Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Social Media Bans for Kids Need Smarter Safety Design
Even before France approved legislation banning social media for children under 15 last January, 13-year-old Benjamin was already wondering what life without social media would look like. “If we want to play football, we won’t be able to organize it. What will we do? Send letters instead?” he joked in an interview for Le Monde.
His reaction captured the central challenge behind the growing wave of youth social media bans: Removing access is one thing; understanding what those platforms mean in children’s lives is another.
Within weeks of Australia’s similar ban, the country’s eSafety Commissioner reported that platforms had restricted access to 4.7 million under-16 accounts. Two months later, though, one in five Australian teenagers under 16 was still using TikTok and Snapchat, according to a parental-control data company. But even if all children’s social media accounts were to disappear, do such bans actually make children safer online?
Governments are moving ahead without answering that question as they follow Australia’s lead. Indonesia’s child-safety framework, which took effect in March, bars children under 16 from holding accounts on “high-risk” platforms. The U.K. government has announced plans to ban social media for under-16s, add default overnight social media curfews for 16- and 17-year-olds, and extend child-safety rules to cover risky AI features. And on 17 September, the European Commission proposed the EU KIDS Act, which would bar children under 13 from social media, set 15 as the EU-wide minimum age for opening an account independently, and require platforms to show that their services are age appropriate and safe by design.
But based on my experience working on Child Online Protection initiatives with the International Telecommunication Union (ITU) across Southeast Asia and the Pacific, I know the bans don’t address the real problems. Instead, we should be paying more attention to the systems that generate harm in the first place—namely, recommender algorithms, engagement-maximizing design, opaque moderation, and extractive data practices.
Account removals are not the same as online child safety
My experience working on protecting children’s online safety has taught me three main lessons:
First, the public institutions responsible for child online protection often lack the staff, budget, or technical capacity to enforce complex online safety policies.
Indonesia is illustrative. A 2026 UNICEF evaluation found capacity constraints among service providers, long-term funding uncertainty, and a need for specialized personnel. At the local level, some staff lacked digital skills, while budget constraints left some areas reliant on external support.
Second, many children, and often their parents, lack the digital literacy and critical thinking skills needed to navigate online risks safely. My policy research on child online protection in Indonesia, published earlier this year in Digital Society, found substantial gaps that account removals cannot repair: Many children lacked guidance on navigating the internet safely, and large numbers did not know how to report harmful experiences.
And third, the platforms have limited independent oversight as they identify underage users, design age-verification systems, and report their own compliance. In Indonesia, platforms themselves are responsible for carrying out age verification, while the Ministry of Communication and Digital Affairs oversees compliance. TikTok’s appeals process for users flagged as underage, for instance, can require a government-issued ID and selfies, which is a problem because it involves collecting the additional personal data on an ID card, beyond that needed to confirm age. Will government regulators ensure that TikTok handles that data responsibly?
The privacy paradox of proving age
Every age-based ban creates an engineering problem: How can a platform reliably determine that a user is old enough, without intruding on other information? Governments and companies may use identity documents, parental authorization, app-store checks, or facial age estimation. Each approach has trade-offs among accuracy, privacy, accessibility, and resistance to circumvention.
There are also technical issues. One tool, facial age estimation, draws on enormous databases but it is probabilistic, not exact, because people vary so much. It’s also been shown to misclassify both children and adults.
The challenge should not merely be to “verify age.” It should be to prove that someone is above a threshold, without disclosing their identity, birth date, or other information third parties might use to create a marketing profile. The European Commission’s age-verification blueprint challenges companies to verify ages without collecting all that additional information.
Privacy-preserving technologies offer promising ways to achieve this. Zero-Knowledge Proofs (ZKPs) can confirm that someone meets an age threshold without revealing their identity or exact date of birth. W3C Verifiable Credentials are cryptographically verifiable digital claims that can disclose only the information needed, such as “over 16.” And device-based age signals can allow a phone or app store to share an age range without revealing a user’s exact birth date. But these methods still require rigorous security testing, common standards, independent oversight, and clear limits on data retention. Otherwise, poorly designed child-safety policies risk creating permanent identity infrastructures in which businesses, not people, control personal data.
Where connection goes when a platform closes
Blocking access to a platform redirects some young people, but not always where expected. Early anecdotal reports in Australia pointed to teenagers migrating to smaller, less-regulated platforms like Yope, a pattern the Cato Institute flagged as a “whack-a-mole” problem for regulators. But industry data collected two months later found no broad-based shift of that kind, aside from a small uptick in WhatsApp use. Many teens simply found a way to stay on the banned platforms.
This points to a deeper gap in current society: the erosion of youth “third places“ physical spaces where young people have room to socialize and build identity outside home and school. As those spaces have diminished, commercial communications platforms have absorbed that role.
For many teenagers, social media workarounds are merely inconvenient. But for isolated, marginalized, disabled, or LGBTQ+ youth who depend on online communities for support that’s otherwise unavailable, displacement can mean losing certain kinds of belonging, or having to move to a platform with even weaker oversight.
How to design safer online systems for children
If blanket social media bans don’t work, then what will? The platforms have created many of the conditions that governments are now trying to contain: engagement-optimized recommenders, intrusive data practices, weak safeguards against unwanted contact, and features such as infinite scroll, autoplay, streaks, and persistent notifications.
These design patterns increasingly face regulatory scrutiny, including what’s required under the European Union’s Digital Services Act. A 2026 study from the 5Rights Foundation that tracked children’s device use minute by minute found that the user interfaces shape children’s attention, sleep, and well-being in real time.
A more durable response would regulate those interfaces directly, treating children as legitimate users whose privacy, agency, and well-being are required protections, not afterthoughts. That means designing for safety from the outset. One example would be for children’s apps to have high-privacy defaults, such as private accounts and location sharing switched off for minors. They could also have recommender systems that explain the main factors shaping a feed and give young users more control over personalization. The European Commission has published age-appropriate interaction guidelines that limit unsolicited contact and prevent minors from being added to groups without consent. Rules could also prohibit engagement-maximizing features that demand users’ attention, such as autoplay, infinite scroll, usage streaks, read receipts, and push notifications, by disabling or limiting them by default.
Governments should define measurable outcomes and fund independent evaluation, platforms should give researchers meaningful data access, and engineers should audit age-assurance systems for bias and data leakage. Schools, parents, and children themselves need a seat in designing the technology that’s designed to protect children.
If policymakers still decide to remove an infrastructure for youth connection, they should offer something better in return. Social media bans may reduce some forms of exposure to harmful content and may be justified for particular ages, services, or risks. But they are just one tool, not a comprehensive substitute for safer design, accountable platforms, digital literacy, institutional capacity, and noncommercial digital “third places”—moderated communities, creative spaces, and public-interest platforms designed for youth participation rather than profit.
The first wave of social media restrictions isn’t enough to keep children safe. Governments are still measuring what’s easiest to count, while neglecting harder-to-measure outcomes such as children’s access to safe third places and meaningful social connection, both online and offline. Until governments can show evidence that harm has actually declined, they will keep mistaking account removal for safety.
From Your Site Articles
Related Articles Around the Web
Tech
Crusoe abandons $1.25B plan to use Boom turbines at AI data centers
Crusoe, a Denver-based AI data center startup that recently raised $3.9 billion, has ended plans to use a new line of stationary power plants developed by fellow Denver company Boom Supersonic.
Founded in 2018 as a bitcoin miner that ran on excess natural gas from oil fields, Crusoe has since become one of the biggest builders of AI data centers, including a massive campus in Abilene, Texas, that supplies computing power to OpenAI.
Boom Supersonic, which is developing a supersonic passenger jet called Overture, launched a new business last year to sell a version of the engine it’s developing for that jet as natural gas-fired stationary power plants. Its Superpower turbine shares about 80% of the same parts with that airborne engine, called Symphony.
Crusoe had signed on to be the first customer for this business, agreeing to spend $1.25 billion on 29 of Boom’s 42-megawatt Superpower turbines. The first deliveries were supposed to begin in 2027. But that deal has since fallen apart, according to Boom Supersonic CEO Blake Scholl.
Friday, in a post on X, after congratulating Crusoe founders Cully Cavness and Chase Lochmiller on the company’s recent raise, Scholl said the companies are no longer moving forward with the turbine launch partnership. Although he did note that other customers were in its pipeline.

“The TL/DR is that turbines are no longer part of Crusoe’s near term primary power mix at Abilene/etc., so a launch partnership just didn’t make sense,” he wrote in the post. “Boom will be delivering about 250MW of Superpowers next year to other sites, and we’re targeting 1GW in 2028. We’re grateful for the help Crusoe gave us in shaping Superpower and continue cheering for their successes. The future is long, and we look forward to potentially teaming up if/when turbines become part of their primary power mix.”
Crusoe confirmed to TechCrunch that it is no longer doing business with Boom.
“We build AI factories from the power up, and we’re bringing new campuses online across the country, powered by innovative energy sources,” spokesperson Andrew Schmitt said in an email. “As our portfolio grows, we stay flexible, choosing the energy solutions that are right for each site as its needs evolve – including turbines, along with wind, solar, batteries and the grid. While Boom has been a great partner, the partnership isn’t the right fit today. We wish them well.”
Crusoe’s initial 1.2 gigawatt data center in Abilene that was built for Oracle and OpenAI is powered by the grid, according to the company. There is also a gas-turbine power plant that is used for backup power only. Crusoe is also building a 900 megawatt data center in Abilene for Microsoft, which will be powered on-site gas turbines.
Losing its launch customer is seemingly a setback for Boom, which raised $300 million last year, largely to commercialize the new business. The idea, Scholl told TechCrunch at the time, was to use profits from the stationary power plant business to fund the development of Overture.
Scholl could not be reached for comment before publication; TechCrunch will update this article if he responds.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Quince Luggage Is Affordable but Doesn’t Feel Cheap (2026)
If I were buying luggage for the first time in a long time or replacing an old set, I’d choose Quince. You’re getting polished, durable suitcases with reliable features, and without paying a premium for the brand name. At $270 for both an expandable carry-on and a large checked bag, it’s an excellent value.
Away doesn’t offer a comparable bundle, but its Large Flex ($425) and Carry-On Flex ($325) are almost identical to Quince’s Expandable Large Check-In ($220) and Expandable Small Carry-On ($140). All four are polycarbonate hard-shell suitcases with similar exterior and interior dimensions, capacity, and weight, though Quince’s are both slightly lighter. They also have similar features: 360-degree spinner wheels, a Travel Sentry combination lock, a removable laundry bag, and, crucially, a lifetime warranty. After traveling with both, I found them to be equally sturdy. I was also able to pack the exact same clothes in both sets, and the Quince Large Check-In actually gave me more room once expanded.
Even the designs are quite similar. Take away Away’s emblem, and it would be tough to tell these suitcases apart. Quince’s branding is even more minimal; there are no flashy logos, which I aesthetically appreciate, but it does make the bags harder to spot on a baggage carousel. Both brands offer a solid range of colors, so that’s mostly a matter of taste. For me, the more important distinction is the price. Quince gives you essentially the same experience for less money, so why pay double for Away?
To further sweeten the deal, the bundle knocks another $90 off the combined price. And Quince’s value isn’t limited to its advantage over Away. It’s significantly less expensive than comparable luggage from popular brands like July, Monos, Travelpro, and Briggs & Riley. Quince also gives customers 365 days to return unused products, which is a much more generous window than competitors.
I’m sold on Quince’s luggage, and I’m already eyeing its Eco Compression Packing Cubes ($46) and Italian Leather Pouch Travel Set ($72) for my next trip. At this point, Quince has earned a suspicious amount of my trust.
Power up with unlimited access to WIRED. Get best-in-class reporting and exclusive subscriber content that’s too important to ignore. Subscribe Today.
Tech
3 underrated movies on Prime Video you should watch this weekend (September 25-27)
None of this weekend’s picks had a massive marketing push, or watched by many in theaters and that’s exactly what’s make them so underrated. One turns a two-minute glitch on a cafe TV into a tiny sci-fi marvel, another follows a drifter who’s hilariously bad at vengeance, and the third gave Brie Larson her best role long before anyone knew her name. All three movies are streaming on Prime Video right now.
We also have guides to the best new movies to stream, the best movies on Netflix, the best movies on Hulu, the best free movies, and the best movies on Amazon Prime Video.
Beyond the Infinite Two Minutes (2020)
Genre: Comedy, Sci-Fi
IMDb rating: 7.2/10
Rotten Tomatoes: 99%
A cafe owner named Kato discovers that the television in his cafe can show him exactly two minutes into the future. Once his employees and neighbors catch wind of it, the fun experiment becomes complicated after they start using it to make money and end up drawing the attention of dangerous people.
What makes the movie so much fun is how far it takes a simple idea. I really like how the characters constantly test the limits of the two-minute window and come up with ideas to create a chaotic infinite loop. Another impressive aspect of this Japanese indie movie is that it was shot to look like one continuous take, with clever, seamless hidden cuts to maintain the illusion of uninterrupted action.
You can watch Beyond the Infinite Two Minutes on Prime Video.
Blue Ruin (2014)
Genre: Crime, Drama, Thriller
IMDb rating: 7.1/10
Rotten Tomatoes: 96%
Dwight, a quiet drifter living out of his car, learns that the man who killed his parents is being released from prison. He decides to kill the murderer. The problem is Dwight has no idea what he’s doing, and his amateurish attempt at revenge drags his estranged sister and her family into a spiraling blood feud with the killer’s own relatives. It’s a revenge thriller about what happens when an ordinary man tries to play executioner.
Macon Blair’s lead performance is the whole engine here – awkward, terrified, and utterly convincing as a man completely unequipped for the violence he’s chosen to unleash. Director Jeremy Saulnier skips the slick choreography entirely in this movie, leaving violence that is tense, ugly, and far more honest about what vengeance actually costs.
You can watch Blue Ruin on Prime Video.
Short Term 12 (2013)
Genre: Drama
IMDb rating: 7.9/10
Rotten Tomatoes: 98%
Grace Howard (Brie Larson) supervises a foster care facility for at-risk teens. She’s funny, patient, and able to reach kids most adults have written off, like Marcus (LaKeith Stanfield), who’s about to age out of the system. When a new resident, Jayden (Kaitlyn Dever), arrives with a story that cuts uncomfortably close to Grace’s own unspoken past, she’s forced to finally confront the trauma she’s spent years outrunning.
Long before Captain Marvel, Brie Larson delivered what I still consider her finest performance right here. She makes Grace warm and tough without ever tipping into sainthood. The film treats these kids with respect without turning their pain into cheap melodrama. It reminded me that the people holding everyone else together are often the ones who need help most.
You can watch Short Term 12 on Prime Video.
Tech
The Metric Is Not The Mission: When They Still Understood Us
The Metric Is Not the Mission is a ten-part examination of how Big Tech moved from building and expanding the open internet to increasingly shaping it around its own metrics, incentives and assumptions. Across the series, the argument follows the evolution of the platform economy—from the optimism of the early internet to the growing tensions around power, prediction, geopolitics, accountability and the future of digital life.
The series will be published in two parts each week over five weeks, with each installment building on the one before it. At the end of the series, the complete essay will be brought together in a single PDF edition, providing the full argument in one place.

Part II — When They Still Understood Us
Part I looked at the slow transformation taking place beneath the daily controversies surrounding Big Tech. This second part goes back to the beginning, asking what these companies originally understood about people and how the metrics that once measured their success gradually became the definition of it.
It has become fashionable to tell the story of Big Tech as though it were always destined to end here. In retrospect, it is easy to portray the rise of the major platforms as the inescapable march of surveillance capitalism, monopolistic ambition, and unchecked technological power. That narrative is emotionally satisfying because it offers clear villains and a comforting sense of inevitability. It also happens to be incomplete.
Cory Doctorow has given this deterioration a memorable name: “enshittification.” His argument is that platforms initially serve users well, then, once users and business customers are locked in, progressively shift value away from both toward shareholders, degrading the service in the process. It is a powerful account of how platforms become extractive. But it is not quite the argument here. The deeper problem is not simply that Big Tech has learned to extract more from us but that it has become increasingly convinced that because it can measure and predict our behavior, it understands us and, by extension, the societies it has come to mediate. The failure is therefore not only economic; it is also epistemic. The metric has become a substitute for the mission.
One cannot understand why these companies now appear increasingly disconnected from the societies they helped shape without first acknowledging that, for a remarkably long time, they understood those societies exceptionally well.
Technology succeeds when it solves technical problems. It changes the world when it solves human ones.
That was the genius of the first generation of internet platforms. Their founders did not invent friendship, curiosity, creativity or community. They simply recognized that the internet had reached a stage where these deeply human instincts required new forms of expression. The web of the late 1990s was exhilarating, but it was also fragmented, uneven and, for many people, intimidating. Finding information often required patience. Discovering interesting websites depended on chance as much as design. Publishing demanded a degree of technical literacy that excluded far more people than it empowered. The internet was open, but openness alone does not necessarily produce accessibility.
The great platforms emerged not because they sought to replace the internet but because they made it intelligible. Google transformed an expanding wilderness of information into something navigable. Wikipedia demonstrated that knowledge could be organized through collaboration rather than hierarchy. YouTube lowered the barriers to publishing so dramatically that expertise escaped universities, broadcasters and production studios. Facebook addressed an even more fundamental challenge. It recognized that the internet was no longer simply about information; it had become about people. Until then, maintaining relationships online had been surprisingly cumbersome. Email was too formal, instant messaging too ephemeral, personal websites too static. Facebook reduced social interaction to something almost frictionless. Its success lay not in technological sophistication but in psychological intuition.
This is easy to forget because the platforms that dominate our lives today bear only a partial resemblance to the ones that first captured our imagination. Facebook did not begin as an endless stream of algorithmically selected content. It was, in essence, a digital address book enriched by photographs, conversations, and the ordinary rituals of everyday life. It became valuable because it mirrored existing relationships rather than attempting to manufacture new ones. There was comfort in discovering former classmates, following the lives of distant relatives, or organizing gatherings that would otherwise have required dozens of emails and phone calls. The platform expanded social life without yet attempting to redefine it.
YouTube offered a similarly modest promise. It was not originally designed to maximize engagement or optimize watch time. It functioned more like an immense public archive whose value derived from its unpredictability. One could arrive searching for a lecture on astronomy and leave having discovered a forgotten jazz performance, a documentary on Greek history, or a repair manual for a washing machine. Recommendation existed, but it remained subordinate to curiosity. Users still felt as though they were exploring rather than being guided.
Even Twitter (now X), before it became a battleground for politics, culture wars, and performative outrage, captured something important about the changing nature of public conversation. It collapsed distance between journalists, academics, politicians, and ordinary citizens in ways that would have seemed extraordinary only a few years earlier. For all its imperfections, it suggested that expertise and authority might become more accessible rather than less.
Looking back, what united these companies was not simply technological innovation but a particular philosophy of the internet. They assumed that openness generated value. The more people connected, the richer the network became. Every new participant increased the possibilities for everyone else. Economists describe this as a network effect, but the phrase barely captures its cultural significance. Participation itself became the source of optimism. The internet appeared to be validating one of the oldest liberal ideas: that societies flourish when individuals are free to exchange ideas, collaborate voluntarily, and build institutions from the bottom up.
It is difficult to overstate how persuasive this vision became. Most governments celebrated the digital economy as an engine of innovation. Investors poured unprecedented sums into technology because the opportunities seemed limitless. Civil society organizations embraced online platforms as tools for democratic participation and global advocacy. Even critics of globalization often regarded the internet as an exception, a domain where openness appeared to distribute power rather than concentrate it.
For a brief historical moment, these interests aligned. What was good for technology companies often appeared to be good for users, for markets, and, in many respects, for the internet itself. The incentives reinforced one another. Companies grew by making the network more useful. Users benefited from larger communities. Developers built new services on open standards. The web expanded because success depended on drawing people further into its richness rather than confining them within a single destination.
History, however, has an inconvenient habit of changing the problems that institutions are asked to solve. The sociologist Robert K. Merton once observed that organizations often become prisoners of their own success. Practices that were rational under one set of conditions gradually harden into routines, and routines into orthodoxies. Institutions continue refining the solutions that once made them indispensable even as the environment around them evolves. Success breeds confidence; confidence breeds certainty; certainty eventually makes adaptation more difficult than persistence.
There is no reason to believe technology companies are exempt from this pattern. If anything, their extraordinary success may have accelerated it.
The platforms that once competed to help users navigate an open internet eventually found themselves managing ecosystems of unprecedented scale. Their priorities changed almost imperceptibly. The models they developed during the internet’s age of expansion proved astonishingly effective at connecting people, organizing information, and lowering the costs of participation. The metrics through which they evaluated success, such as growth, engagement, scale, and network effects, were not arbitrary inventions of venture capital. They reflected a period during which connecting more people genuinely created more value for everyone involved. The problem is that the world changed while the metrics remained stable. A measure that once indicated success gradually became the definition of success itself.
There is an obvious parallel here with Goodhart’s Law: when a measure becomes a target, it ceases to be a good measure. The principle, first articulated by economist Charles Goodhart in the context of monetary policy, describes what happens when an indicator that works as a proxy for an underlying objective is turned into the objective itself. But the problem here is slightly different. The issue is not simply that platforms began gaming their metrics, or that users learned to optimize for them. It is that the metrics gradually became so deeply embedded in the companies’ understanding of success that the distinction between the measure and the mission was lost. The metric did not merely distort the objective; it quietly became the objective.
None of this happened because a group of executives gathered in a boardroom and decided to undermine the open internet. Institutional change is rarely so theatrical. More often, it emerges from countless rational decisions made in pursuit of perfectly reasonable objectives: improve the user experience, reduce friction, personalize recommendations, increase safety, remove inconvenience. Each adjustment appears modest in isolation but collectively they alter the character of the system itself.
This is where history becomes quietly ironic. The companies that had once understood the internet better than anyone else slowly began to forget what had made the internet exceptional in the first place. They continued to believe they were connecting the world, even as they increasingly replaced the world with carefully curated representations of it. They accumulated unprecedented quantities of information about human behavior while becoming progressively less attentive to the human condition.
The distinction is subtle, but it may prove to be the defining story of this technological era. To observe behavior is not the same as understanding experience. A platform can know how long we hesitate before clicking a link, which videos hold our attention for an extra seven seconds, or what sequence of images is most likely to keep us scrolling late into the night. It can infer preferences with astonishing accuracy. It can predict patterns that would have been unimaginable a generation ago. Yet prediction, however sophisticated, remains an impoverished form of understanding. It reveals what people do. It says far less about why they do it, what they fear, what they hope for, or what kind of society they are trying to build together.
That difference, almost invisible at first, is where the story begins to change.
Konstantinos Komaitis, PhD, is a veteran of developing and analysing Internet policy to ensure an open and global Internet.
Filed Under: big tech, enshittification, goodhart’s law, history, metric not mission, open internet
Tech
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it’s offering up to $250 in free promotional credits.
Cloud sessions run Claude Code on Anthropic’s infrastructure instead of your own computer, so you can start a task, leave it running remotely, and return later to review the work.
“Cloud sessions run on Anthropic-hosted infrastructure, so the work keeps going even without your computer running,” Anthropic explained.
In our tests, we observed that you can start a cloud session from claude.ai/code, the Code section of the Claude mobile app, the desktop app, or the CLI using claude --cloud.
Claude Code’s cloud sessions have been available to some users via research preview, but now they’re officially available to eligible subscribers, and Anthropic is offering free usage credits to encourage existing subscribers to try them.
Anthropic explains how you can claim free credits
Anthropic is giving eligible Pro users $100 in promotional cloud-session credits, while Max subscribers get $250.
However, it is worth noting that the credits are separate from normal Claude usage limits and are applied automatically when you start a cloud session.
“If you hit a limit locally, keep going in the cloud until your credit runs out,” Anthropic said.
If you like the idea of Claude Code’s cloud sessions, you can claim the offer from Claude’s website by October 7, and any remaining balance expires on November 4.

Source: BleepingComputer
Once the promotional balance is exhausted, cloud sessions go back to counting against your normal plan limits. There’s no separate charge for the cloud container itself.
The offer is limited to individual Pro and Max subscribers who had an active subscription when the promotion began on September 23.
Tech
‘The prophecy is fulfilled’: Popular 2020 XKCD comic predicted ‘HEIF Heist’ OpenAI hack and even mentions ImageMagick in spooky coincidence
- Hacktron chained a libheif heap overflow, reached through ImageMagick on OpenAI’s Discourse forum, leveraging an OpenAI SSO flaw to briefly take over employee ChatGPT and Codex accounts
- The researchers themselves invoked XKCD #2347, whose 2020 alt text happens to name ImageMagick as the dependency that will one day break
- ImageMagick served as only the pathway to the actual vulnerable component, libheif, an obscure decoder pulled in indirectly across Slack, Meta, and GitHub Enterprise amongst other mediums
When Hacktron AI recently disclosed its months-long libheif research, the researchers reached for a familiar picture that also, to some degree, hints at what let them break into OpenAI in the first place.
They pointed readers to xkcd #2347, Randall Munroe’s 2020 iconic web cartoon of all modern digital infrastructure balanced on a single load-bearing block that some random person in Nebraska has been thanklessly maintaining.
The comparison is relatively easy to follow, and it has a bonus easter egg that one can take as pre-empting the hack.
Latest Videos FromTechRadar
An alt-text that that seems ironically prophetic in 2026
The easter egg in question is one you have to look for; if you hover over the original comic, you get the alt text “Someday ImageMagick will finally break for good, and we’ll have a long period of scrambling as we try to reassemble civilization from the rubble.”
The irony is that six years after the comic was originally posted, ImageMagick was sitting in the exact spot the breach ran through, making its teaser something you could call an unintended prophecy bound to fruition.
The details are unglamorous but worth considering as AI safety continues to take center stage in public discourse, including recent addresses by the CEOs of OpenAI and Anthropic at the UN.
Hacktron found that OpenAI’s community forum, community.openai.com, runs on Discourse. The latter’s usual image checker, FastImage, doesn’t understand HEIF and quietly hands tasks to ImageMagick’s magick command for conversion, which in turn calls libheif, the library that actually decodes the format.
The version shipped to the forum was deployed via Debian and had a heap buffer overflow issue that was fixed the previous year without being labeled a potential security risk, allowing it to serve as a doorway for the Hacktron team.
The team then chained multiple exploits in an elaborate hack that culminated in leveraging a secondary SSO (Single Sign-On) misconfiguration at OpenAI’s end, which essentially allowed the forum to serve as a gateway to ChatGPT and Codex accounts for anyone with a community account who signed in through the forum.
This allowed them access to ChatGPT’s internal GitHub, where they made what they describe as a harmless pull as a proof of concept and notified OpenAI. OpenAI patched it 14 hours later, awarded the team a $6,500 bug bounty, and Discourse patched it after rating the underlying image bug 8.8 on the CVSS scale and adding sandboxing around image processing as a defense-in-depth measure.
The exploit is not exclusive to OpenAI: the same libheif and libde265 decoders reach production through ImageMagick, libvips, Sharp, standard distribution packages, and prebuilt container images. Hacktron traced them across Slack, Meta, GitHub Enterprise, Ruby on Rails, and Node.js frameworks, including Next.js, Astro, and Gatsby, suggesting that potential fallout, if not patched, is far broader than one AI company.
Hacktron’s approach involved using Anthropic’s Claude Opus 4.8 before switching to Opus 5, spending under $3,000 in tokens across a three-person team, and having an exploit ready in just two months. To its credit, the team had to trick Anthropic’s AI into doing the task by framing their own test forum as a capture-the-flag challenge, and it eventually acquiesced.
The exploit itself wasn’t something that couldn’t be done without AI, but it let a much smaller team work at a pace normally expected of a much larger one. Apparently, asking your AI chatbot nicely with a bit of trickery in tow can deliver exceptionally good results in some cases.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Tech
Why Some Smartphones Have Worse Repairability Than Others
Not too long ago, we could easily replace the battery on many smartphones. All one had to do was take off the back cover, take out the existing battery, add the new one, and put the panel back in place. It usually took less than a minute. But those days are long gone, with most smartphones now sealed shut with glue, making simple repairs and part replacements incredibly difficult at home. You need a solid understanding of the hardware side of things and the required tools before you can attempt something like that. Even then, a small mistake can damage other components and render the phone completely unusable.
This doesn’t mean every smartphone on the market is unrepairable. But leading smartphone brands don’t generally fare well. According to the US PIRG “Failing The Fix” 2026 report, Apple ranked last for smartphone repairability with a D- grade, Samsung right above it with a D grade, and Google with a C-. Motorola, on the other hand, bagged the top spot with a B+ grade. If we look at iFixit’s repairability scores, two smartphones, Fairphone 5 and Fairphone 6, earn a perfect 10/10.
That brings us to the more important question: what changed in the past few years that many smartphones now have poor repairability? It all comes down to new design choices manufacturers prioritize and the push to encourage users to upgrade sooner.
Slimmer and waterproof designs are the biggest reasons
In the past few years, smartphone brands have achieved slimmer designs. The iPhone Air is one example, with a thickness of just 5.64 mm. That’s impressive for a smartphone packed with features. But these sleeker, slimmer smartphones can come with a downside: they are not as easy to repair. Smartphones now have components packed more closely together, making at-home repairs difficult, if not outright impossible. Newer designs rely heavily on adhesives to hold everything together, whether it’s the battery, display, or back cover. Even iFixit highlights this use of adhesives as a major drawback on most of the newer smartphones, including those from Apple, Samsung, and Google.
Adhesives do have benefits, especially when it comes to improving smartphones’ structural integrity and making them slimmer and more waterproof. But unlike screws, adhesives also make at-home repairs incredibly challenging. As for doing away with removable batteries and using adhesives to hold them in place, companies generally cite similar reasons, including stronger, slimmer designs and improved water resistance. Apart from that, even the screws used in smartphones aren’t that straightforward. iFixit notes that some modern iPhones have four to five different screwhead types, which complicates repairs.
If you haven’t guessed it already, foldable phones are more difficult to repair because of their complex designs. This added complexity can also increase repair costs. So, you may end up spending more in the long run.
Some phones are still repairable
All that said, it’s not like every smartphone on the market scores poorly on repairability. Some newer brands are making highly repairable phones, with Fairphone and HMD being notable examples. Fairphone, for instance, boasts of streamlined repairs and replacement across its smartphone lineup, with over 40 easily replaceable components. More importantly, these companies incorporate repair-friendly designs and provide clear guides and instructions to allow for common repairs to be performed at home.
Even Apple is moving in a similar direction, although it has links with associations lobbying against Right to Repair. With the launch of Repair Assistant, Apple has made repairs and replacements much easier. For example, professionals, or users themselves, can swap the battery on an iPhone without contacting Apple, as the Repair Assistant handles the calibration. This has, to an extent, addressed the problem of parts pairing. However, you still can’t officially repair or replace every part on every iPhone model. Newer Samsung phones, too, are relatively easier to repair, although it’s still not at the same level as Fairphone.
So, if you are planning to buy a smartphone, you know which brands or models to steer clear of, or at least what you need to check before finalizing one. Better repairability doesn’t just save you money on repairs. It also ensures that your smartphone lasts longer and, at the same time, helps reduce e-waste, a major problem the world is facing right now.
Tech
Cities Across US Oppose Trump FCC Plan to Preempt Local Broadband Rules
Ars Technica reports:
Cities and counties around the U.S. are angry at the Trump administration over a proposal to override local rules that govern the deployment of wired broadband networks… The Federal Communications Commission [FCC] argues that too many local governments “excessively delay approvals and seek to extract exorbitant sums from providers, resulting in costs that render some deployments infeasible.” The FCC plan is supported by broadband providers, but local governments told the FCC that it would override rules that protect public safety.
Local governments say the plan is illegal and that the FCC should instead focus on how Internet providers thwart competition with permit-hoarding and other tactics that prevent competitors from deploying networks… They object to FCC plans to impose a 120-day deadline for processing permits and to proposed limits on fees and compensation that local governments can require from providers… Another filing submitted by the League of California Cities said the FCC has no authority to adopt the proposal. “Federal preemption of traditional state and local authority over public property, construction, public safety, permitting, and rights-of-way management should rest on clear congressional authorization,” the filing said. “The commission should not infer broad preemptive authority where Congress did not expressly provide it….”
A filing by Minnesota cities said the current FCC is making the same mistake it made during the first Trump administration, when its attempt to preempt state net neutrality laws was blocked in court… If the FCC finalizes its new preemption plan, city and state governments could sue and ask a court to rule that the agency exceeded its authority…
Democratic Commissioner Anna Gomez approved the step of asking the public for input but signaled she would vote against the final proposal. “I am dubious about the commission’s authority under Section 253 to use rulemaking to preempt states and localities when it comes to their management of rights of way and fees charged to providers,” she said.
Read more of this story at Slashdot.
Tech
Cricut’s New DIY Machines Let You Print And Cut Your Own Stickers
The Cricut StickerPix Print and Print + Cut could birth a generation of sticker moguls.
Cricut, maker of a growing lineup of cutting, embossing and heat pressing machines for home crafters, is going all in on stickers. The new Cricut StickerPix Print and StickerPix Print + Cut make it easy to print custom stickers, and, in the case of the Print + Cut, combine the company’s cutting tech with a printer for the first time.
The Cricut StickerPix Print is the smaller of the two machines at 7.8 x 5 x 3.5 inches, and is capable of printing on 4 x 6-inch photo paper or pre-cut sticker sheets from Cricut. The StickerPix Print + Cut is larger at 8 x 11.3 x 4.1 inches and can work with 4 x 7-inch sticker sheets and 4 x 6-inch photo paper. Because the machine can cut, you’re also not limited to the predetermined shapes of Cricut’s pre-cut sticker sheets.
Both the Print and the Print + Cut use dye-sublimation to print photos and stickers, which means they apply heat to transfer dye directly onto whatever material you’re printing on. They then add a laminate layer that makes your prints water, scratch and fade-resistant. Other Cricut machines require the use of an inkjet printer and special laminate sheets to get similar results, which means if you’re just interested in printing photos and stickers, the Cricut StickerPix could save you a lot of space.
Unlike Cricut’s other machines, though, both the Print and the Print + Cut can only make what are called kiss-cut stickers that come still attached to a single sheet, rather than the die-cut stickers that are separated from their backing paper as they’re cut. Like all of the company’s machines, you’ll also have to use the Cricut Design Space software on your phone or computer to use either StickerPix, which means you’ll likely also be pushed to pay for Cricut Access, a subscription that lets you access more templates and discounts.
The Cricut StickerPix Print and Print + Cut machines are available now, starting at $169 and $299, respectively. Both machines come bundled with sticker sheets, photo paper and an ink cartridge.
Tech
Goose by The Robot Works Arrives as a Household Robot Built to Grow

Rolling down a hallway with a shirt slung over its neck, Goose looks less like a factory demo and more like a small appliance that decided to grow a personality. Prototype 1 from San Francisco’s The Robot Works is a white, low, rounded base with a long articulated neck, camera eyes set in a bonnet so you can see where it is looking, and a bright orange beak that doubles as a gripper. A blue polka-dot wrap gives the machine a costume instead of a chassis. Founders posted the first public clip this week with a simple brief: tidy, play, live.
Richard Wei has spent months sitting down with families to discuss what they really need from a robot in their house, and the team has used that information to create something they would like to have themselves. Humphrey Hu, who formerly worked with Anki on making highly expressive robot faces, will join him on this project. After considering all of the jobs that tend to build up around the house, as well as how a machine might interact with children and grandparents, they decided against a human-shaped body. Instead, the design features a wide stance close to the floor to keep the creature low to the ground, as well as a long neck that allows it to reach for items such as a sock, a wall outlet, a door handle, or a pile of laundry without having to stand on two legs and tower over the space.
LEGO Disney & Pixar Wall-E & EVE Building Set for Adults, Ages 18+ – Home Office, Book Shelf, or Room…
- LEGO SET FOR ADULTS – The WALL-E and EVE (43279) building set offers adults 18 years old and up an immersive construction challenge featuring…
- 4 DISNEY PIXAR CHARACTERS – Builders can create iconic robots WALL-E, EVE, M-O and Hal from the hit movie—each with authentic functionality like…
- MINDFUL BUILDING EXPERIENCE – This detailed construction set lets builders practice advanced construction techniques for an immersive and relaxing…

They also kept the hardware minimal on purpose, resulting in a robot that rolls, looks around, and then moves on to complete its job. It analyzes its blind spots before moving, and the motors are meant to give way if something like a foot, a chair, or a child gets in the way, and the ability to halt and send it somewhere else was purposefully built in, so it wasn’t an afterthought. A video released shows the robot performing things like placing a man’s foot onto an ottoman, gathering clothes off the hardwood floor, reaching up to a kitchen counter, inserting a plug into a wall outlet, and even pulling open a door when some relatives arrive with children.

Some early write-ups also highlighted some low-key jobs for older individuals who may be less mobile, such as fetching something you’ve tagged, bringing a walker over to the bedside when it’s time for bed, lighting the route to the toilet, keeping an eye out for falls, and sending a ping to family members. Some early elevator and door operations still need a human on the other end of the line, but on the positive side, autonomy is real in some areas and borrowed in others. Which is reasonable for the first version of the product.

The concept is for the robot’s capabilities to evolve as a library rather than coming with a predefined set of talents when you buy it, and they intend to vet each new software before it is released, allowing you to choose what it can see and do. The company is now selling services such as a full-room tidy, checking in on Grandpa, being a companion during story time, taking a look around the house while you’re away, checking the stove, and bringing a parcel inside. The pitch is that life evolves, thus the machine should be able to continually adding new jobs to its repertoire rather of becoming locked in one specific role. That’s the whole point of “built to grow.” They also claim that any household data will remain under your control, rather than being a default action that occurs automatically when the robot arrives.

Unfortunately, orders are currently closed because the initial prototype is still pre-production, with no price or commercial warranty available. Wei says the company is looking for “foster families” that will let Goose learn on real floors, real clutter, and real schedules. You can contact them at therobotworks.ai, while more information will be provided as the device gets closer to launch.
-
Crypto World3 days agoGoldman Sachs and Deutsche Bank Agree: The S&P 500 Rally Isn't Over
-
Tech5 days agoResearchers escape OpenAI Codex sandbox to run commands on host
-
Fashion2 days ago8 iPhone Accessories That Add Personality
-
Crypto World5 days agoWho Needs CLARITY Anyway? ARB Could See 70X Increase: Hodler’s Digest
-
Tech6 days agoTrump suggests rebranding AI with a new name, says he’s also creating an AI Force
-
Business5 days agoAnalog Devices (ADI) Bets $1.35 Billion on Chips that Let Machines Think for Themselves
-
Crypto World3 days agoThis Bearish Netflix Stock Trade Can Cash In On Video Streaming Giant’s Woes
-
Crypto World5 days agoCoinbase, Robinhood, Circle Seen as Tokenized-Stock Winners
-
Crypto World4 days agoTrump-Xi Polymarket Odds for Handshake Hit 50%
-
Tech5 days agoGoogle’s $899 Googlebook is a bet that you’ll buy a new laptop for Gemini
-
Entertainment3 days agoThese 17 Fall Amazon Dresses Seriously Look Like Anthropologie
-
Crypto World2 days agoCrude Oil Prices Pressured by Diplomatic Hopes in the Middle East
-
Business3 days agoOil Price Today (September 23): Crude oil below $100 on hopes of US-Iran talks. What did Trump say?
-
Crypto World2 days agoBitcoin price tests $83,600 Supertrend support after $87K rejection
-
NewsBeat7 days agoEd Sheeran protegees Katseye UNFOLLOW star… days after Macklemore was dropped from his tour over Free Palestine remarks
-
Crypto World2 days agoBitcoin Threatens Sub-$84,000 Breakdown as Long Liquidations Spike
-
Crypto World4 days agoMeta Jumps 11% As Muse Shines and Investors Show an Appetite for Advancing AI
-
Crypto World3 days agoDid Jim Cramer Just Give GameStop Stock the Kiss of Death When He Said the Turnaround Is Working?
-
Crypto World5 days agoBitcoin price holds above $81K as key catalysts line up
-
Crypto World7 days agoCFTC sends crypto market structure rulemaking to White House




You must be logged in to post a comment Login