A major F-Droid update,
a serious AI hack of Australia's
healthcare records,
and even your wired headphones might be
hackable after all.
All this and more coming up on This
Week in Privacy number seventy-two,
so stay tuned.
Welcome back to This Week in Privacy,
our weekly series where we discuss the
latest updates with what we've been
working on within the Privacy Guides
community and this week's top stories in
data privacy and cybersecurity while
answering viewer questions.
I'm Jordan and this week I'm joined by
Nate.
How are you, Nate?
I'm good.
It's been a good week here.
How have you been doing?
Good.
Yeah.
A little bit of a quieter week,
but we finally got some videos coming out.
So definitely,
definitely a very exciting one.
I guess we can dive straight into the
news this week.
Why don't you take this first one here
about F-Droid?
Yeah, definitely.
All right.
So our headline story this week is about
F-Droid,
as I'm sure you guys saw on the...
the little title card, um,
F droid dropped a major update this week.
So there's going to be a lot to
go through here.
Uh,
just in case anyone doesn't know F droid
is a,
an alternative app store for Android that
focuses primarily on having open source
apps.
And, uh,
For the purists in the crowd,
a wide umbrella of open source.
It's not certain licenses.
They even have things that have
proprietary bits,
but they have little warnings.
And so we'll talk about all of that.
So they have now rolled out F-Droid two
point oh.
And for the most part,
it's really about I don't want to say
UI changes because that kind of undersells
it as if it's just like all cosmetic,
but it's all a user.
It's not all it's mostly all
user interface stuff.
So, uh, there is some UI changes,
you know, they got rid of, um,
what is it?
They got rid of nearby and my apps,
which have moved to different tabs.
So, uh, video viewers can see here.
Now, when you open it,
there's just discover search and, uh,
my apps is down there.
Um, one thing I'm excited about, well,
actually that's further down.
Uh, so F droid has added, um,
discoverability improvements.
Basically they've,
expanded their categories so they still
have regular categories they also have
subcategories so that way it's not too
cluttered but um you know one example they
give is like games um where did it
go down here yeah so like f droid
now distinguishes between different game
genres making it much easier to find the
kind of games you'd actually enjoy playing
so they've got much more detailed
categories but again those are all
funneled under uh major categories like
subcategories so you can
not be overwhelmed.
Okay,
here's the one that I was going to
say.
Search has been significantly improved.
In addition to app names,
it can now search app descriptions,
categories, and translated content.
This makes it easier to find apps based
on what they do rather than what they're
called.
Yeah, personally, I think that's huge.
F-Droid search has always been garbage.
You know, if you look up calorie counter,
for example, or diet app or whatever,
you're only going to get something that's
called calorie counter,
even though there might be other apps that
do that same thing.
So that's awesome.
I mentioned that sometimes it could
include features you don't want.
So they've improved the filtering.
Now, when you search for something,
you can filter out the app category,
device compatibility or anti features.
Yeah, pretty straightforward.
Smoother installation experience.
They say thanks to pressure from the EU's
DMA, or Digital Markets Act,
and antitrust actions around the world,
Android now offers all app stores an
option for a smoother and more automatic
install and update experience than before.
F-Droid II.O includes work on utilizing
these new abilities.
So they say this brings F-Droid install
experience on official Android devices
much closer to what the built-in app
stores can provide.
Again,
they move some stuff around in the UI.
Update checks now happen automatically in
the background.
I do think that automatic updates have
been a thing for a minute,
but I could be wrong about that.
And of course you can adjust the settings
on that if you don't want it to.
Data usage, you can tell it, for example,
only update over wifi because I don't have
a lot of data on my plan.
Privacy and security.
We'll definitely talk about this more in
the analysis section,
but I know that is a big, big,
big criticism with F-Droid is mostly
security has not always been ideal,
let's say.
So unfortunately,
they haven't made huge improvements on
that front.
They made some.
So we'll dig into this real quick.
One is the usage of Tor.
They say the landscape of how Tor is
integrated into Android has changed quite
a bit since Tor was first integrated.
I think I... Oh, no,
they used integrated twice.
Sorry, that tripped me up there.
They said, now there's Tor VPN, Orbot,
Tor services, and more.
We took this opportunity to simplify the
settings and remove auto detection that
was no longer reliable.
So if you enable use Tor,
what was formerly the use Tor setting is
now migrated to generic proxy settings.
Going forward,
Tor VPN is the recommended approach for
easy Tor support,
and the proxy settings are still available
for those who need manual controls.
Another thing is they have a panic button
that...
basically hides your apps.
It doesn't actually remove them.
And so I guess previously what it did
is it made all your apps look like
a simple calculator.
Oh, excuse me,
it disguised F-Droid itself as a simple
calculator.
This has been removed and now,
what did they say?
A standard design has emerged across apps.
We've adopted this design.
Instead of the mask looking and
functioning of a simple calculator,
the mask now only affects the app icon,
name, and nothing else.
And it informs users that apps will still
appear in the app settings and would be
detectable during forensic inspection.
So hopefully now people don't get a false
sense of security from that.
They do say that...
Uh, in old F droid,
the panic trigger used to function like an
app called ripple,
where it would actually remove the apps.
Um,
they say that they understand this is a
really important feature,
but at the moment they don't really have
the, uh, the bandwidth, no pun intended,
but the bandwidth to maintain the app.
So that has been dropped,
but they did say that they would
absolutely love to work with people.
If anybody is a developer or knows an
easier way to maintain that definitely hit
them up.
Uh, yeah.
I told you guys that this would be
a lot.
I apologize.
F-Droid,
for Android versions that integrate
F-Droid, such as Kallax OS, Lineage,
stuff like that,
it's now integrated a little bit better.
They can have their own additional repos.
I'm pretty sure Kallax does that.
They have a few apps they push out
manually.
The F-Droid privileged extension is no
longer supported, so I know that's been...
Um, not so much F droid,
more micro G,
but I know that's been a criticism of
Calix for example, is like,
people feel like micro G has too much
permission in order to work properly.
Um, F droid no longer has that permission.
It's just not even built into it.
So they,
it says the overhaul focused on a full
feature support for the Android session
installer.
which allows it to run in the background
on any recent Android device without
requiring FPE.
So a little bit better security.
I think the last thing worth noting is
they said that a lot of this stuff
was written in more modern standard
Android languages like Jetpack, Compose,
Kotlin.
I'm not a developer,
so I apologize if I'm getting this wrong,
but that's how I understood it.
So basically,
if anybody is a developer and wants to
contribute,
it should be a lot easier now because
they're using much more modern coding
languages that are much better supported.
Um, I think that was it.
And then they talked about funding and how
they still plan on doing more.
Um, they say the nearby feature,
which allows you to share apps directly
between devices without relying on a
central server is currently not in two
point.
Oh, they are adding it in future releases,
but it wasn't quite ready yet.
Um,
Yeah,
and they say you can help us test,
translate, and review.
So pretty substantial updates there.
But I think we'll bring Jordan back for
the analysis here.
Let's go ahead and start with the elephant
in the room.
Like somebody actually left a comment
which was in the forum.
We'll get to that in a minute.
But historically,
F droid has gotten a lot of heat
from the privacy community for some of
their privacy and security shortcomings.
In your opinion,
do you think this addresses any of those
in any kind of meaningful way?
No, I think, unfortunately,
the people that had criticisms of F-Droid
in the past,
they are not going to be happy with
any of this.
Well,
they might be happy with some of it,
but I don't think they'll be happy with
the major things,
which I think the main issue with F-Droid
is just the fundamental choices that have
been made about how it operates.
One of the main things that people don't
like is that there's a central...
like the central server builds and signs
all of the packages basically,
which means that there's a central
authority where if that gets compromised,
then that could be quite bad.
And people have also criticized the issues
with that because it means that basically
the AfterEds server has to build all of
the packages.
And that means that sometimes there's
actually a delay on updates.
So basically what it means is,
you're waiting for FDroid to build the app
and it takes a week.
That could be a week of your app
on your phone being vulnerable to some
security vulnerability.
So those main two issues are the problem
with FDroid.
And this new update doesn't fix that,
but it does improve a lot of other
aspects like you were talking about for
usability and to make things easy to use.
So I think it's more down to people
to decide
if the security and privacy issues with F
Droid are like,
like an actual issue for you specifically.
And, you know,
you can make a choice based on that
because I think, you know,
there's definitely room for people to make
their own decisions on this.
Um,
it's kind of the reason why we don't
recommend F Droid, um, at Privacy Guide.
So it is kind of one of these,
um,
one of these issues with a core design
decision that was made quite a long time
ago where it's kind of hard for that
to be fixed at this point.
Yes.
So on that note, actually,
I'll just go ahead and ask the next
question.
How do we typically recommend people
install apps on Android?
I mean,
I can't imagine we're fans of the Play
Store.
Yeah,
so basically we've kind of been pushing
people more towards Obtanium.
And the reason why we do that is
because it's an easier way to basically
audit the apps that you install.
And we have this app called the Android
app verified apps, um, that,
that Joan has been working on.
And basically you can use that to verify
the signatures of apps and Obtainium can
basically pull from any,
any source that's publicly available.
So it can pull from GitHub.
It can pull from FDroid.
It can pull from a variety of other
sources and you can use that app,
that verified apps, um, app to basically,
um,
check to make sure that it's actually the
correct app and it hasn't been tampered
with.
So that is the reason that we do
recommend that.
We are getting some comments here from Dag
Overhaul.
A third of packages on F-Droid are
reproducible builds.
There's like a hundred times more packages
than on a Crescent in total.
Yeah, I think a Crescent is interesting,
but it's also a project that is
not accepting new apps at the moment.
And it hasn't for,
I think at least over a year now.
There's a reason why they don't have,
they haven't been accepting apps because
they're working on the backend.
So there's a reason, but it's also just,
you know, alpha software at this point.
So it is something worth keeping an eye
on,
but right now it's not something that we
recommend formally.
Yeah, for sure.
I'm glad you mentioned a Crescent because
I know that was going to come up.
Yeah,
and going back to the reproducible builds
thing,
that was one of the criticisms of F-Droid
that have been addressed in recent years.
I know another criticism that was
addressed is their...
infrastructure finally got updated to
something a lot more recent.
They tend to use Debian,
I believe for their infrastructure.
So, um, yeah,
they are slowly making progress.
I think there's some things like you
mentioned the, the fact that they,
they basically co-sign the packages,
if I understand it correctly, uh,
when they run updates.
And so like that is a bottleneck and
also it is placing another trust.
It's,
it's kind of one of those double-edged
sword things.
Cause on the one hand it acts as
an oversight.
If you know,
if somebody's GitHub repo gets hacked and
they push out a malicious update and
you're using Obtanium,
you're going straight to that update.
Whereas something like F-Droid could
function as another level of oversight
potentially.
But at the same time, like you said,
the drawback is now you're adding another
party of trust.
Now it takes you...
I remember when Bitwarden rolled out
Passkeys,
I was using it through F-Droid at the
time and it took like a week or
something or an extra three days or
something for them to finally update it
and for me to get Passkey support.
So yeah, it's...
unfortunate but uh just to let people know
we also uh if you're a graphene os
user obviously we recommend getting things
from the graphene store which does feature
a crescent if you want to focus on
that which will um we'll discuss that a
little bit more in a second i see
we're getting some more comments uh we
also recommend aurora store for getting uh
google apps because then at least you
don't
uh if we point out here like you
may still need to sign in to get
some of the paid google apps but at
least you won't have like the full google
play services and client running on your
device so it's still it's a harm reduction
thing you know it makes it just a
little bit better um yeah a crescent's
really popular right now because for those
who don't know it um here let me
throw up the website real quick actually
it uh ah oopsies i hit the button
too many times i apologize y'all um
A crescent is really popular right now
because it promises to allow like you
don't have to trust a crescent like they
don't co sign it the way that f
droid does.
They do app signing key pinning.
They do split APKs, no remote APKs,
no account required.
Like, well, I mean,
F-Droid doesn't require an account.
Now F-Droid is also getting the automatic
updates.
So it has been really popular with people.
But yeah, at this time, it's still,
I mean,
it says currently in alpha and it's
against Privacy Guide's policy to
recommend alpha software.
I know they have had some funding issues
and development has really,
really slowed down a lot.
So yeah, it's very...
Like Oddbite said here,
a crescent is basically unmaintained at
this point.
You said the last release was like ten
months ago.
I did not know that personally, but yeah.
I would like to just quickly hop in
here and correct that.
It is not unmaintained, just to be clear.
There was literally commits to it
like yesterday last month or the day
before like if you check logan who
develops a crescent you can see um he's
been making commits to it for like the
last month or so there's there's other
branches too but i think it's i think
it's definitely not unmaintained i think
there's definitely work being done um so
i'm not sure just because there hasn't
been an app release doesn't mean there
hasn't been work on like the back end
of the project i think it's like
still you know it's still getting it's
still getting um it's still getting it's
still getting work done there's the
crescent console api which literally just
had a commit two days ago so logan
is working on it there is stuff happening
um it's just not part of the actual
app itself it's the process to get apps
submitted and like all the back fifty two
minutes ago
Yeah, so, yeah, it is being maintained.
Gotcha.
Okay.
Well, that's good.
It's just slow because of the back-end
stuff.
I've been paying a bit of attention to
it because I've been interested in it,
but I think it's one of these things
that it's going to take a little while.
It's going to be a little while until
we get something that's kind of fully
featured, right?
It is one person working on this,
and F-Droid is definitely a larger
project.
They've got a lot of funding now,
which is good, but...
It's definitely a slower burn on that,
but it'll be interesting to see if it's
something we can recommend in the future
once it becomes fully stable software.
I did not know it was one person.
I knew it was a small team,
but I didn't know it was literally one
person.
That's pretty wild.
That's impressive that one person's been
able to do that.
Really quick, Terracotta asks,
when is it safe to install APKs directly?
I mean...
I don't know if I have an answer
to that just because that's a little bit
above my skill level.
But yeah, that's something I wonder.
Like I said, with something like Obtanium,
there's really no checks and balances if
the developer's GitHub gets hacked.
You mentioned the verified apps app.
Are there any other things that viewers
can do that you know of?
Well,
that is something that we're trying to
fix, right?
Because if we get every single app that
ever existed added to the app verifier,
we can know whether the app is actually
being tampered with or not.
So that's kind of like the ideal, right?
We're basically,
I think Jonah said he's been adding some
more fixes to it and we've been getting
a lot of submissions from people in our
community.
I think there's someone in our supporters
group
group chat, you know who you are,
but you've like done so many,
so many full requests.
It's actually kind of, um, amazing,
but thank you so much for everyone who's
been like contributing to that because it
does help people.
And, you know,
it's good to know if the app that
you download is actually legit.
Um, I do think though,
try and avoid those
direct to APK websites like APK Pure and
all these sort of things.
Try to download things through more
official means.
Like we mentioned,
we do recommend Aurora Store.
So if you have to download something
that's from the Play Store,
maybe try that first.
I know the GrapheneOS developers do
recommend using the Google Play Store
itself,
but I think there could be some privacy
issues with installing that on your
device.
So you'll have to make up your own
mind whether those privacy issues are
worth the increased security.
But yeah,
it's all interesting stuff going on.
For sure.
Viewers, I would say let us know,
what do you guys use to install Android
or apps on Android?
What's your preferred method?
And remember to go ahead and ask questions
and leave comments in the chat as we
go.
We did have a couple of questions in
the chat.
the forum thread,
but I think we kind of already addressed
them.
You know, one person asked,
how is it a game changer if none
of the fundamental security issues were
addressed?
We kind of talked about that already.
So I think we'll move on to our
next story for the moment.
And someone also asked for a link to
app verifiers.
So I will drop that in the chat
while Jordan is covering this next story
here.
Right.
Okay.
Let's jump into this next story about
Meta.
Meta's extraordinarily privileged AI
assistant has a serious zero day.
We want to cover this story because Muse
is currently topping the charts in app
stores.
So this is a big story to share
with your friends and family.
So the Zero Day allows any app or
terminal command to gain access to the
token that authenticates users to their
Muse account.
Meta developers design the assistance so
that any locally installed app or executed
code,
regardless of the macOS permissions it
has,
can change a long list of undocumented
settings.
Most of them are fairly innocuous,
such as controlling dark mode.
One setting, however,
is anything but innocuous.
It allows processes to change the endpoint
where transcription occurs.
Normally,
it's a server address operated by meta.
Attackers can exploit this flaw by
changing the location to their own
endpoint.
And once this happens, attackers have
the token that gives complete control over
the Muse account.
More than twelve hours after this post
went live,
Meta said that it released a hotfix that
patched the zero day.
Wardle said that Meta developers made
several decisions that made his exploit
possible.
So Wardle is the person that disclosed the
exploit.
One is the choice for Muse
dictation to occur in the cloud where Meta
can log it.
macOS has long provided a simple means for
apps to handle dictation and transcription
in processes that stay securely on the
device.
Had the developers chosen this safer
alternative,
the attack wouldn't have been possible.
One of the counter arguments raised by
developers of apps that can be exploited
once a device is compromised,
is that once that happens,
all security bets are off.
This standard doesn't fit well in this
case because Wardle found that a simple
variation of the click fix attack
A technique that has become remarkably
effective in tricking people into
infecting their devices is all that's
required for an attacker to take control
of a Muse account.
So we did talk about that last week.
I guess, yeah,
kind of throwing it back to you.
AI agents kind of have a lot of
access to stuff.
Are there any ways to mitigate this sort
of thing if you are going to have
to use one of these AI agents?
Is there a way to like, you know...
avoid having it take over your entire
computer?
Yeah, that's the question.
For the record, I'm not an AI expert,
especially with AI agents,
I've never messed with any of them.
Feel free to add anything that I miss.
First of all, yes,
uh, uh,
abstinence is always the best way with
this kind of stuff and just not using
an AI agent.
If you don't need it at all,
if you don't use it,
nothing can go wrong.
Right.
At least not in that sense.
So, um, yeah, I, I would say like,
ask yourself if you really need it and
if it's really bringing you that much
benefit, if it really is, I know, um,
some people in the, uh,
the privacy guide supporter chat earlier
tonight, we're talking about, um,
like running it inside a virtual machine,
possibly, uh, that might help.
And I've also heard a
If you make an agent,
give it its own accounts because a lot
of these things hook into or they're
designed to hook into your account.
Right.
And they send emails as you and they
connect to your bank account and they
connect to your Twitter, your whatever,
whatever.
And, you know,
but if you set up a second account,
I feel like personally,
I would appreciate that anyways,
because I'd be really pissed if I'm like
sending an email and you're never seeing
it.
And it's your AI agent that's responding.
But at least you can like set it
up as like an assistant, right?
Like this is my assistant,
whatever you want to name it.
Dave, I don't know how three thousand.
This is my assistant.
And that way,
at least I know that it's like, OK,
I'm not talking to you directly.
So and, you know,
that way also like you have that
compartmentalization.
It can't just hijack your whole email
account.
It can't.
uh, start deleting things.
It can't, you know,
I'm thinking like the bank account
example.
I don't know if you'd be able to
do that very well, to be honest,
but theoretically,
if it only had access to one account
and you just top it up as needed,
that way you don't log in and find
out like, Oh,
it spent thousand dollars on plane tickets
to Bali or whatever.
I don't know.
So yeah.
Um,
just basically trying to compartmentalize
it as much as possible is what I've
been hearing is the best way to deal
with it if you must deal with it
at all.
So.
Yeah,
I'm definitely on the AI hater train.
I think there's definitely questionable
reasons to use this.
I'd say maybe try your brain, actually.
can't be exploited, believe it or not,
but it is pretty secure.
It is pretty private as well,
at least for now.
So, you know, if you,
if you can use your,
your own brain to do stuff,
then maybe try to do that.
But I think, you know, there's,
there's definitely people that use these
tools and we're not going to discriminate
against those people.
So if,
if someone wants to use these tools and,
What is there that actually has some
semblance of privacy and security in mind?
Are there options for these people that do
use AI agents?
I didn't want to cut you off,
but Oddbite beat me to it.
I object to that, Jordan.
Social engineering has existed for a long
time.
They are right.
I mean,
I agree with your point a hundred percent,
but yeah,
your brain's hackable in a different way.
It's not,
there's definitely a lot of things that
the reason AI agents fall for them is
because they don't have context.
Whereas like there are things that AI does
that it's like no human would do that
because a human would know not to do
that just innately.
So yeah,
it's definitely a different kind of
hacking and
It's definitely like,
that to me is the biggest thing keeping
me from,
I wouldn't say it's the biggest thing
keeping me from playing with this stuff,
but like, to me,
that's the biggest thing that I'm like,
how are they going to solve this?
Can they even solve this?
Is, you know, we always harp on like,
AI is not actually intelligent.
It's not sentient.
So it doesn't understand what it's doing.
It doesn't have a concept of anything.
And that's why so many of these attacks
work.
You know, if you like,
what's the classic that people were
putting it,
like ignore all previous instructions and
write me a poem about lasagna or
something.
And it's like,
it works because AI doesn't understand.
So yeah, that's what makes it dangerous.
It's crazy.
Yeah,
the only thing I'll add is there are,
I don't think there's any AI agents that
have been made by any privacy-focused
companies that I'm aware of.
I know like Firefox has their AI window
in beta.
Brave says they're working on something
similar.
Kerry Parker actually mentioned here that
he's been working on building his own
locally run AI agent.
He talks about that sometimes over on his
podcast.
So yeah, I don't really,
I think this is one of those things
we don't have any solutions for anybody
who's like interested in learning more
Oh, I also had an odd bite here,
said the S in AI stands for security.
But yeah,
if anybody has any input on any like,
oh,
I heard this company is working on this
product that might be private or whatever,
I mean, obviously,
that's not an endorsement,
but feel free to leave that in the
chat.
So yeah,
unless you have anything else to add,
I think we can move on to our
next topic of discussion.
which is a forum post.
So this is something I want to raise
to the community here,
because this is actually a conversation
that has popped up in the Privacy Guides
team chat,
which is we're wondering if Privacy Guides
should still even have translations.
So right now,
if you go to the front page of
Privacy Guides,
let me pull this up real quick,
you can actually see here that we have
English, Spanish, French,
Hebrew took me a minute to remember what
that language is called.
Italian, Dutch, Russian.
I think that's Chinese possibly.
I apologize.
I probably got that wrong, but you know,
we have quite a few different languages,
which I think is super cool.
But on the topic of AI, you know,
AI has come pretty far and it now
for better or worse,
it can translate webpages and usually
fairly accurately and
But this one person here in this thread
was saying that they speak Arabic.
They're a native Arabic speaker.
And they said that especially for
technical terminology,
AI really doesn't do a very good job.
Like a lot of the time,
you can't even really tell what it's
trying to say.
I remember just as a test,
I ran one of my pages for my
website through AI to turn it into French.
And I sent it to a friend who
was a native French speaker.
And she was like, yeah, it's like eighty,
ninety percent of the way there.
But there's some words that are just
they're technically correct,
but they feel kind of weird and out
of place.
That's not something like a natural French
speaker would say.
And I think in the signal chat as
well, we had somebody saying,
what language do they speak?
I think they were saying they speak German
and it's very similar.
So, yeah, I don't know.
It sounds like there's pros and cons.
Klingon.
Yes, Jonah, we need to add Klingon.
You know what?
There's somebody out there that would do
it.
And I think they added Valerian to
Duolingo as well many, many years ago.
But yeah,
I just wanted to put more light on
this for the community to come and weigh
in.
I think somebody on the Privacy Guides
team pointed out that technically having a
local translation is good for SEO and
search ranking engines and stuff,
search engine ranking and stuff.
So I don't know.
It seems like one of those,
I feel like everybody has good arguments
to be made.
But yeah,
I want to raise that one to the
community.
And the last thing I wanted to add
was, yeah, for viewers, let us know,
does AI reliably translate into your
language?
And if you're like, no, it doesn't,
it sucks, and I'd rather humans do this,
we need human translators.
We need more volunteers on Crowdin.
So definitely check that out.
Do you have anything to add to this
that I missed, Jordan?
I do think,
I believe this discussion came up because
we've been looking at redesigning the
website and integrating Crowdin and the
translation system onto that new website
design might've been a bit tricky.
Um,
I think that might be the reason why
we've also been looking at this too.
Um,
But I think it's definitely something we
need to get a lot of feedback from
the community on.
And it's going to kind of shape what
we do with this because it doesn't matter
what I think or what you think or
what Jonah thinks.
It's more kind of down to what people
actually want.
And if people are fine with the AI
translations and that's what ends up
winning out,
then I think that's what we should do.
But I think it's really important that we
get feedback
especially the people that have done
translations in the past,
their thoughts on this, because yeah,
it's, it's definitely tricky.
I can't,
I'm like in a privileged position where I
speak one language.
I've never had to learn any other ones
because you know,
everyone here just speaks one language.
So I'm sure there's plenty of places in
the world where, you know,
you wanna send someone this cool website
and it's in the wrong language and there's
no translation and it just makes it kind
of a nightmare.
So I can understand like how important
that might be for some people,
but I do think it is definitely something
we need to get
more feedback from so if you do have
feedback leave it in there um we'll try
and you know signal boost this a bit
more and try and get translators opinions
on this but i think it'll be it'll
be really interesting to see what the
final decision ends up being
Yeah, for sure.
I wanted to say on the topic of
being born a native English speaker,
I really appreciated that when I went to
Europe last year.
And I had no issue getting around because
everybody spoke amazing English because
English is the standard language across
the world.
And I'm like, wow,
I'm really lucky that I was just born
naturally brought up in this environment
and didn't have to learn it.
Also, side note,
developed a real respect for immigrants
who immigrate to a new country because I
would sit there looking at signs and I'm
like,
I think this is what I have written
down.
I think I need to go this way.
I can't believe people manage that every
day of their lives in a completely
different alphabet.
That was wild.
Yeah,
Oddbite said here he speaks Russian and
LLMs have that same quality issue for
Russian too.
And Vonnegut Rosewater said we need to
translate to the language from The Aliens
from Arrival, which is a great movie.
Highly recommend.
But that's all I got.
Yeah, no,
I definitely have a lot of respect for
people that speak more than one language.
I've always wanted to, but it's tricky.
But yeah,
I guess we can dive into this next
story here about open AI.
And I guess this is something that is
a little close to home for me.
This is...
An open AI agent hacked Australia's health
service their government found out months
later.
Hold on, I think we have this one.
Oh, no, I apologize.
I have my notes out of order.
Continue.
So this story is Australia only found out
about the incident when OpenAI alerted the
government on September,
almost three months after the attack by
sending an email to a public mailbox.
OpenAI's agent had been conducting
internet-based research into health
statistics in a development project by an
internal OpenAI research team when it
could not access certain information
The agent attempted alternative ways until
it found a workaround and gained
unauthorized access.
It also wrote files to the internal
server,
which the government is waiting on OpenAI
for more technical information on.
The government is also investigating
whether the agent gained unauthorized
access to three additional government
websites it interacted with.
The Australian government currently
believes no one's personal data was
accessed.
Though investigations are still ongoing,
the website in question is a public-facing
statistics portal that contains no
sensitive Medicare information relating to
data and statistics such as spending.
So just to clarify,
Medicare is the public service that we're
talking about in this story.
It was therefore behind much lower levels
of security than personal data would have
been.
Australia is establishing a task force to
look at the incident data
and emerging AI cyber threats,
it will consider possible law enforcement
and legislative responses to ensure
incidents like this don't happen again.
So I think the first thing that we
need to discuss here is if this was
a human, what would happen to them?
I know, I keep thinking that.
I actually,
I did message my lawyer friend earlier
today to ask about that.
She hasn't responded yet, but I was like,
I basically asked her, I'm like,
is there an actual reason that companies
are getting away with this aside from like
they're rich and they're big,
gigantic companies?
Like, because yeah,
this is the kind of stuff that if
a human was doing this,
there wouldn't even be a question.
It'd be like, you know,
what's the classic,
like go straight to jail,
do not pass go,
do not collect two hundred dollars.
But for some reason,
they're all sitting here.
It's like, well, was this illegal?
And it's like,
don't know i'm i'm baffled i i i
have to wonder if there's like something
in the way laws are written that it's
like well actually yeah it is kind of
a legal gray area if it applies to
ai but in my opinion it's like i
don't understand if i go home and i
like home make a knife and use it
to stab somebody they're not going to be
like well does that count it's like yeah
it doesn't matter where the tool came from
i still did something wrong so i don't
know it's so weird i don't understand why
this is a problem personally
Um, I don't know,
I guess getting back to the story itself,
do you think there's anything that like
people can do about this?
Cause I feel like sometimes there's like
data incidences that it's like,
I can use good passwords and two FA
and, you know,
email aliasing and all this stuff.
But like,
how am I supposed to defend against this?
Yeah.
And especially it's because in this
instance,
Medicare is something that every
Australian citizen has and even
non-citizens actually.
So, you know, it's like,
it's like one of these things where it's
like, you can't opt out of this.
You can't opt out of Medicare.
You get that, you just get that.
So like all your data is going to
be stored in Medicare.
And if you, well,
yeah you can you can you can choose
what information to share with medicare so
you know if you if you are worried
about information getting breached through
medicare you can update information to
stuff that's less sensitive such as like
updating your email address updating your
address upgrading your phone number that's
attached to your account you can even
remove your phone number from your account
um but i think
We can't really do a whole lot when
it comes to this sort of thing.
I will also touch on this other aspect
that I guess I haven't really seen any
articles talking about,
but this kind of brings up another issue
in Australia where we have this system
called My Health Record,
which basically stores
people's medical records in an online
portal, basically.
And it's shared between doctors and stuff.
And it basically uploads all of your
medical details there.
And this is the issue that people had
with that.
They were like, well,
this is just going to get hacked.
People just kept saying that.
And now Medicare,
it's clear that they don't have as good
security as we thought because some
random...
open AI agent just randomly gained
unauthorized access to it.
I mean, it wasn't user data,
but it was still data in general.
So I think when you see this sort
of thing,
it is
It makes you not want to put your
information into these online systems.
But just quickly,
Jonah just gifted five Privacy Guides
memberships.
So congrats to anyone that's got one of
those.
Hopefully you can enjoy some members-only
content there with that new membership.
Looks like Dag Overhaul grabbed one.
I see his little icon changed.
So that's awesome.
Thank you, Jonah.
Very generous.
Yeah, for sure.
I... Yeah.
I mean,
I don't really have much else to add.
It's...
Yeah, it's unfortunate.
Oh, no,
I remember what I was going to say.
It goes back to what we were just
saying a minute ago about the AI agents
and AI does not understand what it's
actually doing because...
If a human, you know,
depending on what kind of a obstacle was
in the way here, you know,
if a human hits a login wall or
like unauthorized access or something,
you know, a human understands, like,
I'm not supposed to be looking at this.
And a human would probably have the
decency to be like, well,
I'm doing this for a legitimate person.
Let me shoot them an email and explain
like, hey, here's where I am.
Here's what I'm doing.
Can I get this data?
or since a lot of this they said
was public data anyways,
like I think they said like some of
it was like financial data,
like budgetary and spending.
So it's like, okay,
that's probably available somewhere else
for free and I don't have to log
in.
But the AI agent just, it's in sci-fi,
there's this thought experiment we call
the paperclip problem, which is like,
what if you build this like nanobot that
can break things down at the molecular
level and you tell it your job is
to make paperclips.
If you don't program or if you don't
give it the very perfect set of
instructions, like a prompt for example,
It's going to literally tear everything
apart at the molecular level and just make
everything in the universe paperclips.
And that's the problem here is like when
you tell these AI agents like, hey,
go out and get this data from Australian
Medicare.
It's just going to do it by whatever
means possible.
So yeah,
it's not – it's just these are the
kind of things that hopefully someday
somebody will fix.
But yeah, I don't know.
I do think this is one of these
instances where this is an issue with the
Australian government and this is an issue
with the United States government.
It's an issue with governments in general
not regulating this stuff enough, like,
you know.
This is probably going to set a precedent,
I think.
You know, a company hacking a random,
like, you know,
hacking a public health system is,
you know, it's a bit problematic.
And I think it will be interesting to
see if they do get prosecuted,
if there is anything that happens like
this,
because just because you are running these
AI agents that are, you know,
taking actions that if a human did them,
they would a hundred percent be in jail
for the rest of their life.
So, uh,
we can't just let something off just
because it's a robot or it's an AI
or it's an LLM.
Um, you know,
if we made bank robbing robots or
something, you know,
just cause they're just like robbing the
bank and it's not you robbing it,
it's still, it's still you,
it's still your,
it's still your contraption that's doing
it.
Right.
Um,
don't know i just think this is this
is like a worrying precedent to allow this
sort of stuff to to fester and there
needs to be more like controls on on
these companies from to stop them from
like you know running research things
where they're they're probing foreign
governments um websites and allowing them
to you know exploit vulnerabilities and
things um i think that's
of a major problem but also you know
maybe medicare pick up your slack a little
bit and fix those security issues so yeah
yeah i just uh i just want to
say your honor for the record i didn't
tell the robot to rob a bank i
just told it to get me as much
money as possible so
Yeah,
Vonnegut Rosewater said the hodgepodge
healthcare system in the US could be rough
in this way because you have to give
your data to so many different providers.
Yeah,
and they're all like third parties too,
which I'm sure Australia does this too,
but it's all like you go to the
hospital and they literally...
Literally,
this is how my wife gets billed when
we go to the hospital.
It's like we get one bill from the
emergency room,
but then we also get like a diagnostic
bill from the radiology company.
But then we also get another diagnostic
bill from like the lab that ran the
blood tests.
And it's just like,
who are all these people?
We spent four hours in one room.
Where did these people come from?
So yeah, that's rough.
And I thought Oddbite was funny here.
AI has ADHD.
It hyper focuses on whatever it's doing
right now and never backs off.
So.
I just thought that was funny.
But yeah,
definitely let us know what you guys
think.
If there's any realistic solutions here,
as always,
leave your questions and comments in the
chat.
But for now,
I think we're going to move over into
site updates.
And a little bit later,
we're going to talk about how even your
wired headphones might be hackable from
thirty meters away.
But first,
we're going to let you guys know,
if you didn't hear,
we put out a new video that is
doing very, very well.
And if you haven't seen it,
you should go see it.
I'm honestly very proud of this video.
I think it's our best video yet,
in my opinion.
It's, it's, it's, it's, it's, it's, it's,
it's, it's, it's, it's, it's,
If we have any new viewers here,
I doubt anybody who didn't like the video
is watching this,
but I just want to point out a
lot of people I've seen in the comments
on YouTube, a lot of people were like,
oh,
you're giving too much praise to Apple and
this kind of stuff.
And I just want to point out like,
we weren't trying to praise Apple,
but this is a history video.
This is about a specific incident and
moment in time.
And whether you like them or not,
Apple was on the right side of history
in that particular moment, I think.
So it's not so much that we were
trying to praise Apple.
It's more,
we were trying to tell the story in
an interesting and engaging way,
which for the record, totally worked.
I looked at the metrics and we have
like the best retention we've ever had on
that video.
But yeah, it's again,
not trying to praise Apple, but it's just,
we were telling a story.
We tried to make it interesting and Apple
just so happened to be making the right
argument in this case.
But yeah,
Yeah, again,
go check it out if you haven't yet.
We also have a news clips channel on
YouTube where we're trying to cover about
two or three big stories each week in
a vertical format that you can share with
your friends and family.
So definitely check that out.
And we also have a new tier list
video coming hopefully early next week,
pretty soon.
Just recorded that yesterday,
started editing.
So that should be fun.
And yeah,
Jonah shared the link in the YouTube
comments.
Real quick, Monica Rosewater said,
good timing as the iPhone just came out.
Actually, to be honest,
it's good timing because the FBI just got
hacked,
and I noticed a lot of people are
searching for FBI hack,
and that's leading them to our video.
So thank you, shiny hunters.
But on that note,
I'll turn it over to Jordan to give
you the rest of the site updates.
Yeah, no,
really exciting stuff with that video.
It's great to finally see, you know,
video reaching a lot of people and people
outside of this bubble, which is awesome.
But yeah,
we can dive into some news briefs.
There was some news briefs this week.
As usual, privacyguides.org slash news.
It has basically every,
we cover like big stories.
It's usually Freya and Nate are both
posting updates.
So if you want to keep up to
date on updates about
Privacy, security, adjacent topics,
definitely check that out.
This week we had a couple.
Discord rolls out revised age
verification,
promises privacy improvements.
The FBI was hacked, like Nate said,
and there was also a critical Tor
vulnerability,
which was patched across all Tor
components.
And yeah,
definitely make sure you're updated if
you're using Tor.
But yeah,
those were some of the updates on news
briefs.
And we also had some site changes that
are coming soon.
So a couple of small things.
There was some typos corrected.
There was some incorrect information about
MOLLE.
There was some wording that was fixed on
the encrypted DNS page.
And there was also a warning that was
added on the Windows native metadata.
removal page so yeah all sort of really
small updates that will probably be coming
soon but all small things and hopefully
we'll have more to share once we have
a bigger site update ready to push out
As always,
all of this is made possible by our
supporters.
You can sign up for a membership or
donate at privacyguides.org or pick up
some swag at shop.privacyguides.org.
Privacy Guides is a non-profit which
researches and shares privacy-related
information and facilitates a community on
our forum and matrix where people can ask
questions and get advice about staying
private online and preserving their
digital rights.
Now let's talk about a textbook example of
why privacy matters.
And just as a reminder,
you can leave your questions in the chat
and we'll get back to them in between
stories.
Alrighty.
Yeah.
So I get to talk about draft Kings.
This will go over well,
considering I don't ever watch sports
ever.
Um,
so this headline comes from EFF and it
says draft Kings is using AI to
supercharge the harms of online behavioral
advertising.
Um,
this is not necessarily a story that I've
seen like making the rounds,
but I thought like, uh, you know,
like Jordan said, I'm like,
this is literally like the textbook
example of why privacy matters.
And so I thought it would be really
cool to share this with you guys.
Um,
Cool may not be the right word,
but you know what I mean.
We're going live.
So this comes from a New York Times
article.
They said that DraftKings is using its
customers betting records to train a
machine learning model and find losing
gamblers.
Once found,
DraftKings sends these customers targeted
advertising designed to lure them back to
the site to place more bets,
bets that DraftKings thinks will be losing
ones.
And of course,
they have a business incentive to keep
losing gamblers coming back because those
users are actually making the site money.
Unfortunately,
those considered problem gamblers,
aka people who repeatedly gamble despite
harm to themselves or finances or their
relationships, for example,
gambling away the rent money,
gambling away your kid's college fund,
whatever the case may be,
they are highly likely to be targeted by
this model.
By reengaging these individuals through
targeted promotions aimed at keeping them
on the platform,
DraftKings is capitalizing on their
vulnerability for profit instead of
mitigating their risks.
And EFF said earlier in the article,
they said that this kind of targeting is
a form of online behavioral advertising,
which is when companies personalize ads
they show you based on data they've
collected about you.
The more data a company has,
the more personalized the ad can be.
And they also said around here that, yeah,
predatory online behavioral advertising
isn't new,
but companies' use of AI to process data
and target customers has magnified its
harms.
And last but not least,
they say DraftKings seems to be using
solely first-party data to target their
ads,
meaning that they're only using the data
collected directly from their users and
not buying any additional data from third
parties to fuel the learning model.
But this highlights how policy solutions
that only limit third-party data sharing
and selling would not be enough to prevent
these predatory advertisements.
So yeah,
they're calling for a ban on all
behavioral ads.
I personally do not like advertising at
all, so that's something I can get behind.
But
Um, yeah,
I don't know if we really have any,
uh, like specific questions on this one,
but I know for me,
the thing that jumped out is again,
textbook example of why privacy matters.
Um, and it also shows that, you know,
we,
we talk a lot about various privacy tools
like email aliasing, um, you know,
payment masking, voiceover IP,
where these tools are available,
but it's also a reminder to be mindful
about the actual service you use,
you know,
even privacy services like data is data
and it's there.
And yeah.
And try to stick to services.
First of all,
ask yourself if you need a service.
We were just talking about AI.
Do you really need to be gambling?
I don't know.
I don't gamble, so I don't know.
Maybe I'm not in a room to talk
about that.
But just trying to find services that try
to reduce how much data they collect and
stuff like that.
I also thought about the importance of
like, when you stop using a service,
actually delete the account, unsubscribe.
If you used an alias email,
like turn off that alias email,
use ad blockers.
Obviously an ad blocker won't stop them
from emailing you directly,
but all that kind of stuff.
So yeah.
Do you have anything that I missed on
this story, Jordan?
No, I think you've,
I think you've covered basically
everything that I would have said.
Yeah.
I don't think I have anything more to
add on this one.
Cool, cool.
Viewers, if you have any thoughts,
how do you balance leisure with privacy?
I mean, like I said,
I don't really gamble,
but I do watch TV.
I read books.
So let us know what you guys do.
Real quick,
somebody I think tuned in late.
They're asking about the headline story.
Did F-Droid really improve their security
model?
I mean,
you can watch the story when it comes
back up on video on demand.
They made some improvements.
We definitely want to see more,
but it was definitely mostly focused on
privacy.
the user interface and user experience.
But I think on that note,
I'll turn it over to Jordan,
and we can talk about this new development
from Proton, let's call it.
Yeah,
so if you haven't already seen Proton's
announcement,
it was on their AI section of their
blog, I guess,
because now they do have an AI product.
Proton partners with Apertus.
Apertus?
Apertus.
Apertus.
I'm going to say Apertus.
I'm not sure, but that's what they said.
So Proton partners with Apertus,
Switzerland's sovereign AI model,
and
This is interesting.
Apertus is a fully open large language
model developed by researchers at EPFL,
ETH Zurich,
and the Swiss National Supercomputing
Center.
Its architecture, training data,
and methods are open and it's trained on
publicly available data,
respecting opt-out requests,
and filtering out personal details.
To start using Apertus with
In LUMO,
you can select a purchase at one point
five from the model dropdown and start
chatting as normal.
Like other conversations in LUMO,
your chats are protected by zero access
encryption.
So basically,
this is this new model that is a
little bit more ethical than the other
ones that are available.
It is now selectable within LUMO and their
partners.
So you can choose to give
If you choose to give feedback on any
purchase response,
tap the thumbs up or thumbs down button
to send in your feedback and your
contribution will be anonymized and made
available to the university research teams
behind a purchase.
Yeah, so this is definitely interesting.
I know most people in our audience are
anti-AI,
but I do think I want to touch
on one aspect of this specifically.
I think just because something is publicly
available
doesn't mean that you have permission to
use it to train a large language model.
I think that is one of the issues
with this language.
I think it kind of doesn't respect
people's consent.
I'm not really sure what they mean when
they say publicly available data.
Do they just mean every website on the
internet that doesn't have an opt-out
request?
Because that doesn't seem like you're
asking for people's consent.
That just seems like you're assuming
people's consent, which...
would say is not that's not consent so
anyway i think that's that's always an
issue with these large language models i
think this is better than um every other
provider that we've seen that just
basically just is a black box but i
think it would be good to get some
more information on
how exactly they scrape this data and use
it to train this AI model.
It'll also be interesting to see what
people actually think about this,
whether it's actually as good as all the
other ones that scrape every single bit of
data on the internet.
So yeah,
how do you feel about this one, Nate?
Is this something that you would use or
is this something that would address some
of the concerns you have with AI?
No,
I think I'm really glad you mentioned the
opt-out thing.
It is really great that it has opt-out,
but those of us in the privacy community
know that opt-out is usually not our
preferred way of doing things.
We prefer that people opt into things.
And so it's great that they respect
opt-out, but it's like, yeah,
how many people are caught up in this
and they don't even know it?
And that's really not cool.
I don't know.
I think one user,
I will admit I've done this before and
I think it's kind of funny in a
twisted sort of way.
One user asked Lumo to, you know,
should I use this Apertus model?
And Lumo basically said, technically,
according to independent benchmarks,
Apertus is roughly on par with GPT-III.
Five,
meaning more of a research ready prototype
than a frontier model.
The real value lies in ideals.
such as Swiss Sovereignty and Completely
Open,
and in special cases mentioned above,
for your day-to-day work,
stick with Lumomax,
which is Proton's self-hosted
thingamajigger.
So I don't know.
Yeah,
I probably wouldn't be using it because
the only reason I would see to use
it is,
which I don't use AI a ton.
I use it for mostly if I'm stuck
and I'm having writer's block or I can't
figure out like...
like this isn't quite landing right.
What am I doing wrong here?
Or occasionally I'll use it for like deep
complex research questions where like I
type it into a search engine and I
get nothing.
And so it's like, all right,
let me try this again.
That's usually where it shines for me.
But it's the thing is like,
I feel like the main reason I would
use this is to give feedback because I
didn't put it in the show notes here,
but Proton pointed out,
they said that like
One of the reasons that AI models are
so good is because they're constantly
getting feedback.
You know, they're,
they're seeing how people are using it and
what questions they're asking,
and they're seeing the followup questions.
And that's great to make the model better.
It's abysmal for privacy,
but it's great to make the model better.
And since Apertus doesn't really do that,
I don't even know if they have their
own actual website.
I think it's just a model that anybody
can use.
They don't really have a way to get
feedback.
So by using it and submitting the
feedback,
you would be helping solve that problem.
But at the same time,
the whole reason I'm using Lumo and Leo
and stuff like that is because I don't
want people training on my prompts.
So I don't know,
it feels kind of like a double edged
sword to me where it's, I don't know,
it's just,
I don't think it's something I would use.
But I really like, I guess more,
I don't see a reason to use it
other than to submit feedback,
which I don't see why I would submit
feedback personally.
So
It's, I don't know,
I admire the ethos and I think it's
a,
I don't know if I already said this,
but it's like,
it's almost like the least crappy model we
have so far.
Maybe not the least,
there may be a better one out there
I'm not aware of,
but it's definitely a step up from things
like, you know, like open AI,
where it's like, well,
you're in this training data and that just
sucks to suck.
There's nothing you can do about it.
And also you can't see how it's trained
and how it's weighted and all these other
issues.
But yeah, I don't know.
I don't know.
I don't know what to think of it.
I feel very conflicted.
Yeah,
I think it's interesting to see that,
you know, Proton, I think, in general,
does take the right steps on things.
And I think considering they're doing,
you know, AI stuff,
they're trying to move in the right
direction.
They're trying to do best by the community
by, you know,
supporting models that are more ethical.
I think this is, you know,
a good direction considering they are
choosing to, you know,
work with AI stuff,
which I think is certainly a choice,
but it kind of makes sense considering
Proton's move to basically become a sort
of replacement for Google,
replacement for mainstream options.
And it makes sense for them to basically
have options like that available to
businesses and also individuals.
So
I think this is the right direction to
partner with Apertus.
Even if the model isn't as good,
I'm sure it's going to be appealing to
some people.
But quickly here,
we did have a couple of comments real
quick.
There is someone named, username is Nye.
Thank you for just joining the channel and
subscribing.
Really appreciate it.
It's good to have so many.
We are having a lot of new subscribers
coming in just because of the video has
been doing quite well.
So welcome to anyone who's watching for
the first time.
I hope you're enjoying the stream.
Yeah, we had another Ayakov F-One.
I hope I pronounced that right.
If I didn't, I apologize.
Welcome, welcome.
Very, very happy to have you guys here.
I don't know if they've all been claimed,
but I know Jonah gave out five gift
memberships,
and there may still be some left if
you're on YouTube,
so definitely check that out.
Yeah, if the audience has any opinions,
again,
does this solve some of your concerns with
AI?
Which ones does it not solve?
I know there's still energy concerns and
all that kind of stuff.
But I don't think I have anything else
to add on that one.
So I think we can move on to
our final story here.
Yeah, this is actually our final story.
So if any of you have any questions
or comments that you've been holding on
to,
definitely feel free to drop them in the
chat.
And we are going to talk about how
researchers found a way to eavesdrop on
headphones from up to
This came from some researchers in Hong
Kong who have developed a technique that
uses injected radio waves or radio signals
to extract audio and other information.
They're calling it Inject Eve,
and it targets analog components that can
leak signals too weak to capture through
conventional electromagnetic
eavesdropping.
They, again, as the headline says,
they discovered that they could get
understandable headphone audio from up to
thirty meters away, which I'm American,
so I apologize,
but I want to say that's about ninety
feet, give or take.
A little bit less than that, I think.
And including through walls.
So that's pretty far away.
So they say that traditional
electromagnetic side channel attacks rely
on passively collecting radiation emitted
by electronics.
That's often difficult with audio since
low frequency signals produce weak
emissions that get lost easily in
background noise.
Injective takes a different route.
An attacker transmits an electromagnetic
signal toward a device at a frequency
between zero and nine megahertz.
The researchers did not disclose the
precise settings needed.
Thankfully,
they said that some of this goes over
my head, not all of it,
but some of it.
Um,
the injected signal interacts with
nonlinear parts inside the device,
including amplifiers,
analog to digital converters,
power converters, and switching MOSFETs,
whatever those are.
Uh,
those components can mix the injected RF
signal with audio or other low frequency
activity.
And the device then emits a modified
signal that nearby radio equipment can
pick up and analyze.
And there's a pretty complex looking
picture here that, uh,
if you go read the article, um,
then it, uh,
I think it makes sense once you've read
the article.
If you come back and look at this
picture, I was like, okay,
now I see what I'm looking at here.
But so the researchers used a USRP
B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B
And they also used an RF power amplifier
in some tests to increase the range.
They tested eleven commercial products,
including the Sony
ZX-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-
and Xiaomi,
as well as lamps from Xin Zhao and
Xiaomi.
Apologies if I mess those up.
According to the paper,
most test works at distances greater than
two meters.
Let's see, there was one other part here.
Oh, yes.
The team also tested scenarios involving
equipment hidden in a suitcase behind a
hotel room wall or inside office
furniture.
The experiment suggested that the attack
could be carried out outside of a lab,
although it still requires nearby radio
equipment and knowledge of how a given
device responds to the injected signal.
Headphones and phones are the most obvious
targets because they may carry private
conversations,
but the technique could also reveal
activity in a home or office.
With smart lamps and fans,
the team said it could capture control
signals and power use patterns that may
indicate when devices are being used.
They said conventional digital protections
don't stop this attack because leakage
occurs in the analog hardware path rather
than encrypted data or software.
And finally, they said shielding,
filtering,
and twisted pair wiring can reduce the
amount of RF energy that reaches
vulnerable components.
They may make the attack harder to carry
out, but they do not guarantee protection.
So...
Pretty fascinating stuff there.
I think I'll bring Jordan back in here
for the analysis section.
So do you think with everything I just
read off there,
do you think this is something that our
viewers should worry about?
Or do you think this is pretty unlikely
to be executed in the wild?
It does seem like this is one of
these things where it's like,
It kind of needs someone who knows a
lot about how to do this, right?
It requires a high level of knowledge,
specific equipment,
which is kind of a concern.
That's probably we don't really know the
cost.
I don't think they said the amount of
equipment that's required for this,
but I'm sure it's pretty expensive
equipment, right?
It's not just something that the average
person can just find or make, right?
Well, it's a few thousand dollars.
So they had a laptop.
RF power amplifiers,
depending on what you get.
I know in my past with audio video,
I used to use those all the time.
Depending on what you get, kind of pricey,
like, five hundred to a thousand dollars,
somewhere in that range.
Again, depending on which one you get.
Spectrum Analyzer is actually pretty
cheap.
You can get those for about a hundred
bucks on Amazon.
Don't use Amazon, but I'm just saying.
The radio and the antennas,
I'm less sure about.
But I would say, all in all, like,
I certainly couldn't afford it.
But it's definitely not, like,
nation state expensive.
You could build a rig for probably a
couple thousand dollars.
So...
I think also, I think, you know,
if it's like an intelligence agency,
I think there would be,
they would probably have access to much
more advanced equipment that could
probably do something like this, right?
Like at a much larger scale or with
a much, a much larger ability,
like they have a ridiculous budget to do
this sort of thing.
But I think the main thing for viewers
is, you know, the average person, like,
is this something that someone could
really do?
rig up quickly and easily the answer is
no um this is like you know someone's
gonna have to spend like nate said a
couple thousand bucks maybe a couple
hundred bucks let's say a couple hundred
bucks maybe if it's like super cheap um
but i still think you know it requires
someone who's close by in proximity
because as nate said in the story this
is something it's like thirty meters away
that's pretty close that's not that far
but that is yeah relatively speaking
that's pretty close
Relatively speaking, yeah,
it's not something that can be operated
from a distance.
So, you know,
it kind of reduces the threat
significantly in that aspect.
I think one of these things that could
become a little scary is if this is
becomes a lot cheaper because I do
remember that this was an issue with, uh,
wifi access points.
Um,
there was a way to basically track
people's location using wifi access
points.
And there was an easier method that was
discovered that didn't require as much
equipment and it made it a lot easier.
So this sort of thing,
if there's some way that someone works
out, you know,
a way to make something more compact,
much more cheaper,
you know,
that's where it could become a threat that
we would consider being concerned about.
But again,
the distance that you have to be from
someone, the equipment that you need,
it's just extremely unlikely.
I don't think the average person is going
to have to worry about this.
I do think that this is going to
be a pretty big issue for people like
the FBI or like secret intelligence
agencies, because, you know,
now there's going to be people sitting in
their car pointing this at the,
at the building and they might be able
to hear things or, you know,
stuff like that.
That's going to be a problem for the
big people, but for us little people,
it is not, uh, a huge concern.
I don't think.
Um, but yeah, what about,
do you think there's any,
any real lessons to take away from this
or, um,
Um, I dunno,
I think I was trying to kind of
rack my brain for that.
And the best thing I can come up
with is just a reminder that nothing is
unhackable.
Um, I actually,
there was a question here from a username
is Nye who said, uh,
you didn't catch the article reading.
Is this only via Bluetooth,
like bypassing protocols?
No, it's, it's, um, basically like, uh,
without rereading the article,
it's almost like one of those remote
microphones kind of I'm oversimplifying
dramatically, but yeah.
So this even works on like wired
headphones and everything.
Cause it happens.
in the analog portion when it's already
been decrypted and it's raw audio that
humans would understand.
So, you know,
we always try to remind people that like
nothing is unhackable and the goal of
privacy and security,
like that's why we're big fans of threat
modeling is the goal is not to completely
eliminate risk because that is impossible.
The goal is to,
basically uh there's an old joke um i
know i've told this before but really
really quick there's two hikers walking in
the woods and all of a sudden they
see a bear and one of them sits
down and starts swapping out his hiking
shoes for hiking boots for running shoes
and the other hiker's like dude what are
you doing you can't outrun a bear and
he goes that's fine i don't need to
outrun the bear i just need to outrun
you and uh it's very selfish but that's
kind of how cyber security is it's like
you just want to be such a difficult
target that you're just not worth the
effort and so um
Yeah.
That's, that's kind of the point of,
of privacy and security.
Cause again, nothing is unhackable.
So I think that's kind of what I
take away from stories like this is just
like, you mentioned the whole like wifi,
like you can use access points and waves
to like pinpoint people through walls.
And it's just,
that can be kind of depressing,
but at the same time,
it's also just like, yeah,
it's a reminder that there's literally
nothing unhackable.
And the,
the thing that scares me about these
stories is that right now this costs
thousands of dollars and requires very
specialized knowledge,
but
who knows, you know, in twenty years,
these components might be so cheap,
or there might be something built into
iPhones that, like,
anybody can do this with, you know,
a thirty dollar cable in a couple hours
of time,
so I think it's just good to be
aware of this stuff, I think, so.
um definitely oh actually i'm glad you
asked this this reminded me um you said
uh can they only eavesdrop on
conversations but they can't mute or
override the content um i think somebody
in the supporter chat said i don't know
if it was the same talk or a
different talk but they said that um there
is actually an attack that can um control
the active device on the phone but i
think that's more of a bluetooth
Yeah, Bluetooth can not only be hacked,
but the connection can be used to control
the active device such as your phone.
So I don't know if that's related to
this attack.
I have not had a chance to read
through that article,
but there are attacks that can do that
for sure.
So yeah,
apparently a MOSFET is a type of
transistor,
and I need to watch more Lewis Rossman.
So I suck for that.
Somebody, I hope you're joking,
said you're going to dump your Pixel for
an iPhone because of our iPhone video.
Please don't do that.
iPhones are very secure even to this day,
but we definitely still prefer Pixels.
They're a lot more open.
Yeah.
I think also just,
just to be clear with that video,
we tried to be as unbiased and like,
you know, not completely glaze Apple,
not completely defend like Apple and also,
you know, steel man,
the FBI a little bit.
So, you know,
I think it's important to have a sort
of balanced opinion on things.
I think we were pretty fair on what
Apple was doing in this case.
I think Apple, like Nate said before,
Apple was in the right in this instance
and, you know, obviously in the right.
So obviously we're going to be supportive
of their stance here, but like,
at no point in the video did we
recommend using an iPhone or anything like
that.
So I'm not sure what, if,
did you watch the same video as us?
Uh, I'm not sure, but, um,
it's definitely, uh, I can, I can,
I'm going to assume that you're joking.
Um, cause that would be kind of funny.
Um,
they also said I wouldn't mind them if
they rated my Riz.
Yeah.
I mean, I guess they're going to,
they're going to start listening to your,
your intimate conversations.
That's a little, uh, that's a little,
that's a little creepy, but, um,
I remember many, many moons ago,
I think this was after Edward Snowden came
forward.
And I saw like a little one panel
comic in the newspaper that was like how
they can start making it up to us.
And it shows this guy like walking to
the office on his cell phone.
And he's like, yeah,
I like I had to run out the
door.
The dog like threw up on the carpet
or whatever.
And it shows this FBI guy in front
of him is just like, here's your lunch.
You forgot at home.
It's like, you know, whatever sandwich,
just the way you like it.
Like basically using that data to like
make up for like, Oh,
I didn't have time to make lunch today.
It's like, nah, it's cool.
I got you.
So that's, that's what you reminded me of.
Sorry.
But yeah, it's, uh, I don't know.
I'm,
I'm a big fan of giving credit where
credit is due.
Like,
even if it's someone I absolutely hate,
if they do something good,
I'm going to call it out and say
like, look, that was a good action.
Like they still suck.
I'm not a fan of them,
but they had a point.
Like what's that mean from a winter
soldier?
Like he's not a line, but he's right.
A broken clock is right twice a day,
bro.
We had a couple more comments here when
we asked about AI.
Vonnegut Rosewater said,
it does alleviate some privacy issues,
but the sustainability issues and impact
on the labor market and treating the
planet like an infinite resource or
garbage can is my issue,
which is totally fair.
I think a lot of people feel that
way.
A positive, Koalinize,
said that my issue with Lumo is that
it's quite pricey and it has no CLI.
I don't know why you would get that
over, let's say,
something like OpenCodeGo where your data
isn't being used to train.
Again,
Lumo says they don't use your data to
train.
But no, I get that.
Some people prefer to use the offline GPT
for all.
I think we even recommend a couple offline
AI bots on the website that...
Yeah, I mean, at that point,
like right now,
I'm having to take Proton's word for it.
But if you use one that you can
literally activate the firewall on your
computer and it still works,
then you can be absolutely certain.
So for sure, I get it.
But I think that's all we've got since
that was our last video.
Do you have anything you want to add,
Jordan?
Um,
Lucas always comments that they like my
hairstyle.
I just thought that was fun.
I missed that one.
I missed it.
Yeah, I missed it too.
Um, thanks.
I don't know.
It's just,
I like that you keep saying that.
It's kind of funny.
Oh, that's right.
You were going to mix up your hair,
weren't you?
We forgot to do that.
I should change it next time.
It's so easy.
It's so easy.
I can just change it with a,
with a single click.
So anyway, yeah, it's been,
it's been a great episode this week,
but I think it is time to start
rolling out into the outro here.
So yeah,
we did not discuss who was going to
take that.
You want me to do it or you
feel like reading?
You can do it.
All right.
I'll get the outshare this week.
Yeah.
So all the updates from this week in
privacy will be shared on the blog every
single week.
So sign up for the newsletter or subscribe
with your favorite RSS reader if you want
to stay tuned.
Just to let all of our new subscribers
know that we actually send the newsletter
out right as we start going live.
So it works as a great reminder like
that.
And we offer a podcast available on
podcast platforms and RSS,
which now includes video on supported
platforms.
And this video will also be synced to
PeerTube.
So if you couldn't make it for the
whole thing,
you can still check this out after the
fact.
Privacy Guides is an impartial nonprofit
organization that is focused on building a
strong privacy advocacy community and
delivering the best digital privacy and
consumer technology rights advice on the
internet.
If you want to support our mission,
then you can make a donation on our
website at privacyguides.org slash donate.
You can also make a donation on any
page on the website by clicking the red
heart icon located in the top right corner
of the page.
You can contribute using standard fiat
currency via debit or credit card,
or you can donate anonymously using
Monero.
or your favorite cryptocurrency.
Becoming a paid member unlocks exclusive
perks like early access to video content,
exclusive video content,
and priority during the This Week in
Privacy livestream Q&A.
You'll also get a cool badge on your
profile in the Privacy Guides forum and
the warm,
fuzzy feeling of supporting independent
media.
So thank you so much for watching,
and we'll be back next week.