Mullvad’s Co-owner Made A Controversial Donation
Mulvad's co-owner made a controversial
political donation.
A U.S.
court has ruled border agents can search
your phone without a warrant.
And a little bit of good news from
Apple.
All this and more coming up in This
Week in Privacy, number sixty three.
So stay tuned.
Welcome back to This Week in Privacy,
our weekly series where we discuss the
latest updates with what we're working on
within the Privacy Guides community and
this week's top stories in data privacy
and cybersecurity.
I'm Jonah,
and with me this week is Nate.
By the way,
we're going to be ditching our Q&A section
we normally have at the end in favor
of answering questions just throughout the
stream.
So if you have any,
no need to wait.
Just ask away.
We will be checking the chat here,
of course,
and also
um our forum thread and our signal chat
for privacy guides supporters so any of
those places uh yeah let us know if
you want us to discuss anything anyways
how are you doing today nate i'm doing
pretty good um
Yeah,
I don't think I have much to say.
It's been a surprisingly good week,
I think, for me.
How are you?
Good.
You know, I'm doing good as well.
I was just talking to some people,
I know you know about this,
but this morning I booked all of my
stuff for DEF CON in a few weeks.
Kind of a last-minute booking,
which is how I normally handle things.
But that'll be exciting.
So...
If anyone is going to DEFCON,
it would be very cool to meet up
with anyone,
but otherwise I will be doing that and
I'm looking forward to it.
I've never been to Vegas before.
Have you been to Vegas, Nate?
Surprisingly, no.
I actually spent seven years in Southern
California and Vegas was only a few hours
away.
But for the majority of that time,
I was under twenty one.
And a lot of people told me that,
like, yeah,
there's stuff to do if you're not twenty
one.
But there's like and they're not even
talking about gambling,
which is like getting into places like
there's more stuff to do when you are
twenty one.
So I just never really made the time.
But that is really exciting.
I do want to go to DEF CON
one day.
So I hope you have fun.
Yeah, you should come.
Hopefully we can do it next year or
something a bit less last minute for sure.
Yeah, that would be super awesome.
But yeah,
I guess we'll go ahead and jump into
this week's stories and cybersecurity
stuff that you might be discussing at DEF
CON, possibly.
Who knows?
But we're going to start with our big,
big story, which is about Mulvad,
the Mulvad donation controversy.
So for context here,
this actually came to light a few weeks
ago.
I want to say like a month ago
that one of the co-founders of Mulvad VPN
named Daniel Bernson,
I probably pronounced that wrong, donated,
I believe some sources I've found said
five million Swedish kronor,
which is a little bit north of five
hundred thousand US dollars to,
I'm definitely going to pronounce this
wrong, the Orebro party in Sweden.
According to Wikipedia,
this party has been described as both left
and right wing.
But from what I can tell,
they're largely considered left wing.
And this, unfortunately,
this is relevant to the story.
Despite being considered largely left
wing,
the party apparently also has some
significant nationalist,
populist and conservative views.
And one of the big ones that I've
seen thrown around a lot that people are
upset about is remigration,
which is a term I've never heard before.
The summary I found said it's a policy
aimed at encouraging or compelling
immigrants to leave Sweden.
Another summary said the party's platform
includes strong secularism,
immediate closure of Islamic charter
schools,
and the assertion that Sweden belongs to
the Swedes.
So again, for the record,
these are summaries I read and I have
never been to Sweden.
I am not Swedish.
I don't think I know any Swedes other
than I think I've talked to some of
them all bad people for like two seconds
in the past.
So apologies if I got any of that
wrong, but that is what my research is.
turned up.
So again, this, this story started about,
I mean,
apparently this donation took place in
twenty twenty five,
but I guess it just came to light
about a month ago.
And Moldad has officially commented now
because this has become such a big thing.
And I'm just going to kind of pick
out bits and pieces of this story because
there is it's it's
It's not a huge, huge statement,
but it's a little bit too much to
just read off here.
Basically, they said,
this is a private donation from Daniel to
the individual.
Mulvad or its parent and sister companies
did not endorse and were not involved in
it.
And then they kind of went on to
basically say that, well, actually,
let me scroll down a little bit here
and read one more part.
Mulvad does not condone it nor condemn it.
It was most likely a bad idea.
Most things where there are a multitude of
conflicting opinions necessarily are.
i don't know about that but societies need
a great diversity of ideas initiatives and
organizations who can be tested and sifted
until the best ones remain ideally through
rational debate daniel's rationale and
points of view can be read on his
personal blog um which i'll throw up on
screen real quick just so you guys can
see it uh he has written quite a
bit actually um about a number of his
views both related to that party
specifically and politics um so you guys
can go read that if you'd like to
Just to clarify,
when I said I don't know about that,
they said the part where most things where
there are a multitude of conflicting
opinions necessarily are.
I mean there have been a lot of
controversial ideas in the past that I
would argue have stood the test of time,
but whatever.
Yeah.
So basically they go on to say in
this, this post, um,
to kind of summarize it,
they basically say like Mulvad is
nonpartisan.
Um,
their interest is in making a VPN and
providing people with the, uh,
the tools to bypass censorship and access
information and communicate freely and
privately.
And, uh,
they kind of point out like sometimes,
you know, we, we talk about this with,
um,
we talk about this with like,
like encryption, like necessarily people,
unfortunately are going to use encryption
to do bad things,
but that doesn't necessarily mean that we
break everybody's encryption.
Right.
And that's kind of the same argument that
they're taking.
And let me see if I've got it
all down here.
So yeah, Daniel, like I said,
Daniel's got his own blog post over here.
I'll be honest.
I had a little bit of a hard
time following his launch.
I mean, it is, is a lot.
And yeah,
I tried to read it all.
Again, I'm not Swedish,
so I think maybe some of the context
escaped me.
I also,
if I can be a little bit sarcastic
down here, he says, disclaimer,
the views in this text,
while partially inspired by the two who
founded that party,
are mine and not theirs or the party's.
And it's like, so basically you said,
here's why I voted for the party.
And by the way,
nothing I said is what the party said.
So I don't really understand what he's
saying there.
I kind of do,
but I kind of don't.
Anyways, if I read his blog correctly,
he's basically saying like,
he doesn't really believe in that party,
but he, again,
could be reading this wrong,
but he's kind of like trying to encourage
competition.
Like maybe if we have more viable party
options,
maybe the existing politicians will do
better,
which as somebody living under a two party
system,
I can say I kind of understand that
logic,
but I don't know how well it holds
up.
But yeah, I think that's a,
I think that kind of gets us up
to speed.
I think I'm going to throw it back
to Jonah at this point to kick off
the analysis.
Jonah,
could you maybe start by kind of like,
why, why has this become,
I think it's probably obvious for most
people,
but just in case anybody's wondering,
like, why,
why has this become such a hot topic
in the community?
Do you think?
You know, I think well,
in terms of why it became a hot
topic,
I think that the privacy community in
general is a fairly political community
because obviously we are fighting for
privacy, digital rights.
A lot of that has to do with
not only, you know,
getting privacy from big tech companies,
but also having privacy from the
government and making sure that the laws
of
you know,
where you live are protecting your privacy
rights.
And we talk about privacy policies and law
on our forum and on this channel all
of the time.
And I don't think any of the policies
that this party has are specifically
privacy related,
although there are certainly some privacy
implications with some of the re-migration
stuff that they're doing,
which is a whole separate topic.
But it's not surprising to me that
that people who have an interest in
privacy are also going to have an interest
in a lot of other political topics.
And so
It's definitely controversial because it's
the sort of thing that is going to
blow up on social media.
We've seen a ton of this talked about
on Mastodon and on Twitter,
and I'm sure on other platforms where
Malved is as well.
Obviously Malved was feeling the pressure
because they had to post a full response
about it.
And I think a lot of people just
have questions about what it means
for Malvet,
especially if they don't feel like
supporting these policies.
And so we could take a look at
some of the questions.
We've received questions just during this
show already and some statements.
We could look at Take Out the Lobster
on YouTube said,
it's not really an extreme party.
If that's what you're getting at,
sincerely, a Swede.
I will say, neither of us are Swedish,
obviously.
I mean, maybe ancestrally,
but not living in Sweden.
I have no familiarity with Swedish
politics,
and I assume Nate does not really either.
I don't really know much about this party,
to be honest,
and they seem to be all over the
map.
I don't think the question is how extreme
they are, but they do seem to be,
from what I've gathered and from what
other people have said,
just a very populist party,
which is the sort of thing where...
A lot of the times with these populist
parties,
they will have a lot of policies and
say a lot of things mainly to get
votes and support more than actually
supporting it.
And they might not even believe any of
the things that they're supporting.
Or they only have certain policies that
they care about.
I think that this is a big problem
with some parties,
especially ones that are described as both
right and left wing, like this one is,
like Nate was saying.
Because in a lot of cases,
when a party seems like they are kind
of on all sides of the aisle,
they're actually only supporting one side,
but they want to get votes from anyone
that they can convince.
I don't really know...
where I don't really know.
I guess at the end of the day,
his support for it doesn't make a lot
of sense to me.
He said in his own blog post that
he doesn't really support many of the
policies that this party supports.
So I don't know why.
I think it was at the end there,
if you have it on the screen, Nate.
But
Yeah,
it doesn't make a lot of sense to
me to become that party's biggest
supporter But again,
I don't know how much this competition is
really needed in the Swedish political
space A lot of the questions that I've
seen are more about like Just how much
of Mulved's money is actually going to the
causes that the co-founder supports and
As far as I know,
Mulvad is basically co-owned fifty-fifty
between him and another person.
And they're co-CEOs and they kind of just
split everything down the middle.
And so it's, I don't know, Nate,
you could probably elaborate more on this
a bit,
but in terms of like whether you should
continue using Mulvad or not.
It's less of a privacy or a technical
decision and more of a philosophical or
political how you feel.
At the end of the day, your money,
if you support Malved,
some of that is going to be supporting
these things that one of the co-founders
cares about because he's getting the
profits from Malved, right?
Even if Malved's not directly doing it,
you're...
sending money that way which is something
to consider but at the same time you
know you can separate the art from the
artist and if mulvet isn't directly
supporting themselves it's just one guy
who's profiting off of it maybe that's
less of a big deal to you i
don't know what do you think nate i
think it's um i think it's really personal
preference um real quick just to kind of
go back to uh to what um take
out the lobster said uh what i was
getting at is basically just that i just
wanted to
I don't know if hedge my bets is
the right word, but basically like,
I don't know a lot about this party.
I hadn't really heard of them before.
So it was kind of my, like,
I wasn't trying to insinuate they're
necessarily an extreme party.
I was more just saying like,
I apologize if I'm summarizing this wrong,
but yeah, I think it's,
It's so tricky because I think both of
those takes are true.
You know,
Eteru said here that he said in a
real fight,
nobody drops the best shield just because
they dislike the creator.
But at the same time,
I think it's not quite the same.
Like, I see where you're coming from,
and you're absolutely right.
Like, if I was in a firefight,
I'm going to use whatever protection I
have available to cover myself.
But it's so, like...
I don't know.
I think that's a valid take,
but at the same time,
I think not wanting to – because when
you're subscribing to Moldad,
you are directly putting money in this
man's pocket.
Like, full stop.
You are.
Period.
Full stop.
And so you're giving money to him,
which he then in turn turns around and
gives to a party that –
may have serious like political things
that you don't believe in.
You know, if,
if he's talking about forcibly removing
immigrants from the country and you know,
like,
like maybe that's something you don't
believe.
Maybe, I mean, like my wife is Hispanic.
I don't like people.
I'm just going to say here in the
U S I don't like people who have
that whole, like, Oh,
we need to kick them all out.
Like, you know, it's, I don't know, man.
I think they're both valid takes is what
I'm getting at.
Like, if you're like, no,
it's the best tool we have.
it's his money and i don't think we're
gonna find a better tool i i think
that is a perfectly valid take but i
also think it's completely reasonable that
some people would be like yeah but my
money is directly supporting him which is
in turn directly supporting them so it's
basically like i'm giving money to them
but just through a proxy and i don't
want to give them my money like i
think that's also a perfectly valid take
um
Personal opinion,
I think I would like to see in
the community itself,
I think I would like to see more
appreciation for that.
I think not to like kind of be
judgy and call people out, but you know,
this whole, like you said, again,
this comment,
this MOVAD drama shows how people confuse
politics with engineering.
No, like technology is political.
I'm kind of, I don't know.
I'm one of those people who thinks that
everything is political when you dig deep
enough and there's really no such thing as
being non-political or apolitical.
And so it's like,
I think understanding that for some
people, this is really important to them.
And I think that's valid.
And just having that kind of patience that
for some people,
they care for some people, they don't.
And this is something that comes up a
lot.
I think most of the time when like
people say that they're not going to use
something that's widely recommended,
like MOLFAD, we see it with Graphene OS,
for example,
we see it with other projects.
We see it with Proton all the time,
where I think
When somebody says they're not going to
use something for some non-technical
reason,
there's a group of people who get mad
that they're doing that and that they're
not using it,
which is a reaction that doesn't make a
lot of sense to me.
If somebody isn't going to use Malved
because of this,
I don't think there needs to be a
whole argument about why the politics and
how this doesn't actually matter because
Malved is still secure.
It's fine if you don't want to financially
support this sort of thing.
But yeah,
just kind of an annoying thing that I've
seen in the community beyond Malbed's
stuff.
I would say the other thing I wanted
to point out really quick,
I did see a lot of comments in
the community basically talking about the
potential privacy implications for some of
these policies.
The re-migration one in particular,
it does call into question
A lot of privacy concerns about how those
people would be found in Sweden,
for example,
and how they are determining who needs to
stay and who's going to leave,
what metrics are they using.
Obviously, here in the United States,
we've seen a lot of news about ICE,
for example,
and how they're using facial recognition
everywhere,
and they all have these apps on their
phones that they can scan people with,
and all of this data is being collected
into databases.
All of those immigration policies and some
of the stuff that this party is supporting
can directly have privacy implications for
people living in Sweden.
And obviously, we've seen already,
maybe it's not obvious, but in the US,
people who are not targeted by these
policies,
like American citizens who were born here
in whatever,
are are also swept up in in these
privacy invasive things that the
government is doing and it's very possible
that if policies like this were
implemented in Sweden a similar sort of
thing would happen where you know it's not
only going to be targeting illegal
immigration but also it's going to sweep
up Swedish citizens into this this whole
immigration system and a lot of people I
think
Will probably be opposed to that just from
a privacy perspective as well.
I did see a lot of comments about
that on the forum.
So I did want to bring it up
because I do think a lot of people
are saying like, well,
there's no privacy implications at all.
So if you only care about privacy,
it doesn't matter too much, right?
Um,
Yeah, I mean,
there's so many questions and comments on
this one.
Let's take a couple from Jordan's been
relaying some from the Signal chat.
Yeah.
Let's start with some of these.
So how is the co-owner?
I think you answered this.
How is the co-owner invested in Mulvan
financially?
If I pay for Mulvan,
in what way I pay him?
Well, first of all,
I think you said there are fifty fifty
owners.
But also, like, I want to point out,
he draws a paycheck.
That's my understanding.
Yeah.
I don't know how that aspect of it
works because, you know,
when you own a company,
and Movit is a private company,
so all of this stuff is not going
to be, it doesn't have to be disclosed,
basically.
But when you own a company,
you can take a paycheck or a salary
for all of the actual work that you're
doing.
But then if you're an owner,
you can also take profit sharing,
which is usually quite a lot more.
It's why you see all these billionaires
who are like,
my salary's a dollar because they just get
all of their...
money via other means so they don't need
to pull an actual salary.
So I'm sure he takes a salary and
like normal income,
but in terms of what he could be
getting beyond that,
I would imagine it could be up to
fifty percent of the profits.
I don't know who else is entitled to
to get that money outside of Malved,
but could potentially be quite a bit of
support.
Yeah, I know this isn't really the point,
but just to throw that out there,
that's also – it goes the other way
too.
Sometimes you'll see like, oh,
this CEO is making like fifteen million
dollars a year, and it's like, well,
they're actually making less than that.
But when you include all the stock options
and this, that, and the other,
which for the record,
they're still making a disgusting amount
in –
Not literally disgusting,
but they're still making a crap ton of
money in raw liquid cash.
But yeah,
it's usually it's not fifteen million
dollars in liquid cash.
It's like some million in liquid cash and
then the rest is stock options and stuff.
But I don't know if all that works
the same way, but I digress.
Um, so yeah, uh,
here's a fun one from Signal again.
What were the relevant statements and
actions the Mulvad company took to
distance themselves from that and prevent
it in the future?
Uh, none really, to be totally honest.
If you, I mean, if you read this,
this, um, statement, it,
it very specifically says that like,
I don't even know how to summarize it
to be totally honest,
but they didn't condemn it.
They didn't endorse it.
They just basically said this happened and
we don't care and we're just going to
keep doing our thing.
Yeah,
their position is definitely that they're
not going to police what their owners are
doing or what their employees are doing or
what anyone is doing in their personal
time.
It's just going to be...
You know,
Malved themselves are not going to support
things like this,
but what people do with the money that
they earn from Malved is kind of their
problem, is Malved's position.
There's a question on the forum,
and Jordan asked a similar question
earlier in the chat,
so I can kind of cover it.
both of them.
Jordan asked if there should be
restrictions on executives making
political donations to stop this sort of
thing.
Somebody on the forum thread asked at what
point is it acceptable for an executive or
lead developer to support something that
could be deemed controversial.
You know, at the end of the day,
I think all...
executives of companies that have
customers like mall fad are public
figures, whether they like it or not.
And so all of their the things that
they do in their personal lives and the
personal choices that they make,
they're gonna have business impact.
And obviously,
this has had some business impact at mall
that because they had to speak out about
it.
And a lot of people are saying that
they're canceling because of the co owners
personal decision here.
So
mean it's always going to have an impact
at what point is it controversial or
should there be restrictions it really
just depends on the company i think you
know it's not unreasonable i i was
explaining this on the form uh in the
form thread about this to somebody but
like it is fairly normal when you're
dealing with public figures whether that's
an executive of a company or if you're
like hiring an actor for a movie or
something to have clauses in their
contract or morality clauses that kind of
restrict them from
doing controversial things like this
because it does have an actual impact on
the business itself.
It's not just a personal thing.
So like that is something that well that
could do but whether they should do that.
is another question entirely and it kind
of comes down to what the company thinks
is an acceptable risk i mean it's not
like you can mandate this and make like
make it a law or anything um it's
just it comes down to whether malvad wants
to accept that uh it's gonna have an
impact on their business and it seems
clear from their statement that they are
just going to accept that as a as
just the fact of life for their business
A similar story,
I don't know how many people,
maybe not a lot of people know about
this,
but I've read a lot about it because
I've been looking for merch and stuff for
privacy guides and I see people talking
about it on Mastodon,
but a lot of people used to really
like Sticker Mule for stickers and then
their owner turned out to be a big
Trump supporter,
so now a lot of people don't want
to support that company mainly based on
that.
So it's kind of a similar thing.
the personal leanings of the owners of
these companies is going to have a
significant business impact,
whether you or they like it or not.
It's just how it is.
Yeah, I don't know.
I don't know.
I don't think I have much to add
to that because I'm with you in the
sense that I don't really know where that
line should be because on the one part,
they are public figures and you're right
about that stuff.
And people are going to have those
reactions either way, right?
I mean, like,
it happens on both sides of the aisle.
Look at, you know,
Bud Light had like a trans person as
their spokesperson at one point,
which was really weird to be honest for
Bud Light.
That was definitely off brand for them.
But you know,
it happens on both sides of the aisle.
And, but at the same time, it's like,
as a person,
like I remember when I was in the
military, that was the rule there is like,
you don't do anything public,
especially in uniform.
Like, yeah, go vote, go do whatever.
But like,
you are not allowed to speak out publicly
as a uniformed military member and be
like,
I support Obama or whatever publicly.
um so yeah it's it's it's i think
that's where this whole like i think
that's where a lot of the controversy is
coming from is where is the line between
like this person is an individual who has
the right to support whatever ideas they
want even if they're garbage ideas and you
know where is the line between that and
like well your your customers have an
expectation of you and i think you made
a really good point that like the company
definitely depends a lot i think if you're
in like um
If it's like some kind of nonprofit that's
like providing legal assistance for
immigrants and then they go out and donate
a bunch of money to Trump,
that would be super weird.
But yeah, I don't know.
It's tricky for sure.
Kind of related that we had a comment,
kind of an opinion from either you,
hopefully I'm saying that somewhat
correctly,
who said that voting with your wallet is
valid for personal ethics,
but in threat modeling,
prioritizing political alignment over
technical robustness is a trade off.
Kind of two things I want to unpack
here.
The first thing is simple.
I think with VPN companies in particular,
we got to understand that these are not
zero trust technologies like you're
talking about,
you do have to trust your VPN provider.
And so this kind of thing does come
into play because a VPN provider is
basically like an ISP.
You're just shifting your trust to that
VPN.
You're not eliminating the risk involved
with an ISP seeing all of your data.
That's what we're pretty clear about on
our site is the main use case for
a VPN.
So if you don't trust the VPN,
there's literally no point in using it.
And this is a trust question.
but when it does come to zero trust
things or things that can be more
technically cryptographically proven uh
you know i think there is a solid
point here going back to what i was
saying about um graphene os for example or
proton mail with with these sort of things
there are guarantees there's
inspectability so people can um like
see what code is running on Graphene OS.
It's open source.
People can see, like,
Proton is using end-to-end encryption,
so they can't read all of your messages
at rest.
That sort of thing is important,
and it does eliminate trust,
and I think when you can eliminate trust
whenever possible,
which is ideally how all privacy products
would work,
then this kind of thing does become less
important over time,
and it is more of just a personal
morals thing at that point.
I don't feel that bad about it in
this case,
because there are perfectly good
alternative VPN providers you can choose
from.
We have other recommendations on our site.
Whether this is going to cause us to
change our recommendations on our site and
stop listing Malvet,
I don't think it's going to.
And in fact,
despite how controversial this topic has
been and how many people are posting about
it,
I haven't seen anybody really suggest that
we do that.
You know,
you can definitely separate it a bit.
But in the case of a VPN,
I do think it's valid to be concerned
about this at the very least.
Yeah.
On that note,
I did want to make sure that we
pointed out that, um, not,
not trying to tell people what side they
should take,
but this is not something that at this
point in time,
we have any reason to believe is impacting
mold ads, actual technical product.
So again,
going back to that argument of like,
some people are like, I don't care.
It's his money.
It's his business.
The product is solid.
The product is still solid as far as
we know at this time.
And, um,
I think that's something worth noting.
And kind of related to what you were
just asking, somebody in the forum asked,
I'd like to know from the staff what
they think of Mulvad versus other
companies in terms of what they contribute
overall.
Are they offering unique benefits,
not just in their current VPN where we
know there are other good options,
but in terms of what they bring to
development, research, privacy,
advocation, et cetera?
And honestly, yeah, kind of.
I don't know how I feel about sticking
up for Mulvad because I'll make it clear.
I don't agree with the policies of this
party that he supported.
But they ran a huge campaign all around
the world to try and bring privacy more
to the mainstream.
I remember seeing Mulvad buses when I was
in Seattle for something last year.
And I saw the Mulvad buses and I
tried to grab a picture,
but they went by too fast.
I was like, oh, that's cool.
There they are.
But they ran this big ad campaign.
I think they've been...
I could be wrong,
but I think they've been pretty vocal
about being against chat control.
I mean, you say research and development.
They do a lot of innovative things,
in my opinion,
like these RAM-only servers and
their data service, things like that.
So like, yeah,
I think they are really innovative.
And actually there was one other thing I
was gonna point out.
They're not unique.
I'm gonna share this tab real quick.
Jordan brought this to my attention a
while back when we were chatting.
There's a Medium post.
After Andy N went and like made some
kind of pro-Trump comments,
somebody kind of pointed out, and to me,
for the record,
I take this post with a little bit
of a grain of salt because this person
has never posted anything before or since.
And, but, you know,
they point out that like,
Proton has historically donated to a lot
of organizations that are not necessarily
aligned with stuff like that.
And so anyways, my point being is like,
yeah,
MoVAD is not the only company that's out
there donating to good or to,
I shouldn't say good organization.
MoVAD's...
Putting this issue aside,
there are other companies that are out
there doing good things in the privacy
space for advocacy and research and stuff
like that.
And I wanted to tie that back into
what you said with that question.
It mentioned threat modeling.
And yeah, you could go with,
I would feel pretty safe saying that I
think Moldat is probably the best option
right now in terms of privacy and security
and a VPN.
But at the same time,
what is your threat model?
Like,
if your threat model is so high that
you cannot afford anything less than
MoVet,
you probably shouldn't be using a VPN.
You should probably be using Tor or
something like that.
But, you know, Proton is still good.
IVPN is still good.
Like,
I think there are still good options out
there where for your threat model,
you don't have to sacrifice privacy and
security to also still be ideological.
So, yeah.
Okay.
I will add though, on the other hand,
while there are companies that are doing
innovative things just like Mulvet,
I think there are probably companies where
their leadership or employees are doing
controversial things that you don't know
about and haven't heard about.
Some of these things are kind of
unknowable.
And so that's what makes it hard,
I think,
to base your decisions around this.
I mean,
now it's kind of proven that if you
don't agree with the ethics of the
situation,
now you have proof that Malved is
unethical in your eyes.
But you can never really prove that a
different company is any more ethical than
that,
because they could be making very similar
donations behind the scenes that you just
have not heard about.
So it's why it's the sort of thing
that it's hard to...
take as a huge factor when you're making
a purchasing decision, for example,
in my opinion.
Yeah, for sure.
I don't want to be too defensive,
but I do want to point out Gaethje
said, both sides of the aisle.
Bud Light, as we support people,
be yourself.
For the record,
that's not what I meant when I said
both sides.
What I meant is that both sides do
things that alienate their fan base.
No,
I do not believe that both sides are
the same, personally.
So...
I just mean they both do things that
alienate people, but I digress.
Wow.
We spent a lot of time on that
story, but that is,
it's such a complicated story.
It's just, and it's, again,
I want to reiterate in my personal
opinion,
like I think both arguments are valid.
If you're like, well,
that's the best VPN and you want to
stick with it, go for it.
But just be aware where your money's going
and vice versa.
If you're like, nah, screw these guys.
I want to take my money somewhere else.
Like, I think that's cool too, personally.
So.
Was there anything else we wanted to add
to that one before we move on to
the next story?
Yeah,
let me just look at the questions quick.
I don't think there's any remaining that
we haven't answered,
at least about Malvad.
So we can kind of move on.
But if we missed any or if we
missed one in Signal,
feel free to send it again and we
can look at it.
otherwise i think it's probably a good
time to move on to our next story
here uh before i talk about that one
though i want to go back to some
defcon questions we had from earlier
somebody on youtube dragon black knight
asked about hope i'm not going to go
to hope um there are so many conferences
that i would like to go to uh
carrie parker from firewalls don't stop
dragons is in the uh
is in the chat and explained why he
wouldn't be going.
And it's pretty much the same reason for
me.
That's kind of a lot to be doing
right now.
But there are a lot of cool conferences
to go to and there's cool ones in
Europe that I would like to go to
maybe next year.
But at the moment,
no i have no other plans for for
any of that uh somebody else uh in
our signal chat uh in jordan shared this
here um as if we're doing any kind
of meetup at defcon and no privacy guys
isn't doing anything at defcon but if
anybody does want to meet up um send
me a message because i would love to
say hi to people who watch this stream
or or
are familiar with privacy guides in any
way so i will be there i'll be
there uh six through the ninth so yeah
come say come say hi
I didn't put two and two together that
that was about the DEF CON thing.
I just saw his privacy guides doing any
kind of meetup, and I'm like,
that's kind of out of left field.
Why would we be doing a meetup at
DEF CON?
That makes sense.
Yeah,
there was a bit more context in the
signal group than in the chat shared
there.
Yeah,
I need to add the signal chat to
this computer so I can read it during
the streams.
I'll have that in time for next week.
Alright,
I think that's kind of that for now.
We'll move on to this story posted by
the EFF.
The headline is,
An explosion of surveillance towers is
coming to US borders,
costing over one billion dollars.
A new report from the Government
Accounting Office reveals that the
Department of Homeland Security, DHS,
plans to nearly triple the number of
surveillance towers along U.S.
borders from the current eight hundred
thirty to twenty three hundred by twenty
thirty four.
EFF says here that the IST program
operates autonomous surveillance towers
consisting of
AI-based systems using radar, thermal,
infrared,
and optical systems to track targets over
long distances,
integrated fixed towers which are
optimized for surveilling foot traffic and
vehicles,
and remote video surveillance systems
which can often be found very close to
the border fence in Arizona,
including residential neighborhoods where
cameras are capable of spying on homes on
both sides of the border.
They say that DHS expects to purchase more
long-range autonomous towers and to
upgrade existing towers with autonomous
capabilities.
The one billion dollars comes from the
so-called One Big Beautiful Act,
a massive tax in spending law that
President Trump signed into law in twenty
twenty five.
They point out that the technology isn't
exclusive to U.S.
federal agencies.
It's also deployed by state and local law
enforcement,
and it's also deployed by governments on
the Mexican side.
So yeah, a lot to unpack there.
Nate,
what are you thinking about all that?
Yeah,
I think the big thing that stuck out
to me, I mean, first of all,
I think we kind of wanted to share
this because like, yeah,
that's a lot of surveillance towers.
I'm assuming they're
relatively cheap in the sense that a
billion dollars probably buys quite a few
of them um the the thing that stuck
out i guess we know how many it
buys right what's the twenty three hundred
minus did they say oh yeah eight hundred
thirty fourteen one thousand four hundred
seventy yeah i mean to be fair that
probably includes like install costs and
stuff yeah yeah but um no so the
thing that jumped out at me is um
I have driven cross country multiple times
and driving through El Paso,
like if you're crossing from El Paso to
New Mexico or vice versa,
is a really wild experience because you
can literally look out one window and see
this like beautiful,
I think it's like a university or
something,
literally sitting on a hill and it's huge
and it's gorgeous.
And then you look to the other side
and you can see the,
what do they call them?
The like,
the little sheet metal shanty towns in
Juarez, literally across the...
I'm not kidding.
It is a very surreal experience.
And I know that in towns like that,
where there are towns that literally butt
up against the border,
some people cross back and forth for work,
but a lot of people don't.
And my first thought is like,
there's no way that these cameras won't be
catching people
who are just going about their business
you know it's it's it's designed to
monitor the border right and people
crossing the border but there's no way
it's not going to catch the people when
the towns are literally that close it's
not going to catch the people driving down
the highway walking their dog going to
school going to work on their side of
the border like it's just it's going to
catch everybody and that um that very much
uh was kind of my first thought of
like there's
I guess the privacy concern is how it
catches everybody,
even if they're not crossing the border.
Yeah, and kind of famously,
the border control agency,
they have authority, what is it,
like a hundred miles inland or something
like that?
People talk about that when they're
talking about airports all the time,
but it's true here too.
It's not just like towns that butt up
right against the border, right?
They can potentially install these quite a
ways into the United States,
and it could potentially impact a lot of
people, right?
Yeah,
I think any international pretty much any
international port,
whether that's a border, a seaport,
an airport.
So, yeah,
it's honestly there's not a lot of the
U.S.
that isn't covered when when you expand to
that definition,
because there's a lot of like
international airports in the middle of
the country and stuff like that.
So, yeah,
I don't know if that legal theory that
airports are included has been like tested
in court or anything, but like in theory,
it's possible.
But certainly when we're talking about
like a physical border between countries,
it's definitely true.
So it would apply here.
Yeah.
I think the other thing that jumped out
to me is, you know,
I always want to know that like we
were just we just spent thirty minutes
talking about a story of nuance.
Like there is nuance.
Like obviously we want to protect our
borders.
You know,
there are cartels and there are people
crossing illegally.
And but it's just I don't know, man.
It's it feels like one of those things
where it's like a.
Some military general said something about
killing a fly with a sledgehammer.
It feels like this might be overkill,
I think.
Yeah,
Draken said here that most of the US
population lives within that hundred mile
buffer zone, which I think is true,
actually.
Yeah, I was just fact checking that,
but I believe it is true.
Yeah, it's pretty wild.
Yeah.
Vonnegut said,
sounds like the West Bank where there's
settlements that go right up against
refugee camps.
And honestly, yeah,
it's kind of like that.
It's at least the El Paso thing I'm
thinking of.
It's pretty wild, but... I wonder if I...
I think I don't live in that zone.
I think I'm a hundred miles away from
Canada.
I guess I don't know for sure.
I'm pretty sure we live in that zone.
I know there is a map I found.
I think it was from the ACLU did
a map one time of that hundred mile
zone and it's...
Yeah.
It did not include airports or anything.
It was literally just a hundred miles
around the country.
And it's,
it's pretty shocking how far in it goes.
now I kind of want to go see
if I can find it but I digress
yeah real quick I also want to say
I know I'm going to try not to
be political because we've already been
plenty political enough but I think there
are a lot of people I mean we
just covered that with this last story
where it's like oh it's you know it's
all about the tools it's all about the
encryption and they kind of ignore the
politics but like this was directly funded
by the one big beautiful bill act so
it is kind of important to remember that
there are impacts on this stuff and I
would encourage you to try to
to be politically aware,
at least to the extent that you can
handle.
I know it can be really depressing
sometimes that your mental health does
matter, but this stuff does have impacts.
That's all I'm going,
or all I'm getting at.
John in the chat said that the Great
Lakes are considered part of the border.
Yes, that's true.
I do think Minneapolis is more than a
hundred miles away from
any of the Great Lakes,
if I remember correctly.
So I'm pretty sure I am safe,
but I'd have to find that map.
But definitely if you're in probably
what's around the Great Lakes, Wisconsin,
Michigan.
Ohio, Indiana, New York.
The entire Northeast, basically.
Yeah, because when your state is so small,
there's probably,
I don't know how wide
all of those states are but they might
not even be two hundred miles wide in
some cases and so that's gonna cover the
entire state and some of those are quite
large because you'd have to like if you're
in Vermont or something you know you got
the Canadian border on one side you got
the ocean on the other which is also
a border so that hundred miles goes both
ways so yeah does not surprise me that
two-thirds of Americans live in that zone
i'm trying to find this map i found
an interactive one from arc gis that's
kind of cool oh here we go i
think this is the one i was looking
at from the aclu uh as soon as
it'll load carries in the chat saying that
he interviewed nate wessler who had some
points about that so i guess we can
uh show his podcast a bit go check
out that episode i'll have to listen to
that i have not i have not caught
that one
I am still way, way behind.
I think I'm still in April on my
podcast.
So it's fun, though,
because it's almost like a little low-key
nostalgia.
They'll be like, oh,
this incident happened in the cyber world.
And I'm just like, oh, I remember that.
I will say, yeah,
Vonnegut Rosewater said that they haven't
seen a border patrol officer.
Yeah, I mean,
I don't really see them except at the
airport.
There's probably some on the actual border
of Canada,
but it's not like driving from Arizona to
Mexico.
I've done that once and there were border
checkpoints and stuff along the way.
It's definitely not as much of a thing
up north here between the US and Canada
as it is by Mexico.
That's actually what I was about to say.
I thought you were going to say, yeah,
you don't really see them that often.
And I'm like, no, I've, again,
driven in the south a lot.
I've been through the border checkpoints.
Don't see them often here specifically.
Fair.
Which I think kind of removes people from
the whole question a bit because they
think it's not a big deal.
It's a huge thing down there.
It took forever,
but I finally found a map.
Let me throw this up real quick.
yeah that's that's just the coastal border
or like that's not including airports so i
mean like every major city los angeles new
york um those two are almost like ten
percent of america's uh population right
there miami houston seattle buffalo
chicago so fun times yeah
the entire state of Michigan,
the entire state of Maine.
Oh, man, that sucks.
Almost all of California.
Man, that sucks.
Anyways.
Yeah,
that's a map you can go look at
if you do enough digging, I guess.
I think...
Let's see here.
I'm checking the thread.
We're keeping an eye on that as we
go.
All of Florida.
Yeah.
Delaware.
Yeah,
the forum thread had some comments about
this news story,
but I don't know if there's a question.
Let me see here.
Yeah, I didn't see a question.
Yeah,
just some more comments about Molotov
Head.
On that note, though, again,
we're trying some new stuff.
And one of the things we're going to
try is we're going to check in with
the forum periodically and see what's
going on there.
So our forum is always very, very active.
And this week has been no exception.
Lots of chatter going on there,
lots of cool questions and stuff.
and uh this was a a question that
i had a lot of thoughts on but
i i think you did too because uh
you kind of flagged this one in the
show notes is there space for another
private messaging app um do you want to
uh take that one first yeah let me
let me pull it up here um sure
thing this was basically a thread it was
posted a couple days ago asking about um
whether another privacy-related private
messaging app is needed,
whether this version should build one.
And there's a lot of comments about here.
A lot of people saying...
It's probably not the greatest idea,
which,
and I didn't even realize that you posted
a comment about this,
so you can go into some of the
things you were saying after this.
But it doesn't make a lot of sense,
especially with things like the network
effect, for example,
meaning that everyone has to get on board
with a messenger for it to be useful.
It's why we kind of tend to only
recommend Signal,
because it's a net positive if everyone is
on Signal.
this best all-around messenger instead of
using ones that might be technically
better but are less likely for a lot
of average people to use.
The main thing I saw at the beginning
of this
FormThread,
this person said that the biggest walls
are infrastructure cost if it becomes
popular and getting people to join the
network.
And I just mainly wanted to say that
that second point is like way,
way bigger of a wall than the first
point.
Like massively, massively larger problem.
And so if you're only solving the first
problem,
you're not getting anywhere close to like
building a viable messenger.
And I think a lot of people...
even when presented with perfectly good
options are not going to switch so yeah
unfortunately I just cannot encourage
going down this path I think like I
think signal is a very good messenger
obviously I think if you're very concerned
about centralization I think simplex is
also a good one to look into and
between those it's kind of hard to imagine
why you would use
other ones there are other ones that i'm
interested in um personally i really like
what delta chat is doing but a lot
of people that's a very controversial one
on the forum a lot of people really
really do not like delta chat which is
why we only fully recommend it for
everyone right now it's kind of being
debated but like they're at least doing
interesting things that i'm following
There's obviously Matrix and other ones
that have been around as well.
I think at present we kind of have
too many messengers.
The problem isn't needing more messaging
software,
it's getting people to use messengers that
are more private than Telegram and more
private than WhatsApp and more private
than normal SMS and whatever.
So yeah,
maybe you can talk a bit about this
post that you wrote here.
Yeah,
the messenger thing is one of my pet
peeves in the privacy space.
I feel like, like you said,
we have too many messengers.
And for the record, yeah,
none of them are perfect.
I will give you that.
And I think there's even pros and cons.
Because Signal, for example,
a lot of people are upset that Signal
is centralized.
And that has come back to bite us
before.
Signal has, on very rare occasions,
become overwhelmed and crashed.
And I think that...
I think that's valid,
but Signal also makes the point of, like,
we're centralized because, you know,
there's abandoned Matrix servers and
Mastodon servers that are, like,
ten versions out of date and stuff like
that.
So there's literally pros and cons to
everything.
And, um...
I think my thing,
and I kind of went off on a
big tangent here,
but my thing is I feel like people
are focusing,
and I feel like this original poster said
it really well.
Basically, he was like,
I'm a software engineer,
and I've been diving into messaging apps.
And to my surprise,
it's not that difficult to build a
messaging app.
So apparently that's why there's twenty
billion of them.
But the problem is people are focusing on
messaging apps too much, in my opinion.
And I feel like it's one of those
things that like it's sexy, it's exciting,
it's not hard to do apparently.
But, you know,
there are so many apps and I like
I've listed so many here where like there
are no really good like budgeting apps,
especially for phone.
I know we've got like a new cash
or something.
There's like one calorie counter that
looks like it's from nineteen ninety.
Um, as, as a married person,
I think about things like grocery lists,
like right now,
me and my wife have a shared note
in Bitwarden that we use as a grocery
list,
but we don't have an actual dedicated like
grocery app where you can check things off
as you go.
Um, and for the record, like, yeah,
you can't make it like a one-to-one
replacement with the grocery stores app,
because that one will let you do like,
here's the exact item and here's the row
it's in.
And here's a picture of it.
Like, I,
I'm not expecting it to get that good,
but yeah.
I mentioned, you know,
where's a consent based location tracker
so that when the single ninety five pound
girl goes on a blind date,
she can let her best friend track her
location for the next twenty four hours
for safety,
which I think somebody did actually post
something like that recently.
I meant to bookmark it and keep an
eye on it.
But, you know,
I think later on I mentioned some other
ideas that
What else have we got out there?
I don't know.
Maybe I deleted them all.
I reworked some of these messages, but I,
and another thing,
cause I went and I asked my wife,
I'm like,
I know you have to have opinions on
this.
And she's not even that into privacy as
much as I am, but you know,
it's like,
what do you think she's missing?
And in her opinion,
it's like the appearance of these apps.
Like a lot of these apps are very
bare bones and they look very dated.
And some people don't mind that.
Like personally, I don't mind.
I think old Firefox was fine.
I definitely realized that the new fire or
not Firefox Thunderbird,
the old Thunderbird, like,
the new one definitely looks better,
but I didn't mind the old one.
But then there's some things that look
really, really dated and really outdated.
And, you know,
a lot of people want something that looks
visually appealing,
that captures their attention.
And a lot of things nowadays just don't
look like that.
Like they're designed to be lightweight.
And, you know, like,
I feel like some people are just so
hardcore.
Like if you had one extra line of
code that doesn't need to be there now,
all of a sudden it's bloated and it's
completely unusable,
but
But the looks do really matter for some
people in the user interface.
And I think just making things,
bringing them into the twenty first
century and and making them look good and
making sure they're updated like some
things just never really get updates,
which I mean, granted, you know,
things for like a note taking app probably
doesn't need to be updated that often.
But again,
if we had one that looked modern and
stuff like that, so.
I don't know.
That's kind of what I would focus on
is I think we already have too many
messengers and I would like to see people
dedicate their attention to other things
that look good, that work well,
that have the features we need.
I think we need more options in those
spaces personally.
So yeah,
I kind of went on a couple of
posts about that,
but hopefully I wasn't too rude.
Yeah, I absolutely agree.
I think that kind of sums up the
forum thread.
I'll take a kooky side look at some
comments in the chat again.
Yo, yo, yo, Fred Kong,
welcome to the stream.
Eteru said,
thanks for addressing the comments and
having the debate.
Yeah, absolutely.
We can't spend hours and hours talking
about mulfad, right?
But a lot of these discussions we also
have on the forum pretty often,
and I would say if people have follow-up
questions or want to continue posting
about it, go into the forum,
discuss.privacyguides.net.
It's a great way to discuss all of
this stuff if we can't discuss it all
live here on the show.
But of course,
we're happy to answer any questions that
we get here.
So yeah, keep sending them in, everybody.
Yeah.
Yeah.
I know Anand said there are good apps
out there.
I mean, yeah, I'm sure there are.
And some of them are hard to find,
but they're, they're getting better.
But like one of the examples I use
that I really like is like NT,
you know, NT has that really cute.
It has like the duck logo and it's
like really user-friendly and it looks
good.
And it's got all the features that the
normal people want,
but they're all opt in.
Like you can enable machine learning
that's done on device.
So you can search photos and it's,
you know, if you don't want it,
you just don't turn it on and you
can have the memories that, you know,
on this day, five years ago,
and you can have the,
the like all kinds of cool stuff.
Like I think NT is a really good
example of what I'm looking for,
but I don't know.
I'm sure there are some good apps.
I'm just saying instead of making a
Messenger,
make literally anything else because we
need more other stuff.
Yeah, I think if that's all we got,
we can move on to this next story.
Yeah,
do you mind if we do site updates
now and then go to that story?
I mean, we're in Avarin.
Let's get some stuff to talk about.
Before we talk about yet another border
story we have, let's...
go over some quick updates that of what
we've been working on at privacy guys this
week we finally were able to publish uh
a new site update so we have the
changelog there a lot of things um have
been updated a lot of these have been
published on the site for a while but
they weren't like released to the web
server so they weren't live and now now
they are so everything should be up to
date um we're also working on some stuff
so I'm working on
New recommendations for security keys,
kind of changing that up,
and also recommending cryptocurrency
hardware wallets.
I have literally so many of them on
my desk now, just...
messing with them.
And we're discussing those on the forum.
So there's a lot of forum threads about
that.
If you have opinions about cryptocurrency,
hardware wallets, or security keys,
you can go to GitHub.
There's a pull request open that's a draft
right now.
I think it's just titled hardware keys,
security keys.
And
In that pull request,
there's links to all of the forum threads
because there's like five different forum
threads about different things that are
being added.
So yeah, if you have opinions,
definitely let us know, obviously.
But that is something that will be coming
soon.
In other news,
Fria continues to publish news articles,
privacyguides.org slash news.
Nate has also, of course,
published the weekly data breach roundup.
So there's all sorts of...
stuff out there for you to stay up
to date with.
We try to post some of the biggest
stories that we see,
especially ones that we can't talk about
here on the show,
on that page throughout the week.
So that is a good place to stay
informed in addition to the news category
on our forum.
A couple other things we're discussing.
I think the only other thing we're
considering right now is
a new nested reply format for the form.
There's a sticky post on the form right
now called defaulting new post to use
nested replies.
It's kind of a Reddit like format for
posts.
Right now,
we're definitely not going to be switching
to it.
I'll just tell you because it is kind
of
buggy in some ways.
And there's some improvements that I want
to make that I've shared with the
discourse team to see if they decide to
implement any of them.
However, I mean, assuming it does work,
I think that there's probably some reasons
we might want to use it at least
for some threads in the future.
So if you want to check it out,
see what it will probably look like and
how it works.
And see,
let us know about any feedback you have
definitely check out that thread because
In some ways, I like it a lot,
but I'm a big Reddit user,
and there's a lot of ways that the
current form system is also very nice as
well.
So a lot to think about there.
I think that's kind of it in terms
of site updates and things I'm involved
with.
Nate,
why don't you talk about some of the
video stuff that you and Jordan have been
doing?
yeah unfortunately um jordan got sick this
week uh so they are recovering and uh
they were hoping to have the next video
done by now but uh you know things
happen health is more important obviously
so um once they recover they'll be
wrapping that one up and uh yeah i
mean i've already got one video filmed
after that and just reached out to
somebody today about an interview
which I am excited about.
I, uh, I don't think we,
I don't think anybody has had an interview
quite like this one.
Um, maybe Carrie in the, the like,
like ten years he's been doing firewalls,
no stop dragons.
But, um, I,
I think it's going to be a good
one and I'm excited to share that with
you guys.
But, uh,
that's kind of all we've got going on
right now.
So, um,
Yeah,
all this is made possible by our
supporters.
So if you want to help support our
work,
you can sign up for a membership or
donate at privacyguides.org slash donate.
We also still do have the merch shop
that Jonah mentioned earlier,
shop.privacyguides.org.
Privacy Guides is a nonprofit which
researches and shares privacy-related
information and facilitates a community on
our forum and matrix where people can ask
questions and get advice about staying
private online and preserving their
digital identity.
rights.
Before we jump into that, actually,
we did get a couple of questions.
I don't want to say off topic.
We got a question in the forum that
is not related to any of the stories
we've covered so far.
Khaled says,
what are some good ways to spread
disinformation about yourself?
I've heard this talked about in the past
to protect against data brokers and other
places,
but don't know what's the best way.
Do you have any thoughts on that one?
I use a little bit of disinformation.
I don't know if you do.
This is a good question.
Good ways to spread it is hard because
I mean like whenever possible it's good to
use fake information when you can or to
use like email aliases and stuff like that
so things can't be tied together and so
like if data does get released and like
data breaches or whatever it won't be
accurate information but like
intentionally sharing
False information.
I have definitely heard people talking
about this.
I don't really do this myself,
so maybe you can talk a bit more
about it.
But I've always leaned towards more just
kind of trying to eliminate as much as
possible from being out there,
whether that's through data broker removal
services or just putting out minimal
information out there in the first place
or what have you.
So I guess the answer is I don't
really know the best way to go about
this,
but it is an interesting thing to think
about.
Yeah,
I don't know if I know the best
way because I'm kind of with you.
I focus more on removing the data that's
out there.
But I will say that one of the
things I do is I am really militant
about using a PO box.
And that has worked so well that I
know for a fact that in the past,
LexisNexis has thought that was my actual
address,
which is funny because I'm not even going
that hard to like, oh,
I don't put my real name on my
lease or whatever and somehow still fooled
the data brokers.
Yeah.
Drake in here said best way is to
lie about your birthday city where you
live, et cetera.
Yeah.
I mean, little things like that.
Like if I, if I buy anything,
that's not going to a PO box,
I try to use like a,
like a hotel downtown or library or
something is my mailing address.
Um,
LinkedIn, I know I've said this before.
I, when I got into privacy,
there was a specific address that kept
showing up on all these people's search
sites that was like,
ten years out of date.
And I could not figure out where it
was coming from until I realized I had
a LinkedIn account I had never deleted and
never really used.
And that's where it was coming from.
So, uh, yeah,
sign up for LinkedIn and put the wrong
information on there and it'll get out in
about ten minutes.
Um, I'm trying to think what else.
Uh,
I've heard that rewards cards,
like signing up for – it kind of
depends on what you want to do.
Like some people – this mostly comes from
Michael Basil,
but he's recommended like get magazines
shipped to your house in the wrong name.
Some post office people are kind of
militant about not delivering magazines.
mail that's not like if they know that
name doesn't go to that address they won't
deliver it because they think it's wrong
um so some people have had that experience
you could sign up for uh again like
rewards cards at the grocery store using
the wrong name but your actual phone
number like things like that um
I don't know.
Yeah.
I think it's kind of a subtle mix
of things of just kind of figuring out
where, you know,
does this person need this information?
And if they don't,
what information can I give them instead?
Especially if it's required,
like a lot of the time, you know,
if you go to buy something online,
sometimes it won't say, you know,
it won't like the phone number will be
optional,
but then other times it will require a
phone number.
And at that point it's like, okay,
you're never going to call me.
So what fake phone number can I put
there?
You know, things like that,
I think are kind of how I think
about it.
Yeah, I don't know.
I think that's kind of all I got
on that one.
It's more of an art than a science,
I think,
and just kind of looking for those
opportunities.
Sweet.
Well, let's move on.
Why don't you cover this next story also
from EFF here?
Yeah.
So this one is, um,
a little bit disappointing, unfortunately.
And, uh,
it says that the fourth circuit says
border agents can search your phone by
hand.
No suspicion required.
So, um,
for those who don't know here in the
U S um,
borders or searches of your phone are
really kind of a legal gray area that
are, uh, kind of, it's kind of patchwork,
I guess I would say it's very, um,
Like at this place, this rule applies,
but at this place, this rule applies.
And here you need a warrant,
but here you don't, blah, blah, blah.
And it's very confusing.
And so basically there was a case called
U.S.
versus Belmont Cardozo,
who unfortunately does not seem like he
was a cool guy.
Seems like he had CSAM on his phone,
according to some stuff later down here.
But either way,
they tried to argue as a defense that
–
The police should have gotten a warrant to
look through his phone,
and this made it up to the circuit
court, which I forget how circuits work.
I think a circuit –
includes several states like it's kind of
like a regional court i think if i
remember correctly um okay but yeah so the
the uh this went up to the fourth
circuit who decided that border agents are
allowed to search your phone without a
warrant or really any reason as long as
it's a quick manual search so again
there's there's um
I don't want to get too bogged down
in the weeds of context here,
but basically there's different reasons
that people can perform searches.
Cops, I should say, can perform searches.
There is going and getting a warrant.
But obviously, if we assume good faith,
there are still times where it makes sense
that they can't get a warrant.
If they're at the airport and somebody's
acting real shady and their suitcase is
oversized or whatever,
they've got some reason.
Something suspicious is going on here.
Then, you know,
if they can prove if this ends up
going to court or whatever and they can
prove to the judge like, no,
here's why I flagged this guy and here's
why I thought this was suspicious,
then that evidence is allowed in court.
And there are certain things,
according to the EFF, that at the border,
you don't even need a reason.
You don't even need to say like this
is suspicious.
It's just you can do the search.
And as an example,
they gave like your luggage,
even if there's nothing suspicious,
even if there's there's no evidence of
wrongdoing, the cops can be like,
I'm going to search your luggage.
which they do even on domestic flights.
I can tell you that from experience.
And so basically the court has said cops
are allowed to do a search for any
reason, without a warrant,
without any suspicion,
without any probable cause,
as long as it's a quick manual search.
And where did it go here?
So they said that it has to be
a person, not a machine.
They said that the breadth of the search
depends on the officer's time and energy.
They, uh,
while forensic searches are comprehensive,
uh,
manual searches only reveal what a user
can typically access while forensic
searches can uncover deleted files,
cash fragments, metadata, and more.
And manual searches are subject to an
officer's fading memory or imperfect notes
while forensic searches create a permanent
copy.
So basically this is not permission for
them to hook your phone up and run
celebrate and copy your data.
It's, you know,
the cop saying at the border, like,
let me see your phone,
unlock your phone and looking through your
phone.
Okay.
And EFF argues,
and I think most of us watching would
agree,
that that's still not really great because
your phone is so much more sensitive than
like even your luggage.
Like, okay, sure,
your luggage might have some stuff you
don't necessarily want everybody seeing,
but your phone has your messages,
your photos, your banking apps, you know,
Grindr, like religious apps,
like whatever it is.
Like your phone has so much more data
than your luggage would.
And it's so much easier,
at least in my opinion,
it is so much easier when you're packing
your luggage to... I mean,
even as a real example,
when you're packing your luggage,
you can choose to leave out things that
you don't want to put in there,
but you might still have medication
reminders on your phone or a doctor's app
or something like that.
And it's just... Yeah.
The EFF was basically like,
this is really not the same.
And it's kind of disappointing that
there's no real actual...
Anything.
Again, they don't even need suspicion.
They can just go ahead and say,
here's all the –
Yeah.
I don't know.
I'm tripping over my words,
but I think I've kind of made my
point there.
It's really disappointing, unfortunately.
I will say at the end here,
they did point out that in this particular
case, the search only lasted two minutes,
which means that there's a possibility
that even if it is a manual search,
if it goes on longer,
it could require more time.
a more in-depth search.
So like if this guy took the phone
and just opened photos real quick and saw
CSAM, then it's like, okay,
you're under arrest.
But if he's like sitting there with your
phone for ten minutes,
like reading every single message and
checking your browser history, it's like,
come on, man.
You got to be a little more reasonable.
So I think that's probably the good thing.
But I don't know.
I don't understand how a time limit would
work, but I don't know.
I'd have to look more into that.
I wanted to go back to the reason
that you said Belmont Cardozo was
arrested,
because I think it's an important point to
remember that I think people need to
realize when we talk about cases like
this.
Obviously,
he was arrested in this case for having
CSAM,
which led to his arrest in criminal
prosecution.
And I think...
When we see court cases like this,
what you have to remember is that the
things that are happening in this court
case are almost certainly things that the
government does all the time.
Like,
this isn't the first time that they've
done it and now they're trying it in
court.
This happens and...
If it gets challenged in court,
which a lot of people probably won't even
do in the first place,
but if it does, you know,
if it's not as controversial as this,
where he has CSAM on his phone,
the US government is just going to drop
it because they want these court cases to
create precedent for them to do this sort
of thing in the future.
And so they have to find the most
extreme possible case that they can find
because they want to use, you know,
illegitimate reasons, I think,
to kind of justify this instead of looking
at the letter of the law as it
is right now and realizing that this sort
of search is illegal under the
Constitution,
but they want people to overlook that
because of the nature of the crime in
this case.
I just think that's important for people
to remember because a lot of people do
get outraged about this and they'll see
stories like this and they will say like,
well, yeah,
we want to catch people like that.
But how many, you know,
criminals is the government letting go
before we can get to a court case
like this?
And also,
how many times has the government done
this before it reached any court at all
and before it was challenged?
Probably quite a bit.
They're just invading people's privacy
illegally and often it doesn't
get policed at all so yeah I think
I just wanted to remind people that keep
it in mind when you read stories like
this because I think people get too caught
up in what the crime was instead of
what the government is doing and remember
that we kind of have a duty to
police the police officers and make sure
that this sort of thing isn't happening
and isn't legal yeah because that's my my
main point
I don't know if there's anything else I
wanted to add.
You kind of covered a lot.
Sorry.
I mean,
it's kind of a straightforward story,
but it's I also wanted to include it
because like I said,
this
you know the the rules surrounding phone
searches it feels like they're changing by
the day and it's highly contextual and
dependent on things and so it's the more
information we can get about how to to
or like what's going on what the current
landscape is is helpful and also like both
this story and the previous story about
the border we just did it's another thing
sort of similar to what i was saying
about the government where like the
government is doing these things on the
border specifically
because they know that people get really
mad about border-related issues and will
support things that they otherwise
wouldn't support in any other context.
So that's why I think that's why we
see a lot of very extreme stories like
ones dealing with CSIM and that's why I
think we talk about a lot of border
stories like a disproportionate amount on
this show because that is it kind of
seems like in my opinion where the
government wants to test out a lot of
these privacy invasive things first before
we see them
get that out on the streets everywhere in
America.
I think that, I mean,
really like the stuff we were talking
about on the border in terms of
surveillance towers,
that's the sort of thing that they wanted
to test on the border.
And now we see flock cameras on every
street corner in America.
It's just, it's kind of a pared down
cheaper version of all of that
surveillance stuff but it's more
ubiquitous and it's not about protecting
the border it's about surveilling american
citizens um and everywhere they go and
what they're doing so yeah you just gotta
keep all of that in mind it's all
like this has more impact than just like
the specific thing that we're looking at
right now you um you may have heard
of this but it does not get as
much attention as his other phrase and
shitification but uh have you heard of
corey doctor's shitty tech adoption curve
No, I have not heard that.
It's basically what you're arguing.
Do you remember that that winter soldier
drone that Baltimore tried to roll out
like sometime shortly after lockdown,
I think?
Yeah, I believe so.
Yeah.
For those who maybe missed that story,
basically Baltimore,
the city of Baltimore,
I think it was Baltimore,
wanted to fly a surveillance drone like
twenty four seven in the sky that would
just record all the time.
And, you know,
civil rights groups fought back and they
were like, this is surveillance.
This is illegal.
This is a violation of the Fourth
Amendment.
And real quick, I thought it was funny.
They tried to argue.
It's like, well,
it's not really twenty four seven
surveillance because we still have to land
it for a couple hours a night to
refill.
it and stuff so technically it doesn't get
and thankfully the government was like no
this is illegal you can't do this so
they weren't allowed to do it but um
somebody pointed out that that technology
began in afghanistan like it was literally
a modified version of the predator drones
the same surveillance drone we fly around
in war zones and uh cory doctorow coined
this term called the shitty tech adoption
curve which is exactly what you're saying
is like they roll it out in these
situations where unfortunately people
aren't really paying attention in like
wars and prisons and places like that
where it's it's easier for people to
ignore it.
And then they kind of use that as
a testing ground to hone the technology
before rolling it out to surveil the rest
of us.
And unfortunately, ever since I read that,
I see it everywhere.
Corey was very, very right about that.
But yeah,
that's that's basically what you were
describing.
So I know I can never have an
original thought.
Corey's had all of this.
Corey has all of the thoughts.
He is so smart.
I mean, yeah.
None of us can compete with him.
I think before we dive into the next
story,
I think we had another forum post we
wanted to look at,
and I think this one actually came from
you.
about the FCC comment yeah trying to pull
it up again yeah I did just want
to highlight this uh really quick the we
we I think we did you talk about
it on the show I don't think I
was on but I'm sure in one episode
it came up um I think we gave
it a brief mention because this does ring
a bell
The FCC is proposing a plan to require
government ID, your physical address,
and an alternative phone number for every
phone line in the US.
So yeah,
if you sign up for a new phone
line,
you're not going to be able to get
it as anonymously as you currently can.
We've talked about a number of ways to
get phone lines anonymously here on the
channel, and I'm not really sure how...
any of those methods would really survive
a rule change like this.
The deadline to comment on these proposals
is July twenty-fifth,
and so if you are an American,
I think it is really important to submit
a comment to the FCC about this because
they will take this into account in these
hearings,
especially genuine
Personal accounts are going to be very
compelling in terms of pushing back
against this.
Don't just submit an AI-generated comment.
But you can go to this form post
that I've stickied it on the form,
so you should be able to find it
because I have a link to where you
can file an express comment.
And the two docket numbers that you're
going to enter in the top field of
that,
you're going to enter
And just submit a comment for both of
those.
You can do both of them on the
same form, so it's very easy to do.
And I think it's very important that this
sort of thing doesn't get passed,
so hopefully you can speak out about it.
There are some comments in this
forum thread that we could address here.
Expert-FortyEightSeventy asked if KYC
would help with spam.
And the answer is no.
None of this is going to help with
spam in any way.
Because this isn't the reason that spam
calls exist.
Spam calls currently mainly exist due to
technical failings of these telecom
providers and there are systems in place
or they could make systems that would
prevent
Pretty much all of this stuff from
happening,
they just choose not to do it for
a variety of reasons.
But there are different authentication
protocols,
and there are technical ways that they
could just prevent cell phone number
spoofing, which would be a huge...
improvement um that that they're not doing
and it's not clear to me uh how
kyc is going to help this because all
of those exploits and flaws in the current
telecom system will still exist for
spammers to take advantage of however this
is going to make it much much harder
for regular people to get phone lines
which are pretty much mandatory given how
many services require a phone number
nowadays so yeah this is this is
definitely not the solution um
All of the expert opinions that I've seen
on this and all of the people in
the telecom space that I've talked to have
no idea how this is going to improve
the spam situation either,
because it's not.
But yeah.
And also, as Kerry just pointed out,
it doesn't prevent offshore phone
accounts.
Yeah.
Like, this really...
I can't even imagine how they are
justifying that this could solve the
problem that they're trying to address
because there are so many ways for all
of that stuff to continue while this
policy is in place to really take away
privacy from Americans.
So just wanted to put that out there.
Check out the forum thread.
I'll leave it in the...
I can leave it in the chat here
if people want to check it out.
But... It's also in the newsletter.
Oh, it'll be in the newsletter.
It's on the site.
You can go to the forum,
discuss.privacyguys.net.
It'll be at the top.
So I think that'll be... Yeah.
Consider it because...
Public opposition and especially like
grassroots opposition does actually have
an impact on these political decisions.
We've talked about that before,
like in the EU with chat control and
like pushing back against that.
And it's the same here where we got
to nip this in the bud before it
happens, because if it happens,
it's going to be so hard to undo
it.
Yeah, I haven't clicked on this link,
but I said the same thing in the
forum that, you know,
that Kerry kind of hinted at, which is,
you know,
a lot of spam callers come from outside
the US.
They spoof US phone numbers.
And somebody replied to me and said that
they quoted this link here.
The commission further proposes to require
voice service providers to implement
measures to ensure that consumers know
which calls originate from outside the US
and to prohibit spoofing of US telephone
numbers for calls that originate from
outside the US.
Again, I didn't click the full link,
but I'm assuming it doesn't say how
they're supposed to do that.
And to me,
this strikes me as one of those things
that it's like,
do you think they don't want to do
that?
Like,
do you think they're not already trying?
Like everyone hates spam.
There's – they already don't want these
spam calls.
Like, I don't know.
It sounds to me like one of those
things where it's just the politicians
that don't understand how to check their
email on their iPhone are telling us just
nerd harder and find a solution.
And it's like this just – yeah,
I don't see how this is supposed to
actually solve anything other than just
creating a bunch of, like,
legal liability that's just going to make
everything worse.
And –
I think the first time we covered this,
we mentioned this is going to kill
whistleblowers, journalists,
which I'm sure the current political
landscape would be thrilled about all
that, domestic abuse survivors.
All these kind of people that have
perfectly legitimate cases for needing a
burner phone are just up a creek now,
and we're not actually going to fix
everything.
We're just going to make everything worse
for everybody.
So yeah,
I need to leave a comment on this
too.
Before we move on to the next story,
I want to grab another question in the
chat here.
VPN question.
If I change my VPN server regularly a
few times a day or more often,
does it strengthen my privacy or not
significantly?
Thanks.
This is really going to depend on who
you want privacy from,
but in general I wouldn't recommend doing
this.
It could possibly make sense to do this
if you're visiting different websites and
you're using one VPN on one website and
a different VPN with a different one,
but if you're just rotating VPNs
constantly and using the same sites,
this is probably going to have little
impact and this
will make you less private on your local
network, for example,
because it's just more fingerprintable.
But when you're doing things that are kind
of out of the norm,
especially manual things and things that
aren't built-in features,
you're pretty much just standing out from
other users who are not doing that.
And so typically it is best for privacy
As a general rule,
to not take things into your own hands
and implement additional security measures
if it hasn't been fully proven that this
is going to improve your privacy in some
way.
I think that's just a good philosophy in
general, which is the less you can do,
the better.
And this sounds like a lot of extra
work for no proven gains.
So yeah, I wouldn't...
I wouldn't do this probably,
but I think that answers that.
Yeah, I just want to add on that,
in general,
I think VPNs are really over-exaggerated
for privacy.
I think somebody commented this during the
Mulvad story too.
And they have a place.
I use a VPN.
I'm sure Jonah does.
Most people do use VPNs because they're
helpful.
But VPNs really only do two things.
They change your IP address.
and aside from okay three things because
they also do the whole encrypted
connection thing if you use i mean most
modern vpns nowadays come with dns based
blockers that block ads and trackers and
malware but um you know the dns based
things they're only going to block known
things right and they're only going to
block dns base so like if you're if
your ads and trackers are being served
from the same place as the website itself
they can't block that without breaking the
website
if it's a, you know,
a new web address, a new domain,
they can't block that cause they don't
know about it yet.
And, um,
As far as the IP address thing,
I'm firmly convinced we don't actually
know how common fingerprinting is because
companies don't really rush to tell the
world.
And those who do are marketing companies,
so they're probably over-exaggerating it
anyways.
But I'm willing to bet that fingerprinting
is extremely common nowadays.
And in the context of fingerprinting,
your IP address is such a small part
of your fingerprint because a lot of
residential places rotate IP addresses
anyways.
And if you're going from your phone to
your computer to the library to the coffee
shop to work,
IP address is just not a very efficient
way to track people.
So VPNs, I'm not anti-VPN,
but I don't think in the context of
privacy, like I'm with Jonah,
I think rotating regularly would just be
so much overkill for so little gain.
And I think you'd be better off just
focusing on
using a good privacy-respecting browser,
using things like uBlock Origin that are
not blocking purely based off block lists,
things like that,
I think are going to get you way,
way more privacy than rotating VPNs.
All righty.
On that note,
I think we're going to move on to
our next story about OpenAI.
This is kind of a big story this
week,
the whole OpenAI and Hugging Face debacle.
Yeah, this is reported by Wired.
OpenAI models escaped containment and
hacked Hugging Face.
Describing the incident as unprecedented,
OpenAI said its AI models broke out of
a sealed testing environment last week and
hacked into Hugging Face's production
system to steal the answers to a test
they were being graded on.
The models,
the publicly available GPT-Five.
Six sole and an unreleased reported me
reportedly more capable one,
were being evaluated on their offensive
hacking skills with the safeguards that
normally block high risk cyber activity
switched off.
They go on to say,
according to OpenAI and Hugging Face,
the models escaped through a package
registry cache proxy software that allows
developers to install outside code without
connecting to the internet.
The proxy was the only component in
OpenAI's isolated testing environment
permitted to reach the outside world.
In normal use,
that reach extends only to public code
repositories.
Rather than stay contained in the sandbox,
the models exploited a zero-day
vulnerability to gain access to the open
internet as they hyper-focused on finding
a solution for the AI cybersecurity
benchmark known as Exploit Gym.
Such experiments involve prompting that
pressures the models to find solutions,
essentially egging them on.
They say that the flaw that the models
exploited was previously unknown,
as would be implied because it's a
zero-day exploit,
but flaws in this kind of software are
not unusual.
Companies have been patching serious
vulnerabilities in artifact repositories
for a decade.
A bug disclosed in twenty twenty four let
anyone who could reach the server ask for
a file by URL and get it,
which would include configuration files,
passwords,
access tokens without logging in.
Others have let attackers take control of
the server itself.
So a lot to unpack there.
I kind of take a little issue with
a lot of these stories about AI and
security and like their capabilities,
because honestly,
like when Anthropix Claude Fable was
banned by the US government,
we talked about that a few weeks ago
when it happened.
And I kind of had a similar opinion
then, which is that like,
all these stories do is really boost the
impression that like these models are
extremely capable and they're totally
worth paying a lot of money for because
look what look what they can do right
um but at the same time uh it
is it is true that they're finding like
zero-day vulnerabilities and they're
discovering
new vulnerabilities that didn't previously
exist,
and there obviously are cybersecurity
implications there.
Yeah, Nate,
I could talk a bit more about this,
but do you have any thoughts,
or was there anything you saw in the
article that I didn't talk about?
Not too many.
I think your take is definitely accurate
that this is kind of a little bit
marketing for these companies.
Like, oh,
look how super powerful our AI model is.
But it does also kind of point out
that...
I think it's one of those,
it's kind of like when Kerry guessed it
on the podcast and he said, like,
you know, this stuff is coming.
Like, regardless of how you feel about AI,
I think there are some impacts here that
are happening regardless of whether you
use it or not.
Because, you know,
I think when we think about agentic AI,
at least me,
I usually think of stories about like, oh,
some morons AI agent went and erased their
entire inbox.
And it's just like, yeah,
what idiot is using these things to begin
with?
But now we're seeing it's like it can
go beyond that, you know,
and it's unfortunate that it's one of
those things where I think it's privacy
people.
We all kind of relate to, you know,
people will be like, well,
if you don't like Google,
just don't use it.
It's like Google Analytics is on seventy
percent of websites.
How am I supposed to just not use
that?
Like, come on, man.
And it's kind of the same thing where
like now they're starting to use these
agents for like pen testing and hacking.
And it's like,
how am I just supposed to not use
it when this is impacting me?
And
Another thing that occurred to me was we
covered a story a couple episodes ago.
I think I forgot to go –
find that episode.
But, um, we,
we covered a story a while back about
how, uh, with the mythos thing,
I think it may have been,
may have been the episode Carrie was on
where, uh, you know,
there were unauthorized users that were
somehow gaining access to mythos.
And I don't think they ever resolved how
that was happening,
whether it was like some kind of insider
giving them access or something,
but it kind of points out that it's
really delusional with all these tech
companies.
You know, it's like, Oh,
only the good guys are going to have
this.
We're only going to sell it to good
guys,
which is definitely what clear view AI
said right before selling it to
authoritarian regimes.
But it's also like,
even if they are acting in good faith,
you
Clearly,
these people are finding access somehow.
I think the last thing I wrote down
here is towards the end of the article,
They talked about how this is really an
infrastructure problem.
Let me see if I can go find
it.
In recent months,
top AI companies have been raising
concerns about the expanding cybersecurity
capabilities of upcoming frontier models
as the platforms increase in both
expertise, creativity,
and agentic autonomous operation.
But researchers emphasize that this is all
the more reason the fundamentals should
still apply.
Where was it?
It was like the last quote that he
made.
I wish,
this is a veteran security engineer and
researcher, Niels Provost.
He says,
I wish the Frontier Lab spent as much
time on teaching the models to write
secure infrastructure as they're spending
on exploiting vulnerabilities.
And it's just kind of showing that whole
like move fast and break things mentality
is still here.
You know,
they're still out there just trying to
make money,
trying to like push out this newest,
shiniest model.
Like you were saying, it's, you know,
like how scary our model is.
And, you know, yeah,
it's just it's unfortunate that we do not
ever seem to learn our lesson.
And we just keep repeating these mistakes.
Well,
and that quote is especially relevant here
because
When I'm reading this, I'm wondering,
how was this vulnerability found?
What was the vulnerability?
And was there a more standard
configuration for this proxy server that
would have prevented them from doing this?
Maybe if they had configured it
differently when they installed it?
Because I would have to imagine OpenAI
probably is just asking AI
to set up this secure environment and to
set up this proxy server.
Like, I'm sure they use AI super heavily.
And so the idea that like, oh,
these models should be taught more about
like doing things securely in the first
place rather than spending so much time
like exploiting vulnerabilities,
which again,
I think is mainly a marketing thing.
It's much more, I guess,
clickbaity to say like OpenAI hacked this
thing versus OpenAI
made security improvements to this open
source software or something like that.
So unfortunately,
I think like a lot of it is
very
attention-driven.
This sort of story creates a lot of
attention for OpenAI.
Obviously, we're talking about it now,
so it's working.
And that attention is the main thing that
these companies need right now,
just to survive.
They're obviously not making money,
so they have to exist on hype and
vibes alone until, in theory,
they can make money.
I don't know if they ever will,
but that's their hope.
So yeah, I mean,
I don't know if I have much more
to say beyond that.
The AI stuff is just nuts to me.
Yeah,
I don't really know if I have any
more to add either.
I agree with you.
It does make me wonder what you were
saying about like,
did they have the AI configure this?
It's yeah.
I mean, if,
if you have the AI spit out code,
you're just going to skim it.
You're not going to sit there and audit
every single line of code.
You're just going to like, yeah,
it looks good.
Let's run it.
And as opposed to like,
if a human wrote the code, I mean,
maybe the human would just by instinct,
write it in a much more secure way,
but since it looks mostly right,
they don't catch it when the AI does
it.
And I don't know.
Yeah,
I just can't imagine like anyone at OpenAI
is really just doing things on their own
anymore.
Like that would be unbelievable to me.
I don't know, man.
They're probably not even like, yeah,
hopefully they're not.
But I would imagine they have not taken
that advice to heart.
Yeah, who knows?
We had one more forum update that we
were going to cover before jumping into
our final story about Apple.
this one was pretty close to my heart.
Is there a point in supporting projects?
I don't know whose turn it is.
Is this my turn?
You can take it.
Do you want to take this one?
Okay.
So yeah,
this person here says that this is
something that's been on their mind for a
little bit.
And basically,
is there a point in supporting small
projects?
And they talked about Session,
for example.
And they say that, you know,
they want to support projects and they're
happy that they exist,
but at the same time,
does it actually matter?
You know,
if you give five dollars a month,
does that help?
And, you know,
they might still go bankrupt or disappear.
How do I know they won't go into
financial trouble?
So on and so forth.
So.
Here's here's my take based on my
experiences
With the new oil,
with surveillance reports,
and a little bit here at Privacy Guides.
Privacy Guides is a little bit different
than what I was doing at those
organizations.
So the first thing that I want to
reiterate that we always say is your
safety comes first.
We don't want you to donate if you're
going to lose your house,
if you're not going to have money for
food or for the baby formula or whatever.
Definitely take care of yourself first.
But if you have...
disposable income,
I think I actually wrote a big,
long response here.
And I mentioned that at New Oil and
Surveillance Report,
depending on when you measure and how,
only one to five percent of people donated
money.
And I've said many,
many times in the past that if half
of the people who visited the new oil
donated a dollar,
I could have been doing privacy full time
years ago.
And so I think a lot of the
time, like, yeah,
if you look at it as an individual,
like donating five dollars, ten dollars,
even one dollar as an individual, yeah,
is really not going to do anything.
But it becomes – it's almost like a
– this is a problem we have with
voting, right,
where a lot of people are like, oh,
my vote doesn't count, and therefore,
forty percent of America doesn't vote.
And it's like those millions of votes
could have potentially changed the outcome
of the election, either – any election,
either way.
And so it's kind of the same issue
in privacy,
where it's like if everybody goes, yeah,
well, my five dollars,
all I have is a dollar.
That doesn't help.
Yes,
but if a thousand people give a dollar
a month –
That's a thousand dollars.
Like it, it adds up.
And so, um, I would encourage people and,
you know, obviously I have incentive,
but I would encourage people that, yeah,
if you do have money donate and,
and there are so many projects out there
for the record,
I know it's kind of impossible to donate
to all of them.
So.
I would recommend starting with the ones
that, like, if this went away tomorrow,
could you live without it?
Like, I use Signal religiously.
I use, well, now I use Fresh Tomato,
but I used to use DDWRT and, like,
NextCloud.
And, like,
these are all things that if they went
away tomorrow, like, yeah,
I'd be kind of screwed.
Yeah.
Things like – or another thing that's
really common is rotating.
This month I'm going to give five dollars
to Signal.
Next month I'm going to give five dollars
to Fresh Tomato.
Next month I'm going to give five dollars
to Cubes, like that kind of thing.
So I don't know.
I just – yeah,
this is really near and dear to my
heart.
It definitely – if you do have a
disposable income,
I strongly encourage people to donate
because it does help.
It adds up.
Even a dollar.
Like I said,
if a thousand people give a dollar,
that's a thousand dollars a month.
I don't know if I can add much
more to that without repeating myself.
Yeah.
It's hard to say.
I think people are bummed when they
support projects that eventually do go
under or can't continue running.
You need a lot of money to do
all of these things,
and some projects tend to get all of
it, and then most of them don't.
But I think the first reply on this
forum thread...
is a pretty good point,
which is they basically said there's a
fairly strong chance that if no one
donates,
then there's going to be fewer projects
available overall.
I guess you're sort of betting on which
ones are going to succeed,
and sometimes you're going to lose those
bets.
But if you can support all of these
projects, the more you do,
the more likely it is that one of
them will
make a big difference.
And I think if nobody is supporting the
small, tiny projects,
then there will never be any new ones,
because it'll just be too hard to get
it off the ground.
I can definitely tell you all for sure
that probably not as many people donate to
PrivacyGuides as you would think,
so we can always use donations as well,
but there's a ton of projects to support.
can't remember if we do this currently i
should look i feel like yeah for for
a lot of our um recommendations on our
site if they have like a donation option
we we have a button to hit where
you that'll link like directly to their
contribution page so you can find like
where to support all the projects that you
use if you search for the tool on
our site so that could be something to
to look into but i definitely would
recommend supporting anything that you use
and just think of it like you know
if you're using it now and you like
it um and you can afford it you
should you should pay for it i think
yeah if it goes away it's a it's
a and if it disappears it's a shame
but then you can just move on to
supporting something else um and hopefully
uh it doesn't go away
I think it's also one thing I wrote
in my comment here is, um, again, it,
this should be disposable income.
Like this should be money that is not
going to, you know,
keep your kid out of college or something.
But, and the example I use is like,
I am, I'm a sugar addict.
I actually,
I finished a Mountain Dew right before we
started recording.
Um, you know, I, I love sugar.
I'm constantly buying like fraps and sodas
and, and, um, all kinds of sugary stuff.
And, um,
Those things cost, you know, two dollars,
five dollars,
depending on what I get and where I'm
at.
And they last me, what,
a couple hours tops.
And then even the high of the sugar
rush eventually goes or not sugar rush.
But, you know,
the dopamine hit of the sugar eventually
goes away, too.
And so it's one of those things where
it's like, yeah,
I'm spending five dollars and it's going
to last me half a day tops.
the reward of that,
whatever word I'm looking for.
And whereas something like this,
it's kind of one of those things where
it's like,
if I knew for sure that skipping one
coffee a month would keep Signal around,
would I do it?
Yeah, absolutely.
And so to me,
it's kind of that same argument.
It's like trying to reframe that attitude
of like,
I can afford to go without one soda
to help this project stay around, I think.
Yeah.
You know, uh,
Carrie said it to the diffusion of
responsibility.
A lot of people assume that other people
are supporting, uh, like you said, it's,
you know, I, I was surprised real quick.
One, one more quick story.
I went to the cubes.
Uh,
what is it like open collective one time
and their annual budget is like,
and I'm like, hold on, what cubes?
There's like seven developers and
literally not a single one of them could
afford to do this full time.
And they put it out an amazing operating
system.
Like they're probably making a lot less
than you think.
So
Yeah,
I was going to point out that exact
same comment from Carrie.
Because that is the case when I talk
to people about privacy guides as well.
Mainly people who are thinking about
donating and they're asking about how
everything works currently.
And I think there's generally surprise
about how much we're getting because they
assume that we would be getting a lot
more, which I think...
is absolutely just a thing.
I didn't know that it had a name,
Diffusion of Responsibility Phenomenon.
So now I know this, thanks to Carrie.
But I think that's absolutely a thing with
a lot of these projects.
It's very easy to assume that somebody
else is supporting them,
so you don't have to.
It's exactly the same as like,
This is classic,
nine-one-one first responder advice,
like you have to be like,
don't just say like,
somebody call nine-one-one,
you have to say like, you,
pink shirt right there,
call nine-one-one right now if you're in
an emergency situation,
because otherwise nobody will do it,
because everyone,
nobody wants to do things.
So I'm telling all of you right now,
you watching this, donate to something.
You with the face.
Yeah.
One more example.
If you go to NT.com slash open,
they share how many customers they have
and how much revenue they only make like
a million dollars a year,
which for a company providing that kind of
infrastructure, it just,
that blew my mind when I read that.
I'm like, that's it.
Like I've historically always worked for
companies that made way more than that.
And they were still small companies.
Like I can't believe NT is running on
such a small budget, but.
I mean,
now you don't work for a company making
more than that.
Yes, that's why I said historically.
This might be the first company I've ever
worked for that makes less than a million
dollars a year.
But just to point out the example, yeah,
like what we were saying is like people
think that they make a lot more money
than they do.
And when I saw that from Ante,
I was like, really?
That's it?
Like, yeah, it's wild.
They're doing a lot for how little they're
making, but...
Anyways, that's all I had on that one.
Terracotta Pie just said, Light,
thanks for the response.
You're certainly welcome.
Again, ask questions, everyone,
in the chat because we will try and
get to them.
In the meantime,
we're going to talk about Apple and how
Apple has finally fixed...
a vulnerability in hide my email after
being shamed by four or four media,
because sometimes that is what it takes.
So we did cover this.
I actually went and looked it up.
We covered this on episode sixty when
Calix OS came back.
It was our second story, it looks like.
So if you want to hear the original
coverage,
you can go back and check that out.
But long story short,
Apple says it is fixed to vulnerability in
their Hide My Email feature,
which let essentially anyone figure out a
user's real email address,
which was supposed to be protected by the
feature.
It's literally your one job.
So they knew about it for about a
year.
And for those who don't know,
hide my email is exactly what it sounds
like.
It's a paid feature and it lets you
create a new masked email address when you
sign up for something that still forwards
to your main email address.
So that way,
if it gets caught up with spam,
you can just turn it off or whatever
and it won't
you won't keep getting spam or they point
out here, uh,
hackers can also have a harder time
cross-referencing your various accounts.
So Tyler Murphy,
co-founder of easy opt-outs,
which is a service we do recommend.
It is a service that I personally have
been using for years and I love it.
Um,
he discovered this vulnerability and tried
to report it to Apple.
Uh,
Apple,
I think if I remember the original story,
Apple started to reply and, you know,
kind of started to work with him and
then just kind of ghosted him and stopped
responding.
And at that point,
Murphy came to four or four,
four or four published a story.
And now the Apple was shamed.
They had to go ahead and respond again.
They said that it was fixed.
And at the time,
four or four was not disclosing how it
worked because, you know, of course,
it's like they haven't fixed it yet.
Anybody can do this.
But now we have some information.
And to put it simply,
it required sending a target and a message
that gets rejected as spam and you
purposely want it to get rejected.
They said,
we don't know how often hidden email
addresses were leaked in email logs.
For many major email hosts,
the leak was triggered simply by an email
being automatically rejected.
Even if it was legitimate,
such emails probably didn't make it to
your inbox.
So you can't review your spam folder to
learn whether you were affected.
which is kind of scary.
But yeah, basically when it got rejected,
the mail transfer logs could contain the
hidden email address,
your original email address,
which would be exposed to the attacker.
I think they have a link to Tyler's
blog post explaining this stuff,
potentially.
I could be wrong about that.
But yeah, I guess that's kind of...
What's going on here now that we know
more about how it works?
Not much of the story,
just kind of a little tiny little bit
of good news to end on.
I want to bring Jonah in to fact
check me on this one.
But I did a little bit of very,
very rudimentary research.
And I think it is potentially possible
that people like SimpleLogin and Addy
might be vulnerable to this,
depending on how they handle spam
rejections.
Do you know anything about that or
anything?
Is that just pure speculation?
There's not a lot of...
There's not a lot of details about how
this works exactly.
I'd have to look more into it.
Because I suppose...
I suppose this is probably more dependent
on how your... Not the aliasing provider,
but how your mailbox provider handles
messages that are sent to spam.
Um...
I would hope that that would get reported
to the aliasing provider instead of the
person who sent it,
which it sounds like is probably the case
with Apple.
But I actually don't know how that works
or how this vulnerability bug works.
It actually is.
If you go to easyoptouts.com,
there's a little banner right at the top
that says CR statement about Apple's hide
my email vulnerability bug.
It is a twenty minute read,
so we probably can't read it here.
But it looks like he does go into
detail.
If you scroll down to the exploit.
So, interesting.
So, yeah, we might look into that.
I'm very... Here,
I'm going to share it while you're looking
at this.
Okay,
it does say that hidden email addresses
were leaked for a variety of mail hosts,
so they saw them not just for iCloud,
which is one thing I was wondering.
I don't really understand why Apple's
servers would do this,
which is probably what EasyOpt does,
and everyone else doesn't understand.
It just doesn't make sense to me.
So I...
doubt this is an issue.
They do say in this post,
there's another email aliasing services
section,
and they tested this vulnerability against
many of the aliasing services on the
market according to them,
and none of them had the same kinds
of vulnerabilities.
I assume at minimum they tested SimpleLuck
and Addi because those are like the two
main ones people typically look at.
Oh,
I see they have a how to tell
if you're affected section here.
Yeah, so I guess you can test it.
I guess we could test it.
But yeah,
I can't imagine why Apple's service would
be configured in that way.
It really does sound like a specific to
Apple problem.
Yeah, I think you're right.
I see the section here now where it
says,
we did limited testing against many of the
major aliasing services on the market,
none of the ones we tested.
And yeah,
SimpleLogin and Addy are definitely two of
the biggest ones.
So at least SimpleLogin, I would imagine,
was probably tested here.
Yeah.
If nothing else,
hopefully now those providers are aware of
this and they can go test themselves and
make sure they're not configured like
this.
Yeah,
it's always a shame that these companies
have to be kind of pressured into fixing
obvious problems,
but at least it's fixed for everyone using
this.
Yeah, yeah, I agree.
I don't know why they have to drag
their feet so much, but.
I digress.
Yeah,
I was going to say the last note
that I had written down here is we
still do recommend services like
SimpleLogin and Addy over Apple because,
for one, they're more transparent.
They're open source.
I think you can even self-host SimpleLogin
for sure, maybe even Addy.
And lack of vendor lock-in.
If one day you wake up and you're
like, you know what?
I'm going to move to Graphene.
Guess what?
You're not locked into Apple if you go
with something like SimpleLogin.
Yeah.
yeah um but that's i think all i
had yeah taken what maybe a maybe a
look at our final chats here uh
In Signal,
somebody commented about the FCC thing.
I'm also informed in our Signal chat just
during the show, speaking of donations,
that Cape has sent a donation to Privacy
Guides.
I don't know anything about that,
but I'll have to look into that.
But thank you to Cape for donating.
Hopefully, we get other donations too.
But yeah,
I will have to check into that after
the show.
Yeah, thank you.
Like I said, every little bit adds up.
It really does.
Even if it's just a dollar a month.
Years ago, last time I checked,
you guys used to have the Umami Analytics
on the website publicly.
And I remember checking one time out of
curiosity,
and it was literally like a hundred
thousand visitors a month.
And it's like literally if half that
number gave a dollar a month,
I'm sure that would go so far.
That'd be sweet.
If all of them did,
then we'd finally be that million-dollar
revenue.
Yeah,
we don't need nearly that much money,
but we could.
There's definitely improvements that could
be made.
I think I just wanted to,
now that you mentioned it,
kind of look at our stats on the
form, and I think we get...
I mean, we get millions of page views.
I don't know if I can see how
many individual people visit,
but whatever.
And that's another thing I think about a
lot too is like, you know, with Umami,
it's like,
it's kind of privacy respecting analytics.
So it's like,
how many of those are individual and how
many of those just have a different
fingerprint now?
Cause their browser or whatever.
So yeah, it's hard to say for sure,
but I mean, it's still a lot.
So that's why you track visits and page
views.
We did get a question just now from
username five, nine, five, four, nine.
There are a few offline privacy focused
navigation apps,
but none seem to have a good interface.
Do you think it is important to stay
away from Google maps or is the privacy
concern insignificant?
I mean, in my opinion, I think the,
the,
I would still have one of those as
a backup in case you ever lose signal
or something like that,
which I've been in those situations where
just the cell signal is not very good
and I'm kind of screwed.
But from a privacy perspective,
if I'm being honest,
I think it really depends on where you're
going and how often.
If you know how to get around town
and you're only ever using Google Maps
once a month or once every other month
when you're going somewhere new, then...
it's probably not that big a deal.
And especially if you're just like, Oh,
I'm checking out a new restaurant or
something.
But if you're using it like constantly,
like I used to use it at my
last job.
Um,
I was constantly working on different job
sites and because we were on the clock
and we were usually going there during
rush hour,
I was constantly trying to find the
fastest route.
So I really relied on mostly Apple maps
cause I had an iPhone at the time.
And, uh, you know,
but I was using it like every day,
all the time to get to and from
places just to, to skip traffic.
And that was probably not great for
privacy, but you know,
I was on the clock.
What am I going to do?
So I don't know.
That's, that's kind of my take.
I think it depends on how often you're
using it and what for.
So your answer is kind of like,
how much do you want to be tracked
by them?
I mean, pretty much.
Yeah.
Yeah.
That is kind of what it comes down
to, isn't it?
But yeah.
Do you satisfy your curiosity about the
analytics?
It's kind of complicated.
We had a weird spike spike in visitors
on the sixteenth for some reason.
I wonder why that was.
Dude, I get the same thing on mine.
I'm really genuinely convinced it might be
like a scraping because it'll literally go
from like a couple hundred visitors a day
to like ten thousand visitors at four a.m.
on a Tuesday.
And then it'll drop back down and it's
just like something fishy is going on
there.
What did we do on the sixteenth of...
I mean, the weird thing is it stayed...
That was the peak,
but it stayed pretty high for the week
following that on this graph.
I have no idea why that would be.
I don't have a calendar open in front
of me, so that is a good question.
Anyways...
I think we want to close this out,
or you got anything else you want to
add?
I'm not seeing anything on Signal or the
form, so...
Did you see the news about Codeburg
banning cryptocurrency projects?
I skimmed it briefly.
I saw the forum post about it and
something about, you said it was,
what was your wording?
It was extraordinarily poorly worded.
Well, I just don't understand it.
I guess I don't have much to say
about it,
but it seems like they're saying two
different things.
And it doesn't really make a lot of
sense to me,
but just a weird thing I've saw in
the forum lately.
Is it just,
they're basically just bamming scammy
crypto products?
Well, yeah, I mean,
like in this banner at the top of
their page,
they just say cryptocurrency projects are
no longer allowed.
And that's also what it says on their
terms of service.
But then like in a random comment on
this thread about the change,
they explain that it's only scammy ones,
which is not what it says.
But I guess if you go down and
read this random comment,
you would know which ones are allowed and
which ones aren't.
Interesting.
I wonder if it's one of the,
what do they call that,
like a silent policy?
Yeah, I mean,
it feels like it'll just be enforced
probably arbitrarily,
which is probably not how I would prefer
the services that I use operate.
Codeburg kind of annoys me sometimes.
It's one of the reasons I don't want
to switch to it.
I know people ask us that all the
time,
and I don't really like Codeburg or GitLab
or
more than i mean i i like him
like just a little more than github but
not enough to switch off of github but
i do like codebook software i i would
love for joe to get to the point
where we could we could switch to it
but i really wish it had federation and
they have and that's taking a really long
time so sadly i don't know i mean
can't complain about it too much i don't
know how to speed it up so but
it it just is
I'm sure that ActivityPub is not
necessarily perfect for everything,
but I do really like the idea of
so many different services being
ActivityPub compatible because then you've
got this ideal scenario where it's like,
I can comment on YouTube, Instagram,
Twitter, GitHub,
all these different things from one
account.
And I don't need to keep making accounts
if I don't want to.
And that is probably one of my favorite
things about the Fediverse.
Yeah.
And it's like,
I hope they can do it soon.
It feels like it actually wouldn't be that
complicated for this use case because Git
is already decentralized.
So you pretty much only have to federate
issues and stars and pull requests is
probably the hardest one,
but Git already has...
ways to work on things remotely and on
different branches and you can just pull
it in from a different site so it
feels like it wouldn't be extraordinarily
difficult like it's basically just
comments and reactions is the main thing
which is which is already done by every
single activity pub platform out there
that's that's how they work it's comments
and posts right um
But I mean, I'm obviously not coding it,
so I can't provide too much input or
complain about it too much.
Because I'm not going to do it myself,
I can tell you that.
Fair enough.
I think that's kind of it then.
So yeah,
I think you can wrap it up.
Nate, you're muted.
I hit the button too many times.
My bad.
All right.
All the updates from this week in privacy
will be shared on the blog every week.
So sign up for the newsletter or subscribe
with your favorite RSS reader if you want
to stay tuned.
For people who prefer audio,
we also offer a podcast available on all
platforms and RSS.
And this video will be synced to PeerTube.
Privacy Guides is an impartial nonprofit
organization that focuses on building a
strong advocacy community and delivering
the best digital privacy and consumer
technology rights advice on the internet.
If you want to support our mission,
then you can make a donation on our
website, privacyguides.org.
To make a donation,
you can click the red heart icon located
in the top right corner of the page.
You could also just go to
privacyguides.org slash donate and you can
contribute using standard fiat currency
via debit or credit card or opt to
donate anonymously using Monero or your
favorite cryptocurrency.
Becoming a paid member unlocks exclusive
perks like early access to video content,
priority during the live stream Q&A.
You'll also get a cool badge on your
profile in the forum and the warm fuzzy
feeling of supporting independent media.
So thank you all for watching and we'll
see you next week.