Normal view

Received — 1 July 2026 Daring Fireball

The Talk Show: ‘Taking Drugs to Get Fat’

1 July 2026 at 17:48

The great John Moltz returns to the show. Topics include Apple’s hardware price hikes in response to the global RAM/SSD shortage, and some spitballing on what we like about the UI changes in the MacOS 27 Golden Gate beta.

Sponsored by:

  • Coax: Defeat the tyranny of choice. Channel surf your Plex server. Relax with Coax.
  • Even Realities: Even G2, the everyday display smart glasses. Use promo code talkshow to save 10% off the R1 Ring and/or Even Clip.
  • Squarespace: Save 10% off your first purchase of a website or domain using code TALKSHOW.

404 Media: Vulnerability in iCloud’s ‘Hide My Email’ Reveals Peoples’ Real Email Addresses

1 July 2026 at 16:42

Joseph Cox, reporting for 404 Media:

404 Media is not revealing the exact details of the vulnerability because it can still be exploited as of Monday, when 404 Media verified the issue with one of our own hidden email addresses.

“Apple Hide My Email is leaking email addresses that are supposed to be hidden. We reported the issue and replication instructions to Apple over a year ago. We don’t know why it hasn’t been fixed, but we don’t feel comfortable waiting any longer. Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” Tyler Murphy, the co-founder of EasyOptOuts, which discovered and reported the issue to Apple, told 404 Media. [...]

To test the issue I generated a new Hide My Email address and provided it to Murphy. Around five minutes later, he replied with my real email address linked to my Apple account which was supposed to be hidden.

“We don’t know the full scope of the issue, but in our limited tests with volunteers, 100% of Hide My Email addresses were exploitable,” Murphy said.

Not good. Especially the “We reported the issue and replication instructions to Apple over a year ago” part.

(Is this possibly related to the WWDC news that Apple is merging the domain names used for Sign In With Apple and Hide My Email? I can’t see how, but who knows? I suspect the motivation behind the SIWA and HME domain merger is merely convenience, but without an explanation from Apple we’re left to conjecture.)

Update: The original report from the founders of EasyOptOuts.

Gnome

30 June 2026 at 22:54

Gnome is a deceptively clever animated GIF app by Lex Friedman:

The truest thing about animated GIFs is that they are a critical pillar of modern human communication, and yet getting one into a Slack message or an iMessage thread or an email reply usually requires opening a browser, navigating to a website, searching, right-clicking, copying, switching back, pasting, and apologizing for the delay. By then the moment has passed, and the joke is dead, and what was the point of any of this, really?

Gnome lives in your Mac’s menubar. You hit a keyboard shortcut. A little search window appears. You type what you’re looking for — weird al, shrug, nailed it, that’s a paddlin’ — and a grid of GIFs appears. Click the one you want. It’s now on your clipboard. Paste it wherever you were typing. Joke saved. World improved.

That’s really the whole app. It does exactly that, and it gets out of the way. No account. No sign-in. No newsletter. Just GIFs, faster.

When Friedman launched Gnome last month, it was Mac-only. Since then he’s already added an iOS version, and they sync/coordinate nicely. And if you have a local folder of GIFs, you can connect that to Gnome and it’ll show results from your personal curated library before those from Gnome’s online partner Klipy. You share the same local library on Mac and iOS, provided you choose a folder in iCloud Drive, Dropbox, or similar. The iOS version of Gnome offers an extension for Apple’s Messages app and an optional system-wide keyboard. On the Mac, you can disable the menu bar icon and just run Gnome like a regular app (if, like me, the last thing you need is another status icon in your menu bar).

It’s a really simple app with a deceptive amount of craft and attention to detail. I can’t say I send all that many animated GIFs, but Gnome is so nice it makes me want to send more. I dig it. $7 one-time payment on the web, or $8 in the App Store, and if you buy it on the web you can unlock it on iOS, and vice-versa.

Supreme Court Agrees to Review Apple’s Petition Regarding Civil Contempt Finding in ‘Apple v. Epic Games’

30 June 2026 at 22:12

Speaking of the Supreme Court’s end-of-term rulings, they today agreed to grant certiorari to Apple’s petition from last month, ordering:

APPLE INC. V. EPIC GAMES, INC.
The petition for a writ of certiorari is granted limited to Question 1 presented by the petition.

Question 1 regarded the civil contempt finding — basically, whether Apple could be held in contempt for violating the spirit of the injunction by charging a commission on external payments when the letter of the injunction said nothing forbidding commissions on payments. Question 2 raised by Apple regarded the scope of the injunction — arguing that even if the contempt finding were upheld, that it should apply only to Epic, not to all developers in the U.S. App Store.

(I decided against mentioning it in my article last month, “The Fonts of the U.S. Federal Courts”, but in stark contrast to the handsomeness and dignity with which their decisions are typeset (in Century Schoolbook), the Court’s daily orders are, inexplicably, set in Lucida Sans Typewriter.)

Supreme Court Upholds Birthright Citizenship in 6-3 Decision

30 June 2026 at 21:40

Josh Marshall, writing at TPM (gift link):

As you’ve seen, the Supreme Court upheld the constitutionality of birthright citizenship by a 6 — or perhaps 5½ — vote margin. See Kate Riga’s report on the majority decision and Josh Kovensky’s piece on the dissenters’ goal of doing away with birthright citizenship. I repeat my point from yesterday which is that the occasional non-corrupt decision doesn’t make the Court any less corrupt or in need of reform. In this case, in a sane world, the dissents from Neil Gorsuch, Samuel Alito and Clarence Thomas would on their own be sufficient basis for impeachment and removal from office. One might as well believe or pretend to believe that the federal senate is unconstitutional despite its being unambiguously written into the structure of the document itself. The level of abuse of power that is the basis of these dissents can only be seen as criminal in nature and grows from the culture of corruption and impunity that now reigns on the Court.

The 14th Amendment starts:

All persons born or naturalized in the United States, and subject to the jurisdiction thereof, are citizens of the United States and of the State wherein they reside.

The idea that the plain meaning of the birthright citizenship clause of the 14th Amendment was even debatable would have been laughable just 15 years ago. And, hopefully, soon, will be laughable again. It’s like arguing that the clear language of the 19th Amendment doesn’t guarantee women the right to vote. It’s a farce that this case even went to the Supreme Court, let alone that these three mooks dissented. (Alito and Thomas are lost causes; they’d vote for a Fourth Reich. Gorsuch I’m a little surprised by.) Needless to say, it’s rather unnerving that the majority required two — or one-and-a-half, depending on how you view Kavanaugh’s odd partial concurrence — votes from justices Trump put on the Court.

Marshall wrote a great explainer about this back in April (also a gift link):

Birthright citizenship is the unambiguous and certain law of the land. It is also good policy. What is less appreciated is that it undergirds the entire citizenship system in the United States, a country that keeps very, very little record of who is and isn’t a citizen in the first place. The only people who really have any clear record of their citizenship are naturalized citizens. You or I who were born in the U.S. might appear to have those. We have a passport or maybe some other document that you can only have as a citizen. But that is almost always because we said we were a citizen or we provided some document that only had any significance on the basis of birthright citizenship. Usually, of course, that’s a birth certificate. That’s where the factual conversation ends. It is the lynchpin that makes the entire U.S. citizenship system work in the absence of really any record keeping. [...]

Quite apart from the constitutional and civic merits, the whole fabric of U.S. citizenship falls apart without the anchor of birthright citizenship.

The only proof that I’m a U.S. citizen is that I was born here. My birth certificate names my parents but doesn’t say anything about their citizenship. Likewise with their birth certificates. That’s how citizenship in this most remarkable of nations works.

★ The Supreme Court Rules That Law Enforcement’s Use of ‘Geofence Warrant’ Was a ‘Search’ (But May Be Moot, Technically, Since 2024)

30 June 2026 at 20:52

Amy Howe, writing at the ever-excellent SCOTUSblog:

The Supreme Court on Monday ruled that when law enforcement officials used a “geofence warrant” — a warrant that instructed Google to provide location data for cellphone users who were near a particular place during a specific time period — to obtain evidence used to convict a Virginia man of a 2019 bank robbery, they conducted a “search” for purposes of the Fourth Amendment. By a vote of 6-3, the justices sent Okello Chatrie’s case back to the lower court for it to consider whether, as the Fourth Amendment requires, the search was “reasonable.”

Writing for the majority, Justice Elena Kagan emphasized that “[a]n individual has a reasonable expectation of privacy in records about his cell phone’s location, and police intrude on that constitutionally protected interest when they demand the information — even though for only a limited time, and from a third-party tech company.” [...]

The issue at the center of Chatrie v. United States arose after a man armed with a gun entered a federal credit union outside Richmond, Virginia, and gave the teller a note demanding money. He made off with nearly $200,000, but law enforcement officials did not have any leads until they served Google with a geofence warrant, which directed the tech company to provide location data for cellphone users who were near the bank at the time of the robbery.

I agree, wholeheartedly, with the decision. Howe’s coverage, being at SCOTUSblog, is unsurprisingly concerned with the legal aspects. But I’m also fascinated by the technical aspects. It’s remarkable — and regrettable — that Google had this geofence information in the first place. The data was part of a grossly invasive and ill-conceived feature Google called “Location History”, and was used to power a feature called “Timeline” in Google Maps. The data was stored unencrypted by Google in the cloud, tied to your Google account, thus making it available to these geofence warrants.

Back in December 2023 Google announced that it was changing the way it stored this data, defaulting instead to on-device storage and using end-to-end encryption (that Google itself cannot decrypt) for location data it holds online. This change had long been advocated by the EFF, which celebrated Google’s policy change. (Notably, Chatrie robbed that credit union in 2019.)

Most people have an unshakeable belief in the widely-held misconception that “everything” we do — everywhere we go, even everything we say — in the presence of our phones is tracked and recorded, and traceable back to us individually. It’s not at all ridiculous that this belief is so common, given that it is technically feasible. Our phones are precise GPS devices, they do have good microphones, and they are (almost) always connected to cellular and/or Wi-Fi networks. And the surveillance advertising industrial complex — primarily Meta and Google — is so uncannily good at serving ads based on our recent personal interests that the most obvious explanation for how they do it is “they listen to us and track us and record everything we do”. That’s not how they do it. But “they listen to us and track us and record everything we do” is an explanation that everyone can easily understand. If that were how Meta and Google served targeted ads to us, everyone could understand how the ads are so often so uncannily and creepily accurate. The way it actually works is complex and complicated, and thus in the realm of Arthur C. Clarke’s maxim that “any sufficiently advanced technology is indistinguishable from magic”. Incorrect explanations that people understand resonate and take hold and become entrenched beliefs; correct explanations that people don’t understand are dismissed and are not believed. (Exhibit A: evolution.) This is why it is such a precious gift to be able to explain complex technical and scientific subject matter in ways that many people can understand.1

And lo, now here’s a Supreme Court case showing that when the police asked for a list of people whose phones were near a particular bank at a particular time on a particular day, Google had that information and handed it over. Chatrie v. United States is not a particularly celebrated case, but this will only contribute to the entrenching of superstitious incorrect conspiracy theories about the data that “they” — big tech companies — collect about us.

But Google no longer collects this information in a way that is susceptible to geofence warrants, and, more importantly, Apple never did. From my own December 2023 post on Google’s decision to change how it collects this data to ensure privacy:

The reason these overly broad geofence warrants “almost always” were specific to Google is that Apple never collected location data that could be collected in the aggregate like this. From Apple’s most recent government transparency report (PDF), covering the first half of 2022:

Apple may also receive requests from government agencies seeking customer data related to specific latitude and longitudes coordinates (geofence) for a specified time period. Apple does not have any data to provide in response to geofence requests.

I checked with a source at Apple, and they believe they have never collected or stored geolocation data in a manner that can be linked to groups of individuals in a certain area or areas.

So the whole question of geofence-warrant fishing expeditions may have been obviated two years ago by Google for Android users, and was never an issue for iPhone users. Unless, perhaps, they used the Google Maps app on their iPhones and granted it the “always on” location access that it asks for. I suspect, but do not know, that iPhone users who granted “always on” location access to Google Maps (or any other Google iOS app that asked for it? — all of their iOS apps seem to ask for location permissions, but I don’t know how many other than Google Maps ask for always-on access) were just as susceptible to these geofence warrants as Android users.

This decision should still serve as good precedent for location data held by other companies, and I hope the decision serves as good precedent for any searchable Personally Identifiable Information susceptible to fishing-expedition warrants in general.

But the bottom line is: Apple has never held data tracking your location, and while Google did, they no longer do.


  1. It’s good for the expert, too, to prove that they can explain complex subject matter at the level of a freshman lecture — which is the only way to prove that they truly understand it themselves. ↩︎

CMA Consultation on Mobile App Steering and NFC Access

30 June 2026 at 18:33

The UK Competition and Markets Authority:

‘Steering’ — the ability for developers to engage with customers about off‑platform options — is currently banned by Apple and restricted by Google in the UK. Lifting these constraints would allow developers to bypass mandatory fees set by platforms.

The CMA’s consultation includes principles to ensure that the fees Apple and Google charge for steering are fair and reasonable. Using an evidence-based framework, the CMA would expect steering fees to be lower than current app store charges, with savings passed onto UK customers or invested back into the developers’ businesses to support future innovation.

Japan’s MSCA is a good model for this.

U.K. Regulator Considers Requiring App Store to Allow Steering to the Web, and iOS NFC to Be Open

30 June 2026 at 17:44

Sam Tabahriti, reporting for Reuters:

Britain’s competition regulator ​on Tuesday proposed allowing app developers to steer users to alternative payment options outside Apple and Alphabet’s Google app stores to cut fees and boost competition. The Competition and Markets Authority said the proposals would remove restrictions that currently prevent UK developers from directing users to off-platform payment options, which are banned by Apple and restricted by Google.

The watchdog said any fees charged by two of the world’s largest technology companies ​for allowing such “steering” would need to be fair and reasonable, and should be lower than current app store commissions, with ​savings passed on to consumers or reinvested in innovation.

How does one mandate that the savings be passed on to consumers? You may recall that last year Apple published a study — that it commissioned itself — suggesting otherwise. I wrote in December:

This all comes back to the argument that Apple’s App Store commission inflates prices. A recent Apple-funded (and Apple-promoted) study suggests this is not true — that with lower commissions mandated by the DMA, prices paid by consumers stayed the same and the difference went to the developers. That’s good if you’re a developer, but it’s not the argument being made by these consumer advocate groups.

That said, I pointed out just the other day that Tiimo, a to-do app that Apple just named as the iPhone app of the year in the 2025 App Awards, charges about 20 percent less for subscriptions on its website compared to its in-app subscriptions. An Apple-funded, Apple-promoted study showing that the App Store’s commissions don’t raise prices ought to be taken with a few grains of salt.

Requiring Apple to allow apps to steer users to the web to make payments is, I’ve long argued, sensible regulation. I’ve also long argued that Apple has been obstinate in disallowing it. If in-app payments — through Apple’s system — can’t compete with out-of-app payments on the web, something is wrong with IAP. But it’s wrong to assume that payments outside IAP will result in lower prices and better policies for users. IAP subscriptions are easy to cancel and listed all in one place. Web subscriptions are often notoriously difficult to cancel and manage.

Back to Reuters:

The CMA said it was also considering requiring Apple to open up access to its near-field communication technology, which is used for contactless payments, potentially allowing developers to offer payment services within their own iOS apps. This could enable UK fintech companies to build alternatives to ​Apple’s wallet, including account-to-account payments and emerging technologies such as digital currencies, the CMA said.

Even more so than opening up third-party in-app payment processing, this seems like something only “fintech” companies are asking for. For users I think the only result will be a loss of interoperability and increase in confusion. Users get one Wallet app today, with all their credit, debit, and loyalty cards, and all their tickets for things like events and travel. A scenario where each credit card company, airline, and event/ticketing company can mandate the installation of their own app, with access to the iPhone’s NFC, does not strike me as a good outcome.

❌