# Privacy Guides > Established in 2021, Privacy Guides is the largest impartial, non-profit media outlet focused on finding privacy tools and learning about protecting your digital life. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### Privacy & Security News URL: https://www.privacyguides.org/news/ Last updated: 2025-11-23T07:44:56.000Z [RSS Feed](https://www.privacyguides.org/news/rss/) • Follow [**@PrivacyNews**@mstdn.plus](https://mstdn.plus/@privacynews) on Mastodon • [Find more news on the forum](https://discuss.privacyguides.net/c/privacy/news/9409) ### Welcome URL: https://www.privacyguides.org/welcome-members/ Last updated: 2026-05-15T23:38:23.000Z Thank you for your support, members! _This post is for paying subscribers only._ ### Donate (Monero) URL: https://www.privacyguides.org/donate-monero/ Last updated: 2026-07-06T18:24:31.000Z Thank you for supporting our project! We are with one of the few non-profits which proudly supports donations via [anonymous cryptocurrency](https://www.privacyguides.org/en/cryptocurrency/). 💡 We recommend that you donate Monero (XMR) through the [MAGIC Grants campaign website](https://donate.magicgrants.org/privacyguides) instead of the address below. This allows you to specify if you would like to receive a tax deduction, which you may qualify for. You can donate Monero (XMR) to Privacy Guides at the following address. ![](https://www.privacyguides.org/content/images/2026/07/image.png) `882XLsoGHjXipTq8oKF35H2ytPg28TMFrim35MwvQUir54wuAmXUCx68X1mWGgR5KSdZqykf87tKei5xcJiP3dLSCiWgxUk` **OpenAlias:** `privacyguides.magicgrants.org` Donations to this address are directed to our video production campaign. You will receive no receipt for donations to the address above. Please use the [campaign website](https://donate.magicgrants.org/privacyguides) instead if you want a donation receipt, or if you want to donate to a different campaign we're running. The wallet address here is **subject to change** without notice. Please always re-check this page prior to making a donation. ## Posts ### Data Breach Roundup (Sep 11 - 17, 2026) URL: https://www.privacyguides.org/news/2026/09/18/data-breach-roundup-sep-11-17-2026/ Last updated: 2026-09-18T16:10:38.000Z ## Florida confirms DMV database breached via stolen police account The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system. FLHSMV determined that the attacker used compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on the employee's personal electronic device. The attackers, however, claimed they exploited a password reset flaw to gain access to multiple DAVID accounts, including accounts belonging to DMV employees and an FBI agent. [Florida confirms DMV database breached via stolen police accountThe Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee.![](https://www.privacyguides.org/content/images/icon/bleeping-5ae29b98-8104-4b3c-94c7-e6ee5fc39ac8.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/data-leak-69e05aeb-dc3e-43e7-aaf4-005806233a33.jpg)](https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/) ## Revolut confirms customer data breach through fake government requests British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver’s licenses. The data may have also included verification selfies, account statements, and transaction histories, the firm said in its notification. Revolut did not answer questions about how many people were impacted or in what markets. [Revolut confirms customer data breach through fake government requests | TechCrunchRevolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-f3b3e565-8a21-4913-8e88-a0607885f228.png)TechCrunchJagmeet Singh![](https://www.privacyguides.org/content/images/thumbnail/revolut-1f78b110-f825-40e5-a1e1-305e7092eb80.png)](https://techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/) ## Japan's Digital Agency says VPN flaw exposed 246,000 personnel records It is unclear what VPN product was affected or the vulnerability exploited in the breach. The Japanese agency said in a separate Q&A that the issue had a medium severity rating and was not a zero-day. Potentially impacted data includes 236,000 names; 231,000 email addresses; 94,000 telephone numbers; and 1,000 physical addresses. Exposed individuals include government employees, public officials, and associated businesses and individuals who use the Government Solution Service system. The incident did not expose personal data of the general public, and the potentially compromised information does not include My Number identification numbers, bank-account details, or pension numbers. [Japan’s Digital Agency says VPN flaw exposed 246,000 personnel recordsJapan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees.![](https://www.privacyguides.org/content/images/icon/bleeping-b755b986-0214-4b76-a9cb-4c54bb956839.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/japan-7956c82d-2141-4041-b869-e2e45fb73a15.jpg)](https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/) ## CenterPoint Energy confirms customer data stolen in cyberattack CenterPoint Energy is a Houston-based public utility company that provides electric and natural gas services with 7 million customers across Indiana, Minnesota, Ohio, and Texas. The attacker claims to have stolen 7.49 million records including names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers (SSNs). [CenterPoint Energy confirms customer data stolen in cyberattackCenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company.![](https://www.privacyguides.org/content/images/icon/bleeping-d060d6f0-2ee1-49d9-a3bc-59a9b773fcd1.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/CenterPoint-2d1a583e-8d42-4d6f-9c67-c580ef90fdd4.jpg)](https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/) ## Spain's data agency gets first report of AI-powered data breach There's very little information about this breach like what company was impacted or how many people were impacted, or even exactly what information was affected. The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages of the attack, the agent modified personal data and accessed financial documents. [Spain’s data agency gets first report of AI-powered data breachThe Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).![](https://www.privacyguides.org/content/images/icon/bleeping-cfe80959-21db-4c43-ad7e-9eeebe2dcdd9.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/ai-1-75eca987-adf6-4937-bb2a-b7464f6534a4.jpg)](https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/) ### 2026 Instant Messenger Tier List: Are You Secure? URL: https://www.privacyguides.org/videos/2026/09/18/2026-instant-messenger-tier-list-are-you-secure/ Last updated: 2026-09-18T01:30:30.000Z We compared the top instant messengers (and the ones not quite there yet) to find out how they stack up. Let us know where your favorite choice fell, or if we missed anything in the comments! ### UK Rolls Out Passkeys for Millions of Citizens URL: https://www.privacyguides.org/news/2026/09/17/uk-rolls-out-passkeys-for-millions-of-citizens/ Last updated: 2026-09-17T19:36:29.000Z The [UK](https://www.gov.uk/government/news/millions-of-people-to-benefit-from-simpler-more-secure-way-to-sign-in-to-government-services) is rolling out passkeys across GOV.UK One Login to provide more than 23 million people with a more secure way to log in. [Passkeys](https://www.privacyguides.org/articles/2025/03/08/toward-a-passwordless-future/) are secure digital credentials that are meant to replace passwords. They are securely generated and stored on your device, so they're always random and secure since you don't have to come up with them yourself. They operate using public key cryptography, similar to PGP or TLS. Your private key is never stored by the website you're logging in to, so your login credentials can't be leaked in a data leak like passwords can. They're also phishing-resistant: if you try to log in to a fake website with your real credentials, it won't work, since the credentials are tied to that specific website. The UK says that more than 300,000 users have switched to passkeys already during the initial trial phase, and they are now rolling them out to millions of users. > Nearly one in 10 daily GOV.UK One Login sign-ins are now made using passkeys, helping to save the British taxpayer nearly £600 a day in SMS costs. SMS is a common way services try to secure user accounts, but it's clearly costly to send the codes out and SMS is horribly insecure. It has no encryption, so anyone can see your sensitive login code in transit. It's also vulnerable to [SS7 attacks](https://www.cyber8200.com/en/blog/understanding-ss7-attacks-risks-prevention) that allow attackers to intercept and send your login codes wherever they want. For now, there's no option to sign up with a passkey, you have to add one later after you create your GOV.UK account with a password. There's also no way to remove your password after you make a passkey, which negates many of the benefits of passkeys in the first place: an attacker could still pretend to be GOV.UK and simply ask for the password instead, and every user would still be in danger of getting phished. The account also requires an email address, and you can simply bypass the passkey and password by clicking on "forgot my password." This leaves a big gaping security hole where any attacker that has access to your email account, or intercepts the password reset email which is not end-to-end encrypted, can get access to your government account. Still, it's good to see governments offering more secure login methods even if there's still room for improvement. ### Signal Enables Phone Number-less Registration in Beta URL: https://www.privacyguides.org/news/2026/09/16/signal-enables-phone-number-less-registration-in-beta/ Last updated: 2026-09-16T19:02:36.000Z Signal has officially announced signups without phone numbers on their [community forum](https://community.signalusers.org/t/beta-feedback-for-the-upcoming-android-8-28-release/76457) for the Android 8.28 beta version of the app. "Phonenumberless registration" has been a requested feature in Signal for many years. As one of the most highly-recommended private messengers, requiring a phone number was a pain point for many people. A lot of countries have Know Your Customer (KYC) laws that require you to identify yourself when you sign up for a phone number. Even if you live somewhere where you don't have to give your identity in order to buy a phone number, most people use their phone number for multiple very personal things like communicating with their doctor and personal friends and family, so giving it away can still be uncomfortable. Signal previously released a feature that allows you to chat with people under a [username](https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames) and prevent people you're chatting with from seeing your phone number, but Signal itself still asks for your number on signup. Phonenumberless registration will close a big complaint that Signal users have had for many years, and that other messengers like Session, SimpleX Chat, and Threema don't suffer from since they don't require any personal information in order to use them. The registration is only available on Android for now and costs a one-time fee of $2.99\. The fee is meant to make it financially infeasible for spammers to create thousands of accounts and ruin Signal's network. The payment is currently only offered through Play Services, but more payment methods are planned for the future. This means that users who don't have Play Services, such as people running GrapheneOS without Sandboxed Google Play, won't be able to try the feature out just yet. ![](https://www.privacyguides.org/content/images/2026/09/image-2.png) Source: [About Signal](https://aboutsignal.com/news/signal-registration-without-a-phone-number-now-available/) The payment uses the same zero-knowledge proofs as Signal's donation system, so they won't be able to correlate your payment info to you. Interestingly, the username is still optional, and if you don't set one, the account will be "completely unreachable" and the only chats you can participate in are ones you start yourself. Your account will be secured using a new Account ID and Account Key, sort of like a traditional username and password, which you can save in your password manager. You can also enable TOTP 2FA to further secure your account, and they say passkey support is coming in the future. You also won't be able to remove your number from an already-existing account, and they say they're still "thinking through the implications." ### X's Encrypted Messenger, X Chat, Disappears From the App Store and the Google Play Store URL: https://www.privacyguides.org/news/2026/09/15/xs-encrypted-messenger-x-chat-disappears-from-the-app-store-and-the-google-play-store/ Last updated: 2026-09-15T18:46:03.000Z [X Chat](https://x.com/chat), X's dedicated end-to-end encrypted messaging app, has disappeared from both Apple's [App Store](https://apps.apple.com/us/app/xchat/id6760873038) and the [Google Play](https://play.google.com/store/apps/details?id=com.x.chat) Store. According to [9to5Mac](https://9to5mac.com/2026/09/14/xchat-xs-standalone-messaging-app-currently-unavailable-on-app-store/), the app's disappearance is not due to the stores removing the app but instead X removing it of its own accord. X Chat was essentially a standalone version of direct messages on X itself. It only released a few months ago in [April](https://www.forbes.com/sites/kateoflahertyuk/2026/04/24/elon-musks-xchat-app-launch-everything-you-need-to-know/) of this year, making it a very short-lived app if they have officially discontinued it. The official [XChat](https://x.com/chat) account didn't mention anything about it either. The bizarre thing is that X didn't seem to announce that it would be discontinuing the app to give people time to migrate away or let them know they should uninstall the app while it stops receiving updates. X's [documentation](https://help.x.com/en/using-x/about-chat) still mentions the X Chat app, so it seems they haven't even bothered to update their official support pages to reflect the change. As a side note, they can't seem to decide officially if it's called X Chat or XChat. When you try to DM someone on X, it calls *that* "X Chat" and explains that it's E2EE. ![](https://www.privacyguides.org/content/images/2026/09/image-1.png) You don't need the X app either, E2EE messaging seems to be the default for direct messages on the website as well. Hopefully, the removal of the XChat apps doesn't signal a move away from encrypted messaging on X, it's genuinely good that they offer this as a feature. Other platforms have taken a stance against E2EE messaging. Instagram [removed](https://www.privacyguides.org/news/2026/03/18/instagram-ending-e2ee-support/) E2EE support for its messages. TikTok stated that they wouldn't add E2EE for "user safety" reasons. That being said, X's approach to E2EE leaves a lot to be desired. According to their [documentation](https://help.x.com/en/using-x/about-chat), when you start an encrypted conversation, the private key is actually sent to X's infrastructure and is only protected by a flimsy 4-digit PIN. Not only is a 4-digit PIN easy to guess, it's so quick to brute force that it's effectively [instantaneous](https://countingmethods.com/password-security-tool/) using any modern computer. Supposedly, the open-source [Juicebox](https://juicebox.xyz/blog/) protocol X uses prevents brute forcing and hardware security modules are used to rate limit guesses. They also state that their encryption lacks forward secrecy, so an attacker who is able to gain access to the private key of one of your registered devices will have access to all of your messages. Supposedly, plans are in place to introduce forward secrecy in the future. ### Cops Search Flock Database for Reasons Such as "LMAO," "LOL," and Random Keyboard Mashing URL: https://www.privacyguides.org/news/2026/09/14/cops-search-flock-database-for-reasons-such-as-lmao-lol-and-random-keyboard-mashing/ Last updated: 2026-09-14T19:21:23.000Z An [investigation](https://www.eff.org/deeplinks/2026/09/high-crime-lmao-how-cops-are-treating-mass-surveillance-joke) by the EFF found that cops treat mass surveillance as a joke, typing reasons for searches such as "LMAO," "LOL," and other non sequiturs or keyboard mashing in leu of an actual reason. The EFF obtained Flock Safety ALPR search data via public records requests and found within their tables of database accesses a disturbing trend of cops not giving proper reasons for accessing sensitive surveillance data. Several other reasons listed include "haha," "hehe," and "idk lol." The brazen nonchalantness with which the police officers searched people's license plates shows how little these police departments care about invading the privacy of regular citizens. Among the reasons listed are also straight up keyboard mashing such as "gyghkkghghjkghjk." Clearly the reason field is just seen as an annoyance rather than a chance to stop and ask if it's really necessary to access the data. And it is a department-wide problem and not just a few bad apples. The EFF says it's not uncommon for small police departments to have millions of searches from thousands of external agencies across the US. The searches were done for even low-profile crimes such as loud noise complaints, running employee background checks, or targeting a motorcyclist for hiding a cell phone. The actual searches often consist of very vague terms, such as "weird kid" or "weird kid," "driving around weird," or "idiot." There are also searches for "d\*ckhead*,"* "sh\*thead," and "sexy." Among the search terms are active targeting of racial groups such as "Roma" and "g\*psy" targeting the Roma people specifically of suspected crimes. Cops misusing ALPR data has real-world consequences. It's been widely reported that police officers have been caught using these camera systems to stalk their [exes](https://www.washingtonpost.com/technology/2026/08/02/how-police-officers-used-vast-network-cameras-spy-their-exes/) and [potential romantic partners](https://reason.com/2026/07/10/florida-police-officer-used-mass-surveillance-network-to-stalk-romantic-interest/). They've also lead to several [false arrests](https://www.cbsnews.com/news/license-plate-readers-alpr-mistakes/) due to errors by these license plate readers. Not only do law enforcement base arrests on flawed [facial recognition systems](https://quadrangle.michigan.law.umich.edu/index.php/issues/winter-2024-2025/flawed-facial-recognition-technology-leads-wrongful-arrest-and-historic), they also get [license plate numbers wrong](https://www.yahoo.com/news/us/articles/case-case-every-reported-flock-175653036.html?guccounter=1&guce%5Freferrer=aHR0cHM6Ly9kdWNrZHVja2dvLmNvbS8&guce%5Freferrer%5Fsig=AQAAADpMU2kcDkI17g4gXWS3JLt-bXPtP1MoERIR9bh0ru9kcesxiOvDcUqTHJN21Ce%5FjadArw0JRyZcBpg8bY9msBpaYs4LWfM2N6XoQlzIXF6cz4V61emgCuXUTucM1ii5TeY0w5EXM3AyX1ZRsivy-eDta9UaDISDYxAELFT6q5gU): literally the one thing they're designed to do. The lack of scrutiny in these cases is clearly reflected in every step of the process, including the initial search. As the backlash against Flock cameras mounts, it's important to remember that it's not one specific company that's the problem, it's ALPRs as a whole and police departments' inability to use them responsibly. Other companies like [Axon](https://thenewamerican.com/us/cities-drop-flock-expand-surveillance-with-axon/) seem to have picked up the slack, picking up the contracts from some cities that have dropped Flock due to backlash. ### Revolut Gives Away Customer Passports, Selfies, and Transaction Histories to a Fake Government Request URL: https://www.privacyguides.org/news/2026/09/13/revolut-gives-away-customer-passports-selfies-and-transaction-histories-to-a-fake-government-request/ Last updated: 2026-09-13T23:18:09.000Z Revolut [disclosed](https://www.internationalcyberdigest.com/revolut-gave-away-customers-data/) customers' passports, selfies, and full transaction histories to a fake government employee over email. The email requesting the info came from a legitimate government domain, but from an unauthorized account, with valid domain authentication credentials. Because of this, Revolut believed they were sending the info to a real government agency. Revolut later discovered it was not a legitimate government request and sent notices to its customers regarding what data might have been sent. The notice lists full name, date of birth, occupation, postal address, email address, phone number, passports, drivers licenses, facial verification selfies, account statements, account status, opening date, wallet reference number, and complete transaction histories including Bitcoin. Biometric facial telemetry data was not shared, so at least there's that. The company was not hacked, this was a voluntary disclosure of their customers' data. Revolut has not made a public statement about this; we only know what we do from notices sent from Revolut to their customers. Revolut says they've contacted the agency in order to validate the request and alert them to the unauthorized user, blocked the address internally, and began to apply precautionary protections to the affected accounts. Revolut hasn't made public certain information about the case, such as the name of the agency involved, how the person got a valid mailbox on their domain, how many customers were affected, or when they got the request and when it was fulfilled. As usual, multiple things had to go wrong for all of this to take place. The first problem is that Revolut even had so much data in the first place to give away. It's not really their fault though: so-called Know Your Customer (KYC) laws require companies like Revolut to collect sensitive data like passports, drivers licenses, and selfies in order to verify your identity. This obviously makes any financial institution beholden to KYC laws a juicy target for hackers. Handling sensitive user data over email is another massive issue. Email is [extremely insecure](https://www.privacyguides.org/articles/2025/11/15/email-security/) by default and even assuming you do everything right, many vulnerabilities have been found in [encryption software](https://www.privacyguides.org/news/2026/01/07/multiple-vulnerabilities-found-in-gnupg/) used to protect email content, and in [email clients](https://efail.de). It's not known if end-to-end encryption was used, but if it wasn't, that's even more irresponsible. The security of the agency in question is also probably quite poor if someone was able to hack into their system and create an account. It brings the safety of your data into question, from both the companies being forced to process it to comply with laws and from the people issuing it to you in the first place. ### The New Apple Watch is Always Listening?! URL: https://www.privacyguides.org/livestreams/2026/09/11/the-new-apple-watch-is-always-listening/ Last updated: 2026-09-11T23:59:36.000Z Our top stories this week: - Apple Doesn’t Want You to Worry About the New Apple Watch’s Listening Features - LG TVs caught spying even when offline or on standby - GrapheneOS Will Overhaul Default Apps and Implement a Secure Clipboard --- ## TWIP Live 🔴 --- ## Updates from the Team ### Why Big Tech's Privacy Promises Are Lies Melanie Ensign is the founder and CEO of Discernible and former communications lead for Facebook, Uber, AT&T, and DEF CON. She pulls back the curtain on how these large corporations operate, revealing why most internal privacy teams operate like "tax attorneys" rather than privacy advocates. [Why Big Tech’s Privacy Promises Are LiesMelanie Ensign is the founder and CEO of Discernible and former communications lead for Facebook, Uber, AT&T, and DEF CON. She pulls back the curtain on how these large corporations operate, re…![](https://www.privacyguides.org/content/images/icon/favicon-8fcaffac-eda3-48e1-93d0-82070aaba059.png)Neat.TubePrivacy Guides![](https://www.privacyguides.org/content/images/thumbnail/60a6fb9c-1e65-4e62-8b36-07c80e2988d3-bab40551-dda0-4ded-9969-b0f9c085dd59.webp)](https://neat.tube/w/57bdLTrK3s5AjRc9w4MrE5) ### News Briefs Once again, our news briefs remain one of the best ways to stay updated with breaking news in the privacy space. This week we talked about Microsoft's latest record-breaking Patch Tuesday, the return of Nitter, some exciting new announcements from Graphene, and more! [Privacy & Security NewsThe latest news in data privacy, cybersecurity, and consumer rights brought to you by Privacy Guides.![](https://www.privacyguides.org/content/images/icon/pg-yellow-2-c816578d-07b3-4274-9278-33f1403177a0.png)Privacy GuidesJonah Aragon![](https://www.privacyguides.org/content/images/thumbnail/cover-13-8167bb5e-8798-4e25-9dbd-27bc160d709b.png)](https://www.privacyguides.org/news/) ### Site Updates We had just one small commit this week to fix a broken link explaining on the README of our GitHub page explaining how we publish the site. [docs: Remove dead staging preview link (#3271) · privacyguides/privacyguides.org@4ad7b0dSigned-off-by: fria Signed-off-by: Mare Polaris <15004290+ph00lt0@users.noreply.github.com> Signed-off-by: Daniel Gray ![](https://www.privacyguides.org/content/images/icon/favicon-64be56e8-c43b-4a25-807a-439d659dcc83.svg)GitHubprivacyguides![](https://www.privacyguides.org/content/images/thumbnail/4ad7b0d6a1f5f656099fb492727b8e0f2acb11c0-f3eba5d9-a5a7-4ef7-8da4-9a940e20df0f)](https://github.com/privacyguides/privacyguides.org/commit/4ad7b0d6a1f5f656099fb492727b8e0f2acb11c0) --- ## Sources ### Apple Doesn’t Want You to Worry About the New Apple Watch’s Listening Features This week, Apple held their latest product launch event. One of the big stories is how the new Apple Watches will feature a slew of AI-enabled transcription and analysis capabilities that largely rely on listening to you at all times. Thinks like summarizing meetings, transcribing the last 15 seconds of speech, recognizing sounds, and more. Apple appears to have gone out of their way to make this as private and secure as possible, but it still illustrates a worrying trend where privacy invasions are becoming increasingly invisible and ambient. [Apple Doesn’t Want You to Worry About the New Apple Watch’s Listening FeaturesThe new Apple Watch includes several “intelligent” listening features that have privacy and security baked in. But the protections can’t change the facts of what the tools do.![](https://static.ghost.org/v5.0.0/images/link-icon.svg)WIREDLily Hay Newman![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-2293832136-a693fa1d-820b-43ea-86c9-abc1e2c0154e.jpg)](https://www.wired.com/story/apple-doesnt-want-you-to-worry-about-the-new-apple-watchs-listening-features/) ### LG TVs caught spying even when offline or on standby In an explosive story this week, YouTube channel Gamers Nexus published a two-hour (but highly watchable) video where they talked about how they deeply investigated modern LG TVs to see what data is collected. The ones enabled with audio were known to collect conversations from the room even when turned off, while basically all TVs collected data like what you're watching, other devices on the network, and more. If unplugged, they simply stored data and waited to upload until connected again. [LG TVs caught spying even when offline or on standbyGamers Nexus comes for LG again.![](https://www.privacyguides.org/content/images/icon/android-chrome-512x512-bdff989e-fac1-4dd6-9a79-9cd8b960abda.png)The VergeDominic Preston![](https://www.privacyguides.org/content/images/thumbnail/258078_LG_G5_OLED_TV_JHiggins_0007-c46090f6-f92f-4e62-a54c-4965f3ccfbd8.jpg)](https://www.theverge.com/tech/991190/lg-tv-spying-standby-recording-wi-fi-scanning-gamers-nexus) ### GrapheneOS Will Overhaul Default Apps and Implement a Secure Clipboard In an exciting announcement, Graphene OS has declared they will bring RCS compatibility to their native SMS app, thus giving users a little more privacy and security without the need for Google Messages - which is currently the only way for any Android users to take advantage of RCS. They have also announced plans to overhaul the stock apps - many of which they say are outdated - and institute a secure clipboard. [GrapheneOS Will Overhaul Default Apps and Implement a Secure ClipboardGrapheneOS announced that they are overhauling the default apps into “modern” apps, including RCS support in the messaging app, as well as implementing a secure clipboard feature to stop apps from accessing it without permission.![](https://www.privacyguides.org/content/images/icon/pg-yellow-2-77f6149e-2385-48f4-8f76-59707b24f1a7.png)Privacy GuidesFria Reyes![](https://www.privacyguides.org/content/images/thumbnail/photo-1724341039339-036842055cae-bfdae06b-d567-4af0-88b9-229d9a002d26)](https://www.privacyguides.org/news/2026/09/06/grapheneos-overhauled-default-apps-and-secure-clipboard/) --- ## Forum Updates [Android rolling out passkey transfers between password managersIn the past, transferring credentials between password managers involved “downloading them into an unencrypted text file, which left them unprotected on your device.” Meanwhile, passkeys did not originally offer a transfer method, thus requiring you to manually “recreate them across multiple sites and apps.” Since it will work with Android 8+ devices I guess it will need Google play services?![](https://www.privacyguides.org/content/images/icon/50d23e21c43962bb12c02820fa3f19ac61dac917_2_32x32-e05a9d3f-8661-4c8d-9692-47d4456b0f6d.png)Privacy Guides Communityuser1![](https://www.privacyguides.org/content/images/thumbnail/e66787e935263390ce7b51b2dc072dcb4e15169f_2_1024x535-9628c779-d780-4c25-bd27-f7be32fd4ee7.jpeg)](https://discuss.privacyguides.net/t/android-rolling-out-passkey-transfers-between-password-managers/40601 ) [Commodore Callback 8020 - CommodoreI actually put in a pre-order for this, mostly because I think it’s a cool concept. There seems to be a growing market for “dumb” (or at least “a lot less smart”) devices, and I think a lot of this is for privacy reasons.![](https://www.privacyguides.org/content/images/icon/50d23e21c43962bb12c02820fa3f19ac61dac917_2_32x32-10a17394-f15f-450e-b3fc-d2a19a467d0a.png)Privacy Guides CommunityCarey![](https://www.privacyguides.org/content/images/thumbnail/3f66fc7073e06dcb94fedb6baf2b00869f385ef7-cae81c49-5cd6-4383-93a2-77309f365d4b.jpeg)](https://discuss.privacyguides.net/t/commodore-callback-8020-commodore/40488) ### Data Breach Roundup (Sep 4 - 10, 2026) URL: https://www.privacyguides.org/news/2026/09/11/data-breach-roundup-sep-4-10-2026/ Last updated: 2026-09-11T17:46:25.000Z ## Trezor data breach impact now reaches 81,000 customers Cryptocurrency hardware wallet has suffered yet another data breach. This one was initially disclosed in August and said to impact 14,000 customers including full names, shipping addresses, email addresses, and phone numbers. Now Trezor has disclosed an additional 67,000 US customers because their shipping provider was not deleting customer data despite being required to by Trezor. [Trezor data breach impact now reaches 81,000 customersCryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers.![](https://www.privacyguides.org/content/images/icon/bleeping-f7de5235-66e1-4fb6-8b3f-49c7bf2aa0d4.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Trezor-ccc259f5-fccd-4364-b4d4-300a3f763472.jpg)](https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/) ## Trezor: 347,000 users targeted in phishing attacks after Brevo breach Trezor warned on Wednesday that threat actors had breached Brevo, its third-party email provider, and were emailing customers who opted in to receive newsletters. We now know that the attackers conducted phishing attacks against 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. According to customers targeted in this phishing campaign, they received fake "critical security alert" emails from help@trezor.io claiming that a "hardware microcontroller vulnerability" in Trezor cold storage wallets' STM32 microcontrollers could expose their seeds to brute-force cracking. [Trezor: 347,000 users targeted in phishing attacks after Brevo breachTrezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link.![](https://www.privacyguides.org/content/images/icon/bleeping-9656a694-2370-469e-8194-a986a9e1d062.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Trezor-640e0cf3-e4c5-455c-9871-471cfa77876a.jpg)](https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/) ## Mathspace discloses data breach affecting over 1 million people Mathspace is an online math learning platform used in thousands of schools across Australia, New Zealand, the US, and the UK. The compromised access took place between August 10 and August 27, and impacted students and staff from Australia and New Zealand (as well as parents and guardians). The article didn't specify what data was impacted. [Mathspace discloses data breach affecting over 1 million peopleOnline maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.![](https://www.privacyguides.org/content/images/icon/bleeping-c3b9924a-2b35-491e-b186-119ff155f88b.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/0_Mathspace-09202e3a-c539-4568-9e9e-ba35afd85192.jpg)](https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/) ## 220 million traveler records exposed in Vietnam-linked APIS leak An Advance Passenger Information System (APIS) database holding more than 220 million passenger and crew records was accessible online through a chain of security misconfigurations. The article says that APIS's are used worldwide to collect identity, passport, and flight information from airlines before passengers and crew arrive at or depart from a country. The exposed records span January 2017 to April 2026\. The exposed information included passengers' and crew members' names, dates of birth, sex, nationalities, passport or travel-document numbers, document expiration dates, and issuing countries. Associated travel data included flight numbers and dates, airlines, departure, destination and transit airports, seat assignments, baggage references, and scheduled, estimated, and actual flight times, information typically carried by APIS and related airline systems. [220 million traveler records exposed in Vietnam-linked APIS leakExclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026\. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials.![](https://www.privacyguides.org/content/images/icon/bleeping-a2ad2dce-60c4-493d-9a51-251391c8aff2.ico)BleepingComputerAx Sharma![](https://www.privacyguides.org/content/images/thumbnail/Airport-c86dca2d-67e1-47ba-b480-7b545759b0a2.jpg)](https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/) ## ShinyHunters hackers claim breach of Florida "DAVID" DMV database DAVID is the "Driver and Vehicle Information Database" platform operated by the Florida Highway Safety and Motor Vehicles (FLHSMV) agency, used by law enforcement and officials to look up information about a particular driver. As proof of the breach, the threat actors released a screenshot of Jeffrey Epstein's record in the DAVID system. This record includes the person's address, Social Security number, birth date, driver's license ID, issuance and expiration dates, and registered vehicles. The system also has tabs for additional information, including driver's license transactions, addresses, insurance, prior vehicles, and parking permits. They claim to have stolen 200,000 records. (I would also like to note that DAVID was one of the tools a Florida police officer recently used to [stalk](https://www.404media.co/footage-shows-cop-stalking-woman-he-met-on-a-tv-set-after-surveilling-her-with-a-license-plate-reader/) a woman after she turned him down for a date.) [ShinyHunters hackers claim breach of Florida “DAVID” DMV databaseThe ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as “DAVID” and stole over 200,000 records about drivers in the state.![](https://www.privacyguides.org/content/images/icon/bleeping-6767c0a9-a0d4-4baa-ab0f-bd2c4d427f43.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/florida-game-style-08a224dd-0212-4637-8fbb-8267e392868d.jpg)](https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/) ## Veradigm warns of patient data breach after ransomware gang claims attack Veradigm is a Chicago-based healthcare technology company that supplies medical practices with electronic health records, e-prescribing, patient-engagement, practice-management, and revenue-cycle software. The threat actor alleges to be holding 3.5 million patient records that include full names, home addresses, SSNs, email addresses, phone numbers, and personally identifiable information or guarantors. [Veradigm warns of patient data breach after ransomware gang claims attackHealthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data.![](https://www.privacyguides.org/content/images/icon/bleeping-f530ea9e-9f46-4c06-9ddd-4790b48a4e68.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/gentlemen-ee4cb7ca-1335-4514-8908-a1979794e685.jpg)](https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/) ## AdaptHealth confirms 4.1 million people exposed in July cyberattack AdaptHealth provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. The breach impacted full names, contact information, demographic information, health insurance information, and health information. [AdaptHealth confirms 4.1 million people exposed in July cyberattackHealthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group.![](https://www.privacyguides.org/content/images/icon/bleeping-a4a169fb-7424-4176-a47d-18030c96c2b0.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/healthcare-a4d3ed20-72f8-4953-815b-08084e75ad3b.jpg)](https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/) ## ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen IDScan has finally confirmed what we all knew. Stolen information includes people’s full names and driver’s license numbers, along with identity numbers from other government-issued documents, such as passports. As usual, the breach announcement page has a `noindex` tag. [ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen | TechCrunchThe ID checking company said the data breach included people’s full names and driver’s licenses and other government-issued identity documents.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-73117e6a-ad07-4e13-9a2c-e793a959665f.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-681253878-8cbe66a6-3f8c-455b-9e18-33c2c590b7c1.jpg)](https://techcrunch.com/2026/09/10/id-verification-giant-idscan-confirms-data-breach-with-more-than-150-million-drivers-licenses-stolen/) ### Microsoft Shatters Another Record, Patching 973 Vulnerabilities in September URL: https://www.privacyguides.org/news/2026/09/10/microsoft-shatters-another-record-patching-973-vulnerabilities-in-september/ Last updated: 2026-09-10T22:12:00.000Z Microsoft [patched](https://cybersecuritynews.com/microsoft-patch-tuesday-update-september-2026/) a record 973 vulnerabilities this September, beating their other [records](https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/) from earlier this year. Two of the patched vulnerabilities are zero-days being actively exploited in the wild. The majority of them were privilege escalation vulnerabilities, which allow an attacker to give themselves higher privileges on the system than they're supposed to have, and remote code execution (RCE) vulnerabilities, which allow an attacker to run their own code on your machine. The high number of issues fixed can likely at least partially be attributed to their [in-house AI system](https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/) for finding security exploits, codenamed MDASH. AI has become proficient at finding vulnerabilities in software, which has caused many developers to have to fix more vulnerabilities more quickly than ever before. Some exploits have been sitting dormant in code for over a decade in some cases; the Linux kernel has had to fix [multiple](https://www.privacyguides.org/news/2026/08/07/18-year-old-linux-kernel-bug-allows-full-system-takeover/) of these [bugs](https://www.privacyguides.org/news/2026/07/08/15-year-old-linux-kernel-vulnerability-allows-full-system-takeover/) and will likely have to fix many more. Defenders have jumped on AI as a tool for finding and fixing bugs before they're found by attackers. [Mozilla](https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/) has embraced using AI to find and fix as many issues as possible. They're optimistic that, despite the initial workload of fixing so many bugs, these tools will actually tip the balance in favor of defenders in the long run. The deadline before attackers using these tools overwhelm defenders might be approaching, though. [OpenAI](https://openai.com/collective-cyberdefense/) released a call for collective action on the imminent threat of AI vulnerabilities, calling on AI companies, organizations, and governments to coordinate cybersecurity efforts. The letter was signed by a lot of organizations, including big tech companies like Google and IBM to even smaller companies like 1Password. Supposedly, the cascade of issues will slow down once these frontier models find all the low-hanging fruit in the code. So far, though, they only seem to find more and more issues to fix. The whack-a-mole strategy of fixing individual vulnerabilities as they pop up is being strained. Likely a better long-term solution is to categorically remove certain types of vulnerabilities, such as using memory-safe languages to prevent memory safety issues. We can take some comfort in the fact that almost all of the 973 bugs were not known to be actively exploited, and now won't be as long you update your system. ### New "Siri Recap" Feature for Apple Watches Can Create Summaries of Your Conversations Throughout the Day, Apple Says URL: https://www.privacyguides.org/news/2026/09/10/new-siri-recap-feature-for-apple-watches-can-create-summaries-of-your-conversations-throughout-the-day-apple-says/ Last updated: 2026-09-10T03:34:24.000Z Apple today announced [Siri Recap](https://www.apple.com/privacy/docs/Audio%5FIntelligence%5FPrivacy%5FOverview%5FSep%5F2026.pdf), a new feature in their upcoming Apple Watches that will allow it to generate a summary of conversations you have throughout the day. The feature was announced amidst three other new audio features involving the microphone: Live Rewind, Music Recognition, and Sound Recognition, although those are less interesting in terms of privacy. Live Rewind lets you recall what happened in the last 15 seconds in a conversation, although this only works on a continuous 15-second buffer that's always being rewritten. Music Recognition is just Shazam but now it can happen in real time, with the only data processed being the audio signature of the song and not saved audio. It's a similar story with Sound Recognition: it listens continuously for a specific type of sound such as an alarm going off but no sound is ever recorded. They explain in a newly-published [whitepaper](https://www.apple.com/privacy/docs/Audio%5FIntelligence%5FPrivacy%5FOverview%5FSep%5F2026.pdf) that for all of these features, the raw audio is processed in the Secure Exclave of the Apple Watch: "a hardware-isolated compartment built into the silicon to process sensor data separately from the rest of the system." For iPhones 16 and later, the Secure Exclave in the phone can securely pair with the Secure Exclave in the watch so that the raw audio is never made available outside of the respective exclaves. The encryption keys are device-bound and rotate over time, so a lost device shouldn't be a security issue. Siri Recap, the most interesting of the new features, stores a high-level summary of conversations throughout your day. The raw audio never leaves the Secure Exclave, but a condensed transcript of it is generated on-device and then sent encrypted to Apple's servers running [Private Cloud Compute](https://security.apple.com/blog/private-cloud-compute/), the same technology that powers their cloud AI features. The claim is that Apple can't access data sent to PCC, but the way the technology works at some point the data must be decrypted in order to be processed. This makes it distinctly less secure than purely on-device processing. Data is included about context like whether the speech was from a song, whether you were at an event based on your calendar data, and even some location information like your city, state, and country. The summary is then sent back to your phone, encrypted, where it will be stored for 7 days unless you choose to save them. The feature is opt-in, so you don't have to use it, but the amount of data it stores could be concerning. Even in condensed form, 7 days of summaries of all of your conversations could reveal a lot if an attacker gets access to your phone via malware or some other means. ### Why Big Tech's Privacy Promises Are Lies URL: https://www.privacyguides.org/videos/2026/09/09/why-big-techs-privacy-promises-are-lies-2/ Last updated: 2026-09-09T15:00:49.000Z Melanie Ensign is the founder and CEO of Discernible and former communications lead for Facebook, Uber, AT&T, and DEF CON. She pulls back the curtain on how these large corporations operate, revealing why most internal privacy teams operate like "tax attorneys" rather than privacy advocates. If you want to learn more about Melanie's work or get in touch please see the following links: Discernible: [Discernible IncCommunication experts for cybersecurity and privacy teams.![](https://www.privacyguides.org/content/images/icon/Discernible-Icon_Profile-fdad2b76-dc58-49e4-a1d1-118d8a891a17.png)Discernible Inc![](https://www.privacyguides.org/content/images/thumbnail/Website-Headers-1-58671aca-cd1f-4e5c-87c5-35bcf991a340.png)](https://www.discernibleinc.com) Melanie Ensign: [Melanie Ensign - Discernible | LinkedInSpecialized in reputation management, organizational communications, incident response… · Experience: Discernible · Education: Boston University College of Communication · Location: Miami · 500+ connections on LinkedIn. View Melanie Ensign’s profile on LinkedIn, a professional community of 1 billion members.![](https://www.privacyguides.org/content/images/icon/al2o9zrvru7aqj8e1x2rzsrca-7db75e69-bbcf-4a5f-bb43-1b768ace6108)LinkedInMelanie Ensign![](https://www.privacyguides.org/content/images/thumbnail/1c5u578iilxfi4m4dvc4q810q-2dde03be-2d21-4ebf-8c8e-2d1845bfa70f)](https://www.linkedin.com/in/melanieensign) Weekly IR Comms Simulations: [Weekly Incident DrillsThe Discernible Experience Most security professionals build technical instincts through years of hands-on work. Communication instincts don’t develop the same way — unless you practice them intentionally. The Discernible Experience gives you weekly opportunities to practice the communication moments that separate technically strong practitioners from organizationally influential ones. Every![](https://www.privacyguides.org/content/images/icon/Discernible-Icon_Profile-21562f1d-3961-4b10-9541-1f8c542e1abc.png)Discernible IncDiscernible Staff![](https://www.privacyguides.org/content/images/thumbnail/Discernible-Experience-Logo--Website--d7d76da1-0e78-4c26-a0aa-067e19f794e5.png)](https://www.discernibleinc.com/experience/) ### Why Big Tech's Privacy Promises Are Lies URL: https://www.privacyguides.org/videos/2026/09/07/why-big-techs-privacy-promises-are-lies/ Last updated: 2026-09-07T23:15:51.000Z Melanie Ensign is the founder and CEO of Discernible and former communications lead for Facebook, Uber, AT&T, and DEF CON. She pulls back the curtain on how these large corporations operate, revealing why most internal privacy teams operate like "tax attorneys" rather than privacy advocates. _This post is for subscribers only._ ### Alternate X.com Frontend Nitter Announces it Will Continue Despite the Cease and Desist URL: https://www.privacyguides.org/news/2026/09/07/alternate-x-com-frontend-nitter-announces-it-will-be-continue-despite-the-cease-and-desist/ Last updated: 2026-09-07T21:38:12.000Z [Nitter](https://nitter.net), an alternative frontend for X.com, announced that they "will be back up and running shortly" after a cease and desist from X Corp. Nitter had [previously announced](https://www.privacyguides.org/news/2026/08/26/x-com-sends-privacy-frontend-nitter-a-cease-and-desist-permanently-shuts-it-down/) on August 2026 that it would be ceasing development and shutting down following the legal notice from X. Nitter has been the premier alternative frontend for X.com for years, making the sudden shutdown a shock for many of its users. Alternate frontends for websites allow you to access the content hosted by a site without some of the restrictions imposed by the official frontend. For example, you might want to watch YouTube videos without seeing ads or you might just not like the official user interface. X.com has been making its UI more hostile to users who simply want to view content without an account. In many cases, the site will constantly badger you to sign up or even straight up block you from viewing posts unless you sign in. This behavior is very inconsistent, making it more confusing than it needs to be to figure out what you're allowed to view without signing in. Signing in to X requires an email, which some people consider to be private information. It also means every time you're signed in, X can see what you're viewing and keep track of your viewing activity over the long term, and tie that information to your email which could be linked to your real identity. Nitter allows you to bypass these annoying roadblocks, to the apparent chagrin of X Corp. The official [Nitter GitHub](https://github.com/zedeus/nitter) is no longer archived, meaning new changes can be made to the codebase. The official [nitter.net](https://nitter.net) instance is still not up and running as it was for now, but the message on the front page has been updated: ![](https://www.privacyguides.org/content/images/2026/09/image.png) source: nitter.net Other instances that were taken down, like [xcancel.com](https://xcancel.com), appear to be back up and running just like they were after being taken down due to a cease and desist earlier. Nitter seems confident in their legal standing, but they list ways to donate on the front page of their site if you still want to help them out with any potential legal fees. ### GrapheneOS Will Overhaul Default Apps and Implement a Secure Clipboard URL: https://www.privacyguides.org/news/2026/09/06/grapheneos-overhauled-default-apps-and-secure-clipboard/ Last updated: 2026-09-06T20:33:19.000Z GrapheneOS announced that they are [overhauling](https://bsky.app/profile/grapheneos.org/post/3muun5c4fdc2o) the default apps into "modern" apps, including RCS support in the messaging app, as well as implementing a [secure clipboard](https://bsky.app/profile/grapheneos.org/post/3muupuvlfbs2v) feature to stop apps from accessing it without permission. [GrapheneOS (@grapheneos.org)We’re well into the process of converting the Messaging app included in GrapheneOS into a modern app. We’ll be making a new release later today with a completely overhauled user interface written in Android Compose. We’ve made a massive amount of other improvements and bug fixes beyond that too.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-ccdceb58-7fea-4d15-9189-227b6998e5f5.png)Bluesky SocialGrapheneOS![](https://www.privacyguides.org/content/images/thumbnail/bafkreickcnmrwdtb3mwqzz7v7s2xgmczwzrdwp3ucvadpeuorzbsgvunjm-be46e779-e9f2-4cae-9d32-6d6263dd7e2a)](https://bsky.app/profile/grapheneos.org/post/3muun5c4fdc2o) GrapheneOS is based on the [Android Open Source Project](https://source.android.com) (AOSP), an open source operating system that most Android device manufacturers use as a base upon which they add their own proprietary components to ship as the operating system in their devices. AOSP includes some basic apps such as the Gallery app that technically function, but have mostly been abandoned. Google themselves use their own proprietary apps for photos, messaging, etc on the operating system for their Pixel devices. Now, GrapheneOS says they're "overhauling or fully replacing the rest of the AOSP apps in the near future." One of the sticking points that they plan on addressing is RCS messaging support in their default messaging app. Previously, if users wanted to use RCS, they would have to install Google Messages and give it potentially sensitive permissions. Despite RCS not being an "open platform in practice," GrapheneOS says they plan to implement it along with end-to-end encryption support. RCS is a huge usability improvement over SMS, and E2EE messaging support would let you have secure, cross-platform messaging by default. They are also scaling up improvements to the base OS as well. Of particular note is their new secure clipboard that will prevent apps from being able to see other apps' clipboard contents without permission. They say the goal is to preserve usability as much as possibly and only target the "most problematic part" of the clipboard API. iOS has a feature that [prevents](https://developer.apple.com/documentation/uikit/uipasteboard) apps from reading your clipboard without permission under certain circumstances; it'll be interesting to see how the approaches compare. GrapheneOS says they have "many of these features planned," referring to similar OS-wide security features that give you more control over what data apps have like their Storage Scopes and Contact Scopes features. ### Why Did Google Disable this Security Feature? URL: https://www.privacyguides.org/livestreams/2026/09/04/why-did-google-disable-this-security-feature/ Last updated: 2026-09-11T20:54:25.000Z This Week in Privacy #69 _This post is for subscribers only._ ### Data Breach Roundup (Aug 28 - Sep 3, 2026) URL: https://www.privacyguides.org/news/2026/09/04/data-breach-roundup-aug-28-sep-3-2026/ Last updated: 2026-09-04T18:59:10.000Z ## Toy-making giant Hasbro disclose data breach affecting employees The company has not disclosed the number of people impacted, but said data affected potentially includes email, address, phone number, national ID number, or financial information. The breach also affected the Social Security numbers, financial account information, credit/debit card numbers, and driver's license information of 436 Hasbro employees in Massachusetts. The incident likely took place around March 28, as that's when Hasbro disclosed a cyberattack and temporarily took systems offline. [Toy-making giant Hasbro disclose data breach affecting employeesHasbro, one of the world’s largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees.![](https://www.privacyguides.org/content/images/icon/bleeping-f911388f-ab8c-427f-817e-f8574e8a1a3b.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Hasbro-407a50ad-a8cd-4eae-bc68-14bbc529950c.jpg)](https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/) ## McKesson discloses breach after ShinyHunters claims patient data theft McKesson is a US "healthcare and pharmaceutical distribution giant." This incident was discovered on August 25 with attackers claiming they stole 284 million patient data records. ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information. The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics using McKesson's services. Investigation is ongoing. [McKesson discloses breach after ShinyHunters claims patient data theftHealthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.![](https://www.privacyguides.org/content/images/icon/bleeping-a3a098ca-8e8b-4c4b-9b52-b3c25b103d43.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/mckesson-49a479d2-2faf-480e-8168-1b341ba0220e.jpg)](https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/) ## FulcrumSec claims Manchester Airports hack, theft of 86 GB of data Last week, the Manchester Airports Group disclosed that they had a data breach impacting customers at their Manchester, London Stansted, and East Midlands airports, but had little else to share. We now have a rough idea of the data taken, including consolidated profiles that combined customer identifiers with historical booking activity and marketing classifications, and nearly 200,000 records related to upcoming travel during the remainder of 2026\. These records allegedly contain dates, times and booking information linked to personally identifiable information. Beyond the email addresses, phone numbers, vehicle registrations and postcodes disclosed by MAG, sampled records contained purchase and booking references, airport and product selections, prices, discounts, booking status, parking dates and times, historical spending, IP addresses, approximate locations, device information and customer-engagement data. [FulcrumSec claims Manchester Airports hack, theft of 86 GB of dataFulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller’s record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed.![](https://www.privacyguides.org/content/images/icon/bleeping-985c83ca-4ad0-4584-9b80-8637d864e532.ico)BleepingComputerAx Sharma![](https://www.privacyguides.org/content/images/thumbnail/Airport_flight_schedule-e4a2b652-dae1-41d4-892d-b06b5dbadcca.jpg)](https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/) ## Berlin confirms data theft after Rhysida ransomware attack claims The threat actor claims to have exfiltrated 5.79 TB of data, comprising approximately 1.44 million files, from Berlin’s administrative network. According to the attacker, they exfiltrated: - Government, legal, financial, contractual, HR, infrastructure, health, and mapping records. - Thousands of names, email addresses, phone numbers, and 148 IBANs. - Plaintext credentials, database accounts, payment-system data, password vaults, and credentials belonging to senior officials. - Personnel files, payroll information, administrative-offense records, email archives, SQL database dumps, identity documents, and banking information.\\ - Documents related to disciplinary proceedings and other named cases. - Allegedly classified or sensitive government material, including Bundesrat committee records and information about handling classified documents. - Critical-infrastructure security assessments concerning Berlin’s water supply. - More than 3,200 documents marked as nondisclosure agreements. [Berlin confirms data theft after Rhysida ransomware attack claimsBerlin’s city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site.![](https://www.privacyguides.org/content/images/icon/bleeping-f81b43cc-b5b4-4c0c-a8ee-167aba67f2cd.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Berlin-b0006bc9-7055-46c5-a60c-7e362cd1702b.jpg)](https://www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/) ## Novocure data breach affects more than 1,400 cancer patients Novocure is a global oncology company knowing for inventing a non-invasive electromagnetic field therapy for cancer tumors. The attackers accessed over 1,400 U.S. patient records with ID numbers, but those records didn't contain patient names or other identifying data. However, for fewer than 50 other patients in the western U.S, the threat actors accessed identifying information and general contact information for healthcare providers. The data breach also exposed contact information for an undisclosed number of Novocure employees, including job titles and phone numbers. [Novocure data breach affects more than 1,400 cancer patientsHealthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.![](https://www.privacyguides.org/content/images/icon/bleeping-dddd3730-0d58-4dd2-9df7-8ba23995e912.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Novocure-headpic-43688d9e-20dc-409b-853d-27f5268c9827.jpg)](https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/) ## Aesto Health says data breach affects over 9.5 million patients Aesto provides software-as-a-service that healthcare organizations can use to migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices. This intrusion occurred in December 2025 and impacted full names, dates of birth, medical information, driver’s license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. The incident indirectly impacts 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women’s Health. [Aesto Health says data breach affects over 9.5 million patientsAesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals.![](https://www.privacyguides.org/content/images/icon/bleeping-94981b18-3271-4432-b807-30fa5ce42874.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/healthcare-9f869b18-cb4e-4223-8d14-44ddb1069b30.jpg)](https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/) ## FBI Probes Service Selling 153M+ Drivers Licenses This week, investigative independent journalist Brian Krebs wrote about a service called Nexus that claimed to have more than 153 million drivers licenses for people in the US and Canada, as well as more than 10 million ID cards, more than 3 million "travel documents and/or international IDs," and at least 579,000 medical cards. The source of the breach seems to lead back to IDScan.net, an age verification service. The story has since been picked up by several mainstream outlets. [FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security![](https://www.privacyguides.org/content/images/icon/favicon-435d4dae-ec56-4b34-ac15-27fc4bf79edc.ico)Krebs on SecuritySkip to content![](https://www.privacyguides.org/content/images/thumbnail/nexus-phegseth-ab12d52c-8bd7-4348-8933-8750e37d3300.png)](https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/) ## French hospital fined €500,000 after breach exposes data of 727,000 Hôpital privé de la Loire (HPL) is a general hospital in Saint-Étienne, part of the Ramsay Santé healthcare group, providing medical, surgical, maternity, cancer, intensive-care, and emergency services. HPL suffered a data breach in summer of 2025 affecting 524,000 patients and just over 200,00 "trusted third parties." CNIL's investigation found several shortcomings in the hospital's GDPR obligations such as lack of MFA or VPN requirements, inadequate access controls, lack of monitoring and alerting tools, and failure to notify the third parties of the breach. [French hospital fined €500,000 after breach exposes data of 727,000France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data.![](https://www.privacyguides.org/content/images/icon/bleeping-5cfa9128-5fcf-444a-8deb-cd2277507f46.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/flag-of-france-feb2bdf4-5ec9-4015-a717-ae651b09c445.jpg)](https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/) ### Signal Android Beta Has Merged Support for Numberless Accounts, Although It's Not Enabled Yet URL: https://www.privacyguides.org/news/2026/09/03/signal-android-beta-has-support-for-numberless-accounts/ Last updated: 2026-09-05T15:35:00.000Z Signal has merged [numberless accounts](https://community.signalusers.org/t/registration-without-a-phone-number/2222/206) into the code as a feature in the upcoming [Android beta 8.26](https://community.signalusers.org/t/beta-feedback-for-the-upcoming-android-8-26-release/76367), although you can't use it yet. Signal is one of the most commonly recommended messengers for privacy. Its [double-ratchet](https://signal.org/docs/specifications/doubleratchet/) encryption was revolutionary when it came out, and the Signal protocol has since been adopted by other encrypted messengers such as [WhatsApp](https://signal.org/blog/whatsapp-complete/). Signal is also commonly early to implement new improvements such as [Post-Quantum Encryption](https://signal.org/blog/pqxdh/) and [Automatic Key Verification](https://signal.org/blog/automatic-key-verification/). There's been a sticking point for years though that has annoyed privacy advocates and, in my personal experience, caused a roadblock in getting people to switch to Signal: it requires a phone number to sign up. Phone numbers are sensitive personal information for some people. so it's understandable that many people don't like to hand off their phone number to an app they've never heard of before. Many other messengers such as SimpleX Chat and Session don't require a phone number on signup. Signal's answer for why they do is for anti-spam purposes, as a phone number has a monetary cost associated with it and there are a limited number of possible phone numbers available at any given time. Signal CTO Ehren Kret had previously confirmed Signal was looking into account registration without a phone number in a Q and A at the FUTO Don't Be Evil Conference: > that is something we are looking a hopefully for later on this year adding a way to sign up without phone numbers. Uh the main uh downside at the moment and the reason we don't have that yet today is removing accounts who are are spamming people or otherwise engaging in abuse of the service is sort of our our primary way of protecting people from spam and other sort of issues like that that would affect the operational stability of the service. The proposed solution was to make numberless accounts incur a small fee, making it infeasibly expensive for spammers to create thousands of accounts over and over. Hints of numberless accounts were spotted on Signal's [GitHub](https://aboutsignal.com/news/signal-is-working-on-registration-without-a-phone-number/) previously in the form of several commits referencing numberless accounts. There's seemingly no mention of the payment feature, but maybe users of the Signal beta can test it out and see if there's new UI elements for it. I'm not sure how the feature would work in a beta, but it would be interesting to see. ### Google Messages Bug Sends Old Texts to Random People URL: https://www.privacyguides.org/news/2026/09/02/google-messages-bug-sends-old-texts-to-random-peopl/ Last updated: 2026-09-02T23:11:38.000Z A [bug](https://www.androidauthority.com/google-messages-old-texts-bug-3704732/) in Google Messages is causing some people's texts from months or years ago to be sent to random people instead. Multiple users on [Reddit](https://www.reddit.com/r/GoogleMessages/comments/1vn1pex/breaking%5Fdown%5Fcrying/?solution=26db8d9f9fd2e92026db8d9f9fd2e920&js%5Fchallenge=1&jsc%5Ftoken=7afd7253fec22262ff1c52b1703fe9ecc0645089d8a819a9cb15543f2c18a568&jsc%5Forig%5Fr=) have reported seeing their old messages from other chats being sent when they send any type of text, even pictures. Clearing the cache or uninstalling updates only caused all message threads to be combined with old messages, making chats a jumbled mess. Old messages can contain very sensitive information that you don't want in the hands of random people on your contacts list. One user [reported](https://www.reddit.com/r/GoogleMessages/comments/1v34n80/texts%5Fare%5Fbeing%5Freplaced%5Fby%5Fother%5Ftexts%5Ffrom/) having their confirmation of a vet appointment replaced with a text from a friend offering for all her aunties to rough someone up on the playground. Another [reported](https://www.reddit.com/r/GoogleMessages/comments/1uucty9/comment/p65evx5/) that it sent a message about sex to their mother. It doesn't seem to matter whether the messages are SMS or RCS either, all could potentially be sent off to unwanted recipients. The problems aren't limited to just Pixel phones, either. Users on both Pixels and Samsung phones mention being affected, but many phone manufacturers use Google Messages as the default messenger app. Some workarounds, such as factory reseting and restoring your messages, seem to have worked for some people. Some fixes only make the problem worse, however. Google has [acknowledged](https://www.reddit.com/r/GoogleMessages/comments/1vt5ywu/comment/p6s6sx8/) the problem and a fix is being worked on, they confirmed to [Android Authority](https://www.androidauthority.com/google-messages-sending-old-texts-fix-3705920/): > We’re currently rolling out a fix that will reach everyone over the coming weeks. Please ensure you stay up to date with the most recent version of Google Messages. They say Google has pointed to the issue being transferring messages to a new device as the trigger for the bug. Even when the fix is released, it may take weeks for it to reach everyone. The privacy implications of this bug are particularly concerning since Google's RCS implementation is end-to-end encrypted between Google Messages users, and even iOS users if their carrier supports RCS. People likely have highly sensitive data in those encrypted messages that they wouldn't want anyone other than the intended recipient to see. For now, the advice is to install the latest version of Google Messages from the Play Store and keep your device up-to-date. Google's fix should arrive shortly. In the meantime, you could try out an alternate E2EE messenger like [Signal](https://signal.org). ### Pixel 11 Has Hardware MTE Support, "May Still Be Usable" for GrapheneOS URL: https://www.privacyguides.org/news/2026/09/01/pixel-11-has-hardware-mte-support-may-still-be-usable-for-grapheneos/ Last updated: 2026-09-01T15:30:54.000Z After GrapheneOS [previously](https://www.privacyguides.org/news/2026/08/29/grapheneos-unable-to-complete-pixel-11-port-due-to-cut-security-feature/) hit a roadblock porting to the Pixel 11 due to a missing security feature, they found the hardware does have "at least bare minimum support for MTE." [GrapheneOS (@grapheneos.org)We have good news about the Pixel 11\. It still has at least bare minimum support for MTE at a hardware level. We think they removed most of the hardware acceleration from the CPU cache to save money. They ruined the performance so it ended up being fully disabled in firmware. It may still be usable.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-da568016-acb9-4861-84d8-e88799618af1.png)Bluesky SocialGrapheneOS![](https://www.privacyguides.org/content/images/thumbnail/bafkreickcnmrwdtb3mwqzz7v7s2xgmczwzrdwp3ucvadpeuorzbsgvunjm-ce7d651a-df7e-4a68-b037-a33f1c31d7a8)](https://bsky.app/profile/grapheneos.org/post/3mugn23cpx22l) GrapheneOS is a security-focused operating system based on Android Open Source Project (AOSP). Historically, it's only been available on Google Pixel phones since they are currently the only devices that meet the [minimum requirements](https://grapheneos.org/faq#future-devices) for security. One of these requirements is support for a feature called [Memory Tagging Extension](https://newsroom.arm.com/blog/memory-safety-arm-memory-tagging-extension) (MTE). MTE is a feature in ARM chips that can detect memory safety bugs in software: situations in which memory is accessed when it's not supposed to be. Memory safety bugs made up around 76% of vulnerabilities in Android at one point, according to [Google's data](https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html). Switching to memory-safe languages like Rust helped them significantly reduce that number. Not all parts of Android or all apps are written in memory-safe languages though, and for those MTE shines. When MTE detects a memory safety violation, it can crash the offending app to prevent an exploit and protect your phone. Google Pixels were the [first phones](https://projectzero.google/2023/11/first-handset-with-mte-on-market.html) to ship with MTE support, and continue to be the only Android devices that officially support it, according to [AOSP](https://developer.android.com/ndk/guides/arm-mte#hwsupport). Apple shipped their implementation of MTE in the form of [Memory Integrity Enforcement](https://security.apple.com/blog/memory-integrity-enforcement/) (MIE) on iPhone 17 and later devices. Since Pixels have a reputation for being the most secure Android devices, it was a bit of a shock that the Pixel 11 seemingly [removed](https://www.privacyguides.org/news/2026/08/29/grapheneos-unable-to-complete-pixel-11-port-due-to-cut-security-feature/) support for MTE, the feature it had been the first to bring to market. However, with the release of Android 17 QPR2 Beta 4, it appears support has been added back to the firmware. "MTE support is still completely disabled in the OS and arm64.nomte is unconditionally passed by the firmware to the kernel," according to GrapheneOS. They say it's still possible to enable, however. [GrapheneOS (@grapheneos.org)It’s possible to enable reserving the tag memory for MTE via \`fastboot oem mte on\`, boot a non-stock kernel ignoring arm64.nomte and use MTE. We’re in the process of determining whether it’s fully functional and the performance characteristics. It’s likely disabled due to performance being ruined.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-e7356947-7a47-47dc-8095-41c04bb0a597.png)Bluesky SocialGrapheneOS![](https://www.privacyguides.org/content/images/thumbnail/bafkreickcnmrwdtb3mwqzz7v7s2xgmczwzrdwp3ucvadpeuorzbsgvunjm-f4ef0943-5215-4818-b704-a3a189b16ba8)](https://bsky.app/profile/grapheneos.org/post/3mugnnmvofc26) Google has not responded to GrapheneOS's inquiries about MTE. ### Router Manufacturer Found With Multiple Backdoors in its Products URL: https://www.privacyguides.org/news/2026/08/31/router-manufacturer-found-with-multiple-backdoors-in-its-products/ Last updated: 2026-08-31T19:25:29.000Z Researchers at [VulnCheck](https://www.vulncheck.com/blog/zbt-darklantern-speakingstone) found multiple backdoors in routers from Chinese manufacturer Zbtlink allowing a remote server root access to the router with no authentication. Most people don't think much about their router: they buy one that fits their price range and lets them access their internet. Commonly, routers end up vulnerable to hackers due to not being updated, or not being replaced once the manufacturer stops supplying updates. Something most people probably don't consider, however, is the manufacturer itself being hostile. The researchers originally found a backdoor in routers from Zbtlink back on August 5\. The routers were observed continuously phoning home waiting for orders from a command and control (C2) server. This behavior is typical of a device that's been hacked, but these routers were shipped like this from the factory. ENDLESSDOORS, the name given to the backdoor by the researchers, utilizes a tool called rctl (remote control linux) that was uploaded to GitHub in [2015](https://github.com/ycsunjane/rctl) and never touched (the page seems to have been mysteriously taken down now). The tool implements the command and control client and server. It allows the server to send the client (your router) commands. The router will continuously reach a server and, with no authentication or key exchange, start accepting anything the server sends as a command, with no sandbox, always executed as root. The backdoor was found in every firmware offered on zbtlink's site. Zbtlink also sells its routers white-labeled under different brand names like "Wiflyer" so you might have to match the model name your router to check if it's affected. The researchers didn't notify the manufacturer since they believe it's not a vulnerability, but an intentional backdoor. There likely won't be a patch. In a later [blog post](https://www.vulncheck.com/blog/zbt-darklantern-speakingstone), VulnCheck found two more backdoors from the same OEM: SPEAKINGSTONE and DARKLANTERN. SPEAKINGSTONE phones home to ZBT's infrastructure and DARKLANTERN listens and executes arbitrary commands, much like ENDLESSDOORS. The researchers scanned the internet for DARKLANTERN-affected devices and found 16 devices affected. They say likely the deployment was much larger but they caught it on the tail-end of its lifespan. ![](https://www.privacyguides.org/content/images/2026/08/image-4.png) Source: VulnCheck SPEAKINGSTONE had a hardcoded backup C2 domain that it sent data to if there was no primary C2 server was configured. The researchers registered this backup domain themselves and waited for devices to contact it. As of August 21, they had 392 unique devices phoning home, with one phoning home for almost two years straight. ZBT actually [responded](https://www.reuters.com/world/asia-pacific/chinas-zbtlink-suspends-sales-routers-found-contain-backdoor-2026-08-06/) to the backdoor claims, stating "it is intended to assist customers with device troubleshooting and configuration only upon their explicit request and authorization," a hilarious statement considering there is zero authentication involved and the routers were continuously reaching out. ### GrapheneOS Unable to Complete Pixel 11 Port Due to Cut Security Feature URL: https://www.privacyguides.org/news/2026/08/29/grapheneos-unable-to-complete-pixel-11-port-due-to-cut-security-feature/ Last updated: 2026-08-29T21:42:46.000Z [GrapheneOS](https://x.com/GrapheneOS/status/2093731615243411862) has completed a partial port to the new Pixel 11 devices, but they say they're unable to complete it due to Google dropping ARM Memory Tagging Extension (MTE) support. > We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature… > > — GrapheneOS (@GrapheneOS) [August 29, 2026](https://x.com/GrapheneOS/status/2093731615243411862?ref%5Fsrc=twsrc%5Etfw) [MTE](https://developer.arm.com/community/arm-community-blogs/b/architectures-and-processors-blog/posts/enhancing-memory-safety) is a hardware feature in ARM chips that can detect and prevent memory safety violations. It works by assigning a random tag to each location in memory. If memory is accessed but the tags don't match, MTE will detect it as a memory safety violation. Depending on how it's configured, it can crash the program right then and there to stop an exploit early in its tracks. This is a particularly widespread class of vulnerabilities, making up around [76% of all vulnerabilities](https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html) in Android at one point according to Google's data. Eliminating memory safety vulnerabilities would mean categorically removing the largest class of vulnerabilities. Google were the [first](https://projectzero.google/2023/11/first-handset-with-mte-on-market.html) to ship MTE support in their Pixel phones with the Pixel 8 series of devices. According to [Android's documentation](https://developer.android.com/ndk/guides/arm-mte), Pixels are still the only Android phones shipping support for MTE even years later. Apple shipped their own implementation of MTE, calling it [Memory Integrity Enforcement](https://security.apple.com/blog/memory-integrity-enforcement/), on the iPhone 17 series and Macs with the M5 chip and up. GrapheneOS considers it such an essential security feature that it's part of their [requirements](https://grapheneos.org/faq#future-devices) for a device to support GrapheneOS at all. It's a shame, then, that Google has seemingly dropped the feature they were the first to bring to market. GrapheneOS says they haven't decided what to do about the situation quite yet, but they might have to skip supporting the Pixel 11 series entirely. GrapheneOS partnered with [Motorola](https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/) to create devices that meet the minimum requirements for GrapheneOS support, however they're not available yet. For now, they're recommending users stick with Pixel 8, 9, and 10 series phones. The Pixel 11's do ship with security improvements such as the new [Titan M3](https://www.privacyguides.org/news/2026/08/13/google-announced-the-pixel-11-with-their-new-titan-m3-quantum-safe-secure-boot/) security chip that supports quantum-safe secure boot, making it all the more baffling that they would cut such an important security feature as MTE. ### Could This Be The End of Privacy Frontends? URL: https://www.privacyguides.org/livestreams/2026/08/28/could-this-be-the-end-of-privacy-frontends/ Last updated: 2026-09-08T22:23:28.000Z This Week in Privacy #68 _This post is for subscribers only._ ### Data Breach Roundup (August 21 - 27, 2026) URL: https://www.privacyguides.org/news/2026/08/28/data-breach-roundup-august-21-27-2026/ Last updated: 2026-08-28T19:14:11.000Z ## SickKids data breach exposes employee and job applicant info The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a "cybersecurity incident." The hospital says the breach stemmed from a flaw in third-party software. They have not disclosed what data was involved or how many people were impacted. [SickKids data breach exposes employee and job applicant infoToronto’s Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264)![](https://www.privacyguides.org/content/images/icon/bleeping-15b613c8-1754-4124-91dc-16eb52ed1328.ico)BleepingComputerAx Sharma![](https://www.privacyguides.org/content/images/thumbnail/sickkids-c055eb9a-7bb4-46e7-b139-e4d73d64baa4.jpg)](https://www.bleepingcomputer.com/news/security/sickkids-data-breach-exposes-employee-and-job-applicant-info/) ## Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants Apollo is one of the largest private equity firms in the world. This was the result of a social engineering attack and access was gained between July 6 and July 10\. Attackers took names, birth dates, contact information (including home addresses), and Social Security numbers. It's unclear how many people were impacted or if they were Apollo employees or an Apollo subsidiary. [Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants | TechCrunchThe private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-637f69c0-56f8-4dbe-b954-d84ea22d273a.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/apollo-1825445522-e1787320209622-ff2885bc-8bc7-4a56-87f5-8b1c6a23431a.jpg)](https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/) ## Hospital operator Nutex Health says data stolen in cyberattack Nutex Health is a for-profit healthcare company that operates 28 facilities across 12 states. Nutex has yet to determine the type of data that may have been compromised and if the impact includes patients, employees, or business partners. [Hospital operator Nutex Health says data stolen in cyberattackHealthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers.![](https://www.privacyguides.org/content/images/icon/bleeping-8b4e6600-1df9-4b5f-aecb-a8c3e3070a05.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/nutex-477602a1-fc13-4c32-86e8-bac139f1551f.jpg)](https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/) ## LACMA data breach last year exposed social security and medical data This breach occurred in July 2025 and exposed both customer and employee data. After concluding their investigation, the Los Angeles County Museum of Art has determined that the following information may have been accessed: full name, date of birth, Social Security number, driver's license or government-issued ID number, partial financial account numbers, partial payment card information, health insurance information, and medical information such as provider name, medical treatment, diagnosis, treatment dates, or treatment locations. The article did not specify how many people were impacted. [LACMA data breach last year exposed social security and medical dataThe Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information.![](https://www.privacyguides.org/content/images/icon/bleeping-55b439e7-d368-4e68-a704-e57a30a88d65.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/lacma-211e2ea4-53b6-4bad-90f3-5b6243fde107.jpg)](https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-exposed-social-security-and-medical-data/) ## Carhartt data breach exposes information of 12.9 million accounts Carhartt is an American apparel company best known for making clothes that hold up in heavy-duty, blue collar work environments. ShinyHunters claims to have breached the company on August 13 and stolen more than 50GB of data on customers, employees, and the company itself. This includes email addresses, names, phone numbers, and physical addresses. [Carhartt data breach exposes information of 12.9 million accountsThe ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.![](https://www.privacyguides.org/content/images/icon/bleeping-d2d34781-3d58-44b4-b2cb-7f5894708e9c.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Carhartt-a15f73af-d789-48d3-a821-f82785247846.jpg)](https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes-information-of-129-million-accounts/) ## Manchester Airports Group says hackers stole travelers' data The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. The intruder did not access customer payment details, and the attack had no impact on airport operations, the company said. the exfiltrated data also "relates to car park, lounge and Fast Track bookings." The list of compromised details includes customers' email addresses, phone numbers, vehicle registration numbers, and postcodes. [Manchester Airports Group says hackers stole travelers’ dataThe Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports.![](https://www.privacyguides.org/content/images/icon/bleeping-98b69fc8-9ffc-4ae1-94f3-09330f214fd0.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/airport-2936ade2-f01d-4756-8c2c-15f8a74209b5.jpg)](https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/) ### Windows is Testing New Privacy Protections For Apps URL: https://www.privacyguides.org/news/2026/08/28/windows-is-testing-new-privacy-protections-for-apps/ Last updated: 2026-08-28T01:44:59.000Z Windows is making new app-level [permissions](https://learn.microsoft.com/en-us/windows-insider/release-notes/experimental/preview-build-26340-9233#manage-camera-microphone-and-location-access-for-desktop-apps) such as location, camera, and microphone available to Windows Insiders users. > With this update, you can review and control access on an app-by-app basis, giving you greater visibility into which apps are requesting access to sensitive resources and more control over your privacy choices. Our goal is to make privacy permissions easier to understand and manage across the wide range of desktop apps people use every day. Now with this new upcoming feature, you can individually grant or revoke access to each app. This brings Windows more in line with other operating systems like iOS or Android that allow you to give or revoke permissions to apps individually. ![](https://www.privacyguides.org/content/images/2026/08/image-3.png) It's important to note that Windows makes a distinction between "traditional" desktop apps: this feature already exists for some apps on Windows. Windows has had a myriad of different app formats, several with some attempt at providing a similar type of permission feature. [Universal Windows Platform](https://learn.microsoft.com/en-us/windows/uwp/get-started/universal-application-platform-guide) apps were an attempt at modernizing Windows software. They similarly required user permission to access things such as camera, microphone, and location. However, UWP apps are no longer being actively developed, although they will still work on Windows 10 and Windows 11. There is also [MSIX](https://learn.microsoft.com/en-us/windows/msix/overview): > MSIX is the modern Windows app packaging format. It gives any Windows app a reliable, clean install and uninstall, automatic updates, and access to Windows platform features that require a package identity. MSIX apps run in a [container](https://learn.microsoft.com/en-us/windows/msix/msix-containerization-overview) where they are isolated from the rest of the system and must be granted access to specific system resources. Windows also offers [Win32 app isolation,](https://learn.microsoft.com/en-us/windows/win32/secauthz/app-isolation-overview) although this is a feature that's been stuck in preview for a long time, with the latest updates being all the way back in [2024](https://learn.microsoft.com/en-us/windows/win32/secauthz/app-isolation-release-notes). These are what Microsoft considers "[traditional](https://learn.microsoft.com/en-us/cpp/windows/walkthrough-creating-windows-desktop-applications-cpp?view=msvc-170)" desktop apps, with extensive access to your system. Win32 app isolation would put these apps in a "sandboxed environment" to provide additional security. It's not clear how all of these app formats intersect with this new permission system or what the future of Win32 app isolation is in light of the new update. Microsoft says existing app permissions will be preserved and apps that you previously granted access to a resource will continue to have access to it and apps you denied will continue to be denied. ### WhatsApp Offers Improved Security Features URL: https://www.privacyguides.org/news/2026/08/27/whatsapp-offers-improved-security-features/ Last updated: 2026-08-27T00:57:18.000Z WhatsApp is debuting several new security features to help end users better secure their accounts, including additional passkeys, stronger password options, and "call context," according to [Bleeping Computer](https://www.bleepingcomputer.com/news/security/whatsapp-adds-stronger-two-step-verification-multiple-passkeys/). WhatsApp already supports passkeys, but will now allow users to create separate passkeys for each platform. They are also allowing users to create alphanumeric passwords instead of six-digit PINs for two-factor authentication. Additionally, for Android users, calls from non-contacts now display additional information about the caller, such as what country the caller is from and if they have any groups in common. In the article's screenshot, for example, the number states that the caller and the recipient have "2 groups in common, including Fall Soccer Parents." WhatsApp is not one of our [recommended messengers](https://www.privacyguides.org/en/real-time-communication/), however in many parts of the world it has become ubiquitous and a defacto standard, forcing many people to use it at least sometimes. With such a large userbase and many people relying on it for important communications, it's good to see Meta adding new ways for users to protect themselves. ### 2026 Password Manager Tier List: Does Yours Stack Up? URL: https://www.privacyguides.org/videos/2026/08/26/2026-password-manager-tier-list-does-yours-stack-up/ Last updated: 2026-08-26T22:00:23.000Z We compared the top password managers (and the ones not quite there yet) to find out how they stack up. Let us know where your favorite choice fell, or if we missed anything in the comments! ### X.com Sends Privacy Frontend Nitter a Cease and Desist, Permanently Shuts It Down URL: https://www.privacyguides.org/news/2026/08/26/x-com-sends-privacy-frontend-nitter-a-cease-and-desist-permanently-shuts-it-down/ Last updated: 2026-08-26T16:57:32.000Z The popular privacy frontend [Nitter](https://nitter.net) has received a cease and desist letter from X Corp demanding a permanent takedown of the project's repository and all instances. ![](https://www.privacyguides.org/content/images/2026/08/image-2.png) X.com is fairly data-hungry even as social media sites go, and it requires an account to even view many posts, although it's inconsistent about whether it blocks you from viewing. Nitter acted as a frontend for X: it displays content from X but with its own UI that allows users to see posts without the obnoxious sign in that blocks you from being able to simply view content. Logging in to a website allows the website to track your activity between sessions, since you re-identify yourself necessarily by logging in. Accounts also typically require potentially sensitive personal information, for example X requires you to provide either a phone number or an email to sign up. These can potentially be used to link your other accounts together or even link your account to your real identity. Not to mention every extra account you have means more spam in your inbox that no one wants. It also enabled you to view posts without JavaScript enabled, which is a big way advertisers track you around and fingerprint your browser. JavaScript is also a huge attack surface and is responsible for a significant portion of vulnerabilities in web browsers. The main instance, [nitter.net](https://nitter.net), has now been taken offline and replaced with the message above explaining the situation. Other popular Nitter instances, such as [xcancel.com](https://xcancel.com), appear to have also received similar cease and desist letters and consequently taken their service down as well. The [GitHub page](https://github.com/zedeus/nitter) for the Nitter project has been archived, meaning the source code is still available but there will be no more updates or support. The donation methods are still up if you want to support the developer through a difficult time. > 98 SOL in fees so far, the support is honestly overwhelming. > > Nitter has been my main project since 2019, with millions of users. It kickstarted the large wave of alternative front-end projects, and topped out at 114 public instances. > > — Zed (@zedeus\_) [August 26, 2026](https://x.com/zedeus%5F/status/2092601902769078631?ref%5Fsrc=twsrc%5Etfw) This is not the first time something like this has happened. In the past, a popular YouTube video downloader, [youtube-dl](https://github.com/yt-dlp/yt-dlp), was hit with a DMCA takedown and deleted off GitHub. GitHub eventually [reinstated](https://github.blog/news-insights/policy-news-and-insights/standing-up-for-developers-youtube-dl-is-back/) the project and even made a blog post about it. The nature of open source software means that likely someone will just fork the project and maintain their own version. There are still a few Nitter instances up for now such as [nitter.app](https://nitter.app). ### Android Car Head Units Are Getting Hacked Through Their Built-In Updates URL: https://www.privacyguides.org/news/2026/08/25/android-car-head-units-are-getting-hacked-through-their-built-in-updates/ Last updated: 2026-08-25T00:45:29.000Z Researchers at [Securelist](https://securelist.com/android-head-unit-malware/121106/) discovered a new type of Android malware that infects car head units without any user interaction using the built-in updater. The malware doesn't need to trick you to install it, it can install itself without you having to do anything. Head units deal with the multimedia functions of a car as well as having control over some functions of the car itself. According to the researchers, this is the first documented case of malware specifically targeting automotive head units. While most malware that's designed to run on Android can also run on Android head units, typically they aren't specifically targeted since most data that an attacker would want is on the users' phone. For example, a malicious banking app wouldn't work on a head unit since mobile banking is done on smartphones. These head units can still be juicy targets though. Cars nowadays typically contain SIM cards that allow them to connect to the internet and receive updates, power their navigation, and use other online features. The idea of hackers having control over your car is scary, even if it's not full control. However, the trojan here was trying to add cars to a malicious botnet, specifically the BADBOX botnet. BADBOX has been found in cheap and insecure smart devices such as TVs and low-cost Android tablets. It generates fake ad revenue by launching hidden ads and clicking on them. It also routes traffic through your devices without your permission, which could very well be linked to criminal activity. The manufacturer of the head units, DoFun, says they've fixed the security issues. Security inside cars is almost non-existent and the attack surface is massive. Modern cars contain over [300 million](https://www.synopsys.com/blogs/chip-design/600-million-lines-code-cars-2027.html) lines of code from [over 100](https://www.aptiv.com/en/insights/article/what-is-an-electronic-control-unit) electronic control units from different manufacturers, all with their own dedicated chips and software and firmware stacks. It's predicted that they will reach [600 million](https://www.synopsys.com/blogs/chip-design/600-million-lines-code-cars-2027.html) lines of code by 2027. Car manufacturers continue to race to add [self-driving](https://www.nytimes.com/2026/08/10/technology/waymo-expansion-edge-cases.html) features, [agentic AI](https://www.here.com/learn/blog/agentic-ai-in-cars), and now [cameras pointed at the driver](https://cybernews.com/security/eu-car-camera-monitoring/) at all times. All of these represent massive attack surface that needs to be addressed, especially now that cars are actively being targeted by malware in a way we've never seen before. There is a push for cars to have more [security for their ECUs](https://www.electraytech.com/secure-boot-secure-flash-ecu-firmware-protection/), such as implementing secure boot, adding post-quantum cryptography, and more authentication between ECUs. ### Plain English Words Used to Hide Windows Malware URL: https://www.privacyguides.org/news/2026/08/21/plain-english-words-used-to-hide-windows-malware/ Last updated: 2026-08-21T23:34:43.000Z In a currently active malware campaign, hackers are now hiding Windows malware inside lists of plain English words. Discovered in the wild by [Gen Threat Labs](https://www.gendigital.com/blog/insights/research/wordlistloader-delivering-amatera-via-clearfake-campaigns), the technique has been dubbed WordlistLoader. The sophisticate technique is being used as part of Amatera Stealer, and of the most prevalent infostealers, according to the researchers. It's distributed using the extremely effective fake CAPTCHA social engineering technique, where a website is hijacked to show a fake CAPTCHA that requests a user to copy and paste and then run a command in their terminal or command line. Most people aren't familiar with the terminal and will instinctively do as instructed, since that's what CAPTCHAs have trained them to do. macOS has [introduced](https://www.privacyguides.org/news/2026/04/02/macos-26-4-brings-new-terminal-security-feature-to-stop-malicious-commands/) a prompt to warn about such an attack, but ultimately it's impossible to fully prevent unless the terminal is completely disabled. Windows users are instructed to paste the command into the Windows Run dialog box, a favorite of scammers the world over. From there, the innocuous-seeming word list is downloaded containing the malware payload and run. The point of storing the malware inside a wordlist like that is to obfuscate it from researchers and antivirus software. They will just see a harmless list of text instead of a deadly virus. Previously, it was also discovered that hackers have been hiding malware inside [PNG](https://cybersecuritynews.com/phantom-stealer-inside-png/) and [SVG](https://cybersecuritynews.com/dcrat-campaign/) images, and now even [emojis](https://cybersecuritynews.com/hackers-hide-agent-tesla/) in order to obfuscate their payload. At this point, it seems like anything containing data could be hiding malware. Malware obfuscation techniques continue to get more and more advanced, but the method of infection is still tried-and-true social engineering. It's important to remember to never copy and paste commands into your command line, terminal, or Windows Run dialog unless you know exactly what they do. If you have a friend or relative that might be at risk of falling for one of these social engineering attacks, it might be beneficial to [disable](https://www.thewindowsclub.com/enable-or-disable-run-command-winr-box-in-windows-10) these features outright, since most people don't really use them anyway. Beyond that, always keep your OS updated. Never assume any file is inherently safe: [media files](https://cyberpress.org/cybercriminals-exploiting-media-files/) and [text](https://developer.chrome.com/blog/memory-safety-fonts) have long been known to contain potential vulnerabilities. ### Data Breach Roundup (August 14 - 20, 2026) URL: https://www.privacyguides.org/news/2026/08/21/data-breach-roundup-august-14-20-2026/ Last updated: 2026-08-21T22:15:56.000Z ## RingCentral data breach exposed info of 1.6 million accounts RingCentral is a cloud-based collaboration and communication platform used by businesses for services such as calling, messaging, and voicemail. The company discovered the incident on July 28, and ShinyHunters claimed to have taken over 280GB (compressed) of data. Have I Been Pwned confirmed the leak, which included names, email addresses, phone numbers, and physical addresses. [RingCentral data breach exposed info of 1.6 million accountsThe ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.![](https://www.privacyguides.org/content/images/icon/bleeping-b49973a7-f63d-4cc2-99b6-6acb12695636.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/RingCentral-headpic-8c7a5ced-b041-4dd1-be7d-9868d786f2c2.jpg)](https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/) ## SafePal data breach impacts 39,798 customers, stolen info for sale SafePal is a cryptocurrency hardware wallet provider. This breach impacts orders placed between March 2, 2025 and April 11, 2026 and exposed names, email addresses, shipping addresses, phone numbers, and purchase information. The company says the breach did not expose customers' wallet seed phrases, private keys, passwords, bank account information, payment card numbers, government-issued identification numbers, or other credentials. [SafePal data breach impacts 39,798 customers, stolen info for saleCryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.![](https://www.privacyguides.org/content/images/icon/bleeping-2ad56f24-17d9-4b77-b897-782708ee9999.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/safepal-header-6630e316-53ec-4e27-ab27-c66923cada28.jpg)](https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/) ## Pokémon Center data breach exposes customer info, cancels some orders Pokémon Center appears to be the official site for ordering various Pokémon merchandise. Customers in the UK and Germany were impacted after a third-party data breach from CEVA Logistics (which we covered in a previous newsletter). Impacted data includes customers' full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders. In some cases, orders were cancelled. Number of impacted customers was not disclosed. [Pokémon Center data breach exposes customer info, cancels some ordersPokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.![](https://www.privacyguides.org/content/images/icon/bleeping-0be4b8af-ee11-4db6-81a2-f73986d047ce.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/pokemon-center-3eec9a87-6d05-45e1-8711-e6e9bc0a666e.jpg)](https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/) ## Hacker claims 3.6 million Azure account records stolen from major companies A threat actor going by "TheHatman" is offering to sell the Azure infrastructure data from multiple Fortune 500 companies including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. They claim to have 3.64 million data records, including employee records. In the case of McDonald's for example, data includes names, employee IDs, email addresses, job titles, phone numbers, postal addresses, service accounts, and other tenant account records. [Hacker claims 3.6 million Azure account records stolen from major companiesA threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.![](https://www.privacyguides.org/content/images/icon/bleeping-6ab9b631-9e58-4ca3-90ab-c62ea645b1ae.ico)BleepingComputerIonut Ilascu![](https://www.privacyguides.org/content/images/thumbnail/DataLeak-625bf493-ffb8-44f6-954e-853e6df087cc.jpg)](https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/) ## Reverse-Lookup Service Exposed Millions of Photos of People’s Faces ClarityCheck is a people-search tool that allows users to do reverse image searches of people's faces. According to security researcher Jeremiah Fowler, ClarityCheck left an exposed database of roughly 450GB of images (including children) in a publicly-accessible Amazon S3 bucket. A second misconfigured database included email addresses and phone numbers. It is secured now, but Fowler claims it was exposed for months and it's unknown if any malicious actors may have accessed it. [Reverse-Lookup Service Exposed Millions of Photos of People’s FacesThe people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.![](https://www.privacyguides.org/content/images/icon/favicon-76fc0f2e-890a-4d42-8382-24a621471913.ico)WIREDLily Hay Newman and Matt Burgess![](https://www.privacyguides.org/content/images/thumbnail/Security_Data-20Broker-20Leak-20Exposes-208-20Million-20Photos-20of-20People-E2-80-99s-20Faces_v1-b62aad98-4b29-484b-84c2-17e7f47b18d8.jpg)](https://www.wired.com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/) ## Sakura Internet hack exposes data of up to 1.36 million accounts Sakura is a cloud & data center provider. This breach impacts their sales management system, which includes customer contract and membership information. Details have been scant. We will update as we hear more. [Sakura Internet hack exposes data of up to 1.36 million accountsJapanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored.![](https://www.privacyguides.org/content/images/icon/bleeping-58cc318b-8471-4356-af24-8fab1da48740.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/sakura-e5dc3a2a-d0db-4f0a-9a7a-68625fa60a0c.jpg)](https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/) ## French tax authority data breach affects 678,000 individuals An update to an older breach from August of last year. Previously we didn't know the number of people impacted, but we now know that a total of 678,000 individuals and professionals were impacted, including tax data such as reference tax income, family quotient, and withholding tax rate, and, for businesses, data such as their company name and SIREN number. [French tax authority data breach affects 678,000 individualsThe French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.![](https://www.privacyguides.org/content/images/icon/bleeping-5b1b523c-39da-4aec-a8f6-18358712e66b.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/flag-of-france-a09b4bce-c4cb-4bcd-a682-b164838b3430.jpg)](https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/) ## CareCloud confirms 3.7M patients had their medical records stolen in data breach Another update to a previous data breach. This breach was previously disclosed in March without any details. We now know that it's the fifth-largest healthcare data breach in 2026 so far. [CareCloud confirms 3.7M patients had their medical records stolen in data breach | TechCrunchThe cyberattack at CareCloud resulted in one of the largest reported data breaches in the U.S. healthcare industry this year.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-e4caa355-da26-4626-a42f-45309967b7ce.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/hacking-surveillance1-21890a68-7920-470c-a4fd-c5a75d3db0e3.png)](https://techcrunch.com/2026/08/19/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach/) ### Microsoft Copilot Continues To Be A Nightmare URL: https://www.privacyguides.org/livestreams/2026/08/21/microsoft-copilot-continues-to-be-a-nightmare/ Last updated: 2026-09-08T22:23:16.000Z This Week in Privacy #67 _This post is for subscribers only._ ### Windows Copilot Hacks Itself to Steal Your Data in a Single Click URL: https://www.privacyguides.org/news/2026/08/20/windows-copilot-hacks-itself-to-steal-your-data-in-a-single-click/ Last updated: 2026-08-20T02:45:23.000Z CoSnitch is a one-click vulnerability discovered by researchers at [Varonis Threat Labs](https://www.varonis.com/blog/cosnitch) and co-discovered by Copilot itself, that allows an attacker to exfiltrate sensitive data using Copilot's access to your computer. The researchers didn't need to do any reverse engineering to find the flaws: Copilot exposed vulnerabilities in itself all-too-readily. They dubbed this style of attack "meta-hacking," a type of social engineering attack against an AI where you trick it into revealing details about how it works and potentially unknown vulnerabilities. By simply asking Copilot how to execute a prompt without user interaction, it replied with an explanation as to why that won't work. By continually revising the same question and probing about different things like URL structure, what happens when a page is loaded with input already in the field, they got Copilot to reveal more and more about its own inner workings and eventually surfaced an undocumented URL parameter and an explanation of all protections in place to disable it. > We built the URL exactly as described. With no click or confirmation from the user, the prompt was successfully executed automatically Hilariously, Copilot was extremely confident the whole time that the flaw couldn't be exploited. The URL format goes as follows: `https://copilot.microsoft.com/?q=&autorun=1*` with the `?q=` filling in the prompt on page load and the `&autorun=1` parameter automatically acting as an "enter" keypress to submit the prompt without user interaction. The malicious prompt will then execute with full access to any of the victim's connected apps. It will continue executing to completion even if the tab is closed. Copilot can then be directed to exfiltrate data such as emails if they've given Copilot access previously. Not only did they find Copilot was vulnerable to direct prompt injection, but its page summarization feature can be hijacked by a malicious page to inject prompts into its permanent memory that tailors how it acts in all future sessions. So for example, it could be instructed to always exfiltrate its output to the attackers or change its output. There's no way to tell this happened via any network connection, file, log or anything that a piece of security software might flag. This issue is so permanent that it even survives changing passwords, rotating sessions, and re-enrolling the device. The issue was originally reported to Microsoft in December 2025 and they have now thankfully shipped a fix in August 2026, so make sure to update your Windows machines. ### Android Will Allow You to Lock Any App Behind Your Fingerprint or PIN URL: https://www.privacyguides.org/news/2026/08/18/android-will-allow-you-to-lock-any-app-behind-your-fingerprint-or-pin/ Last updated: 2026-08-18T16:37:42.000Z First spotted by [9to5Google](https://9to5google.com/2026/08/14/android-17-qpr2-app-lock/), Android 17 QPR2 Beta 3 adds a native App Lock feature allowing you to lock any app you want behind your biometrics or phone PIN. Apps have long been able to opt-in to locking themselves with your biometrics or your PIN, but this was up to app developers to implement. Some manufacturers such as Samsung implemented this feature in their own proprietary operating systems, but now the feature will be a default part of Android. All you have to do to lock an app is long-press it and the context menu will pop up showing you the option to lock the app. The app lock feature is currently only available on Pixel devices for now but likely it will be expanded to more devices when the full QPR2 update launches. iOS also [shipped](https://www.androidauthority.com/app-lock-ios-18-3450155/) a similar feature in iOS 18 to great fanfare. It's important to note that you shouldn't rely on the feature to protect your app data from advanced threats like state-level actors. It doesn't separately encrypt the app from the rest of your data and it still allows AI agents and some services to access the app if you allow it. You should mainly use this to protect against an unsophisticated attacker with physical access to your phone. The new beta also brings other privacy and security enhancements as well. The [update](https://developer.android.com/about/versions/17/qpr2/release-notes#beta2) brings protection against call forwarding fraud: > Android 17 QPR2 Beta 3 introduces new security restrictions on programmatic call forwarding to protect users from fraud. The system now parses and selectively restricts call-forwarding USSD codes (such as `*21*`) executed via the [TelephonyManager.sendUssdRequest() API](https://developer.android.com/reference/android/telephony/TelephonyManager#sendUssdRequest%28java.lang.String,%20android.telephony.TelephonyManager.UssdResponseCallback,%20android.os.Handler%29). Apps attempting to do this via the `sendUssdRequest()` API will be blocked from doing so. If you manually try to dial call-forwarding codes, you'll be presented with a confirmation dialog in order to combat scams. Unfortunately, Google Pixel 6 devices [reportedly](https://www.androidauthority.com/android-17-qpr2-beta-3-new-features-3699084/) will not be receiving this update as they will have exceeded their support window by the time it fully releases, so if you're still using a Pixel 6 device it might be time to think about upgrading. ### Meta Files Patent for Facial Recognition, Automatic Recording of People URL: https://www.privacyguides.org/news/2026/08/17/meta-files-patent-for-facial-recognition-automatic-recording-of-people/ Last updated: 2026-08-17T22:20:38.000Z Meta filed for a [patent](https://image-ppubs.uspto.gov/dirsearch-public/print/downloadPdf/20260238876) that includes a "memory recall" system that appears to detect people via facial recognition and record them automatically, and show you a highlights real later. Meta's Ray-Ban smart glasses have garnered a reputation as "[pervert](https://futurism.com/future-society/meta-ray-ban-smart-pervert-glasses)" glasses, with many reports of them being used to record people surreptitiously using the onboard camera. The glasses feature a light that's meant to indicate when video is being recorded, but people have been going to [great lengths](https://cybernews.com/privacy/meta-cracks-down-after-finding-users-physically-drilling-out-built-in-privacy-feature-on-ray-ban-meta-glasses/) to disable it. Meta has released [updates](https://9to5google.com/2026/07/07/meta-ray-ban-smart-glasses-privacy-light-camera-update/) trying to disable the camera when the light doesn't work or is covered. They explain how it works in a [press release](https://about.fb.com/news/2026/07/metas-ai-glasses-your-questions-answered/): > Each pair of our AI glasses has a white light called a capture LED that blinks to signify when content is being captured for your gallery — covering or disabling this capture LED automatically disables the camera. They even brag about it being superior to smartphones, which lack the same outward-facing indicator light, but smartphones aren't always out and constantly pointed at everyone you're looking at: > While mobile phones and action cameras don’t have this on their cameras, ours have had them since day one. Later, it came out that a future version of the glasses might [record without the indicator light at all](https://www.privacyguides.org/news/2026/07/13/the-next-version-of-metas-ai-glasses-will-activate-the-camera-without-the-camera-indicator-light/), essentially ruining the entire point of the light in the first place. Combined with this latest news it seems even more creepy. The patent provides illustrations of how the potential feature is mean to work. It would scan and identify people performing actions, then automatically record them. ![](https://www.privacyguides.org/content/images/2026/08/image.png) Source: US Patent and Trademark Office One example Meta gives is using this feature during a dinner party. The AI says "I've generated some highlights of tonights' dinner party. Would you like to see them?" ![](https://www.privacyguides.org/content/images/2026/08/image-1.png) Source: US Patent and Trademark Office There's no example of a prompt asking if you want to record, it just does it when it thinks something important is happening. It's important to note that this patent doesn't mean the feature will exist, but the fact that Meta is even considering it is concerning. Meta earlier was caught earlier this year [sending](https://www.privacyguides.org/news/2026/03/03/meta-smart-glasses-sending-sensitive-recordings-to-workers-to-annotate/) video clips of "bank details, sex and naked people" to workers to train, with almost no privacy protection in place. ### Microsoft Making Passkeys the Default for Microsoft Accounts and Phasing Out SMS Authentication URL: https://www.privacyguides.org/news/2026/08/17/microsoft-making-passkeys-the-default-for-microsoft-accounts-and-phasing-out-sms-authentication/ Last updated: 2026-08-17T02:19:31.000Z Microsoft [says](https://support.microsoft.com/en-us/accounts-billing/manage/microsoft-to-stop-sending-sms-codes-for-personal-accounts) they'll soon stop sending SMS codes for authentication for personal Microsoft accounts and will transition to "passwordless accounts, passkeys, and verified email." SMS multi-factor authentication is a common way companies try to secure online accounts. The idea is that only you have access to your phone number, so only you should have access to any code sent there. However, SMS was never designed to be secure. It's unencrypted so an attacker could intercept the message before it even gets to you. [SIM swap attacks](https://www.trendmicro.com/en/what-is/cyber-attack/types-of-cyber-attacks/sim-swapping-scams.html), where criminals transfer your number to a SIM card they control, can give them full control of all accounts that use SMS MFA. [SS7 attacks](https://havenmessenger.com/blog/posts/ss7-attacks-explained/) can allow attackers to reroute your SMS messages by exploiting a protocol from the 1970's. It's a wonder then that companies still insist on pushing SMS MFA as a secure option to lock down your accounts, sometimes even forcing you to give your phone number and allowing it to override your password and other authentication measures. That's not to mention the privacy issues involved with providing your phone number to every account you have, something that doesn't change very often and is likely tied to your real-life identity. Microsoft is finally looking to remove SMS authentication entirely from their accounts and embracing passkeys as an alternative to passwords: > SMS-based authentication is now a leading source of fraud, and by moving to passwordless accounts, passkeys, and verified email, we're helping you stay ahead of evolving threats while making account access simpler and more seamless. Part of the reason why companies continue requiring things like SMS and email authentication is so you can still get into your account if your forget your password. Passkeys by default in most password managers sync and back up into the cloud, so you don't need to worry about forgetting a password. Disappointingly, Microsoft is still requiring an email on signup. For now, both email account recovery and SMS account recovery are still available. Email isn't much better than SMS for authentication, itself being unencrypted (at least the account recovery emails are). When I tried making an account, they actually tried to make me have *two* emails tied to my Microsoft account. Pretty ridiculous in my opinion. Microsoft don't say if they'll eventually phase out passwords in the future, just that the plan is to make passkeys the default for now. ### How to Securely Generate a Random Bitcoin Seed URL: https://www.privacyguides.org/videos/2026/08/16/how-to-generate-a-bitcoin-seed-securely/ Last updated: 2026-08-16T21:00:25.000Z Coinkite's [Coldcard](https://www.privacyguides.org/news/2026/08/03/nearly-1400-bitcoin-hacked-from-coldcard-wallets/) wallet recently suffered from a major, devastating flaw in its random number generation, exposing millions of dollars in Bitcoin held by their customers to attackers. In this video, we're going to generate a cryptocurrency seed phrase in the real world with only a 6-sided die, to guarantee our randomness isn't subject to an unknown software flaw. [Bitcoin Worksheetbitcointable.pdf28 KBdownload-circle](https://www.privacyguides.org/content/files/2026/08/bitcointable.pdf "Download") [Seed Phrase Word Listwordlist.pdf52 KBdownload-circle](https://www.privacyguides.org/content/files/2026/08/wordlist.pdf "Download") [Seed Phrase Word List (TXT)english\_numbered\_16-word\_sections.txt24 KBdownload-circle](https://www.privacyguides.org/content/files/2026/08/english%5Fnumbered%5F16-word%5Fsections.txt "Download") ### The Pixel 11 is Here, Will it Support GrapheneOS? URL: https://www.privacyguides.org/livestreams/2026/08/14/the-pixel-11-is-here-will-it-support-grapheneos/ Last updated: 2026-08-21T21:06:28.000Z This Week in Privacy #66 _This post is for subscribers only._ ### Data Breach Roundup (August 7 - 13, 2026) URL: https://www.privacyguides.org/news/2026/08/14/data-breach-roundup-august-7-13-2026/ Last updated: 2026-08-14T15:21:18.000Z ## Computer maker Framework notifies ‘all customers’ of a data breach Framework is popular in the privacy community because they make modular, repairable devices that resonate with the "right to repair" ethos. Due to an incident at a third party company that provides "business intelligence," customer names, email addresses, phone numbers, and physical addresses were leaked for all Framework customers. [Computer maker Framework notifies ‘all customers’ of a data breach | TechCrunchFramework told “all” of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-f620eba4-70e9-4f17-849c-77b5e84ca252.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/Framework-Desktop-2-5fde542d-3b29-4b07-89b2-8fea3ea4a7ae.jpg)](https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/) ## Unlimited Technology Systems breach impacts 3.8 million people Healthcare software company Unlimited Technology Systems submitted a data breach notification on July 1st, stating that a breach had occurred in October 2025 but without including any details. We now know the number of people impacted, as well as what data: full names, Social Security numbers, dates of birth, email & mailing address, phone numbers, demographic information, scans of driver's license or other government IDs, insurance cards, intake forms, health insurance policy numbers, claims & benefits information, medical record numbers, dates of service, and diagnosis information. [Unlimited Technology Systems breach impacts 3.8 million peopleHealthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.![](https://www.privacyguides.org/content/images/icon/bleeping-82913a44-82fd-4e79-b172-5346e8a2a796.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/healthcare-f7a2a83d-cd16-484c-a73f-a8566eb20e9e.jpg)](https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/) ## A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond Ceva Logistics, one of the world’s largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. Several companies reported that hackers took their customers’ names, home addresses, phone numbers, and email addresses used to place their orders from Ceva’s systems. Impacted companies include Dutch retail giant Bol, Dutch luxury retailer De Bijenkorf, football club Ajax, banking giant ING, eyeglass maker Ace & Tate, and gaming giant Valve. [A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond | TechCrunchCompanies that rely on Ceva Logistics for shipping their physical goods to customers say their personal data was taken during a recent cyberattack.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-f5abd6dc-7790-4b30-a662-1f4f11b7483a.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/shipping-2288991285-83929986-2c7b-4776-9a0c-c8cc8b6e1f97.jpg)](https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/) ## Wesco confirms security incident after ExfilSquad claims data theft Wesco is a global "supply chain and distribution giant." There's not much information except that the company has confirmed an incident. Attackers meanwhile claim to have stolen 2.6 million records containing customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information. [Wesco confirms security incident after ExfilSquad claims data theftGlobal supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident.![](https://www.privacyguides.org/content/images/icon/bleeping-6a55687e-eaa0-4a8e-ac5a-423f4867c110.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/wesco-fb6320c3-1d94-40e7-a12b-d1fa3c681564.jpg)](https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/) ## Trezor discloses data breach affecting nearly 14,000 customers This breach comes through Trezor's shipping provider ShipMonk. Attackers gained access to customer names, shipping address, email address, and phone numbers and impacted customers in the US, UK, Sweden, Colombia, Brazil, Italy, and Portugal who received orders between May 10th and August 8th 2026. [Trezor discloses data breach affecting nearly 14,000 customersHardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked![](https://www.privacyguides.org/content/images/icon/bleeping-0bccd87a-308a-4c6c-906c-effecc369888.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Trezor-66a17e9a-4a3f-409f-bff4-b2279bd67b4d.jpg)](https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/) ### Google Announced the Pixel 11 With Their New Titan M3 "Quantum-Safe" Secure Boot URL: https://www.privacyguides.org/news/2026/08/13/google-announced-the-pixel-11-with-their-new-titan-m3-quantum-safe-secure-boot/ Last updated: 2026-08-13T21:04:06.000Z Google [announced](https://blog.google/products-and-platforms/devices/pixel/google-pixel-11-pro-xl/) its new Pixel 11 series of phones that bring with them a big security boost in the form of the new Titan M3 security chip that supports post-quantum cryptography for secure boot. In their announcement, they describe how the Titan M3 and new Tensor G6 SoC work in tandem to secure the phone: > As technology evolves, so do the threats. Google Pixel is engineered specifically to help safeguard your most sensitive information from advanced attacks today and from risks like attacks by quantum computers in the future. Our new Titan M3 security chip and custom Tensor G6 processor seamlessly integrate to form our most robust, proactive defense system yet, bringing post-quantum cryptography to secure boot on your device. The previous Titan M2 processor came out back in 2021 with the launch of the [Pixel 6](https://security.googleblog.com/2021/10/pixel-6-setting-new-standard-for-mobile.html), although there have likely been changes and updates to the M2 chip on subsequent Pixels. [Leaks](https://www.androidauthority.com/cellebrite-leak-google-pixel-grapheneos-security-3611794/) from the much-maligned Cellebrite, who sell devices to exploit phones and extract data to law enforcement, show that they struggle to bypass the hardware security features of Pixels from the 6 onward, mainly thanks to the Titan M2. Pixels are also the only devices to support the security-hardened GrapheneOS currently, although a [partnership](https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/) with Motorola will bring a device from that vendor into support in the near future. A peruse of the [tech specs](https://store.google.com/product/pixel%5F11%5Fpro%5Fspecs?hl=en-US) for the new phones shows no support for the infrared hardware that would be necessary to match the iPhone's secure Face ID despite [rumors](https://www.privacyguides.org/news/2026/02/19/googles-project-toscana-will-upgrade-face-unlock/) that the Pixel 11 would support it. In light of developments in quantum computing, Google earlier this year [introduced](https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/) a 2029 deadline for migrating to post-quantum cryptography (PQC) in order to secure our data against attacks from quantum computers, which could theoretically break the classical encryption we use every day once one powerful enough exists. Given the short deadline, Google has been working hard at beefing up its cryptography with PQC as much as possible, beginning all the way back in [2016](https://security.googleblog.com/2016/07/experimenting-with-post-quantum.html). The latest development saw Google adding [support](https://blog.google/security/security-for-the-quantum-era-implementing-post-quantum-cryptography-in-android/) in Android for quantum-safe signatures so that app developers can sign their apps without needing to make their own PQC cryptographic implementations. The new quantum-safe secure boot in Pixel 11 phones seems like a continuation of their work on moving Android into being fully quantum-safe. ### Nightmare-Eclipse Releases Yet Another Devastating Windows 0-day Vulnerability URL: https://www.privacyguides.org/news/2026/08/13/nightmare-eclipse-releases-yet-another-devastating-windows-0-day-vulnerability/ Last updated: 2026-08-13T00:09:44.000Z The prolific and controversial security researcher who goes by Nightmare-Eclipse [released](https://cybersecuritynews.com/nightmare-eclipse-drops-shieldbreak-0-day/#google%5Fvignette) a ninth 0-day vulnerability that allows an attacker to gain SYSTEM level privileges. The vulnerability, titled ShieldBreak, exploits Microsoft Defender and leverages its SYSTEM level access. This new exploit is actually a continuation of an older one released by Nightmare-Eclipse called [RoguePlanet](https://cybersecuritynews.com/windows-defender-0-day-exploit-rogueplanet/). According to the researcher, Microsoft didn’t properly patch RoguePlanet and the patch can be completely bypassed. The original RoguePlanet was based on a race condition, meaning that it relies on specific timing in order to work. Usually this means an exploit won’t work 100% reliably, and they described RoguePlanet as “hit or miss” in their [original](https://github.com/MSNightmare/RoguePlanet) proof-of-concept on GitHub. They also said it might be possible to redesign it so it could have a 100% success rate. The new proof-of-concept for [ShieldBreak](https://github.com/MSNightmare/ShieldBreak) claims a 100% success rate although they say Windows 10 systems aren’t fully supported even though the exploit still affects them. Normally, security researchers go through a coordinated vulnerability disclosure process with vendors like Microsoft to ensure enough time for them to patch the vulnerability before publishing the details. 0-days, however, are not known by the vendor and thus they can be exploited while the software developers make a patch. Nightmare-Eclipse has made a point of intentionally releasing their vulnerabilities to the public without giving Microsoft time to patch them. All this is to get back at Microsoft for some personal slight. They’re unique among threat actors as their actions aren’t driven by money or political activism but a personal grudge against the Microsoft. Their exploits have seen use in [real-world attacks](https://www.huntress.com/blog/nightmare-eclipse-intrusion) against Windows and caused real damage. As Microsoft hits record numbers of vulnerabilities patched in updates this year, the current record sitting at 622 flaws [fixed](https://cybernews.com/security/microsoft-july-2026-patch-tuesday-570-vulnerabilities-kerberos/) in their July patch Tuesday, this is yet more workload that they’ll have to contend with. The fact that the bug can bypass their original patch suggests a flawed approach Microsoft is taking to fixing bugs, potentially leaving more half-fixes just waiting to be reopened. The unprecedented onslaught of AI-assisted vulnerability research has tested the capacity of companies to keep up with the constant stream. It’s unclear if the plan is to keep playing whack-a-mole with vulnerabilities or if there’s a longer term plan to harden operating systems against exploits such as these. It’s difficult to imagine the current state of cybersecurity being sustainable for the long term. ### Severe Zoom Vulnerabilities Allow Malicious Meeting Participants to Take Over Your Device URL: https://www.privacyguides.org/news/2026/08/12/severe-zoom-vulnerabilities-allow-malicious-meeting-participants-to-take-over-your-device/ Last updated: 2026-08-12T01:18:53.000Z [Researchers](https://a.security/blog/asecurity-zoomsday) identified critical vulnerabilities in Zoom that allows a full device takeover with no user interaction, and present on all devices. The work was made possible due to the help of AI, something that's becoming more and more common in security research as AI tools massively accelerate the rate at which bugs are found. Ⓐ Security describes the bug as a "nation-state" level exploit and a "weapon" the likes of which governments would normally have to pay millions for. The researchers discovered it in a single work day using less than 20 prompts on publicly available AI models. Appropriately dubbed "Zoomsday," the exploit is a memory-corruption bug (go figure) in Zoom's annotation feature, a completely proprietary and undocumented protocol. The zoom client automatically parses anything it receives, allowing an attacker to use the vulnerability without any interaction from the victims. The annotation feature doesn't send an image to overlay on the call, it sends instructions on how to draw the onscreen lines, shapes, text, etc in order in a continuous stream of data. The receiver trusts the data stream from the sender to tell it how much more to read. The attacker can target each person individually because of how the annotation streams are set up. The bundle that the annotation feature ships on doesn't use Pointer Authentication Codes or any other feature that would mitigate a memory corruption bug. > With no PAC to authenticate anything, we don't need a complex exploit. We can just point the return address (`X30`/`LR`) at one ready-made instruction sequence (a "gadget") in the system's shared library cache, and let the epilogue pre-load the argument registers for us. The researchers reported the exploit to Zoom on June 10, with Zoom getting a fix out in just twelve days. If you haven't updated Zoom in a while, make sure you're on the latest version. It's a good thing Zoom were so responsive as Zoom is used in so many places from doctors' offices to enterprises that an unpatched exploit like this would put a lot of people's data at risk. The researchers have a bit of an ominous warning though: > Beyond this vulnerability, prepare for the next one, because there will be a next one and not necessarily in Zoom. Every endpoint runs software that parses bytes chosen by outsiders, and you cannot audit any of it. With the rise of AI tools for finding exploits, we've seen a huge jump in vulnerabilities, [some](https://www.privacyguides.org/news/2026/08/07/18-year-old-linux-kernel-bug-allows-full-system-takeover/) almost two decades old, and sometimes [hundreds](https://cybernews.com/security/microsoft-july-2026-patch-tuesday-570-vulnerabilities-kerberos/) of vulnerabilities being patched at once to keep up with the onslaught of AI bug reports. ### This Billion-Dollar Network Is Secretly Tracking Your Car URL: https://www.privacyguides.org/videos/2026/08/11/this-billion-dollar-network-is-secretly-tracking-your-car/ Last updated: 2026-08-11T17:30:14.000Z [Open in YouTube](https://www.youtube.com/watch?v=ZDZlmDtlnvo) If you drive in America today, you've almost certainly been scanned by a Flock camera, maybe even hundreds of times. Your location, along with a timestamp and photo, all stored in a cloud database accessible to police departments across the country. In this video we'll explain how this technology can be used for mass surveillance and tracking and how you can fight back in your local city! #### Sources Video clips shown under fair use for commentary/criticism. 0:49 0:51 0:55 1:00 1:28 1:32 1:40 1:47 1:55 2:02 2:15 2:19 2:28 2:41 2:56 3:06 3:19 3:37 3:46 4:39 4:42 4:51 4:54 5:06 5:21 5:41 5:47 5:57 6:18 ### California City Declares State of Emergency After Cyberattack URL: https://www.privacyguides.org/news/2026/08/11/california-city-declares-state-of-emergency-after-cyberattack/ Last updated: 2026-08-11T00:14:59.000Z The Suisun City Council [declared](https://www.nbcbayarea.com/news/local/suisun-city-state-of-emergency-cyberattack/4125654/) a state of emergency on Saturday after a cyberattack shut down numerous public safety systems, including their 911 routing, police and fire dispatch, and records and city services. Little else is known at this time, though the city said that there is no immediate threat and all public safety services remain active. Public safety calls are being routed through the Solano County dispatch center, but online city services and "internal operations" are unavailable. Stories like these demonstrate the ever-rising stakes as the world has become so digital and connected. Attackers are increasingly becoming emboldened and going after more and more critical services - like water and hospitals. Cybersecurity is increasingly having tangible, real-world, possibly life-or-death impacts. ### Signal is Looking at Adding an Option to Sign Up Without a Phone Number URL: https://www.privacyguides.org/news/2026/08/10/signal-is-looking-at-adding-an-option-to-sign-up-without-a-phone-number/ Last updated: 2026-08-10T22:34:19.000Z [References](https://aboutsignal.com/news/signal-login-registration-without-a-phone-number/) in Signal's source code point to a new feature to sign up without giving a phone number, potentially requiring a one-time payment. Signal is one of the most popular encrypted messengers on the market and is regarded highly by privacy advocates the world over. But one of the major sticking points that turns people off signing up is the phone number requirement. Phone numbers are personal information that can link your accounts back to you. Many countries have Know Your Customer (KYC) laws that require you to give personal information when you sign up for a new phone number. Even when it's not required by law, many carriers collect troves of personally identifying data anyway when you sign up. Signal added [Phone Number Privacy](https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames) as a feature to hide your phone number from other users by default and added [Usernames](https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames#username) that you can set that will allow other people to contact you without a phone number, similar to how many websites have user-settable usernames as identifiers just for that service. Even with these improvements, a phone number is still required to sign up. In a blog post from 2023, Signal estimated that they spend around $6 million dollars per year on verifying phone numbers. Signal CTO Ehren Kret [said](https://youtu.be/C9equPLhKxY?si=zVCXvT%5FfdOzS05m8&t=27) responding to a question at FUTO's Don't Be Evil conference: "that is something we are looking a hopefully for later on this year adding a way to sign up without phone numbers. Uh the main uh downside at the moment and the reason we don't have that yet today is removing accounts who are are spamming people or otherwise engaging in abuse of the service is sort of our our primary way of protecting people from spam and other sort of issues like that that would affect the operational stability of the service." While this confirms their interest in phone numberless signup, it doesn't give any solid confirmation that it will happen. About Signal [spotted](https://aboutsignal.com/news/signal-is-working-on-registration-without-a-phone-number/) several commits on Signal's GitHub with [commit messages](https://github.com/signalapp/Signal-Server/commit/ef2d25704e4f2d26d777303a702026c70c4c2e37) that reference accounts with no phone numbers, such as "Don’t allow or set registration lock on accounts with no phone number," heavily suggesting that Signal is actively working on a feature allowing you to sign up without a phone number. Kret mentioned in the Q and A video that phone numbers introduce a small cost that helps prevent spammers from making loads of new accounts, so a new replacement would need to similarly add a cost to prevent spam. More references in Signal's [source code](https://github.com/signalapp/Signal-Android/blob/66ff18c310d910dd56f4098ae17e18a087c5b9cd/feature/registration/src/main/res/values/strings.xml#L609) suggest this feature will be called "Signal Login" and will indeed be a paid feature. Since payment info can be just as identifying as a phone number, its unclear how Signal plans to protect the privacy of users' payment info. ### The Secret War on Encryption: Inside Bullrun URL: https://www.privacyguides.org/videos/2026/08/09/the-secret-war-on-encryption-inside-bullrun/ Last updated: 2026-08-22T00:27:16.000Z There are a lot of claims online that various services are honeypots or contain secret backdoors. Most of these claims are based only on circumstantial evidence - if any evidence at all. But it's not hard to see why people believe these stories. Governments have done exactly this sort of thing in the past, and continue to do so even to this day. This is the story of Bullrun, the National Security Agency's probably-ongoing effort to have eyes into every single digital service on the planet, and how you can you defend yourself against it. #### Sources 0:06 0:07 0:08 0:09 0:38 1:01 1:14 1:54 2:07 2:26 2:39 3:25 3:52 4:39 5:05 5:30 6:00 6:17 7:03 7:25 7:46 8:10 8:59 9:04 9:09 9:28 9:33 ### 18-Year-Old Linux Kernel Bug Allows Full System Takeover URL: https://www.privacyguides.org/news/2026/08/07/18-year-old-linux-kernel-bug-allows-full-system-takeover/ Last updated: 2026-08-07T23:33:30.000Z Researchers at Tencent Zhuque Lab [uncovered](https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564) an 18-year-old vulnerability in the Linux kernel that can escape containers and gain full root privileges on the host system. Memory safety issues continue to plague operating systems like Linux written in unsafe languages like C++. Google's [data](https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html) shows that memory safety issues used to make up around 76% of vulnerabilities on Android before they started switching to memory-safe languages for new code. They also stated in the same post that most memory safety vulnerabilities tend to show up in newer code, so focusing on switching new code to memory-safe languages in new code is good enough to make a big security difference. Now with AI-assisted security research, [many](https://www.privacyguides.org/news/2026/07/08/15-year-old-linux-kernel-vulnerability-allows-full-system-takeover/) severe, over decade-old vulnerabilities that have alluded human researchers for years are being found, putting into question how safe older code really is. The vulnerability, dubbed SCTPhantom, is a user-after-free vulnerability in the [SCTP protocol](https://docs.kernel.org/networking/sctp.html)'s Dynamic Access Reconfiguration feature in the Linux kernel. The code introducing the bug dates all the way back to 2007 in Linux 2.6.25, making the bug 18 years old. The root cause of the vulnerability lies in ASCONF, which contains operations such as ADD-IP, DEL-IP, and SET-PRIMARY, which are processed in order on Linux. > The vulnerable ASCONF chunk uses two different identities: the IPv4 packet source `S`and the Address Parameter `L` used to select a transport. The DEL-IP check validates the requested address against `S`, while later processing relies on the transport selected through `L`. > Because `S` and `L` are different, `DEL-IP L` passes the source-address check and removes `transport(L)`. The wildcard DEL-IP then reuses the cached pointer to that transport as the path to preserve. As a result, the association can retain the removed transport in `primary_path` and `active_path`, allowing a later socket operation to dereference a stale pointer. The researchers made use of an AI called Corvus during the process of developing the exploit, which they say was a significant help in their research workflow. Linux has already begun [removing](https://www.privacyguides.org/news/2026/06/18/linux-removes-support-for-legacy-appletalk-protocol-in-response-to-ai-patches/) old cruft from the kernel in response to the influx of AI bug reports, but even with those efforts, the kernel is so massive that there's bound to be countless bugs still. Greater efforts toward removing attack surface in the kernel and a push for memory-safe languages like [Rust](https://docs.kernel.org/rust/index.html) would significantly improve its resilience against the current onslaught of bugs. ### Apple’s “Private” Relay Exposed Your IP Address?! URL: https://www.privacyguides.org/livestreams/2026/08/07/apples-private-relay-exposed-your-ip-address/ Last updated: 2026-08-14T22:33:52.000Z This Week in Privacy #65 _This post is for subscribers only._ ### Data Breach Roundup (July 31 - August 6, 2026) URL: https://www.privacyguides.org/news/2026/08/07/data-breach-roundup-july-31-august-6-2026/ Last updated: 2026-08-07T17:55:27.000Z ## ExfilSquad hackers leak info of over 100,000 UK police officers, staff This impacted the UK's Police National Legal Database (PNLD) and exposed full names, organizations, and email addresses of police officers, staff, criminal justice professionals, and government partners. The names and email address of "Ask the Police" users who submitted questions are also believed to be compromised. [ExfilSquad hackers leak info of over 100,000 UK police officers, staffA cyberattack on the U.K.’s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.![](https://www.privacyguides.org/content/images/icon/bleeping-fcfa45f8-4553-420e-81e6-9931278b0fea.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/uk-police-dd64674d-c223-4327-aad9-550f126eee79.jpg)](https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/) ## Swiss government SharePoint breach compromised 200 accounts The Federal Office for Information Technology and Telecommunication (BIT) detected a cyberattack on their SharePoint servers on July 28\. They closed network access, patched the suspected vulnerabilities, and reset passwords for affected accounts. At this time they say no data was stolen other than credentials and it's unclear how many accounts were impacted. [Swiss government SharePoint breach compromised 200 accountsSwitzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts.![](https://www.privacyguides.org/content/images/icon/bleeping-d0955ea7-7bca-42cd-b3ae-c7425a4f66dc.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/Switzerland-flag-f334355f-7cbb-4d4d-913b-d5b7d9e12594.jpg)](https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/) ### Spectre is Back: CPU Mitigations Found to Be Ineffective URL: https://www.privacyguides.org/news/2026/08/07/spectre-is-back-cpu-mitigations-found-to-be-ineffective/ Last updated: 2026-08-07T00:17:01.000Z Researchers [found](https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html) a way to bypass the latest Spectre mitigations and exploit AMD and Intel processors to leak secrets like passwords and encryption keys. Modern CPUs are fast, but they don't achieve that speed just from raw processing power: they use what's called [branch prediction](https://joegm.github.io/blog/branch-prediction-demystified/) and [speculative execution](https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/hardware-behavior-related-to-speculative-execution.html) to try and guess what the outcome of a conditional statement is before it's actually evaluated and execute code earlier. While it seems like magic that this technique can speed up our processors so much, [researchers](https://spectreattack.com/spectre.pdf) found a way to exploit these features to steal data like passwords, encryption keys, browser data, or really anything in an exploit dubbed "Spectre." CPU manufacturers released patches to fix these flaws, but seemingly they weren't enough. Intel's [eIBRS](https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/branch-history-injection.html#:~:text=eIBRS%20prevents%20Branch%20Target%20Injection%20%28Spectre%20v2%29%20by%20preventing%20less%20privileged%20modes%20from%20specifying%20the%20predicted%20targets%20of%20indirect%20jumps.) promises to prevent "Branch Target Injection (Spectre v2) by preventing less privileged modes from specifying the predicted targets of indirect jumps." AMD's Safe RET promises to similarly protect against this attack. According to the [paper](https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf) released by the researchers, modern Spectre mitigations work by "neutralizing" the branch predictor state, sanitizing it and isolating different states, such as when switching between privilege contexts. These features assume that everything between the neutralization phase and when the state is actually used is safe, however there is a small post-neutralization window that's just big enough to completely break the security protections. The researchers dubbed this type of attack Time-of-Neutralization to Time-of-Use (TONTOU). They were able to make use of [interrupts](https://eng.libretexts.org/Courses/Delta%5FCollege/Introduction%5Fto%5FOperating%5FSystems/04%3A%5FComputer%5FArchitecture%5F-%5Fthe%5FCPU/4.02%3A%5FInterrupts) to exploit this window reliably across Intel and AMD chips using what they dub an Interrupt Injection attack. It's widely assumed that interrupts are benign, but as with many assumptions in tech, this proved to be very wrong. They were able to create an end-to-end attack that could reliably expose kernel memory with an accuracy of 91.97%, including the root password located at `/etc/shadow` . The attack only needs local code execution; it works with a completely unprivileged user with all modern Spectre V2 mitigations enabled. The researchers say they disclosed the attack to both AMD and Intel on February 5th, 2026, and both confirmed the behavior. AMD said they will release a patch, which they seemingly [did](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7061.html), but Intel didn't think the attack warranted a fix. They also contacted the Linux kernel about it. [Reportedly](https://thehackernews.com/2026/08/new-interrupt-injection-attack-can.html), a [patch](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f5fdd6665ac4d8528ed1c9242cb1cf7a7f5bdb0e) has landed in the kernel now. ### North Korean Hackers Breached Over 1,600 Organizations Worldwide URL: https://www.privacyguides.org/news/2026/08/06/north-korean-hackers-breached-over-1-600-organizations-worldwide/ Last updated: 2026-08-06T21:14:50.000Z Greek cybersecurity researcher Vangelis Stykas revealed at the Black Hat security conference that he discovered evidence that 1,640 companies across 57 countries have been compromised by North Korean hacking operations. In recent years, North Korea has been implicated in numerous scams and hacks resulting mostly in the theft of cryptocurrency but also sometimes corporate secrets and intellectual property. These attacks have largely been carried out to fund the country in general and its weapons programs since sanctions against them are so internationally widespread and severe. According to [WIRED](https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/), Stykas claims to have gained access to North Korean systems nearly two years ago and is now raising concerns about just how much damage the country's hackers are causing. The most popular attack vector - according to Stykas - is fake interviews where North Korean hackers pose as recruiters offering jobs to developers, then trick the developers into downloading malware under the guise of a coding test. Stykas claims that about 700-800 organizations suffered "really damaging" intrusions including root-level access to servers and blockchain keys in the case of crypto companies. Some of the companies he was willing to name - because he claims they have handled the disclosure well and are likely now patched - include the Boston Children's Hospital, Coinbase, Italy's Supreme Judicial Council, a subsidiary of Saudi Arabia's Al Rajhi Bank, Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, and part of the Flemish government in Belgium. WIRED stated at the time of publication that Stykas "will \[offer\] detail\[s\] at the Black Hat security conference in Las Vegas today," so it's possible more information will be published online in the near future, likely in the form of a video or blog post. ### Data Breach Roundup (July 24 - 30, 2026) URL: https://www.privacyguides.org/news/2026/08/05/data-breach-roundup-july-24-30-2026/ Last updated: 2026-08-05T19:43:32.000Z ## OnTrac notifies customers of data breach after network hack OnTrac is an American delivery company that operates in 35 states, covering roughly 70% of the US population. This breach took place in March. The article referenced notification letters but didn't share how many people or what data was impacted. [OnTrac notifies customers of data breach after network hackOnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers.![](https://www.privacyguides.org/content/images/icon/bleeping-d075fd3c-e83d-4f37-bda2-7a677676c297.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/OnTrac-8e6d6322-fbf2-431a-a93c-967207cfe49d.jpg)](https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-after-network-hack/) ## Tons of Peoples’ Claude Chats and Creations are Exposed on Google When Claude users create a public share link, Claude warns them that anyone with the link can access the chat. However, these links are ending up in Google searches. These chats sometimes include sensitive information like API keys, login credentials, names, addresses, and phone numbers. Some of the data appears to have come from an AI-powered therapy app. [Tons of Peoples’ Claude Chats and Creations are Exposed on GoogleClaude users are creating public share links, but probably don’t realize that means their chats are now ending up in Google searches where anyone can dig through them.![](https://www.privacyguides.org/content/images/icon/favicon-3-b0f4e02c-1bda-41b7-96be-62096dc4ec00.svg)404 MediaJoseph Cox![](https://www.privacyguides.org/content/images/thumbnail/brett-wharton-YmSiFKOecCU-unsplash-5b874c9b-d870-4efe-b356-3c18754c6cb0.jpg)](https://www.404media.co/tons-of-peoples-claude-chats-and-creations-are-exposed-on-google/) ## ShinyHunters claims Brinks Home breach, threatens to leak stolen data The attackers claim to have stolen 4.9 million Salesforce records with personally identifiable information, as well as 3.8 million support chat logs. Brinks claims this did not impact their alarm monitoring capabilities. There's no other information at this time. [ShinyHunters claims Brinks Home breach, threatens to leak stolen dataResidential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data.![](https://www.privacyguides.org/content/images/icon/bleeping-06632eb1-0323-48dc-ae8f-ae5eadd91f2c.ico)BleepingComputerIonut Ilascu![](https://www.privacyguides.org/content/images/thumbnail/Brinks-Home-Security-System-0c828bd5-65df-48b7-9e92-4f5613d8a32f.png)](https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data/) ## CareCloud begins to notify hundreds of thousands after hackers stole medical records This is an update to a story that broke in March. We now know that it impacted just over 345,000 people so far, with the number expected to go up as more disclosures are filed. Data stolen includes names, postal address, Social Security numbers, government-issued ID numbers (such as passport and driver's license), financial information (such as bank account or card numbers), and medical & health-related information. [CareCloud begins to notify hundreds of thousands after hackers stole medical records | TechCrunchThe health tech data giant, which handles vast amounts of patients’ medical data, said hackers struck one of its protected health data stores.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-a9d045e6-6797-46a6-b886-b1151228e102.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/medical-records-getty-8e60537b-b3bd-430b-9994-8a680da370e2.jpg)](https://techcrunch.com/2026/07/30/carecloud-begins-to-notify-hundreds-of-thousands-after-hackers-stole-medical-records/) ## South Korea fines telco giant KT $39 million for customer data breach This is an update to an ongoing story. We learned last year that South Korea's biggest telecommunication providers was compromised for nearly 11 months, exposing the data of over 16,000 subscribers and enabling over $167,000 USD of fraudulent mobile payments. [South Korea fines telco giant KT $39 million for customer data breachSouth Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations.![](https://www.privacyguides.org/content/images/icon/bleeping-a7a44365-897f-474a-9af0-e04831a4a51c.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/kt-9f184241-50f0-433c-bd5f-ce0419e36fee.jpg)](https://www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-39-million-for-customer-data-breach/) ## Data breach at medical billing firm MCBS affects 1.26 million people This breach occurred in 2025 but was just disclosed last month without any details. In addition to number impacted, we now know that full name, physical address, Social Security number, date of birth, health plan beneficiary number, health insurance policy number, subscriber identification number, medical history, mental & physical condition, medical treatment information, and diagnosis information were potentially exposed. [Data breach at medical billing firm MCBS affects 1.26 million peopleHealthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.![](https://www.privacyguides.org/content/images/icon/bleeping-6aad143e-0747-4102-8989-34692f8ada05.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/healthcare-security-62a62792-99aa-4e9c-9779-f888b5d80c51.jpg)](https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/) ## Chick-fil-A data breach affects more than 13,000 customers An update to a story from last week, we now know how many customers were impacted by the Chick-fil-A credential stuffing attack. [Chick-fil-A data breach affects more than 13,000 customersChick-fil-A has confirmed that over 13,000 customers had their accounts breached in a wave of credential stuffing attacks targeting its website and mobile app between June 17 and June 19.![](https://www.privacyguides.org/content/images/icon/bleeping-069f6756-0e6e-4d91-8714-e263dddb2f24.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Chick-fil-A_headpic-7dbc08d8-a375-4360-9e4f-7bb1d8a5f6d1.jpg)](https://www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers/) ### Apple's Private Relay Leaks Your Real IP Address in Safari URL: https://www.privacyguides.org/news/2026/08/05/apples-private-relay-leaks-your-real-ip-address-in-safari/ Last updated: 2026-08-05T18:11:03.000Z App developer/security researchers at [Mysk](https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/) discovered several leaks in Apple's Private Relay and all other browser proxies that allow websites to see your real IP address. [Private Relay](https://support.apple.com/en-us/102602) is a feature that's meant to hide your IP address from the websites you visit in Safari using a dual-hop architecture where the first hop is run by Apple and the second is run by a third-party provider, preventing either party from getting the full picture of who you are and what site you're visiting. Three separate leaks allow this protection to be completely bypassed by any website, however. You can check if your browser is affected by visiting [a website](https://leaks.psylo.app) set up by Mysk. The flaws not only affect Private Relay, but all other browsers that have a proxy feature as well including browsers that route traffic over the Tor network such as Onion browser, since all browsers on iOS are required to use WebKit. VPNs work device-wide so they aren't affected by these leaks at all. The first is via [DNS prefetching](https://developer.mozilla.org/en-US/docs/Web/Performance/Guides/dns-prefetch), a feature meant to speed up page load times. When a website uses DNS prefetching, the site's domain name is resolved using the device's normal DNS path rather than resolving it through the proxy, revealing the real DNS servers of your device. The second is through [WebAuthn](https://developer.mozilla.org/en-US/docs/Web/API/Web%5FAuthentication%5FAPI), a standard for securely authenticating with websites. It's the web API behind passkeys and FIDO2\. Usually passkeys are tied to a specific website's domain name, but Related Origin Requests allow a single passkey to be used across several domains owned by the same entity. To accomplish this, an HTTPS request need to be made to see which domains are allowed. WebKit hands the process off to the operating system's credential service which then makes the request outside of the browser's proxy. The third leak uses [WebTransport](https://developer.mozilla.org/en-US/docs/Web/API/WebTransport), a feature that allows web developers to open connections to other servers. Using this feature opens a connection straight from the device, bypassing the browser's proxy. The researchers didn't [report](https://x.com/mysk%5Fco/status/2085026605529768261) the issue to Apple and instead released it to the public immediately, citing the excessively long wait times and previous rejections from them: > We weren’t willing to wait months, or upwards of a year, sitting on bugs that undermine the core privacy guarantees of Psylo and iOS Tor browsers while saying or doing nothing. A year’s timeline not an exaggeration either: Researchers at EasyOptOut reported to Apple in June 2025 that iCloud Hide My Email leaks real email addresses behind private aliases, and Apple got around to it in July 2026, just about 13 months later. ### WhatsApp is Testing Age Verification URL: https://www.privacyguides.org/news/2026/08/04/whatsapp-is-testing-age-verification/ Last updated: 2026-08-04T23:00:53.000Z The Tech Trace [reports](https://thetechtrace.substack.com/p/edition-32-whatsapp-tests-age-self-declaration-in-india) that a WhatsApp representative has confirmed the messenger is testing out new age verification on some user accounts to comply with a new law in India. The Digital Personal Data Protection Act (DPDP) will come into effect May of 2027, so this is just an early trial and it hasn't rolled out to all users in India yet. Some people are getting new [popups](https://www.reddit.com/r/whatsapp/comments/1vbyids/whats%5Fwrong%5Fwith%5Fwhatsapp/?solution=147cd17082de4ddb147cd17082de4ddb&js%5Fchallenge=1&token=7afd7253fec22262ff1c52b1703fe9ec01e20088d59b30bb4bd6de349af5461c&jsc%5Forig%5Fr=) in WhatsApp asking them to add their age. The popup says "Upcoming laws in India require us to ask for your age." A spokesperson for WhatsApp clarified what specific law and what the feature is meant for: > To comply with upcoming laws in India like the Digital Personal Data Protection Act (DPDP), we are testing privacy-protective ways for people to confirm their age. This doesn’t change how WhatsApp works or your experience. We understand that information about someone’s age is private and it won’t be shared with other WhatsApp users. The law itself doesn't actually require age verification, it requires obtaining "verifiable consent" of a parent or guardian before processing the data of a child. In order to verify that, it's a multi-step process. First, the app needs to check if the user is a child, which can either be self-reported and potentially wrong or enforced by some age verification process. Second, the minor account needs an adult account to claim it and perform "due diligence" to ensure the owner of the account is indeed an adult. Third, they need to confirm that the adult is indeed the parent or guardian of the child. This part is concerning as it would likely involve actually identifying each individual person and not just confirming their age via some kind of privacy-preserving method using [zero-knowledge proofs](https://blog.google/innovation-and-ai/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/) or a similar technology. For the time being, you can just lie about your age and WhatsApp will believe you. It's not clear what they plan for the future in terms of "privacy-protective" age verification but attempts at making digital IDs allow privacy-preserving age verification have been made, with [Google](https://wallet.google/intl/en%5Fus/digitalid/) and [Apple](https://www.apple.com/newsroom/2025/11/apple-introduces-digital-id-a-new-way-to-create-and-present-an-id-in-apple-wallet/) both implementing versions of Digital IDs that allow you to choose specific information to share. The technology is young, however, with many kinks to work out still and not many examples of services actually utilizing the feature. The EU's digital ID app was [hacked](https://cybernews.com/security/eu-age-verification-app-hack/) earlier this year, raising security concerns over the not-yet battle tested technology. ### Multiple Flaws in Google's Synced Passkey Implementation Allow Attackers to Take Over Your Accounts URL: https://www.privacyguides.org/news/2026/08/03/multiple-flaws-in-googles-synced-passkey-implementation-allow-attackers-to-take-over-your-accounts/ Last updated: 2026-08-03T21:52:49.000Z [Unit 42](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/) released new research showing that in Google's synced passkey ecosystem, it's possible for an attacker to take over accounts protected by synced passkeys without user interaction. [Passkeys](https://fidoalliance.org/passkeys/) are a more secure authentication standard that's meant to replace passwords. They don't require you to make them up yourself or remember them, and they're stored bound to specific hardware or synced to the cloud, so you can securely log in on all your devices. They're meant to ensure that you authenticate with biometrics or a device PIN on top of possessing the passkey as well, allowing the to cover multi-factor authentication as well (the passkey you generate is never supposed to allow you to share it or copy it to someone else). Before the passkey theft begins, the attacker needs to see which of your accounts use passkeys. Chrome on Windows makes this data readily available in a local folder that requires no elevated privileges to access, so an attacker running malware on your system could easily get to it. The passkeys themselves are protected by a master key that only the cloud authenticator can decrypt. While Chrome creates a local hardware-bound device identity key that represents user ownership of the device to the cloud authenticator, Chrome allows itself to request a signature from this key without needing to run with elevated privileges or trigger the device to show a prompt for their PIN or biometrics. An attacker can then forward this signature and take over the targeted account, all silently without needing any user interaction. There is a bit that websites can set to explicitly require user verification, but many don't so they can support as many devices as possible. However, even with the User Verified (UV) flag set, many sites won't properly verify it and let an attacker through anyway, it depends on their implementation. The researchers identified a way to bypass the UV flag even when properly implemented as well. Instead of bypassing it, they simply invalidate the old key and register a new one that they control. Old passkeys can be removed without escalated privileges since there aren't any protections to prevent them being removed. The next time Chrome tries to use a passkey for that account, it will put it in a pending state before properly enforcing user verification. The UV key can be forged since there's no check that it's actually generated from secure hardware, so the attacker can use it from then on to authenticate with high-value accounts. In a third attack, the researchers found that the master key can be obtained allowing them to decrypt all passkeys on the user's device. When you trigger a device onboarding flow, Google simply sends you this master key to decrypt all passkeys. Using this, an attacker can have persistent access to your passkeys from that point on. ### Nearly 1,400 Bitcoin Hacked from Coldcard Wallets URL: https://www.privacyguides.org/news/2026/08/03/nearly-1400-bitcoin-hacked-from-coldcard-wallets/ Last updated: 2026-08-03T01:49:52.000Z In the middle of the night on July 30, $70.2 million worth of Bitcoin were stolen from addresses created by hardware wallet manufacturer Coinkite's Coincard products. A firmware bug weakened the recovery phrases generated by several generations of their devices, allowing an attacker to reconstruct their users' private keys without physical access to the devices. According to an analysis by [Galaxy Research](https://x.com/glxyresearch/status/2083181683067506899), over 1,082 coins were stolen between 1:10 AM and 1:51 AM UTC on July 30 from more than a thousand individual [cryptocurrency](https://www.privacyguides.org/en/advanced/payments/#cryptocurrency) addresses, about 30 hours before Coldcard published its first security advisory to their customers. In the days since, this number has grown to nearly 1,400 Bitcoin, likely as other opportunistic hackers have begun searching for vulnerable wallets. The incident did not involve a weakness in Bitcoin’s cryptography. Instead, a programming error caused affected Coldcard firmware to generate wallet seeds with far less randomness than intended. ## Predictable recovery phrases When a user creates a Bitcoin wallet, the device generates a random seed and converts it into a recovery phrase. That seed is the source of the wallet's private keys. Anyone who discovers it can recreate the wallet and spend its funds. Coldcard was theoretically designed to generate seeds with at least 128 bits of entropy, making it effectively impossible to search every possible seed. The bug occurred when the firmware failed to use the device's hardware random number generator during this process, and used a non-secure software fallback instead. As a result Coinkite, the company behind Coldcard, [says](https://blog.coinkite.com/coldcard-mk3-seed-generation-warning/) affected Mk2 and Mk3 firmware may have produced seeds with only about 40 bits of entropy. Affected Mk4, Mk5, and Q devices may have generated seeds with about 72 bits. With the number of possible seeds dramatically reduced, an attacker could generate candidate recovery phrases, derive their corresponding Bitcoin addresses, and compare them against addresses visible on the public blockchain to check their balances. Eventually, they'd transfer those balances to an attacker-controlled wallet. The attacker did not need the physical wallet, its PIN, access to the owner's computer, or a copy of the recovery phrase. ## Multiple Coldcard generations are affected Coldcard's security advisory states that the Coldcard Mk2, Mk3, Mk4, Mk5, and Q are all impacted. They have released a firmware update which fixes this problem when generating new keys, which they encourage users to install immediately. However, while updating the device should prevent it from creating another weak seed, it does not repair an existing one. Users need to check which firmware was installed when their wallet seed was created, not only which version is installed now. Coinkite claims Tapsigner, Opendime, and Satscard are not affected because they use different codebases. ## What users need to do Coldcard users are urged to immediately transfer their funds to a [cryptocurrency wallet](https://www.privacyguides.org/en/cryptocurrency/) unaffected by this issue, then update their devices to the latest firmware as soon as possible. Do not restore your old, existing seed phrase on an updated Coldcard device or a different hardware or software wallet. The vulnerability partly lies in the seed phrase itself, so reusing that seed preserves the weakness no matter which device it is used on. Wallet owners should expect phishing attempts related to the incident. A firmware update or wallet migration should never require entering a recovery phrase into a website. Users should also verify receiving addresses carefully rather than rushing the transfer. Coldcard allows users to add physical dice rolls while generating a wallet. Coinkite says at least 50 fair, independent, and privately recorded rolls should provide 128 bits of entropy from the dice alone. Anyone who didn't do this, used fewer than 50 rolls, or cannot remember how many they used, should migrate to a new seed as soon as possible. Coinkite has also received [criticism](https://x.com/satochip/status/2083805915384332600) for emailing some affected customers, despite claiming they delete all customer data from their storefront after 90 days in marketing material. They have since [clarified](https://x.com/Coinkite/status/2083923990217626021) that Canadian law requires they keep business records for 8 years. ### CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet URL: https://www.privacyguides.org/news/2026/07/31/cisa-releases-guidance-urging-water-treatment-facilities-to-disconnect-equipment-from-the-internet/ Last updated: 2026-07-31T23:53:49.000Z CISA [released](https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs) an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks. In what [CNN](https://www.cnn.com/2026/07/31/politics/sweeping-cyberattack-us-water-systems) described as "one of the most serious cyberattacks on water systems in the US in years," water treatment facilities in seven US states have been hit with a coordinated wave of attacks suspected to be perpetrated by Iran. The suspected goal of the cyberattacks was "to cause loss of system pressure and subsequent potential contamination of water supply," according to a memo from the Minnesota Bureau of Criminal Apprehension obtained by CNN in the same article. No known instances of water contamination have been reported so far. The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe. Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over. The hackers have been locking out operators by logging in and changing the credentials and IP address of the PLCs. CISA says the threat actors are "targeting water entities of all sizes." They warn that all water and wastewater treatment facilities should check for all external connections, including undocumented cellular modems installed by operators, vendors, or system integrators, since all external connections are a potential risk. The specific advice they give is to disconnect all PLCs and only access them through a VPN, enable password protection and change the default passwords, and only allow IPs from known engineering laptops and other critical assets. What's alarming is that it's apparently so common for water utilities to use no password or default passwords that they could give this advice in a general notice to all water utilities. Potentially the chips that control water for millions of Americans were left with no password accessible on the open internet like an old router or webcam. It seems that many utilities that we rely on every day are simply not equipped to deal with even the most basic cyber threat. Previous cyberattacks like [Volt Typhoon](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a) should have been a lesson that we need to shore up the security of public utilities, but nothing seems to change even as this keeps happening over and over. Perhaps the best course of action is to keep these systems fully offline if they can't be secure managed remotely. ### This Graphene OS Feature Can Get You Arrested URL: https://www.privacyguides.org/livestreams/2026/07/31/this-graphene-os-feature-can-get-you-arrested/ Last updated: 2026-08-07T20:51:40.000Z This Week in Privacy #64 _This post is for subscribers only._ ### New "Dynamic Patching" in Chrome Would Allow Updates Without Restarting URL: https://www.privacyguides.org/news/2026/07/30/new-dynamic-patching-in-chrome-would-allow-updates-without-restarting/ Last updated: 2026-07-30T21:24:28.000Z In a blog [post](https://blog.google/security/chrome-stronger-with-every-update/), Google announced it is working on a system in Chrome to apply updates without needing to restart the browser in order to keep up with a mountain of patches. AI in recent years has become remarkably good at finding bugs in software. In some cases, routinely finding bugs from over a [decade](https://www.privacyguides.org/news/2026/07/08/15-year-old-linux-kernel-vulnerability-allows-full-system-takeover/) ago in older projects like the Linux kernel. In just version 149 and 150 of Chrome, Google fixed 1,072 bugs, more than all 23 prior milestones combined. ![](https://www.privacyguides.org/content/images/2026/07/image-5.png) Source: Google With the deluge of new security vulnerabilities found by AI tools, it's become more important than ever for companies to be able to release patches in a timely manner and get them installed on as many systems as possible. Google has worked toward the first goal by moving to a two-week release cycle instead of the previous four-week release cycle in order to get patches out faster. However, getting those patches installed on people's systems is another issue entirely. Many people find updates annoying and disruptive and refuse to update unless they are absolutely forced to. Google claims to have pioneered the silent, background autoupdates that we're so used to now in many operating systems and other software. But although updates can be downloaded and installed without any user interaction, they still need to wait for you to restart your browser before the update can be applied. They say they're looking into more ways they can find opportunities to restart automatically, for example macOS allowing apps to continue running in the background while all windows are closed allows Chrome to detect this and restart automatically as of version 150. Over the longer term though, they want to leverage Chrome's multi-process architecture to allow different background processes to be restarted individually and have updates applied, without restarted Chrome as a whole and disrupting the user experience. Eventually the vision is to have a browser that is always updated with the latest patches with minimal disruptions. Beyond that, they're continuing investment into memory-safe languages and improving memory safety for older C++ code. It's now more important than ever for companies to eliminate entire classes of vulnerabilities like Rust does with memory safety issues. Relying purely on a reactive approach and playing whack-a-mole with vulnerabilities simply isn't sustainable anymore. ### Pokémon Stores Implementing Facial Recognition to Combat Scalpers URL: https://www.privacyguides.org/news/2026/07/29/pokemon-stores-implementing-facial-recognition-to-combat-scalpers/ Last updated: 2026-07-29T23:42:34.000Z The Pokémon Company [announced](https://www.pcgamer.com/games/card-games/the-pokemon-company-is-turning-to-facial-recognition-scans-to-help-combat-scalpers/) that they've implemented mandatory facial recognition in Japanese Pokémon stores to combat card scalpers. Pokémon in its card form is a collectible card game in which you purchase card packs to build your deck. You don't know what you're getting when you buy a card pack. Because Pokémon cards are so popular right now, scalpers will buy up an entire store's stock and sell them at a marked up price in order to make a profit. More daring individuals resort to stealing them outright for an even greater profit. It's apparently become such a problem that some drastic new privacy-invasive measures are being implemented. The facial recognition system will reportedly enforce a limit of one entry per day for each customer. Those subject to face scans are all adults and even all children down to elementary school age. According to a translation of the [original](https://www.pokemon-card.com/info/004753.html) page by [PC Gamer](https://www.pcgamer.com/games/card-games/the-pokemon-company-is-turning-to-facial-recognition-scans-to-help-combat-scalpers/): > If the system detects that the same person has entered the store more than once in one day or received more than one entry ticket, and a notification (alert) to that effect is displayed on the screen, entry will be denied to that person based on the system's judgement. There's no option to opt-out of the system. The Pokémon Company promises that the data won't be held indefinitely but they seem to be scant on the exact timeline. Previously, the company was caught in a scandal where it was revealed they had been using Pokémon Go camera and GPS data to [train](https://www.privacyguides.org/news/2026/03/20/pokemon-go-players-data-used-to-train-visual-positioning-ai/) AI models which were then used for delivery robots to navigate to their destination. Niantic, the studio behind Pokemon go, even bragged about how much data they were collecting: > Each of those images comes with detailed metadata that pinpoints where in space the phone was at the time it captured the image, including which way the phone was facing, which way up it was, whether or not it was moving, how fast and in which direction, and more. With a track record like that, I would have a hard time trusting their word about the privacy of such a system. While cities have been [cancelling](https://stateofsurveillance.org/news/flock-safety-cancel-wave-30-cities-alpr-surveillance-contracts-2026/) their contracts with surveillance companies like Flock, private companies don't have to answer to the public the same way elected officials do. It's more likely they'll listen to a boycott, since it affects their sales are the most important thing to them. ### Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information URL: https://www.privacyguides.org/news/2026/07/29/over-100-vulnerabilities-found-in-irs-contractor-handling-americans-tax-information/ Last updated: 2026-07-29T01:30:09.000Z The Treasury Inspector General for Tax Administration (TIGTA) [found](https://www.tigta.gov/sites/default/files/reports/2026-07/2026208008%20-%20Management%20Alert%20Memo.pdf) over 100 vulnerabilities in a third-party contractor the IRS was using to digitize tax documents. The TIGTA is an independent government agency responsible for overseeing and auditing the IRS. They looked at two sites at which contractors were using to support the IRS's Zero Paper Initiative (ZPI), a push for the IRS to move all of its paper forms to digital files. The TIGTA found that at these sites, 14 employees had accessed areas where Americans' sensitive tax data was stored 1,375 times in a period of only a few months for each site. Upon speaking with management, they said they only need to review the physical access logs annually, when, in fact, they're required to review these logs monthly to help identify unauthorized employees accessing restricted areas. As to how so many people were able to get inside in the first place, the TIGTA found that the facilities lacked basic physical security measures. The perimeter fence and loading dock at one of the sites was left wide open with no security, allowing anyone to simply walk into the document storage area from outside. No guards were employed to control access to the facility whatsoever. The representatives of the operation said their contract, handling the most sensitive data of Americans, didn't require hiring a guard. The requirements actually *do* require that contractors secure the physical property: > Publication 4812, Contractor Security and Privacy Controls, includes physical security requirements for areas that contain taxpayer information. The physical security requirements include reinforced perimeters, locked buildings, and electronic security systems. Further, when a fence and gate are used to secure the perimeter, the gate should be guarded or locked with an alarm. The TIGT also found their digital security lacking. Over 100 vulnerabilities total were found in their digital systems, presumably the same ones that were scanning and storing the tax documents. There's a required timeframe for contractors to fix vulnerabilities, which the contractors completely ignored and let their outdated systems fester for in some cases over 7 times the allowed timeframe. ![](https://www.privacyguides.org/content/images/2026/07/image-4.png) Source: Treasury Inspector General for Tax Administration Also alarming is that the majority of the vulnerabilities are high and critical. One of the sites also used unauthorized software to scan the tax documents. Despite all the security issues, the ZPI still somehow manages to be behind schedule according to another [report](https://www.tigta.gov/sites/default/files/reports/2026-02/2026408003fr.pdf) by the TIGTA. ### Surveillance Cameras Can Now Be Retrofitted to Track Your Wireless Device Fingerprint URL: https://www.privacyguides.org/news/2026/07/27/surveillance-cameras-can-now-be-retrofitted-to-track-your-wireless-device-fingerprint/ Last updated: 2026-07-27T23:32:52.000Z Flock-style license plate reader vendor Leonardo [announced](https://www.leonardocompany-us.com/lpr/elsag-signaltrace) a new system called SignalTrace that can fingerprint your wireless devices while you drive by and track you around without needing to see your license plate. All wireless devices emit electromagnetic signals in order to communicate. These signals can often be uniquely [fingerprinted](https://arxiv.org/pdf/2506.17439) based on differences in the analog hardware components due to differences in manufacturing between devices. When you travel in your car, your smartphone, your smart watch, wireless headphones, and even your car's infotainment system are usually outputting a constant stream of RF emissions. When all of these individual devices are traveling together, it's likely to be the same person. SignalTrace promises to utilize this data to try and more accurately track people while they drive when the license plate number is not known. ![](https://www.privacyguides.org/content/images/2026/07/image-3.png) Source: Leonardo It can even track RFID devices such as credit cards, something that usually only works at short range. The new devices can be retrofitted onto preexisting license plate reader cameras and are meant to work alongside them, storing your device fingerprint alongside your license plate number in a centralized database that police can access at any time. One of the most terrifying things about this is that it not only identifies your car, but tries to identify individual people inside the car. For example, if two people are riding together, it can detect each person's individual fingerprint separately. This also means these readers can now work even if you don't drive. Simply walking or biking close enough will likely mean your unique RF fingerprint is now stored in some database and your movements can be tracked. Laughably, Leonardo tries to advertise that their system "respects individuals' privacy rights" because the actual data itself isn't decrypted or read. This is definitely an example of metadata being more useful than the content. In a separate [page](https://2464672.hs-sites.com/hubfs/260715-LEO-sellsheet-signal-trace-is-isnot-v3-pick-150dpi-final%5FPage%5F1.jpg?hsCtaAttrib=217760420985) solely dedicated to assuaging fears, they try to argue it doesn't identify people but just electronic signatures. However in their promotional material they claim it can identify suspects by the electronic devices they use, which is a clear contradiction. The fact of the matter is that when all sources of RF on your person are combined, including RFID chips like the ones in your credit cards or even smart card from work, it's unlikely that anyone else will have the same fingerprint as you and that's the entire point. ### Why Are People Mad at Mullvad? URL: https://www.privacyguides.org/livestreams/2026/07/24/why-are-people-mad-at-mullvad/ Last updated: 2026-07-31T18:53:08.000Z This Week in Privacy #63 _This post is for subscribers only._ ### Data Breach Roundup (July 17 - 23, 2026) URL: https://www.privacyguides.org/news/2026/07/24/data-breach-roundup-july-17-23-2026/ Last updated: 2026-07-24T16:00:51.000Z ## Ernst & Young discloses data breach after support system hack EY is one of the four largest auditing and "professional services providers," offering tax, consulting, and transaction advisory services to major companies in more than 150 countries. This breach took place over March and April. It's unclear exactly what data was taken or how many people were impacted, but it includes personal & financial data "contained in or used to prepare tax filings." [Ernst & Young discloses data breach after support system hackErnst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.![](https://www.privacyguides.org/content/images/icon/bleeping-e8912de0-65ed-4016-b584-89ac393fe722.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/ey-71378cd2-2cf3-4ff2-b698-eb1681bc1d97.jpg)](https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/) ## Abbott probes two cyber incidents amid extortion claims Abbott Laboratories is an Americal medical devices & healthcare company that produces pharmaceuticals, diagnostic products, nutritional products, and medical devices. They operate in over 160 countries and are a Fortune 500 company. The first incident involves ShinyHunters and includes more than 30 million rows of customer names, email addresses, phone numbers, physical addresses, dates of birth, and more than one million Social Security numbers from their Cancer Diagnostics business. The second incident involves the ShadowByt3$ threat actor and Abbott's LabCentral customer portal, but only contains corporate data and not any personal or customer data. [Abbott probes two cyber incidents amid extortion claimsAbbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.![](https://www.privacyguides.org/content/images/icon/bleeping-cca76520-71b9-4c9b-ac49-238f08b608e4.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/abbott-logo-7ff62409-024d-42a7-b9e4-09b815e20887.jpg)](https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/) ## Hugging Face confirms breach affected internal datasets and credentials, urges users to take action Hugging Face is a platform that hosts AI models for public use. The company disclosed last week that a dataset that was uploaded abused a security vulnerability that resulted in privilege escalation. The company has urged users to rotate credentials and keys. OpenAI later owned up to the breach and claimed that it was an AI agent that escaped containment. Hugging Face claims to have fixed the vulnerability. [Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunchHugging Face is urging users to rotate any access tokens stored on the platform and review account activity.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-def03afa-3b98-4c10-a802-6370800285cb.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/hugging-face-2219339362-1782b57f-5c72-4d90-b555-affaecc0b1ec.jpg)](https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/) ## Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies Craneware is a UK-based healthcare billing software maker. The company has said that a "percentage" of employee & customer data and partner records had been stolen by the attackers. There is no other information at this time. [Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies | TechCrunchEdinburgh-based tech firm Craneware said customer data was stolen during a cyberattack. The company makes software that thousands of U.S. hospitals, pharmacies, and clinics rely on for billing patients, potentially exposing health data.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-9fdc5b55-0c8c-45fe-8916-ef6d533ac217.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-98618495-dcaca13a-a866-49ce-a1b4-7504a79ba49a.jpg)](https://techcrunch.com/2026/07/20/hackers-stole-significant-amount-of-data-from-tech-firm-relied-on-by-thousands-of-us-hospitals-and-pharmacies/) ## Estée Lauder discloses data breach via Oracle E-Business flaw Cosmetics giant Estée Lauder is notifying employees of a data breach that occurred in August but was only detected last month. Data includes full names, postal address, email address, date of birth, Social Security number, passport number, financial account information including bank account numbers, health information, and employment information including payroll & performance reports. The number impacted was not disclosed. [Estée Lauder discloses data breach via Oracle E-Business flawCosmetics giant Estée Lauder is notifying employees of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.![](https://www.privacyguides.org/content/images/icon/bleeping-53d1752d-3dbf-4cef-bbfe-52b7a24fc879.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/estee-31e56973-8a1e-41be-bf0f-1431811e1c0d.jpg)](https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/) ## AI music generator Suno breach affects 55M users, per Have I Been Pwned A recent article from 404 Media discussed how a Suno source code breach revealed that the company scraped sources like Deezer, Genius, and YouTube to train it's AI models. Among this breach, however, was also a significant amount of user data, including customer names, physic and email addresses, purchases, and partial payment card numbers & expiration dates. The company confirmed this when asked, but has not publicly made a statement or contacted users. [AI music generator Suno breach affects 55M users, per Have I Been Pwned | TechCrunchA hacker took names, phone numbers, and physical addresses of millions of customers who used AI music generator Suno.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-2399872c-26a2-42a1-aede-2128f5b85cf9.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/mikey-shulman-2159558534-70423d25-1e71-4966-a957-7f41d1423277.jpg)](https://techcrunch.com/2026/07/21/ai-music-generator-suno-breach-affects-55m-users-per-have-i-been-pwned/) ## Chick-fil-A discloses data breach after credential stuffing attacks Chick-fil-A is the third largest "quick-service" restaurant in the US and also has a presence in Canada, Puerto Rico, the UK, and Singapore. The breach occurred in June and impacted the website and mobile app. Impacted data includes customer names, email addresses, membership numbers & mobile pay numbers, QR codes, amount of Chick-fil-A credit, and last four digits of card number. In some cases attackers could've also access birth dates, phone numbers, and addresses. [Chick-fil-A discloses data breach after credential stuffing attacksAmerican fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks.![](https://www.privacyguides.org/content/images/icon/bleeping-cfd01c39-c173-4fef-879c-766a413c539f.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Chick-fil-A-sign-bedf4267-01db-42b5-b090-c4bd3836ff42.jpg)](https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/) ## South Korea discloses data breach impacting diplomats worldwide Attackers breached South Koreas National Diplomatic Academy for 10 months and stole the personal data of current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. The incident occurred between April 2025 and February 2026 and impacts at least 6,000 individuals including 360 current government agents abroad. Information leaked includes IDs, names, email addresses, and hashed passwords. The MFA claims that no unique ID numbers, sensitive information, mobile numbers, photos, or home addresses were exposed. [South Korea discloses data breach impacting diplomats worldwideSouth Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats.![](https://www.privacyguides.org/content/images/icon/bleeping-95c0faea-dd81-40c2-9c0c-e04844b7303b.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/korea-c974f201-1cf8-47c0-a25b-c771256e2553.jpg)](https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/) ## Australian energy provider Origin says data breach exposes client data The number impacted is unknown, but the article says that Origin has 4.8 million customers and is Australia's largest energy retailer. Impacted data includes full name, physical address, date of birth, phone number, "account information," last four digits of credit card, and/or last three digits of bank account. [Australian energy provider Origin says data breach exposes client dataOrigin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others.![](https://www.privacyguides.org/content/images/icon/bleeping-57ce3e85-0387-48d5-8a15-4dcd3b690938.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/origin-99400016-deeb-4604-83b1-cad2bc16462b.jpg)](https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/) ### macOS Vulnerability Allows Attackers to Replace Any App With Malicious Code URL: https://www.privacyguides.org/news/2026/07/24/macos-vulnerability-allows-attackers-to-replace-any-app-with-malicious-code/ Last updated: 2026-07-24T00:16:46.000Z Researchers [Talal Haj Bakry](https://x.com/hajbakri) and [Tommy Mysk](https://x.com/tommymysk) [discovered](https://mysk.blog/2026/07/23/macos-overwrite-app-executables/) a vulnerability in macOS that allows an attacker to replace already installed apps with malicious versions that look indistinguishable from the real app. The exploit doesn't require any elevated privileges on the system or even a user password, meaning it can be done without triggering any system prompts that might alert you something is going on. It does require that an attacker already have code execution as the current user as a prerequisite, which could be achieved using another malicious app or script. When the malicious version of the app is run, it will appear to you just as the real app would. When it requests permissions such as access to your files or camera, it will show a real system prompt from the real app, but you'll be granting access to the modified app unknowingly. All versions of macOS 26 are affected, and the researchers say likely earlier versions of macOS are also affected but they haven't confirmed this to be the case. The bug only works for apps installed from the web; macOS App Store apps are not affected. The bug relies on some bizarre behavior when archiving `.app` files using `tar`. Apps are typically signed by the app developers. When it's launched for the first time, Gatekeeper prompts you asking if you want to run the app, and if you do, it completes an initial verification and subsequent launches of the app will be allowed. After this first launch, any attempt to modify the app will be blocked, even with `sudo`. However, if you archive the `.app` file with `tar`, delete the original app bundle, and extract the archive back where it was, you'll be able to launch the app even though it's a different copy of the original app. The contents of the app can be modified freely now without triggering any kind of system permission or password prompt. An attacker from here can alter the app to do whatever they want and when you run it, you'll think you're running the same trusted app you had before. The new app won't retain any keychain access or permissions you had perviously granted the real app, but when the malicious app prompts you for access to those things, it will be a real system prompt that looks exactly like it's from the real app. For example, a fake Signal could be planted request access to the real Signal's keychain, tricking you into giving access to your encryption keys. Mysk says they reported the issue to Apple, but Apple dismissed the report as not requiring a security fix. ### Gemini is Allowing Attackers to Bypass the Android Lock Screen URL: https://www.privacyguides.org/news/2026/07/23/gemini-is-allowing-attackers-to-bypass-the-android-lock-screen/ Last updated: 2026-07-23T01:01:42.000Z [*The Register*](https://www.theregister.com/security/2026/07/17/google-fixing-android-lock-screen-bug-that-lets-gemini-send-sms-without-a-pin/5273027)received multiple reports of people being able to access features such as sending SMS or WhatsApp messages from the lock screen when Gemini is enabled. Gemini is Google's AI assistant that can perform actions inside Android apps on your behalf. One bug that was reported allows an unauthenticated user with physical access to an Android device to perform certain actions on the lock screen such as sending SMS and WhatsApp messages even when Gemini access to those apps was revoked. When Gemini is active on the lock screen, an attacker can attempt to send an SMS from Gemini, at which point it will ask you if you want to open the relevant app with a "Continue" button. If you press continue, you'll be presented with a screen to enter your PIN to unlock the app. However, if you press Gemini's "Add attachment" button down while pressing "Continue" at the same time, it will bypass the PIN and allow you to send an SMS through Gemini. This also opens the door for access to other apps. The attacker can now access other apps which were explicitly disallowed from being accessed by Gemini simply by invoking the relevant prompt. For example, you can access WhatsApp through Gemini by entering "@WhatsApp" in the text window with no PIN needed at all. You can unlock your phone properly and check in the settings, and you'll see that WhatsApp is now connected to Gemini without any authentication. A Google spokesperson told *The Register* thatit is a known bug and a fix is incoming this week, and that the bug is not specific to Pixels. Another Gemini lock screen [bypass](https://infosecwriteups.com/android-lock-screen-bypass-via-google-gemini-the-patch-that-wasnt-5509c5c21630) utilizes the "Deep Research" feature. According to the writeup from the security researcher who discovered it: > An attacker with brief physical access to a locked Android device can without ever entering a PIN, pattern, or biometric switch Google accounts, modify security settings, read and exfiltrate Gemini conversation history, and set up persistent lock screen messaging and calling capabilities. Despite Google claiming to have patched it all the way back in 2024, the researcher says it remains unpatched in 2026 due to the original patch not covering the full breadth of the issue. In general, it's best to keep features accessible in the lock screen to an absolute minimum as anything you enable is more attack surface that could lead an exploit. ### Apple Finally Fixes Hide My Email Vulnerability After a Year URL: https://www.privacyguides.org/news/2026/07/21/apple-finally-fixes-hide-my-email-vulnerability-after-a-year/ Last updated: 2026-07-21T19:32:04.000Z [404 Media](https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/) says Apple has fixed a vulnerability in Hide My Email that would allow anyone to find your real email address after knowing about the issue for over a year. Reportedly, Apple deployed the fix on July 3. Hide My Email is an email aliasing service that Apple offers as part of their [iCloud+](https://www.apple.com/icloud/#compare-plans) cloud storage offerings. For $0.99, iCloud+ users can get the service and have near-unlimited @icloud.com email address aliases, making them unlikely to be blocked since they're using a highly popular email domain and providing an easy way to keep your real email hidden. However, 404 Media [broke](https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/) the story back on July 1 that your real email address that's supposed to be hidden could be discovered by anyone. They didn't reveal the details of the exploit, but Tyler Murphy, co-founder of EasyOptOuts and the security researcher who reported it to them had already reported it to Apple over a year ago, said it still hadn't been fixed yet at the time: > We reported the issue and replication instructions to Apple over a year ago. We don't know why it hasn't been fixed, but we don't feel comfortable waiting any longer. Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses. Apple also was [planning](https://techcrunch.com/2026/06/16/apple-plans-to-change-its-hide-my-email-privacy-feature-that-could-make-it-less-effective/) to change newly-generated Hide My Email addresses to use the domain @private.icloud.com instead of @icloud.com, making them significantly easier for services to block, although as of the writing of this article, newly-generated Hide My Email addresses still use the @icloud.com domain. Now that the issue is fixed, in a statement to 404 Media, Tyler Murphy and Ben Weiner revealed some more details about how the exploit works: > For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected. Apple is [currently](https://www.pcmag.com/news/apple-faces-class-action-lawsuit-over-reported-hide-my-email-vulnerability?ref=404media.co) facing a class-action lawsuit over the reported vulnerability. Apple is being accused of misleading its customers about the privacy of Hide My Email. If you use Hide My Email, you might want to generate new email aliases for the services you use since your real email may have been leaked in logs before the fix was rolled out. ### Malware Stored in SVG Images Used to Hack Developers' Machines URL: https://www.privacyguides.org/news/2026/07/21/malware-stored-in-svg-images-used-to-hack-developers-machines/ Last updated: 2026-07-21T15:01:33.000Z According to [Cyber Security News](https://cybersecuritynews.com/north-korean-hackers-ottercookie-malware/), North Korean hackers are targeting developers with fake job interviews containing malicious code stored in SVG images. The malware is related to the [OTTERCOOKIE](https://any.run/cybersecurity-blog/ottercookie-malware-analysis/) family of malware deployed by North Korean-linked hackers to steal credentials from developers through fake coding challenges designed to look like a job interview. In this particular case, developers respond to a job offer and receive what appears to be an e-commerce project that they're asked to run locally. The campaign reportedly started with job messages in a community Slack channel, where they would directly contact developers and send them a malicious coding assignment to finish. The software seems legitimate with no obvious malicious code. The project contains two SVG images depicting country flags, AE.svg and AF.svg. These images hold the malicious code: inside are HTML comment blocks containing the Base64-encoded payload, allowing the malware to easily slip by inspection by the developers and by malware scanning tools. A JavaScript file called serverValidation.js reads the obfuscated code fragments stored in the SVGs and reconstitutes them into the functioning malware when the project is run. The hidden payload runs automatically when the server boots, and the project functions normally to avoid suspicion. Most wouldn't know anything was wrong. Once the malware is running, it has four parts: a browser credential and crypt wallet stealer, a file stealer, a clipboard collector, and a remote-access component. All of these parts allow it to collect sensitive data and allow the attackers to run commands on the afflicted system. Developers should never run unsolicited programs sent to them, even if the software seems benign and works properly. Cyber Security News says before running coding tests, developers should look at the startup files and assets and check for dynamic code execution such as eval() or code that reads image files. Any machines that ran a suspected project should be isolated and have their browser tokens reviewed and keys and credentials rotated. It's important to remember that being more technically-inclined isn't necessarily a panacea against social engineering, and in fact it can make you even more susceptible to specific types of attacks. Also never assume images or other types of media files are inherently safe; they can contain exploits and malware just like anything else. Make sure you know what you are running and from who before you run it. ### LG Monitors Caught Installing Adware and App With Access to "All System Resources" Without Asking URL: https://www.privacyguides.org/news/2026/07/17/lg-monitors-caught-installing-adware-and-app-with-access-to-all-system-resources-without-asking/ Last updated: 2026-07-17T19:50:53.000Z [Gamers Nexus](https://www.youtube.com/watch?v=Q9uefFYe6bM) tested an LG monitor and found it automatically installs an LG app on a Windows system without asking permission, which has access to "All System Resources" and includes McAfee ads. The app in question, the [LG Monitor App Installer](https://apps.microsoft.com/detail/9pm9n6f47jb8?hl=en-US&gl=US), is available on the Microsoft Store and can access "All system resources" and "Access your internet connection." ![](https://www.privacyguides.org/content/images/2026/07/Screenshot-2026-07-17-at-1.37.32---PM.png) ![](https://www.privacyguides.org/content/images/2026/07/image-2.png) The app installs itself automatically via Windows Update when you plug your monitor into your Windows PC without a single prompt. Once installed, the app will present a popup advertising a 30-day free trial of McAfee, essentially making the LG Monitor app unwanted adware. The app will also constantly popup advertising other "recommended" LG software, although in Gamers Nexus's testing, the McAfee ad was displayed the vast majority of the time. Theoretically, with internet access, the app could change out the ads for other things, or exfiltrate data from your system. The LG Monitor App Installer makes itself a startup application, so it will automatically run when you boot as well. LG seems to have been doing this for [years](https://techcommunity.microsoft.com/discussions/windows11/why-the-lg-monitor-app-installed-without-my-notice/4304003), with forum complaints from users dating all the way back to at least 2024. Unwanted apps coming preinstalled on a system is nothing new. Typically, OEMs make shady deals with the likes of Norton antivirus and other bits of software no one willingly installs in order to have them installed by default on your new system. What's not so typical is an external peripheral device like a monitor automatically installing unwanted programs such as these. In Windows, when you plug in a new devices, Windows Update will [automatically](https://support.microsoft.com/en-US/Windows/Hardware/Drivers/automatically-get-recommended-and-updated-hardware-drivers) install the appropriate drivers so the device can work. Windows Update can also automatically install other software such as the LG Monitor App Installer without asking as well. A reddit user on [r/pcmasterrace](https://www.reddit.com/r/pcmasterrace/comments/1uk7v0v/windows%5Fupdate%5Fsilently%5Finstalled%5Flg%5Fbloatware/#:~:text=To%20disable%20this,associated%20with%20metadata) describes how this "feature" can be disabled in the Group Policy Editor: > To disable this from happening *again*, you can change a local group policy setting: > gpedit.msc -> Computer Configuration -> Administrative Templates -> System -> Device Installation -> Prevent automatic download of applications associated with metadata LG's TVs feature "AI-Based Services" installed by default and hidden in their [Terms of Service](https://www.lg.com/uk/lge-terms/#:~:text=You%20acknowledge%20and,provide%20such%20notification.) is a line stating that you need to inform people in your house that they could be recorded in order to comply with wiretapping laws: > You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws. If anyone does not consent, you should disable the microphone or voice features in the settings. LGE disclaims any liability for your failure to obtain such consent or provide such notification. While this appears to be limited to their TVs for now, computer monitors might not be safe forever. ### Windows 0 Day Exploit Situation Is Wild URL: https://www.privacyguides.org/livestreams/2026/07/17/windows-0-day-exploit-situation-is-wild/ Last updated: 2026-07-24T21:17:21.000Z This Week in Privacy #62 _This post is for subscribers only._ ### Data Breach Roundup (July 10 - 16, 2026) URL: https://www.privacyguides.org/news/2026/07/17/data-breach-roundup-july-10-16-2026/ Last updated: 2026-07-17T15:43:43.000Z ## Lidl discloses online shop breach after service provider hack Lidl is a "discount supermarket" based out of Germany. They are notifying customers in Germany, Belgium, and the Netherlands of a data breach of their online shop. Data included first and last name, telephone number, email address, date of birth, and customer number for an undisclosed number of customers. [Lidl discloses online shop breach after service provider hackGerman discount supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands that attackers stole their personal information in a breach at a service provider.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-8faea1dc-143a-4beb-aa9e-32ddcaefeae7.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/LIDL_headpic-4ab6fd78-a72a-4646-8f00-f0b4f8d65dba.jpg)](https://www.bleepingcomputer.com/news/security/lidl-discloses-online-shop-breach-after-service-provider-hack/) ### California Age Checking Law Walks Back Some of Planned Expansion URL: https://www.privacyguides.org/news/2026/07/16/california-age-checking-law-walks-back-some-of-planned-expansion/ Last updated: 2026-07-16T15:07:33.000Z California [AB 1856](https://legiscan.com/CA/text/AB1856/id/3359485) has had its planned expansion of age checking to browsers and websites removed, leaving just closed-source operating systems on the hook for age checking. AB 1856 is an amendment to the main law, [AB 1043](https://legiscan.com/CA/text/AB1043/id/3269704), which requires operating systems to ask users for their age and then provide an interface for developers to check the age bracket of each user. While thankfully it doesn't require any kind of age verification technology like digital IDs or face scans, it still puts operating system and software developers on the hook if they don't take "internal clear and convincing information otherwise available to the developer that indicates that a user’s age is different than the age bracket data indicated by a signal provided by an operating system provider or a covered application store" into account. This encourages operating system providers to potentially collect more data than just the initial age check, in order to avoid liability in the order of $2500 per child at minimum. When you think about how many children use operating systems and apps, that could add up to a lot of money. This part of the law is at odds with another part requiring operating systems and apps to collect and send the minimum information they can to comply. They will be incentivized to collect other data that could indicate age. Luckily, websites, browsers, and open-source operating systems are exempt from this law. It is strange that websites are exempt when they're so much more easily accessible than apps, however. Small developers are particularly burdened by this law, as they likely won't have the resources to afford good legal representation in the event of a lawsuit. While some parts are concrete, like requiring developers to use the operating system API to check age, other parts are heavily open to interpretation, like what counts as "clear and convincing information" on the age of a user outside of the age signal. Nothing is stopping people from just lying about their age either, and developers are not punished if a user lies about their age. Since the age check can be so easily bypassed, it brings into question what the actual point of the law even is. The EFF points to a much better solution: > Rather than creating age gates, a [well-crafted privacy law](https://www.eff.org/deeplinks/2023/10/your-states-child-safety-law-unconstitutional-try-comprehensive-data-privacy) that empowers all of us—young people and adults alike—to control how our data is collected and used would be a crucial step in the right direction. ### Interview With Cape, a Privacy-Focused Carrier URL: https://www.privacyguides.org/videos/2026/07/16/interview-with-cape-a-privacy-focused-carrier/ Last updated: 2026-07-16T14:30:35.000Z Is it possible to create a private and secure mobile carrier? Cape Mobile thinks so! In this video Jonah sits down with Ruddy Wang, Head of Consumer at Cape to answer questions about the service and to dive into how the privacy & security features work. ### Secure Boot Easily Bypassable Using Decade-Old Vulnerabilities URL: https://www.privacyguides.org/news/2026/07/16/secure-boot-easily-bypassable-using-decade-old-vulnerabilities/ Last updated: 2026-07-16T00:40:18.000Z Researchers at [ESET](https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/) discovered that secure boot on Linux and Windows could be bypassed using decade-old UEFI shim bootloaders still signed by Microsoft. > ESET researchers identified 11 old and forgotten UEFI shim bootloaders at versions 0.9 and below that can be used to bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS). Reported shims can be exploited to execute untrusted code during system boot, enabling attackers to deploy malicious UEFI bootkits (such as [Bootkitty](https://www.welivesecurity.com/en/eset-research/bootkitty-analyzing-first-uefi-bootkit-linux/), [HybridPetya](https://www.welivesecurity.com/en/eset-research/introducing-hybridpetya-petya-notpetya-copycat-uefi-secure-boot-bypass/), or [BlackLotus](https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/)) even on systems with UEFI Secure Boot enabled. Microsoft revoked the vulnerable UEFI applications in their June 9th Patch Tuesday. The researchers say all systems with third-party UEFI signing enabled are affected, so make sure to update. Because the issue resides in UEFI firmware, you'll need to update your firmware. The researchers say Windows should handle this for you automatically and on Linux you can use the [Linux Vendor Firmware Service](https://lvfs.readthedocs.io/en/latest/intro.html) (LVFS). UEFI secure boot works by verifying a UEFI driver or app against two databases of certificates: one of allowed certificates and image hashes and one for revoked ones. For it to execute, the image must be trusted by the allowed database and not present in the revoked database. Most OEMs use a set of default Microsoft certificates so that everything works out-of-the-box. Developers can submit their binaries to Microsoft so that they work with secure boot by default on most devices. Every Linux distribution generates its own bootloader binaries, and submitting them all to Microsoft would be nearly impossible. A shim provides the solution to this problem by being a minimal bootloader that Microsoft can sign once, and that then hands the boot process off to the Linux distribution. The shims authorize secondary boot loaders such as GRUB 2 that then boot the rest of the system. The secondary utilities can be quite outdated and contain their own vulnerabilities though, some of which are quite easy to exploit: > The exploit is simple: there are no memory corruption bugs to trigger, no ROP chains to construct, and no complex reverse engineering required. The single prerequisite is building a custom, unsigned [multiboot2-compliant](https://www.gnu.org/software/grub/manual/multiboot2/multiboot.html) kernel image – in practice, little more than an ELF binary containing the required headers and a handful of other specifics. The outdated shims themselves can have vulnerabilities as well, the Microsoft certificate dates all the way back to 2011 so anything signed by it could be as old as that, and unless it's been explicitly revoked, it'll boot just fine. Old unpatched code tends to have lots of known vulnerabilities to exploit that don't require an attacker to discover new ones. The older 2011 certificates have now expired, however the expiration date actually has no effect on secure boot at all. If the certificate is still in the approved database and hasn't been revoked, then it will still boot as if nothing is wrong. Always make sure to install the latest updates, even in your firmware. ### The Next Version of Meta's AI Glasses Will Activate the Camera Without the Camera Indicator Light URL: https://www.privacyguides.org/news/2026/07/13/the-next-version-of-metas-ai-glasses-will-activate-the-camera-without-the-camera-indicator-light/ Last updated: 2026-07-13T20:35:36.000Z The next model of Meta's smart AI glasses will [reportedly](https://9to5google.com/2026/07/09/meta-smart-glasses-privacy-light-always-on/) activate the onboard camera for AI features without notifying anyone via the camera indicator LED. This comes just days after Meta released an [update](https://9to5google.com/2026/07/07/meta-ray-ban-smart-glasses-privacy-light-camera-update/) addressing people blocking or destroying the camera indicator light to get around it, enabling them to creepily film people without their knowledge or consent. Meta explains how the light works in a press [release](https://about.fb.com/news/2026/07/metas-ai-glasses-your-questions-answered/): > There’s a light on the front of every pair of our AI glasses that we call a capture LED. Whenever content is being captured for your gallery, this white light blinks to let people know you’re capturing content. For a photo, it blinks briefly, while for a video,it continues to blink for as long as you are recording. The capture LED has no off switch. Apparently, some people go to great lengths to try and block the light from working: everything from covering it will tape to destroying it to even offering paid services to try and tamper with it to make it not visible, which Meta tries to combat: > In addition to disabling the camera on devices when tampering is detected, we work across Meta to remove ads, posts, and Marketplace listings that advertise these kinds of tampering services and we will take action, up to banning accounts that do this. We also take legal action against people or businesses that sell services designed for tampering with the capture LED — both on and off our own platforms. Despite so much effort to prevent people from disabling the light, Meta themselves will be disabling the light for their "supersensing" feature, previously reported by [9to5Google](https://9to5google.com/2026/06/01/meta-new-smart-glasses-report/). The feature was planned to use the camera for "extended periods of time" and would allow the AI to constantly analyze your surroundings. Supposedly, Meta wouldn't have access to this data, but they were caught sending people's video recordings off to workers to be annotated for use in AI training. Many laptops wire their camera indicators so that the camera can't be [turned on](https://support.apple.com/en-us/102177#:~:text=The%20camera%20is%20engineered%20so%20that%20it%20can’t%20activate%20without%20the%20camera%20indicator%20light%20also%20turning%20on.%20This%20is%20how%20you%20can%20tell%20if%20your%20camera%20is%20on.) without the light also being turned on. However, if the camera on Meta's glasses can be enabled without the light turning on, it means an attacker could possibly find a way to record without the light turning on as well. With so many people apparently dedicated to defeating the indicator light, it seems ill-advised to give any possible route toward doing that. According to a new report: > \[E\]xecutives are currently planning not to activate the LED when the super-sensing features are being used, according to multiple people familiar with the matter. That would make it harder for bystanders to know when they were being recorded, potentially intensifying the privacy concerns surrounding the technology. Those plans could still change, however, several people said. ### OpenAI's AI Atlas Browser Discontinued After Less Than a Year URL: https://www.privacyguides.org/news/2026/07/11/openais-ai-atlas-browser-discontinued-after-less-than-a-year/ Last updated: 2026-07-11T01:13:28.000Z OpenAI's James Sun announced that their agentic AI browser, Atlas, launched just last October, will be discontinued. > Lastly, with all these updates, we are going to be sunsetting Atlas. > > All these capabilities were built on what we learned from Atlas users who took a leap of faith on a new browser. > > You taught us how agents can help make browsing and doing work on the open web better, and we… > > — James Sun (@JamesZmSun) [July 9, 2026](https://x.com/JamesZmSun/status/2075290224327057644?ref%5Fsrc=twsrc%5Etfw) The Atlas browser was a fork of Chromium, the open-source project behind Chrome, with ChatGPT built in. The headlining feature is agentic browsing, meaning ChatGPT can visit webpages and perform actions on your behalf. Atlas promises on their [website](https://atlasbrowserai.com/#faq) that "all automation happens locally in your browser," but the actual queries to ChatGPT itself are not local. The site boldly touts "End-to-End Encrypted," however what they actually mean is "in transit and at rest," which is called transport encryption not end-to-end encryption. This means that as you tell the AI to browse for you, OpenAI can see the data being sent to them, and it's stored on their servers with a key they have access to. The browser won't even let you use it unless you log in to your OpenAI account. [Vulnerabilities](https://thehackernews.com/2025/10/new-chatgpt-atlas-browser-exploit-lets.html) plagued Atlas for its short lifespan. The cybersecurity research and consulting firm Trail of Bits described how agentic browsers resurface old browser vulnerabilities in a new form: > With browser-embedded AI agents, we’re essentially starting the security journey over again. We exploited a lack of isolation mechanisms in multiple agentic browsers to perform attacks ranging from the dissemination of false information to cross-site data leaks. These attacks, which are functionally similar to cross-site scripting (XSS) and cross-site request forgery (CSRF), resurface decades-old patterns of vulnerabilities that the web security community spent years building effective defenses against. The fundamental security issue with AI is that it can't distinguish between data and instructions. Malicious input could potentially rewrite its instructions at any time. Trail of Bits concluded that significant work needed to be done to isolate and secure agentic browsers. As a replacement for Atlas, OpenAI's new all-encompassing ChatGPT app will include a built-in agentic browser and Codex all in one. The app can autonomously browse the web as well as access your local files and apps. There's also a "[cloud browser](https://help.openai.com/en/articles/20001280-using-cloud-browser-in-chatgpt)" that "runs remotely and handles delegated web tasks," likely meaning that OpenAI will have direct access to the browsing that happens inside. There's also now a Chrome extension if you want to turn Chrome into an agentic ChatGPT browser, and send your browsing data to OpenAI. ### Did Apple Add A Keylogger to the App Store? URL: https://www.privacyguides.org/livestreams/2026/07/10/did-apple-add-a-keylogger-to-the-app-store/ Last updated: 2026-07-24T18:38:36.000Z This Week in Privacy #61 _This post is for subscribers only._ ### Data Breach Roundup (July 3 - 9, 2026) URL: https://www.privacyguides.org/news/2026/07/10/data-breach-roundup-july-3-9-2026/ Last updated: 2026-07-10T17:03:13.000Z ## Accenture confirms breach after hacker offers stolen data for sale Accenture is an IT company with a global reach providing consulting, cloud services, and more. A threat actor known as 888 claims to have stolen 35GB of data containing source code, RSA and SSH keys, Azure tokens, [Accenture confirms breach after hacker offers stolen data for saleIT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-dab2f98f-187f-4f54-a9a9-e18f488f0890.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/Accenture-198ea533-fa6d-478d-bb22-29afd2ff37e6.jpg)](https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/) ## Another massive data breach exposed millions of driver’s license numbers AssuranceAmerica is a provider of car and rental insurance in more than a dozen US states. On March 17, they discovered unauthorized access into their systems and concluded that attackers had stolen names, contact information, and driver's license numbers for almost 7 million customers. They said the attackers also took information about customers’ auto insurance policies and accounts, their drivers and vehicles, and details about customer claims. [Another massive data breach exposed millions of driver’s license numbers | TechCrunchThe cyberattack targeting a U.S. insurance giant is the largest known breach of driver’s license numbers so far in 2026.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-0a659234-f209-420f-8b63-dfc177d898ae.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/drivers-licenses-681253878-5403a45d-6ea1-4426-862d-f161badaae82.jpg)](https://techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/) ## Mount Royal University confirms breach as hackers claim attack Canadian university Mount Royal has confirmed a data breach on June 17\. The attack impacted current and former students. The attackers claim to have 10 TB of data. Little else is known at this time, but the university is promising an update once the investigation is complete. [Mount Royal University confirms breach as hackers claim attackMount Royal University in Calgary says hackers stole and then deleted data from its file storage systems after breaching the university’s network.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-25dbfded-bd06-450a-9e14-f4016c892194.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/MRU-aaf17173-31a4-467f-9b53-061e7ccf5fdf.jpg)](https://www.bleepingcomputer.com/news/security/mount-royal-university-confirms-breach-as-hackers-claim-attack/) ## European cloud provider Nextcloud leaks 367K records, exposing staff and clients Nextcloud is a popular option for privacy enthusiasts to self-host their own complete cloud suite, however they do offer managed services for enterprise customers. It appears that this service was misconfigured and exposed nearly 8 GB - 367,000 files - of customer data. It includes data like invoices, email messages, names, email addresses and much more of clients like IONOS, STRATO, and a German school ministry. ## Telco giant KDDI says data breach affects over 12 million people An update to a story from last week. Last week we said that Japanese ISP KDDI's breach could've impacted up to 14 million people. We now know that 12 million accounts have been impacted, as well as 7.6 million passwords. [Telco giant KDDI says data breach affects over 12 million peopleJapanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-68a9dd5a-adca-4bef-a435-6a37ca66c4c7.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/KDDI--logo-bf940c26-5e8a-4b67-88aa-4eaa2e6ff579.jpg)](https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/) ### Apple Patches App Privacy Issue, Many More Left Unaddressed for Now URL: https://www.privacyguides.org/news/2026/07/10/apple-patches-app-privacy-issue-many-more-left-unaddressed-for-now/ Last updated: 2026-07-10T00:22:39.000Z Apple fixed an app fingerprinting issue in iOS 27 Developer Beta 3, an early preview of the next major version of iOS, making it a bit harder for apps to fingerprint you. > Apparently Apple has fixed the clipboard counter in iOS 27 beta 3 thanks to Loupe. ✌️ > Hey Apple, a little shoutout to the Loupe project would have been nice! [pic.twitter.com/UVByFl9y49](https://t.co/UVByFl9y49) > > — Mysk 🇨🇦🇩🇪 (@mysk\_co) [July 9, 2026](https://x.com/mysk%5Fco/status/2075149886484627557?ref%5Fsrc=twsrc%5Etfw) The issue in question is related to the `changeCount` variable, a value that would increment "when pasteboard items are added, modified, or removed," according to Apple's [documentation](https://developer.apple.com/documentation/uikit/uipasteboard/changecount). This value is visible to all apps and counts up from the time your iPhone was set up, providing a method of fingerprinting a user over time, since the value likely won't change very quickly. ![](https://www.privacyguides.org/content/images/2026/07/image-1.png) Reportedly, as of iOS 27 beta 3, `changeCount` will now be reset to 0 after each reboot, effectively eliminating it as a long-term fingerprinting vector. This is stated in Apple's documentation as well: > When users restart a device, the change count is reset to zero. However, this doesn't reflect the behavior of the current stable version of iOS, iOS 26.5.2, indicating that the behavior of counting up since the iPhone was set up is likely a bug. Mysk, the creators of an app called Loupe which allows you to see the information apps have access to in order to fingerprint you or reveal sensitive information, credit the fix to their app, although there's no official statement from Apple crediting them. While this is great news, the Loupe app reveals many other unaddressed privacy issues in iOS. For example, apps can see the exact date and time, down to the second, that your iPhone's storage volume was created, a value that's likely unique to each iPhone. Apps also have unrestricted access to motion data without any permission prompts presented to the user to accept. This can reveal your movement patterns and it's even been shown that audio can be [recovered](https://www.schneier.com/blog/archives/2022/12/recovering-smartphone-voice-from-the-accelerometer.html) using just motion sensor data. When setting up audio accessories such as AirPods, the default name includes the first name of the Apple account of the person setting them up, so oftentimes they'll be named "Steve's AirPods" or something like that. This means for a lot of people, *any app can see their real first name*. Abusing `canOpenURL`, apps can see what other apps are installed based on whether a URL scheme specific to that app will work. Looking at Apple's [documentation](https://developer.apple.com/documentation/uikit/uiapplication/canopenurl%28%5F:%29), it seems like in iOS 15 they restricted this to a maximum of 50 queries and now in iOS 27 will be restricting it further to a maximum of 25, which is a nice improvement but still won't fully fix the underlying issue. ### 15-Year-Old Linux Kernel Vulnerability Allows Full System Takeover URL: https://www.privacyguides.org/news/2026/07/08/15-year-old-linux-kernel-vulnerability-allows-full-system-takeover/ Last updated: 2026-07-08T22:40:15.000Z Researchers at [Nebula Security](https://nebusec.ai/research/ionstack-part-2/) discovered a privilege escalation bug in the Linux kernel that's been lying dormant for over 15 years that affects every Linux distribution before version 7.1. Dubbed "GhostLock," the vulnerability was originally introduced in Linux 2.6.39 in a [rework](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8161239a8bcc) of `rtmutex` from 2011, over 15 years ago. The bug allows an attacker to gain full root permissions and even break out of containers starting from an unprivileged user. It was [fixed](https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=3bfdc63936dd4773109b7b8c280c0f3b5ae7d349) in April 2026 in Linux version 7.1. Nebula says all Linux distributions before the patch are affected, so make sure to update your system to the latest stable version available from your distribution. The researchers were able to reliably exploit the vulnerability 97% of the time and were awarded $92,337 by Google through kernelCTF. The bug lies in the `remove_waiter()` function. It was written to address the situation where a thread blocks on its own and then cleans up after itself. However, the `rt_mutex_start_proxy_lock()` function used it to clean up a different, sleeping thread. Under the right conditions, `remove_waiter()` will remove the pointer for the currently executing task instead of the waiting task, leaving a dangling pointer to kernel memory that can be exploited to escalate privileges. Effectively, the function was used for a purpose it wasn't originally written for and the assumptions it was originally written with caused the bug. The researchers were also able to bypass [address space layout randomization](https://en.wikipedia.org/wiki/Address%5Fspace%5Flayout%5Frandomization) (ASLR), a security feature meant to protect against memory corruption vulnerabilities, by timing the `prefetch` on a given address. > A `prefetch` on a given address runs in a different number of cycles depending on whether that address is mapped in the current page tables, so an unprivileged process can time `prefetch` across the kernel range and read off which addresses are mapped (the [prefetch paper](https://gruss.cc/files/prefetch.pdf) has the details). > It works here as Linux barely randomizes the base of its default kernel image (\~9 bits of entropy for text base), so a little averaging can recover the KASLR base with near 100% reliability. Likely there are plenty of other similar bugs hiding in the massive Linux codebase. [Google](https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html) estimates that around 76% of vulnerabilities in Android were memory safety vulnerabilities before they began their push for memory-safe languages like Rust, with the number dwindling down to 24% (and that was back in 2024). The Linux kernel could benefit from higher adoption of [Rust](https://rust-for-linux.com) in the kernel. Making use of hardware features such as [MTE](https://developer.android.com/ndk/guides/arm-mte) for ARM chips and the upcoming [ChkTag](https://community.intel.com/t5/Blogs/Tech-Innovation/open-intel/ChkTag-x86-Memory-Safety/post/1721490) for x86 chips will be huge in protecting from memory safety vulnerabilities in the future as well. ### Google and FBI Shut Down Malicious Residential Proxy Network Installed in Millions of Smart Devices URL: https://www.privacyguides.org/news/2026/07/07/google-and-fbi-shut-down-malicious-residential-proxy-network-installed-in-millions-of-smart-devices/ Last updated: 2026-07-07T22:45:06.000Z Google, Lumen, and the FBI have [worked](https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks) in lockstep to disrupt the massive malicious residential proxy network NetNut, also known as Popa, that has its claws in millions of devices. NetNut is "among the largest and most popular residential proxy networks," says Google's Threat Intelligence Group (GTIG), with an estimated 2 million devices across the world afflicted. NetNut's strategy involves distributing SDK's, or software development kits, for common household internet of things (IoT) devices such as smart TVs and streaming boxes. Residential proxy providers such as NetNut operate by selling the ability to route traffic through residential IP addresses owned by internet service providers such as the one you likely buy your home internet access from. These IP addresses are seen as less suspicious than ones owned by datacenters, which users of VPN services might notice when being blocked or presented with excessive CAPTCHAs during normal browsing. But, in order to use real residential IP addresses, they need to run code in people's real home networks. With the rise in cheap IoT devices in recent years, security takes a backseat to cost. Many devices either come pre-installed with malware such as NetNut's proxy service, or users may unwittingly install software with hidden proxy code inside, allowing their home network to be used for cybercrime. It also allows attackers to attack other devices behind your router on the same network as your IoT devices. Google warns that you should be wary of any service offering payment for "unused bandwidth" on your network as these are primary methods that these malicious proxy services spread. You're likely making yourself part of a botnet. In order to protect yourself, make sure all IoT devices such as set top boxes are from reputable manufacturers. Google says you can check the [Android TV website](https://www.android.com/tv/) for the most up-to-date list of official Android TV partners and check if your device is [Play Protect certified](https://support.google.com/googleplay/answer/7165974). There's also something to be said for tech minimalism: does your toaster really need Wi-Fi and Bluetooth or can you get one that doesn't have that? Keeping your smart devices to a minimum is probably the best way to protect yourself against threats such as this. Keeping the devices you do have updated is essential as well, so make sure to enable automatic updates and make sure your devices aren't end-of-life. ### New Phishing Technique Steals Account Tokens Through Legitimate Microsoft Login Page URL: https://www.privacyguides.org/news/2026/07/06/new-phishing-technique-steals-account-tokens-through-legitimate-microsoft-login-page/ Last updated: 2026-07-06T18:36:47.000Z Attackers are exploiting a new phishing technique to get access to your account from a legitimate Microsoft login page, according to [Kaspersky](https://securelist.com/microsoft-device-code-phishing-attack/120350/). Historically, phishing worked by tricking people into visiting fake websites that resembled the real one and had a URL that was close enough that you might not spot it easily, like www.goog1e.com. However, a new strategy is emerging to allow phishing via real login pages, specifically the [Microsoft Identity Platform](https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code). They exploit a protocol called Device Authorization Grant. You might have used it before without realizing; it's what allows you to log in to your accounts on smart TVs, IoT hardware, printers, and other devices that don't support a full keyboard to type your login credentials with. The protocol works by generating a one-time code that you must type in on a separate device like a smartphone in order to grant access to your device. The process starts by opening an app on your device, at which point it detects that no one is logged in and sends a POST request to Microsoft containing the unique identifier for the app and the requested permissions. Microsoft responds with a secret code that is displayed to you and a link for you to visit on your phone or computer. You can usually scan a QR code to visit the link or manually type it out, at which point you'll enter the code displayed on your TV for example. The server then issues an access token to log you in, along with a refresh token to allow it to refresh its account access once the access token expires without any user interaction. Unfortunately this refresh token allows attackers to maintain access to your account for extended periods of time. The phishing campaign started with a malicious PDF sent via an email posing as a legal notice from a law firm. Opening the PDF would present you with several documents which would require you to click a link to open them. The link takes you to a real Microsoft address, but the parameters redirect to a phishing resource. You get redirected from the Microsoft address to a fake law firm page, and then a final page where you're instructed to input a one-time code, which is copied to your clipboard automatically. You're then redirected to Microsoft's actual authentication page where you're prompted to input the code, the same way you would for a smart TV. As soon as the authentication is complete, the attackers are able to read and send emails from the victim's address, exfiltrate files from OneDrive, and access Teams conversations. Phishing attacks like these set a scary precedent and make the advice to "always check the URL" obsolete. The best way to defend yourself is to never paste a code if you didn't initiate the process yourself, especially not a code from random emails. ### CalyxOS Is Officially Back! URL: https://www.privacyguides.org/livestreams/2026/07/03/calyxos-is-officially-back/ Last updated: 2026-07-10T20:46:16.000Z This Week in Privacy #60 _This post is for subscribers only._ ### Data Breach Roundup (June 26 - July 2, 2026) URL: https://www.privacyguides.org/news/2026/07/03/data-breach-roundup-june-26-july-2-2026/ Last updated: 2026-07-03T20:38:56.000Z ## Data breach exposes up to 14.2 million email logins at six ISPs Japanese telco KDDI has disclosed a data breach of their email system which is used by five other internet service providers in the country. The other five were STNet, JCom Co, Chubu Telecommunications, NIFTY, and BIGLOBE. KDDI says that the email addresses and passwords of up to 14.22 million customers may have been exposed. The article says that only "some" of the passwords were hashed, but it's not clear how many or what algorithm was used, or why passwords were being stored in plaintext at all. [Data breach exposes up to 14.2 million email logins at six ISPsJapanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-d26646cf-fdbb-4299-a41e-bc4c8e015fae.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/KDDI-c71d9455-9f89-4fd0-a35a-7e1e202cef8e.jpg)](https://www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/) ## NAIC says public data stolen in ShinyHunters' PeopleSoft breach The National Association of Insurance Commissioners (NAIC) is a US insurance regulatory organization. ShinyHunters claimed to have breached 3.1 TB of data, roughly 105,000 files, including regulatory filing PDFs between 2017 and 2024, customer/order/payment records, credentials for certain production environments, and more. [NAIC says public data stolen in ShinyHunters’ PeopleSoft breachThe National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-b7156597-c977-4add-9938-3470b62d5c49.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/DataLeak-3b54707b-d376-4de0-81ab-401ff8cef60e.jpg)](https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/) ## Nissan discloses employee data breach linked to Oracle zero-day attacks Nissan is saying that this data breach impacted current and former employees in the US, Canada, Mexico, and Brazil. Impacted data could include contact information, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary information. [Nissan discloses employee data breach linked to Oracle zero-day attacksNissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-96a03d43-c0af-4adb-975a-1da9c41ed7d9.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/Nissan-1-de155098-152d-4ea1-869b-8e4c34c970be.jpg)](https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/) ## Blackfield ransomware asks Nidec Corporation for $2 million ransom Nidec is a Japanese manufacturer of electronic components that get used in everything from phones and hard rivets to robotics, elevators, and large HVAC systems. There's not much information at this time on exactly what kind of data was stolen or how many records were impacted. [Blackfield ransomware asks Nidec Corporation for $2 million ransomThe Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-288edec5-631f-45fe-980e-ff89c94c305d.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/nidec-fa927fbc-23f3-4694-8187-1e512252b13f.jpg)](https://www.bleepingcomputer.com/news/security/blackfield-ransomware-asks-nidec-corporation-for-2-million-ransom/) ## Insurance giant Aflac discloses data breach after subsidiary hack Aflac is the largest supplemental insurance company in the US, who apparently also has a presence in Japan. Their Japanese arm has suffered a data breach. Impacted files contain policy and coverage details, personal information, and bank account information. There is no further information on the scope at this time. [Insurance giant Aflac discloses data breach after subsidiary hackAmerican insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary’s systems and stole personal and bank account information.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-4806b319-8fb9-425a-8e18-7da47991ac08.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/0_Aflac-be678077-fcae-44a9-8b56-4387982215f5.jpg)](https://www.bleepingcomputer.com/news/security/insurance-giant-aflac-discloses-data-breach-after-subsidiary-hack/) ## Kubota says hackers had month-long access to network systems Kubota is an industrial manufacturer best known for their heavy equipment used in agriculture and construction. This breach took place between March and April of this year, and may have exposed full names (including dependents), Social Security numbers (including dependents), dates of birth (including dependents), taxpayer IDs, driver's license or other government ID numbers, direct deposit bank account information, corporate payment card information, and benefits enrollment and limited claims data (including dependents). [Kubota says hackers had month-long access to network systemsKubota North America Corporation disclosed that hackers had access to some of its network systems for more than a month earlier this year.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-4e85a0ae-a24b-4c52-815e-852a7466ef16.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/kubota-177604a0-a22b-492a-ae7c-4eb71bf9f2d7.jpg)](https://www.bleepingcomputer.com/news/security/kubota-says-hackers-had-month-long-access-to-network-systems/) ## Medtronic notifies customers impacted by ShinyHunters data breach Medtronic is a medical device company who detected a breach in April. Exposed data included full name, contact information, date of birth, Social Security number, and "health-related information." The attackers claimed to have over 9 million records, which were removed from ShinyHunters' site, suggesting that Medtronic likely paid the ransom. [Medtronic notifies customers impacted by ShinyHunters data breachHealthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-d9d5437c-4016-4d8a-b0d0-3d898d6e6148.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Medtronic-e8b878b3-cb8f-4fac-ad7d-1147cb3c5cdb.jpg)](https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/) ### First Documented Ransomware Attack Ran Exclusively by Agentic AI Discovered URL: https://www.privacyguides.org/news/2026/07/03/first-documented-ransomware-attack-ran-exclusively-by-agentic-ai-discovered/ Last updated: 2026-07-03T20:28:44.000Z The Sysdig Threat Research Team has [discovered](https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion) what they believe to be the first ever ransomware attack carried out fully end-to-end by agentic AI. Dubbed JADEPUFFER, the campaign targeted a [flaw](https://nvd.nist.gov/vuln/detail/CVE-2025-3248) in Langflow, a popular open-source framework for creating LLM applications, that would allow attackers to run arbitrary Python on the host machine. Many instances of Langflow are exposed on the open internet and their credentials are often stored in their environment, making them an attractive entry point. > The most striking characteristic, however, was the LLM's behavior. JADEPUFFER's own payloads were self-narrating. They contained natural language reasoning, target prioritization, and the kind of detailed annotations that human operators don’t often write but LLM-generated code produces reflexively. The operation also adapted in real time, retrying failed steps within refined parameters. In one sequence, it went from a failed login to a working fix in 31 seconds. After the Langflow instance was compromised, it moved to the true target: separate production servers containing SQL databases. The AI would encrypt the MySQL database and generate a ransom note containing the demand, a Bitcoin payment address, and a Proton Mail account to contact. Then, the AI would begin deleting data, escalating as it went and rationalizing its decisions the whole time. The researchers note that the speed at which the LLM handled failures indicated automation, with the attacker able to assess the failures and remediate within seconds. Further, the actions weren't merely an automated script, but required understanding and diagnosing the problem to create a specific solution on the fly. The LLM gave a Bitcoin address that was an example address used commonly in developer documentation, meaning it's possible it hallucinated the wrong address in its ransom note. It's also possible however that the attackers configured it with a real address that happens to be the same as the one used in documentation, the researchers say they have no way to know for sure. > **Ransomware is no longer a craft for the highly skilled:** An LLM agent can chain reconnaissance, credential theft, lateral movement, persistence, and destruction without the operator possessing deep expertise in any one step. Tradecraft that once implied a capable human now implies a capable model. This attack sets a scary precedent; with the skill ceiling for ransomware attacks now so low, we could start seeing massive operations of LLMs scanning all over the internet for vulnerable machines to extort for profit, without a human having to do much at all. Particularly it will be important to keep your software patched with the latest security updates, since these models rely on known vulnerabilities for now. ### Brave Adds Containers to Separate Your Browsing URL: https://www.privacyguides.org/news/2026/07/03/brave-adds-containers-to-separate-your-browsing/ Last updated: 2026-07-03T00:55:54.000Z Brave has [released](https://brave.com/blog/containers/) a new containers feature to allow you to isolate your browsing between different identities. The feature is comparable to the Multi-Account Containers feature in Firefox, although that requires an additional extension while Brave Containers are built-in. Brave already isolates different sites from each other via [storage partitioning](https://brave.com/privacy-updates/14-partitioning-network-state/#brave-already-partitions-cookies-aggressively), but with containers, you can be logged in to different accounts on the same site without having to switch browser profiles. It can also help you organize your browsing around specific activities i.e. work, shopping, general browsing, etc. To use containers, go to the Settings under Content and click Enable Containers. If your browser doesn't have that option yet, you can click the hamburger menu at the top right, click Help, click About Brave, and check that you have the latest version installed. If you've been using different browser profiles in Brave to separate your online identities while browsing, containers are a much smoother user experience and let you combine tabs from multiple containers together in the same window. When you need to open a link in a specific container, you can right-click and open new tabs in a specific container. You should color-code them so you can easily tell them apart and don't accidentally "cross the streams." You can also open [temporary containers](https://support.brave.app/hc/en-us/articles/39077103885325-How-do-I-use-Containers-in-Brave#h%5F01KWASJSY7SSM4BXN0NY3X2AY6) that will delete itself once all tabs inside it are closed, clearing all browsing data, sort of like a private browsing mode that you can intersperse with your other tabs. Be aware that some data is shared between containers, specifically - Extensions - Autofill information including credit card details - Settings, Shields, site settings, permissions - Passwords - History The shared information is part of the benefit of containers: you don't have to set up your browser again for every new identity you make. A similar feature also exists in Safari via [Profiles](https://support.apple.com/en-us/105100),. It's bizarre that Firefox requires an extension to use this feature, even though it came out years ago. These are the only three browsers I know of that support this feature. If you tend to always run your browser in private browsing mode, it might be time to give containers a try so you don't have to log in to your accounts over and over again. Just make sure you decide what accounts belong to which identities. ### Google Wants to Scan Your Hand for its reCAPTCHA URL: https://www.privacyguides.org/news/2026/07/01/google-wants-to-scan-your-hand-for-its-recaptcha/ Last updated: 2026-07-01T16:13:16.000Z [Google's](https://docs.cloud.google.com/recaptcha/docs/hand-gesture-verification) reCAPTCHA service will start asking for camera permission to scan your hand in different positions to determine if you're human. CAPTCHAs are a common annoyance among internet users, interrupting your browsing with a picture puzzle seemingly designed to be as obnoxious as possible. They're also bad for privacy, making heavy use of fingerprinting to try and weed out bots. Now, reCAPTCHA is going to be taking fingerprinting more literally by asking you to provide camera access and [scan](https://docs.cloud.google.com/recaptcha/docs/hand-gesture-verification) your hand doing various gestures. > Google analyzes one or more videos of a user's hand as they perform various actions or gestures. The video is processed to extract hand landmark data, which includes [21 hand-knuckle coordinates](https://ai.google.dev/edge/mediapipe/solutions/vision/hand%5Flandmarker). Providing camera access opens the door to all sorts of abuses. Any data the camera sees, from your face to sensitive documents or information on a screen, could be sent off and stored by Google. The documentation makes no mention of on-device processing, although they try to assure you that they handle the videos with care: > Google does not retain any images or videos of a user's hand gestures beyond the verification process or use the data for any other purpose. Videos or images are automatically deleted after the challenge is complete. > The information Google collects is used and stored in accordance with the [Google Privacy Policy](https://policies.google.com/privacy). Unfortunately, you have to fully trust Google that they're deleting the videos, there's no way for you to verify their claims. They also claim not to collect audio but providing camera access in most operating systems also provides audio recording at the same time. There has been [research](https://www.sciencedirect.com/org/science/article/pii/S1546221824004284) into using hand gestures as a form of biometric authentication with a 99% accuracy rating for identifying individuals, raising concerns that Google could identify you individually from your hand gestures. This comes after Google's attempt to make reCAPTCHA [require](https://cybernews.com/privacy/google-qr-code-recaptcha-requires-approved-phone/) a phone app to also grant your camera permission and scan a QR code in order to access websites. For some reason, the old-style CAPTCHAs are still available for people who aren't able to complete the hand gesture, calling into question what the entire point is if it can just be bypassed anyway. The need for privacy-preserving bot detection is at an all-time high with AI agents running amuck all over the internet. Solutions like [Private Access Control Tokens](https://hacks.mozilla.org/2026/06/pact-anonymous-credentials-for-the-web/), which don't require any access to sensitive permissions or sending any fingerprinting or other data, have been proposed by browser vendors. ### Multiple Vulnerabilities Found in Apple AirDrop and Android Quick Share URL: https://www.privacyguides.org/news/2026/07/01/multiple-vulnerabilities-found-in-apple-airdrop-and-android-quick-share/ Last updated: 2026-07-01T00:40:24.000Z [Researchers](https://arxiv.org/pdf/2606.26967) have discovered six vulnerabilities across Apple's AirDrop and Android's Quick Share file sharing protocols, some of which are zero-clicks. AirDrop is a proprietary protocol that allows Apple devices to send files to each other over a local ad hoc wireless connection, avoiding the need to send files to a server first which can slow down the transfer process and requires internet access. Quick Share is Android's answer to AirDrop, allowing the same functionality and even supporting cross-platform transfers with Apple devices on certain models of [Google Pixels](https://blog.google/security/android-quick-share-support-for-airdrop-security/). The first zero-click in AirDrop is a Denial of Service (DoS) attack stemming from a `fatalError` when an enum value doesn't match a specific value. This means any request with an unrecognized URI and a non-empty body will trigger it. An attacker can continually send these and repeatedly crash AirDrop without any interaction on your end. "One short request takes down AirDrop, AirPlay, Handoff, Universal Clipboard, and Continuity Camera at once," said [*Help Net Security*](https://www.helpnetsecurity.com/2026/06/30/apple-airdrop-google-samsung-quick-share-vulnerabilities/)describing the attack. The second zero-day in AirDrop is a stack overflow due to nested `` elements in an XML document. After around 200 nested `` elements, it attempts to write to an unmapped part of memory, raising a memory write fault that crashes the process, although "no useful register or memory write primitive is exposed." The third vulnerability happens when a specially crafted HTTP request causes a null pointer dereference, causing yet another crash. This one could affect any part of the system that processes HTTP requests although the researchers state it may be more difficult outside of AirDrop and related services. The researchers also analyzed Samsung's Quick Share implementation and found two fairly serious vulnerabilities. The first is a pre-authentication bypass that lets attackers establish a connection with the phone and allowing it to process content without any authentication or establishing an encrypted session. When combined with the previous vulnerability, the next one allows an attacker to bypass the encryption and "inject unencrypted control frames into an active Quick Share session." Finally, the Windows Quick Share client suffers a critical memory corruption bug when two connections with the same endpoint identifiers and nonce values arrive at once. Ironically, the developers acknowledged the bug in a comment in the code but their fix implemented the same memory corruption bug again. The researchers reported all vulnerabilities to the respective companies. Apple acknowledged them and is reportedly working on a fix. Samsung determined the bugs were in Google's code and so transferred the responsibility to Google to fix. Google acknowledged all of the Quick Share bugs and awarded the researchers a bug bounty, but no fixes are out yet. ### Fake GTA 6 Crypto Scams Drain Wallets and Install Malware URL: https://www.privacyguides.org/news/2026/06/30/fake-gta-v6crypto-scams-drain-wallets-and-install-malware/ Last updated: 2026-06-30T02:38:20.000Z Fake GTA 6 "early access" sites promise access to the game if you pay hundreds in cryptocurrency, but offer only malware instead. Scammers and hackers have taken advantage of the hype around the upcoming Grand Theft Auto 6 and created convincing fake websites using AI to mimic Rockstar Games' official art. [Malwarebytes](https://www.malwarebytes.com/blog/threat-intel/2026/06/gta-6-early-access-is-nothing-but-a-scam) described it as the "perfect bait" because of just how highly anticipated the game is. ![](https://www.privacyguides.org/content/images/2026/06/gta6-fake-site-3-SD.jpeg) Source: [Malwarebytes](https://www.malwarebytes.com/blog/threat-intel/2026/06/gta-6-early-access-is-nothing-but-a-scam) They will ask for a payment in Bitcoin for "VIP Digital Access" or access to a beta build of the game. It's important to note there is no public beta for GTA 6. Once you've sent the money, there's no recourse; cryptocurrency transactions can't be reversed. Once the money is sent, it's gone. In many cases, there will be a page with a large "DOWNLOAD" button which might install [potentially unwanted applications](https://support.microsoft.com/en-US/security/protect-your-pc-from-potentially-unwanted-applications) or in some cases malware. [NordVPN](https://nordvpn.com/blog/gta-malware-and-scams/) has identified several malware campaigns targeting Windows and Android users. Malicious actors will create convincing clones of well-known piracy and repacking sites to serve malware disguised as GTA 6 to target Windows users. The malware looks like a legitimate game launcher, but when Setup.exe is launched, it abuses dynamic link library (DLL) side loading to load a malicious DLL file. From there, the trojan can modify device memory, download additional malware, and connect to external servers to exfiltrate data off your computer. Another example is a fake GTA 6 APK titled "GTA 6 Mobile." In reality, the app is just an empty Unity project with a fake "Download OBB" link that, when clicked, takes you to a domain that's documented as having a history of serving info stealer malware, trojans, adware, and ransomware. Fake Rockstar Social Club login screens designed to phish your account login details have also been spotted, promising exclusive content and offers for the game. Once you enter your details, they will be sold on the dark web. These sites also tend to distribute malware as well. To stay safe from scams and malware, it's recommended to always stick to official sources for game downloads. Rockstar's [official site](https://www.rockstargames.com) is where you can get any updates about the real game. Avoid piracy and repacking websites as they're common vectors for malware. And, of course, always install the latest security updates for your operating system. ### Framingham, MA Flock Contract Cancelled After Public Backlash URL: https://www.privacyguides.org/news/2026/06/27/framingham-ma-flock-contract-cancelled-after-public-backlash/ Last updated: 2026-06-27T02:04:51.000Z Framingham, MA has [cancelled](https://www.boston.com/news/local-news/2026/06/25/framingham-police-will-not-renew-flock-safety-contract-after-months-of-resident-opposition/) its contract for Flock Safety cameras after months of extensive public backlash due to privacy and civil liberties concerns. Framingham is just the latest in a [list](https://stateofsurveillance.org/news/flock-safety-cancel-wave-30-cities-alpr-surveillance-contracts-2026/) of over 30 cities that have cancelled their contracts, citing similar reasons. Framingham Police Department Administrative Lt. Rachel Mickens told Boston.com "We will continue to balance technology and public safety needs with transparency, accountability, and the privacy concerns of the community." The Flock system will be shut off on June 30\. The city and Flock will coordinate to remove the cameras. Mayor Charlie Sisitsky told Boston.com in the same article "There is no evidence of inappropriate access or sharing of data." This directly contradicts the previous behavior of Flock and police officers relying on their cameras. The cameras work by scanning license plates of cars in order to track down stolen vehicles or ones whose owner is suspected of a crime. Rather than being localized to a specific city, though, there have been multiple cases of Flock cameras used to track someone down that's nowhere near the city, like one case where a Texas cop [searched](https://www.404media.co/a-texas-cop-searched-license-plate-cameras-nationwide-for-a-woman-who-got-an-abortion/) nationwide for a woman who got an abortion, abusing his access to 83,000 cameras all over the U.S. The cameras often mess up and the wrong person gets arrested, like what happened to a man who was [arrested](https://arstechnica.com/tech-policy/2026/06/man-jailed-for-a-month-despite-flock-showing-he-was-5-miles-from-crime-scene/) and thrown in jail for a month even though later it was proven he was 5 miles away at the time. As the Flock network has grown, false positives like this have gotten more common, and the police often fail to do the minimum amount of police work it would take to verify the innocence of these people. Officers also often abuse their access to the national Flock Safety camera network to [stalk](https://ij.org/police-have-reportedly-used-license-plate-readers-to-stalk-romantic-interests-at-least-14-times-in-recent-years/) their exes, not even in relation to a crime. Flock have even outright lied to cities and installed cameras without [permission](https://www.cambridgema.gov/news/2025/12/statementontheflocksafetyalprcontracttermination). The cameras have been shown to have incredibly [lackluster](https://www.youtube.com/watch?v=uB0gr7Fh6lY) security as well. They were shown to run Android 8, an OS from 2017, and had exposed USB ports for hackers to attach a malicious USB device to and take them over. They can also be tricked into connecting to a malicious Wi-Fi network and have their credentials captured since they're sent in plaintext. Hackers could easily be using these cameras as their own personal spy network and likely no one would know. Clearly, the public outcry against Flock is working. Hopefully more cities will cancel their contracts, every bit helps. ### No News is Good News? Q&A Episode URL: https://www.privacyguides.org/livestreams/2026/06/26/no-news-is-good-news-q-a-episode/ Last updated: 2026-07-10T20:45:40.000Z This Week in Privacy #59 _This post is for subscribers only._ ### Data Breach Roundup (June 19-25) URL: https://www.privacyguides.org/news/2026/06/26/data-breach-roundup-june-19-25/ Last updated: 2026-06-26T19:17:43.000Z ## Klue hack results in data breach at several cybersecurity firms An update to a story from last week: "marketing intelligence provider" Klue suffered a data breach that allowed attackers to steal data from the company's customers, such as HackerOne, OneTrust, Jamf, and many more. The stolen data appears to primarily be Salesforce databases and similar formats, including data like names, email addresses, phone numbers, job titles, and some account information of their customers, according to the various affected companies. It's worth noting that Klue's announcement of the incident included a `noindex` tag to prevent it from showing up in search engines. [Klue hack results in data breach at several cybersecurity firms | TechCrunchHuntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-7e3f8818-b4af-450c-9245-cfc7c945ad64.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/data-breach-2024-roundup-027f3d95-f7ea-4c3d-8a76-f336ff531b05.jpg)](https://techcrunch.com/2026/06/22/klue-hack-results-in-data-breach-at-several-cybersecurity-firms/) ## LastPass confirms data breach in Klue supply chain attack LastPass is one of the first companies to admit to falling victim downstream to the Klue breach. Exposed data included customer names, phone numbers, mail addresses, physical addresses, support case information, and sales/CRM-related data. It's unclear how many individuals or records were impacted. [LastPass confirms data breach in Klue supply chain attackLastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company’s OAuth tokens in the Klue supply chain attack earlier this month.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-3a2e665c-cded-4c77-9043-700834791219.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/lastpass-14af4e47-66d0-4c9c-aa20-af053bb0dc88.jpg)](https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/) ## Healthtech firm Xolis suffers data breach impacting 1.4 million people Xolis is a US-based company "that develops AI-powered software used by more than 600 hospitals and health insurers for utilization management, medical necessity reviews, patient status determinations, discharge planning, and reimbursement decisions." This breach was the result of a phishing attack in January and impacted names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information. [Healthtech firm Xolis suffers data breach impacting 1.4 million peopleHealthcare technology company Xsolis says that sensitive data belonging to nearly 1.4 million individuals was compromised in a phishing attack that gave attackers access to its network.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-7f22b213-bcfa-471f-896a-94452c1c342f.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Xsolis-5ee71d19-a69d-45e5-a859-ba9a343b9618.jpg)](https://www.bleepingcomputer.com/news/security/healthtech-firm-xolis-suffers-data-breach-impacting-14-million-people/) ## Meta's Keystroke-Logging Employee AI Training Program on Pause After Internal Data Leak A few weeks ago, Meta announced what was effectively a keylogger on all employee's work computers to help better train AI with tasks like general navigation of a desktop environment. Predictably with Meta's comically long list of data breaches in their past, this has resulted in an internal leak exposing keystrokes, private conversations, and transcripts. [Meta’s Keystroke-Logging Employee AI Training Program on Pause After Internal Data LeakAccording to Business Insider, n internal program at Meta to train AI on employees’ data is on pause after an internal leak exposing keystrokes, private conversations, and transcriptions.![](https://www.privacyguides.org/content/images/icon/pg-yellow-2-183a02f8-dc88-44a3-9f20-40b5d8017e10.png)Privacy GuidesFria Reyes![](https://www.privacyguides.org/content/images/thumbnail/photo-1665799871677-f1fd17338b43-08374cae-841b-4b36-842d-418233bf83c9)](https://www.privacyguides.org/news/2026/06/23/metas-keystroke-logging-employee-ai-training-program-on-pause-after-internal-data-leak/) ## Polymarket says hackers stole users’ funds Gambling app Polymarket has fallen victim to a supply chain attack in which a third-party breach impacted their users. The incident was the result of a phishing campaign and caused about $3 million in cryptocurrency losses. Polymarket says it is reimbursing impacted users. [Polymarket says hackers stole users’ funds | TechCrunchThe prediction market giant Polymarket said it’s refunding users who had funds stolen due to a third-party breach.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-92fd19a1-45c9-410a-a33c-ebeb077ca825.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/polymarket-logo-people-852f10ad-299e-4423-9d5f-a4f0104ce1ab.jpg)](https://techcrunch.com/2026/06/25/polymarket-says-hackers-stole-users-funds/) ## Nearly a million passports just exposed on the public internet—and anyone could access them with a simple URL This appears to be a collection of exposed databases from around Europe. It was discovered by The Verge and remained online for months before being taken down. It's unclear if anyone malicious accessed the documents during this window, but we always advocate for assuming the worst in these cases. [Nearly a million passports just exposed on the public internet—and anyone could access them with a simple URLNearly one million passports and driver’s licenses from multiple countries were left unprotected online with zero password protection. Here’s what happened.![](https://www.privacyguides.org/content/images/icon/CA-Fav-300x300-082d3461-dfd8-484d-9a89-3823cc0ad3b2.png)CA Privacy WatchRivo Raphaël Chreçant![](https://www.privacyguides.org/content/images/thumbnail/passports-driver-licenses-exposed-public-internet-2026-7a1dcab2-fba3-4f49-bf53-99f54ecad992.jpg)](https://cambridgeanalytica.org/data-breaches-scandals/passports-driver-licenses-exposed-public-internet-2026-51096/) ### DOJ Stopped From Requiring Apple and Google to Hand Over the Data of 100,000 People URL: https://www.privacyguides.org/news/2026/06/26/doj-stopped-from-requiring-apple-and-google-to-hand-over-the-data-of-100-000-people/ Last updated: 2026-06-26T00:13:10.000Z A court has [determined](https://www.forbes.com/sites/the-wiretap/2026/06/23/court-stops-doj-from-forcing-apple-google-to-hand-over-100000-peoples-information/) that the US DOJ cannot force Apple and Google to hand over the information of around 100,000 users of the EZ Lynk app. The DOJ had [previously](https://www.privacyguides.org/news/2026/05/27/the-us-doj-wants-identities-and-addresses-of-over-100-000-users-of-a-car-app/) tried to force Apple, Google, Amazon, and Walmart to hand over the data of every user who downloaded the EZ Lynk app or purchased an EZ Lynk device, which could include addresses, names, financial information, and plenty of other identifying information. The DOJ, along with the EPA, is accusing EZ Lynk of selling so-called "defeat devices," or devices designed to bypass emissions controls inside vehicles. EZ Lynk disputes this claim. The devices they sell, along with their [mobile app](https://www.ezlynk.com/app.html), allow users to scan their onboard diagnostics system (OBD) and tune certain settings in the vehicle. The request was described as "nearly unprecedented" by [*Inside EPA*](https://insideepa.com/share/255042)who originally reported on it, with the only similar example being a request for the data of people who purchased [gun scope software](https://www.forbes.com/sites/thomasbrewster/2019/09/06/exclusive-feds-demand-apple-and-google-hand-over-names-of-10000-users-of-a-gun-scope-app/) (albeit significantly less than 100,000 people). EZ Lynk's lawyers described the data as being of "low marginal utility" because investigating whether EZ Lynk sells a defeat device "does not require identifying each person who has used the product." The US government had even previously requested that EZ Lynk create a backdoor in their product in 2019 to allow "government monitoring of unsuspecting users," a request which EZ Lynk refused. Since Apple and Google's stores require an account to use, many users have their real names, emails, phone number, and other personal data tied to the apps they download. This creates a privacy issue that many people likely don't consider, and it means that if the government wants to demand information about what apps you download from these stores, Apple and Google are capable of providing it. In this case, the request was blocked and Apple and Google won't be providing the personally-identifiable information of 100,000 users. But this doesn't mean that every EZ Lynk user is safe; if anyone's personal data turns up in communications with the company, their data may not be protected. Hopefully these types of broad, sweeping demands for data of innocent people don't become a theme with the DOJ in future cases, especially since this time it failed. But it's a stark reminder to be careful about what data you give out, even in seemingly innocent activities like app downloads. ### Meta's Keystroke-Logging Employee AI Training Program on Pause After Internal Data Leak URL: https://www.privacyguides.org/news/2026/06/23/metas-keystroke-logging-employee-ai-training-program-on-pause-after-internal-data-leak/ Last updated: 2026-06-23T21:31:26.000Z According to Business Insider, an internal program at Meta to train AI on employees' data is on [pause](https://www.businessinsider.com/meta-ai-training-data-leak-exposed-employee-activity-across-company-2026-6?op=1) after an internal leak exposing keystrokes, private conversations, and transcriptions. The program, called Model Capability Initiative (MCI), had caused internal backlash from employees after it was originally [announced](https://www.businessinsider.com/meta-new-ai-tool-tracks-staff-activity-sparks-concern-2026-4) back in April. At the time, Meta CTO Andrew Bosworth told employees "there is no option to opt out of this on your work provided laptop." The program essentially amounts to a [keylogger](https://www.microsoft.com/en-us/security/business/security-101/what-is-keylogger), which are, as Microsoft puts it, "a serious risk to personal and organizational security, silently recording keystrokes to steal sensitive information." In this case that's exactly what happened. Turns out, when you install a keylogger on all your employees' machines, it's a data breach waiting to happen. A Meta spokesperson [told](https://www.businessinsider.com/meta-ai-training-data-leak-exposed-employee-activity-across-company-2026-6?op=1#:~:text=We%20have%20carefully%20designed%20this%20program%20with%20privacy%20safeguards%2C%20and%20while%20we%20have%20no%20indication%20at%20this%20time%20that%20any%20data%20was%20improperly%20accessed%20by%20Meta%20employees%2C%20we're%20pausing%20it%20while%20we%20investigate) Business Insider "we have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we're pausing it while we investigate." If there were proper privacy safeguards in place you have to wonder how it was even possible for it to be improperly accessed in the first place. This incident isn't Meta's first brush with data leaks due to AI. Recently, their AI support chatbot was used by hackers to [take over](https://www.privacyguides.org/news/2026/06/04/metas-ai-support-agent-used-by-hackers-to-take-over-instagram-accounts/) Instagram accounts. Their smart glasses were found to be sending sensitive recordings including "bank details, sex and naked people" to outsourced workers. In March, an AI agent went [rogue](https://www.theinformation.com/articles/inside-meta-rogue-ai-agent-triggers-security-alert) and exposed sensitive information and caused a severity level 1 event inside Meta, the second highest level (the highest is 0). This incident rates an SEV 2. Whatever "privacy safeguards" they have in place clearly aren't enough. Using your employees as guinea pigs to harvest data from is not only immoral but makes incidents like this one inevitable. A company with the resources of Meta should be able to figure out a way to train its models without the ridiculous data collection. More advanced systems for training AI exist, such as [federated learning](https://cloud.google.com/discover/what-is-federated-learning), which runs a model locally on your machine and then sends what it learns off to the larger whole, preserving your privacy. Unfortunately, [workplace surveillance](https://www.bbc.com/worklife/article/20230127-how-worker-surveillance-is-backfiring-on-employers) is so normalized now that incidents like this don't seem all that unusual. Security incidents due to invasive surveillance software will continue unless there is a bigger effort to preserve the privacy of employees. ### It's Time to Ditch Plex Media Server... URL: https://www.privacyguides.org/videos/2026/06/23/its-time-to-ditch-plex-media-server-video/ Last updated: 2026-06-25T21:34:38.000Z Plex just announced they are raising the price of their lifetime Plex Pass from $250 to a whopping $750\. If you don’t want to be forced into a perpetual subscription model or or spend $750 US dollars, it’s time to look at a great free, open-source, and privacy-respecting alternative: Jellyfin. In this video, we'll explain in detail how to get setup with Jellyfin if you've never had a home media server, guide you through the setup process, how to add media and finally whether you should allow remote access. #### Sources 0:03 0:27 0:34 0:50 1:12 1:35 1:45 1:46 1:48 2:30 3:01 3:27 3:55 4:33 5:07 5:28 5:35 6:08 6:21 8:10 8:47 9:00 9:30 9:35 10:57 11:15 ### Kansas City Pushes for Facial Recognition on Public Buses URL: https://www.privacyguides.org/news/2026/06/23/kansas-city-pushes-for-facial-recognition-on-public-buses/ Last updated: 2026-06-23T00:00:13.000Z Kansas City, Missouri is [gearing](https://apnews.com/article/kansas-city-facial-recognition-ai-cameras-privacy-87847f57c94b6c2a9e22a7b3a222e703) up to equip public buses with facial recognition cameras designed to detect if a rider is on a list of banned or missing people. There's been a huge push across the U.S. for surveillance cameras to be installed all over the place, the most famous being the Flock cameras that have been shown time and again to be [highly insecure](https://www.privacyguides.org/news/2025/11/17/ben-jordan-exposes-severe-security-vulnerabilities-in-flock-surveillance-cameras/) and repeatedly get [innocent people arrested](https://timesofsandiego.com/crime/2026/06/07/a-flock-license-plate-reader-linked-a-san-diego-man-to-a-violent-crime-he-was-five-miles-away/). There's an equally huge pushback from the public, with many cities [canceling](https://stateofsurveillance.org/news/flock-safety-cancel-wave-30-cities-alpr-surveillance-contracts-2026/) their contracts with Flock. Putting facial recognition cameras in public transportation that many people need to use to get around seems particularly diabolical though. It would allow SafeSpace, the company running these particular surveillance cameras, to track everywhere someone goes throughout their day. SafeSpace Global previously used their facial recognition cameras to track if nursing home residents left the building, and then moved to prisons and schools. This perfectly follows what Cory Doctorow calls the "[Shitty Technology Adoption Curve](https://pluralistic.net/2022/08/21/great-taylors-ghost/?ref=a.wholelottanothing.org)," with the most marginalized members of society getting it first before it rolls out to everyone else. SafeSpace claims that if no match is detected, the facial recognition data won't be retained. However, as we saw with Flock which had images from all the way back in the factory stored on it, claims are not always reality. Even if what they claim is true, in all likelihood the security of these cameras is not the best. If hackers have half as easy a time infiltrating these as they did with Flock cameras, your facial recognition data is essentially forfeit. The facial recognition in these systems is still extremely flawed as well. False arrests have run rampant from day one of facial recognition tech being used and it still continues to this day. Grandmas getting [falsely arrested](https://www.privacyguides.org/news/2026/04/01/grandma-wrongly-arrested-due-to-facial-recognition-software-finally-released-after-months-in-jail/) because cops blindly trust facial recognition is not acceptable. The project has been delayed due to the need to upgrade the onboard routers to support the new cameras, and because state funding fell through. Tyler Means, chief mobility and strategy officer at the Kansas City Transportation Authority, says that despite the delays, the program will launch this year and be significantly expanded to 30 buses instead of the originally planned 9. Boruff, the CEO of SafeSpace Global, says that they're ready to install the cameras as soon as funding comes through. The process should take around 3-4 months. ### Android 17 has arrived on GrapheneOS! (Sort Of) URL: https://www.privacyguides.org/livestreams/2026/06/19/android-17-has-arrived-on-grapheneos-sort-of/ Last updated: 2026-07-02T01:42:20.000Z This Week in Privacy #58 _This post is for subscribers only._ ### Connectivity Standards Alliance Releases Matter 1.6 and Product Security 1.1 Specifications URL: https://www.privacyguides.org/news/2026/06/19/connectivity-standards-alliance-releases-matter-1-6-and-product-security-1-1-specifications/ Last updated: 2026-06-19T21:03:18.000Z The [Connectivity Standards Alliance](https://csa-iot.org) (CSA), creators of the Matter, Zigbee, and Aliro standards for IoT devices, released their new [Matter 1.6](https://csa-iot.org/newsroom/matter-1-6-enables-more-intuitive-setup-multi-ecosystem-experiences-and-context-driven-control/) and [Product Security 1.1](https://csa-iot.org/newsroom/product-security-1-1-the-next-level-of-iot-trust/) specifications for securing smart homes. Matter is an open standard for IoT devices to be able to operate on a local network and communicate with each other. Open standards such as Matter are important for privacy because they allow IoT devices to interoperate with each other without the need to connect to the wider internet. Matter 1.6 adds the ability to set up devices over NFC before they're even powered on. This means, for example, a lightbulb can be set up by NFC before it's screwed in. This was a bit of a pain point before, where the QR code to set up the lightbulb would often be obscured once it was screwed into the socket. There's now an enhanced multi-admin feature called Joint Fabric which allows "multiple user-authorized controllers to co-administer a single shared Matter network." The CSA says this is suited to environments where multiple users need access to the same devices such as "new construction handovers, households running multiple platforms, or professionally managed properties." Thermostat Suggestions is a new feature that allows thermostats to evaluate commands from other devices based on user preferences. Before, they would just act directly on commands without any context. For example, if you set your thermostat to prioritize energy savings, it can prevent an automation from another device from overriding those settings. Matter 1.6 enhances the already-existing support for Certificate Revocation Lists (CRLs) to allow for smaller, independently updated chunks rather than a single huge list, improving the scalability of the certificate infrastructure as the number of certified devices grows. The CSA's [Product Security 1.1 specification](https://csa-iot.org/wp-content/uploads/2026/06/23-80986-022-PSWG1.1-Specification-16-June-2026-Approved.pdf) has also been released with updated security requirements for devices looking to get certified. The goal with the Product Security spec is to unified all the disparate international cybersecurity standards to make it easier for manufacturers to show they meet a baseline level of security in their products. New in 1.1 is two levels of security assessments: Level 1 is a "supplier self-assessment reviewed by an [Authorized Test Laboratory](https://csa-iot.org/certification/testing-providers/) (ATL)" while Level 2 "requires an independent assessment and functional testing conducted by an ATL." Part of the requirements for the certification include requirements to use unique passwords for each device, anti-brute forcing mechanisms, not embedding critical security parameters in the source code, using Best Practice Cryptography, support for erasing user data, removing unused interfaces i.e. testing interfaces, input validation, removing unused functionality, recommendations to perform a secure boot process, automatic software updates, verification of update integrity, and using isolated processing. ### Data Breach Roundup (June 12 - 18, 2026) URL: https://www.privacyguides.org/news/2026/06/19/data-breach-roundup-june-12-18-2026/ Last updated: 2026-06-19T18:39:02.000Z ## Pharma giant Novo Nordisk discloses breach of clinical trials data Novo Nordisk is a Danish pharmaceutical company, best known as the maker of the recent GLP-1 receptor agonist drugs Wegovy and Ozempic. At this time we don't know when the breach occurred or how many people were impacted, but we do know it impacted data related to patients in certain clinical trials including patient IDs (random alphanumeric strings) and information on trial participation, sex, year of birth, biomarkers, health/immunogenicity data, and lifestyle factors (e.g., smoking, alcohol use, BMI). It also affected healthcare professionals (HCPs), whose names, registration numbers, e-mail addresses, phone numbers, WhatsApp details, and office locations have been exposed. The group is [asking](https://www.reuters.com/legal/government/hacking-group-claims-major-hack-novo-nordisk-attempted-25-million-extortion-2026-06-16/) for a $25 million ransom. [Pharma giant Novo Nordisk discloses breach of clinical trials dataDanish pharmaceutical giant Novo Nordisk, the world’s largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-6fb4964f-96eb-47c3-b4eb-961d275329fd.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Novo_Nordisk-2a1ac104-e5df-48f2-82ec-ea1f0f3e8d21.jpg)](https://www.bleepingcomputer.com/news/security/pharmaceutical-giant-novo-nordisk-discloses-security-breach/) ## iRhythm discloses data breach, says hackers stole patient info iRhythm is a digital healthcare company that supports a popular cardiac monitoring service. The company hasn't revealed much, including number of patients impacted or exactly what data was stolen. They said the attacker demanded a ransom after data was stolen from a "third-party-hosted business application," and that the data in question included "proprietary data, patient protected health information and other personal information." The breach occurred earlier this month. [iRhythm discloses data breach, says hackers stole patient infoDigital healthcare company iRhythm Holdings has disclosed a data breach after hackers stole patients’ personal and health information stored on third-party-hosted business applications.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-f15d3d4c-52d4-4d94-a063-4e22be88756b.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/iRhythm-e2ccefa7-e044-4d48-a68b-27238712fb13.jpg)](https://www.bleepingcomputer.com/news/security/irhythm-discloses-data-breach-says-hackers-stole-patient-info/) ## Hackers Publish Knicks and Madison Square Garden Data Online The ShinyHunters ransomware group has posted nearly 45GB of data on the New York Nicks and the venue Madison Square Garden. A sample reviewed by 404 Media includes files mentioning specific sports teams, and specifically Knicks-related personalities, with fields such as “address,” “claim to fame,” “cost of talent,” and sometimes contact information for them or their representatives. [Hackers Publish Knicks and Madison Square Garden Data OnlineThe data contains a list of “talent,” including former Knicks players and coaches, and whether other celebrities are considered “Low Risk” or “High Risk.” The data also contains emails between customers and MSG.![](https://www.privacyguides.org/content/images/icon/favicon-3-dd43c862-f90d-4fee-9c4d-b7d7d9b669a0.svg)404 MediaJoseph Cox![](https://www.privacyguides.org/content/images/thumbnail/Copy-of-Screenshot-as-Lede-Image-27-1f92733f-ff63-4c88-8240-4115518ebda7.png)](https://www.404media.co/hackers-publish-knicks-and-madison-square-garden-data-online/) ## Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ Society Dialog is a private, invitation-only organization cofounded in 2006 by Peter Thiel. It convenes US officials, foreign government figures, and Silicon Valley executives at off-the-record annual retreats. Swiss "hactivist" maia arson crimew said the exposed directory was revealed to them by way of anonymous tip. The list includes 222 names along with information about their attendance and talks. The article goes into a lot of detail. [Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ SocietyMore than 200 of the world’s elites registered for a retreat whose agenda runs from panels on cult-building and sex to prepping for World War III. An associated app offers matchmaking.![](https://www.privacyguides.org/content/images/icon/favicon-d2be8db7-6394-46f4-906a-f428e5b94b7a.ico)WIREDDell Cameron and Yulia Almazova![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-2152107576-4e7c4238-97df-4e01-962e-6fc19ef99406.jpg)](https://www.wired.com/story/leak-exposes-members-of-peter-thiels-secretive-dialog-society/) ## Kodak confirms data breach claimed by ShinyHunters extortion gang As is becoming a pattern, there is very little information at this time. This was the result of a ShinyHunters breach, which claims to have "over 2.2 million records containing customer personally identifiable information (PII) and internal corporate data." [Kodak confirms data breach claimed by ShinyHunters extortion gangKodak has confirmed that it’s working with external cybersecurity experts to investigate a security breach after hackers gained access to some of the company’s data.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-c031d729-c81c-415c-a521-cb43be735056.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Kodak_headpic-aec52f81-4017-4b90-a6f3-10041c1f89c3.jpg)](https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/) ## FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. This incident is making headlines in the tech space. This breach includes usernames, email addresses, and plaintext passwords that appear to be valid credentials for companies including Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and many others. This appears to be a crime group getting ready for a larger operation, and includes credentials gathered from a wide range of techniques and sources. [FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.A newly discovered data leak dubbed “FortiBleed” has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-e6d6dda7-45a9-40e4-b39a-191f311cad59.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/Fortinet-023d0d4c-4b41-4340-9781-1f2cc417c61a.jpg)](https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/) ## Infinite Campus data breach affects 137,000 school staff accounts Infinite Campus is an EdTech company that provides student information systems to thousands of schools in 46 US states. This breach took place in March and this update includes the name of the attackers, and more information about the scope. Impacted data includes names, email addresses, employers, job titles, phone numbers, physical addresses, usernames, and support tickets. [Infinite Campus data breach affects 137,000 school staff accountsThe ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-1ce39eb7-6e9f-46ca-b225-e324e1332c9e.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/School_hacker-26b0e59e-794e-4f3e-a81e-398fc11ff597.jpg)](https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/) ## Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks Klue is a "marketing intelligence platform." The wording of this article seems to suggest that a Klue compromise impacted several of Klue's users and put their data at risk, primarily OAuth tokens. This threat actor appears to be new on the scene, having first been spotted in April 2026. [Klue OAuth breach linked to ‘Icarus’ Salesforce data theft attacksMarket intelligence platform Klue suffered a OAuth breach that enabled the “Icarus” threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-30b99df3-cf11-4bd7-a72d-81e52d76c607.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/data-theft-6462e811-eae8-4e89-9b1d-da85b198d11f.jpeg)](https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/) ## Council of Europe investigates ShinyHunters data breach claims Over the weekend ShinyHunters claimed to have stolen more than 429,000 documents containing HR and payroll data from multiple Council of Europe departments. The allegedly stolen documents include more than 409,000 payslips for 10,000+ staff (ranging from 2011 to 2026), over 3,700 in-house personnel files, more than 14,000 CVs, and other files. They are said to contain a wide range of personal and financial information, including affected individuals' names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, tax and Social Security information, medical records, and more. [Council of Europe investigates ShinyHunters data breach claimsThe Council of Europe, the continent’s oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-7db325a2-aaab-4c16-a18a-daed6c6b0741.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Council-of--Europe-904bbddc-7656-43c8-91a8-0c2c5e94074b.jpg)](https://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/) ## Texas government data breach allowed hackers to steal 3 million driver’s licenses and passports This breach came through the state's Parks & Wildlife department who issues hunting and fishing licenses. Thus attackers were able to access the driver's license information and passport numbers of more than 3 million people. [Texas government data breach allowed hackers to steal 3 million driver’s licenses and passports | TechCrunchA data breach involving government-issued ID documents affects over three million people in Texas.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-f21af9d6-d08b-4c09-b944-5e2907b0c944.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/passport-fake-KYC-f3ac303c-755b-40c9-9e2f-0c28d54c7048.jpg)](https://techcrunch.com/2026/06/18/texas-government-data-breach-allowed-hackers-to-steal-3-million-drivers-licenses-and-passports/) ## Nintendo confirms data stolen in WebMD subsidiary cyberattack TinyPulse is an employee engagement and feedback platform used for anonymous employee surveys, engagement analytics, feedback collection, and workplace culture assessments. A threat actor called Shaowby3$ claims they have stolen nearly 1GB of data containing full names, email addresses, analytics and survey data, bank statements, and W-9 forms with employee IDs, progress plans, and reports between 2016 and 2026. [Nintendo confirms data stolen in WebMD subsidiary cyberattackNintendo of America has confirmed to BleepingComputer that threat actors stole survey data from the third-party TinyPulse service used internally, but its systems were not compromised.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-085d15bb-5abb-4fac-89a2-dd13a2b8d038.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Nintendo-ac14d577-724b-49cb-8a34-b7e99cc4c62b.jpg)](https://www.bleepingcomputer.com/news/security/nintendo-confirms-data-stolen-in-webmd-subsidiary-cyberattack/) ### Unpatchable Exploit Found Apple's A12 and A13 Chips URL: https://www.privacyguides.org/news/2026/06/19/unpatchable-exploit-found-apples-a12-and-a13-chips/ Last updated: 2026-06-19T01:03:57.000Z Researchers at Paradigm Shift [discovered](https://ps.tc/pages/blog-usbliter8.html) a new unpatchable vulnerability, dubbed "usbliter8," in Apple's A12, S4/S5, and A13 chips. The exploit targets the [Boot ROM](https://support.apple.com/guide/security/boot-process-secac71d5623/1/web/1), a piece of code that's immutable by design so that no one can alter it, even Apple. It's the first piece of code that runs during the boot process so it's security-critical. While they don't mention other devices than iPhones, multiple devices share the same chip. The A12 is used in the iPhone XR, iPhone XS/XS Max, iPad Air 3, iPad mini 5, iPad 8, and the second-generation Apple TV 4K. The S4 chip is used in the Apple Watch Series 4, and the S5 is used in the Apple Watch Series 5, first-generation Apple Watch SE, and the HomePad mini. The A13 is used in the 9th-generation iPad, iPhone 11/Pro/Pro Max, the second-generation iPhone SE, and the Studio Display. Of these devices, the iPad Air 3, iPad mini 5, iPad 8, second-generation Apple TV 4K, HomePod mini, iPad 9, iPhone 11's, and Studio Display are still supported by the latest operating system. They claim that support for A12X/Z chips is also possible but they didn't implement it. This would raise the affected devices to include several iPad Pro models. If you use one of these devices, moving to a newer device is the only way to mitigate this vulnerability. The bug targets the USB controller. The chip has a buffer that accepts three Setup packets before writing them out. The USB specification says that these Setup packets must be exactly 8 bytes, so when all three are moved out of the buffer, the controller tries to reset back to its starting position but subtracting 24 bytes. However, the controller accepts smaller packets than 8 bytes, meaning that when it subtracts 24, it goes past the starting point and creates a buffer underflow. The researchers say they believe the flaw is inherent to the controller. It doesn't work on A11 chips because the driver manually resets the address back to the starting position after each packet. On A12 and A13, USB Device Address Resolution Table (DART) is configured in bypass mode, allowing attackers to overwrite SRAM data. A14 and later fix this issue. The researchers state that the A12 chip was easier to exploit because A13 has more mitigations: > Several mitigations had to be bypassed along the way. These include heap metadata checksums, which are verified during heap operations, and LR signing during context switches, which occur whenever the USB task is woken up to process USB packets. The exploit isn't able to touch the [Secure Enclave](https://support.apple.com/en-in/guide/security/sec59b0b31ff/web), which has its own security boundary between it and the rest of the device. But the researchers say this exploit opens up new attack vectors to attack it. ### Linux Removes Support for Legacy AppleTalk Protocol in Response to AI Patches URL: https://www.privacyguides.org/news/2026/06/18/linux-removes-support-for-legacy-appletalk-protocol-in-response-to-ai-patches/ Last updated: 2026-06-18T01:33:14.000Z A surge of AI-generated patches in the Linux kernel has resulted in the [removal](https://www.phoronix.com/news/Linux-Drops-AppleTalk) of support for older protocols, the latest of which being AppleTalk. With the availability of AI tools, open source projects that accept outside patches have been dealing with a surge of reports, creating a lot of work for maintainers. Maintainers of open source projects such as [curl](https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/) have been speaking out about the deluge of "AI slop" bug reports. While organizations such as [Mozilla](https://blog.mozilla.org/en/firefox/ai-security-zero-day-vulnerabilities/) have been able to make use of AI tools for finding and fixing bugs, in amateur hands, they can hallucinate and produce bogus bug reports and patches. The Linux kernel has been suffering just such a problem. Part of their strategy to reduce the load on developers has recently been to [remove](https://www.phoronix.com/news/Linux-7.1-PR-Remove-Old-Net) support for older drivers and other code in order to reduce the attack surface and reduce the burden on developers. Jakub Kicinski said in a pull request to remove some obsolete code: > Old code like amateur radio and NFC have long been a burden to core networking developers. syzbot loves to find bugs in BKL-era code, and noobs try to fix them. > Paolo says we spend \~40% of our time checking LLM outputs, sounds about right. He goes on to describe the code as "basically unused." Apparently, there had been multiple previous attempts to remove the code but someone wanted the code to stick around. > We've talked about these deletions multiple times in the past and every time someone wanted the code to stay. It is never very clear to me how many of those people actually use the code vs are just nostalgic to see it go. The removed code includes HAM radio support and some old legacy ATM protocols and drivers, among other things. The now-[merged](https://www.phoronix.com/news/Linux-7.1-Removes-Old-Net) pull request equates to 138,161 lines of code removed. Now, AppleTalk is on the chopping block in another [pull request](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8a398a0c189ead8bbce98f5be70b8ea0e30b21f8) from Jakub Kicinski. AppleTalk was introduced all the way back in [1985](https://en.wikipedia.org/wiki/AppleTalk), and has since been discontinued by Apple in 2009, leaving it as a prime candidate for removal. > AppleTalk has been removed in MacOS X 10.6 (Snow Leopard), in 2009, according to Wikipedia. We recently got a burst of AI generated fixes to this protocol which nobody is reviewing. > Let AppleTalk follow AX.25 and hamradio out of the Linux tree. We we \[sic\] will maintain the code at: github.com/linux-netdev/mod-orphan for anyone interested in playing with it. This PR adds up to a few thousand more lines of code. It's interesting to see how different projects adapt to the "LLM-pocalypse," removing support for ancient protocols seems like a smart move on multiple fronts. ### Android 17 Launched, What New Privacy/Security Features Does it Bring? URL: https://www.privacyguides.org/news/2026/06/17/android-17-launched-what-new-privacy-security-features-does-it-bring/ Last updated: 2026-06-17T02:33:23.000Z Android 17 has now [officially](https://android-developers.googleblog.com/2026/06/Android-17.html) launched, bringing with it a slew of new privacy and security upgrades like the new Contact Picker and post-quantum app signing. The update has started to ship in Google Pixels and will be rolled out slowly over time. New in Android 17 is the system Contact Picker, which allows you to grant apps access to only a specific subset of your contacts. This is similar to a feature launched in [iOS 18](https://lifehacker.com/tech/you-can-control-which-contacts-apps-can-access-in-ios-18?test%5Fuuid=zXnWOLjQQwkYjMVwrvo5w&test%5Fvariant=A) allowing you to select specific contacts on a per-app basis. The Local Network permission that shipped in Android 16 was opt-in for developers, but now in Android 17 it's required in order to access your local network. Loopback traffic is now [blocked](https://developer.android.com/about/versions/17/behavior-changes-all#block-cross-profile-loopback) between profiles by default as well. According to [Android Authority](https://www.androidauthority.com/android-17-3561251/#androidadvancedprotectionmodenewsafeguards), the Advanced Protection Mode, similar to iOS Lockdown Mode that restricts certain features for security, is getting a few new security enhancements. These include: - Blocking accessibility service for apps that aren't accessibility apps - Disabling device-to-device unlocking - Disabling [WebGPU](https://webgpu.org) in Chrome - Spam detection for chat notifications - And support for Android Enterprise for managed devices Even if apps are granted SMS permission, they will not have access to [SMS OTP](https://developer.android.com/about/versions/17/behavior-changes-all#sms-otp-all-apps) codes, protecting you from a malicious app stealing your account 2FA login details. Android 17 also [enabled](https://developer.android.com/about/versions/17/behavior-changes-17#ech-by-default) Encrypted Client Hello (ECH) by default. ECH is a TLS extension that encrypts the Server Name Indication in the TLS handshake, something that shows what website you're visiting in regular TLS. Your passwords will now be [fully hidden](https://developer.android.com/about/versions/17/behavior-changes-17#hide-pwd-kbd) by default when typing using a physical input device like a keyboard. Google will now be [enabling](https://blog.google/security/whats-new-in-android-security-privacy-2026/#:~:text=These%20features%20will%20now%20be%20enabled%20by%20default%20on%20all%20new%20Android%2017) Theft Protection by default on Android 17 devices to help protect your data against thieves. They've also reduced the number of allowed failed PIN attempts and increased the time in between attempts. You can now grant apps temporary precise location access while they are open, which is revoked when they're closed. Android 17 now support hybrid post-quantum cryptography for app signing, to protect against the future threat of quantum computers. Google views this as the "first phase" in their transition to PQC, which you an read about [here](https://blog.google/security/security-for-the-quantum-era-implementing-post-quantum-cryptography-in-android/). They're also hardening the background audio framework to ensure that apps playing audio in the background don't make changes to the audio that aren't intended by the user. There's many more changes as well, you can read about them in the official [list](https://developer.android.com/about/versions/17/summary) of changes. ### WhatsApp Claims it Thwarted an NSO Spyware Campaign URL: https://www.privacyguides.org/news/2026/06/14/whatsapp-claims-it-thwarted-an-nso-spyware-campaign/ Last updated: 2026-06-14T00:03:28.000Z WhatsApp [claims](https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/) they detected and stopped an NSO spyware campaign against its users. NSO Group is an infamous Israeli spyware company that sells to oppressive governments to use against the most people in society. They are behind the Pegasus spyware that made global headlines back in 2021 and even to this day, with "world leaders, politicians, human rights defenders (HRDs), and journalists" targeted by it, according to [Amnesty International](https://www.amnesty.org/en/documents/doc10/4491/2021/en/). The type of state-backed spyware that NSO Group specialize relies on [zero-day exploits](https://www.ibm.com/think/topics/zero-day) in software; that is, exploits that the developer of the software isn't aware of yet. Because of the security improvements that modern operating systems, especially iOS and Android, have made, typically you need a chain of these exploits to work together to compromise a device. The combination of these factors makes anything that can compromise an iPhone or Android phone quite valuable, and once they're used, they might be discovered by the software vendors and patched. Hence why they're typically only sold to governments with near-unlimited budgets and used in highly targeted attacks against individuals. > We successfully disrupted NSO-linked social engineering attempts, after investigating user reports. They tried to trick people into clicking on malicious links to drive them to external websites outside of WhatsApp, similar to previously [reported](https://www.accessnow.org/publication/between-a-hack-and-a-hard-place-how-pegasus-spyware-crushes-civic-space-in-jordan/) 1-click phishing campaigns linked to NSO. We also caught them creating test accounts and groups on WhatsApp, which we took down. WhatsApp had [previously](https://faq.whatsapp.com/1831251587214580) prevented an attack from NSO in 2019. WhatsApp has taken a particular stance against NSO Group, winning a "landmark [verdict](https://about.fb.com/news/2025/05/winning-the-fight-against-spyware-merchant-nso/)" against the spyware vendor, barring them from using it against WhatsApp users ever again. This attack constitutes a blatant violation of this ruling and as such, WhatsApp is asking the courts to hold them accountable. Ultimately, though, malicious actors like NSO Group operate outside the law and the only way to truly protect against them is for software vendors to improve the security of their apps. Apple has done work in iMessage such as [BlastDoor](https://support.apple.com/guide/security/blastdoor-for-messages-and-ids-secd3c881cee/web) and [Lockdown Mode](https://support.apple.com/en-us/105120) to make attacks more difficult. Signal takes advantage of operating system-provided features like Apple's [Memory Integrity Enforcement](https://security.apple.com/blog/memory-integrity-enforcement/). WhatsApp itself has worked toward improving security in the app by adding a memory-safe, hardened media [library](https://engineering.fb.com/2026/01/27/security/rust-at-scale-security-whatsapp/) to protect against malicious media files and a lockdown mode-style feature called [Strict Account Settings](https://blog.whatsapp.com/whatsapps-latest-privacy-protection-strict-account-settings) that will enforce secure settings on your account. These are all good steps but we need greater adoption of memory-safe languages and sandboxing to protect against state-backed malware. ### Around 1,500 AUR Packages Compromised with "Rootkit-Like" Malware URL: https://www.privacyguides.org/news/2026/06/12/around-1-500-aur-packages-compromised-with-rootkit-like-malware/ Last updated: 2026-06-12T21:10:44.000Z Researchers at Sonatype [uncovered](https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency) a massive supply chain attack against the Arch User Repository (AUR) to harvest credentials and exfiltrate user data by hijacking around 1,500 packages. The attack, dubbed "Atomic Arch" by the researchers, is one of the largest attacks against the AUR of all time. The [AUR](https://wiki.archlinux.org/title/Arch%5FUser%5FRepository) is a collection of unofficial packages made by the Arch Linux community. There's even a warning on the Arch wiki that packages have not been fully vetted and you use the packages at your own risk. The campaign targeted packages that have been abandoned by their maintainers for one reason or another. The attackers are abusing the process for community members to request ownership of orphaned packages. > In the Atomic Arch campaign, attackers appear to be exploiting this process to gain stewardship of trusted packages already used by the community. Attackers adopt orphaned AUR packages. The package keeps its existing name, history, and user trust, but control of its build instructions changes hands. Cleverly, the attackers didn't modify the actual packages themselves, but instead modified the packages' build instructions, thus bypassing traditional methods of detecting malware. Instead, they modify the packages' PKGBUILD to add a post-install script that installs a malicious npm package called atomic-lockfile. The researchers found that the package was hiding its activity to make it harder to identify, which includes looking through your directories and making network connections, including specific references to SSH keys, browser cookie databases, and data stores for spells like Discord, Slack, and Telegram. These indicators strongly suggest credential stealing and data exfiltration. The method of compromise is quite sneaky since users will just assume a new update is available for a trusted package and install it without thinking. The attackers essentially hijack the trust built up over the years by package maintainers and bypass the need to convince users to install something new. > Attackers are not building trust from scratch. They're acquiring projects that have already earned it. That dramatically reduces the warning signs developers normally rely on when evaluating software. 2026 has seen a staggering number of supply chain attacks, normally attacking the [CI/CD](https://www.sonatype.com/blog/axios-compromise-on-npm-introduces-hidden-malicious-package) infrastructure of developers. This attack leveraging a widely-used community repository highlights the risks involved in unofficial packages. Hopefully, Arch can harden the process for adopting orphaned packages to perhaps require more vetting. ### License Plate Readers Are Framing Innocent People URL: https://www.privacyguides.org/livestreams/2026/06/12/license-plate-readers-are-framing-innocent-people/ Last updated: 2026-06-23T01:41:41.000Z This Week in Privacy #57 _This post is for subscribers only._ ### You're Creating Passwords Wrong - Here's Why URL: https://www.privacyguides.org/videos/2026/06/12/youre-creating-passwords-wrong-heres-why/ Last updated: 2026-06-12T16:36:30.000Z Most people don't know how to create a secure password and often reuse them across websites, in this video we explain the best practices. _This post is for paying subscribers only._ ### Data Breach Roundup (June 5 - 11, 2026) URL: https://www.privacyguides.org/news/2026/06/12/data-breach-roundup-june-5-11-2026/ Last updated: 2026-06-12T16:24:31.000Z ## Former cyber executive turned whistleblower accuses IBM of covering up several data breaches The lawsuit in question was filed in 2020 but only unsealed this week. It comes from the former IBM vice president of threat intelligence who alleges that Chinese hackers breached IBM and at least two subsidiaries "routinely" between 2013 and 2016 but the company simply covered up the breaches and never disclosed them. Including this story because past law enforcement raids on [ransomware gangs](https://www.bleepingcomputer.com/news/security/how-the-fbi-seized-blackcat-alphv-ransomwares-servers/) have proven that often companies get breached and never publicly disclose it. [Former cyber executive turned whistleblower accuses IBM of covering up several data breaches | TechCrunchIBM and two of its subsidiary companies were allegedly breached during the mid-2010s — a lawsuit filed by a former cybersecurity executive accuses IBM of not disclosing and actively covering it up.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-1bf9293a-288b-4889-8eee-b8213442ba30.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/ibm-logo-office-76a8b143-140c-4956-a940-3c1fcba61ab7.jpg)](https://techcrunch.com/2026/06/05/former-cyber-executive-turned-whistleblower-accuses-ibm-of-covering-up-several-data-breaches/) ## Oxford University discloses data breach after careers platform hack CareerConnect - which is used by Oxford, King's College, and University of Manchester among others - was breached on May 28\. Attackers were able to access users' first names, last names, email addresses, and encrypted passwords (for users who do not sign in using Single Sign-On). The article did not comment on if any other schools who use the platform were compromised or how many accounts were accessed. [Oxford University discloses data breach after careers platform hackThe University of Oxford disclosed a new data breach last week after being informed by its third-party provider, Group GTI, that its CareerConnect career services platform had been compromised.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-096afea9-c5be-413b-af9b-80061f84f028.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Oxford_University-aa4aacfa-2048-4716-b4a6-8038dfacf734.jpg)](https://www.bleepingcomputer.com/news/security/oxford-university-discloses-data-breach-after-careerconnect-platform-hack/) ## SoFi confirms third-party data breach at Hong Kong subsidiary SoFi is a U.S.-based financial technology company that offers banking, investing, loans, and other personal finance services. We have very little information at this time other than that the breach occurred in April 2026\. The company is advising the usual measures for now: update passwords, enable 2FA, monitor accounts, beware phishing attempts, etc. [SoFi confirms third-party data breach at Hong Kong subsidiarySoFi Hong Kong is warning that it suffered a data breach after hackers gained access to a database at a third-party vendor containing customer information.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-77116a69-c004-4304-8660-bc05bec3370a.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/sofi-hong-kong-c3a3f071-f68d-4cff-ab3e-6997c17bdb0b.jpg)](https://www.bleepingcomputer.com/news/security/sofi-confirms-third-party-data-breach-at-hong-kong-subsidiary/) ## French govt messaging service breached in account hijacking attack Tchap is a messenger based on Matrix who's use is mandated for all French civil servants as of August 2025\. This week a user account was compromised via social engineering, allowing the attacker to scrap the data of all channels that user was in. The attacker claims they scraped 13.5GB of data from the French tax authority and other civil servants, including 560,000 messages and information on over 73,000 accounts, including email addresses, organization information, meeting links, and account and device metadata. [French govt messaging service breached in account hijacking attackDINUM, the digital affairs directorate of the French government, warned that hackers used a hijacked user account to breach Tchap, the French government’s encrypted messaging platform.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-d9540913-f410-46e0-86dd-9a8ed012c25b.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/French_flag-5a3ba101-2efc-4184-b84d-6f729f2ee688.jpg)](https://www.bleepingcomputer.com/news/security/french-govt-messaging-service-breached-in-account-hijacking-attack/) ## ServiceNow discloses security incident exposing customer data This breach was the result of being able to access an API that did not require authentication. ServiceNow patched the vulnerability to require users to authenticate, but hasn't said much else including what data was impacted or how many customers. The article notes, however that "nstances commonly store sensitive enterprise information, including IT support tickets, employee records, internal documentation, asset inventories, security incident reports, workflow data, and configuration details for corporate systems and services." [ServiceNow discloses security incident exposing customer dataServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-cf858f9e-d22a-45d9-983d-54d2a0723fc8.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/servicenow-ac6cf54b-a776-4e1b-a11d-d85b5758c5b2.jpg)](https://www.bleepingcomputer.com/news/security/servicenow-discloses-security-incident-exposing-customer-data/) ## Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks This is less of a specific breach and more of a collection. Oracle says that a rash of breaches impacted both cloud and on-premises PeopleSoft instances have been detected. ShinyHunters has claimed the activity, saying they have stolen data from 300 instances and more than 100 organizations. The article states that this is a combination of old, unpatched vulnerabilities and new zero-days and that configuration may play an additional role in whether or not a server is vulnerable. [Oracle PeopleSoft servers hacked in ShinyHunters data theft attacksOracle PeopleSoft servers are being targeted in ongoing data theft attacks by the ShinyHunters extortion gang, which claims to have stolen data from over 100 organizations.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-bc2dc5b4-349a-4d1c-991e-3b9ccd0b6fd1.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/Oracle-b642f165-6592-4510-82ed-9dc2add2b9ca.jpg)](https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/) ## Nottingham University data breach affects over 450,000 students This breach is allegedly a result of the Oracle PeopleSoft breaches mentioned above. The attackers claim to have over 40GB of documents containing student finance data, billing and payment information, credit card and payment details, and campus portal exports from the University of Nottingham and its Malaysia and China campuses. Documents also contained students' full names, home addresses, IP addresses, phone numbers, and dates of birth. Have I Been Pwned said their analysis additionally showed that ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments were exposed. [Nottingham University data breach affects over 450,000 studentsThe University of Nottingham confirmed on Wednesday that a hacking group gained access to its student records system in a breach affecting both current students and alums.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-d356e963-3a92-4fe6-8770-1cfaff1684ce.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/University_of_Nottingham-0ebd347c-fbac-4169-b55c-221e84fb2bc2.jpg)](https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/) ## Flock Leaked Cops’ License Plate Searches via DuckDuckGo, Bing Some of Flock's searches have been indexed by search engines like Bing (and thus DuckDuckGo), revealing data such license plates, reasons for the search, and in some cases the date range of the search. Flock says they are investigating. [Flock Leaked Cops’ License Plate Searches via DuckDuckGo, BingFlock, the automatic license plate reader (ALPR) company, exposed some of the license plate cops were looking for and the reason for doing so.![](https://www.privacyguides.org/content/images/icon/favicon-3-c77b4540-beed-43ed-b9f9-73d80edd6758.svg)404 MediaJoseph Cox![](https://www.privacyguides.org/content/images/thumbnail/flock-results-ee1f11e6-502a-4df3-967f-910a5747c35b.png)](https://www.404media.co/flock-leaked-cops-license-plate-searches-via-duckduckgo-bing/) ## Japanese energy firm loses drive with data of 10.9 million clients Kyushu Electric Power Co has disclosed that a drive containing backups of customer data has gone missing. It appears to have been stolen, but it's unclear if it was simply misplaced. Data includes customer names, service location addresses, electricity usage data, telephone numbers, names of retail electricity providers, and "other related information." [Japanese energy firm loses drive with data of 10.9 million clientsKyushu Electric Power Co., Inc. has disclosed a physical security incident that affects private data of more than 10 million customers.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-6070c1ff-1a86-4167-b6ec-ba19a3c10a46.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/kyushu-cca10944-3095-4115-9c91-9d844176b01c.jpg)](https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/) ## Coupang hit with record $409 million data breach fine in Korea An update to a breach from last year that occurred in June but was publicly disclosed in November. The e-commerce giant leaked the data of over 33 million customers, making it one of the worst in South Korea's history. The Personal Information Protection Commission has fined Coupang for "unlawfully collecting, using, and handling customers' personal and sensitive data" as well as inadequate security practices, including failures in authentication key management and access controls. [Coupang hit with record $409 million data breach fine in Korea​​The Personal Information Protection Commission (PIPC), South Korea’s data protection regulator, has fined e-commerce giant Coupang a record 624.6 billion won (roughly $409 million) following a massive data breach affecting more than 37 million customers![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-cf227d0b-5796-4239-a347-78e66369f746.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Coupang_headpic-376bd8c7-721c-42ea-8ca4-ff9f7a4604da.jpg)](https://www.bleepingcomputer.com/news/security/south-korea-hits-coupang-with-record-409-million-fine-over-data-breach/) ### Microsoft Patches Some Vulnerabilities from Nightmare Eclipse, Others Left Unpatched URL: https://www.privacyguides.org/news/2026/06/10/microsoft-patches-some-vulnerabilities-from-nightmare-eclipse-others-left-unpatched/ Last updated: 2026-06-10T20:14:02.000Z Microsoft has [patched](https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/) some vulnerabilities from anonymous security researcher going by the pseudonym Nightmare Eclipse, who published yet another vulnerability the same day. The drama started with a [blog post](https://deadeclipse666.blogspot.com/2026/03/) back in March from Nightmare Eclipse ominously titled “I never wanted to do this…” > I never wanted to reopen a blog and a new github account to drop code... > But someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine. Over the next few months, Nightmare Eclipse would post proof-of-concepts for severe zero-day exploits in Windows publicly on GitHub. They’ve since been deleted but, as is often the case on the internet, archives exist. Typically, researchers will disclose the vulnerability first to the software owners, in this case Microsoft, and give a reasonable timeframe for them to patch it before publicly disclosing it. In this case, however, Nightmare Eclipse was retaliating for a supposed breach of an arrangement they had made with Microsoft. Microsoft responded saying they violated “coordinated vulnerability best practices,” followed by revoking their [MSRC](https://www.microsoft.com/en-us/msrc) account. Tuesday’s [Windows update](https://support.microsoft.com/en-us/topic/june-9-2026-kb5094126-os-builds-26200-8655-and-26100-8655-1a9bcba6-5f53-4075-8156-fe11ac631737) fixed several of the vulnerabilities that Nightmare Eclipse had released, one of which being [CVE-2026-45586](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586), also known as [GreenPlasma](https://web.archive.org/web/20260521145051/https://github.com/Nightmare-Eclipse/GreenPlasma). GreenPlasma is a local privilege escalation vulnerability, possibly allowing malware to gain full system access. Microsoft also fixed [MiniPlasma](https://web.archive.org/web/20260521144855/https://github.com/Nightmare-Eclipse/MiniPlasma), a vulnerability that was apparently supposed to be patched by Microsoft years ago but Windows was still vulnerable to years later, with the original proof-of-concept from Google Project Zero still working fine. Overall the patch fixed around 200 vulnerabilities, however several of Nightmare Eclipse’s exploits remain unpatched, such as [YellowKey](https://web.archive.org/web/20260520184528/https://github.com/Nightmare-Eclipse/YellowKey), a severe Bitlocker encryption bypass that lets attackers with physical access to your machine essentially completely bypass the encryption. This one was so bad that they described it as “one of the most insane discoveries I ever found.” Other unpatched vulnerabilities from the researcher include [RedSun](https://web.archive.org/web/20260521144507/https://github.com/Nightmare-Eclipse/RedSun), an exploit in Defender that lets attackers gain administrator privileges, and BlueHammer. With this patch Tuesday, Nightmare Eclipse released yet another new zero day, this time titled [RoguePlanet](https://github.com/MSNightmare/RoguePlanet), another Defender privilege escalation vulnerability. It relies on a race condition, so it’s “hit or miss,” but they say it could be possible to design it to achieve a 100% success rate. Microsoft is clearly struggling to keep up with the vulnerabilities. It’s not clear how much longer this feud will go on, but if one person is able to release vulnerabilities this consistently, maybe it reveals a systemic flaw in how Windows security works. ### Ransomware Gang Exploiting Legacy VPN Protocol in US Federal Agencies URL: https://www.privacyguides.org/news/2026/06/10/ransomware-gang-exploiting-legacy-vpn-protocol-in-us-federal-agencies/ Last updated: 2026-06-10T00:01:47.000Z According to [TechCrunch](https://techcrunch.com/2026/06/09/cisa-gives-us-federal-agencies-three-days-to-fix-a-vpn-bug-under-attack-by-a-ransomware-gang/), CISA is giving US federal agencies until the end of Wednesday to fix an actively exploited VPN vulnerability in the [deprecated IKEv1](https://www.ietf.org/archive/id/draft-ietf-ipsecme-ikev1-algo-to-historic-07.html) key exchange protocol. Check Point Research identified active exploitation of [CVE-2026-50751](https://nvd.nist.gov/vuln/detail/CVE-2026-50751), a bug affecting their own VPN offerings. The bug allows an attacker to bypass authentication and establish a VPN connection without knowing the password. Check Point identified [Qilin](https://blog.qualys.com/vulnerabilities-threat-research/2025/06/18/qilin-ransomware-explained-threats-risks-defenses), a software-as-a-service ransomware group, as the culprits in the active exploitation. > To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate. Among these organizations are reportedly multiple US federal agencies, who have had the deprecated IKEv1 protocol enabled for some reason. Check Point estimates that the attacks began on May 7, but ramped up in June, when they first noticed the activity. They also believe that Qilin is "exploiting other VPN related vulnerabilities such as the ones published by Palo Alto, Fortinet and F5." It's a mystery why US agencies had a deprecated protocol enabled in the first place. Aside from updating to the patched software immediately, Check Point's [remediation](https://support.checkpoint.com/results/sk/sk185033) steps involve disabling IKEv1 and switching to IKEv2 exclusively and disabling support for legacy clients. While investigating this attack, Check Point found another vulnerability, [CVE-2026-50752](https://nvd.nist.gov/vuln/detail/CVE-2026-50752), although they say they didn't see any evidence of this one being actively exploited in the wild. This vulnerability also involves IKEv1: > A condition in the certificate validation logic of the deprecated > IKEv1 key exchange can allow a man-in-the-middle attack on VPN > site-to-site connections. A ransomware gang actively attacking US infrastructure puts the data of all US citizens at risk, and it could involve bringing down vital infrastructure like water treatment plants and power plants. Situations like this one harken back to the [Salt Typhoon](https://stateofsurveillance.org/articles/surveillance/salt-typhoon-telecom-hack/) cyberattacks, where a Chinese hackers infiltrated American telecom infrastructure, compromising the phone calls and data of over 1 million users. Ironically, they used a legally-mandated Communications Assistance for Law Enforcement Act (CALEA) telecom backdoor. Another attack, [Volt Typhoon](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a), involved a years-long campaign targeting US transportation, communication, energy, and water treatment plants. Needless to say, the US government needs to step up their cybersecurity. Disabling deprecated protocols is a no-brainer and should be mandated already across all agencies. ### Common Speakers Can Be Remotely Hacked and Used to Take Over Your PC URL: https://www.privacyguides.org/news/2026/06/08/common-speakers-can-be-remotely-hacked-and-used-to-take-over-your-pc/ Last updated: 2026-06-08T02:10:31.000Z Ethical hacker Rasmus Moorats in a [blog](https://blog.nns.ee/2026/06/03/katana-badusb/) post revealed an exploit in Sound Blaster Katana V2X speakers, dubbed "Pwnd Blaster," that would allow an attacker to remotely take over your PC. The [Katana V2X](https://us.creative.com/p/speakers/sound-blaster-katana-v2x) is a USB-connected soundbar that's advertised as highly customizable. In order to achieve this, you're supposed to install their app to customize the RGB lighting and sound settings etc. This is achieved through a custom proprietary protocol called CTprotocol. Moorats discovered that in order to communicate with the speaker over CTP, there's only a flimsy challenge-response authentication scheme, where the key is completely static and can be derived from the binaries that ship with the Creative App, a pretty pointless step. Firmware updates are also performed using CTP, and there is similarly weak authentication for those. Just a "trivial to patch" SHA-256 checksum, there is no other authentication for the firmware. No signature checks or anything, meaning an attacker can flash malicious firmware on your speakers quite easily. Unfortunately, this attack isn't limited to just USB. The speakers have always-on Bluetooth that's impossible to turn off, and you can flash firmware over Bluetooth just the same as over USB. You don't even need to pair with the device, you can connect over Bluetooth and immediately start reading and writing data to it. "This means anyone can just connect to any Katana V2X over Bluetooth and start sending CTP commands to it, reading information, changing settings, etc." The speakers have microphones and could easily be turned into remote surveillance devices and you'd be none the wiser. Even worse, however, is that the speaker is typically connected over USB, meaning it could trick your computer into thinking it's a keyboard, and then be able to perform any malicious action a keyboard could perform i.e. running commands in the command line. The speaker already sets itself up as a Human Interface Device for some reason, making it even easier for an attacker to achieve this. Moorats was able to do exactly this and create a remotely executed attack that flashes malicious firmware and runs commands in the terminal. Creative made it very difficult to get in contact and months later when they did, they said "they do not consider this to be a vulnerability, as it does not present a cybersecurity risk." As such, the latest firmware is still vulnerable and there are no official patches in sight. It just goes to show the abysmal state of Bluetooth accessory security, and how little many of these companies care about protecting their own customers. ### Brave Launches Paid, "Minimalist" Brave Origin Browser URL: https://www.privacyguides.org/news/2026/06/07/brave-launches-paid-minimalist-brave-origin-browser/ Last updated: 2026-06-07T02:15:04.000Z Brave has officially [released](https://brave.com/blog/brave-origin/) Brave Origin, a minimal version of the regular Brave browser without a lot of the optional features such as Rewards, Leo AI, and Brave's VPN, for a one-time fee. The browser is $60 on Windows and Mac, and free for Linux users. The regular Brave browser will continue to be available with no changes. The full list of removed features are as follows: - Leo AI - News - Playlist (currently iOS only) - Rewards (which also disables browser-based Brave Ads) - Speedreader - Stats like the daily usage ping, crash logs, and privacy-preserving product analytics (P3A) - Talk - Tor - VPN - Wallet (which also disables Web3 domains) - Wayback Machine - Web Discovery Project - Email aliases (currently in Nightly release for desktop) When downloading Brave Origin as a standalone app, the features above will be compiled out of the app, saving space and ensuring none of them can be enabled accidentally. You can already disable these features in standard Brave, but they won't be compiled out of the binary so they will still take up space. You can also upgrade your existing Brave browser, in which case a new settings panel will appear allowing you to disable each feature individually: ![](https://www.privacyguides.org/content/images/2026/06/image-1.png) Many of the disabled features are part of Brave's business model, with the $60 fee essentially allowing you to support Brave while ignoring them all. Brave's CTO, Brian Bondy, stated > Origin gives our users the ad and tracker blocking they want coupled with the ability to manage which features appear in the browser, for a one-time fee across all their devices (and free on Linux). By supporting Brave as a business, users get the browser they asked for in order to manage their Web experience. Brave says that "any new revenue-generating features we release (outside the core of Brave Shields) would not appear in the standalone Origin app." Brave protects your privacy when you make your purchase via their [privacy-preserving subscription credentials](https://github.com/brave/brave-core/blob/master/docs/premium%5Faccount%5Fprivacy.md), based on the open [Privacy Pass](https://www.ietf.org/rfc/rfc9576.html) standard. Using this, they're able to decouple your payment identity from service usage, maintaining unlinkability. The availability of the browser is a bit mixed on each platform for now. On Android and iOS, you can only get it as an upgrade for existing Brave. On macOS and Windows, you can buy the standalone app or upgrade. It's the same on Linux, but you can optionally waive the fee (or pay anyway to support them). Brave will also offer a full refund within 30 days of your purchase if you decide you don't like it, you just need to contact their support. ### GTA V Cheaters Just Got Exposed! URL: https://www.privacyguides.org/livestreams/2026/06/05/gta-v-cheaters-just-got-exposed/ Last updated: 2026-06-23T01:41:28.000Z This Week in Privacy #56 _This post is for subscribers only._ ### Data Breach Roundup (May 29 - June 4, 2026) URL: https://www.privacyguides.org/news/2026/06/05/data-breach-roundup-may-29-june-4-2026/ Last updated: 2026-06-05T18:16:55.000Z ## Charter Communications data breach affects 4.9 million accounts An update to a breach from last week, there's not much new here except that we now know how many people were impacted. ShinyHunters claims the data includes consumer and business customer names, email addresses, physical addresses, phone numbers, phone types, plan information, support ticket data, and some CPNI data. [Charter Communications data breach affects 4.9 million accountsThe ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-a9f0d02685c1ae934d73f628015fe460f76e94804fbbaa2da1ba7f7eaa2eac06.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Charter-0098190643436b0a591939c625e047633abb4f567827e7678580b98a9e712e36.jpg)](https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/) ## Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers Atlas Menu is a popular cheat service for Grand Theft Auto V online, and has now suffered a data breach. Stolen data includes email addresses, usernames, hashed passwords, IP addresses, and support tickets of about 64,000 accounts. There's no information in this article about how Atlas Menu was breached. [Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers | TechCrunchHackers stole usernames, hashed passwords, and other data from a service that allowed players to cheat in Grand Theft Auto V.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-28432ebc5ba0fbbe3ee773966a8b0b21a1747b868baf03ddb27c79b467e86883.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/grand-theft-auto-v-2ed754937c844630dfba001b451ae86cdb67a2455738c564dd37d037fcca0be1.jpg)](https://techcrunch.com/2026/06/01/grand-theft-auto-v-cheat-service-gets-hacked-exposing-thousands-of-gamers/) ## Ultrahuman says hackers accessed customers’ wellness data via internal tool Ultrahuman sells smart rings and metabolic health-tracking devices that enable users to monitor metrics such as sleep, activity, and recovery. The startup is best known for its Ring Air, which competes with the Oura Ring. The company says the incident was the result of gaining credentials stolen from an employee’s malware-infected laptop. They have declined to say how many people or what data was impacted, citing an ongoing investigation. [Ultrahuman says hackers accessed customers’ wellness data via internal tool | TechCrunchThe breach at wearable ring maker Ultrahuman stemmed from credentials stolen from a malware-infected employee laptop.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-28432ebc5ba0fbbe3ee773966a8b0b21a1747b868baf03ddb27c79b467e86883.png)TechCrunchJagmeet Singh![](https://www.privacyguides.org/content/images/thumbnail/uh-ring-air-hand-ff5c13a2fc40de6d888dbf1c599395f6e77b7574da2353ef106c42e6819981a4.jpg)](https://techcrunch.com/2026/06/03/ultrahuman-says-hackers-accessed-customers-wellness-data-via-internal-tool/) ## UN food agency discloses breach affecting 600,000 Gaza households The UN's World Food Programme (WFP) says that the self-registration application (SRA) for Palestine was breached. Affected data included names, ID numbers, phone numbers, and location information (such as neighborhood data recorded during registration). [UN food agency discloses breach affecting 600,000 Gaza householdsThe United Nations’ World Food Programme (WFP), the world’s largest humanitarian organization, revealed over the weekend that its self-registration application (SRA) for Palestine was breached.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-a9f0d02685c1ae934d73f628015fe460f76e94804fbbaa2da1ba7f7eaa2eac06.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/UN_WFP_World_Food_Programme-983eca91227d4dfbb979ac810ce4a3e18b27d248d35bd1cc7d6cead03cc51d16.jpg)](https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affects-600-000-gaza-households/) ## DentaQuest data breach exposed info of 2.6 million accounts DentaQuest, is one of the largest dental benefits administrators in the United States. The breach is the result of the ShinyHunters ransomware gang, and impacts Email addresses full names, phone numbers, government-issued IDs, health insurance information, genders, and dates of birth. [DentaQuest data breach exposed info of 2.6 million accountsA data breach at the dental benefits administrator DentaQuest has reportedly exposed the sensitive data of 2.6 million accounts.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-a9f0d02685c1ae934d73f628015fe460f76e94804fbbaa2da1ba7f7eaa2eac06.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/DentaQuest-b872698c5df7f4a0fb350f50e35ea84b9df8a79b641ed95a5f60ff4ef58ae363.jpg)](https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/) ## California AG sues 23andMe over 2023 breach exposing health data A small update to a story that just won't end. This breach alleges "failure to protect sensitive customer genetic and personal information." We will update you if there's any further information. [California AG sues 23andMe over 2023 breach exposing health dataCalifornia Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company’s failure to protect sensitive customer genetic and personal information.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-a9f0d02685c1ae934d73f628015fe460f76e94804fbbaa2da1ba7f7eaa2eac06.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/23andMe-869251356aa4c3737fc77278107a20191180158d6369b66beb5de0ff84892bae.jpg)](https://www.bleepingcomputer.com/news/security/california-ag-sues-23andme-over-2023-breach-exposing-health-data/) ### Meta’s AI Support Agent Used by Hackers to Take Over Instagram Accounts URL: https://www.privacyguides.org/news/2026/06/04/metas-ai-support-agent-used-by-hackers-to-take-over-instagram-accounts/ Last updated: 2026-06-04T20:45:20.000Z An [exploit](https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/) described as “remarkably simple” allows anyone to add a new email address to any Instagram account using Meta’s AI chat bot, allowing full account takeover. The method involves using a VPN to make it appear as though your traffic is coming from the same country as your victim. Then, you simply request a password reset for your account and choose to chat with Meta’s AI support assistant. You can then just tell the AI assistant to link a new email address to the account, and it will happily comply. The bot sends a one-time password reset link to the account, and you’re in. The exploit was originally showed in a video posted by “pro-Iranian hackers” in a Telegram group. According to the [post](https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/) from Brian Krebs, the Obama White House and Chief Master Sergeant of the U.S. Space Force were “defaced with pro-Iranian images and messages.” Meta hasn‘t officially responded, but Andy Stone, an employee at Meta, stated that the “issue has been resolved“ and the impacted accounts were secured. > This issue has been resolved and we are securing impacted accounts. > > — Andy Stone (@andymstone) [June 1, 2026](https://x.com/andymstone/status/2061486724199379186?ref%5Fsrc=twsrc%5Etfw) AI agents have well-documented security vulnerabilities, including several [inside](https://www.privacyguides.org/news/2026/03/22/severe-meta-cybersecurity-incident-caused-by-ai-agent/) Meta. You don’t always know exactly what AI agents will do since their behavior isn‘t deterministic. With human support agents, you have the potential for [social engineering](https://www.ibm.com/think/topics/social-engineering) attacks, where you convince them to divulge information they shouldn’t or perform actions they shouldn’t. AI agents bring a whole other attack surface in the mix though: they’re vulnerable to prompt injection attacks, where an attacker uses an input prompt to re-write the instructions for the agent. AI can’t tell the difference between input and instructions, so an attacker that can get around any barriers put up can essentially rewrite the AI’s brain. In this case, though, it seems like intended behavior. Generally, when websites want you to reset your password, they will only send a password reset link to an email address already associated with that account. However, in this case, the AI simply accepts any email address provided, essentially letting anyone take over any account they want to. It’s not clear what the AI agent is supposed to be doing that a classic “forgot my password” reset screen can’t. It seems Meta implemented the feature without remotely enough safeguards to prevent misuse. It’s doubtful that AI agents should even be allowed to control account authentication in the first place, but something tells me more companies will add a feature like this to their services anyway. ### No Right to Remain Silent: Negative Rights in a Positive-Rights World URL: https://www.privacyguides.org/posts/2026/06/01/no-right-to-remain-silent-negative-rights-in-a-positive-rights-world/ Last updated: 2026-06-03T16:40:06.000Z Last December, reports began to circulate about the US Government’s proposed new entry requirements for tourists. Travelers may soon be asked to list and make public the social media accounts they’ve held over the last five years, and [much more beyond that](https://www.nbcnews.com/politics/trump-administration/foreign-tourists-five-years-social-media-history-customs-border-protec-rcna248337). At first glance, this might seem a regrettable, yet predictable, progression of surveillance. But it also reveals something more subtle. The new plans are just the latest prominent example of a societal framework that assumes participation. Legibility has become normalized. Having a record is assumed. Lacking one is suspicious. Legally, this same assumption holds true. Laws around the globe focus on positive rights, or control over existing data. You can often request access, correction, deletion, or raise an objection through [regulations](https://www.privacyguides.org/en/activism/toolbox/tip-know-your-privacy-laws/) such as the GDPR or CCPA. Practically none give you the reverse, negative rights. In other words: **the right to produce *no data* broadly doesn’t exist.** To grasp this idea fully, it is important not to consider data merely as a set of discrete items. Of course, systems collect data not only on what you say and do, but equally on what you leave undone. The collection of that data is something you have [scarce power](https://www.gao.gov/products/gao-22-106096) or right to control. Shoshana Zuboff’s *Surveillance Capitalism* succinctly accounts for this constant monitoring. Power stems not from merely observing behavior, but rendering it into a resource. Prediction is profitable, and uncertainty is waste. Opacity, therefore, is a friction that creates uncertainty. And friction, in the eyes of governments or corporations, can look a lot like risk. ## How does that play out today? Consider these two real-world examples. The first, in 2019, involves trials of facial recognition technology by police in London. In several cases, [passers by were stopped](https://www.the-independent.com/news/uk/crime/facial-recognition-cameras-technology-london-trial-met-police-face-cover-man-fined-a8756936.html) for covering their faces or pulling up their hoods. Take also consumer credit. Agencies often rely on large, data-rich models to make decisions quickly. Especially in developing, non-GDPR markets where millions remain ‘unbanked’, [social media profiling](https://riskseal.io/blog/how-social-media-profiling-enhances-credit-risk-management) has been marketed as a more inclusive means of assessing those with a thin credit file, or none at all. Yet for the data-poor, the outcome can be akin to [discriminatory profiling](https://doi.org/10.1007/s00146-023-01676-3). In both of these examples, silence itself is data. And in each example, actions have been taken—some may argue legitimately—to minimize risk. Yet in hindering bad actors or rewarding legibility, we normalize punishing [those that simply wish to be unmeasured](https://www.privacyguides.org/articles/2025/05/10/sam-altman-wants-your-eyeball/). More to the point: if we reduce the conversation about privacy to control of personal information, we miss the human and political value of *not being fully knowable*. Édouard Glissant described a ‘right to opacity’ as a refusal to be reduced to what dominant actors or systems can understand or manage. It was forged as a means to subvert colonial oppression yet remains uncomfortably relevant today. When systems demand that you comply—that you become legible to them—opacity can be a crucial means of retaining self-definition. In this way, silence is generative: it allows you to experiment, dissent, and live on your own terms. Yet often you do not have a choice. A particularly grave reminder is the global rise of welfare access contingent on you providing your biometric data. One report on India documented the [death of a man in his fifties](https://www.theguardian.com/technology/2019/oct/16/glitch-india-biometric-welfare-system-starvation) and his prior struggle with the identity system regulating access to food. Many others describe similar tragedies. ## Why doesn’t the law uphold a right to opacity? Legal systems are built around evidence and accountability. GDPR and equivalent regulations work because they police past data misuse. Policing suspicion towards the unmeasured—from which the harm is often indirect—presents a very different challenge. There is an obvious economic barrier too. A right to be unmeasured would cut against the business model of a plethora of large corporations with enormous political sway. This would come just at a point when data brokers are further tightening their grip: researchers at the University of Cambridge suggest that AI will soon allow organizations to sell your decisions [before you have even made them](https://www.youtube.com/watch?v=E00mNfH75qM), or even control them. The GDPR does, in theory, already prevent some brokering. [Article 25](https://gdpr-info.eu/art-25-gdpr/) is titled ‘*Data protection by design and by default’*, and requires that data be collected and processed only for a specific, stated purpose. The very fact that brokering continues—in a manner that [some view as non-compliant](https://edpl-lexxion-eu.ezp.lib.cam.ac.uk/article/edpl/2023/1/7/display/html)—demonstrates both the challenge in legislating effectively and the need for more focused, comprehensive rights. The idea of an opacity right is not purely utopian, these challenges notwithstanding. Most notably, a [2017 policy document](https://www.rathenau.nl/en/digitalisering/human-rights-robot-age) commissioned by the Council of Europe explicitly recommends a right to not be *electronically measured, analyzed or coached.* The authors contextualize the proposal by highlighting individual defenselessness to mass surveillance, contending that it represents a fundamental affront to the principles of the rule of law. Their summation of the challenge is as follows: > *“There has been little debate about the accumulative effect of mass surveillance. Instead, triggered by specific applications and incidents, ‘mini debates’ about a certain topic have been organized, and the outcome of each debate is a balancing act that mostly favors national security or economic interests. The sum of the debates, however, is the gradual but steady dissolving of privacy and anonymity for the individual.”* One existing negative right has also enshrined its way into popular culture. The US’s Fifth Amendment, while only applicable in criminal contexts, makes a compelling case that it is possible—and deeply important—not to regard silence as inherently suspicious. Today the burden is on you to prove that your opacity is harmless. Rights exist so that you do not have to argue, each time, for the legitimacy of your everyday freedoms. And without an explicit right to your opacity, as the two earlier examples show, even those rights you do already have can be called into question. The legitimacy of dissent, eccentricity, and of ordinary, unrecorded life must be celebrated. Lawmakers must prevent a world that treats silence as deviance. Until then, [saying “no”](https://www.privacyguides.org/articles/2025/06/17/you-can-say-no/) remains one of few tools you have. Not from a place of paranoia, but rather as a claim to a simple freedom: to live, even merely occasionally, without leaving a trace. 💡 **Privacy Guides does not publish guest posts in exchange for compensation, and this* **article* **was independently reviewed by our editorial team prior to publication.* ### GrapheneOS is Taking Accessibility Seriously! URL: https://www.privacyguides.org/livestreams/2026/05/29/grapheneos-is-taking-accessibility-seriously/ Last updated: 2026-06-07T14:30:45.000Z This Week in Privacy #55 _This post is for subscribers only._ ### Data Breach Roundup (May 22 - 28, 2026) URL: https://www.privacyguides.org/news/2026/05/29/data-breach-roundup-may-22-28-2026/ Last updated: 2026-05-29T18:43:30.000Z ## Charter confirms data breach after ShinyHunters extortion threat Charter Communications, one of America's largest ISPs and company behind Spectrum, has admitted to a data breach. They have not disclosed the scope but assure that no sensitive personal customer data was stolen. ShinyHunters claims to have taken over 40 million records containing customer names, email addresses, addresses, phone numbers, phone type, plan information, and some CPNI data. They also claim to have stolen customer support ticket data. [Charter confirms data breach after ShinyHunters extortion threatU.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-137.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/charter-communications.jpg)](https://www.bleepingcomputer.com/news/security/charter-confirms-data-breach-after-shinyhunters-extortion-threat/) ## UK Visa Portal spilled thousands of applicants’ passports and selfies online — and hasn’t fixed the leak An anonymous researcher has alerted TechCrunch that the UK's immigration application portal is exposing at least 100,00 documents. TechCrunch attempted to report the issue, but the company's lawyers and PR firm replied instead of management or security experts. At this time, the issue remains unresolved. [UK Visa Portal spilled thousands of applicants’ passports and selfies online — and hasn’t fixed the leak | TechCrunchThe third-party website exposed applicants’ sensitive documents as part of the U.K. visa application process. Instead of fixing the issue, the company sent attorneys.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-59.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/uk-visa-2186517355.jpg)](https://techcrunch.com/2026/05/26/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak/) ## Scammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing Attacks This story is a bit unclear. It seems that someone somehow (both unidentified) is getting access to hotel booking information and using it to create phishing attacks for travelers to try and steal their credit card numbers. The article is unsure who's behind this or how they're getting access to these systems. [Scammers Are Using Your Real Hotel Reservations to Trick You With Spear-Phishing AttacksCustomer data from more than 350 hotels around the world may have been accessed as part of realistic reservation-hijacking scams.![](https://www.privacyguides.org/content/images/icon/favicon-33.ico)WIREDMatt Burgess![](https://www.privacyguides.org/content/images/thumbnail/Security_HundredsofHotelsCompromisedbyHackersRunningBookingScams_v1.jpg)](https://www.wired.com/story/hundreds-of-hotels-caught-up-in-vacation-booking-scams/) ## Carnival Cruise confirms data breach affecting nearly 6 million people Carnival is the world's largest cruise operator. This breach occurred in April of this year and included names, dates of birth, email addresses, genders, geographic locations, and loyalty program details. [Carnival Cruise confirms data breach affecting nearly 6 million peopleCarnival Corporation, the world’s largest cruise line operator, has confirmed a data breach affecting nearly 6 million people claimed by the ShinyHunters extortion gang in April 2026.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-138.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Carnival_fleet.jpg)](https://www.bleepingcomputer.com/news/security/carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people/) ## Microsoft accused of leaking data of Dutch civil servants working on tech laws to US government Microsoft allegedly shared emails, minutes, and invitations without redacting information required under GDPR such as names. It's unclear what the context of the data sharing was. ## A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses This was an exposed Microsoft Azure server that had no password protection. The researcher who found this said that text messages, handwritten notes, and financial records were also exposed. The server has since been secured but Pay Tel hasn't acknowledged it publicly. [A security lapse at prison pay phone service Pay Tel publicly exposed over 300K callers’ driver’s licenses | TechCrunchPay Tel secured the publicly exposed data after security researchers discovered the leak containing callers’ sensitive ID documents and inmate communications.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-60.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/prison-2023.jpg)](https://techcrunch.com/2026/05/28/a-security-lapse-at-prison-payphone-service-pay-tel-publicly-exposed-over-300000-callers-drivers-licenses/) ## Government24 Personal Data Leak Caused by Negligence: Ministry of the Interior and Safety Fined Over 200 Million Won This is an update to a breach in South Korea from 2024 where the personal data of 1,233 individuals was leaked due to "source code development errors." The data included names, dates of birth, academic records, graduation certifiates, and more. [Government24 Personal Data Leak Caused by Negligence: Ministry of the Interior and Safety Fined Over 200 Million Won - The Asia Business DailyThe Personal Information Protection Commission announced on the 28th that it has imposed a total of more than 500 million won in fines on four public![](https://www.privacyguides.org/content/images/icon/asiae.ico)The Asia Business DailyRoh Kyungjo![](https://www.privacyguides.org/content/images/thumbnail/2026052809324979311_1779928369.jpg)](https://www.asiae.co.kr/en/article/science/2026052809394663105) ## Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses A small update to a story from last week. Trump Mobile has finally acknowledge that they were leaking customer data. They are blaming a third-party provider and claim that no content or financial information was leaked, and no network, systems, or infrastructure were breached. They have not issued notifications yet. [Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses | TechCrunchPresident Trump’s branded cell phone maker and cell provider said the exposure was linked to a third-party platform and was evaluating whether it needs to notify customers.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-58.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/donald-trump-cellphone.jpg)](https://techcrunch.com/2026/05/22/trump-mobile-confirms-it-exposed-customers-personal-data-including-phone-numbers-and-home-addresses/) ## 7-Eleven data breach exposes personal information of 185,000 people Last week we learned that popular convenience chain 7-Eleven had suffered a data breach in April, but little else. We now know the number impacted as well as a better idea of the data: names, dates of birth, unique email addresses, pone numbers, and physical addresses. [7-Eleven data breach exposes personal information of 185,000 peopleThe ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-136.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/7-Eleven.jpg)](https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/) ### Google Family Link Exploit Enables Account Lockout and Surveillance URL: https://www.privacyguides.org/news/2026/05/29/google-family-link-exploit-enables-account-lockout-and-surveillance/ Last updated: 2026-05-29T16:25:58.000Z Google Family Link, Google's child safety feature, can be [leveraged](https://techwolf12.nl/blog/google-family-link-exploit/#total-surveillance-and-control) by an attacker to lock you out of your Google account and surveil and control your activity. A software engineer that goes by the online handle [Techwolf12](https://techwolf12.nl) discovered the vulnerability when it was used against one of their friends. Family Link is designed to help parents manage their children's accounts and devices. As such, anyone with a "child" account has very little ability to manage their own security settings. You won't be allowed to go through the standard Google account recovery process. There's reportedly no known automated way to get access to your account again. The only way users have found to recover your Google account after the attack occurs is to tweet at TeamYoutube on X hoping they will manually help you get your account back. You can also pay for a Google One subscription for the ability to talk to a real human support agent (free accounts don't get live support). They won't be able to do anything but they can escalate to someone who can. Techwolf says 2FA won't protect you against the attack, since cookie-stealing malware bypasses it entirely and changing the age on your Google account and enrolling in Family Link doesn't require 2FA. Enabling [Advanced Protection](https://landing.google.com/advancedprotection/) on your Google account is an effective mitigation, however, since you won't be able to be added to a Family Link group. Once an attacker has your account locked down, they have full visibility into your digital life. They can track your real-time location via Google Maps, lock your Android device whenever they want, see your [screen time](https://support.google.com/families/answer/7103340?hl=en) and intercept app downloads, and read your incoming emails, including password reset emails. The attack works by first gaining access to your password via a data breach, phishing, or any number of methods. Then, the attacker changes your birth year to be under 13, then linking your account to a "parent" Google account (controlled by them). The attacker now has full authority over your account. This exploit shows how forced "child safety" features can easily backfire. Strangely enough, Google has [bragged](https://blog.google/innovation-and-ai/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/) about its digital ID technology but provides no way to prove your age using it. Also alarming is the fact that they are aware of this exploit since multiple users have had to have Google's support staff recover their account for them, but it still stands. For now, anyone with a Google account should lock it down as much as possible and be very vigilant. ### Signal macOS Desktop App Doesn't Actually Delete Messages When it Should URL: https://www.privacyguides.org/news/2026/05/29/signal-macos-desktop-app-doesnt-actually-delete-messages-when-it-should/ Last updated: 2026-05-29T00:28:29.000Z Security researcher [Harry Sintonen](https://infosec.exchange/@harrysintonen/116618393246317371) disclosed that the macOS desktop Signal app doesn't [actually delete messages](https://sintonen.fi/advisories/signal-deleted-but-not-forgotten.txt) when they're deleted in the UI of the app. Sintonen explains that the macOS Signal app uses an SQLcipher database, essentially a SQLite database with encryption, meaning it inherits features from SQLite. All transactions are written to a log file, which is then merged into the actual database once a certain threshold of pages is reached in the log file. The default threshold in Signal is 1000 pages, a number that Sintonen says can take potentially several days to reach, depending on how busy your Signal app is. This means that messages marked deleted in the UI of your Signal app might actually still be there for a long time after you deleted them. Signal is a security-critical app for many people, and one of the features it boasts is time-sensitive [disappearing messages](https://support.signal.org/hc/en-us/articles/360007320771-Set-and-manage-disappearing-messages). The timer for these messages can be set to a very short time, down to a few seconds. This means someone could believe a message was deleted seconds after it was viewed, and it actually isn't deleted until days later. Worse still, the data on disk can end up in [Time Machine](https://support.apple.com/en-us/104984) backups, leaving messages accessible on disk for even longer. Sintonen points out that since the message database file is encrypted, the impact of the vulnerability is lessened. Also, anyone who uses Signal a lot will reach the threshold more quickly, reducing the impact even more. A restart of the Signal app can also force the messages to be properly deleted in the database. A proof-of-concept is available on [GitHub](https://github.com/fjh658/signal-decryption-tool). Sintonen discovered the vulnerability all the way back in November of 2025 and promptly reported it to Signal through the proper channels. He received no acknowledgement back. After a 180 wait and confirming the app was still vulnerable, he publicly disclosed the vulnerability. It's not clear if other Signal apps are affected but he says that likely other Signal desktop apps are affected and Android is also likely affected. However, the iOS app is unaffected. The Signal desktop apps have come under fire in the past for [storing files unencrypted](https://x.com/mysk%5Fco/status/1809184570769650131?ref%5Fsrc=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1809184570769650131%7Ctwgr%5E49ceabce380b15b25b42d5b6d1812de79c8886ad%7Ctwcon%5Es1%5F&ref%5Furl=https%3A%2F%2Fcandid.technology%2Fsignal-encryption-key-flaw-desktop-app-fixed%2F). Representatives at Signal stated that "\[t\]he database key was never intended to be a secret. At-rest encryption is not something that Signal Desktop is currently trying to provide or has ever claimed to provide." Eventually, Signal fixed the issue anyway. Hopefully the complete radio silence for this issue will eventually be met with a fix as well. ### Town Councilmember Proposes Internet and Phone Ban After Flock Contract is Cancelled URL: https://www.privacyguides.org/news/2026/05/28/town-councilmember-proposes-internet-and-phone-ban-after-flock-contract-is-cancelled/ Last updated: 2026-05-28T22:46:58.000Z After the town of Bandera, Texas [voted 3-2 to](https://www.404media.co/after-town-bans-flock-councilmember-crashes-out-proposes-internet-and-phone-ban/) end its contract with the dystopian surveillance company Flock, a pro-Flock councilmember proposed a ban of phones, cameras, the internet, and nearly all technology in a childish outburst more fitting for a pre-school student than a public representative. The vote came after months of outrage from residents, who join [many other cities](https://www.npr.org/2026/02/17/nx-s1-5612825/flock-contracts-canceled-immigration-survillance-concerns) in cancelling their contracts with the up-and-coming surveillance nightmare company. Councilmembers Debbie Breen, Deanna McCabe and Tammy Morrow voted in favor of banning the surveillance apparatus, while council members Lynn Palmer and Jeff Flowers voted to keep the contract with Flock. After the vote, Flowers felt it necessary to release a satirical [statement](https://www.banderabulletin.com/article/3093,council-votes-to-terminate-flock-safety-contract?ref=404media.co) calling for a ban of cellular devices and the internet. The statement very bluntly references the famous satirical piece [*A Modest Proposal*](https://www.gutenberg.org/files/1080/1080-h/1080-h.htm) by Jonathan Swift, except instead of the target being politicians ignoring the poor, it instead makes the citizens of Bandera concerned about their basic constitutional right to privacy the butt of the joke. The piece essentially equates his constituents to unreasonable anti-technology luddites who want to return to the 1800's. Among the arguments presented are a "total ban on all cellular and GPS-capable devices," a "total ban on all outward-facing cameras, including residential doorbells and all commercial CCTV or security camera technology," and "A total termination of all internet services and electronic record-keeping." He also makes the argument that the city is throwing away "free money" (the Flock system was being paid for by a government grant), essentially confirming that he is willing to sell the privacy of his constituents out for a quick buck. It's a view into the mind of someone who seems to have a simplistic, binary view of technology: either it's all good, or it's all bad. People who have actually looked into the security of Flock cameras have found incredibly [embarrassing vulnerabilities](https://www.privacyguides.org/news/2025/11/17/ben-jordan-exposes-severe-security-vulnerabilities-in-flock-surveillance-cameras/) that belie a company that doesn't consider security at all when implementing their surveillance system. Flock cameras have also been responsible for several [false arrests](https://www.gadgetreview.com/when-smart-cameras-flock-up-the-35000-cost-of-one-misread-license-plate) now, with more surely to come in the future. Despite the mountains of evidence that Flock cameras are a bad idea, politicians like Flowers seem incapable of even considering the other point of view. I wonder how he would feel if he or one of his family members were falsely arrested and [kept for months](https://www.privacyguides.org/news/2026/04/01/grandma-wrongly-arrested-due-to-facial-recognition-software-finally-released-after-months-in-jail/) in jail under false pretenses. ### Apple Publishes Source Code for Their Cryptography on GitHub URL: https://www.privacyguides.org/news/2026/05/28/apple-publishes-source-code-for-their-cryptography-on-github/ Last updated: 2026-05-28T01:49:57.000Z Apple has [published](https://security.apple.com/blog/formal-verification-corecrypto/) the source code for their `corecrypto` libraries on GitHub, along with the tools and formal verification libraries they used to evaluate their cryptography, so independent cryptography experts can verify it for themselves. `corecrypto` is, like the name suggests, the core of Apple's cryptography, providing "encryption and decryption, hashing, random number generation, and digital signatures on over 2.5 billion active devices." As such, it's important to ensure their encryption behaves the way it's supposed to. By using mathematical proofs, Apple claims it can "show that our algorithm implementations are correct to a significantly greater degree of assurance than conventional software testing allows." They say that using formal verification, they caught issues that would have slipped by otherwise: > . . . we believe the types of subtle issues that we found and fixed can be uncovered only with formal methods. And while we focused our formal verification work on functional correctness, we also used extensive conventional testing, including simulation tools to cover other aspects of our implementation, such as protection against information leakage. Based on our work to date, we believe that the strongest assurance possible comes from combining formal verification with conventional methods and critically evaluating the end-to-end results. Apple does lay out some limitations of their formal verification. For example, they assume that the compiler behaves correctly. Still, it seems like they believe they've really made some strides in formal verification, and cryptography experts can verify themselves. Anyone interested in cryptography or formal verification can check out the new [GitHub page](https://github.com/apple/corecrypto) and play around with the tooling. It's important to note that, while the source code for `corecrypto` is public, it's not open source software, since you aren't allowed to freely redistribute or modify the software: > The publication of this code is primarily intended for security research and verification purposes. The default license for the corecrypto (cc) project is the evaluation-only corecrypto Internal Use License Agreement contained in [License.txt](https://github.com/apple/corecrypto/blob/main/License.txt). The license doesn't meet the requirements of open source software, as defined by the [Open Source Initiative](https://opensource.org/osd). However, all the security benefits of public access to the source code apply. Anyone is free to analyze it themselves for bugs or errors. Hopefully more projects like WhatsApp publish the source code and formal verification tooling for their cryptography. ### The US DOJ Wants Identities and Addresses of Over 100,000 Users of a Car App URL: https://www.privacyguides.org/news/2026/05/27/the-us-doj-wants-identities-and-addresses-of-over-100-000-users-of-a-car-app/ Last updated: 2026-05-27T15:50:52.000Z The US DOJ is [demanding](https://www.forbes.com/sites/thomasbrewster/2026/05/14/government-demands-apple-and-google-identify-over-100000-users-of-car-app/) the data of all users, equating to over 100,000 people, of the EZ Lynk app over alleged violations of the Clean Air Act, which the company denies. The alleged violation is due to EZ Lynk providing "defeat devices" that allow users to bypass emissions controls in vehicles. EZ Lynk disputes that its primary purpose is to circumvent emissions laws, stating that its apps are intended to allow car owners to tweak their car and monitor its performance. In a letter to the court, first reported by [Inside EPA](https://insideepa.com/share/255042), the DOJ demanded the data of all people who purchased the device from Apple, Google, Amazon, and Walmart. This equates to hundreds of thousands of people's personal information. Inside EPA calls the move "nearly unprecedented," citing the only one other similar case from 2019 when the DOJ wanted to [identify](https://www.forbes.com/sites/thomasbrewster/2019/09/06/exclusive-feds-demand-apple-and-google-hand-over-names-of-10000-users-of-a-gun-scope-app/) about 10,000 purchasers of gun scope software. The EZ Lynk case is proceeding even as the Trump administration and the EPA have moved to [drop similar cases](https://insideepa.com/daily-news/epa-doj-drop-criminal-vehicle-tampering-cases-under-clean-air-act). Investigating the claim that EZ Lynk's devices "does not require identifying each person who has used the product." The case represents a clear overreach by the government to collect troves of personally identifiable information that's not needed. The letter to the court notes that Apple and Google oppose the request. EZ Lynk told *Inside EPA* "Our users’ privacy means everything to us, and we are fully committed to our fight to protect it.” The case shows a big everyday privacy vulnerability: when you purchase items with your credit or debit card, or sign in to your rewards account, all of your purchases can be tied back to you. Similarly, Google and Apple require an account in order to purchase and install apps from their app stores. They have a record of all the apps you have installed from their respective app stores and they could willingly provide that information or be forced to via a government subpoena. Last year in 2025, Apple and Google were sent demands from the government to take down apps such as ICEBlock that allowed people to see where ICE agents were spotted. The government could have easily demanded the personal information of anyone who downloaded the apps as well. We need better privacy protections in App Stores, especially the ability to download free apps from these stores without having to make an account first. ### CISA Leaks Secret Credentials in a Public Github Repo URL: https://www.privacyguides.org/news/2026/05/26/cisa-leaks-secret-credentials-in-a-public-github-repo/ Last updated: 2026-05-26T23:45:14.000Z Brian Krebs [reported](https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/) that a public GitHub repository with sensitive internal CISA credentials "including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets." The original discoverer, Guillaume Valadon from the security firm GitGuardian, reached out to Brian due to the owner of the repository not responding when made aware of the exposed secrets. GitGuardian scans public repositories on GitHub looking for just such information, and alerts the owners about the unintentional data exposure. The repository was ironically named "Private-CISA." Valadon expressed disbelief in an email to Brian: > Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature . . . I honestly believed that it was all fake before analyzing the content deeper. This is indeed the worst leak that I’ve witnessed in my career. It is obviously an individual’s mistake, but I believe that it might reveal internal practices. The repository, owned by a contractor and opened all the way back in 2018, was a "textbook example of poor security hygiene." The CISA administrator explicitly disabled the default setting in GitHub that prevents users from publishing SSH keys in public repositories, in an almost comical level of ineptitude. The exposed files included ones titled "importantAWSTokens" with the administrative credentials for three AWS GovCloud servers. Another file entitled "AWS-Workspace-Firefox-Passwords.csv" listed plaintext usernames and passwords for various internal CISA systems. Anyone who has a relative that puts all their passwords in a plaintext Microsoft excel document will be familiar with the internal security practices at CISA. Although grandma didn't publish her passwords on the public internet, so she's much more secure than CISA. "The use of both a CISA-associated email address and a personal email address suggests the repository may have been used across differently configured environments," observed Philippe Caturegli, founder of the security consultancy firm [Seralys](https://www.seralys.com). Caturegli validated the AWS tokens and observed that the archive included plaintext credentials for CISA's internal repository of all code packages they use to build software, a juicy target for an attacker looking to remained inside CISA's systems permanently. The public GitHub repo has now been made private. [CISA](https://www.cisa.gov) is the premier cybersecurity agency of the US. After the Tump administration, it has seen intense budget cuts and now operates with a [third](https://www.cybersecuritydive.com/news/cisa-cybersecurity-division-reorganization/812155/) of its workforce evaporated. > As the National Coordinator for Critical Infrastructure Security and Resilience, CISA works with partners at every level to identify and manage risk to the cyber and physical infrastructure that Americans rely on every hour of every day. CISA works with partners to defend against today’s threats and collaborate to build a more secure and resilient infrastructure for the future. It's no wonder then that important US [infrastructure](https://dailysecurityreview.com/security-spotlight/volt-typhoon-energy-grid-cyberattack-exposes-us-infrastructure-vulnerabilities/) has been targeted by recent cyberattacks. ### First Public Kernel Memory Exploit of on Apple's M5 Chip Found URL: https://www.privacyguides.org/news/2026/05/26/first-public-kernel-memory-exploit-of-on-apples-m5-chip-found/ Last updated: 2026-05-26T22:13:07.000Z Security researchers at [Calif](https://calif.io/#services) have found the first public memory corruption exploit on Apple's M5 chip, surviving Memory Integrity Enforcement protections. The researchers even shared the vulnerability with Apple in person at a meeting at Apple Park in Cupertino, the company's headquarters. > We wanted to report it in person, instead of getting buried in the submission flood that some unfortunate Pwn2Own participants just experienced. Most respected hackers avoid human interaction whenever possible, so this physical strategy may give us a slight edge in the eternal race for five minutes of fame and glory on Twitter. The researchers decided not to share the full technical details until Apple releases a fix for the fix for the vulnerabilities and the attack path (they already have a domain bought for the occasion). Apple's [Memory Integrity Enforcement](https://security.apple.com/blog/memory-integrity-enforcement/) (MIE) was first introduced in their M5 and A19 chips, bringing protection against memory safety vulnerabilities. These types of bugs are estimated to constitute around [70%](https://www.memorysafety.org/docs/memory-safety/#how-common-are-memory-safety-vulnerabilities) of all vulnerabilities, making them the biggest target for both attackers and defenders. MIE is Apple's implementation of a standard ARM feature called [Memory Tagging Extension](https://developer.arm.com/documentation/108035/0100/Introduction-to-the-Memory-Tagging-Extension) (MTE) designed to help developers catch memory safety bugs. > Memory Integrity Enforcement started with a deeply ambitious goal: to make it immensely more expensive and difficult to develop and maintain mercenary spyware attacks based on memory corruption against our platforms. While there’s no such thing as perfect security, MIE is designed to dramatically constrain attackers and their degrees of freedom during exploitation. The researchers found a data-only vulnerability, meaning that the attack doesn't disrupt the control flow of the program, and instead allowing the program to execute as designed. The exploit chain starts from an unprivileged local user and ends with a root shell, using only normal system calls. They used Anthropic's [Mythos Preview](https://red.anthropic.com/2026/mythos-preview/) to assist in the discovery of the bugs, an AI model that's made [headlines](https://www.nytimes.com/2026/04/07/technology/anthropic-claims-its-new-ai-model-mythos-is-a-cybersecurity-reckoning.html) for its ability to find vulnerabilities in software. MIE was designed to make a specific class of vulnerabilities much more difficult to exploit, but there are still plenty of other classes of exploits that Apple and other operating system and hardware vendors will need to contend with. The researchers describe this as just a glimpse of the "bugmageddon" to come. Defenders will need to develop more and more advanced protections with AI models now able to find security issues more efficiently than ever before. ### Discord Makes All Voice/Video Calls E2EE URL: https://www.privacyguides.org/news/2026/05/25/discord-makes-all-voice-video-calls-e2ee/ Last updated: 2026-05-25T15:18:58.000Z After Discord [announced](https://discord.com/blog/meet-dave-e2ee-for-audio-video) their DAVE end-to-end encryption protocol for audio and video calls in 2024, they’ve finally finished migrating [all](https://discord.com/blog/every-voice-and-video-call-on-discord-is-now-end-to-end-encrypted) calls to use it by default. The move was [three years](https://discord.com/blog/encryption-for-voice-and-video-on-discord) in the making, with experiments with E2EE starting all the way back in 2023. After they introduced the finished their [open-source](https://github.com/discord/libdave) [DAVE](https://discord.com/blog/meet-dave-e2ee-for-audio-video) protocol in 2024, they began migrating audio and video calls over to the new encryption. They worked closely with renowned cybersecurity consulting firm [Trail of Bits](https://www.trailofbits.com) on the design and implementation of DAVE. The migration apparently took almost two years, but it’s finally complete. It’s hard to fault Discord for taking their time to make sure it’s implemented correctly, though. As they point out, E2EE is reliant on clients in order to function properly, and Discord is available on just about all platforms under the sun. A user needs to be able to make the same E2EE call going from a laptop to a phone to a PlayStation seamlessly and without losing the security properties of the encryption. For example, when working on the web version, they ran into an issue in Firefox and had to work directly with Mozilla in order to fix the issue. It’s an approach that’s admirable: do it right the first time, so you don’t spend countless hours fixing your previous mistakes. Discord is currently in the process of completing the final steps of the migration: removing the code for unencrypted calls, after which it won’t be possible to make an unencrypted call on Discord. Text messages on Discord will remain unencrypted, with no current plans to upgrade to E2EE: > We have no current plans to extend E2EE to text messages. Many of the features people use on Discord were built on the assumption that text isn't end-to-end encrypted, and rebuilding them to work with encryption is a meaningful engineering challenge. If anything, though, I think this project shows Discord is up to the challenge if they really wanted to. It’s become a fairly standard feature in messengers to offer E2EE voice and video calls, and E2EE messaging is becoming the standard as well, especially now with the release of [E2EE support](https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/) in RCS clients. The RCS encryption uses the same standard [Messaging Layer Security](https://datatracker.ietf.org/doc/rfc9420/) that Discord chose for their calls, meaning a lot of the groundwork is already laid for encrypted messaging in the future. ### Google’s Smart Glasses Are A Privacy Disaster URL: https://www.privacyguides.org/livestreams/2026/05/22/googles-smart-glasses-are-a-privacy-disaster/ Last updated: 2026-05-29T20:53:00.000Z This Week in Privacy #54 _This post is for subscribers only._ ### Data Breach Roundup (May 15 - 21, 2026) URL: https://www.privacyguides.org/news/2026/05/22/data-breach-roundup-may-15-21-2026/ Last updated: 2026-05-22T16:39:53.000Z ## A hotel check-in system left a million passports and driver’s licenses open for anyone to see Tabiq is a used in several hotels in Japan and primarily relies on facial recognition and document scanning to check in arriving guests. The data was exposed because the Amazon S3 bucket used by Tabiq was set to public and required no password. It's unclear how that happened since S3 buckets are set to private by default. [A hotel check-in system left a million passports and driver’s licenses open for anyone to see | TechCrunchThe tech company that maintains the hotel check-in system set its cloud storage to public, allowing anyone to access customers’ data without a password.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-55.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/passport-fake-KYC.jpg)](https://techcrunch.com/2026/05/15/a-hotel-check-in-system-left-a-million-passports-and-drivers-licenses-open-for-anyone-to-see/) ## NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people This breach took place between November 2025 and February 2026 and was the result of an unnamed third-party vendor breach. Exposed data varies by individual but includes patients’ health insurance plan and policy information, medical information (such as diagnoses, medications, tests, and imagery), billing, claims, and payment information. Other government-issued identity documents including Social Security numbers, passports, and driver’s licenses were also compromised. The notice also said that "precise geolocation data" was taken, but did not elaborate. [NYC Health + Hospitals says hackers stole medical data and fingerprints during breach affecting at least 1.8 million people | TechCrunchThe New York public healthcare system said hackers stole personal and medical data, and scans of biometrics — including fingerprints — in one of the largest recorded breaches of 2026.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-56.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/ambulances-2191226563.jpg)](https://techcrunch.com/2026/05/18/nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people/) ## 7-Eleven confirms data breach claimed by the ShinyHunters gang 7-Eleven, the global convenience store chain, experienced a breach in early April. Unfortunately they haven't disclosed hardly any information such as number of victims or what data was stolen. ShinyHunters claimed the breach and claimed to have 600,000 records from Salesforce, containing "PII and other internal corporate data." [7-Eleven confirms data breach claimed by the ShinyHunters gangConvenience store chain giant 7-Eleven confirmed that its systems were breached in a cyberattack claimed by the ShinyHunters extortion group last month.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-132.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/7-Eleven-headpic.jpg)](https://www.bleepingcomputer.com/news/security/7-eleven-confirms-data-breach-claimed-by-the-shinyhunters-gang/) ## Customers say Trump Mobile is leaking their personal information Trump Mobile is Trump's upcoming branded mobile phone and service. Two YouTubers who preordered the devices for review purposes were contacted by a source who claimed to have discovered the leak, and provided their personal information to prove it. The researcher said he saw "mailing address, email address, you know, everything short of credit card number." Trump Mobile has not responded to any communications and the leak remains unfixed. [Customers say Trump Mobile is leaking their personal information | TechCrunchTrump Mobile is leaking customers’ email and home addresses but has not responded to people alerting the company of the data exposure, according to two YouTubers who said they verified that their leaked data is authentic.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-57.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/trump-mobile-t1-phone-3000px.jpg)](https://techcrunch.com/2026/05/20/customers-say-trump-mobile-is-leaking-their-personal-information/) ### Bonus Questions! Naomi Brockwell Interview URL: https://www.privacyguides.org/videos/2026/05/22/bonus-questions-naomi-brockwell-interview/ Last updated: 2026-05-22T06:56:41.000Z A few bonus questions just for members from our latest interview with Naomi Brockwell _This post is for subscribers only._ ### Dirty Frag Sequel Continues the Streak of Linux Kernel Privilege Escalation Vulnerabilities URL: https://www.privacyguides.org/news/2026/05/17/dirty-frag-sequel-continues-the-streak-of-linux-kernel-privilege-escalation-vulnerabilities/ Last updated: 2026-05-17T12:28:54.000Z [Fragnesia](https://github.com/v12-security/pocs/blob/main/fragnesia%2FREADME.md), the latest local privilege escalation vulnerability in the same family as [Dirty Frag](https://www.privacyguides.org/news/2026/05/08/two-more-major-linux-vulnerabilities-discovered-in-the-same-class-as-copy-fail/), emerges as an “unintended side effect of one of the patches addressing the original Dirty Frag vulnerabilities” according to the original creator of Dirty Frag, Hyunwood Kim. This vulnerability is another logic flaw, meaning there’s no need for attackers to exploit [memory safety](https://media.defense.gov/2022/Nov/10/2003112742/-1/-1/0/CSI%5FSOFTWARE%5FMEMORY%5FSAFETY.PDF) issues or race conditions, it’s just a problem with how the program runs normally. The vulnerability was discovered by [William Bowling](https://x.com/wcbowling?lang=en) with the [V12](https://v12.sh) team. Unlike Dirty Frag, Fragnesia requires no host-level privileges. Fragnesia also doesn’t touch files on the disk, it only modifies the in-memory page cache, so file-integrity monitoring is useless against it. [AppArmor](https://apparmor.net), such as what’s enabled by default in Ubuntu, may serve as a partial mitigation and require extra steps to successfully exploit a machine. As always, the recommendations are to install patches from your Linux distribution as quickly as possible as they’re being shipped. The flaw lies in the same XFRM ESP-in-TCP subsystem as Dirty Frag. According to [Microsoft Threat Intelligence](https://x.com/MsftSecIntel/status/2054701609024934064), the exploit corrupts the “page cache memory of the `/usr/bin/su` binary, which in turn leads to launching a shell with root privilege.” Fragnesia isn’t constrained to the `su` binary, though. “\[I\]t can modify any file readable by the user, including `/etc/passwd`.” Microsoft’s recommendations are to disable esp4, esp6, and related XFRM/IPsec functionality, restrict unnecessary local shell access, harden containerized workloads, and increase monitoring for abnormal privilege escalation activity. [*The Register*](https://www.theregister.com/security/2026/05/14/dirty-frag-gets-a-sequel-as-fragnesia-hands-linux-attackers-root-level-access/5240270) describes the situation quite nicely: > The Linux networking stack is starting to look less like infrastructure and more like a root exploit vending machine. It’s hard to disagree. When so many severe vulnerabilities of the same class appear in such quick succession, this one even allegedly caused by a patch of a previous vulnerability, it starts to look like a systemic failure. ### From Content Creator to Policymaker: Naomi Brockwell Interview URL: https://www.privacyguides.org/videos/2026/05/16/from-content-creator-to-policymaker-naomi-brockwell-interview/ Last updated: 2026-05-21T21:02:11.000Z Naomi Brockwell is one of the most well-known educators in the privacy space today, and recently she’s begun using that voice to influence legislation here in the US that could be a significant step in regaining our privacy as citizens – by default. ### Data Breach Roundup (May 8 - 14, 2026) URL: https://www.privacyguides.org/news/2026/05/16/data-breach-roundup-may-8-14-2026/ Last updated: 2026-05-16T00:05:41.000Z ## Zara data breach exposed personal information of 197,000 people Zara is a Spanish fast-fashion retailer that operates over 1,500 stores worldwide. The company has yet to confirm any major details, but says that names, phone numbers, addresses, credentials, and payment data are safe. Have I Been Pwned analyzed the data exposed so far and said it contains email addresses, geographic locations, purchases, and support tickets. [Zara data breach exposed personal information of 197,000 peopleHackers who gained access to the databases of Spanish fast-fashion retailer Zara stole data belonging to more than 197,000 customers, according to data breach notification service Have I Been Pwned.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-122.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Zara_headpic_red.jpg)](https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/) ## NVIDIA confirms GeForce NOW data breach affecting Armenian users GeForce NOW is a cloud gaming services, allowing users to run games on more powerful hardware in a data center rather than local computers. Exposed data includes full name (if using a Google account), email address, phone number (if registered through a mobile operator), date of birth, and username. Users registered after March 9 are not impacted. [NVIDIA confirms GeForce NOW data breach affecting Armenian usersNVIDIA has confirmed in a statement for BleepingComputer that GeForce NOW user information has been exposed in a data breach.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-123.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/NVIDIA.jpg)](https://www.bleepingcomputer.com/news/security/nvidia-confirms-geforce-now-data-breach-affecting-armenian-users/) ## US bank reports itself after slinging customer data at 'unauthorized AI app' Community Bank - which serves Pennsylvania, Ohio, and West Virginia - filed a data breach notification with regulators, saying that sensitive data was accidentally leaked to an unauthorized AI. We know that names, dates of birth, and Social Security numbers were impacted but we don't know how many customers were affected, which AI was used, or even the exact details of the incident. [US bank reports itself after slinging customer data at ‘unauthorized AI app’Volume and sensitivity of the data cited as chief concerns![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-126.png)theregisterConnor Jones![](https://www.privacyguides.org/content/images/thumbnail/5238826.jpg)](https://www.theregister.com/security/2026/05/12/us-bank-reports-itself-after-ai-customer-data-mishap/5238787) ## Škoda warns of customer data breach after online shop hack The Czech carmaker has reported a breach of their online store that allowed attackers to access data. Data includes names, addresses, contact information, phone numbers, order information, and login credentials (passwords were hashed). It does include financial information and the company has not disclosed how many were impacted. [Škoda warns of customer data breach after online shop hackŠkoda Auto, a wholly owned subsidiary of the Volkswagen Group, has disclosed a data breach after attackers hacked its online shop and stole the personal information of an undisclosed number of customers.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-124.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Skoda.jpg)](https://www.bleepingcomputer.com/news/security/skoda-warns-of-customer-data-breach-after-online-shop-hack/) ## UK fines water supplier $1.3M for exposing data of 664k customers This is an update to a story from 2022\. South Staffordshire Water Plc was attacked by the Cl0p ransomware gang at the time and leaked customer data going back to 2020\. The fine was for "significant failures in the company's approach to data security and left customers and employees vulnerable for nearly two years.” [UK fines water supplier $1.3M for exposing data of 664k customersThe Information Commissioner’s Office has fined South Staffordshire Water Plc and parent company South Staffordshire Plc £963,900 ($1.3 million) over a cyberattack that exposed the personal data of 663,887 customers and employees.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-125.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/UK-ICO.jpg)](https://www.bleepingcomputer.com/news/security/uk-fines-water-supplier-13m-for-exposing-data-of-664k-customers/) ### BitLocker Bypass Found In Latest Series of Windows Vulns URL: https://www.privacyguides.org/news/2026/05/15/bitlocker-bypass-found-researcher-warns-of-more-unreleased-vulnerabilities/ Last updated: 2026-05-15T22:06:02.000Z An anonymous security researchers known as Nightmare-Eclipse has published two more Windows zero-day exploits, [YellowKey](https://github.com/Nightmare-Eclipse/YellowKey) and [GreenPlasma](https://github.com/Nightmare-Eclipse/GreenPlasma), after already publishing 3 earlier this year. The researcher didn't follow standard coordinated vulnerability disclosure procedures and instead published the vulnerabilities publicly on GitHub, a practice that leaves users open to being exploited while the software developers scramble to fix the issue. The researcher describes YellowKey, a BitLocker bypass, as "one of the most insane discoveries I ever found." They go on to speculate that it "almost feels like a **backdoor** but what do you know, maybe I'm just insane." The vulnerability can be performed simply by copying a folder from the YellowKey GitHub onto either an external storage device or directly onto the EFI partition of the main drive. Boot into the Windows Recovery Environment Agent by holding Shift and clicking restart, holding CTRL as it boots up, and you will be presented with a shell that has "unrestricted access to the bitlocker protected volume." > Now why would I say this is a **backdoor** ? The component that is responsible for this bug is not present anywhere (even in the internet) except inside WinRE image and what makes it raise suspicions is the fact that the exact same component is also present with the exact same name in a normal windows installation but without the functionalities that trigger the bitlocker bypass issue. Why ? I just can't come up with an explanation beside the fact that this was intentional. Also for whatever reason, only windows 11 (+Server 2022/2025) are affect, windows 10 is not. It's bizarre that only more recent versions of Windows are affected. While the bug does require physical access to the machine, it's still quite alarming since BitLocker is primarily designed to protect against attackers with physical access to your computer. Supposedly, you can prevent the vulnerability by adding a [PIN](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/configure?tabs=os#require-additional-authentication-at-startup) to your TPM instead of using BitLocker in TPM only mode. The second vulnerability is a privilege escalation vulnerability, which they didn't release a full Proof-of-Concept for, leaving it as a "huge challenge for CTF lovers out there." Previously released exploits include [UnDefend](https://github.com/Nightmare-Eclipse/UnDefend), a tool to stop Windows Defender from getting signature updates, and [RedSun](https://github.com/Nightmare-Eclipse/RedSun), another Windows Defender exploit. > When Windows Defender realizes that a malicious file has a cloud tag, for whatever stupid and hilarious reason, the antivirus that's supposed to protect decides that it is a good idea to just rewrite the file it found again to it's original location. The PoC abuses this behaviour to overwrite system files and gain administrative privileges. These exploits are still [unfixed](https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/5239758) according to *The Register*. Make sure to keep your Windows machines updated and locked down as much as possible. ### Android 17 Is Looking Great for Privacy & Security URL: https://www.privacyguides.org/livestreams/2026/05/15/android-17-is-looking-great-for-privacy-security/ Last updated: 2026-05-29T20:52:45.000Z This Week in Privacy #53 _This post is for subscribers only._ ### Help Defeat Censorship - How To Run A Signal Proxy URL: https://www.privacyguides.org/videos/2026/05/14/help-defeat-censorship-how-to-run-a-signal-proxy/ Last updated: 2026-05-14T17:00:29.000Z Signal is a great option to protect the privacy of your messages, but due to it's centralization it can be easily blocked by governments. In this video we'll explain how you can setup a Signal Proxy to help people access Signal in countries where Signal is blocked. #### Sources 1:10 1:21 4:40 7:03 7:21 10:26 10:53 11:09 11:39 ### Android Introduces New Privacy and Security Protections, with a Focus on Agentic AI URL: https://www.privacyguides.org/news/2026/05/13/android-introduces-new-privacy-and-security-protections-with-a-focus-on-agentic-ai/ Last updated: 2026-05-13T16:09:08.000Z Android has [introduced](https://blog.google/security/whats-new-in-android-security-privacy-2026/) some new protections against scammers and malware, some powered by agentic AI. One of the main targets of these new protections are bank scams. Scammers often spoof their caller ID to look like they’re from your bank or another trusted business. When a scammer is calling you as your bank, Android can now ask your bank app if it is calling you. If the bank’s app confirms it’s not calling you, Android will end the call. Banks can now also designate numbers as inbound-only, meaning they’ll never be used to call customers. Any incoming calls from these numbers will also be ended. Some of the bank apps that will be participating in the new system are Revolut, Itaú and Nubank, with more banks expected in the future. Google is also expanding its live threat detection to analyze app behavior to try and determine if an app is behaving suspiciously. When an app forwards a message to another number with the accessibility overlay, where information is being continuously displayed that ”could be used to trick you into taking an unintended action.” Google calls this “dynamic signal monitoring.” It will monitor for suspicious behaviors an app performs on the system like opening itself in the background, abusing accessibility permissions, or changing its icon. Google says they can also push new rules out to Android phones as new threats emerge. [USB protection](https://support.google.com/android/answer/16778864?hl=en) stops attackers from accessing your USB port when your screen is locked. Currently it’s supported on all Pixel devices running Android 16+, with more supported devices coming in the future. Their new Intrusion Logging system will “enable persistent and privacy-preserving forensics logging to allow for investigation of devices in the event of a suspected compromise.“ They developed the feature in concert with Amnesty International and Reporters Without Borders. This feature should allow for more effective investigations when a devices is suspected to be compromised. Advanced Protection mode will now also remove accessibility permissions from apps that aren’t labeled as accessibility tools. Android will now be enabling the anti theft protections they [announced](https://blog.google/security/android-theft-protection-feature-updates/) earlier this year by default as well. You’ll be able to grant temporary location permissions to an app while it’s being used. Google has also now confirmed the new contact picker in this announcement, bringing the ability to give apps access to individual contacts instead of your entire contacts list. Apps with the SMS permission will also now have to wait three hours before they can access time-sensitive SMS OTP codes, since malicious apps sometimes steal these codes to get into your sensitive accounts. Google describes Android as moving from an operating system to an “intelligence system.” As such, a lot of agentic AI features are being rolled out, which infamously have huge potential to impact [security](https://www.privacyguides.org/news/2026/01/16/trail-of-bits-exposes-vulnerabilities-in-agentic-browsers-compares-to-cross-site-scripting/). To combat this, Google has implemented [security](https://blog.google/security/android-gemini-intelligence-security-privacy/) protections for its Gemini Intelligence features. Firstly, you can opt-in or out of each feature individually. There are permission screens to allow access to apps. Google is using their [Private Compute Core](https://security.googleblog.com/2022/12/trust-in-transparency-private-compute.html), [protected KVM](https://security.googleblog.com/2025/08/Android-pKVM-Certified-SESIP-Level-5.html), and for remote AI, [Private AI Compute](https://blog.google/innovation-and-ai/products/google-private-ai-compute/) to secure the data processed by both local and remote AI. It’s unclear exactly *what* features are protected by which features though. For example, their announcement of Private AI Compute only mentioned the Recorder app making use of it. Chrome’s agentic features released for desktop are now coming to Android, bringing the same potential for exploitation. Google says they’ve implemented safeguards, but the language is a bit vague. Overall, Android 17 is getting some exciting security upgrades, but the agentic future of Android leaves unanswered questions about what data is processed securely and how to protect yourself against prompt injection attacks or even just AI performing actions you didn’t want it to. ### Data Breach Roundup (May 1 - May 7, 2026) URL: https://www.privacyguides.org/news/2026/05/11/data-breach-roundup-may-1-may-7-2026/ Last updated: 2026-05-11T22:31:31.000Z ## Instructure confirms data breach, ShinyHunters claims attack Instructure is an ed-tech giant best known for Canvas, a "learning management" system used by schools at all levels to help manage coursework, assignments, and online learning. Attackers claim to have taken over 240 million records tied to students, teachers, and staff containing names, email addresses, enrolled courses, and private messages. If true, evidence suggests the dataset spans 15,000 institutions in North America, Europe, and Asia. At this time little else has been said, but attackers have also been causing downtime on the platform itself, disrupting students as finals are right around the corner. [Instructure confirms data breach, ShinyHunters claims attackEducational tech giant Instructure has confirmed that data was stolen in a cyberattack, with the ShinyHunters extortion gang claiming responsibility.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-115.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/instructure-canvas.jpg)](https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/) ## Trellix discloses data breach after source code repository hack Trellix is a cybersecurity firm formed after the 2021 merger of McAfee and FireEye. Trellix has disclosed that some source code was accessed, but has not confirmed if attackers had stolen any customer data or sent a ransom demand. [Trellix discloses data breach after source code repository hackCybersecurity firm Trellix disclosed a data breach after attackers gained access to “a portion” of its source code repository.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-116.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/trellix.jpg)](https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/) ## Vimeo data breach exposes personal information of 119,000 people A small update to a story from last week. While Vimeo still hasn't officially confirmed how many victims this attack impacted, Have I Been Pwned says it uploaded the email addresses of 119,200 people. Vimeo says that credentials and financial information were not impacted. [Vimeo data breach exposes personal information of 119,000 peopleThe ShinyHunters extortion gang stole personal information belonging to over 119,000 people after hacking the Vimeo online video platform in April, according to data breach notification service Have I Been Pwned.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-117.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Vimeo-headpic.jpg)](https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/) ### Utah Targets VPNs for Age Verification URL: https://www.privacyguides.org/news/2026/05/11/utah-targets-vpns-for-age-verification/ Last updated: 2026-05-11T14:18:34.000Z Governor Spencer Cox has signed a [law](https://www.eff.org/deeplinks/2026/04/utahs-new-law-regulating-vpns-goes-effect-next-week) stating that websites are accountable for determining if a user is physically located in Utah, even from behind a VPN. The law doesn’t explicitly ban VPNs but it states that anyone physically located in Utah, even if behind a VPN, they must be subject to age verification. This poses a technical challenge for websites on how they’re supposed to verify someone is physically in Utah. While not a full ban, it encourages websites to block VPNs since it could pose a legal risk to them in case someone is physically located in Utah. Even trying to block all VPNs and proxies would be difficult, the EFF describes it as “technical whack-a-mole.” There are plenty of protocols designed to bypass blocking and make traffic look like regular user traffic. [Shadowsocks](https://shadowsocks.org) is widely used in China to bypass the Great Firewall. The MASQUE protocol, and IETF standard, utilizes standard QUIC connections to proxy your connections. [Trusttunnel](https://trusttunnel.org), a newer protocol, disguises your traffic as regular Chrome traffic, among many other privacy features to make your VPN traffic hard to detect. Not to mention that, even without a VPN, IP address geolocation is extremely unreliable. There‘s nothing inherently tying a particular IP address to a specific location, so websites can often be completely wrong while trying to geolocation you via IP address. Laws like these are impossible to enforce and put websites in an impossible position. Instead of admitting that the current approach to age verification is unworkable, lawmakers continue doubling down and trying to close “loopholes” by brute force. While age verification laws aren’t new, this law sets a dangerous precedent in the US. VPNs are a target of lawmakers looking to enforce age verification because they can make you look like you’re somewhere you’re not. When you connect to a website via a [VPN](https://www.privacyguides.org/en/basics/vpn-overview/?h=vpn), the site will see the IP address of your VPN server and not your real IP address assigned to you by your Internet Service Provider. Many sites decide whether they will perform age verification based on where the IP address connecting to them appears to be, so VPNs can be an effective method of bypassing these restrictions. They’re also commonly used tools to protect the privacy of their users. This law threatens VPN users as a whole because websites will now need to be suspicious of all VPN traffic in case some of those users are physically located in Utah. ### Canvas System Used by Over 40% of US Schools Breached URL: https://www.privacyguides.org/news/2026/05/09/canvas-system-used-by-over-40-of-us-schools-breached/ Last updated: 2026-05-09T17:49:06.000Z Canvas, software used by thousands of schools in the U.S., has been [hacked](https://www.pbs.org/newshour/nation/canvas-system-used-by-thousands-of-schools-is-back-online-after-a-cyberattack-created-chaos) and the private data of staff and students stolen. A hacker group called ShinyHunters claims credit for the hack. Large educational institutions like Columbia, Princeton, Harvard, and Georgetown were met with ransom notes on the homepage of their Canvas sites. Instructure, the company behind Canvas, received a ransom note from the group saying that data on millions of users including students, teachers, and staff would be leaked if they didn’t pay up. An unnamed source told [CNN](https://www.cnn.com/2026/05/07/us/canvas-hack-strands-college-students-finals-week) that the FBI has deployed resources to help institutions deal with the situation. As if the data breach itself wasn’t enough, the FBI also warned of scammers contacting those affected claiming to have their data. According to the same CNN article, Instructure says Canvas is “fully calm online and available for use” Friday. Data obtained by the hackers included 275 million users’ users names, email addresses, student ID numbers, and billions of private messages. Apparently, the threat actors had exploited an issue with Instructure’s [Free-for-Teachers](https://www.instructure.com/try-canvas) accounts. Instructure has temporarily disabled this feature in light of the hack. As you can imagine, the hack has caused a huge disruption to educational institutions that are already spread thin as it is. Exams had to be cancelled as teachers waited for a fix. Centralized cloud platforms like Canvas create a central point of failure where all of their customers data and the functionality of their software relies on Instructure being up and running. It also creates a massive central pool of data that makes a very attractive target for hackers. As school rely more and more on complex centralized software for their functions and as surveillance on students becomes more and more common, the risks of data breaches will continue to grow. Schools for years now have been using [software](https://www.eff.org/deeplinks/2024/09/school-monitoring-software-sacrifices-student-privacy-unproven-promises-safety) to collect and monitor keystrokes, communications, photos, and much more. Sensitive data collected by the software can include private communications, passwords, and sensitive images. Such software doesn’t protect students and simply creates a bigger target for hackers. Schools have a duty to protect the data of their students, but they’re floundering at the first hurdle. If you’re a student, it’s always a good idea to practice separation between school activities and personal ones. If you have a school-issued device, don’t use it for anything not school related. If you’re forced to install invasive software on a personal device, have one dedicated to school activities and one for personal use. ### Healthcare Marketplaces Shared Sensitive Data With Advertisers URL: https://www.privacyguides.org/news/2026/05/09/healthcare-marketplaces-shared-sensitive-data-with-advertisers/ Last updated: 2026-05-09T12:00:17.000Z A new investigation from [Bloomberg ](https://www.bloomberg.com/features/2026-healthcare-advertising-trackers-privacy/) has revealed how state-run health insurance marketplaces have - often accidentally - been sharing sensitive data with tech giants. The United States healthcare landscape is complicated. The healthcare system is largely privatized. Many employers offer health insurance to full-time employees, while those not covered can either purchase private insurance or sometimes qualify for government-subsidized plans. Those who aren't provided insurance by their employer often use state-sponsored portals - such as healthcare.gov - to see available plans. In about 20 US states, the state offers a similar service (which healthcare.gov can direct users from those states to). Bloomberg has since discovered that nearly all state-run health insurance marketplaces contain analytics trackers that send sensitive data back to Big Tech companies and advertisers. For example, they found that a Washington applicant's sex, citizenship status, and sometimes race were sent to TikTok. In New York, the pages visited were sent to Meta, Snap, and LinkedIn. The culprit are "pixels" provided by companies like Meta, TikTok, and others. The pixels provide analytics insight to site administrators but also collect data for the parent company to collect for advertising. Many of these companies claim not to collect sensitive, protected data - such as race and religion - but Bloomberg found many of these filters were ineffective at filtering out such data in all cases. This is not a new problem. Since 2022, [The Markup](https://themarkup.org/series/pixel-hunt) has extensively covered situations exactly like this - multiple organizations (including healthcare marketplaces) using tracking pixels for analtyics purposes but companies also getting copies of extremely sensitive data. ### CalyxOS Is (Almost) Back But Is It Any Better? URL: https://www.privacyguides.org/livestreams/2026/05/08/calyxos-is-almost-back-but-is-it-any-better/ Last updated: 2026-05-16T00:06:10.000Z This Week in Privacy #52 _This post is for subscribers only._ ### Two More Major Linux Vulnerabilities Discovered in the Same Class as Copy Fail URL: https://www.privacyguides.org/news/2026/05/08/two-more-major-linux-vulnerabilities-discovered-in-the-same-class-as-copy-fail/ Last updated: 2026-05-08T18:18:12.000Z Two new Linux local privilege escalation vulnerabilities, [Dirty Frag](https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md) and [Copy Fail 2: Electric Boogaloo](https://github.com/0xdeadbeefnetwork/Copy%5FFail2-Electric%5FBoogaloo) were discovered in the same vulnerability class as [Copy Fail](https://copy.fail), affecting most Linux distributions. “Dirty Frag is a vulnerability (class) that achieves root privileges on most Linux distributions by chaining the xfrm-ESP Page-Cache Write vulnerability and the RxRPC Page-Cache Write vulnerability.” The exploit is also a successor of the [Dirty Pipe](https://dirtypipe.cm4all.com) vulnerability. According to the writeup, the patch for the Copy Fail vulnerability won’t help with Dirt Frag, since it can be triggered whether or not `algif_aead` is available. The vulnerability utilizes in-place cryptography just like Copy Fail. Dirty Frag is actually two vulnerabilities chained together. The exploit author, Hyunwoo Kim, explains further: > RxRPC Page-Cache Write does not require the privilege to create a namespace, but the `rxrpc.ko` module itself is not included in most distributions. For example, the default build of RHEL 10.1 does not ship `rxrpc.ko`. However, on Ubuntu, the `rxrpc.ko` module is loaded by default. > Chaining the two variants makes the blind spots cover each other. In an environment where user namespace creation is allowed, the ESP exploit runs first. Conversely, on Ubuntu where user namespace creation is blocked but `rxrpc.ko` is built, the RxRPC exploit works. Both bugs have now been assigned CVEs, CVE-2026-43284 and CVE-2026-43500 respectively, however there is only a [patch](https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4) for the xfrm-ESP Page-Cache Write vulnerability. Another [vulnerability](https://github.com/0xdeadbeefnetwork/Copy%5FFail2-Electric%5FBoogaloo) in a similar vein was found in a different subsystem. > Unprivileged Linux LPE via xfrm ESP-in-UDP MSG\_SPLICE\_PAGES no-COW fast path. Page-cache write into any readable file. Overwrites a nologin line in `/etc/passwd` with `sick::0:0:...:/:/bin/bash` and `su`s into it. Same class as Copy Fail (CVE-2026-31431), different subsystem. They list current versions of Ubuntu, Debian, Arch, and Fedora as being vulnerable. For now, make sure to update your system and check with your distribution to see any steps you might need to take to prevent exploitation. So many high-severity bugs in such a short time is alarming. GrapheneOS stated that they aren’t vulnerable to all three of the recent bugs: > GrapheneOS isn't vulnerable to the 3 recently disclosed Linux kernel vulnerabilities named Copy Fail, Copy Fail 2 and Dirty Frag. Current Android Open Source Project SELinux policies block exploiting all 3 bugs. Standard AOSP GKI kernel configuration also has 2/3 of the… > > — GrapheneOS (@GrapheneOS) [May 8, 2026](https://twitter.com/GrapheneOS/status/2052546809248059435?ref%5Fsrc=twsrc%5Etfw) Perhaps the Linux kernel maintainers and Linux distributions could do more to protect their users against such attacks before they’re found. ### Chrome for Android Now Supports Approximate Location URL: https://www.privacyguides.org/news/2026/05/07/chrome-for-android-now-supports-approximate-location/ Last updated: 2026-05-07T23:00:15.000Z Google [announced](https://blog.google/products-and-platforms/products/chrome/approximate-location-chrome-on-android/) that “you can now choose to share your approximate location with websites, instead of sharing precise location” on Chrome for Android. Websites can ask for your location for a variety of purposes whether it‘s to make a delivery or to give you real-time directions. Some uses don’t require your exact location though, like checking your local weather. For those times, you can now provide a general location instead. Both [iOS](https://support.apple.com/en-us/102647) and [Android](https://support.google.com/accounts/answer/3467281?hl=en) have supported approximate location at the OS level for a while. However, browsers strangely lack this feature. Google says the feature will come to desktop “in the coming months.” > We’re also planning to release new APIs for web developers that will let them request approximate location or specify if they need precise location. We encourage developers to review their location needs and only ask for precise location when it’s required for the site functionality. Google had a proposal for an [Approximate Geolocation API](https://github.com/explainers-by-googlers/approximate-geolocation) as a standard browser feature for a while. Google has several APIs that only work in Chromium-based browsers for now, such as the [Battery Status API](https://developer.mozilla.org/en-US/docs/Web/API/Battery%5FStatus%5FAPI) that let websites see how much battery you have and the [Device Memory API](https://developer.mozilla.org/en-US/docs/Web/API/Device%5FMemory%5FAPI) that lets sites see approximately how much memory you have. As you can imagine, these can be privacy concerns, especially in regards to fingerprinting. It’s no surprise that other browser vendors haven’t adopted them. It seems that Mozilla is [undecided](https://github.com/mozilla/standards-positions/issues/1398) on whether they support the standard or now, but WebKit has now come out as publicly [supporting](https://webkit.org/standards-positions/#position-470) it. This is good news for support for this feature in more browsers in the future. It only makes sense to support approximate location in browsers given it already exists for apps on iOS and Android. Websites are much less trusted than installed apps and as such they should have the least possible data on you in order to function. Apps have been [found](https://www.wired.com/story/gravy-location-data-app-leak-rtb/), even unintentionally, to leak your location data to analytics companies and allow cross-app location tracking. For websites, there are even more untrusted parties involved. Think of every site you visit, and how many of them randomly ask for your location. It can be very easy to unintentionally reveal your precise movements to a lot of parties. This permission is a huge privacy win and I hope we can see widespread adoption soon. I’m not sure what Mozilla’s holdout is, but they should take another look and make a decision. ### Proton Mail Launches Post Quantum Encryption URL: https://www.privacyguides.org/news/2026/05/07/proton-mail-launches-post-quantum-encryption/ Last updated: 2026-05-07T17:42:19.000Z Proton Mail [now](https://proton.me/blog/introducing-post-quantum-encryption) offers post-quantum encryption to protect against future threats from quantum computers. The rise of quantum computers could pose a potential risk to our current encryption algorithms. So far, no quantum computer exists that's powerful enough to break our current encryption, but algorithms already exist that, given a powerful enough quantum computer, could break our current encryption algorithms. Google has recently [moved](https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/) it’s deadline for implementing post-quantum encryption to 2029, a goal they admit is ambitious. The NSA set a [deadline](https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA%5FCNSA%5F2.0%5FALGORITHMS.PDF) for transition to PQC for 2033, already an ambitious goal. The reason for the urgency even though quantum computers capable of breaking our current encryption are likely years away is due to an attack called [*harvest now, decrypt later*](https://thequantuminsider.com/2026/05/01/harvest-now-decrypt-later-why-should-you-care/). Encrypted data you send now over the internet can be stored and decrypted later when quantum computers catch up. Proton has now joined Google, Apple, and many other companies in transitioning to PQC in their products. The feature is being rolled out to all plans gradually in Proton Mail, so if you don’t see the feature yet, it will be available soon. Proton says they’re adding support for OpenPGP v6, a newer version of the standard that supports modern encryption algorithms and PQC. > We are also standardizing quantum-safe encrypted email across the open email ecosystem, including with projects such as Thunderbird, so these protections can work between providers — not just within Proton — and help people stay safe no matter which email service they use. Proton says that for now, you won’t be able to re-encrypt emails that were encrypted with non-PQC. You can check if the feature is available for you and [enable](https://proton.me/support/mail-post-quantum-protection) it now if you want to. There’s been issues with the new OpenPGP standards, with [LibrePGP](https://librepgp.org) rejecting some of the suggested improvements to the OpenPGP standard and creating their own standard based on the previous version. Hopefully this doesn’t create too much of a rift in the PGP landscape and email clients can agree that improved cryptography and other features are important for the future of secure email. Since Proton says they’re working with popular email clients, I hope we can see wider adoption of PQC in email clients going forward. ### FTC to Ban Data Broker From Selling Location Data URL: https://www.privacyguides.org/news/2026/05/07/ftc-to-ban-data-broker-from-selling-location-data/ Last updated: 2026-05-07T12:00:44.000Z The FTC will ban Kochava and subsidiary Collective Data Solutions (CDS) from selling the location data of American consumers without explicit consent as part of a settlement stemming from a lawsuit from August 2022. According to [Bleeping Computer](https://www.bleepingcomputer.com/news/security/ftc-to-ban-data-broker-kochava-from-selling-americans-location-data/), the FTC brought the lawsuit in response to Kochava selling precise location data from "hundreds of millions" of mobile devices. This included sensitive locations like mental health clinics, addiction recovery facilities, reproductive health clinics, houses of worship, and domestic abuse or homeless shelters. The FTC alleged that consumers were unaware and had not consented. Kochava countersued the FTC for overreach but still announced it would introduce a "Privacy Block" feature, which would block sensitive locations from being collected. Under the settlement - if approved - Kochava and CDS would not be allowed to sell location data unless they have "affirmative express consent," and even then the data can only be used to provide "a service that the consumers directly requested." In addition, the companies must also implement a program to verify consumer consent, establish a "sensitive location data" program, submit incident reports to the FTC, and allow consumers to opt out and request who received their data. Bleeping Computer notes that in 2024 the FTC also banned InMarket Media, Outlogic (formerly X-Mode Social), Gravy Analytics, and Mobilewalla from tracking American location data. ### Disneyland California Rolls Out Facial Recognition URL: https://www.privacyguides.org/news/2026/05/06/disneyland-california-rolls-out-facial-recognition/ Last updated: 2026-05-06T20:09:35.000Z Disney has [announced](https://www.theguardian.com/us-news/2026/apr/28/disneyland-entrance-facial-recognition) plans to roll out optional facial recognition software in their world-famous California theme park. Disney theme parks are collectively the most visited in the world, with over 173 million visitors in [2024](https://en.wikipedia.org/wiki/Disneyland). The company says the technology will help prevent fraud and streamline re-entry. For example, it could be used to crack down on sharing of annual passes. They say that it will be optional and visitors can chose lanes not equipped with the technology. Disney previously trialed the technology at their more popular Magic Kingdom theme park in Florida in 2024. ### Apple Confirms RCS E2EE Will Ship with iOS 26.5 URL: https://www.privacyguides.org/news/2026/05/05/apple-confirms-rcs-e2ee-will-ship-with-ios-26-5/ Last updated: 2026-05-05T01:19:12.000Z 9to5mac [spotted](https://9to5mac.com/2026/05/04/apple-confirms-ios-26-5-messages-app-adds-rcs-end-to-end-encryption/) in the release notes of iOS 26.5 RC confirmation that the long-awaited RCS end-to-end encryption feature will ship with iOS 26.5. For many years, if you wanted E2EE messaging between iOS and Android, you needed to install a separate secure messenger like Signal instead of your default messaging app. That's because for a long time, cross-platform messaging between iOS and Android still used SMS and MMS, ancient unencrypted protocols from the [1990](https://www.mobivity.com/mobivity-blog/a-brief-history-of-text-messaging)'s. iMessage has offered E2EE messaging between iOS users since [2011](https://www.cbsnews.com/news/apple-to-launch-imessage-on-wednesday-forget-texting/) when it launched, and Google had E2EE between users of [Google Messages](https://support.google.com/messages/answer/10252671?hl=en). Notably, Google Messages uses the [RCS](https://www.gsma.com/solutions-and-impact/technologies/networks/rcs/) standard, a next-generation texting protocol that was meant to replace SMS. However, the standard didn't support E2EE, so Google made their own in-house [encryption](https://www.gstatic.com/messages/papers/messages%5Fe2ee.pdf) based on the Signal protocol. In September 2024, the GSMA released a [post](https://www.gsma.com/newsroom/article/rcs-nowin-ios-a-new-chapter-for-mobile-messaging/) celebrating Apple's recent support for RCS messaging in iOS 18, and hinting at future "interoperable end-to-end encryption" for RCS. In March 2025, they [announced](https://www.gsma.com/newsroom/article/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging/) the release of Universal Profile 3.0 and with it the promised RCS E2EE based on the [MLS](https://www.ietf.org/blog/mls-secure-and-usable-end-to-end-encryption/) standard. Then, all we needed was to wait for Apple and Google to support the new standard. Code was [spotted](https://www.androidauthority.com/apple-ios-26-rcs-end-to-end-encryption-mls-protocol-3588258/) later that year suggesting iOS 26 would bring the new upgrade, but when iOS 26 rolled around, no dice. A user spotted more hints that Apple was testing out the new encryption in the iOS [26.3 beta](https://www.privacyguides.org/news/2026/01/13/encrypted-rcs-spotted-in-ios-26-3-beta/), but no such luck when it released. Then in the iOS 26.4 beta, the [feature](https://www.privacyguides.org/news/2026/02/19/apple-introduces-end-to-end-encrypted-rcs-messaging-in-the-ios-26-4-beta/) finally made an appearance, but in the final release, it wasn't there. The [iOS 26.5 beta](https://www.privacyguides.org/news/2026/03/31/ios-26-5-beta-supports-rcs-end-to-end-encryption/) also had it but we didn't know whether it would make it to the final version. Now we finally know for sure to expect it to stick around. This isn't the end of the story unfortunately. Carriers still need to support the new encryption in order for it to work. Information about which carriers support E2EE is expected to show up on [this](https://support.apple.com/en-us/109526) page when the update finally ships, so check there to see if your carrier supports it. What specific features will be supported isn't clear either. Most E2EE messengers, including iMessage, offer some way to verify your keys so that you can be sure you're messaging the right person. There have also been several new versions of the Universal Profile since Apple has been working on E2EE. Universal Profile 4.0 has now [released](https://www.gsma.com/newsroom/article/from-rich-text-to-video-rcs-universal-profile-4-0-has-arrived/), so there's plenty of improvements to be made to the messages app after this. With so many parties involved, it might take a while before they all support it however. ### Fedora Sealed Bootable Container Images, Possibly Opening the Door to a “Fully Verified Boot Chain” URL: https://www.privacyguides.org/news/2026/05/04/fedora-sealed-bootable-container-images-possibly-opening-the-door-to-a-fully-verified-boot-chain/ Last updated: 2026-05-04T17:05:13.000Z Fedora 44 has released, and with it comes a new offering: [sealed bootable container](https://planet.kde.org/siosms-blog-2026-04-27-sealed-fedora-atomic-desktop-bootable-container-images/) images, which “include all the components needed to create a fully verified boot chain.” UEFI [Secure Boot](https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-secure-boot) is a feature available on most computers nowadays designed to prevent rootkits and malware persistence on your machine. Whenever your machine boots, Secure Boot is designed to check each part of the system as it boots in order to prevent malware from loading instead of trusted firmware/software. The process relies on what’s called a [chain of trust](https://en.wikipedia.org/wiki/Chain%5Fof%5Ftrust), where each component verifies the next component once it’s been verified. The chain begins with the [root of trust](https://trustedcomputinggroup.org/about/what-is-a-root-of-trust-rot/), which all of the other steps in the chain of trust rely on. In most devices, the [TPM](https://trustedcomputinggroup.org/about/what-is-a-trusted-platform-module-tpm/) chip provides this root of trust. The TPM is a hardware chip that provides several security functions that benefit from hardware-based protection, including handling cryptographic keys. Most operating systems offer some version of this idea, although there’s many names for it and various implementations. In [Windows](https://learn.microsoft.com/en-us/windows/security/operating-system-security/system-security/trusted-boot), Secure Boot verifies everything up to the bootloader, and then Trusted Boot takes over and verifies the kernel and every other part of the boot process. In [macOS](https://support.apple.com/guide/security/boot-process-secac71d5623/1/web/1), the full process is called Secure Boot. The root of trust is the Boot ROM and it verifies all the way up to the [Signed System Volume](https://support.apple.com/guide/security/signed-system-volume-security-secd698747c9/1/web/1) which verifies the integrity of the OS. In [Android](https://source.android.com/docs/security/features/verifiedboot), Verified Boot is instead what handles this. It starts with the hardware-protected root of trust to the bootloader, to the `system`, `vendor`, and optionally the `oem` partitions. [GrapheneOS](https://grapheneos.org/features#anti-persistence) extends Android’s verified boot with enhanced security, reduced attack surface, and allowing it to also verify out-of-band updates to APKs. Previously on most desktop Linux distributions, you could verify the bootloader and the kernel with Secure Boot. But, the rest of the file system isn’t verified. These new sealed bootable container images on Fedora 44 promise to provide a “fully verified boot chain” utilizing systemd as the bootlaoder, [Unified Kernel Images](https://wiki.archlinux.org/title/Init), and a composefs repository with [fs-verity](https://docs.kernel.org/filesystems/fsverity.html) enabled. This could theoretically allow the filesystem to be verified on an immutable system like Fedora Silverblue. For now, the images are only available as test images and they’re not signed with the official keys from Fedora. They’re also only available as containers and not ISO images that you can boot from on baremetal hardware, but it’s an exciting step for desktop Linux security. If you want to test them out, you can get the images from [GitHub](https://github.com/travier/fedora-atomic-desktops-sealed), but be warned: they’re unofficial and only meant for testing purposes, **don’t use them in production**. ### OpenAI Introduces Advanced Account Security URL: https://www.privacyguides.org/news/2026/05/02/openai-introduces-advanced-account-security/ Last updated: 2026-05-02T23:05:53.000Z OpenAI has [introduced](https://openai.com/index/advanced-account-security/) new security protections for ChatGPT accounts called Advanced Account Security, to protect users against account takeover. You can [enable](https://chatgpt.com/advanced-account-security?openaicom%5Freferred=true) the protections now. The new mode requires [passkeys](https://fidoalliance.org/passkeys/) or [hardware security keys](https://www.yubico.com/authentication-standards/fido2/) in order to log in to your account. Both of these use the open [FIDO2 standard](https://www.microsoft.com/en-us/security/business/security-101/what-is-fido2) developed by the [FIDO alliance](https://fidoalliance.org). These are more secure sign in methods than passwords based on public/private key cryptography, similar to the type TLS uses. Password login is disabled, preventing someone who obtains your password from bypassing the security protections of your FIDO2 login. This is important; many services allow you to add passkeys or hardware keys but still let you log in with just your password, severely limiting the security increase the FIDO credentials can provide. Account recovery, another target of account takeover, also sees a big security improvement. Email and SMS account recovery are disabled, since a compromised email account or SIM card could lead to your account being hacked. [SIM swap attacks](https://www.verizon.com/about/account-security/sim-swapping) are a very real threat and hinging your account security on unencrypted SMS that can be [rerouted](https://www.eff.org/deeplinks/2024/07/eff-fcc-ss7-vulnerable-and-telecoms-must-acknowledge) without your knowledge was always a terrible idea, and OpenAI is acknowledging that here. Ditto for email: the recovery emails sent to your inbox are always unencrypted, and the security of almost all of your accounts hinges on the security of your email account. Instead of these, you will need to utilize a great feature of passkeys and hardware keys: you can add multiple of each. Your recovery with this new feature will be 100% up to you, so make sure you store away at least one other passkey or hardware key in a safe place. OpenAI says they won’t be able to recover your account if you are enrolled in Advanced Account Security. Social engineering attacks on support workers are a common vector for attackers to gain control over your account, so putting the onus in the hands of their users is a good call. Another common attack vector is [session hijacking](https://owasp.org/www-community/attacks/Session%5Fhijacking%5Fattack), where an attackers steals your sessions tokens stored on your machine after you have already logged in, essentially bypassing the need to exploit your log in credentials at all. To combat this, OpenAI is reducing the length that sessions are valid for users enrolled in this setting and will give you an easy way to review active sessions across all devices your logged in on, as well as alerts when a new login. In a win for privacy, your conversations will not be used for model training with this setting on. Arguably this should just be the default, but it’s good to have nonetheless. OpenAI also partnered with Yubico to provide better prices on Yubikeys to ChatGPT users via a bundle. OpenAI promises more security and privacy improvements to come in the future, although they’re scant on details. They promised some kind of “[client-side encryption](https://www.privacyguides.org/news/2025/11/15/openai-announces-plans-for-client-side-encryption-for-chatgpt/)” for ChatGPT that has yet to materialize. ### Every Linux Distribution Shipped Since 2017 Vulnerable to New Copy.Fail Exploit URL: https://www.privacyguides.org/news/2026/05/02/every-linux-distribution-shipped-since-2017-vulnerable-to-new-copy-fail-exploit/ Last updated: 2026-05-02T19:11:01.000Z A new exploit called [copy.fail](https://copy.fail) has emerged that can root just about any Linux distribution shipped since 2017 using just an unprivileged user account. The exploit is particularly scary because it doesn't rely on [race conditions](https://www.geeksforgeeks.org/operating-systems/race-condition-in-operating-systems/) or tight timing windows in order to work; it's a flaw in the actual logic of the code. According to a [write-up](https://xint.io/blog/copy-fail-linux-distributions) by Xint.io, the researchers who found it, the same simple Python script works on every distribution they tested including Ubuntu, Amazon Linux, RHEL, and SUSE without modification. The script uses only standard Python modules and no dependencies. It's also very stealthy, making no changes to the disk, so file integrity tools comparing checksums will completely miss it. Only the "in-memory page cache is corrupted." The researchers say it's also a container escape exploit since the page cache is shared across all processes on a system. The core of the vulnerability lies with [AF\_ALG](https://www.kernel.org/doc/html/v4.11/crypto/userspace-if.html), a socket-based interface that allows userspace programs to access cryptographic features of the kernel. > A core primitive underlying this bug is splice(): it transfers data between file descriptors and pipes without copying, passing page cache pages by reference. When a user splices a file into a pipe and then into an AF\_ALG socket, the socket's input scatterlist holds direct references to the kernel's cached pages of that file. The pages are not duplicated; the scatterlist entries point at the same physical pages that back every read(), mmap(), and execve() of that file. . . . > This in-place design is the root cause of the vulnerability. It places page cache pages in a writable scatterlist, separated from the legitimate write region by nothing more than an offset boundary. The design assumes every AEAD algorithm will confine its writes to the intended destination, but nothing in the API enforces this, and nothing documents it as a requirement. The exploit was [fixed](https://github.com/torvalds/linux/commit/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5) by reverting an optimization that was added in 2017: algif.aead being done [in-place](https://github.com/torvalds/linux/commit/72548b093ee38a6d4f2a19e6ef1948ae05c181f7) instead of copying it to a new buffer. The commit that fixed the issue reads: > There is no benefit in operating in-place in algif\_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly. One [user](https://news.ycombinator.com/item?id=47956312) on Hacker News claiming to work on the Linux kernel’s neurologist code expressed concern over the AF\_ALG existing in the first place: > As someone who works on the Linux kernel's cryptography code, the regularly occurring AF\_ALG exploits are really frustrating. AF\_ALG, which was added to the kernel many years ago without sufficient review, should not exist. It's very complex, and it exposes a massive attack surface to unprivileged userspace programs. And it's almost completely unnecessary, as userspace already has its own cryptography code to use. The kernel's cryptography code is just for in-kernel users (for example, dm-crypt). Xint.io recommends patching your kernel in order to avoid this bug. There are already patches out for [Ubuntu](https://ubuntu.com/blog/copy-fail-vulnerability-fixes-available) and other distros, so make sure you update as soon as possible. ### Is Ubuntu Becoming the New Windows? URL: https://www.privacyguides.org/livestreams/2026/05/01/is-ubuntu-becoming-the-new-windows/ Last updated: 2026-05-13T19:13:38.000Z This Week in Privacy #51 _This post is for subscribers only._ ### Data Breach Roundup (Apr 24 - 30 2026) URL: https://www.privacyguides.org/news/2026/05/01/data-breach-roundup-apr-24-30-2026/ Last updated: 2026-05-01T19:17:40.000Z ## ADT confirms data breach after ShinyHunters leak threat The breach took place on April 20 and impacted dates of birth, last four of Social Security numbers, and Tax IDs. No payment information was accessed. The number of victims was not released but the ShinyHunters listing alleges over 10 million records. The article notes that ADT also had breaches in August and October of 2024\. A [later article](https://www.bleepingcomputer.com/news/security/home-security-giant-adt-data-breach-affects-55-million-people/) from Bleeping Computer noted that the breach affects 5.5 million people. [ADT confirms data breach after ShinyHunters leak threatHome security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-110.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/adt-sign.jpg)](https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/) ## Medtronic confirms breach after hackers claim 9 million records theft Medtronic - a medical equipment manufacturer - says they detected an incident that did not impact customers or products or business operations. ShinyHunters, however, claims to have personally identifiable information and "terabytes" of internal corporate data. [Medtronic confirms breach after hackers claim 9 million records theftMedical device giant Medtronic disclosed last week that hackers breached its network and accessed data in “certain corporate IT systems.”![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-111.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Medtronic.jpg)](https://www.bleepingcomputer.com/news/security/medtronic-confirms-breach-after-hackers-claim-9-million-records-theft/) ## Hackers threaten to leak over 9M Amtrak records, including personal info This article is from April 14, but was just posted to our forum this week. There's not really any information as the threats did not mention what kind of information was stolen. Given the lack updates, it seems likely that Amtrack paid, but if anyone has any updates feel free to leave them in the comments. [Hackers threaten to leak over 9M Amtrak records, including personal infoShinyHunters claims to have stolen 9.4 million Amtrak records via Salesforce and is threatening to leak personal data unless a ransom is paid.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-180x180-1.png)CybernewsVilius Petkauskas![](https://media.cybernews.com/images/featured-big/2026/04/amtrak-train-conductor.jpg)](https://cybernews.com/security/hackers-threaten-amtrak-data-leak/) ## Video service Vimeo confirms Anodot breach exposed user data Vimeo is a video hosting and streaming service, one of the largest competitors to YouTube (according to this article), with over 300 million registered users. Anodot is a third-party service vendor who suffered a breach earlier this month. As a result, attackers were able to compromise Vimeo. An undisclosed number of customers had email addresses exposed, but information also included "technical data, video titles, and metadata." [Video service Vimeo confirms Anodot breach exposed user dataVimeo has disclosed that data belonging to some of its customers and users has been accessed without authorization following the recent breach at the Anodot data anomaly detection company.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-112.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Vimeo.jpg)](https://www.bleepingcomputer.com/news/security/video-service-vimeo-confirms-anodot-breach-exposed-user-data/) ## Dental practice software maker fixes bug that exposed patients’ medical records Practice by Numbers makes popular patient management software for dental offices. An insecure direct object reference flaw allowed access to any other patient's records simply by changing the web address. The records were sequential, making them even easier to scrape or view. The company's email address was broken and a LinkedIn message went ignored until TechCrunch got involved. It was finally closed. [Dental practice software maker fixes bug that exposed patients’ medical records | TechCrunchExclusive: The security bug is now fixed, but the patient who found it said it was challenging to alert the software company about the issue.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-51.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/dentist-office-1252046775.jpg)](https://techcrunch.com/2026/04/30/dental-practice-software-maker-fixes-bug-that-exposed-patients-medical-records/) ### Firefox Quietly Adds Brave’s Rust-Based Adblocker URL: https://www.privacyguides.org/news/2026/04/24/firefox-quietly-adds-braves-rust-based-adblocker/ Last updated: 2026-04-24T23:00:41.000Z Firefox has [bundled](https://shivankaul.com/blog/firefox-bundles-adblock-rust) [adblock-rust](https://github.com/brave/adblock-rust), Brave’s memory-safe content blocker, into Firefox in version 149, although disabled by default. It’s an interesting step suggesting a possible default adblocking feature in some future release, although it’s clearly just an [experiment](https://bugzilla.mozilla.org/show%5Fbug.cgi?id=2013888) for now. There’s no UI and no filter lists, but if you want to enable it you can do the following, according to the blog [post](https://shivankaul.com/blog/about/) by the VP of Privacy and Security at Brave, Shivan Kaul: Open `about:config` in Firefox 149 and up and set: ``` privacy.trackingprotection.content.protection.enabled = true ``` Then, you need to give it some filter lists. You can add [EasyList and EasyPrivacy](https://easylist.to): ``` privacy.trackingprotection.content.protection.test_list_urls = https://easylist.to/easylist/easylist.txt|https://easylist.to/easylist/easyprivacy.txt ``` In order to find all prefs related to the feature, just search for `privacy.trackingprotection.content` in `about:config`. The developer found these options: - `privacy.trackingprotection.content.protection.enabled` to enable blocking - `privacy.trackingprotection.content.annotation.enabled` to enable tagging without blocking the content - `privacy.trackingprotection.content.protection.test_list_urls` pipe-delimited list URLs for blocking - `privacy.trackingprotection.content.annotation.test_list_urls` pipe-delimited list URLs for annotation - `privacy.trackingprotection.content.testing` fire observer notifications when lists load (for devs) Shivan says there seems to be two modes currently: Protection and Annotation. Protection is the classic Adblock experience where unwanted content is prevented from loading, while annotation simply tags requests for telemetry and UI but doesn’t block anything. Perhaps the annotation mode is just for testing purposes and not meant to appear in the final release. Brave has made strides in its adblocking engine, from writing it fully in Rust, a memory-safe, high-performance programming language designed to eliminate entire classes of [vulnerabilities](https://www.sciencedirect.com/science/article/pii/S1877050923016757), to their recent work on reducing the memory usage of the engine by 75%, allowing for significantly more filters to be shipped by default. Interestingly, Tor browser has been [looking](https://gitlab.torproject.org/tpo/applications/tor-browser/-/work%5Fitems/17569) into shipping UBlock Origin, a highly popular content blocking extension, into Tor browser by default. This would bring the official Tor browser more in line with other versions such as the one shipped with Tails and Mullvad Browser, both of which have been shipping UBO by default for many years. It’ll be interesting to see how this will play out, as there would no longer be a need for a separate adblocking extension in these projects if Firefox ships one out of the box, closing the gap between Tor browser and Firefox further. ### Would You Pay $60 For A Browser? (ft. Firewalls Don’t Stop Dragons) URL: https://www.privacyguides.org/livestreams/2026/04/24/would-you-pay-60-for-a-browser-ft-firewalls-dont-stop-dragons/ Last updated: 2026-05-13T19:13:04.000Z This Week in Privacy #50 _This post is for subscribers only._ ### Data Breach Roundup (Apr 17 - 23, 2026) URL: https://www.privacyguides.org/news/2026/04/24/data-breach-roundup-apr-17-23-2026/ Last updated: 2026-04-24T17:59:14.000Z ## Vercel confirms breach as hackers claim to be selling stolen data Vercel is a cloud platform that provides hosting and deployment infrastructure for developers, with a strong focus on JavaScript frameworks. It's unclear exactly how many people were compromised but the attacker claims to 580 records of employee information such as names and company email address, in addition to access keys, source code, and API keys. Vercel later [disclosed](https://techcrunch.com/2026/04/23/vercel-says-some-of-its-customers-data-was-stolen-prior-to-its-recent-hack/) that additional breaches predate this initial attack, suggesting the breach may widen in scope as investigation continues. [Vercel confirms breach as hackers claim to be selling stolen dataCloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-106.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/vercel-header-lg.jpg)](https://www.bleepingcomputer.com/news/security/vercel-confirms-breach-as-hackers-claim-to-be-selling-stolen-data/) ## Seiko USA website defaced as hacker claims customer data theft The "Press Lounge" section of watchmaker Seiko's website was updated (seemingly by attackers) to claim that the company's Shopify database was stolen. This includes customer names, email addresses, phone numbers, shipping addresses, order history, notes, and more. [Seiko USA website defaced as hacker claims customer data theftThe Seiko USA website was defaced over the weekend, displaying a message from attackers claiming they stole its Shopify customer database and threatening to leak it unless a ransom is paid.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-107.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/seiko-header-image.jpg)](https://www.bleepingcomputer.com/news/security/seiko-usa-website-defaced-as-hacker-claims-customer-data-theft/) ## French govt agency confirms breach as hacker offers to sell data France Titres (also known as Agence nationale des titres sécurisés or ANTS) is an administration under the Ministry of the Interior that manages all identity and registration documents including driver's licenses, national ID cards, passports, and immigration documents. The attack occurred last week and investigation is still ongoing. It's unknown how many individuals were impacted, but attackers claim 19 million records. Stolen could include login ID, full name, email address, date of birth, unique account number, and in some cases postal address, place of birth, and/or phone number. [French govt agency confirms breach as hacker offers to sell dataFrance Titres, the government agency in France for issuing and managing administrative documents has disclosed a data breach after a threat actor claimed the attack and stealing citizen data.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-108.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Titres.jpg)](https://www.bleepingcomputer.com/news/security/french-govt-agency-confirms-breach-as-hacker-offers-to-sell-data/) ## Cosmetics giant Rituals confirms data breach of customer membership records The Netherlands-based company said that an "unauthorized download" in April contained customers' full name, date of birth, gender, postal and email address, hone number, preferred Rituals store, and account type. There are no other details at this time. [Cosmetics giant Rituals confirms data breach of customer membership records | TechCrunchThe cosmetics retailer, which counts 41 million customers in its membership data, declined to provide an accurate total number of customers affected.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-49.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/rituals-1229232629.jpg)](https://techcrunch.com/2026/04/22/cosmetics-giant-rituals-confirms-data-breach-of-customer-membership-records/) ### Fingerprint.com Discovers Vulnerability That Can Link Your Tor Browsing Together URL: https://www.privacyguides.org/news/2026/04/24/fingerprint-com-discovers-vulnerability-that-can-link-your-tor-browsing-together/ Last updated: 2026-04-24T16:28:40.000Z The fingerprinting company [Fingerprint](https://fingerprint.com/blog/firefox-tor-indexeddb-privacy-vulnerability/) discovered a vulnerability affecting “all Firefox-based browsers” that would allow a “stable process-lifetime identifier” during a browsing session, including after pressing the “New Identity“ button in Tor browser. The vulnerability also persists after closing all Firefox Private Browsing mode windows. Fingerprint.com says they responsibly disclosed the vulnerability to Mozilla and it was quickly addressed in [Firefox 150](https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/#CVE-2026-6770) and [ESR 140.10.0](https://www.mozilla.org/en-US/security/advisories/mfsa2026-32/#CVE-2026-6770). Tor browser is based on Firefox so it inherits the bug. The vulnerability is related to the [IndexDB API](https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB%5FAPI), a feature that allows storage of large, structured data. When creating a database, a website can see the same ordering of items, even across websites or when closing all private browsing windows. The ordering only changes once the browser is shut down and restarted. This poses a problem as cross-site linkability is one of the main goals of privacy features in Firefox and especially Tor browser. It’s a bit unique in that it doesn’t require storing any specific data like cookies or localStorage, it just relies on the behavior of the browser when storing data. Small implementation details like this can have massive privacy costs. The suggested fix is rather simple: impose a canonical ordering for IndexDB items, such as lexographic sorting. Randomizing the output is also a possibility, but having consistent sorting is much simpler and easier for developers. Plus, [Fingerprint](https://fingerprint.com/blog/bypassing-safari-17-audio-fingerprinting-protection/) themselves have previously defeated attempts at randomization. Randomization should always take a backseat to making data look the same across browsers, and only be used in cases where that’s not possible or desirable. Be sure to update your browsers as soon as you can in order to get the fix. With AI finding new [vulnerabilities](https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/) in Firefox at an unprecedented rate, you have to wonder how many subtle privacy flaws also exist in the browser just waiting to be found. Will AI also be used by tracking companies to find these subtle implementation details that can expose Tor browser users? My gut tells me no since these issues are so unique to browsers specifically, whereas memory safety vulnerabilities and the like are more universal across different projects. Mozilla is optimistic about AI being used for finding vulnerabilities: > This can feel terrifying in the immediate term, but it’s ultimately great news for defenders. A gap between machine-discoverable and human-discoverable bugs favors the attacker, who can concentrate many months of costly human effort to find a single bug. Closing this gap erodes the attacker’s long-term advantage by making all discoveries cheap. It remains to be seen if the same applies to the privacy properties of browsers. ### Apple Releases Patch for the Signal Notification Issue That Allowed Recovery of Deleted Messages URL: https://www.privacyguides.org/news/2026/04/23/apple-releases-patch-for-the-signal-notification-issue-that-allowed-recovery-of-deleted-messages/ Last updated: 2026-04-23T17:04:57.000Z Apple has [released](https://support.apple.com/en-us/127002) iOS 26.4.2, which fixes the notification bug that allowed the [FBI](https://apple.news/A8o47iDhNQl23QyrOMKghRw) to extract Signal messages from a defendant’s iPhone. The update is available now to all iOS and iPadOS users with devices that support iOS and iPadOS 26. The relevant text from the changelog reads: > Impact: Notifications marked for deletion could be unexpectedly retained on the device > Description: A logging issue was addressed with improved data redaction. Signal has responded to the update: > We are very happy that today Apple issued a patch and a security advisory. This comes following [@404mediaco](https://twitter.com/404mediaco?ref%5Fsrc=twsrc%5Etfw) reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted. > > Apple’s advisory confirmed that the bugs that allowed this to… > > — Signal (@signalapp) [April 22, 2026](https://twitter.com/signalapp/status/2047070518776356996?ref%5Fsrc=twsrc%5Etfw) According to them, it’s confirmed that the update fixes the vulnerability. They even congratulate Apple on their “quick action.“ According to Signal, no user action is needed and once you install the update, “all inadvertently-preserved notifications will be deleted and no forthcoming notifications will be preserved for deleted applications.” Signal prides itself on protecting user privacy through end-to-end encryption, meaning no one except you and the people you message can read your messages. But each “end“ is a device with its own vulnerabilities that can be exploited by a bad actor with physical possession of the device. Sometimes, apps like Signal need to use features of the OS like notifications in order to provide functionality that users expect. “We learned that specifically on iPhones, if one’s settings in the Signal app allow for message notifications and previews to show up on the lock screen, \[then\] the iPhone will internally store those notifications/message previews in the internal memory of the device,” a person present at a trial where this technique was used told [404 Media](https://apple.news/A8o47iDhNQl23QyrOMKghRw). “Messages were recovered from Sharp’s phone through Apple’s internal notification storage—Signal had been removed, but incoming notifications were preserved in internal memory. Only incoming messages were captured (no outgoing),” says a [website](https://prairielanddefendants.com/court-notes/march-10-federal-trial-day-12/#:~:text=Messages%20were%20recovered%20from%20Sharp%E2%80%99s%20phone%20through%20Apple%E2%80%99s%20internal%20notification%20storage%20%E2%80%94%20Signal%20had%20been%20removed%2C%20but%20incoming%20notifications%20were%20preserved%20in%20internal%20memory.%20Only%20incoming%20messages%20were%20captured%20%28no%20outgoing%29.) made by supporters of the defendant. Messages that had been set to disappear in the Signal app did just that, and the same happened when the app was deleted: all the data contained in the Signal app is gone. Now with this update, message content that should be deleted will now be properly deleted. It’s still important to go through your [notification settings](https://support.apple.com/guide/iphone/change-notification-settings-iph7c3d96bab/ios) and make sure they’re set to not appear on the lock screen if you don’t want people being able to see them without unlocking your phone. You can also change the content of notifications from within [Signal](https://support.signal.org/hc/en-us/articles/360043273491-In-App-Notification-Options#ios%5Fnotification%5Foptions) itself, so if you don’t want private chats popping up on your phone screen, you should restrict it to no name or content. ### Mozilla Used Mythos to Fix 271 Firefox Bugs URL: https://www.privacyguides.org/news/2026/04/22/mozilla-used-mythos-to-fix-271-firefox-bugs/ Last updated: 2026-04-22T22:00:01.000Z Mozilla has [announced](https://www.wired.com/story/mozilla-used-anthropics-mythos-to-find-271-bugs-in-firefox/) that Firefox 150 (set to be released this week) will include fixes for 271 bugs found using Anthropic's "Claude Mythos" AI. Claude Mythos was announced in early April as Anthropic's latest "general purpose" LLM. However, it is alleged to be particularly excellent at cybersecurity tasks, so much so that the company claimed it would be irresponsible to release it publicly without first giving organizations early access to find and patch the type of vulnerabilities it would find. As such, Anthropic launched "Project Glasswing," a consortium of Big Tech companies who would be given early access to the model for the purposes of defense before the public release would inevitably empower the "bad guys" with these same weapons. (OpenAI later released their answer, ChatGPT Cyber, which they claim is also too dangerous for public release.) Mozilla is not part of Project Glasswing, however they do have a preexisting working relationship with Anthropic which they leveraged to have Mythos examine their code. This is not the first time Mozilla has used AI (specifically Anthropic) to find previously-unknown bugs in Firefox. Back in [March](https://blog.mozilla.org/en/firefox/hardening-firefox-anthropic-red-team/), Anthropic's Frontier Red Team submitted around a dozen security discoveries which were patched and fixed in Firefox 148. AI remains as controversial as ever, however it is commonly accepted that Firefox trails behind Chromium in terms of security. It is interesting to see a useful application of AI - instead of flooding content platforms with AI slop - even if it's arguably still an unethical tool at it's core. Personally, I'll be interested to see if this kind of work can close the security gap between Firefox and Chromium, if it can also be applied to improving Firefox's default privacy protections for users, and if other companies will start adopting similar initiatives. ### Madison Square Garden Facial Recognition Surveillance Used to Ban and Track People Around URL: https://www.privacyguides.org/news/2026/04/22/madison-square-garden-facial-recognition-surveillance-used-to-ban-and-track-people-around/ Last updated: 2026-04-22T18:47:55.000Z According to [WIRED](https://apple.news/A4J%5FgziZOSEq76BW-gGXNXA), Madison Square Garden’s incredibly invasive facial recognition system has been used to ban critics of the stadium and even track a trans woman around who did nothing wrong. James Dolan, owner of the venue, has reportedly had a track record of deploying dystopian surveillance in order to keep a ban list of people he doesn’t like for one reason or another, for any reason you can think of. His security team [banned](https://apple.news/Akc4M7JYlTLGYq4FGZoTAlA) a graphic designer for making a shirt that says “Ban Dolan.” For that, it’s suspected he was added to the facial recognition systems. He wasn’t even at MSG, but New York’s Radio City Music Hall, another venue owned by Dolan. The shirt was worn by his friend to MSG, but the security team had seemingly looked up the designer of the shirt and added him to their system via social media pictures. Another [incident](https://apple.news/AAskhkyw9R7Gn67BOJqRfaQ) saw a mother booted from a Rockettes show she was going to see with her 9 year old daughter, just because she worked for a law firm that had been involved with personal injury cases against a restaurant under the umbrella of MSG Entertainment. “I don’t practice in New York. I’m not an attorney that works on any cases against MSG,” she told NBC10 Boston. The ban affected all the other lawyers at the firm as well. A trans woman named Nina Richards was personally targeted by the then security chief Jeff Eversole, a former senior director of global investigations at Oracle, a surveillance [nightmare](https://nationalinterest.org/blog/techland/oracle-is-powering-chinas-surveillance-state) in its own right. Eversole told his deputies to compile dossiers on her and make sure she was in the facial recognition system, and ordered the site’s security to focus on her simply because she was a trans woman, according to a former MSG security staffer, Donnie Ingrasselino, in a lawsuit. Ingrasselino believed that she was targeted explicitly “because of her gender identity.” WIRED interviewed other former employees who alleged that “she posed no threat.” Eversole reportedly showed her picture in meetings and continually misgendered her. WIRED obtained a detailed 18-page report shows how closely she was being monitored: > 0*7:10:20 // CAM 0241 // scans her ticket to section 102, Row 8, Seat 5* > “*07:11:14 // CAM 1434 // goes up terrace escalators on level 3 to level 6 concourse* > *07:12:52 // CAM AC10 // hugs usher* > Appendix A of the report has a screenshot of the embrace, with Richards circled in red. > *08:08:58 // CAM 1093 // talking with F&B worker at the Draft Kings Bar* > *08:10:49 // CAM 0512 // pays for the drinks* > *08:31:19 // CAM 0485 // eating at a table*” Richards was banned from MSG under a false stalking allegation, ironically enough. Richards used to have an Instagram account with 44,000 followers, but today it’s all been nuked, presumably due to the surveillance, even telling WIRED to use a fake name. MSG invested at least $6 million into metal detectors with cameras built in for facial scanning in order to capture every face that enters. This overzealous approach leads to all kinds of innocent people getting flagged as suspicious, including a little girl in one case flagged as “priority 8.” Surely a terrorist in waiting. Madison Square Garden isn’t the only example of excessive surveillance. It’s seemingly becoming less and less possible to exist in public without being constantly under watch. ### Maryland Set To Ban Surveillance Pricing URL: https://www.privacyguides.org/news/2026/04/22/maryland-set-to-ban-surveillance-pricing/ Last updated: 2026-04-22T17:00:15.000Z Maryland's legislature has [passed](https://www.denver7.com/life/money/maryland-becomes-first-state-to-pass-bill-banning-surveillance-pricing) The Protection From Predatory Pricing Act, which is now awaiting Governor Wes Moore's signature. The governor is likely to sign the act, as they encouraged lawmakers to tackle the issue and spoke in support of reigning in the practice earlier this year. Surveillance pricing is the act of using a person's personal data - the same kind gathered for targeted advertising - to "personalize" pricing online. This could result in paying higher prices because the company knows that you can afford it or have no choice. Consumer Reports has warned that the current form of the bill still contains serious loopholes that should be closed, such as exempting loyalty programs or subscription-based services. ### Does everyone have the "Parents Decide Act" wrong? URL: https://www.privacyguides.org/videos/2026/04/22/does-everyone-have-the-parents-decide-act-wrong/ Last updated: 2026-04-22T03:40:17.000Z The Parents Decide Act has been a popular topic this week. We've been fighting age verification for years, but this bill doesn't seem to be as bad as many might lead you to believe. In this video, we break down the backstory of age verification laws, decipher what good could actually come out of "H.R. 8250: Parents Decide Act," and issue a warning about the potential dangers this act could create in our future. #### Sources \- https://www.govtrack.us/congress/bills/119/hr8250/text \- https://www.theguardian.com/news/2025/sep/19/how-accurate-are-age-checks-for-australias-under-16s-social-media-ban-what-trial-data-reveals \- https://www.eff.org/deeplinks/2021/10/face-recognition-isnt-just-face-identification-and-verification \- https://www.nytimes.com/2026/03/25/technology/social-media-trial-verdict.html \- https://www.coincenter.org/software-is-speech-why-regulators-cannot-invent-the-missing-middlemen/ ### Brave Launches Paid, Bloat-Free "Brave Origin" URL: https://www.privacyguides.org/news/2026/04/21/brave-launches-paid-bloat-free-brave-origin/ Last updated: 2026-04-22T15:29:12.000Z Brave has [announced](https://support.brave.app/hc/en-us/articles/38561489788173-What-is-Brave-Origin) a new minimalist version of their popular browser, dubbed "Brave Origin." The new browser will require a one-time license purchase of $60 (except on Linux where the product will be free), and a single license can be used across 10 devices. Brave uses a "blind token based on Privacy Pass, which decouples payment identity from service usage." Brave Origin disables or impacts the following features: - Leo - News - Playlist (currently iOS only) - Rewards (which also disables browser-based Brave Ads) - Speedreader - Stats like the daily usage ping, crash logs, and privacy-preserving product analytics (P3A) - Talk - Tor - VPN - Wallet (which also disables Web3 domains) - Wayback Machine - Web Discovery Project It's worth noting that users can "upgrade" from an existing Brave install to Brave Origin, which will disable the listed features without removing them entirely, allowing a user to re-enable features as desired. This might be useful to do if you're interested in Brave Origin, as some of the affected features (like Speedreader and Wayback Machine) are actually useful and arguably not "bloat." Brave is currently one of our recommendations at *Privacy Guides* for both [**desktop**](https://www.privacyguides.org/en/desktop-browsers/#brave) and [mobile](https://www.privacyguides.org/en/mobile-browsers/#brave) due to it's user friendly, "out of the box" nature and high-quality privacy protection features. [The Tor Browser](https://www.privacyguides.org/en/tor/) still remains our top recommendation for maximum privacy and anonymity. Brave Origin has been met with mixed reactions. Some wonder why anyone would bother paying for a browser, especially since many of Brave's more controversial features (like Leo and Rewards) can be easily disabled or safely ignored. Others tout this as another positive step toward ethical monetization and a sustainable business model. Some have questioned why it's free on Linux but not other operating systems, and some have noted the irony of paying to remove features, particularly features that are relatively unpopular or unrequested. ### Interview with Carissa Véliz, Author of "Privacy is Power" and "Prophecy" URL: https://www.privacyguides.org/videos/2026/04/19/interview-with-carissa-veliz-author-of-privacy-is-power-and-prophecy/ Last updated: 2026-04-19T23:03:58.000Z We sat down with Carissa Véliz, author of [Privacy is Power](https://www.carissaveliz.com/books) and University of Oxford associate professor, to talk about how predictive AI will make a 'meritocracy' impossible, how lifelike chat bots are designed to deceive you, and the importance of privacy in the digital age. Carissa Véliz is an associate professor at the Institute for Ethics in AI at the University of Oxford, a renowned author and speaker, a board member of the Proton Foundation, and a member of UNESCO's Women 4 Ethical AI. **Her new book, 'Prophecy,' comes out on April 21st.** Prophecy is about how extensive use of predictive analytics is undermining our abilities to defy the odds, making systems unaccountable, and increasing risk in business and society while creating a false sense of security. [Prophecy by Carissa Véliz: 9780385550970 | PenguinRandomHouse.com: BooksFrom an award-winning University of Oxford professor comes a brilliant, urgent new look at prophecies—the predictions that determine our lives, from our personal finances and the quality of our healthcare…![](https://www.privacyguides.org/content/images/icon/favicon-192x192.png)PenguinRandomhouse.comDismiss![](https://www.privacyguides.org/content/images/thumbnail/9780385550970)](https://www.penguinrandomhouse.com/books/759692/prophecy-by-carissa-veliz/) Some references in this video can be found on her website: - - #### Transcript This transcript has been lightly edited to improve readability. ****Nate Bartram (Privacy Guides):** ***Thank you so much for your time. We really appreciate you being here. I read your Wired article from 2021\. You said, “If AI is predicting your future, are you still free?” And you noted that in an age of individualized algorithms like personalized insurance rates, you said “you are increasingly paying your own way.”** ***My first thought when I read that is I think a lot of people at face value would say “this sounds awesome!” Like, why should my health insurance be higher because someone else is like a smoker, even though I go running every day, or something like that. I was wondering if you could explain to the audience like why that’s a little bit too good to be true.** ****Carissa Véliz:** Thank you, and thank you for having me. Yeah, I think it’s a very intuitive thought, this thinking that “well if I’m healthier than others, why should I be paying for someone else’s vices?” But precisely the whole point of insurance is to benefit individually from the law of large numbers. So **the law of large numbers* is a statistical phenomenon whereby a certain amount of people will be unlucky, whether it’s suffering from your house getting flooded, or a fire, or getting an illness. You don’t know who is going to be lucky and who’s going to be unlucky, and the idea of insurance is that we pull the risk together such that the lucky pay for the unlucky. And the point is that nobody knows who they’re going to be, and that’s why insurance makes sense, because if you’re paying for your own way, then if you’re part of the unlucky ones, then you’re going to pay a very large amount of money for something that you may or may not be to blame for. We tend to think about cases in which people are unhealthy, and we tend to be harsh in judging them, but the reality is that a big proportion of our health is ruled by random things like genetics, and where you live, and the kind of quality of air you’re inhaling, and and things that are beyond your control. And more importantly there there are two points: One is, the point of solidarity and the point of insurance is partly solidarity, but also partly to keep the community safe. So if we push risk onto the shoulders of individuals, that risk might break them, and when individuals break, society breaks. One example of this was the 2008 financial crisis, in which banks were giving loans that were very high risk because they knew that — or they should have known that — certain people were not going to be able to pay those loans. And the result is not only that those decisions broke those people, but that it created a financial crisis that we all had to suffer. And the other point is a moral one, about what is fair? Why are we allowing people to pay for things that they’re not to be blamed for? And what kind of society we want to build? So, in Prophecy, I discuss this example of Harvard: At some point Harvard had an insurance — a medical insurance program — for its employees, and it had two tiers: a cheap tier, and a more expensive tier. And some people were complaining that the most expensive tier was giving a lot of money to the people who chose it, because Harvard paid for a proportion. So you would get essentially more of a benefit if you went for the expensive tier. And also, there was a problem that Harvard was spending more money than it was bringing in. And it changed into a another kind of program in which Harvard paid just the same fee for everyone, and then people could choose whether they wanted the cheap, or the more expensive program. But that led to the result that only the sicker patients chose the more expensive program, and that made it too expensive on the following year. So after a few years, you didn’t have the expensive program anymore, and everybody lost out: The sicker patients, because they couldn’t access the better program anymore, but also the healthy ones who wanted that peace of mind. ***That’s interesting how it’s it’s almost counterintuitive that, like you said, it’s it’s about making it fair for everyone. One person might pay a little extra and it’s not really like “fair” to them, but it’s also not fair to the other people who are, like you said, born in an area with low air quality or something. So, thank you.** ***You said later on in the same article that we strive to structure our societies on the basis of merit, and you made the argument that AI algorithms can make us nihilistic, and can make society deterministic.** ***I will be honest, I don’t think I have a specific question here, but I was really interested in that idea and I was wondering if you could expand on that a little bit, because I’ve never heard this point raised before, and I think it’s a pretty universal thing that we would all agree, that society would be better if it was merit-based, and I’ve just never heard anyone point that out about algorithms before.** Yes. One of the things I’ve noticed in researching AI is how there is this double narrative going on. On the one hand, we are being told — especially when we’re on the losing end of a decision — that it’s kind of our fault, and that society is merit-based, and if we don’t get an opportunity or get some kind of punishment, then it’s our fault. At the same time, we are using AI more and more as a predictive tool. So instead of judging people on the basis of what they have already done and what they deserve, we judge them on the basis of what an algorithm thinks they will do. And so we get the short end on both narratives \[laughter\]. We get told that on the one hand that we should have done better, but on the other we are being treated as **things*, and not as human agents who have a say in our future. The more we use predictive algorithms on people, the more we close off opportunities before people can even stand a chance to defy the odds. When you look at the history of prediction, there has always been a kind of dance between our philosophical views of free will and what people deserve, and how much prediction we use. And there is a high correlation between an overuse of prediction when it comes to human beings, and authoritarianism. Because when we predict that somebody will do something in the future and treat them accordingly before they even do it, essentially we’re treating them as things. And you know this is the topic of the famous movie **Minority Report*. We are at a historical moment in which we are using predictive algorithms everywhere: in the doctor’s office, in justice systems, when it comes to job opportunities, loan opportunities, even dating apps. This proliferation of prediction is essentially narrowing our field of freedom, and that’s only when it comes to AI, but if you add on top of it other kinds of predictive practices, like prediction markets are gaining a lot of attention now, and they’re not only gaining attention from the part of the public and people who participate in them, but more and more I see newspapers reporting on prediction markets as if it was a trustworthy source of information. When you look at and analyze the history of prediction, we realize that although predictions might seem like quests for knowledge or hypotheses about the future, more often than not their power plays in disguise. In Prophecy, I argue that predictions are like the arena where fights about the future take place. And when somebody’s making a prediction, it might seem like they’re describing the world, but what in fact they’re doing is issuing a kind of command, and ordering people to bend reality to their vision of the future, which is usually a a future that is in their interest. Often it’s a financial interest. ***Another one of your articles that I read was “**[***chatbots shouldn’t use emojis**](https://philpapers.org/rec/VLICSU)***” from March of 2023.** ***And real quick, all** [***these articles are on her website**](https://www.carissaveliz.com/research) **and I highly recommend reading them. They’re very short and very insightful.** ***But you mentioned that some people think they might be a little too clever to be emotionally manipulated by a chatbot, which is why you argue that they shouldn’t use emojis. But, then you cited a 2021 study that found that people consistently underestimate how susceptible they are towards misinformation.** ***So, personally, this is a big argument of mine is that privacy matters… It’s not just about advertisers like nudging us to buy some new shoes or something, right? But sometimes they try to influence our opinions and beliefs. And I feel like I see so many people who think that they’re way too clever to fall for this, so I was curious if you could talk a little bit more about that study because again, I’ve never heard of that either.** Yes, we tend to have a very idealized version of ourselves. We tend to think of ourselves as very rational, and as as following our beliefs, and our beliefs being based on evidence and experience, and for the most part that’s not **entirely* wrong. However, we are influenced in ways that are not obvious to us, and the literature in psychology on this is so extensive that it’s hard to know even where to start. But things like, for example, I remember one study about how **smells* affect us, and when we’re smelling something that is unpleasant, even when we’re not conscious of it, we make harsher judgments. We are mostly influenced in minor ways. So you wouldn’t make a huge life decision on the basis of that kind of influence. However, for example, another study suggests that when judges are hungry, so before lunchtime, they tend to give out harsher sentences. And this is partly because for them it’s just another day at the office. But for the person receiving the judgment, it might be life-altering, or it **will* be life-altering. We are especially vulnerable to being influenced in moments in which we might not be our full selves. It might be that you’re super stressed out because of a particular situation. Or it might be that you are scared about a particular piece of news that is very alarming. Or it might be that you’re in some kind of other emotional state. In those cases, it might make the be the difference between you doing something and not doing something. Also important, is to think about how many billions of people we are. Such that if you have a way to expose millions and millions of people to a very alarming message, just **statistically*, even if we were all pretty rational beings, pretty well informed, pretty smart, you will find a proportion of those people who are who you just catch at the wrong time. They might be in the hospital. They might be worried about their pension, or their loan, or a job, or whatever vulnerable circumstance. And I’ve talked to many friends who have been the subject of of frauds. Every person I’ve met who has fallen for a kind of this scam was called in a moment in which their guard was down, for whatever reason. So I think we need to be much more realistic about how we are influenced by what we see on screens, and how it’s more and more the case that we are not accessing reality through vouched editors — like when you read a newspaper — but through screens that are **designed* to engage us depending on our personalities. That makes us even more vulnerable than we would in a situation before social media came about, or before these algorithms designed for engagement became so common. ***Yeah, for sure. I like what you said about the moment of weakness. Troy Hunt from Have I Been Pwned, I think last year, fell for a phishing attack and he talked about he put a whole blog post about it, about how he had just gotten home from international travel, and he was tired, like all the tricks you mentioned that worked on him. And I think Cory Doctorow fell for one too, but I could be remembering that wrong...** ***Actually, to what the last thing you just said, in that same article, you said it would be more ethical to design chat bots to be noticeably different from humans: “To minimize the possibility of manipulation and harm, we need to be reminded that we are talking to a bot.”** ***Which drives home what you just said, as well as you talk about this in your upcoming book and you talked about it in one of your talks, how every tech is designed with a specific use case and a purpose in mind. It kind of makes you wonder why chatbots are so lifelike.** Yes, they’re **designed* to be impersonators, and that should concern us! That technology is designed to be misleading, to hijack our normal emotional responses. One way in which we could make them different is just not only not allowing them to use emojis, but not allowing them to even use the pronoun “I.” Because using the pronoun “I” suggests there’s someone else on the other side of the screen, and there isn’t. But just like you can still see and get fooled by a visual illusion — even when you know it’s an illusion! — when you talk to a chatbot it’s still so compelling. And furthermore if they catch you at a bad time at a time. when you’re grieving or a time when when you are in need of consolation, you might be particularly vulnerable to these systems. And we are already seeing this effect that some people are calling “chatbot psychosis” or “chatbot delusions” in which because chatbots are designed to essentially please human beings, you get a lot of validation from them which can — a healthy measure of validation can be positive — but when a system consistently validates your every thought, there is this phenomenon whereby people spiral into delusions, and we haven’t seen it once or twice twice or three times: This is something that people are reporting at quite alarming rates. One of the things that keeps us tied to reality is talking to other human beings, **because they disagree with us*. And it’s annoying, and it’s frustrating, and it can lead to conflict. But somebody challenging your views is an essential part of staying mentally sane and having perspective on the world. ***Yeah, I heard somebody say that about the whole “AI girlfriend” phenomenon that they’re like, “Yeah, but a real relationship is like, there’s struggle and there’s disagreement, and an AI girlfriend will never be able to do that.” Going back to your TEDx talk about** [***how privacy can save your life**](https://www.youtube.com/watch?v=xSPRouBvgFE)***, you mentioned, “Every time you share your data, you’re sharing the data of other people as well.”** ***That’s something that I don’t see discussed a lot in the privacy community — just every once in a while — and I was wondering if you could expand on that, and and talk about how we share the data of others with our own.** Using the term “personal data” is quite misleading, because it seems to suggest two things, both of which are false: One is that personal data is a very individual matter, when in fact most of your personal data is shared with someone else. For example, your location data: you usually work in the same place as other people and you usually live with someone else or close to other people, so if you reveal that data, you are revealing the data of other people as well. Even something as individual or **seemingly* individual as genetic data is incredibly collective, because when you share your genetic data, you’re not only sharing your data, you’re sharing the data of all your family. Not only your close family like your siblings and your parents and your children, but also the data of distant kin, who **can* have repercussions from it, and they are not giving consent. The second thing that it suggests — this this term “personal data” — that is false is that it’s a personal choice, it’s a personal preference. So if you’re less shy than other people then and you have nothing to hide, and you’re not a criminal, then it’s fine for you to share the data. But again, that doesn’t take into account how not only does your data contain data about other people, but your decisions about privacy have collective repercussions. For example, in the Cambridge Analytica scandal, people gave away their privacy. I think it was for $2 \[laughs\]. And of course, when they gave away their privacy, they weren’t entirely aware of what they were doing. The terms and conditions didn’t say, “We will use this data to try to sway elections around the world and to profile people.” But that is in essence what what happened. So even when you are sharing data that arguably is only about you, if that data gets used to infer data about other people or to issue targeted ads with a political agenda, then other people are also suffering from that loss of your privacy. That is one reason why we need to have better guard rails, in general, about what is safe. We have seen this in other spheres of life. For example, when it comes to cars, because when you have a crash you might seriously injure yourself, but you might also injure others. So there are reasons for why we should limit your speed, or you might be requested to use your seat belt, etc. And we see this also in public health. So even if you wanted to experience what it’s like to get a very contagious disease, society has an interest that you don’t get it, because you might give it to someone else. Currently in the digital sphere, we haven’t built the right guard rails to protect society as a whole, to protect democracy. It’s not only about you. ***You said in your TEDx talk that currently AI uses incredible amounts of personal data, but it doesn’t have to be that way.** ***A little bit more of a technical question here: If we were to get AI right from a privacy perspective, what do you think that would look like? Would it be some kind of like opt-in signal like a robots.txt file? Would it be the the company’s paying people for the data that they scrape up? Would it be both? Would it be something else? What do you think would be a good start towards that future?** We’re already seeing more hybrid versions of AI, large language models that don’t only use machine learning, but that use decision trees or that use even things like calculators. So, for example, famously, large language models can’t do math because what they are good at is picking up patterns, but that doesn’t mean that they’re making any kind of calculations. You’re already seeing large language models that when the system realizes that the person is is asking for some kind of arithmetic, it swaps into a calculator mode in which you can actually use it as a calculator and it’s not a large language model anymore. Similarly, companies — like for example Empathy Holdings — are using large language models to ask users questions to then narrow down what they are looking for. And for example, if they’re looking for a question about a particular fridge, once the system has recognized the model of the fridge, you get the actual PDF of the manual, and then when you ask questions, you only get a highlight function. And that way you don’t get any kind of confabulation which people call “hallucination,” but I don’t like the term because it suggests that the system has a an **experience*, which it doesn’t. And we are seeing other kinds of AI that is being used in legal settings that asks the system twice to make sure that there there isn’t any kind of fabrication of cases. So we’re we’re already seeing some of it. But for me, the ideal kind of AI for the purposes of privacy would have two sides of it: On the side of its training and creation, it would be very respectful of data and ideally it wouldn’t be trained with personal data at all, much less without the consent or knowledge of people. Once trained, it would be able to delete any kind of personal data, and it would be also trained not to give off any personal data that could be inferred from non-personal data. And then on the other side of the equation, it wouldn’t take any personal data from the people who use the AI. So at the moment, I read an article not too long ago giving an example fleshing out how much information a large language model is getting out of you and how it’s profiling you, and it’s using information that is obvious: like the kinds of things that you say about where you live if you give it your address, or your job title, or other kinds of personal information. But it’s also inferring things from how you use language: It’s inferring things like where you are from, and what kind of social class you belong to, and what kind of educational background you have. It’s using all of that for marketing purposes, or they can sell on that information. And so you would \[need\] respect for privacy on both ends. Interestingly, that coincides with a better approach with respect to ecology and energy, because at the moment these systems are incredibly inefficient. The best kind of AI would be a technology that doesn’t use that much data, and that is based much more on reasoning, and that would be more privacy preserving, more ecologically respectful, and it would also lead to much less confabulation if it’s not a statistical process and it’s more of a reasoning device. That’s a tall order, but that is also a fact. Part of what we’re saying when we criticize AI is saying, well, this is a pretty bad product. It’s a pretty unsafe product, and we should do better, and we deserve better technology. ***You kind of touched on this one a little bit, but in that same vein, if we go back to the Wired article where you talked about how AI is kind of taking away our our agency and our potential, how would we solve that one? Is it just regulating how predictive algorithms are used, or do you think there’s any other solutions to that one?** It’s a combination of things. It’s partly about culture, about identifying the things that we value and nurturing them. For example, at the moment, I think we are valuing convenience too highly. Of course, convenience is a very important feature of life. If you choose always the inconvenient way of doing things, you would never get anything done essentially. However, this using of “convenience” as a kind of trump card for anything just doesn’t pan out. It leads to a pretty bad life. Everything that is most meaningful in your life is pretty inconvenient. Is it convenient to have a family? No. Friends are a pain, and reading is effortful, and doing a PhD is a headache, and exercising is a drag! \[laughs\] You know, part of the the what we get from things is what we invest in them. And when something is effortful, it makes it more meaningful, when when you can reap the the fruits of that. So, it’s partly about not losing skills that we shouldn’t be losing so that we don’t lose our autonomy, and not delegating important things to AI. And what are those important things? Well, it depends. The devil is in the details. But in general, one way to look at it is that democracy is a kind of conversation between citizens. And when we delegate that conversation to AI, when we delegate that language to AI, it’s like we stand up from the table of democracy and and leave our place. Another thing that is very important is to design AI better. To make it safer in in all ways, including privacy. Another element that would be very important is the protection of privacy, because you don’t have democracy without privacy. And at the moment we are still pushing for more and more surveillance. What we’re doing in practice is asking the question, how much surveillance can democracy take? And I really don’t want to find out, but we are pushing in that direction. Another element is about regulating predictions, yes. We hear a lot about AI bias, but I think we’re misdiagnosing some of the problems, because we’re missing the the most primal underlying problem that is having to do with prediction. And it’s like a kind of arrogance to to think that it’s okay for anyone to make any kind of prediction about anyone else in the world, and act accordingly without any kind of supervision, any kind of permission, any kind of input from that person. Even Ancient Rome regulated predictions! So it was illegal to predict the death of the emperor — for obvious reasons! — because it has a tendency to become a self-fulfilling prophecy. Once somebody has said the emperor will die by this day, there will be people vying for power and very often the emperor ended up dead! If Ancient Rome regulated predictions, it’s kind of incredible that we haven’t caught up to that problem. We have to have a public debate about what kinds of predictions are okay to make: when, how should we use them, and what are the limits? ***How do you think we can get to a a better AI scenario like we’ve been talking about? And I’m thinking specifically about how right now these companies are investing unfathomable amounts of money. I feel like it can be discouraging when you’re going up against that kind of economic incentive, and it feels like “well how can I make change?” What do you think are things that we can do to help try to nudge AI in a better in a direction that’s better for society and benefits everyone, instead of just the people at the top?** Part of it, we’re already doing it by having these conversations. This is partly the fabric of democracy. You and I talking about this, and other people listening to this podcast and commenting, and then talking about it with their friends and their family. This is how democracy gets built. Part of it is putting pressure on our political representatives to represent us adequately, and to defend our privacy, and to demand better products from from companies. And that’s not going very well. \[laughter\] But it’s a big job, and and we have to do it. Part of it is demanding better from companies and calling them out when they don’t act right. And part of it is using the right products! Very often we do have a good alternative and not not enough people use it. So Signal is a great example, because it works just as well as WhatsApp, and it doesn’t collect your data, and it was also a game changer for the whole industry. Before Signal came along, it wasn’t common to encrypt messages. And once Signal started encrypting them and making it easy — that you didn’t have to be a technical person, it was just a default — then other companies caught up. So we need companies to be more innovative. Another great example is Proton. And full disclosure, I’m part of the board of the Proton Foundation, but they don’t pay me. And I’m part of their board because I believe in what they’re doing. And they have encrypted email, they have VPNs, they have a password manager. Anyone who’s using Gmail or another provider is using a worse service, and when there are better alternatives. Instead of using Google search, use DuckDuckGo, because every time you use those services you are voting as well. You are sending the message that this is important, that consumers care about this, and if companies want to have a competitive advantage, they better protect us. ### Tracking Opt-Outs Are Useless, Cal.com's Closed Source Chaos, Both Good & Bad Political News, and More! URL: https://www.privacyguides.org/livestreams/2026/04/17/tracking-opt-outs-are-useless-cal-coms-closed-source-chaos-both-good-bad-political-news-and-more/ Last updated: 2026-04-27T01:02:42.000Z This Week in Privacy #49 _This post is for subscribers only._ ### HackerOne Pauses Internet Bug Bounty URL: https://www.privacyguides.org/news/2026/04/17/hackerone-pauses-internet-bug-bounty/ Last updated: 2026-04-17T17:38:48.000Z HackerOne is [reporting](https://www.infoworld.com/article/4154210/internet-bug-bounty-program-hits-pause-on-payouts.html) that they are "pausing submissions" in response to AI putting vulnerability reporting in the express lane, which in turn is overwhelming the recipients' abilities to parse through and fix them. As examples, InfoWorld notes that Curl said they were not participating in the bug bounty program anymore back in January due to a deluge of reports, and Google also stopped accepting AI reports in March. Bug bounties are a popular staple of cybersecurity. Many companies and projects will offer to pay researchers who responsibly disclose vulnerabilities. The amount of payment is typically outlined by the company or project and varies based on severity, which software the vulnerability is found in (eg Chrome or Android), and other factors. In the past, some researchers have even been able to make a living strictly off bug bounties. One of the most popular services for managing bug bounties is HackerOne. You can think of HackerOne like a job board or third-party vendor where companies and projects can sign up, post the guidelines for payout, and accept reports. This makes the whole process seamless and helps smaller projects who don't need to reinvent the wheel or manage an entire system of reporting. Historically AI bug reports have been considered a nuisance, often reporting things that weren't actual bugs or were intended functionality. This would often lead to maintainers wasting valuable, limited time on nonsense. (This is one reason many maintainers set "no AI" policies.) In a recent episode of "[This Week in Privacy](https://www.privacyguides.org/livestreams/2026/04/03/claude-source-code-leak-influencers-kids-can-request-deletion-linkedin-scrapes-your-browser-extensions-and-more/)," myself and Jonah Aragon (*Privacy Guides*' executive director) discussed the topic of AI bug reports and how it's likely that many such spammers are simply trying to "pad" their GitHub submission history in hopes of looking more appealing to potential employers. However, last month [The Register](https://www.theregister.com/2026/03/26/greg%5Fkroahhartman%5Fai%5Fkernel/) quoted a senior Linux kernel maintainer who said that the quality of AI bug reports has sharply increased in recent weeks. It's unclear from the provided statements exactly what HackerOne's concern is. Is the concern that payments are incentivizing sloppy AI bug report spam in the hopes of an easy payout? Or is there concern that the uptick in quality bug reports is unsustainable, either financially or in terms of "time required to fix the bugs?" Time will tell, but we hope that they'll find the answers they seek as the bug bounty program has historically been a net good for the cybersecurity landscape. ### Data Breach Roundup (Apr 10-16, 2026) URL: https://www.privacyguides.org/news/2026/04/17/data-breach-roundup-apr-10-16-2026/ Last updated: 2026-04-17T17:29:07.000Z ## New Booking.com data breach forces reservation PIN resets Booking.com is - as the name suggests - a website that allows users to book travel including flights, car rentals, hotels, and more. They are one of the largest such sites. Users have reported getting emails from noreply@booking.com informing them of a "cybersecurity incident" that may have exposed full names, email addresses, postal addresses, phone numbers, and communication with property providers. Booking.com is not being transparent about the number of users impacted, but said all users will be individually notified. They are also resetting user reservation PINs out of caution. [New Booking.com data breach forces reservation PIN resetsBooking.com has confirmed via a statement to BleepingComputer that it has detected unauthorized access to its systems that has exposed sensitive reservation and user data.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-102.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Booking.jpg)](https://www.bleepingcomputer.com/news/security/new-bookingcom-data-breach-forces-reservation-pin-resets/) ## European Gym giant Basic-Fit data breach affects 1 million members Basic-Fit is one of the largest gym chains in Europe with over 1700 clubs and 430 franchises in 12 countries. In a disclosure published on their website, they have announced a cyberattack that impacted full name, physical address, email address, phone number, date of birth, bank account details, and "other membership information." It appears to have impacted about 1 million members. [European Gym giant Basic-Fit data breach affects 1 million membersDutch fitness giant Basic-Fit announced that hackers breached its systems and gained access to information belonging to a million of its customers.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-103.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/BasicFit.jpg)](https://www.bleepingcomputer.com/news/security/european-gym-giant-basic-fit-data-breach-affects-1-million-members/) ## McGraw-Hill confirms data breach following extortion threat McGraw-Hill is an education company that offers textbooks, online portals, and systems for K-12 schools and universities. This attack appears to have come from a misconfigured Salesforce page. McGraw-Hill says the data exposed was "limited and non-sensitive," but the attacker claims to have 45 million records containing personally identifiable information. [McGraw-Hill confirms data breach following extortion threatEducation company McGraw-Hill has confirmed in a statement to BleepingComputer that hackers exploited a Salesforce misconfiguration and accessed its internal data.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-104.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/McGraw-Hill_Education_wordmark.svg.jpg)](https://www.bleepingcomputer.com/news/security/mcgraw-hill-confirms-data-breach-following-extortion-threat/) ## Crypto-exchange Kraken extorted by hackers after insider breach Kraken says that attackers are threatening to release a video that shows internal systems that host client data. The article is a bit unclear but it does seem that the attackers were showing that they had actual access to the data, though it seems it was through inside employees and not via a technical hack (such as a vulnerability). Kraken said that funds are safe and employees have been terminated. They say the breach was limited to about 2,000 customers but have not shared what information was impacted. [Crypto-exchange Kraken extorted by hackers after insider breachThe Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-105.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Kraken.jpg)](https://www.bleepingcomputer.com/news/security/crypto-exchange-kraken-extorted-by-hackers-after-insider-breach/) ## Fashion retailer Express left customers’ personal data and order details exposed to the internet This was a flaw appears to have been an "insecure direct object reference" vulnerability - where simply tweaking the web address is enough to pull up other pages you may not necessarily have been meant to see. In this case a researcher was able to access other users' order confirmation pages, which included names, phone numbers, email addresses; postal, billing, and delivery addresses; order details including the items that a customer purchased, and partial payment card information including the card type and the last four-digits. [Exclusive: Fashion retailer Express left customers’ personal data and order details exposed to the internetRetail giant Express was publicly spilling customer information to the open web. The bug is now fixed after TechCrunch alerted Express, but the company would not say if it plans to notify customers.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-48.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/express-large-1201281247.jpg)](https://techcrunch.com/2026/04/16/fashion-retailer-express-left-customers-personal-data-and-order-details-exposed-to-the-internet/) ## Fiverr Exposes Private Information of its Users Publicly on Google Search Results From our own staff writer Fria, a researcher on Hacker News claimed that Fiverr - a freelancer job board - was exposing sensitive personal documents such as tax forms containing Social Security Numbers. The data could easily be found by searching `site:fiverr-res.cloudinary.com [keywords of choice, such as "form 1040" or a name]` on most search engines including Google and even DuckDuckGo. According to our internal news chat, the data itself does appear to have been secured. *Privacy Guides* Executive Director Jonah Aragon was unable to reproduce the results on Google, but both Jonah and Fria were able to find the results on DuckDuckGo, though they no longer linked to a valid address. [Fiverr Exposes Private Information of its Users Publicly on Google Search ResultsA security researcher on Hacker News claims that sensitive documents like tax forms shared between Fiverr users in private messages ended up publicly indexed by search engines like Google.![](https://www.privacyguides.org/content/images/icon/pg-yellow-2-63.png)Privacy GuidesFria Reyes![](https://www.privacyguides.org/content/images/thumbnail/photo-1730818876486-86496dfb5fd4)](https://www.privacyguides.org/news/2026/04/16/fiverr-exposes-private-information-of-its-users-publicly-on-google-search-results/) ### India Drops Proposal to Require Biometric ID App After Strong Opposition URL: https://www.privacyguides.org/news/2026/04/17/india-drops-proposal-to-require-biometric-id-app-after-strong-opposition/ Last updated: 2026-04-17T16:35:07.000Z Reuters [reports](https://apple.news/Ab1JVgVG-S0eltRNOPi8kTg) that the Indian government has decided it won’t go through with a proposal to require operating systems to preinstall the biometric ID app Aadhaar. The Aadhaar app is a unique number tied to an individual’s iris and fingerprint scans, used for verification purposes such as in banking or telecom services. It’s used by nearly 1.34 billion Indians. Back in January, UIDAI, the state body in charge of Aadhaar, asked the IT ministry to work with Apple, Google, and other smartphone manufacturers on the possibility of mandating pre-installing the Aadhaar app. The IT ministry gave Reuters no reason as to why they decided against the proposal. Reportedly, this was the sixth time in only two years that the Indian government sought requiring some kind of pre-installed state software on smartphones. Each one was heavily opposed by smartphone manufacturers. > Smartphone makers flagged concerns about device security and compatibility when they received the Aadhaar preload proposal, and also flagged higher production costs as they ‌would have ⁠been required to run separate manufacturing lines for India and export markets, according to documents reviewed by Reuters. Further, an anonymous senior Indian official told Reuters that the IT ministry is “not supportive of any preloading of apps.” With no support from the IT ministry or any device manufacturers, it’s no surprise the proposal died. Apar Gupta, founder of the New Delhi-based digital advocacy group the Internet Freedom Foundation, welcomed the news, saying “hopefully it is a welcome exercise of regulatory restraint that recognises that citizens carry their phones as ​extensions of their autonomy, not as vessels for government order.” With the ongoing international push for age verification in so many countries these days, they’re scrambling for effective methods that aren’t easily bypassed. Submitting photos of identification documents is both easy to forge and a huge privacy and security risk, with [multiple](https://arstechnica.com/tech-policy/2026/02/discord-faces-backlash-over-age-checks-after-data-breach-exposed-70000-ids/) [cases](https://fortune.com/2025/07/26/tea-app-hack-images-online-leaks-users-selfies/) now of people’s ID photos leaking online. Some companies try to solve this with digital scans of your face to prove your age, claiming that the scans aren’t sent anywhere. However, the technology can be easily [bypassed](https://gamerant.com/death-stranding-photo-mode-bypass-age-verification/) and possibly [leaked](https://cybernews.com/privacy/persona-leak-exposes-global-surveillance-capabilities/) in data breaches, not to mention that giving websites camera access is never a good idea. A digital ID is a solution many countries have landed on to fix these problems, supposedly being both privacy-preserving and difficult to bypass. There are standards made by organizations like [ISO](https://www.iso.org/standard/69084.html) and [W3C](https://www.w3.org/TR/digital-credentials/) that lay out how digital IDs and credential should work. [Apple](https://www.apple.com/newsroom/2025/11/apple-introduces-digital-id-a-new-way-to-create-and-present-an-id-in-apple-wallet/) and [Google](https://blog.google/innovation-and-ai/technology/safety-security/opening-up-zero-knowledge-proof-technology-to-promote-privacy-in-age-assurance/) support digital IDs in their digital wallet applications and support private age verification through the use of zero knowledge proofs However, each country seems to want to make their own digital ID, each with their own quirks and security issues. The EU recently announced that their digital ID was ready to launch. It was hacked in minutes. > Hacking the [#EU](https://twitter.com/hashtag/EU?src=hash&ref%5Fsrc=twsrc%5Etfw) [#AgeVerification](https://twitter.com/hashtag/AgeVerification?src=hash&ref%5Fsrc=twsrc%5Etfw) app in under 2 minutes. > > During setup, the app asks you to create a PIN. After entry, the app \*encrypts\* it and saves it in the shared\_prefs directory. > > 1\. It shouldn't be encrypted at all - that's a really poor design. > 2\. It's not… [pic.twitter.com/FGRvWtWzaZ](https://t.co/FGRvWtWzaZ) > > — Paul Moore - Security Consultant  (@Paul\_Reviews) [April 16, 2026](https://twitter.com/Paul%5FReviews/status/2044723123287666921?ref%5Fsrc=twsrc%5Etfw) The FIDO Alliance is working on making digital credentials more standardized and especially focussing on standardizing digital wallets, so embarrassing situations like this don’t happen again. ### Fiverr Exposes Private Information of its Users Publicly on Google Search Results URL: https://www.privacyguides.org/news/2026/04/16/fiverr-exposes-private-information-of-its-users-publicly-on-google-search-results/ Last updated: 2026-04-16T15:39:27.000Z A security researcher on [Hacker News](https://news.ycombinator.com/item?id=47769796) claims that sensitive documents like tax forms shared between Fiverr users in private messages ended up publicly indexed by search engines like Google. Fiverr uses a third-party service to process and serve PDF documents and images in the built-in messaging feature called Cloudinary. The researcher points out that Cloudinary acts like an S3, serving the images and files directly to users. “Like S3, it has support for signed/expiring URLs. However, Fiverr opted to use public URLs, not signed ones, for sensitive client-worker communication.” As of the writing of this article, the documents are still publicly indexed by Google. You can try it out yourself using the example search query site:fiverr-res.cloudinary.com form 1040 or any other keywords. ![](https://www.privacyguides.org/content/images/2026/04/image-2.png) Example search results from Fiverr The researchers also claims that “Fiverr actively buys Google Ads for keywords like "form 1234 filing" despite knowing that it does not adequately secure the resulting work product, causing the preparer to violate the GLBA/FTC Safeguards Rule.” They say they responsibly disclosed the issue to Fiverr 40 days ago via their designated vulnerability email, security@fiverr.com, but they got no response. “Therefore, this is being made public as it doesn't seem eligible for CVE/CERT processing as it is not really a code vulnerability, and I don't know anyone else who would care about it.” In a reply to a Cybernews on X, Fiverr responded to the claims: > To be clear, this is not a cyber incident. Fiverr does not proactively expose users' private information. The content in question was shared by users in the normal course of marketplace activity to showcase work samples, under agreements and approvals between buyers and sellers.… > > — Fiverr (@fiverr) [April 15, 2026](https://twitter.com/fiverr/status/2044389801495773339?ref%5Fsrc=twsrc%5Etfw) In Cybernews’ [article](https://cybernews.com/security/fiverr-leak-exposes-user-ids-contracts-data/) on the subject, they point out that, ironically, Fiverr’s own ISO 27001 certification for information security, expired of course. ![](https://www.privacyguides.org/content/images/2026/04/image-3.png) Credit: [Cybernews](https://cybernews.com/security/fiverr-leak-exposes-user-ids-contracts-data/) The research team at Cybernews analyzed the problem and independently confirmed the claims. Aras Nazarovas, an information security researcher at Cybernews, said “this is a major security lapse by Fiverr, due to the links being publicly accessible and indexable, a lot of resources are already indexed by Google. Essentially all files that were shared between service buyers and sellers, including personal identity documents, sensitive contracts, passwords, and API keys shared with contractors, finished and work-in-progress deliverables.” It’s disappointing to see Fiverr deny the security implications of publicly listing personal details of its users. It would be bad if it was just private messages, but due to the nature of the platform there’s an abundance of *the* most sensitive data that would be maximally devastating to leak. ### Mastodon to Get E2EE for Private Messages Thanks to Sovereign Tech Fund URL: https://www.privacyguides.org/news/2026/04/15/mastodon-to-get-e2ee-for-private-messages-thanks-to-sovereign-tech-fund/ Last updated: 2026-04-15T17:33:00.000Z Mastodon announced they were awarded a €614k service agreement by the [Sovereign Tech Fund](https://www.sovereign.tech) to fund the development of new features and improvements, including end-to-end encrypted private messages. The service agreement covers five major features. Mastodon will be coordinating with the Social Web Foundation, who were commissioned by the STF to work on their [MLS](https://www.rfc-editor.org/rfc/rfc9420.html)\-based E2EE messaging protocol: [MLS over ActivityPub](https://swicg.github.io/activitypub-e2ee/mls). MLS over ActivityPub is currently a W3C draft and not finalized yet. The ActivityPub E2EE Messaging Task Force at the W3C will work on delivering the final specification. Mastodon says they will implement support for ActivityPub E2EE “once the [ActivityPub E2EE Messaging Task Force at the W3C](http://github.com/swicg/activitypub-e2ee) has delivered a specification, and interoperability is demonstrated.” The Social Web Foundation is working with two projects to accomplish this: [Emissary](https://emissary.dev) and [Bonfire](https://bonfirenetworks.org). These projects will implement the protocol and make sure they can interoperate with one another. Mastodon estimates the timeline for the work will be during 2027. With the recent news that Instagram is [ending E2EE messaging](https://cybersecuritynews.com/instagram-end-to-end-encryption/) support, it’s clear that privacy on many social media platforms is not a priority. TikTok has come out and blatantly said it [refuses](https://www.bbc.com/news/articles/cly2m5e5ke4o) to E2EE DMs, citing user safety concerns. Platforms like Snapchat have landed in hot water in the past because they leaked their users data. They supposedly added E2EE in [2019](https://www.telegraph.co.uk/technology/2019/01/09/snapchat-adds-end-to-end-encryption-protect-users-messages/), but there’s no documentation about it. The company doesn’t even seem to acknowledge the feature directly anywhere. X is coming out with its own E2EE chat feature, but it’s been heavily [criticized](https://techcrunch.com/2025/09/05/x-is-now-offering-me-end-to-end-encrypted-chat-you-probably-shouldnt-trust-it-yet/) for its subpar implementation. An open, interoperable E2EE messaging solution for social media based on open standards like MLS goes a long way toward building confidence that it won’t be suddenly removed and that the implementation has had multiple rounds of scrutiny and will continue to in the future. MLS is a protocol that has had several implementations already despite being relatively new in the grand scheme of things, probably the most notable of which being in the GSMA’s [RCS](https://www.gsma.com/newsroom/article/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging/) messaging protocol. Private messages should actually be private, and this will take Mastodon much closer to actually meeting that promise. ### Google Chrome Adding Protection Against Cookie-Stealing Malware URL: https://www.privacyguides.org/news/2026/04/14/google-chrome-adding-protection-against-cookie-stealing-malware/ Last updated: 2026-04-14T17:41:53.000Z Google announced on their [security blog](https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html) that Device Bound Session Credentials (DBSC), a protection against session theft, are shipping for Windows users on Chrome 146. When you log in to an account on your browser, a session cookie is stored that authenticates you with that service until you log out or the cookie expires. Since cookies are just data stored locally on your machine, malware running locally can extract them and allow an attacker to get into your accounts without ever needing your password. Entire strains of infostealer malware exist to do just that. For example, the LummaC2 family of malware was used to infiltrate and harvest data including these session cookies from organizations from 2023 to 2025. Google says there’s “no reliable way to prevent cookie exfiltration using software alone on any operating system.” The only previous way to combat this attack was to detect it using heuristics, which anyone who has gotten an alert when they try to buy something with their credit card knows can be flawed. DBSC works using the Trusted Platform Module (TPM) on Windows and the Secure Enclave on macOS; hardware-backed cryptographic modules designed to prevent keys from being extracted from the machine. Even an attacker that fully compromises your operating system wouldn’t theoretically be able to extract these hardware-bound keys. Short lived session cookies are issued after proving that you possess the correct private key to the server. Google says these cookies would quickly expire and become useless to an attacker. Google says they noticed a significant reduction in session theft since they rolled out an early version of the feature over the last year. With keys being tied to hardware, you might be concerned that sites you log in to could link your sessions together. Fortunately, the feature was designed with privacy in mind: > Each session is backed by a distinct key, preventing websites from using these credentials to correlate a user's activity across different sessions or sites on the same device. Furthermore, the protocol is designed to be lean: it does not leak device identifiers or attestation data to the server beyond the per-session public key required to certify proof of possession. This minimal information exchange ensures DBSC helps secure sessions without enabling cross-site tracking or acting as a device fingerprinting mechanism. DBSC is designed to be an open web standard via the [W3C](https://www.w3.org/TR/dbsc/), which means if it gets finalized, we can start to see it in browsers other than Chrome. ### Librarians Raise Privacy Concerns Over Age Verification Bill URL: https://www.privacyguides.org/news/2026/04/13/librarians-raise-privacy-concerns-over-age-verification-bill/ Last updated: 2026-04-13T16:57:13.000Z The Coalition of Alberta Public Libraries issued a [letter](https://www.caplibraries.ca/newsroom/albertas-public-libraries-raise-serious-concerns-about-bill-28-privacy-local-control-and-the-future-of-library-services) raising privacy concerns over [Bill 28](https://apple.news/AK65z1BGPRSOCNF9hfTSdSA), or the Municipal Affairs and Housing Statues Amendment Act, in Alberta, which requires age restrictions on library materials. The letter states: > The government has indicated that regulations under Bill 28 may require age-based restrictions on borrowing and access to materials. Enforcing these restrictions could require proof of age, parental consent verification and staff-mediated access, creating new barriers for Albertans simply trying to use their public library. These requirements raise unanswered questions about privacy protections, acceptable forms of identification, and how people without government-issued ID, including seniors, people without fixed addresses, and newcomers, would be able to access materials lawfully. The letter states that the bill would apply to all 324 public library “service points” represented by the coalition, serving 99 percent of Albertans. “We are concerned about this proposed legislation because of the ways in which it undermines free speech, expression, local decision-making and the privacy of Albertans,” Sarah Meilleur, CEO of Calgary Public Library, told the [Calgary Herald](https://apple.news/Ay54ZS7GURveeKppCjquhPA). “For us, it’s also about expanded government oversight, the ability for inspectors to come into public libraries, inspect records, understand what is being circulated that creates real, serious privacy concerns for Albertans and everyone using public libraries in Alberta,” she continued. The bill echoes [age verification bills](https://action.freespeechcoalition.com/age-verification-bills/) we’ve seen in the past for online activities like websites and app stores, but this one is notable in that it expands the requirements to a public service like the library. Normally, locally-appointed library boards are trusted to make decisions about library materials. But this bill imposes regulations on a preciously municipally managed service, and risks stretching the already thin funding even thinner. The letter states: > Recent polling by Janet Brown Opinion Research found that 82 per cent of Albertans trust public libraries to make appropriate decisions about materials, compared to just 46 per cent who trust the Government of Alberta on the same question. Sixty-nine percent of Albertans prefer those decisions to be made locally by trained staff guided by local boards, and 60 per cent oppose provincial laws or regulations restricting access to library materials. They also say that formal complaints about inappropriate materials in the library are extremely rare, indicating that the current system is working well. Libraries have faced [attacks](https://americanlibrariesmagazine.org/2025/03/19/tracking-the-trump-administrations-attacks-on-libraries/) from politicians lately. As one of the last remaining public spaces where you can go that don’t ask you to buy something or constantly target you with ads, they make a juicy target for those with an agenda to push. ### Interview with EFF Executive Director Cindy Cohn: "I like to win." URL: https://www.privacyguides.org/videos/2026/04/12/interview-with-eff-executive-director-cindy-cohn-i-like-to-win/ Last updated: 2026-04-19T22:11:22.000Z Privacy Guides sat down with EFF Executive Director Cindy Cohn to reflect on her over 30 years of service defending privacy and digital civil liberties at the Electronic Frontier Foundation, the importance of community in activist spaces, and the big picture in our fight for privacy. Cindy Cohn's memoir, Privacy's Defender, is now available at a variety of retailers. [Privacy’s DefenderEFF Executive Director Cindy Cohn’s Journey Inside the Privacy Battles That Shaped Today’s InternetEFF Executive Director Cindy Cohn has devoted her life to the fight for digital rights. She’s tangled with federal officials to keep our online conversations secure from the government’s prying eyes,…![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-precomposed.png)Electronic Frontier Foundation![](https://www.privacyguides.org/content/images/thumbnail/privacys-defender-cindy-1.png)](https://www.eff.org/Privacys-Defender) Her first major case with the EFF, Bernstein v. United States, established the "right to code" and dismantled the USA's unconstitutional ban on encryption exports, paving the way for people to develop technologies like PGP and other strong encryption tools without having to register as an "arms dealer" and face government restrictions on publishing their ideas. In her career since she's represented many historic cases: suing AT&T for secretly collaborating with the NSA (Hepting v. AT&T), Sony for installing malware DRM, a vote machine company abusing copyright law to silence criticism, the DVD Copy Control Association attacking freedom of speech, and many other fights against the NSA and for internet freedom. Cohn has been with the EFF or over 30 years, and succeeded Shari Steele to become EFF's Executive Director in 2015\. Our interview discusses her works and legacy, the origins of the EFF, and the still-ongoing fight for privacy and digital liberties 💪 #### Transcript Privacy Guides sat down with Cindy Cohn, EFF Executive Director in Ann Arbor, Michigan to reflect on her over 30 years of service defending privacy and digital civil liberties at the Electronic Frontier Foundation, the importance of community in activist spaces, and the big picture in our fight for privacy. Her memoir, **Privacy’s Defender: My Thirty-Year Fight Against Digital Surveillance*, is [now available](https://www.eff.org/Privacys-Defender) at a variety of retailers. In the book, Cindy weaves her own personal story with her role as a leading legal voice representing the rights and interests of technology users, innovators, whistleblowers, and researchers during the Crypto Wars of the 1990s, battles over NSA’s dragnet internet spying revealed in the 2000s, and the fight against FBI gag orders. The following transcript has been lightly edited to improve readability. ****Nate (Privacy Guides):** ***Cindy Cohn is the executive director of the Electronic Frontier Foundation. She first became involved with them in 1993 when she was asked to serve as the lead attorney on Bernstein versus the Department of Justice. She has a long list of accolades and awards and co-hosts EFF’s How to Fix the Internet podcast and recently released her first book, Privacy’s Defender.** ***So, first of all, thank you so much for sitting down and talking to us.** ****Cindy (EFF):** Oh, thank you. ***Our first question today, what do you feel was the most impactful case of your career that you litigated?** I mean, I think it’s got to be [the **Bernstein* case](https://en.wikipedia.org/wiki/Bernstein%5Fv.%5FUnited%5FStates), because we freed up encryption: So much of the internet and the security and privacy we have today depends on encryption. It would have been a very different internet without that. Don’t get me wrong, we still don’t have a secure or private enough internet, but in terms of just the sheer amount of help we were able to give to the world I think the Bernstein case stands alone. ***You can feel free to say same answer, but what case are you most proud of?** Oh that’s such a hard decision. I mean I’m definitely proud of the **Bernstein* case. I’m also very proud of the work we did against NSA spying, because we were able to chip away in a time when it was a lot harder to to confront the national security infrastructure, and because we inspired so many people to get involved. I think that was the biggest kind of public effort that we did. I mean, we did lots of little things that aren’t in the book that I’m very proud of. One of them was, you know, we we defended some people who made a video using **This Land is Made for You and Me* \[sic\], and we ended up getting **This Land is Made for You and Me* into the public domain, recognized into the public domain. So, you know, that that felt really good as well. [The **Jib Jab* case.](https://www.eff.org/fa/cases/jibjab-media-inc-v-ludlow-music-inc) ***Yeah, I noticed the book had like three kind of like “big cases” per se, and NSA was one of them.** Yep. ***So, on the note of the NSA, the EFF has a long history of trying to reign in government surveillance, or government generally, but these days government surveillance to me seems to focus a lot more on surveillance capitalism. Like they they buy a lot of location data from private companies and stuff like that. So, do you still feel that it’s best to focus on government, or should we be trying to reign in companies?** Well, I think that this presents a kind of a false choice. ***Okay.** Because we don’t have an option to decide which one. In fact, all of the spying that I talk about in the book depends on the government drafting off of private companies. The NSA spying is the telecommunications companies, it’s AT&T. And in fact, [we sued AT&T first](https://en.wikipedia.org/wiki/Hepting%5Fv.%5FAT%26T) and then only secondarily [sued the NSA](https://en.wikipedia.org/wiki/Jewel%5Fv.%5FNational%5FSecurity%5FAgency). And then National Security Letter cases that I talk about in a situation in which the government goes to our service providers and gets information from them and then gags them forever from telling us. So, it was never really a choice. I think that now though that it’s a lot clearer how much information about us the government is gathering from private companies, and they’re the number one purchaser from data brokers. and using that data in situations that are very far afield from the kind of narrow scope of national security investigations. But now we’re seeing it used in all sorts of investigations. I think I just saw that a license plate reader was used to give a a bicyclist a ticket. ***\[Editor’s note: We could not find a news story regarding this precise incident, but there are numerous instances of Flock ALPRs being used for investigations far outside the scope of traffic violations\]** You know, I mean, it’s really become part and parcel of law enforcement’s arsenal such that we have to address both, right? And I don’t know that we will get to the bottom of the government misuse of things unless we address the corporate collection of all this data. But in either event, we don’t have the option or the luxury of choosing one or the other. Did the EFF anticipate surveillance capitalism back in the 90s? ***So, are the issues that the EFF is dealing with now the same ones that you expected to be dealing with when EFF formed? And I was kind of reminded in the book you said sometimes you felt like Cassandra, that you were issuing warnings that nobody heeded. So, for example, was surveillance capitalism one of those things you saw coming?** I don’t think we saw surveillance capitalism coming, but we did warn for a long time that the government having so much data about us could easily be marshaled against us. Right? I mean, Frank Church, the [Church Commission](https://www.eff.org/deeplinks/2013/06/response-nsa-we-need-new-church-commission-and-we-need-it-now), and some of the early work, he called it the abyss from which we cannot come back if we didn’t stop mass spying. Ed Snowden called it “turnkey totalitarianism.” So, that’s the Cassandra part: We’ve been saying for a while, all this collection and analysis of data about us in our everyday lives could very easily be turned into something that is marshaled against us by leaders who wanted to do so. And I think we’re living in a time when people are really starting to see that come to fruition — you know — very literally, and their neighbors are being picked up because of data about them that the government has collected or bought. So I think that in that way I think we did anticipate this moment when the government would be willing to really marshal this evidence, this information against us. I think if you think it’s going to stop with just the categories of people who they’re targeting now, you’ve got a misunderstanding of how history works. We’re already seeing it being marshaled against protesters, against people who are engaging in their first amendment right to film the police, and I don’t think there’s any reason to believe it will stop there. But, having said that, I’m not sure that I that I **personally* anticipated the absolute domination that surveillance capitalism would come to make. We called it “creepy, but legal” when Google started placing ads just based on, you know, scanning people’s search terms and things like that. ***The contextual ads.** The contextual ads, like we thought that was creepy but legal. And I still think it is creepy but legal, but it’s nothing compared to what came after. I don’t know that I anticipated that it would become the **predominant* business model online. Some of that is due to the consolidation of the industry, which is also something that I’m not sure I saw. You know, in the 90s and the early 2000s, there were little companies that were coming eating the big companies lunch. You might have started off with an **Alta Vista* search and then and then you used a **Yahoo* search and used… ***Ask Jeeves \[laughter\]** **Ask Jeeves*, and then… right, there was a there was a rolling that stopped with Google, right? And this didn’t stop because there was no better way to search the internet, it stopped because of the consolidation and some business forces, the refusal of the United States to enforce antitrust law in a way that really protected competition, and instead falling prey to some other theories. Those are things that kind of happened **outside* tech that I would say as a constitutional lawyer, thinking about the first and fourth amendment, I didn’t foresee because it really kind of affected our rights, but kind of came from this other direction that isn’t really where we lived, but now has tremendous implications for free speech, for privacy, but it really came out of the business side. And so I think those are a couple of things that I didn’t, we didn’t quite foresee. Of course, we pivoted. EFF has been talking about consumer privacy for a long time. We have definitely got a whole [section](https://www.eff.org/issues/privacy) of the organization devoted to that, and another section devoted to [competition](https://www.eff.org/issues/competition). So we were able to pivot and grow and meet those moments. But if you’d asked “1996 Cindy” if that was where we were going to go, I would not have put those on the list. ***Yeah, it’s very holistic. I like you pointing that out. It’s things that happen over here \[outside of tech\] can still affect our privacy.** Why privacy is fundamental to democracy and self-government Yeah, and we’re living in a time now where I think that the attacks on privacy are coming from so many different directions that it’s easy for people to feel overwhelmed. And I totally get that. On the other hand, I really believe it’s foundational, like not just around kind of consumer issues, but increasingly so as we’re seeing price discrimination, right? The amount you pay for something being based on all the other things that the company knows about you from surveillance, rather than a fairness, or how much the thing is worth, or anything like that, but really maximizing out… and I think it’s starting to hit people a lot more clearly than it used to, and I think it feels very unfair. But also in the context of government surveillance. So I think that we are in a time where we’re seeing some of the impacts of this, and it’s again it feels like it’s coming from all directions sometimes. But you know the the other reason I care about this isn’t about the consumer side as much. The other reason I care about this a lot is: I think privacy is fundamental to democracy to self-government. Privacy is a way that the people who have less power have protection from people who have more power. Right? That little zone of privacy is how we can navigate the world in which we might have a government that we want to change. We might have, you know, my colleague Eva Galperin works with domestic violence victims. These are people who need privacy from people **in their own home* in order to plan their escape for their lives. Whether it’s in your own home or all the way up to **I want to be able to vote for who I want to and not have the government know*— it’s why we have a secret ballot in the United States — privacy is kind of embedded into many, many of the ways that people with less power get protected against people who have more power. ***I remember you mentioned in the book and I’ve heard this argument from other people too that like the founding fathers needed privacy to do what they did. Perfect example.** Yeah, absolutely. And you know [Jefferson has a cipher](https://www.monticello.org/encyclopedia/wheel-cipher) if you go to Monticello. ***I think you mentioned that he did.** It’s a physical thing: You can see the little, you know, turn the things of it. And of course, he was in Paris, and John Adams was in London, and the rest of the founding fathers of Continental Congress was in the United States. They had to have a way to communicate with each other across distances that wouldn’t be read by the British, and they used cryptography. So whether you’re an originalist or somebody who’s really modern, freeing up cryptography I think makes perfect sense. ***Little bit shift of direction, but as a personal note, I want to say thank you for saying in your book that you weren’t really drawn to computers as much as other hackers, because I grew up a little bit sheltered: I kind of missed the days of like BBS’s and IRC and all that kind of stuff. I just really appreciate the the message that I took away from that, is that there’s room for people in the privacy space beyond just developers and coders and like… it’s for everybody.** So much, right? We all need privacy no matter what we do. But I also think that one of the things isthat technical privacy hasn’t been as widely spread and understood, because it has seemed like it’s stuck in this little world, and if you’re not technical you can’t engage in it. I am trying to break that out a little bit because I don’t think we’re going to win — I mean, I’m a strategist in my heart: We’re not going to win if the only people who understand how important privacy are, are people who have other technical skills. So, I think it’s really great that you were drawn to it, and you feel like you can have a place in trying to protect privacy regardless of whether you can say, write an encryption cipher in your spare time, right? Barlow’s “Declaration of the Independence of Cyberspace” ***You said that the moment you read John Perry Barlow’s** [***A Declaration of the Independence of Cyberspace**](https://www.eff.org/cyberspace-independence)***, you disagreed with it.** Yes. ***Um, would you explain why, please?** Yeah… oh, boy. Barlow and I went round and round about this. I mean, I uh… you know, we became very close in the end of our lives, so he’s a dear friend, and I understand why he did it, so… I want to say that, you know, Barlow was trying to project something onto this this the world in hopes that it would make make it self-manifest. ***Uh-huh.** And what he really wanted was the idea that the digital world could be better than the offline world: It could be a place that was more fair, more just, that would treat people equally regardless of who they were, or where they come from, or what color of their skin. You know, he really came out of a a view that maybe this technology could help make things **better*. And so he projected it as if, “oh weary giants of flesh and steel, you have no jurisdiction.” I mean, he was a beautiful writer, too. But like the whole point of it was to try to say **old world, hands off. We were building something new and we’re trying to build something better.* So that, I think, is gorgeous. It’s beautiful, but it is **aspirational*. And… the problem that I had with it is: I think a lot of people took him, you know, he didn’t say “oh, this is my aspiration.” He projected it as if it was an absolute truth. And of course it’s not. First of all, we have brought most of the problems of the non-digital world into the digital world. But also, this idea that governments would have no say in what was going on online wasn’t realistic, even when he wrote it, because wherever your feet touch the ground, you’re subject to the jurisdiction, and those cops, and FBI, and NSA they can come get you. The fact that you did it online is not going to mean that you don’t face any consequences for what happens in the offline world. And I think he was he was trying to do something that inspired people, and honestly, he inspired a lot of people. But I think that the realist in me, and the lawyer in me, had a hard time thinking about it in inspirational terms. I think it also led a lot of people to think that the digital world was **magically* going to be better, like it was **inherently* going to be better, and I don’t think Barlow thought that at all. He founded the EFF. You don’t found an organization committed to digital civil liberties and hire fighty lawyers like me if you think it’s magically going to be better. But I think the way and the posture in which he made the declaration led a lot of people to think both that it was inevitable, and that it was already here. I do think Barlow and I might have disagreed about some of it. ***Sure.** But I think, again, he was a poet trying to inspire people and I’m a lawyer trying to litigate, and I would say 80% of our disagreement was due to just that difference in where we sit. Are our rights inalienable, or do we need to fight for them? ***Similarly, you said that Barlow said that no one gives you your rights, you have to take them.** Yes. ***But, Edward Snowden argues that nobody has to defend their rights. Rather, the government, for example, has to argue why they need to take them away. So who do you think is right? Are we born with those rights and somebody has to explain why they’re taking them, or do we have to go and get them?** I mean, I think this is one where Barlow’s living in the world of the real, and Snowden is living in the world of the philosophical, right? I mean, I believe that we all have inalienable rights that we, we’re born and we have these rights. They’re part of the deal of being born in the United States. You might have a slightly different set of rights if you were born somewhere else. And I think we all should have the universal declaration of human rights just by virtue of being born on this earth. So I do think that they are inherent, and I think that Ed’s right to say that the justification for taking them away, the burden should be on the government who’s trying to take them away, not on us trying to defend them. I think what Barlow was saying was: the reality is, you can’t just sit back and expect that to happen. We **have* to take our rights. We have to defend them. We have to… the reality of the lived world is that we’re not going to have a first amendment online unless we stand up and we say we want the first amendment online. We’re not going to have the Fourth Amendment in our, you know… The EFF was **started* because of some Secret Service raids and cop raids on early bulletin board systems where the government took the position that the Fourth Amendment just didn’t apply. And one of our very first cases, called the Steve Jackson case… [***Steve Jackson Games**](https://www.eff.org/cases/steve-jackson-games-v-secret-service-case-archive)***.** …was to establish that indeed the Fourth Amendment **did* apply. Now, you could say that I think of that as us taking our rights, but it’s not like us taking our rights and creating new ones. It was us **establishing* that this new context doesn’t diminish our rights. So, I think Ed’s right that they shouldn’t have even tried, which \[laughter\] is kind of… ***That would be nice, haha.** Yeah. And I think Barlow’s right we can’t just sit back and assume that the government and society are going to protect our rights. We have to give it a fight. ***So, shifting gears a little bit: In your your memoir, you talked about a certain trip you took to a music festival where you made some lifelong friends, and you said that “having a place of identity outside of law and technology has been critical to my ability to keep doing the work, even when it’s hard, or we don’t win, or have our wins snatched away.” So, if you could, I’d love for you to talk a little bit more about that, because I’ve seen a lot of people in the privacy space burn out from just doing too much, doing more than they need to. And I think that it’s really important for people to have that space they can get away from.** Yeah. I mean, part of why I wanted to write this as a memoir is I did want to include some of the ways that you do this for the long run. And that’s both because I think it’s fun and important, but also strategic. The government attorneys on the other side, they have 30-year careers. If we are taking people and they’re burning out after two or three years, we’re always in the **eternal kindergartner or first grade* on our side and they’re, you know, in junior high, right? Or high school, wherever you want to take the metaphor. So for me anyway, it is true that having a community of people outside of the work, where I do something else and I’m not the leader, has been the way I’ve balanced being the leader in kind of some of these long and hard fights. And you know, it happened for me that it was a community of people who who I go see music with. And we create our own little festival every year, and in that world, I am not the head of it. I am not the executive director of my friends. In many ways I’m very much a follower and let other people lead in that, because putting that down too, I just think that when you’re fighting and you’re fighting for your rights and you’re in these long battles, you got to be able to take off your armor sometimes. You got to be able to show up without that. This is the space where I’m able to do that, and it really does nurture me. You know, you put down your armor, you go over here, you listen to some music for a while, dance with your friends, and then you can come back and put the armor on, and you’re ready for the next thing. I think finding that balance — and what works for me won’t work for other people — but I think that that finding that balance for folks is is really, really important if you want to keep doing this for the long run. My husband has also been doing this kind of work for a very long time, and you know he builds like blinky art… ***Oh, that’s cool.** You know, he’s a pretty geeky person but he does electronics right? His daytime work he does software for human rights, and in the evening he comes home and he’s like hooking up little blinky lights, so ***\[Laughing\]** So everybody, well not everybody, but I think the way to do this in a healthy way for the long run and not burn yourself out is to find something else that feeds you that isn’t that work. ***I can relate to that. I have some other spaces where I’m not really “Nate” and so I can, even though I’m not an executive director obviously, I have that space where I’m not “Nate from Privacy Guides.” I can be this other person, and it’s it’s great.** Yeah. And I think you know being able to — not everybody can compartmentalize like that, but I think if you can, it gives you a cushion. ***It helps a lot, yeah.** Staying motivated in an uphill battle ***On that note, as you noted in your book we often take more losses than wins. Are there any other ways to stay motivated in the face of such a long, drawn out uphill battle?** I mean, I think there’s a couple of things. I mean, I like to win. You know, there is that old saying, “the real victory was the friends we made along the way.” I don’t — I don’t subscribe to that! It’s not a substitute: We need to win because people’s lives are at stake, and it’s important. On the other hand, you **do* meet amazing people. You **do* get incredible things to happen in your lives, and again some of them are stepping away for a while, but some of them are just like building a team having a team that works together, sharing the losses and the things so you don’t feel so alone. We used to joke at EFF that we had an “outrage stick,” like a talking stick, and that we would pass it around, and one day something would happen and you’d be the person holding the outrage stick and you’d be really upset and all your all the rest of the team would be there for you going “yeah that really sucks” and “we’re here for you,” and then the next day it’s somebody else who holds the outrage stick, we would pass it around so that we would kind of take turns both being the people who are really upset, but also the people who are **not* at the moment, and so can kind of hold it together while, you know, you take your moment to be really pissed off. That’s another way that you kind of share the load a little bit with other people. I really think that, you know, I joke that I say that privacy is a team sport, and I mean that kind of literally and that you’ve got to communicate with people. ***Yeah.** But I also think I mean it in a organizing way: like having a team, having a group of people that you’re doing this with, and they don’t have to be physically present. You know, the digital world makes it possible, but having people who you’re in it with is one of the ways that I have certainly held it together over the long run. Eva Galperin, EFF’s resident “outrage fairy” ***I have to ask, because I follow her on Mastodon. How often does** [***Eva \[Galperin\]**](https://mastodon.neat.computer/@evacide@hachyderm.io) **get the outrage stick?** Yeah. You know, for a while, I don’t know if I should say — ***We can cut it if you want.** Eva had a little thing on her door at EFF that said “outrage fairy.” ***I love her. She’s fantastic.** So, yeah, she certainly takes her takes her turn, right? But she has other times where she’s there with every for everybody else. But yeah, absolutely. ***I just — She’s so passionate online. That was my first thought. I’m like, I bet she has that a lot.** She definitely has it. She has her share. But she’s also just more vocal, right? She’s just more willing to be out there in things, and I really, really appreciate that. I’m not somebody who’s as public a person as Eva is. This is a new experience for me. But yeah, I think that she does a good job of expressing outrage and channeling other people’s outrage as well. And the other thing that I think she’s really brilliant at is pointing it in the right direction, right? People get upset, and Eva’s analysis of where you should be mad helps a lot of people kind of focus in on the **bigger picture* bad guys, rather than the **smaller picture* bad guys, and also it’s really easy in this world — I’m getting a little philosophical — we have another phrase at EFF which is “point your guns outside the tent,” with the idea that you’re working with other people and they may not see things the same way you do, they may have a slightly different set of priorities, they may have a different way of doing it. Trying to understand the difference between the people who are basically on your side, but who you disagree with on strategy or tactics or priorities, and making sure that you’re not spending your energy shooting at them, and actually shooting at the people who you’re all trying to to prevail against. And recognizing those differences and not getting caught up in that, because I’ve seen that happen in a lot of joint actions sometimes too, and people end up more pissed at their friends than they are at their enemies, and I’m always like, you know, you can have hard conversations and talk about it, but the guns should be pointed outside the tent. ***Absolutely. You said later in the same passage when you were talking about the music festival, you said that “community is my refueling place.” Like we talked about, it’s good to have balance and everything but can you speak to the importance of community?** I think both inside and outside the movement, again you can look at it purely strategic: which is one person by themselves cannot do nearly the amount that a bunch of people together can, and it’s not just one by one, it gets exponential when you get enough people together. So I think as a strategy matter, one person is never… I mean, we love these little narratives about “the single person who changed the world.” That is never the case in any of the things that I’ve done, except in very, very small situations. And even then when you touch on them, even when you talk to people who are like, “oh, you invented **blah blah blah*.” They’ll be like, “well, yeah, but that’s because Bill invented **this* and Joe invented **this* and Sally invented **this* and then I came along and I just added this little bit on top and now I get all the the attention.” I’ve seen this on the technical and the non-technical side. Strategically, community is critical, right? Having a bunch of people who are doing this together. But it’s also just a place, again, where you can put on a different persona, take a different tact and refuel, really get your get your energy back. That’s how it’s worked for me. Again, I’m an extrovert, I like people. I know there are many, many people who are committed to privacy for whom the idea that **they need to go to a music festival* to get it will recoil them. And I am absolutely not saying that. I’m using my story to try to help people see what is it for you, and it might be being all by yourself with your cats for the weekend. That might be the best refueling that you could do, or whatever. I think that it’s not important **what it is*, it’s important that there **is* a refueling place. ***On that note, how do you think, especially in the privacy community, how do you think we can foster healthy communities?** Well, I think we have to give each other grace. I think if somebody comes in and they want to help, you welcome them, and don’t give them a litmus test about whether they’re cool enough, or they know enough about the tech, or any of those kinds of things that are sometimes done in some of these communities that I think are very unwelcoming and unhealthy. I joke that “the good guys have better parties,” but what I mean is like bring some joy. Like this is hard work. We don’t always win, but that doesn’t mean we have to be sad all the time or unhappy all the time. There is so much room for joy and engagement in this, that helps people in it for the long run but also helps attract people to it. So I think those are all things to think about. I also think you know thinking about kind of doable short-term goals even while you’re aimed at the longer one. So, inside EFF we have these long cases, and and I talk about them in the book. In between them we had lots of short cases that we would win easily. We did a whole set of cases that we call **John Doe cases* that are helping people have the right to speak anonymously online such that the government — or the **whoever* — that’s mad at them has to make a showing that they did something wrong, before they get their names. You know people, would have a website that says like “Tesla sucks” — and this is just an example, it’s not a real case… that I know of — and companies would come and try to scare them out of having that place, in part by trying to identify them and \[make them\] worry about retaliation. We would take these cases just periodically, along with a bunch of other people, and we started moving the law very slowly towards “if you want somebody’s ident — if they’re anonymous and you want their identity, you have to meet at least a threshold level showing that they did something wrong, not just that you’re mad at them. And thereby we protected these things. The thing about the **John Doe* cases is they’re a motion that happens at the very beginning of the case. The whole thing is usually over within 60 days, and a lot of the times we won. I think most of the times we won. Occasionally we wouldn’t win, but like having little wins in the middle of the big fights, and thinking about the work in that way — like is there a chunk we can do now even while we’re doing the longer chunk — that kind of balance is very helpful for longevity as well. And not every fight has those, but if you can get your local community to decide that they need more transparency from the license plate reader company that your law enforcement’s using, and make them do a report about how they work, you might be able to get that **on your way* to maybe getting the city council to decide to unplug them. So thinking about like what’s doable in the **short* term, as long as the short term isn’t getting in the way of the **longer* term, you might be able to get some wins, get some momentum, bring other people into the cause by doing something that is a little easier to do than your long-term goals. ***In the book, you mentioned “**[***jawboning**](https://en.wikipedia.org/wiki/Moral%5Fsuasion#Jawboning)***,” which is when governments put inappropriate pressure on companies to get them to do things that the government wants.** ***This is kind of three questions: How frequent is this? How can projects defend themselves against this? And how can those of us on the outside of those projects know if this is happening or not?** ***I feel like this is a big concern with a lot of privacy people.** A lot of privacy people… Um, jawboning is something that used to be pretty rare, and something that people on the **right* would complain about. It kind of grew up during the COVID era, when a lot of people on the right felt like the Biden administration was going too far and trying to get information, get speech taken down off the internet. And there was a Supreme Court case that happened about that that set the standard. I wouldn’t say we were exactly happy with it, but it wasn’t too bad. But the Trump administration has ramped up jawboning tremendously. And they’re not even hiding it anymore. And [the EFF is representing ICE Block](https://www.privacyguides.org/news/2025/11/22/eff-files-lawsuit-against-doj-and-dhs-to-uncover-information-about-removed-ice-tracking-apps/) in — So this is a little app that helps people report where they see ICE arrests that the government, Kristi Noem when she was the head of DHS, got taken down off of the Apple store and the Google Play Store. ***Google like proactively did it after…** Yeah after, but you know, we don’t know how proactive it was because we don’t know what’s going on in the background. ***Sure.** But yeah, they did, they both took them down, and Apple’s actually taken down some other ones that’re not even close to that, right? They’re now **self-censoring* these kinds of things, so the jawboning worked really well. It worked so well that the companies are now **proactively* taking down perfectly lawful tools, so we’re seeing a lot more of it, and we’re in this litigation to try to push back on it. How can you know that’s happening? Well sometimes the app providers don’t even **know* for a while. I mean, the app stores… it’s pretty hard to know what’s actually going on if your app gets taken down. They’re not very good at being responsive. But pushing on that, I mean, so the app stores — it’s happening in app stores now, so I’m talking about in terms of app stores, but it could happen in any context — But having the \[developers\] who are actually interacting with and putting it up on the app stores tell the community is a really important thing. They are very rarely gagged. I don’t think there’s a situation in which they’re gagged. Sometimes they’re quiet because they’re trying to negotiate. One of the ways people have traditionally tried to figure out these kinds of things is things like warrant canaries. You know, I would say that they haven’t been nearly as useful as people have thought they would be, in part because people don’t check them very much and so you don’t know. ***They’re a little controversial.** I’m a little uh hesitant to endorse them fully, but it is a strategy that some app developers have used for other kinds of government coming in and gagging them. I think most of these app store takedowns are not… there’s no gag. There’s no secrecy that like that the creator of the app is in a position where they can’t tell the community. It’s always just that the app stores are not forthcoming about what’s going on or why. I don’t know that there’s too much we can do about that, absent congressional investigations or the FTC or… you know, assuming a government or even your state AGs or state folks, I don’t think the federal government is going to be your friend if the federal government is the one getting them taken down. Although at this point, look, Kristi Noem came out and said, “We did it.” Like it used to be it was kind of secret, and now it’s not secret at all! They’re very proud that they have the power to take things out of app stores. So it may be that the community doesn’t need to worry about the secrecy. They just need to mobilize against what’s actually happening, because I don’t think it’s that big a secret anymore, at least with this administration. The dangers of the app store duopoly ***Yeah. I’ve I’ve seen some app developers have, like you said, that stuff’s been taken down and they’ve talked about it online and they’ve been — like not for jawboning reasons I think — but they’ve posted like they said “it was for this reason so I emailed them back, and I’m like the code is right here you can see it doesn’t do that,” like it’s whole runaround, so yeah, app stores are not very transparent.** No and it’s why we shouldn’t just have two app stores. I mean, at the end of the day, this duopoly of app stores is problematic, right? Because they only have to put the squeeze on two companies, and they can take stuff away from us. You know, it’s part of why EFF has a whole competition area now, is that we began to see that the consolidation and you know… we’ve had two telecommunications companies, Verizon and AT&T, for a long time. This is part of the network neutrality concerns. And now we’re seeing it with app stores. We’re going to see it with other things, because of the consolidation of the industry. So, it’s a really important for us to support decentralization, to support open source and other kind of ways for people to get things that don’t require either of the big companies. There are people who are trying to build distributed systems where you don’t have to rely on Amazon or Google for cloud storage, right? That’s actually pretty hard given how dominant they are. But I think it’s really important. I don’t think we can trust these companies anymore, that they’re going to be neutral. There was a period in which I think it **was* a safe bet that the companies just wouldn’t get involved. And you know, they they would let people sort it out and they wouldn’t put a thumb on the scales. And I don’t think we can say that’s true anymore. We can’t trust it. ***Near the end of the book, you said that EFF has been instrumental in ending at least one mass surveillance program, and dramatically scaling back another.** ***I feel like we haven’t seen any major whistleblowers since like Vault 7, which was 2017\. Yeah. Um it’s been a while since we’ve had… was it Mark Felt — no, he was deep throat…** Mark Klein. ***Yes,** [***Mark Klein**](https://en.wikipedia.org/wiki/Mark%5FKlein)***, thank you.** …was 2005, and then [Snowden](https://en.wikipedia.org/wiki/Snowden%5Fdisclosures) was 2013. ***Exactly. So how can we get more insight into what the government’s doing right now? Because it to me it feels kind of like a “Vatican secret archive” thing, where it’s like, you have to know what book you’re looking for, and then we’ll go find it. It’s like, well, if I don’t know the programs there, how do I do a FOIA request?** Yeah. I mean, I think that I do worry about that a lot, and I don’t think it’s an unreasonable concern. While I don’t like the FISA amendments act — Section 702 — theoretically, Congress is supposed to have oversight over these things, and many more things have to go in front of the FISA court. Are there things that could be outside of that structure that they’re doing in secret that we don’t know about yet? Absolutely. We just have to wait and see. They are not supposed to be doing other secret things. But… ***\[Laughter\]** I mean, “not supposed to” as in I don’t think the law gives them space to do a lot of it, because that’s part of what Congress tried to do, was to bring them all under this umbrella of **congressional oversight* and **FISA court oversight*. Now, they didn’t do enough, and right now I’m worried Congress is asleep at the switch, right? So, I think it’s worth it to be to be worried, but yeah, we’re going to have to wait and see. It took, you know, after the Patriot Act was passed in 2001, it took until 2006 before [Mark Klein](https://en.wikipedia.org/wiki/Room%5F641A) walked into our door. So… and we had heard rumors. We heard lots of rumors about lots of things. We knew we were actually preparing a complaint with some of these things. We had enough information. I don’t have the same trickle of information right now about new programs, but I don’t take much from that like that. I don’t trust that that means there aren’t things. But look, 702 is up for renewal in April! They’re talking about kicking it down the road again, because it’s actually pretty controversial, it’s not sure they can get it. But this is a good time for people to show up and try because they are looking deeply. Senator Wyden did you know, “the Wyden siren,” I think is what they call it. ***I just heard that for the first time the other day!** \[Laughing\] I just learned that! He gave one of those speeches where he said “if the American people knew what I knew, they would be upset.” So that that tells me there’s stuff going on there. Although, what he said was not necessarily… I didn’t parse it to mean there’s a whole other program we don’t know about, as much as “if the American people knew how they were interpreting the rules that they have so far, they would be very upset.” But yeah, those are the kinds of things we watch for. We watch for whistleblowers. We watch for people like on the intelligence committees like Wyden who are courageous and try to do as much as they can without crossing the line. And when if we learn about more, we’ll jump on it. It’s an ongoing, it never… I mean maybe it would end someday? But in general, the national security people are playing the long game. And the long game for them is that nothing happens anywhere on the globe that they don’t have access to collect it all, manage it all. I understand why they have that philosophy, but it’s a disaster for the rest of us. ***Yeah.** I think it’s very dangerous. And I think it is dependent on this idea — that they are honorable and will never misuse this power — that is just demonstrably false. It was false before the Trump administration came into effect, but it’s definitely false now. They fired all those guys. ***Yeah.** All those guys who used to tell me, “Don’t worry, we have internal protocols, and we would never do anything wrong!” They all got fired and their clearances pulled. So, like that’s got to tell you something, that happened because the Trump administration doesn’t have the same sense of honor, and the idea that it would never misuse these tools in ways that are problematic for civil liberties that their predecessors did. And again, I think we’re seeing that… We’re seeing it in a bunch of different places with the Trump administration. I see no reason to not think that’s the same is true here. ***Last question, turning it over to you. Is there anything I didn’t talk about that you want to bring up?** No, I mean, I just really thank you for doing this. I think you’re doing really heroic work out here. ***Oh, thank you!** I was really psyched to hear from you, and I think that having people all throughout the country who are trying to get the message out, and also really demystify privacy and make it accessible to people, I just think it’s fabulous and I hope you continue to do it. ***Thank you so much.** All right. Thank you. ***We want to thank Cindy so much for being so generous with her time and sharing her wisdom with us.** ***Her new book,** [***Privacy’s Defender**](https://mitpressbookstore.mit.edu/book/9780262051248)***, is out now and available through MIT Press, Bookshop.org, or wherever you buy your books. Nate has read the book and loved it, and many of the questions in this interview were directly inspired by it. If any of the topics in this interview interested you, definitely grab a copy, because we barely scratched the surface.** ### Data Breach Roundup (Apr 3 - 9, 2026) URL: https://www.privacyguides.org/news/2026/04/12/data-breach-roundup-apr-3-9-2026/ Last updated: 2026-04-12T18:07:38.000Z ## Die Linke German political party confirms data stolen by Qilin ransomware Die Linke is a "German democratic socialist political party." Bleeping Computer says they have 123,00 registered members and 64 members in German Parliament. They haven't revealed a lot of details about this breach, but the party claims that the membership database was not accessed while the attackers claim they stole information on employees at the party HQ. [Die Linke German political party confirms data stolen by Qilin ransomwareThe Qilin ransomware group has claimed responsibility for an attack against Die Linke (‘The Left’), forcing an IT systems outage at the political party, and threatening sensitive data leak.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-94.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/DieLinke.jpg)](https://www.bleepingcomputer.com/news/security/die-linke-german-political-party-confirms-data-stolen-by-qilin-ransomware/) ## Mercor, a $10 billion AI startup that works with companies including OpenAI and Anthropic, confirms major data breach Mercor is a startup that provides training data to AI companies. This (unconfirmed) incident, alleged to be part of the recent LiteLLM supply chain attack, claims that some data sets used by Mercor have been leaked. A sample of the data shows Slack data, internal tickets, and two videos between Mercor's AI and contractors using the platform. The attackers claim to possess source code and database records. [Mercor, a $10 billion AI startup, confirms it was caught up in a major security incident | FortuneThe high-flying startup that provides AI training data to OpenAI, Anthropic, and Meta confirms it was hit by a “supply-chain attack.”![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-98.png)FortuneBeatrice Nolan![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-2205174217-e1775146600387.jpg)](https://fortune.com/2026/04/02/mercor-ai-startup-security-incident-10-billion/) ## Hackers steal and leak sensitive LAPD police documents This breach includes 337,000 files totaling 7.7 TB. The stolen data included police officer personnel files, internal affairs investigations, and discovery documents that can include unredacted criminal complaints and personal information, such as witness names and medical data. The data was originally published by World Leaks but taken down for unknown reasons. Distributed Denial of Secrets said that they were able to review it before it was taken down. [Hackers steal and leak sensitive LAPD police documents | TechCrunchThe LAPD said the breach affected “a digital storage system” belonging to the city’s Attorney’s Office. The World Leaks extortion gang was reported to be behind the attack.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-45.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/lapd-car-agents-night-1.jpg)](https://techcrunch.com/2026/04/08/hackers-steal-and-leak-sensitive-lapd-police-documents/) ### Microsoft Hates Security, "Surveillance Wages" Are a Thing Now, FBI Recovered Signal Messages From Notification History, and More! URL: https://www.privacyguides.org/livestreams/2026/04/10/microsoft-hates-security-surveillance-wages-are-a-thing-now-fbi-recovered-signal-messages-from-notification-history-and-more/ Last updated: 2026-04-19T14:26:15.000Z This Week in Privacy #48 _This post is for subscribers only._ ### Your Inbox Isn’t Private — Here’s How to Fix It URL: https://www.privacyguides.org/videos/2026/04/09/your-inbox-isnt-private-heres-how-to-fix-it/ Last updated: 2026-04-09T21:51:45.000Z Your email address is the key to your digital life, learning how to secure it properly is instrumental in protecting your privacy & security. In this video we'll talk about the pitfalls of mainstream email providers, suggest alternatives and how to make the transition to a new email provider smoother. Lets dive in! #### Sources 0:26 1:43 1:59 2:07 2:13 2:39 2:49 3:09 3:24 3:38 4:37 5:24 5:53 6:10 6:52 7:19 7:25 7:32 8:12 8:31 8:44 9:05 9:11 ### OkCupid Settles After Selling 3 Million Photos to a Facial Recognition Company URL: https://www.privacyguides.org/news/2026/04/05/okcupid-settles-after-selling-3-million-photos-to-a-facial-recognition-company/ Last updated: 2026-04-05T20:20:57.000Z The FTC has [determined](https://www.ftc.gov/news-events/news/press-releases/2026/03/ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party) that OkCupid and their owner Match Group don’t have to pay a fine after settling a case in which they shared 3 million user photos and location information to a facial recognition firm. OkCupid and Match did not admit or deny the allegations, but agreed to be permanently prohibited from misrepresenting the way they collect and share personal data. In a [statement](https://apple.news/AN4HcBWnOTdGONA2dehy0gA) to *Ars Technica*, OkCupid said “While we do not admit any wrongdoing, we have settled this matter with the FTC with no monetary penalty to resolve an issue from 2014 and move forward.” They went on to state that they do not operate the same way they did in 2014 and have “strengthened our privacy practices and data governance to ensure we meet the expectations of our users.” An [article](https://www.nytimes.com/2019/07/13/technology/databases-faces-facial-recognition-technology.html) by *The New York Times* from 2019 documents a facial recognition AI company called Clarifai that claimed to have access to OkCupid’s database of faces, likely the company that was sent the data although the party is not named by the FTC. As well as OkCupid, Clarifai had signed a deal with a social media company to use photos of faces from them as well. OkCupid said in the article that they did “not enter into any commercial agreement then and have no relationship with them now.” Clarifai gained access anyway despite the lack of a “commercial agreement,” and its users were not notified or informed in any way how their data was being used. Matt Zeiler, founder and CEO of Clarifai, said that he would “would sell its facial recognition technology to foreign governments, military operations and police departments provided the circumstances were right,” according to the same NYT article. The FTC, in its complaint, detailed that > Humor Rainbow specified that it does not share personal information with anyone other than service providers, business partners, or other businesses within its family of businesses; in response to legal obligations (e.g., in response to a subpoena, court order, or investigation); or when it informs users and gives them an opportunity to opt out of having their personal information shared. Humor Rainbow is the parent company of OkCupid and subsidiary of Match Group. According to the FTC: > when a news story revealed that the third party had obtained large OkCupid datasets, OkCupid claimed to the media and OkCupid users that it was not involved with the third party. The blatant lies and misuse of their customers’ data earned them a whopping $0 fine and essentially a “don‘t do that again” from the FTC. ### Claude Source Code Leak, Influencers' Kids Can Request Deletion, LinkedIn Scrapes Your Browser Extensions, and More! URL: https://www.privacyguides.org/livestreams/2026/04/03/claude-source-code-leak-influencers-kids-can-request-deletion-linkedin-scrapes-your-browser-extensions-and-more/ Last updated: 2026-04-19T14:25:01.000Z This Week in Privacy #47 _This post is for subscribers only._ ### Data Breach Roundup (Mar 27 - Apr 2, 2026) URL: https://www.privacyguides.org/news/2026/04/03/data-breach-roundup-mar-27-apr-2-2026/ Last updated: 2026-04-03T19:45:34.000Z ## Dutch Police discloses security breach after phishing attack There's no details at all at this time, but the Dutch National Police (Politie) are claiming that the breach was extremely limited and hasn't affected any citizen data. It's unclear if any employee data was impacted. [Dutch Police discloses security breach after phishing attackThe Dutch National Police (Politie) says a security breach resulting from a successful phishing attack has had a limited impact and hasn’t affected citizens’ data.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-88.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Dutch_Police.jpg)](https://www.bleepingcomputer.com/news/security/dutch-police-discloses-security-breach-after-phishing-attack/) ## Iranian hackers claim breach of FBI director Kash Patel’s personal email account TechCrunch confirmed that at least some of the emails leaked by Handala were from Patel’s alleged Gmail account by verifying information contained within the message headers. The emails seem to span from 2010-2019\. Neither TechCrunch nor Reuters (who originally reported the story) commented on the contents. [Iranian hackers claim breach of FBI director Kash Patel’s personal email account | TechCrunchHandala, a pro-Iranian hacking group allegedly working for Iran’s government, published emails it said were taken from the Gmail account of FBI director Kash Patel.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-41.png)TechCrunchLorenzo Franceschi-Bicchierai, Zack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/patel-2266851646.jpg)](https://techcrunch.com/2026/03/27/iranian-hackers-claim-breach-of-fbi-director-kash-patels-personal-email-account/) ## Healthcare tech firm CareCloud says hackers stole patient data At this time the company is still determining exactly how many patients and what data was impacted, but it does seem that the measures they had in place were helpful. It says that only one of six environments was compromised and only for about 8 hours. Obviously this is still bad, but it's good to see that they had systems in place to mitigate the damage, and they're being very quick with the disclosure (the event occurred March 16). [Healthcare tech firm CareCloud says hackers stole patient dataHealthcare IT firm CareCloud has disclosed a data breach incident that exposed sensitive data and caused a network disruption lasting approximately eight hours.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-91.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/CareCloud.jpg)](https://www.bleepingcomputer.com/news/security/healthcare-tech-firm-carecloud-says-hackers-stole-patient-data/) ## Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web Duc is a Toronto-based app that claims to offer money transfer services, even to overseas countries like Cuba. It has at least 100,000 downloads according to the Play store. This breach was the result of an exposed Amazon server, revealing hundreds of thousands of files going back to 2020 including government-issued IDs (such as driver's license or passport), selfies (for know-your-customer verification), and spreadsheets with names, addresses, and transaction details. [Exclusive: Money transfer app Duc exposed thousands of driver’s licenses and passports to the open webAn exposed Amazon-hosted server allowed anyone to access reams of customer data without needing a password.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-42.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/money-firehose.jpg)](https://techcrunch.com/2026/04/02/canadian-money-transfer-app-duc-expose-drivers-licenses-passports-amazon-server/) ## Telehealth giant Hims & Hers says its customer support system was hacked Hims & Hers sells weight loss dugs and "sexual health prescriptions." According to a spokesperson, attackers used social engineering to gain access to the stolen data. The company confirmed only that names and contact information were stolen, along with "other unspecified personal data" in the support tickets, but said only that health records were unaffected. The number of victims is also unknown, but California law requires disclosure if it's more than 500, so we know it has to be at least that many. [Telehealth giant Hims & Hers says its customer support system was hacked | TechCrunchThe U.S. telehealth giant says hackers stole customer support ticket data over the course of several days in February.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-43.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/IMG_3413.jpg)](https://techcrunch.com/2026/04/02/telehealth-giant-hims-hers-says-its-customer-support-system-was-hacked/) ## CERT-EU: European Commission hack exposes data of 30 EU entities This breach took place March 19 as part of the [Trivy](https://www.bleepingcomputer.com/news/security/trivy-vulnerability-scanner-breach-pushed-infostealer-via-github-actions/) supply chain attack, and was discovered March 24\. We are now learning the scope and scale of the breach. About 340 GB of data was stolen including names, email addresses, email content, usernames, personal information, and more. It may affect as many as 42 internal EU clients and 29 other EU entities using the "europa.eu" web hosting service. [CERT-EU: European Commission hack exposes data of 30 EU entitiesThe European Union’s Cybersecurity Service (CERT-EU) has attributed the European Commission cloud hack to the TeamPCP threat group, saying the resulting breach exposed the data of at least 29 other Union entities.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-93.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/0_European_Union_flag.jpg)](https://www.bleepingcomputer.com/news/security/cert-eu-european-commission-hack-exposes-data-of-30-eu-entities/) ### macOS 26.4 Brings New Terminal Security Feature to Stop Malicious Commands URL: https://www.privacyguides.org/news/2026/04/02/macos-26-4-brings-new-terminal-security-feature-to-stop-malicious-commands/ Last updated: 2026-04-02T22:10:53.000Z macOS 26.4 is now out, and with it comes a new [feature](https://9to5mac.com/2026/03/25/macos-26-4-has-new-terminal-popup-warning-when-pasting-commands/) in the Terminal app to help prevent malicious commands pasted into the terminal from running. For those not familiar, the [Terminal](https://support.apple.com/en-euro/guide/terminal/welcome/mac) allows advanced users to navigate the filesystem and run commands on their Mac without a graphical interface, allowing for much more control. It’s essentially just another way to control your computer. Unfortunately, the extra power the Terminal provides often allows attackers similar freedom over your system. A common tactic for scammers is to coach victims to open the terminal and input malicious commands. Even experienced terminal users can fall victim to copy-and-pasting malicious [commands](https://www.bleepingcomputer.com/news/security/dont-copy-paste-commands-from-webpages-you-can-get-hacked/) from web pages. The command you see can be completely different than the one that ends up on your clipboard. This attack has been around for years but the most recent variation is [ClickFix](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/). ClickFix takes advantage of various phishing methods like emails and malicious ads that lead users to a page that tricks users into launching their Terminal or PowerShell that downloads an obfuscated malicious code to run. The sites can imitate CAPTCHA verification prompts with instructions to launch your terminal and paste and run the malicious command. The attack is particularly insidious because it exploits a common pattern online that users have been trained over years to do without thinking. Apple’s answer to these attacks is a new feature in Terminal that prevents pasted commands from running, stopping attacks like this in their tracks. If you’re a power user, you don’t have to worry about being prompted every time you paste a command in the Terminal. But users who may not even know what the Terminal is will benefit from this warning immensely I think. ![](https://www.privacyguides.org/content/images/2026/04/image.jpeg) Credit: [Mr. Macintosh](https://x.com/classicii%5Fmrmac/status/2036797948911141129?s=61) The warning also helpfully explains common coaching vectors that might alert people to the techniques scammers use to coach people into running the malicious commands, something we’ve seen with other attempts at combatting scammers inside operating systems like Google’s attempt in [Android](https://www.androidauthority.com/new-anti-scam-features-android-show-3556831/). Scamming relies heavily on social engineering, and any roadblocks put in the way of scammers coaching people will inevitably be bypassed. It’s always a cat-and-mouse game unfortunately, and the best defense will always be education. But features like this one make scamming people more difficult, so even if they can never be 100% effective, it’s worth it in the end. ### Grandma Wrongly Arrested Due to Facial Recognition Software Finally Released After Months in Jail URL: https://www.privacyguides.org/news/2026/04/01/grandma-wrongly-arrested-due-to-facial-recognition-software-finally-released-after-months-in-jail/ Last updated: 2026-04-01T19:35:41.000Z Angela Lipps, an innocent, 50-year-old grandma who was arrested after wrongfully being identified by facial recognition software, has finally been [released](https://www.yahoo.com/news/videos/police-release-tennessee-grandmother-ai-020820079.html). Police in Fargo, North Dakota were investigating a series of bank fraud cases in which a fake U.S. Army military I.D. card was used to withdraw thousands of dollars. Using facial recognition software, in this case [Clearview AI](https://www.cnn.com/2026/03/29/us/angela-lipps-ai-facial-recognition), they identified Lipps as the suspect and arrested her at gunpoint in her home on July 14, 2025. There was a slight problem though: she had never even been to North Dakota. “It was so scary. I can still see it in my head, over and over again” Lipps said of her arrest to [WDAY news](https://www.inforum.com/news/fargo/ai-error-jails-innocent-grandmother-for-months-in-fargo-case). "I've never been to North Dakota, I don't know anyone from North Dakota.” The Fargo police used facial recognition software that had falsely matched Lipps with the suspect. The detectives compared the surveillance footage with Lipps’ driver’s license photo and based on the resemblance, decided to pursue charges. Later, her court-appointed attorney looked at her banking records and purchases made at the time and discovered that she had been in Tennessee during the each incident of fraud. Her attorney, Jay Greenwood told WDAY News "Around the same time she's depositing Social Security checks ... she is buying cigarettes at a gas station, around the same time, she is buying a pizza, she is using a cash app to buy an Uber Eats." Often, facial recognition technology is criticized for its potential for tracking individuals around using unchanging characteristics. However, another problem has arisen: these technologies are highly flawed and produce false matches regularly, leading to false arrests. The police in this case failed to do basic investigatory work to check if the AI system was accurate. Instead of using the technology to narrow down the potential suspects, they assumed it was correct without question. Lipps spent five months wrongfully jailed, away from her family, her life disrupted and untold distress caused by simple laziness. Facial recognition software fundamentally can’t determine if two pictures show the same person; all it can really do is show how similar the facial structures are. It can be affected by things like lighting, angle, the resolution of the picture, and myriad other factors. This case is just the latest in a line of false arrests using facial recognition software. The 2020 Robert Williams case was a landmark in the use of facial recognition. Williams was arrested at his home for felony larceny, his daughter watching as her father was taken away. Facial recognition is about 100 times more likely to give a false positive for people of color. ### iOS 26.5 Beta Supports RCS End-to-End Encryption URL: https://www.privacyguides.org/news/2026/03/31/ios-26-5-beta-supports-rcs-end-to-end-encryption/ Last updated: 2026-03-31T02:04:14.000Z Cross-platform end-to-end encryption in RCS may finally be coming to iOS, as the new iOS 26.5 beta [released](https://9to5mac.com/2026/03/30/ios-26-5s-messages-app-has-rcs-end-to-end-encryption-in-beta/) by Apple has end-to-end encryption support. The default messaging experience on mobile has long been dominated by SMS, a standard from the [1990’s](https://simpletexting.com/blog/30-years-of-texting/) that doesn’t support encryption, typing indicators, or even reasonable image sizes. As such, most people tend to avoid texting on SMS if they can avoid it. Mobile carriers have been looking to upgrade SMS for a long time. RCS has been in the works since [2007](https://sinch.com/blog/history-of-rcs/), but adoption has been low (particularly with the default iOS Messages app lacking support until quite recently in iOS 18). Google messages already supported RCS since [2019](https://techcrunch.com/2019/11/14/google-brings-rcs-support-in-its-android-messages-app-to-the-u-s/), but Apple remained stubbornly resistant. Google Messages also supported their own in-house E2EE back in [2022](https://www.gstatic.com/messages/papers/messages%5Fe2ee.pdf) but it was only between Google Messages users. The GSMA, the organization responsible for the RCS standard, first announced they would support interoperable E2EE all the way back in [September 2024](https://www.gsma.com/newsroom/article/rcs-nowin-ios-a-new-chapter-for-mobile-messaging/). Then they released E2EE as part of [Universal Profile 3.0](https://www.gsma.com/newsroom/article/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging/), based on the Messaging Layer Security (MLS) protocol from the [IETF](https://www.rfc-editor.org/rfc/rfc9420.html), cementing encryption as part of the standard. Then, the ball was in Apple and Google's hands. Google began [migrating](https://security.googleblog.com/2023/07/an-important-step-towards-secure-and.html) their Signal protocol-based encryption over to the new MLS encryption. Apple [confirmed](https://9to5mac.com/2025/03/14/end-to-end-encrypted-rcs-messaging-on-iphone/) they would be working on adding support to the Messages app. Then, silence. In between then and now, several new [versions](https://www.gsma.com/newsroom/article/elevating-the-messaging-experience-with-rcs-universal-profile-3-1/) of the Universal Profile have been released by the GSMA, adding new features. They even released [Universal Profile 4.0](https://www.gsma.com/newsroom/article/from-rich-text-to-video-rcs-universal-profile-4-0-has-arrived/) recently, adding video calls and rich text formatting. The [previous](https://www.privacyguides.org/news/2026/02/19/apple-introduces-end-to-end-encrypted-rcs-messaging-in-the-ios-26-4-beta/) iOS 26.4 beta showed hints of the new RCS E2EE feature, but it did not ship in the stable version. Apple gave a [statement](https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26%5F4-release-notes) confirming as much in the developer notes: > RCS end-to-end encryption is now available for testing in this beta. This feature is not shipping in this release and will be available to customers in a future software update for iOS, iPadOS, macOS, and watchOS. End-to-end encryption is in beta and is not available for all devices or carriers. Conversations labeled as encrypted are encrypted end-to-end, so messages can’t be read while they’re sent between devices. In this beta, RCS encryption is available for testing between Apple devices and is not yet testable with other platforms. They didn't specify which future release, so it's possible iOS 26.5 won't be the one either. The new toggle emphasizes that the feature is still in fact in beta, with a description stating that it's not available for every device or carrier. ![](https://www.privacyguides.org/content/images/2026/03/image-2.png) Credit: [9to5Mac](https://9to5mac.com/2026/03/30/ios-26-5s-messages-app-has-rcs-end-to-end-encryption-in-beta/) Apple has had previous features such as Private Relay and currently Apple Intelligence that have had long periods where the feature was available in stable releases of iOS with a (Beta) marker, so we can expect a long period of the feature not being considered complete even when it ships. In order for the feature to work, your device, the person's device you are messaging, and presumably both of your carriers all need to support at least Universal Profile 3.0, so it might be a while yet before you can message all of your contacts with E2EE by default. ### Systemd Offers Optional Age Verification URL: https://www.privacyguides.org/news/2026/03/30/systemd-offers-optional-age-verification/ Last updated: 2026-03-30T17:51:15.000Z systemd, the init system and service manager used by most major Linux distributions, has added a new `birthDate` field to the user records in the database in response to new age verification laws around the world, [It's FOSS](https://itsfoss.com/news/systemd-age-verification/) reports. In recent weeks, a number of countries and US states have passed or proposed age verification laws that would require verification to be done at the operating system level rather than by apps, websites, or app stores. [The laws](https://www.tomshardware.com/software/operating-systems/california-introduces-age-verification-law) are riddled with contradictions and obvious tech illiteracy, such as defining "operating system" so broadly that it could include nearly anything with a microchip and offering loopholes big enough to send a US Navy carrier through. systemd is already highly-controversial, and many Linux distros that avoid it are flagrantly proud of this fact. Complying with these laws will probably not help their image. Regardless, systemd insists that this field is entirely optional and privacy-respecting, functioning entirely locally. The developer says that the feature is designed to create a standardized, privacy-respecting compliance method for other projects who do wish to take advantage of it. (This goes back to one of the aforementioned loopholes: many of the laws don't specify *how* age needs to be verified, so something as simple as an un-verified "date of birth" field containing any random date legally qualifies in many cases.) Despite these clarifications, there are many who feel that any form of compliance is surrender and that we need to push back on these laws in any form, no matter how toothless and ineffective they may be. Indeed, compliance may embolden lawmakers who may tighten up the laws in the future to be worse for privacy and harder to avoid. It's FOSS notes that there's already a [fork](https://itsfoss.com/news/systemd-fork-strips-out-age-verification/) of systemd with all mentions of the `birthDate` field removed, but it's already fallen several commits behind and probably shouldn't be used in production. Maybe it can at least spark further conversation. ### Walmart Promises Digital Price Labels In Every Store By End Of Year URL: https://www.privacyguides.org/news/2026/03/30/walmart-promises-digital-price-labels-in-every-store-by-end-of-year/ Last updated: 2026-03-30T17:35:43.000Z American retail behemoth Walmart is planning to roll out digital price tags to all stores by the end of the year to replace the old-school paper ones, according to [CNBC](https://www.cnbc.com/2026/03/21/walmart-digital-price-tags-will-be-in-every-us-store-by-end-of-2026.html). The move has sparked concerns about potential abuse for "dynamic pricing." Dynamic pricing is when companies raise or lower prices in real-time in response to temporary conditions. A common example is Uber's "surge pricing." Imagine attending a concert or sporting event. After the event, Uber prices will be significantly higher - especially near the arena - due to the sudden demand for rides. While proponents could argue that this is simple supply & demand, companies like Uber have been accused of using data to personalize prices even further. One accusation was that having a [low battery](https://www.vice.com/en/article/uber-surge-pricing-phone-battery/) could mean a higher price because Uber knows you probably can't wait for demand to die down lest your phone die. Walmart's foray into digital price tags has critics and privacy advocates worried that the company will also experiment with surge pricing in a similar fashion. While at this time it would be difficult for Walmart to individualize prices (due to the high volume of customers on an aisle at any given time), the company could at very least easily adjust prices based on a wide range of other local factors, from benign tactics like lowering a price to sell an item that may expire soon to more usurious scenarios like raising prices at certain times of day when people may have less options (such as the ready-to-eat meals during lunch time). Multiple people speaking on behalf of Walmart stated that the change is purely about efficiency and promised that the system will not be used for any untoward price adjustments. They note advantages like ensuring consistent pricing, the ability to quickly adjust prices for a sale, and the time saved for employees that could be used toward other things such as helping customers or restocking shelves. The article notes that Kroger is also experimenting with digital price tags, and that many states are considering laws to reign in dynamic pricing. ### US Bans Foreign Routers, systemd Age Verification, Meta & Google Lose Social Media Addiction Lawsuit, and more! URL: https://www.privacyguides.org/livestreams/2026/03/27/us-bans-foreign-routers-systemd-age-verification-meta-google-lose-social-media-addiction-lawsuit-and-more/ Last updated: 2026-04-07T18:37:45.000Z This Week in Privacy #46 _This post is for subscribers only._ ### Vizio TVs Will Now Require a Walmart Account URL: https://www.privacyguides.org/news/2026/03/27/vizio-tvs-will-now-require-a-walmart-account/ Last updated: 2026-03-27T17:08:53.000Z After being bought out by [Walmart](https://arstechnica.com/gadgets/2024/02/walmart-buying-tv-brand-vizio-for-its-ad-fueling-customer-data/) in 2024, “select new Vizio OS TVs“ will require a Walmart account to function properly, a representative [told](https://arstechnica.com/gadgets/2024/02/walmart-buying-tv-brand-vizio-for-its-ad-fueling-customer-data/) *Ars Technica*. Customers already needed a Vizio account to use the smart TV features since 2024, for subscription management, support, and special offers, according to their [website](https://www.vizio.com/en/overview-account). The brand relies on selling cheap TVs at a loss and making money from ads to make up for it in its business model. Accounts allow for easy tracking of customers since you have to authenticate to use it, and Vizio are not shy about it given they explicitly list “special offers” as a perk of their accounts. The fact that they want you to manage your purchases and subscriptions through their accounts as well makes it easy for them to track your media habits. Vizio accounts will need to transition to the new Walmart accounts. The representative promised the Walmart account integration is “designed to respect consumer choice and privacy, with data used in aggregated, permissioned, and compliant ways” but didn’t provide any specifics. While Vizio’s business model was predatory and data-hungry, it was limited to media consumption for the most part which many customers may be ok with. Walmart‘s position as a general-purpose supermarket puts it in a better position to collect data about your purchases and general consumption habits, which, combined with your media consumption habits, is an absolute goldmine of personal data to harvest for advertising purposes. Walmart has an ad business that totaled [$6.4 billion](https://www.adexchanger.com/commerce/walmarts-ad-revenue-totaled-6-4-billion-in-2025-as-the-ecom-flywheel-started-to-spin/) in 2025, dwarfing Vizio’s measly [$115.8 million](https://s29.q4cdn.com/107810760/files/doc%5Ffinancials/2024/q3/Exhibit-99-1-Q3-2024-10-31-24.pdf) (compared to it’s hardware business which lost $6.7 million). Walmart CFO John David Rainey said in an earnings call: > We saw triple-digit growth in advertising with our VIZIO business in the quarter. We've talked a lot about this. This is exciting because it gives us yet another channel to market to our customers. Walmart is clearly pushing ad revenue hard with Vizio. In an [announcement](https://corporate.walmart.com/news/2026/03/23/walmart-and-vizio-scale-content-to-commerce-at-newfronts), they brag about their “uniting high-impact storytelling, retail behavior, and closed-loop measurement within a single ecosystem.” Closely following that is an announcement of a partnership with L’Oréal for integrating into “premium content.” The message is clear: Vizio TVs are not products in the traditional sense, they’re vehicles for advertisers to funnel targeted ads at you. For years now, smart TVs have been getting more and more [privacy-invasive](https://www.consumerreports.org/electronics/privacy/how-to-turn-off-smart-tv-snooping-features-a4840102036/). The most recent controversy involves Automatic Content Recognition (ACR). According to MSN: > ACR runs in the background, taking images and screenshots of the data displayed on your TV, then compares them to a large database to identify what you're watching. There has been some [legal](https://texaspolitics.com/2025/12/18/ken-paxtons-temporary-restraining-order-blocks-hisense-from-collecting-texans-tv-data/) pushback against these practices, but without a wider pushback from politicians, the practice likely won’t stop anytime soon. ### Data Breach Roundup (Mar 20 - 26, 2026) URL: https://www.privacyguides.org/news/2026/03/27/data-breach-roundup-mar-20-26-2026/ Last updated: 2026-03-27T16:31:23.000Z ## Crunchyroll probes breach after hacker claims to steal 6.8M users' data Anime streaming service Crunchyroll was contacted by an attacker claiming to have breached the Okta SSO account of a support agent, planted malware, and stolen over 8 million support tickets. The data includes email addresses, user's name, login name, IP address, "general geographic information," and contents of support tickets. [Crunchyroll probes breach after hacker claims to steal 6.8M users’ dataPopular anime streaming platform Crunchyroll is investigating a breach after hackers claimed to have stolen personal information for approximately 6.8 million people.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-82.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/crunchyroll-2.jpg)](https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/) ## Mazda discloses security breach exposing employee and partner data Major automobile manufacturer Mazda is reporting a breach that impacted a system related to warehouse management for parts from Thailand. They say the breach only impacted 692 records and none were customers. Impacted data includes user IDs, full names, email addresses, company names, and business partner IDs. [Mazda discloses security breach exposing employee and partner dataMazda Motor Corporation (Mazda) announced that information belonging to its employees and business partners had been exposed in a security incident detected last December.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-83.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/mazda.jpg)](https://www.bleepingcomputer.com/news/security/mazda-discloses-security-breach-exposing-employee-and-partner-data/) ## Dutch Ministry of Finance discloses breach affecting employees There are virtually no details at this time, especially regarding how many people were impacted or what data was stolen. The incident occurred on March 19th and did not impact the systems used for tax collection, regulations, or subsidies. No cybercrime groups have taken credit yet. [Dutch Ministry of Finance discloses breach affecting employeesThe Dutch Ministry of Finance confirmed on Monday that some of its systems were breached in a cyberattack detected last week.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-84.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Netherlands_Dutch_Ministry_of_Finance.jpg)](https://www.bleepingcomputer.com/news/security/dutch-ministry-of-finance-discloses-breach-affecting-employees/) ## Infinite Campus warns of breach after ShinyHunters claims data theft Infinite Campus is a "K-12 student information system" that manages the data of roughly 11 million students. They were breached after an attacker gained access to an employee's Salesforce account. IC claims most of the data was already public, such as names and contact information for school staff. [Infinite Campus warns of breach after ShinyHunters claims data theftInfinite Campus, a widely used K-12 student information system, is warning customers of a data breach following an extortion attempt by a threat actor.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-85.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/School_hacker.jpg)](https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/) ## HackerOne discloses employee data breach after Navia hack HackerOne is a well-known platform where cybersecurity researchers can report bugs to companies in exchange for payment. Navia is a benefits administrator. HackerOne is blaming a "Broken Object Level Authorization (BOLA)" at Navia allowing for data access between December 2025 and January 2026\. Data impacted includes Social Security numbers, full names, addresses, phone numbers, dates of birth, email addresses, plan enrollment dates, effective dates, and termination dates for each affected employee and their dependents. [HackerOne discloses employee data breach after Navia hackBug bounty platform HackerOne is notifying hundreds of employees that their data was stolen after attackers hacked Navia, one of its U.S. benefits administrators.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-86.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/HackerOne.jpg)](https://www.bleepingcomputer.com/news/security/hackerone-discloses-employee-data-breach-after-navia-hack/) ## Ajax football club hack exposed fan data, enabled ticket hijack Ajax is a professional football ("soccer" to Americans) club from Amsterdam. A recent security incident exposed email addresses of "a few hundred" people, as well as names, email addresses, and dates of birth of about 20 people who were banned from the stadium. [Ajax football club hack exposed fan data, enabled ticket hijackDutch professional football club Ajax Amsterdam (AFC Ajax) disclosed that a hacker exploited vulnerabilities in its IT systems and accessed data belonging to a few hundred people.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-87.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Ajax.jpg)](https://www.bleepingcomputer.com/news/security/ajax-football-club-hack-exposed-fan-data-enabled-ticket-hijack/) ## Internet Yiff Machine: We hacked 93GB of “anonymous” crime tips A group calling themselves "Internet Yiff Machine" claims to have stolen data from P3 Global Intel, which is a company that manages anonymous crime tips for police. The data contains names, email addresses, dates of birth, phone numbers, home addresses, license plate numbers, Social Security numbers, and criminal histories as well as replies from investigators. [Internet Yiff Machine: We hacked 93GB of “anonymous” crime tipsUltra-sensitive data may have been hacked.![](https://www.privacyguides.org/content/images/icon/cropped-ars-logo-512_480-300x300-23.png)Ars TechnicaNate Anderson![](https://www.privacyguides.org/content/images/thumbnail/p3-app-1152x648-1774557739.jpg)](https://arstechnica.com/security/2026/03/internet-yiff-machine-we-hacked-93gb-of-anonymous-crime-tips/) ### Android 17 is Getting a Post Quantum Cryptography Upgrade URL: https://www.privacyguides.org/news/2026/03/26/android-17-is-getting-a-post-quantum-cryptography-upgrade/ Last updated: 2026-03-26T16:26:05.000Z Following their [shortening](https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/) of the deadline to implement post-quantum encryption to 2029, Google today [announced](https://security.googleblog.com/2026/03/post-quantum-cryptography-in-android.html) the “first phase” of its post-quantum transition. Google is upgrading Android with a quantum-resistant chain of trust, starting from Android Verified Boot all the way up to app signing. ![](https://www.privacyguides.org/content/images/2026/03/image.jpeg) Credit: [Google](https://security.googleblog.com/2026/03/post-quantum-cryptography-in-android.html) The [chains of trust](https://source.android.com/docs/security/features/verifiedboot#background) is what allows your operating system to verify you’re running trusted software. You start with a hardware root of trust laid down in the factory which can’t be changed. Then the hardware root of trust verifies the next component, which verifies the next component and so on. Android 17 will support the recently finalized NIST standard [Module-Lattice-Based Digital Signature Algorithm (ML-DSA)](https://csrc.nist.gov/pubs/fips/204/final). This algorithm allows for quantum-safe signatures. Android Verified Boot is essential for security on your system: after all, if you can’t verify you’re running trusted software, then an attacker could run anything they want. They’re also migrating remote attestation to PQC. > By updating KeyMint's certificate chains to support quantum-resistant algorithms, devices can securely prove their state to relying parties, maintaining trust in a post-quantum environment. They're bringing the new cryptography to app signing, too: developers can now utilize the new PQC in the Android Keystore, keeping key material securely isolated from the main operating system. The new ML-DSA-65 and ML-DSA-87 cryptography will be available using the standard [KeyPairGenerator](https://developer.android.com/reference/java/security/KeyPairGenerator) API, meaning developers won't need to roll their own crypto. > Implementing lattice-based cryptography, which requires significantly larger key sizes and memory footprints than classical elliptic curve cryptography, within the severely resource-constrained Trusted Execution Environment (TEE), represents a major engineering achievement. This capability is designed to support the hardware roots of trust and can now generate and verify post-quantum signatures. Cryptographers have long warned that quantum computers could eventually pose a risk to classical cryptography. Quantum computers are always getting better, and recent [advances](https://www.privacyguides.org/news/2026/03/06/new-jvg-quantum-decryption-algorithm-could-pose-risk-to-classical-encryption/) in quantum decryption algorithms have made the prospect seem closer than ever. While Google now puts that day at just three years away in 2029, the NSA puts the deadline for transitioning to PQC at 2033. Quantum computers don't just threaten data in the future though: threat actors are collecting encrypted data today in the hopes that it will be possible to decrypt at a later date, a "[harvest now, decrypt later](https://postquantum.com/post-quantum/harvest-now-decrypt-later-hndl/)" attack. Messengers like [Signal](https://signal.org/blog/spqr/) and [iMessage](https://security.apple.com/blog/imessage-pq3/) have implemented PQC already in preparation for the coming threat. Apple has been adding PQC to their operating system and making it available to developers to use via APIs, and Google have been adding PQC to [Chrome](https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html) and offering it via their [cloud](https://cloud.google.com/security/resources/post-quantum-cryptography?e=48754805) services. ### French Aircraft Carrier Located in Real Time Via Fitness App URL: https://www.privacyguides.org/news/2026/03/24/french-aircraft-carrier-located-in-real-time-via-fitness-app/ Last updated: 2026-03-24T18:51:27.000Z French newspaper *Le Monde* was able to [locate](https://www.lemonde.fr/en/international/article/2026/03/20/stravaleaks-france-s-aircraft-carrier-located-in-real-time-by-le-monde-through-fitness-app%5F6751640%5F4.html) a French aircraft carrier in real time using publicly available profile information of a French Navy officer on the fitness app Strava. While logging his daily run onboard the aircraft carrier Charles de Gaulle, the officer inadvertently posted the current location of the ship he was on publicly and in real time to his Strava account. This level of operational negligence seems almost comical coming from a military, especially during the current conflict. ![](https://www.privacyguides.org/content/images/2026/03/image-1.png) Credit: [Le Monde](https://www.lemonde.fr/en/international/article/2026/03/20/stravaleaks-france-s-aircraft-carrier-located-in-real-time-by-le-monde-through-fitness-app%5F6751640%5F4.html) This is just the latest in a series of events where public Strava data was used to locate military bases, ships, etc. *Le Monde* contacted the French Armed Forces General Staff, who said the behavior “does not comply with current guidelines," which "sailors are regularly made aware of." They went on to say that "appropriate measures will be taken by the command." *Le Monde* says they were able to identify other sailors via their public Strava data as well. The paper has successfully done this [multiple](https://www.lemonde.fr/en/stravaleaks/) times over the years, and yet it keeps happening. In one incident in January 2025, they were able to detect the patrol schedules of French nuclear submarines. In a three part series, they revealed how leaders [Emmanuel Macron](https://www.lemonde.fr/en/france/article/2024/10/27/how-emmanuel-macron-can-be-tracked-watch-the-first-episode-of-stravaleaks%5F6730708%5F7.html), [Joe Biden](https://www.lemonde.fr/en/united-states/article/2024/10/28/biden-and-trump-put-in-danger-by-secret-service-agents-watch-the-second-episode-of-stravaleaks%5F6730825%5F133.html), [Donald Trump](https://www.lemonde.fr/en/united-states/article/2024/10/28/biden-and-trump-put-in-danger-by-secret-service-agents-watch-the-second-episode-of-stravaleaks%5F6730825%5F133.html), and [Vladimir Putin](https://www.lemonde.fr/en/international/article/2024/10/29/putin-s-bodyguards-go-on-runs-near-palace-he-denies-owning-stravaleaks-episode-3%5F6730915%5F4.html) can be tracked via their security guard’s Strava workout data. Just to reiterate: this is all public data, Strava was not compromised at all. Many workout apps offer the ability to sync your workout data to a server, and even compare with friends. However, Strava seems to encourage making your workout data public. In their Strava Labs page, they brag about the “trillions of GPS data points” in their public dataset. Some projects they showcase include [Flyby](https://labs.strava.com/flyby/), a feature that lets you see the exact positions of people who you passed by during your activities, and [Roster](https://labs.strava.com/roster/), a sort of social networking feature that lets you visualize your group activities. It is important to note that Strava provides privacy controls for profiles, so anyone in a sensitive situation, like, say, inside a nuclear submarine base, should take precautions to not reveal sensitive data. Generally, though, it’s best to use fitness [apps](https://www.privacyguides.org/en/health-and-wellness/) that support end-to-end encryption and don’t publicly reveal your workout data. ### GrapheneOS Won’t Implement Age Verification URL: https://www.privacyguides.org/news/2026/03/23/grapheneos-wont-implement-age-verification/ Last updated: 2026-03-23T19:00:04.000Z The security and privacy-focused GrapheneOS stated in an X post that they will “remain usable by anyone around the world without requiring personal information, identification or an account.” > GrapheneOS will remain usable by anyone around the world without requiring personal information, identification or an account. GrapheneOS and our services will remain available internationally. If GrapheneOS devices can't be sold in a region due to their regulations, so be it. > > — GrapheneOS (@GrapheneOS) [March 20, 2026](https://twitter.com/GrapheneOS/status/2034957604682621229?ref%5Fsrc=twsrc%5Etfw) With the passing of California’s [Digital Age Assurance Act](https://www.tomshardware.com/software/operating-systems/california-introduces-age-verification-law), set to take effect on January 1, 2027, all operating systems in California to collect age information from users and provide a real-time API that developers can access to see the age range of their users. California joins [Texas](https://www.mofo.com/resources/insights/251111-texas-targets-app-stores-with-new-accountability-law) and [Utah](https://utahnewsdispatch.com/2026/02/05/tech-companies-lawsuit-utah-age-verification-law-for-app-stores/), both of which had lawsuits over potentially violating the first amendment. Supposedly, the California law avoids such issues by “focusing strictly on age assurance, not content moderation,” according to Buffy Wicks, author of the bill. Concerns abound over how operating systems like most Linux distros which don’t typically have any online account system that could be used to keep track of a user’s age. Some distros like Canonical’s [Ubuntu](https://discourse.ubuntu.com/t/ubuntus-response-to-californias-digital-age-assurance-act-ab-1043/77948?ref=itsfoss.com) are “reviewing it internally with legal counsel” but they have “no concrete plans on how, or even whether, Ubuntu will change in response.” Fedora are exploring possible implementations that wouldn’t require any telemetry and just uses a local API. [Ageless Linux](https://agelesslinux.org/distros.html) is a distro that’s “flagrantly noncompliant” with age verification laws. Their homepage lists how different distros have responded to the laws. Apple has provided the [Declared Range API](https://developer.apple.com/news/?id=f5zj08ey) to comply with laws in several countries and states for iOS and macOS and provided an [FAQ](https://developer.apple.com/support/age-assurance) to help developers navigate the complicated legal landscape that’s resulted from all of these disparate laws. Android’s [Play Age Signals](https://developer.android.com/google/play/age-signals/overview) API serves the same purpose. Both are currently in beta. With varying and contradictory laws across so many different regions, not only do these laws pose a privacy concern, they’re also going to be difficult to enforce and cause chaos as developers and operating systems scramble to find ways to comply. It’s unclear what the future holds for age verification, wherever the laws pass, there seems to be a trail of destruction in its wake. GrapheneOS takes a bold stance against age verification that I wish more operating systems would take. Age verification laws have been used by [governments](https://prestonbyrne.com/2026/01/27/spectator-feature-will-congress-shield-the-us-from-foreign-attacks-on-the-first-amendment/) to attack websites that aren’t even hosted in their country, so it’s not far fetched to say that even if these laws aren’t in your region, they will still affect you. ### Severe Meta Cybersecurity Incident Caused by AI Agent URL: https://www.privacyguides.org/news/2026/03/22/severe-meta-cybersecurity-incident-caused-by-ai-agent/ Last updated: 2026-03-22T23:00:12.000Z *The Information* [reports](https://www.theinformation.com/articles/inside-meta-rogue-ai-agent-triggers-security-alert) that a cybersecurity incident classified as the second-highest severity level Sev 1 occurred due to an AI agent similar to OpenClaw. The incident happened after a Meta employee used an in-house AI agent similar to OpenClaw to analyze a technical question from another employee in an internal discussion forum. The agent then posted a response to the original questions without confirmation from the employee. The employee who posted the question then acted on the advice from the agent. For almost two hours, internal data about employees and users was accessible to engineers who weren’t supposed to have access to it. Reportedly, there was no evidence that anyone took advantage of this access. Meta classified the incident as Sev 1, the second-highest level of severity on an internal scale used to classify security incidents. The employee told *The Information* that other security issues also contributed to the severity of the incident. This isn‘t the first time AI agents have caused issues at Meta. Sumnew Yue, Meta’s director of Safety and Alignment, asked OpenClaw to look over her emails and recommend what to delete and what to archive. She explicitly asked it to confirm before acting, however the agent began deleting emails without permission. > Nothing humbles you like telling your OpenClaw “confirm before acting” and watching it speedrun deleting your inbox. I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb. [pic.twitter.com/XAxyRwPJ5R](https://t.co/XAxyRwPJ5R) > > — Summer Yue (@summeryue0) [February 23, 2026](https://twitter.com/summeryue0/status/2025774069124399363?ref%5Fsrc=twsrc%5Etfw) Even after telling it to stop multiple times, the agent kept on deleting emails. With the rise of AI agent software these types of incidents are becoming more and more common as people rely on them more and more for seemingly innocuous tasks. Many of these agents lack proper safeguards and sandboxing that other types of software have had decades to build up. It’s not an easy problem either: securing AI agents will requires whole new paradigms in security. Not only do they need to be secured against acting without permission like in these incidents, they also need to be secured against attackers. Since AI can’t tell the difference between input and instructions, opening them up to [prompt injection](https://owasp.org/www-community/attacks/PromptInjection) attacks, where an attacker replaces the instructions given to the agent with their own, bypassing safeguards and restrictions. Trail of Bits previously wrote in a [blog](https://blog.trailofbits.com/2026/01/13/lack-of-isolation-in-agentic-browsers-resurfaces-old-vulnerabilities/) post about the weaknesses of agentic browsers. They compare the current shortcomings to those of early cross-site scripting attacks in early web browsers. They give some detailed instructions on how the security of agents can be improved. Google has their own [research](https://research.google/pubs/an-introduction-to-googles-approach-for-secure-ai-agents/) on securing AI agents, and Microsoft describes how they try to [secure](https://blogs.windows.com/windowsexperience/2025/10/16/securing-ai-agents-on-windows/) agents in Windows. We’re still in the early stages of AI agents, where the developers of the software are still trying to figure out the best ways to secure agents so they do what we want and only have access to exactly what they need at any given time. If you’re someone jumping on the AI agent bandwagon, it might be worth it to wait for the security research to catch up with this technology. ### Big Tech Creates “Accord Against Online Scams & Fraud” URL: https://www.privacyguides.org/news/2026/03/22/big-tech-creates-accord-against-online-scams-fraud/ Last updated: 2026-03-22T05:00:16.000Z Eleven companies have signed an [accord](https://services.google.com/fh/files/newsletters/industryaccord.pdf) to address the growing issue of “online scams and fraud,” with the notable exclusion of Apple. We’ve all likely seen the fake job offers, the fake delivery notifications for packages we didn’t order, and any number of other scams designed to steal as much money from you as possible. An estimated $442 billion was [lost](https://www.gasa.org/post/global-scams-on-the-rise-over-half-of-adults-worldwide-report-scam-encounters) to scammers last year. Many of those who lost money were regular people who can’t afford to part with their hard-earned cash. Scams have always been a thorn in the side of society, but with recent [advances](https://www.privacyguides.org/news/2026/03/10/ai-agents-beginning-to-help-attackers-accelerate-stealing-your-data/) in AI, it’s becoming easier and easier for scammers to extract money from their victims. More convincing fake texts, emails, and phone calls are now possible thanks to the generative AI revolution. Attempts by tech companies to [thwart](https://applemagazine.com/ios-26-junk-call-blocking-feature/) [these](https://support.google.com/phoneapp/answer/15654065?hl=en) scams are welcome to see, but they’re not 100% effective as they rely on AI detection. The document states that in order to fight scams, it will require cooperation from not just companies, but also between the public and private sector. The accord is a bit light on the technical details of how this will be achieved, likely they don’t know for sure just yet, only making mention of “robust security features, AI-powered detection systems, and clear usage policies.” The signatories of the accord consist of Adobe, Pinterest, Google, OpenAI, LinkedIn, Match Group, Meta, Amazon, Microsoft, Target, and Levi Strauss & Co. These companies Run the gamut from tech to retail to employment, and it makes sense: these are industries commonly involved in scams. Fake job offers are becoming increasingly common, and of course the initial contact method is a text or phone call. Retailers sell gift cards, a common method of transferring money to scammers. The accord calls on its members to buff up their anti-scam technology. Google has been leading the way on Android with several features designed to prevent scams. Their AI scam detection uses on-device Gemini to [warn](https://security.googleblog.com/2026/02/strengthening-android-lead-in-scam-protection.html) you of potential scams, and they even [disable](https://www.androidauthority.com/android-16-phone-call-protections-3526068/) sideloading and block new accessibility permissions when on a phone call. Technical protections such as these are only a first step though. The accord also emphasizes the need for collaboration and sharing of best practices, and mechanisms to prevent scams when a new one proves effective. They also call out providing a process for scams to be reported to law enforcement as an important measure, albeit without sacrificing user privacy. Information sharing between governments and across different industries is on the docket as well, alongside fixing conflicting laws in different regions to eliminate hindrances to swift and effective scam countermeasures. Scammers are a scourge on society and the more companies and governments can collaborate on this issue, the better off we all are in my book. ### FBI Seeks Info from Gamers Who Installed Malware from Steam URL: https://www.privacyguides.org/news/2026/03/21/fbi-seeks-info-from-gamers-who-installed-malware-from-steam/ Last updated: 2026-03-21T18:00:58.000Z Steam was used to spread [malware](https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/) via several games, and the FBI Seattle division has [announced](https://forms.fbi.gov/victims/Steam%5FMalware) that they’re seeking information from those affected. The malware-ridden games in question include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova. If you installed any of these games, you can fill out the form on their site to potentially access “certain services, restitution, and rights under federal and/or state law.” Responses are purely voluntary but may help in their investigation. The FBI states that it believes the “threat actor primarily targeted users between the timeframe of May 2024 and January 2026.” [PirateFi](https://www.pcmag.com/news/did-you-download-this-steam-game-sorry-its-windows-malware) was designed to steal browser cookies to take over your accounts. Chemia was a legitimate game, but was [hijacked](https://x.com/PRODAFT/status/1948033354609164493) and updated with infostealer malware. BlockBlasters was a [Trojan](https://www.pcmag.com/news/another-steam-game-infects-players-pcs-with-malware-steals-150k-in-crypto) that stole an estimated $150,000 in cryptocurrency. [Lunara](https://steamcommunity.com/discussions/forum/1/601892477917462878/) and [Tokenova](https://www.reddit.com/r/Steam/comments/1is270h/did%5Fi%5Fjust%5Finstall%5Fa%5Fvirus%5Fvia%5Fsteam/) were also exposed as crypto stealing malware. Games have long been a particularly potent vector for malware. They’re typically unsandboxed, closed source, and commonly ask for the lowest-level permissions in your operating system to run things like anti-cheat software or DRM software. They’re also commonly bundled with other programs. Gamers are so used to having random crap installed along with their games that no one would really bat an eye at some malware bundled alongside a legitimate game. Gamers also commonly install cracked versions of games downloaded from unofficial sources, which often contain [malware](https://me-en.kaspersky.com/blog/malware-in-pirated-games-2021/18700/). Multiplayer components of games also expose you to hackers that could [exploit](https://neodyme.io/en/blog/csgo%5Ffrom%5Fzero%5Fto%5F0day/#tldr) your game client. Mods downloaded to customize games are also common [vectors](https://research.checkpoint.com/2025/minecraft-mod-malware-stargazers/) for malware. Storefronts like Steam are meant to provide some protection to their users by vetting software before it gets distributed on their platform, but malware continues to get more and more sophisticated and difficult to detect. If you need to [game privately](https://www.privacyguides.org/posts/2026/03/03/how-to-game-privately/) and securely, you can stick to platforms like the Apple App Store that enforce sandboxing on all games. Make sure to only get games from official sources and be very careful what mods you install, or just avoid mods entirely. You might even consider playing games on a totally separate machine to avoid the risk of your personal files and data getting compromised. It’s clear that trying to vet software for malware isn’t an effective strategy and operating systems need to enforce security features like sandboxing in order to protect their users. macOS has optional sandboxing that can be enabled by app developers when they sign their app. Windows is rolling out [win32 app isolation](https://learn.microsoft.com/en-us/windows/win32/secauthz/app-isolation-overview) that will allow a similar thing in Windows. iOS and Android are already sandboxed by default and provide great security out of the box, so they can be good options for secure gaming. ### Data Breach Roundup (Mar 13-19, 2026) URL: https://www.privacyguides.org/news/2026/03/20/data-breach-roundup-mar-13-19-2026/ Last updated: 2026-03-20T23:54:49.000Z ## UK’s Companies House confirms security flaw exposed business data Companies House is a British government agency that operates the registry for all U.K. companies. There was a flaw that allowed users to view the dashboards of other companies, which could reveal data including dates of birth, home addresses, and email addresses. This leak could've impacted as many as five million companies over five months, allowing attackers to change data or export records. [UK’s Companies House confirms security flaw exposed business dataCompanies House, a British government agency that operates the registry for all U.K. companies, says its WebFiling service is back online after it was closed on Friday to fix a security flaw that exposed companies’ information since October 2025.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-78.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Companies_House.jpg)](https://www.bleepingcomputer.com/news/security/uks-companies-house-confirms-security-flaw-exposed-business-data/) ## Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web Prolific security researcher Jeremy Fowler discovered three databases from Sears exposed to the public which contained 3.7 million chat logs and 1.4 million audio files (with transcripts) from Sears' Home Services customer service chatbot "Samantha." Some of the chats contained detailed personal information like names, phone numbers, home addresses, appliances owned, and information on delivery appointments and repairs. [Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the WebCustomer conversations with chatbots can include contact information and personal details that make it easier for scammers to launch phishing attacks and commit fraud.![](https://www.privacyguides.org/content/images/icon/favicon-24.ico)WIREDLily Hay Newman![](https://www.privacyguides.org/content/images/thumbnail/security_searsleak_Getty.jpg)](https://www.wired.com/story/sears-exposed-ai-chatbot-phone-calls-and-text-chats-to-anyone-on-the-web/) ## Marquis: Ransomware gang stole data of 672K people in cyberattack Marquis is a Texas-based financial services provider, providing digital marketing, data analytics, compliance, and CRM services to more than 700 banks, credit unions, and mortgage lenders across the United States. This incident occurred in August 2025 and impacted names, dates of birth, addresses, phone numbers, Social Security numbers, Taxpayer Identification Numbers, and financial account information. [Marquis: Ransomware gang stole data of 672K people in cyberattackMarquis, a Texas-based financial services provider, revealed this week that a ransomware gang stole the data of over 670,000 individuals in an August 2025 cyberattack that also disrupted operations at 74 banks across the United States.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-79.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Marquis.jpg)](https://www.bleepingcomputer.com/news/security/marquis-ransomware-gang-stole-data-of-672-000-people-in-2025-cyberattack/) ## Aura confirms data breach exposing 900,000 marketing contacts Aura is an "identity protection" company that sells products to consumers like identity theft protection, credit and fraud monitoring, and online security tools like phishing protection. Ironically, an employee fell for a voice phishing attack and exposed the of current and former customers. This included full names, email addresses, home addresses, and phone numbers. The company is claiming only about 35,000 customers were compromised and that the rest were a marketing email list they acquired in 2021. [Aura confirms data breach exposing 900,000 marketing contactsIdentity protection company Aura has confirmed that an unauthorized party gained access to nearly 900,000 customer records containing names and email addresses.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-80.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/hacker.jpg)](https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/) ## Navia discloses data breach impacting 2.7 million people Navia provides software and customer services for Flexible Spending Accounts (FSA), Health Savings Accounts (HSA), Health Reimbursement Arrangements (HRA), Commuter Benefits and COBRA Services. The breached data includes full name, date of birth, Social Security number, phone number, email address, participation in HRA, FSA information, and COBRA enrollment information. [Navia discloses data breach impacting 2.7 million peopleNavia Benefit Solutions, Inc. (Navia) is informing nearly 2.7 million individuals of a data breach that exposed their sensitive information to attackers.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-81.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/navia.jpg)](https://www.bleepingcomputer.com/news/security/navia-discloses-data-breach-impacting-27-million-people/) ### New iPhone Exploit Impacts Hundreds of Millions of Devices, FBI Resumes Buying Location Data, Google's New App Installation Process, and More! URL: https://www.privacyguides.org/livestreams/2026/03/20/new-iphone-exploit-impacts-hundreds-of-millions-of-devices-fbi-resumes-buying-location-data-googles-new-app-installation-process-and-more/ Last updated: 2026-04-03T18:33:35.000Z This Week In Privacy #45 _This post is for subscribers only._ ### KadNap Botnet Hijacks Asus Routers URL: https://www.privacyguides.org/news/2026/03/20/kadnap-botnet-hijacks-asus-routers/ Last updated: 2026-03-20T18:48:41.000Z The Black Lotus Team at Lumen has [discovered](https://blog.lumen.com/silence-of-the-hops-the-kadnap-botnet/) a new malware strain called KadNap that has been creating a botnet of Asus routers since at least August 2025. The network is now reportedly over 14,000 devices strong. The network uses clean residential IP addresses to proxy malicious traffic. The infected routers are sold as a residential proxy service called Doppelganger marketed specifically to cybercriminals, allowing them to hide their traffic. The network stands out for its use of peer-to-peer networking to communicate with the command-and-control (C2) servers. The custom [Kademlia Distributed Hash Table (DHT)](https://codethechange.stanford.edu/guides/guide%5Fkademlia.html) protocol they use to evade network monitoring. The decentralized nature of the DHT protocol makes it difficult for defenders to find and add command-and-control servers to threat lists for blocking. It hides the IP address of these servers and also allows malicious traffic to blend in with legitimate traffic. Black Lotus Labs explains it like this: > To better understand this system, think of Kademlia like using a chain of friends to find someone’s phone number: each friend does not know the whole number but knows someone who can get you closer to the answer. Passing your request along this chain, you quickly put together the whole phone number. Likewise, Kademlia nodes forward queries to others that are “closer” to the target, enabling fast and efficient searches without knowing the whole network. The malware mainly targets Asus routers but Lumen says other edge networking devices have been targeted as well, with separate C2 infrastructure separated by victim type. This isn’t the first time [Asus](https://www.privacyguides.org/news/2025/11/19/thousands-of-asus-routers-compromised-in-sprawling-global-espionage-campaign/) routers have been subject to attack and it certainly won’t be the last. As Internet of Things devices become more and more common, we will have more and more chances for our everyday devices to be compromised and enlisted into malicious botnets used by criminals. Lumen says they have blocked all traffic to the command and control servers and will begin sharing indicators of compromise into public feeds so everyone can fight back against this threat. For consumers, Lumen recommends following best practices for updating routers as outlined by the [Canadian Centre for Cybersecurity](https://www.cyber.gc.ca/en/guidance/routers-cyber-security-best-practices-itsap80019). They also recommend that you change the default password for the management interface and make sure it’s not accessible over the internet. Make sure you replace your connected devices once they reach their end of life and no longer receive updates as well. ### Data Breach Roundup (Mar 6 - Mar 12, 2026) URL: https://www.privacyguides.org/news/2026/03/20/data-breach-roundup-mar-6-mar-12-2026/ Last updated: 2026-03-20T18:44:08.000Z ## Cognizant TriZetto breach exposes health data of 3.4 million patients TriZetto makes software and IT services used by health insurers and healthcare providers. This breach was detected in October 2025 and the subsequent investigation revealed access dating back to November 2024\. Data exposed includes full name, physical address, date of birth, Social Security number, health insurance member number, Medicare beneficiary identifier, provider name, health insurer name, and demographic, health, & insurance information. [Cognizant TriZetto breach exposes health data of 3.4 million patientsTriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive information of over 3.4 million people.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-72.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/healthcare.jpg)](https://www.bleepingcomputer.com/news/security/cognizant-trizetto-breach-exposes-health-data-of-34-million-patients/) ## Ericsson US discloses data breach after service provider hack Ericsson is a Swedish "networking and telecommunications giant." Their US arm is reporting that the data of over 15,000 employees and customers had been exposed including names, addresses, Social Security numbers, driver's license numbers, government-issued ID numbers (passports, state IDs, etc), financial information (account numbers, cred/debit card numbers, etc), medical information, and dates of birth. [Ericsson US discloses data breach after service provider hackEricsson Inc., the U.S. subsidiary of Swedish networking and telecommunications giant Ericsson, says attackers have stolen data belonging to over 15,000 employees and customers after hacking one of its service providers.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-73.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Ericsson.jpg)](https://www.bleepingcomputer.com/news/security/ericsson-us-discloses-data-breach-after-service-provider-hack/) ## DOGE employee stole Social Security data and put it on a thumb drive, report says An unnamed DOGE software engineer - who left in October of last year - says that he took two USB sticks with him containing two databases ("Numident" and "Master Death File") with the intention of re-using the data at his new company. The Social Security Administration disputes this claim. [DOGE employee stole Social Security data and put it on a thumb drive, report says | TechCrunchA whistleblower is accusing a former DOGE member of stealing a large number of Americans’ personal data while he was working at the Social Security Administration, with the plan of using it at his new job.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-39.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/social-security-administration-logo.jpg)](https://techcrunch.com/2026/03/10/doge-employee-stole-social-security-data-and-put-it-on-a-thumb-drive-report-says/) ## Telus Digital confirms breach after hacker claims 1 petabyte data theft Telus Digital is a "business process outsourcing" company. Details on this breach are still very limited. The company has confirmed that a breach but has not responded to any questions. ShinyHunters is claiming the breach, but BleepingComputer has not been able to confirm any of the samples. ShinyHunters claims to have impacted 28 "well-known" companies impacted by the breach, and says data incldes things like customer support agent rankings and fraud detection tools, but also more sensitive data like FBI background checks, financial information, voice recordings of support calls, and call metadata. [Telus Digital confirms breach after hacker claims 1 petabyte data theftCanadian business process outsourcing giant Telus Digital has confirmed it suffered a security incident after threat actors claimed to have stolen nearly 1 petabyte of data from the company in a multi-month breach.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-74.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/telus-building.jpg)](https://www.bleepingcomputer.com/news/security/telus-digital-confirms-breach-after-hacker-claims-1-petabyte-data-theft/) ## England Hockey investigating ransomware data breach England Hockey is the governing board for field hockey in England. A threat actor is claiming to have stolen 129GB of data. No other details have been released yet, but typically in these cases the attacker turns out to be telling the truth so we'll likely have an update in a future newsletter. [England Hockey investigating ransomware data breachEngland Hockey, the governing body for field hockey in England, is investigating a potential data breach after the AiLock ransomware gang listed it as a victim on its data leak site.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-75.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/England_Hockey.jpg)](https://www.bleepingcomputer.com/news/security/england-hockey-investigating-ransomware-data-breach/) ## Canadian retail giant Loblaw notifies customers of data breach The breach contains "basic customer information" like names, phone numbers, and email addresses. The company said that out of caution they logged all customers out of their accounts and recommend (but are not forcing) password changes. [Canadian retail giant Loblaw notifies customers of data breachStill, out of an abundance of caution, Loblaw says it has automatically logged out all customers from their accounts. Account holders who need to access the company’s digital services will have to log in again.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-76.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/loblaws.jpg)](https://www.bleepingcomputer.com/news/security/canadian-retail-giant-loblaw-notifies-customers-of-data-breach/) ## Starbucks discloses data breach affecting hundreds of employees This occurred after attackers gained access to 889 Starbucks Partner Central accounts, which employees use for managing personal details, benefits, and HR information. The article did not explain how this compromise occurred, but said exposed information includes names, Social Security numbers, dates of birth, and financial account information such as routing numbers. [Starbucks discloses data breach affecting hundreds of employeesStarbucks has disclosed a data breach affecting hundreds of employees after threat actors gained access to their Starbucks Partner Central accounts.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-77.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Starbucks_hero.jpg)](https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/) ## Viral 'Quittr' Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of Users This is an update to a story from January. 404 wrote about an app that was leaking user data but declines to name the app because the security issues weren't resolved yet. The app had a misconfiguration that allowed anyone to query the user database. After initially denying the vulnerability and dodging reporters, the vulnerability has been fixed. [Viral ‘Quittr’ Porn Addiction App Exposed the Masturbation Habits of Hundreds of Thousands of UsersA couple of 20-year-old developers make $500,000 a month promising to help men to stop watching porn, but exposed their private porn watching habits.![](https://www.privacyguides.org/content/images/icon/favicon-3-14.svg)404 MediaEmanuel Maiberg![](https://www.privacyguides.org/content/images/thumbnail/alex.jpg)](https://www.404media.co/viral-quittr-porn-addiction-app-exposed-the-masturbation-habits-of-hundreds-of-thousands-of-users/) ### Pokémon Go Players’ Data Used to Train “Visual Positioning” AI URL: https://www.privacyguides.org/news/2026/03/20/pokemon-go-players-data-used-to-train-visual-positioning-ai/ Last updated: 2026-03-20T03:00:56.000Z Niantic spinoff, Niantic Spatial, [used](https://www.technologyreview.com/2026/03/10/1134099/how-pokemon-go-is-helping-robots-deliver-pizza-on-time/) over 30 billion images taken by users of Pokemon Go to train its “visual positioning” system to help robots navigate the world. Pokémon Go, released all the way back in 2016, is an insanely popular game that uses augmented reality to simulate catching Pokemon in the real world. While the game has received lots of praise for encouraging people to get outside and meet people, any app that requires location data and camera access is concerning. It turns out that Niantic was actually collecting all that juicy location and camera data in order to train a model to help robots navigate the world. The data collection was centered around “hot spots”: places that Niantic wanted you to go to collect detailed images in different weather conditions, times of day, etc. “We had a million-plus locations around the world where we can locate you precisely” Brian McClendon, CTO of Niantic Spatial, [told](https://www.technologyreview.com/2026/03/10/1134099/how-pokemon-go-is-helping-robots-deliver-pizza-on-time/) MIT Technology Review. “We know where you’re standing within several centimeters of accuracy and, most importantly, where you’re looking.” Not only is this much more precise than GPS-based location, it relies only on images in order to function. This means, just based on visual data, this model can locate you within centimeters. The article goes on: > Each of those images comes with detailed metadata that pinpoints where in space the phone was at the time it captured the image, including which way the phone was facing, which way up it was, whether or not it was moving, how fast and in which direction, and more. Niantic Spatial is now teaming up with Coco Robotics, a service that provides delivery robots that can “carry up to eight extra-large pizzas or four grocery bags” in a limited number of cities, currently just Los Angeles, Chicago, Jersey City, Miami, and Helsinki. The robots can’t rely on GPS alone since the signals that power GPS can bounce off buildings and interfere with each other, reducing accuracy. Questions of ethics seem inevitable in a case like this: players likely had no idea they were having their data harvested to train AI. Most people won’t read the privacy policy for a game, assuming that they don’t have to worry much and that the data collected will only be used to make the game function properly. This case serves as a stark example of why it’s important to be careful what permissions you grant apps you install. Location, camera, and microphone permissions should be doled out sparingly only in cases where it’s absolutely necessary. With *human* players of games such as [Geoguessr](https://www.geoguessr.com), able to find locations on the planet surprisingly quickly, it’s only a matter of time before models like Niantic’s will be used for less innocent purposes than delivery robots. Erasing metadata from images might no longer be enough to hide your location in the near future, if that’s not the case already. ### Intel’s Fully Homomorphic Encryption Chip Could Revolutionize Privacy URL: https://www.privacyguides.org/news/2026/03/19/intels-fully-homomorphic-encryption-chip-could-revolutionize-privacy/ Last updated: 2026-03-19T18:00:56.000Z Intel’s hardware-accelerated Fully-Homomorphic Encryption chip, [Heracles](https://spectrum.ieee.org/fhe-intel#fhe), could bring fully E2EE server-side processing into viability. Many of us send our data off to servers for processing everyday, whether it’s for directions in Google Maps or searching for a nearby restaurant. This data is processed by servers in the clear and all of these services have full visibility into everything we send them. Some promise they don’t store info on us, but that’s only a promise and not backed up by any technical guarantees. There have been attempts at reducing the trust needed, such as the rise of [TEEs](https://learn.microsoft.com/en-us/azure/confidential-computing/trusted-execution-environment) in servers. > A Trusted Execution Environment is a segregated area of memory and CPU that's protected from the rest of the CPU by using encryption. Any code outside that environment can't read or tamper with the data in the TEE. Authorized code can manipulate the data inside the TEE. These are meant to reduce the “trusted computing base” to be as small as possible so there’s not much of a chance of data leaking out where it’s not meant to go. However, the data is still decrypted and processed in the clear, and there have been [vulnerabilities](https://tee.fail) in the past that caused the data within the TEE to leak out to attackers with physical access to the hardware. To ensure that data can’t be leaked even with physical access, you need proper E2EE similar to how messengers like Signal work where the data is never decrypted by any server. Enter: [Fully Homomorphic Encryption](https://www.ibm.com/think/topics/homomorphic-encryption). FHE allows encrypted data to be processed server-side without ever decrypting it. Because of the type of encryption it uses, it's even quantum-resistant. The catch? It’s thousands of times slower than processing the data normally. This problem means that although FHE has existed for years and years, it hasn't been practical for most applications. Intel's [work](https://community.intel.com/t5/Blogs/Tech-Innovation/Data-Center/Intel-Labs-Continues-Focused-Research-and-Standards-Efforts-to/post/1488532) began 5 years ago with the DARPA program [Data Protection in Virtual Environments (DRIVE)](https://www.darpa.mil/research/programs/data-protection-in-virtual-environments) to research hardware that could accelerate FHE. The chips are optimized to perform computations in parallel, utilizing single instruction multiple data (SIMD) compute engines and high-bandwidth memory to quickly link the processors together. They compute synchronously, so the chips don't get stuck waiting for each other to finish. It all adds up to a huge speed increase over traditional CPUs. According to the IEEE Spectrum [article](https://spectrum.ieee.org/fhe-intel), "across seven key operations, Heracles was 1,074 to 5,547 times as fast." Of course, for FHE to take off there needs to be support at all levels. [Duality Technology](https://dualitytech.com/platform/technology-fully-homomorphic-encryption/) focuses more on the software side of FHE. [Optalsys](https://optalysys.com/photonics/) is a company looking to move away from the limits of traditional computers and utilize photonics, computing with light, to speed up FHE even more. Some incredible progress has been made in the world of FHE. It could be the case that in just a few short years, it'll be the norm to make fully E2EE queries to Google or ask ChatGPT for dinner ideas in a fully E2EE manner. ### Stop Using These "Private" Messengers URL: https://www.privacyguides.org/videos/2026/03/19/stop-using-these-private-messengers/ Last updated: 2026-03-19T15:00:37.000Z When you send a message you assume it's private, however depending on what tool you choose this might not be the case! In this video we dive into issues with popular encrypted messengers and offer recommendations on what to use instead. #### Sources 0:28 0:41 2:33 3:00 3:18 3:28 3:33 3:46 4:09 4:17 4:40 4:44 4:52 4:59 5:25 6:02 6:28 6:32 6:40 ### Bitwarden Announces Entry "Archiving" URL: https://www.privacyguides.org/posts/2026/03/19/bitwarden-announces-entry-archiving/ Last updated: 2026-03-19T12:00:16.000Z Popular password manager Bitwarden has [announced](https://bitwarden.com/blog/keep-your-vault-tidy-with-item-archiving/) a new "archiving" feature, available immediately to paid users. The archive feature will remove selected entries into a "folder" of sorts, all in one place (without subfolders) but hidden from the main view. Additionally, they will not show up in search results or autofill suggestions. (This will not affect any shared entries for the other person.) Interestingly, archived items will still show up in vault health reports, letting you know if a credential has been compromised. Bitwarden touts this as a way to get less-used credentials out of the way of everyday use, but this could also be valuable for those managing old accounts. On the one hand, there are old accounts that you may not use again but it would be unwise to completely delete, such as an old Gmail account you used for years before getting into privacy. Likewise, there are some services who refuse to delete your data or honor deletion requests. In those cases, we often suggest populating them with fake data and then changing the credentials to something secure and holding on to the logins in the hopes that someday down the road the service will start offering data deletion. This new offering could be useful in scenarios like these, and probably several others. ### UK Corporate Registry Exposes Personal Information of Employees URL: https://www.privacyguides.org/news/2026/03/19/uk-corporate-registry-exposes-personal-information-of-employees/ Last updated: 2026-03-19T03:00:27.000Z The UK’s Companies House [alerted](https://www.gov.uk/government/news/update-on-companies-house-webfiling-security-issue) the public of a security issue that allowed other users to access “dates of birth, residential addresses and company email addresses.” The issue was with their WebFiling service, an online service for filing company tax returns. As you can imagine, the data involved is highly sensitive. The Companies House assures that passwords, passport information, or filed documents were not compromised. The issue allowed other users to even edit other companies’ records. They say this wasn’t available to the general public and “only users with an authorised code and logged in to the service could have performed this action.” However, corporate espionage and meddling are very real and it’s possible competitors could have taken advantage of this. The WebFiling service was taken down on Friday the 13th (of course) and stayed down all weekend in response. > We believe that this issue could not have been used to extract data in large volumes or to access records systematically. Any access would have been limited to individual company records, viewed one at a time by a registered WebFiling user. Dan Neidle, the founder of Tax Policy Associates, posted a [video](https://x.com/DanNeidle/status/2032506756786511908) demonstrating how the flaw could be abused. The flaw is now fixed as of Monday. They said they reported the incident to the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC) and are “actively analysing our data to identify any anomalies, and we’ll be emailing every company’s registered email address to explain how to check their details and what steps to take if they have any concerns.” They haven’t found any evidence yet of anyone exploiting the flaw to change company details. The Companies House asks that all companies check their registered details and filing history to make sure everything is correct, and to direct all concerns to [enquiries@companieshouse.gov.uk](mailto:enquiries@companieshouse.gov.uk). They report no confirmed instances of data being changed without permission, but the investigation is ongoing. A page will be published with more information at a later date. ### Instagram Ending E2EE Support URL: https://www.privacyguides.org/news/2026/03/18/instagram-ending-e2ee-support/ Last updated: 2026-03-18T18:46:59.000Z Instagram has notified its users that it will no longer support E2EE after May 8, 2026, according to the [support](https://help.instagram.com/491565145294150) page for the feature. The sudden reversal completely reverts a feature that’s been supported for years. Although it‘s taken quite a while to roll out, Meta has been slowly making its messengers E2EE by default. Messenger first introduced E2EE chats all the way back in [2016](https://about.fb.com/news/2016/07/messenger-starts-testing-end-to-end-encryption-with-secret-conversations/), although it was optional and not on by default, calling it “Secret Conversations.” They then began rolling out E2EE by default in Messenger in [2023](https://engineering.fb.com/2023/12/06/security/building-end-to-end-security-for-messenger/), among other security upgrades. Famously, Facebook [bought](https://about.fb.com/news/2014/02/facebook-to-acquire-whatsapp/) WhatsApp back in 2014\. They didn’t remove the E2EE; in fact, they [worked](https://signal.org/blog/whatsapp/) with Signal to bring the Signal Protocol to WhatsApp, with the work completing in [2016](https://signal.org/blog/whatsapp-complete/). Despite their reputation, Meta seemed to be on the right track with supporting E2EE in its messengers. They published [multiple](https://engineering.fb.com/wp-content/uploads/2023/12/MessengerEnd-to-EndEncryptionOverview%5F12-6-2023.pdf) [whitepapers](https://engineering.fb.com/wp-content/uploads/2023/12/TheLabyrinthEncryptedMessageStorageProtocol%5F12-6-2023.pdf) on their E2EE protocols and bragged about the verifiability of their code via their [Code Verify](https://engineering.fb.com/2022/03/10/security/code-verify/) browser extension. They even helped design the [Messaging Layer Security (MLS)](https://datatracker.ietf.org/doc/rfc9420/) IETF protocol. This move marks a sudden shift in their strategy with messaging. Instagram has made not public statement as to why they’re removing E2EE. It’s not clear whether Meta plans to remove E2EE in its other products in the future as well. Meta already offers simple ways to [report](https://faq.whatsapp.com/414631957536067/?cms%5Fplatform=web) [messages](https://www.facebook.com/help/instagram/568100683269916/) on its platforms including [Instagram](https://help.instagram.com/753893408640265/?helpref=uf%5Fpermalink&parent%5Fcms%5Fid=3490194014566528), so the excuse that it’s needed to protect users doesn’t work. They also offer easy [backup](https://help.instagram.com/766857281395358/?helpref=uf%5Fpermalink&parent%5Fcms%5Fid=3490194014566528) solutions for their platforms as well, so convenience isn‘t an issue either. Whatever the reason, Meta is reversing a years-long trend of positive progress and I hope they revert it. There’s no excuse for a messenger not to be E2EE by default anymore, we have secure encryption, backup solutions, device sync, group chats. Encrypted messaging is just as convenient as unencrypted messaging these days. A sudden reversal of a feature like this also erodes confidence that features you rely on will still be available in the future. At least for now, there’s no indication that Meta intends to reverse E2EE in WhatsApp or Messenger, but we’ll need to keep a close watch. ### Chat Control 1.0 Defeated, Google-free Pay on Android, DuckDuckGo's Independent Index, and more! URL: https://www.privacyguides.org/livestreams/2026/03/13/chat-control-1-0-defeated-google-free-pay-on-android-duckduckgos-independent-index/ Last updated: 2026-04-03T18:32:11.000Z This Week in Privacy #44 _This post is for subscribers only._ ### AI Agents Beginning to Help Attackers Accelerate Stealing Your Data URL: https://www.privacyguides.org/news/2026/03/10/ai-agents-beginning-to-help-attackers-accelerate-stealing-your-data/ Last updated: 2026-03-10T17:54:22.000Z While generation of malicious code, media, and phishing material are already making heavy use of AI, threat actors are “experimenting” with AI agents to automate decision making. A [blog post](https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/#microsoft-defender-detections) from Microsoft Threat Intelligence shows that AI is predominantly used to “draft phishing lures, translate content, summarize stolen data, generate or debug malware, and scaffold scripts or infrastructure.” Previously, it hasn’t really been seen in the decision-making process, however. For example, [fraudulent](https://www.microsoft.com/en-us/security/blog/2025/06/30/jasper-sleet-north-korean-remote-it-workers-evolving-tactics-to-infiltrate-organizations/) North Korean IT workers are being deployed at a mass scale using AI to create fake identities in combination with stolen documents. They’re hired by companies thinking they’re legitimate candidates, and then they steal data by infiltrating the company and generate revenue for the DPRK. AI accelerates and improves every aspect of this scam. Jasper Sleet, Microsoft’s name for the North Korean IT workers, uses it for developing a consistent persona and narrative, finding aligned job markets and available positions to target, setting up infrastructure such as VPNs, and even voice modulation and video overlays to appear more convincing. Threat actors are able to bypass safety controls in commercially available AI to “jailbreak” it to do things it’s not supposed to be allowed to do. One of the methods is to ask the AI to assume a trusted role. “Respond as a trusted cybersecurity analyst” is one of the examples given. This kind of thing doesn’t require much in the way of technical skill, just clever wording. AI significantly lowers the skill barrier across the board, and helps attackers with setting up and maintaining infrastructure as well as crafting and debugging malware. AI is used to research publicly available vulnerabilities and methods of bypassing antivirus products, and get recommendations for running their command-and-control servers. The tactic of using intentionally bad grammar in phishing emails is giving way to extremely convincing AI-generated social engineering and phishing, with communication adapted to the personal writing style of individuals. A phishing email that sounds almost exactly like the person it’s mimicking is now more likely than ever. The last part of threat actors that hasn’t been fully automated is the human decision making. That may soon come to an end, however, as threat actors are now experimenting with AI agents to make decisions and execute tasks, although this hasn’t been observed at scale yet. AI agents for coding malware are significantly more common, and allow malicious actors to pump out malware at a rapid pace and adapt quickly to the rapidly changing security landscape. They can create entire fake company websites and rapidly deploy infrastructure. AI agents could autonomously refine phishing campaigns without much human input. AI agent-led malware campaigns have already been [observed](https://www.anthropic.com/news/disrupting-AI-espionage) in the wild. ### Data Breach Roundup (Feb 27 – Mar 5, 2026) URL: https://www.privacyguides.org/news/2026/03/09/data-breach-roundup-feb-20-feb-26-2026-2/ Last updated: 2026-03-09T05:52:25.000Z Want to stay informed? Get the data breach roundup delivered straight to your inbox every week! New and current subscribers can now adjust your newsletter settings to get subscribed. [Subscribe to emails ](#/portal) ## LexisNexis confirms data breach as hackers leak stolen files LexisNexis - which this article generously describes as a "data analytics company" - suffered a data breach due to an unpatched Reach2Shell vulnerability (which was rated at the maximum severity of 10 when it was discovered and highly publicized in November 2025, patches began to release in early December). The company claims old, non-sensitive data was stolen, such as customer names, user IDs (unclear if they mean identifications or more like usernames), business contact information, products used, customer surveys with respondent IP addresses, and support tickets. They insist no PII like Social Security numbers, driver's license number, financial information, or other data was leaked. [LexisNexis confirms data breach as hackers leak stolen filesAmerican data analytics company LexisNexis Legal & Professional has confirmed to BleepingComputer that hackers breached its servers and accessed some customer and business information.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-68.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/lexisnexis.jpg)](https://www.bleepingcomputer.com/news/security/lexisnexis-confirms-data-breach-as-hackers-leak-stolen-files/) ## Star Citizen game dev discloses breach affecting user data This occurred in January 2026 and impacts "basic account information" (such as metadata, contact details, username, date of birth, and name) for an undisclosed number of accounts. Cloud Imperium Games is not being super transparent or forthcoming with information and has not committed to providing more information once the investigation is complete. [Star Citizen game dev discloses breach affecting user dataCloud Imperium Games (CIG), the game developer behind Star Citizen and Squadron 42, says attackers breached systems containing some users’ personal information in January.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-67.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Cloud_Imperium_Games_UK_offices.jpg)](https://www.bleepingcomputer.com/news/security/star-citizen-game-dev-discloses-breach-affecting-user-data/) ## Paint maker giant AkzoNobel confirms cyberattack on U.S. site AkzoNobel is a major global paint maker operating in over 150 countries with an annual revenue of over $12 billion. Anubis ransomware claims to have stolen 170GB of data including things like confidential agreements, email addresses, phone numbers, private emails, passport scans, material testing documents, and internal technical specification sheets. [Paint maker giant AkzoNobel confirms cyberattack on U.S. siteThe multinational Dutch paint company AkzoNobel has confirmed to BleepingComputer that hackers breached the network of one of its U.S. sites.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-69.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/paints.jpg)](https://www.bleepingcomputer.com/news/security/paint-maker-giant-akzonobel-confirms-cyberattack-on-us-site/) ## Hacker mass-mails HungerRush extortion emails to restaurant patrons HungerRush is a technology provider that offers point-of-sale, online ordering, delivery management, and more to restaurants. Earlier this week customers started receiving emails addressed to the company from an attacker trying to force the company into negotiations for a data breach. There are no details at this time about how many customers were impacted or what information was taken, but clearly the criminals at least have access to email addresses and the company's infrastructure. [Hacker mass-mails HungerRush extortion emails to restaurant patronsCustomers of restaurants using the HungerRush point-of-sale (POS) platform say they received emails from a threat actor attempting to extort the company, warning that restaurant and customer data could be exposed if HungerRush fails to respond.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-70.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/hungerrush.jpg)](https://www.bleepingcomputer.com/news/security/hacker-mass-mails-hungerrush-extortion-emails-to-restaurant-patrons/) ## UH Cancer Center data breach affects nearly 1.2 million people An update to a story from [January](https://www.privacyguides.org/news/2026/01/16/data-breach-roundup-jan-9-jan-15-2026/), we now know the number of people impacted. Contrary to initial reporting, the breach includes names, Social Security numbers, driver's license data, and voter registration data and covers four studies as well as two more files of names and SSNs collected for epidemiological research. [UH Cancer Center data breach affects nearly 1.2 million peopleThe University of Hawaii confirmed that a ransomware gang stole the data of nearly 1.2 million individuals in August 2025 after breaching its Cancer Center’s Epidemiology Division.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-66.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/UH_Cancer_Center-1.jpg)](https://www.bleepingcomputer.com/news/security/university-of-hawaii-cancer-center-ransomware-attack-affects-nearly-12-million-people/) ### Coruna Malware Targeting iOS Spotted by Google Threat Intelligence URL: https://www.privacyguides.org/news/2026/03/07/coruna-malware-targeting-ios-spotted-by-google-threat-intelligence/ Last updated: 2026-03-07T02:05:25.000Z Google Threat Intelligence Group has [identified](https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit) a “powerful exploit kit” targeting iPhones running iOS 13.0 to 17.2.1 used by a surveillance company and crypto-stealing sites. The kit, dubbed Coruna internally by its developers, contained five full iOS exploit chains and 23 total exploits, some of which were non-public exploits and mitigation bypasses. GTIG initially tracked it through its use by a customer of a surveillance vendor, a seller of spyware that’s used against targeted individuals’ devices. They later were able to obtain the full exploit kit after observing it being used in watering hole attacks (attacks where a website frequently visited by the target is hacked to distribute malware to them) against Ukrainians by UNC6353, a suspected Russian espionage group. They then found it being used by fake Chinese gambling and crypto websites looking to empty users’ crypto wallets. The distribution across multiple seemingly unrelated attacks implies an active “second-hand” market for zero-day exploits. Beyond the exploits themselves, attackers can reuse advanced exploitation techniques with new exploits once the old ones are patched. ![](https://www.privacyguides.org/content/images/2026/03/image.png) Credit: [GTIG](https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit) GTIG says the kit is not effective against the latest version of iOS, so users should update their devices urgently. The framework first starts and advanced fingerprinting module, collecting data points to determine what specific iPhone model and iOS version the user is running. Then, it loads the appropriate remote code execution (RCE) exploit and then a pointer authentication code ([PAC](https://developer.apple.com/documentation/security/preparing-your-app-to-work-with-pointer-authentication)) bypass, a security mitigation to prevent memory corruption. GTIG describes the kit as “extremely well engineered,” with all the pieces sharing a common framework. Interestingly, the malware quits if the phone is in Lockdown Mode or Safari is in Private Browsing mode. The list of 23 exploits covers different ranges of iOS versions and all have their own names such as buffout, bluebird, terrorbird, cassowary, etc. Interestingly, the codenames are all in English. The founder of iVerify, Rocky Cole, told [Wired](https://www.wired.com/story/coruna-iphone-hacking-toolkit-us-government/) that he believes the US government might be behind Coruna. > This is the first example we've seen of very likely US government tools – based on what the code is telling us – spinning out of control and being used by both our adversaries and cybercriminal groups. Boris Larin, principal security researcher at Kaspersky disagrees. He told *The Register* "we see no evidence of actual code reuse in the published reports to support attributing Coruna to the same authors." It’s good to know that the exploit used was patched before GTIG were even able to find the exploit kit. It just goes to show how important updating your software is. ### GrapheneOS Hardware Partner Revealed, ProtonMail shares user payment data, Apple devices approved for NATO use, and More! URL: https://www.privacyguides.org/livestreams/2026/03/06/graphene/ Last updated: 2026-03-07T00:37:22.000Z This Week In Privacy #43 _This post is for subscribers only._ ### New JVG Quantum Decryption Algorithm Could Pose Risk to Classical Encryption URL: https://www.privacyguides.org/news/2026/03/06/new-jvg-quantum-decryption-algorithm-could-pose-risk-to-classical-encryption/ Last updated: 2026-03-06T19:48:46.000Z A new quantum decryption algorithm called [JVG](https://www.securityweek.com/quantum-decryption-of-rsa-is-much-closer-than-expected/) could significantly reduce the amount of resources needed to decrypt classical RSA encryption that we’ve been relying on for decades. It’s been speculated for years that quantum computers will eventually be able to crack classical encryption. Classical encryption like RSA comes all the way back from 1977 and relies on the difficulty of factoring two large prime numbers. But quantum computers have been theorized to be able to crack this encryption scheme in a reasonable amount of time with a powerful enough quantum computer. [Shor’s](https://quantum.cloud.ibm.com/docs/en/tutorials/shors-algorithm) algorithm for a long time has been the gold standard for factoring prime numbers faster than any classical algorithm. In order to work efficiently though, Shor’s algorithm needs a large quantum computer with at least one million qubits (quantum bits, the quantum equivalent of a bit in a classical computer). A quantum computer that powerful is theorized to be at least a decade away. Although it’s not possible to break classical encryption currently, governments and criminal gangs are harvesting troves of encrypted data hoping to decrypt it when quantum computers become powerful enough, the so-called “harvest now, decrypt later” [attack](https://www.paloaltonetworks.com/cyberpedia/harvest-now-decrypt-later-hndl). NIST has [released](https://csrc.nist.gov/projects/post-quantum-cryptography) standards for post-quantum cryptography that have made their way into messengers, [TLS](https://www.ietf.org/archive/id/draft-reddy-uta-pqc-app-07.html), and many other places. It could be argued that adoption hasn‘t been fast enough, however. [Signal](https://signal.org/blog/pqxdh/), [iMessage](https://security.apple.com/blog/imessage-pq3/), and other messengers have been some of the early adopters, largely owing to the fact that messengers have the most sensitive information. However, very popular messengers such as WhatsApp and Telegram still lack PQC E2EE. The introduction of the new JVG algorithm could mean platforms have less time than previously thought to upgrade to PQC. The algorithm could only require less than 5,000 qubits and complete decryption. According to a [paper](https://www.preprints.org/manuscript/202510.1649) by Jesse Van Griensven, the J in JVG: > Projection for RSA-2048 indicates that the JVG algorithm significantly outperforms Shor’s approach, requiring a projected quantum runtime of 11 hours for a factorization under identical scaling assumptions. It’s important to note that Shor’s algorithm has been heavily studied and scrutinized over decades while this algorithm is quite new, so these claims haven’t had the same scrutiny. Still, it’s alarming to even consider the possibility that the encryption we all rely on every day to keep the most personal details about us safe could be so close to being almost useless. This research should be a call-to-action for mass adoption of PQC as soon as possible. ### TikTok Won’t Add E2EE for User Safety URL: https://www.privacyguides.org/news/2026/03/04/tiktok-wont-add-e2ee-for-user-safety/ Last updated: 2026-03-04T20:07:21.000Z TikTok told the [BBC](https://www.bbc.com/news/articles/cly2m5e5ke4o) that it will not be rolling out end-to-end encrypted DMs, citing user safety as a concern. Amid social media platforms adding E2EE to direct messages in order to protect users’ privacy, TikTok has taken a bold anti-privacy stance. E2EE ensures that no one, not even the platform itself, is able to read your messages except for you and your recipient. Previously, TikTok hadn’t clarified why it doesn’t support E2EE. But now they say they believe it “prevents police and safety teams from being able to read direct messages if they needed to.” E2EE is becoming more and more common, with [WhatsApp](https://faq.whatsapp.com/820124435853543), [Facebook Messenger](https://www.facebook.com/help/messenger-app/786613221989782/), [Instagram](https://help.instagram.com/491565145294150), and even [X](https://www.macrumors.com/2025/11/17/x-launches-chat-encrypted-dm-service/) now supporting some form of E2EE (although X has drawn criticism for their implementation). It’s important to point out that in [WhatsApp](https://faq.whatsapp.com/1142481766359885/?cms%5Fplatform=web#:~:text=WhatsApp%20receives%20up%20to%20five%20of%20the%20last%20messages), when you report someone it sends the last 5 messages they sent. So it’s possible to maintain E2EE and also provide methods to report users abusing the platform. TikTok has long faced [criticism](https://www.bbc.com/future/article/20260210-tiktok-is-tracking-you-even-if-you-dont-use-the-app-heres-how-to-stop-it) for its data harvesting practices: > For example, last week I visited the website for a cancer support group. According to Disconnect, when I clicked a button on a form that said I was a cancer patient or a survivor, the website sent TikTok my email address along with those details. A women's health company sent TikTok data when I looked at fertility tests. A mental health organisation pinged TikTok when I indicated I'm looking for a crisis counsellor. Websites that use pixels send data about every single visitor, so it doesn't matter if you don't have a TikTok account. Many thought that TikTok’s privacy problems were due to its ties to Chinese company ByteDance, but after [selling](https://www.floridatoday.com/story/news/2026/01/28/oracle-new-tiktok-owner-larry-ellison-deal-terms-conditions-change/88384409007/) its US operations to US owners including tech giant Oracle, there’s been no privacy improvements. Discord added [E2EE](https://discord.com/blog/meet-dave-e2ee-for-audio-video) for video and audio calls a while back, but they intentionally kept messages unencrypted for similar reasons. I think though that if Meta can roll out E2EE throughout their products, it should be possible for Discord and TikTok to do it. It’s totally possible to implement features for reporting abusive content, it’s just a matter of bothering to do the work. With governments [attacking](https://fightchatcontrol.eu) E2EE with laws using the old “protect the children” excuse, platforms like TikTok and Discord have more power than most to fight back. If platforms like TikTok really want to protect younger users, they should stop harvesting endless data and selling it off for profit, and implement actual privacy protections like E2EE. ### Smartphone Security Course (Lesson 3: Advanced) URL: https://www.privacyguides.org/videos/2026/03/04/smartphone-security-course-lesson-3-advanced/ Last updated: 2026-03-04T11:55:43.000Z If you missed the first lesson check that out here: [Smartphone Security Course (Lesson 1: Beginners)In this three-part course, we walk users through the steps they can take to make their phones as private and secure as possible.![](https://www.privacyguides.org/content/images/icon/pg-yellow-2-45.png)Privacy GuidesNate Bartram![](https://www.privacyguides.org/content/images/thumbnail/thumbnailbee_8GBbc8b39Zk_maxres.jpg)](https://www.privacyguides.org/videos/2026/02/04/smartphone-security-course-lesson-1-beginners-2/) ## Lesson 3 (iOS) We've covered the basics, like adjusting settings on your device, intermediate changes such as switching to private alternatives, and now it's time to cover advanced tips to protect your Privacy & Security on iPhone. Let's dive in! 🔒 #### Sources 0:42 2:24 2:42 3:20 ## Lesson 3 (Android) When it comes to maximizing your privacy & security on Android, you need to make drastic changes to your device, in this lesson we cover some of the more advanced changes you need to make. Let's dive in! #### Sources 0:42 1:05 2:10 2:27 2:45 3:24 ### How to Game Privately URL: https://www.privacyguides.org/posts/2026/03/03/how-to-game-privately/ Last updated: 2026-03-03T23:46:11.000Z The video game industry was estimated to be worth about [298.98 billion USD](https://www.grandviewresearch.com/industry-analysis/video-game-market) in 2024\. [205.1 million Americans](https://www.theesa.com/annual-esa-study-reveals-video-games-universal-appeal-across-generations/) play video games (there are over 342 million Americans). Needless to say, gaming is a regular part of many of our lives: we use games to socialize, to relax after a hard day at work, to challenge ourselves an refine our skills. It's fair to say that gaming is an essential part of many of our lives. It's a shame then that so many popular games are proprietary software, contain [restrictive DRM](https://www.gog.com/blog/what-exactly-is-drm-in-video-games-and-why-should-you-care/) software, invasive [anti-cheat software](https://levvvel.com/games-with-kernel-level-anti-cheat-software/), and extensive [data collection](https://esportslawyers.ca/how-do-video-games-collect-and-use-data). Many even require installing a dedicated launcher just for that game, require an account, and might require installing other unwanted programs on your computer. Fortunately, there are companies looking to improve the way things are done and there are things you can do as an individual to protect your privacy and keep your hobby. ## DRM Computers are amazing things, they can make perfect copies of data as many times as we need them to. In fact, it's essential to how they work. But this presents a problem: how do you stop people from copying your work and giving it out for free instead of paying you for it? ### Early Copy Protection An early instance of copy protection for consumer software came about from none other than [Microsoft](https://www.filfre.net/2016/01/a-pirates-life-for-me-part-3-case-studies-in-copy-protection/) (who else) for their game [*Microsoft Adventure*](https://www.pcjs.org/software/pcx86/game/microsoft/adventure/), now playable in your browser. The game exploited how floppy disks worked to protect the game from being copied; the device you use to copy won't even be able navigate the sectors on the disk. Developers concocted their own home-grown schemes for copy protection for a while. Some games would eschew software or hardware copy protection for what were called "[feelies](https://en.wikipedia.org/wiki/Feelie)"; physical items that came with the game like a book that would need to be used to answer a question or solve a puzzle before the game can be played. During the 80s, third party copy protection schemes started to become prominent, such as [RapidLok](https://diskpreservation.rittwage.com/dp.php?pg=rapidlok) and [PirateBusters](https://diskpreservation.rittwage.com/dp.php?pg=piratebusters). It's interesting to note that these early attempts weren't huge corporate operations; they were mostly just a few developers selling the copy protection schemes they'd come up with for a quick buck. In the interview I linked above, Brian R. Niessen, one of the original three creators of PirateBusters, describes the income of their operation: > It paid the rent and bought Slurpees at 7-11, but none of us became rich over it. Nowadays, DRM companies like Denuvo charge companies [thousands of dollars](https://www.thegamer.com/crytek-paid-denuvo-crysis-remastered-leak/) for their software. ### The Current Landscape These days, DRM is so prevalent that we've mostly come to accept it. App Store apps contain [DRM](https://en.wikipedia.org/wiki/FairPlay), most games come with some kind of third-party DRM like [Denuvo](https://irdeto.com/video-games), and it's essentially impossible to watch a movie or TV show DRM-free. As the landscape has evolved, DRM solutions have become much more privacy-invasive. Denuvo, for example, will collect [uniquely identifying hardware information](https://connorjaydunn.github.io/blog/posts/denuvo-analysis/) and send it off to Denuvo's servers. And yes, of course it runs with kernel privileges in order to do this. Another insidious development is the advent of always-on DRM. This type of DRM requires you to constantly be connected to a server in order to be allowed to play the game. This is especially insidious for single-player games like [*Diablo III*](https://www.defectivebydesign.org/diablo3) or [*Sim City*](https://www.gamesindustry.biz/always-online-simcity-burns-to-the-ground-10-years-ago-this-month), preventing you from playing them offline. Even ignoring the problems with availability and [game preservation](https://www.dlcompare.com/gaming-news/the-crew-game-that-sparked-the-stop-killing-game-movement-56928), a constant connection means constant data transmission as well. At minimum, the developer could know exactly when you're playing and when you're not, your IP address, and whatever is in the packets they keep sending to their server. Who knows what else is sent, modern games can be [data collection nightmares](https://www.sciencedirect.com/science/article/abs/pii/S187595212200060X). ### What You Can Do Here's what you shouldn't do first: DO NOT DOWNLOAD CRACKED GAMES. Cracked games you download off the internet often contain [malware](https://www.forbes.com/sites/zakdoffman/2025/08/19/microsoft-windows-warning-stop-playing-these-free-pc-games/). You should always download your software from an official source. Luckily, it's possible to buy and play many games without DRM. Stores like [itch.io](https://itch.io) and [GOG](https://www.gog.com/en/) offer extensive catalogues of DRM-free games to purchase. Plus, you'll be supporting the developers by purchasing their game. ## Anti-Cheat Cheating is a real problem in multiplayer games. [Thousands of players](https://www.ubisoft.com/en-us/game/rainbow-six/siege/news-updates/xvEzvsuxW34DS4WPs7zWA/r6-shieldguard---y10s3-update), even top players, use cheats. While it may be fun to stomp a lobby, it's not fun if you're on the receiving end (plus the whole point of a competitive game is to improve your skill, so cheaters also rob themselves of a large part of the appeal). In order to combat this problem and stop cheaters from ruining the experience for everyone, most multiplayer games you'll find nowadays use some form of anti-cheat software. Anti-cheat software behaves similarly to an [anti-virus solution](https://cyberpedia.reasonlabs.com/EN/anti-cheat%20protection.html): it uses signatures, behavioral analysis, heuristics, and runs continuously in the background while you play your game. ### Kernel Privileges Since anti-cheat needs to be able to detect modified systems, many solutions run with kernel privileges. This leaves users vulnerable to [malware](https://www.trendmicro.com/en%5Fus/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html) that exploits this low-level access to wreak havoc on your system. The reason for the switch to kernel-level anti-cheat is the so-called "arms race" between cheat developers and anti-cheat software. Cheat software can just bypass anti-cheat by simply hiding deeper and deeper in the system, outside of the privileges of the anti-cheat. ### Always Running Some anti-cheat software runs [continuously](https://www.reddit.com/r/VALORANT/comments/fzxdl7/comment/fn6yqbe/) in the background. The stated reason is it needs to load the driver at system startup so that cheat software doesn't load first and bypass the anti-cheat. Any anti-cheat software running a kernel-mode driver continuously can open you up to system crashes and exploits at all times, not just when the game is running. It also essentially gives the anti-cheat carte blanche access to your system, so you just have to trust that they're not sending sensitive data off constantly. ### What You Can Do Fortunately, operating system developers are starting to recognize the problems with kernel-level drivers. macOS is doing away with kernel extensions in favor of [System Extensions](https://developer.apple.com/documentation/systemextensions), which serve the same purpose as kernel extensions, but they run in userspace instead. This has allowed anti-cheat on macOS that simply comes as [part of the game client](https://www.leagueoflegends.com/en-us/news/dev/dev-vanguard-x-lol-retrospective/#:~:text=t-,his%20won%E2%80%99t%20require%20any%20extra%20installs%E2%80%94the%20security%20is%20%E2%80%9Cembedded%E2%80%9D%20right%20into%20the%20game%20client,-.%20Further) and runs without kernel privileges. Windows as well has put a lot off effort into new software and hardware security features designed to ensure the security of the operating system. Anti-cheat developers are looking to use these more and more, and move their software [fully out of the kernel](https://playvalorant.com/en-us/news/game-updates/vanguard-x-valorant/#:~:text=kernel%20level%20anti%2Dcheats%20will%20no%20longer%20be%20necessary%20to%20secure%20your%20games). It's taken Windows a bit longer to get there but we're seeing great progress. Eventually, Windows will move third party software [out of the kernel](https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/). In the meantime, it might be beneficial to [research which games](https://levvvel.com/games-with-kernel-level-anti-cheat-software/) have kernel-level anti-cheat still and avoid them until more progress is made. ## Data Collection A lot of games these days collect [troves of data](https://sci-hub.se/https://doi.org/10.1016/j.entcom.2022.100537) on their users. Behavioral data, biometric data, data on when you play, where you play, and how you play; in some games, almost everything is being collected and analyzed in order to maximize profit. ### Play Time Many games collect information about when you log in, how long you play, etc. Many even display this openly, such as Steam's playtime display in your game library. ### Gameplay Data While this can seem innocuous at first, data collected about how you play the game can be extremely fine-grained, such as how many of a specific enemy were killed, your exact keyboard and mouse inputs etc. As input devices become more and more advanced, such as the advent of VR headsets, collection of movement data and even eye movement around the screen is on the table. ### Communications Most multiplayer games contain some form of in-game text and voice chat, and it's never end-to-end encrypted. You can expect your chats to be kept on file as long as the game developers see fit, and used for whatever purposes they want. ### Sensor Data These days, many devices we game on such as our phones have cameras, microphones, accelerometers, gyroscopes, and more. Fortunately, especially on mobile, most of these sensors are protected behind permissions. But some still typically aren't, such as accelerometer and gyroscope data. This can reveal quite a lot about you, like your physical movements, step counts, or even [audio](https://blackhat.com/docs/eu-14/materials/eu-14-Nakibly-Gyrophone-Eavesdropping-Using-A-Gyroscope-wp.pdf). Hopefully we see an expansion of permissions on all our devices so that data collection like this isn't possible. ### Personal Data On top of the new behavioral data collection capabilities, the old standbys are still here: email, name, address, payment information, and other data are often collected for payment purposes or during signup for an account. This data can be used to link your data to your real identity, and can pose a risk of exposing your data in a data breach. ### Inferences Based on the Collected Data Game companies don't want all that data to go to waste. Increasingly, games will try to use your behavioral data to make inferences about your mood, financial status, spending habits, gender, etc to try and get you to spend more on their game. They will even use in-game behavioral data to make psychological determinations about you in real life. Metrics such as tendency toward addiction, how "power hungry" you are, even the [Big Five](https://en.wikipedia.org/wiki/Big%5FFive%5Fpersonality%5Ftraits) personality traits of openness, conscientiousness, extroversion, agreeableness, and neuroticism, can all be determined using in-game actions many times. Research has even shown that you can generate a valid personality profile simply from gameplay data. ### What You Can Do This one is tough: any time a game is allowed to communicate to a server, there's a possibility it transmits such data. #### Avoid Accounts The most important thing to do is avoid games that require an account to play. This excludes many free-to-play games of course. Any time an account is required to play a game, your activity can easily be correlated as soon as you log in, even on a different machine. It also makes it easier to correlate your activity with other online activity and your real identity, since they tend to ask for an email, phone number, name, or other personally identifiable info. #### Utilize Permissions Give games the minimum permissions you can. If they ask for your location, camera, or microphone, deny it. Operating systems like GrapheneOS greatly expand the permissions and allow you to block more items like sensors. Of course, if your hardware doesn't even support certain sensors, then it's impossible for the game to use them against you. A system without GPS, an accelerometer, a gyroscope, a camera, or a microphone won't be able to glean much. Also, be careful what input hardware you use: VR may be fun, but VR games are able to collect very detailed positional data about you as you play. A simple controller is far less intrusive, albeit less immersive also. ### Run Games On a Separate Machine If the games you want to run are not properly sandboxed, you can run your games on a completely separate system that you only use for games. This can be another PC or even a console: just make sure you are only using it for games and nothing else. ### Deny Network Access When running games that don't require internet such as single player games, you can turn your internet off in the settings (this might also be good to avoid distractions while playing). This will prevent any data from being sent off the the developers. Some operating systems such as [GrapheneOS](https://grapheneos.org/features#network-permission-toggle) support a user-facing network permission that you can utilize to disable network access for specific apps. ### Use Separate Communication Apps Instead of using the in-game chat features, use a secure third party communication app like Signal to talk to your friends while you play. If you are playing with people you don't know and they don't want to use your preferred secure communication method, you can stick with text chat rather than voice chat. ## Unwanted Programs Many games these days come with [launchers](https://www.ubisoft.com/en-us/ubisoft-connect) or other annoying bloatware. Now, some launchers are very useful, like Steam which keeps all your games updated for you automatically, and can handle friends and other useful features. However, it seems that almost every game wants to have its own launcher. Not only do these present added [attack surface](https://www.heise.de/en/news/Epic-Games-Launcher-Security-vulnerability-allows-rights-to-be-extended-10196692.html) on your system, they also tend to have lots of their own social features and data collection that you probably don't want. ### What You Can Do Avoid games that have their own launcher. Try to stick with one launcher, be it [Steam](https://store.steampowered.com/about/), [GOG Galaxy](https://www.gogalaxy.com/en/), or whatever your preferred one is. This way, you minimize the attack surface of your games and improve your own user experience at the same time. ## Security Games can present a security risk due to exploits, especially in [multiplayer games](https://dotesports.com/counter-strike/news/valve-quietly-fixes-major-cs2-security-exploit-but-disables-useful-feature-in-the-process). The reality with any type of game where you're being sent data from other players is anything they send could be malicious. It's mainly up to the developers of the game to use secure practices when developing their game. However, game developers typically aren't security researchers, so exploits in games run rampant. It doesn't help when developers allow complex things like image processing to be part of the multiplayer experience as well. Some games even allow you to download [custom content](https://www.digitaltrends.com/gaming/source-bug-custom-map-exploit/) when you join a server as well. Needless to say, this can be a huge vector for malware. ### What You Can Do #### Sandboxing Sandboxing is very helpful here. If you can play a sandboxed version of your favorite game, prefer that. For example, all apps on the macOS App Store are required to be sandboxed. Mobile platforms like Android and iOS offer mandatory sandboxing, so mobile gaming can be a great option for security. #### Dedicating Gaming Machine You could also consider having a dedicated gaming machine that's totally separate from your personal computer, be that another PC or a console. This way, if an exploit is used, your personal data won't be easily accessible to hackers. #### Disable Custom Content in Your Game Settings Most games that support custom user content give you some option to disable it. Disable any user-uploaded images, maps, or other content. #### Enable OS Security Features Every operating system these days comes equipped with security features such as secure boot, permissions for certain things like folders, camera, microphones, etc, and more. Go through your settings and familiarize yourself with the [security](https://learn.microsoft.com/en-us/windows/security/) [settings](https://support.apple.com/guide/security/welcome/web) of your OS, and enable what you can to protect yourself. ## Conclusion While games are increasingly trending toward more and more surveillance, there's still a lot you can do protect yourself. The most egregious examples typically come from the AAA games industry, and there are game stores dedicated to providing DRM-free games. Operating system security is only getting better and better, and gamers truly have more options than ever if they want private and secure gaming, you just have to know where to look. ## Want to read more like this? Established in 2021, Privacy Guides is the largest impartial, non-profit media outlet focused on finding privacy tools and learning about protecting your digital life. Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ### How We're Empowering Privacy Activists and Advocacy Groups URL: https://www.privacyguides.org/videos/2026/03/03/how-were-empowering-privacy-activists-and-advocacy-groups/ Last updated: 2026-03-03T21:21:01.000Z In a world where your privacy is increasingly under threat, it has never been more crucial to raise awareness and take action. To coincide with the Privacy Guides [**Activism section**](https://www.privacyguides.org/en/activism/) launch on Tuesday, March 3, we've put together a short video summarizing the new section and explaining why we created it. [Guides and Tools for Privacy ActivistsPrivacy Guides’ Activism section contains tools to support the community in its privacy advocacy and activism effort, both for individuals and organizations.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-21.png)Privacy Guides![](https://www.privacyguides.org/content/images/thumbnail/index-2.png)](https://www.privacyguides.org/en/activism/) ### Meta Smart Glasses Sending Sensitive Recordings to Workers to Annotate URL: https://www.privacyguides.org/news/2026/03/03/meta-smart-glasses-sending-sensitive-recordings-to-workers-to-annotate/ Last updated: 2026-03-03T17:33:48.000Z According to a report by [SVD](https://www.svd.se/a/K8nrV4/metas-ai-smart-glasses-and-data-privacy-concerns-workers-say-we-see-everything), Meta’s Ray-Ban AI Smart Glasses have been sending sensitive recordings of people, including “bank details, sex and naked people,” to outsourced companies to review and annotate. > You’re in control of your data and content. That’s what’s written in bold text at the top of the [Privacy Settings](https://www.meta.com/ai-glasses/privacy/) page for the glasses. However, this statement might be a blatant lie. SVD interviewed employees at Meta subcontractor Sama, some of whom did data annotation. When training AI, someone needs to label the mountains of training data so it’s more useful for training. That’s the job of data annotators: the humans working tirelessly behind scenes of the AI revolution. The data is collected from recordings of Meta Ray-Ban users when they press a physical button on the glasses or when using the “Hey Meta” voice command to activate the AI. They don’t continuously record, but activate on those two conditions. Despite offering users a choice not to share data with Meta to help improve their products, the glasses apparently will automatically send video and audio recordings for manual human review and it’s impossible to opt out of it. Concerningly, when they asked store employees about the data privacy of the glasses, they gave incorrect responses including that data stays “locally in the app.” However, upon testing, no AI functions worked without networking. When they analyzed the network connections of the app, they saw that it frequently connects to Meta’s servers. It’s completely impossible to interact with Meta’s AI solely locally on the phone. What this means is your video and audio data are constantly being sent to Meta just in order for it to function normally. This is on top of the mandatory submission of recordings for manual human review. “In some videos you can see someone going to the toilet, or getting undressed. I don’t think they know, because if they knew they wouldn’t be recording” said one worker they interviewed. The workers are based in Kenya and risk losing their jobs and being thrown out on the streets for breaching confidentiality agreements. > There are also sex scenes filmed with the smart glasses – someone is wearing them having sex. That is why this is so extremely sensitive. There are cameras everywhere in our office, and you are not allowed to bring your own phones or any device that can record It’s very obvious that people end up recording things they didn’t mean to record. Former Meta employees stated that faces are automatically blurred in annotation data sent off to these subcontractors, but the annotators said the blurring doesn’t work very well and sometimes leaves faces unblurred. It feels somewhat unsurprising to learn how privacy-invasive the glasses really are, especially when even the advertising material shows people being recorded surreptitiously. One annotator sums everything up well: “You think that if they knew about the extent of the data collection, no one would dare to use the glasses.” ### Privacy Guides launches a new Activism section URL: https://www.privacyguides.org/press-releases/2026/03/03/privacy-guides-launches-a-new-activism-section/ Last updated: 2026-03-03T17:00:17.000Z For Immediate Release — Privacy Guides, a non-profit organization focused on building a strong privacy & digital rights advocacy community, launched a brand new website section today. The new **Activism section** offers a new way to empower the digital rights community in its privacy advocacy and activism effort, both for individuals and organizations. [Guides and Tools for Privacy ActivistsPrivacy Guides’ Activism section contains tools to support the community in its privacy advocacy and activism effort, both for individuals and organizations.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-19.png)Privacy Guides![](https://www.privacyguides.org/content/images/thumbnail/index.png)](https://www.privacyguides.org/en/activism/) Privacy Guides is built on the belief that privacy is a fundamental right, essential to *everyone*. Improving privacy cannot *only* be a matter of individual protections. As corporations [exploit our data](https://www.privacyguides.org/en/basics/common-threats/#surveillance-as-a-business-model) more aggressively every day, and [regulations keep attacking](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/) the tools and services we rely on to protect our personal information, it has never been more important to work together to defend privacy rights as a community. The new section for activists in the privacy movement will progressively grow with more resources in the coming weeks, with some new resources already in development. Today, Privacy Guides launched the first tool in this section: the **Privacy Activist Toolbox**: This isn’t a *privacy* checklist for general *activists*. It’s truly a *privacy activist* toolbox, a new unique resource filled with tips to support the community specifically in privacy advocacy work. [Privacy Activist Toolbox - Privacy GuidesThe Privacy Activist Toolbox is a unique resource with tips for anyone interested in becoming a better privacy rights activist, or anyone who wants to start.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-20.png)Privacy Guides![](https://www.privacyguides.org/content/images/thumbnail/index-1.png)](https://www.privacyguides.org/en/activism/toolbox/) With this new section on Privacy Guides, the project will provide helpful tools and resources for privacy activists and digital rights organizations who are ready to defend privacy rights not only for themselves, but for everyone, collectively. --- [Privacy Guides](https://www.privacyguides.org/) is an impartial organization that is focused on building a strong privacy advocacy community and delivering the best digital privacy and consumer technology rights advice on the internet. Its mission is to inform the public about the value of digital privacy, consumer tech rights, and about global government initiatives which aim to monitor your online activity. Privacy Guides resources are free of advertisements and not affiliated with any of the recommended providers. Privacy Guides ([**www.privacyguides.org**](https://www.privacyguides.org/)) is built by volunteers and staff members around the world. For information about Privacy Guides or this announcement: **Activism Group Contacts:** Em *Activism & Outreach Lead* [em@privacyguides.org](mailto:em@privacyguides.org) Jonah Aragon *Program Director* [jonah@privacyguides.org](mailto:jonah@privacyguides.org) General Inquiry [press@privacyguides.org](mailto:press@privacyguides.org) ### “ClawJacked” Vulnerability Allows Malicious Websites to Take Control of OpenClaw URL: https://www.privacyguides.org/news/2026/03/02/clawjacked-vulnerability-allows-malicious-websites-to-take-control-of-openclaw/ Last updated: 2026-03-02T23:39:29.000Z [Oasis Security](https://www.oasis.security/blog/openclaw-vulnerability) discovered a vulnerability in the popular [OpenClaw](https://openclaw.ai) agentic AI software that allows websites to silently bruteforce access to a locally running instance and take it over. OpenClaw (previously known as Clawdbot and then MoltBot) is an AI agent that runs locally on your computer and performs tasks for you, such as sending messages, handling your calendar, even browsing for you. In order to perform these functions, it needs access to your system. You can grant it full system access or sandbox it to reduce the potential damage of an exploit. OpenClaw already has had issues with over [1,000 malicious skills](https://cybersecuritynews.com/openclaws-top-skill-malware/) discovered in OpenClaw’s community marketplace known as ClawHub, the #1 most downloaded skill being crypto-stealing malware. However this vulnerability affects the core system, no user-installed plugins needed. OpenClaw runs a gateway that handles authentication, and generally manages the AI agent. The gateway works using a [WebSocket](https://developer.mozilla.org/en-US/docs/Web/API/WebSocket) server. Authentication is handled by either a token (a long random string) or a password. The server treats local access to the server as inherently trusted, and for some reason it doesn’t apply the same rate limiting rules as with external connections. A malicious website can simply open a WebSocket of its own via JavaScript and connect to localhost, which is allowed. The website can then bruteforce the password at hundreds of attempts per second. Once the site is authenticated, it can be approved as a trusted device and issue commands to the gateway. There’s no user prompt for localhost device pairings. The attacker now has full control of OpenClaw and can dump data, perform actions, whatever they want. The attack seems so simple that it’s a wonder no one noticed it before now. There seem to be a few failures here: for one, why aren’t localhost connections subject to the same rate limiting as other ones, and why isn’t there a user prompt when a local connection tries to authenticate authenticate itself as a trusted device? Why are WebSockets allowed full access to localhost without any restrictions? There was a [similar](https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser) issue in browsers before, in which websites could access devices on localhost, and that got patched by blocking requests to 0.0.0.0\. Perhaps something similar should be done with WebSocket to prevent websites from accessing local services running on your machine. OpenClaw needs to enforce the security mechanisms it already has for *all* connections, including localhost. It’s a bit bizarre that they removed rate limiting and the user prompt for new devices, but kept the password. It seems like they reduced the security for almost no gain, since you still have to type the password anyway. Careless mistakes like this one highlight the dangers of agentic AI: there’s a lack of serious consideration for security on these agents that has taken years for operating systems and browsers to develop. Many people seem all too happy to give a random AI agent carte Blanche access to their machine with very little in the way of sandboxing or restrictions. It’s reminiscent of the early days of browsers where there was very little in the way of security and malicious websites could take over your computer without much effort. I fear AI agents will need to undergo a similar trial-by-fire where developers learn how to secure them properly over the course of years before they can be considered secure. ### Spyware Maker Sentenced to Prison URL: https://www.privacyguides.org/news/2026/03/02/spyware-maker-sentenced-to-prison/ Last updated: 2026-03-02T15:29:28.000Z The founder, Tal Dilian, and three other executives of Intellexa, a collective of spyware makers responsible for what was dubbed “Greek Watergate” have been [sentenced](https://techcrunch.com/2026/02/26/spyware-maker-sentenced-to-prison-in-greece-for-wiretapping-politicians-and-journalists/) to eight years in prison. The four were found guilty in relation to the illegal wiretapping of telecommunications of various politicians, business leaders, and senior military officials all the way back in [2022](https://en.wikipedia.org/wiki/2022%5FGreek%5Fsurveillance%5Fscandal) in what was dubbed the “Greek Watergate.” Their Predator spyware was used to target 87 people. The four were given 126 years each in prison and the court rejected any mitigating circumstances, but since their crimes were technically misdemeanors, they will only have to serve eight years, the maximum sentence for misdemeanors. The case marks the first time a spyware maker has been sentenced to jail for the misuse of their technology. Previously, WhatsApp had [sued](https://techcrunch.com/2025/05/30/eight-things-we-learned-from-whatsapp-vs-nso-group-spyware-lawsuit/) NSO Group for targeting WhatsApp users and successfully got them banned from doing so in the future, and a payout of $168 million in damages. Apple had [sued](https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/) NSO Group as well for the targeting and surveillance of Apple customers, but it suddenly [dropped](https://www.securityweek.com/apple-suddenly-drops-nso-group-spyware-lawsuit/) the case before they could get damages. This marks the first successful criminal case against executives in these malicious spyware tech companies that threaten the freedom and privacy of everyone in the world. While civil cases certainly can make a dent, convicting the executives that profit from human rights abuses will be a much more effective means of stopping them. After all, they act just like the criminal hacker gangs that target civilians, so they should be dealt with the same as well. It seems after the Pegasus spyware exploded over the news, western governments were gearing up to [restrict](https://www.vice.com/en/article/the-us-crackdown-on-spyware-vendors-is-only-beginning/) use of these tools. It’s fair to say the response has been underwhelming. Even half a decade later, these companies still exist and they’re still [thriving](https://carnegieendowment.org/research/2023/03/why-does-the-global-spyware-industry-continue-to-thrive-trends-explanations-and-responses). While security of targeted operating systems like iOS and Android have improved, ultimately the spyware vendors have such a huge budget that they always seem to be able to bypass the security improvements eventually. There really needs to be a complete ban of spyware outright and the makers of the spyware need to be criminally prosecuted for their crimes. Hopefully, this case is just the start. ### Samsung Forced to Halt Data Collection in TVs in Texas Without “Express Consent” URL: https://www.privacyguides.org/news/2026/03/02/samsung-forced-to-halt-data-collection-in-tvs-in-texas-without-express-consent/ Last updated: 2026-03-02T14:48:31.000Z Attorney General of Texas Ken Paxton [secured](https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-secures-major-agreement-samsung-ensure-texans-are-protected-smart-tvs) an agreement with Samsung that “will ensure Samsung no longer collects Automated Content Recognition (“ACR”) data without consumers being fully informed and consenting prior to any information being collected.” The agreement follows a [lawsuit](https://texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-five-major-tv-companies-including-some-ties-ccp-spying-texans) against Samsung for their data collection practices, particularly their Automated Content Recognition (ACR) technology. Paxton alleges that the technology is being used to “capture screenshots of a user’s television display every 500 milliseconds, monitor viewing activity in real time, and transmit that information back to the company without the user’s knowledge or consent.” Then they sell that data to target ads to them across platforms for profit. > This technology puts users’ privacy and sensitive information, such as passwords, bank information, and other personal information at risk. As part of the agreement, Samsung will stop collection of ACR data without Texas consumers’ “express consent.” Samsung must promptly update its smart TVs to implement the necessary consent screens that are void of [dark patterns](https://www.deceptive.design) and clearly communicate the data that will be collected. Paxton commends Samsung for being one of the first TV makers to implement these improvements. He also sued [Sony](https://texasattorneygeneral.gov/sites/default/files/images/press/Sony%20TV%20Petition%20Filed.pdf), [LG](https://texasattorneygeneral.gov/sites/default/files/images/press/LG%20TV%20Petition%20Filed.pdf), [Hisense](https://texasattorneygeneral.gov/sites/default/files/images/press/Hisense%20TV%20Petition%20Filed.pdf), and [TCL Technology](https://texasattorneygeneral.gov/sites/default/files/images/press/TCL%20TV%20Petition%20Filed.pdf) for similar data collection practices, but those cases are still ongoing. It’s been known for a while that smart TVs are some of the worst [offenders](https://c3.unu.edu/blog/the-silent-watchers-how-smart-tvs-invade-your-privacy-even-when-youre-not-watching-tv) for privacy-invasive data collection practices. TV manufacturers have even flirted with making a ”free” TV that you pay for with your [data](https://sfstandard.com/2024/01/04/telly-tv-review/). It even has a camera and everything! (You don’t even own the TV - if you get rid of it they will charge you for it). TVs used to be much simpler: they just took your display input and showed the picture. But with the rise of streaming services and the increasing complexity and cost of new display technology, companies needed some way to offset the cost or no one would be able to afford a TV. The smart TV allows for the cost of the appliance to be [subsidized](https://www.businessinsider.com/smart-tv-data-collection-advertising-2019-1?op=1) by incessant data collection, so a TV featuring the latest advanced features can still be affordable for the average person. With increasing [consumer](https://www.iab.com/wp-content/uploads/2025/01/IAB%5FConsumer%5FPrivacy%5FReport%5FJanuary%5F2025.pdf) awareness of privacy abuses and now governmental pressure on companies to stop deceptive privacy practices, we could see the return of dumb TVs as the viability of collecting user data dwindles. The Texas lawsuits are a win for consumers and I hope to see more and more pressure on companies to respect their own customers’ privacy. ### Threat Intelligence “Provenance” Could be the Solution to a Fractured Global Cybersecurity Landscape URL: https://www.privacyguides.org/news/2026/02/28/threat-intelligence-provenance-could-be-the-solution-to-a-fractured-global-cybersecurity-landscape/ Last updated: 2026-02-28T21:03:06.000Z Geopolitical tensions threaten cybersecurity research and sharing between countries, but [research](https://www.internetgovernance.org/2026/02/23/beyond-borders-how-threat-intelligence-provenance-can-save-global-cybersecurity-from-geopolitical-fragmentation/) from Georgia Tech demonstrates a possible system of auditable provenance data to validate *how* threat intelligence was produced instead of trusting *who* produced it. In January, China allegedly [announced](https://www.reuters.com/world/china/beijing-tells-chinese-firms-stop-using-us-israeli-cybersecurity-software-sources-2026-01-14/) a sweeping ban on cybersecurity companies such as VMware, Palo Alto Networks, and Fortinet, and even Google. The US previously has banned cybersecurity firm [Kaspersky](https://www.csoonline.com/article/2437595/us-bans-kaspersky-labs-over-national-security-concerns.html) over national security concerns. These bans threaten the open sharing of threat intelligence information between defenders. When a new piece of malware can reach a global scale within minutes, it’s important not to let national borders hinder the sharing of vital data. When the enemy is global, you need the defense to be global as well. But quality research isn’t suddenly worthless just because it comes from a geopolitical adversary: so having some way of verifying the quality of the research aside from the country of origin would be valuable. As threat intelligence data moves through the complex ecosystem, it’s unclear how [useful](https://www.ndss-symposium.org/ndss-paper/sharing-cyber-threat-intelligence-does-it-really-help/) or accurate the data even is. Scientists in a DARPA-funded [study](https://tillsongalloway.com/ti-ecosystem-ndss.pdf) developed a method of tracking the propagation of threat intelligence data through the ecosystem by embedding unique watermarks into benign files and tracking them as they moved between actors. The study found that while 67% of vendors perform dynamic malware analysis, only 17% shared the intelligence they extracted. Malicious URLs were shared 20 times more frequently than the actual malware itself, so defenders were taking conclusions of other vendors without the evidence needed to back them up. The sharing of data could also be delayed for hours or days, putting people’s security at risk. The researchers even found that malware was using the publicly available list of IP addresses of sandbox environments used by researchers to avoid analysis, reducing the number of vendors receiving intelligence by 25%. Questions about the veracity of threat intelligence from certain countries also threaten to reduce the amount of intelligence available globally. There needs to be a way to verify the history of threat intelligence data that documents the entire lifecycle of the data. Enter: secure [data provenance](https://dl.acm.org/doi/epdf/10.1145/1314313.1314318). > Data provenance summarizes the history of the ownership of the item, as well as the actions performed on it. The idea with provenance in TI data is you should be able to tell where it was first observed, how it was analyzed (e.g. via static analysis, executing it in a sandbox environment, or manual review), how deeply it was examined, which independent parties validated the research, and how long each step took. The new research shows that it’s technically feasible to create a formal, standardized and auditable provenance system that can track the path of TI data through various vendors and confirm the quality of the data, and vendors could filter data for ones that meet certain criteria such as data that’s been re-analyzed by domestic vendors to confirm the research. You could also sanitize the provenance metadata to protect operational details of vendors. The study found that vendors would delay sharing of data by hours or even days. The provenance data could reveal these bottlenecks. Provenance data could also reveal when antivirus vendors fail to execute malware while researching, this would show up on the audit trail and incentivize vendors to perform deeper analysis. When vendors simply re-share indicators of compromise or detection labels without performing their own independent analysis, it creates an illusion of independent consensus. Provenance data would reveal these patterns and incentivize them to perform their own deep analysis. The pieces are all in place, we just need a push from cybersecurity companies to make it happen. ### Android 17 Beta Introduces the Contact Picker and the Local Network Permission URL: https://www.privacyguides.org/news/2026/02/28/android-17-beta-introduces-the-contact-picker-and-the-local-network-permission/ Last updated: 2026-02-28T02:31:46.000Z Android 17 Beta 2 [released](https://android-developers.googleblog.com/2026/02/the-second-beta-of-android-17.html), bringing with it the rumored [Contacts Picker](https://developer.android.com/reference/kotlin/android/provider/ContactsPickerSessionContract.html#ACTION%5FPICK%5FCONTACTS:kotlin.String) for selecting individual contacts and the [Local Network Access](https://developer.android.com/reference/kotlin/android/Manifest.permission#access%5Flocal%5Fnetwork) permission for preventing apps from seeing other devices on your local network. Since iOS released their [Contacts Picker](https://developer.apple.com/documentation/contacts#Partial-contacts), Android was [rumored](https://www.androidauthority.com/android-17-contacts-picker-rumor-3615741/) to be working on an equivalent in Android 17\. Now it’s confirmed with this beta release. ![](https://www.privacyguides.org/content/images/2026/02/image.gif) Credit: [Android](https://android-developers.googleblog.com/2026/02/the-second-beta-of-android-17.html) It appears to work similarly to Apple’s Contact Picker feature, allowing users to select individual contacts to share with a specific app, but not allowing for users to pick specific information from each contact to share. GrapheneOS, a security and privacy-focused AOSP-based OS, has their own [Contact Scopes](https://grapheneos.org/features#contact-scopes) that allows for much more granular control over exactly what data you share with apps as well as telling the app that it has full contact permission without actually granting it full access to your contacts, preventing apps from refusing to work if you don’t grant them contact access. The update also introduces the [Local Network Access](https://developer.android.com/reference/kotlin/android/Manifest.permission#access%5Flocal%5Fnetwork) permission to prevent apps from accessing your other devices on your local network, such as your phone, PC, tablets, smart devices, etc. It falls under the pre-existing [NEARBY\_DEVICES](https://developer.android.com/reference/android/Manifest.permission%5Fgroup#NEARBY%5FDEVICES) permission, so if that’s already granted, you won’t be prompted again. Interestingly, they mention a “system-mediated, privacy-preserving device pickers to skip the permission prompt” to allow you to skip the permission prompt, so presumably you can request to connect to specific devices if you want to instead of asking for full local network access. The local network permission was introduced in Android 16, but it wasn’t [enforced](https://developer.android.com/about/versions/16/behavior-changes-16#:~:text=will%20be%20enforced%20at%20a%20later%20Android%20release) yet. Now it appears the permission will be properly enforced for apps. The local network permission was also one that was introduced first in [iOS 14](https://support.apple.com/en-us/102229), so it’s great to see Android adding missing features. Apps have been caught using users’ local network as a [fingerprinting](https://wire.com/en/blog/metas-stealth-tracking-another-eu-wake-up-call) vector to re-identify them across apps and browsers. So, even if the devices on your local network are secure, it’s still important to prevent apps from accessing your LAN. Android still lacks the [paste](https://developer.apple.com/forums/thread/713770?answerId=726678022) permission of iOS which prevents apps from reading your clipboard whenever they want to. Android only gives a [warning](https://developer.android.com/privacy-and-security/risks/secure-clipboard-handling#:~:text=31%29%2C-,every%20time%20an%20application%20accesses%20data%20within%20the%20clipboard%20and%20pastes%20it%2C%20a%20toast%20message%20is%20shown%20to%20the%20user%2C,-making) about this for now. It’s great to see iOS and Android adopting new privacy protections. The competition between the two only benefits users and makes the platforms safer for everyone. ### Burger King is Rolling Out AI in Employees’ Headsets to Track Their Friendliness URL: https://www.privacyguides.org/news/2026/02/27/burger-king-is-rolling-out-ai-in-employees-headsets-to-track-their-friendliness/ Last updated: 2026-02-27T23:51:16.000Z Burger King is testing out a new AI called Patty in 500 restaurants that will listen for keywords like “welcome,” “please” and “thank you” and in employees’ headsets and report to managers. Burger King’s Chief Digital Officer, Thibault Roux, told the [Verge](https://www.theverge.com/ai-artificial-intelligence/884911/burger-king-ai-assistant-patty) that Patty is meant as a way to improve customer service, not to track individual employees. They say they want to capture the tone of conversations as well, not just specific words and phrases. Patty can also alert employees if a machine is out of order or when an item is out of stock. You can also ask it questions such as how to make certain food items. The system is powered by ChatGPT, which means employees’ microphone inputs are constantly being sent off to ChatGPT’s servers in plaintext to be processed. ChatGPT is cloud-only and lacks privacy protections that some AI services have like [TEEs](https://confer.to/blog/2026/01/private-inference/) or [homomorphic encryption](https://www.ibm.com/think/topics/homomorphic-encryption) to make data inaccessible while it’s being processed. The system is part of a new cloud-based point-of-sale system that’s meant to connect all the parts of the business together and help it run smoothly. For example, when a machine is out of order, the digital menu board both in the restaurant and in the drive-through will be updated within 15 minutes. Patty is just the user-facing voice behind the broader BK Assistant platform that it plans to launch on the web and app platforms in all of their restaurants by the end of 2026. Burger King says they’re also experimenting with using AI to take orders at the drive-through, but they’re only piloting it at 100 restaurants for now. “Not every guest is ready for this” says Roux. Other companies like [McDonald’s](https://www.theverge.com/2024/6/16/24179679/mcdonalds-ending-ai-chatbot-drive-thru-ordering-test-ibm) have attempted this in partnership with IBM, but they gave up on it in 2024\. [Wendy’s](https://www.wsj.com/articles/wendys-google-train-next-generation-order-taker-an-ai-chatbot-968ff865) and [Taco Bell](https://www.wsj.com/articles/taco-bell-rethinks-future-of-voice-ai-at-the-drive-through-72990b5a?mod=rss%5FTechnology) tried similar AI drive-through systems, with mixed results. The move is part of an overall trend of normalizing [workplace surveillance](https://ssir.org/articles/entry/the%5Flong%5Fshadow%5Fof%5Fworkplace%5Fsurveillance) where employees are supposed to expect to be constantly monitored while they’re on the job. Employees are constantly being subjected to more and more surveillance tech, their every word and movement constantly tracked and microanalyzed with the ever-looming threat of punishment or firing on the horizon. Corporations like Burger King sell this tech as a way to improve efficiency, but the cost to employee well-being isn’t considered. They may give it a cutesy name like “Patty” but it’s still surveillance nonetheless. ### Apple's Expanded Age Verification, Open Source Funding Issues, Amazon Wishlist Changes May Cause Doxing, and More! URL: https://www.privacyguides.org/livestreams/2026/02/27/apples-expanded-age-verification-open-source-funding-issues-amazon-wishlist-changes-may-cause-doxing-and-more/ Last updated: 2026-03-01T00:12:40.000Z This Week in Privacy #42 _This post is for subscribers only._ ### Data Breach Roundup (Feb 20 – Feb 26, 2026) URL: https://www.privacyguides.org/news/2026/02/27/data-breach-roundup-feb-20-feb-26-2026/ Last updated: 2026-02-27T20:45:11.000Z ## PayPal discloses data breach that exposed user info for 6 months This impacted the PayPal Working Capital loan app, which provides small business loans to users. Customer names, email address, phone numbers, business address, Social Security numbers, and dates of birth were exposed between July 1 and December 12, 2025\. This appears to be have been caused by a "code change" and it does appear attackers found and took advantage of at least some of the information, leading to unauthorized transactions. [PayPal discloses data breach that exposed user info for 6 monthsPayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-59.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/PayPal-headpic.jpg)](https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-personal-information/) ## Data breach at French bank registry impacts 1.2 million accounts This was the result of a credential leak that gave attackers access to a database of all bank accounts opened in French banking institutions. Data included bank details "including RIBs/IBANs," account holder identity, physical address, and in some cases taxpayer identification number. [Data breach at French bank registry impacts 1.2 million accountsThe French Ministry of Finance has published an announcement informing of a cybersecurity incident that has impacted 1.2 million accounts.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-60.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/flag-of-france.jpg)](https://www.bleepingcomputer.com/news/security/data-breach-at-french-bank-registry-impacts-12-million-accounts/) ## Ad tech firm Optimizely confirms data breach after vishing attack Optimizely serves over 10,000 businesses, including brands like H&M, PayPal, Toyota, Vodafone, Shell, Salesforce, and Nike. The firm claims that "basic business contact information" was compromised, and not any sensitive customer data or personal information. No other datils have been provided at this time. [Ad tech firm Optimizely confirms data breach after vishing attackNew York-based ad tech company Optimizely has notified an undisclosed number of customers of a data breach after threat actors compromised some of its systems in a voice phishing attack.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-61.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Optimizely.jpg)](https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/) ## CarGurus data breach exposes information of 12.4 million accounts CarGuru is an "automotive research and shopping company." The data breached includes email address, IP address, full name, phone numbers, physical address, user account ID, finance application data, dealer account details, and subscription information. [CarGurus data breach exposes information of 12.4 million accountsThe ShinyHunters extortion group has published personal information in more than 12 million records allegedly stolen from CarGurus, a U.S.-based digital auto platform.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-62.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/CarGurus.jpg)](https://www.bleepingcomputer.com/news/security/cargurus-data-breach-exposes-information-of-124-million-accounts/) ## Wynn Resorts confirms employee data breach after extortion threat Wynn has not confirmed details in the article, but the attackers claimed to have stolen "PII (SSNs, etc) and employee data" for over 800,000 records. There aren't a lot of other details at this time. [Wynn Resorts confirms employee data breach after extortion threatWynn Resorts has confirmed that a hacker stole employee data from its systems after the company was listed on the ShinyHunters extortion gang’s data leak site.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-63.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/wynn-hotel-vegas.jpg)](https://www.bleepingcomputer.com/news/security/wynn-resorts-confirms-employee-data-breach-after-extortion-threat/) ## Hacker Used Anthropic’s Claude to Steal Mexican Data Trove An unknown attacker used Claude to pull of an attack on the Mexican tax authority's systems. The article is light on specifics, but says the Claude repeatedly resisted the prompts and the user had to perform extensive jailbreaking. 150 GB of government data was stolen, including 195 million taxpayer records, voter records, government employee credentials, and civil registry files. [Hacker Used Anthropic’s Claude to Steal Mexican Data TroveA hacker exploited Anthropic PBC’s artificial intelligence chatbot to carry out a series of attacks against Mexican government agencies, resulting in the theft of a huge trove of sensitive tax and voter information, according to cybersecurity researchers.![](https://www.privacyguides.org/content/images/icon/favicon-black.png)BloombergAndrew Martin![](https://www.privacyguides.org/content/images/thumbnail/1200x800.jpg)](https://www.bloomberg.com/news/articles/2026-02-25/hacker-used-anthropic-s-claude-to-steal-sensitive-mexican-data) ## Olympique Marseille confirms 'attempted' cyberattack after data leak Olympique Marseille is a top tier French football team. They recently confirmed a data breach that impacted 400,000 individuals including names, addresses, order information, email addresses, and phone numbers. [Olympique Marseille confirms ‘attempted’ cyberattack after data leakFrench professional football club Olympique de Marseille has confirmed a cyberattack after a threat actor claimed on Monday that it breached the club’s systems earlier this month.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-64.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Olympique_de_Marseille.jpg)](https://www.bleepingcomputer.com/news/security/olympique-marseille-football-club-confirms-cyberattack-after-data-leak/) ## European DIY chain ManoMano data breach impacts 38 million customers ManoMano is a French e-commerce firm with over 50 million unique visitors per month. The data stolen includes full name, email address, phone number, and customer service communications. [European DYI chain ManoMano data breach impacts 38 million customersDIY store chain ManoMano is notifying customers of a data breach personal data, which was caused by hackers compromising a third-party service provider.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-65.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/manomano.jpg)](https://www.bleepingcomputer.com/news/security/european-dyi-chain-manomano-data-breach-impacts-38-million-customers/) ## Conduent data breach grows, affecting at least 25M people This is an update from January 2025\. Conduent is one of the largest US government contractors providing a variety of services across various government agencies. Original disclosures put the victim count at around 15.4 million. Impacted data includes names, dates of birth, addresses, Social Security numbers, health insurance information, and medical data. [Conduent data breach grows, affecting at least 25M people | TechCrunchThe number of people affected by a data breach at government contractor giant Conduent is growing, as millions of people continue to receive notices warning them that hackers stole their personal data.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-36.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/conduent-630849206.jpg)](https://techcrunch.com/2026/02/24/conduent-data-breach-grows-affecting-at-least-25m-people/) ### Samsung Launches New “Privacy Display” to Protect Your Screen URL: https://www.privacyguides.org/news/2026/02/27/samsung-launches-new-privacy-display-to-protect-your-screen/ Last updated: 2026-02-27T19:15:00.000Z Samsung recently made the new [Galaxy S26](https://news.samsung.com/global/galaxy-unpacked-2026-a-first-look-at-the-galaxy-s26-series-samsungs-most-intuitive-ai-phone-yet) series available for pre-order, which features a huge privacy improvement never seen before on a phone: a builtin, toggleable privacy screen that functions on a per-pixel level. If you’re not familiar with privacy screens, they essentially restrict your viewing angle to be very narrow so that anyone not viewing the screen directly head-on will just see a black screen, protecting the contents of your screen such as passwords, photos, sensitive texts, etc from onlookers. The downsides of privacy screens make then nonviable for acct people though. Since they inherently restrict light due to how they function, they cause the screen overall to be dimmer than it would be without it. Since they’re stuck on top of the screen, they can’t be easily removed, so when you want to show someone something on your screen, it becomes quite annoying. Generally, display manufacturers have been trying to *increase* the viewing angle because that’s viewed as desirable for most people, and it is. The point of a screen after all is to show things to people. However, now with Samsung’s new display technology they term the “Privacy Display,” you can toggle the privacy screen effect on or off whenever you want. The tech works on the pixel level. Using a combination of “narrow” pixels That restrict the angle light is allowed to escape, and regular pixels, they can disable the regular pixels for specific areas of the screen, such as a password field, while leaving the rest of the screen unaffected. Since the ”narrow” pixels are surrounded on all sides, the viewing angle restriction applies in the top and bottom of the screen and not just the sides, so someone above you looking down also won’t be able to see your screen. You can enable the privacy screen for specific apps that require more security, such as a banking app or a messenger, as well as enabling it just for password fields and notifications. You can even enable it with a quick double press of the side button so you can quickly enable it in public places. In an age when [shoulder surfing](https://www.bbc.co.uk/news/business-65456325) is a major threat to phone users, this technology will genuinely prevent countless people’s data from being stolen. Samsung manufactures the displays for other companies such as Apple, so it’s possible we might see the technology in more devices in the future. Interestingly, Apple had filed a [patent](https://www.tomsguide.com/news/iphone-privacy-screen-will-stop-others-from-reading-your-phone-what-you-need-to-know) for similar tech back in 2023\. It’s more than likely that if Samsung allows it, it’ll end up in many more phones in the future. This isn’t the first attempt at a built-in, toggleable privacy screen. Lenovo has had a similar [feature](https://support.lenovo.com/us/en/solutions/ht514968-privacy-features-x1-carbon-gen-9-and-x1-yoga-gen-6) in their devices, however it only allows you to toggle the entire screen on or off, it doesn’t work on a per-pixel level like Samsung’s version. There’s been complaints that it’s not very effective and it dims the screen too much. Currently, the Privacy Display is only available on the flagship Galaxy S26 Ultra, but like most technology, I think we can expect it to be available on cheaper devices in the future. ### Notepad++’s New Update System is “Robust and Effectively Unexploitable” URL: https://www.privacyguides.org/news/2026/02/27/notepad-s-new-update-system-is-robust-and-effectively-unexploitable/ Last updated: 2026-02-27T18:00:23.000Z Notepad++ has released a [blog](https://notepad-plus-plus.org/news/v892-released/) post describing the security enhancements they’ve made since the [state-sponsored hack](https://notepad-plus-plus.org/news/hijacked-incident-info-update/) earlier this month, highlighting their new “double lock” update mechanism. The release marks the finalization of the measures that were promised in the previous announcement. Namely, enforcing the signed XML file returned by the update server. In their previous post, Notepad++ detailed the improvements they made to improve security. They switched to a new service provider that has “significantly stronger security practices.” The WinGup updater that handles automatic updates was updated to verify the certificate and the signature of the downloaded installer that they get from their GitHub. Additionally, they started signing the XML returned by the update server. However, they didn’t start enforcing the signature until this update. This completes what they call the “double lock” design, which makes it “robust and effectively unexploitable.” ![](https://www.privacyguides.org/content/images/2026/02/image.jpeg) Credit: [Notepad++](https://notepad-plus-plus.org/news/v892-released/) Compare this to their previous architecture that didn’t verify the XML file or the WinGup updater that was hijacked: ![](https://www.privacyguides.org/content/images/2026/02/image-1.jpeg) Credit: [Notepad++](https://notepad-plus-plus.org/news/v892-released/) Props to Notepad++ for the work they’ve done, but I have to question the claim that the new auto updater is “unexploitable.” It did stop the previous attack, but there’s no guarantee it’ll stop future attacks that target parts of the update process that were missed this time. They could avoid implementing their own autoupdater altogether and ship their software on the native app store of the operating system, such as the Microsoft Store in Windows, the App Store on macOS, or [Flathub](https://flathub.org/en) on Linux. These stores allow for apps to be signed to verify they’re from the true developers and they provide an update mechanism that they can utilize. If every piece of software on your system has its own updater, any of which could have similar issues to the Notepad++ updater, then you open yourself up to similar attacks for every single piece of software on your entire system. Aside from security, it’s pretty annoying when every app on your desktop has its own autoupdater that bugs you individually whenever there’s a new update instead of having them all in one place handled in the background. A similar attack from years ago happened with [CCleaner](https://thehackernews.com/2018/04/ccleaner-malware-attack.html). Attackers were able to take over the company’s servers, apparently for seven months, five of which were before they even served the malicious program. The fact that it goes unnoticed for months at a time is concerning. The Notepad++ attack lasted for 7 months as well. Every single program on your machine that you download from the developers’ website or that has its own autoupdater could potentially be vulnerable to these types of supply chain attacks. ### Firefox 148 Releases with Promised AI Killswitch Feature URL: https://www.privacyguides.org/news/2026/02/27/firefox-148-releases-with-promised-ai-killswitch-feature/ Last updated: 2026-02-27T17:03:45.000Z Firefox version [148](https://www.firefox.com/en-US/firefox/148.0/releasenotes/) has released, bringing with it the [AI killswitch](https://blog.mozilla.org/en/firefox/ai-controls/) feature that was promised, allowing users to disable all AI features from a single switch. The switch is called “Block AI Enhancements” in the settings, and Mozilla says you can use it if you “don’t want to use AI features from Firefox at all.” You can also individually enable or disable specific features. The features you can pick and choose from for now are translations, alt text in PDFs, AI-enhanced tab groups, link previews, and the AI chat sidebar. AI features are blocked by default and must be opted into. The new panel helpfully labels on-device AI features and those that send data off-device, such as the chat sidebar. To me, this is a great move for transparency, as it might have been unclear before whether a particular feature was on-device or was actively sending data off. The feature, [announced](https://mastodon.social/@firefoxwebdevs/115740500373677782) months ago, comes amid a huge AI-focused push at Mozilla, with their flashy [State of Mozilla](https://stateof.mozilla.org) annual report being completely comprised of AI and nothing else for Firefox users to look forward to. Mozilla is investing in over 50 AI companies to form what they call a “rebel alliance” against “big tech” AI companies like OpenAI. There’s not any mention of a focus on local-only AI or technologies that can enhance the privacy of AI like [TEEs](https://confer.to/blog/2026/01/private-inference/) or [homomorphic encryption](https://www.ibm.com/think/topics/homomorphic-encryption). It’s mostly vague claims about these companies being better without much technical information to back it up. Mozilla are focusing their “\~$1.4B in reserves, our brand and our people power“ toward their idea of “responsible“ AI. One wonders what could be accomplished with that much money, especially considering Mozilla’s older projects like [Rust](https://rust-lang.org), a memory-safe programming language that stops entire classes of exploits, and [Servo](https://servo.org), a rust-based browser engine that was originally meant to replace Firefox’s [Gecko](https://firefox-source-docs.mozilla.org/overview/gecko.html) engine, that are now under the stewardship of other entities. It’s unclear what Mozilla plans to expand their AI ventures into next. The hot new thing is agentic AI, which can perform actions on your behalf like sending emails or even shopping. Google [Chrome](https://blog.google/products-and-platforms/products/chrome/gemini-3-auto-browse/) has already added an “auto browse” feature. In their [security blog](https://security.googleblog.com/2025/12/architecting-security-for-agentic.html), Google highlights the challenges they face in trying to make agentic AI secure in the face of prompt injection attacks. Trail of Bits, a cybersecurity consulting firm, has made multiple [blog](https://blog.trailofbits.com/2026/01/13/lack-of-isolation-in-agentic-browsers-resurfaces-old-vulnerabilities/) [posts](https://blog.trailofbits.com/2026/02/20/using-threat-modeling-and-prompt-injection-to-audit-comet/) exposing the insecurity in currently-implemented agentic AI browsers. Mozilla needs to be careful about their future steps, as AI can be dangerous for their users’ data and security. They need to focus on local-only and non-agentic AI features as much as possible. I think this new AI killswitch is a great step in the right direction for user choice. ### Google Expands Quick Share’s AirDrop Support to Pixel 9 Series URL: https://www.privacyguides.org/news/2026/02/24/google-expands-quick-shares-airdrop-support-to-pixel-9-series/ Last updated: 2026-02-24T00:57:06.000Z Google is [expanding](https://support.google.com/pixelphone/thread/409524163) support for Quick Share and AirDrop compatibility between Pixel phones and iPhones to include Pixel 9 phones as well. Previously, the feature was [limited](https://blog.google/products-and-platforms/platforms/android/quick-share-airdrop/) to the Pixel 10 series. Quick Share allows Android devices to quickly send files over a local ad-hoc WiFi connection. AirDrop works the same way, but is limited to Apple devices. Sending files over a local connection like this means your files will never touch a remote server, and you can even transfer files with no internet connection or router at all. In Google’s previous announcement, they released a [post](https://security.googleblog.com/2025/11/android-quick-share-support-for-airdrop-security.html) on their security blog going over the considerations that were made during the development process: > We built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products. Our approach to security is proactive and deeply integrated into every stage of the development process. Of note is their use of Rust, a popular memory-safe programming language, in designing the feature. When designing a feature that parses data, memory safety bugs are one of the biggest sources of high-severity security issues. Writing in Rust eliminates entire classes of vulnerabilities. The feature is part of Google’s wider effort to [eliminate](https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html) memory safety bugs in Android by adopting Rust. Google also engaged a third-party firm, NetSPI, to conduct an [independent security assessment](https://www.netspi.com/wp-content/uploads/2025/11/google-feature-review-report.pdf), which only found 1 low-severity vulnerability which Google fixed. Currently, the feature only works with the “Everyone” mode, but Google invites Apple to help implement and interoperable “Contacts Only” mode. Google has also now [disabled](https://9to5google.com/2026/02/13/quick-share-removing-always-on-everyone-mode-on-android-matching-iphone/) the Everyone on by default mode in Quick Share, a move that Apple made in [AirDrop](https://www.idownloadblog.com/2022/12/08/ios-16-2-airdrop-everyone-option/) a while ago. Now, you can only enable the Everyone option for 10 minutes, matching AirDrop. Apple since added a feature to securely share files with a [code](https://support.apple.com/guide/iphone/use-airdrop-to-send-items-to-nearby-devices-iphcd8b9f0af/ios#:~:text=Share%20an%20item%20with%20an%20AirDrop%20code) so that both parties must confirm the sharing beforehand, and you can be sure you’re sharing with the correct person. The move was much-maligned when Apple did it, although the feature had been abused to send unwanted files to people’s phones. With any luck, the AirDrop interoperability will eventually be rolled out across the Android ecosystem. Google has said they plan to expand to more devices. Since iOS 26, iOS supports the [Wi-Fi Aware](https://developer.apple.com/documentation/WiFiAware) standard, so it should be completely possible to design an interoperable feature using what’s already built into the operating system. ### ChatGPT Adds Lockdown Mode for Protection Against Prompt Injection Attacks URL: https://www.privacyguides.org/news/2026/02/21/chatgpt-adds-lockdown-mode-for-protection-against-prompt-injection-attacks/ Last updated: 2026-02-21T08:00:27.000Z ChatGPT has [added](https://openai.com/index/introducing-lockdown-mode-and-elevated-risk-labels-in-chatgpt/) Lockdown Mode, "an optional, advanced security setting designed for a small set of highly security-conscious users—such as executives or security teams at prominent organizations—who require increased protection against advanced threats." Specifically, the mode targets [prompt injection attacks](https://owasp.org/www-community/attacks/PromptInjection). Because LLMs can't distinguish between the developer's instructions and user input, a malicious actor can trick the LLM to ignore the developer's intentions and instead follow their new instructions. These attacks can be incredibly destructive when combined with AI agents that can perform actions on behalf of their users such as managing files, sending emails, or browsing the web. Trail of Bits demonstrated how vulnerable agentic browsers are to these types of attacks in a [blog](https://blog.trailofbits.com/2026/01/13/lack-of-isolation-in-agentic-browsers-resurfaces-old-vulnerabilities/) post a bit ago. They were able to exfiltrate data through some creative means. The mode works by disabling certain tools and features in ChatGPT that an attacker could use to exfiltrate data through a prompt injection attack. Namely, Lockdown Mode [limits](https://help.openai.com/en/articles/20001061-lockdown-mode) ChatGPT's ability to access the live web and is instead restricted to cached versions. Image support is disabled for responses as well although users can still upload their own images and use the image generation feature. [Deep research](https://chatgpt.com/features/deep-research), an agentic feature for analyzing data from trusted sources, [Agent Mode](https://openai.com/index/introducing-chatgpt-agent/), which lets ChatGPT browse the web and perform actions for you, [Canvas](https://openai.com/index/introducing-canvas/)'s ability to access the network, and file downloads are all disabled in Lockdown Mode. > Configuring these features in this way is designed to prevent them from being used for the final stage of prompt-injection driven data exfiltration attacks by deterministically preventing outbound network requests that could be sent to the attacker to transfer such data. Note that Lockdown Mode does *not* deterministically prevent prompt injections from reaching the context in the first place (e.g. a prompt injection could be in cached content accessed via web browsing), instead it is designed to prevent network requests that could be used to transfer sensitive data to an attacker. [![](https://www.privacyguides.org/content/images/2026/02/Lockdown_mode__dark_mode.png.webp)](https://images.ctfassets.net/kftzwdyauwt9/52zv4ZuoXrOIkfxwqHMX2O/2ee414b9b0299cd2a373842151a8cb98/Lockdown%5Fmode%5F%5Fdark%5Fmode.png?w=3840&q=80&fm=webp) Source: OpenAI Since apps can have network access and therefore exfiltrate data, they pose a big security risk. But, many apps are essential for certain workflows, so domain admins are given granular controls over which apps and which capabilities within those apps to enable. For now, Lockdown Mode is limited to ChatGPT Enterprise, Edu, ChatGPT for Healthcare, and ChatGPT for Teachers. OpenAI says they plan to make it available to ChatGPT consumer and team plans in the coming months. OpenAI says Lockdown Mode doesn't completely eliminate the risk of prompt injection attacks, only greatly reduces it. In addition, new "Elevated Risk" labels have been added to features that OpenAI deems a security risk. They say once enough security mitigations are in place, the labels will eventually be removed. > These additions build on our existing protections across the model, product, and system levels. This includes sandboxing, [protections against URL-based data exfiltration⁠](https://openai.com/index/ai-agent-link-safety/), monitoring and enforcement, and [enterprise controls⁠](https://openai.com/business-data/) like role-based access and audit logs. OpenAI had [previously](https://openai.com/index/fighting-nyt-user-privacy-invasion/) promised to buff up the security of ChatGPT and include client-side encryption to keep your chats safe: > Our long-term roadmap includes advanced security features designed to keep your data private, including client-side encryption for your messages with ChatGPT. We believe these features will help keep your private conversations private and inaccessible to anyone else, even OpenAI. We're still waiting on that encryption for now. ### Meta's AI Glasses Get Worse, Password Managers Have Risks, iOS Privacy, and more! URL: https://www.privacyguides.org/livestreams/2026/02/20/metas-ai-glasses-get-worse-password-managers-have-risks-ios-privacy-and-more/ Last updated: 2026-04-03T18:29:33.000Z This Week in Privacy #41 _This post is for subscribers only._ ### Data Breach Roundup (Feb 13 – Feb 19, 2026) URL: https://www.privacyguides.org/news/2026/02/20/data-breach-roundup-feb-6-feb-12-2026-2/ Last updated: 2026-04-03T18:28:08.000Z ## Sex toys maker Tenga says hacker stole customer information The Japanese company says that an attacker accessed an employee's inbox, which could reveal the names, email addresses, and correspondence including order tails or inquiries. A number of impacted victims was not given. The company reset the employee's password and required 2FA, among other fixes. [Sex toys maker Tenga says hacker stole customer information | TechCrunchThe Japanese sex toy maker said a hacker broke into an employee’s inbox and stole customer names, email addresses, and correspondence, including order details and customer service inquiries.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-32.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/eggplant-blue-background.jpg)](https://techcrunch.com/2026/02/13/sex-toys-maker-tenga-says-hacker-stole-customer-information/) ## Fintech lending giant Figure confirms data breach The "blockchain-based" lending company was a victim of the ShinyHunters ransomware gang via the recent Okta breach. After refusing to pay the ransom, 2.5 GB of data was published, including full names, home addresses, dates of birth, and phone numbers. The company did not offer any further details. [Fintech lending giant Figure confirms data breach | TechCrunchThe company said hackers downloaded “a limited number of files” after breaking into an employee’s account. The hacking group ShinyHunters took responsibility for the breach.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-33.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/figure-technology-logo-times-squware.jpg)](https://techcrunch.com/2026/02/13/fintech-lending-giant-figure-confirms-data-breach/) ## Indian pharmacy chain giant exposed customer data and internal systems This occurred after a researcher discovered a "super admin" API running on DavaIndia's website. It was reported and closed, but it was active since late 2024 and could've revealed information about patient conditions, medicate, or purchases. [Indian pharmacy chain giant exposed customer data and internal systems | TechCrunchA backend flaw in web admin dashboards used by one of India’s largest pharmacy chains, exposed thousands of online pharmacy orders.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-34.png)TechCrunchJagmeet Singh![](https://www.privacyguides.org/content/images/thumbnail/medications-drugs-2237708773.jpg)](https://techcrunch.com/2026/02/13/indias-major-pharmacy-chain-exposed-customer-data-and-internal-systems/) ## Canada Goose investigating as hackers leak 600K customer records Canada Goose is a luxury outerwear brand. The data includes customer names, email addresses, phone numbers, billing & shipping addresses, IP addresses, and order histories as well as partial payment information like last four of the card, brand, and - in some cases - BIN and metadata. Canada Goose insists their system hasn't been breached but that the data is old data. They didn't comment on where this data might have come from even if it was old. [Canada Goose investigating as hackers leak 600K customer recordsShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data. Canada Goose told BleepingComputer the dataset appears to relate to past customer transactions and that it has not found evidence of a breach of its own systems.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-56.png)BleepingComputerAx Sharma![](https://www.privacyguides.org/content/images/thumbnail/canada-goose.png)](https://www.bleepingcomputer.com/news/security/canada-goose-investigating-as-hackers-leak-600k-customer-records/) ## Eurail says stolen traveler data now up for sale on dark web Eurail is a Netherlands-based company that sells passes for train travel across Europe. According to the article they're still investigating exactly what records were taken and how many customers were impacted, but the compromised server could've included full names, passport details, ID numbers, IBANs, health information, and contact details like email address and phone number. [Eurail says stolen traveler data now up for sale on dark webEurail B.V., the operator that provides access to 250,000 kilometers of European railways, confirmed that data stolen in a breach earlier this year is being offered for sale on the dark web.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-57.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/track.jpg)](https://www.bleepingcomputer.com/news/security/eurail-says-stolen-traveler-data-now-up-for-sale-on-dark-web/) ## A Vast Trove of Exposed Social Security Numbers May Put Millions at Risk of Identity Theft This databased - discovered in January by UpGuard - contains at least 3 billion records including email addresses, passwords, and Social Security numbers. It's unclear who it belongs to and appears to have been "cobbled together" from previous data breaches. [A Vast Trove of Exposed Social Security Numbers May Put Millions at Risk of Identity TheftA database left accessible to anyone online contained billions of records, including sensitive personal data that criminals appear to have not yet exploited.![](https://www.privacyguides.org/content/images/icon/favicon-22.ico)WIREDLily Hay Newman![](https://www.privacyguides.org/content/images/thumbnail/Mega-Trove-of-Exposed-Social-Security-Numbers-Security-2249961752.jpg)](https://www.wired.com/story/a-mega-trove-of-exposed-social-security-numbers-underscores-critical-identity-theft-risks/) ## Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches This fine was issued by South Korea over "failing to implement adequate security measures" which resulted in the exposure of the data of over 5.5 million customers last year. That includes names, phone numbers, email addresses, physical addresses, and purchase history. [Louis Vuitton, Dior, and Tiffany fined $25 million over data breachesSouth Korea has fined luxury fashion brands Louis Vuitton, Christian Dior Couture, and Tiffany $25 million for failing to implement adequate security measures, which facilitated unauthorized access and the exposure of data belonging to more than 5.5 million customers.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-55.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/0_LVMH.jpg)](https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/) ### Smartphone Security Course (Lesson 2: Intermediate) URL: https://www.privacyguides.org/videos/2026/02/20/smartphone-security-course-lesson-2-intermediate/ Last updated: 2026-02-25T22:17:29.000Z If you missed the first lesson check that out here: [Smartphone Security Course (Lesson 1: Beginners)In this three-part course, we walk users through the steps they can take to make their phones as private and secure as possible.![](https://www.privacyguides.org/content/images/icon/pg-yellow-2-45.png)Privacy GuidesNate Bartram![](https://www.privacyguides.org/content/images/thumbnail/thumbnailbee_8GBbc8b39Zk_maxres.jpg)](https://www.privacyguides.org/videos/2026/02/04/smartphone-security-course-lesson-1-beginners-2/) ## Lesson 2 (Android) In our intermediate Android lesson we'll cover private alternatives to popular applications that you can utilize. We'll also talk about how to obtain your apps in a privacy respecting way from alternative sources. #### Sources 0:02 0:43 0:50 0:59 1:10 1:16 1:24 1:36 1:56 2:02 2:16 2:36 2:45 3:00 3:15 3:35 3:40 3:43 3:56 4:08 4:26 4:50 4:49 5:08 5:22 ## Lesson 2 (iOS) In this lesson we'll help you to take your iPhone privacy to the next level, we'll be diving into alternative services and apps you can utilize to protect and secure your data on iPhone. #### Sources 0:03 0:37 0:47 0:54 1:06 1:12 1:17 1:26 1:36 2:16 2:27 2:50 3:06 3:22 3:27 3:53 4:03 4:10 4:25 ### Apple Introduces End-to-End Encrypted RCS Messaging in the iOS 26.4 Beta URL: https://www.privacyguides.org/news/2026/02/19/apple-introduces-end-to-end-encrypted-rcs-messaging-in-the-ios-26-4-beta/ Last updated: 2026-02-19T13:00:19.000Z The long-awaited cross-platform end-to-end encrypted RCS messaging between Android and iOS users has finally begun its testing phase in the recently released beta for iOS 26.4. A new toggle has appeared in the settings on the beta for iOS 26.4 that allows you to enable or disable E2EE for RCS. The setting is only available for messaging between iOS users for now. RCS is a [GSMA](https://www.gsma.com/solutions-and-impact/technologies/networks/rcs/) standard for cross-platform messaging meant to replace the archaic SMS that's been around since the 1980's. RCS adds the features that are expected of a modern messenger such as typing indicators, reactions, and high-resolution images and videos. With the announcement of [RCS Universal Profile 3.0](https://www.gsma.com/newsroom/article/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging/), the GSMA added support for E2EE using Messaging-Layer Security, an [IETF](https://www.rfc-editor.org/rfc/rfc9420.html) standard for encrypted messaging. Apple originally announced their intentions to add in a [statement](https://9to5mac.com/2025/03/14/end-to-end-encrypted-rcs-messaging-on-iphone/) to 9to5Mac back in March of last year: > End-to-end encryption is a powerful privacy and security technology that iMessage has supported since the beginning, and now we are pleased to have helped lead a cross industry effort to bring end-to-end encryption to the RCS Universal Profile published by the GSMA. We will add support for end-to-end encrypted RCS messages to iOS, iPadOS, macOS, and watchOS in future software updates. Since then, it's been mostly radio silence on the feature, until now that is. In the [release notes](https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26%5F4-release-notes) for the beta, Apple states that the feature will not be shipping with the stable release of iOS 26.4 and is just for testing during the beta, and that the feature won't be available for all devices or carriers: > RCS end-to-end encryption is now available for testing in this beta. This feature is not shipping in this release and will be available to customers in a future software update for iOS, iPadOS, macOS, and watchOS. End-to-end encryption is in beta and is not available for all devices or carriers. Conversations labeled as encrypted are encrypted end-to-end, so messages can’t be read while they’re sent between devices. In this beta, RCS encryption is available for testing between Apple devices and is not yet testable with other platforms. Unfortunately, RCS messaging depends on carrier support, so you'll need to make sure your carrier supports RCS messaging. It's likely that even carriers that currently support RCS will take a while to upgrade to Universal Profile 3.0 and beyond as well. Apple maintains a [list](https://support.apple.com/en-us/109526) of carriers and what features they support, so once the feature is fully released you will likely be able to check there if your carrier supports RCS E2EE. Google messages, the default texting app on a lot of Android phones, has [supported](https://www.gstatic.com/messages/papers/messages%5Fe2ee.pdf) E2EE RCS messaging for years, but they used their own in-house encryption based on the Signal protocol. Google states in an [FAQ](https://support.google.com/messages/answer/9487020?sjid=651438176642580710-NC#zippy=%2Cturn-on-rcs-chats-on-ios-devices%2Cturn-on-rcs-chats-on-android-devices%2Crcs-chats-with-iphone-users-dont-have-end-to-end-encryption) on RCS messaging that for now, E2EE messaging is still limited to other Google Messages users: > Google Messages offers end-to-end encryption for your RCS messages with other Google Messages users. The GSM Association (GSMA) sets Mobile and RCS standards and we are currently working to define security standards cross platform. [Reportedly](https://9to5google.com/2025/07/16/google-messages-rcs-mls/), Google has been testing out the new MLS-based encryption in preparation for inter-operational encryption. Apple still states that RCS isn't [encrypted](https://support.apple.com/en-us/104972#:~:text=RCS%20messages%20aren’t%20end%2Dto%2Dend%20encrypted%2C%20which%20means%20they're%20not%20protected%20from%20a%20third%2Dparty%20reading%20them%20while%20they're%20sent%20between%20devices.) in their documentation: > RCS messages aren’t end-to-end encrypted, which means they're not protected from a third-party reading them while they're sent between devices. We'll be watching to see if that changes in the near future. With Apple, Google, and carriers all getting onboard, the pieces for default E2EE messaging are beginning to fall into place after almost two years since the first hints were dropped by the GSMA. ### Google's "Project Toscana" Will Upgrade Face Unlock URL: https://www.privacyguides.org/news/2026/02/19/googles-project-toscana-will-upgrade-face-unlock/ Last updated: 2026-02-19T01:48:56.000Z According to [Android Authority](https://www.androidauthority.com/google-project-toscana-3641601/), Google's secret Project Toscana is upgrading the face unlock on future Pixels and even Chromebooks. > Per our source, Google recently tested Project Toscana with UX testers in Mountain View, CA. Our source used Project Toscana on a Pixel phone with a single hole-punch camera cutout and on two Chromebooks with external cameras (of which the circuitry and motherboard were exposed, so not the final design). Reportedly, the unlock feature worked just as quickly as Apple's [Face ID](https://support.apple.com/en-us/108411) and in varying light conditions, suggesting some kind of infrared hardware. Face Unlock on current Pixels just uses the regular camera for unlocking, so it [struggles](https://support.google.com/pixelphone/answer/9517039?hl=en#:~:text=When%20there%20isn’t%20sufficient%20light%20or%20when%20you%20have%20a%20face%20covering%20or%20sunglasses%2C%20Face%20Unlock%20might%20not%20work) in low light conditions. Google previously shipped infrared hardware that would create a 3D representation of your face in the Pixel 4\. This approach is similar to what iOS has with Face ID, and the source of the much-maligned notch. The hardware allows Face ID to work well in low-light conditions and makes it much more secure, since an attacker needs a 3D representation of your face and not just a 2D image in order to fool it. The feature was canned in one generation though, and Pixel 5 and 6 users only had fingerprint unlock. A neutered version of Face Unlock was added back in the Pixel 7, but it could only be used to unlock the device and not for things like confirming payments. In the Pixel 8, Face Unlock could again be used for payments and signing in to apps, but the secure hardware is still lacking. This is the reason GrapheneOS doesn't support Face Unlock: > We don't want to support face unlock without proper hardware support for it. We supported face unlock on the Pixel 4 and Pixel 4 XL where they had dual IR scanners, an IR dot projector and an IR flood illuminator included above the screen. None of the other Pixels has that. > > — GrapheneOS (@GrapheneOS) [May 12, 2025](https://twitter.com/GrapheneOS/status/1922061711311274395?ref%5Fsrc=twsrc%5Etfw) Android Authority had [reported](https://www.androidauthority.com/google-pixel-11-face-unlock-3494465/) on a previous leak from Google's chips division indicating that they were considering adding the secure hardware back under the display this time, avoiding the ugly notch. Apple is possibly adding under-display Face ID in the iPhone 18, according to a [leak](https://9to5mac.com/2025/12/08/iphone-18-leak-says-face-id-moving-under-display-next-year/) utilizing "micro-transparent glass panels." To give an idea of how much more secure Face Unlock with proper hardware could be, Apple puts the chances of a random person being able to unlock Face ID at [1 in 1,000,000](https://support.apple.com/en-us/102381#:~:text=The%20probability%20that%20a%20random%20person%20in%20the%20population%20could%20look%20at%20your%20iPhone%20or%20iPad%20Pro%20and%20unlock%20it%20using%20Face%20ID%20is%20less%20than%201%20in%201%2C000%2C000), while they estimate Touch ID at 1 in [50,000](https://support.apple.com/en-us/105095#:~:text=Every%20fingerprint%20is%20unique%2C%20so%20it’s%20rare%20that%20even%20a%20small%20section%20of%20two%20separate%20fingerprints%20are%20alike%20enough%20to%20register%20as%20a%20match%20for%20Touch%20ID.%20The%20probability%20of%20this%20happening%20is%201%20in%2050%2C000). Android's [biometric security guidelines](https://source.android.com/docs/security/features/biometric/measure) define the highest Class 3 security level for face unlock to allow for the same 1 in 50,000 failure rate. Android Authority says it's likely we'll see the new hardware in the upcoming Pixel 11 pegged for release this August. As for the Chromebooks, it seems bizarre that Google would be adding such a big upgrade to an operating system they plan to [discontinue](https://www.wired.com/story/google-aluminium-os-chromebook-successor-is-coming/), but perhaps the feature will crop up in the new Aluminium OS machines when they release. ### Why Incognito Mode is a Lie. URL: https://www.privacyguides.org/videos/2026/02/17/why-incognito-mode-is-a-lie/ Last updated: 2026-02-17T20:30:34.000Z Incognito Mode or Private Browsing mode is a feature that every browser has, but what if that was a lie and your activity in private mode could still be tracked? In this video we break down the issues with private browsing mode and what you can do instead to get true privacy! #### Sources 0:02 1:00 1:09 1:55 2:18 2:32 3:03 3:48 3:59 4:42 4:53 5:53 6:34 6:55 7:14 ### Amazon Cancels Ring Partnership with Flock URL: https://www.privacyguides.org/news/2026/02/17/amazon-cancels-ring-partnership-with-flock/ Last updated: 2026-02-17T20:28:30.000Z Amazon has [announced](https://blog.ring.com/about-ring/ring-and-flock-cancel-partnership/) it has cancelled its previous plans to partner with Flock for its [Community Requests](https://ring.com/support/articles/uds27/Community-request) feature. The announcement comes amid backlash for Amazon’s [Search Party for Dogs](https://blog.ring.com/pets/how-search-party-for-dogs-is-reuniting-pets-with-their-owners/) feature that “alerts nearby participating outdoor Ring cameras to help look for your lost dog.” Amazon played an ad for it during the [Super Bowl](https://www.youtube.com/watch?v=OheUzrXsKrY), prompting the widespread privacy concerns. Their [announced](https://www.flocksafety.com/blog/flock-safety-and-ring-partner-to-help-neighborhoods-work-together-for-safer-communities) Flock partnership wasn’t related to Search Party, however. The Community Requests feature that allows police to send out requests to Ring owners so they can voluntarily send videos to the police. Amazon says that the sharing is completely optional and Ring users are in full control over their data being shared: > You have complete control over whether to respond to a Community Request and what you share. Every Community Request is publicly posted and searchable for complete transparency and auditability. While it’s great that the sharing is optional for users, everyone that the camera is pointed at didn’t consent to be filmed and have footage of them sent to law enforcement. It’s worth noting that, while Ring supports *optional* [end-to-end encryption](https://ring.com/support/articles/7e3lk/using-video-end-to-end-encryption-e2ee), non-encrypted data could be accessed by Ring itself and end up in the hands of law enforcement or attackers that manage to infiltrate Ring’s infrastructure. Ring state that they won’t give out user data unless [required](https://ring.com/support/articles/oi8t6/Learn-About-Ring-Law-Enforcement-Guidelines#:~:text=Ring%20does%20not%20disclose%20user%20information%20in%20response%20to%20government%20demands%20%28i.e.%2C%20legally%20valid%20and%20binding%20requests%20for%20information%20from%20law%20enforcement%20agencies%20such%20as%20search%20warrants%2C%20subpoenas%20and%20court%20orders%29%20unless%20we're%20required%20to%20comply%20and%20it%20is%20properly%20served%20on%20us.) by law: > Ring does not disclose user information in response to government demands (i.e., legally valid and binding requests for information from law enforcement agencies such as search warrants, subpoenas and court orders) unless we're required to comply and it is properly served on us. Ring’s stated reason for cancelling the partnership has nothing to do with the privacy backlash, though. They claim the partnership “would require significantly more time and resources than anticipated.” According to them, “no Ring customer videos were ever sent to Flock Safety.“ With massive [security](https://www.youtube.com/watch?v=uB0gr7Fh6lY) flaws found in Flock Safety cameras allowing attackers to completely take them over and massive [abuses](https://www.eff.org/deeplinks/2025/12/effs-investigations-expose-flock-safetys-surveillance-abuses-2025-review?language=en) caused by the company, you have to wonder why Amazon even wanted to partner with such an incompetent operation. Despite announcing a cancellation, Ring still holds that the massive surveillance apparatus they’ve enabled is a good thing. > When a shooting occurred near Brown University in December 2025, every second mattered. The Providence Police Department turned to their community for help, putting out a Community Request. Within hours, 7 neighbors responded, sharing 168 videos that captured critical moments from the incident. One video identified a new key witness, helping lead police to identify the suspect's vehicle and solve the case. With a shooter at large, the community faced uncertainty about their safety. Neighbors who chose to share footage played a crucial role in neutralizing the threat and restoring safety to their community. Despite the cancelled partnership with Flock, Ring’s original [Community Requests](https://blog.ring.com/about-ring/ring-launches-community-requests-a-new-way-to-help-your-community/) feature still exists via their partnership with [Axon](https://www.axon.com), a similar company to Flock that provides surveillance tech to police. ### Discord's Global Mandatory Age Verification, Nest Keeps Footage Even If You Don't Pay, Ring Gets Too Creepy For Everyone, and More! URL: https://www.privacyguides.org/livestreams/2026/02/13/discords-global-mandatory-age-verification-nest-keeps-footage-even-if-you-dont-pay-ring-gets-too-creepy-for-everyone-and-more/ Last updated: 2026-02-23T23:36:19.000Z This Week in Privacy #40 _This post is for subscribers only._ ### Data Breach Roundup (Feb 6 – Feb 12, 2026) URL: https://www.privacyguides.org/news/2026/02/13/data-breach-roundup-feb-6-feb-12-2026/ Last updated: 2026-04-03T18:27:47.000Z ## Flickr discloses potential data breach exposing users' names, emails Photo-sharing app Flickr is reporting a possible data breach after a vulnerability was found in a third-party email service provider. The incident impacts real names, email addresses, IP addresses, and account activity. There are virtually no other details at this time. [Flickr discloses potential data breach exposing users’ names, emailsPhoto-sharing platform Flickr is notifying users of a potential data breach after a vulnerability at a third-party email service provider exposed their real names, email addresses, IP addresses, and account activity.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-51.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Flickr.jpg)](https://www.bleepingcomputer.com/news/security/flickr-discloses-potential-data-breach-exposing-users-names-emails/) ## European Commission discloses breach that exposed staff data This was made possibly when their mobile device management (MDM) platform was hacked. The EC says there's no evidence devices themselves were compromised but names, business email addresses, and phone numbers were impacted. The article notes that the Finnish Ministry of Finance also reported a breach of up to 50,000 users that appears to be possibly be related. [European Commission discloses breach that exposed staff dataThe European Commission is investigating a breach after finding evidence that its mobile device management platform was hacked.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-52.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/European_Union.jpg)](https://www.bleepingcomputer.com/news/security/european-commission-discloses-breach-that-exposed-staff-data/) ## Hacktivist scrapes over 500,000 stalkerware customers’ payment records It appears this all came from the same vendor, called Struktura, but in turn impacted several apps. It exposed email addresses and partial payment information, though TechCrunch was able to call up invoices in some cases. [Exclusive: Hacktivist scrapes over 500,000 stalkerware customers’ payment recordsMore than half-a-million people who bought access to phone surveillance and social media snooping apps had their email address and partial payment card numbers published online.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-31.png)TechCrunchZack Whittaker, Lorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-1128003505.jpg)](https://techcrunch.com/2026/02/09/hacktivist-scrapes-over-500000-stalkerware-customers-payment-records/) ## The Sumsub Incident and the Future of Cloud Compliance Sumsub is a third-party European KYC vendor who does identity verification for banks, crypto, gambling, and other similar services. According to this post, the initial breach happened mid-2024 but was only just detected this year. While IDs are safe, they did still expose names, email address, and phone numbers for an unspecified "subset of accounts." Thanks to the [forum](https://discuss.privacyguides.net/) user who shared this, or else it wouldn't have ended up in my feed. [The Sumsub Incident and the Future of Cloud Compliance - Fincrime CentralThe Sumsub security incident demonstrates the inherent data breach risk when using third party cloud providers for identity verification and transaction monitoring services.![](https://www.privacyguides.org/content/images/icon/FinCrime-Shield-favicon.png)Fincrime Centraladmin![](https://www.privacyguides.org/content/images/thumbnail/sumsub-cloud-cybersecurity-vulnerability-aml-vendors.avif)](https://fincrimecentral.com/sumsub-incident-cloud-aml-risk-management/) ## Odido data breach exposes personal info of 6.2 million customers Odido is one of the largest telcos and ISPs in the Netherlands, at one point falling under the T-Mobile umbrella but now no longer affiliated (as far as I can tell). The breach impacted full name, address, mobile number, customer number, email address, IBAN, date of birth, and ID data (such as passport or driver's license number). [Odido data breach exposes personal info of 6.2 million customersDutch telecommunications provider Odido is warning that it suffered a cyberattack that reportedly exposed the personal data of 6.2 million customers.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-53.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/odido.jpg)](https://www.bleepingcomputer.com/news/security/odido-data-breach-exposes-personal-info-of-62-million-customers/) ## Romania's oil pipeline operator Conpet confirms data stolen in attack This article was light on specifics, but said that the Qilin ransomware gang claims to have nearly 1TB of Conpet's internal documents, and proved it by providing - among other things - passport scans and "financial information." We'll post updates if we hear any. [Romania’s oil pipeline operator Conpet confirms data stolen in attackRomania’s national oil pipeline operator, Conpet S.A., confirmed that the Qilin ransomware gang stole company data in an attack last week.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-54.png)BleepingComputerIonut Ilascu![](https://www.privacyguides.org/content/images/thumbnail/Conpet.jpg)](https://www.bleepingcomputer.com/news/security/romanias-oil-pipeline-operator-conpet-confirms-data-stolen-in-attack/) ### Microsoft Considers Scaling Back on Consumer-Facing AI URL: https://www.privacyguides.org/news/2026/02/07/microsoft-considers-scaling-back-on-consumer-facing-ai/ Last updated: 2026-02-07T06:37:54.000Z Microsoft's aggressive and controversial AI products may soon be reigned in to be less obnoxious, or potentially gone away with entirely in some cases. That's according to unnamed sources who spoke to [Windows Central](https://www.windowscentral.com/microsoft/windows-11/microsoft-is-reevaluating-its-ai-efforts-on-windows-11-plans-to-reduce-copilot-integrations-and-evolve-recall). For the last several years, Microsoft has been aggressively forcing AI into literally [almost everything](https://www.windowscentral.com/software-apps/windows-11/microsoft-integrates-notepad-with-copilot-on-windows-11) they can. This has prompted immense backlash from users for a variety of reasons, including "what possible use could AI have in this product?" to "this is a literal [dystopian nightmare](https://en.wikipedia.org/wiki/Windows%5FRecall), who greenlit this?" At some points the backlash has been so bad that Microsoft has been forced to delay products to rework them (like Recall) but still eventually forced them on users. Now it seems that Microsoft may finally be listening to users for a change. Maybe. Windows Central is light on details, but it seems that Microsoft is completely rethinking basically every AI product they're currently integrating into Windows. It's unclear which products - if any - Microsoft intends to completely roll back, but the wording of the article suggests that it's not off the table with at least some of them. At very least, Microsoft seems intent on reworking the products to make them a smoother experience and more useful. For example, Microsoft is currently "reviewing" the Copilot integrations in Notepad and Paint and may remove them entirely, while Recall is expected to "evolve" rather than be entirely discarded. At this point, any pulling back of the AI features in Windows would be welcome, though it would be preferrable to have them be entirely optional in the first place. ### RAM Shortages Impact Raspberry Pi URL: https://www.privacyguides.org/news/2026/02/07/ram-shortages-impact-raspberry-pi/ Last updated: 2026-02-07T01:37:08.000Z Due to the current global [RAM shortage](https://www.privacyguides.org/posts/2025/12/16/what-can-we-do-about-the-ram-and-shortage/), Raspberry Pi prices will go up. Prices will be correlated with how much RAM is in the model. For example, board with 2GB of RAM will go up $10 while 16GB boards will cost an extra $60\. For devices that are notoriously less than $100, this is a huge deal. The 16GB Pi 5 now costs over $200, according to [Ars Technica](https://arstechnica.com/gadgets/2026/02/ongoing-ram-crisis-prompts-raspberry-pis-second-price-hike-in-two-months/). Because of the historically low cost and small form factor, Raspberry Pis have been immensely popular in the privacy community for a wide range of self-hosted tasks. They're popular for running single-instance Mastodon or Nextcloud servers, home DNS resolvers, and more. Your truly has used them to run Matrix moderation bots, a website to invite friends and family to a Eurovision viewing party, and more. Sadly, like many aspects of life, this price hike will disproportionately affect people on a tight budget, making privacy and data sovereignty even more of a privilege than it already is in many cases. ### Firefox's "AI Killswitch" Coming February 24 URL: https://www.privacyguides.org/news/2026/02/06/firefoxs-ai-killswitch-coming-february-24/ Last updated: 2026-02-06T22:36:33.000Z Firefox's much anticipated "AI Killswitch" is set to [release](https://blog.mozilla.org/en/firefox/ai-controls/) in Firefox 148, expected to ship in just a few weeks on February 24. Mozilla has been pretty universally regarded as a headache for some time, even by their most ardent fans. Nearly all popular browsers are based on Google's [Blink](https://en.wikipedia.org/wiki/Blink%5F%28browser%5Fengine%29) web engine that powers Chromium. Any browser based on Chromium - including Brave, Vivaldi, Opera, and even Edge - is ultimately dependent on Google this way. As such, many people want to see Mozilla's Firefox (based on the [Gecko](https://en.wikipedia.org/wiki/Gecko%5F%28software%29) engine) succeed as a healthy competitor and alternative to Google's "Chromium monopoly." Unfortunately, Mozilla has been consistently and catastrophically bungling this mission for years. Firefox's development has languished, falling behind competitors dramatically in terms of security and end-user facing "quality of life" features such as vertical tabs, HDR support, and improved sandboxing. Meanwhile, the company invested in a variety of unrelated and often controversial ventures such as fake-review-spotting app [Fakespot](https://techcrunch.com/2023/05/02/mozilla-buys-fakespot-identifies-fake-reviews-shopping-tools-firefox/) and analytics company [Anonym](https://www.osnews.com/story/140047/mozilla-acquires-ad-analytics-company-for-some-reason/). Most recently, Mozilla has been aggressively attempting to expand into the AI space. They've integrated AI features into Firefox, such as the [Perplexity](https://blog.mozilla.org/en/firefox/firefox-144/) search engine or the ability to talk to [chatbots](https://support.mozilla.org/kb/ai-chatbot) directly from the sidebar. It's worth noting that absolutely none of these tools come with any privacy improvements from Mozilla. They're provided strictly as a convenience feature - a way to quickly and easily access them. Mozilla explicitly warns users that you're at the mercy of the provider's privacy policy should you interact with them. Because AI in general remains unpopular (probably in addition to all the above context), Mozilla's constant push into AI has resulted in massive pushback from both supporters and critics alike. For a brief period last year it looked like Mozilla might find their way back after a CEO swap and a few [small](https://blog.mozilla.org/en/firefox/fingerprinting-protections/) [improvements](https://blog.mozilla.org/en/firefox/dns-android/) to Firefox, but late last year the new CEO [confirmed](https://blog.mozilla.org/en/mozilla/leadership/mozillas-next-chapter-anthony-enzor-demeo-new-ceo/) that in 2026, we could expect more of the same. Thankfully, he also confirmed one glimmer of hope: an "[AI Killswitch](https://futurism.com/artificial-intelligence/outcry-firefox-promises-kill-switch-ai-features)" to quickly and easily disable all the AI features that are now being included in Firefox. Users haven't had to wait long: the announcement came in late December and we now know it should arrive in late February. It is the hope of all of us at Privacy Guides that Mozilla will continue to invest in Firefox's development apart from AI and return to creating a competitive, fully FOSS browser. ### Apple’s Lockdown Mode Blocked the FBI? URL: https://www.privacyguides.org/livestreams/2026/02/06/apples-lockdown-mode-blocked-the-fbi/ Last updated: 2026-02-16T23:17:33.000Z This Week in Privacy #39 _This post is for subscribers only._ ### Data Breach Roundup (Jan 30 – Feb 5, 2026) URL: https://www.privacyguides.org/news/2026/02/06/data-breach-roundup-jan-30-feb-5-2026/ Last updated: 2026-04-03T18:27:35.000Z ## NationStates confirms data breach, shuts down game site NationStates is a mulitplayer in-browser government simulation game. In late January the developers received a report from a player who claimed to have found a vulnerability, but also accessed user data in the process. The player has a history of reporting vulnerabilities like these and promises that any user data downloaded was deleted, but out of caution the devs are treating this like a breach. The exposed data included email address (including past email addresses), IP address, browser UserAgent strings, passwords stored in MD5, and DMs. [NationStates confirms data breach, shuts down game siteNationStates, a multiplayer browser-based game, has confirmed a data breach after taking its website offline earlier this week to investigate a security incident.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-43.png)BleepingComputerAx Sharma![](https://www.privacyguides.org/content/images/thumbnail/nationstates-16x9-jpg.jpg)](https://www.bleepingcomputer.com/news/security/nationstates-confirms-data-breach-shuts-down-game-site/) ## Panera Bread breach impacts 5.1 million accounts, not 14 million customers Late last month, it was reported that American fast-food chain Panera Bread had suffered a data breach of 14 million customers. It's now been clarified that it was 14 million records, or just over 5 million customers. The data includes email address, name, phone number, and physical address and likely impacts employees as well as customers. Panera Bread has yet to make a formal statement or notify customers. [Panera Bread breach impacts 5.1 million accounts, not 14 million customersThe data breach notification service Have I Been Pwned says that a data breach at the U.S. food chain Panera Bread affected 5.1 million accounts, not 14 million customers as previously reported.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-44.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Panera-Bread.jpg)](https://www.bleepingcomputer.com/news/security/panera-bread-data-breach-impacts-51-million-accounts-not-14-million-customers/) ## Wedding Photo Booth Company Exposes Customers’ Drunken Photos Curator Live - who offers photo booths for weddings, engagement parties, and lobbying events in D.C. - has exposed photos, which include phone numbers. The researcher says they found at least 100 GB of photos and some include children. [Wedding Photo Booth Company Exposes Customers’ Drunken Photos‘Curator Live’, a popular photo booth company for weddings and other events, is exposing all sorts of unsuspecting people’s photos.![](https://www.privacyguides.org/content/images/icon/favicon-3-9.svg)404 MediaJoseph Cox![](https://www.privacyguides.org/content/images/thumbnail/barry-wong-I6RrgO54M5c-unsplash.jpg)](https://www.404media.co/wedding-photo-booth-company-exposes-customers-drunken-photos/) ## Coinbase confirms insider breach linked to leaked support tool screenshots A contractor at Coinbase "improperly accessed" the data of about 30 customers. Coinbase has let him go and notified the impacted customers. Insider threats like this are a reminder why we support zero-knowledge services. [Coinbase confirms insider breach linked to leaked support tool screenshotsCoinbase has confirmed an insider breach after a contractor improperly accessed the data of approximately thirty customers, which BleepingComputer has learned is a new incident that occurred in December.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-46.png)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/coinbase-header.jpg)](https://www.bleepingcomputer.com/news/security/coinbase-confirms-insider-breach-linked-to-leaked-support-tool-screenshots/) ## Newsletter platform Substack notifies users of data breach Discovered just this week, the breach occurred in October 2025 and impacted email addresses and phone numbers. It's unclear how many users were impacted but a BreachForum post contains just shy of 700,000 records. The attacker says the method they used was "patched fast." [Newsletter platform Substack notifies users of data breachNewsletter platform Substack is notifying users of a data breach after attackers stole their email addresses and phone numbers in October 2025.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-48.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Substack.jpg)](https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/) ## Data breach at govtech giant Conduent balloons, affecting millions more Americans This breach occurred in 2024 and was disclosed in October, said to originally affect roughly 10 million people. We now know it affects over 35 million. Stolen data includes names, Social Security numbers, medical data, and health insurance information. [Data breach at govtech giant Conduent balloons, affecting millions more Americans | TechCrunchThe ransomware attack at Conduent allowed hackers to steal a “significant number of individuals’ personal information” from the govtech giant’s systems. Conduent handles personal and health data of more than 100 million people across America.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-30.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/data-breach-2024-roundup.jpg)](https://techcrunch.com/2026/02/05/data-breach-at-govtech-giant-conduent-balloons-affecting-millions-more-americans/) ## Data breach at fintech firm Betterment exposes 1.4 million accounts We covered this story last month. Betterment is an "automated investing platform." Betterment still hasn't confirmed how many accounts were impacted, but Have I Been Pwned said the data of over 1.4 million accounts (including email address, names, and geographic location data) were compromised. This confirms Betterment's statement that primarily name and email address were impacted, as well as physical address, phone number, or birthdate "in some cases." [Data breach at fintech firm Betterment exposes 1.4 million accountsHackers stole email addresses and other personal information from 1.4 million accounts after breaching the systems of automated investment platform Betterment in January.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-47.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Betterment.jpg)](https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-betterment-exposes-14-million-accounts/) ### Smartphone Security Course (Lesson 1: Beginners) URL: https://www.privacyguides.org/videos/2026/02/04/smartphone-security-course-lesson-1-beginners-2/ Last updated: 2026-02-16T23:15:59.000Z ## Course Introduction For many people, smartphones are some of the most intimate peeks into our lives. They contain our messages, photos, schedules, catalogues of interests, financial information, and more. Therefore, we should treat our phones with the gravity they deserve by making them as private and secure as possible. In this three-part course, we walk users through the steps they can take to make their phones as private and secure as possible. Part 1 begins with the easiest, user-friendliest steps such as removing the apps you rarely or never use, swapping out the ones you can with PWAs, and changing default settings to make your phone less “leaky.” ## Lesson 1 (Android) #### Sources 0:06 0:13 0:34 1:11 3:48 4:36 ## Lesson 1 (iPhone) #### Sources 0:06 0:13 0:29 0:43 2:31 2:44 3:36 4:16 4:34 5:18 5:21 6:27 💡 ****Part 2 is coming very soon!** Subscribe to our channel on [YouTube](https://www.youtube.com/channel/UC8q5BGkSzK6Kafk%5F6gKV8HA/) or sign up for [email notifications](#/portal) here to find out when it's released. ### Notepad++ Subject to Supply Chain Attack for Months URL: https://www.privacyguides.org/news/2026/02/03/notepad-subject-to-supply-chain-attack-for-months/ Last updated: 2026-02-03T00:42:21.000Z The popular text editor Notepad++ had their infrastructure compromised from about June 2025 to December 2025, allowing the attackers to deliver malicious updates to unsuspecting users. In their [statement](https://notepad-plus-plus.org/news/hijacked-incident-info-update/), the Notepad++ team states that the vulnerability was in the infrastructure and not in Notepad++ itself. The exact mechanism is under investigation still. Notepad++ did not provide any indicators of compromise to look out for to determine if you might be affected. They recommend downloading the latest version of the program and manually running the installer to update it. However, earlier today cybersecurity company Rapid7 did release a [list of indicators of compromise](https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/) for teams to check out. Notepad++ is addressing the issues by migrating to a more secure hosting provider. WinGUP, the updater, has been hardened to verify the certificate and the signature of the downloaded installer. They also are now signing the XML returned by the update server using [XMLDSig](https://www.w3.org/TR/xmldsig-core/) and the certificate and signature verification will be enforced in a future update. Security researcher [Kevin Beaumont](https://doublepulsar.com/small-numbers-of-notepad-users-reporting-security-woes-371d7a3fd2d9) did a write up about a possible avenue of exploitation regarding WinGUP: > The downloads themselves are signed — however some earlier versions of Notepad++ used a self signed root cert, which is on Github. With 8.8.7, the prior release, this was reverted to GlobalSign. Effectively, there’s a situation where the download isn’t robustly checked for tampering. In version 8.8.8, the downloads are forced to be from GitHub which is much harder to intercept. Kevin notes the presence of an AutoUpdate.exe, which isn’t part of the legit Notepad++. According to an analysis by [Rapid7](https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/), the attack was likely carried out by a Chinese advanced persistent threat (APT) called Lotus Blossom that’s been active since 2009. The attackers delivered a previously unseen custom backdoor that Rapid7 have dubbed Chrysalis. They note that there’s no indication that the actual notepad++.exe and GUP.exe were compromised, but they coincided with the execution of a suspicious “update.exe” file downloaded from 95.179.213.0. ![](https://www.privacyguides.org/content/images/2026/02/image.png) Execution of update.exe. Credit: [Rapid7](https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/) The exe file was actually a NSIS installer, which is commonly used by Chinese APT’s to deliver the initial payload. When the script runs, it creates a new directory called “Bluetooth” in the “%AppData%” folder where the rest of the files will go. It drops and executes BluetoothServices.exe, which is actually just a renamed legitimate Bitdefender Submission Wizard that’s abused to sideload [DLLs](https://learn.microsoft.com/en-us/troubleshoot/windows-client/setup-upgrade-and-drivers/dynamic-link-library). From there, the malicious log.dll is loaded instead of the legitimate library. The malware utilized [Warbird](https://downwithup.github.io/blog/post/2023/04/23/post9.html), an undocumented Microsoft code-obfuscation framework that they designed to make reverse-engineering their DRM more difficult. This incident shows how even programs assumed trustworthy and innocuous like a text editor are just as likely to be exploited as any other program. The lack of sandboxing on desktop operating systems also leaves a lot to be desired compared to mobile operating systems like Android and iOS. Sandboxing features exist on [macOS](https://developer.apple.com/documentation/xcode/configuring-the-macos-app-sandbox) and Linux via [Flatpak](https://flatpak.org). Windows has [win32 App Isolation](https://learn.microsoft.com/en-us/windows/win32/secauthz/app-isolation-overview) coming in the future. Developers should make use of the hardening features provided by the operating system as much as possible. Every operating system these days also provides an App Store that provides a trusted distribution and update mechanism for apps. It would be nice to see more apps distributed via the macOS [App Store](https://www.apple.com/app-store/), [Microsoft Store](https://apps.microsoft.com/home?hl=en-US&gl=US), and [Flathub](https://flathub.org/en) rather than developers trying to have their own individual auto update mechanism for each app. Remember that every app can be a vector for attack, be extra vigilant. ### Google Introduces Stronger Theft Protections in Android URL: https://www.privacyguides.org/news/2026/01/31/google-introduces-stronger-theft-protections-in-android/ Last updated: 2026-01-31T14:14:55.000Z Google [announced](https://security.googleblog.com/2026/01/android-theft-protection-feature-updates.html) that they're bolstering Android's pre-existing theft protection features with security improvements and more granular control. In Android 15, failed [authentication lock](https://support.google.com/android/answer/15146908?hl=en#zippy=%2Cturn-on-failed-authentication-lock) was added which locks the screen after too many failed attempts at authentication, such as your phone's password prompt. Now you'll be able to toggle this feature on and off. [Identity Check](https://security.googleblog.com/2025/01/android-theft-protection-identity-check-expanded-features.html) prevents you from performing certain sensitive actions without authenticating with biometrics first, ensuring a thief can't simply watch you type your password in and then steal your phone and take over your accounts and data. The feature now covers all actions that use the Biometric Prompt, so your third-party banking apps that use the native biometric authentication will be protected. With this safeguard, PIN or password can't be used as a substitute for biometrics. You can set a [Trusted place](https://support.google.com/android/answer/15706581) where the protection won't be enabled for convenience. Google is also increasing the lockout time after failed attempts so thieves can't brute force weak passwords as easily. At the same time, identical guesses won't count toward your retry attempts anymore, so if a child or an annoying friend tries to lock you out it's less likely to happen. [Remote Lock](https://www.google.com/android/find/lock) allows you to lock your device remotely from any browser with just your phone number, crucial after a theft since every second the phone remains unlocked is time they have access to your data. Google is adding an optional security question to this feature so only you are able to remotely lock your device. Defaults are important, so Google is now enabling [Theft Detection Lock](https://support.google.com/android/answer/15146908?hl=en#zippy=%2Cturn-on-theft-detection-lock), a feature that uses AI and the sensors in the phone to detect when it thinks a thief has stolen it out of your hands and locks the scree, and Remote Lock by default in Brazil. Hopefully more countries get these features on by default because they're genuinely really useful. These changes join the previous suite of anti-theft features released all the way back in [2024](https://blog.google/products-and-platforms/platforms/android/android-theft-protection/). [Factory reset protection](https://support.google.com/android/answer/9459346?hl=en-GB) stops others from being able to use your device if they erase it and try to set it up as their own. [Private Space](https://support.google.com/android/answer/15341885?hl=en) lets you set up a separate area to store sensitive apps and data with its own separate PIN from your main authentication method, in case your phone is stolen and the thief knows your phone's PIN. [Offline Device Lock](https://support.google.com/android/answer/15146908?hl=en#zippy=%2Cturn-on-offline-device-lock) locks your device shorty after it goes offline, something a thief may do to try and stop Find My Device from locating it or letting your lock it via Remote Lock. I wish Apple would copy some of these for iOS, they have [some](https://support.apple.com/en-us/120340) of the same features but not full feature parity with Android here. The [Advanced Protection](https://support.google.com/android/answer/16339980?hl=en) setting in Android enables a lot of great security protections including some of the anti-theft ones. There's a few features that I feel should be part of the theft protection umbrella though and not locked behind Advanced Protection. For example, Inactivity Reboot, which automatically restarts your device after 72 hours without being unlocked. When your phone reboots, it enters a more secure mode called "[before first unlock](https://www.msab.com/glossary/bfu-before-first-unlock/)" where the passcode hasn't been entered, so the encrypted data is "[at rest](https://phoenixnap.com/blog/encryption-at-rest)" and can't be accessed without the passcode. This auto reboot timer not only preserves battery which helps with Find My Device, but it also helps keep anyone with physical access to your phone from exploiting it as easily to get the data on it. [USB Protection](https://support.google.com/android/answer/16778864) is another setting locked to Advanced Protection that disables USB access when the device is locked. Again, this would be very useful against thieves who might try to extract data from the phone. Overall, it's good to see Google making improvements against one of the most common threats people face, although I'd still like to see a few improvements. ### A Message Regarding ICE in Minnesota and the USA from Privacy Guides' Program Director Jonah Aragon URL: https://www.privacyguides.org/press-releases/2026/01/31/a-message-regarding-ice-in-minnesota-and-the-usa-from-privacy-guides-program-director-jonah-aragon/ Last updated: 2026-01-31T04:59:29.000Z [A Message from Privacy Guides’ Program Director​@jonaharagon the Privacy Guides Program Director has a message for the community.Clipped from: https://youtube.com/live/Hpgn3xrKmWcPlease 👍 like and 🔔 su…![](https://www.privacyguides.org/content/images/icon/favicon_144x144-1.png)YouTube![](https://www.privacyguides.org/content/images/thumbnail/maxresdefault.jpg)](https://www.youtube.com/watch?v=BQ5%5F4Li9Gsc) This message was delivered in *This Week in Privacy* [Episode 38](https://www.privacyguides.org/livestreams/2026/01/30/whatsapp-may-not-be-safe-tiktoks-new-owners-france-and-uk-ban-minors-from-online-services-and-more/). ## Transcript I want to deliver a brief message as the program director at *Privacy Guides* about the current state of the United States of America. As a Minnesotan, and resident of the City of Minneapolis myself, this is a very important issue to me. We are only one month into 2026, and already this year, ICE agents of the federal government of the United States are responsible for the extrajudicial killings of two American citizens, right here in my city, for exercising their Constitutional rights. This happened as part of a larger ICE campaign to terrorize my neighbors and this country, a campaign I know many Minnesotans protested in force last week, and which I know many American patriots are protesting today. Our mission has always been to support the right to privacy for all people regardless of political views or the country people live in. It’s also our mission to speak out against government overreach, particularly when it comes to surveillance, and especially when government agencies are being pitted against the very taxpayers and citizens they are meant to protect and serve. Here in the United States, that’s meant recently speaking out against the Democrats who aim to increase surveillance and censorship through bills like KOSA or the planned repeals of Section 230, and now against Republicans in our government who are weaponizing the state surveillance systems and law enforcement bodies like ICE to target their perceived political enemies and immigrant members of our communities, without respect to their legal residency status or due process. This weaponization of ICE by the Trump administration is not happening in a vacuum. It is fueled by the very surveillance data and lack of digital boundaries we have been fighting against for years. Laws enacted within my lifetime, like the PATRIOT Act, and loopholes like the continued lack of regulations against commercial data brokers, which allow the government to bypass the 4th Amendment by purchasing our own GPS and social media data from tech companies to map our neighborhoods for raids. Minneapolis has become the testing ground for invasive and inaccurate facial recognition apps like Mobile Fortify, where AI glitches can lead to unlawful detentions of innocent people, and the sort of state-sponsored violence that took the lives of Renee Nicole Good and Alex Pretti. In times of overreach, our greatest defense is our community and our refusal to be intimidated into silence. I’ve seen how powerful this can be firsthand. The reality is that how ICE is operating within our borders is unjustifiable. We recognize the significance of this unprecedented situation, and we stand alongside everyone protesting in support of the protection of our neighbors and for American rights, which is something that all Americans should support. --- [Privacy Guides](https://www.privacyguides.org/) is an impartial organization that is focused on building a strong privacy advocacy community and delivering the best digital privacy and consumer technology rights advice on the internet. Its mission is to inform the public about the value of digital privacy, consumer tech rights, and about global government initiatives which aim to monitor your online activity. Privacy Guides resources are free of advertisements and not affiliated with any of the recommended providers. Privacy Guides ([**www.privacyguides.org**](https://www.privacyguides.org/)) is built by volunteers and staff members around the world. For information about Privacy Guides or this announcement, contact Jonah Aragon at [jonah@privacyguides.org](mailto:jonah@privacyguides.org). **Media Contact:** [press@privacyguides.org](mailto:press@privacyguides.org) ### WhatsApp May Not Be Safe, TikTok's New Owners, France and UK Ban Minors From Online Services, and more! URL: https://www.privacyguides.org/livestreams/2026/01/30/whatsapp-may-not-be-safe-tiktoks-new-owners-france-and-uk-ban-minors-from-online-services-and-more/ Last updated: 2026-01-31T16:42:32.000Z This Week in Privacy #38 _This post is for subscribers only._ ### Apple Acquires Q.ai Startup for "Silent" Voice Input URL: https://www.privacyguides.org/news/2026/01/30/apple-acquires-q-ai-startup-for-silent-voice-input/ Last updated: 2026-01-30T17:16:34.000Z In its second biggest acquisition ever, Apple has [acquired](https://www.reuters.com/business/apple-acquires-audio-ai-startup-qai-2026-01-29/) a company called Q.ai that promises to use "facial micromovements" to provide "private answers to silent questions." Q.ai's [website](https://www.q.ai) is quite sparse, however a [patent](https://ppubs.uspto.gov/api/pdf/downloadPdf/12505190?requestToken=eyJzdWIiOiI5ZmUwNDVmNC00NGU5LTRiNWMtOTY5OC01ZDFmMDM4MmNlNGUiLCJ2ZXIiOiJjNjkwYzBlNS1mNzMxLTQxNjMtYTE4ZC02NzBlNmUzZGE1YjEiLCJleHAiOjB9) filed by the company shows what the technology is. ![](https://www.privacyguides.org/content/images/2026/01/Screenshot-2026-01-29-at-6.43.17---PM.png) Essentially, the technology shines infrared light at your face and can determine your speech based on micromovements in your facial muscles. Even if you don't audibly speak, the device can still determine what you say as long as you mouth the words out still. Current digital assistants require you to either audibly speak or type to them in order to use them, but this would allow you to silently speak your input. I think everyone has been frustrated trying to use Siri or something when other people are talking and you get their input instead of yours, or you normally like to use voice-to-text but you can't in a loud public place. I could also imagine this being good for people who live with family or roommates and don't want them to hear what they say, or don't want to disturb others with loud noise. Concerningly, the patent also describes being able to determine your emotional state, although that's not outside of what cameras are already capable of. Apple has rumored projects ranging from a wearable [AI pin](https://9to5mac.com/2026/01/21/apple-is-working-on-an-ai-powered-wearable-pin-report/) to [glasses](https://9to5mac.com/2025/05/22/apple-smart-glasses-release-date/) and [AirPods](https://9to5mac.com/2025/03/09/airpods-with-cameras-what-to-expect/) with cameras (also AI-capable). It's likely that this technology will eventually find its way into those products if they ever launch. The acquisition marks the second largest yet by Apple, behind only their acquisition of [Beats](https://www.zdnet.com/article/confirmed-apple-acquires-beats-for-2-6b-and-400m-in-stock/) in 2014\. Apple still [sells](https://www.apple.com/shop/accessories/all/beats-featured) Beats branded products over a decade later so they clearly like to make the most of their investments. Outside of AI though, this tech seems genuinely useful and solves a problem I think a lot of people have. I know I would use voice-to-text a lot more if I know other people around me wouldn't hear what I'm saying. I might feel a bit weird silently mouthing out words in public though. It's unclear if the processing of this data will happen locally or in the cloud. Apple's Face ID is fully on-device, so it makes sense that this also would be. The CEO of Q.ai, Aviad Maizels, was also the founder of [PrimeSense](https://en.wikipedia.org/wiki/PrimeSense), a company specializing in 3D sensing. The company was acquired by Apple in 2013 and [allegedly](https://www.reuters.com/business/apple-acquires-audio-ai-startup-qai-2026-01-29/#:~:text=The%20PrimeSense%20deal%20eventually%20helped%20Apple%20move%20away%20from%20fingerprint%20sensors%20on%20its%20iPhones%20and%20toward%20facial%20recognition%20technology.) helped Apple move away from Touch ID and develop Face ID. Seeing as Face ID is now the standard on all iPhones, Maizels has a good track record of delivering on their tech. We'll see how it plays out, at least this likely has uses outside of just AI. ### Data Breach Roundup (Jan 23 – Jan 29, 2026) URL: https://www.privacyguides.org/news/2026/01/30/data-breach-roundup-jan-23-jan-29-2026/ Last updated: 2026-01-30T16:10:26.000Z Want to stay informed? Get the data breach roundup delivered straight to your inbox every week! New and current subscribers can now adjust your newsletter settings to get subscribed. [Subscribe to emails ](#/portal) ## 149 Million Usernames and Passwords Exposed by Unsecured Database Credentials were for Gmail, iCloud, TikTok, Facebook, OnlyFans, Binance, multiple countries' government systems, banks, and more. It was unclear who the database belonged to, so researcher Jeremiah Fowler notified the hosting provider, who took it down as a Terms of Service violation. He said he believes the database was due to an infostealer and that it was growing during his attempts to get it taken down, highlighting that perhaps infostealers are starting to become a bigger problem. [149 Million Usernames and Passwords Exposed by Unsecured DatabaseThis “dream wish list for criminals” includes millions of Gmail, Facebook, banking logins, and more. The researcher who discovered it suspects they were collected using infostealing malware.![](https://www.privacyguides.org/content/images/icon/favicon-19.ico)WIREDLily Hay Newman![](https://www.privacyguides.org/content/images/thumbnail/sec-passwords-leak-1300258740.jpg)](https://www.wired.com/story/149-million-stolen-usernames-passwords/) ## App for Quitting Porn Leaked Users' Masturbation Habits An unnamed app for designed to help users abstain from watching porn is leaking the data of over 600,000 users, 100,000 of whom claim to be minors. The data includes age, how often they masturbate, and how viewing porn makes them feel. The developer initially said he would fix the issue quickly, but has since denied that there is any vulnerability. The author notes that the vulnerability exists in Google Firebase, which frequently has these sort of vulnerabilities. They compare it to how Amazon's S3 used to suffer from poor defaults that frequently resulted in data breaches. [App for Quitting Porn Leaked Users’ Masturbation HabitsHundreds of thousands of users told the app intimate details about their sexual urges, which are now exposed.![](https://www.privacyguides.org/content/images/icon/favicon-3-6.svg)404 MediaEmanuel Maiberg![](https://www.privacyguides.org/content/images/thumbnail/photo-1543794215-cbc7905029fa)](https://www.404media.co/app-for-quitting-porn-leaked-users-masturbation-habits/) ## Hackers Say They've Hacked Match Group, Maker of Hinge, OkCupid The attackers were able to get access by using voice phishing on Okta. From there there were able to collect data from other third parties like Doordash, AppsFlyer, and translation services. The stolen data appears to include mostly internal documents but also some users' unique advertising IDs. [Hackers Say They’ve Hacked Match Group, Maker of Hinge, OkCupidMatch Group says it is investigating claims that a mass of internal data was hacked from its popular dating apps.![](https://www.privacyguides.org/content/images/icon/favicon-3-7.svg)404 MediaJoseph Cox![](https://www.privacyguides.org/content/images/thumbnail/photo-1643639779224-03e4cfabc3cd)](https://www.404media.co/match-group-hacked-tinder-okcupid-hinge/) ## Massive AI Chat App Leaked Millions of Users Private Conversations We're living in the golden age of Firebase misconfiguration breaches. "Chat & Ask AI" - an app that claims 50 million users - has had private messages with chatbots exposed. The leaked messages include troubling prompts like how to cook meth, to write a suicide note, or how to hack various apps. The attacker claims he was able to access over 300 million messages from over 25 million users. The data included complete chat history, timestamps of messages, the name users gave to their chatbots, and which model it used (ChatGPT, Claude, Gemini, etc). On the plus side, the company fixed the issue within hours of disclosure. [Massive AI Chat App Leaked Millions of Users Private ConversationsChat & Ask AI, which claims 50 million users, exposed private chats about suicide and making meth.![](https://www.privacyguides.org/content/images/icon/favicon-3-8.svg)404 MediaEmanuel Maiberg![](https://www.privacyguides.org/content/images/thumbnail/photo-1496814795703-e5b242546673)](https://www.404media.co/massive-ai-chat-app-leaked-millions-of-users-private-conversations/) ## An AI Toy Exposed 50,000 Logs of Its Chats With Kids to Anyone With a Gmail Account A researcher found they were able to log into Bondu's public-facing web console using a Google username and could access children's names, birth dates, family member names, "objectives” for the child chosen by a parent, and detailed summaries and transcripts of every previous chat between the child and their Bondu. The company took the portal down "in a matter of minutes" and relaunched it the next day with proper authentication. [An AI Toy Exposed 50,000 Logs of Its Chats With Kids to Anyone With a Gmail AccountAI chat toy company Bondu left its web console almost entirely unprotected. Researchers who accessed it found nearly all the conversations children had with the company’s stuffed animals.![](https://www.privacyguides.org/content/images/icon/favicon-21.ico)WIREDAndy Greenberg![](https://www.privacyguides.org/content/images/thumbnail/012826-AI-toy-children-chat-3.jpg)](https://www.wired.com/story/an-ai-toy-exposed-50000-logs-of-its-chats-with-kids-to-anyone-with-a-gmail-account/) ## Have I Been Pwned: SoundCloud data breach impacts 29.8 million accounts Back in [December](https://www.privacyguides.org/news/2025/12/20/data-breach-roundup-dec-12-dec-18-2025/), we shared that SoundCloud had suffered a data breach but little information was known at the time. Thanks to Have I Been Pwned, we now know that nearly 30 million users had their email addresses, geographic locations, names, usernames, avatars, and profile statistics scraped from the site. [Have I Been Pwned: SoundCloud data breach impacts 29.8 million accountsHackers have stolen the personal and contact information belonging to over 29.8 million SoundCloud user accounts after breaching the audio streaming platform’s systems.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-39.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/soundcloud-1.jpg)](https://www.bleepingcomputer.com/news/security/have-i-been-pwned-soundcloud-data-breach-impacts-298-million-accounts/) ## France fines unemployment agency €5 million over data breach Back in March 2024, France's unemployment agency (France Travail, formerly Pôle Emploi) suffered a data breach that exposed the personal information of job seekers from the past 20 years, including names, dates of birth, national insurance numbers, email and home address, and phone number. Now CNIL (France's data protection office, among other things) has issued a nearly €6 million fine. [France fines unemployment agency €5 million over data breachThe French data protection authority fined the national employment agency €5 million (nearly €6 million) for failing to secure job seekers’ data, which allowed hackers to steal the personal information of 43 million people.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-41.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/French_flag.jpg)](https://www.bleepingcomputer.com/news/security/france-fines-unemployment-agency-5-million-over-data-breach/) ### Snapcraft Store Rife With Crypto Phishing Scams URL: https://www.privacyguides.org/news/2026/01/30/snapcraft-store-rife-with-crypto-phishing-scams/ Last updated: 2026-01-30T11:19:27.000Z A new article from [Linuxiac](https://linuxiac.com/linux-snap-users-warned-as-attackers-push-malware-through-old-trusted-apps/) asserts that Canonical's Snap Store is rife with malicious and scam apps, and the problem seems to be getting even harder to spot. As long-time Linux users know, there's a wealth of ways to install apps on Linux. Some of the more user-friendly methods include app stores like Snapcraft and Flathub. Many of these app stores allow pretty much anyone to upload pretty much anything. This is great for the purposes of free speech and keeping software accessible to everyone, but it can also provide low-friction avenues for bad actors to spread malware. Historically, this has been abused in Snap in a fairly predictable manner: scammers create new accounts and upload malicious versions of well-known software, usually crypto wallets like Exodus, Ledger, or Trust which secretly send copies of your seed phrase and other useful credentials back to the scammers, who then drain your wallet. Now, however, Alan Pope (a former Canonical employee) is claiming that the situation is escalating. Pope claims that attackers are now on the lookout for existing accounts with expired domains. The attackers will the swoop in and register the domains, using it to gain access to the legitimate Snap accounts and modifying the existing software with malicious updates, which they can then easily push to users. This new tactic would make malicious software harder to spot without the tell-tale signs like a suspiciously new and/or unofficial account, and most end users would likely be unaware of the change in ownership. The article says that Snap publishers are advised to enable [two-factor authentication](https://www.privacyguides.org/en/multi-factor-authentication/) and stay on top of their domain registrations. End users are advised to obtain software (specifically crypto wallets) from "official project websites" rather than app stores, which is sound advice for any software but it's worth noting that many projects do publish official Snaps, so this advice isn't a silver bullet. ### WhatsApp Implements Optional "Strict Account Settings" Mode for Increased Security URL: https://www.privacyguides.org/news/2026/01/30/whatsapp-implements-optional-strict-account-settings-mode-for-increased-security/ Last updated: 2026-01-30T03:17:55.000Z WhatsApp has [announced](https://blog.whatsapp.com/whatsapps-latest-privacy-protection-strict-account-settings) a new setting called Strict Account Settings that increases security against sophisticated threats, similar to Apple's [Lockdown Mode](https://support.apple.com/en-us/105120) or Android's [Advanced Protection](https://support.google.com/android/answer/16339980?hl=en) mode. The mode reduces WhatsApp's attack surface by disabling certain features that can be vulnerable to exploitation. The feature is being rolled out gradually, so don't worry if the setting doesn't appear for you yet. The [setting](https://faq.whatsapp.com/1524220618005378/?helpref=faq%5Fcontent&cms%5Fplatform=web) forces two-factor authentication for your account and forces on [security notifications](https://faq.whatsapp.com/1524220618005378/?helpref=faq%5Fcontent&cms%5Fplatform=web) for when a contact's security code changes. [End-to-end encrypted backups](https://faq.whatsapp.com/820124435853543?helpref=faq%5Fcontent) are "encouraged" (whatever that means) for users with this setting enabled. I haven't been able to test it out because the setting isn't available to me so unfortunately I can't testify how that works. Normally, E2EE backups are optional, meaning that Meta has access to your messages if you or one of your contacts decides to do an unencrypted backup. Media and attachments are blocked for unknown senders and link previews are disabled. This is similar to what Apple does in their Messages app when Lockdown Mode is enabled. The "block unknown account messages" setting is also enabled, although it doesn't block *all* unknown messages, just "high volume" ones. You won't be able to receive calls from [unknown numbers](https://faq.whatsapp.com/1238612517047244/?helpref=faq%5Fcontent&cms%5Fplatform=android) either, and your IP address will be [hidden](https://faq.whatsapp.com/2635108359972899/?helpref=faq%5Fcontent&cms%5Fplatform=android) during calls. Information in your profile such as the last time you were online, photo, about section, and links in your profile will be locked to contacts-only as well. And finally, no one will be able to add you to a Group unless they're on your contacts list or they're part of a "pre-established, more-selective list of people." Mostly, the setting is forcing already-existing settings to be enabled, but I view it as a good thing. It could be a stepping-stone toward these being enabled by default sometime in the future. WhatsApp has also been cooking up a [Rust](https://engineering.fb.com/2026/01/27/security/rust-at-scale-security-whatsapp/) version of their wamedia library that strips metadata and checks to make sure media is conformant to the media format it purports to be. ![](https://www.privacyguides.org/content/images/2026/01/Rust-at-scale_inline.jpg.webp) Image source: [Meta](https://engineering.fb.com/2026/01/27/security/rust-at-scale-security-whatsapp/) Previous exploits in WhatsApp such as the [Stagefright](https://www.cisa.gov/news-events/alerts/2015/07/28/stagefright-android-vulnerability) vulnerability from 2015 exploited the OS-provided media parsing. wamedia acts as a filter of sorts to stop malformed and potentially malicious files before they are processed by those potentially vulnerable libraries. The choice to develop it in Rust (in parallel with a C++ version in order to ensure compatibility) is an obvious one when you consider that [memory safety](https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html) vulnerabilities are a very common path of exploitation in software. Rust is a low-level [memory safe](https://cacm.acm.org/practice/memory-safety-for-skeptics/) programming language that excels in areas like systems programming that historically have been the realm of memory-unsafe C. WhatsApp were able to replace 160,000 lines of C++ code with just 90,000 lines of Rust code, with performance and memory usage advantages as well. The WhatsApp team say that they're working on accelerating Rust adoption in WhatsApp in the coming years. Given the many [vulnerabilities](https://cybersecuritynews.com/cisa-whatsapp-0-day-vulnerability/) that WhatsApp faces as one of the most popular messengers in the world, this is a good step I think toward protecting its users from the constant stream of exploits targeting everyday people. I hope to see a full Rust rewrite of WhatsApp at some point, and default-E2EE backups as well. ### Google Settles Eavesdropping Lawsuit URL: https://www.privacyguides.org/news/2026/01/30/google-settles-eavesdropping-lawsuit/ Last updated: 2026-01-30T01:17:24.000Z Google has [agreed](https://www.bbc.com/news/articles/c4g38jv8zzwo) to pay $68m to settle a class-action lawsuit over Google Assistant's privacy practices. Like Apple's Siri, Google's voice assistant is designed to wait passively in the background until it hears the trigger phrase ("Hey Google"), at which point it records whatever is said next and sends it back to Google's servers for processing - and eventually advertising purposes. The lawsuit alleges that Google Assistant would often get triggered by mistake, but that audio would still be collected and used for advertising anyways. Google denied any wrongdoing, but agreed to the terms. Of course, lawyers will take their cut first (expected to be about 1/3 or $22m), then the remainder will be split up among the plaintiffs. In Q3 of 2025 alone, Google made just over [$102bn](https://www.macrotrends.net/stocks/charts/GOOG/alphabet/revenue). If I did my math right (which is always a big "if" with me), that makes this fine .07% of one quarter of Google's revenue. The article notes that Apple faced a similar controversy last year. At *Privacy Guides*, we typically recommend against such virtual assistants - especially in conjunction with voice activation - for this very reason. ### Indian States Consider Requiring ID For Social Media URL: https://www.privacyguides.org/news/2026/01/29/indian-states-consider-requiring-id-for-social-media/ Last updated: 2026-01-29T23:20:40.000Z [India](https://techcrunch.com/2026/01/27/indian-states-weigh-australia-style-ban-on-social-media-for-children/) may be the next country to jump on the "banning social media for minors" bandwagon. The movement has begun in the states of Goa and Andhra Pradesh, who have stated that they are studying Australia's 2024 "Online Safety Amendment (Social Media Minimum Age) Act" and considering implementing something similar in their own regions. Australia's ban came into effect in December. The full effects are still yet to be seen. Meta [shut down](https://www.theguardian.com/australia-news/2026/jan/12/australia-u16-social-media-ban-meta-blocked-half-million-accounts) over half a million Australian teenagers' accounts already, but for some reason platforms like Discord and Roblox are exempt from the law. Since 2024, numerous other countries like Denmark, France, Spain, Indonesia, Malaysia, and the US have considered a similar law to various extents. TechCrunch notes that laws regulating the internet in India are run at the federal level, meaning that Goa and Andhra Pradesh likely cannot institute such changes unilaterally, but one expert suggested they could still attempt to get support from the central government. ### Video Rental Privacy Laws May Soon Apply to Streaming URL: https://www.privacyguides.org/news/2026/01/29/video-rental-privacy-laws-may-soon-apply-to-streaming/ Last updated: 2026-01-29T22:16:37.000Z The US Supreme Court will soon hear a [case](https://arstechnica.com/tech-policy/2026/01/supreme-court-to-decide-how-1988-videotape-privacy-law-applies-to-online-video/) alleging that Paramount violated the 1988 Video Privacy Protection Act (VPPA). The class action was filed in 2022 and alleges that Paramount violated the VPPA by sharing Michael Salazar's data with Facebook. Salazar says he subscribed to a newsletter at 247sports.com, which is owned by Paramount, and then proceeded to watch some videos on the website. Because Paramount had installed the Meta Tracking Pixel on the website - and because Salazar was signed into Facebook while watching the videos - Facebook was able to get detailed information about which videos he watched, including his email address from the newsletter, which then resulted in better-targeted ads on both sites. The Meta Pixel is an analytics tool - similar to Google Analytics - that has resulted in Facebook collecting obscene amounts of data from visitors to other websites, including sensitive medical data that's usually hidden behind a login portal. [The Markup](https://themarkup.org/pixel-hunt/2022/06/16/facebook-is-receiving-sensitive-medical-information-from-hospital-websites) documented this extensively in 2022, and many organizations stopped using it (if only temporarily) as a result of the scandal. The VPPA defines privacy rights for "consumers" of audio video content, and this is what the case will hinge on. Salazar argues that because he subscribed to the newsletter, that made him a "consumer," which the VPPA defines as “any renter, purchaser, or subscriber of goods or services from a video tape service provider.” (The act further defines "video tape service provider" to include "similar audio visual materials," so 247sports' role as a provider seems to be agreed upon already.) Courts so far have been split on the issue. The case is set to go before the Supreme Court in the 2026-2027 term, which begins in October. If the courts rule in favor of Salazar, this would be a huge privacy win. ### Google Accidentally Leaks Upcoming AluminiumOS Desktop Interface URL: https://www.privacyguides.org/news/2026/01/29/google-accidentally-leaks-upcoming-aluminiumos-desktop-interface/ Last updated: 2026-01-29T20:55:56.000Z According to [9to5Google](https://9to5google.com/2026/01/27/android-desktop-leak/), a [bug report](https://issuetracker.google.com/issues/479094248) (currently inaccessible) about Chrome Incognito tabs leaked the desktop interface for the upcoming AluminiumOS, Google’s merging of ChromeOS and Android. The build number number showed the text “ALOS” which likely corresponds to the codename AluminiumOS. > DEVICE: Brya(Redrix) CHROME BUILD: 145.0.7587.4(Dev before upgrade) and 146.0.7634.0(Dev after upgrade) ALOS: ZL1A.260119.001.A1 The leak showed footage of the desktop environment which contains elements of Android’s current desktop interface, but with a taller status bar more optimized for larger screens. ![](https://www.privacyguides.org/content/images/2026/01/image-1.png) Screenshot from [9to5Google’s](https://9to5google.com/2026/01/27/android-desktop-leak/) footage The bottom status bar is identical to the current Android QPR3 beta 2 desktop mode. The existence of a merging of Android and ChromeOS has been rumored for years before being casually [confirmed](https://www.androidauthority.com/google-combine-chrome-os-android-3577035/) in an interview with Sameer Samat, president of Android ecosystem development at Google. Then at the Snapdragon Summit in September, Google teased its work on merging Android and PC: > We’ve embarked on a project to combine that. We are building together a common technical foundation for our products on PCs and desktop computing systems. In November, a job listing at Google was spotted for “a new Aluminium, Android-based, operating system,” confirming that the name, or codename at least, for the project was Aluminium. A merging of Google’s desktop and mobile offerings would allow Android users to have a unified experience across both platforms, and allow for running desktop programs on their phone. Android’s long-awaited desktop mode promised to bring the desktop experience to Android, but it seems that Android users will get desktop hardware as well. Aluminium OS is expected to contain a lot of AI features, so likely the hardware will need to be a bit beefier (although that’s speculation on my part). That could spell good news for people wanting more performance out of their Chromebooks. If Google ends up making desktop hardware, it would open the door for GrapheneOS to support it as well. A desktop version of GrapheneOS would provide the most secure desktop OS experience available by far. Chromebooks have [10 years](https://support.google.com/chrome/a/answer/6220366?hl=en#:~:text=ChromeOS%20devices%20receive%2010%20years%20of%20updates) of support, unheard of in the mobile landscape. If Google brings that level of support to the Android space, that would beat out their own guaranteed [7 years](https://support.google.com/pixelphone/answer/4457705?hl=en#:~:text=Pixel%208%20and%20later%20phones%20will%20get%20updates%20for%207%20years) of support for Pixel devices. The possibilities of what a merged ChromeOS and Android ecosystem could bring are exciting, if the best parts of each are brought over it could be great for the lifespan and convenience of our devices. After all, if you can replace your desktop with your phone, that means less devices to purchase. ### 1Password Adds Additional Phishing Protection URL: https://www.privacyguides.org/news/2026/01/29/1password-adds-additional-phishing-protection/ Last updated: 2026-01-29T20:33:25.000Z Popular password manager [1Password](https://1password.com/blog/as-ai-supercharges-phishing-scams-1password-introduces-built-in-protection) will be introducing a pop-up to help users better protect against possible phishing attacks. One advantage of a password manager is the "autofill" feature, where you can have your password manager automatically fill in on a login page if you so choose. This can be a helpful line of defense against phishing attacks because if the password manager fails to autofill, that could be your sign to pause and make sure you're on the right page. However - as many password manager users know - this feature isn't always perfect, and it's not uncommon to have to manually copy/paste your credentials. These frequent false alarms can make users less likely to be concerned when it happens. To help combat this, 1Password is now adding pop-up that appears when you try to paste your password. The feature will be enabled by default for individual and family plan users, but must be enabled by admins in enterprise plans. Bitwarden recently [announced](https://bitwarden.com/blog/bitwarden-launches-enhanced-premium-plan/) a similar feature will be coming soon to their premium and family plans, along with a price increase. Due to how common autofill failures are, I personally have concerns that this will become just another thing that users will grow accustomed to in time, though it's equally possible that the nudge may be helpful in the long run, especially for users who may not realize that a lack of autofill could be cause for concern. At *Privacy Guides*, we strongly advocate for the use of "unphishable" authentication methods, such as passkeys or [security keys](https://www.privacyguides.org/en/security-keys/). ### PornHub Withdraws From UK Over Online Safety Act URL: https://www.privacyguides.org/news/2026/01/29/pornhub-withdraws-from-uk-over-online-safety-act/ Last updated: 2026-01-29T20:20:49.000Z As of February 2, PornHub will start [restricting](https://techcrunch.com/2026/01/27/if-you-live-in-the-uk-you-probably-wont-be-able-to-visit-pornhub-anymore/) access to UK users. Since the UK's Online Safety Act came into effect, PornHub (and others) have complied by requiring users to verify their ages. Now, parent company Aylo is reversing course and saying that after February 2nd, access will be restricted: > “Despite the clear intent of the law to restrict minors’ access to adult content and commitment to enforcement, after 6 months of implementation, our experience strongly suggests that the OSA has failed to achieve that objective. We believe this framework in practice has diverted traffic to darker, unregulated corners of the internet, and has also jeopardized the privacy and personal data of U.K. citizens.” Aylo has been advocating for device-based verification rather than requiring services to handle user data, arguing that it is more effective and safer. Aylo's claim that the law has simply driven users to other, seedier platforms who don't comply has been a commonly-voiced concern among critics of the law. The company also claimed that Ofcom - the UK's regulator who enforces the OSA - has failed to adequately enforce the law against other platforms who aren't in compliance. Ofcom disagreed, telling Aylo: > There’s nothing to stop technology providers from developing solutions which work at the device level, and we would urge the industry to get on with that if they can evidence it is highly effective. They also claim to have more than 80 investigations pending and at least one £1 million fine, "with more to come." It's unclear from the article exactly what PornHub's withdrawal will mean in practice. The article says that users who have already verified can still use their accounts after February 2nd, but it's unclear if users can still verify up until February 2nd or if that functionality has already been halted. PornHub experienced a [data breach](https://www.privacyguides.org/news/2025/12/20/data-breach-roundup-dec-12-dec-18-2025/) late last year, which exposed data of Premium subscribers including email addresses, watch history, location, and more. ### The NexPhone: A $549 Android, Linux, and Windows Device URL: https://www.privacyguides.org/news/2026/01/29/the-nexphone-a-549-android-linux-and-windows-device/ Last updated: 2026-01-29T20:02:58.000Z Nex Computer is best known for their dock that allows you to turn your Android phone into a workstation. But now, 14 years after initially announcing the concept, they are accepting preorders for the [NexPhone](https://itsfoss.com/news/nexphone-returns/). By 2026 standards, the NexPhone has relatively dated specs. The article suggests that the phone is essentially a Fairphone 5, which is over 2 years old and received criticism even at the time (particularly around processor speed), but the company admits they envision this phone acting more as a secondary or backup phone rather than a flagship daily driver. Still, the specs seem - to my uneducated initial comparison to the iPhone 16e - pretty decent in some areas such as memory, camera resolution, and internal storage (which can be expanded via SD card). The biggest selling point of the NexPhone is that it runs Android, Debian, and Windows 11\. *It's FOSS* says that NexOS is "a bloatware-free and minimal Android 16 system," and that Debian will run "as an app with GPU acceleration." Windows 11 is available via dual-boot. While I personally find this concept incredibly cool, there are several security considerations. As far as I can tell in my research, NexOS is not source-available and I was unable to find any information about what changes it makes to the Android base (thougn it does claim to run on Android 16) and Debian is not one of the Linux distros we recommend at [*Privacy Guides*](https://www.privacyguides.org/en/desktop/) for several reasons, security being one of them. It also seems that Nex made at very least some cosmetic changes to Windows 11 to optimize it for mobile, which could potentially introduce new bugs or vulnerabilities. Should you be willing to accept these risks, the NexPhone is set to ship in Q3 of this year (July-September) and the $199 deposit is refundable. ### Windows Update Stops Machines from Booting URL: https://www.privacyguides.org/news/2026/01/29/windows-update-stops-machines-from-booting/ Last updated: 2026-01-29T20:02:29.000Z The disastrous [KB5074109](https://support.microsoft.com/en-us/topic/january-13-2026-kb5074109-os-builds-26200-7623-and-26100-7623-3ec427dd-6fc4-4c32-a471-83504dd081cb) Windows update has reportedly caused some people's computers to [fail to boot](https://www.windowslatest.com/2026/01/25/microsoft-suspects-some-pcs-might-not-boot-after-windows-11-january-2026-update-kb5074109/), among the myriad other issues. The update came as a standard security update pushed to all windows users as Microsoft's first patch Tuesday update of the year. As such, the update is installed automatically for most Windows users. Microsoft has officially acknowledged the issue in a [support document](https://admin.cloud.microsoft/Adminportal/Home?source=applauncher#/windowsreleasehealth/:/issue/WI1221934) found by Windows Latest: [![](https://www.privacyguides.org/content/images/2026/01/January-2026-Update-issues-dashboard.jpg)](https://www.windowslatest.com/2026/01/25/microsoft-suspects-some-pcs-might-not-boot-after-windows-11-january-2026-update-kb5074109/) This comes after multiple previous issues had been reported with the same update. Microsoft officially acknowledged a few on their [support page](https://support.microsoft.com/en-us/topic/january-13-2026-kb5074109-os-builds-26200-7623-and-26100-7623-3ec427dd-6fc4-4c32-a471-83504dd081cb) and have issued a few fixes, but users are still having problems and new ones seem to crop up as soon as the previous ones get fixed. The update was causing Outlook to [freeze](https://support.microsoft.com/en-us/office/classic-outlook-profiles-with-pop-accounts-and-psts-hang-after-windows-updates-on-january-13-2026-590fe356-ecc2-49f4-b9e3-bd39fafa58f6) for profiles using POP accounts and profiles using PST files. Specifically, the issue happens when you have PST files stored in OneDrive, Microsoft's non-E2EE cloud storage service that it likes to [enable by default](https://www.howtogeek.com/windows-11-onedrive-automatic-enabled/). The issue was fixed by Microsoft in an out-of-band [update](https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491). The update also caused failed sign-ins on for Remote Desktop on programs like the [Windows App](https://learn.microsoft.com/en-us/windows-app/get-started-connect-devices-desktops-apps?tabs=windows-avd%2Cwindows-w365%2Cwindows-devbox%2Cmacos-rds%2Cmacos-pc&pivots=azure-virtual-desktop), an app for remotely connecting to Windows devices. The issue was fixed with another out-of-band [update](https://support.microsoft.com/en-us/topic/january-17-2026-kb5077744-os-builds-26200-7627-and-26100-7627-out-of-band-27015658-9686-4467-ab5f-d713b617e3e4). [Citrix](https://support.citrix.com/external/article/CTX695983/citrix-director-unable-to-shadow-sessio.html) is having problems as well but seems to remain unaddressed for now. Some computers with [Secure Launch](https://learn.microsoft.com/en-us/windows/security/hardware-security/system-guard-secure-launch-and-smm-protection) enabled were not shutting down properly and instead restarting after the update. Microsoft was able to [fix](https://support.microsoft.com/en-us/topic/january-17-2026-kb5077797-os-build-22631-6494-out-of-band-3fb07d6a-0e35-4510-8518-4e333ed78edc) it for some machines but they say they're still investigating the rest. Microsoft recommended using [Known Issue Rollback](https://techcommunity.microsoft.com/blog/windows-itpro-blog/known-issue-rollback-helping-you-keep-windows-devices-protected-and-productive/2176831) for at least one of the issues, however the feature doesn't work for security fixes. As a security update, most of it can't be fixed using this feature. There are still more issues that Microsoft hasn't acknowledged as it continues to play whack-a-mole. Users are reporting [broken](https://www.reddit.com/r/Windows11/comments/1qbym1c/comment/nzk4tha/) [S3 sleep](https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/system-sleeping-states#system-power-state-s3) on their machines and [wallpapers being changed to black](https://www.reddit.com/r/Windows11/comments/1qbym1c/comment/nzei4j8/). According to [Windows Latest](https://www.windowslatest.com/2026/01/21/2026s-first-windows-11-update-is-causing-more-problems-now-as-microsoft-enters-damage-control-mode/): > Windows Latest understands that there’s a regression bug in Windows 11 25H2 on the desktop S3 sleep path. Even with hybrid sleep and wake timers disabled, the system-level Maintenance Activator (SystemEventsBroker) does not properly clear the maintenance wake context after the first wake, causing the second sleep to wake immediately. There's even a reported bug where the keyboard and mouse don't work correctly. This is not a great start for Windows in 2026\. Microsoft needs to improve its quality assurance so incidents like this don't happen again. ### UK Considers Australia-Style Social Media Ban URL: https://www.privacyguides.org/news/2026/01/24/uk-considers-australia-style-social-media-ban/ Last updated: 2026-01-24T07:57:19.000Z The UK has launched a [consultation](https://www.engadget.com/social-media/the-uk-is-mulling-an-australia-like-social-media-ban-for-users-under-16-130000446.html) on a plan to institute a ban on social media for anyone under 16 years old. They have also announced a consultation. Australia's own social media ban was passed in November 2024 and came into effect in December 2025\. Since it was announced, numerous countries have expressed interest in replicating it to various degrees. The UK already passed the Online Safety Act in 2023, which has already been met with widespread criticism over the implementation and secondary impacts (such as shuttering smaller communities and concerns about free speech). Still, it seems that some feel the Act doesn't go far enough. In addition to the consultation, the UK government is also considering how to enforce the proposed ban, how to limit tech companies from accessing children's data, and other obstacles. Some ministers are also set to visit Australia to see how the existing ban has worked out there. Our primary source claimed that the government was seeking public comment, but despite extensive search I was unable to find anywhere to submit public comments. If any of you find such a portal, please let us know. ### Bitwarden Raises Prices, Microsoft Hands Over Encryption Keys, ICE's Numerous Privacy Concerns, and more! URL: https://www.privacyguides.org/livestreams/2026/01/23/bitwarden-raises-prices-microsoft-hands-over-encryption-keys-ices-numerous-privacy-concerns-and-more/ Last updated: 2026-01-27T02:58:24.000Z This Week in Privacy #37 _This post is for subscribers only._ ### European X/Twitter Alternative W Announced at Davos URL: https://www.privacyguides.org/news/2026/01/23/european-x-twitter-alternative-w-announced-at-davos/ Last updated: 2026-01-23T21:56:42.000Z Europe is set to launch a new X alternative called "W." Unveiled at the World Economic Forum in Davos, the CEO says that "W" stand for "We" and the two Vs combined represent "Values" and "Verified. In that vein, the platform promises to verify all user with photo ID to prevent bots and all data will be hosted in Europe in a decentralized way. W will be a legal subsidiary of "We Don't Have Time," which [Cybernews](https://cybernews.com/tech/europe-social-media-w/) describes as "a media platform for climate action." They claim their focus will be on fighting disinformation. The platform was announced on January 20th but is not yet publicly available. Needless to say, *Privacy Guides* is not a fan of solutions that require identity verification. We're also confused why people keep refusing to use existing X alternatives such as Mastodon - which is already based in Europe and decentralized. W (or We Don't Have Time or whoever) could easily host their own instance require ID verification rather than reinventing the wheel from the ground up. Cybernews also notes that W is likely to face a lot of uphill resistance, given that both Bluesky and Mastodon have failed to retain users long-term even after experiencing sudden booms (several times) after Elon Musk's acquisition of Twitter. ### Data Breach Roundup (Jan 16 – Jan 22, 2026) URL: https://www.privacyguides.org/news/2026/01/23/data-breach-roundup-jan-16-jan-22-2026/ Last updated: 2026-01-23T20:45:02.000Z ## Supreme Court hacker posted stolen government data on Instagram A man used stolen credentials to access the accounts of people at the Supreme Court, but also AmeriCorps (a government agency that runs stipend volunteer programs) and the Department of Veterans Affairs. He then posted some of the data on Instagram under the handle `@ihackthegovernment`. It's unclear what he was attempting to gain (money, intimidation, etc) but the man now faces up to 1 year in jail and and a $100,000 fine. [Supreme Court hacker posted stolen government data on Instagram | TechCrunchNicholas Moore pleaded guilty to stealing victims’ information from the Supreme Court and other federal government agencies, and then posting it on his Instagram @ihackthegovernment.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-25.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/us-supreme-court.jpg)](https://techcrunch.com/2026/01/16/supreme-court-hacker-posted-stolen-government-data-on-instagram/) ## CIRO confirms data breach exposed info on 750,000 Canadian investors CIRO is the Canadian Investment Regulatory Organization. It was formed in 2023 and is "one of the core pillars of the country’s financial regulatory framework." The data - stolen in August 2024 - includes dates of birth, phone numbers, annual income, social insurance numbers, government ID numbers, investment account numbers, and account statements. [CIRO confirms data breach exposed info on 750,000 Canadian investorsThe Canadian Investment Regulatory Organization (CIRO) confirmed that the data breach it suffered last year impacts about 750,000 Canadian investors.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-35.png)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/investment.jpg)](https://www.bleepingcomputer.com/news/security/ciro-data-breach-last-year-exposed-info-on-750-000-canadian-investors/) ## Ingram Micro says ransomware attack affected 42,000 people This breach took place in July 2025 and included name, contact information, date of birth, government ID numbers (including Social Security, driver's license, and passport numbers), and "certain employment-related information (such as work-related evaluations)." [Ingram Micro says ransomware attack affected 42,000 people​Information technology giant Ingram Micro has revealed that a ransomware attack on its systems in July 2025 led to a data breach affecting over 42,000 individuals.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-36.png)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/ingram-micro-hq.jpg)](https://www.bleepingcomputer.com/news/security/ingram-micro-says-ransomware-attack-affected-42-000-people/) ## UStrive security lapse exposed personal data of its users, including children UStrive is a nonprofit online mentoring site formerly known as "Strive for College." The "security lapse" was that personal data was visible using "browser tools" while signed in and navigating the website. This was apparently linked to a vulnerable Amazon-hosted GraphQL endpoint. The researcher said that at least 238,000 records were visible and included data such as full names, email addresses, phone numbers, gender and date of birth. UStrive has not said if they plan to inform users. [Exclusive: UStrive security lapse exposed personal data of its users, including childrenThe online mentoring site UStrive exposed email addresses, phone numbers, and other non-public information to other logged-in users. The nonprofit told TechCrunch that the issue is now fixed, but wouldn’t commit to alerting affected individuals.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-26.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/yellow-padlock-cyber-rating-getty.jpg)](https://techcrunch.com/2026/01/20/ustrive-security-lapse-exposed-personal-data-of-its-users-including-children/) ## Under Armour says it’s ‘aware’ of data breach claims after 72M customer records were posted online Under Armour - mostly known for their fitness clothes - apparently suffered a data breach in November. The data includes name, email address, gender, date of birth, location based on ZIP code, and purchase-related information for 72 million individuals. Under Armour said they were still investigating the incident but made no comment about plans to notify victims. [Under Armour says it’s ‘aware’ of data breach claims after 72M customer records were posted online | TechCrunchTechCrunch obtained a sample of the stolen data, which contained names, email addresses, dates of birth, and the user’s approximate geographic location. Under Armour confirmed some sensitive information was taken in the breach.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-27.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-1455290353.jpg)](https://techcrunch.com/2026/01/22/under-armour-says-its-aware-of-data-breach-claims-after-72m-customer-records-were-posted-online/) ### Pwn2Own Automotive Shows How Insecure Our Vehicles Are URL: https://www.privacyguides.org/news/2026/01/23/pwn2own-automotive-shows-how-insecure-our-vehicles-are/ Last updated: 2026-01-23T20:44:02.000Z The first day of the [Pwn2Own](https://www.zerodayinitiative.com/blog/2026/1/20/pwn2own-automotive-2026-the-full-schedule) Automotive hacking competition has kicked off in Tokyo, Japan, with “a record 73 entries” showing that our vehicles are juicier targets than ever. Competitors attacked infotainment systems and charging stations for electric vehicles, earning a total of $516,500 and exploiting 37 vulnerabilities. Among the victims were Tesla’s infotainment system, hacked by Synacktiv Team, who chained two zero-day vulnerabilities together to hack it. The results of day one have been [posted](https://www.zerodayinitiative.com/blog/2026/1/21/pwn2own-automotive-2026-day-one-results), complete with a leaderboard. The contest takes place during the [Automotive World](https://www.automotiveworld.jp/tokyo/en-gb.html) exhibition, a show of the latest tech from auto manufacturers. The contest, run by Zero Day Initiative, gives us a glimpse into just how vulnerable our vehicles are. Understandably, the focus is mainly on the infotainment system, but I was surprised to see multiple charging controllers also being hacked. You wouldn’t think the charging controller would be vulnerable but clearly that’s not the case. The internal workings of a modern car are essentially a complex network of components talking to each other, all of which can be vulnerable to attack. The competition only focused on specific part of the vehicle, but imagine the damage that could be done if the competition was to hack a full car. You don’t even necessarily need physical access to the car. A [vulnerability](https://samcurry.net/hacking-subaru) in Subaru’s STARLINK system (no not that one) allowed attackers to take control of a vehicle remotely via an exposed and vulnerable admin panel. An attacker could remotely start, stop, unlock, and retrieve the current or previous complete location history of any vehicle, read information from the instruments on the car such as sales history, odometer reading, and previous owners, as well as access personally identifiable information such as emergency contacts, physical address, billing information, and the vehicle PIN. All without needing any kind of complex chain of exploits or physical access like the contestants had. A similar remote [vulnerability](https://samcurry.net/hacking-kia) was found by the same researchers in Kia’s system that would allow an attacker to remotely start/stop, geolocate the vehicle, and remotely lock/unlock it, and even access the cameras on certain models with nothing more than the license plate. The vehicle didn’t even need an active Kia Connect subscription. Vulnerabilities in cars have shot up sharply since around [2019](https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/rising-security-weaknesses-in-the-automotive-industry-and-what-it-can-do-on-the-road-ahead). Auto manufacturers have not caught up to the growing landscape of threats. The [2025](https://www.bleepingcomputer.com/news/security/hackers-get-886-250-for-49-zero-days-at-pwn2own-automotive-2025/) Pwn2Own competition ended with 49 vulnerabilities exploited, the same number as the [previous year](https://www.bleepingcomputer.com/news/security/pwn2own-automotive-13m-for-49-zero-days-tesla-hacked-twice/). There are efforts to address the growing issue of cybersecurity in cars at least. ISO/SAE 21434 provides a standard of best cybersecurity practices for car manufacturers to adhere to. There is also work on [implementing](https://www.vector.com/int/en/products/products-a-z/embedded-software/microsar-hsm/) Secure Boot using Hardware Security Modules for cars, bringing improved security against malware persistence. It seems to be too little, too late, however. We will have to wait and see if car manufacturers will start taking security seriously or just keep dumping more connected features into vehicles carelessly. ### Mandiant Releases Rainbow Tables for Outdated Windows NTLMv1 URL: https://www.privacyguides.org/news/2026/01/20/mandiant-releases-rainbow-tables-for-outdated-windows-ntlmv1/ Last updated: 2026-01-20T22:27:36.000Z Mandiant, a cybersecurity firm and subsidiary of Google, has [released](https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables/) a rainbow table for the outdated Windows NTLMv1 authentication protocol, allowing attackers to crack administrator passwords in under 12 hours using consumer hardware that costs less than $600. [NTLM](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) is used in Windows to authenticate users on a network. It uses hashes of passwords stored on a server in order to verify that your password is correct. A hashing algorithm is a one-way function that takes text as an input and spits out what looks like junk data, but the same input will always render the same output, so you can use it to authenticate passwords. An attacker that breaches the server will have hashes of passwords, but they will need to somehow reverse the hashing algorithm to the original password. That’s where [rainbow tables](https://en.wikipedia.org/wiki/Rainbow%5Ftable) come in: you can precompute these hashes for a large number of inputs and then compare the hashes in the table to find the original plaintext. Because NTLMv1 uses a weak hashing algorithm, the total number of possible values is quite small, so with modern hardware, it’s possible to iterate through to find the password quite quickly. > By releasing these tables, Mandiant aims to lower the barrier for security professionals to demonstrate the insecurity of Net-NTLMv1\. While tools to exploit this protocol have existed for years, they often required uploading sensitive data to third-party services or expensive hardware to brute-force keys. NTLMv1 is decades old and has been known to be insecure since [1999](https://www.schneier.com/academic/archives/1999/09/cryptanalysis%5Fof%5Fmic%5F1.html). Despite this, Mandiant says they still see deployments of it in the wild to this day. Their aims to eliminate the use of NTLMv1 align with Microsoft, who plan on finally [deprecating](https://support.microsoft.com/en-us/topic/upcoming-changes-to-ntlmv1-in-windows-11-version-24h2-and-windows-server-2025-c0554217-cdbc-420f-b47c-e02b2db49b2e) NTLMv1 in the near future. They plan to deprecate NTLM as a whole in the future as well in favor of the much more secure [Kerberos](https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview) authentication. A big reason why many organizations don’t upgrade is compatibility: many of them still use legacy software that requires NTLMv1\. A lot of important infrastructure still runs on [outdated](https://www.techspot.com/news/107960-decades-old-windows-systems-running-trains-printers-hospitals.html) versions of Windows. This points I think to a wider problem in software. How do we make sure systems we have in place today can be upgraded to supported operating systems? Even if you’re running the latest version of Windows, there’s still a lot of old stuff left over for compatibility reasons, such as the Internet Explorer [compatibility](https://support.microsoft.com/en-us/microsoft-edge/internet-explorer-mode-in-microsoft-edge-6604162f-e38a-48b2-acd2-682dbac6f0de) mode in [Edge](https://www.bleepingcomputer.com/news/security/microsoft-restricts-ie-mode-access-in-edge-after-zero-day-attacks/) (needed for some older technologies like ActiveX and Flash). Even NTLM [existing](https://support.microsoft.com/en-us/topic/file-explorer-automatically-disables-the-preview-feature-for-files-downloaded-from-the-internet-56d55920-6187-4aae-a4f6-102454ef61fb) on the system is a danger. There’s a tension between pushing users to use modern and secure software and providing support for older systems. Windows seems to take the gentle hand approach: disabling old features by default, then requiring you to manually enable them, before finally deprecating them properly. With the release of the rainbow table, perhaps this will be the final push to perform a much-needed upgrade for systems still relying on legacy software. I think Mandiant put it best: > Organizations should immediately disable the use of Net-NTLMv1. ### ChatGPT Announces Ads Coming for Free and Go Users URL: https://www.privacyguides.org/news/2026/01/20/chatgpt-announces-ads-coming-for-free-and-go-users/ Last updated: 2026-01-20T01:01:01.000Z OpenAI has [announced](https://openai.com/index/our-approach-to-advertising-and-expanding-access/) it’ll be incorporating ads into ChatGPT for [Free](https://help.openai.com/en/articles/9275245-chatgpt-free-tier-faq) and [Go](https://help.openai.com/en/articles/11989085-what-is-chatgpt-go?q=Free) users in the future. OpenAI states that it won’t sell your data or share your conversations with advertisers, but there’s going to be an option to start a conversation with an ad and *that* will be shared with advertis > If you choose to message an advertiser through an ad (for example, to ask questions while making a purchase decision), the advertiser will only see the messages you send them directly. So be careful which messages you respond to I suppose. The ads will be clearly labeled as ads thankfully, and they won’t affect the answers you get from ChatGPT. There will be ad personalization which you can turn off, but that brings questions of what data ChatGPT is going to be collecting in order to facilitate that feature. After all, they only promise not to share data with advertisers, not collect it for themselves. ChatGPT lacks privacy features to keep your chats private to just you. They don’t implement E2EE for your chat history like Proton’s [Lumo](https://lumo.proton.me), they don’t use confidential computing like [Confer](https://confer.to), and they don’t use [homomorphic encryption](https://www.ibm.com/think/topics/homomorphic-encryption) (although I’m not aware of any chatbots that do currently). ChatGPT *has* promised that they want to implement some kind of [encryption](https://openai.com/index/fighting-nyt-user-privacy-invasion/) to chats, although so far we haven’t heard any news of it. > Our long-term roadmap includes advanced security features designed to keep your data private, including client-side encryption for your messages with ChatGPT. This seems to run counter to their new plans for advertising. After all, how do you serve relevant ads without any data? > To start, we plan to test ads at the bottom of answers in ChatGPT when there’s a relevant sponsored product or service based on your current conversation. The example of an ad they show is quite intrusive as well, taking up about a third of the screen space. It’s unclear how this feature will interact with adblockers or if ChatGPT will take measures to block adblockers like YouTube has been trying to for years now. Likely they’ll be served from the same domain as regular ChatGPT so it will be more difficult to block them than most ads on the internet. It seems ChatGPT is reaching stage 2 of Cory Doctorow’s [Enshittification](https://en.wikipedia.org/wiki/Enshittification) process. First, ChatGPT offered its service for free to lure users in. Now, it will make the user experience worse with ads in order to draw in money from advertisers. With ChatGPT’s precedent set, I think we can expect to see more and more AI services displaying ads in the chat window in the future. ### Signal Founder Announces Private AI Alternative, Privacy Services Form a Privacy Alliance, Threema gets acquired (again) and more! URL: https://www.privacyguides.org/livestreams/2026/01/16/signal-founder-announces-private-ai-alternative-privacy-services-form-a-privacy-alliance-threema-gets-acquired-again-and-more/ Last updated: 2026-01-17T17:07:01.000Z This Week in Privacy #36 _This post is for subscribers only._ ### Data Breach Roundup (Jan 9 – Jan 15, 2026) URL: https://www.privacyguides.org/news/2026/01/16/data-breach-roundup-jan-9-jan-15-2026/ Last updated: 2026-04-03T18:27:25.000Z Welcome to Data Breach Roundups, our new weekly series where we highlight notable data breaches we encounter. They're more common than you might think! If you want this weekly digest delivered to your inbox in the future, edit your newsletter settings to subscribe to the new 'Data Breach Roundups' mailing list. [Edit Newsletter Subscriptions ](#/portal/account/newsletters) ## BreachForums hacking forum database leaked, exposing 324,000 accounts From the "highly ironic" department, this breach contains display names, registration dates, IP addresses, and other internal information. Only about 70,000 of the records appear to have useful information (specifically non-local IP addresses). It also appears to include the administrator's private key. [BreachForums hacking forum database leaked, exposing 324,000 accountsThe latest incarnation of the notorious BreachForums hacking forum has suffered a data breach, with its user database table leaked online.![](https://www.privacyguides.org/content/images/icon/bleeping-27.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/hacker-arms-raised-brighter.jpg)](https://www.bleepingcomputer.com/news/security/breachforums-hacking-forum-database-leaked-exposing-324-000-accounts/) ## Spanish energy giant Endesa discloses data breach affecting customers "Endesa is the largest electric utility company in Spain that distributes gas and electricity to more than 10 million customers in Spain and Portugal. In total, the company says it has about 22 million clients." Data impacted includes "basic identification details," contact information, national identity numbers (DNI), contract details, and payment details, including IBANs. The threat actors are already claiming to have 20 million records - about 1 TB - for sale. [Spanish energy giant Endesa discloses data breach affecting customersSpanish energy provider Endesa and its Energía XXI operator are notifying customers that hackers accessed the company’s systems and accessed contract-related information, which includes personal details.![](https://www.privacyguides.org/content/images/icon/bleeping-28.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/endesa.jpg)](https://www.bleepingcomputer.com/news/security/spanish-energy-giant-endesa-discloses-data-breach-affecting-customers/) ## Fintech firm Betterment confirms data breach after hackers send fake crypto scam notification to users Betterment is an "automated investment platform." Attackers have been abusing the push notification system to try to scam users, promising to "triple the value of their crypto by sending $10,000 to a wallet controlled by the attacker." They also compromised names, email & mailing address, phone numbers, and dates of birth. The especially disappointing part: > Betterment’s security incident web page contains a hidden “noindex” tag in its source code, which tells search engines to ignore the page, making it more difficult for anyone searching the web to discover information about the data breach. Be sure to help spread the word since Betterment is doing everything they can to hide it. Very hostile behavior toward users. [Fintech firm Betterment confirms data breach after hackers send fake crypto scam notification to users | TechCrunchHackers gained access to some Betterment customers’ personal information through a social engineering attack, then targeted some of them with a crypto-related phishing message.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-22.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/betterment-icon-iphone.jpg)](https://techcrunch.com/2026/01/12/fintech-firm-betterment-confirms-data-breach-after-hackers-send-fake-crypto-scam-notification-to-users/) ## University of Hawaii Cancer Center hit by ransomware attack The attack occurred in August 2025, stealing data of study participants as far back as the 1990s. The impact appears limited to a single study and mostly research data, except Social Security Numbers of participants. (The university has switched to different ID methods.) The university paid the ransom and will alert impacted individuals once the investigation is complete. [University of Hawaii Cancer Center hit by ransomware attack​University of Hawaii says a ransomware gang breached its Cancer Center in August 2025, stealing data of study participants, including documents from the 1990s containing Social Security numbers.![](https://www.privacyguides.org/content/images/icon/bleeping-29.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/UH_Cancer_Center.jpg)](https://www.bleepingcomputer.com/news/security/university-of-hawaii-cancer-center-hit-by-ransomware-attack/) ## Central Maine Healthcare breach exposed data of over 145,000 people CMH has over 400,00 patients and manages some regionally-significant locations like Central Maine Medical Center (CMMC), Bridgton Hospital, and Rumford Hospital. The breach took place between March and June 2025 and exposed full names, dates of birth, treatment information, dates of service, provider names, health insurance information, and social security numbers. [Central Maine Healthcare breach exposed data of over 145,000 peopleA data breach last year at Central Maine Healthcare (CMH) exposed sensitive information of more than 145,000 individuals.![](https://www.privacyguides.org/content/images/icon/bleeping-30.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/healthcare-cyber-1.jpg)](https://www.bleepingcomputer.com/news/security/central-maine-healthcare-breach-exposed-data-of-over-145-000-people/) ## Monroe University says 2024 data breach affects 320,000 people Data impacted includes name, date of birth, Social Security number, driver's license number, passport number, government identification number, medical information, health insurance information, electronic account or email username and password, financial account information, and/or student data. The school finished their investigation in September. It's unclear why it took so long or why it took even longer to notify people. [Monroe University says 2024 data breach affects 320,000 peopleMonroe University revealed that threat actors stole the personal, financial, and health information of over 320,000 people after breaching its systems in a December 2024 cyberattack.![](https://www.privacyguides.org/content/images/icon/bleeping-31.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/monroe-university.jpeg)](https://www.bleepingcomputer.com/news/security/monroe-university-says-2024-data-breach-affects-320-000-people/) ## Victorian Department of Education says hackers stole students’ data Exposed data includes names, school names, year levels, school-issued email addresses, and encrypted passwords. Number of impacted students was not disclosed. Dates of birth, home address, and phone numbers were not exposed. [Victorian Department of Education says hackers stole students’ dataThe Department of Education in Victoria, Australia, notified parents that attackers gained access to a database containing the personal information of current and former students.![](https://www.privacyguides.org/content/images/icon/bleeping-32.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/School-hacker.jpg)](https://www.bleepingcomputer.com/news/security/victorian-department-of-education-notifies-parents-of-data-breach/) ## US cargo tech company publicly exposed its shipping systems and customer data to the web > In a now-published blog post, Zveare said he submitted details of the five flaws in Bluspark’s platform to the Maritime Hacking Village, a nonprofit that works to secure maritime space and helps researchers to notify companies working in the maritime industry of active security flaws. > Weeks later, and following multiple emails, voicemails, and LinkedIn messages, the company had not responded to Zveare. All the while, the flaws could still be exploited by anyone on the internet. > On the third time TechCrunch emailed Bluspark’s CEO, we included a partial copy of his password to demonstrate the seriousness of the security lapse. A couple of hours later, TechCrunch received a response — from a law firm representing Bluspark. 🤦‍♂️ Long story short, a horribly-configured API allowed for phishing emails, plaintext password extraction, and more. Baffling that a company could build such a complex portal and invest basically nothing into security. [Exclusive: US cargo tech company publicly exposed its shipping systems and customer data to the webShipping tech company Bluspark left internal plaintext passwords, including those of executives, exposed to the internet, at a time when hacks in the shipping industry are on the rise.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-23.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/bluvoyix-shipping-containers.jpg)](https://techcrunch.com/2026/01/14/us-cargo-tech-company-publicly-exposed-its-shipping-systems-and-customer-data-to-the-web/) ### Bluetooth Exploit Leaves Hundreds of Millions of Accessories Vulnerable to Full Takeover URL: https://www.privacyguides.org/news/2026/01/16/bluetooth-exploit-leaves-hundreds-of-millions-of-accessories-vulnerable-to-full-takeover/ Last updated: 2026-01-16T17:34:48.000Z Researchers have discovered a vulnerability in [Google Fast Pair](https://www.android.com/better-together/fast-pair/), dubbed [WhisperPair](https://whisperpair.eu/), that leaves affected accessories open to being fully controlled by an attacker. The exploit leverages a flaw in the Fast Pair implementation of many popular devices that allows and attacker to pair the accessory with their own device. The attacker then gains complete control over the device and can “play audio at high volumes or record conversations using the microphone.” It can also allow tracking victims around via Google’s [Find Hub Network](https://www.android.com/learn-find-hub/), a feature meant to help you find lost or stolen items. The main crux of the vulnerability is accessories skipping a critical step in the pairing process. When pairing with a Bluetooth device, first your phone or computer must send a message indicating that it wants to pair with the accessory. > The Fast Pair specification states that if the accessory is not in pairing mode, it should disregard such messages. However, many devices fail to enforce this check in practice, allowing unauthorised devices to start the pairing process. After receiving a reply from the vulnerable device, an attacker can finish the Fast Pair procedure by establishing a regular Bluetooth pairing. Since the attack is targeting the device itself instead of the phone or computer it’s connecting to, iOS and other non-Android users with accessories that support Google Fast Pair are still vulnerable. You can check [here](https://whisperpair.eu/vulnerable-devices) if your device is vulnerable. Make sure to update the firmware on your Bluetooth devices ASAP. The researchers indicate that some devices have been patched, but not all manufacturers have released a fix for the flaw yet. If an accessory hasn’t been paired to an Android device before, an attacker can add it to their Google account and track it through the Find Hub Network, essentially turning your headphones into a tracker. You will likely get a notification about headphones not belonging to you that are following you around, but many people will likely dismiss it as a glitch since they’re not aware that their headphones have been exploited. The researchers make a cogent point about how small, nonstandard usability and convenience features can lead to massive security vulnerabilities. Apple has had its own fair share of [issues](https://arstechnica.com/security/2024/01/hackers-can-id-unique-apple-airdrop-users-chinese-authorities-claim-to-do-just-that/) with their own proprietary protocols like AirDrop. > These vulnerable devices passed both the manufacturers' quality assurance tests and Google's certification process, demonstrating a systemic failure rather than an individual developer error. Issues like this being allowed to slip through show a massive flaw in Google’s system for releasing secure products. It’s unclear what changes are going to be implemented on Google and the OEM’s end in order to prevent this type of issue from happening again in the future. Compounding with the issue is the issue of installing firmware updates for Bluetooth accessories. Unless it’s a first-party accessory like [Pixel Buds](https://support.google.com/googlepixelbuds/answer/9642078?hl=en) on a Google Pixel, you won’t be able to update your firmware without installing a third-party app from the OEM. This means that most users don’t update their accessories in the end, and the ones that do risk leaking personal data to the OEM through required accounts on a proprietary app, not to mention the extra [attack surface](https://zimperium.com/blog/mobile-apps-the-new-api-battleground) from OEM apps installed on your phone. It’s unclear what the future holds for Bluetooth as a protocol. It’s never just one issue, multiple issues and failures have culminated in a flaw like WhisperPair. There needs to be more standardization and less proprietary protocols for pairing and interacting with Bluetooth accessories. More eyes looking at it allow for more flaws to be discovered. There also needs to be better systems for detecting these flaws, and more accountability for missing these types of issues. There should be an easier and more standardized way to update firmware for Bluetooth devices. Most people are left vulnerable to exploits that have long been patched because they pair their Bluetooth accessories through the settings and they don’t know that they need the proprietary OEM app in order to update their firmware and fix bugs in their Bluetooth headphones. With the prevalence of Bluetooth [tracking beacons](https://indoortracking.com/bluetooth-beacon-tracker-revolutionizing-indoor-positioning-and-tracking-for-businesses-track-assets-and-people-using-ble-indoor-location-systems/) and severe vulnerabilities frequently [found](https://www.csoonline.com/article/1291144/magic-keyboard-vulnerability-allows-takeover-of-ios-android-linux-and-macos-devices.html), there needs to be more strict rules about enforcing security on Bluetooth devices. Many of the security and privacy features in Bluetooth are also optional, such as [BLE Privacy](https://support.apple.com/guide/security/bluetooth-security-sec82597d97e/web) that randomized your hardware MAC address to prevent tracking via the aforementioned tracking beacons. It’s also unclear how many manufacturers release timely firmware updates or for how long they support devices, typically that information isn’t available from the OEM. It’s always an option to simply use wired accessories instead of Bluetooth if you’re really worried about future Bluetooth vulnerabilities. ### Windscribe launches privacy alliance with Addy.io, Notesnook, Kagi, and Ente URL: https://www.privacyguides.org/news/2026/01/16/windscribe-launches-privacy-alliance-with-addy-io-notesnook-kagi-and-ente/ Last updated: 2026-01-16T12:23:20.000Z Recommendations The Privacy Guides community generally recommends Addy.io, Ente, and Notesnook at this time. Windscribe and Kagi have not been evaluated the same. YMMV! On January 12, 2026, Windscribe VPN released a blog post [announcing](https://windscribe.com/blog/windscribe-partnerships/) their partnership with four major privacy-focused companies: Addy.io, Kagi, Ente, and Notesnook. Windscribe Pro subscribers can now access discounts with the aforementioned companies. As of right now, these sales are only applied to their annual subscription plans. Kailash Z., Head of Product at Windscribe VPN, describes this partnership as a means to compartmentalize product offerings used by their customers. "In a world where convenience can often lead to compromises in security," he adds, "we believe that separating these is the safest approach." Furthermore, Khailash cites the need for specialization over broad ecosystems, believing that dedicated products serve the customer experience are superior than imperfect implementations within a product ecosystem. This is not the first time these partnerships were created. Ente and Tuta launched a similar [partnership](https://tuta.com/blog/ente-friends) that enabled Tuta users to get 25% off a yearly subscription under the "Ente Friends" promotion. A longstanding debate in the privacy community has been whether to rely on a single product ecosystem or multiple products. Companies like Proton and Nextcloud market themselves as competitors to Google Workspace or Microsoft 365\. An end-to-end encrypted application ecosystem can entice new subscribers because of their integration with other services. Without viable alternatives, the average person may prefer the stability and feature-completeness offered by Big Tech ecosystems. Critics of this approach argue that these ecosystems tend to neglect quality-of-life features in favor of developing more apps. Focusing on a core product ensures feature-completeness, encouraging the development of alliances similar to Windscribe's. Product ecosystems offer both benefits and risks. Deciding whether to adopt one depends on your organization’s specific needs and threat model. ### Trail of Bits Exposes Vulnerabilities in Agentic Browsers, Compares to Cross-Site Scripting URL: https://www.privacyguides.org/news/2026/01/16/trail-of-bits-exposes-vulnerabilities-in-agentic-browsers-compares-to-cross-site-scripting/ Last updated: 2026-01-16T09:21:03.000Z Security research and consulting firm Trail of Bits [analyzed](https://blog.trailofbits.com/2026/01/13/lack-of-isolation-in-agentic-browsers-resurfaces-old-vulnerabilities/) agentic AI in browsers and found vulnerabilites that resemble [cross-site scripting](https://www.cloudflare.com/learning/security/threats/cross-site-scripting/) (XSS) and [cross-site request forgery](https://www.cloudflare.com/learning/security/threats/cross-site-request-forgery/) (CSRF) attacks. > With browser-embedded AI agents, we’re essentially starting the security journey over again. [Agentic AI](https://www.ibm.com/think/topics/agentic-ai) is AI that can perform tasks on behalf of the user, for example sending an email or organizing files. Browsers have been quick to jump on the AI train, with seem browsers even offering an AI-only experience. > The root cause of these vulnerabilities is inadequate isolation. Many users implicitly trust browsers with their most sensitive data, using them to access bank accounts, healthcare portals, and social media. The rapid, bolt-on integration of AI agents into the browser environment gives them the same access to user data and credentials. Without proper isolation, these agents can be exploited to compromise any data or service the user’s browser can reach. Agentic browsers allow AI agents to perform all kinds of actions that previously were limited to users, such as making HTTP requests, reading browser history, and accessing the [Document Object Model](https://developer.mozilla.org/en-US/docs/Web/API/Document%5FObject%5FModel) (DOM). Each capability of the AI can create data transfer between trust zones, meaning your data might be going where you don’t want it to. Trail of Bits defines a simplified list of trust zone violations: INJECTION, where untrusted input is injected into the AI, including anything that adds arbitrary data to the chat history, CTX\_IN (context in), where sensitive browsing data is added to the chat context like personal data from webpages, browsing history and the like, REV\_CTX\_IN (reverse context in), where the chat context affects browsing origins such as tools that logs a user in or changes their browsing history, and CTX\_OUT (context out), where chat context is leaked into external requests such as HTTP requests. They point out while individual trust zone violations are bad, they are much worse when combined. Along with the fact that many agentic browsers are based on versions of Chromium that are weeks or months behind in security patches and you can chain these with regular security exploits. They show some real-world attacks on agentic browsers as well. They were able to make the AI claim false information (as if they need help with that) using a GitHub Gist that instructed the AI to claim that Soviet cosmonaut Youri Gagarine was the first man on the moon, simply through the AI ingesting it via normal browser or the users specifically feeding it to the AI to summarize. This is a classic “[prompt injection](https://thehackernews.com/2026/01/researchers-reveal-reprompt-attack.html)” attack that has plagued AI due to its inability to tell the difference between instructions and user input. Another attack involves a malicious page containing a prompt injection and a [magic link](https://www.keepersecurity.com/blog/2024/03/07/magic-links-what-they-are-and-how-they-work/) that logs them into an account controlled by the attacker. When the user asks their AI to summarize the page, it silently logs them in to the attacker‘s account and the user reveals sensitive information, thinking they’re interacting with their own account. Yet another saw the AI generating a link with sensitive data, then opening the link. Agentic browsers reuse cookies for agent-initiated requests, so they were able to exfiltrate data by asking it to go to a certain website that the user is already logged in on and go to an attacker-controlled URL containing the leaked data. A slightly modified version of the same attack can infer data such as location based on the personalized results of a web search, for example searching for nearby restaurants. They also demonstrated the ability to leak personal data from any website that has interaction with other users such as Instagram, GitHub, X, Reddit, Slack, etc. simply by sending a malicious DM with instructions to copy the text from messages to other users and send it to the attacker. Finally, an attack polluting a user’s browsing history with potentially illegal content using the same trick of a malicious page or document with instructions to open a URL to whatever the attacker wants. Despite all the issues, Trail of Bits doesn’t believe the situation is hopeless and provides some suggestions for securing agentic AI browsers. Firstly, they suggest isolation between the user’s browsing and the agent’s. That means separate cookies, history, cache, everything. They should run in their own minimal browser instance. Have task-specific tools instead of overly broad tools that access multiple services, in order to limit attack surface. Provide warnings for the user to review documents instead of blindly trusting the summary, and display previews of documents directly in chat. They admit this is a bit of a weak defense as many users will simply ignore it, but it can help with shorter content. A longer-term and more robust solution is to extend the [Same-Origin Policy](https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Same-origin%5Fpolicy) (SOP) to AI agents, so that agents can’t exfiltrate data easily between different sites. They shout out frameworks such as Nvidia’s [NeMo Guardrails](https://docs.nvidia.com/nemo/guardrails/latest/index.html) for securing agent interactions as well. Finally, they suggest decoupling content processing from task planning.One way of accomplishing this is with a [dual-LLM](https://github.com/google-research/camel-prompt-injection) design: one which is more privileged that processes trusted user input and plans tasks, and a quarantined LLM with no tool access processed untrusted input. Google’s CaMeL tracks data that moves through the system via metadata tags, and it‘s able to determine whether an action is allowed to execute based on whether the sources of the data match the allowed recipients. With the rise of agentic browsers like [ChatGPT Atlas](https://chatgpt.com/atlas), [Opera Neon](https://www.operaneon.com), and Perplexity’s [Comet Browser](https://www.perplexity.ai/comet), not to mention mainstream browsers like [Chrome](https://blog.google/products-and-platforms/products/chrome/new-ai-features-for-chrome/) implementing agentic features, it’s going to be very important that the companies implementing these features take every precaution to make them as secure as possible. Agentic AI is open a hornets nest of new security problems that all need to be carefully addressed, but it seems like many companies are simply jumping onto the AI bandwagon without much thought as to how to do it securely. Agentic features are now being introduces into operating systems such as [Windows](https://developer.microsoft.com/en-us/windows/agentic/) as well. Maybe it pays to ignore the hype and tread carefully when people’s data is at stake. ### Another private equity firm acquires Threema URL: https://www.privacyguides.org/news/2026/01/16/another-private-equity-firm-acquires-threema/ Last updated: 2026-01-16T05:10:29.000Z Swiss encrypted messaging app Threema has agreed to be acquired by Comitis Capital, a German private equity firm, as of January 11, 2026. In a press release, Nikolaus Bethlen, Managing Partner of Comitis, [cites](https://comitiscapital.com/news/comitis-capital-announces-the-acquisition-of-threema) the ongoing trend of digital sovereignty and regulatory compliance in the European Union as reasons for their acquisition: > “Threema is uniquely positioned to benefit from long-term structural growth trends in secure communication, European data sovereignty and regulatory compliance. We look forward to supporting the business during its next phase of growth and build on a legacy of its trusted brand, leading technology and uncompromising privacy.” In 2020, Threema's original cofounders sold the app to private equity firm AFINUM Management but had retained leadership and a "significant share" of the company according to financial advisory firm [GCA Altium](https://majunke.com/gca-altium-advises-threema-on-its-sale-to-afinum). Notably, they have left the company entirely in 2024. The deal with Comitis Capital appears to be a secondary buyout, a transaction in which one private equity firm sells a company to another. On Mastodon, Threema [stresses](https://mastodon.social/@threemaapp/115886606738800202) that their management team, corporate mission, and core values will not change during the transition. Despite this, it is unclear whether Comitis Capital will implement significant changes in the near future. Unlike similar encrypted messengers like Signal, Threema is a paid service aimed at both enterprise and consumer usage cases. The company [claims](https://www.s-ge.com/en/exhibitor/threema-gmbh) they host more than 12 million total users worldwide and 3 million enterprise users on Threema Work. The app was closed-source until its 2020 acquisition by AFINUM Management, in which the private equity firm allowed the move according to an employee [involved](https://todon.eu/@ljrk/115886871429298156) in the transaction in an advisory capacity. ### Why Privacy is Like Broccoli URL: https://www.privacyguides.org/videos/2026/01/15/why-privacy-is-like-broccoli/ Last updated: 2026-01-16T05:09:56.000Z Believe it or not, there’s a lot of parallels between being healthy and privacy. Both seem simple on the surface but get complicated fast. Yet, both are achievable. So what can the health journey teach us about the privacy journey? In this video we break down so of the most common pitfalls people fall into when they begin to care about their privacy. One of the hardest things to do when starting new habits is to actually be consistent and make them stick, so we also talk about the best way to make those changes and make sure that you can continue them sustainably. This is a separate video from the article that appeared on the Privacy Guides blog. #### Sources 0:16 2:02 3:23 3:42 3:59 4:29 4:51 [https://www.privacyguides.org](https://www.privacyguides.org/) 5:12 5:35 6:30 6:48 7:28 ### Encrypted RCS Spotted in iOS 26.3 Beta URL: https://www.privacyguides.org/news/2026/01/13/encrypted-rcs-spotted-in-ios-26-3-beta/ Last updated: 2026-01-13T21:15:14.000Z Mention of the long-awaited RCS end-to-end encryption (E2EE) support in the iOS 26.3 beta was spotted by Tiion-X83 on X via a carrier bundle setting that would let carriers enable E2EE for RCS messaging. > Le chiffrement de bout en bout arrive sur le RCS de l’iPhone ! > > Je viens de vérifier les carrier bundles d’iOS 26.3 bêta 2, et Apple a ajouté un nouveau paramètre permettant aux opérateurs d’activer le chiffrement pour le RCS > > Pour le moment, aucun opérateur ne l’a encore activé [pic.twitter.com/RkFGH5J5ut](https://t.co/RkFGH5J5ut) > > — Tiino-X83 (@TiinoX83) [January 12, 2026](https://twitter.com/TiinoX83/status/2010830920681427199?ref%5Fsrc=twsrc%5Etfw) The GSMA [announced](https://www.gsma.com/newsroom/article/rcs-encryption-a-leap-towards-secure-and-interoperable-messaging/) its Universal Profile 3.0 back in March of 2025, with the headlining feature being cross-platform E2EE support that would bring encrypted texting by default to the masses. Utilizing the open Messaging Layer Security (MLS) [standard](https://blog.mozilla.org/en/mozilla/messaging-layer-security-is-now-an-internet-standard/), the new RCS update promised to provide modern messaging security features to the default messaging app on everyone’s phone. Google Messages offered [E2EE](https://support.google.com/messages/answer/10262381?hl=en#zippy=%2Crcs-conversations-between-google-messages-users-default-to-end-to-end-encryption) RCS messaging for a [long time](https://www.gstatic.com/messages/papers/messages%5Fe2ee.pdf), but it was limited to other Google Messages users. Google Messages also isn't available on iOS, so you would need a different app for cross-platform E2EE. Apple similarly offers E2EE between iOS users via iMessage, without offering the app on Android. With this new find, it seems that longstanding barrier could be ending. Cross-device E2EE messaging may become the new norm for the foreseeable future. SMS isn’t only used for communication, however. It’s frequently used to send two-factor authentication codes when logging in, to receive updates on deliveries, automated messages sent out to many users of a service, etc. It might take a long time for SMS to be fully replaced, meaning messengers will need to support *both* RCS *and* SMS, which is a lot of added attack surface. Not ideal in a time where activists are targeted with state-sponsored [malware](https://cybersecuritynews.com/imessage-0-click-exploit-iphone-users/) via messaging apps. We will need to switch to more robust sign-in solutions that don’t rely on unencrypted communication channels like SMS, ideally passkeys, TOTP, or FIDO hardware keys. We should be using messaging services for messaging, nothing more. Like most things, unseating SMS from its dug-in position is a multi-faceted problem, but RCS adoption is the first step in fixing it. Due to the flaws in SMS, many people rely on separate messaging apps such as WhatsApp in order to facilitate secure communications. The issue is that these apps aren’t interoperable, so if you aren’t already on someone’s messaging apps of choice, one of you needs to sign up for a new app. Between WhatsApp, Signal, Telegram, Google Messages, iMessage, Discord, and many others, it’s typical for people to be on several apps, sometimes just to talk to one or two people. This can be very annoying, lead to excess data exposure (most of these apps require some personal data to sign up, such as your phone number or email), and added security risks. There’s also inconsistent security features between them. Discord doesn’t support E2EE messaging, for example, but does support E2EE voice calls. Once support lands in iOS and Android, carriers will still need to get onboard which will take a bit longer. Currently there are no carriers enabling the feature, according to Tiino-X83’s tweet. In the time it’s taken for Universal Profile 3.0 to land in major platforms, the GSMA has [released](https://www.gsma.com/newsroom/article/elevating-the-messaging-experience-with-rcs-universal-profile-3-1/) Universal Profile 3.1 with some extra improvements to the standard. ### Instagram Password Reset Emails Sent Out to Users Unprompted URL: https://www.privacyguides.org/news/2026/01/13/instagram-password-reset-emails-sent-out-to-users-unprompted/ Last updated: 2026-01-13T19:26:12.000Z Instagram users were [sent](https://www.theverge.com/news/860337/instagram-fixed-password-reset-emails) password reset emails recently that they didn’t request, but Instagram says there was no breach of their system. Malwarebytes reported that the sensitive data of over 17.5 million Instagram accounts was compromised: > Cybercriminals stole the sensitive information of 17.5 million Instagram accounts, including usernames, physical addresses, phone numbers, email addresses, and more. This data is available for sale on the dark web and can be abused by cybercriminals. > > — [Malwarebytes (@malwarebytes.com)](https://bsky.app/profile/did:plc:xpqns3kptvh2uylrla7nuukk?ref%5Fsrc=embed) [2026-01-09T16:34:03.434328959Z](https://bsky.app/profile/did:plc:xpqns3kptvh2uylrla7nuukk/post/3mbywfybiil26?ref%5Fsrc=embed) Instagram claims that there was no breach of their systems: > We fixed an issue that let an external party request password reset emails for some people. There was no breach of our systems and your Instagram accounts are secure. > > You can ignore those emails — sorry for any confusion. > > — Instagram (@instagram) [January 11, 2026](https://twitter.com/instagram/status/2010202301886238822?ref%5Fsrc=twsrc%5Etfw) While these statements might seem contradictory, they really aren’t. The way that most of our online accounts are set up allows anyone to send out a password reset email to anyone by typing their email into the [bar](https://www.instagram.com/accounts/password/reset/). You can try it for yourself right now (sorry bob@gmail.com). Now this in and of itself doesn’t provide access to your account, but it sure can spook you. But if anyone were to intercept this reset email, they would be able to reset your password and have full access to your account. For most of our accounts, the email address tied to your account completely overrides your password, meaning anyone who has access to your emails has full reign to take over your accounts. The reason for this is because people forget their passwords, so they need a way to reset them. Everyone has an email address so that is the obvious choice for a recovery method. These password reset emails are also never end-to-end encrypted, meaning your email service provider, their email service provider, or anyone listening in on their system can intercept your emails. So in order to change the paradigm of services asking for your email on signup, we need to get rid of passwords for online accounts first. [Passkeys](https://www.passkeycentral.org/home) are stored on your device and can be synced with your password manager, so as long as you can get into your password manager, you will be able to log in to your account. This replaces the email recovery paradigm with password managers, removing the need for services to collect email in the first place or have a recovery feature at all since it’s all handled by the password manager. Unfortunately, even when a service adopts passkey support, they tend to still require an email. We should push services to stop collecting unnecessary data such as email addresses and phone numbers so we don’t need to worry about data breaches so much when they inevitably happen. Even when there’s not a data breach, services using email addresses and phone numbers expose unnecessary attack surface to their users through “features” like account recovery. Companies should embrace data minimalism and collect only the minimum data they absolutely need in order to provide their service. Otherwise, they leave their users exposed to data breaches and themselves exposed to lawsuits. The technology exists to solve this problem, we just need to embrace it. ### Google reduces AOSP source code releases, Cloudflare threatens to withdraw in Italy, California DROP Act enforced, and more! URL: https://www.privacyguides.org/livestreams/2026/01/09/google-reduces-aosp-source-code-releases-cloudflare-threatens-to-withdraw-in-italy-california-drop-act-enforced-and-more/ Last updated: 2026-01-17T17:07:23.000Z TWIP #35 _This post is for subscribers only._ ### Data Breach Roundup (Jan 2 – Jan 8, 2026) URL: https://www.privacyguides.org/news/2026/01/09/data-breach-roundup-jan-2-jan-8-2026/ Last updated: 2026-01-09T20:29:08.000Z Welcome to Data Breach Roundups, our new weekly series where we highlight notable data breaches we encounter. They're more common than you might think! If you want this weekly digest delivered to your inbox in the future, edit your newsletter settings to subscribe to the new 'Data Breach Roundups' mailing list. [Edit Newsletter Subscriptions ](https://www.privacyguides.org/#/portal/account/newsletters) ## Cryptocurrency theft attacks traced to 2022 LastPass breach You may or may not remember LastPass' 2022 data breach that was poorly handled from start to finish. It was caused by an employee's Plex server being compromised, which then pivoted to the employee's work device at home, and ultimately resulted in the leak of vaults that were poorly encrypted (or some fields were curiously never encrypted). The most notably impact of this breach has been a continual stream of cryptocurrency thefts that can be linked directly to the breach as vaults continue to be decrypted. Remember to be mindful about where you store your seed phrases and private keys. [Cryptocurrency theft attacks traced to 2022 LastPass breachBlockchain investigation firm TRM Labs says ongoing cryptocurrency thefts have been traced to the 2022 LastPass breach, with attackers draining wallets years after encrypted vaults were stolen and laundering the crypto through Russian exchanges.![](https://www.privacyguides.org/content/images/icon/bleeping-21.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/lastpass-empty-vaults.jpg)](https://www.bleepingcomputer.com/news/security/cryptocurrency-theft-attacks-traced-to-2022-lastpass-breach/) ## Covenant Health says May data breach impacted nearly 478,000 patients Covenant is a healthcare provider based out of Massachusetts providing a number of services across New England. This data breach was disclosed last year, but the number of victims has been updated. [Covenant Health says May data breach impacted nearly 478,000 patientsThe Covenant Health organization has revised to nearly 500,000 the number of individuals affected by a data breach discovered last May.![](https://www.privacyguides.org/content/images/icon/bleeping-22.ico)BleepingComputerIonut Ilascu![](https://www.privacyguides.org/content/images/thumbnail/healthcare-cyber.jpg)](https://www.bleepingcomputer.com/news/security/covenant-health-says-may-data-breach-impacted-nearly-478-000-patients/) ## Ledger customers impacted by third-party Global-e data breach Ledger - producer of hardware crypto wallets and data breaches - has exposed customer data after their third-party payment processor Global-e was hacked. The article was sparse on details but a screenshot suggests at least name and contact information were compromised. Financial information such as seed phrases was not. The article briefly notes that the attackers were able to gain access to "several other brands" and notes that Global-e also works with brains like Netflix, Disney, adidas, and several luxury brands so expect to see those names pop up again soon. [Ledger customers impacted by third-party Global-e data breachLedger is informing some customers that their personal data has been exposed after hackers breached the systems of third-party payment processor Global-e.![](https://www.privacyguides.org/content/images/icon/bleeping-23.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Ledger.jpg)](https://www.bleepingcomputer.com/news/security/ledger-customers-impacted-by-third-party-global-e-data-breach/) ## Hacktivist deletes white supremacist websites live onstage during hacker conference Apparently a hacker, during a presentation at the Chaos Communication Congress, deleted WhiteDate, WhiteChild, and WhiteDeal. Prior to that, this person scraped the personal data from WhiteDate and published it online. This included names, location, and other user-disclosed data such as pictures, age, gender, and more. The attacker says there are no emails, passwords, or DMs "for now." [Hacktivist deletes white supremacist websites live onstage during hacker conference | TechCrunchA hacker known as Martha Root broke in and deleted three white supremacist websites at the end of a talk during the annual hacker conference Chaos Communication Congress in Germany.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-19.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/martha-root-whitedate-hack-screenshot1-e1767638022105.png)](https://techcrunch.com/2026/01/05/hacktivist-deletes-white-supremacist-websites-live-on-stage-during-hacker-conference/) ## US broadband provider Brightspeed investigates breach claims Brightspeed is "one of the largest fiber broadband companies in the United States." Attackers claim to have stolen the data of over 1 million customers, including "personally identifiable information (PII), address information, user account information linked to session/user IDs (including names, emails, and phone numbers), payment history, some payment card information, and appointment/order records containing customer PII." [US broadband provider Brightspeed investigates breach claimsBrightspeed, one of the largest fiber broadband companies in the United States, is investigating security breach and data theft claims made by the Crimson Collective extortion gang.![](https://www.privacyguides.org/content/images/icon/bleeping-24.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Brightspeed.jpg)](https://www.bleepingcomputer.com/news/security/us-broadband-provider-brightspeed-investigates-breach-claims/) ## ownCloud urges users to enable MFA after credential theft reports The reports come from an Israeli cybersecurity company called Hudson Rock who claims that "multiple organizations had their self-hosted file sharing platforms (including some ownCloud Community Edition instances) breached in credential theft attacks." ownCloud stressed that the platform itself was not breached or impacted by a vulnerability, but that this was the result of infostealers. [ownCloud urges users to enable MFA after credential theft reportsFile-sharing platform ownCloud warned users today to enable multi-factor authentication (MFA) to block attackers using compromised credentials from stealing their data.![](https://www.privacyguides.org/content/images/icon/bleeping-25.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/ownCloud.jpg)](https://www.bleepingcomputer.com/news/security/owncloud-urges-users-to-enable-mfa-after-credential-theft-reports/) ## Illinois health department exposed over 700,000 residents’ personal data for years The breach goes as far back as April 2021 and was discovered and fixed in September 2025\. It impact individuals on the Medicaid and Medicare Savings Program and included address, case numbers, and "demographic data" but not names. It also impacted some individuals from the Division of Rehabilitation Services. The IDHS can't determine if anyone viewed the data or not. [Illinois health department exposed over 700,000 residents’ personal data for years | TechCrunchThe security lapse exposed personal information belonging to residents who received state benefits.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-20.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/medical-records-getty.jpg)](https://techcrunch.com/2026/01/08/illinois-health-department-exposed-over-700000-residents-personal-data-for-years/) ### Logitech macOS Software Fails, Leaving Mice and Keyboards Malfunctioning URL: https://www.privacyguides.org/news/2026/01/09/logitech-macos-software-fails-leaving-mice-and-keyboards-malfunctioning/ Last updated: 2026-01-09T19:53:21.000Z Logitech’s [G HUB](https://www.logitechg.com/en-us/software/ghub) and [Logi Options+](https://www.logitech.com/en-us/software/logi-options-plus.html) software stopped working, leaving [users](https://www.reddit.com/r/logitech/comments/1q6a3id/fck%5Fyou%5Flogitch%5Ffor%5Fthis%5Fsoftware/) who relied on it for managing their mice and keyboards high and dry. According to a Logitech employee on [Reddit](https://www.reddit.com/r/logitech/comments/1q5wxug/comment/ny63j4q/?rdt=41791), the issue was caused by an expired certificate that they used to secure interprocess communication, resulting in the software not being able to start as expected. > This was a huge error on our part. I’m extremely sorry we caused an interruption to your work. Since the issue only affected macOS users, many news outlets [reported](https://www.pcmag.com/news/logitech-mice-broke-this-week-after-its-macos-certification-expired) that the problem was caused by macOS not allowing software with an expired DeveloperID code signing certificate to run. However, according to [Jeff Johnson](https://lapcatsoftware.com/articles/2026/1/2.html) (lapcatsoftware): > The blame here lies entirely with Logitech and not with macOS or Developer ID. The Logitech software performed some *additional*, custom validation, which failed after the Logitech Developer ID code signing certificate expired. Many accessories require some kind of custom in-house app from the manufacturer in order to use all the features it has to offer, which leaves customers open to failures such as this. Your accessory not working as you expect might be the least of your concerns however. Custom apps such as G HUB and Log Options+ often require administrator permissions on installation, which is a bad precedent to set as the security researcher/app developer duo Mysk: > [ Post by @mysk@mastodon.social View on Mastodon ](https://mastodon.social/@mysk/115855311675672601) These apps are often not [sandboxed](https://developer.apple.com/documentation/xcode/configuring-the-macos-app-sandbox) and only do the bare minimum required security in order to run on your system, leaving customers open to [exploits](https://www.techtarget.com/searchsecurity/news/252454414/Project-Zero-finds-Logitech-Options-app-critically-flawed). They also tend to be required in order to update the firmware on your devices. Firmware updates are essential for the security of wireless devices like [keyboards](https://impulsec.com/cybersecurity-news/magic-keyboard-vulnerability-allows-takeover-of-ios-android-linux-and-macos-devices/) and [mice](https://bastille.net/research/vulnerabilities-mousejack/#what-is-mouse-jack). Without them, you’re leaving yourself open to potential full-device takeover. The data collection that tends to come with these apps can leave your data vulnerable to [data breaches](https://phandroid.com/2025/11/17/logitech-confirms-data-breach-from-zero-day-exploit-attack/) on the company’s servers as well. There’s a need for standardized solutions for updating and controlling wireless devices. There’s work on systems such as the [Linux Vendor Firmware Service](https://fwupd.org) that aim to give both developers and users a standardized and smooth experience updating firmware for devices, however the developer buy-in leaves a lot to be desired. Not to mention the myriad of proprietary features that come along with devices these days that require a custom app from the hardware vendor in order to control such as custom button bindings, lighting, etc. These are challenges that need to be tackled before we can really have an open and interoperable ecosystem of accessories that don’t require custom apps in order to function. In the mean time, if you can avoid it, used wired accessories or use first-party accessories that don’t need a separate app in order to update and control them. Unfortunately that’s the best option for now until the situation improves. ### Hush Line review: An accessible whistleblowing platform for journalists and lawyers alike URL: https://www.privacyguides.org/posts/2026/01/09/hush-line-review-an-accessible-whistleblowing-platform-for-journalists-and-lawyers-alike/ Last updated: 2026-01-17T17:05:16.000Z Tip lines don't work if your source does not know how to use them. Hush Line tries to make this process easier for the most vulnerable in society, but how does it actually work? _This post is for subscribers only._ ### Texas Man Rescues Daughter Using Phone's Location Feature URL: https://www.privacyguides.org/news/2026/01/07/texas-man-rescues-daughter-using-phones-location-feature/ Last updated: 2026-01-07T21:21:36.000Z A Houston [father](https://www.theguardian.com/us-news/2025/dec/28/texas-father-rescues-kidnapped-daughter-tracking-phone) was able to rescue his daughter after using her phone to track her location. Over the weekend, the 15-year-old took the dog for a walk and never came home. The father then used the parental control features to find her location, about 2 miles away. When we arrived, he found a pickup truck containing his daughter, their dog, and the kidnapper. The daughter was able to escape with help from her father. Police arrested the kidnapper "without incident." Stories like this illustrate several nuances of privacy. For one, every situation and threat model is unique and sometimes it is fair to take a slight privacy trade off for the sake of individual safety. For another, it shows that these tradeoffs can actually work sometimes. But these should be choices made by the individual, not defaults sneakily enforced by companies. It also illustrates how we can have tech that both protects us and respects us if we choose. The article didn't specify if this family was using iPhone, but they most likely were. Apple's "Find My" feature for parental controls is end-to-end-encrypted (even from Apple) and and configurable to ensure only certain apps use location data. This demonstrates that the idea of giving up privacy in exchange for features or safeties is a false dichotomy. ### Telegram Adds Passkey Support, Still Requires Phone Number URL: https://www.privacyguides.org/news/2026/01/07/telegram-adds-passkey-support-still-requires-phone-number/ Last updated: 2026-01-07T06:32:13.000Z Telegram has [added](https://telegram.org/blog/passkeys-and-gift-offers) support for [passkeys](https://fidoalliance.org/passkeys/), a secure and convenient sign-in method, replacing SMS verification codes. Passkeys are secure keys that are stored on your device and can sync with your password manager using end-to-end encryption (E2EE), allowing for secure logins across devices without having to rely on SMS codes that can be intercepted or phished, or blocked due to an interruption in cellular service. They’re also just much more convenient than passwords. According to [Microsoft](https://fidoalliance.org/case-study-microsoft/), sign in success rates jumped to 95% with passkeys from only 30% with passwords. I think most of us can relate to how annoying trying to hold the SMS notification while typing the code in can be, or switching back and forth between apps to put the code in. Unfortunately, Telegram still requires a phone number to sign up. But it’s great to see wider adoption of passkeys. This brings Telegram in line with [WhatsApp](https://faq.whatsapp.com/1850567238795036/?cms%5Fplatform=android)‘s passkey support. It might be good to see Signal incorporate passkeys, as their current account system uses a [PIN](https://support.signal.org/hc/en-us/articles/9021007554074-Open-Signal-on-your-phone-to-keep-your-account-active) for account recovery. I think passkeys would be much more convenient and secure. The SMS verification codes are easily [phished](https://www.bbc.com/news/articles/cgrnw78n1dpo), which has led to many people having their WhatsApp accounts taken over (this was before the introduction of passkeys although passkeys are still optional). On top of the security issues, the SMS verification costs Signal about [$6 million per year](https://signal.org/blog/signal-is-expensive/#:~:text=$6%20million%20dollars%20per%20year.). For a nonprofit, that’s a big chunk of change being wasted on sending insecure SMS verification codes. That’s almost half of their $14 million infrastructure costs as of the 2023 blog post. On top of this, many countries have [Know Your Customer](https://calltrackingmetrics.zendesk.com/hc/en-us/articles/23354330974989-Understanding-Know-Your-Customer-KYC) laws for obtaining a phone number. This makes the prospect of obtaining a phone number and associating it with a messenger a potential privacy risk, even if the messages themselves are E2EE. It’s a bit bizarre why so many messengers still insist on requiring a phone number. According to Signal: > [Requiring phone numbers in Signal lets people see which of their friends they can easily talk to on Signal while limiting the potential for spam within the app.](https://support.signal.org/hc/en-us/articles/6712070553754-Phone-Number-Privacy-and-Usernames#username%5Fphone%5Fnumber%5Frequired) The first reason should be optional. Users of a privacy-focused app such as Signal should have the option to choose whether they want to add a phone number and see which friends are on the app. As for the second point, that’s a bit of a tougher problem to solve. [iOS](https://developer.apple.com/documentation/devicecheck/establishing-your-app-s-integrity) and [Android](https://developer.android.com/privacy-and-security/security-key-attestation) both already have APIs to deal with device integrity. Apps like SimpleX Chat prevent this problem by making it so that you can’t just contact anyone whenever you want, you have to scan a QR code or accept an invite link first. Several other messengers such as Session, Threema, and Briar are able to operate just fine without asking for a phone number. Something tells me Signal, WhatsApp and Telegram could as well if they wanted to. Whatever the answer is, I think the smart people working at Signal and WhatsApp can come up with a better solution than using phone numbers for anti-spam. Phone numbers requirements are similar to email requirements in that they provide very little security and they allow multiple accounts to be tied together. In the case that they’re the only credential used to log in or they are used as a recovery method, they actively *harm* the security of your account. It’s time we stopped using phone numbers for something they were never meant to be used for and adopted new approaches to account security, such as passkeys. ### Multiple Vulnerabilities Found in GnuPG URL: https://www.privacyguides.org/news/2026/01/07/multiple-vulnerabilities-found-in-gnupg/ Last updated: 2026-05-29T17:58:37.000Z GNU Privacy Guard, a popular implementation of the OpenPGP standard, was found to have [multiple vulnerabilities](https://gpg.fail) including modifying the plaintext shown to the user and modifying files on the user’s system. Security researchers published their findings on [gpg.fail](https://gpg.fail) and presented a talk at the Chaos Communication Congress. The 14 listed flaws are as numerous as they are alarming, especially for such a trusted piece of software used to keep private communications safe. The first attack allows an attacker to “arbitrarily swap the plaintext shown to a *GnuPG* user, when the user verifies a detached signature versus views it with `--decrypt`.” Any situation when an attacker can swap the content of your E2EE messages is quite bad. The issue is symptomatic of how the software handles checking signatures as a whole: > In the long run, the state machine should be reworked. A lot of security-critical mechanisms like `c->any.data` and other multiple plaintext mitigations are dependent on state and are measured in brittle ways, e.g. by checking for detached vs. full/clear signatures by counting the plaintext packets while parsing, instead of checking ahead of time whether the shape of the input is sane. The next vulnerability can "lead to creation or overwrite of any file on the system the user can write to. This commonly includes regularly executed scripts and programs leading to remote code execution (RCE)." Attack number three allows a message that contains `\f\n` to have arbitrary text added at those points and still successfully verify. The attacker needs access to the plaintext and the signature for the message. There’s a vulnerability in Modification Detection Codes, which are meant to protect the integrity of the encrypted message. The problem lies in that GPG allows for inputs known to be harmful and that attackers can modify packets in a way that appears harmless. According to the researchers ”a user might be tricked into decrypting and publishing a secret encrypted message, e.g. by changing packet types of a secret message to look like a public key packet.” PGP is a standard originally from [1991](https://www.openpgp.org/about/history/#:~:text=It%20is%20based%20on%20the%20Pretty%20Good%20Privacy%20%28PGP%29%20freeware%20software%20as%20originally%20developed%20in%201991%20by%20Phil%20Zimmermann.), and as such it’s had a long and storied history of [problems](https://www.latacora.com/blog/2019/07/16/the-pgp-problem/) in and of itself, not to mention the clients such as GPG which can introduce their own issues. While it’s now an open standard called [OpenPGP](https://www.openpgp.org), it still lacks many of the features of a modern messenger like Signal. No forward secrecy so if your key leaks, all previous messages are now compromised. You have to manage your own keys, making the aforementioned scenario more likely. There’s no post-quantum encryption either leaving you potentially vulnerable to ”harvest now, decrypt later” attacks. The previous [EFAIL](https://efail.de) E2EE vulnerabilities showed just how flimsy the E2EE guarantees of OpenPGP can sometimes be: > The EFAIL attacks exploit vulnerabilities in the OpenPGP and S/MIME standards to reveal the plaintext of encrypted emails. While E2EE messengers like Signal are constantly adding new features and strengthening their security, OpenPGP is left struggling with backwards compatibility and decades of technical baggage. It leaves you wondering if OpenPGP is possible to bring up-to-snuff or if we should just scrap it and start over. Work is being done on [updating](https://datatracker.ietf.org/wg/openpgp/about/) OpenPGP with modern features such as post-quantum cryptography, forward secrecy, and improved key verification UX such as key transparency and verifying keys using a QR code. This is admirable and I’m excited to see what they’re able to do with it, however not everyone seems to be onboard. In a [blog post](https://www.gnupg.org/blog/20250117-aheinecke-on-sequoia.html) on the GPG site, they state “GnuPG and OpenPGP are extremely mature and basically "done" and “no one seriously considered GnuPG or OpenPGP to be practically vulnerable to attacks.” This is concerning when, on top of lacking modern features expected of a secure messenger, new vulnerabilities are still being found in their software. It remains to be seen what the future holds for PGP. Email is likely here to stay for the foreseeable future due to the network effect and how entangled it is with almost everything from bank accounts to online accounts. At the very least, we should push for higher standards for the software we depend on to keep our communications safe. ### Connectivity Standard Alliance Launches Aliro Standard for Smart Locks URL: https://www.privacyguides.org/news/2026/01/07/connectivity-standard-alliance-launches-aliro-standard-for-smart-locks/ Last updated: 2026-01-07T00:15:27.000Z The Connectivity Standards Alliance has launched their new standard for secure, interoperable smart locks called [Aliro](https://www.forbes.com/sites/bennyhareven/2025/12/31/why-aliro-the-new-smart-lock-standard-matters-for-the-smart-home/). The new standard promises to allow unlocking your locks with just a tap of your phone instead of needing to use an app or type a code into a keypad or use a thumbprint scanner. It will also allow cross-platform compatibility, allowing iOS, Android, and even wearables like smart watches to securely unlock smart locks. The functionality was originally available via [Apple home key](https://support.apple.com/guide/iphone/unlock-door-a-home-key-iphone-apple-watch-iph0dc255875/ios), with the option to either require your phone’s unlock method or simply allowing you to unlock by tapping your phone near the lock, dubbed *Express Mode*. There’s also the option to automatically lock your home when you leave. Apple home key is, of course, exclusive to Apple devices however. With Aliro, this functionality will be available to Android users for the first time. You can even securely allow guests into your home with a temporary access code that you can revoke later, so you don’t have to leave a key under your mat or something. There’s scant details available on the [CSA](https://csa-iot.org/all-solutions/aliro/) website about whether all of the same features will be coming to the Aliro standard, so we’ll just have to wait and see. The CSA also makes the [Matter](https://csa-iot.org/all-solutions/matter/) standard to unify IoT appliances, however Aliro is a separate standard because Matter, an IP-based networking standard, is not appropriate for the Bluetooth, Ultra-Wideband and Near-Field Communication radio-based functionality of these smart locks. It seems like we’ve seen a push in recent years toward making previously proprietary technology more standardized and interoperable. With Google making [QuickShare](https://blog.google/products/android/quick-share-airdrop/) compatible with iPhones and Apple donating its MagSafe tech to the [Qi](https://www.anker.com/qi2-wireless-charging) standard, I think we will continue seeing it more and more. We need to keep pushing for open standards and interoperability, and support laws that make companies accountable for it. Apple has a similar feature for [car keys](https://support.apple.com/en-us/118271). It’s unclear if there are plans to also standardize this feature as well, but even if that happens, it might take a bit of time for auto manufacturers to get on board. Your home keys in the Apple version are stored in your digital wallet. With the recent push from the [FIDO alliance](https://fidoalliance.org/fido-alliance-launches-new-digital-credentials-initiative-to-accelerate-and-secure-an-interoperable-digital-identity-ecosystem/) to standardize digital wallets, I wonder how this new standard will interact with those wallets, if at all. I think it might be a bit early to replace all your home locks with smart locks, however. Locks exist in the physical world and as such are beholden to the limits of the real world. Manufacturing tolerances are often exploited in regular locks to bypass them, and I would expect smart locks to be no different. No matter how secure your cryptography is, it doesn’t matter if you can simply shim it open. There’s also the matter of power: these locks tend to run on a battery that needs to be charged every so often. Although they last months typically, the lock running out of power and locking you out is still a real possibility. Good luck getting a locksmith for your fancy smart lock. Regardless, I think this is a good step for the technology. Manufacturers will likely just need some time to work out the kinks in how to make secure locks that don’t fall to basic physical attacks, although it’s not like regular locks fair much better as subscribers to the channel the Lockpicking Lawyer well know. ### Data Breach Roundup (Dec 26, 2025 – Jan 1, 2026) URL: https://www.privacyguides.org/news/2026/01/07/data-breach-roundup-dec-26-jan-1/ Last updated: 2026-01-07T18:41:46.000Z Welcome to Data Breach Roundups, our new weekly series where we highlight notable data breaches we encounter. They're more common than you might think! If you want this weekly digest delivered to your inbox in the future, edit your newsletter settings to subscribe to the new 'Data Breach Roundups' mailing list. [Edit Newsletter Subscriptions ](https://www.privacyguides.org/#/portal/account/newsletters) ### Hacker claims to leak WIRED database with 2.3 million records An attacker claims to have breached Condé Nast, an American media company. The attacker claims to have 40 million additional records for other properties. The post didn't specify but this could potentially include names like The New Yorker, Ars Technica, Vogue, Vanity Fair, and more. Data includes subscriber's unique internal ID and email address. Other data was optional - like name, phone number, physical address, and birthday. The article says many of these were left empty. [Hacker claims to leak WIRED database with 2.3 million recordsA hacker claims to have breached Condé Nast and leaked an alleged WIRED database containing more than 2.3 million subscriber records, while also warning that they plan to release up to 40 million additional records for other Condé Nast properties.![](https://www.privacyguides.org/content/images/icon/bleeping-17.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/hand-sifting-data.jpg)](https://www.bleepingcomputer.com/news/security/hacker-claims-to-leak-wired-database-with-23-million-records/) ### Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed A new massive vulnerability (8.7 out of 10) in MongoDB has been revealed - including a proof-of-concept - putting tens of thousands of servers at risk. Fixes were already released ten days ago but given the holidays (and the general track record of these things) I'm sure we can expect to see a lot of companies showing up in these weekly updates for the next several weeks. [Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposedA severe vulnerability affecting multiple MongoDB versions, dubbed MongoBleed (CVE-2025-14847), is being actively exploited in the wild, with over 80,000 potentially vulnerable servers exposed on the public web.![](https://www.privacyguides.org/content/images/icon/bleeping-18.ico)BleepingComputerIonut Ilascu![](https://www.privacyguides.org/content/images/thumbnail/mongobleed.jpg)](https://www.bleepingcomputer.com/news/security/exploited-mongobleed-flaw-leaks-mongodb-secrets-87k-servers-exposed/) ### Korean Air data breach exposes data of thousands of employees This was caused by Korean Air's in-flight catering service being hacked. News reports claim about 30,000 records were stolen. The article didn't clarify what data was stolen. [Korean Air data breach exposes data of thousands of employeesKorean Air experienced a data breach affecting thousands of employees after Korean Air Catering & Duty-Free (KC&D), its in-flight catering supplier and former subsidiary, was recently hacked.![](https://www.privacyguides.org/content/images/icon/bleeping-19.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Korean_Air.jpg)](https://www.bleepingcomputer.com/news/security/korean-air-data-breach-exposes-data-of-thousands-of-employees/) ### Trust Wallet confirms extension hack led to $7 million crypto theft A compromised Chrome extension update released on December 24 allowed attackers to steal funds. Trust Wallet has said they will cover the cost to users and are investigating further. Attackers (potentially unrelated) also launched phishing domains around the same time promising a patched version of the extension but would actually steal more funds. This is a reminder to use only trusted, custodial wallets such as Cake Wallet (ideally with Monero). [Trust Wallet confirms extension hack led to $7 million crypto theftSeveral users of the Trust Wallet Chrome extension report having their cryptocurrency wallets drained after installing a compromised extension update released on December 24, prompting an urgent response from the company and warnings to affected users. Simultaneously, BleepingComputer observed a phishing domain launched by hackers.![](https://www.privacyguides.org/content/images/icon/bleeping-16.ico)BleepingComputerAx Sharma![](https://www.privacyguides.org/content/images/thumbnail/crypto-hacker.jpg)](https://www.bleepingcomputer.com/news/security/trust-wallet-confirms-extension-hack-led-to-7-million-crypto-theft/) ### Irish EU Council Presidency, Condé Nast Breach, Voluntary Location Tracking, and More! URL: https://www.privacyguides.org/livestreams/2026/01/02/ireland-to-take-eu-council-presidency-conde-nast-breach-voluntary-location-tracking-and-more/ Last updated: 2026-01-07T18:40:54.000Z This Week in Privacy #34 _This post is for subscribers only._ ### AI Data Centers May Start Using Radio Instead of Copper URL: https://www.privacyguides.org/news/2026/01/02/ai-data-centers-may-start-using-radio-instead-of-copper/ Last updated: 2026-01-02T16:42:56.000Z AI data centers are running up against the physical limits of copper for transmitting data, so [radio](https://spectrum.ieee.org/rf-over-fiber) is being considered as a replacement. When data centers want to expand, they follow two strategies, scaling up or scaling out. Scaling out means linking more computers together to tackle a problem in chunks, while scaling up involves cramming as many GPUs together into the same computer as possible, combining their power to act as one, big GPU. > The two domains rely on two different physical connections. Scaling out mostly relies on [photonic chips and optical fiber](https://spectrum.ieee.org/optical-interconnects-imec-silicon-photonics), which together can sling data hundreds or thousands of meters. Scaling up, which results in networks that are roughly 10 times as dense, is the domain of much simpler and less costly technology—copper cables that often span no more than a meter or two. As you can imagine, these large combinations of GPUs require a lot of bandwidth between them in order to function, so much that copper can’t keep up. As data centers continue to try and pack as much compute power as they possibly can, the throughput of copper wire isn’t enough anymore. Copper cables are subject to a lot of [factors](https://www.elliottelectric.com/StaticPages/ElectricalReferences/DataComm/copper%5Fwire%5Flimits.aspx) that can cause issues with data transmission. Copper can pick up interference from nearby electrical equipment, for example through electromagnetic interference or crosstalk. This is because copper wires act as antennas and can pick up signals around them: the longer the cable, the stronger the antenna. In order to combat this, you need more shielding or shorter cables. Copper cables can also distort the signal as it travels through them. Over time, they become corroded and will need to be replaced to prevent signal distortion. The final problem with copper is that they also give off electromagnetic radiation, which can be captured and decoded out of the air. As you can imagine, this can be an issue for a data center. The solution that’s been utilized to solve this problem is fiber optic cables, which don’t suffer from the same issues. Typically these days, data centers use [fiber optic](https://spectrum.ieee.org/optics-gpu) cables to communicate between server racks. These cables can span tens or hundreds of meters in length. Fiber optic cables work great for this purpose, but they have their issues. They’re power hungry, with data centers already using about [10% of their compute power](https://spectrum.ieee.org/co-packaged-optics#:~:text=a%20staggering%2010%20percent%20of%20the%20total%20GPU%20compute%20power) just for fiber optic connections, according to Nvidia. They are finicky and can’t be bent very far before affecting the signal. They are very sensitive to temperature and they’re notoriously unreliable. So, although [companies](https://spectrum.ieee.org/optics-gpu) are making fiber optic GPU interconnects available, they’re not without drawbacks. [AttoTude](https://www.attotude.com) and [2Point](https://point2tech.com/e-tube/) are looking to replace these interconnects with radio instead, with waveguides that guide the waves to where they need to go. 2Point claims “3x Lower Power, 1000x Lower Latency, and 3x Lower Cost Than Optical Cabling. 10x Cable Reach at Similar Cost of Copper.” Quite impressive. However, whenever new technology like this rolls out, you have to wonder about possible security issues. I couldn’t find any info on how effectively they’re able to prevent RF data leakage or if they even try to, and also how resilient they are to electromagnetic interference. There are standards such as [NIST SP 800-53](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) and exist but they only cover protection against electromagnetic interference (EMI), not really against data leakage from RF. RF shielding is already a [concern](https://www.modusadvanced.com/resources/blog/rf-leakage) for data centers, so shielding solutions are already available. It’s possible to pull a video signal wirelessly from [HDMI](https://hackaday.com/2023/03/07/pulling-data-from-hdmi-rf-leakage/), for example, and there‘s plenty of other examples of data leakage over RF that you can point to in electronics The [ICD 705](https://www.davisconstruction.com/sites/default/files/2025-08/DAVIS%5FICD%20705%20RF%20Shielding%20Requirements.pdf) only covers frequencies between 10 kHz and 10 GHz, which is smaller than the [70 GHz](https://www.nature.com/articles/s41598-020-75363-4#:~:text=carrier%20frequency%20of-,70%C2%A0GHz,-and%20exhibits%20a) frequency of the new interconnect cables. As more and more of our life happens in the cloud and through cloud-based AI models, hopefully there will be stricter requirements for RF shielding in data centers. This also highlights the importance of E2EE: there are so many possible vectors of data leakage that we don’t even think about normally. Encrypting data so that it never touches any server in the clear protects not just from malicious service providers but from accidental data leakage as well. While it’s not performant enough yet for prime time, [homomorphic encryption](https://www.ibm.com/think/topics/homomorphic-encryption) could provide similar E2EE protections for cloud-based AI models in the future. ### Data Breach Roundup (Dec 19 – Dec 25, 2025) URL: https://www.privacyguides.org/news/2025/12/29/data-breach-roundup-dec-19-dec-25-2025/ Last updated: 2025-12-29T17:28:34.000Z Welcome to Data Breach Roundups, our new weekly series where we highlight notable data breaches we encounter. They're more common than you might think! If you want this weekly digest delivered to your inbox in the future, edit your newsletter settings to subscribe to the new 'Data Breach Roundups' mailing list. [Edit Newsletter Subscriptions ](https://www.privacyguides.org/#/portal/account/newsletters) ### University of Phoenix data breach impacts nearly 3.5 million individuals Yet another breach resulting from the Oracle E-Business Suite, the data belonged staff, suppliers, and current and former students. The article didn't say exactly what data was compromised. [University of Phoenix data breach impacts nearly 3.5 million individualsThe Clop ransomware gang has stolen the data of nearly 3.5 million University of Phoenix (UoPX) students, staff, and suppliers after breaching the university’s network in August.![](https://www.privacyguides.org/content/images/icon/bleeping-15.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/University-of_Phoenix.jpg)](https://www.bleepingcomputer.com/news/security/university-of-phoenix-data-breach-impacts-nearly-35-million-individuals/) ### Nissan says thousands of customers exposed in Red Hat breach This took place in September and impacted 21,000 customers in Japan. The data included full names, physical addresses, phone numbers, email addresses, and "customer data used in sales operations." [Nissan says thousands of customers exposed in Red Hat breachNissan Motor Co. Ltd. (Nissan) has confirmed that information of thousands of its customers has been compromised after the data breach at Red Hat in September.![](https://www.privacyguides.org/content/images/icon/bleeping-14.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Nissan-1.jpg)](https://www.bleepingcomputer.com/news/security/nissan-says-thousands-of-customers-exposed-in-red-hat-breach/) ### Baker University says 2024 data breach impacts 53,000 people Baker is a private university based out of Kansas with about 2,300 students and faculty. The information stolen varies from person to person, but includes name, date of birth, Driver's license number, financial account information, health insurance information, medical information, passport information, Social Security number, student identification number, and tax identification number. The fact that breaches like this can go unreported for so long without consequence is a reminder to be proactive with things like [credit freezes](https://thenewoil.org/en/guides/most-important/credit/). [Baker University says 2024 data breach impacts 53,000 peopleBaker University has disclosed a data breach after attackers gained access to its network one year ago and stole the personal, health, and financial information of over 53,000 individuals.![](https://www.privacyguides.org/content/images/icon/bleeping-13.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/Baker-University.jpg)](https://www.bleepingcomputer.com/news/security/baker-university-data-breach-impacts-over-53-000-individuals/) ### US insurance giant Aflac says hackers stole personal and health data of 22.6 million people This is an update to a breach that occurred in June, now providing a number of how many people were impacted. Data included names, dates of birth, home addresses, government-issued ID numbers (such as passports and state ID cards) and driver’s license numbers, and Social Security numbers, as well as medical and health insurance information. The company claims they have about 50 million customers, so this would be nearly half of them. [US insurance giant Aflac says hackers stole personal and health data of 22.6 million people | TechCrunchAflac, one of the largest insurance companies in the U.S., confirmed hackers stole reams of personal data, including Social Security numbers, identity documents, and health information.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-18.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-466757609.jpg)](https://techcrunch.com/2025/12/23/us-insurance-giant-aflac-says-hackers-stole-personal-and-health-data-of-22-6-million-people/) ### Flock Camera Leaks, Google Searches Accessible By Warrant, EU VPN Data Retention, and More! URL: https://www.privacyguides.org/livestreams/2025/12/26/flock-camera-leaks-google-searches-accessible-by-warrant-eu-vpn-data-retention-and-more/ Last updated: 2025-12-29T17:31:54.000Z This Week in Privacy #33 _This post is for subscribers only._ ### Cloudflare Explains Plan for Resilience After Multiple Outages URL: https://www.privacyguides.org/news/2025/12/24/cloudflare-explains-plan-for-resilience-after-multiple-outages/ Last updated: 2025-12-24T23:48:42.000Z Following multiple recent outages, Cloudflare [outlines](https://blog.cloudflare.com/fail-small-resilience-plan/) their plan to improve resilience of their network, titled “Code Orange: Fail Small.” Here, “Code Orange” is an internal designation meaning the work is being prioritized over all other work. They’ve only had to declare a [Code Orange](https://blog.cloudflare.com/major-data-center-power-failure-again-cloudflare-code-orange-tested/) once before, the name being borrowed from Google who reportedly declare a “Code Yellow” or “Code Red” for an existential threat to their business. First [outage](https://blog.cloudflare.com/18-november-2025-outage/) occurred on November 18 and the second [outage](https://blog.cloudflare.com/5-december-2025-outage/) just a few weeks later on December 5th. Cloudflare is used by about 20% of all websites according to [w3techs.com](https://w3techs.com/technologies/details/cn-cloudflare). These outages made a huge portion of websites inaccessible. Cloudflare attributes both incidents to making global changes instantaneously: > Both outages followed a similar pattern. In the moments leading up to each incident we instantaneously deployed a configuration change in our data centers in hundreds of cities around the world. They plan to focus on three main areas: - Requiring “controlled rollouts” for any configuration change that they plan to propagate across the whole network. This would reduce the chances of a huge portion of the network getting taken down just because of one bad change - Reviewing the failure modes of network infrastructure so they fail in a predictable and expected way. > If a configuration file is corrupt or out-of-range (e.g., exceeding feature caps), the system will log the error and default to a known-good state or pass traffic without scoring, rather than dropping requests. Some services will likely give the customer the option to fail open or closed in certain scenarios. This will include drift-prevention capabilities to ensure this is enforced continuously. - Avoid circular dependencies for “break glass” procedures so that customers and Cloudflare can act quickly in the face of failures Cloudflare had already been following a controlled rollout strategy for their software releases, so this change will fall in line with their already-implemented strategies. They plan on introducing a new tool: the Health Mediated Deployment (HMD) system. Every team at Cloudflare that’s responsible for a service will define what indicates a success or failure in a rollout, and a rollback procedure that will automatically happen if the team isn’t able to proceed. To improve failure modes, they are looking at every interface between critical components and assume that failure will occur between them, and handle the failure in the “most reasonable way possible.” This will prevent an unaccounted for error in one of these interfaces from spreading and causing other infrastructure to error out without the ability to easily understand what’s happening. They’re also looking to move to a “fail-open” strategy where the system won’t hard-fail from configuration issues, instead logging the error and reverting to a known-good state. Finally, they will be eliminating circular dependencies from their system. As an example, they use Turnstile for the dashboard as well, so while visitors weren’t able to get on your website because Turnstile was broken, the site owners also couldn’t log in to their dashboard to make critical changes. All of these are great changes, however the outages show how devastating putting so much of the web behind a centralized, single point of failure can be. With self-hosted options like Anubis available, it might be worth moving away from services like Cloudflare. ### The Linux Foundation Announces Formation of the Agentic AI Foundation URL: https://www.privacyguides.org/news/2025/12/24/the-linux-foundation-announces-formation-of-the-agentic-ai-foundation/ Last updated: 2025-12-24T19:48:16.000Z The Linux Foundation [announced](https://www.linuxfoundation.org/press/linux-foundation-announces-the-formation-of-the-agentic-ai-foundation) the newly formed Agentic AI Foundation to standardize and support an open, collaborative ecosystem for agentic AI. The first contributions come from [Anthropic](https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation), [Block](https://block.xyz/inside/block-anthropic-and-openai-launch-the-agentic-ai-foundation), and [OpenAI](https://openai.com/index/agentic-ai-foundation/) with their [Model Context Protocol (MCP)](https://github.com/modelcontextprotocol), [Goose](https://block.github.io/goose/), and [AGENTS.md](https://agents.md) respectively. MCP is a protocol for connecting AI agents to external systesystems, your calendar, email, files, etc that want them to have access to. This forms the basis of what is needed for [agentic AI](https://www.ibm.com/think/topics/agentic-ai), which is AI that can perform tasks on your behalf. Some examples they give are accessing your calendar to personalize your AI and allow it to make appointments, creating 3D models in Blender and print them out on printer, and connecting databases across an organization to have a unified chatbot across the organization. > The protocol has been adopted by Claude, Cursor, Microsoft Copilot, Gemini, VS Code, ChatGPT and other popular ChatGPT,forms, as developers and enterprises gravitate toward its simple integration method, security controls, and faster deployment. Goose is a local-first framework for AI that provides “standardized MCP-based integration to provide a structured, reliable, and trusted environment for building and executing agentic workflows.” Developed by Block, it is considered the reference implementation of the MCP protocol. AGENTS.md is a file that gives AI coding agents info they need to work with information such as build instructions, tests, coding conventions, etc. You can think of it as a README file for AI agents instead of humans. It might contain information that’s needed by an AI agent that humans wouldn’t need. Other contributions come from OpenAI such as the [Agentic Commerce Protocol ](https://developers.openai.com/commerce)OpenAI that allows agents to make purchases on behalf of the user, [Codex CLI](https://openai.com/codex/), an AI coding agent, and [Agents SDK](https://openai.github.io/openai-agents-python/) and [Apps SDK](https://developers.openai.com/apps-sdk/quickstart), tools built on MCP that help developers create apps that work with MCP for an interoperable app ecosystem. This announcement comes after operating systems are already trying to add agentic features, such as Windows’ [experimental agentic](https://support.microsoft.com/en-us/windows/experimental-agentic-features-a25ede8a-e4c2-4841-85a8-44839191dfb3) features. Though they’ve put a lot of work into [securing](https://blogs.windows.com/windowsexperience/2025/10/16/securing-ai-agents-on-windows/) it, it’s not clear if it’s enough. With AI agents deleting [entire databases](https://www.pcmag.com/news/vibe-coding-fiasco-replite-ai-agent-goes-rogue-deletes-company-database) and [hard drives](https://www.newsweek.com/google-ai-accidentally-deletes-hard-drive-data-antigravity-11169711), complete with signature AI lies and hallucinations. These agents need to be highly restricted in what they’re allowed to do to avoid situations such as these from happening. These agents are also vulnerable to [hijacking](https://www.nist.gov/news-events/news/2025/01/technical-blog-strengthening-ai-agent-hijacking-evaluations) by attackers. The agents will produce different outputs for the same prompt, which means attackers can try the same attack multiple times. > To demonstrate this, US AISI took the five injection tasks in the previous section and attempted each attack 25 times. After repeated attempts, the average attack success rate increased from 57% to 80%, and the attack success rate for individual tasks changed significantly. The standardization of agentic AI will help in making it smoother and more usable, but the security will still be largely down to each operating system‘s implementation. We need to proceed with extreme caution, but it seems like some companies are barreling toward agentic AI with their own ideas about how to make it secure. As frequent readers of mine will know, I’m a huge fan of standardization. On top of the interoperability it enables, it gives companies a chance to share what they have all learned, discard the bad parts, and only keep the best stuff. Proprietary products tend to suffer from lacking features that other ones have or having issues that another product has already solved. With standardization, you can decide on the best practices and implement them across an entire ecosystem. While it’s great to see standardization for the protocols, I think it’ll still be up to each operating system to determine how powerful agentic AI is. Perhaps some standardization on that front would be good as well, so they can decide on best practices for how much an AI agent should be able to do, and how to fulfill the principle of least privilege for them. That’s not to mention the issues that could happen if these AI agents are offloaded to a server somewhere. The AI should be totally local to your machine in 100% of cases, no remote AI should have control over your machine and data. In any case, it’ll be interesting to see how agentic AI plays out. I expect to see many news stories about AI agents deleting files or sending them off somewhere remote, and especially being exploited by malicious actors as it opens up entire new attacks we previously couldn’t conceive of. ### Texas sues Smart TV Makers for Spying on People's Watch Habits URL: https://www.privacyguides.org/news/2025/12/24/texas-sues-smart-tv-makers-for-spying-on-peoples-watch-habits/ Last updated: 2025-12-24T18:29:16.000Z The Texas Attorney General has [launched](https://www.bleepingcomputer.com/news/security/texas-sues-tv-makers-for-spying-on-users-selling-data-without-consent/) a lawsuit against five major smart TV manufacturers - Sony, Samsung, LG, Hisense, and TCL - over their use of Automated Content Recognition, or ACR. ACR - which is enabled by default on most (if not all) smart TVs - in which the TV will periodically take screenshots of whatever is currently being displayed and identify the content being watched. Like most privacy-invasive technologies, this is used for things like targeted advertising and content recommendations, and is usually part of aggregate data as well. According to the Texas AG's lawsuit, these manufacturers take said screenshots as often as every half second. The AG's lawsuit declares that this technology violates the privacy of Texans. ACR can be disabled in most (if not all) smart TVs, though as with many privacy-invasive settings the wording can be misleading and thus the process is not always obvious. Consumer Reports has an [article](https://www.consumerreports.org/electronics/privacy/how-to-turn-off-smart-tv-snooping-features-a4840102036/) explaining how to do so on most popular brands. With any smart device, we always recommend taking the time to check the settings to enable any security features (such as 2FA) or opt out of any privacy-invasive ones like targeted ads. ### Neobank Bunq Shares Customers’ Investments to Their Contacts Without Permission URL: https://www.privacyguides.org/news/2025/12/22/neobank-bunq-shares-customers-investments-to-their-contacts-without-permission/ Last updated: 2025-12-22T21:26:21.000Z Bunq, a Dutch neobank that’s been growing in popularity in recent years, has started sharing users’ investments with others on their contacts list, according to [RTL](https://www.rtl.nl/nieuws/economie/artikel/5543026/bunq-laat-zien-welke-aandelen-en-cryptos-jij-koopt). Sebastiaan den Boer, a user of the Bunq app, noticed that they were able to see purchases of stocks from people on your phone’s contact list while they were trying to buy some stock of their own. Supposedly the feature is just to allow you to see activity from your friends, but as Sebastiaan points out, you don’t only have your friends in your contacts list. You probably have people you haven’t spoken to in years that could end up seeing all your stock trading activity if you give the app access to your contacts. Bunq says that they have had the feature for over a year and this is the first complaint they’ve had. The app asks for several permissions when you launch it, including access to your contacts list. Sebastiaan says it’s not clear at all that the permission is used for this purpose. A year ago, Bunq caught some flak for contacting customers who were critical of the app. One customer [claimed](https://www.reddit.com/r/bunq/comments/1g4u60e/gave%5Fmy%5Fopinion%5Fon%5Fbunq%5Fhere%5Fon%5Freddit%5Fdirectly/) they were contacted by Bunq after making a Reddit post critical of the bank, with a threat to terminate their relationship. Another customer [claimed](https://www.reddit.com/r/bunq/comments/1h1qzi0/bunqs%5Fhead%5Fof%5Fcorporate%5Faffairs%5Fmessaging%5Fme%5Ffor/) they were contacted after having made edits on Bunq’s Wikipedia page. [Debanking](https://en.wikipedia.org/wiki/Debanking) has been a hot topic in recent years. With most people’s money and assets tied up in banks that they don’t control, your bank can suddenly close your account without warning, such as what [happened](https://www.news.com.au/finance/business/other-industries/melbourne-sex-worker-wins-debanking-case-against-two-australian-financial-institutions/news-story/c055907df3dd9626d97d31b40fab500f) in 2021 with a sex worker in Australia. We saw censorship from payment processors as well earlier this year, with [Steam](https://gameranx.com/updates/id/546943/article/steam-disputes-mastercards-denial-they-acted-vs-nsfw-games/) fighting Visa and Mastercard and payment processors over payment for legal content. There are so many institutions involved in a simple financial transaction, any of which could arbitrarily decide to deny the transaction. Financial institutions leveraging their power over peoples’ finances leads to censorship and discrimination, and possible silencing of those that speak out against them, leads to the same censorship and chilling effect that authoritarian governments make use of. Bunq is looking to [expand](https://press.bunq.com/255996-bunq-takes-its-first-step-into-the-us-with-broker-dealer-license-approval/) into the US and has gotten past phase one with its broker-dealer license getting approved. It’s time we demanded privacy and fairness from our financial institutions, no one should have to worry about their financial life being ruined from completely legal actions. We all deserve privacy and security in our banks. ### Data Breach Roundup (Dec 12 – Dec 18, 2025) URL: https://www.privacyguides.org/news/2025/12/20/data-breach-roundup-dec-12-dec-18-2025/ Last updated: 2025-12-20T04:42:02.000Z Welcome to Data Breach Roundups, our new weekly series where we highlight notable data breaches we encounter. They're more common than you might think! If you want this weekly digest delivered to your inbox in the future, edit your newsletter settings to subscribe to the new 'Data Breach Roundups' mailing list. [Edit Newsletter Subscriptions ](#/portal/account/newsletters) ### Flaw in photo booth maker’s website exposes customers’ pictures A researcher discovered photos accessible on the servers of Hama Film, a photo booth maker with presence in Australia, UAE, and the US. The article says that Hama Film prints out photos, so it may be possible users have no idea a copy of their photos also gets uploaded to the company's servers. The researcher said the photos do appear to be deleted every 2-3 weeks, but the company has not yet responded to the disclosure in any way. [Flaw in photo booth maker’s website exposes customers’ pictures | TechCrunchHama Film makes photo booths that upload pictures and videos online. But their back-end systems have a simple flaw that allows anyone to download customer pictures.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-13.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/photo-booth.jpg)](https://techcrunch.com/2025/12/12/flaw-in-photo-booth-makers-website-exposes-customers-pictures/) ### Home Depot exposed access to internal systems for a year, says researcher A researcher says that Home Depot exposed access to internal systems for a year after accidentally publishing a private access token online. The leak has been closed, though the researcher's initial disclosure attempts were ignored for "several weeks." [Exclusive: Home Depot exposed access to internal systems for a year, says researcherA security researcher tried to alert Home Depot to the security lapse exposing its back-end GitHub source code repos and other internal cloud systems, but was ignored.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-14.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/home-depot-2200450751.jpg)](https://techcrunch.com/2025/12/12/home-depot-exposed-access-to-internal-systems-for-a-year-says-researcher/) ### Data breach at credit check giant 700Credit affects at least 5.6 million 700Credit is a company that runs credit checks and identity verification for car dealerships nationwide in the US. Impacted people had their names, addresses, dates of birth, and Social Security numbers exposed. [Data breach at credit check giant 700Credit affects at least 5.6 million | TechCrunch700Credit, a company that runs credit checks and identity verification services for auto dealerships across the U.S., had a data breach that allowed a hacker to steal names, addresses, dates of birth, and Social Security numbers.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-15.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/social-security-cards-104145260.jpg)](https://techcrunch.com/2025/12/12/data-breach-at-credit-check-giant-700credit-affects-at-least-5-6-million/) ### PornHub extorted after hackers steal Premium member activity data This was the result of a data breach at a third-party vendor, Mixpanel, who suffered a breach in November 2025 after a successful SMS phishing attack. Pornhub says that this impacted a "limited number" of customers and said that it impacted "historical analytics" data from 2021 and earlier. Meanwhile, the cybercriminals claim to have over 200 million records totaling 94 GB, and includes sensitive data llike email address, video URL, location, time of the event, and more. [PornHub extorted after hackers steal Premium member activity dataAdult video platform PornHub is being extorted by the ShinyHunters extortion gang after the search and watch history of its Premium members was reportedly stolen in a recent Mixpanel data breach.![](https://www.privacyguides.org/content/images/icon/bleeping-5.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/PornHub.png)](https://www.bleepingcomputer.com/news/security/pornhub-extorted-after-hackers-steal-premium-member-activity-data/) ### Askul confirms theft of 740k customer records in ransomware attack Askul is a Japanese "e-commerce giant" specializing in office supplies and logistics. This breach occurred in October 2025\. Askul believes the compromise was the result of an admin account that didn't have 2FA enabled. The company has been very tight-lipped on public details. [Askul confirms theft of 740k customer records in ransomware attackJapanese e-commerce giant Askul Corporation has confirmed that RansomHouse hackers stole around 740,000 customer records in the ransomware attack it suffered in October.![](https://www.privacyguides.org/content/images/icon/bleeping-6.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/ransomware-2.jpg)](https://www.bleepingcomputer.com/news/security/askul-confirms-theft-of-740k-customer-records-in-ransomhouse-attack/) ### SoundCloud confirms breach after member data stolen, VPN access disrupted For the past several days, SoundCloud has been suffering issues. Most notably, users connecting over VPNs have reported issues connecting. We now know this was the result of a cyberattack. SoundCloud says the attacker did manage to breach data, but that this was limited to email addresses and "information already visible on public SoundCloud profiles." [SoundCloud confirms breach after member data stolen, VPN access disruptedAudio streaming platform SoundCloud has confirmed that outages and VPN connection issues over the past few days were caused by a security breach in which threat actors stole a database exposing users’ email addresses and profile information.![](https://www.privacyguides.org/content/images/icon/bleeping-7.ico)BleepingComputerLawrence Abrams![](https://www.privacyguides.org/content/images/thumbnail/soundcloud.jpg)](https://www.bleepingcomputer.com/news/security/soundcloud-confirms-breach-after-member-data-stolen-vpn-access-disrupted/) ### Tech provider for NHS England confirms data breach Another third-party breach, this one from DXS International, a company that provides unspecified "healthcare tech" for England's National Health Service. NHS has not been forthcoming with details other than the fact that a breach did occur. A ransomware group took credit for the breach and claims to have 300 GB of data. [Tech provider for NHS England confirms data breach | TechCrunchU.K.-based healthcare tech provider DXS International said it discovered and contained a data breach on Sunday. A ransomware gang took credit for the breach.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-16.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/GettyImages-1242820303-e1687524150348.jpg)](https://techcrunch.com/2025/12/18/tech-provider-for-nhs-england-confirms-data-breach/) ### University of Sydney suffers data breach exposing student and staff info This attack appears to have impacted a code repository belonging to the university. The article didn't elaborate on what sort of repository or why personal data was also stored there. Regardless, this impacted the names, dates of birth, phone numbers, home addresses, and job details of over 27,000 individuals of all roles (staff, student, alumni, and "affiliates") between 2010-2019. [University of Sydney suffers data breach exposing student and staff infoHackers gained access to an online coding repository belonging to the University of Sydney and stole files with personal information of staff and students.![](https://www.privacyguides.org/content/images/icon/bleeping-10.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/sydney01.png)](https://www.bleepingcomputer.com/news/security/university-of-sydney-suffers-data-breach-exposing-student-and-staff-info/) ### Coupang data breach traced to ex-employee who retained system access An update to a [story](https://www.privacyguides.org/news/2025/12/13/data-breach-roundup-12-5-25-12-11-25/) from last week: It has since come to light that the Coupang data breach was the result of a former employee who still had access to Coupang's systems. It's unclear if this was a malicious use of that access or if some third party (such as a cybercriminal) leveraged this access without the ex-employee's knowledge. [Coupang data breach traced to ex-employee who retained system accessA data breach at Coupang that exposed the information of 33.7 million customers has been tied to a former employee who retained access to internal systems after leaving the company.![](https://www.privacyguides.org/content/images/icon/bleeping-4.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Coupang.jpg)](https://www.bleepingcomputer.com/news/security/coupang-data-breach-traced-to-ex-employee-who-retained-system-access/) ### UK threatens free internet, Berlin’s new police powers, Samourai Wallet sentencing, and more! URL: https://www.privacyguides.org/livestreams/2025/12/19/uk-threatens-free-internet-berlins-new-police-powers-samourai-wallet-sentencing-and-more/ Last updated: 2025-12-24T18:28:41.000Z TWIP #32 _This post is for subscribers only._ ### Google Sunsets "Dark Web Report" Tool URL: https://www.privacyguides.org/news/2025/12/17/google-sunsets-dark-web-report-tool/ Last updated: 2025-12-17T14:56:18.000Z This week, Google [announced](https://www.pcmag.com/news/google-to-retire-dark-web-report-tool-that-scanned-for-leaked-user-data) they would be shutting down their "Dark Web Report" tool which would alert you if your data—such as email address, password, name, address, and more—appeared in any known dark web data breach sites, citing that "it didn't provide helpful next steps." The service was a separate offering from Google's "Results About You" service, which is one tool that we [recommend](https://www.privacyguides.org/en/data-broker-removals/#google-results-about-you-free) depending on your circumstances at *Privacy Guides* to help you manage your data online. Google went on to say they were "making this change to instead focus on tools that give you more clear, actionable steps to protect your information online." The tool will continue to function until January 15th. Data found in data breaches, of course, cannot be removed as criminals who do not listen to legal requests and probably won't respond to "asking nicely." The best any service can do is let you know what data is found. The best way to keep your data out of data breaches is to simply avoiding [giving it up](https://www.privacyguides.org/en/basics/account-creation/) in the first place: be thoughtful and selective about what services you sign up for or apps you download. Give fake information where possible. Always use strong passwords and two-factor authentication, and use encrypted options anywhere they're available. US citizens can also [freeze their credit](https://thenewoil.org/en/guides/most-important/credit/) for free, which will prevent identity thieves from opening new accounts in your name. Credit freezes are also available to some international citizens, though it may not be free. ### What can we do about the RAM and SSD shortage? URL: https://www.privacyguides.org/posts/2025/12/16/what-can-we-do-about-the-ram-and-shortage/ Last updated: 2026-01-17T17:06:24.000Z AI data centers have caused an unprecedented shortage of DRAM and NAND, increasing prices on everything from computers to smartphones. If you want to purchase a device without breaking the bank, here is what you can do so securely. _This post is for subscribers only._ ### Bad Internet Bills: KOSA, The SCREEN Act, and Repealing Section 230 URL: https://www.privacyguides.org/videos/2025/12/16/taylor-lorenz-on-kosa-the-screen-act-and-repealing-section-230/ Last updated: 2025-12-17T20:40:10.000Z Last week in the United States of America, Congress began fast-tracking nearly 20 bills in a massive effort to enact massive censorship on the internet, decimate your ability to use computers privately, and severely restrict free speech online. Your voice matters! If you think your representatives are fighting for your rights here, you're probably wrong. KOSA, the App Store Accountability Act, the SCREEN Act, and the efforts to repeal Section 230 are ****bipartisan** efforts to undermine our civil liberties on a massive scale. **Fight for the Future* has published resources through their ****Bad Internet Bills** campaign to give you the information you need to contact your representatives and demand they not support these bills. Don't let politicians, social media, and the mainstream media fool you: Your voice can make a difference, and has already stopped KOSA and similar bills from being passed for many years now. ****They are counting on you giving up, don't give in!** [Visit BadInternetBills.com ](https://www.badinternetbills.com/) In this video, *Privacy Guides* sits down with technology journalist [Taylor Lorenz](https://www.youtube.com/@TaylorLorenz) to decipher this slate of bills being fast-tracked through Congress which threaten free speech, privacy, and your right to freely access information on the internet. #### Timestamps 00:00 Introduction 00:19 Bad Internet Bills 02:46 Introduction: Taylor Lorenz 03:52 Repealing Section 230 04:57 What is Section 230? 09:37 How Does Section 230 Protect Small Websites? 11:04 How Does Section 230 Relate to Privacy? 12:48 What is the SCREEN Act? 17:13 How Would Identity Verification Work? 20:15 Identity Verification is Already Happening 22:02 What is KOSA? 23:02 KOSA is Bad For Everyone 27:03 How Would KOSA Hurt Small Websites? 29:26 KOSA Would Censor Everyone 32:56 Final Thoughts & BadInternetBills 34:48 Thanks to Taylor 34:58 Support Us! --- **Credits:** Guest: Taylor Lorenz; Hosts: Nate Bartram, Jonah Aragon; Writers: Nate Bartram, Jonah Aragon; Editors: Nate Bartram, Jordan Warne; Producers: Nate Bartram, Jonah Aragon, Jordan Warne; Executive Producer: Jonah Aragon ### Police Arrests Activist For Wiping Phone, Australia Enforces Teen Social Media Ban, Brave Dabbles In AI Browsing, and More! URL: https://www.privacyguides.org/livestreams/2025/12/13/police-arrests-activist-for-wiping-phone-australia-enforces-teen-social-media-ban-brave-dabbles-in-ai-browsing-and-more/ Last updated: 2025-12-13T01:31:09.000Z TWIP #31 _This post is for subscribers only._ ### Data Breach Roundup (12/5/25–12/11/25) URL: https://www.privacyguides.org/news/2025/12/13/data-breach-roundup-12-5-25-12-11-25/ Last updated: 2025-12-13T00:53:25.000Z Welcome to Data Breach Roundups, our new weekly series where we highlight notable data breaches we encounter. They're more common than you might think! If you want this weekly digest delivered to your inbox in the future, edit your newsletter settings to subscribe to the new 'Data Breach Roundups' mailing list. [Edit Newsletter Subscriptions ](#/portal/account/newsletters) ### Huge Trove of Nude Images Leaked by AI Image Generator Startup’s Exposed Database An AI Startup (seemingly called DreamX, although the article isn't completely clear) has left a database exposed containing over 1 million images and videos created using their image generation tools. These include so-called "nudify" images wherein AI can take completely benign, "safe-for-work" photos of real people and return images of what they might look like naked. Very little actionable information here as all the images were AI generated, not the training material. [Huge Trove of Nude Images Leaked by AI Image Generator Startup’s Exposed DatabaseAn AI image generator startup’s database was left accessible to the open internet, revealing more than 1 million images and videos, including photos of real people who had been “nudified.”![](https://www.privacyguides.org/content/images/icon/favicon-14.ico)WIREDMatt Burgess![](https://www.privacyguides.org/content/images/thumbnail/sec-ai-nudes-1365721742.jpg)](https://www.wired.com/story/huge-trove-of-nude-images-leaked-by-ai-image-generator-startups-exposed-database/) ### Pharma firm Inotiv discloses data breach after ransomware attack Inotiv is a US-based pharmaceutical research company. The company has not disclosed exactly what data was stolen, but the theft occurred on August 5-8, 2025 and impacted both current and former employees and their family members. [Pharma firm Inotiv discloses data breach after ransomware attackAmerican pharmaceutical firm Inotiv is notifying thousands of people that their personal information was stolen in an August 2025 ransomware attack.![](https://www.privacyguides.org/content/images/icon/bleeping-2.ico)BleepingComputerSergiu Gatlan![](https://www.privacyguides.org/content/images/thumbnail/inotiv.jpg)](https://www.bleepingcomputer.com/news/security/pharma-firm-inotiv-discloses-data-breach-after-ransomware-attack/) ### Petco’s security lapse affected customers’ SSNs, driver’s licenses, and more Petco is a "pet products and services giant." Last week they confirmed that they suffered a data breach back in September. The initial confirmation was scant on details but we now know a little more. We know that impacted data included names, Social Security numbers, financial account numbers, credit/debit card numbers, and dates of birth. We also know that notices were filed in Texas, California, Massachusetts, and Montana. Exact numbers remain unknown, but California requires disclosure for breaches impacting 500 residents or more. [Petco’s security lapse affected customers’ SSNs, driver’s licenses, and more | TechCrunchPetco said the exposure was due to an error in an application and that it is notifying victims whose data was affected.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-10.png)TechCrunchLorenzo Franceschi-Bicchierai![](https://www.privacyguides.org/content/images/thumbnail/petco-logo-store.jpg)](https://techcrunch.com/2025/12/08/petcos-security-lapse-affected-customers-ssns-drivers-licenses-and-more/) ### Petco takes down Vetco website after exposing customers’ personal information Earlier this week, TechCrunch discovered a vulnerability in Petco's website, allowing anyone to download customer data without any authentication required. This includes home address, email address, phone number, visit summaries, medical histories, records, forms, pretty much everything you can imagine. [Exclusive: Petco takes down Vetco website after exposing customers’ personal informationTechCrunch found Petco’s veterinary clinics were spilling customers’ personal information and medical histories of their pets to the open web.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-11.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/petco-store-1228437454.jpg)](https://techcrunch.com/2025/12/10/petco-takes-down-vetco-website-after-exposing-customers-personal-information/) ### Barts Health NHS discloses data breach after Oracle zero-day hack Barts Health NHS Trust is a major healthcare provider in England. After being attacked by the Clop ransomware gang via a widely-exploited Oracle E-business Suite zero day, the provider has announced that data was also stolen. It spans several years and impacts full names and addresses of patients. [Barts Health NHS discloses data breach after Oracle zero-day hackBarts Health NHS Trust has announced that Clop ransomware actors have stolen files from a database by exploiting a vulnerability in its Oracle E-business Suite software.![](https://www.privacyguides.org/content/images/icon/bleeping-3.ico)BleepingComputerBill Toulas![](https://www.privacyguides.org/content/images/thumbnail/Hospital.jpg)](https://www.bleepingcomputer.com/news/security/barts-health-nhs-discloses-data-breach-after-oracle-zero-day-hack/) ### CEO of South Korean retail giant Coupang resigns after massive data breach Coupang is "often compared to Amazon for its dominance in South Korean e-commerce and logistics." Last month they announced a data breach that impacted nearly 34 million people. This appears to be the latest in a number of security incidents. The breach has since been [linked](https://www.bleepingcomputer.com/news/security/coupang-data-breach-traced-to-ex-employee-who-retained-system-access/) back to a former employee's unrevoked system access, though it's unclear if that employee acted maliciously or some third party leveraged said access. [CEO of South Korean retail giant Coupang resigns after massive data breach | TechCrunchThe massive data breach at the South Korean retail giant Coupang affects more than half of the country’s population.![](https://www.privacyguides.org/content/images/icon/cropped-cropped-favicon-gradient-12.png)TechCrunchZack Whittaker![](https://www.privacyguides.org/content/images/thumbnail/coupang-large-rainbow-2250196254.jpg)](https://techcrunch.com/2025/12/10/ceo-of-south-korean-retail-giant-coupang-resigns-after-massive-data-breach/) ### Brave adds experimental agentic AI browsing feature URL: https://www.privacyguides.org/news/2025/12/12/brave-adds-experimental-agentic-ai-browsing-feature/ Last updated: 2025-12-12T01:48:53.000Z Yesterday, Brave [announced](https://brave.com/blog/ai-browsing/) that they are testing out an agentic AI browsing mode in Brave Nightly - the official testing build of their browser. Users can now test out this feature before it is implemented into regular releases. AI browsing mode functions as a part of Leo, which is Brave's resident large language learning model (LLM) that claims to not store your data. It functions solely in a dedicated user profile, meaning that it cannot access browsing data, such as cookies, of your main browsing session. This prevents the LLM from accessing confidential information that you may not want to share. The company admitted that agentic AI has a long tack record of being insecure. They are vulnerable to prompt injection attacks that allow websites to embed secret instructions into a website for the AI model to execute. These models also have the ability to retain confidential information like passwords and ID numbers into memory. Brave themselves even [disclosed](https://brave.com/blog/unseeable-prompt-injections/) several vulnerabilities affecting similar AI browsers. Brave has developed safeguards that can somewhat lessen these security concerns. Firstly, AI browsing mode utilizes models such as Claude Sonnet, which is trained to resist prompt injection attacks. This is complemented with a second "task model" or "alignment checker" that detects deviations from the original prompt. > This “alignment checker” serves as a guardrail: it receives the system prompt, the user prompt, and the task model’s response, and then checks if the task model’s instructions match the user’s intention. This checker does not *directly* receive raw website content—by firewalling it from untrusted website input, we can reduce (but not eliminate) the risk of subversion by page-level prompt injection Additional security features include a lack of access to internal websites, non-HTTPS websites, Chrome Web Store extension pages, and websites flagged by safe browsing. Users are also allowed to view proposed information to be stored into memory, allowing to detect potential prompt injection attacks and reject the storage of sensitive information. There are also company-wide restrictions. According to their privacy policy, Brave [promises](https://brave.com/privacy/browser/#brave-leo/?) to never collect your data for training purposes or store data collected from Leo. Even so, you should never input your login credentials into Leo, much less in Brave's AI browsing mode. If you decide to test it out, be careful about the information you are giving to any cloud-based LLM. Brave follows other companies experimenting with agentic AI browsing. Startups such as OpenAI and Perplexity have built Chromium‑based browsers, while established players like [Google](https://techcrunch.com/2025/11/05/google-makes-it-easier-to-access-ai-mode-in-chrome-on-ios-and-android/) and [Mozilla](https://blog.mozilla.org/en/firefox/ai-window/) now offer comparable AI browsing modes. Despite the hype, AI browsing often compromises on security and privacy. Only time will tell whether Brave's interpretation of agentic AI is safe enough for users. ### Calyx Institute founder launches private wireless carrier with questionable marketing URL: https://www.privacyguides.org/posts/2025/12/10/calyx-institute-founder-launches-private-wireless-carrier-with-questionable-marketing/ Last updated: 2025-12-10T17:52:00.000Z The Calyx Institute [underwent](https://calyxos.org/news/2025/08/01/a-letter-to-our-community/) a chaotic restructuring process ever since its founder, Nicholas Merrill, departed the organization earlier this year. Although details were unclear, it is now apparent that he desired to focus on the private sector near the end of his tenure at the nonprofit. Last Thursday, Merrill [announced](https://www.businesswire.com/news/home/20251204839897/en/Meet-Phreeli-The-Privacy-by-Design-Mobile-Carrier-You-Can-Trust) the launch of Phreeli, an American prepaid wireless carrier that promises to not collect personally-identifiable information. Unlike traditional wireless carriers, Phreeli is a mobile virtual network operator, or MVNO, based on the T-Mobile network. It joins other MVNO providers like Cape Mobile that claim to provide similar privacy protections for their customers. The only point of customer data that the carrier collects is their zip code. If account recovery is desired, email addresses are optionally used for account registration. Customers also have the choice to use anonymous payment methods such as [Monero](https://www.privacyguides.org/en/cryptocurrency/). It is unknown whether U.S. lawmakers will impose additional Know-Your-Customer (KYC) requirements for wireless carriers like Phreeli in the future. To ensure that customer account data is not linked to an individual SIM card, Phreeli enlisted Least Authority, a cybersecurity consulting firm, to develop a cryptographic protocol known as "Double-Blind Armadillo" or "Double-Blind Privacy Pass" that relies on zero-knowledge proofs. According to their official [white paper proposal](https://www.phreeli.com/files/PhreeliDoubleBlindArmadilloWhitePaper.pdf), it works by routing operations, such as SIM activation or monthly payments, through a blind “mixing” service that ensures that observers cannot link the timing of these actions to specific users. However, the white paper itself [admits](https://discuss.privacyguides.net/t/a-new-anonymous-phone-carrier-lets-you-sign-up-with-nothing-but-a-zip-code/33561/33) that Phreeli uses a "simplified" version of the Double-Blind Privacy Pass—a fact absent from their marketing materials and website. Additionally, Merrill’s recent [statement](https://www.wired.com/story/new-anonymous-phone-carrier-sign-up-with-nothing-but-a-zip-code/) in a *Wired* article suggests that Phreeli can help shield its customers from cell phone tower tracking: > The towers are T-Mobile’s, but the contracts with users—and the decisions about what private data to require from them—are Phreeli’s. “You can't control the towers. But what can you do?” he says. “You can separate the personally identifiable information of a person from their activities on the phone system.” However, reality is much more complicated than that. Even when a SIM card is acquired anonymously, users are still exposed to location‑tracking techniques such as cell‑tower triangulation or tower dumps. When a phone connects to the network, it broadcasts its unique International Mobile Equipment Identity (IMEI) number, which carriers use to pinpoint its position when they are served with a law enforcement subpoena. Thinking about obtaining a burner phone or anonymous SIM card? You can already purchase a Mint Mobile SIM card in a store with cash for significantly cheaper. Phreeli may be suitable for those who cannot obtain them otherwise. Phones are not private by design. Know this before using any cellular device for sensitive tasks. ### The FIDO Alliance Announces Standardized Digital Wallets URL: https://www.privacyguides.org/news/2025/12/10/the-fido-alliance-announces-standardized-digital-wallets/ Last updated: 2025-12-10T17:48:49.000Z The FIDO alliance, in charge of authentication standards such as the FIDO2 standard widely used in hardware keys, has announced a new [digital credentials initiative](https://fidoalliance.org/fido-alliance-digital-credentials/) aimed at standardizing and streamlining the adoption of “verifiable digital credentials and identity wallets.” The newly formed Digital Credentials Working Group (DCWG) will work closely with other standards bodies such as EMVCo, ISO, OpenID Foundation, and W3C to align the fragmented digital identity solutions into an interoperable, secure digital wallet ecosystem. The FIDO alliance cites their success in previous efforts to promote passkey adoption: > FIDO Alliance united the industry to solve the password problem, and the world is now embracing the simplicity and security of passkeys – with billions of accounts now leveraging this seachange in user authentication. We’re now aiming to bring that same proven, collaborative model to the adjacent digital credentials landscape We’ve seen several governments rolling out digital IDs, such as the [European Digital Identity](https://commission.europa.eu/topics/digital-economy-and-society/european-digital-identity%5Fen), the [Australian Digital ID](https://www.digitalidsystem.gov.au), and many [US states](https://www.tsa.gov/digital-id/participating-states). The FIDO alliance describes the ecosystem as it stands today as fragmented. Each country has its own digital ID program and usually an in-house app you have to install, and like what the [GSMA](https://www.gsma.com/newsroom/press-release/new-gsma-report-warns-that-fragmented-cybersecurity-regulation-is-raising-costs-and-increasing-risk-for-mobile-operators/) pointed out, a lack of cooperation between countries can lead to issues. They don’t explicitly say it, but I think that each country having its own wallet app can lead to mistakes being repeated, when governments could cooperate to make a standard that would work in any wallet users might want to use. The friction with relying parties and issuers is explicitly pointed to as a sore spot that needs work, presumably its a big reason why governments want to make their own in-house wallet apps in the first place. In the digital ID ecosystem, an issuer is the one that issues the credential such as the government in the case of digital IDs, and the relying party is the one accepting the credential. In their [documentation](https://fidoalliance.org/fido-alliance-digital-credentials/#:~:text=issuing%20authorities%20often,and%20other%20requirements.) on the subject, the FIDO alliance states: > \[I\]ssuing authorities often have additional requirements on the wallets into which they provision, covering things like device security, holder privacy, and credential life cycle management. The FIDO work will allow issuing authorities to confirm if a wallet being presented for provisioning has been certified against a profile representing the issuing authority’s protocol and other requirements. The FIDO alliance wants to focus on three areas: Wallet certification, drawing on their work with the FIDO certification program, will allow them to “establish certification criteria for digital wallets, ensuring they are secure, protect user privacy, and are interoperable with credential issuers and relying parties.” An issuer can be confident that a wallet certified under this program can presumably be confident that it meets a certain standard of security. It’s unclear exactly how the program will work but it would make sense to have certification “levels” like they currently do for [FIDO](https://fidoalliance.org/certification/authenticator-certification-levels/). Specification development is also on the docket, with explicit mention of presenting credentials across devices and new standards for things such as customer loyalty programs. A private version of a customer loyalty program sounds like a big improvement, since those currently can be used to track your purchases. Finally, they want to make the experience as seamless and usable as possible in order to encourage adoption. They will provide the tools and guidelines to make the transition smooth. As an example of the current fragmentation, the [TSA website](https://www.tsa.gov/digital-id/participating-states) lists which individual digital wallets are supported in each state. This simply isn’t sustainable for an open ecosystem. Open wallet standards should allow for any certified wallet to be used with any issuing authority rather than relying on in-house apps or a few specific wallet apps. User freedom and choice is important, especially for something as sensitive as ID documents. It’s unclear exactly what the end state will be of this program, but you can easily imagine an open ecosystem of digital wallets, certified by FIDO, that will provide a similar experience to that of current password managers. You’ll hopefully be able to choose any wallet you want as long as it meets a certain certification required by your government, and use it for everything from secure digital payments to rewards programs to private rewards programs and even things we can’t think of yet. In an age where [payment processors](https://soatok.blog/2025/07/24/against-the-censorship-of-adult-content-by-payment-processors/) try to control what legal content we view, a digital wallet ecosystem could enable private digital payments along the lines of [GNU Taler](https://www.taler.net/en/index.html). There’s so many possibilities for what this initiative could lead to. It’ll certainly be interesting to see what they manage to do with this. As [age verification](https://www.eff.org/deeplinks/2025/12/10-not-so-hidden-dangers-age-verification?language=en) laws are being rolled out without much thought as to how to make it secure, standards bodies like the FIDO alliance will be the ones we lean on to fix the mess that lawmakers have made. ### Atlanta activist charged with wiping phone before CBP search URL: https://www.privacyguides.org/news/2025/12/10/atlanta-activist-charged-with-wiping-phone-before-cbp-search/ Last updated: 2025-12-10T17:53:24.000Z Samuel Tunick, an Atlanta-based activist, was arrested and charged with destroying evidence after a U.S. Customs and Border Protection (CBP) unit searched his Google Pixel smartphone, 404 Media [reports](https://www.404media.co/man-charged-for-wiping-phone-before-cbp-could-search-it/). The search was conducted by the Tactical Terrorism Response Team, an elite unit of the CBP, on January 25, 2025\. Tunick supposedly erased the data of his Pixel smartphone before the CBP officer searched his device. Although the circumstances of his arrest was unclear, an official indictment [states](https://www.documentcloud.org/documents/26363121-samuel-tunick-indictment/?ref=404media.co) that Tunick allegedly did "knowingly destroy, damage, waste, dispose of, and otherwise take any action to delete the digital contents of a Google Pixel cellular phone." There is no evidence that Tunick committed any crimes beyond this charge. As of today, Tunick has been released and is awaiting further trial proceedings. He is not allowed to leave the Northern District of Georgia in the meantime. *Privacy Guides* cannot confirm if the device had [GrapheneOS](https://www.privacyguides.org/en/android/distributions/) or a similar operating system installed. GrapheneOS is exclusive to the Google Pixel series, providing features such as a [duress pin](https://grapheneos.org/features#duress) that allows users to quickly wipe data off their phone in high-risk situations. Evidence tampering is a crime in most countries. If you are caught erasing data prior to a law enforcement search, you may experience similar charges faced by Tunick. Nonetheless, journalists and activists alike may feel unnerved by this recent development. If you are a U.S. citizen or resident, many experts suggest your best bet is to not wipe your [iPhone](https://www.privacyguides.org/en/os/ios-overview/) or [Pixel](https://www.privacyguides.org/en/mobile-phones/) if you expect an imminent search or arrest. However, by setting a [strong password or passphrase](https://www.privacyguides.org/en/basics/passwords-overview/), your phone may be more resistant to forensics tools like Cellebrite. It also helps that the 5th Amendment of the Constitution protects you against self-incrimination, allowing you to withhold login information from authorities. This is most effective if your phone is in a [Before-First-Unlock (BFU) state](https://www.privacyguides.org/en/os/ios-overview/#before-first-unlock). BFU ensures that the data on your device is fully encrypted and inaccessible because you have not yet unlocked it. For those who struggle to remember longer passwords, you could also set up [biometric authentication](https://www.privacyguides.org/en/os/ios-overview/#face-idtouch-id-passcode) like face unlock or fingerprint, and manually restart your phone before a police search. This will disable biometrics entirely. If you use GrapheneOS, it has a setting that allows you to [automatically reboot](https://grapheneos.org/features#auto-reboot) your phone at a designated duration, such as every four hours, bringing your device back to a BFU state. ### India Considers Enforcing A-GPS on Mobile Devices URL: https://www.privacyguides.org/news/2025/12/09/india-considers-enforcing-a-gps-on-mobile-devices/ Last updated: 2025-12-09T07:54:26.000Z India’s government is considering a [proposal](https://www.reuters.com/sustainability/boards-policy-regulation/india-weighs-greater-phone-location-surveillance-apple-google-samsung-protest-2025-12-05/) to force smartphone manufacturers to enable GPS tracking at all times. The proposal comes courtesy of the [Cellular Operators Association of India (COAI)](https://www.coai.com/home), a non-governmental trade association representing Reliance's Jio and Bharti Airtel, some of the biggest Indian telecom companies. The proposal is in response to the Modi administration’s frustrations that they often don’t get precise locations when making legal requests to telecom firms, since they rely on [cellular tower triangulation](https://ssd.eff.org/module/mobile-phones-location-tracking) which isn’t always very precise. A-GPS, or assisted Global Positioning System, is a form of GPS that combines the satellite-based GPS with some other technology like the cellular network and nearby Wi-Fi access points to achieve a much more precise location than either technology could achieve alone. The proposal would see to it that smartphone users can't disable the technology. This would mean that location services would always have to be enabled without an option to turn them off. Apple, Google, and Samsung all oppose the move on the grounds that "the A-GPS network service ... (is) not deployed or supported for location surveillance" and that the move would be "regulatory overreach," according to a letter from the [India Cellular & Electronics Association (ICEA)](https://icea.org.in), a different non-governmental organization representing Apple and Google. India's government had scheduled to meet with the top smartphone manufacturers to discuss the matter but the meeting was postponed for unknown reasons. At this point, no decision has been made yet. This most recent government overreach comes just days after India had tried to force smartphone manufacturers to [install](https://9to5mac.com/2025/12/01/india-orders-apple-to-pre-instal-an-undeletable-state-security-app-on-iphones/) a government app by default and prevent it from being removed by users. The app, called [Sanchar Saathi](https://sancharsaathi.gov.in), is billed as a "cybersecurity" app that will help recover lost phones. Sanchar Saathi is already available for users to voluntarily download from both Apple and Google's app stores. Apple planned to outright [refuse](https://www.reuters.com/sustainability/boards-policy-regulation/apple-resist-india-order-preload-state-run-app-political-outcry-builds-2025-12-02/) the order, and the Indian government quickly backed down and [reversed](https://9to5mac.com/2025/12/03/after-apple-refusal-indian-government-completes-u-turn-on-mandatory-iphone-app/) the requirement. This followed yet *another* attempt by the Indian government to encroach on users of end-to-end encrypted messaging apps, according to the [Indian Express](https://indianexpress.com/article/business/centre-smartphone-makers-preinstall-cybersecurity-app-sanchar-saath-10395899/#:~:text=Last%20week%2C%20the,every%20six%20hours.): > Last week, the DoT issued a directive to companies like WhatsApp, Signal, and Telegram, under which users will no longer be able to access the applications without the SIM card with which they registered for the services on their phones. The directive will also mean that the companion web services, such as WhatsApp Web, will not be available uninterrupted to users, as they will be automatically logged out every six hours. The Indian government is on the warpath trying to chip away at the privacy rights of Indians. Luckily they've been unsuccessful in their latest bout but they will certainly try again. Resistance from major smartphone manufacturers clearly has a large influence on these proposed policies, so good on Apple, Google and Samsung for fighting against it and I hope they continue to do so in the future. ### Session Announces Overhaul, Proton Sheets Roll-Out, Calyx Founder Launches New Company, and More! URL: https://www.privacyguides.org/livestreams/2025/12/06/session-announces-overhaul-proton-sheets-roll-out-calyx-founder-launches-new-company-and-more/ Last updated: 2025-12-06T12:00:06.000Z This Week in Privacy #30 _This post is for subscribers only._ ### Smart toilet camera misleads customers on end-to-end-encryption URL: https://www.privacyguides.org/news/2025/12/04/smart-toilet-camera-misleads-customers-on-end-to-end-encryption/ Last updated: 2025-12-04T21:52:56.000Z Home goods manufacturer Kohler was caught misleading customers about the end-to-end encryption of the Dekoda, a smart toilet camera that analyzes pictures of your stool to determine your gut health, according to a [report](https://techcrunch.com/2025/12/03/end-to-end-encrypted-smart-toilet-camera-is-not-actually-end-to-end-encrypted/) from TechCrunch. The company [asserts](https://www.kohlerhealth.com/how-it-works/) on its website that the Dekoda is protected by several "Privacy-First Features" like a fingerprint authentication and end-to-end encryption. On the contrary, these claims [may be misleading](https://varlogsimon.leaflet.pub/3m6zrw6k2bs2p) according to a blog post by security researcher Simon Fondrie-Teitler. Kohler's privacy policy reveals that the smart toilet camera relies on Transport Layer Security (TLS) as its encryption protocol. However, TLS is primarily used by HTTPS websites, not end-to-end encrypted messaging applications like [Signal](https://www.privacyguides.org/en/real-time-communication/#signal) and iMessage. Based on information given by a company contact, Teitler argues that the company is misusing this term because images are decrypted before being processed by an machine learning algorithm. > ...emails exchanged with Kohler’s privacy contact clarified that the other “end” that can decrypt the data is Kohler themselves: “User data is encrypted at rest, when it’s stored on the user's mobile phone, toilet attachment, and on our systems. Data in transit is also encrypted end-to-end, as it travels between the user's devices and our systems, where it is decrypted and processed to provide our service.” The contact also told the security researcher that customer data is encrypted-at-rest and in-transit. The training data is supposedly de-identified; however, Teitler argues that there is reasonable suspicion that the company has the ability to decrypt the images at will. If the Dekoda was truly end-to-end encrypted, the images could not have been decrypted by Kohler in the first place. Since this term mostly refers to [user-to-user messaging apps](https://www.privacyguides.org/en/real-time-communication/) or [secure cloud storage providers](https://www.privacyguides.org/en/cloud), it is clear that the company misled customers on their data practices. [Privacy-washing](https://www.privacyguides.org/articles/2025/08/20/privacy-washing-is-a-dirty-business/) is a common technique used by companies to market their products. Instead of developing proper security or privacy features, many services oversell their capabilities to mostly mixed results. They range from comparably benign references to privacy, like [Apple’s "Privacy. That’s iPhone"](https://techcrunch.com/2019/03/14/apple-ad-focuses-on-iphones-most-marketable-feature-privacy/) advertisement campaign, to the disastrous [data breach at Flo Health](https://therecord.media/meta-flo-trial-period-tracking-data-sharing), a menstrual‑tracking app that promised users their data would remain confidential. ### Israel bans Android phones for senior officers, mandating iPhones for security URL: https://www.privacyguides.org/news/2025/12/03/israel-bans-android-phones-for-senior-officers-mandating-iphones-for-security/ Last updated: 2025-12-03T03:50:33.000Z The Israeli Defense Forces (IDF) has [issued](https://www.jpost.com/israel-news/defense-news/article-876327) a directive restricting senior officers from using Android phones because of security concerns, the Jerusalem Post reports. This follows an effort to standardize operating procedures and equipment across the IDF. Officers ranked lieutenant colonel and above are now required to use an Apple iPhone for official communications. Otherwise, they are allowed to use Android devices outside of these duties. Israeli security officials warn that Hamas runs “WhatsApp honeypot” campaigns, which are a type of social‑engineering attack. By hiding under false identities, these attackers trick soldiers into downloading malicious software. Once installed, the app steals "contacts, photos and real‑time location data." These programs are usually sideloaded, meaning that they are downloaded outside the official Google Play Store. By migrating senior officers over to iOS, it appears that this directive was primarily intended to prevent sideloading entirely. Google has long struggled with the reputation that Android devices are vulnerable to malware. To fix this, the company has [removed](https://techcrunch.com/2025/04/29/google-play-sees-47-decline-in-apps-since-start-of-last-year/) millions of apps from the Play Store in the past year and [will require](https://www.privacyguides.org/news/2025/11/17/google-plans-to-restrict-installing-apps-outside-google-play-to-experienced-users/) all developers to participate in a verification program. Open-source projects like F-Droid have [labeled](https://f-droid.org/2025/10/28/sideloading.html) this as the de-facto end of sideloading, warning that it unfairly punishes [alternative app stores](https://www.privacyguides.org/en/android/obtaining-apps/) and small open-source projects. Admittedly, Apple does implement stringent security measures into their devices. The iPhone 17 series has taken steps to mitigate memory-related vulnerabilities via [Memory Integrity Enforcement](https://www.privacyguides.org/posts/2025/09/20/memory-integrity-enforcement-changes-the-game-on-ios/) (MIE). The iOS closed ecosystem also prevents unknowing victims from installing malware onto their device. There is a valid argument that an iPhone could protect non-technically fluent individuals from similar social engineering attacks. While large institutions like the IDF may find it reasonable to restrict sideloading, standards like this one can backfire because they wrongfully communicate to the public that any single device is enough to prevent hacks. What works for one situation [cannot](https://www.privacyguides.org/en/basics/threat-modeling/) necessarily work for the average person. Owning an hardened [iPhone](https://www.privacyguides.org/en/os/ios-overview/) or [Pixel](https://www.privacyguides.org/en/mobile-phones/) does not immediately protect you against social engineering attacks. After all, what you do with your phone matters significantly more. ### Session messenger adds PFS, PQE, and other improvements URL: https://www.privacyguides.org/news/2025/12/03/session-messenger-adds-pfs-pqe-and-other-improvements/ Last updated: 2025-12-03T03:59:51.000Z Session, a popular [encrypted messenger app](https://www.privacyguides.org/en/real-time-communication/) in the privacy community, today [announced](https://getsession.org/blog/session-protocol-v2) several major updates, including one correcting one of their most commonly criticized and serious drawbacks. Session has long been divisive in the community. It began in 2020 as a fork of Signalwith several attractive improvements such as requiring no information to sign up, being onion-routed by default, and being decentralized. But Session has also drawn its fair share of criticism. Session's decentralization depends heavily on their own cryptocurrency (a polarizing topic in and of itself), while questions have been raised about how decentralized the network really is. Perhaps most glaringly, however, is that Session removed *Perfect Forward Secrecy* (*PFS*) in 2021, citing stability issues when paired with Session's decentralized architecture. PFS is—to oversimplify—a way to rotate encryption keys on a regular basis so that even if an adversary were to crack the encryption, previous (and potentially future) messages would still be encrypted. The attacker would only be able to read a specific window of messages that were encrypted using that particular set of keys. Session has long argued that their other features make PFS unnecessary: > The simple fact of the matter is that Session provides protections against these types of threats in other ways — through fully anonymous account creation, onion routing, and metadata minimisation, for example. These protections will prove as effective, or more so, in many real-world scenarios within Session’s scope and threat model. > ([Source](https://getsession.org/session-protocol-explained)) However, many—including the *Privacy Guides* community—have not been convinced. Session has not been a recommended messenger at *Privacy Guides* for quite some time, largely because of the lack of PFS. The winds might be shifting, however, as Session has just announced their "V2 Protocol" which is set to include—among other things—PFS and Post-Quantum Encryption. In their blog post, they give a rough overview of how PFS will work: > ...Accounts will establish a set of Rotating Key Pairs for each linked device and a single rotating key pair that is shared across all linked devices on a per-account basis. Per device keys are stored on each device... When a per device key rotates, the old key is deleted after a period of time, meaning if a device is compromised attackers cannot decrypt previously stored messages... Per-account keys would be kept in sync between linked devices, and these keys would be used by other senders to encrypt messages for your account and, subsequently, all of your linked devices. Per account keys also rotate frequently to ensure an attacker who compromises a device cannot decrypt historic stored messages encrypted by per account keys which are now deleted. > A critical component of the V2 Session Protocol is ensuring that devices remain synchronized as keys rotate, a significant challenge during Session’s previous implementation of PFS using the Signal Protocol. Since then, Session has introduced major infrastructure upgrades, including migrating core cryptographic logic into a shared library called libsession and developing a robust mechanism for synchronizing data across linked devices using "Config Messages". These upgrades, which are already implemented, will serve as the backbone for the V2 protocol and are expected to alleviate the synchronization issues encountered during Session’s previous PFS implementation. Session also says they took this opportunity to add Post-Quantum Encryption to their cryptography. Quantum computers are computers that use a fundamentally different architecture than modern "classical computers," giving them exponentially more processing power. The fear for privacy and security is that while classical computers would take decades or longer to crack properly-implemented modern encryption keys, quantum computers could theoretically do it in exponentially less time - days or even hours. Quantum computers are still very early in development. At this time, these concerns remain theoretical. Still, that hasn't stopped many companies from getting ahead of the curve, including [Signal](https://signal.org/blog/pqxdh/), [Tuta](https://tuta.com/blog/post-quantum-cryptography), and many others in the privacy space, as well as Big Tech companies like [Apple](https://security.apple.com/blog/imessage-pq3), [Cloudflare](https://blog.cloudflare.com/pq-2025/), and more. Session now joins their ranks by deciding to use the ML-KEM encryption standard, which is a NIST-approved post-quantum cryptography already used in both Signal and iMessage. In addition to this, another major and long-requested addition is the ability to manage linked devices (to know when your account has been linked with a new device and to remove it remotely). Session says that in the future this could be expanded to require authorization to link new devices, yet another security improvement. These new developments—particularly the re-introduction of PFS—will bring Session forward dramatically in terms of their security. The V2 Protocol is not yet finalized. Additional details will be released in 2026. --- **Editor's note:* The em-dashes (—) in this article were hand typed ;)* ### Android Authority: “Aluminium” will be code name for merger of Android and ChromeOS URL: https://www.privacyguides.org/news/2025/11/29/android-authority-aluminium-will-be-code-name-for-merger-of-android-and-chromeos/ Last updated: 2025-11-29T18:24:13.000Z According to [Android Authority](https://www.androidauthority.com/aluminium-os-android-for-pcs-3619092/), the operating system that’s meant to merge Android and ChromeOS into one, unified OS is codenamed “Aluminium OS.” We’ve known for a [while](https://www.androidauthority.com/google-combine-chrome-os-android-3577035/) that Google plans on merging Android and ChromeOS, but this is the first time a possible codename for the project has appeared. They were tipped off by a Telegram user about a senior project manager role: > While we already know Google is bringing Android to the PC, the listing explicitly states that the role involves ‘working on a new Aluminium, Android-based, operating system.’ This follows the naming scheme of their open-source Chromium browser that’s the basis of Chrome, and ChromiumOS, that forms the basis of ChromeOS. Google says its Aluminium OS is “built with artificial intelligence (AI) at the core.” The OS will likely have deep integration with their Gemini AI. What this means for the OS is anyone’s guess, but hopefully the AI integration is optional and not fundamental to how the OS works. > The new Senior Product Manager role is tasked with “driving the roadmap and curating a portfolio of ChromeOS and Aluminium Operating System (ALOS) Commercial devices across all form factors (e.g. laptops, detachables, tablets, and boxes) and tiers (e.g., Chromebook, Chromebook Plus, AL Entry, AL Mass Premium, and AL Premium) that meets the needs of users and the business.” So this confirms that ALOS will be available across all form factors. With Google’s development on desktop mode for Android, the lines between desktop and mobile are beginning to blur. Having a unified OS that can work as a traditional desktop or mobile OS will make our devices more versatile and allow us to have less devices. Imagine buying a phone that also doubles as your PC. ### Desktop Mode reaches GrapheneOS, X shows account location, Android becomes compatible with AirDrop, & more! URL: https://www.privacyguides.org/livestreams/2025/11/29/desktop-mode-reaches-grapheneos-x-shows-account-location-android-becomes-compatible-with-airdrop-more-2/ Last updated: 2025-12-04T09:08:31.000Z This Week in Privacy #29 _This post is for subscribers only._ ### Privacy Guides launches merch shop with new designs for in-person advocacy URL: https://www.privacyguides.org/press-releases/2025/11/28/privacy-guides-launches-merch-shop-with-new-designs-for-in-person-advocacy/ Last updated: 2025-11-28T20:32:29.000Z For Immediate Release — Privacy Guides, a non-profit organization focused on building a strong privacy & digital rights advocacy community, launched a new web store today featuring quality product designs for people who want to advocate for digital rights and *Privacy Guides*' resources within their local communities. ![](https://www.privacyguides.org/content/images/2025/11/pdshirt.webp) #### Defender of Privacy The Defender of Privacy uses many tools to keep their data well protected. Equipped with end-to-end encryption, libraries of knowledge, and of course Privacy Guides, you too can be a Defender of Privacy: Fighting against surveillance to protect our fundamental rights. [Shop Now](https://shop.privacyguides.org/collections/defender-of-privacy) 🌟 "This is a new way to support us while making a public statement (in style) about privacy rights" — Em, Product Designer & Staff Writer The shop, currently available at [**shop.privacyguides.org**](https://shop.privacyguides.org), features a variety of designs representing privacy-related concepts. All proceeds from the store are helping *Privacy Guides* continue its mission to advocate for privacy, and empower people with the knowledge they need to fight for their digital rights. ![](https://www.privacyguides.org/content/images/2025/11/rocksglass.webp) #### Surveillance Banner Rocks Glass The "Privacy is a Human Right" banner design (also featured on the Defender of Privacy shirts) shows a variety of invasive surveillance products being cut from their cords. [Shop Now](https://shop.privacyguides.org/products/surveillance-banner-rocks-glass) The Article 12 design represents a declaration that privacy rights are human rights. The Declaration consists of 30 articles. In point 12 is the article asserting that privacy is a fundamental right essential to everyone. ![](https://www.privacyguides.org/content/images/2025/11/art12shirt.webp) #### Article 12 T-Shirt On December 10th, 1948, the Universal Declaration of Human Rights was adopted by the United Nations General Assembly. This international document codifies an agreement between nations recognizing the rights and freedoms that are inherent to all human beings. [Shop Now](https://shop.privacyguides.org/collections/article-12) There are currently a few [designs](https://shop.privacyguides.org/pages/designs) to choose from, and like all *Privacy Guides* work, no generative AI was utilized in the creation of these products. This is the first phase of multiple pro-privacy merch designs that will be released in the future. *Privacy Guides* will also be open-sourcing these designs under a Creative Commons license to be determined within the next few months. The shop also sells [gift cards](https://shop.privacyguides.org/pages/gift-card) in time for the holiday season. In addition to using them anywhere in the shop in the future, unused gift card funds can also be converted to a Privacy Guides membership upon manual request, at a rate of $10 in gift card funds per month. You must not be a current member to redeem this offer, membership time can only be added to free subscribers. --- [Privacy Guides](https://www.privacyguides.org/) is an impartial organization that is focused on building a strong privacy advocacy community and delivering the best digital privacy and consumer technology rights advice on the internet. Its mission is to inform the public about the value of digital privacy, consumer tech rights, and about global government initiatives which aim to monitor your online activity. Privacy Guides resources are free of advertisements and not affiliated with any of the recommended providers. Privacy Guides ([**www.privacyguides.org**](https://www.privacyguides.org/)) is built by volunteers and staff members around the world. For information about Privacy Guides or this announcement, contact Jonah Aragon at [jonah@privacyguides.org](mailto:jonah@privacyguides.org). **Media Contact:** [press@privacyguides.org](mailto:press@privacyguides.org) ### IVPN announces V2Ray obfuscation on Android URL: https://www.privacyguides.org/news/2025/11/28/ivpn-announces-v2ray-obfuscation-on-android/ Last updated: 2025-11-28T20:02:16.000Z IVPN recently [announced](https://www.ivpn.net/blog/v2ray-obfuscation-available-all-ivpn-platforms/) that they now support V2Ray obfuscation on their Android client, meaning they now support it on all platforms where they offer a client. V2Ray masks WireGuard connections as regular HTTPS or HTTP traffic in order to bypass network filters designed to block VPN traffic. You can choose between V2Ray (VMESS/QUIC), which obfuscates your traffic as encrypted QUIC/TLS, and V2Ray (VMESS/TCP), which obfuscates your traffic as normal web browsing. Both protocols work with WireGuard connections in single hop and multihop. IVPN also warns of the performance impact of enabling V2Ray: > Obfuscation introduces performance overhead. Beyond the latency of the additional proxy layer, wrapping WireGuard packets inside V2Ray headers increases packet size. This can lead to data fragmentation (MTU issues), resulting in lower throughput and occasional instability compared to a standard connection. We recommend enabling V2Ray only when necessary to bypass censorship. With more and more countries seeking to [censor](https://cybernews.com/security/russia-disappearing-from-the-internet-cyberwarfare/) [the](https://iranwire.com/en/technology/125541-iranian-authorities-escalate-crackdown-on-vpns/) [internet](https://en.wikipedia.org/wiki/Great%5FFirewall), obfuscation technologies like V2Ray are more vital than ever. I’d like to see more development and standardization of other obfuscation technologies like Mullvad’s [DAITA](https://mullvad.net/en/vpn/daita) to combat the growing threat of AI traffic analysis as well. ### GSMA Report Warns of “Fragmented Cybersecurity Regulation” URL: https://www.privacyguides.org/news/2025/11/27/gsma-report-warns-of-fragmented-cybersecurity-regulation/ Last updated: 2025-11-27T03:09:12.000Z In a new [study](https://www.gsma.com/solutions-and-impact/connectivity-for-good/public-policy/wp-content/uploads/2025/11/Impact-of-Cybersecurity-Regulation-on-Mobile-Operators.pdf) by the GSMA, they criticize the state of cybersecurity regulation “including fragmented policies and regulatory frameworks, limited institutional capacity to support mobile operators, rigid or prescriptive rules, and a lack of effective platforms for threat intelligence sharing.” > As a result, operators often incur disproportionate or unnecessary costs in addressing cybersecurity concerns, and, in some cases, poorly designed policies can even increase cyber risk. Many of these challenges can be mitigated through better regulatory practices, such as more coordinated, risk-based, and outcomes-focused approaches to cybersecurity regulation. They point out the difficulties of complying with multiple different fragmented, sometimes conflicting, regulations, leading to duplicated effort and increased cost spent on complying with regulations rather than actually reducing cybersecurity threats. > Policymakers should ensure that compliance and incident reporting frameworks are aligned across sectors and policy areas. Well-designed horizontal frameworks can preserve sector-specific flexibility while supporting coherent national cybersecurity strategies. The report recommends that countries adhere to already recognized international standards set by organizations such as ISO, NIST, and GSMA, with deviations from these standards being the exception and not the rule. They bemoan the ”box-ticking” culture of compliance checklist and mandated tools as preventing the adoption of new security technologies that could protect their users more effectively. They also call out punitive and “blame-oriented” enforcement, stating that it erodes trust and discourages threat intelligence sharing, making compliance more about avoiding liability than actually preventing risk. They say that reactive regulations that result from specific incidents or media attention are more costly to comply with than a well thought-out and proactive approach. The report is an interesting read, I definitely think international standards made by experts in the field rather than politicians are the way to go. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### X (Twitter) Now Shows Your Account's Country/Region URL: https://www.privacyguides.org/news/2025/11/26/x-twitter-now-shows-your-accounts-country-region/ Last updated: 2026-01-17T17:33:19.000Z Last weekend, X released a new "About This Account" section, accessible by tapping the signup date on a profile, which reveals the location an account is based, among other information. _This post is for subscribers only._ ### Plex begins enforcing new restrictions on remote streaming this week URL: https://www.privacyguides.org/news/2025/11/26/plex-begins-enforcing-new-restrictions-on-remote-streaming-this-week/ Last updated: 2025-11-26T18:56:09.000Z Plex is no longer allowing users to remotely access personal media servers without enrolling into its Plex Pass or Remote Watch Pass subscription plans. Ars Technica [reports](https://arstechnica.com/gadgets/2025/11/plexs-crackdown-on-free-remote-streaming-access-starts-this-week/) that under the previous rules, Plex users on the free plan can allow connections from outside the home network, enabling other people to access their media library. Now, Plex Pass is required to turn on this feature for their media server. Those seeking to connect to an existing library have the option to subscribe to either Plex Pass or Remote Watch Pass. As of November 26, 2025, Plex Pass costs approximately $7 per month, while Remote Watch Pass starts at $2 per month. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) The company has enacted this change back in [April 29](https://www.plex.tv/blog/important-2025-plex-updates/), but has just started enforcing this rule. Roku users will be the first platform impacted by the new restrictions. A developer on the official Plex community forum [elaborates](https://forums.plex.tv/t/changes-coming-to-remote-streaming-on-roku/933671) on the timeline of the impacted devices and client applications: > This requirement change for remote streaming will come to all other Plex TV apps (Fire TV, Apple TV, Android TV, etc) and any third party clients using the API to offer remote streaming in **2026**. This change does not affect the ability to stream from a media server within the home network. Understandably, current Plex users may still want to find alternatives for remote access because of the subscription requirement. One notable example is [Jellyfin](https://jellyfin.org/), which is a free and open source media server client that allow secure remote connections through a service like [Tailscale](https://jellyfin.org/docs/general/post-install/networking/tailscale/). Advanced users also have the option of self-hosting a Wireguard VPN or utilizing a [reverse proxy](https://jellyfin.org/docs/general/post-install/networking/reverse-proxy/) to access the server. There are other reasons for switching as well. Although Plex [claims](https://www.plex.tv/about/privacy-legal/) in their Privacy Policy to not collect or process data from personal media libraries, the company has a track record of data breaches and exploited vulnerabilities. Last September, the company experienced an [incident](https://forums.plex.tv/t/important-notice-of-security-incident/930523) that exposed customer email address, usernames, and hashed passwords. Although the extent of the breach was limited, you may want to think twice before trusting a self-hosted service that requires account registration. Regardless of whether you use Jellyfin or Plex, self‑hosting a media server raises several security concerns. [Misconfiguring](https://www.xda-developers.com/nas-security-mistakes-and-fixes/) your remote connection method can unintentionally expose it to hackers. Additionally, most popular media server clients lack proper application sandboxing, which [contributed](https://thehackernews.com/2023/03/lastpass-hack-engineers-failure-to.html) to a major data breach at LastPass when an engineer’s outdated Plex server was compromised. When you share your media library with friends or family, treat it like managing a server and remember to follow basic security practices like any System Administrator would do. ### GrapheneOS Now Has Experimental Support for Pixel 10 Series URL: https://www.privacyguides.org/news/2025/11/26/grapheneos-now-has-experimental-support-for-pixel-10-series/ Last updated: 2025-11-26T18:29:22.000Z GrapheneOS [announced](https://grapheneos.social/@GrapheneOS/115613410154853462) that they now have experimental support for the Pixel 10, Pixel 10 Pro, Pixel 10 Pro XL and Pixel 10 Pro Fold. Ever since Google announced that they will no longer release the [device trees](https://www.androidauthority.com/google-not-killing-aosp-3566882/) for Pixels as open source, making it difficult for any custom AOSP-based operating systems to ship support for the devices. Pixels have historically been the reference devices for Android, however Google says it wants to make virtual machine Android device called “Cuttlefish” the reference devices going forward. Despite this, the GrapheneOS team are pushing forward with Pixel 10 device support. You can install it from their [staging site](https://staging.grapheneos.org/install/web), however since the support is experimental, don’t expect a perfectly stable experience until it’s fully released into stable. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Data Breach Disrupts Emergency Alert Systems URL: https://www.privacyguides.org/news/2025/11/26/data-breach-disrupts-emergency-alert-systems/ Last updated: 2025-11-26T08:01:41.000Z A cyberattack forced Crisis24 to decommission parts of CodeRED, an emergency notification system used widely across the US by governments, police, and fire agencies. According to [Bleeping Computer](https://www.bleepingcomputer.com/news/security/onsolve-codered-cyberattack-disrupts-emergency-alert-systems-nationwide/), CodeRED is used for emergency notifications, weather alerts, and other "sensitive warnings." It is run by risk management company Crisis24\. After the initial cyberattack, Crisis24 was forced to decommission the "legacy" CodeRED environment, which was apparently still in use among a large number of organizations. The company is rebuilding their backups onto the newer version of the platform, but backup is from March 31 of this year and thus is likely missing important data. To make matters worse, Crisis24 has confirmed that data was stolen during the attack. This includes names, addresses, email addresses, phone numbers, and passwords for user profiles. Crisis24 has said that they've seen "no indication that the stolen data has been publicly published," but Bleeping Computer asserts that INC Ransomware has already posted the data for sale online. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Trail of Bits Adds Constant Time Support to LLVM, Bolstering Encryption Security URL: https://www.privacyguides.org/news/2025/11/26/trail-of-bits-adds-constant-time-support-to-llvm-bolstering-encryption-security/ Last updated: 2025-11-26T06:30:45.000Z Today, Trail of Bits [announced](https://blog.trailofbits.com/2025/11/25/constant-time-support-lands-in-llvm-protecting-cryptographic-code-at-the-compiler-level/) they’ve added constant-time coding support for LLVM, “providing developers with compiler-level guarantees that their cryptographic implementations remain secure against branching-related timing attacks.” [LLVM](https://www.llvm.org) forms the basis of many widely-used compilers such as Clang. Compilers usually try to optimize code, which normally is a great thing. But for cryptography, it can be a huge issue. > The problem is that any data-dependent behavior in the compiled code would create a timing side channel. If the compiler introduces a branch like `if (i == secret_idx)`, the CPU will take different amounts of time depending on whether the branch is taken. Modern CPUs have branch predictors that learn patterns, making correctly predicted branches faster than mispredicted ones. An attacker who can measure these timing differences across many executions can statistically determine which index is being accessed, effectively recovering the secret. Even small timing variations of a few CPU cycles can be exploited with sufficient measurements. What you want is constant-time code, meaning that the input will not affect the amount of time the code takes to execute, thus avoiding timing attacks. To that end, the Trail of Bits team have developed a new family of intrinsics, or built-in functions in the compiler, that will guarantee code that’s meant to be constant-time will stay that way. > Unlike regular code that the optimizer freely rearranges and transforms, this intrinsic acts as a barrier. The optimizer recognizes it as a security-critical operation and preserves its constant-time properties through every compilation stage, from source code to assembly. They mention a [study](https://arxiv.org/pdf/2410.13489) that found that compilers break constant-time guarantees in numerous production cryptographic libraries. With their new intrinsic, they report minimal performance overhead, 100% preservation of constant-time properties, and already successful integration with several major cryptographic libraries. Several languages have already expressed interest in adopting the new intrinsic, including Rust, Swift, and WebAssembly. With attacks like [Spectre](https://spectreattack.com) and [GoFetch](https://gofetch.fail) still fresh on people’s minds, hopefully protections like this can keep our cryptography safe. ### Dartmouth College Confirms Data Breach URL: https://www.privacyguides.org/news/2025/11/26/dartmouth-college-confirms-data-breach/ Last updated: 2025-11-26T04:30:22.000Z Dartmouth, a private Ivy League university in New England, has disclosed a data breach. In a letter filed with the Maine Attorney General's office, Dartmouth disclosed that the data of just shy of 1,500 individuals was impacted via an exploited zero day in Oracle's E-Business Suite. [Bleeping Computer](https://www.bleepingcomputer.com/news/security/dartmouth-college-confirms-data-breach-after-clop-extortion-attack/) speculates the final tally could be much larger as Dartmouth hasn't finished notifying all the relevant authorities. Details are scant at this time about exactly what data was compromised, but it appears to include at very least name and financial account information. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Malware Delivered Through Blender Downloads on Third-Party Sites URL: https://www.privacyguides.org/news/2025/11/26/malware-delivered-through-blender-downloads-on-third-party-sites/ Last updated: 2025-11-26T04:00:48.000Z Malicious Blender files uploaded to third-party download sites have turned out to contain infostealer malware. According to [Bleeping Computer](https://www.bleepingcomputer.com/news/security/malicious-blender-model-files-deliver-stealc-infostealing-malware/), the campaign is linked to Russia and delivers the StealC V2 malware through third party marketplaces such as CGTrader. Blender is a powerful and popular FOSS video editor. It is capable of rendering in 3D and is used for animation, visual effects, and even virtual reality, video games, and entire movies. It has been [used](https://en.wikipedia.org/wiki/Blender%5F%28software%29#Use%5Fin%5Findustry) widely in the entertainment industry on films and shows like *Spider-Man 2*, *Captain America: The Winter Soldier*, *Wonder Woman*, and the Academy Award-winning *Flow*. Bleeping Computer notes that the attack was able to run because many users enable the "Auto Run" feature. If enabled, the malicious download would automatically fetch malware from an external resource, then proceed to silently install and run said malware. The malware is designed to be persistent across reboots and even comes with a second infostealer, possibly as a backup. The latest StealC malware is capable of exfiltrating data from over 23 browsers, more than 100 cryptocurrency wallets, and over 15 crypto wallet apps. It can also steal data from Telegram and Discord, as well as VPN clients (including OpenVPN) and mail clients such as Thunderbird. All this while bypassing User Account Control (UAC), a pop-up on Windows that prompts users to confirm any major actions such as installing new software or running programs as administrator. Bleeping Computer specifically mentions the use of Auto Run as a key attack vector here and offers instructions on how to disable it, but there are a couple other possible points of defense in this scenario as well. For one, users should always get their software directly from the source (in this case, that means blender.org, which features a direct download link, or there's an official Snap available to Linux users). Users - particularly on Desktop - are also strongly encouraged to create a non-admin account and do their day-to-day work there. A non-admin account requires not just a basic "yes or no" pop up on Windows, but the user must also enter the administrator password. This would likely thwart a basic UAC bypass. This attack illustrates the value of **Defense in Depth**, the practice of layering multiple levels of defense so that if one gets breached the others may still provide protection. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### U.S. National Parks Will Soon Require Proof of Residency or Charge Higher Rates URL: https://www.privacyguides.org/news/2025/11/26/u-s-national-parks-will-soon-require-proof-of-residency-or-charge-higher-rates/ Last updated: 2025-11-26T02:56:21.000Z Today, the United States Department of the Interior [announced](https://www.doi.gov/pressreleases/department-interior-announces-modernized-more-affordable-national-park-access) changes to how national parks are accessed beginning Jan. 1, 2026\. In addition to new digital passes and graphics, they are implementing so-called "America-first entry fee policies" to create a two-tiered pricing system. The new pricing for an annual pass will be over 3 times higher for non-residents, while remaining the same for residents. While much of the [coverage](https://www.nytimes.com/2025/11/25/us/politics/national-parks-prices-tourists-trump.html) of this change has focused on the increased charges facing foreign tourists and the negative [impact](https://economictimes.indiatimes.com/news/international/us/visiting-us-parks-just-got-pricier-for-foreign-tourists-thanks-to-trumps-new-order/articleshow/122253103.cms) this will likely have on the United States' tourism industry overall, the Trump administration's new plan also means that residents of the United States will face increased identity or citizenship verification when visiting national parks in the country. The U.S. federal government has been on a ID tear lately, recently [partnering](https://www.privacyguides.org/news/2025/11/15/apple-launches-digital-id-feature-nationwide-in-the-united-states/) with Apple to enable Digital IDs for [age verification](https://www.privacyguides.org/posts/tag/age-verification/) and other purposes through the existing passport system. And earlier this year, the last holdout states against Real ID gave in, making Real ID a nationwide requirement for domestic air travel and to enter federal buildings. The Real ID Act was passed in 2005 by the Bush administration, after it was [added at the last minute](https://web.archive.org/web/20131207014008/http://www.wired.com/politics/security/news/2005/05/67471) to a tsunami relief and Iraq war funding bill without any Senate committee hearings conducted on the Act. While many countries around the world embrace centralized national ID systems as a tool of efficiency, U.S. citizens have historically resisted the implementation of such systems out of concerns for privacy and state sovereignty. Many critics and civil liberties groups argue that national IDs create a dangerous environment where any interaction may be monitored. [According to the EFF:](https://www.eff.org/issues/national-ids) > National ID cards and the databases behind them comprise the cornerstone of government surveillance systems that creates risks to privacy and anonymity. The requirement to produce identity cards on demand habituates citizens into participating in their own surveillance and social control The United States still does not have a singular national ID system, but increasing identification requirements in areas where they weren't previously required is yet another artificial way to make it seem like a national ID is "necessary." It seems that this new requirement from the National Parks Service is just another step in the federal government's march towards ubiquitous identification requirements. Reportedly, not producing valid proof of residency will mean U.S. citizens will simply have to pay the new nonresidents rate of $250 for an annual pass, as opposed to $80\. Pricing for other passes besides the annual pass will also be differentiated between residents and nonresidents. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### State-sponsored spyware campaign targeting Signal and WhatsApp, CISA warns URL: https://www.privacyguides.org/news/2025/11/26/state-sponsored-spyware-campaign-targeting-signal-and-whatsapp-cisa-warns/ Last updated: 2025-11-26T00:30:09.000Z The Cybersecurity and Infrastructure Agency (CISA) [issued](https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications) an alert on Monday warning of a state-sponsored spyware campaign targeting [Signal](https://www.privacyguides.org/en/real-time-communication/#signal) and WhatsApp. The alert mentioned several attack vectors that these threat actors use, including undisclosed zero-day vulnerabilities, malicious device-linking QR codes, and impersonation of official messaging apps. Although victim selection remains opportunistic, CISA believes these threat actors focus on high-value government, political, and military officials. CISA cites two known campaigns targeting Signal and WhatsApp users. The first one being a Russian-affiliated remote phishing operation targeting Signal users in Ukraine. According to a Google Threat Intelligence Group blog, these attacks [exploit](https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/) Signal's Linked Device feature to generate malicious QR codes that pretend to serve another function. > In remote phishing operations observed to date, malicious QR codes have frequently been masked as legitimate Signal resources, such as group invites, security alerts, or as legitimate device pairing instructions from the Signal website. In more tailored remote phishing operations, malicious device-linking QR codes have been embedded in phishing pages crafted to appear as specialized applications used by the Ukrainian military. WhatsApp also includes a Linked Device feature that allows its users to connect non-smartphone devices to their account, which has been [exploited](https://www.certosoftware.com/insights/secret-surveillance-how-abusers-are-exploiting-whatsapps-linked-devices-feature/) by hackers before. The difference lies mostly in Signal's userbase consisting of activists, journalists, and government officials. CISA states that state-sponsored threat actors may deem this demographic lucrative for remote phishing operations. The second incident refers to a Palo Alto Group Unit 42 disclosure [report](https://unit42.paloaltonetworks.com/landfall-is-new-commercial-grade-android-spyware/) on LANDFALL, a commercial spyware software that targets Samsung Galaxy devices across the Middle East. LANDFALL works by embedding itself into malicious images in .DNG format, which is then sent and executed through a known WhatsApp exploit. Notably, the photos were designed specifically to function over this application based on the filenames. > Filenames with strings like WhatsApp Image and WA000 imply attackers could have attempted to deliver the embedded Android spyware via WhatsApp. This matches [earlier public reporting](https://thehackernews.com/2025/08/whatsapp-issues-emergency-update-for.html) of similar DNG image-based exploitation through WhatsApp targeting Apple devices. Furthermore, WhatsApp researchers identified and reported a similar DNG vulnerability, [CVE-2025-21043](https://nvd.nist.gov/vuln/detail/CVE-2025-21043), to [Samsung](https://security.samsungmobile.com/securityUpdate.smsb#:~:text=SVE%2D2025%2D0954-,Meta%20and%20WhatsApp%20Security%20Teams%3A%20SVE%2D2025%2D1702,-SMR%2DAUG%2D2025). Remember that end-to-end encrypted messaging applications cannot protect you against zero-day vulnerabilities or social engineering attacks. Even if you use our recommended services like Signal, [SimpleX](https://www.privacyguides.org/en/real-time-communication/#simplex-chat), or [Matrix](https://www.privacyguides.org/en/social-networks/#posting-content), always ensure that you disable automatic image downloading and URL previews. Do not click on suspicious links or scan untrusted QR codes. Are you still concerned about state-sponsored spyware? Consider reading our knowledge base article on common threat models such as [targeted attacks](https://www.privacyguides.org/en/basics/common-threats/#attacks-against-specific-individuals). You should also review the basic security concepts of your preferred [operating system](https://www.privacyguides.org/en/os/) or [device](https://www.privacyguides.org/en/basics/hardware/). Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Malaysia Considers Social Media Ban for Minors URL: https://www.privacyguides.org/news/2025/11/25/malaysia-considers-social-media-ban-for-minors/ Last updated: 2025-11-25T23:46:03.000Z Malaysia [might](https://techcrunch.com/2025/11/24/malaysia-may-ban-users-under-16-from-social-media-starting-next-year/) join the ranks of countries banning social media for minors. According to TechCrunch, the country's communication minister has reportedly said the administration is considering systems that could enforce the restricting of children under 16 from sites like Facebook and X. Australia led the way in implementing such a law, and France, Denmark, Italy, and Norway are considering joining. Twenty-four US states have already enacted some type of age verification law. Perhaps most notably - and most disastrously - has been the UK's Online Safety Act, which came dangerously close to [banning](https://therecord.media/online-safety-bill-uk-end-to-end-encryption) end-to-end encryption. Age verification schemes often do more harm than good, as noted in the case of the Online Safety Act which has been directly responsible for a data breach at [Discord](https://www.bbc.com/news/articles/c8jmzd972leo) which leaked user IDs and the [closing](https://www.spectator.co.uk/article/ctrl-u-the-online-safety-act-is-shutting-down-the-internet/) down of multiple online communities. In m and the spike in downloads of free VPNs. They are also largely ineffective, pushing users away from existing, reputable platforms toward less regulated or potentially sketchy sites and [services](https://dig.watch/updates/free-vpn-use-surges-in-uk-after-online-safety-law) that may not protect user data (or, in the case of adult sites specifically, may not moderate out content such as CSAM or "revenge porn"). While we at *Privacy Guides* acknowledge that the internet can be a dangerous place in some ways, we believe that existing solutions are too easy to bypass and don't do enough to protect user privacy or free speech, while also ignoring the fact that many of the harms of the platforms being age gated also impact adult users. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Signal Rolls Out Secure Backups for iOS in Beta URL: https://www.privacyguides.org/news/2025/11/25/signal-rolls-out-secure-backups-for-ios-in-beta/ Last updated: 2025-11-25T22:10:08.000Z Signal has rolled out secure end-to-end encrypted backups for iOS users, after Android users already got the features months earlier. If you use Signal on iOS, update your client and you will find a new setting: [Backups](https://support.signal.org/hc/en-us/articles/9708267671322-Signal-Secure-Backups). Signal began rolling out the Android version of the feature back in [September](https://signal.org/blog/introducing-secure-backups/), but they announce their intentions to add the feature to iOS and Desktop. Now the wait is over for iOS users. You can now store encrypted backups of your messages so you no longer need to worry about losing your messages if something happens to your device. > If you enable this feature, your Secure Backup Archive includes all of your text messages and the last 45 days of media — like files, photos, and attachments. For $1.99 per month, you can store up to 100 gigabytes of media. The setup process will create a recovery key that will allow you to restore your messages should you lose your device. The feature is currently in beta, so use it with caution. ### Proton Launches Beta Access for Proton Pass CLI URL: https://www.privacyguides.org/news/2025/11/25/proton-launches-beta-access-for-proton-pass-cli/ Last updated: 2025-11-25T21:39:35.000Z Proton has [launched](https://proton.me/blog/proton-pass-cli) the beta for their command line interface for Proton Pass, Proton’s password manager software. Soon you will be able to access your passwords and credentials securely via the terminal, a highly-requested feature. This launch will bring Proton Pass more in line with other password managers like [Bitwarden](https://bitwarden.com/help/cli/) and [1Password](https://1password.com/downloads/command-line) who also offer a CLI client. The beta, available only to Visionary users for now, promises to help with automation: > With Proton Pass CLI, credentials can be injected directly into scripts, deployments, and CI/CD pipelines without exposing secrets in plaintext, shell, logs, or command history. This enables automation while maintaining Proton’s end-to-end encryption model. This will be a great addition for technical users who are already invested in the Proton ecosystem, users who just prefer CLI tools, or those who can’t use a graphical UI for one reason or another. As always, I don’t recommend using beta software on your real account, but if you have a Visionary account and you want to help Proton test, you can follow the [instructions](https://protonpass.github.io/pass-cli/) they’ve laid out. I’m sure any help is appreciated by Proton. ### Harvard University Discloses Second Data Breach URL: https://www.privacyguides.org/news/2025/11/25/harvard-university-discloses-second-data-breach/ Last updated: 2025-11-25T09:45:14.000Z Harvard University—one of the most prestigious universities in the United States—disclosed a data breach over the weekend impacting its Alumni Affairs and Development systems. The voice phishing attack exposed the personal information of students, alumni, donors, staff, and faculty members, and in some cases their family members. The information included email addresses, telephone numbers, home and business addresses, event attendance records, donation details, and "biographical information pertaining to University fundraising and alumni engagement activities." The university says Social Security numbers, passwords, and financial information was not impacted. This incident comes on the heels of a disclosure in October that the university was likely breached by the Clop ransomware gang using a zero-day in the school's Oracle E-Business Suite servers. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Iberia Airlines discloses customer data breach URL: https://www.privacyguides.org/news/2025/11/25/iberia-airlines-discloses-customer-data-breach/ Last updated: 2025-11-25T07:30:01.000Z Iberia, Spain's largest airline and part of the International Airlines Group (IAG), has begun [notifying](https://www.bleepingcomputer.com/news/security/iberia-discloses-customer-data-leak-after-vendor-security-breach/) customers of a data breach resulting from a third-party vendor. The threat actor claims to have accessed 77GB of data including customer's first and last name, email address, and loyalty card identification number. Iberia says that login credentials and financial information were not accessed. Iberia says the third-party vendor leaked was a "supplier." It's unclear what the nature of this supplier was or why they needed access to customer data. Third-party vendors as a source of data breaches are becoming increasingly common. The more companies that have access to your data, the more chances there are for it to get leaked. Unfortunately this incident also shows how sometimes data can be shared with companies you didn't intend for it to end up with, often without your knowledge. While this breach didn't contain any information that would typically be considered sensitive - such as dates of birth or financial information - knowing where a user has an account can help a cybercriminal convince a more crafting phishing email. Bleeping Computer notes that this disclosure comes close on the heels of a listing on a cyber crime forum claiming to be selling 77 GB of Iberia data, including data from the Airline's internal servers, aircraft technical data, maintenance files, engine information, and other internal documents. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### KeePassXC Awarded ANSSI Security Visa URL: https://www.privacyguides.org/news/2025/11/25/keepassxc-awarded-anssi-security-visa/ Last updated: 2025-11-25T05:36:12.000Z KeePassXC 2.7.11 has been [released](https://keepassxc.org/blog/2025-11-23-2.7.11-released/) with a host of new bug fixes and improvements, especially around attachments, but perhaps the most notable news from KeePass is receiving a First-level Security Certification (CSP) from the French National Cybersecurity Agency (ANSSI). ANSSI Security Visas are somewhat like code audits, but more comprehensive. In addition to rigorous tests from accredited laboratories (including penetration testing), Security Visas are also designed to ensure compliance with government standards. KeePass's Security Visa is valid for three years and is recognized by French and German authorities. The audit report is publicly [available](https://cyber.gouv.fr/produits-certifies/keepassxc-version-279). This audit applies specifically to Version 2.7.9 on Windows 10, however it is a fair assumption that KeePassXC has put the same level of attention and detail into their other apps available on other operating systems. This highlights one of the biggest drawbacks of code audits: they represent a snapshot in time of a specific piece of code. There is no guarantee that Version 2.7.11 didn't introduce some new vulnerability. That said, it's impossible to prove a negative. There's no guarantee that despite all the extensive testing that Version 2.7.9 is completely free of vulnerabilities. Nevertheless, code audits remain an excellent heuristic for judging and vetting a service: if reputable experts spent sufficient resources on examining the code and have found it to be clean, functional, and well-executed, at very least this demonstrates that the entity behind the service is likely qualified, capable, and operating in good faith, meaning that they will most likely continue to do their best to keep their product secure and respond quickly to any problems. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### “Trivially Exploitable” Vulnerabilities Left Cloud Environments Vulnerable for Over 8 Years URL: https://www.privacyguides.org/news/2025/11/25/trivially-exploitable-vulnerabilities-left-cloud-environments-vulnerable-for-over-8-years/ Last updated: 2025-11-25T04:00:08.000Z Researchers at [Oligo](https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover) have found several “trivially exploitable” vulnerabilities in the widely-used [Fluent Bit](https://fluentbit.io) logging software that left users vulnerable for over 8 years. > It runs everywhere: AI labs, banks, car manufactures, all the major cloud providers such as AWS, Google Cloud, and Microsoft Azure, and more. The vulnerabilities allow “attackers to disrupt cloud services, tamper with data, and gain deeper access to the same Cloud and Kubernetes infrastructure.“ Attackers could penetrate deeper into the cloud environment and execute malicious code, and even control the logging of events, rewriting or erasing ones that could alert of the infection and injecting fake entries to throw investigators off the trail. The vulnerabilities include two remote code execution, four that allow tampering with logs, and one that’s both. Severe vulnerabilities in widely deployed and trusted software are nothing new. The widely deployed xz software was found to be [backdoored](https://tukaani.org/xz-backdoor/), leaving countless machines vulnerable. You may also remember the famous [log4j](https://builtin.com/articles/log4j-vulerability-explained) vulnerability that left tons of servers vulnerable. Many of our services we rely on every day run many third-party programs assumed to be trusted, but that haven’t had as much scrutiny put on them as they should. Serious work needs to be put into securing cloud infrastructure to protect against these inevitable flaws. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Forensic Software Company Gives Personalized Password Cracking Tips URL: https://www.privacyguides.org/news/2025/11/25/forensic-software-company-gives-personalized-password-cracking-tips/ Last updated: 2025-11-25T01:00:14.000Z Elcomsoft, seller of forensic tools for law enforcement to extract data from user devices like phones and computers, has released a [blog post](https://blog.elcomsoft.com/2025/11/leveraging-user-profiles-for-smarter-password-attacks/) on using information collected about individuals to make password cracking more efficient. I’ve written [extensively](https://www.privacyguides.org/articles/2025/03/08/toward-a-passwordless-future/) about the many problems with passwords, and this blog post only confirms what I’ve said before. According to them, “almost every password-creation study shows that personal details frequently end up inside passwords.” Since police typically know quite a bit of personal information about suspects, and they can gather even more from online sources like social media profiles, they can use this data to personalize the password cracking attempts for each specific person. Before, the advice was vague. But the post details highly specific advice on how to structure the dictionary attack for the best results. You can scream all day for people to use random, [diceware](https://diceware.dmuth.org) passwords for their local encrypted drives, but in the end passwords incentivize laziness so people will almost always choose terrible passwords. A proper solution needs to enforce randomness and avoid the possibility of human error. Unfortunately, though, we’re still stuck with them for now. So always use a completely random diceware password for local passwords on your encrypted devices and drives, and try to use [passkeys](https://fidoalliance.org/passkeys/) for all your online accounts. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### Tor Project Announces Relay Encryption Scheme Improvements URL: https://www.privacyguides.org/news/2025/11/24/tor-project-announces-relay-encryption-scheme-improvements/ Last updated: 2025-11-24T20:29:21.000Z Today, the Tor Project announced they are sunsetting some of the oldest and most important encryption algorithms in [Tor](https://www.privacyguides.org/en/advanced/tor-overview/): the *relay encryption algorithm*, and replacing them with a research-backed new design called "Counter Galois Onion" (CGO), which will be supported in upcoming Tor and Arti releases. [According to](https://blog.torproject.org/introducing-cgo/) the project, CGO adds forward secrecy to Tor connections, prevents attackers from tampering with encrypted traffic, and "brings Tor's encryption up to modern standards." Their blog post states: > This overhaul will defend users against a broader class of online attackers \[...\] and form the basis for more encryption work in the future. Tor already uses the standard TLS protocol for encryption between relays in a circuit, and encryption between clients and relays. However, for end-to-end protection of the content itself, Tor additionally requires the use of a "specialized algorithm" designed for encrypting user data as it traverses multiple relays. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) The design of this specialized algorithm isn't exactly what you would design today with modern cryptography knowledge. Tor was designed when AES was brand new, and authenticated encryption was only beginning to emerge as a field of study. It's a lack of proper authentication that poses a threat to Tor. The biggest problem Tor is addressing with this change are "tagging attacks," which they describe as the ability for an active attacker to trace traffic by modifying it at one place in the network and then observing behavior elsewhere in the network. Attackers are not able to modify the content you eventually see, but this attack can be used by an attacker to ensure they control both ends of your Tor circuit. Here's why: When an attacker modifies a circuit with a specific pattern, honest relay nodes will fail (not deanonymizing you), but Tor clients will keep retrying that connection. Eventually, your client could try using a relay which is controlled by the same attacker, at which point they could undo the pattern of data they've modified, and return the proper data to your client. Additionally, the specific pattern they use could be used to encode the client's IP address or another unique identifier and transmit it between the attacker's nodes. According to Tor: > The downside for the attacker is that the resulting failure rate of circuits can be detected by the client. Currently, Tor clients emit log notices and warnings when circuit failure rates are excessively high. Unfortunately, as vigilant users have noticed, when the DDoS attacks on Tor become severe, these detectors give false alarms. Tor Project is officially [updating](https://gitlab.torproject.org/tpo/core/torspec/-/issues/318) its threat model to specifically cover threats like this. The other attacks addressed by CGO are minor in comparison, but still worth resolving. The current lack of forward secrecy for messages on a circuit is an issue, but since circuits typically don't last very long in the first place, the window of opportunity for attackers is low. Tor believes longer-lived circuits may be better for anonymity, however, so adding in forward secrecy will allow them to do that in the future if they decide it makes sense. Their blog post has many more technical details if you are interested in learning more about the current and future state of relay encryption: [Counter Galois Onion: Improved encryption for Tor circuit traffic | Tor ProjectTor is upgrading its relay encryption algorithm for improved security. In upcoming releases, Arti and Tor will both support a new encryption algorithm called Counter Galois Onion (CGO). CGO prevents attackers from tampering with encrypted traffic, adds forward secrecy, and brings Tor’s encryption up to modern standards.![](https://www.privacyguides.org/content/images/icon/favicon.png)The Tor Projectnickm![](https://www.privacyguides.org/content/images/thumbnail/lead.png)](https://blog.torproject.org/introducing-cgo/) The Tor Project says implementation of CGO is currently underway. ### Major Banks Reeling After Data Customer Data Leaked in Cyber Attack Against SitusAMC URL: https://www.privacyguides.org/news/2025/11/24/major-banks-reeling-after-data-customer-data-leaked-in-cyber-attack-against-situsamc/ Last updated: 2025-11-24T20:00:07.000Z According to [TechCrunch](https://techcrunch.com/2025/11/24/us-banks-scramble-to-assess-data-theft-after-hackers-breach-financial-tech-firm/), SitusAMC, a company that provides technology for major banks like JPMorgan, Citigroup, Morgan Stanley, and even state governments, has had a major breach of customer data including “accounting records and legal agreements.” SitusAMC provides mechanisms and technologies and acts as a middleman for banks and financial institutions to comply with government regulations. As such, they handle large amounts of sensitive data that‘s not publicly accessible. TechCrunch reached out to SitusAMC and several affected banks asking if they had received demands for money, but none responded. The FBI says that they have identified no operational impact to banking services. This and the lack of encrypting malware normally used in ransomware attacks suggests that the attack was purely meant to exfiltrate data. The banking sector remains a juicy target for hackers due to the huge amount of personal data they process about customers. Perhaps we should question whether so many institutions should be trusted with our personal data, and if a future where banks don’t collect and send so much of it to third parties is possible. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### MAGIC Grants Releases Monero Light-Wallet App for Android URL: https://www.privacyguides.org/news/2025/11/24/magic-grants-releases-monero-light-wallet-app-for-android/ Last updated: 2025-11-24T19:35:39.000Z MAGIC Grants announced today the release of their new, open-source [Skylight Wallet](https://skylight.magicgrants.org/) app for Android, which will also be "available soon" for iOS and Desktop. Skylight Wallet is a [Monero wallet](https://www.privacyguides.org/en/cryptocurrency/#monero-wallets) which uses a Monero Light-Wallet Server (LWS) to detect your transactions, as opposed to traditional Monero wallets which require a lengthy synchronization period to scan the Monero blockchain to find your private transactions before you can use them. 💡 ****Disclosure:** MAGIC Grants is a 501(c)(3) public charity, and the fiscal host of **Privacy Guides* via the [MAGIC Privacy Guides Fund](https://magicgrants.org/funds/privacy%5Fguides/). Our funds are independently governed, and MAGIC Grants does not have editorial control over this publication. This comes after one of the most popular existing light-wallet applications in the [Monero cryptocurrency](https://www.privacyguides.org/en/advanced/payments/#cryptocurrency) ecosystem, MyMonero, [announced](https://mymonero.com/) last month that they would be shutting down operations by January 2026. Light-wallets work by sending your private Monero *view* key to an [LWS](https://github.com/vtnerd/monero-lws), which scans the blockchain on your behalf and sends only transactions which are related to your wallet to your device. Offloading this processing to a centralized server is far more efficient, but your private view key does grant the server operator the ability to see all your transactions. It does not, however, grant any ability for the server operator to spend your funds. MyMonero cited this privacy concern as a primary reason to shut down their service in their announcement in October. That application provided a default LWS for its users to make Monero adoption much quicker and more convenient, but they felt that their centralized model "requiring view keys \[was\] increasingly at odds with Monero's privacy evolution." Skylight Wallet avoids this issue by not providing any LWS by default. Instead, they recommend [running your own](https://www.privacyguides.org/articles/2025/06/12/monero-server-using-truenas/) or using one that's run by a trusted friend or family member. This effectively allows you to offload computing power to a more powerful machine like your computer or NAS, but is more complex than a traditional wallet like the official Monero wallet or Cake Wallet. MAGIC Grants cited the lack of "modern" Monero light-wallets as the reason for developing this app: > Monero LWS is not highly used. MyMonero used its own implementation, and there weren't many good ways to truly run your own LWS with a modern experience. The self-hosted component means this will never be a suitable replacement for a traditional Monero wallet for *everybody.* However, there are many scenarios where a light-wallet will make sense for people, especially those who are juggling multiple devices, frequently restoring their wallets, or wish to provide a central LWS for their friends and community. It's good to have a fully open-source and standardized implementation which isn't reliant on a centralized service provider, for those who appreciate the convenience or efficiency this offloaded design provides. Skylight Wallet also comes with built-in Tor integration thanks to its use of [Arti](https://tpo.pages.torproject.net/core/arti/), a rewritten and more efficient version of the Tor codebase in Rust. You can read the full [press release](https://magicgrants.org/2025/11/24/Introducing-Skylight-Wallet) for the release of Skylight Wallet on MAGIC Grants' website. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### SHA1-HULUD Malware Infects Developers, Posts Secrets to Their Public GitHub Repos URL: https://www.privacyguides.org/posts/2025/11/24/sha1-hulud-malware-infects-developers-posts-secrets-to-their-public-github-repos/ Last updated: 2025-11-24T19:36:27.000Z According to researchers at [Wiz](https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack), a supply chain attack on npm packages is exfiltrating developers’ credentials and posting them to public GitHub repositories. > Wiz Research is tracking over 25,000 affected repositories created across \~350 unique users. A thousand new repositories are being added consistently every 30 minutes throughout the initial hours of this campaign. In addition, Wiz has identified newly compromised packages that contain files linked to this activity. Wiz says the attack “compromised a large number of packages, including Zapier packages, ENS domains packages, ecosystem packages and more. Newly compromised packages are still being identified.” > The payload registers the infected machine as a self hosted runner named 'SHA1HULUD'. The name is a reference to Dune and also likely the ”wormable“ nature of the malware, meaning it‘s able to automatically spread itself without human input. This incident comes after a [similar](https://discuss.privacyguides.net/t/github-is-finally-tightening-up-security-around-npm-following-multiple-attacks/31350) malware incident back in September. The researchers recommend that developers clear their npm cache, rotate all credentials, remove anything from your GitHub and CI/CD environments referencing shai-hulud, and harden automation pipelines. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### CSA Announces Matter 1.5, Adding Secure Camera Support and New Devices URL: https://www.privacyguides.org/news/2025/11/24/csa-announces-matter-1-5-adding-secure-camera-support-and-new-devices/ Last updated: 2025-11-24T19:36:37.000Z Matter 1.5 has [released](https://csa-iot.org/newsroom/matter-1-5-introduces-cameras-closures-and-enhanced-energy-management-capabilities/), bringing with it lots of new supported device types. Among the new additions are support for cameras, soil sensors, and what they call “closures.” [Matter](https://csa-iot.org/all-solutions/matter/) is an open standard for interoperable smart home devices. It allows you to run a secure, local network of smart home devices that can all work together seamlessly. The 1.5 update to the standard allows security cameras to be easily run on your local smart home network without having to rely on some cloud service to control them. The support is based around standard WebRTC technology used in browsers and many other technologies that rely on real-time video and audio such as messaging apps that include calling functionality. The support includes many features you would want in a surveillance system such as multi-stream support, pan-til-zoom controls, motion detection, privacy zones, and the ability to link to cloud or local storage of your choice. Older cameras can be updated to support the new standard, it’s only up to the device vendors to update them to support it. Of note also is the new class of devices called “closures.” These include window shades, drapes, awnings, garage doors, etc. Being able to control these locally and in an automated way so you never leave your garage door open for example or your window shades are always closed at night for example will be a big boost to your privacy should you choose to go the smart home route. It’s great to see open standards like Matter being expanded and adopted industry-wide. Open standards and interoperability are the best path toward a more private and secure future. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### GrapheneOS Releases QPR1 Update URL: https://www.privacyguides.org/news/2025/11/23/grapheneos-releases-android-qpr1-update/ Last updated: 2025-11-24T19:36:48.000Z GrapheneOS users have received the long-awaited Android 16 [QPR1](https://grapheneos.org/releases#2025111800) update to GrapheneOS. The update brings with it the [Material 3 Expressive](https://m3.material.io/blog/building-with-m3-expressive) UI design overhaul with the new Motion physics system, as well as [desktop mode](https://9to5google.com/2025/06/10/android-16-desktop-mode-first-look/), so you can use your phone as a desktop computer. The update was originally launched for Pixels in [September](https://blog.google/products/pixel/september-2025-pixel-drop/) but it was only released into the open source Android Open Source Project (AOSP) [2 months later](https://www.androidauthority.com/android-16-qpr1-source-code-available-3614853/). The long wait for Google to release the source code is the reason why [AOSP-based projects](https://www.privacyguides.org/en/android/distributions/) like GrapheneOS that rely on Google’s open source code haven’t been able to release the update until now. With desktop mode, you could theoretically replace your less secure desktop computer with your GrapheneOS phone, giving you a highly secure option for tasks like doing your taxes that require you to process highly sensitive data. As phones continue to get more and more powerful, we might start seeing more and more tasks we used to need a desktop for done on our phones instead. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) ### The Electronic Frontier Alliance is No More, Says EFF [Updated] URL: https://www.privacyguides.org/news/2025/11/23/the-electronic-frontier-alliance-is-no-more-says-eff/ Last updated: 2025-11-24T19:37:05.000Z **Update 1, November 23, 2025 (19:03 UTC):** [Rory Mir](https://www.eff.org/about/staff/rory-mir), the project lead for EFA at EFF, reached out to *Privacy Guides* on Signal to share some additional details. > EFA members were notified at the beginning of the month over email, and we held a virtual town hall for Q&A. We decided to close the website on the 20th as we were still receiving applications, and that is the date we restructured internally for the change. That said, current EFA members are getting the same level of support through the end of the year, and we have every intention of continuing to work with them. According to Rory, EFA members received a high level of support from EFA, which required an application process and limited who was eligible to join: > In the new year we're ending some of the support entirely, like event promotion and in-person EFA events. However we are maintaining others in a new process, like local campaign assistance and security trainer training. This support will also now be open to more advocates who reach out to EFF, without navigating an EFA membership process. A current EFA member also sent us a copy of an email sent out to allies earlier this month, which also shared some of these details, as well as noted a new "EFF-Allies" initiative that would be coming next year: > \[...\] What this means for you is that on November 20th, EFF will publicly retire the EFA and archive the online site including the ally directory. \[...\] > The new year won’t be the end of our community, though. We’re continuing to support our network through a new online space—EFF-Allies. This will be a continuation of much of what made the Alliance special: collaboration, resource-sharing, and camaraderie among local digital rights supporters. Former EFA groups will all be welcome, as well as a broader tent of trusted local organizers. \[...\] I asked Rory about this program, who said they would be leading these collaborative efforts in their new role, and would be sharing more details publicly in the new year. I've received questions from multiple community members about the EFA's member directory, which allowed people to find local activism groups close by. Rory said that they didn't have public details to share about the directory or a potential replacement, but "it is distinct from the promotional support we are ending for events," and that the EFF blog hopes to continue to highlighting local groups going forward. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) --- **Original article, November 23, 2025 (06:25 UTC):** The Electronic Frontier Alliance has officially ended. In a brief statement on [efa.eff.org](https://efa.eff.org/), the Electronic Frontier Foundation stated that the EFA "concluded on November 20, 2025." The Electronic Frontier Alliance was a grassroots network of community organizations in the United States supporting digital rights in their local communities. Just last year, EFF posted about "[reintroducing the EFA](https://www.eff.org/deeplinks/2024/08/reintroducing-efa)" to their blog, so the sudden shutdown comes as a bit of a surprise. In their closure statement, EFF stated that they will continue to explore ways to engage with local advocates and provide support, and that toolkits which were developed for the EFA will remain available. > For nearly a decade, the Alliance brought together grassroots advocates, technologists, and community groups working to advance digital rights. Its strength came from the relationships and collaboration these groups built with one another, and from the shared commitment to open technology and civil liberties that defined the network. *Privacy Guides* has reached out to EFF for comment, and will provide an update if we receive a response. This change comes amidst a lot of changes at the EFF as of late. In September, they [launched](https://www.eff.org/press/releases/executive-director-cindy-cohn-will-step-down-after-25-years-eff) a search for a new Executive Director, as Cindy Cohn announced she would be stepping down from the role after 25 years of service with the non-profit. It's unfortunate the program seems to have been shut down with seemingly very little fanfare. Outside of the notice on their website, EFF did not issue a press release or announcement, and I have not found other publications picking up this story. As recently as a month ago, the EFF was still actively posting to social media encouraging people to start their own EFA-affiliated group or find existing ones: [Electronic Frontier Foundation (@eff.org)Fight your local tech dystopia today. Connect with a local grassroots group (or start your own) with resources from the Electronic Frontier Alliance. efa.eff.org/ https://efa.eff.org/![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-22.png)Bluesky Social![](https://www.privacyguides.org/content/images/thumbnail/bafkreihlbzz2uphfrnukxznnhm6ygczohwvt747fakp76dx5qbrihzbu44@jpeg)](https://bsky.app/profile/eff.org/post/3m3kkqyzysm22) If you are part of a local EFA member organization, please reach out to us if you have any more insights into this, or received notice from EFF internally. ### iOS Developers Claim 1Password isn’t Removing Deleted Profile Pictures URL: https://www.privacyguides.org/news/2025/11/22/1password-stores-profile-pictures-of-user-accounts-even-after-changing-deleting-your-account-according-to-security-researchers-at/ Last updated: 2025-11-22T20:16:51.000Z The iOS developer and security researcher duo Mysk [claims](https://mastodon.social/@mysk/115594234393521427) that after deleting their 1Password account, their profile picture was still being stored and remained publicly accessible via a URL. The saga started when Mysk discovered that 1Password profile pictures were accessible through a publicly available URL: [Mysk🇨🇦🇩🇪 (@mysk@mastodon.social)Attached: 1 image Oh, 1Password stores user profile pictures on their servers without authentication. Anyone who has the long URL, which also contains the account identifier, can access the picture. It’s not a big deal, but a password manager should definitely be more careful. #privacy #infoSec![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-180x180-DSCV_HvQ-1.png)MastodonMysk🇨🇦🇩🇪![](https://www.privacyguides.org/content/images/thumbnail/52c6fcd173a990ca.jpeg)](https://mastodon.social/@mysk/115544590365572564) [Mysk🇨🇦🇩🇪 (@mysk@mastodon.social)This is a test account we created to test the new feature that 1Password just announced about unlocking the app with the Mac password, as it relates to our recent work. Here’s the link that was shown in the screenshot: https://a.1passwordusercontent.com/VL4OMT3IFZDB3LIJRC67R3ECLU/f2v3kcoxrnemzaf4hrl7vtpw6m.png![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-180x180-DSCV_HvQ-2.png)MastodonMysk🇨🇦🇩🇪](https://mastodon.social/@mysk/115544620428829290) They pointed out that 1Password [considers](https://support.1password.com/1password-privacy/#:~:text=email%20address%2C%20and-,profile%20pictures,-that%20you%20have) profile pictures to be personally identifiable information in their documentation as well. After changing the profile picture on their test account, the old one was still visible from the same link, meaning the image wasn’t deleted and was not only still stored on their servers, but also still publicly available: [Mysk🇨🇦🇩🇪 (@mysk@mastodon.social)Oh woow 😱! After changing the profile picture yesterday, the link to the old profile picture still works even though the old picture is not visible anywhere in the account. Are they storing profile pictures in a CDN? This is not LinkedIn, it’s a password manager 😖![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-180x180-DSCV_HvQ-3.png)MastodonMysk🇨🇦🇩🇪](https://mastodon.social/@mysk/115549043335372869) After deleting the account, the link was still up and accessible 7 days later: [Mysk🇨🇦🇩🇪 (@mysk@mastodon.social)Article 17:65 of the GDPR, the right to be forgotten: A data subject should have the right to have personal data concerning him or her rectified and a ‘right to be forgotten’ where the retention of such data infringes this Regulation or Union or Member State law to which the controller is subject. This 1Password account was deleted on November 15, 2025 and its profile picture is still online: https://a.1passwordusercontent.com/VL4OMT3IFZDB3LIJRC67R3ECLU/f2v3kcoxrnemzaf4hrl7vtpw6m.png![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-180x180-DSCV_HvQ-4.png)MastodonMysk🇨🇦🇩🇪](https://mastodon.social/@mysk/115594234393521427) They’re correct here about the [GDPR](https://gdpr-info.eu/recitals/no-65/), since the profile picture is no longer being used for any purpose. **Editor's note:** We reached out to 1Password for comment, but have not received a response at the time of publishing. We will update this post when we hear back. ### Cybersecurity Company Loses Encryption Key for Internal Election URL: https://www.privacyguides.org/news/2025/11/22/cybersecurity-company-loses-encryption-key-for-internal-election/ Last updated: 2025-11-22T19:55:43.000Z The Internal Association of Cryptologic Research (IACR) was forced to cancel their annual leadership election after one of the officials permanently lost their encryption key, rendering the results permanently encrypted. According to [Ars Technica](https://arstechnica.com/security/2025/11/cryptography-group-cancels-election-results-after-official-loses-secret-key/), the IACR is a nonprofit who conducts research in cryptology. They define cryptology as "the science and practice of designing computation and communication systems that remain secure in the presence of adversaries." To conduct internal elections, the IACR uses an open source voting system called Helios. Per the organization's bylaws, three members are selected as "independent trustees," and each holds a third of the cryptographic key needed to decrypt the results. > “Unfortunately, one of the three trustees has irretrievably lost their private key, an honest but unfortunate human mistake, and therefore cannot compute their decryption share. As a result, Helios is unable to complete the decryption process, and it is technically impossible for us to obtain or verify the final outcome of this election.” > \- The IACR One of the far less exciting but nonetheless crucial topics that the privacy community often neglects is backups. It's said that "two is one, one is none." If you don't have backups, you're gambling with your data. The current conventional wisdom preaches a "3-2-1" rule: - 3 copies of your data - 2 different mediums (such as external hard drive and [cloud storage](https://www.privacyguides.org/en/cloud/)) - 1 live copy It's also worth noting the follow up piece of advice: "if you haven't tested your backups, you don't have backups." There's few feelings worse than needing to recover your backups and realizing they aren't there after all. The IACR has updated their policies: only two of three trustees are now required going forward. New elections have started and polls will close on December 20. ### California Court Ends Smart Meter Dragnet Surveillance Program URL: https://www.privacyguides.org/news/2025/11/22/california-court-ends-smart-meter-dragnet-surveillance-program/ Last updated: 2025-11-22T08:30:30.000Z [According to](https://www.eff.org/deeplinks/2025/11/victory-court-end-dragnet-electricity-surveillance-program-sacramento) the EFF, the Sacramento County Superior Court has determined that a surveillance program run by the Sacramento Municipal Utility District (SMUD) and the police is illegal. The program saw SMUD [searching](https://www.eff.org/deeplinks/2025/07/when-your-power-meter-becomes-tool-mass-surveillance) through countless customers’ data, looking for “high usage” households and submitting over 33,000 tips to police. They were using high energy usage as an indicator that they were growing illegal amounts of cannabis. > SMUD analysts have admitted that such “high” power usage could come from houses using air conditioning or heat pumps or just being large. And the threshold of so-called “suspicion” has [steadily dropped](https://www.eff.org/document/2025-07-18-aaln-petition-exh-falling-kwh-threshold-suspicion), from 7,000 kWh per month in 2014 to just 2,800 kWh a month in 2023\. One SMUD analyst admitted that they themselves “used 3500 \[kWh\] last month.” They had also been targeting Asian customers specifically. > SMUD analysts deemed [one home suspicious](https://www.eff.org/document/2025-07-18-aaln-petition-exh-text-message-4k-asian) because it was “4k \[kWh\], Asian,” and [another suspicious](https://www.eff.org/document/2025-07-18-aaln-petition-exh-text-message-multiple-asians) because “multiple Asians have reported there.” The Asian American Liberation Network was also involved in the lawsuit alongside the EFF because of the unfair racial targeting. As we see with these surveillance programs, mostly innocent civilians are targeted based on bad information. The lawsuit represents a win for the peace of mind of Californians and another example of the failures of mass surveillance. ### Pornhub Urges Big Tech Companies to Adopt Device-Based Age Verification URL: https://www.privacyguides.org/news/2025/11/22/pornhub-urges-big-tech-companies-to-adopt-device-based-age-verification/ Last updated: 2025-11-22T07:10:48.000Z According to [Wired](https://www.wired.com/story/pornhub-is-urging-tech-giants-to-enact-device-based-age-verification/), Pornhub's parent company has sent letters to Apple, Google, and Microsoft urging them to support device-based age verification. Currently, Pornhub has disabled itself in regions requiring age verification due to a lack of good, privacy-preserving age verification options. Many adult sites use third-party services and perform privacy-invasive face scans or ask for you to upload a picture of your government ID in order to access the site. Many others simply ignore the age verification mandates altogether. Pornhub points out that the age verification mandates have been largely ineffective at protecting children and have put user data at risk. They say that they “have found site-based age assurance approaches to be fundamentally flawed and counterproductive.” By site-based age assurance, they mean every website having their own age verification system that needs to individually verify for every site a user visits. Device-based age assurance would be completed once on the user’s device, then the signal can be sent to websites via an application programming interface (API). With [Apple](https://www.apple.com/newsroom/2025/11/apple-introduces-digital-id-a-new-way-to-create-and-present-an-id-in-apple-wallet/) and [Google’s](https://wallet.google/intl/en%5Fus/digitalid/) wallet apps supporting digital IDs, and Chrome and Safari supporting the [Digital Credentials API](https://www.corbado.com/blog/digital-credentials-api), it’s not clear what exactly Pornhub is looking for in terms of platform support. It seems that the Big Tech companies have already been working on a device-based digital ID system for a while now. ### Thunderbird Pro Enters Closed Testing Phase URL: https://www.privacyguides.org/news/2025/11/22/thunderbird-pro-enters-closed-testing-phase/ Last updated: 2025-11-22T06:10:04.000Z A new [announcement](https://blog.thunderbird.net/2025/11/thunderbird-pro-november-2025-update/) from Thunderbird Pro sees the services entering an “initial closed test run” with a “core group of community contributors.” Thunderbird Pro will be a set of extra paid services offered which integrate well with the free Thunderbird email client. The services offered will be Thundermail, their in-house email service, Appointment, a scheduling tool, and Send, an end-to-end encrypted file sharing service. The announcement coincides with the launch of their [new website](https://tb.pro/en-US/). The initial Early Bird plan will be priced at $9 per month and will include all three services, with plans in the future to introduce higher tiers. > This introductory rate directly supports Thunderbird Pro’s early development and growth, positioning it for long-term sustainability. You can head over to their site and join the waitlist if you’re interested. ### Twitch Added to Age Restricted Social Media in Australia URL: https://www.privacyguides.org/news/2025/11/22/twitch-added-to-age-restricted-social-media-in-australia/ Last updated: 2025-11-22T05:00:03.000Z Australia’s eSafety Commissioner has [added](https://www.esafety.gov.au/newsroom/media-releases/twitch-assessed-as-age-restricted-social-media-platform) Twitch to its growing list of age-restricted social media sites. > Following Twitch’s own self-assessment, eSafety assessed Twitch as meeting the criteria for ‘age-restricted social media platform’, because it has the sole or significant purpose of online social interaction with features designed to encourage user interaction, including through livestreaming content. This means that by December 10, “Twitch and the previously announced Facebook, Instagram, Kick, Reddit, Snapchat, Threads, TikTok, X and YouTube, will be required to take reasonable steps to prevent Australian children under the age of 16 from having accounts.” eSafety highlights that it’s ultimately up to the courts to decide, but an assessment from an official government agency is a good indicator that they will have to comply. This comes after Australia launched its [digital ID](https://my.gov.au/en/about/help/digital-id). The Australian government is [trialling](https://www.digitalidsystem.gov.au/news/digital-id-in-action-testing-the-future-of-smarter-business-transactions) the IDs for some applications, but the technology is not widely deployed across services yet. This makes it a bit strange that they are now about to enforce age verification before a robust system for privacy-preserving verification is rolled out. Ideally, the government would work out the kinks in the system *before* requiring it for millions of Australians to use social media. ### EFF Files Lawsuit Against DOJ and DHS to Uncover Information About Removed ICE-Tracking Apps URL: https://www.privacyguides.org/news/2025/11/22/eff-files-lawsuit-against-doj-and-dhs-to-uncover-information-about-removed-ice-tracking-apps/ Last updated: 2025-11-22T03:30:14.000Z The Electronic Frontier Foundation (EFF) has [filed](https://www.eff.org/press/releases/eff-demands-answers-about-ice-spotting-app-takedowns) a lawsuit against the US Department of Justice and the Department of Homeland Security in order to “uncover information about the federal government demanding that tech companies remove apps that document immigration enforcement activities in communities throughout the country.” The lawsuit comes in response to multiple ICE-tracking apps such as ICE Block, Red Dot, and DeICER being taken down from Apple and Google’s app stores. The apps were removed due to [demands](https://www.forbes.com/sites/siladityaray/2025/10/03/apple-takes-down-iceblock-app-after-doj-demand-heres-what-we-know/) from law enforcement. > "We're filing this lawsuit to find out just what the government told tech companies," said EFF Staff Attorney F. Mario Trujillo. "Getting these records will be critical to determining whether federal officials crossed the line into unconstitutional coercion and censorship of protected speech." The EFF argues Americans have a right to record law enforcement activities as part of their [first amendment rights](https://www.eff.org/deeplinks/2025/02/yes-you-have-right-film-ice). This could mean government demands for third parties to take down apps that don’t violate the law are unconstitutional. The EFF previously had filed a Freedom of Information Act (FOIA) request for “records and communications about agency demands that technology companies remove apps and pages that document immigration enforcement activities.” According to the EFF, none of the agencies responded. Google continues to [host](https://www.404media.co/google-has-chosen-a-side-in-trumps-mass-deportation-effort/) a Customs and Border Protection (CBP) app that uses facial recognition to identify immigrants, while describing ICE agents as a “vulnerable group.” Big Tech companies’ behavior clearly shows which side they’re on. ### GrapheneOS migrates server infrastructure from France amid police intimidation claims URL: https://www.privacyguides.org/news/2025/11/22/grapheneos-migrates-server-infrastructure-from-france-amid-police-intimidation-claims/ Last updated: 2025-11-28T19:54:59.000Z The GrapheneOS project has [announced](https://xcancel.com/GrapheneOS/status/1991604700882563267#m) on X that they are ceasing all operations in France, asserting that the country is no longer safe for "open source privacy projects". While the operating system will still be [available](https://xcancel.com/GrapheneOS/status/1991637627737412000#m) to French users, all website and discussion servers are being relocated to countries and providers outside France's jurisdiction. Until now, the project relied on OVH Bearharnois, a French hosting provider, for some core website and social media services. The migration plan moves the Mastodon, Discourse, and Matrix instances to a combination of local and shared servers in Toronto on a provider other than OVH. Critical website infrastructure will be hosted by Netcup, a German‑based company. Thank you for reading this article. If you want to support our news briefs, guides, and videos please consider becoming a Privacy Guides member. **Privacy Guides* is 100% reader-funded. You can subscribe for free, or donate and receive early-access and exclusive content from the team. [Join Privacy Guides ](#/portal/signup) GrapheneOS claims that they does not collect confidential user data in their servers or store critical infrastructure in France. Therefore, the migration does not affect services such as signature verification and downgrade protection for updates. Citing the government's support of the European Union Chat Control proposal, GrapheneOS developers are also refusing travel to France. Developers are no longer allowed to work inside the country due to safety concerns. According to GrapheneOS, law enforcement in France has repeatedly made media statements with "inaccurate and unsubstantiated claims" about GrapheneOS, indicating that French police may be attempting to intimidate the organization into weakening the security of its product. These alleged threats against GrapheneOS in the media and elsewhere from French officials are the reason the organization has decided to sever ties to the country. This decision was publicly initiated after negative press coverage from two articles published by *Le Parisien*. An interview between *Le Parisien* and French cybercrime prosecutor Johanna Brousse [implies](http://leparisien.fr/faits-divers/telephones-proteges-utilises-par-les-narcotrafiquants-rien-nest-inviolable-19-11-2025-3PP34GIBAJGH3EZOVEJVT7OMU4.php) potential legal action against the project: > "With this new tool, there is real legitimacy for a certain portion of users in the desire to protect their exchanges. The approach is therefore different. But that won't stop us from suing the publishers if links are discovered with a criminal organization and they don't cooperate with the law" GrapheneOS [argues](https://xcancel.com/GrapheneOS/status/1991958774584864890#m) that their project is being conflated with government-sponsored forks, which are fake copies of their operating system. The news outlet they cited [refers](https://www.leparisien.fr/faits-divers/google-pixel-et-grapheneos-la-botte-secrete-des-narcotrafiquants-pour-proteger-leurs-donnees-de-la-police-19-11-2025-NTGPQE4JCNGEHLF7XGIQ3CCA2I.php?at%5Fvariant=photo) to a fake Snapchat app, dark web advertising, and a series of unlisted YouTube videos that are not features of GrapheneOS itself. The project had previously [threatened](https://xcancel.com/GrapheneOS/status/1991960139025580466#m) litigation against these government-sponsored forks. One prominent example is ANOM, an FBI-backed shell company that developed a compromised Android operating system and messaging platform as part of [Operation Trojan Horse](https://www.justice.gov/usao-sdca/pr/fbi-s-encrypted-phone-platform-infiltrated-hundreds-criminal-syndicates-result-massive) from 2018 and 2021. --- **Editor's note (Nov. 28, 2025) 19:50 UTC:** The ending of this article has been updated to more clearly indicate that GrapheneOS's decision was caused by concerns about French law enforcement, not negative press republishing those concerns. ### Welcoming Nate to Privacy Guides! Plus, the EU scales back the GDPR, Windows 11 Adds "Agentic AI," & More... URL: https://www.privacyguides.org/livestreams/2025/11/22/welcoming-nate-to-privacy-guides-plus-the-eu-scales-back-the-gdpr-windows-11-adds-agentic-ai-more/ Last updated: 2025-11-22T05:49:25.000Z This Week in Privacy #28 _This post is for subscribers only._ ### Privacy Guides Reveals Full-Time Educational Video Team Hire URL: https://www.privacyguides.org/press-releases/2025/11/22/privacy-guides-reveals-full-time-educational-video-team-hire/ Last updated: 2025-11-22T02:00:37.000Z For Immediate Release — Privacy Guides, an impartial, non-profit organization focused on building a strong privacy & digital rights advocacy community, announced today that Nate Bartram would join its video production team as the latest full-time staff contributor. Bartram has been writing privacy advocacy resources since 2018 with his personal website [*The New Oil*](https://thenewoil.org/en/), and was [formerly](https://www.youtube.com/watch?v=He23NeRG2Eg&pp=ygUTc3VydmVpbGxhbmNlIHJlcG9ydA%3D%3D) the host of the popular *Surveillance Report* podcast. He will now be co-hosting future episodes of the [*This Week in Privacy*](https://www.privacyguides.org/livestreams/) livestreamed show, future scripted videos and shorts, and writing other content to assist the *Privacy Guides* news team. His first major upcoming project will be a video course series on smartphone security, and contributing to regular updates to the [news briefs](https://www.privacyguides.org/news/) section of *Privacy Guides*. 💬 "As we discussed on the latest episode of **This Week in Privacy*, we have so many plans for advancing privacy and making this community even more fantastic going in to 2026, and affording Nate the opportunity to commit to privacy advocacy ****full-time** with us is really a dream come true." — Jonah Aragon, Privacy Guides Program Director His first appearance on *Privacy Guides'* video channels was on November 21, 2025 in [Episode 28](https://youtube.com/live/ZBAqzbxYliE) of *This Week in Privacy,* a weekly livestream where he and the team discussed his role and future plans within the organization, as well as hosted a Q&A session with the community. Program Director Jonah Aragon published an [article to the Privacy Guides community forum with more details](https://discuss.privacyguides.net/t/welcoming-nate-bartram-to-privacy-guides/33092) about this announcement. [Welcoming Nate Bartram to Privacy GuidesAs many of you have now heard, we’re beyond thrilled to welcome Nate Bartram to the Privacy Guides team! As we discussed on the latest episode of This Week in Privacy, we have so many plans for advancing privacy and making this community even more fantastic going in to 2026, and affording Nate the opportunity to commit to privacy advocacy full-time with us is really a dream come true 🤩 Nate’s Role at Privacy Guides Today we shared a lot of details in Episode 28 of the livestream, b…![](https://www.privacyguides.org/content/images/icon/50d23e21c43962bb12c02820fa3f19ac61dac917_2_180x180-36.png)Privacy Guides Communityjonah![](https://www.privacyguides.org/content/images/thumbnail/4efb2e0b56f7c45bc4589cf8f63291cc82a788e8-14.webp)](https://discuss.privacyguides.net/t/welcoming-nate-bartram-to-privacy-guides/33092) --- [Privacy Guides](https://www.privacyguides.org/) is an impartial organization that is focused on building a strong privacy advocacy community and delivering the best digital privacy and consumer technology rights advice on the internet. Its mission is to inform the public about the value of digital privacy, consumer tech rights, and about global government initiatives which aim to monitor your online activity. Privacy Guides resources are free of advertisements and not affiliated with any of the recommended providers. Privacy Guides ([**www.privacyguides.org**](https://www.privacyguides.org/)) is built by volunteers and staff members around the world. For information about Privacy Guides or this announcement, contact Jonah Aragon at [jonah@privacyguides.org](mailto:jonah@privacyguides.org). **Media Contact:** [press@privacyguides.org](mailto:press@privacyguides.org) ### Monero Node RPC Codebase Gets Improved Fuzzing Coverage URL: https://www.privacyguides.org/news/2025/11/21/monero-node-rpc-codebase-gets-improved-fuzzing-coverage/ Last updated: 2025-11-21T18:37:16.000Z The Monero node codebase now has greatly improved fuzzing coverage over its most vulnerable component, its RPC server, including 100% coverage of RPC endpoint functions, and [84% coverage](https://storage.googleapis.com/oss-fuzz-coverage/monero/reports/20251119/linux/src/monero/monero/src/rpc/report.html) of the core RPC server. This improvement is thanks to work by ADA Logics, which was [funded](https://donate.magicgrants.org/monero/projects/fuzzing-monero-rpc) and contracted through MAGIC Grants' [Monero Fund](https://donate.magicgrants.org/monero). "Fuzzing" is an automated code testing technique which involves providing random or unexpected data as the inputs of a computer program, then monitoring that program for crashes, potential memory leaks, or other anomalies. Often, good fuzzing tools can create inputs which are valid enough to be accepted by a program, but are invalid enough to cause problems in corner cases that are not properly dealt with. This [technique](https://brightsec.com/blog/fuzzing/) is used extensively by organizations developing security-critical applications. In 2019, Google discovered over 20,000 vulnerabilities in Chromium via internal fuzz testing. It's a useful technique because it not only proves a bug exists without false positives, but it can show developers the exact cause of the problem. It is also fully automated, so with enough compute resources developers can continuously run fuzzing tests without intervention. The RPC (remote procedure call) server is the part of the program which interacts with *other* software. For example, a [Monero wallet program](https://www.privacyguides.org/en/cryptocurrency/#monero-wallets) would make an RPC connection to a Monero daemon in order to access the blockchain. Some Monero nodes also expose public RPC endpoints to the web for others to utilize. This makes the RPC server a valuable target for hackers, and the most likely receiver of untrustworthy external data. ADA Logics' deliverable to MAGIC Grants included the development of a [fuzzing tool](https://github.com/AdaLogics/monero-e2e-fuzzing) which could target a live `monerod` instance targeting its server component, adding support to Monero via a [PR](https://github.com/monero-project/monero/pull/10004), and publishing a [report](https://magicgrants.org/files/2025-08-17-monero-fuzzing-audit-report.pdf) detailing their findings. The central goal was for their tool to cover "over 75% of Monero’s RPC handler entrypoints." 💡 ****Disclosure:** MAGIC Grants is a 501(c)(3) public charity, and the fiscal host of **Privacy Guides* via the [MAGIC Privacy Guides Fund](https://magicgrants.org/funds/privacy%5Fguides/). Our funds are independently governed, and MAGIC Grants does not have editorial control over this publication. MAGIC Grant's [press release](https://magicgrants.org/2025/11/17/Monero-RPC-Fuzzing) on this project noted that during the development process, ADA Logics discovered three vulnerabilities in Monero which were responsibly reported via HackerOne: One which triggered a stack-based buffer overflow, one which could cause the Monero daemon to crash when receiving a certain request, and one which triggered a soft restart of the daemon. These vulnerabilities have since been fixed. Monero has had access to free compute resources for fuzzing via Google's OSS-Fuzz project since [June 2020](https://github.com/google/oss-fuzz/pull/3941), but the suite of tests was limited to only 10% of Monero's codebase, and did not cover Monero's RPC endpoints at all prior to this change. The improvements to the tests [developed](https://github.com/monero-project/monero/pull/10004) by ADA Logics increased the total codebase coverage of Monero to 22%, a significant improvement. In their report, ADA Logics notes that they "consider it likely that further issues \[in Monero's codebase\] will be reported" once the code is being run by OSS-Fuzz, and that they would monitor the fuzzer in the future in case there are necessary adjustments required. ADA Logics has a long history of experience integrating continuous fuzzing into open-source projects: In [2021](https://adalogics.com/blog/fuzzing-100-open-source-projects-with-oss-fuzz) they had already integrated OSS-Fuzz support into over 100 projects, resulting in over 1,300 issues being verified and fixed. In a [tweet](https://x.com/MagicGrants/status/1990563565275918803), MAGIC Grants said that "the MAGIC Monero Fund intends to fundraise in the near future for a second fuzzing project focused on P2P, FCMP++, and other important code." They have a [newsletter](https://listmonk.magicgrants.org/subscription/form) where you can stay up to date with announcements like this if you are interested in following along. **Update:** This article was updated to include a paragraph on what the RPC server component of Monero is. ### WhatsApp contact discovery vulnerability identifies 3.5 billion users URL: https://www.privacyguides.org/news/2025/11/21/researchers-disclose-whatsapp-contact-discovery-vulnerability-that-identifies-3-5-billion-users/ Last updated: 2025-11-22T02:43:06.000Z Security researchers from the University of Vienna and SBA Research have [disclosed](https://github.com/sbaresearch/whatsapp-census/blob/main/Hey%5Fthere%5FYou%5Fare%5Fusing%5FWhatsApp.pdf) a now-patched vulnerability that can enumerate around 3.5 billion WhatsApp accounts using the app's contact discovery feature. The collected data includes a user's phone number, public encryption keys, and timestamps. If set to public, a threat actor can also access profile pictures and "about" text. This data can be used to infer other information, such as the account's operating system, account age, and even the number of linked devices. The researchers also identified millions of active WhatsApp accounts in countries where the app was [banned](https://www.reuters.com/sustainability/society-equity/which-countries-have-blocked-whatsapp-2025-08-14/), such as China, Iran, and Myanmar. Furthermore, they were able to recognize users of unofficial WhatsApp clients that reuse cryptographic keys. Around half of all affected accounts [appeared](https://www.npr.org/2021/04/09/986005820/after-data-breach-exposes-530-million-facebook-says-it-will-not-notify-users) in a 2021 Facebook data breach of over 500 million phone numbers. This means that leaked phone numbers would have encountered increased risk of being targeted by spam calls if this vulnerability was exploited. Contact discovery works when WhatsApp obtains access to a user's contacts list. The app uses this information to identify other users through their phone numbers. However, the research team claims that there is no limit to how many queries can be sent through WhatsApp's infrastructure, allowing an attacker to comb through millions of contacts. In a press release, Gabriel Gegenhuber, the lead author of the disclosure report, [notes](https://www.univie.ac.at/en/news/detail/forscherinnen-entdecken-grosse-sicherheitsluecke-in-whatsapp) that this behavior is unusual for large services like WhatsApp: > "Normally, a system shouldn't respond to such a high number of requests in such a short time — particularly when originating from a single source...This behavior exposed the underlying flaw, which allowed us to issue an effectively unlimited requests to the server and, in doing so, map user data worldwide." Meta has released a patch mitigating this issue, but concerns remain about the privacy of similar contact discovery features. Users may instead disable contacts access entirely to prevent tracking by both messengers and social media platforms. Alternative messengers have solved this problem by de-emphasizing contact discovery. [Signal](https://www.privacyguides.org/en/real-time-communication/#signal) allows users to manually add and verify contacts via nicknames, while [SimpleX](https://www.privacyguides.org/en/real-time-communication/#signal) and Matrix-based clients like [Element](https://www.privacyguides.org/en/social-networks/#element) do not require phone numbers upon account registration. ### Brave Announces Verifiable and Transparent TEE Support in Leo URL: https://www.privacyguides.org/news/2025/11/20/brave-announces-verifiable-and-transparent-tee-support-in-leo/ Last updated: 2025-11-20T23:45:25.000Z Today, Brave [announced](https://brave.com/blog/browser-ai-tee/) that their Leo AI assistant inside of the Brave browser will utilize [NEAR AI](https://docs.near.ai/cloud/private-inference/#the-private-inference-process) Nvidia-backed Trusted Execution Environments (TEE). TEEs provide an isolated, secure environment for processing user requests. The isolation works at the hardware level, and allows users to remotely cryptographically attest that their requests are actually running in a secure environment and that they're using the desired LLM. The [Confidential Computing](https://confidentialcomputing.io) technology is designed to protect against malicious infrastructure providers, including the owners of the servers the models are running on, and provide strong integrity guarantees, preventing tampering of your results. > Hardware isolation ensures that even a fully compromised OS cannot access or tamper with any code or data residing inside the TEE. In addition to this, TEEs expose unique hardware primitives such as secure boot and remote attestation to ensure only trusted code is loaded into the TEE and so that external parties are able to verify the integrity of TEE. The new technology is available in [Brave Nightly](https://brave.com/download-nightly/) builds for early testing and feedback. This announcement comes as the latest in a series of announcements from various AI providers who wish to improve the privacy and security of their AI offerings. First was Apple with their [Private Cloud Compute](https://security.apple.com/blog/private-cloud-compute/), then Google with their [Private AI Compute](https://blog.google/technology/ai/google-private-ai-compute/), then OpenAI [announced](https://openai.com/index/fighting-nyt-user-privacy-invasion/) plans to implement "client-side encryption" for ChatGPT. This is another great development for private AI, I hope to see more and more AI providers adopting technologies like this to protect the privacy of their users. ### Android's Quick Share is Now Compatible with AirDrop URL: https://www.privacyguides.org/news/2025/11/20/androids-quick-share-is-now-compatible-with-airdrop/ Last updated: 2025-11-20T22:10:21.000Z According to [Android Authority](https://www.androidauthority.com/quick-share-airdrop-compatible-without-apple-3618067/), Android's [Quick Share](https://support.google.com/android/answer/9286773?hl=en) feature for sending files wirelessly over the air is now officially compatible with AirDrop, without any help from Apple. Apple's [AirDrop](https://support.apple.com/guide/iphone/use-airdrop-to-send-items-to-nearby-devices-iphcd8b9f0af/ios) allows secure and simple file sharing to devices within Wi-Fi and Bluetooth range of your device. However, it was designed to be a proprietary feature only for Apple devices. Android's similar [Quick Share](https://en.wikipedia.org/wiki/Quick%5FShare), originally created by Samsung and later adopted by Google to replace its own Nearby Share in Google Play Services, provided the same functionality between Android users. But if you wanted to easily share files across Android and iOS, you were out of luck. Until today that is. Android Authority was able to get official confirmation from Google that the compatibility was strictly their own implementation and research: > We accomplished this through our own implementation. Our implementation was thoroughly vetted by our own privacy and security teams, and we also engaged a third party security firm to pentest the solution. In another statement from Google, they made very clear they are open to collaboration with Apple: > Our goal is to provide an easy and secure file sharing experience for our users, regardless of who they are communicating with. Like with RCS and unknown tracker alerts, we always welcome collaboration opportunities to address interoperability issues between iOS and Android. Apple previously has contributed their MagSafe technology to the Wireless Power Consortium to become part of the open [Qi 2 standard](https://www.chargewithqi.com/media/w0ha5cbk/qi2-certification-rolls-out-news-release-11132023.pdf). With pressure from the [EU](https://9to5mac.com/2025/06/03/apple-could-remove-airdrop-from-eu-iphones-as-legal-battle-heats-up/) to make AirDrop cross-compatible, Apple should be looking to open up their technology to avoid legal troubles and improve the user experience between Android and iOS users. ### Sturnus Android Malware Directly Captures Screen, Bypassing E2EE URL: https://www.privacyguides.org/news/2025/11/20/sturnus-android-malware-can-bypass-encrypted-messaging-capable-of-full-device-takeover/ Last updated: 2025-11-20T23:11:06.000Z A new strain of insidious Android malware has been [discovered](https://www.threatfabric.com/blogs/sturnus-banking-trojan-bypassing-whatsapp-telegram-and-signal#conclusions) that can “bypass encrypted messaging” by capturing content directly from the screen after decryption. The malware can also present convincing fake bank login screens in order to harvest credentials. > In addition, it provides attackers with extensive remote control, enabling them to observe all user activity, inject text without physical interaction, and even black out the device screen while executing fraudulent transactions in the background—without the victim’s knowledge. The researchers estimate that the malware is still in a “development or limited testing stage” but has “already been configured with targeted attacks against financial institutions across Southern and Central Europe.” The malware relies on Accessibility Services logging to capture everything that appears onscreen, “including contacts, full conversation threads, and the content of incoming and outgoing messages.” The malware achieves precise control over the device and is able to issue clicks, text input, accept permission prompts, and essentially provides the attackers full remote control over the device. It can transmit what’s on your screen without triggering the normal screen capture prompts and can even operate when elements are not on your screen. Malware like this is a sobering reminder that advanced capabilities aren’t limited to targeted individuals, we all need to take the security of our devices seriously. ### First Foreign Censorship Shield Bill Proposed in Wyoming URL: https://www.privacyguides.org/news/2025/11/20/first-foreign-censorship-shield-bill-proposed-in-wyoming/ Last updated: 2025-11-20T19:45:16.000Z A [blog post](https://prestonbyrne.com/2025/11/19/the-full-text-of-the-wyoming-granite-act/) by Preston Byrne, the lawyer representing 4chan in the ongoing [legal case with Ofcom](https://www.courtlistener.com/docket/71209929/4chan-community-support-llc-v-uk-office-of-communications/), announced that the GRANITE Act, “the first foreign censorship shield bill ever conceived in the history of the United States,” has been filed in the state of Wyoming. The bill would give Wyoming residents a way to fight back against attempted foreign censorship, such as what the UK Ofcom has been [attempting to do](https://www.openrightsgroup.org/blog/a-dangerous-precedent-for-global-censorship/) after passing the so-called “[Online Safety Act](https://www.gov.uk/government/collections/online-safety-act).” The act enforces age checks for harmful content, which includes things like pornography and mentions of suicide, really the definition could include anything the UK government doesn’t like. Ofcom has tried to fine multiple non-UK websites for failing to comply with the regulations, including [Wikipedia](https://wikimediafoundation.org/news/2025/09/12/wikimedia-foundation-challenges-uk-online-safety-act-regulations/) of all things. Their [targeting](https://www.theregister.com/2025/10/13/4chan%5Fofcom%5Ffine/) of 4chan with fines has resulted in the lawsuit mentioned above. Foreign censorship shield bills like the Wyoming GRANITE Act would provide targets of foreign censorship with significant legal recourse against such overreaches of power. > If we get corresponding federal action, this law – and laws like it – could represent the single greatest victory for global free speech in thirty years. While filing a bill is simply the first step in the legal process, it represents a promising future for free speech. You can read the [full text](https://prestonbyrne.com/wp-content/uploads/2025/11/Wyoming%5FGRANITE%5FAct%5Fv.3.pdf) of the bill courtesy of Preston. ### NovaCustom announces SHIFTphone with iodéOS: Security community concerned URL: https://www.privacyguides.org/news/2025/11/20/novacustom-announces-shiftphone-with-iodeos-security-community-concerned/ Last updated: 2025-11-20T18:00:36.000Z On November 12, Dutch-based computer manufacturer NovaCustom announced that they are selling a configurable version of the SHIFTphone 8.1, a modular smartphone similar to the Fairphone, with iodéOS pre-installed. However, many in the [privacy and security community](https://discuss.privacyguides.net/) have raised [concerns](https://discuss.privacyguides.net/t/novacustom-launches-privacy-friendly-phone-shiftphone-8-1-with-iodeos/32835/15) about the operating system's track record. Best known for their V54 and V56 series of modified Clevo laptops, NovaCustom is one of few European OEMs that sells customized privacy-focused computers. They [are](https://novacustom.com/dasharo-coreboot-plus-heads-firmware-version/) a financial contributor to the HEADS firmware project, which enables certain Qubes OS devices to resist evil-maid and bootloader attacks, and their V54 lineup is officially [Qubes-certified](https://doc.qubes-os.org/en/latest/user/hardware/certified-hardware/novacustom-v54-series.html). Their decision to sell smartphones is reminiscent of startups like Purism that develop similar device ecosystems. It appears that NovaCustom will be replacing the stock Android operating system on the SHIFTphone by pre-installing iodéOS 6, which itself is a fork of Lineage OS 22. iodéOS is a privacy-focused [Android](https://www.privacyguides.org/en/android/) custom ROM which replaces Google Play Services with microG, a free and open-source wrapper for Google Play which replaces Google's proprietary client code with open-source alternatives, though notably it does not replace Google's *server*\-side APIs by default. iodéOS is also [limited](https://lineageos.org/Changelog-29/) by their usage of LineageOS 22 to Android 15 QPR1 and security updates up to November 2024. This [announcement](https://discuss.privacyguides.net/t/novacustom-launches-privacy-friendly-phone-shiftphone-8-1-with-iodeos/32835) was met with mostly negative feedback within the *Privacy Guides* community. Although some members defended NovaCustom's decision as a way to support smaller companies with limited funding, others criticized the move as conflating privacy with security. The developer of the (now-defunct) DivestOS project [questioned](https://discuss.privacyguides.net/t/novacustom-launches-privacy-friendly-phone-shiftphone-8-1-with-iodeos/32835/72) NovaCustom for supporting iodéOS because of its alleged lack of support for the latest version of Chromium WebView, and telemetry to Google via SUPL and hardware provisioning. In their official blog [post](https://archive.ph/g1SC9), NovaCustom justified their decision to choose iodéOS over [GrapheneOS](https://www.privacyguides.org/en/android/distributions/#grapheneos) because of its accessibility to users concerned about "Big Tech tracking." They criticized GrapheneOS for supporting only Google Pixel devices, and praised iodéOS for being a balanced solution for users: > iodéOS is different. It is open source at \[sic\] well, but more minimalistic. In addition, it is technically less complex since microG and the Aurora Store are pre-installed by default. This allows you to install Play Store apps anonymously, while blocking Big Tech tracking as much as possible. > iodéOS offers the perfect balance between privacy, security, and user-friendliness. And that is exactly what we value at NovaCustom. Their original announcement also included comparisons to other operating system choices, including GrapheneOS, but it was since updated to remove those statements following [feedback](https://discuss.privacyguides.net/t/novacustom-launches-privacy-friendly-phone-shiftphone-8-1-with-iodeos/32835/90) from *Privacy Guides*. A follow-up [reply](https://discuss.privacyguides.net/t/novacustom-launches-privacy-friendly-phone-shiftphone-8-1-with-iodeos/32835/96) from NovaCustom's founder, Wessel klien Snakenborg, reveals that a partnership with the GrapheneOS project was attempted, but failed due to significant costs involved. According to NovaCustom, GrapheneOS estimated a successful hardware partnership would require the following: > \[ … \] Our understanding is that it costs something like 5 million USD for licensing everything and then perhaps around 1 million USD per year of support where Qualcomm can provide that for up to 8 years after they consider the platform to have launched. NovaCustom did not wish to resell currently-supported Google Pixel devices either, stating: > Depending on Google for the delivery of hardware isn’t a good idea either in our opinion. That way, you still make yourself dependent on big tech and you feed your enemy. In his post to the *Privacy Guides* community, Snakenborg noted that NovaCustom was open to questions and feedback about the announcement. At the time of writing, community members had posted some specific [questions](https://discuss.privacyguides.net/t/novacustom-launches-privacy-friendly-phone-shiftphone-8-1-with-iodeos/32835/72) for NovaCustom which have not yet been addressed. [NovaCustom launches privacy-friendly phone: SHIFTphone 8.1 with iodéOSAfter extensive testing, it’s finally here: the new SHIFTphone 8.1 with iodéOS is now available at NovaCustom! It’s a privacy-friendly phone that’s not only user-friendly and secure, but also sustainable and fully modular. This smartphone stands for privacy, security, freedom of choice, and repairability: values that perfectly align with NovaCustom’s mission. Privacy-friendly phone: SHIFTphone 8.1 with iodéOS - NovaCustom Why NovaCustom and SHIFTphone are the perfect match At NovaCustom, w…![](https://www.privacyguides.org/content/images/icon/50d23e21c43962bb12c02820fa3f19ac61dac917_2_180x180-33.png)Privacy Guides Communitymaltfield![](https://www.privacyguides.org/content/images/thumbnail/8f647841eacacde30eb8d5c3f6ef2e1163995f30_2_1024x662.png)](https://discuss.privacyguides.net/t/novacustom-launches-privacy-friendly-phone-shiftphone-8-1-with-iodeos/32835) ### Element Will Soon Make Verifying Your Devices Mandatory URL: https://www.privacyguides.org/news/2025/11/20/element-will-soon-make-verifying-your-devices-mandatory/ Last updated: 2025-11-20T16:29:43.000Z The Matrix-based messenger [Element](https://www.privacyguides.org/en/social-networks/#element) announced their [plans](https://element.io/blog/verifying-your-devices-is-becoming-mandatory-2/) to make verifying your devices mandatory before they are able to send or receive end-to-end encrypted messages, so you can be sure the person you’re messaging is really them. This change is scheduled to roll out to Element app users in April 2026. Currently, when you sign in to your [Matrix](https://matrix.org/) homeserver account in Element, your messages will appear with a red warning shield indicating an [unverified device](https://element.io/en/features/device-verification). This feature exists to protect against someone getting into your account and messaging as you. You can verify your new device from one of your pre-existing devices easily to prevent this warning. The issue is that it’s quite easy to ignore the red warning and continue messaging, which can leave your contacts vulnerable to messaging with an attacker instead of you. From my own personal experience, it can also just cause confusion. This update will fix this issue. The new UI simply won’t allow unverified devices to message your contacts. This marks a big improvement to security in Element and Matrix as a whole. ### Mozilla’s Monitor Plus Service is Shutting Down URL: https://www.privacyguides.org/news/2025/11/19/mozillas-monitor-plus-service-is-shutting-down/ Last updated: 2025-11-19T20:10:28.000Z Mozilla’s paid data removal service, Monitor Plus, will be [shut down](https://support.mozilla.org/en-US/kb/monitor-plus-shutting-down) on December 17\. The service offered automatic scanning and removal of personal data that ends up on data broker sites. Mozilla Monitor Plus landed in hot water after it was discovered that the CEO of the company Mozilla had partnered with, Onerep, had also [founded multiple data broker sites](https://freedom.press/digisec/blog/controversy-over-mozillas-anti-data-broker-service/). Mozilla doesn’t comment on the situation with Onerep, with the stated reason for shutting down being more about diverting resources to their other projects: > As part of our ongoing efforts to advance [Mozilla’s mission](https://www.mozilla.org/en-US/mission/) of ensuring people are empowered, safe, and independent online, we’re refocusing our resources on other privacy and security initiatives. This shift will allow us to better serve our users and continue developing tools that have the greatest impact in helping people protect their digital lives. Mozilla is offering refunds to customers, check their support page for more info. Mozilla claims all data related to the service will be deleted after the shutdown date. Monitor's free breach monitoring service and email monitoring service will remain active, however. ### Thousands of ASUS Routers Compromised in Suspected State-Sponsored Cyberattack URL: https://www.privacyguides.org/news/2025/11/19/thousands-of-asus-routers-compromised-in-sprawling-global-espionage-campaign/ Last updated: 2025-11-19T19:00:11.000Z SecurityScorecard’s [STRIKE](https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/) team has worked with ASUS to unveil a massive malware campaign against end-of-life ASUS WRT routers. Specifically, the attackers targeted ASUS’ [AiCloud service](https://www.asus.com/us/content/aicloud/), a service that allows you to combine your home network with an “unlimited personal cloud” that you can access from anywhere in the world via a mobile app. Why a router needs any cloud features is up for debate, but these services should be avoided not just for privacy but also for security reasons, especially if your device is outdated or "end-of-life." End-of-life devices are devices that no longer receive security updates from the manufacturer. This leaves them vulnerable to n-day vulnerabilities, or security issues that have been known about for a period of time, in contrast with 0-days which are vulnerabilities that are unknown to the manufacturer. These n-days can pile up and leave your device more and more vulnerable over time, and give attackers time to develop exploits that can be mass-deployed against swathes of people. The campaign relied on multiple OS command injection vulnerabilities (CVE-2023-41345, CVE-2023-41346, CVE-2023-41347, and CVE-2023-41348) to gain high-level privileges on the device. > Once the hackers compromise a device, it becomes part of a global network of infected routers. SecurityScorecard’s STRIKE team identified over 50,000 unique IP addresses belonging to these compromised devices over the last six months. The team were able to track the campaign thanks to “a shared, self-signed TLS certificate with an unusually long 100-year expiration period” that they were able to use as an indicator of compromise. If you’re an owner of an ASUS router, update immediately, or if it’s end-of-life, purchase a new one or install [custom firmware](https://www.privacyguides.org/en/router/) to stay secure. ### EU Digital Omnibus Supposedly Simplifies Digital Privacy Regulation URL: https://www.privacyguides.org/news/2025/11/19/eu-digital-omnibus-supposedly-simplifies-digital-privacy-regulation/ Last updated: 2025-11-19T18:27:27.000Z The EU Commission has put forth their [Digital Omnibus Regulation Proposal](https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal), which aims to simplify the GDPR in order to foster competitiveness. According to the [document](https://ec.europa.eu/newsroom/dae/redirection/document/121742): > The Digital Omnibus proposal includes a set of technical amendments to a large corpus of digital legislation, selected to bring immediate relief to businesses, public administrations, and citizens alike, to stimulate competitiveness. The amendments are explicitly focused on making data more accessible to companies for economic purposes. > For these reasons, the amendments focus on unlocking opportunities in the use of data, as a fundamental resource in the EU economy, not least in view of supporting the development and use of trustworthy artificial intelligence solutions in the EU market. Targeted amendments to the data protection and privacy rules support this objective and provide immediate simplification measures for businesses and individuals, strengthening their ability to exercise their rights. [Critics](https://www.abc.net.au/news/2025-11-20/eu-ai-big-tech-proposals/106030486) accuse the Commission of bowing to Big Tech pressure. Amnesty International released a [statement](https://www.amnesty.org/en/latest/news/2025/11/eu-digital-omnibus-proposals-will-tear-apart-accountability-on-digital-rights/) about their concerns with the EU's "ongoing deregulatory push" which includes this proposal, saying that it could dismantle the EU's current protections against digital threats. European Digital Rights (EDRi) [echos these concerns](https://edri.org/our-work/commissions-digital-omnibus-is-a-major-rollback-of-eu-digital-protections/), stating that the new Digital Omnibus "risks dismantling the rules-based system that was hard-won over decades," and that... > The Digital Omnibus proposals pander to corporate interests, with Big Tech players as well as European corporations standing to gain significantly. It also plays into the hands of the US administration, which has a vested interest in undermining the EU’s tech policy framework. Industry players also had privileged access to decision-makers and the law-making process: the Commission followed a procedure with legislative shortcuts that circumvented democratic scrutiny, sidelining concerns from civil society acting in the public interest. However, the proposal claims that the changes would level the playing field between small business and Big Tech, explicitly pointing to concerns smaller businesses have with complying with the current GDPR: > some entities, especially smaller companies and associations with a low number of non-intensive, often low-risk data processing operations, expressed concerns regarding the application of some obligations of the General Data Protection Regulation. The proposal also aims at “clarifying that further processing for scientific purposes is compatible with the initial purpose of processing and by clarifying that scientific research constitutes a legitimate interest.” EDRi claims this carve-out for scientific research will enable AI companies to use highly-sensitive personal information for AI training and other "high-risk algorithmic technologies." The EU also calls out those annoying cookie banners and the bad user experience and significant cost incurred by companies to comply. Specifically, the proposal calls for the GDPR to be the only regulation applying to these cookies and highlights that it paves the way for browser-based consent signals that would simplify the user experience and the implementation of websites. You should give the proposal a read for yourself, it’s available for download from their [website](https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal). ### Windows Announces “Experimental Agentic Features,” Admits Potential for Prompt Injection and Malware URL: https://www.privacyguides.org/news/2025/11/19/windows-announces-experimental-agentic-features-admits-potential-for-prompt-injection-and-malware/ Last updated: 2025-11-19T17:35:30.000Z Windows will be getting a new feature called [*Copilot Actions*](https://blogs.windows.com/windows-insider/2025/11/17/copilot-on-windows-copilot-actions-begins-rolling-out-to-windows-insiders/) that will allow Copilot to perform actions on behalf of the user by interacting with local files and applications. The agents will use a separate, contained environment called an ”Agent Workspace,” effectively acting “like a separate desktop instance just for Copilot.” Some example use cases they give are sorting through your files, converting files, and extracting data from PDFs. They say they are starting out with a narrow set of use cases “while we optimize model performance and learn.” Microsoft assures us that they’re taking security seriously with this feature and trying to isolate and give the agents minimal privileges, but there will always be potential for the agents to do something you don’t want them to, as [they themselves admit](https://support.microsoft.com/en-us/windows/experimental-agentic-features-a25ede8a-e4c2-4841-85a8-44839191dfb3): > Additionally, agentic AI applications introduce novel security risks, such as cross-prompt injection (XPIA), where malicious content embedded in UI elements or documents can override agent instructions, leading to unintended actions like data exfiltration or malware installation. This all might bring flashbacks of Windows Recall, a feature that Windows assured us was very [secure](https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/). While it’s admirable to put so much effort into securing new features, in the end it will always be less secure to have it than to not have it. ### Microsoft Issues Patch After Extended Security Updates Fail URL: https://www.privacyguides.org/news/2025/11/18/microsoft-issues-patch-after-extended-security-updates-fail/ Last updated: 2025-11-18T21:47:37.000Z Microsoft has put out a “preparation package” [KB5072653](https://support.microsoft.com/en-gb/topic/kb5072653-extended-security-updates-esu-licensing-preparation-package-for-windows-10-8c8b215c-d2af-44dc-b712-1ec403842cdc) for their Extended Security Updates (ESU) program to fix errors users who believed they were enrolled in the ESU program were experiencing when trying to update after Windows 10 support ended. This marks a rocky start for the already controversial program. With official support for Windows 10 ended on October 14, the [program](https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates) provides critical security updates to those who wish to continue running Windows 10 or who can’t upgrade to Windows 11, but only after charging a yearly subscription starting at $61 per device, with the cost doubling each consecutive year. The program also requires a Microsoft account in order to enroll, continuing the constant insistence by Microsoft to sign in to [an online account](https://pureinfotech.com/microsoft-blocks-windows-11-microsoft-account-bypass/) to use Windows. Microsoft landed itself in hot water in the EU over this program and was forced to provide updates to [EU users for free](https://www.euroconsumers.org/wp-content/uploads/2025/09/Euroconsumers%5Fvs%5FMicrosoft%5F092025.pdf), albeit only for one year. Of course, a Microsoft account is still required. Let’s hope paid updates don’t become the norm in the future. ### Elcomsoft Achieves Full Filesystem Extraction for Apple TV 4K on tvOS 26 URL: https://www.privacyguides.org/news/2025/11/18/elcomsoft-achieves-full-filesystem-extraction-for-apple-tv-4k-on-tvos-26/ Last updated: 2025-11-18T18:06:49.000Z Elcomsoft, purveyor of forensic extraction tools, [announced](https://blog.elcomsoft.com/2025/11/breaking-barriers-first-full-file-system-extraction-from-apple-tv-4k-running-tvos-26/) that they were the first to achieve a full filesystem extraction for the Apple TV 4K running tvOS 26, marking the first forensic extraction of one of Apple's latest operating systems, according to them. They plan to release support in their [iOS Forensic Toolkit](https://www.elcomsoft.com/eift.html) later. The first-generation Apple TV 4K runs the same A10X SoC found in the iPad Pro 2, bringing into question what security features Apple's streaming devices miss out on from [newer chips](https://support.apple.com/guide/security/apple-soc-security-sec87716a080/web). They highlight the difficulties of extracting data when the device lacks a USB C port, however there is apparently a hidden lightning connection in the ethernet port. Apple sells the [Apple TV](https://www.apple.com/shop/buy-tv/apple-tv-4k) in two configurations: one without an ethernet port and one with one, so maybe the one without an ethernet port is a bit more secure against forensic extraction. When we think of security, we tend to focus on securing our phones and desktop computers. But as more and more IoT devices enter our lives, we need to start thinking about the security of those as well. The Apple TV syncs a lot of data from your iCloud, such as [photos](https://support.apple.com/guide/tv/view-your-photos-and-videos-atvbfc5adda8/tvos). The device doesn't sync as much data as an iPhone or a Mac, but it's certainly enough to be worried about. They highlight the fact that the Apple TV can't be protected with a password, leaving your data at risk. It's time to take the security of our IoT devices seriously and demand stronger protections from the companies making these products. ### Trail of Bits Discloses Vulnerabilities in Elliptic JavaScript Library URL: https://www.privacyguides.org/news/2025/11/18/trail-of-bits-finds-vulnerabilities-in-widely-used-cryptographic-library-one-of-which-still-not-fixed-over-a-year-later/ Last updated: 2025-11-18T18:19:41.000Z Today, Trail of Bits, a well-respected security research and auditing firm, has [published a blog post](https://blog.trailofbits.com/2025/11/18/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/) outlining two vulnerabilities in [elliptic](https://www.npmjs.com/package/elliptic), a widely used JavaScript cryptographic library. The library has reportedly been downloaded over 10 million times and is used in almost 3,000 projects. One vulnerability, CVE-2024-48949, was promptly fixed by the maintainers on the *same day* Trail of Bits put forth their proposed patch. The other one, CVE-2024-48948, received no response when Trail of Bits tried to reach out. After 90 days, the vulnerability was made public in October 2024\. As of the posting of the article, the vulnerability *still* wasn't fixed. The vulnerabilities were discovered using [Wycheproof](https://github.com/C2SP/wycheproof), a repository of test vectors for testing attacks against cryptographic libraries and finding other implementation bugs and inconsistencies. This situation highlights the importance of a quick response from software developers to vulnerabilities reported to them. If they aren't addressed quickly, or in this case apparently ignored entirely, millions of people could be left vulnerable. > These vulnerabilities serve as an example of why continuous testing is crucial for ensuring the security and correctness of widely used cryptographic tools. In particular, Wycheproof and other actively maintained sets of cryptographic test vectors are excellent tools for ensuring high-quality cryptography libraries. We recommend including these test vectors (and any other relevant ones) in your CI/CD pipeline so that they are rerun whenever a code change is made. This will ensure that your library is resilient against these specific cryptographic issues both now and in the future. ### Swathes of the Internet are Down Due to Cloudflare Outage URL: https://www.privacyguides.org/news/2025/11/18/swathes-of-the-internet-are-down-due-to-cloudflare-outage/ Last updated: 2025-11-18T14:56:04.000Z Cloudflare, a widely-used provider of [anti-DDoS](https://www.cloudflare.com/ddos/) services to a significant portion of websites on the internet, is out, leaving large portions of the internet inaccessible. According to [W3Techs](https://w3techs.com/technologies/details/cn-cloudflare), Cloudflare is used by 20.4% of all websites. Cloudflare works by acting as a "[reverse-proxy](https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/#cloudflare-as-a-reverse-proxy)"; it sits in front of websites and takes requests from users and either forwards them to the real website or serves the request from their own servers. The benefit is that the real IP address of the website is never revealed, and Cloudflare's massive globe-spanning network can take just about any attack thrown at it. It can also provide faster load times since Cloudflare's servers are located all over the globe and the site can be served from one closest to the user. That is until there's an outage. [Previous Cloudflare outages](https://controld.com/blog/biggest-cloudflare-outages/) have caused similar levels of distress, although admittedly some were not Cloudlfare's fault. [Similar instances](https://aws.amazon.com/premiumsupport/technology/pes/) have happened with products like [Amazon Web Services](https://aws.amazon.com), an incredibly popular cloud solution used by countless businesses and websites. Instances like this bring into question the resiliency of the internet we rely on so heavily. Perhaps centralization of our web infrastructure isn't what we need for a strong and reliable internet: the strength of the internet, after all, is as a diverse and interconnected "web" of computers and networks. If you're looking for something to do while your favorite sites are down, [Privacy Guides](https://www.privacyguides.org/) remains unaffected, since we don't use Cloudflare's CDN/anti-DDoS services. ### GrapheneOS Builds Based on Android QPR1 Available for Public Testing URL: https://www.privacyguides.org/news/2025/11/18/grapheneos-builds-based-on-android-qpr1-available-for-public-testing/ Last updated: 2025-11-18T08:29:36.000Z The long-awaited QPR1 update was pushed to AOSP on [November 11th](https://www.androidauthority.com/android-16-qpr1-source-code-available-3614853/) after a long two-month delay, and the GrapheneOS team are hard at work on a QPR1 update for their operating system. [QPR1](https://source.android.com/docs/whatsnew/android-16-release) brings with it the much anticipated desktop mode, allowing you to plug your phone into a monitor and use it as a mini desktop computer. It also brings the new [Material 3 Expressive](https://m3.material.io) redesign, promising more vibrant colors and a new physics system for UI elements. QPR1 rolled out for Google's proprietary default Android operating system all the way back in early [September](https://9to5google.com/2025/09/03/android-16-qpr1-pixel/) and only just recently released it to AOSP, which is why the open-source GrapheneOS wasn't able to begin implementing the update until very recently. The team found several [regressions](https://grapheneos.social/@GrapheneOS/115564312012469001) from previous versions of AOSP but they've now been [fixed](https://grapheneos.social/@GrapheneOS/115567785127984935) and QPR1 is set to hit their Alpha and Beta channels soon. If you have a spare Pixel and want to help them test, [public builds](https://grapheneos.social/@GrapheneOS/115564312012469001) of the QPR1 update are now available, although they‘re “highly experimental” and not available through their Alpha channel yet. Hopefully the issues can be addressed in upstream AOSP so everyone running Android won’t have to deal with the same issues. [QPR2](https://developer.android.com/about/versions/16/qpr2) has released its third beta at this point. With any luck, it won't get the same excruciating delays, as the entire point of switching to quarterly releases was supposed to be to make it easier for Google to get updates out on time. ### Google: Less Than 20% of New Vulnerabilities in Android are Memory Safety Related URL: https://www.privacyguides.org/news/2025/11/18/google-reports-less-than-20-of-new-vulnerabilities-in-android-are-memory-safety-related/ Last updated: 2025-11-18T18:08:59.000Z A [blog post](https://security.googleblog.com/2025/11/rust-in-android-move-fast-fix-things.html) by Google shows that memory safety vulnerabilities account for less than 20% of new vulnerabilities in Android this year, down from 76% in 2019. This trend is a continuation of Google’s push toward writing new code in memory-safe languages. A [blog post](https://security.googleblog.com/2024/09/eliminating-memory-safety-vulnerabilities-Android.html) from last year described the seemingly disproportionate impact this strategy had on eliminating memory safety issues overall. Essentially, old code written in memory-unsafe languages tends to have significantly fewer vulnerabilities than new code, so instead of trying to rewrite all old code in Rust, it’s better to write new code in Rust since that will have the greatest impact on preventing vulnerabilities. This information shows that it’s possible to massively improve memory safety vulnerabilities in projects that have been written in memory-unsafe languages for years, without having to do a full rewrite. Furthermore, it can start at any time. Rust, as a low level language, allows for the level of control and performance needed for programming things like operating systems and browsers while maintaining memory safety. [CISA](https://www.cisa.gov/news-events/news/urgent-need-memory-safety-software-products) in 2023 put out an urgent call for software developers to use memory safety languages, citing the excessively high proportion of vulnerabilities caused by memory safety bugs. Google’s work should serve as a template for projects looking to incorporate memory-safe languages into their codebase. ### Brave Unveils Coral, Their New System for Verifiable Parsing URL: https://www.privacyguides.org/news/2025/11/18/brave-unveils-coral-their-new-system-for-verifiable-parsing/ Last updated: 2025-11-18T03:12:44.000Z In a new [paper](https://eprint.iacr.org/2025/1420.pdf) and accompanying [blog post](https://brave.com/blog/coral/), Brave has unveiled *Coral*, “a system for proving in zero-knowledge that a committed byte stream corresponds to a structured object in accordance with a Context Free Grammar.” The system aims to plug a previously under-examined hole in zero-knowledge proofs: getting from a raw stream of data to a structured. According to Brave, current solutions “typically assume the API response is already a well-formed JSON object (or HTML).” If invalid HTML or JSON is provided, it could allow a malicious prover to convince the verifier of a wrong fact." The idea behind zero-knowledge proofs is to prove a specific fact without revealing any other data, hence “zero-knowledge.” ZKP consist of a ”prover,” who is trying to prove they know an secret, and a “verifier,” who the prover is trying to prove the statement to without revealing any extra information other than fact that the statement is true. Brave previously released a [blog post](https://brave.com/blog/zkp-age-verification-limits/) detailing the issues with current zero-knowledge proof implementations, among which was the "semantic gap between low-level data (e.g., raw byte streams) and the structured data over which the proof is supposed to operate." They highlighted, albeit only briefly, the fact that "\[most\] systems implicitly assume that inputs are already well-formed, for instance, that a JSON object respects its grammar or that a credential conforms to a standard syntax." The new research seeks to fill this gap and inch us closer to more resilient ZKP systems such as those found in [digital IDs](https://www.apple.com/newsroom/2025/11/apple-introduces-digital-id-a-new-way-to-create-and-present-an-id-in-apple-wallet/) being rolled out in certain countries and states. They highlight some possible future applications: > With parsing in zero knowledge now within reach, new avenues open up. For instance, a prover can commit to a TLS transcript and prove not just that some field exists, but that the transcript itself parsed correctly under the relevant grammar. A user can prove properties of a credential without revealing the token or its structure, knowing that malformed inputs cannot trick the verifier. Compilation chains, often opaque and difficult to audit, can be proven end-to-end: from source code to binary, with the parsing steps included. Even middleboxes can enforce policies while respecting privacy, because they can rely on proofs about the syntactic structure of traffic rather than trust opaque byte streams. With ZKP seemingly becoming more and more relevant to our daily lives, this type of research is much needed. Congrats to the researchers and I can't wait to see what they do next. ### WhatsApp Rolls Out Messaging Interoperability for Europeans URL: https://www.privacyguides.org/news/2025/11/18/whatsapp-rolls-out-messaging-interoperability-for-europeans/ Last updated: 2025-11-18T01:01:50.000Z [Meta](https://about.fb.com/news/2025/11/messaging-interoperability-whatsapp-enables-third-party-chats-for-users-in-europe/) has started allowing third-party messengers to interoperate with WhatsApp in compliance with the European Digital Markets Act (DMA). The law requires Meta to allow third-party messengers that choose to interoperate with WhatsApp the ability to do so. So called "third-party chats" will retain WhatsApp's end-to-end encryption (E2EE), allowing users of third-party messaging apps to retain the "same level of E2EE as WhatsApp." The change is apparently being rolled out gradually and will be opt-in at first. The first third-party messaging apps to support the new interoperability are [BirdyChat](https://www.birdy.chat) and [Haiket](https://haiket.com). > Meta’s partnerships with BirdyChat and Haiket is a result of more than three years of work with European messaging services and the European Commission to build a solution to third-party chats that meets the requirements of the DMA, while preserving privacy and security for users as much as possible. It's unclear whether the feature will eventually be rolled out globally or just stay within the EU. You can read a previous [blog post](https://engineering.fb.com/2024/03/06/security/whatsapp-messenger-messaging-interoperability-eu/) by Meta on how they worked with the commission to design a new secure protocol based on their previous work for the new feature and the challenges therein. It's quite an interesting read. ### Google Plans to Restrict Installing Apps Outside Google Play to "Experienced Users" URL: https://www.privacyguides.org/news/2025/11/17/google-plans-to-restrict-installing-apps-outside-google-play-to-experienced-users/ Last updated: 2025-11-17T16:10:09.000Z Google recently [posted](https://android-developers.googleblog.com/2025/11/android-developer-verification-early.html) a blog seeking feedback about the [Android](https://www.privacyguides.org/en/android/) developer verification program they announced in August. The [original plan](https://android-developers.googleblog.com/2025/08/elevating-android-security.html) was to require all app developers to submit to identity verification before their app could run on a "certified Android device" platform, **regardless** of whether the developer distributed their app on Google Play, via a free and open-source [alternative](https://www.privacyguides.org/en/android/obtaining-apps/) like F-Droid, or on a popular open-source code platform like Codeberg or GitHub. In their most recent post they appear to roll back the original proposal slightly, stating: > While security is crucial, we’ve also heard from developers and power users who have a higher risk tolerance and want the ability to download unverified apps. > Based on this feedback and our ongoing conversations with the community, **we are building a new advanced flow that allows experienced users to accept the risks of installing software that isn't verified.** The company says this "advanced flow" will include clear warnings about the risks of installing apps outside the Play Store and safety checks against potential coercion from scammers. Many of these statements ring hollow, however, against the reality that Google's own software distribution channels (including Google Play and the Chrome Web Store on desktop) are frequently [found](https://discuss.privacyguides.net/t/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware/28984) to [distribute](https://arstechnica.com/security/2024/09/11-million-devices-infected-with-botnet-malware-hosted-in-google-play/) malware, adware, and spyware, sometimes even via apps which have supposedly been verified by Google. In fact, the most prevalent mobile [spyware](https://techrights.org/n/2023/10/19/Google%5FBecoming%5FMore%5FLike%5FApple%5FUser%5FHostile%5FLock%5FDown%5FUsers%5FSo.shtml) of our time, **Google Play Services**, is bundled with the vast majority of apps distributed on the Play Store by design, improperly collecting data and creating security holes in Android security model with its highly privileged design which security-focused Android alternatives like [GrapheneOS](https://www.privacyguides.org/en/android/distributions/) have to go out of their way to sandbox and fix. Last September, F-Droid [released](https://f-droid.org/en/2025/09/29/google-developer-registration-decree.html) a statement saying that Google's proposed changes to the Android platform would "end the F-Droid project and other free/open-source app distribution sources as we know them today," and it does not seem likely these proposed changes will change that. Google knows as well as any computer user that their artificially increased friction will stop many people from using alternative app stores: They lost a lawsuit with Epic Games for this very reason. It seems like Google and Apple are "settling" the issue of no longer being able to legally control which apps get installed on their devices by instead heavily restricting the ways that apps are distributed. It should be clear that this does not hold up as a real solution, and people need to demand a clear line in the sand: that your devices are your own. As F-Droid rightfully pointed out, Google already has a system (Play Protect) that could prevent malware installations on certified Android devices if Google felt confident in their ability to identify malware. What Google is proposing is not new in the tech space, Apple has had a similar practice forever on iOS and for years on desktop, which seems to worsen with every new macOS release. However, it may be the most impactful example of this practice yet if implemented. The rebrand of the user's freedom to install their own apps of their choosing as "sideloading" has been decried for years by free software advocates, who argue that software is fundamentally just information, and no middle-men should be able to block anyone's access to information. Google mandating a verification scheme for developers is just an extension of this Digital Rights Management (DRM) debate that has been ongoing in the United States since 1998. The truth is that if a "Digital Right" is being granted to you by a tech corporation, then it isn't a right at all. ### Ben Jordan Exposes Severe Security Vulnerabilities in Flock Surveillance Cameras URL: https://www.privacyguides.org/news/2025/11/17/ben-jordan-exposes-severe-security-vulnerabilities-in-flock-surveillance-cameras/ Last updated: 2025-11-17T02:37:49.000Z YouTuber and musician Ben Jordan, in a [40 minute exposé](https://www.youtube.com/watch?v=uB0gr7Fh6lY) of Flock Safety's flimsy security, showed just how easy it is for hackers to get the sensitive data stored inside one of their ubiquitous surveillance cameras. The cameras (which apparently run Android) allow anyone with physical access to one of the cameras can simply press a button on the back in a specific, undisclosed sequence, a Wi-Fi access point is created. From here, you simply connect to it, enable [adb](https://developer.android.com/tools/adb), and you essentially have carte blanche access to the device. You can install your own malicious software or really anything you want, it's yours now. "The longest part, actually, is waiting for the hotspot to turn on," said [Jon Gaines](https://gainsec.com/2025/11/05/formalizing-my-flock-safety-security-research/), the original discoverer of the vulnerability, at one point in the video. The device also has completely exposes USB ports which means you can simply plug in a malicious USB device like a [rubber ducky](https://shop.hak5.org/products/usb-rubber-ducky?srsltid=AfmBOorqAwR1FNsb%5FQ3kjAhLYP0a9ZNZU5eH2I12SChVR7-A-J6W3Lxc) that pretends to be a keyboard and executes scripts that way. The interface that police use to access data from Flock cameras also doesn't require 2FA for police departments, a mind-boggling decision considering how sensitive the data is. The cameras also have hard-coded Wi-Fi network names that they will happily connect to when an LTE signal isn't available, making it easy for an attacker to trick them into connecting to a malicious Wi-Fi access point. Some would even connect to the malicious Wi-Fi whether a SIM card was inserted or not. The cameras were sending cleartext credentials, allowing for an extremely easy man-in-the-middle attack. An IMSI catcher, a device which mimics a cell tower to trick cellular devices into connecting to it, could also be used to MITM the devices. The cameras would also store images unencrypted whether a license plate was detected or not. They also found images stored all the way from the devices were tested in the factory, suggesting that images aren't deleted. The cameras were also found to be running Android 8, a version of Android that hasn't had security updates since 2021 and is missing all of the Android security features added since 2017. The video is an absolute treat, you should go give it a watch, and check out Jon Gaines' site and write-up as well. ### Android Might be Getting an iOS NameDrop Equivalent URL: https://www.privacyguides.org/news/2025/11/16/android-might-be-getting-an-ios-namedrop-equivalent/ Last updated: 2025-11-18T18:22:20.000Z According to [Android Authority](https://www.androidauthority.com/google-contact-gesture-exchange-apk-teardown-3615939/), "Contact Exchange," an equivalent to iOS’ NFC NameDrop contact sharing feature, might be coming soon to Android. The feature on iOS allows easy contact sharing by holding your devices close together. It works using [Near-Field Communication](https://nfc-forum.org/learn/nfc-technology/), a technology restricted to very close proximity wireless communication. The iOS feature allows you to choose specifically what you want to share, and it appears the Android version works similarly. NameDrop on iOS also requires Bluetooth and Wi-Fi to be activated in order to work. It’s unclear if Google will use NFC or rely purely on Bluetooth/Wi-Fi to facilitate the feature. Notably, on Android NFC can be disabled system-wide, a feature lacking on iOS, so security-conscious users could theoretically keep it off and only turn it on when they want to share contacts. This feature will be a welcome addition to Android I think, sharing contact info directly in-person rather than over a messaging app or, god forbid, email, prevents a man-in-the-middle attack where your messages are intercepted and read by a third party. Most people don’t [verify their keys](https://support.signal.org/hc/en-us/articles/360007060632-What-is-a-safety-number-and-why-do-I-see-that-it-changed) on the messaging apps they use (although they should). In fact, the in-person meeting could be a good opportunity to verify each other in your messaging app of choice. ### Email Security: Where We Are and What the Future Holds URL: https://www.privacyguides.org/posts/2025/11/15/email-security-where-we-are-and-what-the-future-holds/ Last updated: 2025-11-15T22:46:24.000Z Email is ubiquitous. If you want to function in modern society, you pretty much have to have an email address. What was originally just a simple protocol to send messages between machines has morphed beyond what it was originally intended for into the *de facto* authentication, identity, and "secure" communication channel for almost all technology users today. It's been updated many times to fix security issues and there are more updates to come, but is it worth trying to fix a decades-old protocol, or should we scrap it all and start over? ## Current State of Email Security The [**Simple Mail Transport Protocol (SMTP)**](https://www.rfc-editor.org/rfc/rfc5321.html) is the standard used to send emails. Over the years, multiple protocols have been introduced to fix security issues and improve the usability of email, resulting in a complex mess that we're still feeling the consequences of to this day. ### Encryption By default, there's no encryption in SMTP. Not transport encryption or end-to-end encryption, it's just a plaintext protocol. To remedy this, several solutions have been created. #### STARTTLS [STARTTLS](https://www.rfc-editor.org/rfc/rfc3207) is a command that allows email clients to negotiate TLS encryption. Importantly, the negotiation phase happens in plaintext which leaves it vulnerable to attackers. STARTTLS allows a bit more flexibility at the cost of some security. Since you don't really know if the recipient's email client supports TLS or not, it allows you to continue with the SMTP session anyway if you want to. Since it's just using TLS, STARTTLS can't provide E2EE, just transport encryption. The encryption looks something like: Encrypted between your email client and your SMTP server → decrypted at your SMTP server → Encrypted between your SMTP server and recipient's SMTP server → decrypted at recipient's SMTP server → encrypted between their SMTP server and their POP3/IMAP server → decrypted at their POP3/IMAP server → encrypted between their POP3/IMAP server and their email client → decrypted by their email client. At each point in the process TLS encryption is not guaranteed. Now consider that you can have multiple recipients with their own SMTP servers as well, and you start to see how flimsy this protection can be. And since the initial negotiation is in plaintext, an attacker can simply strip away the STARTTLS command, preventing a secure connection from being established. Authentication is left to another protocol to solve, this just handles the transport encryption. #### SMTPS Also known as "Implicit TLS" (as opposed to the "Explicit TLS" of STARTTLS), SMTPS starts with an encrypted connection, similar to HTTPS, removing the potential for an adversary to downgrade the connection. The [current](https://datatracker.ietf.org/doc/html/rfc8314) recommendations are to use port 465 for SMTPS and port 587 for STARTTLS. Unfortunately, these ports aren't standardized and thus there is disagreement and confusion about what port should be used for SMTPS. In the past, ports 25, 465, 587, and 2525 have all been used for SMTP at various points. This lack of a standardized port means that you end up with services using different ports and being unable to establish a secure connection. Particularly, there is still confusion in some email providers whether to use port 465 or port 587 for SMTPS, although the current recommendation is port 465. #### POP3S [Post Office Protocol version 3](https://en.wikipedia.org/wiki/Post%5FOffice%5FProtocol) or POP3 is a protocol for retrieving mail from a mail server. It's one of the ways your email client can show you your mail. POP3 also supports implicit TLS over port 995, so it can be encrypted by default as well. #### IMAPS [Internet Message Access Protocol](https://en.wikipedia.org/wiki/Internet%5FMessage%5FAccess%5FProtocol) or IMAP is another protocol for retrieving mail from a mail server. Like SMTPS and POP3s, IMAP supports implicit TLS. The implicit TLS port is 993. #### OpenPGP The above features only protect the email in transit and don't protect against the email providers involved, which is a massive security issue if you don't trust your email provider. On top of that, you as a user have no control over which parts of the chain are encrypted. If you want to be sure that no party in between you and your recipient can read or alter your emails, you need to use end-to-end encryption. Unfortunately, by default, email doesn't support end-to-end encryption. [Pretty Good Privacy (PGP)](https://www.openpgp.org/about/) was originally created in 1997 by [Phil Zimmerman](https://www.privacyguides.org/videos/2025/05/08/when-code-became-a-weapon/). While originally proprietary software, an open source version of PGP called OpenPGP has been standardized by the [IETF](https://www.rfc-editor.org/rfc/rfc9580.html). As you can imagine from software originally conceived in the 90s, the user experience isn't the smoothest. Unlike modern messengers like [Signal](https://signal.org), OpenPGP requires you to [manually manage your keys](https://dev.to/adityabhuyan/how-to-generate-your-own-public-and-secret-keys-for-pgp-encryption-1joh). This is a problem not only because it's cumbersome, but the security of E2EE rests on protecting the private key. If the private key is compromised, your messages are compromised. PGP also lacks [forward secrecy](https://en.wikipedia.org/wiki/Forward%5Fsecrecy), meaning that if your private key is ever exposed, all previous messages you've ever sent using that key are also exposed. All it takes is a slight user error for a catastrophic compromise. PGP encryption also usually doesn't encrypt important metadata like `To`, `From`, `Cc`, `Date`, and `Subject`, stored in the [email header](https://en.wikipedia.org/wiki/Email#Message%5Fheader). Usually, only the body of the email is encrypted, which can be a major privacy issue. What the email is about, who you are, and who you're messaging can all be revealed even with E2EE. Some email clients use their hidden headers that can reveal more data about you. #### S/MIME Another common option for email encryption is [S/MIME](https://www.digicert.com/faq/email-trust/what-is-smime-or-encrypted-email), or Secure/Multipurpose Internet Mail Extensions. S/MIME works a bit like HTTPS, using [X.509 digital certificates](https://www.ssl.com/faqs/what-is-an-x-509-certificate/) and [certificate authorities](https://www.digicert.com/blog/what-is-a-certificate-authority) to encrypt and verify the authenticity of emails. While a step up from the manual keys of PGP, S/MIME is still a pain to use, particularly because it usually requires purchasing and managing a certificate from a CA, which can be expensive and annoying. S/MIME also lacks forward secrecy just like PGP, so if there's ever a compromise of your private key, all previously sent messages are also compromised. These issues make S/MIME nonviable for most people outside business settings. #### Web Key Directory A problem with PGP is getting your public key out to people without manually exchanging keys. This problem can be solved with Web Key Directory (WKD), which allows you to upload your public PGP key to a server and clients that want to send E2EE emails to you can ask that server to send you their public key. You can read more on our [email security](https://www.privacyguides.org/en/basics/email-security/?h=email#what-is-the-web-key-directory-standard) page. ### Authentication SMTP by default essentially has no authentication and allows spoofing the `MAIL FROM` header. Your email client will just blindly accept whoever the sender says they are without any authentication. Luckily, there are several solutions for this. There are multiple methods that email providers can implement to verify the authenticity of an email sender. #### SPF The first solution implemented was [Sender Policy Framework (SPF)](https://datatracker.ietf.org/doc/html/rfc7208). SPF uses [DNS TXT records](https://www.cloudflare.com/learning/dns/dns-records/dns-txt-record/). Just like the name sounds, a DNS TXT record allows you to store text in a [DNS record](https://www.cloudflare.com/learning/dns/dns-records/). Here's an example of what a DNS TXT record might look like: | example.com | record type | value | TTL | | ----------- | ----------- | ------------ | ----- | | @ | TXT | "color=blue" | 99999 | SPF lists all the servers that are authorized to send from a specific domain. When an email is received, it checks the sending server against the list of authorized servers for that domain. An SPF record might look like this: | example.com | record type | value | TTL | | ----------- | ----------- | ------------------------------------------------------------------------- | ----- | | @ | TXT | "v=spf1 ip4:200.56.78.99 ip4:156.67.109.43 include:\_spf.google.com -all" | 99999 | The IP addresses are the ones that are authorized to send email from this domain. The `include:` tag denotes what third-party domains are allowed to send email on behalf of `example.com`. The third-party SPF record will be checked and included in the allowed IP addresses. While a good start, SPF still has several glaring weaknesses. Since it relies on DNS, an attack on the DNS infrastructure could cause spoofed DNS data to be accepted. Since SPF doesn't authenticate individual users, it's still possible for a sender to impersonate another user. SPF does not authenticate the `MAIL FROM` header. If you try to send an email from a gmail.com domain, but the server doesn't match gmail.com, it will fail. SPF has a few different modes, allowing for a hard fail, soft fail, or completely ignoring it. `-all` means an email that fails will be rejected, `~all` will mark emails that fail as insecure or spam but still send them, and `+all` will specify that any server is allowed to send emails on behalf of your domain. This flexibility, while convenient, allows for the security benefits of SPF to be completely undermined. #### DKIM [DomainKeys Identified Mail (DKIM)](https://www.cloudflare.com/learning/dns/dns-records/dns-dkim-record/) relies on public key cryptography to verify the domain of an email. Example of a DKIM DNS TXT record: | name | record type | value | TTL | | ---------------------------------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---- | | test-email.\_domainkey.example.com | TXT | "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtY+7sGVwvyS8w+3HgJk7EviazH+C4L8gV4gOJzAq9oKJjZ5En7LDEw3FqAh8C0M59c9sBQcC+Kj8VxMBY9y+E0Pm1fPK9V7sI3Gm7yE7Y9yU4uVZr8R3N+5z+qZ+7V76RU4oZ0mtSvw8m3pX1hZyHd7NZfXaFfKfgd18W5T7YQIDAQAB" | 9999 | DKIM records are stored under a specific name following the format `[selector]_domainkey.[domain]` The public and private keys are generated by the email provider, such as gmail.com. The public key is stored in a publicly available DNS TXT record like the one seen above and is used by the receiver to verify messages. The private key is kept secret by the email provider. Emails sent from the email provider contain a DKIM header with a signature generated from the private key and the content of the message. If the email message is altered or signed with the wrong key, when the receiver verifies the signature using the public key it will be obvious it was altered. An example of a DKIM header: `v=1; a=rsa-sha256; d=example.com; s=test-email; h=from:to:subject bh=uMixy0BsCqhbru4fqPZQdeZY5Pq865sNAnOAxNgUS0s=;b=LiIvJeRyqMo0gngiCygwpiKphJjYezb5kXBKCNj8DqRVcCk7obK6OUg4o+EufEbBtRYQfQhgIkx5m70IqA6dP+DBZUcsJyS9C+vm2xRK7qyHi2hUFpYS5pkeiNVoQk/Wk4wZG4tu/g+OA49mS7VX+64FXr79MPwOMRRmJ3lNwJU=` `v=` shows the version of DKIM, currently version one is the latest (we'll come back to that later). `a=` shows the algorithm used. `d=` shows the domain of the sender. `s=` denotes the selector that is used in the TXT record. `h=` shows the headers that were used to create the signature. `bh=` shows a hash of the body of the email. `b=` is the signature computed from the listed headers and the hash of the body listed in `bh`. In this way, not only does DKIM provide assurance that the email was sent from the correct domain, it also protects the integrity of the message. However, since the keys are controlled by your email provider, it can't stop your email provider from tampering with your messages. Note also that this has nothing to do with encryption of the message, only verifying the authenticity and sender. The message is still sent in plaintext unless another component encrypts it. #### DMARC [Domain-based Message Authentication Reporting and Conformance (DMARC)](https://www.cloudflare.com/learning/dns/dns-records/dns-dmarc-record/) is an authentication method that builds on SPF and DKIM. DMARC tells a receiving email server what to do after checking the SPF and DKIM. If the email fails, the DMARC policy tells the receiver whether to mark it as spam, block it, or allow it through. DMARC also uses TXT records. An example DMARC policy might look like `v=DMARC1; p=quarantine; adkim=s; aspf=s;` The `v=` shows the version of DMARC to use. The `p=` shows what should be done with emails if they fail, in this case `quarantine` means the receiver should put the email in the user's spam folder. `reject` can be specified as well to show that emails that fail should be outright blocked. `adkim=` tells how DKIM should be enforced, with `s` meaning "strict"; for relaxed, `r` is listed instead. Ditto for `aspf=`. #### DNSSEC You may have noticed that all of these authentication methods rely on DNS. Unfortunately, DNS wasn't designed to be secure when it was invented in the 1980s. Ironically, there's no authentication built into DNS by default, so by attacking DNS, a malicious actor can [poison](https://www.cloudflare.com/learning/dns/dns-cache-poisoning/) your DNS cache with false information. [Researchers at CMU in 2014](https://www.sei.cmu.edu/blog/probable-cache-poisoning-of-mail-handling-domains/) found that emails that were supposedly to be sent by Gmail, Yahoo!, and Outlook.com were actually being sent by a rogue email server. This is disastrous for security and breaks the entire email authentication system. There are many such cases of attacks on DNS infrastructure and many more [possible attacks](https://www.akamai.com/glossary/what-are-dns-attack-vectors) on DNS. The solution? [DNSSEC](https://www.cloudflare.com/learning/dns/dnssec/how-dnssec-works/). DNSSEC uses digital signatures to verify the authenticity of the DNS response. Unfortunately, DNSSEC isn't as widely used as it could be so DNS attacks are still a real threat. DNSSEC forms a [chain of trust](https://en.wikipedia.org/wiki/Chain%5Fof%5Ftrust), with each zone forming a parent/child relationship all the way up to the [root zone](https://www.cloudflare.com/learning/dns/glossary/dns-root-server/). The public key infrastructure (PKI) that we rely on for things like HTTPS in browsers similarly relies on a chain of trust, but web PKI relies on many trusted entities whereas DNSSEC effectively reduces it to one: the IANA which signs the root zone key in a [root signing ceremony](https://www.cloudflare.com/learning/dns/dnssec/root-signing-ceremony/). Effectively, DNSSEC is designed so that you can be sure the results of a DNS query are accurate. #### DANE DNS-Based Authentication of Named Entities or DANE applies the security of DNSSEC to email. It forces TLS to be used and binds the TLS certificate to DNS names directly using TLSA, thus allowing email providers to bypass the certificate authority system relied on by HTTPS. #### MTA-STS [MTA-STS](https://www.mailhardener.com/kb/mta-sts) or Mail Transfer Agent Strict Transport Security is a way to force TLS connections for email and validate that the DNS is correct. Instead of DNSSEC, MTA-STS relies on HTTPS and the web PKI to validate DNS. It's not stored as a DNS record but instead an HTTPS server that serves the file. You can think of MTA-STS like HSTS, HTML Strict Transport Security, which forces the use of TLS for websites. It's the same principal, just applied to email. The extra reliance on web PKI introduces more trust than with DNSSEC, but it's easier to implement and relies on the already-established infrastructure of the internet. Both DANE and MTA-STS can be used together for a multilayered approach to email security. ### General Security #### Email as a Backdoor into Your Accounts Something seldom discussed is the fact that email is the default 2FA method for most accounts and also can be used to bypass your password through the password reset function on the login screen of most services. This essentially means the security of all of your accounts rests on the security of your email, which can be very shaky and lacks E2EE usually. It's most comparable to SMS 2FA which is also used a lot of the time as a method for getting into accounts when you forgot your password. I touched on this a bit in my [passkey article](http://127.0.0.1:8001/articles/2025/03/08/toward-a-passwordless-future/), but we need to stop relying on email for security critical applications and start using proper recovery methods like recovery codes. Email should be used for what it's intended for: sending messages and updates to people, announcements, etc. #### Third-Party Clients Many email providers such as Gmail provide their own clients for you to view your inbox, send messages, etc. But many people choose to use third-party clients for their email needs. While it's great that email can support that, it does mean you need to trust another party with your sensitive email and essentially the security of all of your accounts. Not to mention that email clients can have [vulnerabilities](https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/), so you need to be very careful about which one you trust. #### Email Attack Surface A big part of the reason email clients can be so vulnerable to exploits is the vast attack surface afforded by things like JavaScript support in emails. This puts email clients dangerously close to the same territory as browsers in terms of attack surface but without the same level of scrutiny or hardening effort that goes into browsers. Since almost anyone can email you at any time, you have to trust that your email client vendor is able to protect you against [vulnerabilities](https://www.csoonline.com/article/1308164/microsoft-outlook-flaw-opens-door-to-1-click-remote-code-execution-attacks.html) and also has timely patches when they're found. Luckily, lots of email clients let you disable JavaScript and HTML if you want, but not all do, and email clients can have lots of other vulnerabilities as well not related to JavaScript. ## Future of Email Security It's been a multi-decade cross-industry effort to bring email up to snuff as a modern communication system, and we still have a long way to go. There's still efforts to improve the state of email security, so look out for these in the future. ### Improvements to OpenPGP The IETF has a [working group](https://datatracker.ietf.org/wg/openpgp/about/) for OpenPGP that wants to add many improvements to OpenPGP, including post-quantum encryption, forward secrecy, and usability improvements. Key transparency is also a planned feature, similar to what apps like [WhatsApp](https://scontent.xx.fbcdn.net/v/t39.8562-6/379264560%5F846690136905658%5F6336040801441930900%5Fn.pdf?%5Fnc%5Fcat=108&ccb=1-7&%5Fnc%5Fsid=e280be&%5Fnc%5Fohc=gNmDlLkE0DMQ7kNvwEyKONi&%5Fnc%5Foc=AdmucQjSjoTw2nXUszYeZNStyUHGqvM2pj3oRVV7qI4xmLEJMmY2pUV29WcOnKC1KpA&%5Fnc%5Fzt=14&%5Fnc%5Fht=scontent.xx&%5Fnc%5Fgid=5lSqV7L5iCqeiMSQDCwN0w&oh=00%5FAfXoxrF8ukQtSVZM%5FBCBDbveIDviQPfn0kDEV8pSbxX1SQ&oe=68AB9400) have implemented. Key transparency systems use an append-only, auditable and tamper-evident log of keys that allows you to automatically verify the authenticity of whoever you're messaging with. There's even a plan to add the ability to verify keys manually using QR codes, similar to how some messengers let you manually verify keys. ### Improvements to S/MIME The [LAMPS](https://datatracker.ietf.org/wg/lamps/about/) working group is looking at adding post-quantum encryption to S/MIME to protect against future quantum computer threats. This would include "dual-signature" schemes combining traditional encryption with PG encryption, similar to how some messengers handle it. ### DKIM2 [DKIM2](https://www.ietf.org/archive/id/draft-gondwana-dkim2-motivation-00.html) is the planned next version of DKIM. An issue with the current version of DKIM is a malicious actor taking emails signed with DKIM from a different domain and replaying them, spamming them out to thousands of people and eroding trust in the original domain. The new DKIM2 specification would force each hop the email takes along its path to sign it, so any issues will be the fault of the previous hop. DKIM2 aims to simplify the protocol and make it more standardized. For example, in practice, the vast majority of DKIM is singed using relaxed methods, so DKIM2 will only support relaxed. The fact that DKIM relies on an explicit list of headers as part of the signature, there is inconsistent signing of headers and some security-critical headers might not be signed. In order to prevent attackers from adding headers that weren't originally part of the email, providers would sign headers with no information in them. DKIM2 would specify a fixed set of headers in alignment with best practices, so there won't be a need to specify headers. ### DMARCbis [DMARCbis](https://datatracker.ietf.org/doc/draft-ietf-dmarc-dmarcbis/) is a proposed updated version of DMARC. The `pct` tag is going away, which was a tag that would only allow a specified percentage of emails, say 50%, to be sent if they failed. Apparently, this wasn't implemented properly so now it's being replaced with the `t` mode that is a binary pass or fail. The new `np` tag adds the ability to define what to do with a non-existent subdomain of a real domain. This will prevent cybercriminals from subverting DMARC by using a fake subdomain. They are also adding [requirements](https://datatracker.ietf.org/doc/html/draft-ietf-dmarc-dmarcbis-41#name-conformance-requirements-fo) that mail providers must meet to fully conform to the specification, which should eliminate questions about best practices and how DMARC should be implemented. ### Deprecation of Cleartext Email Since there are now protocols in place to at least allow for transport encryption at every stage of the email process, providers should work on [removing support](https://datatracker.ietf.org/doc/html/rfc8314#section-4.1) for unencrypted email entirely. Transport encryption between servers now should be the minimum expected for email services going into the future. ### Passkeys The adoption of [passkeys](https://fidoalliance.org/passkeys/) will eliminate the need for email as a recovery method, since users won't have to remember passwords. Email can be used for what it was originally intended for: a method of communication and sending updates and announcements, nothing more. This will take a concerted effort from service providers though, and it seems for now most services that support passkeys still require and email for some reason. Here's hoping this changes in the future. The adoption of passkeys will also make email services themselves more secure, since at the moment they act as a sort of de facto recovery method for all of our accounts. They should focus on deprecating passwords for improved security. ### Wider Adoption of DNSSEC DNSSEC should be universally adopted to prevent DNS poisoning attacks. This would drastically improve the security of email. ### Guidance for E2EE The usability of E2EE in email is significantly lacking compared to other methods of communication, especially modern messengers like Signal that make the E2EE very seamless and simple. The handling of E2EE by email clients can also vary a lot and leave email users [vulnerable to bypasses](https://efail.de) for the E2EE. An [RFC](https://www.ietf.org/archive/id/draft-ietf-lamps-e2e-mail-guidance-17.html) to address usability issues and best practices for email clients exists, hopefully it can lead to a future of improved user experience and security in email. ### SMTP End-to-End Encryption The biggest obstacle in the way of email privacy is it's not E2EE by default like most modern messengers we use daily. Some providers like Proton Mail will automatically encrypt emails between [Proton Mail](https://proton.me/support/manage-encryption#:~:text=Proton%20Mail%20encrypts%20all%20emails%20sent%20between%20Proton%20accounts%20with%20end%2Dto%2Dend%20encryption%20%28E2EE%29) users. The obvious next step is to build E2EE into SMTP itself. An [RFC proposal](https://dcrubro.com/files/smtp-ee2esign-latest.txt) exists for just such an idea. I'm hopeful something like this can be standardized and widely adopted, and finally bring email into the 21st century. ### OpenAI Announces Plans for "Client-Side Encryption" for ChatGPT URL: https://www.privacyguides.org/news/2025/11/15/openai-announces-plans-for-client-side-encryption-for-chatgpt/ Last updated: 2025-11-15T22:14:37.000Z Coming hot off the heels of their [lawsuit with the New York Times](https://openai.com/index/response-to-nyt-data-demands/), OpenAI has announced plans to [improve the privacy of its users](https://openai.com/index/fighting-nyt-user-privacy-invasion/): > Our long-term roadmap includes advanced security features designed to keep your data private, including client-side encryption for your messages with ChatGPT. We believe these features will help keep your private conversations private and inaccessible to anyone else, even OpenAI. We will build fully automated systems to detect safety issues in our products. Only serious misuse and critical risks—such as threats to someone’s life, plans to harm others, or cybersecurity threats—may ever be escalated to a small, highly vetted team of human reviewers. These security features are in active development and we will share more details about them, and other short-term mitigations, in the very near future. It's unclear if they mean the messages will be encrypted in such a way that they're never processed on their servers in plaintext or if they just mean users' message history will be encrypted after processing. Google recently launched their [Private AI Compute](https://blog.google/technology/ai/google-private-ai-compute/) which uses their Titanium Intelligence Enclaves to keep user data isolated and inaccessible while it's being processed, even from Google themselves. Apple launched a similar feature with their [Private Cloud Compute](https://security.apple.com/blog/private-cloud-compute/) back in 2024. Proton's Lumo doesn't use Secure Enclaves to protect data while it's processed, but they do use [zero-access encryption](https://proton.me/blog/lumo-security-model) to protect your conversation history. It'll be interesting to see what OpenAI is cooking up, hopefully it can prevent another situation like what we saw with the New York Times lawsuit. ### Proton May Start Recycling Abandoned Email Addresses URL: https://www.privacyguides.org/news/2025/11/15/proton-may-start-recycling-abandoned-email-addresses/ Last updated: 2025-11-15T21:26:28.000Z In a [post](https://www.reddit.com/r/ProtonMail/comments/1ovc6k4/reducing%5Fusername%5Fexhaustion/) to the r/ProtonMail Subreddit, Proton quietly announced they are considering a change to their longstanding policy of not recycling mailbox addresses. No decision has yet been made on whether these emails will actually be released to new registrations. According to Proton they are simply gathering community feedback about the potential change. Proton says that many usernames which are locked away are due to the lack of anti-abuse technology they had in their early days, and most of them have never actually been used by legitimate users. However, recycling email addresses has always been a controversial and discouraged idea in the privacy and cybersecurity space. Old email accounts may still receive messages long after the mailbox has been deleted, and these accounts may appear in past data breaches and other data sets that malicious users could use to try and hijack older accounts if they are once again made available to the public. Proton themselves notes this is a concern in the announcement: > Note, some usernames, in particular high value ones with common names (e.g. [firstname@proton.me](mailto:firstname@proton.me)) have been disabled for close to a decade, but actually get email traffic as over the years, people randomly enter them into email forms across the internet (they even end up in breach datasets as a result). If you go to claim one of these common emails, keep this in mind. Members of the *Privacy Guides* community were largely unconvinced that this change would be positive: [Proton on Reddit: Reducing username exhaustionHello! I’m a long time lurker and wanted to see your opinions on Proton possibly recycling/releasing some usernames, but I saw it wasn’t posted here yet, so here we are: Hey everyone, As Proton continues to grow to hundreds of millions of users, occurrences of people not getting their preferred username is increasing. At the same time, we have on our system millions of user accounts which were improperly registered. In the very early days of Proton, before we had anti-abuse systems in place,…![](https://www.privacyguides.org/content/images/icon/50d23e21c43962bb12c02820fa3f19ac61dac917_2_180x180-30.png)Privacy Guides CommunitySimon![](https://www.privacyguides.org/content/images/thumbnail/4efb2e0b56f7c45bc4589cf8f63291cc82a788e8-10.webp)](https://discuss.privacyguides.net/t/proton-on-reddit-reducing-username-exhaustion/32807) ### Android 17 will include a native 'Contact Scopes' feature URL: https://www.privacyguides.org/news/2025/11/15/android-17-will-include-a-native-contact-scopes-feature/ Last updated: 2025-11-15T19:47:02.000Z According to [Android Authority](https://www.androidauthority.com/android-17-contacts-picker-rumor-3615741/), Android 17 will include a new permission that allows app developers to request access to specific contacts. Currently, Android takes an all or nothing approach to contacts access, requiring you to give apps full access to all of your contacts even when it's unnecessary. A new system Contacts Picker tool would instead allow you to pick only specific contacts in your address book to share with a requesting app. [GrapheneOS](https://www.privacyguides.org/en/android/distributions/#grapheneos) has had this functionality for some time now, calling it "Contact Scopes." Their approach seems to be more comprehensive than this new functionality, because it works with all existing apps. Unfortunately, according to Android Authority, Google's new feature will require apps to switch to using a new API to request contact info: > However, this new approach has one major hurdle: it’s optional. Nothing will stop developers from continuing to request broad access to your contacts anyway. For this feature to make a real difference, apps must be updated to use the new Contacts Picker. While some privacy-conscious developers will adopt it quickly, many will not. GrapheneOS also [allows](https://grapheneos.org/usage#contact-scopes) for much more selective access to information within a single contact itself. For example, you can choose to only share a single number or email from a contact. This new Android feature brings the platform up to speed with iOS in this regard. Apple released a new contact picker last year in iOS 18 that allows you to only share certain contacts with apps. ### Apple Launches 'Digital ID' Feature Nationwide in the United States URL: https://www.privacyguides.org/news/2025/11/15/apple-launches-digital-id-feature-nationwide-in-the-united-states/ Last updated: 2025-11-15T19:04:26.000Z This week, Apple [released](https://www.apple.com/newsroom/2025/11/apple-introduces-digital-id-a-new-way-to-create-and-present-an-id-in-apple-wallet/) a new Digital ID feature for United States passport-holders. To add a Digital ID to Apple Wallet, users will scan the passport photo page, then use their iPhone to read the RFID chip at the back of their passport book. Then Apple makes you take a live selfie with recorded head movements to verify your identity against the passport. This feature will initially be available at certain TSA checkpoints for domestic air travel: > Digital ID acceptance will roll out first in beta at TSA checkpoints at more than 250 airports in the U.S. for in-person identity verification during domestic travel, with additional Digital ID acceptance use cases to come in the future. However, in-app guidance already states that this Digital ID will be available for [age verification](https://www.jonaharagon.com/posts/age-verification-is-incompatible-with-the-internet/) and [identity verification](https://www.privacyguides.org/articles/2025/10/15/real-name-policies/) "in apps, online, and in stores." Apple Wallet's Digital ID functionality has already been available in 12 U.S. states and Puerto Rico through their digital driver's licenses. This new option is meant for anyone in the U.S. who doesn't live in a state with digital driver's licenses or don't have a REAL ID. It's important to note that this is a "Digital ID" and not a "Digital Passport." While a passport is used as the source of truth for identity verification, this does not replace your physical passport and cannot be used for digital travel. ## Digital IDs & Censorship The proliferation of Digital IDs is a key part of enforcing government [censorship](https://www.privacyguides.org/en/basics/common-threats/#avoiding-censorship) through "age verification" and similar legal mandates. While Apple's solution is far better than most existing solutions which require uploading photos of your ID to random third-party service providers, this technology will still be used to gate access to harmless information on the internet. When it becomes mandated to scan your digital ID to access resources that are purely knowledge, like *Wikipedia*, as opposed to purchasing age-restricted products like alcohol, this creates a power imbalance where governments can block people from accessing wide swaths of the internet by denying the issuance of passports or Digital IDs to certain groups of people. > When talking about age verification, most assume this only applies to obvious pornographic content. However, many of these laws have [much wider reach](https://www.eff.org/deeplinks/2025/01/impact-age-verification-measures-goes-beyond-porn-sites). > > For example, the Australian law prohibits access to social media altogether for anyone under the age of 16\. This means that, once the law comes into full effect after its transitional period, anyone who uses social media in Australia will have to prove they are older than this age. It is likely that all Australian users will have to provide some form of identifying data to continue using their social media accounts. **This is a privacy nightmare.** > > When laws target specific content, definition of what is appropriate and what isn't is often too broad. Moreover, this definition is subject to change from one administration to another. > > There are also wide differences from one country to another. For example, some countries sadly consider simple discussions of gender identity or sexual orientation to be sensitive content. What is deemed inappropriate to children in one culture might not be the same in another. [Age Verification Wants Your Face, and Your PrivacyAge verification laws forcing platforms to restrict access to content online have been multiplying in recent years. The problem is, implementing such measure necessarily requires identifying each user accessing this content, one way or another. This is bad news for your privacy.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-12.png)Privacy GuidesEm![](https://www.privacyguides.org/content/images/thumbnail/age-verification-wants-your-face.png)](https://www.privacyguides.org/articles/2025/05/06/age-verification-wants-your-face/#where-age-verification-is-or-will-be-required) > As \[the EFF has\] said repeatedly, there’s no such thing as “safe” age verification. Every approach—whether it’s facial or [biometric scans](https://www.eff.org/deeplinks/2025/01/face-scans-estimate-our-age-creepy-af-and-harmful), government ID uploads, or behavioral or account analysis—creates new privacy, security, and expressive harms. [A Surveillance Mandate Disguised As Child Safety: Why the GUARD Act Won’t Keep Us SafeA new bill sponsored by Sen. Hawley (D-MO), Sen. Blumenthal (D-CT), Sen. Britt (R-AL), Sen. Warner (D-VA), and Sen. Murphy (D-CT) would require AI chatbots to verify all users’ ages, prohibit minors from using AI tools, and implement steep criminal penalties for chatbots that promote or solicit certain harms. That might sound reasonable at first, but behind those talking points lies a sprawling surveillance and censorship regime that would reshape how people of all ages use the internet.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-precomposed-114x114.png)Electronic Frontier FoundationMolly Buckley![](https://www.privacyguides.org/content/images/thumbnail/mobile-privacy-knight-2_0.png)](https://www.eff.org/deeplinks/2025/11/surveillance-mandate-disguised-child-safety-why-guard-act-wont-keep-us-safe) ### Mullvad Set to Retire 'Leta' Search Proxy on Nov. 27, 2025 URL: https://www.privacyguides.org/news/2025/11/15/mullvad-set-to-retire-leta-search-proxy-on-nov-27-2025/ Last updated: 2025-11-15T19:04:37.000Z The **Mullvad Leta** [search engine](https://www.privacyguides.org/en/search-engines/) will be retired at the end of this month, according to an [announcement](https://mullvad.net/en/blog/shutting-down-our-search-proxy-leta) from [Mullvad](https://www.privacyguides.org/en/vpn/#mullvad) last week. Their announcement cites changes in the search industry that they feel Leta would not be able to keep up with, stating that their search proxy "will likely become less useful over time." Leta was useful as a proxy to major search engines like Google and Brave. Queries to those search engine providers would be pooled from Mullvad, to reduce the chances of a search engine being able to tie a query to a particular user. Mullvad says that similar privacy can be achieved by accessing those search engines directly through the use of a [private web browser](https://www.privacyguides.org/en/desktop-browsers/) and a VPN. This change makes sense as Mullvad appears to be refocusing on improving their core VPN product. They recently [announced](https://discuss.privacyguides.net/t/introducing-lightweight-wireguard-obfuscation-mullvad-vpn/32753) "Lightweight WireGuard Obfuscation" to help more users bypass firewalls and censorship, in addition to QUIC obfuscation [added in September](https://discuss.privacyguides.net/t/mullvad-release-2025-9-with-quic-obfuscation/30884), as well as their [announcement](https://discuss.privacyguides.net/t/mullvad-is-removing-openvpn-support-by-january-15-2026/22241) that they are deprecating OpenVPN at the beginning of 2026. Mullvad Leta users seeking an alternative could consider following Mullvad's advice and using Google alongside Mullvad Browser and their VPN, or switching to an alternative recommended by *Privacy Guides*: [Recommended Search Engines: Anonymous Alternatives to Google - Privacy GuidesUse privacy-respecting search engines which don’t build an advertising profile based on your searches.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-11.png)Privacy Guides![](https://www.privacyguides.org/content/images/thumbnail/search-engines.png)](https://www.privacyguides.org/en/search-engines/) ### Firefox 145 Boosts Privacy Amid AI Controversy, Android 16 QPR1 Source Code Released, Mullvad Shuts Down Leta Search Engine, and More URL: https://www.privacyguides.org/livestreams/2025/11/14/firefox-145-boosts-privacy-amid-ai-controversy-android-16-qpr1-source-code-released-mullvad-shuts-down-leta-search-engine-and-more/ Last updated: 2025-11-15T17:29:22.000Z This Week in Privacy #27 _This post is for subscribers only._ ### EU Officials Location Data Is Up For Sale, Tinder Is Scanning Your Camera Roll With AI, Chrome Can Now Autofill ID Docs, and more URL: https://www.privacyguides.org/livestreams/2025/11/07/eu-officials-location-data-is-up-for-sale-tinder-is-scanning-your-camera-roll-with-ai-chrome-can-now-autofill-id-docs-and-more/ Last updated: 2025-11-10T15:34:07.000Z This Week in Privacy #26 _This post is for subscribers only._ ### NOYB files criminal complaint against Clearview, Police AI leads to false accusation, Apple plans ads for Maps, and more URL: https://www.privacyguides.org/livestreams/2025/10/31/noyb-files-criminal-complaint-against-clearview-police-ai-leads-to-false-accusation-apple-plans-ads-for-maps-and-more/ Last updated: 2025-11-01T17:10:57.000Z This Week in Privacy #25 _This post is for subscribers only._ ### Data Brokers Know Everything About You (Interview with Yael Grauer) URL: https://www.privacyguides.org/videos/2025/10/28/data-brokers-know-everything-about-you/ Last updated: 2025-10-28T15:00:56.000Z Data brokerage is a billion-dollar industry built on selling your personal information without your knowledge or consent. In this video, we uncover the shady world of data brokers with investigative reporter Yael Grauer (Consumer Reports) to find out how they operate and what you can do about it. [Data Removal Services - Privacy GuidesOur recommended methods for removing your personal information from data brokers and people search sites.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-8.png)Privacy Guides![](https://www.privacyguides.org/content/images/thumbnail/data-broker-removals.png)](https://www.privacyguides.org/en/data-broker-removals/) [EasyOptOuts Review & Real-World TestPeople-search sites represent an immense privacy risk to the majority of Americans. EasyOptOuts is a low-cost online service which automates opt-out requests on your behalf.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-9.png)Privacy GuidesJonah Aragon![](https://www.privacyguides.org/content/images/thumbnail/easyoptouts-review.png)](https://www.privacyguides.org/articles/2025/02/03/easyoptouts-review/) [GitHub - yaelwrites/Big-Ass-Data-Broker-Opt-Out-ListContribute to yaelwrites/Big-Ass-Data-Broker-Opt-Out-List development by creating an account on GitHub.![](https://www.privacyguides.org/content/images/icon/pinned-octocat-093da3e6fa40-2.svg)GitHubyaelwrites![](https://www.privacyguides.org/content/images/thumbnail/Big-Ass-Data-Broker-Opt-Out-List)](https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List) [Filling In the Gaps For People Search Site Removal Services![](https://www.privacyguides.org/content/images/icon/spreadsheets_2023q4.ico)Google Docs![](https://www.privacyguides.org/content/images/thumbnail/AHkbwyKJJj8uf0Xv_GTgi4Oy-zxyv0x9R-79Jnvc3dMREZus8e_MD0xKLpuQzsjJuBegmINjfESxI0BP6xesK0Z9d_bzByR-tP9jzHZ5swcWSW4vyd87v9YX-w1200-h630-p)](https://docs.google.com/spreadsheets/d/115L6LpQg%5FUX638IyUfdwGhRS7dIU3lKwz6fjAcDtE-0) #### Sources 0:54 4:00 4:12 4:57 5:01 5:34 6:29 6:34 6:44 7:09 7:14 7:27 7:36 8:21 9:50 10:02 10:15 10:28 11:22 11:37 12:59 13:06 13:11 13:53 14:41 ### OpenAI launches creepy AI browser, AWS shutters Signal and Smart Mattresses, U.S. states introduce VPN ban bills, and more URL: https://www.privacyguides.org/livestreams/2025/10/25/openai-launches-creepy-ai-browser-aws-shutters-signal-and-smart-mattresses-u-s-states-introduce-vpn-ban-bills-and-more/ Last updated: 2025-10-26T15:54:13.000Z This Week in Privacy #24 _This post is for subscribers only._ ### Official GrapheneOS Phone, Framework Secure Boot Flaw, & Perplexity AI in Firefox URL: https://www.privacyguides.org/livestreams/2025/10/18/official-grapheneos-phone-framework-secure-boot-flaw-perplexity-ai-in-firefox/ Last updated: 2025-10-18T00:09:48.000Z This Week in Privacy #23 _This post is for subscribers only._ ### Real-Name Policies: The War Against Pseudonymity URL: https://www.privacyguides.org/posts/2025/10/15/real-name-policies/ Last updated: 2025-10-15T03:51:43.000Z Real-name policies have existed for well over a decade already, and the problems they cause aren't new. But these problems have become exponentially harmful in today's world, where real-name policies are coupled with monopolistic platforms, increased mass surveillance, AI technologies, and facial recognition capabilities. It's time to fight back against this unsafe and discriminatory privacy-invasive practice. Pseudonymity, or the use of a nickname or fictitious name online, has always been deeply valued on the internet. It grants people protections and freedoms that are often impossible to benefit from offline. Women, and especially women who are part of male-dominated online communities, have regularly used pseudonyms to hide their gender online in order to protect themselves from sexual harassment, stalking, and physical violence even. Transgender and gender-diverse people also regularly use pseudonyms for protection, or use new chosen names to explore their gender identity online. Victims of domestic violence, victims of stalkers, activists, and even journalists often use pseudonyms to protect themselves from aggressors or oppressive regimes. **Pseudonymity saves lives.** And yet, it is constantly under attack. ## What are real-name policies exactly? So called "real-name" policies are platform policies requiring users and subscribers to sign up and display their "real name," often equated to a *legal* name. Facebook for example claims not to require a legal name, but only the "real" name a person uses in their daily life. Yet, the social media giant regularly demands official IDs to verify this "real" name, effectively requiring people associate their account with their *legal* identity. Facebook has even repeatedly taken the liberty to decide which name was "real", and changed the displayed name of users based on verification processes **without any prior consent from users**. For people in vulnerable situations, this can be a *very* dangerous practice. Facebook is perhaps the most infamous platform implementing such discriminatory and intrusive policy, but sadly, it's not the only one. Increasingly more platforms demand that users provide their legal name and official identifications in order to keep using a platform. And this will likely be aggravated significantly by the recent trend for [age-verification](https://www.privacyguides.org/videos/2025/08/15/age-verification-is-a-privacy-nightmare/) policies. ### Explicit and implicit policies There is always two levels of real-name policies: The name displayed publicly to everyone (explicitly required), and the name the platform has associated with the account in its database (implicitly associated). While a requirement to expose one's legal name publicly has clear privacy risks, storing legal names without displaying it to other users is also problematic. For explicit requirements, users who are obligated to display their legal name publicly are not only forced to create a permanent association of this account with their legal identity (with all the problems this can bring), but are also potentially exposing their identity and account to current or future attackers. For example, this can and does enable stalkers to find their victims online (and offline) to cause them harm. For implicit associations, as soon as a legal name is collected and associated with an account in the backend, whether from providing official documentation for age verification, account recovery, payment, or any other processes; this data is at risk of getting leaked or breached, and eventually shared publicly as well. Once this data is [exposed](https://discuss.privacyguides.net/t/discord-data-breach-customers-personal-data-and-scanned-photo-ids-leaked/31904), this account now also becomes permanently associated with a legal identity, publicly. Even without having an openly stated real-name policy, platforms collecting official documentation—or otherwise storing legal names associated with accounts—can effectively end up exposing their users to similar risks. ### What is a real name anyway? Of course, your true *real* name is whatever you decide others should call you. Only *you* can decide this, and others should be respectful of your choice. Your *legal* name, however, is a **data marker attached to your person that can be used to trace many of your activities online and offline**, with a high degree of precision going as far back as when you were born. For everyone, but especially for vulnerable communities, exposing legal names on certain platforms can represent a significant risk. The [use of pseudonymity](https://www.techradar.com/pro/vpn/using-your-real-name-on-social-media-heres-why-you-should-think-twice) is a critical part of online safety, and people should be able to continue using this protective measure without raising suspicion. ## Who is impacted the most by real-name policies? Everyone is impacted by real-name policies, but groups that are at higher risk of discrimination, violence, and online harassment are disproportionally harmed by them. Moreover, anyone who for various reasons uses a name that doesn't match their official ID; has a legal name that doesn't match an expected American name pattern; needs to conceal their gender online for safety; or has to protect their identity online due to their work as an activist, journalist, dissident, or whistleblower can be severely impacted, silenced, and even endangered by requirements to provide a legal name online. ### Victims of domestic violence For many people, using pseudonyms isn't just a good privacy practice, but it can be a matter of life and death. For anyone who is experiencing or has experienced domestic violence, creating a new online identity hidden from the perpetrator can be essential for survival, to prepare a safe escape, or to keep having access to essential support and resources. When people are forced to only use one identity online, an identity attached to their legal identity, this empowers aggressors to find their victims, to silence them, to control them, and to harm them. **Technologies and policies are never neutral.** When policies and features make it difficult or impossible for vulnerable people to use these technologies safely, they are effectively excluding vulnerable people from the platforms. Even if this might seem minor from the outside, when Big Tech becomes so monopolistic that it's almost impossible to fully avoid it in our daily lives, when someone cannot access social groups and support without a Facebook account, and can't find a new job without LinkedIn, then it's not just a minor problem anymore, it's a major problem. **Platforms and online services should be safely accessible to everyone.** And this includes allowing the use of protective pseudonymity without requiring legal identification that could put the most vulnerable in life-threatening situations. ### Victims of stalking Similarly to victims of domestic violence, victims of stalking must protect their identity online to stay safe from their stalkers. When platforms obligate people to use their legal names, explicitly or implicitly, they directly endanger these victims. If a stalker or an aggressor knows a victim's legal name (which is often the case), then it's trivial to find their account on any platforms and services, regardless of if they have blocked them on one. A good protection to prevent severe harassment is to create alternative accounts using a different name or different pseudonym unknown to the aggressor. This can give victims the peace of mind of knowing their stalker will not be able to find them there. For anyone tempted to argue real-name policies reduce the number of perpetrators, this isn't the case. Stalkers and predators of all kind feel generally quite comfortable using their own legal names, this isn't a problem for them. They feel confident knowing that victims generally have little recourses and support, and that there will be no consequences for them even when their legal name is known. Despite the claims, removing pseudonymity doesn't remove misbehavior online, this has been demonstrated [again](https://theconversation.com/online-abuse-banning-anonymous-social-media-accounts-is-not-the-answer-170224), and [again](https://theconversation.com/online-anonymity-study-found-stable-pseudonyms-created-a-more-civil-environment-than-real-user-names-171374), and [again](https://allabouteve.co.in/harassment-of-women-on-linkedin/). Real-name policies don't reduce crime, it only restricts the victims' ability to protect themselves from such crime. ### Activists and political dissidents For activists and political dissidents around the world, using pseudonymity online can be a way to reclaim freedom of speech and criticize power in a safer way. Under oppressive regimes, online privacy can mean life or death. This is another example showing how essential privacy rights are to democracy. **Real-name policies facilitate censorship, discrimination, and political repression.** A Honduran blogger using the pseudonym [La Gringa](https://lagringasblogicito.blogspot.com/2011/10/my-ripples-will-continue.html) used her blog and Facebook page to criticize the Central American government for years. Protecting her legal identity is essential to allow her to speak freely and stay safe from state repression. This isn't an exaggeration, Honduras is one of the most dangerous country for journalists. The Committee to Protect Journalists (CPJ) [recorded](https://latamjournalismreview.org/articles/almost-five-years-after-murder-of-honduran-journalist-gabriel-hernandez-authorities-still-waiting-for-results-of-their-investigations/) that 37 press workers were killed in the country between 1992 and 2023\. Of these murders, 90% were unpunished. But Facebook silenced La Gringa with its real-name policy, requiring her to provide a copy of her official ID to continue advocating on the platform. Evidently, this request is asking her to put her life in danger and cannot be compromised on. Facebook's policy is essentially silencing any dissident and marginalized voices in oppressive regimes. By letting the community report infractions to Facebook's real-name policy, this effectively allows Facebook's rules to be weaponized against marginalized groups already plagued with constant discrimination. It also empowers abusers to silence their victims, and sides with oppressive regimes around the world to censor any critics they might have. As reporter Kevin Morris [commented](https://www.dailydot.com/news/la-gringa-facebook-ban-real-id-dangerous-honduras/) in his Daily Dot piece on the topic: "Pseudonyms are hardly modern phenomena, and it's fair to say democracy wouldn't exist without it." ### Women Women have long used pseudonyms on the internet in order to conceal their gender online, and spare themselves from the sexual harassment and discrimination omnipresent on some platforms. This is even more common in male-dominated communities like online gaming, for example. It's not rare to hear some people claiming that "there aren't any women in their online community." Well, there probably is. Platforms allowing pseudonyms foster a culture of inclusivity where everyone can participate free from discrimination, regardless of their gender. Real-name policies encourage the opposite: platforms where participants are forced to either endure the abuse and compromise their physical safety, or be excluded entirely. As pseudonymous author *skud* [wrote](https://geekfeminismdotorg.wordpress.com/2010/06/10/hacker-news-and-pseudonymity/) for the *Geek Feminism* blog in 2010: > \[...\] women online are regularly admonished to use pseudonyms to protect themselves. Many websites with a culture of pseudonymity \[...\] have a very high proportion of female members, perhaps in part because of the sense of privacy and security that pseudonymity brings. A site which requires real/verified names is automatically flagging itself as a potentially/probably unsafe space for women, or for anyone else at risk of harassment, violence, job discrimination, and the like. Women aren't exactly a minority group. While platforms should be inclusive to everyone of course, including minority groups, enforcing a policy that obligates roughly 50% of the population to lower its safety protections in order to participate should be obviously unacceptable. ### Indigenous people Notwithstanding its own policy, Facebook has regularly suspended accounts with legal names wrongly targeted as fake, based on criteria rooted in colonialism. Indigenous communities have been exceedingly impacted by Facebook's real-name policy, despite following all the platform's rules as requested. In 2009, Facebook abruptly [cut off account access](https://ictnews.org/archive/facebook-no-friend-to-american-indian-names/) to an Indigenous American woman named Robin Kills The Enemy, wrongly accusing her of registering under a false name. But her name was authentic, and indeed her *legal* name. Facebook eventually reinstated her account, but only after a long process where she had to modify the spelling. The burden shouldn't be on Indigenous people to have to prove their identity just because a US-based corporation can't seem to understand the global diversity of naming conventions. Following Kills The Enemy's experience, a journalist started a Facebook group called "Facebook: don't discriminate against Native surnames!!!" that was joined by over a thousand people only a few days after its creation. Many users shared similar experiences and questioned the platform's treatment of Indigenous surnames. Another woman named Melissa Holds The Enemy described a month-long process to recover her account. An Indigenous man named Oglala Lakota Lance Brown Eyes had his account [suspended](https://colorlines.com/article/native-americans-say-facebook-accusing-them-using-fake-names/) by Facebook demanding his "real" name. After Brown Eyes sent all the required proofs, Facebook decided without warning to Americanize his displayed name to "Lance Brown." **This is blatant racism.** His name was eventually corrected and Facebook apologized, but only after Brown Eyes threatened the company with a class action lawsuit. Dana Lone Hill also got her account suspended because of her Indigenous surname, and was forced to go through Facebook's intrusive verification process in order to recover her account. The list goes on and on. Indigenous people have been forced by Facebook to modify and Americanize their *actual legal names*. Many were forced to add hyphens, change the alphabet used, smash words together, or even remove parts of their legal name in order to please Facebook's arbitrary preferences, ignoring its own "real-name" policy. This is yet another demonstration of systemic racism perpetrated by a monopolistic corporation quick to ignore the human rights and diversity of its users. ### People with non-Anglophone names In another case, a woman from Japan named Hiroko Yoda [wasn't able to sign up](https://www.telegraph.co.uk/news/newstopics/howaboutthat/2632170/Woman-called-Yoda-blocked-from-Facebook.html) for a Facebook account due to her surname. Despite being a common surname in Japan, it seems Facebook judged it more important to ban anyone trying to "impersonate" the popular Star Wars character. Of course, the Star Wars character uses a Japanese name because its creator has drawn [inspiration](https://en.wikipedia.org/wiki/Yoda#Creation) from the Japanese culture. But Facebook still seems to somehow think that Star Wars comes first, and Japanese people must pay the price for daring to share a surname with the American Jedi. A Facebook user from Hawaii named Chase Nahooikaikakeolamauloaokalani Silva also had his account suspended despite using his legal name. As a proud Hawaiian, it was important for him to be able to display his Hawaiian given name. But Facebook just didn't like his *legal* name. Silva reported to [HuffPost](https://www.huffpost.com/entry/facebook-chase-nahooikaikakeolamauloaokalani-silva%5Fn%5F5833248) that "Facebook should not be able to dictate what your name is, what you go by, what you answer to," and he's right. More broadly, Facebook's policy [prohibits](https://en.wikipedia.org/wiki/Facebook%5Freal-name%5Fpolicy%5Fcontroversy) name with "too many" words, capital letters, or first names with initials. This assumes the default for names is the Americanized format of one first name, one (short) middle name, and one last name. But this isn't a reality for most of the world. This extremely narrow vision of what a name should look like and how it should be formatted isn't compatible with many if not most cultures. It's unbelievable (and unacceptable) that a platform with an estimated 2.28 billion active users, who seems to want to eat even more of the world every year, is being so ignorant of non-American cultures and global naming conventions in its policies and practices. ### The transgender community For transgender and gender-diverse individuals, their legal name may be a "[dead name](https://en.wikipedia.org/wiki/Deadnaming)." A dead name is a name that they were assigned at birth but no longer identify with. Commonly, transgender people change their name as part of their gender transition. In many countries around the world, there can be many bureaucratic hurdles required to change one's name, meaning that many trans people are unable to update their legal name to reflect their gender identity. Because they no longer identify with their dead name, keeping it private is of great importance for their mental health and safety. Referring to a trans person with their dead name is considered offensive and often involves misgendering someone too. For transgender people, being called a name that they no longer identify with invokes feelings of depression, anxiety, gender dysphoria, and lack of acceptance. Using someone's dead name signals that you don't respect their identity and that you don't care about them enough to use their new name. Unfortunately, transgender people still face widespread discrimination, that's why "dead naming" can be incredibly dangerous. Revealing someone's gender identity or sexuality without their consent is called "outing". By calling someone by their dead name, you may be inadvertently revealing someone is transgender. This can be not only traumatizing and frightening for the individual, but can also lead to violence or put this person in a dangerous situation. The Trevor Project, a non-profit LGBTQ+ organization, conducts a yearly [survey](https://www.thetrevorproject.org/survey-2024/?%5Fhsmi=305272848) on LGBTQ+ youth across the United States. In their 2024 release, they found that "23% of LGBTQ+ young people reported that they have been physically threatened or harmed in the past year due to either their sexual orientation or gender identity." This is why when real-name policies come in, requiring transgender people to use their legal name for their social media accounts, this could force them to "come out" by displaying a name that they no longer identify with, therefore revealing they are transgender. The National LGBTQ Institute on Intimate Partner Violence [describes](https://lgbtqipvinstitute.org/coming-out-safely/) "coming out" as an "ongoing process, by which a person shares aspects of their identity with others." Having aspects of their identity shared without their consent can put this person in significant physical danger because of unsupportive family members, friends, colleagues, and strangers. This is especially the case with LGBTQ+ youth, who are at heightened risk of online, verbal, physical harassment, or violence due to their identity. Coming out can be a very daunting and scary process, particularly for transgender and gender-diverse people, and often can be an ongoing process over many years. In many cases, LGBTQ+ people choose instead to [hide their identity](https://www.stonewall.org.uk/news/new-research-shows-almost-40-of-lgbtq-employees-still-hide-their-identity-at-work) at social and work gatherings. Platforms that enforce real-name policies take away the essential ability to control when and how that process plays out are nothing short of abusive. This might sound hyperbolic, however, "outing" is often used as a mean of control in abusive relationships to coerce an LGBTQ+ individual. The fact that social media platforms are exhibiting similar behavior is alarming. Unfortunately, many websites don't allow updating the name attached to an account easily, often requiring to provide legal documentation showing proof that the name has been legally changed. Having to provide your identification documents to use a website is not only terrible for your privacy, as it links your real life identity to your online account, it also puts your identity at risk. Companies that process and verify identity documents are at a much higher risk of being targeted by malicious actors, because of the sensitive information they store and process. One of the worst offenders of this is Facebook. They require everyone that signs up to use their legal name for their profile, and claim that this is to ensure safety on the platform so that everyone knows who they are talking to is who they say they are. Many transgender and gender-diverse people use aliases on social media platforms to protect their identities and the identities of those around them, because they are more likely to be harassed or doxxed. Facebook's real-name policy has unforeseen consequences for these people, as one transgender Facebook user [found out](https://www.dailydot.com/news/facebook-real-names-cracking-down-transgender/): > I woke up to find my Facebook account deleted. \[...\] I have had a Facebook since about 2007 or 2008\. Other than when I was a kid and was afraid my parents would find out about my account (causing me to use an alias for a little while), my profile always bore my legal name. A week or so ago, however, I changed my display name to "Arc Angel." Finally, because of the discrimination and danger that transgender people face in the real world, they often find refuge in online and internet communities. According to a report by [Hopelab](https://assets.hopelab.org/wp-content/uploads/2025/03/2025-Without-It-I-Wouldnt-Be-Here.pdf) of LGBTQ+ youth: > Transgender young people more often agree that their online communities and friendships were important or very important (84%) when they began to explore their sexuality or gender compared to cisgender LGBQ+ young people (71%). This is why it’s so important that they are able to freely express themselves with a pseudonymous or anonymous identity. If every online platform required these users to use their legal name, this would be extremely dangerous for transgender and gender-diverse people who often rely on online spaces for community, friendship, and support. ### LGBTQ+ people Moreover, real-name policies disproportionately affect LGBTQ+ people, as they often prefer to not associate their legal name with their online activities. This is especially important for people living in countries where LGBTQ+ identities are [criminalized by law](https://en.wikipedia.org/wiki/Criminalization%5Fof%5Fhomosexuality), meaning they can be jailed (or worse) if they associate their online activities with their real life identity. Unfortunately, it gets even worse: harassers and trolls have weaponized Facebook's real-name policy, and are using it to silence their victims by mass reporting them as using a fake name. In an [open letter](https://www.eff.org/document/open-letter-facebook-about-its-real-names-policy) to Facebook about its real-name policy in 2015, many LGBTQ+ and digital rights organizations warned Facebook that this was being used to silence LGBTQ+ people: > Facebook users in the global LGBTQ community, South and Southeast Asia and the Middle East report that groups have deliberately organized (sometimes even coordinating via Facebook) to silence their targets using the "Report Abuse" button. Despite all the recommendations and warnings by LGBTQ+ organizations and digital rights groups more than ten years ago, Facebook is still standing strong in its intention to keep the platform a "real name" only space. Their help center still [states](https://www.facebook.com/help/229715077154790/Names+allowed+on+Facebook/) that you can only use a name that appears on your official identification documents: > The name on your profile should be the name that your friends call you in everyday life. This name should also appear on a form of ID or document from our ID list. Many platforms have been trying to improve the way they handle this and allow for users to select a preferred name that is displayed instead of their legal name. This is an improvement, however it isn't without issues. Platforms shouldn't require you to provide your legal name to begin with. ### Stage performers and small businesses In 2014, Facebook made the news for ramping up its real-name policy and suspending hundreds of accounts from marginalized and vulnerable people (more on this in the [next section](https://pr3149.unreviewed.privacyguides.dev/articles/2025/10/14/real-name-policies/#facebook)). The platform was heavily criticized, and Facebook eventually reinstated many banned accounts. At the time, drag performers were [severely impacted](https://www.cnn.com/2014/09/16/living/facebook-name-policy/) by the policy purge. Drag queen and activist Sister Roma reported having to change her Facebook profile to a legal name she had not used publicly for 27 years. Retired burlesque dancer Blissom Booblé explained that using a pen name on Facebook was essential to continue her advocacy for LGBTQ+ homeless youth and to raise HIV awareness while staying free from discrimination at her workplace. Drag queen Ruby Roo reluctantly complied with Facebook's policy in order to keep contact with his friends, but expressed concerns that people would not recognize him under his legal name. If nobody ever calls you by your legal name, does this still even count as your "real" name? During an earlier purge in 2009, small-business entrepreneur Alicia Istanbul [suddenly lost access](https://www.sfgate.com/business/article/Real-users-caught-in-Facebook-fake-name-purge-3231397.php) to both her personal Facebook account and her jewelry design business page. Once this happens, the burden falls on users to carry on the lengthy and intrusive verification process to restore their accounts. **There is no innocent until proven guilty with Big Tech.** This can represent significant losses in time and money for small businesses. Additionally, many professionals such as teachers, doctors, therapists, and social workers regularly use pseudonyms so that clients and patients will not be able to find their personal accounts. Everyone should have the right to separate their professional lives from their personal lives, and [using pseudonyms is a great practice](https://pr3149.unreviewed.privacyguides.dev/articles/2025/06/10/stay-safe-but-stay-connected/#pseudonymity) to this effect. ### Everyone else Finally, everyone can be impacted negatively by real-name policies, not only marginalized or vulnerable groups. Everyone should be able to choose the protections necessary for themselves, according to their own and unique [threat model](https://www.privacyguides.org/en/basics/threat-modeling/). If someone decides it's safer or more comfortable for them to use a platform under a pseudonymous account, they should be able to do so freely. Privacy is a basic human right, and it should be accessible to all without requiring any justification. The normalization of real-name policies online, aggravated by the growing identity and age verification industry, will have devastating consequences for everyone, and for democracies everywhere. **Real-name policies are authoritarian in nature and have a chilling effect on freedom of speech and other civil liberties.** If we value privacy as a human right, we must push back against real-name policies, especially on social media. ## Where are real-name policies? About ten years ago, pseudonymity became a heated news topic during the so-called [Nymwars](https://en.wikipedia.org/wiki/Nymwars), the wars against pseudo*nyms*. The term mostly refers to a series of conflicts related to real-name policies in the 2010s. It emerged in relation to waves of policy enforcement from Facebook, Google, and the video-game giant Blizzard. With the increasing push for age verification and "human authentication" online, the Nymwars are sadly likely to make a comeback very soon. And for some platforms, the war just never stopped. Sometimes, your legal name might be required online of course. For example, for governmental and financial services. But way too many platforms and services collect legal names when there really isn't any strong justifications for it. While Facebook was mentioned abundantly in previous examples, this problem isn't limited to Meta's social media. You've probably encountered real-name policies everywhere already, but here are some platforms (and even countries) that have been infamous for it: ### Facebook In 2014, Facebook [made the news](https://www.aclunc.org/blog/my-name-why-aclu-facebook-today) (again) for enforcing a [horrible policy](https://www.zdnet.com/article/facebook-nymwars-disproportionately-outing-lgbt-performers-users-furious/) (again) that was [hurting](https://www.eff.org/deeplinks/2014/09/facebooks-real-name-policy-can-cause-real-world-harm-lgbtq-community) marginalized and vulnerable groups the most ([again](https://www.hrc.org/news/metas-new-policies-how-they-endanger-lgbtq-communities-and-our-tips-for-staying-safe-online)). Several human rights groups, including the Electronic Frontier Foundation, Human Rights Watch, and Access Now even joined the [Nameless Coalition](https://www.accessnow.org/nameless-coalition-calls-on-facebook-to-change-its-real-name-policy/) to demand changes to Facebook's policy. Facebook presented this ramping up of their real-name policy enforcement as something important for "authenticity" online. Despite this dubitable claim, Facebook was in all likelihood simply worried about protecting its financial assets, as ever. Back in 2012, Facebook's share price plummeted after a quarterly filing with the Securities and Exchange Commission [revealed](https://www.theguardian.com/technology/2012/aug/02/facebook-share-price-slumps-20-dollars) that an estimated 8.7% of accounts on the platform may be fake, and 5% of active accounts were duplicates (numbers that aren't really that alarming, actually). But this backlash from investors evidently scared Facebook enough to justify intensifying its policy enforcement for accounts using pseudonyms, or suspected of being fake, presumably in an attempt to soothe shareholders. Despite the unpopularity of these policies, the real customer for Facebook isn't its users, but its advertisers (who demand access to your data, Facebook's true product). Advertisers want some assurance that they are paying for *real* humans to see their ads, otherwise this diminishes Facebook's value to them. **It's important to remember that Facebook is, and has always been, an advertising company.** Despicably, Facebook even [encouraged](https://thenextweb.com/news/facebook-now-wants-snitch-friends-arent-using-real-name) people to "snitch on \[their\] friends if they are not using their real name." > Please help us understand how people are using Facebook. Your response is anonymous and won't affect your friend's account. Is this your friend's real name? This kind of prompt fosters mistrust and allows users to weaponize policies against people they simply don't like. Victims of these "report attacks" are often the most vulnerable and the most marginalized in our society. **Real-name policies have nothing to do with safety, in fact, they're horrible for safety.** A decade later, Facebook still encourages and enforces its real-name policy in order to protect its most valuable asset to sell: Your personal data. ### LinkedIn LinkedIn is another well-known platform that enforces a real-name policy. The employment-oriented social media states in its [User Agreement](https://www.linkedin.com/help/linkedin/answer/a1337288/names-allowed-on-profiles) that "LinkedIn does not allow members to use pseudonyms, fake names, business names, associations, groups, email addresses, or special characters that do not reflect your real or preferred professional name." It's unclear how LinkedIn would enforce or verify what is an allowed "preferred professional name." Although this might make slightly more sense on a platform focused on employment, the policy still excludes some professionals and industries that regularly work using pseudonyms, such as performers, writers, visual artists, activists, and privacy advocates even. Additionally, the platform uses the same colonialist discrimination as Facebook, assuming that all names worldwide are composed of "first, middle, and last names" only. ### Google, Quora, and Blizzard abandoned their policies Google made the news in 2011 when it started implementing and enforcing its own real-name policy for its (now defunct) social media platform Google+, and by proxy for YouTube accounts when Google [migrated](https://www.theguardian.com/technology/2014/jul/16/youtube-trolls-google-real-name-commenter-policy) YouTube comments to a Google+ system in 2013. The policy was [largely criticized](https://www.eff.org/deeplinks/2011/07/case-pseudonyms) after a wave of account suspensions, where some famous accounts were banned. In July 2014, Google [abandoned](https://en.wikipedia.org/wiki/Nymwars#Google) the policy altogether and removed restrictions on account names. The question-answering social platform Quora also enforced a real-name policy for a long time. Verification wasn't required, but names deemed "false" could be reported by the community. Again, this kind of reporting system facilitates abuse by allowing the weaponization of platform policies against marginalized groups. Thankfully, Quora [eliminated](https://quorablog.quora.com/Allowing-everyone-to-contribute-to-Quora) the requirement to use a "real" name in 2021, and now allows users to register with protective pseudonyms. The video-game developer Blizzard Entertainment spawned strong criticism online when the company [announced](https://en.wikipedia.org/wiki/Blizzard%5FEntertainment#Privacy%5Fcontroversy%5Fand%5FReal%5FID) in 2010 that it would be implementing a real-name policy for Blizzard's forums. Gamers were not amused. The community came together to fight back in force against the announced policy. Game magazines and forums were inundated with replies and condemnations. At one point, a Blizzard employee trying to demonstrate that the policy "wasn't a big deal" willingly shared his real name on a public post. After this revelation, forum members started to post the employee's personal information, including his phone number, age, picture, home address, and even information related to his family members. Other members were quick to share their own experiences and show how [unsafe](https://web.archive.org/web/20100628055329/http://ve3d.ign.com/articles/news/55728/Is-Blizzards-Real-ID-Safe-Or-A-Playground-For-Sexual-Deviants) a real-name policy would be. Following the powerful community backlash, Blizzard decided to cancel its plan for the invasive policy. ### South Korea Terrifyingly, whole countries have enforced real-name policies online. In 2007, South Korea [implemented](https://www.koreatimes.co.kr/southkorea/20120823/online-real-name-system-unconstitutional) a name registration system for internet users in compliance with the country's Information Communications Law. The law was initially enforced in an attempt to reduce malicious comments online, but **was later ruled unconstitutional and revoked in 2012**. The Constitutional Court said in its verdict that "the system does not seem to have been beneficial to the public. Despite the enforcement of the system, the number of illegal or malicious postings online has not decreased." ### China Sadly, not every country implementing such a system came to the same conclusion. In China, the [Internet real-name system](https://en.wikipedia.org/wiki/Internet%5Freal-name%5Fsystem%5Fin%5FChina) obligates all internet service providers and online platforms to collect users' legal names, ID numbers, and more. This affects services such as internet access, phone service, social media, instant messaging, microblogging, and online gaming. In 2023, large Chinese platforms announced that they would make public the legal names of any accounts with over 500,000 followers. In July 2025, China centralized this control further with the launch of the [national online identity authentication](https://en.wikipedia.org/wiki/National%5Fonline%5Fidentity%5Fauthentication) system, which requires citizens to submit their personal information in order to receive an "Internet certificate" to access online accounts. This effectively imposes a real-name policy on *all* internet services in the country, and makes this information accessible at all time by the government. The new national cyber ID system has been [criticized](https://www.scmp.com/tech/tech-trends/article/3318302/china-rolls-out-voluntary-cyber-id-system-amid-concerns-over-privacy-censorship) over privacy and censorship concerns. So far, it is not mandatory to share identity through the national online identity authentication (although services are still obligated to identity their users in other ways). However, in a country where freedom of speech and access to information is increasingly restricted, it's easy to imagine the national real-name system could become obligatory everywhere soon. ## Real-name policies don't make the web safer It has been demonstrated again and again that real-name policies do not reduce abuse and misbehavior online, and only end up harming the most vulnerable. Despite the evidence and failed attempts, platform owners and policymakers obstinately continue to push for the implementation of these dangerous, authoritarian systems. Platforms will often claim these policies are to protect users from harassment, but when action is required to truly protect users they refuse to act. Facebook, the most infamous platform for enforcing its real-name policy, [ranks the *worst* for online harassment](https://www.theverge.com/news/713976/online-harassment-meta-social-media-environmental-activists). So, who are these real-name policies truly protecting? It's clear that, as is the case for other oppressive policies such as [Age Verification](https://pr3149.unreviewed.privacyguides.dev/articles/2025/05/06/age-verification-wants-your-face/) and [Chat Control](https://pr3149.unreviewed.privacyguides.dev/articles/2025/09/08/chat-control-must-be-stopped/), "safety" is only an excuse for people to accept what this is truly about: **Corporate profit and government control.** Unfortunately, as long as these platforms' business model is to sell users' data to advertisers and other stakeholders, there is no incentive for them to protect our privacy and our right to use protective pseudonyms, as the EFF's Director of Cybersecurity Eva Galperin aptly pointed out in her [talk](https://www.youtube.com/watch?v=d5czLwsa-wE) at the HOPE conference in 2012\. **More data just means more money to them.** When governments impose similar invasive practices, it's a **dangerous and slippery slope towards totalitarianism**. Citizens need to be able to express their views freely online and criticize their government and its leaders without fear of reprisal. Real-name policies (explicit and implicit) are only a tool for censorship, and there is no democracy and no freedom under government censorship. Fighting against policies attacking online pseudonymity, such as real-name policies, age-verification policies, and Chat Control proposals, isn't just a banal fight to keep using silly nicknames online. It's a battle for democracy, for civil liberties, and for human rights. ## What you can do about real-name policies - [**Choose better platforms**](https://news.elenarossini.com/my-fediverse-starter-guide) that do not require you to share your legal name and official IDs, such as [Mastodon](https://pr3149.unreviewed.privacyguides.dev/articles/2025/07/15/mastodon-privacy-and-security/) or other platforms connected to the Fediverse. - [**Inform yourself**](https://safetycrave.com/why-should-not-use-real-names-online/) on the dangers related to using legal names online, and share this information with others. - [**Say no**](https://pr3149.unreviewed.privacyguides.dev/articles/2025/06/17/you-can-say-no/) to sharing official documentation with commercial platforms when it isn't strictly required and when you can avoid it. - [**Understand the difference**](https://www.privacyguides.org/videos/2025/03/14/stop-confusing-privacy-anonymity-and-security/) between privacy, security, anonymity, and pseudonymity. - [**Use pseudonyms**](https://pr3149.unreviewed.privacyguides.dev/articles/2025/06/10/stay-safe-but-stay-connected/#practices-and-tools-that-help-in-various-contexts) on platforms where you can. Use a pseudonym persistent across platforms if you want these accounts to be linked together for trust, or use different pseudonyms to keep them separated. - **Make your voice heard!** Contact your government representatives to let them know that privacy is important to you, and explain to them that pseudonymity is essential for safety, democracy, and free speech online. Complain against platforms using these invasive and exclusionary practices. Citizen action matters, and abusive policies can be reversed. 💡 Keep in mind that only using a pseudonym isn't enough to make you anonymous online. There are many other ways to tie an identity together, such as IP addresses, [browser fingerprinting](https://www.privacyguides.org/videos/2025/09/12/what-is-browser-fingerprinting-and-how-to-stop-it/), photo comparison, facial recognition, and so on and so forth. Pseudonymity is a great practice to **improve* your privacy and safety online, but alone it does have limitations. ### The End of Windows Local Accounts, EU Drops Chat Control, & More URL: https://www.privacyguides.org/livestreams/2025/10/11/the-end-of-windows-local-accounts-eu-drops-chat-control-more/ Last updated: 2025-10-15T21:40:15.000Z This Week in Privacy #22 _This post is for subscribers only._ ### Bits of Freedom & Privacy Guides Partnering to Enhance FixJePrivacy.nl URL: https://www.privacyguides.org/posts/2025/10/08/privacy-guides-bits-of-freedom-partnering-to-enhance-fixjeprivacy-nl/ Last updated: 2025-10-09T14:59:31.000Z To help protect your online privacy and freedom, *Fix je Privacy* is a Dutch-language website launched by Bits of Freedom in 2020\. This website is filled with practical tips to improve your online safety, everything from using a password manager to securely sharing your files. We are excited to start a [collaboration](https://www.bitsoffreedom.nl/2025/10/09/samenwerking-privacy-guides-en-bits-of-freedom/) to ensure the site stays relevant and up-to-date! [Bits of Freedom](https://bitsoffreedom.nl) is a well-known Dutch organization that fights to protect our digital rights, and their mission aligns perfectly with ours. Their website, [**Fixjeprivacy.nl**](https://www.fixjeprivacy.nl/), has been a valuable resource for Dutch-speaking individuals looking to improve their privacy. And now, with our expertise and volunteer-powered community, we’re joining forces to keep the site current with the latest tools and advice. The main focus of our partnership will be helping to keep Fixjeprivacy.nl’s content and recommendations up to date. As technology changes over the years, maintaining a site full of practical advice requires ongoing attention. This is a challenge we know at *Privacy Guides* all too well. Some of the advice on the site was getting outdated, and in some cases, better solutions were available. Our role in this partnership will be actively advising Bits of Freedom on the recommendations going forward. Bits of Freedom will remain making their recommendations independently, and Privacy Guides will support Bits of Freedom by providing input so they stay on top of the developments in the privacy space, and make suggestions where they are needed. We’re excited to work together with Bits of Freedom to ensure that *Fix je Privacy* remains a trusted and relevant resource. Our partnership will help to further increase awareness about online safety, and ultimately enable more people to protect themselves from online trackers and big tech at large. *Fix je Privacy* has been fully updated in September, with more tips and recommendations coming soon. Expect new insights on topics like cloud storage and the use of AI. Want to learn more about safe online banking, using privacy-friendly cycle trackers, or how to remove your data from the web? Check out fixjeprivacy.nl [here](https://fixjeprivacy.nl) (in Dutch). ### Could This Be the End of F-Droid? URL: https://www.privacyguides.org/livestreams/2025/10/04/could-this-be-the-end-of-f-droid/ Last updated: 2025-10-06T17:41:19.000Z This Week in Privacy #21 _This post is for subscribers only._ ### What is Differential Privacy? URL: https://www.privacyguides.org/posts/2025/09/30/differential-privacy/ Last updated: 2025-09-30T16:42:22.000Z Is it possible to collect data from a large group of people but protect each individual's privacy? In this entry of my series on [privacy-enhancing technologies](https://www.privacyguides.org/posts/tag/privacy-enhancing-technologies/), we'll discuss differential privacy and how it can do just that. ## Problem It's useful to collect data from a large group of people. You can see trends in a population. But it requires a lot of individual people to give up personally identifiable information. Even things that seem innocuous like your gender can help identify you. Latanya Sweeney in a [paper](https://dataprivacylab.org/projects/identifiability/paper1.pdf) from 2000 used U.S. Census data to try and re-identify people solely based on the metrics available to her. She found that 87% of Americans could be identified based on only 3 metrics: ZIP code, date of birth, and sex. Obviously, being able to identify individuals based on publicly available data is a huge privacy issue. ## History ### Before Differential Privacy Being able to collect aggregate data is essential for research. It's what the U.S. Census does every 10 years. Usually we're more interested in the data as a whole and not data of individual people as it can show trends and overall patterns in groups of people. However, in order to get that data we must collect it from individuals. It was thought at first that simply [removing names and other obviously identifying details](https://simons.berkeley.edu/news/differential-privacy-issues-policymakers#:~:text=Prior%20to%20the%20line%20of%20research%20that%20led%20to%20differential%20privacy%2C%20it%20was%20widely%20believed%20that%20anonymizing%20data%20was%20a%20relatively%20straightforward%20and%20sufficient%20solution%20to%20the%20privacy%20challenge.%20Statistical%20aggregates%20could%20be%20released%2C%20many%20people%20thought%2C%20without%20revealing%20underlying%20personally%20identifiable%20data.%20Data%20sets%20could%20be%20released%20to%20researchers%20scrubbed%20of%20names%2C%20but%20otherwise%20with%20rich%20individual%20information%2C%20and%20were%20thought%20to%20have%20been%20anonymized.) from the data was enough to prevent re-identification, but [Latanya Sweeney](https://latanyasweeney.org/JLME.pdf) (a name that will pop up a few more times) proved in 1997 that even without names, a significant portion of individuals can be re-identified from a dataset by cross-referencing external data. Previous attempts at anonymizing data have relied on been highly vulnerable to re-identification attacks. #### AOL Search Log Release A famous example is the AOL search log release. AOL had been logging its users searches for research purposes. When they released the data, they only replaced the users' real names with an identifier. Researchers were able to identify [user 4417749](https://archive.nytimes.com/www.nytimes.com/learning/teachers/featured%5Farticles/20060810thursday.html) as Thelma Arnold based on the identifying details of her searches. #### Strava Heatmap Incident In 2018, the fitness app Strava announced a major update to its heatmap, showing the the workout patterns of users of fitness trackers like Fitbit. Analyst [Nathan Ruser](https://x.com/Nrg8000/status/957318498102865920) indicated that these patterns can reveal military bases and troop movement patterns. This is obviously a huge op-sec problem and can endanger the lives of troops. It was also possible to [deanonymize](https://steveloughran.blogspot.com/2018/01/advanced-denanonymization-through-strava.html) individual users in some circumstances. #### Randomized Response One of the earliest ideas for anonymizing data was [randomized response](https://uvammm.github.io/docs/randomizedresponse.pdf), first introduced all the way back in 1965 in a paper by Stanley L. Warner. The idea behind it is quite clever. For certain questions like "have you committed tax fraud?" respondents will likely be hesitant to answer truthfully. The solution? Have the respondent flip a coin. If the coin is tails, answer yes. If the coin lands on heads, answer truthfully. | Respondent | Answer | Coin Flip (not included in the actual dataset just here for illustration) | | ---------- | ------ | ------------------------------------------------------------------------- | | 1 | Yes | Tails (Answer Yes) | | 2 | No | Heads (Answer Truthfully) | | 3 | Yes | Tails (Answer Yes) | | 4 | Yes | Tails (Answer Yes) | | 5 | No | Heads (Answer Truthfully) | Because we know the exact probability that a "Yes" answer is fake, 50%, we can remove it and give a rough estimate of how many respondents answered "Yes" truthfully. Randomized Response would lay the groundwork for differential privacy, but it wouldn't truly be realized for many decades. #### Unrelated Question Randomized Response A variation used later in a [paper](https://www.jstor.org/stable/2283636) by Greenberg et al. called **unrelated question randomized response** would present each respondent with either a sensitive question or a banal question like "is your birthday in January?" to increase the likelihood of people answering honestly, since the researcher doesn't know which question was asked. | Respondent | Question (not visible to researcher) | Answer | | ---------- | ------------------------------------ | ------ | | 1 | Have you ever committed tax evasion? | No | | 2 | Is your birthday in January? | Yes | | 3 | Is your birthday in January? | No | | 4 | Have you ever committed tax evasion? | Yes | | 5 | Have you ever committed tax evasion? | No | #### k-Anonymity Latanya Sweeney and Pierangela Samarati introduced [k-anonymity](https://dataprivacylab.org/dataprivacy/projects/kanonymity/paper3.pdf) to the world back in 1998. It's interesting that even all the way back in 1998 concerns constant data collection were already relevant. > Most actions in daily life are recorded on some computer somewhere. That information in turn is often shared, exchanged, and sold. Many people may not care that the local grocer keeps track of which items they purchase, but shared information can be quite sensitive or damaging to individuals and organizations. Improper disclosure of medical information, financial information or matters of national security can have alarming ramifications, and many abuses have been cited. In a dataset, you might have removed names and other obviously identifying information, but there might be other data such as birthday, ZIP code, etc., that might be unique to one person in the dataset. If someone were to cross-reference this data with outside data, it could be possible to deanonymize individuals. k-anonymity means that for each row, at least k-1 other rows are identical. So for a k of 2, at least one other row is identical to each row. ##### Generalization This is achieved through a few techniques, one of which is generalization. Generalization is reducing the precision of data so that it's not as unique. For example, instead of recording an exact age, you might give a range like 20-30\. You've probably noticed this on surveys you've taken before. Data like this that's not directly identifiable but could be used to re-identify someone is referred to as *quasi-identifiers*. ##### Suppression Sometimes even with generalization, you might have outliers that don't satisfy the k-anonymity requirements. In these cases, you can simply remove the row entirely. ##### Attacks on k-Anonymity k-anonymity has been [demonstrated](https://www.usenix.org/system/files/sec22-cohen.pdf) to not prevent re-identification of individuals despite the data in a dataset being properly k-anonymized by "statistical experts". Researchers were able to deanonymize 3 students from a k-anonymized dataset from Harvard and MIT's EdX platform by cross-referencing data from LinkedIn, putting potentially thousands of students at risk of re-identification. ### Dawn of Differential Privacy Most of the concepts I write about seem to come from the 70s and 80s, but differential privacy is a relatively new concept. It was first introduced in a paper from 2006 called [*Calibrating Noise to Sensitivity in Private Data Analysis*](https://desfontain.es/PDFs/PhD/CalibratingNoiseToSensitivityInPrivateDataAnalysis.pdf). The paper introduces the idea of adding noise to data to achieve privacy, similar to randomized response. However, differential privacy is much more mathematically rigorous and provable. Of course, adding noise to the dataset reduces its accuracy. Ɛ defines the amount of noise added to the dataset, with a small Ɛ meaning more privacy but less accurate data and vice versa. It's also referred to as the "privacy loss parameter" or "privacy budget". #### Central Differential Privacy This early form of differential privacy relied on adding noise to the data *after* it was already collected, meaning you still have to trust a central authority with the raw data. ## Google RAPPOR In 2014, Google introduced [Randomized Aggregatable Privacy-Preserving Ordinal Response](https://arxiv.org/pdf/1407.6981) (RAPPOR), their [open source](https://github.com/google/rappor) implementation of differential privacy. Google RAPPOR implements and builds on previous techniques such as randomized response and adds significant improvements on top. ### Local Differential Privacy In Google's implementation, noise is added to data on-device before it's sent off to any server. This removes the need to trust the central authority to handle your raw data, an important step in achieving truly anonymous data collection. ### Bloom Filters Google RAPPOR makes use of a clever technique called bloom filters that saves space and improves privacy. Bloom filters work by starting out with an array of all 0's `[0, 0, 0, 0, 0, 0, 0, 0, 0]` Then, you run data such as the word "apple" through a hashing algorithm, which will give 1's in specific positions, say position 1, 3, and 5. `[0, 1, 0, 1, 0, 1, 0, 0, 0]` When you want to check if data is present, you run the data through the hashing algorithm and check if the corresponding positions are 1's. If they are, the data *might* be present (other data might have flipped those same bits at some point). If any of the 1's are 0's, then you know for sure that the data is not in the set. ### Permanent Randomized Response A randomization step is performed flipping some of the bits randomly. This response is then "memoized" so that the same random values are used for future reporting. This protects against an "averaging" attack where an attacker sees multiple responses from the same user and can eventually recover the real value by averaging them out over time. ### Instantaneous Randomized Response On top of the permanent randomized data, another randomization step is performed. This time, different randomness is added on top of the permanent randomness so that every response sent is unique. This prevents an attacker from determining a user from seeing the same randomized pattern over and over again. Both the permanent and instantaneous randomized response steps can be fine-tuned to for the desired privacy. ### Chrome Google first used differential privacy in their Chrome browser for detection of [malware](https://blog.chromium.org/2014/10/learning-statistics-with-privacy-aided.html). Differential privacy is also used in Google's [Privacy Sandbox](https://privacysandbox.google.com/private-advertising/aggregation-service/privacy-protection-report-strategy). ### Maps Google Maps uses DP for its [place busyness](https://safety.google/privacy/data/#:~:text=To%20offer%20features%20like%20place%20busyness%20in%20Maps%2C%20we%20apply%20an%20advanced%20anonymization%20technology%20called%20differential%20privacy%20that%20adds%20noise%20to%20your%20information%20so%20it%20can%E2%80%99t%20be%20used%20to%20personally%20identify%20you.) feature, allowing Maps to show you how busy an area is without revealing the movements of individual people. ### Google Fi [Google Fi](https://opensource.googleblog.com/2019/09/enabling-developers-and-organizations.html) uses differential privacy as well to improve the service. ## OpenDP [OpenDP](https://opendp.org) is a community effort to build open source and trustworthy tools for differential privacy. Their members consist of academics from prestigious universities like Harvard and employees at companies like Microsoft. There's been an effort from everyone to make differential privacy implementations open source, which is a breath of fresh air from companies that typically stick to closed source for their products. ## Apple [Apple](https://www.apple.com/privacy/docs/Differential%5FPrivacy%5FOverview.pdf) uses local differential privacy for much of its services, similar to what Google does. They add noise before sending any data off device, enabling them to collect aggregate data without harming the privacy of any individual user. They limit the number of contributions any one user can make via a *privacy budget* (this is the same as Ɛ) so you won't have to worry about your own contributions being averaged out over time and revealing your own trends. This allows them to find new words that people use that aren't included by default in the dictionary, or find which emojis are the most popular. Some of the things they use differential privacy for include - QuickType suggestions - Emoji suggestions - Lookup Hints - Safari Energy Draining Domains - Safari Autoplay Intent Detection - Safari Crashing Domains - Health Type Usage That's just based on their initial white paper, they've likely increased their use of DP since then. ### Sketch Matrix Apple uses a similar method to Google, with a matrix initialized with all zeros. The input for the matrix is encoded with the SHA-256 hashing algorithm, and then bits are flipped randomly at a probability dependent on the epsilon value. Apple only sends a random row from this matrix instead of the entire thing in order to stay within their privacy budget. ### See What's Sent You can see data sent with differential privacy in iOS under Settings > Privacy > Analytics > Analytics Data, it will begin with `DifferentialPrivacy`. On macOS, you can see these logs in the Console. ## U.S. Census Differential privacy isn't just used by big corporations, in 2020 famously the U.S. Census used DP to protect the data of U.S. citizens for the first time. As a massive collection of data from numerous U.S. citizens, it's important for the census bureau to protect the privacy of census participants while still preserving the overall aggregate data. ### Impetus Since the 90s, the U.S. Census used a less formal injection of statistical noise into their data, which they did all the way through 2010. After the 2010 census, the bureau tried to [re-identify individuals](https://www2.census.gov/library/publications/decennial/2020/census-briefs/c2020br-03.pdf) in the census data. > The experiment resulted in reconstruction of a dataset of more than 300 million individuals. The Census Bureau then used that dataset to match the reconstructed records to four commercially available data sources, to attempt to identify the age, sex, race, and Hispanic origin of people in more than six million blocks in the 2010 Census. Considering 309 million people lived in the U.S. in 2010, that's a devastating breach of personal privacy. Clearly more formal frameworks for protecting the privacy of individuals were needed. > Nationwide, roughly 150 million individuals—almost one-half of the population, have a unique combination of sex and single year of age at the block level. They could keep adding noise until these attacks are impossible, but that would make the data nigh unusable. Instead, differential privacy offers a mathematically rigorous method to protect the data from future re-identification attacks without ruining the data by adding too much noise. They can be sure thanks to the mathematical guarantees of DP. ## DPrio Mozilla has been constantly working to make their telemetry more private over the years. Firefox uses [Prio](https://blog.mozilla.org/security/2019/06/06/next-steps-in-privacy-preserving-telemetry-with-prio/), a [Distributed Aggregation Protocol](https://datatracker.ietf.org/doc/html/draft-ietf-ppm-dap)\-based telemetry system. It uses Multi-Party Computation to split the processing of user data between multiple parties. To accomplish this, [Mozilla](https://blog.mozilla.org/en/firefox/partnership-ohttp-prio/) partnered with [Divvi Up](https://divviup.org/blog/divvi-up-in-firefox/) as their DAP provider, and [Fastly](https://www.fastly.com/blog/firefox-fastly-take-another-step-toward-security-upgrade) as their OHTTP provider. OHTTP acts as a multi-hop proxy to separate traffic between two parties when making a connection: neither Mozilla nor Fastly will know both who you are and what you're connecting to. In 2023 researchers from Mozilla also conducted research into making Prio differentially private. The so-named "[DPrio](https://petsymposium.org/popets/2023/popets-2023-0086.pdf)" would combine multi-party computation, OHTTP, and differential privacy in a very impressive display of privacy protection. Unfortunately I couldn't find any evidence to suggest that DPrio has been implemented, but something to keep a lookout for in the future. ## Future of Differential Privacy Differential privacy unlocks the potential for data collection with minimal risk of data exposure for any individual. Already, DP has allowed for software developers to improve their software, for new possibilities in research in the health sector and in government organizations. Adoption of scientifically and mathematically rigorous methods of data collection allows for organizations to collect aggregate data will allow for increased public trust in organizations and subsequently greater potential for research that will result in improvements to our everyday lives. I think for there to be more public trust there needs to be a bigger public outreach. That's my goal with this series, I'm hoping to at least increase awareness of some of the technology being deployed to protect your data, especially since so much of the news we hear is negative. Armed with the knowledge of what's available, we can also demand companies and organizations use these tools if they aren't already. It's heartening to see the level of openness and collaboration in the research. You can see a clear improvement over time as each paper takes the previous research and builds on it. I wish we saw the same attitude with all software. ## Further Research Any programmers interested in learning how to implement differential privacy can check out the book [*Programming Differential Privacy*](https://programming-dp.com) to see Python examples. ### The Threat That Makes Encryption Useless URL: https://www.privacyguides.org/videos/2025/09/27/the-threat-that-makes-encryption-useless/ Last updated: 2025-10-02T13:47:20.000Z #### Sources: 1:27 1:30 3:00 [https://en.wikipedia.org/wiki/Shor's\_algorithm#/media/File:Shor's\_algorithm.svg](https://en.wikipedia.org/wiki/Shor%27s%5Falgorithm#/media/File:Shor's%5Falgorithm.svg) 3:14 4:11 4:24 4:41 4:53 5:17 5:27 [https://en.wikipedia.org/wiki/Shor's\_algorithm#/media/File:Shor's\_algorithm.svg](https://en.wikipedia.org/wiki/Shor%27s%5Falgorithm#/media/File:Shor's%5Falgorithm.svg) 5:49 [https://en.wikipedia.org/wiki/Grover's\_algorithm](https://en.wikipedia.org/wiki/Grover%27s%5Falgorithm) 6:13 6:15 6:52 7:02 7:11 7:15 7:20 7:30 ### Oracle Moves to Take Over TikTok, Firefox for Android Adds DoH, and the UK Plans Mandatory Digital ID URL: https://www.privacyguides.org/livestreams/2025/09/27/who-really-owns-your-tiktok-data-now/ Last updated: 2025-09-27T04:26:28.000Z This Week in Privacy #20 _This post is for subscribers only._ ### The battle to stop Chat Control continues, act now! URL: https://www.privacyguides.org/newsletters/2025/09/23/the-battle-to-stop-chat-control-continues-act-now/ Last updated: 2025-09-23T06:30:00.000Z 🚨 The clock is ticking! Time is running out to stop Chat Control before the final vote on October 14th. Whether you are European or not, you can help! ✊🔒 If you've been following our reporting on Chat Control: **Bad news**: The proposal is going forward to be voted on on October 14th, and there's still no blocking minority achieved, as Germany reverted its position to undecided. **Good news**: There is still time to fight back! [Chat Control](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/) refers to the latest iteration of a series of legislative proposals that would mandate scanning all private digital communications in the European Union. This would include end-to-end encrypted services, effectively creating a backdoor and breaking encryption. Even if you are not European, the proposed legislation would set a dangerous precedent for civil liberties and democracies worldwide. Chat Control proposes an unprecedented **escalation of authoritarian mass surveillance** and infringement on fundamental human rights. Cryptography professor Matthew Green described the 2022 version of Chat Control as "[**the most terrifying thing I've ever seen**](https://fortune.com/2022/05/12/europe-phone-surveillance-crackdown-child-sexual-abuse-material-sparks-outrage-among-cybersecurity-experts-privacy-activists/)". This month, a [joint statement](https://csa-scientist-open-letter.org/Sep2025) submitted on September 9th and **signed by more than 700 scientists and researchers** reports that "it is simply **not feasible** to perform detection of known and new CSAM \[Child Sexual Abuse Material\] for hundreds of millions of users with an acceptable level of accuracy." It adds that the new proposal would "create **unprecedented capabilities for surveillance, control, and censorship** and has an inherent risk for function creep and abuse." Despite strong and repeated opposition from human rights activists, digital rights activists, scientists, cryptography experts, and child protection organizations, the proposal will be put forward for a final vote by EU member states on October 14th. It is critical to stop this dystopian mass-surveillance legislation. ## What can you do to help? 📮 For European Citizens: **Contact your representatives now**, to make sure they receive your message ahead of the vote on October 14th. You can use this [**easy tool**](https://fightchatcontrol.eu/) created by Fight Chat Control to contact them with only a few clicks. 📰 For European Citizens: **Contact your local media now**, to make sure they have enough time to talk about it ahead of the vote on October 14th. Share your concerns and ask if they plan to cover this topic before the final vote. Bring them accurate information to counter disinformation they might have received from lobbyists. ✊ For Everyone: **Spread the word on social media**. Tell others to contact their representatives and contact their local media. Write about it, talk about it, and share accurate information to counter disinformation. ## And what next? Sign up to stay informed. Privacy Guides is a non-profit project fighting for your digital rights. Don't miss out on our updates, recommendations, and other advice: Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. You can learn more about Chat Control, why it's a terrifying proposal, and how it would harm everyone inside and outside of Europe (including the children), by reading our article on the topic: [Chat Control Must Be Stopped, Act Now!Chat Control is back to undermine everyone’s privacy. There’s an important deadline on October 14th, 2025\. We must act now to stop it!![](https://www.privacyguides.org/content/images/icon/favicon-32x32-5.png)Privacy GuidesEm![](https://www.privacyguides.org/content/images/thumbnail/chat-control-must-be-stopped-1.png)](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/) Keep fighting for privacy rights! [Em](https://www.privacyguides.org/articles/author/em) ### Memory Integrity Enforcement Changes the Game on iOS URL: https://www.privacyguides.org/posts/2025/09/20/memory-integrity-enforcement-changes-the-game-on-ios/ Last updated: 2025-09-27T05:03:40.000Z Apple's new support for ARM's Memory Tagging Extension in iOS and their A19 SoC is an underrated feature for journalists, activists, and other high-profile figures. _This post is for subscribers only._ ### Governments Attack Free Speech, Apple Releases MTE, Chat Control is Still Around URL: https://www.privacyguides.org/livestreams/2025/09/19/governments-attack-free-speech-apple-releases-mte-chat-control-is-still-around/ Last updated: 2025-09-21T00:36:32.000Z This Week in Privacy #19 _This post is for subscribers only._ ### Ghosts in the Machine: The Fight for Privacy After Death URL: https://www.privacyguides.org/posts/2025/09/16/the-fight-for-privacy-after-death/ Last updated: 2026-06-01T16:19:00.000Z In the early hours of 6 June 2020, Nicole Smallman and her sister Bibaa Henry had just finished celebrating Bibaa’s birthday with friends in a park in London. Alone and in the dark, they were both [fatally and repeatedly stabbed](https://en.wikipedia.org/wiki/Murders%5Fof%5FBibaa%5FHenry%5Fand%5FNicole%5FSmallman) 36 times. But the police didn’t just fail them in life—they failed them in death too. PC Deniz Jaffer and PC Jamie Lewis, both of the Metropolitan Police, [took selfies](https://www.theguardian.com/uk-news/2021/dec/06/two-met-police-officers-jailed-photos-murdered-sisters-deniz-jaffer-jamie-lewis-nicole-smallman-bibaa-henry) with the dead bodies of the victims, posting them on a WhatsApp group. And no privacy laws prevented them from doing so. This horrific case is just one in the murky, often sinister realm of posthumous privacy. In the UK, Europe, and across the world, privacy protections for the dead are at best a rarity—and at worst, a deep moral and societal failing that we cannot and must not accept. Let’s take a step back. The case of the Smallmans starkly draws attention to the denial in death of guarantees to the living. As a *Privacy Guides* reader, you are no doubt aware that the UK and Europe have firm privacy protections in *The General Data Protection Regulation* (GDPR) and Article 8 of the *European Convention on Human Rights* (ECHR). However, the picture elsewhere is less clear, with a challenging patchwork of laws and regional statutes being the only protection for those in the US and much of the rest of the world. And once you die? Almost universally, these protections [immediately cease](https://gdpr-info.eu/recitals/no-27/). Here the problem begins. This abrupt collapse in privacy rights leaves the deceased and their families—like the Smallman family—newly vulnerable, and at a time when they are already utterly broken. In the absence of law comes the pursuit of it, against a backdrop of flagrant privacy violations. What this pursuit means, in practical terms, is that two primary categories of posthumous privacy dominate legal debate: the medical, where the law has intervened tentatively, and the digital, where it simply hasn’t kept up. Medical protections are tentative because of piecemeal development. Typically involving legal workarounds, they offer rare precedent for what might happen to your digital ghosts now and in the future, with the only clear trend being a reluctance to protect. That said, the US is one country that has taken measures to protect the medical privacy of the dead. The *Health Insurance Portability and Accountability Act* (HIPAA) dictates that 50 years of protection must be given to your personally identifiable medical information after you die. Except there’s a catch. State laws also apply, and state laws differ. In Colorado, Louisiana, and many others, its efficacy is severely challenged by laws dictating the mandatory release of information regarded as public—including autopsy reports and even [your genetic information](http://dx.doi.org.ezp.lib.cam.ac.uk/10.1177/1073110516654124). In lieu of any protections, surviving relatives in Europe have found some success claiming that their own Article 8 rights—that ECHR right to privacy—have been violated through disclosures or inspections related to their deceased. In one case, Leyla Polat, an Austrian national, suffered the awful death of her son just two days after birth following a cerebral hemorrhage. The family refused a postmortem examination, wanting to bury their child in accordance with Muslim beliefs; but doctors insisted it take place, covertly removing his internal organs and filling the hollows with cotton wool. When this was discovered during the funeral rites, the boy had to be buried elsewhere, and without ceremony. After several court cases and appeals, The European Court of Human Rights [found](https://hudoc.echr.coe.int/rum#%7B%22itemid%22:%5B%22002-13361%22%5D%7D) that Leyla’s Article 8 and 9 rights had been violated. ## Is this article interesting? If you want to see more posts like this, we need you to support our independent, non-profit media by subscribing and becoming a member today. Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. As an aside: Stalin’s grandson [tried the same Article 8 route](https://hudoc.echr.coe.int/eng#%7B%22itemid%22:%5B%22001-150568%22%5D%7D) in relation to reputational attacks on his grandfather, reflecting attempts to apply the workaround more widely. It’s not that there hasn’t been some progress. The fundamental problem is that protections—already sparse—are only as good as their material and geographic scopes, their interactions with other laws, and how they are interpreted in a court. Nowhere is this more apparent than in the case of the Smallman sisters. Judge Mark Lucraft KC [found](https://www.judiciary.uk/wp-content/uploads/2022/07/R-v-Jaffer-Lewis-sentencing-061221.pdf) that PCs Jaffer and Lewis, in taking selfies with the murdered victims, had: > *“…wholly disregarded the privacy of the two victims of horrific violence and their families for what can only have been some cheap thrill, kudos, a kick or some form of bragging right by taking images and then passing them to others.”* Yet this acknowledgement of privacy violation is precisely just that. The crime the officers committed was misconduct in public office; they were not convicted on the basis of privacy law. That sense of progress—that we might be beginning to recognize the importance of posthumous privacy—has all but gone out of the window. That does not leave your digital privacy in a good place. Whatever little protection you may be able to tease out for our medical privacy far, far exceeds the control you have over your virtual ghosts. And with AI just about everywhere, the prospects for your data after death are terrifying. We’ve already established that data protections for the living—such as GDPR—expire at death. The simple reality is that dying places your data at the mercy of large technology corporations, and their dubious afterlife tools. Even if you trust such tools to dispose of or act on our data, there is a disconnect between demand and take-up. A [study of UK nationals](https://www.tandfonline.com/doi/full/10.1080/13600869.2025.2506164#abstract) found a majority that wanted their data deleted at death were unaware of the tools, with large tech companies unwilling to share any details on their uptake. Reassuring stuff. But the reality is, you shouldn’t. You’ll recall that [deletion doesn’t usually mean deletion](https://www.privacyguides.org/en/basics/account-deletion/), and after death even GDPR can’t force big tech to delete the data of those lucky enough to have benefited from it. Account deleted or not, our ghosts will all be stuck in the machine. Recent reports have acknowledged dire possibilities. Almost worldwide, you can [legally train AI models on the data of a deceased person](https://www.reuters.com/article/world/data-of-the-dead-virtual-immortality-exposes-holes-in-privacy-laws-idUSKBN21Z0NE/) and recreate them in digital form—all without their prior consent. Organizations exist purely to scour your social media profiles and activity for this exact purpose. Your ghost could be used to generate engagement against your will, disclosing what you tried to hide. You may ask: why should the law care? Why indeed, when it often assumes we [cannot be harmed](https://doi.org/10.1093/acprof:oso/9780199607860.003.0003) after death. To argue thus is to miss the point. **A lack of privacy after death harms the living, often in ways others cannot see.** The effect of [postmortem anxiety](https://www.tandfonline.com/doi/full/10.1080/17577632.2024.2438395#d1e120) is a real one that deeply troubles individuals wishing to keep a part of them hidden from public—or even family—view, whether it be it an [illicit affair](https://www.cardozoaelj.com/wp-content/uploads/2011/02/Edwards-Galleyed-FINAL.pdf) or whatever else. Revelation at the point of death can be just as harmful to those still alive. There is cause for optimism. Article 85 of the *French Data Protection Act* allows you to include [legally enforceable demands concerning your personal data](https://www.cnil.fr/fr/la-loi-informatique-et-libertes#article85) in your will. This is truly a landmark piece of legislation by the French that indicates what the global direction of travel should be, and what we should ultimately demand: protections for the dead, by the dead. But even more urgently, we must demand that governments across the world introduce even the most basic legal framework for postmortem privacy that protects you, your family, and community from egregious harm. The Smallmans deserved dignity, and so does everyone else in death. The law must catch up. --- *This article hasn’t even begun to scratch the surface of the complexity of postmortem privacy, and there are innumerable relevant cases and laws that simply wouldn’t fit. If the topic has caught your interest, and you’d like to dig in more,* [*this white paper*](https://doi.org/10.1016/j.clsr.2022.105737) *by Uta Kohl is a good starting point.* ## Sign up for Privacy Guides Established in 2021, Privacy Guides is the most popular & trustworthy non-profit resource to find privacy tools and learn about protecting your digital life. Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. ### Multi-Party Computation Explained URL: https://www.privacyguides.org/posts/2025/09/15/multi-party-computation/ Last updated: 2025-09-16T16:12:41.000Z We know how to secure data in storage using E2EE, but is it possible to ensure data privacy even while processing it server-side? This is the first in a [series](https://www.privacyguides.org/articles/tags/#tag:privacy-enhancing-technologies) of articles I'll be writing covering the privacy-enhancing technologies being rolled out in the technology space. ## History In a seminal [paper](https://dspace.mit.edu/bitstream/handle/1721.1/148953/MIT-LCS-TM-125.pdf?sequence=1) called "Mental Poker" by Adi Shamir, Ronald L. Rivest, and Leonard M. Adleman from 1979, the researchers attempt to demonstrate a way of playing poker over a distance using only messages and still have it be a fair game. To explain, fan favorites Alice and Bob will make a return. First, Bob encrypts all the cards with his key, then sends them to Alice. Alice picks five to deal back to Bob as his hand, then encrypts five with her own key and sends those to Bob as well. Bob removes his encryption from all ten cards and sends Alice's cards back to her. Notice that Bob needs to be able to remove his encryption *after* Alice has applied hers. This commutative property is important for the scheme to work. This early scheme is highly specialized for this task and not applicable to different situations. ### Secure Two-Party Computation Alice and Bob have struck it rich! They're both millionaires, but they want to be able to see who has more money without revealing exactly how much they have to each other. Luckily, we can use **Multi-Party Computation** (MPC) to solve this "Millionaire's Problem," using a method invented by Andrew Yao called *garbled circuits*. Garbled circuits allow us to use MPC for any problem as long as it can be represented as a boolean circuit, i.e. a set of logic gates such as `AND` `OR` `XOR` etc. ### Garbled Circuits We can split the two parties into an "Evaluator" and a "Generator". The Generator will be responsible for setting up the cryptography that'll be used, and the Evaluator will actually perform the computation. We start by making the truth table for our inputs. In order to hide the values of the truth table, we assign each input a different label. Importantly, we need to assign a different label for each input, so 1 will not be represented by the same label for each. We also need to shuffle the order of the rows, so the values can't be inferred from that. We can still tell what the value is based on knowing the type of logic gate. For example, an `AND` gate would only have one different output, so you could infer that output is 1 and the others are 0\. To fix this, we can encrypt the rows using the input labels as keys, so only the correct output can be decrypted. We still have a problem, though: how can the Evaluator put in their inputs? Asking for both labels would allow them to decrypt more than one output, and giving their input would break the whole point. The solution is something called "Oblivious Transfer". The solution is for the Evaluator to generate two public keys, one of which they have the private key for. The Generator encrypts the two labels for the Evaluator's inputs using the provide public keys and sends them back. Since the Generator only has a private key for one of the labels, they will decrypt the one they want. The Generator puts the labels in order so that the Evaluator can choose which one they want to decrypt. This method relies on the Evaluator not to send multiple keys that can be decrypted. Because some trust is required, this protocol is considered "semi-honest". There's a good explainer for Yao's garbled circuits [here](https://lcamel.github.io/MPC-Notes/story-en-US.html) if you're interested in a step-by-step walkthrough. ### Birth of Multi-Party Computation Multi-Party Computation was solidified with the [research](https://dl.acm.org/doi/pdf/10.1145/28395.28420) of Oded Goldreich, Silvio Micali, and Avi Wigderson and the GMW paradigm (named after the researchers, similar to how RSA is named). #### More Than Two Parties Yao's protocol was limited to two parties. The GMW paradigm expanded the protocol to be able to handle any number of parties and can handle actively malicious actors as long as the majority are honest. #### Secret Sharing The GMW paradigm relies on secret sharing which is a method of splitting private information like a cryptographic key into multiple parts such that it will only reveal the secret if the shares are combined. The GMW protocol uses additive secret sharing, which is quite simple. You come up with a secret number, say 123, and you split it up into however many other numbers you want. `99 + 24 = 123` You distribute each number to a participant and add them all together to get the original secret. While simple, it doesn't play well with multiplication operations. #### Zero-Knowledge Proofs The GMW paradigm introduced protections against malicious adversaries, powered by zero-knowledge proofs (ZKP). ZKP allow one party to convince another party a statement is true without revealing any other information than the fact that the statement is true. The concept of ZKP was first introduced in a [paper](https://dl.acm.org/doi/pdf/10.1145/22145.22178) from 1985 by Shafi Goldwasser, Silvio Micali, and Charles Rackoff. A humorous paper titled [*How to Explain Zero-Knowledge Protocols to Your Children*](https://pages.cs.wisc.edu/~mkowalcz/628.pdf) gives a storybook explanation of how they work (who says academic papers can't be fun?). The main crux revolves around probability: if a party knows the proper way to get a result, they should be able to reliably get the correct answer. To borrow the cave explanation, imagine Alice and Bob have taken up cave exploration. They've found a cave in the shape of a loop with a magic door connecting each entrance together and Alice claims to know how to open it. However, she doesn't want Bob to know the secret to open the door. Alice, acting as the "Prover" goes into the cave. Bob, the "Verifier", stays outside and yells which side of the cave Alice should come out of. They repeat this many times. If Alice can reliably make it out of the correct side of the cave, then she must know how to open the magic door. ### BGW Protocol While the GMW protocol was a huge leap forward for MPC, there were still huge limitations. The garbled circuit protocol is limited to boolean logic gates which makes implementing many different common operations much more difficult. It also requires communication for every single gate, which is highly inefficient. The researchers Michael Ben-Or, Shafi Goldwassert, and Avi Wigderson in their paper [*Completeness Theorems for Non-Cryptographic Fault-Tolerant Distributed Computation*](https://dl.acm.org/doi/pdf/10.1145/62212.62213) made several advancements in the efficiency and robustness of MPC, moving it closer to being practical to use in the real world. #### Arithmetic Circuits Instead of boolean circuits, the BGW protocol uses arithmetic circuits. These allow for easier mathematical operations like multiplication and addition instead of being limited to logic gates on individual bits. This makes a huge difference in the amount of communication between parties and thus the efficiency of the protocol. #### Shamir's Secret Sharing The BGW protocol utilizes [Shamir's Secret Sharing](https://web.mit.edu/6.857/OldStuff/Fall03/ref/Shamir-HowToShareASecret.pdf), which relies on polynomials instead of addition. This allows for more efficiency in multiplication and allows for setting a threshold where only a certain number of shares need to be present in order to reconstruct the secret. #### Less Communication The BGW protocol doesn't require as much communication between parties, partly thanks to its use of Shamir's secret sharing which works well with arithmetic operations. Additionally, it doesn't require Oblivious Transfer or zero-knowledge proofs. Its use of Shamir's secret sharing and error correction codes instead provides the same properties in a more efficient way. ### Fairplay The field was further advanced by the introduction of the [Fairplay](https://www.cs.huji.ac.il/w~noam/FairplayMP.pdf) system. Up until this paper, MPC was limited to boolean circuits or arithmetic circuits: not exactly friendly if you're a programmer that's used to using higher level languages. Fairplay introduces a compiler, SFDL, which can compile higher level languages to boolean circuits and then securely computes the circuit. Fairplay also brings some advancements in efficiency. It utilizes constant rounds, with a fixed 8 rounds, reducing the communication overhead. It also uses the free XOR technique so that encryption operations don't have to be performed on XOR gates, improving efficiency. ### Real-World Usage As MPC saw gradual optimizations and improvements, it grew from an interesting thought experiment to something that could have real-world uses. #### Danish Sugar Beet Auction The first instance of MPC being used in a real-world scenario wouldn't occur until 2008. Denmark's sugar beet industry faced a problem: with the EU significantly reducing its financial support for sugar beet production, they needed to figure out what price the thousands of sugar beet farmers were willing to sell at, and which price the company that bought all the sugar beets would be willing to buy them at, a so-called "double auction" where the buyer and seller figure out the **market clearing price**, or the price at which demand meets supply most effectively. But who should be in charge of the auction? Farmers don't want to trust Danisco with their bids as it reveals information about each individual farmer's business. The farmers can't be in charge of it because they don't trust each other. They could use an external consulting firm, but then the entire operation would rely on that one firm's confidentiality and the reliability of their tools. The [solution](https://a.storyblok.com/f/266767/x/e4c85ffa34/mpc-goes-live%5Fwhitepaper%5F2008-068.pdf) was to use a "virtual auctioneer" that relied on MPC to fairly carry the auction out. It relied on three servers, with one representing each party: Danisco, DKS (the Danish sugar beet growers association), and The SIMAP project (Secure Information Management and Processing, a project sponsored by the Danish National Research Agency). The solution was so successful that it was used every year until 2015 when it was no longer needed. A survey of the farmers found that the vast majority found the system simplified the process of trading contracts and that they were satisfied with the level of confidentiality it provided. The first test run of MPC was a massive success and the potential was now proven. #### The Boston Women's Workforce Council In 2016, the [Boston Women's Workforce Council](https://www.boston.gov/sites/default/files/document-file-09-2017/bwwcr-2016-new-report.pdf) worked with 69 companies to investigate if women are paid the same as men. Using MPC, the companies were able to process their data without revealing the actual wages of any employees. The wage data of 112,600 employees was collected, representing about 11% of the Greater Boston workforce. You can read their detailed findings in the report, but they found that women were indeed being paid less than men: 77 cents for every dollar a man makes on average. It was reported in 2023 that thanks to this data, the Boston Women's Workforce Council was able to reduce the wage gap by 30%. #### Allegheny County In 2018, Allegheny County Department of Human Services partnered with the [Bipartisan Policy Center](https://bipartisanpolicy.org/press-release/bpc-partners-with-allegheny-county-on-new-privacy-preserving-data-project/) to implement MPC, allowing for private and secure sharing of county data on services to the homeless, behavioral health services, causes and incidence of mortality, family interventions, and incarceration. The experiment was considered a success, with a recommendation from the U.S. Commission on Evidence-Based Policymaking to further explore the use of MPC. ## MPC Today Today, the [MPC Alliance](https://www.mpcalliance.org) represents a collective of companies that have come together to advance the use of MPC. MPC is used for everything from [cryptocurrency](https://www.coinbase.com/learn/wallet/what-is-a-multi-party-computation-mpc-wallet) to HIPAA-compliant [medical](https://pmc.ncbi.nlm.nih.gov/articles/PMC6658266/) uses. There are ongoing efforts to [standardize](https://csrc.nist.gov/projects/threshold-cryptography) it from organizations like NIST, although it's a difficult proposition due to the sheer variation in MPC protocols and use cases. There's been research into using MPC for secure and [verifiably fair](https://eprint.iacr.org/2014/075.pdf) [electronic voting](https://arxiv.org/html/2205.10580v4), something that's much needed as countries move toward [electronic voting](https://worldpopulationreview.com/country-rankings/electronic-voting-by-country). It's important to not completely dismiss the march of technology, but these things should be implemented with the utmost caution and scientific rigor. I feel that implementing black-box electronic voting without open and provably secure technologies like MPC is irresponsible and endangers elections. MPC acts as an essential privacy tool in the toolbox. It intersects with other PETs like homomorphic encryption, a method of encrypting data in such a way that operations can still be performed on it without revealing the unencrypted data. MPC is just one tool among many that's reshaping the privacy landscape. I'm excited to see how it's used in the future and what new advancements it unlocks. ### Tor VPN and Signal Backups Beta Released URL: https://www.privacyguides.org/livestreams/2025/09/12/tor-vpn-and-signal-backups-beta-released/ Last updated: 2025-09-12T23:31:28.000Z This Week in Privacy #18 _This post is for subscribers only._ ### What is Browser Fingerprinting? (Interview with Rui Hildt) URL: https://www.privacyguides.org/videos/2025/09/12/what-is-browser-fingerprinting-and-how-to-stop-it/ Last updated: 2025-09-12T00:59:27.000Z In this video interview with Rui Hildt from the Mullvad Browser team, we uncover how this tracking technology works and how you can fight back! [Recommended Web Browsers](https://www.privacyguides.org/en/desktop-browsers/) ## Resources: [ANTI-FINGERPRINTING | Tor Project | Tor Browser ManualDefend yourself against tracking and surveillance. Circumvent censorship. | ANTI-FINGERPRINTING![](https://www.privacyguides.org/content/images/icon/favicon-5.ico)Tor Logo![](https://www.privacyguides.org/content/images/thumbnail/tor-logo@2x.png)](https://tb-manual.torproject.org/anti-fingerprinting/ ) [Browser fingerprinting – tracking behind the curtainWhen it comes to mass surveillance, browser fingerprinting as a means for tracking people, isn’t as straightforward as tracking via IP addresses and cookies.![](https://www.privacyguides.org/content/images/icon/apple-touch-icon-5.png)Mullvad VPN![](https://www.privacyguides.org/content/images/thumbnail/MullvadVPN_logo_Round_RGB_Color_positive.png)](https://mullvad.net/en/browser/browser-fingerprinting) ## Want to know when the next video's out? Don't rely on social media. Get reliable email notifications every time we publish, plus (optionally) follow our newsletter and livestream notifications as well: Subscribe Email sent! Check your inbox to complete your signup. No spam. Unsubscribe anytime. #### Sources 1:10 2:16 2:25 2:33 4:12 4:24 5:38 5:44 7:06 7:20 9:14 9:28 9:38 12:13 12:22 12:37 12:54 13:38 13:51 14:42 15:44 ### We're back... and so is Chat Control 😅 URL: https://www.privacyguides.org/newsletters/2025/09/10/were-back-and-so-is-chat-control/ Last updated: 2025-09-10T20:50:20.000Z 🚨 EU Citizens, you have less than 2 days to take action! The clock is ticking, but we've outlined what you need to do. It just doesn't stop, does it? The European Union has reintroduced **Chat Control** legislation in the form of the Child Sexual Abuse Regulation (CSAR), despite the European human rights court being on the record saying that degrading End-to-End Encryption is illegal and "[cannot be regarded as necessary in a democratic society.](https://www.theregister.com/2024/02/15/echr%5Fbackdoor%5Fencryption/)" Make no mistake, despite the name, CSAR will not protect any children. In fact, **it will place more children at risk**, while eroding the safeguards necessary to keep the internet secure and private. We're talking a lot about this now, because there is a deadline coming up. Countries are expected to finalize their positions on whether they support dismantling the internet's security **this Friday**, so if you are in the EU time is running out to contact your representatives and make sure they know this is unacceptable, especially if your country is poised to support the bill. Our wonderful staff writer [Em](https://www.privacyguides.org/articles/author/em/) published great coverage of this issue earlier this week, outlining what to do if you're an EU resident, and how Chat Control will impact everybody, whether you're in the EU or not: [Chat Control Must Be Stopped, Act Now!Chat Control is back to undermine everyone’s privacy. There’s an important deadline this Friday on September 12th. We must act now to stop it!![](https://www.privacyguides.org/content/images/icon/favicon-32x32.png)Privacy GuidesEm![](https://www.privacyguides.org/content/images/thumbnail/chat-control-must-be-stopped.png)](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/) If you didn't get a chance, take a moment to read it. In the meantime, I'm going to pass this newsletter over to Kevin to share with you some of the other interesting stuff happening in the privacy community we think you should keep an eye on. Stay private! [Jonah](https://www.privacyguides.org/articles/author/jonah/) --- ## This Week in Privacy #17 [Proton is Launching Another Product Already?This Week in Privacy #17![](https://www.privacyguides.org/content/images/icon/pg-yellow-2.png)Privacy GuidesJordan Warne![](https://www.privacyguides.org/content/images/thumbnail/287f5528-2d6e-4a0b-9097-9e5e8190e9aa.jpg)](https://www.privacyguides.org/livestreams/2025/09/05/proton-is-launching-another-product-already/) Last Friday, we launched the 17th episode of This Week in Privacy with the latest privacy and security developments across the world. If you joined us, you may have noticed a new face co-hosting the podcast with Jordan. Our Community & News Intern, Kevin (me!), will regularly take over from Jonah from time to time. While we have encountered some technical difficulties with the audio, the problem has been resolved. Thank you for bearing with us through this issue. If you haven't watched this episode yet, here are the **headlines** we covered: Before we get into those sources though: Human rights like the ****right to privacy** are constantly under attack. We're doing the best we can to spread awareness about this issue, but we need your help. If you've benefited from our guides and programs in any way, consider passing that forward today by sending us a few dollars to support our continued work. [Donate or become a member ](https://donate.magicgrants.org/privacyguides) - [**Proton Meet has quietly launched for Proton Lifetime, Business, and Visionary users in closed beta testing**](https://proton.me/meet)**.** As a browser video conferencing software based on the open-source [Livekit ](https://livekit.io/)framework, Proton Meet has potential to shake up this space. However, we share concerns over whether Proton is expanding its product ecosystem too quickly. - [**Google avoids getting broken up in their anti-trust case but must share search data with competitors**](https://techcrunch.com/2025/09/02/google-avoids-breakup-but-has-to-give-up-exclusive-search-deals-in-antitrust-trial/)**.** Despite holding an illegal monopoly over search engines and browsers, Google has somehow avoided a total breakup by the United States Department of Justice. Ironically, the biggest winners from this decision might be LLM-centered browsers developed by OpenAI and Perplexity – not Brave and DuckDuckGo. - [**Switzerland launches Apertus – an entirely new LLM centered around ethical training data, privacy, and security**](https://www.swiss-ai.org/apertus)**.** While personal testing revealed that Apertus has not reached the same feature parity with mainstream alternatives like ChatGPT and Claude, Apertus is supposedly trained with opt-out signals in mind. We discuss whether private LLMs like Apertus can be "ethical" in the first place. - [**Venezuelan President Nicholas Maduro claims that Huawei Phones are unhackable, especially by "American spy planes" and "satellites"**](https://techcrunch.com/2025/09/03/venezuelas-president-thinks-american-spies-cant-hack-huawei-phones/)**.** Willful ignorance aside, President Maduro is not *entirely* wrong about this. As a regular, non-government consumer, you should never listen to his digital security advice though. Please do not buy a Huawei phone. I beg you. --- ## “We \[Don't\] Care About Your Privacy” [“We \[Don’t\] Care About Your Privacy”Being able to distinguish facts from marketing lies is an essential skill in today’s world. Despite all the privacy washing, there are clues we can look for to help.![](https://www.privacyguides.org/content/images/icon/favicon-32x32-1.png)Privacy GuidesEm![](https://www.privacyguides.org/content/images/thumbnail/red-and-green-privacy-flags.png)](https://www.privacyguides.org/articles/2025/09/03/red-and-green-privacy-flags/) Confused about the constant mention of privacy in marketing campaigns? What does it mean when a company mentions a flashy term like "military-grade encryption" on their advertisements? Our staff writer, Em, has written an amazing article on "privacy washing" and how it can harm real people out there trying to find solutions that work for them. Don't fall for the trap. Make sure to do your research before committing to a product or service. If you have questions, reach out to our[ community forum](https://discuss.privacyguides.net/) and ask them there! There are folks always willing to help out. Confidentially yours, [Kevin](https://www.privacyguides.org/articles/author/kevpham/) ## Want to stay informed? We'll be putting out emails like this regularly from now on, as well as (optional) notifications about new videos and episodes of This Week in Privacy. Subscribe Email sent! Check your inbox to complete your signup. Fully configurable, no spam. Unsubscribe anytime. ### Chat Control Must Be Stopped, Act Now! URL: https://www.privacyguides.org/posts/2025/09/08/chat-control-must-be-stopped/ Last updated: 2025-09-16T16:32:50.000Z If you've heard of [Chat Control](https://www.privacyguides.org/articles/2025/02/03/the-future-of-privacy/) already, bad news: **it's back**. If you haven't, this is a pressing issue you should urgently learn more about if you value privacy, democracy, and human rights. This is happening **right now**, and **we must act to stop it right now**. Take a minute to visualize this: Every morning you wake up with a police officer entering your home to inspect it, and staying with you all day long. The agent checks your bathroom, your medicine cabinet, your bedroom, your closets, your drawers, your fridge, and takes photos and notes to document everything. Then, this report is uploaded to the police's cloud. It's "[for a good cause](https://www.privacyguides.org/articles/2025/04/11/encryption-is-not-a-crime/)" you know, it's to make sure you aren't hiding any child sexual abuse material under your bed. Every morning. Even if you're naked in bed. Even while you're having a call with your doctor or your lover. Even when you're on a date. Even while you're working and discussing your client's confidential information with their attorney. This police officer is there, listening to you and reporting on everything you do. This is the in-person equivalent of Chat Control, a piece of legislation that would mandate **all** services to scan **all** private digital communications of **everyone** residing in the European Union. This is an Orwellian nightmare. ## Act now! This is happening **right now**. European governments will be finalizing their positions on the regulation proposal on September 12th, and there will be a final vote on **October 14th, 2025**. Important: If you are reading this article after September 12th Regardless of the outcome on September 12th, the fight isn't over. The next deadline will be the **final vote on October 14th, 2025**. If you've missed September 12th, make sure to contact your representatives **right now** to tell them to **oppose Chat Control** on October 14th. - If you are not located in Europe: Keep reading, this will affect you too. - If you are still unconvinced: Keep reading, we discuss Chat Control in [more details](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/#why-is-this-bad) below. - If you are located in Europe: You must **act now** to stop it. Use this [**website**](https://fightchatcontrol.eu/) to easily contact your government representatives, and tell them they should **oppose Chat Control**. Even if your country already opposes Chat Control, contact your representatives to tell them you are relieved they oppose, and support them in this decision to protect human rights. This will help reinforce their position. But if your country *supports* Chat Control, or is *undecided*, **it is vital that you contact your representatives as soon as possible**. To support your point, you can share this article with them or one of the many great [resources](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/#resources-to-learn-more-and-fight-for-human-rights) listed at the end. ![](https://www.privacyguides.org/content/images/2025/09/image.png) Image: Patrick Breyer / [chatcontrol.eu](https://www.chatcontrol.eu) ## What is Chat Control? "Chat Control" refers to a series of legislative proposals that would make it mandatory for *all* service providers (text messaging, email, social media, cloud storage, hosting services, etc.) to scan *all* communications and *all* files (including end-to-end encrypted ones), in order to supposedly detect whatever the government deems "abusive material." The push for Chat Control started in 2021 with the approval of a [derogation](https://www.patrick-breyer.de/en/chatcontrol-european-parliament-approves-mass-surveillance-of-private-communications/) to the ePrivacy Directive by the European Parliament. This derogation escalated to a second proposal for *mandatory* scanning a year later, which was [rejected](https://fortune.com/europe/2023/10/26/eu-chat-control-csam-encryption-privacy-european-commission-parliament-johansson-breyer-zarzalejos-ernst/) in 2023\. Nevertheless, lawmakers and lobbyists determined to undermine our safety and civil liberties are bringing it back again two years later, **literally trying to wear you down**. We cannot let authoritarians wear us down until we lose all our privacy rights. Our privacy rights are fundamental to so many other human rights, to civil liberties, to public safety, and to functioning democracies. Chat Control undermines all of this. Cryptography professor and cybersecurity expert Matthew Green described the 2022 proposal document for Chat Control as "[**the most terrifying thing I've ever seen**](https://fortune.com/2022/05/12/europe-phone-surveillance-crackdown-child-sexual-abuse-material-sparks-outrage-among-cybersecurity-experts-privacy-activists/)". And terrifying, it is. The [most recent proposal for Chat Control](https://tuta.com/blog/chat-control-criticism) comes from the EU Council Danish presidency pushing for regulation misleadingly called the **Child Sexual Abuse Regulation** (CSAR). Despite its seemingly caring name, this regulation will **not** help fight child abuse, and will even likely worsen it, impacting negatively what is already being done to fight child abuse (more on this in the [next section](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/#would-this-protect-the-children)). The CSAR proposal (which *is* the latest iteration of Chat Control) could be implemented as early as *next month*, if we do not stop it. **The problem is this: Chat Control will not work, it is unreliable, it will escalate in scope, and it will endanger everyone (including the children).** Even if you are not in Europe, know that Chat Control will affect everyone inside *and* outside of Europe one way or another. Regardless of where you are, you should be concerned and pay attention, and there are things you can do to fight back. This is important. ![](https://www.privacyguides.org/content/images/2025/09/image-1.png) Still image from [video](https://stopscanningme.eu/video/csar-explainer.mp4): Stop Scanning Me / EDRi ## Why is this bad? The idea that it's possible to somehow [magically protect](https://www.privacyguides.org/articles/2025/04/11/encryption-is-not-a-crime/#magical-backdoor-only-for-the-good-guys-is-a-complete-fantasy) information properly while giving access to unquestionably well-intended law enforcement comes from either extreme naivety, lack of information, and plain dishonesty. This proposal would effectively break any end-to-end encryption protections, and potentially expose all your files and communications to not only law enforcement, but eventually also to criminals of all sorts (with the data breaches, data leaks, and corruption that will inevitably follow). Here's a summary of some dangers this regulation would create if approved: - **Breaking end-to-end encryption**: Removing crucial protections for all sensitive files and communications of vulnerable populations, victims, whistleblowers, journalists, activists, and everyone else. - **Mission creep**: Once this mass surveillance system is in place, authorities can decide to add more criteria such as searching all communications for references to drug use, protest attendances, political dissidence, or even [negative comments](https://www.lemonde.fr/en/international/article/2025/03/22/how-a-french-researcher-being-refused-entry-to-the-us-turned-into-a-diplomatic-mess%5F6739415%5F4.html) about a leader. Europol (the EU law enforcement agency) has already called for [expanding the program](https://www.youtube.com/watch?v=L933xDcSS3o&t=2016s). ![](https://www.privacyguides.org/content/images/2025/09/image-2.png) Image: Lorna Schütte / [chatcontrol.eu](https://www.chatcontrol.eu) - **Criminal attacks**: Each time a backdoor exists, it doesn't take long for criminals to find access and steal our information. This could include criminals finding access to each service independently or to the entire database authorities would keep. A database that would be filled with material tagged as sexually explicit text or photos of children. This could even *create* new Child Sexual Abuse Material (CSAM) for criminals. For example, consenting teenagers innocently sexting together could have their photos collected in this database, after being wrongly flagged by the automated system. Then, criminals could steal their intimate photos from the governments. - **False positives**: With a mass surveillance system this large, moreover a system with no transparency and little oversight, false positives are inevitable. Despite marketing promises from the [organizations lobbying government officials](https://www.patrick-breyer.de/en/chat-control-eu-ombudsman-criticises-revolving-door-between-europol-and-chat-control-tech-lobbyist-thorn/), we all know AI technologies regularly misfire and cannot be reliable for anything of such importance. Loving parents could get flagged as pedophiles just for innocently uploading a photo of their child in the bathtub on their *private* cloud. Teenagers exploring their sexuality consensually with each other could get tagged as sexual predators (a label that might stick on them decades later). The police could receive reports for breastfeeding mothers. The list is infinite. ![](https://www.privacyguides.org/content/images/2025/09/image-3.png) Image: Lorna Schütte / [chatcontrol.eu](https://www.chatcontrol.eu) - **Overwhelming resources**: The inevitable false positives will completely overwhelm the agencies responsible for investigating flagged material. This will cost them precious time they will not have to investigate *actual* abuse cases. Organizations fighting child sexual abuse are already overwhelmed and lack resources to prosecute real criminals. - **Hurting victims**: Such system of mass surveillance could prevent victims of child sexual abuse (and other crimes) to reach out for help. Knowing that all their communications would be scanned, they would lose all confidentiality while reporting crimes. The evidences they share could even be tagged by Chat Control, as if they were the perpetrator rather than the victim. Sadly, many will likely decide it's safer not to report at all. - **Self-censorship**: With Chat Control in place, not only victims might censor themselves and stop reaching out for help, but everyone else as well. When people know they are being observed, they feel less free to be themselves and to share openly. This is doubly true for anyone who is part of a marginalized group, such as [LGBTQ+ people](https://www.privacyguides.org/articles/2025/06/03/importance-of-privacy-for-the-queer-community/), or anyone who is being victimized or at risk of victimization. ![](https://www.privacyguides.org/content/images/2025/09/image-4.png) Image: Lorna Schütte / [chatcontrol.eu](https://www.chatcontrol.eu) - **Undermining democracy**: This surveillance system would allow governments to spy on opposition. Chat logs from opposing candidates, activists, and journalists could all be accessed by authorities in order to silence opponents or blackmail candidates. Even if you trust your government to not do this now, this doesn't mean it could not be used in this way by the next government. We have all seen how fast the political landscape can change. - **Violating the GDPR (and other laws)**: The General Data Protection Regulation (GDPR) offers wonderful protections to Europeans. Sadly, Chat Control would make a complete farce of it. The Right to Erasure (right to delete) could be reduced to ashes by Chat Control, including for any highly sensitive information wrongly caught in the CSAR net. Moreover, it would [violate Article 7 and Article 8](https://tuta.com/blog/chat-control-criticism) of the EU Charter of Fundamental Rights. Protecting the children is only the excuse used in hope of convincing a misinformed public. **Chat Control is authoritarian mass surveillance.** Authorities understand well how important protecting communication and information is. This is why they included an exemption to protect *their own* communications, but not yours. ## Would this protect the children? No. This cannot be stressed enough: **This regulation would not protect the children, it would *harm* the children**, and everyone else too, worldwide. Claiming otherwise is either naivety, or misinformation. Last year, the civil and human rights association European Digital Rights (EDRi) put together a [joint statement from 48 organizations](https://edri.org/our-work/joint-statement-on-the-future-of-the-csa-regulation/) for children's protection, digital rights, and human rights, demanding that the European Parliament invest instead in proven strategies to fight child abuse. This appeal to reason does not seem to have been heard by most EU Member States. There are many things we can do as a society to increase protections for children and fight abusers and criminals, but Chat Control is far from it all. Protection of the children is clearly only an excuse here, and a very misleading one. ![](https://www.privacyguides.org/content/images/2025/09/image-5.png) [Image](https://stopscanningme.eu/en/organise-now.html): Stop Scanning Me / EDRi ### Mislabelling children as criminals First, this automated system is flawed in many ways, and the false-positive rate would likely be high. But let's imagine that, magically, the system could flag CSAM at an accuracy rate of 99%. This still means 1% of reports would be false. Expanded to the size of European Union's population of approximately 450 million people, exchanging likely billions of messages and files every day, this still means millions could be falsely tagged as sexual predators, with all the [consequences](https://www.republik.ch/2022/12/08/die-dunklen-schatten-der-chatkontrolle) this implies. Worse, the Swiss federal police reported that currently about 80% of all automated reports received were [false-positives](https://www.patrick-breyer.de/en/posts/chat-control/#WhatYouCanDo). This means in reality, the error rate is likely far higher than 1%, and actually closer to an **80% error rate**. Of the approximate 20% of positive reports, in Germany, over 40% of investigations initiated [targeted children](https://www.polizei-beratung.de/aktuelles/detailansicht/straftat-verbreitung-kinderpornografie-pks-2022/) themselves. Sometimes, flagged content is simply teenagers innocently sexting each other consensually. Not only would they be wrongly tagged as criminals under Chat Control, but they'd be triggering an investigation that would expose their intimate photos to some faceless officers or tech employees working on the system. Even in a magical world where Chat Control AI is 99% accurate, it would still wrongly tag and **expose sensitive data from millions of children**. In reality, no AI system is even remotely close to this accuracy level, and proprietary algorithms are usually opaque black boxes impossible to audit transparently. The number of children Chat Control would harm, and likely traumatize for life, would be disastrous. ### Exposing children's sensitive and sexual information Any content that could be deemed suspicious or explicit by the system, accurately or not, would be flagged and reported. When this content is reported, it will likely be uploaded to a database for human review. This means that if a teenager was sending an intimate photo of themselves to another consenting teenager, they could be flagged as sharing CSAM, even if it's their own photo. Then, their photo would be sent to the police for review. Information that should very much have stayed protected and private between these two teenagers is now exposed to strangers. This is wrong, and dangerous. Even innocuous communications such as daily conversations, teenagers chatting with each other, parents reporting information about their child to a [doctor](https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html), and therapists talking with their patients, could all inadvertently expose children sensitive information. This is information that should have remained *private*, and would now be uploaded to a police database, likely [stored there forever](https://www.iccl.ie/news/an-garda-siochana-unlawfully-retains-files-on-innocent-people-who-it-has-already-cleared-of-producing-or-sharing-of-child-sex-abuse-material/) with few recourses to remove it. The more we collect sensitive information about children (photos, faces, locations, identifications, medical information, private chats, experiences, etc.), the more we risk exposing children to harm. This includes systems used by authorities and governments. Even if everyone with legitimate access to this data is miraculously 100% exemplary and incorruptible citizens, the databases and scanning systems will still be vulnerable to attacks from criminals and hostile governments alike. The only way to protect children's information properly is to **1) not collect it**, and **2) use end-to-end encryption to protect it** when we cannot avoid collecting it. Spying on everyone and every child is the opposite of that. ### Authorities' databases will be attacked It's impossible to perfectly secure information online. There is a lot we can do to improve security (much more than is done now), but data breaches will happen. If governments mandate a backdoor to have access to all our online communication and stored files, it's inevitable that at least some criminals will eventually get access to it as well. This is even truer if this system is closed-source, [privatized](https://fortune.com/europe/2023/09/26/thorn-ashton-kutcher-ylva-johansson-csam-csa-regulation-european-commission-encryption-privacy-surveillance/), and isn't subjected to frequent independent audits with strong accountability. Once a vulnerability is found by criminals, they will have the same access as authorities have to our data. With Chat Control, this means pretty much all our data. In addition, Chat Control could facilitate the proliferation of even more spyware and [stalkerware](https://stopstalkerware.org/) on the market, thriving on the vulnerabilities found in the powerful system. This would allow *anyone* to purchase access to spy on *anyone*, including databases of identified children. It could give a direct backdoor-access to pedophiles. How could *this* be helping to protect the children? ### The danger is inside Even if the idea of online strangers accessing children's sensitive data is terrifying, the worse danger in often much closer. Sadly, we already know that the [vast majority](https://content.c3p.ca/pdfs/C3P%5FSurvivorsSurveyFullReport2017.pdf) of child sexual abuse is perpetrated by adults close to the child, not strangers, and that two-thirds of CSAM images appear to have been [produced at home](https://theconversation.com/new-research-shows-parents-are-major-producers-of-child-sexual-abuse-material-153722). Chat Control would do nothing to fight this. In fact, it could facilitate it. Child abuse is an incredibly important topic to discuss and to fight against as a society. Utilizing this issue as an excuse to pass a surveillance law that would endanger everyone, including the victims, is despicable. When children are living with the abuser, the only escape is outside the home, and sometimes this means *online*. Abusers often use spying technologies to control and restrict access to help for their victims. If we make mass surveillance mandatory and normalized, this risks aggravating the stalkerware problem by obligating providers to implement backdoors in their systems. We would effectively be helping abusers at home to restrict access to help for their victims, including victims of CSAM. This is completely unacceptable. ### How to actually help the children Despite the politicization of this issue to manipulate the public opinion in accepting mass surveillance, there are actually *proven* solutions to help to protect the children, online and offline. First, governments should [listen](https://mogis.info/static/media/uploads/eu-libe-mogis-hahne-07032023%5Fen.pdf) to [organizations already doing the work](https://edri.org/our-work/most-criticised-eu-law-of-all-time/). Most are understaffed and under-resourced to properly support the victims and prosecute the criminals. Thousands of more reports every day would not help them do any effective work. More capacity to conduct *targeted* investigation and arrest criminals, and more capacity to create safe spaces to support the victims and witnesses will help. Privacy should be the default, for everyone. If all our services were using end-to-end encryption when possible, and implemented proper security and privacy features and practices, this would effectively help to protect the children as well. Abusers and criminals are looking for leaked and stolen data all the time. When a cloud photo storage gets hacked, your photos are up for grabs online, including the photos of your children. When parents upload photos of their children and their address online, and this data gets exposed (leaked, breached, AI-scraped, etc.), this data then becomes accessible to criminals. **Better privacy protections also means better protections for the children.** Children themselves should receive better education on how their data is used online and how to protect it. Additionally, it is vital to provide better education on what behaviors aren't normal coming from an adult, and how to reach out for help when it happens. Children should have access to safe and confidential resources to report abuse, whether it's happening outside or inside their home. Parents should be careful when sharing information about their children. And when they have to, they should benefit from complete confidentiality, knowing their communication is fully end-to-end encrypted and not shared with anyone else. There is so much we can do to help to protect better the children online, surveillance is the opposite of it all. ## How would this affect me? If this regulation is approved on **October 14th, 2025** (the date for the final vote), the consequences would be devastating for everyone, even outside the European Union. We have seen how platforms implemented better privacy practices and features after the GDPR became effective in 2018, features that often benefited people worldwide. This could have the same effect in reverse. Every platform potentially handling data of people located in the EU would be subjected to the law. Platforms would be obligated to scan all communications and all files of (at least) data subjects located in the EU, even data currently protected with end-to-end encryption. This would affect popular apps and services like Signal, Tuta, Proton, WhatsApp, Telegram, and much more. ### Outside of Europe This would not only affect Europeans' data, but also the data of anyone outside communicating with someone located in the European Union. Because end-to-end encryption can only work if **both** ends are protected. If Chat Control gets approved and applied, it will become very difficult to communicate with anyone located in the EU while keeping strong protections for your data. Many people might just accept the surveillance passively, and as a result lose their rights, their protections, and compromise their democratic processes. Overtime, this will likely lead to a slippery slope towards dystopian authoritarianism. Outside of Europe, you could expect to see services removing some privacy-protective features, downgrading encryption, blocking European countries that are subjected to the law, or moving outside of Europe entirely. If localization-based scanning is too complicated to handle for an application, some companies might just decide it's simpler to scan communications for all users, worldwide. Additionally, Five Eyes countries (Australia, Canada, New Zealand, the United Kingdom, and the United States) have already [expressed support](https://www.youtube.com/watch?v=L933xDcSS3o&t=2163s) for Chat Control, and might be keen to try the same at home, if this gets approved and tested in Europe first. ### Inside of Europe Without using tools that would be now deemed illegal, you would lose any protections currently granted by end-to-end encryption. It would become impossible for you to send an email, a text message, or a photo without being observed by your government, and potentially also by criminals and foreign governments, following the inevitable data breaches. You would have to constantly self-censor to avoid triggering the system and getting reported to the authorities. At first, you would probably just have to stop sending nudes, sexting, or sending photos of naked children in the bathtub or playing at the beach. Then, this would escalate to never mentioning drug or anything that could sound like drug, even as a joke. Later, you might have to stop texting about going to a protest, and stop organizing protests online. Further down the line, you might even have to self-censor to make sure you are not saying anything negative about a leader, or a [foreign politician](https://www.reuters.com/world/us/trump-administration-resuming-student-visa-appointments-state-dept-official-says-2025-06-18/) even. This isn't that hypothetical, this sort of [oppressive surveillance](https://www.hrw.org/news/2017/11/19/china-police-big-data-systems-violate-privacy-target-dissent) already exists in some countries. Many services you currently rely on right now would simply shut down, or move away from Europe entirely. Businesses might also move outside of Europe if they worry about protecting their proprietary information. This could cause massive layoffs, while organizations move to jurisdictions where they are allowed to keep their data protected and unobserved. Finally, even if this doesn't affect you personally, or you don't believe it will, [**this isn't just about you**](https://www.privacyguides.org/articles/2025/03/10/the-privacy-of-others/). The data of vulnerable people would be exposed and their safety put at risk. Victims might decide to stop reaching out for help or reporting crimes. Sources requiring anonymity might decide the risk isn't worth reporting valuable information to journalists. Opponents of governments in power could be silenced. Every democracy in the European Union would suffer greatly from it. Chat Control is completely antithetical to the values the European Union has been presenting to the world in recent years. ![](https://www.privacyguides.org/content/images/2025/09/image-6.png) [Image](https://stopscanningme.eu/en/organise-now.html): Stop Scanning Me / EDRi ## What can I do about it? Even if the landscape seems dismal, **the battle isn't over**. There are many things you can do, right now, to fight against this authoritarian dystopia. ### For Europeans, specifically - Contact your country representatives **TODAY**. The group Fight Chat Control has put together an [**easy tool**](https://fightchatcontrol.eu/#contact-tool) making this quick with only a few clicks. - After September 12th, the battle isn't over. Although governments will finalize their positions on that day, the final vote happens on **October 14th, 2025**. If you missed the September 12th deadline, keep contacting your representatives anyway. - Tell your family and friends to contact their representatives as well, talk about it, make noise. ### For Everyone, including Europeans - Talk about Chat Control on social media often, especially this month. Make noise online. Use the hashtags #ChatControl and #StopScanningMe to help others learn more about the opposition movement. - Share informative [videos and memes](https://www.privacyguides.org/articles/2025/09/08/chat-control-must-be-stopped/#resources-to-learn-more-and-fight-for-human-rights) about Chat Control. Spread the word in various forms. - Contact your European friends in impacted countries and tell them to contact their representatives NOW. - Even outside the EU, you can contact your own representatives as well, to let them know regulations like Chat Control are horrible for human rights, and you hope your country will never fall for such repressive laws. Tell your political representatives that privacy rights are important to you. **Your voice matters.** We need your help to fight this. For democracy, for privacy, and for all other human rights, we cannot afford to lose this battle. ![](https://www.privacyguides.org/content/images/2025/09/image-7.png) Screenshot: [fightchatcontrol.eu](https://fightchatcontrol.eu/) ## Resources to learn more, and fight for human rights ### Videos about Chat Control - [**Stop Scanning Me**: Short video that summarizes perfectly the issues with Chat Control](https://stopscanningme.eu/video/csar-explainer.mp4) - [**Stop Scanning Me**: German-language version of the same short video](https://www.patrick-breyer.de/posts/chat-control/) - [**Louis Rossmann**: Video discussing why privacy matters, and the impact of Chat Control from a perspective outside of Europe](https://www.youtube.com/watch?v=3NyUgv6dpJc) - [**Shaping Opinion**: Excellent interview with Chat Control expert Patrick Breyer (recommended)](https://www.youtube.com/watch?v=L933xDcSS3o) - [**Patrick Breyer**: PeerTube channel with numerous videos related to Chat Control (German & English)](https://peertube.european-pirates.eu/c/patrick%5Fbreyer%5Fmep%5Fchannel) ### Memes about Chat Control - [**Stop Scanning Me**: Memes, banners, and other graphics](https://stopscanningme.eu/en/organise-now.html) - [**Patrick Breyer**: Memes, explainers, maps, and other graphics](https://www.patrick-breyer.de/posts/chat-control/#WhatYouCanDo) ### Websites with more information - [**Fight Chat Control** (Contact your representatives here **TODAY**!)](https://fightchatcontrol.eu/) - [**Stop Scanning Me** (from EDRi)](https://stopscanningme.eu) - [**Patrick Breyer** (expert and former Member of the European Parliament)](https://www.patrick-breyer.de/posts/chat-control/) - [**European Crypto Initiative**](https://eu.ci/eu-chat-control-regulation/) - [Follow **Fight Chat Control** on Mastodon for updates](https://mastodon.social/@chatcontrol) --- **Update (9/15):** Added modifications related to the second important deadline for action, on October 14th. **Update (9/8):** Added clarification about what Chat Control is for readers unfamiliar with it. ### Proton is Launching Another Product Already? URL: https://www.privacyguides.org/livestreams/2025/09/05/proton-is-launching-another-product-already/ Last updated: 2026-07-24T18:45:32.000Z This Week in Privacy #17 _This post is for subscribers only._ ### “We [Don't] Care About Your Privacy” URL: https://www.privacyguides.org/posts/2025/09/03/we-dont-care-about-your-privacy/ Last updated: 2025-09-21T05:47:33.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/09/03/red-and-green-privacy-flags/) ### Could This Be the End of Android Sideloading? URL: https://www.privacyguides.org/livestreams/2025/08/29/could-this-be-the-end-of-android-sideloading/ Last updated: 2026-07-24T18:45:40.000Z This Week in Privacy #16 _This post is for subscribers only._ ### Privacy is Power. And You're Giving Yours Away. URL: https://www.privacyguides.org/videos/2025/08/29/privacy-is-power/ Last updated: 2025-09-10T16:30:42.000Z [Watch on YouTube](https://www.youtube.com/watch?v=fPYsIJeN5WE) #### Sources - 0:01 - 0:03 - 0:05 - 1:53 - 2:07 - 2:18 - 2:22 - 2:25 - 2:28 - 2:39 - 3:07 - 3:41 - 3:55 - 3:56 - 3:57 - 3:59 - 4:01 - 4:02 - 4:04 ### Clickjacking: A Major Password Manager Flaw? URL: https://www.privacyguides.org/livestreams/2025/08/22/clickjacking-a-major-password-manager-flaw/ Last updated: 2026-07-24T18:45:49.000Z This Week in Privacy #15 _This post is for subscribers only._ ### Privacy Washing Is a Dirty Business URL: https://www.privacyguides.org/posts/2025/08/20/privacy-washing-is-a-dirty-business-2/ Last updated: 2025-08-20T17:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/08/20/privacy-washing-is-a-dirty-business/) ### Age Verification is a Privacy Nightmare... URL: https://www.privacyguides.org/videos/2025/08/15/age-verification-is-a-privacy-nightmare/ Last updated: 2025-09-10T05:52:45.000Z ## Sources - 0:05 - 0:08 - 0:11: - 0:19 - 0:46 - 0:57 - 1:16 - 1:34 - 1:46 - 1:46 - 2:11 - 2:28 - 3:08 - 3:20 - 3:27 - 3:30 - 3:33 - 3:56 - 4:09 - 4:26 - 4:27 - 4:28 - 4:36 - 4:42 - 4:51 - 4:53 - 5:22 - 5:54 - 6:08 - 6:16 - 6:18 - 6:20 - 6:34 - 6:50 - 6:56 - 7:36 - 7:37 - 7:43 - 7:48 - 8:00 - 8:12 - 8:33 - 8:42 - 8:50 - 8:52 - 8:55 - 9:33 - 10:03 ### Is YouTube's New AI Judging What You Watch? URL: https://www.privacyguides.org/livestreams/2025/08/15/is-youtubes-new-ai-judging-what-you-watch/ Last updated: 2026-07-24T18:45:59.000Z This Week in Privacy #14 _This post is for subscribers only._ ### CalyxOS Falters - What's Next for Custom Android? URL: https://www.privacyguides.org/livestreams/2025/08/08/calyxos-falters-whats-next-for-custom-android/ Last updated: 2026-07-24T18:46:06.000Z This Week in Privacy #13 _This post is for subscribers only._ ### ID Verification - A Major Threat to Privacy URL: https://www.privacyguides.org/livestreams/2025/08/01/id-verification-a-major-threat-to-privacy/ Last updated: 2026-07-24T18:46:14.000Z This Week in Privacy #12 _This post is for subscribers only._ ### Proton Released A New Privacy Product? URL: https://www.privacyguides.org/livestreams/2025/07/25/proton-released-a-new-privacy-product/ Last updated: 2026-07-24T18:46:24.000Z This Week in Privacy #11 _This post is for subscribers only._ ### Secureblue: Is This the Most Secure Linux Distro? URL: https://www.privacyguides.org/videos/2025/07/25/secureblue-review/ Last updated: 2025-09-10T02:07:06.000Z _No content available._ ### Privacy Is Like Broccoli URL: https://www.privacyguides.org/posts/2025/07/24/privacy-is-like-broccoli-2/ Last updated: 2025-07-24T18:20:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/07/24/privacy-is-like-broccoli/) ### How To Improve Your Privacy and Security on Mastodon URL: https://www.privacyguides.org/posts/2025/07/22/how-to-improve-your-privacy-and-security-on-mastodon-2/ Last updated: 2025-07-22T20:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/07/22/mastodon-tutorial-privacy-and-security/) ### ChromeOS & Android Are Merging? URL: https://www.privacyguides.org/livestreams/2025/07/18/chromeos-android-are-merging/ Last updated: 2026-07-24T18:46:32.000Z This Week in Privacy #10 _This post is for subscribers only._ ### Privacy and Security on Mastodon URL: https://www.privacyguides.org/posts/2025/07/15/privacy-and-security-on-mastodon-2/ Last updated: 2025-07-22T20:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/07/15/mastodon-privacy-and-security/) ### The End of Anonymous Search? URL: https://www.privacyguides.org/livestreams/2025/07/11/the-end-of-anonymous-search/ Last updated: 2026-07-24T18:46:40.000Z This Week in Privacy #9 _This post is for subscribers only._ ### How the NSA Tried to Backdoor Every Phone URL: https://www.privacyguides.org/videos/2025/07/03/clipper-chip/ Last updated: 2025-09-10T02:07:49.000Z This is the second part of our series on the Crypto Wars, a monumental moment in history that shaped digital privacy forever. ## Sources 0:38 0:52 0:58 1:02 1:06 1:15 3:43 3:46 4:00 4:07 4:27 5:18 5:49 6:27 7:14 7:15 7:35 7:37 ### Queer Dating Apps: Beware Who You Trust With Your Intimate Data URL: https://www.privacyguides.org/posts/2025/06/24/queer-dating-apps-beware-who-you-trust-with-your-intimate-data-2/ Last updated: 2025-06-24T21:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/06/24/queer-dating-apps-beware-who-you-trust/) ### You Can Say NO URL: https://www.privacyguides.org/posts/2025/06/17/you-can-say-no/ Last updated: 2025-06-17T18:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/06/17/you-can-say-no/) ### Creating a Tricked-Out Monero Server with TrueNAS URL: https://www.privacyguides.org/posts/2025/06/12/creating-a-tricked-out-monero-server-with-truenas/ Last updated: 2025-06-12T18:15:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/06/12/monero-server-using-truenas/) ### Stay Safe, but Stay Connected URL: https://www.privacyguides.org/posts/2025/06/10/stay-safe-but-stay-connected/ Last updated: 2025-06-10T17:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/06/10/stay-safe-but-stay-connected/) ### Selling Surveillance as Convenience URL: https://www.privacyguides.org/posts/2025/06/07/selling-surveillance-as-convenience/ Last updated: 2025-06-07T17:35:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/06/07/selling-surveillance-as-convenience/) ### Compartmentalize Your Life (and Your Privacy) URL: https://www.privacyguides.org/videos/2025/06/05/compartmentalize-your-life/ Last updated: 2025-09-10T02:09:09.000Z ## Sources - - - ## Additional resources ### Helplines - [Mindline Trans+ (UK)](https://www.mindinsomerset.org.uk/our-services/adult-one-to-one-support/mindline-trans/): A confidential emotional, mental health support helpline for people who identify as Trans, Agender, Gender Fluid or Non-Binary. - [Trans Lifeline Hotline (US and Canada)](https://translifeline.org/hotline/): Trans peer support over the phone. - [Suicide & Crisis Helpline (US and Canada)](https://988lifeline.org/): General support 24/7 phone number 988. - [Suicide & Crisis Helpline (International)](https://en.wikipedia.org/wiki/List%5Fof%5Fsuicide%5Fcrisis%5Flines): List of suicide crisis lines around the world. ### Supportive organizations - [Egale (Canada, International)](https://egale.ca/asylum/): Resources for LGBTQ+ asylum and immigration requests from outside and inside Canada. - [SOS Homophobie (France)](https://www.sos-homophobie.org/international-content): Non-profit, volunteer-run organization committed to combatting hate-motivated violence and discrimination against LGBTI people. - [The Trevor Project (US)](https://www.thetrevorproject.org/): Suicide prevention and crisis intervention non-profit organization for LGBTQ+ young people. - [Trans Rescue (International)](https://transrescue.org/): Organization assisting trans and queer individuals in relocating from dangerous areas to safer places. - [Twenty10 (Australia)](https://twenty10.org.au/): Sydney-based organization providing a broad range of free support programs to the LGBTIQA+ community. ### International advocacy - [Amnesty International](https://www.amnesty.org/en/what-we-do/discrimination/lgbti-rights/): Human rights organization running campaigns to protect and uphold the rights of LGBTI people globally. - [Human Rights Watch](https://www.hrw.org/topic/lgbt-rights): Human rights non-profit who documents and exposes abuses based on sexual orientation and gender identity worldwide, and advocate for better protective laws and policies. ### The Importance of Data Privacy For The Queer Community URL: https://www.privacyguides.org/posts/2025/06/03/the-importance-of-data-privacy-for-the-queer-community/ Last updated: 2025-06-03T17:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/06/03/importance-of-privacy-for-the-queer-community/) ### Recall Is Back, But You Still Shouldn’t Use It URL: https://www.privacyguides.org/videos/2025/05/22/recall-is-back/ Last updated: 2025-09-10T02:10:46.000Z ## Sources - Introducing Copilot+ PC's Full Keynote - Microsoft: - Introducing Windows 11 - Microsoft: - Introducing Copilot - Microsoft: - Introducing a new Copilot key for Windows 11 PCs - Microsoft: ### The Power of Digital Provenance in the Age of AI URL: https://www.privacyguides.org/posts/2025/05/19/the-power-of-digital-provenance-in-the-age-of-ai/ Last updated: 2025-05-19T20:15:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/05/19/digital-provenance/) ### Your Online Life Is IRL URL: https://www.privacyguides.org/posts/2025/05/16/your-online-life-is-irl/ Last updated: 2025-05-16T16:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/05/16/your-online-life-is-irl/) ### KeePassium Review: A Flexible Password Manager for iOS and macOS URL: https://www.privacyguides.org/posts/2025/05/13/keepassium-review-a-flexible-password-manager-for-ios-and-macos/ Last updated: 2025-05-13T16:30:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/05/13/keepassium-review/) ### Sam Altman Wants Your Eyeball URL: https://www.privacyguides.org/posts/2025/05/10/sam-altman-wants-your-eyeball/ Last updated: 2025-05-10T15:45:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/05/10/sam-altman-wants-your-eyeball/) ### When Code Became a Weapon URL: https://www.privacyguides.org/videos/2025/05/08/when-code-became-a-weapon/ Last updated: 2025-09-10T02:22:17.000Z In this video we'll dive into the history and explain what happened to cause this and why it was eventually overturned. The ability to use strong encryption wasn’t a given; it has been continually fought for throughout history. ## Sources - - - - - - [158,962,555,217,826,360,000 (Enigma Machine) - Numberphile](https://www.youtube.com/watch?v=G2%5FQ9FoD-oQ&pp=ygUSbnVtYmVycGhpbGUgZW5pZ21h) - [Enigma Code](https://www.youtube.com/watch?v=LU2s28-tN08&pp=ygUbZW5pZ21hIG1hY2hpbmUgZGlzY292ZXJ5IHVr) - [Our History](https://www.youtube.com/watch?v=tIDb-rVvHgQ&pp=ygUSb3VyIGhpc3RvcnkgbnNhIHl0) - [The cold war, Checkpoint Charlie](https://www.youtube.com/watch?v=-pUmfKX3C04&pp=ygUSY2hlY2twb2ludCBjaGFybGll) - [Ordinary Life in the USSR 1961](https://www.youtube.com/watch?v=ExHCAjRsZhA&pp=ygUYbGlmZSBpbiB0aGUgdXNzciBmb290YWdl) - [USA: WASHINGTON: ANTI-NUCLEAR PROTESTS](https://www.youtube.com/watch?v=3SbC3EHS04I&pp=ygUZYW50aSBudWtlIHByb3Rlc3QgMTk5MCBhcNIHCQmGCQGHKiGM7w%3D%3D) - [DEF CON 11 - Phil Zimmerman - A Conversation with Phil Zimmermann](https://www.youtube.com/watch?v=4ww8AAkWFhM&pp=ygUTcGhpbCB6aW1tZXJtYW5uIHBncA%3D%3D) - [The Screen Savers - Phil Zimmerman, creator of Pretty Good Privacy (PGP) Interview](https://www.youtube.com/watch?v=cZD36L3BXXs&pp=ygUdcGhpbCB6aW1tZXJtYW5uIHNjcmVlbiBzYXZlcnM%3D) - [Creator of PGP, Phil Zimmermann Talks At Bitcoin Wednesday](https://www.youtube.com/watch?v=M8z0Nx8svC4&pp=ygUXcGhpbCB6aW1tZXJtYW5uIGJpdGNvaW4%3D) - [Life On The Internet: Networking (1996 Usenet Documentary)](https://www.youtube.com/watch?v=jNme5DlNaZY&pp=ygUbbGlmZSBvbiB0aGUgaW50ZXJuZXIgdXNlbmV0) - [Snooping is in the nature of govts – king of encryption Phil Zimmermann](https://www.youtube.com/watch?v=1eYZ8v%5FR9jI&pp=ygUdcGhpbCB6aW1tZXJtYW5uIHNjcmVlbiBzYXZlcnM%3D) - ### Age Verification Wants Your Face, and Your Privacy URL: https://www.privacyguides.org/posts/2025/05/06/age-verification-wants-your-face-and-your-privacy/ Last updated: 2025-05-06T21:45:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/05/06/age-verification-wants-your-face/) ### A Flaw With the Security Level Slider in Tor Browser URL: https://www.privacyguides.org/posts/2025/05/02/a-flaw-with-the-security-level-slider-in-tor-browser/ Last updated: 2025-05-03T15:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/05/02/tor-security-slider-flaw/) ### In Praise of Tor: Why You Should Support and Use Tor URL: https://www.privacyguides.org/posts/2025/04/30/in-praise-of-tor-why-you-should-support-and-use-tor/ Last updated: 2025-05-06T18:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/04/30/in-praise-of-tor/) ### Privacy Pass: The New Protocol for Private Authentication URL: https://www.privacyguides.org/posts/2025/04/21/privacy-pass-the-new-protocol-for-private-authentication/ Last updated: 2025-04-21T17:30:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/04/21/privacy-pass/) ### Think Privacy Is Dead? You're Wrong. URL: https://www.privacyguides.org/videos/2025/04/17/is-privacy-dead/ Last updated: 2025-09-10T02:13:16.000Z ## Sources - - ### Encryption Is Not a Crime URL: https://www.privacyguides.org/posts/2025/04/11/encryption-is-not-a-crime/ Last updated: 2025-04-11T16:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/04/11/encryption-is-not-a-crime/) ### Is Your Data Really Safe? Understanding Encryption URL: https://www.privacyguides.org/videos/2025/04/03/is-your-data-really-safe-understanding-encryption/ Last updated: 2025-09-10T02:14:22.000Z ## Sources - - - - ### Interview with Micah Lee: Cyd, Lockdown Systems, OnionShare, and more URL: https://www.privacyguides.org/posts/2025/03/28/interview-with-micah-lee-cyd-lockdown-systems-onionshare-and-more/ Last updated: 2025-03-28T17:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/03/28/interview-with-micah-lee/) ### Privacy Means Safety URL: https://www.privacyguides.org/posts/2025/03/25/privacy-means-safety/ Last updated: 2025-03-25T20:30:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/03/25/privacy-means-safety/) ### Privacy-Respecting European Tech Alternatives URL: https://www.privacyguides.org/posts/2025/03/19/privacy-respecting-european-tech-alternatives/ Last updated: 2025-03-19T21:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/03/19/private-european-alternatives/) ### KeePassXC + YubiKey: How to set up a local-only password manager URL: https://www.privacyguides.org/posts/2025/03/18/keepassxc-yubikey-how-to-set-up-a-local-only-password-manager/ Last updated: 2025-03-18T17:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/03/18/installing-keepassxc-and-yubikey/) ### Stop Confusing Privacy, Anonymity, and Security URL: https://www.privacyguides.org/videos/2025/03/14/stop-confusing-privacy-anonymity-and-security/ Last updated: 2025-09-10T02:15:23.000Z ## Sources - - ### Privacy is Also Protecting the Data of Others URL: https://www.privacyguides.org/posts/2025/03/10/privacy-is-also-protecting-the-data-of-others/ Last updated: 2025-03-10T20:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/03/10/the-privacy-of-others/) ### Toward a Passwordless Future URL: https://www.privacyguides.org/posts/2025/03/08/toward-a-passwordless-future/ Last updated: 2025-03-08T11:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/03/08/toward-a-passwordless-future/) ### How to Reset Your YubiKey and Create a Backup URL: https://www.privacyguides.org/posts/2025/03/06/how-to-reset-your-yubikey-and-create-a-backup/ Last updated: 2025-03-06T22:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/03/06/yubikey-reset-and-backup/) ### Anonymity for Everyone: Why You Need Tor URL: https://www.privacyguides.org/videos/2025/03/02/why-you-need-tor/ Last updated: 2025-09-10T02:17:33.000Z ## Sources - Tor support documentation: ### The UK Government Forced Apple to Remove Advanced Data Protection URL: https://www.privacyguides.org/posts/2025/02/28/the-uk-government-forced-apple-to-remove-advanced-data-protection-what-does-this-mean-for-you/ Last updated: 2025-09-21T06:28:22.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/02/28/uk-forced-apple-to-remove-adp/) ### No, Privacy is Not Dead: Beware the All-or-Nothing Mindset URL: https://www.privacyguides.org/posts/2025/02/17/no-privacy-is-not-dead-beware-the-all-or-nothing-mindset/ Last updated: 2025-02-17T20:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/02/17/privacy-is-not-dead/) ### 5 Easy Steps to Protect Yourself Online URL: https://www.privacyguides.org/videos/2025/02/14/5-easy-steps-to-protect-yourself-online/ Last updated: 2025-09-10T02:18:38.000Z ## Sources - The biggest data breaches in 2024: - Bitwarden Password Strength Tester: - Proton Pass Showcase video: - Bitwarden Showcase video: - Google Incognito Lawsuit: - Google ad for GIMP was malicious: - Cops were allowed to force a suspect to use thumbprint to unlock phone, says court: ### How to Clear Your Browser History on Chrome, Firefox, and Other Browsers URL: https://www.privacyguides.org/posts/2025/02/13/how-to-clear-your-browser-history-on-chrome-firefox-and-other-browsers/ Last updated: 2025-02-13T21:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/02/13/clearing-browsing-data/) ### Biometrics Explained URL: https://www.privacyguides.org/posts/2025/02/13/biometrics-explained/ Last updated: 2025-02-13T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/02/13/biometrics-explained/) ### CryptPad Review: Replacing Google Docs URL: https://www.privacyguides.org/posts/2025/02/07/cryptpad-review-replacing-google-docs/ Last updated: 2025-02-12T17:45:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/02/07/cryptpad-review/) ### The Future of Privacy: How Governments Shape Your Digital Life URL: https://www.privacyguides.org/posts/2025/02/03/the-future-of-privacy-how-governments-shape-your-digital-life/ Last updated: 2025-02-03T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/02/03/the-future-of-privacy/) ### EasyOptOuts Review & Real-World Test URL: https://www.privacyguides.org/posts/2025/02/03/easyoptouts-review-real-world-test/ Last updated: 2025-02-03T16:20:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/02/03/easyoptouts-review/) ### Using Tails When Your World Doesn't Feel Safe Anymore URL: https://www.privacyguides.org/posts/2025/01/29/using-tails-when-your-world-doesnt-feel-safe-anymore/ Last updated: 2025-01-29T22:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/01/29/installing-and-using-tails/) ### The Protesters' Guide to Smartphone Security URL: https://www.privacyguides.org/posts/2025/01/23/the-protesters-guide-to-smartphone-security/ Last updated: 2025-01-27T20:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/01/23/activists-guide-securing-your-smartphone/) ### Privacy Guides Hires Three Staff Members URL: https://www.privacyguides.org/posts/2025/01/17/privacy-guides-hires-three-staff-members/ Last updated: 2025-01-17T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2025/01/17/privacy-guides-hires-three-staff-members/) ### It's time to stop using SMS, here's why! URL: https://www.privacyguides.org/videos/2025/01/14/its-time-to-stop-using-sms-heres-why/ Last updated: 2025-09-10T02:19:45.000Z ## Sources - - - - - - - - - (Page 12) - - ### Do you need a VPN? URL: https://www.privacyguides.org/videos/2024/12/12/do-you-need-a-vpn/ Last updated: 2025-09-10T02:21:27.000Z More information about VPNs can be found on our website! [Learn more ](https://www.privacyguides.org/en/basics/vpn-overview/) ## Sources - VPN Sponsorship Study: - VPNs Questionable Security Practices: - VPN Relationship Map: ### State of the Web App: Current Woes and Promising Futures URL: https://www.privacyguides.org/posts/2024/11/30/state-of-the-web-app-current-woes-and-promising-futures/ Last updated: 2024-11-30T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/11/30/pwa-vs-iwa/) ### Where are all the Multi-Party Relays? URL: https://www.privacyguides.org/posts/2024/11/17/where-are-all-the-multi-party-relays/ Last updated: 2024-11-17T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/11/17/where-are-all-the-mprs/) ### Privacy Guides is Hiring URL: https://www.privacyguides.org/posts/2024/10/28/privacy-guides-is-hiring/ Last updated: 2024-10-28T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/10/28/job-openings/) ### Onion Browser Review: Tor on iOS URL: https://www.privacyguides.org/posts/2024/09/18/onion-browser-review-tor-on-ios/ Last updated: 2024-09-18T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/09/18/onion-browser-review/) ### Bad-Faith Arguments in the Privacy Community URL: https://www.privacyguides.org/posts/2024/09/09/bad-faith-arguments-in-the-privacy-community/ Last updated: 2024-09-09T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/09/09/bad-faith-arguments/) ### Proton Wallet Review: Is Proton Losing Touch? URL: https://www.privacyguides.org/posts/2024/09/08/proton-wallet-review-is-proton-losing-touch/ Last updated: 2024-09-08T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/09/08/proton-wallet-review/) ### Jonah Aragon Hired as Project Director URL: https://www.privacyguides.org/posts/2024/08/20/jonah-aragon-hired-as-project-director/ Last updated: 2024-08-20T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/08/20/staff-announcement/) ### Privacy Guides Partners With MAGIC Grants 501(c)(3) URL: https://www.privacyguides.org/posts/2024/07/22/privacy-guides-partners-with-magic-grants-501-c-3/ Last updated: 2024-07-22T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/07/22/privacy-guides-partners-with-magic-grants-501-c-3/) ### "Privacy-Preserving" Attribution: Mozilla Disappoints Us Yet Again URL: https://www.privacyguides.org/posts/2024/07/14/privacy-preserving-attribution-mozilla-disappoints-us-yet-again/ Last updated: 2025-09-21T05:44:57.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2024/07/14/mozilla-disappoints-us-yet-again-2/) ### This Week in Privacy #8 URL: https://www.privacyguides.org/livestreams/2024/02/11/this-week-in-privacy-8/ Last updated: 2026-07-24T18:46:48.000Z _This post is for subscribers only._ ### This Week in Privacy #7 URL: https://www.privacyguides.org/livestreams/2024/02/04/this-week-in-privacy-7/ Last updated: 2026-07-24T18:46:55.000Z _This post is for subscribers only._ ### This Week in Privacy #6 URL: https://www.privacyguides.org/livestreams/2024/01/27/this-week-in-privacy-6/ Last updated: 2026-07-24T18:47:01.000Z _This post is for subscribers only._ ### This Week in Privacy #5 URL: https://www.privacyguides.org/livestreams/2024/01/20/this-week-in-privacy-5/ Last updated: 2026-07-24T18:47:08.000Z _This post is for subscribers only._ ### This Week in Privacy #4 URL: https://www.privacyguides.org/livestreams/2024/01/13/this-week-in-privacy-4/ Last updated: 2026-07-24T18:47:14.000Z _This post is for subscribers only._ ### This Week in Privacy #3 URL: https://www.privacyguides.org/livestreams/2024/01/06/this-week-in-privacy-3/ Last updated: 2026-07-24T18:47:20.000Z _This post is for subscribers only._ ### This Week in Privacy #2 URL: https://www.privacyguides.org/livestreams/2023/12/16/this-week-in-privacy-2/ Last updated: 2026-07-24T18:45:21.000Z _This post is for subscribers only._ ### This Week in Privacy #1 URL: https://www.privacyguides.org/livestreams/2023/12/09/this-week-in-privacy-1/ Last updated: 2026-07-24T18:45:12.000Z _This post is for subscribers only._ ### Threads Is the Perfect Twitter Alternative, Just Not for You URL: https://www.privacyguides.org/posts/2023/07/21/threads-is-the-perfect-twitter-alternative-just-not-for-you/ Last updated: 2023-07-21T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2023/07/21/threads-launch-twitter/) ### Privacy Guides Now Has Merchandise URL: https://www.privacyguides.org/posts/2023/05/31/privacy-guides-now-has-merchandise/ Last updated: 2023-05-31T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2023/05/31/merch-announcement/) ### Worried About TikTok? The RESTRICT Act Is Not the Answer URL: https://www.privacyguides.org/posts/2023/04/01/worried-about-tiktok-the-restrict-act-is-not-the-answer-americans-are-looking-for/ Last updated: 2025-09-21T06:28:08.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2023/04/01/restrict-act/) ### Privacy Guides Is Now Multilingual URL: https://www.privacyguides.org/posts/2023/02/26/privacy-guides-is-now-multilingual/ Last updated: 2023-02-26T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2023/02/26/i18n-announcement/) ### Important Changes to Signal Registration and Registration Lock URL: https://www.privacyguides.org/posts/2022/11/10/important-changes-to-signal-registration-and-registration-lock/ Last updated: 2022-11-10T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/11/10/signal-number-registration-update/) ### New Privacy and Security Features in macOS 13 Ventura URL: https://www.privacyguides.org/posts/2022/10/27/new-privacy-and-security-features-in-macos-13-ventura/ Last updated: 2022-10-27T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/10/27/macos-ventura-privacy-security-updates/) ### iOS 16 Privacy Configuration Guide URL: https://www.privacyguides.org/posts/2022/10/22/ios-16-privacy-configuration-guide-2/ Last updated: 2022-10-22T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/10/22/ios-configuration-guide/) ### iOS 16 Privacy Configuration Guide URL: https://www.privacyguides.org/posts/2022/10/22/ios-16-privacy-configuration-guide/ Last updated: 2022-10-22T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/10/22/ios-configuration-guide/) ### A Warning About Signal Proxies in Iran and Other Oppressive Countries URL: https://www.privacyguides.org/posts/2022/10/15/a-warning-about-signal-proxies-in-iran-and-other-oppressive-countries/ Last updated: 2022-10-15T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/10/15/warning-about-signal-proxies/) ### Signal Configuration and Hardening Guide URL: https://www.privacyguides.org/posts/2022/07/07/signal-configuration-and-hardening-guide/ Last updated: 2025-05-24T14:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/07/07/signal-configuration-and-hardening/) ### Hide Nothing URL: https://www.privacyguides.org/posts/2022/06/09/hide-nothing/ Last updated: 2022-06-09T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/06/09/hide-nothing/) ### Erasing Data Securely From Your SSD or HDD URL: https://www.privacyguides.org/posts/2022/05/25/erasing-data-securely-from-your-ssd-or-hdd/ Last updated: 2022-05-25T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/05/25/secure-data-erasure/) ### Move Fast and Break Things URL: https://www.privacyguides.org/posts/2022/04/04/move-fast-and-break-things/ Last updated: 2022-04-04T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2022/04/04/move-fast-and-break-things/) ### Firefox Privacy: 2021 Update URL: https://www.privacyguides.org/posts/2021/12/01/firefox-privacy-2021-update/ Last updated: 2021-12-01T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2021/12/01/firefox-privacy-2021-update/) ### Virtual Insanity URL: https://www.privacyguides.org/posts/2021/11/01/virtual-insanity/ Last updated: 2021-11-01T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2021/11/01/virtual-insanity/) ### Welcome to Privacy Guides URL: https://www.privacyguides.org/posts/2021/09/14/welcome-to-privacy-guides/ Last updated: 2021-09-14T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2021/09/14/welcome-to-privacy-guides/) ### Security, Privacy, and Anonymity URL: https://www.privacyguides.org/posts/2021/02/23/security-privacy-and-anonymity/ Last updated: 2021-02-23T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2021/02/23/security-privacy-anonymity/) ### Why I Decided to Run a Tor Relay URL: https://www.privacyguides.org/posts/2020/05/04/why-i-decided-to-run-a-tor-relay/ Last updated: 2020-05-04T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2020/05/04/why-i-run-a-tor-relay/) ### Choosing the Right Messenger URL: https://www.privacyguides.org/posts/2019/11/27/choosing-the-right-messenger/ Last updated: 2019-11-27T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2019/11/27/choosing-the-right-messenger/) ### The Trouble With VPN and Privacy Review Sites URL: https://www.privacyguides.org/posts/2019/11/20/the-trouble-with-vpn-and-privacy-review-sites/ Last updated: 2019-11-20T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2019/11/20/the-trouble-with-vpn-and-privacy-review-sites/) ### Delisting Wire From Privacy Guides URL: https://www.privacyguides.org/posts/2019/11/19/delisting-wire-from-privacy-guides/ Last updated: 2019-11-19T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2019/11/19/delisting-wire/) ### Delisting Startpage From Privacy Guides URL: https://www.privacyguides.org/posts/2019/11/12/delisting-startpage-from-privacy-guides/ Last updated: 2019-11-12T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2019/11/12/delisting-startpage/) ### Firefox Privacy: Tips and Tricks for Better Browsing URL: https://www.privacyguides.org/posts/2019/11/09/firefox-privacy-tips-and-tricks-for-better-browsing/ Last updated: 2019-11-09T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2019/11/09/firefox-privacy/) ### We've Joined the Open Collective Foundation 501(c)(3) URL: https://www.privacyguides.org/posts/2019/10/31/weve-joined-the-open-collective-foundation-501-c-3/ Last updated: 2019-10-31T19:00:00.000Z [Click here to continue reading this article...](https://www.privacyguides.org/articles/2019/10/31/weve-joined-the-open-collective-foundation/)