theprivacycloud.substack.com
Discord will enable global age verification soon
Now's the time to move
#privacy is an active hashtag on Bluesky. In the last 30 days, 1,050 people shared 5,174 posts with it — around 172 a day. Activity is down 12% versus the previous week, peaking on Jul 8 with 236 posts.
Tags most often used together with #privacy.
theprivacycloud.substack.com
Discord will enable global age verification soon
Now's the time to move
spectrum.ieee.org
Data Walks Reveal Residents' Mixed Feelings on Privacy
How do Long Beach residents feel about data collection in their city? Gwen Shaffer's data walks reveal surprising insights.
grapheneos.org
GrapheneOS releases
Official releases of GrapheneOS, a security and privacy focused mobile OS with Android app compatibility.
deborahcopaken.substack.com
11 steps to keep Meta from stealing your data to train AI
You only have until June 26, 2024 to say no to Meta taking your personal photos and words and using them to train their generative AI. Here are step-by-step directions for opting out.
github.com
Release 151.0.7922.108.0 · GrapheneOS/Vanadium
Changes in version 151.0.7922.108.0: update to Chromium 151.0.7922.108 A full list of changes from the previous release (version 151.0.7922.83.0) is available through the Git commit log between t...
palantirwatch.org
PalantirWatch — Tracking Palantir Technologies
Independent watchdog tracking Palantir's contracts, executives, lobbying, legal exposure, and global footprint. OSINT-driven public interest research.
ftp.crysp.org
Original post on ftp.crysp.org
www.heise.de
Auch KI von Meta hackte sich in eine andere Firma
Nach OpenAI und Anthropic räumt nun auch Meta ein, dass sich eigene KI-Software in fremde Systeme gehackt hat.
ppc.land
Mozilla rates Stardust 2 of 10 over symptom data sent to third parties
Euki scored 10 of 10 for keeping logs on the device, while Period Calendar fed AdMob and DoubleClick from the first open. What does that leave media buyers?
ppc.land
Mozilla rates Stardust 2 of 10 over symptom data sent to third parties
Euki scored 10 of 10 for keeping logs on the device, while Period Calendar fed AdMob and DoubleClick from the first open. What does that leave media buyers?
www.theguardian.com
This man was secretly snapped by someone with smartglasses. He's not alone in calling that a violation of privacy
One summer day earlier this year, Rhys left a Collingwood cafe in Melbourne where he had been working remotely, when his phone pinged with a message on the dating app Grindr. The message was a photo of him sitting at a table outside the cafe on his laptop, with his dog seated on the ground next to him. In the foreground, in a man’s hand was an iPhone unlocked. The photo had been taken moments before with Meta’s Ray-Ban glasses, unbeknown to Rhys. “He essentially wrote something about my dog being cute and apologised for not saying hi,” says Rhys, who asked that his surname not be used. Rhys never noticed a flash, despite Meta Ray-Bans requiring an LED light to alert others to the device filming or taking pictures. It felt creepy, Rhys says, particularly because the person didn’t say hi in the first place before surreptitiously taking a photo to send to him. Smartglasses, such as Meta’s Ray-Bans, which have built-in cameras, microphones, and AI assistants, are growing in popularity as the clunky, ugly designs of earlier models are replaced with styles that are increasingly indistinguishable from regular glasses. Meta says it has sold more than 7m of...
papoo.work
When “shared” means searchable
linuxiac.com
The European Union’s open-source age-verification project has drawn criticism after a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement, raising concerns about Linux, custom Android ROMs, and independently compiled applications. The debate began in the GitHub repository for the project’s Android app, where a user argued that tying credentials to specific hardware environments would make it more difficult to support open systems. “ _Hardware-bound attestation is a requirement of this project, not an implementation detail we can simply drop_ ,” a maintainer responded. The project invited alternative architectural proposals and said a dedicated security review and threat model would be published soon. The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave. However, critics claim that this approach endangers the system by making it dependent on a small number of approved devices, operating systems, and attestation providers. The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers. This distinction matters because hardware-backed key storage does not require a server to approve the entire device, operating system, or application build. The maintainer’s wording leaves some uncertainty over how restrictive production deployments will be. There is also a separate governance limitation. Proof of Age providers are expected to issue credentials only to applications included in a list of compliant apps maintained by the European Commission. This means that publishing the source code does not automatically guarantee that a community-built version can use the real service. Importantly, Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. However, the current architecture does not provide a native Linux wallet, and alternative mobile operating systems could struggle to meet the required trust conditions. So, as you can understand, the controversy goes far beyond a single Android implementation. For now, however, the project’s position is that hardware binding remains required. The expected security review and threat model may provide a more detailed explanation of why that trade-off was selected and whether alternative roots of trust or less restrictive implementations can still comply. Until then, the central question remains unresolved: whether an EU-funded, open-source identity system can meaningfully remain open when real-world access depends not only on available source code, but also on approved applications, supported security hardware, trusted operating environments, and the policies of credential providers.
Two security researchers shipped me a pink plastic kid's smartwatch from Amazon. When I wore it, they tracked my movements, surreptitiously took photos of me, even listened to my conversations. The same backend they hacked is used by 30+ watch brands for kids. 🧵👇 www.wired.com/story/hacker...
www.wired.com
papoo.work
When “shared” means searchable
deflock.org
DeFlock
Find license plate readers (LPRs) near you.
iapp.org
EDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter | IAPP
In light of the U.S. Supreme Court's decision over independent agencies, the European Data Protection Board is urging the European Commission to assess the ruling's potential impacts to the EU-U.S. Da...
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.