and it gets you flagged and resold. The "press 2 to opt out" option is the same trap wearing a helpful mask. And there is no central record to correct. You might be picturing one caller with one database you can fix. It is an ecosystem. Your number was scraped once and sold across dozens of lists and brokers, so there is nothing to call back and change. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/pexels-olly-3777565.jpg) ## The new part: the voice seems real Here is what changed, and it is the part that unsettles me. A year ago these calls were obviously robotic. Now the voice hesitates, says "um," corrects itself, and answers back if you talk to it. Some of them pass for a distracted human having an ordinary day. That realism is the upgrade. It buys a few extra seconds of your attention before the pattern gives it away, and those seconds are where people get caught. This is the same AI impersonation I wrote about in [Fake face. Real money.](https://www.freshfromcache.com/fake-face-real-money), just pointed at your phone instead of a finance department. The law has noticed. In February 2024 the FCC ruled that AI-generated voices count as "artificial" under existing robocall law, which means an operation blasting these at you without consent is already breaking the rules, and the FTC shut down several AI-robocall outfits in a 2024 enforcement sweep. The catch is that "illegal" and "stopped" are two different things. These operations spoof their caller ID and route through carriers that do not ask questions, so the law has not slowed this down at all. ## What actually works You cannot win this with the block button. What works is cutting off the source and keeping everything else away from you. - **Get your real number off the public listing.** - Whatever number sits on your profile is what gets scraped, so set up a free Google Voice number and make that your profile's primary phone, the one customers see and tap. There is no two-number confusion: customers only ever reach that one number, and your real cell goes in the secondary slot, which is for Google's records, not a second "call us" line. - Set the Voice number to forward to your phone, so real calls still ring you and you answer normally, and turn on Voice's spam filter so the robocalls to it drop into a spam folder instead of ringing through. This will not silence today's calls, because your real number is already on the resale lists. - What it does is stop your real number from being harvested again and give the public line a filter you control. (Heads up: Google sometimes reviews or delays a number change, and a fresh Voice number with no other web footprint can trip that review.) - **Let unknown numbers go to voicemail, and** [**let your carrier block what it can**](https://www.freshfromcache.com/stop-spam-calls/)**.** This is the real lever, and it is the opposite of answering. When a call is answered, even silently, the dialer can mark your number as a live line and call it more; when it rings out to voicemail or hits a "not in service" wall, you become a worse target. So do not pick up unknowns. Real customers leave a message, and so will Google on the rare call you asked for. On top of that, turn on your carrier's network blocking (Verizon Call Filter, AT&T ActiveArmor, T-Mobile Scam Shield), which can stop known-bad numbers before they ever ring. It stays a step behind fresh spoofed numbers, so it thins the calls rather than ending them. - **Report it, then let it go.** File at reportfraud.ftc.gov and use Google's own scam-call report form. It will not stop your calls today, but it feeds the enforcement that has already shut some of these operations down. A word on Call Screen, since it is tempting. On a Pixel, Google's assistant answers the call and makes the caller explain themselves, which is great for never having to talk to a scammer. But notice that it answers the call, and to a dialer doing answer-detection that can still read as a live line. It also never hands over the dangerous signal, a human pressing a key or saying "yes," so it is far safer than picking up yourself. Treat it as triage that protects your sanity, not as the thing that shrinks your call volume. ## Don't leave Google Do not take your business off Google. The listing is genuinely useful, the harvesting is the cost of being findable, and pulling it hands the scammers a win without getting your phone back. Your number is already out there. Do what you can, and try to refrain from yelling at the AI. Joel *If you're getting these too, I'd like to know how bad it's gotten for you. Reach me at* [*joel@freshfromcache.com*](mailto:joel@freshfromcache.com)*.* --- **Sources:** Hiya, "Scam of the Month: Google Business Profile scam" (blog.hiya.com); Google's 2022 lawsuit against G Verifier (US District Court for the Southern District of Ohio, Nov 2022); Google Business Profile Help, "Help protect against fraudulent calls"; Google Voice Help, "Block calls & messages or mark as spam"; FCC Declaratory Ruling recognizing AI-generated voices as "artificial" under the TCPA (Feb 8, 2024); FTC "Operation AI Comply" (Sept 2024); Sterling Sky, on hiding or swapping the phone number on a Google Business Profile. ### An IT Guy on Vacation URL: https://www.freshfromcache.com/an-it-guy-on-vacation/ Last updated: 2026-08-11T18:29:31.000Z Do you ever think about how much technology it takes to run a cruise ship? Probably not, and that is by design. A cruise is built to feel effortless, so the last thing anyone wants is for you to notice the wiring holding it together. I noticed. I couldn't help it. It had been almost two years since I had taken any real time off. My wife and I both changed jobs not long after our last vacation, and the stretch in between was mostly just getting our footing again. New jobs, new hours, new routines. By the time we could finally get away, we did not want a trip that felt like work. We wanted somewhere warm with everything included, where the hardest decision was what to eat and when to get in the water. Getting away is hard for us anyway. We have two wonderful, completely spastic dogs who happen to be very needy, and there are maybe five people on the planet who could stand a week with them. It usually falls to my mother-in-law, but she has been swamped lately too. So a real vacation takes some luck. This time the stars aligned. The last trip we planned ourselves was London, and I loved it. But exploring a new country is a lot of planning and logistics. A cruise is mostly easy. You hustle to get to the ship, but once you are on, the freedom is hard to match. You can eat what you want, see what you want, or do nothing at all. We needed that more than we needed another country. You still see somewhere new, but it is a curated version of it. Exploring-lite. For the most part, the not-thinking worked. The day job lifted completely, mostly because I have someone on my team who is good at handling things, though Fresh From Cache and my own consultancy did tag along; uninterrupted time to tinker with your own projects is its own kind of vacation. When I take a shower, I like to watch YouTube. I know, it is a little odd, but it is not so different from people who listen to music in there. So every time I went to take a shower, I would get my YouTube loaded up, hop in, and then it would stop working. I was connected to Wi-Fi, but the video just would not load. Eventually I caught the pattern. Anywhere else on the ship, it was fine. The second I walked into the bathroom, I had nothing. And I was still connected to the AP(Access Point for Wi-Fi), so it was not as if the bathroom were some makeshift Faraday cage. When I looked at my settings, I got that message every IT person dreads: [connected, no internet](https://www.freshfromcache.com/why-does-rebooting-your-router-work/). In my experience, that message usually means one of a couple of things. Either the AP you are connecting to is having issues talking to the rest of the network, or the information the AP is handing you is wrong. I have also seen it from certificate issues and some DHCP wonkiness. So I had theories. The problem was that none of them mattered, because there was nothing I could do about it from inside a shower. If I was in the bathroom, nothing I tried made the internet work. Just outside the bathroom? Perfect. It was not a big deal, but it became a running joke, and it intrigued my IT brain. I wanted to know why, and I wanted to know how to fix it. Once I accepted my fate, I started paying attention to everything that *was* working instead, which on a ship that size is almost everything, almost all the time. The bathroom thing stuck with me, though. It nagged at me enough that when I got home, I went looking for how any of it actually works. (Yes. I researched cruise ship Wi-Fi after my cruise. This is the kind of thing you are dealing with here.) It starts in space. Royal Caribbean runs Starlink, branded as VOOM, rolled out across the fleet starting in 2022\. The reason it no longer feels like the garbage cruise Wi-Fi used to be is that Starlink's satellites sit in low Earth orbit, much closer than the old ones, so the lag is a fraction of what it was. There I was, streaming YouTube in a shower in the middle of the Atlantic. Or trying to. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/inline1-hull-canyon-1.jpg) Then it has to get to you, which is the hard part, because a cruise ship is a giant steel box. A Cisco engineer put it this way: a single ship can run as many access points as a stadium, and 4,000 of them on one ship is not unusual. The trick is putting an access point in nearly every cabin, because the same heavy steel that makes coverage hard also keeps the signal trapped in the room with you. That answered my bathroom problem. The strongest signal is out in the public spaces, and the dead spots are the enclosed metal corners. A bathroom, inside a cabin, inside a hull. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/inline2-provisioning-2-1.jpg) But the Wi-Fi is the part you are supposed to notice, because you paid for it. What gets me is everything you are not. A ship almost identical to mine, built more than a decade ago, shipped with around 1,100 surveillance cameras, a phone and wireless in every single cabin, and a few hundred networked touchscreen signs just to tell you where the next show is. None of which you think about as technology while you are handing over the key card that is also your room key, your wallet, your bar tab, and your boarding pass. Or while several thousand people board in a single afternoon. Or while something, somewhere, spreads the crowds out so the place never feels as packed as it is. There is far more IT than meets the eye, and that is the entire point. You are on a floating amusement park, and nobody wants you to see the wiring. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/inline3-central-park-atrium-1.jpg) Which is what got me thinking. Tourists are some of the most complaint-prone people alive, so the second anything breaks, everyone hears about it. But that is the goal. If one small glitch is the thing that stands out, the rest of the machine is running so well that the glitch is all there is to notice. The frozen video in my bathroom became the running joke of the trip precisely because nothing else broke. It was the one spot where the illusion slipped, and it slipped only because everything around it was holding. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/inline4-royal-beach-club-map.jpg) The same thing happened the second we stepped off the ship. At Perfect Day at CocoCay and at the new Royal Beach Club, there was full Wi-Fi too. I knew where it was coming from. I just wanted to find where they were hiding the APs. They had to be up high, and they had to be physically wired back to something. In most cases they either hid them in fake trees or strapped them to the corner of the signage. There were quite a few, and unless you were really looking for them, they did a great job of both hiding them and covering the whole place. The not-being-able-to-switch-off part did not bother me, because I was not obligated to do anything with it. It was more like watching the technology I work with every day show up somewhere completely opposite, somewhere built from the ground up to maintain an illusion. And it made me think about the stakes. The access points and networks and back-end systems that make a floating amusement park feel effortless are not exotic. The same unremarkable gear, pointed somewhere else, keeps a hospital running, or guards somebody's life savings, or just spares a person a phone call. Same parts, wildly different stakes. That is the part I keep turning over: how the same small handful of tools can be aimed at almost anything. And when all of it clicks into a machine that simply works, I cannot help but appreciate it, whatever job it happens to be doing. I think I was just an IT guy on vacation. That is most of what was rattling around in my head between pool days. I know it is not what most people are thinking about poolside. If the Wi-Fi did nothing for you, that is fair. Maybe you just came for the Bahama pictures. I took plenty of those too. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/gallery1-perfect-day-pier.jpg) ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/gallery2-atlantis.jpg) ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/gallery3-paradise-island-aerial.jpg) ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/PXL_20260526_225717945.jpg) ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/PXL_20260531_042422071-1.jpg) Back home ### Your photos know where you live URL: https://www.freshfromcache.com/your-photos-know-where-you-live/ Last updated: 2026-08-11T18:28:49.000Z I stumbled upon a story about a man who tracked down a pop singer by using a reflection in her eye from a photo of her. It sounded unbelievable, so I had to try an experiment myself. Reverse image search has been around for years, and it’s mostly been handy. Find the source of a meme. Check whether a listing photo is stolen. Useful, but often didn’t give many results. This was entirely different. I opened a fresh chat with an AI assistant (Claude, the one I use, though the same trick went viral with ChatGPT in spring 2025) and handed it a vacation photo from a recent trip to Nassau. A few people and some scenery, nothing I’d have called a giveaway. It named the spot in about two seconds. So I had to make it a bit harder. I dug up a photo from almost ten years ago with nothing in it. The corner of a building. A couple of trees. No signs, no numbers, no street. It slowed down, but not by much. It told me I was in the Pacific Northwest, then narrowed to northwest Oregon, going off the architecture. Nothing in that photo said “Oregon” to me, but it saw something I couldn’t. So I had to try one more time with a little bit more info and a tiny bit of prodding. A photo about seven years old, metadata stripped out, taken looking out of a third-story window onto a street. No street signs or landmarks. Just a few vague outlines of a building in the distance. At first it guessed either Salem or Portland. Close, so I gave it one nudge: Happy Valley. From there it worked out the likely street, then a short list of three candidate buildings. I told it the building wasn’t a hotel and asked it to also guess the floor I was on. After a total of five minutes of me being deliberately stingy with any detail, it had the exact building, floor, and even which side of it I’d been standing on. I was holding back on purpose to test the theory. But if a photo had even one more detail, it wouldn’t have been even close to a fair fight. ## The stalker and a reflection In 2019, a man in Tokyo tracked down a young pop singer named Ena Matsuoka using her own selfies. He enlarged the photos and studied the scenery reflected in her eyes, picked out the train station she used, and matched it on Google Street View. He studied the curtains and the angle of daylight in videos she’d posted from home to figure out her floor. Then he waited outside her building and attacked her. That was one obsessed person, tracking her slowly, by hand. The “slowly, by hand” part has completely changed. ## AI stripped away the hard parts In 2023, a few Stanford students built a model called PIGEON that plays GeoGuessr, the game where you get dropped into a random Street View and have to guess where in the world you are. It beat one of the best human players alive, six rounds to none. [This AI is better than you at figuring out where a street pic was taken just by looking at itPIGEON, from a trio of Stanford computer scientists, geolocates images from visual cues alone and beat a top GeoGuessr player.The Register](https://www.theregister.com/2023/07/15/pigeon%5Fmodel%5Fgeolocation/?ref=freshfromcache.com) Two years later, in April 2025, regular people noticed ChatGPT could do the same thing to any photo you fed it. Someone handed it the inside of a random library; it named the exact library in twenty seconds. [The latest viral ChatGPT trend is doing ‘reverse location search’ from photosPeople are using ChatGPT’s o3 and o4-mini models to figure out the location shown in a photo.TechCrunch](https://techcrunch.com/2025/04/17/the-latest-viral-chatgpt-trend-is-doing-reverse-location-search-from-photos/?ref=freshfromcache.com) There’s now a tool called GeoSpy that sells this as a service and claims it can get you within a few feet. After a 404 Media investigation turned up people using it to track women, the company pulled its free public version and now sells mostly to law enforcement and vetted businesses. Work that used to take a trained intelligence analyst, or a very determined stalker, is now a free feature anyone can poke at over coffee. ## What’s actually happening The most interesting part of this is that it isn’t reading hidden metadata in the photo file. Every photo your phone takes can carry hidden tags called EXIF data, and that includes the exact GPS coordinates of where you stood. For years the advice has been simple: strip that data before you post and you’re covered. Most social platforms strip it for you on upload anyway. That advice is now not good enough. I’d stripped the data out of the apartment and street photo. It found the place (or close to) anyway. The actual picture itself is what gave the location away. It reads what’s in the frame, the way that stalker did, only faster and across the whole planet at once: the architecture, the trees, the color of the soil, the angle and warmth of the light, the font on a half-covered sign, even which side of the road the cars drive on. My blank wall and two trees said “northwest Oregon” because building materials and plant life are a regional fingerprint, even when nothing in the shot is labeled. ## Two different problems There are really two separate things to worry about. The first is the file. Even when the AI ignores your metadata, the photo you upload still lands on a company’s servers with whatever GPS tags are baked in, and so does every photo you text or email to a person. Strip the data and that exposure will go away. The second is the picture. Stripping metadata does nothing here. If the image shows enough of the world, the content is the location, and there’s no field to scrub. The only defense is being careful about what’s in the actual picture. Both are real concerns; they take different habits to handle. ## It’s also wrong, a lot On easy photos it’s instant. On hard ones it gets the region and then fumbles the specifics. One reviewer fed it a resort photo and it nailed the right island but missed the actual resort by forty-six miles. Plenty of attempts simply fail. PIGEON, the model that crushed the GeoGuessr champ, still had a typical miss measured in tens of kilometers. The real risk isn’t dramatic. A single beach photo is unlikely to hand a stranger your home address. The slow and deliberate search is the one that works: a few photos, a pattern of posts, and somebody patient feeding it hints. That’s how my window shot went from “somewhere in Oregon” to an exact floor. I’ve [written before about not panicking over every new AI headline](https://www.freshfromcache.com/boring-ai-advice/), and that still holds. This is worth understanding, but not worth losing sleep over. ## What to do if you’re concerned First, turn off your camera’s location tagging. That solves the GPS-in-the-file problem at the source. On iPhone: Settings, Privacy and Security, Location Services, Camera, set to Never. On Android: open the Camera app’s own settings and turn off location tags (the wording can differ depending on which phone and version). If you’re not sure, you can take a screenshot of your photo instead of posting the original. A screenshot will carry no original metadata. It won’t help with what’s in the content of the photo, but it’s a good habit if you’re worried. Take a second to look at what’s actually in the shot before you post it. The street outside the window, the view that outs your hotel, or, apparently, even the reflection in someone’s eyes. You don’t have to stop posting, take a look first. Check the location settings on the apps you post from. Instagram and the others have [settings that tag or broadcast where you are](https://www.freshfromcache.com/what-location-sharing-actually-shares/); you can turn those down to nobody. And the easy one that matters most: be stingier with photos of where you live and sleep than with everywhere else. 💡 The one habit worth building: turn off your camera’s location tagging, and post a screenshot when you’re not sure what’s in the frame. ### What about the photos I’ve already posted? You can’t recall them, and [the AI can’t un-see what was already public](https://www.freshfromcache.com/meta-instagram-ai-feature/), so don’t spiral. Going forward, turning off your metadata is the easy move (geotagging). For older posts, be more targeted: delete or lock down the handful of photos that show where you live, or anywhere else you wouldn’t want somebody to easily find. You don’t have to delete anything to take this seriously. The best change you can make is to look at your own photos the way a stranger might, and to do it before everyone else gets the chance. If you try this on your own photos, I’d like to hear how it went, especially if it pulled something it had no business knowing. [joel@freshfromcache.com](mailto:joel@freshfromcache.com). Joel ## Sources - **The stalker who located an idol from reflections in her eyes (2019):** Newsweek, "Stalker Finds Japanese Idol's Home From Reflections in Her Pupils," [link](https://www.newsweek.com/stalker-finds-idol-reflection-pupils-1464373?ref=freshfromcache.com). - **PIGEON beating a top GeoGuessr player (2023):** The Register, "This AI is better than you at figuring out where a street pic was taken just by looking at it," [link](https://www.theregister.com/2023/07/15/pigeon%5Fmodel%5Fgeolocation/?ref=freshfromcache.com). - **The April 2025 viral ChatGPT location trend:** TechCrunch, "The latest viral ChatGPT trend is doing reverse location search from photos," [link](https://techcrunch.com/2025/04/17/the-latest-viral-chatgpt-trend-is-doing-reverse-location-search-from-photos/?ref=freshfromcache.com). - **GeoSpy and the investigation into its misuse:** 404 Media, "The Powerful AI Tool That Cops (or Stalkers) Can Use to Geolocate Photos in Seconds," [link](https://www.404media.co/the-powerful-ai-tool-that-cops-or-stalkers-can-use-to-geolocate-photos-in-seconds/?ref=freshfromcache.com). - **The resort photo it missed by 46 miles:** TechRadar, "You can't hide from ChatGPT: we tried the viral AI photo-geolocation challenge," [link](https://www.techradar.com/computing/artificial-intelligence/you-cant-hide-from-chatgpt-new-viral-ai-challenge-can-geo-locate-you-from-almost-any-photo-we-tried-it-and-its-wild-and-worrisome?ref=freshfromcache.com). ### How a stranger on the bus found her secret Instagram URL: https://www.freshfromcache.com/stranger-on-the-bus/ Last updated: 2026-08-11T18:28:54.000Z ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/our-sensors-indicate-you-just-made-eye-contact-with-a-stranger-don-t-worry-i-webp-format-original.jpg) Last week a Reddit user described a small, deeply unsettling moment. A man sat near her on a bus, the two exchanged a glance, and by that evening he had followed her on Instagram. Not the main account she posts from, but the burner: no real name, no profile photo, nothing that points back to her. She never told him her handle. She never even opened the app in front of him. Instagram served her up to him anyway. If you have ever wondered how the app seems to know who you've met without ever searching for them, here is how. ## What "People You May Know" is really up to Instagram and Facebook share a feature usually labeled "People You May Know," or some version of "Suggested for you." It is the engine that surfaces accounts you never searched for, and it runs on a pile of data you probably forgot you handed over: phone contacts you synced once and never cleared, your linked Facebook account, mutual followers, places you have tagged, and (like on the bus) the networks and devices around you. The security researchers who looked at this case were blunt about the mechanism. As one privacy expert told Cybernews, if you have not turned off location sharing and two people are on the same WiFi, Meta "has more than enough data to connect one person to the other." Sit on the same bus, hop on the same free WiFi, and the algorithm gets a fresh data point: these two phones keep landing in the same place at the same time. ## The "burner" was probably never a burner The expert's point was simple and a little brutal. The account she called a burner was probably never anonymous, because she had verified it with a phone number she uses everywhere else. A throwaway account stops being a throwaway the second you attach something real to it, a phone number, an email, even a contact list that has you in it. Meta does not need your name. It needs one thread that ties the account back to you, and most people hand that over during signup. The part that makes people uneasy is that you do not have to upload your own contacts for this to work. Other people upload theirs, and your number is already sitting in plenty of their phones. So when a coworker, an old roommate, or the guy from the bus syncs his contacts, Meta has already matched that number to your account. You can keep your own settings locked down and still get connected through everybody else's address book. Your phone gives things away in other ways too. Leave Bluetooth on and your device announces a name like "Jane's iPhone" to everything in range. You set that name years ago and forgot about it but your phone did not. ## Here's what this means Nobody hacked this woman. There was no breach and no stolen password. She got found by default settings, a synced contact list, and a phone number she reused, all of it working exactly the way it was built to. That is the pattern under almost every "how did they know" story. The data was already collected, [sitting in a profile somewhere](https://www.freshfromcache.com/what-is-a-data-broker/), waiting for a reason to connect two dots. For a small business it scales up fast. If your shop's Instagram runs from the same phone, or the same contacts, as your personal accounts, then "the business" and "me" are the same person wearing two name tags. Something to think about before a cranky customer or a nosy competitor goes looking. ## What to do - **Turn off contact syncing and clear what is already uploaded.** In the app, open your Accounts Center, then Contacts, then "Manage synced contacts." Removing old imports stops them from generating matches forever. - **Set location sharing for the app to "never" or "while using."** There is no reason Instagram needs [your location running in the background at all times](https://www.freshfromcache.com/what-location-sharing-actually-shares/). - **Stop reusing your real phone number on accounts meant to be separate.** An account that is supposed to be anonymous cannot share a number, an email, or a contact list with the real you. A free [Google Voice](https://voice.google.com/?ref=freshfromcache.com) number is one easy way to get that separation. It is not truly anonymous (it is tied to your Google account, and some sites reject internet-based numbers), but it keeps your real cell number off your socials. - **Be careful on public WiFi.** Same network, same place, over and over is exactly the data these systems feed on. If you live on coffee-shop or transit WiFi, a [VPN](https://www.freshfromcache.com/what-a-vpn-actually-does/) pulls a curtain over some of it. - **Rename your Bluetooth devices.** "Jane's iPhone" is a business card you did not mean to hand out, and as one United flight learned the hard way, a device name can [turn a whole plane around](https://www.freshfromcache.com/you-cant-say-bomb-on-an-airplane/). This doesn't make you invisible, and I am not going to pretend it does. Meta does not publish the full recipe for these suggestions, so anyone who tells you exactly which signal did it is guessing. You also probably do not want to quit Instagram over one creepy bus ride. There's nothing magic about it. The app is just very good at reading the trail of breadcrumbs you are leaving. Most of that trail you can sweep up in about ten minutes. Joel If you have any creepy or funny friend-suggestion stories, I'd love to hear them. Reach me at joel@freshfromcache.com. **Source:** [Cybernews, "Stranger danger? Here's how a random person on the bus can still find you on Instagram"](https://cybernews.com/security/social-media-privacy-location-settings/?ref=freshfromcache.com) (June 1, 2026). ### You can’t say bomb on an airplane URL: https://www.freshfromcache.com/you-cant-say-bomb-on-an-airplane/ Last updated: 2026-08-11T18:28:57.000Z Somewhere over the Atlantic last Saturday night, a plane full of people learned that a teenager's taste in speaker names can cost you your whole evening. United Flight 236 left Newark for Palma de Mallorca, Spain, around 6 pm on May 30\. About two hours in, off the coast of Nova Scotia, passengers started noticing something on their phones. A nearby Bluetooth device, sitting in the list of things you could pair with, was named "BOMB." Word got to the crew and the crew was not amused. Flight attendants told everyone to turn Bluetooth off, then said it again, then gave a one-minute warning: shut it down or we turn around. At least two Bluetooth signals were still broadcasting when the minute ran out. The pilots squawked 7700 (the transponder code for a general emergency), pointed the 767 back at New York, and landed to a welcome party of airport police and federal agents. The culprit was a 16-year-old. He had named his portable Bluetooth speaker "BOMB," and on an airplane that name went out to every phone, laptop, and seatback screen in range. He admitted it was his and was taken in for questioning. The other 189 passengers got re-screened, waited out the night, and finally reached Spain about nine hours late. The story blew up on Reddit, where a passenger's account pulled a couple thousand upvotes within hours, and aviation forums started calling it the "Bluetooth flight." ## Why a speaker name lands on everyone's phone Most of your wireless gadgets announce themselves. When Bluetooth is discoverable, your device broadcasts its name to everything nearby that is looking to pair. Same with a Wi-Fi hotspot: the network name (the SSID) is just a bit of text the device sends out for anyone scanning to see. Your phone does it. Your speaker does it. Your printer, [your smart TV, your car](https://www.freshfromcache.com/the-car-alarm-you-never-bought/). You usually never notice, because the names are boring. "Living Room Speaker." "Joel's iPhone." But the name is whatever someone typed in, and it shows up on strangers' screens in any crowded space. No "hacking" required. A kid typed four letters into a settings screen as a joke and caused a Boeing 767 to turn around. ## It has happened before Days earlier, a different United flight had its own scare over a passenger's Wi-Fi hotspot name, with the pilot threatening to call the FBI. Last year a flight out of Austin sat for four and a half hours after someone named their hotspot "I have a bomb." Police boarded, everyone got off, every bag got re-screened. Airlines and the FAA treat the word "bomb" anywhere in the cabin, including on a screen, as a threat until proven otherwise. They have to. ## The useful bit Likely you are not going to name your speaker "BOMB." But your devices are broadcasting names right now, and most people have never looked at what those names say. A default like "Joel's iPhone" hands the coffee shop your first name. A joke name you set five years ago is still going out to every stranger in range. Here are some tips to avoid being labeled a domestic terrorist. - **Rename your iPhone.** Settings, General, About, Name. This is also what your AirDrop and your personal hotspot show other people. Pick something you would not mind a stranger reading. - **Rename your Android phone.** Settings, About phone, Device name. On most phones this also updates your Bluetooth and hotspot names. (Samsung tucks it behind an Edit button on the same screen.) - **Check your hotspot name.** On iPhone it matches the device name above. On Android, Settings, Network and internet, Hotspot and tethering, Wi-Fi hotspot. Keep it dull. - **Tighten up AirDrop and Bluetooth in public.** On iPhone, set AirDrop to Contacts Only or off (Settings, General, AirDrop). Turn Bluetooth off when you are not using it. If a device is not broadcasting, nobody can see it. - **Look at the speaker.** Most Bluetooth speakers get renamed through their companion app, or they ship with a generic default. If yours shows a name you do not recognize, change it. The stuff in your pocket has a public-facing label, and you are the one who decides what it says. Joel *If you spot a gloriously bad device name out in the wild, send it my way:* [*joel@freshfromcache.com*](mailto:joel@freshfromcache.com) **Source:** [The Verge's report on United Flight 236](https://www.theverge.com/transportation/940486/united-flight-236-bluetooth-speaker-name-bomb?ref=freshfromcache.com), with additional reporting from [Simple Flying](https://simpleflying.com/united-airlines-767-returns-newark-bluetooth-name-alert/?ref=freshfromcache.com), [View from the Wing](https://viewfromthewing.com/united-flight-to-spain-turns-back-to-newark-after-teens-bluetooth-speaker-named-bomb/?ref=freshfromcache.com), and [AirLive](https://airlive.net/emergency/2026/05/31/united-flight-turned-around-over-atlantic-as-a-boy-named-his-bluetooth-device-bomb/?ref=freshfromcache.com). ### Microsoft 365 prices go up July 1. URL: https://www.freshfromcache.com/microsoft-365-prices-go-up-july-1/ Last updated: 2026-07-31T20:56:44.000Z ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/unsplash-image-xg02jzibf7o-format-original.jpg) If you run your business or your nonprofit on Microsoft 365, your bill is about to climb. On July 1, Microsoft raises list prices on most of its commercial plans. Business Basic goes from $6 to $7 per user each month. Business Standard, the plan most small offices actually run, goes from $12.50 to $14\. The enterprise plans move too: Office 365 E3 jumps 13% to $26\. Microsoft announced all of this back in December, but now we are only a month away. The increase hits the suites, the bundles of apps and services you pay for per person (Business Basic, Standard, and the E3 and E5 enterprise plans). Standalone Teams and the Copilot add-on aren't in this round. Microsoft is also folding some features into the lower tiers starting in June: an extra 50GB of mailbox space, "Copilot Chat" access, and on Basic and Standard, URL time-of-click protection (a phishing defense that re-checks a link the moment you click it, not just when the email arrived in your inbox). It's the kind of protection that catches the [business-email scams I wrote about here](https://www.freshfromcache.com/fake-face-real-money/) a step later in the chain. One number didn't move: Business Premium stays at $22\. Microsoft just narrowed the gap between Standard ($14) and Premium ($22) from twelve dollars to eight, and Premium is the one that actually includes business-grade security and device management. Here's the part that decides what you pay: existing customers stay on their current price until their plan renews. So whether July 1 costs you anything comes down to your renewal date. Renew on June 30 and you hold today's price for another full term. Renew on July 2 and you're on the new one. On most annual plans bought through Microsoft or a partner, you can renew early to lock the current rate. So now might be the time to take a look at your billing and usage to see if something different makes sense. ## Here's what this means I own one of these packages as well, and the advice I'd give: go find your renewal date before you do anything else. The per-seat increase looks small. A dollar here, a buck-fifty there. Across ten or twenty people, billed every year, it adds up. The other thing I'd push back on: the new features are not a reason to jump tiers. Copilot Chat is fine to have. You don't need to move from Standard to Premium to get it, and you shouldn't let a sales conversation talk you into a plan you weren't going to buy a month ago. ([My standing advice on AI features holds here too](https://www.freshfromcache.com/boring-ai-advice/).) If you were already looking for better security, that's a different conversation. Premium didn't get more expensive this round, which makes it cheaper relative to Standard than it was, and it bundles protection. ## What to do - **Find your renewal date first.** [Microsoft 365 admin center](https://admin.microsoft.com/?ref=freshfromcache.com), then Billing, then Your products. Or ask your provider. Everything else depends on this one fact. - **Renew before July 1 if yours falls after it.** On annual plans you can usually lock the current price for another term. Audit your seats first, though: an annual commit locks your license count too, and most shops are paying for a handful of accounts nobody uses anymore. Confirm the early-renewal option with your billing channel. - **Don't get talked up a tier for features alone.** The bundled additions are nice to have. They aren't worth a plan change you weren't already considering. - **Price out Premium only if security was already on your list.** The Standard-to-Premium gap shrank, and Premium ($22, unchanged) includes Defender and device management. - **Nonprofits: check your exact plan.** Your pricing is pegged to commercial rates through a fixed discount. Business Basic stays free and Premium holds at $5.50, but nonprofit Standard still climbs about 17%. Locking in early only delays the increase by one term. It buys time, not immunity. And to be fair to Microsoft, some of what's arriving is good to have: URL time-of-click protection on the cheaper plans is a genuine upgrade for a small business running with no security layer at all. At renewal, the price going up is the obvious thing to notice. The better question is whether you'll use what you're now paying more for. **Source:** [Microsoft 365 pricing and packaging updates (Microsoft Licensing)](https://www.microsoft.com/en-us/licensing/news/2026-m365-packaging-pricing-updates?ref=freshfromcache.com) **The announcement:** [Advancing Microsoft 365: new capabilities and pricing update (Microsoft 365 Blog, December 4, 2025)](https://www.microsoft.com/en-us/microsoft-365/blog/2025/12/04/advancing-microsoft-365-new-capabilities-and-pricing-update/?ref=freshfromcache.com) ### The AI jobs apocalypse got postponed. URL: https://www.freshfromcache.com/the-ai-jobs-apocalypse-got-postponed/ Last updated: 2026-08-11T18:29:14.000Z A year ago, the two biggest names in AI told us our jobs were in trouble. OpenAI's Sam Altman warned that entire categories of work would vanish. Anthropic's Dario Amodei even put a number on it: roughly half of entry-level white-collar jobs gone within five years, unemployment climbing toward 10 or 20 percent. This month, both of them walked it back. Altman now says he's "delighted to be wrong." Both companies, as it happens, are weeks from asking public investors for a mountain of money. Here's the short version of the about-face. In 2025, the message was urgent: a technology so powerful it would reshape work within a few years, and everyone needed to brace for it. In May 2026, Altman told a banking conference he'd expected far more damage to entry-level jobs by now than has actually shown up. Amodei softened too. He now talks about automation less as a job-killer and more as a way to get more done with the same people. What shifted over the past year was the evidence, not so much the technology. The Yale Budget Lab has tracked AI's effect on US employment since ChatGPT launched, and through March 2026 it found no sign that AI is changing which jobs people hold or how long they stay unemployed. This is true even in the roles most exposed to it. The disruption that was supposedly already underway hasn't happened. The timing of these comments could be suspect. Both OpenAI and Anthropic are preparing to go public this year at valuations in the hundreds of billions. Predicting mass unemployment would be a strange thing to pitch to investors who want growth, and to a public that already feels uneasy about AI. One policy researcher quoted by Fortune put it plainly: it's hard to tell whether the CEOs changed their actual forecasts or just changed the story they tell. The layoffs themselves are real (tech cuts passed 115,000 this year, with Meta, Intuit and others naming AI as a reason), but "we're using AI now" has become a convenient label for cuts companies wanted to make anyway. ## Here's what this means I've said before that the useful posture toward AI is boring: it's a tool, you should learn to use it, and you should ignore most of what the people selling it tell you about the future. [This story is that boring advice proving itself out.](https://www.freshfromcache.com/boring-ai-advice/) The same executives who wrote the doom narrative are revising it every few months, right in step with their fundraising. If you run a small business or a nonprofit, the practical reality is the same, despite the headlines. AI can save you time on tasks. It's [not about to run your operation](https://www.freshfromcache.com/what-is-an-ai-agent/) or replace your people. Yet. ## What to do - **Don't make staffing or career moves off a prediction.** The forecasts have a track record now, and it's poor in both directions. - **Judge AI by what it does on your actual work.** Try it on a task you do every week. That tells you more than any keynote from a CEO. - **Watch the layoff language.** When a company blames AI for cuts, ask whether the math worked without it. It probably will. - [**Keep learning the tools anyway**](https://www.freshfromcache.com/ai-tips-for-everyday-people/)**.** An overhyped apocalypse doesn't make the skills worthless. The walk-back isn't a confession that AI won't change work. Some jobs will keep shifting, and the slow, undramatic version of that is probably the real story. What got cancelled was the timeline, the one that sold well in 2025 and sells differently now that there's stock to move and money to be made. Read the next big prediction with that in mind. **Source:** [Sam Altman and Dario Amodei are walking back their AI jobs apocalypse prophecies (Fortune, May 26, 2026)](https://fortune.com/2026/05/26/sam-altman-dario-amodei-walking-back-ai-jobs-apocalypse-prophecies-ipo/?ref=freshfromcache.com) **The data:** [Yale Budget Lab, AI labor market tracker](https://budgetlab.yale.edu/?ref=freshfromcache.com) ### Leaked Email URL: https://www.freshfromcache.com/leaked-email/ Last updated: 2026-08-11T18:29:24.000Z Your email address is in a leak. Probably more than one. So is mine. That sounds dramatic. The actual implication is not so much. At some point you signed up for an account at LinkedIn or Dropbox or some forum you've forgotten the name of, the company got hacked, and a file containing your email address (and sometimes your password from that account) has been quietly circulating online ever since. The aggregated breach catalogs grew by something like 23 billion rows in the last year alone. There's a free tool that will tell you which of those files you appear in. And a short list of things to do once you know. Here's the process. ## What "leaked" means When a company you've signed up with gets breached, the data they had on you ends up in a file. Email address, password, name, sometimes more. Those files don't stay private. They get traded, sold, posted, and eventually aggregated into giant searchable databases. A security researcher named Troy Hunt has been maintaining one of those aggregations as a free public service since 2013\. It's called ‘[Have I Been Pwned](https://haveibeenpwned.com/?ref=freshfromcache.com)’. It indexes data from thousands of breaches, plus, more recently, stealer-log corpuses. A breach is what happens when a company you trusted with your data gets hacked. A stealer log is the credential database harvested from someone's malware-infected computer (sometimes yours, sometimes a coworker's, sometimes a former employee's). HIBP covers both. The basic email lookup is free. This check tells you two things. Which breaches your email appears in, and what kind of data was exposed in each one. It tells you which doors might already be unlocked, so you can decide which ones to lock first. ## The privacy question You're going to type your email address into a website, and it would be right to pause and think about it first. HIBP has been operating for over a decade, is run by a person whose entire reputation is built on this work, and doesn't store the queries you make. For password checks (which I'll cover below), the tool uses a technique called k-anonymity that means even the service itself never sees the full password you submit. It's about as trustworthy as a third-party check can be. If you'd still rather not type things into someone else's website, your password manager almost certainly has a built-in breach check that does the same job using the same underlying data, without anything leaving your password manager. This is covered below. ## Step 1: Check your email addresses Open [haveibeenpwned.com](https://haveibeenpwned.com/?ref=freshfromcache.com). Type the email address you want to look up into the box. Hit "pwned?" and wait. You'll get one of two results. Either the page is green and says you haven't been found in any known breaches (you can stop reading and feel quietly smug), or the page is red and lists the breaches you appear in. Each entry shows the date, the company, and [the kinds of data that were exposed](https://www.freshfromcache.com/freeze-your-credit/). Repeat for every email address you or your business uses. Don't forget: - Catch-all addresses (info@, hello@, contact@) - Personal emails you use for vendor accounts - Old addresses you stopped using Each one is a separate check. Write down which breaches show up. ## Step 2: Check the passwords you're using This is the part that hurts. HIBP has a sister service called Pwned Passwords at [haveibeenpwned.com/Passwords](https://haveibeenpwned.com/Passwords?ref=freshfromcache.com). You can type any password you're worried about, and the tool tells you how many times that password has appeared in leaked data. For instance ‘Password123’ shows up **1,505,362 times.** The clever bit. Your password gets hashed in your browser before anything is sent, and the service only ever sees the first five characters of the hash. The full password and even the full hash never leave your machine. It's been audited by people whose job is being skeptical. If you'd rather not type a password into a web form, your password manager probably has this check built in. 1Password calls it Watchtower. Bitwarden has a Data Breach Report. LastPass has Security Dashboard. Whatever you use, look for a feature called something like "breach monitoring" or "password health." Every password in your vault gets scored against the same data HIBP uses. ## Step 3: Set up ongoing monitoring The breach you should worry about most is the one that hasn't happened yet. Sign up for free email notifications at [haveibeenpwned.com/NotifyMe](https://haveibeenpwned.com/NotifyMe?ref=freshfromcache.com) for each address you care about. The next time one of those addresses shows up in a new breach, you'll get an email within a day or two. If you run your own business domain ([something@yourbusiness.com](mailto:something@yourbusiness.com)), there's a free tier for domain owners covering up to ten breached addresses. You verify control of the domain, then you can see all addresses on that domain that have ever appeared in a breach. Worth doing for a small business. ## Step 4: Fix what you found This is the only step that matters, and it's the one most people skip. You found out you're in a breach. Now what? **Change the password on every account that uses the leaked one.** The breached service, sure, but also every other place you reused it. If the leaked password is one you've used recently, this is going to mean ten or fifteen logins to clean up. Do it anyway. **Turn on MFA on the important accounts.** Email, bank, accounting software, domain registrar, password manager. MFA is what makes a future leak stop being fatal. I wrote a [separate post](https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/) on which kind to pick and why. **Stop reusing passwords.** [This is what a password manager is for](https://www.freshfromcache.com/start-using-a-password-manager/). If you don't have one, this is the moment to get one. 1Password and Bitwarden are both solid choices; Bitwarden has a free tier that covers most people. **Don't pay shakedown emails.** You may get an email from "yourself" with one of your old passwords in the subject line, demanding bitcoin or "the recipient list will be released." Those are bulk spam. The sender downloaded the same breach file you're now looking at and ran a script that emailed every address in the dump. They have nothing on you beyond that file. Paying confirms you're a real person who panics, which puts you on a more aggressive target list. Delete and move on. ## What to skip The "remove your data from the dark web" subscription services. Once a breach is out, the data is in so many places, and no service can put it back. The companies selling removal are mostly selling you a monitoring subscription that does what HIBP already does for free. The "AI-driven personal cyber risk score" products. Most use HIBP data underneath with a marketing layer on top. If you find a scored version more motivating, fine. The free tools do everything they do. ## What this is really for The actual benefit of going through this isn't the list of breaches you find. It's the moment, three months later, when you get one of those shakedown emails or a suspicious login alert, and instead of panicking, you know exactly which password to change, which account is exposed, and how worried you should actually be. That's the difference between an afternoon of anxiety and a five-minute fix. If you've been through this kind of check and ran into something I didn't cover, I'd love to hear about it. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). Joel ## Sources - **Have I Been Pwned (the tool itself):** Troy Hunt — [haveibeenpwned.com](https://haveibeenpwned.com/?ref=freshfromcache.com). - **Stealer logs in HIBP:** Troy Hunt, *Experimenting with Stealer Logs in Have I Been Pwned* (January 2025) — [link](https://www.troyhunt.com/experimenting-with-stealer-logs-in-have-i-been-pwned/?ref=freshfromcache.com). - **23 billion new rows in the last year:** Troy Hunt, *Processing 23 Billion Rows of ALIEN TXTBASE Stealer Logs* (February 2025) — [link](https://www.troyhunt.com/processing-23-billion-rows-of-alien-txtbase-stealer-logs/?ref=freshfromcache.com). ### Why MFA annoyance is worth it URL: https://www.freshfromcache.com/why-mfa-annoyance-is-worth-it/ Last updated: 2026-08-11T18:29:23.000Z MFA. Few terms make users so annoyed. I'm sure you've seen the pop-ups practically begging you to set up MFA. Your work probably forced an authenticator app or two for you to use every time you want to sign into a work tool. It's annoying! But it's worth it. Have you ever randomly gotten a push notification or email that has a code, but you hadn't logged into anything? Usually it'll say something along the lines of "if you didn't request this, don't give this code to anybody". That's MFA at work protecting your account. Here's what it's actually doing in those moments, which kind to use, and why "my password is strong" isn't the answer. ## Why the codes show up Somewhere, someone is trying to sign in as you. The mental model most people have is that MFA stops hackers from guessing passwords. It does, sort of, but guessing has not been the main threat for years. The real threat is credential stuffing. Pick any old data breach (LinkedIn, Dropbox, MyFitnessPal, a hundred smaller names) and your email address paired with whatever password you used at the time is sitting in a downloadable file somewhere. Bad actors take those lists and try them against every other service in the world. Your bank, your Microsoft 365, your QuickBooks, your insurance portal. [If you reused the password](https://www.freshfromcache.com/start-using-a-password-manager/) (and almost everyone has, somewhere), one of those attempts hits. The attacker doesn't know or care who you are. A script is doing the work. The scale is hard to picture without numbers. One recent estimate puts global credential stuffing attempts at around 26 billion a month. The 2025 aggregation of stealer logs and breach dumps contained roughly 16 billion username-password pairs. MFA breaks the script. Even if your password from 2017 is in the dump, a fresh login attempt has to also produce a code from your phone or a tap on your authenticator. The script can't do that and the attempt dies at step two. That's the actual job MFA is doing. Verifying it was actually you who put in the correct password. ## The three kinds of MFA When a service offers MFA, you usually get a choice. The options look similar on the screen, but they aren’t all made equal. **SMS text codes.** The service texts you a six-digit code. You type it in. This is the weakest acceptable form, and it is still better than nothing. Two problems with this method. A determined attacker can convince your phone carrier to move your number to a SIM card they control (this is called SIM swapping). Any code that arrives by text can be phished by a fake login page that asks for the code right after you type it. Last year NIST formally downgraded SMS one-time codes to a "restricted authenticator" category, the first time the agency has created that designation. Use SMS when nothing else is offered. Don't pick it when there's a better option. **Authenticator app codes.** You install an app on your phone (Microsoft Authenticator, Google Authenticator, Authy, your password manager, several others) and it generates a fresh six-digit code every thirty seconds. The codes never travel over text. SIM swappers have nothing to swap to. The codes can still be phished if you type them into a fake page in real time, but the attacker has to be there actively running the scam, which is a much higher bar. This is the right default for almost everyone. **Push prompts and biometric approvals.** You sign in, your phone or laptop asks you to confirm with Face ID, Touch ID, Windows Hello, or a yes/no tap. There's no code to phish because no code exists. Microsoft has been making this the default sign-in method for new accounts. The newest version of this is called passkeys, which I [wrote about a couple of weeks ago](https://www.freshfromcache.com/what-the-heck-is-a-passkey/). If you have the option, pick the strongest one the service supports. ## What to turn on now You don't have to do everything. You need to cover the four accounts that, if compromised, would do the most damage to you or your business. For most small businesses and nonprofits, those are: - **Your work email** (Microsoft 365 or Google Workspace). Email is the master key. [Lose it and the attacker can reset every other password you have](https://www.freshfromcache.com/email-recovery-check/). - **Your bank and accounting software.** Money. Enough said. - **Your domain registrar** (GoDaddy, Namecheap, Cloudflare, wherever you bought your website name). This is the one that is easy to forget. If your domain gets stolen, your website and your email both stop being yours. An afternoon's work for the attacker; weeks of yours to recover. - **Your password manager**, if you have one. The vault holds everything else. If a criminal gets any of those four, they can chain into most of the rest. Microsoft 365 is the easy case. Microsoft has been turning on Security Defaults automatically for new tenants since 2019, and as of February 2026 the admin center requires MFA for anyone signing in to it. If you haven't been prompted, you will be. Sign in to admin.microsoft.com, look under Entra ID for Security Defaults, confirm it's enabled. For everything else, hunt around in the security or login settings until you find the option. Switch to an authenticator app where you can. SMS where you can't. ## The excuses **"It's annoying."** It is annoying being bugged about MFA if you haven’t set it up. Once you’ve set it up and used it for a week or two, it’ll become second nature. **"What if I lose my phone?"** Every authenticator app offers backup codes, a recovery key, or a second device. Set those up at the same time you turn on MFA. **"My password is strong."** Doesn't matter. The real risk is that some password you've used somewhere is already in a database the attacker downloaded. There are 94 billion credentials and session cookies in the dumps that have surfaced in just the last two years. Some of them are yours. Some of them are mine. You probably can't even remember the site you used the leaked one on. **"My business is too small to be a target."** Nobody is targeting you personally. Scripts target everyone. The credential-stuffing campaigns that run all day, every day are hitting a million addresses an hour with stolen password lists. Small business is a feature for the attacker, not a deterrent. You have money, smaller IT budgets, less monitoring, and (sometimes) softer security habits than a large company. ## What MFA doesn't do I want to be honest about the limits of MFA. MFA stops the most common attack, which is the automated reuse of leaked credentials. It does not stop a careful human attacker who phishes you into pasting a real code into a fake page in real time. It does not stop malware running on a computer you've already trusted. It does not stop social engineering of your IT vendor or your phone carrier. What it does is take the easy path away from the attacker. Most of them give up and move to the next address on the list. That is, genuinely, most of the protection you need. The next time you get one of those random codes for a login you never made, that's the proof. Someone has your password. They tried it. They didn't get in. Annoying setup, real protection. Spend the ten minutes. If you've got your own MFA story, the time it caught something or the time you got locked out at the worst moment, I'd love to hear it. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). Joel ## Sources - **26 billion credential-stuffing attempts a month:** Startup Defense, *Credential Stuffing in 2026: What Startup Teams Need to Know* (citing Fortinet 2025 data), [link](https://www.startupdefense.io/blog/credential-stuffing-startup-security-teams?ref=freshfromcache.com). - **16 billion username-password pairs in the 2025 aggregation:** Cybernews, *Billions of credentials exposed in infostealer data leak* (June 18, 2025), [link](https://cybernews.com/security/billions-credentials-exposed-infostealers-data-leak/?ref=freshfromcache.com). - **NIST's "restricted authenticator" designation for SMS:** NIST Special Publication 800-63B-4, *Digital Identity Guidelines: Authentication and Authenticator Management* (final, July 31, 2025), [link](https://csrc.nist.gov/pubs/sp/800/63/b/4/final?ref=freshfromcache.com). - **Microsoft 365 admin center MFA enforcement and Security Defaults history:** Microsoft, *Announcing mandatory multifactor authentication for the Microsoft 365 admin center*, [link](https://techcommunity.microsoft.com/blog/microsoft%5F365blog/announcing-mandatory-multifactor-authentication-for-the-microsoft-365-admin-cent/4232568?ref=freshfromcache.com). - **94 billion exposed credentials and session cookies:** NordVPN / NordStellar research, *From 54 billion to 94 billion: cookie theft skyrockets* (June 5, 2025), [link](https://nordsecurity.com/press-area/from-54-billion-to-94-billion-cookie-theft-skyrockets-as-hackers-exploit-your-browser?ref=freshfromcache.com). ### What a VPN actually does URL: https://www.freshfromcache.com/what-a-vpn-actually-does/ Last updated: 2026-08-11T18:29:26.000Z A user showed me a VPN ad on her phone last month and asked if she should buy it. The ad had a hooded figure at a coffee shop. Ominous music. A scrolling list of things hackers were apparently doing to her bank account while she ordered a latte. Fifteen dollars a month and you’ll be safe. I explained why it would be overkill. The pitch she'd seen is selling a problem that was real over ten years ago and has mostly been engineered out of the modern web. That doesn't mean VPNs are useless. It means almost nobody in the VPN industry is selling them for the reasons they're actually useful. Once you know what one really does, you can decide whether you need one. ## What a VPN actually is A VPN creates an encrypted tunnel from your device to a server somewhere else. From that server, your traffic continues on to whatever site you're visiting. To the website, the traffic looks like it came from the VPN server, not from you. To the network you're physically connected to (the coffee shop wifi, your home router, your hotel), the traffic looks like an unreadable stream of data going to one specific place. The local network can't see anything past that. That's the entire idea of behind a VPN. A VPN does not block malware or stop phishing. It doesn’t not make you anonymous and it does not protect against the website you're connecting to. It moves the place your traffic appears to start, and it encrypts the first leg of the trip. ## Selling fear Back when the VPN industry built its marketing playbook, lots of websites still ran over plain HTTP. The lock icon in your address bar was new and not the default. An attacker on the same wifi could plausibly grab passwords out of the air or hijack your session. Wifi sniffing was a real thing. Then HTTPS happened. Now almost every site you'd care about encrypts your traffic by default. Browsers warn you before letting you visit a non-encrypted site. Banking apps add their own encryption on top of HTTPS. The router at the coffee shop sees that you're connecting to your bank. It cannot see what you type into the login page. So the sales pitch is selling protection against an attack that mostly doesn't work anymore. The remaining genuine public-wifi risk is the captive portal, the "agree to the terms" page that loads when you join a hotel or airport network. Attackers run fake versions of those to harvest credentials or push malicious downloads. A VPN does not help with that at all. If the page convinces you to type a password or accept a fake update, you're done either way. ## When to use a VPN **Privacy from the network you're on.** Even with HTTPS, the router and your internet service provider can still see which sites you connect to. Not what you type on them, but the names and how long you spend there. A VPN hides that pattern from whoever runs the network. The ISP sees you connecting to a VPN server and stops seeing anything past it. If you don't want your apartment building's wifi or Comcast building a record of every site you visit, that's a real reason to use one. **Remote access to your office.** This is what gave VPNs their name. Your office has files, printers, or systems that only work when you're on the office network, and you need to use them from somewhere else. A business VPN lets your laptop pretend it's plugged in at the office. This is the version your IT person sets up for you, and it's the only kind that's actually solving the problem people in offices used to solve with VPNs. There are even cheap and free options for small businesses. **Tailscale** is one of them. The personal plan is free for up to six users. Business plans start around $6 to $8 per user per month. There's no server in the office to maintain. **Appearing to be in a different country.** Streaming content locked to a different region, services that don't work where you are, sites blocked in the country you're traveling in. This works because the website sees the VPN server's address, not yours. Legitimate use, but also against the terms of service of every streaming platform on the planet, so factor that in. ## What the pitch leaves out **A VPN does not make you anonymous.** It moves your apparent location from your home to wherever the VPN server is. Your browser fingerprint, your logged-in accounts, the cookies your devices carry, the way Google recognizes you across sessions, all of that is unchanged. Real anonymity requires Tor, careful habits, and a different relationship with the internet than most people want. A consumer VPN gives you privacy from your network and your ISP. **A VPN does not protect you from hackers.** It encrypts the first leg of your traffic. Phishing emails still phish. Malware still installs. Your password can still be stolen [if you type it into a dummy site](https://www.freshfromcache.com/start-using-a-password-manager/). Don’t feel a false sense of security just because you have a VPN turned on. ## Need a VPN? For personal use, the two I trust are **Proton VPN** and **Mullvad**. Both have been independently audited. Both have business models that don't depend on selling your traffic. Proton VPN has a free tier (one device, limited servers, unlimited time). Paid plans run about $10 a month if you go monthly, around $5 if you pay annually. It’s even less on a two-year commitment. Same company makes Proton Mail and Proton Drive, and the bundle is reasonable if you want all three. Mullvad charges a flat €5 a month (about $6 US), no tiers, no sales, no first-year discount that doubles at renewal. The price has not changed since 2009\. You can pay with cash mailed to Sweden if that's the kind of thing you'd want to do. For small-business remote access, Tailscale (mentioned above) is the easy answer. ## What to skip **The free VPN apps in your phone's app store, almost without exception**. The business model is selling your traffic to advertisers, and several of them have been caught doing worse. The thing you were hoping a VPN would prevent (someone reading what you do online) is what they're doing for a living. Free, in this category, is a warning label. **The VPN bundled with your antivirus subscription**. Norton, McAfee, and the rest sell these as upsell justification. They tend to be slow, they expire when the antivirus expires, and the company isn't really in the VPN business. If you're picking from scratch, pick something else. ## So? If you've got HTTPS in your browser, MFA on the accounts that matter, and a healthy suspicion of links in email, you do not need a consumer VPN for safety. You might want one for ISP privacy, office access, or to get around a geographic lock. Don’t give in to the fear. Joel [joel@freshfromcache.com](mailto:joel@freshfromcache.com) ### How to spot a phishing email in 2026 URL: https://www.freshfromcache.com/how-to-spot-a-phishing-email/ Last updated: 2026-08-11T18:28:27.000Z Have you ever been phished by your own work? Have you felt betrayed when you clicked a link in an email that looked legit and then your IT department sends you an email assigning you mandatory phishing training? Email phishing has evolved over time, and so has the way to spot a fake email. As phishing has gotten more sophisticated, spotting fakes has become increasingly harder. Luckily there are still tell-tale signs you can look for on any email to spot if it's a scam or if it's *really* a Nigerian prince desperately trying to give you money. ## Why the old advice stopped working For years, the standard phishing-detection advice was "look for typos and bad grammar." That worked when phishing emails were written by humans who didn't speak English well. Or by attackers who didn't care about quality because they were sending millions of messages at a time. The misspellings, the awkward phrasing, the generic "Dear Customer" lines were tells. They're mostly a thing of the past. The 2025 KnowBe4 Phishing Threat Trends Report found that 82.6% of phishing emails now contain AI-generated content. IBM X-Force researchers showed that a generative AI model can produce a convincing, personalized phishing email in five minutes with five prompts. Previously the same email used to take their team about 16 hours to write. Microsoft's 2025 Digital Defense Report measured AI-generated phishing click rates at 54%, compared to 12% for human-written campaigns. The grammar is now perfect. The tone matches your boss's writing style. The signature looks right. The logo is the right resolution. The misspellings and sometimes humorous mistakes of early phishing emails are gone. But there are still tells that give away an email is a phish. ## The five real tells ### 1\. Don't trust the display name Most email clients show you the sender's name in big friendly text and hide the actual email address. "PayPal Customer Service" is a name anyone can type into their email settings. The actual address might be service@paypa1-secure.xyz. Click or tap the sender's name to see the real address. If it doesn't match the company's real domain (@paypal.com), stop. Watch especially for one-letter swaps. The real microsoft.com becomes rnicrosoft.com (that's r-n, not m). The real paypal.com becomes paypa1.com (that's the number 1, not lowercase L). These are easy to miss when scanning your inbox at 8am. ### 2\. Hover before you click On a desktop, hover your mouse over any link and the real destination shows up at the bottom of your browser or email client. On mobile, long-press the link to see a preview. The text of the link can say https://www.microsoft.com and still go anywhere the attacker wants. If the link's real domain isn't the official domain of the company that supposedly sent the email, don't click. Open a new browser tab and go to the company's site directly. ### 3\. Why am I getting this? "Did I expect this?" is now the single most useful question you can ask. A wire transfer request from the CEO. A SharePoint share notification from a colleague. A password reset for an account you didn't reset. An invoice from a vendor you don't use. Even if the email reads perfectly, ask whether the request fits how that person or company normally works with you. AI eliminates the surface-level red flags like grammar and spelling, but the behavioral red flags are still there. ### 4\. Legitimate platforms can be the carrier A modern phishing trick: the email actually does come from QuickBooks, or Zoom, or SharePoint, or PayPal. The attacker uses the real platform to send the message, so it passes every email authentication check and your spam filter never sees it. KnowBe4 reported a 67% jump in this kind of attack in 2025. The scam is in the document, the invoice, or the meeting link the platform is technically sending you "legitimately." Treat any "shared document" or invoice notification you weren't expecting the same way you'd treat an unsolicited wire transfer request: skeptical until verified. ### 5\. Verify odd requests If an email asks you to send money, change credentials, or hand over sensitive information, verify it through a different channel. Call the sender back on a number you already know. Walk down the hall if you both work in office. Open a new browser tab and log into the real site directly. Voice and video can be faked too, as we covered in [fake face, real money](https://www.freshfromcache.com/fake-face-real-money/), but the solution is the same: a second channel of communication you can trust. This is one step that AI can't fake. Yet. ## When in doubt Slow down. Urgency is the number-one manipulation tactic for a reason: it works. Anything that pressures you to act now deserves an extra minute of scrutiny. If you have an IT person or a security helpdesk, forward suspicious emails to them. Most of the time they would rather check a hundred false alarms than miss the one that gets through. If you don't have an IT person, reply to the request through a known channel (not the email) before doing anything irreversible. It is genuinely fine to delay an "urgent" request by ten minutes to verify it. No one who's actually your boss, your bank, or your vendor will be mad about that ten minutes. The only person mad about it is the scammer. ## Real life examples If you want to calibrate your eye on real phishing, both Berkeley and Stanford publish regularly-updated archives of what's actually hitting their users. [Berkeley](https://security.berkeley.edu/news-type/phishing-examples?ref=freshfromcache.com) annotates each example with what makes it a phish, useful if you want to drill into the tells. [Stanford](https://uit.stanford.edu/phishing?ref=freshfromcache.com) is a running list, useful for getting a sense of how often new variants show up. Another good resource is [CISA's phishing page](https://www.cisa.gov/secure-our-world/recognize-and-report-phishing?ref=freshfromcache.com), which covers [what to do after you've clicked something you shouldn't have](https://www.freshfromcache.com/what-to-do-after-a-scam/). ## Closing The mandatory phishing training emails from IT will keep coming, and you might still keep clicking on the occasional test. That's the point of these tests. The simulations are calibrated to catch a small percentage of employees so the training stays useful. The goal is to create a small alarm in your own brain before you click anything that wasn't expected, anything that pressures urgency, or anything that asks for something sensitive. Joel If you have a phishing story (even an embarrassing one), I'd love to hear it. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). **Sources:** - KnowBe4, [Phishing Threat Trends Report Vol. 5](https://www.knowbe4.com/hubfs/Phishing-Threat-Trends-2025%5FReport.pdf?ref=freshfromcache.com), March 2025 - IBM X-Force, [AI vs. human deceit: Unravelling the new age of phishing tactics](https://www.ibm.com/think/x-force/ai-vs-human-deceit-unravelling-new-age-phishing-tactics?ref=freshfromcache.com), November 2025 - Microsoft, [Digital Defense Report 2025](https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025?ref=freshfromcache.com), October 2025 - KnowBe4, [2025 Phishing Threat Trends Report Vol. 6 (Surged Abuse of Legitimate Platforms)](https://www.knowbe4.com/press/knowbe4-uncovers-surged-abuse-of-legitimate-platforms-by-cybercriminals-in-2025?ref=freshfromcache.com), October 2025 ### Patching is the new password URL: https://www.freshfromcache.com/patching-is-the-new-password/ Last updated: 2026-08-11T18:28:11.000Z Verizon publishes a Data Breach Investigations Report every spring. It's the closest thing the security industry has to an annual census, built from real incident data submitted by hundreds of organizations and law-enforcement partners. The 2026 edition dropped yesterday, and it announced something that hadn't happened in the report's nineteen-year history. For the first time, vulnerability exploitation has overtaken stolen credentials as the leading way attackers get into networks. ## What changed For eighteen years, the answer to "how did the attacker get in?" was most often some form of "they had an active username and password." Sometimes that was a phishing success and sometimes it was a credential reused from an old breach. Either way, the answer was pointing at the login. Verizon’s report stated this year: - Vulnerability exploitation is the initial access vector in **31% of breaches.** Last year it was around 20%. - Credential abuse is the initial access vector in **13% of breaches**, down from the top spot it held in every previous DBIR. - Phishing accounted for 16%, which has been flat. This was not an incremental change. The shift was substantial. ## Why it shifted Two things happened at once. Attackers got faster, and defenders got slower. The attacker side is being accelerated by AI in ways that show up clearly in the data. Verizon partnered with Anthropic this year (the company that makes Claude) to study how bad actors are using large language models (LLMs). The median attacker session involved researching 15 different attack techniques in a single conversation; the high end was 40 to 50\. What used to take a competent attacker hours of forum-searching and trial-and-error now takes minutes of asking a chatbot the right questions. The window between a vulnerability being publicly disclosed and a working exploit appearing in the wild has compressed from months to hours. The defender side moved the wrong direction in the ever-ongoing arms race. The median time to fully patch a critical vulnerability rose from 32 days to 43\. Of the vulnerabilities on CISA's Known Exploited Vulnerabilities list (the federal government's catalog of "these are actively being attacked, patch them now"), organizations remediated only 26% in 2025, down from 38% the year before. The number of critical vulnerabilities organizations had to deal with rose by 50% over the same period. So defenders are tracking more vulnerabilities, patching a smaller fraction of them, and taking longer to do it, while attackers exploit them faster. ## What it all means You're going to read versions of this report all month with sweeping conclusions about zero-trust architectures and AI-native security platforms. Most of that is written for organizations with security teams. What this means for a small business or nonprofit is simpler. The boring administrative discipline of installing updates is now the most important security control you have. More important than picking a strong password. More important than buying a security product. Credential theft used to be the thing everyone worried about. Vulnerability exploitation now hits at more than twice that rate. This doesn't mean MFA stops being important. MFA still cuts off most of that 13%, and credential abuse still shows up in 39% of breaches when you count all the breaches it appears in anywhere, not just as the initial access. Both controls are important to have in place. The shift is that patching has moved from "good hygiene" to "the single most likely vector for the next attack." I wrote a piece earlier this week about [a WordPress plugin called Burst Statistics](https://www.freshfromcache.com/wordpress-privacy-plugin/), where about 115,000 sites are still running a vulnerable version a week after the patch shipped. Owners didn't apply it and bad actors can still attack them. ## What to do - [**Turn on automatic updates everywhere they're offered**](https://www.freshfromcache.com/windows-point-in-time-restore/)**.** Windows, macOS, your browser, your phone, your WordPress plugins. The default in 2026 should be automatic unless you have a specific reason otherwise. - **Make a list of what you actually have.** You can't patch [a system you've forgotten exists](https://www.freshfromcache.com/router-expiration-date/). Walk through your office (or your home office) and write down every device that connects to your network, plus the cloud services your business uses. Old WordPress sites, abandoned cloud accounts, a printer with internet access, a network camera nobody has logged into since 2022\. Those are the soft targets. - **For anything internet-facing, treat patches as urgent.** Your website, any remote-access tool, any cloud service with a public login page. If your IT vendor only schedules patches monthly, that needs to be changed. - **Subscribe to one weekly security newsletter.** Not for the entertainment of reading about breaches. So you find out about the patches that affect you before the news cycle moves on. [Bleeping Computer](https://www.bleepingcomputer.com/?ref=freshfromcache.com) and [KrebsOnSecurity](https://krebsonsecurity.com/?ref=freshfromcache.com) are both free. - **If somebody else maintains your systems, ask them when they last applied updates** to your domain registrar, your website host, your line-of-business apps, anything they manage. ## Final thought The threat mix has shifted. The next attack on a small business is more likely to come through unpatched software than through someone guessing or stealing a password. None of this means you should abandon the password and MFA habits you've been building. Both fronts are extremely important, but patching just took the lead. Joel If you've run into a patching nightmare lately, or you've got a system you know needs updating and can't quite figure out how, I'd be glad to hear about it. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). ## Sources - **Verizon 2026 Data Breach Investigations Report (primary):**[Verizon Business: DBIR](https://www.verizon.com/business/resources/reports/dbir/?ref=freshfromcache.com). - **SecurityWeek:** *Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector* (May 19, 2026). [Link](https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/?ref=freshfromcache.com). - **Help Net Security:** *Verizon DBIR: Vulnerability exploitation is the dominant initial access vector* (May 20, 2026). [Link](https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/?ref=freshfromcache.com). - **SC Media:** *Verizon DBIR 2026: Vulnerability exploits top initial access as patching coverage falls* (May 20, 2026). [Link](https://www.scworld.com/news/verizon-dbir-2026-vulnerability-exploits-top-initial-access-as-patching-coverage-falls?ref=freshfromcache.com). ### A WordPress privacy plugin opened 115,000 sites to takeover URL: https://www.freshfromcache.com/wordpress-privacy-plugin/ Last updated: 2026-07-31T20:56:52.000Z A WordPress plugin called Burst Statistics, installed on about 200,000 sites and marketed as a privacy-friendly alternative to Google Analytics, has a critical authentication-bypass flaw that lets attackers walk in as the site administrator. Wordfence discovered it on May 8th. A patch shipped May 12\. As of about a week later, only roughly 85,000 sites had updated. The other 115,000 are wide open, and active exploitation has already started. If you run a WordPress site, this is a stop-what-you're-doing-and-check kind of post. ## What the plugin does, and what broke Burst Statistics is one of the more reasonable choices in the WordPress analytics space. It tracks visitor data on your own server instead of sending it to Google. It doesn't require a cookie banner under most reasonable readings of GDPR, and is generally the kind of tool a small business installs when they want to know how many people read their blog. The flaw, tracked as [CVE-2026-8181](https://nvd.nist.gov/vuln/detail/CVE-2026-8181?ref=freshfromcache.com), scores 9.8 out of 10 on the standard severity scale (the maximum is 10). In versions 3.4.0 and 3.4.1.x, the plugin's integration with another tool (MainWP) had a broken check. The check was supposed to verify that whoever was making a request was actually a logged-in WordPress administrator. It didn't. An unauthenticated attacker who knows an administrator username (which is usually trivial to figure out, since WordPress exposes admin usernames by default) could send a request with any password at all, and the plugin would treat them as that admin. From there: read user data, create new admin accounts, install backdoors. Full site compromise. ## The numbers Wordfence's PRISM platform (their AI-assisted vulnerability research tool) identified the flaw on May 8th. The plugin team shipped a fix four days later, on May 12th. Wordfence customers on paid tiers got firewall protection the same day; free-tier users get it June 7th. In the first 24 hours after disclosure, Wordfence's tracker blocked more than 7,400 exploit attempts. Active exploitation is happening right now, against any unpatched site an attacker can find. By WordPress.org's own download counter, version 3.4.2 has been pulled about 85,000 times since release. That's roughly 42% of the installed base. The other 115,000 sites are either still running a vulnerable version or have decided to remove the plugin entirely. ## What it means Two things stand out. First, the speed. Fifteen days from "vulnerability introduced" to "vulnerability discovered." Four more days to a patch. Hours to active exploitation. That whole cycle used to take months. AI-assisted research is now part of the security stack on the defensive side (Wordfence's PRISM platform is what found this one), but attackers are working with the same tools. The old advice of "update your plugins once a month" is too slow for anything internet-facing. Second, the choice itself was fine. Burst Statistics is a tool you install precisely because you care about your visitors' privacy. You made a thoughtful call to not feed visitor data to Google. That same call is now the door an attacker walks through to take over your whole site. There's no moral lesson in this; every piece of software, however well-intentioned, eventually has a bug. Picking the privacy respecting option is still the right direction. The cost of admission is the same as every other piece of internet-facing software: patch faster than the attackers can move. Security has always been an arms race. ## What to do - **Log in to your WordPress admin and check your installed plugins.** If Burst Statistics is in the list and it's not on version 3.4.2 or later, update it now. If you don't use it, remove it completely. - **While you're in there, click "Updates" in the left sidebar.** Apply every available plugin and theme update. The Burst Statistics one is just the one making news this week; the average WordPress site is running multiple plugins that have patched something in the last month. - **Turn on automatic updates for plugins** if you haven't. WordPress has supported this natively since version 5.5\. The setting is per-plugin, on the Plugins page, in the "Automatic Updates" column. For most small business sites, the upside (zero-day windows close faster) outweighs the downside (a plugin update occasionally breaks something). - **Audit your admin accounts.** A common post-takeover move is to leave a new admin account behind so the attacker can return after you patch. Check the Users page for accounts you don't recognize. - **If someone else maintains your site, ask them when they last applied updates.** "We have a guy" is not an answer to this question. ## What MFA doesn't cover I want to point out something that most security professionals won’t say out loud. MFA on your WordPress admin login would not have helped here. The flaw bypasses the login entirely. There's no password being checked, no MFA prompt being triggered; the plugin just handed an attacker administrator privileges when they asked. Keep MFA on regardless. It still stops the much more common credential-reuse attack against the standard login form. The lesson here is that MFA and patching are separate jobs. You need to do both. If you've found this plugin on a site you manage, or hit something similar lately, I'd be glad to hear about it. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). Joel ## Sources - **Wordfence CVE-2026-8181 disclosure (primary):**[Wordfence Threat Intelligence](https://www.wordfence.com/threat-intel/vulnerabilities/id/8ca830d6-3d3c-4026-85cd-8447b8a568d3?source=cve). - **Bleeping Computer:** *Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin* (May 13, 2026). [Link](https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/?ref=freshfromcache.com). - **CVE record:** CVE-2026-8181 (CVSS 9.8). Assigner: Wordfence. Published May 14, 2026. ### CISA contractor posted admin keys to public GitHub URL: https://www.freshfromcache.com/cisa-contractor-keys-on-github/ Last updated: 2026-08-11T18:28:44.000Z A contractor at the Cybersecurity and Infrastructure Security Agency (CISA), the office of the federal government whose entire job is protecting U.S. critical infrastructure from cyberattacks, kept admin credentials for three Amazon GovCloud accounts in a public GitHub repository for six months. GovCloud is Amazon's cloud platform for federal workloads. The same repository contained a CSV file of plaintext passwords to internal CISA systems, credentials to the agency's internal code repository, and other files that GitGuardian's Guillaume Valadon called "the worst leak that I've witnessed in my career." The repo was named aptly, "Private-CISA." KrebsOnSecurity broke the story Monday after researchers at GitGuardian and Seralys (two security firms that scan public code repositories for exposed credentials) flagged the repo. The contractor's GitHub account had been committing to it regularly since November 13, 2025\. After CISA was notified and the account was taken offline, the exposed AWS admin keys stayed valid for another 2 days. ## How it was found GitGuardian runs automated tools that constantly crawl public GitHub repositories looking for things that should not be there. Passwords, API tokens, signed certificates, that kind of thing. GitHub itself runs a feature called secrets detection that flags this content automatically, and it is turned on by default for new accounts. The CISA administrator manually turned it off. Valadon at GitGuardian was the researcher who first flagged the repo. He reached Krebs after the repo's owner did not respond to GitGuardian's automated alerts. Philippe Caturegli, founder of the security firm Seralys, then tested the credentials independently and confirmed they authenticated to three AWS GovCloud accounts at high privilege levels. ## What was found The file names tell most of the story. One file was called "importantAWStokens". Another was a CSV titled "AWS-Workspace-Firefox-Passwords" with plaintext logins for dozens of internal CISA systems. The archive also included Kubernetes configurations, internal logs, and credentials to the agency's artifactory. The artifactory is the internal repository where CISA stores software packages it uses to build other software. A persistent attacker with that access could inject a backdoor into a package and watch it get deployed throughout the agency's systems on the next software release. The passwords themselves followed a pattern. Many were the name of the platform followed by the current year. GitGuardian flagged the repo via automated scanning and Seralys independently confirmed the credentials worked. The repo creation date and commit history are verifiable from Git metadata. CISA confirmed the incident to Krebs and said it is investigating. CISA noted that "there is no indication that any sensitive data was compromised." They did not add "so far." Caturegli's read on motive is the everyday human behavior. The contractor appears to have been using GitHub as a sync mechanism between a work laptop and a home computer. Six months of weekly commits looks like convenience, not data theft. The contractor works for Nightwing, a government services firm in Dulles, Virginia, which declined to comment. ## Lessons learned The contractor made a mistake. But that mistake is one most of us have probably made in the past out of convenience. How many times have you created a temporary password, promising to change it later. Then later never happens. Using cloud storage (or a code repository, or email-to-self) as a sync mechanism between work and home machines is one of the most common security gaps to encounter. Plaintext passwords in spreadsheets, often in a file literally named passwords.xlsx, is probably the second most common. Disabling security warnings because they get in the way is a close third. Predictable passwords (pet names, kid names, "Password123" with rotating numbers, platform name plus current year) is the fourth. The federal cyber agency is supposed to be the highest-rigor place in the country for this stuff. The contractor was operating inside that environment and still managed to leak the keys to three GovCloud accounts. Whatever you tell yourself about your company being too small to be a target, or your team being good about this, the failure point is convenience. ## What to do [**Replace cross-device sync with a password manager**](https://www.freshfromcache.com/start-using-a-password-manager/)**.** If anyone on your team moves credentials between work and home machines, route them through 1Password, Bitwarden, or another password manager. Password managers are built to sync across platforms. Pick one and have everyone on the team use it. **Hunt down your plaintext password files.** Search OneDrive, Dropbox, Google Drive, and shared network drives for files named "passwords," "logins," "credentials," or spreadsheets with "password" in a column header. Move the contents to a password manager and delete the originals (then be sure to empty the recycle bin). **Turn the guardrails back on.** If you have disabled email security warnings, MFA prompts, or browser warnings because they were annoying, turn them back on and follow the prompts. Setting up these guardrails can seem overwhelming, but once you have them set up, you barely notice them. **Audit who has admin access.** Microsoft 365, Google Workspace, your bank, your payroll system. If you cannot answer in under a minute who holds admin in each, that is the audit you need. Related: the same access-control gap showed up in the [IT twins case](https://www.freshfromcache.com/it-twins-wipe-96-government-databases/) two weeks ago, where contractors kept admin credentials after their contract ended. **If you use GitHub for non-developer work**, do not turn off secrets detection. It is on by default. Leave it on. ## What the story doesn't claim Nothing in this story implies AWS, GitHub, or the cloud are inherently insecure. One person made the same set of mistakes that people make every day. The consequences scaled with how sensitive the leaked material was, because it was federal credentials instead of a small-shop spreadsheet. The mistakes themselves are the same. The chain of a real breach usually starts with whatever was easiest to compromise. Often that is a [phishing email](https://www.freshfromcache.com/how-to-spot-a-phishing-email/) someone clicked. Sometimes it is a credential left somewhere convenient. The most vulnerable cyber attack vector is still humans. Joel If you've spotted your own version of this at work (a passwords spreadsheet, a sync habit, a guardrail nobody turned back on), I'd love to hear about it. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). **Source:** [KrebsOnSecurity: CISA Admin Leaked AWS GovCloud Keys on Github](https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/?ref=freshfromcache.com) (May 18, 2026) ### Meta dropped Instagram DM encryption. Why? URL: https://www.freshfromcache.com/meta-dropped-instagram-encryption/ Last updated: 2026-08-11T18:28:56.000Z Five days later, Meta added a new privacy feature to WhatsApp. If your business or organization uses either app for anything you'd rather Meta not read, here's what changed. ## What changed On May 8, Meta turned off end-to-end encryption (the math that keeps Meta from reading the message) for Instagram Direct Messages. The feature had been opt-in since December 2023, and the toggle sat four menus deep inside individual conversation settings. Any new DMs sent after May 8 are now readable by Meta. Past DMs you sent with E2EE on aren't newly exposed. However, if you didn't export your encrypted history before the cutoff date, you may have lost access to your conversations. On May 13, Mark Zuckerberg personally announced Incognito Chat for Meta AI on WhatsApp. The feature runs your AI conversations inside a hardware-isolated server enclave Meta calls Private Processing. Conversations don't get logged and disappear when you leave the session. These are text-only at launch. Independent security firms NCC Group and Trail of Bits audited the architecture. Just a reminder that WhatsApp's regular messages stay end-to-end encrypted by default. ## Meta's privacy history In 2019, Zuckerberg publicly committed Meta to a privacy-focused future where, in his words, people's private communications should be secure. A 2022 Meta white paper said the company was building end-to-end encryption "by default across Messenger and Instagram DMs." Messenger got it, but Instagram never did. The feature shipped as opt-in in December of 2023, and Meta is now killing the opt-in instead of finishing the default rollout Meta's official explanation is low adoption. The Electronic Frontier Foundation called out the circular logic: turning Instagram E2EE on was a four-step process buried inside individual conversation settings. Meta never advertised the feature and the company is using the entirely predictable low adoption as the excuse for shutting it down. It's self-fulfilling bureaucracy. ## Why this week The U.S. Take It Down Act enforcement deadline arrives on May 19, eleven days after the Instagram cutoff. The law requires platforms to remove non-consensual intimate imagery, including AI deepfakes, [within 48 hours of a takedown notice](https://www.freshfromcache.com/ai-deepfake-has-your-face/). The FTC has set civil penalties at up to $53,088 per violation. End-to-end encryption is incompatible with that obligation. If Meta can't see the content, Meta can't act on a takedown request. The timing of the May 8 cutoff for Instagram encryption isn't a coincidence. Meta needs to become compliant. It's worth noting that Meta is the outlier. Default encrypted platforms like Signal and Apple's iMessage aren't tearing down their encrypted messages to comply with the Take It Down Act. ## What it all means I'd treat Instagram DMs the way I'd treat a personal email site like Gmail. The company hosting the conversation can read it. Anyone with legal authority over that company can compel access. Anyone who breaches Meta's systems can potentially get to it. A week ago that was true only for the users who hadn't opted into E2EE, but now it's true for all users. WhatsApp is still the better Meta option for sensitive person-to-person messages. Meta is openly pointing Instagram users there. Just be careful not to confuse WhatsApp's regular messaging (that is end-to-end encrypted by default) with the new Incognito AI Chat (privacy by Meta's design, not by math). Those two features are meant for two different purposes. ## What to do - **Stop sending anything sensitive through Instagram DMs.** Passwords, account recovery codes, client information, HR matters, photos you wouldn't want a stranger to see. Treat them like you were sending a postcard in the mail. - **Move sensitive conversations to an app that's end-to-end encrypted by default.** Signal is the standard in this space. WhatsApp works for person-to-person messages, but you are still inside Meta's ecosystem. - **Don't treat WhatsApp's Incognito AI Chat as encrypted communication.** It's a real improvement over standard cloud AI, with independent audits behind the technology securing it. But it's still a conversation with a Meta-owned chatbot. Share only what you'd share with any other AI tool. - **If you had Instagram E2EE on and didn't export your encrypted history before May 8, it's gone.** Because the previous messages were truly encrypted, Meta had no access to previous messages. If you hadn't exported and backed up those messages, there is no recovery path. If you have or had important information in chats, maybe check out the [ongoing case for backups](https://www.freshfromcache.com/content/files/2026/06/do-you-need-backups.html). WhatsApp's Private Processing is engineered well. The NCC Group and Trail of Bits audits are real third-party reviews, and the math behind end-to-end encryption is the same math that protects your banking. That means you are getting privacy vetted by actual third parties. What changed is Meta's overall privacy ecosystem. Privacy at Meta is now per app and [decided product by product](https://www.freshfromcache.com/meta-instagram-ai-feature/). Just keep in mind Meta's broken promises of the past and contradicting marketing. Joel ## Sources **Source:** Pieter Arntz, ["Meta's confusing new approach to chat privacy"](https://www.malwarebytes.com/blog/news/2026/05/metas-confusing-new-approach-to-chat-privacy?ref=freshfromcache.com), Malwarebytes Labs, May 15, 2026. **Also:**["Broken Promises: RIP Instagram's End-to-End Encrypted DMs"](https://www.eff.org/deeplinks/2026/05/broken-promises-rip-instagrams-end-end-encrypted-dms?ref=freshfromcache.com), Electronic Frontier Foundation, May 2026\. ["Warning: Instagram DMs Lose End-to-End Encryption Starting Today"](https://www.macrumors.com/2026/05/08/instagram-end-to-end-encryption/?ref=freshfromcache.com), MacRumors, May 8, 2026 (Take It Down Act timing). Kelvin Chan, ["Meta launches WhatsApp 'incognito' mode"](https://www.usnews.com/news/technology/articles/2026-05-13/meta-launches-whatsapp-incognito-mode-to-address-privacy-concerns-for-ai-chats?ref=freshfromcache.com), AP via US News, May 13, 2026. ### What the heck is a Passkey? URL: https://www.freshfromcache.com/what-the-heck-is-a-passkey/ Last updated: 2026-08-11T18:29:22.000Z If you're like me, you've probably been seeing prompts to set up a passkey for about a year now. And if you're also like me, you may have been hitting "not now" every time you see them. Every few weeks Google asks me. Then Amazon. Then Microsoft. The prompt shows up, says something about using my face or fingerprint to sign in instead of a password, and I am always in the middle of something else. Maybe later. Click. Move on. Recently I've noticed more and more websites are giving Passkey prompts when logging in. I realized I had been avoiding a security measure I'd likely recommend to users. So I figured I'd finally read into Passkeys. ## The short answer A passkey is a way to sign into a website or app without typing a password. You unlock your phone or laptop the way you normally do (Face ID, fingerprint, PIN), and that is it. You are in. The "passkey" is actually a small piece of data that is stored locally on your device. The website then stores a matching piece of data to keep on their end. When those two pieces of data match up, you get to log in without ever putting in a password. While this technology is not new, recently companies have been using it differently. ## How it works When you create a passkey, your device generates two related pieces of math called a key pair. One half stays on your device, locked. The other half goes to the website. The next time you sign in, the website sends your device a small puzzle. Your device solves it using its half of the pair. The website checks the answer against its half. If you match, you're in. No password required. There is no password to steal. Even if the website is compromised and [their entire user database gets leaked](https://www.freshfromcache.com/canvas-got-breached-again/), their half is worthless without your half. The half the website stores is public information. Think of your half as a key, and theirs as a lock. The passkey is tied to the exact website it was made for. If a scammer sends you a link to a fake Amazon page, your Amazon passkey will not work there. The browser checks the actual domain before it will let your device respond to the puzzle. Phishing pages stop being a threat because there is nothing to type in. ## Why this matters Passwords have one big design flaw: they are shared secrets. Whatever your password is, you know it and the website's server knows it. Anyone who steals it can use it. Anyone who tricks you into typing it on a fake page can use it. Anyone who reuses an old leaked password from a different site can sometimes use it. That is why we all ended up with password managers, 2FA codes, security questions, and years worth of password changes. All of that existed because your password was a shared secret. Passkeys remove the need for a shared secret. The data stays on your local device, locked behind your face, fingerprint, or PIN. There is nothing a scammer can trick you into giving them. The FIDO Alliance (the standards body behind passkeys) reports that Google has over 800 million accounts using them. Amazon hit 175 million in the first year. Microsoft made passkeys the default for new accounts in May 2025. ## What's the catch? Passkeys are tied to a device, or to an ecosystem account that syncs them across your devices (think Google or Apple accounts). That trade-off has a few implications. If you only set up a passkey on one device and you lose that device, you can be locked out. The way most people avoid this is by letting their phone or password manager sync passkeys across multiple devices. Apple does this through iCloud Keychain. Google does it through Google Password Manager. Microsoft does it through Windows Hello plus a Microsoft account. Most third-party password managers ([1Password, Bitwarden, Dashlane](https://www.freshfromcache.com/start-using-a-password-manager/)) handle it across all three. Apple and Google do not directly sync to each other. If your life is split between an iPhone and an Android, or between a Mac and a Windows PC, you will probably want a third-party password manager handling passkeys so they show up everywhere. Not every site supports passkeys. As of early 2026, around half of the top 100 websites support them. Most major banks still do not. Most line-of-business software for small businesses still does not. The places you most want passkeys (your bank, your accounting software, your CRM) have been the slowest to adopt them. During the transition, most sites still let you fall back to a password. While convenient, it also means an attacker who somehow has your password can still log in and set up their own passkey on their own device. This transition period is genuinely weaker than full passkey-only. The fix is to also have strong two-factor authentication turned on for the password fallback. ## Where to start If you want to try using a passkey, there are a few places that are best to start. **Your email account**. [Whoever controls your email](https://www.freshfromcache.com/email-recovery-check/) can reset the password on almost every other account you have. Set up a passkey on your Gmail, Outlook, or Yahoo account today. It takes about 30 seconds once you find the security settings. **Your Apple ID, Google account, or Microsoft account**. These accounts often unlock other things on your devices, and the cloud sync for your other passkeys may depend on them. **Amazon, eBay, PayPal, and the major retailers**. Amazon's passkey prompt has been showing up after sign-ins for months. The next time you see it, take the time to set up your passkey. **Anything where a takeover would hurt.** Generally it's a good idea to set up a passkey anywhere that is available. If an account could cause serious harm if it fell into the wrong hands, it's a good idea to set up a passkey. You do not have to convert everything in one sitting. The next time a site you actually use offers a passkey, take it. ## What if I lose my phone? This is the question that comes up most often. If your passkeys sync (through Apple, Google, Microsoft, or a password manager) and you can sign into that account on a new phone, your passkeys come with you. Same as your photos and text messages on iMessage. There is nothing extra you have to do. If you did not have sync set up, or you lose access to the account that does the syncing, you fall back to the old recovery options for each site. Password reset emails, backup codes, two-factor codes, etc. The same path you would have used if you forgot a password. The thing to do today: - Make sure your phone has a real PIN (not 1234) - Make sure your iCloud, Google, or Microsoft account has two-factor authentication on - If a site offers backup codes when you set up a passkey, save them somewhere offline (not in your phone) If you follow those steps, you won't have to worry about losing access to any passkey protected sites. ## Final thought Passkeys are a real upgrade and they work, but they are not magic. Eventually they will not be optional. Major platforms are pushing hard toward making them the default and password-only logins are slowly being deprecated. You do not need to do anything dramatic today. The next time a website you actually use offers to set up a passkey for you, say yes, follow the prompts, and let your phone do the work. If you have been clicking "not now" the way I had been, maybe take a minute to set it up. If you have a specific site that has been bugging you to set up a passkey and you want me to walk through what the prompt is asking, I'd love to hear from you! Joel · [joel@freshfromcache.com](mailto:joel@freshfromcache.com) ### Outlook icon confusion URL: https://www.freshfromcache.com/outlook-icon-confusion/ Last updated: 2026-07-31T20:56:45.000Z If you've opened the Start menu on Windows in the last few years and found yourself staring at two or three different Outlook icons, you're not losing your mind. There's a reason the meme above exists. It's confusing. What even is "Outlook (new)"? Microsoft is in the middle of rolling out a brand new Outlook, and the rollout has been going for over two years. They keep pushing the deadline. Even after my years in IT, I still stop and think about which icon to click when I search "Outlook." ## Why so many? Windows 11 comes with Outlook (new) already installed on every PC. Microsoft did that on purpose, so the new app is there for everyone, including people who don't pay for Office. If you also pay for Microsoft 365 (the subscription with Word, Excel, and Outlook Classic), then Classic is installed too. Both apps pin themselves to your Start menu. More icons, more confusion. Inside each app there's a little toggle in the upper-right corner. In Classic it says "Try the new Outlook." In new Outlook it says "New Outlook," and switching it off drops you back to Classic. ## Same look, different foundation ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/microsoft_outlook_icon_-282025-e2-80-93present-29-svg-format-original.png) ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/microsoft_office_outlook_-282018-e2-80-932024-29-svg-format-original.png) They look almost the same at first. Same inbox, same calendar, same general layout. The differences are in the small things, and in what each one is allowed to do. The first one you'll notice is ads. The free version of new Outlook shows ads in your message list, dressed up to look like real emails with a small "Ad" tag. The old Mail app never did that. You can pay your way out of it. An ad-free inbox starts at $1.99 a month through Microsoft 365 Basic. And plenty of people who already pay for full Microsoft 365 still see the ads anyway, because their main address is a Gmail or some other non-Microsoft address and the app doesn't count it as paid. So you're paying, and still getting sold to. Then there's where your email actually lives. New Outlook is built on the web version, which changes something most people never see. When you add a Gmail, Yahoo, or your internet provider's email to it, the app doesn't connect your computer straight to that mailbox the way Classic did. It pulls a copy onto Microsoft's servers first. Your mail makes a stop at Microsoft on the way to you. Microsoft says it doesn't read your messages to show you ads, and doesn't hand your name or email address to advertisers. Proton, a company that sells private email (so keep that in mind), dug into the European sign-up screen and found a list of hundreds of advertising partners written into the consent terms. You can argue about how much that matters. The plain fact underneath it doesn't change: your other mailboxes now route through Microsoft, where before they didn't. The rest of the differences are about features, and those are what's holding up the whole rollout. ## Deadline drift Microsoft has been planning to retire Classic for years. The plan has three phases: 1. You choose which one you want, and you can still go back. 2. New Outlook becomes the default, and you can still go back. 3. Eventually, the old one goes away. Microsoft has missed every deadline it set for phase two. The latest miss was February 2026\. Business users were supposed to start defaulting to new Outlook by April. It didn't happen. Microsoft pushed the date back a year, to March 2027, the third delay for this phase. The reason is always the same: businesses keep telling Microsoft, **loudly**, that new Outlook still doesn't do enough of what the old one does. You can watch the indecision in real time. This past June, Microsoft was set to pull a contact-card feature out of Classic, then paused the removal a few days before it was supposed to land. They're trimming the old app and un-trimming it in the same month. For most people reading this, none of that changes your day. If you use Outlook at home, Microsoft already moved you when it shut down the old Mail and Calendar apps at the end of 2024\. If your business runs on Outlook, your IT team has until at least March 2027 to sort it out, and Classic is supported under contract through at least 2029. So if you're someone who leans on the plug-ins and macros that are still missing, you don't need to panic. Yet. ## Outlook, now with more Outlook So far I've been talking about Outlook on a Windows desktop. Outside of that, the word "Outlook" covers four more products. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/outlook-six-products-map.png) Outlook.com is free webmail. It used to be Hotmail. If your address ends in @hotmail.com, @outlook.com, @live.com, or @msn.com, that's the service running your account. It lives in a browser. Nothing to install. Outlook on the web is the work version of the same idea. If your company uses Microsoft 365 for email, you sign in at outlook.office.com from any browser and there's your work mail. It's the same engine as new Outlook, in a tab. Outlook for Mac is a separate app built for Apple computers. Different program from the Windows one, different code, different history. Since 2023 it's free, no Microsoft 365 needed. Outlook Mobile is the iPhone and Android app. It has its own code too. For phones, this is the standard Microsoft mail app. So depending on who's talking, "Outlook" might mean a free webmail service, a work webmail service, a Windows desktop app (two of those), a Mac app, or a phone app. Six products, one name. It's why a Microsoft Support article can feel like it's describing something you've never seen. It might be. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/screenshot-2026-05-14-132216-format-original.png) ## Watch for fake "upgrade" emails Scammers have noticed the confusion, and they're using it. Because nobody's quite sure what's happening with the Outlook transition, fake "upgrade or lose your email" messages have started going around. They tell you the classic version is being shut off, sometimes "tomorrow," and that you have to act now or lose access. Some come from an @aol.com address or another account that has nothing to do with Microsoft. Some carry a QR code that sends you to a fake sign-in page. (We've covered how these [fake-verification pages](https://www.freshfromcache.com/fake-captcha-scam/) work before.) - Microsoft doesn't email you demanding that you "update" Outlook or lose your mail. The switch between versions happens inside the app, with that toggle, not through a link in an email. - Check who actually sent it. Real Microsoft account email comes from accountprotection.microsoft.com. The display name can say "Microsoft" while the real address is something else entirely, so look at the actual address, not the name. - Don't click the link or scan the code. If you want to change Outlook versions, use the toggle in the app, the one from earlier in this article. - When in doubt, go straight to the app or to account.microsoft.com yourself. Don't take the email's word for it. If a message about Outlook is rushing you, that's the tell. Microsoft has spent over two years not rushing this. The only one in a hurry is the person trying to scam you. ## Cut down the confusion A few practical things if the icons trip you up, or you're just trying to figure out which Outlook to use: **Pick one and pin only that one to your taskbar.** When Outlook confusion first hit me, this is what I did. Open every Outlook you've got. Find the one you want. While it's open, right-click its icon on the taskbar. Choose "Pin to taskbar." Then right-click any other Outlook icons down there and choose "Unpin from taskbar." Now, any time you're not sure you're in the right one, close it and click the single icon on your taskbar. **If you pay for Microsoft 365 and you use plug-ins or macros, stay on Classic for now.** It's supported through at least 2029 and it has the features you depend on. If you got moved to new Outlook automatically, use the toggle to switch back. Microsoft is rolling out "web add-ins" to replace the older "COM add-ins" that power things like CRM connectors, but not every vendor has one yet. If new Outlook interests you, check whether the add-ins you rely on have a web version before you commit. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/unnamed-format-original.png) If your Outlook doesn't look right, try this toggle. **Test both before you commit.** Each one has that toggle in the upper-right corner, and the switch goes both ways. Give the new one a week. If it does what you need, stay. If it doesn't, switch back. **If you just want email, give the new one a try.** Most people who only read and send email will be fine on it. It's free, it loads fast, and it looks like the web version you might already use at work. **If you're still on Windows Mail or Calendar, get out.** Those apps stopped working at the end of 2024\. They still open, but they won't send or receive. Export anything you want to keep and pick a new home for it. ## Thanks Microsoft It's not you. Microsoft built a new product, decided it wasn't ready, and kept shipping it anyway. They renamed the old one to make room, then missed every deadline they set. What's left is a trail of icon devastation on everyone's computers. The fact that this article needs to exist tells you Microsoft dropped the ball. If you remember one thing: there's no rush. Whatever Outlook you're using right now is supported, unless you're on Windows Mail or Calendar. The deadlines are still out in the future, and Microsoft has shown it isn't shy about moving them. Pick the one that works for you. Ignore the rest. Joel If you have a funny Outlook confusion story, or you're *still* confused, I'd love to hear from you. Reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com) *Outlook icons via* [*Wikimedia Commons*](https://commons.wikimedia.org/wiki/Category:Microsoft%5FOutlook%5Flogos?ref=freshfromcache.com)*.* ### IT twins wipe 96 government databases. URL: https://www.freshfromcache.com/it-twins-wipe-96-government-databases/ Last updated: 2026-07-31T20:56:42.000Z On February 18, 2025, twin brothers Sohaib and Muneeb Akhter were fired during a video call from Opexus, a Washington D.C. tech contractor that hosts data for more than 45 federal agencies. By the time the call ended, 96 federal databases were gone. The window from termination to destruction was 56 minutes. The two of them deleted case management systems, records of Freedom of Information Act requests, and investigative files for multiple agencies. After wiping a Department of Homeland Security database, court records show one of the brothers asked an AI chatbot how to clear system logs. Sohaib was convicted last week. He's looking at a sentence that could be up to 21 years in prison. Muneeb is still awaiting trial; his charges could carry up to 45 years. ## What happened? The employer fired them on a video call after discovering that Sohaib had a prior federal felony conviction from 2015 he hadn't disclosed. Both brothers had pleaded guilty that year to accessing State Department systems and stealing personal data, including from the federal agent investigating them. Sohaib served two years and Muneeb served over three. Because of their history, the firing happened on video and with no warning. Sohaib's Windows account and network access were cut while the call was occurring. However, Muneeb's were not. That gap was all they needed. Once Muneeb was still logged in, the two of them write-protected databases (which prevents admins from undoing changes), deleted databases, and tried to cover their tracks. The databases belonged to dozens of agencies that had trusted a single contractor with their data. Opexus later said "the incident made clear that our screening protocols needed to be even more robust." That's a nice way of saying nobody ran a basic background check on a person they then handed admin access to. ## Lessons to be learned Opexus had a glitch in their offboarding procedures. The IT side of offboarding gets less attention than the HR side at most companies, and that gap matters most when an employee is being let go. Every small organization has that gap. An employee leaves, the conversation happens, the paperwork gets filed. But the accounts get disabled later, sometimes much later. In between, the now ex-employee still has the keys to your file server, your email, your client database, your shared password manager. Most of the time, nothing happens. The person collects their stuff and moves on. The Akhters are an extreme case, but the conditions that enabled them are common. For a small business or nonprofit, the list of common places to miss: former employees still sitting in shared password managers, old VPN credentials that still work, Microsoft 365 accounts nobody disabled. Because cases like this are rare, it's easy to become complacent. But even one bad actor could bring a company to its knees with the right access. ## What to do - **Cut access at the start of the termination meeting.** If you know a conversation is coming, the accounts should be disabled as soon as the meeting starts. Opexus did this with Sohaib, but they missed Muneeb. That oversight cost them. - **Keep a written list of every system each person can log into.** If you don't have Active Directory, write it down: Email, file sharing, password manager, VPN, point of sale, accounting software, social media accounts, the building alarm code. If you don't have it before someone leaves, you'll miss something. - **Treat contractors and volunteers like employees on the way out.** If they have access and then leave, the checklist is the same one. - **Back up the things that would hurt to lose.** Most cloud services have built-in restore features that are not on by default. If anyone with access deletes a shared folder, you need to know whether you can get it back. We wrote about [what backups you probably already have](https://www.freshfromcache.com/do-you-need-backups/) a couple of weeks ago; that's the place to start. - **Don't share admin accounts.** If two people log in as "admin" with the same password, you cannot tell what either one did. Every person who needs admin should have their own account. The Opexus story is in the news *because* it's rare. But the gap that made it possible is in every organization. Joel If you have any horror stories about lingering access, I’d love to hear them. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com) **Sources** - Ars Technica, [Drop database: what not to do after losing an IT job](https://arstechnica.com/tech-policy/2026/05/drop-database-what-not-to-do-after-losing-an-it-job/?ref=freshfromcache.com) - BleepingComputer, [Former govt contractor convicted for wiping dozens of federal databases](https://www.bleepingcomputer.com/news/security/former-govt-contractor-convicted-for-wiping-dozens-of-federal-databases/?ref=freshfromcache.com) - CyberInsider, [Former IT contractor convicted for wiping 96 US government databases](https://cyberinsider.com/former-it-contractor-convicted-for-wiping-96-us-government-databases/?ref=freshfromcache.com) - ACS Information Age, [Double trouble: Twin brothers wiped 96 US govt databases](https://ia.acs.org.au/article/2026/double-trouble--twin-brothers-wiped-96-us-govt-databases.html?ref=freshfromcache.com) ### The data center boom reaches Hillsboro, OR. URL: https://www.freshfromcache.com/the-data-center-boom-reaches-hillsboro/ Last updated: 2026-07-31T20:56:49.000Z In Fayette County, Georgia, a data center used over 30 million gallons of water without paying for it. Investigators eventually found two industrial hookups that weren't being monitored. One hookup had been installed without the utility's knowledge. This happened while drought conditions had local officials asking residents to cut back on personal water use. Ars Technica covered the story this week. Data centers are booming worldwide thanks to AI. Hillsboro, just west of Portland, OR, is feeling the pressure. Hillsboro has 18 data center sites built or under construction as of March 2026\. On Tuesday, June 2nd, the Hillsboro City Council will hold a public work session at the Civic Center to discuss the data centers and whether or not to place a temporary pause on new permits. The work session is open to the public and you can also participate online. A few things have already been decided at the state level. The Oregon Legislature passed HB 4084, putting a moratorium on new data center Enterprise Zone applications starting June 6, 2026\. That puts a state pause on tax-abatement. The 2025 POWER Act (HB 3546) created a special electricity rate class so large users like data centers pay their own grid costs instead of shifting them to households. The numbers people are arguing about don't all line up. The City of Hillsboro reports that data centers use 111 million gallons across 14 sites. That's 1.76 percent of the city's total water demand in 2025\. The Tualatin Riverkeepers estimate that a single large-scale data center can use up to 4.5 million gallons of water per day. Hillsboro City Councilor Kipperlyn Sinclair has said residential electricity rates have risen nearly 50%. Data centers pay less than half the per-kilowatt-hour rate residents do. This is largely due to subsidies for infrastructure like the $200 million Hillsboro substation. Statewide, data centers used about 11% of Oregon's electricity in 2023\. That share is expected to double over the next three to four years. Hillsboro's situation is a question about pace and oversight. Not a judgement on whether data centers should exist. The state has paused new tax breaks and the city is deciding whether to also pause new permits. Local journalism and community organizing have raised real questions about cost-shifting, water use, and rate fairness. If you live in Hillsboro, here are a few things you can do: - Read [the city's FAQ](https://www.hillsboro-oregon.gov/community/data-centers?ref=freshfromcache.com). The Hillsboro Data Centers page lays out the city's position with tables and rate comparisons. - Read [the Hillsboro Herald open letter](https://hillsboroherald.com/an-open-letter-to-hillsboro-stating-the-truth-about-our-data-center-future/?ref=freshfromcache.com) and [KATU's coverage of the local petition](https://katu.com/news/local/hillsboro-petition-seeks-pause-data-centers-amid-energy-and-farmland-concerns-washington-county-oregon-city-councilor-kipperlyn-sinclair-jacob-roloff-tammy-carpenter-illsboro-herald-editor-dirk-knudsen-tualatin-riverkeepers-pge?ref=freshfromcache.com) for the perspective of community organizers. - Mark June 2\. Tuesday at 6 pm at the Hillsboro Civic Center. Watch online or show up. Public work sessions are where city councils gather facts before deciding, so this is the time to weigh in. - Watch [the Governor's report](https://www.oregon.gov/energy/get-involved/pages/oregon-data-center-advisory-committee.aspx?ref=freshfromcache.com). The proposed Hillsboro pause is tied to its release. The 18 sites are a count as of March 2026\. The state moratorium covers tax breaks, but not construction. Joel If you live in Hillsboro and have a story or an experience with data centers, I’d love to hear from you. You can reach me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com) **Sources:** - Ars Technica, [Data center used 30 million gallons of water without initially paying](https://arstechnica.com/tech-policy/2026/05/data-center-used-30-million-gallons-of-water-without-initially-paying/?ref=freshfromcache.com) - City of Hillsboro, [Data Centers in Hillsboro FAQ](https://www.hillsboro-oregon.gov/community/data-centers?ref=freshfromcache.com) - KATU, [In Hillsboro, petition seeks pause on new data centers amid energy and farmland concerns](https://katu.com/news/local/hillsboro-petition-seeks-pause-data-centers-amid-energy-and-farmland-concerns-washington-county-oregon-city-councilor-kipperlyn-sinclair-jacob-roloff-tammy-carpenter-illsboro-herald-editor-dirk-knudsen-tualatin-riverkeepers-pge?ref=freshfromcache.com) - KLCC, [Oregon's Data Center Explosion: Who Benefits and Who Bears the Cost?](https://www.klcc.org/podcast/oregon-on-the-record/2026-04-02/oregons-data-center-explosion-who-benefits-and-who-bears-the-cost?ref=freshfromcache.com) - Oregon Center for Public Policy, ["We've Been Very Foolish": Inside Oregon's Data Center Boom](https://www.ocpp.org/2026/03/12/oregons-data-center-boom/?ref=freshfromcache.com) - Hillsboro Herald, [An Open Letter to Hillsboro on Data Centers' Future](https://hillsboroherald.com/an-open-letter-to-hillsboro-stating-the-truth-about-our-data-center-future/?ref=freshfromcache.com) - Oregon Department of Energy, [Oregon Data Center Advisory Committee](https://www.oregon.gov/energy/get-involved/pages/oregon-data-center-advisory-committee.aspx?ref=freshfromcache.com) ### The Chatbot: What We Actually Know About AI Companions and Mental Health URL: https://www.freshfromcache.com/the-chatbot/ Last updated: 2026-08-11T18:29:05.000Z Headlines about AI chatbots and mental health have largely been about teenagers, but the data points elsewhere. In January, *JAMA Network Open* published a survey of nearly 21,000 American adults led by Roy Perlis at Massachusetts General Hospital. Daily users of generative AI were more likely to screen positive for moderate depression than non-users. The group with the steepest odds wasn't the 18-to-24 year olds everyone has been writing about. It was middle-aged adults, ages 45 to 64, where daily AI users were 54% more likely to show moderate-or-worse depression than non-users in their age group. People 65 and older showed no significant association. That's the demographic running small businesses. Leading nonprofits. Managing teams. People old enough to have built something, young enough to still be building. The research can't yet tell us which direction the arrow points. Perlis himself has said he can't rule out the possibility that depressed people are turning to AI more rather than AI making people more depressed. But a separate, year-long study published this spring in *Psychological Science* follows the same people over time, and what it shows is harder to explain away. People who turned to AI for companionship felt more emotionally isolated four months later. Two papers do most of the work in this new area of research. ## The Two Studies The Perlis paper is a snapshot. Over 20,000 American adults, surveyed in spring 2025, depression measured using the PHQ-9 (the standard nine-question clinical screener), AI use self-reported. Daily users were 30% more likely overall to score in moderate-or-worse depression territory. The 45-to-64 subgroup hit 54%. The effect held after adjusting for sex, income, education, urban-or-rural, and the rest of the usual list. A snapshot can't tell you which came first. It can only tell you the two things are showing up together. The Folk and Dunn paper in *Psychological Science* can say more. They followed over 2,000 adults across four English-speaking countries for a full year, with regular check-ins. Two findings emerged. People who started out lonelier did turn to AI for companionship more often. People who turned to AI for companionship felt more emotionally isolated four months later. The effect held up on the specific measure of emotional isolation. On a broader measure of overall social connection, it didn't quite reach statistical significance. The authors flagged that distinction themselves, and the careful framing is the right one. Read together, the two papers say something specific. There is association. The evidence is starting to come in. The most precise version of the claim is that AI companionship doesn't fill the hole, but deepens it. ## 3\. Product Decisions There's a reason this is happening, and it's not an accident. A research team at Stanford and Carnegie Mellon, led by Myra Cheng, published a study in *Science* in March. They tested eleven different AI models against actual human responders on the same scenarios. The AIs affirmed users' actions about 49% more often than the human respondents did. The gap held when the scenarios described things the user had clearly done wrong. The team ran one experiment using 2,000 Reddit posts where the human community had unanimously judged the original poster to be in the wrong. The AIs still sided with the poster a sizable share of the time. Then they did the part that matters most. They had people interact with a sycophantic AI versus a more balanced one, gave them a real interpersonal conflict scenario, and measured willingness to make amends. A single conversation with the agreeable AI was enough to reduce the subject's willingness to repair the conflict. The products are tuned to do this. The metric that pays the bills is engagement, and engagement comes from responses that make the user feel good about the last message they sent. Disagreement, friction, and "are you sure about that" do not move the engagement number. The result is a conversation partner who agrees more readily than your most loyal friend, more readily than your therapist, more readily than the version of you trying to be honest with yourself. We've [covered a related finding](https://www.freshfromcache.com/friendly-ai-is-less-accurate/): an Oxford study showed that the friendlier you tune an AI, the less accurate it gets. The two studies are looking at the same design choice from different angles. Engagement comes from warmth and agreement. Accuracy and pushback come at engagement's expense. The phrase circulating in industry to describe this is "glazing." Sam Altman used it in April 2025 about his own product. He wasn't wrong, and he wasn't unusual. Every consumer chatbot on the market faces the same incentive, and most of them have made similar choices. If you've noticed that ChatGPT seems to think every idea you've ever had is a great one, you might want to get a second opinion. ## 4\. The Spiral Kartik Chandra and colleagues at MIT published a mathematical model this February of what happens when a person with an unusual belief talks to a chatbot biased toward agreement. The result is uncomfortable. Even a perfectly rational person, updating beliefs the way statistics says they should, gets pulled further toward the false belief as the conversation continues. The agreement compounds. The researchers tested two obvious fixes within their model: forcing the chatbot to be strictly truthful, and warning the user up front about agreement bias. Both reduced the effect, but neither fix eliminated it. This isn't a thought experiment. The Human Line Project, an advocacy group tracking these cases, has documented close to 300 instances of what is being called "AI psychosis." At least 14 deaths and five wrongful-death lawsuits are now associated. The most-cited case is Sewell Setzer, the fourteen-year-old in Florida whose mother, Megan Garcia, has testified before the Senate Judiciary Committee. The most recent is Adam Raine, sixteen, in California, where OpenAI's own moderation system flagged 377 of his messages for self-harm content over the course of his conversations. Garcia testified "AI companies and their investors," she told the Senate, "have understood for years that capturing our children's emotional dependence means market dominance." She is pointing out that this is by design, not a glitch. These remain edge cases. Most people using AI experience nothing like this. The mechanism that produces these outcomes, though, is the same mechanism that makes the everyday product feel pleasant to use. This technology is new, and with any new technology, there are certain risks that won't be known until more time has passed. ## 5\. The Other Side Dartmouth ran a randomized controlled trial of an AI chatbot called Therabot, purpose-built and trained on clinically-relevant content, and published results in *NEJM AI* showing significant reductions in depression and anxiety symptoms compared to a waitlist control. A pilot study at NYU last fall found similar reductions in a 305-person cohort using a different purpose-built mental health chatbot, with improvements in social connection over ten weeks. A longitudinal study of 68 older adults in Indonesia, using a culturally-adapted AI companion, showed measurable drops in loneliness scores. A small but growing body of work in autism research suggests AI chatbots can serve as accessible practice partners for social interaction, particularly for autistic adults whose access to neurodivergence-affirming human support is limited. There's a pattern across these positive findings, and it's specific enough to name. AI chatbots tend to help when the use is short, structured, and aimed at a specific outcome: rehearse a hard conversation, work through a cognitive-behavioral exercise, find words for something heavy, draft an email you've been putting off. They tend to hurt when the use is open-ended, unstructured, and substituting for human contact. The same product can do both, depending on how the user is holding it. Perlis himself wrote in his paper that "the nature and context of use may be important to consider." The real question is what they're being used for, and what they're displacing. For most readers, ChatGPT helping draft a tough message to a board chair is fine. ChatGPT as the place you process your hardest week is different. The evidence on that is getting clearer. ## 6\. Chat Window Open The 45-to-64 finding in the Perlis data is the demographic this article is aimed at. If you're reading this, statistically speaking, you are closer to the group with the steepest odds than you are to the teenagers most articles are writing about. You might run a company. You might manage people. You might have a stretch of evening between when the workday actually ends and when you stop thinking about it, and ChatGPT is open on a tab somewhere during that stretch. I'm not going to pretend I haven't been there. I have a job by day and other pursuits by night, and there are weeks where the easiest place to think out loud is a chat window. It's available at 11pm. It doesn't ask how I'm doing in the way that requires me to answer honestly. It just helps me move to the next thing. The reason I think the data is real, and not just a statistical artifact, is that the simplest explanation fits. The 45-to-64 group in this country is not having a great decade. Small business owners, nonprofit leaders, mid-career managers. The people in this bracket are running on fumes more often than they're admitting. Loneliness shows up not as a feeling but as a pattern: longer hours, smaller social radius, the gradual conversion of every relationship into a logistics conversation. When a tool arrives that will respond to a 1 a.m. typed thought with something coherent and slightly flattering, the reach for it is not so surprising. The trouble is what the tool does once you've reached for it. Folk and Dunn's data says four months of that pattern leaves you measurably more isolated than you started, not less. Cheng's data says the tool's instinct in every conversation is to make you feel a little more right than you were when you opened the chat. Put those two together and the picture is not "AI is bad." The picture is: if you are using AI to fill a gap that used to be filled by a friend or partner, the gap is getting bigger while it feels like it's getting smaller. Not as catchy for a headline. I'm not suggesting anyone stop using these tools. I use them every day. I'm suggesting the same thing I've been telling myself, which is that if the chat window has become the place you go to think about your week instead of a person, that's a signal. ## 7\. What to Do Four things worth doing, in roughly the order they cost you. - **Use AI for the task, not the talk.** Drafting an email, summarizing a vendor contract, walking through a config error. That's what these tools are good at, and the harms research barely touches that use pattern. The risk shows up when the chat window stops being a workshop and starts being a confidant. Keep cognizant of which one you're in. FFC has a [practical guide](https://www.freshfromcache.com/boring-ai-advice/) to using AI for the task side of that line. - **Treat the reflexive agreement as the bug it is.** If a chatbot has never told you you're wrong, never pushed back on a draft, never said "are you sure," that's not the model being polite. That's the engagement metric talking. When you catch the flattery pattern, ask the tool directly to argue the other side. Even better, [write this pushback into your](https://www.freshfromcache.com/ai-tips-for-everyday-people/) "instructions". This will filter ALL of your chat responses with pushback being a default. - **Watch the substitution.** The clearest signal in the research is what the AI is replacing. If you'd rather process a hard week with ChatGPT than with a friend, a partner, or a therapist, that's when you should step back and take stock of the situation. - **If you run a team or a nonprofit, have a position before you need one.** Your employees and clients are using these tools right now, and the way they're using them is shaping how they work. You don't necessarily need a policy. You need a stated point of view about what the tools are good for, what they're not good for, and what your organization thinks about people processing emotional weight through them. ## 8\. Smoke, not fire The strongest causal evidence in this piece covers four months. The biggest survey is a snapshot. The lawsuits are in discovery. State laws are taking effect in pieces between now and 2027: New York, California, Illinois, Texas, and more than thirty other states with bills in motion. The Federal Trade Commission has open inquiries against seven companies. The products themselves change faster than the research can keep up. What's defensible to say right now: there's enough smoke to be careful, not enough to be certain of a fire. Anyone telling you AI companions are catastrophic, or that they're fine, is running ahead of the evidence in one direction or the other. The honest answer is the boring one. Use the tools for what they're good at. Pay attention to what they're replacing. Notice when a conversation pattern stops resembling anything a good friend would do. And if you're running a team or serving a community where loneliness is already a factor, this is worth having a position on before it's worth having a policy on. Joel If you’ve had any interesting experiences or stories about using AI, I’d love to hear them! You can email me at [joel@freshfromcache.com](mailto:joel@freshfromcache.com). ## 9\. Sources - Perlis RH et al. "[Generative AI Use and Depressive Symptoms Among US Adults](https://jamanetwork.com/journals/jamanetworkopen/fullarticle/2844128?ref=freshfromcache.com)." *JAMA Network Open*, January 21, 2026. - Folk D, Dunn E. "[How Does Turning to AI for Companionship Predict Loneliness and Vice Versa?](https://journals.sagepub.com/doi/10.1177/09567976261427747?ref=freshfromcache.com)" *Psychological Science*, 2026. - Cheng M et al. "[Sycophantic AI decreases prosocial intentions and promotes dependence](https://www.science.org/doi/10.1126/science.aec8352?ref=freshfromcache.com)." *Science*, March 2026. - Chandra K et al. "[Sycophantic Chatbots Cause Delusional Spiraling, Even in Ideal Bayesians](https://arxiv.org/abs/2602.19141?ref=freshfromcache.com)." arXiv:2602.19141, February 2026. - Heinz MV et al. "[Randomized Trial of a Generative AI Chatbot for Mental Health Treatment](https://ai.nejm.org/doi/abs/10.1056/AIoa2400802?ref=freshfromcache.com)." *NEJM AI*, 2025. - Common Sense Media and Stanford Brainstorm Lab. "[Social AI Companions Risk Assessment](https://www.commonsensemedia.org/sites/default/files/pug/csm-ai-risk-assessment-social-ai-companions%5Ffinal.pdf?ref=freshfromcache.com)," April 2025. - [Megan Garcia, written testimony to Senate Judiciary Committee](https://www.judiciary.senate.gov/imo/media/doc/e2e8fc50-a9ac-05ec-edd7-277cb0afcdf2/2025-09-16%20PM%20-%20Testimony%20-%20Garcia.pdf?ref=freshfromcache.com), September 16, 2025. - [Raine v. OpenAI](https://www.courthousenews.com/wp-content/uploads/2025/08/raine-vs-openai-et-al-complaint.pdf?ref=freshfromcache.com), San Francisco County Superior Court, complaint filed August 26, 2025. ### The Disturbing Reality of AI-Powered Plush Toys URL: https://www.freshfromcache.com/ai-powered-toys/ Last updated: 2026-08-11T18:29:07.000Z Last fall, a $99 plush bear named Kumma told researchers from the US Public Interest Research Group where to find pills and matches and engaged in graphic sexual conversation. The bear is sold on Amazon. It runs on OpenAI's GPT-4o. It's part of the wave Wired covered last week. By October 2025, there were over 1,500 AI toy companies registered in China. BubblePal and FoloToy now sell across the US, UK, Canada, and Europe. Mattel has a partnership with OpenAI to add conversational AI to Barbie and Hot Wheels, with products due this year. These plushies are LLMs with a microphone, a speaker, and a stuffed exterior. They respond in real time. And we thought Teddy Ruxpin playing pre-recorded tape was creepy. ## How they actually work Microphone, speaker, WiFi. The audio gets sent to a cloud API (often OpenAI's and sometimes a Chinese model), the response comes back, and the toy speaks it. The "personality" is a prompt template plus some voice-tuning. A small team with no AI experience can ship a product like this, because the model is rented from someone else. The cost of being wrong is paid by the kid. ## What's already gone wrong PIRG's November 2025 testing turned up the Kumma bear (FoloToy, GPT-4o, $99) walking researchers through where to find pills and how to light matches on prompt. NBC News separately found that a Miiloo bear from Chinese manufacturer Miriat repeated Chinese government talking points, calling comparisons between Xi Jinping and Winnie the Pooh "extremely inappropriate" and asserting that "Taiwan is an inalienable part of China" as an "established fact." This is a toy for kids as young as three. PIRG's RJ Cross summed it up: toy makers use OpenAI's models in ways the policies don't allow, and OpenAI isn't catching it. ## Here's what this means The marketing language for these toys says "educational," "safe for kids," "screen-free companion." Read those as claims. None of them have been independently verified. There is no manual you read once; there's a model running in the cloud that updates without your involvement and can return any output the model is capable of. "Safe for kids" is a guardrail that has to be actively engineered, tested, and held in place. So far the evidence is that most of these toys aren't doing that work. As we looked at last week, the recent Oxford study found that when an AI is tuned to be "personable" or "agreeable," it becomes a "sycophant." It prioritizes keeping the conversation going over being factual. This is concerning for an adult, but for a three-year-old, it’s much more dangerous. If a child asks a "friendly" bear if it's okay to play with matches, a model tuned for warmth and engagement is statistically more likely to go along with the child’s curiosity rather than providing a firm, life-saving "No." The toy is may be designed to be too "nice" to disagree. "Safe for kids" is a guardrail that has to be actively engineered, tested, and held in place. So far, the evidence is that most of these toys aren't doing that work. If you've followed AI's track record with adults (FFC covered [why friendly AI is less accurate](https://www.freshfromcache.com/friendly-ai-is-less-accurate/) last week), handing the same models to three-year-olds without parental visibility is a bigger ask than just "another gadget." ## What to do if a kid in your life has one - **Treat it like any other internet-connected device.** Microphone plus WiFi means the toy is recording your kid's voice and sending it somewhere. Read the privacy policy. - [**Set up parental controls before the kid touches it**](https://www.freshfromcache.com/teen-safety-features-that-work/)**.** On some toys, the controls are paywalled (Miko charges $15 a month). - **Read the transcripts.** Most companion apps log conversations. Skim them at least. - **Skip vendors with no clear customer support history.** A toy that runs on someone else's API can also stop working when the API account gets paused or cancelled. - **If you're a grandparent or relative thinking of gifting one**, talk to the parents first. This is not like gifting a coloring book. ## What's next? I don't know how Mattel's OpenAI partnership will play out. I don't know whether the FTC or any state AG will enforce in this space before next holiday season. I don't know which specific toys will fail, only that several already have. What I do know is marking these as "toys" feels disingenuous. If you wouldn't hand a five-year-old an unsupervised ChatGPT account, think hard before handing them a plush version of one. Joel **Source:** Wired (via Ars Technica), "The new Wild West of AI kids' toys." Additional reporting from [MIT Technology Review (October 2025)](https://www.technologyreview.com/2025/10/07/1125191/ai-toys-in-china/?ref=freshfromcache.com), [CNN Business (December 2025)](https://www.cnn.com/2025/12/01/tech/ai-toys-safety?ref=freshfromcache.com), and [NBC News on the PIRG Education Fund November 2025 report](https://www.nbcnews.com/tech/tech-news/ai-toys-gift-present-safe-kids-robot-child-miko-grok-alilo-miiloo-rcna246956?ref=freshfromcache.com). **See also:** [Friendly AI is less accurate. A new Oxford study explains why.](https://www.freshfromcache.com/friendly-ai-is-less-accurate/) (May 3) ### Google is sending a few clicks back to your website URL: https://www.freshfromcache.com/google-clicks-back/ Last updated: 2026-08-11T19:46:43.000Z Google announced five changes to AI Overviews on Tuesday. The most visible one is a new "Further Exploration" section at the bottom of AI-generated answers that links out to articles, case studies, and reports. The other four are smaller: a "Subscribed" label that flags content from publications you pay for, a new section called Expert Advice or Community Perspectives that pulls in firsthand posts from places like Reddit and forums, hover previews on inline links, and more citations placed next to the AI text instead of stacked at the bottom. These are good changes. They're also a couple of years late. Since AI Overviews started taking over the top of search results, click-through rates to the websites those summaries are built from have dropped heavily. ## What changed and what stayed the same The changes only touch how AI Overviews link out, not how often they appear or how prominent on the page they are. The AI-generated summary still sits at the top of the page. It still answers most questions in a way that makes clicking optional. The Further Exploration links, the Expert Advice quotes, and the inline citations all give users who want more a path to get it. Users who don't want more still get an answer without leaving Google. The Subscribed label is the narrowest of the five. It only shows for content from publications you already pay for. So if you subscribe to the New York Times, links from the Times get tagged and rank higher in your own AI Overviews. If you don't subscribe, the label doesn't show, and the boost doesn't happen. The feature helps the small share of users who pay for big publications. For most small business owners and most of their customers, the label never appears, and even when it does, paid news links are usually something you'd skip on principle. The label changes nothing for FFC readers. ## Why now Google didn't announce these changes out of the goodness of their heart. A February 2026 Ahrefs study found AI Overviews correlate with a 58 percent drop in click-through rates for top ranking pages, almost double the 34.5 percent drop a year earlier. Pew found only 8 percent of users click traditional results when an Overview is present, and 15 percent when one isn't. Smaller publishers got hit hardest: a study in March 2026 reported a 60 percent drop for small sites. Then the lawsuits started. Penske Media (Rolling Stone, Variety, Billboard, and others) filed an antitrust suit. The European Publishers Council filed a formal complaint with the European Commission. Google's search advertising business made over $50 billion just last quarter. That business depends on the websites it's been quietly hollowing out continuing to exist. ## What this means for your business If you run a small business website or a nonprofit site, the practical changes are helpful but limited. The new Further Exploration links favor specific, named content. Generic landing pages and "About us" filler don't fit. The Expert Advice section favors firsthand sources, which means presence in places like Reddit and industry forums has more upside than it did last week. The Subscribed label only matters if your site is something users pay for, which most small business sites aren't. AI Overviews are still designed to keep users on Google's page. These tweaks send some clicks back, but don't change the architecture. Your site is still competing with an AI-generated summary for the same screen space, and most times the summary is going to win. ## What to do - **Check your AI Overviews data in Search Console.** It's already there. The Performance report under "Web" search type counts AI Overview impressions and clicks. Compare the last six months to the prior six. - **Get specific in your content.** The Further Exploration and Expert Advice sections favor specific articles and firsthand experience. A how-to with concrete steps and your actual numbers beats a generic explainer. - **Be present where Expert Advice looks.** If your audience hangs out in a Reddit community, an industry Slack, or a forum, having a real account that answers questions there has more upside than it used to. - **Don't rebuild your strategy yet.** These changes are rolling out gradually, and the click impact takes months to show up in your own numbers. ## The honest version These are decent improvements for users and small business owners. They will send some traffic back, and people like me can stop putting "Reddit" at the end of search results. But these changes won't restore the pre-AI search results. Search is [shifting toward AI as the primary method](https://www.freshfromcache.com/what-is-an-ai-agent/), and the question for any small site is how to stay visible inside it. Tuesday's changes are Google's first serious move to keep the relationship with small business owners workable. Whether it's enough comes down to the data over the next six months. Joel ## Sources - [Google blog post by VP Hema Budaraju](https://blog.google/products/search/ai-search-updates-may-2026/?ref=freshfromcache.com) (May 6, 2026) - [The Next Web on the publisher click decline data](https://thenextweb.com/news/google-ai-overviews-publisher-links-search-traffic?ref=freshfromcache.com) (May 6, 2026) - [Nieman Journalism Lab on the Subscribed label](https://www.niemanlab.org/2026/05/google-highlights-links-from-subscribed-publications-in-new-ai-overviews-update/?ref=freshfromcache.com) (May 6, 2026) - [Engadget on the Expert Advice section](https://www.engadget.com/2166393/google-ai-search-results-will-now-turn-to-reddit-for-expert-advice/?ref=freshfromcache.com) (May 6, 2026) ### Four steps to fix your printer (and the rule for when to stop) URL: https://www.freshfromcache.com/four-steps-to-fix-your-printer/ Last updated: 2026-08-11T18:29:17.000Z People just don't have the need to print as often as they used to. But every once in a while, you end up needing a nice freshly printed document. Usually for something important. You hit the print button and wipe the dust off your old printer waiting for it to come back to life. But you see "Tray 1 missing," even though there is obviously no missing tray. You tap the screen, hit the buttons, and you hear it roar to life. Then... nothing. You go back to your PC and try another print, because *this* time it'll work. It's alive now. Nothing. You try again. Nothing. Printer error messages have always been cryptic. I'm not sure why. Think back to the PC LOAD LETTER error of *Office Space*. Modern printers have replaced phrases like PC LOAD LETTER with "Tray 1 missing" (which doesn't seem like much of an improvement). Essentially the printer is just putting up a flag saying "I'm unhappy," and it's up to you or your friendly IT person to figure out why. ## A rule before you start Below is a list of some easy troubleshooting steps to take that will clear up many of the most common issues. If you have a printer that isn't working right, and you aren't sure why, try these steps in order. Try each step only once. If you keep trying print jobs and rebooting, you are likely wasting your time. If the first print or reboot doesn't work, it's unlikely to work on the second. Also a quick note: if you have your printer connected to your computer via Wi-Fi, any kind of changes to your Wi-Fi password will keep your printer from working. If you got a new Wi-Fi router (and even kept your SSID and password the same), you may still need to reconnect your printer. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/printer-triage-diagram-format-original.png) ## Step 1: Clear the print queue This is the move that fixes the most printer problems for the least effort. Open your computer's printers list (Settings, Bluetooth & devices, Printers & scanners on Windows; System Settings, Printers & Scanners on Mac), pick your printer, and open its queue. If there are old jobs sitting there, cancel them all. Two things this does. First, an old stuck job can block everything behind it, including the print job you just sent. Cancelling the old jobs unblocks the queue. Second, if you've already hit print eight times trying to make this work, those eight jobs are now stacked up. Clear them now or you'll print eight copies of your contract the moment you fix the actual problem. Try printing again. If it works, you're done. ## Step 2: Reboot the printer Power it off. Unplug it. Wait 30 seconds. Plug it back in. Power it on. The 30-second wait matters. A quick off-and-on doesn't fully clear the printer's memory. The capacitors inside need a moment to discharge before the internal state actually resets. This is the difference between a reboot and a flicker. A reboot fixes a surprising number of things: stuck network connections, pending firmware updates that needed a restart to apply, cached jobs the printer thought it was still working on, and the general weirdness of a device that's been running for three months without being turned off. Try printing again. ## Step 3: Remove and re-add the printer on your computer This sounds like a big move and it isn't. In your printers list, find your printer, hit "remove device" (or the equivalent on Mac), then hit "add a printer" and let your computer find it again. What this fixes: a corrupted driver, the printer being set to "paused" or "use printer offline" without you knowing, the wrong printer being set as default (very common when you have a "Microsoft Print to PDF" entry sitting at the top of the list), and any Wi-Fi mismatch that crept in after a network change. Adding the printer back forces a fresh handshake. The computer and printer rediscover each other from scratch. If your printer is wireless and your computer can't find it during the re-add, that's your sign [you have a network problem](https://www.freshfromcache.com/why-does-rebooting-your-router-work/). The printer and the computer have to be on the same Wi-Fi network. Many homes broadcast a 2.4 GHz and a 5 GHz network with different names, plus sometimes a guest network. The printer can only be on one. Your computer needs to be on the same one. ## Step 4: Print a test page directly from the printer Every home printer made in the last decade can print a test page or "configuration sheet" without a computer involved. Usually it's a button-hold sequence on the front panel, or a menu option labeled Reports, Setup, or Maintenance. If you can't find it, search "\[your printer model\] print test page" and the manufacturer will tell you exactly which buttons to push. This is a diagnostic step, not a fix attempt. It tells you where the problem actually lives. If the test page prints, your printer is fine. The problem is in the connection between your computer and the printer (driver, network, software). The four steps you've already run will have fixed most of those, so if you're still stuck, you're past the 90-second window. If the test page doesn't print, your printer has a hardware or supply problem. Out of paper, low ink or toner, a paper jam, or dead. This usually shows on the printer's display panel, but not always. ## When to stop trying If those four steps didn't fix it, you have two options. You can spend the next hour or so doing what an IT person would do: driver reinstalls, firmware updates, manufacturer support tools, and decoding error codes the printer hasn't bothered to explain. If you actually like printers, this can be satisfying. If you don't, it's an hour you'll never get back. Or you can replace the printer. For a small business that prints maybe once a week, replacing it is almost always the right call. A basic black-and-white laser printer runs around $150 to $200\. It will print fine for years. It does not care if you ignore it for six months between print jobs. Inkjets are the opposite. They degrade when they sit unused. The ink in the cartridges dries out, the nozzles clog up, and the printer eventually starts telling you the cartridge is "low" when it's actually full of ink that just can't get out. Every month an inkjet sits, you lose a little more print head function. If you barely print, an inkjet is the worst kind of printer to own. A laser printer doesn't have this problem because toner is a powder, not a liquid. It doesn't dry out. If your printer is more than five years old and you're staring at it after running through these steps, that's your likely answer. At that age, the math of fixing it versus buying a new one almost always says buy a new one. You aren't an IT person, and you don't have to be. ## What to skip A few things that look like fixes and aren't. **Don't replace cartridges as your first move on an inkjet.** A printer that's been sitting has dried-out nozzles, not empty cartridges. The new $40 cartridge will not fix it. Run a printhead clean cycle from the printer's menu first. If two cycles don't fix the streaks, a third won't either, and you're now wasting ink trying. **Don't try to decode error codes on your own.** If your printer shows something like "E5" or "0xC19A," [don't guess at what it means](https://www.freshfromcache.com/copy-text-from-a-photo/). Search "\[your model\] error E5" and the manufacturer will tell you in ten seconds. Looking it up is fast and worth doing. Guessing isn't. **Don't keep hitting print.** Eight failed print jobs is eight items in the queue you'll have to clear later. Plus you're spending energy that could be going toward step 1. ## One last thing Printers suck. I think *most* IT people would agree. We don't like dealing with them. Which means non-IT people *really* hate dealing with them. But printers are just machines that are trying to turn digital information into a physical item. It's not as easy as it sounds under the hood. Which makes them unpredictable at times. But time has shown these steps are a great start to troubleshooting your printer problems before having to call in the IT cavalry. Bonus: if you do end up calling someone, you'll impress your IT person with your excellent troubleshooting steps! If you've found a fix these four steps didn't cover, I'd like to hear about it. Joel [joel@freshfromcache.com](mailto:joel@freshfromcache.com) ### Fake face. Real money. URL: https://www.freshfromcache.com/fake-face-real-money/ Last updated: 2026-08-11T18:28:46.000Z A reporter at 404 Media got on a Microsoft Teams call recently and [watched his own face appear on someone else](https://www.freshfromcache.com/how-to-get-a-deepfake-taken-down/), in real time. The face moved when the other person moved. Lighting changes held. Expressions tracked. The software is designed and sold for impersonation scams, and it works as advertised. This is the engine behind a wave of business impersonation scams hitting small businesses, nonprofits, and large companies. The face you see on a video call is no longer evidence of who you're talking to. A 404 Media reporter tested the deepfake software in a controlled call. The setup is consumer-grade: off-the-shelf laptop, the deepfake tool layered over a normal video conferencing app, and a target face the software has been trained on. The tool is sold openly on Chinese-language messaging channels, with marketing aimed at scammers. It's a commercial product anybody can buy. The illusion held. The face stayed locked to the speaker through head turns, expression changes, even shifts in room lighting that would normally reveal a fake. There were small artifacts if you knew what to look for, but over a video call people have their guard down. The face was a lie, the conversation was real. Business email compromise, or BEC, is the long-running scam where someone impersonates a person you trust (your boss, a vendor, a client) to move money or access where it shouldn't go. The FBI has tracked it for years. Every year it costs US businesses billions. Each generation of the scam has trained us on a new verification habit. Email scams taught us to verify the sender. Voice phishing taught us to call back to a known number. Video calls used to be the layer that ended the chain, because seeing someone's face was honest evidence of who they were. That layer is no more. A few years back, when I started a new leadership job, my LinkedIn title updated and the texts started the same week. They opened with the executive director's name and a "hey." Familiar and casual. The number wasn't saved in my phone, but I was new, didn't know yet what was normal, and the executive director texting me felt plausible. I replied asking what they need. I expected an IT request. The pivot was gift cards for a client, urgent, stuck in a meeting. That's where it fell apart. The opener got my attention. The request gave it away. The scam worked because of social pressure. New employee, polite culture, perceived hierarchy. All pushing the same direction. A deepfake video call is the same scam with one fewer red flag. The asker now looks and sounds right, holds eye contact. The only honest signal left is the request itself. **What to do** - **Adopt a callback rule for money or access.** Any wire transfer, payroll change, vendor banking update, or credentials request that comes through video, voice, or chat gets a callback to a known number before it moves. Known number means saved in your phone before the request happened, not whatever number is on the email signature. - **Make the awkwardness routine.** "Can you confirm via text" or "I'm going to call you back at the office number" should feel normal coming from anyone in the company. Train the team to expect it from each other. The point is to remove the social cost of pausing. - **Push the policy down from the top.** It can't be the bookkeeper's job to figure out whether challenging the boss is allowed. Make it the manager's job to require the callback, and put it in writing. The deepfake software is here, and the people building it aren't waiting for permission. The fix is a habit. The companies that get hit will be the ones where asking the boss to prove they *are* the boss felt rude. Joel **Source:**['HELLO BOSS': Inside the Chinese Realtime Deepfake Software Powering Scams Around the World](https://www.404media.co/hello-boss-inside-the-chinese-realtime-deepfake-software-powering-scams-around-the-world/?ref=freshfromcache.com), 404 Media. ### A third of new websites are AI-generated. A Stanford study explains what changed. URL: https://www.freshfromcache.com/a-third-of-new-websites-are-ai-generated/ Last updated: 2026-08-11T18:29:08.000Z Researchers from Stanford, Imperial College London, and the Internet Archive sampled the web for 33 months and found that by mid-2025, roughly 35% of newly published websites were classified as AI-generated or AI-assisted. That number was zero before ChatGPT launched in late 2022\. Three years to remake a third of the public-facing internet. The headline number is the easy part. The team also tested six common worries about what AI text was doing to the web. Only two held up. Their setup: pull archived snapshots month by month from the Wayback Machine, run the text through Pangram v3 (an AI detector that scores writing as human-written or machine-written), and give each hypothesis a measurable signal. The signals: writing turning sanitized and cheerful, citations dropping out, facts getting hallucinated more often, viewpoints narrowing, the web sliding into one uniform style, or semantic density (roughly, meaning per word) collapsing into word soup. Two findings survived: the web is getting more positive in tone, and semantic diversity (the range of distinct ideas covered) is shrinking. AI text covers a narrower band of any given topic than human writing did. The four the data didn't support are the more interesting result. AI text wasn't more likely to contain false claims (the team paid human fact-checkers, which is the gold standard). It wasn't dropping source links. It wasn't producing low-density word soup. The stylistic monoculture worry came back without statistically significant evidence. What makes this more solid than the average press release is the controls: Wayback Machine snapshots so content didn't shift between sample and analysis, a named detector tested against alternatives, and human fact-checkers rather than one AI grading another. The trend lines are large enough that ordinary detection error doesn't change the direction. **Here's what this means.** I use these tools every day. They save me real time. So when I read this paper, the part that landed wasn't the 35% number. It was a finding tucked into the back half: the team surveyed US adults and found most believed AI was harming the web on dimensions the data couldn't confirm. People who don't use AI believed it most. People who use it daily believed it least. That's awkward, and honest. The loudest worry about AI on the internet (that it's drowning the web in confident lies) is loudest among people with the least direct experience of how AI text actually shows up. What the data did show is quieter: the web got blander and more agreeable. The thing AI is best at is producing copy that doesn't hurt to read, doesn't claim things it can't back up, and has no edges. That's a real change worth noticing. The warning we were given was about something else. For a small business owner reading reviews or comparing tools, the practical effect is that the surface signals you used to spot quality (clean grammar, polished About page, confident tone, citations) don't separate the useful from the bland anymore. Everyone's grammar is fine now. Everyone sounds upbeat. [The signal got swallowed](https://www.freshfromcache.com/fake-face-real-money/). **What to do.** - **Read for friction.** A useful page has specific names, specific complaints, opinions someone actually disagreed with, and details only a practitioner would know. Pleasant positivity is the new spam. - **Click the citations.** AI keeps its sources, the paper says, but doesn't always read them well. Open one and check whether it actually supports the claim above it. - **Ask for a real example.** When a recommendation has no downside or trade-off in it, treat it as marketing. - **For your own site: keep your edges.** Writing that says "this didn't work for us" or "we charged $X and it took Y hours" reads as human in a way it didn't have to before. Don't sand it off. This is one paper, one detector, one slice of the web (newly published sites). "AI-generated" includes drafts a human edited carefully and drafts nobody touched, and the paper can't separate them. I do it myself. But the overall finding holds. The web is changing fast, and the changes worth worrying about are not the ones we were warned about. **Source:** [Study Finds A Third of New Websites are AI-Generated](https://www.404media.co/study-finds-a-third-of-new-websites-are-ai-generated/?ref=freshfromcache.com), 404 Media **The paper:** [The Impact of AI-Generated Text on the Internet](https://ai-on-the-internet.github.io/?ref=freshfromcache.com) (Dolezal, Alam, Graham, Bohacek; arXiv 2604.26965) ### I Can’t Let You Save That, Dave: The AI Hard Drive Hostage Crisis URL: https://www.freshfromcache.com/i-cant-let-you-save-that-dave/ Last updated: 2026-08-11T18:29:15.000Z The AI data center boom has bought up enough storage to break the market for everyone else. Western Digital, one of the biggest hard drive makers, has sold out its entire 2026 enterprise inventory. Micron, the parent company of Crucial, just quit the consumer SSD market entirely. The Internet Archive can't find the 28-to-30 terabyte drives it depends on, and the ones it can find are priced out of reach. A 2 TB Samsung SSD that ran $159 last fall now sells for around $575. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-stat-news-storage-format-original.png) That's what AI infrastructure looks like as a cost everyone else pays. Hard drive and SSD makers can only build so many drives in a year. When AI hyperscalers (the companies behind ChatGPT, Gemini, Copilot, and the rest) started ordering at the scale they needed, they crowded everyone else out. Samsung and SK hynix have warned the shortage might run through 2027 and beyond. Big Tech's capital spending on data centers is on track to hit $725 billion this year, up 77 percent from 2025. Brewster Kahle, who runs the Internet Archive, told 404 Media the drives the archive needs "are just not available or at very high price." The Internet Archive adds 100 terabytes of new material every day on top of more than 210 petabytes already archived. Every drive it can't get is content it can't preserve. The Wikimedia Foundation, which runs Wikipedia, said costs have been climbing since late 2025\. They're stretching hardware life and adjusting purchase plans. A University of North Texas team that archives federal websites between presidential administrations had to rethink server capacity after a planned refresh came back with much higher RAM and SSD prices. Hetzner, a German data center company that hosts a lot of small-business workloads, raised prices up to 37 percent on April 1\. Myrient, an online archive holding 390 terabytes of video games, shut down March 31, 2026\. Storage costs were one of the reasons the founder cited. The libraries, archives, small businesses, and nonprofits that use the same drives are picking up the difference. For a small business or nonprofit, this lands in three places: 1. **Backups got more expensive.** The drives in your NAS or backup server cost more, and the lead times are longer. 2. **New hardware refreshes feel it on the SSD line.** Laptop, server, or workstation upgrades will run higher than they did last year. 3. **Cloud storage takes the hit too.** The same shortage hits cloud providers, and they pass it on. If you're planning storage purchases or backups in the next year: - **Buy storage you've been delaying.** Prices probably [aren't coming back to 2024 levels](https://www.freshfromcache.com/why-your-next-phone-costs-more/). - **Stretch what you have.** Hardware that's still working can keep working. Squeeze more life from existing drives before replacing them. - **Get your backup strategy in writing.**[If you're not sure what your backups even cover](https://www.freshfromcache.com/do-you-need-backups/), find out before storage gets harder to budget for. - **Talk to your IT or MSP about lead times.** Order what you'll need this year now, not in October. My backup drive doubled in price last year because somebody bought a hundred thousand of them for a model nobody asked for. The AI buildout gets paid for in pieces. Small businesses, nonprofits, libraries, and archives are paying some of those pieces. **Source:**[404 Media on the AI hard drive shortage](https://www.404media.co/the-ai-hard-drive-shortage-is-making-it-more-expensive-and-harder-to-archive-the-internet/?ref=freshfromcache.com) **Background:**[Tom's Hardware on the Myrient archive shutdown](https://www.tomshardware.com/video-games/390tb-video-game-archive-being-taken-offline-due-to-skyrocketing-ram-ssd-and-hard-drive-prices-ai-driven-supply-squeeze-results-in-closure-of-one-of-the-largest-online-video-game-archives?ref=freshfromcache.com) ### The big ChatGPT-in-education study just got retracted. URL: https://www.freshfromcache.com/chatgpt-retracted/ Last updated: 2026-07-31T20:56:37.000Z Springer Nature pulled a meta-analysis last month that claimed ChatGPT helps students learn. The paper had been cited hundreds of times. It was a year old. The journal said discrepancies in the analysis undermined their confidence in the findings. The authors didn't respond to the journal's correspondence about the retraction. By the time the retraction went up, the original paper had nearly 10,000 reads and a 382 Altmetric score, which is a rough measure of how much a paper bounces around the press, social media, and policy circles. That's a year of being treated as evidence. The retracted paper is a meta-analysis, meaning the authors didn't run a new study. They combined the results of 51 existing studies on ChatGPT in education, run between November 2022 and February 2025, and produced a single number for each outcome. They reported a large positive effect on learning performance and moderate effects on learning perception and higher-order thinking. Meta-analyses are useful when they're done well. They smooth out the noise of any single study. They're also easy to break. A retraction means the journal pulled the paper outright. The paper still exists on the publisher's site, but it's now stamped RETRACTED. The retraction notice doesn't list specific errors. The editors say they found discrepancies in the meta-analysis and lost confidence in the analysis and its conclusions. They also note that the authors didn't respond to correspondence about the retraction. That last detail lingers. When a journal tells two researchers they're pulling their year-old paper because the math doesn't hold up, and the researchers go quiet, that's not a small thing. Springer Nature retracts papers all the time. What stands out here is the velocity. The paper went up in May 2025 and came down in April 2026\. In that year, it showed up in a lot of AI-in-education pitches. School districts cited it. Vendors cited it. By the time the editors pulled it down, the paper had already done the work somebody wanted it to do. The gap between when a study is published and when the field has had a chance to vet it is where most of the AI-research credibility problems live. Peer review is slow. The hype cycle isn't. If a vendor or a board sent you a deck quoting "studies show ChatGPT improves learning outcomes," that line might have been resting on this exact paper. The retraction doesn't mean ChatGPT is useless, or that every study in the field is bad. It means a citation in a vendor deck is sales material. Treat it that way. How often a paper gets cited tells you it got around. Not whether it holds up. I [wrote about this from a different angle on Sunday](https://www.freshfromcache.com/friendly-ai-is-less-accurate/), when an Oxford team showed that making AI models friendlier made them less accurate. Different mechanism, same lesson. AI marketing is moving faster than the research it leans on. If a vendor cites a study while pitching you AI: - **Ask who paid for the study.** If the company selling the product also funded the research, you need a second opinion before you act on it. - **Search Retraction Watch.** It's a free site. Thirty seconds tells you whether the study still counts. - **One study isn't enough.** A real finding gets confirmed by other research groups doing the same kind of work. Treat anything that rests on a single paper as a maybe. **Ask for the link.** "Studies show" without an actual citation is sales talk. If they can't point you to the paper, they don't have one. I use AI tools daily and [they save me real time](https://www.freshfromcache.com/boring-ai-advice/). Heavily cited and true are different things, and the vendors selling you AI are counting on you to forget the difference. Salespeople are still quoting this study. Sales decks don't get retraction-notices. **Source:** Ars Technica [covered the retraction](https://arstechnica.com/ai/2026/05/influential-study-touting-chatgpt-in-education-retracted-over-red-flags/?ref=freshfromcache.com). **The retraction:** Springer Nature's [official retraction notice](https://www.nature.com/articles/s41599-026-07310-z?ref=freshfromcache.com) (Wang & Fan, *Humanities and Social Sciences Communications*, 2025). ### Canvas got breached. Again. URL: https://www.freshfromcache.com/canvas-got-breached-again/ Last updated: 2026-08-11T18:28:43.000Z Instructure, the company behind the Canvas learning management system used by roughly 7,000 universities and a growing slice of K-12 districts nationwide, confirmed a data breach this weekend. The extortion group ShinyHunters claims they took 3.65 terabytes of data covering 275 million students, teachers, and staff across nearly 9,000 schools, plus billions of private messages. Instructure has confirmed the breach but not the scale. Most outlets are leading with the line that no passwords were stolen. That framing is doing a lot of misleading work. Here's the timeline, from Instructure's own status page. April 30, "limited disruption to tools relying on API keys." May 1, CISO Steve Proud publicly confirmed a "cybersecurity incident perpetrated by a criminal threat actor." May 2, contained. May 3, ShinyHunters listed Instructure on their leak site (the public extortion page criminals use to pressure victims) with sample data that DataBreaches.net reports appears to confirm the claim. One sample file alone listed more than 7,700 institutions. What Instructure says was taken: names, institutional email addresses, student ID numbers, and the contents of messages between Canvas users. What Instructure says was not taken: passwords, dates of birth, government identifiers, financial information. The second list is the consolation prize. The first list is the prize. This is the second confirmed Canvas breach in eight months. September 2025 hit Instructure's Salesforce instance, also attributed to ShinyHunters. PowerSchool lost data on roughly 62 million students in January 2025 and settled for $17.25 million. Infinite Campus disclosed a Salesforce-related theft in March 2026\. The vendors are different. The pattern is not. One SaaS company holding records on tens of millions of students across thousands of districts gets compromised, and every one of those districts inherits the breach simultaneously. **Here's what this means.** A list of real names paired with verified institutional email addresses is not "metadata." It's the input that turns a generic phishing email into one that names your kid's actual professor, the actual class, and the assignment that was actually submitted last week. The breach itself is over. The phishing wave it enables is what most of us will actually have to navigate. Plan on a 60 to 90 day window of "your Canvas access expired" emails and fake "new message from your professor" prompts. The first one is easy to spot. The thread reply that lands 48 hours later, in the same conversational tone, with the right names attached, is the one that gets people. That is the part "no passwords" is hiding. I would rather a school district told me "this is what's coming" than "your password is safe." **What to do this week:** - **Treat any "Canvas" email as suspicious through summer.** Verify by typing canvas.yourschool.edu directly into the browser. Don't click email links. - [**Rotate the password Canvas signs in with**](https://www.freshfromcache.com/start-using-a-password-manager/)**.** Even if Instructure says it wasn't taken. Ninety seconds. - **Turn on a hardware key or passkey if your school offers it.** Phishing-resistant MFA (multi-factor authentication that doesn't break under a real-time relay attack) is the only category that survives this kind of campaign. - **Parents of K-12 kids: ask your district when breach notification is coming.** The updated COPPA rule that took effect April 22 tightened the clock. - **School IT admins: rotate every Canvas API key on your tenant.** Instructure rotated theirs. Yours are yours. Instructure's own response was actually fast: containment in about 36 hours, transparent CISO updates, application keys rotated. The problem isn't this vendor. It's that one company holding 275 million people's records means a very bad day cascades across 9,000 schools at once. **Source:** BleepingComputer, "Instructure confirms data breach, ShinyHunters claims attack," May 3, 2026\. [https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/](https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/?ref=freshfromcache.com) **Background:** BleepingComputer, "Edu tech firm Instructure discloses cyber incident, probes impact," May 1, 2026\. [https://www.bleepingcomputer.com/news/security/edu-tech-firm-instructure-discloses-cyber-incident-probes-impact/](https://www.bleepingcomputer.com/news/security/edu-tech-firm-instructure-discloses-cyber-incident-probes-impact/?ref=freshfromcache.com) ### Boring AI Advice: Five Practical Uses for Your Business or Career URL: https://www.freshfromcache.com/boring-ai-advice/ Last updated: 2026-08-11T18:29:04.000Z There's a policy document I needed to put together not long ago. Nothing fancy. A clean layout, a professional look, the kind of thing that says "this person knows what they're doing" before anyone reads a word. I knew exactly what I wanted to say. Getting it to look right was a different problem entirely. I've used Word and Excel for years the way most people do, just enough to get through whatever I had to get through. In IT, you don't *always* live in those types of applications. You use them when you have to. Because of that, I've never been good at the design aspect of documents. Color theory, layout, spacing, whatever makes something look clean instead of thrown together, that was never my world. So I thought I'd give it a try with AI. I described what I needed. Not vaguely. In detail. I told it what the document was for, who would read it, what tone I wanted, what I was trying to communicate before anyone got to the content. And it produced a clean-looking doc any department would be proud of. That's when things started to click. You've probably played 20 Questions. Someone thinks of something, you ask yes or no questions, and if you're good at it, you narrow it down fast. The whole game depends on asking the right questions in the right order. In a way, it's kind of amazing. AI works like that game, but in reverse. Instead of you asking the questions, the AI is trying to figure out what you need. And just like 20 Questions, the more detail you give it, the faster it gets there. Type two vague sentences and you'll get a generic answer that doesn't quite fit. Give it context, tell it who you are, what you're trying to do, who's going to see the result, and what matters most, and it starts to feel less like a search engine and more like someone who actually understands what you want. \[caption id="" align="alignnone" width="1200"\] ![ The more detail you give, the better it gets. ](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-20questions-diagram-format-original.png) The more detail you give, the better it gets. \[/caption\] Some people who try AI for the first time and walk away unimpressed made one mistake: they didn't give it enough to work with. That's not a knock on them. It's not immediately clear what to do. You open the app, type something, and expect it to just know. But it doesn't. It needs the 20 questions worth of detail. Here's something worth knowing before you dive in. Most AI tools let you set standing instructions, a set of filters that apply to every conversation before it even starts. One of the most useful things you can put in those instructions: tell the AI that whenever it's about to guess at something, it should stop and ask you clarifying questions first. That one change turns a guessing game into a real back-and-forth. It's the difference between an AI that produces something generic and one that produces what you are asking for. Whether you're just getting started, trying to keep up with your own growth, or just looking to get some time back, the tips below are for you. And the best part: most of them are free. One thing before we start. Most free AI tools may use what you type to improve their models. Don't paste anything sensitive, client financial details, account numbers, confidential agreements, into a free tier. Most paid tiers run $15 to $20 a month if you need that protection regularly. That's the only warning. Now for the good stuff. ## Start Here These five things work today, for free or close to it, no setup required. ## 1\. Voice memo to clean email How many times have you thought of exactly what you wanted to say, at exactly the wrong time? Driving, walking around the office, halfway through an entirely different task. By the time you sit down to write the email, the thought is gone or the moment has passed. Poof. Here's the fix. Record a voice memo on your phone, say everything you want to say in whatever order it comes out, and let AI turn it into a clean email draft. No outline required. No sitting down to write. Just talk. **What you need:** Your phone's built-in voice recorder. iPhone users on iOS 18 or newer get automatic transcription for free inside the Voice Memos app. Android users on a Google Pixel get the same thing inside Recorder. Then either ChatGPT or Claude (both free to start). **How to do it:** 1. Open Voice Memos on your iPhone, or Recorder on your Android. 2. Hit record and say what you want the email to cover. Don't worry about order or wording. Just brain dump. 3. Stop the recording when you're done. 4. Tap the memo to see the auto-transcribed text. 5. Copy the transcript. 6. Open ChatGPT or Claude in your browser or app. 7. Paste the transcript and type one line above it: "Turn this into a short, friendly email." (or whatever intention you may have) 8. Read the draft, fix anything that sounds off, and paste it into your email. **Warning:** Like most voice to text, the transcript will get names and numbers wrong. Always read the draft before you send it and never trust a dollar amount or date without checking it yourself. ## 2\. Meeting notes that write themselves You know the feeling. A long meeting wraps up, everyone leaves, and within an hour you're trying to remember who said they'd handle what. By the end of the day it's a blur. If it's Friday, it's gone. AI meeting notes solve this completely. The tool records your call, transcribes it, and when it's over hands you a summary and a bulleted list of action items with owners assigned. Not a wall of text. Actual, usable notes. You can revisit the whole conversation at your own pace, catch what you missed, and respond thoughtfully instead of on the spot. **What you need:** Fathom (fathom.video), free for up to 5 AI summaries per month. Works with Zoom, Google Meet, and Teams. If you need more than 5 summaries a month, Premium is $16 a month billed annually. If you're already using Microsoft Teams at work, check whether your plan includes Copilot or Teams Premium. If it does, you already have this built in. One thing to know: Fathom joins your call as a visible participant named "Fathom Notetaker." Everyone on the call can see it. For most internal meetings that's fine. For sensitive client calls, it's worth a heads up beforehand. **How to do it:** 1. Go to fathom.video and sign up with your Google or Microsoft account. 2. Connect the calendar you use for meetings. 3. Start your next call as normal. Fathom joins and records. 4. When the call ends, check your email or the Fathom app for your summary and action items. 5. Copy the action items into your task list or paste them into a follow-up email. **Note:** Always tell the other people on the call that you're recording. Some states require [two-party consent before recording starts](https://www.freshfromcache.com/should-you-let-ai-record-your-doctor-visit/). ## 3\. Client email replies in your own voice Every inbox has one. The email you've read three times. You know exactly what you want to say, but finding the right way to say it is going to take more energy than you have right now. This is one of the most practical things AI does well. Give it the email you received, tell it who you are, the tone you want, what you are trying to say, and it hands you a draft. Not a finished email, but a solid starting point that takes the intimidation out of a blank page. **What you need:** Claude (claude.ai), free to start. Claude is a good default for anything client-adjacent because it handles sensitive context carefully on the free tier. **How to do it:** 1. Go to claude.ai and sign in or create a free account. 2. Copy the email you received from your client. 3. Paste it into Claude. 4. Add three lines underneath: who you are and what you do, the tone you want (friendly, firm, apologetic, professional), and what you actually want to say in rough bullet points. 5. Hit send. 6. Read the draft. If it sounds too formal or generic, tell Claude: "Make it shorter and more conversational." 7. Once it sounds right, copy it into your email reply. 8. Fix any names, dates, or details before you send. **Tip:** Claude doesn't know your recipient. It will fill in gaps with reasonable guesses, and those guesses are sometimes wrong. If you get results that sound wacky, give the AI more context. You can just use plain language. Try explaining what you're trying to do like the AI is a 5 year old. ## 4\. Clean product photos without a studio If you sell anything physical, you might have run into this problem. Your product looks fantastic in person. Your phone photo looks like you took it on a potato. A white background, clean lighting, and a professional presentation is the difference between a product and a Facebook Marketplace post. Hiring a product photographer doesn't make sense for every item. And most of us aren't going to build a lightbox in the garage. Photoroom removes the background from your product photo in seconds and drops in whatever you need. A clean white background for your Etsy or Amazon listing. A simple color that matches your brand. It's not magic, but it's close enough that most people won't know the difference. **What you need:** Photoroom (photoroom.com or the mobile app). The free tier gives you 250 exports per month, but note that Photoroom's free tier is for personal use only, not commercial listings. If you're putting these photos in your shop, you'll need Pro. Pro is $7.50 a month billed annually, or $12.99 month to month. If you just need background removal and nothing else, Pixelcut (pixelcut.com) is a genuinely free alternative with no watermarks and commercial use allowed, though it's primarily a mobile app. **How to do it:** 1. Take a photo of your product on any background. Even lighting helps, so near a window beats a dark corner. 2. Go to photoroom.com or open the Photoroom app. 3. Upload your photo. 4. Photoroom removes the background automatically in a few seconds. 5. Pick a clean white background, or choose a solid color that fits your brand. 6. If the edges look rough anywhere, use the touch-up brush to clean them up. 7. Export and upload to your shop. **Tip:** The AI lifestyle backgrounds, fake wood tables, fake kitchen counters, usually look fake on close inspection. Stick to a plain white or solid color for your primary listing photo. Save the fancy backgrounds for secondary shots if you want to experiment. ## 5\. Getting answers from a long document Some documents are just not meant to be read by humans. Equipment manuals. Vendor contracts. Insurance policies. Lease agreements. You get it. You'll need one specific piece of information and the only way to get it is to dig through sixty pages of language that seems specifically designed to make you sleep. AI can read it for you. Upload the document, ask your question in plain language, and get the answer pulled directly from the text. No searching, no skimming, no reading the same paragraph four times trying to figure out what it actually means. **What you need:** Google Gemini (gemini.google.com), free with a Google account. Gemini handles long document uploads well on the free tier, which makes it a good default for this. **How to do it:** 1. Go to gemini.google.com and sign in with your Google account. 2. Click the paperclip icon to attach a file. 3. Upload your document. PDFs work well. 4. Type your question in plain English. "What does this say about cancellation fees?" or "What are my obligations if I want to end this early?" works just fine. 5. Read the answer. Gemini will reference the part of the document it pulled from. 6. Go find that section in the original document and confirm it yourself before you act on it. **Warning:** AI tools will sometimes give you a confident answer that isn't actually in the document. Always go back to the original and verify before making any decision that has legal, financial, or contractual weight. Use this to find the section faster, not to replace reading it. [We've actually written about this.](https://www.freshfromcache.com/friendly-ai-is-less-accurate/) ## One More Thing Before you go download six apps and sign up for four free trials, one more thing. There is a whole slew of companies dedicated to selling you a stack of AI tools you don't need. Twelve subscriptions, each solving a slightly different version of the same problem, none of them talking to each other, all of them billing you monthly. Most people who try to build an AI workflow give up within a few months, not because AI doesn't work, but because they collected tools instead of actually using them. The best way to know what kind of AI tools will help your business is to just start. Pick a tool from this list and give it a try. They all work the same way underneath. Using plain language, you can finally tell your computer what you want it to do. And it generally does it. And here's something I didn't expect. The more I used it, the more I learned. Not because I was studying, but because explaining what I needed forced me to understand it better myself. The more I tried to write better prompts, the more I actually learned about the thing I was asking for help with. If you try one of these and it clicks, I'd love to hear which one. And if you've already been using AI in your business in a way I didn't cover here, tell me about it. I'm always interested in hearing real world examples. *There is a part two.* [*AI tips for people who don't want to get left behind*](https://www.freshfromcache.com/ai-tips-for-everyday-people/) *picks up where this one stops: the habits that make AI worth using, and why each one works.* Joel · [joel@freshfromcache.com](mailto:joel@freshfromcache.com) ### Friendly AI is less accurate. A new Oxford study explains why. URL: https://www.freshfromcache.com/friendly-ai-is-less-accurate/ Last updated: 2026-08-11T18:28:26.000Z If you've ever asked ChatGPT, Copilot, or Claude for a second opinion on something and walked away feeling a little too validated, there's now a peer-reviewed reason for that. A new study from the Oxford Internet Institute, published in *Nature* this week, found that AI tools tuned to sound warm and friendly are between 10 and 30 percent more likely to make factual errors, and roughly 40 percent more likely to agree with you when you're flat wrong. The effect is strongest when you tell the AI you're feeling stressed, sad, or worried. The researchers took five widely used AI models, including OpenAI's GPT-4o and Meta's Llama, and ran them through a process the industry calls fine-tuning. That's the step where a company takes a working AI model and nudges its responses toward whatever tone or behavior they want. Want a chatbot that sounds professional? You fine-tune it on professional examples. Want one that sounds like a supportive friend? You fine-tune it on warm, empathetic conversations. The Oxford team did the second one on purpose, ending up with two versions of every model: one original, one extra friendly. Then they generated and evaluated more than 400,000 responses across medical advice, factual questions, and conspiracy theories. What changed was the truth. The warm-tuned models weren't just a little less accurate. They were a lot less accurate, and the gap got worse the moment a user signaled vulnerability. Ask a chatbot a medical question in neutral language and you'd get one quality of answer. Tell that same chatbot you've been feeling really down lately, and the warm version was much more likely to confirm whatever you thought was true, even when it wasn't. This is what AI researchers call sycophancy: the tendency to agree with the person you're talking to, even when they're wrong. It's a known issue. What the Oxford study did differently was put hard numbers on how much worse sycophancy gets when you specifically train a model to be warm. The team also did something clever to make sure the finding wasn't a fluke. They ran a control group: same five models, but trained to sound colder and more distant instead of warmer. The cold models came out as accurate as the originals. So it isn't that any tone change breaks the model. It's warmth, specifically, that makes the model start agreeing with you. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-news-01-paper-figure2-format-original.png) Here's why this matters outside the lab. Almost every consumer AI tool you've used (ChatGPT, Microsoft Copilot, Google Gemini, Claude, the various Meta assistants) has been deliberately tuned to sound warm and friendly. That's what people prefer in a chatbot, and it's what the companies build for. Which means the same dynamic the Oxford study isolated is, in some form, sitting inside the tools you're already using. If you've ever leaned on an AI for a second opinion, a sanity check, or a shortcut to information you didn't want to look up the long way... it's worth taking the finding seriously. The tool you're talking to is, by design, more interested in keeping the conversation pleasant than in correcting you. Polite to a fault. And the Oxford study suggests "to a fault" is closer to literal than I'd assumed. A few things I'd suggest taking from this: - **Be skeptical when AI agrees with you.** Especially if you went into the conversation with a strong opinion and came out feeling validated. That's exactly the failure mode the study describes. - **Try asking for the opposite case.** "What's the strongest argument against this?" or "What am I missing?" is a much better prompt than "Am I right?" - **Don't lean on AI when you're already upset.** That's when the warmth dial is doing the most damage. If you're stressed about a medical issue, a financial decision, or anything legal, talk to a human who has actual training in the thing. - **Treat AI confidence as a separate signal from accuracy.** A chatbot can be wrong with real polish. The smoothness of the answer doesn't mean it's right. ![](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/ffc-stat-v2-news-013-format-original.png) None of this means AI tools are useless. I use them daily and they save me real time. It does mean the tone they speak in is part of the product, and tone is doing more work than most people realize. We've got [an FFC explainer on getting useful answers out of AI tools](https://www.freshfromcache.com/ai-tips-for-everyday-people/) coming soon. Until then, the original Oxford paper is open access in *Nature*, and Ars Technica has a solid summary if you want the longer version. **Source:**[Study: AI models that consider user's feeling are more likely to make errors](https://arstechnica.com/ai/2026/05/study-ai-models-that-consider-users-feeling-are-more-likely-to-make-errors/?ref=freshfromcache.com), Ars Technica. **The paper:**[Training language models to be warm can reduce accuracy and increase sycophancy](https://www.nature.com/articles/s41586-026-10410-0?ref=freshfromcache.com). Ibrahim, Hafner & Rocher, Oxford Internet Institute, *Nature*. ### Why I Built This URL: https://www.freshfromcache.com/why-i-built-this/ Last updated: 2026-07-31T20:56:51.000Z My brother recently opened a pressure washing business. One day I asked him how it was going. He said things were picking up, but he really needed to get on Google Business. He had already taken care of the important stuff, got his LLC, his license, set up a way to take payments. But he mentioned wanting a website too, and I got curious and started looking into what that would actually take. That's kind of where this all started. I was genuinely surprised. Not by how hard it was. By how easy it was. Getting a domain. Setting up a professional email. Building a website that doesn't look like it was made in 2003\. Even registering as a business, which I always assumed was a mountain of paperwork, was way easier and cheaper than I ever imagined. I had this picture in my head of starting a business being this big, complicated, expensive thing. It really wasn't. Getting a PlayStation cost me more. Around that same time I had recently read a few books on the behind the scenes of some of the biggest, most well known companies in the world. Billions of dollars, thousands of employees. And reading about how those places actually operated, the decisions that got made, the problems they ran into, it all felt so... human. Messy. Familiar, even. Some of the situations weren't that different from things I deal with at work. Higher stakes, sure. But still. Some of those people running massive companies were figuring it out as they went. Just like everybody else. That was honestly kind of reassuring. So I thought, why not try? I had spent years in IT building skills across the whole stack, and those skills don't require a lot of overhead to put to use. The barrier to entry was way lower than I ever thought. And honestly, as my career has progressed I've become more and more hands off. I didn't want that. I genuinely like working with people on their problems. I like that moment when something gets fixed and you can see the relief on someone's face. I didn't want to lose that. Calmbit became the way for me to still get to do that. Help everyday people with everyday tech problems, and build something I'm genuinely proud of. Fresh From Cache is the same idea in a different form. A place for tech tips, fixes, and plain language explainers on the stuff that can feel confusing or intimidating. Helpful, hopefully a little fun, and written by someone who sees this stuff every day. That's why I decided to start Calmbit and Fresh From Cache. If you've ever thought about building something of your own, maybe now's the time. Joel \[caption id="" align="alignnone" width="1600"\] ![ calmbit.net ](https://storage.ghost.io/c/7f/c4/7fc42d60-e465-4098-9ae3-9930d415307c/content/images/2026/06/calmbit-banner-descriptor-transparent-format-original.png) calmbit.net \[/caption\] *Joel Folgner is the founder of Calmbit, an IT support company based in Molalla, Oregon. Fresh From Cache is where he writes about technology for people who use it every day.* ### A critical Linux vulnerability called CopyFail just went public URL: https://www.freshfromcache.com/a-critical-linux-vulnerability/ Last updated: 2026-07-31T20:56:33.000Z A critical Linux vulnerability called CopyFail just went public, and it is a bad one. A single script works across nearly every version of Linux to give an attacker full administrator access, no malware required. Most Linux distributions had not shipped the patch yet when the exploit code was released. If your business runs Linux servers, web hosting, or network-attached storage, check with your IT provider or vendor right now about the patch status. If you use a managed service, this is a good reason to ask the question today. Link to full story below [https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scrambles/](https://arstechnica.com/security/2026/04/as-the-most-severe-linux-threat-in-years-surfaces-the-world-scrambles/?ref=freshfromcache.com) ### Do you need backups? You might already have them. URL: https://www.freshfromcache.com/do-you-need-backups/ Last updated: 2026-08-21T01:34:09.000Z Woof! I recently was contacted by a dog rescue that lives in my area. She was looking for somebody to look at their computer because it had been "acting funny for a while" and that they had *all* of their important business files on it. They were wondering if I could come rescue it. I was happy to offer my services, but I cringed inside. Imagine losing all those years of hard work! Have you ever lost a wallet or a purse? The pain isn't the lost cash. The pain is the hours of canceling credit cards, trips to the DMV, and the things you use every day. Except when you lose your data you lose invoices, client files, spreadsheets, workflow, and all the different tools you've acquired over the years. Luckily, you might already have what you need. And if you don't, you can start for free. Doing this for a home computer rather than a business? There is a printable card for that: two pages covering what to back up and the exact clicks for Windows and Mac. [Download the card (PDF)](https://www.freshfromcache.com/content/files/2026/08/back-up-your-pc.pdf). It is part of [The Cache](https://www.freshfromcache.com/cache/), our free library of printable guides. A lot of us run our business on Microsoft 365: Word, Excel, Outlook. If that sounds like you, there's a good chance you already have access to OneDrive. OneDrive keeps your files stored in the cloud and even syncs your files to your desktop. So you never have to worry about manually saving anything. If you pay for Microsoft 365 you have up to 1 TB of storage. That's a lot for a small business. If you use Gmail or Google Workspace for your business email, you already have Google Drive, which is very similar to how OneDrive works. If you are still using that @gmail.com email address for your business. Guess what, you still have up to 15 GB of storage! That's plenty for your important files. Have you ever used iCloud or Google Photos to [back up your photos on your phone](https://www.freshfromcache.com/why-is-my-phone-storage-full/)? You are already using the same system that can back up your files. Check that it still says complete, though. A free tier that has filled up stops backing up without saying so. Is your business big enough to have an IT department? No? When you picture a backup system, you might think of a server room. Floor-to-ceiling racks, cables running everywhere, blinking lights, a cold room with a locked door. The kind of setup that needs its own IT staff just to keep the lights on. You're probably picturing a Google server farm. A two-to-ten person office likely doesn't need a rack-based backup system. There is a lot of literature out there talking about amazing and slick backup systems. All kinds of bells and whistles. And those systems *are* cool. But they really just aren't needed for most small businesses. With the amount of space you can get for a low or no cost, you'll have plenty of warning before you have to think about moving to something more specialized. Here are some resources for you if you *do* have a Gmail or Microsoft 365 environment. **Microsoft:** If you have Microsoft 365, you already have OneDrive. Find it in your system tray (bottom right of your screen on Windows), then: 1. Click settings. 2. Find "Back up your folders" under the Sync and backup tab. 3. Make sure Documents and Desktop are selected. Done. You can now access those files from your desktop, a browser, or your phone. Here is the [official Microsoft 365 doc](https://support.microsoft.com/en-us/office/back-up-your-folders-with-onedrive-d61a7930-a6fb-4b95-b28a-6552e77c3057?ref=freshfromcache.com). It's nice if you're a visual person. **Google:** If you have Google Workspace, or even just a @gmail.com address, you already have Google Drive. 1. Install Google Drive for Desktop. 2. Sign in. 3. Choose which folders on your PC you want to sync. Done. Here's [Google's guide](https://support.google.com/drive/answer/10838124?ref=freshfromcache.com). **Mac:** Don't have either, but you're on a Mac? You probably already have iCloud Drive ready to go. 1. Open System Settings, click your name. 2. Click iCloud, then Drive. 3. Turn on "Desktop & Documents Folders." Now you're just as protected as those Windows people. Here's [Apple's guide](https://support.apple.com/en-us/109344?ref=freshfromcache.com). **Starting from zero:** What if you still have that old @hotmail.com handle? Well it might be time to at least move to Gmail. And good news, when you do, you'll have access to 15 GB for free. Now you can back up your important files for your business *and* you can sell that antique Hotmail handle! Once you're set up, follow the Google path above. If you give any of these a try, you may have years of files needing to sync up to the cloud. Give it at least a night to sync up before you call your friendly local IT support. This doesn't work quite as well for certain industries. If you work in healthcare, finance, or you are required by law to protect certain customer data, you will need a more specialized system. Luckily there are cheaper alternatives out there. There are actually cloud-based backup systems. They can be a little more expensive, but you still don't have to invest in a server farm. A few examples would be if you work with large amounts of files (think videos, high quality photos, etc). You will eventually outgrow these options. If you are running a server or business software that has a database, point of sale systems, stuff like that, it's also a different setup. A good rule of thumb, if you couldn't wait a week for your business documents to be restored, then you might want to look into something more elaborate to protect your business. And if you are one of those businesses and you are reading this... I urge you to go look into those options right now! [File sync is not truly a backup system](https://www.freshfromcache.com/windows-point-in-time-restore/). It's fantastic technology that fills the gap and gives small businesses the chance to hold off until they have grown enough to need something more complex. Got questions about any of this? Send a note to [joel@freshfromcache.com](mailto:joel@freshfromcache.com). New posts also go out through the newsletter. Sign up at freshfromcache.com if you want them in your inbox. Thanks for reading. Joel - *Fresh From Cache*