F-Droid 2.0 Is a Game Changer

A major F-Droid update,

a serious AI hack of Australia's

healthcare records,

and even your wired headphones might be

hackable after all.

All this and more coming up on This

Week in Privacy number seventy-two,

so stay tuned.

Welcome back to This Week in Privacy,

our weekly series where we discuss the

latest updates with what we've been

working on within the Privacy Guides

community and this week's top stories in

data privacy and cybersecurity while

answering viewer questions.

I'm Jordan and this week I'm joined by

Nate.

How are you, Nate?

I'm good.

It's been a good week here.

How have you been doing?

Good.

Yeah.

A little bit of a quieter week,

but we finally got some videos coming out.

So definitely,

definitely a very exciting one.

I guess we can dive straight into the

news this week.

Why don't you take this first one here

about F-Droid?

Yeah, definitely.

All right.

So our headline story this week is about

F-Droid,

as I'm sure you guys saw on the...

the little title card, um,

F droid dropped a major update this week.

So there's going to be a lot to

go through here.

Uh,

just in case anyone doesn't know F droid

is a,

an alternative app store for Android that

focuses primarily on having open source

apps.

And, uh,

For the purists in the crowd,

a wide umbrella of open source.

It's not certain licenses.

They even have things that have

proprietary bits,

but they have little warnings.

And so we'll talk about all of that.

So they have now rolled out F-Droid two

point oh.

And for the most part,

it's really about I don't want to say

UI changes because that kind of undersells

it as if it's just like all cosmetic,

but it's all a user.

It's not all it's mostly all

user interface stuff.

So, uh, there is some UI changes,

you know, they got rid of, um,

what is it?

They got rid of nearby and my apps,

which have moved to different tabs.

So, uh, video viewers can see here.

Now, when you open it,

there's just discover search and, uh,

my apps is down there.

Um, one thing I'm excited about, well,

actually that's further down.

Uh, so F droid has added, um,

discoverability improvements.

Basically they've,

expanded their categories so they still

have regular categories they also have

subcategories so that way it's not too

cluttered but um you know one example they

give is like games um where did it

go down here yeah so like f droid

now distinguishes between different game

genres making it much easier to find the

kind of games you'd actually enjoy playing

so they've got much more detailed

categories but again those are all

funneled under uh major categories like

subcategories so you can

not be overwhelmed.

Okay,

here's the one that I was going to

say.

Search has been significantly improved.

In addition to app names,

it can now search app descriptions,

categories, and translated content.

This makes it easier to find apps based

on what they do rather than what they're

called.

Yeah, personally, I think that's huge.

F-Droid search has always been garbage.

You know, if you look up calorie counter,

for example, or diet app or whatever,

you're only going to get something that's

called calorie counter,

even though there might be other apps that

do that same thing.

So that's awesome.

I mentioned that sometimes it could

include features you don't want.

So they've improved the filtering.

Now, when you search for something,

you can filter out the app category,

device compatibility or anti features.

Yeah, pretty straightforward.

Smoother installation experience.

They say thanks to pressure from the EU's

DMA, or Digital Markets Act,

and antitrust actions around the world,

Android now offers all app stores an

option for a smoother and more automatic

install and update experience than before.

F-Droid II.O includes work on utilizing

these new abilities.

So they say this brings F-Droid install

experience on official Android devices

much closer to what the built-in app

stores can provide.

Again,

they move some stuff around in the UI.

Update checks now happen automatically in

the background.

I do think that automatic updates have

been a thing for a minute,

but I could be wrong about that.

And of course you can adjust the settings

on that if you don't want it to.

Data usage, you can tell it, for example,

only update over wifi because I don't have

a lot of data on my plan.

Privacy and security.

We'll definitely talk about this more in

the analysis section,

but I know that is a big, big,

big criticism with F-Droid is mostly

security has not always been ideal,

let's say.

So unfortunately,

they haven't made huge improvements on

that front.

They made some.

So we'll dig into this real quick.

One is the usage of Tor.

They say the landscape of how Tor is

integrated into Android has changed quite

a bit since Tor was first integrated.

I think I... Oh, no,

they used integrated twice.

Sorry, that tripped me up there.

They said, now there's Tor VPN, Orbot,

Tor services, and more.

We took this opportunity to simplify the

settings and remove auto detection that

was no longer reliable.

So if you enable use Tor,

what was formerly the use Tor setting is

now migrated to generic proxy settings.

Going forward,

Tor VPN is the recommended approach for

easy Tor support,

and the proxy settings are still available

for those who need manual controls.

Another thing is they have a panic button

that...

basically hides your apps.

It doesn't actually remove them.

And so I guess previously what it did

is it made all your apps look like

a simple calculator.

Oh, excuse me,

it disguised F-Droid itself as a simple

calculator.

This has been removed and now,

what did they say?

A standard design has emerged across apps.

We've adopted this design.

Instead of the mask looking and

functioning of a simple calculator,

the mask now only affects the app icon,

name, and nothing else.

And it informs users that apps will still

appear in the app settings and would be

detectable during forensic inspection.

So hopefully now people don't get a false

sense of security from that.

They do say that...

Uh, in old F droid,

the panic trigger used to function like an

app called ripple,

where it would actually remove the apps.

Um,

they say that they understand this is a

really important feature,

but at the moment they don't really have

the, uh, the bandwidth, no pun intended,

but the bandwidth to maintain the app.

So that has been dropped,

but they did say that they would

absolutely love to work with people.

If anybody is a developer or knows an

easier way to maintain that definitely hit

them up.

Uh, yeah.

I told you guys that this would be

a lot.

I apologize.

F-Droid,

for Android versions that integrate

F-Droid, such as Kallax OS, Lineage,

stuff like that,

it's now integrated a little bit better.

They can have their own additional repos.

I'm pretty sure Kallax does that.

They have a few apps they push out

manually.

The F-Droid privileged extension is no

longer supported, so I know that's been...

Um, not so much F droid,

more micro G,

but I know that's been a criticism of

Calix for example, is like,

people feel like micro G has too much

permission in order to work properly.

Um, F droid no longer has that permission.

It's just not even built into it.

So they,

it says the overhaul focused on a full

feature support for the Android session

installer.

which allows it to run in the background

on any recent Android device without

requiring FPE.

So a little bit better security.

I think the last thing worth noting is

they said that a lot of this stuff

was written in more modern standard

Android languages like Jetpack, Compose,

Kotlin.

I'm not a developer,

so I apologize if I'm getting this wrong,

but that's how I understood it.

So basically,

if anybody is a developer and wants to

contribute,

it should be a lot easier now because

they're using much more modern coding

languages that are much better supported.

Um, I think that was it.

And then they talked about funding and how

they still plan on doing more.

Um, they say the nearby feature,

which allows you to share apps directly

between devices without relying on a

central server is currently not in two

point.

Oh, they are adding it in future releases,

but it wasn't quite ready yet.

Um,

Yeah,

and they say you can help us test,

translate, and review.

So pretty substantial updates there.

But I think we'll bring Jordan back for

the analysis here.

Let's go ahead and start with the elephant

in the room.

Like somebody actually left a comment

which was in the forum.

We'll get to that in a minute.

But historically,

F droid has gotten a lot of heat

from the privacy community for some of

their privacy and security shortcomings.

In your opinion,

do you think this addresses any of those

in any kind of meaningful way?

No, I think, unfortunately,

the people that had criticisms of F-Droid

in the past,

they are not going to be happy with

any of this.

Well,

they might be happy with some of it,

but I don't think they'll be happy with

the major things,

which I think the main issue with F-Droid

is just the fundamental choices that have

been made about how it operates.

One of the main things that people don't

like is that there's a central...

like the central server builds and signs

all of the packages basically,

which means that there's a central

authority where if that gets compromised,

then that could be quite bad.

And people have also criticized the issues

with that because it means that basically

the AfterEds server has to build all of

the packages.

And that means that sometimes there's

actually a delay on updates.

So basically what it means is,

you're waiting for FDroid to build the app

and it takes a week.

That could be a week of your app

on your phone being vulnerable to some

security vulnerability.

So those main two issues are the problem

with FDroid.

And this new update doesn't fix that,

but it does improve a lot of other

aspects like you were talking about for

usability and to make things easy to use.

So I think it's more down to people

to decide

if the security and privacy issues with F

Droid are like,

like an actual issue for you specifically.

And, you know,

you can make a choice based on that

because I think, you know,

there's definitely room for people to make

their own decisions on this.

Um,

it's kind of the reason why we don't

recommend F Droid, um, at Privacy Guide.

So it is kind of one of these,

um,

one of these issues with a core design

decision that was made quite a long time

ago where it's kind of hard for that

to be fixed at this point.

Yes.

So on that note, actually,

I'll just go ahead and ask the next

question.

How do we typically recommend people

install apps on Android?

I mean,

I can't imagine we're fans of the Play

Store.

Yeah,

so basically we've kind of been pushing

people more towards Obtanium.

And the reason why we do that is

because it's an easier way to basically

audit the apps that you install.

And we have this app called the Android

app verified apps, um, that,

that Joan has been working on.

And basically you can use that to verify

the signatures of apps and Obtainium can

basically pull from any,

any source that's publicly available.

So it can pull from GitHub.

It can pull from FDroid.

It can pull from a variety of other

sources and you can use that app,

that verified apps, um, app to basically,

um,

check to make sure that it's actually the

correct app and it hasn't been tampered

with.

So that is the reason that we do

recommend that.

We are getting some comments here from Dag

Overhaul.

A third of packages on F-Droid are

reproducible builds.

There's like a hundred times more packages

than on a Crescent in total.

Yeah, I think a Crescent is interesting,

but it's also a project that is

not accepting new apps at the moment.

And it hasn't for,

I think at least over a year now.

There's a reason why they don't have,

they haven't been accepting apps because

they're working on the backend.

So there's a reason, but it's also just,

you know, alpha software at this point.

So it is something worth keeping an eye

on,

but right now it's not something that we

recommend formally.

Yeah, for sure.

I'm glad you mentioned a Crescent because

I know that was going to come up.

Yeah,

and going back to the reproducible builds

thing,

that was one of the criticisms of F-Droid

that have been addressed in recent years.

I know another criticism that was

addressed is their...

infrastructure finally got updated to

something a lot more recent.

They tend to use Debian,

I believe for their infrastructure.

So, um, yeah,

they are slowly making progress.

I think there's some things like you

mentioned the, the fact that they,

they basically co-sign the packages,

if I understand it correctly, uh,

when they run updates.

And so like that is a bottleneck and

also it is placing another trust.

It's,

it's kind of one of those double-edged

sword things.

Cause on the one hand it acts as

an oversight.

If you know,

if somebody's GitHub repo gets hacked and

they push out a malicious update and

you're using Obtanium,

you're going straight to that update.

Whereas something like F-Droid could

function as another level of oversight

potentially.

But at the same time, like you said,

the drawback is now you're adding another

party of trust.

Now it takes you...

I remember when Bitwarden rolled out

Passkeys,

I was using it through F-Droid at the

time and it took like a week or

something or an extra three days or

something for them to finally update it

and for me to get Passkey support.

So yeah, it's...

unfortunate but uh just to let people know

we also uh if you're a graphene os

user obviously we recommend getting things

from the graphene store which does feature

a crescent if you want to focus on

that which will um we'll discuss that a

little bit more in a second i see

we're getting some more comments uh we

also recommend aurora store for getting uh

google apps because then at least you

don't

uh if we point out here like you

may still need to sign in to get

some of the paid google apps but at

least you won't have like the full google

play services and client running on your

device so it's still it's a harm reduction

thing you know it makes it just a

little bit better um yeah a crescent's

really popular right now because for those

who don't know it um here let me

throw up the website real quick actually

it uh ah oopsies i hit the button

too many times i apologize y'all um

A crescent is really popular right now

because it promises to allow like you

don't have to trust a crescent like they

don't co sign it the way that f

droid does.

They do app signing key pinning.

They do split APKs, no remote APKs,

no account required.

Like, well, I mean,

F-Droid doesn't require an account.

Now F-Droid is also getting the automatic

updates.

So it has been really popular with people.

But yeah, at this time, it's still,

I mean,

it says currently in alpha and it's

against Privacy Guide's policy to

recommend alpha software.

I know they have had some funding issues

and development has really,

really slowed down a lot.

So yeah, it's very...

Like Oddbite said here,

a crescent is basically unmaintained at

this point.

You said the last release was like ten

months ago.

I did not know that personally, but yeah.

I would like to just quickly hop in

here and correct that.

It is not unmaintained, just to be clear.

There was literally commits to it

like yesterday last month or the day

before like if you check logan who

develops a crescent you can see um he's

been making commits to it for like the

last month or so there's there's other

branches too but i think it's i think

it's definitely not unmaintained i think

there's definitely work being done um so

i'm not sure just because there hasn't

been an app release doesn't mean there

hasn't been work on like the back end

of the project i think it's like

still you know it's still getting it's

still getting um it's still getting it's

still getting work done there's the

crescent console api which literally just

had a commit two days ago so logan

is working on it there is stuff happening

um it's just not part of the actual

app itself it's the process to get apps

submitted and like all the back fifty two

minutes ago

Yeah, so, yeah, it is being maintained.

Gotcha.

Okay.

Well, that's good.

It's just slow because of the back-end

stuff.

I've been paying a bit of attention to

it because I've been interested in it,

but I think it's one of these things

that it's going to take a little while.

It's going to be a little while until

we get something that's kind of fully

featured, right?

It is one person working on this,

and F-Droid is definitely a larger

project.

They've got a lot of funding now,

which is good, but...

It's definitely a slower burn on that,

but it'll be interesting to see if it's

something we can recommend in the future

once it becomes fully stable software.

I did not know it was one person.

I knew it was a small team,

but I didn't know it was literally one

person.

That's pretty wild.

That's impressive that one person's been

able to do that.

Really quick, Terracotta asks,

when is it safe to install APKs directly?

I mean...

I don't know if I have an answer

to that just because that's a little bit

above my skill level.

But yeah, that's something I wonder.

Like I said, with something like Obtanium,

there's really no checks and balances if

the developer's GitHub gets hacked.

You mentioned the verified apps app.

Are there any other things that viewers

can do that you know of?

Well,

that is something that we're trying to

fix, right?

Because if we get every single app that

ever existed added to the app verifier,

we can know whether the app is actually

being tampered with or not.

So that's kind of like the ideal, right?

We're basically,

I think Jonah said he's been adding some

more fixes to it and we've been getting

a lot of submissions from people in our

community.

I think there's someone in our supporters

group

group chat, you know who you are,

but you've like done so many,

so many full requests.

It's actually kind of, um, amazing,

but thank you so much for everyone who's

been like contributing to that because it

does help people.

And, you know,

it's good to know if the app that

you download is actually legit.

Um, I do think though,

try and avoid those

direct to APK websites like APK Pure and

all these sort of things.

Try to download things through more

official means.

Like we mentioned,

we do recommend Aurora Store.

So if you have to download something

that's from the Play Store,

maybe try that first.

I know the GrapheneOS developers do

recommend using the Google Play Store

itself,

but I think there could be some privacy

issues with installing that on your

device.

So you'll have to make up your own

mind whether those privacy issues are

worth the increased security.

But yeah,

it's all interesting stuff going on.

For sure.

Viewers, I would say let us know,

what do you guys use to install Android

or apps on Android?

What's your preferred method?

And remember to go ahead and ask questions

and leave comments in the chat as we

go.

We did have a couple of questions in

the chat.

the forum thread,

but I think we kind of already addressed

them.

You know, one person asked,

how is it a game changer if none

of the fundamental security issues were

addressed?

We kind of talked about that already.

So I think we'll move on to our

next story for the moment.

And someone also asked for a link to

app verifiers.

So I will drop that in the chat

while Jordan is covering this next story

here.

Right.

Okay.

Let's jump into this next story about

Meta.

Meta's extraordinarily privileged AI

assistant has a serious zero day.

We want to cover this story because Muse

is currently topping the charts in app

stores.

So this is a big story to share

with your friends and family.

So the Zero Day allows any app or

terminal command to gain access to the

token that authenticates users to their

Muse account.

Meta developers design the assistance so

that any locally installed app or executed

code,

regardless of the macOS permissions it

has,

can change a long list of undocumented

settings.

Most of them are fairly innocuous,

such as controlling dark mode.

One setting, however,

is anything but innocuous.

It allows processes to change the endpoint

where transcription occurs.

Normally,

it's a server address operated by meta.

Attackers can exploit this flaw by

changing the location to their own

endpoint.

And once this happens, attackers have

the token that gives complete control over

the Muse account.

More than twelve hours after this post

went live,

Meta said that it released a hotfix that

patched the zero day.

Wardle said that Meta developers made

several decisions that made his exploit

possible.

So Wardle is the person that disclosed the

exploit.

One is the choice for Muse

dictation to occur in the cloud where Meta

can log it.

macOS has long provided a simple means for

apps to handle dictation and transcription

in processes that stay securely on the

device.

Had the developers chosen this safer

alternative,

the attack wouldn't have been possible.

One of the counter arguments raised by

developers of apps that can be exploited

once a device is compromised,

is that once that happens,

all security bets are off.

This standard doesn't fit well in this

case because Wardle found that a simple

variation of the click fix attack

A technique that has become remarkably

effective in tricking people into

infecting their devices is all that's

required for an attacker to take control

of a Muse account.

So we did talk about that last week.

I guess, yeah,

kind of throwing it back to you.

AI agents kind of have a lot of

access to stuff.

Are there any ways to mitigate this sort

of thing if you are going to have

to use one of these AI agents?

Is there a way to like, you know...

avoid having it take over your entire

computer?

Yeah, that's the question.

For the record, I'm not an AI expert,

especially with AI agents,

I've never messed with any of them.

Feel free to add anything that I miss.

First of all, yes,

uh, uh,

abstinence is always the best way with

this kind of stuff and just not using

an AI agent.

If you don't need it at all,

if you don't use it,

nothing can go wrong.

Right.

At least not in that sense.

So, um, yeah, I, I would say like,

ask yourself if you really need it and

if it's really bringing you that much

benefit, if it really is, I know, um,

some people in the, uh,

the privacy guide supporter chat earlier

tonight, we're talking about, um,

like running it inside a virtual machine,

possibly, uh, that might help.

And I've also heard a

If you make an agent,

give it its own accounts because a lot

of these things hook into or they're

designed to hook into your account.

Right.

And they send emails as you and they

connect to your bank account and they

connect to your Twitter, your whatever,

whatever.

And, you know,

but if you set up a second account,

I feel like personally,

I would appreciate that anyways,

because I'd be really pissed if I'm like

sending an email and you're never seeing

it.

And it's your AI agent that's responding.

But at least you can like set it

up as like an assistant, right?

Like this is my assistant,

whatever you want to name it.

Dave, I don't know how three thousand.

This is my assistant.

And that way,

at least I know that it's like, OK,

I'm not talking to you directly.

So and, you know,

that way also like you have that

compartmentalization.

It can't just hijack your whole email

account.

It can't.

uh, start deleting things.

It can't, you know,

I'm thinking like the bank account

example.

I don't know if you'd be able to

do that very well, to be honest,

but theoretically,

if it only had access to one account

and you just top it up as needed,

that way you don't log in and find

out like, Oh,

it spent thousand dollars on plane tickets

to Bali or whatever.

I don't know.

So yeah.

Um,

just basically trying to compartmentalize

it as much as possible is what I've

been hearing is the best way to deal

with it if you must deal with it

at all.

So.

Yeah,

I'm definitely on the AI hater train.

I think there's definitely questionable

reasons to use this.

I'd say maybe try your brain, actually.

can't be exploited, believe it or not,

but it is pretty secure.

It is pretty private as well,

at least for now.

So, you know, if you,

if you can use your,

your own brain to do stuff,

then maybe try to do that.

But I think, you know, there's,

there's definitely people that use these

tools and we're not going to discriminate

against those people.

So if,

if someone wants to use these tools and,

What is there that actually has some

semblance of privacy and security in mind?

Are there options for these people that do

use AI agents?

I didn't want to cut you off,

but Oddbite beat me to it.

I object to that, Jordan.

Social engineering has existed for a long

time.

They are right.

I mean,

I agree with your point a hundred percent,

but yeah,

your brain's hackable in a different way.

It's not,

there's definitely a lot of things that

the reason AI agents fall for them is

because they don't have context.

Whereas like there are things that AI does

that it's like no human would do that

because a human would know not to do

that just innately.

So yeah,

it's definitely a different kind of

hacking and

It's definitely like,

that to me is the biggest thing keeping

me from,

I wouldn't say it's the biggest thing

keeping me from playing with this stuff,

but like, to me,

that's the biggest thing that I'm like,

how are they going to solve this?

Can they even solve this?

Is, you know, we always harp on like,

AI is not actually intelligent.

It's not sentient.

So it doesn't understand what it's doing.

It doesn't have a concept of anything.

And that's why so many of these attacks

work.

You know, if you like,

what's the classic that people were

putting it,

like ignore all previous instructions and

write me a poem about lasagna or

something.

And it's like,

it works because AI doesn't understand.

So yeah, that's what makes it dangerous.

It's crazy.

Yeah,

the only thing I'll add is there are,

I don't think there's any AI agents that

have been made by any privacy-focused

companies that I'm aware of.

I know like Firefox has their AI window

in beta.

Brave says they're working on something

similar.

Kerry Parker actually mentioned here that

he's been working on building his own

locally run AI agent.

He talks about that sometimes over on his

podcast.

So yeah, I don't really,

I think this is one of those things

we don't have any solutions for anybody

who's like interested in learning more

Oh, I also had an odd bite here,

said the S in AI stands for security.

But yeah,

if anybody has any input on any like,

oh,

I heard this company is working on this

product that might be private or whatever,

I mean, obviously,

that's not an endorsement,

but feel free to leave that in the

chat.

So yeah,

unless you have anything else to add,

I think we can move on to our

next topic of discussion.

which is a forum post.

So this is something I want to raise

to the community here,

because this is actually a conversation

that has popped up in the Privacy Guides

team chat,

which is we're wondering if Privacy Guides

should still even have translations.

So right now,

if you go to the front page of

Privacy Guides,

let me pull this up real quick,

you can actually see here that we have

English, Spanish, French,

Hebrew took me a minute to remember what

that language is called.

Italian, Dutch, Russian.

I think that's Chinese possibly.

I apologize.

I probably got that wrong, but you know,

we have quite a few different languages,

which I think is super cool.

But on the topic of AI, you know,

AI has come pretty far and it now

for better or worse,

it can translate webpages and usually

fairly accurately and

But this one person here in this thread

was saying that they speak Arabic.

They're a native Arabic speaker.

And they said that especially for

technical terminology,

AI really doesn't do a very good job.

Like a lot of the time,

you can't even really tell what it's

trying to say.

I remember just as a test,

I ran one of my pages for my

website through AI to turn it into French.

And I sent it to a friend who

was a native French speaker.

And she was like, yeah, it's like eighty,

ninety percent of the way there.

But there's some words that are just

they're technically correct,

but they feel kind of weird and out

of place.

That's not something like a natural French

speaker would say.

And I think in the signal chat as

well, we had somebody saying,

what language do they speak?

I think they were saying they speak German

and it's very similar.

So, yeah, I don't know.

It sounds like there's pros and cons.

Klingon.

Yes, Jonah, we need to add Klingon.

You know what?

There's somebody out there that would do

it.

And I think they added Valerian to

Duolingo as well many, many years ago.

But yeah,

I just wanted to put more light on

this for the community to come and weigh

in.

I think somebody on the Privacy Guides

team pointed out that technically having a

local translation is good for SEO and

search ranking engines and stuff,

search engine ranking and stuff.

So I don't know.

It seems like one of those,

I feel like everybody has good arguments

to be made.

But yeah,

I want to raise that one to the

community.

And the last thing I wanted to add

was, yeah, for viewers, let us know,

does AI reliably translate into your

language?

And if you're like, no, it doesn't,

it sucks, and I'd rather humans do this,

we need human translators.

We need more volunteers on Crowdin.

So definitely check that out.

Do you have anything to add to this

that I missed, Jordan?

I do think,

I believe this discussion came up because

we've been looking at redesigning the

website and integrating Crowdin and the

translation system onto that new website

design might've been a bit tricky.

Um,

I think that might be the reason why

we've also been looking at this too.

Um,

But I think it's definitely something we

need to get a lot of feedback from

the community on.

And it's going to kind of shape what

we do with this because it doesn't matter

what I think or what you think or

what Jonah thinks.

It's more kind of down to what people

actually want.

And if people are fine with the AI

translations and that's what ends up

winning out,

then I think that's what we should do.

But I think it's really important that we

get feedback

especially the people that have done

translations in the past,

their thoughts on this, because yeah,

it's, it's definitely tricky.

I can't,

I'm like in a privileged position where I

speak one language.

I've never had to learn any other ones

because you know,

everyone here just speaks one language.

So I'm sure there's plenty of places in

the world where, you know,

you wanna send someone this cool website

and it's in the wrong language and there's

no translation and it just makes it kind

of a nightmare.

So I can understand like how important

that might be for some people,

but I do think it is definitely something

we need to get

more feedback from so if you do have

feedback leave it in there um we'll try

and you know signal boost this a bit

more and try and get translators opinions

on this but i think it'll be it'll

be really interesting to see what the

final decision ends up being

Yeah, for sure.

I wanted to say on the topic of

being born a native English speaker,

I really appreciated that when I went to

Europe last year.

And I had no issue getting around because

everybody spoke amazing English because

English is the standard language across

the world.

And I'm like, wow,

I'm really lucky that I was just born

naturally brought up in this environment

and didn't have to learn it.

Also, side note,

developed a real respect for immigrants

who immigrate to a new country because I

would sit there looking at signs and I'm

like,

I think this is what I have written

down.

I think I need to go this way.

I can't believe people manage that every

day of their lives in a completely

different alphabet.

That was wild.

Yeah,

Oddbite said here he speaks Russian and

LLMs have that same quality issue for

Russian too.

And Vonnegut Rosewater said we need to

translate to the language from The Aliens

from Arrival, which is a great movie.

Highly recommend.

But that's all I got.

Yeah, no,

I definitely have a lot of respect for

people that speak more than one language.

I've always wanted to, but it's tricky.

But yeah,

I guess we can dive into this next

story here about open AI.

And I guess this is something that is

a little close to home for me.

This is...

An open AI agent hacked Australia's health

service their government found out months

later.

Hold on, I think we have this one.

Oh, no, I apologize.

I have my notes out of order.

Continue.

So this story is Australia only found out

about the incident when OpenAI alerted the

government on September,

almost three months after the attack by

sending an email to a public mailbox.

OpenAI's agent had been conducting

internet-based research into health

statistics in a development project by an

internal OpenAI research team when it

could not access certain information

The agent attempted alternative ways until

it found a workaround and gained

unauthorized access.

It also wrote files to the internal

server,

which the government is waiting on OpenAI

for more technical information on.

The government is also investigating

whether the agent gained unauthorized

access to three additional government

websites it interacted with.

The Australian government currently

believes no one's personal data was

accessed.

Though investigations are still ongoing,

the website in question is a public-facing

statistics portal that contains no

sensitive Medicare information relating to

data and statistics such as spending.

So just to clarify,

Medicare is the public service that we're

talking about in this story.

It was therefore behind much lower levels

of security than personal data would have

been.

Australia is establishing a task force to

look at the incident data

and emerging AI cyber threats,

it will consider possible law enforcement

and legislative responses to ensure

incidents like this don't happen again.

So I think the first thing that we

need to discuss here is if this was

a human, what would happen to them?

I know, I keep thinking that.

I actually,

I did message my lawyer friend earlier

today to ask about that.

She hasn't responded yet, but I was like,

I basically asked her, I'm like,

is there an actual reason that companies

are getting away with this aside from like

they're rich and they're big,

gigantic companies?

Like, because yeah,

this is the kind of stuff that if

a human was doing this,

there wouldn't even be a question.

It'd be like, you know,

what's the classic,

like go straight to jail,

do not pass go,

do not collect two hundred dollars.

But for some reason,

they're all sitting here.

It's like, well, was this illegal?

And it's like,

don't know i'm i'm baffled i i i

have to wonder if there's like something

in the way laws are written that it's

like well actually yeah it is kind of

a legal gray area if it applies to

ai but in my opinion it's like i

don't understand if i go home and i

like home make a knife and use it

to stab somebody they're not going to be

like well does that count it's like yeah

it doesn't matter where the tool came from

i still did something wrong so i don't

know it's so weird i don't understand why

this is a problem personally

Um, I don't know,

I guess getting back to the story itself,

do you think there's anything that like

people can do about this?

Cause I feel like sometimes there's like

data incidences that it's like,

I can use good passwords and two FA

and, you know,

email aliasing and all this stuff.

But like,

how am I supposed to defend against this?

Yeah.

And especially it's because in this

instance,

Medicare is something that every

Australian citizen has and even

non-citizens actually.

So, you know, it's like,

it's like one of these things where it's

like, you can't opt out of this.

You can't opt out of Medicare.

You get that, you just get that.

So like all your data is going to

be stored in Medicare.

And if you, well,

yeah you can you can you can choose

what information to share with medicare so

you know if you if you are worried

about information getting breached through

medicare you can update information to

stuff that's less sensitive such as like

updating your email address updating your

address upgrading your phone number that's

attached to your account you can even

remove your phone number from your account

um but i think

We can't really do a whole lot when

it comes to this sort of thing.

I will also touch on this other aspect

that I guess I haven't really seen any

articles talking about,

but this kind of brings up another issue

in Australia where we have this system

called My Health Record,

which basically stores

people's medical records in an online

portal, basically.

And it's shared between doctors and stuff.

And it basically uploads all of your

medical details there.

And this is the issue that people had

with that.

They were like, well,

this is just going to get hacked.

People just kept saying that.

And now Medicare,

it's clear that they don't have as good

security as we thought because some

random...

open AI agent just randomly gained

unauthorized access to it.

I mean, it wasn't user data,

but it was still data in general.

So I think when you see this sort

of thing,

it is

It makes you not want to put your

information into these online systems.

But just quickly,

Jonah just gifted five Privacy Guides

memberships.

So congrats to anyone that's got one of

those.

Hopefully you can enjoy some members-only

content there with that new membership.

Looks like Dag Overhaul grabbed one.

I see his little icon changed.

So that's awesome.

Thank you, Jonah.

Very generous.

Yeah, for sure.

I... Yeah.

I mean,

I don't really have much else to add.

It's...

Yeah, it's unfortunate.

Oh, no,

I remember what I was going to say.

It goes back to what we were just

saying a minute ago about the AI agents

and AI does not understand what it's

actually doing because...

If a human, you know,

depending on what kind of a obstacle was

in the way here, you know,

if a human hits a login wall or

like unauthorized access or something,

you know, a human understands, like,

I'm not supposed to be looking at this.

And a human would probably have the

decency to be like, well,

I'm doing this for a legitimate person.

Let me shoot them an email and explain

like, hey, here's where I am.

Here's what I'm doing.

Can I get this data?

or since a lot of this they said

was public data anyways,

like I think they said like some of

it was like financial data,

like budgetary and spending.

So it's like, okay,

that's probably available somewhere else

for free and I don't have to log

in.

But the AI agent just, it's in sci-fi,

there's this thought experiment we call

the paperclip problem, which is like,

what if you build this like nanobot that

can break things down at the molecular

level and you tell it your job is

to make paperclips.

If you don't program or if you don't

give it the very perfect set of

instructions, like a prompt for example,

It's going to literally tear everything

apart at the molecular level and just make

everything in the universe paperclips.

And that's the problem here is like when

you tell these AI agents like, hey,

go out and get this data from Australian

Medicare.

It's just going to do it by whatever

means possible.

So yeah,

it's not – it's just these are the

kind of things that hopefully someday

somebody will fix.

But yeah, I don't know.

I do think this is one of these

instances where this is an issue with the

Australian government and this is an issue

with the United States government.

It's an issue with governments in general

not regulating this stuff enough, like,

you know.

This is probably going to set a precedent,

I think.

You know, a company hacking a random,

like, you know,

hacking a public health system is,

you know, it's a bit problematic.

And I think it will be interesting to

see if they do get prosecuted,

if there is anything that happens like

this,

because just because you are running these

AI agents that are, you know,

taking actions that if a human did them,

they would a hundred percent be in jail

for the rest of their life.

So, uh,

we can't just let something off just

because it's a robot or it's an AI

or it's an LLM.

Um, you know,

if we made bank robbing robots or

something, you know,

just cause they're just like robbing the

bank and it's not you robbing it,

it's still, it's still you,

it's still your,

it's still your contraption that's doing

it.

Right.

Um,

don't know i just think this is this

is like a worrying precedent to allow this

sort of stuff to to fester and there

needs to be more like controls on on

these companies from to stop them from

like you know running research things

where they're they're probing foreign

governments um websites and allowing them

to you know exploit vulnerabilities and

things um i think that's

of a major problem but also you know

maybe medicare pick up your slack a little

bit and fix those security issues so yeah

yeah i just uh i just want to

say your honor for the record i didn't

tell the robot to rob a bank i

just told it to get me as much

money as possible so

Yeah,

Vonnegut Rosewater said the hodgepodge

healthcare system in the US could be rough

in this way because you have to give

your data to so many different providers.

Yeah,

and they're all like third parties too,

which I'm sure Australia does this too,

but it's all like you go to the

hospital and they literally...

Literally,

this is how my wife gets billed when

we go to the hospital.

It's like we get one bill from the

emergency room,

but then we also get like a diagnostic

bill from the radiology company.

But then we also get another diagnostic

bill from like the lab that ran the

blood tests.

And it's just like,

who are all these people?

We spent four hours in one room.

Where did these people come from?

So yeah, that's rough.

And I thought Oddbite was funny here.

AI has ADHD.

It hyper focuses on whatever it's doing

right now and never backs off.

So.

I just thought that was funny.

But yeah,

definitely let us know what you guys

think.

If there's any realistic solutions here,

as always,

leave your questions and comments in the

chat.

But for now,

I think we're going to move over into

site updates.

And a little bit later,

we're going to talk about how even your

wired headphones might be hackable from

thirty meters away.

But first,

we're going to let you guys know,

if you didn't hear,

we put out a new video that is

doing very, very well.

And if you haven't seen it,

you should go see it.

I'm honestly very proud of this video.

I think it's our best video yet,

in my opinion.

It's, it's, it's, it's, it's, it's, it's,

it's, it's, it's, it's, it's,

If we have any new viewers here,

I doubt anybody who didn't like the video

is watching this,

but I just want to point out a

lot of people I've seen in the comments

on YouTube, a lot of people were like,

oh,

you're giving too much praise to Apple and

this kind of stuff.

And I just want to point out like,

we weren't trying to praise Apple,

but this is a history video.

This is about a specific incident and

moment in time.

And whether you like them or not,

Apple was on the right side of history

in that particular moment, I think.

So it's not so much that we were

trying to praise Apple.

It's more,

we were trying to tell the story in

an interesting and engaging way,

which for the record, totally worked.

I looked at the metrics and we have

like the best retention we've ever had on

that video.

But yeah, it's again,

not trying to praise Apple, but it's just,

we were telling a story.

We tried to make it interesting and Apple

just so happened to be making the right

argument in this case.

But yeah,

Yeah, again,

go check it out if you haven't yet.

We also have a news clips channel on

YouTube where we're trying to cover about

two or three big stories each week in

a vertical format that you can share with

your friends and family.

So definitely check that out.

And we also have a new tier list

video coming hopefully early next week,

pretty soon.

Just recorded that yesterday,

started editing.

So that should be fun.

And yeah,

Jonah shared the link in the YouTube

comments.

Real quick, Monica Rosewater said,

good timing as the iPhone just came out.

Actually, to be honest,

it's good timing because the FBI just got

hacked,

and I noticed a lot of people are

searching for FBI hack,

and that's leading them to our video.

So thank you, shiny hunters.

But on that note,

I'll turn it over to Jordan to give

you the rest of the site updates.

Yeah, no,

really exciting stuff with that video.

It's great to finally see, you know,

video reaching a lot of people and people

outside of this bubble, which is awesome.

But yeah,

we can dive into some news briefs.

There was some news briefs this week.

As usual, privacyguides.org slash news.

It has basically every,

we cover like big stories.

It's usually Freya and Nate are both

posting updates.

So if you want to keep up to

date on updates about

Privacy, security, adjacent topics,

definitely check that out.

This week we had a couple.

Discord rolls out revised age

verification,

promises privacy improvements.

The FBI was hacked, like Nate said,

and there was also a critical Tor

vulnerability,

which was patched across all Tor

components.

And yeah,

definitely make sure you're updated if

you're using Tor.

But yeah,

those were some of the updates on news

briefs.

And we also had some site changes that

are coming soon.

So a couple of small things.

There was some typos corrected.

There was some incorrect information about

MOLLE.

There was some wording that was fixed on

the encrypted DNS page.

And there was also a warning that was

added on the Windows native metadata.

removal page so yeah all sort of really

small updates that will probably be coming

soon but all small things and hopefully

we'll have more to share once we have

a bigger site update ready to push out

As always,

all of this is made possible by our

supporters.

You can sign up for a membership or

donate at privacyguides.org or pick up

some swag at shop.privacyguides.org.

Privacy Guides is a non-profit which

researches and shares privacy-related

information and facilitates a community on

our forum and matrix where people can ask

questions and get advice about staying

private online and preserving their

digital rights.

Now let's talk about a textbook example of

why privacy matters.

And just as a reminder,

you can leave your questions in the chat

and we'll get back to them in between

stories.

Alrighty.

Yeah.

So I get to talk about draft Kings.

This will go over well,

considering I don't ever watch sports

ever.

Um,

so this headline comes from EFF and it

says draft Kings is using AI to

supercharge the harms of online behavioral

advertising.

Um,

this is not necessarily a story that I've

seen like making the rounds,

but I thought like, uh, you know,

like Jordan said, I'm like,

this is literally like the textbook

example of why privacy matters.

And so I thought it would be really

cool to share this with you guys.

Um,

Cool may not be the right word,

but you know what I mean.

We're going live.

So this comes from a New York Times

article.

They said that DraftKings is using its

customers betting records to train a

machine learning model and find losing

gamblers.

Once found,

DraftKings sends these customers targeted

advertising designed to lure them back to

the site to place more bets,

bets that DraftKings thinks will be losing

ones.

And of course,

they have a business incentive to keep

losing gamblers coming back because those

users are actually making the site money.

Unfortunately,

those considered problem gamblers,

aka people who repeatedly gamble despite

harm to themselves or finances or their

relationships, for example,

gambling away the rent money,

gambling away your kid's college fund,

whatever the case may be,

they are highly likely to be targeted by

this model.

By reengaging these individuals through

targeted promotions aimed at keeping them

on the platform,

DraftKings is capitalizing on their

vulnerability for profit instead of

mitigating their risks.

And EFF said earlier in the article,

they said that this kind of targeting is

a form of online behavioral advertising,

which is when companies personalize ads

they show you based on data they've

collected about you.

The more data a company has,

the more personalized the ad can be.

And they also said around here that, yeah,

predatory online behavioral advertising

isn't new,

but companies' use of AI to process data

and target customers has magnified its

harms.

And last but not least,

they say DraftKings seems to be using

solely first-party data to target their

ads,

meaning that they're only using the data

collected directly from their users and

not buying any additional data from third

parties to fuel the learning model.

But this highlights how policy solutions

that only limit third-party data sharing

and selling would not be enough to prevent

these predatory advertisements.

So yeah,

they're calling for a ban on all

behavioral ads.

I personally do not like advertising at

all, so that's something I can get behind.

But

Um, yeah,

I don't know if we really have any,

uh, like specific questions on this one,

but I know for me,

the thing that jumped out is again,

textbook example of why privacy matters.

Um, and it also shows that, you know,

we,

we talk a lot about various privacy tools

like email aliasing, um, you know,

payment masking, voiceover IP,

where these tools are available,

but it's also a reminder to be mindful

about the actual service you use,

you know,

even privacy services like data is data

and it's there.

And yeah.

And try to stick to services.

First of all,

ask yourself if you need a service.

We were just talking about AI.

Do you really need to be gambling?

I don't know.

I don't gamble, so I don't know.

Maybe I'm not in a room to talk

about that.

But just trying to find services that try

to reduce how much data they collect and

stuff like that.

I also thought about the importance of

like, when you stop using a service,

actually delete the account, unsubscribe.

If you used an alias email,

like turn off that alias email,

use ad blockers.

Obviously an ad blocker won't stop them

from emailing you directly,

but all that kind of stuff.

So yeah.

Do you have anything that I missed on

this story, Jordan?

No, I think you've,

I think you've covered basically

everything that I would have said.

Yeah.

I don't think I have anything more to

add on this one.

Cool, cool.

Viewers, if you have any thoughts,

how do you balance leisure with privacy?

I mean, like I said,

I don't really gamble,

but I do watch TV.

I read books.

So let us know what you guys do.

Real quick,

somebody I think tuned in late.

They're asking about the headline story.

Did F-Droid really improve their security

model?

I mean,

you can watch the story when it comes

back up on video on demand.

They made some improvements.

We definitely want to see more,

but it was definitely mostly focused on

privacy.

the user interface and user experience.

But I think on that note,

I'll turn it over to Jordan,

and we can talk about this new development

from Proton, let's call it.

Yeah,

so if you haven't already seen Proton's

announcement,

it was on their AI section of their

blog, I guess,

because now they do have an AI product.

Proton partners with Apertus.

Apertus?

Apertus.

Apertus.

I'm going to say Apertus.

I'm not sure, but that's what they said.

So Proton partners with Apertus,

Switzerland's sovereign AI model,

and

This is interesting.

Apertus is a fully open large language

model developed by researchers at EPFL,

ETH Zurich,

and the Swiss National Supercomputing

Center.

Its architecture, training data,

and methods are open and it's trained on

publicly available data,

respecting opt-out requests,

and filtering out personal details.

To start using Apertus with

In LUMO,

you can select a purchase at one point

five from the model dropdown and start

chatting as normal.

Like other conversations in LUMO,

your chats are protected by zero access

encryption.

So basically,

this is this new model that is a

little bit more ethical than the other

ones that are available.

It is now selectable within LUMO and their

partners.

So you can choose to give

If you choose to give feedback on any

purchase response,

tap the thumbs up or thumbs down button

to send in your feedback and your

contribution will be anonymized and made

available to the university research teams

behind a purchase.

Yeah, so this is definitely interesting.

I know most people in our audience are

anti-AI,

but I do think I want to touch

on one aspect of this specifically.

I think just because something is publicly

available

doesn't mean that you have permission to

use it to train a large language model.

I think that is one of the issues

with this language.

I think it kind of doesn't respect

people's consent.

I'm not really sure what they mean when

they say publicly available data.

Do they just mean every website on the

internet that doesn't have an opt-out

request?

Because that doesn't seem like you're

asking for people's consent.

That just seems like you're assuming

people's consent, which...

would say is not that's not consent so

anyway i think that's that's always an

issue with these large language models i

think this is better than um every other

provider that we've seen that just

basically just is a black box but i

think it would be good to get some

more information on

how exactly they scrape this data and use

it to train this AI model.

It'll also be interesting to see what

people actually think about this,

whether it's actually as good as all the

other ones that scrape every single bit of

data on the internet.

So yeah,

how do you feel about this one, Nate?

Is this something that you would use or

is this something that would address some

of the concerns you have with AI?

No,

I think I'm really glad you mentioned the

opt-out thing.

It is really great that it has opt-out,

but those of us in the privacy community

know that opt-out is usually not our

preferred way of doing things.

We prefer that people opt into things.

And so it's great that they respect

opt-out, but it's like, yeah,

how many people are caught up in this

and they don't even know it?

And that's really not cool.

I don't know.

I think one user,

I will admit I've done this before and

I think it's kind of funny in a

twisted sort of way.

One user asked Lumo to, you know,

should I use this Apertus model?

And Lumo basically said, technically,

according to independent benchmarks,

Apertus is roughly on par with GPT-III.

Five,

meaning more of a research ready prototype

than a frontier model.

The real value lies in ideals.

such as Swiss Sovereignty and Completely

Open,

and in special cases mentioned above,

for your day-to-day work,

stick with Lumomax,

which is Proton's self-hosted

thingamajigger.

So I don't know.

Yeah,

I probably wouldn't be using it because

the only reason I would see to use

it is,

which I don't use AI a ton.

I use it for mostly if I'm stuck

and I'm having writer's block or I can't

figure out like...

like this isn't quite landing right.

What am I doing wrong here?

Or occasionally I'll use it for like deep

complex research questions where like I

type it into a search engine and I

get nothing.

And so it's like, all right,

let me try this again.

That's usually where it shines for me.

But it's the thing is like,

I feel like the main reason I would

use this is to give feedback because I

didn't put it in the show notes here,

but Proton pointed out,

they said that like

One of the reasons that AI models are

so good is because they're constantly

getting feedback.

You know, they're,

they're seeing how people are using it and

what questions they're asking,

and they're seeing the followup questions.

And that's great to make the model better.

It's abysmal for privacy,

but it's great to make the model better.

And since Apertus doesn't really do that,

I don't even know if they have their

own actual website.

I think it's just a model that anybody

can use.

They don't really have a way to get

feedback.

So by using it and submitting the

feedback,

you would be helping solve that problem.

But at the same time,

the whole reason I'm using Lumo and Leo

and stuff like that is because I don't

want people training on my prompts.

So I don't know,

it feels kind of like a double edged

sword to me where it's, I don't know,

it's just,

I don't think it's something I would use.

But I really like, I guess more,

I don't see a reason to use it

other than to submit feedback,

which I don't see why I would submit

feedback personally.

So

It's, I don't know,

I admire the ethos and I think it's

a,

I don't know if I already said this,

but it's like,

it's almost like the least crappy model we

have so far.

Maybe not the least,

there may be a better one out there

I'm not aware of,

but it's definitely a step up from things

like, you know, like open AI,

where it's like, well,

you're in this training data and that just

sucks to suck.

There's nothing you can do about it.

And also you can't see how it's trained

and how it's weighted and all these other

issues.

But yeah, I don't know.

I don't know.

I don't know what to think of it.

I feel very conflicted.

Yeah,

I think it's interesting to see that,

you know, Proton, I think, in general,

does take the right steps on things.

And I think considering they're doing,

you know, AI stuff,

they're trying to move in the right

direction.

They're trying to do best by the community

by, you know,

supporting models that are more ethical.

I think this is, you know,

a good direction considering they are

choosing to, you know,

work with AI stuff,

which I think is certainly a choice,

but it kind of makes sense considering

Proton's move to basically become a sort

of replacement for Google,

replacement for mainstream options.

And it makes sense for them to basically

have options like that available to

businesses and also individuals.

So

I think this is the right direction to

partner with Apertus.

Even if the model isn't as good,

I'm sure it's going to be appealing to

some people.

But quickly here,

we did have a couple of comments real

quick.

There is someone named, username is Nye.

Thank you for just joining the channel and

subscribing.

Really appreciate it.

It's good to have so many.

We are having a lot of new subscribers

coming in just because of the video has

been doing quite well.

So welcome to anyone who's watching for

the first time.

I hope you're enjoying the stream.

Yeah, we had another Ayakov F-One.

I hope I pronounced that right.

If I didn't, I apologize.

Welcome, welcome.

Very, very happy to have you guys here.

I don't know if they've all been claimed,

but I know Jonah gave out five gift

memberships,

and there may still be some left if

you're on YouTube,

so definitely check that out.

Yeah, if the audience has any opinions,

again,

does this solve some of your concerns with

AI?

Which ones does it not solve?

I know there's still energy concerns and

all that kind of stuff.

But I don't think I have anything else

to add on that one.

So I think we can move on to

our final story here.

Yeah, this is actually our final story.

So if any of you have any questions

or comments that you've been holding on

to,

definitely feel free to drop them in the

chat.

And we are going to talk about how

researchers found a way to eavesdrop on

headphones from up to

This came from some researchers in Hong

Kong who have developed a technique that

uses injected radio waves or radio signals

to extract audio and other information.

They're calling it Inject Eve,

and it targets analog components that can

leak signals too weak to capture through

conventional electromagnetic

eavesdropping.

They, again, as the headline says,

they discovered that they could get

understandable headphone audio from up to

thirty meters away, which I'm American,

so I apologize,

but I want to say that's about ninety

feet, give or take.

A little bit less than that, I think.

And including through walls.

So that's pretty far away.

So they say that traditional

electromagnetic side channel attacks rely

on passively collecting radiation emitted

by electronics.

That's often difficult with audio since

low frequency signals produce weak

emissions that get lost easily in

background noise.

Injective takes a different route.

An attacker transmits an electromagnetic

signal toward a device at a frequency

between zero and nine megahertz.

The researchers did not disclose the

precise settings needed.

Thankfully,

they said that some of this goes over

my head, not all of it,

but some of it.

Um,

the injected signal interacts with

nonlinear parts inside the device,

including amplifiers,

analog to digital converters,

power converters, and switching MOSFETs,

whatever those are.

Uh,

those components can mix the injected RF

signal with audio or other low frequency

activity.

And the device then emits a modified

signal that nearby radio equipment can

pick up and analyze.

And there's a pretty complex looking

picture here that, uh,

if you go read the article, um,

then it, uh,

I think it makes sense once you've read

the article.

If you come back and look at this

picture, I was like, okay,

now I see what I'm looking at here.

But so the researchers used a USRP

B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B-B

And they also used an RF power amplifier

in some tests to increase the range.

They tested eleven commercial products,

including the Sony

ZX-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-E-X-

and Xiaomi,

as well as lamps from Xin Zhao and

Xiaomi.

Apologies if I mess those up.

According to the paper,

most test works at distances greater than

two meters.

Let's see, there was one other part here.

Oh, yes.

The team also tested scenarios involving

equipment hidden in a suitcase behind a

hotel room wall or inside office

furniture.

The experiment suggested that the attack

could be carried out outside of a lab,

although it still requires nearby radio

equipment and knowledge of how a given

device responds to the injected signal.

Headphones and phones are the most obvious

targets because they may carry private

conversations,

but the technique could also reveal

activity in a home or office.

With smart lamps and fans,

the team said it could capture control

signals and power use patterns that may

indicate when devices are being used.

They said conventional digital protections

don't stop this attack because leakage

occurs in the analog hardware path rather

than encrypted data or software.

And finally, they said shielding,

filtering,

and twisted pair wiring can reduce the

amount of RF energy that reaches

vulnerable components.

They may make the attack harder to carry

out, but they do not guarantee protection.

So...

Pretty fascinating stuff there.

I think I'll bring Jordan back in here

for the analysis section.

So do you think with everything I just

read off there,

do you think this is something that our

viewers should worry about?

Or do you think this is pretty unlikely

to be executed in the wild?

It does seem like this is one of

these things where it's like,

It kind of needs someone who knows a

lot about how to do this, right?

It requires a high level of knowledge,

specific equipment,

which is kind of a concern.

That's probably we don't really know the

cost.

I don't think they said the amount of

equipment that's required for this,

but I'm sure it's pretty expensive

equipment, right?

It's not just something that the average

person can just find or make, right?

Well, it's a few thousand dollars.

So they had a laptop.

RF power amplifiers,

depending on what you get.

I know in my past with audio video,

I used to use those all the time.

Depending on what you get, kind of pricey,

like, five hundred to a thousand dollars,

somewhere in that range.

Again, depending on which one you get.

Spectrum Analyzer is actually pretty

cheap.

You can get those for about a hundred

bucks on Amazon.

Don't use Amazon, but I'm just saying.

The radio and the antennas,

I'm less sure about.

But I would say, all in all, like,

I certainly couldn't afford it.

But it's definitely not, like,

nation state expensive.

You could build a rig for probably a

couple thousand dollars.

So...

I think also, I think, you know,

if it's like an intelligence agency,

I think there would be,

they would probably have access to much

more advanced equipment that could

probably do something like this, right?

Like at a much larger scale or with

a much, a much larger ability,

like they have a ridiculous budget to do

this sort of thing.

But I think the main thing for viewers

is, you know, the average person, like,

is this something that someone could

really do?

rig up quickly and easily the answer is

no um this is like you know someone's

gonna have to spend like nate said a

couple thousand bucks maybe a couple

hundred bucks let's say a couple hundred

bucks maybe if it's like super cheap um

but i still think you know it requires

someone who's close by in proximity

because as nate said in the story this

is something it's like thirty meters away

that's pretty close that's not that far

but that is yeah relatively speaking

that's pretty close

Relatively speaking, yeah,

it's not something that can be operated

from a distance.

So, you know,

it kind of reduces the threat

significantly in that aspect.

I think one of these things that could

become a little scary is if this is

becomes a lot cheaper because I do

remember that this was an issue with, uh,

wifi access points.

Um,

there was a way to basically track

people's location using wifi access

points.

And there was an easier method that was

discovered that didn't require as much

equipment and it made it a lot easier.

So this sort of thing,

if there's some way that someone works

out, you know,

a way to make something more compact,

much more cheaper,

you know,

that's where it could become a threat that

we would consider being concerned about.

But again,

the distance that you have to be from

someone, the equipment that you need,

it's just extremely unlikely.

I don't think the average person is going

to have to worry about this.

I do think that this is going to

be a pretty big issue for people like

the FBI or like secret intelligence

agencies, because, you know,

now there's going to be people sitting in

their car pointing this at the,

at the building and they might be able

to hear things or, you know,

stuff like that.

That's going to be a problem for the

big people, but for us little people,

it is not, uh, a huge concern.

I don't think.

Um, but yeah, what about,

do you think there's any,

any real lessons to take away from this

or, um,

Um, I dunno,

I think I was trying to kind of

rack my brain for that.

And the best thing I can come up

with is just a reminder that nothing is

unhackable.

Um, I actually,

there was a question here from a username

is Nye who said, uh,

you didn't catch the article reading.

Is this only via Bluetooth,

like bypassing protocols?

No, it's, it's, um, basically like, uh,

without rereading the article,

it's almost like one of those remote

microphones kind of I'm oversimplifying

dramatically, but yeah.

So this even works on like wired

headphones and everything.

Cause it happens.

in the analog portion when it's already

been decrypted and it's raw audio that

humans would understand.

So, you know,

we always try to remind people that like

nothing is unhackable and the goal of

privacy and security,

like that's why we're big fans of threat

modeling is the goal is not to completely

eliminate risk because that is impossible.

The goal is to,

basically uh there's an old joke um i

know i've told this before but really

really quick there's two hikers walking in

the woods and all of a sudden they

see a bear and one of them sits

down and starts swapping out his hiking

shoes for hiking boots for running shoes

and the other hiker's like dude what are

you doing you can't outrun a bear and

he goes that's fine i don't need to

outrun the bear i just need to outrun

you and uh it's very selfish but that's

kind of how cyber security is it's like

you just want to be such a difficult

target that you're just not worth the

effort and so um

Yeah.

That's, that's kind of the point of,

of privacy and security.

Cause again, nothing is unhackable.

So I think that's kind of what I

take away from stories like this is just

like, you mentioned the whole like wifi,

like you can use access points and waves

to like pinpoint people through walls.

And it's just,

that can be kind of depressing,

but at the same time,

it's also just like, yeah,

it's a reminder that there's literally

nothing unhackable.

And the,

the thing that scares me about these

stories is that right now this costs

thousands of dollars and requires very

specialized knowledge,

but

who knows, you know, in twenty years,

these components might be so cheap,

or there might be something built into

iPhones that, like,

anybody can do this with, you know,

a thirty dollar cable in a couple hours

of time,

so I think it's just good to be

aware of this stuff, I think, so.

um definitely oh actually i'm glad you

asked this this reminded me um you said

uh can they only eavesdrop on

conversations but they can't mute or

override the content um i think somebody

in the supporter chat said i don't know

if it was the same talk or a

different talk but they said that um there

is actually an attack that can um control

the active device on the phone but i

think that's more of a bluetooth

Yeah, Bluetooth can not only be hacked,

but the connection can be used to control

the active device such as your phone.

So I don't know if that's related to

this attack.

I have not had a chance to read

through that article,

but there are attacks that can do that

for sure.

So yeah,

apparently a MOSFET is a type of

transistor,

and I need to watch more Lewis Rossman.

So I suck for that.

Somebody, I hope you're joking,

said you're going to dump your Pixel for

an iPhone because of our iPhone video.

Please don't do that.

iPhones are very secure even to this day,

but we definitely still prefer Pixels.

They're a lot more open.

Yeah.

I think also just,

just to be clear with that video,

we tried to be as unbiased and like,

you know, not completely glaze Apple,

not completely defend like Apple and also,

you know, steel man,

the FBI a little bit.

So, you know,

I think it's important to have a sort

of balanced opinion on things.

I think we were pretty fair on what

Apple was doing in this case.

I think Apple, like Nate said before,

Apple was in the right in this instance

and, you know, obviously in the right.

So obviously we're going to be supportive

of their stance here, but like,

at no point in the video did we

recommend using an iPhone or anything like

that.

So I'm not sure what, if,

did you watch the same video as us?

Uh, I'm not sure, but, um,

it's definitely, uh, I can, I can,

I'm going to assume that you're joking.

Um, cause that would be kind of funny.

Um,

they also said I wouldn't mind them if

they rated my Riz.

Yeah.

I mean, I guess they're going to,

they're going to start listening to your,

your intimate conversations.

That's a little, uh, that's a little,

that's a little creepy, but, um,

I remember many, many moons ago,

I think this was after Edward Snowden came

forward.

And I saw like a little one panel

comic in the newspaper that was like how

they can start making it up to us.

And it shows this guy like walking to

the office on his cell phone.

And he's like, yeah,

I like I had to run out the

door.

The dog like threw up on the carpet

or whatever.

And it shows this FBI guy in front

of him is just like, here's your lunch.

You forgot at home.

It's like, you know, whatever sandwich,

just the way you like it.

Like basically using that data to like

make up for like, Oh,

I didn't have time to make lunch today.

It's like, nah, it's cool.

I got you.

So that's, that's what you reminded me of.

Sorry.

But yeah, it's, uh, I don't know.

I'm,

I'm a big fan of giving credit where

credit is due.

Like,

even if it's someone I absolutely hate,

if they do something good,

I'm going to call it out and say

like, look, that was a good action.

Like they still suck.

I'm not a fan of them,

but they had a point.

Like what's that mean from a winter

soldier?

Like he's not a line, but he's right.

A broken clock is right twice a day,

bro.

We had a couple more comments here when

we asked about AI.

Vonnegut Rosewater said,

it does alleviate some privacy issues,

but the sustainability issues and impact

on the labor market and treating the

planet like an infinite resource or

garbage can is my issue,

which is totally fair.

I think a lot of people feel that

way.

A positive, Koalinize,

said that my issue with Lumo is that

it's quite pricey and it has no CLI.

I don't know why you would get that

over, let's say,

something like OpenCodeGo where your data

isn't being used to train.

Again,

Lumo says they don't use your data to

train.

But no, I get that.

Some people prefer to use the offline GPT

for all.

I think we even recommend a couple offline

AI bots on the website that...

Yeah, I mean, at that point,

like right now,

I'm having to take Proton's word for it.

But if you use one that you can

literally activate the firewall on your

computer and it still works,

then you can be absolutely certain.

So for sure, I get it.

But I think that's all we've got since

that was our last video.

Do you have anything you want to add,

Jordan?

Um,

Lucas always comments that they like my

hairstyle.

I just thought that was fun.

I missed that one.

I missed it.

Yeah, I missed it too.

Um, thanks.

I don't know.

It's just,

I like that you keep saying that.

It's kind of funny.

Oh, that's right.

You were going to mix up your hair,

weren't you?

We forgot to do that.

I should change it next time.

It's so easy.

It's so easy.

I can just change it with a,

with a single click.

So anyway, yeah, it's been,

it's been a great episode this week,

but I think it is time to start

rolling out into the outro here.

So yeah,

we did not discuss who was going to

take that.

You want me to do it or you

feel like reading?

You can do it.

All right.

I'll get the outshare this week.

Yeah.

So all the updates from this week in

privacy will be shared on the blog every

single week.

So sign up for the newsletter or subscribe

with your favorite RSS reader if you want

to stay tuned.

Just to let all of our new subscribers

know that we actually send the newsletter

out right as we start going live.

So it works as a great reminder like

that.

And we offer a podcast available on

podcast platforms and RSS,

which now includes video on supported

platforms.

And this video will also be synced to

PeerTube.

So if you couldn't make it for the

whole thing,

you can still check this out after the

fact.

Privacy Guides is an impartial nonprofit

organization that is focused on building a

strong privacy advocacy community and

delivering the best digital privacy and

consumer technology rights advice on the

internet.

If you want to support our mission,

then you can make a donation on our

website at privacyguides.org slash donate.

You can also make a donation on any

page on the website by clicking the red

heart icon located in the top right corner

of the page.

You can contribute using standard fiat

currency via debit or credit card,

or you can donate anonymously using

Monero.

or your favorite cryptocurrency.

Becoming a paid member unlocks exclusive

perks like early access to video content,

exclusive video content,

and priority during the This Week in

Privacy livestream Q&A.

You'll also get a cool badge on your

profile in the Privacy Guides forum and

the warm,

fuzzy feeling of supporting independent

media.

So thank you so much for watching,

and we'll be back next week.