Mullvad’s Co-owner Made A Controversial Donation
E63

Mullvad’s Co-owner Made A Controversial Donation

Mulvad's co-owner made a controversial

political donation.

A U.S.

court has ruled border agents can search

your phone without a warrant.

And a little bit of good news from

Apple.

All this and more coming up in This

Week in Privacy, number sixty three.

So stay tuned.

Welcome back to This Week in Privacy,

our weekly series where we discuss the

latest updates with what we're working on

within the Privacy Guides community and

this week's top stories in data privacy

and cybersecurity.

I'm Jonah,

and with me this week is Nate.

By the way,

we're going to be ditching our Q&A section

we normally have at the end in favor

of answering questions just throughout the

stream.

So if you have any,

no need to wait.

Just ask away.

We will be checking the chat here,

of course,

and also

um our forum thread and our signal chat

for privacy guides supporters so any of

those places uh yeah let us know if

you want us to discuss anything anyways

how are you doing today nate i'm doing

pretty good um

Yeah,

I don't think I have much to say.

It's been a surprisingly good week,

I think, for me.

How are you?

Good.

You know, I'm doing good as well.

I was just talking to some people,

I know you know about this,

but this morning I booked all of my

stuff for DEF CON in a few weeks.

Kind of a last-minute booking,

which is how I normally handle things.

But that'll be exciting.

So...

If anyone is going to DEFCON,

it would be very cool to meet up

with anyone,

but otherwise I will be doing that and

I'm looking forward to it.

I've never been to Vegas before.

Have you been to Vegas, Nate?

Surprisingly, no.

I actually spent seven years in Southern

California and Vegas was only a few hours

away.

But for the majority of that time,

I was under twenty one.

And a lot of people told me that,

like, yeah,

there's stuff to do if you're not twenty

one.

But there's like and they're not even

talking about gambling,

which is like getting into places like

there's more stuff to do when you are

twenty one.

So I just never really made the time.

But that is really exciting.

I do want to go to DEF CON

one day.

So I hope you have fun.

Yeah, you should come.

Hopefully we can do it next year or

something a bit less last minute for sure.

Yeah, that would be super awesome.

But yeah,

I guess we'll go ahead and jump into

this week's stories and cybersecurity

stuff that you might be discussing at DEF

CON, possibly.

Who knows?

But we're going to start with our big,

big story, which is about Mulvad,

the Mulvad donation controversy.

So for context here,

this actually came to light a few weeks

ago.

I want to say like a month ago

that one of the co-founders of Mulvad VPN

named Daniel Bernson,

I probably pronounced that wrong, donated,

I believe some sources I've found said

five million Swedish kronor,

which is a little bit north of five

hundred thousand US dollars to,

I'm definitely going to pronounce this

wrong, the Orebro party in Sweden.

According to Wikipedia,

this party has been described as both left

and right wing.

But from what I can tell,

they're largely considered left wing.

And this, unfortunately,

this is relevant to the story.

Despite being considered largely left

wing,

the party apparently also has some

significant nationalist,

populist and conservative views.

And one of the big ones that I've

seen thrown around a lot that people are

upset about is remigration,

which is a term I've never heard before.

The summary I found said it's a policy

aimed at encouraging or compelling

immigrants to leave Sweden.

Another summary said the party's platform

includes strong secularism,

immediate closure of Islamic charter

schools,

and the assertion that Sweden belongs to

the Swedes.

So again, for the record,

these are summaries I read and I have

never been to Sweden.

I am not Swedish.

I don't think I know any Swedes other

than I think I've talked to some of

them all bad people for like two seconds

in the past.

So apologies if I got any of that

wrong, but that is what my research is.

turned up.

So again, this, this story started about,

I mean,

apparently this donation took place in

twenty twenty five,

but I guess it just came to light

about a month ago.

And Moldad has officially commented now

because this has become such a big thing.

And I'm just going to kind of pick

out bits and pieces of this story because

there is it's it's

It's not a huge, huge statement,

but it's a little bit too much to

just read off here.

Basically, they said,

this is a private donation from Daniel to

the individual.

Mulvad or its parent and sister companies

did not endorse and were not involved in

it.

And then they kind of went on to

basically say that, well, actually,

let me scroll down a little bit here

and read one more part.

Mulvad does not condone it nor condemn it.

It was most likely a bad idea.

Most things where there are a multitude of

conflicting opinions necessarily are.

i don't know about that but societies need

a great diversity of ideas initiatives and

organizations who can be tested and sifted

until the best ones remain ideally through

rational debate daniel's rationale and

points of view can be read on his

personal blog um which i'll throw up on

screen real quick just so you guys can

see it uh he has written quite a

bit actually um about a number of his

views both related to that party

specifically and politics um so you guys

can go read that if you'd like to

Just to clarify,

when I said I don't know about that,

they said the part where most things where

there are a multitude of conflicting

opinions necessarily are.

I mean there have been a lot of

controversial ideas in the past that I

would argue have stood the test of time,

but whatever.

Yeah.

So basically they go on to say in

this, this post, um,

to kind of summarize it,

they basically say like Mulvad is

nonpartisan.

Um,

their interest is in making a VPN and

providing people with the, uh,

the tools to bypass censorship and access

information and communicate freely and

privately.

And, uh,

they kind of point out like sometimes,

you know, we, we talk about this with,

um,

we talk about this with like,

like encryption, like necessarily people,

unfortunately are going to use encryption

to do bad things,

but that doesn't necessarily mean that we

break everybody's encryption.

Right.

And that's kind of the same argument that

they're taking.

And let me see if I've got it

all down here.

So yeah, Daniel, like I said,

Daniel's got his own blog post over here.

I'll be honest.

I had a little bit of a hard

time following his launch.

I mean, it is, is a lot.

And yeah,

I tried to read it all.

Again, I'm not Swedish,

so I think maybe some of the context

escaped me.

I also,

if I can be a little bit sarcastic

down here, he says, disclaimer,

the views in this text,

while partially inspired by the two who

founded that party,

are mine and not theirs or the party's.

And it's like, so basically you said,

here's why I voted for the party.

And by the way,

nothing I said is what the party said.

So I don't really understand what he's

saying there.

I kind of do,

but I kind of don't.

Anyways, if I read his blog correctly,

he's basically saying like,

he doesn't really believe in that party,

but he, again,

could be reading this wrong,

but he's kind of like trying to encourage

competition.

Like maybe if we have more viable party

options,

maybe the existing politicians will do

better,

which as somebody living under a two party

system,

I can say I kind of understand that

logic,

but I don't know how well it holds

up.

But yeah, I think that's a,

I think that kind of gets us up

to speed.

I think I'm going to throw it back

to Jonah at this point to kick off

the analysis.

Jonah,

could you maybe start by kind of like,

why, why has this become,

I think it's probably obvious for most

people,

but just in case anybody's wondering,

like, why,

why has this become such a hot topic

in the community?

Do you think?

You know, I think well,

in terms of why it became a hot

topic,

I think that the privacy community in

general is a fairly political community

because obviously we are fighting for

privacy, digital rights.

A lot of that has to do with

not only, you know,

getting privacy from big tech companies,

but also having privacy from the

government and making sure that the laws

of

you know,

where you live are protecting your privacy

rights.

And we talk about privacy policies and law

on our forum and on this channel all

of the time.

And I don't think any of the policies

that this party has are specifically

privacy related,

although there are certainly some privacy

implications with some of the re-migration

stuff that they're doing,

which is a whole separate topic.

But it's not surprising to me that

that people who have an interest in

privacy are also going to have an interest

in a lot of other political topics.

And so

It's definitely controversial because it's

the sort of thing that is going to

blow up on social media.

We've seen a ton of this talked about

on Mastodon and on Twitter,

and I'm sure on other platforms where

Malved is as well.

Obviously Malved was feeling the pressure

because they had to post a full response

about it.

And I think a lot of people just

have questions about what it means

for Malvet,

especially if they don't feel like

supporting these policies.

And so we could take a look at

some of the questions.

We've received questions just during this

show already and some statements.

We could look at Take Out the Lobster

on YouTube said,

it's not really an extreme party.

If that's what you're getting at,

sincerely, a Swede.

I will say, neither of us are Swedish,

obviously.

I mean, maybe ancestrally,

but not living in Sweden.

I have no familiarity with Swedish

politics,

and I assume Nate does not really either.

I don't really know much about this party,

to be honest,

and they seem to be all over the

map.

I don't think the question is how extreme

they are, but they do seem to be,

from what I've gathered and from what

other people have said,

just a very populist party,

which is the sort of thing where...

A lot of the times with these populist

parties,

they will have a lot of policies and

say a lot of things mainly to get

votes and support more than actually

supporting it.

And they might not even believe any of

the things that they're supporting.

Or they only have certain policies that

they care about.

I think that this is a big problem

with some parties,

especially ones that are described as both

right and left wing, like this one is,

like Nate was saying.

Because in a lot of cases,

when a party seems like they are kind

of on all sides of the aisle,

they're actually only supporting one side,

but they want to get votes from anyone

that they can convince.

I don't really know...

where I don't really know.

I guess at the end of the day,

his support for it doesn't make a lot

of sense to me.

He said in his own blog post that

he doesn't really support many of the

policies that this party supports.

So I don't know why.

I think it was at the end there,

if you have it on the screen, Nate.

But

Yeah,

it doesn't make a lot of sense to

me to become that party's biggest

supporter But again,

I don't know how much this competition is

really needed in the Swedish political

space A lot of the questions that I've

seen are more about like Just how much

of Mulved's money is actually going to the

causes that the co-founder supports and

As far as I know,

Mulvad is basically co-owned fifty-fifty

between him and another person.

And they're co-CEOs and they kind of just

split everything down the middle.

And so it's, I don't know, Nate,

you could probably elaborate more on this

a bit,

but in terms of like whether you should

continue using Mulvad or not.

It's less of a privacy or a technical

decision and more of a philosophical or

political how you feel.

At the end of the day, your money,

if you support Malved,

some of that is going to be supporting

these things that one of the co-founders

cares about because he's getting the

profits from Malved, right?

Even if Malved's not directly doing it,

you're...

sending money that way which is something

to consider but at the same time you

know you can separate the art from the

artist and if mulvet isn't directly

supporting themselves it's just one guy

who's profiting off of it maybe that's

less of a big deal to you i

don't know what do you think nate i

think it's um i think it's really personal

preference um real quick just to kind of

go back to uh to what um take

out the lobster said uh what i was

getting at is basically just that i just

wanted to

I don't know if hedge my bets is

the right word, but basically like,

I don't know a lot about this party.

I hadn't really heard of them before.

So it was kind of my, like,

I wasn't trying to insinuate they're

necessarily an extreme party.

I was more just saying like,

I apologize if I'm summarizing this wrong,

but yeah, I think it's,

It's so tricky because I think both of

those takes are true.

You know,

Eteru said here that he said in a

real fight,

nobody drops the best shield just because

they dislike the creator.

But at the same time,

I think it's not quite the same.

Like, I see where you're coming from,

and you're absolutely right.

Like, if I was in a firefight,

I'm going to use whatever protection I

have available to cover myself.

But it's so, like...

I don't know.

I think that's a valid take,

but at the same time,

I think not wanting to – because when

you're subscribing to Moldad,

you are directly putting money in this

man's pocket.

Like, full stop.

You are.

Period.

Full stop.

And so you're giving money to him,

which he then in turn turns around and

gives to a party that –

may have serious like political things

that you don't believe in.

You know, if,

if he's talking about forcibly removing

immigrants from the country and you know,

like,

like maybe that's something you don't

believe.

Maybe, I mean, like my wife is Hispanic.

I don't like people.

I'm just going to say here in the

U S I don't like people who have

that whole, like, Oh,

we need to kick them all out.

Like, you know, it's, I don't know, man.

I think they're both valid takes is what

I'm getting at.

Like, if you're like, no,

it's the best tool we have.

it's his money and i don't think we're

gonna find a better tool i i think

that is a perfectly valid take but i

also think it's completely reasonable that

some people would be like yeah but my

money is directly supporting him which is

in turn directly supporting them so it's

basically like i'm giving money to them

but just through a proxy and i don't

want to give them my money like i

think that's also a perfectly valid take

um

Personal opinion,

I think I would like to see in

the community itself,

I think I would like to see more

appreciation for that.

I think not to like kind of be

judgy and call people out, but you know,

this whole, like you said, again,

this comment,

this MOVAD drama shows how people confuse

politics with engineering.

No, like technology is political.

I'm kind of, I don't know.

I'm one of those people who thinks that

everything is political when you dig deep

enough and there's really no such thing as

being non-political or apolitical.

And so it's like,

I think understanding that for some

people, this is really important to them.

And I think that's valid.

And just having that kind of patience that

for some people,

they care for some people, they don't.

And this is something that comes up a

lot.

I think most of the time when like

people say that they're not going to use

something that's widely recommended,

like MOLFAD, we see it with Graphene OS,

for example,

we see it with other projects.

We see it with Proton all the time,

where I think

When somebody says they're not going to

use something for some non-technical

reason,

there's a group of people who get mad

that they're doing that and that they're

not using it,

which is a reaction that doesn't make a

lot of sense to me.

If somebody isn't going to use Malved

because of this,

I don't think there needs to be a

whole argument about why the politics and

how this doesn't actually matter because

Malved is still secure.

It's fine if you don't want to financially

support this sort of thing.

But yeah,

just kind of an annoying thing that I've

seen in the community beyond Malbed's

stuff.

I would say the other thing I wanted

to point out really quick,

I did see a lot of comments in

the community basically talking about the

potential privacy implications for some of

these policies.

The re-migration one in particular,

it does call into question

A lot of privacy concerns about how those

people would be found in Sweden,

for example,

and how they are determining who needs to

stay and who's going to leave,

what metrics are they using.

Obviously, here in the United States,

we've seen a lot of news about ICE,

for example,

and how they're using facial recognition

everywhere,

and they all have these apps on their

phones that they can scan people with,

and all of this data is being collected

into databases.

All of those immigration policies and some

of the stuff that this party is supporting

can directly have privacy implications for

people living in Sweden.

And obviously, we've seen already,

maybe it's not obvious, but in the US,

people who are not targeted by these

policies,

like American citizens who were born here

in whatever,

are are also swept up in in these

privacy invasive things that the

government is doing and it's very possible

that if policies like this were

implemented in Sweden a similar sort of

thing would happen where you know it's not

only going to be targeting illegal

immigration but also it's going to sweep

up Swedish citizens into this this whole

immigration system and a lot of people I

think

Will probably be opposed to that just from

a privacy perspective as well.

I did see a lot of comments about

that on the forum.

So I did want to bring it up

because I do think a lot of people

are saying like, well,

there's no privacy implications at all.

So if you only care about privacy,

it doesn't matter too much, right?

Um,

Yeah, I mean,

there's so many questions and comments on

this one.

Let's take a couple from Jordan's been

relaying some from the Signal chat.

Yeah.

Let's start with some of these.

So how is the co-owner?

I think you answered this.

How is the co-owner invested in Mulvan

financially?

If I pay for Mulvan,

in what way I pay him?

Well, first of all,

I think you said there are fifty fifty

owners.

But also, like, I want to point out,

he draws a paycheck.

That's my understanding.

Yeah.

I don't know how that aspect of it

works because, you know,

when you own a company,

and Movit is a private company,

so all of this stuff is not going

to be, it doesn't have to be disclosed,

basically.

But when you own a company,

you can take a paycheck or a salary

for all of the actual work that you're

doing.

But then if you're an owner,

you can also take profit sharing,

which is usually quite a lot more.

It's why you see all these billionaires

who are like,

my salary's a dollar because they just get

all of their...

money via other means so they don't need

to pull an actual salary.

So I'm sure he takes a salary and

like normal income,

but in terms of what he could be

getting beyond that,

I would imagine it could be up to

fifty percent of the profits.

I don't know who else is entitled to

to get that money outside of Malved,

but could potentially be quite a bit of

support.

Yeah, I know this isn't really the point,

but just to throw that out there,

that's also – it goes the other way

too.

Sometimes you'll see like, oh,

this CEO is making like fifteen million

dollars a year, and it's like, well,

they're actually making less than that.

But when you include all the stock options

and this, that, and the other,

which for the record,

they're still making a disgusting amount

in –

Not literally disgusting,

but they're still making a crap ton of

money in raw liquid cash.

But yeah,

it's usually it's not fifteen million

dollars in liquid cash.

It's like some million in liquid cash and

then the rest is stock options and stuff.

But I don't know if all that works

the same way, but I digress.

Um, so yeah, uh,

here's a fun one from Signal again.

What were the relevant statements and

actions the Mulvad company took to

distance themselves from that and prevent

it in the future?

Uh, none really, to be totally honest.

If you, I mean, if you read this,

this, um, statement, it,

it very specifically says that like,

I don't even know how to summarize it

to be totally honest,

but they didn't condemn it.

They didn't endorse it.

They just basically said this happened and

we don't care and we're just going to

keep doing our thing.

Yeah,

their position is definitely that they're

not going to police what their owners are

doing or what their employees are doing or

what anyone is doing in their personal

time.

It's just going to be...

You know,

Malved themselves are not going to support

things like this,

but what people do with the money that

they earn from Malved is kind of their

problem, is Malved's position.

There's a question on the forum,

and Jordan asked a similar question

earlier in the chat,

so I can kind of cover it.

both of them.

Jordan asked if there should be

restrictions on executives making

political donations to stop this sort of

thing.

Somebody on the forum thread asked at what

point is it acceptable for an executive or

lead developer to support something that

could be deemed controversial.

You know, at the end of the day,

I think all...

executives of companies that have

customers like mall fad are public

figures, whether they like it or not.

And so all of their the things that

they do in their personal lives and the

personal choices that they make,

they're gonna have business impact.

And obviously,

this has had some business impact at mall

that because they had to speak out about

it.

And a lot of people are saying that

they're canceling because of the co owners

personal decision here.

So

mean it's always going to have an impact

at what point is it controversial or

should there be restrictions it really

just depends on the company i think you

know it's not unreasonable i i was

explaining this on the form uh in the

form thread about this to somebody but

like it is fairly normal when you're

dealing with public figures whether that's

an executive of a company or if you're

like hiring an actor for a movie or

something to have clauses in their

contract or morality clauses that kind of

restrict them from

doing controversial things like this

because it does have an actual impact on

the business itself.

It's not just a personal thing.

So like that is something that well that

could do but whether they should do that.

is another question entirely and it kind

of comes down to what the company thinks

is an acceptable risk i mean it's not

like you can mandate this and make like

make it a law or anything um it's

just it comes down to whether malvad wants

to accept that uh it's gonna have an

impact on their business and it seems

clear from their statement that they are

just going to accept that as a as

just the fact of life for their business

A similar story,

I don't know how many people,

maybe not a lot of people know about

this,

but I've read a lot about it because

I've been looking for merch and stuff for

privacy guides and I see people talking

about it on Mastodon,

but a lot of people used to really

like Sticker Mule for stickers and then

their owner turned out to be a big

Trump supporter,

so now a lot of people don't want

to support that company mainly based on

that.

So it's kind of a similar thing.

the personal leanings of the owners of

these companies is going to have a

significant business impact,

whether you or they like it or not.

It's just how it is.

Yeah, I don't know.

I don't know.

I don't think I have much to add

to that because I'm with you in the

sense that I don't really know where that

line should be because on the one part,

they are public figures and you're right

about that stuff.

And people are going to have those

reactions either way, right?

I mean, like,

it happens on both sides of the aisle.

Look at, you know,

Bud Light had like a trans person as

their spokesperson at one point,

which was really weird to be honest for

Bud Light.

That was definitely off brand for them.

But you know,

it happens on both sides of the aisle.

And, but at the same time, it's like,

as a person,

like I remember when I was in the

military, that was the rule there is like,

you don't do anything public,

especially in uniform.

Like, yeah, go vote, go do whatever.

But like,

you are not allowed to speak out publicly

as a uniformed military member and be

like,

I support Obama or whatever publicly.

um so yeah it's it's it's i think

that's where this whole like i think

that's where a lot of the controversy is

coming from is where is the line between

like this person is an individual who has

the right to support whatever ideas they

want even if they're garbage ideas and you

know where is the line between that and

like well your your customers have an

expectation of you and i think you made

a really good point that like the company

definitely depends a lot i think if you're

in like um

If it's like some kind of nonprofit that's

like providing legal assistance for

immigrants and then they go out and donate

a bunch of money to Trump,

that would be super weird.

But yeah, I don't know.

It's tricky for sure.

Kind of related that we had a comment,

kind of an opinion from either you,

hopefully I'm saying that somewhat

correctly,

who said that voting with your wallet is

valid for personal ethics,

but in threat modeling,

prioritizing political alignment over

technical robustness is a trade off.

Kind of two things I want to unpack

here.

The first thing is simple.

I think with VPN companies in particular,

we got to understand that these are not

zero trust technologies like you're

talking about,

you do have to trust your VPN provider.

And so this kind of thing does come

into play because a VPN provider is

basically like an ISP.

You're just shifting your trust to that

VPN.

You're not eliminating the risk involved

with an ISP seeing all of your data.

That's what we're pretty clear about on

our site is the main use case for

a VPN.

So if you don't trust the VPN,

there's literally no point in using it.

And this is a trust question.

but when it does come to zero trust

things or things that can be more

technically cryptographically proven uh

you know i think there is a solid

point here going back to what i was

saying about um graphene os for example or

proton mail with with these sort of things

there are guarantees there's

inspectability so people can um like

see what code is running on Graphene OS.

It's open source.

People can see, like,

Proton is using end-to-end encryption,

so they can't read all of your messages

at rest.

That sort of thing is important,

and it does eliminate trust,

and I think when you can eliminate trust

whenever possible,

which is ideally how all privacy products

would work,

then this kind of thing does become less

important over time,

and it is more of just a personal

morals thing at that point.

I don't feel that bad about it in

this case,

because there are perfectly good

alternative VPN providers you can choose

from.

We have other recommendations on our site.

Whether this is going to cause us to

change our recommendations on our site and

stop listing Malvet,

I don't think it's going to.

And in fact,

despite how controversial this topic has

been and how many people are posting about

it,

I haven't seen anybody really suggest that

we do that.

You know,

you can definitely separate it a bit.

But in the case of a VPN,

I do think it's valid to be concerned

about this at the very least.

Yeah.

On that note,

I did want to make sure that we

pointed out that, um, not,

not trying to tell people what side they

should take,

but this is not something that at this

point in time,

we have any reason to believe is impacting

mold ads, actual technical product.

So again,

going back to that argument of like,

some people are like, I don't care.

It's his money.

It's his business.

The product is solid.

The product is still solid as far as

we know at this time.

And, um,

I think that's something worth noting.

And kind of related to what you were

just asking, somebody in the forum asked,

I'd like to know from the staff what

they think of Mulvad versus other

companies in terms of what they contribute

overall.

Are they offering unique benefits,

not just in their current VPN where we

know there are other good options,

but in terms of what they bring to

development, research, privacy,

advocation, et cetera?

And honestly, yeah, kind of.

I don't know how I feel about sticking

up for Mulvad because I'll make it clear.

I don't agree with the policies of this

party that he supported.

But they ran a huge campaign all around

the world to try and bring privacy more

to the mainstream.

I remember seeing Mulvad buses when I was

in Seattle for something last year.

And I saw the Mulvad buses and I

tried to grab a picture,

but they went by too fast.

I was like, oh, that's cool.

There they are.

But they ran this big ad campaign.

I think they've been...

I could be wrong,

but I think they've been pretty vocal

about being against chat control.

I mean, you say research and development.

They do a lot of innovative things,

in my opinion,

like these RAM-only servers and

their data service, things like that.

So like, yeah,

I think they are really innovative.

And actually there was one other thing I

was gonna point out.

They're not unique.

I'm gonna share this tab real quick.

Jordan brought this to my attention a

while back when we were chatting.

There's a Medium post.

After Andy N went and like made some

kind of pro-Trump comments,

somebody kind of pointed out, and to me,

for the record,

I take this post with a little bit

of a grain of salt because this person

has never posted anything before or since.

And, but, you know,

they point out that like,

Proton has historically donated to a lot

of organizations that are not necessarily

aligned with stuff like that.

And so anyways, my point being is like,

yeah,

MoVAD is not the only company that's out

there donating to good or to,

I shouldn't say good organization.

MoVAD's...

Putting this issue aside,

there are other companies that are out

there doing good things in the privacy

space for advocacy and research and stuff

like that.

And I wanted to tie that back into

what you said with that question.

It mentioned threat modeling.

And yeah, you could go with,

I would feel pretty safe saying that I

think Moldat is probably the best option

right now in terms of privacy and security

and a VPN.

But at the same time,

what is your threat model?

Like,

if your threat model is so high that

you cannot afford anything less than

MoVet,

you probably shouldn't be using a VPN.

You should probably be using Tor or

something like that.

But, you know, Proton is still good.

IVPN is still good.

Like,

I think there are still good options out

there where for your threat model,

you don't have to sacrifice privacy and

security to also still be ideological.

So, yeah.

Okay.

I will add though, on the other hand,

while there are companies that are doing

innovative things just like Mulvet,

I think there are probably companies where

their leadership or employees are doing

controversial things that you don't know

about and haven't heard about.

Some of these things are kind of

unknowable.

And so that's what makes it hard,

I think,

to base your decisions around this.

I mean,

now it's kind of proven that if you

don't agree with the ethics of the

situation,

now you have proof that Malved is

unethical in your eyes.

But you can never really prove that a

different company is any more ethical than

that,

because they could be making very similar

donations behind the scenes that you just

have not heard about.

So it's why it's the sort of thing

that it's hard to...

take as a huge factor when you're making

a purchasing decision, for example,

in my opinion.

Yeah, for sure.

I don't want to be too defensive,

but I do want to point out Gaethje

said, both sides of the aisle.

Bud Light, as we support people,

be yourself.

For the record,

that's not what I meant when I said

both sides.

What I meant is that both sides do

things that alienate their fan base.

No,

I do not believe that both sides are

the same, personally.

So...

I just mean they both do things that

alienate people, but I digress.

Wow.

We spent a lot of time on that

story, but that is,

it's such a complicated story.

It's just, and it's, again,

I want to reiterate in my personal

opinion,

like I think both arguments are valid.

If you're like, well,

that's the best VPN and you want to

stick with it, go for it.

But just be aware where your money's going

and vice versa.

If you're like, nah, screw these guys.

I want to take my money somewhere else.

Like, I think that's cool too, personally.

So.

Was there anything else we wanted to add

to that one before we move on to

the next story?

Yeah,

let me just look at the questions quick.

I don't think there's any remaining that

we haven't answered,

at least about Malvad.

So we can kind of move on.

But if we missed any or if we

missed one in Signal,

feel free to send it again and we

can look at it.

otherwise i think it's probably a good

time to move on to our next story

here uh before i talk about that one

though i want to go back to some

defcon questions we had from earlier

somebody on youtube dragon black knight

asked about hope i'm not going to go

to hope um there are so many conferences

that i would like to go to uh

carrie parker from firewalls don't stop

dragons is in the uh

is in the chat and explained why he

wouldn't be going.

And it's pretty much the same reason for

me.

That's kind of a lot to be doing

right now.

But there are a lot of cool conferences

to go to and there's cool ones in

Europe that I would like to go to

maybe next year.

But at the moment,

no i have no other plans for for

any of that uh somebody else uh in

our signal chat uh in jordan shared this

here um as if we're doing any kind

of meetup at defcon and no privacy guys

isn't doing anything at defcon but if

anybody does want to meet up um send

me a message because i would love to

say hi to people who watch this stream

or or

are familiar with privacy guides in any

way so i will be there i'll be

there uh six through the ninth so yeah

come say come say hi

I didn't put two and two together that

that was about the DEF CON thing.

I just saw his privacy guides doing any

kind of meetup, and I'm like,

that's kind of out of left field.

Why would we be doing a meetup at

DEF CON?

That makes sense.

Yeah,

there was a bit more context in the

signal group than in the chat shared

there.

Yeah,

I need to add the signal chat to

this computer so I can read it during

the streams.

I'll have that in time for next week.

Alright,

I think that's kind of that for now.

We'll move on to this story posted by

the EFF.

The headline is,

An explosion of surveillance towers is

coming to US borders,

costing over one billion dollars.

A new report from the Government

Accounting Office reveals that the

Department of Homeland Security, DHS,

plans to nearly triple the number of

surveillance towers along U.S.

borders from the current eight hundred

thirty to twenty three hundred by twenty

thirty four.

EFF says here that the IST program

operates autonomous surveillance towers

consisting of

AI-based systems using radar, thermal,

infrared,

and optical systems to track targets over

long distances,

integrated fixed towers which are

optimized for surveilling foot traffic and

vehicles,

and remote video surveillance systems

which can often be found very close to

the border fence in Arizona,

including residential neighborhoods where

cameras are capable of spying on homes on

both sides of the border.

They say that DHS expects to purchase more

long-range autonomous towers and to

upgrade existing towers with autonomous

capabilities.

The one billion dollars comes from the

so-called One Big Beautiful Act,

a massive tax in spending law that

President Trump signed into law in twenty

twenty five.

They point out that the technology isn't

exclusive to U.S.

federal agencies.

It's also deployed by state and local law

enforcement,

and it's also deployed by governments on

the Mexican side.

So yeah, a lot to unpack there.

Nate,

what are you thinking about all that?

Yeah,

I think the big thing that stuck out

to me, I mean, first of all,

I think we kind of wanted to share

this because like, yeah,

that's a lot of surveillance towers.

I'm assuming they're

relatively cheap in the sense that a

billion dollars probably buys quite a few

of them um the the thing that stuck

out i guess we know how many it

buys right what's the twenty three hundred

minus did they say oh yeah eight hundred

thirty fourteen one thousand four hundred

seventy yeah i mean to be fair that

probably includes like install costs and

stuff yeah yeah but um no so the

thing that jumped out at me is um

I have driven cross country multiple times

and driving through El Paso,

like if you're crossing from El Paso to

New Mexico or vice versa,

is a really wild experience because you

can literally look out one window and see

this like beautiful,

I think it's like a university or

something,

literally sitting on a hill and it's huge

and it's gorgeous.

And then you look to the other side

and you can see the,

what do they call them?

The like,

the little sheet metal shanty towns in

Juarez, literally across the...

I'm not kidding.

It is a very surreal experience.

And I know that in towns like that,

where there are towns that literally butt

up against the border,

some people cross back and forth for work,

but a lot of people don't.

And my first thought is like,

there's no way that these cameras won't be

catching people

who are just going about their business

you know it's it's it's designed to

monitor the border right and people

crossing the border but there's no way

it's not going to catch the people when

the towns are literally that close it's

not going to catch the people driving down

the highway walking their dog going to

school going to work on their side of

the border like it's just it's going to

catch everybody and that um that very much

uh was kind of my first thought of

like there's

I guess the privacy concern is how it

catches everybody,

even if they're not crossing the border.

Yeah, and kind of famously,

the border control agency,

they have authority, what is it,

like a hundred miles inland or something

like that?

People talk about that when they're

talking about airports all the time,

but it's true here too.

It's not just like towns that butt up

right against the border, right?

They can potentially install these quite a

ways into the United States,

and it could potentially impact a lot of

people, right?

Yeah,

I think any international pretty much any

international port,

whether that's a border, a seaport,

an airport.

So, yeah,

it's honestly there's not a lot of the

U.S.

that isn't covered when when you expand to

that definition,

because there's a lot of like

international airports in the middle of

the country and stuff like that.

So, yeah,

I don't know if that legal theory that

airports are included has been like tested

in court or anything, but like in theory,

it's possible.

But certainly when we're talking about

like a physical border between countries,

it's definitely true.

So it would apply here.

Yeah.

I think the other thing that jumped out

to me is, you know,

I always want to know that like we

were just we just spent thirty minutes

talking about a story of nuance.

Like there is nuance.

Like obviously we want to protect our

borders.

You know,

there are cartels and there are people

crossing illegally.

And but it's just I don't know, man.

It's it feels like one of those things

where it's like a.

Some military general said something about

killing a fly with a sledgehammer.

It feels like this might be overkill,

I think.

Yeah,

Draken said here that most of the US

population lives within that hundred mile

buffer zone, which I think is true,

actually.

Yeah, I was just fact checking that,

but I believe it is true.

Yeah, it's pretty wild.

Yeah.

Vonnegut said,

sounds like the West Bank where there's

settlements that go right up against

refugee camps.

And honestly, yeah,

it's kind of like that.

It's at least the El Paso thing I'm

thinking of.

It's pretty wild, but... I wonder if I...

I think I don't live in that zone.

I think I'm a hundred miles away from

Canada.

I guess I don't know for sure.

I'm pretty sure we live in that zone.

I know there is a map I found.

I think it was from the ACLU did

a map one time of that hundred mile

zone and it's...

Yeah.

It did not include airports or anything.

It was literally just a hundred miles

around the country.

And it's,

it's pretty shocking how far in it goes.

now I kind of want to go see

if I can find it but I digress

yeah real quick I also want to say

I know I'm going to try not to

be political because we've already been

plenty political enough but I think there

are a lot of people I mean we

just covered that with this last story

where it's like oh it's you know it's

all about the tools it's all about the

encryption and they kind of ignore the

politics but like this was directly funded

by the one big beautiful bill act so

it is kind of important to remember that

there are impacts on this stuff and I

would encourage you to try to

to be politically aware,

at least to the extent that you can

handle.

I know it can be really depressing

sometimes that your mental health does

matter, but this stuff does have impacts.

That's all I'm going,

or all I'm getting at.

John in the chat said that the Great

Lakes are considered part of the border.

Yes, that's true.

I do think Minneapolis is more than a

hundred miles away from

any of the Great Lakes,

if I remember correctly.

So I'm pretty sure I am safe,

but I'd have to find that map.

But definitely if you're in probably

what's around the Great Lakes, Wisconsin,

Michigan.

Ohio, Indiana, New York.

The entire Northeast, basically.

Yeah, because when your state is so small,

there's probably,

I don't know how wide

all of those states are but they might

not even be two hundred miles wide in

some cases and so that's gonna cover the

entire state and some of those are quite

large because you'd have to like if you're

in Vermont or something you know you got

the Canadian border on one side you got

the ocean on the other which is also

a border so that hundred miles goes both

ways so yeah does not surprise me that

two-thirds of Americans live in that zone

i'm trying to find this map i found

an interactive one from arc gis that's

kind of cool oh here we go i

think this is the one i was looking

at from the aclu uh as soon as

it'll load carries in the chat saying that

he interviewed nate wessler who had some

points about that so i guess we can

uh show his podcast a bit go check

out that episode i'll have to listen to

that i have not i have not caught

that one

I am still way, way behind.

I think I'm still in April on my

podcast.

So it's fun, though,

because it's almost like a little low-key

nostalgia.

They'll be like, oh,

this incident happened in the cyber world.

And I'm just like, oh, I remember that.

I will say, yeah,

Vonnegut Rosewater said that they haven't

seen a border patrol officer.

Yeah, I mean,

I don't really see them except at the

airport.

There's probably some on the actual border

of Canada,

but it's not like driving from Arizona to

Mexico.

I've done that once and there were border

checkpoints and stuff along the way.

It's definitely not as much of a thing

up north here between the US and Canada

as it is by Mexico.

That's actually what I was about to say.

I thought you were going to say, yeah,

you don't really see them that often.

And I'm like, no, I've, again,

driven in the south a lot.

I've been through the border checkpoints.

Don't see them often here specifically.

Fair.

Which I think kind of removes people from

the whole question a bit because they

think it's not a big deal.

It's a huge thing down there.

It took forever,

but I finally found a map.

Let me throw this up real quick.

yeah that's that's just the coastal border

or like that's not including airports so i

mean like every major city los angeles new

york um those two are almost like ten

percent of america's uh population right

there miami houston seattle buffalo

chicago so fun times yeah

the entire state of Michigan,

the entire state of Maine.

Oh, man, that sucks.

Almost all of California.

Man, that sucks.

Anyways.

Yeah,

that's a map you can go look at

if you do enough digging, I guess.

I think...

Let's see here.

I'm checking the thread.

We're keeping an eye on that as we

go.

All of Florida.

Yeah.

Delaware.

Yeah,

the forum thread had some comments about

this news story,

but I don't know if there's a question.

Let me see here.

Yeah, I didn't see a question.

Yeah,

just some more comments about Molotov

Head.

On that note, though, again,

we're trying some new stuff.

And one of the things we're going to

try is we're going to check in with

the forum periodically and see what's

going on there.

So our forum is always very, very active.

And this week has been no exception.

Lots of chatter going on there,

lots of cool questions and stuff.

and uh this was a a question that

i had a lot of thoughts on but

i i think you did too because uh

you kind of flagged this one in the

show notes is there space for another

private messaging app um do you want to

uh take that one first yeah let me

let me pull it up here um sure

thing this was basically a thread it was

posted a couple days ago asking about um

whether another privacy-related private

messaging app is needed,

whether this version should build one.

And there's a lot of comments about here.

A lot of people saying...

It's probably not the greatest idea,

which,

and I didn't even realize that you posted

a comment about this,

so you can go into some of the

things you were saying after this.

But it doesn't make a lot of sense,

especially with things like the network

effect, for example,

meaning that everyone has to get on board

with a messenger for it to be useful.

It's why we kind of tend to only

recommend Signal,

because it's a net positive if everyone is

on Signal.

this best all-around messenger instead of

using ones that might be technically

better but are less likely for a lot

of average people to use.

The main thing I saw at the beginning

of this

FormThread,

this person said that the biggest walls

are infrastructure cost if it becomes

popular and getting people to join the

network.

And I just mainly wanted to say that

that second point is like way,

way bigger of a wall than the first

point.

Like massively, massively larger problem.

And so if you're only solving the first

problem,

you're not getting anywhere close to like

building a viable messenger.

And I think a lot of people...

even when presented with perfectly good

options are not going to switch so yeah

unfortunately I just cannot encourage

going down this path I think like I

think signal is a very good messenger

obviously I think if you're very concerned

about centralization I think simplex is

also a good one to look into and

between those it's kind of hard to imagine

why you would use

other ones there are other ones that i'm

interested in um personally i really like

what delta chat is doing but a lot

of people that's a very controversial one

on the forum a lot of people really

really do not like delta chat which is

why we only fully recommend it for

everyone right now it's kind of being

debated but like they're at least doing

interesting things that i'm following

There's obviously Matrix and other ones

that have been around as well.

I think at present we kind of have

too many messengers.

The problem isn't needing more messaging

software,

it's getting people to use messengers that

are more private than Telegram and more

private than WhatsApp and more private

than normal SMS and whatever.

So yeah,

maybe you can talk a bit about this

post that you wrote here.

Yeah,

the messenger thing is one of my pet

peeves in the privacy space.

I feel like, like you said,

we have too many messengers.

And for the record, yeah,

none of them are perfect.

I will give you that.

And I think there's even pros and cons.

Because Signal, for example,

a lot of people are upset that Signal

is centralized.

And that has come back to bite us

before.

Signal has, on very rare occasions,

become overwhelmed and crashed.

And I think that...

I think that's valid,

but Signal also makes the point of, like,

we're centralized because, you know,

there's abandoned Matrix servers and

Mastodon servers that are, like,

ten versions out of date and stuff like

that.

So there's literally pros and cons to

everything.

And, um...

I think my thing,

and I kind of went off on a

big tangent here,

but my thing is I feel like people

are focusing,

and I feel like this original poster said

it really well.

Basically, he was like,

I'm a software engineer,

and I've been diving into messaging apps.

And to my surprise,

it's not that difficult to build a

messaging app.

So apparently that's why there's twenty

billion of them.

But the problem is people are focusing on

messaging apps too much, in my opinion.

And I feel like it's one of those

things that like it's sexy, it's exciting,

it's not hard to do apparently.

But, you know,

there are so many apps and I like

I've listed so many here where like there

are no really good like budgeting apps,

especially for phone.

I know we've got like a new cash

or something.

There's like one calorie counter that

looks like it's from nineteen ninety.

Um, as, as a married person,

I think about things like grocery lists,

like right now,

me and my wife have a shared note

in Bitwarden that we use as a grocery

list,

but we don't have an actual dedicated like

grocery app where you can check things off

as you go.

Um, and for the record, like, yeah,

you can't make it like a one-to-one

replacement with the grocery stores app,

because that one will let you do like,

here's the exact item and here's the row

it's in.

And here's a picture of it.

Like, I,

I'm not expecting it to get that good,

but yeah.

I mentioned, you know,

where's a consent based location tracker

so that when the single ninety five pound

girl goes on a blind date,

she can let her best friend track her

location for the next twenty four hours

for safety,

which I think somebody did actually post

something like that recently.

I meant to bookmark it and keep an

eye on it.

But, you know,

I think later on I mentioned some other

ideas that

What else have we got out there?

I don't know.

Maybe I deleted them all.

I reworked some of these messages, but I,

and another thing,

cause I went and I asked my wife,

I'm like,

I know you have to have opinions on

this.

And she's not even that into privacy as

much as I am, but you know,

it's like,

what do you think she's missing?

And in her opinion,

it's like the appearance of these apps.

Like a lot of these apps are very

bare bones and they look very dated.

And some people don't mind that.

Like personally, I don't mind.

I think old Firefox was fine.

I definitely realized that the new fire or

not Firefox Thunderbird,

the old Thunderbird, like,

the new one definitely looks better,

but I didn't mind the old one.

But then there's some things that look

really, really dated and really outdated.

And, you know,

a lot of people want something that looks

visually appealing,

that captures their attention.

And a lot of things nowadays just don't

look like that.

Like they're designed to be lightweight.

And, you know, like,

I feel like some people are just so

hardcore.

Like if you had one extra line of

code that doesn't need to be there now,

all of a sudden it's bloated and it's

completely unusable,

but

But the looks do really matter for some

people in the user interface.

And I think just making things,

bringing them into the twenty first

century and and making them look good and

making sure they're updated like some

things just never really get updates,

which I mean, granted, you know,

things for like a note taking app probably

doesn't need to be updated that often.

But again,

if we had one that looked modern and

stuff like that, so.

I don't know.

That's kind of what I would focus on

is I think we already have too many

messengers and I would like to see people

dedicate their attention to other things

that look good, that work well,

that have the features we need.

I think we need more options in those

spaces personally.

So yeah,

I kind of went on a couple of

posts about that,

but hopefully I wasn't too rude.

Yeah, I absolutely agree.

I think that kind of sums up the

forum thread.

I'll take a kooky side look at some

comments in the chat again.

Yo, yo, yo, Fred Kong,

welcome to the stream.

Eteru said,

thanks for addressing the comments and

having the debate.

Yeah, absolutely.

We can't spend hours and hours talking

about mulfad, right?

But a lot of these discussions we also

have on the forum pretty often,

and I would say if people have follow-up

questions or want to continue posting

about it, go into the forum,

discuss.privacyguides.net.

It's a great way to discuss all of

this stuff if we can't discuss it all

live here on the show.

But of course,

we're happy to answer any questions that

we get here.

So yeah, keep sending them in, everybody.

Yeah.

Yeah.

I know Anand said there are good apps

out there.

I mean, yeah, I'm sure there are.

And some of them are hard to find,

but they're, they're getting better.

But like one of the examples I use

that I really like is like NT,

you know, NT has that really cute.

It has like the duck logo and it's

like really user-friendly and it looks

good.

And it's got all the features that the

normal people want,

but they're all opt in.

Like you can enable machine learning

that's done on device.

So you can search photos and it's,

you know, if you don't want it,

you just don't turn it on and you

can have the memories that, you know,

on this day, five years ago,

and you can have the,

the like all kinds of cool stuff.

Like I think NT is a really good

example of what I'm looking for,

but I don't know.

I'm sure there are some good apps.

I'm just saying instead of making a

Messenger,

make literally anything else because we

need more other stuff.

Yeah, I think if that's all we got,

we can move on to this next story.

Yeah,

do you mind if we do site updates

now and then go to that story?

I mean, we're in Avarin.

Let's get some stuff to talk about.

Before we talk about yet another border

story we have, let's...

go over some quick updates that of what

we've been working on at privacy guys this

week we finally were able to publish uh

a new site update so we have the

changelog there a lot of things um have

been updated a lot of these have been

published on the site for a while but

they weren't like released to the web

server so they weren't live and now now

they are so everything should be up to

date um we're also working on some stuff

so I'm working on

New recommendations for security keys,

kind of changing that up,

and also recommending cryptocurrency

hardware wallets.

I have literally so many of them on

my desk now, just...

messing with them.

And we're discussing those on the forum.

So there's a lot of forum threads about

that.

If you have opinions about cryptocurrency,

hardware wallets, or security keys,

you can go to GitHub.

There's a pull request open that's a draft

right now.

I think it's just titled hardware keys,

security keys.

And

In that pull request,

there's links to all of the forum threads

because there's like five different forum

threads about different things that are

being added.

So yeah, if you have opinions,

definitely let us know, obviously.

But that is something that will be coming

soon.

In other news,

Fria continues to publish news articles,

privacyguides.org slash news.

Nate has also, of course,

published the weekly data breach roundup.

So there's all sorts of...

stuff out there for you to stay up

to date with.

We try to post some of the biggest

stories that we see,

especially ones that we can't talk about

here on the show,

on that page throughout the week.

So that is a good place to stay

informed in addition to the news category

on our forum.

A couple other things we're discussing.

I think the only other thing we're

considering right now is

a new nested reply format for the form.

There's a sticky post on the form right

now called defaulting new post to use

nested replies.

It's kind of a Reddit like format for

posts.

Right now,

we're definitely not going to be switching

to it.

I'll just tell you because it is kind

of

buggy in some ways.

And there's some improvements that I want

to make that I've shared with the

discourse team to see if they decide to

implement any of them.

However, I mean, assuming it does work,

I think that there's probably some reasons

we might want to use it at least

for some threads in the future.

So if you want to check it out,

see what it will probably look like and

how it works.

And see,

let us know about any feedback you have

definitely check out that thread because

In some ways, I like it a lot,

but I'm a big Reddit user,

and there's a lot of ways that the

current form system is also very nice as

well.

So a lot to think about there.

I think that's kind of it in terms

of site updates and things I'm involved

with.

Nate,

why don't you talk about some of the

video stuff that you and Jordan have been

doing?

yeah unfortunately um jordan got sick this

week uh so they are recovering and uh

they were hoping to have the next video

done by now but uh you know things

happen health is more important obviously

so um once they recover they'll be

wrapping that one up and uh yeah i

mean i've already got one video filmed

after that and just reached out to

somebody today about an interview

which I am excited about.

I, uh, I don't think we,

I don't think anybody has had an interview

quite like this one.

Um, maybe Carrie in the, the like,

like ten years he's been doing firewalls,

no stop dragons.

But, um, I,

I think it's going to be a good

one and I'm excited to share that with

you guys.

But, uh,

that's kind of all we've got going on

right now.

So, um,

Yeah,

all this is made possible by our

supporters.

So if you want to help support our

work,

you can sign up for a membership or

donate at privacyguides.org slash donate.

We also still do have the merch shop

that Jonah mentioned earlier,

shop.privacyguides.org.

Privacy Guides is a nonprofit which

researches and shares privacy-related

information and facilitates a community on

our forum and matrix where people can ask

questions and get advice about staying

private online and preserving their

digital identity.

rights.

Before we jump into that, actually,

we did get a couple of questions.

I don't want to say off topic.

We got a question in the forum that

is not related to any of the stories

we've covered so far.

Khaled says,

what are some good ways to spread

disinformation about yourself?

I've heard this talked about in the past

to protect against data brokers and other

places,

but don't know what's the best way.

Do you have any thoughts on that one?

I use a little bit of disinformation.

I don't know if you do.

This is a good question.

Good ways to spread it is hard because

I mean like whenever possible it's good to

use fake information when you can or to

use like email aliases and stuff like that

so things can't be tied together and so

like if data does get released and like

data breaches or whatever it won't be

accurate information but like

intentionally sharing

False information.

I have definitely heard people talking

about this.

I don't really do this myself,

so maybe you can talk a bit more

about it.

But I've always leaned towards more just

kind of trying to eliminate as much as

possible from being out there,

whether that's through data broker removal

services or just putting out minimal

information out there in the first place

or what have you.

So I guess the answer is I don't

really know the best way to go about

this,

but it is an interesting thing to think

about.

Yeah,

I don't know if I know the best

way because I'm kind of with you.

I focus more on removing the data that's

out there.

But I will say that one of the

things I do is I am really militant

about using a PO box.

And that has worked so well that I

know for a fact that in the past,

LexisNexis has thought that was my actual

address,

which is funny because I'm not even going

that hard to like, oh,

I don't put my real name on my

lease or whatever and somehow still fooled

the data brokers.

Yeah.

Drake in here said best way is to

lie about your birthday city where you

live, et cetera.

Yeah.

I mean, little things like that.

Like if I, if I buy anything,

that's not going to a PO box,

I try to use like a,

like a hotel downtown or library or

something is my mailing address.

Um,

LinkedIn, I know I've said this before.

I, when I got into privacy,

there was a specific address that kept

showing up on all these people's search

sites that was like,

ten years out of date.

And I could not figure out where it

was coming from until I realized I had

a LinkedIn account I had never deleted and

never really used.

And that's where it was coming from.

So, uh, yeah,

sign up for LinkedIn and put the wrong

information on there and it'll get out in

about ten minutes.

Um, I'm trying to think what else.

Uh,

I've heard that rewards cards,

like signing up for – it kind of

depends on what you want to do.

Like some people – this mostly comes from

Michael Basil,

but he's recommended like get magazines

shipped to your house in the wrong name.

Some post office people are kind of

militant about not delivering magazines.

mail that's not like if they know that

name doesn't go to that address they won't

deliver it because they think it's wrong

um so some people have had that experience

you could sign up for uh again like

rewards cards at the grocery store using

the wrong name but your actual phone

number like things like that um

I don't know.

Yeah.

I think it's kind of a subtle mix

of things of just kind of figuring out

where, you know,

does this person need this information?

And if they don't,

what information can I give them instead?

Especially if it's required,

like a lot of the time, you know,

if you go to buy something online,

sometimes it won't say, you know,

it won't like the phone number will be

optional,

but then other times it will require a

phone number.

And at that point it's like, okay,

you're never going to call me.

So what fake phone number can I put

there?

You know, things like that,

I think are kind of how I think

about it.

Yeah, I don't know.

I think that's kind of all I got

on that one.

It's more of an art than a science,

I think,

and just kind of looking for those

opportunities.

Sweet.

Well, let's move on.

Why don't you cover this next story also

from EFF here?

Yeah.

So this one is, um,

a little bit disappointing, unfortunately.

And, uh,

it says that the fourth circuit says

border agents can search your phone by

hand.

No suspicion required.

So, um,

for those who don't know here in the

U S um,

borders or searches of your phone are

really kind of a legal gray area that

are, uh, kind of, it's kind of patchwork,

I guess I would say it's very, um,

Like at this place, this rule applies,

but at this place, this rule applies.

And here you need a warrant,

but here you don't, blah, blah, blah.

And it's very confusing.

And so basically there was a case called

U.S.

versus Belmont Cardozo,

who unfortunately does not seem like he

was a cool guy.

Seems like he had CSAM on his phone,

according to some stuff later down here.

But either way,

they tried to argue as a defense that

The police should have gotten a warrant to

look through his phone,

and this made it up to the circuit

court, which I forget how circuits work.

I think a circuit –

includes several states like it's kind of

like a regional court i think if i

remember correctly um okay but yeah so the

the uh this went up to the fourth

circuit who decided that border agents are

allowed to search your phone without a

warrant or really any reason as long as

it's a quick manual search so again

there's there's um

I don't want to get too bogged down

in the weeds of context here,

but basically there's different reasons

that people can perform searches.

Cops, I should say, can perform searches.

There is going and getting a warrant.

But obviously, if we assume good faith,

there are still times where it makes sense

that they can't get a warrant.

If they're at the airport and somebody's

acting real shady and their suitcase is

oversized or whatever,

they've got some reason.

Something suspicious is going on here.

Then, you know,

if they can prove if this ends up

going to court or whatever and they can

prove to the judge like, no,

here's why I flagged this guy and here's

why I thought this was suspicious,

then that evidence is allowed in court.

And there are certain things,

according to the EFF, that at the border,

you don't even need a reason.

You don't even need to say like this

is suspicious.

It's just you can do the search.

And as an example,

they gave like your luggage,

even if there's nothing suspicious,

even if there's there's no evidence of

wrongdoing, the cops can be like,

I'm going to search your luggage.

which they do even on domestic flights.

I can tell you that from experience.

And so basically the court has said cops

are allowed to do a search for any

reason, without a warrant,

without any suspicion,

without any probable cause,

as long as it's a quick manual search.

And where did it go here?

So they said that it has to be

a person, not a machine.

They said that the breadth of the search

depends on the officer's time and energy.

They, uh,

while forensic searches are comprehensive,

uh,

manual searches only reveal what a user

can typically access while forensic

searches can uncover deleted files,

cash fragments, metadata, and more.

And manual searches are subject to an

officer's fading memory or imperfect notes

while forensic searches create a permanent

copy.

So basically this is not permission for

them to hook your phone up and run

celebrate and copy your data.

It's, you know,

the cop saying at the border, like,

let me see your phone,

unlock your phone and looking through your

phone.

Okay.

And EFF argues,

and I think most of us watching would

agree,

that that's still not really great because

your phone is so much more sensitive than

like even your luggage.

Like, okay, sure,

your luggage might have some stuff you

don't necessarily want everybody seeing,

but your phone has your messages,

your photos, your banking apps, you know,

Grindr, like religious apps,

like whatever it is.

Like your phone has so much more data

than your luggage would.

And it's so much easier,

at least in my opinion,

it is so much easier when you're packing

your luggage to... I mean,

even as a real example,

when you're packing your luggage,

you can choose to leave out things that

you don't want to put in there,

but you might still have medication

reminders on your phone or a doctor's app

or something like that.

And it's just... Yeah.

The EFF was basically like,

this is really not the same.

And it's kind of disappointing that

there's no real actual...

Anything.

Again, they don't even need suspicion.

They can just go ahead and say,

here's all the –

Yeah.

I don't know.

I'm tripping over my words,

but I think I've kind of made my

point there.

It's really disappointing, unfortunately.

I will say at the end here,

they did point out that in this particular

case, the search only lasted two minutes,

which means that there's a possibility

that even if it is a manual search,

if it goes on longer,

it could require more time.

a more in-depth search.

So like if this guy took the phone

and just opened photos real quick and saw

CSAM, then it's like, okay,

you're under arrest.

But if he's like sitting there with your

phone for ten minutes,

like reading every single message and

checking your browser history, it's like,

come on, man.

You got to be a little more reasonable.

So I think that's probably the good thing.

But I don't know.

I don't understand how a time limit would

work, but I don't know.

I'd have to look more into that.

I wanted to go back to the reason

that you said Belmont Cardozo was

arrested,

because I think it's an important point to

remember that I think people need to

realize when we talk about cases like

this.

Obviously,

he was arrested in this case for having

CSAM,

which led to his arrest in criminal

prosecution.

And I think...

When we see court cases like this,

what you have to remember is that the

things that are happening in this court

case are almost certainly things that the

government does all the time.

Like,

this isn't the first time that they've

done it and now they're trying it in

court.

This happens and...

If it gets challenged in court,

which a lot of people probably won't even

do in the first place,

but if it does, you know,

if it's not as controversial as this,

where he has CSAM on his phone,

the US government is just going to drop

it because they want these court cases to

create precedent for them to do this sort

of thing in the future.

And so they have to find the most

extreme possible case that they can find

because they want to use, you know,

illegitimate reasons, I think,

to kind of justify this instead of looking

at the letter of the law as it

is right now and realizing that this sort

of search is illegal under the

Constitution,

but they want people to overlook that

because of the nature of the crime in

this case.

I just think that's important for people

to remember because a lot of people do

get outraged about this and they'll see

stories like this and they will say like,

well, yeah,

we want to catch people like that.

But how many, you know,

criminals is the government letting go

before we can get to a court case

like this?

And also,

how many times has the government done

this before it reached any court at all

and before it was challenged?

Probably quite a bit.

They're just invading people's privacy

illegally and often it doesn't

get policed at all so yeah I think

I just wanted to remind people that keep

it in mind when you read stories like

this because I think people get too caught

up in what the crime was instead of

what the government is doing and remember

that we kind of have a duty to

police the police officers and make sure

that this sort of thing isn't happening

and isn't legal yeah because that's my my

main point

I don't know if there's anything else I

wanted to add.

You kind of covered a lot.

Sorry.

I mean,

it's kind of a straightforward story,

but it's I also wanted to include it

because like I said,

this

you know the the rules surrounding phone

searches it feels like they're changing by

the day and it's highly contextual and

dependent on things and so it's the more

information we can get about how to to

or like what's going on what the current

landscape is is helpful and also like both

this story and the previous story about

the border we just did it's another thing

sort of similar to what i was saying

about the government where like the

government is doing these things on the

border specifically

because they know that people get really

mad about border-related issues and will

support things that they otherwise

wouldn't support in any other context.

So that's why I think that's why we

see a lot of very extreme stories like

ones dealing with CSIM and that's why I

think we talk about a lot of border

stories like a disproportionate amount on

this show because that is it kind of

seems like in my opinion where the

government wants to test out a lot of

these privacy invasive things first before

we see them

get that out on the streets everywhere in

America.

I think that, I mean,

really like the stuff we were talking

about on the border in terms of

surveillance towers,

that's the sort of thing that they wanted

to test on the border.

And now we see flock cameras on every

street corner in America.

It's just, it's kind of a pared down

cheaper version of all of that

surveillance stuff but it's more

ubiquitous and it's not about protecting

the border it's about surveilling american

citizens um and everywhere they go and

what they're doing so yeah you just gotta

keep all of that in mind it's all

like this has more impact than just like

the specific thing that we're looking at

right now you um you may have heard

of this but it does not get as

much attention as his other phrase and

shitification but uh have you heard of

corey doctor's shitty tech adoption curve

No, I have not heard that.

It's basically what you're arguing.

Do you remember that that winter soldier

drone that Baltimore tried to roll out

like sometime shortly after lockdown,

I think?

Yeah, I believe so.

Yeah.

For those who maybe missed that story,

basically Baltimore,

the city of Baltimore,

I think it was Baltimore,

wanted to fly a surveillance drone like

twenty four seven in the sky that would

just record all the time.

And, you know,

civil rights groups fought back and they

were like, this is surveillance.

This is illegal.

This is a violation of the Fourth

Amendment.

And real quick, I thought it was funny.

They tried to argue.

It's like, well,

it's not really twenty four seven

surveillance because we still have to land

it for a couple hours a night to

refill.

it and stuff so technically it doesn't get

and thankfully the government was like no

this is illegal you can't do this so

they weren't allowed to do it but um

somebody pointed out that that technology

began in afghanistan like it was literally

a modified version of the predator drones

the same surveillance drone we fly around

in war zones and uh cory doctorow coined

this term called the shitty tech adoption

curve which is exactly what you're saying

is like they roll it out in these

situations where unfortunately people

aren't really paying attention in like

wars and prisons and places like that

where it's it's easier for people to

ignore it.

And then they kind of use that as

a testing ground to hone the technology

before rolling it out to surveil the rest

of us.

And unfortunately, ever since I read that,

I see it everywhere.

Corey was very, very right about that.

But yeah,

that's that's basically what you were

describing.

So I know I can never have an

original thought.

Corey's had all of this.

Corey has all of the thoughts.

He is so smart.

I mean, yeah.

None of us can compete with him.

I think before we dive into the next

story,

I think we had another forum post we

wanted to look at,

and I think this one actually came from

you.

about the FCC comment yeah trying to pull

it up again yeah I did just want

to highlight this uh really quick the we

we I think we did you talk about

it on the show I don't think I

was on but I'm sure in one episode

it came up um I think we gave

it a brief mention because this does ring

a bell

The FCC is proposing a plan to require

government ID, your physical address,

and an alternative phone number for every

phone line in the US.

So yeah,

if you sign up for a new phone

line,

you're not going to be able to get

it as anonymously as you currently can.

We've talked about a number of ways to

get phone lines anonymously here on the

channel, and I'm not really sure how...

any of those methods would really survive

a rule change like this.

The deadline to comment on these proposals

is July twenty-fifth,

and so if you are an American,

I think it is really important to submit

a comment to the FCC about this because

they will take this into account in these

hearings,

especially genuine

Personal accounts are going to be very

compelling in terms of pushing back

against this.

Don't just submit an AI-generated comment.

But you can go to this form post

that I've stickied it on the form,

so you should be able to find it

because I have a link to where you

can file an express comment.

And the two docket numbers that you're

going to enter in the top field of

that,

you're going to enter

And just submit a comment for both of

those.

You can do both of them on the

same form, so it's very easy to do.

And I think it's very important that this

sort of thing doesn't get passed,

so hopefully you can speak out about it.

There are some comments in this

forum thread that we could address here.

Expert-FortyEightSeventy asked if KYC

would help with spam.

And the answer is no.

None of this is going to help with

spam in any way.

Because this isn't the reason that spam

calls exist.

Spam calls currently mainly exist due to

technical failings of these telecom

providers and there are systems in place

or they could make systems that would

prevent

Pretty much all of this stuff from

happening,

they just choose not to do it for

a variety of reasons.

But there are different authentication

protocols,

and there are technical ways that they

could just prevent cell phone number

spoofing, which would be a huge...

improvement um that that they're not doing

and it's not clear to me uh how

kyc is going to help this because all

of those exploits and flaws in the current

telecom system will still exist for

spammers to take advantage of however this

is going to make it much much harder

for regular people to get phone lines

which are pretty much mandatory given how

many services require a phone number

nowadays so yeah this is this is

definitely not the solution um

All of the expert opinions that I've seen

on this and all of the people in

the telecom space that I've talked to have

no idea how this is going to improve

the spam situation either,

because it's not.

But yeah.

And also, as Kerry just pointed out,

it doesn't prevent offshore phone

accounts.

Yeah.

Like, this really...

I can't even imagine how they are

justifying that this could solve the

problem that they're trying to address

because there are so many ways for all

of that stuff to continue while this

policy is in place to really take away

privacy from Americans.

So just wanted to put that out there.

Check out the forum thread.

I'll leave it in the...

I can leave it in the chat here

if people want to check it out.

But... It's also in the newsletter.

Oh, it'll be in the newsletter.

It's on the site.

You can go to the forum,

discuss.privacyguys.net.

It'll be at the top.

So I think that'll be... Yeah.

Consider it because...

Public opposition and especially like

grassroots opposition does actually have

an impact on these political decisions.

We've talked about that before,

like in the EU with chat control and

like pushing back against that.

And it's the same here where we got

to nip this in the bud before it

happens, because if it happens,

it's going to be so hard to undo

it.

Yeah, I haven't clicked on this link,

but I said the same thing in the

forum that, you know,

that Kerry kind of hinted at, which is,

you know,

a lot of spam callers come from outside

the US.

They spoof US phone numbers.

And somebody replied to me and said that

they quoted this link here.

The commission further proposes to require

voice service providers to implement

measures to ensure that consumers know

which calls originate from outside the US

and to prohibit spoofing of US telephone

numbers for calls that originate from

outside the US.

Again, I didn't click the full link,

but I'm assuming it doesn't say how

they're supposed to do that.

And to me,

this strikes me as one of those things

that it's like,

do you think they don't want to do

that?

Like,

do you think they're not already trying?

Like everyone hates spam.

There's – they already don't want these

spam calls.

Like, I don't know.

It sounds to me like one of those

things where it's just the politicians

that don't understand how to check their

email on their iPhone are telling us just

nerd harder and find a solution.

And it's like this just – yeah,

I don't see how this is supposed to

actually solve anything other than just

creating a bunch of, like,

legal liability that's just going to make

everything worse.

And –

I think the first time we covered this,

we mentioned this is going to kill

whistleblowers, journalists,

which I'm sure the current political

landscape would be thrilled about all

that, domestic abuse survivors.

All these kind of people that have

perfectly legitimate cases for needing a

burner phone are just up a creek now,

and we're not actually going to fix

everything.

We're just going to make everything worse

for everybody.

So yeah,

I need to leave a comment on this

too.

Before we move on to the next story,

I want to grab another question in the

chat here.

VPN question.

If I change my VPN server regularly a

few times a day or more often,

does it strengthen my privacy or not

significantly?

Thanks.

This is really going to depend on who

you want privacy from,

but in general I wouldn't recommend doing

this.

It could possibly make sense to do this

if you're visiting different websites and

you're using one VPN on one website and

a different VPN with a different one,

but if you're just rotating VPNs

constantly and using the same sites,

this is probably going to have little

impact and this

will make you less private on your local

network, for example,

because it's just more fingerprintable.

But when you're doing things that are kind

of out of the norm,

especially manual things and things that

aren't built-in features,

you're pretty much just standing out from

other users who are not doing that.

And so typically it is best for privacy

As a general rule,

to not take things into your own hands

and implement additional security measures

if it hasn't been fully proven that this

is going to improve your privacy in some

way.

I think that's just a good philosophy in

general, which is the less you can do,

the better.

And this sounds like a lot of extra

work for no proven gains.

So yeah, I wouldn't...

I wouldn't do this probably,

but I think that answers that.

Yeah, I just want to add on that,

in general,

I think VPNs are really over-exaggerated

for privacy.

I think somebody commented this during the

Mulvad story too.

And they have a place.

I use a VPN.

I'm sure Jonah does.

Most people do use VPNs because they're

helpful.

But VPNs really only do two things.

They change your IP address.

and aside from okay three things because

they also do the whole encrypted

connection thing if you use i mean most

modern vpns nowadays come with dns based

blockers that block ads and trackers and

malware but um you know the dns based

things they're only going to block known

things right and they're only going to

block dns base so like if you're if

your ads and trackers are being served

from the same place as the website itself

they can't block that without breaking the

website

if it's a, you know,

a new web address, a new domain,

they can't block that cause they don't

know about it yet.

And, um,

As far as the IP address thing,

I'm firmly convinced we don't actually

know how common fingerprinting is because

companies don't really rush to tell the

world.

And those who do are marketing companies,

so they're probably over-exaggerating it

anyways.

But I'm willing to bet that fingerprinting

is extremely common nowadays.

And in the context of fingerprinting,

your IP address is such a small part

of your fingerprint because a lot of

residential places rotate IP addresses

anyways.

And if you're going from your phone to

your computer to the library to the coffee

shop to work,

IP address is just not a very efficient

way to track people.

So VPNs, I'm not anti-VPN,

but I don't think in the context of

privacy, like I'm with Jonah,

I think rotating regularly would just be

so much overkill for so little gain.

And I think you'd be better off just

focusing on

using a good privacy-respecting browser,

using things like uBlock Origin that are

not blocking purely based off block lists,

things like that,

I think are going to get you way,

way more privacy than rotating VPNs.

All righty.

On that note,

I think we're going to move on to

our next story about OpenAI.

This is kind of a big story this

week,

the whole OpenAI and Hugging Face debacle.

Yeah, this is reported by Wired.

OpenAI models escaped containment and

hacked Hugging Face.

Describing the incident as unprecedented,

OpenAI said its AI models broke out of

a sealed testing environment last week and

hacked into Hugging Face's production

system to steal the answers to a test

they were being graded on.

The models,

the publicly available GPT-Five.

Six sole and an unreleased reported me

reportedly more capable one,

were being evaluated on their offensive

hacking skills with the safeguards that

normally block high risk cyber activity

switched off.

They go on to say,

according to OpenAI and Hugging Face,

the models escaped through a package

registry cache proxy software that allows

developers to install outside code without

connecting to the internet.

The proxy was the only component in

OpenAI's isolated testing environment

permitted to reach the outside world.

In normal use,

that reach extends only to public code

repositories.

Rather than stay contained in the sandbox,

the models exploited a zero-day

vulnerability to gain access to the open

internet as they hyper-focused on finding

a solution for the AI cybersecurity

benchmark known as Exploit Gym.

Such experiments involve prompting that

pressures the models to find solutions,

essentially egging them on.

They say that the flaw that the models

exploited was previously unknown,

as would be implied because it's a

zero-day exploit,

but flaws in this kind of software are

not unusual.

Companies have been patching serious

vulnerabilities in artifact repositories

for a decade.

A bug disclosed in twenty twenty four let

anyone who could reach the server ask for

a file by URL and get it,

which would include configuration files,

passwords,

access tokens without logging in.

Others have let attackers take control of

the server itself.

So a lot to unpack there.

I kind of take a little issue with

a lot of these stories about AI and

security and like their capabilities,

because honestly,

like when Anthropix Claude Fable was

banned by the US government,

we talked about that a few weeks ago

when it happened.

And I kind of had a similar opinion

then, which is that like,

all these stories do is really boost the

impression that like these models are

extremely capable and they're totally

worth paying a lot of money for because

look what look what they can do right

um but at the same time uh it

is it is true that they're finding like

zero-day vulnerabilities and they're

discovering

new vulnerabilities that didn't previously

exist,

and there obviously are cybersecurity

implications there.

Yeah, Nate,

I could talk a bit more about this,

but do you have any thoughts,

or was there anything you saw in the

article that I didn't talk about?

Not too many.

I think your take is definitely accurate

that this is kind of a little bit

marketing for these companies.

Like, oh,

look how super powerful our AI model is.

But it does also kind of point out

that...

I think it's one of those,

it's kind of like when Kerry guessed it

on the podcast and he said, like,

you know, this stuff is coming.

Like, regardless of how you feel about AI,

I think there are some impacts here that

are happening regardless of whether you

use it or not.

Because, you know,

I think when we think about agentic AI,

at least me,

I usually think of stories about like, oh,

some morons AI agent went and erased their

entire inbox.

And it's just like, yeah,

what idiot is using these things to begin

with?

But now we're seeing it's like it can

go beyond that, you know,

and it's unfortunate that it's one of

those things where I think it's privacy

people.

We all kind of relate to, you know,

people will be like, well,

if you don't like Google,

just don't use it.

It's like Google Analytics is on seventy

percent of websites.

How am I supposed to just not use

that?

Like, come on, man.

And it's kind of the same thing where

like now they're starting to use these

agents for like pen testing and hacking.

And it's like,

how am I just supposed to not use

it when this is impacting me?

And

Another thing that occurred to me was we

covered a story a couple episodes ago.

I think I forgot to go –

find that episode.

But, um, we,

we covered a story a while back about

how, uh, with the mythos thing,

I think it may have been,

may have been the episode Carrie was on

where, uh, you know,

there were unauthorized users that were

somehow gaining access to mythos.

And I don't think they ever resolved how

that was happening,

whether it was like some kind of insider

giving them access or something,

but it kind of points out that it's

really delusional with all these tech

companies.

You know, it's like, Oh,

only the good guys are going to have

this.

We're only going to sell it to good

guys,

which is definitely what clear view AI

said right before selling it to

authoritarian regimes.

But it's also like,

even if they are acting in good faith,

you

Clearly,

these people are finding access somehow.

I think the last thing I wrote down

here is towards the end of the article,

They talked about how this is really an

infrastructure problem.

Let me see if I can go find

it.

In recent months,

top AI companies have been raising

concerns about the expanding cybersecurity

capabilities of upcoming frontier models

as the platforms increase in both

expertise, creativity,

and agentic autonomous operation.

But researchers emphasize that this is all

the more reason the fundamentals should

still apply.

Where was it?

It was like the last quote that he

made.

I wish,

this is a veteran security engineer and

researcher, Niels Provost.

He says,

I wish the Frontier Lab spent as much

time on teaching the models to write

secure infrastructure as they're spending

on exploiting vulnerabilities.

And it's just kind of showing that whole

like move fast and break things mentality

is still here.

You know,

they're still out there just trying to

make money,

trying to like push out this newest,

shiniest model.

Like you were saying, it's, you know,

like how scary our model is.

And, you know, yeah,

it's just it's unfortunate that we do not

ever seem to learn our lesson.

And we just keep repeating these mistakes.

Well,

and that quote is especially relevant here

because

When I'm reading this, I'm wondering,

how was this vulnerability found?

What was the vulnerability?

And was there a more standard

configuration for this proxy server that

would have prevented them from doing this?

Maybe if they had configured it

differently when they installed it?

Because I would have to imagine OpenAI

probably is just asking AI

to set up this secure environment and to

set up this proxy server.

Like, I'm sure they use AI super heavily.

And so the idea that like, oh,

these models should be taught more about

like doing things securely in the first

place rather than spending so much time

like exploiting vulnerabilities,

which again,

I think is mainly a marketing thing.

It's much more, I guess,

clickbaity to say like OpenAI hacked this

thing versus OpenAI

made security improvements to this open

source software or something like that.

So unfortunately,

I think like a lot of it is

very

attention-driven.

This sort of story creates a lot of

attention for OpenAI.

Obviously, we're talking about it now,

so it's working.

And that attention is the main thing that

these companies need right now,

just to survive.

They're obviously not making money,

so they have to exist on hype and

vibes alone until, in theory,

they can make money.

I don't know if they ever will,

but that's their hope.

So yeah, I mean,

I don't know if I have much more

to say beyond that.

The AI stuff is just nuts to me.

Yeah,

I don't really know if I have any

more to add either.

I agree with you.

It does make me wonder what you were

saying about like,

did they have the AI configure this?

It's yeah.

I mean, if,

if you have the AI spit out code,

you're just going to skim it.

You're not going to sit there and audit

every single line of code.

You're just going to like, yeah,

it looks good.

Let's run it.

And as opposed to like,

if a human wrote the code, I mean,

maybe the human would just by instinct,

write it in a much more secure way,

but since it looks mostly right,

they don't catch it when the AI does

it.

And I don't know.

Yeah,

I just can't imagine like anyone at OpenAI

is really just doing things on their own

anymore.

Like that would be unbelievable to me.

I don't know, man.

They're probably not even like, yeah,

hopefully they're not.

But I would imagine they have not taken

that advice to heart.

Yeah, who knows?

We had one more forum update that we

were going to cover before jumping into

our final story about Apple.

this one was pretty close to my heart.

Is there a point in supporting projects?

I don't know whose turn it is.

Is this my turn?

You can take it.

Do you want to take this one?

Okay.

So yeah,

this person here says that this is

something that's been on their mind for a

little bit.

And basically,

is there a point in supporting small

projects?

And they talked about Session,

for example.

And they say that, you know,

they want to support projects and they're

happy that they exist,

but at the same time,

does it actually matter?

You know,

if you give five dollars a month,

does that help?

And, you know,

they might still go bankrupt or disappear.

How do I know they won't go into

financial trouble?

So on and so forth.

So.

Here's here's my take based on my

experiences

With the new oil,

with surveillance reports,

and a little bit here at Privacy Guides.

Privacy Guides is a little bit different

than what I was doing at those

organizations.

So the first thing that I want to

reiterate that we always say is your

safety comes first.

We don't want you to donate if you're

going to lose your house,

if you're not going to have money for

food or for the baby formula or whatever.

Definitely take care of yourself first.

But if you have...

disposable income,

I think I actually wrote a big,

long response here.

And I mentioned that at New Oil and

Surveillance Report,

depending on when you measure and how,

only one to five percent of people donated

money.

And I've said many,

many times in the past that if half

of the people who visited the new oil

donated a dollar,

I could have been doing privacy full time

years ago.

And so I think a lot of the

time, like, yeah,

if you look at it as an individual,

like donating five dollars, ten dollars,

even one dollar as an individual, yeah,

is really not going to do anything.

But it becomes – it's almost like a

– this is a problem we have with

voting, right,

where a lot of people are like, oh,

my vote doesn't count, and therefore,

forty percent of America doesn't vote.

And it's like those millions of votes

could have potentially changed the outcome

of the election, either – any election,

either way.

And so it's kind of the same issue

in privacy,

where it's like if everybody goes, yeah,

well, my five dollars,

all I have is a dollar.

That doesn't help.

Yes,

but if a thousand people give a dollar

a month –

That's a thousand dollars.

Like it, it adds up.

And so, um, I would encourage people and,

you know, obviously I have incentive,

but I would encourage people that, yeah,

if you do have money donate and,

and there are so many projects out there

for the record,

I know it's kind of impossible to donate

to all of them.

So.

I would recommend starting with the ones

that, like, if this went away tomorrow,

could you live without it?

Like, I use Signal religiously.

I use, well, now I use Fresh Tomato,

but I used to use DDWRT and, like,

NextCloud.

And, like,

these are all things that if they went

away tomorrow, like, yeah,

I'd be kind of screwed.

Yeah.

Things like – or another thing that's

really common is rotating.

This month I'm going to give five dollars

to Signal.

Next month I'm going to give five dollars

to Fresh Tomato.

Next month I'm going to give five dollars

to Cubes, like that kind of thing.

So I don't know.

I just – yeah,

this is really near and dear to my

heart.

It definitely – if you do have a

disposable income,

I strongly encourage people to donate

because it does help.

It adds up.

Even a dollar.

Like I said,

if a thousand people give a dollar,

that's a thousand dollars a month.

I don't know if I can add much

more to that without repeating myself.

Yeah.

It's hard to say.

I think people are bummed when they

support projects that eventually do go

under or can't continue running.

You need a lot of money to do

all of these things,

and some projects tend to get all of

it, and then most of them don't.

But I think the first reply on this

forum thread...

is a pretty good point,

which is they basically said there's a

fairly strong chance that if no one

donates,

then there's going to be fewer projects

available overall.

I guess you're sort of betting on which

ones are going to succeed,

and sometimes you're going to lose those

bets.

But if you can support all of these

projects, the more you do,

the more likely it is that one of

them will

make a big difference.

And I think if nobody is supporting the

small, tiny projects,

then there will never be any new ones,

because it'll just be too hard to get

it off the ground.

I can definitely tell you all for sure

that probably not as many people donate to

PrivacyGuides as you would think,

so we can always use donations as well,

but there's a ton of projects to support.

can't remember if we do this currently i

should look i feel like yeah for for

a lot of our um recommendations on our

site if they have like a donation option

we we have a button to hit where

you that'll link like directly to their

contribution page so you can find like

where to support all the projects that you

use if you search for the tool on

our site so that could be something to

to look into but i definitely would

recommend supporting anything that you use

and just think of it like you know

if you're using it now and you like

it um and you can afford it you

should you should pay for it i think

yeah if it goes away it's a it's

a and if it disappears it's a shame

but then you can just move on to

supporting something else um and hopefully

uh it doesn't go away

I think it's also one thing I wrote

in my comment here is, um, again, it,

this should be disposable income.

Like this should be money that is not

going to, you know,

keep your kid out of college or something.

But, and the example I use is like,

I am, I'm a sugar addict.

I actually,

I finished a Mountain Dew right before we

started recording.

Um, you know, I, I love sugar.

I'm constantly buying like fraps and sodas

and, and, um, all kinds of sugary stuff.

And, um,

Those things cost, you know, two dollars,

five dollars,

depending on what I get and where I'm

at.

And they last me, what,

a couple hours tops.

And then even the high of the sugar

rush eventually goes or not sugar rush.

But, you know,

the dopamine hit of the sugar eventually

goes away, too.

And so it's one of those things where

it's like, yeah,

I'm spending five dollars and it's going

to last me half a day tops.

the reward of that,

whatever word I'm looking for.

And whereas something like this,

it's kind of one of those things where

it's like,

if I knew for sure that skipping one

coffee a month would keep Signal around,

would I do it?

Yeah, absolutely.

And so to me,

it's kind of that same argument.

It's like trying to reframe that attitude

of like,

I can afford to go without one soda

to help this project stay around, I think.

Yeah.

You know, uh,

Carrie said it to the diffusion of

responsibility.

A lot of people assume that other people

are supporting, uh, like you said, it's,

you know, I, I was surprised real quick.

One, one more quick story.

I went to the cubes.

Uh,

what is it like open collective one time

and their annual budget is like,

and I'm like, hold on, what cubes?

There's like seven developers and

literally not a single one of them could

afford to do this full time.

And they put it out an amazing operating

system.

Like they're probably making a lot less

than you think.

So

Yeah,

I was going to point out that exact

same comment from Carrie.

Because that is the case when I talk

to people about privacy guides as well.

Mainly people who are thinking about

donating and they're asking about how

everything works currently.

And I think there's generally surprise

about how much we're getting because they

assume that we would be getting a lot

more, which I think...

is absolutely just a thing.

I didn't know that it had a name,

Diffusion of Responsibility Phenomenon.

So now I know this, thanks to Carrie.

But I think that's absolutely a thing with

a lot of these projects.

It's very easy to assume that somebody

else is supporting them,

so you don't have to.

It's exactly the same as like,

This is classic,

nine-one-one first responder advice,

like you have to be like,

don't just say like,

somebody call nine-one-one,

you have to say like, you,

pink shirt right there,

call nine-one-one right now if you're in

an emergency situation,

because otherwise nobody will do it,

because everyone,

nobody wants to do things.

So I'm telling all of you right now,

you watching this, donate to something.

You with the face.

Yeah.

One more example.

If you go to NT.com slash open,

they share how many customers they have

and how much revenue they only make like

a million dollars a year,

which for a company providing that kind of

infrastructure, it just,

that blew my mind when I read that.

I'm like, that's it.

Like I've historically always worked for

companies that made way more than that.

And they were still small companies.

Like I can't believe NT is running on

such a small budget, but.

I mean,

now you don't work for a company making

more than that.

Yes, that's why I said historically.

This might be the first company I've ever

worked for that makes less than a million

dollars a year.

But just to point out the example, yeah,

like what we were saying is like people

think that they make a lot more money

than they do.

And when I saw that from Ante,

I was like, really?

That's it?

Like, yeah, it's wild.

They're doing a lot for how little they're

making, but...

Anyways, that's all I had on that one.

Terracotta Pie just said, Light,

thanks for the response.

You're certainly welcome.

Again, ask questions, everyone,

in the chat because we will try and

get to them.

In the meantime,

we're going to talk about Apple and how

Apple has finally fixed...

a vulnerability in hide my email after

being shamed by four or four media,

because sometimes that is what it takes.

So we did cover this.

I actually went and looked it up.

We covered this on episode sixty when

Calix OS came back.

It was our second story, it looks like.

So if you want to hear the original

coverage,

you can go back and check that out.

But long story short,

Apple says it is fixed to vulnerability in

their Hide My Email feature,

which let essentially anyone figure out a

user's real email address,

which was supposed to be protected by the

feature.

It's literally your one job.

So they knew about it for about a

year.

And for those who don't know,

hide my email is exactly what it sounds

like.

It's a paid feature and it lets you

create a new masked email address when you

sign up for something that still forwards

to your main email address.

So that way,

if it gets caught up with spam,

you can just turn it off or whatever

and it won't

you won't keep getting spam or they point

out here, uh,

hackers can also have a harder time

cross-referencing your various accounts.

So Tyler Murphy,

co-founder of easy opt-outs,

which is a service we do recommend.

It is a service that I personally have

been using for years and I love it.

Um,

he discovered this vulnerability and tried

to report it to Apple.

Uh,

Apple,

I think if I remember the original story,

Apple started to reply and, you know,

kind of started to work with him and

then just kind of ghosted him and stopped

responding.

And at that point,

Murphy came to four or four,

four or four published a story.

And now the Apple was shamed.

They had to go ahead and respond again.

They said that it was fixed.

And at the time,

four or four was not disclosing how it

worked because, you know, of course,

it's like they haven't fixed it yet.

Anybody can do this.

But now we have some information.

And to put it simply,

it required sending a target and a message

that gets rejected as spam and you

purposely want it to get rejected.

They said,

we don't know how often hidden email

addresses were leaked in email logs.

For many major email hosts,

the leak was triggered simply by an email

being automatically rejected.

Even if it was legitimate,

such emails probably didn't make it to

your inbox.

So you can't review your spam folder to

learn whether you were affected.

which is kind of scary.

But yeah, basically when it got rejected,

the mail transfer logs could contain the

hidden email address,

your original email address,

which would be exposed to the attacker.

I think they have a link to Tyler's

blog post explaining this stuff,

potentially.

I could be wrong about that.

But yeah, I guess that's kind of...

What's going on here now that we know

more about how it works?

Not much of the story,

just kind of a little tiny little bit

of good news to end on.

I want to bring Jonah in to fact

check me on this one.

But I did a little bit of very,

very rudimentary research.

And I think it is potentially possible

that people like SimpleLogin and Addy

might be vulnerable to this,

depending on how they handle spam

rejections.

Do you know anything about that or

anything?

Is that just pure speculation?

There's not a lot of...

There's not a lot of details about how

this works exactly.

I'd have to look more into it.

Because I suppose...

I suppose this is probably more dependent

on how your... Not the aliasing provider,

but how your mailbox provider handles

messages that are sent to spam.

Um...

I would hope that that would get reported

to the aliasing provider instead of the

person who sent it,

which it sounds like is probably the case

with Apple.

But I actually don't know how that works

or how this vulnerability bug works.

It actually is.

If you go to easyoptouts.com,

there's a little banner right at the top

that says CR statement about Apple's hide

my email vulnerability bug.

It is a twenty minute read,

so we probably can't read it here.

But it looks like he does go into

detail.

If you scroll down to the exploit.

So, interesting.

So, yeah, we might look into that.

I'm very... Here,

I'm going to share it while you're looking

at this.

Okay,

it does say that hidden email addresses

were leaked for a variety of mail hosts,

so they saw them not just for iCloud,

which is one thing I was wondering.

I don't really understand why Apple's

servers would do this,

which is probably what EasyOpt does,

and everyone else doesn't understand.

It just doesn't make sense to me.

So I...

doubt this is an issue.

They do say in this post,

there's another email aliasing services

section,

and they tested this vulnerability against

many of the aliasing services on the

market according to them,

and none of them had the same kinds

of vulnerabilities.

I assume at minimum they tested SimpleLuck

and Addi because those are like the two

main ones people typically look at.

Oh,

I see they have a how to tell

if you're affected section here.

Yeah, so I guess you can test it.

I guess we could test it.

But yeah,

I can't imagine why Apple's service would

be configured in that way.

It really does sound like a specific to

Apple problem.

Yeah, I think you're right.

I see the section here now where it

says,

we did limited testing against many of the

major aliasing services on the market,

none of the ones we tested.

And yeah,

SimpleLogin and Addy are definitely two of

the biggest ones.

So at least SimpleLogin, I would imagine,

was probably tested here.

Yeah.

If nothing else,

hopefully now those providers are aware of

this and they can go test themselves and

make sure they're not configured like

this.

Yeah,

it's always a shame that these companies

have to be kind of pressured into fixing

obvious problems,

but at least it's fixed for everyone using

this.

Yeah, yeah, I agree.

I don't know why they have to drag

their feet so much, but.

I digress.

Yeah,

I was going to say the last note

that I had written down here is we

still do recommend services like

SimpleLogin and Addy over Apple because,

for one, they're more transparent.

They're open source.

I think you can even self-host SimpleLogin

for sure, maybe even Addy.

And lack of vendor lock-in.

If one day you wake up and you're

like, you know what?

I'm going to move to Graphene.

Guess what?

You're not locked into Apple if you go

with something like SimpleLogin.

Yeah.

yeah um but that's i think all i

had yeah taken what maybe a maybe a

look at our final chats here uh

In Signal,

somebody commented about the FCC thing.

I'm also informed in our Signal chat just

during the show, speaking of donations,

that Cape has sent a donation to Privacy

Guides.

I don't know anything about that,

but I'll have to look into that.

But thank you to Cape for donating.

Hopefully, we get other donations too.

But yeah,

I will have to check into that after

the show.

Yeah, thank you.

Like I said, every little bit adds up.

It really does.

Even if it's just a dollar a month.

Years ago, last time I checked,

you guys used to have the Umami Analytics

on the website publicly.

And I remember checking one time out of

curiosity,

and it was literally like a hundred

thousand visitors a month.

And it's like literally if half that

number gave a dollar a month,

I'm sure that would go so far.

That'd be sweet.

If all of them did,

then we'd finally be that million-dollar

revenue.

Yeah,

we don't need nearly that much money,

but we could.

There's definitely improvements that could

be made.

I think I just wanted to,

now that you mentioned it,

kind of look at our stats on the

form, and I think we get...

I mean, we get millions of page views.

I don't know if I can see how

many individual people visit,

but whatever.

And that's another thing I think about a

lot too is like, you know, with Umami,

it's like,

it's kind of privacy respecting analytics.

So it's like,

how many of those are individual and how

many of those just have a different

fingerprint now?

Cause their browser or whatever.

So yeah, it's hard to say for sure,

but I mean, it's still a lot.

So that's why you track visits and page

views.

We did get a question just now from

username five, nine, five, four, nine.

There are a few offline privacy focused

navigation apps,

but none seem to have a good interface.

Do you think it is important to stay

away from Google maps or is the privacy

concern insignificant?

I mean, in my opinion, I think the,

the,

I would still have one of those as

a backup in case you ever lose signal

or something like that,

which I've been in those situations where

just the cell signal is not very good

and I'm kind of screwed.

But from a privacy perspective,

if I'm being honest,

I think it really depends on where you're

going and how often.

If you know how to get around town

and you're only ever using Google Maps

once a month or once every other month

when you're going somewhere new, then...

it's probably not that big a deal.

And especially if you're just like, Oh,

I'm checking out a new restaurant or

something.

But if you're using it like constantly,

like I used to use it at my

last job.

Um,

I was constantly working on different job

sites and because we were on the clock

and we were usually going there during

rush hour,

I was constantly trying to find the

fastest route.

So I really relied on mostly Apple maps

cause I had an iPhone at the time.

And, uh, you know,

but I was using it like every day,

all the time to get to and from

places just to, to skip traffic.

And that was probably not great for

privacy, but you know,

I was on the clock.

What am I going to do?

So I don't know.

That's, that's kind of my take.

I think it depends on how often you're

using it and what for.

So your answer is kind of like,

how much do you want to be tracked

by them?

I mean, pretty much.

Yeah.

Yeah.

That is kind of what it comes down

to, isn't it?

But yeah.

Do you satisfy your curiosity about the

analytics?

It's kind of complicated.

We had a weird spike spike in visitors

on the sixteenth for some reason.

I wonder why that was.

Dude, I get the same thing on mine.

I'm really genuinely convinced it might be

like a scraping because it'll literally go

from like a couple hundred visitors a day

to like ten thousand visitors at four a.m.

on a Tuesday.

And then it'll drop back down and it's

just like something fishy is going on

there.

What did we do on the sixteenth of...

I mean, the weird thing is it stayed...

That was the peak,

but it stayed pretty high for the week

following that on this graph.

I have no idea why that would be.

I don't have a calendar open in front

of me, so that is a good question.

Anyways...

I think we want to close this out,

or you got anything else you want to

add?

I'm not seeing anything on Signal or the

form, so...

Did you see the news about Codeburg

banning cryptocurrency projects?

I skimmed it briefly.

I saw the forum post about it and

something about, you said it was,

what was your wording?

It was extraordinarily poorly worded.

Well, I just don't understand it.

I guess I don't have much to say

about it,

but it seems like they're saying two

different things.

And it doesn't really make a lot of

sense to me,

but just a weird thing I've saw in

the forum lately.

Is it just,

they're basically just bamming scammy

crypto products?

Well, yeah, I mean,

like in this banner at the top of

their page,

they just say cryptocurrency projects are

no longer allowed.

And that's also what it says on their

terms of service.

But then like in a random comment on

this thread about the change,

they explain that it's only scammy ones,

which is not what it says.

But I guess if you go down and

read this random comment,

you would know which ones are allowed and

which ones aren't.

Interesting.

I wonder if it's one of the,

what do they call that,

like a silent policy?

Yeah, I mean,

it feels like it'll just be enforced

probably arbitrarily,

which is probably not how I would prefer

the services that I use operate.

Codeburg kind of annoys me sometimes.

It's one of the reasons I don't want

to switch to it.

I know people ask us that all the

time,

and I don't really like Codeburg or GitLab

or

more than i mean i i like him

like just a little more than github but

not enough to switch off of github but

i do like codebook software i i would

love for joe to get to the point

where we could we could switch to it

but i really wish it had federation and

they have and that's taking a really long

time so sadly i don't know i mean

can't complain about it too much i don't

know how to speed it up so but

it it just is

I'm sure that ActivityPub is not

necessarily perfect for everything,

but I do really like the idea of

so many different services being

ActivityPub compatible because then you've

got this ideal scenario where it's like,

I can comment on YouTube, Instagram,

Twitter, GitHub,

all these different things from one

account.

And I don't need to keep making accounts

if I don't want to.

And that is probably one of my favorite

things about the Fediverse.

Yeah.

And it's like,

I hope they can do it soon.

It feels like it actually wouldn't be that

complicated for this use case because Git

is already decentralized.

So you pretty much only have to federate

issues and stars and pull requests is

probably the hardest one,

but Git already has...

ways to work on things remotely and on

different branches and you can just pull

it in from a different site so it

feels like it wouldn't be extraordinarily

difficult like it's basically just

comments and reactions is the main thing

which is which is already done by every

single activity pub platform out there

that's that's how they work it's comments

and posts right um

But I mean, I'm obviously not coding it,

so I can't provide too much input or

complain about it too much.

Because I'm not going to do it myself,

I can tell you that.

Fair enough.

I think that's kind of it then.

So yeah,

I think you can wrap it up.

Nate, you're muted.

I hit the button too many times.

My bad.

All right.

All the updates from this week in privacy

will be shared on the blog every week.

So sign up for the newsletter or subscribe

with your favorite RSS reader if you want

to stay tuned.

For people who prefer audio,

we also offer a podcast available on all

platforms and RSS.

And this video will be synced to PeerTube.

Privacy Guides is an impartial nonprofit

organization that focuses on building a

strong advocacy community and delivering

the best digital privacy and consumer

technology rights advice on the internet.

If you want to support our mission,

then you can make a donation on our

website, privacyguides.org.

To make a donation,

you can click the red heart icon located

in the top right corner of the page.

You could also just go to

privacyguides.org slash donate and you can

contribute using standard fiat currency

via debit or credit card or opt to

donate anonymously using Monero or your

favorite cryptocurrency.

Becoming a paid member unlocks exclusive

perks like early access to video content,

priority during the live stream Q&A.

You'll also get a cool badge on your

profile in the forum and the warm fuzzy

feeling of supporting independent media.

So thank you all for watching and we'll

see you next week.