Today in Surveillance:

  • Police logged LMAO, idk, and asdfg as the reason for thousands of Flock license-plate searches. EFF and 404 Media each analyzed Flock Safety ALPR audit logs obtained via public-records requests. EFF found a Goshen, Indiana officer who on May 7, 2025 searched across 6,474 ALPR networks covering 82,413 cameras, and 30+ agencies that ran more than 6,300 searches marked "TBD." 404 Media found a Lake County, Indiana cop who searched across 19,000+ cameras in 1,558 cities and towns with "LMAO" as the stated reason [1][2].
  • 404 Media documented OpenAI's "Project Lily" human-reviewer pipeline. OpenAI is "hiring hundreds of contractors" to read a stream of real users' ChatGPT prompts, with ChatGPT now claiming more than 900 million users. Anthropic separately confirmed to 404 Media it uses human review to improve its models too [3].
  • Manhattan DA Alvin Bragg seized 12 celebrity deepfake sites exposing roughly 1,200 victims. The seizures used New York's deepfake criminal statute, in place since 2023. Bragg declined to confirm whether any images of minors were included [4].
  • The UK is rolling passkeys out to 23 million gov users via GOV.UK One Login. Digital Government Minister Stephanie Peacock framed it as faster and more secure than passwords and SMS 2FA. The trial covered more than 300,000 users, and roughly 10% of daily One Login sign-ins are already using passkeys [5].
  • EFF: Governor Newsom signed a 12-bill package including the contested AB 1709. EFF supported AB 2071 (digital wellness in schools) and AB 2298 (cybersecurity curriculum), and opposed AB 1709, which it calls a functional ban on social media for youth under 16 [6].
  • Researchers showed a hardware interposer can break DDR5 memory encryption. The device, demonstrated against Intel TDX, Intel Scalable SGX, and AMD SEV-SNP, forces a protected VM into debug mode and reads out private memory in plaintext. Intel and AMD told The Register the attack is out of scope for their cloud threat models and no mitigation is planned [7].
  • A long public rebuttal landed against Dario Amodei's "We Must Pace the Frontier" essay. The POP RDI post criticizes Amodei's proposal to regulate open-weight models, restrict distillation, and seek antitrust exemptions for frontier labs, and draws the parallel to the 1990s crypto wars [8].
  • China's intelligence minister warned AI threatens party rule. Chen Yixin, secretary of the Ministry of State Security, called AI "the main battleground for global technological competition." The next day the Cyberspace Administration published version 3.0 of its AI Safety Governance Framework [9].

Police Logged LMAO, idk, and asdfg as the Reason for Thousands of Flock Searches

EFF and 404 Media each published analyses of Flock Safety automatic license-plate-reader (ALPR) audit logs obtained via public-records requests, covering 2023 through late 2025. The headline from both outlets is the same: officers logged junk strings as the stated reason for plate-reader queries that pulled data on thousands of vehicles [1][2].

EFF, with co-authors Rindala Alajaji and Dave Maass, found the biggest single day in the audit logs: a Goshen, Indiana police officer who on May 7, 2025 searched across 6,474 ALPR networks covering 82,413 cameras. The same analysis identified 30+ agencies that ran more than 6,300 searches marked "TBD," with Priceville, Alabama alone responsible for 1,954 of them. EFF grouped the junk entries into gibberish, button-mashing, and generic entries ("investigation," "test," blank), and called Flock's later switch to a dropdown reason list "a loss for transparency" [1]. Flock's argument for the dropdown is that a fixed list reduces typing. EFF's argument is that a fixed list kills the searchable paper trail the audit logs used to be.

404 Media's Jason Koebler focused on a different incident. A Lake County, Indiana Sheriff's Department cop searched across 19,000+ cameras in 1,558 cities and towns with "LMAO" as the stated reason. Other logged reasons Koebler found in the audit logs: "idiot," "WEIRD KID," "blah," "leave me alone," "asdfg," "gyghkkghghjkghjk," "jhjhjkhj," "nmbvcbnm," "LOL," "Hehe," "Haha," "idk," "TBD." Fishers PD told 404 Media that one detective was "counseled" for writing "hehe" and "idk," and was "blah"-searching "when he has issues with the technology." Houston officers were told to be "as vague as permissible" about Flock use. EFF's quoted frame: "Mass surveillance is incompatible with a free society." Koebler's quoted frame: the searches were done "for the lols" [2].

The structural point is the one this site has been making since the first ALPR guides. An audit log is a record of what happened, not a control that prevents it. Every entry in the EFF and 404 Media datasets was created at the moment of the search and is recoverable now only because someone filed a public-records request. The 1,558 cities a single Lake County cop could reach with one search is the network effect that makes warrantless national querying the real product, not the local feature. The warrant-requirement bill moving in Colorado, SB 26-070, is the policy answer. The US Surveillance Scoreboard tracks the cities that have already canceled Flock contracts.

EFF: Cops Are Trained Not to Tell Drivers or Courts About the Spy Tech in Their Reports

EFF's Karen Gullo and Adam Schwartz published a companion piece on September 9 documenting departmental policies that direct officers to withhold ALPR, cell-site simulator (Stingray), facial recognition, Hemisphere, and Ring use from the people they encounter and the judges they appear before. The piece compiles department-level training language, court findings, and prior EFF reporting into a single argument that mass-surveillance tools are being treated as evidence-laundering infrastructure [10].

Three of the policy lines EFF cites: "DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE." "DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY." Houston officers told to be "as vague as permissible" about Flock use. A 2015 Baltimore judge found police had used a pen-register order "to intentionally hide its use of a Stingray" from the court. The EFF piece also names Hemisphere, the AT&T-derived phone surveillance product, and characterizes Hemisphere evidence reconstruction as "parallel construction" and "evidence laundering" [10]. This site's cops-hide companion piece tracks the same training language and the prior Stingray case law.

Read against the LMAO audit logs, the two EFF pieces form a single story. The LMAO searches are what officers do when they think no one is looking. The "DO NOT MENTION" lines are what departments tell officers to write in their reports when someone does look. The same Flock network that logs "asdfg" as a reason is the network the Houston officer is told to describe as "county resources." This is the structure the LMAO logs make visible at scale, and it is the structure the federal car-surveillance mandate would lock in if the rule lands as drafted.

404 Media: Inside "Project Lily," the Humans Reading Your ChatGPT Chats

404 Media's Joseph Cox reported on September 14 that OpenAI is running a large-scale human-review pipeline under the internal name "Project Lily," with the company "hiring hundreds of contractors" to read a stream of real users' ChatGPT prompts. ChatGPT now claims more than 900 million users, which sets the scale. The reviewers see full conversation prompts with usernames redacted and rate or critique the model's replies. OpenAI told 404 Media the program is intended to train the model to "not anthropomorphize itself" and "be less sycophantic." OpenAI also said it tries to remove personal information before prompts reach reviewers, but acknowledged sensitive details can still get through. Anthropic separately confirmed to 404 Media it is also using human review to improve its models [3].

The contractor quoted in Cox's piece captures the consent problem in one sentence: "I don't think they would imagine some contractor somewhere [...] is analyzing the conversations" [3]. The relevant privacy law context, the Canada privacy commissioners' finding that OpenAI's ChatGPT collection violated Canadian privacy law, lives in our earlier brief. Project Lily raises the same consent issue at consumer scale: OpenAI told 404 Media it tries to redact personal information before prompts reach reviewers, but acknowledged sensitive details can still get through, and the company does not name the contractors, the countries they sit in, or the data-retention rules applied to the prompts they read.

The structural point is the one EFF has been making about training-data review since the last cycle. A model trained on user data without human review can still ship biased outputs. A model trained with human review of identifiable prompts is a new surveillance system, with a contractor workforce sitting in it, holding an NDA, and reading what users typed under the impression they were talking to a model. The line between "training a model" and "operating a human review pipeline over private chats" is the line Project Lily redraws, and it is the line the next round of AI privacy regulation will have to draw in statute.

Manhattan DA Bragg Seized 12 Celebrity Deepfake Sites. Roughly 1,200 Victims.

404 Media's Samantha Cole reported on September 14 that Manhattan District Attorney Alvin Bragg's office seized 12 websites hosting non-consensual intimate imagery and celebrity deepfakes, exposing roughly 1,200 people's likenesses. The seizures relied on New York's statute criminalizing sexually explicit deepfakes, in place since 2023 (bill S1042) [4].

Bragg framed the action as broadly protective, not just for public figures. "You are not alone. Help is available. If you let us know that an image has been posted without your permission, without your consent, we can take action as long as that website is accessible from Manhattan." "Our message to the people who are creating and publishing this content: What you are doing is a crime. We are investigating, and support survivors in taking down this content and seeking accountability for folks who break the law." Bragg declined to confirm whether images of minors were included, saying only that "the investigation is ongoing" [4].

This is the first large-scale U.S. prosecutor seizure of NCII / deepfake infrastructure, and it sets a template future state actions will follow. Cole's piece also notes that two domains were previously seized by DOJ/DHS in June, and that MrDeepfakes.com was shut down in May 2025. The structural questions are jurisdiction and takedown speed: a New York seizure does not reach a hosting operation in a jurisdiction that does not criminalize the conduct, and the takedown window is the period between the seizure and the next mirror. The platform side of the same problem is the Canada privacy commissioner's finding that Grok generated sexualized deepfakes, which this site's Canada Grok brief tracks.

The UK Is Rolling Passkeys Out to 23 Million Gov Users

The Register's Carly Page reported on September 14 that the UK government is rolling passkeys out more widely across GOV.UK One Login, with 23 million users set to be able to sign in via fingerprint, Face ID, or device PIN instead of a password plus SMS 2FA. The rollout follows a trial involving more than 300,000 users. The government says roughly 10% of daily One Login sign-ins are already using passkeys and claims the new flow is up to eight times faster than the legacy username/password/2FA path. The switch is already saving taxpayers roughly £600 a day in SMS costs [5].

Jonathon Ellison, director for national resilience at the NCSC, framed the security case: passkeys offer "a highly phishing-resistant alternative to passwords, frustrating attackers and saving the public time." Digital Government Minister Stephanie Peacock framed it as a quality-of-life fix for users tired of forgotten passwords and waiting on text codes. Passkeys remain optional at this stage; the department is not eliminating passwords outright. Page reports the biometric or PIN data stays on the user's device and is not seen or stored by GOV.UK One Login [5].

The surveillance read is about the identity layer, not the cryptographic upgrade. A 23-million-user passkey rollout centralizes the binding between a real-world person and a GOV.UK identity, because each passkey is a device-bound credential tied to a One Login account. The phishing resistance is real. The concentration of authentication in one platform, with one set of recovery flows and one provider of last resort, is the new single point of failure. Account-recovery risk, vendor lock-in, and the scope of any legal order against GOV.UK One Login are the next-round questions, and the answers will be set by the recovery policy as much as by the cryptography.

EFF: Newsom Signed the Digital Literacy Bills. AB 1709 Is the Problem.

EFF's Chao Liu and Rindala Alajaji reported on September 11 that Governor Newsom signed a 12-bill package aimed at "protecting children" online. EFF supported AB 2071, which integrates digital wellness and AI-literacy into middle and high school health classes (co-authored by a group of students), and AB 2298, which adds cybersecurity concepts to recommended school curricula. EFF opposed AB 1709, which the group calls a functional ban on social media use for youth under 16. EFF framed the pair as "an affirmative and constitutional way for the state to address valid concerns," and called AB 1709 the censorship quick-fix: "real digital safety comes from preparation, not isolation," and "We All Deserve a Better Internet, Not A Smaller One" [6].

The age-verification angle is the through-line. AB 1709 only works if platforms can identify which users are under 16, and that identification has to happen at the identity layer. EFF's longstanding position is that an age check is the entry point, and the identity database that results is the surveillance prize. AB 2071 and AB 2298 are the alternate path EFF has been pushing: teach the kids to evaluate what they see instead of building the database that watches what they look at. The site's AB 1709 brief covers the EFF veto call, the French court ruling, and the SCREEN Act vote.

A Hardware Interposer Breaks DDR5 Memory Encryption

The Register's Thomas Claburn reported on September 14 that researchers from KU Leuven (DistriNet), ETH Zurich, Durham University, and Google demonstrated a custom hardware interposer, branded "DDRop," that sits between a processor and a DDR5 memory module and silently drops writes to encrypted memory, enabling a replay attack against confidential-computing guarantees. The team included Jo Van Bulck, Jesse De Meulemeester, Stefan Gloor, Patrick Jattke, Daniel Moghimi, David Oswald, Martin Thompson, Kaveh Razavi, and Ingrid Verbauwhede. The proof of concept ran against Intel TDX, Intel Scalable SGX, and AMD SEV-SNP, the three major confidential-computing platforms. Claburn's reporting puts the device cost at under $200 (compared with roughly $170,000 for the prior "Battering RAM" attack) and says the attack completes deterministically in under two minutes [7].

The mechanism is the part that matters. The interposer "corrupts commands on the high-speed DDR5 memory bus to silently drop writes to encrypted memory. The protected VM keeps computing on old data that still decrypts perfectly." On the TDX demo the researchers injected malicious secure page-table entries to "force any protected VM into debug mode and read out its private memory in plaintext," and used forged TDX attestation reports. Intel and AMD told The Register the attack is out of scope for their cloud computing threat models, with no mitigation planned; the paper itself is being released as open-source hardware. The threat model is physical access, which makes the immediate victim cloud service providers that promised tenants confidential-computing isolation, but the larger pattern is the one prior memory-encryption disclosures have illustrated: vendors claiming a stronger property than the implementation actually delivers.

"Dario, Please": A Long Public Rebuttal to Anthropic's Regulatory Wishlist

An essay published September 14 on the POP RDI blog, signed "0x5FC3," laid out a sustained rebuttal to Anthropic CEO Dario Amodei's "We Must Pace the Frontier" essay. The critique targets the specific policy items Amodei proposed: regulate or ban open-weight models, restrict distillation from frontier systems, grant antitrust exemptions to frontier labs, tighten chip export controls targeting China, and coordinate a voluntary industry slowdown. The post frames the package as fear-mongering aimed at entrenching frontier-lab dominance, and draws the parallel to the 1990s crypto wars (PGP, which Phil Zimmermann released in 1991, the Bernstein lawsuit, the 40-bit export limit) where similar arguments were used to justify export controls and key-escrow proposals that the public-interest side eventually beat [8].

Amodei's quoted lines that the rebuttal cites are worth carrying. "AI will cure most major diseases in the next 5-10 years." "There is precedent for operating technologically complex, safety-critical systems millions of times without anything going wrong, for example, commercial airplanes." "Crack down on unauthorized distillation by companies in authoritarian countries." "Strengthen security at the AI companies and prevent model weight theft." Each of those proposals has a frontier-lab-favorable interpretation and a public-interest-unfriendly one, and the post argues the choice between them will be made in the same rule-making venues where the encryption fight was lost and then won [8].

The surveillance read sits in the distillation proposal. Anthropic's June Senate Banking letter described a 28.8-million-exchange distillation campaign, and the same lab is now arguing for legal restrictions on the practice. The argument is reasonable on its face. The argument is also the argument of the platform that wants to set the rules its future competitors must follow, and that is the argument the 1990s crypto case law already answered: allow the technology, accept that some uses will be harmful, and regulate the harmful uses rather than the publication of the underlying capability.

China's Intelligence Boss Joined the AI Doomsayer List

The Register's Simon Sharwood reported on September 15 that Chen Yixin, party secretary and minister of China's Ministry of State Security, published an article in China Cyberspace Magazine, the flagship publication of China's Cyberspace Administration, warning that AI poses risks to Communist Party governance. The piece calls AI "the main battleground for global technological competition and a new arena for strategic rivalry among major powers," notes that "the application of artificial intelligence brings a large number of uncertainties to social governance and public order," and argues China should "ensure the independent control of key core technologies, firmly grasp technological sovereignty" and "make every effort to ensure AI safety." The day after Chen's article, the Cyberspace Administration published version 3.0 of its AI Safety Governance Framework, which Sharwood quotes as recommending that regulators "actively employ risk-controllable institutional mechanisms such as regulatory sandboxes" [9].

Read with the pop.rdi.sh post, the two pieces are the open-weight debate's two largest governments arguing on the same side. Beijing wants independent control of the underlying technology and a sandbox regime for the applications. Anthropic wants restrictions on the open release of the underlying technology and an industry-coordinated slowdown on the applications. The U.S. open-weight rebuttal says the answer to both is to keep the technology publishable and regulate the harm. The EU AI Act high-risk compliance deadline, which phases in starting August 2 and which this site's age-verification infrastructure brief touches on, is the only one of the three regimes that currently has a date attached and a regulator attached. The other two are still arguing about which property to lock down.

What to Watch This Week

EFF and 404 Media follow-ups. Watch whether either EFF or 404 Media releases the per-agency tallies in machine-readable form. The structural argument depends on the data. Making the data public turns one investigative piece into a year of accountability stories [1][2].

Bragg's minor-image question. Watch whether the Manhattan DA's office clarifies whether the 12 seized sites contained any images of minors. The "investigation is ongoing" line in Cole's piece is doing real legal work, and the answer will set the template for every future state seizure [4].

One Login recovery policy. Watch whether GOV.UK publishes the recovery flow for the 23 million One Login passkeys. The cryptography is the easy part. The recovery policy is the part that decides whether a locked-out user can be helped by a court order or by a GOV.UK support agent [5].

Intel and AMD cloud response. Watch whether Intel or AMD publish a revised threat model for TDX, SGX, and SEV-SNP now that the under-$200 interposer is public. The Register's "no mitigation planned" line will not survive the first paying customer that asks [7].

AI Safety Governance Framework 3.0. Watch for the first sandbox designations under the new framework, and for any export-control language that lands alongside it. The "main battleground" framing in Chen's article is the political signal that the new rules will be applied [9].

Sources

  1. Electronic Frontier Foundation, Rindala Alajaji and Dave Maass: The High Crime of 'LMAO': How Cops Are Treating Mass Surveillance As a Joke (September 14, 2026). https://www.eff.org/deeplinks/2026/09/high-crime-lmao-how-cops-are-treating-mass-surveillance-joke
  2. 404 Media, Jason Koebler: Cops Search Thousands of Flock Cameras for Reasons of 'LMAO,' 'IDK,' 'Hehe,' and 'asdfg' (September 14, 2026). https://www.404media.co/cops-search-thousands-of-flock-cameras-for-reasons-of-lmao-idk-hehe-and-asdfg/
  3. 404 Media, Joseph Cox: Inside 'Project Lily': The Humans Reading Your ChatGPT Chats (September 14, 2026). https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats/
  4. 404 Media, Samantha Cole: New York Seizes 12 Celebrity Deepfake Websites (September 14, 2026). https://www.404media.co/new-york-district-attorney-seizes-12-celebrity-deepfake-websites/
  5. The Register, Carly Page: UK.gov begins killing off passwords for 23 million users (September 14, 2026). https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088
  6. Electronic Frontier Foundation, Chao Liu and Rindala Alajaji: Governor Newsom Signs Student-Backed Digital Literacy Bills Alongside Misguided Bans (September 11, 2026). https://www.eff.org/deeplinks/2026/09/governor-newsom-signs-student-backed-digital-literacy-bills-alongside-misguided
  7. The Register, Thomas Claburn: New hardware device can RAM into encrypted memory, expose your data (September 14, 2026). https://www.theregister.com/security/2026/09/14/new-hardware-device-can-ram-into-encrypted-memory-expose-your-data/5296377
  8. POP RDI, 0x5FC3: dario, please! (September 14, 2026). https://pop.rdi.sh/dario-please/
  9. The Register, Simon Sharwood: The latest AI doomsayer is China's intelligence boss (September 15, 2026). https://www.theregister.com/ai-and-ml/2026/09/15/the-latest-ai-doomsayer-is-chinas-intelligence-boss/5296451
  10. Electronic Frontier Foundation, Karen Gullo and Adam Schwartz: Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR (September 9, 2026). https://www.eff.org/deeplinks/2026/09/cops-play-hide-and-seek-about-using-spy-tech-avoid-scrutiny-and-bad-pr