US Bans More Tech.. Robot Vacuums, Solar Inverters & DJI Shadow Companies

The FCC’s “covered list” of banned foreign technology continues to grow. What began with drones and network routers has now widened to include power inverters and robotic devices, categories broad enough to include products people use at home, including portable battery systems and robot vacuums.

Learn more in my latest video.

Like their router declaration, the FCC’s order extends to any new foreign made product irrespective of where it was made but does not pull existing devices off the market. New products, however, face a different path. Unless a company secures a waiver which includes a commitment to onshore its manufacturing, those devices cannot legally enter the U.S. market.

The power inverter order appears aimed in part at grid-connected equipment. The rationale cited in the FCC order refers to a report alleging that a Chinese inverter manufacturer remotely disabled their products in several countries during a distributor dispute.

But the language does not stop at utility-scale or commercial gear. It will also apply to consumer backup power products and solar-capable battery units that many households use during outages. If a device converts DC to AC or AC to DC and includes some form of remote connectivity like a Bluetooth connection to an app, it will fall under the order. That means a product intended for emergency use in a home could end up in the same regulatory framework as larger infrastructure equipment.

The robotics order is similarly expansive. The FCC’s definition includes mobile robots with obstacle avoidance, navigation, or autonomous movement, as long as they exceed a modest weight threshold and include sensors, connectivity, and software that governs movement or data collection. In practice, that could capture a large number of consumer devices, including robot vacuums and robotic floor cleaners, not just industrial machines or security robots.

The waiver process appears to follow the same model used recently for routers. Companies seeking approval for new products must provide detailed supply-chain disclosures, including components, software, and firmware origins. They also need to present a U.S. manufacturing or onshoring plan. Without both, the FCC is unlikely to allow those products to continue entering the market.

Some companies are already getting waivers in other categories. Netgear, Adtran, Eero, and Nokia all have received permission for their routing products. Also noteworthy is that Flock, the controversial surveillance technology company known for its license plate tracking camera systems, received a drone waiver.

In the case of DJI, Congress specifically banned the company’s “surveillance products” along with those from Autel in legislation last year. The law goes beyond just drones and includes other products like their popular Osmo cameras.

DJI attempted to launch two shadow brands to skirt the ban: Skyrover for drones and Xtra for cameras. The FCC has now added those companies to the list as well, cutting off that route. An Osmo Pocket 4 Pro camera sold under the Xtra name was expected this fall, with deposits had reportedly been taken. But refunds were later issued after it became clear the product would not be allowed into the United States.

For consumers, the immediate effect may be limited. Existing products can still be bought. Gray-market imports may still circulate. Individuals may even be able to bring some products back from overseas for personal use. But over time, these restrictions could narrow choices, delay new releases, and push manufacturers to restructure supply chains around U.S. compliance demands which will undoubtedly drive up prices.

The bigger question is: what consumer products will be targeted next?

Creator Alert! Is YouTube Ending External Linking?

I have recently observed a shift in how YouTube handles external links within its desktop and mobile interfaces. While browsing my own channel and several others, I found that many links to external websites have become unclickable. This includes affiliate links and general references in descriptions for creators such as Astrophysicist Dr. Becky and Hoovies Garage. This issue occurs across devices, browsers and platforms as I found the links were unclickable through the mobile app too.

Curiously, the issue does not affect every channel, as I could still access links on videos from other channels.

See the problem in action in my latest video.

The behavior seems to be tied to specific user accounts included in a recent YouTube user interface “experiment” rather than being a platform-wide rollout at this stage. When switching to a different account, the same links that were previously dead became active again. This suggests that YouTube may be conducting A/B testing with a small subset of its audience.

On the account where the links failed to function, I noticed a revised desktop layout featuring a sidebar for descriptions and comments, along with integrated Gemini AI features. Even within this new sidebar, the external links remained inactive, while YouTube’s internal links and its own affiliate tags continued to function as expected.

This development follows a previous decision by the platform to disable external linking on YouTube Shorts. The possibility that this restriction could expand to long-form content raises questions about the future of the open web on major platforms. Creators rely on these links for a variety of purposes, from citing academic research and source materials to generating revenue through independent affiliate partnerships. If YouTube chooses to restrict these paths, it would further silo users within its own ecosystem and force creators to rely only on revenue sources from which YouTube takes a cut.

There is a broader trend across social media where platforms discourage users from leaving their sites. We see this frequently on services like Facebook, where users have adapted by placing links in comment sections to avoid being penalized by the platform’s algorithms. YouTube’s motivation may be tied to its own revenue interests, particularly as it expands its own affiliate program and seeks more control over how viewers interact with third-party sites. By making it more difficult to navigate away from the site, the platform ensures it retains more data and potential advertising revenue.

Whether this is a technical glitch within a UI experiment or a precursor to a permanent policy change remains to be seen. If the goal is to funnel all traffic through YouTube’s internal tools, it represents a significant shift in how creators manage their businesses and how viewers access information. I tested this on various browsers including Safari, Brave, and Chrome, and the results remained consistent for the impacted account.

If this experiment moves out of the testing phase, the convenience of the open web may become increasingly limited for those who create and consume video content.

Broadcasters Admit Emergency Alert Messages are Encrypted !

Our fight to stop the encryption of over-the-air television continues… The latest broadcast industry filings add a more specific concern to an already contentious transition. Broadcasters pushing DRM for ATSC 3.0 are now effectively acknowledging that emergency alerts can end up behind that encryption layer and will be inaccessible to those who do not purchase an industry blessed tuning box.

See more in my latest video!

The issue surfaced after a filing highlighted that some boxes need an internet connection to decrypt over-the-air signals. If the internet connection is down, those devices may not receive emergency alerts carried on encrypted broadcasts. In response, the A3SA, the private group overseeing this content protection system, argued that nearly all ATSC 3.0 devices can play encrypted content without internet access, while also conceding that not all of them can. It framed the problem as a matter of device design rather than a flaw in the DRM system itself.

What stood out to me is that this distinction does little to ease the practical concern for viewers. If a household owns one of the boxes that does require connectivity, the result is the same: access to emergency information may depend on whether both the device and the internet connection are working properly. That is a different standard from the one many people associate with free broadcast television, which has long been valued in part because it remains available during outages and emergencies.

The filings also addressed two devices that have become central to this debate. One is the HDHomeRun, the most popular ATSC 3.0 tuner on the market that lets viewers watch television across multiple devices on a home network. It remains unable to decrypt protected content because the A3SA has refused to allow it to do so. The other is the ZapperBox, which can decrypt encrypted broadcasts but currently requires an internet connection. In its filing, A3SA called the ZapperBox an outlier and said it is working with the company on the issue.

To me, the HDHomeRun example helps explain why this debate has expanded beyond technical standards and into consumer access. The device is popular because it offers flexibility. Viewers can use it with screens they already own rather than being pushed toward a single approved box or television set. The refusal to extend decryption approval to that type of device has become, for critics, evidence that the system is narrowing consumer choice rather than modernizing it.

A follow-up filing pushed that point further. It noted that Sinclair, one of the companies involved in promoting ATSC 3.0, has directed viewers toward a box that itself requires internet access for decryption. It also cited a notice from KSAT in Texas warning viewers that currently available NextGen TV converter boxes “don’t seem to be reliable” and that station engineers had tested multiple versions without success. KSAT is owned by Graham Media, another supporter of the transition.

That admission is difficult to ignore. Years into what has been described as a market-driven rollout, the available converter hardware still appears limited, inconsistent, and in many cases unreliable. I myself have direct testing experience with all of these boxes, including a second-generation ADTH converter that at times still needed internet access to refresh certificates and at one point failed to decrypt signals during a blizzard despite being connected.

Another filing from Digital Alert Systems, a manufacturer of emergency alert equipment, appears to strengthen the central complaint. The company stated that emergency alert signals are embedded in the protected ATSC 3.0 stream. That means the alert is not simply riding alongside the encryption barrier; it is inside it. If the device cannot decrypt the stream, the alert may not get through.

Now compare this to a smartphone that can also now receive emergency alert messaging. A phone without active service can still receive emergency warnings so long as its internal cellular radio is functioning. But under the A3SA’s model, a television may not be able to deliver similar alerts unless the device is approved, functioning correctly, and in some cases online. That changes the role of broadcast television in a meaningful way. Broadcasters get use of public spectrum in exchange for providing service during emergencies. This breaks that covenant.

The list of available ATSC 3.0 devices reportedly shows that most set-top boxes do not support decryption without internet access. Options that do are limited, and one of the few cited models is currently out of stock due to component shortages. For televisions, the least expensive model capable of tuning encrypted content was said to cost around $580, with many others priced far higher. For viewers hoping to upgrade an older television with a simple low-cost converter, the choices remain thin and unreliable.

There is also a political dimension beginning to take shape. A recent letter to the FCC signed by dozens of members of Congress urged a faster transition to ATSC 3.0. I believe many of the lawmakers signing on may not yet understand how deeply encryption is shaping the rollout. If that is true, the next phase of this debate may depend on whether elected officials come to see DRM not as a technical footnote, but as a structural issue affecting access, affordability, and public safety.

Take a look at the list here, and if your congressperson is on it contact them!!

For now, the FCC has not issued a final decision, and the transition appears to be in a holding pattern. From where I sit, the broad promise of ATSC 3.0 remains tied up in a narrower fight over control: who gets to build devices, who gets to approve them, and under what conditions viewers can receive a signal that was once simply there and accessible to anyone with a tuner.

Is Your ATSC 3.0 Box Spying On You?

For the better part of the last four years, I have been tracking the rollout of the ATSC 3.0 broadcast standard. While marketed as the future of television, this transition has become a point of significant friction between broadcasters and viewers. The primary source of this tension is the decision by major networks to encrypt over-the-air signals, which frequently requires an active internet connection to watch what has historically been a free, offline medium.

In my latest video, I did some deep packet analysis of two of the most popular ATSC 3.0 TV boxes to see what these boxes are doing while users are watching over the air television.

I set up GMKtec Mini PC with two ethernet ports that I configured as a router to sit between the television boxes and the Internet. This setup allowed me to monitor every request sent from the devices to the outside world. I focused my testing on two popular consumer devices: the ADTH box, which is currently one of the most affordable options, and the Zapperbox. While the payloads of the data packets I examined are themselves encrypted, when these packets are triggered along with the destination addresses provide a clear map of which companies are receiving information about my viewing habits.

Starting with the ADTH box, I found that the device is notably “chatty” in its data transmission. Despite marketing claims that it can function without a constant connection, the box failed to tune into encrypted channels in my tests until it was reconnected to the Internet after being offline for a few months. When I tuned into a standard ATSC 1.0 channel—the older, unencrypted standard—the box immediately sent telemetry data to Tulka.tv, the company responsible for the device’s software. The chatter increased significantly when I switched to an ATSC 3.0 encrypted channel.

As the encrypted NBC affiliate loaded, the box initiated several sessions with Yotta, a UK-based company that manages encryption certificates for American broadcasters. However, the most notable discovery was the immediate communication with Google Tag Manager when the mandatory “interactive features” loaded up after tuning into the channel.

In a web environment, Google Tag Manager is used to build marketing profiles based on user activity. In this context, the ADTH box was essentially reporting my viewing choice to a marketing platform. The activation of interactive features on the broadcast triggered further data flows to Amazon’s Cloudfront and a service known as Firehose, which is designed for high-volume data collection. This telemetry occurred automatically, with no visible option for me to opt out.

Even unencrypted ATSC 3.0 channels on the ADTH box showed evidence of tracking. When I tuned into my local ABC affiliate, which does not currently use encryption, the box continued to send telemetry to many of the same servers. This suggests that the data collection is not purely a function of the encryption itself, but a broader feature of how these new broadcast stacks are designed to operate.

In comparison, the Zapperbox exhibited a different profile. It still requires an Internet connection to fetch the necessary licenses for encrypted channels, but it appeared to be less communicative than the ADTH box. I did not see the Google Tag Manager requests during my time with the Zapperbox, though this may be because the device does not yet support the interactive overlays that trigger much of that specific traffic. Most of its communication was limited to the Yotta license servers and Geniatech, the manufacturer’s technical layer. While it was less “chatty,” it still maintains the requirement of an Internet delivered digital handshake to unlock a broadcast signal.

The transition to ATSC 3.0 represents a fundamental change in the relationship between the broadcaster and the viewer. The anonymity that defined over-the-air television for decades is being replaced by a system that mirrors the tracking found in web browsers and streaming apps. I am looking into ways to further intercept this data to see the specific contents of these packets, but the initial map of activity suggests that the “free” nature of broadcast TV now comes with a different kind of cost beyond the DRM hijacking big broadcasters are after.

See more ATSC 3 analysis here.

Fox to Acquire Roku in a $22 Billion Deal.. What’s Next?

The landscape of streaming TV shifted Monday with the announcement that Fox Broadcasting is set to acquire Roku. What will the implications of this $22 billion deal be for the average television viewer?

In my latest video, I dive into the details the two companies released during an investor call.

Roku’s current position in the market is a primary driver for this acquisition. The company currently accounts for 44% of total hours spent viewing connected TV content by brand in the United States. This dominance is not just limited to their standalone streaming sticks but extends to the numerous television sets that use the Roku operating system.

Over the last year, Roku reported approximately $5 billion in revenue, with advertising accounting for half of that figure. The business has transitioned away from hardware, which now represents only about 11% of their revenue, toward a model built on ad sales, data collection for targeted marketing, and a share of subscription fees from third-party services like Netflix.

For Fox, the acquisition provides a path to the top tier of the streaming market. By combining its existing viewership with the Roku Channel, Fox moves into a competitive position alongside industry leaders, trailing only YouTube in terms of market share and gaining ground on Netflix and Paramount. The company expects significant growth in both connected TV advertising and streaming subscriptions through this integrated platform.

Based on the details provided in the investor call, users should expect noticeable changes to the Roku interface. One of the key shifts involves the promotion of Fox-owned content and properties. The current “top picks” and algorithmic recommendations will likely favor Fox programming over other partners. The sports section is also expected to feature a heavier concentration of Fox Sports content. There is a possibility that the traditional grid of apps, which many users prefer for its simplicity, may be moved further down the screen to make room for these promoted recommendations and additional advertising spaces.

While Fox representatives stated they intend to maintain a level of “neutrality” toward other providers like Disney—partly because Roku earns revenue from selling those subscriptions—the emphasis on organic-looking Fox recommendations suggests a more curated experience. The core functionality of the devices is expected to remain intact, as the value of Roku has always depended on its ability to host a wide variety of streaming services. However, the path a user takes to find their preferred apps is likely to require navigating around Fox’s priorities.

The acquisition is structured as a mix of 60% cash and 40% stock, valuing Roku at $160 per share. Once the deal is finalized, Fox shareholders will own 73% of the combined entity, while Roku shareholders will hold the remaining 27%. Anthony Wood, the founder of Roku who previously established ReplayTV, is slated to remain on the board.

The deal still requires approval from shareholders and government regulators. with the companies anticipating the deal closing sometime in 2027. Watching how the interface evolves as we approach the closing date will provide the best indication of what the future of this hardware will look like in a Fox-owned ecosystem.

Let’s Talk About Windows 11’s Bloated Notepad and a Fix!

A few weeks ago, I published a video about Microsoft’s recognition about how bloated Windows has become. You don’t have to look much further than the current status of the Notepad app to see that bloat in action.

In my latest video, we take a look at Notepad.exe’s feature creep and how you can download a free alternative that brings the simple version we have all come to know and love back.

Upon opening Notepad now, the software automatically loads every document previously accessed, syncing them across a Microsoft account and putting each one in its own tab. It includes formatting options, a tabbed interface, and even integrated AI tools like Copilot.

This shift moves away from the utility’s original purpose. When I first used Notepad on Windows 3.1 in the early 1990s, it was a straightforward tool for taking quick notes. It handled one document at a time, requiring the user to close one file before opening another. This simplicity remained largely unchanged through several iterations of the operating system, from the original Windows 1.0 through Windows 10. The utility functioned effectively for decades because it remained focused on basic text entry without additional overhead.

The technical demands of the current version are also notable. In my recent observations, running four small text files in the updated Notepad consumed roughly 87 megabytes of RAM. This footprint appeared to grow the longer the application remained open, adding 10 megabytes during my testing period without opening any additional files, which may suggest background telemetry or memory management issues. To put this in perspective, the entire computer system I used in 1992 operated on only 4 megabytes of total memory. While some users might find the added features beneficial, the increased resource consumption seems high for a simple text editor – especially as Microsoft’s more robust text editor, WordPad, has been removed with its features now added to Notepad.

For those seeking a return to a more minimalist experience, an alternative has emerged from the open-source community. Dave Plummer, a retired Microsoft software engineer, has developed an application called RetroPad. It is designed to function like the classic version of the software, prioritizing speed and a minimal footprint. In a direct comparison, RetroPad used approximately 1.7 megabytes of memory to handle the same text that required nearly 88 megabytes in the official Microsoft version.

The application is currently available via GitHub, where the executable can be downloaded from the project’s binaries folder. Plummer is also developing a version in assembly language to further reduce the executable size, but I noticed its memory footprint was significantly larger than the other version.

For users who find the modern updates to be an unnecessary complication, this project offers a functional way to return to a simpler workflow.

Is the FCC Coming for Burner Phones & Prepaid Accounts?

I have been following reports regarding the Federal Communications Commission’s stance on the future of prepaid mobile devices and sim cards, often referred to as “burner phones.” While some headlines suggest a total ban is imminent, the reality is the FCC is currently weighing requiring that individuals identify themselves with a government ID when purchasing these devices and plans.

In my latest video, I take a look at what the FCC is considering and what the implications might be.

The core of this issue lies in the persistence of illegal call traffic. Many of us are familiar with the daily influx of fraudulent text messages and automated calls, ranging from “pig butchering” investment schemes to fake government notifications. To facilitate these operations, bad actors frequently utilize “SIM farms”—setups where hundreds of SIM cards are loaded into machines to send out bulk messages efficiently. Currently, it is relatively easy to walk into a convenience store, pay cash for a prepaid SIM card, and gain access to the cellular network with total anonymity.

Under a new proposal, the FCC is looking to tighten the requirements for these purchases. The proposed rules would require providers to obtain a customer’s name, physical address, and a government-issued ID number, along with an alternate phone number, before activating service. This would apply to both new and renewing prepaid customers. Furthermore, the commission is considering disqualifying the use of P.O. boxes, mail forwarding services, and shared office locations as valid addresses, arguing that these do not sufficiently verify a user’s identity.

There are, however, significant privacy implications to consider. Certain groups rely on the ability to remain anonymous for their safety and professional integrity. This includes whistleblowers, domestic violence survivors who need to keep their location hidden from abusers, and journalists working on sensitive assignments. By requiring a government ID and a physical home address for every prepaid phone, the barrier to maintaining that privacy becomes much higher.

Groups like the Electronic Frontier Foundation have expressed skepticism about the effectiveness of such a move. The argument is that criminals will likely not be deterred by these requirements; instead, they may simply use stolen identities from the numerous databases already available on the dark web to bypass the system. This creates a risk where the policy could inadvertently incentivize more identity theft while doing little to stop the actual robocalls.

I find the focus on the end-user somewhat misplaced. Mobile carriers have the technical capacity to identify when hundreds of SIM cards are operating from a single location and connecting to the same cell tower to blast out thousands of messages. Concentrating on carrier accountability and the detection of SIM farms might address the root of the problem more effectively than collecting the personal data of every individual user.

Within the commission, there is a visible divide on how to proceed. While the two Republican commissioners (Chairman Brendan Carr and Commissioner Olivia Trusty) have labeled this a top priority for consumer protection, Democrat Anna Gomez has raised concerns regarding the privacy of those who use prepaid services legitimately. Gomez feels the onus should be on the carriers to detect fraudulent traffic.

As this proposal moves through the rule-making process, the commission is seeking public comment on dockets 17-59 and 02-278. In the video I demonstrate how you can submit public comment on this docket.

So while this is not the end of burner phone, the era of anonymous entry into telecommunications network may be nearing an end. I will continue to monitor the docket as this proceeding makes it through the process.

See more analysis pieces like this here!

Local AI is Finally Usable! Real-World Workflows on a 5-Year-Old Mac with Google Gemma

For the past few years, I have been downloading local AI models to determine if they could handle practical automation tasks or summarize long-form content. Historically, these experiments have been unsuccessful, with the models typically failing to provide comprehensive results or losing track of the original context. However, recent developments in model optimization, specifically on Apple hardware, have changed the baseline for what is possible on a personal computer.

In my latest video, I demo running Google’s latest Gemma 4 model, a 26-billion parameter “mixture of experts” model optimized for the Mac using the MLX framework on my 2021 Macbook Pro with an M1 Max and 32GB of RAM.

Check it out here!

I observed the model generating approximately 50 tokens per second. While this is slower than a high-end cloud-based system, it represents a very usuable generation speed for a local setup. The unified memory architecture of the Mac allows the GPU to access data efficiently, which is why these older machines remain relevant for AI tasks that would otherwise require significant cloud computing resources.

During my testing, I provided the model with a transcript from a recent video to see if it could produce a coherent summary. Unlike previous local models that often provided incomplete or erratic responses, this model maintained a consistent narrative and adhered strictly to the provided text. I also tested it with a dense legal document from an FCC docket. After processing a large amount of extracted text, the model was able to delineate the key arguments of the filing and, upon further prompting, condensed the information into a concise executive summary.

I also examined the model’s vision capabilities using a tool called MLX studio, which supports image analysis. I uploaded a photograph with some friends and I in front of a space shuttle and asked the model to describe the scene. While it misidentified the vehicle as a Dreamchaser—a different type of spacecraft—the level of detail was a step forward from earlier local models that often provided much less accurate descriptions. This functionality is particularly useful for my ongoing project to index a large archive of digital photos dating back to 1997. Using a local model for this type of organization could potentially eliminate the costs and privacy issues associated with the thousands of API calls required for cloud-based indexing.

To test the model’s utility in a production environment, I integrated it into my N8N automation server. I currently use a cloud-based AI with my N8N server to scan news feeds and identify relevant stories for my daily work. I ran a portion of this same workflow using the local Gemma model to see if it could replicate the results. It took approximately three minutes to process the news briefing. Although the results were not quite as polished as those from the cloud, the model successfully identified unique stories and avoided duplicated stories about Apple’s WWDC event that were being published at the time.

Google appears to be prioritizing the development of effective local models more than some of its competitors, providing a way for users to utilize AI without incurring expenses beyond the electricity required to run their own hardware. Seeing a 26-billion parameter model function with this level of stability on a five-year-old laptop has caused me to rethink my existing workflows. I am now looking at which of my daily tasks can be moved away from the cloud and managed entirely on my own hardware.

See more videos like this here!

California Backing Off on Linux Age Verification ?

I recently followed up on the developments regarding California’s age verification law, which originally sought to require all operating system providers—including those in the open-source community—to collect the birth dates or ages of their users. A new amendment is currently moving through the California legislature that attempts to address some of the concerns raised by the initial language, specifically by creating a carveout for open-source providers.

We take a look at that in my latest video.

The proposed amendment adds a section to exempt any person or entity that distributes an operating system or application under license terms allowing a recipient to copy, redistribute, and modify the software. Under this definition, open-source projects would likely be exempt from the data collection requirements. However, the scope of this exemption raises questions about major platforms like Android. While Google layers closed-source services onto its devices, the underlying operating system is redistributable and modifiable, which could potentially place it within this new exemption.

Despite the move to protect open-source software, other parts of the amendment introduce new privacy considerations. The updated language specifies that operating systems must share a user’s age information with several third parties, including application stores, developers, browser providers, and internet website operators. Because website operators in California may be held accountable for the age of their users, they are likely to request this data as a matter of course to ensure they are in compliance with the law.

The amendment also places the onus on developers and website operators to act on their own data should it conflict with the age information sent by the operating system. This suggests that the data provided by the operating system may not be treated as a definitive source, which could encourage websites to collect even more personal information independently to avoid legal trouble. Furthermore, the law does not currently appear to restrict these developers or website operators from sharing that age data with other third parties.

This legislative activity passed the California State Assembly last week by a vote of 68 to 1 and is now heading to the State Senate. It is expected to be signed by the governor before the original law takes effect this fall. This is part of a broader national trend, as seen in Texas where the state is currently taking legal action against platforms like Discord to enforce mandatory age verification.

As state governments continue to move forward with these requirements, the impact on individual privacy remains a primary point of discussion. While these laws aim to regulate access, they may also lead to a shift in how people use the internet. I will be watching to see if these measures result in a rise of decentralized, open-source applications that replicate the functionality of major social platforms while operating outside the reach of centralized data collection mandates.

Big Changes Coming to Android Sideloading

I have long valued the Android operating system for its openness, particularly the ability to sideload applications outside of the Google Play store. Whether I am installing a PlayStation 2 emulator on a budget tablet or adding specialized benchmarking tools to a Google TV device, the process of downloading an APK file and bypasssing the official storefront has been a hallmark of the platform.

But this flexibility is set to put under significant restrictions as Google prepares to implement a new policy regarding how apps are distributed and installed outside the Play Store.

See more in my latest analysis video!

Under the new rules, developers who wish to offer apps for sideloading will be required to verify their identity with Google, providing legal names, addresses, and official government identification. For organizations, this includes providing a Dun’s number and a verified website. Even if an app is hosted on a private website rather than the Play Store, it must be registered with Google and signed with a private key. While there is a limited distribution tier for small-scale projects involving fewer than 20 devices, broader distribution will require a registration fee, currently set at approximately $25.

For the average user, the process of installing an app that hasn’t been registered through this process is becoming notably more complex. When attempting to sideload an unsigned application, a user must first confirm they are not being coached by a third party to disable security settings. This is followed by a mandatory device reboot and full reauthentication of their Google account to terminate any potential remote access or active calls. Most notably, a 24-hour waiting period is then triggered. Only after this day-long delay can the user return, verify their identity via biometrics or a PIN, and finally complete the installation.

These protections can be enabled temporarily for seven days or indefinitely on a per-device basis. Google maintains that these steps are necessary to combat rising instances of malware and social engineering, citing examples like banking fraud and malicious software disguised as wedding invitations. By adding these layers of friction, the company aims to protect vulnerable users who might be pressured by scammers into installing dangerous software. Yet, for those who understand the risks and simply want to maintain control over their hardware, these changes introduce a substantial inconvenience.

Opposition to this shift is already organizing under the “Keep Android Open” banner. This group argues that Google is retroactively locking down an operating system that was originally marketed as the open alternative to Apple’s closed ecosystem. A point of concern for many is that these changes are not being implemented through a standard Android OS update. Instead, they are being rolled out via Google Play Services. This means the new rules can be applied to billions of existing devices without a full firmware overhaul. The rollout is scheduled to begin this month in regions including Brazil, Indonesia, Singapore, and Thailand, eventually expanding globally.

The tension here lies between individual autonomy and collective security. While Google’s stated intent is to minimize liability and protect users from financial theft, the methods chosen may fundamentally alter the relationship between the user and their device. I would prefer to see these options managed at the account level, allowing experienced users to opt out of the 24-hour waiting period while keeping protections active for others. As these policies take hold, we may see a rise in interest for alternative, open-source mobile operating systems like GrapheneOS, which prioritize privacy and side-loading without Google’s oversight.

Plex at a Crossroads?

I have spent a significant amount of time covering the evolution of Plex, both as a user of over a decade and as a creator covering the home media space. I got my lifetime Plex Pass in 2015 and have been a user of Plex longer than that.

Recently, the company announced a substantial shift in its pricing model that signals a turning point for its original core product. On July 1, the cost of a lifetime Plex Pass will increase from $250 to $750. This move effectively positions the lifetime license as a deterrent rather than an incentive, clearly designed to steer new users toward recurring monthly or annual subscriptions.

In my latest video, I take a look at this new strategy and provide some of my own analysis on why Plex is doing this. While I have maintained a long-standing sponsorship relationship with Plex, my analysis of this change is based entirely on my own research and opinion – I did not have any input from the company.

It is important to distinguish between the two halves of the current Plex ecosystem: the free, ad-supported streaming side that offers live channels and on-demand content, and the personal media server software that they started with in 2008. This price hike affects only the latter, and specifically the premium features associated with the media server.

When the lifetime subscription was introduced in 2012, it served a specific purpose. As a small startup, Plex needed to demonstrate a paying user base to investors while catering to a community that traditionally avoids subscription models. Plex initially offered the Plex Pass at $3.99 a month, but received backlash from users who preferred on a one-time purchase. So Plex offered a limited time $75 lifetime license that later became a permanent offering.

My own data collection suggests that this early success has created a long-term sustainability issue. In a recent informal poll of my audience, 91% of Plex Pass holders reported being on a lifetime plan, many of whom paid once a 5-10 years ago and have not had to pay more since, despite receiving constant software updates and server maintenance.

Maintaining a modern media server is an expensive endeavor involving a team of developers in a competitive labor marketplace. From a strictly economic standpoint, the lifetime model has ceased to be viable for the personal media server side of the business. While the sky was the limit in 2012 for new users, one could argue that today that potential market is a lot smaller due to most potential users being acquired, and generational differences in how Gen Z and Alpha consume media.

We are seeing Plex react to this by shifting its focus toward the “FAST” (Free Ad-supported Streaming Television) market. Industry data shows these channels now capture nearly 7% of U.S. television viewing, a sector worth billions in potential ad revenue.

A look at the company’s recent history of investment confirms this shift. After years of modest growth, Plex received significant infusions of cash—totaling tens of millions of dollars—starting around 2021. These investments coincided with their pivot toward global streaming and ad-supported video. Today, the Plex homepage barely mentions personal media servers, focusing instead on content discovery and streaming.

This leads to a question about the future of the home server. If the new pricing fails to convert users into recurring subscribers, the company may reach a crossroads. One potential path is the “minimally viable server” model. We are already seeing hints of this through the release of a robust open API, which allows third-party developers to create their own client interfaces. Apps like Plezy are already utilizing this, offering a streamlined, community-driven experience that connects to the Plex backend without the streaming additions.

Ultimately, the personal media server is likely to survive, but its form may change. Whether it remains a primary focus of development or becomes a backend utility for independent developers will depend on how many new users are willing to trade the one-time payment for a monthly commitment. For those of us who have relied on the platform for years, the next year will reveal exactly how Plex intends to balance its roots with its aspirations for the mass market.

“The Marketplace Took it as Far as it Could” – Broadcasters Admit NextGen TV Defeat

The over-the-air television drama continues as broadcasters continue to stumble rolling out the new ATSC 3.0 / NextgenTV broadcast standard. The original plan involved a market-based transition where both ATSC 1.0 and 3.0 signals would run in parallel, with the hopes that technical advancements of 3.0 would lure consumers to purchase new hardware and adopt the new standard.

But, a decision by major broadcasters to encrypt the new standard has created significant hurdles for both manufacturers and viewers. And now, a major broadcast group admits the market test has essentially failed and a government mandate is needed.

See more in my latest analysis video!

Ahead of this year’s National Association of Broadcasters (NAB) show in Las Vegas, broadcasters touted a new “affordable” tuning box program that they said would accelerate consumer adoption of DRM certified tuners. But as I noted in my prior video, they had very little on display beyond some circuit boards.

In a follow-up interview with TVTechnology.com, broadcast owner association Pearl TV made a stunning admission through their president Anne Schelle :

“We’re in a situation where the marketplace took it as far as it could, and this is what’s needed in order to really fully realize a full transition. So that’s basically my answer to that.”

The industry is now looking for a government mandate to move the transition forward despite consumers rejecting the expensive and limited hardware capable of decrypting their content. Broadcasters are advocating for a sunset of the 1.0 standard by 2028 in major markets, with the rest of the country following by 2030. They are also requesting that the FCC mandate the inclusion of expensive DRM certified ATSC 3.0 tuners in all new television sets. So much for the free market…

Part of the disconnect appears to stem from broadcaster misunderstanding of consumer behavior. Research cited by broadcast advocacy groups suggests consumers are willing to pay $60 for a basic converter box that tunes into a single channel at a time. My own observations of current market trends show a different preference.

Currently, the most popular items on retail platforms like Amazon are $30-40 ATSC 1.0 boxes that include recording and playback features that will be lacking in the new ATSC 3.0 “affordable” program. And selling just as strongly are gateway devices like the Tablo or HDHomeRun (compensated affiliate links). These devices allow users to watch TV on any of their devices (Smart TVs, phones, tablets etc) in the home through a single antenna connection – a level of flexibility that current encryption requirements do not allow.

An Amazon search for ATSC 3.0 tuners ordered by sales popularity shows the SiliconDust ATSC 3.0 compatible gateway that broadcasters refuse to DRM certify is outselling a certified ADTH tuning box by a rate of 10 to 1 !

The DRM encryption is at the center of this friction. When the new standard was unencrypted, there was early interest from various makers of tuning hardware. Now, the technical requirements to satisfy these DRM measures have made it difficult for manufacturers to produce affordable, high-functioning equipment. Even existing products that promised gateway functionality for encrypted signals have seen those features delayed repeatedly.

While broadcasters are waiting for a signal from regulators to force a transition, the current lack of adoption suggests that the existing encryption framework does not align with how people actually watch television in 2026.

This is not a market in need of a government mandate; it is a market that will thrive once large broadcasters stop interfering with it.

Utah Age Verification Law Targets VPN Users

I have been closely following a significant shift in how states are approaching internet privacy and content regulation. This week, a new law takes effect in Utah that requires adult content websites to verify the age of their users. While similar laws exist in states like Texas and Florida, Utah is introducing a provision that changes the technical landscape for both users and website operators.

This is the subject of my latest tech analysis video.

What distinguishes this law is its specific focus on location-masking tools. Traditionally, when a state passes such a mandate, many websites simply block any traffic originating from an IP address within that state to avoid liability. Utah, however, is now asserting that its regulations apply to anyone physically located within the state, even if they are using a Virtual Private Network (VPN) or a proxy server to appear as though they are browsing from elsewhere. This places the burden of identification squarely on the website operators rather than the individuals.

In my review of the legislation, I noticed that it requires operators to employ “commercially reasonable” methods to verify age, such as digitized ID cards or third-party verification services. The challenge here is technical. Experts in the field, including major VPN providers, have pointed out that it is essentially impossible for a website to identify every VPN IP address in real time. Because these addresses change constantly, a website cannot reliably know if a user is appearing from a different state or is a Utah resident using a masking tool. This leads to a scenario where websites might feel forced to require identification from every single visitor, regardless of their apparent location, simply to avoid the risk of heavy fines from Utah.

The law includes language intended to protect bonafide news and public interest organizations, but the definition of what qualifies as “bonafide” remains at the discretion of government officials. This introduces a level of subjectivity that many constitutional rights organizations find concerning. While the current focus is strictly on adult content, the legal framework provides a potential template for future restrictions on other types of controversial material. I have seen how legislative language can be adjusted over time; a few small changes or creative legal interpretations by courts could potentially expand these requirements to any content deemed to lack certain artistic or political value for minors.

This development in Utah reflects a broader trend I have been tracking across the country. There are ongoing discussions in other states about moving age verification to the operating system level. If that were to happen, a user’s computer or smartphone would act as a permanent digital ID, authenticating their identity to every website they visit. This would move the internet away from its historically anonymous roots toward a model of constant authentication.

While the Supreme Court has previously upheld the constitutionality of age verification laws in other states, Utah’s specific attempt to regulate VPN usage presents a new set of legal and technical questions. It remains to be seen how the courts will view a mandate that requires companies to solve a technically intractable problem.

As these laws proliferate, the focus may shift from whether content should be restricted to how the very infrastructure of the internet is being redesigned to enforce those restrictions.

Music Labels Lose a Big Piracy Case at the Supreme Court

A twelve year legal battle about piracy between the music industry and internet service providers has finally come to an end by the US Supreme Court. The court overturned a $1 billion verdict against Cox Communications, a decision that has significant implications for how we understand copyright liability and the responsibilities of those who provide our internet access.

See more in my latest video!

The history of this conflict dates back to the early 2000s when the music and film industries struggled to adapt to the rise of digital file sharing. Initially the music industry started suing their own customers, hitting them with federal lawsuits. One instance involved a 12-year-old girl having to cough up $2,000 for a settlement and another where a woman was held liable for hundreds of thousands of dollars for sharing 24 songs.

At the time, piracy was often driven by a lack of convenient, legal digital options. Physical media sales were declining, and digital purchases were often restricted by digital rights management, or DRM, which limited how and where consumers could listen to their music.

When the strategy of suing individual users failed to curb piracy or improve the industry’s public image, the focus shifted toward where the money is: internet service providers. Organizations representing the record and motion picture industries established the Copyright Alert System, partnering with major ISPs to issue warnings to users who were sharing copyright material.

Cox Communications did not participate in this program and that put a target on their back. A lawsuit was filed in 2014 against the ISP with music label BMG arguing that Cox should be held liable for the infringement occurring on its network. BMG claimed that because Cox did not adequately respond to infringement notices, it lost the “safe harbor” protections usually granted to service providers under the Digital Millennium Copyright Act.

A federal jury originally sided with BMG, awarding a billion-dollar verdict against Cox. However, the Supreme Court’s recent reversal of this decision centered on a specific interpretation of federal copyright law. Justice Clarence Thomas, who authored the decision, noted that while Cox may not have met the requirements for DMCA safe harbor protection, other aspects of federal law do provide for an adequate defense. The ruling clarifies that a service provider is only liable if it intended for its service to be used for infringement or if it marketed itself specifically for that purpose. Because Cox provides a general-use internet service and did not induce its users to pirate material, the court found they could not be held responsible for the specific copyrights violated by their subscribers.

This development changes the landscape for other ISPs as well. They now have a defense beyond the safe harbor provisions, meaning they may not feel the same pressure to react to every automated infringement notice they receive. I suspect this will lead to a decrease in the haphazard distribution of warnings to account holders. While direct lawsuits against individuals may still occur, particularly in cases involving large volumes of distribution, the era of trying to hold the entire infrastructure of the internet accountable for individual user behavior seems to be shifting.

It should be noted that the music industry eventually found success not through litigation, but by listening to consumer demand. When they removed DRM from digital music purchases and embraced affordable streaming services, revenues skyrocketed. It is a reminder that market accessibility often addresses the root causes of piracy more effectively than legal threats.

As other industries, such as broadcasting, consider implementing new restrictions on content, the industry changes that have taken place since this case was filed suggests that focusing on what the customer wants is a more sustainable path than pursuing multi-billion dollar judgments against service providers. This ruling brings a level of technical and legal sanity back to the conversation regarding how we use and access the internet.

ATSC 3 Update: Dueling Surveys & Contact Your Congressperson!

In my latest ATSC 3.0 update video, I take a look a dueling consumer surveys from the Consumer Technology Association (CTA) opposing TV tuner mandates and another from broadcasters suggesting consumers will be more than happy to buy expensive hardware when the rug is pulled out from under us.

Pearl TV, an organization representing broadcasters, recently published a survey indicating that most viewers would be willing to purchase a low-cost converter box, estimated at around $60, rather than lose access to free television. When looking at current market behavior on platforms like Amazon, consumers are choosing tuners priced as low as $30 that include recording capabilities—a feature the proposed $60 DRM-compatible basic boxes would lack according to Pearl.

Pearl’s survey results released so far lack the “cross-tabs” that would reveal all of the questions asked and answered. Only a small amount of data appears in the Pearl TV slide deck, yet the methodology slide reveals the median time to complete the survey was 16 minutes. Clearly they are holding a lot of data back.

On the other side of the issue, the Consumer Technology Association (CTA), which represents electronics manufacturers, argues against government mandates that would force the inclusion of expensive ATSC 3.0 tuners in every television. Their research suggests that while antenna usage has seen a slight uptick to about 15% of households, awareness of the NextGen TV brand remains low. Only 5% of respondents claimed to be familiar with the term, and the vast majority had never seen the official logo. This matches my own observations in retail environments, where the technology is rarely a primary concern for consumers compared to the availability of streaming applications on a particular device.

As the National Association of Broadcasters (NAB) prepares for its annual trade show, the lobbying effort has intensified. Recently, 91 members of the House of Representatives signed a letter pressuring the FCC to move forward with the transition. This indicates that congressional offices are hearing primarily from broadcast interests. My review of the signers shows a bipartisan group of representatives from across the country, many of whom may not be fully briefed on the technical limitations and costs these encryption standards impose on their constituents.

My suggestion? It’s time to reach out to your member of Congress. My suggestion would be to forward along what you’ve already filed with the FCC. Short of that you can use some sample language that I put together here. If you’re looking for a one stop shop for finding and contacting your representatives, Democracy.io has a helpful utility for doing so.

The FCC remains cautious. Currently, Commissioner Olivia Trusty is the only official scheduled to appear; she is set to deliver a brief 10-minute presentation on ATSC 3.0 at the Las Vegas Convention Center.

With consumer adoption stuck in neutral, thanks to a complicated DRM encryption scheme, broadcasters are now going to rest their hopes on political pressure to try and force their private regulatory regime on the American people. That’s why it’s important for all of us to educate our representatives on what is really going on.

US Effectively Bans All New Router Products

The U.S. government has effectively implemented a ban on most new routers entering the domestic market, a move driven by a national security determination regarding risks posed by networking equipment produced overseas. While the order is broad, it is important to note that existing models already approved by the FCC—such as those currently found on retail shelves—are not prohibited from being sold or imported. The restriction specifically targets new products that have not yet received FCC certification.

I dive into the order and what it might mean in my latest video.

This action follows long-standing concerns from both the Biden and Trump administrations regarding vulnerabilities in consumer networking hardware.

Specifically, federal authorities pointed to prior sophisticated cyberattacks, such as those the Vault, Flax, and Salt Typhoon attacks, which utilized botnets of small office and home office (SOHO) routers to conceal the origin of attacks against U.S. critical infrastructure. In many cases, these attacks exploited “end-of-life” routers that no longer received security firmware updates from their manufacturers.

To gain authorization for new products, manufacturers must now apply for a conditional approval from the DoW/DOD or DHS. This process requires an extensive disclosure of the company’s supply chain, including a detailed bill of materials, the country of origin for all components and software, and an identification of any single points of failure in the manufacturing process.

Beyond security audits, the government is requiring a commitment to domestic production. Applicants must submit a time-bound plan to establish manufacturing and assembly operations within the United States. This includes detailing planned capital expenditures and providing progress reports on onshoring efforts. Currently, the list of compliant router manufacturers remains empty, as drone makers are the only technology to have successfully navigated a similar regulatory process thus far.

The definition of a “router” under this regulation is tied to NIST standards, focusing on devices marketed for residential use and customer installation. This creates a technical distinction for hardware such as small-form-factor computers; while these devices can be configured to function as routers using open-source software like pfSense, they are not currently subject to the ban because their primary marketed purpose is as a general-use computer.

Industry reactions have been varied according to a report in PC Magazine. TP-Link, which had previously been a specific focus of government scrutiny, expressed confidence in its supply chain and stated it welcomed an evaluation that applies to the entire industry. U.S.-based Netgear commended the action, suggesting that the regulations could lead to a more secure digital future. Both companies will likely benefit from the action – TP-Link gets to survive and Netgear has the capacity to comply with the domestic onshoring when many of their competitors may not.

I will be monitoring the FCC’s exception list to see which manufacturers are the first to successfully onshore their operations and return new hardware to the pipeline. In the meantime, the focus remains on whether these requirements will effectively eliminate orphaned firmware and provide the level of transparency the government is seeking.

Did Microsoft Admit Windows 11 is Too Bloated?

Microsoft is beginning to acknowledge the growing concerns regarding bloatware and performance issues within Windows 11. Windows head Pavan Davaluri recently published a blog post committing to a new standard of Windows quality. In my latest analysis piece, I dive into what Microsoft thinks the problem is and I offer some of my own experiences.

Check it out here!

While Davaluri’s official roadmap highlights specific improvements like increased taskbar customization and a more dependable File Explorer, many of the everyday frustrations experienced by power users and system reviewers remain unaddressed.

The current onboarding process for a new Windows 11 PC takes over an hour, largely due to a gauntlet of updates and forced configuration screens. Even after the initial setup, users frequently encounter a secondary wave of background updates that can lead to audible fan noise and noticeable performance degradation on a brand-new machine.

Beyond the updates, the operating system’s interface is increasingly defined by a series of prompts designed to funnel users into subscription services and cloud storage. These “upsell” screens often prioritize the “Next” or “Accept” buttons, while the options to decline or keep files stored locally are presented in smaller, less prominent text.

OneDrive integration remains a primary point of friction. Even when a user expresses a preference to store files only on their local device, the system defaults to cloud syncing and backup, requiring a manual and repetitive process to disable individual folders. This persistent nudging extends to the Start menu and taskbar, which are frequently populated with icons for features like Copilot, Recall, and the Edge browser immediately following an update. The Start menu itself has become more cluttered, making it increasingly difficult to find what you’re looking for amidst a sea of promotional icons and unhelpful recommendations.

Even basic utility applications are not immune to this expansion of features. Notepad, a tool that remained virtually unchanged for decades, now includes tabbed windows, cloud synchronization requirements tied to a Microsoft account, and integrated co-pilot AI writing assistance. These additions, while intended to modernize the app, introduce new complexities and annoyances for something that doesn’t need any features. Similarly, background processes like the Xbox overlay continue to run by default, regardless of whether the user intends to use the computer for gaming.

While Microsoft’s new commitment to quality is a positive step, the current state of the operating system has led some to rely on third-party debloating utilities to reclaim system performance. There is also a growing awareness of the increasing user-friendliness of Linux distributions, which may be placing additional pressure on Microsoft to streamline its experience. As the company moves forward with its debloating efforts, the true measure of success will be whether it can reduce the constant stream of distractions and return to a more focused, efficient production environment.

I’m curious to see if these promised updates will actually thin out the layers of advertisements and background services, or if the primary goal remains centered on revenue extraction through service nudges.

ATSC 3.0 Update: More DRM Nonsense Filed with the FCC

The broadcast industry’s ongoing effort to encrypt the public airwaves is currently awaiting a decision from the Federal Communications Commission. In a recent ex-parte letter to the FCC, broadcasters cited the US Trade Representative’s 2025 Review of Notorious Markets for Counterfeiting and Piracy report to support their push for the ATSC 3.0 encryption standard. The report focuses heavily on live sports and the revenue lost to global piracy – but none of it indicates broadcast TV signals are being stolen.

See more in my latest ATSC 3.0 update video!

The report’s introduction references the NFL’s broadcasting agreements with networks like CBS, Fox, and NBC, which run through 2033. These contracts were signed without any provisions or assurances requiring future signal encryption, suggesting the league does not view over-the-air broadcasting as a primary piracy vulnerability.

The report provides three specific instances of piracy, including the FIFA World Cup, a mention of European soccer games being pirated and the 2017 Mayweather-McGregor fight. While the FIFA World Cup game was broadcast on television stations here in the USA, it is likely that it was pirated off of encrypted sources along with the other European soccer matches. And the Mayweather-McGregor fight was an encrypted Pay Per View event.

The government’s report cites data from Irdeto, a European company specializing in signal encryption for satellite and streaming providers. A review of their technical literature shows that modern piracy relies on methods like stealing session tokens, purchasing compromised account credentials on the dark web, or utilizing a technique known as CDN leeching.

These methods bypass the physical complexities of installing antennas to intercept local signals, demonstrating that for pirates encrypted content is easy to pirate than the unencrypted broadcast signals.

Furthermore, Irdeto’s guidance emphasizes the necessity of multi-DRM systems to ensure a frictionless viewing experience across different platforms. Currently, ATSC 3.0 DRM only supports Widevine, a Google technology. This single-DRM approach limits compatibility, leaving devices like Apple TV, Roku, Xbox, and standard computers unable to decode the encrypted broadcasts.

The push for encryption appears closely tied to the economics of broadcast retransmission fees. In Connecticut, for example, cable subscribers currently pay around $48.30 a month strictly for local channel access. Encrypting the over-the-air signals forces consumers to either maintain these cable subscriptions or purchase new, proprietary decoding hardware. Ahead of the upcoming NAB show, industry executives have discussed a proposed $60 tuner box. However, this device is expected to function solely as a tuner without DVR or gateway capabilities and cost three times as much as current tuning devices that do include DVR functions.

Broadcasters also point to the A3SA encoding rules, which currently permit time-shifting and recording. But these allowances apply only to content that is actively simulcast with the older ATSC 1.0 standard. Once the simulcast requirement expires, broadcasters provide are not committing to restricting or disabling recording capabilities entirely, shifting control of public airwave usage to a private entity.

The FCC is presently collecting public feedback on a separate but related sports broadcasting docket (26-45), which examines the impact of broadcasting practices on consumers and local market obligations. The comment period for this specific docket remains open for roughly another week, offering another venue for the public to submit their observations regarding how signal encryption may affect access to local sports broadcasts.

California Law to Require Age Verification on All Operating Systems (Including Linux)

Recently, a new California law signed by Governor Gavin Newsom caught my attention due to its potential impact on the open-source community, specifically Linux users. The legislation mandates that operating systems for PCs and other general computing devices like tablets and phones must implement a form of age verification during the initial account setup process.

I take a look at the implications of this law in my latest video.

While California is not the only state pursuing such measures—Texas recently faced legal hurdles over a similar law—this development raises questions about how open-source organizations, rather than traditional corporate entities, will comply.

The text of the California bill, which was signed on October 13, 2025, and takes effect on January 1, 2027, calls for an interface that requires the account holder to provide their birth date or age. This information generates a signal regarding the user’s age bracket—categorized as under 13, 13 to 16, 16 to 18, or over 18—to be read and enforced by applications within a covered app store.

The legislation defines an operating system provider broadly enough to include independent developers creating Linux distributions. Furthermore, a covered application store is defined as a publicly available online service, which could encompass command-line package managers used daily by Linux administrators.

From a practical standpoint, the current requirement relies entirely on self-reporting. Users are asked to volunteer their age, meaning anyone could input inaccurate information to bypass restrictions. Despite this, the penalties for non-compliance are clearly defined. Operating system makers face civil penalties ranging from $2,500 for negligent violations to $7,500 for intentional violations per “affected child.” If a developer has internal data showing a user’s actual age differs from the self-reported signal, they are legally obligated to act on that information or face action from the California Attorney General.

The implications for Linux distributions are notable. Commercial entities with a business nexus in California, such as the organizations behind Ubuntu and Fedora, will likely implement the necessary prompts to comply.

However, smaller projects face a different reality. Many distributions are maintained by volunteer groups without the financial resources or organizational structures to shield them from liability. Midnight BSD has already modified its software license to exclude California residents, but this legal maneuver may not satisfy California regulators if the software remains accessible for download within the state’s borders.

This legislative push is not confined to the West Coast. My home state of Connecticut is currently evaluating controls for minors on the internet, and Colorado is exploring operating system-level age verification. Texas attempted to regulate app stores before a federal court blocked the law, citing First Amendment concerns regarding its broad application. The absence of a unified federal privacy law has resulted in a fragmented regulatory landscape across different regions.

Historically, some internet users have responded to localized regulations by migrating to decentralized platforms. When Discord faced scrutiny over its age verification methods that included video selfies and government IDs, users began exploring open-source alternatives like Revolt and Matrix. These self-hosted and federated platforms demonstrate how technical communities can circumvent centralized data collection and restrictive legal mandates.

As the 2027 deadline approaches, it is likely that many Linux distributions will simply integrate a birth date or age prompt into their installation screens to mitigate legal risks. The technical challenge of passing that age signal consistently to various package managers and standalone applications remains a logistical hurdle. The coming months will test how far state authorities are willing to go in enforcing these mandates on the broader open-source software ecosystem.

ATSC 3.0 TV Encryption Update: The Final Arguments are In..

The final arguments regarding the encryption of over-the-air television have been filed with the FCC, and now it’s in the Commission’s hands. In my latest ATSC 3.0 analysis video, we take a look at how broadcasters responded to encryption concerns.

After reviewing hundreds of pages of documents, it appears the industry’s rebuttal to consumer concerns relies heavily on dismissing documented technical failures as mere anecdotes while asserting that encryption is necessary for the future of broadcast media.

The National Association of Broadcasters (NAB) has characterized reports of DRM failure—such as devices refusing to tune channels—as “early deployment friction” that does not justify stalling a national transition. They argue that individual complaints do not reflect systemic flaws. Yet, this stance contradicts the experience of users who have found that encryption often breaks the basic functionality of a television.

For instance, the A3SA, the body managing the encryption keys, argues that software-based devices require internet-based updates for bug fixes. This requirement introduces a significant dependency on internet connectivity for a medium that is marketed as being free and accessible over the air.

I recently demonstrated this vulnerability when an ADTH set-top box, which marketing materials claimed did not require an internet connection, failed to tune encrypted channels during a snowstorm. This inability to access weather information during an emergency challenges the industry’s assurance that content protection does not impede public safety messaging.

Beyond technical reliability, the industry posits that DRM is essential to combat piracy and secure content for sports broadcasting. The A3SA cited a media report claiming billions in losses due to piracy, yet the article in question focused on cable and streaming theft rather than the unauthorized capture of over-the-air signals.

Historically, DRM has been less about stopping piracy—which remains rampant despite encryption—and more about siloing users into specific hardware and software platforms. By making free over-the-air reception more difficult, broadcasters may be incentivizing consumers to stick with paid cable or streaming packages. Furthermore, claims that major sports leagues will withhold content without encryption are not supported by the current landscape, where broadcast contracts are being renewed for extended periods without such mandates being public.

There is also a significant question regarding the neutrality of the A3SA, which acts as the sole gatekeeper for approving tuning devices. While the organization claims to be neutral, it is comprised of major broadcast entities. This structure effectively allows the industry to pick winners and losers in the hardware market.

Manufacturers of popular gateway devices, such as Silicon Dust’s HDHomeRun, have been unable to secure certification under the current regime. The A3SA’s standards remain opaque and protected by non-disclosure agreements, preventing independent verification by even the FCC and effectively locking out devices that distribute signals across a home network to non-Android devices.

Ironically, while the industry argues that DRM protects consumers from the security risks of illicit streaming, the approved hardware itself presents security concerns. The ADTH box mentioned earlier was found to be running an Android security patch level from 2021, leaving it vulnerable to years of known exploits.

It seems unlikely the FCC will mandate a hard transition to ATSC 3.0 in the near term given the abysmal consumer adoption rates. The current ecosystem is too fragmented, and the cost and complexity of encryption have slowed adoption to a crawl.

And ultimately for consumers, they’re really not getting as much as they did during the prior transition. Back in the early 2000s TV viewers went from analog standard definition signals to digital high definition ones – a huge jump in visual fidelity. While ATSC 3.0’s HEVC video encoding is certainly noticeable for enthusiasts, I doubt most mainstream consumers will notice much of change.

I believe a probable outcome is a “frozen conflict” where the FCC ends the simulcast mandate, allowing stations to voluntarily switch to 3.0 if they choose, while potentially authorizing more efficient video codecs like MPEG-4 for the existing ATSC 1.0 standard.

This would allow the legacy standard to improve and remain viable, effectively leaving ATSC 3.0 to succeed or fail on its own merits without a government mandate forcing consumers to upgrade. We may end up with a better-looking version of the television service we already have, while the next-generation standard struggles to find its footing.