Reddit further erodes anonymous usage,
cops can now bypass the iPhone's automatic
reboot,
and a new attack that can track you
across all operating systems.
All of this and more coming up on
This Week in Privacy number seventy-three,
so stay tuned.
Welcome back to This Week in Privacy,
our weekly series where we discuss the
latest updates with what we're working on
within the Privacy Guides community and
this week's top stories in data privacy
and cybersecurity while answering viewer
questions.
I'm Nate,
and joining me this week is Jonah.
Howdy, Jonah.
It's been a minute.
Yeah, it's good to be back.
And I've been having a good week with
the video stuff that's been going on.
That's been going well for you.
So I hope we could talk about that
later.
But how have you been doing?
Pretty good.
Yeah.
Just, uh, busy with the videos.
Um, like you said,
we'll talk about that later,
but we put out a couple of videos
in the last couple of weeks and we
got more on the way and, um, yeah,
so I mean, good week for sure,
but definitely keeping super busy.
Sweet.
All right.
Yeah, I think with that,
we'll go ahead and jump into the latest,
biggest news from privacy and security in
the past week.
As a reminder to any viewers,
if you have any thoughts or questions
while we're going over the story,
feel free to leave it in the chat
and we will address them at the end
of the story.
So first up,
we're going to talk about Reddit.
And this headline,
this comes from Ars Technica,
says Reddit is putting more limits on
old.reddit.com.
So back in July,
some of you may remember that Reddit
started requiring that users be logged in
to access old Reddit,
which real quick for anyone who doesn't
know for now,
we'll see how long this lasts.
You can literally go to old.reddit.com and
it's the old version of Reddit.
It definitely looks kind of dated these
days, but it's also a lot lighter.
I think there's like less JavaScript.
I think there might even be less trackers,
but don't quote me on that.
But most notably,
It's usually also a lot less strict about
requiring you to sign in.
Some of you may know that if you
try to go to Reddit right now and
you're not signed in,
and especially if you're using a VPN,
it's probably going to block you and force
you to sign in.
Old Reddit didn't do that.
So a lot of privacy people preferred old
Reddit because, again, it was lighter,
it was a little bit less of a
nightmare, and no sign-in required.
But now...
uh the article says today but this is
you know a few days old it says
that the social media platform announced
additional upcoming restrictions on old
reddit a reddit post from an employee said
that in the next few months will further
limit access for logged in users to only
those who have used old reddit in the
last six months which covers the majority
of all old reddit users so if you
want to be grandfathered in now is your
time to uh go log in they said
there will be an exception for moderators
who are still able to view old reddit
regardless of when they last log uh last
used it as long as they are logged
in
And they claim that this is basically to
help reduce scraping and automated abuse.
Yeah.
The article says that there's concerns
that they may completely shut down old
Reddit one day, which...
Yeah, well, let me see here.
Yeah, I mean,
I guess we're at that part of the
article.
It does say down here that in twenty
twenty five,
Huffman said the old Reddit would remain
online as long as people are using it.
But in August, he changed his tune,
saying in a post that the reality is
we're getting to a time where we need
to make some changes.
And those changes would probably include
limiting access,
migrating important uses and rebuilding
old Reddit on a modern tech stack.
So I guess technically it doesn't sound
like it's going anywhere,
but it may not survive in a noticeable
form.
And then.
This is the one that really pissed me
off.
They kind of threw this in here at
the end.
But Reddit is also going to stop
supporting RSS feeds on November,
because RSS is now a common surface for
large-scale scraping and automated abuse.
It will still be available for moderators
who use it for workflows through supported
alternatives,
which I think they said there's an app
called Discord Relay and some other stuff.
Yeah, that's super, super nifty.
I think that's kind of it as far
as stories go or as far as details.
Jonah,
I think I'll turn it over to you.
I know like you, for example, you say,
if I remember correctly,
you're not a super big Reddit user.
And I personally,
I kind of go through phases.
Like right now,
I've actually been on Reddit quite a bit,
but I'm probably going to stop using it
a little bit for a while.
So why does this matter for people like
you and soon to be me who may
not be heavy Reddit users?
Well, you know what?
I think I'm kind of in the same
boat where I use it kind of off
and on.
The reality is I've experienced this a lot
lately where a lot of just niche
information is still only available on
Reddit.
It's just been such a prolific form for
such a long time that
A lot of discussions are still taking
place there,
and especially if you can find older
discussions about things like from two
years ago or something,
instead of all of the AI slop that
is now kind of permeated the search
results.
I think that those Reddit results tend to
still be a bit better,
which is it's a shame that it's all
locked down into that one ecosystem.
But that is, of course,
the main business strategy of Reddit and
why they can make changes like this
because people are kind of stuck using it,
you know?
Yeah, for sure.
The RSS thing really pissed me off because
to me that is just such a
it feels like, um,
what's the word I'm looking for?
Uh, like,
like a canary in a coal mine of
like the direction that the web is headed
in where the web used to be this
open.
And it's funny cause like, I remember, um,
I'll be honest,
I don't know how old you are.
So you may or may not remember this,
but when I was about in high school,
so about like the mid two thousands, um,
RSS really popped off in the mainstream.
And it seemed like every single website
you went to had RSS.
And I didn't even know what it was.
It's almost like apps.
When apps popped off in every single
website, it was like, download our app.
And so every website I went to was
like, we have an RSS feed.
And now what's funny is a lot of
them still support RSS,
but they just don't broadcast it that same
way anymore.
So I don't know where I'm going with
this.
With them saying we're not going to do
RSS anymore, to me, it's just such a...
like it feels like they're just really um
like the whole web is turning into this
walled garden you know like twitter
requires logins now uh facebook and
instagram have required it for a long time
now reddit's doing it it's really sad to
see the internet getting increasingly
siloed and closed off like this and super
turning against what the web was supposed
to be especially considering who was
involved in the founding of reddit but
yeah
Yeah, social media definitely, I think,
played a big part in people moving away
from like personal websites and blogs and
that sort of thing.
It's funny,
I was just watching a video about it
was from I don't know when it was,
two thousand one or something.
It was a video of Steve Jobs kind
of announcing the first Apple store that
they opened and they were selling software
like create your own personal website.
Like at the time,
that was just the thing you would do
online.
And now that's kind of been
uh you know centralized onto all of these
platforms because people don't want to
people don't want to do that but that's
at the risk of um you know these
platforms being able to do whatever they
want with your content at at any time
um and obviously i think reddit is really
no different than a lot of other social
media platforms in the sense that they
have
just awful data practices.
They're doing all of this crazy stuff with
like tracking you across the site.
It's obviously an advertising supported
platform,
and then they're also using that content
on the back end to sell it to
AI companies for for training and stuff
like that.
So
Yeah,
that's kind of just not a fantastic
situation that they've created.
And this is just kind of another anti-user
approach to things.
It's unfortunate that everything just kind
of needs an account these days just to
access.
But we've talked about that with Twitter
or X switching to that as well.
Reddit is kind of no different.
And yeah,
I'm sure this is going to upset
some contingent of Reddit users.
But I think Reddit in general has just
been going downhill for some time.
And I don't know if old Reddit really
saves people from a lot of the stuff
that they're doing.
Fair.
Yeah, I'm glad you mentioned the AI thing.
That was something I wanted to make sure
we mentioned.
Reddit struck a deal with,
I think it's OpenAI,
and now they sell user data to OpenAI
to help train the models.
And
Yeah, real quick,
I do remember those days.
Like you were saying back then,
there were things like GeoCities that were
real plug and play.
And like you said,
everybody had a website.
I think MySpace was probably the first
time that really took off because they had
that ability to inject CSS code and
customize your page.
But even before that,
it was pretty common to run into people
who had a random, you know,
for whatever reason.
So...
Yeah.
I also just want to point out,
I know you kind of touched on this
at the beginning, but unfortunately,
there are still some privacy projects who
only or primarily use Reddit or sometimes
Discord.
Proton.
That's exactly who I'm thinking of.
They're not the only ones,
but they're probably the most prominent
one.
Yeah.
So even when we step back from the
privacy stuff, we think like, oh, well,
you know, we don't need Reddit.
Like, you're right.
We need them to get the memo, though.
It's really frustrating.
So I think that'll bring me to,
you know,
is there anything that we can do about
it?
Are there any alternative platforms?
Or do you think it would help to...
Is there any kind of protest or anything?
In some cases,
like the one you just mentioned with
Proton and these other companies who are
using Reddit as, like, their main...
news announcement form for whatever
reason.
I think it's kind of unfortunate.
Getting them to switch would be great.
But there are alternative ways to access
Reddit.
FoundDoug in the chat mentioned RedLib as
a good self-hosted frontend for Reddit.
We do recommend these frontends for
accessing a lot of social media sites on
a read-only basis.
I don't know if there's...
I haven't looked into...
red lips specifically too much.
I don't know if there's public instances,
but stuff like that that can kind of
abstract
the content of the site away from like
Reddit running a bunch of JavaScript in
your browser and tracking you,
I think is generally a good thing to
do if you're just trying to access Reddit.
But I would certainly just I mean,
because this is what we do and I've
been a big proponent of, you know,
websites and organizations kind of
starting their own forms,
running their own blogs and comment
sections and kind of having their own
communities separate from
these major platforms,
because if you do everything on your own
domain name and you kind of do it
yourself,
that as a as an organization or a
business that provides you with a lot of
safety because you're not just at the
whims of however the business that you're
trying to use operates.
And I think that a lot of people
don't realize that because from a short
term perspective,
you know, having all of this,
all of these tech resources available for
free and very easy to set up,
it's obviously appealing.
But at the same time,
Um, it's just,
it's just a way for you to basically
send all of your users or all of
your customers to these other platforms
who will eventually lock you away from,
from those users,
from your own users and customers.
We've seen it on like Facebook,
for example,
where everyone was like encouraged to make
Facebook pages.
And then all of a sudden,
now that everyone's on Facebook.
Now,
if you want to communicate with people on
Facebook effectively as a,
As a business, for example,
now you have to pay Facebook a bunch
of money for advertising, right?
That's the main goal of really
locking people in to these platforms,
I suppose.
So certainly there's some Fediverse
alternatives.
I'm not super familiar with a lot of
them.
I haven't used them recently,
but Lemmy's around and I know some
communities use that.
I'm a big proponent of Discourse,
the form software.
Thankfully,
I've seen a lot of open source
communities,
especially like Linux distros,
kind of adopt Discourse as the de facto
form software of choice for a lot of
these and for good reason.
I think it's a good.
setup for organizations and businesses.
And of course,
we use that for our form,
discuss that privacy guides.net.
So stuff like that, setting that up,
having going back to like a more
decentralized web,
I think benefits a lot of people,
I think it certainly benefits users.
But it also has a lot of benefits
for businesses to kind of get away from
these from the social media sites that are
shifting to more predatory practices,
I think.
Yeah, for sure.
I think, um, with like, uh,
like discourse,
that's probably not ideal for like a
Reddit replacement per se,
like from a user perspective.
But yeah,
especially when we think of like bigger
projects, like, uh, like Linux distros,
proton Tudor and like places to get help
and tech support.
Like, yeah.
Discourse is,
I think really good for that.
And I think, um,
I think we'll talk about this probably
more in the site updates,
but I left a comment last night on,
uh,
our latest video on the forum where the
comments, uh,
it felt, uh,
cause for those who don't know,
our last couple of videos have gone fairly
viral.
They've,
they've gotten a pretty good reach and
they've also been very polarizing.
And so I commented on the forum.
I'm like, man,
it's really nice to see like sane takes
and like people that even though they
might disagree with us,
they're not like calling me names or
anything.
And it's just, it's so refreshing.
And people kind of pointed out, it's like,
yeah,
this is kind of like the way the
web should be like the future of the
web,
these smaller communities where people can
get along a little easier.
So it's,
I almost wonder if it would be good
for the internet to be a little bit
more, uh,
I don't want to say fragmented,
like decentralized like that.
So yeah, I don't know.
I think I'll turn that one over to
a viewer.
Yeah.
Oh, one more thing.
Yeah.
I found dog said Libra or red lib
was previously called Libra.
I definitely,
I don't know if you mentioned this cause
I'm trying to troubleshoot something over
here,
but I do wonder if they're almost like
a, what was it called?
The knitter, like knitter.
I do wonder how long these things are
going to be able to function when Reddit
is increasingly cracking down on this
stuff and
if they're going to get a cease and
desist.
But in the meantime,
I am all for that kind of stuff.
So yeah,
I think we'll turn it over to viewers.
If you guys use Reddit,
what are you going to do?
What are your recommendations?
Do you have something to add?
Those frontends are definitely a
short-term solution.
I mean, in the long term,
we just got to switch away from platforms
like this.
I know we have an announcement post on
our forum for this live stream,
like we do every week.
We've gotten some comments on the forum
from people who have talked about this
Reddit story.
There's mixed opinions, for sure, on it.
Somebody said...
that that sites that archive like deleted
comments on Reddit and stuff might lose
access because of this.
And that might be a privacy win.
I think that that's a little the I
mean,
there is certainly an argument to be made
a lot of the time.
So I think when you put out content
publicly,
I think people in general need to be
more mindful of content that's put out
publicly because a lot of the time it
does just exist kind of forever.
And so if you're really worried about
that,
There might not be much you can do,
but yeah,
I thought that was an interesting
argument.
Yeah.
I had a thought on that one,
but I don't remember what it was now.
This one,
I think we touched on this one a
little bit, but somebody,
a new user asked,
do you think the anonymous internet access
is becoming impossible and what can users
realistically do to preserve it?
Do you want to weigh in on that
one or want me to start?
Because I do have some thoughts on that.
I don't think it's becoming impossible in
a lot of areas.
I think age verification is certainly
causing problems in that regard,
and we may start to see it becoming
more difficult.
But at the same time,
I don't think it's an unreasonable burden
to switch to these more decentralized
platforms.
I think that's ultimately the solution is
to find or start communities outside of
Reddit that aren't going to be subject to
these onerous restrictions or requirements
to create an account that can be used
for tracking you and what you're browsing.
I would imagine for a lot of the
kind of stuff that people are doing on
Reddit,
having all of that tied to a specific
profile is definitely going to...
tell Reddit, tell advertisers,
tell the people that they're selling data
to a lot of stuff about you and
then tied with your IP address and that
kind of thing.
It's probably trivial to tie a lot of
that information to your real to your real
information.
And so, yeah,
just decentralizing all of that, I think,
is the long term goal to definitely to
definitely work on for for people in
organizations.
Yeah,
and one thing I want to point out,
somebody else responded and basically said
that.
They said the end game of all this
is self-hosting and federation.
And I totally agree with you,
but I want to add to that.
I'm not disagreeing.
I'm always the person who's like, well,
think about the normies and the people who
aren't super tech savvy.
And I think this is one of those
situations where actually those of us who
are more tech savvy can be like the
–
was, I'm not good with words today.
Um, but the anchor point, I guess,
for our friends, you know,
like if you know how to host,
like my, my sister, for example,
has access to my, my, um,
jellyfin server and she can just text me
and be like, Hey, it's not working,
you know, or whatever.
And it's,
it's super easy and she doesn't have to
handle any of it.
And so I think, you know,
there's certain things that like, um,
like switching to graphene or switching to
Linux, like,
or switching to proton mail, you know,
we need, yeah,
the user has to do that.
But when it comes to things like hosting
Mastodon or peer tube or, um, next cloud,
like those are things that you can do
and then manage for your friends and
family.
And, you know,
you kind of need to like,
you need to be upfront with them.
Like, um,
Like we actually,
I actually just installed a pie hole on
my network yesterday.
And I told my wife, I'm like,
just FYI,
technically I can see all the websites you
go to.
I don't really care.
I'm just looking for trackers and stuff
like that,
but I just want you to know.
And she did not care.
So, um, you know,
but like letting people know, like, Hey,
I have this cloud.
You're welcome to use it.
And I mean,
some people will probably take advantage
of that and be super entitled and crappy
about it, but you know,
other people will just like, Oh,
this is really cool.
Thank you.
And
you know?
So, um, yeah,
I guess what I'm getting at is like,
this is one of those rare situations where
like,
it's not so much every single person needs
to host their own Mastodon or, uh,
I think there's, what is it?
Plymora Plymora is like the lightweight
version,
but like you could host a small instance
and just give a few family and friends
access and that helps them out.
And they don't necessarily have to be
super tech savvy.
So yeah, for sure.
As found dogs that we can all be
big tech.
Exactly.
Yeah.
And that's super true.
I think people forget, um,
that like hosting forums in communities,
you could do that on like really low
end content back in like two thousand five
or so low end hardware back in two
thousand five.
Right.
I mean,
it's not like computers are super
powerful.
You could certainly host it on pretty much
anything today.
It's really not very intensive to host a
lot of these to host a lot of
this software.
Not that everyone can do it,
but just like you said,
I think it
can be on some of the more technical
people in certain communities to create
these platforms for other people to join.
It would be great if instead of the
movies subreddit,
if a bunch of people got together to
discuss movies on some site like that.
But it does require a lot of collaboration
and I know that people find that
difficult.
Well, and also just to add onto that,
I was going to say,
if you're hosting a small community,
like again, for like a family,
next cloud instance,
the beauty of that is you probably don't
need to pay a ton in storage because
you're not providing like five gigs for
everybody.
It's just, you know, a handful of people,
I guess,
unless you come from a big family, but,
um,
Yeah.
I was just going to say real quick,
Ben said I use RSS feed regularly to
get the best post without doom scrolling.
It's yeah.
Like RSS is so useful.
I used to, um,
I used to use it to get like,
Oh,
click the wrong button to get like news
feeds.
And then, um, I could filter out like,
uh, right now I use next clouds RSS,
which admittedly is not great for this.
Um, but Thunderbird used to be amazing.
I could filter out like sponsored posts
and ads and like all kinds of cool
stuff.
So yeah, RSS going away really sucks.
Um,
people are chatty tonight uh do you think
they could still get around this like like
knitter yeah we were just talking about
that earlier um right now we do have
a few reddit front ends but it's really
a question of like with this access
closing off are they still going to be
technically feasible and then if they find
workarounds like knitter did are they
still going to be you know are they
going to get hit with a cease and
desist so we don't really know at this
time um we'll just have to wait and
see but um let's see here sorry i'm
trying to read a whole bunch of things
um
Yeah,
somebody in the forum thread pointed out
that apparently the social media
propaganda is much stronger than we
thought it was.
And they actually provided a source for
that.
So that was pretty interesting to read.
I kind of skimmed that because it was
pretty long.
But I was like, oh, lovely.
So yeah,
maybe we should all just get off
mainstream social media.
It's probably not great.
Let me ask or read a couple of
these questions here.
Yeah.
Well,
this kind of goes back to what we
were talking about.
The problem is that the quote unquote
normies are unaware or simply don't care,
outnumber the rest of us.
So the experience on a wide range of
topics ends up being very limited.
Yeah.
I think that's the problem we're all
struggling with is like even something
like Mastodon, in my opinion,
is very feature rich.
It's very mature.
It's, in my opinion,
a very nice experience.
And it's like, well,
how am I supposed to get people?
It's like the network effect, right?
It's like, yeah,
but you can't follow Taylor Swift and Mark
Ruffalo.
Actually, Mark Ruffalo is on Mastodon,
but he hasn't posted in like
a year um you know like all these
big names that you want to follow it's
you can't really find them on a lot
of these other social media it's it's a
problem i think everybody's trying to
figure out yeah uh torsten on the forum
who's a member thanks for your support uh
just left a comment agreeing that like the
small web type self-hosting is nice but
they find it really intimidating uh
because you need to do so much stuff
to protect them protect those servers um
like if you use tail scale, for example,
to kind of limit that,
that's a good way to keep your things
secure.
But then that kind of limits who can
access it by design,
which is hard for communities like larger
communities.
I mean,
it is a tough issue for for sure.
And I think I think a solution for
that is not just like for a lot
of techie people to spin up things on
their own,
but I think people
You know,
coming together and creating a small
community of people who have technical
skills who can kind of work together on
that kind of stuff is going to be
a lot more sustainable.
But that's kind of where the collaboration
stuff comes in again,
at least if we're talking about public
things like a Mastodon instance or a forum
or something like that.
Yeah, for sure.
Anonymous said they just joined.
Have we been talking about Reddit the
whole time?
We have,
but actually I was going to say,
unless you have anything to add or any
last thoughts,
there's one more question here in the
forum.
I wonder if you guys could discuss the
secure paste feature added to Graphene OS.
I think it's a great feature that everyone
should enable.
Do you have any thoughts about this one?
I thought it was still in beta.
I didn't know it was like out out.
I only know that it exists,
but I haven't looked into it myself,
so I don't know how it works.
Okay.
Yeah.
I, um, again,
I thought it was still in beta,
but apparently it is out out.
The only thing I can really say is
side of burritos, the YouTuber,
he does pretty much nothing but graphene
videos on YouTube.
And he did a video about this.
That was really interesting actually.
Um,
which remember for those of you watching
now,
remember when we talk about this later on,
cause I'm going to mention that video
again,
but he built his own little app that,
um,
reads your clipboard to illustrate what
the secure clipboard feature does and why
it's useful.
So, um,
Yeah, I'd say if you're curious about it,
go check it out because I thought that
was a really interesting video.
Yeah,
I think that's all I got on that.
Yeah,
I'm sure other people on the team have
used it and have more experience than me.
There's probably discussion about it on
the forum too.
I think that's a good place to find
out information about new stuff like that.
Probably, yeah.
There's always discussions on the forum,
especially about stuff like graphene.
Yeah,
I think for now it's probably a good
time to go ahead and move on to
the next story.
Yeah,
let's take a look at this one here.
This is by ForoForMedia.
The headline is,
Cops can bypass iPhone's automatic reboot
to get into locked phone's leaked videos.
Claim, Magnet Forensics,
the owner of the gray key phone unlocking
tool,
says it can bypass an iPhone reboot...
It can bypass an iPhone rebooting feature
that was locking cops out.
In November, twenty twenty four,
four or four media revealed that Apple
quietly introduced a new feature in iOS
that automatically reboots an iPhone that
has not been unlocked for seventy two
hours.
And the idea behind this so-called
inactivity reboot
is to revert the phone to a state
that makes it harder for police to break
into the device and thus extract sensitive
data from it with forensics technology.
If you're in the Graphene OS community,
you've certainly heard about this like
before first unlock or after first unlock
state for encryption.
And in a
a phone that's in a before first unlocked
state, whether it's Android or iOS,
is going to be more secure than after
you unlock it for the first time.
So that's where rebooting your phone may
come in,
especially if it hasn't been used in quite
some time.
However,
this new technology to get around the
inactivity reboot on iOS was developed by
Magnet Forensics,
the company behind Gray Key,
a popular tool sold to law enforcement
agencies that allows them to
unlock and access data stored in iPhones
and Android smartphones.
Magnet has developed a new device called
GrayKey Preserve and a feature for its
regular GrayKey devices called Evidence
Preservation Mode,
according to the leaked video.
This is an educational and tutorial video,
which was made exclusively for law
enforcement agents and appears to be dated
early twenty twenty five.
The video does not explain the technical
details behind the new product and
feature,
but it gives some strong hints as to
how it works.
Taking a look here, it says, yeah,
in a quote, now,
one of the many things that the gray
key preserve is going to do is it's
going to enable airplane mode or more
specifically,
it's going to disable our radio
transmissions like Bluetooth,
Wi-Fi and cellular.
In doing this,
that's not only going to allow you to
preserve the data in the field,
but also isolate the data in the field,
as an employee explains.
even if that device doesn't have the
ability to turn on airplane mode or to
turn off the transmitters through the
control center of iOS.
Once initial access is gained and the
device is in a preserved state,
we also disable all of those radios to
make sure the data cannot reach that
device.
Um,
so it says that the after first unlock
state is captured by gray key preserve and
evidence preservation mode.
So that even if that device does reboot
for any number of reasons,
memory maintenance or the power is lost or
whatever the after first unlock state is
not lost.
Um,
So, yeah,
it says when using the new solution,
law enforcement agents only see the iPhone
software version and device model rather
than any data within,
according to the employee in a screenshot
of great keys customer interface that's
included in the video that allows the cops
to preserve the data they care about
without actually seeing it before they're
authorized to do so.
So a researcher who has looked into this
thinks that Magnet has found a way to
manipulate the iPhone clock,
effectively slowing down time or even
stopping the clock from ticking even after
a reboot.
Most likely, according to this researcher,
the Great Key may disable the iPhone tasks
that set data to expire.
So lots of stuff to unpack here.
What does this mean for iPhone users?
What do you think, Nate?
Yeah, I mean, I don't know.
The best I could come up with is,
I mean,
the automatic reboot is designed to be
there as a safety net, right?
And in my opinion,
seventy two hours is a crazy long safety
net anyways.
But I would say my first thought is
don't rely on the automatic reboot if
possible.
Like something I think I mentioned this on
previous episodes.
I don't think my threat model is
particularly high,
but just to be safe when I go
through airports now and, you know,
you have to put everything to go through
the X-ray machine,
I go ahead and reboot my phone.
And by the time it gets through the
x-ray machine,
it's fully rebooted and ready for me to
log back in.
And that way,
in the off chance that I do get
pulled aside and they're like, oh,
we're gonna take your phone into this
other room and do whatever weird stuff
with it.
Well, it's in BFU.
That is literally the best case I can
do.
And I won't have time to like,
oh wait, let me see it real quick.
And obviously they're not gonna let me do
that.
And then I know this is actually a
video that you and I have talked about
making for some time,
but digital minimalism is a bit of a
luxury.
It's not always like,
just don't have anything on your phone,
obviously.
That's one thing people talk about a lot
is if they're traveling internationally,
they're like, oh, bring a burner phone.
And it's like, yeah,
that's cool if you can afford a burner
phone.
But still, just being mindful.
Are there things that you can take off
of your phone,
especially if you do know you're going to
be going to a protest or somewhere where
you might get pulled over or something?
And so, yeah, just kind of,
keeping that kind of stuff in mind,
I think is at least the best I
could come up with.
I don't know if you have any additional
thoughts.
Yeah, for sure.
It's it's tricky to rely on a lot
of these software defenses.
I would think that I mean,
this video is from early twenty twenty
five,
so I don't know if this is like
already been patched.
I would imagine that if it hasn't yet,
Apple will probably look into it now that
this capability is is known.
But yeah,
all of this privacy and security stuff,
it's really just a game of cat and
mouse.
We see all these vulnerabilities come out
all the time and then they get patched
by these companies.
And then the people who are developing
these vulnerabilities for a variety of
reasons will just find new ones because
none of this software is, you know,
it's not going to be perfectly secure by
any means,
especially like if it's Internet
connected,
you're going to have
you're going to potentially run into
problems.
I guess there's a lot of effort being
made in terms of securing new software by
default, or there's things like on iOS,
memory integrity enforcement,
or on Android MTE,
which are going to
keep software more safe and prevent a lot
of these vulnerabilities from happening in
the first place.
But even even with those vulnerabilities
are found in them and the amount of
just old legacy code in all of these
operating systems and apps that we use is
like that's not going to be replaced with
with safer code for quite a while.
So yeah,
I think this kind of stuff will continue
cropping up as an issue.
But of course,
to minimize your risk as much as possible,
uh,
keeping your devices up to date and making
sure you have the very latest security
patches is super important because new
vulnerabilities like this are found, uh,
just constantly.
Yeah, for sure.
Definitely.
Um,
Penguin had a comment here that as far
as we know, graphene is not hackable, um,
especially because graphene comes with,
I think it's enabled by default.
Um, or no,
it's so they have a feature where the
USB port, uh,
you can basically turn it off if you
want to, where it doesn't do anything,
or you can set it to only charge
and not transfer any data.
I think the default is that while the
phone is locked,
it does not transfer any data,
but then when you unlock it,
it can do Android Auto or whatever,
which actually,
it's funny you mentioned that.
We didn't put it in here,
but literally an hour before we went live,
I think it was Jordan posted an article
about how somebody in Canada, yeah,
there's...
I'm not going to share it yet,
but yeah,
somebody in Canada was arrested for a
shooting, I guess.
And the police are currently unable to get
in there,
get into their phone because they're using
graphene.
So please don't use graphene for illegal
things.
But, you know,
these are the kind of articles we look
at and we're like, oh, OK,
like graphene is doing what it says it's
supposed to do.
And.
Yeah.
Username is nice.
It reminds me of when people used to
set their set the date to January first,
nineteen seventy to break their phones.
I didn't know about that.
That's funny.
Nick Spice here said that they thought if
people had the accessory blocking enabled,
that would help combat this.
I know that's not enabled by default,
so it's possible that that would have
combated it,
but it's just not a common thing for
people to have.
I know that in the past,
ways around that have been discovered as
well.
It's why even graphing OS, for example,
when you can disable the USB-C port,
there's varying levels of how much you can
disable it.
I have it disabled
to where the USB-C port only works if
the phone is off,
and then it's only used for charging when
the device is off.
But if it's on,
you can't use it at all,
even for charging.
I know they have a charging-only feature,
and then they have the feature like Nate
was talking about where it's just
restricted when it's locked.
iOS obviously doesn't have quite that
granular of an approach, but it...
Yeah,
I don't know if this would have prevented
this specific case,
but enabling features like that is
probably good.
I know that a lot of these
vulnerabilities,
especially when the phone is locked on
iOS,
can also come from having a lot of
features enabled on the lock screen.
If you go to your Face ID and
password settings,
there's a lot of switches for like,
do you want to allow Siri when the
device is locked?
Do you want to allow Control Center?
And in this case,
I think they mentioned even if Control
Center is disabled,
they can get around some of that stuff.
like as a general rule disabling all of
that stuff and locking down your phone
when it's locked is going to any little
bit helps when it comes to security like
this
Yeah, for sure.
And I was going to say like one
thing that stood out to me that I,
the moments I always feel kind of mixed
is it talks about how like,
I wonder if this is a technical limitation
or like a pinky promise like flock,
but it says that like when they use
this thing,
they can only see the phone software
version and device model.
So in theory,
it's designed to just like prevent the
phone from BFU.
Cause I don't know if I copied it
in the notes here,
but they mentioned that a lot of the
time when they, they get these phones.
Yeah.
You know,
Oh,
I don't think I put it in the
notes here.
A lot of the time...
when they get these phones,
they don't break into them right away
because they have to get a warrant or
they have to get approval from a judge.
And so I, I kind of like that,
like, um,
like you still can't see the data.
You still have to wait and get legal
approval, but I don't know.
It's, I mean, it's the same with anything,
right?
Like, sure.
In theory, it's great.
The celebrate can be used to hack phones
that are being used by, you know,
violent cartel members and pedophiles and
stuff like that.
But also it can just as easily,
easily be used by authoritarian
governments to spy on journalists and
stuff.
So,
Yeah, it's definitely an interesting case.
I mean,
this is that's more of a case of
like gray key policy kind of coming into
play and preventing police officers from
like going rogue and using this for
personal purposes, which, of course,
is a big issue.
You know,
we've talked about it in numerous videos
in the past of like law enforcement agents
kind of abusing these powers for their own
personal gain.
And maybe this prevents that.
But it doesn't.
I mean, at the end of the day,
they still have the data,
even if it's not accessible to an
individual officer before it goes through
like this approval process.
And it kind of calls into question we
talked about this with flock cameras,
for example,
which are kind of collecting all of this
data all the time and storing it in
a database.
And even though you're only supposed to
access that database with a warrant,
in some cases,
you know,
the fact that the data exists in the
database in the first place,
I think is is an issue and in
a Fourth Amendment violation,
like just on its own without regardless of
whether that data was queried by a
government agent.
I don't think that I think the data
collection in the first place is kind of
the bar where a warrant should be
required.
It's not just when a government agent
later tries to access and view that data
should a warrant be required.
So I think that stronger laws need to
be in place
for a variety for something like this,
because my dog is being loud.
I don't know where I was going with
that.
The point is,
I think stronger warrant requirements
should be in place just for this data
collection to be happening in the first
place.
And we're not really seeing that right
now.
Yeah, no, totally agree.
I just, like I said,
I don't know if, you know, that,
that thing,
like they can only see the software
version and device model.
That's why I'm like,
I don't know if that's a literal technical
limitation.
Like, no, no matter what,
they can only see that with this tool.
Or if it's like you said,
is it a,
a policy thing like flock where it's like,
well,
they're only supposed to look at that
tool,
but in theory they can access other stuff
too.
So I don't know.
It's either way.
I have mixed feelings about it.
Not a fan.
I'll be looking forward to Apple to patch
it.
Yeah, I'm looking for a comment here.
I think it was, yeah, FoundDog said,
I'm surprised Apple hasn't ditched the
USB-C port entirely.
I don't think that that...
is going to well,
the way that it's implemented is probably
not going to help because I know Apple
is going to want some sort of diagnostic
way to access these devices,
and that'll be just as useful as a
USB-C port,
especially to these well-funded companies
like like Magnet and Craykey and
Celebrate, for example.
I know like on the Apple Watch,
for example,
There isn't a USB-C port, obviously,
but they can still do some diagnostics in
an Apple Store or if you send it
in.
On the original Apple Watches,
it used to be like there was a
hidden port you would need a special
connector for.
Nowadays, there isn't a hidden port.
It's all wireless, but it's like a...
They have like a sixty gigahertz wireless
connection that they can do in the store
to basically establish the same thing as a
as a wired connection.
And I would imagine that Apple would leave
something like that in the iPhones that
can be, in theory, accessed by only,
you know, tools that Apple has.
But if that is available,
it wouldn't be that hard for a specialized
company to develop a way to connect to
that, even if, you know,
that that connection point isn't available
to Apple.
mere mortals like us who just want to
connect to our phone anymore.
So I don't think that just going to
a portless design is really going to help
when it comes to when it comes to
this problem, unfortunately.
Yeah, what's funny,
Apple seems to like I shouldn't be
surprised by this,
but they seem to be one of those
companies that like when it when it
benefits them, they're OK with it.
I used to know somebody who worked for
Apple for the the Genius Bar,
and they said that they've actually used
celebrate tools before.
like in their job officially,
like Apple has had celebrate tools in the
past.
I don't know how long ago this was.
It was a while ago from what they
told me,
but like they used to use celebrate tools
as part of their job to like,
you know,
help people recover data if they brought
it into the genius bar or something.
So it's, you know, I mean,
fortunately they were doing it with
consent, you know, like this is my iPhone,
I'm broke, it's broken, whatever.
But yeah, it's like, it's weird how like,
okay,
you're willing to use this when it
benefits you and your employees.
But I don't know, it's Apple's weird.
They're a weird company.
I did have a couple of questions I
flagged while we were talking.
One of them,
I think this went back to our first
story.
Nick said,
for those of us who are more tech
savvy and wanna be more private online,
where do we draw the line between
self-hosting and self-creation?
I think they're talking about making your
own tools, but I'm not too sure.
Do you have any thoughts on that one?
I mean,
certainly that's going to be more and more
of a thing with AI.
I think anyone can make their own tools
these days.
Yeah,
I don't know exactly what you're asking.
To be honest,
I would need more clarification on what
that means.
But I think doing anything yourself is
going to be an improvement over...
again, using those centralized platforms.
I think that that is kind of what
has caused a lot of the issues with
the Internet that we've now run into more
than anything else.
For sure.
And username is Nye here said we should
write an article about privacy fatigue.
I feel like have we done that?
I feel like we have in the past.
um we certainly have we have some videos
about that um i don't remember the exact
title of it right now i could look
but sometimes we change titles on things
and yeah that's fun lose track of it
okay because um i know i've written about
it a little bit at my old blog
on the new oil i've talked about burnout
um not specifically privacy related but
i've i've definitely talked about burnout
for sure um i'm looking through some of
our past articles here privacy washing
Mastodon tutorial, dating apps.
In the meantime,
mixed by said self-dev work.
I think in the self-hosting space,
if there is something you can self-host
that already does what you want it to
do, I think standardizing on certain...
Maybe not standardizing,
but supporting existing implementations of
things tends to be the better way to
go.
It's just easier for other people.
You benefit from a community of software
just as much as you benefit from a
community using these self-hosted
platforms to host discussions and stuff.
And so if you're all on a similar
platform, like Discourse, for example,
there's a wide variety of plugins that you
can install on the forum that make
community management easier.
And so using self-hosted tools like that,
if you're trying to start a community that
other people would use, is very helpful.
And it's the same with
like Mastodon, for example,
I think a reason like a lot of
the big public instances of these
Fediverse platforms use Mastodon because
it is really geared more towards larger
public communities.
And it has the largest ecosystem on the
Fediverse, for example.
And so you can get more support from
it from other people if things are going
wrong.
And I think that that's important when
you're when you're self hosting things.
I used the search button and I did
not find anything on our website.
So yeah,
we may have to add an article about
that because that is definitely an
important topic.
I think we all get burned out from
time to time.
We definitely do have a video about
privacy being like what if privacy feels
overwhelming to you,
strategies that you can do.
For example, it's one of our first videos.
So if you go back to the older
ones, I think it's...
Oh yeah, here it is on the list.
It's just how privacy can stop being
overwhelming.
If you're looking for strategies on how to
secure your digital life,
if you're facing kind of burnout and
stuff,
it's a good place to start for sure.
Yeah.
And I think, um,
I do actually really want to write this
as an article now, so I'm not,
I'm not going to dig too deep into
it, but, um, I mean,
just basic burnout strategies.
Like, you know, we talked to Cindy Cohen,
um, about how does she,
cause she's been fighting for privacy in
some form or another for like years.
And I remember asking her, I'm like,
how do you stay motivated?
And she's like,
I celebrate the little wins I have.
Um,
this is a big one personally is like,
I have spaces that are not privacy spaces,
like, especially, um,
I don't wanna sound full of myself and
I promise I'm not, but being Nate,
I know I'm a bit of a well-known
figure in the space,
but outside of privacy, I'm nobody.
Privacy is a very small space.
And honestly, I love that.
I love the fact that there are other
spaces that I can step outside and I'm
not this expert anymore that people are
like, well, what's your opinion on this?
It's like,
I can have an opinion and nobody cares.
because i'm just another normal person
like everybody else and i think just
having those spaces where you can go you
know whether it's video games whether it's
music whether it's um you know whatever it
is camping i don't know like having things
you can do where you can unplug and
disconnect is really fantastic uh at least
it is for me so anyways odd bite
one of our biggest supporters welcome to
the stream hello
Yeah, as username is nice,
I think calibrating one's threat model
step by step is one way to stop
being bored.
I think that's definitely a good strategy
because
You do have to have a plan going
into it of what's most important to you,
where you have to start out.
I think if you don't have a plan
and it's just kind of an unstructured,
try to secure everything,
try to make everything as private as
possible approach,
you're just going to have way too much
to deal with from the start.
like on our website, the knowledge base,
for example,
we do have a list of like common
threats that people face,
and maybe those aren't the things that
you're concerned about.
Maybe they are,
but it could give you a starting off
point or an idea of like, oh,
I never thought about this issue before,
but maybe I'm concerned about it.
Or it could help you narrow down like
which of these things on the list you're
most concerned about,
and then you can focus on it from
from there.
I think that definitely makes things a lot
easier,
which is why we talk about
threat modeling all the time instead of
just doing everything you can because you
can um it's just a more sustainable way
to to do things and i think you
can also it helps you be a lot
more thorough uh because you can kind of
set goals for yourself and evaluate how
you're doing and stuff like that which i
think helps a lot of people as well
Yeah, I was going to say,
I think a lot of the burnout I
see,
like there's definitely the burnout of
just like, you know,
I've been in the privacy space for years
and it feels like we're always losing,
which is not true,
but it can feel that way sometimes.
I think there's a difference between that.
The one I see most often is what
you were just saying is like somebody is
trying to do everything and they're just
overwhelmed by like, oh, cool.
Now there's this new my neighbor's Wi-Fi
can sense my position because of this new
attack or whatever.
And it's like.
Like you said,
like stepping back and being like, OK,
what's my actual threat model?
What am I really trying to defend against?
What don't I care about?
And what's like realistic, you know,
like it's yeah, I think personally,
I do think people should go as far
as they can to protect their privacy.
But there does hit a point where,
you know,
it starts to become a lot of work
and you have to ask yourself, like,
what am I getting?
What am I gaining?
What am I losing?
Like,
is this really worth it once I'm going
beyond the minimum?
And but you don't know that if you
don't know where the minimum is,
which is the threat model.
So
Yeah, it's important.
I'm going to have to briefly remind
Oddbite that if you opt into sharing your
membership status on the forum,
that's going to be publicly available on
our website.
I think we have a list of members.
And if you opt into sharing that publicly,
we include the list of members at the
end of videos now to thank people.
Definitely want to highlight all the
people supporting us.
Of course, this could be an impersonator.
Who knows if you're the real Oddbite,
but...
Um, again,
we won't spend too long on this,
but yeah, one person said, uh,
doing things in phases and set a cap
for how much is on my plate.
Um, yeah, doing things in steps for sure.
Um, not trying to do everything at once.
Uh,
what's this one compartmentalization with
identities for sure.
So, yeah, I mean,
there's a lot of stuff out there.
Maybe, uh,
Yeah,
I think there's some interest in this.
We should talk about this some more in
the future.
But for now,
I think I'm going to turn it over
to you to go over our first forum
post here that we wanted to highlight,
which I think is just kind of a
signal boost about Chat Control
Yeah, just an update.
Somebody posted here.
There's always chat control stuff going
on, I feel like.
Patrick Breyer,
who's a former MEP with the Pirate Party
and current, of course,
digital freedom activist,
posted about the upcoming sixth...
Trilog on ChatControl.
The Trilog negotiates extent of the later
proposal, which,
according to a leaked document,
is said to now include a workaround to
deploy a mass scanning by allowing
scanning of parts of a service in search
plans,
which Breyer calls mass surveillance by
another name.
The council's own legal service says such
framing would not hold up in judicial
review.
This is likely due to targeted
targeted being reframed as parts of a
service instead of a person.
So what information do we have here?
Of course,
you can always go to fightchatcontrol.eu.
You can go to fightchatcontrol.eu
hound sign, delegates,
or find the delegates section on that
site.
You can set the filter to EP Trilog
Shadows and you can see all eight
responsible MEPs.
If you're in the EU and you are
represented by these people at all,
definitely worth voicing your support.
I mean,
this is the kind of thing where for
some reason,
all of these track control measures are
just a constant fight in the EU.
Seemingly, it'll never end and hopefully
all of you in the EU can get
your act together and pass some law that
prevents this from happening.
So it doesn't just have to come up
all the time.
But that's really going to come down to
getting your representatives to do what
you want, which is always challenging.
So yeah,
were there any replies to this post that
you wanted to highlight, Nate?
Yeah,
Chat Control is definitely like a terrible
movie franchise that just will not die.
Yeah,
there was one here somewhere from another
user said,
don't forget that Canada has its own chat
control in the form of Bill C-Twenty-Two.
So if you're Canadian,
definitely keep that on your radar.
This other person actually commented
about,
I know there's been some talk about Canada
becoming an EU associate member,
which is not a thing that currently
exists.
So nobody even really knows what that
means.
But they did point out that if that
does go through,
that it might like pressure Canada to,
Play by similar, what'd they say?
More like an obligation to play by rules
by similar demand or by popular demand.
So yeah,
definitely stuff to keep an eye on.
And there was actually a video down here.
I think Freya shared it in the chat
where it's not chat controlled directly,
but apparently there's this similar
proposal called the EU Kids Act.
And the Stop Killing Games movement posted
a video where they basically talked about
how, like,
there's a whole bunch of things to it.
But one of the things I remembered is
it would basically make it illegal to
self-host games.
Like,
if you self-host your own Minecraft
server,
that would effectively become illegal.
And it's just, it's wild.
So, yeah, things are...
in a tough spot right now.
I will end by saying this person updated
their post and said that for now,
the plan to work around the targeting
limitation has been blocked.
But again,
there may be a seventh trial log in
November, possibly.
So, yeah, if you're in Canada,
if you're in the EU,
I would say go ahead and follow this
this forum post so that you get updates
and just, yeah,
try to keep updated with this stuff.
I know it's a lot.
We were just talking about burnout.
It's a lot, but unfortunately,
it's important stuff.
Username is Nye.
I want to know more details about this
Jonah act.
That's what I was going to say.
I saw that.
What is the Jonah act?
Two chat, two control.
Love it.
Yeah,
so I think that's all we got on
that one.
I think now we can move on to
the
site updates.
I guess I'll kick this one off.
In a little bit,
we're going to be talking about a new
attack that can track you regardless of
what operating system you use and does not
require administrative privileges,
by the way.
But first, like I said,
we're going to do some site updates.
Yeah, like I mentioned, we did, well,
we put out a video last week about
My brain is blanking.
The twenty sixteen San Bernardino shooting
and the fight that followed between Apple
and the FBI,
with the FBI trying to pressure Apple to
unlock it and Apple saying no.
And that one got I think it's now
got over a million views on YouTube,
which
i don't want to downplay it but i
will say um youtube changed the way they
count views now so it's more like a
million clicks than a million views but
even so it's got i think half a
million what they call engaged views which
is what we used to know as views
so um like half a million real views
which is pretty amazing um definitely the
most viral i've ever any video i've ever
worked on so super proud of that but
yeah this week um
Lewis Rossman,
a lot of you guys probably saw,
posted a video where he revoked his
endorsement of Privacy.com.
And for any of you who haven't seen
this video, I've met Lewis.
I consider him a friend.
He's a really cool guy.
And I didn't disagree with him,
but I remember sitting here and thinking,
like, while I'm watching his video,
I'm like, okay, so what's...
What's the alternative?
Every service is going to KYC you.
And I just thought it was part of
a bigger discussion.
And so I kind of pitched it to
Jonah.
I kind of expected Jonah to say no,
to be honest.
But I was like, hey,
what if we make this video?
And he was like, yeah, let's do it.
So we whipped that up pretty quick and
posted that.
And that is now available.
And it has not gone as viral,
but it's definitely gotten a ton of
discussion in the comments.
I feel like that's an issue that comes
up a lot with maybe idealists in the
privacy space.
We see it especially in cybersecurity
where I think people can let perfect be
the enemy of the good.
As long as you know the downsides of
things,
a lot of tools do have
aspects of them that can help your privacy
in meaningful ways.
And I think Privacy.com is one of them.
Of course, there are alternatives to that.
And so if you disagree with the specific
provider that Privacy.com is using,
you can switch to my pseudo or another
provider that's similar,
or you can switch to prepaid debit cards.
There's a lot of those which you can
obtain completely anonymously.
Right now, all the virtual card services,
they do KYC in a similar manner.
They just use different companies, but
But those prepaid cards can or gift cards
could be obtained with cryptocurrency or
cash.
And so that's always an option.
But I think
Yeah,
as long as you understand you're giving up
some privacy in some respect when you're
using privacy.com, which is unfortunate.
I've never liked the name of this
privacy.com service because I think that
is a little misleading.
But at the same time,
being able to use a different card number
on every site that you use,
it has security benefits for sure because
you can disable those cards.
And it also has privacy benefits
because...
uh merchants can't track you based on your
billing information or like two websites
can't collaborate and share their
databases and link your accounts because
you can use not only different card
numbers but you can use different billing
addresses or whatever you want with
privacy.com it doesn't get checked on
those cards so they're like it sucks that
they're doing this uh it's very annoying
but at the same time if you want
those privacy benefits
in a different respect,
you also don't have a lot of options.
But I do think privacy.com should stop
doing that.
And I think that if you do use
privacy.com right now,
you should write to them and complain.
I don't use privacy.com.
Personally,
I use virtual cards from my bank,
which I think is the more convenient
option if you have that option.
But yeah,
Yeah, for sure.
And for the record, again,
if anybody hasn't seen the video,
we said all this in the video.
Like I even said at one point,
I'm like, look, I think at bare minimum,
Privacy.com could have gone with a
different provider that's not funded by
Peter Thiel.
Did you see the comment that said I
was defending Peter Thiel somehow?
I stared at that one for a minute.
I'm like, what?
Where?
But yeah, anyways.
Yeah.
So, I mean, we, we said that like,
look, they, they should do better.
There's probably providers who are
slightly better, but they're not all like,
there is no provider that's like, oh,
this one's great.
And they should have gone with them.
It's like, yeah, there's a lesser evil,
but not by much.
And yeah,
we did go over some of the alternatives,
like you mentioned.
And yeah, I don't know.
Anyways, that's,
that's a video that's out there.
If y'all want to check that out.
I think on that note,
I will turn it over to Jonah to
discuss any site changes that are coming
up.
Yeah, there's some minor updates.
As usual,
people keep plugging away at pull requests
on the site.
And if you have any suggestions or want
to add new content,
we always accept that stuff on on GitHub.
We have some changes revising the guidance
we have for Android app installation.
We have some changes to
We have some improvements to our Tor
interview and how we changed that,
and we changed our custom domain
requirement for email services again.
This is all based on forum discussions
that we have,
so if you want to get involved,
you can either create a pull request based
on discussions that you've seen on the
forum that people generally agree on,
or if you want to make a change,
you can open a discussion on the forum
at discuss.privacyguides.net.
That's the best way to contribute to our
shared knowledge base,
and we can hopefully get
the best privacy information we can out
there.
Of course,
Freya and others constantly work on news
briefs that we post to privacyguides.org
slash news.
These come up very regularly and they
cover a lot of news topics,
especially ones that we can't cover on the
show because we do a lot of discussion
on the show.
Of course, we can't
We can't cover every news story.
Some of the headlines from this week.
Critical Tor vulnerabilities were patched
across all Tor components from the LLM
report firehose.
New technique was discovered for breaking
RSA faster than ever before.
Meta promises to upgrade Ray-Ban smart
glasses with private processing.
Whatever that means,
you'll have to read the article to find
out.
um highly sensitive data of three million
people in the pentagon system were
accessed by unauthorized users and german
police are using linked devices to read
messages from messaging apps without
cracking the encryption which i believe
we've talked about a similar story on the
show before um of course every week nate
also publishes the data breach roundup to
this same page privacyguides.org news you
can also subscribe to it as a newsletter
but there's just constantly
data breaches happening all the time.
And it's kind of just a way to
show how often it happens,
because I think people wouldn't believe
how often these companies get hacked.
So yeah,
if you want to either be aware of
that,
or if you just want to see how
often it happens,
that's a good resource to check out.
Yeah, all of the stuff that we publish,
all the stuff that I talked about and
the videos that Nate talked about,
all of it's made possible by our
supporters.
You can sign up for a membership or
you can donate at privacyguides.org slash
donate.
You can also pick up some swag at
shop.privacyguides.org if you like.
At Privacy Guides, we are a nonprofit.
We research and share privacy-related
information,
and we facilitate a community on our forum
and matrix and these other platforms like
here on YouTube where people can ask
questions and get advice about staying
private online and preserving your digital
rights.
So yeah,
with my spiel out of the way, Nate,
let's talk about some new research on car
privacy or the lack thereof.
And everyone, remember...
The chat's been pretty active,
which is fantastic.
But if you do have questions,
either about what we're talking about or
just questions in general,
we will get to all those questions in
between stories.
So definitely feel free to leave them.
Now you don't have to wait.
Yeah, real quick,
I'll jump into a couple of those
questions.
First of all,
apparently the Jonah Act is the just open
nothing and hide act.
So if you were curious about that.
Username is Naya said,
where's Tudor encryption wise?
They receive government funding to
post-quantum cryptography.
I think either they're still rolling it
out or it might be done.
I know Tudor Drive uses post-quantum
encryption.
Yeah, I, I know it's,
it's in progress at very least if it's
not already fully rolled out.
I believe they fully rolled it out and
it should protect all that data.
Um, yeah, yeah.
Proton still is not rolled it out
annoyingly,
even though they have it supposedly.
Um, but yeah,
I've complained about that on the Reddit
and hopefully we,
hopefully we see that soon.
You know,
I really want to add a soundboard on
my little stream deck here for the clip
from Letter Kenny,
where he just says allegedly,
because I feel like I use that a
lot.
But anyways, I digress.
We'll move on to the next story,
which is a study about cars.
And I do apologize.
I'm going to read pretty much all of
this article.
It's not very long for the record.
And I read fast,
but it's one of those articles where
there's really not a lot of fluff and
it's very dense.
So it's one of those times I found
myself taking notes and I'm like,
I literally just copied the whole article.
So the headline says,
this study looks at how and with whom
connected cars share your data.
So I can actually summarize the first
couple of paragraphs.
Back in twenty twenty three,
Mozilla published a report that actually
broke all the way into the mainstream.
And what they did was they looked at
the privacy policies of more than two
dozen automakers.
And they said, quote,
cars are the worst product category we
have ever reviewed for privacy.
But this article notes like, yeah,
that was conducted by reading the privacy
policies.
But now we have actual research.
Northeastern University and Consumer
Reports tested twenty one cars from
nineteen different brands.
And let's see two attempts to actually see
what was in the data packets using
modified certificates failed in every
case.
But the network traces still yielded
valuable information,
including the domains contacted via DNS
traffic.
uh server name indication in tls
handshakes the volume and timing of
transmissions and differences in behavior
across experimental scenarios so all of
the cars contacted a first party domain uh
you know honda.com mercedes.com whatever
um uh where did they say
A few left it there,
such as the Buick Invista and the
Mercedes-Benz EQS didn't appear to reach
out anywhere else, for example.
Others were far more promiscuous,
with Tesla topping the chart.
The Model Three contacted thirty-four
advertising, tracking,
and analytics domains,
as well as thirty-seven domains from apps
integrated into the infotainment system.
Alphabet's domains were most frequently
contacted,
which is not enormously surprising given
the penetration of Android Automotive OS
into the sector.
They said,
but there were many second level domains
that were not necessary for core services
like DoubleClick.net and
GoogleSyndication.com,
which are used for advertising.
Media streaming like Spotify, SiriusXM,
and so on are also there,
as well as mapping companies like Here,
TomTom, and Mapbox.
They said using a car's infotainment
system resulted in contacting the most
domains versus just sitting idle or
driving for all the cars tested,
which would make sense,
apart from the Cybertruck,
which instead contacts twenty six more
third party domains while driving than
stationary, which is.
What?
I digress.
So with the EVs,
they were able to put them in a
Faraday tent and actually test.
They couldn't do that with the internal
combustion engine cars because of fumes,
but they were able to put them in
a tent and see would they try a
different way to phone home.
And they said some of the EVs,
including the Cadillac Lyric,
Chevy Blazer, Honda Prologue,
and Rivian R-I simply stopped using those
connected subsystems.
But some of the cars redirected their
traffic to Wi-Fi,
allowing the researchers to see traffic
flows that were previously unobservable.
And then they tested thirty different
connected car apps.
So I'm not gonna lie.
I tried one of these one time just
because I was hoping that we would be
able to remote start our car in the
winter and let it like warm up.
It did not do that.
So I deleted the app because in our
case, you know,
you download an app for like Honda,
Toyota, whoever,
and
in my opinion they're pretty useless it
like tells you it tells you things the
car already tells you like you know oh
you've driven this far oh it's time to
get an oil change and it's like what
do i need an app for that but
anyways um they said in some cases uh
this exposed users to more than twenty new
advertising tracking and analytics
companies from general motors toyota and
nissan were the worst offenders
um the authors reached out to seventeen of
the automakers and heard back from
fourteen the replies are not entirely
encouraging all of the oems told
researchers that data sharing with with
third parties was covered by contracts
prohibiting the use of pii outside the
scope of their privacy agreements the same
privacy agreements that horrified bozilla
in uh some of the automakers deflected
blame onto the embedded browser running
inside the infotainment system and said it
was up to the users to select the
right prompt or reject a cookie uh seven
said it's the consumer's responsibility to
read and accept all the terms and
conditions
even though in many cases the software is
already installed and the author's note
that declining a data sharing agreement
can result in loss of services and
functionality not a great solution if it
means losing useful features you expect to
work when you bought the car they said
there was at least one positive outcome
after being contacted Honda changed its
data practices and no longer shares
precise location data with at least one
tracking company so yeah that was a lot
but
i don't know the the fun thing about
cars is i feel like right now there's
not a lot of defenses i mean are
you aware of any any uh defenses against
car privacy invasions jonah it's
definitely a field that could use a lot
more research unfortunately um i don't
know maybe that's an opportunity for us to
look into that but it's it's tricky as
these
Yeah,
cars just become even more connected and
they're all kind of doing their own thing,
of course,
because like all of these companies,
they just want to monetize that data.
I'm sure very soon we'll see information
like the LG TV information that just came
out, except without with cars.
Certainly we know of a lot of privacy
invasions that cars have even today,
and it's only kind of getting worse.
what exactly we can do about it i
don't know though i don't have specific
car advice unfortunately um but it would
be great if there was was an option
yeah for sure i know one thing that
gets thrown around a lot is like just
drive an older car um you know australis
actually said we're cooked when all the
old cars break down that's not always a
feasible um solution because i know i used
to have a that was my last car
was a
and I got rid of that just a
couple years ago,
so I had it about thirteen years or
so, ten years, something like that,
and it was a very common car,
I'm not gonna say what it was for
obvious reasons,
but it was a very common car,
and yet,
I remember the last time I went into
an AutoZone, and I was like, yeah,
I need a headlight, and they're like, oh,
we don't have any headlights for that car,
and I'm like,
What do you mean you don't have any
headlights for that car?
I passed six other ones on the way
here.
This is not an unusual car.
And you know, especially like my new car,
one of our AC fan broke,
which was just wonderful when we lived in
Texas.
Our AC fan broke and I jumped online
and I spent days scouring,
not just YouTube, but like forums,
like multiple search engines.
I was like,
there has to be tutorials on how to
swap out this fan.
And I could not find any tutorials.
I could find,
I found that repair for a different make
and model, the right make and model,
but different repairs.
But we are no longer living in the
glory days of YouTube where it's like
anything you can think of,
there's a tutorial on YouTube for it.
So my point being is we're hitting a
point where
just drive an older car it's only going
to work if you have the money to
like get parts custom ordered and
fabricated and go to a mechanic every time
it breaks down because it's just becoming
impossible to like maintain these cars
anymore so i don't know personal rant on
that one but um anonymous one shared uh
a link about rivians um this has come
out
come up a few times when we talked
about car privacy and EVs.
I haven't looked into it.
Rivian claims that you can disable a lot
of the stuff, which is cool.
You do lose some features.
It is sort of like
very similar to trusting Apple with like,
is it truly disabled?
Are they collecting all of this stuff?
If you want to.
Yeah,
if you want to trust that that's
happening,
it could be it could be an option.
And it's cool that, you know,
they at least recognize that this is a
privacy problem.
But I think I don't know if people
have evaluated that yet.
um another comment i saw was from username
isn't high grok helps me drive this
comment is how i just found out that
tesla's integrate grok now i was just
looking this up um and that is very
sad knowledge for me to have so thank
you for sharing that with me um that
is that is terrible
Um, I'd buy said it here.
Thank you so much.
I was trying to remember the name of
the company.
Carrie Parker mentioned them a couple
months ago on firewalls.
Don't stop dragons.
Apparently slate alleges that you can turn
off all the tracking.
Same thing with Rivian.
It's like, how much do you trust it?
I will say, um, in my opinion,
what's up?
Sorry,
I was just going to say Slate might
be a better option than Rivian because my
understanding is there's not even a
computer unless you buy one.
Everything is kind of modular with the
Slate truck.
That's what it is.
Yeah, the Slate's all modular.
I remember looking at Slade and kind of
configuring one on their website.
I don't have the thirty grand to buy
a slate truck,
but I think even like the speaker system
they recommend is basically a Bluetooth
speaker that you mount there and then a
phone holder.
So
I mean,
that is kind of the ideal way to
do it in some in some sense,
because I think it makes a lot of
sense to kind of have everything on your
phone and kind of only trust this one
computer instead of this whole system that
you're using.
But I also don't know anything about the
slate truck or how nice it is the
drive or how many people will buy it.
But it's an interesting concept for sure.
a little bit off topic, but you said,
I don't have the thirty grand to buy
it.
I remember one time just purely for
laughs,
I went to system seventy six's website.
This was years ago before the ramp
apocalypse.
And just for laughs, I was like,
what is the most powerful computer they
sell?
So I got like the best,
like the most RAM,
the biggest hard drives,
like multiple GPUs.
And it came out to like seventy thousand
dollars.
I mean, to be fair,
it had like nine I-Nines in it or
something crazy.
So it's, yeah, but I just,
just for fun,
I like to do that every now and
then just how bad does it get?
But yeah,
we actually have quite a few here.
Oh,
I remember I was going to say like
with the
whole like Rivian, you know,
you can go to this link thing.
Yeah, we're kind of trusting them.
Like you said, it's like Apple.
We're kind of trusting them to turn it
off.
But it's one of those things,
in my opinion,
where it can't hurt to do it because
worst case scenario,
you're in the same boat you started in.
Best case scenario,
they do actually shut off at least some
of the telemetry.
Worst case scenario,
literally nothing has changed.
So it's not like you're going to be
worse off for doing it, in my opinion.
But...
Yeah,
what about a start a farm life when
the digital world is too much?
Seems like a lot of people are retiring
to the farm life.
Oh, what do we have here?
Jonah, it's different from Apple.
They say you can disable all cellular
connectivity.
It's a simple on off.
So but, you know,
it's like a proprietary system, right?
Just like Apple.
You just have to trust other switches
work.
I mean,
there's got to be a way to like
check and see if there's anything coming
off of it.
I would feel like I don't know.
I'm really curious.
I remember when we looked at the review
and stuff last time,
it does disable things like active lane
centering, which isn't great.
It disables navigation,
which might make sense.
But I mean,
even even in like two thousand eight to
twenty ten,
we had cars that just had maps in
them.
Could we just could we just have offline
maps for a fan?
Maybe I'm curious whether
I don't know anything about Rivian,
honestly.
I don't know if it supports CarPlay.
I wonder if you could disable this but
still use CarPlay for music streaming.
Or Android Auto.
Either one,
depending on the phone you have.
Yeah, it's interesting.
This article does say that they can
disable the eSIM entirely through a
service appointment,
which maybe would be even better.
But yeah,
it all depends on how well they've
implemented this.
But I would certainly hope it works as
advertised.
Yeah.
Yeah.
Um,
the last thing I'll add before we move
on is, uh,
I know there's services out there.
The two I know of is privacy for
cars and vehicle privacy report.
Um,
they basically submit opt-outs on your
behalf,
or you can do it yourself if you're
a masochist.
Um, it's,
it's one of those things where you're
trusting another party.
Uh,
this is not an official privacy guides
recommendation, but, um,
you are trusting a third party because you
have to,
and I think you even have to like
check a box that basically says like,
I am giving you legal authorization to act
on my behalf in this instance.
And even then, it's not really,
it's very limited.
It's like a lot of websites where it's
like, oh, opt out of targeted advertising.
And it's like, okay,
but opting out of targeted advertising is
not the same as opting out of collecting
the data for targeted advertising.
So it's definitely not,
I'm not trying to say it's foolproof and
like, oh,
you sign up for one of these and
they'll delete everything or whatever.
But again,
it's one of those things where I think
I would argue you're probably not worse
off.
Like I've done it.
I haven't had any downsides other than I
got a bunch of letters that are like,
we received your request and we'll process
and blah, blah, blah, blah, blah, blah.
And then, you know,
at very least it sends a message.
You know,
if they get tens of thousands of these
requests,
then maybe they might just be like, hmm,
people feel strongly about this.
So I don't know if it would be
enough to change, but yeah.
So I just wanted to throw that out
there.
I think you have a forum post to
pull up, but right before that,
I want to do one more comment here.
Foundog said,
I think I'd want the ability to remove
the five G modem.
I think that that would be like that's
that's the main thing.
If I was going to look into this
vehicle stuff more,
which maybe we should do, to be honest,
because nobody else seems to be doing it
these days since Mozilla stopped updating
that.
But I think that that would be probably
the best solution is just
there's probably going to be some vehicles
where you can just pull out this module
or make make a change to like force
it to no longer be connected and then
see like what functionality remains.
I think looking into that would be would
be cool.
I know that
Henry from Teklor suggested something
similar because at one point,
I think he got like a Nissan Leaf
or something,
but it was like an older EV that
only had two G connectivity.
So then when all of the towers stopped
supporting two G,
he said that that would that would make
it private.
know that's certainly an approach i think
removing it entirely would be uh certainly
a lot better um but i don't know
of any cars that make that super easy
to do but i feel like there might
be some out there where you could just
like remove a fuse or like disconnect a
module and and lose that functionality and
they they might be options to explore and
i think doing more research into that
would be pretty useful.
So we should think about that.
Username is not what's bad about five G
exactly.
I think just any connectivity,
like if you could remove the connectivity
features of your,
of your vehicle pretty easily,
no cellular, no, no wifi.
That would,
that would stop a lot of these privacy
problems.
You'd lose functionality.
So I think looking into like what
functionality you,
you would lose if you disconnected,
that would be something to, to look into,
but it would be good for privacy.
If that's a possibility.
Yeah, I don't know if it's true.
I've heard some claims that that could
potentially be like a warranty voiding
thing,
but also if you're buying a car
secondhand, usually there is no warranty,
so.
yeah another thing we'd have to look into
like can you easily reconnect it when you
bring it in for servicing maybe and that's
what i was about to say i feel
like a good mechanic could probably like
you said like there's probably just one
cable they just pull out and you know
but also a lot of the time i
no offense to mechanics a lot of you
guys seem to like talk down to
non-mechanics well you know you're gonna
lose this this and this yeah i i
know just please unplug it i i did
my research so
I don't know, but yeah, anyways,
actually we did have a couple of questions
before I dive into the forum post.
We had one basically, okay, sorry,
I closed it out.
Now I can't see it.
It's basically, they found on our forum,
there were some recommendations for
Venadium and one of them was to turn
off, do not track,
but since it's on by default,
wouldn't that make Venadium users stand
out more?
What do you think of that?
That's definitely true that it could.
In theory,
the reality is Vanadium doesn't have
billions or millions or even probably no
more than like a handful of thousand
users.
Right.
So fingerprinting is kind of already going
to be an issue for a lot of
people.
It's not really
geared to prevent fingerprinting.
I think that Graphene OS has said they
want to focus more on that in the
future.
I believe that they've said in regards to
fingerprinting,
it'd be cool to release Vanadium on the
Play Store so other people kind of blend
in with it.
But the reality is with a lot of
these mobile devices,
it's almost impossible to prevent a lot of
browser fingerprinting.
And even Tor Browser on Android is not
as good at preventing fingerprinting as...
as it is on like desktop with mobile
browser or Tor browser, for example.
It's just there's too many variables.
We talk about this all the time with
cellular devices.
They're machines that are basically built
for tracking.
So
There's only so much that can be done
with the current operating systems,
unfortunately.
Yeah,
Jordan just said in the chat that Graphene
OS has said they have around a half
a million users.
So yeah, in the grand scheme of things,
as far as browser fingerprinting goes,
that's a pretty insignificant number of
users who are browsing the web.
So you're going to stand out if you
use Vanadium either way.
I think the idea...
You said this was advice from a...
community wiki posts,
those are obviously maybe not obviously,
but those are submitted by people in our
community and they're kind of collaborated
on by other forum users,
but they haven't been like added to our
website.
So this isn't a post that I've read,
but I would imagine changing some of these
settings may help Vanadium users blend in
more with like Google Chrome users,
which may be a bit more beneficial.
But again, even Google Chrome users,
despite there being a ton of them,
because the browser is
sharing so much unique information,
you're still going to be fingerprintable.
So it's just not a thing that really
any browser on Android, to my knowledge,
tackles.
Tor browser might be doing the best,
but there's so few Tor browser users on
Android that you run into exactly the same
issue.
So that's not really a protection either.
You're just not going to be protected from
this on Android at the end of the
day.
That's what I would say.
Another thing Jordan said that I know you
kind of touched on is not everyone that
uses Graphene OS uses Vanadium either,
which is true.
I use Brave, so yeah.
Yeah,
I use Brave on mobile just because I
think they're the best at what they do.
Yeah, Oddbyte said Brave.
I use it because it syncs, you know.
I don't use the sync.
Oh, no?
I just, I like that it has,
I feel like it has the best
anti-fingerprinting for an Android
browser, but, you know.
It's good ad blocking, too, yeah.
Oh, yeah, ad blocking.
I don't remember what the ad blocking
situation is on Finadium, but...
I heard they were going to make a
change list built in,
but it's not really robust.
That sounds like it might be right.
Um, yeah,
username is nice that some websites can
ignore and bypass do not track requests.
And I also know that, um,
there is a. Uh,
I don't know if this necessarily, like,
I don't know how this compares versus, um,
like the idea of trying to make everybody
blend in on vanadium,
but do not track can also be used
ironically to track people because of the
way it works and the headers.
And so that's typically why it is
disabled.
Yeah.
Yeah.
I was going to say that's,
that's probably why we re uh,
or that forum post recommended.
You wouldn't want to disable it.
I think it's a good point.
Like in general,
if the other people who use your browsers
have it enabled by default,
you probably wouldn't want to disable it.
But I think in this case,
it probably doesn't matter too much in the
grand scheme of things.
So as
Yeah, who said that?
Where did that chat go?
Well, it doesn't matter.
The do not track setting is ignored by
sites because, yeah, that one.
Because it's not a legal requirement.
I mean,
it's just kind of a request that you
make.
There is a new standard,
I think it's called GPC,
Global Privacy Control,
but I could be wrong about that.
But the nice thing about that one,
in theory,
is that in states like California,
for example,
in other regions where there are stronger
privacy laws,
they've decided that this setting is...
considered a legally binding request,
whereas Do Not Track isn't because there's
some like requirements on how GPC is used.
It can't be like enabled by default on
standard browsers.
People have to opt into it.
So that's more like an affirmative choice.
I think a big problem with Do Not
Track is that like it just got enabled
on Firefox, for example, by default,
and then everyone was using it and then
Nobody really respected that request or
checked it because they wanted to track a
bunch of Firefox users.
Probably back in the day when a lot
of people use Firefox.
Now Firefox would probably get away with
enabling it by default,
arguing that most Firefox users care about
privacy.
But there was a time where people used
Firefox for non-privacy reasons back in
the day.
But I think those people are few and
far between now, unfortunately.
Well,
what's funny is I think Brave enables GPC
by default, but yeah,
that's another video idea I've submitted
but we haven't gotten around to.
Because if you market your browser as
specifically for privacy,
everywhere on Brave it's the privacy
browser.
So people are opting into it because they
downloaded a privacy browser.
But even Firefox probably couldn't justify
enabling it by default and Chrome
certainly couldn't.
you can't say this person specifically
requested privacy.
Would it be nice if we just had
data privacy laws that you don't have to
opt into?
Yes, that would be awesome.
But yeah, we don't.
Fair.
Yeah.
Somebody said Vanadium uses easy list and-
Yeah, I think that's about it.
There was another question from that
person real quick.
We'll just run through these.
Basically,
if I enable some hardening exploit
protection on Graphene OS,
when should I enable it for specific apps?
In my experience,
you should enable it by default.
I've only ever had to,
I kind of bounce around between a lot
of different operating systems to keep
testing them.
In my experience,
I've only ever had to disable exploit
protection once and it was with Apple
Music because it was,
for some reason it started giving me a
lot of trouble about like,
it wouldn't let me sign in and then
when I did sign in,
it like wouldn't find my library and then
like,
It wouldn't download music.
It was giving me all kinds of errors.
And finally,
when I disabled exploit protection,
suddenly it worked perfectly.
So, I don't know.
I would use a whitelist approach,
personally.
Every other app I've ever tried has worked
just fine.
Yeah.
I enabled all of them by default,
and I have not run into any issues
on my Pixel.
I would say...
If you can deal with that pop-up,
there are definitely a few apps where I
open them and I get that pop-up,
but nothing really seems to change.
I think that gallery app,
Avis Gallery or whatever it's called,
has this issue where sometimes I open it,
that pops up, but it's perfectly fine.
And if you can kind of just deal
with that pop-up, then it's...
whatever.
But also,
if you get that pop-up and functionality
is clearly impacted,
you can consider disabling it.
It just depends on how much you trust
that app, right?
It's just a sign.
I wouldn't disable these features every
time an app breaks or crashes because I
think it's a good...
point in time to evaluate whether you need
this app in the first place or whether
you can find an alternative that's not
going to break because of security
features.
But if you really do need this app,
then the whitelist approach,
like you said, Nate,
is the way to go,
where you just have everything enabled by
default and just disable it very
selectively.
Oddbite also read my mind.
Oddbite said you can disable the pop up,
which honestly is what I do, because,
yeah, it shows up all the time.
And then but there's like never a
functionality issue.
It's so yeah,
you just had at least one if you
have.
I was going to say,
I think I have at least one functionality
issue.
I don't remember what it was, though.
But yeah,
like I also just said that that's usually
used by tracking SDKs.
I think that that's most of the reason
that it pops up.
Can you disable that pop up?
for a specific app or can you just
disable the pop-up from the system in
general?
Because that's what I would wonder.
I would still want the pop-up for some
apps,
but if it was an issue with a
specific app, I'd want to turn it off.
But I've never looked into disabling it.
I can't remember.
They're saying per app.
They're saying per app in the chat.
So great.
That's a great option.
All right, and then last one,
this one's really quick.
Is there a difference between wired and
wireless headphones security-wise?
Generally speaking,
wired is going to be more secure.
We did, I think last week, actually,
we did cover an attack that also works
on wired headphones because it targets the
actual analog components.
But yeah,
usually when there's security issues,
it has to do with the Bluetooth of
wireless headphones.
Yeah, I mean, Bluetooth is just not a...
very private standard.
And anytime you're like, I mean,
it's radio waves,
this can be picked up by somebody if
they have the equipment.
Yeah.
for sure.
All right.
On that note, uh,
we'll get into the forum post here, which,
uh, this is a forum discussion.
It was actually,
I think our most popular forum discussion
this week is how often are people sending
encrypted emails?
Um,
so I'm not going to read any specific
messages here because basically the whole
thread of it was somebody was like,
I feel like a lot of the people
I email are using like Gmail or outlook
or Yahoo and everybody else kind of just,
uh, um, agreeing like, yeah, everyone I,
I email is, is, uh,
using one of these mainstream providers
there was some discussion about like you
know should you like teaching people how
to use mail envelope or how it comes
built in with like firefox or uh not
firefox um thunderbird and uh i saw some
people said that they've actually stopped
using encrypted email providers for that
reason specifically but i don't know i uh
i also wanted to talk about this because
i have opinions about this and uh i
actually don't know
I'm assuming you are probably on the same
page as me with this one,
but in your opinion,
is there a point to using an encrypted
email provider even if nobody else is?
Yeah.
I think we hammered this down pretty hard
on our website actually,
but the main reason we recommend these
providers is their protection at rest,
and especially if you can prevent the
provider from having the keys to open
that, that would be great.
A lot of people will say, well,
your data is encrypted by email.
Google and their servers because they use
disk encryption.
But Google has the keys to unlock it.
So how secure is that really?
Whereas with Proton,
you have the key to unlock it and
they can't do it.
And I think that in terms of long
term storage of emails,
you might be emailed a lot of sensitive
information.
You're certainly emailed like a lot of
account related stuff.
But like I almost never
use email for communication because
there's no point to it.
And we really, I think,
discourage people from using email for
communication in general.
And so
I think we're not really pushing for a
lot of end-to-end encryption for email
just because there are much better
platforms to use if you want to
communicate securely.
Whereas I just use it as an inbox
for all the accounts that I have.
And having that data encrypted at rest is
very important to me.
And that has nothing to do with the
end-to-end encrypted stuff.
Anyways,
what I would say is it's probably a
good thing that we're not focusing so much
on end-to-end encryption in email because
I think everyone should spend their time
switching to better instant messengers
like Signal instead of working on that.
Yeah, for sure.
I feel kind of the same way.
It's to me,
I think of it in terms of like
a data breach.
Like, okay,
if I'm using Proton or Tudor and I'm
communicating with people who are using
Gmail and Outlook and whatnot,
if that person has a data breach, yes,
my correspondence with them is going to be
leaked,
But it's not gonna be my whole inbox.
Like you said,
it's not gonna be my doctor's office,
my bank, all these different things.
That's not gonna be in there.
It's going to be my communication with
them, which may still be bad,
but it's not as bad.
And to me,
it's also cutting the risk in half
because, like you said,
my inbox is still encrypted at rest.
And that can't be as easily breached as
something like Gmail or Outlook,
especially Outlook.
So it's again, yeah,
it's not a perfect solution,
but it's a it's a risk reduction solution.
So I still think it's worth it.
Also, again, you know,
these providers are not like farming your
your email for marketing information,
which I think Google said they stopped
doing that, but whatever.
And yeah, I had that in the notes,
too,
that email is a legacy tech to begin
with.
And all these things like PGP,
even like Tudor,
I know Tudor like has their own version
of PGP where they encrypt even more
metadata.
But even that is still just like adding
band aids on top of email.
And there are better things like Signal or
SimpleX or whatever.
So but unfortunately,
we are at a point where, you know,
my bank is not going to signal me
a login code.
So we do still need email from time
to time for sure.
Yeah.
Jordan just said that,
but it would be nice if we could
use something else,
but I don't see that happening anytime
soon.
Yeah, Intel just said it's the standard,
and it is.
And it's just so entrenched in everything
that it's very unlikely that we'll switch
away from using it.
But protecting as much as you can,
I think...
I think the risk of,
just from a security perspective,
the risk of a data breach impacting your
email provider is much higher than the
risk of your emails being intercepted
live.
That all depends on your threat model,
of course,
but end-to-end encryption is a huge
benefit just for that data at rest against
data breaches,
even if it doesn't stop active attackers.
Switching to something like Proton,
even if you can't convince anyone else to
switch, and I think somebody even said,
yeah, anonymous once,
I'm not going to spend time on convincing
people to change email for writers.
Yeah,
I think that's not the best use of
anyone's time, but...
It would be great if people switch because
it would secure their own emails.
And just from a personal perspective,
it's one of those things where if you
switch, you benefit a lot,
even if nobody else uses it.
I think that's a problem that we have
with instant messengers when we think
about Signal or SimpleX.
like you don't get a lot of benefit
from Signal if nobody else is using
Signal.
So there's more of that problem,
but there's a clear benefit to switching
to a more private, secure email provider.
So yeah, highly recommend.
Yeah,
that's something I think about that I'm
probably gonna write a blog post at some
point about is like there's certain
privacy actions that do require you to get
other people to change, like you said,
like using Signal or something.
But then there's a lot of things that
you can do yourself that don't depend on
anybody else.
Like you can switch to Brave or Firefox.
You can switch to Linux if you can
afford to do that.
Yeah,
you can switch to a private email
provider.
Like there's a lot of privacy stuff you
can do on your own for sure, so.
Anyways, on that note,
I'm going to turn things over to you
now and you can tell us all about
this new attack.
This is actually our last story of the
day.
So if anybody has been holding on to
any questions that you haven't asked yet,
please do drop those in the chat and
Jonah will tell us all about this new
attack.
Yeah, Fria wrote this article,
new attack can track you across operating
systems without elevated privileges.
Fria, sorry,
researchers at the Graz University of
Technology Austria demonstrated a new
attack that can track you via file change
events on all systems allowing for various
data leaks.
They say that modern operating systems
like Linux,
Windows and Mac OS provide built in
subsystems to monitor file system events.
I notify redirectory changes to view NFS
events.
User processes,
programs on your computer can subscribe to
receive file operation notifications when
actions like accessing, writing,
opening and closing are performed on a
monitored file or directory.
And so the research paper that was
published essentially points out that
these tools can be used by programs to
read information about
large number of operating system files and
other files on your computer.
A lot of these files that can be
read or that you can monitor events for
can be read by any program without any
special privileges.
I saw people talking about this story on
Reddit on the r slash privacy subreddit.
And I think people were like, well,
this attack can only be,
it only matters if you're like locally
running software.
It's not like an attack you can get
over the internet.
But I didn't really understand that
argument because malware exists.
People are downloading software on their
computers all the times and this,
I think it gives any malware a large
amount of insight into your system and
what's running on it without that malware
needing any special permissions other than
just running on your device.
So it's not something that would need to
escalate to admin privileges.
And according to the researchers in this
paper,
it leaks a lot of information that
like more information than you would
think.
So it says on Linux,
they were able to achieve a keystroke
timing attack,
which is a type of side channel attack
that measures the timing between key
presses in order to infer information
about the text being typed,
including the actual text.
That attack could potentially leak
passwords or sensitive text being typed,
such as private messages.
They were also able to perform a
fingerprinting attack on the top one
hundred websites,
since visiting certain websites would
trigger specific access patterns for fonts
in the fonts directory.
So from just this alone,
an attacker can figure out what websites
you're visiting,
basically
malware running on your computer without
any access to your browser at all,
because it's sandbox,
can see whether you're accessing a certain
site, like a major one,
or at least guess and potentially track
you based on just files in the operating
system that can be read by pretty much
any software running on your device.
So I think it is a concerning problem.
And the paper also goes into
similar attacks to that on on Android,
on Windows, on Mac OS.
So, yeah, if you read this article,
you can read some specific attacks in the
paper is is linked.
But I think that that is kind of
the the situation there.
So, yeah.
Do you have any thoughts about like the
malware running on your computer side of
things or anything like that?
Well, I do want to answer,
username is Nye, said,
is this article peer-reviewed?
I don't think so,
but it is kind of confirmed.
The last sentence of the article says,
in particular,
Microsoft stated that the private data
leakage was actually there by design,
which is a pretty insane thing to say,
but whatever.
Yeah, I think, to me,
the thing that stuck out to me, so,
okay,
I know this was an hour and a
half ago,
but at the beginning of the live stream,
I talked about
that video from Side of Burritos where he
demonstrated how the secure clipboard
works on graphene.
And one thing he pointed out is that
there are certain apps that as soon as
you copy something to the clipboard,
as soon as you open the app,
before you even hit paste,
they already read what's on the clipboard.
So if you've got,
let's say you've got three apps open,
and you're trying to copy from app A
to app C,
but you accidentally open app B along the
way for whatever reason,
and it's one of those apps that does
that, even though you never hit paste,
it can read what's on your clipboard.
So to me, and for the record,
I don't think all apps do that,
I'm just saying some have that capability,
which is why the secure clipboard exists.
So to me,
that kind of reminds me of this thing,
where when we talk about malware,
we talk about malware, right?
Like whether it's bundled in a cracked
game or a phishing link or something,
but I'm also thinking of just really
shady, unethically acting apps,
like a game you download or anything from
Meta that is not technically malware,
like it is not actually malware in the
literal sense,
But it basically behaves like malware.
And now it's probing your system and doing
all this stuff.
And now it could potentially be picking
up,
even if it's hopefully not picking up your
actual passwords and the messages you're
texting,
it could still be tracking what websites
you visit.
Like you said,
even though the browser is sandbox,
it can still use these other side channels
to track what you're doing and pick up
information that it's not supposed to
have.
And it's not a virus.
It's not actual malware.
It's just behaving like it.
And yeah, it just...
To me,
that's the big thing that stuck out to
me.
It's like, this is a problem,
and this is actually why I wanted to
include it on this stream,
is because it's like,
this isn't strictly malware.
This could be...
Sorry, I know I'm rambling a little bit,
but that whole thing with Signal a year
ago where Signal was storing the
encryption keys unencrypted on Windows
devices on the desktop,
and everybody was like, dude,
what the heck?
And they're like, well,
if you have malware on your computer,
you're already screwed anyways.
Okay, what if I don't have malware?
What if I have this?
So, yeah, I don't know.
To me,
this is just a really important thing,
and Microsoft is completely insane for
saying, yeah, we know.
I digress.
Let's see.
This sounds like a thing that does not
sound bad until more research is done and
then a real world targeted attack gets
done to show us an actual example.
Yeah, that too.
Now that it's out there,
how many tech bros,
this will be a quick rant, I promise.
How many tech bros watched Black Mirror
and then went, hey,
that's a good idea for a business?
How many other tech bros do you think
are gonna read this article and be like,
ooh, build this functionality in?
So yeah, pretty bad.
It's a situation like this malware can't
in a lot of cases,
read the files involved.
But if you can read all this metadata,
we talk about metadata,
revealing all sorts of sensitive
information all the time,
just in so in this case,
like just the idea that software can see
when you open the file,
even if it knows nothing about the file
itself,
that can reveal a lot of information.
So yeah, all of this metadata protection,
I think needs to be,
like always taken taken more seriously
than it than it often is.
I just want to say,
I think I might go back and read
the actual paper itself because I want to
see if Microsoft justifies why this is
there by design.
Like, what do you, why?
What purpose?
I don't know.
But yeah,
I don't really know if there's any,
because again, this doesn't necessarily,
this isn't taking advantage of any
vulnerabilities.
This doesn't,
um this isn't uh like actual malware so
i don't know if there's any defenses
against this other than don't use windows
um but yeah just being careful what you
download and run uh hopefully apple and
linux will roll out some some fixes for
this but yeah you got any additional
thoughts uh yeah i don't think so just
just goes to show that you know any
any local software you run just like you
said can
running anything locally will give will
give programs a lot of information about
you,
regardless of like privileges in a lot of
cases,
just because the operating system is so
vast, right?
There's so many potential things that
software can access that it just isn't
locked down.
So being aware of that is important.
Yeah, yeah, if you need further examples,
y'all should look up what's going on with
Meadows Muse AI on Mac.
That is the gift that keeps on giving.
Username is Nye said,
did you watch the Hotel Reverie episode?
No,
I haven't watched anything since the
season with Miley Cyrus doing Nine Inch
Nails songs.
I want to, I just,
I'm not gonna lie,
This is going to sound completely
deranged.
I miss the old Black Mirror where I
would watch an episode and be like, wow,
that was really good.
That was also really intense and soul
crushing.
And I can't watch another episode for at
least a week.
And I miss that version of Black Mirror.
Now it's more just like sci-fi,
like occasionally a little bit bleak.
And I'm like,
like that season I mentioned,
I binged that entire season in two days,
which at the time I was still working
like my super long hour job.
So two days is really fast for me,
was really fast for me.
So it's like,
What happened to that Black Mirror where
it's like every episode crushed me
internally?
Yeah,
I'm sure the creator of Black Mirror has
definitely said this in numerous
interviews.
But with this type of show,
you can't outpace reality at this point.
It's hard to think of things that wouldn't
already be done.
And I think some of the most recent
seasons of Black Mirror were absolutely
all about that.
Like that one where they made a parody
of Netflix.
But Netflix basically does...
They're working on all the stuff in that
episode.
They're working on AI content.
They're working on content specifically
tailored to you.
Yeah,
I just think that we've seen a lot
of the Black Mirror stuff come true.
It's real products.
I will say I did watch Hotel Reverie.
That was a great episode.
Yeah.
I mean,
I'm definitely planning to catch up.
I've actually been the last six months or
so,
I've really been putting a dent in my
to watch list and I've been catching up
on stuff.
So it's on my list.
It's just not very high on my list
because there's so many other things that
like, you know,
It's like,
I've been meaning to watch this forever.
I was really excited about this and I
just never had time.
And so, yeah,
and I'll get to it eventually for sure.
But yeah, I get what you mean.
Like the onion is like that too.
Like they have to go so ridiculously over
the top now because politics has gotten so
ridiculous.
It's the only way they can,
which that's a different thing.
But Jordan said,
is it really a stream if Nate doesn't
talk about sci-fi?
Yeah.
I was actually going to throw it out
there.
Since it's October,
I know a lot of people are doing
that thirty one for thirty one thing.
If you all have any horror movies you
think I should check out, definitely.
I don't think you can message me on
the forum.
I think I shut that off,
but I don't know.
We need to start a forum thread for
this.
I'm down.
Yeah, leave it in this forum thread.
I don't know, ping me.
I don't even know what Thirty One for
Thirty One is, should I?
Am I missing out?
I mean,
I'm not going to do actual Thirty One
for Thirty One because I'm just not that
committed.
It's basically every day of October you
watch a different horror movie.
And I mean,
I guess the good news is you can
circle back.
It can be movies you've seen before.
Good excuse to watch The Invisible Man
again.
I love that movie.
That is a, oh my God,
that is such a good movie.
Yeah, I love that one.
I don't know.
I've been on kind of a horror movie
kick.
I finally watched Weapons.
I finally watched Fall of House of Usher.
I've got like,
twenty minutes left on the black phone,
too, because I'm just, like I said,
I'm not that invested.
I mean,
I'm invested enough that I'm gonna finish
it, but it's like, you know,
I started watching it last night,
and it was like,
it got to be about bedtime and it
was still like an hour left in the
movie.
And I'm like, yeah, no,
I'm not that invested.
I'm going to bed.
And then today,
Fridays are always my busy day because of
the show.
So username is not,
the onion has no more material left.
How can anybody really, I think, I mean,
we definitely see that in black mirror.
I think the last season of black mirror,
uh,
unless there's been a more recent one that
i am unaware of i don't i don't
know how often they make these but the
last one that i saw it kind of
ended on like a werewolf note like we're
just getting out of sci-fi now you're kind
of you're trying to spin off into a
new franchise it seems like because you
just can't come up with any more any
more bleak tech stuff anymore i think the
the tech space is just bleak as is
so it's not not it's no longer
groundbreaking
I wonder if he's just afraid to inspire
more people.
Like I have a ton of ideas,
but I know that they keep watching this
and every time, because I'm telling you,
I've seen so many news articles and it's
like, oh,
there's this new startup that does this.
And I'm like,
that is literally a Black Mirror episode.
Why?
So I digress.
Yeah, I'm looking in the forum.
I'm looking in Signal.
I'm not seeing any more questions.
So unless you or anybody else has
anything, I think we can wrap this up.
Yeah, probably can wrap it up.
I mean,
we've asked for questions this whole time.
So if you haven't sent it in yet,
I think that's on you,
but you can save it for the next
stream.
For sure.
Yeah.
Do you want to wrap this up, Nate?
Sure.
I got this.
All right.
So all the updates from this week in
privacy will be shared on the blog every
week.
So sign up for the newsletter or subscribe
with your favorite RSS reader.
If you want to stay tuned as a
reminder,
that newsletter actually goes out right at
the same time that we start streaming.
So that works as a good notification as
well.
And there's a link to the stream in
the newsletter.
So super convenient, super easy.
We also offer a podcast available on all
podcast platforms and RSS,
which now includes video on supported
platforms, if you prefer that.
And this video will also be synced to
PeerTube.
PrivacyGuides is an impartial nonprofit
organization that is focused on building a
strong privacy advocacy community and
delivering the best digital privacy and
consumer technology rights advice on the
internet.
If you want to support our mission,
you can make a donation on our website
at privacyguides.org slash donate.
You can also make a donation on any
page of the website by clicking the red
heart icon located in the top right corner
of the page.
You can contribute using standard fiat
currency via debit or credit card,
or you can donate anonymously using Monero
or your favorite cryptocurrency.
Becoming a paid member unlocks exclusive
perks like early access to video content,
exclusive video content,
and priority during the Q&A.
You'll also get a cool badge on your
profile in the Privacy Guides forum and
the warm,
fuzzy feeling of supporting independent
media.
Thank you everyone who watched.
It was awesome to have you guys in
the chat and we will be back next
week.
Thanks everyone.