The Pixel 11 is Here, Will it Support GrapheneOS?
Will the Pixel XI support Graphene OS?
Is your Firefox install compromised?
Will Signal allow a way to register
without a phone number?
All this and more coming up on This
Week in Privacy, so stay tuned.
Welcome back to This Week in Privacy,
our weekly series where we discuss the
latest updates with what we're working on
within the Privacy Guides community and
this week's top stories in data privacy
and cybersecurity while taking questions
from viewers like you.
I am Nate,
and with me this week after a bit
of an absence is Jordan.
How have you been, Jordan?
Good.
Just been super busy with video content on
the back end,
but really excited to hop back on here
with you to discuss the latest privacy and
security news.
Yeah,
there is a boatload of stuff happening
with videos that we will definitely get to
later on in the episode,
but it is good to have you back
for sure.
Um, I guess with that,
we'll go ahead and jump right into our
first story, which is about the new pixel.
And, uh,
I believe you're going to be taking that
one first, Jordan.
So I'll turn it over to you.
Yeah, let's dive into that.
Um,
so this story here is about Google's new
pixel, eleven series devices.
I'm quoting from this.
Google says the tensor G six delivers up
to twenty five percent faster browsing
and fifteen percent faster app loads
compared to last year's Tensor G-Five.
The Tensor G-Six is the updated system on
a chip in the Pixel-Eleven series of
devices.
The chip pairs with an upgraded image
signal processor with a new TPU,
and Google says it's fifty percent more
powerful than the previous generation,
enabling features like a hundred and
twenty times pro zoom,
instant night sight on the pro models,
and this new
This TPU chip also drives Gemini Nano,
Google's on-device AI model,
which the company says now runs with
higher quality and lower latency.
But the most important thing that we
wanted to highlight from this story is the
Tensor G.
works alongside a new Titan M three
security processor built for post quantum
cryptography,
which Google describes as protection
against emerging highly advanced digital
attacks.
And the company adds that the Titan M
three has earned common criteria
certification at the same level that's
used for SIM and bank cards.
The chip also handles quantum safe secure
boot and runs trusty Google's trusted
execution environment on all four phones.
So this is always a thing that happens
every time Google announces a new device.
I guess we should dive into the most
obvious thing and the question that we
have as this week's episode is,
Will this support Graphene OS?
So I guess I'll throw this back over
to you, Nate,
and we can kind of discuss this a
little bit.
Is this, you know,
what's the timeline going to look like for
this?
Do you think it's something that we can
expect soon?
What are the updates that Graphene OS has
shared so far?
Yeah, so I guess I'll...
I guess I'll lead with the answer,
which is, honestly, we don't know.
For those who may be just joining us
or haven't heard, Google last year,
I think it was, mostly last year,
made a lot of
changes to their policies that kind of
shoot all android developers in the foot
or at least um android roms like graphene
calyx lineage which is uh they slowed down
the number of releases that they're
publishing for uh the aosp project um
they've i think they slowed down the
number of security patches too but i could
be wrong about that um they uh
they stopped publishing the pixel device
tree specifically.
So basically now they have to like reverse
engineer all the hardware changes.
And then on top of it,
they made a lot of the development closed
source.
So it used to be that they did
all their merge requests and everything
up,
or I may be using the wrong term
there, merge requests,
but they did all their development stuff
in the open.
So people could kind of see like, okay,
they're working on this,
they're working on that.
We could also push back if we're like,
hey,
why are you adding this feature that
sounds sus?
now instead they're doing it all closed
and then just every so often they're like
all right here's an aosp update publicly
so it's still technically source available
in open source it's just now we don't
get to see what they're doing until
they're done and between all of that uh
graphene at the time pixel ten was the
newest one and they were basically like
look you know we'll support the pixel ten
but we don't really know what the future
is going to hold because of all this
and
Um,
they said that they want to keep trying
to support pixels as much as they can,
but between that, and there's also,
it's worth noting,
there are other hardware changes to the
pixel, uh, to the pixel XI,
aside from just like the tensor and the,
the Titan chip.
Um,
the most notable one that I've seen people
mentioning is they switched the modem.
It used to be a Samsung Exynos,
I believe.
And now it's like a MediaTek something.
So yeah, it's, I mean,
even Graphene themselves have basically
said like, look,
we're not going to know until we actually
have a Pixel XI in our hands.
And then we can like kind of take
a look at it and see.
I think you shared,
if I can go find it,
you did share in our chat from the
Graphene forums.
It was like there when they were keeping
people updated.
Yeah, so here it is on screen here.
I've got the link here.
If you want to take a look at
that.
Yeah.
Okay.
Yeah, so if we look here,
it's kind of a timeline of the events
that happened to get this support for the
Pixel X,
which I guess we can kind of extrapolate
somewhat to the Pixel XI.
So if you don't know,
the Pixel X was announced on August,
August, August, August, August, August,
August, August, August, August, August,
August, August, August, August, August,
order and confirm that it supports
unlocking.
So, you know,
at this point it's been not even a
week yet.
So we don't really know what the outcome
of that's going to be.
If the devices will be unlockable,
we can assume that it might be,
but obviously the GrapheneOS team hasn't
actually gotten the devices yet.
So if you scroll all the way back
up to the top, January,
is when it was considered stable.
So a couple of months, four months,
pretty much what we're looking at here for
the Pixel X.
So I would not be buying a Pixel
XI if your immediate need is to run
Graphene OS because from their previous
experience doing this,
it took four months.
It may take less.
It may take more.
We don't really know because like Nate
said,
it's all stuff that's like
not information that we know at this
point.
And also like, you know,
they have to reverse engineer that.
And one other thing I quickly wanted to
share as well is GrapheneOS did do a
post on Twitter and they said,
the PIX-Eleven hasn't been released yet.
We aren't going to have an idea about
how long it will take until after we
have access to devices and the code.
We'll post about it on our feed when
we have information to share.
No need to ask us for updates since
we'll make posts about it.
So that's kind of the current situation,
unfortunately.
which is kind of,
it's good to know that they're going to
post updates,
but we don't really have a huge amount
of information at this point.
Yeah, for sure.
And one other thing that's worth noting,
for those of you who are not following
us on any of our social media,
we did actually push out a quick short
about this whole thing.
Google, or excuse me, not Google,
Graphene has that whole...
their partnership with Motorola now.
And so that could really play into this
either way.
Um,
It could be that because of that
partnership,
they're able to get their hands on certain
software resources like AOSP.
Maybe they can get a copy of AOSP
from Motorola early,
and that will help them speed up the
timeline.
Maybe they're able to take advantage of
some of their expertise.
I don't know.
Or maybe they'll just hit a point where
they're just like, screw it.
If Google's going to make it this hard,
we've got this other manufacturer that
we're working closely with,
and we have
complete insight into the whole process.
We really, really don't know.
But yeah,
I just wanted to make sure that's a
mention too.
It's part of the math, I would think,
but we don't know what part of the
math.
Yeah, fortunately,
I don't think we have to wait too
long for the pixels to ship.
They usually the preorder, I think,
is usually just a couple of weeks before
they start shipping.
So hopefully by the end of the month,
we'll we'll have an update.
But yeah.
Yeah, I guess kind of somewhat off topic.
But what do you personally think of the
devices?
Is this something you're going to be
preordering?
Are you going to be upgrading this this
year or no?
Um, probably.
So my wife and I both have the
pixel six a,
which I think stops getting support in
July.
I was looking at the pixel eleven.
So I'm the kind of person that I
like to buy the newest one just so
that way I've got like the longest amount
of security updates and stuff.
And then I'll run that into the ground.
So I'm probably going to get the eleven
a whenever they announce it.
Although my wife jokingly,
I sent her the eleven fold and I
was like, oh, we should get you this.
And she was like, unironically, yes,
that looks so cool.
I would happily buy that.
So I think what we're going to do
because we don't really have a thousand
dollars to drop right now.
I think what we're going to do is
probably wait until the twelve fold.
So like next year's phone and then go
ahead and order that for her and I'll
just get the eleven a.
Because I don't really care.
I don't need my phone to do a
whole lot.
But she likes to play some games.
She has ten billion pictures of the cats.
Like all that kind of stuff.
So she could use a little bit nicer
of a phone.
How about you?
The main thing for me.
So I do have.
I kind of have a bunch of phones.
Because obviously we need to do testing.
On different devices and things.
But the device that I do have.
Is a Pixel Nine Pro.
And I think the funniest thing.
About the Eleven Pro.
is that it starts with twelve gigabytes of
RAM,
which is less than the nine and the
ten.
So you're actually getting less RAM on
this year's model unless you pay more.
So I don't know.
I was not really impressed.
Let's just say that is a little I
know that RAM prices are getting high and
stuff,
but like if you're decreasing the amount
of RAM,
on a pro device, um, year after year,
then I dunno, that's,
that doesn't leave a very nice taste in
my mouth, but yeah,
I've got five years of,
of security updates left,
so I'm not in any rush to,
to go and upgrade.
And I've never really had any issue with
performance or anything.
Um,
so I am not going to be upgrading,
uh,
unless Google does something like really
cool, like, you know,
there's like some really massive security
feature that they add, which, you know,
the, the,
the Titan M three security process is
really cool and stuff,
but it does seem like it's not,
you know,
a massive leap in security that that would
be worth spending my goodness,
a thousand dollars or more on a new
phone.
Um, so, you know,
I'm always trying to get them secondhand
and not, um,
Not give Google money because, yeah,
Google, not a great company.
But, yeah,
so I guess we could also talk a
little bit.
You did put together like a short this
week kind of describing a lot of what
we talked about this week as well,
if you want to dive into that a
bit.
Oh, yeah.
I mean, there's not really much to say,
to be honest.
Let me see if I can pull it
up real quick here.
But yeah, I just...
Every once in a while when there are
these big announcements,
like the graphene thing or the...
excuse me,
the graphene siding with Motorola thing or
this announcement,
we try to make sure that we get
some kind of video out pretty quick.
There wasn't really a lot about the
privacy and security this time around.
Like you said, the Titan,
it's got the post-quantum cryptography
stuff on it,
but that's kind of future-proofing and
getting ahead of the curve.
It's not something that everybody needs to
run out and buy right now.
There wasn't really enough to justify a
whole video, but yeah,
we did put out this...
this short here,
which is not on this channel.
I'll have to go find it.
But yeah,
we just put out a little short video,
kind of giving people a quick rundown of
all this new stuff.
So I don't know,
that's a I don't think there's too much
to say about that one.
Yeah,
I guess we can just cover this comment
here from Dag Overhaul.
Pixel XI looks like a downgrade from the
Pixel X, lol.
Yeah, it's like what I was saying.
The Pixel X looks like it might be
better in some aspects.
It's obviously we don't really know the
specifics yet on performance and things
because...
you know,
I think it's only being given to like
people that are media and, you know,
they're obviously going to have tainted
opinions cause they've gotten a free
product from Google.
So let's wait and see, um,
what that looks like.
But Google's never had good performing
devices and, oh yeah.
So here's the, um,
here's the short we put out, um,
that Nate put together.
So, uh, yeah,
if you want to share that with people
in your, in your life about this,
about this new release and that'd be cool
too.
Um,
Yeah, I think it's some interesting news.
We wanted to cover it kind of as
the highlight this week because I feel
like everyone in the community is probably
going to be having this question.
So yeah,
so Dag says it's twelve gigabytes of RAM
versus sixteen in the Pixel X. Yeah,
that's what I was saying.
It's like it's actually wild.
It's kind of ridiculous that that's
something they decided to do.
Yeah, for sure.
NotThatPrivate asked,
what post-quantum cryptography algorithm
does the M-III use?
From what I can tell,
it doesn't look like they've disclosed
that yet.
I think they're still planning to publish
a lot more technical details.
This was just kind of the initial get
people interested, which is also why,
like you mentioned,
there's probably some tech YouTubers that
have this and stuff,
but they kind of focus on the hardware,
the performance, and everything.
Yeah.
Um, it looks like the open Titan chips,
um, this comes from the AI summary.
So I apologize if this is wrong.
It says the open Titan chips,
which is Google's open source route of
trust currently use Sphinx plus also known
as SLA SLH DSA or FIPS two Oh
five for post quantum and secure boot with
future extensions planned for lattice
based schemes like dilithium and Kyber.
So, um,
if that helps a lot of the,
the more technical stuff goes way over my
head,
but
Yeah, I think just keep an eye out,
and I'm sure they'll be releasing more
details in the near future.
Yeah,
I guess we can dive into some quick
forum threads here.
There were some people asking some
questions and saying, you know,
some comments.
Do you want to just grab one of
those real quick?
Yeah, sure.
So we posted about this on the forum,
discuss.privacyguides.net.
There's a good place to go and ask
your questions in advance if you won't be
able to watch the stream.
And we had a couple of comments
speculating, again,
on whether or not Graphene will support
it.
Um, but, uh, yeah, I mean,
it's mostly just that.
So one person said that they think
graphene will support it.
And they cited,
I think the same quote that you cited
earlier from Twitter where they said it
hasn't been released yet.
We don't have an idea how long it'll
take.
Um, somebody else said, I think not.
Uh, somebody said,
I'm crossing my fingers that the eleven
will be supported.
Titan M three and graphene could be a
match made in heaven.
So, um, yeah, that's kind of it.
Sweet.
I think that'll take us into our next
story here.
And we're going to talk about the White
House
is potentially allowing cybersecurity
firms to do offensive hackbacks,
which is new.
This is never beneficial before.
So on Wednesday,
the National Security Presidential
Memorandum was signed that instructs the
National Coordination Center to establish
a program that would allow private
security companies to apply for approval
to hack foreign cybercrime organizations.
Let's see,
the program will be overseen by executive
directors designated by the justice and
Homeland security departments and security
firms participating in the program will
undergo vetting before entering into
contracts with one of the two departments.
Additionally,
the memorandum requires procedures
ensuring operations comply with US
constitution,
federal law and international obligations.
Participating companies will have to
maintain a bond or escrow of at least
a million dollars that will be forfeit
forfeited if they don't comply with
contractual agreements.
And they must also immediately stop
operations if they discover activity
exceeding approved limits,
including unintended target of US citizens
or US based systems and notify the
National Coordination Center.
The White House said the program is
intended to disrupt foreign criminal
organizations involved in ransomware
attacks, phishing campaigns,
financial fraud.
extortion schemes and impersonation scams.
And it added that us consumers have
reported losing more than twenty point
eight billion dollars with a B to cyber
enabled crime in twenty twenty five.
So this is this is a bit of
a departure.
Because up until now, I mean, yeah,
like nobody has ever authorized
like this.
That's kind of what they're calling it.
And I don't know.
This is just really...
It's hard for me to put into words.
It's one of those things where it's very
aggressive and it's very...
I mean,
I think there's a lot of questions here.
Like for one, this kind of blurs,
or I should say further blurs the line
between government and private companies,
right?
We already have so many issues with all
these defense contractors and surveillance
contractors,
Flock and Palantir and all these data
brokers.
And there's already like a very blurry
line, especially in the military, right?
Between like private contractors and
government.
And when you have a private contractor
acting on behalf of the government,
that's definitely a
not cool.
Um,
I have questions personally about
differentiating cyber crime from state
sanctioned activities.
Like this is companies are notoriously
cautious about, um,
about attributing cyber attacks to other
countries.
And some of that is a political thing.
Like you don't want to accuse somebody of
something unless you're a hundred percent
positive, but also at the same time,
it's just, it can be really hard.
Like code is code and there can be
little indicators
based on patterns,
but it's really hard to definitively say
like this company or this group was behind
this attack.
When an organization comes forward and
attributes a cyber attack,
it's a pretty big deal actually.
And especially I'm thinking of like North
Korea, for example, which for the record,
I'm not defending this,
but North Korea largely funds themselves
by like Bitcoin theft and scams and stuff
like that.
Like their government has been so heavily
sanctioned.
That's the only way the country can make
money anymore and stay afloat.
And so that just feels like a gray
area to me where it's like, okay,
if North Korea hacks Coinbase and steals a
bunch of Bitcoin,
is that a cybercrime or is that a
state-sponsored attack?
And are they allowed to hack back or
not?
Because it does... I mean,
I didn't read the memorandum itself.
I probably should.
But this article didn't say anything about
attacking state operations.
It said trying to deter cybercrime and
disrupt cybercrime.
So like...
I don't know,
that just feels like a really big gray
area to me.
And the other thing that they noted in
here is that this could cause perverse
incentives.
Like a million dollars for most company is
not really much.
I mean,
we see companies get fined millions of
dollars for privacy violations and it's
just a cost of doing business for them.
So this whole idea of like, oh,
you have to put down a million dollars.
That's like telling me I have to put
five dollars in as a deposit to get
somewhere.
Like, oh, five dollars in,
five dollars back.
I don't even care.
It's five dollars.
Keep it.
Like, I'm not that hard up for money.
So
Yeah.
And what was it at the very end?
One of the people they interviewed said
that they described it as a perpetual
motion for billable threats.
So the idea is that private firms might
have a financial incentive to create or
exaggerate threats to justify their
contracts,
which we already see that happening a lot.
So yeah.
Yeah.
And this is,
I'm assuming you added this here, Jordan,
but at the end of the notes here,
we have like,
why is this still important for people
living outside of the United States?
Which is a really good question.
And I think it's just because this really
raises,
this raises the possibility of something
going wrong.
If a private company attacks a
Um, let's say they attribute it to,
I don't know,
China and they hack a Chinese company and
China says, no, we weren't behind this,
whether they mean it,
like whether it's true or not,
if China insists,
like we are not behind this,
that could escalate things.
And it's just,
the world is so closely interconnected now
that.
everything i mean we've been seeing it
play out for the last couple years right
it's like everything that especially big
countries china russia uk us everything
that we do has knock-on effects to other
countries around the world so it's just
one of those things where like i i
feel like there's so many opportunities
for things to go wrong there's so much
and especially in the cyberspace you can't
physically see where you're at right i'm
gonna digress real quick um darknet
diaries did an episode where he talked
about he's done a lot of episodes where
he talked about um
pen testers.
And one of them that stuck out to
me specifically was they were hired to
test a hospital.
And they talked about all the different
systems they got into.
And one of them,
they didn't know what the system was,
but they wrote it down in their report.
And they mentioned like, oh,
we got into this system.
And that particular system,
as soon as they said that,
everybody was like, wait, what?
Which one?
Hold on.
We'll call you back.
And it turned out they had hacked into...
I think it was like a laser machine
being used for surgery,
like actively being used in a surgery
while they were in the system.
And thankfully they didn't do anything.
Like they just went in and they were
like, all right, make a note.
We got into this,
move on to the next target.
And,
but that just kind of shows that like
when you're in cyberspace,
you're looking at an IP address,
you're looking at a server name.
You can't tell if that's in Beijing or
Moscow or Uganda or Germany.
Like you don't know necessarily right off
the bat.
So I think there's just a lot of,
a lot of room for things to go
wrong here for people to get caught up
in crossfire for uh tensions to escalate
um yeah i don't know that's that's kind
of my take on this thing i don't
know if i missed anything on this story
that you had any more thoughts on but
yeah no i don't really have anything to
add but i think it's uh definitely an
important discussion to have um
And I guess I would say,
what can people do about this?
Is this something that people can have a
say about?
Or is this something that's kind of just
been decided without any review from the
public?
I don't know, to be honest with you.
I would imagine...
maybe somebody who's a lawyer can correct
me.
I would imagine that this is probably
going to get challenged by somebody in
court, um,
just for being like reckless and scary and
possibly like some kind of international
illegal thing.
Not like we seem to care about that
these days, but I don't, I don't know.
I don't know what the average person can
do other than just the usual advice we
would give to anybody, which is, you know,
try to keep your stuff updated,
try to keep your stuff, uh,
good passwords and stuff.
Try to keep your stuff as relatively
hacker proof as possible.
Um,
I don't want to sound paranoid,
but maybe a little disaster prep.
I mean,
we've covered so many cyber attacks that
take down, you know, hospitals,
fuel pumps,
just kind of having like enough basic cash
and food on hand to get you through
a few days is really not a bad
idea ever for anybody.
Because you never know if a cyber attack
will bring down the payment systems or
whatever.
So
I don't know.
I don't know if we, the people,
have a whole lot of options here.
You could maybe try contacting your
representatives and being like, hey,
this seems bad.
Can we not do this?
But I don't realistically know if there
are any laws being violated here.
Right.
Okay.
Yeah.
I guess we can dive into some site
updates here.
I'll just dive into some of the stuff
I've been working on and then Nate can
go and explain some of the videos we've
published this week.
So we've got upcoming videos here.
We've got a tier list,
a password tier list video that's coming
up.
Nate has been editing that and it looks
like it's pretty much ready to go.
We just have to do a little bit
of final checking.
There's a video about
creating a Bitcoin wallet without
connecting to the internet,
completely cold, instead of, you know,
using some sort of generation method.
And the reason why we wanted to talk
about that,
we use diceware system instead of,
you know,
using a chip to generate that wallet seed
phrase,
because
There was a recent issue that we did
do a post on the privacy news section
of our site about cold wallet, I believe,
cold card, cold card, hardware wallets.
And basically the generation system that
they used was predictable,
which allowed basically anyone to
access the wallet seed phrases so
obviously that is extremely bad and that
was a complete disaster so Jonah was like
well there's a way to fix this right
so he put together this video on how
you can use basically a dice a word
list and how you can basically create a
really secure seed phrase that
is a hundred percent random instead of
being predictable,
like with the terrible situation that
happened with cold card.
So that's going to be an interesting one,
which, which should be out on,
I believe two days from now.
So definitely look out for that.
And yeah,
that's kind of what we've been doing in
terms of I've been working on some things
on the behind the scenes stuff,
working on thumbnails,
stuff like that for videos.
We've kind of trying to be debugging the
flock video a little bit.
We're not really sure why,
but it didn't seem to reach too many
people.
So we're trying to work out
why that was the case and kind of
be messing around with that too.
Okay.
So there's also some,
there's a release this week as well for
the site, which had some updates.
We updated the foundations and
organizational donors on the website,
removed a spam link,
and there was a fix to the Yubico
UTF on Linux page.
So yeah,
that was kind of a small amount of
updates this week on the site.
And there was some articles as well that
Freya and Nate have been working on.
So
There was one about a zero-day
vulnerability in Windows from Nightmare
Eclipse,
severe Zoom vulnerability allowing
malicious meeting participants to take
over your device,
Californian city declares state of
emergency after cyber attack,
and there was also one about an
system takeover.
So yeah,
let me throw it back to you, Nate,
and you can talk a little bit about
the videos that we've been publishing and
that are coming out soon.
Yeah.
So, um,
we've been kind of pushing out a lot
of videos in very short order, uh,
which is exciting.
Very cool for us.
Um, we put out one, uh,
we've been advertising this one for
awhile.
There was a, uh,
we did a video about bull run,
which was the NSA's attempt in like the
nineties, eighties nineties,
two thousands, I think to either, um,
what did we say here to either hack,
cooperate, interdict or influence.
basically everything and all the different
ways they tried to compromise encryption
on the internet.
That went out last week,
but now it's finally out to the public.
So everybody can go watch it.
Definitely go check that out.
Um, very proud of that video.
And then also, yeah, this is the, uh,
the flock one that Jordan mentioned.
Um, we're not really sure why,
but for some reason it really,
really did not perform well.
Um,
which is sad because this is an issue
that everybody's, uh, you know,
I think I mentioned last week that it
was on a John Oliver episode and like,
this is an issue that has hit the
mainstream.
And for some reason the video just didn't
do very well.
Um,
So I don't know if you have any
ideas, let us know for sure.
But in the meantime,
you can head over to neat.tube and check
it out.
Or there's also a link in the newsletter,
of course,
and you can check it out for yourself,
share it with your friends and family.
There's actually a national week of action
against ALPRs starting Sunday and going
through Saturday.
So this video was kind of released to
coincide with that and kind of hopefully
get people interested and fired up for it.
But I think that's noalprs.com for more
information on that.
But
Yeah,
that is pretty much all we've been up
to in terms of videos.
I mean,
pretty much all we've been up to.
It's a lot.
It's a lot for a week.
We've done a lot this week.
But yeah,
all this is made possible by our
supporters.
You can sign up for a membership or
donate at privacyguides.org.
Or of course,
pick up some swag at
shop.privacyguides.org.
Privacy Guides is a nonprofit which
researches and shares privacy-related
information and facilitates a community on
our forum and matrix.
where people can ask questions and get
advice about staying private online and
preserving their digital rights.
Now, as a reminder,
as you're watching the stream,
go ahead and leave any questions you have
for us in the chat.
They can be related to the stories or
they can be random privacy and security
questions.
Actually, on that note,
I'm going to go back real quick to...
laptop here left a couple questions when
we were talking about the White House
story.
You said,
why would it stop being bad just because
the state is doing it?
It's not that it stops being bad.
It's that then that becomes an attack.
If we go after,
if there's a private hacking group in,
I'm just picking a random country and I'm
sorry.
If there's a private hacking group in
Cambodia that's going around doing scams
and hacking into people's Facebook
accounts and
And we take them out.
That is distinctly different from like
attacking a government.
If the government of Cambodia is breaking
into people's Facebook accounts,
it's just politically,
it turns into a very different thing.
It's the difference between like taking
out a mugger versus taking out a soldier,
which is still,
there's still a lot of like,
I don't know.
I feel icky,
like operating in other people's space,
but my point being,
it doesn't necessarily stop being bad.
It's just,
it's a whole different can of worms.
And yeah,
You also said our IP address is allocated
more or less regionally.
You might be right.
I don't know.
That goes above my head.
I'm just saying it's not as obvious as
like if you're flying over a physical
country and you drop a physical bomb,
it's a little bit harder or at least
– I mean obviously missiles can hit the
wrong target.
We've seen that a lot in the last
twenty-five years.
But my point being is like,
it's not like you're flying over one
country and you drop a bomb and it
lands in a completely different continent.
Like, I don't know.
It just it feels to me like there's
a lot more room for things to go
wrong on that.
But I could be wrong.
I don't know.
But speaking about being wrong,
I think we're going to move on to
our next stories,
which we have a few stories about
companies acting shady,
starting with surprise, surprise, Amazon.
And I'm going to let Jordan go ahead
and take this one away.
Yeah, let's do that.
So this story here is Amazon will train
on Twitch streamers content by default
unless they opt out.
So I think we should start by saying,
just in case you don't know,
Twitch is owned by Amazon.
They're basically the same company, right?
It kind of makes sense, actually, because,
you know,
Amazon has such a large presence in the
hosting space, I guess.
They have Amazon Web Services, which,
you know,
kind of makes sense why they would be
able to run such a service like this.
So this is kind of a very controversial
change.
I think a lot of streamers are going
to be disabling this because, you know,
obviously,
why would you want your content to be
used to train AI?
I'm not really sure.
It doesn't really benefit you exactly.
So just, I guess,
reading a couple of quotes from this
article here.
In a stream on the official Twitch
channel, Twitch head of community,
Mary Kish and chief product officer,
Mike Minton,
addressed a live audience of nearly three
thousand aggrieved users,
many of whom were posting anti-AI
sentiments in the chat.
Why is it not opt in?
That's what everyone is spamming in the
chat.
I get it.
Let me opt in versus making me opt
out, Minton said.
Well, there's an honest answer.
If this was opt in,
nobody would opt in.
And that's honestly the answer.
So I think that kind of highlights the
main issue that we have with this, right?
Like this sort of thing is
something that is kind of becoming an
issue right a lot of these ai companies
will do this well they'll say you can
use our services but you have to opt
out and the opt out is kind of
hard to see it's not really super obvious
that it's possible um i think this does
the same basically the same thing right um
And quoting again from the article,
in some cases,
this created confusion among streamers
about whether their content had already
been fed to Amazon without their
knowledge.
When one user asked if their videos had
already been used for training,
Minton responded,
I don't actually know the answer to that
question because I don't know what Amazon
has done in terms of model training and
what they've used and not used.
So obviously that is extremely concerning,
especially because, you know,
They should have not been doing that if
you didn't opt into that.
I guess they could technically do that
based on their terms of service,
but not really great.
Kish noted that Twitch is not unique in
its use of user content for AI training.
Meta, for example,
uses public content from its platforms to
train its own AI models,
meaning that if your Facebook and
Instagram accounts are public,
then your data has probably already been
used for Meta's AI training.
And if you live in the UK,
you can opt out of Meta's training
If not,
the only way to opt out is to
use the private setting,
which isn't feasible for creators who
monetize their accounts.
So I guess throwing this back to you,
Nate,
this is like one of these obvious things
where it's like, why is this opt in?
Shouldn't this be like, I mean,
why is this opt out?
Why isn't this, you know,
the other way around?
It doesn't really make a lot of sense.
What's going on there?
Yeah, I mean,
it's exactly like this guy said,
this Kish dude.
They know that most people would not opt
in.
And to their very, very tiny defense,
I don't think he necessarily meant that
maliciously.
I think he just meant it's a fact.
Most people don't change the defaults.
um most people seem to even forget that
a lot of their accounts and devices have
settings uh and most people just don't go
looking for that kind of stuff they just
they get a phone or they get an
account and they just hit the ground and
start running and you know especially with
things like this like yeah they'll tweak
the profile picture and the banner and the
bio but they're not going to go into
the privacy settings that's just they
don't even care about that
So, yeah, if it was opt-in,
nobody would opt-in just because people
never change the default settings.
But that is also like the malicious side
of it is they know that nobody changes
the default settings.
So if we make it opt-out, most people,
even when they hear about this,
they're just going to be like, eh,
whatever.
It's too much work to click three things,
which actually, to be fair,
I think I saw somebody say somewhere that
–
they weren't able to do this on their
phone in the mobile app and they had
to actually like log in on the desktop.
So they're kind of making this as
obnoxious as possible,
although somebody else responded to them
and said the mobile app isn't designed for
stream or for creators.
It's designed for audience and this
applies to creators.
So but yeah, I mean,
that's the simple answer is like people
don't change the default settings.
So if they make it opt out,
most people just never bother to log in
and and fix it.
But yeah, I guess another thing is,
you know,
is there really anything that, uh,
people can do that?
Are there alternatives?
Like, is there even another platform?
I feel like, you know,
what have we got?
We've got YouTube.
Maybe I feel like YouTube would also be
doing kind of some stuff with AI training
data as well.
So it's like,
it almost feels like this is becoming like
an industry standard thing.
Like you said, with meta and,
and all that, what do you,
how are you feeling about it?
Yeah, it, it really sucks.
Um,
My wife actually sent me a TikTok about
this the other day.
That's where she heard about it.
Oh man, this real quick,
this announcement was a train wreck.
The TikTok that she sent me was like
a person.
No, for real.
It was a person like commenting on,
on all these different,
the parts that were in here and like
how amazing it was that they're just like,
Oh yeah,
we don't know if they've already trained
on your data.
And they didn't mention it in the article,
but at one point somebody asked them like,
is the official Twitch channel going to
opt out of this?
And the, what's her name?
The Mary Kish.
She was like,
Yeah, I think so.
Probably.
And it's just like, wait, what?
It's opted and you're going to opt out.
But yeah, it's it's I mean, it's tough.
Laptop here said your featured link is
this StreamYard thing.
But yeah,
StreamYard only gives you like a hundred
views.
And I don't think there's a free tier,
actually.
I think we're paying even for this tier.
Um,
it only gives you a hundred people and
it's,
I feel like the issue is discoverability,
right?
Cause like, honestly, yeah,
there's a ton of options.
You could stream in discord.
You could stream in on zoom.
You could stream in a, you know,
signal you could street,
like there's a million other places,
but yeah,
The reason people use social media at all,
the reason we use Twitter and Blue Sky
and YouTube is the discoverability.
Like, we're trying to reach new people,
especially with our message of privacy.
And when you're a Twitch streamer,
you're trying to reach new people.
So...
I don't know.
There's so many things working against
people, right?
There's, like, the network effect of,
like, again, yeah,
you could set up your own PeerTube
instance and stream off that, but, like,
who the hell is using PeerTube?
And then that becomes a self-fulfilling
prophecy and a feedback loop of, like, oh,
I'm not going to set up PeerTube because
nobody's there.
Well,
nobody's there because nobody sets up a
PeerTube.
And it's just – it's tough.
There's really no easy ways out, I think,
especially when we talk about video
because, like,
video is –
so massive and like i guess the nice
thing about streaming is you don't have to
keep the old replays um so that helps
but like youtube for example if you're
gonna make like a pure tube channel with
all your youtube videos like video storage
adds up quick and gets really expensive
really fast so it's uh it's not great
yeah laptop it's called the network effect
so
Yeah, all right.
I guess we can dive into this forum
post here, which you can grab,
because I know you definitely had some
thoughts about this one.
Yeah, all right.
So one of our forum updates we're going
to focus on here is about ProtonVPN.
ProtonVPN got accused this week of running
price sensitivity testing,
AKA AB testing on their customers.
And the reason that this particularly
became an, well, I mean,
there's a couple layers to this, right?
Well, let me just read.
Okay,
I'll read two posts here that kind of
sum this up.
So the person who originally posted this
said, since Friday, August seven,
twenty twenty six.
So we saw this actually after we streamed,
I think multiple Redditors have reported
that they are seeing different prices for
Proton VPN plus suggesting that Proton is
running price sensitivity testing on their
customers.
also called AB testing.
And they've got some screenshots here.
They said proton is formally denied it.
They've got a screenshot of that.
And they said, but when,
when scribe is calling them out on Twitter
for lying by providing evidence.
And there's a screenshot of when scribes
and they linked to all this stuff too.
Um,
so this turned into a whole discussion.
Apparently you can actually see, uh,
what is it?
I think this came from a wind scribes
tweet.
You can actually see in the code where
it says there's like an AB test.
And if you're getting content a or content
B, um, and, uh,
we did pin at the top of the
post here, protons response.
Um,
so this came from somebody on Reddit who
I believe works at proton and says, uh,
They said this topic went very strange,
very fast.
So let me expand and clarify.
Proton VPN is nine ninety nine a month
or eighty three eighty eight a year.
We used to have an introductory offer for
two years at four forty nine per month.
There's been a two year intro price of
two ninety nine per month.
It has been running for a while on
some back to back campaigns.
That price ended in July and since then
it has been three forty nine a month.
um they say that there were some like
legitimate pricing errors in the
screenshots but they said uh at the end
of a long-standing sale period we often
try an a b run of the old
and new pricing on the website during the
transition to see if anything has changed
as explained to answer the speculation
already and as confirmed by others who
independently checked it there is no
adaptive pricing as in it does not vary
by browser operating system etc and it is
one hundred percent randomized
So for the past several days,
some people will still have seen the
older, cheaper two ninety nine price.
I had been of the impression that the
A.B.
was already concluded and there must have
been some cashing going on.
But it's actually due to end on Monday
when one hundred percent of people should
see the three forty nine price.
He says there's no denial that we were
doing an A.B.
evaluation.
And then.
Yeah.
So basically they're saying, like, yes,
we were.
Doing.
A, B testing,
but we weren't doing it based on user.
It was completely random.
I could go to their website right now.
Allegedly, the test should be over.
But theoretically,
if the test was running,
I could go to their website right now
and see one test.
And then if I close my browser and
clear my cookies or whatever,
and I come back later the same day,
I might see a different test.
So...
I think, I mean, personally,
I have a lot of thoughts about this,
yeah.
But I mean,
I think I'll throw this one to Jordan
since you've been kind of throwing some
questions my way.
Do you think there's any concerns over
this kind of stuff,
even if it's randomized?
Like if they're not tracking you and
they're not doing it based on your data,
because usually that's what companies try
to do, right?
They try to, the surveillance pricing,
like we think you'd be willing to pay
a little bit more,
so we're going to give you the higher
price.
But if it's completely randomized,
do you still think that's kind of a
problem?
I think that this is one of those
things where it's like,
obviously this is because we know now that
this wasn't based on people's information.
This is not a privacy issue per se.
This is one of these things where it's
like, is this a good business practice?
Is this ethical?
Is this something that we want a company
like this to be doing?
Is this a good practice that they should
be doing?
And I think, you know,
not to pull out the slippery slope
argument, but once you start,
we've definitely seen Proton adopting more
mainstream marketing tactics,
for instance,
like running Black Friday sales,
running advertising campaigns to get
people to sign up for discounted plans and
stuff like that.
And people have been very vocal in the
community about how they don't like this,
like having banners in their inbox,
especially if they're like a paying
customer.
Some people have,
very strong feelings about that.
I think it's tricky because Proton is one
of those companies where they make all
their money from people buying
subscriptions.
And there are so many people that don't
buy subscriptions and it's kind of tricky
for them to be able to, you know,
stay afloat if they don't have that
constant stream of subscribers.
But I think the fact that they were
using, you know,
some sort of AB testing is obviously it's
not a privacy concern,
but it is one of these things where
it's like,
This feels a little shady.
It's one of these things that we don't
really like when it comes to marketing
tactics.
I think the most important thing here is
to not jump to immediate conclusions and
assume that Proton was being malicious in
this aspect.
I think Jonah had an incredible response
on this thread, by the way,
if you haven't read that.
His kind of take was A-B testing
objectively isn't adaptive slash dynamic
pricing nor price discrimination.
So this is like basically what he said
is it's basically effectively the same as
a targeted or limited time sale.
So...
you know, it's interesting.
I think Jonah had probably the most
level-headed response in that thread.
I think it's important to be a little
bit more discerning and not to jump to
conclusions immediately because this
wasn't as big of an issue as I
think people are making it out to be.
Personally,
I am not really a big fan of
Proton's whole marketing strategy when
they come to, you know,
promoting their products and their
pricing.
I think it's a little rough to be
paying
I was on the visionary plan,
but paying for the visionary plan,
still not getting everything in the proton
suite.
And I still, you know,
had some things that weren't included.
But I think it would also be kind
of annoying if, you know,
you're on the unlimited plan,
which is like two hundred bucks every two
years or whatever.
And, you know,
you're getting banners telling you to
upgrade and stuff like that.
I can see why some people might have
issues with that.
this sort of tactics,
but at the end of the day,
it doesn't compromise the privacy of the
product.
So it's not a huge concern from that
aspect.
So I don't,
I'm not sure if it really matters that
much.
How do you feel about it?
Are you kind of on the fence or
are you also kind of not a fan?
I mean,
I agree with you with the marketing.
Like I pay for the duo plan for
me and my wife.
And yeah,
we still get emails occasionally about
like, Oh, upgrade to the family plan.
And it's like, have what?
Just four accounts sitting around doing
nothing.
Like,
We don't know anybody that's willing to
take us up on it, man.
I'm sorry.
But yeah, I agree with you.
I don't know.
I think I think I'm with Jonah.
Yeah, I forgot about that response.
That is a really good response.
But yeah,
it's like it's it's if it's completely
random,
if it's not profiling you based on browser
or location or any of that kind of
stuff, in my opinion, I think that's fine.
I think it's the same as a sale.
Um,
as long as it's not targeting specific
people.
And even if it's not targeting Jordan and
Nate, you know,
if it's targeting brave users or Mac
users, or cause I,
I think airlines do that or somebody does
that.
They're like,
if they detect you're on a Mac,
they'll like raise the prices a little bit
online.
Cause they're like, Oh, you're on a Mac.
Clearly you must have money.
And it's like,
or maybe it was a gift.
Maybe I got it refurbished.
Like maybe I got it on a student
discount when I was in college.
Like, come on, man.
That's, that's crazy.
So, um,
yeah i i don't personally mind as long
as it's not actually based on any real
data and if it's totally randomized um i'm
a little disappointed to see wind scribe
kind of jump on this and attack other
privacy i i really don't like seeing
privacy projects attack other privacy
projects because to me it feels very
self-defeating like we're all the example
i like to put it in is like
if we talk about like putting it in
terms of real life security
Everybody shuts their door,
locks their door when they leave their
house, right?
If you leave your house,
you lock your door.
And yes,
that's inconvenient when you come home
with an armful of groceries and you have
to fumble with the key and unlock the
door.
But we all agree, like, why not?
Like, it's low cost.
It's very relatively low effort.
Like, it's not as convenient,
but it's safer to deter somebody.
And in the digital world,
most people are basically like leaving the
door wide open, unlocked,
opening all the windows and then hanging a
sign in the front yard that says gone
to Dubai for two weeks.
Like, and for some reason, you know,
for some reason we're busy like
complaining about, Oh,
you ran a marketing campaign.
And it's like, dude,
we're all trying to get people on the
same, like at least me, we're like,
we're just trying to get people to like
care at all to like shut the door.
And I don't know.
I just don't like seeing privacy
companies, uh,
attack each other like that.
If you want to attack the non-privacy
companies,
if you want to attack WhatsApp and stuff
like that, like go for it.
But
I don't know.
That was in poor taste, in my opinion.
But I digress.
Yeah,
I think it'd be better if people were
using Proton.
Then they'll be like, oh,
I don't want to use Proton.
Their marketing is so bad.
I'm going to go back to Gmail.
And it's like, well,
that's just not a good idea.
It doesn't work.
So I don't know.
I do think that it's important to hold
these companies accountable,
but also it is a little disappointing and
unprofessional when we see
like these organizations kind of taking
pot shots at each other.
I am not a fan,
but obviously that's up to these
organizations to work out in their
marketing and public image.
And it really does not to linger on
it too long,
but what ends up happening is for people
who...
especially if they're on their own and
they don't know who to trust,
they end up, like you said,
just quitting and going back because if
everything's like, oh,
don't use Proton because it's got this
minor thing wrong with it.
Don't use Mulvad because of this.
Don't use Windscribe because of it.
Like eventually they hit a point where,
like you said, they're just like,
screw it, I quit.
I'm just going back to what I was
doing because every time I use something,
somebody comes along and tells me that
sucks and I shouldn't be using it.
And it's just,
especially without knowing their threat
model.
And it's one of those things where like,
if they don't have somebody that they can
go to, like I have friends and family,
they hit me up all the time and
they're like, hey,
are iPhones really that private?
And it's like, well,
I know this person is never going to
use graphene.
So honestly, yes,
I'd rather you buy an iPhone instead of
like a crappy LG phone or something.
And it's just, people don't have like, if,
if you make it too hard,
they're just going to give up.
And yeah, it's,
it's not cool to see that happening in
the space.
I digress.
I'm getting off topic, but yeah.
So that was the thing.
And, uh,
just remember not to jump to conclusions
and, um, uh, uh,
another company,
it was another company laptop did another
company attack proton or a customer.
It was wind scribe, uh,
picked up this story and, um,
basically called out proton and said, no,
you are doing AB tests.
Here's the code.
But again, it's, you know,
it wasn't adaptive pricing.
That's which you can still say you don't
like AB tests.
That's fine.
I'm not telling you not to say that,
but I just want to make that clear
that like they weren't tracking people
based on browser or location or anything
like that.
It was just randomized what price you saw,
but.
I digress.
With that,
we're going to jump into a story about
Mozilla,
who had to issue new GPG keys following
an exposure, which is never fun.
That always sucks.
Let's see,
Mozilla announced on Monday that it had
issued a new GPG signing subkey used for
some Firefox and Thunderbird artifacts
after the previous key was accidentally
exposed in a GitHub repository.
The exposed key was used to sign Firefox
and Thunderbird artifacts,
such as Linux tarballs, RPM packages,
and checksum files.
An unencrypted copy was inadvertently
committed to a GitHub repo,
but it was a private repository accessible
only to a small group of Mozilla
developers who already had access to the
key via other means.
Mozilla said that our review of available
audit records found no evidence the key
was accessed by an unauthorized party.
Nevertheless,
they decided to revoke the exposed key and
issue a new one.
And in addition,
they said that they had added protections
to prevent similar incidents in the
future.
They do say that most users do not
need to take any action.
Users who manually verify GPG signatures
will have to import the new key and
revoke the old one.
And in addition,
those who use Firefox RPM packages may
need to take some steps,
which that might include me because I'm a
cubes user and everything's based on
Fedora.
So I should click that link.
And Mozilla has shared detailed
instructions right there.
Um, so yeah, I think, uh, um,
I will say this is a little bit
of a disappointing lack of transparency in
my opinion.
Um,
it sucks that they didn't really seem to
give a whole lot of details about how
did this happen?
How long was the key exposed?
Um,
I don't remember if they gave details
about what they did to prevent this from
happening again.
Um,
Um, but I,
I guess I will give them a lot
of credit for like coming forward with it
and being proactive.
I mean, it was like a private repo,
right?
So in theory, there shouldn't be any risk,
but still just being like, uh,
let's just be safe and rotate it.
Like I do respect that, but, um,
Jordan, to throw this back to you,
I think the first question that I think
a lot of people would have is,
do you think this is a reason for
people to reconsider using Firefox?
Is this like an oh crap moment that
shows negligence or anything,
or do you think this is just kind
of like things happen?
I think we've got to give Firefox a
decent amount of props here because they
did exactly the right thing.
There was a mistake.
Mistakes do happen.
There's always going to be mistakes,
but it's the way that they handled it,
which I think is the most important part,
which, like you said,
immediately rotating that GPG key is the
most important part.
And they did that.
They notified everyone.
They did exactly what they should have
done in that situation.
If, for instance, we found...
that they did leak that key and then
they just decided to do nothing about it,
then that's where we would start having
issues where I would be like, OK,
maybe you should probably not use Firefox
because they seem a little negligent.
But, you know, mistakes happen.
They fixed it.
They've done everything in their control
to notify everyone.
And, you know,
that's basically the best case scenario in
a situation like this and i think it's
it's always good there's always going to
be issues uh especially when it comes to
like you know supply chain attacks where
um someone can you know get access over
packages and stuff like that um i think
it's always important to be proactive and
be aware of what's happening but i think
in this case
It sounds like most users don't have to
be too concerned about anything apart from
the RPM packages and also people that
manually verify the GPG key,
which I'm sure if you're one of those
people,
then that's probably something that you'll
have to look into yourself.
But for everyone else,
nothing you have to do.
I think this is a good
Uh, this is good that Mozilla was, uh,
open and transparent about making a
mistake and fixing it properly.
So that's basically the best case scenario
in my opinion.
Yeah.
Supply chain attacks are really a whole
different animal.
Cause you know,
we always tell people to like,
make sure you use official outlets,
like get things from the official source
and whatnot, but like.
If it's a supply chain attack,
what can you do?
You really just have to hope that the
company is doing everything in their power
and they're quick to respond and kind of
sucks.
But yeah.
Before we jump into our next story,
actually,
we did get a quick question in the
supporter signal chat.
This person said,
for transportation in general,
is there anything we can do to be
more private about where we go?
And they said that, for example,
if you live in an area with public
transit, trains, metro, subways, buses,
all these things often ask for some
identifying information,
such as your name and phone number,
but usually lack the rigorous verification
processes that places like airports
enforce.
Like, you know,
usually nobody checks my ID when I get
on a bus.
A lot of the time they don't even
check if I paid.
They said,
is it a good idea to travel under
different names and use aliases wherever
you can, or are there problems with that?
And what are some other strategies we can
use to combat surveillance when traveling?
I mean, I'm not a lawyer.
I kind of view travel more from a
data breach perspective, you know,
because a lot of the time,
especially nowadays with things moving
into apps,
a lot of the time it's like you
don't,
physically,
like I'm pretty sure back where I lived
in Texas,
you couldn't even pay in cash for a
bus ticket.
I could be wrong.
Um, but whenever I took the bus,
I usually used an app.
And so at that point it's, you know,
using a, my pseudo number,
using a simple login alias, um,
trying to use a VPN,
just trying to think like if this app
has a data breach,
what information will it be able to
reveal?
I think I didn't even have to give
it location information.
I think I could just tell it what
bus stop I wanted to look at.
But, um, yeah,
I don't know.
That's kind of how I look at it.
Cause also I don't want to sound
defeatist,
but a lot of buses nowadays also have
cameras and your phone's tracking your
location.
So I don't know.
I feel like that's kind of overkill to
use aliasing information.
And I do wonder if there would be
any legal repercussions there.
Like it's one of those things where if
something goes wrong,
is it going to cause more problems that
your ticket doesn't match your ID?
I don't know, but yeah.
I also don't do a lot of public
transit because I live in America and
unfortunately our public transit is not
that great.
I would love to do more public transit,
but it's just not always feasible.
Do you have any thoughts on that question,
Jordan?
I would say there's,
I can't really comment on like,
I've never heard of any public transport
needing an app.
So try and avoid using an app if
you can.
I'm not sure if that's always possible,
but if you can avoid using an app,
I would say avoid that.
A lot of public transit systems that I've
used have always had a card that you
could use and you can top it up
with cash.
I'm not sure if that's also about,
like you'll have to do research into that
because a lot of places they'll have
different options available because,
you know, there's people that are like,
don't know how to use a phone or
don't have a phone.
So what do you do then?
Oh,
I guess you can't use the bus or
like, you know, it doesn't,
there's always,
they have to make some different options.
So
definitely look into that um i think the
most important part is also just um try
not to uh
share data with these transit companies if
you can.
Don't download the app,
don't give it your phone number,
don't give it your address,
don't give it all that information.
Try and minimize the amount of data that
you're sharing with those companies,
or if it's a public system,
then the government.
So I think that's also an important thing.
I think
I'm kind of a little bit biased,
but I do a lot of cycling and
no, no,
no personal information required to do
that.
Walking also no personal information
required, obviously, you know,
that is, like Nate said,
it kind of depends where you live,
if that's an option or not.
If you live in, you know,
a rural town,
I'm sure that's probably not as viable,
but that is another thing.
And I think, you know,
there's also so much information that you
can share when you're driving a car too,
like we've talked about with Flock, right?
You know, when you're driving around,
there's cameras everywhere,
recording your car,
recording your number plate.
It's also not a great
option either it's pretty terrible cars
are kind of terrible for privacy as well
they share a bunch of information so it's
just trying to like do harm reduction um
where you can
And obviously everyone has different
requirements because some people need to
drive, some people can't drive,
all sorts of things.
So it's just about reducing what you can
and not, like Nate said,
not going overboard because as Nate said,
there's cameras in the public transit
system.
There's all sorts of tracking that happens
through that as well.
And I'm sure somebody could work out
who you are, if they see, oh,
this person taps on it this time,
and then they just check the security
cameras and they can see it's you.
So, you know, there's, there's, um,
there's always a trail when it comes to
public transit.
And anytime you step out your front door,
you're basically going to be recorded.
So just take that in mind.
Um,
I guess we can jump here into the
next story though.
This is kind of a group of stories
this week, and it's about signal, um,
Signal making a bunch of new updates.
So this week I'll talk about the first
one and then I'll hand it over back
to Nate.
So this one is more linked devices are
on the table and the Android tablet.
Now you can easily link another Android
phone or Android tablet to your Signal
account.
We're also expanding linked device support
on iOS.
So you can link an iPhone to your
Signal account in addition to our ongoing
support for iPads.
look for Signal iOS version eight point
two two and Signal Android eight point two
in the app slash Play Store near you.
So I think this is one of these
things that we've all been like basically
begging for Signal to do.
And it was like,
one of these things that's so easy for
them to do as well.
And it's like a no-brainer for them to
enable this.
I think the most interesting thing about
this is that previously, you know,
a lot of people were complaining that they
would have to use MOLLE
instead of the official Signal app to be
able to link another Android device to
your account.
And now that feature has been expanded
officially to the official Signal app,
which is really important.
And it's better to be using the official
Signal app if you can.
just to reduce the amount of trust you
have to have in different projects.
So it's really cool that they've been able
to release that as a new feature.
Do you have any thoughts on this one,
Nate?
No, I just, yeah,
I think it's really cool.
I mean,
obviously everybody's in a different
situation,
but my first thought was at my last
job,
I used my iPhone as a work phone.
And so I would have my Android was
my personal phone.
And then my iPhone would have like teams
and all that crap on it.
And the only reason I had to carry
around the Android was because of signal,
because my wife exclusively uses signal.
And there was a period where I,
Um,
basically I got some feedback that I was
on my phone too much.
So I was trying to be on my
phone less and I had to go make
like a separate signal account for the
iPhone so that my wife could text me
there.
And it's like,
it'd be really cool if we could just
like, if this had existed at the time,
it's like,
I could have just put signal on my
iPhone and been good to go.
And so, yeah,
I think this is really cool.
I'm also thinking of the infamous time
that my phone exploded.
And I remember sitting there and going,
how do I recover my,
my signal account now?
And, uh, you know, thankfully it was,
it was pretty easy cause I had all
the, I knew the pins and everything, but,
um, yeah,
to just like have that backup and
everything is a definitely super,
super cool.
So, um,
before I jump into the next one real
quick, laptop said,
what's wrong with Molly?
There's nothing wrong with it or actually,
actually I'll turn that one over to you
since you're the one that said it.
Um, what's, what's wrong with Molly?
Um, obviously, you know,
when you're trusting a third party,
like with, with your,
with your signal chats and stuff.
So it's adding another party that you have
to trust, like in addition to signal.
Um, and also Norli has been,
unfortunately,
they've been a bit slow on keeping up
to date with signals updates.
So like,
that is also a concern from a securities
perspective.
It adds a bunch of interesting new like
privacy and security features,
but it does seem like, um,
you know,
it's definitely a risk analysis thing.
If the chats that you're having on Signal
are really important and secure and stuff
that can't leak,
then obviously you want to reduce the
amount of exposure that you could possibly
have.
So I think another important thing to have
to talk about in this story is just
the expansion of risk that happens when
you add linked devices to your Signal
account.
I think there's less risk when it comes
to adding a mobile device as a linked
device.
Whereas if you're adding a desktop device,
that's where we do have more concerns.
We've had stories in the past where the
local database on the Signal desktop app
was not encrypted or it's easier to access
on a desktop because it doesn't have as
robust permission system to restrict
access from malicious apps.
So every linked device you're adding is
increasing the attack surface.
That's one another thing to discuss as
well when it comes to this.
And like I said,
the MOLLE using MOLLE is going to increase
the attack surface because there's adding
another device and you're also trusting
another group of people to to manage that
app, which.
Is.
isn't the only party you have to trust
more or less because of the end-to-end
encryption, the client, I mean.
I mean,
there's the Signal developers and then
there's the MOLLE developers.
So you're trusting the Signal developers
to develop the Signal app.
And then Signal is based on, no, sorry,
MOLLE is based on Signal,
which then they also have to add code
on top of that.
So you are trusting MOLLE and
signal developers at the same time so
that's an extra party you have to trust
to make sure that they are not inserting
any malicious code for instance because if
your client is compromised then this this
the end-to-end encryption doesn't matter
because you know it's only end-to-end um
so that's why it's important um hopefully
that makes sense
And also, real quick,
I'm glad you mentioned the device raises
your threat model thing.
That is a good point.
But I just want to point out,
it's not even necessarily a malicious
thing.
It's just you have to trust them to
implement it correctly.
I don't know why this example just popped
into my head,
but if there's a Christmas gift,
and let's say I'm going to give...
I don't know.
Let's say I'm going to give my sister
a Christmas gift or let's say my wife
wants to give my sister a Christmas gift
and she wraps it up and hands it
to me.
And then for some reason,
I deliver it to my sister.
You have to trust me not to open
it.
Or in this case,
like for some whatever reason, again,
I don't know why this example popped in
my head.
For some reason, I decide to rewrap it.
You have to trust me to wrap it
right the same way that she did.
Like it's just it's more people involved.
It's more chances for something to go
wrong.
Even if it's not malicious,
it's just people make mistakes.
Yes, Mali is open source,
but are they auditing every single
release?
Is there somebody out there who's combing
through every single release?
Are there multiple somebodies?
Because the first person who combed
through it could have missed something.
It's just you're always...
there is always a level of trust involved.
Um,
you're never going to completely remove
trustless is kind of a buzzword in my
opinion,
because there is no such thing as
trustless.
You're always trusting someone somewhere,
but the idea is to remove as much
trust as possible.
So, um,
Yeah,
Dag here did mention that Mali can encrypt
local logs on the device, which, yeah,
I mean, Mali does some cool stuff.
And we're not saying don't use it.
It's just keep in mind those are the
trade-offs.
You're introducing another party into the
mix.
On that note,
we'll jump into the next quick Signal
update,
which is that Signal is introducing
automatic key verification.
Um, this is pretty cool.
So, uh,
this is supposed to compliment the
existing safety number system.
It's not supposed to replace it.
Uh,
it works through a system of verifications
performed by you,
your signal connections and third-party
auditors that together provide the same
assurance as manually verifying safety
numbers.
Unlike safety numbers,
these verifications are done independently
and do not require an in-person meeting or
secondary communication channel.
This system of verifications ensures that
the association between a phone number or
username and its public encryption
key is globally consistent and transparent
to all participants.
This protects against scenarios where a
key is swapped out without the owner's
knowledge.
For example,
a malicious party compromised signal and
associated a different key with your
connection's phone number.
There are technical details in the blog
post if you want to learn more.
I'm not going to go into them because
I'll skim here real quick and you can
see it's very detailed.
I actually do need to finish reading this.
They do try to break it down into
understandable terms,
which is super awesome.
And I do want to finish reading it,
but I'm not going to read it all
here.
They said to see it in action,
go to a Signal Connections profile,
hit view safety number and tap the verify
automatically button under the automatic
key verification.
The button will show a green check mark
and encryption verified when the feature
is available and verification succeeds.
Over time,
this verification combined with the ones
continually performed by your Signal
Connection and third party auditors
ensures the consistency of a Signal
Connections key across Signal ecosystem.
Uh,
I did try to test this out personally,
um, with one of my contacts,
I'm guessing they haven't updated yet
because it didn't let me, uh,
it was like grayed out.
Um,
I also have an issue where I'm usually
pretty good about actually like doing the
safety number thing with people just for
fun.
So I kind of had to dig through
and be like,
who have I not verified yet?
But, uh, yeah.
Um, that's what I've got here.
Uh,
I don't know if I have any thoughts
on that one.
Um,
Yeah,
I don't really have any thoughts on that
one.
Again,
it's just it's not a replacement for the
safety numbers.
Do you have any opinions of that one,
Jordan?
No,
I think this is just signal bolstering
their ability to verify contacts and
stuff.
I think it's always important to give
extra verification stuff,
especially because I'm not verifying every
single person in my contacts,
but I think it's also good to mention
what
why would you want to verify your
contacts?
Why would you want to do that in
the first place?
What benefit does this give, I guess?
And I guess that would be if somebody's
account gets taken over,
you can tell that their account's been
taken over because their safety number
changes.
That's one thing.
Um,
it basically allows you to know that the
person you're talking to is actually the
person that, you know, on the other end.
Right.
Um, so this automated like, um,
key verification system is, uh,
I guess just like another additional
layer, like you said,
it's not something that's going to replace
the safety number system, but it's like,
you know,
if something is going on with that,
if like there's an issue with the
encryption, then it's going to notify you,
I guess.
So I think that is,
is also important to have that.
It does kind of, I guess,
make me wonder if there's going to be,
further changes to how the the key system
works maybe uh is this like something that
they're gonna improve on more in the
future um i'm not really sure but i
think a lot of people are don't like
i see some people in my contacts who
their safety number constantly keeps
changing and it's like you know i think
if this system is able to kind of
keep it so that at least I know
that this person is going to receive the
message, like it's, I don't know,
it's just,
it's another thing that can help, uh,
verify that.
Right.
So I don't know.
I'm not really, um,
I'm not really super hyped for this
feature, but I think it's a good, uh,
increase in, in safety for some people.
Yeah,
it's definitely one of those behind the
scenes, not super sexy.
Like I'm not sitting here like, oh yeah,
but I'm just like, oh, okay,
that's interesting.
That's cool.
So yeah, I hear you.
It's not the most exciting thing out
there,
but it is cool to see Signal constantly
improving like that.
Yeah,
I guess talking about Signal constantly
improving,
there's another update here from Signal.
Signal is working on registration without
a phone number,
but what form will it take?
So this article here is from this
unofficial website called aboutsignal.com.
And basically what they've done is they've
put together this article that
basically shows every point where Signal
is working towards removing the phone
number requirement.
There's been hints in GitHub code that
Signal is exploring support for
registration without a phone number,
which, oh my goodness, if this happens,
I'm going to be so happy because that's
like one of the biggest issues that some
people have with Signal, right?
It's like, oh,
I don't want to give it my phone
number.
This is obviously a honeypot.
It's like, well, if they remove it,
then what's the argument at that point?
There is no argument.
And I think, you know,
I think this is exactly what we want
Signal to be doing.
We want them to be closing every single
loophole that pushes people away from this
app because we
We want people to have the most secure
communications possible.
I guess here's a rundown of what the
changes look like.
There's a commit here that said,
don't allow or set registration lock on
accounts with no phone number.
Add utility methods for getting country
region codes for accounts that may not
have phone numbers.
Add support for pessimistic locking of
phone number lists accounts.
Do not allow accounts without phone
numbers to perform P&I key operations.
Basically,
all those commits together show that
Signal is making backend changes to
support accounts without phone numbers.
registration without a phone number will
be optional.
So if someone is still wanting to use
their phone number to sign up, they can.
I think everyone in the privacy community
is not going to be using a phone
number.
So that's cool.
One issue that I did see with this
that is probably the most frustrating
thing is it looks like you can't convert
a Signal account that uses a phone number
into one that doesn't use a phone number,
at least from the information that we have
already,
which is
I think might become a bit of an
issue because if you're like me,
you probably have like a hundred signal
contacts or whatever,
like fifty signal contacts.
And if you have to start a new
account,
you're going to have to re-add every
single signal contact that you have on
your new account,
which is kind of a pain.
There's no easy way to do that.
So that's probably my biggest concern with
this.
It's going to be kind of annoying to
have to recreate your signal account.
I'm not really that bothered by this,
the phone number requirement.
So maybe this is just going to push
people that were kind of resistant to
using Signal over to using that.
I'm not sure.
But yeah,
I guess this is one of those things
that's like, Nate, you were saying before,
like, oh,
this isn't like a really cool and sexy
change.
This is that.
So how do you feel about it?
I feel pretty good about it.
One thing we should add is that this
article links to another article from
August seventh that's titled signal login
colon operational or optional registration
without a phone number will require one
time payment.
That's really it.
There's no information in the article.
It's just, again, speculating.
We don't know.
Presumably it will allow like Apple Pay,
Google Pay for convenience,
but we don't know if they're going to
allow like Monero or cryptocurrency or
something as an alternative.
Yeah, I think overall, I mean,
I'm definitely a fan of this.
Me personally, I think I'm a little bit...
paranoid again having had my phone explode
and like so much of my life is
in signal i'm kind of okay with like
yeah i'm just gonna leave my phone number
there as a backup just in case i
don't think my threat model is so high
that i need to get rid of the
phone number but yeah it is it does
kind of suck that you won't be able
to remove a phone number um i do
wonder if uh i wonder if that's like
a technical thing that there's just like
really no way for them to pull it
off or maybe that'll be something they do
down the road i'm not really sure but
um
I don't know,
the phone number thing has never bothered
me too much,
but also I recognize my privilege of
living in America where I can have as
many phone numbers as I want and I
don't have to show ID to get a
SIM card and stuff like that.
I think...
I think Signal did the best they could
to protect that information in the sense
that like phone numbers are hashed.
So the government can't go, hey,
give us a list of phone numbers or
like, you know,
give us a list of these people.
But there's nothing stopping the
government, again,
going back to countries where you need to
turn over ID to get a SIM card.
There's nothing stopping the government
from going, hey, here's a phone number.
Do you have this as a user?
And they can confirm or deny that,
which is unfortunate.
It's also,
they say that it's the goal is to
prevent spam.
But again,
Spammers don't care,
so what's to stop them from just creating
infinite VoIP numbers and creating Signal
accounts?
I don't know.
I've never really had a spam problem on
Signal,
but I've heard that some people have,
so I don't know how effective that
actually was.
I don't think it's fair how much heat
Signal took for this.
Like you said, people are always like, oh,
it's a honeypot.
I think people confuse anonymity and
privacy way too much.
Signal never promised you to be anonymous,
but it is private.
It protects you, but
Uh, still, I think this is a win.
I think for people who don't want to
turn over a phone number for any reason,
whether it's a perfectly sensible one or
just paranoia, it doesn't really matter.
I think that's great that they have this
option and I just hope that they will
support some form of private payment
option because otherwise I,
I think it's kind of a hollow victory.
If it's like,
you don't have to hand over your phone
number,
but now you have to pay through the
app store,
which is even less private than that in
most cases.
So yeah,
I think those are kind of my only
thoughts.
Yeah, totally fair.
It'll be interesting to see how this ends
up rolling out.
I'm assuming that we'll probably get
something in the beta slash alpha channel
at some point where we'll be able to
check out this and definitely make sure to
get subscribed here on YouTube or whatever
platform you're on.
And we'll have updates on that as it
rolls out.
But yeah,
that's kind of everything on that one,
unless you had anything more to add.
I just wanted to mention what Jonah said
here.
But yeah,
everyone hates three month for this.
He's got a point if, if, I mean,
to be fair,
I guess signal offers the alternative,
right?
Like you can use a phone number,
but yeah, a lot of people,
I haven't seen so much hate for three
month because they charge,
but I've seen a lot of people point
out.
It's like, yeah,
it's a tough sell to get your family
to spend five dollars on a messenger or
whatever.
So I don't know if there's pros and
cons, but yeah, he's,
he's got a point there.
Uh, speaking of anonymity,
what do you think is the best messenger
to use with a pseudonym?
Um, I mean,
I think I have a thought on that.
Do you have a thought on that one?
I mean, I have a thought.
Yeah.
Why don't you start us off here?
Probably, probably simple X.
That was the first thing that came to
mind for me is SimpleX doesn't require any
information to sign up.
Decentralized.
Actually,
one thing I do like about SimpleX that
I... Oh my God,
I would kill for Signal to introduce this
is SimpleX does...
different profiles that are all managed if
i understand it correctly i haven't used
it a ton but there's like different
profiles but they're all managed in the
same inbox so like i could add you
on simplex as nate and then i could
add like my wife on simplex under my
real name and i'd use them both from
the same screen but you guys would both
see a different identity which is just
like holy crap that is amazing if if
i'm understanding that correctly i might
be wrong but um
Yeah, no,
it's interesting because I have this
problem.
I won't go super into depth about it,
but I don't go by the name that
I use on here in real life.
And sometimes I have to add people on
Signal and I'm like, oh, yeah,
so that's like my name,
like not like the name that you should
call me,
but like that's another name that I use
and people are kind of confused.
And it's good when it gives you that
option.
to basically have another name appear or
like you said that would be really cool
if you could just have it like be
able to choose how you appear to that
specific person um that does sound really
cool actually I really hope that that's uh
that's something that Signal could add
because it's an issue with Signal I know
like
I don't know if you want to talk
about it a bit,
but I noticed you definitely do have an
interesting strategy regarding that on
Signal.
And I've thought about doing that because,
like,
sometimes I don't want to share what my
real name is with people,
and it's kind of one of those issues.
I guess we should just quickly,
before I swap it back to you here,
though,
we should probably discuss what are our
recommendations for
right now on privacy guides so like you
said there's SimpleX which does offer the
ability to do that so that was probably
the main recommendation that you could use
for that as far as I know none
of the other recommendations really give
you that option
So yeah,
basically what Nate said is SimpleX is
going to be your best option,
the only option really in our
recommendations.
So definitely at least test that out.
I've used SimpleX before.
It works quite well.
I think it's definitely not on par in
terms of usability to Signal.
So maybe you can talk a little bit
about your interesting strategy that you
use.
If you want, it's up to you.
No, that's fine.
Yeah, so my thing on Signal...
Cause for a while I had like a
personal one and a new oil one.
And then for some reason,
I think I just wasn't,
I think actually what it was is like,
as the privacy side of my life has
slowly become more of a main important
part.
Um,
I wanted more like instant access to
things like, uh,
especially when Henry and I worked
together on surveillance report.
Like I didn't want to wait until I
got home at the end of the day
to get messages from him.
So I started using my personal signal
account a lot more for,
for new oil stuff.
And, um,
I think there was even like something else
I started using it for.
I can't remember,
but I started using it for another thing.
And I,
I am that psycho who uses different names
in different parts of my life.
So I'm very open about the fact that
Nate is not my real name.
And I use different names for like music
and writing and stuff.
And so I hit a point where, yeah,
I had like all these different signal
accounts, like,
or like different parts of my life
converging in signal.
And the way I decided to get around
it was to just make my display name
was the man with many names.
Um, because I did realize I'm like, yeah,
most people know, uh,
especially once they get to know me,
you know, I'm like, yeah.
So I have this, I work in privacy.
I go by Nate.
And like, when I tell people, it's like,
yeah, I have multiple names,
which weirdly people are not surprised by.
I don't know what that says about me,
but, um,
It's a, yeah,
it just hits a point where it's like,
people are just kind of used to it.
Like, oh yeah, the man with many names.
Cause they know it's true.
He has so many names and it, uh,
yeah, that's how I got around that.
But I mean, a lot of people,
you know, put a nickname or X or,
you know, anonymous or whatever, um,
as the display name,
but it's definitely not as,
as robust of a system as the profile
thing from simple X,
which laptop here said,
I think you actually have to switch
screens for profiles,
but I still think it's easier with
it's still an easier implementation than
like having signal and Molly or having
like different graphene profiles or,
you know,
all these different ways of doing things.
So.
Yeah.
It's been an issue that I've been running
into where I've got like,
two Signal accounts.
And then I'm like, oh,
but then I can't talk to someone using
another one because it's got that name on
it and it's got things that would reveal
other information that I don't want to
share.
So it is kind of frustrating if you're
stuck using something like Signal.
It's like, oh,
if it had that as a feature,
that would be great.
But it's just not something that Signal
supports right now.
So you're kind of stuck with using SimpleX
Chat,
which
do recommend on our site so definitely
check that out if that's something that
you um jonah said just make all your
names start with the same letter and your
signal profile can just be n or something
yeah yeah but then the problem is i
like to randomly generate my names that
way there's no um there's no like
You know how it's like people aren't as
random as they think they are.
So if you try to like randomly come
up with passwords,
they're probably not going to be as random
as you think you are.
And I don't know.
I just, I'm, I'm weird about it.
I literally just use a random name
generator.
So I'm kind of at the mercy of
what that comes up with.
I know I'm a, I'm weird.
You know what though?
It's working.
Like I said,
like a nine out of ten times people
are just like,
they don't even bat an eyelash.
So yeah.
And I've,
I've had multiple people in different
situations be like,
who does this person know yet?
Like they'll meet somebody new,
like a friend or something.
And they're just like,
what name do they know you as?
Um, laptop,
does simple X have multi-device yet?
Not exactly.
It has, um,
like they have to be on the same
LAN and you can like scan a QR
code and connect them.
Um, but technically yes.
So, yeah.
Let's see.
If anybody has any last questions,
go ahead and drop them now.
I'm looking at the privacy guides.
I'm looking at the forum thread.
No new questions in there.
And I've had the signal chat open as
well.
I mean, if nobody has any questions,
I'll go watch the latest episode of Silo.
Damn, yeah.
I'm not seeing any questions in here
either,
so I feel like we can start wrapping
it up.
Just a reminder, though,
if you are a member,
Privacy Guides member,
that we do have a signal group and
you can ask questions there.
If you don't want to share the question
publicly or anything like that,
definitely consider asking.
posting in there if you're a member and
you want to hear what we have to
say about a topic then feel free to
do that oh looks like we got a
question here from terracotta pie should i
be concerned with linkedin requiring me to
verify my id with persona after changing
my email um it depends right like i
think
It obviously sucks because Persona is a
really suspicious company.
Every single age verification or ID
verification company is pretty suspicious.
And I think Persona has been shown to
be linked to some weird stuff.
And not particularly surprisingly,
it obviously has concerns about data
privacy because you have to submit your ID
to them.
So I think...
It depends on how much you need LinkedIn.
I think there's some industries where it's
like if you don't have a LinkedIn,
you're basically never going to get a job.
So if you have connections through
LinkedIn that are really important,
then obviously you need to make a decision
based on that.
I think LinkedIn is one of those
platforms that I think it really depends
on the industry that you're in and you
know having professional connections is
important right if you want to find a
job so it's kind of up to you
I personally
have given LinkedIn my ID.
So I don't know,
I think you got to,
you got to weigh up,
you got to weigh up the downsides and
benefits for that yourself.
And if it's,
if you don't really have that many
connections and you're not really using it
that much,
then maybe it's time to let it go.
But if you do need it for like
professional connections,
then I would say it's probably a good
idea to
uh to do it unfortunately it kind of
sucks they're forcing your hand so jonas
said watch silo live on stream i'll do
it man i was gonna say what if
we uh what if we do it in
the the supporters chat in the signal chat
i'll just stream it there so you know
sign up for a membership and you can
watch silo with me every week
Um, yeah, I just,
I just want to echo what you said
about the, um,
like sometimes you got to do,
I I'm with you.
Like, I don't even have a LinkedIn.
Thank God I haven't needed one, but I've,
I've met people that say that same thing.
It's like, yeah,
no LinkedIn is where I found like my
last four jobs.
Like it's,
it's really critical to my industry.
And unfortunately at the end of the day,
you have to make sure you're taken care
of.
Like,
I mean,
I guess if you want to go live
out of your car or be homeless because
you just don't want the data brokers to
have an address, that's on you.
But seriously, jokes aside,
if your privacy is so extreme that it's
holding you back from getting a job,
advancing in your career, finding love,
having a family,
having stable mental health,
and I'm being a little bit joking but
also serious,
that's when it's gone too far.
Yeah.
Um, yeah, if you don't need LinkedIn,
if you don't need to give them your
ID, then please don't.
But if,
if that's the only way you're going to
be able to like keep food on the
table, then by all means,
you gotta do what you gotta do.
So, yeah.
But, uh,
let me check the forum post again.
Nothing yet.
I do like that the forum automatically
updates every once in a while.
There have been a couple of comments since
we started.
And they're not questions.
They're just comments to other users.
But I like that I don't have to
refresh the page.
I just pull it up,
and it's automatically like, boom,
new comment.
I think that's pretty awesome.
But I think that's all we got.
I guess we'll go ahead and call it
a stream.
So all the updates from this week in
privacy will be shared on the blog every
week.
So sign up for the newsletter or subscribe
with your favorite RSS reader if you want
to stay tuned.
For people who prefer audio,
we also offer a podcast available on all
podcast platforms and RSS.
And this video will be synced to PeerTube.
Privacy Guides is an impartial nonprofit
organization that is focused on building a
strong privacy advocacy community and
delivering the best digital privacy and
consumer technology rights advice on the
internet.
If you want to support our mission,
you can make a donation on our website
at privacyguides.org.
To make a donation,
click the red heart icon located in the
top right corner of the page.
You can contribute using standard fiat
currency via debit or credit card or opt
to donate anonymously using Monero or your
favorite cryptocurrency.
Becoming a paid member unlocks exclusive
perks like early access to video content
and priority during the Q&A.
You'll also get a cool badge on your
profile in the Privacy Guides forum and
the warm,
fuzzy feeling of supporting independent
media.
Thank you so much for watching and we'll
see you next week.
See you next week.