The Pixel 11 is Here, Will it Support GrapheneOS?
E66

The Pixel 11 is Here, Will it Support GrapheneOS?

Will the Pixel XI support Graphene OS?

Is your Firefox install compromised?

Will Signal allow a way to register

without a phone number?

All this and more coming up on This

Week in Privacy, so stay tuned.

Welcome back to This Week in Privacy,

our weekly series where we discuss the

latest updates with what we're working on

within the Privacy Guides community and

this week's top stories in data privacy

and cybersecurity while taking questions

from viewers like you.

I am Nate,

and with me this week after a bit

of an absence is Jordan.

How have you been, Jordan?

Good.

Just been super busy with video content on

the back end,

but really excited to hop back on here

with you to discuss the latest privacy and

security news.

Yeah,

there is a boatload of stuff happening

with videos that we will definitely get to

later on in the episode,

but it is good to have you back

for sure.

Um, I guess with that,

we'll go ahead and jump right into our

first story, which is about the new pixel.

And, uh,

I believe you're going to be taking that

one first, Jordan.

So I'll turn it over to you.

Yeah, let's dive into that.

Um,

so this story here is about Google's new

pixel, eleven series devices.

I'm quoting from this.

Google says the tensor G six delivers up

to twenty five percent faster browsing

and fifteen percent faster app loads

compared to last year's Tensor G-Five.

The Tensor G-Six is the updated system on

a chip in the Pixel-Eleven series of

devices.

The chip pairs with an upgraded image

signal processor with a new TPU,

and Google says it's fifty percent more

powerful than the previous generation,

enabling features like a hundred and

twenty times pro zoom,

instant night sight on the pro models,

and this new

This TPU chip also drives Gemini Nano,

Google's on-device AI model,

which the company says now runs with

higher quality and lower latency.

But the most important thing that we

wanted to highlight from this story is the

Tensor G.

works alongside a new Titan M three

security processor built for post quantum

cryptography,

which Google describes as protection

against emerging highly advanced digital

attacks.

And the company adds that the Titan M

three has earned common criteria

certification at the same level that's

used for SIM and bank cards.

The chip also handles quantum safe secure

boot and runs trusty Google's trusted

execution environment on all four phones.

So this is always a thing that happens

every time Google announces a new device.

I guess we should dive into the most

obvious thing and the question that we

have as this week's episode is,

Will this support Graphene OS?

So I guess I'll throw this back over

to you, Nate,

and we can kind of discuss this a

little bit.

Is this, you know,

what's the timeline going to look like for

this?

Do you think it's something that we can

expect soon?

What are the updates that Graphene OS has

shared so far?

Yeah, so I guess I'll...

I guess I'll lead with the answer,

which is, honestly, we don't know.

For those who may be just joining us

or haven't heard, Google last year,

I think it was, mostly last year,

made a lot of

changes to their policies that kind of

shoot all android developers in the foot

or at least um android roms like graphene

calyx lineage which is uh they slowed down

the number of releases that they're

publishing for uh the aosp project um

they've i think they slowed down the

number of security patches too but i could

be wrong about that um they uh

they stopped publishing the pixel device

tree specifically.

So basically now they have to like reverse

engineer all the hardware changes.

And then on top of it,

they made a lot of the development closed

source.

So it used to be that they did

all their merge requests and everything

up,

or I may be using the wrong term

there, merge requests,

but they did all their development stuff

in the open.

So people could kind of see like, okay,

they're working on this,

they're working on that.

We could also push back if we're like,

hey,

why are you adding this feature that

sounds sus?

now instead they're doing it all closed

and then just every so often they're like

all right here's an aosp update publicly

so it's still technically source available

in open source it's just now we don't

get to see what they're doing until

they're done and between all of that uh

graphene at the time pixel ten was the

newest one and they were basically like

look you know we'll support the pixel ten

but we don't really know what the future

is going to hold because of all this

and

Um,

they said that they want to keep trying

to support pixels as much as they can,

but between that, and there's also,

it's worth noting,

there are other hardware changes to the

pixel, uh, to the pixel XI,

aside from just like the tensor and the,

the Titan chip.

Um,

the most notable one that I've seen people

mentioning is they switched the modem.

It used to be a Samsung Exynos,

I believe.

And now it's like a MediaTek something.

So yeah, it's, I mean,

even Graphene themselves have basically

said like, look,

we're not going to know until we actually

have a Pixel XI in our hands.

And then we can like kind of take

a look at it and see.

I think you shared,

if I can go find it,

you did share in our chat from the

Graphene forums.

It was like there when they were keeping

people updated.

Yeah, so here it is on screen here.

I've got the link here.

If you want to take a look at

that.

Yeah.

Okay.

Yeah, so if we look here,

it's kind of a timeline of the events

that happened to get this support for the

Pixel X,

which I guess we can kind of extrapolate

somewhat to the Pixel XI.

So if you don't know,

the Pixel X was announced on August,

August, August, August, August, August,

August, August, August, August, August,

August, August, August, August, August,

order and confirm that it supports

unlocking.

So, you know,

at this point it's been not even a

week yet.

So we don't really know what the outcome

of that's going to be.

If the devices will be unlockable,

we can assume that it might be,

but obviously the GrapheneOS team hasn't

actually gotten the devices yet.

So if you scroll all the way back

up to the top, January,

is when it was considered stable.

So a couple of months, four months,

pretty much what we're looking at here for

the Pixel X.

So I would not be buying a Pixel

XI if your immediate need is to run

Graphene OS because from their previous

experience doing this,

it took four months.

It may take less.

It may take more.

We don't really know because like Nate

said,

it's all stuff that's like

not information that we know at this

point.

And also like, you know,

they have to reverse engineer that.

And one other thing I quickly wanted to

share as well is GrapheneOS did do a

post on Twitter and they said,

the PIX-Eleven hasn't been released yet.

We aren't going to have an idea about

how long it will take until after we

have access to devices and the code.

We'll post about it on our feed when

we have information to share.

No need to ask us for updates since

we'll make posts about it.

So that's kind of the current situation,

unfortunately.

which is kind of,

it's good to know that they're going to

post updates,

but we don't really have a huge amount

of information at this point.

Yeah, for sure.

And one other thing that's worth noting,

for those of you who are not following

us on any of our social media,

we did actually push out a quick short

about this whole thing.

Google, or excuse me, not Google,

Graphene has that whole...

their partnership with Motorola now.

And so that could really play into this

either way.

Um,

It could be that because of that

partnership,

they're able to get their hands on certain

software resources like AOSP.

Maybe they can get a copy of AOSP

from Motorola early,

and that will help them speed up the

timeline.

Maybe they're able to take advantage of

some of their expertise.

I don't know.

Or maybe they'll just hit a point where

they're just like, screw it.

If Google's going to make it this hard,

we've got this other manufacturer that

we're working closely with,

and we have

complete insight into the whole process.

We really, really don't know.

But yeah,

I just wanted to make sure that's a

mention too.

It's part of the math, I would think,

but we don't know what part of the

math.

Yeah, fortunately,

I don't think we have to wait too

long for the pixels to ship.

They usually the preorder, I think,

is usually just a couple of weeks before

they start shipping.

So hopefully by the end of the month,

we'll we'll have an update.

But yeah.

Yeah, I guess kind of somewhat off topic.

But what do you personally think of the

devices?

Is this something you're going to be

preordering?

Are you going to be upgrading this this

year or no?

Um, probably.

So my wife and I both have the

pixel six a,

which I think stops getting support in

July.

I was looking at the pixel eleven.

So I'm the kind of person that I

like to buy the newest one just so

that way I've got like the longest amount

of security updates and stuff.

And then I'll run that into the ground.

So I'm probably going to get the eleven

a whenever they announce it.

Although my wife jokingly,

I sent her the eleven fold and I

was like, oh, we should get you this.

And she was like, unironically, yes,

that looks so cool.

I would happily buy that.

So I think what we're going to do

because we don't really have a thousand

dollars to drop right now.

I think what we're going to do is

probably wait until the twelve fold.

So like next year's phone and then go

ahead and order that for her and I'll

just get the eleven a.

Because I don't really care.

I don't need my phone to do a

whole lot.

But she likes to play some games.

She has ten billion pictures of the cats.

Like all that kind of stuff.

So she could use a little bit nicer

of a phone.

How about you?

The main thing for me.

So I do have.

I kind of have a bunch of phones.

Because obviously we need to do testing.

On different devices and things.

But the device that I do have.

Is a Pixel Nine Pro.

And I think the funniest thing.

About the Eleven Pro.

is that it starts with twelve gigabytes of

RAM,

which is less than the nine and the

ten.

So you're actually getting less RAM on

this year's model unless you pay more.

So I don't know.

I was not really impressed.

Let's just say that is a little I

know that RAM prices are getting high and

stuff,

but like if you're decreasing the amount

of RAM,

on a pro device, um, year after year,

then I dunno, that's,

that doesn't leave a very nice taste in

my mouth, but yeah,

I've got five years of,

of security updates left,

so I'm not in any rush to,

to go and upgrade.

And I've never really had any issue with

performance or anything.

Um,

so I am not going to be upgrading,

uh,

unless Google does something like really

cool, like, you know,

there's like some really massive security

feature that they add, which, you know,

the, the,

the Titan M three security process is

really cool and stuff,

but it does seem like it's not,

you know,

a massive leap in security that that would

be worth spending my goodness,

a thousand dollars or more on a new

phone.

Um, so, you know,

I'm always trying to get them secondhand

and not, um,

Not give Google money because, yeah,

Google, not a great company.

But, yeah,

so I guess we could also talk a

little bit.

You did put together like a short this

week kind of describing a lot of what

we talked about this week as well,

if you want to dive into that a

bit.

Oh, yeah.

I mean, there's not really much to say,

to be honest.

Let me see if I can pull it

up real quick here.

But yeah, I just...

Every once in a while when there are

these big announcements,

like the graphene thing or the...

excuse me,

the graphene siding with Motorola thing or

this announcement,

we try to make sure that we get

some kind of video out pretty quick.

There wasn't really a lot about the

privacy and security this time around.

Like you said, the Titan,

it's got the post-quantum cryptography

stuff on it,

but that's kind of future-proofing and

getting ahead of the curve.

It's not something that everybody needs to

run out and buy right now.

There wasn't really enough to justify a

whole video, but yeah,

we did put out this...

this short here,

which is not on this channel.

I'll have to go find it.

But yeah,

we just put out a little short video,

kind of giving people a quick rundown of

all this new stuff.

So I don't know,

that's a I don't think there's too much

to say about that one.

Yeah,

I guess we can just cover this comment

here from Dag Overhaul.

Pixel XI looks like a downgrade from the

Pixel X, lol.

Yeah, it's like what I was saying.

The Pixel X looks like it might be

better in some aspects.

It's obviously we don't really know the

specifics yet on performance and things

because...

you know,

I think it's only being given to like

people that are media and, you know,

they're obviously going to have tainted

opinions cause they've gotten a free

product from Google.

So let's wait and see, um,

what that looks like.

But Google's never had good performing

devices and, oh yeah.

So here's the, um,

here's the short we put out, um,

that Nate put together.

So, uh, yeah,

if you want to share that with people

in your, in your life about this,

about this new release and that'd be cool

too.

Um,

Yeah, I think it's some interesting news.

We wanted to cover it kind of as

the highlight this week because I feel

like everyone in the community is probably

going to be having this question.

So yeah,

so Dag says it's twelve gigabytes of RAM

versus sixteen in the Pixel X. Yeah,

that's what I was saying.

It's like it's actually wild.

It's kind of ridiculous that that's

something they decided to do.

Yeah, for sure.

NotThatPrivate asked,

what post-quantum cryptography algorithm

does the M-III use?

From what I can tell,

it doesn't look like they've disclosed

that yet.

I think they're still planning to publish

a lot more technical details.

This was just kind of the initial get

people interested, which is also why,

like you mentioned,

there's probably some tech YouTubers that

have this and stuff,

but they kind of focus on the hardware,

the performance, and everything.

Yeah.

Um, it looks like the open Titan chips,

um, this comes from the AI summary.

So I apologize if this is wrong.

It says the open Titan chips,

which is Google's open source route of

trust currently use Sphinx plus also known

as SLA SLH DSA or FIPS two Oh

five for post quantum and secure boot with

future extensions planned for lattice

based schemes like dilithium and Kyber.

So, um,

if that helps a lot of the,

the more technical stuff goes way over my

head,

but

Yeah, I think just keep an eye out,

and I'm sure they'll be releasing more

details in the near future.

Yeah,

I guess we can dive into some quick

forum threads here.

There were some people asking some

questions and saying, you know,

some comments.

Do you want to just grab one of

those real quick?

Yeah, sure.

So we posted about this on the forum,

discuss.privacyguides.net.

There's a good place to go and ask

your questions in advance if you won't be

able to watch the stream.

And we had a couple of comments

speculating, again,

on whether or not Graphene will support

it.

Um, but, uh, yeah, I mean,

it's mostly just that.

So one person said that they think

graphene will support it.

And they cited,

I think the same quote that you cited

earlier from Twitter where they said it

hasn't been released yet.

We don't have an idea how long it'll

take.

Um, somebody else said, I think not.

Uh, somebody said,

I'm crossing my fingers that the eleven

will be supported.

Titan M three and graphene could be a

match made in heaven.

So, um, yeah, that's kind of it.

Sweet.

I think that'll take us into our next

story here.

And we're going to talk about the White

House

is potentially allowing cybersecurity

firms to do offensive hackbacks,

which is new.

This is never beneficial before.

So on Wednesday,

the National Security Presidential

Memorandum was signed that instructs the

National Coordination Center to establish

a program that would allow private

security companies to apply for approval

to hack foreign cybercrime organizations.

Let's see,

the program will be overseen by executive

directors designated by the justice and

Homeland security departments and security

firms participating in the program will

undergo vetting before entering into

contracts with one of the two departments.

Additionally,

the memorandum requires procedures

ensuring operations comply with US

constitution,

federal law and international obligations.

Participating companies will have to

maintain a bond or escrow of at least

a million dollars that will be forfeit

forfeited if they don't comply with

contractual agreements.

And they must also immediately stop

operations if they discover activity

exceeding approved limits,

including unintended target of US citizens

or US based systems and notify the

National Coordination Center.

The White House said the program is

intended to disrupt foreign criminal

organizations involved in ransomware

attacks, phishing campaigns,

financial fraud.

extortion schemes and impersonation scams.

And it added that us consumers have

reported losing more than twenty point

eight billion dollars with a B to cyber

enabled crime in twenty twenty five.

So this is this is a bit of

a departure.

Because up until now, I mean, yeah,

like nobody has ever authorized

like this.

That's kind of what they're calling it.

And I don't know.

This is just really...

It's hard for me to put into words.

It's one of those things where it's very

aggressive and it's very...

I mean,

I think there's a lot of questions here.

Like for one, this kind of blurs,

or I should say further blurs the line

between government and private companies,

right?

We already have so many issues with all

these defense contractors and surveillance

contractors,

Flock and Palantir and all these data

brokers.

And there's already like a very blurry

line, especially in the military, right?

Between like private contractors and

government.

And when you have a private contractor

acting on behalf of the government,

that's definitely a

not cool.

Um,

I have questions personally about

differentiating cyber crime from state

sanctioned activities.

Like this is companies are notoriously

cautious about, um,

about attributing cyber attacks to other

countries.

And some of that is a political thing.

Like you don't want to accuse somebody of

something unless you're a hundred percent

positive, but also at the same time,

it's just, it can be really hard.

Like code is code and there can be

little indicators

based on patterns,

but it's really hard to definitively say

like this company or this group was behind

this attack.

When an organization comes forward and

attributes a cyber attack,

it's a pretty big deal actually.

And especially I'm thinking of like North

Korea, for example, which for the record,

I'm not defending this,

but North Korea largely funds themselves

by like Bitcoin theft and scams and stuff

like that.

Like their government has been so heavily

sanctioned.

That's the only way the country can make

money anymore and stay afloat.

And so that just feels like a gray

area to me where it's like, okay,

if North Korea hacks Coinbase and steals a

bunch of Bitcoin,

is that a cybercrime or is that a

state-sponsored attack?

And are they allowed to hack back or

not?

Because it does... I mean,

I didn't read the memorandum itself.

I probably should.

But this article didn't say anything about

attacking state operations.

It said trying to deter cybercrime and

disrupt cybercrime.

So like...

I don't know,

that just feels like a really big gray

area to me.

And the other thing that they noted in

here is that this could cause perverse

incentives.

Like a million dollars for most company is

not really much.

I mean,

we see companies get fined millions of

dollars for privacy violations and it's

just a cost of doing business for them.

So this whole idea of like, oh,

you have to put down a million dollars.

That's like telling me I have to put

five dollars in as a deposit to get

somewhere.

Like, oh, five dollars in,

five dollars back.

I don't even care.

It's five dollars.

Keep it.

Like, I'm not that hard up for money.

So

Yeah.

And what was it at the very end?

One of the people they interviewed said

that they described it as a perpetual

motion for billable threats.

So the idea is that private firms might

have a financial incentive to create or

exaggerate threats to justify their

contracts,

which we already see that happening a lot.

So yeah.

Yeah.

And this is,

I'm assuming you added this here, Jordan,

but at the end of the notes here,

we have like,

why is this still important for people

living outside of the United States?

Which is a really good question.

And I think it's just because this really

raises,

this raises the possibility of something

going wrong.

If a private company attacks a

Um, let's say they attribute it to,

I don't know,

China and they hack a Chinese company and

China says, no, we weren't behind this,

whether they mean it,

like whether it's true or not,

if China insists,

like we are not behind this,

that could escalate things.

And it's just,

the world is so closely interconnected now

that.

everything i mean we've been seeing it

play out for the last couple years right

it's like everything that especially big

countries china russia uk us everything

that we do has knock-on effects to other

countries around the world so it's just

one of those things where like i i

feel like there's so many opportunities

for things to go wrong there's so much

and especially in the cyberspace you can't

physically see where you're at right i'm

gonna digress real quick um darknet

diaries did an episode where he talked

about he's done a lot of episodes where

he talked about um

pen testers.

And one of them that stuck out to

me specifically was they were hired to

test a hospital.

And they talked about all the different

systems they got into.

And one of them,

they didn't know what the system was,

but they wrote it down in their report.

And they mentioned like, oh,

we got into this system.

And that particular system,

as soon as they said that,

everybody was like, wait, what?

Which one?

Hold on.

We'll call you back.

And it turned out they had hacked into...

I think it was like a laser machine

being used for surgery,

like actively being used in a surgery

while they were in the system.

And thankfully they didn't do anything.

Like they just went in and they were

like, all right, make a note.

We got into this,

move on to the next target.

And,

but that just kind of shows that like

when you're in cyberspace,

you're looking at an IP address,

you're looking at a server name.

You can't tell if that's in Beijing or

Moscow or Uganda or Germany.

Like you don't know necessarily right off

the bat.

So I think there's just a lot of,

a lot of room for things to go

wrong here for people to get caught up

in crossfire for uh tensions to escalate

um yeah i don't know that's that's kind

of my take on this thing i don't

know if i missed anything on this story

that you had any more thoughts on but

yeah no i don't really have anything to

add but i think it's uh definitely an

important discussion to have um

And I guess I would say,

what can people do about this?

Is this something that people can have a

say about?

Or is this something that's kind of just

been decided without any review from the

public?

I don't know, to be honest with you.

I would imagine...

maybe somebody who's a lawyer can correct

me.

I would imagine that this is probably

going to get challenged by somebody in

court, um,

just for being like reckless and scary and

possibly like some kind of international

illegal thing.

Not like we seem to care about that

these days, but I don't, I don't know.

I don't know what the average person can

do other than just the usual advice we

would give to anybody, which is, you know,

try to keep your stuff updated,

try to keep your stuff, uh,

good passwords and stuff.

Try to keep your stuff as relatively

hacker proof as possible.

Um,

I don't want to sound paranoid,

but maybe a little disaster prep.

I mean,

we've covered so many cyber attacks that

take down, you know, hospitals,

fuel pumps,

just kind of having like enough basic cash

and food on hand to get you through

a few days is really not a bad

idea ever for anybody.

Because you never know if a cyber attack

will bring down the payment systems or

whatever.

So

I don't know.

I don't know if we, the people,

have a whole lot of options here.

You could maybe try contacting your

representatives and being like, hey,

this seems bad.

Can we not do this?

But I don't realistically know if there

are any laws being violated here.

Right.

Okay.

Yeah.

I guess we can dive into some site

updates here.

I'll just dive into some of the stuff

I've been working on and then Nate can

go and explain some of the videos we've

published this week.

So we've got upcoming videos here.

We've got a tier list,

a password tier list video that's coming

up.

Nate has been editing that and it looks

like it's pretty much ready to go.

We just have to do a little bit

of final checking.

There's a video about

creating a Bitcoin wallet without

connecting to the internet,

completely cold, instead of, you know,

using some sort of generation method.

And the reason why we wanted to talk

about that,

we use diceware system instead of,

you know,

using a chip to generate that wallet seed

phrase,

because

There was a recent issue that we did

do a post on the privacy news section

of our site about cold wallet, I believe,

cold card, cold card, hardware wallets.

And basically the generation system that

they used was predictable,

which allowed basically anyone to

access the wallet seed phrases so

obviously that is extremely bad and that

was a complete disaster so Jonah was like

well there's a way to fix this right

so he put together this video on how

you can use basically a dice a word

list and how you can basically create a

really secure seed phrase that

is a hundred percent random instead of

being predictable,

like with the terrible situation that

happened with cold card.

So that's going to be an interesting one,

which, which should be out on,

I believe two days from now.

So definitely look out for that.

And yeah,

that's kind of what we've been doing in

terms of I've been working on some things

on the behind the scenes stuff,

working on thumbnails,

stuff like that for videos.

We've kind of trying to be debugging the

flock video a little bit.

We're not really sure why,

but it didn't seem to reach too many

people.

So we're trying to work out

why that was the case and kind of

be messing around with that too.

Okay.

So there's also some,

there's a release this week as well for

the site, which had some updates.

We updated the foundations and

organizational donors on the website,

removed a spam link,

and there was a fix to the Yubico

UTF on Linux page.

So yeah,

that was kind of a small amount of

updates this week on the site.

And there was some articles as well that

Freya and Nate have been working on.

So

There was one about a zero-day

vulnerability in Windows from Nightmare

Eclipse,

severe Zoom vulnerability allowing

malicious meeting participants to take

over your device,

Californian city declares state of

emergency after cyber attack,

and there was also one about an

system takeover.

So yeah,

let me throw it back to you, Nate,

and you can talk a little bit about

the videos that we've been publishing and

that are coming out soon.

Yeah.

So, um,

we've been kind of pushing out a lot

of videos in very short order, uh,

which is exciting.

Very cool for us.

Um, we put out one, uh,

we've been advertising this one for

awhile.

There was a, uh,

we did a video about bull run,

which was the NSA's attempt in like the

nineties, eighties nineties,

two thousands, I think to either, um,

what did we say here to either hack,

cooperate, interdict or influence.

basically everything and all the different

ways they tried to compromise encryption

on the internet.

That went out last week,

but now it's finally out to the public.

So everybody can go watch it.

Definitely go check that out.

Um, very proud of that video.

And then also, yeah, this is the, uh,

the flock one that Jordan mentioned.

Um, we're not really sure why,

but for some reason it really,

really did not perform well.

Um,

which is sad because this is an issue

that everybody's, uh, you know,

I think I mentioned last week that it

was on a John Oliver episode and like,

this is an issue that has hit the

mainstream.

And for some reason the video just didn't

do very well.

Um,

So I don't know if you have any

ideas, let us know for sure.

But in the meantime,

you can head over to neat.tube and check

it out.

Or there's also a link in the newsletter,

of course,

and you can check it out for yourself,

share it with your friends and family.

There's actually a national week of action

against ALPRs starting Sunday and going

through Saturday.

So this video was kind of released to

coincide with that and kind of hopefully

get people interested and fired up for it.

But I think that's noalprs.com for more

information on that.

But

Yeah,

that is pretty much all we've been up

to in terms of videos.

I mean,

pretty much all we've been up to.

It's a lot.

It's a lot for a week.

We've done a lot this week.

But yeah,

all this is made possible by our

supporters.

You can sign up for a membership or

donate at privacyguides.org.

Or of course,

pick up some swag at

shop.privacyguides.org.

Privacy Guides is a nonprofit which

researches and shares privacy-related

information and facilitates a community on

our forum and matrix.

where people can ask questions and get

advice about staying private online and

preserving their digital rights.

Now, as a reminder,

as you're watching the stream,

go ahead and leave any questions you have

for us in the chat.

They can be related to the stories or

they can be random privacy and security

questions.

Actually, on that note,

I'm going to go back real quick to...

laptop here left a couple questions when

we were talking about the White House

story.

You said,

why would it stop being bad just because

the state is doing it?

It's not that it stops being bad.

It's that then that becomes an attack.

If we go after,

if there's a private hacking group in,

I'm just picking a random country and I'm

sorry.

If there's a private hacking group in

Cambodia that's going around doing scams

and hacking into people's Facebook

accounts and

And we take them out.

That is distinctly different from like

attacking a government.

If the government of Cambodia is breaking

into people's Facebook accounts,

it's just politically,

it turns into a very different thing.

It's the difference between like taking

out a mugger versus taking out a soldier,

which is still,

there's still a lot of like,

I don't know.

I feel icky,

like operating in other people's space,

but my point being,

it doesn't necessarily stop being bad.

It's just,

it's a whole different can of worms.

And yeah,

You also said our IP address is allocated

more or less regionally.

You might be right.

I don't know.

That goes above my head.

I'm just saying it's not as obvious as

like if you're flying over a physical

country and you drop a physical bomb,

it's a little bit harder or at least

– I mean obviously missiles can hit the

wrong target.

We've seen that a lot in the last

twenty-five years.

But my point being is like,

it's not like you're flying over one

country and you drop a bomb and it

lands in a completely different continent.

Like, I don't know.

It just it feels to me like there's

a lot more room for things to go

wrong on that.

But I could be wrong.

I don't know.

But speaking about being wrong,

I think we're going to move on to

our next stories,

which we have a few stories about

companies acting shady,

starting with surprise, surprise, Amazon.

And I'm going to let Jordan go ahead

and take this one away.

Yeah, let's do that.

So this story here is Amazon will train

on Twitch streamers content by default

unless they opt out.

So I think we should start by saying,

just in case you don't know,

Twitch is owned by Amazon.

They're basically the same company, right?

It kind of makes sense, actually, because,

you know,

Amazon has such a large presence in the

hosting space, I guess.

They have Amazon Web Services, which,

you know,

kind of makes sense why they would be

able to run such a service like this.

So this is kind of a very controversial

change.

I think a lot of streamers are going

to be disabling this because, you know,

obviously,

why would you want your content to be

used to train AI?

I'm not really sure.

It doesn't really benefit you exactly.

So just, I guess,

reading a couple of quotes from this

article here.

In a stream on the official Twitch

channel, Twitch head of community,

Mary Kish and chief product officer,

Mike Minton,

addressed a live audience of nearly three

thousand aggrieved users,

many of whom were posting anti-AI

sentiments in the chat.

Why is it not opt in?

That's what everyone is spamming in the

chat.

I get it.

Let me opt in versus making me opt

out, Minton said.

Well, there's an honest answer.

If this was opt in,

nobody would opt in.

And that's honestly the answer.

So I think that kind of highlights the

main issue that we have with this, right?

Like this sort of thing is

something that is kind of becoming an

issue right a lot of these ai companies

will do this well they'll say you can

use our services but you have to opt

out and the opt out is kind of

hard to see it's not really super obvious

that it's possible um i think this does

the same basically the same thing right um

And quoting again from the article,

in some cases,

this created confusion among streamers

about whether their content had already

been fed to Amazon without their

knowledge.

When one user asked if their videos had

already been used for training,

Minton responded,

I don't actually know the answer to that

question because I don't know what Amazon

has done in terms of model training and

what they've used and not used.

So obviously that is extremely concerning,

especially because, you know,

They should have not been doing that if

you didn't opt into that.

I guess they could technically do that

based on their terms of service,

but not really great.

Kish noted that Twitch is not unique in

its use of user content for AI training.

Meta, for example,

uses public content from its platforms to

train its own AI models,

meaning that if your Facebook and

Instagram accounts are public,

then your data has probably already been

used for Meta's AI training.

And if you live in the UK,

you can opt out of Meta's training

If not,

the only way to opt out is to

use the private setting,

which isn't feasible for creators who

monetize their accounts.

So I guess throwing this back to you,

Nate,

this is like one of these obvious things

where it's like, why is this opt in?

Shouldn't this be like, I mean,

why is this opt out?

Why isn't this, you know,

the other way around?

It doesn't really make a lot of sense.

What's going on there?

Yeah, I mean,

it's exactly like this guy said,

this Kish dude.

They know that most people would not opt

in.

And to their very, very tiny defense,

I don't think he necessarily meant that

maliciously.

I think he just meant it's a fact.

Most people don't change the defaults.

um most people seem to even forget that

a lot of their accounts and devices have

settings uh and most people just don't go

looking for that kind of stuff they just

they get a phone or they get an

account and they just hit the ground and

start running and you know especially with

things like this like yeah they'll tweak

the profile picture and the banner and the

bio but they're not going to go into

the privacy settings that's just they

don't even care about that

So, yeah, if it was opt-in,

nobody would opt-in just because people

never change the default settings.

But that is also like the malicious side

of it is they know that nobody changes

the default settings.

So if we make it opt-out, most people,

even when they hear about this,

they're just going to be like, eh,

whatever.

It's too much work to click three things,

which actually, to be fair,

I think I saw somebody say somewhere that

they weren't able to do this on their

phone in the mobile app and they had

to actually like log in on the desktop.

So they're kind of making this as

obnoxious as possible,

although somebody else responded to them

and said the mobile app isn't designed for

stream or for creators.

It's designed for audience and this

applies to creators.

So but yeah, I mean,

that's the simple answer is like people

don't change the default settings.

So if they make it opt out,

most people just never bother to log in

and and fix it.

But yeah, I guess another thing is,

you know,

is there really anything that, uh,

people can do that?

Are there alternatives?

Like, is there even another platform?

I feel like, you know,

what have we got?

We've got YouTube.

Maybe I feel like YouTube would also be

doing kind of some stuff with AI training

data as well.

So it's like,

it almost feels like this is becoming like

an industry standard thing.

Like you said, with meta and,

and all that, what do you,

how are you feeling about it?

Yeah, it, it really sucks.

Um,

My wife actually sent me a TikTok about

this the other day.

That's where she heard about it.

Oh man, this real quick,

this announcement was a train wreck.

The TikTok that she sent me was like

a person.

No, for real.

It was a person like commenting on,

on all these different,

the parts that were in here and like

how amazing it was that they're just like,

Oh yeah,

we don't know if they've already trained

on your data.

And they didn't mention it in the article,

but at one point somebody asked them like,

is the official Twitch channel going to

opt out of this?

And the, what's her name?

The Mary Kish.

She was like,

Yeah, I think so.

Probably.

And it's just like, wait, what?

It's opted and you're going to opt out.

But yeah, it's it's I mean, it's tough.

Laptop here said your featured link is

this StreamYard thing.

But yeah,

StreamYard only gives you like a hundred

views.

And I don't think there's a free tier,

actually.

I think we're paying even for this tier.

Um,

it only gives you a hundred people and

it's,

I feel like the issue is discoverability,

right?

Cause like, honestly, yeah,

there's a ton of options.

You could stream in discord.

You could stream in on zoom.

You could stream in a, you know,

signal you could street,

like there's a million other places,

but yeah,

The reason people use social media at all,

the reason we use Twitter and Blue Sky

and YouTube is the discoverability.

Like, we're trying to reach new people,

especially with our message of privacy.

And when you're a Twitch streamer,

you're trying to reach new people.

So...

I don't know.

There's so many things working against

people, right?

There's, like, the network effect of,

like, again, yeah,

you could set up your own PeerTube

instance and stream off that, but, like,

who the hell is using PeerTube?

And then that becomes a self-fulfilling

prophecy and a feedback loop of, like, oh,

I'm not going to set up PeerTube because

nobody's there.

Well,

nobody's there because nobody sets up a

PeerTube.

And it's just – it's tough.

There's really no easy ways out, I think,

especially when we talk about video

because, like,

video is –

so massive and like i guess the nice

thing about streaming is you don't have to

keep the old replays um so that helps

but like youtube for example if you're

gonna make like a pure tube channel with

all your youtube videos like video storage

adds up quick and gets really expensive

really fast so it's uh it's not great

yeah laptop it's called the network effect

so

Yeah, all right.

I guess we can dive into this forum

post here, which you can grab,

because I know you definitely had some

thoughts about this one.

Yeah, all right.

So one of our forum updates we're going

to focus on here is about ProtonVPN.

ProtonVPN got accused this week of running

price sensitivity testing,

AKA AB testing on their customers.

And the reason that this particularly

became an, well, I mean,

there's a couple layers to this, right?

Well, let me just read.

Okay,

I'll read two posts here that kind of

sum this up.

So the person who originally posted this

said, since Friday, August seven,

twenty twenty six.

So we saw this actually after we streamed,

I think multiple Redditors have reported

that they are seeing different prices for

Proton VPN plus suggesting that Proton is

running price sensitivity testing on their

customers.

also called AB testing.

And they've got some screenshots here.

They said proton is formally denied it.

They've got a screenshot of that.

And they said, but when,

when scribe is calling them out on Twitter

for lying by providing evidence.

And there's a screenshot of when scribes

and they linked to all this stuff too.

Um,

so this turned into a whole discussion.

Apparently you can actually see, uh,

what is it?

I think this came from a wind scribes

tweet.

You can actually see in the code where

it says there's like an AB test.

And if you're getting content a or content

B, um, and, uh,

we did pin at the top of the

post here, protons response.

Um,

so this came from somebody on Reddit who

I believe works at proton and says, uh,

They said this topic went very strange,

very fast.

So let me expand and clarify.

Proton VPN is nine ninety nine a month

or eighty three eighty eight a year.

We used to have an introductory offer for

two years at four forty nine per month.

There's been a two year intro price of

two ninety nine per month.

It has been running for a while on

some back to back campaigns.

That price ended in July and since then

it has been three forty nine a month.

um they say that there were some like

legitimate pricing errors in the

screenshots but they said uh at the end

of a long-standing sale period we often

try an a b run of the old

and new pricing on the website during the

transition to see if anything has changed

as explained to answer the speculation

already and as confirmed by others who

independently checked it there is no

adaptive pricing as in it does not vary

by browser operating system etc and it is

one hundred percent randomized

So for the past several days,

some people will still have seen the

older, cheaper two ninety nine price.

I had been of the impression that the

A.B.

was already concluded and there must have

been some cashing going on.

But it's actually due to end on Monday

when one hundred percent of people should

see the three forty nine price.

He says there's no denial that we were

doing an A.B.

evaluation.

And then.

Yeah.

So basically they're saying, like, yes,

we were.

Doing.

A, B testing,

but we weren't doing it based on user.

It was completely random.

I could go to their website right now.

Allegedly, the test should be over.

But theoretically,

if the test was running,

I could go to their website right now

and see one test.

And then if I close my browser and

clear my cookies or whatever,

and I come back later the same day,

I might see a different test.

So...

I think, I mean, personally,

I have a lot of thoughts about this,

yeah.

But I mean,

I think I'll throw this one to Jordan

since you've been kind of throwing some

questions my way.

Do you think there's any concerns over

this kind of stuff,

even if it's randomized?

Like if they're not tracking you and

they're not doing it based on your data,

because usually that's what companies try

to do, right?

They try to, the surveillance pricing,

like we think you'd be willing to pay

a little bit more,

so we're going to give you the higher

price.

But if it's completely randomized,

do you still think that's kind of a

problem?

I think that this is one of those

things where it's like,

obviously this is because we know now that

this wasn't based on people's information.

This is not a privacy issue per se.

This is one of these things where it's

like, is this a good business practice?

Is this ethical?

Is this something that we want a company

like this to be doing?

Is this a good practice that they should

be doing?

And I think, you know,

not to pull out the slippery slope

argument, but once you start,

we've definitely seen Proton adopting more

mainstream marketing tactics,

for instance,

like running Black Friday sales,

running advertising campaigns to get

people to sign up for discounted plans and

stuff like that.

And people have been very vocal in the

community about how they don't like this,

like having banners in their inbox,

especially if they're like a paying

customer.

Some people have,

very strong feelings about that.

I think it's tricky because Proton is one

of those companies where they make all

their money from people buying

subscriptions.

And there are so many people that don't

buy subscriptions and it's kind of tricky

for them to be able to, you know,

stay afloat if they don't have that

constant stream of subscribers.

But I think the fact that they were

using, you know,

some sort of AB testing is obviously it's

not a privacy concern,

but it is one of these things where

it's like,

This feels a little shady.

It's one of these things that we don't

really like when it comes to marketing

tactics.

I think the most important thing here is

to not jump to immediate conclusions and

assume that Proton was being malicious in

this aspect.

I think Jonah had an incredible response

on this thread, by the way,

if you haven't read that.

His kind of take was A-B testing

objectively isn't adaptive slash dynamic

pricing nor price discrimination.

So this is like basically what he said

is it's basically effectively the same as

a targeted or limited time sale.

So...

you know, it's interesting.

I think Jonah had probably the most

level-headed response in that thread.

I think it's important to be a little

bit more discerning and not to jump to

conclusions immediately because this

wasn't as big of an issue as I

think people are making it out to be.

Personally,

I am not really a big fan of

Proton's whole marketing strategy when

they come to, you know,

promoting their products and their

pricing.

I think it's a little rough to be

paying

I was on the visionary plan,

but paying for the visionary plan,

still not getting everything in the proton

suite.

And I still, you know,

had some things that weren't included.

But I think it would also be kind

of annoying if, you know,

you're on the unlimited plan,

which is like two hundred bucks every two

years or whatever.

And, you know,

you're getting banners telling you to

upgrade and stuff like that.

I can see why some people might have

issues with that.

this sort of tactics,

but at the end of the day,

it doesn't compromise the privacy of the

product.

So it's not a huge concern from that

aspect.

So I don't,

I'm not sure if it really matters that

much.

How do you feel about it?

Are you kind of on the fence or

are you also kind of not a fan?

I mean,

I agree with you with the marketing.

Like I pay for the duo plan for

me and my wife.

And yeah,

we still get emails occasionally about

like, Oh, upgrade to the family plan.

And it's like, have what?

Just four accounts sitting around doing

nothing.

Like,

We don't know anybody that's willing to

take us up on it, man.

I'm sorry.

But yeah, I agree with you.

I don't know.

I think I think I'm with Jonah.

Yeah, I forgot about that response.

That is a really good response.

But yeah,

it's like it's it's if it's completely

random,

if it's not profiling you based on browser

or location or any of that kind of

stuff, in my opinion, I think that's fine.

I think it's the same as a sale.

Um,

as long as it's not targeting specific

people.

And even if it's not targeting Jordan and

Nate, you know,

if it's targeting brave users or Mac

users, or cause I,

I think airlines do that or somebody does

that.

They're like,

if they detect you're on a Mac,

they'll like raise the prices a little bit

online.

Cause they're like, Oh, you're on a Mac.

Clearly you must have money.

And it's like,

or maybe it was a gift.

Maybe I got it refurbished.

Like maybe I got it on a student

discount when I was in college.

Like, come on, man.

That's, that's crazy.

So, um,

yeah i i don't personally mind as long

as it's not actually based on any real

data and if it's totally randomized um i'm

a little disappointed to see wind scribe

kind of jump on this and attack other

privacy i i really don't like seeing

privacy projects attack other privacy

projects because to me it feels very

self-defeating like we're all the example

i like to put it in is like

if we talk about like putting it in

terms of real life security

Everybody shuts their door,

locks their door when they leave their

house, right?

If you leave your house,

you lock your door.

And yes,

that's inconvenient when you come home

with an armful of groceries and you have

to fumble with the key and unlock the

door.

But we all agree, like, why not?

Like, it's low cost.

It's very relatively low effort.

Like, it's not as convenient,

but it's safer to deter somebody.

And in the digital world,

most people are basically like leaving the

door wide open, unlocked,

opening all the windows and then hanging a

sign in the front yard that says gone

to Dubai for two weeks.

Like, and for some reason, you know,

for some reason we're busy like

complaining about, Oh,

you ran a marketing campaign.

And it's like, dude,

we're all trying to get people on the

same, like at least me, we're like,

we're just trying to get people to like

care at all to like shut the door.

And I don't know.

I just don't like seeing privacy

companies, uh,

attack each other like that.

If you want to attack the non-privacy

companies,

if you want to attack WhatsApp and stuff

like that, like go for it.

But

I don't know.

That was in poor taste, in my opinion.

But I digress.

Yeah,

I think it'd be better if people were

using Proton.

Then they'll be like, oh,

I don't want to use Proton.

Their marketing is so bad.

I'm going to go back to Gmail.

And it's like, well,

that's just not a good idea.

It doesn't work.

So I don't know.

I do think that it's important to hold

these companies accountable,

but also it is a little disappointing and

unprofessional when we see

like these organizations kind of taking

pot shots at each other.

I am not a fan,

but obviously that's up to these

organizations to work out in their

marketing and public image.

And it really does not to linger on

it too long,

but what ends up happening is for people

who...

especially if they're on their own and

they don't know who to trust,

they end up, like you said,

just quitting and going back because if

everything's like, oh,

don't use Proton because it's got this

minor thing wrong with it.

Don't use Mulvad because of this.

Don't use Windscribe because of it.

Like eventually they hit a point where,

like you said, they're just like,

screw it, I quit.

I'm just going back to what I was

doing because every time I use something,

somebody comes along and tells me that

sucks and I shouldn't be using it.

And it's just,

especially without knowing their threat

model.

And it's one of those things where like,

if they don't have somebody that they can

go to, like I have friends and family,

they hit me up all the time and

they're like, hey,

are iPhones really that private?

And it's like, well,

I know this person is never going to

use graphene.

So honestly, yes,

I'd rather you buy an iPhone instead of

like a crappy LG phone or something.

And it's just, people don't have like, if,

if you make it too hard,

they're just going to give up.

And yeah, it's,

it's not cool to see that happening in

the space.

I digress.

I'm getting off topic, but yeah.

So that was the thing.

And, uh,

just remember not to jump to conclusions

and, um, uh, uh,

another company,

it was another company laptop did another

company attack proton or a customer.

It was wind scribe, uh,

picked up this story and, um,

basically called out proton and said, no,

you are doing AB tests.

Here's the code.

But again, it's, you know,

it wasn't adaptive pricing.

That's which you can still say you don't

like AB tests.

That's fine.

I'm not telling you not to say that,

but I just want to make that clear

that like they weren't tracking people

based on browser or location or anything

like that.

It was just randomized what price you saw,

but.

I digress.

With that,

we're going to jump into a story about

Mozilla,

who had to issue new GPG keys following

an exposure, which is never fun.

That always sucks.

Let's see,

Mozilla announced on Monday that it had

issued a new GPG signing subkey used for

some Firefox and Thunderbird artifacts

after the previous key was accidentally

exposed in a GitHub repository.

The exposed key was used to sign Firefox

and Thunderbird artifacts,

such as Linux tarballs, RPM packages,

and checksum files.

An unencrypted copy was inadvertently

committed to a GitHub repo,

but it was a private repository accessible

only to a small group of Mozilla

developers who already had access to the

key via other means.

Mozilla said that our review of available

audit records found no evidence the key

was accessed by an unauthorized party.

Nevertheless,

they decided to revoke the exposed key and

issue a new one.

And in addition,

they said that they had added protections

to prevent similar incidents in the

future.

They do say that most users do not

need to take any action.

Users who manually verify GPG signatures

will have to import the new key and

revoke the old one.

And in addition,

those who use Firefox RPM packages may

need to take some steps,

which that might include me because I'm a

cubes user and everything's based on

Fedora.

So I should click that link.

And Mozilla has shared detailed

instructions right there.

Um, so yeah, I think, uh, um,

I will say this is a little bit

of a disappointing lack of transparency in

my opinion.

Um,

it sucks that they didn't really seem to

give a whole lot of details about how

did this happen?

How long was the key exposed?

Um,

I don't remember if they gave details

about what they did to prevent this from

happening again.

Um,

Um, but I,

I guess I will give them a lot

of credit for like coming forward with it

and being proactive.

I mean, it was like a private repo,

right?

So in theory, there shouldn't be any risk,

but still just being like, uh,

let's just be safe and rotate it.

Like I do respect that, but, um,

Jordan, to throw this back to you,

I think the first question that I think

a lot of people would have is,

do you think this is a reason for

people to reconsider using Firefox?

Is this like an oh crap moment that

shows negligence or anything,

or do you think this is just kind

of like things happen?

I think we've got to give Firefox a

decent amount of props here because they

did exactly the right thing.

There was a mistake.

Mistakes do happen.

There's always going to be mistakes,

but it's the way that they handled it,

which I think is the most important part,

which, like you said,

immediately rotating that GPG key is the

most important part.

And they did that.

They notified everyone.

They did exactly what they should have

done in that situation.

If, for instance, we found...

that they did leak that key and then

they just decided to do nothing about it,

then that's where we would start having

issues where I would be like, OK,

maybe you should probably not use Firefox

because they seem a little negligent.

But, you know, mistakes happen.

They fixed it.

They've done everything in their control

to notify everyone.

And, you know,

that's basically the best case scenario in

a situation like this and i think it's

it's always good there's always going to

be issues uh especially when it comes to

like you know supply chain attacks where

um someone can you know get access over

packages and stuff like that um i think

it's always important to be proactive and

be aware of what's happening but i think

in this case

It sounds like most users don't have to

be too concerned about anything apart from

the RPM packages and also people that

manually verify the GPG key,

which I'm sure if you're one of those

people,

then that's probably something that you'll

have to look into yourself.

But for everyone else,

nothing you have to do.

I think this is a good

Uh, this is good that Mozilla was, uh,

open and transparent about making a

mistake and fixing it properly.

So that's basically the best case scenario

in my opinion.

Yeah.

Supply chain attacks are really a whole

different animal.

Cause you know,

we always tell people to like,

make sure you use official outlets,

like get things from the official source

and whatnot, but like.

If it's a supply chain attack,

what can you do?

You really just have to hope that the

company is doing everything in their power

and they're quick to respond and kind of

sucks.

But yeah.

Before we jump into our next story,

actually,

we did get a quick question in the

supporter signal chat.

This person said,

for transportation in general,

is there anything we can do to be

more private about where we go?

And they said that, for example,

if you live in an area with public

transit, trains, metro, subways, buses,

all these things often ask for some

identifying information,

such as your name and phone number,

but usually lack the rigorous verification

processes that places like airports

enforce.

Like, you know,

usually nobody checks my ID when I get

on a bus.

A lot of the time they don't even

check if I paid.

They said,

is it a good idea to travel under

different names and use aliases wherever

you can, or are there problems with that?

And what are some other strategies we can

use to combat surveillance when traveling?

I mean, I'm not a lawyer.

I kind of view travel more from a

data breach perspective, you know,

because a lot of the time,

especially nowadays with things moving

into apps,

a lot of the time it's like you

don't,

physically,

like I'm pretty sure back where I lived

in Texas,

you couldn't even pay in cash for a

bus ticket.

I could be wrong.

Um, but whenever I took the bus,

I usually used an app.

And so at that point it's, you know,

using a, my pseudo number,

using a simple login alias, um,

trying to use a VPN,

just trying to think like if this app

has a data breach,

what information will it be able to

reveal?

I think I didn't even have to give

it location information.

I think I could just tell it what

bus stop I wanted to look at.

But, um, yeah,

I don't know.

That's kind of how I look at it.

Cause also I don't want to sound

defeatist,

but a lot of buses nowadays also have

cameras and your phone's tracking your

location.

So I don't know.

I feel like that's kind of overkill to

use aliasing information.

And I do wonder if there would be

any legal repercussions there.

Like it's one of those things where if

something goes wrong,

is it going to cause more problems that

your ticket doesn't match your ID?

I don't know, but yeah.

I also don't do a lot of public

transit because I live in America and

unfortunately our public transit is not

that great.

I would love to do more public transit,

but it's just not always feasible.

Do you have any thoughts on that question,

Jordan?

I would say there's,

I can't really comment on like,

I've never heard of any public transport

needing an app.

So try and avoid using an app if

you can.

I'm not sure if that's always possible,

but if you can avoid using an app,

I would say avoid that.

A lot of public transit systems that I've

used have always had a card that you

could use and you can top it up

with cash.

I'm not sure if that's also about,

like you'll have to do research into that

because a lot of places they'll have

different options available because,

you know, there's people that are like,

don't know how to use a phone or

don't have a phone.

So what do you do then?

Oh,

I guess you can't use the bus or

like, you know, it doesn't,

there's always,

they have to make some different options.

So

definitely look into that um i think the

most important part is also just um try

not to uh

share data with these transit companies if

you can.

Don't download the app,

don't give it your phone number,

don't give it your address,

don't give it all that information.

Try and minimize the amount of data that

you're sharing with those companies,

or if it's a public system,

then the government.

So I think that's also an important thing.

I think

I'm kind of a little bit biased,

but I do a lot of cycling and

no, no,

no personal information required to do

that.

Walking also no personal information

required, obviously, you know,

that is, like Nate said,

it kind of depends where you live,

if that's an option or not.

If you live in, you know,

a rural town,

I'm sure that's probably not as viable,

but that is another thing.

And I think, you know,

there's also so much information that you

can share when you're driving a car too,

like we've talked about with Flock, right?

You know, when you're driving around,

there's cameras everywhere,

recording your car,

recording your number plate.

It's also not a great

option either it's pretty terrible cars

are kind of terrible for privacy as well

they share a bunch of information so it's

just trying to like do harm reduction um

where you can

And obviously everyone has different

requirements because some people need to

drive, some people can't drive,

all sorts of things.

So it's just about reducing what you can

and not, like Nate said,

not going overboard because as Nate said,

there's cameras in the public transit

system.

There's all sorts of tracking that happens

through that as well.

And I'm sure somebody could work out

who you are, if they see, oh,

this person taps on it this time,

and then they just check the security

cameras and they can see it's you.

So, you know, there's, there's, um,

there's always a trail when it comes to

public transit.

And anytime you step out your front door,

you're basically going to be recorded.

So just take that in mind.

Um,

I guess we can jump here into the

next story though.

This is kind of a group of stories

this week, and it's about signal, um,

Signal making a bunch of new updates.

So this week I'll talk about the first

one and then I'll hand it over back

to Nate.

So this one is more linked devices are

on the table and the Android tablet.

Now you can easily link another Android

phone or Android tablet to your Signal

account.

We're also expanding linked device support

on iOS.

So you can link an iPhone to your

Signal account in addition to our ongoing

support for iPads.

look for Signal iOS version eight point

two two and Signal Android eight point two

in the app slash Play Store near you.

So I think this is one of these

things that we've all been like basically

begging for Signal to do.

And it was like,

one of these things that's so easy for

them to do as well.

And it's like a no-brainer for them to

enable this.

I think the most interesting thing about

this is that previously, you know,

a lot of people were complaining that they

would have to use MOLLE

instead of the official Signal app to be

able to link another Android device to

your account.

And now that feature has been expanded

officially to the official Signal app,

which is really important.

And it's better to be using the official

Signal app if you can.

just to reduce the amount of trust you

have to have in different projects.

So it's really cool that they've been able

to release that as a new feature.

Do you have any thoughts on this one,

Nate?

No, I just, yeah,

I think it's really cool.

I mean,

obviously everybody's in a different

situation,

but my first thought was at my last

job,

I used my iPhone as a work phone.

And so I would have my Android was

my personal phone.

And then my iPhone would have like teams

and all that crap on it.

And the only reason I had to carry

around the Android was because of signal,

because my wife exclusively uses signal.

And there was a period where I,

Um,

basically I got some feedback that I was

on my phone too much.

So I was trying to be on my

phone less and I had to go make

like a separate signal account for the

iPhone so that my wife could text me

there.

And it's like,

it'd be really cool if we could just

like, if this had existed at the time,

it's like,

I could have just put signal on my

iPhone and been good to go.

And so, yeah,

I think this is really cool.

I'm also thinking of the infamous time

that my phone exploded.

And I remember sitting there and going,

how do I recover my,

my signal account now?

And, uh, you know, thankfully it was,

it was pretty easy cause I had all

the, I knew the pins and everything, but,

um, yeah,

to just like have that backup and

everything is a definitely super,

super cool.

So, um,

before I jump into the next one real

quick, laptop said,

what's wrong with Molly?

There's nothing wrong with it or actually,

actually I'll turn that one over to you

since you're the one that said it.

Um, what's, what's wrong with Molly?

Um, obviously, you know,

when you're trusting a third party,

like with, with your,

with your signal chats and stuff.

So it's adding another party that you have

to trust, like in addition to signal.

Um, and also Norli has been,

unfortunately,

they've been a bit slow on keeping up

to date with signals updates.

So like,

that is also a concern from a securities

perspective.

It adds a bunch of interesting new like

privacy and security features,

but it does seem like, um,

you know,

it's definitely a risk analysis thing.

If the chats that you're having on Signal

are really important and secure and stuff

that can't leak,

then obviously you want to reduce the

amount of exposure that you could possibly

have.

So I think another important thing to have

to talk about in this story is just

the expansion of risk that happens when

you add linked devices to your Signal

account.

I think there's less risk when it comes

to adding a mobile device as a linked

device.

Whereas if you're adding a desktop device,

that's where we do have more concerns.

We've had stories in the past where the

local database on the Signal desktop app

was not encrypted or it's easier to access

on a desktop because it doesn't have as

robust permission system to restrict

access from malicious apps.

So every linked device you're adding is

increasing the attack surface.

That's one another thing to discuss as

well when it comes to this.

And like I said,

the MOLLE using MOLLE is going to increase

the attack surface because there's adding

another device and you're also trusting

another group of people to to manage that

app, which.

Is.

isn't the only party you have to trust

more or less because of the end-to-end

encryption, the client, I mean.

I mean,

there's the Signal developers and then

there's the MOLLE developers.

So you're trusting the Signal developers

to develop the Signal app.

And then Signal is based on, no, sorry,

MOLLE is based on Signal,

which then they also have to add code

on top of that.

So you are trusting MOLLE and

signal developers at the same time so

that's an extra party you have to trust

to make sure that they are not inserting

any malicious code for instance because if

your client is compromised then this this

the end-to-end encryption doesn't matter

because you know it's only end-to-end um

so that's why it's important um hopefully

that makes sense

And also, real quick,

I'm glad you mentioned the device raises

your threat model thing.

That is a good point.

But I just want to point out,

it's not even necessarily a malicious

thing.

It's just you have to trust them to

implement it correctly.

I don't know why this example just popped

into my head,

but if there's a Christmas gift,

and let's say I'm going to give...

I don't know.

Let's say I'm going to give my sister

a Christmas gift or let's say my wife

wants to give my sister a Christmas gift

and she wraps it up and hands it

to me.

And then for some reason,

I deliver it to my sister.

You have to trust me not to open

it.

Or in this case,

like for some whatever reason, again,

I don't know why this example popped in

my head.

For some reason, I decide to rewrap it.

You have to trust me to wrap it

right the same way that she did.

Like it's just it's more people involved.

It's more chances for something to go

wrong.

Even if it's not malicious,

it's just people make mistakes.

Yes, Mali is open source,

but are they auditing every single

release?

Is there somebody out there who's combing

through every single release?

Are there multiple somebodies?

Because the first person who combed

through it could have missed something.

It's just you're always...

there is always a level of trust involved.

Um,

you're never going to completely remove

trustless is kind of a buzzword in my

opinion,

because there is no such thing as

trustless.

You're always trusting someone somewhere,

but the idea is to remove as much

trust as possible.

So, um,

Yeah,

Dag here did mention that Mali can encrypt

local logs on the device, which, yeah,

I mean, Mali does some cool stuff.

And we're not saying don't use it.

It's just keep in mind those are the

trade-offs.

You're introducing another party into the

mix.

On that note,

we'll jump into the next quick Signal

update,

which is that Signal is introducing

automatic key verification.

Um, this is pretty cool.

So, uh,

this is supposed to compliment the

existing safety number system.

It's not supposed to replace it.

Uh,

it works through a system of verifications

performed by you,

your signal connections and third-party

auditors that together provide the same

assurance as manually verifying safety

numbers.

Unlike safety numbers,

these verifications are done independently

and do not require an in-person meeting or

secondary communication channel.

This system of verifications ensures that

the association between a phone number or

username and its public encryption

key is globally consistent and transparent

to all participants.

This protects against scenarios where a

key is swapped out without the owner's

knowledge.

For example,

a malicious party compromised signal and

associated a different key with your

connection's phone number.

There are technical details in the blog

post if you want to learn more.

I'm not going to go into them because

I'll skim here real quick and you can

see it's very detailed.

I actually do need to finish reading this.

They do try to break it down into

understandable terms,

which is super awesome.

And I do want to finish reading it,

but I'm not going to read it all

here.

They said to see it in action,

go to a Signal Connections profile,

hit view safety number and tap the verify

automatically button under the automatic

key verification.

The button will show a green check mark

and encryption verified when the feature

is available and verification succeeds.

Over time,

this verification combined with the ones

continually performed by your Signal

Connection and third party auditors

ensures the consistency of a Signal

Connections key across Signal ecosystem.

Uh,

I did try to test this out personally,

um, with one of my contacts,

I'm guessing they haven't updated yet

because it didn't let me, uh,

it was like grayed out.

Um,

I also have an issue where I'm usually

pretty good about actually like doing the

safety number thing with people just for

fun.

So I kind of had to dig through

and be like,

who have I not verified yet?

But, uh, yeah.

Um, that's what I've got here.

Uh,

I don't know if I have any thoughts

on that one.

Um,

Yeah,

I don't really have any thoughts on that

one.

Again,

it's just it's not a replacement for the

safety numbers.

Do you have any opinions of that one,

Jordan?

No,

I think this is just signal bolstering

their ability to verify contacts and

stuff.

I think it's always important to give

extra verification stuff,

especially because I'm not verifying every

single person in my contacts,

but I think it's also good to mention

what

why would you want to verify your

contacts?

Why would you want to do that in

the first place?

What benefit does this give, I guess?

And I guess that would be if somebody's

account gets taken over,

you can tell that their account's been

taken over because their safety number

changes.

That's one thing.

Um,

it basically allows you to know that the

person you're talking to is actually the

person that, you know, on the other end.

Right.

Um, so this automated like, um,

key verification system is, uh,

I guess just like another additional

layer, like you said,

it's not something that's going to replace

the safety number system, but it's like,

you know,

if something is going on with that,

if like there's an issue with the

encryption, then it's going to notify you,

I guess.

So I think that is,

is also important to have that.

It does kind of, I guess,

make me wonder if there's going to be,

further changes to how the the key system

works maybe uh is this like something that

they're gonna improve on more in the

future um i'm not really sure but i

think a lot of people are don't like

i see some people in my contacts who

their safety number constantly keeps

changing and it's like you know i think

if this system is able to kind of

keep it so that at least I know

that this person is going to receive the

message, like it's, I don't know,

it's just,

it's another thing that can help, uh,

verify that.

Right.

So I don't know.

I'm not really, um,

I'm not really super hyped for this

feature, but I think it's a good, uh,

increase in, in safety for some people.

Yeah,

it's definitely one of those behind the

scenes, not super sexy.

Like I'm not sitting here like, oh yeah,

but I'm just like, oh, okay,

that's interesting.

That's cool.

So yeah, I hear you.

It's not the most exciting thing out

there,

but it is cool to see Signal constantly

improving like that.

Yeah,

I guess talking about Signal constantly

improving,

there's another update here from Signal.

Signal is working on registration without

a phone number,

but what form will it take?

So this article here is from this

unofficial website called aboutsignal.com.

And basically what they've done is they've

put together this article that

basically shows every point where Signal

is working towards removing the phone

number requirement.

There's been hints in GitHub code that

Signal is exploring support for

registration without a phone number,

which, oh my goodness, if this happens,

I'm going to be so happy because that's

like one of the biggest issues that some

people have with Signal, right?

It's like, oh,

I don't want to give it my phone

number.

This is obviously a honeypot.

It's like, well, if they remove it,

then what's the argument at that point?

There is no argument.

And I think, you know,

I think this is exactly what we want

Signal to be doing.

We want them to be closing every single

loophole that pushes people away from this

app because we

We want people to have the most secure

communications possible.

I guess here's a rundown of what the

changes look like.

There's a commit here that said,

don't allow or set registration lock on

accounts with no phone number.

Add utility methods for getting country

region codes for accounts that may not

have phone numbers.

Add support for pessimistic locking of

phone number lists accounts.

Do not allow accounts without phone

numbers to perform P&I key operations.

Basically,

all those commits together show that

Signal is making backend changes to

support accounts without phone numbers.

registration without a phone number will

be optional.

So if someone is still wanting to use

their phone number to sign up, they can.

I think everyone in the privacy community

is not going to be using a phone

number.

So that's cool.

One issue that I did see with this

that is probably the most frustrating

thing is it looks like you can't convert

a Signal account that uses a phone number

into one that doesn't use a phone number,

at least from the information that we have

already,

which is

I think might become a bit of an

issue because if you're like me,

you probably have like a hundred signal

contacts or whatever,

like fifty signal contacts.

And if you have to start a new

account,

you're going to have to re-add every

single signal contact that you have on

your new account,

which is kind of a pain.

There's no easy way to do that.

So that's probably my biggest concern with

this.

It's going to be kind of annoying to

have to recreate your signal account.

I'm not really that bothered by this,

the phone number requirement.

So maybe this is just going to push

people that were kind of resistant to

using Signal over to using that.

I'm not sure.

But yeah,

I guess this is one of those things

that's like, Nate, you were saying before,

like, oh,

this isn't like a really cool and sexy

change.

This is that.

So how do you feel about it?

I feel pretty good about it.

One thing we should add is that this

article links to another article from

August seventh that's titled signal login

colon operational or optional registration

without a phone number will require one

time payment.

That's really it.

There's no information in the article.

It's just, again, speculating.

We don't know.

Presumably it will allow like Apple Pay,

Google Pay for convenience,

but we don't know if they're going to

allow like Monero or cryptocurrency or

something as an alternative.

Yeah, I think overall, I mean,

I'm definitely a fan of this.

Me personally, I think I'm a little bit...

paranoid again having had my phone explode

and like so much of my life is

in signal i'm kind of okay with like

yeah i'm just gonna leave my phone number

there as a backup just in case i

don't think my threat model is so high

that i need to get rid of the

phone number but yeah it is it does

kind of suck that you won't be able

to remove a phone number um i do

wonder if uh i wonder if that's like

a technical thing that there's just like

really no way for them to pull it

off or maybe that'll be something they do

down the road i'm not really sure but

um

I don't know,

the phone number thing has never bothered

me too much,

but also I recognize my privilege of

living in America where I can have as

many phone numbers as I want and I

don't have to show ID to get a

SIM card and stuff like that.

I think...

I think Signal did the best they could

to protect that information in the sense

that like phone numbers are hashed.

So the government can't go, hey,

give us a list of phone numbers or

like, you know,

give us a list of these people.

But there's nothing stopping the

government, again,

going back to countries where you need to

turn over ID to get a SIM card.

There's nothing stopping the government

from going, hey, here's a phone number.

Do you have this as a user?

And they can confirm or deny that,

which is unfortunate.

It's also,

they say that it's the goal is to

prevent spam.

But again,

Spammers don't care,

so what's to stop them from just creating

infinite VoIP numbers and creating Signal

accounts?

I don't know.

I've never really had a spam problem on

Signal,

but I've heard that some people have,

so I don't know how effective that

actually was.

I don't think it's fair how much heat

Signal took for this.

Like you said, people are always like, oh,

it's a honeypot.

I think people confuse anonymity and

privacy way too much.

Signal never promised you to be anonymous,

but it is private.

It protects you, but

Uh, still, I think this is a win.

I think for people who don't want to

turn over a phone number for any reason,

whether it's a perfectly sensible one or

just paranoia, it doesn't really matter.

I think that's great that they have this

option and I just hope that they will

support some form of private payment

option because otherwise I,

I think it's kind of a hollow victory.

If it's like,

you don't have to hand over your phone

number,

but now you have to pay through the

app store,

which is even less private than that in

most cases.

So yeah,

I think those are kind of my only

thoughts.

Yeah, totally fair.

It'll be interesting to see how this ends

up rolling out.

I'm assuming that we'll probably get

something in the beta slash alpha channel

at some point where we'll be able to

check out this and definitely make sure to

get subscribed here on YouTube or whatever

platform you're on.

And we'll have updates on that as it

rolls out.

But yeah,

that's kind of everything on that one,

unless you had anything more to add.

I just wanted to mention what Jonah said

here.

But yeah,

everyone hates three month for this.

He's got a point if, if, I mean,

to be fair,

I guess signal offers the alternative,

right?

Like you can use a phone number,

but yeah, a lot of people,

I haven't seen so much hate for three

month because they charge,

but I've seen a lot of people point

out.

It's like, yeah,

it's a tough sell to get your family

to spend five dollars on a messenger or

whatever.

So I don't know if there's pros and

cons, but yeah, he's,

he's got a point there.

Uh, speaking of anonymity,

what do you think is the best messenger

to use with a pseudonym?

Um, I mean,

I think I have a thought on that.

Do you have a thought on that one?

I mean, I have a thought.

Yeah.

Why don't you start us off here?

Probably, probably simple X.

That was the first thing that came to

mind for me is SimpleX doesn't require any

information to sign up.

Decentralized.

Actually,

one thing I do like about SimpleX that

I... Oh my God,

I would kill for Signal to introduce this

is SimpleX does...

different profiles that are all managed if

i understand it correctly i haven't used

it a ton but there's like different

profiles but they're all managed in the

same inbox so like i could add you

on simplex as nate and then i could

add like my wife on simplex under my

real name and i'd use them both from

the same screen but you guys would both

see a different identity which is just

like holy crap that is amazing if if

i'm understanding that correctly i might

be wrong but um

Yeah, no,

it's interesting because I have this

problem.

I won't go super into depth about it,

but I don't go by the name that

I use on here in real life.

And sometimes I have to add people on

Signal and I'm like, oh, yeah,

so that's like my name,

like not like the name that you should

call me,

but like that's another name that I use

and people are kind of confused.

And it's good when it gives you that

option.

to basically have another name appear or

like you said that would be really cool

if you could just have it like be

able to choose how you appear to that

specific person um that does sound really

cool actually I really hope that that's uh

that's something that Signal could add

because it's an issue with Signal I know

like

I don't know if you want to talk

about it a bit,

but I noticed you definitely do have an

interesting strategy regarding that on

Signal.

And I've thought about doing that because,

like,

sometimes I don't want to share what my

real name is with people,

and it's kind of one of those issues.

I guess we should just quickly,

before I swap it back to you here,

though,

we should probably discuss what are our

recommendations for

right now on privacy guides so like you

said there's SimpleX which does offer the

ability to do that so that was probably

the main recommendation that you could use

for that as far as I know none

of the other recommendations really give

you that option

So yeah,

basically what Nate said is SimpleX is

going to be your best option,

the only option really in our

recommendations.

So definitely at least test that out.

I've used SimpleX before.

It works quite well.

I think it's definitely not on par in

terms of usability to Signal.

So maybe you can talk a little bit

about your interesting strategy that you

use.

If you want, it's up to you.

No, that's fine.

Yeah, so my thing on Signal...

Cause for a while I had like a

personal one and a new oil one.

And then for some reason,

I think I just wasn't,

I think actually what it was is like,

as the privacy side of my life has

slowly become more of a main important

part.

Um,

I wanted more like instant access to

things like, uh,

especially when Henry and I worked

together on surveillance report.

Like I didn't want to wait until I

got home at the end of the day

to get messages from him.

So I started using my personal signal

account a lot more for,

for new oil stuff.

And, um,

I think there was even like something else

I started using it for.

I can't remember,

but I started using it for another thing.

And I,

I am that psycho who uses different names

in different parts of my life.

So I'm very open about the fact that

Nate is not my real name.

And I use different names for like music

and writing and stuff.

And so I hit a point where, yeah,

I had like all these different signal

accounts, like,

or like different parts of my life

converging in signal.

And the way I decided to get around

it was to just make my display name

was the man with many names.

Um, because I did realize I'm like, yeah,

most people know, uh,

especially once they get to know me,

you know, I'm like, yeah.

So I have this, I work in privacy.

I go by Nate.

And like, when I tell people, it's like,

yeah, I have multiple names,

which weirdly people are not surprised by.

I don't know what that says about me,

but, um,

It's a, yeah,

it just hits a point where it's like,

people are just kind of used to it.

Like, oh yeah, the man with many names.

Cause they know it's true.

He has so many names and it, uh,

yeah, that's how I got around that.

But I mean, a lot of people,

you know, put a nickname or X or,

you know, anonymous or whatever, um,

as the display name,

but it's definitely not as,

as robust of a system as the profile

thing from simple X,

which laptop here said,

I think you actually have to switch

screens for profiles,

but I still think it's easier with

it's still an easier implementation than

like having signal and Molly or having

like different graphene profiles or,

you know,

all these different ways of doing things.

So.

Yeah.

It's been an issue that I've been running

into where I've got like,

two Signal accounts.

And then I'm like, oh,

but then I can't talk to someone using

another one because it's got that name on

it and it's got things that would reveal

other information that I don't want to

share.

So it is kind of frustrating if you're

stuck using something like Signal.

It's like, oh,

if it had that as a feature,

that would be great.

But it's just not something that Signal

supports right now.

So you're kind of stuck with using SimpleX

Chat,

which

do recommend on our site so definitely

check that out if that's something that

you um jonah said just make all your

names start with the same letter and your

signal profile can just be n or something

yeah yeah but then the problem is i

like to randomly generate my names that

way there's no um there's no like

You know how it's like people aren't as

random as they think they are.

So if you try to like randomly come

up with passwords,

they're probably not going to be as random

as you think you are.

And I don't know.

I just, I'm, I'm weird about it.

I literally just use a random name

generator.

So I'm kind of at the mercy of

what that comes up with.

I know I'm a, I'm weird.

You know what though?

It's working.

Like I said,

like a nine out of ten times people

are just like,

they don't even bat an eyelash.

So yeah.

And I've,

I've had multiple people in different

situations be like,

who does this person know yet?

Like they'll meet somebody new,

like a friend or something.

And they're just like,

what name do they know you as?

Um, laptop,

does simple X have multi-device yet?

Not exactly.

It has, um,

like they have to be on the same

LAN and you can like scan a QR

code and connect them.

Um, but technically yes.

So, yeah.

Let's see.

If anybody has any last questions,

go ahead and drop them now.

I'm looking at the privacy guides.

I'm looking at the forum thread.

No new questions in there.

And I've had the signal chat open as

well.

I mean, if nobody has any questions,

I'll go watch the latest episode of Silo.

Damn, yeah.

I'm not seeing any questions in here

either,

so I feel like we can start wrapping

it up.

Just a reminder, though,

if you are a member,

Privacy Guides member,

that we do have a signal group and

you can ask questions there.

If you don't want to share the question

publicly or anything like that,

definitely consider asking.

posting in there if you're a member and

you want to hear what we have to

say about a topic then feel free to

do that oh looks like we got a

question here from terracotta pie should i

be concerned with linkedin requiring me to

verify my id with persona after changing

my email um it depends right like i

think

It obviously sucks because Persona is a

really suspicious company.

Every single age verification or ID

verification company is pretty suspicious.

And I think Persona has been shown to

be linked to some weird stuff.

And not particularly surprisingly,

it obviously has concerns about data

privacy because you have to submit your ID

to them.

So I think...

It depends on how much you need LinkedIn.

I think there's some industries where it's

like if you don't have a LinkedIn,

you're basically never going to get a job.

So if you have connections through

LinkedIn that are really important,

then obviously you need to make a decision

based on that.

I think LinkedIn is one of those

platforms that I think it really depends

on the industry that you're in and you

know having professional connections is

important right if you want to find a

job so it's kind of up to you

I personally

have given LinkedIn my ID.

So I don't know,

I think you got to,

you got to weigh up,

you got to weigh up the downsides and

benefits for that yourself.

And if it's,

if you don't really have that many

connections and you're not really using it

that much,

then maybe it's time to let it go.

But if you do need it for like

professional connections,

then I would say it's probably a good

idea to

uh to do it unfortunately it kind of

sucks they're forcing your hand so jonas

said watch silo live on stream i'll do

it man i was gonna say what if

we uh what if we do it in

the the supporters chat in the signal chat

i'll just stream it there so you know

sign up for a membership and you can

watch silo with me every week

Um, yeah, I just,

I just want to echo what you said

about the, um,

like sometimes you got to do,

I I'm with you.

Like, I don't even have a LinkedIn.

Thank God I haven't needed one, but I've,

I've met people that say that same thing.

It's like, yeah,

no LinkedIn is where I found like my

last four jobs.

Like it's,

it's really critical to my industry.

And unfortunately at the end of the day,

you have to make sure you're taken care

of.

Like,

I mean,

I guess if you want to go live

out of your car or be homeless because

you just don't want the data brokers to

have an address, that's on you.

But seriously, jokes aside,

if your privacy is so extreme that it's

holding you back from getting a job,

advancing in your career, finding love,

having a family,

having stable mental health,

and I'm being a little bit joking but

also serious,

that's when it's gone too far.

Yeah.

Um, yeah, if you don't need LinkedIn,

if you don't need to give them your

ID, then please don't.

But if,

if that's the only way you're going to

be able to like keep food on the

table, then by all means,

you gotta do what you gotta do.

So, yeah.

But, uh,

let me check the forum post again.

Nothing yet.

I do like that the forum automatically

updates every once in a while.

There have been a couple of comments since

we started.

And they're not questions.

They're just comments to other users.

But I like that I don't have to

refresh the page.

I just pull it up,

and it's automatically like, boom,

new comment.

I think that's pretty awesome.

But I think that's all we got.

I guess we'll go ahead and call it

a stream.

So all the updates from this week in

privacy will be shared on the blog every

week.

So sign up for the newsletter or subscribe

with your favorite RSS reader if you want

to stay tuned.

For people who prefer audio,

we also offer a podcast available on all

podcast platforms and RSS.

And this video will be synced to PeerTube.

Privacy Guides is an impartial nonprofit

organization that is focused on building a

strong privacy advocacy community and

delivering the best digital privacy and

consumer technology rights advice on the

internet.

If you want to support our mission,

you can make a donation on our website

at privacyguides.org.

To make a donation,

click the red heart icon located in the

top right corner of the page.

You can contribute using standard fiat

currency via debit or credit card or opt

to donate anonymously using Monero or your

favorite cryptocurrency.

Becoming a paid member unlocks exclusive

perks like early access to video content

and priority during the Q&A.

You'll also get a cool badge on your

profile in the Privacy Guides forum and

the warm,

fuzzy feeling of supporting independent

media.

Thank you so much for watching and we'll

see you next week.

See you next week.

Episode Video

Creators and Guests