Security

Email Bombs Exploit Lax Authentication In Zendesk (krebsonsecurity.com) 11

Cybercriminals are exploiting weak email authentication settings in Zendesk, using the platform's customer support systems to bombard targets with thousands of spam and harassing messages that appear to come from legitimate companies like The Washington Post, Discord, and NordVPN. KrebsOnSecurity reports: Zendesk is an automated help desk service designed to make it simple for people to contact companies for customer support issues. Earlier this week, KrebsOnSecurity started receiving thousands of ticket creation notification messages through Zendesk in rapid succession, each bearing the name of different Zendesk customers, such as CapCom, CompTIA, Discord, GMAC, NordVPN, The Washington Post, and Tinder.

The abusive missives sent via Zendesk's platform can include any subject line chosen by the abusers. In my case, the messages variously warned about a supposed law enforcement investigation involving KrebsOnSecurity.com, or else contained personal insults. Moreover, the automated messages that are sent out from this type of abuse all come from customer domain names -- not from Zendesk. [...]

In all of the cases above, the messaging abuse would not have been possible if Zendesk customers validated support request email addresses prior to sending responses. Failing to do so may make it easier for Zendesk clients to handle customer support requests, but it also allows ne'er-do-wells to sully the sender's brand in service of disruptive and malicious email floods.
"We recognize that our systems were leveraged against you in a distributed, many-against-one manner," said Carolyn Camoens, communications director at Zendesk. "We are actively investigating additional preventive measures. We are also advising customers experiencing this type of activity to follow our general security best practices and configure an authenticated ticket creation workflow."
Television

Meta Is Building a Smart TV In VR (lowpass.cc) 19

Meta has officially launched Horizon TV, a virtual reality "smart TV" app for its Quest headsets. The app mirrors modern smart TV interfaces with deep-linked streaming apps and curated recommendations -- but it's still missing major players like Netflix and Disney+. From a report: Except Horizon TV isn't running on a TV or streaming stick, but on the company's Meta Quest headsets. Unveiled at Meta Connect last month, the app is a big part of Meta's push to attract older, less gaming-focused audiences to VR -- a push that also includes a partnership with James Cameron, and investments into sports, and other types of leanback entertainment content.

Re-creating the smart TV experience in virtual reality also represents a monetization opportunity for Meta, which has for some time now tried to figure out how to bring advertising to VR. However, the approach also means that Meta is inheriting some of the very problems smart TV platform operators have struggled with for a long time. And if consumers do warm up to watching more content with their headsets, they're bound to realize that even in VR, you can't escape the collateral damage of the streaming wars.

Firefox

Mozilla Is Recruiting Beta Testers For a Free, Baked-In Firefox VPN (theregister.com) 36

Mozilla is testing a free, built-in VPN for Firefox that routes traffic through Mozilla-managed servers directly in the browser. The Register reports: According to a staff post on Mozilla Connect, the company's idea-sharing platform, Firefox VPN is still an experimental feature in the early stages of development, but users will be selected at random to test it "over the next few months." Moz describes the feature as one that will sit beside the search bar on Firefox, routing web traffic through a Mozilla-managed VPN server, concealing the user's real IP address while adding a layer of encryption to their communications. Firefox VPN is a different project entirely from Mozilla VPN, a separate, paid-for product. The Firefox version will be free to use and confined to the browser itself, while Mozilla VPN can be used by up to five devices at a time.

The Moz staffer on the product team who announced the feature said of the upcoming beta test: "We'll start simple, then gradually add new capabilities while learning how it impacts browsing, usage, and overall satisfaction. "Our long-term vision is ambitious: to build the best VPN-integrated browser on the market." In response to feedback, the staffer noted that while it will be a desktop browser feature first, "mobile is definitely a natural next step."

Security

F5 Says Hackers Stole Undisclosed BIG-IP Flaws, Source Code (bleepingcomputer.com) 16

An anonymous reader quotes a report from BleepingComputer: U.S. cybersecurity company F5 disclosed that nation-state hackers breached its systems and stole undisclosed BIG-IP security vulnerabilities and source code. The company states that it first became aware of the breach on August 9, 2025, with its investigations revealing that the attackers had gained long-term access to its system, including the company's BIG-IP product development environment and engineering knowledge management platform.

F5 is a Fortune 500 tech giant specializing in cybersecurity, cloud management, and application delivery networking (ADN) applications. The company has 23,000 customers in 170 countries, and 48 of the Fortune 50 entities use its products. BIG-IP is the firm's flagship product used for application delivery and traffic management by many large enterprises worldwide. [...]

F5 is still reviewing which customers had their configuration or implementation details stolen and will contact them with guidance. To help customers secure their F5 environments against risks stemming from the breach, the company released updates for BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients. Despite any evidence "of undisclosed critical or remote code execution vulnerabilities," the company urges customers to prioritize installing the new BIG-IP software updates.

GUI

NordVPN Embraces Open Source By Releasing Its Linux GUI On GitHub (nerds.xyz) 10

BrianFagioli shares a report from NERDS.xyz: NordVPN has open sourced its Linux GUI on GitHub, giving the community full access to the code behind its graphical client. The move follows a 70 percent surge in daily active Linux users since the GUI's debut earlier this year, showing clear demand for a user friendly VPN experience on the platform. Alongside the previously open sourced command line tool, the GUI codebase is now available for anyone to audit, modify, and contribute to. While NordVPN's core backend infrastructure remains proprietary, the company says the open source release reflects its commitment to transparency and collaboration with the Linux community. The GUI can also now be installed with a single command using Snap, simplifying setup and ensuring automatic updates across distributions.
Programming

GitHub Will Prioritize Migrating To Azure Over Feature Development (thenewstack.io) 32

An anonymous reader shares a report: After acquiring GitHub in 2018, Microsoft mostly let the developer platform run autonomously. But in recent months, that's changed. With GitHub CEO Thomas Dohmke leaving the company this August, and GitHub being folded more deeply into Microsoft's organizational structure, GitHub lost that independence. Now, according to internal GitHub documents The New Stack has seen, the next step of this deeper integration into the Microsoft structure is moving all of GitHub's infrastructure to Azure, even at the cost of delaying work on new features.

[...] While GitHub had previously started work on migrating parts of its service to Azure, our understanding is that these migrations have been halting and sometimes failed. There are some projects, like its data residency initiative (internally referred to as Project Proxima) that will allow GitHub's enterprise users to store all of their code in Europe, that already solely use Azure's local cloud regions.

AI

Google's Nano Banana AI-Image Editing Is Coming to Search, NotebookLM and Photos 9

Google's viral Nano Banana AI image editor is being woven into Search, NotebookLM, and Photos. Engadget reports: Perhaps the most notable integration here is with NotebookLM. Nano Banana is being used to drastically change up Video Overviews, offering up six new styles like watercolor and anime. It also now generates contextual illustrations based on sources and there's a new option for micro-videos called Briefs. For the uninitiated, Video Overviews is a neat little tool available to NotebookLM users that automatically generates explainer videos from documents. It can even whip up a narrated slideshow with visuals. The AI-heavy update starts rolling out to Pro users this week and to all users in "the upcoming weeks."

Search integration offers new ways to make and edit images while using the official Google app. The company says folks can use a chat prompt to, say, ask the bot to create a stylized version of a pre-existing image. Additionally, photos can be snapped directly from the Lens tool and then edited via the AI. This is rolling out right now in English for US customers, with more countries and languages coming in the near future. We don't have any actual information as to what the Photos integration will look like, with Google simply saying it's bringing Nano Banana to the platform in "the weeks ahead."
United States

Three New California Laws Target Tech Companies' Interactions with Children 47

California Governor Gavin Newsom signed three bills on Monday that establish the nation's most comprehensive framework for regulating how technology companies interact with minors. AB 56 requires social media platforms to display health warnings to users under 18. A child must view a skippable ten-second warning upon logging on each day. An unskippable thirty-second warning must appear if a child spends more than three hours on a platform. That warning repeats after each additional hour. The warnings must state that social media "can have a profound risk of harm to the mental health and well-being of children and adolescents." Minnesota passed a similar law in July.

SB 243 makes California the first state to regulate AI companion chatbots. The law takes effect January 1, 2026. Companies must implement age verification and disclose that interactions are artificially generated. Chatbots cannot represent themselves as healthcare professionals. Companies must offer break reminders to minors and prevent them from viewing sexually explicit images. The legislation gained momentum after teenager Adam Raine died by suicide following conversations with OpenAI's ChatGPT. A Colorado family filed suit against Character AI after their daughter's suicide following problematic conversations with the company's chatbots.

AB 1043 requires device-makers like Apple and Google to collect birth dates when parents set up devices for children. Device-makers must group users into four age brackets and share this information with apps. Google, Meta, OpenAI, and Snap supported the bill. The Motion Picture Association opposed it.
AI

Hollywood Demands Copyright Guardrails from Sora 2 - While Users Complain That's Less Fun (yahoo.com) 56

Enthusiasm for Sora 2 "wasn't shared in Hollywood," reports the Los Angeles Times, "where the new AI tools have created a swift backlash" that "appears to be only just the beginning of a bruising legal fight that could shape the future of AI use in the entertainment business." [OpenAI] executives went on a charm offensive last year. They reached out to key players in the entertainment industry — including Walt Disney Co. — about potential areas for collaboration and trying to assuage concerns about its technology. This year, the San Francisco-based AI startup took a more assertive approach. Before unveiling Sora 2 to the general public, OpenAI executives had conversations with some studios and talent agencies, putting them on notice that they need to explicitly declare which pieces of intellectual property — including licensed characters — were being opted-out of having their likeness depicted on the AI platform, according to two sources familiar with the matter who were not authorized to comment. Actors would be included in Sora 2 unless they opted out, the people said. OpenAI disputes the claim and says that it was always the company's intent to give actors and other public figures control over how their likeness is used.

The response was immediate.... [Big talent agencies objected, along with performers' unions and major studios.] "Decades of enforceable copyright law establishes that content owners do not need to 'opt out' to prevent infringing uses of their protected IP," Warner Bros. Discovery said in a statement... The strong pushback from the creative community could be a strategy to force OpenAI into entering licensing agreements for the content they need, legal experts said... One challenge is figuring out a way that fairly compensates talent and rights holders. Several people who work within the entertainment industry ecosystem said they don't believe a flat fee works.

Meanwhile, "the complete copyright-free-for-all approach that OpenAI took to its new AI video generation model, Sora 2, lasted all of one week," writes Gizmodo. But that means the service has "now pissed off its users." As 404 Media pointed out, social channels like Twitter and Reddit are now flooded with Sora users who are angry they can't make 10-second clips featuring their favorite characters anymore. One user in the OpenAI subreddit said that being able to play with copyrighted material was "the only reason this app was so fun."
Futurism published more reactions, including ""It's official, Sora 2 is completely boring and useless with these copyright restrictions." Others accused OpenAI of abusing copyright to hype up its new app. "This is just classic OpenAI at this point," another user wrote. "They do this s*** all the time. Let people have fun for a day or two and then just start censoring like crazy." The app now has a measly 2.9-star rating on the App Store, indicative of growing disillusionment and frustration with censorship... [It's not dropped to 2.8.]

In an apparent effort to save face, Altman claimed this week that many copyright holders are actually begging to have their characters appear on Sora, instead of complaining about the trend. "In the case of Sora, we've heard from a lot of concerned rightsholders and also a lot of rightsholders who are like 'My concern is you won't put my character in enough,'" he told the a16z podcast earlier this week. "So I can completely see a world where subject to the decisions that a rightsholder has, they get more upset with us for not generating their character often enough than too much," he added. Whether most rightsholders would agree with that sentiment remains to be seen.

Business Insider offers another reaction. After watching Sora 2's main public feed, they write that Sora 2 "seems to be overrun with teenage boys."
Advertising

Is OpenAI Planning to Turn ChatGPT Into an Ad Platform? (adweek.com) 46

"OpenAI is staffing up to expand ChatGPT's marketing reach and build on-platform marketing tools," reports Adweek: A recent job listing shows the company is hiring a Growth Paid Marketing Platform Engineer to develop internal tools for ad platform integration, campaign management, and real-time attribution. The position is part of a newly formed "ChatGPT Growth team," and tasked with "building the technical infrastructure behind OpenAI's paid marketing platform...." This job listing is a rare signal of OpenAI's plans for an in-house marketing platform within ChatGPT, and part of the AI company's broader growth plans...

This adds to recent reporting showing that OpenAI is quickly ramping up its advertising ambitions... Alex Heath of Sources reported that OpenAI's CEO of Applications, Fidji Simo, was meeting with candidates to "lead a new team that will be tasked with bringing ads to ChatGPT...." OpenAI did not respond to requests for comment...

Critically, this job listing would support building backend infrastructure — APIs, data pipelines, and services — to manage campaigns, measure attribution, and optimize ad spend. This internal infrastructure would give OpenAI the ability to run marketing at scale without relying on external agencies, two industry insiders said, adding that successfully doing so for itself could lay the foundation for a broader product that lets other brands run campaigns through ChatGPT... [Jacob Bourne, an analyst at eMarketer] added that while it may be striking to see a company that began as a nonprofit research lab make this kind of move, it reflects OpenAI's for-profit pivot and broader push into revenue generation.

"In a new Stratechery interview, Altman admitted Instagram changed his mind about ads," the site Search Engine Land reported Wednesday, citing these two quotes from the interview: - "I love Instagram ads, they've added value to me, I found stuff I never would've found, I bought a bunch of stuff, I actively like Instagram ads. I think there's many things I respect about Meta, but getting that so right was a surprisingly cool thing for me. Other than that, I viewed ads on the Internet as sort of like a tax."

- "I believe there probably is some cool ad product we can do that is a net win to the user and a sort of positive to our relationship with the user. I don't know what it is yet, I'm not like, 'Here is our ad model' already."

Their article also cites a tweet from an ad industry director who says OpenAI's own revenue projections now show "free-user monetization"...
Transportation

Lyft Plans Fleet of Hundreds of Tensor Robocars From 2027 (msn.com) 42

Lyft is teaming up with Tensor Auto to launch hundreds of AI-powered "Robocars" across Europe and North America starting in 2027. Bloomberg reports: Tensor Robocars, the first deliveries of which are planned in late 2026, have more than 100 sensors including cameras, lidars and radars, and processes sensor data with artificial intelligence technology powered by Nvidia Corp. chips on board. The vehicles will come from the manufacturer with Lyft's platform installed, which will allow owners to make money on the rideshare network in markets where level 4 autonomous technology is available, according to the joint statement. Lyft has reserved hundreds of Robocars via its affiliates for its own fleet operations, subject to regulatory approvals.
Youtube

YouTube Opens 'Second Chance' Program To Creators Banned For Misinformation (theverge.com) 110

YouTube has launched a "second chance" program allowing some creators previously banned for COVID-19 or election misinformation to apply for new channels, as long as their violations were tied to policies that have since been deprecated. Bans for copyright or severe misconduct still remain permanent. The Verge reports: Under political pressure, the company had said last month that it was going to set up this pilot program for "a subset of creators" and "channels terminated for policies that have been deprecated." [...] The new pilot program kicks off today and will roll out to "eligible creators" over the "next several weeks," YouTube says. "We'll consider several factors when evaluating requests for new channels, like whether the creator committed particularly severe or persistent violations of our Community Guidelines or Terms of Service, or whether the creator's on- or off-platform activity harmed or may continue to harm the YouTube community."

The pilot won't be available if you were banned for copyright infringement or for violating YouTube's Creator Responsibility policies, the company says. If you deleted your YouTube channel or Google account, you won't be able to request a new channel "at this time." And YouTube notes that if your channel has been banned, you won't be eligible to apply for a new one until one year after it was terminated.
"We know many terminated creators deserve a second chance -- YouTube has evolved and changed over the past 20 years, and we've had our share of second chances to get things right with our community too," YouTube says. "Our goal is to roll this out to creators who are eligible to apply over the coming months, and we appreciate the patience as we ramp up, carefully review requests, and learn as we go."
Intel

Intel's Next-Generation Panther Lake Laptop Chips Could Be a Return To Form (arstechnica.com) 23

Intel today announced its Panther Lake laptop processors, consolidating the confusing split between Lunar Lake and Arrow Lake chips that define its current generation. The new processors use a unified architecture across all models instead of mixing different technologies at different price points. Panther Lake comes in three configurations. An 8-core model targets mainstream ultrabooks. A 16-core version adds PCI Express lanes for gaming laptops and workstations with discrete GPUs. A third 16-core variant with 12 Xe3 graphics cores aims at high-end thin-and-light laptops without dedicated graphics cards.

All three chips use the same Cougar Cove P-cores, Darkmont E-cores, and Xe3 GPU architecture. They share an NPU capable of 50 trillion operations per second and identical media encoding capabilities. The main differences are core counts and I/O options rather than fundamental architectural variations. The approach contrasts with Intel's current Core Ultra 200 series. Lunar Lake chips integrated RAM on-package and used the latest Battlemage GPU architecture but were mostly used in high-end thin laptops.

Arrow Lake processors offered more flexibility but paired newer CPU cores with older graphics and an NPU that did not meet Microsoft Copilot+ requirements. Intel claims Panther Lake delivers up to 10% better single-threaded performance than Lunar Lake and up to 50% faster multi-threaded performance than both previous generations. The GPU is roughly 50% quicker. Power consumption drops 10% compared to Lunar Lake and 40% versus Arrow Lake. The chips use Intel's 18A manufacturing process for the compute tile. TSMC fabricates the platform controller tile. Intel said systems with Panther Lake processors should ship by the end of 2025.
Businesses

Polymarket Founder Is Youngest Self-Made Billionaire After Deal With NYSE Owner (yahoo.com) 56

Shayne Coplan, a 27-year-old NYU dropout who founded Polymarket from his bathroom in 2020, has become the youngest self-made billionaire after Intercontinental Exchange (owner of the NYSE) invested up to $2 billion in his once-controversial prediction market platform. Bloomberg reports: A couple of years after dropping out of New York University with dreams of making it big in crypto, Shayne Coplan was so broke that he took an inventory of his Lower East Side apartment so that he could sell belongings to make rent. Fed up with crypto grifts, in 2019 he started to explore economist Robin Hanson's ideas on prediction markets and their potential for improving society's ability to identify likely outcomes. "This is too good of an idea to just exist in whitepapers," he recalled thinking in a later post on X. Then Covid struck -- the perfect time to develop an app for stuck-at-home folks to bet on real-world outcomes, he reasoned. He began building Polymarket from his bathroom and launched the platform in June 2020.

It wasn't a smooth road. The company's move-fast, ask-permission-later approach repeatedly ran afoul of regulators, who forced it to ban US-based users for years because it wasn't a registered exchange. A week after the 2024 presidential election -- one that Polymarket users wagered more than $3 billion on -- Coplan's apartment was raided by FBI agents. But he and his company are now riding high after Intercontinental Exchange Inc., the owner of the New York Stock Exchange, said it would invest as much as $2 billion in Polymarket at an $8 billion pre-money valuation. That deal makes its 27-year-old founder the youngest self-made billionaire tracked by the Bloomberg Billionaires Index.

Privacy

Salesforce Says It Won't Pay Extortion Demand in 1 Billion Records Breach (arstechnica.com) 28

Salesforce says it's refusing to pay an extortion demand made by a crime syndicate that claims to have stolen roughly 1 billion records from dozens of Salesforce customers. From a report: The threat group making the demands began their campaign in May, when they made voice calls to organizations storing data on the Salesforce platform, Google-owned Mandiant said in June. The English-speaking callers would provide a pretense that necessitated the target connect an attacker-controlled app to their Salesforce portal. Amazingly -- but not surprisingly -- many of the people who received the calls complied.

[...] Earlier this month, the group created a website that named Toyota, FedEx, and 37 other Salesforce customers whose data was stolen in the campaign. In all, the number of records recovered, Scattered LAPSUS$ Hunters claimed, was "989.45m/~1B+." The site called on Salesforce to begin negotiations for a ransom amount "or all your customers [sic] data will be leaked." The site went on to say: "Nobody else will have to pay us, if you pay, Salesforce, Inc." The site said the deadline for payment was Friday.

AI

YouTube's Biggest Star MrBeast Fears AI Could Impact 'Millions of Creators' After Sora Launch (fortune.com) 68

An anonymous reader shares a report: YouTube megastar Jimmy Donaldson, the creator behind the platform's biggest channel MrBeast, is worried there are "scary times" ahead for the creator economy as AI video tools make it increasingly difficult to tell what is real.

"When AI videos are just as good as normal videos, I wonder what that will do to YouTube and how it will impact the millions of creators currently making content for a living.. scary times," Donaldson said on X on Sunday. Donaldson's concerns come on the heels of OpenAI's release of a Sora social media platform able to AI generated short-form videos, including of individuals who "upload" themselves onto the app. Meta launched its similar video-generating Vibes platform last month.

Businesses

AstraZeneca Signs Up For $555 Million AI Deal With Algen To Develop Therapies

AstraZeneca has licensed Algen Biotechnologies' AI-powered gene-editing platform, AlgenBrain, to develop immune-related therapies in a deal worth up to $555 million. Reuters reports: AstraZeneca will get exclusive rights to develop and sell approved therapies, if any, that target immune system-related disorders in exchange for upfront and milestone payments to Algen. AstraZeneca has been advancing its cell and gene therapy capabilities through acquisitions and partnerships as it works towards its target of $80 billion in sales by 2030. Globally too, drugmakers are increasingly turning to artificial intelligence for drug development.

Monday's deal, however, does not include AstraZeneca buying a stake in the company, Algen CEO and co-founder Chun-Hao Huang told Reuters in an interview. "Together with AstraZeneca's deep expertise in translational science and clinical development, we aim to uncover new biological insights to accelerate the development of novel therapies," Huang said. Algen was spun out from the UC Berkeley lab where biochemist Jennifer Doudna pioneered the CRISPR technology that won her the Nobel Prize. The biotech firm's AI platform, AlgenBrain, can map genes to disease outcomes, helping the companies decide their development focus for targeted therapies.
Crime

Suspect Arrested After Threats Against TikTok's Culver City Headquarters 11

Police arrested 33-year-old Joseph Mayuyo after a series of online threats forced TikTok to evacuate its Culver City headquarters. TechCrunch reports: A press release from the Culver City Police Department says that TikTok employees reported receiving multiple threats, across various social media platforms, from 33-year-old Hawthorne resident Joseph Mayuyo. After an additional message threatened TikTok's Culver City headquarters, police say company security evacuated the office "out of an abundance of caution."

Police then investigated Mayuyo's home, according to the press release. During the investigation, he allegedly posted additional threatening statements, including one declaring that he would not be taken alive. Detectives obtained search and arrest warrants, and they negotiated with Mayuyo for 90 minutes before he voluntarily exited his home and was taken into custody, the police department says.

Business Insider reports that one TikTok employee described the threats as "really scary," while another was concerned that they seemed to specifically target the e-commerce department. Mayuyo's X account has reportedly been suspended for violating the platform's hateful content policy. A Medium account under his name published a post in July criticizing TikTokShop USA as a "scam."
Transportation

Porsche Can't Add Wireless Charging To Macan, Taycan EV Because the Inductive Plate Doesn't Fit (thedrive.com) 64

Porsche's wireless charging system will not be available on the Macan Electric and Taycan because the inductive charging plate cannot physically fit between the front suspension on those models. Dr. Maximilian Muller, Porsche's high voltage engineering lead, told The Drive during a visit to the company's Leipzig facility that the Cayenne Electric's larger dimensions create the necessary space for the charging hardware beneath the front motor. The Cayenne Electric is wider than both the Taycan and Macan Electric. The larger vehicle forced Porsche to design different suspension geometry even though it shares the PPE platform with the Macan Electric. The changes create additional packaging constraints that prevent retrofitting the wireless charging system into existing electric models.
Businesses

Cory Doctorow Explains Why Amazon is 'Way Past Its Prime' (theguardian.com) 116

"It's not just you. The internet is getting worse, fast," writes Cory Doctorow. Sunday he shared an excerpt from his upcoming book Enshittification: Why Everything Suddenly Got Worse and What to Do About It.

He succinctly explains "this moment we're living through, this Great Enshittening" using Amazon as an example. Platforms amass users, but then abuse them to make things better for their business customers. And then they abuse those business customers too, abusing everybody while claiming all the value for themselves. "And become a giant pile of shit."

So first Amazon subsidized prices and shipping, then locked in customers with Prime shipping subscriptions (while adding the chains of DRM to its ebooks and audiobooks)... These tactics — Prime, DRM and predatory pricing — make it very hard not to shop at Amazon. With users locked in, to proceed with the enshittification playbook, Amazon needed to get its business customers locked in, too... [M]erchants' dependence on those customers allows Amazon to extract higher discounts from those merchants, and that brings in more users, which makes the platform even more indispensable for merchants, allowing the company to require even deeper discounts...

[Amazon] uses its overview of merchants' sales, as well as its ability to observe the return addresses on direct shipments from merchants' contracting factories, to cream off its merchants' bestselling items and clone them, relegating the original seller to page umpty-million of its search results. Amazon also crushes its merchants under a mountain of junk fees pitched as optional but effectively mandatory. Take Prime: a merchant has to give up a huge share of each sale to be included in Prime, and merchants that don't use Prime are pushed so far down in the search results, they might as well cease to exist. Same with Fulfilment by Amazon, a "service" in which a merchant sends its items to an Amazon warehouse to be packed and delivered with Amazon's own inventory. This is far more expensive than comparable (or superior) shipping services from rival logistics companies, and a merchant that ships through one of those rivals is, again, relegated even farther down the search rankings.

All told, Amazon makes so much money charging merchants to deliver the wares they sell through the platform that its own shipping is fully subsidised. In other words, Amazon gouges its merchants so much that it pays nothing to ship its own goods, which compete directly with those merchants' goods.... Add all the junk fees together and an Amazon seller is being screwed out of 45-51 cents on every dollar it earns there. Even if it wanted to absorb the "Amazon tax" on your behalf, it couldn't. Merchants just don't make 51% margins. So merchants must jack up prices, which they do. A lot... [W]hen merchants raise their prices on Amazon, they are required to raise their prices everywhere else, even on their own direct-sales stores. This arrangement is called most-favoured-nation status, and it's key to the U.S. Federal Trade Commission's antitrust lawsuit against Amazon...

If Amazon is taxing merchants 45-51 cents on every dollar they make, and if merchants are hiking their prices everywhere their goods are sold, then it follows you're paying the Amazon tax no matter where you shop — even the corner mom-and-pop hardware store. It gets worse. On average, the first result in an Amazon search is 29% more expensive than the best match for your search. Click any of the top four links on the top of your screen and you'll pay an average of 25% more than you would for your best match — which, on average, is located 17 places down in an Amazon search result.

Doctorow knows what we need to do:
  • Ban predatory pricing — "selling goods below cost to keep competitors out of the market (and then jacking them up again)."
  • Impose structural separation, "so it can either be a platform, or compete with the sellers that rely on it as a platform."
  • Curb junk fees, "which suck 45-51 cents on every dollar merchants take in."
  • End its most favoured nation deal, which forces merchants "to raise their prices everywhere else, too.
  • Unionise drivers and warehouse workers.
  • Treat rigged search results as the fraud they are.

These are policy solutions. (Because "You can't shop your way out of a monopoly," Doctorow warns.) And otherwise, as Doctorow says earlier, "Once a company is too big to fail, it becomes too big to jail, and then too big to care."

In the mean time, Doctorow also makes up a new word — "the enshitternet" — calling it "a source of pain, precarity and immiseration for the people we love.

"The indignities of harassment, scams, disinformation, surveillance, wage theft, extraction and rent-seeking have always been with us, but they were a minor sideshow on the old, good internet and they are the everything and all of the enshitternet."

Thanks to long-time Slashdot readers mspohr and fjo3 for sharing the article.


Slashdot Top Deals