home.social

#posthog — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #posthog, aggregated by home.social.

fetched live
  1. Ah, the marvel of "open source" where you get a read-only version of #PostHog, minus all the juicy bits, like a #donut with no filling. 🍩🔍 Meanwhile, #GitHub suggests you solve all your woes with AI—because who needs real #innovation when you’ve got Copilot to lead you astray? 🤖🚀
    github.com/PostHog/posthog-foss #open-source #AI #HackerNews #ngated

  2. Ah, the marvel of "open source" where you get a read-only version of #PostHog, minus all the juicy bits, like a #donut with no filling. 🍩🔍 Meanwhile, #GitHub suggests you solve all your woes with AI—because who needs real #innovation when you’ve got Copilot to lead you astray? 🤖🚀
    github.com/PostHog/posthog-foss #open-source #AI #HackerNews #ngated

  3. The White House's National Design Studio has also built or taken control of websites that belong,
    by law or by convention,
    to other federal agencies.

    The sites handle some of the most sensitive personal information Americans give to the government.

    Passports.gov is now run from inside the White House,
    not from the state department.

    The state department operates US passport services through its existing site at travel.state.gov.

    The studio’s version collects identity information from people applying for passports.

    It carries no privacy notice.

    Developer test code was left running on the live page.

    In response to a request for comment,
    a state department spokesperson wrote:

    “The Department of State is working closely with the White House to deliver the best possible service for our passport customers
    while safeguarding US national security.”

    They added:
    “US passport books and passport cards
    – and the programs and websites that support them
    – represent the gold standard in secure international travel documents,
    underpinned by state-of-the-art security and technology.”

    They referred additional questions to the White House.

    Trumpaccounts.gov is the federal website for the children’s investment programme created in last summer’s tax legislation.

    The treasury department, which administers the programme,
    is the registrant of record for the site.

    But the site itself runs through the same White House-controlled commercial account as the studio’s own sites:

    ndstudio.gov,
    the prescription-drug site trumprx.gov,
    the food-policy site realfood.gov
    and others.

    The treasury department did not respond to a request for comment.

    Login.gov is the federal sign-in gateway that more than 150 million Americans use to access services from social security to tax filing.

    The studio’s preview of vote.gov,
    described in the previous post,
    uses Login.gov to verify the identities of visitors.

    The Guardian contacted the General Services Administration (GSA), which operates Login.gov, for comment.

    A spokesperson replied in an email:
    “Login.gov is committed to the highest standards of privacy, transparency, and security.

    Our Privacy Impact Assessment was most recently reviewed in March 2026.

    All personnel supporting Login.gov,
    including detailees,
    are required to comply with applicable GSA policies, security requirements, privacy controls, and governance processes.”

    The NDS, meanwhile, seems to be expanding its footprint across more government websites.

    In late May, three new addresses tied to the NDS appeared in the public records:
    chat.staging.ndstudio.gov,
    onboarding.ndstudio.gov
    and upload.ndstudio.gov.

    #posthog #nds #doge #tracking #surveillance

    theguardian.com/us-news/2026/j

  4. The White House's National Design Studio has also built or taken control of websites that belong,
    by law or by convention,
    to other federal agencies.

    The sites handle some of the most sensitive personal information Americans give to the government.

    Passports.gov is now run from inside the White House,
    not from the state department.

    The state department operates US passport services through its existing site at travel.state.gov.

    The studio’s version collects identity information from people applying for passports.

    It carries no privacy notice.

    Developer test code was left running on the live page.

    In response to a request for comment,
    a state department spokesperson wrote:

    “The Department of State is working closely with the White House to deliver the best possible service for our passport customers
    while safeguarding US national security.”

    They added:
    “US passport books and passport cards
    – and the programs and websites that support them
    – represent the gold standard in secure international travel documents,
    underpinned by state-of-the-art security and technology.”

    They referred additional questions to the White House.

    Trumpaccounts.gov is the federal website for the children’s investment programme created in last summer’s tax legislation.

    The treasury department, which administers the programme,
    is the registrant of record for the site.

    But the site itself runs through the same White House-controlled commercial account as the studio’s own sites:

    ndstudio.gov,
    the prescription-drug site trumprx.gov,
    the food-policy site realfood.gov
    and others.

    The treasury department did not respond to a request for comment.

    Login.gov is the federal sign-in gateway that more than 150 million Americans use to access services from social security to tax filing.

    The studio’s preview of vote.gov,
    described in the previous post,
    uses Login.gov to verify the identities of visitors.

    The Guardian contacted the General Services Administration (GSA), which operates Login.gov, for comment.

    A spokesperson replied in an email:
    “Login.gov is committed to the highest standards of privacy, transparency, and security.

    Our Privacy Impact Assessment was most recently reviewed in March 2026.

    All personnel supporting Login.gov,
    including detailees,
    are required to comply with applicable GSA policies, security requirements, privacy controls, and governance processes.”

    The NDS, meanwhile, seems to be expanding its footprint across more government websites.

    In late May, three new addresses tied to the NDS appeared in the public records:
    chat.staging.ndstudio.gov,
    onboarding.ndstudio.gov
    and upload.ndstudio.gov.

    #posthog #nds #doge #tracking #surveillance

    theguardian.com/us-news/2026/j

  5. Some of the NDS’s work is even more opaque,
    including an apparent redesign of the federal government’s voting registration hub.

    A sign-in page run by the studio on a White House-controlled web address carries the title
    “Log in to vote.gov preview”.

    Above the password field is a notice: “For official use only. Actions will be recorded in accordance with applicable law.”

    Vote.gov is a federal voter registration website.

    By law it belongs to the Election Assistance Commission (EAC),
    an independent, bipartisan body that Congress established in 2002 after the disputed 2000 election.

    Congress created the commission specifically so no sitting president would control the federal voter-registration system.

    The studio’s version has been live on White House systems since
    17 September 2025, according to public records of secure web addresses.

    Late last year, the NDS began presenting its system to state election directors.

    The first such briefing, on 17 October, was on a call of the National Association of State Election Directors (NASED).

    Call notes summarising the meeting record members representing states of both parties expressing
    “serious concerns with this project not complying with state law”
    and noting that
    “the developers do not seem to want to spend the time to understand election official concerns”.

    Brianna Schletz,
    the Election Assistance Commission’s executive director,
    reportedly told state directors on the same call that the conversations were “informal”,
    and that commissioners would later vote on whether to stay involved.

    No record of any such vote has since appeared in the commission’s public proceedings.

    Asked for comment by the Guardian,
    a NASED spokesperson, Amy Cohen,
    confirmed by email that
    “NASED held a call in October joined by representatives from the National Design Studio and members of the EAC leadership team”.

    Cohen added:
    “NASED does not have a position on this project.

    NASED has had no further communication with the National Design Studio on this or any other project;

    both NASED as an organization and our members in their individual capacities engage with the EAC regularly about a variety of different topics and projects.”

    Six days after the
    17 October meeting,
    on 23 October,
    a National Design Studio engineer, Akash Bobba,
    reportedly briefed the system on a recorded conference call organised by the
    National Association of Secretaries of State.

    Under the studio’s design, voters would be required to verify their identity through Login.gov,
    the federal sign-in gateway,
    and to have their citizenship checked against a database run by the Department of Homeland Security.

    Asked on the call what the federal government would retain of the personal information voters entered into the system,
    Bobba reportedly said that
    “clear data retention policies” would be given to states ahead of implementation,
    but conceded:
    “I don’t know what they retain and what they are logging.”

    The Election Assistance Commission has been part of the discussions.

    Its chair, Donald Palmer, reportedly said the commission was
    “facilitating discussion with state election officials on modernizing an accessible tool to provide a verifiable digital registration option”.

    The Guardian contacted the Election Assistance Commission for comment but received no response.

    The EPIC’s Davisson said:
    “With vote.gov, that’s the province of the Election Assistance Commission.

    But if you’re centralizing that in the White House, the White House is going to have sort of access to that backbone of data.

    He added:
    “Doing that outside of the appropriate channels,
    I think, is definitely going to
    – it’s dangerous
    and it’s going to erode trust.”

    The Help America Vote Act of 2002 put
    voter-registration administration under an independent bipartisan commission,
    structurally outside the reach of any sitting president.

    The studio’s version appears to collapse this arm’s-length arrangement.

    The Guardian has not seen what is on the other side of the sign-in,
    but published Cisa records show who runs the system it lives on,
    which is under White House control.

    The commission Congress put in charge of vote.gov has not decided to formally participate in the initiative.

    The build itself is on White House systems.

    #posthog #AkashBobba #nds #doge #tracking #surveillance

  6. Some of the NDS’s work is even more opaque,
    including an apparent redesign of the federal government’s voting registration hub.

    A sign-in page run by the studio on a White House-controlled web address carries the title
    “Log in to vote.gov preview”.

    Above the password field is a notice: “For official use only. Actions will be recorded in accordance with applicable law.”

    Vote.gov is a federal voter registration website.

    By law it belongs to the Election Assistance Commission (EAC),
    an independent, bipartisan body that Congress established in 2002 after the disputed 2000 election.

    Congress created the commission specifically so no sitting president would control the federal voter-registration system.

    The studio’s version has been live on White House systems since
    17 September 2025, according to public records of secure web addresses.

    Late last year, the NDS began presenting its system to state election directors.

    The first such briefing, on 17 October, was on a call of the National Association of State Election Directors (NASED).

    Call notes summarising the meeting record members representing states of both parties expressing
    “serious concerns with this project not complying with state law”
    and noting that
    “the developers do not seem to want to spend the time to understand election official concerns”.

    Brianna Schletz,
    the Election Assistance Commission’s executive director,
    reportedly told state directors on the same call that the conversations were “informal”,
    and that commissioners would later vote on whether to stay involved.

    No record of any such vote has since appeared in the commission’s public proceedings.

    Asked for comment by the Guardian,
    a NASED spokesperson, Amy Cohen,
    confirmed by email that
    “NASED held a call in October joined by representatives from the National Design Studio and members of the EAC leadership team”.

    Cohen added:
    “NASED does not have a position on this project.

    NASED has had no further communication with the National Design Studio on this or any other project;

    both NASED as an organization and our members in their individual capacities engage with the EAC regularly about a variety of different topics and projects.”

    Six days after the
    17 October meeting,
    on 23 October,
    a National Design Studio engineer, Akash Bobba,
    reportedly briefed the system on a recorded conference call organised by the
    National Association of Secretaries of State.

    Under the studio’s design, voters would be required to verify their identity through Login.gov,
    the federal sign-in gateway,
    and to have their citizenship checked against a database run by the Department of Homeland Security.

    Asked on the call what the federal government would retain of the personal information voters entered into the system,
    Bobba reportedly said that
    “clear data retention policies” would be given to states ahead of implementation,
    but conceded:
    “I don’t know what they retain and what they are logging.”

    The Election Assistance Commission has been part of the discussions.

    Its chair, Donald Palmer, reportedly said the commission was
    “facilitating discussion with state election officials on modernizing an accessible tool to provide a verifiable digital registration option”.

    The Guardian contacted the Election Assistance Commission for comment but received no response.

    The EPIC’s Davisson said:
    “With vote.gov, that’s the province of the Election Assistance Commission.

    But if you’re centralizing that in the White House, the White House is going to have sort of access to that backbone of data.

    He added:
    “Doing that outside of the appropriate channels,
    I think, is definitely going to
    – it’s dangerous
    and it’s going to erode trust.”

    The Help America Vote Act of 2002 put
    voter-registration administration under an independent bipartisan commission,
    structurally outside the reach of any sitting president.

    The studio’s version appears to collapse this arm’s-length arrangement.

    The Guardian has not seen what is on the other side of the sign-in,
    but published Cisa records show who runs the system it lives on,
    which is under White House control.

    The commission Congress put in charge of vote.gov has not decided to formally participate in the initiative.

    The build itself is on White House systems.

    #posthog #AkashBobba #nds #doge #tracking #surveillance

  7. A 2002 federal law,
    the E-Government Act,
    requires any federal agency that collects personal information through a website to first publish a written privacy impact assessment
    explaining what it collects and where the information goes.

    The Privacy Act of 1974 requires a separate, parallel public notice,
    a “system of records notice”,
    describing the records the agency keeps.

    A 2010 office of management and budget memorandum extended both requirements to federal agencies’ use of commercial
    web-tracking tools, including the kind that PostHog provides.

    The Guardian could find no such filings for the studio’s web-tracking layer.

    None of the four sites carry a privacy impact assessment naming PostHog or describing the IP addresses and on-site activity the tool collects.

    None of the four are covered by a system of records notice that addresses what is collected or where it goes.

    The one published privacy instrument that relates to any of the four programmes,
    a treasury notice for the Trump Accounts programme,
    describes how the children’s-investment programme is administered
    but does not name PostHog and does not describe the tracking on trumpaccounts.gov at all.

    Davisson, the EPIC attorney,
    called the studio’s failure to publish such a notice
    “a pretty clearcut violation of section 208” of the E-Government Act,

    adding: “There’s just no suggestion that they’re trying to comply in good faith with any of their obligations when it comes to the collection of personal information.”

    It’s not known what data was collected from users of the government websites while the tools were live,
    whether it was retained
    and who has custody of the data.

    #posthog #JoeGebbia #nds #doge #tracking #surveillance

  8. A 2002 federal law,
    the E-Government Act,
    requires any federal agency that collects personal information through a website to first publish a written privacy impact assessment
    explaining what it collects and where the information goes.

    The Privacy Act of 1974 requires a separate, parallel public notice,
    a “system of records notice”,
    describing the records the agency keeps.

    A 2010 office of management and budget memorandum extended both requirements to federal agencies’ use of commercial
    web-tracking tools, including the kind that PostHog provides.

    The Guardian could find no such filings for the studio’s web-tracking layer.

    None of the four sites carry a privacy impact assessment naming PostHog or describing the IP addresses and on-site activity the tool collects.

    None of the four are covered by a system of records notice that addresses what is collected or where it goes.

    The one published privacy instrument that relates to any of the four programmes,
    a treasury notice for the Trump Accounts programme,
    describes how the children’s-investment programme is administered
    but does not name PostHog and does not describe the tracking on trumpaccounts.gov at all.

    Davisson, the EPIC attorney,
    called the studio’s failure to publish such a notice
    “a pretty clearcut violation of section 208” of the E-Government Act,

    adding: “There’s just no suggestion that they’re trying to comply in good faith with any of their obligations when it comes to the collection of personal information.”

    It’s not known what data was collected from users of the government websites while the tools were live,
    whether it was retained
    and who has custody of the data.

    #posthog #JoeGebbia #nds #doge #tracking #surveillance

  9. The use of commercial tools on the sites departs from federal web-team conventions.

    Davisson, the senior counsel at the EPIC, described the studio’s work as
    “trying to establish their own sort of fly-by-night version of what federal agencies normally do with added tracking technologies
    and less oversight”.

    This is most apparent in the NDS’s employment of user tracking prior to outreach from the Guardian,
    such that when a member of the public visited one of the studio’s federal websites,
    a commercial tool called PostHog recorded what they did on the page.

    PostHog’s session-recording feature,
    which can replay every click, scroll and keystroke of a visitor’s time on a webpage,
    is installed in the code of all four sites and enabled on two of them.

    On the remaining two, the recording is held inactive only by a single setting inside PostHog’s dashboard,
    which can be changed by whoever controls the website at any time.

    The Guardian emailed PostHog for comment on its apparent provision of tracking tools to the NDS, but received no response.

    Adblockers and similar privacy tools are used by millions of people to limit what third parties can learn about them as they browse.
    Most of them work by intercepting requests that a visitor’s browser makes to known tracking services
    – and blocking them before any data leaves the device.

    Website source code shows that PostHog has been configured on
    NDS-run sites to route analytics requests through an address on the federal website itself,
    rather than through PostHog’s own servers.

    Because the request appears to go to the site the user is already visiting, rather than to a recognisable third-party address, adblockers don’t flag it.

    As PostHog explains in its own documentation,
    this works “because ad blockers haven’t visited your domain to catalog your setup.
    They don’t know what to block.”

    In other words, the technique is specifically designed to evade privacy tools
    – by presenting commercial tracking as ordinary website activity.

    Serge Egelman, research director of the Usable Security and Privacy Group at the International Computer Science Institute (ICSI), explained:

    “The issue there is that over the last several years,
    due to abuses relating to this type of data collection,
    there’s basically an arms race with tools being released to allow consumers to try and exert some control over what data gets collected.”

    Egelman said that he had not looked specifically at the PostHog tool or its deployment on federal websites,
    but he did point to a lawsuit involving the addition of commercial tracking technology to a state government website.

    “I testified on Meta where the [Meta] Pixel was put on the California DMV website.

    And Meta was able to obtain information about when people are requesting, say, disability placards,
    reinstating a suspended license, things like that
    – sensitive information that’s actually protected by federal law.”

    He added: “It’s not like someone going to the DMV website expects a private company to receive their personal data and then be allowed to use that however they want.”

    PostHog comes with a separate feature called session recording,
    which plays back every click, scroll and keystroke a visitor makes,
    like a video recording of their entire visit.

    Princeton University researchers who first documented the technology in 2017 wrote that watching such a recording was “as if someone is looking over your shoulder”.

    On the Trump Accounts and TrumpRX websites, the feature has been built into the page code and is held inactive only by a single setting inside PostHog’s dashboard.

    The NDS can turn it on at any time, on either site, without making changes in the underlying website code.

    Separately, until the Guardian sought comment on this reporting, the NDS’s own website, ndstudio.gov,
    ran a 539-line piece of bespoke code that recorded visitors’ clicks, form entries and navigation;

    assigned each visitor a session identifier;

    and forwarded the captured data to an address that does not appear anywhere on the public internet.

    The script’s source code refers to it as AutoMonitor.

    #posthog #JoeGebbia #nds #doge #tracking #surveillance

  10. The use of commercial tools on the sites departs from federal web-team conventions.

    Davisson, the senior counsel at the EPIC, described the studio’s work as
    “trying to establish their own sort of fly-by-night version of what federal agencies normally do with added tracking technologies
    and less oversight”.

    This is most apparent in the NDS’s employment of user tracking prior to outreach from the Guardian,
    such that when a member of the public visited one of the studio’s federal websites,
    a commercial tool called PostHog recorded what they did on the page.

    PostHog’s session-recording feature,
    which can replay every click, scroll and keystroke of a visitor’s time on a webpage,
    is installed in the code of all four sites and enabled on two of them.

    On the remaining two, the recording is held inactive only by a single setting inside PostHog’s dashboard,
    which can be changed by whoever controls the website at any time.

    The Guardian emailed PostHog for comment on its apparent provision of tracking tools to the NDS, but received no response.

    Adblockers and similar privacy tools are used by millions of people to limit what third parties can learn about them as they browse.
    Most of them work by intercepting requests that a visitor’s browser makes to known tracking services
    – and blocking them before any data leaves the device.

    Website source code shows that PostHog has been configured on
    NDS-run sites to route analytics requests through an address on the federal website itself,
    rather than through PostHog’s own servers.

    Because the request appears to go to the site the user is already visiting, rather than to a recognisable third-party address, adblockers don’t flag it.

    As PostHog explains in its own documentation,
    this works “because ad blockers haven’t visited your domain to catalog your setup.
    They don’t know what to block.”

    In other words, the technique is specifically designed to evade privacy tools
    – by presenting commercial tracking as ordinary website activity.

    Serge Egelman, research director of the Usable Security and Privacy Group at the International Computer Science Institute (ICSI), explained:

    “The issue there is that over the last several years,
    due to abuses relating to this type of data collection,
    there’s basically an arms race with tools being released to allow consumers to try and exert some control over what data gets collected.”

    Egelman said that he had not looked specifically at the PostHog tool or its deployment on federal websites,
    but he did point to a lawsuit involving the addition of commercial tracking technology to a state government website.

    “I testified on Meta where the [Meta] Pixel was put on the California DMV website.

    And Meta was able to obtain information about when people are requesting, say, disability placards,
    reinstating a suspended license, things like that
    – sensitive information that’s actually protected by federal law.”

    He added: “It’s not like someone going to the DMV website expects a private company to receive their personal data and then be allowed to use that however they want.”

    PostHog comes with a separate feature called session recording,
    which plays back every click, scroll and keystroke a visitor makes,
    like a video recording of their entire visit.

    Princeton University researchers who first documented the technology in 2017 wrote that watching such a recording was “as if someone is looking over your shoulder”.

    On the Trump Accounts and TrumpRX websites, the feature has been built into the page code and is held inactive only by a single setting inside PostHog’s dashboard.

    The NDS can turn it on at any time, on either site, without making changes in the underlying website code.

    Separately, until the Guardian sought comment on this reporting, the NDS’s own website, ndstudio.gov,
    ran a 539-line piece of bespoke code that recorded visitors’ clicks, form entries and navigation;

    assigned each visitor a session identifier;

    and forwarded the captured data to an address that does not appear anywhere on the public internet.

    The script’s source code refers to it as AutoMonitor.

    #posthog #JoeGebbia #nds #doge #tracking #surveillance

  11. Analysis of the underlying source code for four of the websites written by the secretive National Design Studio (NDS)
    found that on at least two of them,
    the studio installed a commercial tool called PostHog
    that closely tracks what every visitor does on the site.

    Another tool, apparently made in-house, sends user data to a destination that is not visible on the public internet.

    The NDS apparently removed this tracking software after the Guardian reached out to the White House with a detailed series of questions on the NDS’s operations on 4 June.

    On 17 June, White House spokesperson Liz Huston responded:

    “All National Design Studio personnel comply with all legal requirements in their important work to improve how citizens interact with their government.”

    The studio has also built versions of services legally assigned to other agencies,
    including a passports website,
    and a copy of
    💥Login.gov,
    the gateway more than 150 million Americans use to sign in to federal services,
    -- the latter reportedly being overseen by a former Doge engineer who moved to the studio.

    The NDS has also apparently built a copy of
    💥vote.gov,
    the federal voter-registration site that by law belongs to an independent bipartisan commission
    inside a website site only accessible with a White House login.

    🔥A federal voter-registration system run from inside the White House,
    with identity and citizenship checks routed through systems the administration controls,
    could let an incumbent see who is registering,
    or check their registration, in the weeks before an election.

    Public ownership records maintained by the Cybersecurity and Infrastructure Security Agency (Cisa)
    list the executive office of the president as the registrant of the studio’s sites,
    including passports.gov and the vote.gov copy,
    👉meaning that the office controls the domains.

    Questions remain about the sort of access that this could give the White House to voter registration data.

    John Davisson, senior counsel at the Electronic Privacy Information Center (EPIC),
    said the studio’s approach risked creating a second version
    “a whole sort of second skunk-works version of the federal government
    with all these shady tracking technologies
    and outside of the parameters of normal federal privacy laws”.

    A skunk works is a figurative term for an experimental department within a larger organization with freedom to operate outside normal procedure.

    The Guardian sent a detailed list of questions about the NDS to the White House Press Office for the attention of Gebbia and the White House chief of staff, Susie Wiles,
    who has oversight of the studio.

    Separately, the Guardian sent a request to Gebbia’s presumed email at the NDS
    (no addresses are publicly listed).
    There was no response.

    #posthog
    #JoeGebbia #nds #doge #tracking #surveillance

  12. Analysis of the underlying source code for four of the websites written by the secretive National Design Studio (NDS)
    found that on at least two of them,
    the studio installed a commercial tool called PostHog
    that closely tracks what every visitor does on the site.

    Another tool, apparently made in-house, sends user data to a destination that is not visible on the public internet.

    The NDS apparently removed this tracking software after the Guardian reached out to the White House with a detailed series of questions on the NDS’s operations on 4 June.

    On 17 June, White House spokesperson Liz Huston responded:

    “All National Design Studio personnel comply with all legal requirements in their important work to improve how citizens interact with their government.”

    The studio has also built versions of services legally assigned to other agencies,
    including a passports website,
    and a copy of
    💥Login.gov,
    the gateway more than 150 million Americans use to sign in to federal services,
    -- the latter reportedly being overseen by a former Doge engineer who moved to the studio.

    The NDS has also apparently built a copy of
    💥vote.gov,
    the federal voter-registration site that by law belongs to an independent bipartisan commission
    inside a website site only accessible with a White House login.

    🔥A federal voter-registration system run from inside the White House,
    with identity and citizenship checks routed through systems the administration controls,
    could let an incumbent see who is registering,
    or check their registration, in the weeks before an election.

    Public ownership records maintained by the Cybersecurity and Infrastructure Security Agency (Cisa)
    list the executive office of the president as the registrant of the studio’s sites,
    including passports.gov and the vote.gov copy,
    👉meaning that the office controls the domains.

    Questions remain about the sort of access that this could give the White House to voter registration data.

    John Davisson, senior counsel at the Electronic Privacy Information Center (EPIC),
    said the studio’s approach risked creating a second version
    “a whole sort of second skunk-works version of the federal government
    with all these shady tracking technologies
    and outside of the parameters of normal federal privacy laws”.

    A skunk works is a figurative term for an experimental department within a larger organization with freedom to operate outside normal procedure.

    The Guardian sent a detailed list of questions about the NDS to the White House Press Office for the attention of Gebbia and the White House chief of staff, Susie Wiles,
    who has oversight of the studio.

    Separately, the Guardian sent a request to Gebbia’s presumed email at the NDS
    (no addresses are publicly listed).
    There was no response.

    #posthog
    #JoeGebbia #nds #doge #tracking #surveillance

  13. Is anyone working to block #PostHog first-party routing on U.S. federal websites?

    It appears that #UBlockOrigin could do it but it would require a list of custom network filters.

    theguardian.com/us-news/2026/j

    #infosec #eff

  14. 👨‍💻 In the latest saga of "I did it #without trying", our hero claims to have revamped PostHog's #SQL #parser, achieving #warp #speed 🚀 without even glancing at the code. Clearly, the next logical step is to solve #world #hunger with a casual scroll through Pinterest 🍕.
    posthog.com/blog/sql-parser #PostHog #coding #effort #solution #HackerNews #ngated

  15. 👨‍💻 In the latest saga of "I did it #without trying", our hero claims to have revamped PostHog's #SQL #parser, achieving #warp #speed 🚀 without even glancing at the code. Clearly, the next logical step is to solve #world #hunger with a casual scroll through Pinterest 🍕.
    posthog.com/blog/sql-parser #PostHog #coding #effort #solution #HackerNews #ngated

  16. damn, #posthog has an #mcp server!!!

    connect that s* to your AI and let it give you actionable tips...

    man why did I not do this sooner!!!

    #saas #bootstrap #solopreneur #buildinpublic

  17. damn, #posthog has an #mcp server!!!

    connect that s* to your AI and let it give you actionable tips...

    man why did I not do this sooner!!!

    #saas #bootstrap #solopreneur #buildinpublic

  18. When the federal government collects information about citizens,
    the law requires specific things first.

    Privacy disclosures.

    Notices in the Federal Register.

    Published contracts with outside vendors.

    I went looking for all of it across twelve National Design Studio programs and found none of it,
    not a single required document filed across any of the twelve.

    Every missing document is, by itself, a violation of federal law,
    and these are the laws Congress wrote after Watergate to make sure the federal government could not run secret surveillance programs on its own citizens.

    The only document they did publish is a privacy policy on TrumpRx,
    and it contradicts itself two paragraphs apart.

    The first paragraph says PostHog records the pages users visit and the medications they view.

    Two paragraphs later, it says they do not collect health or medical information.

    A federal health website is lying to the people using it and cannot even keep the lie consistent.

    I wanted to know whether there were more sites the studio had not announced.

    Here is something almost nobody outside of security research knows.

    Every website with a padlock in the address bar has a certificate,
    and there is a rule that every certificate issued anywhere in the world must be logged in a public ledger the moment it is created,
    no exceptions.

    The side effect of that rule is that every new website on the internet,
    even ones nobody has announced and even ones hidden behind a login,
    leaves a public fingerprint the moment it is built.

    There is a free search engine called 👉 crt.sh where anyone can look up those logs.

    I typed in the studio’s domain, and underneath the public sites I already knew about were roughly forty more, unannounced,
    with no links pointing to them from any public page.

    I started reading the names.

    Sites that looked like they belonged to the State Department.
    To NASA.
    To the Department of Homeland Security.

    And then two that stopped me cold:

    a working preview of vote.gov,

    and something called fbi-kirk-tipline.

    I checked the public ownership records for every subdomain,
    and every single one traced back to the same place,
    the Executive Office of the President.

    The National Design Studio had built pre-launch versions of websites belonging to other federal agencies
    and registered all of it to the White House.
    #NationalDesignStudio
    #surveillance #gebbia
    #PostHog #AutoMonitor

  19. When the federal government collects information about citizens,
    the law requires specific things first.

    Privacy disclosures.

    Notices in the Federal Register.

    Published contracts with outside vendors.

    I went looking for all of it across twelve National Design Studio programs and found none of it,
    not a single required document filed across any of the twelve.

    Every missing document is, by itself, a violation of federal law,
    and these are the laws Congress wrote after Watergate to make sure the federal government could not run secret surveillance programs on its own citizens.

    The only document they did publish is a privacy policy on TrumpRx,
    and it contradicts itself two paragraphs apart.

    The first paragraph says PostHog records the pages users visit and the medications they view.

    Two paragraphs later, it says they do not collect health or medical information.

    A federal health website is lying to the people using it and cannot even keep the lie consistent.

    I wanted to know whether there were more sites the studio had not announced.

    Here is something almost nobody outside of security research knows.

    Every website with a padlock in the address bar has a certificate,
    and there is a rule that every certificate issued anywhere in the world must be logged in a public ledger the moment it is created,
    no exceptions.

    The side effect of that rule is that every new website on the internet,
    even ones nobody has announced and even ones hidden behind a login,
    leaves a public fingerprint the moment it is built.

    There is a free search engine called 👉 crt.sh where anyone can look up those logs.

    I typed in the studio’s domain, and underneath the public sites I already knew about were roughly forty more, unannounced,
    with no links pointing to them from any public page.

    I started reading the names.

    Sites that looked like they belonged to the State Department.
    To NASA.
    To the Department of Homeland Security.

    And then two that stopped me cold:

    a working preview of vote.gov,

    and something called fbi-kirk-tipline.

    I checked the public ownership records for every subdomain,
    and every single one traced back to the same place,
    the Executive Office of the President.

    The National Design Studio had built pre-launch versions of websites belonging to other federal agencies
    and registered all of it to the White House.
    #NationalDesignStudio
    #surveillance #gebbia
    #PostHog #AutoMonitor

  20. The structure of the National Design Studio will be familiar to anyone who has been paying attention.

    Staff are hired under a federal authority called Section 3161,
    written for temporary advisory bodies,
    which means most of them are part-time advisors or volunteers.

    They do not appear on the White House salary report.

    They answer to no inspector general, because the Executive Office of the President does not have one.

    If that sounds familiar, it should,
    because it is exactly how DOGE was run.

    Gebbia spent six months at DOGE before taking his current role.

    The senior staff at the National Design Studio, when you pull the bylines from their blog posts and run the names against court filings, come back from the same place,
    -- DOGE -- the same DOGE currently named as defendant in multiple federal lawsuits for letting engineers without proper security clearance access Social Security data and Department of Homeland Security data,
    and for sharing sensitive federal information with outside parties.

    The National Design Studio is not a successor to DOGE.

    It is DOGE with a better logo and a design philosophy.

    Now, back to TrumpRx looking at you.

    Every webpage you load is making phone calls.

    Not to people, but to servers around the internet,
    -- dozens per second, all invisible to you.

    When I opened TrumpRx, I right-clicked the page, opened the browser’s built-in inspector, and started reading the list.

    Mixed in with the routine traffic was a name I recognized:
    #PostHog.

    PostHog is a Silicon Valley analytics company whose entire business model is recording what visitors do on a website and reporting it back to whoever owns the site.

    Mouse movements, clicks, scrolls, keystrokes.

    I had not typed anything. I had not clicked anything.

    I had just opened the page, and it was already on the phone with PostHog telling them about me.

    The recordings are not anonymized.

    IP addresses are not stripped.

    And the way it is configured, the data looks to your browser like it is going back to TrumpRx,
    but it is actually being forwarded behind the scenes to PostHog.

    That is a technique used to slip past ad blockers by disguising where the data is really going,
    and it is not something I expected to find on a federal health website.

    So I went and looked at the other sites the studio had built.

    Real Food, the federal food policy site.

    Trump Accounts, the children’s savings program.

    The studio’s own homepage, ndstudio.gov.

    All of them had the same vendor, the same setup,
    IP addresses not stripped,
    the same forwarding trick.

    And on ndstudio.gov alone,
    running alongside PostHog,
    was something someone had built entirely by hand.

    Five hundred and forty lines of custom JavaScript with a name embedded directly in the code:
    #AutoMonitor.

    What it appears to do is rewire the part of the browser that handles how a page talks to the outside world,
    so that every conversation the page has with any server gets copied and forwarded to a private backend with no public presence.

    The studio has the structural ability to keep a copy of every recording as it passes through their infrastructure.

    I cannot prove they are keeping one.

    The pipe is built that way on purpose, and that is the part that matters.

    thedreydossier.substack.com/p/

  21. The structure of the National Design Studio will be familiar to anyone who has been paying attention.

    Staff are hired under a federal authority called Section 3161,
    written for temporary advisory bodies,
    which means most of them are part-time advisors or volunteers.

    They do not appear on the White House salary report.

    They answer to no inspector general, because the Executive Office of the President does not have one.

    If that sounds familiar, it should,
    because it is exactly how DOGE was run.

    Gebbia spent six months at DOGE before taking his current role.

    The senior staff at the National Design Studio, when you pull the bylines from their blog posts and run the names against court filings, come back from the same place,
    -- DOGE -- the same DOGE currently named as defendant in multiple federal lawsuits for letting engineers without proper security clearance access Social Security data and Department of Homeland Security data,
    and for sharing sensitive federal information with outside parties.

    The National Design Studio is not a successor to DOGE.

    It is DOGE with a better logo and a design philosophy.

    Now, back to TrumpRx looking at you.

    Every webpage you load is making phone calls.

    Not to people, but to servers around the internet,
    -- dozens per second, all invisible to you.

    When I opened TrumpRx, I right-clicked the page, opened the browser’s built-in inspector, and started reading the list.

    Mixed in with the routine traffic was a name I recognized:
    #PostHog.

    PostHog is a Silicon Valley analytics company whose entire business model is recording what visitors do on a website and reporting it back to whoever owns the site.

    Mouse movements, clicks, scrolls, keystrokes.

    I had not typed anything. I had not clicked anything.

    I had just opened the page, and it was already on the phone with PostHog telling them about me.

    The recordings are not anonymized.

    IP addresses are not stripped.

    And the way it is configured, the data looks to your browser like it is going back to TrumpRx,
    but it is actually being forwarded behind the scenes to PostHog.

    That is a technique used to slip past ad blockers by disguising where the data is really going,
    and it is not something I expected to find on a federal health website.

    So I went and looked at the other sites the studio had built.

    Real Food, the federal food policy site.

    Trump Accounts, the children’s savings program.

    The studio’s own homepage, ndstudio.gov.

    All of them had the same vendor, the same setup,
    IP addresses not stripped,
    the same forwarding trick.

    And on ndstudio.gov alone,
    running alongside PostHog,
    was something someone had built entirely by hand.

    Five hundred and forty lines of custom JavaScript with a name embedded directly in the code:
    #AutoMonitor.

    What it appears to do is rewire the part of the browser that handles how a page talks to the outside world,
    so that every conversation the page has with any server gets copied and forwarded to a private backend with no public presence.

    The studio has the structural ability to keep a copy of every recording as it passes through their infrastructure.

    I cannot prove they are keeping one.

    The pipe is built that way on purpose, and that is the part that matters.

    thedreydossier.substack.com/p/

  22. Posthog announces they went with the nuclear AI option, a new AI policy that makes Copilot look like a champion for privacy.

    All #posthog data outside the EU, across all paid usage tiers, will be used to train a #ai new model. Organizations like mine woke up to find they were already automatically enrolled. Oh, but you can opt-out of course. "Why this is opt out, not opt in... Put simply, because otherwise we will not have enough data to train a model that's actually useful" (posthog.com/blog/training-ai-m). While on their own account management page, "you are responsible for ensuring your use complies with applicable laws and regulations."

    If your business model depends on violating customer #privacy and exposing your clients to novel legal/PR/ethical risks, then you have a bad business. I chose to pay posthog instead of free #google analytics because of their stronger privacy position. Guess I got that one wrong.

  23. Posthog announces they went with the nuclear AI option, a new AI policy that makes Copilot look like a champion for privacy.

    All #posthog data outside the EU, across all paid usage tiers, will be used to train a #ai new model. Organizations like mine woke up to find they were already automatically enrolled. Oh, but you can opt-out of course. "Why this is opt out, not opt in... Put simply, because otherwise we will not have enough data to train a model that's actually useful" (posthog.com/blog/training-ai-m). While on their own account management page, "you are responsible for ensuring your use complies with applicable laws and regulations."

    If your business model depends on violating customer #privacy and exposing your clients to novel legal/PR/ethical risks, then you have a bad business. I chose to pay posthog instead of free #google analytics because of their stronger privacy position. Guess I got that one wrong.

  24. 🤖✨ In a stunning display of corporate altruism, #PostHog is generously allowing its users to contribute their #data to train #AI models... by default. It's an opt-out extravaganza where your data fuels the future of AI, whether you like it or not. 🛠️🔍 Remember, nothing screams "cutting-edge innovation" quite like turning your customers into unwitting guinea pigs! 🐹💾
    posthog.com/blog/training-ai-m #CorporateAltruism #UserPrivacy #Innovation #DataEthics #HackerNews #ngated

  25. 🤖✨ In a stunning display of corporate altruism, #PostHog is generously allowing its users to contribute their #data to train #AI models... by default. It's an opt-out extravaganza where your data fuels the future of AI, whether you like it or not. 🛠️🔍 Remember, nothing screams "cutting-edge innovation" quite like turning your customers into unwitting guinea pigs! 🐹💾
    posthog.com/blog/training-ai-m #CorporateAltruism #UserPrivacy #Innovation #DataEthics #HackerNews #ngated

  26. 🦔 HogLens v1.2 is here — the biggest update yet.

    You can now import dashboards directly from PostHog. Plus: Funnel & Retention charts.
    Native PostHog analytics on macOS & iOS.

    hoglens.link/f8c

    #PostHog #analytics #macOS #iOS #KREANIQS
    hoglens.link/f8c

  27. 🎉🎈 Breaking news: a worm named after a fictional sandworm attacked on November 24th, 2025! No, it’s not from a sci-fi novel, it's from the land of #PostHog 🤦‍♂️. Read on for a riveting tale of what went wrong, because who doesn't love a good #postmortem of digital chaos? 😜
    posthog.com/blog/nov-24-shai-h #BreakingNews #DigitalChaos #WormAttack #SciFiFiction #HackerNews #ngated

  28. 🎉🎈 Breaking news: a worm named after a fictional sandworm attacked on November 24th, 2025! No, it’s not from a sci-fi novel, it's from the land of #PostHog 🤦‍♂️. Read on for a riveting tale of what went wrong, because who doesn't love a good #postmortem of digital chaos? 😜
    posthog.com/blog/nov-24-shai-h #BreakingNews #DigitalChaos #WormAttack #SciFiFiction #HackerNews #ngated